Safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program
The safety evaluation device decentralizes system security assessments by using encrypted agents and trusted execution environments, addressing operational load concentration and security risks in supply chains, enabling flexible and secure evaluations.
Patent Information
- Application Number
- PCT/JP2024/016117
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-24
- Publication Date
- 2025-10-30
AI Technical Summary
Existing safety evaluation systems in supply chains face operational load concentration and increased costs due to the need for centralized management and recalculating safety indices when system components are modified, leading to security risks and inefficiencies.
A safety evaluation device and method that utilizes a trusted execution environment to encrypt and evaluate system configuration information, distributing the evaluation process to system users while ensuring security through agents and encryption keys, allowing decentralized safety assessments.
Distributes operational load, reduces security risks, and enhances flexibility in safety evaluations by enabling system users to perform evaluations independently, thus alleviating the burden on system providers and maintaining security.
Smart Images

Figure JP2024016117_30102025_PF_FP_ABST
Abstract
Description
Safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program
[0001] The present disclosure relates to a safety evaluation device, a safety evaluation system, a safety evaluation method, and a safety evaluation program.
[0002] In a supply chain where multiple organizations work together, when the entire supply chain manufactures a single information processing system (hereinafter referred to as "system"), activities to prepare for security risks in the supply chain by generating information on the system's software and hardware configuration (hereinafter referred to as "system information") are becoming more prevalent.
[0003] Supply chain security risk refers to the risk that an attacker will exploit vulnerabilities in weak security areas in a supply chain made up of components from various organizations with different security levels, thereby compromising the entire supply chain.
[0004] In this context, maintaining system security throughout the entire supply chain requires properly understanding information about each component and the interdependencies between the components, and maintaining the required level of security for each component. To achieve this, digitizing system information using, for example, a software bill of materials (SBOM) is considered promising. An SBOM is also called a software bill of materials, and can be likened to, for example, a food ingredient list.
[0005] As systems become larger, the supply chain structure becomes more complex, with many components interacting with each other in complex ways, making it virtually impossible to manually grasp the relationships between the components or the potential vulnerabilities each component possesses.Therefore, managing this information using data that can be handled mechanically, such as with SBOM, has the advantage of making it easier to manage the security of the entire supply chain.
[0006] Patent Document 1 discloses an invention of an audit system that makes it possible to obtain information about the security of a system without requiring the user to present information about the specific configuration of the system.
[0007] Patent document 2 discloses an invention for a transmitting device that can appropriately provide information about vulnerabilities that may be contained in a container to be transmitted by storing and transmitting, in a container, information about the acquired prohibited area, information indicating that the prohibited area has not been changed, and information about vulnerability testing for the prohibited area.
[0008] JP 2022-47160 A International Publication No. 2021 / 260753
[0009] However, while the audit system described in Patent Document 1 can quantify the system's security and securely share only that information, it does not address how to handle security when system users change the system's contents or settings to suit their usage scenarios. For example, when Supplier B, which provides a product system incorporating components provided by Supplier A, modifies the component's settings, Supplier A must reevaluate the security. If Supplier B has acquired the component's configuration information and information equivalent to the SBOM, it can simply update the component's settings. However, if Supplier B only has the configuration information and safety index values calculated from them, rather than the SBOM, it must request Supplier A to recalculate the safety index values. As a result, centralized management is required, requiring an audit system, an evaluation server, and maintenance personnel to convert the system's configuration information into safety index values, resulting in complex operations and increased costs, as well as concerns about cyberattacks against concentrated resources.
[0010] The transmitting device described in Patent Document 2 requires the transmitting side to prepare information regarding the acquired prohibited areas, information indicating that the prohibited areas have not been changed, and information regarding vulnerability testing for the prohibited areas, which creates the problem of centralizing the work.
[0011] The present disclosure aims to provide a safety evaluation device, a safety evaluation system, a safety evaluation method, and a safety evaluation program that can alleviate the concentration of operational load on a safety evaluation system owned by a system provider.
[0012] The safety evaluation device disclosed herein is characterized by comprising an execution environment construction unit that constructs a safe execution environment in which users cannot directly manipulate data, an acquisition unit that acquires configuration information of a system that is the subject of safety evaluation and an agent that calculates a safety evaluation value that quantifies the safety of the configuration information and stores them in the execution environment, and an output unit that outputs the safety evaluation value calculated by the agent.
[0013] The safety evaluation system of the present disclosure is characterized by having a safety evaluation device described in any one of claims 1 to 4, a supplier that provides the agent and the encrypted configuration information to the safety evaluation device, and a certification authority that provides the supplier with an encryption key for encrypting the configuration information and provides the safety evaluation device with a decryption key for decrypting the encrypted configuration information.
[0014] The safety evaluation method disclosed herein is a safety evaluation method executed by a computer, and is characterized by comprising the steps of: constructing a safe execution environment in which users cannot directly manipulate data; acquiring and storing in the execution environment configuration information of a system that is the subject of safety evaluation and an agent that calculates a safety evaluation value that quantifies the safety of the configuration information; and outputting the safety evaluation value calculated by the agent.
[0015] The safety evaluation program disclosed herein is characterized by having a computer execute the steps of: constructing a safe execution environment in which users cannot directly manipulate data; acquiring and storing in the execution environment configuration information of a system that is the subject of safety evaluation and an agent that calculates a safety evaluation value that quantifies the safety of the configuration information; and outputting the safety evaluation value calculated by the agent.
[0016] According to the present disclosure, by agentizing a configuration that performs a safety evaluation based on system configuration information and supplying it from the system provider to the system user, the system user can perform a safety evaluation of the system and its components, thereby making it possible to provide a safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program that can alleviate the concentration of operational load on the system provider's safety evaluation system.
[0017] Fig. 1 is a schematic diagram showing an example of the configuration of an information processing system including a safety evaluation device according to embodiment 1. Fig. 2 is a block diagram showing an example of the configuration of a safety evaluation device according to embodiment 1. Fig. 3 is a hardware configuration diagram showing a safety evaluation device according to embodiment 1. Fig. 4 is a block diagram showing an example of the configuration of a safety evaluation device according to embodiment 2.
[0018] Hereinafter, safety evaluation devices according to embodiments will be described with reference to the drawings. The following embodiments are merely examples, and the embodiments can be appropriately combined and modified.
[0019] 1 is a schematic diagram showing an example of the configuration of an information processing system 10 including a safety evaluation device according to embodiment 1. The information processing system 10 includes a supplier 100 that provides a system or components, a supplier 101 that builds a final system using the system or components provided by the supplier 100, and a certificate authority 102 that provides an encryption key 105 to the supplier 100 and a decryption key 106 to the supplier 101.
[0020] The supplier 101 may sell or transfer the final system that it has constructed to another party, or may use the final system only for itself or its own organization, and the role of the supplier 101 is not limited to that of a vendor.
[0021] The supplier 101 requires a safety evaluation of the supplier's 100 system or components to evaluate the safety of the final system to be constructed, and therefore includes a safety evaluation device 200 as shown in FIG. 2 . The safety evaluation device 200 in the supplier 101 obtains the safety evaluation agent (hereinafter abbreviated as "agent") 103 shown in FIG. 1 from the supplier 100. The agent 103 is software that operates in an intermediary relationship with a user or other software. In the present disclosure, the agent 103 performs safety evaluation of input system information and system information changed by the input change information, for example. The agent 103 may also include a system for ensuring that the data has not been tampered with by unauthorized means other than the supplier 100, or that output data using the agent 103 has been evaluated using the agent 103. The agent 103 may use, for example, a hash function or digital signature technology, and the present disclosure does not limit the specific means or purpose thereof. Furthermore, the agent 103 itself may be subjected to anti-reverse engineering techniques such as obfuscation, and there are no restrictions on the method of sending the agent 103.
[0022] The supplier 101 obtains encrypted system information 104, which is the subject of security evaluation, from the supplier 100. The encryption key 105 and the decryption key 106 (described later) are provided by an external certificate authority 102 or the like. The communication means for the encryption key 105 and the decryption key 106 are outside the scope of this disclosure. The supplier 100 encrypts system configuration information using the encryption key 105 and sends it to the supplier 101 as system information 104. The security evaluation device 300 in the supplier 101 decrypts the system information 104 using the decryption key 106. The agent 103 evaluates the security of the decrypted system information in predetermined categories. As an example of the evaluation method, the agent 103 performs a security evaluation in accordance with ISO / IEC 15408 and quantifies the security of the system information on a five-point scale. The agent 103 may also perform a three-dimensional evaluation of confidentiality, integrity, and availability as risk analysis.
[0023] When evaluating security, if the system information 104 is decrypted and necessary parts of the system information 104 are changed within the agent 103, the supplier 100 will no longer need to present unnecessary system configuration information to outside the organization, thereby improving security.
[0024] 2 is a block diagram showing an example of the configuration of a safety evaluation device 200 according to the first embodiment. The safety evaluation device 200 is configured to perform a safety evaluation in the supplier 101 of FIG. 1. The safety evaluation device 200 is used by the supplier 101, which is the user of the component parts, rather than the supplier 100, which is the provider of the component parts. Specifically, the safety evaluation device 200 may be a PC, a server, or a dedicated device created for performing safety evaluation. Furthermore, the safety evaluation device 200 may be configured by a processing circuit.
[0025] The safety evaluation device 200 is provided with a UI 205 for inputting and outputting system changes and safety evaluation values in the supplier 101. The specific UI configuration method of the UI 205 as an input device is not limited, but may be, for example, a keyboard, a mouse, a pen tablet, etc. The UI 205 as an output device may be, for example, a display, a printer, a plotter, a speaker, etc.
[0026] The agent 103 shown in FIG. 1 is arranged as an agent 202 in the safety evaluation device 200. The safety evaluation device 200 is provided with a trusted execution environment 201 such as a TEE (Trusted Execution Environment). A TEE generally refers to a processing space provided in a computing device that is isolated from the normal CPU (Central Processing Unit), OS (Operating System), memory space, etc., and is used as a secure space in which the user of the computing device cannot directly manipulate data. While the execution environment 201 is not a required component in this disclosure, it is desirable to provide it because it has the secondary effect of allowing the supplier 100 to provide system information to other companies with peace of mind.
[0027] 1 is also stored in the key storage unit 203 in the trusted execution environment 201. As a result, neither the supplier 101 nor anyone other than authorized personnel can be involved in the operation of the decryption key 106 or the agent 202 using the decryption key 106, or in changing the state, thereby further increasing security.
[0028] The supplier 100 operates the UI 205 to input system change information 206 to the agent 202, and the agent 202 to which the change information 206 has been input provides a safety evaluation value 207 to the supplier 101 via the UI 205. The safety evaluation value 207 is information that indicates the degree of safety, and is, for example, a five-point evaluation value with "5" representing the highest safety and "1" representing the lowest safety.
[0029] 2 is configured by a computer in which a CPU 21, which is a processing element (processor), a main memory 22, an input / output interface (I / O interface) 23, and a storage unit 24 are each connected to a system bus 25, as shown in Fig. 3. The computer (safety evaluation device 200) may be configured by a plurality of computers connected via a network.
[0030] The CPU 21 is an integrated circuit (IC) that performs arithmetic processing. Instead of the CPU 21, a computing element such as a digital signal processor (DSP), a graphics processing unit (GPU), a network processor, or a field programmable gate array (FPGA) may be used. By executing the security evaluation program according to the first embodiment, the CPU 21 functions as a function of constructing the execution environment 201, a key storage function of storing the decryption key 106 in the execution environment 201, a function of acquiring the agent 103 and the encrypted system information 204 and storing them in the execution environment 201, a function of decrypting the encrypted system information 304 with the decryption key, and a function of outputting a security evaluation value calculated by the agent 202. As a result, the CPU 21 functions as an execution environment construction unit, a key storage unit 203, an acquisition unit, a decryption unit, and an output unit by executing the safety evaluation program. The safety evaluation program is provided, for example, on a recording medium on which it is recorded.
[0031] The main memory 22 is configured by a volatile storage device such as a RAM (Random Access Memory) or a non-volatile storage device such as a ROM (Read Only Memory). The storage unit 24 is configured by a non-volatile storage device such as a HDD (Hard Disk Drive) or a flash memory.
[0032] The I / O interface 23 is a port to which the supplier 100 and the certificate authority 102 are connected. Specific examples of the I / O interface 23 include a USB (Universal Serial Bus) terminal, an IEEE 1394 terminal, a Thunderbolt terminal, or the like, and further includes a communication interface such as Ethernet (registered trademark).
[0033] Assuming that the construction of the safety evaluation environment has been completed, the operation of the safety evaluation system according to the first embodiment will be described below.
[0034] First, the supplier 100 distributes system information 204 encrypted with the encryption key 105 to the supplier 101 via a network, a storage medium, or the like. The encrypted system information 204 is stored in a memory in the trusted execution environment 201 of the safety evaluation device 200, and is decrypted with the decryption key 106 stored in the key storage unit 203.
[0035] Furthermore, the supplier 101 provides the agent 202 with necessary change information 206, and after the change information 206 is added to the decrypted system information, the agent 202 performs a predetermined safety evaluation to calculate a safety evaluation value. The calculated safety evaluation value 207 is provided to the supplier 101 via the UI 205. Note that it is safer to delete the input encrypted system information 204 after processing, for example.
[0036] In the first embodiment, the encrypted system information 204 may be designed to be decrypted within the agent 202 or may be designed to be decrypted outside the agent 202. In particular, in a device environment where the trusted execution environment 201 is not available, completing as much processing as possible within the agent 202 improves security.
[0037] As explained above, the safety evaluation system according to the first embodiment converts a configuration for performing a safety evaluation based on system configuration information into an agent and supplies the agent from supplier 100, who is the system provider, to supplier 101, who is the system user, thereby enabling the system user to perform the safety evaluation of the system and its components, thereby making it possible to provide a safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program that can alleviate the concentration of the operational load on the safety evaluation system on the system provider side. As a result, the operational load can be distributed without relying on the system provider for safety evaluation.
[0038] Furthermore, by encrypting the system information 204, the system provider can avoid disclosing system configuration information unnecessarily, thereby reducing security risks in the supply chain.
[0039] In the safety evaluation system according to the first embodiment, the system provider can design the agent related to the safety evaluation by himself / herself. For example, the system provider can prevent system users from interfering with the safety evaluation by designing the agent so that the encryption of system information and the safety evaluation are integrated.
[0040] Furthermore, by providing the agent involved in the safety evaluation with signature technology, it is possible to ensure that the safety evaluation was indeed carried out by that agent and that the agent has not been tampered with.
[0041] Second Embodiment Next, a safety evaluation device 300 according to the second embodiment will be described. Fig. 4 is a block diagram showing an example of the configuration of the safety evaluation device 300 according to the second embodiment. The safety evaluation device 300 according to the second embodiment differs from the safety evaluation device 200 according to the first embodiment in that it includes, in the trusted execution environment 301, a function selection unit 308 that changes part of the function of the agent 302 in accordance with evaluation item information 309 input via a UI 305. However, the trusted execution environment 301, the key storage unit 303, the encrypted system information 304, the UI 305, the change information 306, and the safety evaluation value 307 are each the same as those in the first embodiment, and therefore detailed description thereof will be omitted.
[0042] In the safety evaluation device 300 according to the second embodiment, similar to the safety evaluation device 200 according to the first embodiment, an agent 302 and a key storage unit 303 are arranged in a trusted execution environment 301, and after receiving encrypted system information 304, change information 306 by the supplier 101 is added, and a calculated safety evaluation value 307 is output. However, the safety evaluation agent 302 is provided by the system provider, and from the perspective of the system user, it may be limited to evaluation using predetermined indicators or evaluation items, which may lack flexibility. In the second embodiment, the supplier 101 himself changes the evaluation items of the agent 302 in the safety evaluation, and inputs evaluation item information 309 for making partial changes to the functions of the agent 302 via a UI 305.
[0043] The evaluation item information 309 may, for example, exclude items that are not desired to be used in the safety evaluation from the system information 304, or indicate an arbitrary combination of items as a safety index. The evaluation item information 309 may be parameterized according to the content of the safety evaluation.
[0044] The function selection unit 308 acquires evaluation item information 309 via the UI 305, verifies whether the specified evaluation item information 309 causes any discrepancies in the safety evaluation function of the agent 302, and then notifies the agent 302 of the evaluation items. A discrepancy in the safety evaluation function may occur, for example, when the evaluation item information 309 deviates from the specified items for evaluating safety, or when the specified items for evaluating safety are insufficient. A discrepancy in the safety evaluation function may also occur if the evaluation item information 309 specifies content that is inappropriate as a predetermined item for evaluating safety. Examples of content that is inappropriate as a predetermined item for evaluating safety include when an impossible property value is specified or when an undefined value is input.
[0045] The agent 302 evaluates the safety of the decrypted system information based on the evaluation item information 309 and outputs a safety evaluation value 307 via the UI 305 .
[0046] As described above, the safety evaluation device 300 according to the second embodiment allows the system users themselves to control the content of the safety evaluation, thereby enabling flexible responses that take into account the circumstances of the system users' system operations.
[0047] 10 Safety evaluation system, 21 CPU, 22 Main memory, 23 I / O interface, 24 Memory unit, 25 System bus, 100, 101 Supplier, 102 Certificate authority, 103 Agent, 104 System information, 105 Encryption key, 106 Decryption key, 200 Safety evaluation device, 201 Trusted execution environment, 202 Agent, 203 Key storage unit, 204 Encrypted system information, 205 UI, 206 Change information, 207 Safety evaluation value, 300 Safety evaluation device, 301 Trusted execution environment, 302 Agent, 303 Key storage unit, 304 Encrypted system information, 305 UI, 306 Change information, 307 Safety evaluation value, 308 Function selection unit, 309 Evaluation item information.
Claims
1. A safety evaluation device comprising: an execution environment construction unit that constructs a safe execution environment in which users cannot directly manipulate data; an acquisition unit that acquires configuration information of a system that is the subject of safety evaluation and an agent that calculates a safety evaluation value that quantifies the safety of the configuration information, and stores them in the execution environment; and an output unit that outputs the safety evaluation value calculated by the agent.
2. The safety evaluation device according to claim 1, further comprising: a key storage unit that stores a decryption key in the execution environment; and a decryption unit that decrypts the encrypted configuration information with the decryption key, wherein the agent calculates the safety evaluation value of the decrypted configuration information.
3. The safety evaluation device according to claim 2, further comprising an input unit to which modification information for modifying the configuration information is input, wherein the agent calculates the safety evaluation value of the configuration information modified by the modification information.
4. The safety evaluation device according to claim 3, further comprising a function selection unit that receives evaluation item information via the input unit to change the evaluation items of the agent in the safety evaluation and verifies that the evaluation item information does not cause any inconsistencies in the safety evaluation function of the agent, and the agent calculates the safety evaluation value of the configuration information based on the evaluation item information that has been verified by the function selection unit to cause no inconsistencies in the safety evaluation function of the agent.
5. A safety evaluation system comprising: a safety evaluation device according to any one of claims 2 to 4; a supplier that provides the agent and the encrypted configuration information to the safety evaluation device; and a certification authority that provides the supplier with an encryption key for encrypting the configuration information and the safety evaluation device with the decryption key.
6. A safety evaluation method executed by a computer, comprising the steps of: constructing a safe execution environment in which users cannot directly manipulate data; acquiring and storing in the execution environment configuration information of a system that is the subject of safety evaluation and an agent that calculates a safety evaluation value that quantifies the safety of the configuration information; and outputting the safety evaluation value calculated by the agent.
7. A safety evaluation program that causes a computer to execute the following steps: constructing a safe execution environment in which users cannot directly manipulate data; acquiring and storing in the execution environment configuration information of a system that is the subject of a safety evaluation and an agent that calculates a safety evaluation value that quantifies the safety of the configuration information; and outputting the safety evaluation value calculated by the agent.
Citation Information
Patent Citations
Application execution system, application execution method, and authentication server and authentication program for use in the same
JP2007310686A
Audit system and program
JP2022047160A
Information processing device, information processing method, and information processing program
WO2020115782A1