TWI499317B - A secure removable card and a mobile wireless communication device - Google Patents

A secure removable card and a mobile wireless communication device Download PDF

Info

Publication number
TWI499317B
TWI499317B TW099130297A TW99130297A TWI499317B TW I499317 B TWI499317 B TW I499317B TW 099130297 A TW099130297 A TW 099130297A TW 99130297 A TW99130297 A TW 99130297A TW I499317 B TWI499317 B TW I499317B
Authority
TW
Taiwan
Prior art keywords
internet
user data
memory
network
card
Prior art date
Application number
TW099130297A
Other languages
Chinese (zh)
Other versions
TW201212664A (en
Inventor
Bing Yeh
Original Assignee
Greenliant Llc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Greenliant Llc filed Critical Greenliant Llc
Priority to TW099130297A priority Critical patent/TWI499317B/en
Publication of TW201212664A publication Critical patent/TW201212664A/en
Application granted granted Critical
Publication of TWI499317B publication Critical patent/TWI499317B/en

Links

Landscapes

  • Telephonic Communication Services (AREA)
  • Telephone Function (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

安全可移除式卡片及行動無線通訊裝置Secure removable card and mobile wireless communication device 技術領域Technical field

本發明有關於一安全可移除式卡片,其具有一處理器及一非依電性記憶體且適於一行動無線通訊裝置用來連接至互連電腦網路的一網路「網際網路」),其中該非依電性記憶體儲存組配成被處理器執行的程式碼及使用者資料。可移除式卡片具有一處理器及帶有兩部分的一記憶體,其中該處理器限制使用者存取第一部分,而允許使用者存取第二部分以儲存使用者資料。然而,由於網路運營商(network carrier provider)會存取這兩部分且可將第二部分中的使用者資料儲存在網際網路上作為備份,故必須使第二部分中的使用者資料安全,即便網路運營商也不能獲取。The invention relates to a secure removable card having a processor and a non-electrical memory and adapted for a mobile wireless communication device to be connected to a network "internet" of an interconnected computer network The non-electrical memory storage group is configured as a code and user data to be executed by the processor. The removable card has a processor and a memory with two parts, wherein the processor restricts the user from accessing the first portion and allows the user to access the second portion to store user data. However, since the network carrier provider accesses the two parts and can store the user data in the second part on the Internet as a backup, the user data in the second part must be secured. Even network operators can't get it.

發明背景Background of the invention

行動無線通訊裝置,諸如手機,在技術中是習知的。通常,一手機具有一可移除式卡片(稱為「SIM卡片」),該可移除式卡片由均安裝於其上的一處理器(帶有RAM、ROM或EEPROM或快閃記憶體)、I/O墊片、及安全監控電路組成。SIM卡片中的非依電性記憶體係用以儲存進接行動運行商的網路需要的資訊。因而,卡片可儲存資訊,諸如電話號碼、存取碼、分鐘數目、呼叫計劃等等。Mobile wireless communication devices, such as cell phones, are well known in the art. Typically, a mobile phone has a removable card (called a "SIM card") that is attached to a processor (with RAM, ROM or EEPROM or flash memory) , I / O gaskets, and safety monitoring circuits. The non-electrical memory system in the SIM card is used to store information needed to access the mobile operator's network. Thus, the card can store information such as phone numbers, access codes, number of minutes, call plans, and the like.

互連電腦網路的一網路(「網際網路」)在技術中亦是習知的。網際網路可被具有一直接連接(有線或無線)的電腦進 接或透過一公用載波(common carrier)無線網路進接。A network ("Internet") that interconnects computer networks is also well known in the art. The Internet can be accessed by a computer with a direct connection (wired or wireless) Connected through or through a common carrier wireless network.

隨著行動網路(諸如3G網路)速度的增長,行動無線裝置的使用者期望經由他們的行動無線通訊裝置來進接網際網路。儘管行動網路的速度在增加,但使用此網路的成本亦可隨較大量使用公用載波網路而增加,特別是在進接網際網路時。As the speed of mobile networks (such as 3G networks) grows, users of mobile wireless devices desire to enter the Internet via their mobile wireless communication devices. Although the speed of mobile networks is increasing, the cost of using this network can also increase with the use of a larger number of public carrier networks, especially when entering the Internet.

因此,期望提供一種機制,藉此機制使用者透過行動網路進接網際網路的體驗不降低,但同時提供手段減小透過行動網路進接網際網路的成本。此外,由於儲存容量的成本繼續日益降低,使用者將把有價值資訊(包括個人及私有資訊)儲存於此類可攜式裝置中。由於行動裝置可進接網際網路,公用載波服務提供商可提供在網際網路上對該資料備份之服務。因而,期望保全儲存於此可攜式行動裝置中的資料。此外,即使公用載波提供商不提供網際網路資料備份服務,使用者仍期望可保全資料,因為可攜式行動裝置可易於丟失或被盜。Therefore, it is desirable to provide a mechanism whereby the user's experience of accessing the Internet through the mobile network is not reduced, but at the same time providing means to reduce the cost of accessing the Internet through the mobile network. In addition, as the cost of storage capacity continues to decrease, users will store valuable information (including personal and private information) in such portable devices. Since the mobile device can access the Internet, the public carrier service provider can provide a backup service for this data on the Internet. Therefore, it is desirable to preserve the data stored in the portable mobile device. In addition, even if the public carrier provider does not provide the Internet data backup service, the user still expects to preserve the data because the portable mobile device can be easily lost or stolen.

因此,期望使用者提供的資料被安全儲存於此一行動裝置中。Therefore, it is expected that the data provided by the user is safely stored in this mobile device.

發明概要Summary of invention

因此,在本發明中,一可移除式卡片具有用以連接至一行動無線通訊裝置的電氣連接,該行動無線通訊裝置供一使用者使用以進接一公用載波網路來進接互連電腦網路的一網路(「網際網路」)。卡片包含一處理器及連接至該處 理器的一非依電性記憶體。該非依電性記憶體具有兩部分:一第一部分與一第二部分。第一部分可被公用載波網路提供商存取,處理器限制使用者對第一部分的存取。第二部分可被公用載波網路提供商存取,及處理器允許使用者存取第二部分以在其內儲存使用者資料。最後,可移除式卡片具有邏輯電路,其用來編碼使用者資料以產生經加密使用者資料供儲存於第二部分中。Accordingly, in the present invention, a removable card has an electrical connection for connection to a mobile wireless communication device for use by a user to access a common carrier network for interconnection A network of computer networks ("Internet"). The card contains a processor and is connected to the location A non-electrical memory of the processor. The non-electrical memory has two parts: a first part and a second part. The first portion is accessible by the public carrier network provider, which limits the user's access to the first portion. The second portion is accessible by the public carrier network provider, and the processor allows the user to access the second portion to store user data therein. Finally, the removable card has logic circuitry for encoding user data to generate encrypted user data for storage in the second portion.

本發明亦有關於一行動無線通訊裝置,其供一使用者使用以進接一公用載波網路來進接互連電腦網路的一網路(「網際網路」)。該裝置包含一收發器,其用以經由一無線公用載波網路來無線通訊。該裝置進一步具有一第一處理器,其用以控制裝置的通訊以連接至該公用載波網路。該裝置進一步具有一第二處理器及連接至該第二處理器的一非依電性記憶體。該非依電性記憶體具有兩部分:一第一部分及一第二部分。該第一部分可被公用載波網路提供商存取,第二處理器限制使用者對第一部分的存取。該第二部分可被公用載波網路提供商存取,及第二處理器允許使用者存取第二部分以在其內儲存使用者資料。最後,裝置具有一邏輯電路,該邏輯電路用來編碼使用者資料以產生加密使用者資料供儲存於第二部分中。The present invention also relates to a mobile wireless communication device for use by a user to access a public carrier network to access a network ("Internet") interconnecting the computer network. The device includes a transceiver for wirelessly communicating via a wireless common carrier network. The apparatus further has a first processor for controlling communication of the device to connect to the common carrier network. The device further has a second processor and a non-electrical memory connected to the second processor. The non-electrical memory has two parts: a first part and a second part. The first portion is accessible by a public carrier network provider and the second processor limits user access to the first portion. The second portion is accessible by the public carrier network provider, and the second processor allows the user to access the second portion to store user data therein. Finally, the device has a logic circuit for encoding user data to generate encrypted user data for storage in the second portion.

圖式簡單說明Simple illustration

第1圖是連接至本發明行動無線通訊裝置以供連接至一行動網路及網際網路之本發明可移除式卡片的一圖。1 is a diagram of a removable card of the present invention connected to a mobile wireless communication device of the present invention for connection to a mobile network and the Internet.

第2圖是連接至本發明行動無線通訊裝置之本發明可 移除式卡片的一示意圖。Figure 2 is a diagram of the present invention connected to the mobile wireless communication device of the present invention. A schematic diagram of a removable card.

第3圖是本發明可移除式卡片的一方塊層面圖電路圖。Figure 3 is a block diagram circuit diagram of the removable card of the present invention.

第4圖是本發明可移除式卡片之處理器部分的一詳細電路圖。Figure 4 is a detailed circuit diagram of the processor portion of the removable card of the present invention.

第5圖是行動無線通訊裝置用本發明可移除式卡片與網際網路通訊之兩模式的一圖,其中在第一模式中,可移除式卡片透過無線通訊裝置與行動網路無線通訊以進接網際網路,及其中在一第二模式中,可移除式卡片連接至一網路入口裝置以連接至網際網路。Figure 5 is a diagram of two modes of the mobile wireless communication device using the removable card and the Internet communication of the present invention, wherein in the first mode, the removable card wirelessly communicates with the mobile network through the wireless communication device To access the Internet, and in a second mode, the removable card is connected to a network entry device to connect to the Internet.

第6圖是本發明之具有安全特徵的可移除式卡片的一方塊層面圖。Figure 6 is a block diagram of a removable card having security features of the present invention.

較佳實施例之詳細說明Detailed description of the preferred embodiment

參考第1圖,其繪示了在一公眾可接入(公用載波)無線通訊網路(諸如包括蜂巢進接塔120之一蜂巢網路110)中使用之一行動無線通訊裝置100(例如,一手機100)的一圖形說明。蜂巢網路110透過位於手機塔120上或附近的進接伺服器(未繪示)可連接至互連電腦網路的一網路150,亦稱為網際網路150。因而,在手機網路110上手機100可與其它手機100無線通訊。此外,手機100可透過手機網路110與網際網路150無線通訊,手機網路110具有連接至網際網路150的進接伺服器。此外,如將在下文展示,手機100的可移除式卡片10部分亦可透過一網路入口裝置(諸如攜行電腦塢160)直接連接至網際網路150,該網路入口裝置連接至連接到網際網路150之一個人電腦。Referring to FIG. 1, a mobile wireless communication device 100 (eg, one) is used in a publicly accessible (common carrier) wireless communication network, such as a cellular network 110 including a cellular access tower 120. A graphical illustration of the mobile phone 100). The cellular network 110 is connectable to a network 150, also known as the Internet 150, of the interconnected computer network via an ad server (not shown) located on or near the tower 120. Thus, the handset 100 can communicate wirelessly with other handsets 100 on the handset network 110. In addition, the mobile phone 100 can wirelessly communicate with the Internet 150 via the mobile phone network 110, and the mobile phone network 110 has an incoming server connected to the Internet 150. In addition, as will be shown below, the removable card 10 portion of the handset 100 can also be directly connected to the Internet 150 via a network entry device (such as a carrying computer dock 160) that is connected to the connection. Go to one of the Internet 150 personal computers.

本發明的手機100具有一可移除式卡片10,十分類似於先前技術的可移除式SIM卡片。然而,如將看到,本發明的可移除式卡片10的特徵較先前技術的可移除式SIM卡片十分不同且經改進。The handset 100 of the present invention has a removable card 10 that is very similar to prior art removable SIM cards. However, as will be seen, the features of the removable card 10 of the present invention are quite different and improved over prior art removable SIM cards.

參考第2圖,其繪示了連接至本發明行動無線通訊裝置100之本發明可移除式卡片10的一示意圖。由於裝置100設計成在整個蜂巢網路110中無線運作,裝置100包含一天線102。一收發器104連接至天線102。收發器104將經調變信號發射至蜂巢網路110並自蜂巢網路110接收經調變信號。此類組件在技術中是習知的。所接收的信號可經解調變及接著轉換成數位信號並提供至一閘道106。閘道106亦可具有一NAT(網路位址轉換)電路。一NAT電路106將一私有IP位址轉換或映射至一公用IP位址的一或多個埠。如下文將討論,裝置100(透過可移除式卡片10)在其連接至網際網路150時可分配一公用位址(透過習知DHCP協定),且在運作為一本地伺服器使得裝置100不連接至網際網路150時可具有一私有位址。欲發射的數位信號被收發器104調變及轉換成適當的電磁頻率信號以供天線102傳輸。由於裝置100可進接網際網路150,亦提供一瀏覽器及媒體播放器112。瀏覽器及媒體播放器112以習知TCP/IP協定及HTTP協定與閘道106介面連接以提供及接收裝置100自網際網路150接收的數位信號,該數位信號可顯示於一顯示器108上。與瀏覽器及媒體播放器112相關聯的是一處理器(未繪示),其亦控制裝置100的收發器104及其它習知硬體電路以與網路110通訊。Referring to FIG. 2, a schematic diagram of a removable card 10 of the present invention coupled to the mobile wireless communications device 100 of the present invention is shown. Since the device 100 is designed to operate wirelessly throughout the cellular network 110, the device 100 includes an antenna 102. A transceiver 104 is coupled to the antenna 102. The transceiver 104 transmits the modulated signal to the cellular network 110 and receives the modulated signal from the cellular network 110. Such components are well known in the art. The received signal can be demodulated and then converted to a digital signal and provided to a gateway 106. Gate 106 can also have a NAT (Network Address Translation) circuit. A NAT circuit 106 translates or maps a private IP address to one or more ports of a public IP address. As will be discussed below, device 100 (via removable card 10) can be assigned a common address (via a conventional DHCP protocol) when it is connected to the Internet 150, and operates as a local server such that device 100 There may be a private address when not connected to the Internet 150. The digital signal to be transmitted is modulated by the transceiver 104 and converted to an appropriate electromagnetic frequency signal for transmission by the antenna 102. Since the device 100 can access the Internet 150, a browser and media player 112 is also provided. The browser and media player 112 interfaces with the gateway 106 in accordance with conventional TCP/IP protocols and HTTP protocols to provide and receive digital signals received by the device 100 from the Internet 150, which digital signals can be displayed on a display 108. Associated with the browser and media player 112 is a processor (not shown) that also controls the transceiver 104 of the device 100 and other conventional hardware circuitry to communicate with the network 110.

本發明的可移除式卡片10透過一習知USB介面114透過攜行電腦塢160連接至裝置100。USB介面114連接至閘道106。因此,透過攜行電腦塢160、透過USB介面114、透過閘道106及透過收發器104,來自可移除式卡片10的數位信號被提供至裝置100及自裝置100被提供至天線102。The removable card 10 of the present invention is coupled to the device 100 via a portable computer dock 160 via a conventional USB interface 114. The USB interface 114 is connected to the gateway 106. Therefore, the digital signal from the removable card 10 is provided to the device 100 and the self device 100 is provided to the antenna 102 through the portable computer dock 160, through the USB interface 114, through the gateway 106, and through the transceiver 104.

本發明的可移除式卡片10在第3圖中更詳細繪示。特別地,卡片10包含一主機控制器12,其透過一USB匯流排113與USB介面114介面連接。此外,主機控制器12透過一匯流排16連接至一記憶體控制器14。記憶體控制器14控制一NAND記憶體20及一PSRAM 22。記憶體控制器14控制NAND記憶體20及PSRAM 22的操作,在2007年6月28日公開案2007-0147115下公開的美國專利申請案序列號第11/637,420號中完整描述,並指派給本受讓人,其揭露全部併入本文以供參考。主機控制器12亦能可取捨地連接至一近距離無線通訊器(NFC)24。一NFC 24是一近距離RF電路,其允許極接近的無線通訊。因此,帶有NFC 24的裝置100可充當一「電子錢包」以供商業交易或識別目的,或作為對網際網路150的另一進接。當然,裝置100亦可經由其它形式的無線網路(諸如一Wi-Fi網路)與網際網路150無線連接。The removable card 10 of the present invention is shown in more detail in FIG. In particular, the card 10 includes a host controller 12 that interfaces with the USB interface 114 via a USB bus 113. In addition, the host controller 12 is coupled to a memory controller 14 via a busbar 16. The memory controller 14 controls a NAND memory 20 and a PSRAM 22. The memory controller 14 controls the operation of the NAND memory 20 and the PSRAM 22, which is fully described and assigned in U.S. Patent Application Serial No. 11/637,420, the entire disclosure of which is incorporated by reference. The present disclosure is hereby incorporated by reference in its entirety. The host controller 12 can also be removably connected to a proximity wireless communicator (NFC) 24. An NFC 24 is a close range RF circuit that allows for very close wireless communication. Thus, the device 100 with NFC 24 can act as an "electronic wallet" for commercial transactions or identification purposes, or as an alternative to the Internet 150. Of course, the device 100 can also be wirelessly connected to the Internet 150 via other forms of wireless networks, such as a Wi-Fi network.

參考第4圖,其繪示了主機控制器12的一詳細示意方塊圖。主機控制器12包含一高速匯流排50,一主機介面30附接至此高速匯流排50以連接至記憶體控制器14。主機介面30亦包含暫存器32以臨時保存供應至記憶體控制器14及來自記憶體控制器14的資料。主機控制器12亦包含一FIFO(先進先出)電路51,其連接至高速匯流排50。FIFO 51亦連接至一USB控制器電路54,USB控制器電路54連接至一PHY電路56(其是針對一USB埠的標準實體層介面。電路56包括墊片、電壓準位移位器及時鐘恢復電路。)以連接至USB匯流排113。一安全處理器,諸如一ARM SC-100處理器52亦連接至高速匯流排50。Referring to FIG. 4, a detailed schematic block diagram of the host controller 12 is shown. The host controller 12 includes a high speed bus bar 50 to which a host interface 30 is attached for connection to the memory controller 14. The host interface 30 also includes a scratchpad 32 to temporarily store data supplied to the memory controller 14 and from the memory controller 14. The host controller 12 also includes a FIFO (First In First Out) circuit 51 that is coupled to the high speed bus bar 50. The FIFO 51 is also coupled to a USB controller circuit 54, which is coupled to a PHY circuit 56 (which is a standard physical layer interface for a USB port). The circuit 56 includes a pad, a voltage level shifter, and a clock. Restore the circuit.) to connect to the USB bus 113. A secure processor, such as an ARM SC-100 processor 52, is also coupled to the high speed bus 50.

主機控制器12亦包含一RSA/AES/DES引擎60,其是ARM SC-100處理器52的一安全共處理器。引擎60透過一仲裁電路62連接至高速匯流排50。由於引擎60與處理器52可同時請求高速匯流排50的記憶體或其它資源,仲裁電路62仲裁存取匯流排50的同步請求。引擎60亦能存取一專用高速快取RAM,諸如SRAM 64。最後,一橋接電路68亦連接至高速匯流排50。橋接電路68亦連接至一較慢匯流排70。一計時器72、一時鐘產生器74、一電力管理電路76、一安全監控電路78、一UART 80、及一SPI電路82(串行周邊介面-一習知匯流排)連接至此較慢匯流排70。UART 80及SPI 82亦連接至一匯流排91,匯流排91是一ISO7816串行介面匯流排。它是電話與SIM卡片之間通常在先前技術手機中找到的一位元組導向的通用異步接收器/發射器(UART)介面。這種類型介面(使用UART)正用USB介面代替。因此,出現匯流排91只是為了向後相容。Host controller 12 also includes an RSA/AES/DES engine 60, which is a secure coprocessor of ARM SC-100 processor 52. The engine 60 is coupled to the high speed busbar 50 via an arbitration circuit 62. Since the engine 60 and the processor 52 can simultaneously request the memory or other resources of the high speed bus 50, the arbitration circuit 62 arbitrates the synchronization request for accessing the bus 50. The engine 60 can also access a dedicated high speed cache RAM, such as SRAM 64. Finally, a bridge circuit 68 is also coupled to the high speed bus bar 50. Bridge circuit 68 is also coupled to a slower busbar 70. A timer 72, a clock generator 74, a power management circuit 76, a security monitoring circuit 78, a UART 80, and an SPI circuit 82 (serial peripheral interface - a conventional bus) are connected to the slower bus 70. UART 80 and SPI 82 are also coupled to a busbar 91, which is an ISO7816 serial interface bus. It is a tuple-oriented universal asynchronous receiver/transmitter (UART) interface between a telephone and a SIM card that is commonly found in prior art handsets. This type of interface (using the UART) is being replaced with a USB interface. Therefore, the bus bar 91 appears only for backward compatibility.

行動無線通訊裝置的操作Operation of a mobile wireless communication device

本發明的行動無線通訊裝置100有許多操作模式。初始地,應指出的是,行動網路運營商(MNO)(蜂巢網路運營商110),分發各個可移除式卡片10,且亦具有連接至網際網路150的一伺服器200。MNO所分發之本發明可移除式卡片10中的每一個由MNO指派一唯一公用IP位址,該IP位址儲存於可移除式卡片10的非依電性記憶體部分中。唯一公用IP位址使裝置100指向MNO伺服器200。如在2007年6月28日公開案2007-0147115下公開的美國專利申請案序列號第11/637,420號中揭露,非依電性記憶體出現於植入控制器14內之NAND記憶體20及NOR記憶體中。無論如何,MNO指派及預儲存一唯一公用IP位址於可移除式卡片10的非依電性記憶體部分。非依電性記憶體可劃分成兩部分,第一部分220a與第二部分220b之間的劃分可改變。第一部分/第二部分的劃分可由可移除式卡片的MNO提供商來完成。第一部分220a可由控制收發器104及瀏覽器與媒體播放器112、以及控制裝置100的通訊的另一硬體電路之處理器存取。第二部分220b可由使用者可存取的可移除式卡片10中的處理器52存取。此外,處理器52控制一使用者對第一部分220a可具有的存取程度。無論如何,為欲討論的原因,MNO指派的唯一公用IP位址儲存於第一部分220a中,及處理器52禁止對第一部分的存取。然而,其它類型的資訊,諸如敏感使用者資訊(諸如使用者名字、信用卡、等等)亦可儲存於第一部分220a中及處理器52可允許使用者對這些類型資訊的受限制存取。The mobile wireless communication device 100 of the present invention has many modes of operation. Initially, it should be noted that a mobile network operator (MNO) (homic network operator 110) distributes each removable card 10 and also has a server 200 connected to the Internet 150. Each of the inventive removable cards 10 distributed by the MNO is assigned a unique public IP address by the MNO, which is stored in the non-electrical memory portion of the removable card 10. The unique public IP address causes device 100 to point to MNO server 200. A non-electrical memory appears in the NAND memory embedded in the controller 14 as disclosed in U.S. Patent Application Serial No. 11/637,420, the entire disclosure of which is incorporated by reference. 20 and NOR memory. In any event, the MNO assigns and pre-stores a unique public IP address to the non-electrical memory portion of the removable card 10. The non-electrical memory can be divided into two parts, and the division between the first part 220a and the second part 220b can be changed. The division of the first part/second part can be done by the MNO provider of the removable card. The first portion 220a can be accessed by a processor of another hardware circuit that controls the transceiver 104 and the browser to communicate with the media player 112 and the control device 100. The second portion 220b is accessible by the processor 52 in the removable card 10 accessible to the user. In addition, processor 52 controls the degree of access a user can have to first portion 220a. In any event, for the reasons to be discussed, the unique public IP address assigned by the MNO is stored in the first portion 220a, and the processor 52 prohibits access to the first portion. However, other types of information, such as sensitive user information (such as user names, credit cards, etc.) may also be stored in the first portion 220a and the processor 52 may allow the user to have restricted access to these types of information.

在本發明的可移除式卡片10分發給使用者,且使用者已把卡片10插入本發明裝置100中之後,使用者接著可使用裝置100來在蜂巢網路110上運作,如在先前技術中那樣進行。類似於先前技術,卡片10亦可使有關於裝置100的使用之資訊(諸如,電話號碼、存取碼、分鐘數目、呼叫計劃等等)儲存於卡片10之記憶體部分的第一部分220a(使用者受限)。顯然,把此類型資訊儲存於使用者受限制的部分是適當的,這樣使用者無法擁有不受限的存取。以此方式,可移除式卡片10當在蜂巢網路110使用時較先前技術的SIM卡片發揮相同作用。After the removable card 10 of the present invention is distributed to the user and the user has inserted the card 10 into the device 100 of the present invention, the user can then use the device 100 to operate on the cellular network 110, as in the prior art. Do that in the middle. Similar to the prior art, the card 10 can also store information about the use of the device 100 (such as phone number, access code, number of minutes, call plan, etc.) in the first portion 220a of the memory portion of the card 10 (using Limited). Obviously, it is appropriate to store this type of information in the restricted portion of the user so that the user cannot have unrestricted access. In this manner, the removable card 10 functions the same as the prior art SIM card when used in the cellular network 110.

在使用者試圖使用裝置100來進接網際網路150時可見本發明的發明特徵。至少有兩種可能的模式(第一模式或第二模式)來進接網際網路150。儲存於非依電性記憶體14中的程式化碼可致使處理器52在操作的第一模式抑或第二模式中進接網際網路150。The inventive features of the present invention are seen when a user attempts to use the device 100 to access the Internet 150. There are at least two possible modes (first mode or second mode) to access the Internet 150. The stylized code stored in the non-electrical memory 14 can cause the processor 52 to enter the Internet 150 in either the first mode of operation or the second mode.

在第一模式中,可移除式卡片10可透過裝置100透過蜂巢網路110進接網際網路150。如果那樣的話,裝置100透過塔120附近連接至蜂巢網路110的進接伺服器連接至網際網路150。當啟動時,進接伺服器(類似於一網際網路服務提供商(ISP))可在裝置100連接至網際網路150的會話期間將一動態IP位址指派給裝置100。在裝置100連接至網際網路150時此公用IP位址的動態指派在技術中是習知的且依據DHCP協定。可選擇地,如前討論,公用IP位址可預指派且儲存於可移除式卡片10中。裝置100的瀏覽器及媒體播放器112接著用來瀏覽或漫遊網際網路150。來自網際網路150的內容接著可被下載且保存於可移除式卡片10中,在卡片10的使用者受限制記憶體部分或使用者可存取部分。In the first mode, the removable card 10 can access the Internet 150 through the cellular network 110 via the device 100. In that case, device 100 is coupled to Internet 150 via an incoming server connected to cellular network 110 near tower 120. When activated, an incoming server (similar to an Internet Service Provider (ISP)) can assign a dynamic IP address to device 100 during a session in which device 100 is connected to Internet 150. The dynamic assignment of this public IP address when device 100 is connected to the Internet 150 is well known in the art and is in accordance with the DHCP protocol. Alternatively, as previously discussed, the public IP address can be pre-assigned and stored in the removable card 10. The browser and media player 112 of the device 100 is then used to browse or roam the Internet 150. The content from the Internet 150 can then be downloaded and saved in the removable card 10, in the restricted memory portion or user accessible portion of the user of the card 10.

為與網際網路安全通訊,卡片10之記憶體部分的使用者受限制部分可儲存一密鑰。主機控制器12的RSA/AES/DE引擎60可使用該密鑰來加密及/或解密至及來自網際網路150的通訊。密鑰可在當MNO初始分發可移除式卡片10時由其提供,或當裝置連接至網際網路150時可自連接至網際網路150的MNO伺服器200下載。In order to communicate securely with the Internet, a restricted portion of the memory portion of the card 10 can store a key. The RSA/AES/DE engine 60 of the host controller 12 can use the key to encrypt and/or decrypt communications to and from the Internet 150. The key may be provided by the MNO when it initially distributes the removable card 10, or may be downloaded from the MNO server 200 connected to the Internet 150 when the device is connected to the Internet 150.

經由無線網路110自網際網路150獲取的資訊可被保存於可移除式卡片10的使用者受限制部分中,其與一指派私有IP位址相關聯。私有IP位址可首先由MNO指派且在分發之前儲存於可移除式卡片中。可選擇地,私有IP位址可由連接至蜂巢網路120的進接伺服器指派。最後,私有位址可僅僅為由進接伺服器動態指派並接著被NAT電路106轉換成一私有IP位址之公用IP位址。在來自網際網路150的資訊被儲存於可移除式卡片10中之後,它可被瀏覽器及媒體播放器112獲取、並顯示於裝置100的顯示器108上(使用私有IP位址)。這類似於一內部網路的操作。因而,可移除式卡片10用來作為將儲存於其記憶體內的資料提供至瀏覽器及媒體播放器112之一本地(私有)伺服器來發揮作用。Information obtained from the Internet 150 via the wireless network 110 can be stored in a restricted portion of the user of the removable card 10 that is associated with an assigned private IP address. The private IP address may be first assigned by the MNO and stored in the removable card prior to distribution. Alternatively, the private IP address can be assigned by an ingress server connected to the cellular network 120. Finally, the private address may simply be a public IP address that is dynamically assigned by the incoming server and then converted by the NAT circuit 106 into a private IP address. After the information from the Internet 150 is stored in the removable card 10, it can be retrieved by the browser and media player 112 and displayed on the display 108 of the device 100 (using a private IP address). This is similar to the operation of an internal network. Thus, the removable card 10 functions to provide information stored in its memory to a local (private) server of the browser and media player 112.

當在一本地模式中瀏覽器112正存取時使用一「私有」IP位址是有利的,因為這比具有指派給裝置100的兩公用IP位址更經濟,該兩公用IP位址:當漫遊或瀏覽網際網路150時一IP位址用於裝置100的電話部分,及當檢視可移除式卡片10的內容時另一公用IP位址用於可移除式卡片10。由於儲存於可移除式卡片10中的內容是針對使用裝置100的使用者,沒有必要使可移除式卡片10具有一公用IP位址。此外,在使用者正檢視儲存於可移除式卡片10中的內容時,裝置100可不連接至網際網路150。It is advantageous to use a "private" IP address when the browser 112 is accessing in a local mode, as this is more economical than having two public IP addresses assigned to the device 100: Roaming or browsing the Internet 150 is used for the telephone portion of the device 100, and another public IP address is used for the removable card 10 when viewing the contents of the removable card 10. Since the content stored in the removable card 10 is for the user using the device 100, it is not necessary to have the removable card 10 have a public IP address. Further, the device 100 may not be connected to the Internet 150 while the user is viewing the content stored in the removable card 10.

在一第二模式中,裝置100可不透過蜂巢網路110進接網際網路150。一方式是透過一網路入口裝置170,諸如連接至一PC的一終端(舉例而言,透過一USB埠)。另一方式是透過一無線鏈接,諸如Wi-Fi,其無線連接至連接到網際網路150的一接收裝置(未繪示)。在任一方式中,裝置100具有一電腦塢開關160。參考第5圖,其示意繪示了此通訊模式(連同第一模式)的一圖。通常,在第一模式中,可移除式卡片10透過電腦塢開關160連接至USB介面114。然而,當裝置100連接至PC 170或透過NFC 24,電腦塢開關160被改變,致使可移除式卡片10斷開與USB介面114的連接。因而,舉例而言,當一USB電纜連接至電腦塢開關160時,可移除式卡片10斷開與USB介面114的連接而沿其USB埠直接連接至PC 170。電腦塢開關160接著斷開可移除式卡片10與裝置100剩餘部分(包括收發器104)之間的連接。因為,可移除式卡片10包含蜂巢網路110進接資訊,若裝置100透過蜂巢網路110正無線進接網際網路,裝置100將停止無線地發射至蜂巢網路110及自蜂巢網路110接收。類似於第一操作模式,當裝置100透過電腦塢開關160連接至網際網路150、至PC閘道170時,由網際網路服務提供商(ISP)初始指派一公用IP位址以連接至網際網路150。同樣,這是一動態指派公用IP位址供裝置100連接至網際網路150的會話期間使用。In a second mode, device 100 may enter Internet 150 without going through cellular network 110. One way is through a network entry device 170, such as a terminal connected to a PC (for example, via a USB port). Another way is through a wireless link, such as Wi-Fi, which is wirelessly connected to a receiving device (not shown) connected to the Internet 150. In either manner, device 100 has a computer dock switch 160. Referring to Figure 5, a diagram of this communication mode (along with the first mode) is schematically illustrated. Typically, in the first mode, the removable card 10 is coupled to the USB interface 114 via the computer dock switch 160. However, when the device 100 is connected to or through the NFC 24, the computer dock switch 160 is changed, causing the removable card 10 to disconnect from the USB interface 114. Thus, for example, when a USB cable is connected to the computer dock switch 160, the removable card 10 is disconnected from the USB interface 114 and directly connected to the PC 170 along its USB port. Computer dock switch 160 then disconnects the removable card 10 from the remainder of device 100, including transceiver 104. Because the removable card 10 includes the cellular network 110 receiving information, if the device 100 is wirelessly entering the Internet through the cellular network 110, the device 100 will stop transmitting wirelessly to the cellular network 110 and from the cellular network. 110 received. Similar to the first mode of operation, when the device 100 is connected to the Internet 150 through the computer dock switch 160 to the PC gateway 170, an Internet Service Provider (ISP) initially assigns a public IP address to connect to the Internet. Network 150. Again, this is used during a session in which the public IP address is dynamically assigned for the device 100 to connect to the Internet 150.

最後,因為可移除式卡片10將MNO指派的一公用IP位址儲存於記憶體的使用者受限制部分中,該公用IP位址使裝置100指向MNO伺服器200。在裝置透過PC入口170連接至網際網路150且使用者未正在瀏覽或漫遊網際網路150的時段內,(如在舉例而言裝置100處於連接至電腦塢開關160的攜行電腦塢中以給裝置100的電池充電時),裝置100可使用儲存於可移除式卡片10中的公用IP位址走MNO伺服器200。MNO伺服器200接著可致使內容,諸如電影或程式化碼(針對裝置100的更新)被下載且儲存於裝置100之可移除式卡片10的使用者受限制部分中。此模式的益處在於,當裝置100未連接至蜂巢網路110,及當使用者未主動漫遊或瀏覽網際網路150時,可下載大量內容。所下載的電影或其它材料可隨後由授權代碼及/或付款代碼激活。由於電影或其它內容是自MNO伺服器200下載,使用者可確定內容的可靠性(亦即,免受病毒感染等等)。此外,由於內容擁有者知曉內容是以一安全方式下載且儲存於一使用者受限制部分中,它們可受確保將不作非法複製。以此方式,這變為對所有方而言的一可靠程序。最後,亦藉由允許程式化碼以此方式來分發,一有效率及方便模式被提供來確保裝置100的更新。Finally, because the removable card 10 stores a public IP address assigned by the MNO in the user restricted portion of the memory, the public IP address causes the device 100 to point to the MNO server 200. During a time period when the device is connected to the Internet 150 through the PC portal 170 and the user is not browsing or roaming the Internet 150 (eg, for example, the device 100 is in a carrying computer dock connected to the computer dock switch 160) When charging the battery of device 100), device 100 can walk through MNO server 200 using the public IP address stored in removable card 10. The MNO server 200 can then cause content, such as a movie or stylized code (updated for the device 100) to be downloaded and stored in the user restricted portion of the removable card 10 of the device 100. The benefit of this mode is that when the device 100 is not connected to the cellular network 110, and when the user does not actively roam or browse the Internet 150, a large amount of content can be downloaded. The downloaded movie or other material may then be activated by an authorization code and/or a payment code. Since the movie or other content is downloaded from the MNO server 200, the user can determine the reliability of the content (ie, from virus infection, etc.). In addition, since the content owner knows that the content is downloaded in a secure manner and stored in a restricted portion of the user, they can be guaranteed not to be illegally copied. In this way, this becomes a reliable procedure for all parties. Finally, by allowing the programmatic code to be distributed in this manner, an efficient and convenient mode is provided to ensure the update of device 100.

此外,每一可移除式卡片10亦可由MNO運營商指派一唯一IP位址。這提供了本發明的另一獨特特徵。當裝置100(可移除式卡片10連接至它)連接至網際網路150,及可移除式卡片10具有一唯一IP位址時,亦連接至網際網路150的MNO伺服器200可下載針對所有可移除式卡片10或僅某些可移除式卡片10或甚至僅一可移除式卡片10的資訊。下載至一或多個可移除式卡片10的資訊可儲存於卡片10的使用者受限制記憶體部分中。可儲存於使用者受限制部分中之資訊的範例包括:行政管理資訊,諸如呼叫計劃的改變、分鐘的增加等等。此外,「資訊」可以是資料或可以是供主機控制器12執行的程式化碼(包括Java applets)。因此,舉例而言,自MNO伺服器下載的「資訊」可以是致使主機控制器12執行程式碼的一程式,該程式碼致使裝置100進接蜂巢網路110以週期性進接網際網路150或進接網際網路150上的特定位置(諸如,MNO伺服器200的IP位址)或以某特定方式來獲取更新、下載、等等。In addition, each removable card 10 can also be assigned a unique IP address by the MNO operator. This provides another unique feature of the invention. When the device 100 (the removable card 10 is connected to it) is connected to the Internet 150, and the removable card 10 has a unique IP address, the MNO server 200 also connected to the Internet 150 can be downloaded. Information for all removable cards 10 or only some removable cards 10 or even only one removable card 10. Information downloaded to one or more removable cards 10 may be stored in the user restricted memory portion of card 10. Examples of information that can be stored in the restricted portion of the user include administrative information such as changes to the call plan, an increase in minutes, and the like. In addition, the "information" may be data or may be a programmatic code (including Java applets) for execution by the host controller 12. Thus, for example, the "information" downloaded from the MNO server can be a program that causes the host controller 12 to execute the code that causes the device 100 to enter the cellular network 110 to periodically enter the Internet 150. Or enter a particular location on the Internet 150 (such as the IP address of the MNO server 200) or obtain updates, downloads, and the like in a particular manner.

因為裝置100可透過公用載波網路連接至網際網路,使用者可將使用者資料儲存於記憶體20的第二部分220b中。然而,由於記憶體20可被MNO存取,MNO可向使用者提供服務,諸如對儲存於記憶體20之第二部分220b中的使用者資料備份。然而,由於儲存於第二部分220b中的使用者資料可為使用者的個人或機密資訊,所以使用者將希望使用者資料受保全,即便是MNO也不能獲取,還有在裝置100 丟失或被盜的情況下也不會被獲取。參考第6圖,其繪示本發明的安全可移除式卡片10之一部分的一方塊層面圖。卡片10具有一非依電性記憶體20,其具有使用者受限制存取的第一部分220a及使用者可儲存使用者資料的一第二部分220b。MNO可存取記憶體20的第一部分220a及第二部分220b。卡片10亦具有一依電性記憶體250,其用以儲存一使用者提供的密碼。依電性記憶體僅當電力供應至卡片10或裝置100時才保留密碼。當電力移除時,同一密碼需要使用者再次輸入。卡片10亦包含一加密電路230,其接收輸入的使用者資料以及依電性記憶體250的輸出。加密電路用密碼對使用者資料加密及進而經加密資料被提供至記憶體20的第二部分以供儲存。當期望自記憶體20的第二部分220b讀取資料時,經加密資料係自第二部分220b讀取並提供至一解密電路240。解密電路使用來自依電性記憶體的密碼來對加密資料解密並將經解密使用者資料供回至使用者。Since the device 100 can be connected to the Internet through a common carrier network, the user can store the user data in the second portion 220b of the memory 20. However, since the memory 20 is accessible by the MNO, the MNO can provide services to the user, such as backing up user data stored in the second portion 220b of the memory 20. However, since the user data stored in the second portion 220b can be the user's personal or confidential information, the user will want the user data to be preserved, even if the MNO is not available, and also in the device 100. It will not be acquired if it is lost or stolen. Referring to Figure 6, a block diagram of a portion of the secure removable card 10 of the present invention is illustrated. The card 10 has a non-electrical memory 20 having a first portion 220a that is restricted access by the user and a second portion 220b from which the user can store user data. The MNO can access the first portion 220a and the second portion 220b of the memory 20. The card 10 also has an electrical memory 250 for storing a password provided by the user. The electrical memory retains the password only when power is supplied to the card 10 or device 100. When power is removed, the same password needs to be entered again by the user. The card 10 also includes an encryption circuit 230 that receives the input user data and the output of the electrical memory 250. The encryption circuit encrypts the user data with a password and is then provided with encrypted data to a second portion of the memory 20 for storage. When it is desired to read data from the second portion 220b of the memory 20, the encrypted data is read from the second portion 220b and provided to a decryption circuit 240. The decryption circuit uses the password from the power-dependent memory to decrypt the encrypted data and provide the decrypted user data back to the user.

自前面可見,本發明卡片10極度安全。儲存於一第二部分220b中的內容始終是經加密資料。因而,即使裝置100丟失或被盜及一可能的駭客視圖讀取第二部分220b中的資料,該駭客會發現只有經加密的資料。安全程度僅受加密電路130的複雜性及對使用者資料加密的密碼位元數目限制。此外,僅當電力供應時加密才主動進行。如果裝置100關閉,及再次開啟,一新會話開始及使用者將需要再次輸入密碼。As can be seen from the foregoing, the card 10 of the present invention is extremely safe. The content stored in a second portion 220b is always encrypted material. Thus, even if the device 100 is lost or stolen and a possible hacker view reads the data in the second portion 220b, the hacker will find only encrypted data. The degree of security is limited only by the complexity of the encryption circuit 130 and the number of cryptographic bits that encrypt the user data. In addition, encryption is only active when power is supplied. If device 100 is turned off and turned back on, a new session begins and the user will need to enter the password again.

最後,如果使用者忘記密碼,應注意的是,密碼未儲存於記憶體20的任一部分中。因而,如果忘記密碼,害處十分大。減輕此殘酷結果的一方式是將一「暗示」問題或片語(諸如你最喜歡寵物的名字是什麽)儲存於第二記憶體220b中,使得使用者可迅速回憶起忘記的密碼。然而,此「暗示」亦可破解卡片10的安全。但是,密碼本身從不儲存於記憶體20中。Finally, if the user forgets the password, it should be noted that the password is not stored in any part of the memory 20. Therefore, if you forget your password, it is very harmful. One way to alleviate this cruel result is to store a "hind" question or phrase (such as what your favorite pet's name is) in the second memory 220b so that the user can quickly recall the forgotten password. However, this "hinting" can also break the security of the card 10. However, the password itself is never stored in the memory 20.

10...可移除式卡片10. . . Removable card

12...主機控制器12. . . Host controller

14...記憶體控制器、控制器14. . . Memory controller, controller

16、90、91...匯流排16, 90, 91. . . Busbar

20...NAND記憶體、記憶體20. . . NAND memory, memory

22...PSRAMtwenty two. . . PSRAM

24...近距離無線通訊器twenty four. . . Short-range wireless communicator

30...主機介面30. . . Host interface

32...暫存器32. . . Register

50...高速匯流排50. . . High speed bus

51...先進先出電路51. . . FIFO circuit

52...ARM SC-100處理器52. . . ARM SC-100 processor

54...USB控制器電路54. . . USB controller circuit

56...PHY電路56. . . PHY circuit

60...RSA/AES/DES引擎60. . . RSA/AES/DES engine

62...仲裁電路62. . . Arbitration circuit

64...SRAM64. . . SRAM

68...橋接電路68. . . Bridge circuit

70...較慢匯流排70. . . Slower bus

72...計時器72. . . Timer

74...時鐘產生器74. . . Clock generator

76...電力管理電路76. . . Power management circuit

78...安全監控電路78. . . Safety monitoring circuit

80...通用異步接收器/發射器80. . . Universal asynchronous receiver/transmitter

82...串行周邊介面電路、串行周邊介面82. . . Serial peripheral interface circuit, serial peripheral interface

100...無線通訊裝置、手機100. . . Wireless communication device, mobile phone

102...天線102. . . antenna

104...收發器104. . . transceiver

106...閘道、網路位址轉換電路106. . . Gateway, network address conversion circuit

108‧‧‧顯示器108‧‧‧ display

110‧‧‧手機網路、蜂巢網路、無線網路110‧‧‧Mobile network, cellular network, wireless network

112‧‧‧瀏覽器及媒體播放器112‧‧‧Browser and media player

113‧‧‧USB匯流排113‧‧‧USB bus

114‧‧‧USB介面114‧‧‧USB interface

120‧‧‧蜂巢進接塔、手機塔120‧‧‧Hive in the tower, mobile tower

150‧‧‧網際網路150‧‧‧Internet

160‧‧‧電腦塢開關160‧‧‧Computer dock switch

170‧‧‧網路入口裝置、PC、PC閘道、PC入口170‧‧‧Internet access device, PC, PC gateway, PC entrance

200‧‧‧伺服器、行動網路運行商伺服器200‧‧‧Server, mobile network operator server

220a‧‧‧第一部分220a‧‧‧Part 1

220b‧‧‧第二部分220b‧‧‧Part II

230‧‧‧加密電路230‧‧‧Encryption circuit

240‧‧‧解密電路240‧‧‧Decryption circuit

250‧‧‧依電性記憶體250‧‧‧Electrical memory

第1圖是連接至本發明行動無線通訊裝置以供連接至一行動網路及網際網路之本發明可移除式卡片的一圖。1 is a diagram of a removable card of the present invention connected to a mobile wireless communication device of the present invention for connection to a mobile network and the Internet.

第2圖是連接至本發明行動無線通訊裝置之本發明可移除式卡片的一示意圖。Figure 2 is a schematic illustration of a removable card of the present invention coupled to a mobile wireless communication device of the present invention.

第3圖是本發明可移除式卡片的一方塊層面圖電路圖。Figure 3 is a block diagram circuit diagram of the removable card of the present invention.

第4圖是本發明可移除式卡片之處理器部分的一詳細電路圖。Figure 4 is a detailed circuit diagram of the processor portion of the removable card of the present invention.

第5圖是行動無線通訊裝置用本發明可移除式卡片與網際網路通訊之兩模式的一圖,其中在第一模式中,可移除式卡片透過無線通訊裝置與行動網路無線通訊以進接網際網路,及其中在一第二模式中,可移除式卡片連接至一網路入口裝置以連接至網際網路。Figure 5 is a diagram of two modes of the mobile wireless communication device using the removable card and the Internet communication of the present invention, wherein in the first mode, the removable card wirelessly communicates with the mobile network through the wireless communication device To access the Internet, and in a second mode, the removable card is connected to a network entry device to connect to the Internet.

第6圖是本發明之具有安全特徵的可移除式卡片的一方塊層面圖。Figure 6 is a block diagram of a removable card having security features of the present invention.

10‧‧‧可移除式卡片10‧‧‧Removable card

100‧‧‧無線通訊裝置、手機100‧‧‧Wireless communication devices, mobile phones

110‧‧‧手機網路110‧‧‧Mobile network

120‧‧‧蜂巢進接塔120‧‧‧Hive in the tower

150‧‧‧網際網路150‧‧‧Internet

200‧‧‧伺服器200‧‧‧Server

Claims (9)

一種可移除式卡片,其具有用以連接至一行動無線通訊裝置的電氣連接,供一使用者使用以進接一公用載波網路來進接互連電腦網路的一網路(「網際網路」),該可移除式卡片包含:一處理器;連接至該處理器的一非依電性記憶體,該非依電性記憶體具有兩部分:一第一部分與一第二部分,其中該第一部分可被該公用載波網路提供商存取,該處理器限制該使用者存取該第一部分;及其中該第二部分可被該公用載波網路提供商存取,該處理器允許該使用者存取該第二部分以在其內儲存使用者資料;及邏輯電路,其用來編碼該使用者資料以產生經加密使用者資料,其中該經加密使用者資料儲存於該第二部分中,其中該邏輯電路包含一依電性記憶體,其用以儲存一使用者提供之密碼,其中該密碼僅在電力供應至該記憶體時儲存於該依電性記憶體中;一加密電路,用以接收該使用者提供之使用者資料與該依電性記憶體之輸出,以及用以自該依電性記憶體以該密碼加密該使用者資料以產生經加密使用者資料,以及用以儲存該經加密使用者資料於該第二部分中;以及一解密電路,用以接收儲存於該第二部分中之經加密使用者資料與該依電性記憶體之該輸出,以及用以自該依電性記憶體以該密碼解密該經加密使用者資料以產生使用者資料。 A removable card having an electrical connection for connecting to a mobile wireless communication device for use by a user to access a public carrier network to access a network interconnecting the computer network ("Internet The removable card includes: a processor; a non-electrical memory connected to the processor, the non-electrical memory having two parts: a first part and a second part, Wherein the first portion is accessible by the public carrier network provider, the processor restricting the user from accessing the first portion; and wherein the second portion is accessible by the public carrier network provider, the processor Allowing the user to access the second portion to store user data therein; and logic circuitry for encoding the user data to generate encrypted user data, wherein the encrypted user data is stored in the first In the second part, the logic circuit includes an electrical memory for storing a password provided by the user, wherein the password is stored in the electrical memory only when power is supplied to the memory; plus a circuit for receiving user data provided by the user and the output of the power-based memory, and for encrypting the user data with the password from the power-dependent memory to generate encrypted user data, and For storing the encrypted user data in the second portion; and a decryption circuit for receiving the encrypted user data stored in the second portion and the output of the electrical memory, and The encrypted user data is decrypted with the password from the power memory to generate user data. 如申請專利範圍第1項所述之可移除式卡片,其中該第一部分與該第二部分的該劃分是可改變的。 The removable card of claim 1, wherein the division of the first portion and the second portion is changeable. 如申請專利範圍第1項所述之可移除式卡片,其中該非依電性記憶體具有儲存於內部、被組配成由該處理器處理且可在下面兩模式之一模式中操作的程式碼:一第一模式,其中該卡片連接至該裝置,該卡片儲存該裝置自該網際網路無線接收的資訊;及一第二模式,其中該卡片連接至連接到該網際網路的一網路埠口裝置,該卡片儲存透過該網路埠口裝置自該網際網路接收的資訊。 The removable card of claim 1, wherein the non-electrical memory has a program stored internally, configured to be processed by the processor, and operable in one of the following two modes Code: a first mode in which the card is connected to the device, the card stores information wirelessly received by the device from the internet; and a second mode in which the card is connected to a network connected to the internet A gateway device that stores information received from the Internet through the network port device. 如申請專利範圍第3項所述之可移除式卡片,其中在該第一模式中,該卡片儲存該裝置透過具有連接至該網際網路的一無線進接裝置之一無線網路而無線接收的資訊,及其中在該第二模式中,該卡片透過該網路埠口裝置直接連接至該網際網路。 The removable card of claim 3, wherein in the first mode, the card stores the device wirelessly through a wireless network having a wireless access device connected to the Internet The received information, and in the second mode, the card is directly connected to the internet through the network port device. 一種行動無線通訊裝置,其供一使用者使用以進接一公用載波網路來進接互連電腦網路的一網路(「網際網路」),該行動無線通訊裝置包含:一收發器,其用以經由一無線公用載波網路無線通訊;一第一處理器,其用以控制該裝置的通訊以連接至該公用載波網路;一第二處理器;連接至該第二處理器的一非依電性記憶體,該非依電性記憶體具有兩部分:一第一部分及一第二部分,其 中該第一部分可被該公用載波網路提供商存取,該第二處理器限制該使用者存取該第一部分;及其中該第二部分可被該公用載波網路提供商存取,及該第二處理器允許該使用者存取該第二部分以在其內儲存使用者資料;及邏輯電路,其用來編碼該使用者資料以產生經加密使用者資料供儲存於該第二部分中,其中該邏輯電路包含一依電性記憶體,其用以儲存一使用者提供的密碼,其中該密碼僅在電力供應至該記憶體時儲存於該依電性記憶體中;一加密電路,用以接收該使用者提供之使用者資料與該依電性記憶體之輸出,以及用以自該依電性記憶體以該密碼加密該使用者資料以產生經加密使用者資料,以及用以儲存該經加密使用者資料於該第二部分中;以及一解密電路,用以接收儲存於該第二部分中之經加密使用者資料與該依電性記憶體之該輸出,以及用以自該依電性記憶體以該密碼解密該經加密使用者資料以產生使用者資料。 A mobile wireless communication device for a user to access a public carrier network to access a network ("Internet") interconnecting a computer network, the mobile wireless communication device comprising: a transceiver For communicating wirelessly via a wireless common carrier network; a first processor for controlling communication of the device to connect to the common carrier network; a second processor; connecting to the second processor a non-electrical memory having two parts: a first part and a second part, The first portion is accessible by the public carrier network provider, the second processor restricting the user from accessing the first portion; and wherein the second portion is accessible by the public carrier network provider, and The second processor allows the user to access the second portion to store user data therein; and logic circuitry for encoding the user profile to generate encrypted user data for storage in the second portion The logic circuit includes an electrical memory for storing a password provided by a user, wherein the password is stored in the electrical memory only when power is supplied to the memory; an encryption circuit Receiving user data provided by the user and the output of the power-dependent memory, and encrypting the user data with the password from the power-based memory to generate encrypted user data, and using Storing the encrypted user data in the second portion; and a decryption circuit for receiving the encrypted user data stored in the second portion and the output of the power-dependent memory According to the nonvolatile memory from the body to the password to decrypt the encrypted user data to generate user data. 如申請專利範圍第5項所述之裝置,其中該第二處理器、非依電性記憶體、及邏輯電路包含於一可移除式卡片中。 The device of claim 5, wherein the second processor, the non-electrical memory, and the logic circuit are included in a removable card. 如申請專利範圍第6項所述之裝置,其中該第一部分與該第二部分的該劃分是可改變的。 The device of claim 6, wherein the division of the first portion and the second portion is changeable. 如申請專利範圍第7項所述之裝置,其中該非依電性記憶體具有儲存於內部、被組配成由該第二處理器處理且可在下面兩模式之一模式中操作的程式碼:一第一模式,其中該卡片連接至該收發器,該卡片儲存該裝置自該網際網路無線接收的資訊;及一第二模式,其中該卡片連接至連接到該網際網路的一網路埠口裝置,該卡片儲存透過該網路埠口裝置自該網際網路接收的資訊。 The device of claim 7, wherein the non-electrical memory has a code stored internally, configured to be processed by the second processor, and operable in one of the following two modes: a first mode, wherein the card is connected to the transceiver, the card stores information wirelessly received by the device from the internet; and a second mode, wherein the card is connected to a network connected to the internet A mouthwash device that stores information received from the Internet through the network port device. 如申請專利範圍第8項所述之裝置,其中在該第一模式中,該卡片儲存該裝置透過具有連接至該網際網路的一無線進接裝置之一無線網路而無線接收的資訊,及其中在該第二模式中,該裝置透過該網路埠口裝置直接連接至該網際網路。 The device of claim 8, wherein in the first mode, the card stores information wirelessly received by the device through a wireless network having a wireless access device connected to the Internet. And in the second mode, the device is directly connected to the internet through the network port device.
TW099130297A 2010-09-08 2010-09-08 A secure removable card and a mobile wireless communication device TWI499317B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW099130297A TWI499317B (en) 2010-09-08 2010-09-08 A secure removable card and a mobile wireless communication device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW099130297A TWI499317B (en) 2010-09-08 2010-09-08 A secure removable card and a mobile wireless communication device

Publications (2)

Publication Number Publication Date
TW201212664A TW201212664A (en) 2012-03-16
TWI499317B true TWI499317B (en) 2015-09-01

Family

ID=46764634

Family Applications (1)

Application Number Title Priority Date Filing Date
TW099130297A TWI499317B (en) 2010-09-08 2010-09-08 A secure removable card and a mobile wireless communication device

Country Status (1)

Country Link
TW (1) TWI499317B (en)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070074273A1 (en) * 2005-09-23 2007-03-29 Bill Linden Method and device for increasing security during data transfer
US20080288700A1 (en) * 2001-08-02 2008-11-20 Michael Holtzman Removable computer with mass storage

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080288700A1 (en) * 2001-08-02 2008-11-20 Michael Holtzman Removable computer with mass storage
US20070074273A1 (en) * 2005-09-23 2007-03-29 Bill Linden Method and device for increasing security during data transfer

Also Published As

Publication number Publication date
TW201212664A (en) 2012-03-16

Similar Documents

Publication Publication Date Title
US8200281B2 (en) Secure removable card and a mobile wireless communication device
KR101035468B1 (en) A removable card and a mobile wireless communication device
US7979717B2 (en) Secure removable card having a plurality of integrated circuit dies
KR100689504B1 (en) Device for protecting transmission of contents
KR101510784B1 (en) Method of secure personalization of a nfc chipset
JP5496652B2 (en) Method for ensuring secure access to a proximity communication module of a mobile terminal
US20060173846A1 (en) Access information relay device, a network device, an access information managing device, a resource managing device, and an access control system
WO2014048354A1 (en) Method, terminal and universal integrated circuit card (uicc) for realizing subscriber identity module (sim) card function in terminal
CN113132091B (en) Method for sharing equipment and electronic equipment
US8346215B2 (en) Retrospective implementation of SIM capabilities in a security module
US20100312926A1 (en) Switch for a two way connection between a removable card, a mobile wireless communication device, or a computer
EP2530631A1 (en) A method for accessing at least one service, corresponding communicating device and system
US11539403B2 (en) User device using NFC, authentication system and operation method thereof
ES2401358T3 (en) Procedure and terminal to provide controlled access to a memory card
TWI499317B (en) A secure removable card and a mobile wireless communication device
US11516215B2 (en) Secure access to encrypted data of a user terminal
RU2517375C2 (en) Intermediate platform, card with pcb and generation of authentication key
JP3798397B2 (en) Access management system and access management device
KR20190047557A (en) Earphone Device for Providing OTP by using Asynchronous Local Area Radio Communication
CN108769989A (en) A kind of wireless network connection method, wireless access device and equipment
KR20180093057A (en) A method and system for secure communication between a mobile unit and a server interlocked with a smartphone
KR101777041B1 (en) Method for Generating One Time Password based on Asynchronous Local Area Radio Communication
WO2008149126A2 (en) Methods, apparatuses and software for initiating a circuit switched call to a key server, for receiving incoming circuit switched calls and for attaching a computer peripheral device
KR20190047558A (en) Method for Providing One Time Password by using Asynchronous Local Area Radio Communication of Earphone Device
KR20150004954A (en) Method for Providing One Time Code by using End-To-End Authentication between SD Memory and Server