Executing unsigned content and securing access in a closed system
20 claims: 3 independent, 17 dependent
- 1クローズドシステムにおいて無署名 ソフトウェア コンテンツ コンポーネント を実行し、アクセスをセキュアにするためのシステムにおいて、 クローズドコンピューティングデバイスであって、前記クローズドコンピューティングデバイスは 、複数のクローズドコンピューティングデバイスのいずれかにおいて動作するために 署名当局によって許可されたソフトウェアコンテンツコンポーネントを実行するように構成されているものと、 少なくとも1つの無署名ソフトウェアコンテンツコンポーネントであって、前記少なくとも1つの無署名 ソフトウェア コンテンツコンポーネントは、前記署名当局によって許可された前記ソフトウェアコンテンツコンポーネント用のインタフェースを提供することに加えて、前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネント用のインタフェースを前記クローズドコンピューティングデバイスに仮想化させることによって 、前記クローズドコンピューティングデバイスのリソースへのアクセスを可能にし、 前記クローズドコンピューティングデバイス上で実行されるものと、を備えたことを特徴とするシステム。
- 2前記インタフェースは、グラフィックスレイヤ、オーディオレイヤ、入力レイヤ、およびストレージレイヤのうちの少なくとも1つに対応していることを特徴とする請求項1に記載のシステム。
- 3前記グラフィックスレイヤ、前記オーディオレイヤ、前記入力レイヤ、および前記ストレージレイヤのうちの少なくとも1つは、前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントに関連するデータがストアされる第1のバッファ、および前記データが前記第1のバッファからコピーされる第2のバッファで構成されると共に、前記データは前記第2のバッファにおいて有効性検査されることを特徴とする請求項2に記載のシステム。
- 4前記データは、前記有効性検査のあと、前記クローズドコンピューティングデバイスに関連するリソースに提供されることを特徴とする請求項3に記載のシステム。
- 5前記データは、前記有効性検査のあと、前記クローズドコンピューティングデバイスに関連するリソースに提供される前にリングバッファに提供されることを特徴とする請求項3に記載のシステム。
- 6前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントは、コンピューティングデバイスからのコネクションを通して前記クローズドコンピューティングデバイスに提供されることを特徴とする請求項1に記載のシステム。
- 7前記少なくとも1つの無署名ソフトウェアコンポーネントは、(a)コンピューティングデバイスからのダイナミックコミュニケーションおよび(b)前記コンピューティングデバイスからのストリーミングのうちの一方を使用して前記クローズドコンピューティングデバイスに提供されることを特徴とする請求項1に記載のシステム。
- 8クローズドシステムにおいて無署名 ソフトウェア コンテンツ コンポーネント を実行し、アクセスをセキュアにするための方法であって、 該方法は、前記クローズドシステムに記憶されたコンピュータプログラムを前記クローズドシステムが実行することによって実行され、 クローズドコンピューティングデバイスを、 複数のクローズドコンピューティングデバイスのいずれかにおいて動作するために 署名当局によって許可されたソフトウェアコンテンツコンポーネントを実行するように構成するステップと、 前記クローズドコンピューティングデバイスを、前記クローズドコンピューティングデバイス上で少なくとも1つの無署名ソフトウェアコンテンツコンポーネントを実行するように構成するステップと、を含み、 前記少なくとも1つの無署名ソフトウェアコンポーネントは、前記署名当局によって許可された前記ソフトウェアコンテンツコンポーネント用のインタフェースを提供することに加えて、前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネント用のインタフェースを前記クローズドコンピューティングデバイスに仮想化させることによって 、前記クローズドコンピューティングデバイスのリソースへのアクセスを可能にし、 前記クローズドコンピューティングデバイス上で実行されることを特徴とする方法。
- 9前記クローズドコンピューティングデバイスにユニークなユーザIDを割り当てて、前記クローズドコンピューティングデバイスの違反有無を前記ユニークなユーザIDを通してトラッキングするステップを、さらに含むことを特徴とする請求項8に記載の方法。
- 10前記インタフェースを使用するステップをさらに含み、前記インタフェースはグラフィックスレイヤ、オーディオレイヤ、入力レイヤ、およびストレージレイヤのうちの少なくとも1つに対応していることを特徴とする請求項8に記載の方法。
- 11前記グラフィックスレイヤ、前記オーディオレイヤ、前記入力レイヤ、および前記ストレージレイヤのうちの少なくとも1つを、前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントに関連するデータがストアされる第1のバッファ、および前記データが前記第1のバッファからコピーされる第2のバッファでなるように構成するステップをさらに含み、前記データは前記第2のバッファにおいて有効性検査されることを特徴とする請求項10に記載の方法。
- 12前記有効性検査のあと、前記データを前記クローズドコンピューティングデバイスに関連するリソースに提供するステップをさらに含むことを特徴とする請求項11に記載の方法。
- 13前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントを、コンピューティングデバイスからのコネクションを通して前記クローズドコンピューティングデバイスに提供するステップをさらに含むことを特徴とする請求項8に記載の方法。
- 14前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントを、(a)コンピューティングデバイスからのダイナミックコネクションおよび(b)前記コンピューティングデバイスからのストリーミングのうちの一方を使用して前記クローズドコンピューティングデバイスに提供するステップをさらに含むことを特徴とする請求項8に記載の方法。
- 15クローズドシステムにおいて無署名 ソフトウェア コンテンツ コンポーネント を実行し、アクセスをセキュアにするためのコンピュータ実行可能命令を収めているコンピュータ可読 記憶 媒体であって、前記コンピュータ実行可能命令は、 クローズドコンピューティングデバイスを、 複数のクローズドコンピューティングデバイスのいずれかにおいて動作するために 署名当局によって許可されたソフトウェアコンテンツコンポーネントを実行するように構成することと 少なくとも1つの無署名ソフトウェアコンテンツコンポーネントを前記クローズドコンピューティングデバイス上で実行するように構成することと、を含み、 前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントは、前記署名当局によって許可された前記ソフトウェアコンテンツコンポーネント用のインタフェースを提供することに加えて、前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネント用のインタフェースを前記クローズドコンピューティングデバイスに仮想化させることによって 、前記クローズドコンピューティングデバイスのリソースへのアクセスを可能にし、 前記クローズドコンピューティングデバイス上で実行されることを特徴とするコンピュータ可読 記憶 媒体。
- 16前記クローズドコンピューティングデバイスにユニークなユーザIDを割り当てて、前記コンピューティングデバイスの違反有無を前記ユニークなユーザIDを通してトラッキングすること、をさらに含むことを特徴とする請求項15に記載のコンピュータ可読 記憶 媒体。
- 17前記インタフェースを使用することをさらに含み、前記インタフェースはグラフィックスレイヤ、オーディオレイヤ、入力レイヤ、およびストレージレイヤのうちの少なくとも1つに対応していることを特徴とする請求項15に記載のコンピュータ可読媒体。
- 18前記グラフィックスレイヤ、前記オーディオレイヤ、前記入力レイヤ、および前記ストレージレイヤのうちの少なくとも1つを、前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントに関連するデータがストアされる第1のバッファ、および前記データが前記第1のバッファからコピーされる第2のバッファからなるように構成することをさらに含み、前記データは前記第2のバッファにおいて有効性検査されることを特徴とする請求項17に記載のコンピュータ可読 記憶 媒体。
- 19前記有効性検査のあと、前記データを前記クローズドコンピューティングデバイスに関連するリソースに提供することをさらに含むことを特徴とする請求項18に記載のコンピュータ可読 記憶 媒体。
- 20前記少なくとも1つの無署名ソフトウェアコンテンツコンポーネントを、(a)コンピューティングデバイスからのダイナミックコネクションおよび(b)前記コンピューティングデバイスからのストリーミングのうちの一方を使用して前記クローズドコンピューティングデバイスに提供することをさらに含むことを特徴とする請求項15に記載のコンピュータ可読 記憶 媒体。
Independent claims20
58 paragraphs, as filed
The technology relates to the field of computing, and more specifically to the gaming environment.
Gaming systems are widespread in today's computing environments. A game console is typically a closed system that allows only signed games controlled by a hardware vendor to run on that console. .. The reason for this limitation is to leave a business model for publishers with minimal intellectual property fraud in a tightly controlled environment, or to play the type of game on a gaming machine. It varies with or without control, for example, allowing content that meets the expectations of parents for the child playing the content. In addition, allowing signed code to be executed is fraudulent in games in online communities where it is essential that certain assumptions are accurate, such as community scores and digital currencies. Will help control and mitigate the possibility of doing.
However, these tight limitations that exist in game consoles prevent the entire larger creative community from developing games or game-like applications on closed game consoles. Therefore, the important thing is, among other things, the need to enable developers, gamers, general game enthusiasts (hobbyists), and student game developers to write games for traditional closed systems. Is to deal with. Also importantly, we are spending time and effort hacking into the game console to allow the execution of unsigned code on that console (otherwise, this specification described below. According to the subject matter disclosed in the book, it is to address the problem (when you do not have to spend such time and effort).
Mechanisms are provided that allow the execution of unsigned content in a closed system and secure resources when such unsigned content is executed on that system. In one aspect of the subject matter disclosed herein, an access layer is used between the operating system layer of a closed system and the actual unsigned content. Further, this access layer can be composed of various sublayers such as a graphics layer, an audio layer, an input layer, and a storage layer. These layers can control the type and amount of access that unsigned content can make to the native operating system layer and its associated resources.
In one aspect, not limited to the examples, any of the sublayers listed above includes an input buffer when the closed system is in user mode and a corresponding validation buffer when the closed system is in supervisor mode. , It can consist of various buffers, where information (code and / data) is copied from the input buffer to the validation buffer (because it is validated in the validation buffer). To). In addition, various other components can be used, such as the ring buffer, which can store the commands validated in the validation buffer above.
As can be understood from the above, this brief description is a brief introduction to some of the concepts detailed below in the detailed description section. This summary does not identify the key features or basic features of the subject matter described in the claim, nor does it assist in determining the scope of the subject matter described in the claim.
The above-mentioned outline description is described with reference to the accompanying drawings in order to facilitate its understanding, together with the detailed description described below. To illustrate the disclosures of the present invention, various aspects of the disclosures are shown. However, the matters to be disclosed are not limited to the specific aspects being discussed. In the drawing<figref num="1">FIG. 5 illustrates a traditional system in which only signed software components, i.e., signed games, can run on a typical closed system.</figref><figref num="2">It is a figure which shows the system which both the signed game and the unsigned game can run on a closed system.</figref><figref num="3">It is a figure which shows that the signed game is authenticated, and the unsigned game is not authenticated.</figref><figref num="4">It is a diagram showing that there is a game access layer between the gaming operating system and the unsigned content, where this intervening layer controls access by the unsigned content.</figref><figref num="5">FIG. 5 is a detailed diagram showing that the access layer abstracted in FIG. 4 is composed of various sublayers such as a graphics layer, an audio layer, an input layer, and a storage layer.</figref><figref num="6">FIG. 5 is a detailed view showing the aspects discussed with reference to FIG. 5, that is, the aspects discussed with a focus on the various buffers used by the sublayers.</figref><figref num="7">It is a diagram showing that what the closed system is doing is virtualizing the hardware so that the unsigned code is executed.</figref><figref num="8">It is a diagram showing that there are innumerable ways to enable unsigned content to be provided from a computing source to a closed system.</figref><figref num="9">FIG. 5 is a block diagram illustrating an exemplary system environment (but not limited to) capable of executing unsigned content according to the subject matter disclosed herein.</figref><figref num="10">FIG. 6 is a block diagram illustrating an exemplary multimedia console device (but not limited to) capable of performing said unsigned content according to another aspect of the subject matter disclosed herein.</figref><figref num="11">It is a figure which shows the execution and access security of unsigned content in a closed system in a block diagram format.</figref>
<u style="single">Overview</u> In general, game consoles allow only signed games to run. To prevent signed games from exposing closed consoles in an exploitive way, games are forced to go through a process called certification. This certification requires the game to follow a strict set of rules before allowing it to be signed. These strict rules unknowingly create exploits that can allow closed consoles to be hacked in ways that interfere with content publishers as well as manufacturers. Is designed to prevent. Specifically, it is important to prevent piracy of content on closed consoles.
All games running on a closed console require access to resources such as memory, CPU access, GPUs, optical disk drives, input devices, and persistent storage (such as hard disk drives). Unsigned games are not passed through the typical authentication process required for signed games, so this specification is to show how to ensure that the data flowing to the resources protected from unsigned games is valid. Systems, methods, and computer-readable media are disclosed.
In aspects not limited to the illustrations disclosed herein, all data is passed through a resource management layer that handles validation of data flowing back and forth from unsigned games and protected resources in a closed gaming console. This layer ensures that all protected resources are not directly accessible by unsigned games, and that all entry points that enter the protected resource are well known. If an unsigned game attempts to gain unauthorized access to a protected resource, or access a resource that is totally off limits, this layer can immediately stop all execution. In addition, the entry points available from the resource management layer can be fixed and pre-determined by the console maker. This can help prevent unsigned code from arbitrarily creating new entry points.
Some more dangerous protection resources can provide different levels of abstraction. High-level buffers can be used in conjunction with specialized protocols to abstract most calls to the underlying resource. Calls in high-level buffers at keypoints can be flushed to the resource management layer, validated, and then sent to protected resources.
Finally, when the resource management system detects an unexpected activity, such as a security breach, it can log that activity to a central location. Using this mechanism in combination with a unique user identity system, console makers can track the number of security breaches grouped by user. The data presented by this system allows console makers to track the sources of security exploits and properly handle inviolate users.
<u style="single">Aspects of unsigned content in closed systems</u> This section of the subject matter disclosed herein refers to the execution of unsigned content in a closed system in such a way that its execution is secure (ie, in a manner that protects resources in the closed system). The explanation is centered. To facilitate understanding of these aspects, it is helpful to compare these aspects with prior art.
Therefore, FIG. 1 is a diagram showing a conventional system in which only a signed software component, that is, a signed game can be executed on a typical closed system. Specifically, a closed system 180 is shown, in which various signed games, such as games A185 and game B190, can be run 195 against the closed system 180. These games 185, 190 are generally licensed by the manufacturer of the closed system 180, but in some respects they may also be licensed by the game developer or some other third party. In each case, the system 180 is considered "closed" in the sense that not all software applications can run there, as in the case of a general purpose personal computer (PC).
Typical signature processes are well known in this area and, as mentioned above, serve a variety of purposes, such as limiting intellectual property infringement and controlling who has access to the content. ing. However, despite the many advantages of this type of closed system 180, it does not necessarily limit the development of other "unsigned" games (games that are not officially authorized by the signing authorities). Not always. Such unsigned games can be games built on top of existing games (or even such signed games, if permission is obtained from the publisher of the "signed" game. Yes), or it could be a newly developed game that is not feasible on a closed system.
So, in contrast to Figure 1, Figure 2 shows a system that allows both signed and unsigned games to run on a closed system. In contrast to the closed system of FIG. 1, ie, the closed system 180, this different closed system 200 can run not only the signed games A205 and B210, but also the unsigned games C215 and D220. It should be noted that, as is well understood, the illustrated closed systems 180 and 200 are merely illustrations and are not limited to any particular manufacturer or generation of computing devices (systems of this type are shown in Figure 1). (Shown in an abstract box, not a concrete diagram in Figure 2).
As mentioned above, running unsigned gaming content C215 and D220 on system 200, which generally cannot run unsigned content, extends the gaming capabilities of such system 200. Will be done. However, running unsigned gaming content also poses a security issue. Eventually, malicious or unwanted code and data runs on the gaming system 220 because the games C215 and D220 are unsigned, that is, they have not been verified for what they are intended for. May be done. The presence of a security layer is required, as described briefly below with reference to Figure 4. This layer of security also has the advantage, first of all, that it not only allows the execution of unsigned games, but also prevents unwanted code and data from interacting with the resources of the gaming system 200.
Next, FIG. 3 shows that the signed game is authenticated and the unsigned game is not. Specifically, games A305 and B310 have been signed by some certification or validation authority to allow these games to run 335 on a particular closed system appointed by that authority. Such signed games A305 and b310 are said to be certified 325. In contrast, the unauthenticated game 330 is a game that has not been signed by any of these authorities, namely games A 315 and B 320, so it is generally not possible to run it on the closed system 300. According to the above and following aspects of the disclosures herein, such games 315, 320 can be run on the closed system 300 (in addition to the originally signed games A305 and B310).
Next, with reference to FIG. 4, FIG. 4 shows that there is an access layer between the gaming operating system and the unsigned content, where this intervening layer controls access by the unsigned content. Shown. Game access layer 405 is abstracted (this is explained in detail below with reference to Figures 5 and 6). Briefly, this can be understood in a broad sense as a kind of interface that the unsigned content 410 interacts with. In practice, this represents virtualized hardware for unsigned content 410, ensuring that unsigned content 410 does not have to be rigorously compatible with operating system layer 400 (this is signed gaming). Content, eg, similar to games A305 and B310 shown in Figure 3).
Specifically, the access layer 405, which is shown as an abstraction in FIG. 4, is described in detail with reference to FIG. The access layer 405 can consist of at least six layers: a graphics layer 510, an audio layer 515, an input layer 520, a storage layer 525, a network layer 527, and a numerical math layer 528. Each of these layers is responsible for a different task. For example, the graphics layer 510 may be responsible for rendering graphics, including, but not limited to, flat shading, regular mapping, texture mapping, and the like. The audio layer 515, as its title suggests, can be responsible for the audio on the closed system (as is well understood, this audio may or may not be associated with unsigned content. It may not be, it could be independent audio from a CD, DVD, or some kind of computer device file). The input layer 520 can be responsible for handling input from the user, such as selecting controller buttons, clicking with an input device, and so on. Storage Layer 525 can be responsible for storing some gaming content or recalling some gaming content (and this is code that brings the gaming content to the same level as the new console hardware). And / or by storing data, legacy software (legacy) Can be used to enable the execution of software)). Network Layer 527 enables multiplayer gaming, where both the console side and one of the associated server side networking stacks are enabled to enable an online multiplayer experience. Finally, the math layer 528 allows the execution of certain math functions, for example, to streamline map rendering (if graphics are involved). In each case, each of these layers 510, 515, 520, 525, 527, 528 must pass through an unsigned code such as managed code 530 to ensure secure computing. The unsigned code helps to obtain a secure gate between user mode 500 and supervisor (eg kernel) mode 505 (ie, for purposes not intended by the console maker or other related parties). It does not inherit the underlying native OS Layer 540 and any related console sources).
Therefore, as shown in FIG. 5, some managed codes 530 related to the unsigned code can be configured by various sublayers 510, 515, 520, 525, 527, 528 as described above. Provided to layer 405. The managed code 530 is provided from the user mode 500 side, filtered through these sublayers and passed to the supervisor mode 505 side. These 6 layers 510, 515, 520, 525, 527, 528 are (1) the appropriate interface exposed to managed code 530, and (2) within native OS layer 540, managed code. It guarantees that only managed code 530 will access the resources that the 530 is supposed to access. Thus, overall, the access layer 405 plays a useful role in the first case and a defensive role in the second case, each allowing the execution of unsigned content, with incorrect unsigned content. Prevent access to certain resources. In other cases, if managed code 530 has direct access to native OS layer 540 in supervisor mode 505, then code 530 has full control over resources that are native to the gaming console. Become. However, this may not be desirable for the reasons mentioned above, such as the console being used for purposes not intended by the manufacturer.
FIG. 6 is a detailed view showing the above-described aspects with reference to FIG. For example, if a person receives one of the above sublayers, such as graphics layer 510, and looks at that subcomponent, these components will look like the components shown on the right side of Figure 6. .. First, the graphics layer 510 is shown on the left side of Figure 6, which will receive some input 600 (which may provide output, but this aspect is here limited to input presentation purposes. ing).
Therefore, the graphics layer 510 can include an input buffer 605 that accepts the input 600. As will be easily understood by those familiar with this field, it is possible to use different types of buffers here, such as vertex buffers, index buffers, vertices and pixel shaders. is there. After the code and / or data is entered, it can be copied from the user mode 500 side to the supervisor mode 505 side. Therefore, it is copied from input buffer 605 to validation buffer 610. In this validation buffer 610, the information (code, data, and other equivalents) is validated and that it is the type of information that is supposed to be allowed access to supervisor mode 505. You can be sure.
The criteria under which what is expected to be accessible in supervisor mode 505 can be defined by the console manufacturer or other third party, which is continually updated and updated by such party. Can be monitored. Therefore, a check is made on the information stored in the validation buffer 610. For example, the handle can be validated in the validation buffer 610. Here, the "handle" is understood to be a token, typically a pointer, that allows a program to access a resource such as a library function or some hardware resource, as described above. .. If this information is valid, it can be passed to ring buffer 615 for execution by native console resources.
As is well understood, other buffer architectures can be used if the type of information input 600 is known. The side of ring buffer 615 may be used when the command is stored in validation buffer 610. On the other hand, the ring buffer 615 may not be needed if there are parameters for the command.
In another aspect of the subject matter disclosed herein, FIG. 7 shows that what a closed system does is virtualize the hardware on which the unsigned code is executed. Therefore, basically, a virtual environment 708 in the form of a virtual machine is constructed, in which unsigned code can be executed. Since such unsigned code can be executed in user mode, when in supervisor mode 505, control over the system 706 resources that the unsigned code should otherwise have is limited. The native OS layer 704 can virtualize software and hardware commensurate with the unsigned code, giving the unsigned code only the desired set of resources that the native OS layer 704 can access and / or control.
As anyone familiar with the field will understand, it is possible to use different virtual machines, each with a different virtual environment for each unsigned game. Alternatively, it is possible to use some kind of universal virtual machine standard to run all or part of an important subset of unsigned games there. In this case, these are merely implementation details intended by the material disclosure of Closed System 706, which provides a virtual machine environment for unsigned games to run there.
Finally, there are many ways in which unsigned content can be delivered to a closed system from a computing source, as shown in Figure 8. The intent of this aspect is to show that the access layer 504, referred to in FIG. 4 and detailed with reference to FIGS. 5 and 6, can handle various types of unsigned content. The type of content intended in this aspect is content that is provided only once to the access layer of closed computing system 808, content that is streamed to system 806, or content that is streamed to system 806 on a regular and dynamic basis. There is content to be provided.
As used herein, an architecture that provides various types of content is intended herein. In some types, there may be an intervening server 810 between the compute sources 802, 804, 806 and the closed system 808, while in other types there is a direct connection between the compute source and the closed system 808. There are times when. As anyone familiar with the field can easily understand, there are many ways in which content can be delivered to a closed system. When content is given to closed system 808, system 808 receives this content in access layer 405 shown in FIG. 4, graphics layer 510 shown in FIG. 5, audio layer 515, input layer 520 and storage layer 525, and FIG. Its contents can be run through the various buffers 605, 610 and 615 shown. How the information is received, stored, and passed to the system 808 source depends on the constraints imposed by the system 808 manufacturer on the access layer, and thus on the content of the unsigned content.
<u style="single">Illustrative computing device</u> As mentioned above, the subject matter disclosed herein applies to any device, where it is desirable for unsigned content to run otherwise on a closed system. It should be noted that, as will be appreciated as described above, other content equivalent to that of unsigned content can also work with all types of computing objects disclosed herein. Therefore, the following general purpose remote computer described below with reference to FIG. 9 is merely an example, and the subject matter disclosed herein is a stand-alone device or has network / bus interoperability and interoperability. It can be implemented with any client device or portable device, regardless of the device. Therefore, the subject matter disclosed herein is networked hosted such that very few or minimal resources are involved. It can be realized in a service) environment, for example, in a networked environment where the client device is only an interface with the network / bus, such as an object placed on an appliance.
Although not necessarily required, the subject matter disclosed herein may also be achieved in part through an operating system for use by developers of services for devices or objects, and / or herein. It can also be incorporated into application software that operates in connection with the subject of disclosure. Software can be described in the general context of computer executable instructions executed by one or more computers, such as client workstations, servers or other devices, such as program modules. As will be appreciated by those familiar with the field, the subject matter disclosed herein can be implemented in conjunction with other computer system configurations and protocols.
Therefore, FIG. 9 is a diagram showing an example of an appropriate computing system environment 100a in which various aspects described with reference to FIGS. 2 to 8 can be realized, and as is clear from the above, this is a diagram. The computing system environment 100a is merely an example of a suitable computing environment for a running device and does not imply any limitation on the use or scope of functionality of these aspects. Nor is this computing environment 100a understood to have any dependencies or requirements with respect to any or a combination of the components shown in the exemplary operating environment 100a.
Explained with reference to FIG. 9, the exemplary remote device for realizing this aspect includes a general purpose computing device in the form of a computer 110a. The components of the computer 110a include, but are not limited to, a processing unit 120a, a system memory 130a, and a system bus 121a that connects various system components including the system memory to the processing unit 120a. The system bus 121a can be in any of several types of bus structures, including memory buses or memory controllers, peripheral buses, and local buses using any of the bus architectures. ing.
The computer 110a is generally equipped with various computer-readable media. The computer-readable medium can be any medium accessible by the computer 110a, if available. For example, computer-readable media include, but are not limited to, computer storage media and communication media. Computer storage media are volatile and non-volatile, removable and non-removable, realized by any method or technology for storing information such as computer-readable instructions, data structures, program modules or other data. Both media are included. Computer storage media include RAM, ROM, EEPROM, flash memory or other memory technologies, CDROMs, DVDs (digital versatile). Includes disk) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or other media that can be used to store desired information and is accessible by computer 110a. However, it is not limited to these. Communication media embody computer-readable instructions, data structures, program modules or other data with modulated data signals such as carrier waves or other transport mechanisms, including some information distribution medium. It is common.
System memory 130a includes computer storage media in the form of volatile and / or non-volatile memory, such as ROM (read only memory) and / or RAM (random access memory). A basic input / output system consisting of basic routines that help transfer information between elements in computer 110a, such as at startup, can be stored in memory 130a. The memory 130a typically has immediate access to the processing unit 120a and / or also houses the data and / or program modules that are currently being operated on by the processing unit 120a. For example, memory 130a can also, but is not limited to, store operating systems, application programs, other program modules, and program data.
Computer 110a may also include other removable / non-removable volatile / non-volatile computer storage media. For example, the computer 110a may include a hard disk drive that reads and writes to and from a non-removable non-volatile magnetic medium, a magnetic disk drive that reads and writes to and to a removable non-volatile magnetic disk, and / or a CD-ROM or other. It is also possible to include an optical disk drive that reads and writes to and from a removable non-volatile optical disk such as an optical medium. Other removable / non-removable volatile / non-volatile computer storage media that can be used in the illustrated operating environment include magnetic tape cassettes, flash memory cards, and DVDs (digital versatile). disk), digital videotapes, solid-state RAM, solid-state ROM, etc., but not limited to these. Hard disk drives are typically connected to system bus 121a through a non-removable memory interface such as an interface, and magnetic disk drives or optical disk drives are connected to system bus 121a through a removable memory interface such as an interface. It is common to have an interface.
In addition to allowing the user to give input to a closed computer device through a controller, the user can command and information through the input device, such as a keyboard and mouse, a trackball or a pointing device commonly referred to as a touchpad. Can be entered into the computer 110a. In addition to these peripheral devices, other input devices include microphones, joysticks, gamepads, satellite dishes, scanners, and the like. These and other input devices are often connected to the processing unit 120a through a user input 140a and an associated interface coupled to the system bus 121a, but are a parallel port, game port or USB (universal serial). It may also be connected by other interfaces and bus structures, such as bus). The graphics subsystem may be connected to system bus 121a. A monitor or other type of display device is also connected to the system bus 121a through an interface, such as the output interface 150a, which may be in contact with video memory. In addition to monitors, computers may also be equipped with other peripheral output devices such as speakers and printers, which may be connected through an output interface.
Computer 110a can operate in a networked or distributed environment using logical connections with one or more other remote computers, such as remote computer 170a, and the remote computer is a device. May have different media capabilities than 110a. The remote computer 170a may be a personal computer, server, router, network PC, peer device or other common network node, or any other remote media consuming or transmitting device and is an element described above in connection with computer 110a. May have any or all of. The logical connection shown in Figure 9 includes a network 171a such as a LAN (local area network) or WAN (wide area network), but may also include other networks / buses. Such networking environments are widespread in homes, offices, corporate computer networks, intranets and the Internet.
When used in a LAN networking environment, computer 110a is connected to LAN171a through a network interface or adapter. When used in a WAN networking environment, the computer 110a is typically equipped with a modem or other means for establishing communication over the WAN, such as the Internet. Modems can be internal or external, both of which can be connected to system bus 121a via a user input interface with input 140a or other suitable mechanism. In a networked environment, the program module illustrated in connection with computer 110a or a portion thereof can be stored in a remote memory storage device. As will be understood from the above, the network connections illustrated and described are exemplary, and other means for establishing communication links between computers can also be used.
<u style="single">Illustrated multimedia (closed) console environment</u> Next, with reference to FIG. 10, FIG. 10 is closed for a limited amount of software components signed by a signing authority (whether a closed device maker or a gaming publisher). It is a block diagram showing another example computing device (but not limited to this example), that is, an example multimedia console, which may have been. FIG. 10 shows the functional components of the Multimedia Console 100 that can realize the aspects of the subject matter disclosed herein. This multimedia console 100 has a level 1 (L1) cache 102, a level 2 (L2) cache 104, and a flash ROM (Read-only). It is equipped with a central processing unit (CPU) 101 equipped with Memory) 106. Level 1 cache 102 and level 2 cache 104 improve processing speed and throughput by temporarily storing data and reducing the number of memory access cycles. The flash ROM 106 can store executable code that is loaded during the initial phase of the boot process when the multimedia console 100 is powered on. Alternatively, the executable code loaded during the initial boot phase may be stored in a FLASH memory device (not shown). In addition, ROM 106 may be located in a different location than CPU 101.
The console is equipped with various resources such as graphics processing unit (GPU) 108 and video encoder / video codec (coder / decoder) 114, and video processing for high speed and high resolution graphics processing. Available from the pipeline to the console. In this setup, data is sent from the graphics processing unit 108 to the video encoder / video decoder via the bus. The video processing pipeline outputs the data to A / V (audio / video) port 140, from which it is sent to the television or other display. A memory controller 110 is connected to the GPU 108 and CPU 101 to facilitate processor access to various types of memory 112, such as RAM (Random Access Memory). The various types of memory are not limited to RAM.
The multimedia console 100 includes an I / O controller 120, a system management controller 122, an audio processing unit 123, a network interface controller 124, a first USB host controller 126, a second USB controller and a front panel I / O subassembly 130. Equipped, these are preferably mounted on module 118. USB controllers 126 and 128 include peripheral controllers 142 (1) -142 (2), wireless adapter 148, and external memory unit 146 (eg, flash memory, external CD / DVD). Acts as a host for ROM drives, removable media, etc.). Network interface 124 and / or wireless adapter 148 allows access to networks (eg, the Internet, home networks, etc.) and Ethernet® (Ethernet®) cards, modems, Bluetooth modules. It can be any of a wide variety of wired or wireless Internet components, including cable modems and the like.
The system memory 143 is for storing application data loaded during the boot process period. Media drive 144 is available, which can be configured with a DVD / CD drive, hard disk, or other removable media drive. The media drive 144 may be built into the multimedia console 100 or external. The application data is accessed through the media drive 144 and can be executed, played back, etc. by the multimedia console 100. The media drive 144 is connected to the I / O controller 120 via a serial ATA bus or other bus such as a high speed connection (eg IEEE1394).
The system management controller 122 provides various service functions related to guaranteeing the availability of the multimedia console 100. The audio processing unit 123 and the audio codec 133 form a corresponding audio processing pipeline with high fidelity and stereo processing. The audio data is carried between the audio processing unit 123 and the audio codec 126 via a communication link. The audio processing pipeline outputs data to the A / V port and is reproduced by an external audio player or device with audio capabilities.
The front panel I / O subassembly 130 supports not only the power button 150 and eject button 152, but also the exposed LEDs (light emitting diodes or other indicators) on the outside of the multimedia console 100. System power supply. Module 136 powers the components of the multimedia console 100. Fan 138 cools the circuitry inside the multimedia console 100.
The CPU 101, GPU 108, memory controller 110, and various other components inside the multimedia console 100 are interconnected via one or more buses, some of which use one of the various bus architectures. Includes serial and parallel buses, memory buses, peripheral buses, and processor or local buses.
When the multimedia console 100 is powered on or rebooted, application data is loaded from system memory 143 into memory 112 and / or caches 102, 104, allowing it to run on CPU 101. The application can present a graphical user interface that ensures a consistent user experience when navigating to the various media types available in the multimedia console 100. During operation, applications and / or other media contained within Media Drive 144 can be launched or played from Media Drive 144 to provide additional functionality to the Multimedia Console 100.
The multimedia console 100 can operate as a stand-alone system simply by connecting the system to a television or other display. When in this standalone mode, the multimedia console 100 allows one or more users to interact with the system, watch movies, listen to music, and so on. However, with built-in broadband connectivity made available through network interface 124 or wireless adapter 148, the multimedia console 100 can even operate as a participant in a larger network community.
The multimedia console illustrated in FIG. 10 is a typical multimedia console that can be used to run multimedia applications such as games. Multimedia applications should be enhanced with system features, including, for example, system settings, voice chat, networked gaming, the ability to interact with other users over the network, email, browser applications, etc. Can be done. By using such a system function, it is possible to improve the function of the multimedia console so that players in different locations can play a common game via the Internet.
Also, over time, system features may be updated or added to multimedia applications. According to the systems and methods described herein, multimedia developers can use multimedia applications without making significant changes to the multimedia applications to obtain these system features. These system features can be obtained through another system application that runs in association. For example, by incorporating features related to networking capabilities into system applications, multimedia (eg, game) developers can easily adapt multimedia applications to get networking capabilities with less effort. Becomes possible. One such feature is the system level notification feature for multi-user and networked users. If you make system-level notifications part of your system application instead of handling them by individual multimedia applications like games running on your system, you can handle notification displays such as game invitations for multimedia application developers. By being excluded from the development process, developers can focus on the multimedia application itself.
As described above, exemplary embodiments of the invention have been described in relation to various computing devices and network architectures, the underlying concept of which is the use of input devices to control devices or systems. It can be applied to any computing device or system with. For example, an algorithmic and hardware implementation of the aspects described here can be downloaded from the server as an independent object on the device, as part of another object, or as a reusable control. Even if it is an object, it is a "middle" between the device or object and the network. It can be applied to the operating system of computing devices provided as "man)", as a distributed object, as hardware, in memory, or in any combination of those listed above. Illustrative programming languages, names and examples have been selected herein to represent various choices, but the languages, names and examples thereof are not limiting. Figure 11 shows one way to achieve a flow of algorithms that allows unsigned code to run on a closed system, but will be understood by anyone with normal knowledge in this area. In addition, there are many ways to prepare object codes and nomenclatures that achieve the same, similar or equivalent functions achieved by the various embodiments of the subject.
As mentioned above, the various techniques described herein can be implemented in association with hardware or software and, where applicable, in association with a combination of hardware and software. Accordingly, the methods and devices disclosed herein, or certain aspects or parts thereof, are tangible, such as floppy diskettes, CD-ROMs, hard drives, or any other machine-readable storage medium. It can be in the form of program code (ie, an instruction) embodied in a medium, where when the program code is loaded into a machine such as a computer and executed by the machine, that machine is disclosed herein. It becomes a device for carrying out the side of. When the program code is executed on a programmable computer, the computing device is a processor, a storage medium readable by the processor (including volatile and non-volatile memory and / or storage elements), and at least one input device. , And at least one output device is typically installed. One or more programs that can implement or utilize the software provided in accordance with these aspects are preferably written in a high-level procedural or object-oriented programming language to communicate with a computer. However, these programs can also be written in assembly or machine language if desired. In either case, the language can be a compiled or interpretive language and can be combined with what is implemented in hardware.
The methods and devices of the aspects disclosed herein are embodied in the form of program code transmitted over some transmission medium, such as electrical wiring or cabling, fiber optics, or any other form of transmission. It can also be done through communication, where the program code is received, loaded into the machine, such as EPROM, gate array, programmable logic device (PLD), client machine, and executed by the machine. When so, the machine becomes a device for carrying out the subject matter disclosed herein. When implemented on a general purpose processor, the program code, in combination with the processor, provides a unique device that operates to activate the features of the subject matter disclosed herein. Moreover, the storage techniques used in connection with this aspect can always be a combination of hardware and software.
The aspects described above have been described in relation to preferred embodiments of various drawings, but as will be appreciated, the use of other similar embodiments may also be modified or added to the embodiments described above. , It is also possible to perform the same function without departing from that range. For example, as will be recognized by those familiar with the field, the methods described herein relate to whether they are wired or wireless, such as gaming consoles, handheld computers, portable computers, etc. It can be applied to any computing device or environment, and can be applied to any number of such computing devices connected over a communication network and interacting through the network.
Moreover, as it is not surprising, a variety of computer platforms are intended, including handheld device operating systems and other application-specific operating systems, especially with the increasing number of networked wireless devices. There is. Further, the functions of the subject matter disclosed herein can be implemented within or across multiple processing chips or devices, and storage can also span multiple devices. is there. Accordingly, the aspects described herein are not limited to any single embodiment, the area or scope of which is to be construed as described in the claims.
<u style="single">wrap up</u> To summarize the above, various methods, systems, and computer-readable media can embody the aspects described above. For example, in FIG. 11, the following aspects are intended to execute unsigned content in a closed system and secure access. In block 1100 of Figure 11, such execution and securing can be done using a closed computing device such as a gaming console, where the closed computing device is software authorized by the signing authority. It is configured to run content components, such as signed software. In addition, unsigned software content components can be run on such closed computing devices, where unsigned software content components allow closed computing devices to virtualize their interfaces, ie, unsigned software. Is running on a closed computing device by having the closed system provide input so that it can run, as shown in block 1105. Therefore, the term "interface" herein is intended to broadly understand the inputs and outputs commonly used by software. Such a virtualization interface is provided in addition to the provision of a representative interface for signed software content components authorized by the signing authority. Therefore, in block 1100, it is determined whether the signed content is running in block 1115 or the unsigned content is running in block 1120. The former case is a conventional case described with reference to FIG. The latter case, described in detail herein with reference to FIGS. 2-8, provides an extended use of the closed gaming system.
Thus, as already mentioned above, and as shown in block 1125 of FIG. 11, the interface is among the graphics layer, audio layer, input layer, and storage layer (first shown in FIG. 5). It can be associated with at least one. In addition, at least one of the graphics layer, audio layer, input layer, and storage layer is the first buffer in which the unsigned software content component is stored, and the first buffer in which the data is stored, as shown in block 1130. It can consist of various buffers, such as a second buffer copied from (where the data is validated in the second buffer). These aspects are clearly shown in Figure 6. Therefore, the data can be given to resources related to the closed computing device (memory, CPU access, optical disk drive, input device, hard disk drive, etc.) after the validity check is performed. Alternatively, the data can be fed to the ring buffer after this validation is done and before it is fed to the resource associated with the closed computing device. It should be noted that, as will be understood by those familiar with the field, this is merely an example aspect of the subject matter disclosed herein, and is not limited to this aspect.
As mentioned above in connection with other drawings, such as Figure 8, unsigned software content components (eg, user- or developer-created games) are delivered through a connection from a computing device (or otherwise, In the usual case, it can be provided to a closed computing device (through a DVD or some other optical device, magnetic device or equivalent device, etc.). In addition, such offerings can be made dynamically through communication from computing devices (whether PCs, servers, or other gaming consoles), or else from such computing devices. It can also be done by streaming the unsigned content of. Not surprisingly, this summary is not limited, but merely an example. Also, as is clear, assigning a unique user ID to a closed computing device and tracking the presence or absence of a violation of the closed computing device through that unique user ID is not described here, but described above. Other aspects of this are also intended herein, even if not explicitly mentioned in this summary.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| US20050223239A1 | Cites | United States of America |
| JP2004348397A | Cites | Japan |
| JP2004328359A | Cites | Japan |
| JP11112494A | Cites | Japan |
| JP2006330835A | Cites | Japan |
| JP2006244508A | Cites | Japan |
11 members in 6 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 11636199 | United States of America | – | |
| 63619906 | United States of America | A | |
| 2007085062 | United States of America | W | |
| 2006636199 | – | – | – |
| 2007085062 | – | – | – |
| US20060636199 | – | – | – |
| WO2007US85062 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| US2008140958A1 | United States of America | A1 | |
| CA2669011A1 | Canada | A1 | |
| WO2008073676A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN101553840A | China | A | |
| EP2126831A1 | European Patent Office (EPO) | A1 | |
| JP2010528343A | Japan | A | |
| EP2126831A4 | European Patent Office (EPO) | A4 | |
| JP5111516B2This record | Japan | B2 | |
| US8875271B2 | United States of America | B2 | |
| CA2669011C | Canada | C | |
| CN101553840B | China | B |
19 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5111516
- Publication, DOCDB
- 5111516
- Publication, EPODOC
- JP5111516B
- Application
- 2009540373
- Application, DOCDB
- 2009540373
- Application, EPODOC
- JP20090540373
Titles2
- Japanese
- クローズドシステムにおける無署名コンテンツの実行とアクセスのセキュアリング
- English
- Secure ring of unsigned content execution and access in closed systems
Classification
- CPC, 5
- G06F21/6281
- G06F3/0659
- G06F9/455
- G06F9/545
- G06F2221/2109
- IPC, 3
- G06F21 12
- A63F13 00
- G06F21 64
