DATA PROCESSING TERMINAL, CONFIDENTIAL DATA ACCESS CONTROL METHOD, PROGRAM, STORAGE MEDIUM, AND INTEGRATED CIRCUIT
    1.
    发明公开
    DATA PROCESSING TERMINAL, CONFIDENTIAL DATA ACCESS CONTROL METHOD, PROGRAM, STORAGE MEDIUM, AND INTEGRATED CIRCUIT 有权
    数据处理终端,方法控制访问机密数据存储设备和集成电路

    公开(公告)号:EP2549402A1

    公开(公告)日:2013-01-23

    申请号:EP11755810.6

    申请日:2011-02-09

    IPC分类号: G06F21/24

    摘要: An information processing terminal (101) includes: a storage area (206), in which general information (211) and confidential information (210) are recorded; an input/output receiving unit (201) which receives an access command to general information (211) or confidential information (210); a route information holding unit (203) in which route information is held, the route information indicating an area of activity in which access to the confidential information (210) is allowed; a current location acquisition unit (304) which acquires current location information indicating the current location of the information processing terminal (101); an access determination unit (305) which allows access to the confidential information (210) when the location of the information processing terminal (101) indicated by the current location information is in the route information; and a confidential information access unit (306) which accesses the confidential information (210) in response to the access allowance by the access determination unit (305).

    摘要翻译: 一种信息处理终端(101)包括:被记录在哪个一般信息的存储区域(206)(211)和机密信息(210); 输入/输出接收单元(201),其接收命令,以访问的一般信息(211)或机密信息(210); 在哪条路线的信息的路径信息保持单元(203)被保持,路径信息指示活动的区域,其中访问该机密信息(210)被允许; 当前位置获取单元(304),其取得当前的位置信息,其指示所述信息处理终端(101)的当前位置; 访问判定部(305),其允许访问机密信息(210)当由当前位置信息所表示的信息处理终端(101)的位置是在路径信息; 和其访问响应于所述访问允许由接入判定部(305)的保密信息(210)保密信息的访问单元(306)。

    HEALTHCARE SYSTEM
    2.
    发明公开
    HEALTHCARE SYSTEM 审中-公开
    KRANKENPFLEGESYSTEM

    公开(公告)号:EP2416522A1

    公开(公告)日:2012-02-08

    申请号:EP10761384.6

    申请日:2010-03-30

    摘要: A measurement device (11) measures vital data, encrypts the vital data using an encryption key to generate encrypted vital data, and generates, from a decryption key of the vital data, two pairs of a first share FSD and a second share SSD which enable reproduction of the decryption key. The measurement device (11) generates an encrypted second share by encrypting the second share SSD. The measurement device (11) transmits the encrypted vital data, the first share FSD, the encrypted second share to a server device (15) via an intermediate device (13).

    摘要翻译: 测量装置(11)测量重要数据,使用加密密钥对重要数据进行加密以产生加密的重要数据,并从重要数据的解密密钥生成两对第一共享FSD和第二共享SSD, 再现解密密钥。 测量装置(11)通过加密第二共享SSD生成加密的第二共享。 测量装置(11)经由中间装置(13)将加密的重要数据,第一共享FSD,加密的第二共享传送到服务器装置(15)。

    INFORMATION PROCESSING DEVICE
    3.
    发明公开
    INFORMATION PROCESSING DEVICE 审中-公开
    INFORMATIONSVERARBEITUNGSEINRICHTUNG

    公开(公告)号:EP2261832A1

    公开(公告)日:2010-12-15

    申请号:EP09713679.0

    申请日:2009-02-23

    IPC分类号: G06F21/22

    CPC分类号: G06F21/575

    摘要: A terminal having a plurality of virtual machines in one-to-one correspondence with a plurality of stakeholders is enabled to activate in compliance with the trust dependency relation among the virtual machines and a virtual machine monitor. The terminal includes: the plurality of virtual machines in one-to-one correspondence with the plurality of stakeholders; a plurality of tamper-resistant modules in one-to-one correspondence with the virtual machines, and a management unit controlling the virtual machines and the tamper-resistant modules in mutually related manner. Each virtual machine securely boots with reference to a certificate having a trust dependency with one or other virtual machines.

    摘要翻译: 具有与多个利益相关者一一对应的多个虚拟机的终端能够根据虚拟机和虚拟机监视器之间的信任依赖关系来激活。 所述终端包括:所述多个虚拟机与所述多个利益相关者一一对应; 与虚拟机一一对应的多个防篡改模块,以及以相互关联的方式控制虚拟机和防篡改模块的管理单元。 参考具有与一个或其他虚拟机的信任依赖关系的证书,每个虚拟机都将安​​全启动。

    SECURE BOOT TERMINAL, SECURE BOOT METHOD, SECURE BOOT PROGRAM, RECORDING MEDIUM, AND INTEGRATED CIRCUIT
    5.
    发明公开
    SECURE BOOT TERMINAL, SECURE BOOT METHOD, SECURE BOOT PROGRAM, RECORDING MEDIUM, AND INTEGRATED CIRCUIT 审中-公开
    具有安全启动,安全启动方法,安全启动程序的记录介质及集成电路TERMINAL

    公开(公告)号:EP2196936A1

    公开(公告)日:2010-06-16

    申请号:EP08835878.3

    申请日:2008-09-30

    IPC分类号: G06F21/22 G06F9/445

    CPC分类号: G06F21/575

    摘要: A terminal that performs secure boot processing when booting, thereby booting reliably even if, during updating of a software module, the power is cut off or the update is otherwise interrupted. The terminal comprises a CPU, a software module storage unit, a certificate storage unit, an updating unit for updating the software module and certificate, a security device provided with a configuration information storage unit for storing the configuration information of the software module, an alternate configuration information storage unit for storing the configuration information of a software module in the configuration before the update, and a boot control unit for verifying and executing the software module by using the certificate. The terminal verifies the certificate of the software module by comparing the configuration information stored by the configuration information storage unit with the configuration information stored by the alternate configuration information storage unit.

    摘要翻译: 终末确实执行安全启动处理启动时,启动从而可靠地就算了,一个软件模块的更新期间,电源被切断或更新,否则中断。 该终端包括一个CPU,一个软件模块存储单元,证书存储单元,备用的更新单元,用于更新所述软件模块和证书,用于存储所述软件模块的配置信息设置有配置信息存储单元中的安全设备,以 为更新之前存储的软件模块中的配置的配置信息的配置信息存储单元,以及用于核实和通过使用证书执行的软件模块的引导控制单元。 该终端通过比较由所述配置信息存储单元与由备用配置信息存储部所存储的配置信息存储在配置信息来验证软件模组的证书。

    INFORMATION PROCESSING DEVICE AND INFORMATION PROCESSING METHOD
    7.
    发明公开

    公开(公告)号:EP2650809A1

    公开(公告)日:2013-10-16

    申请号:EP11847025.1

    申请日:2011-11-29

    IPC分类号: G06F21/00

    CPC分类号: G06F21/52 G06F21/56

    摘要: To improve the responsiveness of a system call process without compromising safety, an information processing device (100A) according to the present invention includes: an application identification unit (1511) configured to identify a program being executed in the information processing device, by acquiring the application identifier; a caller identification unit (1523) configured to identify a caller indicating a portion of the program from which a program code is called when the identified program calls the program code; a checked-application management unit (1500) configured to manage a check result which is information including a result of previous check for safety of executing the identified program; and an attack check determination unit (1510) configured to determine, based on the identified caller and the check result, whether a check if the identified program is under attack is to be made.

    摘要翻译: 为了提高系统呼叫处理的响应性而不损害安全性,根据本发明的信息处理设备(100A)包括:应用识别单元(1511),被配置为通过获取所述信息处理设备中的正在执行的程序, 应用程序标识符 呼叫者识别单元(1523),被配置为当所识别的节目调用节目代码时,识别表示节目代码被调用的节目的一部分的呼叫者; 检查应用程序管理单元(1500),被配置为管理检查结果,所述检查结果是包括执行所识别的程序的安全性的先前检查结果的信息; 以及攻击检查确定单元,被配置为基于所识别的呼叫者和检查结果来确定是否检查所识别的程序是否受到攻击。

    INFORMATION PROCESSING DEVICE AND METHOD FOR PREVENTING UNAUTHORIZED APPLICATION COOPERATION
    8.
    发明公开
    INFORMATION PROCESSING DEVICE AND METHOD FOR PREVENTING UNAUTHORIZED APPLICATION COOPERATION 有权
    信息处理设备和防止未经授权的应用程序合作的方法

    公开(公告)号:EP2626803A1

    公开(公告)日:2013-08-14

    申请号:EP11830340.3

    申请日:2011-09-26

    IPC分类号: G06F21/00 G06F21/24

    摘要: An information processing terminal (40) includes: a network control unit (250); an installation control unit (260); a process control unit (200) for starting up an application and establishing cooperation among applications including the application; an access-history map updating unit (290) for updating an access-history map (281) which represents history information on an access relationship among the applications when a request is made to start up the application or to establish cooperation among the applications; and an unauthorized-cooperation-of-applications control unit (220) for (i) determining whether or not an unauthorized cooperation, which is directed at sensitive information kept secret, is established among the applications with reference to information obtained from the access-history map (281) and an application authorizing list (271), and (ii) controlling execution of the application using an application execution control technique in the case where a result of the determination shows that the unauthorized cooperation is established.

    摘要翻译: 一种信息处理终端(40)包括:网络控制单元(250); 一个安装控制单元(260); 过程控制单元(200),用于启动应用并建立包括所述应用的应用之间的协作; 访问历史地图更新单元(290),用于当请求启动应用程序或建立应用程序之间的协作时,更新表示关于应用程序之间的访问关系的历史信息的访问历史地图(281) 以及应用程序未授权控制单元(220),用于(i)参考从访问历史获得的信息确定在应用程序之间是否建立了针对保密的敏感信息的未授权协作 (281)和应用程序授权列表(271)中的至少一个,以及(ii)在确定的结果表明未授权协作已建立的情况下,使用应用程序执行控制技术来控制应用程序的执行。

    INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING METHOD, AND PROGRAM DISTRIBUTION SYSTEM
    9.
    发明公开
    INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING METHOD, AND PROGRAM DISTRIBUTION SYSTEM 有权
    信息资源管理系统,信息管理系统

    公开(公告)号:EP2568408A1

    公开(公告)日:2013-03-13

    申请号:EP11777373.9

    申请日:2011-04-19

    IPC分类号: G06F21/20 G06F21/22 G06F21/24

    摘要: Provided is an information processing device which is capable of preventing data leakage caused by a malicious application or malicious device driver and of allowing cooperation among virtual machines. The information processing device (110) includes: an external connection unit (1309) which connects to an external device; and a communication control unit which obtains data from a first virtual machine (1002), transmits the data to a second virtual machine (1003), and transmits, to the external connection unit, transmission completion information indicating that the data is already transmitted to the second virtual machine, wherein the external connection unit (i) determines, based on the transmission completion information, whether or not a virtual machine is the second virtual machine to which the data is already transmitted, when the external connection unit receives, from the virtual machine, a request for a connection to the external device, and (ii) permit a connection between the virtual machine and the external device, when the external connection unit determines that the virtual machine is not the second virtual machine to which the data is already transmitted.

    摘要翻译: 提供一种信息处理装置,其能够防止恶意应用或恶意设备驱动程序引起的数据泄漏并允许虚拟机之间的协作。 信息处理装置(110)包括:外部连接单元(1309),其连接到外部设备; 以及通信控制单元,其从第一虚拟机(1002)获取数据,将数据发送到第二虚拟机(1003),并向外部连接单元发送指示已经发送了数据的传输完成信息 第二虚拟机,其中,所述外部连接单元(i)基于所述传输完成信息,确定所述虚拟机是否是已经发送了所述数据的所述第二虚拟机,所述外部连接单元从所述虚拟机 机器,连接到外部设备的请求,以及(ii)当所述外部连接单元确定所述虚拟机不是所述数据已经到达的所述第二虚拟机时,允许所述虚拟机与所述外部设备之间的连接 传输。

    DETECTION DEVICE AND DETECTION SYSTEM
    10.
    发明公开
    DETECTION DEVICE AND DETECTION SYSTEM 审中-公开
    ERKENNUNGSVORRICHTUNG UND ERKENNUNGSSYSTEM

    公开(公告)号:EP2562548A1

    公开(公告)日:2013-02-27

    申请号:EP11771721.5

    申请日:2011-04-08

    IPC分类号: G01R11/24 G01R22/00

    CPC分类号: G01R22/066

    摘要: A detection apparatus (102) connected to a device in a residence and an electricity meter (100) indicating an amount of electric power consumed by the device in the residence, the detection apparatus (102) including: a reception unit (1021) which receives the amount of electric power from the electricity meter (100); a collection unit (1024) which collects usage status of the device; a device information holding unit (1027) which holds device information including the usage status of the device and electric power consumption of the device corresponding to the usage status; and a determination unit (1025) which determines whether or not the electricity meter (100) is tampered, by comparing an estimated electric power consumption amount with the amount of electric power received by the reception unit (1021), the estimated electric power consumption amount being estimated from the usage status of the device by using the device information, in which the determination unit (1025) determines that the electricity meter (100) is tampered, when a difference between the estimated electric power consumption amount and the amount of electric power received by the reception unit (1021) is equal to or more than a predetermined threshold.

    摘要翻译: 一种连接到住宅内的装置的检测装置(102)和表示该住宅内的装置消耗的电力量的电表(100),检测装置(102)包括:接收部(1021),其接收 来自电表(100)的电力量; 收集单元(1024),其收集所述设备的使用状态; 装置信息保持单元,其保存包括与使用状态对应的设备的使用状态和设备的电力消耗的设备信息; 以及确定单元(1025),其通过将所估计的电力消耗量与由所述接收单元(1021)接收的电力量进行比较来确定所述电表(100)是否被篡改,所述估计电力消耗量 通过使用确定单元(1025)确定电表(100)被篡改的设备信息从设备的使用状态估计出来,当估计电力消耗量与电力量之间的差异 由接收单元(1021)接收的信号等于或大于预定阈值。