Security device and method for information processing apparatus
Claim Score by NHIP
Abstract
Security data such as a password is stored as backup in flash memory in a PC, and even if someone removes a coin battery for CMOS backup from the PC, the removal is detected and the data backed up in the flash memory is reset in the CMOS. This feature strengthens the prevention of data theft from recording media such as HDDs due to unauthorized use or access of PCs.

Term
Term ended
Projected expiry passed 28 November 2025, 0.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
2 claims: 2 independent, 0 dependent
- 1A security device for an information processing apparatus, the security device comprising:a first recording medium which is installed in the information processing apparatus and which stores legitimate security data entered at a time of starting the information processing apparatus;a second recording medium which is installed in the information processing apparatus and which stores the legitimate security data;and a detection means for detecting that the legitimate security data stored in the first recording medium has been one of being erased and damaged, wherein when the detection means has detected that the legitimate security data stored in the first recording medium has been one of being erased and damaged, the legitimate security data stored in the second recording medium is stored in the first recording medium.
- 2Broadest claimClaim Score 85, broad(NHIP)A security method for an information processing apparatus provided with a plurality of recording media, the security method comprising:detecting that legitimate security data stored in a first recording medium has been one of being erased and damaged;and upon detection that the legitimate security data stored in the first recording medium has been one of being erased and damaged, storing the legitimate security data stored in a second recording medium in the first recording medium.
Independent claims2
36 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
00011. Field of the Invention
0002The present invention relates to a security device and method for an information processing apparatus such as a personal computer.
00032. Background Art
0004In recent years, portable information processing apparatus such as laptop personal computers (hereinafter, PCs) have been in widespread use. In return for the convenience of portability, however, a large number of theft cases of these devices as well as of information stored in them have been occurring, and this has become a social issue. In order to address this problem, as is well known, recent PCs are provided with a security function. For example, a PC can be protected from unauthorized use by not activating the OS (Operating System) unless a password is entered and verified, thereby preventing the PC from starting. An information processing apparatus with a structure of this kind is disclosed in Japanese Patent Unexamined Publication No. 10-105432.
0005When a user accesses individual information in a PC, it is common that the validity of the password is checked. However, it can be understood with a certain level of knowledge about PCs where in the PC the password consisting of a certain number of alphanumeric characters is stored. Therefore, there are probably a lot of people who know that a PC can be started without entering any password only by clearing the data in the region for storing a password, which will be described later. This fact indicates that the provision of a password-checking step cannot reduce the risk for this system to be broken, thereby making it impossible to effectively protect individual information from unauthorized access.
0006For security, most laptop PCs are designed not to start unless a correct password is entered. <figref idref="DRAWINGS">FIG. 3B</figref> shows an entry screen for a BIOS password, which is required for a program called BIOS (Basic Input/Output System). When a BIOS password (hereinafter, referred to simply as “password”) is set, it is impossible even to load data from the hard disk without entering this password, thereby indicating the strength of the security.
0007When setting a password, a BIOS setup menu is called up. <figref idref="DRAWINGS">FIG. 3A</figref> shows a BIOS password setting screen. The set content is stored in a CMOS region called the “south bridge” in the LSI, and maintained by a backup battery after the power is off, so that the password data is never erased. Therefore, with this password set on the BIOS, it is difficult to start the PC without entering this password.
0008However, this conventional structure is not sufficient for the security of PCs because of the following reasons.
0009If a backup battery mounted on the PC motherboard is temporarily removed, and the electric charge remaining on the motherboard is discharged by short-circuiting the printed board pattern, then the password and other security function settings stored in the CMOS are all cleared. The removed backup battery can be put back onto the motherboard to restore at least the factory default BIOS settings. Since the set password has been cleared, the PC can be started without entering any password. In this manner, data stored in the HDD (Hard Disk Drive) in a PC may be taken without authorization.
SUMMARY OF THE INVENTION
0010The present invention provides a security device for an information processing apparatus, the security device comprising: a first recording medium which is installed in the information processing apparatus and which stores legitimate security data entered at a time of starting the information processing apparatus; a second recording medium which is installed in the information processing apparatus and which stores the legitimate security data; and a detection means for detecting that the legitimate security data stored in the first recording medium has been one of being erased and damaged, wherein when the detection means has detected that the legitimate security data stored in the first recording medium has been one of being erased and damaged, the legitimate security data stored in the second recording medium is stored in the first recording medium.
0011The present invention also provides a security method for an information processing apparatus provided with a plurality of recording media, the security method comprising: detecting that legitimate security data stored in a first recording medium has been one of being erased and damaged; and upon detection that the legitimate security data stored in the first recording medium has been one of being erased and damaged, storing the legitimate security data stored in a second recording medium in the first recording medium.
0012According to the present invention, security data such as a password is stored as backup in flash memory in a PC, and even if someone removes a coin battery for CMOS backup from the PC, the removal is detected and the backup information about the security data such as the password stored in the flash memory is reset in the CMOS. This feature strengthens the prevention of data theft from recording media such as HDDs due to unauthorized use or access of PCs.
BRIEF DESCRIPTION OF THE DRAWINGS
0013<figref idref="DRAWINGS">FIG. 1</figref> is a view to show a general PC hardware structure according to a first embodiment of the present invention.
0014<figref idref="DRAWINGS">FIG. 2</figref> is a flowchart depicting a security method for an information processing apparatus according to the first embodiment of the present invention.
0015<figref idref="DRAWINGS">FIG. 3A</figref> is a view to show a BIOS password setting screen.
0016<figref idref="DRAWINGS">FIG. 3B</figref> is a BIOS password entry screen.
DETAILED DESCRIPTION OF PREFERRED EMBODIMENT
0017An embodiment of the present invention will be described as follows with reference to accompanying drawing. It should be noted that the present invention is not limited to the embodiment.
Embodiment
0018In <figref idref="DRAWINGS">FIG. 1</figref>, motherboard <b>101</b> is a part on which to fix or mount main components of a PC. North bridge <b>103</b> and south bridge <b>104</b> constitute what is commonly called a chip set. North bridge <b>103</b> controls data flow between CPU (Central Processing Unit) <b>102</b>, memory and a graphic chip. South bridge <b>104</b> controls data flow between ATA (IDE) interface <b>105</b> connecting HDD <b>106</b> and CD/DVD drive <b>107</b>, the interface of a keyboard and mouse, expansion cards (PCI slots such as a LAN card or sound card) and other interfaces. Nonvolatile flash memory <b>108</b> contains a program which is called the BIOS to control peripherals such as HDD <b>106</b>, CD/DVD <b>107</b> and FDD (Floppy Disk Drive unillustrated) connected to the PC. The set content of the BIOS can be modified by the user pushing a predetermined button to call up a setup menu immediately after the starting of the PC. The set content is stored in CMOS <b>109</b> which is in the CMOS region of south bridge <b>104</b>, and maintained even after the power is turned off because it is backed up by coil battery <b>110</b>.
0019Flash memory <b>108</b> is a nonvolatile semiconductor memory which can read data as well as erase and rewrite data in a predetermined sequence, and can also maintain data even after the power is turned off.
0020The following is a description about the operation of a security device for the PC thus structured. The password is stored in CMOS <b>109</b> and maintained even after the PC is shut down because coin battery <b>110</b> backs up CMOS <b>109</b>. However, if someone removes the coin battery <b>110</b> temporarily from motherboard <b>101</b> and short-circuits the printed circuit pattern, then the password stored in CMOS <b>109</b> is erased because the function to back up CMOS <b>109</b> is lost. This problem is avoided by the following procedure.
0021(1) The BIOS is programmed in such a manner that when the user calls up the setup menu to set a password, backup region <b>111</b> is separately secured in flash memory <b>108</b> where the BIOS itself is stored, and data which is important in terms of security such as a password is stored in backup region <b>111</b>.
0022(2) The BIOS is programmed in such a manner that if someone removes coin battery <b>110</b> for CMOS-data backup from the PC, the CMOS data is checked at the starting of the PC so as to detect the removal of coin battery <b>110</b> by checksum or other method. A checksum, which is an error detection scheme, is obtained by dividing data into blocks and taking the sum of numerical values of the data in these blocks. The calculated checksum is stored with the data. When the stored data is read out, a checksum is also calculated from the data stream to check whether it coincides with the checksum read out. If they are different, then that means the read data has an error, indicating that the coin battery <b>110</b> has been removed from the PC. It goes without saying that not only the removal of the battery from the PC, but also drain and deterioration of the battery are detected as well.
0023(3) The BIOS is programmed in such a manner that when the removal of coin battery <b>110</b> is detected by the checking of the CMOS data by the checksum, the password data separately stored in backup region <b>111</b> of flash memory <b>108</b> is reset in CMOS <b>109</b> so as to restore the data.
0024(4) The BIOS is programmed in such a manner that data which is important in terms of security besides a password is read from backup region <b>111</b> of flash memory <b>108</b>, and the damaged or erased security data is reset in CMOS <b>109</b> so as to restore the data.
0025The following is a description about a security method for an information processing apparatus of the present invention with reference to <figref idref="DRAWINGS">FIG. 2</figref>.
0026The BIOS is programmed to proceed as follows. When the PC is started from a shutdown/hibernation state (S<b>10</b>), it is determined whether a password has been set or not (S<b>11</b>). When a password has been set, the user is prompted to enter the password (S<b>20</b>). The password is checked for validity and when the password is determined to be valid, the PC starts normally so as to start the OS (S<b>21</b>).
0027On the other hand, when it is determined that no password has been set (S<b>11</b>), it is determined whether the coin battery has been removed or not from the checking results of CMOS <b>109</b> (S<b>12</b>).
0028When it is determined that the coin battery has been removed from the PC (S<b>12</b>), the password backed up in flash memory <b>108</b> is reset in CMOS <b>109</b> (S<b>13</b>). The other backup information is also reset in CMOS <b>109</b> (S<b>14</b>) to restart the PC (S<b>17</b>). Since the password has been restored at this point in time, entering the password (S<b>20</b>) can make the PC start normally (S<b>21</b>).
0029In contrast, when it is determined that the coin battery has not been removed (S<b>12</b>), the PC is determined to be in the factory default state and the user is allowed to set the CMOS at Step (S<b>15</b>). The CMOS setting is done by the user with the BIOS setup utility so as to efficiently perform the collective setting of CMOS data when he/she begins to use the PC. In the setting, as shown by the arrow of <figref idref="DRAWINGS">FIG. 2</figref>, flash memory <b>108</b> backs up the CMOS data which have been set collectively at the password setting (S<b>15</b>) and the security menu item setting (S<b>16</b>). After the security menu item setting at Step (S<b>16</b>) and the CMOS setting are over, the user restarts the PC (S<b>17</b>) to use it.
0030The security menu item setting (S<b>16</b>) includes an HDD protection function. This is a function to prevent the data stored in the HDD from being read out when the HDD alone is removed and attached to another PC. The user can choose the setting between enabled and disenabled in the security menu.
0031For example, as shown in the bottom line of <figref idref="DRAWINGS">FIG. 3A</figref>, when Hard Disk<b>1</b> Password is made Enabled, the password entry unit is displayed on the next line. Then, setting and entering a HDD password in the password entry unit makes it impossible to read the data stored in the HDD with an invalid password when the HDD is attached to another PC.
0032The BIOS also has a retry number setting function to set the number of password faults allowed. When an invalid password is entered over this number, the PC is forcibly powered off. The BIOS also has a data erase function for self protection to erase programs or data in the HDD when an invalid password is entered more than the number of password faults allowed. The setting between enabled and disabled of the data erasing function and the retry number setting function are included in the security menu item setting (S<b>16</b>).
0033As described hereinbefore, the security device and method for an information processing apparatus of the present invention have the following features.
0034Security data such as a password is stored as backup in flash memory in a PC, and even if someone removes a coin battery for CMOS backup from the PC, the removal is detected and the backup information about the password and other security data stored in the flash memory is reset in the CMOS. This feature strengthens the prevention of data theft from recording media such as HDDs due to unauthorized use or access of PCs.
0035Therefore, the security device and method for an information processing apparatus of the present invention can be used for various information processing apparatus including PCs.
Contents4
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11537757B2 | Cited by | United States of America | Search report |
| US11126237B2 | Cited by | United States of America | Search report |
| CN107704772A | Cited by | China | Search report |
| US8800023B2 | Cited by | United States of America | Search report |
| US11402885B2 | Cited by | United States of America | Applicant |
| US2012036574A1 | Cited by | United States of America | Pre-grant |
| US2018373900A1 | Cited by | United States of America | Search report |
| US2021373631A1 | Cited by | United States of America | Search report |
| US2018373900A1 | Cited by | United States of America | Search report |
| US2005154782A1 | Cites | United States of America | Pre-grant |
| US2006200679A1 | Cites | United States of America | Pre-grant |
| US5736932A | Cites | United States of America | Pre-grant |
| US5748084A | Cites | United States of America | Pre-grant |
| US5799145A | Cites | United States of America | Pre-grant |
| US5821654A | Cites | United States of America | Pre-grant |
| US5892906A | Cites | United States of America | Pre-grant |
| US6333684B1 | Cites | United States of America | Pre-grant |
| US6370647B1 | Cites | United States of America | Pre-grant |
| US7103909B1 | Cites | United States of America | Pre-grant |
| US7210166B2 | Cites | United States of America | Pre-grant |
2 members in 2 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 2005170634 | Japan | – | |
| 2005170634 | Japan | A | |
| 2005170634 | Japan | A | |
| 2005170634 | – | – | – |
| JP20050170634 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| US2006282902A1 | United States of America | A1 | |
| JP2006344113A | Japan | A |
43 transactions on the USPTO file
Abandoned after 2 non-final rejections, 1 final rejection and 1 appeal.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Mail Express Abandonment (During Examination)AbandonedMABN3 | MABN3 | |
| Express Abandonment (during Examination)AbandonedABN3 | ABN3 | |
| Mail Supplemental Non-Final ActionMSRNF | MSRNF | |
| Letter of Express Abandonment FiledAbandonedEABN | EABN | |
| Supplemental Non-Final ActionSRNF | SRNF | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Mail Appeals conf. Reopen Prosec.MAPCR | MAPCR | |
| Pre-Appeals Conference Decision - Reopen ProsecutionAPCR | APCR | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Is Now CompleteCOMP | COMP | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Request for Foreign Priority (Priority Papers May Be Included)RQPR | RQPR | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Initial Exam Team nnIEXX | IEXX |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationEXPRESSLY ABANDONED -- DURING EXAMINATIONSTCB | STCB | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 20060282902
- Publication, DOCDB
- 2006282902
- Publication, EPODOC
- US2006282902
- Application
- 11287782
- Application, DOCDB
- 28778205
- Application, EPODOC
- US20050287782
Titles
- English
- Security device and method for information processing apparatus
Classification
- CPC, 3
- G06F21/31
- G06F21/554
- G06F21/575
- IPC, 4
- H04N7 16
- G06F1 00
- G06F12 14
- G06F21 62
- USPC, 1
- 726026000