Safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program

The safety evaluation device decentralizes system security assessments by using a protected agent to calculate safety indices, addressing operational load concentration and security vulnerabilities in supply chains.

WO2025225074A1PCT designated stage Publication Date: 2025-10-30MITSUBISHI ELECTRIC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/043430
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-24
Filing Date
2024-12-09
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing safety evaluation systems in supply chains face operational load concentration and increased costs due to the need for centralized management and recalculating safety indices when system configurations change, leading to security vulnerabilities.

Method used

A safety evaluation device and method that utilizes a safety evaluation agent stored in a protected environment to calculate safety indices for system configurations, allowing decentralized evaluation by system users without direct manipulation of data, thereby reducing operational load on the system provider.

Benefits of technology

Distributes the operational load of safety evaluations across the supply chain, enhancing security by preventing unauthorized access and reducing costs associated with centralized management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024043430_30102025_PF_FP_ABST
    Figure JP2024043430_30102025_PF_FP_ABST
Patent Text Reader

Abstract

A safety evaluation device (20, 200, 300) constructs a secure execution environment (201), such as a trusted execution environment (TEE), in which a user cannot directly operate data, and acquires and stores, in the execution environment (201), each of system information (104), which is a target of safety evaluation, and an agent (202), which calculates a safety evaluation value (207) numerically representing a safety of the system information (104). The agent (202) calculates and outputs the safety evaluation value indicating the safety of the system information (104).
Need to check novelty before this filing date? Find Prior Art

Description

Safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program

[0001] The present disclosure relates to a safety evaluation device, a safety evaluation system, a safety evaluation method, and a safety evaluation program.

[0002] In a supply chain where multiple organizations work together, when the entire supply chain manufactures a single information processing system (hereinafter referred to as "system"), activities to prepare for security risks in the supply chain by generating information on the system's software and hardware configuration (hereinafter referred to as "system information") are becoming more prevalent.

[0003] Supply chain security risk refers to the risk that an attacker will exploit vulnerabilities in weak security areas in a supply chain made up of components from various organizations with different security levels, thereby compromising the entire supply chain.

[0004] In this context, maintaining system security throughout the entire supply chain requires properly understanding information about each component and the interdependencies between the components, and maintaining the required level of security for each component. To achieve this, digitizing system information using, for example, a software bill of materials (SBOM) is considered promising. An SBOM is also called a software bill of materials, and can be likened to, for example, a food ingredient list.

[0005] As systems become larger, the supply chain structure becomes more complex, with many components interacting with each other in complex ways, making it virtually impossible to manually grasp the relationships between the components or the potential vulnerabilities each component possesses.Therefore, managing this information using data that can be handled mechanically, such as with SBOM, has the advantage of making it easier to manage the security of the entire supply chain.

[0006] Patent Document 1 discloses an invention of an audit system that makes it possible to obtain information about the security of a system without requiring the user to present information about the specific configuration of the system.

[0007] Patent document 2 discloses an invention for a transmitting device that can appropriately provide information about vulnerabilities that may be contained in a container to be transmitted by storing and transmitting, in a container, information about the acquired prohibited area, information indicating that the prohibited area has not been changed, and information about vulnerability testing for the prohibited area.

[0008] JP 2022-47160 A International Publication No. 2021 / 260753

[0009] However, while the audit system described in Patent Document 1 can quantify the system's security and securely share only that information, it does not address how to handle security when system users change the system's contents or settings to suit their usage scenarios. For example, when Supplier B, which provides a product system incorporating components provided by Supplier A, modifies the component's settings, Supplier A must reevaluate the security. If Supplier B has acquired the component's configuration information and information equivalent to the SBOM, it can simply update the component's settings. However, if Supplier B only has the configuration information and safety index values ​​calculated from them, rather than the SBOM, it must request Supplier A to recalculate the safety index values. As a result, centralized management is required, requiring an audit system, an evaluation server, and maintenance personnel to convert the system's configuration information into safety index values, resulting in complex operations and increased costs, as well as concerns about cyberattacks against concentrated resources.

[0010] The transmitting device described in Patent Document 2 requires the transmitting side to prepare information regarding the acquired prohibited areas, information indicating that the prohibited areas have not been changed, and information regarding vulnerability testing for the prohibited areas, which creates the problem of centralizing the work.

[0011] The present disclosure aims to provide a safety evaluation device, a safety evaluation system, a safety evaluation method, and a safety evaluation program that can alleviate the concentration of operational load on the safety evaluation system owned by the system provider (first entity).

[0012] The present disclosure relates to a safety assessment of a construction system constructed by a second entity using a system or component parts provided by a first entity, and is characterized in that the configuration information and an agent that calculates a safety assessment value that quantifies the safety of the configuration information of the construction system that is the subject of the safety assessment are acquired, and stored in an execution environment having a protected area where users cannot directly manipulate the data, and the agent stored in the protected area calculates a safety assessment value for predetermined items from the configuration information stored in the protected area.

[0013] According to the present disclosure, by agentizing a configuration for performing a safety evaluation based on system configuration information and supplying it from the system provider (first entity) side to the system user (second entity) side, the system user (second entity) side can perform the safety evaluation of the system and its components, thereby making it possible to provide a safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program that can alleviate the concentration of operational load on the safety evaluation system on the system provider (first entity) side.

[0014] 1 is a schematic diagram showing an example of the configuration of a safety evaluation system including the functions of a safety evaluation device and a system information providing device according to embodiment 1. FIG. 2 is a block diagram showing an example of the configuration of a safety evaluation device according to embodiment 1. FIG. 3 is a hardware configuration diagram showing a safety evaluation device according to embodiment 1. FIG. 4 is a flowchart showing an example of the configuration of a safety evaluation method according to embodiment 1. FIG. 5 is a schematic diagram showing an example of the configuration of an information processing system including the functions of a safety evaluation device and a system information providing device according to embodiments 2 and 3. FIG. 6 is a block diagram showing an example of the configuration of a safety evaluation device according to embodiment 2. FIG. 7 is a hardware configuration diagram showing a safety evaluation device according to embodiments 2 and 3. FIG. 8 is a hardware configuration diagram showing a system information providing device according to embodiments 2 and 3. FIG. 9 is a flowchart showing an example of the configuration of a safety evaluation method according to embodiment 2. FIG. 10 is a block diagram showing an example of the configuration of a safety evaluation device according to embodiment 3. FIG. 11 is a block diagram showing an example of the configuration in which a trained model is applied to a function selection unit of a safety evaluation device according to embodiment 3. FIG. 12 is a flowchart showing an example of the configuration of a safety evaluation method according to embodiment 3.

[0015] Hereinafter, a safety evaluation device according to an embodiment will be described with reference to the drawings. The following embodiments are merely examples, and it is possible to combine the embodiments as appropriate and to modify each embodiment as appropriate. Furthermore, duplicated explanations of the same reference numerals may be omitted.

[0016] First Embodiment FIG. 1 is a schematic diagram showing an example of the configuration of a safety evaluation system 10 including a safety evaluation device according to a first embodiment. The safety evaluation system 10 includes a first entity 100 that provides a system or components, and a second entity 101 that builds a final system using the system or components provided by the first entity 100. In the present disclosure, the systems or components are collectively referred to as system information 104, or may be referred to as configuration information 104, which has the same meaning as the system or components. Note that the entities develop the system and define and identify the components. In other words, the first entity 100 and the second entity 101 can each be considered suppliers.

[0017] Specifically, the first entity 100 is a supplier that provides a system or components. The second entity 101 is a supplier that builds a new system using the system or components provided by the first entity. A supplier is also called a business entity, and is a general term for manufacturers, vendors, developers, system integrators, maintenance companies, service providers, employees, products, customers, business partners, etc.

[0018] The second entity 101 may sell or transfer the newly constructed system to another party, or may use the system only for itself or its own organization. Therefore, the role of the second entity 101 is not limited to that of a vendor. The newly constructed system can be referred to as a final system. Hereinafter, to avoid any misunderstanding, this newly constructed system, that is, the final system, will be referred to as a constructed system. In other words, a system constructed by the second entity 101 is a constructed system. Therefore, in the present disclosure, the safety evaluation device (safety evaluation device 20, safety evaluation device 200, safety evaluation device 300) can be said to perform a safety evaluation on a constructed system constructed by the second entity 101 using a system or components provided by the first entity 100.

[0019] For example, the safety evaluation device 20 according to the first embodiment includes an execution environment 201 having a protected area in which a user cannot directly manipulate data, a safety evaluation agent (hereinafter abbreviated as "agent") 103 that calculates a safety evaluation value 207 that quantifies the safety of configuration information 104 of an implementation system that is the target of the safety evaluation, and an acquisition unit that acquires the configuration information 104 and stores it in the protected area of ​​the execution environment 201. The agent 103 stored in the protected area can obtain the safety evaluation value by calculating a safety evaluation value for predetermined items from the configuration information 104 stored in the protected area. Note that the acquisition unit may be configured to receive the agent 103 and the configuration information 104 from a provision unit 110 formed on the first entity 100 side.

[0020] Fig. 2 is a block diagram showing an example of the configuration of the safety evaluation device 20 according to the first embodiment. Fig. 3 is a hardware configuration diagram showing the safety evaluation device 20 according to the first embodiment. From Figs. 1 and 2, it can be said that the safety evaluation device 20 is a device on the side of the second entity 101. On the other hand, although not shown, it can be said that a system information providing device for providing a system or component to the second entity 101 is a device on the side of the first entity 100. The providing unit 110 shown in Fig. 3 is a component included in the system information providing device 111 described later.

[0021] As mentioned above, Fig. 2 is a block diagram showing an example of the configuration of the safety evaluation device 20 according to embodiment 1. The second entity 101 needs to evaluate the safety of the system or components (configuration information 104) of the first entity 100 in order to evaluate the safety of the constructed system (final system) to be constructed, and therefore includes the safety evaluation device 20 shown in Fig. 2. The safety evaluation device 20 in the second entity 101 obtains the agent 103 shown in Fig. 1 from the first entity 100.

[0022] The agent 103 refers to software that is constructed from a system or components and acts on its own initiative to achieve a given purpose. As a specific example, the agent 103 is software that operates in an intermediary relationship with a user or other software, and in the present disclosure, the agent 103 is assumed to perform, for example, safety evaluation of input system information and system information changed by input change information.

[0023] The agent 103 may also include a system for ensuring that it has not been tampered with by unauthorized means other than the first entity 100, or that output data using the agent 103 has been evaluated using the agent 103. For example, a hash function or digital signature technology may be used for the agent 103, and the present disclosure does not limit the specific means or purpose. Furthermore, the agent 103 itself may be applied with anti-reverse engineering technology such as obfuscation, and the method of sending the agent 103 is not limited.

[0024] The agent 103 evaluates the safety of the system information 104 in predetermined items. As an example of an evaluation method, the agent 103 performs a safety evaluation in accordance with ISO / IEC 15408, and quantifies the safety of the system information 104 on a five-point scale. Here, the safety evaluation value 207 is information that indicates the degree of safety, and is a five-point evaluation value, for example, with "5" representing the highest safety and "1" representing the lowest safety.

[0025] As another example of an evaluation method, the agent 103 may perform a three-axis evaluation of confidentiality, integrity, and availability as a risk analysis. Here, the safety evaluation value 207 is information that indicates the degree of safety, and for example, each of confidentiality, integrity, and availability is an evaluation value within a predetermined range. The three evaluation values ​​of confidentiality, integrity, and availability are plotted on three axes to form a three-axis evaluation. The evaluation values ​​within the predetermined range may be, for example, "5" for the highest security and "1" for the lowest security.

[0026] The safety evaluation device 20 shown in Fig. 2 is configured to perform safety evaluation in the second entity 101 of Fig. 1. The safety evaluation device 20 is used by the second entity 101 that uses the component, rather than by the first entity 100 that provides the component. Specifically, the safety evaluation device 20 may be a PC, a server, or a dedicated device created for performing safety evaluation. The safety evaluation device 20 may also be configured by a processing circuit.

[0027] The safety evaluation device 20 is provided with a User Interface (hereinafter abbreviated as "UI") 205 for inputting and outputting system changes and safety evaluation values ​​in the second entity 101. The UI 205 is an input device 205 or input unit 205, and can also be said to be an output device 205 or output unit 205. The specific UI configuration method of the UI 205 as the input device 205 (input unit 205) is not limited, and may be, for example, a keyboard, a mouse, or a pen tablet. The UI 205 as the output device 205 (output unit 205) is, for example, a display, a printer, a plotter, or a speaker.

[0028] 1 and 2 is arranged as an agent 202 in a safety evaluation device 200 according to a second embodiment, which will be described later. The safety evaluation device 200 is provided with a trusted execution environment 201 such as a TEE (Trusted Execution Environment). The TEE generally refers to a processing space provided in a computing device in a state isolated from a normal CPU (Central Processing Unit), OS (Operating System), memory space, etc., and is used as a secure space in which a user of the computing device cannot directly manipulate data.

[0029] The memory space may have, for example, a protected area in which the user cannot directly manipulate data, and an area outside the protected area, on a volatile storage device such as RAM (Random Access Memory). Of course, all areas may be protected areas. At least, the execution environment 201 needs to have a protected area in which the user cannot directly manipulate data. Although not a required configuration in the present disclosure, it is desirable to have the execution environment 201 because it has the secondary effect of allowing the first entity 100 to safely provide the system information 104 to, for example, a second entity 101 of another company other than the first entity 100.

[0030] 2 is configured as a computer in which a processing element (processor) 21 such as a CPU, a main memory 22, an input / output interface (I / O interface) 23, and a storage unit 24 are each connected to a system bus 25, like the safety evaluation device 20 shown in Fig. 3. The computer (safety evaluation device 20) may be configured as a plurality of computers connected via a network.

[0031] The arithmetic element 21 is an integrated circuit (IC) that performs arithmetic processing. For example, in addition to the CPU 21, an arithmetic element such as a digital signal processor (DSP) 21, a graphics processing unit (GPU) 21, a network processor 21, or a field programmable gate array (FPGA) 21 may be used. In the present disclosure, a case where the arithmetic element 21 is the CPU 21 will be described as an example.

[0032] By executing a safety evaluation program according to a first embodiment, which will be described later, the CPU 21 functions to construct an execution environment 201, to acquire the agent 103 and the system information 104 and store them in the execution environment 201, and to output a safety evaluation value 207 calculated by the agent 103. As a result, by executing the safety evaluation program, the CPU 21 functions as an execution environment constructing unit, a decryption key storage unit, an acquisition unit, and an output unit (UI 205). The safety evaluation program is provided, for example, on a recording medium on which these are recorded.

[0033] The main memory 22 is configured by a volatile storage device such as a RAM (Random Access Memory) or a non-volatile storage device such as a ROM (Read Only Memory). The storage unit 24 is configured by a non-volatile storage device such as a HDD (Hard Disk Drive) or a flash memory. The I / O interface 23 is a port to which the providing unit 110 on the first entity 100 side is connected. Specific examples of the I / O interface 23 include a USB (Universal Serial Bus) terminal, an IEEE 1394 terminal, a Thunderbolt terminal, or the like, and further includes a communication interface such as Ethernet (registered trademark).

[0034] In this way, the safety evaluation device 20 according to the first embodiment has a safety evaluation environment constructed by the CPU 21, which is reliable hardware, a protected area on the memory generated by the CPU 21, and a system bus 25 between the CPU 21 and the protected area on the memory. Assuming that such a safety evaluation environment has been constructed, the operation of the safety evaluation system according to the first embodiment will be described below.

[0035] First, the providing unit 110 on the first entity 100 side distributes the system information 104 to the acquiring unit on the second entity 101 side via a network, a storage medium, or the like. The system information 104 is stored in a memory in the trusted execution environment 201 of the safety evaluation device 20. The safety evaluation device 20 on the second entity 101 side performs a predetermined safety evaluation using the agent 202, and calculates a safety evaluation value 207. The calculated safety evaluation value 207 is provided to the second entity 101 via the UI 205. Note that it is safe to delete the input system information 104 after processing, for example.

[0036] Although details will be described in the second embodiment, the safety evaluation device 20 (safety evaluation system) according to the first embodiment may have the following configuration: The acquisition unit changes the configuration information 104 based on the input change information, and the agent 103 stored in the protection area calculates the safety evaluation value 207 from the configuration information 104 changed by the change information.

[0037] Furthermore, although details will be described in embodiment 3, the safety evaluation device 20 (safety evaluation system) according to embodiment 1 may have the following configuration. It has a function selection unit 308, which receives evaluation item information 309 for changing predetermined items and verifies whether the items changed by the evaluation item information 309 are appropriate or inappropriate. The function selection unit 308 is formed within the protection area. The function selection unit 308 may also be one that performs verification using a trained model 310 based on machine learning. The trained model 310 may be generated by a learning unit that learns by associating the evaluation item information 309 with determination result information 312 indicating whether the items changed by the evaluation item information 309 are appropriate or inappropriate.

[0038] Up to now, we have mainly explained the safety evaluation device 20 (safety evaluation system) according to embodiment 1, but from here on, we will explain the safety evaluation method and safety evaluation program according to embodiment 1. The safety evaluation method according to embodiment 1 is a safety evaluation method executed by a computer (safety evaluation device 20). In detail, the safety evaluation method executes a safety evaluation by a computer for a built system built by a second entity 101, using a system or components (system information 104) provided by a first entity 100. As mentioned above, the computer (safety evaluation device 20) may be composed of multiple computers connected via a network.

[0039] 4 is a flowchart showing an example of the configuration of a safety evaluation method according to the first embodiment. The safety evaluation method according to the first embodiment includes step 11 (S11) and step 12 (S12). In FIG. 4, step 11 (S11) is a step of acquiring an agent 103 that calculates a safety evaluation value 207 that quantifies the safety of configuration information 104 of an implementation system that is the subject of a safety evaluation, and the configuration information 104, and storing the acquired information in an execution environment having a protected area in which the user cannot directly manipulate the data. Step 12 (S12) is a step in which the agent 103 stored in the protected area calculates the safety evaluation value 207 for a predetermined item from the configuration information 104 stored in the protected area.

[0040] Step 11 (S11) causes the computer to function as an acquisition unit. Step 12 (S12) causes the computer to function as an agent 103. As will be described in detail in a second embodiment, the safety evaluation method according to the first embodiment may further include a step in which the agent 103 stored in the protected area calculates a safety evaluation value 207 from configuration information changed by the change information. Furthermore, as will be described in detail in a third embodiment, the safety evaluation device 20 (safety evaluation system) according to the first embodiment may further include a step of changing predetermined items by evaluation item information, and a step of verifying whether the items changed by the evaluation item information are appropriate.

[0041] The safety assessment program according to the first embodiment can be said to be a safety assessment program that causes a computer to execute the safety assessment method according to the first embodiment described above. Note that the computer (safety assessment device 20) that executes the safety assessment program according to the first embodiment may also be configured from a plurality of computers connected via a network.

[0042] As explained above, the safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program according to the first embodiment make it possible to provide a safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program that can alleviate the concentration of the operational load on the safety evaluation system on the system provider side by agentizing a configuration that performs safety evaluation based on system configuration information and supplying it from the first entity 100, which is the system provider, to the second entity 101, which is the system user, so that the system user side can perform the safety evaluation of the system and its components. As a result, the operational load can be distributed without relying on the system provider for safety evaluation.

[0043] In the safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program according to embodiment 1, the system provider can design the agent related to the safety evaluation by himself / herself. For example, the system provider can prevent system users from interfering with the safety evaluation by designing the agent so that the encryption of system information and the safety evaluation are integrated.

[0044] Furthermore, by providing the agent involved in the safety evaluation with signature technology, it is possible to ensure that the safety evaluation was indeed performed by that agent and that the agent has not been tampered with.

[0045] <<Embodiment 2>> A safety evaluation device, a safety evaluation system, a safety evaluation method, and a safety evaluation program according to embodiment 2 will be described. Descriptions of parts common to the safety evaluation device, the safety evaluation system, the safety evaluation method, and the safety evaluation program according to embodiment 1 may be omitted. Figure 5 is a schematic diagram showing an example of the configuration of a safety evaluation system 10 including a safety evaluation device according to embodiment 2. Comparing Figure 1 with Figure 5, it can be seen that in embodiment 2, the safety evaluation system 10 has a certificate authority 102.

[0046] The security evaluation system 10 includes a first entity 100 that provides a system or component, a second entity 101 that builds a final system using the system or component provided by the first entity 100, and a certificate authority 102 that provides an encryption key 105 to the first entity 100 and a decryption key 106 to the second entity 101.

[0047] The second entity 101 needs to evaluate the safety of the system or components of the first entity 100 in order to evaluate the safety of the final system to be constructed, and therefore includes a safety evaluation device 200 as shown in Fig. 2. The safety evaluation device 200 in the second entity 101 obtains the agent 103 shown in Fig. 5 from the first entity 100.

[0048] The second entity 101 obtains encrypted system information (configuration information) 204, which is the target of security evaluation, from the first entity 100. The encryption key 105 and a decryption key 106, which will be described later, are each provided by an external certificate authority 102 or the like. The communication means for the encryption key 105 and the decryption key 106 are outside the scope of this disclosure. The first entity 100 encrypts the system configuration information using the encryption key 105 and sends it to the second entity 101 as system information 204. The security evaluation device 200 in the second entity 101 decrypts the system information 204 using the decryption key 106. The agent 103 evaluates the security of the decrypted system information 104 in predetermined items, similar to the evaluation method exemplified in the first embodiment.

[0049] When evaluating security, if the system information 104 is decrypted and necessary parts of the system information 104 are changed within the agent 103, the first entity 100 will no longer need to present unnecessary system configuration information to outside the organization, thereby improving security.

[0050] FIG. 6 is a block diagram showing an example of the configuration of a safety evaluation device 200 according to the second embodiment. The safety evaluation device 200 is configured to perform a safety evaluation in the second entity 101 of FIG. 5. The safety evaluation device 200 is used not by the first entity 100 that is the provider of the component, but by the second entity 101 that is the user of the component. Specifically, the safety evaluation device 200 may be a PC, a server, or a dedicated device created for performing safety evaluation. Furthermore, the safety evaluation device 200 may be configured by a processing circuit.

[0051] 5 is stored in the decryption key storage unit 203 in the trusted execution environment 201. As a result, only authorized personnel of the second entity 101 can be involved in the operation of the decryption key 106 and the agent 202 using the decryption key 106, or in changing the state, thereby further increasing security.

[0052] The first entity 100 operates the UI 205 to input system change information 206 to the agent 202, and the agent 202 to which the change information 206 has been input provides a safety evaluation value 207 to the second entity 101 via the UI 205. The safety evaluation value 207 is information indicating the degree of safety, and is, for example, a five-point evaluation value in which "5" indicates the highest safety and "1" indicates the lowest safety. The details are as described in the first embodiment.

[0053] That is, as described with reference to Fig. 6, the safety evaluation device 200 according to the second embodiment includes a decryption key storage unit 203 that stores the decryption key 106 in the protected area of ​​the execution environment 201, and a decryption unit that is formed inside or outside the agent 202 in the execution environment 201 and that decrypts the encrypted system information 204 using the decryption key 106. In this case, the acquisition unit 211 acquires the encrypted configuration information 104 and stores it in the protected area. Then, the agent 202 stored in the protected area calculates the safety evaluation value 207 from the configuration information 104 decrypted by the decryption unit.

[0054] Furthermore, the safety evaluation device 200 according to the second embodiment can execute processing using the change information 206 described in the first embodiment. In Fig. 6 , the acquisition unit 211 changes the configuration information 104 based on the input change information 206, and the agent 202 stored in the protected area calculates the safety evaluation value 207 from the configuration information 104 changed by the change information 206.

[0055] As shown in Fig. 7, the safety evaluation device 200 shown in Fig. 6 is configured by a computer, as in the first embodiment. Similarly, the computer (safety evaluation device 200) may be configured by multiple computers connected via a network. Comparing Fig. 3 with Fig. 7, it can be seen that in the second embodiment, the certificate authority 102 is connected to the I / O interface 23 in addition to the providing unit 110. The safety evaluation device 200 obtains the decryption key 106 sent from the certificate authority 102 via the I / O interface 23.

[0056] By executing the safety evaluation program according to the second embodiment, the CPU 21 of the computer (safety evaluation device 200) functions as a function to construct an execution environment 201, a key storage function to store the decryption key 106 in the execution environment 201, a function to acquire the agent 103 (agent 202) and the encrypted system information 204 and store them in the execution environment 201, a function to decrypt the encrypted system information 204 with the decryption key 106, and a function to output the safety evaluation value 207 calculated by the agent 202. As a result, by executing the safety evaluation program, the CPU 21 functions as an execution environment constructing unit, a decryption key storage unit 203, an acquisition unit 211, a decryption unit, and an output unit 205. The safety evaluation program is provided, for example, on a recording medium on which these are recorded.

[0057] Assuming that the construction of the safety evaluation environment has been completed, the operation of the safety evaluation system according to the second embodiment will be described below.

[0058] First, the first entity 100 distributes system information 204 encrypted with the encryption key 105 to the second entity 101 via a network, a storage medium, or the like. The encrypted system information 204 is stored in a memory in the trusted execution environment 201 of the safety evaluation device 200, and is decrypted with the decryption key 106 stored in the decryption key storage unit 203.

[0059] Furthermore, the second entity 101 provides the agent 202 with the necessary change information 206, and after the change information 206 is added to the decrypted system information 104, the agent 202 performs a predetermined safety evaluation to calculate a safety evaluation value 207. The calculated safety evaluation value 207 is provided to the second entity 101 via the UI 205. Note that the input encrypted system information 204 can be safely deleted after processing, for example.

[0060] In the second embodiment, the decryption unit that decrypts the encrypted system information 204 may be designed to perform decryption within the agent 202, or may be designed to perform decryption outside the agent 202. In particular, in a device environment where the trusted execution environment 201 is not available, completing as much processing as possible within the agent 202 improves security.

[0061] The safety evaluation system according to the second embodiment will be described using a system information providing device according to the second embodiment, that is, a device on the first entity side that provides the system information 204 encrypted with the encryption key 105 and the agent 103 (agent 202) to the safety evaluation device according to the second embodiment. Fig. 8 is a block diagram showing an example of the configuration of the system information providing device 111 according to the second embodiment. Fig. 9 is a hardware configuration diagram showing the system information providing device 111.

[0062] In Figure 8, the system information providing device 111 includes an encryption key storage unit 114 that stores the encryption key 105, an encryption unit 113 that encrypts the configuration information 104 with the encryption key 105, a management unit 112 that manages the agent 103 and the encrypted system information 204, and a providing unit 110 that provides the system information 204 encrypted with the encryption key 105 and the agent 103 to an acquisition unit 211.

[0063] It can be said that the safety evaluation system according to the second embodiment includes a safety evaluation device 200 and a system information providing device 111. Of course, the safety evaluation system may also include a certificate authority 102. That is, the safety evaluation system may further include a certificate authority 102 that provides an encryption key 105 stored in an encryption key storage unit 114 and a decryption key 106 stored in a protected area.

[0064] Like the system information providing device 111 shown in Fig. 9, the system information providing device 111 shown in Fig. 8 is configured by a computer in which a CPU 11, which is a processing element (processor), a main memory 12, an input / output interface (I / O interface) 13, and a storage unit 14 are each connected to a system bus 15. The computer (system information providing device 111) may be configured by multiple computers connected via a network. In other words, the hardware configuration of the system information providing device 111 may be similar to that of the safety evaluation device 20 shown in Fig. 3 or the safety evaluation device 200 shown in Fig. 7.

[0065] Like the arithmetic element 21, the arithmetic element 11 is an IC that performs arithmetic processing. For example, other than the CPU 11, arithmetic elements such as a DSP 11, a GPU 11, a network processor 11, or an FPGA 11 may be used. In the present disclosure, a case where the arithmetic element 11 is the CPU 11 will be described as an example.

[0066] By executing a program that causes a computer to execute the system information providing device 111, the CPU 11 functions to store the encryption key 105, encrypt the configuration information 104 with the encryption key 105, manage the agent 103 and the encrypted system information 204, and provide the system information 204 encrypted with the encryption key 105 and the agent 103 to the acquisition unit 211. As a result, by executing the program, the CPU 11 functions as the encryption key storage unit 114, the encryption unit 113, the management unit 112, and the provision unit 110.

[0067] The main memory 12 is configured with a volatile storage device such as RAM or a non-volatile storage device such as ROM. The storage unit 14 is configured with a non-volatile storage device such as HDD or flash memory. The I / O interface 13 is a port to which the acquisition unit 211 on the second entity 101 side and the certificate authority 102 are connected. Specific examples of the I / O interface 13 include a USB terminal, an IEEE 1394 terminal, a Thunderbolt terminal, etc., and further includes a communication interface such as Ethernet (registered trademark).

[0068] Up to now, we have mainly explained the safety evaluation device 200 (safety evaluation system) according to embodiment 2, but from here on, we will explain the safety evaluation method and safety evaluation program according to embodiment 2. The safety evaluation method according to embodiment 2 is a safety evaluation method executed by a computer (safety evaluation device 200). Fig. 10 is a flowchart showing an example of the configuration of the safety evaluation method according to embodiment 2. The safety evaluation method according to embodiment 2 includes step 21 (S21) between step 11 (S11) and step 12 (S12) described in embodiment 1.

[0069] In FIG. 10 , step 11 (S11) is a step of acquiring the agent 103 and the configuration information 104 and storing them in an execution environment having a protected area where the user cannot directly manipulate the data. Step 21 (S21) is a step of the agent 202 (agent 103) stored in the protected area changing the configuration information 104 using the change information. Step 12 (S12) is a step of calculating a safety evaluation value 207 from the changed configuration information 104. Step 21 (S21) and step 12 (S12) may be combined into one step, where the agent 202 (agent 103) stored in the protected area calculates a safety evaluation value from the configuration information changed using the change information. Step 11 (S11) and step 21 (S21) cause the computer to function as the acquisition unit 211. Step 12 (S12) causes the computer to function as the agent 202.

[0070] The safety assessment program according to the second embodiment can be said to be a safety assessment program that causes a computer to execute the safety assessment method according to the second embodiment described above. Note that the computer that executes the safety assessment program according to the second embodiment (safety assessment device 200) may also be configured from multiple computers connected via a network.

[0071] As described above, according to the safety evaluation device 200 (safety evaluation system) of embodiment 2, in addition to the configuration of the safety evaluation device 20 of embodiment 1, by encrypting the system information 104 to create system information 204, the system provider does not need to unnecessarily disclose system configuration information, thereby reducing security risks in the supply chain.

[0072] <<Embodiment 3>> A safety evaluation device, a safety evaluation system, a safety evaluation method, and a safety evaluation program according to embodiment 3 will be described. In the following description, descriptions of parts common to the safety evaluation device, the safety evaluation system, the safety evaluation method, and the safety evaluation program according to embodiment 1 or 2 may be omitted. The safety evaluation device 300 according to embodiment 3 can execute processing using the function selection unit 308 described in embodiment 1.

[0073] The following drawings are basically the same as those of embodiment 2 except for some changes in symbols, etc. FIG. 5 is a schematic diagram showing an example of the configuration of an information processing system including the functions of a safety evaluation device and a system information providing device according to embodiment 3. FIG. 7 is a hardware configuration diagram showing a safety evaluation device according to embodiment 3. FIG. 8 is a block diagram showing an example of the configuration of a system information providing device according to embodiment 3. FIG. 9 is a hardware configuration diagram showing a system information providing device according to embodiment 3.

[0074] Next, a safety evaluation device 300 according to embodiment 3 will be described. Fig. 11 is a block diagram showing an example of the configuration of the safety evaluation device 300 according to embodiment 3. In Fig. 11, the safety evaluation device 300 includes a function selection unit 308 formed in a protection area, which receives evaluation item information 309 for changing predetermined items and verifies whether the items changed by the evaluation item information 309 are appropriate or inappropriate.

[0075] That is, the safety evaluation device 300 according to the third embodiment differs from the safety evaluation device 20 according to the first embodiment and the safety evaluation device 200 according to the second embodiment in that it includes, in the trusted execution environment 201, a function selection unit 308 that changes part of the function of the agent 202 in accordance with evaluation item information 309 input via a UI 205. However, the trusted execution environment 201, the decryption key storage unit 203, the encrypted system information 204, the UI 205, the change information 206, and the safety evaluation value 207 are each the same as those in the first or second embodiment, and therefore detailed description thereof will be omitted.

[0076] In the safety evaluation device 300 according to the third embodiment, similarly to the safety evaluation device 20 according to the first embodiment and the safety evaluation device 200 according to the second embodiment, an agent 202 (agent 103) and a decryption key storage unit 203 are arranged in a trusted execution environment 201, and after receiving encrypted system information 204, change information 206 by the second entity 101 is added to the system information 204, and a calculated safety evaluation value 207 is output. In the first or second embodiment, the agent 202 (agent 103) for safety evaluation is provided by the system provider, and from the perspective of the system user, evaluation may be limited to predetermined indices or evaluation items, which may lack flexibility. In the third embodiment, the second entity 101 itself changes the evaluation items for the agent 202 in the safety evaluation, and evaluation item information 309 for making partial changes to the functions of the agent 202 is input via the UI 205.

[0077] The evaluation item information 309 may, for example, exclude items that are not desired to be used in the safety evaluation from the system information 104 (encrypted system information 204), or indicate an arbitrary combination of items as a safety index. The evaluation item information 309 may be parameterized according to the content of the safety evaluation.

[0078] The function selection unit 308 acquires evaluation item information 309 via the UI 205, verifies whether the specified evaluation item information 309 causes any discrepancies in the safety evaluation function of the agent 202, and then notifies the agent 202 of the evaluation items. A discrepancy in the safety evaluation function may occur, for example, when the evaluation item information 309 deviates from the specified items for evaluating safety, or when the specified items for evaluating safety are insufficient. A discrepancy in the safety evaluation function may also occur if the evaluation item information 309 specifies content that is inappropriate as a predetermined item for evaluating safety. Examples of content that is inappropriate as a predetermined item for evaluating safety include when an impossible property value is specified or when an undefined value is input.

[0079] The agent 202 evaluates the safety of the decrypted system information based on the evaluation item information 309 and outputs the safety evaluation value 207 via the UI 205 .

[0080] In the function selection unit 308 of the safety evaluation device 300 (safety evaluation system) according to embodiment 3, verification as to whether or not any discrepancies occur in the safety evaluation function of the agent 202 due to the specification of the evaluation item information 309 may be performed using a trained model 310 based on machine learning using AI (Artificial Intelligence).

[0081] FIG. 12 is a block diagram showing an example of a configuration in which a trained model is applied to the function selection unit of the safety evaluation device according to embodiment 3. In FIG. 12, the function selection unit 308 performs verification using a trained model 310 based on machine learning. The trained model 310 is generated by a learning unit 311 that learns by associating evaluation item information 309 with determination result information 312 indicating whether an item changed by the evaluation item information 309 is appropriate or inappropriate. The determination result information 312 is information indicating the determination result as to whether the changed item is appropriate or inappropriate. This information is appropriate if it can be determined that no discrepancy will occur in the safety evaluation function of the agent 202 described above, and is inappropriate if it can be determined that a discrepancy will occur.

[0082] The evaluation item information learning device 313 shown in Figure 12 can be said to be the evaluation item information learning device 313 according to the third embodiment, and generates a trained model 310. This trained model 310 verifies whether a change to a predetermined item for calculating a safety evaluation value in a safety evaluation device, safety evaluation system, safety evaluation method, and safety evaluation program, which can alleviate the concentration of operational load on a safety evaluation system owned by the system provider (first entity 100), is appropriate or inappropriate. Therefore, the evaluation item information learning device 313 can be said to include the aforementioned learning unit 311 that learns by associating evaluation item information 309 with determination result information 312 indicating whether the item changed by the evaluation item information 309 is appropriate or inappropriate.

[0083] Furthermore, although not shown, the evaluation item information learning device 313 may further include an evaluation item information input unit for inputting the evaluation item information 309, and a judgment result information input unit for inputting the judgment result information 312. In this case, the evaluation item information input unit and the judgment result information input unit are connected to the learning unit 311. In other words, the learning unit 311 learns by associating the evaluation item information 309 input to the evaluation item information input unit with the judgment result information 312 input to the judgment result information input unit.

[0084] Up to now, we have mainly described the safety evaluation device 300 (safety evaluation system) according to embodiment 3. From here on, we will describe the safety evaluation method and safety evaluation program according to embodiment 3. The safety evaluation method according to embodiment 3 is a safety evaluation method executed by a computer (safety evaluation device 300). FIGS. 13 and 14 are flowcharts showing an example of the configuration of the safety evaluation method according to embodiment 3. In the safety evaluation method according to embodiment 3, the example in FIG. 13 includes step 31 (S31) and step 32 (S32) between step 11 (S11) and step 12 (S12) described in embodiment 1. The example in FIG. 14 includes step 31 (S31) and step 32 (S32) between step 21 (S21) and step 12 (S12) described in embodiment 1.

[0085] In FIG. 13 , step 11 (S11) is a step of acquiring the agent 103 and the configuration information 104 and storing them in an execution environment having a protected area where the user cannot directly manipulate the data. Step 31 (S31) is a step of changing predetermined items using the evaluation item information 309. Step 32 (S32) is a step of verifying whether the items changed using the evaluation item information 309 are appropriate. If the items are appropriate (YES) in step 32 (S32), proceed to step 12 (S12). If the items are inappropriate (NO), return to step 31 (S31). Step 12 (S12) is a step of calculating a safety evaluation value 207 from the configuration information 104. Step 31 (S31) and step 12 (S12) may be combined into one step in which the agent 202 (agent 103) stored in the protected area calculates a safety evaluation value from the configuration information changed by the change information. Step 11 (S11) causes a computer to function as the acquisition unit 211. Step 31 (S31) and step 32 (S32) cause the computer to function as the function selection unit 308. Step 12 (S12) causes the computer to function as the agent 103.

[0086] In FIG. 14 , step 11 (S11) is a step of acquiring the agent 103 and the configuration information 104 and storing them in an execution environment having a protected area where the user cannot directly manipulate the data. Step 21 (S21) is a step of the agent 202 (agent 103) stored in the protected area changing the configuration information 104 using the change information. Step 31 (S31) is a step of changing the items predetermined by the evaluation item information 309. Step 32 (S32) is a step of verifying whether the items changed by the evaluation item information 309 are appropriate. If the items are appropriate (YES) in step 32 (S32), proceed to step 12 (S12). If the items are inappropriate (NO), return to step 31 (S31). Step 12 (S12) is a step of calculating the safety evaluation value 207 from the configuration information 104. Step 21 (S21) and step 12 (S12) may be combined into one step in which the agent 202 (agent 103) stored in the protected area calculates a safety evaluation value from the configuration information changed by the change information. Step 11 (S11) and step 21 (S21) cause the computer to function as the acquisition unit 211. Step 31 (S31) and step 32 (S32) cause the computer to function as the function selection unit 308. Step 12 (S12) cause the computer to function as the agent 103.

[0087] 13 and 14 illustrate an example of a flow in which, in step 32 (S32), the item changed by the evaluation item information 309 is verified to be appropriate, and if it is determined to be inappropriate (NO), the flow returns to step 31 (S31). However, this is not limiting. For example, if it is determined to be inappropriate in step 32 (S32), the safety evaluation value 207 may be calculated for the item preceding the item changed by the evaluation item information 309, and the flow may proceed to step 32 (S32). Furthermore, if it is determined to be inappropriate in step 32 (S32), a notification may be made to prompt the user to input different evaluation item information 309 into the function selection unit 308. The notification may be made using the output device 205, which is the UI 205.

[0088] The safety assessment program according to the third embodiment can be said to be a safety assessment program that causes a computer to execute the safety assessment method according to the third embodiment described above. Note that the computer that executes the safety assessment program according to the third embodiment (safety assessment device 300) may also be configured from a plurality of computers connected via a network.

[0089] As explained above, according to the safety evaluation device 300 (safety evaluation system) of embodiment 3, in addition to the explanations of the safety evaluation device 20 of embodiment 1 and the safety evaluation device 200 of embodiment 2, the system users themselves can control the content of the safety evaluation, which enables flexible responses taking into account the circumstances of the system users' system operation.

[0090] 10 Safety evaluation system, 11 Processing element, 12 Main memory, 13 I / O interface, 14 Storage unit, 15 System bus, 20 Safety evaluation device, 21 Processing element, 22 Main memory, 23 I / O interface, 24 Storage unit, 25 System bus, 100 First entity, 101 Second entity, 102 Certificate authority, 103 Agent, 104 System information, 105 Encryption key, 106 Decryption key, 110 Provision unit, 111 System information providing device 114 Encryption key storage unit, 200 Safety evaluation device, 201 Trusted execution environment, 202 Agent, 203 Decryption key storage unit, 204 Encrypted system information, 205 UI, 206 Change information, 207 Safety evaluation value, 211 Acquisition unit, 300 Safety evaluation device, 308 Function selection unit, 309 Evaluation item information, 310 trained model, 311 learning unit, 312 judgment result information, 313 evaluation item information learning device.

Claims

1. A safety evaluation device that performs a safety evaluation on a built system built by a second entity using a system or components provided by a first entity, comprising: an execution environment having a protected area where users cannot directly manipulate data; an agent that calculates a safety evaluation value that quantifies the safety of the configuration information of the built system that is the subject of the safety evaluation; and an acquisition unit that acquires the configuration information and stores it in the protected area of ​​the execution environment, wherein the agent stored in the protected area calculates the safety evaluation value for predetermined items from the configuration information stored in the protected area.

2. The safety evaluation device according to claim 1, further comprising: a decryption key storage unit that stores a decryption key in the protected area of ​​the execution environment; and a decryption unit formed within or outside the agent in the execution environment that decrypts the encrypted configuration information using the decryption key, wherein the acquisition unit acquires the encrypted configuration information and stores it in the protected area, and the agent stored in the protected area calculates the safety evaluation value from the configuration information decrypted by the decryption unit.

3. The safety evaluation device according to claim 2, wherein the acquisition unit changes the configuration information based on the input change information, and the agent stored in the protected area calculates the safety evaluation value from the configuration information changed by the change information.

4. The safety evaluation device according to claim 3, further comprising a function selection unit formed within the protection area, which receives evaluation item information that modifies the predetermined items and verifies whether the items modified by the evaluation item information are appropriate or inappropriate.

5. The safety evaluation device according to claim 4, wherein the function selection unit performs verification using a trained model based on machine learning.

6. The safety evaluation device according to claim 5, wherein the trained model is generated by a learning unit that learns by associating the evaluation item information with judgment result information on whether the items changed by the evaluation item information are appropriate or inappropriate.

7. A safety evaluation system comprising: a safety evaluation device according to any one of claims 2 to 6; an encryption key storage unit that stores an encryption key; an encryption unit that encrypts the configuration information with the encryption key; a management unit that manages the agent and the encrypted configuration information; and a provision unit that provides the configuration information encrypted with the encryption key and the agent to the acquisition unit.

8. The security evaluation system according to claim 7, further comprising a certification authority that provides the encryption key stored in the encryption key storage unit and the decryption key stored in the protected area.

9. A safety assessment method for performing a safety assessment by a computer on a built system built by a second entity using a system or components provided by a first entity, the safety assessment method comprising the steps of: acquiring an agent that calculates a safety assessment value that quantifies the safety of the configuration information of the built system that is the subject of the safety assessment, and the configuration information, and storing the configuration information in an execution environment having a protected area where users cannot directly manipulate data; and a step of the agent stored in the protected area calculating the safety assessment value for predetermined items from the configuration information stored in the protected area.

10. The safety evaluation method according to claim 9, further comprising a step in which the agent stored in the protection area calculates the safety evaluation value from the configuration information changed by the change information.

11. A safety evaluation method as described in claim 10, further comprising the steps of: changing the predetermined items based on evaluation item information; and verifying whether the items changed based on the evaluation item information are appropriate.

12. A safety evaluation program that causes a computer to execute the safety evaluation method according to any one of claims 9 to 11.

Citation Information

Patent Citations

  • Audit system and program

    JP2022047160A

  • Software information management device and software information management method

    JP2024021523A

  • System, method, and program for inspecting website vulnerabilities

    JP7320211B1

  • Information processing device, information processing method, and information processing program

    WO2020115782A1

  • Cryptosystem, function value calculation method and program

    WO2021009860A1