Information processing device and device protection method
The control device's battery power monitoring system addresses the inefficiencies of conventional methods by remotely detecting tampering attempts and adapting startup behavior to ensure safety and reliability.
Patent Information
- Application Number
- JP2023058092
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-31
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2043-03-31
AI Technical Summary
Conventional device protection methods for control devices in plants are cumbersome, costly, and lack effective remote tamper detection, leading to potential security vulnerabilities and reliability issues.
The control device is designed with a detachable housing and a battery power monitoring system that detects loss of battery power when the case is opened or detached, recording this event and controlling startup behavior based on pre-set safety guidelines to ensure security.
This approach allows for swift, remote detection of tampering attempts, reduces the need for physical security measures, and ensures reliable operation by automatically adapting startup behavior to maintain safety.
Smart Images

Figure 0007794164000001 
Figure 0007794164000002 
Figure 0007794164000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device and a device protection method. [Background technology]
[0002] In various plants that use oil, petrochemical, chemical, gas, etc., control systems perform various controls such as opening and closing valves and maintaining constant temperatures. Therefore, control systems must ensure reliability according to the objects they control. Examples of such control systems include distributed control systems (DCS), safety instrumented systems (SIS), and other factory automation (FA) equipment.
[0003] In a control system, a control device equipped with a microprocessor, a processor, a memory, etc. operates. The control device is attached to an adapter equipped with wiring for power supply, wiring and connectors for inter-device communication with various plant devices, other control devices, information processing devices, etc. The control device is attached to the adapter so that it can be inserted and removed for inspection, maintenance, etc.
[0004] There are various risks to such control devices, such as tampering with the boards on which the processors and memories are mounted, unauthorized acquisition of data from the memory, or writing of malicious data to the memory. To maintain the reliability of the plant system, sufficient measures against these risks are required.
[0005] Regardless of whether the main power is on or off, if the control device is removed from the adapter or if a part of the housing case is opened, there is a risk of tampering with the circuits located inside the case, so it is desirable to detect the removal from the adapter or the opening of the case. Also, depending on the security level, when it detects that the control device has been removed from the adapter or the case has been opened, it may be required to notify the occurrence of the event, stop the device from starting, and erase data that requires security protection, etc.
[0006] There are two conventional security measures for such control devices. The first method is physical device protection. Specifically, the control device case is sealed with security screws or security seals to raise the barrier to tampering and also to make any traces of tampering visible. Sealing with security screws is achieved by attaching the control device to the adapter with security screws, and special tools are used for tightening and loosening. Furthermore, when sealing with security seals, after removing the security seal, the area left by the removal must be cleaned and the security seal must be reattached.
[0007] The second method is an electronic device protection method. Specifically, an electronic open detection function is installed in the control device. For example, an infrared sensor, a magnetic sensor, or a wire break detection sensor is used to detect the opening of the control device's case or removal from the adapter. Another method is to detect the opening of the case using a mechanical switch such as a button that is pressed when the case is attached.
[0008] In addition, a technology has been proposed in which a detection unit is attached to the lid of the case, monitoring software resides on a server that communicates periodically with the detection unit, and the digital value obtained from the signal voltage of the detection unit is compared with a stored initial value to determine whether there is an abnormality. [Prior art documents] [Patent documents]
[0009] [Patent Document 1] Japanese Patent Application Laid-Open No. 2007-65865 Summary of the Invention [Problem to be solved by the invention]
[0010] However, with conventional physical device protection methods, even when opening a case for maintenance or other purposes using the correct procedures, it requires the use of special tools and the time-consuming task of sealing it. Furthermore, when using security screws, special tools must be prepared and managed by a specific administrator, making security operations cumbersome. Furthermore, with physical device protection methods, it is difficult to remotely check for the possibility of electronic tampering, and tamper detection requires visual inspection of the actual device, which can result in a time lag in tamper detection.
[0011] Furthermore, when using conventional electronic equipment protection methods, the use of sensors requires the placement and adjustment of reflective materials, magnets, or elements facing the sensors, as well as the wiring and adjustment of patterns on the case and circuit board, which can complicate the design and increase costs. Furthermore, some sensors have a limited lifespan, which increases the amount of work required to ensure safety, such as maintenance. On the other hand, when using mechanical switches, information processing devices used for plant control are likely to be operated continuously for long periods of time, 24 hours a day, 365 days a year, which can lead to mechanical switch failure due to contact corrosion. In this case, it is difficult to diagnose whether the mechanical switch is functioning without opening the device, which increases the workload required to ensure safety.
[0012] Furthermore, with technology that determines an abnormality by comparing a digital value obtained from the signal voltage of a detector located on the lid of the case with a stored initial value, it is difficult to detect removal of the device from the adapter, and it cannot be said that sufficient safety is ensured. Therefore, it is difficult to improve the reliability of the information processing device. As such, it is difficult to ensure the safety of information processing devices such as control devices with conventional device protection technology.
[0013] One aspect of the present invention is to ensure the safety of an information processing device. [Means for solving the problem]
[0014] An information processing device according to one aspect includes the following units. The housing includes a first case and a second case that are detachable from each other, and the battery power source is connected to the first case. The detection unit is a power supply wiring extending from a battery power supply. The first case was removed from the second case The battery power supply monitors the voltage from the battery power source through a battery power line that is disconnected when the voltage supplied from the battery power source falls below a threshold, and detects a loss of battery power when the voltage supplied from the battery power source falls below a threshold. When the loss of battery power is detected, the first control unit records the detection of the loss of battery power. When the first control unit has a record of the detection of the loss of battery power, the second control unit causes the device to perform a predetermined behavior at startup. [Effects of the Invention]
[0015] According to the present invention, the safety of the information processing device can be ensured. [Brief explanation of the drawings]
[0016] [Figure 1] FIG. 2 is a side view of the control device according to the embodiment. [Figure 2] FIG. 2 is a front view of the control device according to the embodiment. [Figure 3] 2 is a block diagram showing the internal configuration of the control device according to the first embodiment. FIG. [Figure 4] 6 is a flowchart of a device protection process when the case according to the first embodiment is opened. [Figure 5] 4 is a flowchart of device protection processing at startup according to the first embodiment. [Figure 6] FIG. 10 is a block diagram showing the internal configuration of a control device according to a second embodiment. [Figure 7] 10 is a flowchart of a device protection process when a control device is detached from an adapter according to the second embodiment. [Figure 8]10 is a flowchart of a device protection process at startup according to the second embodiment. [Figure 9] 10A and 10B are diagrams illustrating an example of another structure of the housing of the control device. [Figure 10] FIG. 10 is a block diagram of an example of a control device having the housing structure shown in FIG. [Figure 11] 10A and 10B are diagrams illustrating another example of a method for connecting battery cases. [Figure 12] FIG. 2 is a diagram illustrating an example of a hardware configuration of a control device. DETAILED DESCRIPTION OF THE INVENTION
[0017] Hereinafter, embodiments of an information processing device and a device protection method will be described with reference to the drawings. Note that the same elements are given the same reference numerals, and duplicated descriptions will be omitted as appropriate. Furthermore, each embodiment can be appropriately combined within a range that does not cause inconsistencies.
[0018] (First embodiment) (Overall composition) FIG. 1 is a side view of a control device according to an embodiment. However, for convenience of explanation, FIG. 1 shows part of the interior of the housing with part of the exterior being visible through the lens. FIG. 2 is a front view of the control device according to an embodiment. The control device 10 is a device that performs various controls on the plant 20, such as controlling the opening and closing of valves in the plant 20 and maintaining a constant temperature. The control device 10 is an example of an information processing device.
[0019] The adapter 105 is connected to the plant 20 via a network or the like. The adapter 105 is also equipped with wiring for power supply, wiring for inter-device communication with other information processing devices, etc., and a connector for connecting the control device 10.
[0020] The control device 10 has a housing including case 1 and case 2. Case 1 and case 2 are separable. By opening case 1, built-in devices such as a board on which a processor and memory mounted, which are arranged inside case 2, are exposed to the outside and can be accessed. Case 1 is an example of a "first case," and case 2 is an example of a "second case."
[0021] A battery case 3 is provided inside the case 1. The battery case 3 is connected and fixed to the case 1 by a latch or the like, as shown in Figure 2. A battery power source 101 is mounted in the battery case 3.
[0022] Case 2 houses a board on which a processor, memory, etc. are mounted. The board is fixed to case 2. The board controls plant 20 using the mounted processor, memory, etc. Furthermore, case 2 has an adapter connector 104 for connecting wiring and power supply paths extending from the board to adapter 105. When adapter connector 104 is inserted into and connected to adapter 105, wiring for power supply built into adapter 105 is connected to the power supply path of board 210, and further, a line extending from the board is connected to a line for connection to plant 20. This allows power to be supplied to the board and enables communication between board 210 and plant 20.
[0023] A battery connector 102 on the case 1 side and a battery connector 103 on the board side are provided on the battery power supply wiring extending from the battery power supply 101 to the board. The battery connectors 102 and 103 are detachable.
[0024] (Control device) 3 is a block diagram showing the internal configuration of the control device according to the first embodiment. As already explained, the control device 10, which is an information processing device, has cases 1 and 2, a battery case 3, a battery power supply 101, a battery connector 102, a battery connector 103, and an adapter connector 104. The control device 10 further has a main power supply 106, a battery power supply wiring 200, a communication port 204, and a circuit board 210.
[0025] The substrate 210 has a battery power loss detection unit 201, a record retention control unit 202, a tampering risk notification unit 203, and a behavior control unit 205. The battery power loss detection unit 201, the record retention control unit 202, the tampering risk notification unit 203, and the behavior control unit 205 are realized, for example, by a processor and memory mounted on the substrate 210. Alternatively, the battery power loss detection unit 201, the record retention control unit 202, the tampering risk notification unit 203, and the behavior control unit 205 may be realized by a microprocessor, a programmable logic device (PLD), or a field programmable gate array (FPGA).
[0026] When the adapter connector 104 and the adapter 105 are coupled, the main power supply 106 receives power via the adapter 105, as indicated by "VIN+" in Fig. 3. The main power supply 106 is also connected to ground (GND). The main power supply 106 is further connected to the substrate 210, and supplies power to the battery power loss detection unit 201, the record retention control unit 202, the tampering risk notification unit 203, and the behavior control unit 205, as indicated by "VOUT" in Fig. 3.
[0027] The battery power supply 101 is housed in a battery case 3 that is coupled to the case 1 with a latch or the like. With the battery connector 102 and the battery connector 103 coupled, the battery power supply 101 is connected to the circuit board 210 through a battery power supply wiring 200, and supplies a monitoring voltage and power to the battery power loss detection unit 201. The battery power loss detection unit 201 may operate from the main power supply 106 if one is available. If the main power supply 106 is not available, the battery power supply 101 operates from the battery power supply 101 or an auxiliary power supply such as a supercapacitor.
[0028] When battery connector 102 and battery connector 103 are coupled, battery power wiring 200 connects battery power supply 101 and circuit board 210, thereby supplying power from battery power supply 101 to circuit board 210. Battery power wiring 200 is broken when battery connector 102 and battery connector 103 are separated. In other words, when battery connector 102 and battery connector 103 are separated, the supply of voltage to be monitored from battery power supply 101 to battery power loss detection unit 201 is cut off.
[0029] The battery connector 102 and the battery connector 103 are disposed on the battery power wiring 200. When the battery connector 102 and the battery connector 103 are coupled, the battery power wiring 200 connects the battery power source 101 and the battery power loss detection unit 201. Conversely, when the battery connector 102 and the battery connector 103 are separated, the battery power wiring 200 is disconnected between the battery power source 101 and the battery power loss detection unit 201.
[0030] Here, battery connector 102 is fixed to case 1. Battery connector 103 is fixed to a substrate 210 mounted on case 2. Therefore, when case 1 is opened and separated from case 2, the connection between battery connector 102 and battery connector 103 is released, and battery connector 102 is separated from battery connector 103. Conversely, when case 1 is closed and case 1 is mated with case 2, battery connector 102 is connected to battery connector 103.
[0031] That is, opening the case 1 cuts off the supply of voltage to be monitored from the battery power supply 101 to the battery power loss detection unit 201 mounted on the board 210. Conversely, closing the case 1 starts the supply of voltage to be monitored from the battery power supply 101 to the battery power loss detection unit 201 mounted on the board 210.
[0032] The communication port 204 is an interface for communication between the control device 10 and an external device. The communication port 204 is connected to a tampering risk notification unit 203 of the substrate 210. The communication port 204 is also connected via an external communication network 301 to a server 300 that is authenticated for communication with the control device 10.
[0033] Battery power loss detection unit 201 receives power from battery power supply 101 when battery connector 102 and battery connector 103 are connected. Battery power loss detection unit 201 detects loss of battery power when the voltage of battery power supply 101 falls below a threshold, for example, when battery connector 102 and battery connector 103 are separated and the voltage supply to the monitored object from battery power supply 101 is cut off. Upon detecting loss of battery power, battery power loss detection unit 201 outputs a detection signal of loss of battery power to record retention control unit 202 and tampering risk detection unit 203. Battery power loss detection unit 201 is an example of a "detection unit."
[0034] Record retention control unit 202 has a non-volatile storage area. When power is being supplied from main power supply 106 and the voltage of battery power supply 101 falls below a threshold, record retention control unit 202 receives an input of a battery power loss detection signal from battery power loss detection unit 201. Record retention control unit 202 then records information on the detection of battery power loss in its own non-volatile storage area. This record retention control unit 202 is an example of a "first control unit."
[0035] Furthermore, as a measure for when power is not being supplied from the main power supply 106, the record retention control unit 202 may have, for example, a supercapacitor or the like that stores power. In this case, when a detection signal of loss of battery power is received while power is not being supplied from the main power supply 106, information on the detection of loss of battery power can be recorded in its own non-volatile memory area using the power stored in the supercapacitor or the like. In this configuration, it is preferable that a microprocessor with low power consumption is mounted on the substrate 210.
[0036] The tampering risk notification unit 203 operates using power supplied from the main power supply 106. When the voltage of the battery power supply 101 falls below a threshold, the tampering risk notification unit 203 receives an input of a battery power loss detection signal from the battery power loss detection unit 201. The tampering risk notification unit 203 then notifies the authenticated server 300, which performs alarm monitoring and the like, of the risk of tampering via the communication port 204. This is because, if the case 1 is opened, external access to the board 210, etc. becomes possible, increasing the possibility of tampering. This tampering risk notification unit 203 is an example of a "notification unit."
[0037] The behavior control unit 205 is configured with pre-set safety guidelines, such as a security level and the operation of the protected object. The behavior control unit 205 then stores in advance a startup operation based on the security level, the operation of the protected object, and the like. If the record retention control unit 202 has a record of the detection of battery power loss remaining in the non-volatile storage area and there is a risk of tampering, the behavior control unit 205 causes the control device 10 to execute a predetermined behavior at startup. For example, the behavior control unit 205 controls startup behavior by stopping startup, erasing data, starting in safe mode, or any combination thereof, in accordance with the set security level, the operation of the protected object, and the like.
[0038] When startup begins, for example, by inserting the adapter connector 104 into the adapter 105 and receiving power from the main power supply 106, the behavior control unit 205 determines whether or not a record of the detection of loss of battery power is recorded in the non-volatile area of the record retention control unit 202. If a record of the detection of loss of battery power is not recorded in the non-volatile area of the record retention control unit 202, the behavior control unit 205 executes normal startup of the control device 10.
[0039] On the other hand, if the record of the detection of the loss of battery power is recorded in the non-volatile area of the record retention control unit 202, the behavior control unit 205 checks the safety guidelines such as the pre-set security level and the behavior of the protected object, etc. Then, the behavior control unit 205 executes the behavior control at the time of startup of the control device 10 according to the checked security level and the safety guidelines such as the behavior of the protected object.
[0040] Here, even if it is unclear whether the case 1 has actually been opened and the circuit has been tampered with, the behavior control unit 205 can suspect tampering and perform safety-oriented control such as stopping the activation of the control device 10 or starting it in safe mode, or erasing predetermined data. This behavior control unit 205 is an example of a "second control unit."
[0041] (Device protection processing) Fig. 4 is a flowchart of the device protection process when the case according to the first embodiment is opened. Fig. 5 is a flowchart of the device protection process at startup according to the first embodiment. Next, the flow of the device protection process when the case 1 is opened and at startup will be described with reference to Figs. 4 and 5. Here, the case where power remains supplied from the main power supply 106 will be described as an example.
[0042] A description will be given of the device protection process when case 1 shown in Fig. 4 is opened. Case 1 of control device 10 is opened, and case 1 and case 2 are separated (step S1).
[0043] When the cases 1 and 2 are separated, the battery connectors 102 and 103 fixed to the cases 1 and 2 are separated (step S2).
[0044] When the battery connector 102 and the battery connector 103 are separated, the battery power supply wiring 200 is broken, the power supply from the battery power supply 101 to the board 210 is stopped, and the battery power is lost (step S3).
[0045] The battery power loss detection unit 201 detects that the voltage of the battery power supply 101 has fallen below a threshold (step S4). The battery power loss detection unit 201 outputs a detection signal of the loss of battery power to the record retention control unit 202 and the tampering risk detection unit 203.
[0046] Upon receiving the detection signal of loss of battery power from battery power loss detection section 201, tampering risk detection section 203 notifies server 300 of the risk of tampering (step S5).
[0047] Record keeping control unit 202 receives the detection signal of loss of battery power from battery power loss detection unit 201 and records information on the detection of loss of battery power in its own nonvolatile storage area (step S6).
[0048] Next, a description will be given of the flow of device protection processing at startup shown in Fig. 5. When power is supplied from the main power supply 106 by inserting the adapter connector 104 into the adapter 105, the behavior control unit 205 starts startup (step S11).
[0049] Next, the behavior control unit 205 determines whether or not a record of the detection of loss of battery power exists in the non-volatile area of the record retention control unit 202 (step S12).
[0050] If the record of the detection of loss of battery power is recorded in the non-volatile area of the record retention control unit 202 (step S12: Yes), the behavior control unit 205 checks the pre-set security level or the operation of the protected object (step S13).
[0051] Then, the behavior control unit 205 executes control at the time of startup of the control device 10 in accordance with the confirmed security level and the standards of safety guidelines such as the behavior of the protected object (step S14).
[0052] On the other hand, if the record of the detection of the loss of battery power is not recorded in the non-volatile area of the record retention control unit 202 (step S12: No), the behavior control unit 205 executes normal startup of the control device 10 (step S15).
[0053] (effect) As described above, the control device 10 according to the embodiment detects loss of battery power when the housing case 1 is opened by disconnecting the battery power wiring 200 extending from the battery power supply 101 and cutting off the power supply to the substrate 210. Next, the control device 10 records the detection information of the loss of battery power in a non-volatile storage area and notifies the authenticated server 300, which performs alarm monitoring, of the detection of the loss of battery power. Furthermore, the control device 10 checks the non-volatile storage area at startup, and if a record of the detection of the loss of battery power remains, controls its behavior at startup in accordance with safety guidelines such as a pre-set security level and the operation of the protected object.
[0054] This allows remote confirmation that case 1 has been opened, enabling swift action to be taken against any unauthorized activity. Furthermore, if case 1 is opened, the startup behavior is controlled in accordance with safety guidelines, making it possible to automatically protect control device 10.
[0055] That is, by linking the loss of battery power with the opening and closing of the case 1, the risk of opening the case 1 can be electronically detected when a risk occurs if power is being supplied from the main power source 106, or immediately before startup if power is not being supplied, thereby contributing to safety management of the control device 10. Furthermore, even when power is not being supplied from the main power source 106, the risk of the case 1 being opened can be easily detected by using a supercapacitor or the like. Furthermore, without using a sensor or mechanical switch, the risk of the case 1 being opened can be easily detected using an existing processor, PLD, and battery monitoring circuit, and with simple wiring and housing design. Furthermore, the electronic nature of the device protection method eliminates the need for security seals, security screws, special tools, and the like, which must be stored with security in mind. Furthermore, the device protection method according to this embodiment can also contribute to deterring fraudulent activities because the security measures in place cannot be seen at a glance. Therefore, the safety of an information processing device, such as the control device 10, can be easily ensured.
[0056] (Second embodiment) 6 is a block diagram showing the internal configuration of a control device according to the second embodiment. The control device 10 according to this embodiment differs from the first embodiment in that it detects loss of battery power even when the control device 10 is detached from the adapter 105. In the following explanation, explanations of the operations of the same parts as in the first embodiment will be omitted.
[0057] (Control device) 6, in the control device 10 according to this embodiment, the battery power supply wiring 200 extending from the battery power supply 101 to the substrate 210 passes through the joint between the adapter connector 104 and the adapter 105. When the case 2 is removed from the adapter 105, the adapter connector 104 and the adapter 105 are separated, and the battery power supply wiring 200 passing through the joint between the adapter connector 104 and the adapter 105 is broken.
[0058] When case 2 is removed from adapter 105, adapter connector 104 is separated from adapter 105, and the supply of voltage to the monitored object from battery power supply 101 stops, causing the voltage of battery power supply 101 to fall below a threshold, and battery power loss detection unit 201 detects loss of battery power. In this case, because the power supply from main power supply 106 has been lost, an auxiliary power supply such as a supercapacitor is used as the driving power source for battery power loss detection unit 201. Upon detecting loss of battery power, battery power loss detection unit 201 outputs a detection signal of loss of battery power to record retention control unit 202 and tampering risk detection unit 203.
[0059] When case 2 is removed from adapter 105, power supply from main power supply 106 stops and power supply from battery power supply 101 also stops. Therefore, record retention control unit 202 holds, for example, a supercapacitor or the like that stores power, and uses the power stored in the supercapacitor or the like to record information on the detection of loss of battery power in its own nonvolatile storage area.
[0060] When the adapter connector 104 is inserted into the adapter 105, power is supplied from the main power supply 106, and restarting begins, the behavior control unit 205 determines whether or not a record of the detection of loss of battery power is recorded in the non-volatile area of the record retention control unit 202. If a record of the detection of loss of battery power is not recorded in the non-volatile area of the record retention control unit 202, the behavior control unit 205 executes normal startup of the control device 10.
[0061] On the other hand, if the record of the detection of the loss of battery power is recorded in the non-volatile area of the record retention control unit 202, the behavior control unit 205 checks the safety guidelines such as the pre-set security level and the behavior of the protected object, etc. Then, the behavior control unit 205 executes the behavior control at the time of startup of the control device 10 according to the checked security level and the safety guidelines such as the behavior of the protected object.
[0062] (Device protection processing) Fig. 7 is a flowchart of the device protection process when the control device is removed from the adapter according to the second embodiment. Fig. 8 is a flowchart of the device protection process at startup according to the second embodiment. Next, the flow of the device protection process when the case 2 is opened and at restart will be described with reference to Figs. 7 and 8.
[0063] A description will be given of the device protection process when the control device 10 is removed from the adapter 105 shown in Fig. 7. The control device 10 is removed from the adapter 105, and the case 2 and the adapter 105 are separated (step S21).
[0064] When the case 2 and the adapter 105 are separated, the adapter connector 104 and the adapter 105 fixed thereto are separated, and the battery power supply wiring 200 is broken (step S22).
[0065] When the adapter connector 104 and the adapter 105 are separated, the battery power supply wiring 200 is broken, the power supply from the battery power supply 101 to the board 210 is stopped, and the battery power is lost (step S23).
[0066] The battery power loss detection unit 201 detects that the voltage of the battery power supply 101 has fallen below a threshold (step S24). The battery power loss detection unit 201 outputs a detection signal of the loss of battery power to the record retention control unit 202 and the tampering risk detection unit 203.
[0067] Upon receiving the detection signal of loss of battery power from the battery power loss detection unit 201, the record retention control unit 202 uses the power stored in a supercapacitor or the like to record information on the detection of loss of battery power in its own non-volatile memory area (step S25).
[0068] Next, a description will be given of the device protection process at startup shown in Fig. 8. After adapter connector 104 is attached to adapter 105, power is supplied from main power supply 106, and behavior control unit 205 starts startup (step S31).
[0069] Next, the behavior control unit 205 determines whether or not a record of the detection of loss of battery power exists in the non-volatile area of the record retention control unit 202 (step S32).
[0070] If the record of the detection of loss of battery power is recorded in the non-volatile area of the record retention control unit 202 (step S32: Yes), the behavior control unit 205 checks the pre-set security level or the operation of the protected object (step S33).
[0071] Then, the behavior control unit 205 executes control at the time of startup of the control device 10 in accordance with the confirmed security level and the standards of safety guidelines such as the behavior of the protected object (step S34).
[0072] On the other hand, if the record of the detection of the loss of battery power is not recorded in the non-volatile area of the record retention control unit 202 (step S32: No), the behavior control unit 205 executes normal startup of the control device 10 (step S35).
[0073] (effect) As described above, the control device 10 according to this embodiment, which is an information processing device, detects loss of battery power not only when the case 1 is opened but also when the control device 10 is detached from the adapter 105. When the control device 10 is restarted, it checks the non-volatile storage area, and if a record of the detection of loss of battery power remains, it controls its behavior at startup in accordance with safety guidelines such as a pre-set security level and the operation of the protected object.
[0074] This makes it possible to remotely grasp the risk of fraudulent activity and quickly deal with it even when the control device 10 is detached from the adapter 105. Therefore, it becomes possible to easily ensure the safety of an information processing device, such as the control device 10.
[0075] (Variation) In each of the above-described embodiments, detection of loss of battery power does not distinguish between replacement of a genuine battery power supply 101, removal of the control device 10 from a genuine adapter 105, and actions that may indicate tampering. Therefore, the control device 10 merely notifies that there is a "possibility" of tampering, and performs protective operations assuming that tampering has occurred.
[0076] Therefore, when the battery power supply 101 is replaced or the control device 10 is removed from the adapter 105 according to the normal procedure, the server 300, which has been authenticated in advance, notifies the control device 10 of the removal notice via the communication port 204 by secure communication.
[0077] The record retention control unit 202 of the control device 10 receives the removal notice from the server 300 via the tampering risk notification unit 203, and records the removal notice in a non-volatile storage area held by the control device 10. Thereafter, when the battery power supply 101 is replaced or the control device 10 is removed from the adapter 105 according to a normal procedure, the record retention control unit 202 leaves a record of the detection of the loss of battery power in the non-volatile storage area held by the control device 10.
[0078] If there is a record of a removal notice in the nonvolatile storage area of the record retention control unit 202 at the time of rebooting, the behavior control unit 205 determines that there is no risk as a normal procedure and performs normal startup even if there is a record of detection of loss of battery power. Then, the record retention control unit 202 clears the removal notice after rebooting to prepare for the next detection of loss of battery power.
[0079] As a result, when work is performed according to the normal procedures, normal startup is performed with no risk involved, and the efficiency of operation of the control device 10 can be improved.
[0080] Alternatively, the record retention control unit 202 may receive the removal time together with the removal notice from the server 300 and record the removal time together with the removal notice in the non-volatile storage area. In this case, the record retention control unit 202 also records the time when the battery power was lost in the non-volatile storage area.
[0081] At the time of reboot, the behavior control unit 205 compares the removal time recorded in the nonvolatile storage area of the record retention control unit 202 with the time of battery power loss, and if the difference is within a certain time, determines that the procedure is normal.
[0082] This makes it possible to realize protection by lock time, such as preventing missed work when work is not actually performed despite notice of removal, or disabling if a certain time passes before the battery power supply 101 is replaced or the control device 10 is removed from the adapter 105.
[0083] Alternatively, the loss of battery power can be detected by other means than recording the detection of the loss of battery power in a nonvolatile memory area and checking the aforementioned area at restart. For example, the record retention control unit 202 may be an IC (Integrated Circuit) that operates on either the main power supply 106 or the battery power supply 101 and has a memory area that cannot maintain the state before the power loss and returns to the initial value when both power supplies are lost.
[0084] For example, the control device 10 is equipped with an RTC (Real Time Clock) as the record retention control unit 202. The RTC has a non-volatile flag that detects the stop of oscillation and retains the flag until it is cleared by software. Therefore, if both the main power supply 106 and the battery power supply 101 are lost, the RTC stops oscillating and the flag can be used to detect the loss of battery power when the power supply from the main power supply 106 is lost and record the loss in the non-volatile storage area. In this case, the behavior control unit 205 can confirm the detection of the loss of battery power by checking the value of the flag retained by the RTC, which is the record retention control unit 202, at the time of restart.
[0085] Furthermore, even when an RTC is used as the record retention control unit 202, it is possible to detect loss of battery power and record the time of battery power loss. For example, some types of RTCs have a non-volatile storage area that detects a drop in the voltage of the battery power supply 101 and retains the time until it is cleared by software. By using such an RTC, the record retention control unit 202 can also record the time of battery power loss.
[0086] As described above, when an RTC is used as the record retention control unit 202, the RTC is often implemented in an information processing device, and has the advantage that it can be realized without adding extra ICs such as a supercapacitor or a low-power microcomputer for recording in a non-volatile memory area when both the main power supply 106 and the battery power supply 101 are lost.
[0087] Furthermore, in each of the above-described embodiments, it was possible to open case 1 and separate it from case 2 while leaving case 2 in adapter 105. However, case 1 and case 2 may have other structures.
[0088] Fig. 9 is a diagram showing an example of another structure of the housing of the control device. Fig. 9 includes a plan view 111, a side view 112, a rear view 113, and a side view 114 seen from the opposite direction to the side view 112. Cases 11 and 12 have a connecting portion on the adapter 105 side, and this connecting portion is hidden from the outside. When cases 11 and 12 are connected, they cover and conceal the circuitry.
[0089] In this case, the control device 10 can be separated into the case 11 and the case 12 by removing it from the adapter 105. In this case, the record keeping control unit 202 is preferably configured to keep a record of the detection of the loss of battery power in the event of a loss of both the main power supply 106 and the battery power supply 101, such as a configuration including a supercapacitor or a configuration realized by an RTC.
[0090] Fig. 10 is a block diagram of an example of a control device having the housing structure shown in Fig. 9. In the case of the housing structure shown in Fig. 9, the connection operations between case 1 and case 2 and battery connectors 102 and 103 connected to battery case 3 do not need to be linked. That is, as shown in Fig. 10, the control device 10 does not need to be equipped with battery connectors 102 and 103. Alternatively, the battery power source 101 may be directly mounted on the substrate 210 without using the battery case 3.
[0091] The control device 10 detects a loss of battery power, for example, when the battery case 3 is removed while the control device 10 is connected to the adapter 105 and the main power supply 106 is still on. However, in the case of the configuration shown in Figures 9 and 10, the cases 11 and 12 are not disassembled unless the control device 10 is removed from the adapter 105, so there is little risk that the battery case 3 will be removed while the control device 10 is connected to the adapter 105. Therefore, the tampering risk notification unit 203 can simply notify the user of the loss of battery power in such a case without issuing a tampering risk notification.
[0092] Fig. 11 is a diagram showing another example of a method for connecting battery cases. Alternatively, instead of connecting the battery case 3 to the case 1 as in the above-described embodiments, the battery connector 30 at the end of the battery cable 31 extending from the battery case 3 may be connected to the battery power supply wiring 200 so as to straddle the case 1, as shown in Fig. 11. In the configuration shown in Fig. 11, by unplugging the battery connector 30 and removing the battery power supply 101, it is possible to open the case 1 and separate the case 1 from the case 2. In this way, even with a structure in which the battery connector 30 connected to the battery power supply 101 is connected to the battery power supply wiring 200 through the case 1, it is possible to detect a loss of battery power when the case 1 is opened.
[0093] [system] The information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed arbitrarily unless otherwise specified.
[0094] Furthermore, the components of each device shown in the figure are functional concepts and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown. In other words, all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc.
[0095] Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU (Central Processing Unit) and a program analyzed and executed by the CPU, or can be realized as hardware using wired logic. As shown above, a microprocessor, PLD, or FPGA can also be used instead of a CPU.
[0096] [Hardware] Next, an example of the hardware configuration of the control device 10 will be described. FIG. 12 is a diagram showing an example of the hardware configuration of the control device. As shown in FIG. 12, the control device 10 includes a processor 91, a memory 92, a communication device 93, and an HDD (Hard Disk Drive) 94. The processor 91 is connected to the memory 92, the communication device 93, and the HDD 94 via a bus. Here, the HDD 94 can be replaced with a flash memory, an eMMC (embedded multi media card), an SD memory, an SSD (Solid State Drive), or the like. For example, in the case of an embedded system, a CPU chip equipped with the processor 91 is provided with a main memory interface, a communication interface, and a flash memory interface as ports connected to an internal bus, to which the memory 92, the communication port, the flash memory, and the like are connected.
[0097] The communication device 93 is equipped with a communication function and is used for communication with other information processing devices. In the case of an embedded system, the function of the communication device 93 is realized by combining the communication function built into the CPU 91 with an IC external to the CPU 91.
[0098] The HDD 94 is an auxiliary storage device and stores various programs including programs for implementing the functions of the battery power loss detection unit 201, the record retention control unit 202, the tampering risk notification unit 203, and the behavior control unit 205.
[0099] The processor 91 reads out various programs stored in the HDD 94, expands them into the memory 92, and executes them. As a result, the processor 91 realizes the functions of a battery power loss detection unit 201, a record retention control unit 202, a tampering risk notification unit 203, and a behavior control unit 205.
[0100] In this way, the control device 10 operates as an information processing device that executes various processing methods by reading and executing a program. The control device 10 can also realize functions similar to those of the above-described embodiment by reading the program from a recording medium using a media reader and executing the read program. Note that the program referred to here is not limited to being executed by the control device 10. For example, the present invention can also be applied in the same way to cases where another computer or server executes the program, or where these execute the program in cooperation with each other.
[0101] This program can be distributed via a network such as the Internet. In addition, this program can be recorded on a computer-readable recording medium such as a hard disk, a flexible disk (FD), a CD-ROM, a magneto-optical disk (MO), or a digital versatile disk (DVD), and can be executed by being read from the recording medium by a computer.
[0102] Some examples of combinations of the disclosed technical features are described below.
[0103] (1) a detection unit that monitors a voltage from the battery power source through a power supply wiring extending from the battery power source, the power supply wiring being disconnected when a predetermined operation is performed on the housing, and detects a loss of battery power when the voltage supplied from the battery power source falls below a threshold; a first control unit that records the detection of the loss of battery power when the loss of battery power is detected; a second control unit that executes a predetermined behavior upon startup if the first control unit has a record of the detection of the loss of battery power; An information processing device comprising: (2) The information processing device according to (1) further comprises a notification unit that notifies an external device of the detection of the loss of battery power when the detection unit detects the loss of battery power. (3) the first control unit has a nonvolatile storage area, and records the detection of the loss of battery power in the nonvolatile storage area; The second control unit determines whether the detection of the loss of battery power is recorded in the nonvolatile storage area. The information processing device according to (1) or (2) is characterized in that: (4) the housing includes a first case and a second case that are detachable from each other; the battery power source is coupled to the first case; the detection unit is fixed to the second case, The battery power supply wiring is disconnected when the first case is detached from the second case as the predetermined operation. The information processing device according to any one of (1) to (3) above. (5) The information processing device according to any one of (1) to (4), wherein the second control unit determines and controls behavior at startup based on a preset safety guideline. (6) the housing is removably connected to an adapter for supplying main power and connecting to a communication line with another device; The battery power supply wiring is a wiring that connects the battery power supply and the detection unit through the inside of the adapter, and is disconnected when the housing is removed from the adapter as the predetermined operation. The information processing device according to any one of (1) to (5) above. (7) a power supply wiring extending from the battery power supply that is disconnected when a predetermined operation is performed on the housing, and a voltage from the battery power supply is monitored through the power supply wiring, and a loss of battery power is detected when the voltage supplied from the battery power supply falls below a threshold value; If the loss of battery power is detected, recording the detection of the loss of battery power; If the battery power loss detection record is found, a predetermined behavior is executed upon startup. 10. A device protection method comprising: [Explanation of symbols]
[0104] 1,2 cases 3 Battery case 10 Control device 101 Battery Power 102,103 Battery connector 104 Adapter Connector 105 Adapter 106 Main power supply 200 Battery power wiring 201 Battery power loss detection unit 202 Record Retention Control Unit 203 Tampering Risk Notification Department 204 communication port 205 Behavior control unit 210 Substrate 300 servers 301 Communication Network
Claims
1. A housing including a first case and a second case that are detachable from each other; a battery power source coupled to the first case; a detection unit that monitors a voltage from the battery power supply through a power supply wiring extending from the battery power supply, the power supply wiring being disconnected when the first case is detached from the second case, and detects a loss of battery power when the voltage supplied from the battery power supply falls below a threshold; a first control unit that records the detection of the loss of battery power when the loss of battery power is detected; a second control unit that executes a predetermined behavior at startup if the first control unit has a record of the detection of the loss of battery power; An information processing device comprising:
2. A housing removably connected to an adapter for supplying main power and connecting to a communication line with another device; a detection unit that monitors a voltage from the battery power source through a power supply wiring that extends from the battery power source and connects the battery power source via the inside of the adapter, the power supply wiring being disconnected when the housing is removed from the adapter, and that detects loss of battery power when the voltage supplied from the battery power source falls below a threshold; a first control unit that records the detection of the loss of battery power when the loss of battery power is detected; a second control unit that executes a predetermined behavior at startup if the first control unit has a record of the detection of the loss of battery power; An information processing device comprising:
3. 3. The information processing apparatus according to claim 1, further comprising a notification unit that, when the detection unit detects the loss of battery power, notifies an external device of the detection of the loss of battery power.
4. the first control unit has a nonvolatile storage area, and records the detection of the loss of battery power in the nonvolatile storage area; The second control unit determines whether the detection of the loss of battery power is recorded in the nonvolatile storage area.
3. The information processing apparatus according to claim 1, wherein the information processing apparatus is a computer.
5. The detection unit is fixed to the second case.
2. The information processing apparatus according to claim 1, wherein:
6. 3. The information processing apparatus according to claim 1, wherein the second control unit determines and controls a behavior at startup based on a preset safety guideline.
7. A computer comprising: a battery power supply connected to a first case of a housing including a first case and a second case that are detachable from each other, the battery power supply being connected to the first case via a power supply wiring inside an adapter, the battery power supply wiring being disconnected when the first case is detached from the second case, and a loss of battery power is detected when the voltage supplied from the battery power supply falls below a threshold; If the loss of battery power is detected, recording the detection of the loss of battery power; If the battery power loss detection record is found, a predetermined behavior is executed upon startup.
1. A method for protecting a device, comprising:
8. A computer comprising: a power supply wiring extending from the battery power supply, supplying main power and connecting to a communication line with another device, in a housing removably connected to the adapter, the power supply wiring connecting the battery power supply via the inside of the adapter, the power supply wiring being disconnected when the housing is removed from the adapter, and detecting loss of battery power when the voltage supplied from the battery power supply falls below a threshold; If the loss of battery power is detected, recording the detection of the loss of battery power; If the battery power loss detection record is found, a predetermined behavior is executed upon startup.
1. A method for protecting a device, comprising:
Citation Information
Patent Citations
Safety confirming device
JP1993197634A
Opening and closing detection system
JP2007065865A
Game machine and game frame
JP2017169683A
Systems And Methods For Detecting Chassis Intrusion And / Or Tampering Events In Battery-Powered Information Handling Systems
US20210225159A1