Information processing device, information processing method, configuration device, and configuration method
By employing execution environment isolation and separation mechanisms, the information processing device addresses vulnerabilities in automatic control systems, reducing security breach risks and enhancing defensive capabilities through secure configuration and risk assessment.
Patent Information
- Application Number
- JP2024540109
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-08-09
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2042-08-09
AI Technical Summary
Existing information processing devices in automatic control systems, particularly in automotive applications, are vulnerable to security breaches due to external attacks, which can compromise their functionality and safety, and existing technologies do not adequately address reducing the risk or scope of such breaches.
Implementing an information processing device with execution environment isolation and separation mechanisms, including an execution environment isolation setting unit, deployment unit, and configuration risk assessment, to logically separate and secure execution environments, assess risks, and control system settings, thereby reducing the risk of security breaches and enhancing defensive capabilities.
The solution effectively reduces the risk of security breaches and enhances the robustness of information processing devices by isolating execution environments, assessing configuration risks, and controlling system settings, thereby improving defensive capabilities and narrowing the scope of potential breaches.
Smart Images

Figure 0007789222000001 
Figure 0007789222000002 
Figure 0007789222000003
Abstract
Description
[Technical Field]
[0001] The present application relates to an information processing device, an information processing method, a configuration device, and a configuration method. [Background technology]
[0002] There are cases where multiple functions are coordinated and integrated in an automatic control system. Automatic control systems are expected to recognize the surrounding environment, make appropriate decisions, and perform optimal control. For example, an automatic driving system for a car consists of an automatic driving control unit that generates optimal control parameters according to the surrounding conditions, and an engine control unit, a brake control unit, and a steering control unit that respectively realize engine control, brake control, and steering control of the vehicle.
[0003] As the level of autonomy of automated driving, as exemplified by the automated driving levels defined by the Society of Automotive Engineers (SAE) in the United States, increases, information processing devices are required to connect to external systems and perform coordinated processing. Information processing devices that make up highly autonomous automatic control systems configure the entire system by connecting to a variety of other information processing devices through a network. Furthermore, even when performing system diagnosis of an information processing device, the information processing device must connect to external systems and diagnostic equipment and perform coordinated processing.
[0004] In recent years, the automotive industry has begun to adopt OTA (Over The Air) technology for updating software in vehicle control devices. OTA technology refers to sending and receiving data using wireless communication. In particular, in the case of wireless communication devices such as smartphones, the term OTA is often used to refer to data communication for updating the device's own operating system (OS) or installed application software.
[0005] It is also necessary to add and update functions to the information processing devices that make up automatic control systems. OTA technology is beginning to be used to add and update software to information processing devices.
[0006] As connections and collaborative processing with various external systems and diagnostic devices become more sophisticated, security risks increase. To address this, information processing devices equipped with intrusion detection devices exist. However, security breaches can occur by evading intrusion detection and launching security attacks on functions connecting to the outside world. Starting from a compromised device or function, attackers can find vulnerable parts in the attack interface across the entire information processing device, and by attacking these weak points, they can cause the information processing device to malfunction.
[0007] To address this issue, a technology has been proposed that takes steps to prevent the spread of an abnormality when an abnormality is detected by an information processing device in an in-vehicle system.The technology determines the location of the abnormality and the extent of the abnormality depending on the abnormality location and the abnormality state, and switches to an available driving mode, allowing the vehicle to continue driving (for example, Patent Document 1). [Prior art documents] [Patent documents]
[0008] [Patent Document 1] Patent No. 6723955 Summary of the Invention [Problem to be solved by the invention]
[0009] According to the technology described in Patent Document 1, in the event of a security attack on a vehicle information processing device, candidate destinations of the abnormal state are calculated according to the location of the abnormality and the abnormal state. In order to eliminate the impact on the driving state according to the calculated candidate destinations, a specific driving mode is selected and a transition is made from the current driving mode. This makes it possible for the vehicle to continue driving.
[0010] However, the technology in Patent Document 1 is not a technology for reducing the risk of security breaches against external attacks, nor is it a technology for narrowing the scope of security breaches and hardening the system, and it does not mention any methods for doing so. This application has been made in light of these problems.
[0011] The present application aims to provide an information processing device and an information processing method that reduce the risk of security breaches due to security attacks and improve defensive capabilities, as well as to narrow the scope of security breaches and improve the robustness of the information processing device and the information processing method.
[0012] The present application aims to provide a configuration device and a configuration method for changing and updating the software configuration of an information processing device while reducing the risk of security breaches due to security attacks and improving defensive capabilities. It also aims to provide a configuration device and a configuration method for changing and updating the software configuration of a robust information processing device while narrowing the scope of security breaches. [Means for solving the problem]
[0013] The information processing device according to the present application comprises: Computer hardware, system software that manages and controls computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each piece of application software is executed, a configuration risk definition table that defines the risk of external infringement for each execution environment, a configuration risk assessment unit that calculates a risk value for each execution environment based on the configuration risk definition table, and a launch setting unit that sets the execution environment of the application software and executes launch processing; and an execution environment separation deployment unit that deploys the execution environment in the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the launch configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit. An information processing device, the execution environment separation setting unit has an execution environment separation definition table that defines the setting of the execution environment for a log function that records the processing content of the information processing device; the execution environment separation arrangement unit arranges, in the computer hardware, a log function execution environment in which the log function is executed based on the separation information defined by the execution environment separation definition table; Executes the log function deployed by the execution environment isolation deployment unit It is something. In addition, the information processing device according to the present application is Computer hardware, system software that manages and controls computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each piece of application software is executed, a configuration risk definition table that defines the risk of external infringement for each execution environment, a configuration risk assessment unit that calculates a risk value for each execution environment based on the configuration risk definition table, and a launch setting unit that sets the execution environment of the application software and executes launch processing; an execution environment separation deployment unit that deploys an execution environment on computer hardware based on a setting of the execution environment defined by an execution environment separation definition table in accordance with an instruction from a launch configuration unit, and executes application software in the execution environment deployed by the execution environment separation deployment unit, The execution environment separation definition table has the name of the execution environment to be set, a space separation setting indicating the space to be set, an execution environment file system setting indicating the file system to be used in the execution environment, a system call permission list indicating the system calls for which permission is sought to be made to the system software in the execution environment, a system function permission list indicating the functions of the system software to be used in the execution environment, a resource allocation setting indicating the resources to be allocated from the resources managed by the system software in the execution environment, and a device access control setting indicating the devices managed by the system software that are accessed in the execution environment. In addition, the information processing device according to the present application is Computer hardware, system software that manages and controls computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each piece of application software is executed, a configuration risk definition table that defines the risk of external infringement for each execution environment, a configuration risk assessment unit that calculates a risk value for each execution environment based on the configuration risk definition table, and a launch setting unit that sets the execution environment of the application software and executes launch processing; an execution environment separation deployment unit that deploys an execution environment on computer hardware based on a setting of the execution environment defined by an execution environment separation definition table in accordance with an instruction from a launch configuration unit, and executes application software in the execution environment deployed by the execution environment separation deployment unit, The configuration risk definition table has a risk identifier that identifies a configuration risk definition, a risk definition that indicates an execution environment and isolation definition that has a configuration risk, and a risk value that indicates the degree of risk for the risk definition. In addition, the information processing device according to the present application is Computer hardware, system software that manages and controls computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each piece of application software is executed, a configuration risk definition table that defines the risk of external infringement for each execution environment, a configuration risk assessment unit that calculates a risk value for each execution environment based on the configuration risk definition table, and a launch setting unit that sets the execution environment of the application software and executes launch processing; an execution environment separation deployment unit that deploys an execution environment on computer hardware based on a setting of the execution environment defined by an execution environment separation definition table in accordance with an instruction from a launch configuration unit, and executes application software in the execution environment deployed by the execution environment separation deployment unit, The computer hardware includes a communication device; the execution environment separation setting unit has an execution environment separation definition table that defines the setting of a system setting control execution environment in which an authentication and secure access unit that performs authentication processing and secure communication processing for receiving system setting control information for setting at least one of the system software and the application software from an external component device via a communication device, and a system setting control processing unit that sets and executes at least one of the system software and the application software based on the received system setting control information, function; The execution environment separation arrangement unit arranges the system setting control execution environment in the computer hardware based on the separation information defined by the execution environment separation definition table. In addition, the information processing device according to the present application is Computer hardware, system software that manages and controls computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each piece of application software is executed, a configuration risk definition table that defines the risk of external infringement for each execution environment, a configuration risk assessment unit that calculates a risk value for each execution environment based on the configuration risk definition table, and a launch setting unit that sets the execution environment of the application software and executes launch processing; an execution environment separation deployment unit that deploys an execution environment on computer hardware based on a setting of the execution environment defined by an execution environment separation definition table in accordance with an instruction from a launch configuration unit, and executes application software in the execution environment deployed by the execution environment separation deployment unit, The computer hardware has a diagnostic port for connecting to an external diagnostic device, the execution environment separation setting unit has an execution environment separation definition table that defines the setting of a diagnostic connection execution environment for performing a diagnostic function of receiving a diagnostic request from a diagnostic device, executing a diagnostic test on the information processing device, and transmitting a result of the diagnostic test to the diagnostic device; The execution environment separation arrangement unit arranges the diagnostic connection execution environment in the computer hardware based on the separation information defined by the execution environment separation definition table.
[0014] The information processing method according to the present application comprises: Computer hardware, system software that manages and controls computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each piece of application software is executed, a configuration risk definition table that defines the risk of external infringement for each execution environment, a configuration risk assessment unit that calculates a risk value for each execution environment based on the configuration risk definition table, and a launch setting unit that sets the execution environment of the application software and executes launch processing; and an execution environment separation deployment unit that deploys the execution environment in the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the launch configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit. In the information processing device, a first step in which a startup setting unit acquires a configuration evaluation indicating whether or not the risk of the information processing device is tolerable from a configuration risk definition table; a second step in which the launch setting unit starts a launch process for each execution environment defined in the execution environment isolation definition table when the evaluation at the time of configuration is acceptable, and ends the processing of the launch setting unit when the evaluation at the time of configuration is unacceptable; a third step in which the launch setting unit waits for a determination as to whether the launch process result of each execution environment is good or bad; and The startup setting unit is provided with a fourth step in which, if the startup processing result of the execution environment is good and there is an execution environment defined in the execution environment separation definition table for which startup processing has not been performed, the startup processing of one of the execution environments is started and then the unit proceeds to a third step, if the startup processing result is good and there is no execution environment for which startup processing has not been performed, the unit terminates the processing, and if the startup processing result is bad, all execution environments for which startup processing has been performed are terminated. In addition, the information processing method according to the present application is Computer hardware, system software that manages and controls computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each piece of application software is executed, a configuration risk definition table that defines the risk of external infringement for each execution environment, a configuration risk assessment unit that calculates a risk value for each execution environment based on the configuration risk definition table, and a launch setting unit that sets the execution environment of the application software and executes launch processing; an execution environment separation deployment unit that deploys an execution environment on computer hardware based on a setting of the execution environment defined by an execution environment separation definition table in accordance with an instruction from a launch configuration unit, and executes application software in the execution environment deployed by the execution environment separation deployment unit, a first step in which a startup setting unit acquires a configuration evaluation indicating whether or not the risk of the information processing device is tolerable from a configuration risk definition table; a second step in which the launch setting unit proceeds to a next step of processing of the launch setting unit of the execution environment defined in the execution environment isolation definition table if the evaluation at the time of configuration is acceptable, and terminates the processing of the launch setting unit if the evaluation at the time of configuration is unacceptable; a third step in which the launch setting unit generates an execution environment launch process that performs a process of launching the execution environment, and if an error occurs during the process of launching the execution environment, the execution environment launch process notifies the execution environment launch process of the error result, terminates the already-launched execution environment, and terminates the process of the launch setting unit; a fourth step in which the execution environment startup process generates an initial process for the startup processing of the execution environment; a fifth step in which the execution environment startup process instructs the execution environment separation placement unit to place the execution environment via the space separation unit of the system software based on the description of the space separation setting specified in the execution environment separation definition table for the initial process; a sixth step in which the execution environment startup process specifies a root file system to be used in the execution environment based on the root file system set in the execution environment file system setting specified in the execution environment isolation definition table; a seventh step in which the execution environment startup process specifies a shared file system path to be used in the execution environment based on the shared file system path described in the execution environment file system setting specified in the execution environment isolation definition table; an eighth step in which the execution environment startup process allocates devices to be used in the execution environment based on the device access control settings specified in the execution environment isolation definition table, and enables only the specified access methods; a ninth step in which the execution environment startup process starts the startup process of the function process of the execution environment from the initial process of the execution environment and performs the initial setting of the function process; a tenth step in which the execution environment startup process waits for completion of initialization of the function processes of the execution environment; an eleventh step in which the execution environment startup process limits the system calls that can be called from the execution environment based on the system call permission list specified in the execution environment isolation definition table via the system call control unit of the system software; a twelfth step in which the execution environment startup process limits the functions of the system software that the execution environment can use based on the system function permission list specified in the execution environment isolation definition table via the system function control unit of the system software; a thirteenth step in which the execution environment startup process limits the computer hardware resources available to the execution environment based on the resource allocation settings specified in the execution environment isolation definition table via the hard resource control unit of the system software; a 14th step in which the execution environment startup process performs a log function setting process if the execution environment is a log function execution environment; a fifteenth step in which the execution environment startup process determines whether the log function execution environment has been started if there is a function that accesses the log in the function process in the execution environment, and if it has not been started, notifies an error result and terminates the started execution environment; and The execution environment activation process includes a sixteenth step in which processing after initial setting of the functional process in the execution environment is started and the functional process is marked as activated.
[0015] The component device according to the present application comprises: an HMI having an input unit and a display unit; Transmission execution environment separation definition table, Sending log function setting definition table, Sending configuration risk definition table; a transmission configuration risk assessment unit; a system setting control instruction description in which processing to be executed by a system setting control processing unit of a system setting control execution environment provided in the information processing device is described; A transmission authentication and secure access unit that performs authentication processing and secure communication processing between the system setting control execution environment provided in the information processing device. a transmission execution environment separation definition table, and a transmission log function setting definition table; a deployment unit that transmits information including a transmission configuration risk definition table and a system configuration control instruction description to a system configuration control execution environment of the information processing device; and is connected to an information processing device.
[0016] The configuration method according to the present application comprises: In the component device, a first step in which the deployment unit causes the transmission configuration risk assessment unit to calculate a risk value based on the transmission configuration risk definition table; A second step in which the deployment unit obtains a configuration assessment of the outgoing configuration risk definition table; a third step in which, if the evaluation at the time of configuration is acceptable, the deployment unit configures a secure interconnection path between the transmission authentication and secure access unit of the configuration device and the authentication and secure access unit of the information processing device; The method includes a fourth step in which the deployment unit transmits data including a transmission execution environment isolation definition table, a transmission log function setting definition table, a transmission configuration risk definition table, and a system setting control instruction description to the information processing device. [Effects of the Invention]
[0017] The information processing device and information processing method according to the present application can reduce the risk of security breaches due to security attacks and improve defensive capabilities. In addition, the scope of security breaches can be narrowed, making the information processing device more robust.
[0018] The configuration device and configuration method according to the present application can change and update the software configuration of an information processing device while reducing the risk of security breaches due to security attacks and improving defense. Also, it can change and update the software configuration of an information processing device while narrowing the scope of security breaches and making the information processing device more robust. [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a block diagram showing a configuration of an information processing device according to a first embodiment. [Figure 2] 1 is a conceptual diagram of the hardware configuration of an information processing device and a component device according to a first embodiment. [Figure 3] 2 is a block diagram showing a configuration of an execution environment separation setting unit of the information processing device according to the first embodiment. FIG. [Figure 4] 2 is a block diagram showing the configuration of a system setting control execution environment and an application execution environment of the information processing device according to the first embodiment. FIG. [Figure 5] 2 is a block diagram showing the configuration of an external connection execution environment and a log function execution environment of the information processing device according to the first embodiment. FIG. [Figure 6]2 is a block diagram showing a configuration of system software of the information processing device according to the first embodiment. FIG. [Figure 7] 1 is a first diagram illustrating an execution environment separation definition table of the information processing device according to the first embodiment. FIG. [Figure 8] FIG. 10 is a second diagram illustrating the execution environment separation definition table of the information processing device according to the first embodiment. [Figure 9] 4 is a diagram showing a log function setting definition table of the information processing device according to the first embodiment; FIG. [Figure 10] FIG. 4 is a diagram showing a configuration risk definition table of the information processing device according to the first embodiment. [Figure 11] 4 is a flowchart of a setting and startup process of a startup setting unit of the information processing device according to the first embodiment. [Figure 12] 4 is a first flowchart of a startup process of a startup setting unit of the information processing device according to the first embodiment. [Figure 13] 10 is a second flowchart of the startup process of the startup setting unit of the information processing device according to the first embodiment. [Figure 14] 10 is a flowchart of a log function setting process of a startup setting unit of the information processing device according to the first embodiment. [Figure 15] 10 is a flowchart of a configuration risk assessment performed by a configuration risk assessment unit of the information processing device according to the first embodiment. [Figure 16] 1 is a block diagram showing a configuration of a component device according to a first embodiment. [Figure 17] 4 is a diagram showing a system setting control instruction description of a component device according to the first embodiment. FIG. [Figure 18] 10 is a flowchart of a configuration process of a deploy unit of the configuration device according to the first embodiment. [Figure 19] FIG. 10 is a block diagram showing a configuration of an information processing device according to a second embodiment. [Figure 20] FIG. 11 is a block diagram showing a configuration of an information processing device according to a third embodiment. [Figure 21] 11 is a first flowchart of a state management process of a state management unit of an information processing device according to the third embodiment. [Figure 22] 11 is a second flowchart of the state management process of the state management unit of the information processing device according to the third embodiment. [Figure 23] FIG. 10 is a block diagram showing a configuration of an information processing device according to a fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0020] Hereinafter, an information processing device, an information processing method, a configuration device, and a configuration method according to embodiments of the present application will be described with reference to the drawings.
[0021] 1. First Embodiment <Configuration of information processing device> 1 is a block diagram showing the configuration of an information processing device 1000 according to Embodiment 1. The information processing device 1000 includes at least an execution environment separation setting unit 1100, an execution environment separation deployment unit 1200, system software 1300, and computer hardware 1400.
[0022] System software is software for the basic control and management of the computer hardware 1400. It is a general term for firmware, OS, middleware, and combinations of these. It exists as the basic structure on which application software that performs specific tasks is executed.
[0023] The execution environment separation setting unit 1100 has setting information related to the separation setting of the execution environment configured on the system software 1300. The execution environment is an environment in which application software is executed. When the application software is actually executed, the software is deployed on the main memory device 1420 of the computer hardware 1400, and the execution environment is deployed so that it can be executed by using hardware resources such as the arithmetic unit 1410, peripheral device 1460, and communication device 1430, and further by using functions provided by the system software 1300.
[0024] FIG. 1 illustrates an external connection execution environment 1500, a log function execution environment 1600, a system setting control execution environment 1700, and an application execution environment 1800 as execution environments. These execution environments are deployed by the execution environment isolation setting unit 1100 via the execution environment isolation deployment unit 1200. The execution environment isolation deployment unit 1200 logically separates the execution environments of application software, deploying them at separate addresses in the main memory device 1420, deploying caches and memories during calculations at separate addresses, and using different arithmetic units 1410 or using the arithmetic units 1410 at separate timings, thereby isolating each execution environment from others. This reduces the risk of security breaches due to external security attacks and improves defensive capabilities. Furthermore, it narrows the scope of security breaches and makes the information processing device more robust.
[0025] A network processing unit 1350 of the system software 1300 transmits and receives communication data to and from external information processing devices 1900, 1910, and component devices 9000 connected to the information processing device 1000, and performs basic communication protocol processing for the transmitted and received communication data. Communication with the external information processing device 1910 can also be realized via the cloud.
[0026] <Computer Hardware> The computer hardware 1400 includes at least an arithmetic unit 1410, a main memory device 1420, a communication device 1430, a non-volatile memory device 1440, a security module device 1450, and a peripheral device 1460. The arithmetic unit 1410 includes at least one arithmetic core that performs arithmetic processing. The arithmetic cores of the arithmetic unit 1410 are assigned and controlled by the system software 1300 to function programs that operate in the execution environments 1500 to 1800 and function programs included in the execution environment separation setting unit 1100.
[0027] The main memory device 1420 stores data for performing arithmetic processing. The main memory device 1420 also supports data for a buffer that functions as an append circular buffer 1360 on the system software 1300. The system software 1300 performs allocation control of the storage area of the main memory device 1420 for function programs that run in each execution environment and for function programs included in the execution environment separation setting unit 1100.
[0028] The communication device 1430 transmits and receives data by communicating with the information processing devices 1900 and 1910 and the component device 9000. The system software 1300 allocates and controls the QoS (Quality of Service) control and communication bandwidth of the communication device 1430 in accordance with the function programs operating in the execution environment and the function programs included in the execution environment separation setting unit 1100.
[0029] The non-volatile storage device 1440 permanently stores the recorded data. The system software 1300 allocates and controls the storage area of the non-volatile storage device 1440 to the function programs that run in the execution environment and the function programs included in the execution environment separation setting unit 1100.
[0030] The security module device 1450 performs at least key management for use in encryption or digital signatures, random number generation, and encryption processing. The security module device 1450 can be the origin of trust in the secure boot of the information processing device 1000. Here, secure boot is a mechanism that verifies whether the OS and application software have been tampered with when the device is started up before starting up.
[0031] By using the security module device 1450 as the origin of trust, the system software 1300, the execution environment isolation setting unit 1100, the execution environment isolation deployment unit 1200, and one or more of the execution environments can be started in a state where safety is ensured. The security module device 1450 is assigned and controlled by the system software 1300 to the function programs that operate within the execution environment and the function programs included in the execution environment isolation setting unit 1100.
[0032] The peripheral device 1460 is a peripheral device included in the computer hardware 1400. The system software 1300 allocates and controls the peripheral device 1460 to the function programs that operate in the execution environment and the function programs included in the execution environment separation setting unit 1100.
[0033] <Hardware configuration concept of information processing devices and component devices> FIG. 2 is a conceptual diagram of a hardware configuration applicable to the information processing devices 1000, 1000A, 1000B, and 1000C and the component device 9000 according to the first embodiment. The information processing device 1000 will be described below as a representative example. Each function of the information processing device 1000 is realized by a processing circuit included in the information processing device 1000. Specifically, as shown in FIG. 2, the information processing device 1000 includes, as processing circuits, an arithmetic device 1410 (computer) such as a CPU (Central Processing Unit), a storage device 91 that exchanges data with the arithmetic device 1410, an input circuit 92 that inputs external signals to the arithmetic device 1410, an output circuit 93 that outputs signals from the arithmetic device 1410 to the outside, and interfaces such as a communication device 1430 that transmits and receives data via a communication path 98. Diagnostic ports may be provided as the input circuit 92 and the output circuit 93.
[0034] The arithmetic device 1410 may include an ASIC (Application Specific Integrated Circuit), an IC (Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), various logic circuits, various signal processing circuits, etc. SoC (System on a Chip) technology may be applied to the arithmetic device 1410. Furthermore, the arithmetic device 1410 may include a plurality of the same or different types of arithmetic devices 1410, each of which may share and execute various processes. The information processing device 1000 may include, as the storage device 91, a RAM (Random Access Memory) configured to be able to read and write data from the arithmetic device 1410, a ROM (Read Only Memory) configured to be able to read data from the arithmetic device 1410, a disk device as a large-capacity storage device, etc. The storage device 91 may be built into the arithmetic device 1410. In FIG. 1, the storage device 91 is configured as a main storage device 1420, a non-volatile storage device 1440, or the like, depending on the application.
[0035] The input circuit 92 is connected to input signals, sensors, and switches, and includes an A / D converter and the like that inputs the signals of these input signals, sensors, and switches to the arithmetic unit 1410. The output circuit 93 is connected to electrical loads such as gate drive circuits that drive switching elements on and off, and includes drive circuits that output control signals from the arithmetic unit 1410 to these electrical loads. The communication unit 1430 can exchange data with external devices such as external control devices via a communication path 98.
[0036] Each function of the information processing device 1000 is realized by the arithmetic device 1410 executing software (programs) stored in a storage device 91 such as a RAM, a ROM, or a disk device, and cooperating with other hardware of the information processing device 1000 such as the storage device 91, an input circuit 92, and an output circuit 93. Setting data such as thresholds and judgment values used by the information processing device 1000 is stored as part of the software (programs) in the storage device 91 such as a RAM, a ROM, or a disk device. Each function of the information processing device 1000 may be configured by a software module, or may be configured by a combination of software and hardware.
[0037] <Execution environment isolation setting section> 3 is a block diagram showing the configuration of the execution environment separation setting unit 1100 of the information processing device 1000 according to embodiment 1. The execution environment separation setting unit 1100 has setting information related to the separation setting of the execution environment configured on the system software 1300, and performs startup setting of the execution environment. The execution environment separation deployment unit 1200 performs separation deployment of the execution environment based on the information of the execution environment separation setting unit 1100 in response to an instruction from the execution environment separation setting unit 1100. Examples of the execution environments shown include an external connection execution environment 1500, a log function execution environment 1600, a system setting control execution environment 1700, and an application execution environment 1800.
[0038] The execution environment isolation setting unit 1100 includes a startup setting unit 1110, a configuration risk assessment unit 1120, an execution environment isolation definition table 1130, a log function setting definition table 1140, and a configuration risk definition table 1150. The startup setting unit 1110 starts and sets up the execution environment via the execution environment isolation deployment unit 1200 based on the setting description in the execution environment isolation definition table 1130.
[0039] The configuration risk assessment unit 1120 assesses the risk of the system configuration of the information processing device 1000 based on the configuration risk definition table 1150. The execution environment isolation definition table 1130 describes the isolation definition of the execution environment. The log function setting definition table 1140 describes the setting definition of the log function for each log function that operates in the log function execution environment 1600 that constitutes the execution environment. The configuration risk definition table 1150 describes the security risk in the setting description of the execution environment isolation definition table 1130.
[0040] <System setting control execution environment, application execution environment> 4 is a block diagram showing the configuration of a system setting control execution environment 1700 and an application execution environment 1800 of the information processing device 1000 according to embodiment 1. The information processing device 1000 includes the system setting control execution environment 1700 configured as an execution environment. The system setting control execution environment 1700 includes an authentication and secure access unit 1710 and a system setting control processing unit 1720.
[0041] The authentication and secure access unit 1710 represents a function required for implementing authentication and guaranteed access when transmitting and receiving data between the information processing device 1000 and the external information processing devices 1900, 1910 and the component device 9000. In particular, when the information processing device 1000 receives an instruction from the external component device 9000 to change or update the software it runs, authentication and guaranteed access become important.
[0042] The system setting control execution environment 1700 receives a system setting control instruction description from the component device 9000 and executes the instruction description, thereby changing and updating the software executed by the information processing device 1000. Note that the information processing device 1900 may also be used as a component device.
[0043] The application execution environment 1800 indicates an execution environment for each application software 1810 for processing tasks executed on the system software 1300. The application software 1810 to be executed can be selected from a plurality of application software and executed.
[0044] <External connection execution environment, logging function execution environment> 5 is a block diagram showing the configuration of an external connection execution environment 1500 and a log function execution environment 1600 of the information processing device 1000 according to embodiment 1. The information processing device 1000 has the external connection execution environment 1500 configured as an execution environment for connecting to external information processing devices 1900 and 1910 and a component device 9000 via a communication device 1430. The external connection execution environment 1500 includes a firewall 1510, a proxy 1520, an intrusion detection function 1530, and an intrusion prevention function 1540 as communication data processing functions.
[0045] The information processing apparatus 1000 has a log function execution environment 1600. The log function execution environment 1600 has an audit log function 1610 and an application log function 1620.
[0046] Within the external connection execution environment 1500, each time a Firewall 1510, a Proxy 1520, or an intrusion detection function 1530 performs processing, a log is appended to the append circular buffer 1360. The contents recorded in the append circular buffer 1360 are then read by the audit log function 1610 of the log function execution environment 1600 and recorded and saved in the non-volatile storage device 1440.
[0047] Furthermore, when application software 1810 is changed, updated, started, or executed in the application execution environment 1800, a log is additionally written to the additional circular buffer 1360. The contents recorded in the additional circular buffer 1360 are then read by the application log function 1620 of the log function execution environment 1600 and recorded and saved in the non-volatile storage device 1440.
[0048] In this way, by appending logs to the append circular buffer 1360 in the external connection execution environment 1500 and the application execution environment 1800, the logs are reliably recorded without being erased. Then, the log function execution environment 1600 transfers the records in the append circular buffer 1360 to the non-volatile storage device 1440. This ensures stable storage of the records. This also makes it possible to preserve records of external attacks on the information processing device, which can be used to understand and respond to the current status and to predict future events. This can therefore contribute to reducing the risk of security breaches due to security attacks and improving defensiveness.
[0049] <System Software> 6 is a block diagram showing the configuration of system software 1300 of information processing device 1000 according to embodiment 1. System software 1300 includes at least a spatial separation unit 1310, a system call control unit 1320, a system function control unit 1330, a hardware resource control unit 1340, a network processing unit 1350, and an append circular buffer 1360.
[0050] The spatial separation unit 1310 controls spatial separation of the execution environment, which includes at least a process ID space, a user / group ID space, a mount point space, an inter-process communication space, a host / domain name space, and a network space.
[0051] The system call control unit 1320 controls permission of system calls at least for function programs that operate within the execution environment. The system function control unit 1330 controls permission of system functions at least for function programs that operate within the execution environment.
[0052] The hardware resource control unit 1340 controls allocation of hardware resources of the computer hardware 1400 and access to hardware devices for at least the function programs that run in the execution environment. By combining these functions of the system software 1300, it becomes possible to support the configuration of any number of separate execution environments.
[0053] The network processing unit 1350 transmits and receives communication data to and from the information processing devices 1900 and 1910 and the component device 9000 connected to the information processing device 1000, and performs basic communication protocol processing for the transmitted and received communication data. The append circular buffer 1360 is a memory recording mechanism that enables appending and reading of log data. Data cannot be modified or deleted after it has been written.
[0054] <Execution environment isolation definition table> Fig. 7 is a first diagram showing the execution environment separation definition table 1130 of the information processing apparatus 1000 according to embodiment 1. Fig. 8 is a second diagram showing the execution environment separation definition table 1130. Figs. 7 and 8 show the entire execution environment separation definition table 1130.
[0055] 7, the execution environment separation definition table 1130 is shown to have an identifier 2000, an execution environment name 2001, a space separation setting 2002, an execution environment file system setting 2003, and a system call permission list 2004. In Fig. 8, the execution environment separation definition table 1130 is shown to have a system function permission list 2005, a resource allocation setting 2006, a device access control setting 2007, and a boot start order 2008.
[0056] The column of identifier 2000 lists identifiers indicating execution environments 1500 to 1800. The column of execution environment name 2001 lists the names of execution environments 1500 to 1800. The column of space separation setting 2002 lists the space for which separation setting is to be performed among the spaces provided by system software 1300 for each execution environment 1500 to 1800. The space separation includes at least a process ID space, a user / group ID space, a mount point space, an inter-process communication space, a host / domain name space, and a network space.
[0057] The column for execution environment file system settings 2003 lists the root file systems to be assigned to the execution environments 1500 to 1800, and the paths of the file systems to be shared with the system software 1300 for the execution environments 1500 to 1800. The column for system call permission list 2004 lists the system calls that are permitted to be issued to the system software 1300 for the function programs running in the execution environments 1500 to 1800. Note that permitted arguments may also be specified for each system call listed (not shown). Regular expressions may be used to specify the arguments.
[0058] The column for system function permission list 2005 lists functions that are permitted to be used among the functions provided by system software 1300 for function programs running in execution environments 1500 to 1800. The column for resource allocation settings 2006 lists control settings for resources managed by system software 1300 for execution environments 1500 to 1800.
[0059] For example, description will be given of the resource allocation setting 2006 of the external connection execution environment 1500 in which the column of the identifier 2000 in Fig. 8 is C0. The resource allocation setting 2006 describes a computation core time allocation (Fig. 8 illustrates a setting that guarantees a computation core a maximum allocation of quota_C0 [us] per period_C0 [us]) for the computation core of the computing device 1410. Also, examples are given of a maximum utilization allocation for the computation core (Fig. 8 illustrates a setting that guarantees a maximum allocation of usage_C0 [%] for the computation core) and a computation core allocation (Fig. 8 illustrates a setting that allocates computation core 2 and computation core 3).
[0060] A maximum memory allocation (FIG. 8 illustrates a setting that guarantees a maximum memory allocation of limit_mem_C0 [Bytes]) is shown for the main memory 1420. A maximum communication bandwidth allocation (FIG. 8 illustrates a setting that guarantees a maximum communication bandwidth of limit_bw_C0 [Bytes / s]) is shown for the communication device 1430.
[0061] Furthermore, for the non-volatile storage device 1440, a block IO maximum bandwidth allocation (FIG. 8 illustrates a setting that guarantees allocation of the maximum block IO bandwidth of limit_block_C0 [Bytes / s]) is illustrated. As a resource allocation setting for the system software 1300, a maximum number of processes that can run in the execution environments 1500 to 1800 (FIG. 8 illustrates a setting of a maximum number of PIDS_C0 processes) is illustrated. Note that the resource allocation setting 2006 is not limited to these examples, and other resource control settings managed by the system software 1300 may also be described.
[0062] Device access control settings 2007 describe access control settings for devices managed by system software 1300 for runtime environments 1500 to 1800. For example, in Fig. 8, device access control settings 2007 for external connection runtime environment 1500 describes, for example, read access permission for non-volatile storage device 1440 (denoted as {non-volatile storage device, Read} in Fig. 8) and send / receive permission for communication device 1430 (denoted as {communication device, SendRecv} in Fig. 8).
[0063] The description of the device access control setting 2007 of the log function execution environment 1600, in which the identifier 2000 column in Fig. 8 is C2, will be explained. The read / write access permission of the non-volatile storage device 1440 (denoted as {non-volatile storage device, ReadWrite} in Fig. 8) is exemplified.
[0064] The description of the device access control setting 2007 of the system setting control execution environment 1700, which has C3 in the identifier 2000 column in Fig. 8, is now explained. The read / write access permission of the non-volatile memory device 1440 (denoted as {non-volatile memory device, ReadWrite} in Fig. 8) is described. The send / receive permission and control permission of the communication device 1430 (denoted as {communication device, SendRecvCtrl} in Fig. 8) and the all access permission of the security module device 1450 (denoted as {security module device, All} in Fig. 8) are described.
[0065] A FIFO file shared with system software 1300 exists, and read / write access permissions (indicated as {FIFO_C3, ReadWrite} in Figure 8), and a Socket file shared with system software 1300 exists, and read / write access permissions (indicated as {Socket_C3, ReadWrite} in Figure 8) are exemplified.
[0066] The FIFO file and Socket file shown as examples are not devices linked to the computer hardware 1400, but are pseudo-devices managed by the system software 1300 and are used when sending and receiving data between function programs. Note that the device access control settings 2007 are not limited to these examples, and may describe access control settings to devices managed by the system software 1300.
[0067] The activation start order 2008 describes the activation start order of the execution environments 1500 to 1800. This order may be set taking into consideration the dependency of functional processing between the execution environments 1500 to 1800.
[0068] <Log function setting definition table> 9 is a diagram showing the log function setting definition table 1140 of the information processing device 1000 according to Embodiment 1. The log function setting definition table 1140 includes a log function name 3000, a log buffer setting 3001, a log buffer access function 3002, and a log file setting 3003.
[0069] In the column of log function name 3000, the log function name indicating the log function operating in the log function execution environment 1600 is written together with the identifier 2000 of the log function execution environment 1600. The log buffer setting 3001 is assigned to the log function for each log function name 3000. The append circular buffer 1360 and the size value of the append circular buffer 1360 are written.
[0070] The column for log buffer access function 3002 lists the execution environments (1500, 1700 to 1800) that access the append circular buffer 1360 and the functions that operate in the execution environments (1500, 1700 to 1800) that access the append circular buffer 1360. The column for log file setting 3003 lists the log file in which the log function operating in the log function execution environment 1600 records and stores the contents of the append circular buffer 1360. The log file may be stored in non-volatile storage device 1440.
[0071] <Configuration risk definition table> 10 is a diagram showing the configuration risk definition table 1150 of the information processing device 1000 according to Embodiment 1. The configuration risk definition table 1150 includes a risk identifier 4000, a risk definition 4001, a risk value 4002, and a configuration evaluation 4003.
[0072] The column of risk identifier 4000 lists identifiers that identify the risk definitions of security risks in the setting descriptions of the execution environment isolation definition table 1130. The column of risk definition 4001 lists execution environments 1500 to 1800 that have security risks and isolation settings for the execution environments 1500 to 1800.
[0073] Furthermore, the column of risk definition 4001 includes at least a logical evaluation formula based on risk identifier 4000 and an evaluation formula based on the sum of risk values 4002. In Fig. 10, when risk identifier 4000 is R0, risk definition 4001 shows, as an example, that the external connection execution environment 1500 is used as the execution environment, and that the device access control setting 2007 has a setting that allows read and write access to non-volatile memory device 1440 as the separation definition.
[0074] An example of a logical evaluation formula is a risk definition 4001 with a risk identifier 4000 of Rm, and an example of a risk evaluation formula is a logical product of risk identifiers R0 and R2. An example of an evaluation formula based on the sum of risk values 4002 is a risk definition 4001 with a risk identifier 4000 of Rn.
[0075] The risk value 4002 describes a risk value indicating the degree of risk for the risk definition 4001. Furthermore, it includes at least a risk value indicating an unacceptable risk definition (illustrated as "Unacceptable" in FIG. 10).
[0076] The configuration time evaluation 4003 indicates a risk evaluation for the configuration of the information processing device 1000 as a whole. The configuration time evaluation 4003 describes information on the configuration time evaluation by the configuration risk evaluation unit 1120. The information on the configuration time evaluation 4003 includes at least information on whether the evaluation is acceptable or unacceptable. For example, FIG. 10 illustrates an example of an acceptable evaluation at the configuration time evaluation and a total risk value calculated by the configuration risk evaluation unit 1120 when the evaluation is acceptable. Also illustrated is an example of an unacceptable evaluation at the configuration time evaluation and a risk identifier 4000 for a risk definition 4001 that the configuration risk evaluation unit 1120 determines to be unacceptable when the evaluation is unacceptable.
[0077] <Startup settings and startup process> 11 is a flowchart showing a setting and startup process executed by the startup setting unit 1110 of the execution environment separation setting unit 1100 in the information processing device 1000 according to Embodiment 1. The process shown in FIG. 11 may be executed every time software is changed or updated in the information processing device 1000, or every time software is started up.
[0078] In step S5000, the startup setting unit 1110 starts the setting and startup process. In step S5001, the startup setting unit 1110 acquires the configuration time evaluation 4003 from the configuration risk definition table 1150.
[0079] In step S5002, the startup setting unit 1110 determines whether the evaluation of the configuration time evaluation 4003 is acceptable. If the evaluation of the configuration time evaluation 4003 is acceptable (determination is YES), the process proceeds to step S5003. If the evaluation of the execution environment configuration time evaluation 4003 is inappropriate (determination is NO), the process proceeds to step S5008, and the process ends.
[0080] In step S 5003 , the startup setting unit 1110 repeats the processing from step S 5003 to step S 5006 for each execution environment name 2001 in accordance with the startup start order 2008 in the execution environment separation definition table 1130 .
[0081] In step S5004, startup setting unit 1110 generates a runtime environment startup process that starts runtime environments 1500 to 1800, and causes the generated runtime environment startup process to execute the startup process. Details of the runtime environment startup process in step S5004 are shown in Figures 12 and 13. The processes in Figures 12 and 13 may be subroutines called from step S5004.
[0082] In step S5005, the startup setting unit 1110 receives a result notification of the execution environment startup processing by the execution environment startup process and determines whether the processing was successful, i.e., whether the startup processing result is good or bad, based on the presence or absence of errors. If there are no errors and the processing is successful (determination is NO), the process proceeds to step S5006. If there are errors and the processing is unsuccessful (determination is YES), the process proceeds to step S5007.
[0083] In step S5006, the startup setting unit 1110 determines whether or not the execution environment name 2001 in the execution environment separation definition table 1130 has been completed. If it has been completed, the process proceeds to step S5008. If it has not been completed, the process returns to step S5003.
[0084] In step S5007, the startup setting unit 1110 terminates all of the already-started execution environments 1500 to 1800. Then, the process proceeds to step S5008. In step S5008, the startup setting unit 1110 terminates the setting and startup process.
[0085] <Startup process of startup setting section> Fig. 12 is a first flowchart of the startup processing of startup setting unit 1110 of information processing device 1000 according to embodiment 1. Fig. 13 is a second flowchart of the startup processing. Fig. 13 shows a continuation of the flowchart of Fig. 12. The processing started in Fig. 12 shows details of the runtime environment startup processing of step S5004 in Fig. 11.
[0086] In step S6000, the startup process is started by the execution environment startup process generated by the startup setting unit 1110. The execution of processing by the execution environment startup process can be considered to be essentially the execution of processing by the startup setting unit 1110. In step S6001, when an error occurs during the startup processing, the execution environment startup process returns an error result notification to the startup setting unit 1110, which is the caller, and in step S6016 performs settings to end the startup processing.
[0087] In step S6002, the execution environment startup process generates an initial process within execution environments 1500 to 1800. In step S6003, the execution environment startup process performs space separation setting specified in space separation setting 2002 of execution environment separation definition table 1130 on the initial process in space separation unit 1310 of system software 1300 via execution environment separation placement unit 1200.
[0088] In step S6004, the execution environment startup process switches the root file system of the execution environments 1500 to 1800 to the root file system specified in the execution environment file system setting 2003. In step S6005, the execution environment startup process sets the path specified by the shared file system path in the execution environment file system setting 2003 to be shared between the system software 1300 and the execution environments 1500 to 1800.
[0089] In step S6006, the execution environment startup process assigns the devices specified in device access control setting 2007 to execution environments 1500 to 1800, and enables only the access methods specified as permitted. In step S6007, the execution environment startup process starts functional processes to be executed in execution environments 1500 to 1800 from the initial processes in execution environments 1500 to 1800. As a result, the functional processes are also executed in a spatially separated manner.
[0090] In step S6008, the runtime environment startup process waits for the completion of the initial setting process of the functional processes executed within the runtime environments 1500 to 1800. Next, the process proceeds to step S6009 in FIG.
[0091] 13, the execution environment startup process limits the system calls that can be called for the execution environments 1500 to 1800. The execution environment startup process sets the system call control unit 1320 of the system software 1300 to prohibit calls to system calls other than those specified in the system call permission list 2004. If permitted arguments are specified for each system call, the execution environment startup process prohibits calls to be made with arguments other than those specified. Regular expressions may be used to specify the arguments.
[0092] In step S6010, the execution environment startup process limits the system functions that can be used for execution environments 1500 to 1800. The execution environment startup process sets system function control unit 1330 of system software 1300 to prohibit use of system functions other than those specified in system function permission list 2005.
[0093] In step S6011, the execution environment startup process limits the resources available to execution environments 1500 to 1800. The execution environment startup process sets the resources specified in resource allocation setting 2006 in hard resource control unit 1340 of system software 1300.
[0094] In step S6012, the execution environment startup process performs log function setting processing if the execution environment is the log function execution environment 1600. Details of the log function setting processing in step S6012 are shown in Fig. 14. The processing in Fig. 14 may be a subroutine called from step S6012.
[0095] In step S6013, if the execution environment (1500, 1700, or 1800) has the function to access the append circular buffer 1360, the execution environment startup process proceeds to step S6014. If not, the process proceeds to step S6015.
[0096] In step S6014, the execution environment startup process determines an error if the log function execution environment 1600 has not been started. In step S6015, the execution environment startup process starts post-initialization processing for the function processes in the execution environments 1500 to 1800. When starting processing, the corresponding execution environment processes are determined to have been started.
[0097] In step S6016, the execution environment startup process ends the startup processing.
[0098] <Log function setting process> 14 is a flowchart of the log function setting by the activation setting unit 1110 of the information processing device 1000 according to the first embodiment. The process started in FIG. 14 shows details of the log function setting process in step S6012 in FIG. 13.
[0099] In step S7000, the activation setting unit 1110 starts the process of setting the log function. In step S7001, the activation setting unit 1110 repeats steps S7001 to S7007 for each log function indicated by the log function name 3000 in the log function setting definition table 1140 in the log function setting process.
[0100] In step S7002, in the log function setting process, the startup setting unit 1110 creates an append circular buffer 1360 of the size specified in the log buffer setting 3001. In step S7003, in the log function setting process, the startup setting unit 1110 sets up a write interface to the append circular buffer 1360 for the execution environments 1500 to 1800 specified in the log buffer access function 3002.
[0101] In step S7004, in the log function setting process, the startup setting unit 1110 sets write permission to the append circular buffer 1360 for the function specified in the log buffer access function 3002. In step S7005, in the log function setting process, the startup setting unit 1110 creates the log file specified in the log file setting 3003 as the log file to be recorded and saved by the log function name 3000.
[0102] In step S7006, the startup setting unit 1110 puts the log function indicated by the log function name 3000 into a standby state until log data arrives in the append circular buffer 1360. In the log function setting process, the log function indicated by the log function name 3000 performs a process of reading log data and a process of recording and saving the log data in a log file. For this purpose, the log function indicated by the log function name 3000 waits until log data arrives in the append circular buffer 1360.
[0103] In step S7007, the activation setting unit 1110 determines whether or not the log function indicated by the log function name 3000 in the log function setting definition table 1140 has been completed in the log function setting process. If the log function has been completed, the process proceeds to step S7008. If the log function has not been completed, the process returns to step S7001. In step S7008, the activation setting unit 1110 completes the setting process in the log function setting process.
[0104] <Configuration Risk Assessment> 15 is a flowchart of the configuration risk assessment performed by the configuration risk assessment unit of the information processing device according to Embodiment 1. In step S8000, configuration risk assessment unit 1120 starts the assessment process.
[0105] In step S8001, the configuration risk assessment unit 1120 repeats steps S8001 to S8007 for each risk identifier 4000 in the configuration risk definition table 1150. In step S8002, the configuration risk assessment unit 1120 searches whether the execution environment isolation definition table 1130 contains content that matches the execution environments 1500 to 1800 and separation definition specified in the risk definition 4001, or whether the risk definition 4001 contains a description of a risk assessment formula or a risk value total.
[0106] In step S8003, if the configuration risk assessment unit 1120 finds that matching content exists (determination is YES), the process proceeds to step S8004. If matching content does not exist (determination is NO), the process proceeds to step S8007.
[0107] In step S8004, the configuration risk assessment unit 1120 acquires the risk value 4002 specified by the risk value 4002 of the risk identifier 4000. In step S8005, the configuration risk assessment unit 1120 determines whether the risk value 4002 is acceptable. If the risk value 4002 is acceptable (determination is YES), the process proceeds to step S8006. Specifically, if the risk value 4002 is less than a predetermined unacceptable value, it is determined to be acceptable. If the risk value 4002 is unacceptable (determination is NO), the process proceeds to step S8009. Specifically, if the risk value 4002 is equal to or greater than a predetermined unacceptable value, it is determined to be unacceptable.
[0108] In step S8006, the configuration risk assessment unit 1120 adds the risk value to the total risk value. However, if the identifier from which the risk value was obtained is the last risk identifier specified in the configuration risk definition table, the risk value is not added. The total risk value is specified in the last Rn column of the risk identifier 4000, and whether it is acceptable or not is determined based on whether it is less than Rv_rate. Rv_rate may be the same as the unacceptable value described above.
[0109] In step S8007, the configuration risk assessment unit 1120 determines whether or not the risk identifier 4000 in the configuration risk definition table 1150 has been completed. If it has been completed, the process proceeds to step S8008. If it has not been completed, the process returns to step S8001 and the process is repeated.
[0110] In step S8008, the evaluation at configuration time 4003 is recorded as acceptable. Furthermore, the total value of the risk value may be recorded in configuration time evaluation 4003.
[0111] In step S8009, the configuration risk assessment unit 1120 records the assessment of the configuration assessment 4003 as unacceptable. Furthermore, the risk identifier 4000 may be recorded as Unacceptable in the configuration assessment 4003.
[0112] In step S8010, the configuration risk assessment unit 1120 ends the assessment process. As illustrated in Fig. 1, the processing flows of Fig. 11 to Fig. 15 can be processed in a state where safety is ensured, with the security module device 1450 as the starting point of trust in the secure boot of the information processing device 1000.
[0113] <Component device> 16 is a block diagram showing the configuration of a component device 9000 according to the first embodiment. The component device 9000 includes at least a user HMI unit 9001, a deployment unit 9002, a transmission configuration risk assessment unit 9003, a transmission authentication and secure access unit 9004, a transmission execution environment isolation definition table 9005, a transmission log function setting definition table 9006, a transmission configuration risk definition table 9007, and a system setting control instruction description 9008. Deploying refers to distributing and deploying software in an actual operating environment for practical use. The deployment unit 9002 of the component device 9000 causes the information processing device 1000 to change and update the software configuration.
[0114] The user HMI unit 9001 includes a user input unit and a display unit (not shown). The deployment unit 9002 has a function of transmitting information including a transmission execution environment separation definition table 9005, a transmission log function setting definition table 9006, a transmission configuration risk definition table 9007, and a system setting control instruction description 9008 to the system setting control execution environment 1700 provided in the information processing device 1000.
[0115] The transmission configuration risk assessment unit 9003 is similar to the configuration risk assessment unit 1120 provided in the information processing device 1000 , except that it is executed by the configuration device 9000 in response to a user instruction via the user HMI unit 9001 .
[0116] The transmission authentication and secure access unit 9004 performs authentication and secure communication with the system setting control execution environment 1700 provided in the information processing device 1000. The transmission execution environment isolation definition table 9005 is similar to the configuration risk assessment unit 1120 provided in the information processing device 1000. The user may create and change the transmission execution environment isolation definition table 9005 via the user HMI unit 9001.
[0117] The transmission log function setting definition table 9006 is the same as the log function setting definition table 1140 provided in the information processing apparatus 1000. The user may create and change the transmission log function setting definition table 9006 via the user HMI unit 9001.
[0118] The transmission configuration risk definition table 9007 has the same configuration as the configuration risk definition table 1150 provided in the information processing device 1000. A user may create or modify the transmission configuration risk definition table 9007 via the user HMI unit 9001. The system setting control instruction description 9008 describes the processing to be executed by the system setting control processing unit 1720 of the system setting control execution environment 1700 provided in the information processing device 1000.
[0119] <System setting control instruction description> 17 is a diagram showing a system setting control instruction description 9008 of the configuration device 9000 according to the first embodiment. In the system setting control instruction description 9008, each line describes a process to be executed by the system setting control processing unit 1720 of the system setting control execution environment 1700 provided in the information processing device 1000. The system setting control instruction description 9008 may be a process description written in a general script language including conditional branches, loops, functions, etc., and the system setting control processing unit 1720 only needs to be able to execute the processing system of the script language.
[0120] The component device 9000 can cause the information processing device 1000 to change or update the software configuration while reducing the risk of security breaches due to security attacks and improving defense. Regarding communication between the component device 9000 and the information processing device 1000, the authentication and secure access unit 1710 can ensure a highly reliable communication path that is resistant to attacks. With the security module device 1450 as the starting point of trust, processing can be performed in a state where safety is ensured. Furthermore, by having the transmission configuration risk assessment unit 9003 perform a risk assessment in advance of the software to be changed or updated, risks can be avoided.
[0121] <Configuration processing> 18 is a flowchart of the configuration process of the deployment unit of the component device 9000 according to the first embodiment. Instructions for software change, update, startup, etc. are transmitted to the component device 9000 via the user HMI unit 9001. In response to these instructions, the deployment unit 9002 causes the information processing device 1000 to change and update the software configuration while reducing the risk of security breaches due to security attacks and improving defense.
[0122] In step S11000, the deployment unit 9002 starts the deployment process. In step S11001, the deployment unit executes risk assessment using the transmission configuration risk assessment unit 9003 provided in the component device 9000. Note that the execution of the transmission configuration risk assessment unit 9003 is similar to the processing of the configuration risk assessment unit 1120 provided in the information processing device 1000 shown in FIG. 15, except that it is executed by the component device 9000.
[0123] In step S11002, the deployment unit acquires the configuration evaluation 4003 of the transmission configuration risk definition table 9007 provided in the configuration device 9000. In step S11003, if the evaluation of the configuration evaluation 4003 is acceptable (determination is YES), the process proceeds to step S11004. If it is inappropriate (determination is NO), the process proceeds to step S11006.
[0124] In step S11004, the deployment unit configures a secure interconnection path between the transmission authentication and secure access units 9004, 1710 of both the component device 9000 and the information processing device 1000. In step S11005, the deployment unit transmits to the information processing device 1000 data including a transmission execution environment separation definition table 9005 provided in the component device 9000, a transmission log function setting definition table 9006 provided in the component device 9000, a transmission configuration risk definition table 9007 provided in the component device 9000, and a system setting control instruction description 9008 provided in the component device 9000.
[0125] In step S11006, the deploy unit ends the deploy process. Note that the process flow illustrated in Fig. 18 is executed in a state where safety is ensured in the secure boot of the component device 9000.
[0126] 2. Second Embodiment <Diagnostic equipment> Fig. 19 is a block diagram showing the configuration of an information processing device 1000A according to embodiment 2. The difference from information processing device 1000 of Fig. 1 according to embodiment 1 is that a diagnostic connection execution environment 12000, a diagnostic function 12010 in diagnostic connection execution environment 12000, and a diagnostic port 1470 in computer hardware 1400A are added as execution environments, and that external diagnostic devices A 1920 and B 1930 are connected to information processing device 1000A.
[0127] The information processing device 1000A has a diagnostic connection execution environment 12000 that connects to an external diagnostic device B 1930 via a diagnostic port 1470 that the computer hardware 1400A has. Furthermore, the information processing device 1000A has an external connection execution environment 1500 that connects to an external diagnostic device A 1920 via a communication device 1430 that the computer hardware 1400A has.
[0128] The diagnostic connection execution environment 12000 includes at least a diagnostic function 12010 that acquires diagnostic information about the information processing device 1000A, performs diagnostic testing on the information processing device 1000A, and performs diagnostic control on the information processing device 1000A. The external connection execution environment 1500 also includes a Proxy 1520 that transmits communication data of a diagnostic device A 1920 connected via a communication device 1430 to the diagnostic function 12010.
[0129] By adopting such a connection method, diagnosis can be performed from diagnostic device A1920 and diagnostic device B1930 to information processing device 1000A while reducing the risk of security breaches due to security attacks and improving defensiveness. Furthermore, for communication between diagnostic device A1920, diagnostic device B1930 and diagnostic function 12010, a highly reliable communication path that is resistant to attacks may be ensured by the authentication and secure access units that diagnostic device A1920, diagnostic device B1930 and diagnostic function 12010 have.
[0130] 3. Embodiment 3 <Status Management Unit> Fig. 20 is a block diagram showing the configuration of an information processing device 1000B according to embodiment 3. The difference from the information processing device 1000 of Fig. 1 according to embodiment 1 is that an execution environment separation setting unit 1100B is provided with a state management unit 13010 that manages the system state within the information processing device 1000B, and that the information processing device 1000B has an execution environment separation definition table 13030 that can be selected for each state managed by the state management unit 13010, a selectable log function setting definition table 13040, and a selectable configuration risk definition table 13050. The items in each table are the same as the items in each table shown in Figs. 7 to 10.
[0131] <Status management process> Fig. 21 is a first flowchart of the state management process of the state management unit 13010 of the information processing device 1000B according to Embodiment 3. Fig. 22 is a second flowchart of the state management process. Fig. 22 shows a continuation of the flowchart in Fig. 21.
[0132] The state management unit 13010 may start processing in response to a system state transition within the information processing device 1000B. By switching the application software to be executed and the execution environment to be executed depending on the operating state of the information processing device 1000B, changes in the surrounding environment, and external attacks and intrusion situations, it becomes possible to perform optimal operation.
[0133] In step S14000, the state management unit 13010 starts processing. In step S14001, the state management unit 13010 determines whether or not a second configuration risk definition table 13050A corresponding to the state transition destination exists. If a second configuration risk definition table 13050A suitable for the state after the transition exists (determination is YES), the process proceeds to step S14002. If no such table exists (determination is NO), the process proceeds to step S14011. (Step S14011 is shown in FIG. 22.)
[0134] In step S14002, the state management unit 13010 compares the execution environment separation definition table 13030 corresponding to the source of the state transition with the second execution environment separation definition table 13030A corresponding to the destination of the state transition. For each execution environment name 2001 in each table, the execution environments that have differences in the setting items 2002 to 2007 are extracted.
[0135] In step S14003, the state management unit 13010 performs termination processing for the extracted execution environment. Then, the process proceeds to step S14004. (Step S14004 is shown in FIG. 22.)
[0136] 22, the state management unit 13010 compares the log function setting definition table 13040 corresponding to the state transition source with the second log function setting definition table 13040A corresponding to the state transition destination. For each log function name 3000 in each table, the log function names 3000 that have differences in setting items 3001 to 3003 are extracted.
[0137] In step S14005, the state management unit 13010 performs termination processing for the extracted log function name 3000. In step S14006, the state management unit 13010 discards the access permission set for the function specified by the log buffer access function 3002 of the extracted log function name 3000.
[0138] In step S14007, the state management unit 13010 discards the interface to the append circular buffer installed in the execution environment specified by the log buffer access function 3002 of the extracted log function name 3000. In step S14008, the state management unit 13010 performs termination processing for the append circular buffer specified by the log buffer setting 3001 of the extracted log function name 3000.
[0139] In step S14009, the state management unit 13010 executes configuration and startup by the startup configuration unit 1110 for each of the extracted execution environments. In the configuration and startup process of Fig. 11 according to embodiment 1, the process of repeating the process for each execution environment shown in step S5003 from step S5003 is executed according to the startup start order. In step S14009 of Fig. 22, the same process as the configuration and startup process of Fig. 11 may be executed as a process of repeating configuration and startup according to the startup start order only for the extracted execution environments with differences.
[0140] In step S14010, the state management unit 13010 executes log function setting for each extracted log function. In the log function setting in FIG. 14 according to embodiment 1, the process shown in steps S7001 to S7007 is repeated for each log function. In step S14010 in FIG. 22, the same process as the log function setting in FIG. 14 may be executed as a process repeated for each extracted log function. In step S14011, the state management unit 13010 ends the process.
[0141] The information processing device 1000B according to the third embodiment can reduce the risk of security breaches due to security attacks and improve defensive capabilities, while switching the application software to be executed and the execution environment to be executed in accordance with the operating state of the information processing device 1000B, changes in the surrounding environment, and external attacks and breach situations, thereby enabling optimal operation.By narrowing the scope of security breaches and making the information processing device more robust, it is possible to switch the application software to be executed and the execution environment to be executed, thereby enabling optimal operation.
[0142] 4. Embodiment 4 <Information processing device using virtual machines> Fig. 23 is a block diagram showing the configuration of an information processing device 1000C according to embodiment 4. The difference from the information processing device 1000 of Fig. 1 according to embodiment 1 is that a hypervisor 15000 is provided on computer hardware 1400, and a virtual device layer 15010 is provided in the hypervisor 15000, and virtual machines such as an external connection virtual machine 15100, a real-time control virtual machine 15200, and a virtual machine n 15300 are provided.
[0143] 23, the software and execution environment (1100C, 1200C, 1300C, 1500C, 1600C, 1700C, 1800C) in the externally connected virtual machine 15100 are allocated virtual computer hardware by the hypervisor 15000. Therefore, the externally connected virtual machine 15100 can perform the same functions as the information processing device 1000 shown in FIG. 1 according to the first embodiment.
[0144] Then, it is possible to use the information processing method described above for the information processing device 1000. Furthermore, as described above, it is also possible to configure the externally connected virtual machine 15100 using the configuration device 9000.
[0145] Although various exemplary embodiments and examples are described in this application, the various features, aspects, and functions described in one or more embodiments are not limited to the application of a particular embodiment, but may be applied to the embodiments alone or in various combinations. Therefore, countless variations not illustrated are contemplated within the scope of the technology disclosed in this specification. For example, this includes cases where at least one component is modified, added, or omitted, or where at least one component is extracted and combined with components of another embodiment. [Explanation of symbols]
[0146] 1000, 1000A, 1000B, 1000C information processing device, 1100, 1100B, 1100C execution environment isolation setting unit, 1110 startup setting unit, 1120 configuration risk evaluation unit, 1130, 13030 execution environment isolation definition table, 1140, 13040 log function setting definition table, 1150, 13050 configuration risk definition table, 1200, 1200C execution environment isolation placement unit, 1300, 1300C system software, 1320 system call control unit, 1330 system function control unit, 1340 hardware resource control unit, 1360 append circular buffer, 1400 computer hardware, 1430 communication device, 1440 nonvolatile storage device, 1450 security module device, 1470 diagnostic port, 1500, 1500C External connection execution environment, 1600, 1600C log function execution environment, 1700 system setting control execution environment, 1710 authentication and secure access unit, 1720 system setting control processing unit, 1810 application software, 1920 diagnostic device A, 1930 diagnostic device B, 2001 execution environment name, 2002 space separation setting, 2003 execution environment file system setting, 2004 system call permission list, 2005 system function permission list, 2006 resource allocation setting, 2007 device access control setting, 2008 startup order, 3000 log function name, 3001 log buffer setting, 3002 log buffer access function, 3003 log file setting, 4000 risk identifier, 4001 risk definition, 4002 risk value, 4003 configuration evaluation, 9000 configuration device, 9001 user HMI unit, 9002 Deployment unit, 9003 Transmission configuration risk assessment unit, 9004 Transmission authentication and secure access unit, 9005 Transmission execution environment isolation definition table, 9006 Transmission log function setting definition table, 9007 Transmission configuration risk definition table, 9008 System setting control instruction description, 12000 Diagnostic connection execution environment, 12010 Diagnostic function, 13010 Status management unit, 13030A Second execution environment isolation definition table, 13040A Second log function setting definition table, 13050A Second configuration risk definition table
Claims
1. Computer hardware, system software that manages and controls the computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each of the application software programs is executed, a configuration risk definition table that defines the risk of external infringement for each of the execution environments, a configuration risk assessment unit that calculates a risk value for each of the execution environments based on the configuration risk definition table, and a launch setting unit that sets the execution environment of each of the application software programs and executes launch processing; an execution environment separation deployment unit that deploys the execution environment on the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the startup configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit, the execution environment separation setting unit has the execution environment separation definition table that defines the setting of the execution environment for a log function that records processing details of the information processing device, the execution environment separation arrangement unit arranges, in the computer hardware, a log function execution environment in which a log function is executed based on separation information defined by the execution environment separation definition table; An information processing device that executes the log function arranged by the execution environment separation arrangement unit.
2. 2. The information processing device according to claim 1, wherein the startup setting unit starts the application software deployed by the execution environment separation deployment unit, and stops the startup of the application software if the risk value calculated by the configuration risk assessment unit is equal to or greater than a predetermined unacceptable value.
3. The information processing apparatus according to claim 1 , wherein the startup setting unit starts the application software in accordance with a startup start order defined in the execution environment separation definition table.
4. The information processing apparatus according to claim 1 , wherein the execution environment separation setting unit sets a log function execution environment in which the log function is executed for each log function defined based on the log function setting definition table.
5. Computer hardware, system software that manages and controls the computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each of the application software programs is executed, a configuration risk definition table that defines the risk of external infringement for each of the execution environments, a configuration risk assessment unit that calculates a risk value for each of the execution environments based on the configuration risk definition table, and a launch setting unit that sets the execution environment of each of the application software programs and executes launch processing; an execution environment separation deployment unit that deploys the execution environment on the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the startup configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit, an execution environment separation definition table for an information processing device, the execution environment separation definition table having: a name of the execution environment to be set; a space separation setting indicating the space to be set; an execution environment file system setting indicating the file system to be used in the execution environment; a system call permission list indicating system calls for which permission is sought to be made to the system software in the execution environment; a system function permission list indicating the functions of the system software to be used in the execution environment; a resource allocation setting indicating resources to be allocated from resources managed by the system software in the execution environment; and a device access control setting indicating devices managed by the system software that are accessed in the execution environment.
6. 5. The information processing device according to claim 4, wherein the log function setting definition table includes a name of the log function, a log buffer setting that identifies a log buffer allocated to the log function and indicates the size of the log buffer, a log buffer access function that indicates the execution environment that accesses the log buffer and a function that operates in that execution environment, and a log file setting that identifies a log file that records the contents of the log buffer.
7. Computer hardware, system software that manages and controls the computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each of the application software programs is executed, a configuration risk definition table that defines the risk of external infringement for each of the execution environments, a configuration risk assessment unit that calculates a risk value for each of the execution environments based on the configuration risk definition table, and a launch setting unit that sets the execution environment of each of the application software programs and executes launch processing; an execution environment separation deployment unit that deploys the execution environment on the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the startup configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit, The configuration risk definition table is an information processing device that has a risk identifier that identifies a configuration risk definition, a risk definition that indicates the execution environment and separation definition that have the configuration risk, and a risk value that indicates the degree of risk for the risk definition.
8. In the configuration risk definition table, the risk definition includes a logical evaluation formula using the risk identifier and a total evaluation formula by summing up risk values, and the risk value includes an indication that the risk value is unacceptable; The information processing device described in claim 7, wherein the configuration risk definition table has a configuration-time evaluation that indicates that the total value of risk values calculated by the configuration risk evaluation unit is acceptable if it is smaller than a predetermined unacceptable value, and is unacceptable if it is equal to or greater than the unacceptable value.
9. the computer hardware includes a communication device and a nonvolatile storage device; the system software has an append circular buffer that allows append writing and reading; the execution environment separation setting unit has an execution environment separation definition table that defines settings of an external connection execution environment for connecting to another information processing device via the communication device, the execution environment separation arrangement unit arranges the externally connected execution environment on the computer hardware based on separation information defined by the execution environment separation definition table; writing a log output by a processing function in the external connection execution environment to an append circular buffer; 2. The information processing apparatus according to claim 1, wherein the log function reads the communication log written in the write-once circular buffer and records it in the nonvolatile storage device.
10. Computer hardware, system software that manages and controls the computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each of the application software programs is executed, a configuration risk definition table that defines the risk of external infringement for each of the execution environments, a configuration risk assessment unit that calculates a risk value for each of the execution environments based on the configuration risk definition table, and a launch setting unit that sets the execution environment of each of the application software programs and executes launch processing; an execution environment separation deployment unit that deploys the execution environment on the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the startup configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit, the computer hardware includes a communication device; the execution environment separation setting unit has an execution environment separation definition table that defines the setting of a system setting control execution environment in which an authentication / secure access unit that performs authentication processing and secure communication processing for receiving system setting control information for setting at least one of the system software and the application software from an external component device via the communication device, and a system setting control processing unit that sets and executes at least one of the system software and the application software based on the received system setting control information, function; The execution environment separation arrangement unit is an information processing device that arranges the system setting control execution environment on the computer hardware based on separation information defined by the execution environment separation definition table.
11. Computer hardware, system software that manages and controls the computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each of the application software programs is executed, a configuration risk definition table that defines the risk of external infringement for each of the execution environments, a configuration risk assessment unit that calculates a risk value for each of the execution environments based on the configuration risk definition table, and a launch setting unit that sets the execution environment of each of the application software programs and executes launch processing; an execution environment separation deployment unit that deploys the execution environment on the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the startup configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit, the computer hardware has a diagnostic port for connecting to an external diagnostic device; the execution environment separation setting unit has an execution environment separation definition table that defines the setting of a diagnostic connection execution environment for performing a diagnostic function of receiving a diagnostic request from the diagnostic device, executing a diagnostic test on the information processing device, and transmitting a result of the diagnostic test to the diagnostic device; The execution environment separation arrangement unit is an information processing device that arranges the diagnostic connection execution environment on the computer hardware based on separation information defined by the execution environment separation definition table.
12. The information processing device described in claim 4, wherein the execution environment separation setting unit has a state management unit that manages the system state of the information processing device, and has a plurality of execution environment separation definition tables, a plurality of log function setting definition tables, and a plurality of configuration risk definition tables corresponding to the system state managed by the state management unit.
13. Computer hardware, system software that manages and controls the computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each of the application software programs is executed, a configuration risk definition table that defines the risk of external infringement for each of the execution environments, a configuration risk assessment unit that calculates a risk value for each of the execution environments based on the configuration risk definition table, and a launch setting unit that sets the execution environment of each of the application software programs and executes launch processing; an execution environment separation deployment unit that deploys the execution environment on the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the startup configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit, a first step in which the startup setting unit acquires a configuration-time evaluation indicating whether or not a risk of the information processing device is tolerable from the configuration risk definition table; a second step in which the startup setting unit starts startup processing of the execution environment for each of the execution environments defined in the execution environment isolation definition table when the configuration time evaluation is acceptable, and ends processing by the startup setting unit when the configuration time evaluation is unacceptable; a third step in which the startup setting unit waits for a determination as to whether the startup process result of each of the execution environments is acceptable; and an information processing method comprising: a fourth step in which, if the startup processing result of the execution environment is good and there are execution environments defined in the execution environment separation definition table for which startup processing has not been performed, the startup setting unit starts the startup processing of one of the execution environments and then proceeds to the third step; if the startup processing result is good and there are no execution environments for which startup processing has not been performed, the processing is terminated; and if the startup processing result is bad, all of the execution environments for which startup processing has been performed are terminated.
14. Computer hardware, system software that manages and controls the computer hardware; a plurality of application software programs that run on the system software; an execution environment isolation setting unit having an execution environment isolation definition table that defines the settings of each execution environment in which each of the application software programs is executed, a configuration risk definition table that defines the risk of external infringement for each of the execution environments, a configuration risk assessment unit that calculates a risk value for each of the execution environments based on the configuration risk definition table, and a launch setting unit that sets the execution environment of each of the application software programs and executes launch processing; an execution environment separation deployment unit that deploys the execution environment on the computer hardware based on the settings of the execution environment defined by the execution environment separation definition table in accordance with an instruction from the startup configuration unit, and executes the application software in the execution environment deployed by the execution environment separation deployment unit, a first step in which the startup setting unit acquires a configuration-time evaluation indicating whether or not a risk of the information processing device is tolerable from the configuration risk definition table; a second step in which the startup setting unit proceeds to a next step of processing of the startup setting unit of the execution environment defined in the execution environment isolation definition table if the configuration time evaluation is acceptable, and terminates the processing of the startup setting unit if the configuration time evaluation is unacceptable; a third step in which the launch setting unit generates a runtime environment launch process for launching the runtime environment, and if an error occurs during the launch process of the runtime environment, the runtime environment launch process notifies the user of the error result, terminates the already-launched runtime environment, and terminates the processing of the launch setting unit; a fourth step in which the execution environment startup process generates an initial process for startup of the execution environment; a fifth step in which the execution environment startup process instructs the execution environment separation placement unit to place the execution environment via the space separation unit of the system software based on the description of the space separation setting specified in the execution environment separation definition table for the initial process; a sixth step in which the execution environment startup process specifies the root file system to be used in the execution environment based on a root file system described in an execution environment file system setting specified in the execution environment isolation definition table; a seventh step in which the execution environment startup process specifies the shared file system path to be used in the execution environment based on the shared file system path described in the execution environment file system setting specified in the execution environment isolation definition table; an eighth step in which the execution environment startup process allocates devices to be used in the execution environment based on the device access control settings specified in the execution environment isolation definition table, and enables only designated access methods; a ninth step in which the execution environment startup process starts a startup process of a functional process of the execution environment from the initial process of the execution environment and executes an initial setting of the functional process; a tenth step in which the execution environment startup process waits for completion of initialization of the function process of the execution environment; an eleventh step in which the execution environment startup process limits system calls that can be called from the execution environment based on the system call permission list specified in the execution environment isolation definition table via a system call control unit of the system software; a twelfth step in which the execution environment startup process limits functions of the system software that can be used by the execution environment based on the description of the system function permission list specified in the execution environment isolation definition table via a system function control unit of the system software; a thirteenth step in which the execution environment startup process limits the computer hardware resources available to the execution environment based on the resource allocation settings specified in the execution environment separation definition table via a hard resource control unit of the system software; a fourteenth step in which the execution environment startup process executes a log function setting process if the execution environment is a log function execution environment; a fifteenth step in which the execution environment startup process determines whether the log function execution environment has been started if there is a function that accesses a log in the function process in the execution environment, and if it has not been started, notifies an error result and terminates the started execution environment; and a sixteenth step in which the execution environment startup process starts processing of the functional process in the execution environment after initial setting and marks the functional process as started.
15. the execution environment separation setting unit has a log function setting definition table, The fourteenth step includes: a seventeenth step in which the startup setting unit creates an append circular buffer of a size described in a log buffer setting for each log function described in a log function name specified in the log function setting definition table; an eighteenth step in which the startup setting unit sets up a write interface to the append circular buffer for an environment described in a log buffer access function specified in the log function setting definition table; a nineteenth step in which the startup setting unit sets a write permission to the append circular buffer for a function described in a log buffer access function specified in the log function setting definition table; a twentieth step in which the startup setting unit creates a log file described in the log file setting specified in the log function setting definition table as a file to be recorded and saved; The sixteenth step includes:
15. The information processing method according to claim 14, further comprising a 21st step in which the startup setting unit puts the log function into a standby state until the log data is written to the append circular buffer in order to read the log data from the append circular buffer and record the log data to the log file.
16. Before the first step, a fifth step in which the configuration risk assessment unit determines, for each risk identifier specified in the configuration risk definition table, whether or not the execution environment isolation definition table contains content that matches the execution environment and isolation definition described in the risk definition, or whether or not the risk definition contains a description of a risk assessment formula or a risk value total; a sixth step of executing the fifth step for the next risk identifier if the execution environment and isolation definition described in the risk definition for the risk identifier do not exist in the execution environment isolation definition table and if the risk definition does not contain a description of the risk evaluation formula or the total risk value, and if the execution environment and isolation definition for each risk identifier specified in the configuration risk definition table exist in the execution environment isolation definition table or if a description of the risk evaluation formula or the total risk value exists, the configuration risk evaluation unit acquires the risk value described in the risk value for each risk identifier specified in the configuration risk definition table; a seventh step in which, if the acquired risk value is not allowable, the configuration risk assessment unit records the acquired risk value as being unsuitable for the configuration assessment specified in the configuration risk definition table, and terminates the process; an eighth step in which the configuration risk assessment unit adds the acquired risk value to a total value of risk values and executes the fifth step if the acquired risk value is acceptable and the risk identifier related to the risk value is not the last risk identifier specified in the configuration risk definition table; The information processing method described in claim 13 further comprises a ninth step in which, if the acquired risk value is acceptable and the risk identifier associated with the risk value is the last risk identifier specified in the configuration risk definition table, the configuration risk assessment unit records the risk as acceptable in the configuration risk definition table.
17. 13. The information processing device according to claim 12, a first step of extracting execution environments for which there is a difference in setting contents for each execution environment name between a first execution environment isolation definition table for before the state transition and a second execution environment isolation definition table for after the state transition when the state management unit determines that a state transition has occurred in the system state of the information processing device and when a second configuration risk definition table for after the state transition exists; a second step in which the state management unit performs a termination process for the execution environment in which a difference exists in the extracted setting content; a third step in which the state management unit extracts log functions for which there is a difference in setting content for each log function name between a first log function setting definition table for before the state transition and a second log function setting definition table for after the state transition; a fourth step in which the state management unit performs a termination process for the log function for which a difference exists in the extracted setting content; a fifth step in which the state management unit discards the access permission written in the log buffer access function specified in the log function setting definition table of the log function for which a difference exists in the extracted setting content; a sixth step in which the state management unit discards an interface to the append circular buffer described in the log buffer access function specified in the log function setting definition table of the log function having a difference in the extracted setting content; a seventh step in which the state management unit performs a process of terminating the append circular buffer described in the log buffer setting specified in the log function setting definition table of the log function having a difference in the extracted setting content; an eighth step in which the startup setting unit executes a setting and startup process for the execution environment in which there is a difference in the extracted setting content; and an information processing method comprising: a ninth step in which the startup setting unit executes log function settings for the log functions for which there is a difference in the extracted setting contents.
18. an HMI having an input unit and a display unit; Transmission execution environment separation definition table, Sending log function setting definition table, Sending configuration risk definition table; a transmission configuration risk assessment unit; a system setting control instruction description in which processing to be executed by the system setting control processing unit of the system setting control execution environment provided in the information processing device is described; a transmission authentication and secure access unit that performs authentication processing and secure communication processing between the information processing device and the system setting control execution environment; the transmission execution environment separation definition table, and the transmission log function setting definition table; a deployment unit that transmits information including the transmission configuration risk definition table and the system setting control instruction description to the system setting control execution environment of the information processing device; A component device connected to the information processing device according to claim 10, comprising:
19. 19. The component device of claim 18, a first step in which the deployment unit causes the transmission configuration risk assessment unit to calculate a risk value based on a transmission configuration risk definition table; a second step in which the deployment unit acquires a configuration time evaluation of the transmission configuration risk definition table; a third step in which, when the evaluation at the time of configuration is acceptable, the deployment unit configures a secure interconnection path between the transmission authentication and secure access unit of the configuration device and the authentication and secure access unit of the information processing device; A configuration method comprising a fourth step in which the deployment unit transmits data including the transmission execution environment isolation definition table, the transmission log function setting definition table, the transmission configuration risk definition table, and the system setting control instruction description to the information processing device.
Citation Information
Patent Citations
Virtual machine arrangement program and device
JP2011028328A
Information processing device and abnormality handling method
JP6723955B2
Vertically integrated automatic threat level determination for containers and hosts in a containerization environment
US20200110873A1
System and method for evaluating adequacy of applications in execution environments
WO2011018827A1
Information processing apparatus
WO2011074168A1