Information processing apparatus, control method, and storage medium
An information processing apparatus includes a first verification unit configured to perform hardware verification of the hardware by using a hardware verification unit, and if the hardware verification is successful, performs a software verification of software stored in a storage unit. If both verifications are successful and a particular function is executed, a second verification unit performs software verification of a program stored in the storage unit. And, if one or both of the verifications is unsuccessful, a restriction unit restricts use of the information processing apparatus.
1. An information processing apparatus comprising:
a memory; and
a processor in communication with the memory and configured to perform operations including:
performing, as a hardware verification, at least a verification of a startup program stored in read only memory,
storing a plurality of programs that includes a plurality of control programs and a plurality of function programs, wherein the plurality of control programs includes at least a kernel and a loader, and the plurality of function programs includes at least an application program,
displaying a screen for receiving a first setting of whether to perform verification at startup for performing verification when the information processing apparatus is started up and a second setting of whether to perform verification at execution for performing verification when the plurality of function programs are executed,
performing control so that the second setting of the verification at execution is receivable via the screen in a case where the verification at startup is set via the screen, and performing control so that the second setting of the verification at execution is not received via the screen in a case where the verification at startup is not set via the screen,
receiving, via the screen, (i) the first setting of performing the verification at startup and the second setting of not performing the verification at execution, or (ii) the first setting of performing the verification at startup and the second setting of performing the verification at execution,
performing, in the case where the verification at startup is set via the screen, a first verification process including the verification of the startup program by using the hardware verification, and performing, in a case where the verification of the startup program is successful, a software verification by the first verification process of the stored plurality of control programs and the stored plurality of function programs stored in the storage unit,
restricting use of the information processing apparatus in a case where a verification by the first verification process fails,
performing, in a case where the verification at execution is set via the screen, a second verification process after the verification by the first verification process succeeds and startup of the information processing apparatus is completed, wherein, in a case where a particular function is executed, the second verification process is a process of verifying one or more function programs of the plurality of function programs based on the executed particular function, and
restricting use of at least a function program for executing the particular function in a case where a verification by the second verification process fails,
wherein the second verification process is not executed in the case where the verification by the first verification process fails or in a case where the startup of the information processing apparatus is not completed.
2. The information processing apparatus according to claim 1 ,
wherein, the case where the verification by the second verification process fails, restricting use of at least the function program includes disabling use of at least the function program for executing the particular function, and
wherein, when the use of the function program for executing the particular function is disabled, a notification to notify that tampering has been detected is displayed on a notification screen of the information processing apparatus.
3. The information processing apparatus according to claim 1 ,
wherein the first verification process is performed when electric power is supplied to the information processing apparatus and the startup of the information processing apparatus is initiated, and
wherein the second verification process is performed when an instruction to execute the particular function of the information processing apparatus is issued.
4. The information processing apparatus according to claim 1 ,
wherein, in the software verification by the first verification process, the software verification is performed on the plurality of programs sequentially on a program-by-program basis in a program start order, and
wherein, when the software verification fails for any one of the plurality of programs, use of the information processing apparatus is restricted.
5. The information processing apparatus according to claim 4 , wherein, in the software verification by the first verification process, for a control program included in the plurality of control programs to be started next, a hash value is calculated and is compared with a hash value associated with a control program included in the plurality of control programs verified immediately before.
6. The information processing apparatus according to claim 1 , wherein, in the software verification by the second verification process, a hash value is calculated for each of the one or more function programs of the plurality of function programs corresponding to the particular function which is selected by a user, and the calculated hash value is compared with a hash value included in a list of second hash values stored for use by the second verification process.
7. The information processing apparatus according to claim 6 ,
wherein, in a case where the software verification by the second verification process fails, restricting use of the information processing apparatus includes determining whether a function program which failed the second verification process is a known function program, and
wherein, in a case where it is determined that the function program which failed the second verification process is not a known function program, restricting use of the information processing apparatus includes not restricting use of the information processing apparatus but notifying that executing of an unknown function program has been restricted.
8. The information processing apparatus according to claim 1 , wherein the startup program verified by the hardware verification unit is a Basic Input/Output System (BIOS).
9. The information processing apparatus according to claim 8 ,
wherein a loader load-and-verify program is included in the BIOS, and the loader load-and-verify program includes a public key corresponding to a process of verifying the loader and a signature assigned to the loader, and
wherein the BIOS also includes a process of loading the stored loader and starting the loaded loader.
10. The information processing apparatus according to claim 1 , wherein the read only memory and the processor are connected by a bus which is internal to an integrated circuit and not accessible outside of the integrated circuit.
11. The information processing apparatus according to claim 1 , further comprising:
an operation unit;
a printer unit; and
a scanner unit,
wherein the plurality of function programs includes at least a copy function, a scanning function, and a printing function.
12. A method for controlling an information processing apparatus, the method comprising:
performing, as a hardware verification, at least a verification of a startup program stored in read only memory;
storing a plurality of programs that includes a plurality of control programs and a plurality of function programs, wherein the plurality of control programs includes at least a kernel and a loader, and the plurality of function programs includes at least an application program;
displaying a screen for receiving a first setting of whether to perform verification at startup for performing verification when the information processing apparatus is started up and a second setting of whether to perform verification at execution for performing verification when the plurality of function programs are executed;
performing control so that the second setting of the verification at execution is receivable via the screen in a case where the verification at startup is set via the screen, and performing control so that the second setting of the verification at execution is not received via the screen in a case where the verification at startup is not set via the screen;
receiving, via the screen, (i) the first setting of performing the verification at startup and the second setting of not performing the verification at execution, or (ii) the first setting of performing the verification at startup and the second setting of performing the verification at execution;
performing, in the case where the verification at startup is set via the screen, a first verification process including the verification of the startup program by using the hardware verification, and performing, in a case where the verification of the startup program is successful, a software verification by the first verification process of the stored plurality of control programs and the stored plurality of function programs;
restricting use of the information processing apparatus in a case where a verification by the first verification process fails;
performing, in a case where the verification at execution is set via the screen, a second verification process after the verification by the first verification process succeeds and startup of the information processing apparatus is completed, wherein, in a case where a particular function is executed, the second verification process is a process of verifying one or more function programs of the plurality of function programs based on the executed particular function; and
restricting use of at least a function program for executing the particular function in a case where a verification by the second verification process fails,
wherein the second verification process is not executed in the case where the verification by the first verification process fails or in a case where the startup of the information processing apparatus is not completed.
13. The method according to claim 12 ,
wherein, in the case where the verification by the second verification process fails, restricting use of at least the function program includes disabling use of at least the function program for executing the particular function, and
wherein, when the use of the function program for executing the particular function is disabled, a notification to notify that tampering has been detected is displayed on a notification screen of the information processing apparatus.
14. The method according to claim 12 ,
wherein the first verification process is performed when electric power is supplied to the information processing apparatus and the startup of the information processing apparatus is initiated, and
wherein the second verification process is performed when an instruction to execute the particular function of the information processing apparatus is issued.
15. The method according to claim 12 ,
wherein, in the software verification by the first verification process, the software verification is performed on the plurality of programs sequentially on a program-by-program basis in a program start order, and
wherein, when the software verification fails for any one of the plurality of programs, use of the information processing apparatus is restricted.
16. The method according to claim 15 , wherein, in the software verification by the first verification process, for a control program included in the plurality of control programs to be started next, a hash value is calculated and is compared with a hash value associated with a control program included in the plurality of control programs verified immediately before.
17. The method according to claim 12 , wherein, in the software verification by the second verification process, a hash value is calculated for each of the one or more function programs of the plurality of function programs corresponding to the particular function which is selected by a user, and the calculated hash value is compared with a hash value included in a list of second hash values stored for use by the second verification process.
18. The method according to claim 17 ,
wherein, in a case where the software verification by the second verification process fails, restricting use of the information processing apparatus includes determining whether a function program which failed the second verification process is a known function program, and
wherein, in a case where it is determined that the function program which failed the second verification process is not a known function program, restricting use of the information processing apparatus includes not restricting use of the information processing apparatus but notifying that executing of an unknown function program has been restricted.
19. The method according to claim 12 , wherein the startup program verified by the hardware verification is a Basic Input/Output System (BIOS).
20. A non-transitory computer-readable storage medium storing a program to cause a computer to perform a method for controlling an information processing apparatus, the method comprising:
performing, as a hardware verification, at least a verification of a startup program stored in read only memory;
storing a plurality of programs that includes a plurality of control programs and a plurality of function programs, wherein the plurality of control programs includes at least a kernel and a loader, and the plurality of function programs includes at least an application program;
displaying a screen for receiving a first setting of whether to perform verification at startup for performing verification when the information processing apparatus is started up and a second setting of whether to perform verification at execution for performing verification when the plurality of function programs are executed;
performing control so that the second setting of the verification at execution is receivable via the screen in a case where the verification at startup is set via the screen, and performing control so that the second setting of the verification at execution is not received via the screen in a case where the verification at startup is not set via the screen;
receiving, via the screen, (i) the first setting of performing the verification at startup and the second setting of not performing the verification at execution, or (ii) the first setting of performing the verification at startup and the second setting of performing the verification at execution;
performing, in the case where the verification at startup is set via the screen, a first verification process including the verification of the startup program by using the hardware verification, and performing, in a case where the verification of the startup program is successful, a software verification by the first verification process of the stored plurality of control programs and the stored plurality of function programs;
restricting use of the information processing apparatus in a case where a verification by the first verification process fails;
performing, in a case where the verification at execution is set via the screen, a second verification process after the verification by the first verification process succeeds and startup of the information processing apparatus is completed, wherein, in a case where a particular function is executed, the second verification process is a process of verifying one or more function programs of the plurality of function programs based on the executed particular function; and
restricting use of at least a function program for executing the particular function in a case where a verification by the second verification process fails,
wherein the second verification process is not executed in the case where the verification by the first verification process fails or in a case where the startup of the information processing apparatus is not completed.