Power Control Unit for Firmware Verification and Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information processing apparatuses lack effective mechanisms to efficiently manage power consumption during tampering verification processes, particularly in scenarios where firmware integrity is compromised, leading to potential security vulnerabilities and increased power usage.

Innovation Solution

An information processing apparatus equipped with a verification unit to detect tampering, a recovery unit for restoring the firmware, and a power control unit to manage power supply to these components based on verification results, ensuring efficient power usage and security by stopping power to non-tampered components and maintaining power to tampered ones for recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If power is continuously supplied to the verification unit and second storage unit during tampering verification, then verification reliability is improved, but power consumption increases

Engineering Contradiction:
Improveverification reliabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies dynamics by making the power supply state changeable based on verification results. The power supply control unit dynamically adjusts power supply: continuously supplying power during verification to ensure reliability, then stopping power to the second storage unit after verification completes whether tampering is detected or not. This transforms a static power supply system into a dynamic one that adapts to verification needs.

Inventive Principle:
Principle #15Dynamics

2Use of energy by moving object

If power is stopped to the second storage unit after verification when no tampering is detected, then power consumption is reduced, but verification reliability may be compromised

Engineering Contradiction:
Improvepower consumptionVSAvoidverification reliability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent applies preliminary action by completing the verification process before stopping power supply. The power supply control unit ensures that verification is fully completed and results are confirmed before cutting power to the second storage unit. This preliminary completion of verification ensures reliability is not compromised while still achieving power savings.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the recovery unit overwrites the backup program with the tampered program, then firmware integrity is restored, but power consumption increases during recovery

Engineering Contradiction:
Improvefirmware integrityVSAvoidpower consumption during recovery
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies taking out by extracting the recovery operation from continuous power supply. The power supply control unit stops power to the second storage unit after verification, then selectively restores power only when recovery is needed. This separates the verification phase (requiring continuous power) from the recovery phase (intermittent power), reducing overall power consumption while maintaining firmware integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20230367873A1Information processing apparatus and control method of information processing apparatus
Publication Date: 2023.11.16 CANON KK
  • US20230367873A1 patent drawing
  • US20230367873A1 patent drawing
  • US20230367873A1 patent drawing

AI summary

An information processing apparatus including a first storage unit storing a program and a second storage unit storing a backup program of the program includes a verification unit configured to verify tampering of the program stored in the first storage unit, a recovery unit configured to perform recovery by overwriting the backup program stored in the second storage unit with the program stored in the first storage unit in a case where the program is tampered, and a power control unit configured to stop power to the verification unit and the second storage unit upon termination of the verification by the verification unit in a case where the program is not tampered, and stop power to the verification unit and the second storage unit upon termination of the verification by the verification unit and termination of the recovery by the recovery unit in a case where the program is tampered.