Information processing device, its control method, and program

A dual-CPU system with a hardware sequencer and notification mechanism addresses the need for low-cost tampering notifications in startup programs, eliminating the need for duplicate display hardware and ensuring user awareness during recovery.

JP7853007B2Active Publication Date: 2026-04-28CANON KK
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
CANON KK
Filing Date
2022-02-01
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing systems require additional hardware for display control to notify users of startup program tampering, leading to functional duplication and increased costs.

Method used

A dual-CPU system where a sub-CPU verifies and recovers the startup program, using a hardware sequencer to switch between CPUs and a notification mechanism with multiple patterns to inform users of tampering and recovery status via LEDs or other means.

Benefits of technology

Enables low-cost error notifications when startup program tampering is detected without the need for additional display control hardware, maintaining user awareness during recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007853007000001
    Figure 0007853007000001
  • Figure 0007853007000002
    Figure 0007853007000002
  • Figure 0007853007000003
    Figure 0007853007000003
Patent Text Reader

Abstract

To provide an information processing apparatus capable of easily giving error notice at low cost if alteration of a start program is detected, and a control method and a program therefor.SOLUTION: An information processing apparatus 100 comprises: a main CPU 101 which executes various programs; a sub-CPU 115 which performs verification on alteration of a start program of the main CPU 101 and recovery processing on the alteration; FLASH Memory 112 which stores a boot code; a hard sequencer 201 which switches one of the main CPU 101 and sub-CPU 115 selectively to allow access the FLASH Memory 112; and an LED 211 which has notice patterns of illumination and two kinds of blinking. The hard sequencer 201 changes the notice patterns of the LED 211 according to states of an alteration detection determination signal 213 and an UNDER_RECOVERY signal 207 from the sub-CPU 115.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, a control method thereof, and a program, and particularly to an information processing apparatus, a control method thereof, and a program for verifying tampering of a startup program.

Background Art

[0002] In recent years, attacks that tamper with software and exploit computers by taking advantage of software vulnerabilities have become a problem. As a countermeasure against such attacks, a method for verifying tampering of a startup program executed by a CPU mounted on an information processing apparatus is known.

[0003] Normally, the CPU itself that executes the startup program cannot verify tampering of the startup program. For this reason, a CPU different from the CPU that executes the startup program (hereinafter referred to as the main CPU) (hereinafter referred to as the sub CPU) verifies whether the startup program has been tampered with.

[0004] Furthermore, as a security standard requirement, when tampering of the startup program is detected as a result of the above verification, it is required to overwrite the correct code in a safe manner and restart. However, since it takes time to overwrite the memory capacity to overwrite and restart according to the standard requirements, it is necessary to stop the startup of the main CPU during that time. Here, in a normal system, the main CPU also has a display control function, and during the overwrite time, the information processing apparatus becomes a completely black screen. As a result, the user may not know what is happening, feel uneasy, and may inadvertently turn off / on the device.

[0005] For example, in Patent Document 1, when tampering of the startup program is detected, an error notification program is started, and an error notification is made at the operation unit.

Prior Art Documents

Patent Documents

[0006] [Patent Document 1] Japanese Patent Publication No. 2020-57040 [Overview of the Initiative] [Problems that the invention aims to solve]

[0007] However, in order to provide error notifications from the control panel, hardware for display control, such as an LCD controller, is required. In a typical system where the main CPU also has display control capabilities, this would result in a duplication of functions and increase costs.

[0008] Therefore, the present invention aims to provide an information processing device, a control method thereof, and a program that can easily and inexpensively notify users of an error when tampering with the startup program is detected. [Means for solving the problem]

[0009] To solve the above problems, the information processing apparatus according to the present invention comprises a first CPU that executes various programs, a second CPU that verifies tampering with the startup program of the first CPU and performs recovery processing of the tampering, a memory that stores at least the boot code of the startup program, a switching means that selectively switches either the first CPU or the second CPU to access the memory, and a notification means that has a plurality of notification patterns, wherein the second CPU performs tampering detection Proof, before Record recovery process , and the recovery of the aforementioned startup program notify First control signal, Second control signal , and the third control signal The output is sent to the switching means, and the switching means, Among the above multiple notification patterns, The first ~ The three Control signals combination Depending on the condition Ta Notification patterns Instruct the notification means to send the notification. It is characterized by the following. [Effects of the Invention]

[0010] According to the present invention, error notifications can be sent simply and at low cost when tampering with the startup program is detected. [Brief explanation of the drawing]

[0011] [Figure 1] This is a simplified block diagram of the information processing device according to this embodiment. [Figure 2] This is a detailed block diagram illustrating the signal processing flow between the control panel interface, main CPU, and sub-CPU in Figure 1, and the hardware sequencer connected to them. [Figure 3] This is a flowchart of the tampering verification process according to this embodiment, which is executed by the sub-CPU. [Figure 4] This is a flowchart of the tampering verification result notification process according to this embodiment, which is executed by a hardware sequencer. [Figure 5] This is a flowchart of the startup process according to this embodiment, which is executed by the main CPU. [Figure 6] This is a timing chart of each module and signal of the information processing device according to this embodiment during normal startup, i.e., when the first tampering detection result is OK. [Figure 7] This is a timing chart of each module and signal of the information processing device according to this embodiment, in a case where the first tampering detection result was NG, but the second tampering detection result after recovery processing was OK. [Figure 8] This is a timing chart of each module and signal of the information processing device 100 according to this embodiment, in the case where the first tampering detection result is NG and the second tampering detection result after recovery processing is also NG. [Modes for carrying out the invention]

[0012] Embodiments of the present invention will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the scope of the present invention as defined in the claims, and not all combinations of features described in these embodiments are necessarily essential to the solution of the present invention.

[0013] <Information Processing Apparatus> FIG. 1 is a simplified block diagram of an information processing apparatus 100 according to the present embodiment.

[0014] In FIG. 1, the information processing apparatus 100 includes a main CPU 101, a DRAM 102, an operation unit 103, a network I / F 104, a printer unit 105, a scanner unit 106, a FAX 107, an HDD 108, and a signal bus 109. The information processing apparatus 100 also includes an image processing unit 111, a FLASH Memory (registered trademark) 112, an SPI bus 114, a sub CPU 115, a power control unit 117, and a reset circuit 118.

[0015] The main CPU 101 (first CPU) is a Central Processing Unit (hereinafter simply referred to as "CPU") and controls the entire information processing apparatus 100. The DRAM 102 is a Dynamic Random Access Memory, stores various programs executed by the main CPU 101, and functions as a work area for temporary data.

[0016] The operation unit 103 is composed of a touch panel, serves as a notification unit that receives operations by a user and notifies the operation content to the main CPU 101 via an operation unit I / F 113, and also serves as a display unit for the main CPU 101 to display the device state.

[0017] The network I / F 104 is connected to a LAN 120 and communicates with external devices. The printer unit 105 prints image data on paper. The scanner unit 106 optically reads an image on paper and converts it into an electrical signal to generate a scanned image. The FAX 107 is connected to a public line 110 and performs facsimile communication with external devices.

[0018] HDD108 is a hard disk drive that stores programs executed by the main CPU101 and is also used as a spool area for print jobs, scan jobs, etc. It is also used as an area for storing and reusing scanned images. The signal bus 109 connects each module to each other for communication.

[0019] The image processing unit 111 converts print jobs received via the network interface 104 into images suitable for printing by the printer unit 105, and performs processing such as noise reduction, color space conversion, rotation, and compression on scanned images read by the scanner unit 106. It also performs image processing on scanned images stored in the HDD 108.

[0020] FLASHMemory112 (memory) stores the boot program, including the boot code executed by the main CPU 101, and also stores the default settings of the information processing unit 100. The SPI bus 114 is a bus for interconnecting the main CPU 101, FLASHMemory112, and subCPU 115. Although not shown in Figure 1, the hardware sequencer 201, which will be described later in Figure 2, is also connected to the SPI bus 114.

[0021] The sub-CPU 115 (second CPU) is a CPU that, when the information processing device 100 starts up, reads the startup program for the main CPU 101 (boot code in this embodiment) from the FLASHMemory 112 and verifies whether it has been tampered with. As a method of detecting tampering, for example, the public key information of the digital signature of the boot code is stored in the OTP (One Time Program) area of ​​the sub-CPU 115 during manufacturing, and the read boot code is decrypted with this public key information and verified. Public key cryptography is a value obtained by public key encryption of a hash value, and methods include RSA2048 and ECDSA. The sub-CPU 115 and the main CPU 101 are connected to a hardware sequencer 201 (Figure 2), which is not shown in Figure 1. If there is no problem with the result of the tampering verification, the sub-CPU 115 changes the tampering detection judgment signal 213 (Figure 2: first control signal) to "Hi" (Hi level) and sends it to the hardware sequencer 201. In this case, the hardware sequencer 201 sends a "Hi" reset signal to the reset terminal of the main CPU 101. This transmission releases the main CPU 101 from its reset state.

[0022] The power supply control unit 117 controls the power supply to each module in the information processing device 100.

[0023] When the system power is turned on, the reset circuit 118 transitions the reset signal 119, which is sent to the sub-CPU 115 after a predetermined delay, from "Lo" (Low level) to "Hi" (High level). When the reset signal 119 reaches the "Hi" level, the sub-CPU 115 is released from reset and starts up.

[0024] Figure 2 is a detailed block diagram illustrating the signal processing flow between the control interface I / F 113, the main CPU 101, the sub-CPU 115, and the hardware sequencer 201 connected to them.

[0025] Although not shown in Figure 1, the information processing device 100 further includes a hard sequencer 201, a sub-FLASH memory 205, an LED 211 located in the operation unit 103, and a ROM 212, as shown in Figure 2.

[0026] The hardware sequencer 201 (switching means) is connected to the sub-CPU 115 and the main CPU 101 in a communicative manner and has a switching function that selectively switches one of these to access the FLASHMemory 112. Specifically, the hardware sequencer 201 selects either the SPI bus 202 connected to the sub-CPU 115 or the SPI bus 203 connected to the main CPU 101 in response to the tamper detection judgment signal 213 indicating the result of tamper verification by the sub-CPU 115. Subsequently, the hardware sequencer 201 outputs the signal from the selected bus to the FLASHMemory 112 via the SPI bus 114.

[0027] The reset signal 204 is a signal transmitted from the hardware sequencer 201 to the reset terminal of the main CPU 101. In response to changes in the tamper detection judgment signal 213, it transitions from "Lo" to "Hi" to release the reset of the main CPU 101.

[0028] Sub-FLASHMemory205 is a memory module (not shown in Figure 1) that stores boot code for reading as the master memory in case FLASHMemory112 is tampered with. Sub-FLASHMemory205 is connected to the SPI bus 206, which is accessible only from sub-CPU115.

[0029] The UNDER_RECOVERY signal 207 (second control signal) is a signal that notifies the sub-CPU 115 that it is performing a recovery process, and is sent from the sub-CPU 115 to the hard sequencer 201. The recovery process is a process in which the sub-CPU 115 safely overwrites the tampered startup program (boot code in this embodiment) with the correct code and restarts the system. The details of this process will be described later in steps S310 and S311 of Figure 3.

[0030] The RECOVERY_FAIL signal 208 (third control signal) is a signal used to notify an error when recovery is not possible (even after the recovery process, verification of tampering is not successful), and is sent from the sub-CPU 115 to the hardware sequencer 201.

[0031] LED211 (notification means) is located inside the operation unit 103 and has two types of blinking as notification patterns in addition to being lit. Specifically, LED211 notifies the user that recovery processing is in progress by blinking pattern 1 (first notification pattern), and that recovery is not possible by blinking pattern 2 (second notification pattern). LED211 also notifies the user that it is functioning normally by being lit (pattern 0).

[0032] The LED control signal 209 is a signal for controlling the LED 211 located in the operation unit 103 via the operation unit I / F 113, and is transmitted from the hardware sequencer 201 to the operation unit I / F 113. The hardware sequencer 201 changes the control method of the LED 211 in the operation unit 103 according to the state of the signal received from the sub-CPU 115 to notify the tamper detection status. In other words, the LED control signal 209 changes the notification pattern of the LED 211 according to the state of the UNDER_RECOVERY signal 207, RECOVERY_FAIL signal 208, and tamper detection judgment signal 213 from the sub-CPU 115. Details of this control method will be described later using Figures 4 and 6-8.

[0033] Furthermore, the LCD control signal 210 is a signal that, after the main CPU 101 starts up, displays the device status on the LCD display of the operation unit 103 via the operation unit I / F 113.

[0034] ROM212 is a memory (not shown in Figure 1) that stores the boot software and tamper-proofing software for the sub-CPU115, and is directly connected to the sub-CPU115.

[0035] Figure 3 is a flowchart of the tampering verification process according to this embodiment, which is executed by the sub-CPU 115.

[0036] This process begins when the power switch of the information processing device 100 (not shown) is turned on.

[0037] First, in step S301, the reset signal 119 that the reset circuit 118 sends to the sub-CPU 115 is changed from "Lo" to "Hi". This change in the level of the reset signal 119 causes the sub-CPU 115 to be released from reset.

[0038] In step S302, the sub-CPU 115 reads the boot software located in ROM 212 and starts up, and then reads the tamper-proofing software stored in ROM 212.

[0039] Next, in step S303, the sub-CPU 115 reads the boot code for the main CPU 101 located in FLASHMemory 112 via the hardware sequencer 201.

[0040] In step S304, the sub-CPU 115 verifies whether the boot code read in step S303 has been tampered with, and in step S305, it determines whether the tampering verification result is OK or OK. If the tampering verification result is OK (YES in step S305), the process proceeds to step S306. On the other hand, if the tampering verification result is NG (NO in step S305), the process proceeds to step S307.

[0041] In step S306, the sub-CPU 115 changes the tamper detection judgment signal 213 that it is sending to the hardware sequencer 201 to "Hi" and terminates this process.

[0042] In step S307, the sub-CPU 115 determines whether or not it is the first time the tampering has been verified. If it is the first time the tampering has been verified (YES in step S307), the process proceeds to step S309. On the other hand, if it is not the first time the tampering has been verified (NO in step S307), the process proceeds to step S308.

[0043] In step S309, the sub-CPU 115 changes the UNDER_RECOVERY signal 207 that it is sending to the hard sequencer 201 to "Hi" to notify it that recovery processing is underway, and then proceeds to step S310.

[0044] In step S310, the sub-CPU 115 reads the master boot code for the main CPU 101 stored in the sub-FLASHMemory 205, and then proceeds to step S311.

[0045] In step S311, the sub-CPU 115 overwrites the boot code stored in FLASHMemory 112 with the master boot code read in step S310, and then returns to step S303. As a result, the sub-CPU 115 reads the master boot code for the main CPU 101 again and performs a second tampering verification in step S304. If the determination result in step S305 and the tampering verification result after the recovery process are OK, the process transitions to step S306, and the tampering detection judgment signal 213 is changed to "Hi" to terminate this process. In this case, the UNDER_RECOVERY signal 207 is also changed from "Hi" to "Lo". On the other hand, if the determination result in step S305 and the tampering verification result are not OK even after the recovery process, the process transitions from step S307 to step S308. In step S308, the sub-CPU 115 changes the RECOVERY_FAIL signal 208 sent to the hardware sequencer 201 to "Hi". As a result, the system notifies the user that recovery is not possible using the LED 211 in the control unit 103, and then terminates the process.

[0046] Figure 4 is a flowchart of the tampering verification result notification process according to this embodiment, which is executed by the hard sequencer 201.

[0047] This process begins when the power switch of the information processing device 100 (not shown) is turned on.

[0048] First, in step S401, the reset circuit 118 sends a reset signal 119 to the sub-CPU 115, and at the timing when the reset signal changes from "Lo" to "Hi", the hardware sequencer 201 is released from reset and starts up in step S402.

[0049] In step S403, the hardware sequencer 201 monitors whether either the tamper detection signal 213 or the UNDER_RECOVERY signal 207 from the sub-CPU 115 changes to "Hi". If the monitoring determines that either has changed to "Hi" (YES in step S403), the program proceeds to step S404.

[0050] In step S404, the hardware sequencer 201 determines whether the signal that changed to "Hi" in step S403 is the tamper detection judgment signal 213. If the signal that changed to "Hi" is the tamper detection judgment signal 213 (YES in step S404), the program proceeds to step S405. On the other hand, if the signal that changed to "Hi" is the UNDER_RECOVERY signal 207 (NO in step S404), the program proceeds to step S407.

[0051] In step S405, the hardware sequencer 201 switches the SPI bus connection to FLASHMemory112, where the boot code of the main CPU 101 is stored, to SPI bus 203 from the main CPU 101, and then proceeds to step S406.

[0052] In step S406, the hardware sequencer 201 transitions the reset signal 204 to the main CPU 101 from "Lo" to "Hi," and then terminates this process.

[0053] In step S407, the hardware sequencer 201 changes the LED control signal 209 to a control signal that instructs the LED 211 to blink in pattern 1, indicating that recovery processing is underway (a blinking control signal for recovery), and then proceeds to step S408.

[0054] In step S408, the hardware sequencer 201 waits again for the tampering verification result from the sub-CPU 115. That is, it monitors whether either the tampering detection judgment signal 213 or the UNDER_RECOVERY signal 207 changes to "Hi". If, as a result of this monitoring, it is determined that either has changed to "Hi" (YES in step S408), the program proceeds to step S409.

[0055] In step S409, the hardware sequencer 201 determines whether the signal that changed to "Hi" in step S408 is the tamper detection judgment signal 213. If the signal that changed to "Hi" is the tamper detection judgment signal 213 (YES in step S409), the program proceeds to step S405 and performs the processing described above. At this time, the hardware sequencer 201 returns the LED control signal 209, which was changed to a blinking control signal for recovery in step S407, to its initial control signal and terminates the notification to the user that recovery processing is underway via LED 211. On the other hand, if the signal that changed to "Hi" is the UNDER_RECOVERY signal 207 (NO in step S409), the program proceeds to step S410.

[0056] In step S410, the hardware sequencer 201 changes the LED control signal 209 to a control signal that instructs LED 211 to blink in pattern 2, indicating that recovery is not possible (a blinking control signal for recovery failure), and then terminates this process.

[0057] Figure 5 is a flowchart of the startup process according to this embodiment, which is executed by the main CPU 101.

[0058] This process begins when the reset signal 204 that the hard sequencer 201 sends to the main PU 101 in step S406 is changed from "Lo" to "Hi".

[0059] In step S501, the reset signal 204 level transition causes the main CPU 101 to be released from reset, and the process proceeds to step S502.

[0060] In step S502, the main CPU 101 reads the boot code stored in FLASHMemory112 that has passed the tampering verification test, performs various normal startup operations, and then terminates this process.

[0061] Figure 6 shows the timing charts for each module and signal of the information processing device 100 according to this embodiment, when no tampering is found as a result of the tampering verification by the sub-CPU 115 immediately after startup (i.e., the first tampering detection result was OK).

[0062] First, when the power switch of the information processing device 100 (not shown) is turned on, the reset signal 119 transmitted from the reset circuit 118 to the sub-CPU 115 transitions from "Lo" to "Hi" after a predetermined delay time, and the sub-CPU 115 is released from reset. Once the sub-CPU 115 is released from reset, it reads the startup software from the ROM 212 and starts the startup process. At this time, the hardware sequencer 201 is also released from reset. Once the hardware sequencer 201 is released from reset, it connects to the SPI buses 114 and 202, and the LED control signal 209 transmitted from the hardware sequencer 201 to the operation unit I / F 113 transitions to "Hi" level, causing the LED 211 to light up.

[0063] After the startup process, the sub-CPU 115 reads the boot code of the main CPU 101 stored in FLASHMemory 112 via SPI bus 202, hardware sequencer 201, and SPI bus 114 to verify for tampering. If no tampering is found as a result of this verification, the sub-CPU 115 changes the level of the tampering detection judgment signal 213 from "Lo" to "Hi". The hardware sequencer 201 switches the connection from SPI bus 202 to SPI bus 203 in response to the change in the tampering detection judgment signal 213 to the "Hi" level. The hardware sequencer 201 also changes the level of the reset signal 204 that it is sending to the main CPU 101 from "Lo" to "Hi". The main CPU 101 is reset in response to the change in the reset signal 204 to the "Hi" level. When the reset is released, the main CPU 101 gains access to the FLASHMemory 112 via the SPI bus 203, the hard sequencer 201, and the SPI bus 114, and reads the stored boot code to perform the startup process.

[0064] Figure 7 shows the timing charts for each module and signal of the information processing device 100 according to this embodiment, in a case where tampering was detected (the first tampering detection result was NG), but the second tampering detection result after recovery processing was OK.

[0065] The process by which the sub-CPU 115 performs the tampering verification after the startup process is the same as in Figure 6, so the explanation is omitted.

[0066] If the sub-CPU 115 finds tampering as a result of the verification, it transitions the UNDER_RECOVERY signal 207, which it sends to the hardware sequencer 201, to the "Hi" level in order to perform recovery processing. In response to the transition of the UNDER_RECOVERY signal 207 to the "Hi" level, the hardware sequencer 201 switches the LED control signal 209 to a blinking control signal for recovery and blinks the LED 211 in pattern 1. During this time, the sub-CPU 115 performs the recovery process for the tampered FLASHMemory 112, and then verifies for tampering again.

[0067] If, after the recovery process, no tampering is found during the second verification (the second tampering detection result is OK), the sub-CPU 115 changes the level of the tampering detection judgment signal 213 from "Lo" to "Hi". The hardware sequencer 201 switches the connection from SPI bus 202 to SPI bus 203 in response to the change in the tampering detection judgment signal 213 to the "Hi" level. The hardware sequencer 201 also changes the level of the reset signal 204 that it sends to the main CPU 101 from "Lo" to "Hi". Furthermore, the sub-CPU 115 changes the level of the UNDER_RECOVERY signal 207 from "Hi" to "Lo". The hardware sequencer 201 returns the LED control signal 209 to normal lighting control in response to the change in the UNDER_RECOVERY signal 207 to the "Lo" level. Subsequent operations are the same as during normal startup and are therefore omitted.

[0068] Figure 8 shows the timing chart of each module and signal of the information processing device 100 according to this embodiment, when the first tampering detection result is NG and the second tampering detection result after recovery processing is also NG.

[0069] The process by which sub-CPU 115 performs the tampering verification again after the recovery process is the same as in Figure 6, so the explanation is omitted.

[0070] If the result of the second tampering detection after the recovery process (second tampering detection result) is NG, the sub-CPU 115 changes the RECOVERY_FAIL signal 208 sent to the hardware sequencer 201 to the "Hi" level. The sub-CPU 115 also changes the UNDER_RECOVERY signal 207 sent to the hardware sequencer 201 back to the "Lo" level. In response to these signal changes, the hardware sequencer 201 switches the LED control signal 209 to the recovery NG blinking control signal and switches the LED 211 from pattern 1 to pattern 2 and blinks it.

[0071] As described above, according to this embodiment, if the sub-CPU 115 detects tampering with the startup program after the system power is turned on, the hardware sequencer 201 changes the notification pattern of the LED 211 according to the state of each signal output from the sub-CPU 115. In other words, even if the main CPU 101 does not start up and the touch panel screen of the operation unit 103 cannot be displayed, the information processing device 100 can notify the user in a simple and low-cost manner that recovery processing is in progress or that recovery is not possible.

[0072] In this embodiment, the notification pattern of the LED 211 is changed according to the current state of the information processing device 100. However, the notification device to the user is not limited to the LED 211, as long as it is a user notification device that can be controlled by the hard sequencer 201. For example, the user notification device may be a buzzer that changes the type of alarm as a notification pattern according to the current state of the information processing device 100, or a vibration generator that changes the type of vibration as a notification pattern according to the current state of the information processing device 100.

[0073] (Other embodiments) In this embodiment, the system can also be implemented by supplying a program that implements one or more functions to a computer of a system or device via a network or storage medium, and the system control unit of that system or device reads and executes the program. The system control unit has one or more processors or circuits and may include a plurality of separate system control units or a network of a plurality of separate processors or circuits in order to read and execute executable instructions.

[0074] A processor or circuit may include a central processing unit (CPU), a microprocessing unit (MPU), a graphics processing unit (GPU), an application-specific integrated circuit (ASIC), or a field-programmable gate array (FPGA). Alternatively, a processor or circuit may include a digital signal processor (DSP), a dataflow processor (DFP), or a neural processing unit (NPU).

[0075] Although preferred embodiments of the present invention have been described above, the present invention is not limited to these embodiments, and various modifications and changes are possible within the scope of its gist. [Explanation of Symbols]

[0076] 201 Hardware Sequencer 202 SPI bus 203 SPI bus 204 Reset signal 205 SubFLASHMemory 206 SPI bus 207 UNDER_RECOVERY signal 208 RECOVERY_FAIL signal 209 LED control signal 210 LCD control signals 211 LED 212 ROM

Claims

1. The first CPU that executes various programs, A second CPU performs verification of tampering with the startup program of the first CPU and recovery processing of the tampering, A memory that stores at least the boot code of the aforementioned startup program, A switching means for selectively switching one of the first CPU and the second CPU to access the memory, It comprises a notification means having multiple notification patterns, The aforementioned second CPU is The first control signal, the second control signal, and the third control signal, which notify the verification of the tampering, the recovery process, and the recovery of the startup program, are output to the switching means. The switching means is characterized by instructing the notification means to provide notification in a notification pattern corresponding to the state of the combination of the first to third control signals from among the plurality of notification patterns.

2. The information processing apparatus according to claim 1, characterized in that, after the system power is turned ON, if the second CPU detects tampering through the first tampering verification, it starts the recovery process and switches the second control signal from a Low level to a High level that indicates that the recovery process is in progress.

3. The information processing apparatus according to claim 2, characterized in that the switching means instructs the notification means to provide notification in the first notification pattern when the second control signal is switched to a high level.

4. The information processing apparatus according to claim 3, wherein if the second CPU does not detect any tampering in the second verification of tampering after the initiated recovery process, it switches the first control signal from a Low level to a Hi level that indicates there was no problem in the verification of tampering, and returns the second control signal to a Low level.

5. The information processing apparatus according to claim 4, characterized in that when the first control signal is switched to a Hi level, the switching means instructs the notification means to terminate the notification in the first notification pattern and instructs the first CPU to release the reset.

6. The information processing apparatus according to any one of claims 1 to 5, characterized in that, when the second CPU detects tampering by verifying tampering for the second time after the initiated recovery process, it returns the second control signal to a Low level and switches the third control signal from a Low level to a Hi level that indicates that the startup program cannot be recovered.

7. The information processing apparatus according to claim 6, characterized in that the switching means instructs the notification means to provide notification in the second notification pattern when the second control signal returns to a Low level and the third control signal switches to a High level.

8. The information processing apparatus according to any one of claims 1 to 7, characterized in that the notification means is an LED, and the notification pattern is a combination of illumination and two types of flashing by the LED.

9. The information processing apparatus according to any one of claims 1 to 8, characterized in that the switching means selects one of the first SPI bus connected to the second CPU and the second SPI bus connected to the first CPU, and outputs a signal from the selected SPI bus to the memory.

10. The information processing apparatus according to any one of claims 1 to 9, characterized in that the switching means lights up the notification means before the verification of the tampering by the second CPU is completed when the power supply of the information processing apparatus is turned ON and the reset is released.

11. A control method for an information processing apparatus comprising: a first CPU for executing various programs; a second CPU for verifying tampering with the startup program of the first CPU and performing recovery processing for such tampering; a memory for storing at least the boot code of the startup program; switching means for selectively switching either the first CPU or the second CPU to access the memory; and notification means having a plurality of notification patterns, A first output step in which the second CPU outputs a first control signal, a second control signal, and a third control signal that notify the verification of the tampering, the recovery process, and the recovery of the startup program to the switching means, A control method characterized by having a second output step of outputting a control signal from the switching means to the notification means that instructs the notification to be made using a notification pattern corresponding to the state of the combination of the first to third control signals among the plurality of notification patterns.

12. A computer-executable program that causes a computer to function as each step of the information processing apparatus described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • Information processing device, control method therefor, and program

    JP2020057040A

  • Information processing device and control method thereof

    JP2020087321A

  • Information processor and control method thereof

    JP2020095470A

  • Information processing apparatus, control method for the same, and program for the same

    JP2021072060A

  • Information processing device and method

    JP2021131709A