WO2017208445A1 - 自動取引システム及びその制御方法並びにカードリーダ - Google Patents
自動取引システム及びその制御方法並びにカードリーダ Download PDFInfo
- Publication number
- WO2017208445A1 WO2017208445A1 PCT/JP2016/066630 JP2016066630W WO2017208445A1 WO 2017208445 A1 WO2017208445 A1 WO 2017208445A1 JP 2016066630 W JP2016066630 W JP 2016066630W WO 2017208445 A1 WO2017208445 A1 WO 2017208445A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- card
- information
- card reader
- control unit
- key
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/10—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
- G06Q20/108—Remote banking, e.g. home banking
- G06Q20/1085—Remote banking, e.g. home banking involving automatic teller machines [ATMs]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/18—Payment architectures involving self-service terminals [SST], vending machines, kiosks or multimedia terminals
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/20—Point-of-sale [POS] network systems
- G06Q20/202—Interconnection or interaction of plural electronic cash registers [ECR] or to host computer, e.g. network details, transfer of information from host to ECR or from ECR to ECR
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3821—Electronic credentials
- G06Q20/38215—Use of certificates or encrypted proofs of transaction rights
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/409—Device specific authentication in transaction processing
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q40/00—Finance; Insurance; Tax strategies; Processing of corporate or income taxes
- G06Q40/02—Banking, e.g. interest calculation or account maintenance
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F19/00—Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
- G07F19/20—Automatic teller machines [ATMs]
- G07F19/211—Software architecture within ATMs or in relation to the ATM network
Definitions
- the present invention relates to an automatic transaction system, a control method therefor, and a card reader.
- an ATM Automated Teller Machine
- an automatic transaction system having an accounting host computer that approves the deposit / withdrawal transaction.
- Confidential information handled by ATM includes magnetic information recorded on a magnetic tape attached to the back of the card, card information such as a card number and a financial institution code (Patent Document 1).
- card information such as a card number and a financial institution code (Patent Document 1).
- Patent Document 1 When magnetic information is leaked, a counterfeit card may be created based on the magnetic information and used illegally. If the card number is leaked together with the expiration date, etc., there is a possibility that it is illegally used for online shopping using the information.
- the account host computer that approves the transaction after the card information read from the card loaded in the ATM by the user is encrypted in the control unit of the ATM.
- the method of transmitting to can be considered.
- the ATM control unit encrypts and transmits the card information to the accounting host computer as described above, it controls the operation of the ATM internal devices, particularly the entire ATM, and When the ATM control unit that performs communication between them is infected with malware, the card information may flow out to the outside through the ATM control unit.
- the present invention has been made in consideration of the above points, and intends to propose a highly reliable automatic transaction system capable of practically preventing leakage of card information, a control method therefor, and a card reader.
- the present invention has an automatic transaction apparatus and a host apparatus, and transmits a request message of transaction according to a user operation on the automatic transaction apparatus from the automatic transaction apparatus to the host apparatus.
- the automatic transaction system in which the automatic transaction apparatus performs the transaction based on a response message from the host device to the request message, the first recorded in the automatic transaction apparatus on the card medium loaded by the user.
- a card reader that reads the card information of the device, and a device control unit that generates the request message, transmits the request message to the host device, and executes a control process for performing the transaction based on the response message from the host device.
- the card reader stores a first card in which information relating to the format of the first card information unique to each financial institution is registered.
- the predetermined confidential information including the card number is acquired from the first card information read from the card medium by referring to the first card format information, and the acquired confidential information is stored. Is transmitted to the device control unit, and the device control unit generates the request message including the encrypted confidential information transmitted from the card reader and transmits the request message to the host device. did.
- the automatic transaction apparatus includes a first card recorded on the card medium loaded by the user.
- a card reader that reads information; and a device control unit that generates the request message, transmits the request message to the host device, and executes a control process for performing the transaction based on the response message from the host device.
- the card reader has a first card format in which information relating to the format of the first card information unique to each financial institution is registered.
- the card reader obtains predetermined confidential information including the card number from the first card information read from the card medium with reference to the first card format information.
- 1 step a second step in which the card reader encrypts the acquired confidential information and transmits it to the device control unit, and the device control unit receives the encrypted data transmitted from the card reader.
- a request message of a transaction according to a user operation is transmitted to the host device, and provided in an automatic transaction device that performs the transaction based on a response message from the host device to the request message,
- the card medium loaded on the automatic transaction apparatus is transported, and the card medium A card conveying / reading unit that reads card information; and a card reader encryption processing unit that encrypts the card information read from the card medium by the card conveying / reading unit, and the automatic transaction apparatus includes the request message Is generated and transmitted to the host device, and the transaction is performed based on the response message from the host device.
- An apparatus control unit that executes control processing, and the card reader encryption processing unit holds first card format information in which information related to the format of the first card information is registered, which is unique to each financial institution. , Referring to the first card format information, acquiring predetermined confidential information including the card number from the first card information read from the card medium, and encrypting the acquired confidential information It was made to transmit to a control part.
- FIG. 1 denotes an automatic transaction system according to the present embodiment as a whole.
- this automatic transaction system 1 one or a plurality of ATMs 2 and a billing host computer 3 are connected via a wide area network 4 such as a LAN (Local Area Network) or a WAN (Wide Area Network).
- the certificate authority 5 is provided separately from the host computer 3.
- ATM2 is an automatic transaction device that performs transactions such as cash deposits and withdrawals in response to user operations.
- the ATM 2 is provided on the front surface of the ATM 2, an ATM control unit 10 for controlling the operation of the entire ATM 2, an I / O control unit 11 for controlling various display lamps of the ATM 2, detection of door opening / closing, and the like.
- the banknote processing unit 12 that counts the banknotes inserted into the deposit / withdrawal port and transports it to the storage, stores it, or takes out the banknotes to be withdrawn from the storage and transports it into the deposit / withdrawal port, and for transactions at ATM2 It has a card reader 13 that reads information recorded on the card medium from a necessary card medium such as a cash card, and a numeric keypad for entering the transaction amount, password, etc.
- An encryption keypad 14 having an encryption function, a receipt printer 15 that is a transaction statement printer, a passbook printer 16 that is a passbook printer, and an ATM transaction log A journal printer 17 for recording the image, a security monitoring camera 18 for taking a picture of the face of the ATM user, a display unit 19 for displaying information related to transactions such as deposit transactions and withdrawal transactions, and an accounting host computer 3 And a communication processing unit 20 that performs communication.
- the display unit 19 may be a display operation unit that receives an operation from the user.
- ATM2 may be provided with a coin processing unit (not shown) that handles deposited coins and dispensed coins.
- a coin processing unit not shown
- IC Integrated Circuit Card
- FIG. 2 shows a schematic configuration of the ATM control unit 10.
- the ATM control unit 10 has a microcomputer configuration including information processing resources such as a CPU (Central Processing Unit) 30 and a memory 31.
- the CPU 30 is a processor that controls operation of the entire ATM control unit 10.
- the memory 31 is composed of a semiconductor memory, for example, and stores programs and data.
- the storage area of the memory 31 of the ATM control unit 10 is managed by being divided into a program area 31A and a data area 31B.
- an ATM application 40 for controlling the entire transaction of ATM2 an I / O (Input / Output) control unit 11, a banknote processing unit 12, a card reader 13, an encryption keypad 14, a receipt printer 15, Software for controlling the passbook printer 16, journal printer 17, monitoring camera 18, display unit 19 and communication processing unit 20 (I / O control unit control software 41, banknote processing unit control software 42, card reader control software 43, Encryption keypad control software 44, receipt printer control software 45, passbook printer control software 46, journal printer control software 47, surveillance camera control software 48 and communication processing software 49), and a configuration file such as software environment And software configuration file 50 is is stored.
- data necessary for deposit / withdrawal transactions at ATM2 is stored.
- a transaction that is transaction message data including a card number 60, an ATC (ATm Controler) random number 61 generated for each transaction to increase the security of transaction messages with the account host computer 3 (FIG. 1), magnetic information, etc.
- the total deposit amount 69 is stored in the data area 31B.
- FIG. 3A shows a schematic configuration of the card reader 13 (FIG. 1).
- the card reader 13 includes a card reader control unit 70, a card transport / read unit 71, and a card reader encryption processing unit 72.
- the card reader control unit 70 controls the card transport / read unit 71 and the card reader encryption processing unit 72 and has a function of exchanging data between the card transport / read unit 71 and the card reader encryption processing unit 72.
- the card transport / reading unit 71 transports the IC card 21 between the card insertion slot (not shown) of the ATM 2 and the reading unit of the card reader 13 inside the ATM 2 and through the contact of the IC card 21.
- the card reader encryption processing unit 72 is a hardware unit having a function of performing encryption processing such as encryption of card information in the card reader 13.
- a removable encryption processing device such as SAM (Secure Access Module) can be used.
- the card reader control unit 70 includes a CPU 80 that controls the operation of the entire card reader control unit 70 and information processing resources such as a memory 81 including, for example, a semiconductor memory.
- the storage area of the memory 81 of the card reader controller 70 is managed by being divided into a program area 81A and a data area 81B, and the entire control firmware 82, the IC card communication control firmware 83, and the CSE (Card reader) are stored in the program area 81A.
- Secure Element) control firmware 84 is stored, and an overall control buffer 85, an IC card communication buffer 86, and a CSE communication buffer 87 are provided in the data area 81B.
- the overall control firmware 82 is software having a function of controlling communication with the ATM control unit 10 and carrying control of the card transfer / reading unit 71 (FIG. 3A).
- the IC card communication control firmware 83 is , Software having a function of performing data input / output control with the IC card 21.
- the CSE control firmware 84 is software that controls the card reader encryption processing unit 72 (FIG. 3A) and performs communication control with the card reader encryption processing unit 72.
- the overall control buffer 85 is a data area used for overall control including a buffer for communication with the ATM control unit 10, and the IC card communication buffer 86 and the CSE communication buffer 87 are the IC card 21 and the card reader, respectively. This is a buffer for controlling communication with the encryption processing unit 72.
- the card reader encryption processing unit 72 performs information processing such as a CPU 90 that is a processor that controls the operation of the entire card reader encryption processing unit 72, and a memory 91 including a semiconductor memory, for example. Constructed with resources.
- the storage area of the memory 91 of the card reader encryption processing unit 72 is divided into a program area 91A and a data area 91B and managed in the same manner as the card reader control unit 70 (FIG. 3B).
- an application 92 is software having a function of controlling the entire card reader encryption processing unit 72
- the communication control firmware 93 is software having a function of performing communication control with the card reader control unit 70.
- the cryptographic processing firmware 94 is software having functions for performing electronic signature processing, encryption, and the like.
- the data area 91B includes a root verification key 95, a CR signature key 96, a CR verification key 97, a CR verification key signature 98, an EPP public key 99, a host public key 100, a CR-EPP master key 101, and a CR-EPP session key.
- 102, the CR-host master key 103, the CR-host session key 104, and the like are appropriately stored in the course of various processes to be described later.
- the encryption keypad (EPP) 14 includes an encryption keypad controller 110, a keypad 111, and the like.
- the encryption keypad control unit 110 is a hardware unit that has a function of controlling the keypad 111 and exchanging data between the encryption keypad control unit 110 and the keypad 111. It is a hardware unit that is installed so as to accept operations by customers on the ATM2 housing, and accepts input of personal identification numbers and amounts by customers.
- the encryption keypad control unit 110 includes a CPU 120 that controls the operation of the entire encryption keypad control unit 110, and information processing resources such as a memory 121 including, for example, a semiconductor memory. Composed.
- the storage area of the memory 121 of the encryption keypad control unit 110 is managed by being divided into a program area 121A and a data area 121B.
- an application 122 is software having a function of controlling the entire encryption keypad control unit 110
- the communication control firmware 123 is software having a function of performing communication control with the ATM control unit 10 and the card reader 13. is there.
- the cryptographic processing firmware 124 is software having functions for performing electronic signature processing, encryption, and the like.
- the data area 121B is provided with an overall control buffer 125 and a communication buffer 126, as well as a route verification key 95, an EPP private key 105, an EPP public key 99, an EPP public key signature 106, a CR verification key 97, and a CR-
- the EPP master key 101, the CR-EPP session key 102, and the like are appropriately stored during various processes described later.
- FIG. 5 shows a schematic configuration of the IC card 21.
- the IC card 21 includes an IC area 130 constituted by an IC chip mounted on the IC card 21 and a magnetic area 140 constituted by a magnetic tape attached to the back surface of the IC card 21.
- the IC area 130 includes information processing resources such as a CPU 131 and a memory 132.
- the CPU 131 is a processor that controls the operation of the IC area 130 of the IC card 21.
- the memory 132 is composed of, for example, a semiconductor memory.
- the storage area of the memory 132 in the IC area 130 is managed by being divided into a program area 132A and a data area 132B.
- the program area 132A stores an IC application 133 that controls processing in the IC area 130, a communication control firmware 134, a cryptographic processing firmware 135, and the like.
- the IC application 133 is software for controlling the entire IC card 21, and the communication control firmware 134 is software having a function of controlling data communication with the card reader 13 (FIG. 1).
- the cryptographic processing firmware 135 is software having a cryptographic processing function for generating a message authentication code and verifying the message authentication code transmitted from the accounting host computer 3.
- data necessary for processing in the IC area 130 is stored in the data area 132B.
- a processing buffer 136 and a communication buffer 137 necessary for controlling the IC area 130 are provided, and transaction data 138 necessary for a transaction using the IC card 21 is stored.
- the transaction data 138 includes a card number (hereinafter referred to as PAN (Primary Account Number)), information having substantially the same content as magnetic information described later stored in the magnetic area 140, and the IC card.
- PAN Primary Account Number
- Discretionary information that is information that can be freely stored by the financial institution that issued 21 is included.
- This magnetic information includes an identifier (financial institution ID) unique to the financial institution assigned to the financial institution that issued the IC card 21 and a personal identification number (hereinafter referred to as PIN (Personal Identification) specified by the financial institution). Number) (maximum PIN length), the number of PAN digits (PAN length) in the financial institution, a code (language code) indicating a language associated with the IC card 21, and the like.
- FIG. 6 shows a schematic configuration of the accounting host computer 3.
- the account host computer 3 is a computer device that stores and manages information relating to the account and balance of the ATM2 user, and is configured to include information processing resources such as a CPU 150 and a memory 151 as shown in FIG. .
- the CPU 150 is a processor that controls the operation of the entire accounting host computer 3.
- the memory 151 is composed of, for example, a semiconductor memory.
- the storage area of the memory 151 of the accounting host computer 3 is managed by being divided into a program area 151A and a data area 151B.
- the program area 151A stores a host application 152 that controls the entire processing of the accounting host computer 3, communication control software 153, encryption processing software 154, and the like.
- the host application 152 is software that controls the entire accounting host computer 3.
- the communication control software 153 is software having a function of controlling data communication between the accounting host computer 3 and each ATM 2.
- the cryptographic processing software 154 is software having a cryptographic processing function for verifying a message authentication code transmitted from the ATM 2 and generating a new message authentication code.
- the data area 151B data necessary for processing in the account host computer 3 is stored.
- the data area 151B is provided with an overall control buffer 155 and a communication buffer 156 necessary for the overall control of the accounting host computer 3, as well as a route verification key 95, a host secret key 107, and a host disclosure.
- the key 100, the host public key signature 108, the CR verification key 97, the CR-host master key 103, the CR-host session key 104, and the like are appropriately stored in the course of various processes to be described later.
- an FIT (Financial Institution Table) 157 necessary for transactions using the IC card 21 is also stored.
- the FIT 157 is a table storing various types of information unique to each financial institution. As shown in FIG. 7A, the financial institution ID offset, the financial institution ID, the maximum PIN length, the PAN offset, the PAN length, Information 161 to 167 such as language code offset and PIN block format is stored as information of a record 160 (hereinafter referred to as record information) collected for each financial institution.
- record information information of a record 160 collected for each financial institution.
- the financial institution ID is an identifier unique to the financial institution assigned to the corresponding financial institution as described above.
- the financial institution ID offset represents an offset amount from the head in which the financial institution ID of the financial institution is stored in the storage area of the magnetic tape attached to the back surface of the IC card 21 issued by the financial institution.
- the maximum PIN length represents the maximum length of a PIN (personal identification number) determined by the financial institution as described above.
- the PAN offset represents the amount of offset from the head where the PAN (card number) is stored in the storage area of the magnetic tape of the IC card 21 issued by the financial institution, and the PAN length is the card number in the financial institution. Represents the length of.
- the language code offset represents an offset amount from the head where the language code is stored in the storage area of the magnetic tape of the IC card 21 issued by the financial institution.
- the PIN block format represents a format (encrypted format) when the PIN input by the user is encrypted with the encryption keypad 14.
- FIG. 8 shows a schematic configuration of the certificate authority 5.
- the certificate authority 5 is a computer device that gives a signature to a necessary public key, and includes information processing resources such as a CPU 170 and a memory 171.
- the CPU 170 is a processor that controls operation of the entire certificate authority 5.
- the memory 171 is composed of a semiconductor memory, for example.
- the storage area of the memory 171 of the certificate authority 5 is managed by being divided into a program area 171A and a data area 171B.
- the program area 171A there are an application 172 that controls the entire processing of the certificate authority 5, communication control software 173 for outputting a verification key, and cryptographic processing software 174 that has various functions related to encryption. Stored.
- the data area 171B data necessary for processing in the certificate authority 5 is stored. Specifically, the data area 171B is provided with a processing buffer 175 necessary for controlling the entire certificate authority 5, a communication control buffer 176 used for communication control, and a route signature key 109 and a route verification key 95. It is stored as appropriate in the course of various processes to be described later.
- FIG. 9 is executed for the ATM 2 card reader 13 (FIG. 3A) and the certificate authority 5 (FIG. 8). The flow of setting the initial key (root key pair and card reader key pair) is shown.
- card reader is also referred to as “CR” as appropriate.
- a root key that is an asymmetric encryption key is used in the certificate authority 5 in a secure environment where the responsible party of secure transactions (mainly assuming an ATM vendor) in the automatic transaction system 1 is secure.
- a pair (root signature key 109 and root verification key 95) is generated (S1).
- the certificate authority 5 stores the root signature key 109 and the route verification key 95 generated at this time in the data area 171B of the memory 171 (FIG. 8) of the certificate authority 5 (S2).
- the card reader encryption processing unit 72 of the card reader 13 (FIG. 3A) generates a CR key pair (CR signature key 96 and CR verification key 97) that is an asymmetric encryption key (S3).
- the card reader encryption processing unit 72 stores the generated CR signature key 96 and CR verification key 97 in the data area 91B (FIG. 3C) of the memory 91 (FIG. 3C) (S4). Thereafter, the card reader encryption processing unit 72 transmits the CR verification key 97 to the certificate authority 5 in order to give an electronic signature to the CR verification key 97 using the root signature key 109 (S5).
- the certificate authority 5 Upon receiving the CR verification key 97 (S6), the certificate authority 5 gives an electronic signature (CR verification key signature 98) to the CR verification key 97 using the root signature key 109 generated in step S1 (S7). Further, the certificate authority 5 transmits the assigned CR verification key signature 98 and the route verification key 95 generated in step S1 to the card reader encryption processing unit 72 (S8).
- the card reader encryption processing unit 72 Upon receiving the CR verification key signature 98 and the route verification key 95 (S9), the card reader encryption processing unit 72 stores them in the data area 91B (FIG. 3C) of the memory 91 (FIG. 3C) (S10).
- FIG. 10 shows the encryption keypad key pair executed between the encryption keypad 14 and the certificate authority 5. The flow of setting is shown.
- the “encryption keypad” is also referred to as “EPP” as appropriate.
- the encryption keypad 14 After the certificate authority 5 generates the root signature key 109 and the root verification key 95 described above in FIG. 9, the encryption keypad 14 generates an EPP key pair (EPP private key 105 and EPP public key 99) that is an asymmetric encryption key. (S20).
- the encryption keypad 14 (specifically, the encryption keypad control unit 110, the same applies hereinafter) stores the generated EPP private key 105 and EPP public key 99 in the memory 121 of the encryption keypad control unit 110 (FIG. 4B) is stored in the data area 121B (FIG. 4B) (S21). Further, the encryption keypad 14 transmits the generated EPP public key 99 to the certificate authority 5 in order to give an electronic signature using the root signature key 109 (S22).
- the certificate authority 5 when the certificate authority 5 receives the EPP public key 99 (S23), it gives an electronic signature to the EPP public key 99 using the root signature key 109 (S24). Further, the certificate authority 5 sends the EPP public key signature 106 and the route verification key 95, which are the attached electronic signature, together to the encryption keypad 14 (S25).
- the encryption keypad 14 When the encryption keypad 14 receives the EPP public key signature 106 and the route verification key 95 (S26), the encryption keypad 14 stores the EPP public key signature 106 and the route verification key 95 in the memory 121 of the encryption keypad control unit 110 (FIG. 4B) is stored in the data area 121B (FIG. 4B) (S27).
- FIG. 11 shows a flow of host key setting for setting a host key for the accounting host computer 3.
- the accounting host computer 3 After the certificate authority 5 generates the root signature key 109 and the root verification key 95 described above with reference to FIG. 9, first, the accounting host computer 3 generates a host key pair (host secret key 107 and host public key 100) that is an asymmetric encryption key. Generate (S30). Then, the accounting host computer 3 stores the generated host private key 107 and host public key 100 in the data area 151B (FIG. 6) of the memory 151 (FIG. 6) (S31).
- a host key pair host secret key 107 and host public key 100
- S30 the accounting host computer 3 stores the generated host private key 107 and host public key 100 in the data area 151B (FIG. 6) of the memory 151 (FIG. 6) (S31).
- the accounting host computer 3 transmits the host public key 100 to the certificate authority 5 in order to give an electronic signature using the root signature key 109 (S32).
- the certificate authority 5 Upon receiving the host public key 100 (S33), the certificate authority 5 gives an electronic signature to the host public key 100 using the root signature key 109 (S34). In addition, the certificate authority 5 transmits the host public key signature 108 and the route verification key 95, which are electronic signatures assigned to the host public key 100 at this time, to the accounting host computer 3 (S35).
- the accounting host computer 3 When receiving the host public key signature 108 and the route verification key 95 (S36), the accounting host computer 3 stores them in the data area 151B (FIG. 5) of the memory 151 (FIG. 6) (S37).
- the card reader encryption processing unit 72 (FIG. 3C) of the card reader 13 transmits the CR verification key 97 and the CR verification key signature 98 to the encryption keypad 14 (S40).
- the encryption keypad 14 When receiving the CR verification key 97 and the CR verification key signature 98 (S41), the encryption keypad 14 verifies the validity of the signature of the CR verification key signature 98 using the root verification key 95 (S42). If the verification is verified, the CR verification key 97 is stored in the data area 121B (FIG. 4B) of the memory 121 (FIG. 4B) (S43). Then, the encryption keypad 14 transmits the EPP public key 99 and the EPP public key signature 106 to the card reader encryption processing unit 72 of the card reader 13 (S44).
- the card reader encryption processing unit 72 Upon receiving the EPP public key 99 and the EPP public key signature 106 (S45), the card reader encryption processing unit 72 verifies the validity of the signature of the EPP public key signature 106 using the route verification key 95 (S46). If the validity is verified, the EPP public key 99 is stored in the data area 91B (FIG. 3C) of the memory 91 (FIG. 3C) (S47).
- the card reader encryption processing unit 72 generates a CR-EPP master key 101 using random numbers (S50), and uses the generated CR-EPP master key 101 as data in the memory 91 (FIG. 3C). Store in the area 91B (FIG. 3C) (S51).
- the card reader encryption processing unit 72 encrypts the CR-EPP master key 101 using the EPP public key 99 and further encrypts the CR-EPP master key 101 (hereinafter referred to as an encrypted CR-EPP master key).
- An electronic signature is given to the call using the CR signature key 96 (S52). Then, the card reader encryption processing unit 72 transmits the encrypted CR-EPP master key 101A and the electronic signature 101B to the encryption keypad 14 (S53).
- the encryption keypad 14 Upon receiving these encrypted CR-EPP master key 101A and electronic signature 101B (S54), the encryption keypad 14 first verifies the validity of the electronic signature 101B using the CR verification key 97 (S55). When the validity is verified, the encryption keypad 14 decrypts the encrypted CR-EPP master key 101A using the EPP private key 105 (S56), and the decrypted CR-EPP master key 101 is stored in the memory 121. The data is stored in the data area 121B (FIG. 4B) of FIG. 4B (S57).
- the billing host computer 3 Upon receiving the CR verification key 97 and the CR verification key signature 98 (S61), the billing host computer 3 verifies the validity of the signature of the CR verification key signature 98 using the root verification key 95 (S62). If the verification is verified, the CR verification key 97 is stored in the data area 151B (FIG. 6) of the memory 151 (FIG. 6) (S63). Further, the accounting host computer 3 thereafter transmits the host public key 100 and the host public key signature 108 to the card reader encryption processing unit 72 (S64).
- the card reader encryption processing unit 72 Upon receiving the host public key 100 and the host public key signature 108 (S65), the card reader encryption processing unit 72 verifies the validity of the signature of the host public key signature 108 using the route verification key 95 (S66). If the validity is verified, the host public key 100 is stored in the data area 91B (FIG. 3C) of the memory 91 (FIG. 3C) (S67).
- the card reader encryption processing unit 72 generates a CR-host master key 103 using random numbers (S70), and generates the generated CR-host master key 103 in the data area 91B of the memory 91 (FIG. 3C). (S71).
- the card reader encryption processing unit 72 encrypts the CR-host master key 103 using the host public key 100, and converts it into an encrypted host public key 100 (hereinafter referred to as an encrypted host public key). Then, an electronic signature is assigned using the CR signature key 96 (S72), and thereafter, the encrypted CR-host master key and the electronic signature are transmitted to the accounting host computer 3 (S73).
- the billing host computer 3 When receiving the encrypted CR-host master key and the electronic signature (S74), the billing host computer 3 first verifies the validity of the electronic signature using the CR verification key 97 (S75). If the account host computer 3 can verify the validity of the electronic signature, it decrypts the encrypted CR-host master key using the host secret key 107 (S76), and the decrypted CR- The host master key 103 is stored in the data area 151B (FIG. 6) of the memory 151 (FIG. 6) (S77).
- the card reader encryption processing unit 72 generates a CR-EPP session key 102 using a random number (S80), and uses the generated CR-EPP session key 102 as a data area 91B (FIG. 3C) of the memory 91 (FIG. 3C). (S81).
- the card reader encryption processing unit 72 encrypts the CR-EPP session key 102 using the CR-EPP master key 101 (S82), and encrypts the CR-EPP session key 102 (hereinafter referred to as an encrypted CR- The EPP session key 102A) is transmitted to the encryption keypad 14 (S83).
- the encryption keypad 14 When the encryption keypad 14 receives the encrypted CR-EPP session key 102A (S84), the encryption keypad 14 decrypts the encrypted CR-EPP session key 102A using the CR-EPP master key 101 (S85). The decrypted CR-EPP session key 102 is stored in the data area 121B (FIG. 4B) of the memory 121 (FIG. 4B) (S86).
- the card reader encryption processing unit 72 generates a CR-host session key 104 using a random number (S90), and uses the generated CR-host session key 104 as a data area 91B (FIG. 3C) of the memory 91 (FIG. 3C). (S91).
- the card reader encryption processing unit 72 encrypts the CR-host session key 104 using the CR-host master key 103 (S92), and encrypts the CR-host session key 104 (hereinafter referred to as encrypted CR-).
- the host session key 104A) is transmitted to the accounting host computer 3 (S93).
- the accounting host computer 3 Upon receipt of the encrypted CR-host session key 104A (S94), the accounting host computer 3 decrypts the encrypted CR-host session key 104A using the CR-host master key 103 (S95), thus obtaining it.
- the decrypted CR-host session key 104 is stored in the data area 151B (FIG. 6) of the memory 151 (FIG. 6) (S96).
- a key sharing method such as DUKPT (Derived Unique Key Per Transaction).
- the FIT 157 (see FIG. 7A) is prepared by the accounting host computer 3, but the ATM 2 (FIG. 1) has an updated version.
- the FIT 157 needs to be updated and synchronized.
- the FIT 157 is encrypted using the CR-host session key 104 (FIG. 17) (S100), and the encrypted FIT (hereinafter referred to as encrypted FIT 157A) is transmitted to the ATM control unit 10 (S101). .
- the ATM control unit 10 sends the encrypted FIT 157A as it is to the card reader 13 (FIG. 1).
- the card reader encryption processing unit 72 receives the encrypted FIT 157A (S102), and decrypts the received encrypted FIT 157A using the CR-host session key 104 (S103). Further, the card reader encryption processing unit 72 stores the original FIT 157 obtained by the decryption in the data area 91B (FIG. 3C) of the memory 91 (FIG. 3C) (S104).
- the card reader control unit 70 When the card reader control unit 70 receives the card reading request (S111), the card reader control unit 70 starts the card reading process and accepts the IC card 21 loaded by the user (S112). Thereafter, the card reader control unit 70 causes the card transport / read unit 71 (FIG. 3A) to read the magnetic information 180 recorded on the magnetic tape on the back surface of the IC card 21 (S113). ). Then, the card reader control unit 70 transmits the magnetic information 180 acquired in this way to the card reader encryption processing unit 72 (S114).
- the card reader encryption processing unit 72 Upon receiving the magnetic information 180 (S115), the card reader encryption processing unit 72 stores the magnetic information 180 in the data area 91B (FIG. 3C) of the memory 91 (FIG. 3C) (S116). Thereafter, the card reader encryption processing unit 72 performs masking and encryption on the magnetic information 180 (S117, S118).
- “masking” is a part of the magnetic information 180 in which specific confidential information including PAN is stored (for example, a few digits in the middle of the PAN) or all “*”. It means that it is concealed by converting it to a symbol such as, another character or a number, and includes, for example, a process of converting digits other than the first few digits into a random number like a token PAN.
- Encryption means that the portion of the magnetic information 180 in which such confidential information is stored is encrypted.
- the card reader encryption processing unit 72 uses the masked magnetic information 180 (hereinafter referred to as masked magnetic information 180A) thus obtained and the encrypted magnetic information 180 (hereinafter referred to as encryption). (Referred to as magnetic information 180B) is transmitted to the ATM control unit 10 (S119).
- the ATM control unit 10 stores them in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) (S121).
- the ATM control unit 10 transmits a FIT verification request to the card reader 13 in order to obtain information necessary for the current transaction, as shown in FIG. (S130).
- the card reader encryption processing unit 72 Upon receiving this FIT verification request (S131), the card reader encryption processing unit 72 executes FIT verification processing for verifying the magnetic information 180 with the FIT 157 (S132). Then, the card reader encryption processing unit 72 identifies the financial institution that issued the IC card 21 among the information regarding each financial institution registered in the FIT 157 by this FIT collation processing, and records 160 regarding the identified financial institution. Record information (FIG. 7A) (hereinafter referred to as FIT record information 183 of the financial institution) is acquired (S133).
- the card reader encryption processing unit 72 uses the FIT record information 183 to acquire the PAN of the IC card 21 from the magnetic information 180, encrypts the acquired PAN (S134), and stores the FIT record information 183.
- the language code of the IC card 21 is acquired from the magnetic information 180 by using it (S135).
- the card reader encryption processing unit 72 uses the encrypted PAN thus obtained (hereinafter referred to as encrypted PAN 181A), the language code 182 and other FIT record information 183 as the FIT verification result 184.
- the data is transmitted to the ATM control unit 10 (S136).
- the ATM control unit 10 stores the received FIT collation result 184 in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) (S138).
- the ATM control unit 10 thereafter displays various screens in a language corresponding to the language code 182 based on the language code 182 included in the FIT collation result 184 acquired at this time (FIG. 1).
- information such as the PIN length and PIN block format included in the FIT record information 183 is transmitted to the encryption keypad 14.
- the encryption keypad 14 accepts the PIN at the time of transaction and encrypts the PIN based on the PIN length and PIN block format.
- the ATM control unit 10 transmits an IC chip reading request to the card reader control unit 70 (S140).
- the card reader control unit 70 Upon receiving this IC chip reading request (S141), the card reader control unit 70 causes the card transport / reading unit 71 (FIG. 3A) to read the IC information 190 from the IC chip mounted on the IC card 21. Is acquired (S142). Then, the card reader control unit 70 is information to be classified (PAN and the above-mentioned discretionary information, etc., among the IC information 190 acquired in this way, and hereinafter, this is referred to as confidential IC information. 191) is transmitted to the card reader encryption processing unit 72 (S143).
- the card reader encryption processing unit 72 Upon receiving the confidential IC information 191 (S144), the card reader encryption processing unit 72 stores the received confidential IC information 191 in the data area 91B (FIG. 3C) of the memory 91 (FIG. 3C) (S145).
- the card reader encryption processing unit 72 masks and encrypts the confidential IC information 191 (S146 and S147), and the masked confidential IC information 191 (hereinafter referred to as masked confidential IC information).
- the encrypted confidential IC information 191 (hereinafter referred to as encrypted confidential IC information 191B) is transmitted to the ATM control unit 10 (S148).
- “masking” and “encryption” are the same as “masking” and “encryption” of the magnetic information 180 described above.
- the ATM control unit 10 Upon receiving the masked confidential IC information 191A and the encrypted confidential IC information 191B (S149), the ATM control unit 10 stores them in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) (S150). .
- the ATM control unit 10 transmits a PIN input acceptance request to the encryption keypad 14 (S160).
- the encryption keypad 14 receives this PIN input acceptance request (S161), the encryption keypad 14 starts a PIN input acceptance process, and displays an operation instruction screen for prompting the user to enter the PIN (FIG. 1). ), And then waits for the user to input a PIN by pressing a key on the keypad 111 (FIG. 4A) of the encryption keypad 14.
- step S162 the encryption keypad 14 transmits information indicating that the key has been pressed (hereinafter referred to as key press information) 200 to the ATM control unit 10.
- key press information information indicating that the key has been pressed
- step S162 only information that the key is pressed from the encryption keypad 14 (hereinafter referred to as key pressing information 200) is notified to the ATM control unit 10, and which key is pressed. The information is not notified to the ATM control unit 10.
- the ATM control unit 10 displays information on how many digits the user has entered the PIN on the ATM screen as necessary.
- the encryption keypad 14 indicates that the input of the PIN is completed when the user completes the input of the PIN, for example, when the confirmation key of the keypad 111 is eventually pressed or the input PIN reaches the specified number of digits.
- a notification (hereinafter referred to as an input completion notification) is transmitted to the ATM control unit 10 (S164).
- the ATM control unit 10 recognizes that the PIN input is completed based on the input completion notification (S165).
- the completion of PIN input may be determined from the number of digits input by the ATM control unit 10.
- the encryption keypad 14 then stores the PIN entered by the user at that time in the data area 121B (FIG. 4B) of the memory 121 (FIG. 4B) (S166).
- the ATM control unit 10 thereafter requests the encrypted keypad 14 to transfer the encrypted PIN (hereinafter, this request is referred to as an encrypted PIN transfer request) (S167).
- this request is referred to as an encrypted PIN transfer request
- the encrypted PAN 181A is sent together with the encrypted PIN transfer request.
- This encrypted PAN 181A is stored in the FIT verification result 184 (FIG. 20) stored in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) by the ATM control unit 10 in step S138 of the process described above with reference to FIG. It is included.
- the encryption keypad 14 side Upon receiving the encrypted PIN transfer request (S168), the encryption keypad 14 side decrypts the encrypted PAN 181A as necessary (S169), and encrypts the PIN using the decrypted PAN (S170). . Then, the encryption keypad 14 transmits the encrypted PIN (hereinafter referred to as “encrypted PIN”) 201 to the ATM control unit 10 (S171).
- the ATM control unit 10 when receiving the encrypted PIN 201 (S172), stores the encrypted PIN 201 in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) (S173).
- the ATM control unit 10 requests that the user input the transaction amount to the encryption keypad 14 as shown in FIG. Is transmitted (S180).
- the encryption keypad 14 receives this amount input request (S181), the encryption keypad 14 starts an amount input process and displays an operation instruction screen on the display unit 19 (FIG. 1) to input the transaction amount to the user.
- the user waits for the user to input a transaction amount by pressing a key on the keypad 111 (FIG. 4A).
- the encryption keypad 14 Each time the user presses the key on the keypad 111, the encryption keypad 14 notifies the ATM controller 10 of the pressed key value as the pressed key information 210 (S182). Further, when the ATM control unit 10 receives the pressed key information 210 (S183), based on the pressed key information 210, the transaction amount input by the user so far is displayed on the ATM screen as monetary information.
- the encryption keypad 14 then notifies the ATM control unit 10 of a notification (input completion notification) when the input of the transaction amount by the user is completed by pressing the confirmation key on the keypad 111 in the course of time ( S184).
- the ATM control unit 10 recognizes that the input of the transaction amount has been completed based on this input completion notification (S185).
- the ATM control unit 10 stores the transaction amount input by the user in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) as the amount information 211 (S186).
- the ATM control unit 10 should create card authentication data for the IC card 21 via the card reader control unit 70 as shown in FIG.
- the card authentication data creation request is transmitted (S190).
- the ATM control unit 10 transmits information 220 such as a transaction amount necessary for creating the card authentication data to the IC card 21 together with the card authentication data creation request.
- the IC card 21 When receiving the card authentication data creation request (S191), the IC card 21 creates the card authentication data 221 by using the information 220 transmitted together with the card authentication data creation request (S192). Then, the IC card 21 transmits the created card authentication data 221 to the ATM control unit 10 via the card reader control unit 70 (S193).
- the ATM control unit 10 stores the card authentication data 221 in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) (S195).
- the ATM control unit 10 encrypts the masked magnetic information 180A stored in the data area 31B of the memory 31 and encrypts it as shown in FIG.
- a transaction request message 230 for the accounting host computer 3 is created from information such as the magnetic information 180B, masked confidential IC information 191A, encrypted confidential IC information 191B, amount information 211, and card authentication data 221 (S200).
- the transaction request message 230 is transmitted to the accounting host computer 3 (S201).
- the accounting host computer 3 decrypts the encrypted magnetic information 180B and the encrypted confidential IC information 191B included in the received transaction request message 230 (S203).
- the transaction request message 231 is recreated by using the magnetic information 180 and the IC information 190 obtained by decryption (S204).
- the account host computer 3 transmits the recreated transaction request message 231 to the card brand issuer (not shown) via the external network 232 (S205).
- the billing host computer 3 responds to the transaction request message 231 from the card brand issuer (not shown) via the external network 232.
- the transaction response message 240 is received (S210).
- This transaction response message 240 includes money amount information 241 and issuer authentication data 242.
- the accounting host computer 3 When receiving the transaction response message 240, the accounting host computer 3 recreates the transaction response message 243 for the ATM control unit 10 from the information (S211), and recreates the regenerated transaction response message 243 in the ATM control unit. 10 (S212).
- the transaction response message 243 includes money amount information 241 and issuer authentication data 242.
- the ATM control unit 10 When the ATM control unit 10 receives the transaction response message 243 (S213), the ATM control unit 10 stores the message information such as the money amount information 241 and the issuer authentication data 242 included in the transaction response message 243 in the data area 31B (FIG. 2). (S214).
- the ATM control unit 10 sends the issuer authentication data 242 and the issuer authentication request for requesting the issuer authentication to the card reader control unit. 70 to the IC card 21 (S220).
- the IC card 21 When receiving the issuer authentication data 242 and the issuer authentication request (S221), the IC card 21 performs the issuer authentication (S222). Then, the IC card 21 transmits the authentication result of the executed issuer authentication to the ATM control unit 10 as the issuer authentication result 244 (S223).
- the ATM control unit 10 determines whether or not the issuer authentication is successful, and if the issuer authentication is successful, the withdrawal including the amount to be withdrawn.
- the information 245 and the withdrawal request are transmitted to the banknote processing unit 12 (S225). And the banknote process part 12 will withdraw the money amount based on the withdrawal information received at that time, if this withdrawal request
- the card reader encryption processing unit 72 (FIG. 3C) of the card reader 13 holds the FIT 157 (FIG. 7A), Referring to the FIT 157, necessary information is obtained after encrypting confidential information including PAN in the card information (magnetic information 180 (FIG. 19) and confidential IC information 191 (FIG. 21)) read from the IC card 21.
- the card information is transmitted to the accounting host computer 3 via the ATM control unit 10.
- the ATM control unit 10 of the ATM 2 is infected with malware and the card information is leaked to the outside, the confidential information is encrypted. It is possible to prevent PAN leakage necessary for the use of online shopping, and thus to realize a highly reliable automatic transaction system.
- the ATM control unit 10 since the ATM control unit 10 does not handle an unencrypted card number, the ATM control unit 10 is removed from the inspection target when receiving the certification of PCIDSS (Payment Card Industry Data Security Standards). As a result, it is possible to obtain an effect that the ATM2 is easily certified by PCIDSS.
- PCIDSS Payment Card Industry Data Security Standards
- the FIT 157 can be provided to the ATM control unit 10 on condition that the financial institution number possessed by the FIT 157 can be limited to only digits that do not correspond to confidentiality. Below, this case is made into 2nd Embodiment, and the procedure which carries out transaction using IC card 21 is demonstrated only about a different part from 1st Embodiment.
- FIG. 28 shows an automatic transaction system 250 according to the second embodiment.
- This automatic transaction system 250 is the automatic transaction system 1 according to the first embodiment except that the functions related to the partial processing of the accounting host computer 251 and the ATM controller 253 and the card reader 254 of the ATM 252 are different (FIG. 1). ).
- the billing-system host computer 251 performs processing contents related to FIT update described later with reference to FIG. 29 executed by the CPU 150 (FIG. 6) based on the host application 152 (FIG. 6) stored in the memory 151.
- 30 has the same configuration as that of the accounting host computer 3 of the first embodiment except that the processing content of the processing relating to FIT verification described later is different.
- the ATM 252 includes processing contents of processing described later with reference to FIGS. 29 and 30 executed by the CPU 30 (FIG. 2) of the ATM control unit 253 based on the ATM application 40 (FIG. 2) stored in the memory 31, and the card reader 254. 29 and 30 executed by the CPU 90 (FIG. 3C) of the card reader encryption processing unit 255 (FIG. 29) of FIG. 29 based on the application 92 (FIG. 3C) stored in the memory 91 (FIG. 3C).
- the configuration is the same as that of the ATM 2 of the first embodiment except that the content is different.
- FIG. 29 shows the processing procedure of the FIT update process executed in the automatic transaction system 250 of this embodiment instead of the FIT update process of the first embodiment described above with reference to FIG. .
- the FIT 157 is prepared by the account host computer 251 (FIG. 28).
- the ATM 252 is used. It is necessary to synchronize by updating the FIT 157 of (FIG. 28).
- the accounting host computer 251 transmits the updated FIT 157 to the ATM control unit 253 of the ATM 252 (S250).
- the ATM control unit 253 receives this FIT 157 (S251)
- the received updated FIT 157 is stored in the data storage area 31B (FIG. 2) of the memory 31 (FIG. 2) and a hard disk device in the ATM 252 (not shown). (S252).
- the ATM control unit 253 includes items related to confidential information among various kinds of information unique to each financial institution included in the FIT 157 (here, records 160 (FIG. 7A) of each financial institution). Of the record information, each piece of information 161, 162, 164, 165, 166 of financial institution ID offset, financial institution ID, PAN offset, PAN length, and language code offset) is extracted for each financial institution. Thus, the FIT confidentiality related table 157A, which is a subset of the FIT 157, is created (S253). Then, the ATM control unit 253 transmits the FIT security related table 157A created in this way to the card reader 254 (FIG. 28) (S254).
- the card reader encryption processing unit 255 receives the FIT security related table 157A via the card reader control unit 70 (S255), and the received FIT security related table 157A is a data area 91B of the memory 91 (FIG. 3C). (S256).
- FIG. 30 shows the processing procedure of FIT verification processing executed in the automatic transaction system 250 of this embodiment instead of the FIT verification processing of the first embodiment described above with reference to FIG. Indicates.
- the ATM control unit 253 checks the masked magnetic information 180A with the FIT 157 (S260). From the collation result, record information other than the confidential data (here, PAN and language code) of the record 160 of the corresponding financial institution is acquired (S261). Further, the ATM control unit 253 is a number indicating the number of the record 160 of the corresponding financial institution among the records 160 of each financial institution registered in the FIT 157 based on the reference result of step S260. The table index 300 is transmitted to the card reader 254 (FIG. 28), and the acquisition of confidential data included in the corresponding record 160 is requested (S262).
- the card reader encryption processing unit 255 of the card reader 254 When the card reader encryption processing unit 255 of the card reader 254 receives the request via the card reader control unit 70 (S263), the card reader encryption processing unit 255 starts processing for acquiring confidential data, and first stores the magnetic information 180 in the FIT security related table 157A (FIG. 7B). ), The PAN offset information 164 (FIG. 7B) is acquired from the record 160A corresponding to the table index 300 on the FIT secret relation table 157A (S264). The card reader encryption processing unit 255 acquires the PAN and language code on the magnetic information 180 using the acquired PAN offset information 164, and generates the encrypted PAN 181A by encrypting the acquired PAN ( S265).
- the card reader encryption processing unit 255 acquires the language code 182 from the magnetic information 180 by using the language code offset information 166 (FIG. 7B) acquired from the FIT secret relation table 157A (S266). Then, the card reader encryption processing unit 255 transmits the encrypted PAN 181A and language code 182 generated or acquired in this way to the ATM control unit 253 (S267).
- the ATM control unit 253 When the ATM control unit 253 receives the encrypted PAN 181A and the language code 182 via the card reader control unit 70 (S268), the received encrypted PAN 181A, language code 182, and other FIT 157 and FIT secret related table 157A. Is stored in the data area 31B (FIG. 2) of the memory 31 (FIG. 2) (S269).
- the card reader encryption processing unit 255 of the card reader 254 (FIG. 28) is included in the FIT 157 instead of the FIT 157.
- the FIT security related table 157A in which only the information 161, 162, 164 to 166 for acquiring the confidential information is extracted, and the IC card 21 is based on the FIT security related table 157A.
- the PAN is acquired from the read magnetic information 180, and the acquired PAN is encrypted and transmitted to the ATM control unit 253.
- the ATM control unit 253 holds the FIT 157, and acquires card information that can be acquired from the masked magnetic information 180A with reference to the FIT 157.
- the data amount of the FIT confidential relation table 157A is much smaller than the data amount of the FIT 157. Therefore, according to the automatic transaction system 250 of the present embodiment, in addition to the effects obtained by the automatic transaction system 1 of the first embodiment, the card reader encryption processing unit 255 of the card reader 254 is connected from the IC card 21 to the PAN. It is also possible to obtain an effect that the memory capacity of the memory 91 (FIG. 3C) for holding a table necessary for obtaining the data can be reduced.
- the processing for acquiring the card information from the magnetic information 180 is performed by the card reader encryption processing unit 255 and the ATM.
- the processing load of the card reader encryption processing unit 255 can be reduced and the processing time of the card reader encryption processing unit 255 related to the acquisition of card information can be reduced.
- the automatic transaction system 260 according to this embodiment (FIG. 31) will be described.
- the automatic transaction system 260 according to the present embodiment generates the CR-host master key 103 (FIG. 33) by the account host computer 261, and generates the generated CR-host master key 103 from the account host computer 261 to the card reader of the ATM 262.
- the other points are the same as the automatic transaction system 1 (FIG. 1) of the first embodiment.
- the card reader encryption processing unit 270 of the card reader 263 of this embodiment performs the processing shown in FIG.
- the host verification key 271 is appropriately held in the data area 91B of the memory 91 in place of the host public key 100, and the CR secret key 272 and the CR public key 273 are appropriately held in the data area 91B of the memory 91.
- the rest of the configuration of the card reader 263 is the same as that of the card reader 13 (FIG. 1) of the first embodiment except for the function of the application 275 (FIG. 32) relating to the processing of FIGS.
- the accounting host computer 261 of the present embodiment as shown in FIG. 33 in which the same reference numerals are assigned to the corresponding parts in FIG. 6, in the process of various processes described later, the host secret key 107 in FIG. Instead of the host public key 100, the host public key signature 108, and the CR verification key 97, the host signature key 280, the host verification key 281 and the host verification key signature 282 are held in the data area 151B of the memory 151.
- the configuration of the account host computer 261 other than this is the same as that of the account host computer 3 (FIG. 1) of the first embodiment except for the function of the application 283 (FIG. 33) relating to the processing of FIGS. is there.
- part of the processing contents of the processing of FIGS. 34 to 37 executed by the CPU 170 of the certificate authority 264 (FIG. 31) based on the application 172 stored in the memory 171 is different from that of the first embodiment.
- the other processing contents are the same as those of the certificate authority 5 of the first embodiment.
- FIG. 34 shows an initial key (root key pair and CR key pair) executed in the automatic transaction system 260 (FIG. 31) of this embodiment instead of FIG. (CR key pair) setting procedure flow is shown.
- a root key that is an asymmetric encryption key is used in the certification authority 264 in which the responsible party of secure transactions (mainly assuming an ATM vendor) in the automatic transaction system 260 is a secure environment.
- a pair (route signature key 109 and route verification key 95) is generated (S270).
- the certificate authority 264 stores the root signature key 109 and the route verification key 95 generated at this time in the data area 171B of the memory 171 (FIG. 8) of the certificate authority 264 (S271).
- the card reader encryption processing unit 270 (FIG. 32) of the card reader 263 (FIG. 31) generates a CR key pair (CR secret key 272 and CR public key 273) as an asymmetric encryption key. (S272).
- the card reader encryption processing unit 270 stores the generated CR private key 272 and CR public key 273 in the data area 91B (FIG. 32) of the memory 91 (FIG. 32) (S273). Thereafter, the card reader encryption processing unit 270 transmits the CR public key 273 to the certificate authority 264 in order to give an electronic signature to the CR public key 273 using the root signature key 109 (S274).
- the certificate authority 264 Upon receiving the CR public key 273 (S275), the certificate authority 264 gives an electronic signature to the CR public key 273 using the root signature key 109 generated in step S270 (S276). In addition, the certificate authority 264 transmits the CR public key signature 274 and the route verification key 95, which are the attached electronic signature, to the card reader encryption processing unit 270 (S277).
- the card reader encryption processing unit 270 Upon receiving the CR public key signature 274 and the route verification key 95 (S278), the card reader encryption processing unit 270 stores them in the data area 91B (FIG. 32) of the memory 91 (FIG. 32) (S279).
- FIG. 35 shows an initial key (host key) executed in the automatic transaction system 260 (FIG. 31) of this embodiment instead of FIG. The flow of setting procedure is shown.
- the host account computer 261 After the certificate authority 264 generates the root signature key 109 and the root verification key 95 described above with reference to FIG. 34, first, the host account computer 261 generates a host key pair (host signature key 280 and host verification key 281) that is an asymmetric encryption key. Generate (S280). Then, the accounting host computer 261 stores the generated host signature key 280 and host verification key 281 in the data area 151B (FIG. 33) of the memory 151 (FIG. 33) (S281).
- a host key pair host signature key 280 and host verification key 281 that is an asymmetric encryption key. Generate (S280).
- the accounting host computer 261 stores the generated host signature key 280 and host verification key 281 in the data area 151B (FIG. 33) of the memory 151 (FIG. 33) (S281).
- the account host computer 261 transmits a host verification key 281 to the certificate authority 264 in order to give an electronic signature using the root signature key 109 (S282).
- the certificate authority 264 Upon receiving the host verification key 281 (S283), the certificate authority 264 gives an electronic signature to the host verification key 281 using the root signature key 109 (S284). In addition, the certificate authority 264 transmits the host verification key signature 282 and the root verification key 95, which are electronic signatures assigned to the host verification key 281 at this time, to the accounting host computer 261 (S285).
- the accounting host computer 261 When receiving the host verification key signature 282 and the route verification key 95 (S286), the accounting host computer 261 stores them in the data area 151B (FIG. 33) of the memory 151 (FIG. 33) (S287).
- Master key exchange (CR-host) 36 and 37 are executed to share the master key between the card reader 263 and the billing host computer 261 in the automatic transaction system 260 (FIG. 31) according to the present embodiment instead of FIGS. 14 and 15.
- the flow of processing is shown.
- the card reader encryption processing unit 270 transmits the CR public key 273 and the CR public key signature 274 to the account host computer 261 (S290).
- the billing host computer 261 When receiving the CR public key 273 and the CR public key signature 274 (S291), the billing host computer 261 verifies the validity of the signature of the CR public key signature 274 using the route verification key 95 (S292). If the verification is verified, the CR public key 273 is stored in the data area 151B (FIG. 33) of the memory 151 (FIG. 33) (S293). Further, the billing host computer 261 thereafter transmits the host verification key 281 and the host verification key signature 282 to the card reader encryption processing unit 270 (S294).
- the card reader encryption processing unit 270 Upon receiving the host verification key 281 and the host verification key signature 282 (S295), the card reader encryption processing unit 270 verifies the validity of the signature of the host verification key signature 282 using the route verification key 95 (S296). If the validity is verified, the host verification key 281 is stored in the data area 91B (FIG. 32) of the memory 91 (FIG. 32) (S297).
- the accounting host computer 261 generates a CR-host master key 103 using random numbers (S300), and stores the generated CR-host master key 103 in the data area of the memory 91 (FIG. 32). It is stored in 91B (FIG. 32) (S301).
- the billing host computer 261 encrypts the CR-host master key 103 using the CR public key 273 and also encrypts the CR-host master key 103 (hereinafter referred to as an encrypted CR-host master key 103A).
- An electronic signature is assigned to the caller using the host signature key 280 (S302), and thereafter, the encrypted CR-host master key 103A and the electronic signature are transmitted to the card reader encryption processing unit 270 (S303). .
- the card reader encryption processing unit 270 Upon receiving the encrypted CR-host master key 103A and the electronic signature (S304), the card reader encryption processing unit 270 first verifies the validity of the electronic signature using the host verification key 281 (S305). When the validity of the electronic signature can be verified, the card reader encryption processing unit 270 decrypts the encrypted CR-host master key 103A using the CR secret key 272 (S306), and the decrypted information thus obtained is decrypted.
- the CR-host master key 103 is stored in the data area 91B (FIG. 32) of the memory 91 (FIG. 32) (S307).
- the card reader encryption processing unit 72 generates a CR-host session key and transmits it to the host computer 3 to transmit the CR-host session.
- the host computer 261 generates a CR-host session key, encrypts it, and transmits it to the card reader encryption processing unit 270.
- the CR-host session key is shared as in FIG.
- the card reader encryption processing unit 270 of the card reader 263 of the ATM 262 and the accounting host computer 261 communicate with each other.
- the account host computer 261 generates a CR-host master key 103 used for encrypting the CR-host session key 104 Therefore, the CR-host master key 103 between a plurality of ATMs 262 can be collectively managed in the accounting host computer 261.
- ATMs 2, 252 and 262 as automatic transaction apparatuses are configured as shown in FIG. 1, FIG. 28 or FIG. Although the case has been described, the present invention is not limited to this, and various other configurations can be widely applied. Moreover, as transaction of ATM2,252,262, the transaction performed after card
- the present invention is not limited to this, and the present invention is applied even when the card medium is a magnetic card. be able to.
- a transaction request message 230 (FIG. 25) is generated and transmitted to the account host computer 3 (host device), and the transaction response from the account host computer 3 is transmitted.
- the present invention is not limited to this, and various other configurations can be widely applied.
- the FIT 157 and the FIT secret related table 157A have been described as tables, but the format is not limited to tables, and is necessary for executing the above-described processing. Any information that relates information (for example, information related to the format of card information for each financial institution) may be used.
- the FIT confidentiality related table 157A includes the financial institution ID offset, the financial institution ID, the PAN offset, the PAN length, and the language code offset among the record information of the record 160A of each financial institution.
- the present invention is not limited to this, and the information 161, 162, 164, 165 is described. Information other than 167 may be included.
- the present invention can be applied to an automatic transaction system having an ATM for performing deposit / withdrawal transactions based on card information and user operations, and an accounting host computer for approving the deposit / withdrawal transactions.
Landscapes
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Engineering & Computer Science (AREA)
- Finance (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Computer Security & Cryptography (AREA)
- Development Economics (AREA)
- Economics (AREA)
- Marketing (AREA)
- Technology Law (AREA)
- Software Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
【課題】 カード情報の漏洩を実用上十分に防止し得る信頼性の高い自動取引システム及びその制御方法並びにカードリーダを提案する。 【解決手段】 自動取引システムにおいて、利用者により装填されたカード媒体に記録された第1のカード情報を読み出すカードリーダと、要求電文を生成してホスト装置に送信し、ホスト装置からの応答電文に基づいて取引を行うための制御処理を実行する装置制御部とを自動取引装置に設け、カードリーダが、金融機関ごとの第1のカード情報のフォーマットに関する情報が登録された第1のカードフォーマット情報を保持し、第1のカードフォーマット情報を参照して、カード媒体から読み出した第1のカード情報からカード番号を含む所定の機密情報を取得し、取得した機密情報を暗号化して装置制御部に送信し、装置制御部が、カードリーダから送信されてきた暗号化された機密情報を含む要求電文を生成してホスト装置に送信するようにした。
Description
本発明は、自動取引システム及びその制御方法並びにカードリーダに関し、例えば、クレジットカードやキャッシュカードに記録されたカード情報と、利用者の操作とに基づいて入出金取引を行うATM(Automated Teller Machine)と、当該入出金取引の承認等を行う勘定系ホストコンピュータとを有する自動取引システムに適用して好適なものである。
近年、急速な情報化社会の進展に伴い、企業や自治体等において個人情報や機密情報に対する管理意識が高まっている。また、これまで問題視されてこなかったATM内の閉じたネットワークについてもマルウェアによる機密情報の詐取や不正取引が大きな問題となっている。
ATMで扱う機密情報としては、カード裏面に貼着された磁気テープに記録されている磁気情報やカード番号及び金融機関コードなどのカード情報がある(特許文献1)。磁気情報が漏洩した場合、その磁気情報を元に偽造カードが作成され、不正使用される可能性がある。またカード番号が有効期限等と併せて漏洩した場合には、その情報を利用してネットショッピングなどで不正使用される可能性がある。
このような情報漏洩を防止するための対策として、利用者によりATMに装填されたカードから読み取ったカード情報を、ATMの制御部において暗号化した上で、取引の承認等を行う勘定系ホストコンピュータに送信する方法が考えられる。
しかしながら、上述のようにATMの制御部が勘定系ホストコンピュータにカード情報を暗号化して送信するようにしたとしても、ATMの内部デバイス、特にATM全体の動作制御を司り、勘定系ホストコンピュータとの間の通信を行うATM制御部がマルウェアに感染した場合に、当該ATM制御部を介してカード情報が外部に流出するおそれがある。
本発明は以上の点を考慮してなされたもので、カード情報の漏洩を実用上十分に防止し得る信頼性の高い自動取引システム及びその制御方法並びにカードリーダを提案しようとするものである。
かかる課題を解決するため本発明においては、自動取引装置及びホスト装置を有し、前記自動取引装置に対する利用者の操作に応じた取引の要求電文を前記自動取引装置から前記ホスト装置に送信し、前記要求電文に対する前記ホスト装置からの応答電文に基づいて前記自動取引装置が前記取引を行う自動取引システムにおいて、前記自動取引装置に、前記利用者により装填された前記カード媒体に記録された第1のカード情報を読み出すカードリーダと、前記要求電文を生成して前記ホスト装置に送信し、前記ホスト装置からの前記応答電文に基づいて前記取引を行うための制御処理を実行する装置制御部とを設け、前記カードリーダが、金融機関ごとに固有な、前記第1のカード情報のフォーマットに関する情報が登録された第1のカードフォーマット情報を保持し、前記第1のカードフォーマット情報を参照して、前記カード媒体から読み出した前記第1のカード情報から前記カード番号を含む所定の機密情報を取得し、取得した前記機密情報を暗号化して前記装置制御部に送信し、前記装置制御部が、前記カードリーダから送信されてきた暗号化された前記機密情報を含む前記要求電文を生成して前記ホスト装置に送信するようにした。
また本発明においては、自動取引装置及びホスト装置を有し、前記自動取引装置に対する利用者の操作に応じた取引の要求電文を前記自動取引装置から前記ホスト装置に送信し、前記要求電文に対する前記ホスト装置からの応答電文に基づいて前記自動取引装置が前記取引を行う自動取引システムの制御方法において、前記自動取引装置は、前記利用者により装填された前記カード媒体に記録された第1のカード情報を読み出すカードリーダと、前記要求電文を生成して前記ホスト装置に送信し、前記ホスト装置からの前記応答電文に基づいて前記取引を行うための制御処理を実行する装置制御部とを有し、前記カードリーダは、金融機関ごとに固有な、前記第1のカード情報のフォーマットに関する情報が登録された第1のカードフォーマット情報を保持し、前記カードリーダが、前記第1のカードフォーマット情報を参照して、前記カード媒体から読み出した前記第1のカード情報から前記カード番号を含む所定の機密情報を取得する第1のステップと、前記カードリーダが、取得した前記機密情報を暗号化して前記装置制御部に送信する第2のステップと、前記装置制御部が、前記カードリーダから送信されてきた暗号化された前記機密情報を含む前記要求電文を生成して前記ホスト装置に送信する第3のステップとを設けるようにした。
さらに本発明においては、利用者の操作に応じた取引の要求電文を前記ホスト装置に送信し、前記要求電文に対する前記ホスト装置からの応答電文に基づいて前記取引を行う自動取引装置に設けられ、前記利用者により前記自動取引装置に装填されたカード媒体から当該カード媒体に記録されたカード情報を読み出すカードリーダにおいて、前記自動取引装置に装填された前記カード媒体を搬送し、前記カード媒体から前記カード情報を読み取るカード搬送・読取部と、前記カード搬送・読取部により前記カード媒体から読み取られた前記カード情報を暗号化するカードリーダ暗号処理部とを設け、前記自動取引装置は、前記要求電文を生成して前記ホスト装置に送信し、前記ホスト装置からの前記応答電文に基づいて前記取引を行うための制御処理を実行する装置制御部を有し、前記カードリーダ暗号処理部が、金融機関ごとに固有な、前記第1のカード情報のフォーマットに関する情報が登録された第1のカードフォーマット情報を保持し、前記第1のカードフォーマット情報を参照して、前記カード媒体から読み出した前記第1のカード情報から前記カード番号を含む所定の機密情報を取得し、取得した前記機密情報を暗号化して前記装置制御部に送信するようにした。
本自動取引システム及びその制御方法並びにカードリーダによれば、仮にATMの制御部がマルウェアに感染して第1のカード情報が外部に流出したとしても、機密情報が暗号化されているため、偽造カードの作成や不正なネットショッピングの利用に必要なカード番号の漏洩を防止することができる。
本発明によれば、カード情報の漏洩を実用上十分に防止し得る信頼性の高い自動取引システム及びその制御方法並びにカードリーダを実現できる。
以下図面について、本発明の一実施の形態を詳述する。
(1)第1の実施の形態
(1-1)本実施の形態による自動取引システムの構成
図1において、1は全体して本実施の形態による自動取引システムを示す。この自動取引システム1は、1又は複数のATM2と、勘定系ホストコンピュータ3とがLAN(Local Area Network)又はWAN(Wide Area Network)などの広域ネットワーク4を介して接続され、これらATM2及び勘定系ホストコンピュータ3とは別個に認証局5が設けられることにより構成されている。
(1-1)本実施の形態による自動取引システムの構成
図1において、1は全体して本実施の形態による自動取引システムを示す。この自動取引システム1は、1又は複数のATM2と、勘定系ホストコンピュータ3とがLAN(Local Area Network)又はWAN(Wide Area Network)などの広域ネットワーク4を介して接続され、これらATM2及び勘定系ホストコンピュータ3とは別個に認証局5が設けられることにより構成されている。
ATM2は、利用者の操作に応じて現金の入出金等の取引を行う自動取引装置である。図1に示すように、ATM2は、当該ATM2全体の動作制御を司るATM制御部10と、ATM2の各種表示ランプ制御や扉開閉検知等を行うI/O制御部11と、ATM2の前面に設けられた入出金口内に投入された紙幣を計数して収納庫に搬送、保管し又は出金すべき紙幣を収納庫から取り出して入出金口内に搬送する紙幣処理部12と、ATM2での取引に必要なキャッシュカード等のカード媒体から当該カード媒体に記録されている情報を読み取るカードリーダ13と、取引金額や暗証番号等を入力するためのテンキーを有し、入力された暗証番号等の情報を暗号化する機能を有する暗号化キーパッド14と、取引明細票用のプリンタでなるレシートプリンタ15と、通帳用のプリンタでなる通帳プリンタ16と、ATM取引のログを記録するジャーナルプリンタ17と、ATM利用者の顔写真を撮影するセキュリティ用の監視カメラ18と、入金取引、出金取引などの取引に関する情報を表示する表示部19と、勘定系ホストコンピュータ3と通信を行う通信処理部20とを備えて構成される。なお、表示部19は、利用者からの操作を受け付ける表示操作部であってもよい。
ただしATM2は、入金された硬貨や出金する硬貨を取り扱う硬貨処理部(図示せず)を備えていてもよい。また、本実施の形態においては、カード媒体としてIC(Integrated Circuit Card)カード21が使用される例について説明する。
図2は、ATM制御部10の概略構成を示す。この図2に示すように、ATM制御部10は、CPU(Central Processing Unit)30、メモリ31等の情報処理資源を備えたマイクロコンピュータ構成を有する。CPU30は、ATM制御部10全体の動作制御を司るプロセッサである。メモリ31は、例えば半導体メモリから構成され、プログラムやデータが格納される。
ATM制御部10のメモリ31の記憶領域は、プログラム領域31A及びデータ領域31Bに区分されて管理される。そしてプログラム領域31Aには、ATM2の取引全体を制御するATMアプリケーション40と、I/O(Input/Output)制御部11、紙幣処理部12、カードリーダ13、暗号化キーパッド14、レシートプリンタ15、通帳プリンタ16、ジャーナルプリンタ17、監視カメラ18、表示部19及び通信処理部20をそれぞれ制御するためのソフトウェア(I/O制御部制御ソフトウェア41、紙幣処理部制御ソフトウェア42、カードリーダ制御ソフトウェア43、暗号化キーパッド制御ソフトウェア44、レシートプリンタ制御ソフトウェア45、通帳プリンタ制御ソフトウェア46、ジャーナルプリンタ制御ソフトウェア47、監視カメラ制御ソフトウェア48及び通信処理ソフトウェア49)と、ソフトウェア環境等の設定ファイルであるソフトウェア設定ファイル50とが格納される。
またデータ領域31Bには、ATM2での入出金取引に必要なデータが格納される。例えば、カード番号60、勘定系ホストコンピュータ3(図1)との取引電文のセキュリティを高めるために取引ごとに生成されるATC(ATm Controler)乱数61、磁気情報などを含む取引電文データである取引データ62、ARQC(Authentication Request Cryptogram)63、取引を成立させてよいかどうかを判断した結果のデータである取引可否データ64、ARPC(Authentication Response Cryptogram)65、ARPCの正当性を検証した結果であるARPC検証結果66、ICカード21(図1)によって取引可否が検証された結果である取引検証結果67、紙幣処理部12(図1)に対して送信されるコマンドデータである紙幣処理部制御データ68及び入金取引時において紙幣処理部12(図1)がATM2(図1)に投入された紙幣を計数した合計金額である入金計数金額69などがデータ領域31Bに格納される。
図3Aは、カードリーダ13(図1)の概略構成を示す。この図3Aに示すように、カードリーダ13は、カードリーダ制御部70、カード搬送・読取部71及びカードリーダ暗号処理部72を備えて構成される。カードリーダ制御部70は、カード搬送・読取部71及びカードリーダ暗号処理部72を制御すると共に、これらカード搬送・読取部71及びカードリーダ暗号処理部72の間でデータのやり取りを行う機能を有するハードウェアユニットである。また、カード搬送・読取部71は、ATM2のカード挿入口(図示せず)と、ATM2内部にあるカードリーダ13の読取部との間でICカード21を搬送すると共に、ICカード21の接点を通じてICカード21との間でデータの入出力を行う機能を有するハードウェアユニットである。さらにカードリーダ暗号処理部72は、カードリーダ13内でカード情報の暗号化などの暗号処理を行う機能を有するハードウェアユニットである。カードリーダ暗号処理部72として、SAM(Secure Access Module)等、取り外し可能な暗号処理デバイスを用いることもできる。
カードリーダ制御部70は、図3Bに示すように、カードリーダ制御部70全体の動作制御を司るCPU80と、例えば半導体メモリなどから構成されるメモリ81などの情報処理資源を備えて構成される。カードリーダ制御部70のメモリ81の記憶領域は、プログラム領域81A及びデータ領域81Bに区分されて管理されており、プログラム領域81Aに、全体制御ファームウェア82、ICカード通信制御ファームウェア83及びCSE(Card reader Secure Element)制御ファームウェア84が格納され、データ領域81Bに、全体制御用バッファ85、ICカード通信用バッファ86及びCSE通信用バッファ87が設けられる。
全体制御ファームウェア82は、ATM制御部10との間の通信を制御したり、カード搬送・読取部71(図3A)の搬送制御などを行う機能を有するソフトウェアであり、ICカード通信制御ファームウェア83は、ICカード21との間でデータの入出力制御を行う機能を有するソフトウェアである。またCSE制御ファームウェア84は、カードリーダ暗号処理部72(図3A)を制御したり、当該カードリーダ暗号処理部72との間の通信制御を行うソフトウェアである。
また全体制御用バッファ85は、ATM制御部10との通信用バッファも含む全体制御に使われるデータエリアであり、ICカード通信用バッファ86及びCSE通信用バッファ87はそれぞれ、ICカード21又はカードリーダ暗号処理部72との通信制御用バッファである。
カードリーダ暗号処理部72は、図3Cに示すように、当該カードリーダ暗号処理部72全体の動作制御を司るプロセッサであるCPU90と、例えば、半導体メモリなどから構成されるメモリ91となどの情報処理資源を備えて構成される。
カードリーダ暗号処理部72のメモリ91の記憶領域は、カードリーダ制御部70(図3B)と同様に、プログラム領域91A及びデータ領域91Bに区分されて管理されている。
そしてプログラム領域91Aには、アプリケーション92、通信制御ファームウェア93及び暗号処理ファームウェア94が格納される。アプリケーション92は、カードリーダ暗号処理部72全体の制御を行う機能を有するソフトウェアであり、通信制御ファームウェア93は、カードリーダ制御部70との間の通信制御を行う機能を有するソフトウェアである。また暗号処理ファームウェア94は、電子署名処理や暗号化などを行う機能を有するソフトウェアである。
またデータ領域91Bには、ルート検証鍵95、CR署名鍵96、CR検証鍵97、CR検証鍵署名98、EPP公開鍵99、ホスト公開鍵100、CR-EPPマスタ鍵101、CR-EPPセッション鍵102、CR-ホストマスタ鍵103及びCR-ホストセッション鍵104などが後述する各種処理の過程で適宜格納される。
暗号化キーパッド(EPP)14は、図4Aに示すように、暗号化キーパッド制御部110及びキーパッド111などを備えて構成される。暗号化キーパッド制御部110は、キーパッド111を制御すると共に、暗号化キーパッド制御部110及びキーパッド111の間でデータのやり取りを行う機能を有するハードウェアユニットであり、キーパッド111は、ATM2の筺体上で顧客による操作を受け付けるように設置され、顧客による暗証番号や金額などの入力を受け付けるハードウェアユニットである。
暗号化キーパッド制御部110は、図4Bに示すように、暗号化キーパッド制御部110全体の動作制御を司るCPU120と、例えば半導体メモリなどから構成されるメモリ121などの情報処理資源を備えて構成される。
暗号化キーパッド制御部110のメモリ121の記憶領域は、プログラム領域121A及びデータ領域121Bに区分されて管理されている。
そしてプログラム領域121Aには、アプリケーション122、通信制御ファームウェア123及び暗号処理ファームウェア124が格納される。アプリケーション122は、暗号化キーパッド制御部110全体の制御を行う機能を有するソフトウェアであり、通信制御ファームウェア123は、ATM制御部10やカードリーダ13との間の通信制御を行う機能を有するソフトウェアである。また暗号処理ファームウェア124は、電子署名処理や暗号化などを行う機能を有するソフトウェアである。
またデータ領域121Bには、全体制御用バッファ125及び通信用バッファ126が設けられるほか、ルート検証鍵95、EPP秘密鍵105、EPP公開鍵99、EPP公開鍵署名106、CR検証鍵97、CR-EPPマスタ鍵101及びCR-EPPセッション鍵102などが後述する各種処理の過程で適宜格納される。
図5は、ICカード21の概略構成を示す。ICカード21は、当該ICカード21に搭載されたICチップにより構成されるIC領域130と、当該ICカード21の裏面に貼着された磁気テープにより構成される磁気領域140とを備えている。
このうちIC領域130は、CPU131及びメモリ132等の情報処理資源を備えて構成される。CPU131は、ICカード21のIC領域130の動作制御を司るプロセッサである。メモリ132は、例えば半導体メモリから構成される。
IC領域130のメモリ132の記憶領域は、プログラム領域132A及びデータ領域132Bに区分されて管理される。そしてプログラム領域132Aには、IC領域130の処理を制御するICアプリケーション133、通信制御ファームウェア134及び暗号処理ファームウェア135などが格納される。
ICアプリケーション133は、ICカード21全体の制御を行うソフトウェアであり、通信制御ファームウェア134は、カードリーダ13(図1)との間でのデータ通信を制御する機能を有するソフトウェアである。また暗号処理ファームウェア135は、メッセージ認証コードを生成したり、勘定系ホストコンピュータ3から送信されてくるメッセージ認証コードを検証したりする暗号処理機能をもつソフトウェアである。
またデータ領域132Bには、IC領域130での処理に必要なデータが格納される。具体的には、IC領域130の制御に必要な処理用バッファ136及び通信用バッファ137が設けられるほか、ICカード21を用いた取引に必要な取引データ138などが格納される。なお、取引データ138には、カード番号(以下、これをPAN(Primary Account Number)と呼ぶ)や、磁気領域140に格納されている後述の磁気情報とほぼ同じ内容の情報、及び、そのICカード21を発行した金融機関が自由に格納できる情報であるディスクレショナリ(discretionary)情報などが含まれる。
さらに磁気領域140には、磁気テープの各トラック(図5ではトラック1~トラック3)140Aにそれぞれ必要な磁気情報が格納される。この磁気情報には、そのICカード21を発行した金融機関に付与されたその金融機関に固有の識別子(金融機関ID)、その金融機関が定めている暗証番号(以下、これをPIN(Personal Identification Number)と呼ぶ)の最大桁数(最大PIN長)、その金融機関におけるPANの桁数(PAN長)、そのICカード21に対応付けられた言語を表すコード(言語コード)などが含まれる。
図6は、勘定系ホストコンピュータ3の概略構成を示す。勘定系ホストコンピュータ3は、ATM2の利用者の口座や残高に関する情報などを記憶及び管理するコンピュータ装置であり、図6に示すように、CPU150、メモリ151等の情報処理資源を備えて構成される。CPU150は、勘定系ホストコンピュータ3全体の動作制御を司るプロセッサである。またメモリ151は、例えば半導体メモリから構成される。
勘定系ホストコンピュータ3のメモリ151の記憶領域は、プログラム領域151A及びデータ領域151Bに区分されて管理される。そしてプログラム領域151Aには、勘定系ホストコンピュータ3の処理全体を制御するホストアプリケーション152、通信制御ソフトウェア153及び暗号処理ソフトウェア154などが格納される。
ホストアプリケーション152は、勘定系ホストコンピュータ3全体の制御を行うソフトウェアである。また通信制御ソフトウェア153は、勘定系ホストコンピュータ3と各ATM2との間でのデータ通信を制御する機能を有するソフトウェアである。暗号処理ソフトウェア154は、ATM2から送信されてくるメッセージ認証コードを検証したり、新たなメッセージ認証コードを生成したりする暗号処理機能をもつソフトウェアである。
またデータ領域151Bには、勘定系ホストコンピュータ3での処理に必要なデータが格納される。具体的には、かかるデータ領域151Bには、勘定系ホストコンピュータ3全体の制御に必要な全体制御用バッファ155及び通信用バッファ156が設けられるほか、ルート検証鍵95、ホスト秘密鍵107、ホスト公開鍵100、ホスト公開鍵署名108、CR検証鍵97、CR-ホストマスタ鍵103及びCR-ホストセッション鍵104などが後述する各種処理の過程で適宜格納される。
また勘定系ホストコンピュータ3のメモリ151のデータ領域151Bには、ICカード21を利用した取引に必要なFIT(Financial Institution Table)157も格納されている。
FIT157は、金融機関ごとに固有な各種情報取が格納されたテーブルであり、図7Aに示すように、金融機関ごとの金融機関IDオフセット、金融機関ID、最大PIN長、PANオフセット、PAN長、言語コードオフセット及びPINブロックフォーマットなどの情報161~167がそれぞれ金融機関ごとにまとめられたレコード160の情報(以下、これをレコード情報と呼ぶ)としてそれぞれ格納されている。
このうち金融機関IDは、上述のように対応する金融機関に付与されたその金融機関に固有の識別子である。また金融機関IDオフセットは、その金融機関が発行したICカード21の裏面に貼着された磁気テープの記憶領域における、その金融機関の金融機関IDが格納されている先頭からのオフセット量を表す。さらに最大PIN長は、上述のようにその金融機関が定めているPIN(暗証番号)の最大長を表す。
またPANオフセットは、その金融機関が発行したICカード21の磁気テープの記憶領域における、PAN(カード番号)が格納されている先頭からのオフセット量を表し、PAN長は、その金融機関におけるカード番号の長さを表す。
さらに言語コードオフセットは、その金融機関が発行したICカード21の磁気テープの記憶領域における、言語コードが格納されている先頭からのオフセット量を表す。さらにPINブロックフォーマットは、利用者により入力されたPINを暗号化キーパッド14で暗号化する際のフォーマット(暗号化フォーマット)を表す。
図8は、認証局5の概略構成を示す。認証局5は、必要な公開鍵に対して署名を付与するコンピュータ装置であり、CPU170及びメモリ171等の情報処理資源を備えて構成される。CPU170は、認証局5全体の動作制御を司るプロセッサである。またメモリ171は、例えば半導体メモリから構成される。
認証局5のメモリ171の記憶領域は、プログラム領域171A及びデータ領域171Bに区分されて管理される。そしてプログラム領域171Aには、認証局5の処理全体を制御するアプリケーション172、検証鍵の出力等を行うための通信制御ソフトウェア173及び暗号化に関する各種処理を実行する機能を有する暗号処理ソフトウェア174などが格納される。
またデータ領域171Bには、認証局5での処理に必要なデータが格納される。具体的に、データ領域171Bには、認証局5全体の制御に必要な処理用バッファ175及び通信制御に利用する通信制御用バッファ176が設けられ、さらにルート署名鍵109及びルート検証鍵95などが後述する各種処理の過程で適宜格納される。
(1-2)本自動取引システムにおける各種処理の流れ
次に、本実施の形態の自動取引システム1において実行される各種処理の流れについて説明する。なお以下においては、各種処理の処理主体をATM制御部10(図2)、カードリーダ制御部70(図3B)、カードリーダ暗号処理部72(図3C)、暗号化キーパッド制御部110(図4B)、ICカード21(図5)、勘定系ホストコンピュータ3(図6)、認証局5(図8)として説明するが、実際上は、これらATM制御部10、カードリーダ制御部70、カードリーダ暗号処理部72、暗号化キーパッド制御部110、ICカード21、勘定系ホストコンピュータ3又は認証局5内のCPU30,80,90,120,131,150,170(図2、図3B、図3C、図4B、図5、図6、図8)が対応するプログラムやソフトウェアに基づいてその処理を実行することは言うまでもない。
次に、本実施の形態の自動取引システム1において実行される各種処理の流れについて説明する。なお以下においては、各種処理の処理主体をATM制御部10(図2)、カードリーダ制御部70(図3B)、カードリーダ暗号処理部72(図3C)、暗号化キーパッド制御部110(図4B)、ICカード21(図5)、勘定系ホストコンピュータ3(図6)、認証局5(図8)として説明するが、実際上は、これらATM制御部10、カードリーダ制御部70、カードリーダ暗号処理部72、暗号化キーパッド制御部110、ICカード21、勘定系ホストコンピュータ3又は認証局5内のCPU30,80,90,120,131,150,170(図2、図3B、図3C、図4B、図5、図6、図8)が対応するプログラムやソフトウェアに基づいてその処理を実行することは言うまでもない。
(1-2-1)鍵設定の流れ
まず、本自動取引システム1においてセキュアな取引を実施するために必要な暗号鍵の設定の流れについて説明する。この鍵設定は、ATM2を利用者に利用可能とする前までに行われる。
まず、本自動取引システム1においてセキュアな取引を実施するために必要な暗号鍵の設定の流れについて説明する。この鍵設定は、ATM2を利用者に利用可能とする前までに行われる。
(1-2-1-1)ルート鍵ペア及びカードリーダ鍵ペアの初期設定の流れ
図9は、ATM2のカードリーダ13(図3A)と、認証局5(図8)とを対象として実行される初期鍵(ルート鍵ペア及びカードリーダ鍵ペア)の設定手順の流れを示す。なお、以下においては、適宜、「カードリーダ」を「CR」とも呼ぶものとする。
図9は、ATM2のカードリーダ13(図3A)と、認証局5(図8)とを対象として実行される初期鍵(ルート鍵ペア及びカードリーダ鍵ペア)の設定手順の流れを示す。なお、以下においては、適宜、「カードリーダ」を「CR」とも呼ぶものとする。
かかる初期鍵の設定を行う場合、まず、本自動取引システム1におけるセキュアな取引の責任元(主にATMベンダを想定)がセキュアな環境である認証局5おいて、非対称暗号鍵であるルート鍵ペア(ルート署名鍵109及びルート検証鍵95)を生成する(S1)。そして認証局5は、このとき生成したこれらルート署名鍵109及びルート検証鍵95を認証局5のメモリ171(図8)のデータ領域171Bに格納する(S2)。
また、ATM2側では、カードリーダ13(図3A)のカードリーダ暗号処理部72において、非対称暗号鍵であるCR鍵ペア(CR署名鍵96及びCR検証鍵97)を生成する(S3)。そしてカードリーダ暗号処理部72は、生成したCR署名鍵96及びCR検証鍵97をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S4)。この後、カードリーダ暗号処理部72は、CR検証鍵97に対してルート署名鍵109を用いて電子署名を付与するため、CR検証鍵97を認証局5に送信する(S5)。
認証局5は、かかるCR検証鍵97を受信すると(S6)、ステップS1で生成したルート署名鍵109を用いてCR検証鍵97に電子署名(CR検証鍵署名98)を付与する(S7)。また認証局5は、付与したCR検証鍵署名98及びステップS1で生成したルート検証鍵95をカードリーダ暗号処理部72に送信する(S8)。
そしてカードリーダ暗号処理部72は、これらCR検証鍵署名98及びルート検証鍵95を受信すると(S9)、これらをメモリ91(図3C)のデータ領域91B(図3C)に格納する(S10)。
(1-2-1-2)暗号化キーパッド鍵ペアの初期設定の流れ
一方、図10は、暗号化キーパッド14と、認証局5との間で実行される暗号化キーパッド鍵ペアの設定の流れを示す。なお、以下においては、適宜、「暗号化キーパッド」を「EPP」とも呼ぶものとする。
一方、図10は、暗号化キーパッド14と、認証局5との間で実行される暗号化キーパッド鍵ペアの設定の流れを示す。なお、以下においては、適宜、「暗号化キーパッド」を「EPP」とも呼ぶものとする。
図9において上述したルート署名鍵109及びルート検証鍵95を認証局5が生成後、暗号化キーパッド14が非対称暗号鍵であるEPP鍵ペア(EPP秘密鍵105及びEPP公開鍵99)を生成する(S20)。
そして暗号化キーパッド14(正確には暗号化キーパッド制御部110であり、以下、同様)は、生成したEPP秘密鍵105及びEPP公開鍵99を暗号化キーパッド制御部110のメモリ121(図4B)のデータ領域121B(図4B)に格納する(S21)。また暗号化キーパッド14は、生成したEPP公開鍵99を、ルート署名鍵109を用いて電子署名を付与するため、認証局5に送信する(S22)。
一方、認証局5は、かかるEPP公開鍵99を受信すると(S23)、ルート署名鍵109を用いてこのEPP公開鍵99に電子署名を付与する(S24)。また、認証局5は、付与した電子署名であるEPP公開鍵署名106とルート検証鍵95とを併せて暗号化キーパッド14に送付する(S25)。
そして暗号化キーパッド14は、これらEPP公開鍵署名106及びルート検証鍵95を受信すると(S26)、これらEPP公開鍵署名106及びルート検証鍵95を暗号化キーパッド制御部110のメモリ121(図4B)のデータ領域121B(図4B)に格納する(S27)。
(1-2-1-3)暗号鍵(ホスト鍵)の初期設定の流れ
他方、図11は、勘定系ホストコンピュータ3に対してホスト鍵を設定するホスト鍵設定の流れを示す。
他方、図11は、勘定系ホストコンピュータ3に対してホスト鍵を設定するホスト鍵設定の流れを示す。
図9について上述したルート署名鍵109及びルート検証鍵95を認証局5が生成後、まず、勘定系ホストコンピュータ3が非対称暗号鍵であるホスト鍵ペア(ホスト秘密鍵107及びホスト公開鍵100)を生成する(S30)。そして勘定系ホストコンピュータ3は、生成したホスト秘密鍵107及びホスト公開鍵100をメモリ151(図6)のデータ領域151B(図6)に格納する(S31)。
また勘定系ホストコンピュータ3は、ルート署名鍵109を用いて電子署名を付与するため、ホスト公開鍵100を認証局5に送信する(S32)。
認証局5は、かかるホスト公開鍵100を受信すると(S33)、ルート署名鍵109を用いてホスト公開鍵100に電子署名を付与する(S34)。また認証局5は、このときホスト公開鍵100に付与した電子署名であるホスト公開鍵署名108及びルート検証鍵95を勘定系ホストコンピュータ3に送信する(S35)。
そして勘定系ホストコンピュータ3は、かかるホスト公開鍵署名108及びルート検証鍵95を受信すると(S36)、これらをメモリ151(図6)のデータ領域151B(図5)に格納する(S37)。
(1-2-1-4)マスタ鍵交換(CR-EPP間)
本実施の形態の自動取引システム1では、カードリーダ13及び暗号化キーパッド14間と、カードリーダ13及び勘定系ホストコンピュータ3間とで機密情報をセキュアにやり取りするために当該機密情報をセッションキーを用いて暗号化する。このセッションキーをカードリーダ13及び暗号化キーパッド14間と、カードリーダ13及び勘定系ホストコンピュータ3間とでセキュアに共有するためにマスタキーを用いて暗号化する。
本実施の形態の自動取引システム1では、カードリーダ13及び暗号化キーパッド14間と、カードリーダ13及び勘定系ホストコンピュータ3間とで機密情報をセキュアにやり取りするために当該機密情報をセッションキーを用いて暗号化する。このセッションキーをカードリーダ13及び暗号化キーパッド14間と、カードリーダ13及び勘定系ホストコンピュータ3間とでセキュアに共有するためにマスタキーを用いて暗号化する。
以下、このマスタキーをカードリーダ13及び暗号化キーパッド14間とでセキュアに共有するための手順について、図12及び図13を参照して説明する。
この場合、まず、カードリーダ13のカードリーダ暗号処理部72(図3C)が、CR検証鍵97及びCR検証鍵署名98を暗号化キーパッド14に送信する(S40)。
暗号化キーパッド14は、これらCR検証鍵97及びCR検証鍵署名98を受信すると(S41)、CR検証鍵署名98の署名の正当性をルート検証鍵95を用いて検証し(S42)、正当性が検証されればそのCR検証鍵97をメモリ121(図4B)のデータ領域121B(図4B)に格納する(S43)。そして暗号化キーパッド14は、この後、EPP公開鍵99及びEPP公開鍵署名106をカードリーダ13のカードリーダ暗号処理部72に送信する(S44)。
カードリーダ暗号処理部72は、かかるEPP公開鍵99及びEPP公開鍵署名106を受信すると(S45)、EPP公開鍵署名106の署名の正当性をルート検証鍵95を用いて検証し(S46)、正当性が検証されればEPP公開鍵99をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S47)。
続いて、カードリーダ暗号処理部72は、図13に示すように、乱数によりCR-EPPマスタ鍵101を生成し(S50)、生成したCR-EPPマスタ鍵101をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S51)。
またカードリーダ暗号処理部72は、このCR-EPPマスタ鍵101をEPP公開鍵99を用いて暗号化し、さらに暗号化したCR-EPPマスタ鍵101(以下、これを暗号化CR-EPPマスタ鍵と呼ぶ)に対してCR署名鍵96を用いて電子署名を付与する(S52)。そしてカードリーダ暗号処理部72は、この後、この暗号化CR-EPPマスタ鍵101A及び電子署名101Bを暗号化キーパッド14に送信する(S53)。
暗号化キーパッド14は、これら暗号化CR-EPPマスタ鍵101A及び電子署名101Bを受信すると(S54)、まず、その電子署名101Bの正当性をCR検証鍵97を用いて検証する(S55)。そして、暗号化キーパッド14は、かかる正当性が検証されれば暗号化CR-EPPマスタ鍵101AをEPP秘密鍵105を用いて復号し(S56)、復号したCR-EPPマスタ鍵101をメモリ121(図4B)のデータ領域121B(図4B)に格納する(S57)。
(1-2-1-5)マスタ鍵交換(CR-ホスト間)
次に、図14及び図15を参照して、カードリーダ13及び勘定系ホストコンピュータ3間でマスタキーを共有する手順について説明する。この場合、まず、カードリーダ暗号処理部72が、CR検証鍵97及びCR検証鍵署名98を勘定系ホストコンピュータ3に送信する(S60)。
次に、図14及び図15を参照して、カードリーダ13及び勘定系ホストコンピュータ3間でマスタキーを共有する手順について説明する。この場合、まず、カードリーダ暗号処理部72が、CR検証鍵97及びCR検証鍵署名98を勘定系ホストコンピュータ3に送信する(S60)。
勘定系ホストコンピュータ3は、かかるCR検証鍵97及びCR検証鍵署名98を受信すると(S61)、CR検証鍵署名98の署名の正当性をルート検証鍵95を用いて検証し(S62)、正当性が検証されればCR検証鍵97をメモリ151(図6)のデータ領域151B(図6)に格納する(S63)。また勘定系ホストコンピュータ3は、この後、ホスト公開鍵100及びホスト公開鍵署名108をカードリーダ暗号処理部72に送信する(S64)。
カードリーダ暗号処理部72は、かかるホスト公開鍵100及びホスト公開鍵署名108を受信すると(S65)、ホスト公開鍵署名108の署名の正当性をルート検証鍵95を用いて検証し(S66)、正当性が検証されればホスト公開鍵100をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S67)。
またカードリーダ暗号処理部72は、図15で示すように、乱数によりCR-ホストマスタ鍵103を生成し(S70)、生成したCR-ホストマスタ鍵103をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S71)。
さらにカードリーダ暗号処理部72は、かかるCR-ホストマスタ鍵103をホスト公開鍵100を用いて暗号化すると共に、暗号化したホスト公開鍵100(以下、これを暗号化ホスト公開鍵と呼ぶ)に対してCR署名鍵96を用いて電子署名を付与し(S72)、この後、これらの暗号化CR-ホストマスタ鍵及び電子署名を勘定系ホストコンピュータ3に送信する(S73)。
そして勘定系ホストコンピュータ3は、これら暗号化CR-ホストマスタ鍵及び電子署名を受信すると(S74)、まず、その電子署名の正当性をCR検証鍵97を用いて検証する(S75)。そして勘定系ホストコンピュータ3は、かかる電子署名の正当性を検証できた場合、暗号化CR-ホストマスタ鍵をホスト秘密鍵107を用いて復号し(S76)、かくして得られた復号されたCR-ホストマスタ鍵103をメモリ151(図6)のデータ領域151B(図6)に格納する(S77)。
(1-2-1-6)セッション鍵交換(CR-EPP)
次に、図16を参照して、カードリーダ13及び暗号化キーパッド14間で必要なカード情報を暗号化するためのセッション鍵(CR-EPPセッション鍵102)を共有する手順について説明する。
次に、図16を参照して、カードリーダ13及び暗号化キーパッド14間で必要なカード情報を暗号化するためのセッション鍵(CR-EPPセッション鍵102)を共有する手順について説明する。
まず、カードリーダ暗号処理部72が、乱数を用いてCR-EPPセッション鍵102を生成し(S80)、生成したCR-EPPセッション鍵102をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S81)。
またカードリーダ暗号処理部72は、このCR-EPPセッション鍵102をCR-EPPマスタ鍵101を用いて暗号化し(S82)、暗号化したCR-EPPセッション鍵102(以下、これを暗号化CR-EPPセッション鍵102Aと呼ぶ)を暗号化キーパッド14に送信する(S83)。
暗号化キーパッド14は、かかる暗号化CR-EPPセッション鍵102Aを受信すると(S84)、この暗号化CR-EPPセッション鍵102AをCR-EPPマスタ鍵101を用いて復号し(S85)、かくして得られた復号されたCR-EPPセッション鍵102をメモリ121(図4B)のデータ領域121B(図4B)に格納する(S86)。
(1-2-1-7)セッション鍵交換(CR-ホスト)
次に、図17を参照して、カードリーダ13と勘定系ホストコンピュータ3の間で必要なカード情報を暗号化するためのセッション鍵(CR-ホストセッション鍵)を共有する手順について説明する。
次に、図17を参照して、カードリーダ13と勘定系ホストコンピュータ3の間で必要なカード情報を暗号化するためのセッション鍵(CR-ホストセッション鍵)を共有する手順について説明する。
まず、カードリーダ暗号処理部72が、乱数を用いてCR-ホストセッション鍵104を生成し(S90)、生成したCR-ホストセッション鍵104をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S91)。
またカードリーダ暗号処理部72は、かかるCR-ホストセッション鍵104をCR-ホストマスタ鍵103を用いて暗号化し(S92)、暗号化したCR-ホストセッション鍵104(以下、これを暗号化CR-ホストセッション鍵104Aと呼ぶ)を勘定系ホストコンピュータ3に送信する(S93)。
勘定系ホストコンピュータ3は、かかる暗号化CR-ホストセッション鍵104Aを受信すると(S94)、この暗号化CR-ホストセッション鍵104AをCR-ホストマスタ鍵103を用いて復号し(S95)、かくして得られた復号されたCR-ホストセッション鍵104をメモリ151(図6)のデータ領域151B(図6)に格納する(S96)。ここではセッション鍵の共有をマスタ鍵で暗号化して送付する方式で説明したが、DUKPT(Derived Unique Key Per Transaction)等の鍵共有方式を利用しても同等の効果が得られる。
(1-2-2)本実施の形態における取引の流れ
次に、本実施の形態の自動取引システム1におけるICカード21(図1)を用いた取引の流れについて説明する。
次に、本実施の形態の自動取引システム1におけるICカード21(図1)を用いた取引の流れについて説明する。
(1-2-2-1)FIT更新
図18に示すように、FIT157(図7A参照)は勘定系ホストコンピュータ3にて用意されるが、更新された場合などはATM2(図1)が持つFIT157を更新して同期を取る必要がある。この場合、CR-ホストセッション鍵104(図17)を用いてFIT157を暗号化し(S100)、暗号化したFIT(以下、これを暗号化FIT157Aと呼ぶ)をATM制御部10に送信する(S101)。またATM制御部10は、この暗号化FIT157Aをそのままカードリーダ13(図1)に送付する。
図18に示すように、FIT157(図7A参照)は勘定系ホストコンピュータ3にて用意されるが、更新された場合などはATM2(図1)が持つFIT157を更新して同期を取る必要がある。この場合、CR-ホストセッション鍵104(図17)を用いてFIT157を暗号化し(S100)、暗号化したFIT(以下、これを暗号化FIT157Aと呼ぶ)をATM制御部10に送信する(S101)。またATM制御部10は、この暗号化FIT157Aをそのままカードリーダ13(図1)に送付する。
カードリーダ13側では、カードリーダ暗号処理部72がこの暗号化FIT157Aを受信し(S102)、受信した暗号化FIT157AをCR-ホストセッション鍵104を用いて復号する(S103)。またカードリーダ暗号処理部72は、かかる復号により得られた元のFIT157をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S104)。
(1-2-2-2)カード読取(磁気情報)
利用者が取引開始のための所定操作を行い、ICカード21をATM2に装填すると、図19に示すように、ATM制御部10がカードリーダ13(図1)のカードリーダ制御部70に対してカード読取要求を送信する(S110)。
利用者が取引開始のための所定操作を行い、ICカード21をATM2に装填すると、図19に示すように、ATM制御部10がカードリーダ13(図1)のカードリーダ制御部70に対してカード読取要求を送信する(S110)。
カードリーダ制御部70は、かかるカード読取要求を受信すると(S111)、カード読取処理を開始して、利用者が装填したICカード21を受け付ける(S112)。またカードリーダ制御部70は、この後、ICカード21の裏面の磁気テープに記録されている磁気情報180をカード搬送・読取部71(図3A)に読み取らせることにより、これを取得する(S113)。そしてカードリーダ制御部70は、このようにして取得した磁気情報180をカードリーダ暗号処理部72に送信する(S114)。
カードリーダ暗号処理部72は、かかる磁気情報180を受信すると(S115)、この磁気情報180をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S116)。またカードリーダ暗号処理部72は、この後、この磁気情報180に対するマスク化及び暗号化をそれぞれ行う(S117,S118)。なお、ここでの「マスク化」とは、磁気情報180のうちのPANを含む特定の機密情報が格納されている部分の一部(例えば、PANの真ん中の数桁)又は全部を「*」等の記号、他の文字又は数字に変換するなどして隠蔽することを意味し、例えば、トークンPANのように最初の数桁以外の桁をランダムな数字に変換する処理も含む。また「暗号化」とは、磁気情報180のうちのかかる機密情報が格納されている部分を暗号化することを意味する。
この後、カードリーダ暗号処理部72は、かくして得られたマスク化された磁気情報180(以下、これをマスク化磁気情報180Aと呼ぶ)と、暗号化された磁気情報180(以下、これを暗号化磁気情報180Bと呼ぶ)とをATM制御部10にそれぞれ送信する(S119)。
そしてATM制御部10は、かかるマスク化磁気情報180A及び暗号化磁気情報180Bを受信すると(S120)、これらをメモリ31(図2)のデータ領域31B(図2)に格納する(S121)。
(1-2-2-3)FIT照合
続いて、ATM制御部10は、図20に示すように、今回の取引に必要な情報を取得すべく、カードリーダ13に対してFIT照合要求を送信する(S130)。
続いて、ATM制御部10は、図20に示すように、今回の取引に必要な情報を取得すべく、カードリーダ13に対してFIT照合要求を送信する(S130)。
カードリーダ暗号処理部72は、このFIT照合要求を受信すると(S131)、磁気情報180をFIT157と照合するFIT照合処理を実行する(S132)。そして、カードリーダ暗号処理部72は、このFIT照合処理により、FIT157に登録されている各金融機関に関する情報のうちのそのICカード21を発行した金融機関を特定し、特定した金融機関に関するレコード160(図7A)のレコード情報(以下、これをその金融機関のFITレコード情報183と呼ぶ)を取得する(S133)。
またカードリーダ暗号処理部72は、このFITレコード情報183を使用して磁気情報180からそのICカード21のPANを取得し、取得したPANを暗号化すると共に(S134)、かかるFITレコード情報183を使用して磁気情報180からそのICカード21の言語コードを取得する(S135)。
そしてカードリーダ暗号処理部72は、このようにして取得した暗号化したPAN(以下、これを暗号化PAN181Aと呼ぶ)と、言語コード182と、その他のFITレコード情報183とをFIT照合結果184としてATM制御部10に送信する(S136)。
またATM制御部10は、かかるFIT照合結果184を受信すると(S137)、受信したFIT照合結果184をメモリ31(図2)のデータ領域31B(図2)に格納する(S138)。
なおATM制御部10は、この後、このとき取得したFIT照合結果184に含まれる言語コード182に基づいて、各種画面をその言語コード182に応じた言語で表示するよう表示部19(図1)を制御する一方、FITレコード情報183に含まれるPIN長やPINブロックフォーマットなどの情報を暗号化キーパッド14に送信する。そして暗号化キーパッド14は、このPIN長やPINブロックフォーマットに基づいて、取引時におけるPINの受付けや、PINの暗号化を行う。
(1-2-2-4)カード読取(IC情報)
次に、図21に示すように、ATM制御部10がカードリーダ制御部70に対してICチップ読取要求を送信する(S140)。
次に、図21に示すように、ATM制御部10がカードリーダ制御部70に対してICチップ読取要求を送信する(S140)。
カードリーダ制御部70は、このICチップ読取要求を受信すると(S141)、ICカード21に実装されたICチップからIC情報190をカード搬送・読取部71(図3A)に読み取らせることにより、これを取得する(S142)。そしてカードリーダ制御部70は、このようにして取得したIC情報190のうち、機密にすべき情報(PAN及び上述のディスクレショナリ(discretionary)情報などであり、以下、これを機密IC情報と呼ぶ)191をカードリーダ暗号処理部72に送信する(S143)。
カードリーダ暗号処理部72は、かかる機密IC情報191を受信すると(S144)、受信した機密IC情報191をメモリ91(図3C)のデータ領域91B(図3C)に格納する(S145)。
そしてカードリーダ暗号処理部72は、この後、機密IC情報191のマスク化及び暗号化をそれぞれ行い(S146,S147)、かかるマスク化された機密IC情報191(以下、これをマスク化機密IC情報191Aと呼ぶ)と、かかる暗号化された機密IC情報191(以下、これを暗号化機密IC情報191Bと呼ぶ)とをATM制御部10にそれぞれ送信する(S148)。なお、ここでの「マスク化」及び「暗号化」とは、上述した磁気情報180の「マスク化」及び「暗号化」と同様である。
そしてATM制御部10は、かかるマスク化機密IC情報191A及び暗号化機密IC情報191Bを受信すると(S149)、これらをメモリ31(図2)のデータ領域31B(図2)に格納する(S150)。
(1-2-2-5)PIN入力
次に、ATM制御部10は、図22に示すように、暗号化キーパッド14にPIN入力受付要求を送信する(S160)。そして、暗号化キーパッド14は、このPIN入力受付要求を受信すると(S161)、PIN入力受付処理を開始して、利用者にPINを入力すべき旨の操作指示画面を表示部19(図1)に表示させ、その後、利用者が暗号化キーパッド14のキーパッド111(図4A)のキーを押下してPINを入力するのを待ち受ける。
次に、ATM制御部10は、図22に示すように、暗号化キーパッド14にPIN入力受付要求を送信する(S160)。そして、暗号化キーパッド14は、このPIN入力受付要求を受信すると(S161)、PIN入力受付処理を開始して、利用者にPINを入力すべき旨の操作指示画面を表示部19(図1)に表示させ、その後、利用者が暗号化キーパッド14のキーパッド111(図4A)のキーを押下してPINを入力するのを待ち受ける。
そして暗号化キーパッド14は、利用者がキーパッド111のキーを押下するごとに、キーが押下された旨の情報(以下、これをキー押下情報と呼ぶ)200をATM制御部10に送信する(S162)。なお、このステップS162では、暗号化キーパッド14からはキーが押下されたという情報(以下、これをキー押下情報200と呼ぶ)のみがATM制御部10に通知され、どのキーが押されたかという情報はATM制御部10に通知されない。
また、このときATM制御部10は、かかるキー押下情報200を受信すると(S163)、必要に応じて利用者がPINを何桁目まで入力したかという情報をATM画面に表示させる。
そして暗号化キーパッド14は、やがてキーパッド111の確定キーが押下され又は入力されたPINが指定桁数に到達するなどにより利用者によるPINの入力が完了すると、PINの入力が完了した旨の通知(以下、これを入力完了通知と呼ぶ)をATM制御部10に送信する(S164)。かくしてATM制御部10は、この入力完了通知に基づいてPIN入力が完了したことを認識する(S165)。ただしATM制御部10が入力された桁数からPIN入力完了を判断するようにしてもよい。また暗号化キーパッド14は、この後、そのとき利用者が入力したPINをメモリ121(図4B)のデータ領域121B(図4B)に格納する(S166)。
ATM制御部10は、この後、暗号化したPINの転送を暗号化キーパッド14に要求(以下、この要求を暗号化PIN転送要求と呼ぶ)する(S167)。この際、PINの暗号化方式の中にはPANを必要とするものがあるため、暗号化PAN181Aをかかる暗号化PIN転送要求と併せて送付する。この暗号化PAN181Aは、図20について上述した処理のステップS138でATM制御部10がメモリ31(図2)のデータ領域31B(図2)に格納しておいたFIT照合結果184(図20)に含まれているものである。
暗号化キーパッド14側では、かかる暗号化PIN転送要求を受信すると(S168)、必要に応じて暗号化PAN181Aを復号し(S169)、復号したPANを使用してPINを暗号化する(S170)。そして暗号化キーパッド14は、暗号化したPIN(以下、これを暗号化PINと呼ぶ)201をATM制御部10に送信する(S171)。
またATM制御部10は、かかる暗号化PIN201を受信すると(S172)、この暗号化PIN201をメモリ31(図2)のデータ領域31B(図2)に格納する(S173)。
(1-2-2-6)取引金額入力
この後、ATM制御部10は、図23に示すように、暗号化キーパッド14に対して利用者に取引金額を入力させるべき旨の金額入力要求を送信する(S180)。そして暗号化キーパッド14は、この金額入力要求を受信すると(S181)、金額入力処理を開始して、利用者に取引金額を入力すべき旨の操作指示画面を表示部19(図1)に表示させ、その利用者がキーパッド111(図4A)のキーを押下して取引金額を入力するのを待ち受ける。
この後、ATM制御部10は、図23に示すように、暗号化キーパッド14に対して利用者に取引金額を入力させるべき旨の金額入力要求を送信する(S180)。そして暗号化キーパッド14は、この金額入力要求を受信すると(S181)、金額入力処理を開始して、利用者に取引金額を入力すべき旨の操作指示画面を表示部19(図1)に表示させ、その利用者がキーパッド111(図4A)のキーを押下して取引金額を入力するのを待ち受ける。
そして暗号化キーパッド14は、利用者がキーパッド111のキーを押下するごとに、押下されたキーの値を押下キー情報210としてATM制御部10に通知する(S182)。またATM制御部10は、かかる押下キー情報210を受信すると(S183)、この押下キー情報210に基づいて、そのときまでに利用者が入力した取引金額を金額情報としてATM画面に表示させる。
そして暗号化キーパッド14は、やがてキーパッド111の確定キーが押下されることにより利用者による取引金額の入力が完了すると、その旨の通知(入力完了通知)をATM制御部10に通知する(S184)。かくしてATM制御部10は、この入力完了通知に基づいて取引金額の入力が完了したことを認識する(S185)。
そしてATM制御部10は、この後、利用者により入力された取引金額を金額情報211としてメモリ31(図2)のデータ領域31B(図2)に格納する(S186)。
(1-2-2-7)カード認証データ要求
続いて、ATM制御部10は、図24に示すように、カードリーダ制御部70経由でICカード21に対してカード認証データを作成すべき旨のカード認証データ作成要求を送信する(S190)。この際、ATM制御部10は、かかるカード認証データの作成に必要な取引金額等の情報220をカード認証データ作成要求と共にICカード21に送信する。
続いて、ATM制御部10は、図24に示すように、カードリーダ制御部70経由でICカード21に対してカード認証データを作成すべき旨のカード認証データ作成要求を送信する(S190)。この際、ATM制御部10は、かかるカード認証データの作成に必要な取引金額等の情報220をカード認証データ作成要求と共にICカード21に送信する。
ICカード21は、かかるカード認証データ作成要求を受信すると(S191)、当該カード認証データ作成要求と共に送信されてきた情報220を利用して、カード認証データ221を作成する(S192)。そしてICカード21は、作成したカード認証データ221をカードリーダ制御部70経由でATM制御部10に送信する(S193)。
またATM制御部10は、かかるカード認証データ221を受信すると(S194)、そのカード認証データ221をメモリ31(図2)のデータ領域31B(図2)に格納する(S195)。
(1-2-2-8)取引要求
次いで、ATM制御部10は、図25に示すように、これまでの処理でメモリ31のデータ領域31Bに格納されているマスク化磁気情報180A、暗号化磁気情報180B、マスク化機密IC情報191A、暗号化機密IC情報191B、金額情報211及びカード認証データ221などの情報から、勘定系ホストコンピュータ3に対する取引要求電文230を作成し(S200)、作成した取引要求電文230を勘定系ホストコンピュータ3に送信する(S201)。
次いで、ATM制御部10は、図25に示すように、これまでの処理でメモリ31のデータ領域31Bに格納されているマスク化磁気情報180A、暗号化磁気情報180B、マスク化機密IC情報191A、暗号化機密IC情報191B、金額情報211及びカード認証データ221などの情報から、勘定系ホストコンピュータ3に対する取引要求電文230を作成し(S200)、作成した取引要求電文230を勘定系ホストコンピュータ3に送信する(S201)。
また勘定系ホストコンピュータ3は、かかる取引要求電文230を受信すると(S202)、受信した取引要求電文230に含まれる暗号化磁気情報180B及び暗号化機密IC情報191Bをそれぞれ復号し(S203)、かかる復号により得られた磁気情報180及びIC情報190などを用いて取引要求電文231を作成し直す(S204)。
そして勘定系ホストコンピュータ3は、作成し直した取引要求電文231を外部ネットワーク232経由でカードブランド・イシュア(図示せず)に送信する(S205)。
(1-2-2-9)取引応答
この後、勘定系ホストコンピュータ3は、図26に示すように、外部ネットワーク232経由でカードブランド・イシュア(図示せず)から上述の取引要求電文231に対する取引応答電文240を受信する(S210)。この取引応答電文240には、金額情報241及びイシュア認証データ242等が含まれる。
この後、勘定系ホストコンピュータ3は、図26に示すように、外部ネットワーク232経由でカードブランド・イシュア(図示せず)から上述の取引要求電文231に対する取引応答電文240を受信する(S210)。この取引応答電文240には、金額情報241及びイシュア認証データ242等が含まれる。
そして勘定系ホストコンピュータ3は、かかる取引応答電文240を受信すると、その情報から、ATM制御部10に対する取引応答電文243を作成し直し(S211)、作成し直した取引応答電文243をATM制御部10に送信する(S212)。なお、この取引応答電文243には、金額情報241及びイシュア認証データ242が含まれる。
ATM制御部10は、かかる取引応答電文243を受信すると(S213)、当該取引応答電文243に含まれる金額情報241及びイシュア認証データ242等の電文情報をメモリ31(図2)のデータ領域31B(図2)に格納する(S214)。
(1-2-2-10)イシュア認証及び出金
この後、ATM制御部10は、図27に示すように、イシュア認証データ242と、イシュア認証を要求するイシュア認証要求とをカードリーダ制御部70経由でICカード21に送信する(S220)。
この後、ATM制御部10は、図27に示すように、イシュア認証データ242と、イシュア認証を要求するイシュア認証要求とをカードリーダ制御部70経由でICカード21に送信する(S220)。
ICカード21は、かかるイシュア認証データ242及びイシュア認証要求を受信すると(S221)、イシュア認証を実施する(S222)。そしてICカード21は、実行したイシュア認証の認証結果をイシュア認証結果244としてATM制御部10に送信する(S223)。
ATM制御部10は、かかるイシュア認証結果244を受信すると(S224)、イシュア認証が成功したか否かを判定し、イシュア認証が成功であった場合には、出金すべき金額を含む出金情報245及び出金要求を紙幣処理部12に送信する(S225)。そして紙幣処理部12は、かかる出金要求を受信すると、そのとき受信した出金情報に基づく金額を出金する(S226)。
(1-3)本実施の形態の効果
以上のように本実施の形態の自動取引システム1では、カードリーダ13のカードリーダ暗号処理部72(図3C)がFIT157(図7A)を保持し、当該FIT157を参照して、ICカード21から読み取ったカード情報(磁気情報180(図19)及び機密IC情報191(図21))のうちのPANを含む機密情報を暗号化した上で、必要なカード情報をATM制御部10を介して勘定系ホストコンピュータ3に送信する。
以上のように本実施の形態の自動取引システム1では、カードリーダ13のカードリーダ暗号処理部72(図3C)がFIT157(図7A)を保持し、当該FIT157を参照して、ICカード21から読み取ったカード情報(磁気情報180(図19)及び機密IC情報191(図21))のうちのPANを含む機密情報を暗号化した上で、必要なカード情報をATM制御部10を介して勘定系ホストコンピュータ3に送信する。
従って、本実施の形態によれば、仮にATM2のATM制御部10がマルウェアに感染してカード情報が外部に流出したとしても、機密情報が暗号化されているため、偽造カードの作成や不正なネットショッピングの利用に必要なPANの漏洩を防止することができ、かくして信頼性の高い自動取引システムを実現することができる。
また本実施の形態によれば、ATM制御部10が暗号化されていないカード番号を取り扱わなくなるため、PCIDSS(Payment Card Industry Data Security Standards)の認定を受ける際の検査対象からATM制御部10を外すことができ、その分、ATM2がPCIDSSの認定を受け易くなるという効果をも得ることができる。
(2)第2の実施の形態
第1の実施の形態では、FIT157(図7A)をカードリーダ暗号処理部72で処理する方式を説明した。FIT157が持つ金融機関番号が機密に該当しない桁のみに限定できるという条件で、ATM制御部10にFIT157を持たせることができる。以下ではこのケースを第2の実施の形態として、ICカード21を用いて取引を実施する手順を第1の実施の形態と異なる箇所についてのみ説明する。
第1の実施の形態では、FIT157(図7A)をカードリーダ暗号処理部72で処理する方式を説明した。FIT157が持つ金融機関番号が機密に該当しない桁のみに限定できるという条件で、ATM制御部10にFIT157を持たせることができる。以下ではこのケースを第2の実施の形態として、ICカード21を用いて取引を実施する手順を第1の実施の形態と異なる箇所についてのみ説明する。
(2-1)本実施の形態による自動取引システムの構成
図1との対応部分に同一符号を付して示す図28は、第2の実施の形態による自動取引システム250を示す。この自動取引システム250は、勘定系ホストコンピュータ251と、ATM252のATM制御部253及びカードリーダ254の一部処理に関する機能が異なる点を除いて第1の実施の形態による自動取引システム1(図1)と同様に構成されている。
図1との対応部分に同一符号を付して示す図28は、第2の実施の形態による自動取引システム250を示す。この自動取引システム250は、勘定系ホストコンピュータ251と、ATM252のATM制御部253及びカードリーダ254の一部処理に関する機能が異なる点を除いて第1の実施の形態による自動取引システム1(図1)と同様に構成されている。
この場合、勘定系ホストコンピュータ251は、そのCPU150(図6)がメモリ151に格納されたホストアプリケーション152(図6)に基づいて実行する図29について後述するFIT更新に関する処理の処理内容と、図30について後述するFIT照合に関する処理の処理内容とが異なる点を除いて第1の実施の形態の勘定系ホストコンピュータ3と同様の構成を有する。
またATM252は、ATM制御部253のCPU30(図2)がメモリ31に格納されたATMアプリケーション40(図2)に基づいて実行する図29及び図30について後述する処理の処理内容と、カードリーダ254のカードリーダ暗号処理部255(図29)のCPU90(図3C)がメモリ91(図3C)に格納されたアプリケーション92(図3C)に基づいて実行する図29及び図30について後述する処理の処理内容とが異なる点を除いて第1の実施の形態のATM2と同様の構成を有する。
(2-2)FIT更新
図29は、図18について上述した第1の実施の形態のFIT更新処理に代えて本実施の形態の自動取引システム250において実行されるFIT更新処理の処理手順を示す。本実施の形態の場合、図29に示すように、第1の実施の形態と同様、FIT157は勘定系ホストコンピュータ251(図28)にて用意されるが、FIT157が更新された場合などはATM252(図28)が持つFIT157を更新して同期を取る必要がある。
図29は、図18について上述した第1の実施の形態のFIT更新処理に代えて本実施の形態の自動取引システム250において実行されるFIT更新処理の処理手順を示す。本実施の形態の場合、図29に示すように、第1の実施の形態と同様、FIT157は勘定系ホストコンピュータ251(図28)にて用意されるが、FIT157が更新された場合などはATM252(図28)が持つFIT157を更新して同期を取る必要がある。
そこで、本実施の形態において、勘定系ホストコンピュータ251は、更新されたFIT157をATM252のATM制御部253に送信する(S250)。ATM制御部253は、このFIT157を受信すると(S251)、受信した更新後のFIT157をメモリ31(図2)のデータ領域31B(図2)及び図示しないATM252内のハードディスク装置等からなる外部記憶装置に格納する(S252)。
またATM制御部253は、図7Bに示すように、このFIT157に含まれる金融機関ごとに固有な各種情報のうちの機密情報に関連する項目(ここでは各金融機関のレコード160(図7A)のレコード情報のうち、金融機関IDオフセット、金融機関ID、PANオフセット、PAN長及び言語コードオフセット)の各情報161,162,164,165,166を金融機関ごとにそれぞれ抜粋してこれらそれぞれその金融機関のレコード160Aとすることにより、FIT157のサブセットとなるFIT機密関連テーブル157Aを作成する(S253)。そしてATM制御部253は、このようにして作成したFIT機密関連テーブル157Aをカードリーダ254(図28)に送信する(S254)。
カードリーダ254は、かかるFIT機密関連テーブル157Aをカードリーダ暗号処理部255がカードリーダ制御部70経由で受信し(S255)、受信したFIT機密関連テーブル157Aをメモリ91(図3C)のデータ領域91B(図3C)に格納する(S256)。
(2-3)FIT照合
一方、図30は、図20について上述した第1の実施の形態のFIT照合処理に代えて本実施の形態の自動取引システム250において実行されるFIT照合処理の処理手順を示す。
一方、図30は、図20について上述した第1の実施の形態のFIT照合処理に代えて本実施の形態の自動取引システム250において実行されるFIT照合処理の処理手順を示す。
本実施の形態の場合、ATM制御部253は、マスク化磁気情報180AをFIT157と照合する(S260)。照合結果より、該当する金融機関のレコード160の機密データ(ここではPAN及び言語コード)以外のレコード情報を取得する(S261)。またATM制御部253は、ステップS260の参照結果に基づいて、FIT157に登録された各金融機関のレコード160のうち、該当する金融機関のレコード160が何番目のレコードであるかを表す番号でなるテーブルインデックス300をカードリーダ254(図28)に送信し、該当するレコード160に含まれる機密データの取得を要求する(S262)。
カードリーダ254のカードリーダ暗号処理部255は、かかる要求をカードリーダ制御部70経由で受信すると(S263)、機密データの取得処理を開始し、まず磁気情報180をFIT機密関連テーブル157A(図7B)と照合することにより、FIT機密関連テーブル157A上のかかるテーブルインデックス300に対応するレコード160AからPANのオフセットの情報164(図7B)を取得する(S264)。またカードリーダ暗号処理部255は、取得したPANオフセットの情報164を用いて、磁気情報180上にあるPAN及び言語コードを取得し、取得したPANを暗号化することにより暗号化PAN181Aを生成する(S265)。
さらにカードリーダ暗号処理部255は、FIT機密関連テーブル157Aから取得した言語コードオフセットの情報166(図7B)を用いて、磁気情報180から言語コード182を取得する(S266)。そしてカードリーダ暗号処理部255は、このように生成又は取得した暗号化PAN181A及び言語コード182をATM制御部253に送信する(S267)。
ATM制御部253は、カードリーダ制御部70を介してこれらの暗号化PAN181A及び言語コード182を受信すると(S268)、受信した暗号化PAN181A、言語コード182、及びその他のFIT157及びFIT機密関連テーブル157Aを照合した結果259をメモリ31(図2)のデータ領域31B(図2)に格納する(S269)。
(2-4)本実施の形態の効果
以上のように本実施の形態の自動取引システム250では、カードリーダ254(図28)のカードリーダ暗号処理部255が、FIT157に代えて、FIT157に含まれる各種情報161~167のうち、機密情報を取得するための情報161,162,164~166のみを抜粋したFIT機密関連テーブル157Aを保持し、このFIT機密関連テーブル157Aに基づいてICカード21から読み出した磁気情報180からPANを取得し、取得したPANを暗号してATM制御部253に送信する。また、ATM制御部253は、FIT157を保持し、このFIT157を参照してマスク化磁気情報180Aから取得可能なカード情報を取得する。
以上のように本実施の形態の自動取引システム250では、カードリーダ254(図28)のカードリーダ暗号処理部255が、FIT157に代えて、FIT157に含まれる各種情報161~167のうち、機密情報を取得するための情報161,162,164~166のみを抜粋したFIT機密関連テーブル157Aを保持し、このFIT機密関連テーブル157Aに基づいてICカード21から読み出した磁気情報180からPANを取得し、取得したPANを暗号してATM制御部253に送信する。また、ATM制御部253は、FIT157を保持し、このFIT157を参照してマスク化磁気情報180Aから取得可能なカード情報を取得する。
この場合、FIT機密関連テーブル157Aのデータ量は、FIT157のデータ量と比べて格段的に少ない。従って、本実施の形態の自動取引システム250によれば、第1の実施の形態の自動取引システム1により得られる効果に加えて、カードリーダ254のカードリーダ暗号処理部255がICカード21からPANを取得する際に必要なテーブルを保持するためのメモリ91(図3C)のメモリ容量を低減させることができるという効果をも得ることができる。
また本自動取引システム250では、上述のようにカードリーダ暗号処理部255からPANと言語コードのみを取得すれば良く、磁気情報180からカード情報を取得する処理をカードリーダ暗号処理部255と、ATM制御部253とで分担することになるため結果的に、カードリーダ暗号処理部255の処理負荷を低減し、カード情報の取得に関するカードリーダ暗号処理部255の処理時間を低減させることができる。
(3)第3の実施の形態
(3-1)本実施の形態による自動取引システムの概要及び構成
次に、図31~図37を参照して、本実施の形態による自動取引システム260(図31)について説明する。本実施の形態の自動取引システム260は、CR-ホストマスタ鍵103(図33)を勘定系ホストコンピュータ261で生成し、生成したCR-ホストマスタ鍵103を勘定系ホストコンピュータ261からATM262のカードリーダ263に送付する点を特徴とし、他の部分は第1の実施の形態の自動取引システム1(図1)と同様に構成されている。
(3-1)本実施の形態による自動取引システムの概要及び構成
次に、図31~図37を参照して、本実施の形態による自動取引システム260(図31)について説明する。本実施の形態の自動取引システム260は、CR-ホストマスタ鍵103(図33)を勘定系ホストコンピュータ261で生成し、生成したCR-ホストマスタ鍵103を勘定系ホストコンピュータ261からATM262のカードリーダ263に送付する点を特徴とし、他の部分は第1の実施の形態の自動取引システム1(図1)と同様に構成されている。
このため図3Cとの対応部分に同一符号を付して示す図32に示すように、本実施の形態のカードリーダ263のカードリーダ暗号処理部270は、後述する各種処理の過程において、図3Cのホスト公開鍵100に代えてホスト検証鍵271をメモリ91のデータ領域91Bに適宜保持すると共に、CR秘密鍵272及びCR公開鍵273をメモリ91のデータ領域91Bに適宜保持する。これ以外のカードリーダ263の構成は、図34~図37の処理に関するアプリケーション275(図32)の機能を除いて第1の実施の形態のカードリーダ13(図1)と同様である。
また本実施の形態の勘定系ホストコンピュータ261は、図6との対応部分に同一符号を付して示す図33に示すように、後述する各種処理の過程において、図6のホスト秘密鍵107、ホスト公開鍵100、ホスト公開鍵署名108及びCR検証鍵97に代えて、ホスト署名鍵280、ホスト検証鍵281及びホスト検証鍵署名282をメモリ151のデータ領域151Bに保持する。これ以外の勘定系ホストコンピュータ261の構成は、図34~図37の処理に関するアプリケーション283(図33)の機能を除いて第1の実施の形態の勘定系ホストコンピュータ3(図1)と同様である。
さらに認証局264(図31)のCPU170がメモリ171に格納されたアプリケーション172に基づいて実行する図34~図37の処理の処理内容の一部も第1の実施の形態と異なっているが、これ以外の処理内容は第1の実施の形態の認証局5と同様である。
(3-2)ルート鍵ペア及びCR鍵ペアの初期設定の流れ
図34は、図9に代えて本実施の形態の自動取引システム260(図31)において実行される初期鍵(ルート鍵ペア及びCR鍵ペア)の設定手順の流れを示す。
図34は、図9に代えて本実施の形態の自動取引システム260(図31)において実行される初期鍵(ルート鍵ペア及びCR鍵ペア)の設定手順の流れを示す。
かかる初期鍵の設定を行う場合、まず、本自動取引システム260におけるセキュアな取引の責任元(主にATMベンダを想定)がセキュアな環境である認証局264おいて、非対称暗号鍵であるルート鍵ペア(ルート署名鍵109及びルート検証鍵95)を生成する(S270)。そして認証局264は、このとき生成したこれらルート署名鍵109及びルート検証鍵95を認証局264のメモリ171(図8)のデータ領域171Bに格納する(S271)。
またATM262(図31)側では、カードリーダ263(図31)のカードリーダ暗号処理部270(図32)において、非対称暗号鍵であるCR鍵ペア(CR秘密鍵272及びCR公開鍵273)を生成する(S272)。そしてカードリーダ暗号処理部270は、生成したCR秘密鍵272及びCR公開鍵273をメモリ91(図32)のデータ領域91B(図32)に格納する(S273)。この後、カードリーダ暗号処理部270は、CR公開鍵273に対して、ルート署名鍵109を用いて電子署名を付与するため、CR公開鍵273を認証局264に送信する(S274)。
認証局264は、かかるCR公開鍵273を受信すると(S275)、ステップS270で生成したルート署名鍵109を用いてCR公開鍵273に電子署名を付与する(S276)。また認証局264は、付与した電子署名であるCR公開鍵署名274及びルート検証鍵95をカードリーダ暗号処理部270に送信する(S277)。
そしてカードリーダ暗号処理部270は、これらCR公開鍵署名274及びルート検証鍵95を受信すると(S278)、これらをメモリ91(図32)のデータ領域91B(図32)に格納する(S279)。
(3-3)暗号鍵(ホスト鍵)の初期設定の流れ
一方、図35は、図11に代えて本実施の形態の自動取引システム260(図31)において実行される初期鍵(ホスト鍵)の設定手順の流れを示す。
一方、図35は、図11に代えて本実施の形態の自動取引システム260(図31)において実行される初期鍵(ホスト鍵)の設定手順の流れを示す。
図34について上述したルート署名鍵109及びルート検証鍵95を認証局264が生成後、まず、勘定系ホストコンピュータ261が非対称暗号鍵であるホスト鍵ペア(ホスト署名鍵280及びホスト検証鍵281)を生成する(S280)。そして勘定系ホストコンピュータ261は、生成したホスト署名鍵280及びホスト検証鍵281をメモリ151(図33)のデータ領域151B(図33)に格納する(S281)。
また勘定系ホストコンピュータ261は、ルート署名鍵109を用いて電子署名を付与するため、ホスト検証鍵281を認証局264に送信する(S282)。
認証局264は、かかるホスト検証鍵281を受信すると(S283)、ルート署名鍵109を用いてホスト検証鍵281に電子署名を付与する(S284)。また認証局264は、このときホスト検証鍵281に付与した電子署名であるホスト検証鍵署名282及びルート検証鍵95を勘定系ホストコンピュータ261に送信する(S285)。
そして勘定系ホストコンピュータ261は、かかるホスト検証鍵署名282及びルート検証鍵95を受信すると(S286)、これらをメモリ151(図33)のデータ領域151B(図33)に格納する(S287)。
(3-4)マスタ鍵交換(CR-ホスト)
図36及び図37は、図14及び図15に代えて本実施の形態による自動取引システム260(図31)において、カードリーダ263及び勘定系ホストコンピュータ261間でマスタキーを共有するために実行される処理の流れを示す。この場合、まずカードリーダ暗号処理部270が、CR公開鍵273及びCR公開鍵署名274を勘定系ホストコンピュータ261に送信する(S290)。
図36及び図37は、図14及び図15に代えて本実施の形態による自動取引システム260(図31)において、カードリーダ263及び勘定系ホストコンピュータ261間でマスタキーを共有するために実行される処理の流れを示す。この場合、まずカードリーダ暗号処理部270が、CR公開鍵273及びCR公開鍵署名274を勘定系ホストコンピュータ261に送信する(S290)。
勘定系ホストコンピュータ261は、かかるCR公開鍵273とCR公開鍵署名274を受信すると(S291)、CR公開鍵署名274の署名の正当性をルート検証鍵95を用いて検証し(S292)、正当性が検証されればCR公開鍵273をメモリ151(図33)のデータ領域151B(図33)に格納する(S293)。また勘定系ホストコンピュータ261は、この後、ホスト検証鍵281及びホスト検証鍵署名282をカードリーダ暗号処理部270に送信する(S294)。
カードリーダ暗号処理部270は、かかるホスト検証鍵281及びホスト検証鍵署名282を受信すると(S295)、ホスト検証鍵署名282の署名の正当性をルート検証鍵95を用いて検証し(S296)、正当性が検証されればホスト検証鍵281をメモリ91(図32)のデータ領域91B(図32)に格納する(S297)。
この後、図37に示すように、勘定系ホストコンピュータ261は、乱数によりCR-ホストマスタ鍵103を生成し(S300)、生成したCR-ホストマスタ鍵103をメモリ91(図32)のデータ領域91B(図32)に格納する(S301)。
さらに勘定系ホストコンピュータ261は、CR公開鍵273を用いてCR-ホストマスタ鍵103を暗号化すると共に、暗号化したCR-ホストマスタ鍵103(以下、これを暗号化CR-ホストマスタ鍵103Aと呼ぶ)に対してホスト署名鍵280を用いて電子署名を付与し(S302)、この後、これらの暗号化CR-ホストマスタ鍵103A及び電子署名をカードリーダ暗号処理部270に送信する(S303)。
カードリーダ暗号処理部270は、暗号化CR-ホストマスタ鍵103A及び電子署名を受信すると(S304)、まず、その電子署名の正当性をホスト検証鍵281を用いて検証する(S305)。そしてカードリーダ暗号処理部270は、かかる電子署名の正当性を検証できた場合、暗号化CR-ホストマスタ鍵103AをCR秘密鍵272を用いて復号し(S306)、かくして得られた復号されたCR-ホストマスタ鍵103をメモリ91(図32)のデータ領域91B(図32)に格納する(S307)。
続くセッション鍵の生成についても、第1の実施の形態(図17)ではカードリーダ暗号処理部72にてCR-ホストセッション鍵を生成し、これをホストコンピュータ3に送信することでCR-ホストセッション鍵の共有を行っているのに対し、第3の実施の形態ではホストコンピュータ261にてCR-ホストセッション鍵を生成し、暗号化し、カードリーダ暗号処理部270に送信し、カードリーダ暗号処理部270にて復号化したCR-ホストセッション鍵を、メモリ91に記憶することで、図17と同様にCR-ホストセッション鍵を共有する。
(3-5)本実施の形態の効果
以上のように本実施の形態の自動取引システム260によれば、ATM262のカードリーダ263のカードリーダ暗号処理部270と、勘定系ホストコンピュータ261とが通信を行う際の暗号化に利用するCR-ホストセッション鍵104を共有する際、当該CR-ホストセッション鍵104を暗号化するのに利用するCR-ホストマスタ鍵103を勘定系ホストコンピュータ261で生成するため、複数のATM262との間のCR-ホストマスタ鍵103を勘定系ホストコンピュータ261において一括管理することができる。
以上のように本実施の形態の自動取引システム260によれば、ATM262のカードリーダ263のカードリーダ暗号処理部270と、勘定系ホストコンピュータ261とが通信を行う際の暗号化に利用するCR-ホストセッション鍵104を共有する際、当該CR-ホストセッション鍵104を暗号化するのに利用するCR-ホストマスタ鍵103を勘定系ホストコンピュータ261で生成するため、複数のATM262との間のCR-ホストマスタ鍵103を勘定系ホストコンピュータ261において一括管理することができる。
従って、第1の実施の形態のようにかかるCR-ホストマスタ鍵103を各ATM2(図1)のカードリーダ13(図1)のカードリーダ暗号処理部72(図3C)で生成する場合と比べてその管理が容易であり、また端末である各ATM262においてCR-ホストマスタ鍵103を管理する場合と比べてハッキングを受けたときのリスクを低減することができる。
(4)他の実施の形態
なお上述の第1~第3の実施の形態においては、自動取引装置としてのATM2,252,262を図1、図28又は図31のように構成するようにした場合について述べたが、本発明はこれに限らず、この他種々の構成を広く適用することができる。また、ATM2,252,262の取引としては、入金取引、出金取引、送金取引、残高確認などのカード認証後に行う取引きであってよい。
なお上述の第1~第3の実施の形態においては、自動取引装置としてのATM2,252,262を図1、図28又は図31のように構成するようにした場合について述べたが、本発明はこれに限らず、この他種々の構成を広く適用することができる。また、ATM2,252,262の取引としては、入金取引、出金取引、送金取引、残高確認などのカード認証後に行う取引きであってよい。
また上述の第1~第3の実施の形態においては、カード媒体がICカード21である場合について述べたが、本発明はこれに限らず、カード媒体が磁気カードの場合でも本発明を適用することができる。
さらに上述の第1~第3の実施の形態においては、取引要求電文230(図25)を生成して勘定系ホストコンピュータ3(ホスト装置)に送信し、当該勘定系ホストコンピュータ3からの取引応答電文243(図26)に基づいて取引を行うための制御処理を実行する装置制御部としてのATM制御部10,253を図2、図28のように構成するようにした場合について述べたが、本発明はこれに限らず、この他種々の構成を広く適用することができる。
さらに、上述の第1~第3の実施の形態においては、FIT157、FIT機密関連テーブル157Aをテーブルとして説明したがその形式はテーブルに限るものではなく、上述の処理を実行する上で必要となる情報を関連付けた情報(例えば、金融機関毎のカード情報のフォーマットに関する情報)であればよい。
さらに上述の第2の実施の形態においては、FIT機密関連テーブル157Aを、各金融機関のレコード160Aのレコード情報のうち、金融機関IDオフセット、金融機関ID、PANオフセット、PAN長及び言語コードオフセットの各情報161,162,164,165,167を金融機関ごとにそれぞれ抜粋して作成するようにした場合について述べたが、本発明はこれに限らず、これらの情報161,162,164,165,167以外の情報を含ませるようにしても良い。
本発明は、カード情報と、利用者の操作とに基づいて入出金取引を行うATMと、当該入出金取引の承認等を行う勘定系ホストコンピュータとを有する自動取引システムに適用することができる。
1,250,260……自動取引システム、2,252,262……ATM、3,251,261……勘定系ホストコンピュータ、5,264……認証局、10,253……ATM制御部、13,254,263……カードリーダ、14……暗号化キーパッド、21……ICカード、30,90,120,150,170……CPU、72……カードリーダ暗号処理部、110……暗号化キーパッド制御部、130……IC領域、140……磁気領域、157……FIT、157A……FIT機密関連テーブル。
Claims (9)
- 自動取引装置及びホスト装置を有し、前記自動取引装置に対する利用者の操作に応じた取引の要求電文を前記自動取引装置から前記ホスト装置に送信し、前記要求電文に対する前記ホスト装置からの応答電文に基づいて前記自動取引装置が前記取引を行う自動取引システムにおいて、
前記自動取引装置は、
前記利用者により装填された前記カード媒体に記録された第1のカード情報を読み出すカードリーダと、
前記要求電文を生成して前記ホスト装置に送信し、前記ホスト装置からの前記応答電文に基づいて前記取引を行うための制御処理を実行する装置制御部と
を備え、
前記カードリーダは、
金融機関ごとに固有な、前記第1のカード情報のフォーマットに関する情報が登録された第1のカードフォーマット情報を保持し、
前記第1のカードフォーマット情報を参照して、前記カード媒体から読み出した前記第1のカード情報から前記カード番号を含む所定の機密情報を取得し、
取得した前記機密情報を暗号化して前記装置制御部に送信し、
前記装置制御部は、
前記カードリーダから送信されてきた暗号化された前記機密情報を含む前記要求電文を生成して前記ホスト装置に送信する
ことを特徴とする自動取引システム。 - キーパッドを有し、前記キーパッドを介して前記利用者が入力した暗証番号を暗号化して前記装置制御部に送信する暗号化キーパッドを備え、
前記カードリーダは、
前記機密情報のうちの暗号化した前記カード番号を前記装置制御部を経由して前記暗号化キーパッドに送信する
ことを特徴とする請求項1に記載の自動取引システム。 - 前記第1のカードフォーマット情報には、前記第1のカード情報のフォーマットに関する情報の一部が登録され、
前記第1のカードフォーマット情報に登録された前記第1のカード情報のフォーマットに関する情報の一部は、前記金融機関ごとの前記機密情報を前記第1のカード情報から取得するのに必要な情報であり、
前記カードリーダは、
前記カード媒体から読み出した前記第1のカード情報のうちの前記機密情報を暗号化して前記装置制御部に送信すると共に、前記第1のカード情報のうちの前記機密情報をマスク化し、他の情報をマスク化していない第2のカード情報を前記装置制御部に送信し、
前記装置制御部は、
前記金融機関ごとの前記カード情報のフォーマットに関する情報が登録された第2のカードフォーマット情報を保持し、当該第2のカードフォーマット情報を参照して、前記第2のカード情報の中から必要な情報を取得する
ことを特徴とする請求項1に記載の自動取引システム。 - 前記ホスト装置は、
前記自動取引装置の前記カードリーダとの間で通信を行う際の暗号化に利用するセッション鍵を暗号化するためのマスタ鍵を生成し、
生成した前記マスタ鍵を前記カードリーダと共有する
ことを特徴とする請求項1に記載の自動取引システム。 - 自動取引装置及びホスト装置を有し、前記自動取引装置に対する利用者の操作に応じた取引の要求電文を前記自動取引装置から前記ホスト装置に送信し、前記要求電文に対する前記ホスト装置からの応答電文に基づいて前記自動取引装置が前記取引を行う自動取引システムの制御方法において、
前記自動取引装置は、
前記利用者により装填された前記カード媒体に記録された第1のカード情報を読み出すカードリーダと、
前記要求電文を生成して前記ホスト装置に送信し、前記ホスト装置からの前記応答電文に基づいて前記取引を行うための制御処理を実行する装置制御部とを有し、
前記カードリーダは、
金融機関ごとに固有な、前記第1のカード情報のフォーマットに関する情報が登録された第1のカードフォーマット情報を保持し、
前記カードリーダが、前記第1のカードフォーマット情報を参照して、前記カード媒体から読み出した前記第1のカード情報から前記カード番号を含む所定の機密情報を取得する第1のステップと、
前記カードリーダが、取得した前記機密情報を暗号化して前記装置制御部に送信する第2のステップと、
前記装置制御部が、前記カードリーダから送信されてきた暗号化された前記機密情報を含む前記要求電文を生成して前記ホスト装置に送信する第3のステップと
を備えることを特徴とする自動取引システムの制御方法。 - 前記自動取引システムは、
キーパッドを有し、前記キーパッドを介して前記利用者が入力した暗証番号を暗号化して前記装置制御部に送信する暗号化キーパッドを含み、
前記第2のステップにおいて、前記カードリーダは、
前記機密情報のうちの暗号化した前記カード番号を前記装置制御部を経由して前記暗号化キーパッドに送信する
ことを特徴とする請求項5に記載の自動取引システムの制御方法。 - 前記第1のカードフォーマット情報には、前記第1のカード情報のフォーマットに関する情報の一部が登録され、
前記第1のカードフォーマット情報に登録された前記第1のカード情報のフォーマットに関する情報の一部は、前記金融機関ごとの前記機密情報を前記第1のカード情報から取得するのに必要な情報であり、
前記第2のステップにおいて、前記カードリーダは、
前記カード媒体から読み出した前記第1のカード情報のうちの前記機密情報を暗号化して前記装置制御部に送信すると共に、前記第1のカード情報のうちの前記機密情報をマスク化し、他の情報をマスク化していない第2のカード情報を前記装置制御部に送信し、
前記装置制御部は、
前記金融機関ごとに固有な、前記カード情報のフォーマットに関する情報が登録された第2のカードフォーマット情報を保持し、
前記第3のステップにおいて、前記装置制御部は、
前記第2のカードフォーマット情報を参照して、前記第2のカード情報の中から必要な情報を取得する
ことを特徴とする請求項5に記載の自動取引システムの制御方法。 - 前記ホスト装置は、
前記自動取引装置のカードリーダとの間で通信を行う際の暗号化に利用するセッション鍵を暗号化するためのマスタ鍵を生成し、
生成した前記マスタ鍵を前記カードリーダと共有する
ことを特徴とする請求項5に記載の自動取引システムの制御方法。 - 利用者の操作に応じた取引の要求電文を前記ホスト装置に送信し、前記要求電文に対する前記ホスト装置からの応答電文に基づいて前記取引を行う自動取引装置に設けられ、前記利用者により前記自動取引装置に装填されたカード媒体から当該カード媒体に記録されたカード情報を読み出すカードリーダにおいて、
前記自動取引装置に装填された前記カード媒体から前記カード情報を読み取るカード読取部と、
前記カード読取部により前記カード媒体から読み取られた前記カード情報を暗号化するカードリーダ暗号処理部と
を備え、
前記自動取引装置は、
前記要求電文を生成して前記ホスト装置に送信し、前記ホスト装置からの前記応答電文に基づいて前記取引を行うための制御処理を実行する装置制御部を有し、
前記カードリーダ暗号処理部は、
金融機関ごとに固有な、前記第1のカード情報のフォーマットに関する情報が登録された第1のカードフォーマット情報を保持し、
前記第1のカードフォーマット情報を参照して、前記カード媒体から読み出した前記第1のカード情報から前記カード番号を含む所定の機密情報を取得し、
取得した前記機密情報を暗号化して前記装置制御部に送信する
ことを特徴とするカードリーダ。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2016/066630 WO2017208445A1 (ja) | 2016-06-03 | 2016-06-03 | 自動取引システム及びその制御方法並びにカードリーダ |
| US16/072,619 US20190034891A1 (en) | 2016-06-03 | 2016-06-03 | Automated transaction system, method for control thereof, and card reader |
| JP2018520323A JPWO2017208445A1 (ja) | 2016-06-03 | 2016-06-03 | 自動取引システム及びその制御方法並びにカードリーダ |
| DE112016006145.5T DE112016006145T5 (de) | 2016-06-03 | 2016-06-03 | Automatisiertes Transaktionssystem, Verfahren zu dessen Steuerung und Kartenleser |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2016/066630 WO2017208445A1 (ja) | 2016-06-03 | 2016-06-03 | 自動取引システム及びその制御方法並びにカードリーダ |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017208445A1 true WO2017208445A1 (ja) | 2017-12-07 |
Family
ID=60478116
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2016/066630 Ceased WO2017208445A1 (ja) | 2016-06-03 | 2016-06-03 | 自動取引システム及びその制御方法並びにカードリーダ |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20190034891A1 (ja) |
| JP (1) | JPWO2017208445A1 (ja) |
| DE (1) | DE112016006145T5 (ja) |
| WO (1) | WO2017208445A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2021524074A (ja) * | 2018-04-03 | 2021-09-09 | カレンシー セレクト ピーティーワイ リミテッドCurrency Select Pty Ltd. | 取引セキュリティのためのシステム、装置、サーバ及び方法 |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111275440B (zh) * | 2020-01-19 | 2023-11-10 | 中钞科堡现金处理技术(北京)有限公司 | 远程密钥下载方法及系统 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH10171717A (ja) * | 1996-12-05 | 1998-06-26 | Matsushita Electric Ind Co Ltd | Icカードおよびそれを用いた暗号通信システム |
| JP2002259866A (ja) * | 2001-02-27 | 2002-09-13 | Nec Commun Syst Ltd | 携帯端末接続型カードリーダ装置及びそれを用いた認証決済方法 |
| JP2010020402A (ja) * | 2008-07-08 | 2010-01-28 | Oki Electric Ind Co Ltd | 認証装置および自動取引装置ならびに認証システム |
| JP2016091132A (ja) * | 2014-10-31 | 2016-05-23 | キヤノンマーケティングジャパン株式会社 | 情報処理装置、情報処理装置の制御方法、プログラム |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2855946B2 (ja) | 1992-03-26 | 1999-02-10 | 富士通株式会社 | 現金自動取引機 |
-
2016
- 2016-06-03 JP JP2018520323A patent/JPWO2017208445A1/ja active Pending
- 2016-06-03 DE DE112016006145.5T patent/DE112016006145T5/de not_active Withdrawn
- 2016-06-03 WO PCT/JP2016/066630 patent/WO2017208445A1/ja not_active Ceased
- 2016-06-03 US US16/072,619 patent/US20190034891A1/en not_active Abandoned
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH10171717A (ja) * | 1996-12-05 | 1998-06-26 | Matsushita Electric Ind Co Ltd | Icカードおよびそれを用いた暗号通信システム |
| JP2002259866A (ja) * | 2001-02-27 | 2002-09-13 | Nec Commun Syst Ltd | 携帯端末接続型カードリーダ装置及びそれを用いた認証決済方法 |
| JP2010020402A (ja) * | 2008-07-08 | 2010-01-28 | Oki Electric Ind Co Ltd | 認証装置および自動取引装置ならびに認証システム |
| JP2016091132A (ja) * | 2014-10-31 | 2016-05-23 | キヤノンマーケティングジャパン株式会社 | 情報処理装置、情報処理装置の制御方法、プログラム |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2021524074A (ja) * | 2018-04-03 | 2021-09-09 | カレンシー セレクト ピーティーワイ リミテッドCurrency Select Pty Ltd. | 取引セキュリティのためのシステム、装置、サーバ及び方法 |
| JP7222453B2 (ja) | 2018-04-03 | 2023-02-15 | カレンシー セレクト ピーティーワイ リミテッド | 取引セキュリティのためのシステム、装置、サーバ及び方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20190034891A1 (en) | 2019-01-31 |
| DE112016006145T5 (de) | 2018-09-20 |
| JPWO2017208445A1 (ja) | 2018-11-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7681048B2 (ja) | ブロックチェーンに格納された個人データを安全に共有するための非接触カードの使用 | |
| CN107230079B (zh) | 使用数字货币芯片卡进行离线支付的方法及系统 | |
| JP6360101B2 (ja) | Ic識別カードを使用した支払いシステムおよび方法 | |
| CN107230051B (zh) | 数字货币的支付方法和支付系统 | |
| US8608064B2 (en) | Payment system and method of IC card and a multi-application IC card as well as a payment terminal | |
| US7103575B1 (en) | Enabling use of smart cards by consumer devices for internet commerce | |
| CN113924588A (zh) | 用于将电子币数据记录直接发送到另一设备的设备和支付系统 | |
| CN107230050B (zh) | 基于可视数字货币芯片卡进行数字货币支付的方法和系统 | |
| CN107230068B (zh) | 使用可视数字货币芯片卡支付数字货币的方法和系统 | |
| US6023508A (en) | Polymorphic data structures for secure operation of a virtual cash system | |
| US20060136332A1 (en) | System and method for electronic check verification over a network | |
| US20060123465A1 (en) | Method and system of authentication on an open network | |
| CN107230053B (zh) | 使用现金兑换数字货币的方法及系统 | |
| CN108292330A (zh) | 安全令牌分发 | |
| WO2012063892A1 (ja) | サービス提供システム及びユニット装置 | |
| CN107230049A (zh) | 提供数字货币的方法和系统 | |
| US12493878B2 (en) | System for inputting a pin block to a network | |
| CN107230072A (zh) | 使用数字货币芯片卡进行网上支付的方法和系统 | |
| CN106330888B (zh) | 一种保证互联网线上支付安全性的方法及装置 | |
| CN107230069B (zh) | 使用数字货币芯片卡支付数字货币的方法和系统 | |
| CN115777190A (zh) | 用于基于接近度的访问装置交互的具选择性去令牌化的令牌处理 | |
| CN107230073B (zh) | 在可视数字货币芯片卡之间支付数字货币的方法和系统 | |
| CN107230078B (zh) | 使用可视数字货币芯片卡进行数字货币支付的方法和系统 | |
| US20120041882A1 (en) | Method of and computer programme for changing an identification code of a transaction authorisation medium | |
| WO2017208445A1 (ja) | 自動取引システム及びその制御方法並びにカードリーダ |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 2018520323 Country of ref document: JP |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 112016006145 Country of ref document: DE |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16904070 Country of ref document: EP Kind code of ref document: A1 |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16904070 Country of ref document: EP Kind code of ref document: A1 |