IP Library › Granted Patent US 11,055,413
Granted Patent B2
US 11,055,413 · App. 16/155,950 · Granted Jul 6, 2021

Information processing apparatus, method, and storage medium to sequentially activate a plurality of modules after activation of a boot program

Inventor: Shota Shimizu (Kawasaki, JP)
Assignee: Canon Kabushiki Kaisha
G06F21/572G06F21/575H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,055,413
App. No.
16/155,950
Granted
Jul 6, 2021
Kind
B2
Abstract

The present information processing apparatus sequentially activates a plurality of modules after the activation of a boot program. Each module uses verification information for verifying a signature of the module to be activated next to detect alteration of the module that is next to be activated, and activates the module to be activated next in a case where verification of the signature succeeds. Furthermore, each module holds in advance the verification information and its own signature.

Claims (38)

1. A peripheral that has a printing function and is operable to sequentially activate a plurality of modules, implemented as software, after activation of a hoot program by an embedded controller of the peripheral, the peripheral comprising:

at least one processor; and

at least one memory coupled to the at least one processor and having stored thereon instructions which, when executed by the at least one processor, cause the at least one processor to function as

a detection unit to execute a verification process which uses verification information for verifying a signature of a module to be activated next to detect alteration of the module to be activated next, and

an activation unit to execute an activation process which activates the module to be activated next in a case where verification of the signature by the detection unit succeeds,

wherein the plurality of modules include at least a Basic Input/Output System (BIOS), a loader, a first kernel, and a first program, and the plurality of modules are activated in the following order: the BIOS, the loader, the first kernel, and the first program,

wherein each module holds in advance the verification information and its own signature, and

wherein peripheral holds at least a second kernel in addition to the first kernel as a spare, and executes, in a case where the second kernel is activated as a boot target, the verification process by the detection unit and the activation process by the activation unit.

2. The peripheral according to claim 1 , wherein

the embedded controller for executing the boot program:

comprises the detection unit and the activation unit, and

holds in advance the verification information.

3. The peripheral according to claim 1 , wherein the activation unit stops activation of the peripheral in a case where verification of a signature by the detection unit fails.

4. The peripheral according to claim 1 , wherein

the boot program and the BIOS are stored in a Read-Only Memory (ROM), the loader, the first kernel, and the first program are stored in a flash memory, and a second program to be activated next after the first program is stored in a Hard Disk Drive (HDD).

5. The peripheral according to claim 4 , wherein

the flash memory also stores the second program, and

in a case where verification of a signature by the detection unit for the second program stored in the HDD fails, the activation unit of a module that activates the second program redeploys the second program stored in the flash memory to the HDD, and activates the second program.

6. The peripheral according to claim 1 , wherein

the activation unit replaces and activates a module to be activated next in accordance with a user input,

each module holds in advance verification information for each of a plurality of modules that can be activated next, and its own signature.

7. The peripheral according to claim 1 ,

further comprising a main controller that controls each module,

wherein the embedded controller has a memory and a processor separate from the main controller.

8. A method of controlling a peripheral that has a printing function and is operable to sequentially activate a plurality of modules, implemented as software, after activation of a boot program by an embedded controller of the peripheral, wherein

each module of the plurality of modules can perform:

a verification process using verification information for verifying a signature of a module to be activated next to detect alteration of the module to be activated next, and

an activation process for activating the module to be activated next when verification of the signature succeeds, and

wherein the plurality of modules includes at least a Basic Input/Output System (BIOS), a loader, a first kernel, and a first program, and the plurality of modules are activated in the following order: the (BIOS), the loader, the first kernel, and the first program,

wherein each module holds in advance the verification information and its own signature, and

wherein the peripheral holds at least a second kernel in addition to the first kernel as a spare, and executes, in a case where the second kernel is activated as a boot target, the verification process for verifying and the activation process for activating.

9. A non-transitory computer-readable storage medium storing a computer program for causing a computer to execute each step of a method of controlling a peripheral that has a printing function and is operable to sequentially, activate a plurality of modules, implemented as software, after activation of a boot program by an embedded controller of the peripheral, wherein

each module of the plurality of modules can perform:

a verification process using verification information for verifying a signature of a module to be activated next to detect alteration of the module to be activated next, and

an activation process for activating the module to be activated next when verification of the signature succeeds, and

wherein the plurality of modules includes at least a Basic Input/Output System (BIOS), a loader, a first kernel, and a first program, and the plurality of modules are activated in the following order: the BIOS, the loader, the first kernel, and the first program,

wherein each module holds in advance the verification information and its own signature, and

wherein the peripheral holds at least a second kernel in addition to the first kernel as a spare, and executes, in a case where the second kernel is activated as a boot target, the verification process for verifying and the activation process for activating.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2019
From: SHIMIZU, SHOTA
To: CANON KABUSHIKI KAISHA
Reel/Frame 047910/0997 →
Priority Claims (1)
JP JP2017-201956 · Oct 18, 2017 · national
Continuity (1)
Related Publication 20190114429A1 · Apr 18, 2019
Cited By (1)
US 12,204,633