Encoding device, and program and method for encoding
Abstract
Problem to be solved.To provide an encoding device capable of avoiding the unauthorized generation of encoded data.
Solution.A SAM 12 selects an encoding method from a number of different encoding methods based on device identifier data IDM in an IC 15 inputted from a computer 11. Based on a code "CODE" of the IC 15, SAM 12 selects code plaintext data encoded from among a number of different code plaintext data. SAM 12 outputs the encoded data of the selected code plaintext data which are encoded by the selected encoding method.
Copyright (C)2005,JPO&NCIPI
Term
Term ended
Projected expiry passed 9 January 2024, 2.7 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
10 claims: 3 independent, 7 dependent
- 1An encryption device that generates encrypted data based on the specified identification data, the first selection means for selecting an encryption method from a plurality of different encryption methods based on the identification data, and the identification. The second selection means for selecting the cipher plain text data to be encrypted from a plurality of different cipher plain text data based on the data, and the cipher plain text data selected by the second selection means are selected from the first. An encryption device having an encryption means for acquiring encrypted data encrypted by the encryption method selected by the selection means of the above. 指定された識別データを基に暗号データを生成する暗号化装置であって、 前記識別データを基に複数の異なる暗号化方法のなかから暗号化方法を選択する第1の選択手段と、 前記識別データを基に、複数の異なる暗号平文データのなかから暗号化対象とする暗号平文データを選択する第2の選択手段と、 前記第2の選択手段が選択した前記暗号平文データを、前記第1の選択手段が選択した前記暗号化方法で暗号化した暗号データを取得する暗号化手段と を有する暗号化装置。
- 9A program executed by a data processing device that generates encrypted data based on the specified identification data, and the first procedure for selecting an encryption method from a plurality of different encryption methods based on the identification data. The second step of selecting the cipher plain text data to be encrypted from a plurality of different cipher plain text data based on the identification data, and the cipher plain text data selected in the second step are the first. A program that causes the data processing device to execute a third step of acquiring encrypted data encrypted by the encryption method selected in step 1. 指定された識別データを基に暗号データを生成するデータ処理装置が実行するプログラムであって、 前記識別データを基に複数の異なる暗号化方法のなかから暗号化方法を選択する第1の手順と、 前記識別データを基に、複数の異なる暗号平文データのなかから暗号化対象とする暗号平文データを選択する第2の手順と、 前記第2の手順で選択した前記暗号平文データを、前記第1の手順で選択した前記暗号化方法で暗号化した暗号データを取得する第3の手順と を前記データ処理装置に実行させるプログラム。
- 10A first step of selecting an encryption method from a plurality of different encryption methods based on the identification data, which is a data processing method performed by a data processing device that generates encrypted data based on the specified identification data. The second step of selecting the cipher plain text data to be encrypted from a plurality of different cipher plain text data based on the identification data, and the cipher plain text data selected in the second step are described. A data processing method having a third step of acquiring encrypted data encrypted by the encryption method selected in the first step. 指定された識別データを基に暗号データを生成するデータ処理装置が行うデータ処理方法であって、 前記識別データを基に複数の異なる暗号化方法のなかから暗号化方法を選択する第1の工程と、 前記識別データを基に、複数の異なる暗号平文データのなかから暗号化対象とする暗号平文データを選択する第2の工程と、 前記第2の工程で選択した前記暗号平文データを、前記第1の工程で選択した前記暗号化方法で暗号化した暗号データを取得する第3の工程と を有するデータ処理方法。
Independent claims3
34 paragraphs, as filed
The present invention relates to an encryption device for generating encrypted data, a program thereof, and a method thereof.
For example, the authentication system authenticates using the encrypted data generated by the encryption device. Such an encryption device identifies the encrypted plain text data corresponding to the input data based on the correspondence table data showing the correspondence relationship between the input data and the encrypted plain text data, and encrypts the specified encrypted plain text data. To generate encrypted data. In the conventional encryption device, the above-specified encrypted plaintext data is encrypted by a predetermined single encryption method.
<p> However, since the conventional encryption device described above employs only a single encryption method, if the correspondence table data and the encryption method are illegally acquired, the encrypted data can be illegally generated. Therefore, in an authentication system using such an encryption device, there is a demand to prevent unauthorized generation of encrypted data and to improve the reliability of authentication.</p><p> The present invention has been made in view of such circumstances, and an object of the present invention is to provide a cryptographic device, a program thereof, and a data processing device thereof that can effectively avoid unauthorized generation of encrypted data. To do.</p>
<p> In order to achieve the above object, the encryption device of the first invention is an encryption device that generates encrypted data based on the specified identification data, and a plurality of different encryption methods based on the identification data. A first selection means for selecting an encryption method from among the above, a second selection means for selecting an encryption plain text data to be encrypted from a plurality of different encrypted plain text data based on the identification data, and a second selection means. It has an encryption means for acquiring the encrypted plain text data selected by the second selection means and encrypted by the encryption method selected by the first selection means.</p><p> The operation of the encryption device of the first invention is as follows. First, the first selection means selects an encryption method from a plurality of different encryption methods based on the identification data. Further, the second selection means selects the encrypted plaintext data to be encrypted from among a plurality of different encrypted plaintext data based on the identification data. Next, the encryption means acquires the encrypted plaintext data selected by the second selection means and the encrypted data encrypted by the encryption method selected by the first selection means.</p><p> The program of the second invention is a program executed by a data processing device that generates encrypted data based on the specified identification data, and is an encryption method from among a plurality of different encryption methods based on the identification data. The first step of selecting the above, the second step of selecting the cipher plain text data to be encrypted from among a plurality of different cipher plain text data based on the identification data, and the second step of the above selection. The data processing apparatus is made to execute the third procedure of acquiring the encrypted data encrypted by the encryption method selected in the first procedure from the encrypted plain text data.</p><p> The operation of the program of the second invention is as follows. According to the first procedure of the program, the data processing device selects an encryption method from a plurality of different encryption methods based on the identification data. Further, according to the second procedure, the data processing device selects the encrypted plaintext data to be encrypted from a plurality of different encrypted plaintext data based on the identification data. Next, according to the third procedure, the data processing device acquires the encrypted plaintext data selected in the second procedure and encrypted by the encryption method selected in the first procedure. ..</p><p> The data processing method of the third invention is a data processing method performed by a data processing apparatus that generates encrypted data based on the designated identification data, and is among a plurality of different encryption methods based on the identification data. The first step of selecting an encryption method, the second step of selecting the encrypted plain text data to be encrypted from among a plurality of different encrypted plain text data based on the identification data, and the second step of the above. It has a third step of acquiring the encrypted data encrypted by the encryption method selected in the first step from the encrypted plain text data selected in the above.</p><p> The operation of the data processing method of the third invention is as follows. In the first step, the data processing apparatus selects an encryption method from a plurality of different encryption methods based on the identification data. Further, in the second step, the data processing device selects the encrypted plaintext data to be encrypted from among a plurality of different encrypted plaintext data based on the identification data. Next, in the third step, the data processing device acquires the encrypted plaintext data selected in the second step and encrypted by the encryption method selected in the first step. ..</p>
<p> According to the present invention, it is possible to provide a cryptographic device, a program thereof, and a data processing device thereof that can avoid unauthorized generation of cryptographic data.</p>
Hereinafter, the card system according to the embodiment of the present invention will be described.<u style="single">1st Embodiment</u> FIG. 1 is a configuration diagram of the card system 1 of the present embodiment. As shown in FIG. 1, for example, the card system 1 cooperates with each other after the IC (Integrated Circuit) 15 of the IC card 10 and the SAM (Secure Application Module) 12 authenticate via the computer 11. Perform processing related to services. Here, the SAM 12 corresponds to the encryption device of the present invention, and the IC 15 corresponds to the output source of the present invention.
As will be described later, the IC15 stores data related to various services received by the user of the IC15 using the SAM12 and file data of a program, and usage authority is set for the service using the file data. The SAM 12 inputs the device identification data IDM unique to the IC 15 and the code CODE for identifying the service to be authenticated (the designated service to be received using the IC 15) from the IC 15 via the computer 11. The SAM12 selects an encryption method from a plurality of different encryption methods based on the device identification data IDM. Further, the SAM12 selects the encrypted plaintext data to be encrypted from among a plurality of different encrypted plaintext data based on the code CODE. Then, the SAM 12 outputs the encrypted plain text data selected above and the encrypted data encrypted by the selected encryption method to the IC 15. SAM12 and IC15 perform authentication based on the above encrypted data, and on condition that mutual validity is confirmed, IC15 and SAM12 cooperate with each other to perform processing related to the above service.
Hereinafter, each component shown in FIG. 1 will be described. [IC15] FIG. 2 is a configuration diagram of the IC15 built in the IC card 10 shown in FIG. As shown in FIG. 2, the IC 15 has, for example, an interface 21, a memory 22, and a CPU 23, which are connected via the internal bus 20. The IC 15 is, for example, an anti-tamper electronic circuit, and has a configuration in which the data stored in the memory 22 and the data being processed by the CPU 23 cannot be monitored and tampered with from the outside (difficult). The interface 21 inputs and outputs data to and from the SAM 12 via the computer 11.
As shown in FIG. 3, the memory 22 stores the device identification data IDM unique to each IC card 10. Further, the memory 22 stores data used for processing related to various services received by the user of the IC 15 using the SAM 12 and file data of the program. For example, the memory 22 stores the system code SYS_C, the area code AR_C, and the service code SER_C, as shown in FIG. The system code SYS_C, area code AR_C and service code SER_C are output to SAM12 via computer 11 as code CODE. In this embodiment, the code CODE is used to identify the target of authentication according to the service specified by the user. The system code SYS_C is identification data commonly assigned to SAM12 belonging to the same system, and IC15 and SAM12 mutually authenticate based on the system code SYS_C and the key data associated with the system code SYS_C, and their validity of each other. Access to IC15 by SAM12 is permitted on condition that is confirmed. Further, the file data of various services stored in the memory 22 are stored in an area which is a folder having a hierarchical structure. Further, each area is associated with an area code AR_C for identifying the area and key data. In this embodiment, access to the area by SAM12 is performed on condition that IC15 and SAM12 perform mutual authentication based on the area code AR_C and the key data associated with the area code AR_C and their validity is confirmed. Allowed. Further, the file data for providing various services stored in the area is associated with the service code SER_C for identifying the file data and the key data. In the present embodiment, the service code SER_C and the key data associated with the service code SER_C are mutually authenticated based on the IC15 and the SAM12, and the file data by the SAM12 is subjected to the condition that the validity of each is recognized. Access is granted.
The CPU 23 exchanges data with the SAM 12 via the interface 21 and the computer 11 based on the program read from the memory 22 and the key data, and performs mutual authentication with the SAM 12. Further, when the CPU 23 confirms the validity of each other by the above mutual authentication, the CPU 23 cooperates with the SAM 12 to execute the process related to the service associated with the key data used in the mutual authentication.
[Computer 11] For example, when the computer 11 receives a service instruction from the user of the IC card 10 via an operation unit (not shown), the computer 11 reads the device identification data IDM and the code CODE from the IC 15 of the IC card 10 and sends them to the SAM 12. Output. The code CODE is the system code SYS_C, the area code AR_C corresponding to the service instructed above, and the service code SER_C. In the present embodiment, when a predetermined service is specified according to the operation of the computer 11 by the user, the computer 11 inputs, for example, the system code SYS_C of the IC 15 from the IC 15 as a code CODE, and outputs this to the SAM 12. .. Then, when the validity of each other is confirmed by mutual authentication using the system code SYS_C between IC15 and SAM12, the computer 11 subsequently stores the file data related to the specified service. Is specified, and the area code AR_C of the specified area is input from IC15. Then, when the validity of each other is confirmed by mutual authentication using the area code AR_C between IC15 and SAM12, the computer 11 subsequently receives the service associated with the file data related to the specified service. Enter the code SER_C from IC15. Then, when the validity of each other is confirmed by mutual authentication using the service code SER_C between IC15 and SAM12, the IC15 and SAM12 cooperate with each other based on the file data to process the predetermined service. Is done.
[SAM12] FIG. 4 is a configuration diagram of SAM12 shown in FIG. As shown in FIG. 4, the SAM 12 has, for example, an interface 30, an encryption method selection unit 31, a ciphertext selection unit 32, and an encryption unit 33. In the present embodiment, the interface 30, the encryption method selection unit 31, the encryption plaintext selection unit 32, and the encryption unit 33 are realized by, for example, an electronic circuit. Here, the encryption method selection unit 31 corresponds to the first selection means of the first invention, the encryption plaintext selection unit 32 corresponds to the second selection means of the second invention, and the encryption unit 33 corresponds to the second selection means. It corresponds to the encryption means of the invention of 1. The SAM12 is, for example, a tamper-resistant electronic circuit, and has a configuration in which the data stored in the SAM12 and the data being processed cannot be monitored and tampered with from the outside (difficult).
The interface 30 outputs the device identification data IDM (first identification data of the present invention) input from the computer 11 to the encryption method selection unit 31. Further, the interface 30 outputs the code CODE (second identification data of the present invention) input from the computer 11 to the ciphertext selection unit 32. Further, the interface 30 outputs the encrypted data ED input from the encryption unit 33 to the computer 11.
As shown in FIG. 5A, the encryption method selection unit 31 has a correspondence table data TDA indicating the corresponding encryption methods M1 to Mn for each of the plurality of device identification data IDM1 to IDMn. The encryption method selection unit 31 selects one or more encryption methods M1 to Mn corresponding to the device identification data IDM input from the interface 30 based on the correspondence table data TDA shown in FIG. 5 (A). The selection data S31 indicating the selected encryption method is output to the encryption unit 33. All or part of the above encryption methods M1 to Mn are different encryption methods, for example, a public key cryptosystem and a common key cryptosystem. Further, all or a part of the above encryption methods M1 to Mn differ from each other in, for example, the encryption strength and the amount of encryption processing (burden). Such a difference is realized, for example, by using key data of different data lengths for encryption. As an example, since narrow bandwidth is required for the device identification data IDM of the IC15 incorporated in a mobile phone device or the like that performs wireless communication, a common key encryption method is associated as an encryption method. In addition, since it is prioritized to realize high security for the device identification data IDM of the IC 15 incorporated in the IC card 10 for making payments, a public key cryptosystem is associated as an encryption method. The encryption method of the present embodiment may be a process of editing the encrypted plaintext data P in addition to the encryption process performed based on the private key data, the public key data, the common key data, and the like.
As shown in FIG. 5 (B), the ciphertext selection unit 32 has a correspondence table data TDB indicating the ciphertext data P1 to Pm corresponding to each of the plurality of code CODEs. The encrypted plaintext data P1 to Pm are, for example, mutually different data. The ciphertext selection unit 32 selects the ciphertext data P1 to Pm corresponding to the code CODE input from the interface 30 based on the correspondence table data TDB shown in FIG. 5 (B), and selects the selected ciphertext data P. Output to the encryption unit 33.
The encryption unit 33 encrypts the encrypted plain text data P input from the encrypted plain text selection unit 32 by the encryption method indicated by the selection data S31 input from the encryption method selection unit 31 to generate the encrypted data ED, and generates the encrypted data ED. Output to interface 30.
An operation example of the card system 1 shown in FIG. 1 will be described below. Step ST1: The user of the IC card 10 inputs an instruction of a service to be received by using the IC card 10 through an operation unit (not shown) of the computer 11. Step ST2: The computer 11 reads the device identification data IDM and the code CODE corresponding to the instruction from the memory 22 of the IC 15 of the IC card 10 shown in FIG. 2 in response to the instruction input in step ST1, and outputs this to the SAM 12. To do. The SAM 12 outputs the device identification data IDM input via the interface 30 shown in FIG. 4 to the encryption method selection unit 31. Further, the SAM 12 outputs the code CODE input via the interface 30 to the ciphertext selection unit 32.
Step ST3: The encryption method selection unit 31 selects the encryption methods M1 to Mn corresponding to the device identification data IDM input in step ST2 based on the correspondence table data TDA shown in FIG. 5 (A), and selects the encryption method M1 to Mn. The selected data S31 indicating the encrypted encryption method is output to the encryption unit 33. Step ST4: The ciphertext selection unit 32 selects the ciphertext data P1 to Pm corresponding to the code CODE input in step ST2 based on the correspondence table data TDB shown in FIG. 5 (B), and the selected ciphertext data P1 to Pm. Data P is output to the encryption unit 33.
Step ST5: The encryption unit 33 encrypts the encryption plain text data P input from the encryption plain text selection unit 32 in step ST4 by the encryption method indicated by the selection data S31 input from the encryption method selection unit 31 in step ST3. Generate cryptographic data ED. Step ST6: The encryption unit 33 outputs the encrypted data ED generated in step ST5 to the computer 11 via the interface 30. The computer 11 outputs the input encrypted data ED to the IC 15. Step ST7: CPU23 of IC15 decrypts the encrypted data ED input in step ST6 with the corresponding key data to generate decrypted data. Further, the CPU 23 encrypts the decrypted data based on a predetermined key data to generate encrypted data. The CPU 23 outputs the encrypted data to the SAM 12 via the interface 21 and the computer 11. Step ST8: SAM12 authenticates the validity of IC15 based on the encrypted data input from IC15 in step ST7.
As described above, according to SAM12, as described in FIGS. 4 and 5, in addition to selecting the encrypted plaintext data P1 to Pm corresponding to each code CODE, each device identification data IDM is supported. Select the encryption method M1 to Mn. Therefore, even if the code CODE is the same, if the device identification data IDM is different, the encrypted data ED obtained by encrypting the code CODE is different. Therefore, even if the correspondence table data TDB is illegally leaked, the encrypted plaintext data P cannot be specified by which encryption method, and the encrypted data ED cannot be illegally generated. This makes it possible to increase the reliability of the authentication between SAM12 and IC15.
<u style="single">Modification example of the first embodiment</u> In the above-described embodiment, the device identification data IDM unique to each IC card 10 is illustrated as the first identification data of the present invention, but other identification indicating the security level of authentication performed with the IC card 10 is shown. It may be data or identification data specified according to the processing load of the authentication. That is, in addition to the identification data unique to each IC card 10, the identification data shared by the plurality of IC cards 10 may be used as the first identification data of the present invention. Further, in the above-described embodiment, the encryption performed by the encryption unit 33 based on the selection data S31 generated by the encryption method selection unit 31 is, for example, an individual program in which the encryption unit 33 describes a plurality of encryption methods in advance. The program is selected based on the selected data S31, and the selected data S31 indicating the encryption method script selected by the encryption method selection unit 31 is output to the encryption unit 33 to be output to the encryption unit 33. 33 may interpret and execute the script.
Further, the encryption method selection unit 31 generates selection data S31 indicating a plurality of encryption methods and their processing order, not a single encryption method among the encryption methods M1 to Mn, and uses this as the encryption unit 33. It may be output to. In this case, the encryption unit 33 performs encryption processing on the encrypted plaintext data P input from the encryption plaintext selection unit 32 in the processing order specified by the selection data S31 by a plurality of specified encryption methods. To generate encrypted data ED.
<u style="single">Second Embodiment</u> In the first embodiment described above, the encryption unit 33 of the SAM 12 actually uses the encryption method indicated by the selection data S31 input from the encryption method selection unit 31 to input the encryption plain data P from the encryption plain selection unit 32. An example is shown in which encryption is performed to generate encrypted data ED. The encryption unit 33a of the SAM 12a of the present embodiment holds in advance the encrypted data when the encrypted plain data is encrypted by each of the encryption methods M1 to Mn for each of the encrypted plain data P1 to Pm, and encrypts the encrypted plain data. Based on the plain text data and the selected data S31, the corresponding encrypted data is acquired. That is, the encryption unit 33a does not perform the encryption data generation process after inputting the encrypted plaintext data P and the selected data S31.
FIG. 8 is a configuration diagram of the SAM 12a of the present embodiment. As shown in FIG. 8, the SAM12a includes, for example, an interface 30, an encryption method selection unit 31, a ciphertext selection unit 32, and an encryption unit 33a. In the present embodiment, the encryption unit 33a is realized by, for example, an electronic circuit, similarly to the interface 30, the encryption method selection unit 31 and the encryption plaintext selection unit 32. Here, the interface 30, the encryption method selection unit 31 and the encryption plaintext selection unit 32 having the same reference numerals as those in FIG. 4 are the same as those in the first embodiment. Hereinafter, the encryption unit 33a will be described. The encryption unit 33a has the correspondence table data TDC. FIG. 9 is a diagram for explaining the correspondence table data TDC shown in FIG. In the correspondence table data TDC shown in FIG. 9, the row direction indicates the encrypted plain text data P, the column direction indicates the encryption method M, and the encrypted plain text data P corresponding to the row is set at the address specified by the row and the column. It holds the encrypted data PM obtained by encrypting with the encryption method M corresponding to the column. That is, the correspondence table data TDC defines the encrypted data when the encrypted plaintext data is encrypted by each of the encryption methods M1 to Mn for each of the encrypted plaintext data P1 to Pm.
The encryption unit 33a refers to the correspondence table data TDC shown in FIG. 9, and refers to the encryption plain text data Px input from the encryption plain text selection unit 32 and the encryption method indicated by the selection data S31 input from the encryption method selection unit 31. Acquires the encrypted data PM corresponding to My and outputs it to the interface 30 as the encrypted data ED. Here, x is any integer from 1 to m, and y is any integer from 1 to n. The card system of the present embodiment is the same as the card system 1 described in the first embodiment except for the configuration and operation of the encryption unit 33a described above.
According to the present embodiment, since the encryption unit 33a acquires the encryption data ED based on the correspondence table data TDC and does not perform the encryption data ED generation processing, the processing time of the encryption unit 33a can be shortened and the encryption is performed. The conversion unit 33a can be easily and small-scalely configured.
<u style="single">Modification example of the second embodiment</u> In the second embodiment described above, for all of the encrypted plain text data P1 to Pm, a correspondence table data TDC that defines the encrypted data when the encrypted plain text data is encrypted using all of the encryption methods M1 to Mn is exemplified. However, for at least one of the encrypted plain text data P1 to Pm and the encryption method M1 to Mn, a correspondence table data TDC that specifies only a part of the encrypted plain text data or the encrypted data corresponding to the encryption method may be used. In this case, the encryption unit 33a defines the encryption data corresponding to the selection data S31 input from the encryption method selection unit 31 and the encryption plain data P input from the encryption plain text selection unit 32 in the correspondence table data TDC. If it is determined that, the encrypted data is acquired based on the correspondence table data TDC, and if it is determined that it is not specified in the correspondence table data TDC, the encrypted plain text is encrypted by the encryption method indicated by the selected data S31 without using the correspondence table data TDC. Data P is actually encrypted and generated.
Further, in the second embodiment, as in the case of the modification of the first embodiment, the encryption method selection unit 31 is not a single encryption method among the encryption methods M1 to Mn, but a plurality of encryption methods. And the selection data S31 indicating the processing order may be generated and output to the encryption unit 33a. In this case, the encryption unit 33a performs the encryption processing of the encrypted plaintext data P input from the encryption plaintext selection unit 32 by the specified plurality of encryption methods in the processing order specified by the selection data S31. To generate encrypted data ED. In the process of sequentially performing encryption processing by a plurality of encryption methods in this way, the encryption unit 33a, when the corresponding encrypted data is specified in the correspondence table data TDC, starts with the correspondence table data TDC. If it is not specified, the encryption result up to that point is not canceled, and the encrypted data not specified in the corresponding table data TDC that follows is actually encrypted using the encryption result. Generate.
Further, in the second embodiment, the encryption unit 33a may further encrypt the encryption data acquired from the correspondence table data TDC by a predetermined encryption method to generate the encryption data ED. In addition, such encryption may be introduced at the time of upgrade.
The present invention is not limited to the embodiments described above. In the above-described embodiment, the case where the encryption method selection unit 31, the encryption plaintext selection unit 32, and the encryption units 33, 33a are realized as electronic circuits has been illustrated, but all or a part of them is processed by data processing of a computer or the like. This may be achieved by the device performing the corresponding steps in the program. In this case, for example, the procedures of steps ST3, ST4, and ST5 shown in FIG. 6 are described by a program, and the data processing apparatus executes the steps, so that the first procedure and the second procedure of the second invention are performed. And the third step is realized.
Further, in the above-described embodiment, the IC15 of the IC card 10 is exemplified as the authentication destination of the present invention (output source of the present invention), but the authentication destination may be a computer or the like.
<figref num="1">FIG. 1 is a block diagram of a card system according to a first embodiment of the present invention.</figref><figref num="2">FIG. 2 is a configuration diagram of an IC built in the IC card shown in FIG.</figref><figref num="3">FIG. 3 is a diagram for explaining the data defined in the IC shown in FIG.</figref><figref num="4">FIG. 4 is a functional block diagram of the SAM shown in FIG.</figref><figref num="5">FIG. 5 (A) is a diagram for explaining the correspondence table data TDA held by the encryption method selection unit shown in FIG. 4, and FIG. 5 (B) is a correspondence table data TDB held by the encryption plaintext selection unit shown in FIG. It is a figure for demonstrating.</figref><figref num="6">FIG. 6 is a flowchart for explaining an operation example of the card system shown in FIG.</figref><figref num="7">FIG. 7 is a continuation flowchart of FIG. 6 for explaining an operation example of the card system shown in FIG.</figref><figref num="8">FIG. 8 is a configuration diagram of a SAM of a card system according to the first embodiment of the present invention.</figref><figref num="9">FIG. 9 is a diagram for explaining the correspondence table data TDC held by the encryption unit shown in FIG.</figref>
Code description
1 ... card system, 10 ... IC card, 11 ... computer, 12,12a ... SAM, 20 ... internal bus, 21 ... interface, 22 ... memory, 23 .. .CPU, 30 ... interface, 31 ... encryption method selection part, 32 ... encryption plain text selection part, 33,33a ... encryption part
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2014042244A | Cited by | Japan | Examiner |
| JP2000036015A | Cites | Japan | Search report |
| JPH0830745A | Cites | Japan | Search report |
| JPH09179950A | Cites | Japan | Search report |
| JPH09179951A | Cites | Japan | Search report |
| JPH1115940A | Cites | Japan | Search report |
| JPS6481087A | Cites | Japan | Search report |
7 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004004827 | Japan | A | |
| JP20040004827 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| CN1638327A | China | A | |
| JP2005198211AThis record | Japan | A | |
| SG113551A1 | Singapore | A1 | |
| US2005207570A1 | United States of America | A1 | |
| CN100466512C | China | C | |
| JP4696449B2 | Japan | B2 | |
| US8079078B2 | United States of America | B2 |
18 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of patent or utility model registrationJAPANESE INTERMEDIATE CODE: R151R151 | R151 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2005198211
- Publication, DOCDB
- 2005198211
- Publication, EPODOC
- JP2005198211
- Application
- 4827
- Application, DOCDB
- 2004004827
- Application, EPODOC
- JP20040004827
Titles3
- English
- Cryptographic device, its program and its method
- Japanese
- 暗号化装置、そのプログラムおよびその方法
- English
- ENCODING DEVICE, AND PROGRAM AND METHOD FOR ENCODING
Classification
- CPC, 56
- H04J13/12
- G06F21/6245
- H04L2209/127
- G06Q20/10
- H04L9/32
- G06Q20/1235
- H04L67/306
- G06Q20/385
- G06Q20/401
- G07F17/16
- G06Q20/425
- G06Q30/0277
- G06Q30/0609
- G06Q50/188
- H04B7/0604
- H04B7/084
- H04B7/0894
- H04B7/15507
- H04B7/15535
- H04L1/0041
- H04L1/0045
- H04L1/0066
- H04L1/0069
- H04L1/0071
- H04L1/06
- H04L1/08
- H04L1/1819
- H04L1/1841
- H04L1/1845
- H04L1/1848
- H04L5/0023
- H04L5/0042
- H04L5/0044
- H04L5/0083
- H04L63/0428
- H04L27/2602
- H04L63/065
- H04L47/10
- H04L63/102
- H04L47/14
- H04L47/28
- H04W28/14
- H04L47/34
- H04W52/143
- H04W52/225
- H04W52/24
- H04W52/241
- H04L67/14
- H04W52/242
- H04W52/245
- H04L2001/0096
- H04W52/46
- Y10S707/99933
- Y10S707/99936
- Y10S707/99939
- H04W8/04
- IPC, 37
- H03M13 27
- G06F21 00
- G06Q10 00
- G06Q20 10
- G06Q20 12
- G06Q20 38
- G06Q20 40
- G06Q20 42
- G06Q30 00
- G06Q30 02
- G06Q30 06
- G06Q50 18
- G07F17 16
- G09C1 00
- H03M13 23
- H03M13 29
- H04B1 00
- H04B7 005
- H04B7 02
- H04B7 06
- H04B7 08
- H04B7 216
- H04B7 26
- H04B14 04
- H04J13 12
- H04K1 00
- H04L1 00
- H04L1 06
- H04L1 08
- H04L1 18
- H04L9 06
- H04L9 10
- H04L9 14
- H04L9 32
- H04L12 56
- H04L27 26
- H04L69 40