Unauthorized use prevention system and unauthorized use prevention method
The control device's mode setting unit addresses the need for continuous removable media by allowing suspended license checks, ensuring uninterrupted control processing and flexible usage scenarios.
Patent Information
- Application Number
- PCT/JP2024/041092
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-08
- Filing Date
- 2024-11-20
- Publication Date
- 2025-09-11
AI Technical Summary
Existing systems require continuous insertion of a removable media containing license data for control applications, occupying the RM socket during the control period and limiting flexibility in usage scenarios.
A control device with a mode setting unit that allows for different operation modes, including a stop mode where license checks are suspended, enabling continued execution of protected programs even without the removable media, and allowing for log collection and debugging without requiring constant license verification.
Enables uninterrupted control processing and flexible usage scenarios by allowing license checks to be temporarily suspended, reducing the need for continuous removable media presence and enhancing usability in debugging and simulation environments.
Smart Images

Figure JP2024041092_12092025_PF_FP_ABST
Abstract
Description
Unauthorized use prevention system and method
[0001] The present invention generally relates to preventing program fraud.
[0002] There is a control device (e.g., an industrial controller) that controls a controlled device such as an industrial device (e.g., an industrial motor or a compressor). The control device controls the controlled device by executing a control application. The control application can perform control by calling one or more program modules (e.g., one or more libraries such as one or more function blocks) in the course of a control process.
[0003] An implementing entity, which is an entity (typically an organization such as a company) that implements control of a control target device, and a providing entity, which is an entity that provides a control application or at least one program module, may be different. It is desirable for the providing entity to be able to prevent the implementing entity from misusing the control application or program module (e.g., from viewing the source code of the control application or program module).
[0004] Known technology for preventing unauthorized use of programs is disclosed in, for example, Patent Document 1. According to Patent Document 1, if a valid license corresponding to an application program does not exist in a portable memory device, execution of the application program is stopped.
[0005] Japanese Patent Application Laid-Open No. 2006-73002
[0006] Based on the technology disclosed in Patent Document 1, unauthorized use of a control application or program module can be prevented, for example, as follows. That is, a control device has a socket for a removable media (RM) such as a portable memory device, and determines whether license data for the control application or program module exists in the RM connected to the socket. If such license data does not exist, the control device prohibits (e.g., suspends) use of the control application or program module.
[0007] However, with this technology, an RM containing the license data for the control application or program module must always be inserted into the RM socket during the control period, which means that the RM socket is occupied by the RM containing the license data during the control period.
[0008] A control device periodically performs control processing of a controlled device and is provided with an RM socket and an RM I / F 53. The control device accepts a mode specification and sets the specified mode. The control device periodically performs a license check to determine whether an RM storing license data representing the license of a protected program is inserted into the socket and connected to the RM I / F 53. If the result of the license check is not false, the control device executes the protected program in the control processing. If the set mode is a stop mode, which means that license checks are stopped, the control device stops performing license checks.
[0009] The control can be continued even if the RM containing the license data is not inserted into the RM socket during the control period. Problems, configurations, and effects other than those described above will become clear from the following description.
[0010] 1 shows an example of the physical configuration of an entire system including a control system according to an embodiment; FIG. 2 shows an example of the logical configuration of a control device; FIG. 3 shows an example of a mode setting screen; FIG. 4 shows an example of the flow of license protection control; FIG. 5 shows an example of the flow of program execution control in normal mode; FIG. 6 shows an example of the flow of program execution control in log collection mode; FIG. 7 shows an example of the flow of program execution control in simulation; FIG. 8 shows an example of the flow of program execution control in debugging; and FIG. 9 shows an example of the flow of program execution control in building / downloading a program to be protected.
[0011] In the following description, an "interface apparatus" may refer to one or more interface devices, which may be one or more homogeneous communication interface devices or two or more heterogeneous communication interface devices.
[0012] In the following description, "memory" refers to one or more memory devices, typically a primary storage device. At least one of the memory devices may be a volatile memory device or a non-volatile memory device.
[0013] In the following description, a "persistent storage device" refers to one or more persistent storage devices. A persistent storage device is typically a non-volatile storage device (e.g., an auxiliary storage device), and specifically, for example, a hard disk drive (HDD) or a solid state drive (SSD).
[0014] In the following description, the term "storage device" may refer to at least one of memory and persistent storage device.
[0015] Furthermore, in the following description, a "processor" may refer to one or more processor devices. The at least one processor device may typically be a microprocessor device such as a CPU (Central Processing Unit), but may also be other types of processor devices such as a GPU (Graphics Processing Unit). The at least one processor device may be a single-core or multi-core. The at least one processor device may also be a processor core. The at least one processor device may also be a processor device in a broader sense, such as a hardware circuit that performs part or all of the processing (for example, an FPGA (Field-Programmable Gate Array), a CPLD (Complex Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit)).
[0016] In the following description, processing may be described using a "program" as the subject. However, since a program is executed by a processor to perform a predetermined process using a storage device and / or an interface device, etc., as appropriate, the subject of the process may also be the processor (or a device such as a controller having the processor). A program may be installed in a device such as a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable (e.g., non-transitory) recording medium. In the following description, two or more programs may be realized as one program, or one program may be realized as two or more programs.
[0017] Furthermore, in the following description, functions may be described using the expression "yyy unit," but the functions may be realized by one or more computer programs being executed by a processor. When a function is realized by a program being executed by a processor, the specified processing is performed using a storage device and / or an interface device, etc., as appropriate, and therefore the function may be considered to be at least a part of the processor. Processing described using a function as the subject may also be processing performed by a processor or a device having that processor. The description of each function is an example, and multiple functions may be combined into one function, or one function may be divided into multiple functions.
[0018] In the following description, information that provides an output in response to an input may be described using expressions such as "xxx table." However, this information may be data of any structure (for example, structured data or unstructured data), or may be a neural network that generates an output in response to an input, or a learning model such as a genetic algorithm or random forest. Therefore, "xxx table" may be referred to as "xxx information." In the following description, the structure of each table is an example, and one table may be divided into two or more tables, or all or part of two or more tables may be one table.
[0019] In addition, in the following description, an ID, a name, or a number is used as an example of identification information, but the identification information may include other types of elements instead of or in addition to at least one of the ID, name, and number.
[0020] In addition, in the following description, when describing elements of the same type without distinguishing between them, common parts of the reference symbols will be used, and when describing elements of the same type with distinction between them, reference symbols will be used.
[0021] In the following description, an example of a control program is a control app, and an example of an information program is an information app. "App" is an abbreviation for application program, and is an example of a computer program.
[0022] FIG. 1 shows an example of the physical configuration of the entire system including the control system according to the embodiment.
[0023] The control system 109 is installed in a factory 10 where a control target device 12 is located. The control target device 12 is, for example, industrial equipment such as an industrial motor or a compressor. The factory 10 is an example of a site where the control target device 12 is located.
[0024] The management system 101 and the control system 109 are connected to a communication network 108 (e.g., the Internet or a WAN (Wide Area Network)). The control system 109 is connected to, for example, a communication network 19 (e.g., a LAN (Local Area Network)) within the factory 10. The control system 109 can communicate with the management system 101 via the communication networks 19 and 108. The communication networks 108 and 19 are examples of communication networks used when an information application performs information communication processing (communication processing different from the control processing performed by a control application).
[0025] The control system 109 and one or more I / O modules 119 (an example of an I / O port) are connected to a communication network 118 (e.g., Ethernet (registered trademark)). The communication network 118 is an example of a communication network used to transmit control data to the control target device 12 in the control process performed by the control application.
[0026] The communication networks 19, 108, and 118 may be different networks, or two or more of the communication networks 19, 108, and 118 may be the same network.
[0027] One or more peripheral devices 120 are connected to one or more I / O modules 119. The peripheral devices 120 may be devices such as sensors or media drives (e.g., HDDs or SSDs). The I / O modules 119 function as bus slots to which the peripheral devices 120 are detachably attached as needed. The control target devices 12 are connected to the I / O modules 119 with or without the peripheral devices 120. The control target devices 12 and the I / O modules 119 may be connected in a one-to-one, one-to-multiple, multiple-to-one, or multiple-to-multiple configuration. Some of the I / O modules 119 may be connected to the communication network 108 in addition to the communication network 118. That is, some of the I / O modules 119 may be devices shared by the control application and the information application. At least one I / O module 119 may be at least a part of the network I / F device and I / O control device of at least one computing device 40.
[0028] The management system 101 is an example of a higher-level system of the control system 109. The management system 101 includes a nonvolatile storage device 201, a CPU 202, a memory 203, a peripheral control device 205, a UI (User Interface) device 206, and a network I / F device 207. The management system 101 is connected to the communication network 108 via the network I / F device 207. The UI device 206 includes an input device (e.g., a keyboard and a pointing device) and a display device.
[0029] The control system 109 includes one or more computing devices 40. Each computing device 40 includes an interface device, a storage device, and a processor connected to the ... At least the control device 40M of the arithmetic device 40 may be called a sequence control device, a motion control device, an industrial controller, or a programmable logic controller (PLC). The control content may be written in a control-specific programming language such as ladder logic (LD language), sequential function chart (SFC language), function block (FBD language), structured text (ST language), or instruction list (IL language). Furthermore, a description in a general-purpose programming language such as C language may be replaced in part or in whole with a description in a ladder language or the like.
[0030] The system configuration of the control system 109 varies depending on whether an expansion device 40E is present, the type of communication medium to which the expansion device 40E is connected, and which computing device 40 contains the information application that communicates with the control application. In other words, the system configuration depends on the presence or absence of the expansion device 40E, the type of communication medium to which the control device 40M and the expansion device 40E are connected, and the computing device 40 on which each application is located. In the example of FIG. 1 , the expansion device 40E1 is connected to the communication network 118. The expansion device 40E2 is connected to a PIO bus 28 (an example of a bus) ("PIO" stands for Programmed I / O). The PIO bus 28 may be a bus printed on a baseboard. By connecting the control device 40M and the expansion device 40E2 to the baseboard, the control application executed by the control device 40M and the information application executed by the expansion device 40E2 may communicate (share) data via the PIO bus 28.
[0031] In addition, in an embodiment in which the control application can also be placed on the expansion device 40E, or in an embodiment in which any of the computing devices 40 can be expanded or reduced and any of the computing devices 40 can be used to place the control application, the system configuration also depends on the control application.
[0032] As described above, the control system 109 includes at least one control device 40M. The control device 40M is a computing device in which at least one control application is installed. The role of the control device 40M is to periodically execute the control application to control the control target device 12 without delay.
[0033] The control application periodically performs a scan process. The "scan process" may include reading information from a device connected to an I / O (Input / Output) port, calculating the read information, and writing the calculated information. The scan process may be an example of a control process.
[0034] The hardware configuration of the arithmetic unit 40 will be described below using the control unit 40M as an example. That is, the control unit 40M includes a memory 169, a peripheral control unit 212, an I / O control unit 214, a nonvolatile storage device 215, a network I / F 213, an RM I / F 53, and a CPU 209 connected thereto. The I / O control unit 214, the network I / F 213, and the RM I / F 53 are examples of interface devices. The memory 169 and the nonvolatile storage device 215 are examples of storage devices. The CPU 209 is an example of a processor. "I / F" stands for interface device. "RM" stands for removable media. The control unit 40M has an RM socket 51 into which an RM 52 is inserted, and the RM 52 inserted into the RM socket 51 is connected to the RM I / F 53. The RM 52 may be a removable memory such as an SD card or a USB (Universal Serial Bus) memory, a dongle, or an HSM (Hardware Security Module). Specifically, in this embodiment, there are RM-L 52L, which is an RM that stores license data, and RM-N 52N, which is a normal RM that does not store license data (see FIG. 8).
[0035] The peripheral control device 212 is connected to a network I / F 213, an I / O control device 214, a non-volatile storage device 215, and a bus 211. The bus 211 also connects to a memory 169 and a CPU 209. The memory 169 may include an EPROM and a main memory. The EPROM (or the non-volatile storage device 215) may store at least one control application and one information application in advance, or may store programs downloaded from a program source such as a program distribution server (not shown). The control system 109 may be equipped with not just one control application and one information application, but may also be equipped with multiple control applications and / or multiple information applications by setting the resources available to the control system 109 for each program.
[0036] The CPU 209 reads the control app (and information app) stored in, for example, an EPROM into the main memory, executes it, and controls the operation of the control app (and information app). For example, by executing the control app, the CPU 209 controls multiple peripheral devices 120 via the peripheral control device 212, the I / O control device 214, and multiple I / O modules 119. The peripheral devices 120 may be associated with the I / O modules 119 on a one-to-one basis. The CPU 209 may be either a single-core or multi-core. One core may execute at least one of one or more control apps and one or more information apps. Typically, one core may execute one control app, one control app and one or more information apps, or one or more information apps.
[0037] Information processing terminals such as a development environment terminal 71 and a simulation terminal 72 are connected to the control system 109 (e.g., the control device 40M) via the communication network 19 (or without the communication network 19). Both the terminals 71 and 72 are, for example, computers (e.g., desktop, laptop, or tablet personal computers, or smartphones) having input devices, display devices, interface devices, storage devices, and processors connected thereto. The development environment terminal 71 is an information processing terminal used to develop programs to be executed on the control device 40M (or the expansion device 40E). The simulation terminal 72 is an information processing terminal that simulates the execution of programs on the control device 40M (or the expansion device 40E). The development environment terminal 71 may also function as the simulation terminal 72. An RM 52 may be connected to at least one of the terminals 71 and 72.
[0038] FIG. 2 shows an example of the logical configuration of the control device 40M.
[0039] The control device 40M has a program execution unit 251, a web server 252, a mode setting unit 253, an RM cooperation unit 254, and a license confirmation unit 255. At least some of these functions 251 to 255 may be realized by the CPU 209 executing a control application or an information application, or may be realized by the CPU 209 executing a program different from the control application or the information application.
[0040] The program execution unit 251 executes the protection target program 260. The protection target program 260 may be an application program such as a control application or an information application, or alternatively or in addition to the protection target program 260, may be a library, such as an FB (function block), as an example of a program module called from an application program (e.g., a control application).
[0041] The web server 252 communicates with a browser 251 in the management system 101. Information provided by the web server 252 is displayed on the UI device 206 by the browser 251. Instead of the UI device 206, the information may be displayed on a remote information processing terminal connected to the management system 101.
[0042] The mode setting unit 253 displays a mode setting screen, which is an example of a UI (User Interface), on the browser 251 via the web server 252, accepts a mode selection from the user via the mode setting screen, and sets the selected mode.
[0043] The RM linking unit 254 communicates with the connected RM 52. For example, the RM 52 has a memory 275 (e.g., a flash memory) and an internal controller 271 (e.g., a memory controller) connected to the memory 275, and the RM linking unit 254 communicates with the internal controller 271.
[0044] The license confirmation unit 255 confirms whether the license data 272 of the protection target program 260 is stored in the connected RM 52. If the RM 52 is an RM-L52LX in which the license data 272 is stored in the memory 275, the license data 272 is acquired from the RM-L52LX, and it is confirmed that the license data 272 of the protection target program 260 is stored.
[0045] FIG. 3 shows an example of a mode setting screen 300 .
[0046] One mode can be selected from a plurality of modes, such as a normal mode and a log collection mode. As described above, the mode setting screen 300 is provided by the mode setting unit 253 via the web server 252 and displayed by the browser 251.
[0047] The mode setting screen 300 has, as GUI components, for example, radio buttons 301 and a setting button 302. The radio buttons 301 are provided for each mode as an option. When either the normal mode radio button 301A or the log collection mode radio button 301B is selected and the setting button 302 is pressed, the mode corresponding to the selected radio button 301 is set by the mode setting unit 253 in, for example, the memory 169.
[0048] Here, "normal mode" refers to a mode in which license data is checked. "Log collection mode" refers to a mode in which license data checking is stopped and log collection is performed. The log collection mode may be an example of a mode in which license checking is stopped.
[0049] 4 shows an example of the flow of license protection control. The license protection control may be performed when a mode is set via the mode setting screen 300, or may be performed periodically. Furthermore, the license protection control may be performed when the license check stop time has elapsed in the case where step S403 (license check stop) described below is performed.
[0050] The license confirmation unit 255 confirms the mode set by the mode setting unit 253 (S401).
[0051] If the confirmed mode is the normal mode (S401: normal mode), the license confirmation unit 255 continues the license check (S402). Specifically, as shown in FIG. 5 , the license confirmation unit 255 periodically checks, via the RM cooperation unit 254, whether the RM 52 contains license data 272 representing the license of the protected program 260 (S501). S501 may be periodically performed in S402. The license protection control cycle shown in FIG. 4 and the license check cycle in S501 may be the same or different. The scan process cycle is relatively short, eliminating the need for a license check each time a scan process is performed. Therefore, the license protection control cycle and the license check cycle may be longer than the scan process cycle. On the other hand, to enhance the strictness of preventing unauthorized use, the license protection control cycle and the license check cycle may be the same as or shorter than the scan process cycle.
[0052] If such license data 272 exists (S501: YES), that is, if the RM52 is an RM-L52LX and such license data 272 has been read from the RM-L52LX, the license confirmation unit 255 permits execution of the protected program 260 (S502). When S502 is performed, the protected program 260 can be executed in the scan process.
[0053] On the other hand, if such license data 272 does not exist (S501: NO), for example, if such license data 272 was not read or if the read data was not license data 272 representing the license of the protection target program 260, the license confirmation unit 255 prohibits execution of the protection target program 260 (S503). When S503 is performed, execution of the protection target program 260 is not permitted in the scan process, and the license confirmation unit 255 may output a warning of unauthorized use, for example, to the management system 101 via the Web server 252.
[0054] If the confirmed mode is the log collection mode (S401: log collection mode), the license confirmation unit 255 stops the license check (S402). The license check may be stopped for a fixed period of time, or for a period of time set through the mode setting screen 300 (or by another method). This "period" may be defined by a start time and an end time, or may be defined by a length of time. If a length of time is set as the period of time, the license check may be stopped for this length of time after the log collection mode is set.
[0055] In the log collection mode, the program execution control shown in Fig. 6 is performed. That is, the license confirmation unit 255 determines, via the RM linkage unit 254, whether the RM 52 is RM-L52LX, that is, whether the license data 272 is in the RM 52 (S601).
[0056] If the RM 52 is RM-L52LX (S601: YES), the license confirmation unit 255 prohibits log collection (S602). When S602 is performed, it is not possible to write a log related to the protected program 260 to the RM 52 via the RM cooperation unit 254.
[0057] If the RM 52 is not an RM-L52LX (S601: NO), the license confirmation unit 255 permits log collection (S603). When S603 is performed, it is possible to write a log related to the protected program 260 to the RM 52 via the RM linkage unit 254. In this case, an RM-N52NX is inserted into the RM socket 51 instead of an RM-L52LX, and the license confirmation unit 255 writes a log related to the protected program 260 to the RM-N52NX via the RM linkage unit 254 during the license check stop time.
[0058] Although one embodiment has been described above, this is merely an example for explaining the present invention, and the scope of the present invention is not limited to this embodiment. The present invention can be implemented in various other forms.
[0059] The above description can be summarized, for example, as follows: The following summary may include supplementary and modified explanations of the above description.
[0060] A control device 40M that periodically performs control processing of the control target device 12 and is provided with an RM 52 socket 51 and an RM I / F 53 is provided with a mode setting unit 253, a license confirmation unit 255, and a program execution unit 251. The unauthorized use prevention system may include at least the mode setting unit 253, the license confirmation unit 255, and the program execution unit 251.
[0061] The mode setting unit 253 accepts the mode designation and sets the designated mode. The license confirmation unit 255 periodically performs a license check to determine whether an RM-L52LX, which stores license data 272 representing the license of the protected program 260, is inserted into the receptacle 51 and connected to the RM I / F 53. If the result of the license check is not false, the program execution unit 251 executes the protected program 260 in the control process. If the set mode is a stop mode, which means that license checks are stopped, the license confirmation unit 255 stops performing license checks.
[0062] While the license check is stopped, even if the RM-L52LX is removed from the socket 51 and an RM-N52NX, which is intended for purposes other than license checks, is inserted into the socket 51 and connected to the RM I / F 53, the program execution unit 251 executes the protected program 260 in the control process because there is no false result (negative result) as a result of the license check. As a result, even if the RM-L52LX containing the license data 272 is not inserted into the socket 51 during the control implementation period, control can continue.
[0063] The protected program 260 may be a control application, an information application, or, instead of or in addition to the control application and / or the information application, one or more FBs (function blocks) of the control application and / or the information application. The license data 272 may exist for each FB, or may be data representing the license of each of one or more LBs. An FB is an example of a library, and a library may be an example of a program module.
[0064] If the set mode is the stop mode, the license confirmation unit 255 may determine (for example, the determination in S601) whether the RM 52 connected to the RM I / F 53 is an RM-L52LX in which the license data 272 is stored. If the result of this determination is false, the license confirmation unit 255 may write data to the RM-N52NX connected to the RM I / F 53. As a result, the storage area in the RM-L52LX in which the license data 272 is stored may be a logical storage area based on a physical storage area that is a memory (for example, a flash memory) with an upper limit on the number of times the data can be written or erased. In other words, if the area of such a logical storage area other than the area where the license data is stored is made a user area that can be used freely, then depending on the frequency of writing data to the user area and erasing data, the number of times that the physical storage area is written to or erased from may reach an upper limit, making the physical storage area unusable and, as a result, making the RM-L52LX unusable.However, since data is written to the RM-N52NX, the possibility of the RM-L52LX becoming unusable can be reduced.
[0065] When the set mode is the stop mode (e.g., the log collection mode), in debugging a periodic control process, the license verification unit 255 may write a log related to the control process at each cycle to the RM 52 connected to the RM I / F 53. In debugging a control process, the cycle of the control process is fixed, and therefore the frequency of log writing is also fixed. The cycle of the control process is generally relatively short, and therefore the frequency of log output is relatively high. Furthermore, a large amount of information is output as a log (contained in the log) at each cycle. One possible method is to accumulate the log in a temporary area such as a buffer in the memory 169 and output it to external storage such as network storage via the communication network 19, but in this case, the accumulation speed in the temporary area is likely to be faster than the output speed to the external storage. Furthermore, if log accumulation in a temporary area is unnecessary, the process can be simplified compared to when log accumulation in a temporary area is necessary. Therefore, as described above, during debugging, the log is written to the RM 52 at each cycle of the control process.
[0066] Furthermore, during debugging, the control device 40M and a development environment terminal 71 (an example of a first information processing terminal) for the protected program 260 may be communicably connected. The development environment terminal 71 may determine whether license data representing the license for the protected program 260 is present. If the result of this determination is true, the development environment terminal 71 may send an execution instruction for a test target of the protected program 260 to the control device 40M. When the control device 40M receives this execution instruction from the development environment terminal 71, the program execution unit 251 may execute the protected program 260 without a license check by the license confirmation unit 255, and the license confirmation unit 255 may write a log related to the protected program 260 to the RM 52 (preferably an RM-N52NX) connected to the RM I / F 53.
[0067] An example of the flow of program execution control during debugging will be described with reference to Fig. 8. In the description with reference to Fig. 8, the license for the protected program 260 is subdivided, specifically into a build or download license and an execution license. A debug control unit is realized by executing the program on the development environment terminal 71, and the debug control unit may perform the processing of the development environment terminal 71 among the processing illustrated in Fig. 8.
[0068] The control device 40M and the development environment terminal 71 are connected so as to be able to communicate with each other, and each enters a debug execution state (S801). The source code of the protection target program 260 exists in the development environment terminal 71, and the entity of the protection target program 260 exists in the control device 40M.
[0069] The development environment terminal 71 starts debugging (S802). The development environment terminal 71 determines whether or not there is license data representing a license for building or downloading the protected program 260 (S803). Specifically, for example, the development environment terminal 71 determines whether an RM-L52LY (see FIG. 1 ) storing license data representing a license for building or downloading the protected program 260 is inserted into the RM socket of the development environment terminal 71 and connected to the RM-I / F of the development environment terminal 71.
[0070] If such an RM-L52LY is not connected to the development environment terminal 71, or if the license represented by the license data is not a license for building or downloading the protected program 260, the result of S803 is false. In this case (S803: NO), the development environment terminal 71 stops debugging (S804).
[0071] If the result of S803 is true (S803: YES), and if there are still test targets in the source code of the protected program 260 (S804: YES), the development environment terminal 71 continues debugging. That is, the development environment terminal 71 instructs the control device 40M to execute the test targets (S805X), and the program execution unit 251 in the control device 40M executes the instructed test targets in the protected program 260 (S805Y). Because the license for building or downloading the protected program 260 has already been checked (S803), S805Y is performed without a license check by the license confirmation unit 255 (i.e., without checking whether or not the protected program 260 has an execution license). Furthermore, when the program is executed during debugging, a log related to the execution results is output, and the license confirmation unit 255 writes the output log to the RM-N52NX. In other words, during debugging, it is not necessary for the RM-L52LX to be inserted into the socket 51, and therefore the RM-N52NX, which is the destination for writing logs during debugging, may be inserted into the socket 51 throughout the debugging process.
[0072] If there is no test target in the source code of the protected program 260 (S804: NO), the debugging ends. That is, the control device 40M and the development environment terminal 71 each release the debugging execution state (S806).
[0073] Note that the ability to execute the protected program 260 without a license check on the control device 40M does not need to be limited to debugging. The development environment terminal 71 may determine whether license data representing the license for the protected program 260 is present. If the determination is true, the development environment terminal 71 may transmit permission information, which is information indicating that a license is present, to the control device 40M. If the mode set in the control device 40M is normal mode (an example of a license mode that indicates a license check), the license confirmation unit 255 may execute the protected program 260 without a license check by the license confirmation unit 255 if the control device 40M has received permission information from the development environment terminal 71. A specific example of this will be described with reference to FIG. 9 . A build / download control unit is realized by executing a program on the development environment terminal 71, and the build / download control unit may perform the processes of the development environment terminal 71 among the processes illustrated in FIG. 9 . Furthermore, in FIG. 9 (and FIGS. 8 and 1 ), the development environment terminal 71 and the management system 101 may be integrated.
[0074] The control device 40M and the development environment terminal 71 are connected so that they can communicate with each other. The development environment terminal 71 may determine whether a predetermined condition is met (S901). The "predetermined condition" in this paragraph refers to the number of control devices 40M on which the protected program 260 is built or downloaded (built or downloaded) being equal to or greater than a predetermined number. In other words, in a case where the protected program 260 is executed on each of multiple control devices 40M, the development environment terminal 71 may perform the license check instead of all control devices 40M performing the license check. This eliminates the need for an RM-L52LX for each development environment terminal 71.
[0075] If the result of the determination in S901 is true (S901: YES), or if the determination in S901 is not made, the development environment terminal 71 determines whether or not license data representing a license for the protected program 260 is present (S902). If the result of the determination in S902 is true (S902: YES), the development environment terminal 71 outputs permission information indicating that a license is present (S903). The development environment terminal 71 builds or downloads the protected program 260 to the control device 40M (S904). If permission information is present, the permission information is also transmitted from the development environment terminal 71 to the control device 40M in S904.
[0076] The control device 40M receives the protection target program 260 (and the permission information) (S911), and installs the protection target program 260 (S912).
[0077] The license checking unit 255 checks the mode set by the mode setting unit 253 (S913). If the checked mode is the log collection mode (S913: log collection mode), the license checking unit 255 stops the license check (S915).
[0078] If the confirmed mode is the normal mode (S401: normal mode), the license confirmation unit 255 determines whether permission information has been received (S914).
[0079] If the determination result in S914 is true (S914: YES), the license confirmation unit 255 permits execution of the protection target program 260 (S916). When S916 is performed, the protection target program 260 can be executed.
[0080] If the determination result in S914 is false (S914: NO), the license confirmation unit 255 prohibits the execution of the protection target program 260 (S917).
[0081] The control device 40M and the simulation terminal 72 (an example of a second information processing terminal serving as a simulation execution environment) may be communicatively connected. If the result of the license check is true, the simulation terminal 72 may perform a simulation of the protected program 260 without determining whether license data representing the license of the protected program 260 exists. In this way, if the result of the license check by the control device 40M is true, an RM-L52LZ (see FIG. 1) may be connected to the simulation terminal 72, eliminating the need for the simulation terminal 72 to perform a license check. This allows the simulation to be performed while maintaining protection against unauthorized use. A specific example of this will be described with reference to FIG. 7. A simulation control unit may be implemented by executing a program on the simulation terminal 72, and the simulation control unit may perform the processing illustrated in FIG. 7.
[0082] The simulation terminal 72 determines whether the result of the license check of the protected program 260 in the control device 40M is true (i.e., licensed) and whether a true result has been received from the license confirmation unit 255 of the control device 40M (S701).
[0083] If the determination result in S701 is false (S701: NO), the simulation terminal 72 determines whether or not there is license data representing the license of the protection target program 260 (S702). Specifically, for example, the simulation terminal 72 determines whether or not an RM-L52LZ (see FIG. 1) storing license data representing the license of the protection target program 260 is inserted into the RM socket of the simulation terminal 72 and connected to the RM-I / F of the simulation terminal 72.
[0084] If the determination result of S702 is true (S702: YES), the simulation terminal 72 executes a simulation of the protected program 260 (S703). Note that if the determination result of S701 is true (S701: YES), S703 is performed without S702.
[0085] If the determination result in S702 is false (S702: NO), the simulation terminal 72 does not execute the simulation of the protection target program 260.
[0086] The control device 40M may have a retention mechanism (e.g., a latch mechanism). The retention mechanism may lock the RM 52 inserted into the socket 51 and connected to the RM I / F 53, and unlock the lock when a predetermined unlocking operation is performed. Examples of the RM 52 that can be locked by the retention mechanism include an SD card and an HSM. At the site (e.g., factory 10) where the control device 40M is installed, vibrations from the controlled device 12 can have an effect, and without a retention mechanism, the RM 52 may fall out of the control device 40M. Furthermore, it is not easy to increase the number of sockets with a retention mechanism using a device such as a hub. Therefore, depending on the environment of the site where the control device 40M is installed, it is highly technically significant to be able to use the limited number of sockets 51 for multiple purposes without occupying them.
[0087] 109...Control System
Claims
1. An unauthorized use prevention system comprising: a mode setting unit, a license confirmation unit, and a program execution unit provided in a control device that periodically performs control processing of a controlled device and is provided with an RM (removable media) insertion port and an RM I / F (removable media interface device), wherein the mode setting unit accepts a mode specification and sets the specified mode, the license confirmation unit periodically performs a license check to determine whether an RM that stores license data representing the license of a protected program is inserted into the insertion port and connected to the RM I / F, and if the result of the license check is not false, the program execution unit executes the protected program in the control processing, and the license confirmation unit stops performing the license check if the set mode is a stop mode which means the license check is stopped.
2. The fraud prevention system according to claim 1, wherein, when the set mode is the stop mode, the license confirmation unit determines whether the RM connected to the RM I / F is an RM in which license data is stored, and if the result of the determination is false, writes data to the RM connected to the RM I / F.
3. The fraud prevention system according to claim 1, wherein when the set mode is the stop mode, in debugging periodic control processing, the license confirmation unit writes a log relating to the control processing in each cycle to the RM connected to the RM I / F for each cycle of the control processing.
4. The fraud prevention system of claim 3, wherein in the debugging, the control device and a first information processing terminal serving as a development environment for the protected program are communicatively connected, the first information processing terminal determines whether or not license data representing a license for the protected program is present, and if the result of the determination is true, the first information processing terminal sends an execution instruction for a test target of the protected program to the control device, and when the control device receives the execution instruction from the first information processing terminal, the program execution unit executes the protected program without the license check by the license confirmation unit, and the license confirmation unit writes a log related to the protected program to an RM connected to the RM I / F.
5. The fraud prevention system of claim 1, wherein a plurality of control devices including the control device and a first information processing terminal are communicatively connected, the first information processing terminal determines whether or not there is license data representing a license for the protected program, and if the result of the determination is true, the first information processing terminal transmits permission information to the control device, which is information representing that a license exists, and if the set mode is a license mode meaning the license check, the license confirmation unit, if the control device has received the permission information from the first information processing terminal, causes the program execution unit to execute the protected program without the license check by the license confirmation unit.
6. The fraud prevention system of claim 1, wherein the control device and a second information processing terminal as a simulation execution environment are communicatively connected, and when the result of the license check is true, the second information processing terminal simulates the protected program without determining whether or not license data representing the license of the protected program exists.
7. The fraud prevention system according to claim 1, wherein the control device has a retention mechanism that locks the RM inserted into the socket and connected to the RM I / F, and releases the lock when a predetermined unlocking operation is performed.
8. A method for preventing unauthorized use, which periodically performs control processing of a controlled device, and uses a control device provided with an RM (removable media) insertion port and an RM I / F (removable media interface device), to accept mode designation and set the designated mode, periodically performs a license check to determine whether an RM storing license data representing the license of a protected program is inserted into the insertion port and connected to the RM I / F, and if the result of the license check is not false, executes the protected program in the control processing, and if the set mode is a stop mode which means the license check is stopped, stops the license check.
Citation Information
Patent Citations
Method and system providing portable application and data
JP2006073002A
Control system, control device and program execution method
JP2013239036A
Method for executing software program and circuit device for implementing the method
WO1994020901A1