WO2002076013A1 - Systeme de gestion d'acces aux donnees et procede de gestion utilisant un billet de commande d'acces - Google Patents
Systeme de gestion d'acces aux donnees et procede de gestion utilisant un billet de commande d'acces Download PDFInfo
- Publication number
- WO2002076013A1 WO2002076013A1 PCT/JP2002/002113 JP0202113W WO02076013A1 WO 2002076013 A1 WO2002076013 A1 WO 2002076013A1 JP 0202113 W JP0202113 W JP 0202113W WO 02076013 A1 WO02076013 A1 WO 02076013A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- ticket
- access
- memory
- data
- authentication
- Prior art date
Links
- 238000007726 management method Methods 0.000 title claims description 212
- 238000012545 processing Methods 0.000 claims abstract description 721
- 230000015654 memory Effects 0.000 claims abstract description 447
- 238000005192 partition Methods 0.000 claims description 1303
- 238000000034 method Methods 0.000 claims description 1137
- 230000008569 process Effects 0.000 claims description 621
- 238000012795 verification Methods 0.000 claims description 543
- 230000006854 communication Effects 0.000 claims description 112
- 238000004891 communication Methods 0.000 claims description 108
- 238000012790 confirmation Methods 0.000 claims description 50
- 238000003860 storage Methods 0.000 claims description 50
- 238000003672 processing method Methods 0.000 claims description 29
- 238000013475 authorization Methods 0.000 claims description 19
- 230000004044 response Effects 0.000 claims description 19
- 238000004590 computer program Methods 0.000 claims description 15
- 208000033748 Device issues Diseases 0.000 claims description 9
- 238000010200 validation analysis Methods 0.000 claims description 9
- 238000010586 diagram Methods 0.000 description 77
- 238000012217 deletion Methods 0.000 description 61
- 230000037430 deletion Effects 0.000 description 61
- 238000004519 manufacturing process Methods 0.000 description 59
- 238000012546 transfer Methods 0.000 description 43
- 230000006870 function Effects 0.000 description 28
- 230000002457 bidirectional effect Effects 0.000 description 17
- 230000007717 exclusion Effects 0.000 description 17
- 230000005540 biological transmission Effects 0.000 description 16
- 238000004422 calculation algorithm Methods 0.000 description 15
- 239000002131 composite material Substances 0.000 description 12
- 238000000638 solvent extraction Methods 0.000 description 12
- 238000013500 data storage Methods 0.000 description 8
- 150000001875 compounds Chemical class 0.000 description 7
- 238000013524 data verification Methods 0.000 description 6
- 239000004065 semiconductor Substances 0.000 description 6
- 238000011161 development Methods 0.000 description 5
- 238000009826 distribution Methods 0.000 description 5
- 230000008520 organization Effects 0.000 description 5
- 238000010926 purge Methods 0.000 description 5
- 230000008901 benefit Effects 0.000 description 4
- 125000004122 cyclic group Chemical group 0.000 description 4
- 238000013523 data management Methods 0.000 description 4
- 230000009467 reduction Effects 0.000 description 4
- 230000014509 gene expression Effects 0.000 description 3
- 230000003287 optical effect Effects 0.000 description 3
- 230000008859 change Effects 0.000 description 2
- 238000001514 detection method Methods 0.000 description 2
- 101000603877 Homo sapiens Nuclear receptor subfamily 1 group I member 2 Proteins 0.000 description 1
- 101000613565 Homo sapiens PRKC apoptosis WT1 regulator protein Proteins 0.000 description 1
- 101001135199 Homo sapiens Partitioning defective 3 homolog Proteins 0.000 description 1
- 101001098560 Homo sapiens Proteinase-activated receptor 2 Proteins 0.000 description 1
- 101001098557 Homo sapiens Proteinase-activated receptor 3 Proteins 0.000 description 1
- 101001113471 Homo sapiens Proteinase-activated receptor 4 Proteins 0.000 description 1
- 101000823955 Homo sapiens Serine palmitoyltransferase 1 Proteins 0.000 description 1
- 101000713170 Homo sapiens Solute carrier family 52, riboflavin transporter, member 1 Proteins 0.000 description 1
- 108050000123 Inactive phospholipase C-like protein 1 Proteins 0.000 description 1
- 125000002066 L-histidyl group Chemical group [H]N1C([H])=NC(C([H])([H])[C@](C(=O)[*])([H])N([H])[H])=C1[H] 0.000 description 1
- 102100022929 Nuclear receptor coactivator 6 Human genes 0.000 description 1
- 102100032341 PCNA-interacting partner Human genes 0.000 description 1
- 101710196737 PCNA-interacting partner Proteins 0.000 description 1
- 102100037132 Proteinase-activated receptor 2 Human genes 0.000 description 1
- 102100037133 Proteinase-activated receptor 3 Human genes 0.000 description 1
- 102100023710 Proteinase-activated receptor 4 Human genes 0.000 description 1
- 102100022068 Serine palmitoyltransferase 1 Human genes 0.000 description 1
- 230000009471 action Effects 0.000 description 1
- 229910052782 aluminium Inorganic materials 0.000 description 1
- XAGFODPZIPBFFR-UHFFFAOYSA-N aluminium Chemical compound [Al] XAGFODPZIPBFFR-UHFFFAOYSA-N 0.000 description 1
- 238000004364 calculation method Methods 0.000 description 1
- 230000006837 decompression Effects 0.000 description 1
- 238000000151 deposition Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000008030 elimination Effects 0.000 description 1
- 238000003379 elimination reaction Methods 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 230000002452 interceptive effect Effects 0.000 description 1
- 238000013318 key system verification Methods 0.000 description 1
- 239000004973 liquid crystal related substance Substances 0.000 description 1
- KRTSDMXIXPKRQR-AATRIKPKSA-N monocrotophos Chemical compound CNC(=O)\C=C(/C)OP(=O)(OC)OC KRTSDMXIXPKRQR-AATRIKPKSA-N 0.000 description 1
- 238000000547 structure data Methods 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06K—GRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
- G06K19/00—Record carriers for use with machines and with at least a part designed to carry digital markings
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
Definitions
- Patent application title Data access management system, memory mounted device, data access management method, and program storage medium
- the present invention relates to a data access management system, a memory mounted device, a data access management method, and a program storage medium.
- one memory is divided into a plurality of areas (partitions), and data managed by the service provider or related entities is stored in each partition.
- the present invention relates to a data access management system, a memory-mounted device, a data access management method, and a program storage medium that can be used for various services. Background art
- tape media floppy disks, hard disks, optical disks, semiconductor media, etc.
- semiconductor media is attracting attention as a device that can securely manage the memory in the device. The reason is that semiconductor memories can easily realize a structure that is not easily accessed from outside, that is, a tamper-resistant structure.
- the tamper-resistant structure is, for example, a device having a single-chip configuration made of a semiconductor, which is equipped with a control unit, a memory controller, a non-volatile memory, a voltage detection unit, a frequency detection unit, and the like. This is realized by adopting a configuration sandwiched between dummy layers such as an aluminum layer so that it cannot be performed.
- the conventional memory structure of such a secure device will be described with reference to FIG. 96 “Conventional memory structure”.
- the memory in FIG. 96 shows a memory configuration that can be used, for example, as electronic money. As shown in Figure 96, the memory area is roughly divided into three. A data area, a memory management area, and a system area.
- the memory management area stores a storage address for accessing each data in the data area, an access method, an access authentication key, and the like. For example, it is shown that access to data 1 (user name) in the data storage area is only possible to read (Read) by using the access authentication key (0123 ).
- the system area stores a device identifier (ID), a memory management key as an authentication key for securing a memory area in the data area, and the like.
- the data area of the memory device shown in FIG. 96 can be divided into a plurality of areas, and these divided data areas can be divided into different service entities, for example, electronic money management service providers (ex. (Bank).
- the data in each segmented area can be read by individual service providers as well as readers / writers as device access devices (exclusive reader / writers or PCs) installed in users, for example, stores that sell products using electronic money. ) Reads and writes the data, and (ex. Updates the remaining balance).
- Fig. 97 The relationship between the administrator and the user of a secure device with multiple divided data areas as shown in Fig. 96 is shown in Fig. 97 "Memory administrator ⁇ user".
- a memory administrator who is the subject of issuing a secure device, and a memory user who has a memory area allocated by this memory administrator and uses the allocated memory.
- the memory user is, for example, a bank or a store according to the above-described example of the electronic money manager.
- the memory administrator knows the memory management key for access control to secure the memory area, and uses this memory management key to store the memory of each memory user (split data area). assign.
- the memory user knows the access authentication key for accessing the data in each data area, and can use the access authentication key to access the memory in the data area allocated to each. .
- the data 4 in the memory shown in FIG. 96 is the amount data, and as shown in FIG. 97, the user of the data 4 performs the processing of the decrement (Decrement) and the reading / writing ( R ead / Write) processing is possible.
- the access key differs between the processing of data 4 reduction (De- crement) and the processing of reading and writing (Read / Write), and the access key corresponding to each processing is different. It is necessary to use skis to access the memory.
- FIG. 98 is a view for explaining a memory securing process in which a memory manager allocates a certain temporary area in the memory device to a memory user.
- the memory manager uses the memory allocation reader / writer (R / W: Reader / Writer) shown on the left side of the figure to read the memory shown on the right side of the figure. Executes data area allocation processing for the device.
- the memory securing reader / writer (R / W: Reader / Writer) is equipped with a secure NVRAM (Non-Volatile RAM) to hold the memory management key.
- NVRAM Non-Volatile RAM
- the R / W for securing memory may be a dedicated read / write R / W for a secure device, or if the secure device is a device with an I / F such as USB or PCM CIA, these interfaces may be used. It may be a device readable and writable via a PC, for example, a PC.
- R / W first read the device ID from the secure device.
- an authentication key is generated using the memory management key and the device ID, and mutual authentication is performed with the secure device using the generated authentication key.
- the mutual authentication process is executed according to, for example, mutual authentication using a common key method (ex. IS0 / IEC9798-2).
- RZW After successful mutual authentication, RZW encrypts the data structure, data size, access method, and access authentication key with the session key, and adds a MAC (Message Authentication Code) value for data verification as necessary.
- the secure device Upon receiving the command, the secure device decrypts the received data, verifies the falsification by MAC verification as needed, and then stores the data in the memory area according to the data size of the received data. Secure the memory area, write the data structure in the secured area, and write the address, access method, and access authentication key of the secured memory in the memory management area. In this way, a plurality of divided data areas are set in the memory device.
- the reader / writer on the left side of Fig. 9-9 is a memory access reader / writer (R / W) owned by the memory user.
- the reader / writer is composed of a dedicated R / W or PC.
- the memory access reader / writer (R / W) has a secure NVRAM for holding the access authentication key. To access the secure device overnight using R / W, first read the device ID from the secure device.
- an authentication key is generated using the access authentication key and the device ID, and mutual authentication is performed with the secure device using the generated authentication key.
- the R / W makes a predetermined access to the data in the temporary storage area corresponding to the access authentication key.
- payment terminals can increase security like ATMs, but withdrawal terminals are often used as cash collection machines when delivering goods at stores, etc., installation locations are various, and terminal theft Risk is high and it is difficult to increase the level of security. Therefore, a configuration in which the access authentication key is made different for data access is effective.
- an authentication processing using a memory management key or an access authentication key is performed in the memory data area securing processing and the access processing of each data area.
- the authentication process used are specifically configurations that apply a common key using, for example, a DES encryption algorithm, and perform authentication using a public key method or verification using a public key method. It is not what was expected.
- the configuration using a common key for the memory management key and access authentication key as described above has the advantage that authentication and access permission are executed in one process, but memory access using the leaked key is possible due to leakage of the authentication key. This is a security problem.
- the present invention has been made in view of the state of the prior art as described above, and various types of access control tickets are provided for accessing a memory area divided into a plurality of partitions.
- An independent management configuration of data in each partition by issuing a process under the management of the device or partition management entity and executing processing based on the rules described in each ticket on the device with memory. The purpose is to realize.
- a service permission ticket (SPT) as an access control ticket in which an access mode allowed for an access device is set is issued individually for each access device. It is an object of the present invention to provide a data access management system, a memory-mounted device, a data access management method, and a program storage medium that realize a configuration in which an access in a different mode can be executed according to the following.
- the memory-equipped device receives the specified or received fax from the access device.
- the public key method or the common key method is determined and executed based on the description of the access control ticket based on the description of the access control ticket.
- the access control ticket verification method is also determined and executed, for example, either the public key method or the common key method, so that it can be used in various environments and in various access control ticket modes. It is therefore an object of the present invention to provide a data processing system, a memory-mounted device, a data processing method, and a program storage medium that enable secure data communication between a device and an access device.
- the memory-equipped device receives the access control ticket configured as access control data from the access device, performs authentication based on the authentication rule described in the access control ticket, and performs the authentication based on the authentication rule described in the access control ticket.
- the data access is allowed under the condition that the identification of the access device has been confirmed immediately, so that access to the memory can be executed under more secure management, and various authentication modes and ticket modes are provided for each access.
- the purpose of the present invention is to provide a data access control system, a device with memory, a data access control method, and a program storage medium that realize access management with a security level set according to memory access processing. I do.
- the present invention has been made in view of the current state of the art as described above, and receives an access control ticket from an access device for access to a memory area divided into a plurality of partitions, and
- the configuration is such that the access process to the data file is executed, and the access process to the plurality of data files based on the plurality of access control tickets can be executed as a mode in which the decompression process is reduced. It is an object of the present invention to provide a memory access control system, a memory mounted device, a memory access control method, and a program storage medium.
- a data access management system that manages access processing from an access device to a memory-equipped data file for a memory-equipped device having a memory part capable of storing data,
- the access device receives a service permission ticket (SPT) as an access control ticket in which an access mode permitted for the access device is set from the ticket issuing means, and receives the received service permission ticket.
- S PT is output to the memory-equipped device
- the memory-equipped device receives the service permission ticket (SPT) from the access device, and executes processing according to the access mode described in the service permission ticket (SPT).
- SPT service permission ticket
- the present invention is directed to a data access management system characterized by having a configuration as described below.
- the service permission ticket (SPT) includes a file identifier for identifying a data file to be accessed
- the memory-equipped device includes: Receiving the service permission ticket (SPT) from the access device, selecting a data file according to the file identifier described in the service permission ticket (SPT), and selecting the data file for the selected file. It is characterized by having a configuration for executing processing according to the access mode.
- the service permission ticket (SPT) has a configuration that includes a plurality of file identifiers for identifying a plurality of data files to be accessed, and one of the plurality of file identifiers is set as a target file identifier. And read permission or write permission data for the target file.
- the memory-equipped device receives the service permission ticket (SPT) from the access device and follows the access mode according to the access mode.
- a configuration for executing read or write processing in accordance with write permission data To.
- the service permission ticket (SPT) has a configuration including a plurality of file identifiers for identifying a plurality of data files to be accessed. Among multiple file identifiers, One sets the target file identifier and stores read / write permission data for the target file, and sets the access mode of the other data file to encryption using the encryption key stored in the data file.
- the memory-equipped device receives the service permission ticket (SPT) from the access device, and performs a process according to the access mode to execute the processing of the evening get file.
- the internal encryption processing in the memory-equipped device is executed by reading and executing the encryption processing using the encryption key.
- the ticket issuing means for issuing the service permission ticket is under the management of an entity that manages a memory area of the memory-mounted device.
- the memory-equipped device is configured to execute a file open process based on a service permission ticket (SPT) received during a session with the access device.
- SPT service permission ticket
- a file open table is generated in which the file identifier as the identification data is associated with the access mode described in the service permission ticket (SPT), and the access from the access device is referred to by referring to the file open table. It is characterized in that it has a configuration for determining whether to execute a received command.
- the memory section of the memory-equipped device includes one or more partition areas each serving as a memory area managed by a corresponding partition manager.
- the data file is stored in any of the one or more partition areas, and the memory-equipped device performs a process for an access request for a data file in each partition by a ticket under the control of a partition manager. Issued by the issuing means, from the access device as a ticket using means to the memory-equipped device. It is characterized in that it is configured to be executed based on the description of the service permission ticket (SPT) that is input to it.
- SPT service permission ticket
- the service permission ticket (SPT) is an interactive service to be executed between the memory-equipped device and the access device that has output the ticket.
- the device with memory includes a mutual authentication mode designating data designating an authentication mode, wherein the memory-equipped device executes mutual authentication according to the mutual authentication mode designation data of the service permission ticket (SPT), and establishes the authentication.
- the service permission ticket (SPT) may be configured to execute a process corresponding to a record of the reception ticket as a condition.
- a ticket verification designation data designating a verification mode of the service permission ticket (SPT) received by the memory-equipped device;
- the chair performs the ticket verification processing of the service permission ticket (SPT) according to the designated data, and executes the processing according to the record of the received ticket on condition that the verification is established. It is characterized by having a configuration.
- a second aspect of the present invention provides:
- a memory-equipped device having a memory part capable of storing data
- Control means for controlling access processing from the access device to the data file stored in the memory unit
- the control means includes:
- a data file is selected according to the file identifier described in the service permission ticket (SPT) to be received, and the selected file is followed in accordance with the access mode described in the service permission ticket (SPT).
- SPT service permission ticket
- a memory-mounted device having a configuration for executing the above-described processing.
- the service permission ticket includes a file identifier for identifying a data file to be accessed, and Receiving the service permission ticket (SPT), selecting a data file according to the file identifier described in the service permission ticket (SPT), and entering the access mode for the selected file. It is characterized in that it has a configuration for executing the following processing.
- the service permission ticket has a configuration including a plurality of file identifiers for identifying a plurality of data files to be accessed, and One of which is set as a target file identifier and stores read / write permission data for the target file, wherein the control means transmits the service permission ticket from the access device.
- the service permission ticket (SPT) has a configuration including a plurality of file identifiers for identifying a plurality of data files to be accessed, and Of the file identifiers, one is set as the target file identifier, the read / write permission data for the target file is stored, and the other data file is stored in the data file as the access mode.
- the control unit has a configuration in which an encryption process using an encryption key is set, and the control unit receives the service permission ticket (SPT) from the access device, and performs the process according to the access mode, By reading the evening gate file and executing the encryption process using the encryption key, the memory Characterized by being configured to perform an internal encryption processing in the mounting device.
- the control means includes an identification data of a file that has been subjected to a file open process based on a service permission ticket (SPT) received during a session with the access device.
- SPT service permission ticket
- the memory part of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager, and The file is stored in one of the one or more partition areas, and the control unit issues a process for an access request to a data file in each partition by a ticket issuing unit under the control of a partition manager.
- the present invention is characterized in that it is configured to be executed based on a description of a service permission ticket (SPT) input from the access device as a ticket using means to the memory-mounted device.
- SPT service permission ticket
- the service permission ticket designates a mutual authentication mode to be executed between the memory-equipped device and the access device that has output the ticket.
- the control means executes the mutual authentication according to the mutual authentication mode designation data of the service permission ticket (SPT), and records the received ticket on condition that the authentication is established. It is characterized by having a configuration for executing a corresponding process.
- the service permission ticket is a ticket verification designation designating a verification mode of the service permission ticket (SPT) received by the memory-equipped device.
- the control means executes a ticket verification process in accordance with the ticket verification designation data of the service permission ticket (SPT), and responds to the record of the received ticket on condition that the verification is established. It is characterized by having a configuration for executing processing.
- a third aspect of the present invention is that
- the access device receives a service permission ticket (SPT) as an access control ticket in which an access mode permitted for the access device is set from the ticket issuing means, and receives the received service permission ticket (SPT).
- SPT is output to the memory-equipped device,
- the memory-equipped device receives the service permission ticket (SPT) from the access device and executes a process according to the access mode described in the service permission ticket (SPT).
- the data access management method is characterized in that:
- the service permission ticket (SPT) includes a file identifier for identifying a data file to be accessed
- the memory-equipped device includes: Receiving the service permission ticket (SPT) from the access device, selecting a data file according to the file identifier described in the service permission ticket (SPT), and selecting the data file according to the selected file. And executes a process according to the access mode.
- the service permission ticket (SPT) has a configuration including a plurality of file identifiers for identifying a plurality of data files to be accessed.
- One of the plurality of file identifiers is set as a target file identifier and stores read or write permission data for the target file, and the memory-equipped device receives the service from the access device, Upon receiving the permission ticket (SPT), the processing according to the access mode is executed, and the target file set as the target file identifier in the service permission ticket (SPT) is received. The read or write permission data set in the service permission ticket (SPT). And executes a read or write process in accordance with the data.
- the service permission ticket (SPT) has a configuration including a plurality of file identifiers for identifying a plurality of data files to be accessed.
- One of the plurality of file identifiers is set as a target file identifier and stores read or write permission data for the target file, and the data file is set as an access mode of the other data file.
- the device with the memory has a configuration in which an encryption process using an encryption key stored in the access device is set, and the memory-equipped device receives the service permission ticket (SPT) from the access device, and As processing according to the The internal encryption process in the memory-mounted device is executed by reading the evening get file and executing the encryption process using the encryption key.
- the ticket issuing means for issuing the service permission ticket (SPT) is controlled by an entity that manages a memory area of the memory-equipped device.
- the ticket issuance means is provided for each access device by individually issuing a service permission ticket (SPT) in which various access modes are set according to each access device. , An access in a different mode can be executed according to
- the memory-equipped device includes a file identification data of a file that has been subjected to a file open process based on a service permission ticket (SPT) received during a session with the access device.
- SPT service permission ticket
- the memory unit of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager.
- the file is stored in one of the one or more partition areas, and the device with the memory issues a process for an access request to the data file in each partition by a ticket issuing unit under the control of the partition manager. And, it is executed based on a description of a service permission ticket (SPT) inputted from the access device as a ticket using means to the memory mounted device.
- SPT service permission ticket
- the service permission ticket (SPT) includes a mutual authentication to be executed between the memory-equipped device and the access device that has output the ticket.
- the device with the memory includes the mutual authentication mode designation data designating the mode, wherein the memory-equipped device includes the service permission ticket (SPT).
- the mutual authentication according to the mutual authentication mode designation data is executed, and the processing according to the record of the received ticket is executed on condition that the authentication is established.
- the service permission ticket is a ticket verification designation designating a verification mode of the service permission ticket (SPT) received by the memory-equipped device.
- the memory-equipped device performs a ticket verification process in accordance with the ticket verification designation data of the service permission ticket (SPT), and records the received ticket on condition that the verification is completed. Characterized in that it has a configuration for executing a process according to.
- a fourth aspect of the present invention is that
- a computer program which causes a computer system to execute a computer access management process for managing an access process from an access device to a memory-equipped device having a memory portion capable of storing data from an access device.
- a program storage medium wherein the computer program comprises:
- a service permission ticket is received as an access control ticket in which an access mode permitted in an access device for executing access to the memory-mounted device is set, and the service permission ticket (SPT) is received. And a step of executing a process according to the access mode described in (1).
- a fifth aspect of the present invention provides:
- a data processing system that executes data processing on the memory unit in response to an access request from an access device to a device with a memory having a memory unit capable of storing data
- the memory-equipped device is configured to receive an access control ticket configured corresponding to data processing for the memory unit from the access device, and execute data processing based on a rule described in the access control ticket. And, based on the description of the access control ticket specified or received from the access device, determine and execute a method of mutual authentication with the access device, and describe the received access control ticket. How to verify access control tickets based on The data processing system is characterized in that it has a configuration that determines and executes an equation and responds to an access request from the access device on condition that both mutual authentication and ticket verification are established.
- the method of the mutual authentication is either a public key method or a common key method
- the verification method of the access control ticket is a public key method or a common key method.
- the memory-equipped device has a MAC verification key for performing verification of the access control ticket, and the access control ticket received from the access device. If the verification of the access control ticket is performed in accordance with the common key method, the falsification check process using the MAC verification key is performed. It is characterized in that signature verification processing is executed based on the public key of the ticket issuing means obtained from the public key certificate.
- the memory-equipped device has a plurality of MAC verification keys for executing the access control ticket verification, and the access control ticket received from the access device. It is characterized in that it is configured to select the MAC verification key to be applied according to the information recorded in the log.
- the access control ticket includes a data update ticket (DUT) that allows a process of updating data stored in a memory unit of the memory-equipped device
- the memory-equipped device has a plurality of MAC verification keys for executing the access control ticket verification, and the memory-equipped device is designated by a data update ticket (DUT) received from the access device.
- the update target data is a MAC verification key for performing access control ticket verification
- a data update received by selecting a MAC verification key that does not fall under the update target from a plurality of MAC verification keys is received. It is characterized in that it executes the verification process of the ticket (DUT).
- the memory unit of the memory-mounted device is managed by a corresponding partition manager.
- the memory-equipped device has at least one partition area as a memory area to be accessed, and the memory-equipped device issues a ticket under the control of each partition manager for processing an access request for data in each partition from the access device.
- the access control ticket is issued based on a description of an access control ticket input from the access device as a ticket using unit to the memory-mounted device.
- the memory section of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager.
- the device generates an authentication table in which the public key authentication information and the session key acquired by the partition authentication or the device authentication executed during the session with the access device or the common key authentication information and the session key are associated with each other. It is characterized in that it has a configuration to hold it during the session.
- a sixth aspect of the present invention provides
- a memory-equipped device having a memory part capable of storing data overnight
- Control means for executing data processing on the memory unit in response to an access request from an access device
- the control means receives an access control ticket configured corresponding to data processing for the memory unit from the access device, and executes data processing based on a rule described in the access control ticket.
- a memory-equipped device Based on the description of the access control ticket specified or received from the access device, a method of mutual authentication with the access device is determined and executed, and based on the description of the received access control ticket, A memory-equipped device characterized in that it determines and executes the access control ticket verification method and responds to the access request from the access device described above, provided that both mutual authentication and ticket verification are established. It is in.
- control means selectively executes either a public key method or a common key method as the mutual authentication method, and verifies an access control ticket.
- public key method or secret key method Is selectively executed.
- the memory-equipped device has a MAC verification key for executing the verification of the access control ticket, and the control unit receives the MAC verification key from the access device. If the verification of the access control ticket is performed according to the common key method, a falsification check process using the MAC verification key is executed,
- signature verification is performed based on the public key of the ticket issuing means obtained from the public key certificate of the ticket issuing means.
- the memory-equipped device has a plurality of MAC verification keys for executing the access control ticket verification, It is characterized in that a MAC verification key to be applied is selected in accordance with the information recorded in the received access control ticket.
- the access control ticket includes a data update ticket (DUT) that allows a process of updating data stored in a memory unit of the memory-equipped device
- the on-board device has a plurality of MAC verification keys for executing the access control ticket verification, and the control unit performs the update specified in the data update ticket (DUT) received from the access device. If the target data is a MAC verification key for executing access control ticket verification, a data update ticket (MAC update key) received by selecting a MAC verification key that does not fall under the update target from multiple MAC verification keys DUT) verification processing.
- DUT data update ticket
- the memory part of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager, and the control means
- the ticket issuing means under the control of each partition manager issues a process in response to an access request for data in each partition from the access device, and the access device serving as a ticket using device issues the memory mounted device.
- the access device serving as a ticket using device issues the memory mounted device.
- It is characterized in that it is executed based on the description of the access control ticket that is input by the user.
- the memory part of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager, and the control means Generating an authentication table in which the public key method authentication information and the session key obtained by the partition authentication or the device authentication executed during the session with the access device or the common key method authentication information and the session key are associated with each other; It is characterized in that it has a configuration to hold it during the session period.
- the seventh aspect is that
- an access control ticket configured corresponding to data processing for the memory unit, and executing data processing based on a rule described in the access control ticket
- the method of mutual authentication with the access device is determined and executed, and based on the description of the received access control ticket, A data processing method characterized in that a method of verifying an access control ticket is determined and executed, and an access request from the access device is executed on condition that both mutual authentication and ticket verification are established. Confuse.
- the mutual authentication method is either a public key method or a common key method
- the verification method of the access control ticket is a public key method or a common key method. It is characterized by one of the key systems.
- the memory-equipped device has a MAC verification key for performing verification of the access control ticket, and the access control received from the access device. Ticket verification is performed using the common key method. If the access control ticket is verified according to the public key method, the falsification check process using the MAC verification key is performed. It performs signature verification processing based on the public key of the ticket issuing means obtained from.
- the memory-equipped device has a plurality of MAC verification keys for executing the verification of the access control ticket, and the access received from the access device.
- a feature is that a MAC verification key to be applied is selected according to the information recorded in the control ticket.
- the access control ticket includes a data update ticket (DUT) that allows update processing of data stored in a memory unit of the memory-equipped device.
- the memory-equipped device has a plurality of MAC verification keys for executing the access control ticket verification, and the memory-equipped device has a data update ticket (DUT) received from the access device. If the data to be updated specified in () is a MAC verification key for performing access control ticket verification, select a MAC verification key that does not fall under the update target from multiple MAC verification keys. It is characterized by executing the verification process of the received data update ticket (DUT).
- the memory unit of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager.
- the memory-equipped device issues a process in response to an access request for data in each partition from the access device by ticket issuing means under the control of each partition manager, and the access device serving as a ticket using device issues the memory from the access device. It is executed based on the description of the access control ticket input to the mounted device.
- the memory unit of the memory-equipped device has one or more partition areas as memory areas each managed by a corresponding partition manager.
- the on-board device will perform the partition authentication or authentication performed during the session with the access device. Generates an authentication table in which public key authentication information and a session key obtained by device authentication or a common key authentication information and a session key are associated with each other, and holds the authentication table for the session period.
- an eighth aspect of the present invention provides
- a computer for causing a computer system to execute data processing on the memory unit in response to an access request from an access device to a memory-equipped device having a memory unit capable of storing data; a program storage medium for providing a program; The computer program
- a ninth aspect of the present invention is a
- a data access control system for issuing a command from an access device to a memory-equipped device having a memory unit capable of storing data overnight and executing a process on data stored in the memory unit,
- the memory-equipped device receives, from the access device, an access control ticket configured as access control data for the data stored in the memory unit, and executes an authentication rule described in the access control ticket.
- the data access control system is characterized in that the data access control system is configured to permit data access on condition that authentication based on the access control ticket is established and identification data of the access device described in the access control ticket is confirmed.
- the access control ticket includes a public key authentication method or a common key authentication method as an authentication method.
- the authentication type is described as authentication method designation information indicating that any one of them is permitted, and the device with memory executes an authentication process according to the authentication type described in the access control ticket received from the access device. It is characterized by having a configuration.
- the access control ticket stores a category or an identifier of a means for issuing the access control ticket
- the memory-equipped device receives the access control ticket from an access device. Based on the category or identifier of the access control ticket issuing means described in the specified access control ticket, a process for confirming that the ticket is issued by a valid issuing means is executed. The data access is permitted under the condition of the confirmation.
- the access control ticket stores a category or an identifier of a means for issuing the access control ticket, and the memory-equipped device receives the category from an access device.
- the access control ticket stores a category or an identifier of an access device that is a use unit of the access control ticket
- the memory-equipped device includes: On the basis of the category or identifier of the access device, which is a means of using the access control ticket described in the access control ticket received from the access device, the ticket is provided by a ticket provided by a valid use means.
- the present invention is characterized in that a confirmation process is performed to confirm that the data access is permitted on condition of the confirmation.
- the access control ticket stores a category or an identifier of a use means of the access control ticket, and the memory-equipped device receives the category from an access device.
- the category or identifier of the access device which is a means of using the access control ticket described in the access control ticket, and the user information stored in the public key certificate of the means of using the access control ticket.
- the ticket is confirmed to be a ticket provided by a legitimate use means, and data access is permitted on condition of the confirmation.
- the memory section of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager,
- the memory-equipped device corresponds to the public key authentication information and the session key obtained by the partition authentication or the device authentication executed during the session with the access device, or the common key authentication information and the session key. It is characterized by having a configuration for generating an attached authentication table.
- a tenth aspect of the present invention provides:
- a memory-equipped device having a memory part capable of storing data
- Control means for issuing a command from the access device to execute processing on data stored in the memory unit
- the control means includes:
- an access control ticket configured as access control data for data stored in the memory unit, establishing authentication based on the authentication rule described in the access control ticket; and
- the memory-equipped device is characterized in that data access is permitted under the condition that the identification of the access device described in the access control ticket is confirmed immediately.
- the access control ticket includes, as the authentication method designating information indicating that any one or both of a public key authentication method and a common key authentication method are allowed as the authentication method.
- the control means is configured to execute an authentication process in accordance with the authentication type described in the access control ticket received from the access device.
- the access control ticket includes a category or an identifier of a means for issuing the access control ticket.
- the control unit stores the ticket issued by the valid issuing unit based on the category or identifier of the issuing unit of the access control ticket described in the access control ticket received from the access device. A confirmation process is performed, and data access is permitted on condition of the confirmation.
- the access control ticket stores a category or an identifier of a means for issuing the access control ticket, and the control means controls the access received from the access device.
- the ticket is generated based on a comparison between the category or identifier of the access control ticket issuing means described in the control ticket and the user information stored in the public key certificate of the access control ticket issuing means. It is characterized in that it performs a process of confirming that a ticket has been issued by a valid issuing means, and permits overnight access on condition that the ticket is issued.
- the access control ticket stores a category or an identifier of an access device that is a use unit of the access control ticket, and the control unit includes an access control ticket. Based on the category or identifier of the access device that is the means of using the access control ticket described in the access control ticket received from the device, the ticket is a ticket provided by a legitimate use method. It is characterized in that it is configured to execute a confirmation process to confirm that there is a certain condition and permit data access on condition of the confirmation.
- the access control ticket stores a category or an identifier of a use unit of the access control ticket
- the control unit stores the access control ticket received from an access device.
- the comparison is made between the category or identifier of the access device, which is the means of using the access control ticket described in the control ticket, and the user information stored in the public key certificate of the means of using the access control ticket.
- the ticket is confirmed to be a ticket provided by legitimate use means, and data access is allowed on condition of the confirmation.
- the memory unit of the device has one or more partition areas each as a memory area managed by a corresponding partition manager, and the control unit executes partition authentication or device authentication performed during a session with the access device. And generating an authentication table in which the public key type authentication information and the session key or the common key type authentication information and the session key are associated with each other.
- the eleventh aspect of the present invention includes:
- the memory-equipped device receives, from the access device, an access control ticket configured as access control data for data stored in the memory unit, and performs authentication based on the authentication rule described in the access control ticket.
- a data access control method characterized in that data access is permitted on condition that the above conditions are satisfied and that the identification data of the access device described in the access control ticket is confirmed.
- the access control ticket includes an authentication method designating that any one of a public key authentication method and a common key authentication method is permitted as an authentication method.
- An authentication type as information is described, and the memory-equipped device performs an authentication process according to an authentication type described in an access control ticket received from an access device.
- the access control ticket stores a category or an identifier of a means for issuing the access control ticket, and the memory-equipped device includes an access device. Based on the category or identifier of the issuance means of the access control ticket described in the received access control ticket, a check is made to confirm that the ticket is a ticket issued by a valid issuance means, and Data access is permitted under the condition of the confirmation.
- the access control ticket stores the category or identifier of the access control ticket issuing means, and the memory-equipped device issues the access control ticket described in the access control ticket received from the access device.
- the ticket is issued by a valid issuing unit based on a comparison between the category or identifier of the unit and the user information stored in the public key certificate of the issuing unit of the access control ticket. And confirming that the data access is permitted on condition of the confirmation.
- the access control ticket stores a category or an identifier of an access device that is a use unit of the access control ticket
- the memory-mounted device includes: Based on the category or identifier of the access device that is a means of using the access control ticket described in the access control ticket received from the access device, the ticket is provided by a ticket provided by a legitimate use means.
- the present invention is characterized in that a confirmation process is performed, and data access is permitted on condition of the confirmation.
- the access control ticket stores a category or an identifier of a use unit of the access control ticket
- the memory-equipped device includes an The category or identifier of the access device that is the means of using the access control ticket described in the received access control ticket and the user information stored in the public key certificate of the means of using the access control ticket
- a confirmation process is performed to confirm that the ticket is a ticket provided by a valid use means, and data access is permitted on condition of the confirmation.
- the memory unit of the memory-equipped device has one or more partition areas each as a memory area managed by a corresponding partition manager.
- the device generates an authentication table in which the public key authentication information and the session key obtained by the partition authentication or the device authentication executed during the session with the access device or the common key authentication information and the session key are associated with each other. It is characterized by.
- the first and second aspects of the present invention include:
- a storage medium, wherein the computer program is:
- an access control ticket configured as access control data for data stored in the memory unit; and establishing authentication based on an authentication rule described in the access control ticket. And permitting data access on condition that the identification data of the access device described in the access control ticket is confirmed.
- a thirteenth aspect of the present invention provides:
- a memory access control system that controls memory access from an access device to a device with a memory that has a memory unit that stores a plurality of data files.
- the memory unit of the memory-equipped device is the memory unit of the memory-equipped device.
- the memory-equipped device includes:
- It has a configuration for receiving an access control ticket from the access device and executing an access process for a data file in accordance with the description of the access control ticket, and an access process for a plurality of data files based on the plurality of access control tickets.
- the device authentication as authentication for the memory-equipped device or the partition authentication as authentication for each partition storing the data file to be accessed is established as a condition. In the access control system.
- the authentication mode that can be set for each of the partitions is configured as access control data.
- the memory-equipped device receives the access control ticket from the access device, and determines an authentication mode required for each partition according to the description of the access control ticket. It is characterized by the configuration that performs
- the memory-equipped device performs a file access in a plurality of different partitions based on a plurality of access control tickets on condition that the device authentication is established.
- the feature is that the configuration is acceptable.
- the memory-equipped device includes a file access in a plurality of different partitions based on a plurality of access control tickets, for each of the different partitions. It is characterized in that the configuration is allowed under the condition that all the authentications of the partition authentication or device authentication, which are the authentication conditions set correspondingly, are established.
- the memory-equipped device includes a plurality of session keys obtained as a result of a plurality of authentication processes executed as file access conditions in a plurality of different partitions. And generating a unique integrated session key based on the integrated session key, and encrypting communication data with the access device based on the integrated session key.
- the memory-equipped device includes a plurality of session keys obtained as a result of a plurality of authentication processes executed as file access conditions in a plurality of different partitions.
- a unique integrated session key is generated by exclusive OR operation of each session key, and encryption processing of communication data with the access device is executed based on the integrated session key.
- the memory-equipped device includes a plurality of session keys acquired as a result of a plurality of authentication processes executed as file access conditions in a plurality of different partitions. , A single session key is selected, and encryption processing for communication with the access device is executed based on the selected session key. Further, in one embodiment of the memory access control system of the present invention, the memory-equipped device includes a public key method authentication information and a session key obtained by partition authentication or device authentication performed with the access device. Alternatively, an authentication table in which the common key type authentication information and the session key are associated with each other is generated and held for the duration of the session.
- a fifteenth aspect of the present invention provides:
- a memory-equipped device having a memory unit storing a plurality of data files, comprising control means for controlling memory access from an access device,
- the memory unit stores
- Each has at least one partition area as a memory area managed by a corresponding partition manager, and the data file has at least one partition area.
- the control means includes:
- An access control ticket is received from the access device, and an access process to a data file is executed in accordance with the description of the access control ticket, and an access to a plurality of data files based on the plurality of access control tickets is performed.
- the processing is performed on condition that device authentication as authentication for the memory-equipped device or partition authentication as authentication for each of the partitions storing the data file to be accessed is established. In the device with memory.
- the authentication mode that can be set for each of the partitions is described in an access control ticket configured as access control data.
- the access control ticket is received from an access device, and the control means determines a required authentication mode for each partition according to the description of the access control ticket.
- control means is configured to allow a file access in a plurality of different partitions based on a plurality of access control tickets on condition that the device authentication is established. Specially Sign.
- control means performs file access in a plurality of different partitions based on a plurality of access control tickets, in an authentication set corresponding to each of the different partitions.
- the feature is that the configuration is permitted under the condition that all the authentications of the partition authentication or the device authentication are completed.
- control unit determines only one based on a plurality of session keys obtained as a result of a plurality of authentication processes executed as a file access condition in a plurality of different partitions.
- the integrated session key is generated, and encryption processing for communication with the access device is executed based on the integrated session key.
- control unit determines only one based on a plurality of session keys obtained as a result of a plurality of authentication processes executed as a file access condition in a plurality of different partitions.
- the integrated session key is generated by an exclusive-OR operation of each session key, and encryption processing of communication data with the access device is executed based on the integrated session key.
- control means selects one of a plurality of session keys obtained as a result of a plurality of authentication processes executed as file access conditions in a plurality of different partitions.
- a unique session key is selected, and encryption processing for communication with the access device is executed based on the selected session key.
- control means includes a public key type authentication information and a session key, or a common key, obtained by partition authentication or device authentication performed with the access device. It is characterized in that an authentication table in which system authentication information and a session key are associated with each other is generated and held during the session.
- a fifteenth aspect of the present invention provides:
- a memory access control method for controlling memory access from an access device includes:
- the memory-equipped device includes:
- It has a configuration for receiving an access control ticket from the access device and executing an access process to a data file in accordance with the description of the access control ticket, and an access process to a plurality of data files based on the plurality of access control tickets.
- Memory access which is executed on condition that the device authentication as authentication for the memory-equipped device or the partition authentication as authentication for each partition storing the data file to be accessed is established. Control method.
- the authentication mode that can be set for each partition is described in an access control ticket configured as access control data. Receiving the access control ticket from the access device, and determining an authentication mode required for each partition # according to the description of the access control ticket.
- the memory-equipped device has a plurality of file access in different partitions based on a plurality of access control tickets on condition that the device authentication is established.
- the feature is to allow.
- the memory-equipped device sets file access in a plurality of different partitions based on a plurality of access control tickets in correspondence with each of the different partitions. It is characterized in that it is permitted under the condition that all the authentications of the partition authentication or the device authentication, which are the authentication conditions, are established.
- the memory-equipped device includes a file access condition in a plurality of different partitions.
- a unique integrated session key is generated based on the obtained plurality of session keys, and encryption of communication data with the access device is performed based on the integrated session key.
- the memory-equipped device is configured based on a plurality of session keys obtained as a result of a plurality of authentication processes executed as file access conditions in a plurality of different partitions.
- a unique integrated session key is generated by an exclusive OR operation of each session key, and encryption processing of communication data with the access device is executed based on the integrated session key.
- the memory-equipped device includes a plurality of session keys obtained as a result of a plurality of authentication processes executed as file access conditions in a plurality of different partitions.
- a unique session key is selected from the selected session keys, and encryption processing for communication with the access device is executed based on the selected session key.
- the memory-equipped device further includes a public key authentication information and a session key obtained by partition authentication or device authentication executed with the access device, or It is characterized in that an authentication table in which the common key type authentication information and the session key are associated with each other is generated and held for the session period.
- a sixteenth aspect of the present invention provides:
- a computer that causes a computer to execute a memory access control process for controlling a memory access from an access device to a memory-equipped device having a memory unit in which a plurality of data files are stored.
- a program storage medium that provides a program. Wherein the computer program is:
- An access process for a plurality of data files based on an access control ticket received from the access device on condition that the authentication in the authentication step is established is performed. Steps to perform;
- the program storage medium of the present invention is, for example, a medium that provides a computer program in a computer-readable format to a general-purpose computer system that can execute various program codes.
- the form of the medium is not particularly limited, such as a recording medium such as CD, FD, and MO, and a communicable medium.
- Such a program storage medium defines a structural or functional cooperative relationship between a computer program and a storage medium for realizing a predetermined combination program function on a computer system. It is. In other words, by installing the computer program in the computer system via the storage medium, a cooperative operation is exerted on the computer system, and the same operation and effect as in the other aspects of the present invention are obtained. You can do it.
- a system is a logical set of a plurality of devices, and is not limited to a device having each configuration in the same housing.
- FIG. 1 is a schematic diagram (part 1) of the system configuration for explaining the outline of the system configuration of the present invention.
- FIG. 2 is a system configuration schematic diagram (part 2) for explaining the outline of the system configuration of the present invention.
- FIG. 3 is a system configuration schematic diagram (part 3) for explaining a specific example of the system configuration of the present invention.
- FIG. 4 is a diagram for explaining the relationship between the access control ticket issuing means and the use means in the system of the present invention.
- FIG. 5 is a diagram showing a device configuration having a memory unit in the system of the present invention.
- FIG. 6 is a diagram showing a memory format of the device of the present invention.
- FIG. 7 is a diagram showing a device manager configuration in the system of the present invention.
- FIG. 8 is a diagram showing the configuration of the control means of the device manager in the system of the present invention.
- FIG. 9 is a diagram showing a configuration of a partition manager in the system of the present invention.
- FIG. 10 is a diagram showing the configuration of a reader / writer (R / W) in the system of the present invention.
- FIG. 11 is a diagram illustrating the format of a public key certificate that can be used in the system of the present invention.
- FIG. 12 is a diagram showing a signature generation processing method of the public key system that can be used in the system of the present invention.
- FIG. 13 is a diagram showing a signature verification processing method of the public key system that can be used in the system of the present invention.
- FIG. 14 is a diagram showing a data configuration of a manufacturing information block in data stored in the memory unit in the device of the present invention.
- FIG. 15 is a diagram showing a data configuration of a device management information block stored in the memory unit of the device of the present invention during the data transmission.
- FIG. 16 is a diagram showing a data structure of a public key device key definition block in data stored in the memory unit in the device of the present invention.
- FIG. 17 is a diagram showing a data structure of a common key-based development key definition block in data stored in the memory unit in the device of the present invention.
- FIG. 18 is a diagram showing a data configuration of a device key area in data stored in the memory unit in the device of the present invention.
- FIG. 19 is a diagram showing a data configuration of a partition definition block in data stored in the memory unit in the device of the present invention.
- FIG. 20 is a diagram showing a data configuration of a partition management information block during data storage stored in the memory unit in the device of the present invention.
- FIG. 21 is a diagram showing a data structure of a public key system partition key definition block in data stored in the memory unit in the device of the present invention.
- FIG. 22 is a diagram showing a data structure of a common key system partition key definition block in data stored in the memory unit in the device of the present invention.
- FIG. 23 is a diagram showing a data structure of a partition key area in data stored in the memory unit in the device of the present invention.
- FIG. 24 is a diagram showing a data configuration of a file definition block in data stored in the memory unit in the device of the present invention.
- FIG. 25 is a diagram for explaining the type of the structure of a file in data stored in the memory unit in the device of the present invention.
- FIG. 26 is a diagram showing a format of a partition registration ticket (PRT) as an access control ticket applied in the system of the present invention.
- FIG. 27 is a diagram showing a format of a file registration ticket (FRT) as an access control ticket applied in the system of the present invention.
- PRT partition registration ticket
- FRT file registration ticket
- FIG. 28 is a diagram showing a format (example 1) of a service permission ticket (SPT) as an access control ticket applied in the system of the present invention.
- FIG. 29 is a diagram for explaining types of file access modes using a service permission ticket (SPT) as an access control ticket applied in the system of the present invention.
- FIG. 30 is a diagram for explaining a file structure to be accessed using a service permission ticket (SPT) as an access control ticket applied in the system of the present invention.
- SPT service permission ticket
- FIG. 31 is a diagram showing a format (example 2) of a service permission ticket (SPT) as an access control ticket applied in the system of the present invention.
- FIG. 32 is a diagram showing a format of a data update ticket (DUT) as an access control ticket applied in the system of the present invention.
- FIG. 33 is a diagram for explaining a data update target using a data update ticket (DUT) as an access control ticket applied in the system of the present invention.
- FIG. 34 is a diagram for explaining an outline of processing up to device use in the system of the present invention.
- FIG. 35 is a diagram showing a device initial registration process flow by the device manufacturing entity in the system of the present invention.
- FIG. 36 is a diagram showing a device registration process flow (part 1) by the device manager in the system of the present invention.
- FIG. 37 is a diagram showing a device registration process flow (part 2) by the device manager in the system of the present invention.
- FIG. 38 is a diagram showing a device registration process flow (part 3) by the device manager in the system of the present invention.
- FIG. 39 is a diagram showing a device registration process flow (part 4) by the device manager in the system of the present invention.
- FIG. 40 is a diagram showing a device registration process flow (part 5) by the device manager in the system of the present invention.
- FIG. 41 is a diagram illustrating device storage data after the device initial registration process by the device manager in the system of the present invention.
- FIG. 42 is a diagram showing a public key certificate issuance processing flow (part 1) by the device manager in the system of the present invention.
- FIG. 43 is a diagram showing a public key certificate issuance processing flow (part 2) by the device manager in the system of the present invention.
- FIG. 44 is a diagram illustrating a process of issuing a public key certificate by a device manager in the system of the present invention.
- FIG. 45 is a diagram illustrating a process of issuing a public key certificate by a device manager in the system of the present invention.
- FIG. 46 is a diagram for explaining data stored in the device after the public key certificate issuance processing by the device manager in the system of the present invention.
- FIG. 47 is a diagram showing a flow of a partition generation / deletion process for a device in the system of the present invention.
- FIG. 48 is a flowchart (part 1) for explaining the mutual authentication process with a device in the system of the present invention.
- Fig. 49 shows the mutual authentication process with devices in the system of the present invention (development authentication). (2).
- FIG. 50 is a diagram for explaining a mutual authentication process of a public key system with a device in the system of the present invention.
- FIG. 51 is a diagram illustrating the configuration of an authentication table generated in a device after the mutual authentication process with the device in the system of the present invention.
- FIG. 52 is a diagram illustrating the configuration of an authentication table generated in the redirector after the mutual authentication processing with the device in the system of the present invention.
- FIG. 53 is a diagram illustrating a mutual authentication process using a common key method with a device in the system of the present invention.
- FIG. 54 is a diagram for explaining a mutual authentication process using a common key method with a device in the system of the present invention.
- FIG. 55 is a flowchart (part 3) for explaining the mutual authentication processing (partition authentication) with the device in the system of the present invention.
- FIG. 56 is a flowchart (part 4) for explaining a mutual authentication process (partition authentication) with a device in the system of the present invention.
- FIG. 57 is a flowchart (part 1) for explaining the validity of a ticket and the user check process in the system of the present invention.
- FIG. 58 is a flowchart (part 2) for explaining the validity of the ticket and the user check processing in the system of the present invention.
- FIG. 59 is a flowchart (part 1) for explaining the MAC generation method applicable to the validity of the ticket in the system of the present invention.
- FIG. 60 is a flowchart (part 1) for explaining partition creation and deletion operations in the system of the present invention.
- FIG. 61 is a flowchart (part 2) for explaining partition creation / deletion operations in the system of the present invention.
- FIG. 62 is a flowchart (part 1) illustrating the initial registration processing of a partition in the system of the present invention.
- FIG. 63 is a flowchart (part 2) illustrating the initial registration processing of a partition in the system of the present invention.
- FIG. 64 is a flowchart (part 3) for explaining the partition initial registration process in the system of the present invention.
- FIG. 65 is a diagram illustrating device storage data after the initial registration processing of a partition in the system of the present invention.
- FIG. 66 is a diagram (part 1) illustrating a process of issuing a public key certificate by the partition manager in the system of the present invention.
- FIG. 67 is a diagram (part 2) illustrating a process of issuing a public key certificate by the partition manager in the system of the present invention.
- FIG. 68 is a diagram for explaining processing in the case where public key authentication and public key ticket verification are executed in the partition generation processing by the partition manager in the system of the present invention.
- FIG. 69 is a view for explaining processing when public key authentication and common key scheme ticket verification are executed in the partition generation processing by the partition manager in the system of the present invention.
- FIG. 70 is a view for explaining processing in a case where a common key scheme authentication and a common key scheme ticket verification are executed in the partition generation processing by the partition manager in the system of the present invention.
- FIG. 71 is a view for explaining processing in a case where a common key scheme authentication and a public key scheme ticket verification are executed in the partition generation processing by the partition manager in the system of the present invention.
- FIG. 72 is a flowchart illustrating the file generation / erasure process using the file registration ticket (FRT) in the system of the present invention.
- FIG. 73 is a flowchart illustrating a file generation / deletion operation to which the file registration ticket (FRT) is applied in the system of the present invention.
- FIG. 74 is a diagram illustrating device storage data after file generation using the file registration ticket (FRT) in the system of the present invention.
- FIG. 75 is a view for explaining processing in a case where public key scheme authentication and public key scheme ticket verification are executed in the file generation processing by the file registration ticket (FRT) in the system of the present invention.
- FIG. 76 is a view for explaining processing in a case where public key scheme authentication and common key scheme ticket verification are executed in the file generation processing by the file registration ticket (FRT) in the system of the present invention.
- FIG. 77 is a view for explaining processing in a case where a common key scheme authentication and a common key scheme ticket verification are executed in the file generation processing by the file registration ticket (FRT) in the system of the present invention.
- FIG. 78 is a view for explaining processing in a case where a common key scheme authentication and a public key scheme ticket verification are executed in the file generation processing by the file registration ticket (FRT) in the system of the present invention.
- FIG. 79 is a diagram showing a file access processing port to which a service permission ticket (SPT) is applied in the system of the present invention.
- SPT service permission ticket
- FIG. 80 is a diagram showing a file opening operation port to which a service permission ticket (SPT) is applied in the system of the present invention.
- SPT service permission ticket
- FIG. 81 is a diagram (example 1) illustrating the configuration of a file open table generated by a file open operation using a service permission ticket (SPT) in the system of the present invention.
- SPT service permission ticket
- FIG. 82 is a diagram (example 2) illustrating the configuration of a file open table generated by a file open operation using a service permission ticket (SPT) in the system of the present invention.
- SPT service permission ticket
- FIG. 83 is a diagram (example 1) illustrating an example of a file access process to which the service permission ticket (SPT) is applied in the system of the present invention.
- SPT service permission ticket
- FIG. 84 is a diagram (example 2) illustrating an example of a file access process to which the service permission ticket (SPT) is applied in the system of the present invention.
- SPT service permission ticket
- FIG. 85 is a diagram illustrating handling of a session key generated by authentication in the system of the present invention.
- FIG. 86 is a flowchart (example 1) illustrating an example of a file access process to which the service permission ticket (SPT) is applied in the system of the present invention.
- SPT service permission ticket
- FIG. 87 is a flowchart (example 2) illustrating an example of a file access process to which the service permission ticket (SPT) is applied in the system of the present invention.
- FIG. 88 is a view for explaining an example of access processing of a compound file to which the service permission ticket (SPT) is applied in the system of the present invention.
- FIG. 89 is a view for explaining processing when public key authentication and public key ticket verification are executed in the file access processing by the service permission ticket (SPT) in the system of the present invention.
- SPT service permission ticket
- FIG. 90 is a view for explaining processing in the case where public key authentication and common key ticket verification are executed in the processing by the service permission ticket (SPT) in the system of the present invention.
- SPT service permission ticket
- FIG. 91 is a diagram for explaining processing in a case where a common key scheme authentication and a common key scheme ticket verification are executed in the processing by the service permission ticket (SPT) in the system of the present invention.
- SPT service permission ticket
- FIG. 92 is a diagram for explaining the processing in the case where the common key scheme authentication and the public key scheme ticket verification are executed in the processing by the service permission ticket (SPT) in the system of the present invention.
- SPT service permission ticket
- FIG. 93 is a diagram showing a data update processing flow by the data update ticket (DUT) in the system of the present invention.
- FIG. 94 is a diagram showing a data update operation flow by the data update ticket (DUT) in the system of the present invention.
- FIG. 95 is a view for explaining an example of the overnight update processing by the overnight update ticket (DUT) in the system of the present invention.
- FIG. 96 is a diagram showing a conventional memory structure.
- FIG. 97 is a diagram for explaining a conventional relationship between a memory manager and a user.
- FIG. 98 is a view for explaining conventional memory area securing processing.
- FIG. 99 is a diagram for explaining a conventional memory access method. BEST MODE FOR CARRYING OUT THE INVENTION
- a 7. Device specific information and device partition information area A 7. 2. Partition area
- FIG. 1 shows an overview of a data management system of the present invention.
- a memory-equipped device (hereinafter referred to as a device) 100 is manufactured by a device manufacturing entity (manufacturer) 500 and provided to a user under the management of a device manager (DM) 200 as a device management entity and used. .
- the device may be provided to the user in any form, such as lending or selling (including transfer).
- the memory area is divided into partitions as a plurality of data storage areas, and each partition (ParUtion ⁇ , ⁇ , ⁇ ) is composed of various service entities (A, ⁇ ,-). ⁇ ) It is used for various services under the management of the partition manager from 300 ⁇ to 300 0.
- a valid ticket issuer (Ticket Issuer) is issued for the partition setting registration processing for the device 100, the file setting registration processing in the partition set for the device, and the access processing for each registered file. Requires an access control ticket for the specified device.
- the partition setting registration process for device 100 requires a partition registration ticket (PRT) issued by a valid ticket issuer (Ticket Issuer).
- the file registration ticket (FRT: File Registration Ticket) issued by a valid ticket issuer (Ticket Issuer) is used to register the file settings in the application.
- SPT Service Permission Ticket
- Each ticket includes an access rule for the device 100, for example, a rule for a mutual authentication process between the device / writer and a reader / writer that performs various processes such as reading / writing to the device, and a partition registration ticket (PRT) for example. If it is a partition size that can be set, if it is a file registration ticket (FRT), it can be a file size that can be set, and if it is a service permission ticket (SPT), an executable access mode (ex. Data read, write Etc.), and information on ticket issuers, ticket users, and other information. In addition, an integrity check value (ICV) for falsification check of the data stored in the ticket is recorded, and the processing within the range recorded in the ticket can be executed on condition that the ticket is not falsified. The details of these tickets will be described later.
- PRT partition registration ticket
- the ticket issuing means (Ticket Issuer) for issuing the partition registration ticket (PRT) is set in the device manager (DM) 200, and is set in the service entity A, 30 OA as the partition manager.
- a ticket issuer (Ticket Issuer) that issues a file registration ticket (FRT) and a service permission ticket (SPT) is set.
- the configuration in Fig. 1 is basically the same for service entity B-Z and 300B-300Z as service entity A.
- Each service entity has a file registration ticket (FRT), And a ticket issuer (Ticket Issuer) that issues a service permission ticket (SPT) is set.
- the service entity and the partition manager are shown as the same entity, but these entities are not necessarily the same, and the partition as a memory area set in the device is not required.
- a partition manager to manage and a partition, a memory area managed by the partition manager, are borrowed from the partition manager under a predetermined contract, and various files are stored in the borrowed partition to provide services.
- the providing service entity may exist as a separate entity.
- the partition manager (PM) as each service entity 300A-300Z issues a partition registration ticket (PRT) to the device manager (DM) 200 under a predetermined contract, for example, by paying a corresponding price.
- a partition registration ticket PRT
- the ticket issuer (Ticket Issuer) in the device manager (DM) issues a request to the partition manager (PM) as the service entity.
- Each service entity (partition manager (PM)) 300 accesses the user's own device 100 via the communication interface (I / F), and registers the partition received from the device manager (DM) 200. Performs authentication, verification, and other processing in accordance with the rules recorded in the ticket (PRT), and executes the setting registration processing for partitions within the permitted range recorded in the partition registration ticket (PRT). This processing will be described later in detail.
- the communication I / F may be any interface that enables data communication with external devices (devices), whether wired or wireless.
- external devices devices
- the USB I / F is used.
- it is an IC card type, if it is a reader / writer for IC reader, a device with various communication functions such as public line, communication line, Internet, or a device that can be connected to these communication devices It is configured as a data communication I / F according to each communication method.
- each service entity 300 accesses the device 100 owned by the user via the communication interface (I / F), Performs authentication, verification, etc. according to the rules recorded in the file registration ticket (FRT) issued by the ticket issuer (Ticket Issuer) of each service entity 300, and executes the file registration ticket (FRT). Executes the setting registration process of the file within the permitted range recorded in. This processing will be described in detail later.
- each service entity 300 communicates via the communication interface (IZF). -Access to the device 100 owned by the user and perform authentication, verification, etc. according to the rules recorded in the service permission ticket (SPT) issued by the ticket issuer (Ticket Issuer) of each service entity. Execute the process and execute the access (ex. Data read, write, etc.) process within the permitted range recorded in the service permission ticket (SPT). This processing will be described later in detail.
- a code management organization 400 is set above the device manager 200 and the partition manager 300, and the individual device managers and the partition managers receive the code as identification information of each entity. The process of allocating one dollar is performed.
- the code assigned to each of these managers is used as storage data for access control tickets such as the partition registration ticket (PRT) and file registration ticket (FRT) described above.
- a device manager (DM) 200 that manages the provided device is set, and the device manager code and the like are provided in the provided device.
- the management information of the device manager is written. Details of these data will be described later.
- Figure 2 shows a device manager as a device management entity, and a code management organization that assigns identification codes to the two partition managers 300A, 300B and 200 as the management entities for each partition set in the device. 400 is shown. Further, in response to a public key certificate issuance request from a registration authority 210 under the jurisdiction of the device manager 200, the device manager 200 and each device under the jurisdiction of the device manager (partition registration ticket (PRT) issuance means (PRT Issuer) ) 210, or a device manager-compatible Certificate Authority (CA (DEV): 6100) that issues a device-related public key certificate (CERT-DEV) corresponding to device 100, 300A.
- PRT partition registration ticket
- PRT Issuer PRT Issuer
- CA device manager-compatible Certificate Authority
- FRT File registration ticket
- SPT service permission ticket issuing means
- Reader as a device access device that is a ticket user Writer 7 1 1 to 7 1 4, or a partition manager compatible certificate authority (CA (PAR): Certificate Authority) 620, 630 that issues a partition corresponding public key certificate (CERT-PAR) corresponding to the device 100 partition.
- CA partition manager compatible certificate authority
- the CAs are Device Manager-compatible CAs (Certificate Authority) for DM (or CA (DEV)) 610, and Partition Manager-compatible CAs are CA for PAR (or CA (PAR). )) 620 and 630 are shown separately, but there is only one certificate authority that has both functions, or a common certificate authority corresponding to multiple partition managers and a certificate authority corresponding to the depth manager Are provided separately, and the configuration is free.
- the device manager 200 and the partition managers 300A and 300B have their own public key certificates, public key certificates of devices (ticket issuing means, ticket users) managed by each manager, or devices.
- the public key certificate issuance request from 100 is accepted, the received issuance request is verified, and after verification, the certificate issuance request is transferred to the certificate authority, and the issued public key certificate is issued.
- Registration Authority RA: Registration Authority
- the public key certificate issued from each certificate authority (CA) 6100, 620, 630 via the registration authority (RA) 220, 330 is stored in the device 100, and For example, a partition setting process as a process, or a file setting process as a process for a partition, a mutual authentication process at the time of an access process to a file, etc., or a process for verifying the validity of each ticket described above. Used for Details of the public key certificate issuing process and each process using the public key certificate will be described later.
- device 100 is a partition manager as a partition, a management partition of 300 A, PM A Area, a partition manager 2, 300 B, and a management partition of 300 B: PM2. It has an area, and further has a DMA area as a management area of the device manager 200.
- the device manager 200 has a partition registration ticket issuing means (PRT Issuer) 210, and the partition manager 300 has a file registration ticket issuing means (FRT Issuer) 310 and a service permission ticket.
- Issuing means (S PT Issuer) 320 each issue a ticket.
- the partition manager 1, 300 A has a configuration in which each PRT, FRT, and SPT ticket has a dedicated reader / writer (interface for data read / write to devices) 7 1 1 to 7 13
- the partition manager 2, 300 B shows a configuration having a common leader / writer 14 for each ticket.
- the reader / writer can have various configurations as described above. Further, a specific example of the entity will be described with reference to FIG. Figure 3 assumes two service entities, Tozai Railway Co., Ltd. and Namboku Railway Co., Ltd., as partition managers as service entities that provide services using partitions set in the device.
- the figure shows an example of a device usage configuration assuming an organization called the Japan Railways Group as a device manager that registers settings for partitions with the partition manager.
- Tozai railway Co., Ltd. has set and registered multiple files in its own managed partition: PM1 set in the user's device. That is, a commuter pass file, a prepaid file, and other files.
- the partition manager as each service entity can register various files in the partition assigned by the device manager set according to the service provided by itself. However, a file registration ticket (FRT) is required to register file settings.
- FRT file registration ticket
- Tozai railway Co., Ltd. functions as a partition manager that manages one partition of the device: PMLaea.
- Partition PM L Area is certified and verified by the Japan Railway Group as a device manager according to the rules recorded in the Partition Registration Ticket (PRT) issued by the Japan Railway Group PRT Issuer. Is executed, and is set by the partition registration process within the permitted range recorded in the partition registration ticket (PRT), and is granted to East-West railway Company.
- PRT Partition Registration Ticket
- a commuter pass file and a prepaid file In the data storage area in the commuter pass file, for example, Record various data required as commuter pass management data, such as commuter pass user name, period of use, and section of use.
- the prepaid file records the user name, prepaid amount, balance data, and the like.
- processing such as authentication and verification in accordance with the rules recorded in the file registration ticket (FRT) issued by the East-West railway FRT Issuer is executed, and the file registration ticket (FRT) is used. It is set by the setting registration process of the file within the recorded permitted range.
- FRT file registration ticket
- the user can use to set the device to the ticket gate having a evening Ridarai as device access device by using the device It is.
- a legitimate reader / writer provided at the ticket gate accesses the commuter pass file and reads the use section.
- the prepaid file is accessed, and the balance data in the prepaid file is updated.
- the service issued by the East-West Railway Service Permission Ticket (SPT) issuer determines which file in the device is accessed and what processing (read, write, reduce, etc.) is executed. Recorded in the permission ticket (SPT). For example, a reader / writer as a legitimate device access device provided for a ticket gate stores these tickets, and performs processing such as authentication processing between devices and ticket verification according to the rules recorded in the tickets. Is executed. If the Reader / Writer as the device access device and the device are valid devices and the use ticket is valid, the processing within the permitted range (ex. File) recorded in the service permission ticket (SPT) Data reading, writing, etc.) will be executed.
- SPT East-West Railway Service Permission Ticket
- Ticket Issuer that issues various kinds of tickets, such as the partition registration ticket (PRT), file registration ticket (FRT), and service permission ticket (SPT).
- PRT partition registration ticket
- FRT file registration ticket
- SPT service permission ticket
- Figure 4 shows the general correspondence between ticket users who use tickets.
- the ticket issuer is under the control of a device manager or a partition manager, and has a partition registration ticket (PRT) corresponding to a process for a device. ), File registration ticket (F RT) and Service Permission Ticket (SPT).
- a ticket user is a device or means that uses a ticket issued by a ticket issuing means. Specifically, for example, a ticket user is a device that executes processing such as writing and reading data to and from a device. A device such as a reader / writer is equivalent.
- a ticket user can store and use a plurality of tickets.
- a service permission ticket SPT
- SPT service permission ticket
- the ticket gate for a railway company which is a service entity (partition manager), only reads the commuter pass, and only the service permission ticket (SPT) that permits reading of the section data of the commuter pass file described above is available.
- a reader / writer is set as a device access device that stores, and the unit reads data from the device owned by the user.
- a reader / writer as a device for accessing a ticket gate that executes both commuter pass and prepaid processing is provided with a service permission ticket (SPT) that permits only the reading of section data in the above commuter pass file, and a prepaid ticket.
- SPT service permission ticket
- partition registration ticket PRT
- file registration ticket FRT
- SPT service permission ticket
- FIG. 5 shows the configuration of the device.
- the device 100 has a CPU (Central Processing Unit) 101 having a program execution function and an arithmetic processing function, and is connected to an external device such as a reader / writer as a device access device.
- CPU Central Processing Unit
- a communication interface 102 having an interface function for communication processing, a ROM (Read Only Memory) 103 storing various programs executed by the CPU 101, for example, an encryption processing program, a load area of an execution program,
- RAM Random Access Memory
- the cryptographic processing unit 105 stores, for example, an EEP which stores device-specific information including various key data while setting and storing the above-described partitions and files. It has a memory section 106 constituted by a ROM (Electrically Erasable Programmable ROM). Information stored in the memory section 106 (ex. EPROM) 106 will be described in detail later.
- FIG. 6 shows the data storage configuration of the memory unit 106.
- the memory unit is, for example, a flash memory which is a form of an electrically rewritable nonvolatile memory called an ERPROM (Electrically Erasable Programmable ROM).
- ERPROM Electrically Erasable Programmable ROM
- the present embodiment has a data storage area of 32 bytes per block and a number of blocks of 0 XFFFF.
- the main area is a partition area, an unused area, device-specific information, and in-device partition information. Have an area.
- a partition which is a management area by the partition manager described above is set and registered. Note that the memory shown in Fig. 6 shows an example in which partitions have already been set, but a newly manufactured device has no partitions set and has no partition area.
- the partition manager as a service entity performs a predetermined procedure, that is, (1) Set the memory in the device according to the rules set in the registration ticket (PRT).
- the device-specific information and the in-device partition information area contain the device It stores information about the configuration entity, information about the device manager, configuration partition information, and key information required to execute the partition registration process by accessing the device. Details of these stored information will be described later.
- the data stored in the device unique information area can be used as data corresponding to ID m as a device unique value applied at the time of mutual authentication described later.
- the partition area further has one or more file areas, unused areas, partition specific information, and file areas in the partition.
- the file area is an area for storing a file set by the service entity as a partition manager for each service such as a commuter pass and a prepaid service as described above.
- the unused area is an area where a file can be further set.
- the partition specific information and the file information area in the partition store, for example, information about files in the partition, key information necessary for file access processing, and the like. Details of these stored information will be described later.
- the device manager is a management entity for devices provided (sold or lent) to users.
- the device manager 200 enables a partition setting for a device in response to a request from a partition manager serving as a service entity that provides a service using a partition set as a divided area of a memory unit in the device.
- the device manager 200 issues a device-compatible public key certificate (CERT-DEV) corresponding to the device.
- the device manager 200 receives a public key certificate issuance request from a device, verifies the received issuance request, and after verification, sends the certificate issuance request to a certificate authority (CA (DEV): Certif icate Authority).
- CA certificate authority
- RA Registration Authority
- the partition registration ticket (PRT) issuance means (PRT Issuer) 210 of the device manager 200 has a control means 211 and a data base 212, and has a data base.
- partition management ticket (PRT) issuance management data data for ticket issuance management, for example, a partition manager identifier, a ticket identifier, a ticket user (e X. Reader / writer, PC, etc.) Stores data associated with identifiers.
- a registration authority (RA) 220 has a control unit 221, and a database 222 for managing issuance of public key certificates. Stores the data in which the identifier of the device that issued the certificate, the identifier of the public key certificate (serial picker), etc. are associated.
- Control Means 211 is a Partition Registration Ticket (PRT) via data communication with the Partition Manager. Execute issuance processing.
- the control means 221 of a registration authority (RA) 220 executes a process of issuing a public key certificate to a device. At this time, communication with a device, a device manager-compatible certification authority (CA (DEV )) Execute communication with 6 10. The details of these processes will be described later.
- CA device manager-compatible certification authority
- the control unit 211 is constituted by a central processing unit (CPU) that executes various processing programs.
- R0M (Read only Memory) 2 1 1 2 is a memory that stores an execution processing program such as an encryption processing program.
- a RAM (Random Access Memory) 211 is a storage area for programs executed by the control unit 211, for example, an execution program such as a database management program, an encryption processing program, a communication program, and the like. Used as a work area.
- the display unit 211 has a display means such as a liquid crystal display device and a CRT. Under the control of the control unit 211, data is displayed during execution of various programs, for example, in data to be processed. Display the contents.
- the input unit 211 has a pointing device such as a keyboard, for example, a mouse, and outputs a command and a data input from each of these input devices to the control unit 211.
- the HDD (Hard Disk Drive) 2 1 16 stores programs such as a database management program, an encryption processing program, a communication program, and various data.
- the drive 211 is a magnetic disk such as an HD (Hard Disk) or FD (Floppy Disk), an optical disk such as a CD-ROM (Compact Disk ROM), a magneto-optical disk such as a mini disk, a ROM or a flash memory. It has a function to control access to various types of recording media such as semiconductor memories. Various recording media such as magnetic disks store programs, data, and the like.
- the communication interface 218 functions as an interface for communication via a wired or wireless network such as a network, a cable connection, and a telephone line, and each entity such as a user device, a partition manager, and a certificate authority. Functions as a communication interface with the device.
- the partition manager is a management entity for partitions set on devices provided (sold or lent) to users.
- the partition manager 300 uses the partition registration ticket (PRT) assigned by the device manager to assign a partition as a divided area in the memory section of the user's device according to the rule recorded in the assigned PRT. Set and provide services using the set partition.
- PRT partition registration ticket
- the file setting and data access processing are performed by the ticket user, that is, for example, a reader / writer as a dedicated device access device using the ticket.
- Partition Manager 300 provides a ticket for such tickets.
- ⁇ ⁇ ⁇ It has a file registration ticket (FRT) issuing means (FRT Issuer) 310 as service issuing means and a service permission ticket (SPT) issuing means (SPT Issuer) 320.
- FRT file registration ticket
- SPT service permission ticket
- the partition manager 300 issues a partitioning public key certificate (CERT-PAR) corresponding to each partition of the device.
- the partition manager 300 receives a request for issuing a public key certificate from a device, verifies the received request, and verifies the request for a public key certificate. After the verification, the certificate request (CA (PAR): 620) is issued. It has a function as a Registration Authority (RA) 330 that performs processing to transfer to the public key certificate and manages issued public key certificates.
- RA Registration Authority
- the file registration ticket (FRT) issuance means (FRT Issuer) 310 of the partition manager 300 has a control means 311 and a database 312.
- the ticket 312 includes, as issuance management data of the file registration ticket (FRT), data for managing issuance of a ticket, for example, an identifier of a ticket user (ex. Reader / writer, PC, etc.) of a ticket issuance destination; Stores data associated with a ticket identifier.
- the service permission ticket (SPT) issuing means (SPT Issuer) 320 of the partition manager 300 has a control means 321 and a database 322, and the database 322 is a service permission ticket (SPT).
- SPT service permission ticket
- Data for managing the issue of tickets such as the ticket issuer of the ticket issuer (ex. Reader / writer as a device access device, PC, etc.) identifier, ticket identifier, etc. Is stored.
- a registration authority (RA) 330 has a database 332 for issuing and managing public key certificates, and includes, as management data for issuing public key certificates, for example, a device identifier for issuing a public key certificate. , The partition identifier, the identifier of the public key certificate (serial picker), etc. are stored.
- the file registration ticket (FRT) issuance means (FRT Issuer) 310 of the partition manager 300 is a control means 311 of the ticket manager (ex. Reader / writer as a device access device, PC, etc.) Of the night
- the issuance processing of the isle registration ticket (FRT) is executed, and the control means 321 of the service permission ticket (SPT) issuance means (Ticket Issuer) 320 is operated by a ticket user (eX. Reader / writer as a device access device, Executes service permission ticket (SPT) issuance processing by data communication with PC, etc.).
- the control means 331 of the registration authority (RA) 330 executes a process of issuing a public key certificate to the device. At this time, communication with the device and a certificate authority (CA) corresponding to the partition manager are executed. (PAR)) Execute communication with the 620. The details of these processes will be described later.
- control means 311, 321, 331 of the partition manager 300 is the same as the control means of the device manager described above with reference to FIG. I do.
- the reader / writer as a device access device is configured as a device that performs various processes such as setting partitions for devices, setting files, reading and writing data, and subtracting and adding money data. Processing for the device follows the rules recorded in the partition registration ticket (PRT), file registration ticket (FRT), or service permission ticket (SPT) that apply during processing. That is, all processing for the device is restricted by these applied tickets.
- PRT partition registration ticket
- FRT file registration ticket
- SPT service permission ticket
- FIG. 10 shows a configuration example of a reader / writer as a device access device.
- a reader / writer 700 has a CPU (Central Processing Unit) 701 having a program execution function and an arithmetic processing function, and includes a device, a ticket issuer (Ticket Issuer), and the like.
- a communication interface 702 having an interface function for communication processing with devices, a ROM (Read Only Memory) 703 storing various programs executed by the CPU 701, for example, an encryption processing program, and loading of an execution program RAM (Random Access Memory) 704 that functions as a work area in each program processing, authentication processing with external devices, generation of digital signatures, verification processing, encryption of stored data, encryption processing such as decryption processing, etc.
- Run A memory section 705 composed of, for example, an electrically erasable programmable ROM (EEPR0M) that stores various key data for authentication processing, encryption and decryption processing, and reader / writer unique information.
- EEPR0M electrically erasable
- the data transmission side and the data reception side are mutually legal data. After confirming that it is the target of transmission and reception, the necessary information is transferred.
- encryption processing of transfer data, signature generation for data, and verification processing Is applied.
- the encrypted data can be returned to a decrypted data (plaintext) that can be used by a decryption process according to a predetermined procedure.
- a decrypted data plaintext
- Data encryption and decryption methods using an encryption key for such information encryption processing and a decryption key for decryption processing have been well known.
- a public key encryption method There are various types of data encryption / decryption methods using an encryption key and a decryption key, and one example is a method called a public key encryption method.
- Public key cryptography uses a different key for the sender and the receiver, one for the public key that can be used by unspecified users, and the other for the secret key that keeps the secret.
- the encryption key is a public key and the decryption key is a secret key.
- it is used in a mode in which the authenticator generation key is a secret key and the authenticator verification key is a public key.
- the public key encryption method has an advantage in key management because the secret key that needs to be kept secret must be held by a specific user. It is.
- the public key cryptosystem is slower in data processing speed than the common key cryptosystem, and is often used for objects with a small amount of data, such as private key distribution and digital signatures.
- a typical public key cryptosystem is RSA (Rivest-Shamir-Adleman) encryption. It uses the product of two very large prime numbers (for example, 150 digits) and takes advantage of the difficulty of factoring the product of two large prime numbers (for example, 150 digits).
- a public key can be used by an unspecified number of people, and a method of using a public key certificate to certify whether the public key to be distributed is valid or not is called a public key certificate.
- Many are used.
- user A generates a key for a public key and a secret key, sends the generated public key to a certificate authority, and obtains a public key certificate from the certificate authority.
- User A publishes the public key certificate to the public.
- An unspecified user obtains the public key through a predetermined procedure from the public key certificate, encrypts the document, etc., and sends it to User A.
- User A is a system that uses a secret key to decrypt an encrypted document.
- user A signs a document or the like using a private key, and an unspecified user obtains a public key through a predetermined procedure from a public key certificate and verifies the signature. It is.
- a public key certificate is a certificate issued by a certificate authority (CA) in public key cryptography, and when a user submits his / her ID and public key to the certificate authority, the certificate authority side It is a certificate created by adding information such as the ID of the certificate authority and the expiration date, and adding a signature by the certificate authority.
- CA certificate authority
- Figure 11 outlines the format of a public key certificate. The outline of each data is explained.
- the certificate version number indicates the version of the projected key certificate format.
- serial number of the certificate is a serial number (SN: Serial Number), which is the serial number of the public key certificate set by the public key certificate issuing authority (certificate authority: CA).
- the signature algorithm (algori thm) and algorithm parameters (parameters) of the signature algorithm identifier field (Signature algori thm Identifier) are fields that record the signature algorithm of the public key certificate and its parameters.
- the signature algorithms include elliptic curve cryptography and RSA. The parameters and key length are recorded when elliptic curve cryptography is applied, and the key length is recorded when RSA is applied. .
- the name of the Issuing Authority (Certificate Authority: CA) is a format (Distinguished Name) that can identify the issuer of the public key certificate, that is, the name (Issuer) of the public key certificate issuing authority (CA). This is the field recorded in.
- the start date and time and the end date and time which are the validity period of the certificate, are recorded.
- the identification data of the authentication target person who is the user is recorded. Specifically, for example, an identifier or category such as an ID of a user device or an ID of a service provider is recorded.
- the key algorithm (algorithm) and key (subject Public key) of the user public key field (subject Public Key Info) are the fields that store the key algorithm itself as the user's public key information and the key information itself. It is.
- user attribute data and other optional data for issuing and using public key certificates are recorded.
- attribute data a device manager code (DMC) and a partition manager code (PMC) are recorded as user group information.
- DMC device manager code
- PMC partition manager code
- the user is a user of the public key certificate, such as a device manager, a partition manager, a ticket user, a ticket issuing means, and a device.
- categories such as ticket users, ticket issuing means, entities such as devices, device managers and partition managers, and device types are recorded as category information.
- the partition registration ticket issuing means code PRTIC: PRT Issuer Code
- DMC device management code
- the partition manager also serves as a file registration ticket issuing means and a service permission ticket issuing means
- the file registration ticket issuing means code FRTIC: FRT Issuer Code
- SPTIC SPT Issuer Code
- PMC partition management code
- DMC Device Management Code
- PMC Partition Manager Code
- An issuing authority signature is an electronic signature that is executed on the data of a public key certificate using the private key of the public key certificate authority (CA). Verification is performed using the public key of the Certificate Authority (CA), and it is possible to check whether the public key certificate has been tampered with.
- CA public key certificate authority
- FIG. 12 is a flow of a process of generating digital signature data using EC—DSA ((Elliptic Curve Digital Signature Algorithm), IEEE P1363 / D3).
- ECC elliptic curve cryptography
- a similar public key cryptosystem for example, an RSA cryptosystem ((Rivest, Shamir, Adleman), etc. (ANSI X9.31)) may be used. It is possible.
- the base point on the curve be r the order of G
- K s be the secret key (0 ⁇ K s ⁇ r).
- a hash function is a function that takes a message as input, compresses it into data of a predetermined bit length, and outputs it as a hash value.
- a hash function it is difficult to predict the input from the hash value (output), and when one bit of the data input to the hash function changes, many bits of the noise value change.
- Another feature is that it is difficult to find different input data with the same hash value.
- MD4, MD5, SHA-1 or the like may be used, or DE S-CBC may be used.
- the final output value MAC (check value: equivalent to I CV) is the hash value.
- step S3 a random number u (0 ⁇ u ⁇ r) is generated, and in step S4, a coordinate V (Xv, Yv) obtained by multiplying the base point by u is calculated.
- a coordinate V (Xv, Yv) obtained by multiplying the base point by u is calculated.
- the mo dr is calculated, and it is determined whether or not d is 0 in step S8. If d is not 0, c and d are output as digital signature data in step S9. Assuming that r has a length of 160 bits, the digital signature data is 320 bits long. If c is 0 in step S6, the process returns to step S3 to generate a new random number again. Similarly, if d is 0 in step S8, the process returns to step S3 to generate a random number again.
- step S12 it is verified whether the digital signature data c and d satisfy 0 ⁇ c ⁇ r and 0 ⁇ d ⁇ r.
- step S18 Xp modr is calculated and compared with the digital signature data c. Finally, if the values match, the process proceeds to step S19, where it is determined that the electronic signature is correct.
- the data has not been tampered with, indicating that the person holding the private key corresponding to the public key generated the electronic signature.
- step S12 If the digital signature data c or d does not satisfy 0 ⁇ c ⁇ r, 0 ⁇ d ⁇ r in step S12, the process proceeds to step S20. If the point P is a point at infinity in step S17, the process proceeds to step S20. Furthermore, if the value of Xpmodr does not match the digital signature data c in step S18, the process proceeds to step S20.
- step S20 If it is determined in step S20 that the electronic signature is incorrect, it is known that the data has been falsified or that the person holding the private key corresponding to the public key has not generated the electronic signature.
- the device in the system of the present invention stores a device-specific public key certificate (CERT-DEV) issued to the device via the device manager's management and registration authority in the device.
- a public key certificate (CERT-PAR) corresponding to the partition issued to the partition of the device via the registration authority is stored in each partition of the device.
- These public key certificates are processed for the device, that is, the partition registration setting process using the partition registration ticket (PRT) and the file registration ticket (FRT) are applied.
- the device has a memory unit made up of, for example, EEPROM, and has as its main areas a partition area, an unused area, device-specific information, and an in-device partition information area.
- EEPROM electrically erasable programmable read-only memory
- the device-specific information and the in-device partition information area contain information on the device manufacturing entity, information on the device manager, configuration partition information, and key information required when executing access to the device and performing partition configuration registration processing. Is stored.
- Figure 14 shows the data structure of the Manufacturing Information Block.
- the numerical value of each area indicates the number of bytes.
- the configuration of the present embodiment has a one-block: 32-byte configuration.
- the gray portions in the figure may be encrypted data or may not be encrypted.
- the following information is stored in the Manufacturing Information Block.
- ID m is defined as a unique identifier of the device based on this information.
- the device unique identifier is obtained from the entire information written in the manufacturing information block (Manufacture Information Block), a part of the written information, or arithmetic data obtained based on the written information. It is also possible to adopt a configuration in which:
- FIG. 15 shows the data structure of the Device Management Information Block. The following data is stored in the Device Management Information Block.
- DMC Version The version of the device manager code (DMC). For example, it is used as a comparison condition when updating DMC.
- FIG 16 shows the data structure of a public key device key definition block (PUB).
- POB Public Key Definition Block
- Pointer Pointer to the block that stores the public key of the device manager compatible CA (CA (DEV)) that issues public key certificates via the registration authority under the jurisdiction of the device manager.
- CA device manager compatible CA
- CERTJEV Pointer Pointer to the block where the public key certificate of the device (Device) issued by the certification authority CA (DEV) is stored.
- CERT—DEV Size The size of the public key certificate of the device issued by the certification authority CA (DEV).
- the relocation list in the above data is a list of unauthorized devices, for example, a device exclusion list issued by the administrator of the device distribution system, and is a list of identification data of unauthorized devices. is there. If the device set in the reader / writer as a device access device is a device listed in the revocation list, take measures such as stopping the processing.
- the data update ticket (DUT: Data Update Ticket) in the above data is an access restriction ticket for permitting and restricting the update process when performing various update processes stored in the device. Like the PRT, FRT, and SPT tickets described above, this is a ticket that records access rules for devices. This data update ticket (DUT: Data Update Ticket) will be described in more detail later.
- FIG 17 shows the data structure of the common key system device key definition block (Device Key Definition Block (Common)). The following data is stored in the common key-related device key definition block (Device Key Definition Block (Common)).
- Pointer Pointer of master key for two-way individual key authentication (MKauth_DEV_A)
- Mkauth_DEV_A Size Size of master key for two-way individual key authentication (MKauth_DEV—A)
- Kauth_DEV_B Size The size of the key for two-way individual key authentication (Kauth—DEV—B)
- Kprt Pointer Pointer to the block that stores the MAC verification key (Kprt) of the partition registration ticket (PRT)
- Kprt Size Size of the MAC verification key (Kprt) of the partition registration ticket (PRT)
- Kdut_DEVl-4 Pointer to the block that stores the MAC key (Kdut) for the data update ticket (DUT)
- Kdut—DEV 4 Size Size of the MAC key (Kdut) for the data update ticket (DUT)
- IRL_DEV Pointer Pointer to the block where the device ID (Device ID) of the unauthorized device is stored as a device relocation list (Revocation List).
- IRL_DEV Size Size of Revocation List of Device
- Kdut_DEV There are four types of Kdut_DEV, which are used in pairs of (Kdut-DEVI, Kdut_DEV2) and (Kdut-DEV3, Kdut_DEV4).
- Kdut_DEVl, 3 is used for MAC generation
- Kdut_DEV2,4 is used for encryption.
- Fig. 18 shows the data structure of the device key area. The following data is stored in the Device Key Area. Each storage key in the device key area (Device Key Area) also stores version information. When the key is updated, the version is also updated.
- IRL_DEV Revocation list (Device), which registers the identifiers (IDs) of excluded devices (reader / writer as device access device, ticketer such as PC, ticket issuing means). ID))
- CRLJEV Revoked device that registered the public key certificate identifier (ex. Serial number: SN) of the excluded device (Device), the excluded device (a reader / writer as a device access device, a ticket user such as a PC, a ticket issuing means).
- Revocation List (Certmcate)
- Kdut.DEVl Key for verifying the MAC of the data update ticket (DUT)
- Kdut_DEV2 Encryption key for data update
- Kdut_DEV3 MAC key for data update ticket (DUT)
- CERTJEV Public key certificate of the device (Device) issued by the certification authority CA (DEV) that issues the public key corresponding to the device manager.
- the device key area (Device Key Area) shown in the figure stores Kauth-DEV_A: a common key for bidirectional individual key authentication, and MKauth-DEV-B: a master key for bidirectional individual key authentication. However, these keys may be configured not to be stored unless the device is requested to perform the common key authentication process. Kprt: The device also does not store the MAC verification key of the partition registration ticket (PRT). If the configuration does not execute the verification process, the configuration may not be stored.
- PRT partition registration ticket
- IRL_DEV Revocation List (Device ID) in which the device identifier (ID) of the exclusion device (Device) is registered
- CRL_DEV Public key certificate identifier of the exclusion device (Device) (ex. : Revocation List (Certificate), which has registered the SN), if there is no revoked device, or obtain the revocation list using another source. In this case, the revocation list may not be stored.
- Figure 19 shows the data structure of the Partition Definition Block. The following data is stored in the Partition Definition Block.
- PMC Partition Manager Code: Code (PMC) assigned to the Notification Manager (Partition Manager). For example a number.
- Partition Size Size of the partition (Partition)
- the above is the device specific information of the memory section of the device and each data of the partition information area in the device.
- the partition area is the management area of the partition manager.
- the partition manager As mentioned earlier, Depaisma Based on the PRT ticket issued by the partition registration ticket (PRT Issuer) managed by the manager, the partition manager as each service entity performs a predetermined procedure, that is, the partition registration ticket (PRT). ) Set in the memory in the device according to the rules set in).
- the data structure of the partition area will be described.
- Fig. 20 shows the data structure of a Partition Management Information Block. The following data is stored in the Partition Management Information Block.
- FIG. 21 shows the data structure of the projected key system partition key information block (Partition Key Definition Block (PUB)). The following data is stored in the public key partition key information block (Partition Key Definition Block (PUB)).
- Partition Key Definition Block Partition Key Definition Block
- Pointer Pointer to the block that stores the public key of the certification authority CA (PAR) that issues the public key certificate via the registration manager of the partition manager.
- PRI_PAR Pointer Pointer to the block in which the secret key of the partition (Partition) is stored
- CERT_PAR Pointer Pointer to the block that stores the public key certificate of the partition (Partition) issued by the certification authority CA (PAR).
- CERT_PAR Size The size of the public key certificate of the partition (Partition) issued by the certification authority CA (PAR)
- FIG. 22 shows a configuration of a common key type partition key information block (Partition Key Definition Block (Co-band)). The following data is stored in the common key system partition key information block (Partition Key Definition Block (Common)).
- Partition Key Definition Block Partition Key Definition Block (Co-band)
- Pointer Pointer of master key for two-way individual key authentication (MKauth_PAR_A)
- Mkauth_PAR_A Size Size of master key (MKauth_PAR_A) for two-way individual key authentication
- Kfrt Pointer Pointer to the block where the MAC verification key (Kfrt) of the file registration ticket (FRT) is stored.
- Kfrt Size Size of the MAC verification key (Kfrt) of the file registration ticket (FRT) * Kdut_PAIU-4 Pointer: Pointer to the block where the MAC key (Kdut) for the data update ticket (DUT) is stored.
- Kdut_PARl-4 Size The size of the key (Kdut) for MAC verification of the data update ticket (DUT).
- IRL_PAR Pointer Pointer to the block that stores the revocation list (Revocation List-Device ID) that stores the ID of the partition elimination device.
- Kdut_PAR There are four types of Kdut_PAR, which are used in pairs (Kdut_PARl, Kdut_PAR2), (Kdut_PAR3, Kdut_PAR4).
- Kdut—PARI 3 is used for MAC generation
- Kdut_PAR2 is used for encryption.
- FIG. 23 shows a data structure of a partition key area.
- the following data is stored in the Partition Key Area.
- version information is stored together with each storage key of the partition key area (Partition Key Area).
- Partition Key Area When the key is updated, the version is also updated.
- IRL—PAR Revocation list in which the identifier (ID) of the partition access exclusion device (Device) and the exclusion device (a reader / writer as a device access device, a ticket user such as a PC, and a ticket issuing means) are registered. (Revocation List (Device ID))
- CRL_PAR The public key certificate identifier (ex. Serial number: SN) of the partition access exclusion device (Device) and exclusion device (reader / writer as device access device, ticket user such as PC, ticket issuing means) Registered Revocation List (Certificate)
- Kdut_PARl Key for verifying the MAC of the data update ticket (DUT)
- Kdut PAR2 Data update encryption key
- Kdut_PAR3 Key for MAC verification of data update ticket (DUT)
- CERT_PAR Public key certificate of the partition (Partition) issued by Certificate Authority CA (PAR)
- Figure 24 shows the data structure of a file definition block (FDB: File Definition Block). The following data is stored in the File Definition Block.
- FDB File Definition Block
- Acceptable Authentication Type Indicates the acceptable authentication type.
- the access mode defined for each file structure type corresponds to each bit of this field (up to 16 in this example). Details will be described below.
- Acceptable Verification Type Indicates the acceptable verification type. For each file structure type, the defined access mode corresponds to each bit of this field (up to 16 in this example). Details will be described below.
- Kspt MAC key for service permission ticket (SPT) (Kspt)
- SPT service permission ticket
- Kspt The above-mentioned Acceptable Authentication Type includes the access mode defined for each File Structure Type and the bits of this field (up to 16 in this example).
- a permissible authentication type that is set to correspond For example, when executing a certain access mode, if the bit corresponding to the mode is set to 1, public key authentication has been completed and authentication has not been completed. Is not executed. As a result, when executing commands with higher importance (for example, payment processing), public key authentication is obligatory and security can be ensured.
- the Acceptable Authentication Type is different from the ticket and is stored in the device as a part of the file definition block (FDB: File Definition Block). This information is not changed after the file is created. Therefore, it is possible to provide the minimum guarantee of security by using it when you want to give a strong restriction that never changes the allowable authentication type.
- FDB File Definition Block
- the above Acceptable Verification Type is the access mode defined for each File Structure Type and each bit of this field (up to 1 in this example). 6) are allowable verification types that are set to correspond to each other. For example, when a certain access mode is executed and the bit corresponding to the mode is set to 1, the ticket using the public key method is used. It will not be executed unless the verification is completed.
- each field is divided into two bytes, so that only 16 access modes can be associated with each other.However, by increasing the field size as needed, more commands can be associated. It can be configured.
- the allowable authentication type (Acceptable Authentication Type) and the allowable verification type (Acceptable Verification Type) are set to “1”
- authentication or verification of the public key method is required.
- each of these fields is configured in units of 2 bits. If the value is “1 1”, the public key method is used.If the value is “01”, the common key method is used. In the case of “10”, it is also possible to set the subdivision such that the public key method and the common key method are both allowed.
- the file structure type (File Structure Type) in the above data is This is a code indicating the structure of the file generated in the action.
- Figure 25 shows an example of the correspondence between the file structure and the code.
- the file structure has various structures (File Structure) shown in Fig. 25, and codes 001 to 007 are assigned to each of them. The meaning of each structure is shown below.
- the data with this file structure is the money amount information data, and is a data file that can perform value change processing such as subtraction (Sub) and addition (Add).
- Cyclic Data with this file structure has a cyclic (Cyclic) file structure that can be written overnight.
- Log Data with this file structure is a log data file, which is a record information file for each piece of processing information.
- Composite file A file having a composite structure (EX. Purse and Log) of the above various file structures. Different codes are assigned to the composite file depending on the combination pattern (in the figure, 006: composite file 1, 007: composite file 2).
- the partition registration registration process (PRT: Partition Registration Ticket) issued by a valid ticket issuer (Partition Registration Ticket) and the partition set in the device are executed in the partition setting registration process for the device.
- the file registration ticket (FRT: File Registration Ticket) issued by the valid ticket issuer (Ticket Issuer) is used to register and register the file in the file. Also, the valid ticket is used to access each file.
- a Service Permission Ticket (SPT) issued by the issuing means (Ticket Issuer) is required. It was also explained briefly in the data description section of the memory section of the device described above. As described above, updating the stored data requires a data update ticket (DUT).
- Each of these tickets is composed of a data string that describes the access rules for the devis as binary data.
- the ticket is transmitted from the ticket user, for example, a reader / writer as a device access device to the device in response to the processing for the device.
- the device Upon receipt of the ticket, the device performs a ticket validity verification process. If the validity is successfully verified, various processes (ex. Partition generation, file generation, data generation, etc.) are performed according to the rules recorded in the ticket. Access) is executed.
- the data format of each of these tickets will be described.
- the partition registration ticket (PRT: Partition Registration Ticket) is an access control ticket applied at the time of partition setting registration processing for a device. Using the PRT issued by the Ticket Issuer under the legitimate device manager, follow the procedures recorded in the PRT and follow the procedures recorded in the PRT to the ticket manager under the jurisdiction of the partition manager (ex. By accessing the device with a writer, the partition can be set within the limits recorded in the PRT.
- FIG 26 shows the data format of the partition registration ticket (PRT).
- the data described below is stored in the partition registration ticket (PRT: Partition Registration Ticket).
- Authentication Flag Flag that indicates whether mutual authentication with the device is required in the process of using the ticket.
- Ticket User affiliation Group: Ticket user affiliation * Authentication Type: Mutual authentication type of the device (Public key authentication or symmetric key authentication, or any type (Any))
- [Authentication Type] is public key authentication: Distinguished Name (DN) or Category (Category) or serial number (SN) is used. Stored. In the case of common key authentication,: Authentication ID is stored. If authentication is not required, storage is not mandatory.
- DN Distinguished Name
- Category Category
- SN serial number
- Operation Type Specify whether to create or delete a Partition (Create / Delete)
- Partition Size Size of Partition
- Integrity Check Value Validity value of ticket (public key method: signature, common key method: MAC)
- partition registration ticket (PRT) When a ticket issued by the partition registration ticket (PRT) issuance means (PRT Issuer) is transmitted to the ticket user, the partition registration ticket (PRT) is used in the case of the public key method.
- PRT The public key certificate (CERT_PRTI) of the issuing means (PRT Issuer) is also sent together.
- the attribute (Attribute) of the public key certificate (CERT_PRTI) of the PRT issuing means matches the identifier (PRTIC) of the PRT issuing means (PRT Issuer).
- [Authentication Type] that records the type of mutual authentication of the device (Public key authentication or Common key authentication or Any) should be performed as mutual authentication using a ticket.
- the authentication type is recorded. The details will be described later in detail. Indicates that both authentications are to be performed, and whether the public key method or the common key method is to be performed, or whether both types of authentication are possible.
- the File Registration Ticket is an access control ticket applied when setting and registering a file in the partition set for the device.
- FRT File Registration Ticket
- Figure 27 shows the format of the file registration ticket (FRT: File Registration Ticket). The following data is stored in the file registration ticket (FRT: File Registration Ticket).
- Authentication Flag A flag that indicates whether mutual authentication with the device is required in the process of using the ticket.
- Authentication Type Mutual authentication type of the device (Public key authentication or symmetric key authentication, or any type (Any))
- [Authentication Type] is public key authentication: Distinguished Name (DN) or Category (Category) or serial number (CN) ) Is stored, and in the case of common key authentication,: Authentication ID is stored. If authentication is not required, storage is not mandatory.
- DN Distinguished Name
- Category Category
- CN serial number
- Operation Type Specify whether to create or delete a file (Generate / Delete)
- Acceptable Authentication Type A bit string that indicates the type of mutual authentication (either public key, public key, or secret key is required) required to execute the access mode for the file defined by this ticket.
- Kspt described in the File Definition Block Data Kfrt (Kspt) obtained by encrypting the MAC verification key Kspt of the service permission ticket (SPT) to be encrypted with the MAC verification key Kfrt of the file registration ticket of the partition
- Integrity Check Type Type of ticket validity verification value (Public key method (Public) / Common key method (Co plate on))
- Integrity Check Value Validity value of ticket (Public key method: Signature, Common key method: MAC)
- the file registration ticket (FRT) When transmitting a ticket (Ticket) issued by the file registration ticket (FRT) issuance means (FRT Issuer) to a ticket user, in the case of the public key method, the file registration ticket (FRT) is used.
- the public key certificate (CERT-FRTI) of the issuing means (FRT Issuer) is also sent together.
- the attribute (Attribute) of the public key certificate (CERT_FRTI) of the FRT issuing means matches the identifier (FRTIC) of the file registration ticket (FRT) issuing means (FRT Issuer).
- [Authentication Type] that records the type of mutual authentication of the device (Public key authentication or Common key authentication or Any) should be performed as mutual authentication using a ticket.
- the authentication type is recorded. More specifically, as will be described in detail later, it is specified that either device authentication, partition authentication, or both authentications be executed, and whether public key method or common key method is executed, or Information on whether authentication is also possible is recorded.
- the [Integrity Check Value] field that records the validity verification value of the ticket (public key method: Signature, common key method: MAC) is a file registration ticket if it is a public key method.
- a signature (see Fig. 12) based on the secret key of the issuing means (FRT Issuer) is generated and stored. If the partition manager itself also serves as a file registration ticket issuing means (FRT issuer), a signature is generated using the private key of the partition manager.
- the public key of the file registration ticket issuing means is used. Therefore, the device that performs the ticket verification must obtain the public key (public key certificate) of the file registration ticket issuing means (FRT Issuer) (ex, partition manager) upon receipt of the ticket or in advance.
- the Service Permission Ticket is a service permission ticket that accesses each data in the partition set for the device to read, write, subtract, and add money data. This is the access control ticket applied when executing.
- the ticket user ex. A reader / writer as a device access device accesses the device according to the procedure recorded in the SPT. Data processing can be performed within the limits recorded in the SPT.
- the service permission ticket (SPT: Service Permission Ticket) is a format that allows access to only one file among the files set in the partition, and also allows access to multiple files. Format, and each format is explained.
- Figure 28 shows the data format of the Service Permission Ticket (SPT), which is a format that permits access to only one of the files set in the partition. Show.
- SPT Service Permission Ticket
- the service permission ticket (SPT: Service Permission Ticket) stores the data described below.
- * Authentication Flag A flag that indicates whether mutual authentication with the device is required in the process of using the ticket.
- Ticket User affiliation Group: Ticket user affiliation
- Authentication Type Mutual authentication type of the device (Public key authentication or symmetric key authentication, or any type (Any))
- Integrity Check Value Validity value of ticket (Public key method: Signature, Common key method: MAC)
- the service permission ticket (SPT) When transmitting a ticket (Ticket) issued by the service permission ticket (SPT Issuer) to a ticket user, the service permission ticket (SPT) is used in the case of a public key method.
- the public key certificate (CERT_SPTI) of the issuing means (SPT Issuer) is also sent together.
- the attribute (Attribute) of the public key certificate (CERT_SPTI) of the SPT issuing means matches the (SPTIC) of the (SPT) issuing means (SPT Issuer).
- the code of the service permission ticket (SPT) issuance means (SPT Issuer) is set as the partition manager code (PMC). It is possible to
- [Authentication Type] that records the type of mutual authentication of the device (Public key authentication or Common key authentication or Any) should be performed as mutual authentication using a ticket.
- the authentication type is recorded.
- device authentication, partition authentication, or both authentications it is possible to specify that either device authentication, partition authentication, or both authentications be performed, and that either public key method or common key method be performed, or either authentication be possible Information about the event is recorded.
- Partition Manager upon receipt of the ticket. is necessary. After verifying the public key certificate (CERT_SPTI) of the service permission ticket (SPT Issuer), the service permission ticket (SPT Issuer) of the service permission ticket (SPT Issuer) extracted from the public key certificate (CERT_SPTI) is verified.
- the public key enables signature verification of ICV (Integrity Check Value).
- data generated as a file such as user identification data, amount data, encryption key data, log data, or composite file data, and access processing according to each data, that is, Data reading, writing, erasing, adding, subtracting, encrypting, decrypting ... will be performed on the access data.
- the File Access Mode of the Service Permission Ticket defines which access mode is permitted among these various access modes.
- Figure 29 shows the list of access modes.
- the access mode shown in Fig. 29 is an example, and other access modes can be set according to the data stored in the device. can do.
- FIG. 30 shows an example of such a file structure, a settable access mode, and a command transmitted from a reader / writer as a device access device to a device.
- FIG. 30 shows the access modes and command examples that can be set when the file structure is Random and when the file structure is a compound file.
- the file structure is R and om and the access mode is Read
- the only command that the depice can accept is [Read].
- the file structure is Random and the access mode is encrypted read (Read)
- the only command that the device can accept is encrypted read [EncRead].
- Allowed commands corresponding to the deposit system in file access mode define the above-mentioned Deposit Command, set the file access mode (File Access Mode) of the access permission ticket to [Payment], and set the file ID (File ID) as the electronic ID.
- SPT access permission ticket
- Deposit Command deposit amount data along with the deposit command
- the device holds the definition data of the command permitted for each file stored in the memory unit as a table as shown in FIG. 30, and the command input from the access device is defined in the definition data. Execute command only if it is a command.
- the definition of the commands allowed for the composite file includes a sequence command consisting of a plurality of commands executable for each of the plurality of files included in the composite file as described above.
- FIG. 31 shows the data format of a service permission ticket (SPT: Service Permission Ticket) that allows access to multiple files among the files set in the partition.
- the service permission ticket (SPT: Service Permission Ticket) stores the data described below.
- Authentication Flag Flag that indicates whether mutual authentication with the device is required in the process of using the ticket.
- Authentication Type Mutual authentication type of the device (Public key authentication or symmetric key authentication, or any type (Any))
- [Authentication Type] is public key authentication: Distinguished Name (DN) or Category (Category) is stored and shared.
- DN Distinguished Name
- Category Category
- Target File ID Identifier (ID) of the file (File) for which access is permitted
- Read / Write Permission Permission of the processing mode (Read, Write) for the file (Target File) to which access is permitted
- Integrity Check Value Validity value of ticket (Public key method: Signature, Common key method: MAC)
- a Group of Target File a group of files (File) to which access is permitted and recording it in the ticket, access to multiple files in the partition is the only service permission ticket.
- SPT When transmitting the ticket issued by the service permission ticket (SPT Issuer) described above to the ticket user, the service permission ticket in the case of the public key method is used.
- SPT The public key certificate (CERT_SPTI) of the issuing means (SPT Issuer) is also sent together.
- the attribute (Attribute) of the public key certificate (CERT_SPTI) of the SPT issuing means matches the identifier (SPTIC) of the service permission ticket (SPT) issuing means (SPT Issuer).
- [Authentication Type] that records the type of mutual authentication of the device (Public key authentication or Common key authentication or Any) should be performed as mutual authentication using a ticket.
- the authentication type is recorded. More specifically, as will be described in detail later, it is specified that either device authentication, partition authentication, or both authentications be executed, and whether public key method or common key method is executed, or Information on whether authentication is also possible is recorded.
- the service permission ticket (SPT) issuance means (SPT Issuer) extracted from the public key certificate (CERT—SPTI) ) Can be used to verify ICV (Integrity Check Value) signatures.
- a data update ticket (DUT: Data Update Ticket) is an access control ticket applied when accessing various data stored in a device and executing data update processing.
- DUT Data Update Ticket
- Ticket Issuer a valid data update ticket
- ticket user ex. A reader / writer as a device access device
- data processing can be performed within the limits recorded in the DUT.
- the data update ticket (DUT: Data Update Ticket) consists of a ticket DUT (DEV) applied to execute the update process of the data items managed by the device manager, and a partition managed by the partition manager.
- Ticket: DUT (DEV) issuing means is under the control of the device manager
- Ticket: DUT (PAR) issuing means is under the control of the partition manager.
- Figure 32 shows the data format of two data update tickets (DUT: Data Update Ticket) ⁇ DUT (DEV) and DUT (PAR). The data described below is stored in the Data Update Ticket (DUT).
- Ticket Issuer Device / partition manager identifier. If the type of ticket (Ticket Type) is DUT (DEV), DMC, DUT (PA),
- This field is data linked with [Authentication Type].
- [Authentication Type] is public key authentication: Distinguished Name (DN) or Category (Category) is stored, and common key authentication is performed. In case of: Authentication ID is stored. If authentication is not required, storage is not mandatory.
- Authentication Type Type of mutual authentication of the device (Public key authentication or Common key authentication, or any type (Any))
- New Data New data to be updated (may be encrypted).
- Integrity Check Value Validity value of ticket (Public key method: Signature, Common key method: MAC)
- Exact can be updated overnight if the value specified in the following [Data Version Condition] is the same.
- [Authentication Type] that records the type of mutual authentication of the device (Public key authentication or Common key authentication, or Any type) should be performed as mutual authentication using a ticket.
- the authentication type is recorded. More specifically, as will be described in detail later, it is specified that either device authentication, partition authentication, or both authentications be executed, and whether public key method or common key method is executed, or Information on whether authentication is also possible is recorded.
- the code of the DUT (DEV) issuing means (DUTIssuer) is used.
- Ticket User 1 can be set as a device manager code (DMC).
- DMC device manager code
- PAR data update ticket-DUT
- PAR data update ticket-DUT
- DUT Issuer the code of the data update ticket DUT (PAR) issuance means
- PMC jar code
- [Authentication Type] that records the type of mutual authentication of the device (Public key authentication or Common key authentication or Any) should be performed as mutual authentication using a ticket.
- the authentication type is recorded. More specifically, as will be described in detail later, it is specified that either device authentication, partition authentication, or both authentications be executed, and whether public key method or common key method is executed, or Information on whether authentication is also possible is recorded.
- the device update packet is used.
- a signature (see Fig. 12) based on the private key of the DUT Issuer is generated and stored.
- DUT Issuer a signature is generated using the secret key of the device manager.
- DUT Issuer a signature is generated using the secret key of the partition manager.
- the public key of the device manager or the partition manager is used in the signature verification process (see Fig. 13). Therefore, the device performing the ticket verification must obtain the public key (public key certificate) of the device update ticket issuing means (DUT issuer) (ex. Device manager or partition manager) upon receipt of the ticket or in advance. is necessary.
- the public key of DUT Issuer enables signature verification of ICV (Integrity Check Value).
- Figure 33 shows an example of data that is updated by applying a data update ticket (DUT: Data Update Ticket).
- the data to be updated includes a device manager code, a device manager code version, a partition manager code, a partition manager code, and each ticket issuing means. Includes code, MAC generation key and version for each ticket, repock list, etc.
- Each of these data to be updated is updated according to the rules recorded in the DUT by applying the Data Update Ticket (DUT). The specific procedure of the update process will be described later using a flow. Note that the device management code, the version number of the partition management code, and other version information will be updated together with the update processing of the data added to each version. . These version information is stored in the Data Update Ticket (DUT).
- a device having an EE PROM flash memory
- EE PROM flash memory
- a device manufacturing entity manufactured by a device manufacturing entity (manufacturer)
- an initial data write is executed by a device manager
- the device is provided (ex. Sold, leased) to a user.
- partitions are set up by the partition manager in the memory of the device, and the data for service provision is stored in the set partitions. File must be set.
- various processes for the device that is, partition settings using the partition registration ticket (PRT), file settings using the file registration ticket (FRT), and service permission tickets (SPT) are used.
- various procedures are executed between the device and the ticket user (ex. Reader / writer as a device access device) that executes the process on the device. For example, mutual authentication processing to confirm that both are valid devices and devices, or signature generation and verification processing to guarantee and confirm the validity of transferred data, as well as data encryption and decryption processing.
- the configuration of the present invention proposes a configuration using a public key certificate for these processes. Therefore, the public key certificate issuance process for the device and the device storage process are executed before the use of the service by the device.
- FIG. 34 is a diagram schematically showing the flow from device manufacturing to use. Each of these processes will be described in detail later with reference to the flow. However, in order to understand the overall process, each stage shown in FIG. 34 will be briefly described.
- the device is manufactured by a manufacturing entity.
- a device code as identification data (ID) of each device is assigned to each device.
- various manufacturing information Manufacture Information Block (see Fig. 14)) such as device code and manufacturing code is written to the device and stored in the device memory.
- the device manager sends the device management information (Device ID, Public key of the certificate authority (PUBCA (DEV))).
- Management Information such as Management Information (see Fig. 15)
- Device Key see Fig. 18
- the device with the management information written by the device manager is provided to the user.
- the user executes the process of obtaining a public key certificate for the device, and stores the obtained public key certificate for the device (CERTDEV) in the device key area of the device (see Fig. 18).
- CERTDEV public key certificate for the device
- the service entity (partition manager) who sets a partition in the memory part of the device and intends to provide a service requests the partition manager from the device manager, obtains the license, and issues a partition registration ticket (PRT). To receive. Also, specify the public key (PUB C A (PAR)) of the certificate authority used in the communication process with the device.
- PRT partition registration ticket
- the device communicates with a ticket manager (ex. Reader / writer as a device access device) managed by the partition manager, and registers the partition using the partition registration ticket (PRT).
- the public key (PUB CA (PAR)) of the certification authority is stored in the partition key area (see Fig. 23).
- the device in which the partition has been set sends a request for issuance of a partition-compatible public key certificate to the partition manager, and obtains the obtained partition pair.
- the public key certificate (CERT PAR) is stored in the partition key area (see Fig. 23).
- the above processes 5 to 7 for setting a partition and other processes are executed for each partition manager that intends to provide a service by setting a partition, and a plurality of partitions are registered in the device.
- the partition manager executes, for example, a service setting file setting registration process by applying a file registration ticket (FRT) in the partition set in the device.
- FRT file registration ticket
- the service permission ticket is applied to processes such as reading and writing data in a file. That is, only when the service permission ticket (SPT) issued by the valid ticket or ticket issuing means is applied, data reading, writing, etc. are executed in accordance with the rules recorded in the SPT.
- data to be updated (ex. Device management code, device management code, etc.) in the data stored in the device may be used as necessary using a data update ticket (DUT).
- Update processing of the version, partition manager code, partition manager code version, each ticket issuing means code, MAC generation key and version of each ticket, revocation list, etc.) is executed.
- the version information of the release manager, the version manager, and the version information of the partition manager are updated together with the update processing of the data added to each version. Will be.
- These version information is stored in a data update ticket (DUT).
- Fig. 35 shows the processing of the registration device of the device manufacturing entity (Manufacture), and the right side shows the processing of the device (see Fig. 5).
- the device manufacturing The registration device of the manufacturer (Manufacture) is configured as a reader / writer (see Fig. 10) as a dedicated device access device that can read and write data to the device.
- step S101 the registration device transmits a read command of a write flag (Writable Flag) of a manufacturing information block (MIB: Manufacture Information Block (see Fig. 14)) to the device.
- a write flag Writeable Flag
- MIB Manufacturing Information Block
- the registration device that has received the write (Writable) flag in the manufacturing information block (MIB) (S102) determines whether or not the write flag (WritableFlag) is set to writable (0Xffff) (S10). 1 03). If the writable flag (Writable Flag) is not set to writable (Oxffff), the following manufacturing information block (MIB: Manufacture Information Block) cannot be written, and the process ends with an error.
- MIB Manufacture Information Block
- writable flag (Writable Flag) is set to writable (0xffff)
- MIB Manufacture Information Block (see Fig. 14)
- S104 a device manufacturing information block
- the MIB data is transmitted to the device along with the command (S105).
- the device that receives the MIB write command and the MIB data verifies the MIB write flag (Writable Flag) (S124), and sets the write flag (Writable Flag) to writable (0xffff). If it is not set, the following manufacturing information block (MIB: Manufacture Information Block) cannot be written, and the process ends with an error. If the write flag (Writable Flag) is set to be writable (Oxffff), the received MIB data is written to the MIB area (S125).
- MIB Manufacture Information Block
- a write completion notification is transmitted to the registration device (S126).
- the registration device that has received the write end notification (S106) sends an initial registration completion command to the device (S107), and the device that receives the initial registration completion command (S127) sends the manufacturing information block (S127).
- MIB Manufacture Information
- the write flag (Writable Flag) of the Block is set to non-writable (0x0000) (S128), and a write completion notification is transmitted to the registration device (S129).
- the registration device Upon receiving the write completion notification (S108), the registration device transmits a read command of the write flag (Writable Flag) of the manufacturing information block (MIB: Manufacture Information Block (see Fig. 14)) to the device ( S 1 09) Yes.
- the device Upon receiving the command (S130), the device transmits a write flag (Writable Flag) in the manufacturing information procedure (MIB) of the memory section of the device to the registration device (S131).
- the registration device that has received the write flag (Writable Flag) in the manufacturing information block (MIB) determines whether or not the write flag (Writable Flag) is set to write disabled (0 X 0000). It is determined (S111). If the write flag (Writable Flag) is not set to write-disabled (0x00000), it indicates that normal MIB data write processing has not been completed, and the processing ends as an error. If the write flag (Writable Flag) is set to write-disabled (0x00000), the process ends assuming that the normal MIB data write process has been completed.
- the device manager processes that are executed before the use of the device include the device management information block (DMIB) in the memory part of the device and the device key definition block (DKD B). (PUB)) Device key definition block (DKDB: Device Key Area), a device registration process executed as a process of writing data to a device key area (Device Key Area), and a device. There is a process to issue a public key certificate (CERT DEV) corresponding to the DePies for the.
- DMIB device management information block
- DKD B device key definition block
- CERT DEV public key certificate
- the left side shows the processing of the initial registration device of the device manager (DM)
- the right side shows the processing of the device (see Figure 5).
- the initial registration device of the device manager (DM) is a device that can read and write data to the device (e.x., a reader / writer as a device access device, a PC). It has a configuration corresponding to a reader / writer.
- step S201 a read command of the device identifier IDm is output to the device.
- the device receives the command (S211) and transmits the device identifier IDm to the registration device (S212).
- step S203 the registration device that has received the device identifier ID m (S202) writes the device management information block (DMIB: Device Management Information Block (see FIG. 15)) write flag (see FIG. 15) for the device.
- DMIB Device Management Information Block
- Step S2113 the device transmits a write flag (Writable Flag) in the device management information block (DMIB) in the memory section of the device to the registration device (S214).
- the registered device that has received the write flag (Writable Flag) in the device management information block (DM IB) determines whether or not the write flag (Writable Flag) is set to writable (0Xffff). Is determined (S205). If the writable flag (Writable Flag) is not set to writable (0xffff), the following device management information block (DMIB: Device Management Information Block) cannot be written, and an error occurs. Exit as one. If the writable flag (Writable Flag) is set to writable (0xffff), send the device manager code (DMC) and the DMC version write (DMC Write) command to the device (S206). . This code is data that has been pre-assigned to the device manager by the code management organization (see Figs. 1 to 3).
- the device that has received the DMC Write command verifies the DMIB write flag (Writable Flag) (S216), and the write flag (Writable Flag) is set to writable (Oxffff). If not, follow the device management
- the write processing of the information block (DM IB: Device Management Information Block) cannot be executed, and the processing ends with an error.
- the write flag (Writable Flag) is set to writable (Oxfffff)
- the received device management code (DMC) and DMC version are written to the DMIB area (S21 Device Manager
- a write end notification is transmitted to the registration device (S218).
- the device sends a Device Total Block Number write command to the device (S208)
- the device that receives the Device Total Block Number write command (S219) sends the DM IB write flag (Writable) to the device. Flag (S 220), and if the writable flag (Writable Flag) is not set to writable (0xffff), the following device management information block (DM IB: If the write flag (Writable Flag) is set to writable (0xffff), the total number of received device blocks (Device Total Block) cannot be executed. Number) is written to the DMIB area (S221), and the device writes TB-4 to the device free block number information area (Free Block Number in Device) in the DMIB area (S222).
- TB stands for Device Total Block Number
- 4 blocks of TB-4 are MIB (Manufacture Information Block) and Device Management Information Block (DM IB: Device Management) Information Block), Public Key Device Key Definition Block (DKB: Device Key Definition Block (PUB)), Common Key Device Key Definition Block (DK DB: Device Key Definition Block (Common)) ing.
- MIB Manufacture Information Block
- DM IB Device Management Information Block
- DKB Public Key Device Key Definition Block
- DK DB Device Key Definition Block (Common))
- the device writes 0 in the partition number (Partition Number) area of the device management information block (DM IB) (S223). At this point, no partitions have been set for the device. Further, 0 is written into the pointer of the free area of the DMIB (Pointer of Free Area) (S224), and the completion of the writing process is transmitted to the registration device (S225).
- the registration device that has received the write processing completion notification from the device (S209) determines whether to use a common key for device authentication (S231). The authentication process will be described in detail later, but it is possible to execute either the public key authentication method or the common key authentication method, and the device manager can set the necessary authentication method for the device. It becomes possible.
- the device manager sets the information required for symmetric key authentication (ex. Key for generating an authentication key, etc.) to the device, and the device performs symmetric key authentication. If it is a device that does not execute, this information will not be stored in the device.
- the depth manager sets in the device data that can execute either common key authentication, public key authentication, or both methods.
- steps S232 to S233 and S241 to S245 are performed.When no common key is used for the Depeise authentication, these steps are performed. Omitted.
- step S232 the registration device sends a common key authentication data write command as MKauth—DEV_A: master key for bidirectional individual key authentication, Kauth—DEV—B: bidirectional individual key authentication Common key, IRL—DEV: Revocation List (Device ID) in which the device identifier (ID) of the exclusion device (Device) is registered, and the version information thereof are transmitted to the device.
- Step S 24 the device receives the above-mentioned write command.
- step S242 the device confirms that the write flag (Writable Flag) of the DMIB is writable, and stores the received data in the decryption key area (see FIG. 18).
- Write (S243) Next, the pointer, size, and number of free blocks in the device generated by data writing are adjusted (S244), and the write is completed. Send a notification to the registration device to signal (S 245).
- the registration device that has received the write end notification determines in step S234 whether to use a public key for device authentication. As shown in FIG. 37, if a public key is used for device authentication, steps S235 to S239 and S246 to S254 are performed.If a public key is not used for device authentication, these steps are omitted. Is done.
- the registration device sends a public key authentication data write command as PUB_CA (DEV): the public key of a certification authority CA (DEV) that issues a public key corresponding to the depth manager.
- PUB_CA PUB_CA
- PARAM_DEV Public key parameter of the device (Device)
- CRL— DEV Revocation list (Certificate of public key certificate identifier of the exclusion device (Device) (ex. Serial Namer: SN)) ), And these version information are transmitted to the device.
- step S246 the device receives the above-described write command.
- step S246 the device confirms that the write flag (Writable Flag) of the DMIB is writable, and stores the received data in the device key area ( (See Fig. 18).
- the pointer, size, and number of free blocks in the device generated by the data writing are adjusted (S249), and a write completion notification is transmitted to the registration device (S250).
- the registration device that has received the write end notification (S236) transmits a key-key generation command of the public key and the secret key to the device (S237).
- the key pair is generated by the device, but the key pair may be generated by the registration device and provided to the device.
- the device that receives the key pair generation command (S251) generates a pair of a public key (P UB D EV) and a secret key (PRIDEV) in the encryption processing unit (see Fig. 5) in the device, and generates the pair.
- the generated key is written to the decompile key area (see Fig. 18) (S252).
- the public key (P UB D EV) is temporarily stored in the CERT / DEV area of the device key area, and then released when the public key certificate containing the public key (P UB DEV) is received. Replaced by a key certificate (CERT).
- CERT key certificate
- the pointer, size, and the number of free blocks in the device generated by data writing are adjusted (S253), and the generated and stored public key is transmitted to the registration device (S254).
- the registration device receives the public key (PUB D EV) from the device and the database in the device manager (DB (DEV) (see Fig. 7)), together with the device identifier ID m previously received from the device. To save.
- the registered device of the device manager checks the partition registration ticket (PR T: It is determined whether a common key is used for the verification process of the Partition Registration Ticket (S261).
- the ticket verification includes a common key method using MAC value verification and the like, and a signature generation using a private key and a signature verification using a public key described with reference to FIGS. 12 and 13 described above. It is possible to apply any of the public key methods to be performed, and the device manager can set the verification processing method adopted by the device.
- the device manager sets a device that can execute either the common key, the public key, or both depending on the PRT ticket verification method adopted by the device.
- the device manager performs symmetric key authentication, the device manager sets the information necessary for PRT verification using the common key method (ex. PRT verification common key) in the depice, and the depe If the device does not perform authentication, this information will not be stored in the device.
- the common key method ex. PRT verification common key
- steps S262 to 263 and S271 to S275 are performed. If the common key method is not used for PRT verification, these steps are omitted. Is done.
- the registration device transmits Kprt: the MAC key of the partition registration ticket (PRT) and version information as a PRT verification common key write command. Send to device.
- Kprt the MAC key of the partition registration ticket (PRT) and version information as a PRT verification common key write command.
- step S271 the device receives the above-described write command.
- step S272 the device confirms that the write flag (W tableFlag) of the DMIB is writable, and stores the received data in the device key area (FIG. 1). 8) (S273).
- step S274 the pointer, the size, and the number of free blocks in the device generated by the data writing are adjusted (S274), and a write completion notification is transmitted to the registration device (S275).
- the registration device that has received the write end notification determines whether or not to use a public key for PRT verification in step S264. As shown in FIG. 38, if a public key is used for PRT verification, steps S265 to S266 and S276 to S282 are performed.If a public key is not used for PRT verification, these steps are performed. Omitted.
- the registration device sends a PRTIC (PUT Issuer Category): partition registration ticket (PRT) issuer category as a ⁇ R ⁇ verification data write command, PUB_CA (DEV): Public key of the CA (DEV) that issues the public key corresponding to the device manager, PARAM_DEV: Public key parameter of the device, CRL— DEV: Public key certificate identifier of the excluded device (Device)
- the revocation list (Revocation List (Certificate)) in which (ex. Serial number: SN) is registered, and the version information are transmitted to the device.
- step S276 the device receives the above-described write command.
- step S277 the device confirms that the write flag (Writable Flag) of the DMIB is writable.
- PRTIC PRT Issuer Category: Writes the partition registration ticket (PRT) issuer category to a public key device key definition block (DKDB) (see Figure 16) and writes version information. Write to the version area of the block.
- step S279 the device determines whether or not the public key data of PUB—CA (DEV): a certification authority CA (DEV) that issues a public key corresponding to the device manager has been written. If not, in step S280, write PUB_CA (DEV), PARAM_DEV, and CRL_DEV to the device key area (see Fig. 18). Next, the pointer, the size, and the number of free blocks in the device generated by data writing are adjusted (S281), and a write completion notification is transmitted to the registration device (S282).
- DEV public key data of PUB—CA
- DEV certification authority CA
- CRL_DEV CRL_DEV
- step S291 the registration device that has received the write end notification (S266) determines whether or not the device supports updating of the common key data.
- Some of the data stored in the device can be updated using the above-mentioned data update ticket (DUT: Data Update Ticket) (see Fig. 32) as the data to be updated.
- the data to be updated is as described above with reference to FIG.
- the device manager sets data on the device that can execute either or both methods depending on the device.
- the device manager sends the information required for data update processing using the common key method (ex. MAC key for the data update ticket (DUT), etc.). If it is set to a device and the device does not perform symmetric key authentication, this information will not be stored in the device.
- Steps S292 to S293 and S301 to S305 are performed when the common key method is used for the data update process using (Ticket), and these steps are performed when the common key method is not used for the data update. Is omitted.
- step S292 the registration device
- Kdut_DEVl Data verification ticket (DUT) MAC verification key
- Kdut— DEV2 Data overnight update encryption key
- Kdut— DEV3 Transmits the MAC key of the overnight update ticket (DUT)
- Kdut_DEV4 Transmits the data update encryption key and their version information to the device.
- step S301 the device receives the write command described above.
- step S 294 the registration device that has received the write end notification (S 293) checks whether the device has a data update ticket (DUT: Data
- Update Ticket is used to determine whether to support overnight update processing.
- step S295 the registration device transmits a DUTIC_DEV (DUT Issuer Category): data update ticket (DUT) as a command for writing a data update ticket (DUT: data update ticket) issuer code. : Data Update Ticket) Sends the issuer category and version information to the device.
- DUTIC_DEV DUT Issuer Category
- DUT data update ticket
- DUT data update ticket
- issuer code Data Update Ticket
- step S306 the device receives the above-described write command.
- step S307 the device confirms that the write flag (Writable Flag) of the DMIB is writable.
- step S308 the device determines the received data. Write to the public key device key definition block (DKDB (PUB): Device Key Definition Block (PUB)) (S308). Next, the pointer, the size, and the number of free blocks in the device generated by the data writing are adjusted (S309), and a write completion notification is transmitted to the registration device (S310).
- DKDB public key device key definition block
- PDB Device Key Definition Block
- the registration device that has received the write completion notification (S296) transmits a device manager (DM) initial registration completion command to the device in step S321.
- the device that has received the command (S331) verifies the mutual authentication, the partition registration ticket (PRT), the data update ticket (DUT), and at least the data update ticket (DUT). It is determined whether data that can execute either the public key method or the common key method has been set. If there is a shortage in these data, one of the processes cannot be executed, and the initial registration by the device manager is determined to be in error, and the process ends.
- step S332 mutual authentication, verification of partition registration ticket (PRT), and verification of data update ticket (DUT), at least one of public key method and common key method can be executed for each. If it is determined that the data has been set, in step S333, the device cannot write the write (Writable) flag of the device management information block (DM IB: Device Management Information Block) (0x0000). And sends a write end notification to the registration device (S334).
- PRT partition registration ticket
- DUT verification of data update ticket
- the registration device that has received the write completion notification departs the device.
- a read command of the write flag (Writable Flag) of the device management information block (DM IB: Device Management Information Block) (see Fig. 15) is transmitted (S323).
- the device Upon receiving the command (S335), the device transmits a write flag (Writable Flag) in the device management information block (DMIB) in the memory section of the device to the registration device (S336).
- the registration device that has received (S324) the write flag (Writable Flag) in the device management information program (DM IB) has the write flag (Writable Flag) set to write disabled (0x00000). Is determined. If the write flag (Writable Flag) is not set to write disable (0x0 000), it indicates that the normal DMIB data write processing has not been completed, and the processing ends as an error. If the write flag (Writable Flag) is set to write-disabled (0x0000), the process ends as if normal DMIB data write processing was completed.
- FIG. 41 shows the manufacturing information block (Manufacture Information Block), device management information block (Device Management Information Block), and public key device key definition (Fig. 6 and Figs. 14 to 18).
- Device Key Definition Block PMB
- Device Key Area At this point, no partitions have been formed in the memory.
- a device code and the like as device-specific information are written in the manufacturing information block (Manufacture Information Block).
- the information written in the manufacturing information block (manufacture information block), a part of the written information, or operation data obtained based on the written information corresponds to a device identifier (IDm).
- IDm device identifier
- Kauth—DEV_B a common key for bidirectional individual key authentication
- MKauth—DEV_A a master key for bidirectional individual key authentication
- Kprt MAC key of the Participant Registration Ticket (PRT)
- PRT Participant Registration Ticket
- IRL_DEV Revocation List (Device ID) in which the device identifier (ID) of the rejected device (Device) is registered
- CRLJEV Public key certificate identifier for the rejected device (Device) (ex. : Revocation List (Certificate) with SN registered is also available if no device has been re-poked (excluded) at the time of device issuance, or a revocation list is obtained using another source.
- a configuration in which a revocation list is not stored may be adopted.
- the device includes a device-wide public key certificate (CERT DEV) that can be used for device-wide authentication, device-based processing, and authentication and other verification processing when processing a specific partition in the device.
- CERT DEV device-wide public key certificate
- An applicable partitioning public key certificate (CERT PAR) may be stored.
- the public key certificate for partition (CERT PAR) can be set and stored for each partition set in the device.
- the device-compatible public key certificate (CERT DEV) is stored in the device key area (Device Key Area) (see Fig. 18), which is the memory area under the jurisdiction of the device manager. ) Is stored in the Partition Key Area (see Figure 23), which is the memory area under the control of each partition manager.
- the public key certificate (CERT DEV) for the device is given to the device by the public key certificate issued by the certificate authority (CA for DM) (see Figs. 2 and 3) via the registration authority under the jurisdiction of the device manager. It manages the public key certificate (CERT DEV) issued by the registration authority of the device manager (database 222 (see Fig. 7)).
- the public key certificate (CERT PAR) corresponding to the partition is a public key certificate issued by a certificate authority (CA for PM) (see Figs. 2 and 3) via a registration authority under the jurisdiction of the partition manager. It manages the public key certificate (CERT PAR) issued by the registration manager of the partition manager (database 332 (see Fig. 9)).
- FIG. 44 shows the relationship between the issuing device (DM), the certification authority (CA), and the user device that extracted only the registration authority (RA) configuration of the device manager.
- the control means 221 has an encryption processing means.
- the cryptographic processing is performed by executing a program related to the cryptographic processing under the control of the control unit (CPU (2111 in FIG. 8)).
- the left side is the CERT (public key certificate) issuing device of the registration authority under the jurisdiction of the device manager, more specifically, the processing of the control means 221 in the configuration diagram of the device manager shown in FIG. 7, and the right side is Device processing.
- CERT public key certificate
- the CERT issuing device obtains the user information of the device for which the device-related public key certificate (CERT DEV) is to be issued, permits (determines) the issuance of the certificate, and issues the certificate. Establish a communication path with the device.
- the user information of the device for which the device-related public key certificate (CERT DEV) is issued can be obtained, for example, from data generated at the time of initial registration of the device. Alternatively, the user's name, address, telephone number, e-mail address, etc. may be separately obtained through another route. Note that the user information may be obtained from the device after setting the communication path with the device.
- the communication path may be secured as a communication path capable of transmitting and receiving data regardless of whether it is wired or wireless.
- step S352 the CERT issuing device transmits an authentication data generation command including a random number to the device.
- the device that has received the authentication data generation command (S361) generates a digital signature (S) by applying the device private key (PRIDEV) to the combination of the received random number R and the device identifier (IDm).
- the process (see FIG. 12) is executed (S362).
- the device uses the device identification data (I Dm) and signature (S) are sent to the CERT issuing device.
- the CE RET issuing device that has received the identification data (IDm) and the signature (S) from the device (S353) uses the received device identification data (IDm) as a search key to generate a database DB (DEV). Get the stored device public key (PUBDEV) from 222. Furthermore, the signature (S) is verified (see FIG. 13) by applying the obtained device public key (PUB DEV) (S355). If the verification is not successful, the data transmitted from the device is determined to be invalid data, and the process ends.
- a request is issued to the certification authority (CA for DM) 610 to issue a public key certificate (CERTDEV) for the device (S357).
- the device manager receives the public key certificate (CERT DEV) for the device issued by the certificate authority 610 (S358) and transmits it to the device (S359).
- the device that has received the device-compatible public key certificate (CERTDEV) from the device manager (Registration Authority) uses the certificate authority's public key (P UB CA (DEV)) that has been stored in the device key area in advance. Performs signature verification of the corresponding public key certificate (CERT DEV). That is, the public key certificate has a signature executed with the private key of the certificate authority (see FIG. 11), and the signature is verified (S366).
- the signature verification is successful, compare the device public key (PUB DEV) stored in the device-compatible public key certificate (CERT DEV) with the device public key (PUB DEV) stored in the local device (S 382) If they do not match, an error notification is executed. If they match, the received device-compatible public key certificate (CERTDEV) is stored in the device key area (see FIG. 18) (S383). Before issuing the public key certificate (CERTDEV) for the device, the public key (PUB DEV) generated by the device is stored in this area, and the public key certificate (CERT DEV) for the valid device is issued. At that point, it is stored as a process for overwriting with the device-compatible public key certificate (CERT DEV).
- FIG. 45 shows a diagram illustrating the process of sending and receiving data between the device manager 200, the device 100, and the certificate authority (CA) 6110 during the issuance of a public key certificate (CERT DEV) corresponding to the device. .
- the processing is executed in the order of Nos. 1 to 14 in FIG. It should be noted that the process No. 1 of the device manager 200 obtains the device identifier (IDm) and the device public key (PUB DEV) from the device 100, and the process No. 2 device identifier (I The registration process of Dm) is a process executed in the initial registration by the device manager.
- the procedure for issuing a device-compatible public key certificate is from process No.3, 3) Acquisition of customer information from the device by the device manager, 4. Registration of customer information (not required if already registered) 5. Acquire the device identifier (IDm) from the device. 6. Perform a database search on the acquired device identifier (IDm) to acquire the corresponding public key (P UB DEV).
- the authentication process between the device and the device manager which was omitted in the processes in Figs. 42 and 43, is not shown in Figs. 42 and 43 when the device identifier (IDm) is obtained from the device.
- Signature verification was performed, and authentication was omitted by confirming the transmission data of the communication partner. It is desirable to execute at least one or both of the signature verification in FIGS. 42 and 43 and the authentication in FIG. The details of the authentication process will be explained later in B.4.
- FIG. 46 shows the data storage configuration of each block of the memory after storing this device-specific public key certificate (CERT DEV) in the device key storage area of the memory.
- FIG. 46 shows the manufacturing information block (Manufacture Information Block), the device management information block (Device Management Information Block), and the public key device key definition (Device Key) described with reference to FIG. 6, and FIGS. Definition Block (PUB)), Device Key Definition Block (Common) for common key system, and Device Key Area.
- PUBB Device Key Definition Block
- the device key area (Device Key Area) shown in FIG. 46 stores a device-related public key certificate (CERT DEV). Before issuing the device-compatible public key certificate (CERT DEV), this area stores the public key (P UB DEV) generated by the device. When the device-compatible public key certificate (CERT DEV) is received, Overwrite processing is performed by the device-compatible public key certificate (CERT DEV). If there are pointers, sizes, and management data due to this overwriting process, necessary changes are performed.
- CERT DEV device-related public key certificate
- P UB DEV public key generated by the device.
- the processing executed before the use of the device is started will be described.
- the processing performed by the partition manager prior to the start of use of the device includes the process of setting a partition in the memory part of the device and the process of issuing a partitioning public key certificate (CERT PAR) to the device.
- CERT PAR partitioning public key certificate
- the process of setting up the partition includes mutual authentication between the device and the partition manager (device authentication or partition authentication), and validity verification of the partition registration ticket (PRT: Partition Registration Ticket).
- PRT Partition Registration Ticket
- the process of deleting a partition can be basically executed according to the same procedure as that for creating a partition. I do.
- the partition setting process includes the mutual authentication process (device authentication or partition authentication) between the device and the partition manager, and the partition registration ticket (PRT: Partition Registration Ticket). ), And these processes are also explained.
- FIG. 47 The partition setting registration / deletion processing flow shown in Fig. 47 will be described.
- the left side shows the partition creation / deletion device of the partition manager
- the right side shows the processing of the device (see Fig. 5).
- the partition creation / deletion device of the partition manager is a device (eX. A reader / writer as a device access device, a PC) that can read and write data to the device. It corresponds to a reader / writer as a device.
- the outline of the partition creation and deletion processing will be described with reference to FIG. 47, and then the details of each processing included in this processing will be sequentially described using the flow of FIG.
- a mutual authentication process is performed between the partition creation / deletion device and the device.
- the two means of transmitting and receiving data mutually check whether the other party is the correct data communicator and then perform the necessary data transfer.
- the process of checking whether the other party is the correct data communicator is the mutual authentication process.
- One preferred data transfer method is to generate a session key during the mutual authentication process, and to perform data transmission by performing an encryption process using the generated session key as a shared key.
- Authentication Flag Flag that indicates whether mutual authentication with the device is required in the process of using the ticket.
- Authentication Type Mutual authentication type of the device (Public key authentication or symmetric key authentication, or any type (Any))
- the partition creation / deletion device sends a partition registration ticket (PRT) to the device.
- the partition registration ticket (PRT) is a ticket issued to the partition manager by the partition registration ticket (PRT) issuance means (PRT Issuer) managed by the development manager at the request of the partition manager.
- the partition registration ticket (PRT) is an access control ticket for the device, and has the data format configuration of FIG. 26 described above.
- the public key certificate (CERT_PRTI) of the partition registration ticket (PRT) issuing means PRT Issuer
- the attribute (Attribute) of the public key certificate (CERT_PRTI) of the PRT issuing means matches the identifier (PRTIC) of the partition registration ticket (PRT) issuing means (PRT User).
- the device that has received the partition registration ticket (PRT) executes the validity of the received ticket (PRT) and the user check processing (S413).
- the verification of the validity of the ticket is performed by applying either the MAC verification using the common key method or the signature verification processing using the public key method.
- the user check is a process for checking the validity of the device (ticket user) that has transmitted the ticket. Mutual authentication has been established, and the identification data of the authentication partner and the data recorded in the ticket are used. For verifying the match with the ticket user identifier (see Figure 26) Is executed as Details of these processes will be described later.
- the partition registration ticket (PRT) Notify the reception creation error to the partition creation / deletion device (S418). If the ticket and the user are confirmed to be legitimate (Yes in S414), the partition in the memory section in the device is followed in accordance with the rules described in the received partition registration ticket (PRT). Generate or delete the file. The details of this process will be described later using another flow.
- the partition creation / deletion device receives the PRT reception result (S404), determines the PRT processing result, and if the PRT reception result is an error (No in S405), ends the processing as an error. If the PRT reception result is successful (Yes in S405) and the process is partition generation, the partition initial data writing process (S406, S419) is executed. The writing process in the initial stage will be described in detail later using another flow. If the process of writing the initial data of the partition is completed, and if the PRT reception result is successful (Yes in S405) and the process is to delete the partition, transmission / reception of the session clear command (S407, S420) is performed. Execute, discard the authentication table generated on the device side (S421), and end the processing. The authentication table is a table generated in the mutual authentication processing in steps S401 and S410, and the details will be described later.
- the partition registration ticket (PRT) is used to create a new partition in the device or delete the created partition.
- the mutual authentication process (S401, S410) included in this process, the validity of the ticket and the user's check (S413), the generation and deletion of partitions (S411) 5) and the partition initial data write processing (S406, S419) will be described in detail.
- the mutual authentication process executed in steps S401 and S410 in FIG. 47 will be described.
- the mutual authentication process described below is performed for other tickets, namely, a file registration ticket (FRT: File Registration Ticket), a service permission ticket (SPT: Service Permission Ticket), and a data update ticket (DU).
- FRT File Registration Ticket
- SPT Service Permission Ticket
- DU Data update ticket
- T Data Update Ticket
- FIG. 48 shows a processing flow of the mutual authentication processing.
- the left side shows the processing of the authentication device of the partition manager
- the right side shows the processing of the device (see FIG. 5).
- the authentication device of the partition manager is a device (ex. Reader / writer as device access device, PC) capable of processing data read / write to the device, and has a configuration corresponding to the reader / writer in FIG.
- the authentication device reads an authentication method required for using the partition registration ticket (PRT) from the ticket and determines the authentication method.
- PRT partition registration ticket
- the authentication mode is not limited to the authentication method described in the ticket.
- the depth authentication and the partition authentication may be determined according to a method specified by an access device (ex. A reader / writer).
- the determined authentication methods be A (1) to A (n).
- Various authentication processing modes are set in the partition registration or deletion processing to which the partition registration ticket (PRT) is applied.
- the registration of a partition requires device authentication for the device, and the deletion of a partition requires both device authentication and the authentication of the partition to be deleted.
- the authentication method required for PRT use processing is described in the [Authentication Type] of the partition registration ticket (PRT), and the authentication device uses the authentication method required for using the partition registration ticket (PRT). Is read from the ticket And the authentication procedure is defined as A (i): A (1) to A (n).
- step S432 the first authentication processing method A (1) is read out, and it is determined whether the authentication method of A (1) is device authentication or partition authentication (S433). Execute (S434, S441), and execute the partition authentication (S435, S442) if it is the partition authentication. As a result of the authentication processing with the device, if the authentication is not successful, the processing ends as an error. If the authentication is successful, i is incremented in step S437, and the process returns to step S433 to determine the next authentication method and execute authentication according to the method. Execute these processes from A (1) to A (n), and proceed to the next step if all the authentications are successful.
- the device authentication processing will be described with reference to the flow in FIG. In FIG. 49, the left side shows the processing of the device authentication device of the partition manager, and the right side shows the processing of the device (see FIG. 5).
- the device authentication device of the partition manager is a device that can read and write data to and from the device (ex. A reader / writer as a device access device, PC), and the reader / writer as a device access device in Fig. 10 Has a configuration corresponding to
- step S451 the device authentication device determines whether or not to apply a public key authentication method using a public key to the device authentication process based on the partition registration ticket (PRT).
- Device authentication is performed using either the public key method or the common key method, and the ticket specifies the execution method.
- the processing in steps S452 to S455 and S461 to S465 in FIG. 49 is not performed, and the process proceeds to step S456.
- the device authentication device transmits a public key device authentication start command to the device in step S452.
- the device Upon receiving the command (S461), the device refers to the public key device key definition block (see Fig. 16) in the memory part of the device, and stores the public key certificate (CERT DEV) corresponding to the device. Is verified (S462). If the device-compatible public key certificate (CERT DEV) is not stored, mutual authentication using the public key method cannot be executed, and an error occurs. The determination is made and the process ends.
- FIG. 50 shows a mutual authentication sequence using a public key cryptosystem, elliptic curve cryptography (ECC) with a length of 160 bits.
- ECC elliptic curve cryptography
- B first generates a random number R b of 64 bits and transmits it to A. Upon receiving this, A generates a new 64-bit random number Ra and a random number Ak smaller than the characteristic p. Then, a point Avx AkxG obtained by multiplying the base point G by Ak is obtained, an electronic signature A.
- Sig for Ra, b, Av (X coordinate and Y coordinate) is generated, and returned to B together with A's public key certificate.
- Ra and Rb are each 64 bits
- the X and Y coordinates of Av are each 160 bits
- the digital signature is generated for a total of 448 bits.
- the user When using a public key certificate, the user verifies the electronic signature of the public key certificate using the public key of the public key certificate authority (CA) held by the user, and verifies the electronic signature. After successful authentication, extract the public key from the public key certificate and use the public key. Therefore, all users who use the public key certificate need to hold the public key of the common public key certificate issuing authority (C #). Note that the method of verifying the electronic signature has been described in FIG.
- B is calculated as BkxAv (Bk is a random number, but Av is a point on the elliptic curve, so scalar multiplication of the point on the elliptic curve is required), and ⁇ is Ak xBV is calculated, and the lower 64 bits of the X coordinate of these points are used as a session key for subsequent communication (when the common key encryption is a 64-bit key length common key encryption).
- the session key may be generated from the Y coordinate, and may not be the lower 64 bits. Note that in secret communication after mutual authentication, the transmitted data may not only be encrypted with the session key, but also may be digitally signed.
- the transmission data is encrypted by using the generated session key, and the mutual data communication is performed.
- step S464 the CRL stored in the device key area (see FIG. 18) of the memory portion of the device.
- DEV Register the exclusion device (Device) and the public key certificate identifier (eX. Serial number: SN) of the exclusion device (a reader as a device access device, a ticket user such as a PC, a ticket issuing means).
- SN public key certificate identifier
- the exclusion device a reader as a device access device, a ticket user such as a PC, a ticket issuing means.
- revocation list (Certificate) that has been sent to verify that the device authentication device that is the communication partner has not been re-poked.
- step S465 the session key K ses generated in the mutual authentication and key sharing process and the communication partner (a reader / writer as a device access device constituting the device authentication device, a PC, etc.) are disclosed.
- Key Store the distinguished name (DN: Distinguished Name), serial number, and category in the certificate in the authentication table that associates the device management code (DMC) with the key.
- DN Distinguished Name
- DMC device management code
- step S454 the device authentication device also checks whether the devise has been revoked.
- CRL_DEV Excluded device (Device), Excluded device (Reader / Writer as device access device, ticket user such as PC, ticket issuing means)
- the revocation list (Revocation List (Certificate)) in which the public key certificate identifier (ex. Serial number: SN) is registered is determined.
- the device authentication device can obtain the repock list (CRL-DEV) from the registration authority (RA (PAR)). If re-poked, the partition generation processing cannot be permitted, so the processing ends with an error.
- step S455 the session key K ses generated in the mutual authentication and key sharing process, the distinguished name (DN: Distinguished Name) in the public key certificate of the communication partner (device), and the serial number
- the numbers and categories are stored in an authentication table that associates the device manager code (DMC) as a key.
- DMC device manager code
- Fig. 51 shows an example of an authentication table generated in the device.
- Fig. 52 shows an example of an authentication table generated in a reader / writer (PC also possible) as a device access device as an authentication device.
- FIG. 51 shows an example of an authentication table generated in the device at the time when the device authentication and the authentication of the partitions 1 and 2 as the partition authentication described later are completed.
- DMC Device Manager
- PMC Partition Manager Code
- the session key K ses and the communication partner (rewriter writer as a device access device) )
- the identifier (IDRW) is stored.
- the authentication table is destroyed when the session is cleared.
- the device can check the authentication status of the device and each partition by referring to the information in the table, and can check the session key to be used.
- FIG. 52 shows an authentication table on the reader / writer side as a device access device.
- This example is also an example of the authentication table at the time when the device authentication and the authentication of the partitions 1 and 2 as the partition authentication are completed.
- the basic configuration is the same as the authentication table in the device.
- PMC is recorded, and data is stored for each authentication method performed.
- the session key K ses, the distinguished name (DN: Distinguished Name) in the public key certificate of the communication partner (device), the serial number, and the category are the same.
- the session key K ses and the identifier (IDRW) of the communication partner (device) are stored.
- the authentication table on the reader / writer side is also destroyed when the session is cleared.
- the presence or absence of the authentication status of the device and the partition can be determined by referring to the information in the authentication table, and the session key to be used can be confirmed. Become.
- the device authentication device determines in step S451 that the device authentication method is not the public key method
- the device authentication device outputs a common key device authentication command to the device in step S456.
- the device receives the command (S 466)
- the device refers to the common key device key definition block (see FIG. 16) in the memory of the device, and the two-way individual key authentication mask used for common key authentication. It verifies whether or not one key (MKauth-DEV) is stored (S467). If the master key for two-way individual key authentication (MKauth—DEV) is not stored, mutual authentication using the common key method cannot be executed, and the error is determined. And the process ends.
- MKauth-DEV master key for two-way individual key authentication
- a and B are entities that perform common key authentication using a master key, and A has its own identifier IDa, two-way individual key authentication common key Ka, and two-way individual key.
- B has a master key MKb for key authentication, and B has its own identifier IDb, a common key Kb for two-way individual key authentication, and a one-key MKa for two-way individual key authentication.
- the DES algorithm (ex.DES, triple DES) is used as the common key cryptosystem, but other cryptosystems can be applied as long as the common key cryptosystem is the same. It is possible.
- B generates a 64-bit random number Rb, and sends Rb and its own ID, IDb, to A.
- A Upon receiving this, A generates a new 64-bit random number Ra, and DES encrypts the IDb with the master key MKb for bidirectional individual key authentication to generate the common key Kb for bidirectional individual key authentication.
- the keys Ka and Kb the data is encrypted in the CBC mode of DESS in the order of Ra, Rb, IDa, and IDb, and is returned to B together with its own identifier IDa.
- B Upon receiving this, B first obtains the bidirectional individual key authentication common key Ka by performing IDa DES encryption processing using the bidirectional individual key authentication master key MKa. Furthermore, the received data is decrypted with the keys Ka and Kb. It verifies that Rb and I Db among Ra, Rb, I Da, and I Db obtained by decoding match those transmitted by B. If this verification passes, B authenticates A as valid.
- B generates a 64-bit random number K ses to be used as a session key, and uses the keys Kb and Ka in order of Rb, Ra, IDb, IDa, and Kses in CBC mode of DES. Encrypt the data and send it back to A.
- A decrypts the received data with the keys Ka and Kb. It verifies that Ra, Rb, IDa, and IDb obtained by decryption match those transmitted by A. If it passes, A authenticates B as valid. Authenticate each other Later, the session key K ses is used as a common key for secret communication after authentication.
- FIG. 54 is a diagram for explaining the data flow of the common key authentication using the master key associated with the data stored in the system of the present invention.
- the reader / writer (R / W) as a device access device generates a 64-bit random number Rb, and sends Rb and its own ID rw to the device (Device). I believe.
- the device (Device) receiving this generates a new 64-bit random number Ra, and bidirectional individual key authentication is performed by DES encryption of the ID rw using DEV_A, a master key for bidirectional individual key authentication.
- the data is encrypted in the order of Ra, Rb, and ID rw, for example, in DES—CBC mode, and It is returned to the reader / writer (R / W) as a device access device along with the identifier IDm.
- the reader / writer (R / W) first performs a two-way individual key authentication common key Kauth— DEV_B by performing a two-way individual key authentication master key MKauth—DEV—B and performs IDM DES encryption processing. To get. Further, it decrypts the received data with the key Kauth-DEV-A and Kauth_DEV_B. Verify that the decrypted Rb and ID rw match the ones sent by the reader / writer (RZW) as the device access device. If the verification passes, the leader writer (R / W) authenticates the device (Device) as valid.
- the reader / writer (R / W) generates a 64-bit random number K ses to be used as a session key, and uses the bidirectional individual key authentication common keys Kauth_DEV_A and auth_DEV_B to generate Rb, Ra,
- the data is encrypted using, for example, a triple DES mode as a DES algorithm, and returned to the device (Device).
- the device receiving this decrypts the received data with the common key for bidirectional individual key authentication Kauth-DEV_A and Kauth-DEV_B. Verify that the decrypted Ra, Rb, and ID rw match those transmitted by the device (Device). Pass this verification In this case, the device (Device) authenticates the reader / writer (R / W) as valid, and after authentication, uses the session key K ses as a common key for secret communication.
- IDm the unique value of the device
- a value based on the data stored in the device manager management area can be applied as described above using the device memory format of FIG.
- the individual key of the communication partner generated by executing the process based on the master key of the communication partner
- two keys are set as common keys, and mutual authentication is performed by the common key method using the two set keys.
- the common key is stored in the device or access device in advance. A more secure authentication system and method are realized as compared with the conventional common key authentication configuration.
- the device determines in step S469 that the IRL_DEV stored in the device key area (see FIG. 18) of the memory portion of the device. : Revocation list (ID) in which the identifiers (IDs) of excluded devices (Devices) and excluded devices (rewriters as device access devices, ticketers such as PCs, and ticket issuing means) are registered. ), Verify that the device authentication device that is the communication partner has not been revoked. If revoked, the partition generation processing cannot be permitted, and the processing ends as an error.
- ID Revocation list
- step S470 the session key K ses generated in the mutual authentication and key sharing process and the identification of the communication partner (a reader / writer as a device access device constituting the device authentication device, a PC, etc.)
- the information (ID rw) is stored in an authentication table (see Fig. 51) that associates the device manager code (DMC) with a key.
- step S458 the device authentication apparatus also checks whether the device has been revoked.
- I RL_DEV Excluded device (Device), Excluded device (Rewriter / writer as device access device, ticket user such as PC, issue ticket) Means) Judge by referring to the Revocation List (ID) in which the identifier (ID) is registered.
- the device authentication device can acquire the relocation list (IRL_DEV) from the registration authority (RA (PAR)). If re-poked, the partition generation process cannot be permitted, so the process ends as an error.
- RA Registration authority
- step S459 the session key K ses generated in the mutual authentication and key sharing process and the identification information (IDm) of the communication partner (device) are used as the device manager code (DMC) as a key. It is stored in the associated authentication table (see Fig. 52).
- the above processing is the device authentication processing executed between the device and the redirector as the device access device under the control of the partition manager.
- the partition authentication processing executed in steps S435 and S442 in FIG. 48 will be described with reference to FIGS.
- device authentication or partition authentication or both authentications are required according to the process as described above.
- partition registration ticket PRT
- FIG. 55 the left side shows the processing of the partition authentication device of the partition manager, and the right side shows the processing of the device (see FIG. 5).
- the partition authentication device of the partition manager is a device that can read and write data to the device (ex. A reader / writer as a device access device, a PC), and corresponds to the reader / writer as a device access device in Fig. 10. Having a configuration.
- step S471 the partition authentication device outputs a partition A existence check command for executing the existence confirmation of the partition A to be authenticated to the device.
- the device that has received the command (S481) checks whether partition A exists in the memory part of the device (S482).
- a partition manager code (PMC) is used as the partition identifier A, and the device is, for example, a partition definition block.
- PMC partition manager code
- the presence or absence of a partition can be determined based on the PMC. If the device determines whether a partition exists, the check result is sent to the partition authentication device.
- the partition authentication device that has received the check result (S472) verifies the check result (S473), and if it receives the result that the partition does not exist, the authentication is not possible, and the error is terminated. If the check result indicates that a partition exists, the partition authentication device determines in step S474 that the public key that uses the public key for the partition authentication process based on the partition registration ticket (PRT). It is determined whether to apply the authentication method. Similar to the device authentication described above, the partition authentication is executed in either the public key method or the common key method, and the specification of the execution method is described in the ticket. If the common key method is specified, the processing in steps S475 to S478 and S484 to S488 in FIG. 55 is not performed, and the flow advances to step S491.
- the partition authentication device transmits a public key partition A authentication start command to the device in step S475.
- the device Upon receiving the command (S484), the device stores the public key certificate for partition A (C ERT PAR) by referring to the public key system partition key definition block (see Fig. 21) in the memory part of the device. Verify (S485) whether or not it has been performed. If the public key certificate corresponding to partition A (CERT PAR) is not stored, mutual authentication of the public key method cannot be executed, and it is determined that an error has occurred and the process ends.
- the public key certificate used for partition authentication is a public key certificate issued by a partition manager compatible certificate authority (CA (PAR)), and the signature verification of this public key certificate requires the partition manager compatible certificate.
- CA partition manager compatible certificate authority
- PA R partition manager compatible certificate authority
- PAR public key
- the public key (PUB CA (PAR)) is stored in the partition key area (see Figure 23). In such a mutual authentication process, transmission data is encrypted using the generated session key, and mutual data communication is performed.
- CRL_PAR Excluded device (Device), public key certificate identifier (ex. Serial number: SN) of excluded device (rewriter / writer as device access device, ticket user such as PC, ticket issuing means)
- rewriter / writer as device access device
- ticket user such as PC
- ticket issuing means Refers to the registered revocation list (Revocation List (Certificate)) to verify that the partition authentication device that is the communication partner has not been revoked. Processing or deletion cannot be permitted, and the processing ends as an error.
- step S488 the session key K ses generated in the mutual authentication and key sharing process and the communication partner (a reader / writer as a device access device constituting the partition authentication device, a PC, etc.) are disclosed.
- the distinguished name (DN: Distinguished Name), serial number, and category in the key certificate are stored in an authentication table that associates the partition manager code (PMC) with the key.
- PMC partition manager code
- step S477 the partition authentication device also checks whether the device has not been re-reported.
- CRL_PAR Excluded device (Device), Excluded device (Reader / writer as device access device, ticket user such as PC, ticket issuer)
- the Revocation List (Certificate) in which the public key certificate identifier (ex. Serial number: SN) registered in step (2) is registered.
- the device authentication device can obtain the repock- ment list (CRL_PAR) from the registration authority (RA (PAR)). If revoked, the process of creating or deleting the partition cannot be permitted, so the process ends as an error.
- step S4708 the session key K ses generated in the mutual authentication and key sharing process and the communication partner (device) are opened.
- the identification name (DN: Distingui shed Name), serial number, and category in the key certificate are stored in an authentication table in which the partition manager code (PMC) is used as a key.
- PMC partition manager code
- FIG. 51 the authentication table shown in the device
- FIG. 52 the authentication table shown in FIG. 52 is generated in the reader / writer (PC is also possible) as the device for device access as the partition authentication device.
- FIGS. 51 and 52 show examples of an authentication table generated in the device and the reader / writer as the device access device at the end of the device authentication and the authentication of partitions 1 and 2 as the partition authentication.
- partition manager code PMC
- the details of each authentication method executed are stored.
- the session key K ses and the distinguished name DN: Distinguised Name
- serial number the number of the public key certificate of the communication partner
- category in the public key certificate of the communication partner are stored in a table as described above
- key authentication the session key K ses and the identifier of the communication partner are stored.
- the authentication table is destroyed when the session is cleared. For devices and device access devices, the authentication status of the device and each partition can be confirmed by referring to the information in the table, and the session key to be used can be confirmed. .
- the partition authentication device determines in step S474 that the partition authentication method is not the public key method, the partition authentication device outputs a common key partition A authentication command to the device in step S491.
- the device receives the command (S501), it refers to the common key system pass block in the memory section of the device (see Fig. 22) and performs two-way individual key authentication used for common key authentication. It verifies whether or not the master key for use (MKauth-PAR_A) is stored (S502). If the master key for two-way individual key authentication (MKauth_PAR-A) is not stored, mutual authentication using the common key method cannot be executed, and an error is determined and the process ends.
- MKauth-PAR_A master key for two-way individual key authentication
- the master key for two-way individual key authentication (MKauth—PAR_A) is stored, in steps S492 and S503, mutual authentication using the master key is performed.
- the certificate and key sharing process is executed.
- Mutual authentication and key sharing processing using the common key method are the same as those described with reference to FIGS. 53 and 54 in the previous device authentication, and therefore description thereof is omitted.
- the key to be applied in the case of partition authentication is defined in the partition key definition block (see Fig. 22), and the common key (Kauth) for two-way individual key authentication stored in the) -tion key area (see Fig. 23) — PAR_B) and master key for two-way individual key authentication (MKauth—PAR_A).
- IR PAR Revocation List in which the identifiers (IDs) of rejected devices (Device), rejected devices (rewriter / writer as device access device, ticketer such as PC, ticket issuing means) are registered. (ID), verify that the partition authentication device that is the communication partner has not been revoked. If it has been re-poked, the process of generating or deleting the partition cannot be permitted, so the process ends as an error.
- step S505 the session key K ses generated in the mutual authentication and key sharing process and the communication partner (a reader / writer or a PC as a device access device constituting the device authentication device)
- the identification information (ID rw) is stored in the authentication table (see Fig. 51) that is associated with the partition management code (PMC) as a key.
- the partition authentication device also checks whether the device has been revoked.
- I RL_PAR Excluded device (Device), Excluded device (Reader / writer as device access device, ticket user such as PC, issue ticket) Judgment is made with reference to the Revocation List (ID) in which the identifier of the (method) is registered.
- the partition authentication device can obtain the relocation list (IRL_PAR) from the registration authority (RA (PAR)). If re-poked, the process of creating or deleting partitions cannot be permitted, so the process ends with an error.
- step S494 the mutual authentication and key
- the session key K ses generated in the sharing process and the identification information (IDm) of the communication partner (device) are stored in the authentication table (see Fig. 52), which is associated with the partition manager code (DMC) as a key. .
- the above process is a partition authentication process executed between a device and a reader / writer as a device access device under the control of the partition manager. Through such mutual authentication, authentication between the device or partition and the reader / writer as the device access device is established, sharing of the session key is achieved, and encrypted communication of the communication data using the session key becomes possible.
- the above-described device authentication processing and partition authentication processing are performed using other tickets, that is, a file registration ticket (FRT: File Registration Ticket) and a service permission ticket (SPT: Service Permission Ticket). This process is also performed as needed when performing device access using a ticket (DUT: Data Update Ticket). These will be described later in the description of processing using each ticket.
- FRT File Registration Ticket
- SPT Service Permission Ticket
- the validity of the ticket and the user check process are based on the ticket received from the ticket user (ex. Reader / writer as a device access device, PC, etc.) executing communication with the device (see Fig. 5). ) Is the processing to be executed.
- the device uses the ticket and the ticket user (ex. A reader / writer as a device access device, a PC, etc.) in the validity of the ticket and the user check processing. After confirming the legitimacy of a user, allow processing within the limit described in the ticket.
- step S511 in FIG. 57 the device that has received the ticket from the ticket user (ex. A reader / writer as a device access device, a PC, etc.) verifies the ticket type, and the ticket is registered in the partition registration ticket (PRT). : Partition Registration Ticket). The ticket type is recorded for each ticket (see Figure 26, Figure 27, Figure 28, Figure 31 and Figure 32).
- step S512 If the ticket type is a partition registration ticket (PRT: Partition Registration Ticket), execute steps S512 to S514 to execute the node registration ticket (PRT: If it is not a Partition Registration Ticket), go to step S515.
- PRT Partition Registration Ticket
- step S512 the Integrity Check Type (Ticket) described in the ticket is used. It is determined whether the setting of the type of validity verification value (public key method (Public) / common key method (Common))) is the public key method (Public).
- Public public key method
- Common key method Common key method
- step S513 If the type (Integrity Check Type) of the validity verification value is the public key method (Public), the process proceeds to step S513 to execute various processes.
- the processing executed in step S513 is as follows: First, the public key certificate (Ticket Issuer) of the ticket issuer using the public key PU BCA (DEV) of the certificate authority (CA (DEV)) corresponding to the device manager. C ERT) verification process.
- the partition registration is performed in the case of the public key method.
- the public key certificate (CERT_PRTI) of the ticket (PRT) issuer (PRT Issuer) is also sent to the device.
- the attribute of the public key certificate (CERT_PRTI) of the PRT issuing means matches the identifier (PRTIC) of the partition registration ticket (PRT) issuing means (PRT User).
- the public key certificate (see Fig. 11) has a signature executed with the private key of the CA (DEV) corresponding to the device manager. )) Is verified using the public key PUB CA (DEV).
- the signature generation and verification are executed, for example, as processing according to the flow of FIGS. 12 and 13 described above.
- This signature verification it is determined whether the ticket issuer's public key certificate (CERT) is a valid public key certificate (CERT) that is not falsified.
- step S513 the code as the user's power category recorded in the option area of the public key certificate (CERT) of the ticket issuing means, whose validity has been confirmed by signature verification, is transferred to the DKD in the device.
- CERT public key certificate
- PRT IC PRT Issuer Code
- the public key certificate includes a ticket issuer (PRT, FRT, SPT, etc.) as a means for issuing each ticket.
- Affiliation code in this case, PRT IC (PRT Issuer Code) is recorded.
- PRTIC PRT Issuer Code
- DKDB Device Key Definition Block
- the device uses CRL_DEV (excluded device (Device :), exclusion device (reader / writer as device access device, PC, etc.
- CRL_DEV excludeded device (Device :)
- exclusion device reader / writer as device access device, PC, etc.
- the Ticket Issuer refers to the revocation list (Revocation List (Certificate)) that has registered the public key certificate identifier (ex. Serial number: SN) of the ticket issuer. It is determined whether or not re-poke has been performed.
- the public key certificate (CERT) of the ticket issuer (Ticket Issuer) is a valid public key certificate (CERT) that is not falsified
- PRT IC PRT Issuer
- the ticket issuer (Ticket Issuer) has not been re-poked
- step S512 the Integrity Check Type (the type of the validity verification value of the ticket (Public / Public key / Coanda on)) described in the ticket is If it is determined that the setting is the common key method (Co-band), the process proceeds to step S514 to perform MAC (Message Authentication Code) verification.
- the device performs the MAC verification process on the ticket using the MAC verification key: Kprt of the partition registration ticket (PRT) stored in the device key area (see Figure 18) of the device.
- Figure 59 shows an example of MAC value generation using the DES encryption processing configuration.
- the target message is divided into 8-byte units (hereinafter, the divided messages are referred to as Ml, ⁇ 2, ⁇ , ⁇ ), and first, the initial value ( Exclusive OR the Initial Value (hereinafter referred to as IV)) and M 1 (the result is referred to as I 1).
- I 1 is put into the DES encryption unit, and is encrypted using a MAC verification key: K prt (output is E 1).
- E 1 and M 2 are XORed, and the output I 2 is input to the DES encryption unit, and is encrypted using the key K prt (output E 2).
- this process is repeated, and encryption processing is performed on all messages.
- the last EN that appears is the Message Authentication Code (MAC). Note that, as the message, partial data that constitutes the data to be verified can be used. is there.
- the same ICV Integrity Check Value
- the ICV generated by the data transmitting side at the time of data generation which is guaranteed not to be tampered with, is described in the description of the format of the partition registration ticket (PRT) in Fig. 26. (Integrity Check Value) field.
- PRT partition registration ticket
- the ICV generated by the device is compared with the ICV stored in the received ticket (PRT). If they match, it is determined that the ticket is valid. If they do not match, it is determined that the ticket has been tampered. Then, cancel the process using the ticket.
- the above processing completes the ticket verification processing when the Integrity Check Type described in the ticket is the common key method.
- step S511 If it is determined in step S511 that the ticket type is not a partition registration ticket (PRT: Partition Registration Ticket), the ticket type is verified in step S515 and the ticket is determined to be a file registration ticket. (FRT: File Registration Ticket).
- PRT Partition Registration Ticket
- step S516 If the ticket type is a file registration ticket (FRT: File Registration Ticket), steps S516 to S518 are executed. If the ticket type is not a file registration ticket (FRT: File Registration Ticket), step S516 is executed. Go to 5 1 9 If the ticket type is a file registration ticket (FRT: File Registration Ticket), in step S516, the type of the integrity check type (validity verification value of the ticket (Ticket) described in the ticket) It is determined whether the setting of the key method (Public) / common key method (Common))) is the public key method (Public). If the type (Integrity Check Type) of the validity verification value is the public key method (Public), the process proceeds to step S 5 17 to execute various processes. The processing executed in step S 517 is as follows. First, the public key certificate of the ticket issuer (Ticket Issuer) using the public key PUB CA (PAR) of the partition manager compatible certificate authority (CA (PAR)) This is verification processing of a certificate (CERT).
- PUB CA P
- the File Registration Ticket (FRT) Issuer When a ticket issued by the File Registration Ticket (FRT) Issuer (FRT Issuer) is transmitted to the ticket user, in the case of the public key method, the File Registration Ticket (FRT) issuance means
- the public key certificate (CERT_FRTI) of (FRT Issuer) is also sent to the device.
- the attribute (Attribute) of the public key certificate (CERT_FRTI) of the FRT issuing means matches the identifier (FRTIC) of the file registration ticket (FRT) issuing means (FRT Issuer).
- the public key certificate (see Fig. 11) has a signature executed with the private key of the CA (PAR) corresponding to the partition manager, and this signature is used to transfer the signature to the CA (CA (PAR)). PAR)) using public key PUB CA (PAR).
- the signature generation and verification are executed, for example, as processing according to the flow of FIGS. 12 and 13 described above. This signature verification determines whether the ticket issuer's public key certificate (CERT) is a legitimate public key certificate (CERT) that is not falsified.
- step S 517 the user belonging code recorded in the option area of the public key certificate (CERT) of the ticket issuing means that has been verified by signature verification and the PKDB ( It is determined whether it matches the ticket issuer code (FRT IC: FRT Issuer Code) recorded in the Partition Key Definition Block (PUB).
- CERT public key certificate
- PKDB It is determined whether it matches the ticket issuer code (FRT IC: FRT Issuer Code) recorded in the Partition Key Definition Block (PUB).
- FRT IC FRT Issuer Code
- the public key certificate includes a ticket issuer (PRT, FRT, SPT, etc.) which is a means for issuing each ticket.
- Affiliation code in this case, FRT IC (FRT Issuer Code).
- FRT IC FRT Issuer Code
- PTB Partition Key Definition Block
- the device uses CRL_PAR (Excluded Device (Device), Excluded Device (Reader / Writer as device access device, Ticket User such as PC, etc.) stored in the Partition Key Area (see Figure 23) Issuing means) Refers to the revocation list (Revocation List (Certificate)) that has registered the public key certificate identifier (ex. Serial number: SN) of the public key certificate, and checks whether the ticket issuing means (Ticket Issuer) has been re- judge.
- CRL_PAR Excluded Device (Device), Excluded Device (Reader / Writer as device access device, Ticket User such as PC, etc.
- Issuing means Refers to the revocation list (Revocation List (Certificate)) that has registered the public key certificate identifier (ex. Serial number: SN) of the public key certificate, and checks whether the ticket issuing means (Ticket Issuer) has been re- judge.
- the signature recorded in the file registration ticket (FRT) (see FIG. 27), which is the reception ticket, that is, the integrity check value (validation value of the ticket (public key method: signature)) )
- the integrity check value validation value of the ticket (public key method: signature)
- the signature verification is executed in accordance with the same sequence as the flow of FIG. 13, for example, similar to the signature verification of the public key certificate.
- the public key certificate (CERT) of the ticket issuer (Ticket Issuer) is a valid public key certificate (CERT) that is not falsified
- PKDB Partition Key Definition Block
- the validity verification of the file registration ticket (FRT) shall be successful.
- step S518 the setting of the Integrity Check Type (the type of the validity verification value of the ticket (Public) / Public key method (Common)) described in the ticket is changed. If it is determined that the common key method (Common) is used, the process proceeds to step S518 to execute MAC (Message Authentication Code) verification.
- the device uses the file registration ticket (FRT) MAC verification key: Kfrt stored in the partition key area of the device (see Fig. 23) to execute the MAC verification process on the ticket.
- the MAC verification processing is executed according to the MAC value generation processing using the DES encryption processing configuration of FIG. 59 described above.
- the ICV generated by the data transmitting side at the time of data generation which is guaranteed not to be falsified, can be used as described in the description of the format of the file registration ticket (FRT) in Fig. 27. Value) field.
- the ICV generated by the device is compared with the ICV stored in the received ticket (FRT). If they match, it is determined that the ticket is valid. If they do not match, the ticket has been tampered with. Judge and cancel the process using the ticket.
- step S 515 If it is determined in step S 515 that the ticket type is not a file registration ticket (FRT: File Registration Ticket), the ticket type is verified in step S 519, and the ticket is determined to be a service permission ticket (FRT).
- FRT File Registration Ticket
- SPT Service Permission Ticket
- step S520 the type of the Integrity Check Type (validation value of the ticket) described in the ticket (Public key method (Public) / Common key method (Common))))) It is determined whether the setting is public key method (Public).
- the process proceeds to step S521, and various processes are executed.
- the process executed in step S521 is as follows. First, the public key certificate of the ticket issuer (Ticket Issuer) using the public key PUB CA (PAR) of the certificate authority (CA (PAR)) corresponding to the partition manager. This is the verification process of the certificate (CERT).
- Service permission ticket When a ticket (Ticket) issued by an issuance means (SPT Issuer) is transmitted to a ticket user, in the case of the public key method, a service permission ticket (SRT) Public key certificate (CERT_SPTI) of issuing means (SPT Issuer) Is also sent to the device together.
- the attribute (Attribute) of the public key certificate (CERT_SPTI) of the SPT issuing means matches the identifier (SPTIC) of the service permission ticket (SPT) issuing means (SPT Issuer).
- the public key certificate (see Fig. 11) has a signature executed with the private key of the CA (PAR) corresponding to the partition manager, and this signature is used to transfer the signature to the CA (CA). (PAR)) using the public key PUB CA (PAR).
- the signature generation and verification are executed, for example, as processing according to the flow of FIGS. 12 and 13 described above. This signature verification determines whether the ticket issuer's public key certificate (CERT) is a legitimate public key certificate (CERT) that is not falsified.
- step S521 the user's belonging code recorded in the option area of the public key certificate (CERT) of the ticket issuing means that has been verified by signature verification and the file definition block ( It is determined whether or not it matches the ticket issuing means code (SPTIC: SPT Issuer Code) recorded in FDB: File Definition Block).
- CERT public key certificate
- FDB File Definition Block
- the public key certificate includes a ticket issuer (PRT, FRT, SPT, etc.) as a means for issuing each ticket (Ticket Issuer). ),
- the SPT IC SPT Issuer Code
- SPTIC SPT Issuer Code
- the device can store CRL_PAR (excluded device (Device)) and excluded devices (reader / writer as device access device, ticket user such as PC, ticket, etc.) stored in the partition key area (see Fig. 23) in the memory section of the device.
- the ticket issuing means (Ticket Issuer) has been recalled by referring to the revocation list (Revocation List (Certificate)) in which the public key certificate identifier (ex. Serial number: SN) of the issuing means has been registered. Determine if there is any.
- the service permission ticket (SPT) which is the receiving ticket (Fig. 28, Fig. 31) Verify) the signature recorded in the certificate, that is, the Integrity Check Value (validation value of the ticket (Ticket) (public key method: Signature)), and check whether the ticket has been tampered with.
- SPT service permission ticket
- the signature verification is executed in the same manner as the signature verification of the public key certificate, for example, according to the same sequence as the flow in FIG.
- the public key certificate (CERT) of the ticket issuer (Ticket Issuer) is a valid public key certificate (CERT) that is not falsified
- the ticket issuer (Ticket Issuer) The code recorded in the optional area of the public key certificate (CERT) matches the ticket issuing means code (SPTIC: SPT Issuer Code) recorded in the FDB (File Definition Block) in the device.
- SPTIC SPT Issuer Code
- the ticket issuer (Ticket Issuer) has not been revoked
- the ticket has not been tampered with by verifying the signature of the received ticket (SPT).
- SPT Service Definition Block
- step S520 the setting of the Integrity Check Type (the type of the validity verification value of the ticket (Public) / Public key method (Co-band on)) described in the ticket is changed. If it is determined that the common key method (Common) is used, the process advances to step S522 to perform MAC (Message Authentication Code) verification.
- the device performs the MAC verification process on the ticket using the service authorization ticket (SPT) MAC verification key: Kspt stored in the file definition block of the device (see Fig. 24).
- SPT service authorization ticket
- the MAC verification processing is executed according to the MAC value generation processing using the DES encryption processing configuration of FIG. 59 described above.
- the ICV Intelligent Check Value
- the ICV generated by the data sender at the time of data generation, which is guaranteed to be free from tampering
- the ICV generated by the data receiver based on the received data. If the CV is obtained, it is guaranteed that the data has not been tampered with. If the ICV is different, it is determined that the data has been tampered with.
- the ICV generated at the time of data generation by the data sender which is guaranteed not to be tampered, was described in the description of the format of the service permission ticket (SPT) in Figs. 28 and 31. As such, it is stored in the I CV (Integrity Check Value) field of the SPT.
- the ICV generated by the device is compared with the ICV stored in the received ticket (SPT). If they match, the ticket is judged to be valid. If they do not match, the ticket has been tampered. Judge and stop the process using the service permission ticket (SPT). The above processing completes the service permission ticket (SPT) verification processing when the Integrity Check Type described in the service permission ticket (SPT) is a common key method.
- step S 519 If it is determined in step S 519 that the ticket type is not a service permission ticket (SPT: Service Permission Ticket), the ticket type is verified in step S 523, and the ticket is replaced by a data update ticket.
- DEV Data Update Ticket
- the data update ticket (DUT) is an access permission ticket used when updating various data stored in the memory of the device, and is applied to the process of updating the management data of the device manager.
- DEV Data Update Ticket
- DUT Data Update Ticket
- PAR data update ticket-PAR
- step S524 executes steps S524 to S528 to execute the data update ticket (DEV) (DUT: Data Update Ticket). If not (DEV)), the flow advances to step S529.
- DEV data update ticket-D EV
- step S524 the type of the integrity check type (the validity verification value of the ticket (Ticket)) described in the ticket ( It is determined whether the setting of the public key method (Public) / common key method (Coon))) is the public key method (Public).
- step S525 When the type (Integrity Check Type) of the validity verification value is the public key method (Public), the process proceeds to step S525 to execute various processes.
- the process executed in step S525 is as follows. First, the public key certificate (C) of the ticket issuer (Ticket Issuer) using the public key PU BCA (D EV) of the certificate authority (CA (DEV)) corresponding to the device manager. ERT) verification processing.
- Data application ticket-DEV (DUT (DEV))
- DUT Data application ticket-DEV
- the public key certificate (CERT_DUTI) of the ticket (DUT) issuer (DUT Issuer) is also sent to the device.
- the attribute of the public key certificate (CERT_DUTI) of the DUT issuance means is the ticket issuance code (DUTIC) recorded in the DKD B (PUB) (Device Key Definition Block) (PUB) in the device.
- DUTIC ticket issuance code
- the public key certificate (see Fig. 11) has a signature executed with the private key of the certificate authority (CA (DEV)) corresponding to the device manager, and this signature is used by the certificate authority corresponding to the device manager (CA (DEV)). )) Using public key PUB CA (D EV).
- the signature generation and verification are executed, for example, as processing according to the flow of FIGS. 12 and 13 described above. This signature verification determines whether the ticket issuer's public key certificate (CERT) is a legitimate public key certificate (CERT) that is not falsified.
- step S525 the user's belonging code recorded in the option area of the public key certificate (CERT) of the ticket issuing means that has been verified by signature verification and the DKDB (PUB) in the device Judge whether it is the same as the ticket issuing means code (DUTIC-DEV: DUT Issuer Category for Device) recorded in (Device Key Definition Block) (PUB).
- CERT public key certificate
- PUB DKDB
- the public key certificate has a ticket issuing means (Ticket issuing means) (PRT, FRT, SPT, DUT). Issuer) belonging code, in this case, DUT IC (DUT Issuer Code).
- Ticket issuing means PRT, FRT, SPT, DUT
- Issuer belonging code, in this case, DUT IC (DUT Issuer Code).
- the code of this option area and the ticket issuing means code (DUTIC—DEV: DUT Issuer Category for Device) recorded in the DKDB (PUB) (Device Key Definition Block) (PUB) in the device (see Figure 16) Confirm that the received ticket (DUT) is a ticket issued by a valid ticket issuing means by confirming the match.
- the device has a device key area in the memory part of the device (see Figure 18).
- Public key certificate identifier (ex. Serial number: SN) of CRL_DEV (rejected device (Device), rejected device (rewriter / writer as device access device, ticket user such as PC, ticket issuing means)) stored in Refers to the Revocation List (Certificate)) in which is registered, and determines whether the ticket issuer (Ticket Issuer) has been revoked.
- the signature recorded in the data update ticket-DEV (DUT (DEV)) (see FIG. 32), which is the reception ticket, that is, the integrity check value (the validity verification value of the ticket (Ticket) (public key)
- the integrity check value the validity verification value of the ticket (Ticket) (public key)
- the signature verification is the same as the signature verification of the public key certificate, for example, the flow shown in Fig. 13 It is executed according to the sequence of
- the public key certificate (CERT) of the ticket issuer (Ticket Issuer) is a valid public key certificate (CERT) that is not falsified
- the ticket issuer (Ticket Issuer). Public key certificate (CERT) in the optional area
- the ticket issuing code (DUTIC—DEV) recorded in the DKDB (PUB) (Device Key Definition Block) (PUB) in the device. : (DUT Issuer Category for Device) match, (3) Ticket issuer (Ticket Issuer) has not been revoked, (4) Received ticket (DUT) signature (Signature) verification indicates that the ticket has been tampered with. Confirmation that there is not.
- the data update ticket-DEV (DUT (DEV)) shall be verified as valid on the condition that all the above confirmations have been made. If any of the above (1) to (4) is not confirmed, it is determined that the validity of the data update-ticket-DEV (DUT (DEV)) cannot be obtained, and the data update ticket is not available. -Processing using DEV (DUT (DEV)) is stopped.
- step S524 the setting of Integrity Check Type (the type of the validity verification value of the ticket (Ticket) (public key method (Public) / common key method (Common))) described in the ticket is changed to the common key. If it is determined that the method is “Coanda on”, in step S526, the data indicated by the Old Data Code described in the data update ticket-DEV (DUT (DEV)) is stored in the device key area (see FIG. 1 8) It is determined whether it is Kdut_DEVl (MAC key for data update ticket (DUT) MAC) or Kdut_DEV2 (encryption key for data update).
- Kdut_DEVl MAC key for data update ticket (DUT) MAC
- Kdut_DEV2 encryption key for data update
- Kdut_DEVl where the data indicated by the old data code (old data code to be updated) described in the DEV (DUT (D EV)) is stored in the development key area (see Fig. 18). (If it is a key for verifying the MAC of the data update ticket (DUT)) or Kdut_DEV2 (encryption key for data update), it is stored in the device key area (see Fig. 18) in step S528.
- Kdut_DEV3 the MAC key for the update update ticket (DUT)
- Kdut_DEVl data update ticket (DUT) MAC verification key
- Kdut_DEV2 data update encryption key
- the data to be updated is Kdut_DEVl (the MAC key for the data update ticket (DUT)) or Kdut_DEV2 (the data update key) If the key is an encryption key, the key data will be suspended for some reason, such as leakage of key information. This is to avoid C verification.
- the MA C verification processing is executed according to the MAC value generation processing using the DES encryption processing configuration of FIG. 59 described above.
- the device stores a new Kdut_DEVl (data update ticket (DUT) MAC verification key) in the device key area of the device (see Fig. 18), it stores the previously stored Kdut_DEV3 (data update ticket). (DUT) MAC swap key), that is, swapping. Further, when newly storing Kdut_DEV2 (encryption key for data update), swapping with the previously stored Kdut_DEV4 (encryption key for data update), that is, replacement processing is performed.
- Kdut DEVI swap with Kdut DEV3, and Kdut DEV2
- Kdut DEV4 Kdut_DEV3 (data update ticket (DUT) MAC verification key) and Kdut_DEV4 (data update key) are always paired with Kdut_DEVl (data update ticket (DUT) MAC verification key)
- Kdut_DEV2 (encryption key for updating data) which is kept at a newer version.
- Kdut_DEVl and Kdut_DEV2 keys are always used keys
- Kdut_DEV3 and Kdut_DEV4 update Kdut-DEVl and Kdut_DEV2 in an emergency and replace them with the currently used Kdut-DEVI and Kdut_DEV2 keys. It has a role as a key for the backup to be performed.
- the same ICV can be obtained. In this case, it is guaranteed that the data has not been tampered with. If the ICVs are different, it is determined that the data has been tampered with. For example, an ICV that is guaranteed to be free from tampering and that is generated by the data sender at the time of data generation is used as described in the description of the format of the data update ticket (DUT) in Fig. 32. (DUT) is stored in the I CV (Integrity Check Value) field.
- ICV Integrity Check Value
- the ICV generated by the device is compared with the ICV stored in the data update packet -DEV (DUT (DEV)), which is the receive ticket, and if they match, it is determined that the ticket is valid. If they do not match, it is determined that the ticket has been tampered with, and the process using the data update ticket-DEV (DUT (DEV)) is discontinued.
- the above process completes the data update ticket-D EV (DUT (DEV)) verification process when the Integrity Check Type described in the data update ticket-D EV (DUT (DEV)) is a common key method. .
- step S523 If it is determined in step S523 that the ticket type is not the update date ticket-DEV (DUT (DEV)), the ticket is the data update ticket-PAR (DUT (PAR)) (see FIG. 32)) is determined.
- the data update ticket-PAR (DUT (PAR)) is a ticket applied to processing for updating the management data of the partition manager.
- step S529 the Integrity Check Type (the type of the validity verification value of the ticket (Ticket) (public key method (Public) / common key method (Co plate on))) described in the ticket It is determined whether the setting is a public key method (Public).
- step S530 the process executed in step S530 is performed by using the public key certificate (CERT) of the ticket issuer (Ticket Issuer) using the public key PUB CA (PAR) of the partition manager compatible certificate authority (CA (PAR)). ) Verification process.
- CERT public key certificate
- PAR partition manager compatible certificate authority
- the public key certificate (CERTJUTI) of the DUT issuer (DUT Issuer) is also sent to the device.
- the attribute of the public key certificate (CERT_DUTI) of the DUT issuing means is the ticket issuing means code (DUTIC-PAR) recorded in the PKD (PUB) (Pqrtition Key Definition block) in the device. Matches.
- the public key certificate (see Fig. 11) has a signature executed with the private key of the CA (PAR) corresponding to the partition manager, and this signature is used to transfer the signature to the CA (CA). (PAR)) using the public key PUB CA (PAR).
- the signature generation and verification are executed, for example, as processing according to the flow of FIGS. 12 and 13 described above. This signature verification determines whether the ticket issuer's public key certificate (CERT) is a legitimate public key certificate (CERT) that is not falsified.
- step S530 the user's belonging code recorded in the option area of the public key certificate (CERT) of the ticket issuing means that has been verified by signature verification, and the PKDB (PUB ) Judge whether it matches the ticket issuing means code (DUTIC_PAR: DUT Issuer Category for Partition) recorded in (Pqrtition Key Definition block).
- the public key certificate has a ticket issuing means that is a means for issuing each ticket (PRT, FRT, SPT, DUT). (Ticket Issuer) belonging code, in this case, DUT IC (DUT Issuer Code). Code of this option area and PKDB (PUB) in the device
- the ticket issuing means code (DUTIC: DUT Issuer Category) (see Fig. 21) recorded in the (Pqrtition Key Definition block) matches, the received ticket (DUT) is valid. Check that the ticket is issued by the issuing means.
- the device uses the CRL—DEV (Excluded Device (Device), Excluded Device (a reader / writer as a device access device, a ticket user such as a PC) stored in the device key area (see Fig. 18) in the memory section of the device.
- the Ticket Issuer refers to the Revocation List (Certificate) that has registered the public key certificate identifier (ex. Serial Naming: SN) of the Ticket Issuer. It is determined whether or not it has been performed.
- the signature recorded in the received update packet the overnight update ticket-PAR (DUT (PAR)) (see Fig. 32), that is, the validity verification of the Integrity Check Value (Ticket) It verifies the value (public key method: Signature) to check whether the ticket has been tampered with, as in the case of the previous public key certificate signature verification. It is executed according to the same sequence as in the flow of FIG.
- the public key certificate (CERT) of the ticket issuer (Ticket Issuer) is a legitimate public key certificate (CERT) that is not falsified
- the ticket issuer (Ticket Issuer). Public key certificate (CERT) in the optional area and the ticket issuance code (MTIC_PAR: DUT Issuer Category) recorded in the PKB (PUB) (Pqrtition Key Definition block) in the device. for Partition)
- PKB PKB
- Ticket Issuer has not been re-poked
- Ticket has not been tampered with verification of Signature of Received Ticket (DUT) Confirmation.
- the data update ticket-PAR (DUT) validity verification shall be successful on condition that all the above confirmations have been made. If any of the above (1) to (4) is not confirmed, it is determined that the validity of the data update ticket -PAR (DUT (PAR)) cannot be obtained, and Evening Update ticket-Processing using PAR (DUT (PAR)) is stopped.
- step S529 the setting of the Integrity Check Type (the type of the validity verification value of the ticket (Ticket) (public key method (Public) / common key method (Common)) described in the ticket is changed to the common key. If it is determined that the data type is “Co-band”, in step S531, the old data code described in the overnight update ticket -PAR (DUT (PAR)) is used. The data indicated by the evening code) is Kdut_PARl (MAC key for data update ticket (DUT) MAC) or Kdut_PAR2 (encryption key for data update) stored in the partition key area (see Fig. 23). Determine whether or not.
- Kdut_PARl MAC key for data update ticket (DUT) MAC
- Kdut_PAR2 encryption key for data update
- the data indicated by the old data code (old data code to be updated) described in the data update packet-PAR (DUT (PAR)) is stored in the partition key area (see Fig. 23).
- PARI MAC key for data update ticket (DUT) MAC
- Kdut_PAR2 encryption key for data update
- the partition key area see Fig. 23
- the MAC verification process is performed using Kdut_PAR3 (the MAC key for the data update ticket (DUT)) stored in), and the old data described in the data update ticket-PAR (DUT (PAR)) is executed.
- Kdut_PARl data update key for verification of MAC of DUT
- Kdut—PAR2 Data Update (old data to be updated)
- the partition key area see Figure 23
- the MAC verification process is performed using Kdut_PARl (MAC verification key of the data update ticket (DUT)) stored in the partition key area (see FIG. 23). I do.
- the reason for using the MAC verification key properly as described above is that the data to be updated is Kdut_PARl (MAC key for data update ticket (DUT) MAC) or Kdut_PAR2 (encryption key for data update).
- this key data is information that will be discontinued for some reason, for example, leakage of key information, etc. is there.
- the MAC verification process is a MAC value generation process using the DES encryption process configuration in Fig. 59 described above. It is executed according to the rules.
- the ICV Integrity Check Value
- the ICV generated by the data transmitting side at the time of data generation is the time of data generation, which is guaranteed not to be falsified. If the CV is obtained, it is guaranteed that the data has not been tampered with. If the ICV is different, it is determined that the data has been tampered with.
- the ICV generated at the time of data generation by the data transmission side, which is guaranteed not to be falsified is the IV of the data update ticket (DUT) as described in the description of the format of the data update ticket (DUT) in FIG. Stored in the CV (Integrity Check Value) field.
- the ICV generated by the device is compared with the ICV stored in the data update packet-PAR (DUT (PAR)), which is a receive ticket.If they match, it is determined that the ticket is valid and does not match. In this case, it is determined that the ticket has been tampered with, and the processing using the data update ticket-PAR (DUT (PAR)) is stopped.
- the data update ticket-PAR (DUT (PAR)) verification processing when the Integrity Check Type described in the data update ticket-PAR (DUT (PAR)) is a common key method is completed.
- step S541 of FIG. 58 the user check, that is, the reader as a device access device executing communication with the device as a ticket user. Performs a writer (or PC) check.
- step S541 the device determines whether or not mutual authentication with the device is required in the process of using the Authentication Flag of the received ticket (PRT, FRT, SPT, or DUT). Check flag). If the flag indicates that authentication is not required, the process ends without executing the process.
- step S541 if the flag indicates that authentication is required, the flow advances to step S542, where the ticket user (as a device access device that intends to execute processing applying the ticket to the device).
- the ticket user (as a device access device that intends to execute processing applying the ticket to the device).
- Authentication table (see Figure 51) using the affiliation (group) of the reader / writer, PC, etc. as a key. See).
- step S5453 the Authentication Type of the received ticket (the type of mutual authentication of the device (Device) (public key authentication or symmetric key authentication, or any of them (Any)) is recorded). Is checked, and if both are acceptable (Any), the process goes to step S544 and the mutual authentication data of the group checked in step S542 is an authentication table (see Fig. 51). Judge whether it is stored in or not. Mutual authentication information of the corresponding group is stored in the table, and the mutual authentication between the ticket user (a reader / writer as a device access device, a PC, etc., which attempts to execute the process applying the ticket to the device) and the device If it is determined that the ticket has been verified, the validity of the ticket user (ex.
- step S5453 the Authentication Type of the received ticket (the data that records the type of mutual authentication of the Device (public key authentication or symmetric key authentication, or any type of data)) is set. If neither of them is possible (Any), it is determined in step 545 whether the Authentication Type is public key authentication.
- the process proceeds to step S546, and whether the public key mutual authentication data of the group checked in step S542 is stored in the authentication table (see FIG. 51). Determine whether or not.
- the public key mutual authentication information of the corresponding group is stored in the table, and the mutual authentication between the ticket user (a reader / writer as a device access device, a PC, etc. trying to execute the process applying the ticket to the device) and the device is disclosed. If it is determined that the key authentication processing has been established, the process proceeds to step S5457, and it is determined whether the ticket user identifier exists in the processing target ticket (PRT, FRT, SPT, or DUT).
- the identifier recorded as the identification data (DN) in the public key certificate of the authentication partner (such as a reader / writer as a device for accessing a device as a ticket user) in step S548.
- the identifier recorded as the identification data (DN) in the public key certificate of the authentication partner (such as a reader / writer as a device for accessing a device as a ticket user) in step S548.
- category or serial (SN) It is determined whether the identifier, category, or serial number (SN) recorded as the identification data of the ticket stored in the packet matches. If they match, the process ends with user confirmation successful.
- step S 546 the public key mutual authentication data of the group checked in step S 542 is not stored in the authentication table (see FIG. 51), and the ticket user (executes a process that applies a ticket to the device). If it is determined that mutual authentication between the device (reader / writer as an access device, PC, etc.) and the device has not been established as public key authentication processing, it is determined that the user check has not been completed, and the error is terminated.
- step S548 the identifier and the category or serial or SN recorded as the identification data (DN) in the public key certificate of the authentication partner (such as a reader / writer as a device access device that is a ticket user) are added to the ticket. If it is determined that the identifiers of the stored ticket users do not match, it is determined that the user check has not been completed, and the error is terminated.
- the authentication partner such as a reader / writer as a device access device that is a ticket user
- step S548 If there is no ticket user identifier in the ticket, the process in step S548 is not executed, and the process ends as the user confirmation is successful.
- step S545 the Authentication Type of the received ticket (the type of mutual authentication of the device (public key authentication or symmetric key authentication, or any one of which is recorded as Any)) is set. If it is determined that the authentication is not public key authentication, the process advances to step S549 to determine whether or not the common key mutual authentication data of the group checked in step S542 is stored in the authentication table (see FIG. 51). The common key mutual authentication information of the corresponding group is stored in the table, and the ticket user (such as a reader / writer as a device access device or a PC that attempts to execute a process that applies the ticket to the device) between the device and the device.
- the ticket user such as a reader / writer as a device access device or a PC that attempts to execute a process that applies the ticket to the device
- step S550 the process proceeds to step S550, and the ticket user identifier (PRT, FRT, SPT, or DUT) is assigned to the process target ticket.
- step S551 the identification data (ID rw) of the authentication partner (such as a reader / writer as a device access device that is a ticket user) and the ticket are determined. Ticket user identifier stored in It is determined whether or not to perform. If they match, the process ends as the user confirmation is successful.
- step S549 the common key mutual authentication data for the group checked in step S542 is not stored in the authentication table (see FIG. 51), and the ticket user (executes a process that applies a ticket to the device). If it is determined that mutual authentication between the device (reader / writer as an access device, PC, etc.) and the device has not been established as common key authentication processing, it is determined that the user check has not been completed, and the error is terminated.
- step S551 it is determined that the identification data (ID rw) of the authentication partner (such as a reader / writer as a device access device that is a ticket user) does not match the identifier of the ticket user stored in the ticket. Also in this case, it is determined that the user check has not been completed, and the error is terminated.
- ID rw the identification data of the authentication partner
- step S550 If there is no ticket user identifier in the ticket or if all ticket users are available, the process in step S550 is not executed, and the process ends as a user confirmation success.
- partition creation and deletion processing based on the partition registration ticket (PRT) executed in step S415 shown in the flow of FIG. 47 will be described. This will be described using one.
- the process of creating and deleting partitions is based on the partition registration ticket (PRT) when a device that receives a partition registration ticket (PRT) from a ticket user (ex. A reader / writer as a device access device, PC, etc.) receives the partition registration ticket (PRT). This is the process to be executed.
- step S601 of FIG. 60 the device specifies the processing type recorded in the received partition registration ticket (PRT: PartitionRegistration ticket), that is, specifies whether to create or delete the Operation Type (Partition). Verify (Generate) / Delete (Delete))). If the processing type (Operation Type) is to create a partition (Partition), execute steps S602 and below. If the processing type is to delete a partition (Partition), execute steps S621 and below. I do.
- PRT PartitionRegistration ticket
- step S602 the device verifies whether a partition having the same code as the partition management code (PMC) described in the partition registration ticket (PRT) exists in the memory portion of the device. . This determination can be made by verifying whether the same code as the description code of the reception ticket (PRT) is described in the partition definition block (see Figure 19) in the memory section of the device. It is. If a partition with the same code (PMC) already exists in the device, the existence of a duplicate partition with the same code is not allowed, the partition is not created, and the error ends.
- PMC partition management code
- PRT partition registration ticket
- step S603 the number of free blocks (Free Block Number in Device) in the device (Device) in the device management information block (see FIG. 15) and the partition registration ticket Compare with the partition size (Partion Size) described in (PRT), and check if there is a free block area in the device memory that is equal to or larger than the partition size (Partion Size) described in the ticket (PRT). Determine whether or not. If it does not exist, a partition of the size described in the PRT cannot be generated, so the error is terminated.
- step S604 If it is determined that an empty block area equal to or larger than the partition size (Partion Size) described in the ticket (PRT) exists in the memory of the device, the process proceeds to step S604, and the empty area pointer of the device management information block is determined. Refer to (Pointer of Free Area) and secure partition definition block (PDB) area (see Fig. 19) in the highest block of free area in device (Free Area in Device).
- partition Size partition size described in the ticket
- the device copies (S605) the partition manager code (PMC) described in the partition registration ticket (PRT) to the secured partition definition work (PDB) area, and writes the copy to the PRT. Execute the copy of the PMC version (S606).
- a device management information block ( Figure 15) is added to the partition start position (Partition Start Position) in the partition definition block (PDB) area. (See S 607), and further registers the partition registration ticket in the partition size of the partition definition block (PDB).
- the copy processing of the partition size (Partion Size) described in the PRT (PRT) is executed (S608).
- the value copied to the partition size (Partion Size) of the partition definition block (PDB) area is added to the free area pointer (Pointer of Free Area) of the device management information block (see Fig. 15) (S60). 9) Then, the partition size (Partion Size) + 1 is subtracted from the number of free blocks (Free Block Number in Device) in the device (Device) of the device management information block (see Fig. 15) (S610). In addition, +1 means a block for a partition definition block (PDB).
- Partition Number the number of partitions (Partition Number) of the device management information block (see Fig. 15), that is, the number of generated partitions (1) is added (S611) o
- step S631 in FIG. 61 the highest-order block of the generated partition area is set as a partition management information block (PMIB) (see FIG. 20).
- the PMC of the partition registration ticket (PRT) is copied to the partition manager code (PMC) field of the set partition management information block (PMI B) (S632), and the partition management information block is executed.
- the copy processing of the PMC purge of the partition registration ticket (PRT) is executed in the PMC version field of the (PM IB) (S633), and the partition total block of the partition management information block (PMIB) is executed. Total Block number in Partition field
- the copy processing of e) is executed (S634).
- partition Size of the partition registration ticket (PRT)-3 is recorded in the Free Block number in Partition field of the partition management information block (PMI B) (S 635).
- the meaning of 13 means that the partition management information block (PM IB), the common key partition key definition block (PKD B (co ⁇ on)), the public key partition key definition block ( It means subtracting 3 blocks of PKDB (PUB)).
- the start position of the partition definition block (PDB) is copied to the free area pointer (Pointer of Free Area) of the partition management information block (PM IB), and the partition setting registration is completed. .
- step S621 it is verified whether or not a partition having the same code as the partition manager code (PMC) described in the partition registration ticket (PRT) exists in the memory of the device. This determination is made by verifying whether or not the same code as the description code of the reception ticket (PRT) is described in the partition definition block (see FIG. 19) of the memory section of the device. Can be determined.
- PMC partition manager code
- PRT partition registration ticket
- step S622 it is determined whether a partition created after the partition to be deleted exists in the device. If not, the partition to be deleted is the latest partition, and in step S629, the partition definition block (PDB) (see FIG. 19) of the partition to be deleted is deleted.
- PDB partition definition block
- step S622 If it is determined in step S622 that a partition created after the partition to be deleted exists on the device, the partition created later is deleted.
- the data of the issue (post-partition) is shifted down by the size of the partition to be deleted (PS) (S623), and the partition definition block (PDB) of the post-partition is moved up by one block. Is performed (S624). Further, a process of subtracting the size (PS) of the deletion partition from the partition start position (Partition Start Portion) recorded in the partition definition work (PDB) of the subsequent partition is executed (S625).
- step S626 the number of empty blocks (Free Block Number in Device) in the device of the device management information block (DMIB) (see FIG. 15) is read. ) Is added to the size of the deleted partition (PS) +1. +1 means a block for the partition definition block (PDB) of the deleted partition.
- DMIB device management information block
- step S627 the size (PS) of the partition to be deleted is subtracted from the value of the free area pointer (Pointer of Free Area) in the device management information block (see FIG. 15). Further, in step S628, 1 is subtracted from the number of partitions (Partition Number) of the device management information block (see FIG. 15), that is, the number of deleted partitions (1) is subtracted to obtain a partition registration ticket (PRT). The partition deletion processing based on is terminated.
- PRT partition registration ticket
- FIG. 47 details of the partition initial data write processing of steps S 406 and S 419 in the processing flow of FIG. 47, that is, the partition initial registration processing based on the partition registration ticket (PRT) are shown in FIG. It will be explained using the first word.
- the left side shows the processing of the initial registration device under the control of the Partition Manager
- the right side shows the processing of the device (see FIG. 5).
- the initial registration device under the jurisdiction of the partition manager is a device that can read and write data to the device (ex. A reader / writer as a device access device, a PC). Re It has a configuration corresponding to one dalitar.
- mutual authentication is established between the initial registration device and the device, and the ticket and the user (the ticket) are checked in the validity of the ticket and the user check.
- step S641 in FIG. 62 the initial registration device determines whether to use a common key for partition authentication. This determination is based on the type of mutual authentication of the authentication type (Device) of the partition registration ticket (PRT) (see Figure 26) to be used (public key authentication or symmetric key authentication, or any ))) This is done with reference to the field.
- the authentication type Device
- PRT partition registration ticket
- steps S642 to 643 and S651 to S654 are performed. If a common key is not used for partition authentication, these steps are omitted. Is done.
- the initial registration device sends a common key authentication data write command as MKauth—PAR_A: master key for bidirectional individual key authentication, Kauth—PAR_B: bidirectional Common key for individual key authentication, IRL—PAR: Revocation List (Device ID) in which the device identifier (ID) of the exclusion device (Device) is registered, and the version information are sent to the device. I do.
- step S651 the device receives the write command described above, and
- the received data is written to the partition key area (see Fig. 23).
- the pointer, size, and the number of free locks in the device generated by the data write are adjusted (S653), and a write completion notification is transmitted to the registration device (S653).
- the registration device that has received the write end notification determines in step S644 whether or not to use a public key for partition authentication. As shown in Figure 62 If a public key is used for partition authentication, steps S645 to 649 and S655 to S662 are executed. If no public key is used for partition authentication, these steps are omitted.
- the registration unit sends a public key authentication data write command as PUB_CA (PAR): a certificate authority CA (PAR) that issues a public key certificate corresponding to the partition manager.
- PAR public key authentication data write command
- PARAM_PAR Public key parameter of the partition (Partition)
- CRL_PAR Revocation list (Revocation List (Certificate) in which the public key certificate identifier (ex. ))
- Devise a public key authentication data write command as PUB_CA
- PARAM_PAR Public key parameter of the partition (Partition)
- CRL_PAR Revocation list (Revocation List (Certificate) in which the public key certificate identifier (ex. )) And their version information to Devise.
- step S655 the device receives the above-mentioned write command, and in step S656, writes the received data into the partition key area (see FIG. 23).
- step S657 the pointer, size, and the number of free locks in the device generated by data writing are adjusted (S657), and a write completion notification is transmitted to the registration device (S658).
- the registration device that has received the write end notification (S 646) transmits a public key and secret key key generation command to the device (S 647).
- the key pair is generated by the device, but the key pair may be generated by the registration device and provided to the device.
- the device that has received the key pair generation command (S 659) generates and generates a pair of a public key (PUB PAR) and a secret key (PR I PAR) in the encryption processing unit (see Fig. 5) in the device.
- the key is written in the partition key area (see FIG. 23) (S660).
- the pointer, size, and the number of free blocks in the device generated by the data writing are adjusted (S661), and the generated and stored public key is transmitted to the registration device (S666).
- the registration device receives the public key (PUB PAR) from the device (S648), and the database (DB (PAR)) in the partition manager together with the device identifier I Dm previously received from the device (see Fig. 9). )) Save to.
- the partition manager's registration device uses the file registration ticket (FR T: It is determined whether or not a common key is used for the verification processing of the File Registration Ticket (S671).
- ticket verification can be performed using either a common key method using MAC value verification or the like, or a public key method using signature generation using a private key and signature verification using a public key.
- the manager can set the verification processing method adopted by the device.
- the partition manager sets the data that can execute either the common key, the public key, or both methods to the device according to the FRT ticket verification method adopted by the device.
- the partition manager is configured to execute common key authentication in the verification processing of the file registration ticket (FRT: File Registration Ticket)
- FRT File Registration Ticket
- the information required for common key FRT verification (ex. FRT verification common key) is set in the device, and if the device does not perform common key authentication, this information will not be stored in the device.
- step S672 the registration device transmits the Kfrt: file verification ticket (FRT) MAC verification key and version information to the device as an FRT verification common key write command. Send.
- FRT file verification ticket
- step S681 the device receives the above-mentioned write command, and in step S682, writes the received data in the partition key area (see FIG. 23).
- step S683 the pointer, the size, and the number of free blocks in the device generated by the data writing are adjusted (S683), and a write completion notification is transmitted to the registration device (S684).
- the registration device that has received the write end notification determines in step S674 whether to use a public key for FRT verification. As shown in FIG. 63, if a public key is used for FRT verification, steps S675 to S676 and S685 to S690 are executed, and if a public key is not used for FRT verification, these steps are omitted. Is done.
- the registration device sends an FRT verification data write command as FRTIC (FRT Issuer Category): PUB_CA (PAR): Public key of the certification authority CA (PAR) that issues the public key certificate corresponding to the Partition Manager, PARAM_PAR: Public key of the Partition (Partition) Overnight, CRL_PAR: Revocation List (Certificate) in which the public key certificate identifier (ex. Serial number: SN) of the rejected device (Device) is registered, and the version information of the revocation list Send to FRTIC (FRT Issuer Category): PUB_CA (PAR): Public key of the certification authority CA (PAR) that issues the public key certificate corresponding to the Partition Manager, PARAM_PAR: Public key of the Partition (Partition) Overnight, CRL_PAR: Revocation List (Certificate) in which the public key certificate identifier (ex. Serial number: SN) of the rejected device (Device) is registered, and the version information of the revocation
- step S685 the device receives the write command described above, and in step S686, defines the FRTIC (FRT Issuer Category): file registration ticket (FRT) issuer category in the received data as a public key type partition key.
- FRTIC FRT Issuer Category
- FRT file registration ticket
- step S686 defines the FRTIC (FRT Issuer Category): file registration ticket (FRT) issuer category in the received data as a public key type partition key.
- PKDB Partition Key Definition block (PUB) (see Fig. 22)
- PDB Partition Key Definition block
- step S687 the device determines whether or not the public key data of the certificate authority CA (PAR) that issues the public key certificate corresponding to PUB_CA (PAR): Partition manager has been written. If not, in step S688, PUB—CA (PAR), PARAM_PAR, and CRL_PAR are written to the partition key area (see FIG. 23). Next, the pointer, the size, and the number of free blocks in the device generated by the data write are adjusted (S689), and a write end notification is transmitted to the registration device (S690).
- PAR public key data of the certificate authority CA
- PARAM_PAR PARAM_PAR
- CRL_PAR CRL_PAR
- the registration device that has received the write end notification determines in step S701 whether or not the device is a device that supports updating of the common key data.
- Some of the data stored in the device can be updated using the above-mentioned data update ticket (DUT: Data Update Ticket) (see Fig. 32) as the data to be updated.
- the data to be updated is as described above with reference to FIG.
- the update process using the Data Update Ticket either the common key method or the public key method is possible, and the partition manager responds to the set partition. Configure the device to run either or both methods.
- the partition manager is configured to execute the data update of the set partition using the common key method, the information necessary for the data update processing of the common key method is used.
- Information (ex. The MAC key of the data update ticket (DUT), etc.) is set in the partition key area of the device, and if the device does not execute symmetric key authentication, this information is stored in the device. Do not store in the partition key area.
- steps S702-703 and S711-S71 are performed. If step 4 is performed and the secret key method is not used for data update, these steps are omitted.
- step S702 the registration device sends a data update ticket (DUT: Data Update Ticket) verification common key write command as Kdut_PARl: data update ticket (DUT).
- Kdut_PAR2 Data update key
- Kdut— PAR3 Data update ticket (DUT)
- Kdut_PAR4 Data update key
- step S711 the device receives the write command described above, and in step S712, writes the received data to the partition key area (see FIG. 23).
- step S713 the pointer, size, and the number of flip-locks in the device generated by the data writing are adjusted (S713), and a write completion notification is transmitted to the registration device (S714).
- step S704 the registration device that has received the write end notification (S703) updates the data using a data update ticket (DUT: Data Update Ticket) using a public key method for the partition set in the device. Determines whether to support the process. As shown in FIG. 64, if the public key method is supported, steps S705 to S706 and S715 to S718 are performed.If the public key method is not supported, these steps are performed. Omitted.
- step S705 the registration device sends a DUTIC_PAR (DUT Issuer Category): data update ticket (DUT) as a command to write a data update ticket (DUT: Data Update Ticket) issuer code. : Data Update Ticket) Issuer category and version information Send to vice.
- DUTIC_PAR DUT Issuer Category
- DUT data update ticket
- DUT Data Update Ticket
- Issuer category and version information Send to vice.
- step S715 the device receives the above-mentioned write command, and in step S716, receives the received data from the public key partition key definition block (PK DB (PUB): Partition Key Definition Block (PUB). )).
- PK DB public key partition key definition block
- step S716 receives the received data from the public key partition key definition block (PK DB (PUB): Partition Key Definition Block (PUB). )).
- PDB public key partition key definition block
- PDB Partition Key Definition Block
- FIG. 65 shows an example of the configuration of the data stored in the memory of the device in a state where the initial registration processing (the processing flow in FIGS. 62 to 64) by the partition manager has been completed.
- the partition key area in the partition area shown in FIG. 65 the following data transmitted from the registration device and written in the above-mentioned opening (FIGS. 62 to 64) is written.
- IRL—PAR Relocation list in which the partition access exclusion device (Device) and the identifier (ID) of the exclusion device (reader / writer as device access device, ticket user such as PC, ticket issuing means) are registered. (Revocation List (Device ID))
- CRL_PAR The public key certificate identifier (ex. Serial number: SN) of the partition access exclusion device (Device) and exclusion device (reader / writer as device access device, ticket user such as PC, ticket issuing means) Registered Revocation List (Certificate)
- Kdut_PARl Key for verifying the MAC of the data update ticket (DUT)
- Kdut_PAR3 Key for MAC verification of data update ticket (DUT)
- Partition Key Information Block Partition Key Definition Block (Common)
- Partition Key Definition Block Partition Key Definition Block (PUB)
- Partition Management Information Block is data that is written when a partition is created (see processing flow charts 60 and 61).
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Databases & Information Systems (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Storage Device Security (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Description
Claims
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR1020027015410A KR100860162B1 (ko) | 2001-03-15 | 2002-03-07 | 액세스 제어 티켓을 이용한 데이터 액세스 관리 시스템 및관리 방법 |
EP02702791A EP1303075A4 (en) | 2001-03-15 | 2002-03-07 | DATA ACCESS MANAGEMENT SYSTEM AND MANAGEMENT METHOD USING ACCESS CONTROL BILL |
HK04104631.3A HK1062971A1 (en) | 2001-03-15 | 2004-06-28 | Data access management system and management method using access control ticket, data access management system, memory-equipped device, data access management method |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2001-73353 | 2001-03-15 | ||
JP2001073353A JP2002278839A (ja) | 2001-03-15 | 2001-03-15 | データアクセス管理システム、メモリ搭載デバイス、およびデータアクセス管理方法、並びにプログラム記憶媒体 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2002076013A1 true WO2002076013A1 (fr) | 2002-09-26 |
Family
ID=18930794
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/JP2002/002113 WO2002076013A1 (fr) | 2001-03-15 | 2002-03-07 | Systeme de gestion d'acces aux donnees et procede de gestion utilisant un billet de commande d'acces |
Country Status (7)
Country | Link |
---|---|
US (1) | US20030188117A1 (ja) |
EP (1) | EP1303075A4 (ja) |
JP (1) | JP2002278839A (ja) |
KR (1) | KR100860162B1 (ja) |
CN (1) | CN100483991C (ja) |
HK (1) | HK1062971A1 (ja) |
WO (1) | WO2002076013A1 (ja) |
Families Citing this family (149)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US10181953B1 (en) | 2013-09-16 | 2019-01-15 | Amazon Technologies, Inc. | Trusted data verification |
JP2002298105A (ja) * | 2001-03-30 | 2002-10-11 | Sony Corp | データ記憶装置および方法、情報処理装置および方法、記録媒体、並びにプログラム |
US7509683B2 (en) * | 2002-08-26 | 2009-03-24 | Hewlett-Packard Development Company, L.P. | System and method for authenticating digital content |
US7370212B2 (en) | 2003-02-25 | 2008-05-06 | Microsoft Corporation | Issuing a publisher use license off-line in a digital rights management (DRM) system |
EP1754157B1 (en) * | 2004-04-30 | 2013-05-22 | Research In Motion Limited | Content protection ticket method and device |
FR2874440B1 (fr) | 2004-08-17 | 2008-04-25 | Oberthur Card Syst Sa | Procede et dispositif de traitement de donnees |
US8051052B2 (en) * | 2004-12-21 | 2011-11-01 | Sandisk Technologies Inc. | Method for creating control structure for versatile content control |
US8601283B2 (en) | 2004-12-21 | 2013-12-03 | Sandisk Technologies Inc. | Method for versatile content control with partitioning |
US20060242151A1 (en) * | 2004-12-21 | 2006-10-26 | Fabrice Jogand-Coulomb | Control structure for versatile content control |
US8504849B2 (en) | 2004-12-21 | 2013-08-06 | Sandisk Technologies Inc. | Method for versatile content control |
US20060242067A1 (en) * | 2004-12-21 | 2006-10-26 | Fabrice Jogand-Coulomb | System for creating control structure for versatile content control |
US20060242150A1 (en) * | 2004-12-21 | 2006-10-26 | Fabrice Jogand-Coulomb | Method using control structure for versatile content control |
US20060242066A1 (en) * | 2004-12-21 | 2006-10-26 | Fabrice Jogand-Coulomb | Versatile content control with partitioning |
US20060143417A1 (en) * | 2004-12-23 | 2006-06-29 | David Poisner | Mechanism for restricting access of critical disk blocks |
US8438645B2 (en) | 2005-04-27 | 2013-05-07 | Microsoft Corporation | Secure clock with grace periods |
US8725646B2 (en) | 2005-04-15 | 2014-05-13 | Microsoft Corporation | Output protection levels |
US8127147B2 (en) * | 2005-05-10 | 2012-02-28 | Seagate Technology Llc | Method and apparatus for securing data storage while insuring control by logical roles |
US20060265758A1 (en) * | 2005-05-20 | 2006-11-23 | Microsoft Corporation | Extensible media rights |
US7743409B2 (en) | 2005-07-08 | 2010-06-22 | Sandisk Corporation | Methods used in a mass storage device with automated credentials loading |
US9054879B2 (en) * | 2005-10-04 | 2015-06-09 | Google Technology Holdings LLC | Method and apparatus for delivering certificate revocation lists |
US9177114B2 (en) * | 2005-10-04 | 2015-11-03 | Google Technology Holdings LLC | Method and apparatus for determining the proximity of a client device |
US20070136226A1 (en) * | 2005-12-14 | 2007-06-14 | Xerox Corporation | Jdf package management method |
US9158467B2 (en) * | 2006-02-21 | 2015-10-13 | Spectra Logic Corporation | Optional data encryption by partition for a partitionable data storage library |
US20070226507A1 (en) * | 2006-03-22 | 2007-09-27 | Holzwurm Gmbh | Method and System for Depositing Digital Works, A Corresponding Computer Program, and a Corresponding Computer-Readable Storage Medium |
JP2008009717A (ja) * | 2006-06-29 | 2008-01-17 | Megachips Lsi Solutions Inc | 情報処理端末およびコンテンツ書き込みシステム |
US20080010458A1 (en) * | 2006-07-07 | 2008-01-10 | Michael Holtzman | Control System Using Identity Objects |
US8140843B2 (en) | 2006-07-07 | 2012-03-20 | Sandisk Technologies Inc. | Content control method using certificate chains |
US20080022395A1 (en) * | 2006-07-07 | 2008-01-24 | Michael Holtzman | System for Controlling Information Supplied From Memory Device |
US8613103B2 (en) | 2006-07-07 | 2013-12-17 | Sandisk Technologies Inc. | Content control method using versatile control structure |
US20080010449A1 (en) * | 2006-07-07 | 2008-01-10 | Michael Holtzman | Content Control System Using Certificate Chains |
US8639939B2 (en) | 2006-07-07 | 2014-01-28 | Sandisk Technologies Inc. | Control method using identity objects |
US8245031B2 (en) * | 2006-07-07 | 2012-08-14 | Sandisk Technologies Inc. | Content control method using certificate revocation lists |
US8266711B2 (en) * | 2006-07-07 | 2012-09-11 | Sandisk Technologies Inc. | Method for controlling information supplied from memory device |
US20080034440A1 (en) * | 2006-07-07 | 2008-02-07 | Michael Holtzman | Content Control System Using Versatile Control Structure |
US9537943B2 (en) * | 2006-10-06 | 2017-01-03 | Core Wireless Licensing S.A.R.L. | System, method, apparatus, and computer program product for providing a social network diagram in a P2P network device |
US7841010B2 (en) * | 2007-01-08 | 2010-11-23 | Apple Inc. | Software or other information integrity verification using variable block length and selection |
FR2913511B1 (fr) * | 2007-03-06 | 2009-04-24 | Thales Sa | Procede de modification de secrets compris dans un module cryptographique, notamment en milieu non protege |
US20090144557A1 (en) * | 2007-07-26 | 2009-06-04 | Hyblue, Inc. | Recoverable secure data store system and method |
US20090038007A1 (en) * | 2007-07-31 | 2009-02-05 | Samsung Electronics Co., Ltd. | Method and apparatus for managing client revocation list |
JP5024056B2 (ja) * | 2008-01-07 | 2012-09-12 | 富士ゼロックス株式会社 | 操作管理システム |
FR2931968B1 (fr) * | 2008-06-02 | 2012-11-30 | Alcatel Lucent | Procede et equipement de stockage de donnees en ligne |
US8275830B2 (en) | 2009-01-28 | 2012-09-25 | Headwater Partners I Llc | Device assisted CDR creation, aggregation, mediation and billing |
US8832777B2 (en) | 2009-03-02 | 2014-09-09 | Headwater Partners I Llc | Adapting network policies based on device service processor configuration |
US8924543B2 (en) | 2009-01-28 | 2014-12-30 | Headwater Partners I Llc | Service design center for device assisted services |
US8346225B2 (en) | 2009-01-28 | 2013-01-01 | Headwater Partners I, Llc | Quality of service for device assisted services |
US8391834B2 (en) | 2009-01-28 | 2013-03-05 | Headwater Partners I Llc | Security techniques for device assisted services |
US8924469B2 (en) | 2008-06-05 | 2014-12-30 | Headwater Partners I Llc | Enterprise access control and accounting allocation for access networks |
US8402111B2 (en) | 2009-01-28 | 2013-03-19 | Headwater Partners I, Llc | Device assisted services install |
US8898293B2 (en) | 2009-01-28 | 2014-11-25 | Headwater Partners I Llc | Service offer set publishing to device agent with on-device service selection |
US8635335B2 (en) | 2009-01-28 | 2014-01-21 | Headwater Partners I Llc | System and method for wireless network offloading |
US8626115B2 (en) | 2009-01-28 | 2014-01-07 | Headwater Partners I Llc | Wireless network service interfaces |
US8548428B2 (en) | 2009-01-28 | 2013-10-01 | Headwater Partners I Llc | Device group partitions and settlement platform |
US8725123B2 (en) | 2008-06-05 | 2014-05-13 | Headwater Partners I Llc | Communications device with secure data path processing agents |
US8340634B2 (en) | 2009-01-28 | 2012-12-25 | Headwater Partners I, Llc | Enhanced roaming services and converged carrier networks with device assisted services and a proxy |
US8589541B2 (en) | 2009-01-28 | 2013-11-19 | Headwater Partners I Llc | Device-assisted services for protecting network capacity |
US8406748B2 (en) | 2009-01-28 | 2013-03-26 | Headwater Partners I Llc | Adaptive ambient services |
US8321526B2 (en) | 2009-01-28 | 2012-11-27 | Headwater Partners I, Llc | Verifiable device assisted service usage billing with integrated accounting, mediation accounting, and multi-account |
US20090327634A1 (en) * | 2008-06-25 | 2009-12-31 | Microsoft Corporation | Secure configuration of transient storage devices |
US9104618B2 (en) | 2008-12-18 | 2015-08-11 | Sandisk Technologies Inc. | Managing access to an address range in a storage device |
US9955332B2 (en) | 2009-01-28 | 2018-04-24 | Headwater Research Llc | Method for child wireless device activation to subscriber account of a master wireless device |
US9253663B2 (en) | 2009-01-28 | 2016-02-02 | Headwater Partners I Llc | Controlling mobile device communications on a roaming network based on device state |
US10237757B2 (en) | 2009-01-28 | 2019-03-19 | Headwater Research Llc | System and method for wireless network offloading |
US9755842B2 (en) | 2009-01-28 | 2017-09-05 | Headwater Research Llc | Managing service user discovery and service launch object placement on a device |
US10057775B2 (en) | 2009-01-28 | 2018-08-21 | Headwater Research Llc | Virtualized policy and charging system |
US11973804B2 (en) | 2009-01-28 | 2024-04-30 | Headwater Research Llc | Network service plan design |
US10779177B2 (en) | 2009-01-28 | 2020-09-15 | Headwater Research Llc | Device group partitions and settlement platform |
US10326800B2 (en) | 2009-01-28 | 2019-06-18 | Headwater Research Llc | Wireless network service interfaces |
US11985155B2 (en) | 2009-01-28 | 2024-05-14 | Headwater Research Llc | Communications device with secure data path processing agents |
US9572019B2 (en) | 2009-01-28 | 2017-02-14 | Headwater Partners LLC | Service selection set published to device agent with on-device service selection |
US10264138B2 (en) | 2009-01-28 | 2019-04-16 | Headwater Research Llc | Mobile device and service management |
US9980146B2 (en) | 2009-01-28 | 2018-05-22 | Headwater Research Llc | Communications device with secure data path processing agents |
US8893009B2 (en) | 2009-01-28 | 2014-11-18 | Headwater Partners I Llc | End user device that secures an association of application to service policy with an application certificate check |
US9578182B2 (en) | 2009-01-28 | 2017-02-21 | Headwater Partners I Llc | Mobile device and service management |
US10248996B2 (en) | 2009-01-28 | 2019-04-02 | Headwater Research Llc | Method for operating a wireless end-user device mobile payment agent |
US9392462B2 (en) | 2009-01-28 | 2016-07-12 | Headwater Partners I Llc | Mobile end-user device with agent limiting wireless data communication for specified background applications based on a stored policy |
US20220360461A1 (en) | 2009-01-28 | 2022-11-10 | Headwater Research Llc | Device-Assisted Services for Protecting Network Capacity |
US9647918B2 (en) | 2009-01-28 | 2017-05-09 | Headwater Research Llc | Mobile device and method attributing media services network usage to requesting application |
US10715342B2 (en) | 2009-01-28 | 2020-07-14 | Headwater Research Llc | Managing service user discovery and service launch object placement on a device |
US10492102B2 (en) | 2009-01-28 | 2019-11-26 | Headwater Research Llc | Intermediate networking devices |
US10783581B2 (en) | 2009-01-28 | 2020-09-22 | Headwater Research Llc | Wireless end-user device providing ambient or sponsored services |
US9270559B2 (en) | 2009-01-28 | 2016-02-23 | Headwater Partners I Llc | Service policy implementation for an end-user device having a control application or a proxy agent for routing an application traffic flow |
US10064055B2 (en) | 2009-01-28 | 2018-08-28 | Headwater Research Llc | Security, fraud detection, and fraud mitigation in device-assisted services systems |
US10841839B2 (en) | 2009-01-28 | 2020-11-17 | Headwater Research Llc | Security, fraud detection, and fraud mitigation in device-assisted services systems |
US8745191B2 (en) | 2009-01-28 | 2014-06-03 | Headwater Partners I Llc | System and method for providing user notifications |
US8793758B2 (en) | 2009-01-28 | 2014-07-29 | Headwater Partners I Llc | Security, fraud detection, and fraud mitigation in device-assisted services systems |
US10200541B2 (en) | 2009-01-28 | 2019-02-05 | Headwater Research Llc | Wireless end-user device with divided user space/kernel space traffic policy system |
US9557889B2 (en) | 2009-01-28 | 2017-01-31 | Headwater Partners I Llc | Service plan design, user interfaces, application programming interfaces, and device management |
US9706061B2 (en) | 2009-01-28 | 2017-07-11 | Headwater Partners I Llc | Service design center for device assisted services |
US9565707B2 (en) | 2009-01-28 | 2017-02-07 | Headwater Partners I Llc | Wireless end-user device with wireless data attribution to multiple personas |
US10798252B2 (en) | 2009-01-28 | 2020-10-06 | Headwater Research Llc | System and method for providing user notifications |
US9351193B2 (en) | 2009-01-28 | 2016-05-24 | Headwater Partners I Llc | Intermediate networking devices |
US10484858B2 (en) | 2009-01-28 | 2019-11-19 | Headwater Research Llc | Enhanced roaming services and converged carrier networks with device assisted services and a proxy |
US9858559B2 (en) | 2009-01-28 | 2018-01-02 | Headwater Research Llc | Network service plan design |
US11218854B2 (en) | 2009-01-28 | 2022-01-04 | Headwater Research Llc | Service plan design, user interfaces, application programming interfaces, and device management |
US9954975B2 (en) | 2009-01-28 | 2018-04-24 | Headwater Research Llc | Enhanced curfew and protection associated with a device group |
KR101111617B1 (ko) * | 2009-08-26 | 2012-02-14 | 희성정밀 주식회사 | 공조 시스템용 서비스 밸브 및 그 연결 구조 |
JP5521479B2 (ja) * | 2009-10-14 | 2014-06-11 | 富士通株式会社 | プログラム、データ記憶装置及びデータ記憶システム |
US8776204B2 (en) * | 2010-03-12 | 2014-07-08 | Alcatel Lucent | Secure dynamic authority delegation |
US8370648B1 (en) * | 2010-03-15 | 2013-02-05 | Emc International Company | Writing and reading encrypted data using time-based encryption keys |
CN103052957A (zh) * | 2010-10-25 | 2013-04-17 | 株式会社日立制作所 | 存储装置和其管理方法 |
US8904411B2 (en) * | 2010-11-30 | 2014-12-02 | International Business Machines Corporation | Framework for system communication for handling data |
US9258312B1 (en) | 2010-12-06 | 2016-02-09 | Amazon Technologies, Inc. | Distributed policy enforcement with verification mode |
US9237155B1 (en) | 2010-12-06 | 2016-01-12 | Amazon Technologies, Inc. | Distributed policy enforcement with optimizing policy transformations |
US9154826B2 (en) | 2011-04-06 | 2015-10-06 | Headwater Partners Ii Llc | Distributing content and service launch objects to mobile devices |
US8973108B1 (en) * | 2011-05-31 | 2015-03-03 | Amazon Technologies, Inc. | Use of metadata for computing resource access |
US8769642B1 (en) | 2011-05-31 | 2014-07-01 | Amazon Technologies, Inc. | Techniques for delegation of access privileges |
US9197409B2 (en) | 2011-09-29 | 2015-11-24 | Amazon Technologies, Inc. | Key derivation techniques |
US9178701B2 (en) | 2011-09-29 | 2015-11-03 | Amazon Technologies, Inc. | Parameter based key derivation |
US9203613B2 (en) | 2011-09-29 | 2015-12-01 | Amazon Technologies, Inc. | Techniques for client constructed sessions |
US9215076B1 (en) | 2012-03-27 | 2015-12-15 | Amazon Technologies, Inc. | Key generation for hierarchical data access |
US8739308B1 (en) | 2012-03-27 | 2014-05-27 | Amazon Technologies, Inc. | Source identification for unauthorized copies of content |
US8892865B1 (en) | 2012-03-27 | 2014-11-18 | Amazon Technologies, Inc. | Multiple authority key derivation |
US8909929B2 (en) * | 2012-05-31 | 2014-12-09 | Atmel Corporation | Stored public key validity registers for cryptographic devices and systems |
US9258118B1 (en) | 2012-06-25 | 2016-02-09 | Amazon Technologies, Inc. | Decentralized verification in a distributed system |
US9660972B1 (en) | 2012-06-25 | 2017-05-23 | Amazon Technologies, Inc. | Protection from data security threats |
CN103034799B (zh) * | 2012-12-14 | 2016-03-30 | 南京中孚信息技术有限公司 | 一种内核级的桌面访问控制方法 |
US10038565B2 (en) * | 2012-12-20 | 2018-07-31 | GM Global Technology Operations LLC | Methods and systems for bypassing authenticity checks for secure control modules |
US9245249B2 (en) | 2013-03-12 | 2016-01-26 | Labtech Llc | General, flexible, resilent ticketing interface between a device management system and ticketing systems |
WO2014159862A1 (en) | 2013-03-14 | 2014-10-02 | Headwater Partners I Llc | Automated credential porting for mobile devices |
US9754133B2 (en) | 2013-03-14 | 2017-09-05 | Microchip Technology Incorporated | Programmable device personalization |
US9407440B2 (en) | 2013-06-20 | 2016-08-02 | Amazon Technologies, Inc. | Multiple authority data security and access |
US9521000B1 (en) | 2013-07-17 | 2016-12-13 | Amazon Technologies, Inc. | Complete forward access sessions |
US9311500B2 (en) | 2013-09-25 | 2016-04-12 | Amazon Technologies, Inc. | Data security using request-supplied keys |
US9237019B2 (en) | 2013-09-25 | 2016-01-12 | Amazon Technologies, Inc. | Resource locators with keys |
US10243945B1 (en) | 2013-10-28 | 2019-03-26 | Amazon Technologies, Inc. | Managed identity federation |
US9276910B2 (en) * | 2013-11-19 | 2016-03-01 | Wayne Fueling Systems Llc | Systems and methods for convenient and secure mobile transactions |
US9420007B1 (en) | 2013-12-04 | 2016-08-16 | Amazon Technologies, Inc. | Access control using impersonization |
US9369461B1 (en) | 2014-01-07 | 2016-06-14 | Amazon Technologies, Inc. | Passcode verification using hardware secrets |
US9374368B1 (en) | 2014-01-07 | 2016-06-21 | Amazon Technologies, Inc. | Distributed passcode verification system |
US9292711B1 (en) | 2014-01-07 | 2016-03-22 | Amazon Technologies, Inc. | Hardware secret usage limits |
US9270662B1 (en) | 2014-01-13 | 2016-02-23 | Amazon Technologies, Inc. | Adaptive client-aware session security |
US10140194B2 (en) * | 2014-03-20 | 2018-11-27 | Hewlett Packard Enterprise Development Lp | Storage system transactions |
US10771255B1 (en) | 2014-03-25 | 2020-09-08 | Amazon Technologies, Inc. | Authenticated storage operations |
US9258117B1 (en) | 2014-06-26 | 2016-02-09 | Amazon Technologies, Inc. | Mutual authentication with symmetric secrets and signatures |
US10326597B1 (en) | 2014-06-27 | 2019-06-18 | Amazon Technologies, Inc. | Dynamic response signing capability in a distributed system |
CN105787721A (zh) * | 2014-12-26 | 2016-07-20 | 中兴通讯股份有限公司 | 充值实现方法及系统 |
CN104765991A (zh) * | 2015-03-17 | 2015-07-08 | 成都智慧之芯科技有限公司 | 集中控制系统中设备授权管理方法 |
US10122689B2 (en) | 2015-06-16 | 2018-11-06 | Amazon Technologies, Inc. | Load balancing with handshake offload |
US10122692B2 (en) | 2015-06-16 | 2018-11-06 | Amazon Technologies, Inc. | Handshake offload |
US10044752B1 (en) * | 2015-09-30 | 2018-08-07 | EMC IP Holding Company LLC | Null-byte injection detection |
JP6719079B2 (ja) | 2016-05-31 | 2020-07-08 | パナソニックIpマネジメント株式会社 | 情報機器、データ処理システム、データ処理方法およびコンピュータプログラム |
US10116440B1 (en) | 2016-08-09 | 2018-10-30 | Amazon Technologies, Inc. | Cryptographic key management for imported cryptographic keys |
JP2018113493A (ja) * | 2017-01-06 | 2018-07-19 | キヤノン株式会社 | クライアント装置、システム、情報処理方法及びプログラム |
WO2018209217A1 (en) * | 2017-05-11 | 2018-11-15 | Antique Books, Inc. | Attached storage device for enhanced data and program protection |
CN108418692B (zh) * | 2018-03-28 | 2021-05-25 | 湖南东方华龙信息科技有限公司 | 认证证书的在线写入方法 |
US11070539B2 (en) | 2018-04-10 | 2021-07-20 | ArecaBay, Inc. | Network security dynamic access control and policy enforcement |
JP7040467B2 (ja) * | 2019-01-11 | 2022-03-23 | 日本電信電話株式会社 | 更新装置および更新方法 |
JP7253809B2 (ja) * | 2020-05-28 | 2023-04-07 | 株式会社ユビキタスAi | 情報処理システム、情報処理方法、IoTデバイス、情報処理装置およびその制御プログラム |
US11868503B2 (en) | 2020-11-24 | 2024-01-09 | International Business Machines Corporation | Recommending post modifications to reduce sensitive data exposure |
Citations (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JPH04232586A (ja) * | 1990-12-27 | 1992-08-20 | Pentel Kk | ハンディタ−ミナル |
JPH06222980A (ja) * | 1993-01-27 | 1994-08-12 | Dainippon Printing Co Ltd | メモリ領域の管理方法 |
JPH06289782A (ja) * | 1993-04-07 | 1994-10-18 | Matsushita Electric Ind Co Ltd | 相互認証方法 |
JPH0784959A (ja) * | 1993-09-14 | 1995-03-31 | Toshiba Corp | ユーザ認証システム |
JPH103257A (ja) * | 1996-06-18 | 1998-01-06 | Toshiba Corp | 電子署名付加方法及び電子署名装置並びに電子署名検証方法 |
JPH1166259A (ja) * | 1997-08-12 | 1999-03-09 | Kokusai Electric Co Ltd | 多機能型メモリカード |
JPH11285582A (ja) * | 1998-04-03 | 1999-10-19 | Pa Net Gijutsu Kenkyusho:Kk | 遊技機監視システム |
JP2000020631A (ja) * | 1998-06-30 | 2000-01-21 | Hitachi Maxell Ltd | 電子マネー保守管理システムおよびこれに使用するicカード |
JP2000151583A (ja) * | 1996-02-23 | 2000-05-30 | Fuji Xerox Co Ltd | アクセス資格認証方法および装置ならびに証明用補助情報作成方法および装置 |
JP2000148567A (ja) * | 1998-09-02 | 2000-05-30 | Internatl Business Mach Corp <Ibm> | スマ―ト・カ―ドのメモリにデ―タ・オブジェクトを記憶する方法 |
JP2000215165A (ja) * | 1999-01-26 | 2000-08-04 | Nippon Telegr & Teleph Corp <Ntt> | 情報アクセス制御方法および装置と情報アクセス制御プログラムを記録した記録媒体 |
Family Cites Families (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
GB8613069D0 (en) * | 1986-05-29 | 1986-07-02 | Univ Manchester | Parallel storage allocation |
US5628023A (en) * | 1993-04-19 | 1997-05-06 | International Business Machines Corporation | Virtual storage computer system having methods and apparatus for providing token-controlled access to protected pages of memory via a token-accessible view |
JPH08263438A (ja) * | 1994-11-23 | 1996-10-11 | Xerox Corp | ディジタルワークの配給及び使用制御システム並びにディジタルワークへのアクセス制御方法 |
CA2138302C (en) * | 1994-12-15 | 1999-05-25 | Michael S. Fortinsky | Provision of secure access to external resources from a distributed computing environment |
US5987134A (en) * | 1996-02-23 | 1999-11-16 | Fuji Xerox Co., Ltd. | Device and method for authenticating user's access rights to resources |
GB2319862A (en) * | 1996-11-28 | 1998-06-03 | Ibm | Performing computer-based on-line commerce using an intelligent agent |
US6233683B1 (en) * | 1997-03-24 | 2001-05-15 | Visa International Service Association | System and method for a multi-application smart card which can facilitate a post-issuance download of an application onto the smart card |
JP3613929B2 (ja) * | 1997-05-07 | 2005-01-26 | 富士ゼロックス株式会社 | アクセス資格認証装置および方法 |
US6065120A (en) * | 1997-12-09 | 2000-05-16 | Phone.Com, Inc. | Method and system for self-provisioning a rendezvous to ensure secure access to information in a database from multiple devices |
IL126552A (en) * | 1998-10-13 | 2007-06-03 | Nds Ltd | Remote administration of smart cards for secure access systems |
US6324087B1 (en) * | 2000-06-08 | 2001-11-27 | Netlogic Microsystems, Inc. | Method and apparatus for partitioning a content addressable memory device |
US6446045B1 (en) * | 2000-01-10 | 2002-09-03 | Lucinda Stone | Method for using computers to facilitate and control the creating of a plurality of functions |
SG96597A1 (en) * | 2000-02-17 | 2003-06-16 | Ibm | Archiving and retrieval method and apparatus |
US7134138B2 (en) * | 2001-02-15 | 2006-11-07 | Emc Corporation | Methods and apparatus for providing security for a data storage system |
-
2001
- 2001-03-15 JP JP2001073353A patent/JP2002278839A/ja not_active Abandoned
-
2002
- 2002-03-07 US US10/275,499 patent/US20030188117A1/en not_active Abandoned
- 2002-03-07 KR KR1020027015410A patent/KR100860162B1/ko not_active IP Right Cessation
- 2002-03-07 EP EP02702791A patent/EP1303075A4/en not_active Withdrawn
- 2002-03-07 WO PCT/JP2002/002113 patent/WO2002076013A1/ja active Application Filing
- 2002-03-07 CN CNB028016823A patent/CN100483991C/zh not_active Expired - Fee Related
-
2004
- 2004-06-28 HK HK04104631.3A patent/HK1062971A1/xx not_active IP Right Cessation
Patent Citations (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JPH04232586A (ja) * | 1990-12-27 | 1992-08-20 | Pentel Kk | ハンディタ−ミナル |
JPH06222980A (ja) * | 1993-01-27 | 1994-08-12 | Dainippon Printing Co Ltd | メモリ領域の管理方法 |
JPH06289782A (ja) * | 1993-04-07 | 1994-10-18 | Matsushita Electric Ind Co Ltd | 相互認証方法 |
JPH0784959A (ja) * | 1993-09-14 | 1995-03-31 | Toshiba Corp | ユーザ認証システム |
JP2000151583A (ja) * | 1996-02-23 | 2000-05-30 | Fuji Xerox Co Ltd | アクセス資格認証方法および装置ならびに証明用補助情報作成方法および装置 |
JPH103257A (ja) * | 1996-06-18 | 1998-01-06 | Toshiba Corp | 電子署名付加方法及び電子署名装置並びに電子署名検証方法 |
JPH1166259A (ja) * | 1997-08-12 | 1999-03-09 | Kokusai Electric Co Ltd | 多機能型メモリカード |
JPH11285582A (ja) * | 1998-04-03 | 1999-10-19 | Pa Net Gijutsu Kenkyusho:Kk | 遊技機監視システム |
JP2000020631A (ja) * | 1998-06-30 | 2000-01-21 | Hitachi Maxell Ltd | 電子マネー保守管理システムおよびこれに使用するicカード |
JP2000148567A (ja) * | 1998-09-02 | 2000-05-30 | Internatl Business Mach Corp <Ibm> | スマ―ト・カ―ドのメモリにデ―タ・オブジェクトを記憶する方法 |
JP2000215165A (ja) * | 1999-01-26 | 2000-08-04 | Nippon Telegr & Teleph Corp <Ntt> | 情報アクセス制御方法および装置と情報アクセス制御プログラムを記録した記録媒体 |
Non-Patent Citations (3)
Title |
---|
D. HAGIMONT, J.-J. VANDEWALLE: "JCCap: capability-based access control for Java card", 4TH SMART CARD RESEARCH AND ADVANCED APPLICATION CONFERENCE, September 2000 (2000-09-01), pages 1 - 40, XP002952764, Retrieved from the Internet <URL:http://sirac.inrialpes.fr/~hagimont/publications/cardis-jccap-2000-pdf> [retrieved on 20000404] * |
MASAKI KYOJIMA, KIL-HO SHIN: "Ticket authentication protocols version 1.0", FUJI XEROX CO., LTD., 15 January 2000 (2000-01-15), pages 1 - 38, XP002952765, Retrieved from the Internet <URL:http://www.accessticket.com/990618TAP.pdf> [retrieved on 20020404] * |
See also references of EP1303075A4 * |
Also Published As
Publication number | Publication date |
---|---|
US20030188117A1 (en) | 2003-10-02 |
KR20030005354A (ko) | 2003-01-17 |
EP1303075A4 (en) | 2008-08-06 |
JP2002278839A (ja) | 2002-09-27 |
KR100860162B1 (ko) | 2008-09-24 |
HK1062971A1 (en) | 2004-12-03 |
CN1465160A (zh) | 2003-12-31 |
CN100483991C (zh) | 2009-04-29 |
EP1303075A1 (en) | 2003-04-16 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
KR100860162B1 (ko) | 액세스 제어 티켓을 이용한 데이터 액세스 관리 시스템 및관리 방법 | |
KR100874061B1 (ko) | 액세스 제어 티켓을 이용한 메모리 액세스 제어 시스템 및관리 방법 | |
CN100423041C (zh) | 数据处理设备和数据处理方法 | |
TW514844B (en) | Data processing system, storage device, data processing method and program providing media | |
JP4660900B2 (ja) | 個人認証適用データ処理システム、個人認証適用データ処理方法、および情報処理装置、並びにプログラム提供媒体 | |
US20080089517A1 (en) | Method and System for Access Control and Data Protection in Digital Memories, Related Digital Memory and Computer Program Product Therefor | |
CN102214280A (zh) | 存储器装置、主机装置以及存储器系统 | |
CN112433817B (zh) | 信息配置方法、直接存储访问方法及相关装置 | |
KR20060107826A (ko) | 데이터 처리장치 | |
WO2002089048A1 (fr) | Systeme de traitement de donnees, dispositif memoire, processeur de donnees, procede de traitement de donnees et programme associe | |
KR20040030454A (ko) | 콘텐츠 이용권한 관리시스템, 콘텐츠 이용권한 관리방법및 정보처리장치와 컴퓨터 프로그램 | |
KR20200133881A (ko) | 분산 환경에서의 신원 인증 방법 | |
US11405198B2 (en) | System and method for storing and managing keys for signing transactions using key of cluster managed in trusted execution environment | |
KR20030019316A (ko) | 정보 처리 시스템 및 방법 | |
US9400876B2 (en) | Content data management system and method | |
CN100547598C (zh) | 基于对称密钥加密保存和检索数据 | |
WO2019082442A1 (ja) | データ登録方法、データ復号方法、データ構造、コンピュータ、及びプログラム | |
CN102081575A (zh) | 虚拟磁盘存储空间的动态分配方法和装置 | |
TW201902179A (zh) | 具隱密性的kyc資料共享系統及其方法 | |
JP2002279390A (ja) | データアクセス制御システム、メモリ搭載デバイス、およびデータアクセス制御方法、並びにプログラム記憶媒体 | |
JP2002281009A (ja) | 相互認証システム、相互認証方法、およびメモリ搭載デバイス、メモリアクセス機器、並びにプログラム記憶媒体 | |
JP2002281023A (ja) | データ処理システム、メモリ搭載デバイス、およびデータ処理方法、並びにプログラム記憶媒体 | |
JP2006262393A (ja) | 耐タンパ装置およびファイル生成方法 | |
CN113836516B (zh) | 一种打印机硒鼓防伪与打印次数保护系统、方法 | |
JP2002278842A (ja) | メモリアクセス制御システム、メモリ搭載デバイス、およびメモリアクセス制御方法、並びにプログラム記憶媒体 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AK | Designated states |
Kind code of ref document: A1 Designated state(s): CN KR SG US |
|
AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE TR |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2002702791 Country of ref document: EP |
|
WWE | Wipo information: entry into national phase |
Ref document number: 1020027015410 Country of ref document: KR |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
WWE | Wipo information: entry into national phase |
Ref document number: 028016823 Country of ref document: CN |
|
WWP | Wipo information: published in national office |
Ref document number: 1020027015410 Country of ref document: KR |
|
WWP | Wipo information: published in national office |
Ref document number: 2002702791 Country of ref document: EP |
|
WWE | Wipo information: entry into national phase |
Ref document number: 10275499 Country of ref document: US |