Storage device including a non-volatile memory
Abstract
According to the present invention, a tamper-resistant module and a flash memory are mounted in a recording device, so that the CPU 128 in the tamper-resistant module 121 determines the confidentiality of data received from the outside according to a command, and the confidentiality is high. Small-capacity data is stored in the internal memory of the tamper-resistant module, large-capacity data with high secrecy is encrypted and written to flash memory (0), and data with low secrecy is written to flash memory as it is. level) and can store a large amount of data. Nonvolatile memory, security level, recording device, decision result, host terminal device
Term
Term ended
Expired 6 February 2022, 4.6 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
26 claims: 10 independent, 16 dependent
- 1제1 불휘발성 메모리를 갖는 컨트롤러와, 상기 제1 불휘발성 메모리보다도 기억 용량이 큰 제2 불휘발성 메모리를 구비하고, 상기 컨트롤러는, 호스트 단말 장치와 접속되기 위한 제1 인터페이스와, 상기 제2 불휘발성 메모리와 접속되기 위한 제2 인터페이스와, 중앙 처리 장치를 더 갖고, 상기 컨트롤러의 제1 불휘발성 메모리는, 상기 중앙 처리 장치가 실행하는 프로그램으로서 상기 제1 불휘발성 메모리에 저장해야 할 프로그램을 암호화 또는 복호화하기 위한 제1 비밀 데이터를 상기 중앙 처리 장치가 저장하기 위한 저장 영역을 구비하고, 상기 제2 불휘발성 메모리는, 사용자에 의한 액세스가 허가되고, 또한 상기 호스트 단말 장치로부터의 데이터를 상기 컨트롤러가 저장하기 위한 제1 영역과, 상기 사용자에 의한 액세스가 제한되고 또한 상기 제1 비밀 데이터를 이용하여 상기 컨트롤러에 의해 암호화된 프로그램을 저장하기 위한 제2 영역을 갖는 기록 장치.
- 2제1항에 있어서, 상기 제1 비밀 데이터는 키 정보와 증명서 중 적어도 하나를 포함하는 기록 장치.
- 3제1항에 있어서, 상기 컨트롤러는, 상기 호스트 단말 장치로부터의 커맨드 또는 데이터의 속성에 따라, 상기 제1 불휘발성 메모리에 액세스할지 또는 상기 제2 불휘발성 메모리에 액세스할지를 결정하는 기록 장치.
- 4제1항에 있어서, 상기 컨트롤러는, 상기 제1 불휘발성 메모리의 빈 용량에 따라, 상기 제1 불휘발성 메모리에 액세스할지 또는 상기 제2 불휘발성 메모리에 액세스할지를 결정하는 기록 장치.
- 5제1항에 있어서, 상기 컨트롤러는, 상기 호스트 단말 장치로부터의 커맨드 또는 데이터의 속성에 따라, 상기 호스트 단말 장치로부터 수신되고 또한 상기 제2 불휘발성 메모리에 기입하기 위한 일반 데이터를 암호화할지의 여부를 결정하는 기록 장치.
- 6제5항에 있어서, 상기 제1 불휘발성 메모리는, 상기 일반 데이터를 암호화 또는 복호화하기 위한 제2 비밀 데이터를 저장하기 위한 저장 영역을 더 구비하는 기록 장치.
- 7제1항에 있어서, 상기 컨트롤러는, 상기 제1 불휘발성 메모리의 빈 용량에 따라, 상기 호스트 단말 장치로부터 수신되고 또한 상기 제2 불휘발성 메모리에 기입하기 위한 일반 데이터를 암호화할지의 여부를 결정하는 기록 장치.
- 8제7항에 있어서, 상기 제1 불휘발성 메모리는, 상기 일반 데이터를 암호화 또는 복호화하기 위한 제2 비밀 데이터를 저장하기 위한 저장 영역을 더 구비하는 기록 장치.
- 9제1항에 있어서, 상기 제1 불휘발성 메모리는, 상기 호스트 단말 장치와 네트워크를 통해 접속되는 서버와 상기 호스트 단말 장치가 암호 통신을 행하기 위한 제2 비밀 데이터를 저장하기 위한 저장 영역과, 상기 서버와 상기 기록 장치가 암호 통신을 행하기 위한 제3 비밀 데이터를 저장하기 위한 저장 영역 중 적어도 하나를 더 구비하는 기록 장치.
- 10제9항에 있어서, 상기 컨트롤러는, 상기 제1 비밀 데이터를 이용하여, 상기 제2 비밀 데이터에 대응하는 암호화 프로그램과 상기 제3 비밀 데이터에 대응하는 암호화 프로그램 중 적어도 하나를 암호화하고, 상기 제2 불휘발성 메모리의 상기 제2 영역에 기입하는 기록 장치.
- 11제1항에 있어서, 상기 컨트롤러는, 상기 호스트 단말 장치로부터의 데이터의 시큐리티 레벨에 따라 상기 제1 불휘발성 메모리에 액세스할지 또는 상기 제2 불휘발성 메모리에 액세스할지를 결정하는 기록 장치.
- 12제1항에 있어서, 상기 컨트롤러는, 상기 호스트 단말 장치로부터의 데이터의 시큐리티 레벨에 따라 상기 호스트 단말 장치로부터 수신되고 또한 상기 제2 불휘발성 메모리에 기입하기 위한 일반 데이터를 암호화할지의 여부를 결정하는 기록 장치.
- 13제12항에 있어서, 상기 제1 불휘발성 메모리는, 상기 일반 데이터를 암호화 또는 복호화하기 위한 제2 데이터를 저장하기 위한 저장 영역을 더 구비하는 기록 장치.
- 14제1항에 있어서, 상기 컨트롤러는 IC 칩이고, 상기 제2 불휘발성 메모리는 플래시 메모리 칩인 기록 장치.
- 15제1 불휘발성 메모리를 갖는 컨트롤러와 상기 제1 불휘발성 메모리보다도 기억 용량이 큰 제2 불휘발성 메모리를 구비하고 또한 착탈 가능한 기록 장치와, 상기 기억 장치와 접속되기 위한 제1 인터페이스와, 제1 중앙 처리 장치를 구비한 호스트 단말 장치에 있어서, 상기 컨트롤러는, 상기 제1 인터페이스와 접속되기 위한 제2 인터페이스와, 상기 제2 불휘발성 메모리와 접속되기 위한 제3 인터페이스와, 제2 중앙 처리 장치를 더 구비하고, 상기 컨트롤러의 제1 불휘발성 메모리는 상기 중앙 처리 장치가 실행하는 프로그램을 암호화하기 위한 제1 비밀 데이터를 상기 중앙 처리 장치가 저장하기 위한 저장 영역을 구비하고, 상기 제2 불휘발성 메모리는, 사용자에 의한 액세스가 허가되고 또한 상기 호스트 단말 장치로부터의 데이터를 상기 컨트롤러가 저장하기 위한 제1 영역과, 상기 사용자에 의한 액세스가 제한되고 또한 상기 제1 비밀 데이터를 이용하여 상기 컨트롤러에 의해 암호화된 프로그램을 저장하기 위한 제2 영역을 구비하는 호스트 단말 장치.
- 16제15항에 있어서, 상기 컨트롤러의 상기 제1 불휘발성 메모리는, 또한 상기 호스트 단말 장치와 네트워크를 통해 접속되는 서버와 상기 호스트 단말 장치가 암호 통신을 행하기 위한 제2 비밀 데이터를 저장하고, 상기 제1 중앙 처리 장치는, 상기 컨트롤러의 상기 제1 불휘발성 메모리로부터 상기 제2 비밀 데이터를 판독하고, 상기 서버로 복호 가능한 암호 키를 이용하여 상기 제2 비밀 데이터를 암호화하고, 암호화된 상기 제2 비밀 데이터를 상기 서버에 송신하고, 상기 제2 비밀 데이터를 이용하여 암호화된 데이터를 상기 서버로부터 수신하는 호스트 단말 장치.
- 17제15항에 있어서, 상기 컨트롤러의 상기 제1 불휘발성 메모리는, 또한 상기 호스트 단말 장치와 네트워크를 통해 접속되는 서버와 상기 기록 장치가 암호 통신을 행하기 위한 제2 비밀 데이터를 저장하고, 상기 제2 중앙 처리 장치는, 상기 컨트롤러의 상기 제1 불휘발성 메모리로부터 상기 제2 비밀 데이터를 판독하고, 상기 서버에서 복호 가능한 암호 키를 이용하여 상기 제2 비밀 데이터를 암호화하고, 암호화된 상기 제2 비밀 데이터를 상기 서버에 송신하고, 상기 제2 비밀 데이터를 이용하여 암호화된 데이터를 상기 서버로부터 수신하는 호스트 단말 장치.
- 18제1 불휘발성 메모리를 갖는 컨트롤러와, 상기 제1 불휘발성 메모리보다도 기억 용량이 큰 제2 불휘발성 메모리를 구비한 기록 장치에 있어서, 상기 컨트롤러는, 중앙 처리 장치와, 상기 중앙 처리 장치에 의해 이용되는 휘발성 메모리를 포함하고, 상기 컨트롤러의 상기 제1 불휘발성 메모리는 키 데이터를 저장하고, 상기 컨트롤러는, 상기 중앙 처리 장치에 의해 실행되는 프로그램으로서 상기 제1 불휘발성 메모리에 저장해야 할 프로그램을 상기 키 데이터에 의해 암호화하고, 암호화된 상기 프로그램을 상기 제1 불휘발성 메모리가 아닌 상기 제2 불의 휘발성 메모리에 저장하고, 상기 컨트롤러는, 상기 제2 불휘발성 메모리로부터 상기 프로그램을 판독하고, 상기 키 데이터를 이용하여 상기 프로그램을 복호화하고, 상기 중앙 처리 장치는, 복호화된 상기 프로그램을 실행하는 기록 장치.
- 19제18항에 있어서, 상기 컨트롤러는, 상기 컨트롤러의 상기 제1 불휘발성 메모리의 빈 용량이 적은지 큰지를 판정하고, 상기 컨트롤러의 상기 제1 불휘발성 메모리의 빈 용량이 적은 경우에 상기 프로그램을 상기 키 데이터에 의해 암호화하고, 암호화된 상기 프로그램을 상기 제1 불휘발성 메모리가 아닌 상기 제2 불휘발성 메모리에 저장하고, 상기 컨트롤러의 상기 제1 불휘발성 메모리의 빈 용량이 큰 경우에 상기 프로그램을 암호화하지 않고 상기 제1 불휘발성 메모리에 저장하는 기록 장치.
- 20삭제
- 21삭제
- 22삭제
- 23삭제
- 24삭제
- 25삭제
- 26삭제
Independent claims26
43 paragraphs in 2 sections, as filed
A recording device having a non-volatile memory {STORAGE DEVICE INCLUDING A NON-VOLATILE MEMORY}
1 is a block diagram showing an embodiment of a storage device to which the present invention is applied;
Fig. 2 is a diagram showing the configuration of a system using a recording apparatus to which the present invention is applied.
Fig. 3 is a configuration diagram of a portable terminal to which a recording device to which the present invention is applied is connected;
Fig. 4 is a block diagram of a decoder circuit mounted on a portable terminal;
Fig. 5 is a diagram showing a command system between a recording apparatus and a portable terminal and a server;
Fig. 6 is a flowchart of encryption communication path establishment processing;
Fig. 7 is a flowchart showing a processing procedure in which a recording device connected to a portable terminal acquires content and a license from a server;
8 is a diagram showing the configuration of software of each device to which the present invention is applied.
Fig. 9 is a diagram showing establishment of an encrypted communication path in the present invention;
Fig. 10 is a diagram showing movement of a license in the present invention;
Fig. 11 is a diagram showing movement of content in the present invention;
Fig. 12 is a flowchart showing a processing procedure at the time of downloading in the present invention;
Fig. 13 is a flowchart showing the exchange of commands at the time of license acquisition in the present invention;
Fig. 14 is a flowchart showing the exchange of commands at the time of content acquisition in the present invention;
Fig. 15 is a diagram showing the configuration of an apparatus at the time of content reproduction according to the present invention;
Fig. 16 is a flowchart showing processing at the time of reproduction in the present invention;
Fig. 17 is a flowchart showing the exchange of a license acquisition command in the decoder circuit;
Fig. 18 is a flowchart showing the exchange of commands for acquiring content in the decoder circuit;
Fig. 19 is a diagram showing the configuration of an access command in the present invention;
Fig. 20 is a flowchart showing the flow of command interpretation by the recording apparatus;
Fig. 21 is a flowchart showing the procedure of data sorting processing of the recording apparatus;
Fig. 22 is a diagram showing a notation rule used in the present invention;
<Explanation of symbols for main parts of the drawing>
100 : service provider
103 : mobile terminal
108 : public line
110 : access command
120 : recording device
121 : Tamper resistant module
122 : host interface
123 : inner pass
124 : Flash memory interface
126 : Cryptographic processing circuit
127 : Application RAM
129 : RAM
130 : ROM
140 : Flash memory
204 : Mobile terminal control circuit
206 : decoder circuit
207 : Recording device interface
306 : Non-volatile memory
<backgroundart><p>BACKGROUND OF THE INVENTION 1. Field of the Invention [0001] The present invention relates to a storage device and an information device connected to the storage device, and more particularly, to a method of controlling data transfer between the information device and the recording device. </p><p>In recent years, with the development of a network society such as the Internet, the importance of technology for protecting the copyright of music or image contents distributed on the network is increasing. As a copyright protection technology, a secret key storage circuit for storing a secret key used for encryption/decryption and a data storage circuit for storing data are mounted, and a write control circuit is used to write the secret key into the secret key storage circuit. A memory IC card having a function and a function of authenticating an external device has been proposed. This technique is disclosed in, for example, Japanese Patent Laid-Open No. 2000-163547.</p></backgroundart><abstractproblem><p>In Japanese Patent Laid-Open No. 2000-163547, all data is recorded on a recording medium on a packaged storage device such as a memory IC card. A packaged storage device such as a memory IC card has a structure (tamper resistant module) in which it is difficult to interpret internal data from the outside of the card in order to prevent theft of contents or the like. In general, a packaged storage device such as a memory IC card having a tamper resistant module is expensive, and the storage capacity of the memory is small. Therefore, it is very difficult to store a large amount of data with high secrecy in a packaged storage device such as a memory IC card.</p><p>In addition, in Japanese Unexamined Patent Publication No. 2000-163547, in a packaged storage device such as a memory IC card, data with high confidentiality and low data was stored in the tamper-resistant module as it is in accordance with a transmission instruction from a higher-level device without judgment by the recording device. . For this reason, all data that does not need to be hidden is stored in the tamper-resistant module, and the storage area in the tamper-resistant module cannot be effectively utilized.</p><p>Further, in Japanese Patent Laid-Open No. 2000-163547, a nonvolatile memory (hereinafter referred to as NV memory) such as an EEPROM is used as a storage area for data storage. However, the NV memory used in the prior art has few rewritable times, and it is difficult to replace many contents many times.</p><p>Further, in Japanese Patent Laid-Open No. 2000-163547, as described above, since the storage capacity of a packaged storage device such as a memory IC card is small, even when an application is executed on the memory IC card, only applications with a small storage capacity used by the program are used. Couldn't run </p><p>On the other hand, Japanese Patent Laid-Open No. 10-334205 discloses a card incorporating an IC chip and a flash memory. However, since the IC chip and the flash memory are independent, the IC chip cannot write data to or read data from the flash memory.</p><p>SUMMARY OF THE INVENTION An object of the present invention is to provide a storage device and a host terminal device capable of storing highly confidential data at low cost and in a large amount many times. </p><p>It is an object of the present invention to provide a storage device and a host terminal device that can effectively use a recording area in a controller. </p><p>It is an object of the present invention to provide a storage device and a host terminal device in which various applications are recorded and capable of executing large-scale applications. </p></abstractproblem>
<p>According to the present invention, secret data is recorded in the nonvolatile memory in the controller, and information that cannot be written in the nonvolatile memory in the controller is encrypted with the secret key and then written in the nonvolatile memory outside the controller. </p><p>According to the present invention, the controller determines the confidentiality (security level, etc.) of information transmitted from the outside, records high confidentiality information in the nonvolatile memory in the controller, and writes low confidentiality information in the flash memory. Classify the data. </p><p>According to the present invention, a work memory (for example, RAM) for executing an application in a controller is mounted, the application is encrypted with a secret key in the controller, and stored in an access-restricted area of a nonvolatile memory external to the controller, and if necessary Accordingly, the application is read from the nonvolatile memory external to the controller, decoded, and then deployed to the work memory and executed. </p><p>According to the present invention, it is possible to store a large amount of data while ensuring confidentiality (security level) according to the data. </p><p>1 is a block diagram of a recording apparatus 120 to which the present invention is applied. </p><p>The recording device 120 has a tamper resistant module 121 and a flash memory 140 . The tamper resistant module 121 is an electronic circuit configured to make it difficult to perform a physical analysis from the outside, and is used in electronic devices requiring high security, such as an IC card. That is, the tamper resistance of the tamper resistant module 121 is higher than that of the flash memory 140 . The inner path 123 is used to transmit and receive information between each circuit. The flash memory interface 124 is used to connect the flash memory 140 and the tamper resistant module 121 .</p><p>The host interface 122 is used to transmit/receive an access command 110 between the recording apparatus 120 and an external device connected to the recording apparatus 120 . The CPU 128 controls each circuit in the recording device 120 . The encryption processing circuit 126 is used by the CPU 128 to perform encryption processing in the recording apparatus 120 . The RAM 129 is a work RAM (work memory) used for temporarily recording data. In the ROM 130, programs and data permanently used by the CPU 128 are recorded. The NV memory 125 is a nonvolatile memory with a small capacity and a small number of writes. In the NV memory 125, dangerous information is recorded when interpreted from the outside. The NV memory 125 includes, for example, an EEPROM (electrically rewritable ROM).</p><p>The NV memory 125 stores the following information and programs. </p><p>The secret information KM 151 includes key information and the like used by the tamper resistant module 121 to encrypt and decrypt data when writing and reading data to and from the flash memory 140 . The KM-compatible encryption processing program 152 is an application that performs encryption processing using the secret information KM 151 .</p><p>In the secret information KO 153 , the server 180 of the service provider 100 and the portable terminal 103 are used to establish an encrypted communication path on a public line 108 , which will be described later, information of a key and a certificate. etc. are included. The KO-compatible encryption processing program 152 is an application that performs encryption processing using the secret information KO 153 .</p><p>In the secret information KI 155, the distribution application 181 in the server 180 of the service provider 100 and the recording device 120 are used to establish an encrypted internal communication path 109, which will be described later. This includes information on certificates, keys, and the like. The KI-compatible encryption processing program 156 is an application that performs encryption processing using the secret information KI 155 .</p><p>The secret information KL 157 includes information on certificates, keys, and the like necessary when an application executed by the CPU 128 performs cryptographic processing. The KL-compatible encryption processing program 158 is an application that performs encryption processing using the secret information KI 157 . In addition, the KL 157 may be used for a unique purpose by an application. A plurality of KL 157 may exist for each application.</p><p>The NV memory 125 has a data area 160 . In the data area 160 , personal information of a person who uses the recording device 120 , for example, a phone book, schedule, credit card information, electronic money, personal authentication information, and the like is stored.</p><p>It is also conceivable to store these important personal information (key information, etc.) in the flash memory 140, but since there is a possibility that the card may be read by maliciously destroying the card, it is difficult to read the tamper-resistant module 121 from the outside. stored in the NV memory 125 of </p><p>The application RAM 127 is used for the CPU 128 to decrypt and execute the encrypted application 144 read from the flash memory 140 when the application is executed. </p><p>The flash memory 140 is a nonvolatile memory that can be electrically erased and written, for example, a flash memory chip such as a multi-value flash memory having a large storage capacity. The flash memory 140 has a user-access-prohibited area 142 and a user-access-permitted area 141 in which the user's access is prohibited or restricted. The data stored in the user access prohibited area 142 is erased and written only by the CPU 128 in the tamper resistant module 121 . In the user access-prohibited area 142 , information that is difficult to be manipulated by the user, such as an encrypted application 144 executed by the recording device 120 , and important information 143 such as firmware of the recording device 120 , is stored. In addition, an electronic signature may be added to this data so that it cannot be forged from the outside. The user access permission area 141 is an area that can be freely accessed from an external device connected to the storage device 120 , and content 402 , an encrypted program, and other data having no problem even when viewed externally are stored. Firmware refers to hardware-ized software (program). Specifically, it refers to BIOS or drivers.</p><p>A variety of application programs used by the CPU 128 are pre-encrypted and stored in the flash memory 140 . The encrypted application program 144 is supplied to the tamper resistant module 121 before being used. At that time, the CPU 128 uses the KM 151 and the KM-compatible encryption processing program 152 to decrypt the application program and loads it into the application RAM 127 . When the load is complete, the application program becomes executable. Meanwhile, content 402 such as voice and image is stored in the flash memory 140 . At this time, the CPU 128 automatically analyzes the data storage destination according to the access command 110 . Details of the analysis means will be described later.</p><p>2 is a block diagram of a system using the embodiment of the storage device 120 to which the present invention is applied. </p><p>The portable terminal 103 is connected to the recording device 120 and has a function of communicating with the service provider 100 using the recording device 120 . The portable terminal 103 has a display screen 104 , a speaker 105 , a microphone 106 , and a CCD camera 107 .</p><p>The service provider 100 has a server 180 that distributes content and the like to the recording device 120 . The server 180 has a distribution application 181 and content 182 to be distributed.</p><p>It is possible to establish an encrypted communication path on the public line 108 between the service provider 100 and the portable terminal 103 to prevent data leakage. Also, the recording device 120 connected to the portable terminal 103 may establish an encrypted internal communication path 109 within the encrypted communication path established with the service provider 100 as well. In the drawing, the internal communication path 109 is shown only for the portable terminal 103, but in reality, the path is also secured on the public line 108. As shown in FIG. Details will be described later.</p><p>In this system using the service provider 100, the portable terminal 103, and the recording device 120, when the service provider 100 and the recording device 120 transmit/receive data, the data is transferred to the service provider 100 . Depending on the encryption processing method used in the portable terminal 103 or the like, data is encrypted in N+M between the service provider 100 and the portable terminal 103 , and the portable terminal 103 and the recording device 120 . In some cases, it is encrypted with M weights. In addition, the device for connecting the recording apparatus 120 is not limited to the portable terminal 103, and the public line 108 may be a wired line or a wireless line. As a wired line, an optical cable etc. can be considered.</p><p>3 is a block diagram of the portable terminal 103 . </p><p>The CPU 201 controls each circuit of the portable terminal 103 . The RAM 202 temporarily stores data used by the CPU 201 . In the ROM 203, data not to be rewritten which is permanently used by the CPU 201 is recorded. The portable terminal control circuit 204 performs processing such as transmission/reception of information between the portable terminal 103 and an external device. The input/output interface 205 performs processing such as key input and screen display by a person using the portable terminal 103 . The recording device interface 207 transmits/receives information to and from the recording device 120 . The decoder circuit 206 decodes the information read from the recording device 120 into audio, video, or the like. The bus 208 is used for transmitting and receiving information between circuits.</p><p>4 is a diagram showing the configuration of the decoder circuit 206. As shown in FIG. </p><p>Since the decoder circuit 206 decodes and reproduces the data read from the recording device 120, it is necessary to make the decoded data inaccessible from the outside. For this reason, the decoder circuit 206 is a tamper resistant module. The control circuit 301 controls each circuit in the decoder circuit 206 . In the RAM 302, decoded information and the like are temporarily recorded. In the ROM 303, information that is permanently used, such as a program of a control circuit, is recorded with low confidentiality. In the nonvolatile memory 306, highly confidential information such as a certificate of the decoder circuit 206 and a key required for decrypting the encrypted data extracted from the recording device 120 is recorded. The interface 307 is an interface used for connection with an external circuit. The bus 308 is used for transmitting and receiving information between each circuit.</p><p>5 is a diagram showing an example of a communication method in a system in which the recording apparatus 120 to which the present invention is applied is used. </p><p>The transmission/reception of information between the recording device 120 and the portable terminal 103 is performed with an access command 110 . The access command 110 is defined as a layered access command (hereinafter referred to as a "layered command": 405). The physical access command 408 is a basic command such as input/output of data to and from the recording device 120 . The logical access command 409 is transmitted and received as data of the physical access command 408 . The recording apparatus 120 and the portable terminal 103 interpret the physical access command 408, extract and execute the logical access command 409 from the data area. With such a command configuration, it is possible to easily expand the commands without changing the basic commands between the portable terminal 103 and the recording device 120 .</p><p>The license 401 is information including a key for decrypting the encrypted content 402 . The encrypted content 402 is content encrypted by the license 401 . The arrow of the license delivery 404 indicates when the license 401 is delivered from the service provider 100 to the tamper resistant module 121 of the recording device 120 via the network 403 and the portable terminal 103 represents An arrow in the content delivery 407 indicates a case in which the content 402 is delivered from the service provider 100 to the recording device 120 . Between the service provider 100 and the portable terminal 103 , the license 401 and the content 402 are distributed using the layering command 406 . Between the portable terminal 103 and the recording device 120 , the license 401 is distributed using the layering command 405 and stored in the tamper resistant module 121 . The content 402 is delivered to the flash memory 140 in the recording device 120 using only a physical access command 408 between the portable terminal 103 and the recording device 120 . </p><p>19 is a diagram showing a configuration example of the physical access command 408 and the logical access command 409 . </p><p>The physical access command 408 is composed of a command code 1801 , a length 1802 , and a data area 1803 . The command code 1801 is composed of a command type 1810 , an attribute 1811 , and a security level 1812 . In the command type 1810 and the attribute 1811, information on a correspondence relationship as shown in the table of FIG. 19 is stored. The attribute 1811 is, for example, a tag indicating whether data is personal information, key information, or other general information. Hereinafter, data indicating such an attribute is referred to as attribute data. The security level 1812 stores information indicating the level of confidentiality of data transmitted by the command. The airtightness level is divided into three levels in the case of this embodiment. A security level is added to the access command 110 upon issuance by the device issuing the access command 110 according to the nature of the data being transmitted.</p><p>The length 1802 stores information indicating the length of the data area 1803 . The data area 1803 includes a logical access command 409 in addition to normal data.</p><p>A logical access command 409 consists of a command code 1804 , a length 1805 , and data 1806 . The command code 1804 is the same as the command code 1801 of the physical access command 408 . The length 1805 stores information indicating the length of data stored in the data 1806 . Data 1806 stores actual data.</p><p>The layered command 406 and the physical access command 410 and logical access command 411 constituting them also have the same configuration as the layered command 405 . The layering command 406 is used when the mobile terminal 103 and the server 180 transmit and receive information through the network 403 . Note that the specific command codes of the layering command 405 and the layering command 406 may be different.</p><p>20 is a flowchart showing the classification processing of the command received layered command performed by the recording apparatus 120. As shown in FIG. </p><p>The recording device 120 receives a physical access command 408 (1901). The CPU 128 in the recording device 120 checks the command code 1801 of the physical access command 408 (1902). If the logical access command 409 exists, the CPU 128 executes the interpretation of the logical access command (1904). The CPU 128 processes the logical access command 409 (1905). When the logical access command 409 is not included in the physical access command 408, the CPU 128 executes the physical access command processing (1903). When the processing of the command is finished, the CPU 128 performs data sorting processing, discriminating data with high confidentiality and data with low confidentiality, and writing to an area suitable for each data (1906).</p><p>21 is a flowchart showing a data sorting process 1906 that the CPU 128 executes. </p><p>The CPU 128 checks whether the command type 1810 of the physical access command 408 or the logical access command 409 received from the portable terminal 103 is a WRITE command (2002), and if it is other than the WRITE command, processing ends (2009). If the command type 1810 is a WRITE command, the CPU 128 examines the data in the data area and checks whether the attribute data exists in the attribute 1811 (2003). If the attribute data does not exist in the attribute 1811, the CPU 128 checks the security level 1812 of the command code (2004). If the security level is 1, the CPU 128 checks the empty capacity of the NV memory 125 (2005), and if the empty capacity is sufficient, stores data in the NV memory 125 (2006). If the free capacity is not sufficient, the CPU 128 encrypts the data (2007) and writes the data to the flash memory 140 (2008). If the security level is 2, the CPU 128 encrypts the data (2007) and writes the data to the flash memory 140 (2008). If the security level is 3, the CPU 128 writes data to the flash memory 140 (2008). If it is determined in step 2003 that attribute data exists in the attribute 1811, the CPU 128 determines the content of the attribute data (2010). If the attribute data determines that the data transmitted by the access command is small-capacity confidential data, the CPU 128 checks the free capacity of the NV memory 125 (2011), and if there is an empty capacity, the data is NV It is stored in the memory 125 (2012). If the free capacity is not sufficient, the CPU 128 encrypts the data (2013) and stores the data in the flash memory 140 (2014). If it is determined that the data is large-capacity confidential data, the CPU 128 encrypts the data (2013) and stores the data in the flash memory 140 (2014). If encryption is not required, the CPU 128 stores the data as it is in the flash memory 140 (2014). </p><p>6 is a flowchart showing the encrypted communication path establishment processing 510 and the encrypted internal communication path establishment processing 520 in the public line 108. As shown in FIG. These procedures are collectively referred to as encrypted communication path establishment processing 500 .</p><p>An encrypted communication path establishment process 510 in the public line 108 will be described. The portable terminal 103 extracts the secret information KO 153 from the recording device 120 (502). The portable terminal 103 encrypts the secret information KO 153 and transmits it to the service provider 100 (503). The server 180 of the service provider 100 that has received the encrypted secret information KO 153 decrypts and extracts the secret information KO 153 (504). In the subsequent communication, the server 180 and the portable terminal 103 encrypt and transmit/receive information in the secret information KO (153). Accordingly, an encrypted communication path is established (506).</p><p>The encryption internal communication path establishment process 520 will be described. The recording device 120 encrypts the secret information KI 155, and uses the encrypted communication path established between the portable terminal 103 and the service provider 100 to store the encrypted secret information KI 155. It transmits to the service provider 100 (509). The server 180 of the service provider 100 that has received the encrypted secret information KI 155 decrypts and extracts the secret information KI 155 (510). Thereafter, the server 180 and the recording device 120 encrypt and transmit information using the secret information KI 155 (511). Accordingly, an encrypted internal communication path is established (512).</p><p>7 is a diagram showing a basic flow of copyright protection between the portable terminal 103, the recording device 120, and the server 180. As shown in FIG. In this figure, a case is shown in which the content 402 for which copyright protection is desired is transmitted from the server 180 to the recording device 120 . The notation of each transmission procedure follows the notation rule 2101 shown in FIG. In addition, in FIG. 7 , KS1 is generated by the server 180 using a random number or the like. KS2 is generated by the encryption processing circuit 126 of the recording device 120 using a random number or the like.</p><p>When the user operates the portable terminal 103 and instructs the recording apparatus 120 to acquire content, the recording apparatus 120 transmits a content request 601 via the portable terminal 103 to It is issued to the server 180 . Accordingly, the recording device 120 transmits to the server 180 a Content ID corresponding to the content 402 to be acquired and a certificate C (KA, KPMC ¦IMC) proving that the recording device 120 is a legitimate device. (602). When server 180 receives the content ID and certificate, it checks the certificate. If the certificate is legitimate, the session key E (KPMC, KS1) is transmitted to the recording device 120 (603). When the recording device 120 receives the session key KS1, it transmits various pieces of information including the session key Ks2 to the server 180 as E(KS1, KPM1 KS2 CRLUPDATE) (604). Upon receiving this, the server 180 transmits various pieces of information including the license 401 as E(KS2, CRL|E(KPM1, TRANSACATIONID|ACM|KC|ACP)) to the recording device 120 (605). The server 180 then transmits the content 402 to the recording device 1210 as E(KC, CONTENT) (606). The transmission and reception of information described below uses the method described here.</p><p>Fig. 8 shows a hierarchical structure of software of the recording device 120, the portable terminal 103, and the server 180, respectively. In the following description, description of the service provider 100 is omitted. In the recording device 120 , an application 701 is configured on the encryption calculation unit 702 . The application 701 uses the encryption calculation unit 702 to perform encryption processing and the like. The software is configured in the tamper resistant module 121 . The application 701 is loaded with the application 701 according to the service provided by the recording apparatus, such as data processing in the recording apparatus 120 to encrypted communication. The encryption calculation unit 702 performs calculation processing related to encryption. The encryption processing unit 702 is used not only for the application 701 , but also for the encryption communication processing unit 704 of the portable terminal 103 .</p><p>In the portable terminal 103, the encryption communication processing unit 704 is configured on the communication basic processing unit 705, and the portable terminal application 703 is configured thereon. The communication basic processing unit 705 performs basic processing of communication with the portable terminal 103, for example, processing such as communication path encoding, communication speed change, data transmission/reception, and the like. The encryption communication processing unit 704 encrypts data to be transmitted and received using an encryption method determined between the server 180 and the server 180 . Preparation of data necessary for encrypted communication and processing such as encryption calculation are performed using the encryption calculation unit 702 of the recording device 120 . The portable terminal application 703 is various applications used by the user in the portable terminal 103, such as a menu display and an e-mail function. In the server 180 , the software includes a basic communication processing unit 706 , an encrypted communication processing unit 707 , and a server application 708 . The basic communication processing unit 706 and the encrypted communication processing unit 707 operate the same as the basic communication processing unit 704 and the encrypted communication processing unit 705 of the portable terminal 103 . However, the encryption communication processing unit 707 does not need to use the recording device 120 when performing encryption-related processing. The server application 708 is an application required to generally function as a server, such as management of the content 402 delivered to the portable terminal 103 and management of users.</p><p>A case in which the recording device 120 acquires the content 402 from the server 180 via the portable terminal 103 will be described. As shown in Fig. 9, the encrypted communication processing units 704 and 707 of the portable terminal 103 and the server 180 constitute an encrypted communication path 801 through the basic communication processing units 705 and 706 (this is equivalent to an encrypted internal communication path 109). The encrypted communication processing unit 704 performs encryption-related calculations using the encryption calculation unit 702 in the recording device 120 and transmits user information to the server 180, and the encrypted communication path 801 ) to record temporary key information used for encryption and decryption.</p><p>When the encrypted communication path 701 is configured, each application of the recording device 120 , the portable terminal 103 , and the server 180 is started as shown in FIG. 10 . The application 701 of the recording device 120 acquires a license 401 corresponding to the content 402 to be acquired from the server application 708 via the portable terminal 103 and the encrypted communication path 701, It is stored in the tamper resistant module 121 of the storage device 120 .</p><p>When the acquisition of the license 401 is finished, as shown in FIG. 11 , the application 701 of the recording device 120 encrypts the mobile terminal 103 and the server application 708 via the encrypted communication path 801 . The content 401 is acquired and stored in the flash memory 140 of the portable terminal 103 . In addition, since the content 401 has already been encrypted, in this procedure, it is sufficient to simply store the data received from the server 180 in the recording device 120, so that only the physical access command 408 is used for processing. do A logical access command 409 may be used.</p><p>Fig. 12 is a flowchart showing a communication processing procedure in Figs. 8 to 11; </p><p>Application startup processing is executed (1100). The portable terminal 103 selects, in the recording device 120, an application that performs processing necessary for communication performed by the portable terminal 103 (1101). The CPU 128 checks whether the application stored in the flash memory 140 selected in the portable terminal 103 is encrypted ( S1103 ). If encrypted, the CPU 128 decrypts the application using the secret information KM 151 and stores it in the application RAM 127 (1104). If not encrypted, the CPU 128 reads it from the flash memory 140 as it is, and stores it in the application RAM 127 in an executable state. The CPU 128 executes the application ( 1106 ).</p><p>When the application starts up, the portable terminal 103 and the storage device 120 execute the encrypted communication path establishment process 500 to establish a communication path with the server 180 . </p><p>A transmission/reception process 1120 is executed between the storage device 120 and the server 180 . At this time, the server 180 and the recording device 120 encrypt each other's data using the secret information KI 155 used in the encrypted internal communication path establishment processing 520 of the encrypted communication path establishment processing 500, The portable terminal 103 is stopped to perform transmission and reception (1107 to 1118). The portable terminal 103 cannot see the data transmitted and received by the storage device 120 . Since the portable terminal 103 can identify only the data indicating the end of transmission of the recording device 120 , when the corresponding data is transmitted from the storage device 120 , the transmission/reception processing 1120 is finished.</p><p>The portable terminal 103 executes an end process 1130 to end the transmission/reception process 1120 . Specifically, the portable terminal 103 sends a processing end notification to the recording apparatus 103 and the server 180 (1132, 1135) to break the communication path to the server 180 (1133), and the recording apparatus 120 ) to terminate the application (1136).</p><p>FIG. 13 is a diagram showing the exchange of specific commands in the case of downloading the license 401 from the server 180 to the recording device 120 via the portable terminal 103 . The description is given in correspondence with FIG. 12 .</p><p>In the application start processing 1100, the following commands are exchanged. </p><p>The OPEN_CHANNEL 1201 is a command issued from the portable terminal 103 to the recording device 120 to establish a virtual communication path between the two. The recording device 120 returns the number of the virtual communication path. Subsequent communication is performed using the virtual communication path number.</p><p>OPEN_FILE 1202 is a command for specifying a file in which the portable terminal 103 stores the license 401 in the recording device 120 . The recording device 120 returns the assigned number of the specified file. Subsequent processing is performed using this file allocation number. VERIFY 1203 is a command for the portable terminal 103 to issue an authentication code for activating an application in the recording device 120 . If the recording device 120 authenticates that the authentication code is legitimate, the application inside the recording device 120 is started, and the file designated by the OPEN_FILE 1202 can be accessed.</p><p>An encrypted communication path establishment process 510 in the public line is performed. </p><p>In the encrypted internal communication path establishment process 520, the following commands are exchanged.</p><p>The SEND_CERT 1205 is a command that requests the portable terminal 103 to transmit a certificate proving that the recording apparatus 120 is a legitimate recording apparatus 120 . The recording device 120 transmits the certificate to the portable terminal 103 .</p><p>The OPEN 1206 is a command for the portable terminal 103 to transmit the certificate and the CONTENT ID read from the recording device 120 to the server 180 . When the server 180 authenticates the certificate, the server 180 generates a session key KS1 and transmits it to the portable terminal 103 .</p><p>SET_SESSION_KEY 1207 is a command for the portable terminal 103 to transmit the session key KS1 received from the server 180 to the recording device 120 . Also, the commands of SEND_CERT 1205, OPEN 1206 and SET_SESSION_KEY 1207 correspond to content request 601 and session key KS1 transmission 602 in FIG.</p><p>In the transmission/reception process 1120, the following commands are exchanged. </p><p>ESTABLISH_WRITE_SESSION 1208 is a command for the recording device 120 to generate a session key KS2, and to transmit the encrypted KS1 to the portable terminal 103 . </p><p>ESTABLISH_WRITE_SESSION 1209 is a command for the mobile terminal 103 to transmit KS2 encrypted with KS1 received from the recording device 120 to the server 180 . Upon receiving the encrypted KS2, the server 180 decrypts the encrypted KS2 with Ks1, encrypts the license 401 with Ks2, and transmits the encrypted license 401 to the portable terminal 103. FIG.</p><p>The SET_LICENSE 1210 is a command for the portable terminal 103 to transmit the license 401 to the recording device 120 . </p><p>In the WRITE_LICENSE 1211, the portable terminal 103 decrypts the license 401 to KS2 in the recording device 120, writes a license storage area in the NV memory 125 of the tamper resistant module 121, and there This command is issued to save. In addition, ESTABLISH_WRITE_SESSION (1208, 1209), SET_LICENSE (1210), and WRITE_LICENSE (1211) correspond to session key Ks2 transmission 603 and license transmission 604 to KS1 in FIG.</p><p>In the end processing 1130, the following commands are exchanged. </p><p>The CLOSE 1212 is a command from the portable terminal 103 notifying the server 180 of the end of the license acquisition process. When the server 180 receives the CLOSE 1212 , the server 180 destroys the encrypted communication path 801 between the portable terminal 103 and the server 180 .</p><p>The CLOSE_FILE 1213 is a command issued by the portable terminal 103 to close a file in the recording device 120 . </p><p>The CLOSE_CHANNEL 1214 is a command issued by the portable terminal 103 to close the virtual communication path being used with the recording device 120 and end the process. </p><p>FIG. 14 is a diagram showing the exchange of commands when the content 402 is downloaded from the server 180 to the recording device 120 via the portable terminal 103 . The description is given in correspondence with FIG. 11 .</p><p>An encrypted communication path establishment process 510 in the public line 108 is performed. </p><p>In the transmission/reception process 1120, the following commands are exchanged. The OPEN 1301 is a command for the mobile terminal 103 to transmit the desired CONTENT ID to the server 180 . When the server 180 receives the CONTENT ID, the server 180 transmits the encrypted content 402 to the portable terminal 103 .</p><p>The SET_BLOCKS_TRANSFERRED 1302 is a command for the portable terminal 103 to transmit the size of the encrypted content 402 received from the server 180 to the recording device 120 . </p><p>The WRITE_BLOCK 1303 is a command for the portable terminal 103 to transmit the encrypted content 402 received from the server 180 to an arbitrary address on the flash memory 140 in the recording device 120 . As a method of specifying an address, a file system is installed on the flash memory 140, a file corresponding to the encrypted content 402 is created based on the CONTENT ID, and an address determined by the file system is specified. have. When the encrypted content 402 has a large capacity, SET_BLOCKS_TRANSFERRED 1302 and WRITE_BLOCK 1303 may be issued multiple times.</p><p>CLOSE 1304 is a command by which the portable terminal 103 notifies the server 180 that the license acquisition process has ended. When the server 180 receives the CLOSE 1304 , the server 180 breaks the encrypted communication path between the portable terminal 103 and the server 180 . In addition, the procedure of FIG. 14 corresponds to content transmission 605 of FIG.</p><p>15 is a conceptual diagram in a case where the decoder circuit 206 in the portable terminal 103 reproduces the encrypted content 402 in the recording device 120. As shown in FIG. The decoder circuit 206 may be used while being mounted in a device other than the portable terminal 103 . The recording device 120 can also be connected to devices other than the portable terminal 103 . Specific examples include MP3 players, stereos, digital image players, and the like. The decoder circuit 206 extracts the license 401 of the encrypted content 402 to be reproduced from the tamper resistant module 121 of the recording device 120 . The decoder circuit 206 extracts the encrypted content 402 from the flash memory 140, decrypts the encrypted content 402 with the license 401, and then reproduces it. The license transmission 1402 is done using the layering command 405 . The content transmission 1403 is done using the physical access command 408 . In addition, the structure of the command at the time of each transmission is not limited to this.</p><p>Fig. 16 is a flowchart showing details of communication in Fig. 15; </p><p>The processing from the application start processing 1100 to the execution of the application 1106 is the same as the flow described with reference to FIG. 11, and therefore the description is omitted. </p><p>When the application starts up, the encryption internal communication path establishment process 520 is executed, and the communication path between the decoder circuit 206 and the recording device 120 is established. In this case, a communication path is established using the secret information KL 157 dedicated to the decoder circuit 206 .</p><p>Transmission/reception processing 1500 is executed, and data transmission/reception is actually performed between the recording device 120 and the decoder circuit 206 . At this time, using the secret information KL 157 used in the encrypted internal communication path establishment process 520, the decoder circuit 206 and the recording device 120 encrypt and transmit/receive data to each other (1501 to 1508). In the middle of the transmission/reception process 1500 , the control of the portable terminal 103 is performed by the decoder circuit 206 . Upon completion of transmission/reception, the decoder circuit 206 sends a command notifying the end interrupt to the CPU 201 of the portable terminal. Upon receiving the command of the end interrupt, the CPU 201 starts the end process (1510). Specifically, the CPU 201 of the portable terminal 103 transmits a processing end notification to the recording device 120 (1512), and terminates the application (1513).</p><p>Fig. 17 shows the commands of the procedure between the decoder circuit 206 and the recording device 120 when the license 401 is acquired. The description is given in correspondence with FIG. 16 . In Fig. 17, all portions described as confidential information KI 155 as the material of data in the notation rule 2101 are replaced with confidential information KL. Further, KS5 is generated by the encryption processing circuit 126 of the recording device 120 using a random number or the like, and KS6 is generated by the encryption processing circuit 304 of the decoder circuit 206 using a random number or the like.</p><p>In the application start processing 1100, the following commands are exchanged. </p><p>The OPEN_CHANNEL 1600 is issued to the recording device 120 via the recording device interface 207 of the portable terminal 103 so that the decoder circuit 206 establishes a virtual communication path with the storage device 120 . is a command to The recording device 120 receiving the OPEN_CHANNEL (1600) command returns the number of the virtual communication path. Subsequent communication is performed using this virtual communication path number.</p><p>The OPEN_FILE 1601 is a command for the decoder circuit 206 to designate a file in which the license 401 in the recording device 120 is stored. The recording device 120, which has received the OPEN_FILE (1601) command, returns the assigned number of the specified file. Subsequent processing is performed using the file allocation number.</p><p>VERIFY 1602 is a command for the decoder circuit 206 to issue an authentication code for activating an application in the recording device 120 . If the recording device 120 authenticates that the authentication code is legitimate, the application inside the recording device 120 is started, and the file designated by the OPEN_FILE 1601 can be accessed.</p><p>In the encrypted internal communication path establishment process 520 in which the secret information KL 157 is used, the following commands are exchanged. </p><p>VERIFY_CERT 1604 is a command for decoder circuit 206 to send a certificate to recording device 120 . The recording device 120 receiving the VERIFY_CERT 1604 command authenticates the certificate.</p><p>The SEND_SESSION_KEY 1605 is a command for the recording device 120 to transmit the session key KS5 generated by the encryption processing circuit 126 to the decoder circuit 200 . </p><p>ESTABLISH_PLAY_SESSION 1606 is a command that the decoder circuit 206 having received KS5 generates the session key KS6 generated by the encryption processing circuit 304, encrypts KS6 with KS5, and transmits it to the recording device 120 . </p><p>In the transmission/reception process 1500, the following commands are exchanged. </p><p>The READ_LICENSE 1607 is a command instructing the decoder circuit 206 to prepare the license 401 to be read to the recording device 120 . The SEND_PLAY_LICENSE 1608 is a command for the decoder circuit 206 to read the license 401 from the recording device 120 .</p><p>In the end process 1510, the following commands are exchanged. </p><p>The CLOSE_FILE 1609 is a command issued by the decoder circuit 206 to close the file of the recording device 120 . </p><p>The CLOSE_CHANNEL 1610 is a command issued by the portable terminal 103 to close the virtual communication path used with the recording device 120 and to end the process. </p><p>FIG. 18 is a diagram showing the processing of reading the encrypted content 402 reproduced from the recording device 120 by the decoder circuit 206 after the license 401 has been acquired. In this procedure, since the content 402 is already encrypted, it is sufficient to simply read the data from the recording device 120 to the decoder circuit 206, so that the processing is performed using only the physical access command 408. do A logical access command 409 may be used.</p><p>In the process of Fig. 18, the following commands are exchanged. </p><p>The SET_BLOCKLEN 1704 is a command for the decoder circuit 206 to transmit the size of the encrypted content 402 to be read to the recording device 120 . </p><p>SENT_BLOCKS_TRANSFERRED 1705 is a command that specifies the amount by which the decoder circuit 206 reads the encrypted content 402 in the recording device 120 at one time. </p><p>READ_BLOCK 1706 is a command issued by the decoder circuit 206 to read the encrypted content 402 by designating the address of the encrypted content 402 to be reproduced to the recording device 120 and to perform reproduction. </p><p>With such a configuration, a large amount of data can be safely stored. </p>
<p>In the present invention, since data with high secrecy is encrypted in a storage device equipped with a tamper-resistant module and a large-capacity flash memory and stored in a large-capacity flash memory, it is possible to retain large-capacity data with high secrecy while maintaining data confidentiality. It is possible to construct a low-cost recording device that can In addition, since encryption processing is performed inside the recording apparatus and there is no need for the external apparatus to perform encryption key or encryption/decryption, the burden on the external apparatus is reduced.</p><p>Further, in the present invention, a CPU is mounted on the tamper-resistant module, which determines the confidentiality of data transmitted from the outside according to various conditions, and information with high confidentiality is stored in a nonvolatile memory in the tamper-resistant module, Since information with low confidentiality is stored in an external flash memory, data processing is faster than when all data is encrypted, and the recording area in the tamper-resistant module can be effectively used. </p><p>In addition, in the present invention, applications executed in the tamper-resistant module are encrypted and stored in an external flash memory, and, if necessary, they are read from the flash memory to the internal RAM and executed so that various applications can be written to the recording device at once. It is possible to mount it, and it is also possible to execute a large-scale application in the recording apparatus.</p>
Contents2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0065602A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| KR20000052449A | Cites | Republic of Korea | Search report |
| KR20010006968A | Cites | Republic of Korea | Search report |
| KR20010083073A | Cites | Republic of Korea | Search report |
| KR20030071461A | Cites | Republic of Korea | Search report |
| WO9938078A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
6 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001030384 | Japan | A | |
| 2001030384 | Japan | A | |
| P200100030384 | Japan | – | |
| JP20010030384 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| KR20020065855A | Republic of Korea | A | |
| JP2002229861A | Japan | A | |
| US2002169960A1 | United States of America | A1 | |
| TW578049B | Taiwan Province of China | B | |
| KR100503588B1This record | Republic of Korea | B1 | |
| US7162645B2 | United States of America | B2 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapse due to unpaid annual feeLapsedLAPS | LAPS | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-0503588
- Publication, DOCDB
- 100503588
- Publication, EPODOC
- KR100503588B
- Application
- 100006734
- Application, DOCDB
- 20020006734
- Application, EPODOC
- KR20020006734
Titles2
- Korean
- 불휘발성 메모리를 갖는 기록 장치
- English
- Recording device with non-volatile memory
Classification
- CPC, 4
- G06F21/78
- G06K19/073
- G06F21/10
- G06F2221/2113
- IPC, 12
- G06F12 14
- G06K19 073
- G06F3 06
- G06F3 08
- G06F21 10
- G06F21 12
- G06F21 14
- G06F21 60
- G06F21 62
- G11C16 02
- H04L9 08
- H04L9 10