WO2025248643A1 - システム、サーバ装置、インストール方法、セキュア方法、及びプログラム - Google Patents

システム、サーバ装置、インストール方法、セキュア方法、及びプログラム

Info

Publication number
WO2025248643A1
WO2025248643A1 PCT/JP2024/019592 JP2024019592W WO2025248643A1 WO 2025248643 A1 WO2025248643 A1 WO 2025248643A1 JP 2024019592 W JP2024019592 W JP 2024019592W WO 2025248643 A1 WO2025248643 A1 WO 2025248643A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
data
maintenance
key
authentication information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/JP2024/019592
Other languages
English (en)
French (fr)
Inventor
征男 岡村
崇 岸本
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Glory Ltd
Original Assignee
Glory Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Glory Ltd filed Critical Glory Ltd
Priority to PCT/JP2024/019592 priority Critical patent/WO2025248643A1/ja
Publication of WO2025248643A1 publication Critical patent/WO2025248643A1/ja
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00Administration; Management
    • G06Q10/20Administration of product repair or maintenance
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/18Payment architectures involving self-service terminals [SST], vending machines, kiosks or multimedia terminals

Definitions

  • This disclosure relates to a system, a server device, an installation method, a secure method, and a program.
  • Patent Document 1 discloses technology for preventing the fraudulent use of an update program for updating an identification program that identifies currency in a currency processing device such as the one described above.
  • the manufacturer encrypts the update program with an authorization code and stores it on an SD card. They also encrypt the authorization code with the device code of the currency identification device to generate a PIN code, and distribute the PIN code along with the SD card. Furthermore, in the technology disclosed in Patent Document 1, when the distributed SD card is inserted into the target currency identification device and the distributed PIN code is entered, the authorization code is decrypted using the device code of the currency identification device, and the update program is decrypted from the SD card using the authorization code. Therefore, the technology disclosed in Patent Document 1 can prevent the unauthorized use of the update program on other currency identification devices.
  • the present disclosure aims to provide a system, server device, update method, secure method, and program that can increase security in the process of installing data in a currency processing device.
  • a system is a system including a currency processing device that processes currency, wherein the currency processing device comprises: a receiving unit that receives second data obtained by performing secure processing on first data by a server device that provides a secure processing service on a first cloud; a decryption unit that decrypts the second data into the first data; and an installation unit that installs the decrypted first data into the currency processing device.
  • the first data may be data to be installed in the currency processing device.
  • the receiving unit may receive the second data via a maintenance terminal.
  • the maintenance terminal may transmit the first data to the server device.
  • the currency processing device may further include a currency identification unit that performs an identification process for the type of currency, including at least one of the denomination, authenticity, and fitness of the currency, and the first data may be data used in the identification process.
  • the first data may include a threshold value that is compared with a detection value detected from the currency during the identification process.
  • the secure processing may include an encryption process using a first key
  • the currency processing device may further include a storage unit that stores a second key
  • the decryption unit may use the second key to decrypt the second data into the first data.
  • the first key and the second key may be a common key.
  • the secure processing may include an electronic signature process that generates an electronic signature for the first data using a third key
  • the second data may include the electronic signature
  • the currency processing device may use the electronic signature to determine whether the integrity of the first data is guaranteed
  • the installation unit may install the first data into the currency processing device if the integrity of the first data is guaranteed.
  • the currency processing device may further include a storage unit that stores a fourth key that pairs with the third key.
  • the decryption unit may decrypt the first data and the electronic signature from the second data, and use the decrypted first data, the decrypted electronic signature, and the fourth key to determine whether the integrity of the decrypted first data is guaranteed.
  • the storage unit may be at least one of a memory in a safe provided in the currency processing device and a TPM (Trusted Platform Module).
  • TPM Trusted Platform Module
  • the system may further include a server device, and the server device may include a data receiving unit that receives the first data, a secure processing unit that performs the secure processing on the first data to generate the second data, and a first transmitting unit that transmits the second data to an external device.
  • the data receiving unit may receive the first data from the maintenance terminal used for maintaining the currency processing device.
  • the first transmitting unit may transmit the second data to the maintenance terminal.
  • the server device further includes an authentication information receiving unit that receives maintenance staff authentication information for authenticating a maintenance staff member performing maintenance on the currency processing device, and an authentication control unit that controls authentication of the maintenance staff using the maintenance staff authentication information and a first authentication service, and the secure processing unit may generate the second data if authentication of the maintenance staff is successful.
  • the maintenance staff may be a person who performs maintenance on the currency processing device using a maintenance terminal.
  • the authentication information receiving unit may receive the maintenance staff authentication information from the maintenance terminal.
  • the first authentication service may be provided on a second cloud different from the first cloud.
  • the server device may further include a key storage unit that stores a key
  • the secure processing unit may perform the secure processing on the first data using the key
  • the first authentication service may be an authentication service that uses a maintenance personnel database managed within the second cloud.
  • the key may include a first key that is common to a second key managed by the currency processing device, and the secure processing may include an encryption process that performs encryption using the first key.
  • the key may include a third key that pairs with a fourth key managed by the currency processing device
  • the secure processing may include an electronic signature process that generates an electronic signature for the first data using the third key
  • the second data may include the electronic signature
  • the authentication information receiving unit may further receive administrator authentication information for authenticating an administrator who manages the keys, and the authentication control unit may control authentication of the administrator using the administrator authentication information and a second authentication service.
  • the administrator may be a person who manages the keys using a management terminal.
  • the authentication information receiving unit may receive the administrator authentication information from the management terminal.
  • the second authentication service may be an authentication service that uses an administrator database managed in the second cloud.
  • the maintenance staff authentication information and the administrator authentication information may include first authentication information.
  • the first authentication information included in the maintenance staff authentication information is information that identifies the maintenance staff.
  • the first authentication information included in the administrator authentication information is information that identifies the administrator.
  • the authentication control unit when the authentication control unit determines to use the second authentication service for authentication, the authentication control unit may use the first authentication information included in the administrator authentication information and the second authentication service to control authentication of whether the administrator has key management authority.
  • the maintenance staff authentication information may further include second authentication information that identifies the maintenance staff and is different from the first authentication information, and when the authentication control unit determines to use the first authentication service for authentication, the authentication control unit may use the second authentication information and the first authentication service to control authentication of whether the maintenance staff has maintenance authority for the currency processing device.
  • the maintenance personnel authentication information may further include third authentication information that identifies the maintenance personnel and is different from the first authentication information and the second authentication information, and the authentication control unit may further control authentication of the legitimacy of the maintenance personnel using the third authentication information.
  • the system may further include the maintenance terminal, and the maintenance terminal may include an authentication unit that authenticates the legitimacy of the maintenance personnel, and a second transmission unit that transmits the maintenance personnel authentication information to the server device if the authentication is successful.
  • the authentication unit may authenticate the legitimacy of the maintenance personnel using a hardware key carried by the maintenance personnel.
  • the maintenance terminal may include a data generation unit that generates the first data.
  • the data generation unit may generate the first data based on data indicating the results of a flow test received from the currency processing device connected to the maintenance terminal.
  • the results of the flow test may be, for example, the result of identifying test banknotes by the currency identification unit.
  • the second authentication information may be information that identifies a hardware key held by the maintenance personnel.
  • the third authentication information may be a one-time password based on a hardware key held by the maintenance personnel.
  • the authentication control unit may issue a JWT (JSON Web Token) if the maintenance personnel is authenticated, and the first transmission unit may transmit the JWT to an external device.
  • the data receiving unit may receive the first data and the JWT from an external device, and the secure processing unit may authenticate the JWT and determine whether or not to execute the secure processing on the first data.
  • the authentication control unit may issue a JWT if it is authenticated that the maintenance personnel is legitimate and has at least one of the maintenance authority.
  • the authentication control unit may issue a JWT if it is authenticated that the maintenance personnel is legitimate and has both the maintenance authority.
  • the first transmission unit may transmit the JWT to the maintenance terminal.
  • the data receiving unit may receive the first data and the JWT from the maintenance terminal.
  • a server device is a server device that provides secure processing services on a first cloud, and includes a data receiving unit that receives first data to be installed in the currency processing device from an external device, a secure processing unit that performs secure processing on the first data to generate second data, and a transmitting unit that transmits the second data to an external device.
  • the data receiving unit may receive the first data from a maintenance terminal used for maintaining the currency processing device.
  • the transmitting unit may transmit the second data to the maintenance terminal.
  • a server device may further include an authentication information receiving unit that receives maintenance staff authentication information for authenticating a maintenance staff member performing maintenance on the currency processing device, and an authentication control unit that controls authentication of the maintenance staff using the maintenance staff authentication information and a first authentication service, and the secure processing unit may generate the second data if authentication of the maintenance staff is successful.
  • the maintenance staff may be a person who performs maintenance on the currency processing device using a maintenance terminal.
  • the authentication information receiving unit may receive the maintenance staff authentication information from the maintenance terminal.
  • the first authentication service may be provided on a second cloud different from the first cloud.
  • a server device may further include a key storage unit that stores a key, the secure processing unit performs the secure processing on the first data using the key, and the first authentication service may be an authentication service that uses a maintenance personnel database managed within the second cloud.
  • the key may include a first key that is common to a second key managed by the currency processing device, and the secure processing may include an encryption process that performs encryption using the first key.
  • the key may include a third key that pairs with a fourth key managed by the currency processing device
  • the secure processing may include an electronic signature process that generates an electronic signature for the first data using the third key
  • the second data may include the electronic signature
  • the authentication information receiving unit may further receive administrator authentication information for authenticating an administrator who manages the keys, and the authentication control unit may control authentication of the administrator using the administrator authentication information and a second authentication service.
  • the administrator may be a person who manages the keys using a management terminal.
  • the authentication information receiving unit may receive the administrator authentication information from the management terminal.
  • the second authentication service may be an authentication service that uses an administrator database managed within the second cloud.
  • the maintenance staff authentication information and the administrator authentication information may include first authentication information.
  • the first authentication information included in the maintenance staff authentication information is information that identifies the maintenance staff.
  • the first authentication information included in the administrator authentication information is information that identifies the administrator.
  • the authentication control unit when the authentication control unit determines to use the second authentication service for authentication, the authentication control unit may use the first authentication information included in the administrator authentication information and the second authentication service to control authentication of whether the administrator has key management authority.
  • the maintenance staff authentication information may further include second authentication information that identifies the maintenance staff and is different from the first authentication information, and when the authentication control unit determines to use the first authentication service for authentication, the authentication control unit may use the second authentication information and the first authentication service to control authentication of whether the maintenance staff has maintenance authority for the currency processing device.
  • the maintenance personnel authentication information may further include third authentication information that identifies the maintenance personnel and is different from the first authentication information and the second authentication information, and the authentication control unit may further control authentication of the legitimacy of the maintenance personnel using the third authentication information.
  • the second authentication information may be information that identifies a hardware key possessed by the maintenance personnel.
  • the third authentication information may be a one-time password based on a hardware key possessed by the maintenance personnel.
  • the authentication control unit may issue a JWT (JSON Web Token) if the maintenance personnel is authenticated, and the first transmission unit may transmit the JWT to an external device.
  • the data receiving unit may receive the first data and the JWT from an external device, and the secure processing unit may determine whether or not to execute the secure processing on the first data based on the JWT.
  • the authentication control unit may issue a JWT if it is authenticated that the maintenance personnel is legitimate and has at least one of the maintenance authority.
  • the authentication control unit may issue a JWT if it is authenticated that the maintenance personnel is legitimate and has both the maintenance authority.
  • the first transmission unit may transmit the JWT to the maintenance terminal.
  • the data receiving unit may receive the first data and the JWT from the maintenance terminal.
  • An installation method is an installation method executed in a currency processing device that processes currency, and includes a receiving step in which a server device that provides a secure processing service on a first cloud receives second data resulting from secure processing of first data; a decrypting step in which the second data is decrypted into the first data; and an installing step in which the decrypted first data is installed in the currency processing device.
  • the first data may be data to be installed in the currency processing device.
  • the receiving step may receive the second data via a maintenance terminal.
  • the maintenance terminal may transmit the first data to the server device.
  • a secure method is a secure method executed by a server device that provides a secure processing service on a first cloud, and includes a data receiving step of receiving first data to be installed in the currency processing device, a secure processing step of performing secure processing on the first data to generate second data, and a transmission step of transmitting the second data to the maintenance terminal.
  • the data receiving step may receive the first data from a maintenance terminal used for maintaining the currency processing device.
  • the transmission step may transmit the second data to the maintenance terminal.
  • a program is a program executed by a currency processing device that processes currency, and causes a computer of the currency processing device to execute the following steps: a receiving step in which a server device that provides a secure processing service on a first cloud receives second data obtained by performing secure processing on first data; a decrypting step in which the second data is decrypted into the first data; and an installing step in which the decrypted first data is installed in the currency processing device.
  • the first data may be data to be installed in the currency processing device.
  • the receiving step may receive the second data via a maintenance terminal.
  • the maintenance terminal may transmit the first data to the server device.
  • a program is a program executed on a server device that provides a secure processing service on a first cloud, and causes a computer of the server device to execute a data reception step of receiving first data to be installed in the currency processing device from an external device, a secure processing step of performing secure processing on the first data to generate second data, and a transmission step of transmitting the second data to an external device.
  • the data reception step may receive the first data from a maintenance terminal used for maintaining the currency processing device.
  • the transmission step may transmit the second data to the maintenance terminal.
  • FIG. 1 is a block diagram showing an example of the configuration of a system according to this embodiment.
  • FIG. 2 is a block diagram showing an example of the hardware configuration of the maintenance terminal of this embodiment.
  • FIG. 3 is a block diagram showing an example of the hardware configuration of the server device of this embodiment.
  • FIG. 4 is a schematic diagram showing an example of the mechanical configuration of the currency handling apparatus of this embodiment.
  • FIG. 5 is a block diagram showing an example of the hardware configuration of the main board of this embodiment.
  • Figure 6 is a block diagram showing an example of the functional configuration of the maintenance terminal, server device, and currency processing device of this embodiment.
  • FIG. 7 is a sequence diagram showing an example of a maintenance personnel authentication process performed in the system of this embodiment.
  • FIG. 1 is a block diagram showing an example of the configuration of a system according to this embodiment.
  • FIG. 2 is a block diagram showing an example of the hardware configuration of the maintenance terminal of this embodiment.
  • FIG. 3 is a block diagram showing an example of the hardware configuration of the server
  • FIG. 8 is a flowchart showing an example of the authority authentication process for the maintenance personnel and the first manager performed in the system of this embodiment.
  • FIG. 9 is a diagram illustrating an example of information stored in the authentication destination DB of this embodiment.
  • FIG. 10 is a diagram illustrating an example of information stored in the maintenance personnel DB of this embodiment.
  • FIG. 11 is a diagram illustrating an example of information stored in the administrator DB of this embodiment.
  • FIG. 12 is a sequence diagram showing an example of an installation process performed in the system of this embodiment.
  • FIG. 13 is a diagram showing an example of installation data generated by the data generating unit of this embodiment.
  • FIG. 14 is a diagram showing an example of information stored in the key storage unit of this embodiment.
  • the system of this embodiment enhances security in the process of installing data in currency processing devices.
  • the secure processing function that performs secure processing on data installed in the currency processing device is cloud-based.
  • the keys used for secure processing can be managed on the cloud, which not only increases the security (e.g., confidentiality and integrity) of the installed data itself, but also prevents key theft and loss of keys by maintenance personnel who generate the installed data.
  • the secure processing will be described as an example of encryption processing and electronic signature processing. However, secure processing is not limited to these, and may be either encryption processing or electronic signature processing.
  • the authorization authentication function which authenticates maintenance authority for the currency processing device, such as installing data on the currency processing device, is also cloud-based and realized as a cloud service separate from the secure processing function.
  • the keys used for secure processing and the information used for authorization authentication can be managed in separate cloud environments, preventing unauthorized installation on the currency processing device by unauthorized parties while increasing the robustness of the system against leaks of the above keys and information.
  • FIG. 1 is a block diagram showing an example of the configuration of system 1 of this embodiment.
  • system 1 includes a maintenance terminal 10, a hardware key 20, a first management terminal 30, a first cloud 40, a second cloud 60, a second management terminal 70, and a currency processing device 80.
  • the maintenance terminal 10 is a terminal device used by maintenance personnel when maintaining the currency processing device 80, and may be, for example, a PC (Personal Computer) with a maintenance program installed.
  • the maintenance terminal 10 may be connected to the currency processing device 80 via a network such as a LAN (Local Area Network), or may be directly connected to the currency processing device 80 via a communication cable or the like.
  • the maintenance terminal 10 is also connected to the first cloud 40 via a public network such as the Internet.
  • maintenance software based on the maintenance program can be executed.
  • the maintenance software is used to generate and read data to be installed on the currency processing device 80.
  • the maintenance software is also used to request authentication from the first cloud 40 as to whether or not the maintenance staff has the authority to maintain the currency processing device, such as installing data on the currency processing device 80.
  • the maintenance software is also used to request the first cloud 40 to perform secure processing on the data to be installed on the currency processing device 80.
  • the maintenance software is also used to send the securely processed installation data to the currency processing device 80.
  • the hardware key 20 is a hardware device used to control the use of maintenance software.
  • a hardware key 20 is distributed to each maintenance technician, and when the maintenance technician connects their own hardware key 20 to the maintenance terminal 10 and is successfully authenticated, the maintenance software becomes available for use.
  • the hardware key 20 is described as a dongle in USB (Universal Serial Bus) memory format, but the hardware key 20 is not limited to USB memory format, nor is it limited to a dongle.
  • the hardware key 20 may be, for example, a smart card (IC card), an HSM (Hardware Security Module), or a security token.
  • the first management terminal 30 is a terminal device, such as a PC, used by the first administrator to manage keys used in the secure processing service provided as a cloud service by the first cloud 40.
  • the first management terminal 30 is connected to the first cloud 40 via a public network such as the Internet.
  • the first management terminal 30 is used to request authentication from the first cloud 40 as to whether the first administrator has the authority to manage keys.
  • the first management terminal 30 is also used by the first administrator to access the first cloud 40 and register, modify, and delete various keys managed by the first cloud 40.
  • the first cloud 40 is a cloud service that provides secure processing services.
  • the first cloud 40 includes a firewall 41, an authentication destination DB (DataBase) 43, and a server device 50.
  • the server device 50 is connected to the firewall 41 and the authentication destination DB 43 via a network such as a LAN.
  • the first cloud 40 (server device 50) is also connected to the second cloud 60 via a public network such as the Internet.
  • the firewall 41 is used to prevent unauthorized access to the first cloud 40, and may be, for example, a network device such as a router or a dedicated firewall device.
  • the firewall 41 filters access from external environments, including, for example, the maintenance terminal 10 and the first management terminal 30.
  • the authentication destination DB 43 is a database used to determine which of the multiple authentication services provided as cloud services by the second cloud 60 should be used to process an authentication request made to the first cloud 40.
  • the server device 50 is used to provide secure processing services on the first cloud 40, and may be a server computer or the like.
  • the server device 50 may be realized by a single computer or multiple computers.
  • the server device 50 controls authentication requests to the first cloud 40 from the maintenance terminal 10 and the first management terminal 30. For example, the server device 50 authenticates the legitimacy of the maintenance personnel itself. Also, for example, when authenticating permissions such as the first administrator's key management authority or the maintenance personnel's maintenance authority, the server device 50 refers to the authentication destination DB 43 and determines an authentication service to process the authentication from among multiple authentication services provided by the second cloud 60. Once the server device 50 determines the authentication service to process the authentication, it performs the authentication process using that authentication service.
  • the server device 50 also stores a key for performing secure processing on the installation data transmitted from the maintenance terminal 10.
  • the secure processing involves, for example, encryption and digital signature processing being performed on the installation data, so the server device 50 stores a key for the encryption processing and a key for the digital signature processing.
  • the secure processing may be processing other than encryption and digital signature processing, or may be either encryption or digital signature processing, so the server device 50 only needs to store a key appropriate for the secure processing.
  • any encryption method may be used for encryption processing and electronic signature processing
  • this embodiment will be described using an example in which a common key encryption method is used for encryption processing and a public key encryption method is used for electronic signature processing.
  • the server device 50 stores a common key as the key for encryption processing and a private key as the key for electronic signature processing, but the keys stored by the server device 50 are not limited to these.
  • the server device 50 When the server device 50 receives the installation data from the maintenance terminal 10, it performs secure processing using a stored key. Specifically, the server device 50 encrypts the installation data using a stored common key. The server device 50 also calculates a hash value from the installation data using a hash function, encrypts the hash value using a stored private key, and generates a digital signature for the installation data.
  • the server device 50 transmits the installation data that has undergone secure processing to the maintenance terminal 10. Specifically, the server device 50 attaches the generated digital signature to the encrypted installation data and transmits it to the maintenance terminal 10.
  • the second cloud 60 is a cloud service that provides multiple authentication services.
  • the second cloud 60 includes a firewall 61, a maintenance staff DB 63, an administrator DB 65, and an administrator authentication device 67.
  • the firewall 61 and the maintenance staff DB 63 are connected via a network such as a LAN
  • the administrator DB 65 and the administrator authentication device 67 are connected via a network such as a LAN.
  • the firewall 61 is used to prevent unauthorized access to the maintenance staff DB 63, and may be, for example, a network device such as a router or a dedicated firewall device.
  • the firewall 61 filters access from external environments, including, for example, the server device 50 of the first cloud 40.
  • the maintenance staff DB 63 is a database that manages maintenance staff and their maintenance authority. As one of its authentication services, the second cloud 60 provides a maintenance staff authentication service that allows an authentication source outside the second cloud 60 to use the maintenance staff DB 63. For example, when the server device 50 of the first cloud 40 processes an authentication request from the maintenance terminal 10 using the maintenance staff authentication service of the second cloud 60, it accesses the maintenance staff DB 63 via the firewall 61 and authenticates the maintenance staff's maintenance authority.
  • Administrator DB65 is a database that manages first administrators and their key management authority. Administrator authentication device 67 uses administrator DB65 to authenticate the first administrator's key management authority, and may be, for example, one or more computers used as servers.
  • the second cloud 60 provides a first administrator authentication service by an administrator authentication device 67 using an administrator DB 65.
  • the server device 50 of the first cloud 40 processes an authentication request from the first management terminal 30 using the first administrator authentication service of the second cloud 60, it sends the authentication request to the administrator authentication device 67 and receives the authentication result from the administrator authentication device 67.
  • the second management terminal 70 is a terminal device, such as a PC, used by the second administrator to manage the maintenance staff DB 63 and administrator DB 65 included in the second cloud 60.
  • the second management terminal 70 is connected to the second cloud 60 via a public network such as the Internet.
  • the second management terminal 70 is used to access the second cloud 60 and register maintenance staff managed in the maintenance staff DB 63, modify and delete maintenance authority, etc.
  • the second management terminal 70 is also used to access the second cloud 60 and register first administrators managed in the administrator DB 65, modify and delete key management authority, etc.
  • the second management terminal 70 may be the same terminal device as the first management terminal 30.
  • the currency processing device 80 processes currency, taking in currency and performing various processes related to the taken-in currency.
  • Currency includes at least one of banknotes and coins, but is not limited to these.
  • Currency may also include various types of securities such as checks, gift certificates, or stock certificates.
  • Various processes related to currency include, but are not limited to, identification processes that identify and process the currency's denomination, authenticity, fitness, etc.
  • Currency identification processes typically use identification data (configuration files) that define thresholds for identifying the denomination, authenticity, fitness, etc. for each currency type.
  • the currency processing device 80 When the currency processing device 80 receives securely processed installation data from the maintenance terminal 10, it decrypts the installation data.
  • the currency processing device 80 manages a common key that is shared with the common key for encryption processing stored in the server device 50, and a public key that pairs with the private key for electronic signature processing stored in the server device 50. Therefore, the currency processing device 80 extracts the electronic signature from the securely processed installation data and decrypts the hash value using the public key.
  • the currency processing device 80 also uses the common key to decrypt the installation data (plain text) from the securely processed installation data.
  • the currency processing device 80 also uses a hash function to calculate a hash value from the decrypted installation data and determines whether it matches the decrypted hash value. If the two hash values match and the integrity of the installation data is guaranteed, the currency processing device 80 installs the decrypted installation data, updating the identification data (configuration file) used in the currency processing device 80.
  • Figure 1 illustrates an example in which the maintenance terminal 10 and currency processing device 80 are located at site A, the first management terminal 30 is located at site B, and the second management terminal 70 is located at site C.
  • the location of each terminal and device is not limited to this.
  • the first management terminal 30 and the second management terminal 70 may be located at the same site.
  • Examples of site A include, but are not limited to, at least one of various stores such as banks and retail outlets where currency handling devices 80 are used, and public facilities such as train stations.
  • Examples of site B include, but are not limited to, a branch office or sales office of the manufacturer of currency handling devices 80 that manages maintenance of currency handling devices 80.
  • Examples of site C include, but are not limited to, a site where the manufacturer's system management office is located, such as the head office of the manufacturer of currency handling devices 80.
  • Examples of maintenance personnel include, but are not limited to, employees of contractors contracted to perform maintenance work by the manufacturer of currency handling equipment 80, and employees of the manufacturer of currency handling equipment 80.
  • Examples of first managers include, but are not limited to, employees of the manufacturer of currency handling equipment 80 who are responsible for maintenance management work for currency handling equipment 80 or employees who have been granted maintenance management authority.
  • Examples of second managers include, but are not limited to, employees assigned to the system management office of the manufacturer of currency handling equipment 80.
  • the second cloud 60 may be a cloud service newly developed for the system 1, or it may be a cloud service with functions such as a directory service that the manufacturer of the currency processing device 80 already had for purposes such as employee management.
  • a cloud service By using an existing cloud service in the latter case, the development costs and running costs of the system 1 can be reduced.
  • FIG. 2 is a block diagram showing an example of the hardware configuration of the maintenance terminal 10 of this embodiment.
  • the maintenance terminal 10 includes a control device 11, a main memory device 12, an auxiliary memory device 13, a display device 14, an input device 15, a communication device 16, a reader device 17, and various buses 18.
  • the control device 11, main memory device 12, auxiliary memory device 13, display device 14, input device 15, communication device 16, and reader device 17 are connected via the various buses 18.
  • the maintenance terminal 10 of this embodiment has a general hardware configuration that utilizes a normal computer.
  • the control device 11 controls the overall operation of the maintenance terminal 10.
  • Examples of the control device 11 include at least one of a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit), but are not limited to these. There may be any number of CPUs or GPUs, as long as there is one or more, and they may be single-core or multi-core.
  • the main memory device 12 may be, for example, a ROM (Read Only Memory) or a RAM (Random Access Memory), but is not limited to these.
  • the ROM stores various programs, such as a program for controlling the maintenance terminal 10 and the maintenance program of this embodiment.
  • the RAM is used as a working area when the control device 11 performs various controls based on the programs stored in the ROM.
  • the auxiliary storage device 13 stores the various programs and data described above.
  • the various programs described above may be stored in at least one of the main storage device 12 and the auxiliary storage device 13.
  • Examples of the auxiliary storage device 13 include, but are not limited to, existing storage devices capable of magnetic, electrical, or optical storage, such as HDDs (Hard Disk Drives), SSDs (Solid State Drives), and DVDs (Digital Versatile Discs).
  • the auxiliary storage device 13 may be built into the maintenance terminal 10 or may be externally attached to the maintenance terminal 10 via an interface such as a USB (Universal Serial Bus).
  • the auxiliary storage device 13 may also be a NAS (Network Attached Storage) connected via a network such as a LAN or WAN (Wide Area Network).
  • the display device 14 displays various screens when using the maintenance software, and serves as a user interface with the user (maintenance personnel). Examples of the display device 14 include, but are not limited to, various displays such as a liquid crystal display, an organic electro-luminescence (EL) display, and a touch panel display.
  • the display device 14 may be an internal display built into the maintenance terminal 10, or an external display connected to the maintenance terminal 10 via a display interface such as HDMI (registered trademark).
  • the input device 15 is used for various inputs when using the maintenance software, and serves as a user interface with the user (maintenance personnel). Examples of the input device 15 include, but are not limited to, a keyboard, mouse, and touch panel.
  • the input device 15 may be built into the maintenance terminal 10, or may be externally connected to the maintenance terminal 10 via an interface such as USB.
  • the communication device 16 may be, for example, a communication device for a wired LAN or a wireless communication device for a wireless LAN, but is not limited to these.
  • the communication device 16 may also be used to obtain the maintenance program and data of this embodiment from an external source.
  • the reader device 17 may be, for example, a device that reads data from an external device connected to a port such as a USB port, but is not limited to this. In this embodiment, the reader device 17 is used to read information from the hardware key 20.
  • the maintenance terminal 10 may further include hardwired circuits such as an IC (Integrated Circuit), an ASIC (Application Specific Integrated Circuit), and an FPGA (Field-Programmable Gate Array) that are specific to the maintenance terminal 10.
  • hardwired circuits such as an IC (Integrated Circuit), an ASIC (Application Specific Integrated Circuit), and an FPGA (Field-Programmable Gate Array) that are specific to the maintenance terminal 10.
  • FIG. 3 is a block diagram showing an example of the hardware configuration of the server device 50 of this embodiment.
  • the server device 50 includes a control device 51, a main memory device 52, an auxiliary memory device 53, a communication device 56, and various buses 58.
  • the control device 51, the main memory device 52, the auxiliary memory device 53, and the communication device 56 are connected via the various buses 58.
  • the server device 50 of this embodiment has a general hardware configuration that utilizes a typical computer.
  • the control device 51 controls the overall operation of the server device 50.
  • the implementation method of the control device 51 is similar to that of the control device 11, so a detailed explanation will be omitted.
  • the ROM of the main memory device 52 stores various programs, such as programs for controlling the server device 50, as well as programs for performing secure processing and programs for controlling authentication processing.
  • the implementation method for the main memory device 52 is the same as that for the main memory device 12, so a detailed explanation will be omitted.
  • the auxiliary storage device 53 stores the various programs and data described above.
  • the various programs described above may be stored in at least one of the main storage device 52 and the auxiliary storage device 53.
  • the method for implementing the auxiliary storage device 53 is the same as that for the auxiliary storage device 13, so a detailed explanation will be omitted.
  • the implementation method for communication device 56 is the same as that for communication device 16, so a detailed explanation will be omitted.
  • the server device 50 may also be equipped with hardwired circuits such as ICs, ASICs, and FPGAs specific to the server device 50.
  • Figure 4 is a schematic diagram showing an example of the mechanical configuration of the currency handling device 80 of this embodiment.
  • the side on which the first door 823 (described below) is provided may be referred to as the front, and the side opposite the side on which the first door 823 is provided may be referred to as the rear.
  • the currency handling device 80 performs processing on loose banknotes.
  • the currency handling device 80 has an upper processing unit 81 and a lower safe 82.
  • the safe 82 has a first safe unit 821 and a second safe unit 822.
  • the processing unit 81 has an upper housing 811. Inside the upper housing 811, a deposit unit 812, a withdrawal unit 813, a recognition unit 814, and part of the transport path are arranged.
  • safe 82 The interior of safe 82 is divided into two areas. Inside safe 82, there is a storage section 83, part of the transport path, and a main board 855, which will be described later. Safe 82 protects the storage section 83 and main board 855 at a security level above a predetermined level. The security level of safe 82 is higher than that of upper housing 811.
  • the safe 82 has a first door 823 and a second door 824.
  • the first door 823 is equipped with an electronic lock 825.
  • the electronic lock 825 is normally locked.
  • the first manager unlocks the electronic lock 825, the first door 823 can be opened.
  • the storage section 83 of the first safe section 821 can be pulled out to the front of the currency handling device 80.
  • the second door 824 is provided with an electronic lock 826.
  • the electronic lock 826 is normally locked.
  • the first manager unlocks the electronic lock 826
  • the second door 824 can be opened.
  • the storage section 83 of the second safe section 822 can be pulled out to the front of the currency handling device 80.
  • a first administrator with special authority can unlock electronic lock 825 and electronic lock 826.
  • the authority required to unlock electronic lock 825 does not have to be the same as the authority required to unlock electronic lock 826.
  • the deposit unit 812 is the section into which banknotes to be deposited are inserted, for example, during a deposit process in which banknotes are deposited into a storage unit described below.
  • the deposit unit 812 holds multiple banknotes in a stacked state.
  • the deposit unit 812 has a mechanism for taking banknotes into the device one by one.
  • the dispensing unit 813 is a unit that holds the banknotes to be dispensed, for example, during a dispensing process in which banknotes are dispensed from a storage unit described below.
  • the dispensing unit 813 holds multiple banknotes in a stacked state.
  • a user of the currency handling device 80 can manually remove banknotes from the dispensing unit 813.
  • users of the currency handling device 80 include not only the first manager, but also general users such as maintenance personnel and customers of the store where the currency handling device 80 is installed.
  • the recognition unit 814 is provided on the loop conveying path 841, which will be described later.
  • the recognition unit 814 detects banknotes conveyed along the loop conveying path 841.
  • the recognition unit 814 acquires an image of each detected banknote.
  • the recognition unit 814 uses the acquired images to identify at least whether the banknote is genuine, counterfeit, denomination, and fitness.
  • the recognition unit 814 acquires the serial number of the banknote.
  • the storage unit 83 stores banknotes.
  • the storage unit 83 stores banknotes, for example, in a stack format (where banknotes are stacked) or a tape format (where banknotes are wound up with tape).
  • the multiple storage sections 83 are each provided inside the first safe section 821 or the second safe section 822.
  • the multiple storage sections 83 may include storage cassettes that are detachable from the currency handling device 80.
  • At least one of the storage sections 83 provided in the first safe section 821 is supported by a support section 827.
  • the support section 827 has, for example, a rail structure, and can move forward while supporting the storage section 83 when the first door 823 is open. This allows the storage section 83 of the first safe section 821 to be pulled out toward the front of the currency handling device 80.
  • a sensor that detects the passage of banknotes is attached to the banknote entrance/exit of storage unit 83. Based on the detection signal from the sensor, storage unit board 854, which will be described later, counts the number of banknotes that have entered storage unit 83 and the number of banknotes that have left storage unit 83. Based on the counted number, storage unit board 854 manages the number of banknotes stored in storage unit 83.
  • the transport unit 84 transports banknotes within the currency handling device 80.
  • the transport unit 84 has a transport path. Although not shown in the figure, the transport path is made up of a combination of numerous rollers, multiple belts, motors that drive these, and multiple guides.
  • the transport unit 84 transports banknotes one by one along the transport path, for example, with the long edge of the banknote forward and leaving a gap between each banknote.
  • the transport unit 84 may also transport banknotes with the short edge forward.
  • the transport unit 84 has a loop transport path 841.
  • the loop transport path 841 is provided inside the upper housing 811.
  • the transport unit 84 transports banknotes along the loop transport path 841 in the clockwise and counterclockwise directions in FIG. 2.
  • the deposit unit 812 is connected to the loop conveying path 841 via a connection path 842.
  • the withdrawal unit 813 is connected to the loop conveying path 841 via a connection path 843.
  • Each storage unit 83 is connected to the loop conveying path 841 via a connecting path 844.
  • Each connecting path 844 extends vertically across the processing unit 81 and the first safe unit 821. A portion of the connecting path 844 extends vertically across the processing unit 81, the first safe unit 821, and the second safe unit 822.
  • the conveying unit 84 conveys banknotes from the loop conveying path 841 to each storage unit 83 via the connecting path 844.
  • the conveying unit 84 conveys banknotes from each storage unit 83 to the loop conveying path 841 via the connecting path 844.
  • the upper housing 811 is provided with a temporary holding section 86.
  • the temporary holding section 86 temporarily stores banknotes.
  • the temporary holding section 86 can be used for a variety of purposes.
  • the temporary holding section 86 is disposed at a front position within the upper housing 811.
  • the temporary holding section 86 is connected to the loop conveying path 841 via a connection path 845.
  • An external safe storage unit 840 can be attached to the currency handling device 80.
  • the external safe storage unit 840 can be removed from the currency handling device 80.
  • the external safe storage unit 840 is a removable storage unit.
  • the external safe storage unit 840 is connected to the loop transport path 841 via a connection path 846.
  • the currency handling device 80 comprises an identification board 851, an upper board 852, a lower board 853, a storage board 854, and a main board 855.
  • Each board comprises a memory device, a processor, and a communication interface.
  • the memory device is composed of semiconductor memory such as RAM, ROM, eMMC (embedded multi-media card), or SSD.
  • Various data and software are stored in the memory device.
  • the processor reads and executes various software from the memory device.
  • the communication interface communicates based on a specified communication standard such as USB or RS-422.
  • the main board 855 performs the security management function of the currency handling device 80.
  • the main board 855 has a distinctive hardware configuration to realize the security management function.
  • FIG. 5 is a block diagram showing an example of the hardware configuration of the main board 855 of this embodiment.
  • the main board 855 includes a processor 870, a storage device 871, a communication interface 872, and a security chip 880 (an example of a storage unit).
  • Processor 870 like the processors (microcomputers) on other boards, executes software in storage device 871.
  • Processor 870 has embedded therein code that can be executed by processor 870 itself (hereinafter referred to as internal code).
  • internal code code that can be executed by processor 870 itself
  • Processor 870 is configured so that the internal code cannot be changed. In other words, a third party cannot tamper with the internal code.
  • Processor 870 executes the internal code when processor 870 starts up.
  • the processor 870 is provided with a memory area 873 that stores predetermined information (digital data).
  • the memory area 873 is configured so that once data is written, the contents cannot be changed. It is impossible to tamper with the information in the memory area 873.
  • the manufacturer of the currency handling device 80 writes information to the memory area 873 before the currency handling device 80 is shipped (for example, when the currency handling device 80 is manufactured).
  • Security chip 880 is a tamper-resistant semiconductor device. Tamper resistance refers to the property of making it difficult for data recorded inside to be analyzed, read, or altered from the outside.
  • Security chip 880 can be a security chip (TPM: Trusted Platform Module) that complies with security specifications defined by the TCG (Trusted Computing Group).
  • Security chip 880 is provided with a storage device 881 that stores specified information (digital data).
  • the security chip 880 is connected to the processor 870 via the bus 856.
  • a specific authentication code is required for the processor 870 to access (write, read) the security chip 880.
  • the security chip 880 has the function of storing the aforementioned common key and public key.
  • the security chip 880 may also have the function of calculating hash values.
  • the storage device 881 may store data for authenticating software in the storage device 871.
  • the data for authenticating the software is, for example, a hash value of the software.
  • the memory device 871 has the same configuration as the memory devices provided on other boards.
  • the memory device 871 may be composed of multiple types of devices (e.g., eMMC and ROM).
  • the memory device 871 on the main board 855 includes an eMMC.
  • the memory device 871 stores basic software and application software.
  • the communication interface 872 has the same configuration as the communication interfaces provided on other boards.
  • the identification board 851 and upper board 852 are provided in the upper housing 811.
  • the identification board 851 controls the identification unit 814 and outputs the identification results by having the processor execute specified software. For example, the identification board 851 identifies the authenticity, denomination, and fitness of a banknote based on an image of the banknote.
  • the identification board 851 is connected to the upper board 852 via a communications interface.
  • the identification board 851 outputs the identification results to the upper board 852 via the communications interface.
  • the upper board 852 controls the operation of the deposit unit 812, withdrawal unit 813, transport unit 84, temporary holding unit 86, etc. by having the processor execute specified software.
  • the upper board 852 controls the drive mechanisms (motors) provided in the transport unit 84, etc.
  • the lower board 853, storage unit board 854, and main board 855 are provided within the safe 82. More specifically, the lower board 853 and main board 855 are provided within the first safe unit 821. In other words, the main board 855 is installed in a location where the electronic lock 825 needs to be unlocked.
  • the storage unit board 854 is provided in each of the storage units 83.
  • a storage unit board 854 is provided for each storage unit 83.
  • the memory device of each storage unit board 854 stores the ID and door opening/closing log of the corresponding storage unit 83. These memory devices may also store at least one of the type and number of banknotes stored.
  • the storage section board 854 is connected to the lower board 853 via a communication interface. In response to a request from the lower board 853, the storage section board 854 transmits ID and door opening/closing log information to the lower board 853 via the communication interface.
  • the lower board 853 controls each storage unit 83 and transport unit 84 by having the processor execute specific software.
  • the lower board 853 collects the IDs and log data of the storage units 83.
  • the lower substrate 853 is connected to the upper substrate 852 via a communication interface.
  • the lower substrate 853 sends a predetermined signal (command) to the upper substrate 852 via the communication interface.
  • the main board 855 is responsible for starting up the currency handling device 80, communicating with the outside world, and managing various software programs by having the processor execute specified software.
  • the memory device 871 of the main board 855 is equipped with basic software (OS: Operating System).
  • the main board 855 is located inside the first safe section 821, so third parties cannot access the main board 855. As a result, third parties cannot access the common key and public key stored in the security chip 880.
  • the main board 855 is connected to the lower board 853 via the communication interface 872.
  • Log data, update files, etc. are sent and received between the main board 855 and the lower board 853.
  • the main board 855 is connected to the identification board 851 via the communication interface 872.
  • the main board 855 transmits identification data to the identification board 851 and receives banknote image data from the identification board 851.
  • the identification data is data used to identify the authenticity, denomination, and fitness of banknotes.
  • the banknote image data is image data of banknotes acquired by the identification board 851.
  • the currency processing device 80 has a user interface (UI) unit (not shown).
  • the UI unit includes an operation unit (keyboard, trackball, touch panel, etc.). By operating the operation unit, the user can give various instructions to the currency processing device 80.
  • the upper board 852 receives user instructions via the UI unit, and if the instruction is not one that it can handle, it transfers the received instruction to the corresponding board.
  • the board that handles the instruction outputs a signal to at least one of the deposit unit 812, withdrawal unit 813, recognition unit 814, storage unit 83, transport unit 84, temporary holding unit 86, and external safe storage unit 840 to execute the process corresponding to the instruction.
  • FIG. 6 is a block diagram showing an example of the functional configuration of the maintenance terminal 10, server device 50, and currency processing device 80 of this embodiment.
  • the maintenance terminal 10 includes an authentication unit 101, a transmission unit 103 (an example of a second transmission unit), a reception unit 105, and a data generation unit 107.
  • the authentication unit 101, transmission unit 103, reception unit 105, and data generation unit 107 can be realized, for example, by the control device 11, main memory device 12, communication device 16, and reader device 17 described in FIG. 2.
  • the control device 11 reads the maintenance program of this embodiment stored in the main memory device 12 (ROM) or auxiliary memory device 13 and loads it into the main memory device 12 (RAM).
  • the control device 11 executes various processes in accordance with the loaded program, thereby implementing the above-mentioned functional units as maintenance software. Furthermore, at least one of the authentication unit 101, transmission unit 103, reception unit 105, and data generation unit 107 may be a dedicated circuit for executing various processes.
  • the server device 50 includes an authentication information receiving unit 501, an authentication control unit 503, a transmission unit 505 (an example of a first transmission unit), a data receiving unit 507, a secure processing unit 509, and a key storage unit 511.
  • the authentication information receiving unit 501, the authentication control unit 503, the transmission unit 505, the data receiving unit 507, and the secure processing unit 509 can be realized, for example, by the control device 51, main memory device 52, and communication device 56 described in FIG. 3.
  • the control device 51 reads out a program for performing the secure processing of this embodiment and a program for controlling the authentication processing stored in the main memory device 52 (ROM) or the auxiliary memory device 53, and expands them into the main memory device 52 (RAM).
  • the control device 51 realizes each of the above-mentioned functional units by executing various processes in accordance with the expanded programs.
  • the key storage unit 511 can be realized, for example, by the auxiliary memory device 53 described in FIG. 3.
  • At least one of the authentication information receiving unit 501, authentication control unit 503, transmission unit 505, data receiving unit 507, and secure processing unit 509 may be a dedicated circuit for performing various processes.
  • the currency handling device 80 includes a receiving unit 891, a decryption unit 893, an installation unit 895, and a currency identification unit 897.
  • the receiving unit 891, decryption unit 893, and installation unit 895 can be realized, for example, by the main board 855 described in FIG. 5, and the currency identification unit 897 can be realized, for example, by the identification board 851 described in FIG. 5.
  • the board realizes each of the above-mentioned functional units by executing a program stored on the board.
  • At least one of the receiving unit 891, decryption unit 893, and installation unit 895 may be a dedicated circuit for performing various processes.
  • Figure 7 is a sequence diagram showing an example of the maintenance personnel authentication process performed in system 1 of this embodiment.
  • the authentication unit 101 of the maintenance terminal 10 authenticates the legitimacy of the maintenance personnel using the hardware key 20, which is a dongle carried by the maintenance personnel (step S101).
  • the authentication of the maintenance personnel using the hardware key 20 is two-factor authentication, and the authentication unit 101 performs the first factor of authentication, but the authentication method for the maintenance personnel is not limited to this.
  • the hardware key 20 stores, for example, a password, a certificate for two-factor authentication, and a private key.
  • the certificate may include, for example, information that defines a dongle ID (identification) that identifies the hardware key 20 and a user ID that identifies the maintenance personnel carrying the hardware key 20.
  • a maintenance technician logs in to the maintenance terminal 10, connects the hardware key 20 to the maintenance terminal 10, starts up the maintenance software, and enters a password.
  • the authentication unit 101 accepts the password entered by the maintenance technician, reads the password stored in the hardware key 20 connected to the maintenance terminal 10, and compares the two passwords. If the password comparison is successful, the authentication unit 101 determines that the first element of authentication of the maintenance technician's legitimacy has been successful; if the password comparison is unsuccessful, it determines that authentication of the maintenance technician has failed.
  • the first element of authentication is not limited to the password matching described above.
  • the person possessing the hardware key 20 may be considered to be a legitimate maintenance worker, and the authentication unit 101 may determine that the first element of authentication has been successful when the hardware key 20 is connected to the maintenance terminal 10.
  • the transmission unit 103 of the maintenance terminal 10 transmits maintenance staff authentication information to the server device 50 to authenticate the maintenance staff who will be using the maintenance terminal 10 to perform maintenance on the currency handling device 80 (step S103). Note that if authentication of the maintenance staff fails in step S101, the processing from step S103 onwards is not performed.
  • the maintenance staff authentication information includes at least the certificate stored in the hardware key 20.
  • the maintenance staff authentication information since the second element of authentication is performed using a challenge-response method, the maintenance staff authentication information also includes a one-time password based on the hardware key 20, but is not limited to this.
  • the maintenance personnel authentication information includes the maintenance personnel's user ID, the dongle ID of the hardware key 20 held by the maintenance personnel, and a one-time password based on the hardware key 20 held by the maintenance personnel.
  • the maintenance personnel's user ID, the dongle ID of the hardware key 20, and the one-time password based on the hardware key 20 are all information that identifies the maintenance personnel, but are different from each other.
  • the maintenance personnel's user ID is an example of first authentication information
  • the dongle ID of the hardware key 20 is an example of second authentication information
  • the one-time password based on the hardware key 20 is an example of third authentication information.
  • the transmission unit 103 requests a challenge from the server device 50 before transmitting the maintenance personnel authentication information.
  • the authentication information reception unit 501 of the server device 50 receives the challenge request from the maintenance terminal 10, the authentication control unit 503 of the server device 50 generates the challenge, and the transmission unit 505 of the server device 50 transmits the generated challenge to the maintenance terminal 10.
  • the reception unit 105 of the maintenance terminal 10 receives the challenge from the server device 50.
  • the transmission unit 103 of the maintenance terminal 10 uses a hash function to calculate a hash value of the challenge received from the server device 50, and encrypts the hash value using the private key stored in the hardware key 20.
  • the hash value of the challenge is an example of a one-time password based on the hardware key 20.
  • the transmission unit 103 generates maintenance staff authentication information including the encrypted hash value of the challenge and the certificate stored in the hardware key 20, and transmits it to the server device 50.
  • the authentication information receiving unit 501 of the server device 50 receives the maintenance staff authentication information from the maintenance terminal 10 (step S103).
  • the authentication control unit 503 of the server device 50 obtains the hash value of the encrypted challenge from the received maintenance staff authentication information, and controls authentication of the legitimacy of the maintenance staff using the hash value of the encrypted challenge (step S105).
  • the authentication control unit 503 decrypts the hash value of the encrypted challenge using the public key that is paired with the private key stored in the hardware key 20.
  • the public key is stored in the key storage unit 511 (described below) in association with, for example, the dongle ID, and therefore the authentication control unit 503 can obtain the public key from the key storage unit 511 using the dongle ID as a key.
  • the authentication control unit 503 also calculates a hash value of the generated challenge using a hash function and compares it with the decrypted hash value. If the hash value comparison is successful, the authentication control unit 503 determines that the second element of authentication of the maintenance personnel's legitimacy has been successful; if the hash value comparison is unsuccessful, the authentication control unit 503 determines that the authentication of the maintenance personnel has failed.
  • the authentication control unit 503 may also perform a second factor of authentication of the maintenance personnel by taking into account factors such as whether the comparison was performed within the validity period of the hash values and the validity of the certificate included in the maintenance personnel authentication information.
  • the authentication control unit 503 also controls the authentication of maintenance personnel using the maintenance personnel authentication information and a first authentication service provided on a second cloud 60 that is different from the first cloud 40.
  • the first authentication service is, for example, an authentication service that uses a maintenance personnel DB 63 managed within the second cloud 60, and the authentication control unit 503 controls the authentication of whether or not the maintenance personnel has maintenance authority for the currency processing device 80.
  • the authentication information receiving unit 501 also receives administrator authentication information for authenticating the first administrator (an example of an administrator) using the first management terminal 30, which is used to manage the keys stored in the key storage unit 511 (described below), from the first management terminal 30.
  • the authentication control unit 503 controls the authentication process for the first administrator using the administrator authentication information and a second authentication service provided on the second cloud 60.
  • the administrator authentication information includes at least a user ID that identifies the first administrator.
  • the user ID of the first administrator is an example of first authentication information.
  • the second authentication service is, for example, an authentication service that uses an administrator DB 65 managed within the second cloud 60, and the authentication control unit 503 controls authentication to determine whether the first administrator has key management authority.
  • the authentication control unit 503 If the authentication control unit 503 successfully authenticates the legitimacy of the maintenance personnel in step S105, it controls authentication to determine whether the maintenance personnel has maintenance authority over the currency processing device 80 (step S107). Note that if authentication of the maintenance personnel fails in step S105, processing from step S107 onwards is not performed. Furthermore, the authentication control to determine whether the maintenance personnel has maintenance authority shares much in common with the authentication control to determine whether the first administrator has key management authority, and therefore will be explained together using the flowchart shown in Figure 8.
  • FIG. 8 is a flowchart showing an example of the authorization authentication process for the maintenance personnel and the first administrator performed in system 1 of this embodiment.
  • the authentication control unit 503 determines whether the first authentication service or the second authentication service will be used for authentication based on the user ID included in the maintenance staff authentication information or the administrator authentication information. Specifically, the authentication control unit 503 references the user ID and the authentication destination DB 43 to determine whether the first authentication service or the second authentication service will be used for authentication. The authentication control unit 503 may also determine whether the first authentication service or the second authentication service will be used for authentication based on the sender of the authentication information. Specifically, the authentication control unit 503 may use the first authentication service if the sender of the authentication information is the maintenance terminal 10 or maintenance software, and may use the second authentication service if the sender of the authentication information is the first management terminal 30 or management software running on the first management terminal 30.
  • FIG. 9 is a diagram showing an example of information stored in the authentication destination DB 43 of this embodiment.
  • the authentication destination DB 43 stores user IDs in association with authentication destination information.
  • the user ID indicating the first administrator is associated with the administrator DB 65 as authentication destination information
  • the user ID indicating the maintenance staff is associated with the maintenance staff DB 63 as authentication destination information.
  • the authentication control unit 503 uses the user ID as a key to obtain authentication destination information associated with the user ID from the authentication destination DB 43 (step S201).
  • the authentication control unit 503 determines to use an authentication service that uses the DB indicated by the obtained authentication destination information for authentication. Specifically, if the obtained authentication destination information indicates the maintenance staff DB 63 (Yes in step S203), the authentication control unit 503 determines to use the first authentication service (step S205). Therefore, in step S107 of the sequence diagram shown in FIG. 7, the authentication control unit 503 determines to use the first authentication service for authentication of the maintenance staff's maintenance authority using the maintenance staff authentication information.
  • the authentication control unit 503 uses the dongle ID (more specifically, the dongle ID defined in the certificate) included in the maintenance staff authentication information and the first authentication service to control authentication of whether the maintenance staff has maintenance authority over the currency processing device 80. Specifically, the authentication control unit 503 references the dongle ID and the maintenance staff DB 63 to authenticate the maintenance staff's maintenance authority over the currency processing device 80.
  • FIG 10 is a diagram showing an example of information stored in the maintenance staff DB 63 of this embodiment.
  • the maintenance staff DB 63 stores a user ID, a dongle ID, and the device ID of a currency processing device for which the maintenance staff has maintenance authority, in association with each other.
  • the device ID "currency processing device A" indicates currency processing device 80.
  • the authentication control unit 503 uses the dongle ID as a key to obtain the device ID associated with the dongle ID from the maintenance staff DB 63, and authenticates whether or not the maintenance staff has maintenance authority for the currency processing device indicated by the device ID (step S207). Therefore, in the example shown in Figure 10, if the dongle ID indicates maintenance staff A, the authentication control unit 503 obtains the device ID "currency processing device A" indicating the currency processing device 80, and therefore authenticates that maintenance staff A has maintenance authority for the currency processing device 80.
  • the authentication control unit 503 obtains the device ID "currency processing device B" indicating a currency processing device 80 other than the currency processing device 80, and therefore authenticates that maintenance staff B does not have maintenance authority for the currency processing device 80. Note that in step S107 of the sequence diagram shown in Figure 7, the dongle ID indicates maintenance staff A, and therefore the authentication control unit 503 authenticates that maintenance staff A has maintenance authority for the currency processing device 80.
  • the maintenance authority of maintenance personnel is set on a device-by-device basis, but this is not limited to this, and maintenance authority may also be set on a device-by-device function basis.
  • the maintenance authority of maintenance personnel can be flexibly set, such as by granting authority to perform simple maintenance on currency processing devices to a wide range of maintenance personnel, and granting authority to perform important maintenance such as installation to a limited number of maintenance personnel.
  • a dongle ID is used to authenticate maintenance authority, but this is not limited to this, and a user ID may also be used. Note that the dongle ID is stored in the hardware key 20 and is less likely to be seen by others, so it is more confidential than a user ID and therefore provides higher security.
  • the authentication control unit 503 decides to use the second authentication service (step S209). Therefore, in this embodiment, the authentication control unit 503 decides to use the second authentication service for authentication of the first administrator's key management authority using the administrator authentication information.
  • the authentication control unit 503 decides to use the second authentication service for authentication, it uses the user ID and second authentication service included in the administrator authentication information to control authentication of whether the first administrator has key management authority. Specifically, the authentication control unit 503 notifies the administrator authentication device 67 of the user ID and obtains the authentication result of the first administrator's key management authority, which the administrator authentication device 67 performs using the administrator DB 65.
  • FIG. 11 is a diagram showing an example of information stored in the administrator DB 65 of this embodiment. As shown in FIG. 11, the administrator DB 65 stores user IDs and key management authority information in association with each other.
  • the authentication control unit 503 notifies the administrator authentication device 67 of the user ID (step S211).
  • the administrator authentication device 67 uses the user ID notified by the authentication control unit 503 as a key to obtain key management authority information associated with the user ID from the administrator DB 65, authenticates the first administrator's key management authority (step S213), and notifies the authentication control unit 503 of the authentication result (step S215). Therefore, in the example shown in FIG. 11, when the user ID indicates administrator A, key management authority "yes" is obtained, and the authentication control unit 503 obtains an authentication result that administrator A has key management authority. On the other hand, when the user ID indicates administrator B, key management authority "no" is obtained, and the authentication control unit 503 obtains an authentication result that administrator B does not have key management authority.
  • key management authority may also be set on a device-by-device basis for each currency processing device.
  • the authentication control unit 503 authenticates in step S107 that the maintenance personnel has maintenance authority over the currency processing device 80, it issues a JWT (JSON Web Token) (step S109).
  • the JWT is, for example, a token that proves that the maintenance personnel is authenticated as having the legitimacy and maintenance authority.
  • the JWT is used, for example, to omit subsequent authentication, such as when the secure processing unit 509 (described below) performs secure processing on installation data. Note that if the maintenance personnel is authenticated in step S107 as not having maintenance authority, processing from step S109 onwards will not be performed.
  • the transmitting unit 505 of the server device 50 transmits the JWT issued by the authentication control unit 503 to the maintenance terminal 10 as the authentication result using the maintenance personnel authentication information by the authentication control unit 503 (step S111). Note that if authentication of the maintenance personnel fails in step S105, or if the maintenance personnel is authenticated as not having maintenance authority in step S107, the transmitting unit 505 transmits an authentication result indicating authentication failure to the maintenance terminal 10. In addition, the transmitting unit 505 transmits the authentication result using the administrator authentication information by the authentication control unit 503 to the first management terminal 30.
  • FIG. 12 is a sequence diagram showing an example of the installation process performed by system 1 of this embodiment.
  • the authentication unit 101 of the maintenance terminal 10 When the receiving unit 105 of the maintenance terminal 10 receives the authentication result using the maintenance personnel authentication information from the server device 50, the authentication unit 101 of the maintenance terminal 10 performs control according to the authentication result. For example, if the authentication result indicates authentication failure, the authentication unit 101 terminates the maintenance software. Also, for example, if the authentication result is JWT, the authentication unit 101 makes the maintenance software functions, such as generating installation data, available. Note that if authentication of maintenance authority is performed on a function-by-function basis, control may be performed so that functions for which the maintenance personnel have authority are available.
  • the data generation unit 107 generates installation data, which is data (an example of first data) to be installed in the currency processing device 80, in response to operational input from the maintenance personnel (step S301).
  • installation data is explained as identification data used to identify currency, but is not limited to this.
  • FIG 13 is a diagram showing an example of installation data generated by the data generation unit 107 of this embodiment.
  • the installation data shown in Figure 13 is data in which new thresholds are defined for updating the various thresholds of the identification data currently being used by the currency processing device 80.
  • the installation data shown in Figure 13 defines thresholds for determining the authenticity of banknotes based on the output of the infrared sensor for each banknote denomination and transport direction.
  • the installation data shown in Figure 13 defines thresholds for determining authenticity not only for the infrared sensor but also for each sensor such as the magnetic sensor and thickness detection sensor.
  • the installation data shown in Figure 13 defines thresholds for determining the denomination not only for authenticity determination but also for denomination determination, and also for fitness determination, a threshold for fitness determination is defined. Note that not all thresholds in the installation data need to be new thresholds, and the installation data may contain thresholds that are the same as the thresholds of the identification data currently in use.
  • a maintenance technician generates installation data using the data generation unit 107 while conducting a flow test using currency that will actually be used.
  • the data generation unit 107 may receive data indicating the results of the flow test from the currency processing device 80 connected to the maintenance terminal 10 and generate installation data.
  • the results of the flow test may be, for example, the results of identifying test banknotes by the currency identification unit 897.
  • the generation of installation data by the data generation unit 107 also includes loading installation data previously generated by the maintenance technician into the maintenance software.
  • the transmission unit 103 of the maintenance terminal 10 transmits the installation data generated by the data generation unit 107, the device ID of the currency processing device 80, and the JWT to the server device 50 and requests secure processing (step S303).
  • the data reception unit 507 of the server device 50 receives the installation data, the device ID of the currency processing device 80, and the JWT from the maintenance terminal 10 (step S303).
  • the secure processing unit 509 of the server device 50 performs secure processing on the installation data received by the data receiving unit 507 to generate secured installation data (an example of second data). Specifically, the secure processing unit 509 authenticates the JWT received by the data receiving unit 507 and determines whether secure processing can be performed on the installation data (step S305). For example, if the JWT authenticates the legitimacy of the maintenance personnel and that they have maintenance authority, the secure processing unit 509 determines that secure processing can be performed on the installation data. In other words, if the authentication control unit 503 successfully authenticates the maintenance personnel, the secure processing unit 509 generates secured update data.
  • the secure processing unit 509 performs secure processing on the installation data using a key stored in the key memory unit 511.
  • the secure processing unit 509 performs encryption processing and electronic signature processing as described above.
  • the key memory unit 511 stores a common key (an example of a first key) as the key for encryption processing, and a private key (an example of a third key) as the key for electronic signature processing.
  • a common key an example of a first key
  • a private key an example of a third key
  • the common key and private key are prepared on a currency processing device basis, but this is not limited to this.
  • at least one of the common key and the private key may be prepared on a group basis for currency processing devices.
  • the key memory unit 511 may also store a public key (a public key that decrypts the hash value of the encrypted challenge) used for the second element of authentication of the legitimacy of the maintenance personnel described above.
  • Figure 14 is a diagram showing an example of information stored in the key storage unit 511 of this embodiment.
  • the key storage unit 511 stores IDs and various keys in association with each other.
  • the key storage unit 511 stores not only the common key and private key used for secure processing, but also the public key used for authenticating the first element of the legitimacy of the maintenance personnel.
  • the key storage unit 511 stores the common key and private key in association with the device ID of the currency processing device.
  • the key used for authenticating the first element of the legitimacy of the maintenance personnel it stores the public key in association with the dongle ID.
  • the secure processing unit 509 uses the device ID received by the data receiving unit 507 as a key to obtain the common key and private key associated with the device ID from the key storage unit 511.
  • the secure processing unit 509 generates a digital signature for the installation data using the obtained private key, and performs encryption processing to encrypt the installation data using the obtained common key.
  • the secure processing unit 509 calculates a hash value from the installation data using a hash function, encrypts the hash value using the obtained private key, and generates a digital signature for the installation data (step S307).
  • the secure processing unit 509 also encrypts the installation data using the obtained common key (step S309).
  • the secure processing unit 509 assigns a digital signature to the encrypted installation data to create secured installation data.
  • the transmitting unit 505 of the server device 50 transmits the secured installation data to the maintenance terminal 10, and the receiving unit 105 of the maintenance terminal 10 receives the secured installation data (step S311).
  • the transmitting unit 103 of the maintenance terminal 10 transmits the received secured installation data to the currency processing device 80 in response to operational input from the maintenance personnel in order to install the secured installation data in the currency processing device 80 (step S313).
  • the receiving unit 891 of the currency processing device 80 receives the secured installation data from the maintenance terminal 10 (step S313).
  • the decryption unit 893 of the currency processing device 80 decrypts the secured installation data received by the receiving unit 891 into installation data.
  • the security chip 880 of the currency processing device 80 stores a common key (an example of a second key) that is common to the common key for encryption processing stored in the server device 50, and a public key (an example of a fourth key) that pairs with the private key for electronic signature processing stored in the server device 50. Therefore, the decryption unit 893 obtains the common key and public key from the security chip 880.
  • the decryption unit 893 uses the acquired common key to decrypt the installation data from the secured installation data.
  • the decryption unit 893 also acquires a digital signature from the secured installation data, and uses the decrypted installation data, digital signature, and acquired public key to determine whether the integrity of the decrypted installation data can be guaranteed.
  • the decryption unit 893 decrypts the encrypted installation data using the acquired common key (step S315).
  • the decryption unit 893 also decrypts a hash value from the digital signature using the acquired public key, and calculates a hash value from the decrypted installation data using a hash function.
  • the decryption unit 893 authenticates the integrity of the decrypted installation data by determining whether the two hash values match (step S317).
  • the installation unit 895 of the currency processing device 80 installs the decrypted installation data into the currency processing device 80 (step S319). Specifically, if the integrity of the decrypted installation data is guaranteed by the decryption unit 893, the installation unit 895 installs the decrypted installation data into the currency processing device 80.
  • the currency identification unit 897 of the currency handling device 80 uses the aforementioned identification data (settings file) to perform a process of identifying the type of currency, including at least one of the currency's denomination, authenticity, and fitness. As mentioned above, various thresholds are defined in the identification data, and the currency identification unit 897 performs the identification process by comparing the detection value detected from the currency with the various thresholds.
  • this embodiment is described taking as an example a case where the installation data installed in the currency processing device 80 is identification data (settings file) used in the above-mentioned identification process. Therefore, when the installation data is installed in the currency processing device 80 by the installation unit 895, the above-mentioned identification data (settings file) is updated, and the currency identification unit 897 performs the identification process using the updated identification data (settings file).
  • identification data settings file
  • the installation of installation data is not limited to updating data, but may also be a program update, or the setting of new data or programs in the currency processing device 80. Furthermore, the installation of installation data may simply involve placing the data or programs in a predetermined location, or may include adding or changing OS settings.
  • the secure processing function that performs secure processing on data installed in the currency processing device is cloud-based. Therefore, the keys used for secure processing can be managed on the cloud, which increases the security (e.g., confidentiality and integrity) of the installed data itself and prevents the leakage of keys via maintenance personnel who generate the installed data.
  • the data installed in a currency processing device is identification data used to identify currency
  • maintenance personnel will need to be able to maintain (update, etc.) the above-mentioned identification data in order to maintain the currency processing device.
  • the secure processing function is cloud-based as described above, which not only increases the security of the data installed and prevents the leakage of keys via maintenance personnel, but also maintains the availability of maintenance work by maintenance personnel. Therefore, this embodiment can improve security in the process of installing data in a currency processing device.
  • the authorization authentication function which authenticates maintenance authority for the currency processing device, such as installing data on the currency processing device, is also cloud-based and realized as a cloud service separate from the secure processing function.
  • the keys used for secure processing and the information used for authorization authentication can be managed in separate cloud environments, preventing unauthorized installation on the currency processing device by unauthorized parties while increasing the robustness of the system against leaks of the above keys and information.
  • two-factor authentication is used for authorization authentication, which further enhances security in the process of installing data in currency processing devices.
  • the currency processing device also manages the keys for decrypting secure processing in the safe's memory or TPM, which increases the security (e.g., confidentiality and integrity) of the installed data itself and prevents key leakage.
  • the public key is used to authenticate the integrity of the installation data, so even if the public key were to be leaked from the currency processing device 80, it is unlikely that this would result in the installation of unauthorized data.
  • the common key may be stored in the memory or TPM within the safe 82, and the public key may be stored in a memory unit other than the memory or TPM within the safe 82.
  • program The programs executed by each device and each terminal in the above embodiments and modified examples are provided as files in an installable or executable format stored on a computer-readable storage medium such as a CD-ROM, CD-R, memory card, DVD, or flexible disk (FD).
  • a computer-readable storage medium such as a CD-ROM, CD-R, memory card, DVD, or flexible disk (FD).
  • the programs executed by each device and each terminal in the above embodiments and modified examples may be stored on a computer connected to a network such as the Internet and provided by downloading via the network. Further, the programs executed by each device and each terminal in the above embodiments and modified examples may be provided or distributed via a network such as the Internet. Further, the programs executed by each device and each terminal in the above embodiments and modified examples may be provided by being pre-installed in ROM or the like.
  • the programs executed by each device and terminal in the above embodiment and modified example have a modular configuration for implementing the above-mentioned units on a computer.
  • the CPU reads the learning program from the HDD onto RAM and executes it, thereby implementing the above-mentioned units on a computer.
  • the above embodiment and the above modified example can improve security in the process of installing data in a currency processing device.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Human Resources & Organizations (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Strategic Management (AREA)
  • Accounting & Taxation (AREA)
  • Finance (AREA)
  • Economics (AREA)
  • Entrepreneurship & Innovation (AREA)
  • Marketing (AREA)
  • Operations Research (AREA)
  • Quality & Reliability (AREA)
  • Tourism & Hospitality (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本開示の一態様に係るシステムは、貨幣を処理する貨幣処理装置を含むシステムであって、前記貨幣処理装置は、前記貨幣処理装置にインストールされる第1データを第1クラウド上でセキュア処理サービスを提供するサーバ装置に送信する保守端末を介して、前記サーバ装置が前記第1データにセキュア処理を施した第2データを受信する受信部と、前記第2データを前記第1データに復号する復号部と、復号された前記第1データを前記貨幣処理装置にインストールするインストール部と、を備える。

Description

システム、サーバ装置、インストール方法、セキュア方法、及びプログラム
 本開示は、システム、サーバ装置、インストール方法、セキュア方法、及びプログラムに関する。
 従来から、貨幣を取り込み、取り込んだ貨幣を識別して処理する貨幣処理装置が知られている。例えば、特許文献1には、上述したような貨幣処理装置において、貨幣を識別する識別プログラムを更新するための更新用プログラムの不正利用を防止する技術が開示されている。
 特許文献1に開示された技術では、製造者側が、許可コードで更新用プログラムを暗号化してSDカードに格納するとともに、貨幣識別装置の装置コードで許可コードを暗号化してPINコードを生成し、SDカードとともにPINコードを配布する。また、特許文献1に開示された技術では、配布されたSDカードを対象の貨幣識別装置に挿入して配布されたPINコードを入力すると、当該貨幣識別装置の装置コードにより許可コードが復号され、許可コードによりSDカードから更新用プログラムが復号される。このため、特許文献1に開示された技術では、他の貨幣識別装置での更新用プログラムの不正利用を防止できる。
特開2011-14080号公報
 一般的に、許可コードや装置コードなどの漏洩を完全に防止することは困難なため、不正なデータのインストールやインストール用のデータの不正利用などを招いてしまうおそれがある。
 本開示は、貨幣処理装置にデータをインストールするためのプロセスにおけるセキュリティを高めることが可能なシステム、サーバ装置、更新方法、セキュア方法、及びプログラムを提供することを目的とする。
 本開示の一態様に係るシステムは、貨幣を処理する貨幣処理装置を含むシステムであって、前記貨幣処理装置は、第1クラウド上でセキュア処理サービスを提供するサーバ装置が第1データにセキュア処理を施した第2データを受信する受信部と、前記第2データを前記第1データに復号する復号部と、復号された前記第1データを前記貨幣処理装置にインストールするインストール部と、を備える。前記第1データは、前記貨幣処理装置にインストールされるデータであってもよい。前記受信部は、保守端末を介して、前記第2データを受信してもよい。前記保守端末は、第1データを前記サーバ装置に送信してもよい。
 本開示の一態様に係るシステムにおいて、前記貨幣処理装置は、前記貨幣の金種、真偽、及び正損の少なくとも1つを含む前記貨幣の種類の識別処理を行う貨幣識別部を更に備え、前記第1データは、前記識別処理に用いられるデータであってもよい。
 本開示の一態様に係るシステムにおいて、前記第1データは、前記識別処理において前記貨幣から検出される検出値と比較される閾値を含んでもよい。
 本開示の一態様に係るシステムにおいて、前記セキュア処理は、第1の鍵を用いた暗号化を行う暗号化処理を含み、前記貨幣処理装置は、第2の鍵を記憶する記憶部を更に備え、前記復号部は、前記第2の鍵を用いて、前記第2データを前記第1データに復号してもよい。前記第1の鍵と前記第2の鍵は共通の鍵であってもよい。
 本開示の一態様に係るシステムにおいて、前記セキュア処理は、第3の鍵を用いて前記第1データの電子署名を生成する電子署名処理を含み、前記第2データは、前記電子署名を含み、前記貨幣処理装置は、前記電子署名を用いて、前記第1データの完全性が保証されるか否かを判定し、前記インストール部は、前記第1データの完全性が保証された場合、当該第1データを前記貨幣処理装置にインストールしてもよい。前記貨幣処理装置は、前記第3の鍵と対になる第4の鍵を記憶する記憶部を更に備えてもよい。前記復号部は、前記第2データから前記第1データ及び前記電子署名を復号し、復号した前記第1データ、復号した前記電子署名、及び前記第4の鍵を用いて、復号した前記第1データの完全性が保証されるか否かを判定してもよい。
 本開示の一態様に係るシステムにおいて、前記記憶部は、前記貨幣処理装置が備える金庫内のメモリ及びTPM(Trusted Platform Module)の少なくともいずれかであってもよい。
 本開示の一態様に係るシステムにおいて、前記サーバ装置を更に備え、前記サーバ装置は、前記第1データを受信するデータ受信部と、前記第1データに前記セキュア処理を施して前記第2データを生成するセキュア処理部と、前記第2データを外部に送信する第1送信部と、を備えてもよい。前記データ受信部は、前記貨幣処理装置の保守に用いられる前記保守端末から前記第1データを受信してもよい。前記第1送信部は、前記第2データを前記保守端末に送信してもよい。
 本開示の一態様に係るシステムにおいて、前記サーバ装置は、前記貨幣処理装置の保守を行う保守員を認証するための保守員認証情報を受信する認証情報受信部と、前記保守員認証情報、及び第1認証サービスを用いた前記保守員の認証を制御する認証制御部と、を更に備え、前記セキュア処理部は、前記保守員の認証に成功した場合、前記第2データを生成してもよい。前記保守員は、保守端末を使用して前記貨幣処理装置の保守を行う者であってもよい。前記認証情報受信部は、前記保守端末から前記保守員認証情報を受信してもよい。前記第1認証サービスは、前記第1クラウドと異なる第2クラウド上で提供されてもよい。
 本開示の一態様に係るシステムにおいて、前記サーバ装置は、鍵を記憶する鍵記憶部を更に備え、前記セキュア処理部は、前記鍵を用いて前記第1データに前記セキュア処理を施し、前記第1認証サービスは、前記第2クラウド内で管理されている保守員データベースを用いた認証サービスであってもよい。
 本開示の一態様に係るシステムにおいて、前記鍵は、前記貨幣処理装置で管理されている第2の鍵と共通の第1の鍵を含み、前記セキュア処理は、前記第1の鍵を用いた暗号化を行う暗号化処理を含んでもよい。
 本開示の一態様に係るシステムにおいて、前記鍵は、前記貨幣処理装置で管理されている第4の鍵と対になる第3の鍵を含み、前記セキュア処理は、前記第3の鍵を用いて前記第1データの電子署名を生成する電子署名処理を含み、前記第2データは、前記電子署名を含んでもよい。
 本開示の一態様に係るシステムにおいて、前記認証情報受信部は、前記鍵の管理を行う管理者を認証するための管理者認証情報を更に受信し、前記認証制御部は、前記管理者認証情報、及び第2認証サービスを用いた前記管理者の認証を制御してもよい。前記管理者は、管理端末を使用して前記鍵の管理を行う者であってもよい。前記認証情報受信部は、前記管理端末から、前記管理者認証情報を受信してもよい。前記第2認証サービスは、前記第2クラウド内で管理されている管理者データベースを用いた認証サービスであってもよい。
 本開示の一態様に係るシステムにおいて、前記保守員認証情報及び前記管理者認証情報のいずれかに基づいて、前記第1認証サービス及び前記第2認証サービスのいずれを認証に用いるかを決定してもよい。前記保守員認証情報及び前記管理者認証情報は、第1認証情報を含んでもよい。前記保守員認証情報に含まれる前記第1認証情報は、前記保守員を識別する情報である。前記管理者認証情報に含まれる前記第1認証情報は、前記管理者を識別する情報である。
 本開示の一態様に係るシステムにおいて、前記認証制御部は、前記第2認証サービスを認証に用いることを決定した場合、前記管理者認証情報に含まれる前記第1認証情報及び前記第2認証サービスを用いて、前記管理者が鍵の管理権限を有するか否かの認証を制御してもよい。
 本開示の一態様に係るシステムにおいて、前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報とは異なる第2認証情報を更に含み、前記認証制御部は、前記第1認証サービスを認証に用いることを決定した場合、前記第2認証情報及び前記第1認証サービスを用いて、前記保守員が前記貨幣処理装置に対する保守権限を有するか否かの認証を制御してもよい。
 本開示の一態様に係るシステムにおいて、前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報及び第2認証情報とは異なる第3認証情報を更に含み、前記認証制御部は、更に、前記第3認証情報を用いて前記保守員の正当性の認証を制御してもよい。
 本開示の一態様に係るシステムにおいて、前記保守端末を更に備え、前記保守端末は、前記保守員の正当性を認証する認証部と、認証に成功した場合、前記保守員認証情報を前記サーバ装置に送信する第2送信部と、を備えてもよい。前記認証部は、前記保守員が所持するハードウェアキーを用いて前記保守員の正当性を認証してもよい。前記保守端末は、前記第1データを生成するデータ生成部を備えてもよい。データ生成部は、前記保守端末と接続された前記貨幣処理装置から受信した流動テストの結果を示すデータを基に、前記第1データを生成してもよい。流動テストの結果は、例えば、テスト用紙幣を前記貨幣識別部で識別した結果であってもよい。
 本開示の一態様に係るシステムにおいて、前記第2認証情報は、前記保守員が所持するハードウェアキーを識別する情報であってもよい。前記第3認証情報は、前記保守員が所持するハードウェアキーに基づくワンタイムパスワードであってもよい。
 本開示の一態様に係るシステムにおいて、前記認証制御部は、前記保守員が認証された場合、JWT(JSON Web Token)を発行し、前記第1送信部は、前記JWTを外部に送信してもよい。前記データ受信部は、外部から前記第1データ及び前記JWTを受信し、前記セキュア処理部は、前記JWTを認証し、前記第1データに対する前記セキュア処理の実行の可否を判定してもよい。前記認証制御部は、前記保守員の正当性及び前記保守権限の少なくとも一方を有することが認証された場合、JWTを発行してもよい。前記認証制御部は、前記保守員の正当性及び前記保守権限の両方を有することが認証された場合、JWTを発行してもよい。前記第1送信部は、前記JWTを前記保守端末に送信してもよい。前記データ受信部は、前記保守端末から前記第1データ及び前記JWTを受信してもよい。
 本開示の一態様に係るサーバ装置は、第1クラウド上でセキュア処理サービスを提供するサーバ装置であって、外部から、前記貨幣処理装置にインストールされる第1データを受信するデータ受信部と、前記第1データにセキュア処理を施して第2データを生成するセキュア処理部と、前記第2データを外部に送信する送信部と、を備える。前記データ受信部は、貨幣処理装置の保守に用いられる保守端末から、前記第1データを受信してもよい。前記送信部は、前記第2データを前記保守端末に送信してもよい。
 本開示の一態様に係るサーバ装置において、前記貨幣処理装置の保守を行う保守員を認証するための保守員認証情報を受信する認証情報受信部と、前記保守員認証情報、及び第1認証サービスを用いて、前記保守員の認証を制御する認証制御部と、を更に備え、前記セキュア処理部は、前記保守員の認証に成功した場合、前記第2データを生成してもよい。前記保守員は、保守端末を使用して前記貨幣処理装置の保守を行う者であってもよい。前記認証情報受信部は、前記保守端末から前記保守員認証情報を受信してもよい。前記第1認証サービスは、前記第1クラウドと異なる第2クラウド上で提供されてもよい。
 本開示の一態様に係るサーバ装置において、鍵を記憶する鍵記憶部を更に備え、前記セキュア処理部は、前記鍵を用いて前記第1データに前記セキュア処理を施し、前記第1認証サービスは、前記第2クラウド内で管理されている保守員データベースを用いた認証サービスであってもよい。
 本開示の一態様に係るサーバ装置において、前記鍵は、前記貨幣処理装置で管理されている第2の鍵と共通の第1の鍵を含み、前記セキュア処理は、前記第1の鍵を用いた暗号化を行う暗号化処理を含んでもよい。
 本開示の一態様に係るサーバ装置において、前記鍵は、前記貨幣処理装置で管理されている第4の鍵と対になる第3の鍵を含み、前記セキュア処理は、前記第3の鍵を用いて前記第1データの電子署名を生成する電子署名処理を含み、前記第2データは、前記電子署名を含んでもよい。
 本開示の一態様に係るサーバ装置において、前記認証情報受信部は、前記鍵の管理を行う管理者を認証するための管理者認証情報を更に受信し、前記認証制御部は、前記管理者認証情報、及び第2認証サービスを用いた前記管理者の認証を制御してもよい。前記管理者は、管理端末を使用して前記鍵の管理を行う者であってもよい。前記認証情報受信部は、前記管理端末から、前記管理者認証情報を受信してもよい。前記第2認証サービスは、前記第2クラウド内で管理されている管理者データベースを用いた認証サービスであってもよい。
 本開示の一態様に係るサーバ装置において、前記保守員認証情報及び前記管理者認証情報のいずれかに基づいて、前記第1認証サービス及び前記第2認証サービスのいずれを認証に用いるかを決定してもよい。前記保守員認証情報及び前記管理者認証情報は、第1認証情報を含んでもよい。前記保守員認証情報に含まれる前記第1認証情報は、前記保守員を識別する情報である。前記管理者認証情報に含まれる前記第1認証情報は、前記管理者を識別する情報である。
 本開示の一態様に係るサーバ装置において、前記認証制御部は、前記第2認証サービスを認証に用いることを決定した場合、前記管理者認証情報に含まれる前記第1認証情報及び前記第2認証サービスを用いて、前記管理者が鍵の管理権限を有するか否かの認証を制御してもよい。
 本開示の一態様に係るサーバ装置において、前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報とは異なる第2認証情報を更に含み、前記認証制御部は、前記第1認証サービスを認証に用いることを決定した場合、前記第2認証情報及び前記第1認証サービスを用いて、前記保守員が前記貨幣処理装置に対する保守権限を有するか否かの認証を制御してもよい。
 本開示の一態様に係るサーバ装置において、前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報及び第2認証情報とは異なる第3認証情報を更に含み、前記認証制御部は、更に、前記第3認証情報を用いて前記保守員の正当性の認証を制御してもよい。
 本開示の一態様に係るサーバ装置において、前記第2認証情報は、前記保守員が所持するハードウェアキーを識別する情報であってもよい。前記第3認証情報は、前記保守員が所持するハードウェアキーに基づくワンタイムパスワードであってもよい。
 本開示の一態様に係るサーバ装置において、前記認証制御部は、前記保守員が認証された場合、JWT(JSON Web Token)を発行し、前記第1送信部は、前記JWTを外部に送信してもよい。前記データ受信部は、外部から前記第1データ及び前記JWTを受信し、前記セキュア処理部は、前記JWTに基づいて、前記第1データに対する前記セキュア処理の実行の有無を判定してもよい。前記認証制御部は、前記保守員の正当性及び前記保守権限の少なくとも一方を有することが認証された場合、JWTを発行してもよい。前記認証制御部は、前記保守員の正当性及び前記保守権限の両方を有することが認証された場合、JWTを発行してもよい。前記第1送信部は、前記JWTを前記保守端末に送信してもよい。前記データ受信部は、前記保守端末から前記第1データ及び前記JWTを受信してもよい。
 本開示の一態様に係るインストール方法は、貨幣を処理する貨幣処理装置で実行されるインストール方法であって、第1クラウド上でセキュア処理サービスを提供するサーバ装置が第1データにセキュア処理を施した第2データを受信する受信ステップと、前記第2データを前記第1データに復号する復号ステップと、復号された前記第1データを前記貨幣処理装置にインストールするインストールステップと、を含む。前記第1データは、前記貨幣処理装置にインストールされるデータであってもよい。前記受信ステップは、保守端末を介して、前記第2データを受信してもよい。前記保守端末は、第1データを前記サーバ装置に送信してもよい。
 本開示の一態様に係るセキュア方法は、第1クラウド上でセキュア処理サービスを提供するサーバ装置で実行されるセキュア方法であって、前記貨幣処理装置にインストールされる第1データを受信するデータ受信ステップと、前記第1データにセキュア処理を施して第2データを生成するセキュア処理ステップと、前記第2データを前記保守端末に送信する送信ステップと、を含む。前記データ受信ステップは、貨幣処理装置の保守に用いられる保守端末から、前記第1データを受信してもよい。前記送信ステップは、前記第2データを前記保守端末に送信してもよい。
 本開示の一態様に係るプログラムは、貨幣を処理する貨幣処理装置で実行されるプログラムであって、第1クラウド上でセキュア処理サービスを提供するサーバ装置が第1データにセキュア処理を施した第2データを受信する受信ステップと、前記第2データを前記第1データに復号する復号ステップと、復号された前記第1データを前記貨幣処理装置にインストールするインストールステップと、を前記貨幣処理装置のコンピュータに実行させるためのものである。前記第1データは、前記貨幣処理装置にインストールされるデータであってもよい。前記受信ステップは、保守端末を介して、前記第2データを受信してもよい。前記保守端末は、第1データを前記サーバ装置に送信してもよい。
 本開示の一態様に係るプログラムは、第1クラウド上でセキュア処理サービスを提供するサーバ装置で実行されるプログラムであって、外部から、前記貨幣処理装置にインストールされる第1データを受信するデータ受信ステップと、前記第1データにセキュア処理を施して第2データを生成するセキュア処理ステップと、前記第2データを外部に送信する送信ステップと、を前記サーバ装置のコンピュータに実行させるためのものである。前記データ受信ステップは、貨幣処理装置の保守に用いられる保守端末から、前記第1データを受信してもよい。前記送信ステップは、前記第2データを前記保守端末に送信してもよい。
図1は、本実施形態のシステムの構成の一例を示すブロック図である。 図2は、本実施形態の保守端末のハードウェア構成の一例を示すブロック図である。 図3は、本実施形態のサーバ装置のハードウェア構成の一例を示すブロック図である。 図4は、本実施形態の貨幣処理装置の機械的構成の一例を示す模式図である。 図5は、本実施形態の主基板のハードウェア構成の一例を示すブロック図である。 図6は、本実施形態の保守端末、サーバ装置、及び貨幣処理装置の機能構成の一例を示すブロック図である。 図7は、本実施形態のシステムで行われる保守員の認証処理の一例を示すシーケンス図である。 図8は、本実施形態のシステムで行われる保守員及び第1管理者の権限認証処理の一例を示すフローチャートである。 図9は、本実施形態の認証先DBに記憶されている情報の一例を示す図である。 図10は、本実施形態の保守員DBに記憶されている情報の一例を示す図である。 図11は、本実施形態の管理者DBに記憶されている情報の一例を示す図である。 図12は、本実施形態のシステムで行われるインストール処理の一例を示すシーケンス図である。 図13は、本実施形態のデータ生成部により生成されるインストール用のデータの一例を示す図である。 図14は、本実施形態の鍵記憶部に記憶されている情報の一例を示す図である。
 以下、図面を参照しながら、本開示の実施形態(以下、単に「本実施形態」と称する)を詳細に説明する。なお、本開示は、以下の実施形態に限定されるものではない。また、以下の実施形態及び変形例は、適宜に組み合わせることもできる。
 本実施形態のシステムは、貨幣処理装置にデータをインストールするためのプロセスにおけるセキュリティを高めたシステムである。
 具体的には、本実施形態のシステムでは、貨幣処理装置にインストールされるデータにセキュア処理を施すセキュア処理機能をクラウド化している。これにより、本実施形態のシステムでは、セキュア処理に用いる鍵をクラウド上で管理できるので、インストールされるデータそのもののセキュア性(例えば、機密性や完全性)を高められるとともに、鍵の盗難や、インストールされるデータを生成する保守員による鍵の遺失を防止できる。なお、以下の本実施形態では、セキュア処理が暗号化処理及び電子署名処理である場合を例にとり説明する。但し、セキュア処理は、これらに限定されるものではないし、暗号化処理及び電子署名処理のいずれか一方であってもよい。
 また、本実施形態のシステムでは、貨幣処理装置にデータをインストールするなどの貨幣処理装置の保守権限を認証する権限認証機能もクラウド化し、セキュア処理機能とは別のクラウドサービスとして実現している。これにより、本実施形態のシステムでは、セキュア処理に用いる鍵と権限認証に用いる情報とを別々のクラウド環境で管理でき、権限なき者による貨幣処理装置への不正なインストールを防止しつつ、上記鍵及び情報の漏洩に対するシステムの堅牢性を高めている。
 以下、本実施形態のシステムの構成及び動作について具体的に説明する。
 図1は、本実施形態のシステム1の構成の一例を示すブロック図である。図1に示すように、システム1は、保守端末10と、ハードウェアキー20と、第1管理端末30と、第1クラウド40と、第2クラウド60と、第2管理端末70と、貨幣処理装置80と、を備える。
 保守端末10は、保守員が貨幣処理装置80を保守する際に用いる端末装置であり、例えば、保守プログラムがインストールされたPC(Personal Computer)などが挙げられる。保守端末10は、LAN(Local Area Network)などのネットワークを介して貨幣処理装置80と接続されていてもよいし、通信ケーブルなどを介して貨幣処理装置80と直接接続されていてもよい。また、保守端末10は、インターネットなどの公衆ネットワークを介して第1クラウド40と接続される。
 保守端末10では、保守プログラムがインストールされることで保守プログラムに基づく保守ソフトウェアが実行可能となる。保守ソフトウェアは、貨幣処理装置80にインストールされるデータの生成や読み込みに用いられる。また、保守ソフトウェアは、保守員が貨幣処理装置80にデータをインストールするなどの貨幣処理装置の保守権限を有するか否かの認証を第1クラウド40に要求するために用いられる。また、保守ソフトウェアは、貨幣処理装置80にインストールされるデータに対してセキュア処理を施すことを第1クラウド40に要求するために用いられる。また、保守ソフトウェアは、セキュア処理が施されたインストール用のデータを貨幣処理装置80に送信するために用いられる。
 ハードウェアキー20は、保守ソフトウェアの利用制御に用いられるハードウェアデバイスである。本実施形態では、保守員一人ひとりにハードウェアキー20が配布されており、保守員が自身のハードウェアキー20を保守端末10に接続して認証に成功すると、保守ソフトウェアが利用可能となる。本実施形態では、ハードウェアキー20がUSB(Universal Serial Bus)メモリ形式のドングルである場合を例にとり説明するが、ハードウェアキー20は、USBメモリ形式に限定されず、また、ドングルにも限定されるものではない。ハードウェアキー20は、例えば、スマートカード(ICカード)、HSM(Hardware Security Module)、又はセキュリティトークンなどであってもよい。
 第1管理端末30は、第1クラウド40がクラウドサービスとして提供するセキュア処理サービスに用いられる鍵を第1管理者が管理するために用いる端末装置であり、例えば、PCなどが挙げられる。第1管理端末30は、インターネットなどの公衆ネットワークを介して第1クラウド40と接続される。第1管理端末30は、第1管理者が鍵を管理する権限を有するか否かの認証を第1クラウド40に要求するために用いられる。また、第1管理端末30は、第1クラウド40にアクセスして、第1管理者が第1クラウド40で管理されている各種鍵の登録、修正、及び削除などを行うために用いられる。
 第1クラウド40は、セキュア処理サービスを提供するクラウドサービスである。第1クラウド40は、ファイアウォール41と、認証先DB(DataBase)43と、サーバ装置50と、を備える。サーバ装置50は、例えば、LANなどのネットワークを介して、ファイアウォール41及び認証先DB43と接続されている。また、第1クラウド40(サーバ装置50)は、インターネットなどの公衆ネットワークを介して第2クラウド60と接続される。
 ファイアウォール41は、第1クラウド40への不正アクセスを防止するためのものであり、例えば、ルーターなどのネットワーク機器やファイアウォール単体の専用機器などが挙げられる。ファイアウォール41は、例えば、保守端末10や第1管理端末30などを含む外部環境からのアクセスに対するフィルタリングを行う。
 認証先DB43は、第1クラウド40に対して行われた認証要求を、第2クラウド60がクラウドサービスとして提供する複数の認証サービスのいずれを用いて処理するかを決定するために用いられるデータベースである。
 サーバ装置50は、第1クラウド40上でセキュア処理サービスを提供するためのものであり、サーバ用のコンピュータなどが挙げられる。なお、サーバ装置50は、単数のコンピュータにより実現されてもよいし、複数台のコンピュータにより実現されてもよい。
 サーバ装置50は、保守端末10や第1管理端末30からの第1クラウド40に対する認証要求を制御する。例えば、サーバ装置50は、保守員の正当性の認証については自身で認証する。また例えば、サーバ装置50は、第1管理者の鍵の管理権限や保守員の保守権限などの権限認証については、認証先DB43を参照して、第2クラウド60が提供する複数の認証サービスの中から、当該認証を処理する認証サービスを決定する。サーバ装置50は、認証を処理する認証サービスを決定すると、当該認証サービスを用いて認証処理を行う。
 またサーバ装置50は、保守端末10から送信されたインストール用のデータに対してセキュア処理を施すための鍵を記憶する。本実施形態では、セキュア処理として、例えば、インストール用のデータに対して暗号化処理及び電子署名処理が施されるため、サーバ装置50は、暗号化処理用の鍵及び電子署名処理用の鍵を記憶する。なお、セキュア処理は、暗号化処理及び電子署名処理以外の処理であってもよいし、暗号化処理及び電子署名処理のいずれか一方であってもよいため、サーバ装置50は、セキュア処理に応じた鍵を記憶すればよい。
 また、暗号化処理及び電子署名処理にはどのような暗号方式を用いても構わないが、本実施形態では、暗号化処理には共通鍵暗号方式、電子署名処理には公開鍵暗号方式を用いる場合を例にとり説明する。このため本実施形態では、サーバ装置50は、暗号化処理用の鍵として共通鍵、電子署名処理用の鍵として秘密鍵を記憶するものとするが、サーバ装置50が記憶する鍵はこれらに限定されるものではない。
 サーバ装置50は、保守端末10からインストール用のデータを受信すると、記憶している鍵を用いてセキュア処理を施す。具体的には、サーバ装置50は、記憶している共通鍵を用いてインストール用のデータに暗号化処理を施す。また、サーバ装置50は、ハッシュ関数を用いてインストール用のデータからハッシュ値を算出し、記憶している秘密鍵を用いてハッシュ値を暗号化し、インストール用のデータの電子署名を生成する。
 サーバ装置50は、セキュア処理が施されたインストール用のデータを保守端末10に送信する。具体的には、サーバ装置50は、暗号化処理が施されたインストール用のデータに、生成された電子署名を付与して、保守端末10に送信する。
 第2クラウド60は、複数の認証サービスを提供するクラウドサービスである。第2クラウド60は、ファイアウォール61と、保守員DB63と、管理者DB65と、管理者認証装置67と、を備える。ファイアウォール61と保守員DB63とは、例えば、LANなどのネットワークを介して接続され、管理者DB65と管理者認証装置67とは、例えば、LANなどのネットワークを介して接続されている。
 ファイアウォール61は、保守員DB63への不正アクセスを防止するためのものであり、例えば、ルーターなどのネットワーク機器やファイアウォール単体の専用機器などが挙げられる。ファイアウォール61は、例えば、第1クラウド40のサーバ装置50などを含む外部環境からのアクセスに対するフィルタリングを行う。
 保守員DB63は、保守員及び当該保守員の保守権限を管理するデータベースである。第2クラウド60は、認証サービスの1つとして、保守員DB63を第2クラウド60外の認証元に利用させる保守員認証サービスを提供する。例えば、第1クラウド40のサーバ装置50が、保守端末10からの認証要求を第2クラウド60の保守員認証サービスで処理する場合、ファイアウォール61を介して保守員DB63にアクセスし、保守員の保守権限を認証する。
 管理者DB65は、第1管理者及び当該第1管理者の鍵の管理権限を管理するデータベースである。管理者認証装置67は、管理者DB65を用いて第1管理者の鍵の管理権限を認証するものであり、例えば、サーバ用の1台以上のコンピュータなどが挙げられる。
 第2クラウド60は、認証サービスの1つとして、管理者DB65を用いた管理者認証装置67による第1管理者認証サービスを提供する。例えば、第1クラウド40のサーバ装置50が、第1管理端末30からの認証要求を第2クラウド60の第1管理者認証サービスで処理する場合、当該認証要求を管理者認証装置67に送信し、管理者認証装置67から認証結果を受信する。
 第2管理端末70は、第2クラウド60に含まれる保守員DB63及び管理者DB65を第2管理者が管理するために用いる端末装置であり、例えば、PCなどが挙げられる。第2管理端末70は、インターネットなどの公衆ネットワークを介して第2クラウド60と接続される。第2管理端末70は、第2クラウド60にアクセスして、保守員DB63で管理されている保守員の登録、保守権限の修正、及び削除などを行うために用いられる。また、第2管理端末70は、第2クラウド60にアクセスして、管理者DB65で管理されている第1管理者の登録、鍵の管理権限の修正、及び削除などを行うために用いられる。第2管理端末70は、第1管理端末30と同じ端末装置であってもよい。
 貨幣処理装置80は、貨幣を処理するものであり、貨幣を取り込み、取り込んだ貨幣に関する種々の処理を実行する。貨幣としては、紙幣及び硬貨の少なくともいずれかが挙げられるが、これらに限定されるものではない。また、貨幣には、小切手、商品券、又は株券などの各種の有価証券が含まれていてもよい。
 貨幣に関する種々の処理としては、例えば、貨幣の金種、真偽、及び正損等を識別して処理する識別処理が挙げられるが、これに限定されるものではない。なお、貨幣の識別処理には、通常、貨幣の種別毎に、金種、真偽、及び正損等を識別するための閾値等が定義された識別データ(設定ファイル)が用いられる。
 本実施形態では、貨幣処理装置80にインストールされるデータが上述の識別データである場合を例にとり説明するが、貨幣処理装置80にインストールされるデータは、これに限定されるものではない。
 貨幣処理装置80は、保守端末10からセキュア処理が施されたインストール用のデータを受信すると、インストール用のデータを復号する。貨幣処理装置80は、サーバ装置50に記憶されている暗号化処理用の共通鍵と共通の共通鍵、及びサーバ装置50に記憶されている電子署名処理用の秘密鍵と対になる公開鍵を管理している。このため、貨幣処理装置80は、セキュア処理が施されたインストール用のデータから電子署名を取り出し、公開鍵でハッシュ値を復号する。また、貨幣処理装置80は、共通鍵を用いて、セキュア処理が施されたインストール用のデータからインストール用のデータ(平文)を復号する。また、貨幣処理装置80は、ハッシュ関数を用いて、復号したインストール用のデータからハッシュ値を算出し、復号したハッシュ値と一致するか否かを判定する。貨幣処理装置80は、両ハッシュ値が一致し、インストール用のデータの完全性が保証される場合、復号したインストール用のデータをインストールすることで、貨幣処理装置80で使用される識別データ(設定ファイル)を更新する。
 なお、図1では、保守端末10及び貨幣処理装置80がサイトAに配置され、第1管理端末30がサイトBに配置され、第2管理端末70がサイトCに配置されている場合を例示している。但し、各端末及び装置の配置はこれに限定されるものではない。例えば、第1管理端末30と第2管理端末70が同じサイトに配置されていてもよい。
 サイトAとしては、例えば、貨幣処理装置80が使用される銀行及び小売店などの各種店舗、並びに駅などの公共施設の少なくともいずれかが挙げられるが、これらに限定されるものではない。また、サイトBとしては、例えば、貨幣処理装置80の保守を管理する、貨幣処理装置80のメーカーの支社や営業所などが挙げられるが、これらに限定されるものではない。また、サイトCとしては、例えば、貨幣処理装置80のメーカーの本社など当該メーカーのシステム管理室が設置されているサイトなどが挙げられるが、これらに限定されるものではない。
 保守員としては、例えば、貨幣処理装置80のメーカーから保守業務を請け負っている請負業者の従業員や、貨幣処理装置80のメーカーの従業員などが挙げられるが、これらに限定されるものではない。第1管理者としては、例えば、貨幣処理装置80のメーカーの従業員であって、貨幣処理装置80の保守管理業務の責任者や保守管理権限が与えられた従業員などが挙げられるが、これらに限定されるものではない。第2管理者としては、例えば、貨幣処理装置80のメーカーのシステム管理室に配属されている従業員などが挙げられるが、これらに限定されるものではない。
 なお、第2クラウド60については、システム1用に新規に開発したクラウドサービスであってもよいし、貨幣処理装置80の製造元の企業が社員管理などの用途に元々有していたディレクトリサービスなどの機能を有するクラウドサービスであってもよい。後者のように、既存のクラウドサービスを流用することで、システム1の開発コストやランニングコストを削減できる。
 図2は、本実施形態の保守端末10のハードウェア構成の一例を示すブロック図である。図2に示すように、保守端末10は、制御装置11と、主記憶装置12と、補助記憶装置13と、表示装置14と、入力装置15と、通信装置16と、リーダ装置17と、各種バス18と、を備える。制御装置11、主記憶装置12、補助記憶装置13、表示装置14、入力装置15、通信装置16、及びリーダ装置17は、各種バス18を介して接続されている。このように本実施形態の保守端末10は、通常のコンピュータを利用した一般的なハードウェア構成となっている。
 制御装置11は、保守端末10の全体の動作を制御する。制御装置11としては、例えば、CPU(Central Processing Unit)及びGPU(Graphics Processing Unit)などの少なくともいずれかが挙げられるが、これらに限定されるものではない。CPUやGPUは、1以上であればいくつであってもよく、シングルコアであってもマルチコアであっても構わない。
 主記憶装置12としては、例えば、ROM(Read Only Memory)及びRAM(Random Access Memory)などが挙げられるが、これらに限定されるものではない。ROMは、保守端末10を制御するためのプログラム及び本実施形態の保守プログラムなど各種プログラムを記憶する。RAMは、制御装置11がROMに記憶されたプログラムに基づいて各種制御を行う際の作業領域として用いられる。
 補助記憶装置13は、上述した各種プログラム及び各種データを記憶する。なお、上述した各種プログラムは、主記憶装置12及び補助記憶装置13の少なくとも一方に記憶されていればよい。補助記憶装置13としては、例えば、HDD(Hard Disk Drive)、SSD(Solid State Drive)、及びDVD(Digital Versatile Disc)などの磁気的、電気的、又は光学的に記憶可能な既存の記憶装置の少なくともいずれかが挙げられるが、これらに限定されるものではない。補助記憶装置13は、保守端末10に内蔵されていても、USB(Universal Serial Bus)などのインターフェースを介して保守端末10に外付けされていても構わない。また補助記憶装置13は、LANやWAN(Wide Area Network)などのネットワークを介して接続されるNAS(Network Attached Storage)であっても構わない。
 表示装置14は、保守ソフトウェアを使用する際の各種画面を表示するものであり、ユーザ(保守員)との間のユーザインターフェースとしての役割を担う。表示装置14としては、例えば、液晶ディスプレイ、有機EL(Organic Electro-Luminescence)ディスプレイ、及びタッチパネルディスプレイなどの各種ディスプレイが挙げられるが、これらに限定されるものではない。表示装置14は、保守端末10に内蔵された内臓ディスプレイであっても、保守端末10にHDMI(登録商標)などのディスプレイ用のインターフェースを介して接続される外部ディスプレイであっても構わない。
 入力装置15は、保守ソフトウェアを使用する際の各種入力に用いられるものであり、ユーザ(保守員)との間のユーザインターフェースとしての役割を担う。入力装置15としては、例えば、キーボード、マウス、及びタッチパネルなどが挙げられるが、これらに限定されるものではない。入力装置15は、保守端末10に内蔵されていても、保守端末10にUSBなどのインターフェースを介して外付けされていても構わない。
 通信装置16としては、例えば、有線LAN用の通信装置や無線LAN用の無線通信装置などが挙げられるが、これらに限定されるものではない。通信装置16は、本実施形態の保守プログラムやデータを外部から取得する際に用いられてもよい。
 リーダ装置17としては、例えば、USBポートなどのポートに接続された外部デバイスからデータの読み取りを行う装置などが挙げられるが、これらに限定されるものではない。本実施形態では、リーダ装置17は、ハードウェアキー20からの情報の読み取りに用いられる。
 なお、保守端末10は、上記構成に加え、保守端末10特有のIC(Integrated Circuit)、ASIC(Application Specific Integrated Circuit)、及びFPGA(Field-Programmable Gate Array)などのハードワイヤード回路を更に備えるようにしてもよい。
 図3は、本実施形態のサーバ装置50のハードウェア構成の一例を示すブロック図である。図3に示すように、サーバ装置50は、制御装置51と、主記憶装置52と、補助記憶装置53と、通信装置56と、各種バス58と、を備える。制御装置51、主記憶装置52、補助記憶装置53、及び通信装置56は、各種バス58を介して接続されている。このように本実施形態のサーバ装置50は、通常のコンピュータを利用した一般的なハードウェア構成となっている。
 制御装置51は、サーバ装置50の全体の動作を制御する。制御装置51の実現手法については、制御装置11と同様であるため、詳細な説明は省略する。
 主記憶装置52のROMは、サーバ装置50を制御するためのプログラム、並びにセキュア処理を行うためのプログラムや認証処理を制御するためのプログラムなど各種プログラムを記憶する。主記憶装置52の実現手法については、主記憶装置12と同様であるため、詳細な説明は省略する。
 補助記憶装置53は、上述した各種プログラム及び各種データを記憶する。なお、上述した各種プログラムは、主記憶装置52及び補助記憶装置53の少なくとも一方に記憶されていればよい。補助記憶装置53の実現手法については、補助記憶装置13と同様であるため、詳細な説明は省略する。
 通信装置56の実現手法については、通信装置16と同様であるため、詳細な説明は省略する。
 なお、サーバ装置50は、上記構成に加え、サーバ装置50特有のIC、ASIC、及びFPGAなどのハードワイヤード回路を更に備えるようにしてもよい。
 図4は、本実施形態の貨幣処理装置80の機械的構成の一例を示す模式図である。以下の説明において、後述する第1扉823が設けられている側を前、第1扉823が設けられている側と反対側を後と記載することがある。
 図4に示す例では、貨幣処理装置80は、バラ紙幣に関する処理を実行する。貨幣処理装置80は、上部の処理部81と下部の金庫82とを有している。金庫82は、第1金庫部821及び第2金庫部822を有している。
 処理部81は、上部筐体811を有している。上部筐体811の中には、入金部812、出金部813、識別部814、及び搬送路の一部が配設されている。
 金庫82の内部は、2つの領域に分かれている。金庫82の中には、収納部83と、搬送路の一部と、後述する主基板855と、が設けられている。金庫82は、所定以上のセキュリティレベルで収納部83及び主基板855を防護する。金庫82のセキュリティレベルは、上部筐体811より高い。
 金庫82は、第1扉823及び第2扉824を有している。第1扉823には、電子錠825が設けられている。電子錠825は、通常、施錠されている。第1管理者が電子錠825を解錠すると、第1扉823は開くことができる状態となる。第1扉823が開いた状態で、第1金庫部821の収納部83は、貨幣処理装置80の前方に引き出される。
 第2扉824には、電子錠826が設けられている。電子錠826は、通常、施錠されている。第1管理者が電子錠826を解錠すると、第2扉824は開くことができる状態となる。第2扉824が開いた状態で、第2金庫部822の収納部83は、貨幣処理装置80の前方に引き出される。
 特別な権限を有する第1管理者が、電子錠825及び電子錠826を解錠できる。電子錠825を解錠するために必要な権限と、電子錠826を解錠するために必要な権限とは、同じでなくてもよい。
 入金部812は、例えば紙幣を後述の収納部に入金する入金処理の際に、入金対象の紙幣が投入される部分である。入金部812は、複数枚の紙幣を、重ねた状態で保持する。入金部812は、紙幣を一枚ずつ装置内に取り込む機構を有している。
 出金部813は、例えば紙幣を後述の収納部から出金する出金処理の際に、出金対象の紙幣を保持する部分である。出金部813は、複数枚の紙幣を、重ねた状態で保持する。貨幣処理装置80のユーザは、出金部813から紙幣を手で取り出すことができる。なお、貨幣処理装置80のユーザとは、第1管理者の他、保守員や貨幣処理装置80が設置された店舗の顧客などの一般ユーザを含む。
 識別部814は、後述するループ搬送路841に設けられている。識別部814は、ループ搬送路841に沿って搬送される紙幣を検知する。識別部814は、検知した紙幣の一枚一枚について画像を取得する。識別部814は、取得した画像を用いて、少なくとも、真偽、金種及び正損を識別する。識別部814は、紙幣の記番号を取得する。
 収納部83は、紙幣を収納する。収納部83は、例えば、スタック式(紙幣を積み重ねる方式)、またはテープ式(テープとともに紙幣を巻き取る方式)で紙幣を収納する。
 複数の収納部83は、それぞれ、第1金庫部821又は第2金庫部822の内部に設けられている。複数の収納部83は、貨幣処理装置80に対して着脱可能な収納カセットを含んでもよい。第1金庫部821に設けられている収納部83のうちの少なくともいずれかは、支持部827によって支持されている。支持部827は、例えばレール構造を有しており、第1扉823が開いた状態で収納部83を支持したまま前方に移動することができる。これにより、第1金庫部821の収納部83が貨幣処理装置80の前方に引き出される。
 収納部83の紙幣の出入口には、紙幣の通過を検知するセンサが取り付けられている。後述する収納部基板854は、当該センサの検知信号に基づいて、収納部83へ入った紙幣の枚数と、収納部83から出た紙幣の枚数とを数える。収納部基板854は、数えた枚数に基づいて、収納部83が収納している紙幣の枚数を管理する。
 搬送部84は、貨幣処理装置80内で紙幣を搬送する。搬送部84は搬送路を有している。搬送路は、図示は省略するが、多数のローラ、複数のベルト、これらを駆動するモータ、および、複数のガイドの組み合わせによって構成されている。搬送部84は、例えば紙幣の長手の縁を前にして、紙幣と紙幣との間に間隔を空けて、紙幣を一枚ずつ、搬送路に沿って搬送する。搬送部84は、紙幣の短手の縁を前にして搬送してもよい。
 搬送部84は、ループ搬送路841を有している。ループ搬送路841は、上部筐体811内に設けられている。搬送部84は、紙幣を、ループ搬送路841に沿って、図2における時計回り方向及び反時計回り方向に搬送する。
 入金部812は、接続路842を介して、ループ搬送路841に接続されている。出金部813は、接続路843を介して、ループ搬送路841に接続されている。
 収納部83は、それぞれ、接続路844を介してループ搬送路841に接続されている。接続路844は、それぞれ、処理部81と第1金庫部821とにまたがるように、上下方向に伸びている。接続路844の一部は、処理部81、第1金庫部821、および第2金庫部822にまたがるように、上下方向に伸びている。搬送部84は、接続路844を介してループ搬送路841から収納部83のそれぞれに紙幣を搬送する。搬送部84は、接続路844を介して収納部83のそれぞれからループ搬送路841へ紙幣を搬送する。
 上部筐体811には、一時保留部86が設けられている。一時保留部86は、紙幣を一時的に収納する。一時保留部86は、様々な用途に使用することができる。一時保留部86は、上部筐体811の中における、前方位置に配設されている。一時保留部86は、接続路845を介してループ搬送路841に接続されている。
 貨幣処理装置80には、金庫外収納部840を取り付けることができる。金庫外収納部840は、貨幣処理装置80から取り外すことができる。金庫外収納部840は、着脱式の収納部である。金庫外収納部840は、接続路846を介して、ループ搬送路841に接続される。
 貨幣処理装置80は、識別基板851、上部基板852、下部基板853、収納部基板854、及び主基板855を備えている。各基板は、記憶装置、プロセッサ、及び通信インターフェースを備えている。記憶装置は、RAM、ROM、eMMC(embedded Multi Media Card)、又はSSDなどの半導体メモリによって構成されている。記憶装置には、種々のデータ、およびソフトウェアが格納される。プロセッサは、記憶装置からの各種ソフトウェアを読み出して実行する。通信インターフェースは、USB又はRS-422などの所定の通信規格に基づいて通信を行う。
 貨幣処理装置80では、主基板855が貨幣処理装置80におけるセキュリティ管理機能を発揮する。主基板855は、セキュリティ管理機能の実現のために、ハードウェア構成に特徴を有している。
 図5は、本実施形態の主基板855のハードウェア構成の一例を示すブロック図である。主基板855は、プロセッサ870、記憶装置871、通信インターフェース872、及びセキュリティチップ880(記憶部の一例)を備えている。
 プロセッサ870は、他の基板のプロセッサ(マイクロコンピュータ)と同様に、記憶装置871内のソフトウェアを実行する。プロセッサ870には、プロセッサ870自身によって実行可能なコード(以下、内部コードという)が埋め込まれている。プロセッサ870は、内部コードを変更できないように構成されている。換言すると、第三者は、内部コードを改竄できない。プロセッサ870は、内部コードをプロセッサ870の起動時に実行する。
 プロセッサ870には、所定の情報(デジタルデータ)を保持する記憶領域873が設けられている。記憶領域873は、書き込みを一度行うと、内容を変更できないように構成されている。記憶領域873内の情報の改竄は、不可能である。記憶領域873には、貨幣処理装置80が出荷される前(例えば貨幣処理装置80の製造時)に、貨幣処理装置80の製造元が、情報を書き込む。
 セキュリティチップ880は、耐タンパ性を有した半導体装置である。耐タンパ性とは、外部から、内部に記録されたデータの解析、読み取り、改竄がされにくいという特性を意味している。セキュリティチップ880には、TCG(Trusted Computing Group)で定義されたセキュリティの仕様に準拠したセキュリティチップ(TPM:Trusted Platform Module)を採用することができる。セキュリティチップ880には、所定の情報(デジタルデータ)を保持する記憶装置881が設けられている。
 セキュリティチップ880は、バス856によって、プロセッサ870と接続されている。プロセッサ870からセキュリティチップ880にアクセス(書き込み、読み出し)するには、所定の認証コードが必要となる。
 セキュリティチップ880は、前述の共通鍵及び公開鍵を格納する機能を備えている。また、セキュリティチップ880は、ハッシュ値を算出する機能を備えていてもよい。記憶装置881は、記憶装置871内のソフトウェアを認証するためのデータを記憶してもよい。ソフトウェアを認証するためのデータは、例えば、ソフトウェアのハッシュ値である。
 記憶装置871は、他の基板が備える記憶装置と同様の構成である。記憶装置871は、複数種類のデバイス(例えばeMMC及びROM)によって構成されてもよい。本実施形態では、主基板855の記憶装置871には、eMMCが含まれている。記憶装置871は、基本ソフトウェアおよびアプリケーションソフトウェアを記憶する。
 通信インターフェース872は、他の基板が備える通信インターフェースと同様の構成である。
 図4に戻り、説明を続ける。識別基板851及び上部基板852は、上部筐体811に設けられている。
 識別基板851は、プロセッサが所定のソフトウェアを実行することによって、識別部814の制御と、識別結果の出力とを行う。例えば、識別基板851は、紙幣の画像に基づいて、紙幣の真偽、金種および正損を識別する。識別基板851は、通信インターフェースを介して上部基板852と接続されている。識別基板851は、通信インターフェースを介して、識別結果を上部基板852へ出力する。
 上部基板852は、プロセッサが所定のソフトウェアを実行することによって、入金部812、出金部813、搬送部84、及び一時保留部86などの動作を制御する。例えば、上部基板852は、搬送部84などが備えている駆動機構(モータ)などの制御を行う。
 下部基板853、収納部基板854、及び主基板855は、金庫82内に設けられている。より詳しくは、下部基板853と主基板855とは、第1金庫部821内に設けられている。すなわち、主基板855は、電子錠825の解除が必要となる場所に設置されている。収納部基板854は、収納部83のそれぞれに設けられている。
 収納部基板854は、収納部83毎に設けられている。各収納部基板854の記憶装置には、対応する収納部83のID及び扉開閉ログが記憶される。これらの記憶装置には、収納されている紙幣の種類及び枚数の少なくとも一方が記憶される場合がある。
 収納部基板854は、通信インターフェースを介して、下部基板853に接続されている。収納部基板854は、下部基板853からの要求に応じて、ID及び扉開閉ログの情報を、通信インターフェースを介して下部基板853に送信する。
 下部基板853は、プロセッサが所定のソフトウェアを実行することによって、各収納部83及び搬送部84を制御する。下部基板853は、収納部83のIDやログデータを収集する。
 下部基板853は、通信インターフェースを介して、上部基板852と接続されている。下部基板853は、搬送部84を制御する場合には、通信インターフェースを介して、上部基板852に所定の信号(命令)を送る。
 主基板855は、プロセッサが所定のソフトウェアを実行することによって、貨幣処理装置80の起動、貨幣処理装置80の外部との通信、及び各種ソフトウェアの管理を担当する。主基板855の記憶装置871には、基本ソフトウェア(OS:Operation System)が搭載される。
 貨幣処理装置80においては、主基板855が第1金庫部821の内部に設けられているため、第三者は主基板855にアクセスすることができない。このため、第三者がセキュリティチップ880に格納された共通鍵及び公開鍵にアクセスすることができない。
 主基板855は、通信インターフェース872を介して、下部基板853と接続されている。主基板855と下部基板853との間では、ログデータ、アップデートファイルなどの送受信が行われる。
 主基板855は、通信インターフェース872を介して、識別基板851と接続されている。主基板855は、識別データを識別基板851に送信したり、紙幣イメージデータを識別基板851から受け取ったりする。識別データは、前述の通り、紙幣の真偽、金種及び正損を識別するためのデータである。紙幣イメージデータは、識別基板851において取得された紙幣のイメージデータである。
 貨幣処理装置80は、図示せぬユーザインターフェース(UI)部を有している。UI部は、操作部(キーボード、トラックボール、タッチパネルなど)を含む。ユーザは、操作部を操作することによって、種々の指示を貨幣処理装置80に与えることができる。
 上部基板852は、UI部を介してユーザの指示を受け付け、自身が対応する指示でなければ、受け付けた指示を対応する基板に転送する。これにより、指示に対応する基板は、当該指示に対応する処理を実行するように、入金部812、出金部813、識別部814、収納部83、搬送部84、一時保留部86、及び金庫外収納部840の少なくともいずれかへ信号を出力する。
 図6は、本実施形態の保守端末10、サーバ装置50、及び貨幣処理装置80の機能構成の一例を示すブロック図である。図6に示すように、保守端末10は、認証部101と、送信部103(第2送信部の一例)と、受信部105と、データ生成部107と、を含む。認証部101、送信部103、受信部105、及びデータ生成部107は、例えば、図2で説明した制御装置11、主記憶装置12、通信装置16、及びリーダ装置17などにより実現できる。例えば、制御装置11は、主記憶装置12(ROM)や補助記憶装置13に記憶されている本実施形態の保守プログラムを読み出して主記憶装置12(RAM)に展開する。制御装置11は、展開したプログラムに従って各種処理を実行することで、保守ソフトウェアとして、上述した各機能部を実現する。また、認証部101、送信部103、受信部105、及びデータ生成部107の少なくとも1つは、各種処理を実行する専用の回路であってもよい。
 また、図6に示すように、サーバ装置50は、認証情報受信部501と、認証制御部503と、送信部505(第1送信部の一例)と、データ受信部507と、セキュア処理部509と、鍵記憶部511と、を含む。認証情報受信部501、認証制御部503、送信部505、データ受信部507、及びセキュア処理部509は、例えば、図3で説明した制御装置51、主記憶装置52、及び通信装置56などにより実現できる。例えば、制御装置51は、主記憶装置52(ROM)や補助記憶装置53に記憶されている本実施形態のセキュア処理を行うためのプログラムや認証処理を制御するためのプログラムを読み出して主記憶装置52(RAM)に展開する。制御装置51は、展開したプログラムに従って各種処理を実行することで、上述した各機能部を実現する。鍵記憶部511は、例えば、図3で説明した補助記憶装置53などにより実現できる。認証情報受信部501、認証制御部503、送信部505、データ受信部507、及びセキュア処理部509の少なくとも1つは、各種処理を実行する専用の回路であってもよい。
 また、図6に示すように、貨幣処理装置80は、受信部891と、復号部893と、インストール部895と、貨幣識別部897と、を含む。受信部891、復号部893、及びインストール部895は、例えば、図5で説明した主基板855などにより実現でき、貨幣識別部897は、例えば、図5で説明した識別基板851などにより実現できる。例えば、基板は、基板に記憶したプログラムを実行することで、上述した各機能部を実現する。受信部891、復号部893、及びインストール部895の少なくとも1つは、各種処理を実行する専用の回路であってもよい。
 以下、シーケンス図及びフローチャートを適宜参照しながら、本実施形態の保守端末10、サーバ装置50、及び貨幣処理装置80の各機能部について説明する。
 図7は、本実施形態のシステム1で行われる保守員の認証処理の一例を示すシーケンス図である。
 保守端末10の認証部101は、保守員が所持するドングルであるハードウェアキー20を用いて保守員の正当性を認証する(ステップS101)。本実施形態では、ハードウェアキー20を用いた保守員の認証は、2要素認証であり、認証部101は、1要素目の認証を行うものとするが、保守員の認証方式は、これに限定されるものではない。ハードウェアキー20は、例えば、パスワード、2要素認証のための証明書及び秘密鍵などを記憶する。証明書としては、例えば、ハードウェアキー20を識別するドングルID(identification)及びハードウェアキー20を所持する保守員を識別するユーザIDなどが定義された情報などが挙げられる。
 例えば、保守員が保守端末10にログインし、ハードウェアキー20を保守端末10に接続して保守ソフトウェアを立ち上げ、パスワードを入力する。認証部101は、保守員により入力されたパスワードを受け付けるとともに、保守端末10に接続されたハードウェアキー20に記憶されているパスワードを読み出し、両パスワードを照合する。認証部101は、パスワードの照合に成功すれば、保守員の正当性の1要素目の認証に成功したと判定し、パスワードの照合に失敗すれば、保守員の認証に失敗したと判定する。
 但し、1要素目の認証は、上記パスワード照合に限定されるものではない。例えば、ハードウェアキー20を所持する者は、正当な保守員であると考え、認証部101は、ハードウェアキー20が保守端末10に接続されていることをもって、1要素目の認証に成功したと判定するようにしてもよい。
 保守端末10の送信部103は、認証部101による認証に成功した場合、保守端末10を使用して貨幣処理装置80の保守を行う保守員を認証するための保守員認証情報をサーバ装置50に送信する(ステップS103)。なお、ステップS101において、保守員の認証に失敗した場合、ステップS103以降の処理は行われない。
 保守員認証情報は、ハードウェアキー20に記憶された証明書を少なくとも含む。なお本実施形態では、2要素目の認証をチャレンジレスポンス方式で行うため、保守員認証情報は、ハードウェアキー20に基づくワンタイムパスワードを更に含むものとするが、これに限定されるものではない。
 つまり本実施形態では、保守員認証情報は、保守員のユーザID、保守員が所持するハードウェアキー20のドングルID、保守員が所持するハードウェアキー20に基づくワンタイムパスワードを含む。保守員のユーザID、ハードウェアキー20のドングルID、及びハードウェアキー20に基づくワンタイムパスワードは、いずれも保守員を識別する情報ではあるが、互いに異なる情報である。なお、保守員のユーザIDは、第1認証情報の一例であり、ハードウェアキー20のドングルIDは、第2認証情報の一例であり、ハードウェアキー20に基づくワンタイムパスワードは、第3認証情報の一例である。
 具体的には、送信部103は、保守員認証情報の送信に先立ち、サーバ装置50にチャレンジを要求する。サーバ装置50の認証情報受信部501は、保守端末10からチャレンジの要求を受信し、サーバ装置50の認証制御部503は、チャレンジを生成し、サーバ装置50の送信部505は、生成されたチャレンジを保守端末10に送信する。保守端末10の受信部105は、サーバ装置50からチャレンジを受信する。
 保守端末10の送信部103は、ハッシュ関数を用いて、サーバ装置50から受信したチャレンジのハッシュ値を算出し、ハードウェアキー20に記憶された秘密鍵を用いてハッシュ値を暗号化する。チャレンジのハッシュ値は、ハードウェアキー20に基づくワンタイムパスワードの一例である。送信部103は、暗号化されたチャレンジのハッシュ値とハードウェアキー20に記憶された証明書を含む保守員認証情報を生成し、サーバ装置50に送信する。
 サーバ装置50の認証情報受信部501は、保守端末10から保守員認証情報を受信する(ステップS103)。サーバ装置50の認証制御部503は、受信した保守員認証情報から暗号化されたチャレンジのハッシュ値を取得し、当該暗号化されたチャレンジのハッシュ値を用いた保守員の正当性の認証を制御する(ステップS105)。
 具体的には、認証制御部503は、ハードウェアキー20に記憶された秘密鍵の対となる公開鍵を用いて、暗号化されたチャレンジのハッシュ値を復号する。なお、公開鍵は、例えば、ドングルIDに対応付けられて後述の鍵記憶部511に記憶されているため、認証制御部503は、ドングルIDをキーにして鍵記憶部511から公開鍵を取得できる。また、認証制御部503は、ハッシュ関数を用いて、生成したチャレンジのハッシュ値を算出し、復号したハッシュ値と照合する。認証制御部503は、ハッシュ値の照合に成功すれば、保守員の正当性の2要素目の認証に成功したと判定し、ハッシュ値の照合に失敗すれば、保守員の認証に失敗したと判定する。
 なお、認証制御部503は、ハッシュ値の照合以外に、ハッシュ値の有効期限内に照合が行われていることや、保守員認証情報に含まれる証明書の正当性なども加味して保守員の2要素目の認証を行うようにしてもよい。
 また、認証制御部503は、保守員認証情報、及び第1クラウド40と異なる第2クラウド60上で提供される第1認証サービスを用いた保守員の認証を制御する。第1認証サービスは、例えば、第2クラウド60内で管理されている保守員DB63を用いた認証サービスであり、認証制御部503は、保守員が貨幣処理装置80に対する保守権限を有するか否かの認証を制御する。
 なお、認証情報受信部501は、後述の鍵記憶部511に記憶されている鍵の管理に用いられる第1管理端末30から、当該第1管理端末30を使用する第1管理者(管理者の一例)を認証するための管理者認証情報も受信する。この場合、認証制御部503は、管理者認証情報、及び第2クラウド60上で提供される第2認証サービスを用いて、第1管理者の認証処理を制御する。管理者認証情報は、第1管理者を識別するユーザIDを少なくとも含む。なお、第1管理者のユーザIDは、第1認証情報の一例である。第2認証サービスは、例えば、第2クラウド60内で管理されている管理者DB65を用いた認証サービスであり、認証制御部503は、第1管理者が鍵の管理権限を有するか否かの認証を制御する。
 ステップS105において、認証制御部503は、保守員の正当性の認証に成功した場合、保守員が貨幣処理装置80に対する保守権限を有するか否かの認証を制御する(ステップS107)。なお、ステップS105において、保守員の認証に失敗した場合、ステップS107以降の処理は行われない。また、保守員が保守権限を有するか否かの認証制御は、第1管理者が鍵の管理権限を有するか否かの認証制御と共通する部分が多分にあるため、図8に示すフローチャートを用いてまとめて説明する。
 図8は、本実施形態のシステム1で行われる保守員及び第1管理者の権限認証処理の一例を示すフローチャートである。
 認証制御部503は、保守員認証情報や管理者認証情報に含まれるユーザIDに基づいて、第1認証サービス及び第2認証サービスのいずれを認証に用いるかを決定する。具体的には、認証制御部503は、ユーザID及び認証先DB43を参照して、第1認証サービス及び第2認証サービスのいずれを認証に用いるかを決定する。また、認証制御部503は、認証情報の送信元に基づいて、第1認証サービス及び第2認証サービスのいずれを認証に用いるかを決定してもよい。具体的には、認証制御部503は、認証情報の送信元が保守端末10または保守ソフトウェアである場合は第1認証サービスを用い、認証情報の送信元が第1管理端末30または第1管理端末30で動作する管理ソフトウェアである場合は、第2認証サービスを用いると決定してもよい。
 図9は、本実施形態の認証先DB43に記憶されている情報の一例を示す図である。図9に示すように、認証先DB43は、ユーザIDと認証先情報と対応付けて記憶している。なお、図9に示す例では、第1管理者を示すユーザIDには、認証先情報として管理者DB65が対応付けられ、保守員を示すユーザIDには、認証先情報として保守員DB63が対応付けられている。
 認証制御部503は、ユーザIDをキーにして、認証先DB43からユーザIDに対応付けられた認証先情報を取得する(ステップS201)。認証制御部503は、取得した認証先情報が示すDBを用いる認証サービスを認証に用いることを決定する。具体的には、認証制御部503は、取得した認証先情報が保守員DB63を示す場合(ステップS203でYes)、第1認証サービスを用いることを決定する(ステップS205)。従って、図7に示すシーケンス図のステップS107では、認証制御部503は、保守員認証情報を用いた保守員の保守権限の認証については、第1認証サービスを認証に用いることを決定する。
 認証制御部503は、第1認証サービスを認証に用いることを決定した場合、保守員認証情報に含まれるドングルID(詳細には、証明書に定義されたドングルID)及び第1認証サービスを用いて、保守員の貨幣処理装置80に対する保守権限を有するか否かの認証を制御する。具体的には、認証制御部503は、ドングルID及び保守員DB63を参照して、保守員の貨幣処理装置80に対する保守権限を認証する。
 図10は、本実施形態の保守員DB63に記憶されている情報の一例を示す図である。図10に示すように、保守員DB63は、ユーザIDと、ドングルIDと、保守権限を有する貨幣処理装置の装置IDとを、対応付けて記憶している。なお、図10に示す例では、装置ID「貨幣処理装置A」が貨幣処理装置80を示すものとする。
 認証制御部503は、ドングルIDをキーにして、保守員DB63からドングルIDに対応付けられた装置IDを取得し、当該装置IDが示す貨幣処理装置に対する保守権限を有するか否かを認証する(ステップS207)。従って、図10に示す例では、ドングルIDが保守員Aを示す場合、認証制御部503は、貨幣処理装置80を示す装置ID「貨幣処理装置A」を取得するため、保守員Aが貨幣処理装置80に対する保守権限を有すると認証する。一方、ドングルIDが保守員Bを示す場合、認証制御部503は、貨幣処理装置80以外の貨幣処理装置80を示す装置ID「貨幣処理装置B」を取得するため、保守員Bは貨幣処理装置80に対する保守権限を有さないと認証する。なお、図7に示すシーケンス図のステップS107では、ドングルIDが保守員Aを示すため、認証制御部503は、保守員Aが貨幣処理装置80に対する保守権限を有すると認証するものとする。
 本実施形態では、保守員の保守権限が装置単位で設定されている場合を例にとり説明したが、これに限定されず、装置が有する機能単位で保守権限を設定してもよい。このようにすれば、貨幣処理装置に対する簡易な保守の権限は、幅広く保守員に与え、インストール権限など重要な保守の権限は、限られた保守員に与えるなど、保守員の保守権限を柔軟に設定できる。
 また本実施形態では、セキュリティを高めるため、保守権限の認証にドングルIDを用いたが、これに限定されず、ユーザIDを用いるようにしてもよい。なお、ドングルIDは、ハードウェアキー20に記憶されており、人目につくことが少ないため、ユーザIDに比べ秘匿性が高く、セキュリティが高くなる。
 一方、認証制御部503は、取得した認証先情報が管理者DB65を示す場合(ステップS203でNo)、第2認証サービスを用いることを決定する(ステップS209)。従って、本実施形態では、認証制御部503は、管理者認証情報を用いた第1管理者の鍵の管理権限の認証については、第2認証サービスを認証に用いることを決定する。
 認証制御部503は、第2認証サービスを認証に用いることを決定した場合、管理者認証情報に含まれるユーザID及び第2認証サービスを用いて、第1管理者が鍵の管理権限を有するか否かの認証を制御する。具体的には、認証制御部503は、ユーザIDを管理者認証装置67に通知し、管理者認証装置67が管理者DB65を用いて行った第1管理者の鍵の管理権限の認証結果を取得する。
 図11は、本実施形態の管理者DB65に記憶されている情報の一例を示す図である。図11に示すように、管理者DB65は、ユーザIDと鍵の管理権限情報とを対応付けて記憶している。
 認証制御部503は、ユーザIDを管理者認証装置67に通知する(ステップS211)。管理者認証装置67は、認証制御部503から通知されたユーザIDをキーにして、管理者DB65からユーザIDに対応付けられた鍵管理権限情報を取得し、第1管理者の鍵の管理権限を認証し(ステップS213)、認証結果を認証制御部503へ通知する(ステップS215)。従って、図11に示す例では、ユーザIDが管理者Aを示す場合、鍵の管理権限「あり」が取得されるため、認証制御部503は、管理者Aが鍵の管理権限を有するとの認証結果を取得する。一方、ユーザIDが管理者Bを示す場合、鍵の管理権限「無し」が取得されるため、認証制御部503は、管理者Bが鍵の管理権限を有さないとの認証結果を取得する。
 本実施形態では、第1管理者の鍵の管理権限が単純に有り無しで設定されている場合を例にとり説明したが、これに限定されず、貨幣処理装置の装置単位で鍵の管理権限を設定してもよい。
 図7に戻り、説明を続ける。認証制御部503は、ステップS107において、保守員が貨幣処理装置80に対する保守権限を有すると認証した場合、JWT(JSON Web Token)を発行する(ステップS109)。JWTは、例えば、保守員の正当性及び保守権限を有することが認証されたことを証明するトークンである。JWTは、例えば、後述のセキュア処理部509がインストール用のデータに対してセキュア処理を施す場合の認証など以降の認証を省略するために用いられる。なお、ステップS107において、保守権限を有さないと認証された場合、ステップS109以降の処理は行われない。
 サーバ装置50の送信部505は、認証制御部503による保守員認証情報を用いた認証結果として、認証制御部503により発行されたJWTを保守端末10に送信する(ステップS111)。なお、ステップS105において、保守員の認証に失敗した場合や、ステップS107において、保守権限を有さないと認証された場合、送信部505は、認証失敗を示す認証結果を保守端末10に送信する。また、送信部505は、認証制御部503による管理者認証情報を用いた認証結果については第1管理端末30に送信する。
 図12は、本実施形態のシステム1で行われるインストール処理の一例を示すシーケンス図である。
 保守端末10の受信部105がサーバ装置50から保守員認証情報を用いた認証の認証結果を受信すると、保守端末10の認証部101は、認証結果に応じた制御を行う。例えば、認証部101は、認証結果が認証失敗を示す場合、保守ソフトウェアを終了する。また例えば、認証部101は、認証部101は、認証結果がJWTである場合、インストール用のデータの生成など保守ソフトウェアの機能を利用可能とする。なお、保守権限の認証が機能単位で行われている場合には、保守員が権限を有する機能が利用可能となるように制御してもよい。
 データ生成部107は、保守員からの操作入力に応じて、貨幣処理装置80にインストールされるデータ(第1データの一例)であるインストール用のデータを生成する(ステップS301)。本実施形態では、前述の通り、インストール用のデータが貨幣の識別に用いられる識別データである場合を例にとり説明するが、これに限定されるものではない。
 図13は、本実施形態のデータ生成部107により生成されるインストール用のデータの一例を示す図である。図13に示すインストール用のデータは、貨幣処理装置80で現在使用されている識別データの各種閾値を更新するための新たな閾値が定義されたデータとなっている。図13に示すインストール用のデータでは、紙幣の金種及び搬送方向毎に、赤外線センサの出力を基に紙幣の真偽を判定するための閾値が定義されている。
 なお、図13に示すインストール用のデータは、図13では図示を省略しているが、赤外線センサだけでなく、磁気センサや厚み検知センサなどのセンサ毎に、真偽を判定するための閾値が定義されている。同様に、図13に示すインストール用のデータは、図13では図示を省略しているが、真偽判定だけでなく、金種判定についても金種を判定するための閾値が定義され、正損判定についても正損を判定するための閾値が定義されている。なお、インストール用のデータは、全ての閾値が新たな閾値である必要ではなく、現在使用されている識別データの閾値と同一の閾値が混在していてもよい。
 例えば、保守員は、実際に使用される貨幣を用いる流動テストを行いながら、データ生成部107を用いて、インストール用のデータを生成する。データ生成部107は、保守端末10と接続された貨幣処理装置80から、流動テストの結果を示すデータを受信し、インストール用のデータを生成してもよい。流動テストの結果は、例えば、テスト用紙幣を貨幣識別部897で識別した結果であってもよい。なお本実施形態では、データ生成部107がインストール用のデータを生成することには、保守員が予め生成したインストール用のデータを保守ソフトウェアに読み込ませることも含まれるものとする。
 保守端末10の送信部103は、データ生成部107により生成されたインストール用のデータ、貨幣処理装置80の装置ID、及びJWTをサーバ装置50に送信し、セキュア処理を要求する(ステップS303)。サーバ装置50のデータ受信部507は、保守端末10からインストール用のデータ、貨幣処理装置80の装置ID、及びJWTを受信する(ステップS303)。
 サーバ装置50のセキュア処理部509は、データ受信部507により受信されたインストール用のデータにセキュア処理を施して、セキュア化されたインストール用のデータ(第2データの一例)を生成する。具体的には、セキュア処理部509は、データ受信部507により受信されたJWTを認証し、インストール用のデータに対するセキュア処理の実行の可否を判定する(ステップS305)。セキュア処理部509は、例えば、JWTにより保守員の正当性及び保守権限を有することが認証されれば、インストール用のデータに対するセキュア処理の実行が可能であると判定する。つまり、セキュア処理部509は、認証制御部503による保守員の認証に成功した場合、セキュア化された更新用データを生成する。
 なお、セキュア処理部509は、鍵記憶部511に記憶されている鍵を用いてインストール用のデータにセキュア処理を施す。本実施形態では、セキュア処理部509は、セキュア処理として、前述のように、暗号化処理及び電子署名処理を施す。このため、鍵記憶部511は、暗号化処理用の鍵として共通鍵(第1の鍵の一例)、電子署名処理用の鍵として秘密鍵(第3の鍵の一例)を記憶する。なお本実施形態では、共通鍵及び秘密鍵が、貨幣処理装置単位で用意されている場合を例にとり説明するが、これに限定されるものではない。例えば、共通鍵及び秘密鍵の少なくともいずれかを貨幣処理装置のグループ単位で用意するようにしてもよい。また、鍵記憶部511は、前述した保守員の正当性の2要素目の認証に用いる公開鍵(暗号化されたチャレンジのハッシュ値を復号する公開鍵)についても記憶するようにしてもよい。
 図14は、本実施形態の鍵記憶部511に記憶されている情報の一例を示す図である。図14に示すように、鍵記憶部511は、IDと各種鍵とを対応付けて記憶している。図14に示す例では、前述したように、鍵記憶部511は、セキュア処理に用いる共通鍵及び秘密鍵だけでなく、保守員の正当性の1要素目の認証に用いる公開鍵も記憶している。鍵記憶部511は、セキュア処理に用いる鍵については、貨幣処理装置の装置IDに対応付けて共通鍵及び秘密鍵を記憶する。また、保守員の正当性の1要素目の認証に用いる鍵については、ドングルIDに対応付けて公開鍵を記憶する。
 セキュア処理部509は、データ受信部507により受信された装置IDをキーにして、鍵記憶部511から装置IDに対応付けられた共通鍵及び秘密鍵を取得する。セキュア処理部509は、取得した秘密鍵を用いてインストール用のデータの電子署名を生成し、取得した共通鍵を用いてインストール用のデータを暗号化する暗号化処理を施す。具体的には、セキュア処理部509は、ハッシュ関数を用いてインストール用のデータからハッシュ値を算出し、取得した秘密鍵を用いてハッシュ値を暗号化し、インストール用のデータの電子署名を生成する(ステップS307)。またセキュア処理部509は、取得した共通鍵を用いてインストール用のデータを暗号化する(ステップS309)。セキュア処理部509は、暗号化されたインストール用のデータに電子署名を付与して、セキュア化されたインストール用のデータとする。
 サーバ装置50の送信部505は、セキュア化されたインストール用のデータを保守端末10に送信し、保守端末10の受信部105は、当該セキュア化されたインストール用のデータを受信する(ステップS311)。
 保守端末10の送信部103は、受信したセキュア化されたインストール用のデータを貨幣処理装置80にインストールするために、保守員からの操作入力に応じて、当該セキュア化されたインストール用のデータを貨幣処理装置80に送信する(ステップS313)。貨幣処理装置80の受信部891は、保守端末10からセキュア化されたインストール用のデータを受信する(ステップS313)。
 貨幣処理装置80の復号部893は、受信部891により受信されたセキュア化されたインストール用のデータをインストール用のデータに復号する。本実施形態では、前述のように、貨幣処理装置80のセキュリティチップ880が、サーバ装置50に記憶されている暗号化処理用の共通鍵と共通の共通鍵(第2の鍵の一例)、及びサーバ装置50に記憶されている電子署名処理用の秘密鍵と対になる公開鍵(第4の鍵の一例)を記憶している。このため、復号部893は、セキュリティチップ880から共通鍵及び公開鍵を取得する。
 復号部893は、取得した共通鍵を用いて、セキュア化されたインストール用のデータからインストール用のデータを復号する。また、復号部893は、セキュア化されたインストール用のデータから電子署名を取得し、復号したインストール用のデータ、電子署名、及び取得した公開鍵を用いて、復号したインストール用のデータの完全性が保証されるか否かを判定する。具体的には、復号部893は、取得した共通鍵を用いて暗号化されたインストール用のデータを復号する(ステップS315)。また、復号部893は、取得した公開鍵を用いて電子署名からハッシュ値を復号するとともに、ハッシュ関数を用いて復号したインストール用のデータからハッシュ値を算出し、両ハッシュ値が一致するか否かを判定することで、復号したインストール用のデータの完全性を認証する(ステップS317)。
 貨幣処理装置80のインストール部895は、復号されたインストール用のデータを貨幣処理装置80にインストールする(ステップS319)。具体的には、インストール部895は、復号されたインストール用のデータの完全性が復号部893により保証された場合、当該復号されたインストール用のデータを貨幣処理装置80にインストールする。
 貨幣処理装置80の貨幣識別部897は、前述の識別データ(設定ファイル)を用いて、貨幣の金種、真偽、及び正損の少なくとも1つを含む貨幣の種類の識別処理を行う。識別データには、前述の通り各種閾値が定義されており、貨幣識別部897は、貨幣から検出した検出値と当該各種閾値を比較することで、識別処理を行う。
 本実施形態では、前述の通り、貨幣処理装置80にインストールされるインストール用のデータが上記識別処理に用いられる識別データ(設定ファイル)である場合を例に取り説明している。このため、インストール部895によりインストール用のデータが貨幣処理装置80にインストールされると、上記識別データ(設定ファイル)が更新され、貨幣識別部897は、更新された識別データ(設定ファイル)を用いて、識別処理を行うことになる。
 但し、インストール用のデータのインストールは、データの更新に限定されるものではなく、プログラムの更新であってもよいし、貨幣処理装置80への新たなデータやプログラムの設定であってもよい。また、インストール用のデータのインストールは、データやプログラムを所定の位置に配置するだけであってもよいし、OSの設定の追加や変更を含むものであってもよい。
 以上のように本実施形態では、貨幣処理装置にインストールされるデータにセキュア処理を施すセキュア処理機能をクラウド化している。このため、セキュア処理に用いる鍵をクラウド上で管理できるので、インストールされるデータそのもののセキュア性(例えば、機密性や完全性)を高められるとともに、インストールされるデータを生成する保守員を介した鍵の漏洩を防止できる。
 例えば、貨幣処理装置にインストールされるデータが貨幣の識別に用いられる識別データである場合、保守員は、貨幣処理装置の保守を行うため、上述の識別データの保守(更新等)を行える必要がある。一方、保守ソフトウェアに鍵を埋め込んでおき、保守端末上でセキュア処理を行えるようにしてしまうと、保守ソフトウェアが解析されることにより鍵が流出してしまうリスクがある。これに対し、本実施形態では、上述のようにセキュア処理機能をクラウド化しているため、インストールされるデータのセキュア性を高めたり、保守員を介した鍵の漏洩を防止できたりするだけでなく、保守員による保守作業の可用性も維持できる。従って本実施形態によれば、貨幣処理装置にデータをインストールするためのプロセスにおけるセキュリティを高めることができる。
 また、本実施形態では、貨幣処理装置にデータをインストールするなどの貨幣処理装置の保守権限を認証する権限認証機能もクラウド化し、セキュア処理機能とは別のクラウドサービスとして実現している。これにより、本実施形態のシステムでは、セキュア処理に用いる鍵と権限認証に用いる情報とを別々のクラウド環境で管理でき、権限なき者による貨幣処理装置への不正なインストールを防止しつつ、上記鍵及び情報の漏洩に対するシステムの堅牢性を高めている。
 また、本実施形態では、権限認証に2要素認証を用いているため、貨幣処理装置にデータをインストールするためのプロセスにおけるセキュリティをより高めることができる。
 また、本実施形態では、貨幣処理装置側でも、セキュア処理を復号するための鍵を金庫内のメモリやTPMで管理しているため、インストールされるデータそのもののセキュア性(例えば、機密性や完全性)を高められるとともに、鍵の漏洩を防止できる。
(変形例1)
 上記実施形態では、貨幣処理装置80のセキュリティチップ880に共通鍵及び公開鍵が記憶されており、共通鍵及び公開鍵が、貨幣処理装置80の備える金庫82内のメモリかつTPMに記憶されている場合について説明した。但し、貨幣処理装置80による共通鍵及び公開鍵の管理態様は、これに限定されるものではなく、例えば、共通鍵及び公開鍵は、貨幣処理装置80の備える金庫82内のメモリ又はTPMのいずれかに記憶されていればよい。また、共通鍵及び公開鍵の双方を同一の記憶部に記憶する必要は無く、例えば、いずれか一方の鍵を金庫82内のメモリやTPMに記憶するようにしてもよい。
 一般的には、共通鍵に比べ公開鍵の秘匿性の重要度は下がる傾向にある。本実施形態においても、公開鍵は、インストール用のデータの完全性を認証するためのものであるため、仮に公開鍵が貨幣処理装置80から漏洩したとしても、そのことが原因で不正なデータがインストールされる可能性は低い。このため、共通鍵を金庫82内のメモリやTPMに記憶し、公開鍵を金庫82内のメモリやTPM以外の記憶部に記憶するようにしてもよい。
(プログラム)
 上記実施形態及び上記変形例の各装置及び各端末で実行されるプログラムは、インストール可能な形式又は実行可能な形式のファイルでCD-ROM、CD-R、メモリカード、DVD、フレキシブルディスク(FD)等のコンピュータで読み取り可能な記憶媒体に記憶されて提供される。
 また、上記実施形態及び上記変形例の各装置及び各端末で実行されるプログラムを、インターネット等のネットワークに接続されたコンピュータ上に格納し、ネットワーク経由でダウンロードさせることにより提供するようにしてもよい。また、上記実施形態及び上記変形例の各装置及び各端末で実行されるプログラムを、インターネット等のネットワーク経由で提供または配布するようにしてもよい。また、上記実施形態及び上記変形例の各装置及び各端末で実行されるプログラムを、ROM等に予め組み込んで提供するようにしてもよい。
 上記実施形態及び上記変形例の各装置及び各端末で実行されるプログラムは、上述した各部をコンピュータ上で実現させるためのモジュール構成となっている。実際のハードウェアとしては、例えば、CPUがHDDから学習プログラムをRAM上に読み出して実行することにより、上記各部がコンピュータ上で実現されるようになっている。
 以上説明したとおり、上記実施形態及び上記変形例によれば、貨幣処理装置にデータをインストールするためのプロセスにおけるセキュリティを高めることができる。
 なお、上記実施形態及び上記変形例は、本開示を実施するにあたっての具体化の一例を示したものに過ぎず、これらによって本開示の技術的範囲が限定的に解釈されるものではない。従って本開示は、その要旨、またはその主要な特徴から逸脱することの無い範囲で、様々な形で実施することができる。例えば、上記実施形態及び上記各変形例は、それぞれ構成単位で適宜組み合わせてもよい。また例えば、上記実施形態及び上記各変形例において、全構成要素からいくつかの構成要素を削除してもよい。
 1 システム
 10 保守端末
 20 ハードウェアキー
 30 第1管理端末
 40 第1クラウド
 41 ファイアウォール
 43 認証先DB
 50 サーバ装置
 60 第2クラウド
 61 ファイアウォール
 63 保守員DB
 65 管理者DB
 67 管理者認証装置
 70 第2管理端末
 80 貨幣処理装置
 82 金庫
 101 認証部
 103 送信部
 105 受信部
 107 データ生成部
 501 認証情報受信部
 503 認証制御部
 505 送信部
 507 データ受信部
 509 セキュア処理部
 511 鍵記憶部
 821 第1金庫部
 822 第2金庫部
 851 識別基板
 855 主基板
 871 記憶装置
 880 セキュリティチップ
 881 記憶装置
 891 受信部
 893 復号部
 895 インストール部
 897 貨幣識別部
 

Claims (35)

  1.  貨幣を処理する貨幣処理装置を含むシステムであって、
     前記貨幣処理装置は、
     前記貨幣処理装置にインストールされる第1データを第1クラウド上でセキュア処理サービスを提供するサーバ装置に送信する保守端末を介して、前記サーバ装置が前記第1データにセキュア処理を施した第2データを受信する受信部と、
     前記第2データを前記第1データに復号する復号部と、
     復号された前記第1データを前記貨幣処理装置にインストールするインストール部と、を備える。
  2.  請求項1に記載のシステムであって、
     前記貨幣処理装置は、
     前記貨幣の金種、真偽、及び正損の少なくとも1つを含む前記貨幣の種類の識別処理を行う貨幣識別部を更に備え、
     前記第1データは、前記識別処理に用いられるデータである。
  3.  請求項2に記載のシステムであって、
     前記第1データは、前記識別処理において前記貨幣から検出される検出値と比較される閾値を含む。
  4.  請求項1~3のいずれか1項に記載のシステムであって、
     前記セキュア処理は、第1の鍵を用いた暗号化を行う暗号化処理を含み、
     前記貨幣処理装置は、
     前記第1の鍵と共通の第2の鍵を記憶する記憶部を更に備え、
     前記復号部は、前記第2の鍵を用いて、前記第2データを前記第1データに復号する。
  5.  請求項1~4のいずれか1項に記載のシステムであって、
     前記セキュア処理は、第3の鍵を用いて前記第1データの電子署名を生成する電子署名処理を含み、
     前記第2データは、前記電子署名を含み、
     前記貨幣処理装置は、
     前記第3の鍵と対になる第4の鍵を記憶する記憶部を更に備え、
     前記復号部は、前記第2データから前記第1データ及び前記電子署名を復号し、復号した前記第1データ、復号した前記電子署名、及び前記第4の鍵を用いて、復号した前記第1データの完全性が保証されるか否かを判定し、
     前記インストール部は、復号された前記第1データの完全性が保証された場合、当該第1データを前記貨幣処理装置にインストールする。
  6.  請求項4又は5に記載のシステムであって、
     前記記憶部は、前記貨幣処理装置が備える金庫内のメモリ及びTPM(Trusted Platform Module)の少なくともいずれかである。
  7.  請求項1~6のいずれか1項に記載のシステムであって、
     前記サーバ装置を更に備え、
     前記サーバ装置は、
     前記貨幣処理装置の保守に用いられる前記保守端末から前記第1データを受信するデータ受信部と、
     前記第1データに前記セキュア処理を施して前記第2データを生成するセキュア処理部と、
     前記第2データを前記保守端末に送信する第1送信部と、を備える。
  8.  請求項7に記載のシステムであって、
     前記サーバ装置は、
     前記保守端末から、当該保守端末を使用して前記貨幣処理装置の保守を行う保守員を認証するための保守員認証情報を受信する認証情報受信部と、
     前記保守員認証情報、及び前記第1クラウドと異なる第2クラウド上で提供される第1認証サービスを用いた前記保守員の認証を制御する認証制御部と、を更に備え、
     前記セキュア処理部は、前記保守員の認証に成功した場合、前記第2データを生成する。
  9.  請求項8に記載のシステムであって、
     前記サーバ装置は、
     鍵を記憶する鍵記憶部を更に備え、
     前記セキュア処理部は、前記鍵を用いて前記第1データに前記セキュア処理を施し、
     前記第1認証サービスは、前記第2クラウド内で管理されている保守員データベースを用いた認証サービスである。
  10.  請求項9に記載のシステムであって、
     前記鍵は、前記貨幣処理装置で管理されている第2の鍵と共通の第1の鍵を含み、
     前記セキュア処理は、前記第1の鍵を用いた暗号化を行う暗号化処理を含む。
  11.  請求項9又は10に記載のシステムであって、
     前記鍵は、前記貨幣処理装置で管理されている第4の鍵と対になる第3の鍵を含み、
     前記セキュア処理は、前記第3の鍵を用いて前記第1データの電子署名を生成する電子署名処理を含み、
     前記第2データは、前記電子署名を含む。
  12.  請求項9~11のいずれか1項に記載のシステムであって、
     前記認証情報受信部は、前記鍵の管理に用いられる管理端末から、当該管理端末を使用する管理者を認証するための管理者認証情報を更に受信し、
     前記認証制御部は、前記管理者認証情報、及び前記第2クラウド内で管理されている管理者データベースを用いた認証サービスである第2認証サービスを用いた前記管理者の認証を制御する。
  13.  請求項12に記載のシステムであって、
     前記保守員認証情報及び前記管理者認証情報は、第1認証情報を含み、
     前記保守員認証情報に含まれる前記第1認証情報は、前記保守員を識別する情報であり、
     前記管理者認証情報に含まれる前記第1認証情報は、前記管理者を識別する情報であり、
     前記認証制御部は、前記第1認証情報に基づいて、前記第1認証サービス及び前記第2認証サービスのいずれを認証に用いるかを決定する。
  14.  請求項13に記載のシステムであって、
     前記認証制御部は、前記第2認証サービスを認証に用いることを決定した場合、前記管理者認証情報に含まれる前記第1認証情報及び前記第2認証サービスを用いて、前記管理者が鍵の管理権限を有するか否かの認証を制御する。
  15.  請求項13又は14に記載のシステムであって、
     前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報とは異なる第2認証情報を更に含み、
     前記認証制御部は、前記第1認証サービスを認証に用いることを決定した場合、前記第2認証情報及び前記第1認証サービスを用いて、前記保守員が前記貨幣処理装置に対する保守権限を有するか否かの認証を制御する。
  16.  請求項15に記載のシステムであって、
     前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報及び第2認証情報とは異なる第3認証情報を更に含み、
     前記認証制御部は、更に、前記第3認証情報を用いて前記保守員の正当性の認証を制御する。
  17.  請求項16に記載のシステムであって、
     前記保守端末を更に備え、
     前記保守端末は、
     前記保守員が所持するハードウェアキーを用いて前記保守員の正当性を認証する認証部と、
     認証に成功した場合、前記保守員認証情報を前記サーバ装置に送信する第2送信部と、を備える。
  18.  請求項16又は17に記載のシステムであって、
     前記第2認証情報は、前記保守員が所持するハードウェアキーを識別する情報であり、
     前記第3認証情報は、前記保守員が所持するハードウェアキーに基づくワンタイムパスワードである。
  19.  請求項18に記載のシステムであって、
     前記認証制御部は、前記保守員の正当性及び前記保守権限を有することが認証された場合、JWT(JSON Web Token)を発行し、
     前記第1送信部は、前記JWTを前記保守端末に送信し、
     前記データ受信部は、前記保守端末から前記第1データ及び前記JWTを受信し、
     前記セキュア処理部は、前記JWTを認証し、前記第1データに対する前記セキュア処理の実行の可否を判定する。
  20.  第1クラウド上でセキュア処理サービスを提供するサーバ装置であって、
     貨幣処理装置の保守に用いられる保守端末から、前記貨幣処理装置にインストールされる第1データを受信するデータ受信部と、
     前記第1データにセキュア処理を施して第2データを生成するセキュア処理部と、
     前記第2データを前記保守端末に送信する送信部と、を備える。
  21.  請求項20に記載のサーバ装置であって、
     前記保守端末から、当該保守端末を使用して前記貨幣処理装置の保守を行う保守員を認証するための保守員認証情報を受信する認証情報受信部と、
     前記保守員認証情報、及び前記第1クラウドと異なる第2クラウド上で提供される第1認証サービスを用いて、前記保守員の認証を制御する認証制御部と、を更に備え、
     前記セキュア処理部は、前記保守員の認証に成功した場合、前記第2データを生成する。
  22.  請求項21に記載のサーバ装置であって、
     鍵を記憶する鍵記憶部を更に備え、
     前記セキュア処理部は、前記鍵を用いて前記第1データに前記セキュア処理を施し、
     前記第1認証サービスは、前記第2クラウド内で管理されている保守員データベースを用いた認証サービスである。
  23.  請求項22に記載のサーバ装置であって、
     前記鍵は、前記貨幣処理装置で管理されている第2の鍵と共通の第1の鍵を含み、
     前記セキュア処理は、前記第1の鍵を用いた暗号化を行う暗号化処理を含む。
  24.  請求項22又は23に記載のサーバ装置であって、
     前記鍵は、前記貨幣処理装置で管理されている第4の鍵と対になる第3の鍵を含み、
     前記セキュア処理は、前記第3の鍵を用いて前記第1データの電子署名を生成する電子署名処理を含み、
     前記第2データは、前記電子署名を含む。
  25.  請求項22~24のいずれか1項に記載のサーバ装置であって、
     前記認証情報受信部は、前記鍵の管理に用いられる管理端末から、当該管理端末を使用する管理者を認証するための管理者認証情報を更に受信し、
     前記認証制御部は、前記管理者認証情報、及び前記第2クラウド内で管理されている管理者データベースを用いた認証サービスである第2認証サービスを用いた前記管理者の認証を制御する。
  26.  請求項25に記載のサーバ装置であって、
     前記保守員認証情報及び前記管理者認証情報は、第1認証情報を含み、
     前記保守員認証情報に含まれる前記第1認証情報は、前記保守員を識別する情報であり、
     前記管理者認証情報に含まれる前記第1認証情報は、前記管理者を識別する情報であり、
     前記認証制御部は、前記第1認証情報に基づいて、前記第1認証サービス及び前記第2認証サービスのいずれを認証に用いるかを決定する。
  27.  請求項26に記載のサーバ装置であって、
     前記認証制御部は、前記第2認証サービスを認証に用いることを決定した場合、前記管理者認証情報に含まれる前記第1認証情報及び前記第2認証サービスを用いて、前記管理者が鍵の管理権限を有するか否かの認証を制御する。
  28.  請求項26又は27に記載のサーバ装置であって、
     前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報とは異なる第2認証情報を更に含み、
     前記認証制御部は、前記第1認証サービスを認証に用いることを決定した場合、前記第2認証情報及び前記第1認証サービスを用いて、前記保守員が前記貨幣処理装置に対する保守権限を有するか否かの認証を制御する。
  29.  請求項28に記載のサーバ装置であって、
     前記保守員認証情報は、前記保守員を識別する情報であって、前記第1認証情報及び第2認証情報とは異なる第3認証情報を更に含み、
     前記認証制御部は、更に、前記第3認証情報を用いて前記保守員の正当性の認証を制御する。
  30.  請求項29に記載のサーバ装置であって、
     前記第2認証情報は、前記保守員が所持するハードウェアキーを識別する情報であり、
     前記第3認証情報は、前記保守員が所持するハードウェアキーに基づくワンタイムパスワードである。
  31.  請求項30に記載のサーバ装置であって、
     前記認証制御部は、前記保守員の正当性及び前記保守権限を有することが認証された場合、JWT(JSON Web Token)を発行し、
     前記第1送信部は、前記JWTを前記保守端末に送信し、
     前記データ受信部は、前記保守端末から前記第1データ及び前記JWTを受信し、
     前記セキュア処理部は、前記JWTに基づいて、前記第1データに対する前記セキュア処理の実行の有無を判定する。
  32.  貨幣を処理する貨幣処理装置で実行されるインストール方法であって、
     前記貨幣処理装置にインストールされる第1データを第1クラウド上でセキュア処理サービスを提供するサーバ装置に送信する保守端末を介して、前記サーバ装置が前記第1データにセキュア処理を施した第2データを受信する受信ステップと、
     前記第2データを前記第1データに復号する復号ステップと、
     復号された前記第1データを前記貨幣処理装置にインストールするインストールステップと、を含む。
  33.  第1クラウド上でセキュア処理サービスを提供するサーバ装置で実行されるセキュア方法であって、
     貨幣処理装置の保守に用いられる保守端末から、前記貨幣処理装置にインストールされる第1データを受信するデータ受信ステップと、
     前記第1データにセキュア処理を施して第2データを生成するセキュア処理ステップと、
     前記第2データを前記保守端末に送信する送信ステップと、を含む。
  34.  貨幣を処理する貨幣処理装置で実行されるプログラムであって、
     貨幣を処理する貨幣処理装置にインストールされる第1データを第1クラウド上でセキュア処理サービスを提供するサーバ装置に送信する保守端末を介して、前記サーバ装置が前記第1データにセキュア処理を施した第2データを受信する受信ステップと、
     前記第2データを前記第1データに復号する復号ステップと、
     復号された前記第1データを前記貨幣処理装置にインストールするインストールステップと、
     を前記貨幣処理装置のコンピュータに実行させるためのプログラム。
  35.  第1クラウド上でセキュア処理サービスを提供するサーバ装置で実行されるプログラムであって、
     貨幣処理装置の保守に用いられる保守端末から、前記貨幣処理装置にインストールされる第1データを受信するデータ受信ステップと、
     前記第1データにセキュア処理を施して第2データを生成するセキュア処理ステップと、
     前記第2データを前記保守端末に送信する送信ステップと、
     を前記サーバ装置のコンピュータに実行させるためのプログラム。
     
PCT/JP2024/019592 2024-05-28 2024-05-28 システム、サーバ装置、インストール方法、セキュア方法、及びプログラム Pending WO2025248643A1 (ja)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/JP2024/019592 WO2025248643A1 (ja) 2024-05-28 2024-05-28 システム、サーバ装置、インストール方法、セキュア方法、及びプログラム

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2024/019592 WO2025248643A1 (ja) 2024-05-28 2024-05-28 システム、サーバ装置、インストール方法、セキュア方法、及びプログラム

Publications (1)

Publication Number Publication Date
WO2025248643A1 true WO2025248643A1 (ja) 2025-12-04

Family

ID=97869823

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2024/019592 Pending WO2025248643A1 (ja) 2024-05-28 2024-05-28 システム、サーバ装置、インストール方法、セキュア方法、及びプログラム

Country Status (1)

Country Link
WO (1) WO2025248643A1 (ja)

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005339049A (ja) * 2004-05-25 2005-12-08 Toshiba Corp 紙葉類処理システム
JP2007316694A (ja) * 2006-05-23 2007-12-06 Nec Access Technica Ltd 認証装置、電子機器、認証用プログラム
WO2010106665A1 (ja) * 2009-03-19 2010-09-23 グローリー株式会社 紙幣識別計数装置および紙幣識別計数方法
JP2011014080A (ja) * 2009-07-06 2011-01-20 Glory Ltd 貨幣識別装置のプログラム更新システム及び、貨幣識別装置のプログラム更新方法
JP2014505318A (ja) * 2011-02-11 2014-02-27 シーメンス・ヘルスケア・ダイアグノスティックス・インコーポレーテッド 安全なソフトウェアの更新のためのシステム及び方法
WO2016185989A1 (ja) * 2015-05-15 2016-11-24 グローリー株式会社 貨幣管理システム及び貨幣管理方法
US20210385093A1 (en) * 2019-02-26 2021-12-09 Shanghai Finanasia Inc. Digital signature terminal and secure communication method
US20230336991A1 (en) * 2021-04-02 2023-10-19 Vmware, Inc. System and method for establishing trust between multiple management entities with different authentication mechanisms

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2005339049A (ja) * 2004-05-25 2005-12-08 Toshiba Corp 紙葉類処理システム
JP2007316694A (ja) * 2006-05-23 2007-12-06 Nec Access Technica Ltd 認証装置、電子機器、認証用プログラム
WO2010106665A1 (ja) * 2009-03-19 2010-09-23 グローリー株式会社 紙幣識別計数装置および紙幣識別計数方法
JP2011014080A (ja) * 2009-07-06 2011-01-20 Glory Ltd 貨幣識別装置のプログラム更新システム及び、貨幣識別装置のプログラム更新方法
JP2014505318A (ja) * 2011-02-11 2014-02-27 シーメンス・ヘルスケア・ダイアグノスティックス・インコーポレーテッド 安全なソフトウェアの更新のためのシステム及び方法
WO2016185989A1 (ja) * 2015-05-15 2016-11-24 グローリー株式会社 貨幣管理システム及び貨幣管理方法
US20210385093A1 (en) * 2019-02-26 2021-12-09 Shanghai Finanasia Inc. Digital signature terminal and secure communication method
US20230336991A1 (en) * 2021-04-02 2023-10-19 Vmware, Inc. System and method for establishing trust between multiple management entities with different authentication mechanisms

Similar Documents

Publication Publication Date Title
EP3610607B1 (en) Cryptographic key management based on identity information
KR102197218B1 (ko) 분산 id와 fido 기반의 블록체인 신분증을 제공하는 시스템 및 방법
US8100323B1 (en) Apparatus and method for verifying components of an ATM
US9537857B1 (en) Distributed password verification
KR100806477B1 (ko) 리모트 액세스 시스템, 게이트웨이, 클라이언트 기기,프로그램 및 기억 매체
US8245042B2 (en) Shielding a sensitive file
US8608057B1 (en) Banking machine that operates responsive to data bearing records
US8555075B2 (en) Methods and system for storing and retrieving identity mapping information
US9900157B2 (en) Object signing within a cloud-based architecture
US20060253702A1 (en) Secure gaming server
US7922080B1 (en) Automated banking machine that operates responsive to data bearing records
KR102407432B1 (ko) 디지털 id 보관 및 연계 서비스 장치
TW200949603A (en) System and method for providing a system management command
Eludiora et al. A User Identity Management Protocol For Cloud Computing Paradigm.
US10158623B2 (en) Data theft deterrence
CN118872231A (zh) 用于恢复对远程服务器上的加密货币钱包的访问的概念
US11715079B2 (en) Maintaining secure access to a self-service terminal (SST)
WO2025248643A1 (ja) システム、サーバ装置、インストール方法、セキュア方法、及びプログラム
US20030061492A1 (en) Method and arrangement for a rights ticket system for increasing security of access control to computer resources
CN102833296A (zh) 用于构建安全的计算环境的方法和设备
JP2025152565A (ja) 有価媒体処理装置、有価媒体処理システム、および処理方法
CN120266113A (zh) 更新特定访客实例的安全访客元数据
CN113987461A (zh) 身份认证方法、装置和电子设备
CN110532754A (zh) 控制对外围存储设备的信息的访问的系统和方法
Hudson A Single Path Towards Achieving Information Privacy and Record Authentication

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24941809

Country of ref document: EP

Kind code of ref document: A1