MY124136A

Communication method, and information processing apparatus

Abstract

MUTUAL AUTHENTICATION IS PERFORMED. A READER/WRITER (1) TRANSMITS TO AN IC CARD (2) A CODE (C1) SUCH THAT A RANDOM NUMBER (RA) IS ENCRYPTED USING A KEY( KB).THE IC CARD (2) DECRYPTS THE CODE (C1) INTO PLAIN TEXT (M1) USING THE KEY (KB).THE IC CARD (2) TRANSMITS TO THE R/W (1) A CODE (C2) SUCH THAT THE PLAIN TEXT (M1) IS ENCRYPTED USING A KEY (KA) AND A CODE (C3) SUCH THAT A RANDOM NUMBER (Rs) IS ENCRYPTED USING THE KEY (KA). THE R/W (1) DECRYPTS THE CODES (C2) AND (C3) INTO PLAIN TEXT (M2) AND PLAIN TEXT (M3), RESPECTIVELY, USING THE KEY (KA).WHEN THE R/W (1) DETERMINES THAT THE PLAIN TEXT (M2) AND THE RANDOM NUMBER (RA) ARE THE SAME, IT AUTHENTICATES THE IC CARD (2). NEXT, THE R/W (1) TRANSMITS TO THE IC CARD (2) A CODE (C4) SUCH THAT THE PLAIN TEXT (M3) IS ENCRYPTED USING THE KEY (KB). THE IC CARD (2) DECRYPTS THE CODE (C4) INTO PLAIN TEXT (M4) USING THE KEY (KB). WHEN THE IC CARD (2) DETERMINES THAT THE PLAIN TEXT (M4) AND THE RANDOM NUMBER (RB) ARE THE SAME, IT AUTHENTICATES THE R/W.(FIG. 9)

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

29 claims: 4 independent, 25 dependent

  1. 1
    An authentication method between a first information processing apparatus (1) and a second information processing apparatus(2), wherein said first information processing apparatus(l) and said second information processing apparatus(2) include storage means(14,84) for storing a first key(Ke) and a second key(KA), encryption means(12,82) for encrypting predetermined data using either one of said first key(Ke) and said second key (KA)and decryption means(13,83) for decrypting a code generated by either one of said second key (KA)and said first key(Ka), said method comprising the steps of:encrypting random first data(RA )into a first code(Ci) using said first key(Ke) of said L 0 encryption means of said first information processing apparatus;decrypting said first code(Ci) into second data(Mi)using said first key(Ke) of said decryption means of said second information processing apparatus;encrypting said second data(Mi) into a second code(C2) using said second key (Ka) of said encryption means of said second information processing apparatus;15 encrypting random third data(Re) into a third code(Ca) using said second key(KA) of said encryption means of said second information processing apparatus;decrypting said second code(C2) into fourth data(M2) using said second key(KA) of said decryption means of said first information processing apparatus;authenticating said second information processing apparatus by said first information jQ processing apparatus on the basis of said first data(RA) and said fourth data(M2);decrypting said third code (Ca) into fifth data(Ma) using said second key(KA) of said decryption means of said first information processing apparatus;encrypting said fifth data(Ma) into a fourth code(C4) using said first key(Ke) of said encryption means of said first information processing apparatus;25 decrypting said fourth code(C4) into sixth data(M4)using said first key(Ke) of said di ατηηοαο-ι decryption means of said second information processing apparatus;and authenticating said first information processing apparatus by said second information processing apparatus on the basis of said third data(Re) and said sixth data(M i).
  2. 2
    A communication method between a first information processing apparatus(l) and a second information processing apparatus(2), wherein said first information processing apparatus(l) and said second information processing apparatus(2) include storage means(14,84) for storing a first key and a second key, encryption means(12,82) for encrypting predetermined data using either one of said first key and said second key, decryption means(13,83) for decrypting a code generated by either one of said second key and said first key, transmission means(16,86) for transmitting said encrypted predetermined data and receiving means( 18,88) for receiving said encrypted predetermined data, said method comprising the steps of:encrypting random first data into a first code using said first key of said encryption means of said first information processing apparatus;transmitting said first code to said second information processing apparatus using said transmission means of said first information processing apparatus;receiving said first code from said first information processing apparatus using said receiving means of said second information processing apparatus;decrypting said first code into second data using said first key of said decryption means of said second information processing apparatus;encrypting said second data into a second code using said second key of said encrypting means of said second information processing apparatus;encrypting random third data into a third code using said second key of said encryption means of said second information processing apparatus;transmitting said second code and said third code to said first information processing apparatus using said transmission means of said second information processing apparatus;receiving said second code and said third code from said second information processing apparatus using said receiving means of said first information processing apparatus;decrypting said second code into fourth data using said second key of said decryption means of said first information processing apparatus;authenticating said second information processing apparatus by said first information processing apparatus on the basis of said first data and said fourth data;decrypting said third code into fifth data using said second key of said decryption means of said first information processing apparatus;encrypting said fifth data into a fourth code using said first key of said second encryption means of said first information processing apparatus;transmitting said fourth code to said second information processing apparatus using said transmission means of said first information processing apparatus;receiving said fourth code from said first information processing apparatus using said receiving means of said second information processing apparatus;decrypting said fourth code into sixth data using said first key of said decryption means of said second information processing apparatus;and authenticating said first information processing apparatus by said second information processing apparatus on the basis of said third data and said sixth data.
  3. 15
    An information processing apparatus(l) of a plurality of information processing apparatuses, comprising:storage means (14) for storing a first key and a second key;encryption means(12)for encrypting predetermined data using one of said first key and said second key;decryption means(13) for decrypting a code generated by one of said second key and said first key;transmission means(
  4. 16
    16)for transmitting a code encrypted by said encryption means to one of said plurality of information processing apparatuses;receiving means(18) for receiving a code from said one of said plurality of information processing apparatuses;and authentication means for authenticating said one of said plurality of information processing apparatuses on the basis of said predetermined data and data generated by decrypting the code received from said one of said plurality of information processing apparatuses, wherein said encryption means(12) encrypts random first data(RA) into a first code (Ci)using said first key(Ks), said transmission means(16) transmits said first code(Ci) to said one of said plurality of information processing apparatuses, said receiving means (18) receives a second code(C2) and a third code(Ca) from said one of said plurality of information processing apparatuses, said decryption means(13) decrypts said second code (C2)into fourth data(M2) using said second key(KA) and decrypts said third code (C3) into fifth data(Ms) using said second key(KA), said authentication means authenticates said one of said plurality of information processing apparatuses on the basis of said first data(RA) and said fourth data(M2), said encryption means encrypts said fifth data(Ms) into a fourth code(C i) using said first key, and said transmission means transmits said fourth code(C i) to said one of said plurality of information processing apparatuses. Q 16. The information processing apparatus of said plurality of information processing apparatuses according to claim 15, wherein said first data is a predetermined identification number, said third data is a third key, said encryption means encrypts a first command into a fifth code using said third key and encrypts said predetermined identification number into a sixth code using said third key, and said transmission 1 θ means transmits said fifth code with said sixth code to said one of said plurality of information processing apparatuses.
  5. 23
    24. An information processing apparatus for use with a plurality of information processing apparatuses, comprising:storage means(84) for storing a first key(Ke) and a second key(KA);encryption means(82) for encrypting predetermined data using one of said first key and said second key;decryption means(83) for decrypting a code generated by one of said second key and said first key;transmission means(86) for transmitting a code encrypted by said encryption means to one of said plurality of information processing apparatuses;DI ΟΎΛΛΟΟη-ί receiving means(88) for receiving a code from said one of said plurality of information processing apparatuses;and authentication means for authenticating said one of said plurality of information processing apparatuses on the basis of said predetermined data and data obtained by decrypting said code received from one of said plurality of information processing apparatuses, wherein said receiving means receives a first code from said one of said plurality of information processing apparatuses, said decryption means decrypts said first code into first data using said first key, said encryption means encrypts said first data into a second code using said second key and encrypts random second data into a third code using said second key, said transmission means transmits said second code and said third code to said one of said plurality of information processing apparatuses, said receiving means receives a fourth code from said one of said plurality of information processing apparatuses, said decryption means decrypts said fourth code into third data using said second key, and said authentication means authenticates said one of said plurality of information processing apparatuses on the basis of said second data and said third data.