Program management device, program management method, and program
Patent Information
- Application Number
- JP2024557306
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-05-08
- Publication Date
- 2025-07-17
AI Technical Summary
Industrial machines using general-purpose computers as control devices face issues with unauthorized program extraction and copying, as existing security systems rely on online verification, which fails when machines operate offline, leading to potential unauthorized execution of illegally copied programs.
A program management device utilizing a security chip to seal and unseal encryption keys, allowing only authorized execution of programs by decrypting them using the unsealed key, ensuring that programs can be executed securely offline without online communication.
Prevents execution of illegally copied programs while enabling proper use of programs offline by ensuring that only authorized execution is possible, even when machines are not connected to a network.
Abstract
Description
Program management device, program management method, and computer-readable recording medium
[0001] The present disclosure relates to a program management device and a program management method for preventing unauthorized use of programs, and further to a computer-readable recording medium on which a program for realizing these is recorded.
[0002] Conventionally, automated industrial machines have been used in factories to reduce labor. Examples of industrial machines include belt conveyors, door opening / closing devices, and defective product detection devices. In such industrial machines, automation is achieved by a control device that controls each part of the machine according to a control program.
[0003] In order to reduce costs, general-purpose computers are often used as control devices for industrial machinery. However, this poses a problem in that the control programs can be easily extracted from the computers and copied.
[0004] To solve this problem, a mechanism is needed to prevent illegally copied programs from being executed on a computer other than the original computer. For example, Patent Document 1 discloses a system that allows only programs with matching identification information to be executed.
[0005] In the system disclosed in Patent Document 1, a security chip acquires in advance from a software distributor identification information that identifies the latest version number. Then, when a program that constitutes the software is loaded into memory, the security chip checks the version number of the loaded program against the identification information. If the result of the check shows that the program version number is not the latest, the program is forcibly terminated.
[0006] JP 2010-61182 A
[0007] However, industrial machines are sometimes used without being connected to a network. This is to prevent attacks on the control devices via the network. In such cases, since identification information cannot be obtained, the system disclosed in Patent Document 1 cannot execute the program even on an authorized computer.
[0008] An example of an objective of the present disclosure is to prevent the execution of illegally copied programs while realizing proper offline use of programs.
[0009] In order to achieve the above object, a program management device according to one aspect of the present disclosure is characterized by comprising: a sealing unit that uses a security chip to seal an encryption key used to encrypt an executable program; an unsealing unit that uses the security chip to unseal the encryption key when execution of the executable program begins; and a program execution unit that decrypts the executable program using the unsealed encryption key, making the decrypted executable program executable.
[0010] In addition, in order to achieve the above object, a program management method according to one aspect of the present disclosure is characterized by having: a sealing step of sealing an encryption key used to encrypt an executable program using a security chip; an unsealing step of unsealing the encryption key using the security chip when execution of the executable program starts; and a program execution step of decrypting the executable program using the unsealed encryption key, thereby making the decrypted executable program executable.
[0011] Furthermore, in order to achieve the above object, a computer-readable recording medium according to one aspect of the present disclosure is characterized in that it records a program including instructions for causing a computer to execute the following steps: a sealing step of sealing an encryption key used to encrypt an executable program using a security chip; an unsealing step of unsealing the encryption key using the security chip when execution of the executable program begins; and a program execution step of decrypting the executable program using the unsealed encryption key, thereby making the decrypted executable program executable.
[0012] As described above, according to the present disclosure, it is possible to prevent the execution of illegally copied programs while realizing the proper use of programs offline.
[0013] FIG. 1 is a configuration diagram showing a schematic configuration of an example of a program management device. FIG. 2 is a configuration diagram specifically showing the configuration of an example of a program management device. FIG. 3 is a flow diagram showing an example of the operation of the program management device before shipping of an industrial machine. FIG. 4 is a block diagram for explaining the operation shown in FIG. 3. In FIG. 4, only the functional blocks that operate are shown. FIG. 5 is a flow diagram showing an example of the operation of the program management device after shipping of an industrial machine. FIG. 6 is a block diagram for explaining the operation shown in FIG. 5. In FIG. 6, only the functional blocks that operate are shown. FIG. 7 is a block diagram showing an example of a computer that realizes the program management device.
[0014] (Embodiments) In the first embodiment, examples of a program management device, a program management device, and a program will be described below with reference to FIGS.
[0015] [Device Configuration] First, the schematic configuration of an example of a program management device will be described with reference to Fig. 1. Fig. 1 is a diagram showing the schematic configuration of an example of a program management device.
[0016] 1, a program management device 10 is a device for preventing unauthorized use of programs used in a computer. As shown in FIG. 1, the program management device 10 includes a sealing unit 11, an unsealing unit 12, and a program execution unit 13.
[0017] The sealing unit 11 uses a security chip to seal the encryption key used to encrypt the executable program. The unsealing unit 12 uses the security chip to unseal the encryption key when the executable program starts to run. The program execution unit 13 then decrypts the executable program using the unsealed encryption key, making the decrypted executable program executable.
[0018] In this way, the program management device 10 allows encrypted programs to be executed without online communication, thereby realizing proper offline use of programs. Furthermore, since the executable program can only be executed by the program management device 10, the execution of an illegally copied executable program is prevented.
[0019] Next, the configuration and functions of an example of a program management device will be specifically described with reference to Fig. 2. Fig. 2 is a configuration diagram specifically showing the configuration of an example of a program management device.
[0020] As shown in Figure 2, in this embodiment, the program management device 10 is constructed by a program on an operating system 20 of a computer 100. The program that constructs the program management device 10 is a separate program from the execution program described above (execution program 22 in Figure 2). The program that constructs the program management device 10 will be described later. In this embodiment, the computer 100 is incorporated into industrial machinery and functions as a control device for the industrial machinery.
[0021] The computer 100 includes a processor 30 and a memory 40. An execution program 22 is managed by an operating system 20. In the computer 100, the processor 30 includes a security chip 31. The encryption key 21 is generated by an encryption key generation unit 14 of the program management device 10, as will be described later.
[0022] The security chip 31 has a function of allowing only a program that has been sealed to execute unsealing. In the embodiment, when the program management device 10 executes sealing of the encryption key 21, the security chip 31 allows only the program management device 10 to execute unsealing. "Sealing" refers to encryption using the value of the platform configuration register of the security chip 31 and a private key generated by the security chip. Furthermore, the security chip 31 may be configured as a chip independent from the processor 30.
[0023] A specific example of the security chip 31 is a TPM (Trusted Platform Module). The TPM is a module that includes an encryption algorithm engine, a hash engine, a key generator, a random number generator, and the like, and provides various security functions. Another specific example of the security chip 31 is Intel (registered trademark) SGX (Software Guard Extensions). Intel SGX is provided as an extension function of the Intel CPU (Central Processing Unit).
[0024] As shown in FIG. 2, the program management device 10 includes an encryption key generation unit 14 and an encryption processing unit 15 in addition to the sealing unit 11, unsealing unit 12, and program execution unit 13 described above.
[0025] Before shipping the industrial machine, the encryption key generation unit 14 generates an encryption key 21. The encryption processing unit 15 uses the encryption key 21 to encrypt the execution program 22 and stores the encrypted execution program 22 as resource data.
[0026] As described above, the sealing unit 11 uses the security chip 31 to seal the encryption key 21 used to encrypt the execution program 22. The sealing of the encryption key 21 by the sealing unit 11 is also performed before the shipping of the above-mentioned industrial machine.
[0027] The unsealing unit 12 executes processing when the industrial machine is started up after shipment. In the embodiment, when the unsealing unit 12 is instructed to start the execution program 22, it first receives execution control from the operating system 20 instead of the execution program 22. The unsealing unit 12 then unseals the sealed encryption key 21 using the security chip 31. As a result, the encryption key 21 is no longer sealed.
[0028] The program execution unit 13 decrypts the execution program 22 using the unsealed encryption key 21 and maps the decrypted execution program 22 to the memory 40. This makes the execution program 22 executable. Specifically, the program execution unit 13 analyzes the format of the execution program 22, which has been decrypted into plain text, and places the execution program 22 in the memory 40 in the same state as when the operating system 20 starts the execution program 22.
[0029] The program execution unit 13 then executes the decrypted execution program 22. Specifically, the program execution unit 13 uses the functions of the operating system 20 to start up the execution program 22 located in the memory 40.
[0030] The sealing unit 11 and the program execution unit 13 may not be configured before or at the time of shipping the industrial machine. The sealing unit 11 and the program execution unit 13 may be configured by the program management device 10 when the industrial machine is started up.
[0031] [Device Operation] Next, the operation of program management device 10 will be described using Figures 3 and 4. In the following description, Figures 1 and 2 will be referenced as appropriate. In addition, in the embodiment, a program management method is implemented by operating program management device 10. Therefore, the description of the program management method in the embodiment will be replaced by the following description of the operation of program management device 10.
[0032] First, the operation of the program management device 10 before shipping of the industrial machine to which the program management device 10 is applied will be described. Fig. 3 is a flow diagram showing an example of the operation of the program management device before shipping of the industrial machine. Fig. 4 is a block diagram for explaining the operation shown in Fig. 3. Fig. 4 shows only the functional blocks that operate.
[0033] 3 and 4, in the program management device 10, the encryption key generation unit 14 first generates the encryption key 21 (step A1). Next, the encryption processing unit 15 uses the encryption key 21 to encrypt the execution program 22 (step A2). In step A2, the encrypted execution program 22 is stored as resource data.
[0034] Next, the sealing unit 11 uses the security chip to seal the encryption key 21 used to encrypt the execution program 22 (step A3). Thereafter, the industrial machine is shipped with the execution program 22 encrypted and the encryption key 21 sealed.
[0035] Next, the operation of the program management device 10 after the shipment of the industrial machine will be described with reference to Figures 5 and 6. Figure 5 is a flow diagram showing an example of the operation of the program management device after the shipment of the industrial machine. Figure 6 is a block diagram for explaining the operation shown in Figure 5. Figure 6 shows only the functional blocks that operate.
[0036] First, after the industrial machine is shipped, when an instruction to start the execution program 22 is given, the unsealing unit 12 receives execution control from the operating system 20 instead of the execution program 22 (step B1). Note that before the execution of step B1, the sealing unit 11 and the program execution unit 13 may be constructed by the program management device 10.
[0037] Next, the unsealing unit 12 uses the security chip 31 to unseal the encryption key 21 (step B2).
[0038] Next, the program execution unit 13 decrypts the execution program 22 using the unsealed encryption key 21, and places the decrypted execution program 22 in the memory 40 (step B3).
[0039] Thereafter, the program execution unit 13 uses the functions of the operating system 20 to execute the execution program 22 placed in the memory (step B4).
[0040] As described above, in this embodiment, the program management device 10 makes the encrypted program executable without online communication. As a result, proper use of the program is realized even in an environment where online access is not possible. Furthermore, even if an attempt is made to execute an illegally copied execution program 22 on another computer, the execution program 22 cannot be executed because the encryption key 21 required to execute the execution program 22 cannot be unsealed on the other computer.
[0041] [Program] The following describes a program in the embodiment for constructing the program management device 10. The program in the embodiment is not the execution program 22 described above.
[0042] In terms of execution, the program may be any program that causes a computer to execute steps A1 to A3 shown in Fig. 3 and steps B1 to B4 shown in Fig. 5. By installing and executing this program on a computer, the program management device 10 and program management method according to the embodiment can be realized. In this case, the processor of the computer functions as a sealing unit 11, an unsealing unit 12, a program execution unit 13, an encryption key generation unit 14, and an encryption processing unit 15, and performs the processing.
[0043] The computer referred to here is the computer 100 shown in Fig. 2. Examples of the computer include a general-purpose PC, a smartphone, and a tablet terminal device.
[0044] [Physical Configuration] An example of a computer 100 that implements the program management device 10 by executing a program in the embodiment will now be described with reference to Fig. 4. Fig. 7 is a block diagram showing an example of a computer that implements the program management device.
[0045] 7, the computer 100 includes a CPU (Central Processing Unit) 111, a main memory 112, a storage device 113, an input interface 114, a display controller 115, a data reader / writer 116, and a communication interface 117. These components are connected to each other via a bus 121 so as to be able to communicate data with each other.
[0046] Furthermore, the computer 100 may include a GPU (Graphics Processing Unit) or an FPGA (Field-Programmable Gate Array) in addition to or instead of the CPU 111. In this aspect, the GPU or FPGA can execute the programs in the embodiments.
[0047] The CPU 111 loads a program in the embodiment, which is composed of a group of codes and stored in the storage device 113, into the main memory 112 and executes each code in a predetermined order to perform various calculations. The main memory 112 is typically a volatile storage device such as a DRAM (Dynamic Random Access Memory).
[0048] The program in the embodiment is provided in a state stored in a computer-readable recording medium 120. The program in the embodiment may be distributed over the Internet connected via the communication interface 117.
[0049] Specific examples of the storage device 113 include a hard disk drive and a semiconductor storage device such as a flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and a mouse. The display controller 115 is connected to a display device 119 and controls the display on the display device 119.
[0050] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120, reads programs from the recording medium 120, and writes processing results from the computer 100 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.
[0051] Specific examples of the recording medium 120 include general-purpose semiconductor storage devices such as CF (Compact Flash (registered trademark)) and SD (Secure Digital), magnetic recording media such as flexible disks, or optical recording media such as CD-ROMs (Compact Disk Read Only Memory).
[0052] The program management device 10 in the embodiment can be realized not by a computer on which a program is installed, but by hardware corresponding to each part, such as an electronic circuit. Furthermore, the program management device 10 may be realized in part by a program and the remaining part by hardware. In the embodiment, the computer is not limited to the computer shown in FIG. 7.
[0053] Some or all of the above-described embodiments can be expressed by (Supplementary Note 1) to (Supplementary Note 9) described below, but are not limited to the following descriptions.
[0054] (Supplementary Note 1) A program management device comprising: a sealing unit that uses a security chip to seal an encryption key used to encrypt an execution program; an unsealing unit that uses the security chip to unseal the encryption key when execution of the execution program starts; and a program execution unit that decrypts the execution program using the unsealed encryption key, making the decrypted execution program executable.
[0055] (Supplementary Note 2) The program management device according to Supplementary Note 1, wherein the security chip has a function of permitting only the program management device that is the entity that executes the sealing to execute unsealing.
[0056] (Supplementary Note 3) The program management device according to Supplementary Note 1 or 2, wherein the program execution unit makes the decrypted execution program executable by mapping the decrypted execution program to a memory.
[0057] (Supplementary Note 4) A program management method comprising: a sealing step of sealing an encryption key used to encrypt an execution program using a security chip; an unsealing step of unsealing the encryption key using the security chip when execution of the execution program starts; and a program execution step of decrypting the execution program using the unsealed encryption key, thereby making the decrypted execution program executable.
[0058] (Supplementary Note 5) The program management method according to Supplementary Note 4, wherein the security chip has a function of permitting only an entity that executes sealing to execute unsealing.
[0059] (Supplementary Note 6) The program management method according to Supplementary Note 4 or 5, wherein in the program execution step, the decrypted execution program is made executable by mapping the decrypted execution program to a memory.
[0060] (Supplementary Note 7) A program causing a computer to execute the following steps: a sealing step of sealing an encryption key used to encrypt an executable program using a security chip; an unsealing step of unsealing the encryption key using the security chip when execution of the executable program starts; and a program execution step of decrypting the executable program using the unsealed encryption key, thereby making the decrypted executable program executable.
[0061] (Supplementary Note 8) The program according to Supplementary Note 7, wherein the security chip has a function of permitting only an entity that executes sealing to execute unsealing.
[0062] (Supplementary Note 9) The program according to Supplementary Note 7 or 8, wherein in the program execution step, the decrypted execution program is made executable by mapping the decrypted execution program to a memory.
[0063] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.
[0064] This application claims priority based on Japanese Patent Application No. 2022-180764, filed November 11, 2022, the disclosure of which is incorporated herein by reference in its entirety.
[0065] As described above, the present disclosure enables proper offline use of programs while preventing the execution of illegally copied programs. The present disclosure is useful, for example, in the field of industrial machinery that uses general-purpose computers as control devices.
[0066] 10 Program management device 11 Sealing unit 12 Unsealing unit 13 Program execution unit 20 Operating system 20 21 Encryption key 22 Execution program 30 Processor 31 Security chip 40 Memory 100 Computer 111 CPU 112 Main memory 113 Storage device 114 Input interface 115 Display controller 116 Data reader / writer 117 Communication interface 118 Input device 119 Display device 120 Recording medium 121 Bus
Claims
1. A sealing unit that seals an encryption key used for encrypting an execution program using a security chip; An unsealing unit that unseals the encryption key using the security chip when the execution of the execution program starts; A program execution unit that decrypts the execution program using the unsealed encryption key and makes the decrypted execution program executable; A program management apparatus comprising the above, characterized in that.
2. The security chip has a function of permitting execution of unsealing only to the program management apparatus which is the execution entity of sealing. The program management apparatus according to Claim 1.
3. The program execution unit makes the decrypted execution program executable by mapping the decrypted execution program to a memory. The program management apparatus according to Claim 1.
4. Using a security chip to seal an encryption key used for encrypting an execution program; When starting execution of the execution program, using the security chip to unseal the encryption key; Using the unsealed encryption key to decrypt the execution program and making the decrypted execution program executable; A program management method characterized by the above.
5. The security chip has a function of permitting execution of unsealing only to the execution entity of sealing. The program management method according to Claim 4.
6. When making the execution program executable, the decrypted execution program is made executable by mapping the decrypted execution program to a memory. The program management method according to Claim 4.
7. A program for causing a computer to execute a step of sealing an encryption key used for encrypting an execution program using a security chip; execute a step of unsealing the encryption key using the security chip when starting execution of the execution program; execute a step of decrypting the execution program using the unsealed encryption key and making the decrypted execution program executable.
8. The security chip has a function of permitting execution of unsealing only to the execution entity of sealing. The program according to claim 7.
9. In the step of making the execution program executable, by mapping the decoded execution program to a memory, the decoded execution program is made executable. The program according to claim 7.