IP Library › Granted Patent US 11,681,809
Granted Patent B2
US 11,681,809 · App. 16/383,252 · Granted Jun 20, 2023

Information processing apparatus, control method, and storage medium

Inventor: Akira Ishikawa (Kawasaki, JP)
Assignee: Canon Kabushiki Kaisha
G06F21/572G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,681,809
App. No.
16/383,252
Granted
Jun 20, 2023
Kind
B2
Abstract

An information processing apparatus includes a first verification unit configured to perform hardware verification of the hardware by using a hardware verification unit, and if the hardware verification is successful, performs a software verification of software stored in a storage unit. If both verifications are successful and a particular function is executed, a second verification unit performs software verification of a program stored in the storage unit. And, if one or both of the verifications is unsuccessful, a restriction unit restricts use of the information processing apparatus.

Claims (74)

1. An information processing apparatus comprising:

a memory; and

a processor in communication with the memory and configured to perform operations including:

performing, as a hardware verification, at least a verification of a startup program stored in read only memory,

storing a plurality of programs that includes a plurality of control programs and a plurality of function programs, wherein the plurality of control programs includes at least a kernel and a loader, and the plurality of function programs includes at least an application program,

displaying a screen for receiving a first setting of whether to perform verification at startup for performing verification when the information processing apparatus is started up and a second setting of whether to perform verification at execution for performing verification when the plurality of function programs are executed,

performing control so that the second setting of the verification at execution is receivable via the screen in a case where the verification at startup is set via the screen, and performing control so that the second setting of the verification at execution is not received via the screen in a case where the verification at startup is not set via the screen,

receiving, via the screen, (i) the first setting of performing the verification at startup and the second setting of not performing the verification at execution, or (ii) the first setting of performing the verification at startup and the second setting of performing the verification at execution,

performing, in the case where the verification at startup is set via the screen, a first verification process including the verification of the startup program by using the hardware verification, and performing, in a case where the verification of the startup program is successful, a software verification by the first verification process of the stored plurality of control programs and the stored plurality of function programs stored in the storage unit,

restricting use of the information processing apparatus in a case where a verification by the first verification process fails,

performing, in a case where the verification at execution is set via the screen, a second verification process after the verification by the first verification process succeeds and startup of the information processing apparatus is completed, wherein, in a case where a particular function is executed, the second verification process is a process of verifying one or more function programs of the plurality of function programs based on the executed particular function, and

restricting use of at least a function program for executing the particular function in a case where a verification by the second verification process fails,

wherein the second verification process is not executed in the case where the verification by the first verification process fails or in a case where the startup of the information processing apparatus is not completed.

2. The information processing apparatus according to claim 1 ,

wherein, the case where the verification by the second verification process fails, restricting use of at least the function program includes disabling use of at least the function program for executing the particular function, and

wherein, when the use of the function program for executing the particular function is disabled, a notification to notify that tampering has been detected is displayed on a notification screen of the information processing apparatus.

3. The information processing apparatus according to claim 1 ,

wherein the first verification process is performed when electric power is supplied to the information processing apparatus and the startup of the information processing apparatus is initiated, and

wherein the second verification process is performed when an instruction to execute the particular function of the information processing apparatus is issued.

4. The information processing apparatus according to claim 1 ,

wherein, in the software verification by the first verification process, the software verification is performed on the plurality of programs sequentially on a program-by-program basis in a program start order, and

wherein, when the software verification fails for any one of the plurality of programs, use of the information processing apparatus is restricted.

5. The information processing apparatus according to claim 4 , wherein, in the software verification by the first verification process, for a control program included in the plurality of control programs to be started next, a hash value is calculated and is compared with a hash value associated with a control program included in the plurality of control programs verified immediately before.

6. The information processing apparatus according to claim 1 , wherein, in the software verification by the second verification process, a hash value is calculated for each of the one or more function programs of the plurality of function programs corresponding to the particular function which is selected by a user, and the calculated hash value is compared with a hash value included in a list of second hash values stored for use by the second verification process.

7. The information processing apparatus according to claim 6 ,

wherein, in a case where the software verification by the second verification process fails, restricting use of the information processing apparatus includes determining whether a function program which failed the second verification process is a known function program, and

wherein, in a case where it is determined that the function program which failed the second verification process is not a known function program, restricting use of the information processing apparatus includes not restricting use of the information processing apparatus but notifying that executing of an unknown function program has been restricted.

8. The information processing apparatus according to claim 1 , wherein the startup program verified by the hardware verification unit is a Basic Input/Output System (BIOS).

9. The information processing apparatus according to claim 8 ,

wherein a loader load-and-verify program is included in the BIOS, and the loader load-and-verify program includes a public key corresponding to a process of verifying the loader and a signature assigned to the loader, and

wherein the BIOS also includes a process of loading the stored loader and starting the loaded loader.

10. The information processing apparatus according to claim 1 , wherein the read only memory and the processor are connected by a bus which is internal to an integrated circuit and not accessible outside of the integrated circuit.

11. The information processing apparatus according to claim 1 , further comprising:

an operation unit;

a printer unit; and

a scanner unit,

wherein the plurality of function programs includes at least a copy function, a scanning function, and a printing function.

12. A method for controlling an information processing apparatus, the method comprising:

performing, as a hardware verification, at least a verification of a startup program stored in read only memory;

storing a plurality of programs that includes a plurality of control programs and a plurality of function programs, wherein the plurality of control programs includes at least a kernel and a loader, and the plurality of function programs includes at least an application program;

displaying a screen for receiving a first setting of whether to perform verification at startup for performing verification when the information processing apparatus is started up and a second setting of whether to perform verification at execution for performing verification when the plurality of function programs are executed;

performing control so that the second setting of the verification at execution is receivable via the screen in a case where the verification at startup is set via the screen, and performing control so that the second setting of the verification at execution is not received via the screen in a case where the verification at startup is not set via the screen;

receiving, via the screen, (i) the first setting of performing the verification at startup and the second setting of not performing the verification at execution, or (ii) the first setting of performing the verification at startup and the second setting of performing the verification at execution;

performing, in the case where the verification at startup is set via the screen, a first verification process including the verification of the startup program by using the hardware verification, and performing, in a case where the verification of the startup program is successful, a software verification by the first verification process of the stored plurality of control programs and the stored plurality of function programs;

restricting use of the information processing apparatus in a case where a verification by the first verification process fails;

performing, in a case where the verification at execution is set via the screen, a second verification process after the verification by the first verification process succeeds and startup of the information processing apparatus is completed, wherein, in a case where a particular function is executed, the second verification process is a process of verifying one or more function programs of the plurality of function programs based on the executed particular function; and

restricting use of at least a function program for executing the particular function in a case where a verification by the second verification process fails,

wherein the second verification process is not executed in the case where the verification by the first verification process fails or in a case where the startup of the information processing apparatus is not completed.

13. The method according to claim 12 ,

wherein, in the case where the verification by the second verification process fails, restricting use of at least the function program includes disabling use of at least the function program for executing the particular function, and

wherein, when the use of the function program for executing the particular function is disabled, a notification to notify that tampering has been detected is displayed on a notification screen of the information processing apparatus.

14. The method according to claim 12 ,

wherein the first verification process is performed when electric power is supplied to the information processing apparatus and the startup of the information processing apparatus is initiated, and

wherein the second verification process is performed when an instruction to execute the particular function of the information processing apparatus is issued.

15. The method according to claim 12 ,

wherein, in the software verification by the first verification process, the software verification is performed on the plurality of programs sequentially on a program-by-program basis in a program start order, and

wherein, when the software verification fails for any one of the plurality of programs, use of the information processing apparatus is restricted.

16. The method according to claim 15 , wherein, in the software verification by the first verification process, for a control program included in the plurality of control programs to be started next, a hash value is calculated and is compared with a hash value associated with a control program included in the plurality of control programs verified immediately before.

17. The method according to claim 12 , wherein, in the software verification by the second verification process, a hash value is calculated for each of the one or more function programs of the plurality of function programs corresponding to the particular function which is selected by a user, and the calculated hash value is compared with a hash value included in a list of second hash values stored for use by the second verification process.

18. The method according to claim 17 ,

wherein, in a case where the software verification by the second verification process fails, restricting use of the information processing apparatus includes determining whether a function program which failed the second verification process is a known function program, and

wherein, in a case where it is determined that the function program which failed the second verification process is not a known function program, restricting use of the information processing apparatus includes not restricting use of the information processing apparatus but notifying that executing of an unknown function program has been restricted.

19. The method according to claim 12 , wherein the startup program verified by the hardware verification is a Basic Input/Output System (BIOS).

20. A non-transitory computer-readable storage medium storing a program to cause a computer to perform a method for controlling an information processing apparatus, the method comprising:

performing, as a hardware verification, at least a verification of a startup program stored in read only memory;

storing a plurality of programs that includes a plurality of control programs and a plurality of function programs, wherein the plurality of control programs includes at least a kernel and a loader, and the plurality of function programs includes at least an application program;

displaying a screen for receiving a first setting of whether to perform verification at startup for performing verification when the information processing apparatus is started up and a second setting of whether to perform verification at execution for performing verification when the plurality of function programs are executed;

performing control so that the second setting of the verification at execution is receivable via the screen in a case where the verification at startup is set via the screen, and performing control so that the second setting of the verification at execution is not received via the screen in a case where the verification at startup is not set via the screen;

receiving, via the screen, (i) the first setting of performing the verification at startup and the second setting of not performing the verification at execution, or (ii) the first setting of performing the verification at startup and the second setting of performing the verification at execution;

performing, in the case where the verification at startup is set via the screen, a first verification process including the verification of the startup program by using the hardware verification, and performing, in a case where the verification of the startup program is successful, a software verification by the first verification process of the stored plurality of control programs and the stored plurality of function programs;

restricting use of the information processing apparatus in a case where a verification by the first verification process fails;

performing, in a case where the verification at execution is set via the screen, a second verification process after the verification by the first verification process succeeds and startup of the information processing apparatus is completed, wherein, in a case where a particular function is executed, the second verification process is a process of verifying one or more function programs of the plurality of function programs based on the executed particular function; and

restricting use of at least a function program for executing the particular function in a case where a verification by the second verification process fails,

wherein the second verification process is not executed in the case where the verification by the first verification process fails or in a case where the startup of the information processing apparatus is not completed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 4, 2019
From: ISHIKAWA, AKIRA
To: CANON KABUSHIKI KAISHA
Reel/Frame 049679/0306 →
Priority Claims (1)
JP JP2018-080775 · Apr 19, 2018 · national
Continuity (1)
Related Publication 20190325138A1 · Oct 24, 2019
Cited By (1)
US 12,585,776