Memory Update Device, Information Processing System, Memory Update Method, and Program

JPWO2024057411A5Active Publication Date: 2025-05-27NEC CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024546566
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-09-13
Filing Date
2022-09-13
Publication Date
2025-05-27
Estimated Expiration
2042-09-13

AI Technical Summary

Technical Problem

Existing memory protection technologies using tree structures struggle with efficient node verification during memory updates, as they often perform unnecessary verification on all nodes, leading to inefficient processing and potential security risks if tampering is not detected correctly.

Method used

A memory update device and method that verifies nodes in a tree structure by determining if the updated content of a leaf node depends on the previous plaintext, generating a path from the leaf node to the root, and using message authentication codes with unique nonces to verify tags, reducing unnecessary verification and enhancing security.

Benefits of technology

This approach reduces the computational burden of verification and ensures the integrity of memory updates by only verifying nodes that require it, thereby enhancing the efficiency and security of memory protection systems.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present invention provides a memory update device with which it is possible, when updating memory content, to efficiently perform a process for verifying nodes that constitute a tree structure. An input unit (502) accepts a tree structure and update information as inputs. An update determination unit (504) determines, using the update information, whether update content of a leaf node that contains plaintext to be updated is dependent on pre-update plaintext. A memory verification unit (506) generates a path from the leaf node to a root node in the tree structure. The memory verification unit (506) verifies the tags of nodes other than the leaf node in the path if the update content of the leaf node is not dependent on the pre-update plaintext. A plaintext update unit (508) updates the plaintext in the leaf node that is to be updated, on the basis of the update information, if the verification result indicates that no falsification was detected. A tag update unit (510) generates a post-update tag if the verification result indicates that no falsification was detected.
Need to check novelty before this filing date? Find Prior Art

Description

Memory update device, information processing system, memory update method, and computer-readable medium

[0001] The present disclosure relates to a memory update device, an information processing system, a memory update method, and a computer-readable medium.

[0002] In recent years, with the increasing number of devices connected to networks, memory protection technology has become important, such as detecting tampering and concealing data stored in devices. In relation to this technology, Patent Documents 1, 2, 3, and 4 configure a tree structure in which target memories are leaf nodes for memory protection.

[0003] International Publication No. 2021 / 214922 U.S. Patent No. 7,451,310 U.S. Patent No. 9,076,019 U.S. Patent No. 4,309,569

[0004] The technology disclosed in Patent Document 4 does not allow parallel processing of hash generation in a tree structure, and therefore may not be able to perform efficient processing. In contrast, the technologies disclosed in Patent Documents 2 and 3 enable parallel processing of each node in memory content update processing. However, even though parallel processing of each node in update processing is now possible, it is desirable to perform node verification processing more efficiently in update processing.

[0005] The object of the present disclosure has been made to solve such problems, and is to provide a memory update device, an information processing system, a memory update method, and a program that are capable of efficiently performing verification processing of nodes that make up a tree structure when updating the contents of memory in a configuration that uses a tree structure for memory protection.

[0006] a memory verification means for generating a path from the leaf node to a root node in the tree structure, and for verifying whether each node has been tampered with by inputting at least a nonce unique to each node into a message authentication code to generate a tag to be used for verification and verifying the tag stored in each node, and outputting the verification result; a plaintext update means for updating the plaintext to be updated in the leaf node based on the update information if the verification result indicates that no tampering has been detected; and a tag update means for generating a post-update tag by inputting at least a nonce unique to each node into a message authentication code if the verification result indicates that no tampering has been detected. If the update content of the leaf node does not depend on the plaintext before the update, the memory verification means verifies the tags of nodes other than the leaf node in the path.

[0007] The information processing system according to the present disclosure includes a memory structure initialization device that receives plaintext for which tampering detection is desired as input and outputs at least an initial tree structure configured to protect a memory; a memory verification device that receives at least a storage location of plaintext for which tampering is desired and the tree structure as input and verifies whether or not the memory corresponding to the storage location has been tampered with; and a memory update device that receives at least a storage location of plaintext for which an update is desired and its update content and the tree structure as input and outputs the updated tree structure or an error message indicating that tampering has been detected, wherein the memory update device includes input means for inputting the tree structure and update information that is information regarding a node to be updated in the tree structure; update determination means that uses the update information to determine whether or not the update content of a leaf node including the plaintext to be updated depends on the plaintext before the update; The system comprises: memory verification means for generating a path from a leaf node to a root node, and for each node in the path, generating a tag to be used for verification by inputting at least a nonce unique to each node into a message authentication code and verifying the tag stored in each node, thereby verifying whether each node has been tampered with and outputting the verification result; plaintext update means for updating the plaintext to be updated in the leaf node based on the update information if the verification result shows that no tampering has been detected; and tag update means for generating an updated tag by inputting at least a nonce unique to each node into a message authentication code if the verification result shows that no tampering has been detected, wherein the memory verification means verifies the tags of nodes other than the leaf node in the path if the update content of the leaf node does not depend on the plaintext before the update.

[0008] The memory update method according to the present disclosure inputs a tree structure configured to protect memory and update information, which is information about a node to be updated in the tree structure; uses the update information to determine whether the update content of a leaf node containing plaintext to be updated depends on the plaintext before the update; if the update content of the leaf node does not depend on the plaintext before the update, generates a path in the tree structure from the leaf node to the root node; at each node in the path, a tag to be used for verification is generated by inputting a nonce unique to at least each node into a message authentication code, and the tag stored in a node other than the leaf node is verified to verify that each node has not been tampered with; outputs the verification result; if the verification result indicates that no tampering has been detected, updates the plaintext to be updated in the leaf node based on the update information; and if the verification result indicates that no tampering has been detected, generates an updated tag by inputting a nonce unique to at least each node into a message authentication code.

[0009] The program according to the present disclosure causes a computer to execute the following steps: inputting a tree structure configured to protect memory and update information, which is information about a node to be updated in the tree structure; determining, using the update information, whether the update content of a leaf node including plaintext to be updated depends on the plaintext before the update; if the update content of the leaf node does not depend on the plaintext before the update; generating a path from the leaf node to the root node in the tree structure, and at each node in the path, generating a tag to be used for verification by inputting at least a unique nonce at each node into a message authentication code, and verifying the tag stored in a node other than the leaf node, thereby verifying whether each node has been tampered with, and outputting the verification result; if the verification result indicates that no tampering has been detected, updating the plaintext to be updated in the leaf node based on the update information; and if the verification result indicates that no tampering has been detected, generating an updated tag by inputting at least a unique nonce at each node into a message authentication code.

[0010] According to the present disclosure, in a configuration that uses a tree structure for memory protection, it is possible to provide a memory update device, an information processing system, a memory update method, and a program that can efficiently perform verification processing of nodes that make up the tree structure when updating the contents of memory.

[0011] 1 is a block diagram showing an example of the configuration of a memory protection system. FIG. 1 is a block diagram showing an example of the configuration of a memory structure initialization device according to the first embodiment. FIG. 2 is a block diagram showing an example of the configuration of a memory verification device according to the first embodiment. FIG. 3 is a block diagram showing an example of the configuration of a memory update device according to the first embodiment. FIG. 4 is a flowchart showing an example of a processing procedure of the memory structure initialization device according to the first embodiment. FIG. 5 is a flowchart showing an example of the processing procedure of the memory verification device according to the first embodiment. FIG. 6 is a flowchart showing an example of the processing procedure of the memory update device according to the first embodiment. FIG. 7 is a flowchart showing an example of the processing procedure of the memory update device according to the first embodiment. FIG. 8 is a diagram showing an example of a tree structure configured by the memory protection system according to the first embodiment. FIG. 9 is a diagram showing an example of a path generated by a tag verification unit in the memory verification device according to the first embodiment. FIG. 10 is a diagram showing an example of a tree structure configured by the memory protection system according to the second embodiment. FIG. 11 is a diagram showing an example of a tree structure configured by the memory protection system according to the third embodiment. FIG. 12 is a block diagram showing an example of the configuration of a memory structure initialization device according to the fourth embodiment. FIG. 13 is a block diagram showing an example of the configuration of a memory verification device according to the fourth embodiment. FIG. 14 is a block diagram showing an example of the configuration of a memory update device according to the fourth embodiment. FIG. 15 is a flowchart showing an example of the processing procedure of the memory structure initialization device according to the fourth embodiment. FIG. 16 is a flowchart showing an example of the processing procedure of the memory verification device according to the fourth embodiment. FIG. 17 is a flowchart showing an example of the processing procedure of the memory update device according to the fourth embodiment. Fig. 10 is a flowchart showing an example of a processing procedure of a memory update device according to a fourth embodiment. Fig. 11 is a diagram showing an example of a tree structure configured by a memory protection system according to a fourth embodiment. Fig. 12 is a diagram showing an example of a tree structure configured by a memory protection system according to a fifth embodiment. Fig. 13 is a diagram showing an example of a tree structure configured by a memory protection system according to a sixth embodiment. Fig. 14 is a diagram showing the configuration of a memory update device according to a seventh embodiment. Fig. 15 is a flowchart showing a memory update method executed by a memory update device according to the seventh embodiment.FIG. 1 is a block diagram illustrating an example of the hardware configuration of a calculation processing device capable of realizing an apparatus and a system according to each embodiment.

[0012] (Outline of Embodiments of the Present Disclosure) Prior to describing the embodiments of the present disclosure, an outline of the embodiments of the present disclosure will be described. Note that, although the embodiments of the present disclosure will be described below, the following embodiments do not limit the invention according to the claims. Furthermore, not all combinations of features described in the embodiments are necessarily essential to the solution of the invention. Furthermore, the indexes (alphabetical letters) used in the following description are not necessarily common throughout this specification.

[0013] With the increasing number of devices connected to the network, such as IoT (Internet of Things) devices, attacks on devices can potentially lead to larger-scale attacks by using the devices as a springboard to launch attacks across the network. Therefore, memory protection technologies, such as tamper detection and confidentiality of data stored on devices, are important for maintaining the security of not only the devices themselves but also the networks connected to them.

[0014] In addition, the demand for non-volatile memory has been increasing in recent years, and memory protection technology is becoming even more important due to the increased possibility that memory is exposed to attacks even when power is cut off. Meanwhile, with the recent increase in memory capacity, memory protection technology is required to efficiently detect tampering only with the accessed portion when accessing a small portion of large data.

[0015] Furthermore, in memory protection technology, two areas are assumed in memory: on-chip and off-chip. The on-chip is a secure area. Therefore, it is impossible for an attacker to eavesdrop on or tamper with data stored on the on-chip. On the other hand, the off-chip is an insecure area. Therefore, it is possible for an attacker to eavesdrop on or tamper with data stored on the off-chip. For example, the on-chip is realized by a memory or the like within a CPU (Central Processing Unit), and the off-chip is realized by a main memory device or an auxiliary memory device. Here, since the realization cost of the on-chip is overwhelmingly greater than that of the off-chip, there is a problem of wanting to detect tampering of a portion of large-scale data with fewer on-chips.

[0016] Examples of memory protection technologies that solve this problem include technologies disclosed in Patent Documents 1, 2, and 3. As described above, in the technologies disclosed in Patent Documents 1, 2, and 3, a tree structure is constructed in which the target memory is a leaf node for memory protection. Here, elemental technologies used in constructing the tree structure include a message authentication code (MAC) and authenticated encryption (AE).

[0017] A message authentication code (MAC) is a technology that uses a secret key shared in advance between two communicating parties to calculate an authentication tag for a plaintext message to detect tampering. Applying a MAC to a communication path makes it possible to detect unauthorized tampering of a plaintext message. In memory protection technology using a tree structure, storing a secret key on-chip and storing a plaintext message and an authentication tag off-chip makes it possible to detect tampering of a plaintext message.

[0018] Authenticated encryption (AE) is a technology that encrypts plaintext messages and calculates authentication tags for tamper detection using a secret key shared in advance between two communicating parties. Applying authenticated encryption to a communication channel makes it possible to conceal the contents against eavesdropping and detect unauthorized tampering of ciphertext, resulting in strong protection of the communication contents. In memory protection technology using a tree structure, similar to MAC, the secret key is stored on-chip and the ciphertext and authentication tag are stored off-chip, making it possible to conceal the plaintext message and detect tampering.

[0019] As described above, the techniques disclosed in Patent Documents 2 and 3 enable parallelization of the processing of each node in the update process of memory contents (plaintext). However, even though parallelization of the processing of each node in the update process is possible, it is desirable to perform node verification processing more efficiently in the update process. In particular, the techniques disclosed in Patent Documents 2 and 3 are configured to perform verification processing on all nodes when performing node verification processing in the update process, even if verification processing on all nodes is not necessary depending on the update content. This may result in inefficient node verification processing when updating memory contents. In contrast, in the present embodiment, as described below, it is possible to efficiently perform node verification processing when updating memory contents.

[0020] (First embodiment) Hereinafter, an embodiment will be described with reference to the drawings. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. In addition, the same elements in each drawing are given the same reference numerals, and duplicate explanations are omitted as necessary. Note that the configuration of the first embodiment corresponds to an improved version of the configuration of Patent Document 2 mentioned above.

[0021] In the first embodiment, an example will be described in which the tree structure configured in the memory protection system has two branches and a depth of d. That is, the number of leaf nodes in the first embodiment is 2^d. The depth of the root node is defined as 0, and the depth of the leaf nodes is defined as d. In this system, it is assumed that the number of nodes and the amount of data in each node are predetermined. Here, a "node" corresponds to each element that configures the tree structure. The "root node" is the node with the shallowest depth in the tree structure. The "leaf node" is the node with the deepest depth in the tree structure.

[0022] FIG. 1 is a block diagram showing an example configuration of a memory protection system 1. The memory protection system 1 is, for example, a computer. Therefore, the memory protection system 1 functions as an information processing system. Note that the memory protection system 1 may implement each of the components shown in FIG. 1 by executing a software program on a central processing unit. Furthermore, each of the components implemented in the memory protection system 1 may be implemented as an individual device, a functional unit, or an electronic circuit. This also applies to other embodiments described below.

[0023] As shown in FIG. 1, a memory protection system 1 (information processing system) according to the first embodiment includes a memory structure initialization device 10, a memory verification device 20, and a memory update device 30. The memory structure initialization device 10, the memory verification device 20, and the memory update device 30 may be physically integrated or may be separate. Furthermore, the components of each device described below with reference to FIGS. 2 to 4 may be realized by separate devices. The memory protection system 1 detects memory tampering.

[0024] When referring to other embodiments described later, the memory structure initialization device 10 may be referred to as memory structure initialization devices 10a and 10c. Similarly, when referring to other embodiments described later, the memory verification device 20 may be referred to as memory verification devices 20a and 20c. Similarly, when referring to other embodiments described later, the memory update device 30 may be referred to as memory update devices 30a and 30c. The same applies to the components shown in Figures 2 to 4.

[0025] FIG. 2 is a block diagram showing an example of the configuration of the memory structure initialization device 10 according to the first embodiment. FIG. 3 is a block diagram showing an example of the configuration of the memory verification device 20 according to the first embodiment. FIG. 4 is a block diagram showing an example of the configuration of the memory update device 30 according to the first embodiment. FIG. 5 is a flowchart showing an example of the processing procedure of the memory structure initialization device 10 according to the first embodiment. FIG. 6 is a flowchart showing an example of the processing procedure of the memory verification device 20 according to the first embodiment. FIGS. 7 to 9 are flowcharts showing an example of the processing procedure of the memory update device 30 according to the first embodiment. FIGS. 2 to 9 will be described later.

[0026] In the memory protection system 1 according to the first embodiment, the memory structure initialization device 10 receives plaintext (plaintext message) for which tampering detection is desired as input and outputs a tree structure in an initial state. Each node in the tree structure is associated with a nonce that is unique to that node. In other words, the nonce is a value that is unique to each node. Therefore, the tree structure may include a set of nonce. This also applies to the second and third embodiments described below. The memory structure initialization device 10 can also function as a memory processing device.

[0027] Furthermore, plaintext is expressed as a combination of 2^d plaintext blocks. That is, the following formula 1 holds: (Formula 1) M = M[1] || M[2] || ... || M[2^d] Here, M represents plaintext, and M[k] represents the k-th plaintext block. Furthermore, "||" represents concatenation. Furthermore, one plaintext block is defined as Block bits.

[0028] The memory verification device 20 receives as input the storage location of plaintext (plaintext block) to be checked for tampering and a tree structure, and verifies whether the memory corresponding to that storage location has been tampered with. The memory update device 30 receives as input the storage location of the plaintext (plaintext block) to be updated, the update content, and the tree structure. The memory update device 30 then outputs the updated tree structure or an error message indicating that tampering has been detected.

[0029] Fig. 10 is a diagram showing an example of a tree structure configured by the memory protection system 1 according to the first embodiment. Fig. 10 shows a tree structure in the case where d = 3. Note that Root, Inter, and Leaf will be described later.

[0030] The memory protection system 1 also uses a message authentication code (MAC) as a fundamental technology. A MAC function MAC_K using a secret key K receives a nonce N and plaintext M as input, and outputs an authentication tag Tag. That is, the memory protection system 1 performs the calculation expressed by the following equation 2: MAC_K(N, M)=Tag (Equation 2)

[0031] Furthermore, the memory protection system 1 calculates MAC_K(N', M') for the nonce N', plaintext M', and authentication tag Tag' to be verified, and verifies whether the calculation result matches Tag'. If they match, it is determined that the nonce N' and plaintext M' have not been tampered with, and if they do not match, it is determined that they have been tampered with. In other words, the memory protection system 1 performs the calculation expressed by the following equation 3: (Equation 3) MAC_K(N', M') = Tag'' The memory protection system 1 can determine that there has been no tampering if Tag'' = Tag', and that there has been tampering if Tag'' ≠ Tag'.

[0032] [Description of the Configuration of the Memory Structure Initialization Device] Fig. 2 is a block diagram showing an example of the configuration of the memory structure initialization device 10 according to the first embodiment. As shown in Fig. 2, the memory structure initialization device 10 according to the first embodiment includes a plaintext input unit 100, a nonce assignment unit 101, and a tag generation unit 102. The memory structure initialization device 10 also includes a leaf node generation unit 103, an intermediate node generation unit 104, a root node generation unit 105, and a tree structure output unit 106.

[0033] The plaintext input unit 100 functions as a plaintext input means. The nonce assignment unit 101 functions as a nonce assignment means. The tag generation unit 102 functions as a tag generation means. The leaf node generation unit 103 functions as a leaf node generation means. The intermediate node generation unit 104 functions as an intermediate node generation means. The root node generation unit 105 functions as a root node generation means. The tree structure output unit 106 functions as a tree structure output means.

[0034] The memory structure initialization device 10 is, for example, a computer. The memory structure initialization device 10 may implement each of the components shown in FIG. 2 by executing a software program on a central processing unit. Each of the components implemented in the memory structure initialization device 10 may also be implemented as an individual device, a functional unit, or an electronic circuit. This also applies to other embodiments described below.

[0035] The plaintext input unit 100 accepts input of plaintext M to be protected. The plaintext input unit 100 outputs the accepted plaintext M to the tag generation unit 102. Here, the method by which the plaintext input unit 100 accepts input of plaintext M is not limited to a specific method. For example, the plaintext input unit 100 may be equipped with a character input device such as a keyboard and accept a user operation to input plaintext M. Alternatively, the plaintext input unit 100 may receive plaintext M from another device.

[0036] The nonce assignment unit 101 assigns node-specific nonce information to each node in the tree structure. The nonce assignment unit 101 then outputs the nonce information to the tag generation unit 102. Here, a nonce is, by its nature, uniquely determined for each node. That is, the nonce information is specific to each node. In other words, a nonce is assigned to each node so that there is no duplication throughout the entire tree structure. That is, a nonce is assigned to each node so that the nonce value assigned to each node does not overlap with nonce values ​​assigned to other nodes. By assigning nonces so that there is no duplication throughout the entire tree structure, data swapping attacks between nodes can be prevented. Furthermore, the number of nodes and the amount of data in each node are predetermined. Therefore, it is possible to assign a nonce to each node before defining the content information of each node. In other words, because the method for assigning nonce to each node is predetermined, it is possible to assign nonces to each node in parallel.

[0037] Here, when 0<=i<=d, 1<=j_i<=2^{i}, the nonce assigned to the j_ith node at depth i is represented as N(i, j_i). Note that "<=" means "≦". In other words, a<=b means "b is greater than or equal to a (or a is less than or equal to b)." The nonce information assigned to all nodes in the tree structure is written as nonce set N, as in Equation 4 below. (Equation 4) N=(N(0,1), N(1,1), N(1,2), N(2,1), N(2,2), ..., N(d,2^d-1), N(d,2^d))

[0038] Here, "N(0,1)" corresponds to the nonce of the root node. Also, "N(d,1), ..., N(d,2^d)" correspond to the nonces of multiple leaf nodes. The others correspond to the nonces of intermediate nodes. Also, the nonce set N can be included in a tree structure.

[0039] Furthermore, when a nonce is expressed as N(a, b), a indicates the depth in the tree structure of the node to which the nonce is assigned, and b indicates the order (ordinal number) of the node to which the nonce is assigned at depth a. This also applies to the notation of a tag, Tag(a, b), which will be described later.

[0040] Furthermore, in order to assign nonces so that there are no duplications throughout the entire tree structure, the nonce assignment method may be such that it satisfies, for example, the following condition A: The shallower the node in the tree structure, the smaller the nonce value assigned. For nodes at the same depth, the earlier the node is in the order at that depth (the smaller the ordinal number at that depth), the smaller the nonce value assigned. When nonces are assigned to each node under condition A as above, the nonce set shown in equation 4 becomes N(0,1)<N(1,1)<N(1<2)<N(2<1)<N(2<2)< ... <N(d<2^d-1)<N(d<2^d).

[0041] The tag generation unit 102 generates a tag for tamper detection using the plaintext M output by the plaintext input unit 100, the nonce set N output by the nonce allocation unit 101, and the secret key K. The MAC function described above is used for tag generation. First, the tag generation unit 102 generates data expressed by the following formula 5 as a tag to be used in a leaf node. (Formula 5) TagLeaf=((M[1], Tag(d,1)), (M[2], Tag(d,2)), ..., (M[2^d], Tag(d,2^d))) Tag(d,j_d)=MAC_K(N(d,j_d),M[j_d]) where 1<=j_d<=2^d

[0042] Next, the tag generation unit 102 generates data expressed by the following formula 6 as a tag to be used at the intermediate node. (Formula 6) TagInter=(Tag(1,1), ..., Tag(d-1, 2^{d-1})) Tag(i, j_i)=MAC_K((N(i, j_i), N(i+1, 2j_i-1)||N(i+1, 2j_i)) where 1<=i<=d-1, 1<=j_i<=2^i

[0043] Next, the tag generation unit 102 generates data expressed by the following formula 7 as a tag to be used in the root node: TagRoot=(Tag(0,1)) Tag(0,1)=MAC_K(N(0,1),N(1,1)∥N(1,2)) (Formula 7)

[0044] From Equations 5, 6, and 7, the tag corresponding to each node, in the case of a leaf node, corresponds to the calculation result of a MAC in which the plaintext block corresponding to the node itself is used as plaintext, and the nonce of the node and its plaintext are used as inputs. Also, in the case of a node other than a leaf node, the tag corresponding to each node corresponds to the calculation result of a MAC in which the concatenation of nonces of multiple child nodes is used as plaintext, and the nonce of the node itself and its plaintext are used as inputs.

[0045] As shown in the example of FIG. 10, when the depth d of the entire tree structure is d=3, the tag corresponding to each node is expressed by the following formula 8. Here, i is the depth index. Also, j_i is the index (order; ordinal number) of the node at depth i. (Formula 8) For 0<=i<=3, 1<=j_i<=2^i, (For 0<=i<=2) Tag(i,j_i)=MAC_K(N(i,j_i),N(i+1,2j_i-1)||N(i+1,2j_i)) (For i=3) Tag(i,j_i)=MAC_K(N(i,j_i),M[j_i])

[0046] Then, the tag generation unit 102 outputs the tag set TagLeaf to the leaf node generation unit 103. The tag generation unit 102 also outputs the tag set TagInter to the intermediate node generation unit 104. The tag generation unit 102 also outputs the tag set TagRoot to the root node generation unit 105.

[0047] The leaf node generation unit 103 generates leaf nodes in a tree structure using the tag set TagLeaf output by the tag generation unit 102. Here, since the depth i=d in the leaf nodes, 1<=j_d<=2^d holds. The j_dth leaf node is generated as shown in the following formula 9: (Formula 9) (N(d, j_d), M[j_d], Tag(d, j_d))

[0048] All leaf nodes are written as in the following formula 10. Leaf=((N(d,1), M[1], Tag(d,1)), ((N(d,2), M[2], Tag(d,2)), ..., (N(d,2^d), M[2^d], Tag(d,2^d))) (Formula 10)

[0049] 10, when the depth of the entire tree structure is d=3, each leaf node is expressed as in the following formula 11: Leaf=((N(3,1), M[1], Tag(3,1)), (N(3,2), M[2], Tag(3,2)), ..., (N(3,8), M[8], Tag(3,8))) (Formula 11)

[0050] The leaf node generating unit 103 outputs the generated leaf node set Leaf to the tree structure output unit 106.

[0051] The intermediate node generation unit 104 generates intermediate nodes in a tree structure using the tag set TagInter output by the tag generation unit 102. Here, in the intermediate nodes, 1<=i<=d-1, 1<=j_i<=2^i. Then, the j_ith intermediate node at depth i is generated as shown in the following formula 12. (Formula 12) (N(i, j_i), Tag(i, j_i))

[0052] All intermediate nodes are described as in the following formula 13. Inter=((N(1,1), Tag(1,1)), (N(1,2), Tag(1,2)), ..., (N(d-1, 2^{d-1}), Tag(d-1, 2^{d-1}))) (Formula 13)

[0053] 10, when the depth of the entire tree structure is d=3, each intermediate node is expressed as in the following formula 14: Inter=((N(1,1), Tag(1,1)), (N(1,2), Tag(1,2)), ..., (N(2,4), Tag(2,4))) (Formula 14)

[0054] The intermediate node generating unit 104 outputs the generated intermediate node set Inter to the tree structure output unit 106.

[0055] The root node generation unit 105 generates a root node of a tree structure using the tag TagRoot output by the tag generation unit 102. The root node Root is generated as shown in the following formula 15. The root node generation unit 105 outputs the generated root node Root to the tree structure output unit 106. (Formula 15) Root=(N(0,1), Tag(0,1))

[0056] The tree structure output unit 106 connects the leaf node set Leaf output by the leaf node generation unit 103, the intermediate node set Inter output by the intermediate node generation unit 104, and the root node Root output by the root node generation unit 105. The tree structure output unit 106 then outputs the connected data string as data indicating a tree structure (tree structure Tree) to a computer display, printer, or the like. As described above, the data indicating the tree structure includes data indicating the nonce set N.

[0057] [Description of the Configuration of the Memory Verification Device] Fig. 3 is a block diagram showing an example of the configuration of the memory verification device 20 according to the first embodiment. As shown in Fig. 3, the memory verification device 20 according to the first embodiment includes a tree structure input unit 200, a verification point input unit 202, a tag verification unit 203, and a verification result output unit 204.

[0058] The tree structure input unit 200 functions as a tree structure input unit. The verification point input unit 202 functions as a verification point input unit. The tag verification unit 203 functions as a tag verification unit. The verification result output unit 204 functions as a verification result output unit.

[0059] The memory verification device 20 is, for example, a computer. The memory verification device 20 may implement each of the components shown in FIG. 3 by executing a software program in a central processing unit. Each of the components implemented in the memory verification device 20 may be implemented as an individual device, a functional unit, or an electronic circuit. This also applies to other embodiments described below.

[0060] The tree structure input unit 200 accepts input of a tree structure Tree for protecting the memory to be verified. The tree structure input unit 200 then outputs the tree structure Tree to the tag verification unit 203. Here, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. The tree structure Tree may be a data string in which the leaf node set Leaf, the intermediate node set Inter, and the root node Root are linked together, which are output by the tree structure output unit 106. As described above, information on the nonce set N is included in the tree structure Tree.

[0061] The verification point input unit 202 accepts input of a verification point CheckNode in memory. Then, the verification point input unit 202 outputs the verification point CheckNode to the tag verification unit 203. Note that CheckNode is data indicating a node corresponding to the verification point in memory. Specifically, CheckNode is a numerical value between 1 and 2^d, and indicates that the verification point is the CheckNode-th leaf node. In other words, CheckNode indicates the position (order; ordinal number) of the leaf node corresponding to the verification point.

[0062] The tag verification unit 203 verifies whether the memory specified by the CheckNode has been tampered with, using the tree structure Tree, the verification location CheckNode, and the secret key K. Then, the tag verification unit 203 outputs the verification result to the verification result output unit 204. First, the tag verification unit 203 generates a path Path from the CheckNode-th leaf node to the root node. Here, the path Path is data indicating the route of nodes from the leaf node to the root node. The path Path is expressed by the following formula 16. (Formula 16) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0))

[0063] Here, when 0<=i<=d and 1<=j_i<=2^{i}, each element (i, j_i) of Path represents the j_ith node at depth i. In other words, j_i represents the ordinal number of the node at depth i. Note that when p_d=CheckNode and 0<=i<=d-1, p_i is defined by the following formula 17. (Formula 17) p_i=ceiling(p_{i+1} / 2) where ceiling(·) represents the ceiling function. Also, the value of p_0 is always 1.

[0064] 11 is a diagram showing an example of a path generated by the tag verification unit 203 in the memory verification device 20 according to the first embodiment. For example, when d=4 and CheckNode=10, as shown in FIG. 11, the path is as follows: Path=((4,10), (3,5), (2,3), (1,2), (0,1))

[0065] Next, the tag verification unit 203 calculates the following formula 18 using the tree structure Tree output from the tree structure input unit 200 and the secret key K. (Formula 18) PathTag'=(Tag'(d, p_d), Tag'(d-1, p_{d-1}), ..., Tag'(0, p_0)) Tag'(d, p_d)=MAC_K(N(d, p_d), M[p_d]) Tag'(i, p_i)=MAC_K(N(i, p_i), N(i+1, 2p_i-1)||N(i+1, 2p_i)) where 0<=i<=d-1

[0066] Here, MAC_K is substantially the same as the method used in the tag generation unit 102 of the memory structure initialization device 10 in the first embodiment, and therefore a description thereof will be omitted. Tag'(i, p_i) is obtained by inputting the nonce of the node in question into the nonce portion of the input of the MAC function, and inputting the concatenated two nonces of the child nodes of the node in question into the plaintext portion of the input of the MAC function.

[0067] Next, the tag verifying unit 203 obtains a value expressed by the following formula 19 from the tree structure Tree that is the output of the tree structure input unit 200. PathTag=(Tag(d, p_d), Tag(d−1, p_{d−1}), ..., Tag(0, p_0)) (Formula 19)

[0068] Then, the tag verification unit 203 checks whether the PathTag' calculated by itself is equal to the PathTag acquired from the tree. When 0<=i<=d, if Tag'(i, p_i)=Tag(i, p_i) holds for all i, the tag verification unit 203 sets the verification result to ACK. Here, ACK indicates that the information of the nodes related to the path has not been tampered with. Furthermore, the verification result is represented as B, and the fact that the verification result is ACK is represented as B=ACK.

[0069] On the other hand, when 0<=i<=d, if Tag'(i,p_i)≠Tag(i,p_i) holds for a certain i, the tag verification unit 203 sets the verification result to NCK. Here, NCK indicates that information on a node related to the path has been tampered with. In addition, the fact that the verification result is NCK is expressed as B=NCK.

[0070] The tag verification unit 203 outputs the verification result B to the verification result output unit 204. The verification result output unit 204 outputs the verification result B output by the tag verification unit 203 to a computer display, a printer, or the like.

[0071] [Description of the Configuration of the Memory Update Device] Fig. 4 is a block diagram showing an example of the configuration of the memory update device 30 according to the first embodiment. As shown in Fig. 4, the memory update device 30 according to the first embodiment includes a tree structure input unit 300, an update location input unit 302, a memory verification unit 303, a nonce update unit 304, a tag update unit 305, and an update result output unit 306. The memory update device 30 according to the first embodiment also includes an update determination unit 310 and a plaintext update unit 312.

[0072] The tree structure input unit 300 functions as a tree structure input means. The update location input unit 302 functions as an update location input means. The memory verification unit 303 functions as a memory verification means. The nonce update unit 304 functions as a nonce update means. The tag update unit 305 functions as a tag update means. The update result output unit 306 functions as an update result output means. The update determination unit 310 functions as an update determination means. The plaintext update unit 312 functions as a plaintext update means.

[0073] The memory update device 30 is, for example, a computer. Note that the memory update device 30 may implement each of the components shown in FIG. 4 by executing a software program in a central processing unit. Furthermore, each of the components implemented in the memory update device 30 may be implemented as an individual device, a functional unit, or an electronic circuit. This also applies to the other embodiments described below.

[0074] The tree structure input unit 300 accepts input of a tree structure Tree for protecting the memory to be updated. Then, as indicated by the dashed-dotted lines in FIG. 4 , the tree structure input unit 300 outputs the tree structure Tree to the memory verification unit 303 and the nonce update unit 304. The tree structure input unit 300 may also output the tree structure Tree to the plaintext update unit 312. Here, as described above, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. Note that the function of the tree structure input unit 300 is substantially the same as the function of the tree structure input unit 200 in the memory verification device 20 according to the first embodiment, and therefore a description thereof will be omitted.

[0075] The update location input unit 302 accepts input of memory update information UpdateNode. Then, as indicated by the dotted lines in FIG. 4 , the update location input unit 302 outputs the memory update information UpdateNode to the update determination unit 310, the plaintext update unit 312, the memory verification unit 303, and the tag update unit 305. Here, the memory update information UpdateNode is information about a node to be updated in the tree structure. UpdateNode includes data indicating the node to be updated (node ​​position) and data indicating the update content of the plaintext related to the node to be updated. In other words, UpdateNode includes data indicating the node to be updated (update location) and data indicating the update content of the leaf node including the plaintext to be updated.

[0076] Here, UpdateNode = (UpdateIndex, UpdateInfo). UpdateIndex is data indicating the leaf node corresponding to the update location. For example, the update location UpdateIndex is a numerical value between 1 and 2^d, indicating that the update location is the UpdateIndex-th leaf node. In other words, UpdateIndex indicates the order (ordinal number) of the leaf node corresponding to the update location at depth d.

[0077] UpdateInfo is data indicating the update content. UpdateInfo represents Block bit information for updating the plaintext block M[UpdateIndex], which is information included in the UpdateIndex-th leaf node. The plaintext block M[UpdateIndex] can be updated according to the update content UpdateInfo.

[0078] The update determination unit 310 uses the update information UpdateNode to determine whether the update content of the leaf node including the plaintext to be updated depends on the plaintext before the update. Specifically, the update determination unit 310 determines the update content of the plaintext block M[UpdateIndex] included in the leaf node indicated by the update location UpdateIndex based on the update content UpdateInfo. The update determination unit 310 then determines whether the update content UpdateInfo indicates that the plaintext (plaintext block) will be updated using the plaintext before the update. If the update content UpdateInfo indicates that the plaintext (plaintext block) will be updated using the plaintext before the update, the update determination unit 310 determines that the update content of the leaf node including the plaintext (plaintext block) to be updated depends on the plaintext before the update. On the other hand, if the update content UpdateInfo indicates that the plaintext (plaintext block) is updated without using the plaintext before the update, the update determination unit 310 determines that the update content of the leaf node containing the plaintext (plaintext block) to be updated does not depend on the plaintext before the update.

[0079] Here, the value of the plaintext block before the update is assumed to be x, and the value of the plaintext block after the update is assumed to be x'. In this case, if x' depends on x, the update determination unit 310 determines that the update content of the leaf node including the plaintext to be updated depends on the plaintext before the update. For example, if the update content UpdateInfo indicates x' = x + 1, x' depends on x. Also, for example, if the update content UpdateInfo indicates x' = 2 * x, x' depends on x. In these cases, the plaintext block is updated using the plaintext block before the update. Therefore, in this case, the update determination unit 310 determines that the update content of the leaf node including the plaintext to be updated depends on the plaintext before the update.

[0080] Furthermore, the value of the plaintext block before the update of the j1_d-th leaf node j1_d is set to x1, and the value of the plaintext block before the update of the j2_d-th leaf node j2_d is set to x2. The value of the plaintext block after the update of the leaf node j1_d is set to x1'. In this case, if the update content UpdateInfo indicates x1' = x1 + x2, x1' depends on the plaintext before the update. In other words, the plaintext is updated using the plaintext before the update. Therefore, in this case, the update determination unit 310 determines that the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update.

[0081] On the other hand, if c is a fixed value and the update content indicates x' = c, x' does not depend on the plaintext (plaintext block) before the update. In other words, the fixed value c used for the update is independent of the plaintext before the update. In this case, the plaintext block is updated without using the plaintext block before the update. Therefore, in this case, the update determination unit 310 determines that the update content of the leaf node containing the plaintext to be updated does not depend on the plaintext before the update. In other words, when determining whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update, the update determination unit 310 may determine whether the plaintext to be updated is replaced with a fixed value independent of the plaintext. Note that the fixed value c may correspond to the value of a plaintext block that was updated at a previous timing for a leaf node different from the leaf node to be updated. However, if the plaintext block x before the update is expressed as x = x1 + x2 and the update content indicates x' = c + x2, only a part of the plaintext block (x1) is replaced with a fixed value, and therefore the update content depends on the plaintext before the update (x2, which is part of the plaintext block). Therefore, in this case, the update determination unit 310 determines that the update content of the leaf node containing the plain text to be updated depends on the plain text before the update.

[0082] The fixed value used for the update may be included in the update content UpdateInfo. That is, the fixed value used for the update may be included in the update information UpdateNode. The fixed value in the update information UpdateNode may also be specified by the user. This allows the user to easily specify the update content of the plaintext (plaintext block). Furthermore, when the fixed value used for the update is included in the update information UpdateNode, the update determination unit 310 may determine that the update content of the leaf node including the plaintext (plaintext block) to be updated does not depend on the plaintext before the update.

[0083] Alternatively, the fixed value used for the update may not be included in the update content UpdateInfo. For example, the fixed value used for the update may be stored in advance in a storage device of the memory update device 30. In this case, the update content UpdateInfo may indicate the location (address) of the storage device where the fixed value is stored. In addition, in this case, the fixed value used for the update may be stored in an on-chip area (secure area) of the memory.

[0084] The memory verification unit 303 verifies whether the memory specified by UpdateNode has been tampered with, using the tree structure Tree, memory update information UpdateNode, and a private key K. That is, the memory verification unit 303 verifies whether the node corresponding to the path related to the leaf node specified by UpdateNode has been tampered with. The processing performed by the memory verification unit 303 is substantially the same as the processing performed by the tag verification unit 203 in the memory verification device 20 of the first embodiment, but the output results are different. The tag verification unit 203 in the memory verification device 20 of the first embodiment outputs a verification result B, but the memory verification unit 303 also outputs a path Path from the node to the root node along with the verification result B.

[0085] 4, the memory verification unit 303 outputs the verification result B to the nonce update unit 304, the tag update unit 305, and the update result output unit 306. The memory verification unit 303 may also output the verification result B to the plaintext update unit 312. The memory verification unit 303 also outputs the path Path to the nonce update unit 304 and the tag update unit 305, as shown by the thick solid line in FIG.

[0086] Path is expressed as in the following formula 20. (Formula 20) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0)) Here, from the operation performed by the memory verification unit 303, it can be seen that p_d=UpdateIndex.

[0087] That is, the memory verification unit 303 generates a path Path from a leaf node to a root node in a tree structure. Furthermore, for each node in the path Path, the memory verification unit 303 generates (calculates) a tag used for verification by inputting at least a nonce unique to each node into a message authentication code (MAC) and verifies the tag stored in each node. That is, the memory verification unit 303 generates a tag Tag' for each node in the path Path by calculating the above-described formula 18. For each node, the memory verification unit 303 compares the generated tag Tag' with the stored tag Tag (a tag related to the tree) and determines whether they match. In this way, the memory verification unit 303 verifies whether each node has been tampered with. That is, the memory verification unit 303 performs integrity verification for each node. Then, the memory verification unit 303 outputs a verification result B.

[0088] Here, the memory verification unit 303 according to the first embodiment may not verify the tag of the leaf node depending on the determination result of the update determination unit 310. Specifically, if the update content of the leaf node does not depend on the plain text before the update, the memory verification unit 303 verifies the tags of nodes other than the leaf node in the path Path. On the other hand, if the update content of the leaf node depends on the plain text before the update, the memory verification unit 303 verifies the tags of all nodes including the leaf node in the path Path.

[0089] When the verification result B indicates that no tampering has been detected, the plaintext updating unit 312 updates the plaintext to be updated in the leaf node based on the update information UpdateNode. Specifically, the plaintext updating unit 312 updates the plaintext block M[UpdateIndex] in accordance with the update content UpdateInfo. For example, when the update content UpdateInfo includes a fixed value used for the update, the plaintext updating unit 312 updates the plaintext block M[UpdateIndex] by replacing the value of the plaintext block M[UpdateIndex] with the fixed value. Furthermore, when the update content UpdateInfo indicates the above-mentioned x' = x + 1, the plaintext updating unit 312 updates the plaintext block M[UpdateIndex] from the value x before the update to x' = x + 1. The plaintext update unit 312 outputs information (UpdateNode) relating to the updated plaintext (plaintext block) to the tag update unit 305 .

[0090] The nonce updating unit 304 updates the nonce for each node related to the Path every time an update process is performed on a leaf node (plaintext block) related to that Path. This makes it possible to prevent replay attacks. The nonce updating unit 304 updates the nonce of the node specified by the Path using the tree structure Tree, the verification result B, and the path Path. Specifically, if B=ACK, the nonce updating unit 304 updates the nonce of the node specified by the Path. Then, the nonce updating unit 304 outputs the new tree structure NewTree' as the update result to the tag updating unit 305. On the other hand, if B=NCK, the nonce updating unit 304 does not perform any process and does not output anything.

[0091] Here, the method for updating the nonce assigned to each node is predetermined. For example, when a nonce is assigned to each node as per the above-mentioned condition A, the nonce value N(0, 1) of the root node may be updated by adding 1 to N(d, 2^d), which is the largest nonce value before the update. Then, the nonce value may be updated for each node in the Path so as to satisfy the above-mentioned condition A. This allows the nonce of each node to be updated even if the update process for the plaintext block included in the root node in the Path has not yet finished, and therefore allows the nonce to be updated for each node in parallel.

[0092] The tag update unit 305 updates the tag of the node specified by Path using the tree structure NewTree' of the update result, the nonce set N, the update information UpdateNode in the memory, the verification result B, the path Path, and the private key K. If B=ACK, the tag update unit 305 performs the calculation of the following equation 21 for 0<=i<=d-1. (Equation 21) Tag(d, p_d)←MAC_K(N(d, p_d), UpdateInfo) Tag(i, p_i)←MAC_K(N(i, p_i), N(i+1, 2p_i-1)||N(i+1, 2p_i))

[0093] Note that (d, p_d) indicates the leaf node to be updated, and p_d indicates the order (ordinal number) of the leaf node to be updated at depth d. Also, "UpdateInfo" indicates the plaintext block after the update in the leaf node to be updated. Note that MAC_K is the same as the method used in the tag generation unit 102 of the memory structure initialization device 10 and the tag verification unit 203 of the memory verification device 20 in the first embodiment. Also, Tag(i, p_i) is obtained by inputting the updated nonce of the node in question into the nonce portion of the input of the MAC function, and inputting the concatenated two updated nonces of the child nodes of the node in question into the plaintext portion of the input of the MAC function.

[0094] Then, the tag update unit 305 outputs the tree structure NewTree resulting from the update to the update result output unit 306. The new tree structure NewTree is composed of an updated leaf node set Leaf, an updated intermediate node set Inter, and an updated root node Root. Note that, as shown in Equation 11, the updated plaintext information is included in the updated leaf node set Leaf. On the other hand, if B=NCK, the tag update unit 305 does not perform any processing and does not output anything.

[0095] The update result output unit 306 outputs the update result using the verification result B output by the memory verification unit 303 and the tree structure NewTree output by the tag update unit 305. If B=ACK, the update result output unit 306 outputs NewTree to a computer display, a printer, or the like. Note that the update result output unit 306 may output UpdateNode separately from NewTree. On the other hand, if B=NCK, the update result output unit 306 outputs the verification result B=NCK to a computer display, a printer, or the like.

[0096] 5 is a flowchart showing the operation (memory structure initialization method) of the memory structure initialization device 10. In step S101, the plaintext input unit 100 accepts input of plaintext M to be protected. In step S102, the nonce assignment unit 101 assigns a nonce to each node in the tree structure to generate a nonce set N. In step S103, the tag generation unit 102 uses the plaintext M and the nonce set N to generate a tag set (TagLeaf, TagInter, TagRoot) for tamper detection.

[0097] In step S104, the leaf node generation unit 103 generates a leaf node set Leaf of a tree structure using the tag set TagLeaf output by the tag generation unit 102. In step S105, the intermediate node generation unit 104 generates an intermediate node set Inter of a tree structure using the tag set TagInter output by the tag generation unit 102. In step S106, the root node generation unit 105 generates a root node Root of a tree structure using the tag TagRoot output by the tag generation unit 102.

[0098] In step S107, the tree structure output unit 106 connects the leaf node set Leaf, the intermediate node set Inter, and the root node Root, and outputs the connected data string indicating the tree structure to a computer display, a printer, etc. After step S107, the memory structure initialization device 10 ends the processing of FIG.

[0099] 6 is a flowchart showing the operation (memory verification method) of the memory verification device 20. In step S201, the tree structure input unit 200 accepts input of a tree structure Tree for protecting the memory to be verified. As described above, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. As described above, the tree structure Tree also includes a nonce set N assigned to the tree structure for protecting the memory to be verified. Furthermore, the verification point input unit 202 accepts input of a verification point CheckNode of the memory.

[0100] In step S202, the tag verification unit 203 verifies the tag of each node using the tree structure Tree and the verification location CheckNode. This allows the tag verification unit 203 to verify whether the memory specified by CheckNode has been tampered with. Furthermore, the tag verification unit 203 determines acceptance (ACK) or non-acceptance (NCK) and outputs verification result B. In step S203, the verification result output unit 204 outputs verification result B to a computer display, printer, or the like. After step S203, the memory verification device 20 ends the processing of FIG. 6.

[0101] 7 to 9 are flowcharts showing the operation (memory update method) of the memory update device 30. In step S300, the tree structure input unit 300 accepts input of a tree structure Tree for protecting the memory to be updated. As described above, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. The tree structure Tree also includes a nonce set N. Also in step S300, the update location input unit 302 accepts input of memory update information UpdateNode. As described above, the update information UpdateNode is defined as UpdateNode = (UpdateIndex, UpdateInfo).

[0102] In step S301, the update determination unit 310 determines whether the update content UpdateInfo of the update information UpdateNode replaces the plaintext block corresponding to the update location UpdateIndex with a fixed value. At this time, the update determination unit 310 may determine whether the update content UpdateInfo of the update information UpdateNode includes a fixed value. If the update content UpdateInfo of the update information UpdateNode replaces the plaintext block with a fixed value (if the determination result in S301 is YES), the processing proceeds to step S302. On the other hand, if the update content UpdateInfo of the update information UpdateNode does not replace the plaintext block with a fixed value (if the determination result in S301 is NO), the processing proceeds to step S312.

[0103] As shown in FIG. 8 , in step S302, the memory verification unit 303 verifies the tags of nodes other than leaf nodes using the tree structure Tree and memory update information UpdateNode. This allows the memory verification unit 303 to verify whether each node has been tampered with. Furthermore, the memory verification unit 303 determines acceptance (ACK) or rejection (NCK) and outputs a verification result B. The memory verification unit 303 then outputs the verification result B and the path Path used for memory verification. If B=ACK, i.e., memory tampering is not detected (S302: B=ACK (accepted)), processing proceeds to step S304. On the other hand, if B=NCK, i.e., memory tampering is detected (S302: B=NCK (rejected)), processing proceeds to step S303.

[0104] In step S303, the update result output unit 306 outputs the verification result B output by the memory verification unit 303 to a computer display, a printer, etc. After step S303, the memory update device 30 ends the process.

[0105] In step S304, the nonce updating unit 304 updates the nonce of the node specified by Path, using the tree structure Tree output by the tree structure input unit 300 and the path Path output by the memory verification unit 303. Then, the nonce updating unit 304 outputs a new tree structure NewTree' as a result of the update.

[0106] In step S305, the plaintext of the leaf node and the tag corresponding to the path Path are updated using the tree structure NewTree', the path Path, and the update information UpdateNode in the memory. Specifically, the plaintext update unit 312 updates the plaintext (plaintext block) of the leaf node indicated by the update information UpdateNode. The tag update unit 305 also updates the tag of the node indicated by Path. The tag update unit 305 then outputs the new tree structure NewTree as a result of the update.

[0107] In step S306, the update result output unit 306 outputs the tree structure NewTree output by the tag update unit 305. After step S306, the memory update device 30 ends the process.

[0108] On the other hand, as shown in FIG. 9 , in step S312, the memory verification unit 303 uses the tree structure Tree and memory update information UpdateNode to verify the tags of all nodes on the path related to the leaf node specified by UpdateNode. As a result, the memory verification unit 303 verifies whether each node has been tampered with. Furthermore, the memory verification unit 303 determines acceptance (ACK) or rejection (NCK) and outputs verification result B. The memory verification unit 303 then outputs verification result B and the path Path used for memory verification. If B=ACK, i.e., memory tampering is not detected (S312: B=ACK (accepted)), processing proceeds to step S314. On the other hand, if B=NCK, i.e., memory tampering is detected (S312: B=NCK (rejected)), processing proceeds to step S313.

[0109] As in S303, in step S313, the update result output unit 306 outputs the verification result B output by the memory verification unit 303 to a computer display, a printer, etc. After step S313, the memory update device 30 ends the process.

[0110] As in S304, in step S314, the nonce updating unit 304 updates the nonce of the node specified by Path, using Tree output by the tree structure input unit 300 and Path output by the memory verification unit 303. Then, the nonce updating unit 304 outputs a new tree structure NewTree' as a result of the update.

[0111] As in S305, in step S315, the plaintext of the leaf node and the tag corresponding to the path Path are updated using the tree structure NewTree', the path Path, and the update information UpdateNode stored in the memory. Specifically, the plaintext update unit 312 updates the plaintext (plaintext block) of the leaf node indicated by the update information UpdateNode. The tag update unit 305 also updates the tag of the node indicated by Path. The tag update unit 305 then outputs the new tree structure NewTree resulting from the update.

[0112] In the same manner as in S306, in step S316, the update result output unit 306 outputs the tree structure NewTree output by the tag update unit 305. After step S316, the memory update device 30 ends the process.

[0113] [Description of Effects] When updating plaintext corresponding to a leaf node, the memory update device 30 according to the first embodiment uses update information to determine whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update. Then, when the update content of the leaf node does not depend on the plaintext before the update, the memory update device 30 verifies the tags of nodes other than the leaf node on the path from the leaf node to the root node. Here, in the technology disclosed in Patent Document 2, verification is performed for all nodes on the path regardless of the update content. Therefore, with the above configuration, the amount of calculation required for verification can be reduced compared to the technology disclosed in Patent Document 2. Therefore, when updating memory contents, node verification can be performed efficiently.

[0114] Here, when the contents of the memory are updated, there is a possibility that the tree structure is tampered with. Therefore, when the memory is updated, there is a possibility that the plaintext contained in the leaf node before the update is tampered with. Therefore, if the update content of the leaf node depends on the plaintext before the update, there is a possibility that the plaintext will be updated using the tampered plaintext before the update, which may compromise the security of the memory. Therefore, it is necessary to verify the tags of all nodes including the leaf node in the path Path. On the other hand, if the update content of the leaf node does not depend on the plaintext before the update, such as when the plaintext to be updated is replaced with a fixed value, even if the plaintext contained in the leaf node before the update is tampered with, the plaintext will be updated to data that is not based on the tampered plaintext. Therefore, the security of the memory is not compromised.

[0115] Furthermore, the tag of a leaf node is generated based on the plaintext and nonce of the leaf node, as shown in Equation 5. Therefore, the tag of a leaf node is generated validly if the plaintext and nonce of the leaf node are valid. As for the plaintext, as described above, it is valid if the updated content of the leaf node does not depend on the plaintext before the update.

[0116] Even if a nonce is tampered with, the tampering can be detected by verification at the node above it (such as a parent node). Assume that an attacker performs a replay attack on the tree structure shown in FIG. 10 . Suppose the attacker tampers with the nonce value N(3,1) of the leaf node (N(3,1), M[1], Tag(3,1)) to create a different value N(3,1)'. In this case, the attacker must also tamper with Tag(2,1) and N(2,1) of the parent node to create Tag(2,1)' and N(2,1)'. Otherwise, the security of the MAC will allow the tampering to be detected during integrity verification of the MAC at the node (N(2,1), Tag(2,1)). Note that Tag(2,1)'=MAC_K(N(2,1)', N(3,1)'∥N(3,2)).

[0117] Here, assume that the attacker knows Tag(2,1)' and N(2,1)' in advance. In other words, assume that N(3,1)' < N(3,1) and N(2,1)' < N(2,1), and that MAC_K(N(2,1)', N(3,1)' || N(3,2)) is known to the attacker in advance. In this case, the attacker can correctly forge Tag(2,1)' and N(2,1)' by rollback. Such tampering cannot be detected by integrity verification using MAC. Then, the attacker similarly tampers with the tag and nonce of node (N(1,1), Tag(1,1)), which is the parent node of node (N(2,1), Tag(2,1)), to make them Tag(1,1)' and N(1,1)', respectively. Such tampering cannot be detected by MAC-based integrity verification.

[0118] On the other hand, if an attacker tampers with N(1,1) to make it N(1,1)', he must also tamper with Tag(0,1) and N(0,1) of the root node (N(0,1), Tag(0,1)). If he does not do so, the tampering will be detected during MAC integrity verification at the root node due to the security of the MAC. Therefore, the attacker must tamper with Tag(0,1) and N(0,1) to make them Tag(0,1)' and N(0,1)'. Note that Tag(0,1)' = MAC_K(N(0,1)', N(1,1)'||N(1,2)). However, N(0,1) is stored on-chip, which is a secure area. Therefore, it is impossible to tamper with N(0,1). Therefore, even if tampering is not detected at node (N(1,1), Tag(1,1)), tampering will always be detected at the root node. Therefore, if the update content of a leaf node does not depend on the plaintext before the update, even if the nonce of the leaf node is tampered with, the tampering will be detected by verification at a higher node. Therefore, if the update content of a leaf node does not depend on the plaintext before the update, security will not be compromised even if verification of the tag for the leaf node is not required.

[0119] Furthermore, assuming that the amount of calculation required for verification is the same for all nodes, in the case of a tree structure of depth d, the amount of calculation required for memory verification processing in the memory update device 30 according to this embodiment is (d-1) / d times the amount of calculation required for the technology disclosed in Patent Document 2. If the cost of verification processing for leaf nodes is greater than the cost of verification processing for other nodes, the effect of reducing the amount of calculation achieved by the method according to this embodiment is even greater. Furthermore, the depth d is typically a single-digit integer, which is relatively small. Here, the smaller d is, the smaller (d-1) / d becomes. Therefore, the effect of reducing the amount of calculation achieved by the method according to this embodiment is relatively large.

[0120] (Second Embodiment) Next, a second embodiment will be described. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. Furthermore, in each drawing, the same elements are given the same reference numerals, and duplicate explanations are omitted as necessary. Therefore, the following description will mainly focus on differences from the first embodiment described above. The configuration of the second embodiment corresponds to an improvement of the configuration of Patent Document 2 described above. Furthermore, the second embodiment differs from the first embodiment in the number of branches in the tree structure. In the second embodiment, an example will be described in which the number of branches in the tree structure configured by the memory protection system is b and the depth is d. In other words, the number of leaf nodes in the second embodiment is b^d.

[0121] 12 is a diagram showing an example of a tree structure configured by the memory protection system 1 according to the second embodiment. Fig. 12 shows a tree structure in which the number of branches b=3 and the depth d=3. Note that the Root, Inter, and Leaf are substantially the same as those in the first embodiment. Furthermore, in the second embodiment, the number of branches b can be any integer equal to or greater than 3.

[0122] The memory protection system 1 according to the second embodiment includes a memory structure initialization device 10a, a memory verification device 20a, and a memory update device 30a. The memory structure initialization device 10a according to the second embodiment receives plaintext (plaintext message) for which tampering detection is desired as input and outputs an initial tree structure.

[0123] In the second embodiment, a plaintext is represented by a combination of b^d plaintext blocks. That is, the following formula 22 holds: M=M[1]||M[2]||...||M[b^d] (Formula 22) Furthermore, one plaintext block is defined as Block bits.

[0124] The memory verification device 20a receives as input the storage location of a plaintext block to be checked for tampering and a tree structure, and verifies whether the memory corresponding to that storage location has been tampered with. The memory update device 30a receives as input the storage location of the plaintext block to be updated, the update content, and the tree structure. The memory update device 30a outputs the updated tree structure or an error message indicating that tampering has been detected.

[0125] [Description of the Configuration of the Memory Structure Initialization Device] The memory structure initialization device 10a according to the second embodiment includes a plaintext input unit 100, a nonce assignment unit 101a, and a tag generation unit 102a. The memory structure initialization device 10a according to the second embodiment also includes a leaf node generation unit 103a, an intermediate node generation unit 104a, a root node generation unit 105, and a tree structure output unit 106. The plaintext input unit 100 is substantially the same as the plaintext input unit 100 in the memory structure initialization device 10 according to the first embodiment, and therefore a description thereof will be omitted.

[0126] The nonce allocation unit 101a, like the nonce allocation unit 101, allocates node-specific nonce information to each node in the tree structure. Here, when 0<=i<=d, 1<=j_i<=b^{i}, the nonce allocated to the j_ith node at depth i is represented as N(i, j_i). The nonce information allocated to all nodes in the tree structure is written as a nonce set N, as shown in the following formula 23. (Formula 23) N=(N(0,1), N(1,1), N(1,2), ..., N(1,b), N(2,1), N(2,2), ..., N(d,b^d-1), N(d,b^d))

[0127] Similar to the tag generation unit 102, the tag generation unit 102a generates a tag for tamper detection using the plaintext M output by the plaintext input unit 100, the nonce set N output by the nonce assignment unit 101a, and the secret key K. First, the tag generation unit 102a generates data expressed by the following formula 24 as a tag to be used in a leaf node. (Formula 24) TagLeaf=((M[1], Tag(d,1)), (M[2], Tag(d,2)), ..., (M[b^d], Tag(d,b^d))) Tag(d,j_d)=MAC_K(N(d,j_d),M[j_d]) where 1<=j_d<=b^d

[0128] Next, the tag generation unit 102a generates data expressed by the following formula 25 as a tag to be used in the intermediate node. (Formula 25) TagInter=(Tag(1,1), ..., Tag(d-1,b^{d-1})) Tag(i, j_i)=MAC_K((N(i, j_i), N(i+1, b.j_i-(b-1))...||N(i+1, b.j_i)) where 1<=i<=d-1, 1<=j_i<=b^i Also, "N(i+1, b.j_i-(b-1))...||N(i+1, b.j_i)" is a concatenation of the nonces of b child nodes of node (i, j_i).

[0129] Next, the tag generation unit 102a generates data expressed by the following formula 26 as a tag to be used in the root node. (Formula 26) TagRoot=(Tag(0,1)) Tag(0,1)=MAC_K(N(0,1),N(1,1)∥ ... ∥N(1,b)) Note that "N(1,1)∥ ... ∥N(1,b)" represents the concatenation of the nonces of b child nodes of the root node (0,1).

[0130] From Equations 24, 25, and 26, the tag corresponding to each node, in the case of a leaf node, corresponds to the calculation result of a MAC in which the plaintext block corresponding to the node itself is used as plaintext, and the nonce of the node and its plaintext are used as inputs. Also, in the case of a node other than a leaf node, the tag corresponding to each node corresponds to the calculation result of a MAC in which the concatenation of nonces of multiple child nodes is used as plaintext, and the nonce of the node itself and its plaintext are used as inputs.

[0131] As shown in the example of FIG. 12, when the depth d of the entire tree structure is d=3 and the number of branches b is b=3, the tag corresponding to each node is expressed by the following formula 27. Here, i is the depth index. Also, j_i is the index (order; ordinal number) of the node at depth i. (Formula 27) For 0<=i<=3, 1<=j_i<=3^i, (For 0<=i<=2) Tag(i,j_i)=MAC_K(N(i,j_i),N(i+1,3j_i-2)||N(i+1,3j_i-1)||N(i+1,3j_i)) (For i=3) Tag(i,j_i)=MAC_K(N(i,j_i),M[j_i])

[0132] The tag generation unit 102a then outputs the tag set TagLeaf to the leaf node generation unit 103a, the tag set TagInter to the intermediate node generation unit 104a, and the tag set TagRoot to the root node generation unit 105.

[0133] The leaf node generation unit 103a, like the leaf node generation unit 103, generates leaf nodes in a tree structure using the tag set TagLeaf output by the tag generation unit 102a. Here, since the depth i=d in the leaf nodes, 1<=j_d<=b^d holds. The j_dth leaf node is generated as shown in the following formula 28. (Formula 28) (N(d, j_d), M[j_d], Tag(d, j_d))

[0134] All leaf nodes are written as in the following formula 29. Leaf=((N(d,1),M[1],Tag(d,1)), ((N(d,2),M[2],Tag(d,2)), ..., (N(d,b^d),M[b^d],Tag(d,b^d))) (Formula 29)

[0135] 12 , when the depth of the entire tree structure is d=3, each leaf node is expressed as in the following formula 30. (Formula 30) Leaf=((N(3,1), M[1], Tag(3,1)), (N(3,2), M[2], Tag(3,2)), ..., (N(3,27), M

[27] , Tag(3,27))) Furthermore, the leaf node generation unit 103a outputs the generated leaf node set Leaf to the tree structure output unit 106.

[0136] The intermediate node generation unit 104a, like the intermediate node generation unit 104, generates intermediate nodes in a tree structure using the tag set TagInter output by the tag generation unit 102a. Here, in the intermediate nodes, 1<=i<=d-1, 1<=j_i<=b^i. Then, the j_ith intermediate node at depth i is generated as shown in the following formula 31. (Formula 31) (N(i, j_i), Tag(i, j_i))

[0137] All intermediate nodes are described as in the following formula 32. Inter=((N(1,1), Tag(1,1)), (N(1,2), Tag(1,2)), ..., (N(d-1, b^{d-1}), Tag(d-1, b^{d-1}))) (Formula 32)

[0138] 12 , when the depth of the entire tree structure is d=3, each intermediate node is expressed by the following formula 33: (Formula 33) Inter=((N(1,1), Tag(1,1)), (N(1,2), Tag(1,2)), ..., (N(2,9), Tag(2,9))) Furthermore, the intermediate node generation unit 104a outputs the generated intermediate node set Inter to the tree structure output unit 106.

[0139] The root node generation unit 105 is substantially the same as the root node generation unit 105 in the memory structure initialization device 10 of the first embodiment, and therefore a description thereof will be omitted. The tree structure output unit 106 is substantially the same as the tree structure output unit 106 in the memory structure initialization device 10 of the first embodiment, and therefore a description thereof will be omitted.

[0140] [Description of the Configuration of the Memory Verification Device] The memory verification device 20a according to the second embodiment includes a tree structure input unit 200, a verification location input unit 202a, a tag verification unit 203a, and a verification result output unit 204. The tree structure input unit 200 is substantially the same as the tree structure input unit 200 in the memory verification device 20 according to the first embodiment, and therefore a description thereof will be omitted. Note that the tree structure Tree input to the tree structure input unit 200 includes a nonce set N as shown in the above-described Expression 23.

[0141] The verification point input unit 202a accepts input of a verification point CheckNode of the memory, similar to the verification point input unit 202. Then, the verification point input unit 202a outputs the verification point CheckNode to the tag verification unit 203a. Here, in the second embodiment, CheckNode is a numerical value between 1 and b^d, inclusive, and indicates that the verification point is the CheckNode-th leaf node.

[0142] Similar to the tag verification unit 203, the tag verification unit 203a verifies whether the memory specified by the CheckNode has been tampered with, using the tree structure Tree, the verification location CheckNode, and the secret key K. Then, the tag verification unit 203 outputs the verification result to the verification result output unit 204. First, the tag verification unit 203 generates a path Path from the CheckNode-th leaf node to the root node. The path Path is expressed by the following formula 34. (Formula 34) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0))

[0143] Here, when 0<=i<=d and 1<=j_i<=b^{i}, each element (i, j_i) of Path represents the j_ith node at depth i. In other words, j_i represents the ordinal number of the node at depth i. Note that when p_d=CheckNode and 0<=i<=d-1, p_i is defined by the following formula 35. (Formula 35) p_i=ceiling(p_{i+1} / b) where ceiling(·) represents the ceiling function. Also, the value of p_0 is always 1.

[0144] Next, tag verification unit 203a calculates the following formula 36 using tree structure Tree, which is the output of tree structure input unit 200, and secret key K. (Formula 36) PathTag'=(Tag'(d,p_d), Tag'(d-1,p_{d-1}), ..., Tag'(0,p_0)) Tag'(d,p_d)=MAC_K(N(d,p_d),M[p_d]) Tag'(i,p_i)=MAC_K(N(i,p_i),N(i+1,b·p_i-(b-1))|| ...||N(i+1,b·p_i-1)||N(i+1,b·p_i)) where 0<=i<=d-1

[0145] Here, MAC_K is substantially the same as the method used in the tag generation unit 102a of the memory structure initialization device 10a in the second embodiment, and therefore a description thereof will be omitted. Tag'(i, p_i) is obtained by inputting the nonce of the node in question into the nonce portion of the input of the MAC function, and inputting a concatenation of b nonces of the child nodes of the node in question into the plaintext portion of the input of the MAC function.

[0146] Next, the tag verifying unit 203a obtains a value expressed by the following formula 37 from the tree structure Tree that is the output of the tree structure input unit 200. PathTag=(Tag(d, p_d), Tag(d−1, p_{d−1}), ..., Tag(0, p_0)) (Formula 37)

[0147] Then, the tag verification unit 203a checks whether the PathTag' calculated by itself is equal to the PathTag acquired from the tree. When 0<=i<=d, if Tag'(i, p_i)=Tag(i, p_i) holds for all i, the tag verification unit 203a sets the verification result to ACK. Here, ACK indicates that the information of the nodes related to the path has not been tampered with. Furthermore, the verification result is denoted as B, and the fact that the verification result is ACK is denoted as B=ACK.

[0148] On the other hand, when 0<=i<=d, if Tag'(i,p_i)≠Tag(i,p_i) holds for a certain i, the tag verification unit 203a sets the verification result to NCK. Here, NCK indicates that information on a node related to the path has been tampered with. In addition, the fact that the verification result is NCK is expressed as B=NCK.

[0149] The tag verification unit 203a outputs the verification result B to the verification result output unit 204. The verification result output unit 204 is substantially the same as the verification result output unit 204 in the memory verification device 20 of the first embodiment, and therefore a description thereof will be omitted.

[0150] [Description of the Configuration of the Memory Update Device] The memory update device 30a according to the second embodiment includes a tree structure input unit 300, an update location input unit 302a, a memory verification unit 303a, a nonce update unit 304, a tag update unit 305a, an update result output unit 306, an update determination unit 310, and a plaintext update unit 312. The tree structure input unit 300 is substantially the same as the tree structure input unit 300 in the memory update device 30 of the first embodiment, and therefore a description thereof will be omitted. Note that the tree structure Tree input to the tree structure input unit 300 includes a nonce set N as shown in the above-described Expression 23.

[0151] The update location input unit 302a accepts input of memory update information UpdateNode, similar to the update location input unit 302. Then, the update location input unit 302a outputs the memory update information UpdateNode to the update determination unit 310, the plaintext update unit 312, the memory verification unit 303a, and the tag update unit 305a.

[0152] Here, UpdateNode = (UpdateIndex, UpdateInfo). UpdateIndex is data indicating the leaf node corresponding to the update location. For example, UpdateIndex is a numerical value between 1 and b^d, indicating that the update location is the UpdateIndex-th leaf node. In other words, UpdateIndex indicates the order (ordinal number) of the leaf node corresponding to the update location at depth d.

[0153] UpdateInfo is data indicating the update content. UpdateInfo represents Block bit information for updating the plaintext block M[UpdateIndex], which is information included in the UpdateIndex-th leaf node. The plaintext block M[UpdateIndex] can be updated according to the update content UpdateInfo.

[0154] The update determination unit 310 is substantially the same as the update determination unit 310 in the memory update device 30 of the first embodiment, and therefore a description thereof will be omitted.

[0155] Like the memory verification unit 303, the memory verification unit 303a uses a tree structure Tree, memory update information UpdateNode, and a secret key K to verify whether the memory specified by UpdateNode has been tampered with. In other words, the memory verification unit 303a verifies whether the node corresponding to the path related to the leaf node specified by UpdateNode has been tampered with. The verification process performed by the memory verification unit 303a is substantially the same as that performed by the tag verification unit 203a in the memory verification device 20a of the second embodiment, but the output results are different. The tag verification unit 203a in the memory verification device 20a of the second embodiment outputs a verification result B, but the memory verification unit 303a also outputs a path Path from the node to the root node along with the verification result B. The memory verification unit 303a outputs the verification result B to the nonce update unit 304, the plaintext update unit 312, the tag update unit 305a, and the update result output unit 306. The memory verification unit 303a also outputs the path Path to the nonce update unit 304 and the tag update unit 305a.

[0156] Path is expressed as in the following formula 38. (Formula 38) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0)) Here, from the operation performed by the memory verification unit 303a, it can be seen that p_d=UpdateIndex.

[0157] Note that other functions of the memory verification unit 303a are substantially the same as those of the memory verification unit 303 according to the first embodiment, and therefore description thereof will be omitted. In other words, like the memory verification unit 303, the memory verification unit 303a may not verify the tag of a leaf node depending on the determination result of the update determination unit 310.

[0158] The plaintext updating unit 312 is substantially the same as the plaintext updating unit 312 in the memory updating device 30 of the first embodiment, and therefore a description thereof will be omitted. Also, the nonce updating unit 304 is substantially the same as the nonce updating unit 304 in the memory updating device 30 of the first embodiment, and therefore a description thereof will be omitted.

[0159] The tag update unit 305a updates the tag of the node specified by Path using the tree structure NewTree' of the update result, the nonce set N, the update information UpdateNode in the memory, the verification result B, the path Path, and the private key K. If B=ACK, the tag update unit 305 performs the calculation of the following equation 39 for 0<=i<=d-1. (Equation 39) Tag(d, p_d)←MAC_K(N(d, p_d), UpdateInfo) Tag(i, p_i)←MAC_K(N(i, p_i), N(i+1, b·p_i-(b-1))...N(i+1, b·p_i))

[0160] Note that MAC_K is essentially the same as the method used in the tag generation unit 102a of the memory structure initialization device 10a and the tag verification unit 203a of the memory verification device 20a in the second embodiment, and therefore a description thereof will be omitted. Tag(i, p_i) is obtained by inputting the nonce of the node in question into the nonce portion of the input of the MAC function, and inputting a concatenation of b nonces of the child nodes of the node in question into the plaintext portion of the input of the MAC function. The tag update unit 305a then outputs the tree structure NewTree resulting from the update to the update result output unit 306. On the other hand, if B=NCK, the tag update unit 305a does not perform any processing and does not output anything.

[0161] The update result output unit 306 is substantially the same as the update result output unit 306 in the memory update device 30 of the first embodiment, and therefore a description thereof will be omitted.

[0162] [Explanation of Effects] The effects of the second embodiment are substantially the same as those of the first embodiment. However, while the first embodiment assumes that the constructed tree structure is a binary tree, the second embodiment allows the tree structure to have any number of branches. Therefore, the effects of the first embodiment can be realized even for tree structures with any number of branches.

[0163] (Third Embodiment) Next, a third embodiment will be described. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. Furthermore, in each drawing, the same elements are assigned the same reference numerals, and duplicate explanations are omitted as necessary. The third embodiment is a modification of the first embodiment. Therefore, the following description will mainly focus on differences from the first embodiment. The configuration of the third embodiment corresponds to an improvement of the configuration of Patent Document 2 mentioned above. In the third embodiment, an example of a memory protection system that, in addition to memory verification, encrypts input plaintext to conceal it will be described. However, the tree structure constructed by the memory protection system 1 according to the third embodiment is defined as having two branches and a depth of d, as in the first embodiment.

[0164] Fig. 13 is a diagram showing an example of a tree structure configured by the memory protection system 1 according to the third embodiment. Fig. 13 shows a tree structure in the case where the number of branches b = 2 and the depth d = 3. Note that the Root, Inter, and Leaf are substantially the same as those in the first embodiment described above.

[0165] The memory protection system 1 according to the third embodiment includes a memory structure initialization device 10c, a memory verification device 20c, and a memory update device 30c. The memory protection system 1 detects and conceals memory tampering. The memory structure initialization device 10c according to the third embodiment receives plain text for which tampering detection and concealment are desired as input, and outputs an initial tree structure.

[0166] The memory verification device 20c receives as input the storage location of a ciphertext block to be checked for tampering and a tree structure, and verifies whether the memory corresponding to that storage location has been tampered with. The memory update device 30c receives as input the storage location of a ciphertext block to be updated, the update content, and the tree structure. The memory update device 30c outputs the updated tree structure or an error message indicating that tampering has been detected.

[0167] The memory protection system 1 according to the third embodiment uses authenticated encryption (AE) as a component technology in addition to the MAC used in the memory protection system 1 according to the first embodiment. AE using a secret key K is defined by two functions: an encryption function AE.Enc_K and a decryption function AE.Dec_K that pairs with this encryption function AE.Enc_K. AE.Enc_K receives a nonce N and plaintext M as input, and outputs ciphertext C and an authentication tag Tag. The encryption function is expressed as in the following equation 40: AE.Enc_K(N, M)=(C, T) (Equation 40)

[0168] AE.Dec_K receives three inputs: nonce N, ciphertext C, and authentication tag T, and outputs the decrypted plaintext M if no tampering is detected, and outputs an error message ⊥ if tampering is detected. This can be expressed as the following equation 41. (Equation 41) AE.Dec_K(N, C, T) = M (if no tampering is detected) AE.Dec_K(N, C, T) = ⊥ (if tampering is detected)

[0169] [Description of the Configuration of the Memory Structure Initialization Device] The memory structure initialization device 10c according to the third embodiment includes a plaintext input unit 100, a nonce assignment unit 101, and a tag generation unit 102c. The memory structure initialization device 10c according to the third embodiment also includes a leaf node generation unit 103c, an intermediate node generation unit 104, a root node generation unit 105, and a tree structure output unit 106.

[0170] The plaintext input unit 100 is substantially the same as the plaintext input unit 100 in the memory structure initialization device of the first embodiment, and therefore a description thereof will be omitted. The nonce allocator 101 is substantially the same as the nonce allocator 101 in the memory structure initialization device of the first embodiment, and therefore a description thereof will be omitted.

[0171] The tag generation unit 102c generates tags and ciphertext for tamper detection using the plaintext M output by the plaintext input unit 100, the nonce set N output by the nonce allocation unit 101, and the secret keys K_1 and K_2. It is assumed that MAC is used to generate tags for intermediate nodes and the root node, and authenticated encryption (AE) is used to encrypt the plaintext (leaf nodes) and generate tags. Examples of AE algorithms include OCB (Offset CodeBook).

[0172] First, the tag generation unit 102c generates data expressed by the following formula 42 as the ciphertext and tag to be used in the leaf node. (Formula 42) TagLeaf=((C[1], Tag(d,1)), (C[2], Tag(d,2^d)), ..., (C[2^d], Tag(d,2^d))) (C[j_d], Tag(d,j_d))=AE.Enc_{K_1}(N(d,j_d),M[j_d]) where 1<=j_d<=2^d

[0173] Note that AE.Enc_{K_1}(·,·) represents the encryption function of AE, and C[j_d] represents the j_dth ciphertext block.

[0174] Next, the tag generation unit 102c generates data expressed by the following formula 43 as a tag to be used at the intermediate node. (Formula 43) TagInter=(Tag(1,1), ..., Tag(d-1, 2^{d-1})) Tag(i, j_i)=MAC_{K_2}((N(i, j_i), N(i+1, 2j_i-1)||N(i+1, 2j_i)) where 1<=i<=d-1, 1<=j_i<=2^i

[0175] Next, the tag generation unit 102c generates data expressed by the following formula 44 as a tag to be used in the root node. TagRoot=(Tag(0,1)) Tag(0,1)=MAC_{K_2}(N(0,1),N(1,1)∥N(1,2)) (Formula 44)

[0176] From Equations 42, 43, and 44, the tag corresponding to each node corresponds to the calculation result of AE in the case of a leaf node, where the plaintext block corresponding to the node is used as plaintext and the nonce of the node and its plaintext are input. A ciphertext block is output as the calculation result. In the case of a node other than a leaf node, the tag corresponding to each node corresponds to the calculation result of MAC in the case of a node other than a leaf node, where the concatenation of nonces of multiple child nodes is used as plaintext and the nonce of the node and its plaintext are input.

[0177] As shown in the example of FIG. 13, when the depth d of the entire tree structure is d=3, Equations 42, 43, and 44 are expressed by the following Equation 45. Here, i is the depth index. Also, j_i is the index (order; ordinal number) of the node at depth i. (Equation 45) For 0<=i<=3, 1<=j_i<=2^i, (For 0<=i<=2) Tag(i,j_i)=MAC_{K_2}(N(i,j_i),N(i+1,2j_i-1)||N(i+1,2j_i)) (For i=3) (C[j_i], Tag(i,j_i))=AE.Enc_{K_1}(N(i,j_i),M[j_i])

[0178] The tag generation unit 102c then outputs the tag set TagLeaf to the leaf node generation unit 103c. The tag generation unit 102c also outputs the tag set TagInter to the intermediate node generation unit 104. The tag generation unit 102c also outputs the tag set TagRoot to the root node generation unit 105.

[0179] The leaf node generation unit 103c generates leaf nodes in a tree structure using the ciphertext and tag set TagLeaf output by the tag generation unit 102c. Here, since the depth i=d in the leaf nodes, 1<=j_d<=2^d holds. The j_dth leaf node is generated as shown in the following formula 46: (Formula 46) (N(d, j_d), C[j_d], Tag(d, j_d))

[0180] All leaf nodes are written as in the following formula 47. Leaf=((N(d,1), C[1], Tag(d,1)), ((N(d,2), C[2], Tag(d,2)), ..., (N(d,2^d), C[2^d], Tag(d,2^d))) (Formula 47)

[0181] 13, when the depth of the entire tree structure is d=3, each leaf node is expressed as in the following formula 48. (Formula 48) Leaf=((N(3,1), C[1], Tag(3,1)), (N(3,2), C[2], Tag(3,2)), ..., (N(3,8), C[8], Tag(3,8))) The leaf node generation unit 103c outputs the generated leaf node set Leaf to the tree structure output unit 106.

[0182] The intermediate node generation unit 104 is substantially the same as the intermediate node generation unit 104 in the memory structure initialization device 10 of the first embodiment, and therefore a description thereof will be omitted. The root node generation unit 105 is substantially the same as the root node generation unit 105 in the memory structure initialization device 10 of the first embodiment, and therefore a description thereof will be omitted. The tree structure output unit 106 is substantially the same as the tree structure output unit 106 in the memory structure initialization device 10 of the first embodiment, and therefore a description thereof will be omitted.

[0183] [Description of the Configuration of the Memory Verification Device] The memory verification device 20c according to the third embodiment includes a tree structure input unit 200, a verification point input unit 202, a tag verification unit 203c, and a verification result output unit 204. The tree structure input unit 200 is substantially the same as the tree structure input unit 200 in the memory verification device 20 of the first embodiment, and therefore a description thereof will be omitted. The verification point input unit 202 is substantially the same as the verification point input unit 202 in the memory verification device 20 of the first embodiment, and therefore a description thereof will be omitted.

[0184] The tag verification unit 203c verifies whether the memory specified by the CheckNode has been tampered with, using the tree structure Tree, the verification location CheckNode, and the private keys K_1 and K_2. Then, the tag verification unit 203c outputs the verification result to the verification result output unit 204. First, the tag verification unit 203c generates a path Path from the CheckNode-th leaf node to the root node. Here, the path Path indicates the route of nodes from the leaf node to the root node, and is expressed by the following formula 49. (Formula 49) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0))

[0185] Here, when 0<=i<=d and 1<=j_i<=2^{i}, each element (i, j_i) of Path represents the j_ith node at depth i. In other words, j_i represents the ordinal number of the node at depth i. Note that when p_d=CheckNode and 0<=i<=d-1, p_i is defined by the following formula 50. (Formula 50) p_i=ceiling(p_{i+1} / 2) where ceiling(·) represents the ceiling function. Also, the value of p_0 is always 1.

[0186] Next, the tag verifying unit 203c calculates the following formula 51 using the tree structure Tree output from the tree structure input unit 200 and the secret keys K_1 and K_2: AE.Dec_{K_1}(N(d,p_d),C[p_d],Tag(d,p_d)) (Formula 51)

[0187] If the above calculation result is an error message ⊥, the tag verification unit 203c defines the verification result B as B = NCK, outputs B, and ends the process. Note that AE.Dec_{K_1}(·,·,·) is a decryption function corresponding to the method AE.Enc_{K_1} used in the tag generation unit 102c of the memory structure initialization device 10c in the third embodiment. Furthermore, NCK indicates that the information of the nodes related to the path has been tampered with.

[0188] On the other hand, if the above calculation result is plaintext M[p_d], that is, if it indicates that ciphertext C[p_d] has been correctly decrypted, the tag verifying unit 203c continues to calculate the following formula 52. (Formula 52) PathTag'=(Tag'(d-1, p_{d-1}), ..., Tag'(0, p_0)) Tag'(i, p_i)=MAC_{K_2}(N(i, p_i), N(i+1, 2p_i-1)||N(i+1, 2p_i)) where 0<=i<=d-1

[0189] Here, MAC_{K_2}(.) is substantially the same as the MAC method used in the tag generation unit 102c of the memory structure initialization device 10c in the third embodiment, so a description thereof will be omitted. Also, as in the first embodiment, Tag'(i, p_i) is obtained by inputting the nonce of the node in question into the nonce portion of the input of the MAC function, and inputting the concatenated two nonces of the child nodes of the node in question into the plaintext portion of the input of the MAC function.

[0190] Next, the tag verifying unit 203c obtains a value expressed by the following formula 53 from the tree structure Tree that is the output of the tree structure input unit 200. PathTag=(Tag(d−1, p_{d−1}), . . . , Tag(0, p_0)) (Formula 53)

[0191] Then, the tag verification unit 203c checks whether the PathTag' calculated by itself is equal to the PathTag acquired from the tree. When 0<=i<=d-1, if Tag'(i, p_i)=Tag(i, p_i) holds for all i, the tag verification unit 203c sets the verification result to ACK. Here, ACK indicates that the information of the nodes related to the path has not been tampered with. Furthermore, the verification result is represented as B, and the fact that the verification result is ACK is represented as B=ACK.

[0192] On the other hand, when 0<=i<=d-1, if Tag'(i, p_i)≠Tag(i, p_i) holds for a certain i, the tag verification unit 203c sets the verification result in NCK.

[0193] The tag verification unit 203c outputs the verification result B. The verification result output unit 204 is substantially the same as the verification result output unit 204 in the memory verification device 20 of the first embodiment, and therefore a description thereof will be omitted.

[0194] [Description of the Configuration of the Memory Update Device] The memory update device 30c according to the third embodiment includes a tree structure input unit 300, an update location input unit 302, a memory verification unit 303c, a nonce update unit 304, a tag update unit 305c, an update result output unit 306, an update determination unit 310, and a plaintext update unit 312. The tree structure input unit 300 is substantially the same as the tree structure input unit 300 in the memory update device 30 of the first embodiment, and therefore a description thereof will be omitted. The update location input unit 302 is substantially the same as the update location input unit 302 in the memory update device 30 of the first embodiment, and therefore a description thereof will be omitted. The update determination unit 310 is substantially the same as the update determination unit 310 in the memory update device 30 of the first embodiment, and therefore a description thereof will be omitted.

[0195] The memory verification unit 303c uses the tree structure Tree, memory update information UpdateNode, and secret keys K_1 and K_2 to verify whether the memory specified by UpdateNode has been tampered with. In other words, the memory verification unit 303c verifies whether the node corresponding to the path related to the leaf node specified by UpdateNode has been tampered with. The verification process performed by the memory verification unit 303c is substantially the same as that of the tag verification unit 203c in the memory verification device 20c of the third embodiment, but the output results are different. The tag verification unit 203c in the memory verification device 20c of the third embodiment outputs verification result B, but the memory verification unit 303c also outputs the path Path from the node to the root node along with verification result B. The memory verification unit 303c outputs the verification result B to the plaintext update unit 312, the nonce update unit 304, the tag update unit 305c, and the update result output unit 306. The memory verification unit 303c also outputs the path Path to the nonce update unit 304 and the tag update unit 305c.

[0196] Note that other functions of the memory verification unit 303c are substantially the same as those of the memory verification unit 303 according to the first embodiment, and therefore description thereof will be omitted. In other words, like the memory verification unit 303, the memory verification unit 303c may not verify the tag of a leaf node depending on the determination result of the update determination unit 310.

[0197] The plaintext updating unit 312 is substantially the same as the plaintext updating unit 312 in the memory updating device 30 of the first embodiment, and therefore a description thereof will be omitted. Also, the nonce updating unit 304 is substantially the same as the nonce updating unit 304 in the memory updating device 30 of the first embodiment, and therefore a description thereof will be omitted.

[0198] The tag update unit 305c updates the tag of the node specified by Path using the tree structure NewTree' of the update result, the nonce set N, the memory update information UpdateNode, the verification result B, the path Path, and the private keys K_1 and K_2. If B=ACK, the tag update unit 305c performs the calculation of the following equation 54 for 0<=i<=d-1. (Equation 54) (C[p_d], Tag(d, p_d))←AE.Enc_{K_1}(N(d, p_d), UpdateInfo) Tag(i, p_i)←MAC_{K_2}(N(i, p_i), N(i+1, 2p_i-1)||N(i+1, 2p_i))

[0199] Note that AE.Enc_{K_1}(·,·) and MAC_{K_2}(·) are substantially the same as those used in the tag generation unit 102c of the memory structure initialization device 10c and the tag verification unit 203c of the memory verification device 20c in the third embodiment. The tag update unit 305c then outputs the tree structure NewTree resulting from the update. On the other hand, if B=NCK, the tag update unit 305c does not perform any processing and does not output anything.

[0200] The update result output unit 306 is substantially the same as the update result output unit 306 in the memory update device 30 of the first embodiment, and therefore a description thereof will be omitted.

[0201] [Explanation of Effects] The effect of the third embodiment is that, in addition to the effect of the first embodiment, memory confidentiality is possible. In the first embodiment, a MAC is used to detect tampering of a plaintext message. In contrast, in the third embodiment, by performing AE processing on a plaintext message, it is possible to detect tampering and also to conceal the plaintext message. Furthermore, the amount of calculation for AE is generally greater than or equal to the amount of calculation for MAC. Therefore, by making it possible to eliminate the need for integrity verification of leaf nodes during update processing as in this embodiment, it is possible to reduce the calculation of AE, which requires a large amount of calculation, and thereby further reduce the amount of calculation required for verification. Therefore, it is possible to perform node verification processing more efficiently when updating memory contents.

[0202] Furthermore, it is assumed that the AE used is a rate 1 scheme such as OCB, i.e., a scheme that can achieve plaintext encryption and authentication tag generation at the cost of encryption alone, and that a scheme can be adopted in which the data volumes of plaintext and ciphertext are the same. In this case, compared to the first embodiment, the data volume of the entire tree structure and the amount of calculation required by each device are almost unchanged. In other words, the third embodiment enables tamper detection and confidentiality with the same data volume and calculation volume as the first embodiment. Furthermore, although a binary tree is assumed for the tree structure in the third embodiment, it is naturally possible to use a tree structure with an increased number of branches, as in the second embodiment.

[0203] (Fourth embodiment) Next, a fourth embodiment will be described. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. In addition, the same elements in each drawing are given the same reference numerals, and duplicate explanations are omitted as necessary. The configuration of the fourth embodiment corresponds to an improvement of the configuration of Patent Document 3 mentioned above.

[0204] In the fourth embodiment, an example will be described in which the tree structure configured in the memory protection system has two branches and a depth of d. That is, the number of leaf nodes in the fourth embodiment is 2^d. The depth of the root node is defined as 0, and the depth of the leaf node is defined as d.

[0205] A memory protection system 1 (information processing system) according to the fourth embodiment includes a memory structure initialization device 12, a memory verification device 22, and a memory update device 32. The memory protection system 1 of the fourth embodiment corresponds to a system in which the memory structure initialization device 10, memory verification device 20, and memory update device 30 of FIG. 1 are replaced with the memory structure initialization device 12, memory verification device 22, and memory update device 32, respectively. The memory structure initialization device 12, memory verification device 22, and memory update device 32 may be physically integrated or may be separate. Furthermore, the components of each device, which will be described later with reference to FIGS. 14 to 16, may be realized by separate devices.

[0206] When referring to other embodiments described later, the memory structure initialization device 12 may be referred to as memory structure initialization devices 12a and 12c. Similarly, when referring to other embodiments described later, the memory verification device 22 may be referred to as memory verification devices 22a and 22c. Similarly, when referring to other embodiments described later, the memory update device 32 may be referred to as memory update devices 32a and 32c. The same applies to the components shown in Figures 14 to 16.

[0207] Fig. 14 is a block diagram showing an example of the configuration of the memory structure initialization device 12 according to the fourth embodiment. Fig. 15 is a block diagram showing an example of the configuration of the memory verification device 22 according to the fourth embodiment. Fig. 16 is a block diagram showing an example of the configuration of the memory update device 32 according to the fourth embodiment. Fig. 17 is a flowchart showing an example of the processing procedure of the memory structure initialization device 12 according to the fourth embodiment. Fig. 18 is a flowchart showing an example of the processing procedure of the memory verification device 22 according to the fourth embodiment. Figs. 19 to 21 are flowcharts showing an example of the processing procedure of the memory update device 32 according to the fourth embodiment. Figs. 14 to 21 will be described later.

[0208] In the memory protection system 1 according to the fourth embodiment, the memory structure initialization device 12 receives plaintext (plaintext message) for which tampering detection is desired as input, and outputs an initial tree structure and a set of memory addresses for each node in the tree structure. The plaintext is expressed as a combination of 2^d plaintext blocks. That is, the following formula 55 holds: (Formula 55) M=M[1]||M[2]|| ...||M[2^d] Furthermore, one plaintext block is defined as Block bits.

[0209] The memory verification device 22 receives as input the storage location of the plaintext (plaintext block) to be checked for tampering, a tree structure, and the memory addresses of each node in the tree structure, and verifies whether the memory corresponding to that storage location has been tampered with. The memory update device 32 receives as input the storage location of the plaintext (plaintext block) to be updated, the update content, the tree structure, and the memory addresses of each node in the tree structure. The memory update device 32 then outputs the updated tree structure or an error message indicating that tampering has been detected.

[0210] Fig. 22 is a diagram showing an example of a tree structure configured by the memory protection system 1 according to the fourth embodiment. Fig. 22 shows a tree structure in the case where d = 3. Note that Root, Inter, and Leaf will be described later.

[0211] [Description of the Configuration of the Memory Structure Initialization Device] Fig. 14 is a block diagram showing an example of the configuration of the memory structure initialization device 12 according to the fourth embodiment. As shown in Fig. 14, the memory structure initialization device 12 according to the fourth embodiment includes a plaintext input unit 120, a memory address allocation unit 121, and a tag generation unit 122. The memory structure initialization device 12 also includes a leaf node generation unit 123, an intermediate node generation unit 124, a root node generation unit 125, a tree structure output unit 126, and a memory address output unit 127.

[0212] The plaintext input unit 120 functions as a plaintext input means. The memory address allocation unit 121 functions as a memory address allocation means. The tag generation unit 122 functions as a tag generation means. The leaf node generation unit 123 functions as a leaf node generation means. The intermediate node generation unit 124 functions as an intermediate node generation means. The root node generation unit 125 functions as a root node generation means. The tree structure output unit 126 functions as a tree structure output means. The memory address output unit 127 functions as a memory address output means.

[0213] The memory structure initialization device 12 is, for example, a computer. The memory structure initialization device 12 may implement each of the components shown in FIG. 14 by executing a software program in a central processing unit. Each of the components implemented in the memory structure initialization device 12 may also be implemented as an individual device, a functional unit, or an electronic circuit. This also applies to other embodiments described below.

[0214] The plaintext input unit 120 accepts input of plaintext M to be protected. The plaintext input unit 120 outputs the accepted plaintext M to the tag generation unit 122. Here, the method by which the plaintext input unit 120 accepts input of plaintext M is not limited to a specific method. For example, the plaintext input unit 120 may be equipped with a character input device such as a keyboard and accept a user operation to input plaintext M. Alternatively, the plaintext input unit 120 may receive plaintext M from another device.

[0215] The memory address allocation unit 121 allocates node-specific memory address information to each node in the tree structure. The memory address allocation unit 121 then outputs the memory address information to the tag generation unit 122 and the memory address output unit 127. Here, since the number of nodes and the amount of data in each node are predetermined, it is possible to allocate memory addresses before defining the content information of each node. Furthermore, by its very nature, memory address information is uniquely determined for each node. In other words, the memory address information is specific to each node. This makes it possible to prevent data swapping attacks between nodes.

[0216] Here, when 0<=i<=d, 1<=j_i<=2^{i}, the memory address assigned to the j_ith node at depth i is represented as add(i, j_i). Then, the memory address information assigned to all nodes in the tree structure is written as a memory address set Add as shown in the following formula 56. (Formula 56) Add=(add(0,1), add(1,1), add(1,2), add(2,1), add(2,2), ..., add(d,2^d-1), add(d,2^d))

[0217] Here, "add(0,1)" corresponds to the memory address of the root node. Also, "add(d,1), ..., add(d,2^d)" correspond to the memory addresses of multiple leaf nodes. The others correspond to the memory addresses of intermediate nodes.

[0218] Furthermore, when a memory address is written as add(a, b), a indicates the depth in the tree structure of the node to which the memory address is assigned. Furthermore, b indicates the order (ordinal number) of the node to which the memory address is assigned at depth a. This also applies to the tag notation Tag(a, b), which will be described later.

[0219] The tag generation unit 122 generates a tag for tamper detection using the plaintext M output by the plaintext input unit 120, the memory address set Add output by the memory address allocation unit 121, and the secret key K. The MAC function described above is used for tag generation. First, the tag generation unit 122 generates data expressed by the following formula 57 as a tag to be used in a leaf node. (Formula 57) TagLeaf=((M[1], Tag(d,1)), (M[2], Tag(d,2)), ..., (M[2^d], Tag(d,2^d))) Tag(d,j_d)=MAC_K(add(d,j_d)||ctr(d,j_d),M[j_d]) where 1<=j_d<=2^d

[0220] Note that ctr(d, j_d) represents the counter value of the j_dth leaf node at depth d, and is incremented by 1 each time the node is updated. Here, we define ctr(d, j_d) = 0^{CTR-1}||1 for all j_d. Also, CTR is the bit length of the local counter value stored in each node, and "0^{CTR-1}" represents a bit string consisting of CTR-1 concatenated 0s. We assume that the value of CTR is determined in advance.

[0221] Next, the tag generation unit 122 generates data expressed by the following formula 58 as a tag to be used in the intermediate node. (Formula 58) TagInter=(Tag(1,1), ..., Tag(d-1, 2^{d-1})) Tag(i, j_i)=MAC_K(add(i, j_i)||ctr(i, j_i), ctr(i+1, 2j_i-1)||ctr(i+1, 2j_i)) where 1<=i<=d-1, 1<=j_i<=2^i

[0222] Next, the tag generation unit 122 generates data expressed by the following formula 59 as a tag to be used in the root node. TagRoot=(Tag(0,1)) Tag(0,1)=MAC_K(add(0,1)∥ctr(0,1),ctr(1,1)∥ctr(1,2)) (Formula 59)

[0223] From Equations 57, 58, and 59, the tags corresponding to each node are as follows. That is, for leaf nodes, the tag corresponding to each node corresponds to the calculation result of a MAC in which the concatenation of the memory address of the node and the local counter value is used as a nonce, the plaintext block corresponding to the node is used as plaintext, and the nonce and plaintext are used as inputs. Also, for nodes other than leaf nodes, the tag corresponding to each node corresponds to the calculation result of a MAC in which the concatenation of the memory address of the node and the local counter value is used as a nonce, the concatenation of the local counter values ​​of multiple child nodes is used as plaintext, and the nonce and plaintext are used as inputs.

[0224] As shown in the example of FIG. 22, when the depth d of the entire tree structure is d=3, the tag corresponding to each node is expressed by the following formula 60. Here, i is the depth index. Also, j_i is the index (order; ordinal number) of the node at depth i. (Formula 60) For 0<=i<=3, 1<=j_i<=2^i, (For 0<=i<=2) Tag(i,j_i)=MAC_K(add(i,j_i)||ctr(i,j_i),ctr(i+1,2j_i-1)||ctr(i+1,2j_i)) (For i=3) Tag(i,j_i)=MAC_K(add(i,j_i)||ctr(i,j_i),M[j_i])

[0225] Then, the tag generation unit 122 outputs the tag set TagLeaf to the leaf node generation unit 123. The tag generation unit 122 also outputs the tag set TagInter to the intermediate node generation unit 124. The tag generation unit 122 also outputs the tag set TagRoot to the root node generation unit 125.

[0226] The leaf node generation unit 123 generates leaf nodes in a tree structure using the tag set TagLeaf output by the tag generation unit 122. Here, since the depth i=d in the leaf nodes, 1<=j_d<=2^d holds. The j_dth leaf node is generated as shown in the following formula 61. (Formula 61) (ctr(d, j_d), M[j_d], Tag(d, j_d))

[0227] Furthermore, all leaf nodes are described as in the following formula 62. (Formula 62) Leaf=((ctr(d,1), M[1], Tag(d,1)), ((ctr(d,2), M[2], Tag(d,2)), ..., (ctr(d,2^d), M[2^d], Tag(d,2^d))) Furthermore, the leaf node generation unit 123 outputs the generated leaf node set Leaf to the tree structure output unit 126.

[0228] The intermediate node generation unit 124 generates intermediate nodes in a tree structure using the tag set TagInter output by the tag generation unit 122. Here, for the intermediate nodes, 1 <= i <= d-1, 1 <= j_i <= 2^i. Then, the j_ith intermediate node at depth i is generated as shown in the following formula 63. (Formula 63) (ctr(i, j_i), Tag(i, j_i)) Here, it is defined that ctr(i, j_i) = 0^{CTR-1}||1 for all i and j_i.

[0229] All intermediate nodes are described as in the following formula 64. Inter=((ctr(1,1), Tag(1,1)), (ctr(1,2), Tag(1,2)), ..., (ctr(d-1, 2^{d-1}), Tag(d-1, 2^{d-1}))) (Formula 64)

[0230] 22 , when the depth of the entire tree structure is d=3, each intermediate node is expressed by the following formula 65. (Formula 65) Inter=((ctr(1,1), Tag(1,1)), (ctr(1,2), Tag(1,2)), ..., (ctr(2,4), Tag(2,4)))) Furthermore, the intermediate node generation unit 124 outputs the generated intermediate node set Inter to the tree structure output unit 126.

[0231] The root node generation unit 125 generates a root node of a tree structure using the tag TagRoot output by the tag generation unit 122. The root node is generated as shown in the following formula 66. Here, ctr(0,1)=0^{CTR-1}||1 is defined. (Formula 66) Root=(ctr(0,1), Tag(0,1)) Furthermore, the root node generation unit 125 outputs the generated root node Root to the tree structure output unit 126.

[0232] The tree structure output unit 126 connects the leaf node set Leaf output by the leaf node generation unit 123, the intermediate node set Inter output by the intermediate node generation unit 124, and the root node Root output by the root node generation unit 125. The tree structure output unit 126 then outputs the connected data string as data indicating the tree structure (tree structure Tree) to a computer display, a printer, etc. The memory address output unit 127 outputs the memory address Add output by the memory address assignment unit 121 to a computer display, a printer, etc.

[0233] 15 is a block diagram showing an example of the configuration of a memory verification device 22 according to the fourth embodiment. As shown in Fig. 15, the memory verification device 22 according to the fourth embodiment includes a tree structure input unit 220, a memory address input unit 221, a verification location input unit 222, a tag verification unit 223, and a verification result output unit 224.

[0234] The tree structure input unit 220 functions as a tree structure input means. The memory address input unit 221 functions as a memory address input means. The verification point input unit 222 functions as a verification point input means. The tag verification unit 223 functions as a tag verification means. The verification result output unit 224 functions as a verification result output means.

[0235] The memory verification device 22 is, for example, a computer. The memory verification device 22 may implement each of the components shown in FIG. 15 by executing a software program in a central processing unit. Each of the components implemented in the memory verification device 22 may be implemented as an individual device, a functional unit, or an electronic circuit. This also applies to other embodiments described below.

[0236] The tree structure input unit 220 accepts input of a tree structure Tree for protecting a memory to be verified. The tree structure input unit 220 then outputs the tree structure Tree to the tag verification unit 223. Here, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. The tree structure Tree may be a data string in which the leaf node set Leaf, the intermediate node set Inter, and the root node Root, which are output by the tree structure output unit 126, are linked together.

[0237] The memory address input unit 221 accepts input of a memory address set Add assigned to a tree structure for protecting the memory to be verified. Then, the memory address input unit 221 outputs the memory address set Add to the tag verification unit 223. Add is written as in the following formula 67. (Formula 67) Add=(add(0,1), add(1,1), add(1,2), add(2,1), add(2,2), ..., add(d, 2^d-1), add(d, 2^d)) However, when 0<=i<=d and 1<=j_i<=2^{i}, the memory address of the j_ith node at depth i is represented by add(i, j_i).

[0238] The verification point input unit 222 accepts input of a verification point CheckNode in memory. Then, the verification point input unit 222 outputs the verification point CheckNode to the tag verification unit 223. Note that CheckNode is data indicating a node corresponding to the verification point in memory. Specifically, CheckNode is a numerical value between 1 and 2^d, and indicates that the verification point is the CheckNode-th leaf node. In other words, CheckNode indicates the position (order; ordinal number) of the leaf node corresponding to the verification point.

[0239] The tag verification unit 223 verifies whether the memory specified by CheckNode has been tampered with, using the tree structure Tree, the memory address set Add, the verification location CheckNode, and the secret key K. Then, the tag verification unit 223 outputs the verification result to the verification result output unit 224. First, the tag verification unit 223 generates a path Path from the CheckNode-th leaf node to the root node. Here, the path Path is data indicating the route of nodes from the leaf node to the root node. The path Path is expressed by the following formula 68. (Formula 68) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0))

[0240] Here, when 0<=i<=d and 1<=j_i<=2^{i}, each element (i, j_i) of Path represents the j_ith node at depth i. In other words, j_i represents the ordinal number of the node at depth i. Note that when p_d=CheckNode and 0<=i<=d-1, p_i is defined by the following formula 69. (Formula 69) p_i=ceiling(p_{i+1} / 2) where ceiling(·) represents the ceiling function. Also, the value of p_0 is always 1.

[0241] Next, the tag verification unit 223 calculates the following formula 70 using Add, which is the output of the memory address input unit 221, the tree structure Tree, which is the output of the tree structure input unit 220, and the secret key K. (Formula 70) PathTag'=(Tag'(d,p_d), Tag'(d-1,p_{d-1}), ..., Tag'(0,p_0)) Tag'(d,p_d)=MAC_K(add(d,p_d)||ctr(d,p_d), M[p_d]) Tag'(i,p_i)=MAC_K(add(i,p_i)||ctr(i,p_i),ctr(i+1,2p_i-1)||ctr(i+1,2p_i)) where 0<=i<=d-1

[0242] Here, MAC_K is substantially the same as the method used in the tag generation unit 122 of the memory structure initialization device 12 in the fourth embodiment, so a description thereof will be omitted. Tag'(i, p_i) is obtained by inputting the concatenation of the address of the node and the local counter into the nonce portion of the input of the MAC function, and inputting the concatenation of two local counters of child nodes of the node into the plaintext portion of the input of the MAC function.

[0243] Next, the tag verification unit 223 obtains a value expressed by the following formula 71 from the tree structure Tree that is the output of the tree structure input unit 220. PathTag=(Tag(d, p_d), Tag(d−1, p_{d−1}), ..., Tag(0, p_0)) (Formula 71)

[0244] Then, the tag verification unit 223 checks whether the PathTag' calculated by itself is equal to the PathTag acquired from the tree. When 0<=i<=d, if Tag'(i,p_i)=Tag(i,p_i) holds for all i, the tag verification unit 223 sets the verification result to ACK. The verification result is denoted as B, and the fact that the verification result is ACK is denoted as B=ACK.

[0245] On the other hand, when 0<=i<=d, if Tag'(i,p_i)≠Tag(i,p_i) holds for a certain i, the tag verification unit 223 sets the verification result to NCK. Also, the fact that the verification result is NCK is expressed as B=NCK.

[0246] The tag verification unit 223 outputs the verification result B to the verification result output unit 224. The verification result output unit 224 outputs the verification result B output by the tag verification unit 223 to a computer display, a printer, or the like.

[0247] [Description of the Configuration of the Memory Update Device] Fig. 16 is a block diagram showing an example of the configuration of a memory update device 32 according to the fourth embodiment. As shown in Fig. 16, the memory update device 32 according to the fourth embodiment includes a tree structure input unit 320, a memory address input unit 321, an update location input unit 322, a memory verification unit 323, a counter update unit 324, a tag update unit 325, and an update result output unit 326. The memory update device 32 according to the fourth embodiment also includes an update determination unit 330 and a plaintext update unit 332.

[0248] The tree structure input unit 320 functions as a tree structure input means. The memory address input unit 321 functions as a memory address input means. The update location input unit 322 functions as an update location input means. The memory verification unit 323 functions as a memory verification means. The counter update unit 324 functions as a counter update means. The tag update unit 325 functions as a tag update means. The update result output unit 326 functions as an update result output means. The update determination unit 330 functions as an update determination means. The plaintext update unit 332 functions as a plaintext update means.

[0249] The memory update device 32 is, for example, a computer. Note that the memory update device 32 may implement each of the components shown in FIG. 16 by executing a software program in a central processing unit. Furthermore, each of the components implemented in the memory update device 32 may be implemented as an individual device, a functional unit, or an electronic circuit. This also applies to the other embodiments described below.

[0250] The tree structure input unit 320 accepts input of a tree structure Tree for protecting the memory to be updated. Then, as indicated by the dashed-dotted line in FIG. 16 , the tree structure input unit 320 outputs the tree structure Tree to the memory verification unit 323 and the counter update unit 324. The tree structure input unit 320 may also output the tree structure Tree to the plaintext update unit 332. As described above, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. Note that the function of the tree structure input unit 320 is substantially the same as the function of the tree structure input unit 220 in the memory verification device 22 according to the fourth embodiment, and therefore description thereof will be omitted.

[0251] The memory address input unit 321 receives an input of a memory address set Add assigned to a tree structure for protecting a memory to be verified. Then, as indicated by the solid lines in Fig. 16, the memory address input unit 321 outputs the memory address set Add to the memory verification unit 323 and the tag update unit 325. Note that the function of the memory address input unit 321 is substantially the same as the function of the memory address input unit 221 in the memory verification device 22 according to the fourth embodiment, and therefore a description thereof will be omitted.

[0252] The update location input unit 322 accepts input of memory update information UpdateNode. Then, as indicated by the dotted lines in Fig. 16 , the update location input unit 322 outputs the memory update information UpdateNode to the update determination unit 330, the plaintext update unit 332, the memory verification unit 323, and the tag update unit 325. Here, as described above, the memory update information UpdateNode is information related to a node to be updated in the tree structure. UpdateNode is substantially the same as that in the first embodiment described above, and therefore description thereof will be omitted.

[0253] The update determination unit 330 uses the update information UpdateNode to determine whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update. The function of the update determination unit 330 is substantially the same as the function of the update determination unit 310 according to the first embodiment, and therefore a description thereof will be omitted.

[0254] The memory verification unit 323 verifies whether the memory specified by UpdateNode has been tampered with using the tree structure Tree, the memory address set Add, the memory update information UpdateNode, and the secret key K. That is, the memory verification unit 323 verifies whether the node corresponding to the path related to the leaf node specified by UpdateNode has been tampered with. The processing performed by the memory verification unit 323 is substantially the same as the processing performed by the tag verification unit 223 in the memory verification device 22 of the fourth embodiment, but the output results are different. The tag verification unit 223 in the memory verification device 22 of the fourth embodiment outputs verification result B, but the memory verification unit 323 also outputs the path Path from the node to the root node along with verification result B. As indicated by the thick dashed line in FIG. 16 , the memory verification unit 323 outputs verification result B to the counter update unit 324, the tag update unit 325, and the update result output unit 326. 16, the memory verification unit 323 may output the verification result B to the plaintext update unit 332. The memory verification unit 323 also outputs the path Path to the counter update unit 324 and the tag update unit 325.

[0255] Path is expressed as in the following formula 72. (Formula 72) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0)) Here, from the operation performed by the memory verification unit 323, it can be seen that p_d=UpdateIndex.

[0256] That is, the memory verification unit 323 generates a path Path from a leaf node to a root node in a tree structure. Furthermore, for each node in the path Path, the memory verification unit 323 generates a tag used for verification by inputting a concatenation of at least each node's unique memory address and a local counter stored in each node as a nonce into the MAC. In this way, the memory verification unit 323 verifies the tag stored in each node. That is, the memory verification unit 323 generates a tag Tag' for each node in the path Path by calculating the above-described formula 70. For each node, the memory verification unit 323 compares the generated tag Tag' with the stored tag Tag (a tag related to the tree) and determines whether they match. In this way, the memory verification unit 323 verifies whether each node has been tampered with. That is, the memory verification unit 323 performs integrity verification for each node. The memory verification unit 323 then outputs a verification result B.

[0257] Here, similar to the memory verification unit 303 according to the first embodiment, the memory verification unit 323 according to the fourth embodiment may not verify the tag of a leaf node depending on the determination result of the update determination unit 330. Specifically, if the update content of the leaf node does not depend on the plaintext before the update, the memory verification unit 323 verifies the tags of nodes other than the leaf node in the path Path. On the other hand, if the update content of the leaf node depends on the plaintext before the update, the memory verification unit 323 verifies the tags of all nodes including the leaf node in the path Path.

[0258] If the verification result B indicates that no tampering has been detected, the plaintext update unit 332 updates the plaintext to be updated in the leaf node based on the update information UpdateNode. The function of the plaintext update unit 332 is substantially the same as the function of the plaintext update unit 312 according to the first embodiment, and therefore a description thereof will be omitted.

[0259] The counter update unit 324 uses the tree structure Tree, the verification result B, and the path Path to update the information of the node specified by Path. If B=ACK, the following process is performed. First, the counter update unit 324 adds 1 to the counter value of the node specified by Path to update the counter value. That is, for 0<=i<=d, the counter update unit 324 performs the calculation of the following equation 73: (Equation 73) ctr(i,p_i)←ctr(i,p_i)+1 where a←b indicates that a is updated with b. The counter update unit 324 then outputs the tree structure NewTree' resulting from the update to the tag update unit 325. On the other hand, if B=NCK, the counter update unit 324 does not perform any processing and does not output anything.

[0260] The tag update unit 325 updates the tag of the node specified by Path using the tree structure NewTree' of the update result, the memory address set Add, the memory update information UpdateNode, the verification result B, the path Path, and the private key K. If B=ACK, the tag update unit 325 performs the calculation of the following equation 74 for 0<=i<=d-1. (Equation 74) Tag(d, p_d)←MAC_K(add(d, p_d)||ctr(d, p_d), UpdateInfo) Tag(i, p_i)←MAC_K(add(i, p_i)||ctr(i, p_i), ctr(i+1, 2p_i-1)||ctr(i+1, 2p_i))

[0261] MAC_K is the same as the method used in the tag generation unit 122 of the memory structure initialization device 12 and the tag verification unit 223 of the memory verification device 22 in the fourth embodiment. Tag(i, p_i) is obtained by inputting the concatenation of the address of the node and the local counter into the nonce part of the input of the MAC function, and inputting the concatenation of two local counters of child nodes of the node into the plaintext part of the input of the MAC function.

[0262] Then, the tag update unit 325 outputs the tree structure NewTree resulting from the update to the update result output unit 326. The new tree structure NewTree is composed of an updated leaf node set Leaf, an updated intermediate node set Inter, and an updated root node Root. Note that, as shown in Equation 62, the updated plaintext information is included in the updated leaf node set Leaf. On the other hand, if B=NCK, the tag update unit 325 does not perform any processing and does not output anything.

[0263] The update result output unit 326 outputs the update result using the verification result B output by the memory verification unit 323 and the tree structure NewTree output by the tag update unit 325. If B=ACK, the update result output unit 326 outputs NewTree to a computer display, printer, or the like. Note that the update result output unit 326 may output UpdateNode separately from NewTree. On the other hand, if B=NCK, the update result output unit 326 outputs the verification result B=NCK to a computer display, printer, or the like.

[0264] 17 is a flowchart showing the operation (memory structure initialization method) of the memory structure initialization device 12. In step S121, the plaintext input unit 120 accepts input of plaintext M to be protected. In step S122, the memory address allocation unit 121 allocates memory addresses to each node in the tree structure to generate a memory address set Add. In step S123, the tag generation unit 122 uses the plaintext M and the memory address set Add to generate a tag set (TagLeaf, TagInter, TagRoot) for tamper detection.

[0265] In step S124, the leaf node generation unit 123 generates a leaf node set Leaf of a tree structure using the tag set TagLeaf output by the tag generation unit 122. In step S125, the intermediate node generation unit 124 generates an intermediate node set Inter of a tree structure using the tag set TagInter output by the tag generation unit 122. In step S126, the root node generation unit 125 generates a root node Root of the tree structure using the tag TagRoot output by the tag generation unit 122.

[0266] In step S127, the tree structure output unit 126 connects the leaf node set Leaf, the intermediate node set Inter, and the root node Root, and outputs the connected data string indicating the tree structure to a computer display, a printer, etc. Furthermore, the memory address output unit 127 outputs the memory address Add output by the memory address assignment unit 121 to a computer display, a printer, etc. After step S127, the memory structure initialization device 12 ends the processing of FIG.

[0267] 18 is a flowchart showing the operation (memory verification method) of the memory verification device 22. In step S221, the tree structure input unit 220 accepts input of a tree structure Tree for protecting the memory to be verified. As described above, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. The memory address input unit 221 also accepts input of a memory address set Add assigned to the tree structure for protecting the memory to be verified. Furthermore, the verification point input unit 222 also accepts input of a memory verification point CheckNode.

[0268] In step S222, the tag verification unit 223 verifies the tag of each node using the tree structure Tree, the memory address set Add, and the verification location CheckNode. This allows the tag verification unit 223 to verify whether the memory specified by CheckNode has been tampered with. Furthermore, the tag verification unit 223 determines acceptance (ACK) or non-acceptance (NCK) and outputs a verification result B. In step S223, the verification result output unit 224 outputs the verification result B to a computer display, printer, or the like. After step S223, the memory verification device 22 ends the processing of FIG. 18.

[0269] 19 to 21 are flowcharts showing the operation (memory update method) of the memory update device 32. In step S320, the tree structure input unit 320 accepts input of a tree structure Tree for protecting the memory to be updated. As described above, the tree structure Tree is composed of a leaf node set Leaf, an intermediate node set Inter, and a root node Root. Also in step S320, the memory address input unit 321 accepts input of a memory address set Add assigned to the tree structure for protecting the memory to be verified. Furthermore, in step S320, the update location input unit 322 accepts input of memory update information UpdateNode. As described above, the update information UpdateNode is defined as UpdateNode = (UpdateIndex, UpdateInfo).

[0270] In step S321, the update determination unit 330 determines whether the update content UpdateInfo of the update information UpdateNode replaces the plaintext block corresponding to the update location UpdateIndex with a fixed value. Specifically, the update determination unit 330 may determine whether the update content UpdateInfo of the update information UpdateNode includes a fixed value. If the update content UpdateInfo of the update information UpdateNode replaces the plaintext block with a fixed value (if the determination result in S321 is YES), the processing proceeds to step S322. On the other hand, if the update content UpdateInfo of the update information UpdateNode does not replace the plaintext block with a fixed value (if the determination result in S321 is NO), the processing proceeds to step S332.

[0271] As shown in FIG. 20 , in step S322, the memory verification unit 323 verifies the tags of nodes other than leaf nodes using the tree structure Tree, the memory address set Add, and the memory update information UpdateNode. This allows the memory verification unit 323 to verify whether each node has been tampered with. Furthermore, the memory verification unit 323 determines acceptance (ACK) or rejection (NCK) and outputs a verification result B. The memory verification unit 323 then outputs the verification result B and the path Path used for memory verification. If B=ACK, i.e., memory tampering is not detected (S322: B=ACK (accepted)), processing proceeds to step S324. On the other hand, if B=NCK, i.e., memory tampering is detected (S322: B=NCK (rejected)), processing proceeds to step S323.

[0272] In step S323, the update result output unit 326 outputs the verification result B output by the memory verification unit 323 to a computer display, a printer, etc. After step S323, the memory update device 32 ends the process.

[0273] In step S324, the counter update unit 324 updates the counter of the node specified by the tree structure Tree output by the tree structure input unit 320 and the path Path output by the memory verification unit 323. Then, the counter update unit 324 outputs a new tree structure NewTree' as a result of the update.

[0274] In step S325, the plaintext of the leaf node and the tag corresponding to the path Path are updated using the tree structure NewTree', the path Path, and the update information UpdateNode in the memory. Specifically, the plaintext update unit 332 updates the plaintext (plaintext block) of the leaf node indicated by the update information UpdateNode. The tag update unit 325 also updates the tag of the node indicated by Path. The tag update unit 325 then outputs the new tree structure NewTree as a result of the update.

[0275] In step S326, the update result output unit 326 outputs the tree structure NewTree output by the tag update unit 325. After step S326, the memory update device 32 ends the process.

[0276] Meanwhile, as shown in FIG. 21 , in step S332, the memory verification unit 323 verifies the tags of all nodes in the path. Specifically, the memory verification unit 323 uses the tree structure Tree, the memory address set Add, and the memory update information UpdateNode to verify the tags of all nodes in the path related to the leaf node specified by UpdateNode. In this way, the memory verification unit 323 verifies whether each node has been tampered with. Furthermore, the memory verification unit 323 determines acceptance (ACK) or rejection (NCK) and outputs a verification result B. The memory verification unit 323 then outputs the verification result B and the path Path used for memory verification. If B=ACK, i.e., if memory tampering is not detected (S332: B=ACK (accepted)), the process proceeds to step S334. On the other hand, if B=NCK, that is, if memory tampering is detected (S332: B=NCK (not accepted)), the process proceeds to step S333.

[0277] As in S323, in step S333, the update result output unit 326 outputs the verification result B output by the memory verification unit 323 to a computer display, a printer, etc. After step S333, the memory update device 32 ends the process.

[0278] As in S324, in step S334, the counter update unit 324 updates the counter of the node specified by the tree structure Tree output by the tree structure input unit 320 and the path Path output by the memory verification unit 323. Then, the counter update unit 324 outputs a new tree structure NewTree' as a result of the update.

[0279] As in S325, in step S335, the plaintext of the leaf node and the tag corresponding to the path Path are updated using the tree structure NewTree', the path Path, and the update information UpdateNode stored in the memory. Specifically, the plaintext update unit 332 updates the plaintext (plaintext block) of the leaf node indicated by the update information UpdateNode. The tag update unit 325 also updates the tag of the node indicated by Path. The tag update unit 325 then outputs the new tree structure NewTree resulting from the update.

[0280] As in S326, in step S336, the update result output unit 326 outputs the tree structure NewTree output by the tag update unit 325. After step S336, the memory update device 32 ends the process.

[0281] [Explanation of Effects] When updating plaintext corresponding to a leaf node, the memory update device 32 according to the fourth embodiment uses update information to determine whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update. Then, when the update content of the leaf node does not depend on the plaintext before the update, the memory update device 32 verifies the tags of nodes other than the leaf node on the path from the leaf node to the root node. Meanwhile, in the technology of Patent Document 3, verification is performed for all nodes on the path regardless of the update content. Therefore, with the above configuration, the amount of calculation required for verification can be reduced compared to the technology of Patent Document 3. Therefore, as in the first embodiment, it is possible to efficiently perform node verification processing when updating memory contents.

[0282] Furthermore, as described above, there is a possibility that the tree structure may be tampered with when the contents of the memory are updated. On the other hand, as in the first embodiment, in the fourth embodiment, if the updated contents of a leaf node do not depend on the plaintext before the update, even if the plaintext included in the leaf node before the update is tampered with, the plaintext is updated to data that is not based on the tampered plaintext. Therefore, the security of the memory is not compromised. Furthermore, even if the local counter is tampered with, the tampering of the local counter is detected, just as in the case where the nonce is tampered with in the first embodiment described above. Therefore, if the updated contents of a leaf node do not depend on the plaintext before the update, security is not compromised even if verification of the tag for the leaf node is not required.

[0283] Furthermore, assuming that the amount of calculation required for verification is the same for all nodes, in the case of a tree structure of depth d, the amount of calculation required for memory verification processing in the memory update device 32 according to this embodiment is (d-1) / d times the amount of calculation required for the technology of Patent Document 2. If the cost of verification processing for leaf nodes is greater than the cost of verification processing for other nodes, the effect of reducing the amount of calculation achieved by the method according to this embodiment is even greater. Furthermore, the depth d is usually a relatively small integer, about one digit. Here, the smaller d is, the smaller (d-1) / d becomes. Therefore, the effect of reducing the amount of calculation achieved by the method according to this embodiment is relatively large.

[0284] (Fifth Embodiment) Next, a fifth embodiment will be described. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. Furthermore, in each drawing, the same elements are assigned the same reference numerals, and duplicate explanations are omitted as necessary. The fifth embodiment is a modification of the fourth embodiment. Therefore, the following description will mainly focus on differences from the fourth embodiment. The configuration of the fifth embodiment corresponds to an improvement of the configuration of Patent Document 3 mentioned above. Furthermore, the fifth embodiment differs from the fourth embodiment in the number of branches in the tree structure. In the fifth embodiment, an example will be described in which the number of branches in the tree structure configured by the memory protection system is b and the depth is d. In other words, the number of leaf nodes in the fifth embodiment is b^d.

[0285] Fig. 23 is a diagram showing an example of a tree structure configured by a memory protection system according to the fifth embodiment. Fig. 23 shows a tree structure in the case where the number of branches b = 3 and the depth d = 3. Note that the Root, Inter, and Leaf are substantially the same as those in the fourth embodiment described above.

[0286] The memory protection system 1 according to the fifth embodiment includes a memory structure initialization device 12a, a memory verification device 22a, and a memory update device 32a. The memory structure initialization device 12a according to the fifth embodiment receives plain text for which tampering detection is desired as input, and outputs an initial tree structure and a set of memory addresses of each node in the tree structure.

[0287] In the fifth embodiment, a plaintext is represented by a combination of b^d plaintext blocks. That is, the following formula 75 holds: M=M[1]||M[2]||...||M[b^d] (Formula 75) Furthermore, one plaintext block is defined as Block bits.

[0288] The memory verification device 22a receives as input the storage location of a plaintext block to be checked for tampering, a tree structure, and the memory address of each node in the tree structure, and verifies whether the memory corresponding to that storage location has been tampered with. The memory update device 32a receives as input the storage location of a plaintext block to be updated, the update content, the tree structure, and the memory address of each node in the tree structure. The memory update device 32a outputs the updated tree structure or an error message indicating that tampering has been detected.

[0289] [Description of the Configuration of the Memory Structure Initialization Device] The memory structure initialization device 12a according to the fifth embodiment includes a plaintext input unit 120, a memory address allocation unit 121a, and a tag generation unit 122a. The memory structure initialization device 12a according to the fifth embodiment also includes a leaf node generation unit 123a, an intermediate node generation unit 124a, a root node generation unit 125, a tree structure output unit 126, and a memory address output unit 127. The plaintext input unit 120 is substantially the same as the plaintext input unit 120 in the memory structure initialization device 12 according to the fourth embodiment, and therefore a description thereof will be omitted.

[0290] The memory address allocation unit 121a allocates memory address information to each node in the tree structure. Here, when 0<=i<=d, 1<=j_i<=b^{i}, the memory address allocated to the j_ith node at depth i is represented as add(i, j_i). Then, the memory address information allocated to all nodes in the tree structure is written as a memory address set Add as shown in the following formula 76 (Formula 76). Add=(add(0,1), add(1,1), add(1,2), ..., add(1,b), add(2,1), add(2,2), ..., add(d,b^d-1), add(d,b^d))

[0291] Similar to the tag generation unit 122, the tag generation unit 122a generates a tag for tamper detection using the plaintext M output by the plaintext input unit 120, the memory address set Add output by the memory address allocation unit 121a, and the secret key K. First, the tag generation unit 122a generates data expressed by the following formula 77 as a tag to be used in a leaf node. (Formula 77) TagLeaf=((M[1], Tag(d,1)), (M[2], Tag(d,2)), ..., (M[b^d], Tag(d,b^d))) Tag(d,j_d)=MAC_K(add(d,j_d)||ctr(d,j_d)), M[i]) 1<=j_d<=b^d

[0292] Note that ctr(d, j_d) represents the counter value of the j_dth leaf node at depth d, and is incremented by 1 each time the node is updated. Here, we define ctr(d, j_d) = 0^{CTR-1}||1 for all j_d. Also, CTR is the bit length of the local counter value stored in each node, and "0^{CTR-1}" represents a bit string consisting of CTR-1 concatenated 0s. We assume that the value of CTR is determined in advance.

[0293] Next, the tag generation unit 122a generates data expressed by the following formula 78 as a tag to be used in the intermediate node. (Formula 78) TagInter=(Tag(1,1), ..., Tag(d-1,b^{d-1})) Tag(i, j_i)=MAC_K((add(i, j_i)ctr(i, j_i), ctr(i+1,b.j_i-(b-1)) | ... || ctr(i+1,b.j_i)) where 1 <= i <= d-1, 1 <= j_i <= b^i Also, "ctr(i+1,b.j_i-(b-1)) ... || ctr(i+1,b.j_i)" is a concatenation of the local counter values ​​of b child nodes of node (i, j_i).

[0294] Next, the tag generation unit 122a generates data expressed by the following formula 79 as a tag to be used in the root node. (Formula 79) TagRoot=(Tag(0,1)) Tag(0,1)=MAC_K(add(0,1)||ctr(0,1),ctr(1,1)|| ... ||ctr(1,b)) Note that "ctr(1,1)| ... ||ctr(1,b)" indicates the concatenation of the local counter values ​​of b child nodes of the root node (0,1).

[0295] From Equations 77, 78, and 79, the tags corresponding to each node are as follows. That is, for leaf nodes, the tag corresponding to each node corresponds to the calculation result of a MAC in which the concatenation of the memory address of the node and the local counter value is used as a nonce, the plaintext block corresponding to the node is used as plaintext, and the nonce and plaintext are used as inputs. Also, for nodes other than leaf nodes, the tag corresponding to each node corresponds to the calculation result of a MAC in which the concatenation of the memory address of the node and the local counter value is used as a nonce, the concatenation of the local counter values ​​of multiple child nodes is used as plaintext, and the nonce and plaintext are used as inputs.

[0296] 23, when the depth d of the entire tree structure is d=3 and the number of branches b is b=3, the tag corresponding to each node is expressed by the following formula 80. Here, i is the depth index, and j_i is the index (order; ordinal number) of the node at depth i. (Formula 80) For 0<=i<=3, 1<=j_i<=3^i, (For 0<=i<=2) Tag (i, j_i) = MAC_K(add (i, j_i) | | ctr (i, j_i), ctr (i+1, 3j_i-2) | | ctr (i+1, 3j_i-1) | | ctr (i+1, 3j_i)) (For i = 3) Tag (i, j_i) = MAC_K (add (i, j_i) | | ctr (i, j_i), M[j_i])

[0297] The tag generation unit 122a then outputs the tag set TagLeaf to the leaf node generation unit 123a, the tag set TagInter to the intermediate node generation unit 124a, and the tag set TagRoot to the root node generation unit 125.

[0298] The leaf node generation unit 123a, like the leaf node generation unit 123, generates leaf nodes in a tree structure using the tag set TagLeaf output by the tag generation unit 122a. Here, since the depth i=d in the leaf nodes, 1<=j_d<=b^d holds. The j_dth leaf node is generated as shown in the following formula 28: (Formula 81) (ctr(d, j_d), M[j_d], Tag(d, j_d))

[0299] Furthermore, all leaf nodes are written as in the following formula 82. (Formula 82) Leaf=((ctr(d,1), M[1], Tag(d,1)), (ctr(d,2), M[2], Tag(d,2)), ..., (ctr(d,b^d), M[b^d], Tag(d,b^d))) Furthermore, the leaf node generation unit 123a outputs the generated leaf node set Leaf to the tree structure output unit 126.

[0300] The intermediate node generation unit 124a, like the intermediate node generation unit 124, generates intermediate nodes in a tree structure using the tag set TagInter output by the tag generation unit 122a. Here, for the intermediate nodes, 1 <= i <= d-1, 1 <= j_i <= b^i. Then, the j_ith intermediate node at depth i is generated as shown in the following formula 83. (Formula 83) (ctr(i, j_i), Tag(i, j_i)) Here, it is defined that ctr(i, j_i) = 0^{CTR-1}||1 for all i and j_i.

[0301] All intermediate nodes are described as in the following formula 84. Inter=((ctr(1,1), Tag(1,1)), (ctr(1,2), Tag(1,2)), ..., (ctr(d-1, b^{d-1}), Tag(d-1, b^{d-1}))) (Formula 84)

[0302] 12 , when the depth of the entire tree structure is d=3, each intermediate node is expressed by the following formula 85. (Formula 85) Inter=((ctr(1,1), Tag(1,1)), (ctr(1,2), Tag(1,2)), ..., (ctr(2,9), Tag(2,9))) In addition, the intermediate node generation unit 124a outputs the generated intermediate node set Inter to the tree structure output unit 126.

[0303] The root node generation unit 125 is substantially the same as the root node generation unit 125 in the memory structure initialization device 12 of the fourth embodiment, and therefore a description thereof will be omitted. The tree structure output unit 126 is substantially the same as the tree structure output unit 126 in the memory structure initialization device 12 of the fourth embodiment, and therefore a description thereof will be omitted. The memory address output unit 127 is substantially the same as the memory address output unit 127 in the memory structure initialization device 12 of the fourth embodiment, and therefore a description thereof will be omitted.

[0304] [Description of the Configuration of the Memory Verification Device] The memory verification device 22a according to the fifth embodiment includes a tree structure input unit 220, a memory address input unit 221a, a verification location input unit 222a, a tag verification unit 223a, and a verification result output unit 224. The tree structure input unit 220 is substantially the same as the tree structure input unit 220 in the memory verification device 22 according to the fourth embodiment, and therefore a description thereof will be omitted.

[0305] The memory address input unit 221a accepts input of a memory address set Add assigned to a tree structure for protecting the memory to be verified. Then, the memory address input unit 221a outputs the memory address set Add to the tag verification unit 223a. Add is written as in the following formula 86. (Formula 86) Add=(add(0,1), add(1,1), add(1,2), ..., add(1,b), add(2,1), add(2,2), ..., add(d,b^d-1), add(d,b^d)) where, when 0<=i<=d and 1<=j_i<=b^{i}, the memory address of the j_ith node at depth i is represented as add(i,j_i).

[0306] The verification point input unit 222a accepts input of a verification point CheckNode of the memory, similar to the verification point input unit 222. Then, the verification point input unit 222a outputs the verification point CheckNode to the tag verification unit 223a. Here, in the fifth embodiment, CheckNode is a numerical value between 1 and b^d, and indicates that the verification point is the CheckNode-th leaf node.

[0307] Similar to the tag verification unit 223, the tag verification unit 223a verifies whether the memory specified by CheckNode has been tampered with, using the tree structure Tree, the memory address set Add, the verification location CheckNode, and the secret key K. Then, the tag verification unit 223a outputs the verification result to the verification result output unit 224. First, the tag verification unit 223a generates a path Path from the CheckNode-th leaf node to the root node. The path Path is expressed by the following formula 87. (Formula 87) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0))

[0308] Here, when 0<=i<=d and 1<=j_i<=b^{i}, each element (i, j_i) of Path represents the j_ith node at depth i. In other words, j_i represents the ordinal number of the node at depth i. Note that when p_d=CheckNode and 0<=i<=d-1, p_i is defined by the following formula 88. (Formula 88) p_i=ceiling(p_{i+1} / b) where ceiling(·) represents the ceiling function. Also, the value of p_0 is always 1.

[0309] Next, the tag verification unit 223a calculates the following equation 89 using Add, which is the output of the memory address input unit 221a, Tree, which is the output of the tree structure input unit 220, and the secret key K. (Formula 89) PathTag' = (Tag' (d, p_d), Tag' (d-1, p_{d-1}), ..., Tag' (0, p_0)) Tag' (d, p_d) = MAC_K (add (d, p_d) | | ctr (d, p_d), M[p_d]) Tag' (i, p_i) = MAC_K (add (i, p_i) | | ctr (i, p_i), ctr (i + 1, b p_i - (b - 1)) | | ... | | ctr (i + 1, b p_i - 1) | | ctr (i + 1, b p_i)) However, 0<=i<=d-1

[0310] Here, MAC_K is substantially the same as the method used in the tag generation unit 122a of the memory structure initialization device 12a in the fifth embodiment, and therefore a description thereof will be omitted. Tag'(i, p_i) is obtained by inputting the concatenation of the address of the node and the local counter into the nonce portion of the input of the MAC function, and inputting the concatenation of b local counters of the child nodes of the node into the plaintext portion of the input of the MAC function.

[0311] Next, the tag verifying unit 223a obtains a value expressed by the following formula 90 from the tree structure Tree that is the output of the tree structure input unit 220. PathTag=(Tag(d, p_d), Tag(d−1, p_{d−1}), ..., Tag(0, p_0)) (Formula 90)

[0312] Then, the tag verification unit 223a checks whether the PathTag' calculated by itself is equal to the PathTag acquired from the tree. When 0<=i<=d, if Tag'(i,p_i)=Tag(i,p_i) holds for all i, the tag verification unit 223a sets the verification result to ACK. The verification result is denoted as B, and the fact that the verification result is ACK is denoted as B=ACK.

[0313] On the other hand, when 0<=i<=d, if Tag'(i,p_i)≠Tag(i,p_i) holds for a certain i, the tag verification unit 223a sets the verification result to NCK. Also, the fact that the verification result is NCK is expressed as B=NCK.

[0314] The tag verification unit 223a outputs the verification result B to the verification result output unit 224. The verification result output unit 224 is substantially the same as the verification result output unit 224 in the memory verification device 22 of the fourth embodiment, and therefore a description thereof will be omitted.

[0315] [Description of the Configuration of the Memory Update Device] The memory update device 32a according to the fifth embodiment includes a tree structure input unit 320, a memory address input unit 321a, an update location input unit 322a, a memory verification unit 323a, a counter update unit 324, a tag update unit 325a, and an update result output unit 326. The memory update device 32 according to the fifth embodiment also includes an update determination unit 330 and a plaintext update unit 332. The tree structure input unit 320 is substantially the same as the tree structure input unit 320 in the memory update device 32 of the fourth embodiment, and therefore description thereof will be omitted.

[0316] The memory address input unit 321a receives an input of a memory address set Add assigned to a tree structure for protecting a memory to be verified. The memory address input unit 321a then outputs the memory address set Add to the memory verification unit 323a and the tag update unit 325a. The function of the memory address input unit 321a is substantially the same as the function of the memory address input unit 221a in the memory verification device 22a of the fifth embodiment, and therefore a description thereof will be omitted.

[0317] The update location input unit 322a accepts input of memory update information UpdateNode. The update location input unit 322a then outputs the memory update information UpdateNode to the update determination unit 330, the plaintext update unit 332, the memory verification unit 323a, and the tag update unit 325a. As described above, the memory update information UpdateNode is information related to a node to be updated in the tree structure. UpdateNode is substantially the same as that in the second embodiment described above, and therefore description thereof will be omitted.

[0318] The update determination unit 330 is substantially the same as the update determination unit 330 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted.

[0319] Like the memory verification unit 323, the memory verification unit 323a verifies whether the memory specified by UpdateNode has been tampered with, using a tree structure Tree, a memory address set Add, memory update information UpdateNode, and a secret key K. In other words, the memory verification unit 323a verifies whether the node corresponding to the path related to the leaf node specified by UpdateNode has been tampered with. The verification process performed by the memory verification unit 323a is substantially the same as that of the tag verification unit 223a in the memory verification device 22a of the fifth embodiment, but the output results are different. The tag verification unit 223a in the memory verification device 22a of the fifth embodiment outputs a verification result B, but the memory verification unit 323a also outputs a path Path from the node to the root node along with the verification result B. The memory verification unit 323a outputs the verification result B to the counter update unit 324, the plaintext update unit 332, the tag update unit 325a, and the update result output unit 326. The memory verification unit 323a also outputs the path Path to the counter update unit 324 and the tag update unit 325a.

[0320] Path is expressed as in the following formula 91. (Formula 91) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0)) Here, from the operation performed by the memory verification unit 323a, it can be seen that p_d=UpdateIndex.

[0321] Note that other functions of the memory verification unit 323a are substantially the same as those of the memory verification unit 323 according to the fourth embodiment, and therefore description thereof will be omitted. In other words, like the memory verification unit 323, the memory verification unit 323a may not verify the tag of a leaf node depending on the determination result of the update determination unit 330.

[0322] The plaintext update unit 332 is substantially the same as the plaintext update unit 332 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted. The counter update unit 324 is substantially the same as the counter update unit 324 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted.

[0323] The tag update unit 325a updates the tag of the node specified by Path using the tree structure NewTree' of the update result, the memory address set Add, the memory update information UpdateNode, the verification result B, the path Path, and the private key K. If B=ACK, the tag update unit 325a performs the calculation of the following equation 92 for 0<=i<=d-1. (Equation 92) Tag(d, p_d)←MAC_K(add(d, p_d)||ctr(d, p_d), UpdateInfo) Tag(i, p_i)←MAC_K(add(i, p_i)||ctr(i, p_i), ctr(i+1, b·p_i-(b-1))|| ...||ctr(i+1, b·p_i))

[0324] Note that MAC_K is essentially the same as the method used in the tag generation unit 122a of the memory structure initialization device 12a and the tag verification unit 223a of the memory verification device 22a in the fifth embodiment, and therefore a description thereof will be omitted. Tag(i, p_i) is obtained by inputting the concatenation of the address of the node and the local counter into the nonce portion of the input of the MAC function, and inputting the concatenation of b local counters of the child nodes of the node into the plaintext portion of the input of the MAC function. The tag update unit 325a then outputs the tree structure NewTree resulting from the update to the update result output unit 326. On the other hand, if B=NCK, the tag update unit 325a does not perform any processing and does not output anything.

[0325] The update result output unit 326 is substantially the same as the update result output unit 326 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted.

[0326] [Explanation of Effects] The effects of the fifth embodiment are substantially the same as those of the fourth embodiment. However, while the fourth embodiment assumes that the constructed tree structure is a binary tree, the fifth embodiment allows the tree structure to have any number of branches. Therefore, the effects of the fourth embodiment can be realized even for tree structures with any number of branches.

[0327] (Sixth Embodiment) Next, a sixth embodiment will be described. For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. Furthermore, in each drawing, the same elements are given the same reference numerals, and duplicate explanations are omitted as necessary. The sixth embodiment is a modification of the fourth embodiment. Therefore, the following description will mainly focus on differences from the fourth embodiment. In the sixth embodiment, an example of a memory protection system that not only performs memory verification but also encrypts input plaintext to conceal it will be described. However, the tree structure constructed by the memory protection system 1 according to the sixth embodiment is defined to have two branches and a depth of d, as in the fourth embodiment.

[0328] Fig. 24 is a diagram showing an example of a tree structure configured by the memory protection system 1 according to the sixth embodiment. Fig. 24 shows a tree structure in the case where the number of branches b = 2 and the depth d = 3. Note that the Root, Inter, and Leaf are substantially the same as those in the fourth embodiment described above.

[0329] The memory protection system 1 according to the sixth embodiment includes a memory structure initialization device 12c, a memory verification device 22c, and a memory update device 32c. The memory protection system 1 detects and conceals memory tampering. The memory structure initialization device 12c according to the sixth embodiment receives plain text for which tampering detection and concealment are desired as input, and outputs an initial tree structure and a set of memory addresses for each node in the tree structure.

[0330] The memory verification device 22c receives as input the storage location of the ciphertext block to be checked for tampering, the tree structure, and the memory addresses of each node in the tree structure, and verifies whether the memory has been tampered with. The memory update device 32c receives as input the storage location of the ciphertext block to be updated, the update details, the tree structure, and the memory addresses of each node in the tree structure. The memory update device 32c outputs the updated tree structure or an error message indicating that tampering has been detected.

[0331] The memory protection system 1 according to the sixth embodiment uses authenticated encryption (AE) as a component technology, similar to the third embodiment, in addition to the MAC used in the memory protection system 1 according to the fourth embodiment. AE using a secret key K is defined by two functions: an encryption function AE.Enc_K and a decryption function AE.Dec_K that is paired with this encryption function AE.Enc_K. AE.Enc_K receives a nonce N and plaintext M as input, and outputs ciphertext C and an authentication tag Tag. The encryption function can be expressed as the following equation 93: (Equation 93) AE.Enc_K(N, M)=(C, T)

[0332] AE.Dec_K receives three inputs: nonce N, ciphertext C, and authentication tag, and outputs the decrypted plaintext M if no tampering is detected, and outputs an error message ⊥ if tampering is detected. This can be expressed as the following equation 94. (Equation 94) AE.Dec_K(N, C, T) = M (if no tampering is detected) AE.Dec_K(N, C, T) = ⊥ (if tampering is detected)

[0333] [Configuration of Memory Structure Initialization Device] The memory structure initialization device 12c according to the sixth embodiment includes a plaintext input unit 120, a memory address allocation unit 121, and a tag generation unit 122c. The memory structure initialization device 12c according to the sixth embodiment also includes a leaf node generation unit 123c, an intermediate node generation unit 124, a root node generation unit 125, a tree structure output unit 126, and a memory address output unit 127.

[0334] The plaintext input unit 120 is substantially the same as the plaintext input unit 120 in the memory structure initialization device of the fourth embodiment, and therefore a description thereof will be omitted. The memory address allocation unit 121 is substantially the same as the memory address allocation unit 121 in the memory structure initialization device of the fourth embodiment, and therefore a description thereof will be omitted.

[0335] The tag generation unit 122c generates tags and ciphertext for tamper detection using the plaintext M output by the plaintext input unit 120, the memory address set Add output by the memory address allocation unit 121, and the secret keys K_1 and K_2. It is assumed that MAC is used to generate tags for the intermediate nodes and the root node, and authenticated encryption (AE) is used to encrypt the plaintext (leaf nodes) and generate tags.

[0336] First, the tag generation unit 122c generates data expressed by the following formula 95 as the ciphertext and tag to be used in the leaf node. (Formula 95) TagLeaf=((C[1], Tag(d,1)), (C[2], Tag(d,2)), ..., (C[2^d], Tag(d,2^d))) (C[j_d], Tag(d,j_d))=AE.Enc_{K_1}(add(d,j_d)||ctr(d,j_d),M[j_d]) where 1<=j_d<=2^d

[0337] Note that AE.Enc_{K_1}(·,·) represents the encryption function of AE, and C[j_d] represents the j_dth ciphertext block.

[0338] Next, the tag generation unit 122c generates data expressed by the following formula 96 as a tag to be used in the intermediate node. (Formula 96) TagInter=(Tag(1,1), ..., Tag(d-1, 2^{d-1})) Tag(i, j_i)=MAC_{K_2}((add(i, j_i)||ctr(i, j_i), ctr(i+1, 2j_i-1)||ctr(i+1, 2j_i)) where 1<=i<=d-1, 1<=j_i<=2^i

[0339] Next, the tag generation unit 122c generates data expressed by the following formula 97 as a tag to be used in the root node. TagRoot=(Tag(0,1)) Tag(0,1)=MAC_{K_2}(add(0,1)∥ctr(0,1),ctr(1,1)∥ctr(1,2)) (Formula 97)

[0340] From Equation 95, Equation 96, and Equation 97, the tag corresponding to each node is as follows. That is, for leaf nodes, the tag corresponding to each node corresponds to the calculation result of AE, where the concatenation of the memory address of the node and the local counter value is used as the nonce, and the plaintext block corresponding to the node is used as the plaintext, and the nonce and plaintext are used as inputs. Also, a ciphertext block is output as the calculation result. Also, for nodes other than leaf nodes, the tag corresponding to each node corresponds to the calculation result of MAC, where the concatenation of the memory address of the node and the local counter value is used as the nonce, and the concatenation of the local counter values ​​of multiple child nodes is used as the plaintext, and the nonce and plaintext are used as inputs.

[0341] As shown in the example of FIG. 24, when the depth d of the entire tree structure is d=3, formulas 95, 96, and 97 are expressed by the following formula 98. Here, i is the depth index. Also, j_i is the index (order; ordinal number) of the node at depth i. (Formula 98) For 0<=i<=3, 1<=j_i<=2^i, (For 0<=i<=2) Tag(i,j_i)=MAC_{K_2}(add(i,j_i)||ctr(i,j_i),ctr(i+1,2j_i-1)||ctr(i+1,2j_i)) (For i=3) (C[j_i], Tag(i,j_i))=AE. Enc_{K_1} (add (i, j_i) | | ctr (i, j_i), M[j_i])

[0342] The leaf node generation unit 123c generates leaf nodes in a tree structure using the ciphertext and tag set TagLeaf output by the tag generation unit 122c. Here, since the depth i=d in the leaf nodes, 1<=j_d<=2^d holds. The j_dth leaf node is generated as shown in the following formula 99: (Formula 99) (ctr(d, j_d), C[j_d], Tag(d, j_d))

[0343] All leaf nodes are written as in the following formula 100. Leaf=((ctr(d,1), C[1], Tag(d,1)),...,(ctr(d,2^d), C[2^d], Tag(d,2^d))) (Formula 100)

[0344] 24, when the depth of the entire tree structure is d=3, each leaf node is expressed by the following formula 101. (Formula 101) Leaf=((ctr(3,1), C[1], Tag(3,1)), (ctr(3,2), C[2], Tag(3,2)), ..., (ctr(3,8), C[8], Tag(3,8))) The leaf node generation unit 123c outputs the generated leaf node set Leaf to the tree structure output unit 126.

[0345] The intermediate node generation unit 124 is substantially the same as the intermediate node generation unit 124 in the memory structure initialization device 12 of the fourth embodiment, and therefore a description thereof will be omitted. The root node generation unit 125 is substantially the same as the root node generation unit 125 in the memory structure initialization device 12 of the fourth embodiment, and therefore a description thereof will be omitted. The tree structure output unit 126 is substantially the same as the tree structure output unit 126 in the memory structure initialization device 12 of the fourth embodiment, and therefore a description thereof will be omitted. The memory address output unit 127 is substantially the same as the memory address output unit 127 in the memory structure initialization device 12 of the fourth embodiment, and therefore a description thereof will be omitted.

[0346] [Description of the Configuration of the Memory Verification Device] The memory verification device 22c according to the sixth embodiment includes a tree structure input unit 220, a memory address input unit 221, a verification location input unit 222, a tag verification unit 223c, and a verification result output unit 224. The tree structure input unit 220 is substantially the same as the tree structure input unit 220 in the memory verification device 22 of the fourth embodiment, and therefore a description thereof will be omitted. The memory address input unit 221 is substantially the same as the memory address input unit 221 in the memory verification device 22 of the fourth embodiment, and therefore a description thereof will be omitted. The verification location input unit 222 is substantially the same as the verification location input unit 222 in the memory verification device 22 of the fourth embodiment, and therefore a description thereof will be omitted.

[0347] The tag verification unit 223c verifies whether the memory specified by CheckNode has been tampered with, using the tree structure Tree, the memory address set Add, the verification location CheckNode, and the private keys K_1 and K_2. Then, the tag verification unit 223c outputs the verification result to the verification result output unit 224. First, the tag verification unit 223c generates a path Path from the CheckNode-th leaf node to the root node. Here, the path Path indicates the route of nodes from the leaf node to the root node, and is expressed by the following formula 102. (Formula 102) Path=((d, p_d), (d-1, p_{d-1}), (d-2, p_{d-2}), ..., (1, p_1), (0, p_0))

[0348] Here, when 0<=i<=d and 1<=j_i<=2^{i}, each element (i, j_i) of Path represents the j_ith node at depth i. In other words, j_i represents the ordinal number of the node at depth i. Note that when p_d=CheckNode and 0<=i<=d-1, p_i is defined by the following formula 103. (Formula 103) p_i=ceiling(p_{i+1} / 2) where ceiling(·) represents the ceiling function. Also, the value of p_0 is always 1.

[0349] Next, the tag verification unit 223c calculates the following formula 104 using Add, which is the output of the memory address input unit 221, Tree, which is the output of the tree structure input unit 220, and the secret keys K_1 and K_2: (Formula 104) AE.Dec_{K_1}(add(d,p_d)∥ctr(d,p_d),C[p_d],Tag(d,p_d))

[0350] If the above calculation result is an error message ⊥, the tag verification unit 223c defines the verification result B as B = NCK, outputs B, and ends the process. Note that AE.Dec_{K_1}(·,·,·) is a decryption function of the method AE.Enc_{K_1} used in the tag generation unit 122c of the memory structure initialization device 12c in the sixth embodiment. Furthermore, NCK indicates that the information of the nodes related to the path has been tampered with.

[0351] On the other hand, if the above calculation result is the plaintext M[p_d], that is, if it indicates that the ciphertext C[p_d] has been correctly decrypted, the tag verifying unit 223c continues to calculate the following formula 105. (Formula 105) PathTag'=(Tag'(d-1, p_{d-1}), ..., Tag'(0, p_0)) Tag'(i, p_i)=MAC_{K_2}(add(i, p_i)||ctr(i, p_i), ctr(i+1, 2p_i-1)||ctr(i+1, 2p_i)) where 0<=i<=d-1

[0352] Here, MAC_{K_2}(.) is substantially the same as the MAC method used in the tag generation unit 122c of the memory structure initialization device 12c in the sixth embodiment, so a description thereof will be omitted. Also, Tag'(i, p_i) is obtained by inputting the concatenation of the address of the node and the local counter into the nonce portion of the input of the MAC function, and inputting the concatenation of two local counters of child nodes of the node into the plaintext portion of the input of the MAC function.

[0353] Furthermore, the tag verifying unit 223c obtains a value expressed by the following formula 106 from the tree structure Tree that is the output of the tree structure input unit 220. PathTag=(Tag(d−1, p_{d−1}), . . . , Tag(0, p_0)) (Formula 106)

[0354] Then, the tag verification unit 223c checks whether the PathTag' calculated by itself is equal to the PathTag acquired from the tree. When 0<=i<=d-1, if Tag'(i,p_i)=Tag(i,p_i) holds for all i, the tag verification unit 223c sets the verification result to ACK. The verification result is represented as B, and the fact that the verification result is ACK is represented as B=ACK.

[0355] On the other hand, when 0<=i<=d−1, if Tag′(i, p_i)≠Tag(i, p_i) holds for a certain i, the tag verification unit 223 sets the verification result in NCK.

[0356] The tag verification unit 223 outputs the verification result B. The verification result output unit 224 is substantially the same as the verification result output unit 224 in the memory verification device 22 of the fourth embodiment, and therefore a description thereof will be omitted.

[0357] [Description of the Configuration of the Memory Update Device] The memory update device 32c according to the sixth embodiment includes a tree structure input unit 320, a memory address input unit 321, an update location input unit 322, a memory verification unit 323c, a counter update unit 324, a tag update unit 325c, and an update result output unit 326. The memory update device 32c according to the sixth embodiment also includes an update determination unit 330 and a plaintext update unit 332. The tree structure input unit 320 is substantially the same as the tree structure input unit 320 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted. The memory address input unit 321 is substantially the same as the memory address input unit 321 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted. The update location input unit 322 is substantially the same as the update location input unit 322 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted. The update determination unit 330 is substantially the same as the update determination unit 330 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted.

[0358] The memory verification unit 323c uses the tree structure Tree, the memory address set Add, the memory update information UpdateNode, and the secret keys K_1 and K_2 to verify whether the memory specified by UpdateNode has been tampered with. In other words, the memory verification unit 323c verifies whether the node corresponding to the path related to the leaf node specified by UpdateNode has been tampered with. The verification process performed by the memory verification unit 323c is substantially the same as that of the tag verification unit 223c in the memory verification device 22c of the sixth embodiment, but the output results are different. The tag verification unit 223c in the memory verification device 22c of the sixth embodiment outputs verification result B, but the memory verification unit 323c also outputs the path Path from the node to the root node along with verification result B. The memory verification unit 323c outputs the verification result B to the plaintext update unit 332, the counter update unit 324, the tag update unit 325c, and the update result output unit 326. The memory verification unit 323c also outputs the path Path to the counter update unit 324 and the tag update unit 325c.

[0359] Note that other functions of the memory verification unit 323c are substantially the same as those of the memory verification unit 323 according to the fourth embodiment, and therefore description thereof will be omitted. In other words, like the memory verification unit 323, the memory verification unit 323c may not verify the tag of a leaf node depending on the determination result of the update determination unit 330.

[0360] The plaintext update unit 332 is substantially the same as the plaintext update unit 332 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted. Also, the counter update unit 324 is substantially the same as the counter update unit 324 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted.

[0361] The tag update unit 325c updates the tag of the node specified by Path using the tree structure NewTree' of the update result, the memory address set Add, the memory update information UpdateNode, the verification result B, the path Path, and the private keys K_1 and K_2. If B=ACK, the tag update unit 325c performs the calculation of the following equation 107 for 0<=i<=d-1. (Equation 107) (C[p_d], Tag(d, p_d))←AE. Enc_{K_1} (add (d, p_d) | | ctr (d, p_d), UpdateInfo) Tag (i, p_i) ← MAC_{K_2} (add (i, p_i) | | ctr (i, p_i), ctr (i+1, 2p_i-1) | | ctr (i+1, 2p_i))

[0362] Note that AE.Enc_{K_1}(·,·), MAC_{K_2}(·), and IncMAC_{K_2} are substantially the same as those used in the tag generation unit 122c of the memory structure initialization device 12c and the tag verification unit 223c of the memory verification device 22c in the sixth embodiment. The tag update unit 325c then outputs the tree structure NewTree resulting from the update. On the other hand, if B=NCK, the tag update unit 325c does not perform any processing and does not output anything.

[0363] The update result output unit 326 is substantially the same as the update result output unit 326 in the memory update device 32 of the fourth embodiment, and therefore a description thereof will be omitted.

[0364] [Explanation of Effects] The sixth embodiment has the effect of enabling memory confidentiality in addition to the effect of the fourth embodiment. In the fourth embodiment, a MAC was used to detect tampering of a plaintext message. In contrast, in the sixth embodiment, by performing AE processing on a plaintext message, it is possible to detect tampering and also to conceal the plaintext message. Furthermore, the amount of calculation for AE is generally greater than or equal to the amount of calculation for MAC. Therefore, by making it possible to eliminate the need for integrity verification of leaf nodes during update processing as in this embodiment, it is possible to reduce the calculation of AE, which requires a large amount of calculation, and thereby further reduce the amount of calculation required for verification. Therefore, it is possible to perform node verification processing more efficiently when updating memory contents.

[0365] Furthermore, it is assumed that the AE used is a rate 1 scheme such as OCB, i.e., a scheme that can achieve plaintext encryption and authentication tag generation at the cost of encryption alone, and that a scheme can be adopted in which the data volumes of plaintext and ciphertext are the same. In this case, compared to the fourth embodiment, the data volume of the entire tree structure and the amount of calculation required by each device are almost unchanged. In other words, the sixth embodiment enables tamper detection and confidentiality with the same data volume and calculation volume as the fourth embodiment. Furthermore, although a binary tree is assumed for the tree structure in the sixth embodiment, it is naturally possible to use a tree structure with an increased number of branches, as in the fifth embodiment.

[0366] (Seventh Embodiment) Next, a seventh embodiment will be described. FIG. 25 is a diagram showing the configuration of a memory update device 500 according to the seventh embodiment. The memory update device 500 according to the seventh embodiment corresponds to the memory update device 30 and the memory update device 32 described above. The memory update device 500 has an input unit 502, an update determination unit 504, a memory verification unit 506, a plaintext update unit 508, and a tag update unit 510. The input unit 502 functions as input means. The update determination unit 504 functions as update determination means. The memory verification unit 506 functions as memory verification means. The plaintext update unit 508 functions as plaintext update means. The tag update unit 510 functions as tag update means.

[0367] The input unit 502 can be realized by functions substantially similar to the functions possessed by the above-described tree structure input unit 300, tree structure input unit 320, update location input unit 302, and update location input unit 322. The update determination unit 504 can be realized by functions substantially similar to the functions possessed by the above-described update determination unit 310 and update determination unit 330. The memory verification unit 506 can be realized by functions substantially similar to the functions possessed by the above-described memory verification unit 303 and memory verification unit 323. The plaintext update unit 508 can be realized by functions substantially similar to the functions possessed by the above-described plaintext update unit 312 and plaintext update unit 332. The tag update unit 510 can be realized by functions substantially similar to the functions possessed by the above-described tag update unit 305 and tag update unit 325.

[0368] The input unit 502 receives a tree structure configured to protect memory and update information, which is information about nodes to be updated in the tree structure. The update determination unit 504 uses the update information to determine whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update.

[0369] The memory verification unit 506 generates a path from a leaf node to a root node in a tree structure. Furthermore, for each node in the path, the memory verification unit 506 generates a tag to be used for verification by inputting at least a nonce unique to each node into a message authentication code, and verifies the tag stored in each node. The memory verification unit 506 thereby verifies whether each node has been tampered with and outputs the verification result.

[0370] If the verification result indicates that no tampering has been detected, the plaintext update unit 508 updates the plaintext to be updated in the leaf node based on the update information.If the verification result indicates that no tampering has been detected, the tag update unit 510 generates an updated tag by inputting at least a nonce unique to each node into a message authentication code.Here, if the update content of the leaf node does not depend on the plaintext before the update, the memory verification unit 506 verifies the tags of nodes other than the leaf node in the path.

[0371] Here, as described above, the update determination unit 504 may determine that the update content of the leaf node does not depend on the plaintext before the update when the update content of the leaf node replaces the plaintext to be updated with a fixed value independent of the plaintext. In this case, the plaintext update unit 508 may update the plaintext by replacing the plaintext to be updated in the leaf node with a fixed value. Furthermore, the update determination unit 504 may determine that the update content of the leaf node does not depend on the plaintext before the update when the update information includes a fixed value independent of the plaintext to be updated. Furthermore, the fixed value may be specified by the user.

[0372] Furthermore, when the memory update device 500 according to the seventh embodiment corresponds to the memory update device 30 according to the first or second embodiment, the memory update device 500 may be configured as follows. At each node in the path, the memory verification unit 506 may generate a tag used for verification by inputting a nonce and plaintext unique to each node, or a concatenation of a nonce and nonces at multiple child nodes of each node, into a message authentication code. The memory update device 500 may further include a component (nonce update unit; nonce update means) corresponding to the nonce update unit 304. In this case, the nonce update unit may update the nonce value at each node in the path when the verification result indicates that no tampering has been detected. In this case, the tag update unit 510 may generate an updated tag by inputting an updated nonce and updated plaintext at each node, or a concatenation of an updated nonce and updated nonces at multiple child nodes of each node, into a message authentication code.

[0373] Furthermore, when the memory update device 500 according to the seventh embodiment corresponds to the memory update device 30 according to the third embodiment, the memory update device 500 may be configured as follows. The memory verification unit 506 may generate a path from a leaf node including a ciphertext to be updated to a root node in a tree structure. The memory verification unit 506 may generate a tag used for verification at each node in the path by inputting a nonce and a concatenation of nonces at multiple child nodes of each node into a message authentication code. The memory verification unit 506 may verify whether the ciphertext has been tampered with by inputting the nonce, the ciphertext, and the tag used for verification into an authenticated ciphertext to verify whether the plaintext has been tampered with and output the verification result. The tag update unit 510 may generate an updated ciphertext and an updated tag by inputting the updated nonce and a concatenation of updated nonces at multiple child nodes of each node into a message authentication code and inputting the updated nonce and updated plaintext into an authenticated ciphertext.

[0374] Furthermore, when the memory update device 500 according to the seventh embodiment corresponds to the memory update device 32 according to the fourth or fifth embodiment, the memory update device 500 may be configured as follows. The input unit 502 may input a memory address assigned to a tree structure. The memory verification unit 506 may use, at each node in the path, a concatenation of the memory address unique to each node and a local counter stored in each node as a nonce. The memory verification unit 506 may then input the nonce and plaintext, or the nonce and a concatenation of local counters in multiple child nodes of each node, into a message authentication code to generate a tag used for verification. The memory update device 500 may further include a component (counter update unit; counter update means) corresponding to the counter update unit 324. In this case, the counter update unit may update the value of the local counter at each node in the path when the verification result indicates that no tampering has been detected. In this case, the tag update unit 510 may use, as a nonce, a concatenation of the memory address unique to each node and the updated local counter at each node. The tag update unit 510 may then generate an updated tag by inputting the nonce and the updated plaintext, or the nonce and a concatenation of the updated local counters at multiple child nodes of each node, into a message authentication code.

[0375] Furthermore, when the memory update device 500 according to the seventh embodiment corresponds to the memory update device 32 according to the sixth embodiment, the memory update device 500 may be configured as follows. The memory verification unit 506 may generate a path from a leaf node including the ciphertext to be updated to a root node in a tree structure. Furthermore, the memory verification unit 506 may use, at each node in the path, a concatenation of a memory address unique to each node and a local counter stored in each node as a nonce. Furthermore, the memory verification unit 506 may generate a tag used for verification by inputting the nonce and a concatenation of local counters in multiple child nodes of each node into a message authentication code. Furthermore, the memory verification unit 506 may input the nonce, the ciphertext, and the tag used for verification into an authentication encryption to verify whether the plaintext has been tampered with, thereby verifying whether the ciphertext has been tampered with and outputting the verification result. Furthermore, the tag update unit 510 may use, as a nonce, a concatenation of a memory address unique to each node and the updated local counter of each node. In addition, the tag update unit 510 may generate an updated ciphertext and an updated tag by inputting the nonce and a concatenation of updated local counters at multiple child nodes of each node into a message authentication code, and inputting the nonce and updated plaintext into an authentication encryption.

[0376] 26 is a flowchart showing a memory update method executed by the memory update device 500 according to the seventh embodiment. The input unit 502 inputs a tree structure and update information (step S503). The update determination unit 504 uses the update information to determine whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update (step S504). If the determination result in S504 is NO, that is, if the update content of the leaf node containing the plaintext to be updated does not depend on the plaintext before the update, the process proceeds to S506. On the other hand, if the determination result in S504 is YES, that is, if the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update, the process proceeds to S508.

[0377] If the update content of the leaf node does not depend on the plaintext before the update (NO in S504), the memory verification unit 506 verifies the tags of nodes other than the leaf node on the path from the leaf node to the root node (step S506). Specifically, the memory verification unit 506 generates a path from the leaf node to the root node in the tree structure. Furthermore, for each node on the path, the memory verification unit 506 generates tags to be used for verification by inputting at least a nonce unique to each node into a message authentication code, and verifies the tags stored in each node other than the leaf node. The memory verification unit 506 then outputs the verification result. If the verification result indicates that no tampering has been detected, the processes of S510 and S512 are executed.

[0378] On the other hand, if the update content of the leaf node depends on the plaintext before the update (YES in S504), the memory verification unit 506 verifies the tags of all nodes on the path from the leaf node to the root node (step S508). Specifically, the memory verification unit 506 generates a path from the leaf node to the root node in the tree structure. The memory verification unit 506 also generates tags to be used for verification at each node on the path by inputting at least a nonce unique to each node into a message authentication code, and verifies the tags stored in all nodes, including the leaf node. The memory verification unit 506 then outputs the verification result. If the verification result indicates that no tampering has been detected, the processes of S510 and S512 are executed.

[0379] If the verification result indicates that no tampering has been detected, the plaintext update unit 508 updates the plaintext to be updated in the leaf node based on the update information (step S510).If the verification result indicates that no tampering has been detected, the tag update unit 510 generates an updated tag by inputting at least a nonce unique to each node into the message authentication code (step S512).

[0380] As with the above-described embodiments, the memory update device 500 according to the seventh embodiment can reduce the amount of calculation required for verification compared to the techniques described in Patent Documents 2 and 3. Therefore, when updating memory contents, node verification can be performed efficiently. Note that, in cases where parallel processing is not possible, as in Patent Document 4, verification of tags related to leaf nodes may be unnecessary when verifying tags at nodes. However, the tree structures are completely different between cases where parallel processing is not possible, as in Patent Document 4, and cases where parallel processing is possible, as in this embodiment. Therefore, even if verification of tags related to leaf nodes can be eliminated using the technology described in Patent Document 4 to eliminate the need for verification of tags related to leaf nodes in a tree structure that enables parallel processing, security may be compromised. Therefore, from a security perspective, it is not easy to simply combine the technology described in Patent Document 4 with the technology described in Patent Documents 2 or 3 to eliminate the need for verification of tags related to leaf nodes.

[0381] (Hardware Configuration Example) An example of the configuration of hardware resources for realizing the devices and systems according to the above-described embodiments using one calculation processing device (information processing device, computer) will be described. However, the devices according to the embodiments (memory structure initialization device, memory verification device, and memory update device) may be physically or functionally realized using at least two calculation processing devices. Furthermore, the devices according to the embodiments may be realized as dedicated devices or may be realized by general-purpose information processing devices.

[0382] FIG. 27 is a block diagram illustrating an example of the hardware configuration of a calculation processing device capable of realizing the device and system according to each embodiment. The calculation processing device 1000 is a computer. The calculation processing device 1000 includes a CPU 1001, a volatile storage device 1002, a disk 1003, a non-volatile recording medium 1004, and a communication IF (Interface) 1007. Therefore, it can be said that the device according to each embodiment includes the CPU 1001, the volatile storage device 1002, the disk 1003, the non-volatile recording medium 1004, and the communication IF 1007. The calculation processing device 1000 may be connectable to an input device 1005 and an output device 1006. The calculation processing device 1000 may also include the input device 1005 and the output device 1006. Furthermore, the calculation processing device 1000 can transmit and receive information to and from other calculation processing devices and communication devices via the communication IF 1007.

[0383] The nonvolatile recording medium 1004 is a computer-readable medium, such as a compact disc or a digital versatile disc. The nonvolatile recording medium 1004 may also be a universal serial bus (USB) memory, a solid state drive, or the like. The nonvolatile recording medium 1004 stores the program and allows portability without requiring a power supply. The nonvolatile recording medium 1004 is not limited to the above-mentioned medium. Instead of the nonvolatile recording medium 1004, the program may be supplied via the communication IF 1007 and a communication network.

[0384] The volatile storage device 1002 is computer-readable and can temporarily store data. The volatile storage device 1002 is a memory such as a dynamic random access memory (DRAM) or a static random access memory (SRAM).

[0385] That is, when executing a software program (computer program; hereinafter simply referred to as "program") stored on disk 1003, CPU 1001 copies the program to volatile storage device 1002 and executes the arithmetic processing. CPU 1001 reads data necessary for executing the program from volatile storage device 1002. When display is required, CPU 1001 displays the output result on output device 1006. When inputting a program from the outside, CPU 1001 acquires the program from input device 1005. CPU 1001 interprets and executes programs corresponding to the functions (processing) of each component shown in FIGS. 2 to 4, 14 to 16, and 25 described above. CPU 1001 executes the processing described in each of the above-mentioned embodiments. In other words, the functions of each component shown in FIGS. 2 to 4, 14 to 16, and 25 described above can be realized by CPU 1001 executing a program stored on disk 1003 or volatile storage device 1002.

[0386] That is, each of the embodiments can be realized by the above-described program. Furthermore, each of the embodiments can be realized by a computer-readable non-volatile recording medium on which the above-described program is recorded.

[0387] (Modifications) The present invention is not limited to the above-described embodiment, and can be modified as appropriate without departing from the spirit of the present invention. For example, in the above-described flowchart, the order of each process (step) can be modified as appropriate. Furthermore, one or more of the multiple processes (steps) may be omitted.

[0388] Furthermore, in the above-described embodiment, the technology disclosed in Patent Documents 2 and 3 has been improved as a technology that enables parallelization of processing of each node in updating the contents of a memory, but the present disclosure is not limited to such a configuration. The technology disclosed herein can also be applied to technologies that enable parallelization of processing of nodes other than those disclosed in Patent Documents 2 and 3.

[0389] In the above examples, the program includes instructions (or software code) that, when loaded into a computer, cause the computer to perform one or more functions described in the embodiments. The program may be stored on a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD) or other memory technology, CD-ROM, digital versatile disk (DVD), Blu-ray disc or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage device. The program may also be transmitted on a transitory computer-readable medium or communication medium. By way of example and not limitation, transitory computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.

[0390] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the invention.

[0391] A part or all of the above-described embodiments can be described as, but not limited to, the following supplementary notes. 1. A memory updating device comprising: input means for inputting a tree structure configured to protect a memory and update information which is information relating to a node to be updated in the tree structure; update determination means for using the update information to determine whether or not an update content of a leaf node including plaintext to be updated depends on the plaintext before the update; memory verification means for generating a path from the leaf node to a root node in the tree structure, and for verifying whether or not each node has been tampered with by generating a tag to be used for verification at each node in the path by inputting at least a nonce unique to each node into a message authentication code and verifying the tag stored in each node, and outputting a verification result; plaintext updating means for updating the plaintext to be updated in the leaf node based on the update information if the verification result indicates that no tampering has been detected; and tag update means for generating an updated tag by inputting at least a nonce unique to each node into a message authentication code if the verification result indicates that no tampering has been detected, wherein the memory verification means verifies the tags of nodes other than the leaf node in the path if the update content of the leaf node does not depend on the plaintext before the update. (Supplementary Note 2) The memory update device according to Supplementary Note 1, wherein the memory verification means verifies tags of all nodes in the path including the leaf node if the update content of the leaf node depends on the plaintext before the update. (Supplementary Note 3) The memory update device according to Supplementary Note 1, wherein the update determination means determines that the update content of the leaf node does not depend on the plaintext before the update if the update content of the leaf node replaces the plaintext to be updated with a fixed value independent of the plaintext, and the plaintext update means updates the plaintext by replacing the plaintext to be updated in the leaf node with the fixed value. (Supplementary Note 4) The memory update device according to Supplementary Note 3, wherein the update determination means determines that the update content of the leaf node does not depend on the plaintext before the update if the update information includes the fixed value.(Supplementary Note 5) The memory update device according to Supplementary Note 1, wherein the update determination means determines that the update content of the leaf node does not depend on the plaintext before the update when the update information includes a fixed value independent of the plaintext to be updated, and the plaintext update means updates the plaintext by replacing the plaintext to be updated in the leaf node with the fixed value. (Supplementary Note 6) The memory update device according to Supplementary Note 4 or 5, wherein the fixed value in the update information is specified by a user. (Supplementary Note 7) The memory update device according to Supplementary Note 1, wherein the memory verification means generates a tag to be used for verification at each node in the path by inputting a nonce unique to each node and the plaintext, or a concatenation of the nonce and nonces at multiple child nodes of each node, into a message authentication code; and further comprises nonce update means that updates the value of the nonce at each node in the path when the verification result shows that no tampering has been detected; and the tag update means generates an updated tag by inputting an updated nonce and updated plaintext at each node, or an updated nonce and a concatenation of updated nonces at multiple child nodes of each node, into a message authentication code when the verification result shows that no tampering has been detected. (Supplementary Note 8) The memory updating device according to Supplementary Note 7, wherein the memory verifying means generates a path in the tree structure from the leaf node including the ciphertext to be updated to a root node, and at each node in the path, generates a tag to be used for verification by inputting the nonce and a concatenation of nonces at multiple child nodes of each node into a message authentication code, and verifies whether the ciphertext has been tampered with by inputting the nonce, the ciphertext, and the tag to be used for verification into an authentication cipher to verify whether the plaintext has been tampered with, and outputs a verification result; and when the verification result indicates that no tampering has been detected, the tag updating means inputs the updated nonce and a concatenation of updated nonces at multiple child nodes of each node into a message authentication code, and inputs the updated nonce and updated plaintext into an authentication cipher to generate an updated ciphertext and an updated tag.(Supplementary Note 9) The memory update device according to Supplementary Note 1, wherein the input means inputs a memory address assigned to the tree structure, and the memory verification means, at each node in the path, uses a concatenation of the memory address unique to each node and a local counter stored in each node as a nonce, and inputs the concatenation of the nonce and the plaintext, or the nonce and the local counters in multiple child nodes of each node, into a message authentication code to generate a tag used for verification, and further comprises counter update means for updating a value of the local counter at each node in the path when the verification result indicates that no tampering has been detected, and the tag update means, when the verification result indicates that no tampering has been detected, uses a concatenation of the memory address unique to each node and the updated local counters of each node as a nonce, and inputs the nonce and the updated plaintext, or the nonce and the updated local counters in multiple child nodes of each node, into a message authentication code to generate an updated tag. (Supplementary Note 10) The memory verification means generates a path from the leaf node including the ciphertext to be updated to a root node in the tree structure, and at each node in the path, generates a tag used for verification by using a nonce as a concatenation of the memory address unique to each node and a local counter stored in each node, and inputs the nonce and a concatenation of the local counters in multiple child nodes of each node into a message authentication code, verifies whether the ciphertext has been tampered with by inputting the nonce, the ciphertext, and the tag used for verification into an authentication ciphertext to verify whether the plaintext has been tampered with, and outputs a verification result; and when the verification result indicates that no tampering has been detected, the tag update means generates a nonce as a concatenation of the memory address unique to each node and the updated local counters in each node, and inputs the nonce and a concatenation of the updated local counters in multiple child nodes of each node into a message authentication code, and generates an updated ciphertext and an updated tag by inputting the nonce and the updated plaintext into an authentication ciphertext. 10. The memory update device according to claim 9.(Supplementary Note 11) A memory structure initialization device that receives plaintext for which tampering detection is desired as input and outputs at least a tree structure in an initial state that is configured to protect a memory; a memory verification device that receives at least a storage location of plaintext for which tampering is desired and the tree structure as input and verifies whether or not a memory corresponding to said storage location has been tampered with; a memory update device that receives at least a storage location of plaintext for which an update is desired and its update content and the tree structure as input and outputs the tree structure after the update or an error message indicating that tampering has been detected, wherein the memory update device comprises: input means for inputting the tree structure and update information that is information regarding a node to be updated in the tree structure; update determination means that uses the update information to determine whether or not the update content of a leaf node including the plaintext to be updated depends on the plaintext before the update; an information processing system comprising: a memory verification means for generating a path from the leaf node to a root node in the tree structure, and for each node in the path, generating a tag to be used for verification by inputting at least a unique nonce at each node into a message authentication code and verifying the tag stored at each node, thereby verifying whether each node has been tampered with and outputting a verification result; a plaintext update means for updating the plaintext to be updated in the leaf node based on the update information when the verification result shows that no tampering has been detected; and a tag update means for generating an updated tag by inputting at least a unique nonce at each node into a message authentication code when the verification result shows that no tampering has been detected, wherein the memory verification means verifies the tags of nodes other than the leaf node in the path when the update content of the leaf node does not depend on the plaintext before the update.(Supplementary Note 12) A memory update method comprising: inputting a tree structure configured to protect a memory and update information that is information about a node to be updated in the tree structure; determining, using the update information, whether or not an update content of a leaf node including plaintext to be updated depends on the plaintext before the update; if the update content of the leaf node does not depend on the plaintext before the update, generating a path from the leaf node to a root node in the tree structure; and, at each node in the path, generating a tag to be used for verification by inputting at least a unique nonce at each node into a message authentication code, and verifying the tag stored in a node other than the leaf node, thereby verifying whether or not each node has been tampered with, and outputting a verification result; if the verification result indicates that no tampering has been detected, updating the plaintext to be updated in the leaf node based on the update information; and if the verification result indicates that no tampering has been detected, generating an updated tag by inputting at least a unique nonce at each node into a message authentication code. (Supplementary Note 13) The memory updating method according to Supplementary Note 12, wherein, if the update content of the leaf node depends on the plaintext before the update, at each node in the path, a tag used for verification is generated by inputting at least a nonce unique to each node into a message authentication code, and the tag is verified by verifying the tags stored in all nodes in the path including the leaf node. (Supplementary Note 14) The memory updating method according to Supplementary Note 12, wherein, if the update content of the leaf node is to replace the plaintext to be updated with a fixed value independent of the plaintext, it is determined that the update content of the leaf node does not depend on the plaintext before the update, and the plaintext is updated by replacing the plaintext to be updated in the leaf node with the fixed value. (Supplementary Note 15) The memory updating method according to Supplementary Note 14, wherein, if the update information includes the fixed value, it is determined that the update content of the leaf node does not depend on the plaintext before the update.(Supplementary Note 16) The memory updating method according to Supplementary Note 12, wherein, if the update information includes a fixed value independent of the plaintext to be updated, it is determined that the update content of the leaf node does not depend on the plaintext before the update, and the plaintext to be updated in the leaf node is updated by replacing the plaintext to be updated with the fixed value. (Supplementary Note 17) The memory updating method according to Supplementary Note 15 or 16, wherein the fixed value in the update information is specified by a user. (Supplementary Note 18) The memory update method according to Supplementary Note 12, wherein at each node in the path, a tag to be used for verification is generated by inputting a nonce unique to each node and the plaintext, or a concatenation of the nonce and nonces at multiple child nodes of each node, into a message authentication code; if the verification result shows that no tampering has been detected, the value of the nonce at each node in the path is updated; and if the verification result shows that no tampering has been detected, an updated tag is generated by inputting an updated nonce and updated plaintext at each node, or an updated nonce and a concatenation of updated nonces at multiple child nodes of each node, into a message authentication code. (Supplementary Note 19) The memory update method according to Supplementary Note 18, comprising: generating, in the tree structure, a path from the leaf node including a ciphertext to be updated to a root node; at each node in the path, generating a tag to be used for verification by inputting the nonce and a concatenation of nonces at multiple child nodes of each node into a message authentication code; verifying whether the ciphertext has been tampered with by inputting the nonce, the ciphertext, and the tag to be used for verification into an authentication ciphertext to verify whether the plaintext has been tampered with, and outputting a verification result; and if the verification result indicates that no tampering has been detected, inputting the updated nonce and a concatenation of updated nonces at multiple child nodes of each node into a message authentication code, and inputting the updated nonce and updated plaintext into an authentication ciphertext to generate an updated ciphertext and an updated tag.(Supplementary Note 20) The memory update method according to Supplementary Note 12, comprising: inputting a memory address assigned to the tree structure; at each node in the path, using a nonce as a concatenation of the memory address unique to each node and a local counter stored in each node; and inputting the nonce and the plaintext, or the nonce and the local counters in multiple child nodes of each node, into a message authentication code to generate a tag to be used for verification; if the verification result indicates that no tampering has been detected, updating the value of the local counter at each node in the path; if the verification result indicates that no tampering has been detected, using a nonce as a concatenation of the memory address unique to each node and the updated local counters of each node, and inputting the nonce and the updated plaintext, or the nonce and the updated local counters in multiple child nodes of each node, into a message authentication code to generate an updated tag. (Supplementary Note 21) The memory update method according to Supplementary Note 20, further comprising the steps of: generating, in the tree structure, a path from the leaf node including a ciphertext to be updated to a root node; at each node in the path, a nonce is generated by concatenating the memory address unique to each node with a local counter stored in each node; generating a tag to be used for verification by inputting the nonce and the concatenation of the local counters in multiple child nodes of each node into a message authentication code; verifying whether the ciphertext has been tampered with by inputting the nonce, the ciphertext, and the tag to be used for verification into an authentication ciphertext to verify whether the plaintext has been tampered with, and outputting a verification result; and if the verification result indicates that no tampering has been detected, generating an updated ciphertext and an updated tag by inputting the nonce, the concatenation of the memory address unique to each node with the updated local counters in each child node of each node into a message authentication code;a step of inputting a tree structure configured to protect memory and update information that is information about a node to be updated in the tree structure; a step of determining, using the update information, whether or not the update content of a leaf node including plaintext to be updated depends on the plaintext before the update; a step of generating a path from the leaf node to a root node in the tree structure in the case where the update content of the leaf node does not depend on the plaintext before the update, and at each node in the path, generating a tag to be used for verification by inputting at least a unique nonce at each node into a message authentication code, and verifying the tag stored in a node other than the leaf node, thereby verifying whether each node has been tampered with, and outputting the verification result; a step of updating the plaintext to be updated in the leaf node based on the update information in the case where the verification result indicates that no tampering has been detected; and a step of generating an updated tag by inputting at least a unique nonce at each node into a message authentication code in the case where the verification result indicates that no tampering has been detected.

[0392] 1 Memory protection system 10 Memory structure initialization device 100 Plain text input unit 101 Nonce assignment unit 102 Tag generation unit 103 Leaf node generation unit 104 Intermediate node generation unit 105 Root node generation unit 106 Tree structure output unit 12 Memory structure initialization device 120 Plain text input unit 121 Memory address assignment unit 122 Tag generation unit 123 Leaf node generation unit 124 Intermediate node generation unit 125 Root node generation unit 126 Tree structure output unit 127 Memory address output unit 20 Memory verification device 200 Tree structure input unit 202 Verification point input unit 203 Tag verification unit 204 Verification result output unit 22 Memory verification device 220 Tree structure input unit 221 Memory address input unit 222 Verification point input unit 223 Tag verification unit 224 Verification result output unit 30 Memory update device 300 Tree structure input unit 302 Update location input unit 303 Memory verification unit 304 Nonce update unit 305 Tag update unit 306 Update result output unit 310 Update determination unit 312 Plain text update unit 32 Memory update device 320 Tree structure input unit 321 Memory address input unit 322 Update location input unit 323 Memory verification unit 324 Counter update unit 325 Tag update unit 326 Update result output unit 330 Update determination unit 332 Plain text update unit 500 Memory update device 502 Input unit 504 Update determination unit 506 Memory verification unit 508 Plain text update unit 510 Tag update unit

Claims

1. Input means for inputting a tree structure configured to protect a memory and update information which is information regarding a node updated in the tree structure; Update determination means for determining, using the update information, whether the update content of a leaf node including the plaintext to be updated depends on the plaintext before update; Memory verification means for generating a path from the leaf node to the root node in the tree structure, and at each node in the path, generating a tag used for verification by inputting at least a nonce unique to each node into a message authentication code and verifying the tag stored in each node, thereby verifying whether each node has been tampered with and outputting a verification result; Plaintext update means for updating the plaintext of the update target in the leaf node based on the update information when the verification result indicates that no tampering has been detected; Tag update means for generating an updated tag by inputting at least a nonce unique to each node into a message authentication code when the verification result indicates that no tampering has been detected; comprising; when the update content of the leaf node does not depend on the plaintext before update, the memory verification means verifies the tags of the nodes other than the leaf node in the path; Memory update device.

2. when the update content of the leaf node depends on the plaintext before update, the memory verification means verifies the tags of all nodes including the leaf node in the path; The memory update device according to claim 1.

3. when the update content of the leaf node replaces the plaintext to be updated with a fixed value independent of the plaintext, the update determination means determines that the update content of the leaf node does not depend on the plaintext before update; The plaintext update means updates the plaintext by replacing the plaintext of the update target in the leaf node with the fixed value; The memory update device according to claim 1.

4. when the fixed value is included in the update information, the update determination means determines that the update content of the leaf node does not depend on the plaintext before update; The memory update device according to claim 3.

5. when the update information includes a fixed value independent of the plaintext to be updated, the update determination means determines that the update content of the leaf node does not depend on the plaintext before update; The plaintext update means updates the plaintext by replacing the plaintext to be updated in the leaf node with the fixed value. The memory update device according to claim 1.

6. The fixed value in the update information is specified by the user. The memory update device according to claim 4 or 5.

7. The memory verification means generates a tag used for verification by inputting, for each node in the path, the nonce unique to each node and the plaintext, or the concatenation of the nonces in the nonce and the plurality of child nodes of each node, into the message authentication code. When the verification result indicates that no forgery is detected, it further has nonce update means for updating the value of the nonce in each node in the path. When the verification result indicates that no forgery is detected, the tag update means generates an updated tag by inputting the updated nonce and the updated plaintext in each node, or the concatenation of the updated nonces in the plurality of child nodes of each node, into the message authentication code. The memory update device according to claim 1.

8. The memory verification means generates a path from the leaf node containing the ciphertext to be updated to the root node in the tree structure, and generates a tag used for verification by inputting, for each node in the path, the concatenation of the nonce and the nonces in the plurality of child nodes of each node, into the message authentication code. By inputting the nonce, the ciphertext, and the tag used for verification into the authentication cipher to verify whether the plaintext has been forged, it verifies whether the ciphertext has been forged and outputs a verification result. When the verification result indicates that no forgery is detected, the tag update means inputs the concatenation of the updated nonce and the updated nonces in the plurality of child nodes of each node into the message authentication code, and inputs the updated nonce and the updated plaintext into the authentication cipher to generate an updated ciphertext and an updated tag. The memory update device according to claim 7.

9. The input means inputs the memory address assigned to the tree structure. The memory verification means takes, at each node in the path, the concatenation of the memory address unique to each node and the local counter stored in each node as a nonce, and inputs the nonce and the plaintext, or the concatenation of the nonce and the local counters in the plurality of child nodes of each node into a message authentication code to generate a tag used for verification. When the verification result indicates that no forgery is detected, it further has counter update means for updating the value of the local counter at each node in the path. When the verification result indicates that no forgery is detected, the tag update means takes, as a nonce, the concatenation of the memory address unique to each node and the updated local counter at each node, and inputs the nonce and the updated plaintext, or the concatenation of the nonce and the updated local counters in the plurality of child nodes of each node into a message authentication code to generate an updated tag. The memory update device according to claim 1.

10. The memory verification means generates a path from the leaf node containing the ciphertext to be updated to the root node in the tree structure. At each node in the path, the concatenation of the memory address unique to each node and the local counter stored in each node is taken as a nonce, and the concatenation of the nonce and the local counters in the plurality of child nodes of each node is input into a message authentication code to generate a tag used for verification. The nonce, the ciphertext, and the tag used for verification are input into an authentication cipher to verify whether the plaintext has been forged, thereby verifying whether the ciphertext has been forged and outputting a verification result. When the verification result indicates that no forgery is detected, the tag update means takes, as a nonce, the concatenation of the memory address unique to each node and the updated local counter at each node, inputs the concatenation of the nonce and the updated local counters in the plurality of child nodes of each node into a message authentication code, and inputs the nonce and the updated plaintext into an authentication cipher to generate an updated ciphertext and an updated tag. The memory update device according to claim 9.

11. A memory structure initialization device that takes as input the plaintext for which forgery detection is desired and outputs at least a tree structure in an initial state and configured to protect the memory. A memory verification device that takes as input at least the storage location of the plaintext for which forgery is to be checked and the tree structure, and verifies whether the memory corresponding to the storage location has been forged. A memory update device that takes as input at least the storage location of the plaintext to be updated, the update content thereof, and the tree structure, and outputs an updated tree structure or an error message indicating that forgery has been detected. It has The memory update device Input means for inputting the tree structure and update information which is information about the node to be updated in the tree structure. Update determination means for determining, using the update information, whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update. In the tree structure, a path from the leaf node to the root node is generated, and at each node in the path, at least a tag used for verification is generated by inputting a nonce unique to each node into a message authentication code and verifying the tag stored in each node, thereby verifying whether each node has been forged, and outputting the verification result. When the verification result indicates that no forgery has been detected, plaintext update means for updating the plaintext to be updated in the leaf node based on the update information. When the verification result indicates that no forgery has been detected, tag update means for generating an updated tag by inputting at least a nonce unique to each node into a message authentication code. It has When the update content of the leaf node does not depend on the plaintext before the update, the memory verification means verifies the tags of the nodes other than the leaf node in the path. An information processing system.

12. Input a tree structure configured to protect the memory and update information which is information about the node to be updated in the tree structure. Using the update information, determine whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update. When the update content of the leaf node does not depend on the plaintext before update, in the tree structure, generate a path from the leaf node to the root node, and at each node in the path, generate a tag for verification by inputting at least a nonce unique to each node into the message authentication code, and verify the tag stored in the node other than the leaf node, thereby verifying whether each node has been tampered with, and output the verification result. When the verification result indicates that no tampering is detected, update the plaintext to be updated in the leaf node based on the update information. When the verification result indicates that no tampering is detected, generate an updated tag by inputting at least a nonce unique to each node into the message authentication code. Memory update method.

13. When the update content of the leaf node depends on the plaintext before update, at each node in the path, generate a tag for verification by inputting at least a nonce unique to each node into the message authentication code, and verify the tag stored in all nodes including the leaf node in the path, thereby verifying whether each node has been tampered with. The memory update method according to claim 12.

14. When the update content of the leaf node is to replace the plaintext to be updated with a fixed value independent of the plaintext, determine that the update content of the leaf node does not depend on the plaintext before update. Update the plaintext by replacing the plaintext to be updated in the leaf node with the fixed value. The memory update method according to claim 12.

15. When the update information includes the fixed value, determine that the update content of the leaf node does not depend on the plaintext before update. The memory update method according to claim 14.

16. When the update information includes a fixed value independent of the plaintext to be updated, determine that the update content of the leaf node does not depend on the plaintext before update. Update the plaintext by replacing the plaintext to be updated in the leaf node with the fixed value. The memory update method according to claim 12.

17. The fixed value in the update information is specified by the user. The memory update method according to claim 15 or 16.

18. At each node in the path, a tag used for verification is generated by inputting the unique nonce of each node and the plaintext in the path, or the concatenation of the nonce and the nonces in a plurality of child nodes of each node into a message authentication code. When the verification result indicates that no forgery is detected, update the value of the nonce at each node in the path. When the verification result indicates that no forgery is detected, a new tag is generated by inputting the updated nonce and the updated plaintext at each node, or the concatenation of the updated nonce and the updated nonces in a plurality of child nodes of each node into a message authentication code. The memory update method according to claim 12.

19. In the tree structure, a path from the leaf node containing the ciphertext to be updated to the root node is generated. At each node in the path, a tag used for verification is generated by inputting the concatenation of the nonce and the nonces in a plurality of child nodes of each node into a message authentication code. By inputting the nonce, the ciphertext, and the tag used for verification into an authentication cipher to verify whether the plaintext has been forged, it is verified whether the ciphertext has been forged, and a verification result is output. When the verification result indicates that no forgery is detected, a new ciphertext and a new tag are generated by inputting the concatenation of the updated nonce and the updated nonces in a plurality of child nodes of each node into a message authentication code and inputting the updated nonce and the updated plaintext into an authentication cipher. The memory update method according to claim 18.

20. Input the memory address assigned to the tree structure. At each node in the path, the concatenation of the unique memory address of each node and the local counter stored in each node is used as a nonce. A tag used for verification is generated by inputting the concatenation of the nonce and the plaintext, or the concatenation of the nonce and the local counters in a plurality of child nodes of each node into a message authentication code. When the verification result indicates that no forgery is detected, update the value of the local counter at each node in the path. When the verification result indicates that no forgery is detected, concatenate the unique memory address of each node with the updated local counter of each node as a nonce, and input the nonce and the updated plaintext, or the concatenation of the nonce and the updated local counters in a plurality of child nodes of each node into a message authentication code to generate an updated tag. The memory update method according to claim 12.

21. In the tree structure, generate a path from the leaf node containing the ciphertext to be updated to the root node. At each node in the path, concatenate the unique memory address of each node with the local counter stored in each node as a nonce, and input the concatenation of the nonce and the local counters in a plurality of child nodes of each node into a message authentication code to generate a tag used for verification. Input the nonce, the ciphertext, and the tag used for verification into an authentication cipher to verify whether the plaintext has been forged, thereby verifying whether the ciphertext has been forged and outputting a verification result. When the verification result indicates that no forgery is detected, concatenate the unique memory address of each node with the updated local counter of each node as a nonce, input the concatenation of the nonce and the updated local counters in a plurality of child nodes of each node into a message authentication code, and input the nonce and the updated plaintext into an authentication cipher to generate an updated ciphertext and an updated tag. The memory update method according to claim 20.

22. A step of inputting a tree structure configured to protect a memory and update information which is information regarding a node updated in the tree structure. A step of determining, using the update information, whether the update content of the leaf node containing the plaintext to be updated depends on the plaintext before the update. If the updated content of the leaf node does not depend on the plaintext before the update, in the tree structure, generate a path from the leaf node to the root node, and at each node in the path, generate a tag used for verification by inputting at least the nonce unique to each node into the message authentication code, and verify the tag stored in the node other than the leaf node, and verify whether each node has been tampered with, and output the verification result; When the verification result indicates that no tampering is detected, update the plaintext to be updated in the leaf node based on the update information; When the verification result indicates that no tampering is detected, generate an updated tag by inputting at least the nonce unique to each node into the message authentication code; A program for causing a computer to execute.