Information Terminal Secure Key Reregistration via ROM Monitor
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In information processing systems, the leakage or tampering of private keys used for authentication poses a significant challenge, leading to the need for re-registration, which is labor-intensive, costly, and time-consuming, especially when dealing with multiple information processing terminals.
Innovation Solution
The implementation of a secure system where a non-volatile memory stores a private key and a reregistration key, with a ROM monitor ensuring the soundness of the system software and facilitating a reregistration process using a reregistration key for secure authentication, thereby reducing the need for physical visits and streamlining the recovery process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a worker visits the installation location of the information processing terminal to handle private key leakage, then the confidentiality can be recovered, but the labor, cost, and processing time increase significantly
Solution Approach 1:
The information processing terminal performs self-diagnosis and self-recovery operations. The terminal automatically detects private key leakage, initiates re-registration procedures, and communicates with the management server without requiring worker intervention, thereby recovering confidentiality while eliminating the need for physical visits
Solution Approach 2:
The patent replaces the mechanical/physical intervention system (worker visiting installation location) with an automated information processing system. The terminal uses its own processing capabilities and communication functions to handle the recovery process, substituting human physical presence with electronic automation
2Reliability
If a worker visits the installation location of the information processing terminal to handle private key leakage, then the confidentiality can be recovered, but the labor and cost increase significantly
Solution Approach 1:
The terminal autonomously performs the recovery operation by detecting private key leakage conditions, generating re-registration requests, and communicating with the management server. This self-service mechanism eliminates the need for worker intervention, significantly reducing labor requirements and associated costs
Solution Approach 2:
The management server acts as an intermediary that receives re-registration requests from the terminal, verifies the conditions, and facilitates the private key re-registration process. This intermediary system enables remote handling of the recovery operation, eliminating the need for physical worker intervention at the terminal location
3Reliability
If the system software is tampered with, then the identification information may be tampered with, but the server cannot entirely identify the information processing terminal for re-registering the private key
Solution Approach 1:
The terminal performs preliminary actions by first detecting whether private key leakage is due to system software tampering before initiating re-registration. The terminal checks the system software integrity status and only proceeds with re-registration when necessary, ensuring that identification information is not tampered with during the process
Solution Approach 2:
The management server provides feedback to the terminal about the system software integrity status and identification information validity. Based on this feedback, the terminal determines whether to proceed with re-registration, creating a feedback loop that ensures accurate terminal identification and prevents tampered systems from incorrectly registering
Data Source
AI summary
A system software unit performs a first authentication operation with an external device using a first key that is registered in advance. A secure software unit determines whether or not system software satisfies a soundness condition. A dedicated memory unit is used to store a second key. While performing a reregistration operation for reregistering the first key, a system software unit requests the secure software unit to read the second key. When the system software satisfies the soundness condition, the secure software unit generates verification data using the second key. When a second authentication operation performed with the external device using the verification data is successful, the system software unit performs the reregistration operation.


