Hibernation State Device Certification Hash Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional device certification techniques fail to verify software integrity after an information processing apparatus returns from a hibernation state, as the hash values stored in volatile memory are lost, leading to false positives indicating software alteration.

Innovation Solution

An information processing apparatus with a storage unit for volatile memory to store hash values, a request unit to initiate device certification, and an excluding unit to exclude pre-hibernation software modules from certification, ensuring accurate verification by comparing stored hash values with activation logs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If the information processing apparatus uses hibernation function to power off and resume, then activation speed is improved, but device certification fails because hash values in volatile memory are lost

Engineering Contradiction:
Improveactivation speedVSAvoiddevice certification
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The invention stores hash values of activated software modules in non-volatile storage before hibernation occurs. This preliminary action ensures that when the system resumes from hibernation, the hash values are already available in storage, allowing device certification to proceed without failure while maintaining fast activation.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If all activated software modules are included in device certification after hibernation, then verification completeness is improved, but false positives increase due to lost hash values

Engineering Contradiction:
Improveverification completenessVSAvoidcertification accuracy
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

Hash values of software modules activated before hibernation are stored in non-volatile storage in advance. When certification is performed after hibernation, these pre-stored hash values are used to verify the corresponding software modules, ensuring both completeness and accuracy of verification without false positives.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Non-volatile storage acts as an intermediary between the volatile memory (which loses data during hibernation) and the device certification process. It preserves hash values across power cycles and provides them to the certification process, enabling accurate verification of software modules activated before hibernation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If hash values are stored only in volatile memory, then storage simplicity is improved, but data loss occurs during hibernation

Engineering Contradiction:
Improvestorage structureVSAvoidhash value retention
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The invention combines volatile memory and non-volatile storage into a hybrid storage system. Volatile memory maintains fast access for active operations, while non-volatile storage provides persistent retention of hash values. The system merges these two storage types to achieve both speed and data retention without significantly increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10346179B2Information processing apparatus, server apparatus, information processing system, control method, and computer program
Publication Date: 2019.07.09 CANON KK
  • US10346179B2 patent drawing
  • US10346179B2 patent drawing
  • US10346179B2 patent drawing

AI summary

An information processing apparatus having a function of entering and returning from a hibernation state and communicable with a server apparatus performing device certification includes a storage unit configured to, in a case where a software module is activated, store a hash value of the activated software module in a volatile memory, a request unit configured to request device certification based on a hash value stored in the volatile memory from the server apparatus, and an excluding unit configured to, in a case where the device certification is requested after returning from the hibernation state, exclude a software module activated before entering the hibernation state from a target of the device certification.