Program execution apparatus, control method, control program and integrated circuit
Abstract
This record has no abstract on file.
Term
Projected expiry 6 January 2030.
- Priority
- Filed
- Granted
- Today
- Projected expiry
14 claims: 8 independent, 6 dependent
- 1A program execution device that operates by switching between normal mode and protection mode, and is a falsification detection means that detects falsification of a program that includes an instruction that instructs information security processing using a key.A protective storage means that is accessible only in the protected mode and securely stores the key in association with the program.With normal storage means accessible in normal mode, In the normal mode, when the tampering is not detected, the program operates according to the program, and when the instruction is detected in the program, an execution means for outputting an instruction for information security processing, and in the normal mode, when the instruction is received, Normal security measures that control switching to protected mode, andProtectIn protection modeFrom the protective storage meansA protective security processing means for reading the key, outputting the read key, and controlling the switching to the normal mode is provided, and the normal security processing means is provided in the normal mode.Using the output key as the second keyReceived, received saidThe second key is stored in the normal storage means, and the second key is stored.Perform the information security process usingAndThe tampering detection means further detects tampering with the program second.Further, when the falsification is detected by the second detection, the normal security processing means deletes the second key stored in the normal storage means in the normal mode and switches to the protection mode. Control andFurther, in the protection mode, the protection security processing means executes the information security processing by using the key stored in the protection storage means. A program execution device characterized by the fact that. 通常モードと保護モードとを切り替えて動作するプログラム実行装置であって、 鍵を用いる情報セキュリティ処理を指示する命令を含むプログラムの改竄を検出する改竄検出手段と、保護モードの場合のみアクセス可能であり、前記プログラムに対応付けて鍵を安全に記憶している保護記憶手段と、通常モードの場合にアクセス可能な通常記憶手段と、 通常モードにおいて、前記改竄が検出されない場合に、前記プログラムに従って動作し、前記プログラムの中から前記命令を検出すると情報セキュリティ処理の指示を出力する実行手段と、 通常モードにおいて、前記指示を受けると、保護モードに切り替えるよう制御する通常セキュリティ処理手段と、保護モードにおいて、前記保護記憶手段から前記鍵を読み出し、読み出した鍵を出力し、通常モードに切り替えるよう制御する保護セキュリティ処理手段とを備え、 前記通常セキュリティ処理手段は、通常モードにおいて、出力された前記鍵を第2鍵として受け取り、受け取った前記第2鍵を前記通常記憶手段に記憶し、前記第2鍵を用いて前記情報セキュリティ処理を実行し、前記改竄検出手段は、さらに、前記プログラムの改竄の第2の検出を行い、前記通常セキュリティ処理手段は、さらに、前記第2の検出により、前記改竄が検出された場合に、通常モードにおいて、前記通常記憶手段に記憶している前記第2鍵を削除し、保護モードに切り替えるよう制御し、前記保護セキュリティ処理手段は、さらに、保護モードにおいて、前記保護記憶手段に記憶している前記鍵を用いて、前記情報セキュリティ処理を実行する ことを特徴とするプログラム実行装置。
- 5The protective security processing means further generates a hash value of the program in the protection mode, and associates the generated hash value with the generated key.For the protective storage meansCharacterized by rememberingClaim 4The program execution device described in. 前記保護セキュリティ処理手段は、さらに、保護モードにおいて、前記プログラムのハッシュ値を生成し、生成したハッシュ値と生成した前記鍵とを対応付けて前記保護記憶手段に記憶する ことを特徴とする請求項4に記載のプログラム実行装置。
- 6The protective security processing means further, in the protected mode,From the protective storage meansThe hash value is read together with the key, the hash value is output together with the key, and the normal security processing means further, in the normal mode,As the second keyThe hash value is received together with the key, and the hash value is associated with the hash value.No. 2The keyTo the normal storage meansCharacterized by rememberingClaim 5The program execution device described in. 前記保護セキュリティ処理手段は、さらに、保護モードにおいて、前記保護記憶手段から前記鍵とともに前記ハッシュ値を読み出し、前記鍵とともに前記ハッシュ値を出力し、 前記通常セキュリティ処理手段は、さらに、通常モードにおいて、前記第2鍵としての前記鍵とともに前記ハッシュ値を受け取り、前記ハッシュ値に対応付けて前記第2鍵を前記通常記憶手段に記憶する ことを特徴とする請求項5に記載のプログラム実行装置。
- 7In the normal mode, the normal security processing means further receives an instruction for information security processing from another program, calculates a hash value of the other program, and obtains the calculated hash value.To the normal storage meansJudge whether it matches the stored hash value, and if it does not match,To the normal storage meansI remember the aboveNo. 2Characterized by deleting the keyClaim 6The program execution device described in. 前記通常セキュリティ処理手段は、さらに、通常モードにおいて、他のプログラムから情報セキュリティ処理の指示を受け、当該他のプログラムのハッシュ値を算出し、算出したハッシュ値が前記通常記憶手段に記憶しているハッシュ値と一致しているか否かを判断し、一致していなければ、前記通常記憶手段に記憶している前記第2鍵を削除する ことを特徴とする請求項6に記載のプログラム実行装置。
- 8The normal security processing means further, when the execution of the program is requested, in the normal mode,To the normal storage meansCorresponds to the programNo. 2Determine if you have the key and hold itIWhen it is determined that the program does not have a key generation instruction, the key generation instruction of the program is output and controlled to switch to the protection mode. Further, when the protection security processing means receives the key generation instruction in the protection mode, the key generation instruction is received.For the protective storage meansWhen determining whether or not the key corresponding to the program is retained and determining that the key is retained,From the protective storage meansIt is characterized in that the key is read, the read key is output, and control is performed so as to switch to the normal mode.Claim 4The program execution device described in. 前記通常セキュリティ処理手段は、さらに、前記プログラムの実行が要求されたとき、通常モードにおいて、前記通常記憶手段に当該プログラムに対応する第2鍵を保持しているか否かを判断し、保持していないと判断する場合に、当該プログラムの鍵の生成指示を出力し、保護モードに切り替えるよう制御し、 前記保護セキュリティ処理手段は、さらに、保護モードにおいて、前記鍵の生成指示を受けると、前記保護記憶手段に当該プログラムに対応する鍵を保持しているか否かを判断し、保持していると判断する場合に、前記保護記憶手段から前記鍵を読み出し、読み出した前記鍵を出力し、通常モードに切り替えるように制御する ことを特徴とする請求項4に記載のプログラム実行装置。
- 12It is provided with a protected storage means that can be accessed only in the protected mode and that securely stores the key in association with the program and a normal storage means that can be accessed in the normal mode.A control method used in a program execution device that operates by switching between normal mode and protection mode, in which a tampering detection step for detecting tampering of a program including an instruction for instructing information security processing using a key and a tampering detection step in normal mode When the tampering is not detected, the program operates according to the program, and when the instruction is detected in the program, an execution step of outputting an information security processing instruction is performed. In the normal mode, when the instruction is received, the mode is switched to the protection mode. With normal security processing steps to controlProtectIn protection modeFrom the protective storage meansA protective security processing step that reads the key, outputs the read key, and controls switching to the normal mode.Including, In the normal security processing step, in the normal mode,Using the output key as the second keyReceived, received saidThe second key is stored in the normal storage means, and the second key is stored.To execute the information security process usingIn the tampering detection step, a second detection of tampering with the program is further performed.In the normal security processing step, when the tampering is detected by the second detection, in the normal mode, the second key stored in the normal storage means is deleted and the mode is switched to the protection mode. Control andIn the protection security processing step, further, in the protection mode, the information security processing is executed by using the key stored in the protection storage means. A control method characterized by that. 保護モードの場合のみアクセス可能であり、前記プログラムに対応付けて鍵を安全に記憶している保護記憶手段及び通常モードの場合にアクセス可能な通常記憶手段を備え、通常モードと保護モードとを切り替えて動作するプログラム実行装置で用いられる制御方法であって、 鍵を用いる情報セキュリティ処理を指示する命令を含むプログラムの改竄を検出する改竄検出ステップと、 通常モードにおいて、前記改竄が検出されない場合に、前記プログラムに従って動作し、前記プログラムの中から前記命令を検出すると情報セキュリティ処理の指示を出力する実行ステップと、 通常モードにおいて、前記指示を受けると、保護モードに切り替えるよう制御する通常セキュリティ処理ステップと、保護モードにおいて、前記保護記憶手段から前記鍵を読み出し、読み出した鍵を出力し、通常モードに切り替えるよう制御する保護セキュリティ処理ステップとを含み、 前記通常セキュリティ処理ステップにおいて、通常モードにおいて、出力された前記鍵を第2鍵として受け取り、受け取った前記第2鍵を前記通常記憶手段に記憶し、前記第2鍵を用いて前記情報セキュリティ処理を実行し、前記改竄検出ステップにおいて、さらに、前記プログラムの改竄の第2の検出を行い、前記通常セキュリティ処理ステップにおいて、さらに、前記第2の検出により、前記改竄が検出された場合に、通常モードにおいて、前記通常記憶手段に記憶している前記第2鍵を削除し、保護モードに切り替えるよう制御し、前記保護セキュリティ処理ステップにおいて、さらに、保護モードにおいて、前記保護記憶手段に記憶している前記鍵を用いて、前記情報セキュリティ処理を実行する ことを特徴とする制御方法。
- 13It is provided with a protected storage means that can be accessed only in the protected mode and that securely stores the key in association with the program and a normal storage means that can be accessed in the normal mode.A control program used in a program execution device that operates by switching between normal mode and protection mode and recorded on a computer-readable recording medium, including instructions for instructing the computer to perform information security processing using a key. A tampering detection step that detects tampering with a program, and an execution step that operates according to the program when the tampering is not detected in the normal mode and outputs an instruction for information security processing when the instruction is detected from the program. In the normal mode, when the instruction is received, a normal security processing step that controls to switch to the protection mode andProtectIn protection modeFrom the protective storage meansThe key is read, the read key is output, and a protective security processing step that controls switching to the normal mode is executed. In the normal security processing step, in the normal mode,Using the output key as the second keyReceived, received saidThe second key is stored in the normal storage means, and the second key is stored.To execute the information security process usingIn the tampering detection step, a second detection of tampering with the program is further performed.In the normal security processing step, when the tampering is detected by the second detection, in the normal mode, the second key stored in the normal storage means is deleted and the mode is switched to the protection mode. Control andIn the protection security processing step, further, in the protection mode, the information security processing is executed by using the key stored in the protection storage means. Control program for. 保護モードの場合のみアクセス可能であり、前記プログラムに対応付けて鍵を安全に記憶している保護記憶手段及び通常モードの場合にアクセス可能な通常記憶手段を備え、通常モードと保護モードとを切り替えて動作するプログラム実行装置で用いられ、コンピュータ読み取り可能な記録媒体に記録されている制御プログラムであって、 コンピュータに、 鍵を用いる情報セキュリティ処理を指示する命令を含むプログラムの改竄を検出する改竄検出ステップと、 通常モードにおいて、前記改竄が検出されない場合に、前記プログラムに従って動作し、前記プログラムの中から前記命令を検出すると情報セキュリティ処理の指示を出力する実行ステップと、 通常モードにおいて、前記指示を受けると、保護モードに切り替えるよう制御する通常セキュリティ処理ステップと、保護モードにおいて、前記保護記憶手段から前記鍵を読み出し、読み出した鍵を出力し、通常モードに切り替えるよう制御する保護セキュリティ処理ステップとを実行させ、 前記通常セキュリティ処理ステップにおいて、通常モードにおいて、出力された前記鍵を第2鍵として受け取り、受け取った前記第2鍵を前記通常記憶手段に記憶し、前記第2鍵を用いて前記情報セキュリティ処理を実行し、前記改竄検出ステップにおいて、さらに、前記プログラムの改竄の第2の検出を行い、前記通常セキュリティ処理ステップにおいて、さらに、前記第2の検出により、前記改竄が検出された場合に、通常モードにおいて、前記通常記憶手段に記憶している前記第2鍵を削除し、保護モードに切り替えるよう制御し、前記保護セキュリティ処理ステップにおいて、さらに、保護モードにおいて、前記保護記憶手段に記憶している前記鍵を用いて、前記情報セキュリティ処理を実行する ための制御プログラム。
- 14An integrated circuit for executing a program that operates by switching between a normal mode and a protection mode, and a tampering detection means for detecting tampering of a program including an instruction for instructing information security processing using a key.A protective storage means that is accessible only in the protected mode and securely stores the key in association with the program.With normal storage means accessible in normal mode, In the normal mode, when the tampering is not detected, the program operates according to the program, and when the instruction is detected in the program, an execution means for outputting an instruction for information security processing, and in the normal mode, when the instruction is received, Normal security measures that control switching to protected mode, andProtectIn protection modeFrom the protective storage meansA protective security processing means for reading the key, outputting the read key, and controlling the switching to the normal mode is provided, and the normal security processing means is provided in the normal mode.Using the output key as the second keyReceived, received saidThe second key is stored in the normal storage means, and the second key is stored.Execute the information security process usingAndThe tampering detection means further detects tampering with the program second.Further, when the falsification is detected by the second detection, the normal security processing means deletes the second key stored in the normal storage means in the normal mode and switches to the protection mode. Control andFurther, in the protection mode, the protection security processing means executes the information security processing by using the key stored in the protection storage means. An integrated circuit characterized by that. 通常モードと保護モードとを切り替えて動作するプログラム実行のための集積回路であって、 鍵を用いる情報セキュリティ処理を指示する命令を含むプログラムの改竄を検出する改竄検出手段と、保護モードの場合のみアクセス可能であり、前記プログラムに対応付けて鍵を安全に記憶している保護記憶手段と、通常モードの場合にアクセス可能な通常記憶手段と、 通常モードにおいて、前記改竄が検出されない場合に、前記プログラムに従って動作し、前記プログラムの中から前記命令を検出すると情報セキュリティ処理の指示を出力する実行手段と、 通常モードにおいて、前記指示を受けると、保護モードに切り替えるよう制御する通常セキュリティ処理手段と、保護モードにおいて、前記保護記憶手段から前記鍵を読み出し、読み出した鍵を出力し、通常モードに切り替えるよう制御する保護セキュリティ処理手段とを備え、 前記通常セキュリティ処理手段は、通常モードにおいて、出力された前記鍵を第2鍵として受け取り、受け取った前記第2鍵を前記通常記憶手段に記憶し、前記第2鍵を用いて前記情報セキュリティ処理を実行し、前記改竄検出手段は、さらに、前記プログラムの改竄の第2の検出を行い、前記通常セキュリティ処理手段は、さらに、前記第2の検出により、前記改竄が検出された場合に、通常モードにおいて、前記通常記憶手段に記憶している前記第2鍵を削除し、保護モードに切り替えるよう制御し、前記保護セキュリティ処理手段は、さらに、保護モードにおいて、前記保護記憶手段に記憶している前記鍵を用いて、前記情報セキュリティ処理を実行する ことを特徴とする集積回路。
Independent claims8
249 paragraphs, as filed
The present invention switches between a secure software execution environment and a normal software execution environment to encrypt data, decrypt encrypted data, generate a digital signature, and verify a digital signature in a program execution device that executes a computer program. It is related to the technology to perform information security processing such as high speed and safety.
In recent years, the theft of data such as personal information stored in information processing devices such as personal computers (PCs) and mobile phones has become a problem. The above-mentioned data theft may be carried out by a malicious computer program. This computer program was illegally downloaded from an open network such as the Internet to an information processing device such as a PC or mobile phone. This computer program operates illegally in this information processing device against the intention of the user of the information processing device. For example, this computer program reads data stored in a storage device of a PC or a mobile phone, and sends the read data to an attacker or the like via a network. The attacker thus achieves the goal of stealing data. In the following, a malicious computer program is also referred to as a malicious computer program.
In order to prevent such data theft, Patent Document 1 and Patent Document 2 (Patent Document 1 (Japanese Gazette) and Patent Document 2 (US Gazette) disclose the same contents). The following technologies are disclosed for the purpose of providing an access control system that can suppress access even if an intruder from the network attempts to read or write an unauthorized file using any user authority. ing.
Multiple operating systems run simultaneously on the server information processing device. One of the OSs is a service OS, and the other is a security OS. The multiple OS control programs running on the server information processing device perform various controls for the service OS and the security OS to run on the server information processing device. In addition, the server program runs on the service OS, and the access control program runs on the security OS. In addition, the I / O manager and file I / O hook program run in the service OS. The inter-OS communication processing unit operates in multiple OS control programs.
When the server program requests file access, the request reaches the file I / O hook program via the I / O manager. The file I / O hook program requests the access control program to check the access authority related to the file access request via the inter-OS communication processing unit. The access control program collates the contents of the received request with the contents of the policy file, and transmits the result as a response to the file I / O hook program via the inter-OS communication processing unit. The file I / O hook program determines whether or not the access is possible based on the contents of the received response, and sets an error code if the access is not possible. If an error code is set, the I / O manager returns an error to the server program.
In this way, it is possible to prevent unauthorized data access by executing the determination of permission / non-permission of data on the security OS, which is a safe execution environment. Next, Patent Document 3 discloses the following technology for the purpose of solving the problem that unencrypted data remains in the cache in an encryption system that operates integrally with a computer system. ing.
A computer system having an operating system and a storage device (hard disk) has a function of automatically encrypting files stored in a predetermined folder. When the encryption processing function is switched ON / OFF, the cache data attached to the file to be encrypted held in the cache memory managed by the computer system is invalidated or rewritten.
In this way, unencrypted data does not remain in the cache, and unauthorized use of these data can be prevented.
<p><patcit num="1"><text>Japanese Patent Application Laid-Open No. 2008-204468</text></patcit><patcit num="2"><text>US 2001/0025311 A1 Gazette</text></patcit><patcit num="3"><text>Japanese Patent Application Laid-Open No. 2004-240699</text></patcit></p>
<p> In the technology disclosed in Patent Document 1 and Patent Document 2, there is a problem that communication processing between OSs is required between the service OS and the security OS each time data is accessed, and the overhead is large. is there. Further, in the technique disclosed in Patent Document 3, it is necessary to read the key into the cache again when the data dark decoding is performed again after the data dark decoding is completed.</p><p> In order to solve the above problems, the present invention provides a program execution device and a control method capable of suppressing overhead due to processing not directly related to information security processing while ensuring confidentiality in information security processing such as encryption and decryption. , Control programs and integrated circuits.</p>
<p> In order to solve the above-mentioned conventional problems, one embodiment of the present invention is a program execution device that operates by switching between a normal mode and a protection mode, and falsifies a program including an instruction for instructing information security processing using a key. Tampering detection means to detect<u style="single">Protected storage means that can be accessed only in the protected mode and securely stores the key in association with the program, and normal storage means that can be accessed in the normal mode.</u>In the normal mode, when the falsification is not detected, the program operates according to the program, and when the instruction is detected in the program, an execution means for outputting an instruction for information security processing, and in the normal mode, when the instruction is received, Normal security measures that control switching to protected mode, and<u style="single">Protect</u>In protection mode<u style="single">From the protective storage means</u>A protective security processing means for reading the key, outputting the read key, and controlling the switching to the normal mode is provided, and the normal security processing means is provided in the normal mode.<u style="single">Using the output key as the second key</u>Received, received said<u style="single">The second key is stored in the normal storage means, and the second key is stored.</u>Perform the information security process using<u style="single">Then, the tampering detecting means further detects the tampering of the program, and the normal security processing means further detects the tampering by the second detection in the normal mode. , The second key stored in the normal storage means is deleted and controlled to switch to the protected mode, and the protected security processing means further, in the protected mode, the key stored in the protected storage means. Is used to execute the information security process.</u>It is characterized by that.</p>
<p> According to this configuration, in the normal mode, the information security process is executed according to the instruction of the program confirmed not to be tampered with by using the key acquired from the protected mode, so that the information security process performed in the normal mode is confidential. Can be kept. In this way, when the key is acquired, the normal mode is further switched to the protected mode, but after the key is acquired, it is not necessary to switch to the protected mode again during the execution of the information security process, and the encryption is performed. It has the excellent effect of suppressing the overhead of processing that is not directly related to information security processing such as encryption and decryption.</p>
<figref num="1">The configuration of the information processing system 1 of the first embodiment is shown.</figref><figref num="2">The configuration of the information processing device 100 is shown.</figref><figref num="3">The software configuration of the information processing apparatus 100 is shown.</figref><figref num="4">An example of the data structure of the normal key table 128 is shown.</figref><figref num="5">It is a conceptual diagram explaining the procedure of key deletion by an information processing apparatus 100.</figref><figref num="6">It is a flowchart which shows the operation at the time of power-on of the information processing apparatus 100.</figref><figref num="7">It is a flowchart which shows a series of steps of use of data by an application program.</figref><figref num="8">It is a state transition diagram which shows the state transition at the time of data encryption.</figref><figref num="9">It is a sequence diagram which shows the procedure of registration of an application program.</figref><figref num="10">It is a sequence diagram which shows the operation when the key is acquired from the protection mode, and is encrypted by using the data dark decoding function part of a normal mode.</figref><figref num="11">It is a sequence diagram which shows the operation at the time of encryption using only the data dark decoding function part of a normal mode.</figref><figref num="12">It is a sequence diagram which shows the operation at the time of encryption using the protection data manipulation part of protection mode.</figref><figref num="13">It is a sequence diagram which shows the operation when the encryption request is made from the malicious application program.</figref><figref num="14">It is a figure which shows the state transition at the time of decryption of the encrypted data.</figref><figref num="15">It is a sequence diagram which shows the operation when the key is acquired from the protection mode, and the key is decoded by using the data dark decoding function part of a normal mode.</figref><figref num="16">It is a flowchart which shows the operation of the verification of an application program.</figref><figref num="17">It is a flowchart which shows the operation when the information processing apparatus 100 starts by a safe boot.</figref><figref num="18">It is a flowchart which shows the operation of the mode switching A which performs the transition from a normal mode to a protection mode.</figref><figref num="19">It is a flowchart which shows the operation of the hash value generation and verification A of an application program.</figref><figref num="20">It is a flowchart which shows the operation of the verification of a server information.</figref><figref num="21">It is a flowchart which shows the operation of a key generation and storage.</figref><figref num="22">It is a flowchart which shows the operation which verifies the data dark decoding function part.</figref><figref num="23">It is a flowchart which shows the operation of the mode switching B which performs the transition from a protection mode to a normal mode.</figref><figref num="24">It is a flowchart which shows the operation of the hash value generation and verification B of an application program.</figref><figref num="25">It is a flowchart which shows the operation of the verification of other application programs.</figref><figref num="26">It is a flowchart which shows the operation of the key confirmation A.</figref><figref num="27">It is a flowchart which shows the operation of the key confirmation B.</figref><figref num="28">It is a flowchart which shows the operation of the key storage.</figref><figref num="29">The software configuration of the information processing apparatus 100b of the second embodiment is shown.</figref><figref num="30">The software configuration of the information processing apparatus 100c according to the third embodiment is shown.</figref><figref num="31">It is a sequence diagram which shows the operation of registration of the application program of Embodiment 3. Continue to Figure 32.</figref><figref num="32">It is a sequence diagram which shows the operation of registration of the application program of Embodiment 3. Continued from Figure 31.</figref><figref num="33">It is a flowchart which shows the operation of the verification and the key table update of the application program of Embodiment 3.</figref><figref num="34">It is a flowchart which shows the operation of the key table update of Embodiment 3.</figref><figref num="35">The data structure of the ordinary key table 128d of the fourth embodiment is shown.</figref><figref num="36">It is a flowchart which shows the operation of the key confirmation A of Embodiment 4.</figref><figref num="37">The configuration of the information processing apparatus 100e according to the fifth embodiment is shown.</figref><figref num="38">The data structure of the ordinary key table 128e of the fifth embodiment is shown.</figref><figref num="39">It is a flowchart which shows the operation of the key confirmation A of Embodiment 5.</figref><figref num="40">The software configuration of the information processing apparatus 100f according to the sixth embodiment is shown.</figref><figref num="41">The data structure of the decrypted data storage position table 297 of the sixth embodiment is shown.</figref><figref num="42">It is a flowchart which shows the operation of the hash value generation and verification B of the application program of Embodiment 6.</figref><figref num="43">It is a sequence diagram which shows the operation of confirmation of another application program of Embodiment 6.</figref>
The program execution device that operates by switching between the normal mode and the protection mode, which is one embodiment of the present invention, includes a falsification detection means for detecting falsification of a program including an instruction for instructing information security processing using a key.<u style="single">Protected storage means that can be accessed only in the protected mode and securely stores the key in association with the program, and normal storage means that can be accessed in the normal mode.</u>In the normal mode, when the falsification is not detected, the program operates according to the program, and when the instruction is detected in the program, an execution means for outputting an instruction for information security processing, and in the normal mode, when the instruction is received, Normal security measures that control switching to protected mode, and<u style="single">Protect</u>In protection mode<u style="single">From the protective storage means</u>A protective security processing means for reading the key, outputting the read key, and controlling the switching to the normal mode is provided, and the normal security processing means is provided in the normal mode.<u style="single">Using the output key as the second key</u>Received, received said<u style="single">The second key is stored in the normal storage means, and the second key is stored.</u>Perform the information security process using<u style="single">Then, the tampering detecting means further detects the tampering of the program, and the normal security processing means further detects the tampering by the second detection in the normal mode. , The second key stored in the normal storage means is deleted and controlled to switch to the protected mode, and the protected security processing means further, in the protected mode, the key stored in the protected storage means. Is used to execute the information security process.</u>It is characterized by that.
here,<u style="single">Before</u>In addition, the usual security processing means is<u style="single">In the second detection,</u>If the tampering is not detected, in normal mode,<u style="single">To the normal storage means</u>I remember the above<u style="single">No. 2</u>The information security process may be executed using the key.
here,<u style="single">Before</u>The tampering detection means further detects tampering with another program operating in the normal mode, and the normal security processing means further detects tampering with the other program in the normal mode.<u style="single">To the normal storage means</u>I remember the above<u style="single">No. 2</u>The key is deleted and controlled to switch to the protected mode, and the protective security processing means further, in the protected mode,<u style="single">For the protective storage means</u>The information security process may be executed using the stored key.
Here, the normal security processing means further outputs a key generation instruction of the program in the normal mode and controls to switch to the protected mode when the execution of the program is requested, and the protected security processing means. Further, in the protection mode, when the key generation instruction is received, the key of the program is generated and associated with the program.<u style="single">For the protective storage means</u>You may remember.
Here, the protective security processing means further generates a hash value of the program in the protection mode, and associates the generated hash value with the generated key.<u style="single">For the protective storage means</u>You may remember. Here, the protective security processing means further, in the protection mode,<u style="single">From the protective storage means</u>The hash value is read together with the key, the hash value is output together with the key, and the normal security processing means further, in the normal mode,<u style="single">As the second key</u>The hash value is received together with the key, and the hash value is associated with the hash value.<u style="single">No. 2</u>The key<u style="single">To the normal storage means</u>You may remember.
Here, the normal security processing means further receives an instruction for information security processing from another program in the normal mode, calculates a hash value of the other program, and the calculated hash value is obtained.<u style="single">To the normal storage means</u>Judge whether it matches the stored hash value, and if it does not match,<u style="single">To the normal storage means</u>I remember the above<u style="single">No. 2</u>You may delete the key. Here, the normal security processing means further, when the execution of the program is requested, in the normal mode,<u style="single">To the normal storage means</u>Corresponds to the program<u style="single">No. 2</u>Determine if you have the key and hold it<u style="single">I</u>When it is determined that the program does not have a key generation instruction, the program is controlled to be switched to the protection mode, and when the protection security processing means further receives the key generation instruction in the protection mode, the key generation instruction is output.<u style="single">For the protective storage means</u>When determining whether or not the key corresponding to the program is retained and determining that the key is retained,<u style="single">From the protective storage means</u>You may control to read the key, output the read key, and switch to the normal mode.
here,<u style="single">The protective storage means</u>Furthermore, the maximum number of times the key has been used is safely stored in association with the key.<u style="single">The protective security processing means further</u>In the protection mode, the maximum number of times of use is output, and the normal security processing means further, in the normal mode,<u style="single">As the second key</u>Receive the maximum number of uses together with the key, and the maximum number of uses received<u style="single">To the normal storage means</u>It is memorized, it is determined whether or not the current number of uses exceeds the memorized maximum number of uses, and if it is determined that it is exceeded, a new generation instruction is output and the mode is switched to the protection mode. Controlled, the protective security processing means further generates a new key and a new maximum number of uses when it receives a new generation instruction in the protected mode, and generates a new key and a new maximum number of uses. Is output and controlled to switch to the normal mode, and the normal security processing means further receives a new key and a new maximum number of uses in the normal mode.<u style="single">To the normal storage means</u>I remember<u style="single">The second</u>Delete the key and the maximum number of uses, and associate the new key received with the new maximum number of uses.<u style="single">To the normal storage means</u>You may remember.
here,<u style="single">The protective storage means</u>Further, the last date and time when the key can be used is safely stored in association with the key.<u style="single">The protective security processing means further</u>, The last date and time is output in the protection mode, and the normal security processing means further, in the normal mode,<u style="single">As the second key</u>Received the last date and time together with the key, and received the last date and time<u style="single">To the normal storage means</u>It memorizes, determines whether the current date and time exceeds the memorized last date and time, and if it is determined that it exceeds, outputs a new generation instruction and controls to switch to the protection mode. Further, when the protection security processing means receives a new generation instruction in the protection mode, the protection security processing means generates a new key and a new last date and time, and outputs the generated new key and a new last date and time. , The normal security processing means further receives a new key and a new last date and time in the normal mode.<u style="single">To the normal storage means</u>I remember<u style="single">The second</u>Delete the key and the last date and time, and associate the new key received with the new last date and time.<u style="single">To the normal storage means</u>You may remember.
Here, the information security process may be any one of encryption, decryption, generation of a digital signature, verification of a digital signature, and generation of a keyed hash. It is also an embodiment of the present invention.<u style="single">It is provided with a protected storage means that can be accessed only in the protected mode and that securely stores the key in association with the program and a normal storage means that can be accessed in the normal mode.</u>The control method used in the program execution device that operates by switching between the normal mode and the protection mode is a tampering detection step for detecting tampering of a program including an instruction for instructing information security processing using a key, and the tampering in the normal mode. Is not detected, the program operates according to the program, and when the instruction is detected in the program, an execution step for outputting an instruction for information security processing is performed, and in the normal mode, when the instruction is received, the mode is controlled to switch to the protection mode. Normal security processing steps and<u style="single">Protect</u>In protection mode<u style="single">From the protective storage means</u>A protective security processing step that reads the key, outputs the read key, and controls switching to the normal mode.<u style="single">Including</u>In the normal security processing step, in the normal mode,<u style="single">Using the output key as the second key</u>Received, received said<u style="single">The second key is stored in the normal storage means, and the second key is stored.</u>To execute the information security process using<u style="single">In the tampering detection step, the second detection of tampering of the program is further performed, and in the normal security processing step, when the tampering is detected by the second detection, the tampering is detected in the normal mode. The second key stored in the normal storage means is deleted and controlled to switch to the protected mode. In the protected security processing step, and further in the protected mode, the key stored in the protected storage means is used. And execute the information security process</u>It is characterized by that.
It is also an embodiment of the present invention.<u style="single">It is provided with a protected storage means that can be accessed only in the protected mode and that securely stores the key in association with the program and a normal storage means that can be accessed in the normal mode.</u>A control program used in a program execution device that operates by switching between a normal mode and a protection mode and recorded on a computer-readable recording medium is a program that includes an instruction for instructing a computer to perform information security processing using a key. A tampering detection step that detects tampering, an execution step that operates according to the program when the tampering is not detected in the normal mode, and outputs an instruction for information security processing when the instruction is detected from the program, and usually In the mode, when the instruction is received, a normal security processing step that controls to switch to the protection mode and<u style="single">Protect</u>In protection mode<u style="single">From the protective storage means</u>In the normal security processing step, in the normal mode, the protection security processing step that reads the key, outputs the read key, and controls to switch to the normal mode is executed.<u style="single">Using the output key as the second key</u>Received, received said<u style="single">The second key is stored in the normal storage means, and the second key is stored.</u>To execute the information security process using<u style="single">In the tampering detection step, the second detection of tampering of the program is further performed, and in the normal security processing step, when the tampering is detected by the second detection, the tampering is detected in the normal mode. The second key stored in the normal storage means is deleted and controlled to switch to the protected mode. In the protected security processing step, and further in the protected mode, the key stored in the protected storage means is used. And execute the information security process</u>It is characterized by that.
Further, the integrated circuit for executing a program that operates by switching between the normal mode and the protection mode, which is one embodiment of the present invention, detects tampering of a program including an instruction for instructing information security processing using a key. Means and<u style="single">Protected storage means that can be accessed only in the protected mode and securely stores the key in association with the program, and normal storage means that can be accessed in the normal mode.</u>In the normal mode, when the falsification is not detected, the program operates according to the program, and when the instruction is detected in the program, an execution means for outputting an instruction for information security processing, and in the normal mode, when the instruction is received, Normal security measures that control switching to protected mode, and<u style="single">Protect</u>In protection mode<u style="single">From the protective storage means</u>A protective security processing means for reading the key, outputting the read key, and controlling the switching to the normal mode is provided, and the normal security processing means is provided in the normal mode .<u style="single">Using the output key as the second key</u>Received, received said<u style="single">The second key is stored in the normal storage means, and the second key is stored.</u>Execute the information security process using<u style="single">Then, the tampering detecting means further detects the tampering of the program, and the normal security processing means further detects the tampering by the second detection in the normal mode. , The second key stored in the normal storage means is deleted and controlled to switch to the protected mode, and the protected security processing means further, in the protected mode, the key stored in the protected storage means. Is used to execute the information security process.</u>It is characterized by that.
Hereinafter, embodiments of the present invention will be described with reference to the drawings. 1. Embodiment 1 The information processing system 1 as an embodiment of the present invention will be described. 1.1 Configuration of information processing system 1 As shown in FIG. 1, the information processing system 1 is composed of an information processing device 100 and a server device 10, and the information processing device 100 and the server device 10 are connected to each other via a network 20. The information processing device 100 transmits / receives data to / from the server device 10 via the network 20.
The information processing device 100 encrypts the data input by the user and stores it in the non-volatile storage unit 102 (described later) which is contained therein. Next, if necessary, the encrypted data is decrypted and uploaded to the server device 10 via the network 20. Further, the information processing device 100 downloads data or a program from the server device 10 via the network 20, encrypts the downloaded data or program, and stores the downloaded data or program in the non-volatile storage unit 102. The data encryption and decryption will be described later.
Here, the network 20 may be a public communication network such as the Internet or a communication path constructed ad hoc. The information processing device 100 is, for example, a personal computer, a mobile phone, a mobile information terminal, a game machine, a DVD playback device, a DVD recording device, a DVD playback / recording device, a BD playback device, a BD recording device, a BD playback / recording device, and a digital broadcast. A receiver, a digital broadcast reception / recording device, and a digital broadcast playback device. 1.2 Configuration of information processing device 100 The information processing device 100 constitutes a computer system, and as shown in FIG. 2, a system LSI 101, a non-volatile storage unit 102, a memory unit 103, a dedicated memory unit 104, a system bus 105, and an input / output unit (not shown). And other elements not shown. The system LSI 101, the non-volatile storage unit 102, the memory unit 103, and the dedicated memory unit 104 are connected to each other via the system bus 105.
The information processing device 100 is a program execution device that operates by switching between a normal mode and a protection mode. (1) System LSI101 The system LSI 101 is composed of a CPU 141, a peripheral circuit 142, a mode switching unit 143, an internal protection memory unit 144, an internal bus 145, and a dedicated bus 146. The CPU 141, the peripheral circuit 142, and the mode switching unit 143 have an internal bus 145. They are connected to each other via. Further, the mode switching unit 143 and the internal protection memory unit 144 are connected via a dedicated bus 146. The system LSI 101 has a normal mode and a protection mode, and operates by switching between the normal mode and the protection mode.
The CPU 141 controls the operation of the entire information processing apparatus 100 by operating according to an instruction code included in a program or the like stored in the memory unit 103 and the internal protection memory unit 144. The CPU 141 includes a general-purpose register 147 used by software, a control register 148 that controls memory management (Memory Managemenet Unit, MMU) and arithmetic acceleration functions, and a buffer area 149 used for cache and the like.
When the CPU 141 operates according to the instruction code included in the program stored in the memory unit 103 or the internal protection memory unit 144, the program and the CPU 141 form one hardware unit, and this hardware unit is formed. Can appear to be working. The peripheral circuit 142 has fixed functions such as DMA (Direct Memory Access) and is controlled by software. Further, the peripheral circuit 142 includes a control register 150 and a buffer area 151. The control register 150 and the buffer area 151 are used by software to control the peripheral circuits 142.
The mode switching unit 143 switches between the normal mode and the protection mode in the system LSI 101. Further, the mode switching unit 143 uses the dedicated memory unit 104 to exchange data between the normal mode and the protection mode. Details will be described later. Further, the mode switching unit 143 connects or disconnects the internal bus 145 and the internal protection memory unit 144. That is, in the case of the protection mode, the mode switching unit 143 connects the internal protection memory unit 144 and the internal bus 145. In the normal mode, the mode switching unit 143 separates the internal protection memory unit 144 from the internal bus 145.
The internal protection memory unit 144 stores a secure operating system 152, a dynamic tampering detection function unit 153, a secure boot unit 154, a protection data operation unit 155 (also referred to as a protection security processing unit), and protection switching data 156. The secure operating system 152, the dynamic tampering detection function unit 153, the secure boot unit 154, and the protected data operation unit 155 are computer programs, each of which is configured to include a plurality of instructions. The internal protection memory unit 144 is a memory that can be accessed from the CPU 141 only in the protection mode, and the inaccessible and inaccessible switching control is performed by the mode switching unit 143. (2) Non-volatile storage unit 102 The non-volatile storage unit 102 includes an area for storing the encrypted data 163 for the application program A and the encrypted data 164 for the application program B. (3) Memory unit 103 The memory unit 103 stores a general-purpose operating system 157, an application program A158, an application program B159, a data decryption function unit 160 (also called a normal security processing unit), an encrypted protection switching data 161 and a normal switching data 162. It has an area to do.
The general-purpose operating system 157, the application program A158, the application program B159, and the data decoding function unit 160 are computer programs each including a plurality of instructions. The protection switching data includes the data stored in the general-purpose register 147 of the CPU 141, the control register 148, and the buffer area 149 at the time immediately before switching from the protection mode to the normal mode, and the control register of the peripheral circuit 142. The data are stored in 150 and the buffer area 151, respectively.
The normal switching data 162 includes the data stored in the general-purpose register 147 of the CPU 141, the control register 148, and the buffer area 149, and the control register 150 of the peripheral circuit 142 and the control register 150 at the time immediately before switching from the normal mode to the protected mode. This is the data stored in the buffer area 151. (4) Dedicated memory unit 104 The dedicated memory unit 104 stores data for transfer from the normal mode to the protected mode or from the protected mode to the normal mode. 1.3 Software configuration of information processing device 100 Figure 3 shows the software configuration of the information processing device 100.
As shown in FIG. 3, the information processing apparatus 100 includes a software execution environment 120 in a normal mode and a safe software execution environment 121 in a protection mode. The information processing device 100 switches between the normal mode and the protection mode to execute each software. The details of the operation of switching between the normal mode and the protected mode will be described later. (1) Description of software components that operate in the normal mode execution environment 120 The normal mode execution environment 120 includes a general-purpose operating system 157, a data decryption function unit 160, an application program A158, and an application program B159. (General-purpose operating system 157) The general-purpose operating system 157 is an operating system that operates in the normal mode, and includes a load function unit 129 and a tamper detection unit 157x. The general-purpose operating system 157 uses the load function unit 129 to load and execute the application program on the memory unit 103. Also, the application program is deleted (unloaded) from the memory unit 103. The tampering detection unit 157x detects tampering. (Application program A158 and application program B159) The application program A158 and the application program B159 are software that provide users with functions such as a Web browsing function and an e-mail function, respectively. Application program A158 and application program B159 encrypt or decrypt data.
The application program A158 and the application program B159 each include an instruction for instructing information security processing using a key and other instructions. Here, the information security process is a process such as data encryption, decryption of encrypted data, generation of a digital signature, verification of a digital signature, and calculation of a keyed hash. Further, the instruction for instructing information security processing using a key is an instruction for instructing data encryption using a key or an instruction for instructing decryption of data encrypted using a key. In addition, an instruction for instructing the generation of a digital signature using a key, an instruction for instructing verification of a digital signature using a key, an instruction for instructing an operation of a hash with a key using a key, and the like also instruct information security processing. Included in the instruction.
The CPU 141 reads these instructions, decodes the read instructions, and operates according to the decoding result. When the CPU 141 detects an instruction for instructing information security processing in the application program, it outputs the instruction for information security processing to the data dark decoding function unit 160. In this way, the application program requests the information security processing request, here, the data crypt decoding request to the data crypt decoding function unit 160.
By operating the CPU 141 according to the instruction code included in the application program, the application program and the CPU 141 form one hardware unit and make it appear as if this hardware unit is operating. Can be done. This hardware unit is sometimes called an execution means. (Data dark decoding function unit 160) The data cryptic function unit 160 (usually also called a security processing unit) is a computer program that receives a data cryptic request from a higher-level application program and crypts data in response to the received data cryptic request, and is a plurality of computer programs. Includes instruction code. The data dark decoding function unit 160 includes a normal key table 128, a normal dark decoding unit 126, and a normal operation unit 127.
When the CPU 141 operates according to the instruction code included in the data dark decoding function unit 160, the data dark decoding function unit 160 and the CPU 141 form one hardware unit, and this hardware unit operates. You can make it look like you are doing it. This hardware unit is also usually called a security processing means. The normal operation unit 127 receives a data decryption request from a higher-level application program such as application program A or application program B, determines the presence / absence of a data decryption key and the presence / absence of another application program, and is a normal dark decoding unit. Data is dark-decrypted using 126 or the protected data manipulation unit 155. The normal operation unit 127 includes a tampering detection unit 127x. The tampering detection unit 127 detects tampering.
The normal dark decryption unit 126 includes a encryption unit and a decryption unit (not shown), and performs dark decryption of data using a key stored in the normal key table 128. The normal key table 128 is a table that temporarily stores a key used for encrypting or decrypting data used by a higher-level application program, and holds one or more key information as an example in FIG. It has an area for storage. Each key information is composed of a reference hash value of an application program and one or more server key information, and each server key information is composed of server information and a key. As described above, the normal key table 128 is a data table configured so that a unique key can be searched by using the reference hash value of the application program and the server information.
The application program is, for example, a browser program that provides a Web browsing function. This browser program receives the encrypted music and the encrypted movie from the music distribution server device and the movie distribution server device, respectively. In each server device, the key used for encryption is different, and the key used for decryption is also different. As described above, the application program is related to the music distribution server device and the movie distribution server device.
The reference hash value of the application program is a hash value generated by applying a hash to the entire application program. An example of a hash is SHA-1. The server key information corresponds to the server device related to the application program. The server information is identification information for identifying a server device related to the application program. The server information may be an IP (Internet Protocol) address, a URL (Universal Resource Location), or an identifier that can uniquely identify other servers.
The key is a key used for encrypting or decrypting data when receiving a service from a server device related to the application program. By having such a data structure, the management of associating the hash value of a predetermined application program with the corresponding dark decryption key becomes reliable and simple. Therefore, the management of the confidentiality of the dark decryption key can be made reliable and simple.
Further, by having such a data structure, when a plurality of dark decryption keys are generated for one application program according to a plurality of server devices, the server identification information, the hash value of the application program, and the corresponding darkness are generated. The management of associating the decryption key becomes reliable and simple. Therefore, it is possible to reliably and easily manage the confidentiality of a plurality of dark decryption keys for one application program. (2) Description of software components running in the protection mode execution environment 121 The protected mode execution environment 121 includes a secure operating system 152, a dynamic tamper detection function unit 153, a secure boot unit 154, and a protected data operation unit 155. (Secure Operating System 152) The secure operating system 152 is an operating system that operates in the protected mode, and is software that manages software that operates in the protected mode. (Dynamic tampering detection function unit 153) The dynamic tampering detection function unit 153 is software for verifying whether or not the load function unit 129 and the data dark decoding function unit 160 in the normal mode have been tampered with. Details will be described later. (Secure boot part 154) The secure boot unit 154 performs secure boot when the power of the information processing apparatus 100 is turned on. Details will be described later. The secure boot unit 154 includes a tamper detection unit 154x. The tampering detection unit 154x detects tampering. (Protected data manipulation unit 155) The protected data manipulation unit 155 (also called the protection security processing unit) is composed of a permission list 133, a protection encryption / decoding unit 134, a protection operation unit 135, and a protection key table 136. I do.
By operating the CPU 141 according to the instruction code included in the protected data operation unit 155, the protected data operation unit 155 and the CPU 141 form one hardware unit, and this hardware unit operates. You can make it look like you are. This hardware unit is sometimes called a protective security processing means. The permission list 133 is configured to include one or more server information that identifies the server device to which connection should be permitted. The server information is identification information for identifying a server device related to the application program. Here, the server information may be an IP address, a URL, or an identifier that can uniquely identify other servers.
The protection operation unit 135 includes a key generation unit (not shown) that generates a key used for encrypting or decrypting data, and a tampering detection unit 135x. In addition, the protected dark decoding unit 134 is instructed to encrypt the data. Further, the tampering detection unit 135x detects tampering and determines whether or not the application program that has requested the dark decoding of the data is an invalid application program. The method of determining whether or not the application program is malicious will be described later.
Further, in the case of an unauthorized application program, the protection operation unit 135 includes a key deletion unit (not shown) that deletes the key held by the data dark decoding function unit 160. Further, in the normal mode, when there is no malicious application program, the protection operation unit 135 reads the key stored in the protection key table 136, and reads the read key into the mode switching unit 143 and the dedicated memory. A key duplication unit (not shown) that outputs to the data cryptic function unit 160 via unit 104 and stores the key in the data cryptic function unit 160 is included. That is, the protection operation unit 135 copies the key stored in the protection key table 136 to the data dark decoding function unit 160. The details will be described later.
The protected dark decryption unit 134 includes an encryption unit that encrypts data and a decryption unit that decrypts the encrypted data by using the key stored in the protection key table 136. The protection key table 136 is a data table that stores a key used when encrypting data used by a higher-level application program or when decrypting encrypted data. The protection key table 136 has a data structure similar to that of the normal key table 128, and includes an area for storing one or more key information. Each key information is composed of a reference hash value of an application program and one or more server key information, and each server key information is composed of server information and a key. Since these reference hash values, server information, and keys are the same as those included in the normal key table 128, the description thereof will be omitted. 1.4 Operation procedure in the information processing device 100 (1) Procedure for deleting the key by the information processing device 100 The procedure for deleting the key used for data encryption and decryption in the information processing apparatus 100 will be described with reference to FIG.
When the application program A158 outputs a data encryption / decryption request to the data encryption / decryption function unit 160 (S11), the data encryption / decryption function unit 160 reads the entire request source application program from the memory unit 103. , The entire read application program is hashed, and for example, SHA-1 is applied to generate a hash value of the application program (S12). Next, all the key information is read from the normal key table 128, the reference hash value is extracted from each key information, and the generated hash value is compared with all the extracted reference hash values (S13). If there is no reference hash value that matches the generated hash value, that is, if all the reference hash values do not match the generated hash value, then all the key information normally stored in the key table 128 is displayed. Delete (S14). (2) Secure boot procedure by information processing device 100 The secure boot procedure until the power is turned on and the application program can be operated in the information processing apparatus 100 will be described with reference to the flowchart shown in FIG.
When the power of the information processing device 100 is turned on (S100), the information processing device 100 then activates the secure boot unit 154, which is software that operates in the protection mode (S101). Next, the tampering detection unit 154x of the secure boot unit 154 verifies the general-purpose operating system 157. Specifically, the tampering detection unit 154x of the secure boot unit 154 generates a hash value of the general-purpose operating system 157 stored in the memory unit 103, and the generated hash value and the secure boot unit 154 safely store in advance. By comparing with the reference hash value, it is verified whether the general-purpose operating system 157 has been tampered with (S102). In addition, it may be verified using the secure boot specified in the Mobile Phone WG (MPWG) of the Trusted Computing Group (TCG).
If it is determined that the general-purpose operating system 157 has not been tampered with (YES in S103), the tampering detection unit 154x of the secure boot unit 154 verifies the data decryption function unit 160 stored in the memory unit 103. Do. Specifically, the falsification detection unit 154x of the secure boot unit 154 generates a hash value of the data dark decoding function unit 160, and the generated hash value and the reference hash value safely stored in advance by the secure boot unit 154 are used. By comparing, it is verified whether or not the data encryption / decoding function unit 160 has been tampered with (S104). In addition, it may be verified using the secure boot specified in the Mobile Phone WG (MPWG) of the Trusted Computing Group (TCG). The verification of step S104 may be performed by the general-purpose operating system 157 that has been verified to have not been tampered with.
If it is determined that the data dark decoding function unit 160 has not been tampered with (YES in S106), the protected data operation unit 155 reads all the key information from the protected key table 136, and the mode switching unit 143 and the dedicated memory. The read key information is written to the normal key table 128 via unit 104. That is, the key information stored in the protected key table 136 is copied to the normal key table 128 (S107). Next, the information processing device 100 transitions to a state in which the application program can be executed (S108).
If it is determined that the general-purpose operating system 157 has been tampered with (NO in S103), or if it is determined that the data dark decoding function unit 160 has been tampered with (NO in S106), a warning message is notified to the user. Further, the information indicating that the information processing device has stopped abnormally is stored in the non-volatile storage unit 102, and then the start-up of the information processing device 100 is stopped (S105).
Of the key information shown in FIG. 4, the reference hash value of the application program and the server information are stored in advance in the normal key table 128 of the data dark decoding function unit 160, and the key information is copied in step S107. Instead, only the key may be copied in association with the reference hash. (3) A series of procedures for using data by the application program of the information processing device 100 A series of procedures for using data by the application program will be described using the flowchart shown in FIG. When the application program uses the data, the information processing apparatus 100 executes the following procedure.
The application program registration process is performed (S110), then the application program encrypts the data (S111) or decrypts the encrypted data (S112), and then the application program reads the data or Write (S113). The application program uses the data while dark-decoding the data by repeating steps S111 to S113 as necessary.
Next, when the user performs a process such as uninstalling the application program, the application program is deleted (S114), and then the use of the data ends. (4) State transition when encrypting data In the information processing apparatus 100, when the data is encrypted, as shown in FIG. 8, the transition is made between the four states 172, 173, 174 and 175.
The state 172 is a state in which it is detected that an invalid application program is stored in the memory unit 103 immediately after the power of the information processing device 100 is turned on. State 173 is a state in which the protected data manipulation unit 155 encrypts the data in the protected mode. State 174 is a state in which, when encrypting data, a key is acquired from the protection mode in the normal mode, and the acquired key is used for encryption by the data decryption function unit 160. The state 175 is a state in which the data encryption / decryption function unit 160 uses the key of the normal key table 128 in the normal mode to encrypt the data.
When the power of the information processing device 100 is turned on (171), it is determined whether or not an invalid application program is stored in the memory unit 103, and when the invalid application program is not detected (181), the state 173 is set. Transition. On the other hand, when a malicious application program is detected (182), the state transitions to state 172. In state 173, when a data encryption request is received from the application program (184), the state transitions to state 174.
In state 174, when a request for data encryption is further received from the application program (185), the state transitions to state 175. In state 175, when a data encryption request is received from the application program (186), the state transitions to state 175 again. On the other hand, when it is detected that an invalid application program is stored in the memory unit 103 (187), the state transitions to the state 173.
In the state 172, it is determined whether or not the invalid application program is stored in the memory unit 103, and if the invalid application program is not stored (183), the state transitions to the state 173. On the other hand, when an invalid application program is stored (188), the state transitions to the state 172 again. (5) Procedure for registering the application program in the information processing device 100 The procedure for registering the application program in the information processing apparatus 100 will be described with reference to the sequence diagram shown in FIG.
When the execution of the application program is instructed by the request from the user, the execution request of the application program is output to the general-purpose operating system 157 (S200). At this time, the general-purpose operating system 157 stores in the memory unit 103 an address indicating the position where the application program, which is the target of the execution request, is stored in the execution request address storage position in the memory unit 103. The execution request address storage position exists in a predetermined position in the memory unit 103. When each program reads the application program to be executed, it can refer to the execution request address storage position and know the storage position of the application program from the address stored there. When there are a plurality of application programs to be executed, there are a plurality of execution request address storage positions.
The general-purpose operating system 157 verifies the application program using the tamper detection unit 157x (S201), and if the application program is the correct application program, starts executing the application program (S202). The application program outputs an application registration request with server information as an argument to the data dark decoding function unit 160 (S203).
Upon receiving the application registration request (S203), the data dark decoding function unit 160 requests the mode switching unit 143 to switch the mode switching A so as to switch from the normal mode to the protected mode (S204), and the mode switching unit 143 requests the mode switching unit 143 to switch from the normal mode to the protected mode. Perform mode switching A to switch from normal mode to protected mode (S205). The mode switching A (S205) activates the dynamic tampering detection function unit 153, and the dynamic tampering detection function unit 153 generates a hash value of the application program and performs verification A (S206). Details of hash value generation and verification A of the application program will be described later.
Next, the dynamic tampering detection function unit 153 verifies the server information (S207). Details of server information verification will be described later. Next, the dynamic tampering detection function unit 153 makes a key generation request to the protected data operation unit 155 with the hash value and the server information as arguments (S208). The protected data manipulation unit 155 generates and stores the key, and stores the key in the internal protection memory unit 144 (S209). The details of key generation and storage will be described later.
Then, the protection data operation unit 155 notifies the dynamic tampering detection function unit 153 of the result indicating that the key storage is completed, that is, the registration of the application program is completed (S210). The dynamic tampering detection function unit 153 verifies whether or not the data dark decoding function unit 160 has been tampered with (S211). The operation corresponding to step S211 may be performed between step S205 and step S206.
Then, the dynamic tampering detection function unit 153 requests the mode switching unit 143 to switch the mode switching B from the protected mode to the normal mode (S212), and the mode switching unit 143 switches from the protected mode to the normal mode. Mode switching B is performed (S213). Here, the mode switching unit 143 writes the data to be transferred from the protection mode to the normal mode, here, the above result to the dedicated memory unit 104, switches to the normal mode, and then data from the dedicated memory unit 104. Is read, and the read data is output to the normal mode side. The details of mode switching B will be described later.
The mode switching B (S213) activates the data dark decoding function unit 160, the data dark decoding function unit 160 receives the result from the mode switching unit 143, and the data dark decoding function unit 160 sends the application program to the application program. Notify the result (S214). This completes the application program registration process. (6) Operation for state transition from state 173 to state 174 The operation of the state transition from the state 173 to the state 174 shown in FIG. 8, that is, the operation of the transition to the state 174 showing the encryption using the data dark decryption function unit 160 in the normal mode after acquiring the key from the protection mode. Will be described with reference to the sequence diagram shown in FIG.
In the case of the state 173 shown in FIG. 8, when the data encryption request is made by the application program and there is no invalid application program in the memory unit 103, the following operation is performed. After the sequence shown in FIG. 10 is completed, the state transitions to the state 174 shown in FIG. The application program makes a data encryption request to the data decryption function unit 160 with plaintext data and server information as arguments (S220).
The data dark decoding function unit 160 performs key confirmation A and confirms that the key is not normally stored in the key table 128 (S221). Next, the data dark decoding function unit 160 outputs the plaintext data and the server information to the mode switching unit 143, and requests the mode switching unit 143 to switch the mode switching A so as to switch from the normal mode to the protected mode (S222). .. The mode switching unit 143 performs mode switching A (S223). Here, the mode switching unit 143 writes the data to be transferred from the normal mode to the protected mode, here, the plain text data and the server information to the dedicated memory unit 104, and after switching to the protected mode, the dedicated memory unit 104. Data is read from, and the read data is output to the protection mode side. Details of mode switching A will be described later. Mode switching A (S223) activates the protected data manipulation unit 155. The protection data operation unit 155 receives plaintext data and server information from the mode switching unit 143.
The tampering detection unit 155x of the protected data operation unit 155 performs hash value generation and verification B of the application program, and verifies whether or not the application program that requested the data encryption is an invalid application program (S224). The details of hash value generation and verification B of the application program will be described later. Next, the tampering detection unit 155x of the protection data manipulation unit 155 verifies other application programs (S225). Here, it is assumed that other application programs have not been started. The details of verification of other application programs will be described later.
As a result, when the application program other than the predetermined application program corresponding to the hash value used when generating the dark decryption key finishes starting and there is no risk of using the dark decryption key, the risk of using the dark decryption key disappears. The decryption key is duplicated again in the normal key table 128 that is allowed access, as shown below. Therefore, after the risk of using the decryption key by other application programs other than the predetermined application program disappears, the complicated encryption process required for secretly managing the decryption key is greatly performed. While reducing the amount of data, it is possible to secure the secret of the public decryption key and restore the data to a state where the confidentiality can be guaranteed.
Next, the protected data manipulation unit 155 performs key confirmation B (S226). The details of key confirmation B will be described later. Then, the key is read from the protection key table 136 of the internal protection memory unit 144 (S227), and the key is transmitted to the dynamic tampering detection function unit 153 (S228). The key is transmitted via the shared memory between the protected data operation unit 155 existing in the internal protection memory unit 144 and the dynamic tampering detection function unit 153. It should be noted that other methods may be used for transmission. As one of the other methods, the general-purpose register 147 of the CPU 141 may be used.
The dynamic tampering detection function unit 153 verifies the data dark decoding function unit 160 and verifies whether or not it has been tampered with (S229). Then, the dynamic tampering detection function unit 153 specifies the key received from the protection data operation unit 155, and requests the mode switching unit 143 to switch the mode switching B from the protection mode to the normal mode (S230). ..
The mode switching unit 143 stores the key specified by the dynamic tampering detection function unit 153 in the dedicated memory unit 104, and performs mode switching B (S231). Details of mode switching B will be described later. The mode switching B (S231) activates the data dark decoding function unit 160. Further, the mode switching unit 143 reads the key from the dedicated memory unit 104 and transmits the read key to the data dark decoding function unit 160. The key is transmitted via the shared memory existing in the memory unit 103. It should be noted that other methods may be used for transmission. As another method, the general-purpose register 147 of the CPU 141 may be used.
The data dark decoding function unit 160 stores the transmitted key (S232). The details of key storage will be described later. Next, the data decryption function unit 160 encrypts the plaintext data using the key stored in the normal key table 128 of the memory unit 103 (S233). Here, as the encryption algorithm, an AES algorithm, a Triple DES algorithm, an RSA algorithm, or an elliptical curve encryption algorithm may be used.
Next, the data decryption function unit 160 assigns a data ID, which is a unique identifier, to the encrypted data and manages it. In addition, the data ID is notified to the higher-level application program (S234). Note that, without assigning a data ID to the encrypted data, all the encrypted data may be notified to the higher-level application program, and the higher-level application program may manage the encrypted data.
As described above, the dark decryption key is stored in the protection key table 136 in the protection mode in which access is restricted, and the access is made the first time when the protection data operation unit 155 performs the dark decoding process using the dark decoding. Performs the process of switching the mode in order to obtain the dark decryption key from the restricted protection key table 136. After that, the dark decryption key is duplicated in the normal key table 128 to which access is permitted, and the dark decryption key is used for dark decryption. Therefore, since the process of switching the mode is not required for each dark decryption process, the complicated encryption process required when the dark decryption key is managed secretly can be significantly reduced. (7) Operation of transition to state 175 The operation of the transition to the state 175 shown in FIG. 8 will be described with reference to the sequence diagram shown in FIG.
In the case of state 174 "obtaining the key from the protection mode and encrypting using the data decryption function unit in normal mode" shown in FIG. 8, and state 175 "encryption using only the data decryption function unit in normal mode". In the case of ", when a data encryption request is made and there is no malicious application, the operation shown in FIG. 11 is performed. After the operation shown in FIG. 11 is completed, the state transitions to the state 175 in FIG.
The application program makes a data encryption request to the data decryption function unit 160 with plaintext data and server information as arguments (S240). The tampering detection unit 127x of the data decryption function unit 160 performs hash value generation and verification B of the application program, and verifies whether or not the application program that requested the data encryption is an invalid application program (S241). ). Details of application hash value generation and verification B will be described later. Here, it is assumed that the application program that made the data encryption request is not an invalid application program.
Next, when the application program is not invalid, the tampering detection unit 127x of the data dark decoding function unit 160 verifies another application program (S242). Here, it is assumed that other application programs have not been started. Details of verification of other application programs will be described later. Next, the data dark decoding function unit 160 performs key confirmation A (S243). Here, it is assumed that the key exists. The details of key confirmation A will be described later. Next, the data decryption function unit 160 reads the key stored in the normal key table 128 of the memory, and encrypts the plaintext data using the read key (S244). Here, as the encryption algorithm, an AES algorithm, a Triple DES algorithm, an RSA algorithm, or an elliptical curve encryption algorithm may be used.
Next, the data decryption function unit 160 assigns a data ID, which is a unique identifier, to the encrypted data and manages the encrypted data. In addition, the data ID is notified to the higher-level application program (S245). Note that, without assigning a data ID to the encrypted data, all the encrypted data may be notified to the higher-level application program, and the higher-level application program may manage the encrypted data.
According to this, the dark decryption key is stored in the protection key table 136 in the protection mode in which access is restricted, and the access is restricted at the first time when the protection data operation unit 155 performs the dark decoding process using the dark decoding. The mode is switched to obtain the public-key decryption key from the protected key table 136, but after that, the public-key cryptographic key is duplicated in the normal key table 128 where access is permitted, and the duplicated public-key decryption key is used. Use for dark decoding. Therefore, since the process of switching the mode is not required for each dark decryption process, the complicated encryption process required when the dark decryption key is managed secretly can be significantly reduced. (8) Operation of transition to state 173 The operation of the transition to the state 173 encryption using the protected data manipulation unit in the protected mode shown in FIG. 8 will be described with reference to the sequence diagram shown in FIG.
In the case of state 175 encryption using only the data encryption / decryption function unit in normal mode in FIG. 8, when a data encryption request is made and an unauthorized application exists, the operation shown in FIG. 12 is performed. .. After the operation shown in FIG. 12 is completed, the state transitions to the state 173 in FIG. 8 again. The application program makes a data encryption request to the data decryption function unit 160 with plaintext data and server information as arguments (S250).
Next, the tampering detection unit 127x of the data decryption function unit 160 performs hash value generation and verification B of the application program, and verifies whether or not the application program that requested the data encryption is an invalid application program. (S251). Here, it is assumed that the application program is not a malicious program. The details of hash value generation and verification B of the application program will be described later.
Next, the tampering detection unit 127x of the data dark decoding function unit 160 verifies other application programs (S252). Here, it is assumed that the existence of another malicious application program is detected. The details of verification of other application programs will be described later. In that case, the data dark decoding function unit 160 deletes all the keys stored in the normal key table 128. When deleting, the key stored in the normal key table 128 may be overwritten with a specific value such as "0", or a random number may be generated and the random number may be overwritten.
Then, the data dark decoding function unit 160 performs key confirmation A (S253). Here, it is assumed that it is confirmed that the key does not exist in the memory unit 103. The details of key confirmation A will be described later. Next, a mode switching request is made to the mode switching unit 143 (S254). The mode switching unit 143 performs mode switching A (S255). The details of mode switching A will be described later.
Mode switching A (S255) activates the protected data manipulation unit 155. The tampering detection unit 155x of the protected data operation unit 155 performs hash value generation and verification B of the application program between steps S255 and S257, and the application program that made the data encryption request is an invalid application program. Verify whether or not (S256). Here, it is assumed that the application program that made the data encryption request is not an invalid application program.
Next, the protected data manipulation unit 155 performs key confirmation B (S257). Here, it is assumed that the key exists. The details of key confirmation B will be described later. Next, the protected data manipulation unit 155 reads the key from the internal protected memory unit 144 and encrypts the data using the read key (S258). Here, as the encryption algorithm, an AES algorithm, a Triple DES algorithm, an RSA algorithm, or an elliptical curve encryption algorithm may be used.
Next, the protected data operation unit 155 notifies the dynamic tampering detection function unit 153 of the encrypted data (S259). The dynamic tampering detection function unit 153 verifies the data dark decoding function unit 160 and verifies whether or not it has been tampered with (S260). Next, the dynamic tampering detection function unit 153 notifies the mode switching unit 143 of the encrypted data, and requests mode switching B to switch from the protected mode to the normal mode (S261).
The mode switching unit 143 stores the received encrypted data in the dedicated memory unit 104 and performs mode switching B (S262). Details of mode switching B will be described later. The mode switching B (S262) activates the data dark decoding function unit 160. In this case, the mode switching unit 143 reads the encrypted data from the dedicated memory unit 104 and notifies the data dark / decryption function unit 160 of the encrypted data.
The data decryption function unit 160 assigns a data ID, which is a unique identifier, to the notified encrypted data and manages it. In addition, the data ID is notified to the higher-level application program (S263). Note that, without assigning a data ID to the encrypted data, all the encrypted data may be notified to the higher-level application program, and the higher-level application program may manage the encrypted data.
As a result, after the dark decryption key duplicated in the normal key table 128 is erased from the normal key table 128, the data dark decoding function unit 160 does not perform the dark decoding process in the normal mode state, but in the normal mode. Switch to the protection mode from, and let the protection data operation unit 155, which can access the protection key table 136 in which the dark decryption key is stored, perform the dark decryption process. Therefore, after the dark decryption key duplicated in the normal key table 128 is erased from the normal key table 128, the mode switching process is performed, but the secret of the dark decryption key can be secured, and as a result, the confidentiality of the data is maintained. Can be guaranteed. (9) Operation when an encryption request is made from an unauthorized application program The operation when an encryption request is made from an unauthorized application program will be described with reference to the sequence diagram shown in FIG.
When an encryption request is made from an unauthorized application program, the state of the information processing device 100 transitions to the state 173 encryption using the protected data manipulation unit in the protected mode in FIG. The application program makes a data encryption request to the data decryption function unit 160 with plaintext data and server information as arguments (S270).
The tampering detection unit 127x of the data decryption function unit 160 performs hash value generation and verification B of the application program, and verifies whether or not the application program that requested the data encryption is an invalid application program (S271). .. Here, it is assumed that the application program is determined to be invalid. If it is determined that the application program is malicious, the data decryption function unit 160 deletes all the keys stored in the normal key table 128 (S272). As a method of deleting the key, a specific value may be overwritten on the key normally stored in the key table 128, or a random number may be generated and the random number may be overwritten. The details of hash value generation and verification B of the application program will be described later.
Next, the data decryption function unit 160 notifies the application program that the encryption process has failed (S273). As a result, application programs other than the application program corresponding to the hash value used when generating the public decryption key (described later with reference to FIG. 21) are stored in the normal key table 128 whose access is not restricted. When there is a risk of using a public-key cryptographic key, the public-key cryptographic key normally stored in the key table 128 is erased, so that the private public-key cryptographic key can be kept secret, and as a result, the confidentiality of data is guaranteed. it can.
Therefore, it is possible to secure the secret of the dark decryption key and guarantee the confidentiality of the data while greatly reducing the complicated encryption processing required when the secret decryption key is managed secretly. (10) State transition of decryption of encrypted data In the information processing apparatus 100, when decrypting the encrypted data, as shown in FIG. 14, the information processing apparatus 100 transitions between the four states 192, 193, 194, and 195.
The state 192 is a state in which it is detected that an invalid application program is stored in the memory unit 103 immediately after the power of the information processing device 100 is turned on. State 193 is a state in which the protected data manipulation unit 155 performs decryption in the protected mode when decrypting the encrypted data. The state 194 is a state in which, when decrypting the encrypted data, the key is acquired from the protection mode in the normal mode, and the data dark decoding function unit 160 decrypts the key using the acquired key. The state 195 is a state in which the data dark / decryption function unit 160 uses the key of the normal key table 128 in the normal mode when decrypting the encrypted data.
When the power of the information processing device 100 is turned on (191), it is determined whether or not an invalid application program is stored in the memory unit 103, and when the invalid application program is not detected (201), the state 193 is set. Transition. On the other hand, when a malicious application program is detected (202), the state transitions to state 192. In state 193, when a request for decryption of encrypted data is received from the application program (204), the state transitions to state 194.
In the state 194, when a request for decryption of the encrypted data is further received from the application program (205), the state transitions to the state 195. In the state 195, when the request for decryption of the encrypted data is received from the application program (206), the state transitions to the state 195 again. On the other hand, when it is detected that an invalid application program is stored in the memory unit 103 (207), the state transitions to the state 193.
In the state 192, it is determined whether or not the invalid application program is stored in the memory unit 103, and if the invalid application program is not stored (203), the state transitions to the state 193. On the other hand, when an invalid application program is stored (208), the state transitions to the state 192 again. The state transition of data encryption shown in FIG. 8 and the state transition of decryption of encrypted data shown in FIG. 14 differ only in that the data is encrypted or the encrypted data is decrypted. Therefore, in the following description of decryption of encrypted data, only the typical "decryption using the data dark decryption function unit 160 in the normal mode after acquiring the key from the protection mode" is targeted. (11) Operation of information processing device 100 when transitioning to state 194 The sequence diagram shown in FIG. 15 is used for the operation of the information processing apparatus 100 when transitioning to the state 194 obtaining the key from the protection mode and decoding using the data dark decoding function unit 160 in the normal mode shown in FIG. I will explain.
In the case of the state 193 "decryption using the protected data manipulation unit in the protected mode" shown in FIG. 14, when the decryption request for the encrypted data is made and there is no unauthorized application, the information processing device 100 is shown in FIG. It works as shown in 15. After the operation is completed as shown in FIG. 15, the state transitions to the state 194 obtaining the key from the protection mode and decoding using the data dark decoding function unit 160 in the normal mode shown in FIG.
The application program makes a data decryption request to the data decryption function unit 160 with the data ID indicating the encrypted data and the server information as arguments (S280). The data dark decoding function unit 160 performs key confirmation A (S281). Here, it is assumed that the key is not normally stored in the key table 128. Next, the data dark decoding function unit 160 requests the mode switching unit 143 to switch the mode switching A so as to switch from the normal mode to the protected mode (S282). The mode switching unit 143 performs mode switching A (S283). The details of mode switching A will be described later. Mode switching A (S283) activates the protected data manipulation unit 155.
The tampering detection unit 155x of the protected data operation unit 155 performs hash value generation and verification B of the application program, and verifies whether or not the application program that made the data decryption request is an invalid application program (S284). Here, it is assumed that the application program is not a malicious program. The details of hash value generation and verification B of the application program will be described later.
Next, the tampering detection unit 155x of the protection data manipulation unit 155 verifies other application programs (S285). Here, it is assumed that other application programs have not been started. The details of verification of other application programs will be described later. Next, the protected data manipulation unit 155 performs key confirmation B (S286). Here, it is assumed that the key exists. The details of key confirmation B will be described later. Further, the protected data manipulation unit 155 reads the key from the protection key table 136 of the internal protection memory unit 144 (S287), and transmits the read key to the dynamic tampering detection function unit 153 (S288). The key is transmitted via the shared memory between the protected data operation unit 155 existing in the internal protection memory unit 144 and the dynamic tampering detection function unit 153. It should be noted that other methods may be used for transmission. As another method, the general-purpose register 147 of the CPU 141 may be used.
The dynamic tampering detection function unit 153 verifies the data dark decoding function unit 160 and verifies whether or not it has been tampered with (S289). Here, it is assumed that the data dark decoding function unit 160 has not been tampered with. Next, the dynamic tampering detection function unit 153 requests the mode switching unit 143 to switch the mode switching B from the protected mode to the normal mode by designating the key (S290).
The mode switching unit 143 stores the key specified by the dynamic tampering detection function unit 153 in the dedicated memory unit 104, and performs mode switching B (S291). The details of mode switching B will be described later. The mode switching B (S291) activates the data dark decoding function unit 160. Further, the mode switching unit 143 reads the key from the dedicated memory unit 104 and transmits the read key to the data dark decoding function unit 160. The key is transmitted via the shared memory existing in the memory. It should be noted that other methods may be used for transmission. As another method, the general-purpose register 147 of the CPU 141 may be used.
The data decryption function unit 160 stores the transmitted key in the normal key table 128 (S292). The details of key storage will be described later. Next, the data dark decryption function unit 160 reads the key stored in the normal key table 128 of the memory unit 103, and decrypts the encrypted data using the read key (S293). Here, as the decoding algorithm, an AES algorithm, a Triple DES algorithm, an RSA algorithm, or an elliptic curve cryptographic algorithm may be used.
Next, the data dark decoding function unit 160 assigns a data ID, which is a unique identifier, to the generated plaintext data and manages it. Furthermore, the data ID is notified to the higher-level application program (S294). When the data ID is not assigned to the plaintext data, the data dark decoding function unit 160 passes the plaintext data as an argument to the application program instead of the data ID. (12) Application program verification operation The operation of verifying the application program by the information processing device 100 will be described with reference to the flowchart shown in FIG.
The operation of the application program verification described here is the details of the application program verification shown in step S201 of FIG. The tampering detection unit 157x of the general-purpose operating system 157 reads the application program from the memory unit 103, and generates a hash value for the read application program by using a one-way function such as SHA-1 as an example ( S401).
Next, the tampering detection unit 157x of the general-purpose operating system 157 determines whether or not the generated hash value matches any of the hash values held by the normal key table 128 (S402). If they match (YES in S402), the application program verification ends normally. If they do not match (NO in S402), the application program verification ends abnormally.
In case of abend, general-purpose operating system 157 does not execute the application program, that is, prohibits execution. In addition, information indicating that the application program is malicious may be stored in the non-volatile storage unit 102 as a log. Further, when the power of the information processing device 100 is turned off and then turned on, the information processing device 100 may be started in the safe mode by using the log of information indicating that the application program is malicious. .. Note that booting in safe mode will be described later as safe boot.
In addition, a one-way function other than SHA-1 may be used in the generation of the hash value. For example, MD5, SHA-256, AES, DES may be used. (13) Safe boot operation The operation of safe boot will be described with reference to the flowchart shown in FIG. When the information processing device 100 is turned on (S680), the secure boot unit 154, which is the software in the protection mode, is then started (S681).
Next, the secure boot unit 154 determines whether or not the information indicating that the application program stored in the memory unit 103 is an invalid application program is stored in the non-volatile storage unit 102 as a log (S682). ). If there is information in the log indicating that the application program stored in the memory unit 103 is an invalid application program (YES in S682), the mode shifts to safe mode (S683). In the safe mode, the secure boot unit 154 does not copy the dark decryption key stored in the protected key table 136 to the normal key table 128 in the normal mode in the subsequent dark decryption process for the protected data manipulation unit 155. The protected data manipulation unit 155 is set to perform the dark decoding process. Next, control is transferred to step S684.
If there is no log that indicates the existence of a malicious application program (NO in S682), the tamper detection unit 154x of the secure boot unit 154 verifies the general-purpose operating system 157 (S684). Specifically, the tampering detection unit 154x of the secure boot unit 154 generates a hash value of the general-purpose operating system 157, compares the generated hash value with the reference hash value safely stored in advance, and performs the general-purpose operating system. Verify if 157 has been tampered with. It may be verified by using the secure boot specified by the Mobile Phone WG (MPWG) of the Trusted Computing Group (TCG).
If it is determined that the general-purpose operating system 157 has not been tampered with (YES in S685), the tampering detection unit 154x of the secure boot unit 154 verifies the data dark decoding function unit 160. Specifically, the falsification detection unit 154x of the secure boot unit 154 generates a hash value of the data dark decoding function unit 160, compares the generated hash value with the reference hash value safely stored in advance, and data. It is verified whether or not the dark decoding function unit 160 has been tampered with. It may be verified by using the secure boot specified by the Mobile Phone WG (MPWG) of the Trusted Computing Group (TCG).
If it is determined that the data dark decoding function unit 160 has not been tampered with (YES in S687), it is determined whether or not it is in safe mode (S688), and if it is not in safe mode (NO in S688), the protected data manipulation unit 155 copies the hash value stored in the safe key table 136 to the normal key table 128 of the data decryption function unit 160 (S689), and then transitions to a state in which the application program can be executed (S691). ..
If it is in safe mode (YES in S688), then the application program transitions to an executable state (S691). Information processing when it is determined that the general-purpose operating system 157 has been tampered with (NO in S685), or when it is determined that the data dark decoding function unit 160 has been tampered with (NO in S687). Stop starting device 100. In addition, the user may be notified of a warning message (S690).
The verification of step S686 may be performed by the general-purpose operating system 157 that has been verified to have not been tampered with. Further, instead of copying the hash value in step S689, the normal key table 128 of the data dark decoding function unit 160 may store the hash value in advance. (14) Operation of mode switching A The operation of mode switching A for transitioning from the normal mode to the protection mode will be described with reference to the flowchart shown in FIG. The operation described here is the details of step S205 shown in FIG. 9, step S223 shown in FIG. 10, step S255 shown in FIG. 12, and step S283 shown in FIG.
The mode switching unit 143 includes data stored in the general-purpose register 147, the control register 148, and the buffer area 149 of the CPU 141 of the system LSI 101, and data stored in the control register 150 and the buffer area 151 of the peripheral circuit 142. Is stored in the memory unit 103 as normal switching data 162 (S411). Next, the mode switching unit 143 resets the CPU 141 and the peripheral circuit 142 of the system LSI 101, and sets the internal protection memory unit 144 to be accessible (S412).
Next, the data stored in the general-purpose register 147, the control register 148, and the buffer area 149 of the CPU 141 of the system LSI 101 used in the protection mode, and the data stored in the control register 150 and the buffer area 151 of the peripheral circuit 142. It is determined whether or not each data is encrypted and stored in the memory unit 103 (S413). If it is determined that the data is stored (YES in S413), the mode switching unit 143 decrypts the encrypted protection switching data 161 stored in the memory unit 103 (S414). Here, the AES algorithm, the Triple DES algorithm, the RSA algorithm, and the elliptic curve cryptographic algorithm may be used as the decoding algorithm used in the decoding of the protection switching data 161. Further, when decoding the protection switching data 161, the key stored in the internal protection memory unit 144 may be used as the decoding key, or the key unique to the system LSI 101 may be used.
Next, the mode switching unit 143 sets the protection switching data generated by decoding in the general-purpose register 147, the control register 148, and the buffer area 149 of the CPU 141 of the system LSI 101, and the control register 150 and the buffer area 151 of the peripheral circuit 142. (S415). In this way, mode switching A ends. If it is determined that the encrypted protection switching data is not stored (NO in S413), then mode switching A ends. (15) Application program hash value generation and verification A operation The operation of hash value generation and verification A of the application program will be described with reference to the flowchart shown in FIG. The operation of hash value generation and verification A described here is the details of step S206 in FIG.
The dynamic tampering detection function unit 153 generates a hash value for the execution image of the application program expanded on the memory unit 103 by using a one-way function such as SHA-1 (S421). Next, the dynamic tampering detection function unit 153 determines whether or not a value matching the generated hash value is included in the hash value held by the protection key table 136 (S422).
If it is determined to be included (YES in S422), the hash value generation and verification A of the application ends normally. If it is determined that it is not included (NO in S422), the hash value generation and verification A of the application will end abnormally. In case of abend, the secure operating system 152 prohibits the execution of application programs. Further, information indicating that the application program is malicious may be stored in the non-volatile storage unit 102 as a log.
A one-way function other than SHA-1 may be used in the generation of the hash value. For example, MD5, SHA-256, AES, DES may be used. (16) Operation of server information verification The operation of verifying the server information will be described with reference to the flowchart shown in FIG. The operation of verifying the server information described here is the details of step S207 in FIG.
The dynamic tampering detection function unit 153 determines whether or not the specified server information is included in the permission list 133 (S431). If the specified server information is included in authorization list 133 (YES in S431), the verification of the server information is successful and the server information is justified. If the server information is not included in the authorization list 133 (NO in S431), the verification of the server information ends abnormally and the server information is found to be invalid. Upon abnormal termination, the secure operating system 152 prohibits the execution of application programs. Further, information indicating that the application program is malicious may be stored in the non-volatile storage unit 102 as a log.
In addition, instead of the permission list 133, the protection data manipulation unit 155 may store the non-permission list. The disallowed list is configured to include one or more server information that identifies the server device that is not permitted. The disallowed list does not have to include server information that identifies the server device that is not permitted. In this case, the dynamic tampering detection function unit 153 determines whether or not the specified server information is included in the disallowed list, and if it is not included, the verification of the server information ends normally and is included. If so, the verification of the server information may be terminated abnormally.
Further, the server information may be verified by using the permission list 133 and the non-permission list. The permitted list and the disallowed list may have an electronic signature for detecting falsification. The verification of the electronic signature is performed in the protection mode, and the verification key may be the key of the terminal manufacturer. (17) Key generation and storage operations The operation of key generation and storage will be described with reference to the flowchart shown in FIG. The key generation and storage operations described here are the details of step S209 in FIG.
The protected data manipulation unit 155 generates a dark decryption key based on the hash value of the application program, the server information, and the terminal-specific information (S441). Specifically, the dark decryption key is generated by the following formula. Dark decryption key = Hash (hash value + server information + terminal-specific information) Here, A = Hash (B) indicates that B is hashed to obtain A, and the operator "+" indicates a join. That is, the hash value, the server information, and the terminal-specific information are combined in this order, and the combined result is hashed to obtain a dark decryption key. Here, the hash is SHA-1 as an example.
Further, the terminal-specific information is identification information that uniquely identifies the information processing device 100, and is stored in advance in the protected data operation unit 155. Next, the protected data manipulation unit 155 stores the generated dark decryption key in the key information corresponding to the hash value and the server information in the protected key table 136 (S442). This completes the key generation and storage process.
In the key generation in step S441, the key may be generated without using the terminal-specific information. Specifically, the dark decryption key is generated by the following formula. Dark decryption key = Hash (hash value + server information) As a result, since the dark decryption key does not depend on the terminal-specific information, even if the encrypted data is moved to another information processing device, the dark decryption key that does not depend on the terminal-specific information can be generated in this other information processing device. , The encrypted data can be decrypted by using the generated dark decryption key.
The dark decryption key generated in the key generation in step S411 may be stored in the non-volatile storage unit accessible only in the protection mode (not shown). As a result, the key can be held even if the power of the information processing device is turned off. Further, in the key generation in step S411, the dark decryption key may be generated using only the hash value of the application program. As a result, the dark decryption key can be unique to the application program.
Specifically, the dark decryption key is generated by the following formula. Dark decryption key = Hash (hash value) Further, in the key generation in step S411, the dark decryption key may be generated using only the server information. As a result, the dark decryption key can be made unique to the server. Specifically, the dark decryption key is generated by the following formula.
Dark decryption key = Hash (server information) Further, in the key generation in step S411, the dark decryption key may be generated using only the terminal-specific information. As a result, the dark decryption key can be unique to the terminal. Specifically, the dark decryption key is generated by the following formula. Dark decryption key = Hash (terminal-specific information) Further, in the key generation in step S411, a random number may be generated using a timer (not shown), and a dark decryption key may be generated using the generated random number, the hash value of the application, the server information, and the terminal-specific information. Good. As a result, random numbers are added to the dark decryption key, which makes it difficult to guess the value of the key.
Specifically, the dark decryption key is generated by the following formula. Dark decryption key = Hash (random number + hash value + server information + terminal-specific information) According to this, when one application program transmits data to a plurality of server devices, a plurality of encryption keys can be generated for one application program according to a plurality of servers. (18) Operation to verify the data dark decoding function unit 160 The operation of verifying the data dark decoding function unit 160 will be described with reference to the flowchart shown in FIG. The operation for verifying the data dark decoding function unit 160 described here is the details of step S211 in FIG. 9, step S229 in FIG. 10, step S260 in FIG. 12, and step S289 in FIG.
The dynamic tampering detection function unit 153 uses a one-way function such as SHA-1 for the execution image of the data dark decoding function unit 160 expanded in the memory unit 103, and uses the data dark decoding function unit 160. Generate a hash value (S451). The dynamic tampering detection function unit 153 determines whether or not the generated hash value matches the reference hash value of the normal key table 128 of the data dark decoding function unit 160 stored in advance (S452).
If it is determined that they match (YES in S452), the verification of the data dark decoding function unit 160 is completed normally, and the data dark decoding function unit 160 is recognized as valid. On the other hand, if it is determined that they do not match (NO in S452), the verification of the data dark decoding function unit 160 ends abnormally, and the data dark decoding function unit 160 is recognized as invalid. In the case of abnormal termination, the information processing apparatus 100 stops operating. Alternatively, the secure operating system 152 stops the decryption of the data. Further, the information indicating that the data dark decoding function unit 160 has been tampered with may be stored in the non-volatile storage device as a log. Further, if the normal key table 128 of the data decryption function unit 160 holds the key, this key is deleted.
A one-way function other than SHA-1 may be used in the generation of the hash value. For example, MD5, SHA-256, AES, DES may be used. (19) Operation of mode switching B The operation of the mode switching B for transitioning from the protection mode to the normal mode will be described with reference to the flowchart shown in FIG. The operation of the mode switching B described here is the details of step S213 in FIG. 9, step S231 in FIG. 10, step S262 in FIG. 12, and step S291 in FIG.
The mode switching unit 143 includes data stored in the general-purpose register 147, the control register 148, and the buffer area 149 of the CPU 141 of the system LSI 101, and data stored in the control register 150 and the buffer area 151 of the peripheral circuit 142. It is determined whether or not there is enough free space in the internal protection memory unit 144 to store the data (S461).
If it is determined that there is not enough free space (NO in S461), the mode switching unit 143 will use the data stored in the general-purpose register 147, control register 148, and buffer area 149 of the CPU 141 of the system LSI 101. , The data stored in the control register 150 of the peripheral circuit 142 and the buffer area 151 is encrypted and stored in the memory unit 103 as the encrypted protection switching data 161 (S462).
Next, the mode switching unit 143 resets the components of the system LSI 101 and sets the internal protection memory unit 144 to be inaccessible (S464). Next, the mode switching unit 143 sets the contents of the normal switching data 162 stored in the memory unit 103 to the general-purpose register 147 of the system LSI 101, the control register 148, the buffer area 149, and the control register 150 of the peripheral circuit 142. Set to buffer area 151 (S465). This completes the operation of mode switching B.
If it is determined that there is sufficient free space (YES in S461), the mode switching unit 143 will use the data stored in the general-purpose register 147, control register 148, and buffer area 149 of the CPU 141 of the system LSI 101. The data stored in the control register 150 of the peripheral circuit 142 and the buffer area 151 is stored in the internal protection memory unit 144 as the protection switching data 156 (S463). Next, control is transferred to step S464. (20) Application program hash value generation and verification B operation The hash value generation and verification B operation of the application program will be described with reference to the flowchart shown in FIG. The operation of hash value generation and verification B described here is as follows: step S224 in FIG. 10, step S241 in FIG. 11, step S251 in FIG. 12, step S256 in FIG. 12, step S271 in FIG. 13 and step 15 in FIG. Details of S284.
The tampering detection unit 155x of the protected data operation unit 155 (or the tampering detection unit 127x of the data dark decoding function unit 160) is unidirectional such as SHA-1 with respect to the execution image of the application program stored in the memory unit 103. Generate a hash value using a sex function (S471). Next, in the tampering detection unit 155x of the protected data operation unit 155 (or the tampering detection unit 127x of the data cryptic function unit 160), the generated hash value is the normal key of the protection key table 136 (or the data cryptic function unit 160). It is determined whether or not it is included in the hash value held by Table 128) (S472).
If included (YES in S472), validation B completes successfully and the application program is justified. On the other hand, if it is not included (NO in S472), the protected data manipulation unit 155 (or data dark decoding function unit 160) deletes the key held by the data dark decoding function unit 160, and verification B terminates abnormally. However, the application program is found to be unreasonable. In case of abend, the secure operating system 152 prohibits the execution of application programs. In addition, information indicating that the application program is malicious may be stored in the non-volatile storage unit 102 as a log.
A one-way function other than SHA-1 may be used in the generation of the hash value. For example, MD5, SHA-256, AES, DES may be used. (21) Verification operation of other application programs The operation of verifying other application programs will be described with reference to the flowchart shown in FIG. The operation of verifying the other application programs described here is the details of step S225 in FIG. 10, step S242 in FIG. 11, step S252 in FIG. 12, and step S285 in FIG.
The tampering detection unit 155x of the protected data manipulation unit 155 (or the tampering detection unit 127x of the data decryption function unit 160) is held in the protected key table 136 (or the normal key table 128) of the currently running application programs. Check if there is an application program that does not correspond to the hash value (S481). Note that this confirmation is obtained by holding the hash value of the application program loaded by the load function unit 129, and hashing the hash value held by the load function unit 129 and the running application program. This is done by comparing with the hash value obtained.
If no other application program exists (NO in S481), the verification operation of the other application program ends. On the other hand, if another application program exists (YES in S481), the protected data manipulation unit 155 (or data decryption function unit 160) holds the key held in the protected key table 136 (or the normal key table 128). Delete (S483), and the verification operation of other application programs ends. (22) Key confirmation A operation The operation of the key confirmation A will be described with reference to the flowchart shown in FIG. The operation of the key confirmation A described here is the details of step S221 in FIG. 10, step S243 in FIG. 11, step S253 in FIG. 12, and step S281 in FIG.
The data decryption function unit 160 confirms whether or not the key corresponding to the generated hash value and the server information is held by the normal key table 128 (S491). If the normal key table 128 holds the corresponding key (YES in S491), the key confirmation A operation ends. On the other hand, if the corresponding key is not held (NO in S491), a mode switching request is made so that the mode switching unit 143 acquires the key, the key is acquired from the protected mode, and the mode switching unit 143 again. A mode switching request is made to, and the mode is switched to the normal mode (S492). In this way, the operation of key confirmation A ends. (23) Key confirmation B operation The operation of the key confirmation B will be described with reference to the flowchart shown in FIG. The operation of the key confirmation B described here is the details of step S226 in FIG. 10, step S257 in FIG. 12, and step S286 in FIG.
The protected data manipulation unit 155 confirms whether or not the protected key table 136 holds the key corresponding to the hash value and the server information (S501). If the protected key table 136 holds the corresponding key (YES in S501), the protected data manipulation unit 155 obtains the corresponding key from the protected key table 136 (S502), and the operation of the key confirmation B is performed. , Ends normally.
On the other hand, if the protection key table 136 does not hold the corresponding key (NO in S501), Key confirmation B ends abnormally. In case of abend, the secure operating system 152 prohibits the execution of application programs. In addition, information indicating that the application program is malicious may be stored in the non-volatile storage unit 102 as a log.
In addition, instead of the information indicating that the application program is malicious, a flag indicating the existence of the malicious application program may be stored in the non-volatile storage unit 102. Further, the information indicating that the application program is malicious may be a hash value generated from the malicious application program. A safe boot may be performed by using a log of information indicating that the application program is malicious. (24) Key storage operation The operation of storing the key will be described with reference to the flowchart shown in FIG. The key storage operation described here is the details of step S232 in FIG. 10 and step S292 in FIG.
The data dark decoding function unit 160 stores the key in the normal key table 128 in association with the hash value and the server information (S511). In this way, the key storage operation ends. 1.5 Summary According to the present embodiment, the access is performed the first time when the encryption key is stored in the internal protection memory unit 144 whose access is restricted and the data decryption function unit 160 performs the encryption process using the encryption key. Performs the process of switching the mode in order to acquire the encryption key from the restricted internal protection memory unit 144. After that, the encryption key is duplicated in the memory unit 103 to which the access is permitted, and the encryption key duplicated in the memory unit 103 is used in the normal mode. In this way, the normal mode is not switched to the protected mode.
As a result, the process of switching the mode for each encryption process becomes unnecessary, and the complicated encryption process required when the encryption key is managed secretly can be significantly reduced. On the other hand, the key generation unit of the protection operation unit 135 generates the encryption key based on the hash value of a predetermined application program, stores the generated encryption key in the internal protection memory unit 144, and uses the encryption key for generation. When there is a processing request to encrypt the predetermined data stored in the memory unit 103, the data dark decoding function unit 160 stores the generated hash value in the memory unit 103, and the hash value of the application program that made the processing request. If the calculated hash value and the hash value stored in the memory unit 103 do not match, the encryption key duplicated in the memory unit 103 is erased.
As a result, application programs other than the application program corresponding to the hash value used when generating the encryption key are stored in the memory unit 103 whose access by the data decryption function unit 160 is not restricted. When there is a risk of using the above, the encryption key stored in the memory unit 103 is erased, so that the confidentiality of the encryption key can be secured, and as a result, the confidentiality of the data can be guaranteed.
Therefore, it is possible to secure the confidentiality of the encryption key and guarantee the confidentiality of the data while significantly reducing the complicated processing of encryption required when the encryption key is managed secretly. 2. Embodiment 2 The information processing apparatus 100b (not shown) as another embodiment of the present invention will be described. The information processing device 100b has the same configuration as the information processing device 100.
Hereinafter, the differences from the information processing apparatus 100 will be mainly described. Figure 29 shows the software configuration of the information processing device 100b. The information processing device 100b is composed of a software execution environment 120b in a normal mode and a secure software execution environment 121 in a protection mode. Like the information processing device 100, the information processing device 100b switches between a normal mode and a protection mode to execute each software.
Unlike the information processing device 100, the information processing device 100b also controls an intermediate language application program that controls the virtual machine itself. Since the intermediate language application program is used to control the virtual machine, it is generally considered that the data managed by the application program is not decrypted. Therefore, when the information processing apparatus 100b receives a request for dark decoding from an intermediate language application program, the information processing device 100b always rejects the request. If it is found that the request source for dark decoding is an intermediate language application program, the hash value is not generated and verified. Therefore, the number of hash values to be held can be reduced.
The execution environment 121 of the information processing apparatus 100b is the same as the execution environment 121 of the first embodiment. On the other hand, the execution environment 120b of the information processing apparatus 100b further includes the intermediate language machine 205 and the intermediate language application program 206 in addition to the components included in the execution environment 120 of the first embodiment. As described above, in the information processing apparatus 100b, the application program running on the general-purpose operating system 157 performs data dark decoding, and the intermediate language application program does not perform data dark decoding.
Further, the intermediate language machine 205 includes an intermediate language load function unit 218. The intermediate language machine 205 is a virtual machine operated by an instruction from the intermediate language application program 206. The intermediate language loading function unit 218 has a function of loading the intermediate language application program 206.
The intermediate language application program 206 is an application program written using a program language for operating a virtual machine. In the second embodiment, the hash value generation and verification A (step S206 of FIG. 9) and the hash value generation and verification B (step S224 of FIG. 10 and step S251 of FIG. 12) of the application program of the first embodiment are performed. In S256 and S271) in FIG. 13, the request from the intermediate language machine 205 by the intermediate language application program 271 terminates abnormally.
Further, the verification and determination methods of the application program in the hash value generation and verification A of the application program and the hash value generation and verification B of the application program are the same as those in the first embodiment. By distinguishing between the intermediate language application program 206 and the application program (native language application program) 158 in this way, the number of hash values to be held can be reduced. Further, in the case of the intermediate language application program, since the generation and verification of the hash value fails, even if the intermediate language application program requests the dark decoding of the data, the dark decoding of the data is not performed.
The configuration of the second embodiment is the same as that of the first embodiment except for the intermediate language machine 205 and the intermediate language application program 206. 3. Embodiment 3 An information processing apparatus 100c (not shown) as another embodiment of the present invention will be described. The information processing device 100c has the same configuration as the information processing device 100.
Hereinafter, the differences from the information processing apparatus 100 will be mainly described. Figure 30 shows the software configuration of the information processing device 100c. The information processing device 100c is composed of a software execution environment 120 which is a normal mode and a safe software execution environment 121c which is a protection mode. Like the information processing device 100, the information processing device 100c switches between a normal mode and a protection mode to execute each software.
The information processing device 100c is an information processing device to which an application that performs data dark decoding can be added. The execution environment 121c of the information processing apparatus 100c has the same configuration as the execution environment 121 of the first embodiment, and the protection data operation unit 155 further includes the protection key table update unit 237. The information processing device 100c newly adds an application program managed by the protection key table 136. The execution environment 120 of the information processing apparatus 100c is the same as the execution environment 120 of the first embodiment.
Next, a method of adding the application program managed by the protection key table 136 will be described with reference to FIGS. 31 to 34. (1) Application program registration procedure The procedure for registering the application program will be described with reference to FIGS. 31 and 32.
The procedure for registering the application program of the third embodiment is similar to the procedure shown in FIG. 9 of the first embodiment. In the following, the differences will be mainly described. There are two differences from the registration of the application program of the first embodiment. First, instead of the hash value generation and verification A (step S206 in FIG. 9) of the application program of the first embodiment, in the registration of the application program of the third embodiment, as shown in FIG. 31, a table update request is made. (S605), application program verification, key table update (S606), and notification (S607).
The other is that in the registration of the application program of the third embodiment, as shown in FIG. 32, the data dark decoding function unit 160 updates the key table (S615) after the mode switching B (S213). is there. Other points are the same as the operation shown in FIG. 9 of the first embodiment. (2) Application program verification and key table update operation The operation of verifying the application program and updating the key table will be described with reference to the flowchart shown in FIG. 33. The operation of verifying the application program and updating the key table described here is the details of step S606 in FIG.
The protected key table update unit 237 generates a hash value of the application program (S621). Next, the protection key table update unit 237 verifies the electronic signature corresponding to the application program (S622). The verification key used for the verification of the electronic signature is a key held by the protection key table update unit 237 and provided by the manufacturer of the information processing apparatus 100c. The algorithm used for verifying the electronic signature is a digital signature verification algorithm using RSA or elliptic curve cryptography.
If the verification is completed normally (YES in S623), the protection key table update unit 237 determines whether or not the hash value generated in step S621 is the hash value stored in the protection key table 136. (S624). If the generated hash value is the hash value stored in the protected key table 136 (YES in S624), the application program verification and the key table update are completed.
If the generated hash value is not the hash value stored in the protected key table 136 (NO in S624), create key information as a new entry in the protected key table 136 and refer to the application program for the new key information. The hash value generated in step S621 is stored in the hash value field (S626), and the verification of the application program and the update of the key table are completed.
Further, when the key information is added as a new entry to the protected key table 136 and the generated hash value is stored in this key information, the notification in step S210, the mode switching request in step S212, and the mode switching request in step S213 are performed. With mode switching B, the generated hash value is also notified. (3) Normal key table 128 update operation The operation of updating the normal key table 128 will be described with reference to the flowchart shown in FIG. The operation of updating the normal key table 128 described here is the details of step S615 in FIG.
The data decryption function unit 160 adds the key information as a new entry to the normal key table 128, and stores the hash value notified from the protection mode in the new key information (S631). This completes the normal key table 128 update operation. In this way, by adding the application program that is normally managed by the key table 128, the data of the newly added application program can be protected.
The key used in the verification of the application program in step 622 may be a key other than the key provided by the manufacturer of the information processing apparatus 100c. The key other than the key provided by the manufacturer of the information processing device 100c may be, for example, a key provided by a service company that operates a server, or a key provided by a content company that provides content. It may be a key. 4. Embodiment 4 The information processing apparatus 100d (not shown) as another embodiment of the present invention will be described. The information processing device 100d has the same configuration as the information processing device 100.
Hereinafter, the differences from the information processing apparatus 100 will be mainly described. The information processing device 100d controls the number of times the key used for dark decoding of data is used. Hereinafter, a technique for controlling the number of times the key is used by the information processing apparatus 100d will be described with reference to FIGS. 35 and 36. (1) Data structure of normal key table 128d The protection data manipulation unit 155 of the information processing device 100d stores the protection key table 136d (not shown) instead of the protection key table 136 of the information processing device 100. Further, the data dark decoding function unit 160 stores the normal key table 128d shown as an example in FIG. 35 instead of the normal key table 128 of the information processing device 100.
The normal key table 128d has the same data structure as the protection key table 136d. Here, the data structure of the normal key table 128d will be described, and the description of the data structure of the protection key table 136d will be omitted. The normal key table 128d is a table that temporarily stores a key used for encrypting or decrypting data used by an application program, and stores one or more key information as shown as an example in FIG. 35. Has an area for. Each key information is composed of a reference hash value of an application program and one or more server key information, and each server key information is composed of server information, a key, a maximum number of uses, and a current number of uses. Since the reference hash value and the server information of the application program are as described above, the description thereof will be omitted.
The maximum number of uses is the maximum number of times the corresponding application program can use the corresponding key, and the current number of uses is the number of times the corresponding application program has actually used the corresponding key so far. .. The normal key table 128d differs from the key table of the information processing apparatus 100 in that it includes the maximum number of times of use and the current number of times of use. (2) Key confirmation A operation The operation of the key confirmation A by the information processing device 100d will be described with reference to the flowchart shown in FIG. The data dark decoding function unit 160 of the information processing device 100d performs the key confirmation A according to the procedure shown below instead of the operation of the key confirmation A of the information processing device 100 (shown in FIG. 26).
The operation of the key confirmation A described here is the details of step S221 in FIG. 10, step S243 in FIG. 11, step S253 in FIG. 12, and step S281 in FIG. The data dark decoding function unit 160 determines whether or not the key corresponding to the generated hash value and server information is held by the normal key table 128d (S641). If the normal key table 128d holds the key corresponding to the generated hash value and server information (YES in S641), the data decryption function unit 160 generates the hash value and the server from the normal key table 128d. The maximum number of times of use corresponding to the information and the current number of times of use are read, and it is determined whether or not the current number of times of use read exceeds the maximum number of times of use read (S642).
If the current number of uses does not exceed the maximum number of uses (NO in S642), the data anti-decryption function unit 160 adds "1" to the current number of uses corresponding to the generated hash value and server information, and " The current number of times of use to which "1" is added is overwritten in the normal key table 128d (S643), and the operation of key confirmation A ends. When the current number of uses exceeds the maximum number of uses (YES in S642), the data dark decoding function unit 160 performs mode switching A with respect to the mode switching unit 143, and sets a new key and a new maximum number of times of use. The new key and maximum usage count are generated in the protected mode, the new key and maximum usage count are output for the normal mode, and after switching to the normal mode again, the data is darkened. The decryption function unit 160 acquires a new key and a new maximum number of uses (S644). The new key is generated in the execution environment 121 by using a timer (not shown) to generate a random number and using the generated random number, the hash value of the application program, the server information, and the terminal-specific information. There may be.
Next, the data dark decryption function unit 160 decrypts the encrypted data using the key before the update, and re-encrypts the obtained data using the new key notified from the protection mode (S645). Next, the data decryption function unit 160 deletes the key before update corresponding to the generated hash value and server information in the normal key table 128d, and sets the current number of uses corresponding to the generated hash value and server information. Set "0", set the maximum number of uses notified from the protected mode in the field of the maximum number of uses corresponding to the generated hash value and server information, and generate a new key notified from the protected mode. Set in the key field corresponding to the hash value and server information (S646), and end the operation of key confirmation A.
If the normal key table 128d does not hold the key corresponding to the generated hash value and server information (NO in S641), the data dark decoding function unit 160 performs mode switching A with respect to the mode switching unit 143. Request (S647) and end the operation of key confirmation A. (3) As explained above, according to the information processing device 100d, the number of times the key used for data decryption can be used can be limited, and the same dark decryption key can be used continuously beyond the maximum number of times of use. Therefore, the possibility of leakage of the dark decryption key can be reduced. In addition, when the maximum number of uses is exceeded, the key is newly updated, so the attacker can generate all the patterns of the expected dark decryption key and try each one to protect it from brute force attacks. Can be strengthened. 5. Embodiment 5 The information processing apparatus 100e as another embodiment of the present invention will be described. The information processing device 100e has the same configuration as the information processing device 100. Hereinafter, the differences from the information processing apparatus 100 will be mainly described.
The information processing device 100e controls the usage time of the key used for dark decoding of data. Hereinafter, a technique of controlling the usage time of the key used for dark decoding of data by the information processing apparatus 100e will be described with reference to FIGS. 37 to 39. (1) Configuration of information processing device 100e As shown in FIG. 37, the information processing device 100e has a configuration similar to that of the information processing device 100.
The information processing device 100e is different from the information processing device 100 in that the system LSI 101e newly includes a clock 265. Further, the protection data operation unit 155 of the information processing device 100e stores the protection key table 136e (not shown) instead of the protection key table 136 of the information processing device 100. Further, the data dark decoding function unit 160 stores the normal key table 128e shown as an example in FIG. 38 instead of the normal key table 128 of the information processing device 100. Other configurations are the same as those of the information processing device 100. (1) Clock 265 The clock 265 is a time measuring unit that measures the time, and holds time information indicating the current time. The clock 265 is connected to the CPU 141, the peripheral circuit 142, and the mode switching unit 143 via the internal bus 145. Further, the clock 265 is connected to the mode switching unit 143 via a dedicated line 266.
In the CPU 141, access to the time information held in the clock 265 is restricted by the mode switching unit 143. When the system LSI 101e is in the protection mode, the mode switching unit 143 controls the time information stored in the clock 265 via a dedicated line 266 so that the time information can be read and changed. Further, the mode switching unit 143 controls the time information stored in the clock 265 via the dedicated line 266 so that only the time information stored in the clock 265 can be read when the system LSI 101e is in the normal mode. (2) Key table data structure The normal key table 128e has the same data structure as the protection key table 136e. Here, the data structure of the normal key table 128e will be described, and the description of the data structure of the protection key table 136e will be omitted.
The normal key table 128e is a table that temporarily stores a key used for encrypting or decrypting data used by an application program, and stores one or more key information as shown as an example in FIG. 38. Has an area for. Each key information is composed of a reference hash value of an application program and one or more server key information, and each server key information is composed of server information, a key, and a last date and time. Since the reference hash value and the server information of the application program are as described above, the description thereof will be omitted.
The last date and time is the last date and time when the corresponding application program can use the corresponding key, and is composed of the year, month, day, hour, minute, and second as an example. The normal key table 128e differs from the key table of the information processing apparatus 100 in that it includes the last date and time. (3) Key confirmation A operation The operation of the key confirmation A by the information processing device 100e will be described with reference to the flowchart shown in FIG. 39. The data dark decoding function unit 160 of the information processing device 100e performs the key confirmation A according to the procedure shown below instead of the operation of the key confirmation A of the information processing device 100 (shown in FIG. 26).
The operation of the key confirmation A described here is the details of step S221 in FIG. 10, step S243 in FIG. 11, step S253 in FIG. 12, and step S281 in FIG. The data dark decoding function unit 160 determines whether or not the key corresponding to the generated hash value and server information is held by the normal key table 128e (S651). If the normal key table 128e holds the key corresponding to the generated hash value and server information (YES in S651), the data dark decoding function unit 160 acquires the time information from the clock 265 and the normal key table. The last date and time corresponding to the hash value and server information generated from 128e is read, and it is determined whether or not the current date and time indicated by the acquired time information exceeds the acquired last date and time (S652).
If the current date and time does not exceed the last date and time (NO in S652), the key confirmation A process ends. When the current date and time exceeds the last date and time (YES in S652), the data dark decoding function unit 160 performs mode switching A for the mode switching unit 143 and acquires a new key and a new last date and time. After the new key and last date and time are generated in the protected mode, the new key and last date and time are output to the normal mode, and the mode is switched to the normal mode again, the data dark decoding function unit 160 , Get a new key and a new last date and time (S653). Even if the new key is generated by generating a random number using a clock 265 or a timer (not shown), and using the generated random number, application program hash value, server information, and terminal-specific information. Good.
Next, the data dark decryption function unit 160 decrypts the encrypted data using the key before the update, and re-encrypts the obtained data using the new key notified from the protection mode (S654). Next, the data dark decoding function unit 160 deletes the key corresponding to the generated hash value and server information in the normal key table 128e. Further, in the normal key table 128e, the last date and time notified from the protection mode is set in the field of the last date and time corresponding to the generated hash value and server information. Further, in the normal key table 128e, the new key notified from the protected mode is set in the key field corresponding to the generated hash value and the server information (S655). Next, the process of key confirmation A is completed.
If the normal key table 128e does not hold the key corresponding to the generated hash value and server information (NO in S651), the data dark decoding function unit 160 requests the mode switching unit 143 for mode switching A. (S656). Next, the process of key confirmation A is completed. (3) This makes it possible to limit the date and time when the key used for decrypting data is used, and the same encryption key will not continue to be used beyond the final date and time, so there is a possibility of leakage of the encryption key. Can be reduced. In addition, since the key is newly updated when the last date and time is exceeded, the protection from brute force attacks where the attacker generates all the expected patterns of the dark decryption key and tries each one to attack is strengthened. it can. 6. Embodiment 6 The information processing apparatus 100f as another embodiment of the present invention will be described. The information processing device 100f has the same configuration as the information processing device 100. Hereinafter, the differences from the information processing apparatus 100 will be mainly described.
When the information processing device 100f detects an unauthorized application program, it decrypts the encrypted data and deletes the plaintext data generated. Hereinafter, with reference to FIGS. 40 to 43, a technique for deleting the plaintext data generated by decrypting the encrypted data when an unauthorized application program is detected will be described. (1) Software configuration of information processing device 100f Figure 40 shows the software configuration of the information processing device 100f.
The information processing device 100f is composed of a software execution environment 120f in a normal mode and a safe software execution environment 121 in a protection mode. The information processing device 100f switches between the normal mode and the protection mode to execute each software. The execution environment 120f is similar to the execution environment 120 of the information processing device 100, and includes a data dark decoding function unit 160f instead of the data dark decoding function unit 160 of the information processing device 100. The data dark decoding function unit 160f is similar to the data dark decoding function unit 160 of the information processing apparatus 100, and has a decryption data storage position table 297 in addition to the components of the data dark decoding function unit 160. ing.
The execution environment 120 of the information processing device 100f is the same as the execution environment 120 of the information processing device 100. As described above, the execution environment 120f of the information processing apparatus 100f is different from the execution environment 120 of the information processing apparatus 100 in that the data dark decoding function unit 160f further includes the decoded data storage position table 297. (2) Data structure of decrypted data storage position table 297 As shown in FIG. 41, the decrypted data storage position table 297 is a data table configured to include a plurality of decrypted information. Each decryption information corresponds to the data to be encrypted or decrypted in the application program running on the information processing apparatus 100f. Each decryption information is composed of a data ID, an encrypted data storage file name, a hash value of the provided application program, a decryption data storage address, and a decryption data size.
The data ID is an identifier that uniquely identifies the encrypted data. The encrypted data storage file name is the name of the file in which the encrypted data is stored. The hash value of the provided application program is the hash value of the application program provided as plain text data by decrypting the encrypted data, and is an identifier that identifies the application program.
The decrypted data storage address is the start address of the memory that stores the plaintext data obtained by decrypting the encrypted data. The address is stored here when the plaintext data obtained by decrypting the encrypted data is provided to the application program. The decrypted data size is the size of the plaintext data obtained by decrypting the encrypted data. The size is stored here when the encrypted data is decrypted and provided to the application program. (3) Application program hash value generation and verification B operation The hash value generation and verification B operation of the application program will be described with reference to the flowchart shown in FIG.
The data dark decoding function unit 160f (or protected data manipulation unit 155) of the information processing device 100f is shown below instead of the hash value generation and verification B operation (shown in FIG. 24) of the application program of the information processing device 100. Perform hash value generation and verification B of the application program according to the procedure. The operation of hash value generation and verification B described here is as follows: step S224 in FIG. 10, step S241 in FIG. 11, step S251 in FIG. 12, step S256 in FIG. 12, step S271 in FIG. 13 and step 15 in FIG. Details of S284.
The tampering detection unit 127x (or the tampering detection unit 155x of the protected data manipulation unit 155) of the data dark decoding function unit 160f is used for SHA-1 etc. for the execution image of the application program stored and expanded on the memory unit 103. A hash value is generated using a one-way function (S661). Here, a one-way function other than SHA-1 may be used in the generation of the hash value. For example, MD5, SHA-256, AES, DES may be used.
Next, in the tampering detection unit 127x (or the tampering detection unit 155x of the protected data manipulation unit 155) of the data dark decoding function unit 160f, the generated hash value is a hash held by the normal key table 128 (or the protected key table 136). Determine if it is included in the value (S662). If it is determined to be included (YES in S662), the hash value generation and verification B processing of the application program ends normally.
If it is determined that it is not included (NO in S662), the data decryption function unit 160f (or protected data manipulation unit 155) deletes the key held by the normal key table 128 (or protected key table 136). (S664) Next, the address and size for storing the decrypted data are read from the decrypted data storage position table 297, and the decrypted data is deleted based on the read address and size (S665). The deletion may be performed by overwriting a specific value, or by generating a random number and overwriting the random number. In this way, the hash value generation of the application program and the processing of verification B end abnormally. In case of abnormal termination, execution of the application program is prohibited. In addition, information indicating that the application program is malicious may be stored in the non-volatile storage unit 102 as a log. (4) As explained above, not only the decryption key but also the plaintext data decrypted in the past using the dark decryption key is deleted. Therefore, not only the plaintext data generated in the future but also the plaintext data generated in the past is deleted. Data can also be protected from malicious application programs. (5) Verification operation of other application programs The operation of verifying other application programs will be described with reference to the flowchart shown in FIG.
The data decoding function unit 160f (or protection data manipulation unit 155) of the information processing device 100f replaces the verification operation (shown in FIG. 25) of another application program of the information processing device 100 according to the procedure shown below. Performs verification operations for other application programs. The operation of verifying the other application programs described here is the details of step S225 in FIG. 10, step S242 in FIG. 11, step S252 in FIG. 12, and step S285 in FIG.
The tampering detection unit 127x (or the tampering detection unit 155x of the protected data manipulation unit 155) of the data encryption / decoding function unit 160f is held in the normal key table 128f (or the protection key table 136f) among the currently running application programs. Check if there is an application program that does not correspond to the hash value (S671). Note that this confirmation holds the hash value of the application program loaded by the load function unit 129, and the value may be confirmed.
If there is no corresponding application program (NO in S671), the verification operation of other application programs ends normally. If there is an unsupported application program (YES in S671), the data decryption function unit 160f (or protected data manipulation unit 155) deletes the key held by the normal key table 128f (or protected key table 136f). (S672), the decrypted data storage position table 297 is searched for and read from the address and size for storing the decrypted data, and the decrypted data is deleted based on the read address and size (S673). This completes the confirmation operation of other application programs. The restored data may be deleted by overwriting a specific value. Further, the deletion may be realized by generating a random number and overwriting the restored data with the random number. (6) Of the operations of the information processing device 100f, the hash value generation and verification B of the application program and the verification of other application programs are as described above, and the other operations are the information processing device 100. Is the same as.
As described above, in the information processing apparatus 100f, the encryption key is stored in the internal protection memory unit 144 whose access is restricted, and the data encryption / decryption function unit 160f performs encryption processing using the encryption key, for example, the first time. At this time, the normal mode is switched to the protected mode in order to acquire the encryption key from the internal protected memory unit 144 whose access is restricted. After that, it is not necessary to duplicate the encryption key in the memory unit 103 to which the access is permitted and to switch to the protection mode again. As a result, it is not necessary to switch the mode for each encryption process, so that the complicated encryption process required when the encryption key is managed secretly can be significantly reduced.
On the other hand, the key generation unit of the protection operation unit 135 generates the encryption key based on the hash value of a predetermined application, stores the generated encryption key in the internal protection memory 144, and uses the hash to generate the encryption key. The value is stored in the memory unit 103, and when there is a processing request for encrypting the predetermined data stored in the memory unit 103, the data dark decoding function unit 160f calculates the hash value of the application that made the processing request. If the calculated hash value and the hash value stored in the memory unit 103 do not match, the encryption key duplicated in the memory unit 103 is erased. As a result, applications other than the application corresponding to the hash value used when generating the encryption key use the encryption key stored in the memory unit 103 whose access by the data decryption function unit 160f is not restricted. When there is a risk of this, the encryption key stored in the memory unit 103 is erased, so that the confidentiality of the encryption key can be secured, and as a result, the confidentiality of the data can be guaranteed.
Therefore, it is possible to secure the confidentiality of the encryption key and guarantee the confidentiality of the data while significantly reducing the complicated processing of encryption required when the encryption key is managed secretly. 7. Other The information processing apparatus according to the first aspect of the present invention includes a first memory for storing predetermined data, a second memory for storing an encryption key, a storage unit for storing a predetermined application, and a hash of the predetermined application. Access to the first memory and the key generation unit that generates the encryption key based on the value and stores it in the second memory and stores the hash value used for generating the encryption key in the first memory is permitted. And access to the second memory is prohibited, and access to the first memory by the encryption unit that reads the predetermined data from the first memory and encrypts the predetermined data and the predetermined application is permitted. In addition, the predetermined application is started by setting the first mode for prohibiting access to the second memory, and a processing request for encrypting the predetermined data stored in the first memory is issued from the predetermined application. When the encryption key is not stored in the first memory, the key generation unit is switched to the second mode for permitting the access to the first memory and the second memory by the key generation unit. The encryption key stored in the second memory is duplicated in the first memory, the mode is switched to the first mode, and the predetermined data is encrypted by the encryption unit using the encryption key duplicated in the first memory. The encryption unit includes a control unit for the processing request, and the encryption unit calculates the hash value of the application that made the processing request in response to the processing request, and the calculated hash value and the hash stored in the first memory. If the values do not match, the encryption key duplicated in the first memory is erased.
According to this aspect, it is possible to secure the confidentiality of the encryption key and guarantee the confidentiality of data while significantly reducing the complicated processing of encryption required when the encryption key is managed secretly. To protect the confidentiality of data, it is necessary to keep the encryption key for encrypting data secretly. In order to manage the encryption key secretly, it is necessary to restrict access to the memory for storing the encryption key. On the other hand, if access to the memory for storing the encryption key is restricted, the encryption process using the encryption key becomes complicated. That is, it is necessary to perform a process for acquiring the encryption key from the memory whose access is restricted for each encryption process.
Therefore, according to this aspect, the information processing apparatus stores the encryption key in the second memory whose access is restricted, and the access is performed, for example, the first time when the encryption unit performs the encryption process using the encryption key. Performs the process of switching the mode in order to acquire the encryption key from the limited second memory. However, after that, the encryption key is duplicated in the first memory to which the access is permitted, and the process of switching the mode is unnecessary. This eliminates the need for the process of switching the mode for each encryption process, so that the complicated encryption process required when the encryption key is managed secretly can be significantly reduced.
Further, according to this configuration, the key generation unit of the information processing apparatus generates the encryption key based on the hash value of a predetermined application, stores the encryption key in the second memory, and uses the hash value used for generating the encryption key. When there is a processing request to encrypt the predetermined data stored in the first memory and the encryption unit stores the predetermined data stored in the first memory, the encryption unit calculates the hash value of the application that made the processing request, and the calculation is performed. If the hash value is inconsistent with the hash value stored in the first memory, the encryption key duplicated in the first memory is erased. As a result, there is a risk that an application other than the application corresponding to the hash value used when generating the encryption key will use the encryption key stored in the first memory whose access by the encryption unit is not restricted. If there is, the encryption key stored in the first memory is erased, so that the confidentiality of the encryption key can be secured, and as a result, the confidentiality of the data can be guaranteed.
Therefore, it is possible to secure the confidentiality of the encryption key and guarantee the confidentiality of the data while significantly reducing the complicated processing of encryption required when the encryption key is managed secretly. Further, in the information processing apparatus according to the second aspect of the present invention, when the control unit receives the processing request from the predetermined application, the encryption key is stored in the first memory. If so, the predetermined data is encrypted by the encryption unit using the encryption key duplicated in the first memory without switching to the second mode.
According to this aspect, when the processing request is received from the predetermined application and the encryption key is stored in the first memory, the encryption unit does not switch to the second mode. The predetermined data is encrypted using the encryption key duplicated in the first memory. According to this, the encryption key is stored in the second memory whose access is restricted, and the second memory whose access is restricted when the encryption unit performs encryption processing using the encryption key, for example, the first time. The mode is switched in order to obtain the encryption key from, and thereafter, the encryption key is duplicated in the first memory to which the access is permitted, and the encrypted encryption key is used for encryption. Therefore, since the process of switching the mode is not required for each encryption process, the complicated encryption process required when the encryption key is managed secretly can be significantly reduced.
Further, in the information processing device according to the third aspect of the present invention, the predetermined application is an application for storing data to be transmitted to the external device in the first memory, and the key generation unit is the external device. The encryption key is generated based on the identification information of the device and the hash value of the predetermined application, and the control unit encrypts the data to be transmitted to the external device with the encryption key and stores it in the third memory. It is a thing.
According to this aspect, when the predetermined application is an application that stores data to be transmitted to the external device in the first memory, the key generation unit uses the identification information of the external device and the predetermined application. The encryption key is generated based on the hash value of. According to this, when one application stores data to be transmitted to a plurality of external devices, a plurality of encryption keys can be generated for one application according to a plurality of external terminals.
Further, in the information processing apparatus according to the fourth aspect of the present invention, the key generation unit reads the predetermined data from the first memory, reads the encryption key from the second memory, and obtains the predetermined data. It has a second encryption unit that encrypts the data of the above, and the control unit is in the first memory. When the processing request is received from the predetermined application in the first mode after the duplicated encryption key is erased from the first memory, the key generation unit transfers the duplicated encryption key to the first memory and the second memory. The mode is switched to the second mode in which access is permitted, and the predetermined data stored in the first memory is encrypted by using the encryption key stored in the second memory for the second encryption unit. ..
According to this aspect, the key generation unit has a second encryption unit that reads the predetermined data from the first memory, reads the encryption key from the second memory, and encrypts the predetermined data. .. Further, when the control unit receives the processing request from the predetermined application after the encryption key duplicated in the first memory is erased from the first memory, the control unit receives the processing request from the predetermined application, the first memory by the key generation unit. And the predetermined data stored in the first memory by switching to the second mode for permitting access to the second memory and using the encryption key stored in the second memory for the second encryption unit. To encrypt. As a result, after the encryption key duplicated in the first memory is erased from the first memory, the encryption unit is not forced to perform the encryption process in the state of the first mode, but from the first mode. The key generation unit, which can access the second memory in which the encryption key is stored by switching to the second mode, is made to perform the encryption process. Therefore, after the encryption key duplicated in the first memory is erased from the first memory, the mode switching process is performed, but the confidentiality of the encryption key can be secured, and as a result, the confidentiality of the data can be guaranteed. ..
Further, the information processing apparatus according to the fifth aspect of the present invention further provides a monitoring unit for monitoring whether or not the application is running, and the monitoring unit erases the encryption key duplicated in the first memory. After that, when it is determined that the application that has made the processing request and the application corresponding to the hash value that does not match the hash value stored in the first memory has been started, the control unit performs the first. When the processing request is received from the predetermined application in the mode and the encryption key is not stored in the first memory, the second memory that allows the key generator to access the first memory and the second memory. The mode is switched, and the encryption key stored in the second memory is duplicated in the first memory for the first encryption unit.
According to this aspect, the application that made the processing request after the encryption key duplicated in the first memory is erased and corresponds to the hash value that does not match the hash value stored in the first memory. When it is determined that the activation of is completed, the encryption key stored in the second memory is duplicated in the first memory again. As a result, when an application other than the predetermined application corresponding to the hash value used when generating the encryption key finishes starting and the risk of using the encryption key disappears, the encryption unit causes the encryption unit. The encryption key is duplicated again in the first memory to which access is permitted. Therefore, after the risk of using the encryption key by an application other than the predetermined application disappears, the complicated encryption process required when the encryption key is managed secretly is greatly reduced. At the same time, it is possible to secure the confidentiality of the encryption key and restore the state in which the confidentiality of the data can be guaranteed.
Further, in the information processing apparatus according to the sixth aspect of the present invention, the key generation unit further indicates an encryption key corresponding to the predetermined application based on the hash value of the predetermined application at the time of initial setting of the predetermined application. Is generated and stored in the second memory, a key generation list for associating the hash value of the predetermined application with the corresponding encryption key is generated and stored in the second memory, and exists in the key generation list. The hash value to be used is stored in the first memory.
According to this aspect, the key generator has the hash value of the predetermined application and the said. Generate a key generation list that corresponds to the corresponding encryption key. As a result, the management of associating the hash value of the predetermined application with the corresponding encryption key becomes reliable and simple. Therefore, the management of the confidentiality of the encryption key can be made reliable and simple. Further, the information processing device according to the seventh aspect of the present invention further acquires the identification information of the external device to which the predetermined application transmits data at the time of initial setting of the predetermined application through the predetermined application. Then, an encryption key corresponding to the predetermined application is generated based on the identification information of the external device and the hash value of the predetermined application and stored in the second memory, and the identification information of the external device, the predetermined A second key generation list corresponding to an application hash value and the corresponding encryption key is generated and stored in the second memory, and a hash value existing in the second key generation list is stored in the first memory. Is.
According to this aspect, the key generation unit generates a second key generation list corresponding to the identification information of the external device, the hash value of the predetermined application, and the corresponding encryption key. As a result, when a plurality of encryption keys are generated for one application according to a plurality of external terminals, the management of associating the identification information of the external device, the hash value of the predetermined application, and the corresponding encryption keys is performed. It will be reliable and simple. Therefore, it is possible to reliably and easily manage the confidentiality of a plurality of encryption keys for one application.
Further, in the information processing apparatus according to the eighth aspect of the present invention, when the key generation unit replicates the encryption key to the first memory, the information indicating the number of times the encryption key is used is stored in the first memory. When the number of times the encryption key is used exceeds the number of times the information indicates the number of times the encryption key is used, the encryption unit erases the encryption key duplicated in the first memory, and the control unit receives a new encryption key. Upon requesting duplication, the control unit switches to the second mode, causes the key generation unit to generate a new encryption key, and causes the key generation unit to copy to the first memory.
According to this aspect, since the same encryption key is not used continuously, the possibility of leakage of the encryption key can be reduced, and the attacker can generate all the expected encryption key patterns and try and attack one by one. You can strengthen the protection from hit attacks. Further, the information processing apparatus according to the ninth aspect of the present invention further provides a time measuring unit for measuring the day and time, and the key generating unit receives the encryption key when replicating the encryption key to the first memory. The time information indicating the last day and the last time when the use of is permitted is stored in the first memory, and the encryption unit sets the date and time when the time measuring unit measures the last day and the last time indicated by the time information. When it exceeds, the encryption key duplicated in the first memory is erased, the control unit is requested to duplicate the new encryption key, the control unit switches to the second mode, and the key generation unit is newly charged. An encryption key is generated and copied to the first memory.
According to this aspect, since the same encryption key is not used continuously, the possibility of leakage of the encryption key can be reduced, and all the encryption key patterns expected by the attacker are generated and tried one by one to attack. You can increase protection from attacks. The information processing apparatus according to the tenth aspect of the present invention includes a first memory for storing a predetermined encrypted data, a second memory for storing a decryption key, a storage unit for storing a predetermined application, and the predetermined application. The key generation unit that generates the decryption key based on the hash value and stores it in the second memory, and stores the hash value used for generating the decryption key in the first memory, and the access to the first memory A decryption unit that is permitted and access to the second memory is prohibited, reads the predetermined encrypted data from the first memory and decrypts the predetermined encrypted data, and the first memory by the predetermined application. The predetermined processing request for setting the first mode for permitting access and prohibiting access to the second memory, starting the predetermined application, and decrypting the predetermined encrypted data stored in the first memory. When the decryption key is not stored in the first memory and received from the application of The mode is switched to the second mode in which the key generation unit is allowed to access the first memory and the second memory, and the decryption key stored in the second memory is duplicated in the first memory for the key generation unit. The decryption unit is provided with a control unit for decoding the predetermined encrypted data using the decryption key duplicated in the first memory, and the decryption unit is provided with the processing request. The hash value of the application that made the processing request is calculated according to the above, and if the calculated hash value and the hash value stored in the first memory do not match, the decryption key duplicated in the first memory is used. Further, the decryption unit is provided with a fourth memory for storing the plain text data obtained by decrypting the predetermined encryption data using the decryption key, and the decryption unit responds to the processing request and performs the processing. The hash value of the requesting application is calculated, and when the calculated hash value and the hash value stored in the first memory do not match, the plain text data stored in the fourth memory is deleted.
According to this aspect, not only the decryption key but also the plaintext data decrypted in the past by using the decryption key is erased, so that not only the plaintext data generated in the future but also the plaintext data generated in the past is invalid. Can be protected from various applications. 8. Other variants (1) In each of the above embodiments, the general-purpose operating system 157 includes a load function unit 129 that verifies the application program. However, it may be realized by other software modules. The other module may be, for example, download software that downloads an application program from a network and stores it in an information processing device.
(2) In each of the above embodiments, when a malicious application program is detected, the key stored in the normal key table is deleted. However, other data may be deleted. The other data is, for example, decrypted plaintext data. The other data is a file in which an invalid application program is stored. (3) In each of the above embodiments, when a malicious application program is detected, the key stored in the normal key table is deleted. However, other operations may be performed. For example, a warning message may be sent to the application program that holds the decrypted plaintext data. Further, the detection information indicating that an invalid application program has been detected is stored in the non-volatile storage unit 102, and whether or not the detection information is stored in the non-volatile storage unit 102 at the next startup of the information processing device 100. If it is stored, control such as increasing the frequency of dynamic tampering check at the time of startup may be performed.
(4) In each of the above embodiments, the hash value is generated by using the SHA-1 algorithm, but other methods may be used. For example, the SHA-256 algorithm or the MD5 algorithm may be used. (5) In each of the above embodiments, the data encryption / decryption function unit 160 performs "application by acquiring the key from the protection mode and encryption using the data encryption / decryption function unit in the normal mode" (FIG. 10). Program hash value generation and verification B, and verification of other application programs "was not performed before key confirmation A (S221).
However, after the data encryption request (S220) and before the key confirmation A (S221), "application program hash value generation and verification B, and verification of other application programs" may be performed. As a result, the processing is unified between "encryption using only the data decryption function unit in the normal mode" (Fig. 11) and "encryption using the protected data manipulation unit in the protected mode" (Fig. 12). It is possible to standardize the processing of the data dark decoding function unit 160 and reduce the instruction code in the program.
(6) In each of the above embodiments, the data dark decoding function unit 160 performs the "application program" in "decryption using the data dark decoding function unit in the normal mode after acquiring the key from the protection mode" (FIG. 15). Hash value generation and verification B, and verification of other application programs "was not performed before key confirmation A (S281). However, after the data decryption request (S280) and before the key confirmation A (S281), "application program hash value generation and verification B, and verification of other application programs" may be performed.
As a result, the processing is unified between "decoding using only the data dark decoding function unit in the normal mode" (Fig. 15) and "decoding using the protected data manipulation unit in the protected mode" (not shown). It is possible to standardize the processing of the data dark decoding function unit 160 and reduce the instruction code in the program. (7) In each of the above embodiments, the server information is not verified after step S224 in FIG.
However, after step S224, the server information may be verified. As a result, when invalid server information is specified, it is not necessary to perform subsequent processing, and processing when an abnormality occurs can be performed at high speed. (8) In each of the above embodiments, the server information is not verified after step S241 in FIG.
However, after step S241, the server information may be verified. As a result, when invalid server information is specified, it is not necessary to perform subsequent processing, and processing when an abnormality occurs can be performed at high speed. (9) In each of the above embodiments, the server information is not verified after step S256 in FIG.
However, after step S256, the server information may be verified. As a result, when invalid server information is specified, it is not necessary to perform subsequent processing, and processing when an abnormality occurs can be performed at high speed. (10) In each of the above embodiments, the hash value of the application program is generated in "Hash value generation and verification B of the application program".
However, in "application program hash value generation and verification B", the hash value generated in "application program hash value generation and verification A" may be used. As a result, the number of times of hash value generation can be reduced, and processing can be performed at high speed.
(11) In each of the above embodiments, mode switching between the normal mode and the protection mode is used, but other methods may be used. For example, two software execution environments may be constructed using operating system virtualization technology to control access to a specific software execution environment. As a result, an information processing device equipped with an operating system virtualization technology can perform safe and high-speed data dark decoding processing.
(12) In each of the above embodiments, the hash value and the reference hash generated when the application program that requested the data encryption is authenticated in "Application program hash value generation and verification B" in step S224. Comparison with the value was used, but other methods may be used. For example, signature verification of an application program may be used. Further, when the signature verification of the application program is used, a hash value may be newly generated and notified to the data dark decoding function unit.
Note that the signature verification of the application and the generation and notification of the hash value can be realized by performing the following steps. (i) The protected data manipulation unit 155 holds the signature verification key in advance, and uses the signature verification key to verify the digital certificate of the electronically signed application program. (ii) After verifying that the electronic certificate of the application program has not been tampered with, the hash value of the application program is generated, and the generated hash value and the reference hash value stored in the electronic certificate of the application program are used. To compare.
(iii) When the generated hash value and the reference hash value match, the protected data manipulation unit 155 sends the hash value to the data dark decoding function unit 160 via the dynamic tampering detection function unit 153 and the mode switching unit 143. Notify. Further, in the verification of the digital certificate of the electronically signed application program described above, the RSA algorithm or the elliptic curve cryptographic algorithm may be used.
Further, in the above (i), (ii), and (iii), when the verification fails, tampering is detected, or the hash value mismatch is detected, the protected data manipulation unit 155 performs the step S224, " Perform the same operation as the abnormal termination of "Hash value generation and verification B" of the application program. As a result, the amount of data to be stored in the protection key table 136 held by the protection data manipulation unit 155 can be reduced.
(13) In each of the above embodiments, the data decryption key is generated when the application program is registered, but the data decryption key may be generated at other timings. For example, it may be the timing when the application program requests data dark decoding for the first time after the power of the information processing apparatus is turned on.
When the application program generates the key at the timing when the data encryption / decryption is requested for the first time after the power of the information processing apparatus is turned on, the "key confirmation B" in step S226 and the "key reading" in step S227 of FIG. 10 are performed. Instead, it can be achieved by performing "key generation and storage" in step S209 of FIG. As a result, it is not necessary to store the data decryption key in the non-volatile storage unit protected from unauthorized access (not shown), and the non-volatile storage unit protected from unauthorized access can be reduced. ..
(14) In each of the upper embodiments, the operation of encrypting the data using the encryption key and the operation of decrypting the encrypted data using the decryption key has been described, but other operations may be performed. For example, it may be a Keyed Hash operation. Here, the Keyed Hash operation is an information security process. In the case of the Keyed Hash operation, the dark decoding operation of each of the above embodiments may be replaced with the Keyed Hash operation. The data encryption key of the encryption operation of each of the above embodiments is replaced with the IV (Initial Vector) value of the Keyed Hash operation. As a result, in addition to data dark decoding, safe and high-speed operations can be performed.
Further, instead of encrypting the data and decrypting the encrypted data, the digital signature using the key and the digital signature using the key may be verified. Here, the digital signature and the detection of the digital signature are information security processes. In this way, information security processing using a key, such as encryption using a key, decryption, Keyed Hash operation, digital signature using a key, and verification of a digital signature, may be performed.
(15) With respect to the components described in each of the above-described embodiments, some or all of them may be implemented as software to the extent feasible. In this case, the amount of hardware that must be placed on the integrated circuit can be suppressed, so that the degree of integration can be further improved. (16) Each device of each of the above-described embodiments is a computer system composed of a microprocessor, ROM, RAM, a hard disk unit, a display unit, an input unit, a communication unit, and the like. A computer program is stored in the RAM or the hard disk unit. Here, the computer program is configured by combining a plurality of instruction codes indicating instructions to the computer in order to achieve a predetermined function. When the microprocessor operates according to the computer program, each device achieves its function. That is, the microprocessor reads each instruction included in the computer program one by one, decodes the read instruction, and operates according to the decoding result.
Note that each device is not limited to a computer system including all of a microprocessor, ROM, RAM, hard disk unit, display unit, and the like, and may be a computer system composed of a part thereof. In addition, the microprocessor operates according to the instructions contained in the computer program stored in the RAM or the hard disk unit, so that the computer program and the microprocessor form one hardware circuit, and this hardware You can make the circuit appear to be working.
(17) The components described in the above embodiment may be composed of one system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating a plurality of components on a single chip. Specifically, it is a computer system including a microprocessor, ROM, RAM, and the like. .. A computer program is stored in the RAM. When the microprocessor operates according to the computer program, the system LSI achieves its function.
Further, each part of the component components constituting each of the above devices may be individually integrated into one chip, or may be integrated into one chip so as to include a part or all of them. In this case, the processing can be made faster than the above components are implemented by software. (18) System LSIs are sometimes called ICs, LSIs, super LSIs, and ultra LSIs depending on the degree of integration, but any of the above integrations of system LSI 101 is included in the present invention. Needless to say. Further, an FPGA (Field Programmable Gate Array) that can be programmed after the LSI is manufactured, or a reconfigurable processor that can reconfigure the connection and setting of the circuit cells inside the LSI may be used.
Furthermore, if an integrated circuit technology that replaces an LSI appears due to advances in semiconductor technology or another technology derived from it, the components may be integrated using that technology. There is a possibility of adaptation of biotechnology. (19) Some or all of the components constituting each of the above devices may be composed of an IC card or a single module that can be attached to and detached from each device. The IC card or the module is a computer system composed of a microprocessor, ROM, RAM, and the like. The IC card or the module may include the above-mentioned ultra-multifunctional LSI. When the microprocessor operates according to a computer program, the IC card or the module achieves its function. This IC card or this module may be tamper resistant.
(20) The present invention also relates to a computer-readable recording medium such as a flexible disk, a hard disk, a CD-ROM, a MO, a DVD, a DVD-ROM, a DVD-RAM, or a BD (Blu). -rayDisc), may be recorded on a semiconductor memory, etc. Further, it may be the digital signal recorded on these recording media.
Further, the present invention may transmit the computer program or the digital signal via a telecommunication line, a wireless or wired communication line, a network typified by the Internet, data broadcasting, or the like. Further, the present invention is a computer system including a microprocessor and a memory, in which the memory stores the computer program, and the microprocessor may operate according to the computer program.
Further, it is carried out by another independent computer system by recording and transferring the program or the digital signal on the recording medium, or by transferring the program or the digital signal via the network or the like. May be. (21) It may be a combination of these embodiments and modifications.
In the data dark decoding method according to the present invention, when the data is dark-decrypted, it is confirmed whether the data dark decoding function unit holds the key, and if it is held, the data is darkened without switching the execution environment. Perform decryption processing. Furthermore, in the case of a malicious application program, the key held by the data decryption function unit is deleted, and the data is decrypted in a secure execution environment until the malicious application program no longer exists. It has the effect of preventing leakage and reducing the number of times of switching to a safe execution environment. Therefore, it is particularly effective in the field of equipment that performs high-speed data dark decoding.
1 Information processing system 10 Server device 20 networks 100, 100b, 100c, 100d, 100e, 100f Information processing equipment 101, 101e system LSI 102 Non-volatile storage 103 Memory section 104 Dedicated memory section 105 system bus 120, 120b, 120f Execution environment 121, 121c Execution environment 126 Normal dark decoding unit 127 Normal operation unit 128, 128d, 128e, 128f Normal key table 129 Load function section 133 Permit list 134 Protected dark decoder 135 Protective operation unit 136, 136d, 136e, 136f Protective key table 141 CPU 142 Peripheral circuit 143 Mode switching unit 144 Internal protection memory 145 Internal bus 146 Private bus 147 General purpose register 148 Control register 149 Buffer area 150 control register 151 Buffer area 152 Secure Operating System 153 Dynamic tamper detection function unit 154 Secure boot section 155 Protected data manipulation unit 157 General purpose operating system 158 Application Program A 159 Application program B 160 Data dark decoding function 160f Data dark decoding function 205 Intermediate language machine 206 Intermediate Language Application Program 218 Intermediate language load function 237 Protected key table update section 265 clock 266 Leased line 297 Decrypted data storage position table
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10916969B2 | Cited by | United States of America | Applicant |
| US10096881B2 | Cited by | United States of America | Applicant |
| US10777873B2 | Cited by | United States of America | Applicant |
| US9871282B2 | Cited by | United States of America | Applicant |
| US10341142B2 | Cited by | United States of America | Applicant |
| US10784670B2 | Cited by | United States of America | Applicant |
| US9893795B1 | Cited by | United States of America | Applicant |
| US9800327B2 | Cited by | United States of America | Applicant |
| US10446936B2 | Cited by | United States of America | Applicant |
| US10291334B2 | Cited by | United States of America | Applicant |
| US10135146B2 | Cited by | United States of America | Applicant |
| US10139820B2 | Cited by | United States of America | Applicant |
| US9906269B2 | Cited by | United States of America | Applicant |
| US10027398B2 | Cited by | United States of America | Applicant |
| US9912419B1 | Cited by | United States of America | Applicant |
| US10225842B2 | Cited by | United States of America | Applicant |
| US10341142B2 | Cited by | United States of America | Applicant |
| US10535928B2 | Cited by | United States of America | Applicant |
| US10136434B2 | Cited by | United States of America | Applicant |
| US9876570B2 | Cited by | United States of America | Applicant |
| US10051483B2 | Cited by | United States of America | Applicant |
| US9917341B2 | Cited by | United States of America | Applicant |
| US10009065B2 | Cited by | United States of America | Applicant |
| US9998932B2 | Cited by | United States of America | Applicant |
| US9788326B2 | Cited by | United States of America | Applicant |
| US10020587B2 | Cited by | United States of America | Applicant |
| US9866309B2 | Cited by | United States of America | Applicant |
| US9608692B2 | Cited by | United States of America | Applicant |
| US9912033B2 | Cited by | United States of America | Applicant |
| US9948333B2 | Cited by | United States of America | Applicant |
| US10168695B2 | Cited by | United States of America | Applicant |
| US10051629B2 | Cited by | United States of America | Applicant |
| US9749083B2 | Cited by | United States of America | Applicant |
| US10205655B2 | Cited by | United States of America | Applicant |
| US9628854B2 | Cited by | United States of America | Applicant |
| US10090594B2 | Cited by | United States of America | Applicant |
| US10051630B2 | Cited by | United States of America | Applicant |
| US10243784B2 | Cited by | United States of America | Applicant |
| US10009067B2 | Cited by | United States of America | Applicant |
| US9705610B2 | Cited by | United States of America | Applicant |
| US9935703B2 | Cited by | United States of America | Applicant |
| US10348391B2 | Cited by | United States of America | Applicant |
| US10298293B2 | Cited by | United States of America | Applicant |
| US9860075B1 | Cited by | United States of America | Applicant |
| US10142086B2 | Cited by | United States of America | Applicant |
| US9887447B2 | Cited by | United States of America | Applicant |
| US9866276B2 | Cited by | United States of America | Applicant |
| US10142010B2 | Cited by | United States of America | Applicant |
| US9838078B2 | Cited by | United States of America | Applicant |
| US9762289B2 | Cited by | United States of America | Applicant |
| US9967002B2 | Cited by | United States of America | Applicant |
| US10755542B2 | Cited by | United States of America | Applicant |
| US10665942B2 | Cited by | United States of America | Applicant |
| US10938108B2 | Cited by | United States of America | Applicant |
| US10074886B2 | Cited by | United States of America | Applicant |
| US9627768B2 | Cited by | United States of America | Applicant |
| US9998870B1 | Cited by | United States of America | Applicant |
| US9912027B2 | Cited by | United States of America | Applicant |
| US10090601B2 | Cited by | United States of America | Applicant |
| US9871283B2 | Cited by | United States of America | Applicant |
| US10224981B2 | Cited by | United States of America | Applicant |
| US10411356B2 | Cited by | United States of America | Applicant |
| US9853342B2 | Cited by | United States of America | Applicant |
| US10305190B2 | Cited by | United States of America | Applicant |
| US10103422B2 | Cited by | United States of America | Applicant |
| US10382976B2 | Cited by | United States of America | Applicant |
| US10349418B2 | Cited by | United States of America | Applicant |
| US10320586B2 | Cited by | United States of America | Applicant |
| US9667317B2 | Cited by | United States of America | Applicant |
| US9768833B2 | Cited by | United States of America | Applicant |
| US10389037B2 | Cited by | United States of America | Applicant |
| US9973940B1 | Cited by | United States of America | Applicant |
| US10359749B2 | Cited by | United States of America | Applicant |
| US9847566B2 | Cited by | United States of America | Applicant |
| US10044409B2 | Cited by | United States of America | Applicant |
| US9780834B2 | Cited by | United States of America | Applicant |
| US9876264B2 | Cited by | United States of America | Applicant |
| US9882277B2 | Cited by | United States of America | Applicant |
| US10326689B2 | Cited by | United States of America | Applicant |
| US9912382B2 | Cited by | United States of America | Applicant |
| US9729197B2 | Cited by | United States of America | Applicant |
| US9742462B2 | Cited by | United States of America | Applicant |
| US9674711B2 | Cited by | United States of America | Applicant |
| US10074890B2 | Cited by | United States of America | Applicant |
| US10819035B2 | Cited by | United States of America | Applicant |
| US10361489B2 | Cited by | United States of America | Applicant |
| US10811767B2 | Cited by | United States of America | Applicant |
| US10355367B2 | Cited by | United States of America | Applicant |
| US10154493B2 | Cited by | United States of America | Applicant |
| US9787412B2 | Cited by | United States of America | Applicant |
| US9755697B2 | Cited by | United States of America | Applicant |
| US9973299B2 | Cited by | United States of America | Applicant |
| US9871558B2 | Cited by | United States of America | Applicant |
| US10326494B2 | Cited by | United States of America | Applicant |
| US10530505B2 | Cited by | United States of America | Applicant |
| US9948355B2 | Cited by | United States of America | Applicant |
| US9929755B2 | Cited by | United States of America | Applicant |
| US10027397B2 | Cited by | United States of America | Applicant |
| US10727599B2 | Cited by | United States of America | Applicant |
| US9912381B2 | Cited by | United States of America | Applicant |
4 members in 2 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 2009002479 | Japan | A | |
| 2009002479 | Japan | A | |
| 2009002479 | Japan | – | |
| 2010001120 | Japan | A | |
| 200920092479 | – | – | – |
| JP20090002479 | – | – | – |
| JP20100001120 | – | – | – |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| US2010174919A1 | United States of America | A1 | |
| JP2010182296A | Japan | A | |
| US8555089B2 | United States of America | B2 | |
| JP5475475B2This record | Japan | B2 |
10 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5475475
- Publication, DOCDB
- 5475475
- Publication, EPODOC
- JP5475475B
- Application
- 1120
- Application, DOCDB
- 2010001120
- Application, EPODOC
- JP20100001120
Titles2
- English
- Program execution device, control method, control program and integrated circuit
- Japanese
- プログラム実行装置、制御方法、制御プログラム及び集積回路
Classification
- CPC, 3
- G06F21/554
- G06F21/62
- G06F21/74
- IPC, 7
- G06F21 12
- G06F21 14
- G06F21 62
- G06F21 64
- H04L9 08
- G06F21 57
- G06F21 60