Information Processing Apparatus Alteration Detection Whitelist
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing apparatuses face challenges in detecting alterations to software programs after distribution, as conventional digital signatures do not effectively prevent overwrites and ensure operational compatibility, leading to potential misuse and tampering.
Innovation Solution
An information processing apparatus is designed with an installation unit to make programs compatible with the operational environment, a generation unit to create verification data, and a detection unit to identify alterations using hash values or signatures, ensuring the integrity and compatibility of installed programs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital signatures are added to all programs at distribution stage, then program integrity can be verified, but any overwrite after distribution is deemed as alteration even when necessary for compatibility
Solution Approach 1:
The patent applies preliminary action by creating a whitelist of authorized overwrites before they occur. The management server pre-approves necessary modifications for compatibility, and the information processing apparatus stores these approvals. When an overwrite occurs, the system checks against the pre-established whitelist rather than treating all overwrites as alterations, thus resolving the contradiction between integrity verification and compatibility adaptation.
2Reliability
If all overwrites are treated as alterations, then security is maintained, but legitimate compatibility updates are blocked
Solution Approach 1:
The patent introduces an intermediary management server that mediates between security requirements and installation needs. The management server acts as a trusted third party that authorizes specific overwrites, allowing the information processing apparatus to distinguish between malicious alterations and legitimate compatibility updates. This intermediary mechanism enables secure yet flexible program installation by providing pre-authorized overwrite approvals.
3Measurement precision
If conventional digital signature verification is used, then tampering can be detected, but overwritten programs are incorrectly detected as altered
Solution Approach 1:
The patent implements feedback by establishing a verification mechanism where the information processing apparatus reports overwrites to the management server, which then provides authorization feedback. The system uses this feedback loop to distinguish between unauthorized alterations and authorized compatibility updates. The management server's authorization decisions are fed back to the apparatus, allowing it to correctly identify legitimate overwrites and avoid false positive detections.
Data Source
AI summary
An information processing apparatus includes an installation unit that installs a first program after overwriting the first program so as to make the first program compatible with an operational environment on the information processing apparatus. A generation unit is included to generate first verification data based on the first program overwritten by the installation unit. A first detection unit is also included to detect an alteration to the first program after the installation based on the first verification data generated by the generation unit.


