Secure device and relay terminal
Abstract
Problem to be solved.To provide a secure device capable of safely and surely writing information to a secure memory. An IC card 10 includes a tamper-resistant module 12 having one or more applications 16 and a card control unit 14 that controls the operation of the IC card 10, and a secure memory area 18 that can be accessed only from the tamper-resistant module 12. , It is equipped with a non-contact interface 24 for communicating with the service terminal 60. The card control unit 14 generates storage instruction information, and the non-contact interface 24 transmits the storage instruction information to the service terminal 60. The storage instruction information includes the address of the secure memory area 18 to which the data is written, the address of the normal memory area 20 indicating the storage destination for temporarily storing the data, and the normal memory area 20 to the secure memory area 18. Includes the identifier of the application that executes the data movement and the address of the relay terminal 40 that relays the data. [Selection diagram] Fig. 1

Term
Term ended
Projected expiry passed 14 October 2025, 0.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
17 claims: 7 independent, 10 dependent
- 1サービス端末から送信されるデータを、情報書込み機能を有する中継端末を介して受信するセキュアデバイスであって、 1以上のアプリケーションと前記セキュアデバイスの動作を制御するデバイス制御部とを有する耐タンパモジュールと、 前記耐タンパモジュールからのみアクセス可能なセキュアメモリと、 前記サービス端末と通信するための通信部と、を備え、 前記デバイス制御部は、前記データの書込み先を示す前記セキュアメモリのアドレスと前記セキュアメモリへのデータ書込みが不能であった場合の対処法に関する情報とから成る格納指示情報を生成、格納し、 前記通信部は、前記格納指示情報を前記サービス端末へ送信するセキュアデバイス。
- 2前記対処法に関する情報は、一時的に前記データを保管するための保管先を示す前記セキュアデバイス又は前記中継端末の有する通常メモリのアドレスと、前記通常メモリに保管されたデータを前記セキュアメモリへ移動させる前記アプリケーションの識別子を有する請求項1に記載のセキュアデバイス。
- 3前記対処法に関する情報は、一時的に前記データを保管するための保管先、または、前記データの書き込み先のメモリ領域の少なくとも一方を確保しておく期限を示す格納先確保期限を有する請求項2に記載のセキュアデバイス。
- 4前記通信部は、前記サービス端末から送信されるデータの属性情報を受信し、 前記デバイス制御部は、前記属性情報に基づいて前記サービス端末から送信されるデータを中継する中継端末を決定し、決定された前記中継端末のアドレスを前記格納指示情報に含める請求項1に記載のセキュアデバイス。
- 5前記通信部は、前記サービス端末から送信されるデータの属性情報を受信し、 前記デバイス制御部は、前記属性情報に基づいて前記中継端末と前記サービス端末との間の通信方式を決定し、前記格納指示情報に含める請求項1に記載のセキュアデバイス。
- 6サービス端末から送信されたデータを通信可能に接続されたセキュアデバイスに書き込む中継端末であって、 前記データと、前記データの書込み先を示す前記セキュアデバイスが有するセキュアメモリのアドレスと前記セキュアメモリへのデータ書込みが不能であった場合の対処法に関する情報とから成る格納指示情報とを、前記サービス端末から受信するデータ受信部と、 受信したデータを前記格納指示情報で指定された前記セキュアメモリのアドレスへ書き込む命令を前記セキュアデバイスに送信し、前記命令に対する前記セキュアデバイスからの応答を受信する命令送信部と、 前記応答に基づいて前記セキュアメモリへのデータ書込みの可否を判断し、書込み不能と判断した場合に、前記格納指示情報で指定された対処法に関する情報に基づいて、前記セキュアデバイス又は該中継端末の有する通常メモリに前記データを書き込む制御部と、 を備える中継端末。
- 7サービス端末から送信されたデータを通信可能に接続されたセキュアデバイスに書込む中継端末であって、 前記データと、前記データの書込み先を示す前記セキュアデバイスが有するセキュアメモリのアドレスと前記セキュアメモリへのデータ書込みが不能であった場合の対処法に関する情報とから成る格納指示情報とを、前記サービス端末から受信するデータ受信部と、 前記セキュアデバイスの処理状態を管理し、前記処理状態に基づいて前記セキュアメモリへのデータ書込みの可否を判断し、書込み不能と判断した場合に、前記格納指示情報で指定された対処法に関する情報に基づいて、前記セキュアデバイス又は該中継端末の有する通常メモリに前記データを書き込む制御部と、 を備える中継端末。
- 8前記中継端末は、さらに、前記格納指示情報にて指定された通常メモリのアドレスへのデータの書込みの完了に応じて前記格納指示情報を削除する削除部を備える請求項6または7に記載の中継端末。
- 9前記対処法に関する情報は、一時的に前記データを保管するための保管先を示す前記セキュアデバイス又は前記中継端末の有する通常メモリのアドレスと、前記通常メモリに保管されたデータを前記セキュアメモリへ移動させる前記アプリケーションの識別子を含む請求項6に記載の中継端末。
- 10前記命令送信部は、前記格納指示情報で指定されたアプリケーションの識別子に基づいて、前記アプリケーション識別子に対応するアプリケーションの起動命令を出力し、 起動した前記アプリケーションに対し、前記通常メモリに一時的に保管された前記データを前記セキュアメモリのアドレスに移動させるデータ移動命令を出力する請求項9に記載の中継端末。
- 11前記対処法に関する情報は、一時的に前記データを保管するための保管先を示す前記セキュアデバイス又は前記中継端末の有する通常メモリのアドレスと、前記通常メモリに保管されたデータを前記セキュアメモリへ移動させる前記アプリケーションの識別子を含む請求項7に記載の中継端末。
- 12前記対処法に関する情報は、一時的に前記データを保管するための保管先、または、前記データの書き込み先のメモリ領域の少なくとも一方を確保しておく期限を示す格納先確保期限を有する請求項11に記載の中継端末。
- 13前記命令送信部は、 前記格納指示情報で指定されたアプリケーションの識別子に基づいて、前記アプリケーション識別子に対応するアプリケーションの起動命令を出力し、 起動した前記アプリケーションは、前記格納指示情報を参照し、前記通常メモリに一時的に保管されたデータを前記セキュアメモリのアドレスに移動させる請求項9または請求項11に記載の中継端末。
- 14前記格納指示情報で指定された通常メモリのアドレスにアクセスして、前記通常メモリに一時的に保管されたデータを読み出すデータ読出部をさらに備え、 前記命令送信部は、 前記格納指示情報で指定されたアプリケーションの識別子に基づいて、前記アプリケーション識別子に対応するアプリケーションの起動命令を出力し、 起動した前記アプリケーションに対し、前記データ読出部で読み出した前記データの前記セキュアメモリのアドレスへの書き込みを指示する書込み命令を出力する請求項9または請求項11に記載の中継端末。
- 15前記命令送信部は、前記格納指示情報で指定された格納先確保期限を参照し、前記通常メモリに一時的に保管されたデータを削除する請求項12に記載の中継端末。
- 16サービス端末から送信されるデータを、情報書込み機能を有する中継端末を介して受信するセキュアデバイスの動作方法であって、 前記セキュアデバイスが、前記データの書込み先を示す前記セキュアデバイスの有するセキュアメモリのアドレスと前記セキュアメモリへのデータ書込み不能であった場合の対処法に関する情報とから成る格納指示情報を生成するステップと、 前記セキュアデバイスが前記格納指示情報を前記サービス端末へ送信するステップと、 を備えるセキュアデバイスの動作方法。
- 17サービス端末から送信されるデータを情報書込み機能を有する中継端末を介して受信するためのセキュアデバイスによって読み取り可能なプログラムであって、 前記データの書込み先を示す前記セキュアデバイスの有するセキュアメモリのアドレスと前記セキュアメモリへのデータ書込み不能であった場合の対処法に関する情報とから成る格納指示情報を生成するステップと、 前記格納指示情報を前記サービス端末へ送信するステップと、 を前記セキュアデバイスに実行させるプログラム。
Independent claims17
79 paragraphs, as filed
The present invention relates to a secure device having an anti-tamper area and a relay terminal for writing data to the secure device.
Conventionally, as a method of securely storing digital contents, for example, a method using an IC card has been adopted. The IC card has a secure memory area that can be accessed only from the tamper-resistant module and cannot be read by unauthorized means. However, since the secure memory area has a small capacity, the digital content to be protected is encrypted and decrypted. The key for this was stored in the secure memory area, and the encrypted digital content was stored in the normal memory area of the terminal or on the memory card. When such a storage form is adopted, for example, as disclosed in Patent Document 1, a key for decrypting digital content is distributed to a secure memory using an encrypted communication path, and the encrypted digital content is encrypted. Will be delivered to the normal memory area later.<patcit num="1"><text>JP-A-2002-124960</text></patcit>
<p> With the increase in the memory capacity of IC cards in recent years, there is an increasing demand for storing digital contents themselves in secure memory. However, the data received from the outside cannot be directly written to the secure memory area, and can be accessed only from the anti-tamper module. Therefore, when the anti-tamper module is performing other high-load processing, the distributed information may not be saved.</p><p> In order to prevent such inconvenience, when the anti-tamper module is performing other processing, that is, when it is in a busy state, the data is temporarily saved in the relay terminal, and the temporarily saved data is tolerated at an appropriate timing. A procedure for moving to secure memory via the tamper module can be considered.</p><p> However, in this procedure, if the IC card is moved to another card reader / writer, the temporarily saved data cannot be moved to the secure memory which is the final storage destination. Also, it cannot be grasped that the data saved in the card reader / writer is the data temporarily saved. Further, storing the information for the card reader / writer to transfer to the tamper-resistant module not only increases the load on the card reader / writer, but also has a security problem.</p><p> In view of the above background, an object of the present invention is to provide a secure device and a relay terminal capable of safely and surely writing data to a secure memory area regardless of the situation of the anti-tamper module.</p>
<p> The secure device of the present invention is a secure device that receives data transmitted from a service terminal via a relay terminal having an information writing function, and is a device control unit that controls the operation of one or more applications and the secure device. The device control unit includes a tamper-resistant module having the above, a secure memory that can be accessed only from the tamper-resistant module, and a communication unit for communicating with the service terminal, and the device control unit indicates a secure memory indicating a write destination of the data. The storage instruction information is generated and stored, and the communication unit transmits the storage instruction information to the service terminal. ..</p><p> By generating the storage instruction information and transmitting it to the service terminal in this way, the data can be received via the relay terminal designated by the secure device. In addition, by including information on the countermeasures when writing is not possible in the storage instruction information, when data cannot be written to the secure memory, the secure device receives the information by referring to the information on the above countermeasures. Measures such as storing the data in a designated place as an emergency evacuation can be taken.</p><p> The information on what to do when the writing is impossible is stored in the normal memory and the address of the normal memory of the secure device or the relay terminal indicating the storage destination for temporarily storing the data. It may have an identifier of the application that moves the data to the secure memory.</p><p> By including the address of the normal memory for temporarily storing the data, the data can be temporarily written to the normal memory when the data cannot be written to the secure memory. Therefore, after the data can be written to the secure memory, the data can be read from the normal memory and the data can be written to the secure memory. As a result, even if the data cannot be temporarily written to the secure memory, the data can be reliably written to the secure memory.</p><p> The information on what to do when the writing is impossible is a storage indicating a storage destination for temporarily storing the data or a storage period indicating a time limit for securing at least one of the memory areas of the data writing destination. It may have a pre-securing deadline.</p><p> By including the memory allocation deadline, it is possible to release the memory in which data is not stored even after the deadline. As a result, it is possible to prevent a decrease in the memory capacity due to the memory area being unreasonably secured.</p><p> In the secure device, the communication unit receives attribute information of data transmitted from the service terminal, and the device control unit relays data transmitted from the service terminal based on the attribute information. Is determined, and the determined address of the relay terminal may be included in the storage instruction information.</p><p> With this configuration, an appropriate relay terminal can be determined according to the attribute information received from the service terminal. Here, the attribute information includes, for example, the amount of data to be transmitted, the extension, the type of relay terminal, and the like. For example, according to the attribute of the amount of data, if the amount of data is large, it is determined as a home PC, and if the amount of data is small, it is determined as a relay terminal that receives a mobile terminal. It is possible to avoid the inconvenience that the mobile terminal cannot process the data until it is received.</p><p> In the secure device, the communication unit receives the attribute information of the data transmitted from the service terminal, and the device control unit is a communication method between the relay terminal and the service terminal based on the attribute information. May be included in the storage instruction information.</p><p> With this configuration, an appropriate communication method can be determined according to the attribute information received from the service terminal.</p><p> The relay terminal of the present invention is a relay terminal that writes data transmitted from the service terminal to a communicably connected secure device, and is a secure memory included in the secure device indicating the data and a write destination of the data. The data receiving unit that receives the storage instruction information, which consists of the address of the data and the information on what to do when the data cannot be written to the secure memory, and the secure memory that receives the received data specified by the storage instruction information. A command transmitter that sends a command to write to the address of the above to the secure device and receives a response from the secure device to the command, determines whether or not data can be written to the secure memory based on the response, and cannot write. It has a configuration including a control unit for writing the data to the normal memory of the secure device or the relay terminal based on the information on the coping method specified in the storage instruction information when the determination is made.</p><p> By writing data to normal memory when data cannot be written to secure memory in this way, data can be transferred from normal memory to secure memory when data can be written to secure memory later. You can move. As a result, even if the data cannot be temporarily written to the secure memory, the data can be reliably written to the secure memory.</p><p> The relay terminal according to another aspect of the present invention is a relay terminal that writes data transmitted from a service terminal to a communicably connected secure device, and indicates the data and the secure to which the data is written. A data receiving unit that receives storage instruction information including an address of a secure memory possessed by the device and information on a countermeasure when data cannot be written to the secure memory from the service terminal, and the secure device. The processing state is managed, whether or not data can be written to the secure memory is determined based on the processing state, and when it is determined that the data cannot be written, the above-mentioned information is based on the countermeasure specified in the storage instruction information. It has a configuration including a control unit for writing the data to a normal memory of the secure device or the relay terminal.</p><p> In this way, the control unit manages the processing status of the secure device, and if it is determined that writing is not possible based on the processing status, the data is written to the normal memory so that the data can be stored in the secure memory later. When writable, data can be moved from normal memory to secure memory. As a result, even if the data cannot be temporarily written to the secure memory, the data can be reliably written to the secure memory.</p><p> The relay terminal according to another aspect of the present invention has a configuration including a deletion unit that deletes the storage instruction information when the writing of data to the address of the normal memory specified in the storage instruction information is completed.</p><p> As a result, the risk of unauthorized reading of the storage instruction information from the relay terminal can be reduced, and security can be improved.</p><p> The information on the above-mentioned countermeasures includes the address of the normal memory of the secure device or the relay terminal indicating the storage destination for temporarily storing the data, and the data stored in the normal memory is moved to the secure memory. It may include the identifier of the application to be made to.</p><p> As a result, by including the address of the normal memory for temporarily storing the data, when the data cannot be written to the secure memory, the data can be temporarily written to the normal memory. Therefore, after the data can be written to the secure memory, the data can be read from the normal memory and the data can be written to the secure memory. As a result, even if the data cannot be temporarily written to the secure memory, the data can be reliably written to the secure memory.</p><p> The information regarding the above-mentioned remedy may include a storage destination reservation deadline indicating a storage destination for temporarily storing the data or at least one of the memory areas for writing the data. Good.</p><p> As a result, it is possible to release the memory in which the data is not stored even after the expiration date, and it is possible to prevent the memory capacity from being reduced due to the memory area being unreasonably secured.</p><p> In the relay terminal, the command transmission unit outputs a start command of the application corresponding to the application identifier based on the identifier of the application specified in the storage instruction information, and for the started application, the normal memory. A data movement instruction for moving the data temporarily stored in the secure memory to the address of the secure memory may be output.</p><p> By transmitting the instruction to move the data from the normal memory to the secure memory to the secure device together with the identifier of the application specified by the storage instruction information read from the secure device in this way, the secure device transfers the data from the normal memory. The read data can be read and the read data can be stored in the secure memory. As a result, the data temporarily stored in the normal memory can be moved to the secure memory.</p><p> In the relay terminal, the command transmission unit outputs an application start command corresponding to the application identifier based on the application identifier specified in the storage instruction information, and the started application is the storage instruction information. The data temporarily stored in the normal memory may be moved to the address of the secure memory with reference to.</p><p> By transmitting the identifier of the application specified by the storage instruction information read from the secure device to the secure device in this way, the secure device starts the specified application. Then, the launched application refers to the storage instruction information held by the secure device itself, reads the data stored in the normal memory and stores it in the secure memory, so that the data temporarily stored in the normal memory is stored. Can be moved to secure memory.</p><p> The relay terminal further includes a data reading unit that accesses the address of the normal memory specified by the storage instruction information and reads out the data temporarily stored in the normal memory, and the command transmitting unit is the storage unit. Based on the identifier of the application specified in the instruction information, an application start command corresponding to the application identifier is output, and the started application is sent to the secure memory address of the data read by the data reading unit. You may output a write instruction instructing the writing of.</p><p> Based on the address of the normal memory specified in the storage instruction information read from the secure device in this way, the data stored in the normal memory is read, and the data write command to the secure memory is transmitted to the secure device together with the read data. By doing so, the data temporarily stored in the normal memory can be moved to the secure memory.</p><p> The operation method of the secure device of the present invention is an operation method of a secure device that receives data transmitted from a service terminal via a relay terminal having an information writing function, and the secure device is the write destination of the data. A step of generating storage instruction information including an address of a secure memory of the secure device indicating the above and information on a countermeasure when data cannot be written to the secure memory, and the secure device generates the storage instruction information. It has a configuration including a step of transmitting to the service terminal.</p><p> With this configuration, similarly to the secure device of the present invention, even in a state where data cannot be temporarily written to the secure memory, data can be reliably written to the secure memory based on the storage instruction information. .. It is also possible to apply various configurations of the secure device of the present invention to the operation method of the secure device of the present invention.</p><p> The program of the present invention is an operation program of a secure device that receives data transmitted from a service terminal via a relay terminal having an information writing function, and is an address of a secure memory indicating a writing destination of the data and the secure memory. The secure device is made to execute a step of generating storage instruction information including information on a coping method when data cannot be written to the data, and a step of transmitting the storage instruction information to the service terminal.</p><p> With this configuration, similarly to the secure device of the present invention, even in a state where data cannot be temporarily written to the secure memory, data can be reliably written to the secure memory based on the storage instruction information. .. It is also possible to apply various configurations of the secure device of the present invention to the program of the present invention.</p>
<p> According to the present invention, by including the address of the normal memory for temporarily storing the data in the storage instruction information, when the data cannot be written to the secure memory area, the data is temporarily written to the normal memory. After the data can be written to the secure memory area, the write can be executed, and even if the data cannot be temporarily written to the secure memory area, the data can be reliably written to the secure memory area. be able to.</p>
Hereinafter, the secure device and the relay terminal according to the embodiment of the present invention will be described with reference to the drawings. In the following description, an IC card system in which data is transmitted from the service terminal 60 to the relay terminal 40 and the relay terminal 40 writes data to the IC card 10 which is one of the secure devices will be described as an example. In this system, the purchase of content is determined by communication between the service terminal 60 and the IC card 10, and the purchased content data is distributed from the service terminal 60 to the relay terminal 40. Then, the relay terminal 40 operates in a flow of storing the content data in the secure memory area 18 of the IC card 10.
FIG. 1 is a diagram showing an IC card system including an IC card and a relay terminal according to the first embodiment of the present invention. The IC card system includes an IC card 10, a service terminal 60 that provides information to the IC card 10, and a relay terminal 40 that writes information to the IC card 10.
The IC card 10 includes a Tamper Resistant Module (hereinafter referred to as TRM) 12 and a memory 22 including a secure memory area 18 and a normal memory area 20. The secure memory area 18 is an area accessible only by the TRM 12. The normal memory area 20 is an area accessible from the TRM 12 and the contact interface 26.
The TRM 12 includes a card control unit 14 that controls the operation of the IC card 10 and a single or multiple card application (hereinafter referred to as card application) 16. The TRM12 hardware is a single module with a CPU and ROM. The card application 16 is stored in the ROM, and the CPU reads the card application 16 from the ROM and executes it to control the operation of the IC card 10.
Further, the IC card 10 has a non-contact interface 24 and a contact interface 26. In the present embodiment, the non-contact interface 24 communicates with the service terminal 60, and the contact interface 26 communicates with the relay terminal 40.
The contact interface 26 is connected to the TRM 12 and the normal memory area 20. When the contact interface 26 receives a memory access command from the outside, it normally accesses the memory area 20, and when it receives an IC card access command, it accesses the secure memory area 18 via the TRM 12. While the memory access command is always received by the contact interface 26, the IC card access command is not received when the IC card 10 is busy and returns an error to the contact I / F 52. Examples of the busy state of the IC card 10 include the case where the non-contact interface 24 is processing in the IC card 10 in which the non-contact interface 24 and the contact interface 26 cannot operate at the same time, and other processing in the single-channel IC card 10. It may have been done.
Also, instead of detecting busyness by sending an IC card access command to the IC card 10 and receiving an error, the card access control unit 54 of the relay terminal 40 indicates that the IC card 10 is starting non-contact processing. It is possible to manage that the contact processing is being started and not to send the start request of the other communication processing to the IC card 10 when one of the processing is being performed. Further, even when the connection is established up to the maximum number of channels during the contact process, the card access control unit 54 may determine that the connection is busy and prevent further access requests from being transmitted to the IC card 10.
The non-contact interface 24 is connected to the TRM 12. The non-contact interface 24 transmits the information input from the outside to the TRM 12 and also transmits the information passed from the TRM 12 to the outside. As the non-contact interface 24, for example, an interface such as ISO / IEC 14443 Type A or Type B, JICSAP 2.0, infrared communication, or Bluetooth can be used. In the example shown in FIG. 1, the non-contact I / F 24 is located in the IC card 10, but the present invention is not limited to this, and a part or all of the non-contact I / F is the relay terminal 40. The IC card 10 may be configured to perform non-contact communication with the service terminal 60 via the contact I / Fs 26 and 52 on the side.
The relay terminal 40 includes a terminal control unit 42, RAM44, ROM46, display unit 48, and communication unit 50 provided in a general computer, as well as a contact interface 52 for reading and writing information on the IC card 10 and card access control. It has a part 54. As the relay terminal 40, for example, a mobile terminal with a mobile phone function, an Internet-connected PC, an Internet-connected TV, or the like can be used.
The service terminal 60 includes a non-contact interface 72 for wireless communication with the IC card 10 in addition to the configuration of the control unit 62, RAM64, ROM66, communication control unit 68, and communication interface 70 provided in a general computer. The content data to be transmitted to the IC card 10 is stored in the ROM 66 of the service terminal 60.
Next, the operation of the IC card system of the first embodiment will be described. First, the operation when the IC card 10 can normally write data to the secure memory area 18 instead of busy will be described, and then the operation when the TRM 12 is busy will be described.
FIG. 2 is a diagram showing a flow of data transmitted / received between the IC card 10, the service terminal 60, and the relay terminal 40. First, non-contact communication is performed between the IC card 10 and the service terminal 60 to connect a session (S10).
FIG. 3 is a diagram showing in detail the processing of the IC card 10 and the service terminal 60. First, the IC card 10 and the service terminal 60 activate the card application 16 (S40). After that, mutual authentication is performed between the IC card 10 and the service terminal 60 (S42), a secure communication path is generated, and the session key is shared (S44). By the operations up to this point, the IC card 10 and the service terminal 60 are saved up to the common session key shown in FIG. 2 (S12).
Next, as shown in FIG. 3, payment processing is performed between the IC card 10 and the service terminal 60 (S46). Here, the IC card 10 transmits a content data purchase request to the service terminal 60, and the service terminal 60 determines the distribution of the content data in response to the purchase request. As a result, payment processing for content data purchase is performed between the IC card 10 and the service terminal 60. Subsequently, the service terminal 60 transmits the attribute information of the content data to the IC card 10 (S48).
When the IC card 10 receives the attribute information transmitted from the service terminal 60 (S50), the IC card 10 generates the storage instruction information 30 based on the received attribute information (S52). Here, the storage instruction information 30 generated by the IC card 10 will be described.
FIG. 4 is a diagram showing an operation in which the IC card 10 generates the storage instruction information 30 and transmits it to the service terminal 60. First, the service terminal 60 transmits data attribute information to the IC card 10 (S60). Data attribute information includes data amount, data type, and the like. When the card application 16 of the IC card 10 receives the attribute information transmitted from the service terminal 60, the card application 16 passes the received attribute information to the card control unit 14 (S62). The card control unit 14 determines the transmission destination and transmission route of the data transmitted from the service terminal 60 based on the attribute information (S64). The processing of S64 to S74 of the card control unit may be incorporated into the card OS in the form of a library, or may be held in the TRM in the form of a card application.
FIG. 5 is a diagram showing an example of a table held by the card control unit for determining a destination and a temporary storage destination in the event of a write error when the data size is received as attribute information. As shown in FIG. 5, the table has destination information and information indicating what to do in case of an error in relation to the data size. In the table shown in FIG. 5, when the data size is less than 100KB, the device address of the mobile terminal is specified as the relay terminal, and when the data size is 100KB or more, the device address of the home server is specified as the relay terminal. As a result, in the case of a small amount of data, it can be received by a mobile terminal and used smoothly, and in the case of a large amount of data, it can be received by a home server having a large storage capacity. As for the countermeasures in case of an error, if the data is less than 100KB, it is specified to store it in the normal memory area 20 in the IC card 10. As a result, it is possible to avoid pressure on the memory of the mobile terminal. If the data is 100KB or more and less than 100MB, it is specified to be stored in the normal memory of the home server. As a result, the normal memory of a large-capacity home server can generally be used as a temporary storage area. In this way, using the table shown in FIG. 5, it is possible to determine an appropriate destination and temporary storage destination according to the data size. In addition, you may specify two or more measures to deal with an error. For example, the first countermeasure is to specify storage in the normal memory area 20 in the IC card 10, and the second countermeasure is to specify storage in the normal memory area in the relay terminal 40. By doing so, even if the IC card is not inserted in the relay terminal, it can be temporarily saved in the normal memory in the relay terminal 40 by the second countermeasure. Further, the attribute information received from the service terminal 60 is not limited to the data size, and for example, the data type may be received as the attribute information. In this case, for example, a table as shown in FIG. 6 is provided, and the destination is determined according to the data type.
As for the countermeasures in case of an error, after checking the free memory area (S66, S68, S70, S72 in Fig. 4), the card control unit 14 of the 10 IC cards dynamically responds to the free memory area. You may decide. In that case, the column of the action to be taken in case of an error may be omitted in the tables of FIGS. 5 and 6.
As shown in FIG. 4, after determining the destination, the card control unit 14 confirms the free area of the secure memory area 18 (S66) and secures the data storage area (S68). As a result, it is possible to prevent writing of other data to the secured data storage area and reliably store the data in the secure memory area 18. Subsequently, the card control unit 14 confirms the free area in the normal memory area 20 (S70), and secures the area of the temporary storage destination of the data (S72). This prevents writing of other data to the reserved temporary storage area, and even if the IC card 10 is busy and cannot store data in the secure memory area 18, the data can be reliably stored in the normal memory area 20. Can be stored. However, for the normal memory area 20 which is a temporary storage destination of data, the writing destination may not be specified or the memory area may be secured, and the data may be written in an empty area. That is, step S72 may be omitted. Next, the card control unit 14 creates the storage instruction information 30 (S74).
FIG. 7 is a diagram showing an example of the storage instruction information 30. As shown in FIG. 7, the storage instruction information 30 includes each information of "destination information", "card application ID", "storage destination address", "storage destination at the time of error", and "data size". The destination information is the address of the destination determined in the step of determining the destination. In the example shown in FIG. 7, the destination information includes the device address of the mobile terminal as the relay terminal of the destination, and also includes the information "blt" indicating that the communication method is Bluetooth. When the communication method is infrared, IP, file transfer, etc., the information shown in FIG. 8 is included in the destination information. The card application ID is information that identifies the card application 16 that executes data reception processing. The storage destination address is information indicating the address of the storage destination area secured in step S68. The storage destination at the time of an error is information indicating the address of the storage destination area secured in step S72. The data size is information indicating the data size of the reserved area. If the storage destination area at the time of an error is not secured, only the normal memory area is specified as the storage destination at the time of an error.
In addition, the storage instruction information 30 may also include a storage destination reservation deadline. The storage destination reservation deadline is a date and time indicating the deadline for securing the area secured in steps S68 and S72.
As shown in FIG. 4, the card control unit 14 of the IC card 10 transmits the storage instruction information 30 to the generated card application 16 (S76). The card application 16 saves the received storage instruction information 30 and transmits the storage instruction information 30 to the service terminal 60 (S78, S80). As shown in FIG. 9, the storage instruction information 30 stored in the IC card 10 does not have to include the destination information. Since the destination information is information for the service terminal 60 to grasp the relay terminal 40 to which the data should be transmitted, it does not have to be included in the data transmitted from the service terminal 60 to the relay terminal 40. The storage instruction information has been described above.
As shown in FIG. 3, the IC card 10 transmits the storage instruction information 30 to the service terminal 60 (S54). The service terminal 60 receives the storage instruction information 30 transmitted from the IC card 10, and the communication between the IC card 10 and the service terminal 60 is completed (S56).
As shown in FIG. 2, when the service terminal 60 receives the storage instruction information 30 transmitted from the IC card 10 (S20), the service terminal 60 relays the content data requested from the IC card 10 as specified by the storage instruction information 30. Send to terminal 40 (S22 ~ S28).
FIG. 10 is a diagram showing in detail the processing of the service terminal 60 and the relay terminal 40. First, the service terminal 60 encrypts the data to be transmitted with the session key and generates the encrypted data (S90). When the encryption is completed, the service terminal 60 deletes the session key used for the encryption (S92). Next, the service terminal 60 adds a header to the encrypted data and transmits the encrypted data to the relay terminal 40 (S94).
11 (a) and 11 (b) are diagrams showing an example of data transmitted from the service terminal 60 to the relay terminal 40. As shown in FIG. 11A, a header is added to the encrypted data in the data transmitted here. It is preferable to adopt the TLV format for the header. Figure 11 (b) shows the contents of the data contained in the header. The header includes a terminal middleware (MW) ID that identifies the relay terminal 40, and storage instruction information 30. Further, as shown in FIG. 11 (b), the session ID, the data ID, and the R / W ID may be included in the header.
The communication unit 50 of the relay terminal 40 receives the encrypted data transmitted from the service terminal 60 (S96). Then, the relay terminal 40 transmits a response signal regarding the reception processing of the encrypted data to the service terminal 60 (S98), and the service terminal 60 receives the response signal between the service terminal 60 and the relay terminal 40. Communication is complete (S100). By the operations up to this point, the transmission of the encrypted data shown in FIG. 2 and the transmission of the response are completed (S26, S28).
Next, the relay terminal 40 writes the received encrypted data to the IC card 10 (S30).
FIG. 12 is a diagram showing in detail the processing of the relay terminal 40 and the IC card 10, and FIG. 13 is a diagram showing the flow of data when writing data to the IC card 10. As shown in FIG. 12, when the relay terminal 40 receives the storage instruction information 30 and the encrypted data transmitted from the service terminal 60 (S110), the application ID is specified for the IC card 10 and the card application 16 Instruct to start (S112). Specifically, the card access control unit 54 of the relay terminal 40 transmits an IC access command for activating the card application 16. When the card control unit 14 of the IC card 10 receives the IC access command transmitted from the relay terminal 40, it activates the designated card application 16 and transmits the processing result to the relay terminal 40 (S114).
Next, the card access control unit 54 of the relay terminal 40 transmits the encrypted data to the IC card 10 and instructs the IC card 10 to store the encrypted data at the storage destination address specified in the storage instruction information 30. (S116). The card application 16 of the IC card 10 decrypts the received encrypted data with the session key (S118), and passes the decrypted data to the card control unit 14 (S120). The card control unit 14 encrypts the decrypted data with the storage key (S122), and stores the encrypted data in the secure memory area 18 (S124). When the card control unit 14 receives an OK notification indicating the result of correctly storing the encrypted data (S126), the card control unit 14 notifies the card application 16 of the result of the storage process (S128). When the card application 16 receives an OK notification indicating the result of correctly storing the data, it deletes the session key (S130) and sends the result to the card control unit 14 (S132). When the card control unit 14 receives an OK notification from the card application 16, it releases the storage destination memory reserved as a temporary storage destination in the event of an error (S133). Then, the storage instruction information 30 is deleted (S134), and the result of the data storage process is transmitted to the relay terminal 40 (S136). When the relay terminal 40 receives the OK notification indicating the result of correctly storing the data, the relay terminal 40 deletes the storage instruction information 30 (S138). The processing order of the session key deletion processing (S128 to S132) and the storage destination memory release processing (S133) is not limited to the above, and may be interchanged. Further, if the temporary storage destination is not secured at the time of an error and the temporary storage destination is to be temporarily stored in the free area, step S133 may be omitted. The operation of writing data normally without the IC card 10 being busy has been described above.
Next, the operation when the TRM 12 of the IC card 10 is busy when writing data in the secure memory area 18 will be described. To explain the outline of the operation, when the TRM 12 is busy, the relay terminal 40 temporarily stores the encrypted data in the normal memory area 20, and stores the storage instruction information 30 from the IC card 10 at an appropriate timing. It is read and data is moved from the normal memory area 20 to the secure memory area 18 based on the storage instruction information 30. The busy state of the IC card 10 may be detected by an error notification when the IC card 10 is accessed, or may be determined by the card access control unit 54 of the relay terminal 40.
FIG. 14 is a diagram showing the processing of the relay terminal 40 and the IC card 10, and FIG. 15 is a diagram showing the data flow when the IC card 10 is busy when writing data in the secure memory. As shown in FIG. 14, when the relay terminal 40 receives the storage instruction information 30 and the encrypted data from the service terminal 60 (S140), the relay terminal 40 specifies the application ID for the IC card 10 and starts the card application 16. Instruct (S142). Specifically, the card access control unit 54 of the relay terminal 40 transmits an IC access command for activating the card application 16. Since the IC card 10 is in a busy state, the IC card 10 transmits the NG processing result indicating the application startup failure to the relay terminal 40 (S144).
When the relay terminal 40 receives the NG processing result from the IC card 10, it stores the encrypted data in the normal memory area 20 of the IC card 10 (S146). Specifically, the card access control unit 54 of the relay terminal 40 sends a memory access command by designating the address of the temporary storage destination specified in the storage instruction information 30. Since the memory access command is always received by the IC card 10 and an area for storing data is secured in the normal memory area 20, the encrypted data can be reliably stored in the normal memory area 20. Here, as shown in FIG. 15, the encrypted data received by the relay terminal 40 is stored as it is in the normal memory area 20. If only normal memory is specified as the storage destination when an error occurs in the storage instruction information 30, the storage destination address is dynamically set by the card control unit. Then, the card control unit adds the address in which the data is stored to the storage destination of the storage instruction information 30 held internally at the time of an error. In the case of the relay terminal 40 in which the card access control unit 54 can determine the busy state of the card, the encrypted data is directly encrypted without receiving the activation instruction (S142) of the card application 16 and the reception of the NG processing result (S144). Is stored in the normal memory area 20 of the IC card 10 (S146).
When the relay terminal 40 receives the OK processing result indicating that the encrypted data storage in the normal memory area 20 is successful from the IC card 10 (S148), the storage instruction information 30 is deleted (S150). By the above operation, when the IC card 10 is in a busy state, data can be temporarily stored in the normal memory area 20.
Next, the operation of moving the data stored in the normal memory area 20 to the secure memory area 18 at an appropriate timing will be described.
FIG. 16 is a diagram showing the processing of the relay terminal 40 and the IC card 10, and FIG. 17 is a diagram showing a data flow when the data stored in the normal memory area 20 is moved to the secure memory area 18. As shown in FIG. 16, the relay terminal 40 transmits a request for acquisition of the storage instruction information 30 to the IC card 10 (S160). The timing for transmitting the acquisition request for the storage instruction information 30 may be when a certain period of time has passed since the busyness of the IC card 10 was detected, or the IC card access command for monitoring the status of the IC card 10 is sent to the IC card 10. It may be sent to and received an OK response.
When the card control unit 14 of the IC card 10 receives the acquisition request of the storage instruction information 30 from the relay terminal 40, the card control unit 14 transmits the storage instruction information 30 to the relay terminal 40 (S162). Next, the relay terminal 40 specifies the application ID specified in the acquired storage instruction information 30, and transmits an IC access command for activating the card application 16 to the IC card 10 (S164). When the card control unit 14 of the IC card 10 receives the IC access command, it performs the activation processing of the designated card application 16 and transmits the processing result to the relay terminal 40 (S166). In the example shown in FIG. 16, the card application 16 is normally started, and OK is transmitted to the relay terminal 40 as a processing result.
After the card application 16 is started, the relay terminal 40 transmits a data movement command from the normal memory area 20 to the secure memory area 18 to the IC card 10 (S168). Specifically, the address where the encrypted data is temporarily stored and the address of the secure memory area 18 which is the storage destination are extracted from the storage instruction information 30, and an IC access command including the extracted address information is transmitted to the IC card 10. .. When the card application 16 of the IC card 10 receives a data movement command from the relay terminal 40, the card application 16 moves data based on the received data movement command. That is, the card application 16 accesses the normal memory area 20 based on the specified storage address and reads the encrypted data stored in the normal memory area 20 (S170, S172). Subsequently, the card application 16 decrypts the read encrypted data with the session key (S174), and passes the decrypted data and the data storage destination address to the card control unit 14 (S176).
The card control unit 14 encrypts the data passed from the card application 16 with the storage key (S178), and stores the encrypted data in the secure memory area 18 indicated by the specified storage address (S180). When the card control unit 14 receives an OK response indicating that the encrypted data has been successfully stored (S182), the card control unit 14 sends an OK response to the card application 16 (S184). In response to this OK response, the card application 16 deletes the session key (S186) and sends an OK response to the card control unit 14 (S188). In response to this OK response, the card control unit 14 deletes the storage instruction information 30 (S190) and sends an OK response to the relay terminal 40 (S192). When the relay terminal 40 receives an OK notification from the IC card 10 indicating that the data movement has been completed normally, the relay terminal 40 deletes the storage instruction information 30 (S194). By moving the data (S170, S172), the memory area of the temporary storage destination of the data secured in step 72 is released. As described above, by the operations shown in FIGS. 16 and 17, the data temporarily stored in the normal memory area 20 can be moved to the secure memory area 18.
Next, when the data stored in the normal memory area 20 cannot be moved to the secure memory area 18 at an appropriate timing, and the "storage destination reservation deadline" instructed in the storage instruction information 30 has come. Will be described.
FIG. 27 is a diagram showing processing of the relay terminal 40 and the IC card 10 when the storage destination reservation deadline has come. The card access control unit 54 of the relay terminal 40 notifies from the card control unit 14 that the date and time indicated in the "storage destination reservation deadline" has been reached, or the relay terminal 40 is inside the card control unit 14. It is detected by acquiring the stored storage instruction information 30. When detecting by the notification from the card control unit 14, the relay terminal 40 immediately acquires the storage instruction information 30 from the IC card 10. Since the procedure for acquiring the storage instruction information 30 is the same as that shown in FIG. 16, it is omitted in FIG. 27.
When the card access control unit 54 of the relay terminal 40 detects that the date and time indicated in the "storage destination reservation deadline" has been reached (S271), the data stored in the normal memory area 20 is moved to the secure memory area 18 again. Perform the process of causing. Specifically, the application ID specified in the storage instruction information 30 is specified, and an IC access command for activating the card application 16 is transmitted to the IC card 10 (S272). If the card application 16 fails to start (S273), or if an error occurs during the data movement process as shown in Fig. 16 and the data is not moved normally, the card access control of the relay terminal 40 54 sends a clear command to the card control unit 14 (S274). When the card control unit 14 receives the clear command, the data temporarily stored in the normal memory is deleted (S275 to S277), the session key stored by the card application is deleted (S278 to S280), and the card control unit 14 is secured in step 68. Release the secure memory area 18 (S281). Then, the storage instruction information 30 is deleted (S282), and the relay terminal 40 is notified that it has succeeded (S283). Upon receiving the notification, the relay terminal 40 deletes the storage instruction information 30 acquired in advance (S284). The processing order of the data deletion process temporarily stored in the normal memory, the session key deletion process stored in the card application, and the release process of the secure memory area 18 is not limited to the above, and may be interchanged.
As described above, by the operation shown in FIG. 27, it is possible to prevent the remaining amount of memory from becoming low even though the data is not stored while the secure memory area is secured.
In addition, when the encrypted data is not transmitted from the service terminal 60 to the relay terminal 40 (S26 in FIG. 2) and the storage destination reservation deadline instructed in the storage instruction information 30 has come, FIG. 27 Similarly, the card access control unit 54 of the relay terminal 40 sends a clear command to the card control unit 14 (S274). However, in this case, the deletion of the data temporarily stored in the normal memory (S275 to S277) may be omitted.
In the embodiment of the present invention, the card access control unit 54 of the relay terminal 40 always stores the storage instruction information 30 in the card control unit 14 when the IC card 10 is inserted into the relay terminal 40 and the initial processing of the IC card is performed. Check if it is saved. When the storage instruction information 30 is saved, the above-mentioned movement process of the saved data is performed. If the storage destination reservation period has expired, the clearing process shown in FIG. 27 is performed.
The IC card 10 and the relay terminal 40 according to the first embodiment of the present invention have been described above.
The IC card 10 of the first embodiment stores the storage instruction information 30 that specifies the data storage destination and the temporary storage destination, and stores the data in the card control unit 14. Then, when writing the data in the secure memory area 18 of the IC card 10 from the relay terminal 40, if the TRM12 of the IC card 10 is busy, the data is temporarily stored in the normal memory area 20 of the temporary storage destination. After that, the data is moved from the temporary storage destination to the secure memory area 18 which is the final storage destination. As a result, data can be reliably stored in the secure memory area 18 of the IC card 10 even when the TRM 12 is busy.
Further, since the relay terminal 40 temporarily stores the data in the normal memory area 20, the storage instruction information 30 is deleted, and the storage instruction information 30 is read from the IC card 10 when the data is moved later. The risk of reading the storage instruction information 30 including the temporary storage destination address from the relay terminal 40 can be reduced, and the security can be improved.
Further, since the relay terminal 40 of the data transmission destination is determined according to the attribute information of the data and the storage instruction information 30 including the destination information for specifying the relay terminal 40 is transmitted to the service terminal 60, the service terminal 60 Can send data to the appropriate relay terminal 40.
Further, since the card control unit 14 secures the storage destination in the secure memory area 18, data can be stored in the secure memory area 18 without causing a memory shortage, and the relay terminal can be stored according to the storage destination reservation deadline. By executing the clear process by 40, it is possible to prevent the memory from being secured and the available area of the secure memory area from being reduced.
Further, since the relay terminal 40 always checks for the presence or absence of the storage instruction information 30 when the IC card 10 is newly inserted, the data to be securely stored remains normally stored in the memory area 20. Can be prevented and security can be improved.
Next, a modified example of the IC card system of the first embodiment will be described. The basic configuration of the IC card system according to the modified example is the same as that of the IC card system of the first embodiment, but the operation when moving data from the normal memory area 20 to the secure memory area 18 is different.
FIG. 18 is a diagram showing the processing of the relay terminal 40 and the IC card 10, and FIG. 19 is a diagram showing a data flow when the data stored in the normal memory area 20 is moved to the secure memory area 18. In the IC card system according to the modified example, the operation of moving data from the normal memory area 20 to the secure memory area 18 is basically the same as that of the first embodiment, but the data movement command transmitted by the IC card 10 Is different in that the temporary storage address and the storage address are not included. When the card application 16 of the IC card 10 receives the data movement command from the relay terminal 40 (S208), the card application 16 reads the storage instruction information 30 stored in the card control unit 14 (S210, S212), and then the temporary storage destination address and the storage destination. Get the address. The operation after acquiring the temporary storage destination address and the storage destination address is the same as that of the IC card system of the first embodiment.
Next, the IC card system according to the second embodiment of the present invention will be described. The basic configuration of the IC card system of the second embodiment is the same as that of the IC card system of the first embodiment, but the configuration of the IC card 10 used in the second embodiment is the first. It is different from the embodiment of. Along with this, the procedure for moving the data temporarily stored in the normal memory area 20 to the secure area is also different from that of the first embodiment.
FIG. 20 is a diagram showing a configuration of an IC card 10 used in the second embodiment. In the IC card 10 of the second embodiment, unlike the first embodiment, the TRM 12 cannot normally access the memory area 20. With this configuration, the TRM 12 and the secure memory area 18 can be separated from the normal memory area 20 to further improve security.
FIG. 21 is a diagram showing the processing of the relay terminal 40 and the IC card 10, and FIG. 22 is a diagram showing a data flow when the data stored in the normal memory area 20 is moved to the secure memory area 18.
As shown in FIG. 21, the operation until the relay terminal 40 acquires the storage instruction information 30 from the IC card 10 at an appropriate timing and starts the card application 16 (S240 to S246) is the first embodiment. It is the same. In the second embodiment, after starting the card application 16, the relay terminal 40 accesses the normal memory area 20 of the IC card 10 and reads out the temporarily stored data. Specifically, the relay terminal 40 transmits a memory access command for reading the encrypted data from the storage destination address specified in the storage instruction information 30 (S248), and receives the data from the IC card 10 (S250).
Next, the relay terminal 40 transmits the encrypted data read from the normal memory area 20 to the IC card 10 and also transmits an IC access command for storing the encrypted data (S252). The card application 16 of the IC card 10 decrypts the received encrypted data with the session key (S254), and passes the decrypted data to the card control unit 14 (S256). The card control unit 14 encrypts the data passed from the card application 16 with the storage key (S258), and stores the encrypted data in the secure memory area 18 (S260). The operation after the card control unit 14 stores the data in the secure memory area 18 (S262 to S274) is the same as that of the first embodiment.
The IC card 10 and the relay terminal 40 according to the second embodiment of the present invention have been described above.
The relay terminal 40 of the second embodiment reads data temporarily stored in the normal memory area 20 of the IC card 10 and writes the read data to the secure memory area 18. With this configuration, even in the IC card 10 of the type in which the TRM 12 cannot normally access the memory area 20, there is an effect that data can be reliably received as in the first embodiment.
Next, a modified example of the IC card system of the second embodiment will be described. The IC card system according to the modified example differs from the second embodiment in that the terminal memory area (RAM) 44 temporarily stores the data received by the relay terminal 40.
FIG. 23 is a diagram showing the processing of the relay terminal 40 and the IC card 10, and FIG. 24 is a diagram showing the data flow when the data stored in the terminal memory area 44 is moved to the secure memory area 18.
As shown in FIG. 23, the operation until the relay terminal 40 acquires the storage instruction information 30 from the IC card 10 at an appropriate timing and starts the card application 16 (S280 to S286) is the second embodiment. It is the same. In the modified example, the card access control unit 54 of the relay terminal 40 accesses the terminal memory area 44 (S288) after starting the card application 16, and reads out the temporarily stored data (S290). The operation after reading the temporarily stored data (S292 to S314) is the same as that of the second embodiment.
In this way, the received data is temporarily stored in the terminal memory area 44, and the data in the secure memory area 18 is moved from the terminal memory area 44 to limit the remaining capacity of the normal memory area 20 of the IC card 10. I don't receive it. That is, even when the remaining capacity of the normal memory area 20 is small , the IC card 10 can reliably receive data.
Although the secure device and the relay terminal of the present invention have been described in detail with reference to the embodiments, the secure device and the relay terminal of the present invention are not limited to the above-described embodiments.
In the above-described embodiment, when writing data from the relay terminal 40 to the IC card 10, signature verification may be performed with the session key.
FIG. 25 is a diagram showing a data writing process including step S330 of signature verification using the session key. As shown in FIG. 25, the security can be further improved by performing signature verification using the session key after the IC card 10 receives the encrypted data.
Further, in the above-described embodiment, the session key may be managed for each session ID.
FIG. 26 is a diagram showing a data writing process including step S332 for selecting the session key according to the session ID. As shown in FIG. 25, after the IC card 10 receives the encrypted data, the session ID is read from the header and the session key corresponding to the session ID is selected. Then, the IC card 10 decodes the data using the selected session key. With this configuration, an appropriate session key can be selected according to the session ID, so that data can be processed appropriately even when there are a plurality of sessions for transmitting data from the service terminal 60 to the IC card 10.
In the above-described embodiment, the IC card 10 has been described as an example of the secure device, but the present invention can also be applied to a secure device other than the IC card.
As described above, the present invention has the effect of being able to reliably write data to the secure memory, and is useful as a secure device or the like having a tamper-resistant area.
<figref num="1">The figure which shows the structure of the IC card system of 1st Embodiment</figref><figref num="2">The figure which shows the outline of the operation of the IC card system of 1st Embodiment</figref><figref num="3">Diagram showing the details of processing of IC cards and service terminals</figref><figref num="4">Diagram showing the operation of generating storage instruction information</figref><figref num="5">Diagram showing an example of a table used to determine the destination</figref><figref num="6">Diagram showing an example of a table used to determine the destination</figref><figref num="7">Diagram showing an example of storage instruction information</figref><figref num="8">The figure which shows the example of the destination information included in the storage instruction information</figref><figref num="9">Diagram showing an example of storage instruction information</figref><figref num="10">The figure which shows the processing of a relay terminal and a service terminal</figref><figref num="11">(a) A diagram showing the format of data transmitted from the service terminal to the relay terminal (b) A diagram showing the contents of the header</figref><figref num="12">Diagram showing the operation of writing data to an IC card</figref><figref num="13">Diagram showing the flow of data when writing data to an IC card</figref><figref num="14">Diagram showing data writing operation when the IC card is busy</figref><figref num="15">Diagram showing the flow of data when writing data when the IC card is busy</figref><figref num="16">The figure which shows the operation of moving data from a normal memory area to a secure memory area.</figref><figref num="17">Diagram showing the flow of data when moving data from the normal memory area to the secure memory area</figref><figref num="18">The figure which shows the operation of moving data from a normal memory area to a secure memory area.</figref><figref num="19">Diagram showing the flow of data when moving data from the normal memory area to the secure memory area</figref><figref num="20">The figure which shows the structure of the IC card used in the 2nd Embodiment</figref><figref num="21">The figure which shows the operation of the data movement in the 2nd Embodiment</figref><figref num="22">The figure which shows the data flow of the data movement in the 2nd Embodiment</figref><figref num="23">The figure which shows the operation of the data movement in the 2nd Embodiment</figref><figref num="24">The figure which shows the data flow of the data movement in the 2nd Embodiment</figref><figref num="25">The figure which shows the operation of writing data to an IC card in a modification</figref><figref num="26">The figure which shows the operation of writing data to an IC card in a modification</figref><figref num="27">Diagram showing the operation of data deletion when the storage destination reservation deadline is reached</figref>
Code description
10 IC card 12 Tamper resistant module 14 Card control unit 16 Card application 18 Secure memory area 20 Normal memory area 22 Memory 24 Non-contact interface 26 Contact interface 30 Storage instruction information 40 Relay terminal 42 Terminal control unit 44 RAM46 ROM48 Display unit 50 Communication unit 52 Contact interface 54 Card access control unit 60 Service terminal 62 Control unit 64 RAM66 ROM68 Communication control unit 70 Communication interface 72 Non-contact interface
28 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP5576984B2 | Cited by | Japan | Examiner |
| JP2021517409A | Cited by | Japan | Search report |
| US11902449B2 | Cited by | United States of America | Applicant |
| JP2011248495A | Cited by | Japan | Search report |
| JP2015195445A | Cited by | Japan | Search report |
| JP2008102861A | Cited by | Japan | Examiner |
| JP2015195445A | Cited by | Japan | Search report |
| US9900559B2 | Cited by | United States of America | Applicant |
| WO2012160634A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2011215983A | Cited by | Japan | Examiner |
| JP2000040138A | Cites | Japan | Examiner |
| JP2002124960A | Cites | Japan | Examiner |
| JP2003085034A | Cites | Japan | Examiner |
| JPH06502271A | Cites | Japan | Examiner |
| JPH08101751A | Cites | Japan | Examiner |
| JPH0895715A | Cites | Japan | Examiner |
7 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2004323873 | Japan | – | |
| 2004323873 | Japan | A |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| WO2006049224A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2006155589AThis record | Japan | A | |
| US2007223696A1 | United States of America | A1 | |
| CN101048779A | China | A | |
| CN100474327C | China | C | |
| JP4794269B2 | Japan | B2 | |
| US8184810B2 | United States of America | B2 |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2006155589
- Application
- 300832
Titles2
- Japanese
- セキュアデバイスおよび中継端末
- English
- Secure devices and relay terminals
Classification
- CPC, 5
- G07F7/1008
- G06K19/073
- G06Q20/341
- G06Q20/3576
- G06Q20/40975
- IPC, 5
- G06F12 14
- H04L9 10
- G06K19 07
- G06K19 073
- G06K17 00