Program execution device
Abstract
A program execution device capable of protecting a program against unauthorized analysis and alteration is provided. The program execution device includes an execution unit, a first protection unit, and a second protection unit. The execution unit executes a first program and a second program, and is connected with an external device that is capable of controlling the execution. The first protection unit disconnects the execution unit from the external device while the execution unit is executing the first program. The second protection unit protects the first program while the execution unit is executing the second program.
Term
Projected expiry 5 February 2029.
- Priority
- Filed
- Granted
- Today
- Projected expiry
9 claims: 5 independent, 4 dependent
- 1Multiple processesStatusAny of the processesBecome in a stateAn information processing device that stores a set of first program instructions including a program instruction for detecting tampering, a storage means for storing a second set of program instructions, and a memory protected from being observed by an external device. Program instructions included in the first set of program instructions using the protected memoryAt least part ofBy executing, it is determined whether or not at least a part of the second set of program instructions has been tampered with, and when it is determined that there is no tampering, the program instructions included in the second set of program instructions are executed. With the control unit、An interface that connects the control unit and the external device, A cutting means for disconnecting the control unit from the interface, A connecting means for connecting the control unit to the interface is provided. The first set of program instructions includes a disconnect command or a connection command to connect the control unit to the external device by disconnecting or connecting the control unit from the interface to the disconnecting means. The control unit further executes a program instruction included in the first set of program instructions.In the middleTo the aboveBy executing the disconnect command to cause the disconnecting means to disconnect the control unit from the interface, the state of the information processing apparatus can be changed.First, the contents of the memory are protected from observation by the external device.StatusWhen switching to and executing the program instructions included in the second set of program instructions,By causing the connection means to connect the control unit to the interface by executing the connection command.Second, the contents of the memory are not protected from observation by the external deviceStatusAn information processing device characterized by switching to. 複数の処理状態のうちいずれかの処理状態になる情報処理装置であって、 改竄の検出を行うプログラム命令を含む第1のプログラム命令の集合と、第2のプログラム命令の集合とを格納する格納手段と、 外部装置から観察できないよう保護されたメモリである保護メモリを用いて前記第1のプログラム命令の集合に含まれるプログラム命令の少なくとも一部を実行することにより、前記第2のプログラム命令の集合の少なくとも一部について改竄の有無を判断し、改竄が無いと判断された場合に、前記第2プログラム命令の集合に含まれるプログラム命令を実行する制御部と、前記制御部と前記外部装置とを接続するインターフェースと、 前記制御部を前記インターフェースと切断する切断手段と、 前記制御部を前記インターフェースと接続する接続手段とを備え、 前記第1のプログラム命令の集合は、前記切断手段に前記制御部を前記インターフェースから切断又は接続させることにより、前記制御部を前記外部装置と切断する切断命令又は接続する接続命令を含み、 前記制御部は、更に、 前記第1のプログラム命令の集合に含まれるプログラム命令を実行する最中に、前記切断命令の実行により前記切断手段に前記制御部を前記インターフェースから切断させることにより、前記情報処理装置の状態を前記メモリの内容が前記外部装置による観察から保護される第1状態へ切り替え、 前記第2のプログラム命令の集合に含まれるプログラム命令を実行する際に、前記接続命令の実行により前記接続手段に前記制御部を前記インターフェースに接続させることにより、前記メモリの内容が前記外部装置による観察から保護されない第2状態へ切り替える ことを特徴とする情報処理装置。
- 4The program instruction included in the first set of program instructions executed by the control unit calculates a hash value for at least a part of the second set of program instructions, and uses the calculated hash value as the second set. Claim 1 is characterized in that it is determined whether or not at least a part of the second set of program instructions has been tampered with by comparing at least a part of the set of program instructions of the above with a tampering detection value calculated in advance. The information processing device described in. 前記制御部によって実行された前記第1のプログラム命令の集合に含まれるプログラム命令は、前記第2のプログラム命令の集合の少なくとも一部についてハッシュ値を計算し、計算したハッシュ値を、前記第2のプログラム命令の集合の少なくとも一部について予め算出された改竄検出値と比較することにより、前記第2のプログラム命令の集合の少なくとも一部の改竄の有無を判断する ことを特徴とする請求項1に記載の情報処理装置。
- 7Multiple processesStatusAny of the processesBecome in a stateA secure processing method used in an information processing device, the information processing device stores a set of first program instructions including a program instruction for detecting tampering and a set of second program instructions. ,Furthermore, a control unit that executes the first program instruction and the second program instruction,An interface for connecting the control unit and an external device is provided. The secure processing method is A step of executing a program instruction for disconnecting the control unit from the interfaceA step of executing a program instruction for connecting the control unit to the interface, Program instructions included in the first set of program instructions using a protected memory, which is a memory protected so that it cannot be observed from an external device.At least part ofBy executing the step of determining whether or not at least a part of the second set of program instructions has been tampered with, and when it is determined that at least a part of the second set of program instructions has not been tampered with. , The step of executing the program instruction included in the second set of program instructions is included, and the program instruction included in the first set of program instructions is executed.In the middleToBy executing a program instruction that disconnects the control unit from the interface, the state of the information processing device can be changed.First, the contents of the memory are protected from observation by the external device.StatusWhen switching to and executing the program instructions included in the second set of program instructions,By executing a program instruction that connects the control unit to the interface.Second, the contents of the memory are not protected from observation by the external deviceStatusA secure processing method characterized by switching to. 複数の処理状態のうちいずれかの処理状態となる情報処理装置で用いられるセキュア処理方法であって、 前記情報処理装置は、改竄の検出を行うプログラム命令を含む第1のプログラム命令の集合と、第2のプログラム命令の集合とを格納しており、更に、第1のプログラム命令と第2のプログラム命令を実行する制御部と、当該制御部と外部装置とを接続するインターフェースとを供え、 前記セキュア処理方法は、 前記制御部を前記インターフェースから切断するプログラム命令を実行するステップと前記制御部を前記インターフェースと接続するプログラム命令を実行するステップと、 外部装置から観察できないよう保護されたメモリである保護メモリを用いて前記第1のプログラム命令の集合に含まれるプログラム命令の少なくとも一部を実行することにより、前記第2のプログラム命令の集合の少なくとも一部について改竄の有無を判断するステップと、 前記第2のプログラム命令の集合の少なくとも一部について改竄が無いと判断された場合に、前記第2プログラム命令の集合に含まれるプログラム命令を実行するステップとを含み、 前記第1のプログラム命令の集合に含まれるプログラム命令を実行する最中に、前記制御部を前記インターフェースから切断するプログラム命令を実行することにより、前記情報処理装置の状態を前記メモリの内容が前記外部装置による観察から保護される第1状態へ切り替え、 前記第2のプログラム命令の集合に含まれるプログラム命令を実行する際に、前記制御部を前記インターフェースと接続するプログラム命令を実行することにより、前記メモリの内容が前記外部装置による観察から保護されない第2状態へ切り替える ことを特徴とするセキュア処理方法。
- 8Multiple processesStatusAny of the processesBecome in a stateA computer program used in an information processing device, the information processing device stores a first set of program instructions including a program instruction for detecting tampering and a second set of program instructions.Furthermore, a control unit that executes the first program instruction and the second program instruction,An interface for connecting the control unit and an external device is provided.A program instruction that disconnects the control unit from the interface, andIt stores program instructions that connect the control unit to the interface. The computer program uses a protected memory, which is a memory protected from the information processing device so that it cannot be observed from an external device, and includes program instructions included in the first set of program instructions.At least part ofIs executed to determine whether or not at least a part of the second set of program instructions has been tampered with, and when it is determined that at least a part of the second set of program instructions has not been tampered with, the above The program instructions included in the second set of program instructions are executed, and the program instructions included in the first set of program instructions are executed.In the middleToA program instruction for disconnecting the control unit from the interface is executed to change the state of the information processing device.First, the contents of the memory are protected from observation by the external device.StatusWhen switching to and executing the program instructions included in the second set of program instructions,A program instruction for connecting the control unit to the interface is executed to change the state of the information processing device.Second, the contents of the memory are not protected from observation by the external deviceStatusA computer program characterized by switching to. 複数の処理状態のうちいずれかの処理状態となる情報処理装置で用いられるコンピュータプログラムであって、 前記情報処理装置は、改竄の検出を行うプログラム命令を含む第1のプログラム命令の集合と、第2のプログラム命令の集合とを格納しており、更に、第1のプログラム命令と第2のプログラム命令を実行する制御部と、当該制御部と外部装置とを接続するインターフェースとを供え、前記制御部を前記インターフェースから切断するプログラム命令と、前記制御部を前記インターフェースと接続するプログラム命令とを格納しており、 前記コンピュータプログラムは、前記情報処理装置に対して、 外部装置から観察できないように保護されたメモリである保護メモリを用いて前記第1のプログラム命令の集合に含まれるプログラム命令の少なくとも一部を実行することにより、前記第2のプログラム命令の集合の少なくとも一部について改竄の有無を判断させ、 前記第2のプログラム命令の集合の少なくとも一部について改竄が無いと判断された場合に、前記第2のプログラム命令の集合に含まれるプログラム命令を実行させ、 前記第1のプログラム命令の集合に含まれるプログラム命令を実行する最中に、前記制御部を前記インターフェースから切断するプログラム命令を実行させ、前記情報処理装置の状態を前記メモリの内容が前記外部装置による観察から保護される第1状態へ切り替え、 前記第2のプログラム命令の集合に含まれるプログラム命令を実行する際に、前記制御部を前記インターフェースと接続するプログラム命令を実行させ、前記情報処理装置の状態を前記メモリの内容が前記外部装置による観察から保護されない第2状態へ切り替える ことを特徴とするコンピュータプログラム。
- 9Multiple processesStatusAny of the processesBecome in a stateA computer-readable recording medium for recording a computer program used in an information processing device, wherein the information processing device includes a first set of program instructions including a program instruction for detecting tampering and a second set of program instructions. Stores a set of program instructionsFurthermore, a control unit that executes the first program instruction and the second program instruction,An interface for connecting the control unit and an external device is provided.A program instruction that disconnects the control unit from the interface, andIt stores program instructions that connect the control unit to the interface. The computer program uses a protected memory, which is a memory protected from the information processing device so that it cannot be observed from an external device, and includes program instructions included in the first set of program instructions.At least part ofIs executed to determine whether or not at least a part of the second set of program instructions has been tampered with, and when it is determined that at least a part of the second set of program instructions has not been tampered with, the above The program instructions included in the second set of program instructions are executed, and the program instructions included in the first set of program instructions are executed.In the middleToA program instruction for disconnecting the control unit from the interface is executed to change the processing state of the information processing device.First, the contents of the memory are protected from observation by the external device.StatusWhen switching to and executing the program instructions included in the second set of program instructions,A program instruction for connecting the control unit to the interface is executed.Second, the contents of the memory are not protected from observation by the external deviceStatusA recording medium characterized by switching to. 複数の処理状態のうちいずれかの処理状態となる情報処理装置で用いられるコンピュータプログラムを記録しているコンピュータ読み取り可能な記録媒体であって、 前記情報処理装置は、改竄の検出を行うプログラム命令を含む第1のプログラム命令の集合と、第2のプログラム命令の集合とを格納しており、更に、第1のプログラム命令と第2のプログラム命令を実行する制御部と、当該制御部と外部装置とを接続するインターフェースとを供え、前記制御部を前記インターフェースから切断するプログラム命令と、前記制御部を前記インターフェースと接続するプログラム命令とを格納しており、 前記コンピュータプログラムは、前記情報処理装置に対して、 外部装置から観察できないように保護されたメモリである保護メモリを用いて前記第1のプログラム命令の集合に含まれるプログラム命令の少なくとも一部を実行することにより、前記第2のプログラム命令の集合の少なくとも一部について改竄の有無を判断させ、 前記第2のプログラム命令の集合の少なくとも一部について改竄が無いと判断された場合に、前記第2のプログラム命令の集合に含まれるプログラム命令を実行させ、 前記第1のプログラム命令の集合に含まれるプログラム命令を実行する最中に、前記制御部を前記インターフェースから切断するプログラム命令を実行させ、前記情報処理装置の処理状態を前記メモリの内容が前記外部装置による観察から保護される第1状態へ切り替え、 前記第2のプログラム命令の集合に含まれるプログラム命令を実行する際に、前記制御部を前記インターフェースと接続するプログラム命令を実行させ、前記メモリの内容が前記外部装置による観察から保護されない第2状態へ切り替える ことを特徴とする記録媒体。
Independent claims5
89 paragraphs, as filed
The present invention relates to a technique for preventing unauthorized falsification and analysis of a program.
In recent years, with the spread of PCs and the Internet, it has become possible to easily copy and edit digital contents. Anti-tamper technology is indispensable to prevent unauthorized analysis and falsification of such software. Anti-tamper technology has been studied for a long time, and Non-Patent Document 1 describes basic principles and concrete methods for preventing software analysis. In addition, Non-Patent Document 2 describes technical issues and countermeasures for software analysis prevention.<nplcit num="1"><text>"Protecting software from reverse analysis and modification" Nikkei Electronics 1998.1.5 (pages 209-220)</text></nplcit><nplcit num="2"><text>"Software Anti-Tamper Technology" Fuji Xerox Technical Report No.13 (pages 20-28)</text></nplcit>
<p> However, in order to protect the program from malicious users, it is required to provide various protection technologies.</p>
<p> Therefore, the present invention has been made in view of such problems, and an object of the present invention is to provide an information processing device, a secure processing method, a computer program, and a recording medium that prevent unauthorized alteration and analysis and execute a program securely. And. In order to achieve the above object, the information processing apparatus according to the embodiment of the present invention stores a set of first program instructions including a program instruction for detecting tampering and a set of second program instructions. A set of the second program instructions is executed by executing the program instructions included in the first set of program instructions by using the storage means and the protected memory which is a memory protected so as not to be observed from an external device. It is characterized in that it includes a control unit that determines whether or not at least a part of the program instructions has been tampered with and executes a program instruction included in the second set of program instructions when it is determined that the program instruction has not been tampered with.</p>
<p> The information processing device according to the embodiment of the present invention has a storage means for storing a set of first program instructions including a program instruction for detecting tampering and a set of second program instructions, and observation from an external device. By executing the program instructions included in the first set of program instructions using the protected memory, which is a memory protected so as not to be able to perform, at least a part of the second set of program instructions has been tampered with. It is characterized in that it includes a control unit that executes a program instruction included in the set of the second program instructions when it is determined that the program instruction has not been tampered with.</p><p> With this configuration, program instructions can be protected from both external hardware attacks and software attacks.</p>
The information processing apparatus according to claim 1 is a storage means for storing a first set of program instructions including a program instruction for detecting tampering, a second set of program instructions, and an external device. Whether or not at least a part of the second set of program instructions has been tampered with by executing the program instructions included in the first set of program instructions using the protected memory, which is a memory protected so as not to be observed. It is characterized in that it is provided with a control unit that executes a program instruction included in the set of the second program instructions when it is determined that there is no tampering.
The information processing apparatus according to claim 2 further uses a first key that is accessible only by executing a program instruction included in the first set of program instructions, and encryption using the first key. It is characterized by providing a key storage means for storing the converted second key. In the information processing apparatus according to claim 3, the first key is unique to the information processing apparatus.
The information processing apparatus according to claim 4 further includes an interface for connecting the control unit and the external device, and a cutting means for disconnecting the control unit from the interface, and the first program. The set of instructions is characterized by including instructions for disconnecting the control unit from the external device by causing the disconnecting means to disconnect the control unit from the interface.
In the information processing apparatus according to claim 5, the program instructions included in the first set of program instructions executed by the control unit are hashed with respect to at least a part of the second set of program instructions. By calculating the values and comparing the calculated hash values with the tamper detection values pre-calculated for at least a portion of the second set of program instructions, at least a portion of the second set of program instructions. It is characterized by determining the presence or absence of tampering.
The information processing apparatus according to claim 6 operates in any of a plurality of processing modes, and the control unit further sets the processing mode of the information processing apparatus to the first program. When executing a program instruction included in the set of instructions, the memory contents are switched to the first mode in which the contents of the memory are protected from observation by the external device, and the program instruction included in the second set of program instructions is executed. At that time, the contents of the memory are switched to the second mode in which the contents of the memory are not protected from the observation by the external device.
In the information processing apparatus according to claim 7, the first set of program instructions includes a program instruction that handles a key used for decrypting encrypted digital contents. In the information processing apparatus according to claim 8, the second set of program instructions includes a program instruction for decrypting encrypted digital contents by using a decryption key.
Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. 1. Configuration of secure processing system 1 As shown in FIG. 1, the secure processing system 1 includes a certificate authority device 100, a ROM writer 200, a mobile terminal 300, and a memory card 400. The secure processing system 1 is a system that protects the program executed by the mobile terminal 300 from unauthorized analysis and falsification. The program to be protected is generated in the certificate authority device 100 and written to the ROM by the ROM writer 200. The ROM in which the program is written is incorporated in the mobile terminal 300.
Here, the case where the program to be protected is an encrypted music data decryption program that decrypts the encrypted music data recorded in the memory card 400 will be described as an example. 1.1 Certificate Authority Device 100 The authentication station device 100 is a device that generates a second secure processing program including an area allocation program, an interrupt prohibition program, a call program, a key reception program, an execution flag, an interrupt handler, a decryption program, and a secure program. Secure programs include encrypted music data decryption programs to be protected.
The generated second secure processing program is recorded in ROM by the ROM writer 200 and incorporated into the mobile terminal 300. Each program will be described later. As shown in FIG. 2, the certificate authority device 100 includes a compiler 101, a program encryption unit 102, a key encryption unit 103, a hash value calculation unit 104, a data embedding unit 105, a storage unit 106, and a transmission unit 107. To.
Specifically, the certificate authority device 100 is a computer system including a microprocessor, ROM, RAM, a hard disk unit, a display unit, a keyboard, and the like. A computer program is stored in the RAM or the hard disk unit. The certificate authority device 100 achieves its function by operating the microprocessor according to the computer program. (1) Compiler 101 The compiler 101 accepts the source code of the protection program, the calling program, the decoding program, and the secure program including the area allocation program, the interrupt prohibition program, the key receiving program, the execution flag, and the interrupt handler as input. The calling program is a program that transmits data to be used when detecting whether or not it has been tampered with when executing the second secure processing program, and includes the TRS area start address. The TRS area program corresponds to the decryption program 516 and the encryption program 517 of the second secure processing program. The TRS area start address is the start address on the memory after being incorporated in the mobile terminal 300.
When the compiler 101 receives the source code of the calling program, the decoding program, the secure program, and the protection program, it compiles each program as shown in FIG. First, lexical analysis is performed (step S621), parsing is performed (step S622), and binary data, which is an executable program, is generated (step S623). The compiler 101 outputs the generated call program binary data and protection program binary data to the data embedding unit 105. Further, the decryption program binary data and the secure program binary data are output to the program encryption unit 102. (2) Program encryption unit 102 The program encryption unit 102 receives the decryption program binary data and the secure program binary data. It also accepts program key input. The program encryption unit 102 uses the program key to apply the encryption algorithm E1 to the secure program to generate an encryption program. The encryption algorithm E1 is an example of AES (Advanced Encryption). Standard). Since AES is known, the description thereof will be omitted. Of course, other encryption algorithms may be used.
The program encryption unit 102 outputs the decryption program and the encryption program to the data embedding unit 105 as a TRS area program. In addition, the generated TRS area program is output to the hash value calculation unit 104. (3) Key encryption unit 103 The key encryption unit 103 accepts the input of the program key and the master key.
The key encryption unit 103 uses the master key to apply the encryption algorithm E1 to the program key to encrypt it, and generate an encryption key. The generated encryption key is output to the data embedding unit 105. (4) Hash value calculation unit 104 The hash value calculation unit 104 calculates a hash value for at least a part of the second secure processing program.
Here, the TRS area program and the private key are accepted as inputs, and the hash value for the TRS area program is calculated using the private key. As an example, the algorithm used in HMAC (Keyed-Hashing for Message Authentication) shall be used to calculate the hash value. Here, H is a hash function, K is a private key, text is the data to be hashed, opad is a character string in which the byte value Ox36 is repeated 64 times, and ipad is a character string in which the byte value Ox5C is repeated 64 times. Then, the hash value calculation algorithm is expressed as H (K XOR opad, H (K XOR ipad, text)).
Further, the hash value calculation unit 104 derives the binary size of the TRS area program. The hash value calculation unit 104 outputs the generated hash value and the binary size of the TRS area program for which the hash value is calculated to the data embedding unit 105. (5) Data embedding unit 105 The data embedding unit 105 receives the calling program binary data and the protection program binary data from the compiler 101, and receives the hash value and the binary size from the hash value calculation unit 104. In addition, the encryption key is received from the key encryption unit 103, and the TRS area program is received from the program encryption unit 102.
The data embedding unit 105 embeds the hash value received from the hash value calculation unit 104 in the calling program as a falsification detection value. Also, embed the binary size and encryption key in the calling program. Further, the calling program in which the data is embedded is included in the protection program, and the protection program and the TRS area program received from the program encryption unit 102 are combined to generate a second secure processing program and write it to the storage unit 106. (6) Storage unit 106 The storage unit 106 stores the second secure processing program written by the data embedding unit 105. (7) Transmitter 107 The transmission unit 107 outputs the second secure processing program stored in the storage unit 106 to the ROM writer. 1.2 ROM Writer 200 The ROM writer is connected to the certificate authority device 100 and writes the second secure processing program received from the certificate authority device 100 to the ROM. The ROM in which the program is written by the ROM writer 200 is incorporated into the mobile terminal 300. 1.3 Memory card 400 As shown in FIG. 4, the memory card 400 includes a control unit 401, an input / output unit 402, an authentication unit 403, and an information storage unit 404. (1) Input / output unit 402 When the memory card 400 is connected to another device, the input / output unit 402 inputs / outputs data between the other device and the control unit 401. (2) Information storage unit 404 Further, the information storage unit 404 includes a data area 410 and a secure area 420.
The data area 410 stores the encrypted music data 411. The encrypted music data 411 is generated by applying the encryption algorithm E1 to the music data in the MP3 format using the title key 421. The secure area 420 stores the title key 421, and can be read only by a device that has succeeded in mutual authentication with the authentication unit 403.
When recording the data in the information storage unit 404, it may be encrypted and recorded based on the information unique to the memory card 400. (3) Authentication unit 403 The authentication unit 403 performs mutual authentication based on the mechanism of the mobile terminal 300 and CPRM (Content Protection for Recordable Media), and when the authentication is successful, shares the key with the authenticated device. The shared key is output to the control unit 401. Since CPRM is known, the description thereof will be omitted. Further, it may be authenticated according to another authentication method. (4) Control unit 401 The control unit 401 inputs / outputs information to / from other devices via the input / output unit 402. The data stored in the secure area 420 permits access only to devices that have been successfully authenticated by the authentication unit 403. When outputting the data stored in the secure area 420, the data is encrypted using the shared key generated by the authentication by the authentication unit 403 and output.
The data stored in the data area 410 is allowed to be accessed from other devices without authentication. 1.4 Mobile terminal 300 As shown in FIG. 5, the mobile terminal 300 includes a CPU 301, a debugger interface 302, a debugger invalidation circuit 303, an interrupt controller 304, a memory 305, a memory card interface 306, an input unit 307, a display unit 308, a speaker 309, and a decoder 310. It is composed of a microphone 312, a conversion unit 313, a radio control unit 314, a radio unit 315, and an interface 316, which are connected by a bus 317, and an interrupt line 318 is connected from the interrupt controller 304 to the CPU 301.
Hereinafter, each configuration will be described. (1) Debugger invalidation circuit 303, Debugger interface 302 The debugger invalidation circuit 303 is provided between the CPU 301 and the debugger interface 302, and can connect or disconnect the CPU 301 and the debugger interface 302.
When the debugger invalidation circuit 303 receives the debugger control signal indicating "valid" from the CPU 301, it connects the CPU 301 and the debugger interface 302, and when it receives the debugger control signal indicating "invalid" from the CPU 301, the debugger 301 and the debugger interface 302 are connected. And disconnect. When the CPU 301 and the debugger interface 302 are connected, the debugger connected to the outside of the debugger interface 302 is valid, and when the CPU 301 and the debugger interface 302 are disconnected, the debugger is connected to the outside of the debugger interface 302. The debugger being used is invalid. As a specific example, the debugger invalidation circuit 303 is realized by a switch. It should be noted that the connection may be physically disconnected as in the switch circuit, or the connection may be electrically disconnected.
The debugger interface 302 is an interface for connecting the mobile terminal 300 and an external debugger. (2) Memory 305 The memory 305 stores the first secure processing program 501, the second secure processing program 502, the vector table 503, the music playback program 504, and the application 505 shown in FIG.
(A) Second secure processing program 502 The second secure processing program 502 is a program generated by the above-mentioned certificate authority device 100 and recorded in the ROM, and is composed of each program shown in FIG. 7. Hereinafter, each program will be described. (Area reservation program 511) The area allocation program 511 allocates a memory area for allocating the dynamic memory used during the execution of the authentication communication program 523 and the encrypted music data decryption program 524.
(Interruption prohibition program 512) The interrupt prohibition program 512 prohibits interrupt processing by masking interrupts. (Call program 513) The calling program 513 calls and activates the first secure processing program 501.
The calling program 513 includes tampering detection data including a tampering detection value 541, a TRS area start address 542, a binary size 543, and an encryption key 544 shown in FIG. Calls the first secure processing program 501 and sends tampering detection data. The tampering detection data is the data embedded in the data embedding unit 105 of the certificate authority device 100. The tampering detection value 541 is a hash value calculated by the certificate authority device 100 for the range of the TRS area of the second secure processing program 502.
The TRS area start address 542 indicates the start address in the memory 305 of the data for which the hash value is calculated. The binary size 543 indicates the binary size of the data for which the hash value is calculated. The encryption key 544 is generated by encrypting the program key using the master key by the key encryption unit 103 of the certificate authority device 100.
(Key receiving program 514) The key receiving program 514 receives the program key transmitted from the first secure processing program 501 and transmits it to the decryption program 516. (Execution flag 515) Execution flag 515 indicates whether or not the secure program is being executed. Before the decryption program 516 decrypts the encryption program 517, the state is set to "ON" indicating that the secure program is being executed, and the state is set to the "OFF" state when the execution of the secure program is completed.
(Decryptor 516) The decryption program 516 receives the program key from the key receiving program 514, applies the decryption algorithm D1 to the encryption program 517 using the program key, decrypts the program, and generates a secure program. Here, the technology published in WO04 / 013744 (2004.02.12) is used to decrypt the encryption program. This technology loads the encryption program into memory little by little and executes it. Therefore, since the entire decrypted program does not exist in the memory, the program is not analyzed even if the data in the memory is illegally read from the outside.
(Encryption program 517) The encryption program 517 is generated by encrypting the secure program. The secure programs include the interrupt prohibition release program 521, the area initialization program 522, the authentication communication program 523, the encrypted music data decryption program 524, the area key 525, the area encryption program 526, the area decryption program 527, and the area shown in FIG. It consists of the termination processing program 528. The interruption prohibition release program 521, the area initialization program 522, the authentication communication program 523, the area key 525, the area encryption program 526, the area decryption program 527, and the area termination processing program 528 use the encrypted music data decryption program 524 as another program. Protect from the program.
(a) Interrupt prohibition release program 521 The interrupt prohibition release program 521 cancels the interrupt prohibition performed by the interrupt prohibition program 512. (b) Area initialization program 522 The area initialization program 522 initializes the memory area secured by the area reservation program 511 and secures a storage area to be encrypted.
The storage area is a storage area used by the authentication communication program 523 and the encrypted music data decryption program 524, and data used during execution is written in the storage area. (b) Authentication communication program 523 The authentication communication program 523 holds the authentication key 531. The authentication communication program 523 performs one-way authentication as to whether or not the first secure processing program 501 is a legitimate program.
(c) Encrypted music data decryption program 524 The encrypted music data decryption program 524 decrypts the encrypted music data 411 recorded in the memory card 400 by applying the decryption algorithm D1 using the title key to generate music data. The decryption algorithm D1 is an algorithm that performs the reverse processing of the encryption algorithm E1.
(d) Area key 525 The area key 525 is used in the following area encryption program 526 to encrypt the data in the storage area and to decrypt the encrypted data in the area decryption program 527. (e) Area encryption program 526 The area encryption program 526 uses the area key 525 to encrypt the data in the storage area by applying the encryption algorithm E2. The encryption algorithm E2 is an algorithm capable of performing processing at a higher speed than the encryption algorithm E1, and is an XOR operation as an example. The encryption algorithm E2 is not limited to the XOR operation, and other encryption algorithms may be used, and is determined by the required security strength and the processing power of the CPU.
When the second secure processing program 502 calls the first secure processing program 501, the area encryption program 526 encrypts the data in the storage area before the control is transferred to the first secure processing program 501. (f) Region decoding program 527 When control returns from the first secure processing program 501 to the second secure processing program 502, the area decryption program 527 applies the decryption algorithm D2 to the encrypted data in the storage area to decrypt the data, and returns the data to plain text. ..
(g) Area termination processing program 528 The area termination processing program 528 releases the storage area secured by the area initialization program 522, calls the termination function of the first secure processing program 501, and terminates the music data reproduction processing. (Interrupt handler 518) The interrupt handler 518 is executed when an interrupt occurs during the execution of the second secure processing program 502. The interrupt handler 518 holds an encryption / decryption key (not shown).
Figure 9 shows the processing of the interrupt handler 518. Although the interrupt handler 518 is actually a computer program, it will be described using a flowchart for the sake of simplicity in FIG. Read execution flag 515 (step S611). Next, it is determined whether the read execution flag 515 indicates "ON" or "OFF" (step S612), and when it indicates "ON" (ON in step S612), the encryption / decryption key is used and the storage area is stored. The data in the data is encrypted by applying the encryption algorithm E2 (step S613). After that, it moves to interrupt processing. If the read execution flag indicates "OFF" (OFF in step S612), interrupt processing proceeds without encrypting the data in the storage area.
When the interrupt processing is completed, if the execution flag indicates "ON" (ON in step S614), the data in the storage area is decrypted by applying the decryption algorithm D2 using the encryption / decryption key (step S615), and the original processing is performed. Return to. When the execution flag indicates "OFF" (OFF in step S614), the process returns to the original process without performing the decryption process. (B) First Secure Processing Program 501 As shown in FIG. 10, the first secure processing program 501 is described from the circuit disconnection program 551, the alteration detection program 552, the key decryption program 553, the key transmission program 554 and the authentication communication program 555, the data read program 556, and the circuit connection program 557. It is configured and executed in the secure processing mode of CPU301. The secure processing mode will be described later.
(Circuit disconnection program 551) When the first secure processing program 501 is started, the circuit disconnection program 551 outputs a debugger control signal indicating "invalid" to the debugger invalidation circuit 303. (Manipulation detection program 552) The tampering detection program 552 includes the private key 562 and detects tampering with the second secure processing program 502. The tampering detection program 552 acquires tampering detection data from the second secure processing program 502.
The tampering detection program 552 reads the data of the size indicated by the binary size from the position indicated by the acquired TRS area start address in the memory 305 as the TRS area program for which the hash value is calculated. A hash function is applied to the read TRS area program using the private key 562 to calculate the hash value. The calculated hash value is compared with the acquired tampering detection value, and if they are the same, it is determined that the tampering has not been performed. If they are not the same, it is judged that they have been tampered with, and subsequent processing is prohibited.
(Key decryption program 553) The key decryption program 553 includes a master key 563. When the tampering detection program 552 does not detect the tampering of the second secure processing program 502, the key decryption program 553 applies the decryption algorithm D1 to the encryption key 544 using the master key 563 to decrypt the program key. Generate. The generated program key is transmitted to the key transmission program 554.
(Key transmission program 554) The key transmission program 554 receives the program key from the key decryption program 553 and transmits it to the second secure processing program 502. (Authentication communication program 555) The authentication communication program 555 includes the authentication key 565 and authenticates with the second secure processing program 502 using the authentication key 565. Also, if the authentication is successful, the session key is shared. After that, when sending / receiving data to / from the second secure processing program 502, encrypted communication is performed using the session key.
(Data reading program 556) The data reading program 556 performs mutual authentication with the memory card 400 according to the CPRM method, and when the authentication is successful, accesses the secure area 420 of the memory card 400 and acquires the title key 421. (Circuit connection program 557) The circuit connection program 557 outputs a debugger control signal indicating valid to the debugger invalidation circuit 303.
(C) Vector table 503 As shown in FIG. 11, the vector table 503 describes the processing destinations when software interrupts, exceptions, and hardware interrupts occur. (D) Music playback program 504 The music playback program 504 is a program that plays back the music data decoded by the second secure processing program 502, and sends the music data to be played back to the buffer 311.
(E) Application 505 Application 505 accepts input by user operation. Also, according to the input, the second secure processing program 502 is started. (3) CPU301 The CPU 301 operates according to the program stored in the memory 305. In addition, the operation is controlled by the instruction of the debugger connected via the debugger interface 302. As shown in FIG. 12, the CPU 301 fetches the instruction of the program stored in the memory 305 (step S601), interprets the read instruction (step S602), and executes it (step S603). Further, the address of the program counter is advanced (step S604), the next instruction is fetched, and the process is repeated.
Here, the CPU 301 performs processing in either a secure processing mode or a normal processing mode. The normal processing mode indicates a state in which the CPU 301 is performing normal processing, and the secure processing mode is a mode in which processing is performed while maintaining high security so that the data in the memory cannot be observed from the outside. .. The CPU 301 executes the first secure processing program 501 in the secure processing mode and executes the second secure processing program 502 in the normal mode.
Further, the CPU 301 receives an interrupt signal from the interrupt controller 304 via the interrupt line 318. The CPU 301 does not accept interrupts when the interrupt prohibition program 512 of the second secure processing program 502 is being executed. When an interrupt signal is received when the interrupt prohibition is canceled, the vector table in FIG. 11 is referred to and the address corresponding to the processing of the received interrupt signal is read. Processing is performed according to the interrupt handler of the read address, and when the interrupt processing is completed, the process returns to the original processing.
When the interrupt signal is received during the execution of the second secure processing program 502, the CPU 301 refers to the vector table 503 and executes the interrupt handler 518 shown in FIG. (4) Input unit 307 The input unit 307 accepts an external input by the user. When the input unit 307 receives an input from the outside, the input unit 307 notifies the interrupt controller 304 of the occurrence of an interrupt. (5) Interrupt controller 304 When the interrupt controller 304 is notified by the input unit 307 or the wireless control unit 314 that an interrupt such as an email reception, an incoming call, or an operation by a user has occurred, the interrupt controller 304 outputs an interrupt signal to the CPU 301 by the interrupt line 318. (6) Speaker 309, decoder 310 The decoder 310 includes a buffer 311. The buffer 311 buffers the audio data received from the CPU 301, and the speaker 309 generates and outputs an audio signal from the audio data stored in the buffer 311. (7) Memory card interface 306 The memory card interface 306 is an interface for connecting the mobile terminal 300 and the memory card 400. Under the control of the CPU 301, the data is output to the memory card 400, and when the data is received from the memory card 400, the data is output to the CPU 301. To do. (8) Wireless control unit 314, wireless unit 315, antenna 316 The antenna 316, the radio unit 315, and the radio control unit 314 transmit and receive voice or information to and from the connected device of the other party via the radio base station and the mobile phone network.
Here, the radio control unit 314 notifies the interrupt controller 304 of an interrupt when receiving mail via the antenna 316 and the radio unit 315 and when there is an incoming call. (9) Microphone 312, converter 313 The conversion unit 313 converts the voice received from the microphone 312 into an electric signal and outputs it to the wireless control unit 314. 2. Operation of secure processing system 2.1 Operation of Certificate Authority Device 100 When the compiler 101 receives the input of the calling program source code and the protection program source code, it compiles and generates the calling program binary data and the protection program binary data, and outputs the generated binary data to the data embedding unit 105. In addition, the input of the decryption program source code and the secure program source code is received, compiled to generate binary data of each program, and the generated binary data is output to the program encryption unit 102.
When the program encryption unit 102 receives the binary data of the decryption program and the secure program and receives the program key, the program encryption unit 102 encrypts the secure program using the program key and generates an encryption program. The decryption program and the generated encryption program are output to the data embedding unit 105 and the hash value calculation unit 104 as a TRS area program.
When the hash value calculation unit 104 receives the TRS area program and receives the private key, it applies a hash function to calculate the hash value for the TRS area program. It also derives the size of the TRS area program binary data. The hash value calculation unit 104 outputs the hash value and the binary size to the data embedding unit 105. When the key encryption unit 103 receives the input of the program key and the master key, the key encryption unit 103 encrypts the program key using the master key and generates an encryption key. The generated encryption key is output to the data embedding unit 105.
When the data embedding unit 105 receives the calling program binary data and receives the hash value, the binary size, and the encryption key, the data embedding unit 105 embeds the hash value as a tampering detection value in the calling program, and further embeds the binary size and the encryption key in the calling program binary. Embed in data. When the protection program binary data is received from the compiler and the TRS area program is received from the program encryption unit 102, the protection program including the calling program and the TRS area program are combined to generate a second secure processing program and store it. Write to 106.
The transmission unit 107 reads the second secure processing program from the storage unit 106 and outputs the second secure processing program to the ROM writer 200. 2.2 Operation of music data playback processing on mobile terminal 300 (1) The operation when the mobile terminal 300 reproduces the music data recorded on the memory card 400 will be described with reference to FIGS. 13 to 17.
When the user operates the input unit 307 of the mobile terminal 300 to receive an input to play the music data recorded in the memory card 400, the application 505 activates the second secure processing program 502 (step S701). .. The second secure processing program 502 allocates a virtual memory space for dynamically allocating memory while executing the TRS area program by executing the area allocation program 511 (step S702). In addition, the interrupt prohibition program 512 is executed to disable interrupts, and the analysis action of the program using interrupts is invalidated (step S703). After that, the interrupt is masked until the interrupt prohibition is released. Next, the calling program 513 is executed, the tampering detection data is transmitted, and the first secure processing program 501 is called (step S704).
The first secure processing program 501 receives the tampering detection value, the TRS area start address, the binary size, and the encryption key as tampering detection data from the second secure processing program 502 (step S705). In addition, the circuit disconnection program 551 is executed to output a debugger control signal indicating "invalid" to the debugger invalidation circuit 303 (step S706). As a result, the debugger invalidation circuit 303 disconnects the switch and invalidates the analysis by the debugger.
In addition, the tampering detection program 552 is executed as follows. The tampering detection program 552 reads the data in the range indicated by the binary size from the position indicated by the TRS area start address received in step S705 as the target data for hash value calculation. In addition, the hash value for the retrieved target data is calculated using the private key (step S709).
The calculated hash value is compared with the tampering detection value received in step S708, and it is determined whether or not they match (step S710). If they do not match (NO in step S710), it is assumed that they have been tampered with, and subsequent processing is suppressed. Further, the circuit connection program 557 is executed to output a debugger control signal indicating "valid" to the debugger invalidation circuit 303 (step S737), and the process is terminated.
If the hash value calculated in step S709 matches the tampering detection value (step S710 YES), it is assumed that the hash value has not been tampered with, and the subsequent processing is continued. The first secure processing program 501 executes the key decryption program 553. The key decryption program 553 uses the master key 563 to decrypt the encryption key received in step S708 and generate a program key (step S711). Send the generated program key to the key transmission program 554. The key transmission program 554 transmits the received program key to the second secure processing program 502 (step S712).
The second secure processing program 502 receives the program key by executing the key receiving program 514 (step S713). Also, set the execution flag to "ON" (step S714). Next, the decryption program 516 is executed. The decryption program 516 decrypts the encryption program 517 using the received program key, and generates a secure program (step S715). When a secure program is generated, the program key used for decryption is erased (step S716).
The second secure processing program 502 starts executing the secure program (step S717). First, the interrupt prohibition release program 521 is executed. The interrupt prohibition release program 521 cancels the interrupt prohibition performed in step S703 (step S718). After that, when an interrupt occurs, the secure program is interrupted and interrupt processing is executed. The processing when an interrupt occurs will be described later.
Next, the area initialization program 522 is executed to secure a storage area to be encrypted in the memory space (step S719). The second secure processing program 502 executes the authentication communication program 523 and performs the processing described later to authenticate the first secure processing program 501 (step S720). Further, the first secure processing program 501 executes the authentication communication program 555 to be authenticated. The second secure processing program 502 suppresses the subsequent processing when the authentication fails. If the authentication fails, the first secure processing program 501 outputs a debugger control signal indicating "valid" to the debugger invalidation circuit 303 (step S737) and ends the processing.
If the authentication is successful, the second secure processing program 502 and the first secure processing program 501 share the session key. After that, when communicating between the second secure processing program 502 and the first secure processing program 501, encrypted communication is performed using the shared session key. The second secure processing program 502 transfers control to the music playback program when the authentication is successful.
The music playback program 504 reads the encrypted music data 411 from the memory card 400 (step S721). Further, the music playback program 504 requests the second secure processing program 502 to decrypt the encrypted music data 411 (step S722). The second secure processing program 502 executes the area encryption program 526 when the decryption of the encrypted music data 411 is requested. The area encryption program 526 encrypts the data in the storage area secured in step S719 by using the area key 525 (step S723). When the storage area is encrypted, the second secure processing program 502 requests the first secure processing program 501 to acquire the title key (step S724).
The first secure processing program 501 executes the data reading program 556. The data reading program 556 performs mutual authentication with the authentication unit 403 of the memory card 400 (step S725), and if the authentication is successful (YES in step S726), accesses the information storage unit 404 of the memory card 400 to access the title key. To get. If the authentication fails, the title key cannot be acquired, and the first secure processing program 501 outputs a debugger control signal indicating "valid" to the debugger invalidation circuit 303 (step S737) to end the processing. ..
When the first secure processing program 501 succeeds in mutual authentication with the memory card 400 and obtains the title key (step S727), the title key is encrypted using the session key shared in step S720, and the encrypted title key is obtained. Generate (step S728). The generated encrypted title key is transmitted to the second secure processing program 502. The second secure processing program 502 executes the area decoding program 527. The area decryption program 527 decrypts the encrypted storage area using the area key 525 and returns it to the original state (step S729). Further, the authentication communication program 523 decrypts the encrypted title key received from the first secure processing program 501 by using the session key to obtain the title key (step S730). Next, the second secure processing program 502 executes the encrypted music data decryption program 524. The encrypted music data decryption program 524 decrypts the encrypted music data 411 read from the memory card 400 by the music playback program using the title key (step S731), and generates music data. The generated music data is transmitted to the music playback program.
The music playback program plays the received music data (step S732). When the reproduction of the music data is completed (step S733), control is transferred to the second secure processing program 502, and the second secure processing program 502 executes the area termination processing program 528. The area termination processing program 528 releases the storage area secured in step S719 (step S734) and calls the termination function of the first secure processing program 501 (step S735). Also, set the execution flag to "OFF" (step S736).
The first secure processing program 501 executes the circuit connection program 557, outputs a debugger control signal indicating valid to the debugger invalidation circuit 303 (step S737), and ends the processing. (2) Authentication The process when the second secure processing program 502 authenticates the first secure processing program 501 in step S720 described above will be described with reference to FIG.
The second secure processing program 502 generates a random number R0 and transmits it to the first secure processing program 501 (step S751). The first secure processing program 501 receives the random number R0, encrypts the received random number R0 using the authentication key 565, and generates the authentication value R1 (step S752). The generated authentication value R1 is transmitted to the second secure processing program 502 (step S753).
The second secure processing program 502 receives the authentication value R1 from the first secure processing program 501. In addition, the random number R0 generated by using the authentication key 531 is encrypted to generate the authentication value R2 (step S754). The second secure processing program 502 compares the received authentication value R1 with the generated authentication value R2 (step S755), and if they do not match (NO in step S755), "different" to the first secure processing program 501. The judgment result shown is transmitted and the process is terminated. If the comparison results in step S755 match (YES in step S755), the determination result indicating "same" is transmitted to the first secure processing program 501. In addition, a session key is generated from the generated random number R0 and the authentication key 531 using a one-way function (step S759).
When the received determination result indicates "different" (different in step S758), the first secure processing program 501 ends the processing. If the received judgment result indicates "same" (same in step S758), a session key is generated from the random number R0 and the authentication key 565 using a one-way function (step S760). In this way, the second secure processing program 502 authenticates the first secure processing program 501, and if the authentication is successful, the session key is shared. After that, when data is transmitted / received between the second secure processing program 502 and the first secure processing program 501, the session key is used for encrypted communication. (3) Interrupt The operation of the CPU 301 when an interrupt occurs will be described with reference to FIG. Here, the case where an e-mail is received will be described as an example.
When the CPU 301 receives the interrupt signal from the interrupt controller 304 (step S771), the CPU 301 reads the vector table (step S772). Also, the interrupt handler is executed according to the vector table (step S773). First, the execution flag is read (step S774), and it is determined whether it is "ON" or "OFF" (step S775). When "ON" (ON in step S775), the data in the storage area is encrypted using the area key 525 (step S776). In addition, the context is saved (step S777) and the mail reception process is performed (step S778). If the execution flag is "OFF" (OFF in step S775), the processing of steps S777 and 778 is performed without encrypting the storage area.
When the mail reception process is completed, if the execution flag is "ON" (ON in step S779), the data in the storage area is decrypted (step S780), and the process returns to the original process. If the execution flag is "OFF" (OFF in step S779), the process returns to the original process without performing the decryption process. 3. Other variants Although the present invention has been described based on the above-described embodiment, it goes without saying that the present invention is not limited to the above-described embodiment. The following cases are also included in the present invention. (1) In the present embodiment, the case of protecting the encrypted music data decryption program executed by the mobile terminal has been described as an example, but it goes without saying that the present invention is not limited to this.
The device that executes the program to be protected may be a DVD player, a DVD recorder, a PC, a PDA, or the like. Further, the program to be protected may be a decoding program used when executing video contents or games on a mobile terminal, or may be a recording program used when recording contents with a DVD recorder. Any program that is good and wants to prevent unauthorized analysis and tampering will do. (2) In the present embodiment, the hash value is used as the tampering detection value, but the tampering detection value may be a value uniquely determined for the TRS area program and is a digital signature for the TRS area program. Alternatively, the encrypted data generated by encrypting the TRS area program may be used as the tampering detection value. Further, the hash value may be calculated by using another algorithm.
Further, although the tampering detection value is generated for the TRS area program, it may be generated for at least a part of the TRS area program, and it may be generated for at least a part of the second secure processing program. It may be generated. In addition, matching for a part or all of the second secure processing program or TRS area program, detection of tampering by embedding pseudo-random numbers, etc. may be performed, and it is detected whether or not the program to be executed is the same as when it was generated. If possible, other tampering detection methods may be used.
Further, in the present embodiment, the tampering detection is performed after the debugger invalidation circuit is disconnected, but the tampering is detected before the debugger invalidation circuit is disconnected, and when the tampering is not detected, the debugger invalidation circuit is used. It may be disconnected and the subsequent processing may be performed. (3) The tampering detection data is transmitted by the calling program of the second secure processing program to the first secure processing program 501, but it may be transmitted by a program different from the second secure processing program. In this case, the calling program only calls the first secure processing program 501, and the transmission program that performs the transmission processing of the tampering detection data is stored in the memory 305, and the first secure processing program 501 is the second secure processing. When called by a program and started, it requests the sending program to send tampering detection data. The transmission program transmits tampering detection data upon request.
In this case, the certificate authority device 100 does not include the transmission program in the protection program, but generates it as a program separate from the second secure processing program. Further, the first secure processing program 501 may hold the tampering detection data of the second secure processing program in advance. (4) In the present embodiment, the second secure processing program performs one-way authentication for authenticating the first secure processing program 501, but bidirectional authentication may be performed. In addition, although challenge-response type authentication is performed, the present invention is not limited to this, and other authentication methods may be used as long as the legitimacy of the communication partner can be authenticated.
Further, the authentication values R1 and R2 are generated by encrypting the random number R0 using the authentication key, but the random number R0 may be generated by applying a one-way function. Further, although the session key is generated from the random number R0 and the authentication key by using the one-way function, it may be generated by using the encryption method. (5) The area encryption program 526 is supposed to encrypt the storage area when calling the first secure processing program 501 from the second secure processing program, but when calling an external function from the second secure processing program, etc. 2 When control is transferred to a program other than the secure processing program, the storage area is encrypted to protect the data in the storage area.
Further, the area decoding program 527 decodes the data in the storage area and returns it to the original data when the control is returned from another program to the second secure processing program. (6) The master key may be unique to each device that executes the program to be protected. In this case, even if the master key is stolen by an unauthorized user, other devices are encrypted using another key except for the device from which the key was stolen, so even if an unauthorized master key is used, the other devices will not be able to use it. It does not work properly. Therefore, it is possible to reduce the damage caused by fraudulent acts. (7) The authentication key is configured to be held by the first secure processing program 501 and the second secure processing program, but it may be calculated based on the program key or the tampering detection value.
Further, the certificate authority device 100 may encrypt the authentication key by using the master key. In this case, the program key for decrypting the encryption program is calculated based on the authentication key. As described above, if the key used for authentication and the key used for decrypting the encryption program have a dependency relationship, any key may be encrypted. Further, the encryption layer may be deepened by using more keys, such as encrypting the encrypted key by using another key. (8) The present invention may be the method shown above. Further, it may be a computer program that realizes these methods by a computer, or it may be a digital signal composed of the computer program.
The present invention also relates to a computer-readable recording medium such as a flexible disk, a hard disk, a CD-ROM, MO, a DVD, a DVD-ROM, a DVD-RAM, or a BD (Blu-ray Disc). ), It may be recorded in a semiconductor memory or the like. Further, it may be the computer program or the digital signal recorded on these recording media.
Further, the present invention may transmit the computer program or the digital signal via a telecommunication line, a wireless or wired communication line, a network typified by the Internet, or the like. Further, the present invention is a computer system including a microprocessor and a memory, in which the memory stores the computer program, and the microprocessor may operate according to the computer program.
Further, it is carried out by another independent computer system by recording and transferring the program or the digital signal on the recording medium, or by transferring the program or the digital signal via the network or the like. May be. (9) The above-described embodiment and the above-mentioned modification may be combined.
The present invention can be used business-wise, iteratively, and continuously in the software industry in which copyrighted works such as movies and music provide software such as digitized contents and computer programs. Further, the program execution device of the present invention can be produced and sold in a manufacturing industry such as an electric appliance.
<figref num="1">It is a figure which shows the whole structure of the secure processing system 1.</figref><figref num="2">It is a block diagram which shows the structure of the certificate authority apparatus 100.</figref><figref num="3">It is a flowchart which shows the processing content of a compiler.</figref><figref num="4">It is a block diagram which shows the structure of the memory card 400.</figref><figref num="5">It is a block diagram which shows the structure of a mobile terminal 300.</figref><figref num="6">It is a figure which shows the program recorded in the memory 305.</figref><figref num="7">It is a figure which shows the data structure of the 2nd secure processing program.</figref><figref num="8">It is a figure which shows the data structure of a calling program.</figref><figref num="9">It is a flowchart which shows the processing content of an interrupt handler.</figref><figref num="10">It is a figure which shows the data structure of the 1st secure processing program 501.</figref><figref num="11">It is a figure which shows the structure of a vector table.</figref><figref num="12">It is a figure which shows the operation of CPU301.</figref><figref num="13">It is a flowchart which shows music data reproduction processing. Continued in Figure 14.</figref><figref num="14">It is a flowchart which shows music data reproduction processing. Continued in Figure 15.</figref><figref num="15">It is a flowchart which shows music data reproduction processing. Continued in Figure 16.</figref><figref num="16">It is a flowchart which shows music data reproduction processing. Continued in Figure 17.</figref><figref num="17">It is a flowchart which shows music data reproduction processing.</figref><figref num="18">It is a flowchart which shows the authentication process.</figref><figref num="19">It is a flowchart which shows the operation of CPU 301 when an interrupt occurs.</figref>
1 Secure processing system 100 Certificate Authority Equipment 101 compiler 102 Program Encryption Department 103 Key cryptosystem 104 Hash value calculation unit 105 Data embedding part 200 ROM writer 300 mobile terminals 303 Debugger invalidation circuit 304 Interrupt controller 305 memory 306 Memory card interface 317 bus 318 Interrupt line 400 memory card 421 Title key 501 Secure Processing Program 502 Secure processing program
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP07244584A | Cites | Japan |
| JP09231068A | Cites | Japan |
| JP2002244757A | Cites | Japan |
| JP2002279376A | Cites | Japan |
| JP2003157202A | Cites | Japan |
44 members in 6 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 2003301554 | Japan | A | |
| 2003301554 | Japan | A | |
| 2003301554 | Japan | – | |
| 2009025043 | Japan | A | |
| 20032003301554 | – | – | – |
| JP20030301554 | – | – | – |
| JP20090025043 | – | – | – |
Members44
| Document | Office | Kind | |
|---|---|---|---|
| WO2005020043A2 | World Intellectual Property Organization (WIPO) | A2 | |
| JP2005100378A | Japan | A | |
| WO2005020043A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1680724A2 | European Patent Office (EPO) | A2 | |
| KR20060119876A | Republic of Korea | A | |
| CN1871568A | China | A | |
| US2006294369A1 | United States of America | A1 | |
| US7533276B2 | United States of America | B2 | |
| US2009150685A1 | United States of America | A1 | |
| JP2009151805A | Japan | A | |
| CN1871568B | China | B | |
| CN101853352A | China | A | |
| JP4691337B2 | Japan | B2 | |
| KR101059257B1 | Republic of Korea | B1 | |
| JP2011253558A | Japan | A | |
| JP4892018B2This record | Japan | B2 | |
| US8181040B2 | United States of America | B2 | |
| US2012198243A1 | United States of America | A1 | |
| CN101853352B | China | B | |
| US8522053B2 | United States of America | B2 | |
| JP5291159B2 | Japan | B2 | |
| US2013312064A1 | United States of America | A1 | |
| US8874938B2 | United States of America | B2 | |
| US2014380503A1 | United States of America | A1 | |
| US9218485B2 | United States of America | B2 | |
| US2016070938A1 | United States of America | A1 | |
| EP3043232A1 | European Patent Office (EPO) | A1 | |
| US9524404B2 | United States of America | B2 | |
| US2017061165A1 | United States of America | A1 | |
| US9811691B2 | United States of America | B2 | |
| US2018025184A1 | United States of America | A1 | |
| US2018247089A1 | United States of America | A1 | |
| US10108821B2 | United States of America | B2 | |
| EP1680724B1 | European Patent Office (EPO) | B1 | |
| US10318768B2 | United States of America | B2 | |
| US2019251300A1 | United States of America | A1 | |
| US10607036B2 | United States of America | B2 | |
| US2020167509A1 | United States of America | A1 | |
| EP3798874A1 | European Patent Office (EPO) | A1 | |
| US10970424B2 | United States of America | B2 | |
| US2021192095A1 | United States of America | A1 | |
| US11651113B2 | United States of America | B2 | |
| US2023306145A1 | United States of America | A1 | |
| US12019789B2 | United States of America | B2 |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 4892018
- Publication, DOCDB
- 4892018
- Publication, EPODOC
- JP4892018B
- Application
- 25043
- Application, DOCDB
- 2009025043
- Application, EPODOC
- JP20090025043
Titles2
- Japanese
- 情報処理装置、セキュア処理方法、コンピュータプログラム及び記録媒体。
- English
- Information processing equipment, secure processing methods, computer programs and recording media.
Classification
- CPC, 15
- G06F21/14
- G06F21/00
- G06F21/87
- G06F2221/2153
- G06F21/52
- G06F21/10
- G06F1/00
- H04L63/105
- G06F21/53
- G06F21/57
- G06F12/1408
- G06F2212/1052
- H04L9/3234
- H04L9/3247
- G06F21/74
- IPC, 8
- G06F21 22
- G06F21 24
- G06F21 06
- G06F21 12
- G06F21 62
- G06F21 64
- G06F21 75
- G06F21 86