Falsification Detection in Startup Programs via Dual Key Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional information processing apparatuses require program changes to utilize a second decryption key for detecting falsification during startup, which is inconvenient and vulnerable to key exposure.
Innovation Solution
An information processing apparatus with a first and second storage portion for decryption keys, where the presence or absence of a connection between these portions determines which key is used to decrypt electronic signatures for detecting falsification in detection target programs, allowing detection without changing program content and enhancing security by making the second decryption key unreadable upon a triggering condition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a second decryption key is stored in a replaceable storage portion (TPM) to enhance security, then security against key exposure is improved, but program changes are required to utilize the second decryption key which increases device complexity
Solution Approach 1:
The patent applies preliminary action by determining whether the second storage portion is connected before the falsification detection process. The determination processing portion checks the connection status of the TPM in advance, and based on this predetermined determination, the detection processing portion selects which decryption key to use. This eliminates the need for program changes while maintaining security, as the key selection is handled through runtime determination rather than requiring modified detection programs.
2Reliability
If the second decryption key is made unreadable upon a triggering condition to prevent unauthorized access, then security is improved, but the ability to detect falsification when the second storage portion is connected is reduced
Solution Approach 1:
The patent resolves this contradiction by performing preliminary determination of the connection status before the falsification detection. The determination processing portion checks whether the second storage portion is connected in advance, and based on this predetermined result, the detection processing portion appropriately selects the first or second decryption key. This ensures that when the TPM is connected, the system uses the second decryption key for accurate falsification detection, while maintaining security by making the second key unreadable only when the TPM is not connected or when triggering conditions occur.
Data Source
AI summary
An information processing apparatus includes a first storage portion, a connection portion, and a detection processing portion. The first storage portion stores a first decryption key used to decrypt a first electronic signature, wherein the first electronic signature and a second electronic signature have been added to detection target programs that are expanded into a memory during a start-up of the information processing apparatus. The connection portion is configured to be connected with a second storage portion storing a second decryption key used to decrypt the second electronic signature. When the second storage portion is connected to the connection portion, the detection processing portion detects presence/absence of falsification in the detection target programs by using second decrypted data that is acquired by decrypting the second electronic signature by using the second decryption key.


