Information processing terminal and information safety protecting method therefor
Abstract
[Subject] It enables it to prevent disclosure of code information, using a common keyboard in code information inputting and the input of other information adopting a versatile OS and offering the development environment of free application software. [Solution means] While the control mechanism 23, and the 1st and 2nd information processing mechanisms 21 and 22 and the control mechanism 23 are constituted by another object, Have the trigger detection parts 13 and 11a, and the protection feature 10 for aiming at the safety of information and protection in execution of the 2nd application is offered, When the control mechanism 23 detects the above-mentioned trigger operation in the trigger detection parts 13 and 11a, while restricting execution of the 1st application, it constitutes so that the execution control department 23a which operates the 1st and 2nd information processing mechanism 21 and 22 that execution should be shifted to the 2nd application may be offered. [Selection figure] Fig. 3
Term
Term ended
Projected expiry passed 31 March 2024, 2.5 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
6 claims: 2 independent, 4 dependent
- 1The first information processing mechanism that can execute a general-purpose first application, the second information processing mechanism that can execute a second application that requires information security and protection, and the processing in the above first and second information processing mechanisms. The management mechanism to be managed and the above-mentioned first and second information processing mechanisms and the management mechanism are separately configured, and the trigger operation for activating the above-mentioned second information processing mechanism is detected and the management thereof is performed. When the management mechanism detects the trigger operation by the trigger detection unit, which has a trigger detection unit that outputs to the mechanism and has a protection mechanism for ensuring the safety and protection of information in the execution of the second application. In addition, it is characterized in that it is configured with an execution management unit that operates the first and second information processing mechanisms in order to limit the execution of the first application and shift the execution to the second application. , Information processing terminal. 汎用の第1アプリケーションを実行しうる第1情報処理機構と、 情報の安全および保護を要する第2アプリケーションを実行しうる第2情報処理機構と、 上記の第1および第2情報処理機構における処理を管理する管理機構と、 上記の第1および第2情報処理機構並びに管理機構とは別体に構成されるとともに、上記第2情報処理機構を起動するためのトリガ操作を検出しその旨を該管理機構に出力するトリガ検出部を有し、上記第2アプリケーションの実行における情報の安全および保護を図るための保護機構とをそなえ、 該管理機構が、該トリガ検出部で上記トリガ操作を検出した場合に、上記第1アプリケーションの実行を制限するとともに上記第2アプリケーションに実行を移行すべく上記の第1,第2情報処理機構を動作させる実行管理部を、そなえて構成されたことを特徴とする、情報処理端末。
- 5The first information processing mechanism that can perform a general-purpose first application, the second information processing mechanism that is activated by an external trigger operation and can perform a second application while ensuring the safety and protection of information, and the first and above In order to separate the management mechanism that manages the processing in the second information processing mechanism and the first and second information processing mechanisms and the management mechanism described above, and to secure and protect the information in the second application. This is an information security protection method for an information processing terminal equipped with the protection mechanism of the above, and when the protection mechanism detects a trigger operation from the outside, a trigger detection step for notifying the management mechanism to that effect, and a trigger detection step. When the notification of the detection of the trigger operation is received in the trigger detection step, the read step of reading the program data and the password information from the second application storage unit, and the management mechanism and the protection mechanism cooperate with each other. In the authentication step, the program data read in the read step is authenticated by using the password information read together with the program data. Information characterized in that the management mechanism is configured to include an execution step of causing the second information processing mechanism to execute the second application by using the program data authenticated in the authentication step. Information security protection method for processing terminals. 汎用の第1アプリケーションを行ないうる第1情報処理機構と、外部からのトリガ操作によって起動され、情報の安全および保護を図りながら第2アプリケーションを行ないうる第2情報処理機構と、上記の第1および第2情報処理機構における処理を管理する管理機構と、上記の第1および第2情報処理機構並びに管理機構とは別体に構成されるとともに、上記第2アプリケーションにおける情報の安全および保護を図るための保護機構と、をそなえてなる情報処理端末の情報安全保護方法であって、 該保護機構が、該外部からのトリガ操作を検出すると、その旨を該管理機構に通知するトリガ検出ステップと、 該トリガ検出ステップにおいて上記トリガ操作の検出の通知を受けると、該第2アプリケーション用記憶部から、上記のプログラムデータおよび暗証情報を読み出す読み出しステップと、 上記の管理機構および保護機構が協働することにより、該読み出しステップにおいて読み出されたプログラムデータを、当該プログラムデータとともに読み出された暗証情報を用いて認証を行なう認証ステップと、 該認証ステップにおいて認証されたプログラムデータを用いることにより、該管理機構が、該第2情報処理機構に上記第2アプリケーションを実行させる実行ステップと、をそなえて構成されたことを特徴とする、情報処理端末の情報安全保護方法。
Independent claims2
52 paragraphs, as filed
The present invention relates to an information processing terminal and its information security protection method, particularly to an information processing terminal and its information security protection method, which is suitable for use when making a payment for a registered purchased product.
In recent years, a trading system has been developed in which a mobile terminal such as a handheld terminal or a PDA (Personal Digital Assistant) is used to perform payment processing by credit or the like together with order processing of products. Such a form of transaction using a mobile terminal is attracting attention because of its convenience, but in particular, security of information about the user associated with payment processing, that is, prevention of leakage of confidential information about the user. It is extremely important how to secure the measures to be taken.
Normally, when inputting information about such a user, the person is authenticated by inputting a personal identification number to prevent payment processing or the like impersonating another person. Therefore, it is important to prevent others from knowing their own PIN, and various methods for protecting the security of their own PIN have been developed in the past. For example, on a terminal that has an environment in which an application operates on a general-purpose OS (Operating System), there is a possibility that a spoofing application for entering a personal identification number can be easily created and operated. Therefore, such a spoofing application It is conceivable that the PIN will be leaked through. To deal with this, by using a special private OS that operates only when handling the PIN code, the possibility of creating and operating the spoofing application as described above is blocked, and the leakage of the PIN code is prevented. Was being done.
In addition, since the keyboard for inputting the personal identification number is usually used for other purposes, both the personal identification number and the data for other purposes are input through the common keyboard driver. Therefore, the key code of the PIN code converted by this common keyboard driver may be leaked to other applications through the OS. In response to this, a separate keyboard dedicated to inputting the password has been provided to prevent leakage of the password.
As a related technique of the present invention, there is also a technique described in Patent Document 1 shown below. In the technology described in Patent Document 1, the personal identification number is input through the mobile phone, and the payment terminal is paired with the payment terminal by transmitting and receiving to and from the mobile terminal to analyze the personal identification number. The pin pad is not required, and the leakage of the password through the reader that can be attached to the pin pad can be prevented.<patcit num="1"><text>Japanese Unexamined Patent Publication No. 2003-157239</text></patcit>
<p> However, there are the following problems in the conventional technique for preventing the leakage of the personal identification number. First, when using a special private OS that operates only when handling a PIN, the person who can develop an application program that handles the PIN is limited to those who know the special private OS. , There is a problem that the development environment and human resources of application programs are limited.</p><p> Further, when a keyboard dedicated to inputting a personal identification number is separately provided, the scale of the device increases, so that there is a problem that the convenience as a mobile terminal is lowered. Even in the technique described in Patent Document 1 described above, the password input from the mobile phone may be leaked through the spoofing application incorporated in the mobile phone itself. Therefore, in order to prevent this spoofing application. If a special OS is used, there is a problem that the development environment and human resources of the application program are limited as in the above case.</p><p> The present invention was devised in view of such a problem, and uses a common keyboard for inputting password information and inputting other information while providing a free application software development environment by adopting a general-purpose OS. At the same time, it is an object of the present invention to provide an information processing terminal and its information security protection method that can prevent leakage of password information.</p>
<p> Therefore, the information processing terminal of the present invention includes a first information processing mechanism capable of executing a general-purpose first application, a second information processing mechanism capable of executing a second application requiring information security and protection, and the above. To activate the second information processing mechanism while being configured separately from the management mechanism that manages the processing in the first and second information processing mechanisms and the first and second information processing mechanisms and the management mechanism. It has a trigger detection unit that detects the trigger operation of the above and outputs the fact to the management mechanism, and has a protection mechanism for ensuring the safety and protection of information in the execution of the second application, and the management mechanism is the management mechanism. When the trigger detection unit detects the trigger operation, the execution management unit that operates the first and second information processing mechanisms to limit the execution of the first application and shift the execution to the second application is provided. , It is characterized by being configured in preparation.</p><p> In this case, preferably, the trigger detection unit is configured to include a connection detection unit that detects that an external storage medium capable of storing data is connected as the trigger operation from the outside. In addition, an input / output interface for performing interface processing between the input / output device for inputting / outputting data in the processing in the first and second applications and the first and second information processing mechanisms described above is provided, and the execution thereof is performed. When the management unit detects the trigger operation, the input / output interface is switched from an operation mode in which the input / output interface is linked to the first information processing mechanism through the management mechanism to an operation mode in which the input / output interface is directly linked to the second information processing mechanism. The operation mode switching unit can also be configured.</p><p> Further, the second information processing mechanism is provided with a storage unit for the second application that stores the program data for the second application and the password information created from the program data, and the protection mechanism is provided with a storage unit for the second application. The key information storage unit that stores the key information and the password information stored in the second application storage unit are input from the management mechanism, and the input password information and the key information storage unit are stored. When the first collation information generation unit capable of generating the first collation information by using the above key information and the above management mechanism detects the trigger operation by the trigger detection unit, the said A reading unit that reads the program data and the password information from the second application storage unit, a separation unit that separates the program data and the password information read by the reading unit, and a separation unit that separates the password information. The second collation information generation unit that can generate the second collation information from the above program data is compared with the first and second collation information generated by the first and second collation information generation units, respectively. By doing so, the determination unit for determining whether or not the program data for the second application can be authenticated is provided, and the execution management unit of the management mechanism can be authenticated by the determination unit. Later, it may be configured to execute the second application by the second information processing mechanism.</p><p> Further, the information security protection method for the information processing terminal of the present invention is activated by a first information processing mechanism capable of performing a general-purpose first application and an external trigger operation, and is activated by a second application while ensuring the safety and protection of information. The second information processing mechanism capable of performing the above, the management mechanism for managing the processing in the first and second information processing mechanisms, and the first and second information processing mechanisms and the management mechanism described above are separately configured. At the same time, it is an information security protection method for an information processing terminal provided with a protection mechanism for ensuring the safety and protection of information in the second application, and when the protection mechanism detects a trigger operation from the outside. , A trigger detection step that notifies the management mechanism to that effect, and when the notification of detection of the trigger operation is received in the trigger detection step, the above program data and the password information are read out from the storage unit for the second application. An authentication step in which the step and the above-mentioned management mechanism and protection mechanism cooperate to authenticate the program data read in the reading step using the password information read together with the program data, and the authentication step. By using the program data authenticated in the authentication step, the management mechanism is configured to include an execution step of causing the second information processing mechanism to execute the second application.</p>
<p> As described above, according to the present invention, the operation of the second information processing mechanism itself is operated under the control of the general-purpose OS by the protection mechanism and the management mechanism, while the input / output of information necessary for maintaining confidentiality is other. Since it is possible to prevent information from being leaked to applications, while using a general-purpose OS to provide a free application software development environment, while using a common keyboard for password information input and other information input. There is an advantage that it is possible to prevent leakage of password information.</p>
Hereinafter, embodiments of the present invention will be described with reference to the drawings. [A] Description of One Embodiment of the Present Invention FIG. 1 is a block diagram showing an information processing terminal 1 according to an embodiment of the present invention together with a center 30 connected via a line 40. The information processing terminal 1 shown in FIG. 1 is a portable information processing terminal such as a PDA, which includes a computer 2, a display 6, a touch panel 7, and a line connection portion 8, and is a characteristic configuration of the present invention. The protection mechanism 10 is incorporated in one housing.
Here, the computer 2 includes firmware such as a CPU (Central Processing Unit) 3, a ROM (Read Only Memory) 4, a RAM (Random Access Memory) 5, and other drivers, and is a program stored in the ROM 4. Is expanded to RAM5 and executed by CPU3, so that various applications can be executed.
Specifically, by executing a POS (Point Of Sales) application, the customer or the operator of the terminal 1 can register the products to be purchased and calculate the price (process to obtain a subtotal). In addition to being able to execute the POS operation to be performed, by performing the payment application, it is possible to perform payment using credits, debits, etc. for the products registered by the POS application.
The display 6 is for performing display processing associated with various applications on the computer 2, and the touch panel 7 is for performing an input operation by touching the display on the screen of the display 6, and the line connection unit 8 is used. Is for connecting to network 40. In particular, when performing the above-mentioned POS operation on the information processing terminal 1, the line connection unit 8 communicates with the center 30 via the network 40 to acquire inventory information of products desired to be purchased from the center 30. You can also do it.
Further, the protection mechanism 10 is for ensuring the security and protection of the information required for the application. For example, the above-mentioned payment application is an application that handles information that should be kept secret, such as personal information for payment, and is required to have a particularly high level of security and protection for the information to be handled. The protection mechanism 10 in the present embodiment makes it possible to ensure the protection and security of the information handled in the payment application.
Further, the protection circuit 10 includes an encryption processing circuit 11, a keyboard 12, a card reader / writer 13, and an anti-tamper function unit 14. The encryption processing circuit 11 performs encryption processing for ensuring information security before and during the execution of the second application, and is provided with a card insertion / removal management unit 11a and a protection driver 11d as shown in FIG. , It is configured to include a key information storage unit 11b and a first verification information generation unit 11c that are configured to operate when the payment application is started.
Further, the keyboard 12 is configured as a key input unit in the information processing terminal 1, and performs necessary input operations such as inputting a PIN (Personal Identification Number), that is, a personal identification number when executing a POS application or a payment application. The key input information input by the keyboard 12 is passed to the computer 2 through the protection driver 11d. As will be described later, the encryption processing circuit 11 is configured so that the operation mode of the protection driver 11d is switched during the execution of the payment application so that the key input information is not leaked to other applications.
The card reader / writer 13 reads, for example, the contents stored in the IC card and writes information in the IC card in order to perform payment using an external storage medium such as an IC card in the above-mentioned payment application. In addition, the connection detection unit can detect that an external storage medium is connected, specifically, the insertion of an IC card into the card insertion slot.
The insertion / removal (insertion / removal) of the IC card into the above-mentioned card insertion slot is managed by the card insertion / removal management unit 11a of the encryption processing circuit 11, and in the computer 2, the insertion / removal state of this IC card is controlled. It can be recognized through the card insertion / removal management unit 11a. Further, the tamper-resistant function unit 14 is for preventing leakage of confidential information such as the contents stored in the key information storage unit 11b from unauthorized access such as prying open of the housing, and is as shown in FIG. , The above-mentioned unauthorized access detection unit 14a that detects unauthorized access is provided, and when unauthorized access is detected by the unauthorized access detection unit 14a, the key information stored in the key information storage unit 11b and other information that should be kept secret are stored. , It is configured with an erasing unit 14b that erases it so that it will not be taken out by unauthorized access.
FIG. 2 is a block diagram showing the above-mentioned computer 2 focusing on its firmware and software configuration. As shown in FIG. 2, the computer 2 executes the POS application 2a based on the general-purpose OS. At the same time, the payment application 2b can be executed. 2d is a video driver for display control for display 6, 2e is a touch panel driver for input / output control by touch panel 7, 2f is a keyboard driver for input by keyboard 12, and 2g is protection mechanism 10 and computer 2. The serial driver 2c for performing interface processing between the above is a general-purpose OS kernel (hereinafter, simply referred to as an OS kernel) for comprehensively controlling the above-mentioned two applications 2a and 2b and each driver 2d ~ 2f. ..
The above drivers 2d to 2f include a display 6, a touch panel 7 and a keyboard 12 as input / output devices for inputting / outputting data in processing in the POS application 2a and the payment application 2b, and the first and second information processing mechanisms 21, 22. It functions as an input / output interface that performs interface processing with and from. In addition, drivers 2d to 2f can switch the execution operation mode for each application based on the instructions from the OS kernel 2c. That is, when executing the POS application 2a as described above, the drivers 2d to 2f are in the normal operation mode of linking with the POS application 2a through the OS kernel 2c, but when executing the payment application 2b, the payment is made. Only application 2b will be in a protected operating mode that can be directly linked to drivers 2d ~ 2f.
By the way, in the execution of the above-mentioned POS application 2a and the execution of the payment application 2b, the operating state of the computer 2 is switched so that information leakage can be prevented. FIG. 3 is a block diagram showing the information processing terminal 1 according to the present embodiment, focusing on the functions associated with the execution of the payment application 2b as described above.
As shown in FIG. 3, the computer 2 performs the processing of the first information processing mechanism 21 that can process the POS application 2a (first application), which is a general-purpose application, and the processing of the payment application 2b (second application). It comprises a second information processing mechanism 22 and a management mechanism 23 that manages the processes of the first and second information processing mechanisms 21 and 22 described above.
That is, the first and second information processing mechanisms 21 and 22 and the management mechanism 23 are all realized by sharing the hardware resources of the computer 2 shown in FIG. 1, but the protection mechanism 10 is a serial driver 2g. It is connected to the computer 2 via the computer 2 and is configured as a separate module without sharing the hardware resources of the computer 2. Specifically, the first information processing mechanism 21 is realized by the execution of the POS application 2a by the computer 2 and the operation of the drivers 2d to 2f in the normal operation mode, and the second information processing mechanism 22 is the payment application 2b by the computer 2. It is realized by the operation of drivers 2d ~ 2f in the protected operation mode with the execution of, and the management mechanism 23 is realized mainly by the operation of the OS kernel 2c and the serial driver 2g.
The second information processing mechanism 22 has a storage unit 22a for a payment (second) application, and the storage unit 22a for the payment application contains program data for processing the payment application 2b and this program data. It stores the electronic signature information as the password information created from, and is composed of ROM 4 shown in FIG. This electronic signature information is for authenticating the validity of the program of the payment application 2b (whether or not it is properly incorporated at the manufacturing stage of the terminal 1) by the management mechanism 23 described later, and is for authenticating with FIG. 4 As shown in, it is created at the manufacturing stage of the information processing terminal 1 (for example, in a clean room) and stored in ROM 4 (see FIG. 1) of the computer 2 together with the payment application 2b.
That is, a hash A (D2) is created from the program data (D1) of the payment application 2b by a predetermined algorithm, and this hash A is used, for example, by a 3-DES (Triple-Data Encryption Standard) method using an encryption key (D3). The obtained ciphertext (Cryptogram) is used as digital signature information (D4). Then, this electronic signature information (D4) is added to the program data (D1) and written to ROM4.
The management mechanism 23 shown in FIG. 3 includes an execution management unit 23a, a reading unit 23b, a separation unit 23c, a second collation information generation unit 23d, and a determination unit 23e. When the IC card reader / writer 13 detects the insertion of an IC card, the execution management unit 23a restricts the execution of the POS application 2a and shifts the execution to the payment application 2b. It operates 21,22, so that when a payment application is performed, input information or the like can be prevented from being leaked to an application other than the payment application.
The reading unit 23b, the password information separation / output unit 23c, the second collation information generation unit 23d, and the determination unit 23e are configured to operate when the payment application 2b is started. This will be explained together with the explanation of the operation when the payment application 2b of the information processing terminal 1 is started. In the information processing terminal 1 according to the embodiment of the present invention having the above configuration, the management mechanism 23 and the above-mentioned protection mechanism 10 cooperate with each other to obtain information in the payment application as shown in the flowchart of FIG. For safety and protection.
First, during the operation of the normal POS application 2a, the computer 2 operates as the first information processing mechanism 21. At this time, each driver 2d to 2f operates as a normal operation mode linked with the POS application 2a through the OS kernel 2c. Then, the key input information input from the keyboard 12 is processed by the POS application 2a through the protection driver 11d, the serial driver 2g, the keyboard driver 2f, and the OS kernel 2c.
When the payment process is performed by the payment application 2b following the execution of the above-mentioned POS application 2a, the card reader / writer 13 of the protection mechanism 10 triggers that the payment IC card is inserted into a card insertion slot (not shown). As a payment application 2b is started. At this time, when the card reader / writer 13 detects that the IC card is inserted into the card insertion slot and the IC card is connected to the information processing terminal 1 (step A1), the card insertion / removal management unit 11d of the encryption processing circuit 11 Then, an unmaskable interrupt is generated and output to that effect to the OS kernel 2c that forms the management mechanism 23 [Step A2, Trigger detection step, see (1) in Fig. 2]. Therefore, the card reader / writer 13 and the card insertion / removal management unit 11a described above constitute a trigger detection unit for activating the second information processing mechanism 22.
When the execution management unit 23a (OS kernel 2c) of the management mechanism 23 recognizes the IC card insertion detected by the card reader / writer 13 and the card insertion / removal management unit 11a, the execution of the POS application 2a is restricted and the payment application 2b is set. By shifting the execution, the 1st and 2nd information processing mechanisms 21 and 22 are operated to secure and protect the information in the processing of the payment application 2b.
Here, the execution management unit 23a (OS kernel 2c) can switch the operation mode from the normal operation mode to the protected operation mode for each driver 2d ~ 2f, and only the payment application 2b can directly link with the driver 2d ~ 2f. [See Step A3, Figure 2 (2)]. In other words, when the execution management unit 23a recognizes the IC card insertion as the trigger operation detected by the card reader / writer 13 and the card insertion / removal management unit 11a, the driver 2d to 2f as the input / output interface is operated by the management mechanism 23. An operation mode switching unit for switching from an operation mode linked to the first information processing mechanism 21 to an operation mode directly linked to the second information processing mechanism 22 is configured.
Then, when the card insertion / removal management unit 11a detects the card insertion as described above, the second information processing of the input from the keyboard 12 when performing the payment application also regarding the operation mode of the protection driver 11d of the encryption processing circuit 11. It is output to the second information processing mechanism 22 in a format that can be identified only by the mechanism 22. That is, when the card insertion / removal management unit 11a detects the IC card insertion, the input information from the keyboard 12 is output with a key code that can be identified only by the second information processing mechanism 22 until the IC card is removed. It is. In other words, in the second information processing mechanism 22, key input information can be received only by the payment application 2b through the keyboard driver 2f operating in the protected operation mode, and the key input information is not received in the OS kernel 2c. [See (3) in Figure 2].
In the payment process, normally, after inserting the IC card, a highly confidential PIN etc. is input from the keyboard 12, so a payment application that can handle the PIN etc. properly until the IC card is removed. It makes it possible to process key input information only by itself. When the IC card is inserted and the drivers 2d to 2f are switched to the protected operation mode as described above, the information input through the keyboard 12 and touch panel 7 and the display 6 and the like are displayed until the IC card is removed. The information to be sent will not be leaked to anyone other than the payment application due to the action of drivers 2d ~ 2f and protection driver 11d.
Then, as shown in (1) of FIG. 6, the reading unit 23b of the management mechanism 23 reads the program data and the electronic signature information for the payment application 2b from the payment application storage unit 22a (step A4, reading step). ). Then, when the reading unit 23b receives the above-mentioned program data and the electronic signature information, the management mechanism 23 and the protection mechanism 10 cooperate to read the program data read by the reading unit 23b together with the program data. Authentication is performed using the issued electronic program name information (step A5, authentication step).
Specifically, as shown in (2) of FIG. 6, the separation unit 23c of the management mechanism 23 separates the electronic signature information and the program data read by the reading unit 23b, and also separates the program data from the program data (3) of FIG. ), In the second collation information generation unit 23d, the program data (D5) separated by the separation unit 23c is hashed as the second collation information by the same algorithm as in the case of FIG. 4 described above. Generate A'(D7) (second collation information generation step).
Further, in the above-mentioned separation unit 23c, as shown in (4) of FIG. 6, the separated electronic signature information (D6) is output to the first verification information generation unit 11c of the protection mechanism 10 (password information output step). ). Then, as shown in (5) of FIG. 6, in the first collation information generation unit 11c, the electronic signature information (D8) from the separation unit 23c and the key information (D9) stored in the key information storage unit 11b. ) And, in the same manner as in the case of FIG. 4 described above, the hash A (D10) as the first collation information is generated (first collation information generation step), and the obtained hash is generated. Output "A" to the management mechanism 22 [see (6) in Fig. 6].
Here, the key information (D9) stored in the above-mentioned key information storage unit 11b is the same as the key information (D3) used when generating the electronic signature information (D4) shown in FIG. 4 described above. .. Therefore, if the hash A "obtained by the first collation information generation unit 11c in the protection mechanism 10 and the hash A'obtained by the second collation information generation unit 23d in the management mechanism 23 are the same. , The program data read by the reading unit 23b of the management mechanism 23 is valid.
That is, in the determination unit 23e of the management mechanism 23, as shown in (7) of FIG. 6, the hash A (D10) obtained by the above-mentioned first collation information generation unit 11c and the second collation information generation are generated. By comparing with the hash A'(D7) obtained in the part 23d, it is determined whether or not the program read by the reading unit 23b can be authenticated. In this case, these hash A "and the hash A'are one. If it is done, it is judged that the authentication is possible (authentication successful), and if it does not match, it is judged as the authentication failure (authentication failure) (judgment step).
Then, when the authentication is successful in the authentication step (step A5 in FIG. 5) as described above, the execution management unit 23a of the management mechanism 23 uses the program data for which the authentication is successful to use the second information processing mechanism 22. To execute the payment application (step A6 in Fig. 5, execution step). At this time, in the payment application executed by the second information-technology promotion agency 22, it is confirmed that the IC card inserted in the card insertion slot is an IC card that can be used in the payment application, and the actual use of this IC card is confirmed. The payment process will be started (from the YES route in step A7 to step A8).
Then, when the actual payment processing using the above-mentioned IC card is completed, the second information-technology promotion agency 22 makes a request to remove the IC card through a display function such as a display (step A9). Even if an IC card that cannot be used in the payment application is inserted, the same removal request is made through the display function such as display 6 without performing the actual payment processing (from the NO route in step A7). Step A9).
After that, by removing the IC card inserted in the card insertion slot, the payment application processing by the second information-technology promotion agency 22 is completed, and the drivers 2d to 2f are switched to the normal operation mode together with the protection driver 11d. , The POS application by the 1st Information Technology Promotion Agency 21 can be executed. That is, when the card insertion / removal management unit 11a detects that the IC card has been removed, the operation mode of the protection driver 11d is switched from the protection operation mode to the normal operation mode. In addition, when the execution management unit 23a (OS kernel 2c) recognizes the above-mentioned IC card removal from the card insertion / removal management unit 11a through the serial driver 2g, the drivers 2d to 2f are switched from the protected operation mode to the normal operation mode, and the POS application. Run 2a [see (4) in Figure 2].
As described above, according to the information processing terminal 1 according to the embodiment of the present invention, the protection mechanism 10 and the execution management unit 23a operate the second information processing mechanism 22 itself under the control of the general-purpose OS. Since the input / output of information necessary for maintaining confidentiality can prevent information from being leaked to other applications, it is possible to input password information while providing a free application software development environment by adopting a general-purpose OS. There is an advantage that it is possible to prevent leakage of password information while using a common keyboard for inputting other information.
[B] Others According to the present invention, regardless of the above-described embodiment, various modifications can be made without departing from the spirit of the present invention. In the information processing terminal 1 according to the above-described embodiment, the second application that requires information security and protection and should maintain confidentiality is configured as a payment application, and the general-purpose first application is configured as a POS application. However, according to the present invention, the present invention is not limited to this, and it is of course possible to combine other applications.
Further, according to the above-described embodiment, it is possible to manufacture the apparatus of the present invention. [C] Appendix (Appendix 1) A first information processing mechanism that can execute a general-purpose first application, a second information processing mechanism that can execute a second application that requires information security and protection, and the above first and first information processing mechanisms. The management mechanism that manages the processing in the second information processing mechanism is configured separately from the first and second information processing mechanisms and the management mechanism, and the trigger operation for activating the second information processing mechanism. It has a trigger detection unit that detects and outputs to the management mechanism, and also has a protection mechanism for ensuring the safety and protection of information in the execution of the second application, and the management mechanism is the trigger detection unit. When the trigger operation is detected in, the execution management unit that operates the first and second information processing mechanisms to limit the execution of the first application and shift the execution to the second application is provided. An information processing terminal characterized by being configured.
(Appendix 2) The trigger detection unit is configured to include a connection detection unit that detects that an external storage medium capable of storing data is connected as the trigger operation from the outside. Information processing terminal described in 1. (Appendix 3) An input / output interface that performs interface processing between the input / output device that inputs / outputs data in the processing in the above 1st and 2nd applications and the above 1st and 2nd information processing mechanisms is provided. When the execution management unit detects the trigger operation, the operation mode in which the input / output interface is linked to the first information processing mechanism through the management mechanism is changed to the operation mode in which the input / output interface is directly linked to the second information processing mechanism. The information processing terminal according to Appendix 1, characterized in that it is configured with an operation mode switching unit for switching to.
(Appendix 4) The second information processing mechanism has a storage unit for the second application that stores the program data for the second application and the password information created from the program data, and the protection mechanism. However, the key information storage unit that stores the key information and the password information stored in the second application storage unit are input from the management mechanism, and the input password information and the key information storage unit are input. When the first collation information generation unit capable of generating the first collation information by using the stored key information is provided, and the above management mechanism detects the trigger operation by the trigger detection unit. , A reading unit that reads the above program data and the password information from the storage unit for the second application, a separation unit that separates the above program data and the password information read by the reading unit, and the separation unit. A second collation information generator that can generate second collation information from the separated program data, By comparing the first and second collation information generated by the first and second collation information generation units, respectively, the determination unit that determines whether the program data for the second application can be authenticated and the determination unit. In addition, the execution management unit of the management mechanism is configured to execute the second application by the second information processing mechanism after the program data is authenticated by the authentication unit. The featured information processing terminal described in Appendix 1.
(Appendix 5) When the protection mechanism detects the unauthorized access of the protection mechanism and the unauthorized access detection unit, the unauthorized access is stored in the first key information storage unit. The information processing terminal described in Appendix 4, which is configured to include a key information erasing unit for erasing key information. (Appendix 6) When the protection mechanism is provided with a key input unit and the trigger detection unit detects the trigger operation, the input from the key input unit when performing the second application is the second. The information processing according to any one of Appendix 1 to 5, characterized in that it is configured with a protection driver for outputting to the second information processing mechanism in a format that can be identified only by the information processing mechanism. Terminal.
(Appendix 7) The first application is configured to perform the process of registering the product to be purchased, and the second application is configured to perform the payment processing for the registered product to be purchased. The information processing terminal according to any one of Appendix 1 to 5, which is a feature. (Appendix 8) The above-mentioned first and second information processing mechanisms and management mechanisms are composed of a shared computer, and the protection mechanism is incorporated in one housing together with the above-mentioned shared computer. The information processing terminal according to any one of Appendix 1 to 7, which is characterized by the above.
(Appendix 9) The first information processing mechanism that can perform a general-purpose first application, the second information processing mechanism that is activated by an external trigger operation and can perform a second application while ensuring the safety and protection of information, and the above. The management mechanism that manages the processing in the first and second information processing mechanisms of No. 1 and the above-mentioned first and second information processing mechanisms and the management mechanism are separately configured, and the security of information in the above-mentioned second application and It is an information security protection method for an information processing terminal equipped with a protection mechanism for protection, and when the protection mechanism detects a trigger operation from the outside, a trigger for notifying the management mechanism to that effect. Upon receiving the notification of the detection step and the detection of the trigger operation in the trigger detection step, the read step of reading the program data and the password information from the storage unit for the second application, and the management mechanism and the protection mechanism described above are performed. In cooperation with the authentication step, the program data read in the read step is authenticated by using the password information read together with the program data. Information characterized in that the management mechanism is configured to include an execution step of causing the second information processing mechanism to execute the second application by using the program data authenticated in the authentication step. Information security protection method for processing terminals.
(Appendix 10) In the management mechanism, the second verification information generation step capable of generating the second verification information from the above program data read in the read step, and the management mechanism. The password information output step that outputs the password information read in the read step to the protection mechanism, the password information output in the password information output step in the protection mechanism, and the key stored in the protection mechanism. The first collation information generation step that generates the first collation information by using the information, and the first and second collation information generation steps generated in the first and second collation information generation steps in the management mechanism, respectively. The second collation information is compared, and if the first and second collation information match, it is determined that the authentication is successful, and if they do not match, it is determined that the authentication is unsuccessful. The information security protection method for the information processing terminal described in Appendix 9, which is characterized by the fact that the information has been used.
<figref num="1">It is a block diagram which shows the information processing terminal which concerns on one Embodiment of this invention together with the center connected via a line.</figref><figref num="2">It is a block diagram which shows the main part of the information processing terminal which concerns on one Embodiment of this invention.</figref><figref num="3">It is a block diagram which focuses on the function which accompanies the execution of the payment application about the information processing terminal which concerns on this Embodiment.</figref><figref num="4">It is a figure for demonstrating the creation of the electronic signature information in this embodiment.</figref><figref num="5">It is a flowchart for demonstrating operation of this Embodiment.</figref><figref num="6">It is a figure for demonstrating the authentication procedure using the electronic signature information in this embodiment.</figref>
Code description
1 Information processing terminal 2 Computer 2a POS application 2b Payment application 2c OS kernel 2d Video driver (input / output interface) 2e Touch panel driver (input / output interface) 2f Keyboard driver (input / output interface) 2g Serial driver 3 CPU 4 ROM 5 RAM 6 Display (I / O device) 7 Touch panel (I / O device) 8 Line connection 10 Protection mechanism 11 Cryptographic processing circuit 11a Card insertion / removal management (trigger detection) 11b Key information storage 11c 1st verification information generation 11d Protection driver 12 Keyboard (input / output device) 13 Card reader / writer (trigger detection unit, connection detection unit) 14 Tamper resistance function unit 14a Unauthorized access detection unit 14b Erase unit 21 1st information processing mechanism 22 2nd information processing mechanism 22a Payment application storage unit (second application storage unit) 23 Management mechanism 23a Execution management unit (operation mode switching unit) 23b Read unit 23c Separation unit 23d Second verification information generation unit 23e Judgment unit 30 Center 40 lines
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2006195599A | Cited by | Japan | Examiner |
| JP2015191318A | Cited by | Japan | Search report |
| US8892889B2 | Cited by | United States of America | Applicant |
| US9760739B2 | Cited by | United States of America | Applicant |
| US8910242B2 | Cited by | United States of America | Applicant |
| US9667426B2 | Cited by | United States of America | Applicant |
| US9773131B2 | Cited by | United States of America | Applicant |
| JP2015194800A | Cited by | Japan | Search report |
| JP5685739B1 | Cited by | Japan | Search report |
| US9607181B2 | Cited by | United States of America | Applicant |
| JP2015201025A | Cited by | Japan | Search report |
| JP2011028688A | Cited by | Japan | Search report |
| JP2011028688A | Cited by | Japan | Search report |
| US9679166B2 | Cited by | United States of America | Applicant |
| JP2015201025A | Cited by | Japan | Search report |
| JP5685739B1 | Cited by | Japan | Examiner |
| JP2015114790A | Cited by | Japan | Examiner |
| JP2015114790A | Cited by | Japan | Search report |
| US9799022B2 | Cited by | United States of America | Applicant |
| JP2015114788A | Cited by | Japan | Search report |
| JP2015215687A | Cited by | Japan | Search report |
| EP0456548A1 | Cites | European Patent Office (EPO) | Examiner |
| JP2003099144A | Cites | Japan | Examiner |
| JP2003157239A | Cites | Japan | Examiner |
| JP2003506921A | Cites | Japan | Search report |
| JPH04232588A | Cites | Japan | Examiner |
6 members in 3 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004105208 | Japan | A | |
| JP20040105208 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| EP1583051A1 | European Patent Office (EPO) | A1 | |
| US2005222958A1 | United States of America | A1 | |
| JP2005293058AThis record | Japan | A | |
| US7519993B2 | United States of America | B2 | |
| JP4636809B2 | Japan | B2 | |
| EP1583051B1 | European Patent Office (EPO) | B1 |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Notification of change in applicantA711 | A711 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2005293058
- Publication, DOCDB
- 2005293058
- Publication, EPODOC
- JP2005293058
- Application
- 105208
- Application, DOCDB
- 2004105208
- Application, EPODOC
- JP20040105208
Titles2
- Japanese
- 情報処理端末およびその情報安全保護方法
- English
- Information processing terminal and its information security protection method
Classification
- CPC, 15
- G07F7/0886
- G06F21/74
- G06F21/83
- G06F2221/2105
- G06Q20/085
- G06Q20/20
- G06Q20/341
- G06Q20/343
- G06Q20/382
- G06Q20/4012
- G07F7/02
- G07F7/1008
- H04L9/0897
- H04L9/3236
- H04L9/3247
- IPC, 13
- G06F1 00
- G06F12 00
- G06F15 00
- G06F21 00
- G06F21 12
- G06F21 14
- G06Q20 00
- G06Q20 40
- G06Q20 42
- G07F7 02
- G07F7 10
- H04L9 00
- H04L9 32