Storage medium control method
Claim Score by NHIP
Abstract
A storage medium control apparatus capable of improving the processing performance, while protecting copyright protection information in a security mode, includes: a secure resource which executes mutual authentication processing with an authentication area of a storage medium, and performs encryption or decryption of data; a normal resource which sends or receives data to or from the storage medium; an encryption control unit which performs encryption or decryption of data by controlling the secure resource in the secure mode; a storage medium control unit which sends or receives data encrypted by the encryption control unit or data decrypted by the encryption control unit to or from the storage medium by controlling the normal resource, in the secure mode; and a storage medium processing unit which performs predetermined processing for the data decrypted by the encryption control unit or unencrypted data read from the storage medium by the storage medium control unit.

Term
Projected expiry 12 October 2027.
- Priority
- Filed
- Published
- Today
- Projected expiry
20 claims: 3 independent, 17 dependent
- 1Broadest claimClaim Score 53, average(NHIP)A storage medium control method for controlling data communication with a storage medium while switching between a secure mode in which use of a secure resource is permitted and a normal mode in which only use of a normal resource is permitted, wherein the storage medium includes:an authentication area which can be accessed after mutual authentication is performed;and a normal area which can be accessed without performing the mutual authentication, the secure resource is a module which executes mutual authentication processing with the authentication area of the storage medium, the normal resource is a module which sends or receives data to or from the storage medium, and said storage medium control method comprises a secure-mode data sending/receiving step of sending or receiving data to or from the storage medium by controlling of the normal resource without switching to the normal mode by a storage medium control unit which controls the storage medium, in the secure mode.
- 16A storage medium control apparatus which controls data communication with a storage medium while switching between a secure mode in which use of a secure resource is permitted and a normal mode in which only use of a normal resource is permitted, wherein the storage medium includes:an authentication area which can be accessed after mutual authentication is performed;and a normal area which can be accessed without performing the mutual authentication, and said storage medium control apparatus comprises: said secure resource which executes mutual authentication processing with the authentication area of the storage medium, and encryption or decryption of data;said normal resource which sends or receives data to or from the storage medium;an encryption control unit operable to execute encryption or decryption of data by controlling the secure resource in the secure mode;a storage medium control unit operable to send or receive data to or from the storage medium by controlling of said normal resource without switching to the normal mode, in the secure mode, the data being the data encrypted by said encryption control unit or data to be decrypted by said encryption control unit;and a storage medium processing unit operable to execute predetermined processing for the data decrypted by said encryption control unit or unencrypted data read from the storage medium by said storage medium control unit, in the secure mode.
- 20A program for causing a computer to function as a storage medium control apparatus which controls data communication with a storage medium while switching between a secure mode in which use of a secure resource is permitted and a normal mode in which only use of a normal resource is permitted, wherein the storage medium includes:an authentication area which can be accessed after mutual authentication is performed;and a normal area which can be accessed without performing the mutual authentication, and the program causes the computer to function as: the secure resource which executes mutual authentication processing with the authentication area of the storage medium, and encryption or decryption of data;the normal resource which sends or receives data to or from the storage medium;an encryption control unit operable to execute encryption or decryption of data by controlling the secure resource in the secure mode;a storage medium control unit operable to send or receive data to or from the storage medium by controlling of the normal resource without switching to the normal mode, in the secure mode, the data being the data encrypted by the encryption control unit or data to be decrypted by the encryption control unit;and a storage medium processing unit operable to execute predetermined processing for the data decrypted by the encryption control unit or unencrypted data read from the storage medium by the storage medium control unit.
Independent claims3
363 paragraphs in 5 sections, as filed
BACKGROUND OF THE INVENTION
0001(1) Field of the Invention
0002The present invention relates to a storage medium control method for controlling access to a storage medium including an authentication area which can be accessed after executing a mutual authentication processing and a normal area which can be accessed without executing the mutual authentication processing.
0003(2) Description of the Related Art
0004Recently, a necessity for copyright protection of contents has been increased. In terrestrial digital broadcasting and the like, contents distribution including right information, which is described later, has been performed. When such contents are recorded in a storage medium, it is necessary to record the right information together with the contents.
0005The “right information” includes information which is important to protect copyright, such as information about whether or not the contents can be moved, copied or reproduced and information about the number of times the contents can be removed, copied or reproduced, and the like. Therefore, various equipment for handling such contents is required to handle them in a manner that the right information is not falsified.
0006Information required to be protected, such as the right information, is stored in an “authentication area” of a storage medium, and it is not possible to access data stored in the authentication area until mutual authentication is performed between the storage medium and the various equipment. Meanwhile, other information is stored in a “normal area” of the storage medium which can be accessed without a necessity of mutual authentication.
0007There has been proposed, as a data access apparatus for accessing the storage medium, a data processing apparatus in which a monitor program switches between a “secure mode” enabling access to secure data and secure applications required to be protected and a “normal mode” in which the secure data and the secure applications cannot be accessed, and executes the mode (for example, see Japanese Unexamined Patent Application Publication No. 2005-182774).
0008The data processing apparatus described in Japanese Unexamined Patent Application Publication No. 2005-182774 reproduces the contents while protecting the right information by switching between the normal mode and the secure mode to access the storage medium.
0009However, a processing, such as a save/restore processing, of security information is required to switch between the secure mode and the normal mode. Furthermore, in the data processing apparatus described in Japanese Unexamined Patent Application Publication No. 2005-182774, switching between both modes caused by alternately accessing a secure resource and a normal resource frequently occurs, especially in copyright protection processing such as the mutual authentication or access to the authentication area. Therefore, there is a problem that the processing performance significantly deteriorates. Note that the “secure resource” refers to hardware for executing the mutual authentication processing or performing encryption or decryption of data, which can operate only in the secure mode. On the other hand, the “normal resource” refers to hardware for writing and reading of data to and from the storage medium, which can operate only in the normal mode.
SUMMARY OF THE INVENTION
0010The present invention has been made to solve the above problems, and its object is to provide a storage medium control method which makes it possible to improve a processing performance while protecting copyright protection information in a secure mode.
0011A storage medium control method according to an aspect of the present invention is a storage medium control method for controlling data communication with a storage medium while switching between a secure mode in which use of a secure resource is permitted and a normal mode in which only use of a normal resource is permitted. The storage medium includes: an authentication area which can be accessed after mutual authentication is performed; and a normal area which can be accessed without performing the mutual authentication. The secure resource is a module which executes mutual authentication processing with the authentication area of the storage medium, and the normal resource is a module which sends or receives data to or from the storage medium. The storage medium control method includes a secure-mode data sending/receiving step of sending or receiving data to or from the storage medium by controlling of the normal resource without switching to the normal mode by a storage medium control unit which controls the storage medium, in the secure mode.
0012According to this configuration, it is possible to directly access the normal resource even in the secure mode. Therefore, it is not necessary to perform switching to the normal mode when accessing the data stored in the storage medium in the secure mode. Accordingly, it is possible to reduce the number of times of switching between the secure mode and the normal mode. Furthermore, it is possible to perform a processing without handling copyright protection information (right information) on the normal mode side. Accordingly, it is possible to improve the processing performance while protecting the copyright protection information (right information) in the security mode.
0013It is preferable that the secure resource further execute the mutual authentication processing with the authentication area of the storage medium. The secure-mode data sending/receiving step includes a secure-mode encrypted/decrypted data sending/receiving step of sending or receiving the data to or from the storage medium by controlling of the normal resource without switching to the normal mode by the storage medium control unit which controls the storage medium, in the secure mode, the data being the data encrypted by an encryption control unit which controls encryption or decryption of data or the data to be decrypted by an encryption control unit. The storage medium control method further includes: a secure-mode encryption/decryption step of encrypting or decrypting data by controlling of the secure resource by the encryption control unit, in the secure mode; and a secure-mode predetermined processing execution step of executing predetermined processing, by a storage medium processing unit, for the data decrypted in said secure-mode encrypting/decrypting step or unencrypted data read from the storage medium in said secure-mode encrypted/decrypted data sending/receiving step, in the secure mode.
0014The storage medium control unit includes: a storage medium authentication area control unit which controls the authentication area of the storage medium in the secure mode; and a storage medium normal area control unit which controls the normal area of the storage medium in the normal mode. The storage medium processing unit includes: a storage medium authentication area processing unit which executes predetermined processing for data in the secure mode; and a storage medium normal area processing unit which executes predetermined processing for data in the normal mode. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource without switching to the normal mode by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit. In the secure-mode predetermined processing execution step, the storage medium authentication area processing unit executes the predetermined processing for the data decrypted in the secure-mode encryption/decryption step or the unencrypted data read from the authentication area of the storage medium in the secure-mode encrypted/decrypted data sending/receiving step, in the secure mode. The storage medium control method further includes: a normal-mode data sending/receiving step of sending or receiving data to and from the normal area of the storage medium by controlling of the normal resource by the storage medium normal area control unit, in the normal mode; and a normal-mode predetermined processing execution step of executing predetermined processing, by the storage medium normal area processing unit, for the data sent or received in said normal-mode data sending/receiving step, in the normal mode.
0015According to this configuration, it is further possible to perform data access to the normal area and data access to the authentication area while sharing the same normal resource under the control from the normal mode side and the control from the secure mode side. Therefore, it is not necessary to switch to the normal mode when accessing the data stored in the storage medium in the secure mode, and it is possible to reduce the number of times of switching between the secure mode and the normal mode. Thereby, the processing can be speeded up.
0016Furthermore, it is usually possible to easily add the storage medium authentication area control unit and the storage medium authentication area processing unit while avoiding a modification of the storage medium normal area control unit and the storage medium normal area processing unit configured by an existing general-purpose OS as much as possible.
0017The storage medium control method further includes: an initialization step of acquiring storage medium information including at least address information, area size or access size about the storage medium by executing initialization processing of the storage medium by the storage medium normal area control unit; and a notification step of notifying the storage medium authentication area control unit of the storage medium information acquired in said initialization step. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource using the storage medium information without switching to the normal mode by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit.
0018According to this configuration, it is possible to access the storage medium on the normal mode side and on the secure mode side simply by performing an initialization of the storage medium only on the normal mode side.
0019The storage medium control method further includes: an initialization step of acquiring storage medium information including at least address information, area size or access size about the storage medium by executing initialization processing of the storage medium, irrespective of whether or not the storage medium has already been executed, by the storage medium authentication area control unit, when transitioning to the secure mode. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource using the storage medium information without switching to the normal mode by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit.
0020According to this configuration, it is possible for the storage medium authentication area control unit to acquire the storage medium information independent from the storage medium normal area control unit. Therefore, the operation is possible without synchronizing the storage medium normal area control unit and the storage medium authentication area control unit, so that the processing can be speeded up.
0021The storage medium control method further includes: an initialization step of acquiring storage medium information including at least address information, area size or access size about the storage medium by executing initialization processing of the storage medium by the storage medium normal area control unit; an encryption step of encrypting, using a secret key, the storage medium information acquired in said initialization step; a notification step of notifying the storage medium authentication area control unit of the encrypted storage medium information, the encrypted storage medium information being the storage medium information that has been encrypted; and a decryption step of decrypting, using the secret key, the encrypted storage medium information by the storage medium authentication area control unit. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource using the storage medium information without switching to the normal mode by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data decrypted by the encryption control unit.
0022According to this configuration, the storage medium information is encrypted. Therefore, it is possible to improve the strength of security of data in sending and receiving the data.
0023The storage medium control method further includes: a step of judging, by the storage medium normal area processing unit, whether or not the storage medium normal area control unit is accessing the normal area of the storage medium; a step of permitting the storage medium authentication area control unit to use the normal resource when it is judged that the normal area of the storage medium is not being accessed; a step of judging, by the storage medium authentication area processing unit, whether or not the storage medium authentication area control unit is accessing the authentication area of the storage medium; and a step of permitting the storage medium normal area control unit to use the normal resource when it is judged that the authentication area of the storage medium is not being accessed.
0024According to this configuration, it is possible to perform an exclusive control so that the storage medium normal area control unit and the storage medium authentication area control unit do not access the storage medium at the same time.
0025The storage medium control method further includes: a step of judging a condition of access to the storage medium by referencing of storage medium access data indicating the condition of access to the storage medium by the storage medium authentication area control unit, the storage medium access data allowing referencing from both the storage medium authentication area control unit and the storage medium normal area control unit; a step of permitting the storage medium authentication area control unit to use the normal resource when the storage medium authentication area control unit judges that the storage medium is not being accessed; a step of judging a condition of access to the storage medium by referencing of the storage medium access data by the storage medium normal area processing unit; and a step of permitting the storage medium normal area control unit to use the normal resource when the storage medium normal area control unit judges that the storage medium is not being accessed.
0026According to this configuration, it is possible to perform the exclusive control so that the storage medium normal area control unit and the storage medium authentication area control unit do not access the storage medium at the same time.
0027The storage medium control method further includes: a step of resetting the normal resource by the storage medium normal area control unit or the storage medium authentication area control unit, each time mode switching between the secure mode and the normal mode occurs; and a step of setting a set value including access bit width for accessing the storage medium or access size of data sent to or received from the storage medium for the normal resource by the storage medium normal area control unit or the storage medium authentication area control unit, the storage medium normal area control unit or the storage medium authentication area control unit resetting the normal resource. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource without switching to the normal mode, in accordance with the set value set for the normal resource, by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit. In the normal-mode data sending/receiving step, the data is sent to or received from the normal area of the storage medium by controlling of the normal resource, in accordance with the set value set for the normal resource, by the storage medium normal area control unit, in the normal mode.
0028According to this configuration, each of the storage medium normal area control unit and the storage medium authentication area control unit resets and sets set values for the normal resource. Therefore, the storage medium authentication area control unit can access the storage medium without depending on the set values of the normal resource set by the storage medium normal area control unit, and the storage medium normal area control unit can access the storage medium without depending on the set values of the normal resource set by the storage medium authentication area control unit.
0029The storage medium control method further includes: a step of backing up, in a predetermined memory area, a set value including access bit width for accessing the storage medium or access size of data sent to or received from the storage medium when switching from the normal mode to the secure mode, the storage medium being used by the storage medium normal area control unit; a step of setting the set value to be used by the storage medium authentication area control unit for the normal resource after the set value is backed up in the predetermined memory area; and a step of setting the set value to be used by the storage medium normal area control unit for the normal resource when exiting the secure mode, the set value being backed up in the predetermined memory area. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource without switching to the normal mode, in accordance with the set value set for the normal resource, by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit. In the normal-mode data sending/receiving step, the data is sent to or received from the normal area of the storage medium by controlling of the normal resource, in accordance with the set value set for the normal resource, by the storage medium normal area control unit, in the normal mode.
0030According to this configuration, it is not necessary to set the set values for a normal resource in the normal mode. Therefore, it is not necessary to modify an existing storage medium normal area control unit.
0031The normal resource is connected to a set value storage unit which is a module storing a set value including access bit width for accessing the storage medium or access size of data sent to or received from the storage medium, the set value being used when the normal resource accesses the storage medium. The storage medium control method further includes a step of setting the set value stored in the set value storage unit for each mode by the normal resource, each time mode switching between the normal mode and the secure mode occurs. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling the normal resource without switching to the normal mode, in accordance with the set value set for the normal resource, by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit. In the normal-mode data sending/receiving step, data is sent to or received from the normal area of the storage medium by controlling of the normal resource, in accordance with the set value set for the normal resource, by the storage medium normal area control unit, in the normal mode.
0032According to this configuration, when the mode is switched, the normal resource reads the set values from the set value storage unit, which is hardware, and sets the set values. Therefore, it is possible to change the set values at a high speed with the switching of the mode.
0033The storage medium control method further includes: a step of judging whether or not access to the storage medium is a first access after resetting of the storage medium by the storage medium normal area processing unit, when the access to the storage medium occurs; a step of initializing the storage medium by the storage medium normal area processing unit when it is judged that the access is the first access after the resetting of the storage medium; and a step of notifying the storage medium authentication area control unit of storage medium access information when the normal mode is switched to the secure mode, the storage medium access information being identification information identifying the storage medium and obtained along with the initialization of the storage medium. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource in accordance with the storage medium access information without switching to the normal mode by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit. It should be noted that the storage medium is reset when turning the power on or off, inserting or removing the storage medium, occurrence of an abnormal state, or the like takes place.
0034According to this configuration, when the mode is switched, it is possible to notify not the storage medium information but only the storage medium access information to the storage medium authentication area control unit. Therefore, the processing by the storage medium authentication area control unit can be speeded up.
0035The storage medium control method further includes a step of executing mutual authentication processing by the storage medium authentication area control unit, only when the mutual authentication processing with the authentication area of the storage medium has not succeeded at all after the resetting of the storage medium, with the authentication area of the storage medium, in the secure mode.
0036According to this configuration, it is possible to omit the second and subsequent mutual authentication processing. Therefore, the processing can be speeded up.
0037The storage medium control method further includes: a step of initializing the storage medium by the storage medium normal area control unit, each time a request to access the storage medium occurs; and a step of notifying the storage medium authentication area control unit of storage medium access information when the normal mode is switched to the secure mode, the storage medium access information being identification information for identifying the storage medium and obtained along with the initialization of the storage medium. In the secure-mode encrypted/decrypted data sending/receiving step, the data is sent to or received from the authentication area of the storage medium by controlling of the normal resource without switching to the normal mode, in accordance with the storage medium access information, by the storage medium authentication area control unit, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit.
0038According to this configuration, the storage medium normal area control unit can always start processing after the storage medium is reset, and on the contrary, a storage medium authentication area control unit can always start a processing on the assumption that the storage medium has been reset. Thereby, the processing for judging reset of the storage medium is reduced, and the processing can be speeded up.
0039A storage medium control apparatus according to other aspect of the present invention is a storage medium control apparatus which controls data communication with a storage medium while switching between a secure mode in which use of a secure resource is permitted and a normal mode in which only use of a normal resource is permitted. The storage medium includes: an authentication area which can be accessed after mutual authentication is performed; and a normal area which can be accessed without performing the mutual authentication. The storage medium control apparatus includes: the secure resource which executes mutual authentication processing with the authentication area of the storage medium, and encryption or decryption of data; the normal resource which sends or receives data to or from the storage medium; an encryption control unit which executes encryption or decryption of data by controlling the secure resource in the secure mode; a storage medium control unit which sends or receives data to or from the storage medium by controlling of the normal resource without switching to the normal mode, in the secure mode, the data being the data encrypted by said encryption control unit or data to be decrypted by said encryption control unit; and a storage medium processing unit which executes predetermined processing for the data decrypted by the encryption control unit or unencrypted data read from the storage medium by the storage medium control unit, in the secure mode.
0040According to this configuration, it is possible to directly access the normal resource even in the secure mode. Therefore, it is not necessary to perform the switching to the normal mode when accessing the data stored in the storage medium in the secure mode. Accordingly, it is possible to reduce the number of times of switching between the secure mode and the normal mode. Furthermore, it is possible to perform the processing without handling the copyright protection information (right information) on the normal mode side. Accordingly, it is possible to improve the processing performance while protecting the copyright protection information (right information) in the security mode.
0041The storage medium control unit includes: a storage medium authentication area control unit which sends or receives data to or from the authentication area of the storage medium by controlling of the normal resource, in the secure mode, the data being the data encrypted by the encryption control unit or the data to be decrypted by the encryption control unit; and a storage medium normal area control unit which sends or receives data to or from the normal area of the storage medium by controlling of the normal resource, in the normal mode. The storage medium processing unit includes: a storage medium authentication area processing unit which executes predetermined processing for the data decrypted by the encryption control unit or unencrypted data read from the authentication area of the storage medium by the storage medium authentication area control unit, in the secure mode; and a storage medium normal area processing unit which executes predetermined processing for the unencrypted data read from the normal area of the storage medium by the storage medium normal area control unit, in the normal mode.
0042According to this configuration, it is further possible to perform the data access to the normal area and the data access to the authentication area while sharing the same normal resource under the control from the normal mode side and the control from the secure mode side. Therefore, it is not necessary to switch to the normal mode when accessing the data stored in the storage medium in the secure mode, and it is possible to reduce the number of times of switching between the secure mode and the normal mode. Thereby, the processing can be speeded up.
0043Furthermore, it is usually possible to easily add the storage medium authentication area control unit and the storage medium authentication area processing unit while avoiding the modification of the storage medium normal area control unit and the storage medium normal area processing unit configured by the existing general-purpose OS as much as possible.
0044The storage medium control apparatus further includes: an encoding processing unit which receives video/audio contents from the storage medium normal area control unit, analyzes an encoding format of the received video/audio contents, decodes the video/audio contents, and outputs video/audio data in particular data unit; and a video/audio reproduction unit which receives and reproduces the video/audio data outputted from the encoding processing unit in the particular data unit.
0045The storage medium control apparatus further includes: a video/audio recording unit which receives video/audio data in particular data unit; and an encoding processing unit which encodes the video/audio data received by the video/audio recording unit on the basis of a particular encoding format, and outputs the data to the storage medium normal area control unit.
0046According to the present invention, it is possible to provide the storage medium control method and the like capable of improving the processing performance while protecting the copyright protection information in the secure mode.
Further Information about Technical Background to this Application
0047The disclosure of Japanese Patent Application No. 2006-284373 filed on Oct. 18, 2006 including specification, drawings and claims is incorporated herein by reference in its entirety.
0048The disclosure of Japanese Patent Application No. 2007-129806 filed on May 15, 2007 including specification, drawings and claims is incorporated herein by reference in its entirety.
BRIEF DESCRIPTION OF THE DRAWINGS
0049These and other objects, advantages and features of the invention will become apparent from the following description thereof taken in conjunction with the accompanying drawings that illustrate a specific embodiment of the invention. In the Drawings:
0050<figref idref="DRAWINGS">FIG. 1</figref> is a diagram showing an aspect of utilization of a storage medium control system;
0051<figref idref="DRAWINGS">FIG. 2</figref> is a functional block diagram showing a configuration of a storage medium control system according to a first embodiment;
0052<figref idref="DRAWINGS">FIGS. 3A to 3C</figref> are flowcharts showing control processing of a storage medium according to the first embodiment;
0053<figref idref="DRAWINGS">FIG. 4</figref> is a functional block diagram showing a configuration of a storage medium control system according to a second embodiment;
0054<figref idref="DRAWINGS">FIGS. 5A to 5C</figref> are flowcharts showing a control processing of a storage medium according to the second embodiment;
0055<figref idref="DRAWINGS">FIGS. 6A and 6B</figref> are flowcharts showing a control processing of a storage medium according to a third embodiment;
0056<figref idref="DRAWINGS">FIG. 7</figref> is a flowchart showing a control processing of a storage medium according to a first modification of the third embodiment;
0057<figref idref="DRAWINGS">FIGS. 8A and 8B</figref> are flowcharts showing a control processing of a storage medium according to a second modification of the third embodiment;
0058<figref idref="DRAWINGS">FIGS. 9A and 9B</figref> are flowcharts showing a control processing of a storage medium according to a fourth embodiment;
0059<figref idref="DRAWINGS">FIGS. 10A and 10B</figref> are flowcharts showing a control processing of a storage medium according to a modification of the fourth embodiment;
0060<figref idref="DRAWINGS">FIGS. 11A and 11B</figref> are flowcharts showing a control processing of a storage medium according to a fifth embodiment;
0061<figref idref="DRAWINGS">FIG. 12</figref> is a flowchart showing a control processing of a storage medium according to a first modification of the fifth embodiment;
0062<figref idref="DRAWINGS">FIG. 13</figref> is a functional block diagram showing a configuration of a storage medium control system according to a second modification of the fifth embodiment;
0063<figref idref="DRAWINGS">FIGS. 14A and 14B</figref> are flowcharts showing a control processing of a storage medium according to the second modification of the fifth embodiment;
0064<figref idref="DRAWINGS">FIGS. 15A and 15B</figref> are flowcharts showing a control processing of a storage medium according to a sixth embodiment;
0065<figref idref="DRAWINGS">FIGS. 16A and 16B</figref> are flowcharts showing a control processing of a storage medium according to a first modification of the sixth embodiment;
0066<figref idref="DRAWINGS">FIG. 17</figref> is a flowchart showing a control processing of a storage medium according to a second modification of the sixth embodiment;
0067<figref idref="DRAWINGS">FIG. 18</figref> is a diagram showing a configuration of a storage medium video and audio reproduction system according to an seventh embodiment; and
0068<figref idref="DRAWINGS">FIG. 19</figref> is a diagram showing a configuration of a storage medium video and audio recording system according to an eighth embodiment.
DESCRIPTION OF THE PREFERRED EMBODIMENTS
First Embodiment
0069A storage medium control system according to a first embodiment of the present invention will be described with reference to drawings.
0070<figref idref="DRAWINGS">FIG. 1</figref> is a diagram showing an aspect of utilization of the storage medium control system.
0071A storage medium control system <b>20</b> is provided with a mobile phone <b>10</b> and a copyright-protection-function-equipped memory card <b>11</b> to be mounted in the mobile phone <b>10</b>.
0072The mobile phone <b>10</b> acquires an encryption key from the memory card <b>11</b> and sets it for the mobile phone <b>10</b>. The mobile phone <b>10</b> acquires contents which have been encrypted (hereinafter referred to as “encrypted contents”) from the memory card <b>11</b>. The mobile phone <b>10</b> decrypts the acquired video contents or audio contents and reproduces the decrypted video contents or audio contents.
0073Alternatively, the mobile phone <b>10</b> encrypts video contents or audio contents delivered from a contents distribution apparatus <b>12</b> via a TV broadcast network <b>13</b>, the Internet <b>14</b>, or a mobile phone network <b>15</b> and records the encrypted contents in the memory card <b>11</b> together with the encryption key.
0074Note that, though the memory card <b>11</b> is assumed to be the storage medium in <figref idref="DRAWINGS">FIG. 1</figref>, the storage medium for realizing the storage medium control system is not limited to a memory card. It may be any other storage medium, such as a Digital Versatile Disk (DVD), a Hard Disk (HD), or a Random Access Memory (RAM).
0075The mobile phone <b>10</b> is assumed to be a storage medium control apparatus which controls the storage medium. However, the storage medium control apparatus for realizing the storage medium control system is not limited to the mobile phone <b>10</b>. It may be any other storage medium control apparatus, such as a TV set, a DVD recorder, or a digital still camera.
0076<figref idref="DRAWINGS">FIG. 2</figref> is a functional block diagram showing a configuration of the storage medium control system <b>20</b>.
0077The storage medium control system <b>20</b> is provided with a storage medium <b>121</b> and a storage medium control apparatus <b>100</b>. The memory card <b>11</b> shown in <figref idref="DRAWINGS">FIG. 1</figref> is an example of the storage medium <b>121</b>, and the mobile phone <b>10</b> is an example of the storage medium control apparatus <b>100</b>.
0078The storage medium <b>121</b> is a medium which stores data and is configured by a normal area <b>123</b>, an authentication area <b>124</b>, and a data sending/receiving control device <b>122</b>.
0079The normal area <b>123</b> is a storage area which can be accessed without performing mutual authentication with the storage medium control apparatus <b>100</b>, and it is a storage area for storing data including unencrypted plain text contents <b>125</b> and encrypted contents <b>126</b>.
0080The authentication area <b>124</b> is a storage area which can be accessed after mutual authentication is performed with the storage medium control apparatus <b>100</b>, and it includes a right information storage area <b>127</b> inside it. The right information storage area <b>127</b> is a storage area for storing right information about the encrypted contents <b>126</b> stored in the normal area <b>123</b>.
0081The data sending/receiving control device <b>122</b> is a processing unit which performs input/output control of the data stored in the normal area <b>123</b> and the authentication area <b>124</b> on the basis of a data read or write request from the storage medium control apparatus <b>100</b>.
0082The storage medium control apparatus <b>100</b> is an apparatus which reads and writes data to and from the storage medium <b>121</b>, and it is provided with a normal mode unit <b>106</b>, a secure mode unit <b>101</b>, and a data sending/receiving control device <b>108</b>.
0083The storage medium control apparatus <b>100</b> is provided with a common Central Processing Unit (CPU), a memory, and the like, and it realizes the normal mode unit <b>106</b> and the secure mode unit <b>101</b> described above by executing a program stored in the memory.
0084The data sending/receiving control device <b>108</b> is configured by hardware.
0085Note that, since other components are not directly related to the present invention, they are not shown, and a description thereof is omitted.
0086The data sending/receiving control device <b>108</b> is provided with a normal resource <b>110</b> and a secure resource <b>109</b>.
0087The normal resource <b>110</b> is a processing unit for reading data from the storage medium <b>121</b> and writing data to the storage medium <b>121</b>.
0088The secure resource <b>109</b> is a processing unit which performs the mutual authentication with the storage medium <b>121</b> using data specified by the normal resource <b>110</b>. The secure resource <b>109</b> also decrypts the encrypted contents <b>126</b> read from the normal area <b>123</b>. Furthermore, the secure resource <b>109</b> encrypts unencrypted contents which are used within the storage medium control apparatus <b>100</b>.
0089The normal mode unit <b>106</b> is a processing unit realized by executing a general-purpose Operating System (OS) represented by Linux® on the CPU, and it is provided with a normal mode switching control unit <b>107</b>.
0090The normal mode switching control unit <b>107</b> is a software module which performs a processing for switching between a normal mode and a secure mode, and it sends and receives data between the normal mode unit <b>106</b> and the secure mode unit <b>101</b>.
0091Here, the “normal mode” refers to a mode in which the secure resource <b>109</b> cannot be accessed and in which only the normal resource <b>110</b> can be accessed.
0092The “secure mode” refers to a mode in which the secure resource <b>109</b> can be accessed. Note that, in the “secure mode” in the present embodiment, it is also possible to access the normal resource <b>110</b>.
0093The secure mode unit <b>101</b> is a processing unit realized by executing a secure OS on the CPU, and it is provided with an encryption control unit <b>105</b>, a storage medium control unit <b>104</b>, a storage medium processing unit <b>103</b>, and a secure mode switching control unit <b>102</b>.
0094The encryption control unit <b>105</b> is a software module which controls the secure resource <b>109</b> to execute a mutual authentication processing between the storage medium <b>121</b> and the storage medium control apparatus <b>100</b>, and to perform encryption and decryption of contents.
0095The storage medium control unit <b>104</b> is a software module which controls data writing to and data reading from the normal area <b>123</b> and the authentication area <b>124</b> inside the storage medium <b>121</b> via the normal resource <b>110</b>, and controls the encryption control unit <b>105</b>.
0096The storage medium processing unit <b>103</b> is a software module which performs access to the storage medium <b>121</b>, mutual authentication between the storage medium <b>121</b> and the storage medium control apparatus <b>100</b>, and encryption and decryption of contents data, via the storage medium control unit <b>104</b> and the encryption control unit <b>105</b>.
0097The secure mode switching control unit <b>102</b> is a software module which switches between the normal mode and the secure mode, and sends and receives the data between the normal mode unit <b>106</b> and the secure mode unit <b>101</b>.
0098Next, a control processing of the storage medium <b>121</b> from the secure mode unit <b>101</b> will be described.
0099<figref idref="DRAWINGS">FIGS. 3A to 3C</figref> are flowcharts showing the control processing of the storage medium <b>121</b> from the secure mode unit <b>101</b>.
0100As the scenes where it is assumed that the above processing is performed, various scenes are assumed, such as a case of inserting the memory card <b>11</b> into the mobile phone <b>10</b> to reproduce encrypted contents recorded in the memory card <b>11</b> and a case of inserting the memory card <b>11</b> into the mobile phone <b>10</b> to record the encrypted contents in the memory card <b>11</b>. Note that timing of executing the above processing depends on the storage medium control apparatus <b>100</b> such as the mobile phone <b>10</b>, and the processing may be executed at any timing.
0101When a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>100</b> (S<b>2</b>: YES), the normal mode switching control unit <b>107</b> sends a command to the secure mode switching control unit <b>102</b> to switch from the normal mode to the secure mode (S<b>4</b>). When a request to access the storage medium <b>121</b> is not issued (S<b>2</b>: NO), the processing normally ends.
0102When the secure mode switching control unit <b>102</b> receives the command from the normal mode switching control unit <b>107</b>, it is assumed that the transition from the normal mode to the secure mode has succeeded (S<b>6</b>: YES). When the secure mode switching control unit <b>102</b> cannot receive the command from the normal mode switching control unit <b>107</b>, it is assumed that the transition to the secure mode has failed (S<b>6</b>: NO), and the storage medium control apparatus <b>100</b> abnormally ends.
0103When transition to the secure mode has succeeded (S<b>6</b>: YES), the secure mode switching control unit <b>102</b> performs a processing on the basis of the command received from the normal mode switching control unit <b>107</b>.
0104When the received command is a command to access the normal area <b>123</b> of the storage medium <b>121</b> (S<b>8</b>: YES), the secure mode switching control unit <b>102</b> sends, to the storage medium processing unit <b>103</b>, a command to request access to the normal area <b>123</b> (S<b>10</b>).
0105After confirming that the received command is a command to request the access to the normal area <b>123</b>, the storage medium processing unit <b>103</b> sends, to the storage medium control unit <b>104</b>, the command to request the access to the normal area <b>123</b> (S<b>10</b>). After confirming that the received command is a command to access the normal area <b>123</b>, the storage medium control unit <b>104</b> controls the normal resource <b>110</b> of the data sending/receiving control device <b>108</b> to send, to the storage medium <b>121</b> via a data bus <b>128</b>, the command to access the normal area <b>123</b> (S<b>10</b>).
0106After the data sending/receiving control device <b>122</b> receives the access command sent from the normal resource <b>110</b>, and the storage medium <b>121</b> confirms that the received access command is a command to access the normal area <b>123</b>, the storage medium <b>121</b> accesses the normal area <b>123</b> and sends the access result to the normal resource <b>110</b> via the data sending/receiving control device <b>122</b> and the data bus <b>128</b>.
0107The normal resource <b>110</b> receives the access result from the data sending/receiving control device <b>122</b> (S<b>12</b>). The normal resource <b>110</b> which has received the access result notifies the storage medium control unit <b>104</b> that the access to the normal area <b>123</b> has completed and it has received the access result (S<b>14</b>).
0108When the result of the access to the normal area <b>123</b> received from the normal resource <b>110</b> by the storage medium control unit <b>104</b> indicates success (S<b>16</b>: YES), the processing proceeds to S<b>18</b>. When the result of the access to the normal area <b>123</b> received from the normal resource <b>110</b> indicates failure (S<b>16</b>: NO), the storage medium control apparatus <b>100</b> abnormally ends.
0109When the data of the normal area <b>123</b> read at S<b>12</b> is the encrypted contents <b>126</b> (S<b>18</b>: YES), the storage medium processing unit <b>103</b> sends, to the storage medium control unit <b>104</b>, a command to read an encryption key for encrypting the read data of the normal area <b>123</b>, which is stored in the authentication area <b>124</b>. The storage medium control unit <b>104</b> controls the normal resource <b>110</b> to send, to the storage medium <b>121</b>, the command to read the encryption key from the authentication area <b>124</b> (S<b>20</b>).
0110After confirming that the command received by the data sending/receiving control device <b>122</b> is a command to read encryption key data from the authentication area <b>124</b>, the storage medium <b>121</b> reads the encryption key from the authentication area <b>124</b> and sends the encryption key to the normal resource <b>110</b> via the data bus <b>128</b> (S<b>20</b>).
0111The normal resource <b>110</b> sends the received encryption key to the storage medium control unit <b>104</b>, and the storage medium control unit <b>104</b> sends the received encryption key to the storage medium processing unit <b>103</b> (S<b>20</b>).
0112The storage medium processing unit <b>103</b> sends the encryption key received from the storage medium control unit <b>104</b> to the encryption control unit <b>105</b> (S<b>20</b>).
0113The encryption control unit <b>105</b> sets the received encryption key for the secure resource <b>109</b>, and notifies a setting completion notification to the encryption control unit <b>105</b> (S<b>20</b>). The encryption control unit <b>105</b> notifies the setting completion notification to the storage medium processing unit <b>103</b> (S<b>20</b>).
0114The storage medium processing unit <b>103</b> which has received the setting completion notification from the encryption control unit <b>105</b> sends the encrypted contents <b>126</b> which have been read to the encryption control unit <b>105</b> and notifies a command to decrypt the data to the encryption control unit <b>105</b> (S<b>22</b>).
0115When the received command is a command to decrypt the data, and an encryption key corresponding to the encrypted contents <b>126</b> received in advance is set for the secure resource <b>109</b>, the encryption control unit <b>105</b> sends the received encrypted contents <b>126</b> and the command to decrypt the data to the secure resource <b>109</b> (S<b>22</b>).
0116When the received command is a command to decrypt the data, the secure resource <b>109</b> decrypts the received encrypted contents <b>126</b> with the previously set encryption key corresponding to the encrypted data of the normal area <b>123</b> (S<b>22</b>).
0117When the decryption completes and succeeds, the secure resource <b>109</b> sends the decrypted encrypted contents <b>126</b> to the encryption control unit <b>105</b>, and the encryption control unit <b>105</b> sends them to the storage medium processing unit <b>103</b> (S<b>22</b>). When the decryption fails, the secure resource <b>109</b> sends the decryption failure result to the encryption control unit <b>105</b>, and the encryption control unit <b>105</b> sends it to the storage medium processing unit <b>103</b> (S<b>22</b>).
0118When receiving the decryption failure result from the encryption control unit <b>105</b> (S<b>24</b>: NO), the storage medium processing unit <b>103</b> proceeds to an abnormality processing.
0119When receiving the decrypted encrypted contents <b>126</b> from the encryption control unit <b>105</b> (S<b>24</b>: YES), the storage medium processing unit <b>103</b> proceeds to S<b>26</b>.
0120When the data of the normal area <b>123</b> read at S<b>12</b> is unencrypted plain text contents <b>125</b> (S<b>18</b>: NO), the storage medium processing unit <b>103</b> proceeds to S<b>26</b>.
0121The storage medium processing unit <b>103</b> performs various processings for the plain text contents <b>125</b> read at S<b>12</b>, the decrypted encrypted contents <b>126</b>, and the data of the normal area <b>123</b> (S<b>26</b>). After completion of the processings, the storage medium processing unit <b>103</b> proceeds to S<b>28</b>.
0122When there is any other data of the normal area <b>123</b> to be processed (S<b>28</b>: YES), the storage medium processing unit <b>103</b> proceeds to S<b>10</b>.
0123When there is not any other data of the normal area <b>123</b> to be processed (S<b>28</b>: NO), the storage medium processing unit <b>103</b> proceeds to normal end.
0124When the command received from the normal mode switching control unit <b>107</b> is a command to access the authentication area <b>124</b> of the storage medium <b>121</b> (S<b>8</b>: NO; S<b>30</b>: YES), the secure mode switching control unit <b>102</b> sends, to the storage medium processing unit <b>103</b>, a command to request the access to the authentication area <b>124</b> (S<b>32</b>).
0125After confirming that the received command is a command to access the authentication area <b>124</b>, the storage medium processing unit <b>103</b> sends, to the storage medium control unit <b>104</b>, a command to acquire data for performing the mutual authentication with the storage medium <b>121</b> (S<b>34</b>).
0126After confirming that the received command is a command to acquire the data for the mutual authentication, the storage medium control unit <b>104</b> controls the normal resource <b>110</b> to send the data-for-mutual-authentication acquisition command to the storage medium <b>121</b> via the data bus <b>128</b> (S<b>34</b>).
0127When the received command is a data-for-mutual-authentication acquisition command, the storage medium <b>121</b> sends the result of the data-for-mutual-authentication acquisition command (the data for the mutual authentication acquired on the basis of the data-for-mutual-authentication acquisition command) to the normal resource <b>110</b>.
0128The normal resource <b>110</b> receives the result of the data-for-mutual-authentication acquisition command from the storage medium <b>121</b> (S<b>36</b>). Furthermore, the normal resource <b>110</b> notifies the result of the data-for-mutual-authentication acquisition command received from the storage medium <b>121</b> to the storage medium control unit <b>104</b>, and the storage medium control unit <b>104</b> notifies the received result to the storage medium processing unit <b>103</b> (S<b>36</b>).
0129When the received result of the data-for-mutual-authentication acquisition command indicates abnormality (S<b>38</b>: NO), the storage medium processing unit <b>103</b> proceeds to the abnormality processing.
0130When the received result of the data-for-mutual-authentication acquisition command indicates normality (S<b>38</b>: YES), the storage medium processing unit <b>103</b> sends, to the encryption control unit <b>105</b>, a part of the received result of the data-for-mutual-authentication acquisition command required for mutual authentication or all of the received result of the data-for-mutual-authentication acquisition command together with a mutual authentication command (S<b>40</b>).
0131After confirming that the received command is a mutual authentication command, the encryption control unit <b>105</b> sends a part or all of the received data for mutual authentication and the mutual authentication command to the secure resource <b>109</b> (S<b>40</b>).
0132After confirming that the secure resource <b>109</b> has received the mutual authentication command and a part or all of the data for mutual authentication, it executes a mutual authentication processing and returns the result of the mutual authentication processing to the encryption control unit <b>105</b> (S<b>42</b>).
0133The encryption control unit <b>105</b> notifies the result of the mutual authentication processing to the storage medium processing unit <b>103</b>. When the received result of the mutual authentication processing indicates abnormality (S<b>44</b>; NO), the storage medium processing unit <b>103</b> proceeds to the abnormality processing.
0134When the received result of the mutual authentication processing indicates normality (S<b>44</b>: YES), the storage medium processing unit <b>103</b> sends, to the storage medium control unit <b>104</b>, a command to request access to the authentication area <b>124</b>. After confirming that the received command is a command to access the authentication area <b>124</b>, the storage medium control unit <b>104</b> controls the normal resource <b>110</b> of the data sending/receiving control device <b>108</b> to send, to the storage medium <b>121</b> via the data bus <b>128</b>, the command to access the authentication area <b>124</b> (S<b>46</b>).
0135The storage medium <b>121</b> receives the access command sent from the normal resource <b>110</b> by the data sending/receiving control device <b>122</b>. After confirming that the received access command is a command to access the authentication area <b>124</b>, the storage medium <b>121</b> accesses the authentication area <b>124</b> and sends the access result to the normal resource <b>110</b> via the data sending/receiving control device <b>122</b> and the data bus <b>128</b>.
0136The normal resource <b>110</b> receives the access result from the data sending/receiving control device <b>122</b> (S<b>48</b>). The normal resource <b>110</b> which has received the access result notifies the storage medium control unit <b>104</b> that the access to the authentication area <b>124</b> has completed and that it has received the access result (S<b>50</b>).
0137The storage medium control unit <b>104</b> judges whether the access result indicates success or failure. When the result of accessing the authentication area <b>124</b>, which has been received from the normal resource <b>110</b>, indicates success (S<b>52</b>: YES), the processing proceeds to S<b>54</b>. When the result of accessing the authentication area <b>124</b>, which has been received from the normal resource <b>110</b>, indicates failure (S<b>52</b>: NO), the storage medium control apparatus <b>100</b> abnormally ends.
0138When the data of the authentication area <b>124</b> read at S<b>48</b> is encrypted (S<b>54</b>: YES), the storage medium processing unit <b>103</b> sends the read data of the authentication area <b>124</b> to the encryption control unit <b>105</b> and requests a decryption processing (S<b>56</b>).
0139The encryption control unit <b>105</b> sends the received data of the authentication area <b>124</b> to the secure resource <b>109</b> and controls the secure resource <b>109</b> to decrypt the received data of the authentication area <b>124</b> (S<b>56</b>).
0140The encryption control unit <b>105</b> controls the secure resource <b>109</b> to send the decrypted data of the authentication area <b>124</b> to the storage medium processing unit <b>103</b> (S<b>56</b>). The encryption control unit <b>105</b> controls the secure resource <b>109</b> to send a decryption failure result to the storage medium processing unit <b>103</b> when the decryption of the data of the authentication area <b>124</b> fails (S<b>56</b>).
0141When receiving the decrypted data of the authentication area <b>124</b> (S<b>58</b>: YES), the storage medium processing unit <b>103</b> proceeds to S<b>60</b>.
0142When receiving the decryption failure result from the encryption control unit <b>105</b> (S<b>58</b>: NO), the storage medium processing unit <b>103</b> proceeds to the abnormality processing.
0143When the data of the authentication area <b>124</b> read at S<b>48</b> is the unencrypted plain text contents <b>125</b> (S<b>54</b>: NO), the storage medium processing unit <b>103</b> proceeds to S<b>60</b>.
0144The storage medium processing unit <b>103</b> performs various processings for the plain text contents <b>125</b> read at S<b>48</b>, the decrypted encrypted contents <b>126</b>, and the data of the authentication area <b>124</b> (S<b>60</b>). After completion of the processings, the storage medium processing unit <b>103</b> proceeds to S<b>62</b>.
0145When there is any other data of the authentication area <b>124</b> to be processed (S<b>62</b>: YES), the storage medium processing unit <b>103</b> proceeds to S<b>46</b>.
0146When there is not any other data of the authentication area <b>124</b> to be processed (S<b>62</b>: NO), the storage medium processing unit <b>103</b> proceeds to the normal end.
0147As described above, according to the present embodiment, it is possible to directly access the normal resource <b>110</b> from the secure mode unit <b>101</b> even in the secure mode. Therefore, it is not necessary to perform the switching to the normal mode when accessing the data stored in the storage medium <b>121</b> in the secure mode. Accordingly, it is possible to reduce the number of times of switching between the secure mode and the normal mode. Furthermore, it is possible to perform the processing without the normal mode unit <b>106</b> handling the copyright protection information (the right information). Accordingly, it is possible to improve the processing performance while protecting the copyright protection information (the right information) in the security mode.
Second Embodiment
0148A storage medium control system according to a second embodiment of the present invention will be described with reference to drawings.
0149An aspect of utilization of the storage medium control system is similar to what is shown in <figref idref="DRAWINGS">FIG. 1</figref>. The aspect of utilization of the storage medium control system according to a third embodiment and subsequent embodiments is also similar.
0150<figref idref="DRAWINGS">FIG. 4</figref> is a functional block diagram showing a configuration of a storage medium control system <b>20</b> according to the second embodiment.
0151The storage medium control system <b>20</b> is provided with a storage medium <b>121</b> and a storage medium control apparatus <b>200</b>.
0152The storage medium <b>121</b> is similar to what is shown in the first embodiment. Therefore, a detailed description thereof is not repeated here.
0153As for the storage medium control apparatus <b>200</b>, a description will be made mainly on differing points from the storage medium control apparatus <b>100</b> according to the first embodiment shown in <figref idref="DRAWINGS">FIG. 2</figref>.
0154The storage medium control apparatus <b>200</b> is an apparatus which reads and writes data to and from the storage medium <b>121</b>, and it is provided with a normal mode unit <b>206</b>, a secure mode unit <b>201</b>, and a data sending/receiving control device <b>210</b>.
0155The storage medium control apparatus <b>200</b> is provided with a common CPU, a memory, and the like, and it realizes the normal mode unit <b>206</b> and the secure mode unit <b>201</b> described above by executing programs stored in the memory.
0156The data sending/receiving control device <b>210</b> is configured by hardware.
0157Note that, since other components are not directly related to the present invention, they are neither illustrated nor described.
0158The secure mode unit <b>201</b> is provided with a secure mode switching control unit <b>202</b>, a storage medium authentication area processing unit <b>203</b>, a storage medium authentication area control unit <b>204</b>, and an encryption control unit <b>205</b>.
0159The normal mode unit <b>206</b> is provided with a normal mode switching control unit <b>207</b>, a storage medium normal area processing unit <b>208</b>, and a storage medium normal area control unit <b>209</b>.
0160The data sending/receiving control device <b>210</b> is provided with a secure resource <b>211</b> and a normal resource <b>212</b>.
0161The storage medium normal area control unit <b>209</b> and the storage medium authentication area control unit <b>204</b> correspond to the storage medium control unit <b>104</b> in the storage medium control apparatus <b>100</b>, and they are software modules which control, via the normal resource <b>212</b>, reading and writing of data to and from the normal area <b>123</b> and the authentication area <b>124</b> inside the storage medium <b>121</b>, and also control the encryption control unit <b>205</b>.
0162The storage medium normal area control unit <b>209</b> is a software module which accesses only the normal area <b>123</b> of the storage medium <b>121</b> via the normal resource <b>212</b>.
0163The storage medium authentication area control unit <b>204</b> is a software module which accesses only the authentication area <b>124</b> of the storage medium <b>121</b> via the normal resource <b>212</b> and the secure resource <b>211</b>.
0164The storage medium normal area processing unit <b>208</b> and the storage medium authentication area processing unit <b>203</b> correspond to the storage medium processing unit <b>103</b> in the storage medium control apparatus <b>100</b>, and they are software modules which perform access to the storage medium <b>121</b>, mutual authentication between the storage medium <b>121</b> and the storage medium control apparatus <b>200</b>, and encryption and decryption of contents data, via the storage medium normal area processing unit <b>208</b>, the storage medium authentication area control unit <b>204</b>, and the encryption control unit <b>205</b>.
0165The storage medium normal area processing unit <b>208</b> is a software module which performs a processing of data of the normal area <b>123</b> of the storage medium <b>121</b> via the storage medium normal area control unit <b>209</b>.
0166The storage medium authentication area processing unit <b>203</b> is a software module which performs a processing of the data of the authentication area <b>124</b> of the storage medium <b>121</b> via the storage medium authentication area control unit <b>204</b>.
0167That is, what differs from the first embodiment is that the storage medium normal area control unit <b>209</b> and the storage medium normal area processing unit <b>208</b> exist in the normal mode unit <b>206</b>, and the storage medium authentication area control unit <b>204</b> and the storage medium authentication area processing unit <b>203</b> exist in the secure mode unit <b>201</b>.
0168Other configuration requirements, that is, the secure mode switching control unit <b>202</b>, the encryption control unit <b>205</b>, the normal mode switching control unit <b>207</b>, the data sending/receiving control device <b>210</b>, the secure resource <b>211</b>, and the normal resource <b>212</b> respectively correspond to the secure mode switching control unit <b>102</b>, the encryption control unit <b>105</b>, the normal mode switching control unit <b>107</b>, the data sending/receiving control device <b>108</b>, the secure resource <b>109</b>, and the normal resource <b>110</b> shown in <figref idref="DRAWINGS">FIG. 2</figref>.
0169Next, a control processing for the storage medium <b>121</b> performed by both the secure mode unit <b>201</b> and the normal mode unit <b>206</b> will be described.
0170<figref idref="DRAWINGS">FIGS. 5A to 5C</figref> are flowcharts showing the control processing for the storage medium <b>121</b> performed by both the secure mode unit <b>201</b> and the normal mode unit <b>206</b>. What differs from the first embodiment is that a processing load in the secure mode is reduced by performing only a processing for accessing the authentication area <b>124</b> of the storage medium <b>121</b>, an encryption processing, and a decryption processing in the secure mode.
0171As the scenes where it is assumed that the above processing is performed, various scenes are assumed, such as a case of inserting the memory card <b>11</b> into the mobile phone <b>10</b> to reproduce encrypted contents recorded in the memory card <b>11</b> and a case of inserting the memory card <b>11</b> into the mobile phone <b>10</b> to record the encrypted contents in the memory card <b>11</b>. Note that the timing of performing the above processing depends on the storage medium control apparatus <b>100</b> such as the mobile phone <b>10</b>, and the processing may be performed at any timing.
0172When a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b> (S<b>102</b>: YES), and it can be confirmed that access to the authentication area of the storage medium <b>121</b> has occurred (S<b>104</b>: YES), the normal mode switching control unit <b>207</b> sends a command to the secure mode switching control unit <b>202</b> to switch from the normal mode to the secure mode (S<b>106</b>). When the request to access the authentication area of the storage medium <b>121</b> has not been issued (S<b>104</b>: NO), the processing proceeds to S<b>148</b>.
0173When the secure mode switching control unit <b>202</b> receives the command from the normal mode switching control unit <b>207</b>, it is assumed that the transition from the normal mode to the secure mode has succeeded (S<b>108</b>: YES). When the secure mode switching control unit <b>202</b> of the secure mode unit <b>201</b> cannot receive the command from the normal mode switching control unit <b>207</b> of the normal mode unit <b>206</b>, it is assumed that the transition to the secure mode has failed (S<b>108</b>: NO), and the storage medium control apparatus <b>200</b> abnormally ends.
0174The secure mode switching control unit <b>202</b> performs processing on the basis of the command received from the normal mode switching control unit <b>207</b>. However, when the received command is a command to access the authentication area <b>124</b> of the storage medium <b>121</b>, the secure mode switching control unit <b>202</b> sends, to the storage medium authentication area processing unit <b>203</b>, a command to request the access to the authentication area <b>124</b> (S<b>112</b>).
0175After confirming that the received command is a command to access the authentication area <b>124</b>, the storage medium authentication area processing unit <b>203</b> sends, to the storage medium authentication area control unit <b>204</b>, a command to acquire data for performing the mutual authentication with the storage medium <b>121</b> (S<b>114</b>).
0176After confirming that the received command is a data-for-mutual-authentication acquisition command, the storage medium authentication area control unit <b>204</b> controls the normal resource <b>212</b> to send the data-for-mutual-authentication acquisition command to the storage medium <b>121</b> via the data bus <b>128</b> (S<b>114</b>).
0177When the received command is a data-for-mutual-authentication acquisition command, the storage medium <b>121</b> sends the result of the data-for-mutual-authentication acquisition command to the normal resource <b>212</b>.
0178The normal resource <b>212</b> notifies the result of the data-for-mutual-authentication acquisition command received from the storage medium <b>121</b> to the storage medium authentication area control unit <b>204</b> (S<b>116</b>), and the storage medium authentication area control unit <b>204</b> notifies it to the storage medium authentication area processing unit <b>203</b> (S<b>116</b>).
0179When the received result of the data-for-mutual-authentication acquisition command indicates abnormality (S<b>118</b>: NO), the storage medium authentication area processing unit <b>203</b> proceeds to an abnormality processing.
0180When the result of the received data-for-mutual-authentication acquisition command indicates normality (S<b>118</b>: YES), the storage medium authentication area processing unit <b>203</b> sends, to the encryption control unit <b>205</b>, a part of the received result of the data-for-mutual-authentication acquisition command required for mutual authentication or all of the received result of the data-for-mutual-authentication acquisition command together with the mutual authentication command (S<b>120</b>).
0181After confirming that the received command is a mutual authentication command, the encryption control unit <b>205</b> sends a part or all of the received data for mutual authentication and the mutual authentication command to the secure resource <b>211</b> (S<b>120</b>).
0182After confirming that the secure resource <b>211</b> has received the mutual authentication command and a part or all of the data for mutual authentication, it executes a mutual authentication processing and returns the result of the mutual authentication processing to the encryption control unit <b>205</b> (S<b>122</b>).
0183The encryption control unit <b>205</b> notifies the result of the mutual authentication processing to the storage medium authentication area processing unit <b>203</b>. When the received result of the mutual authentication processing indicates abnormality (S<b>124</b>: NO), the storage medium authentication area processing unit <b>203</b> proceeds to the abnormality processing.
0184When the received result of the mutual authentication processing indicates normality (S<b>124</b>: YES), the storage medium authentication area processing unit <b>203</b> sends, to the storage medium authentication area control unit <b>204</b>, a command to request access to the authentication area <b>124</b> (S<b>126</b>). After confirming that the received command is a command to access the authentication area <b>124</b>, the storage medium authentication area control unit <b>204</b> controls the normal resource <b>212</b> of the data sending/receiving control device <b>210</b> to send, to the storage medium <b>121</b> via the data bus <b>128</b>, a command to access the authentication area <b>124</b> (S<b>126</b>).
0185The storage medium <b>121</b> receives the access command sent from the normal resource <b>212</b> by the data sending/receiving control device <b>122</b>. After confirming that the received access command is a command to access the authentication area <b>124</b>, the storage medium <b>121</b> accesses the authentication area <b>124</b> and sends the access result to the normal resource <b>212</b> via the data sending/receiving control device <b>122</b> and the data bus <b>128</b> (S<b>128</b>).
0186The normal resource <b>212</b> which has received the access result from the normal resource <b>212</b> notifies the storage medium authentication area control unit <b>204</b> that the access to the authentication area <b>124</b> has completed and that it has received the access result (S<b>130</b>).
0187When the result of the access to the authentication area <b>124</b> received from the normal resource <b>212</b> indicates success (S<b>132</b>: YES), the storage medium authentication area control unit <b>204</b> proceeds to S<b>134</b>. When the result of the access to the authentication area <b>124</b> received from the normal resource <b>212</b> indicates failure (S<b>132</b>: NO), the storage medium control apparatus <b>200</b> abnormally ends.
0188When the data of the authentication area <b>124</b> read at S<b>128</b> is encrypted (S<b>134</b>: YES), the storage medium authentication area processing unit <b>203</b> sends, to the storage medium authentication area control unit <b>204</b>, a command to read an encryption key stored in the authentication area <b>124</b> (S<b>136</b>).
0189The storage medium authentication area control unit <b>204</b> controls the normal resource <b>212</b> to send, to the storage medium <b>121</b>, the command to read an encryption key from the authentication area <b>124</b> (S<b>136</b>).
0190After confirming that the command received by the data sending/receiving control device <b>122</b> is a command to read encryption key data from the authentication area <b>124</b>, the storage medium <b>121</b> reads the encryption key from the authentication area <b>124</b> and sends the encryption key to the normal resource <b>212</b> via the data bus <b>128</b> (S<b>136</b>).
0191The normal resource <b>212</b> sends the received encryption key to the storage medium authentication area control unit <b>204</b>, and the storage medium authentication area control unit <b>204</b> sends the received encryption key to the storage medium authentication area processing unit <b>203</b> (S<b>136</b>).
0192The storage medium authentication area processing unit <b>203</b> sends the encryption key received from the storage medium authentication area control unit <b>204</b> to the encryption control unit <b>205</b> (S<b>136</b>).
0193The encryption control unit <b>205</b> sets the received encryption key for the secure resource <b>211</b>, and notifies a setting completion notification to the encryption control unit <b>205</b>. The encryption control unit <b>205</b> notifies the setting completion notification to the storage medium authentication area processing unit <b>203</b> (S<b>136</b>).
0194The storage medium authentication area processing unit <b>203</b> sends the read data of the authentication area <b>124</b> to the encryption control unit <b>205</b> and requests the decryption processing (S<b>138</b>).
0195The encryption control unit <b>205</b> sends the received data of the authentication area <b>124</b> to the secure resource <b>211</b>, and controls the secure resource <b>211</b> to decrypt the received data of the authentication area <b>124</b> (S<b>138</b>).
0196The encryption control unit <b>205</b> controls the secure resource <b>211</b> to send the decrypted data of the authentication area <b>124</b> to the storage medium authentication area processing unit <b>203</b> (S<b>138</b>). The encryption control unit <b>205</b> controls the secure resource <b>211</b> to send a decryption failure result to the storage medium authentication area processing unit <b>203</b> when the decryption of the data of the authentication area <b>124</b> failed (S<b>140</b>: NO).
0197When receiving the decryption failure result from the encryption control unit <b>205</b> (S<b>140</b>: NO), the storage medium authentication area processing unit <b>203</b> proceeds to the abnormality processing.
0198When receiving the decrypted data of the authentication area <b>124</b> (S<b>140</b>: YES), the storage medium authentication area processing unit <b>203</b> proceeds to S<b>142</b>.
0199The storage medium authentication area processing unit <b>203</b> performs various processings for the read plain text contents <b>125</b>, the decrypted encrypted contents <b>126</b>, and the data of the authentication area <b>124</b> (S<b>142</b>).
0200When there is any other data of the authentication area <b>124</b> to be processed (S<b>144</b>: YES), the storage medium authentication area processing unit <b>203</b> proceeds to S<b>10</b>.
0201When there is not any other data of the authentication area <b>124</b> to be processed (S<b>144</b>: NO), the storage medium authentication area processing unit <b>203</b> proceeds to S<b>146</b>.
0202When the normal area <b>123</b> of the storage medium <b>121</b> is not accessed (S<b>146</b>: NO), the storage medium control apparatus <b>200</b> normally ends.
0203When the normal area <b>123</b> of the storage medium <b>121</b> is accessed (S<b>146</b>: YES), the secure mode switching control unit <b>202</b> sends a command to the normal mode switching control unit <b>207</b> to switch to the normal mode (S<b>148</b>). When the normal mode switching control unit <b>207</b> receives the command from the secure mode switching control unit <b>202</b>, a return from the secure mode unit <b>201</b> to the normal mode unit <b>206</b> is successful (S<b>150</b>: YES).
0204When the normal mode switching control unit <b>207</b> cannot receive the command from the secure mode switching control unit <b>202</b>, it is assumed that the return to the normal mode failed (S<b>150</b>: NO), and the storage medium control apparatus <b>200</b> abnormally ends.
0205After confirming that the received command is a command to access the normal area <b>123</b>, the storage medium normal area processing unit <b>208</b> sends, to the storage medium normal area control unit <b>209</b>, a command to request the access to the normal area <b>123</b> (S<b>152</b>). After confirming that the received command is a command to access the normal area <b>123</b>, the storage medium normal area control unit <b>209</b> controls the normal resource <b>212</b> of the data sending/receiving control device <b>210</b> to send, to the storage medium <b>121</b> via a data bus <b>128</b>, a command to access the normal area <b>123</b> (S<b>152</b>).
0206The storage medium <b>121</b> receives the access command sent from the normal resource <b>212</b> by the data sending/receiving control device <b>122</b>. After confirming that the received access command is a command to access the normal area <b>123</b>, the storage medium <b>121</b> accesses the normal area <b>123</b> and sends the access result to the normal resource <b>212</b> via the data sending/receiving control device <b>122</b> and the data bus <b>128</b>.
0207The normal resource <b>212</b> receives the access result from the data sending/receiving control device <b>122</b> (S<b>154</b>). The normal resource <b>212</b> which has received the access result notifies the storage medium normal area control unit <b>209</b> that the access to the normal area <b>123</b> has completed and it has received the access result (S<b>156</b>).
0208When the result of the access to the normal area <b>123</b> received by the storage medium control unit <b>209</b> from the normal resource <b>212</b> indicates success (S<b>158</b>: YES), the processing proceeds to S<b>160</b>. When the result of the access to the normal area <b>123</b> received from the normal resource <b>212</b> indicates failure (S<b>158</b>: NO), the storage medium control apparatus <b>200</b> abnormally ends.
0209When the decryption processing of the encrypted contents <b>126</b> stored in the normal area is performed by the storage medium normal area processing unit <b>208</b>, and an encryption key corresponding to the encrypted contents <b>126</b> is set for the secure resource <b>211</b> in advance in the secure mode (S<b>160</b>: YES), the received encrypted contents <b>126</b> and a command to decrypt the data are sent to the normal resource <b>212</b> (S<b>162</b>).
0210When the received command is a command to decrypt the data, the normal resource <b>212</b> decrypts the received encrypted contents <b>126</b> with the encryption key corresponding to the encrypted data of the normal area <b>123</b>, which has been set in advance, via the secure resource <b>211</b> (S<b>162</b>). However, though the decryption processing is actually performed by the secure resource <b>211</b>, the processing for setting for the secure resource <b>211</b> is not performed. Therefore, it is possible to perform the processing by the normal mode unit <b>206</b>.
0211After the decryption is successfully completed, the normal resource <b>212</b> sends the decrypted encrypted contents <b>126</b> to the storage medium normal area control unit <b>209</b>, and the storage medium normal area control unit <b>209</b> sends them to the storage medium normal area processing unit <b>208</b> (S<b>162</b>). When the decryption fails, the normal resource <b>212</b> sends the decryption failure result to the storage medium normal area control unit <b>209</b>, and the storage medium normal area control unit <b>209</b> sends the received decryption failure result to the storage medium normal area processing unit <b>208</b> (S<b>162</b>).
0212When receiving the decryption failure result from the storage medium normal area control unit <b>209</b> (S<b>164</b>: NO), the storage medium normal area processing unit <b>208</b> proceeds to the abnormality processing.
0213When receiving the decrypted encrypted contents <b>126</b> from the storage medium normal area control unit <b>209</b> (S<b>164</b>: YES), the storage medium normal area processing unit <b>208</b> proceeds to S<b>166</b>.
0214The storage medium authentication area processing unit <b>203</b> performs various processings for the read plain text contents <b>125</b>, the decrypted encrypted contents <b>126</b>, and the data of the normal area <b>123</b> (S<b>166</b>).
0215When there is any other data of the normal area <b>123</b> to be processed (S<b>168</b>: YES), the storage medium normal area processing unit <b>208</b> proceeds to S<b>152</b>.
0216When there is not any other data of the normal area <b>123</b> to be processed (S<b>168</b>: NO), the storage medium normal area processing unit <b>208</b> proceeds to normal end.
0217As described above, according to the present embodiment, it is possible to directly access the normal resource <b>212</b> from the secure mode unit <b>201</b>, similarly to the first embodiment. Therefore, it is not necessary to perform the switching to the normal mode when accessing the data stored in the storage medium <b>121</b> in the secure mode. Accordingly, it is possible to reduce the number of times of switching between the secure mode and the normal mode.
0218Furthermore, it is possible to easily add the secure mode unit <b>201</b> and the data sending/receiving control device <b>210</b> while avoiding a modification of the software modules of the normal mode unit <b>206</b> configured by an existing general-purpose OS as much as possible. Therefore, it is possible to easily add a function of accessing the authentication area <b>124</b> of the storage medium <b>121</b> to an existing storage medium control system which accesses the normal area <b>123</b> of the storage medium <b>121</b>.
Third Embodiment
0219A storage medium control system according to a third embodiment of the present invention will be described with reference to drawings.
0220A configuration of the storage medium control system according to the third embodiment is similar to that of the storage medium control system according to the second embodiment shown in <figref idref="DRAWINGS">FIG. 4</figref>. Therefore, a detailed description thereof is not repeated here.
0221Next, a control processing for a storage medium <b>121</b> performed by both a secure mode unit <b>201</b> and a normal mode unit <b>206</b> will be described.
0222<figref idref="DRAWINGS">FIGS. 6A</figref>, <b>6</b>B and <b>5</b>C are flowcharts showing the control processing for the storage medium <b>121</b> performed by both the secure mode unit <b>201</b> and the normal mode unit <b>206</b>.
0223Though the basic processing is similar to that of the second embodiment, a storage medium authentication area control unit <b>204</b> acquires storage medium information to be described later, in order to keep the consistency between access to an authentication area <b>124</b> from the secure mode unit <b>201</b> and access to an normal area <b>123</b> from the normal mode unit <b>206</b>. The present embodiment also differs from the second embodiment in that the storage medium <b>121</b> is accessed on the basis of the storage medium information.
0224Hereinafter, a description will be made mainly on the different processings.
0225In the present embodiment, it is assumed that a shared memory (not shown) which is shared by the secure mode unit <b>201</b> and the normal mode unit <b>206</b> is provided in the storage medium control apparatus <b>200</b>. The storage medium information acquired by the storage medium authentication area control unit <b>204</b> is stored in the shared memory and shared by the secure mode unit <b>201</b> and the normal mode unit <b>206</b>.
0226With reference to <figref idref="DRAWINGS">FIG. 6A</figref>, when a request to access the storage medium <b>121</b> is issued by a storage medium control apparatus <b>200</b> (S<b>102</b>: YES), a storage medium normal area processing unit <b>208</b> confirms whether an initialization processing of the storage medium <b>121</b> has succeeded (S<b>202</b>) before it is confirmed at S<b>104</b> to be executed later whether access to the authentication area <b>124</b> of the storage medium <b>121</b> has occurred.
0227When the initialization processing has not succeeded (S<b>202</b>: NO), the storage medium normal area processing unit <b>208</b> sends a request to initialize the storage medium <b>121</b> to a storage medium normal area control unit <b>209</b>. On the basis of the initialization request, the storage medium normal area control unit <b>209</b> acquires “storage medium information” such as address information, area size, and access size about the storage medium <b>121</b>, notifies the information to the storage medium normal area processing unit <b>208</b> (S<b>203</b>), and proceeds to S<b>204</b>.
0228When the initialization processing has already succeeded (S<b>202</b>: YES) or after S<b>203</b> is executed, the acquired storage medium information is stored at a particular address of the shared memory which can be commonly accessed by the normal mode unit <b>206</b> and the secure mode unit <b>201</b> (S<b>204</b>).
0229With reference to <figref idref="DRAWINGS">FIG. 6B</figref>, when access to the authentication area <b>124</b> of the storage medium <b>121</b> occurs after that (S<b>104</b>: YES) and success of transition to the secure mode is confirmed (S<b>108</b>: YES), the storage medium authentication area control unit <b>204</b> acquires the storage medium information from the shared memory on the basis of the address information about the shared memory handed from the storage medium authentication area processing unit <b>203</b>, and internally holds the storage medium information (S<b>207</b>). After that, the storage medium information held by the storage medium authentication area control unit <b>204</b> is used when data is sent to or received from the storage medium <b>121</b>.
0230As described above, according to the present embodiment, the storage medium information is designed to be stored in the shared memory which can be accessed by both the secure mode unit <b>201</b> and the normal mode unit <b>206</b>, in addition to the advantages of the embodiments described above. Therefore, the initialization processing for a storage medium may be performed only in any one of the normal mode and the secure mode.
(First Modification)
0231In the storage medium control system according to the third embodiment, the storage medium authentication area control unit <b>204</b> of the secure mode unit <b>201</b> may independently acquire the storage medium information without using the shared memory.
0232That is, the storage medium control system according to the third embodiment may perform the processings shown in <figref idref="DRAWINGS">FIGS. 5A</figref>, <b>7</b> and <b>5</b>C instead of the processings shown in <figref idref="DRAWINGS">FIGS. 6A</figref>, <b>6</b>B and <b>5</b>C.
0233With reference to <figref idref="DRAWINGS">FIG. 7</figref>, when success of transition to the secure mode is confirmed at S<b>108</b> (S<b>108</b>: YES), the storage medium authentication area control unit <b>204</b> initializes the storage medium <b>121</b>, acquires and holds the storage medium information, on the basis of an instruction from the storage medium authentication area processing unit <b>203</b> (S<b>304</b>), irrespective of whether or not the storage medium <b>121</b> has been initialized. After that, the storage medium information held by the storage medium authentication area control unit <b>204</b> is used when data is sent to or received from the storage medium <b>121</b>.
0234According to a first modification, the storage medium authentication area control unit <b>204</b> can acquire the storage medium information independently from the storage medium normal area control unit <b>209</b>. Therefore, the operation is possible without synchronizing the storage medium normal area control unit <b>209</b> and the storage medium authentication area control unit <b>204</b>, so that the processing can be speeded up.
(Second Modification)
0235In the storage medium control system according to the third embodiment, the storage medium information may be encrypted and handed from the normal mode unit <b>206</b> to the secure mode unit <b>201</b> using the shared memory.
0236That is, the storage medium control system according to the third embodiment may execute the processings shown in <figref idref="DRAWINGS">FIGS. 8A</figref>, <b>8</b>B and <b>5</b>C instead of the processings shown in <figref idref="DRAWINGS">FIGS. 6A</figref>, <b>6</b>B and <b>5</b>C.
0237First, it is assumed that a common secret key used for cryptography is shared by the storage medium normal area processing unit <b>208</b> and the storage medium authentication area processing unit <b>203</b>.
0238With reference to <figref idref="DRAWINGS">FIG. 8A</figref>, when a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b> (S<b>102</b>: YES), the storage medium normal area processing unit <b>208</b> confirms whether the initialization processing of the storage medium <b>121</b> has succeeded (S<b>202</b>) before it is confirmed at S<b>104</b> to be executed later whether access to the authentication area <b>124</b> of the storage medium <b>121</b> has occurred.
0239When the initialization processing has not succeeded (S<b>202</b>: NO), the storage medium normal area processing unit <b>208</b> issues a request to initialize the storage medium <b>121</b> to the storage medium normal area control unit <b>209</b>. On the basis of the initialization request, the storage medium normal area control unit <b>209</b> acquires “storage medium information” such as the address information, the area size, and the access size about the storage medium <b>121</b>, notifies the information to the storage medium normal area processing unit <b>208</b> (S<b>203</b>), and proceeds to S<b>404</b>.
0240When the initialization processing has already succeeded (S<b>202</b>: YES) or after S<b>203</b> is executed, an encryption processing is performed for the acquired storage medium information using the common secret key in accordance with a particular algorithm to generate encrypted storage medium information (S<b>404</b>).
0241The encrypted storage medium information is stored at a particular address of the shared memory which can be commonly accessed by the normal mode unit <b>206</b> and the secure mode unit <b>201</b> (S<b>405</b>).
0242With reference to <figref idref="DRAWINGS">FIG. 8B</figref>, when access to the authentication area <b>124</b> of the storage medium <b>121</b> occurs after that (S<b>104</b>: YES), and success of transition to the secure mode is confirmed (S<b>108</b>: YES), the storage medium authentication area control unit <b>204</b> acquires the encrypted storage medium information set at S<b>405</b> from the shared memory, on the basis of the address information about the shared memory handed from the storage medium authentication area processing unit <b>203</b>, and internally holds the storage medium information after setting the common secrete key for the encryption control unit <b>205</b> and decrypting the encrypted storage medium information (S<b>408</b>). After that, the storage medium information held by the storage medium authentication area control unit <b>204</b> is used when data is sent to or received from the storage medium <b>121</b>.
0243According to a second modification, by encrypting data when the data is sent and received between the storage medium normal area control unit <b>209</b> and the storage medium authentication area control unit <b>204</b>, it is possible to improve the strength of security of data in sending/receiving of the data.
Fourth Embodiment
0244A storage medium control system according to a fourth embodiment of the present invention will be described with reference to drawings.
0245A configuration of the storage medium control system according to the fourth embodiment is similar to that of the storage medium control system according to the second embodiment shown in <figref idref="DRAWINGS">FIG. 4</figref>. Therefore, a detailed description thereof is not repeated here.
0246Next, a method for controlling a storage medium <b>121</b> by both a secure mode unit <b>201</b> and a normal mode unit <b>206</b> will be described.
0247<figref idref="DRAWINGS">FIGS. 5A</figref>, <b>9</b>A and <b>9</b>B are flowcharts showing a control processing of the storage medium <b>121</b> from both of the secure mode unit <b>201</b> and the normal mode unit <b>206</b>.
0248Though a basic processing is similar to that of the second embodiment, the present embodiment differs from the second embodiment in that it includes a processing for confirming which area is being accessed so as to avoid a conflict between access to the authentication area <b>124</b> of the storage medium <b>121</b> and access to the normal area <b>123</b> of the storage medium <b>121</b>, in order to keep the consistency between access to the authentication area <b>124</b> from the secure mode unit <b>201</b> and access to the normal area <b>123</b> from the normal mode unit <b>206</b>.
0249Hereinafter, a description will be made below mainly on the different processes.
0250Since the processing in <figref idref="DRAWINGS">FIG. 5A</figref> is as described above, a description thereof is not repeated.
0251With reference to <figref idref="DRAWINGS">FIG. 9A</figref>, when a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b>, and it is confirmed that a request to access the authentication area <b>124</b> of the storage medium <b>121</b> has been issued (S<b>104</b>: YES), the storage medium normal area processing unit <b>208</b> confirms whether or not the storage medium normal area control unit <b>209</b> accesses the normal area <b>123</b> of the storage medium <b>121</b> (S<b>503</b>). When it is judged that the normal area <b>123</b> is not accessed (S<b>503</b>: NO), a flow proceeds to S<b>106</b> to transition to the secure mode.
0252When it is judged that the normal area <b>123</b> is accessed (S<b>503</b>: YES), the storage medium control apparatus <b>200</b> abnormally ends at once. Alternatively, there is no problem that, instead of the abnormal end, the storage medium control apparatus <b>200</b> keep the processing waiting for a predetermined time to wait until the access to the normal area <b>123</b> ends, and then the flow proceeds to S<b>106</b> to transition to the secure mode.
0253On the contrary, with reference to <figref idref="DRAWINGS">FIG. 9B</figref>, when it is confirmed that a request to access the normal area <b>123</b> of the storage medium <b>121</b> has been issued (S<b>146</b>: YES), the storage medium authentication area processing unit <b>203</b> confirms whether the storage medium authentication area control unit <b>204</b> accesses the authentication area <b>124</b> of the storage medium <b>121</b> (S<b>511</b>). When it is judged that the authentication area <b>124</b> is not accessed (S<b>511</b>: NO), the flow proceeds to S<b>152</b> to access the storage medium <b>121</b>, and send and receive data.
0254When it is judged that the authentication area <b>124</b> is accessed (S<b>511</b>: YES), the storage medium control apparatus <b>200</b> abnormally ends at once. Alternatively, there is no problem that, instead of the abnormal end, the storage medium control apparatus <b>200</b> keeps the processing waiting for a predetermined time to wait until the access to the authentication area <b>124</b> ends, and then the flow proceeds to S<b>152</b>.
0255As described above, according to the fourth embodiment, it is possible to perform exclusive control so that the storage medium normal area control unit <b>209</b> and the storage medium authentication area control unit <b>204</b> do not access the storage medium <b>121</b> at the same time, in addition to the operation and advantages of the embodiments described above.
(Modification)
0256In the storage medium control system according to the fourth embodiment, it is also possible to hold a state of access to a storage medium in a shared memory (not shown) which can be accessed from both the secure mode unit <b>201</b> and the normal mode unit <b>206</b>, and to perform the exclusive control on the basis of the access state so that the storage medium normal area control unit <b>209</b> and the storage medium authentication area control unit <b>204</b> do not access the storage medium <b>121</b> at the same time.
0257That is, the storage medium control system according to the fourth embodiment may perform the processings shown in <figref idref="DRAWINGS">FIGS. 5A</figref>, <b>10</b>A and <b>10</b>B instead of the processings shown in <figref idref="DRAWINGS">FIGS. 5A</figref>, <b>9</b>A and <b>9</b>B.
0258With reference to <figref idref="DRAWINGS">FIG. 10A</figref>, when a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b> (S<b>104</b>: YES), and it is confirmed that a request to access the authentication area <b>124</b> of the storage medium <b>121</b> has been issued (S<b>104</b>: YES), the mode immediately transitions to the secure mode at S<b>106</b>.
0259When transition to the secure mode is normally executed (S<b>108</b>: YES), the storage medium authentication area control unit <b>204</b> confirms whether or not a bit indicating a condition of access to the storage medium <b>121</b>, which is stored at a particular address in the shared memory (hereinafter referred to as a “storage medium access bit”) is set to “accessed state” (S<b>604</b>). When the bit indicating the state of access to the storage medium <b>121</b> is set to “unaccessed state” (S<b>604</b>: YES), the storage medium access bit is set to the “accessed state” (S<b>605</b>). Then, the flow proceeds to S<b>112</b> where data is sent and received to and from the storage medium <b>121</b>.
0260When the storage medium access bit is set to the “accessed state” in advance (S<b>604</b>: NO), the storage medium control apparatus <b>200</b> abnormally ends at once. Alternatively, there is no problem that, instead of the abnormal end, the storage medium control apparatus <b>200</b> keeps the processing waiting for a predetermined time to wait until the access to the storage medium <b>121</b> ends, and then the flow proceeds to S<b>112</b> to send and receive the data to and from the storage medium <b>121</b>.
0261After that, when it is judged that there is no processing data in the storage medium authentication area (S<b>144</b>: NO), the storage medium authentication area control unit <b>204</b> sets the storage medium access bit set at S<b>604</b> to the “unaccessed state” (S<b>145</b>). Thereby, the access to the storage medium <b>121</b> is enabled.
0262On the contrary, with reference to <figref idref="DRAWINGS">FIG. 10B</figref>, when it is confirmed that a request to access the normal area <b>123</b> of the storage medium <b>121</b> has been issued (S<b>146</b>: YES), the storage medium normal area control unit <b>209</b> confirms whether or not the bit indicating the condition of access to the storage medium, which is stored at a particular address of the shared memory, is set to the “accessed state” (S<b>611</b>). When the storage medium access bit is set to the “unaccessed state” (S<b>611</b>: YES), the storage medium access bit is set to the “accessed state” (S<b>612</b>). Then, the flow proceeds to S<b>152</b> to send and receive data to and from the storage medium <b>121</b>.
0263When the storage medium access bit is set to the “accessed state” in advance (S<b>611</b>: NO), the storage medium control apparatus <b>200</b> abnormally ends at once. Alternatively, there is no problem that, instead of the abnormal end, the storage medium control apparatus <b>200</b> keeps the processing waiting for a predetermined time until the access to the storage medium <b>121</b> ends, and then the flow proceeds to S<b>152</b> to send and receive data to and from the storage medium <b>121</b>.
0264After that, when it is judged that there is no processing data in the normal area <b>123</b> of the storage medium <b>121</b> (S<b>168</b>: NO), the storage medium normal area control unit <b>209</b> sets the storage medium access bit set at S<b>612</b> to the “unaccessed state” (S<b>613</b>). Thereby, the access to the storage medium <b>121</b> is enabled.
0265According to this modification, it is possible to perform the exclusive control so that the storage medium normal area control unit <b>209</b> and the storage medium authentication area control unit <b>204</b> do not access the storage medium <b>121</b> at the same time.
0266Furthermore, since the exclusive control is performed only by confirmation of a bit, the processing can be performed at a high speed.
Fifth Embodiment
0267A storage medium control system according to a fifth embodiment of the present invention will be described with reference to drawings.
0268A configuration of the storage medium control system according to the fifth embodiment is similar to that of the storage medium control system according to the second embodiment shown in <figref idref="DRAWINGS">FIG. 5</figref>. Therefore, a detailed description thereof is not repeated here.
0269Next, a method for controlling a storage medium <b>121</b> by both a secure mode unit <b>201</b> and a normal mode unit <b>206</b> will be described.
0270<figref idref="DRAWINGS">FIGS. 5A</figref>, <b>11</b>A and <b>11</b>B are flowcharts showing a control processing for the storage medium <b>121</b> performed by both the secure mode unit <b>201</b> and the normal mode unit <b>206</b>.
0271Though a basic processing is similar to that of the second embodiment, the present embodiment differs from the second embodiment in that it includes a processing stage of preventing set values of a normal resource <b>212</b> set by a storage medium authentication area control unit <b>204</b> from being modified by a storage medium normal area control unit <b>209</b>, and a processing stage of preventing the set values of the normal resource <b>212</b> set by the storage medium normal area control unit <b>209</b> from being modified by the normal resource <b>212</b>, in order to keep the consistency between access to the authentication area <b>212</b> from the secure mode unit <b>201</b> and access to the normal area <b>209</b> from the normal mode unit <b>206</b>. The “set values” refer to values about access bit width for accessing the storage medium <b>121</b>, access size of data sent to or received from the storage medium <b>121</b>, and the like.
0272Hereinafter, a description will be made mainly on different points. That is, there will be described a method for securing the independence of the set values by resetting the normal resource <b>212</b> and re-setting the register to be used each time the mode is switched.
0273Since the processing in <figref idref="DRAWINGS">FIG. 5A</figref> is as described above, a description thereof is not repeated.
0274With reference to <figref idref="DRAWINGS">FIG. 11A</figref>, when a request to access the storage medium <b>121</b> is issued by a storage medium control apparatus <b>200</b> (S<b>104</b>: YES), and it is confirmed that a request to access an authentication area <b>124</b> of the storage medium <b>121</b> has been issued (S<b>104</b>: YES), the mode immediately transitions to the secure mode (S<b>106</b>).
0275When a processing for transitioning to the secure mode is normally performed (S<b>108</b>: YES), the storage medium authentication area control unit <b>204</b> performs a reset processing of the normal resource <b>212</b> which accesses the storage medium <b>121</b> (S<b>704</b>). That is, the set values of the registers of the normal resource <b>212</b> set by the storage medium normal area control unit <b>209</b> in advance are cleared. Then, the storage medium authentication area control unit <b>204</b> sets the set values to be used to access the storage medium <b>121</b> for the registers of the normal resource <b>212</b> (S<b>704</b>). Then, the flow proceeds to S<b>112</b> where data is sent and received to and from the storage medium <b>121</b> on the basis of the set values set for the registers of the normal resource <b>212</b>.
0276On the contrary, with reference to <figref idref="DRAWINGS">FIG. 11B</figref>, when it is confirmed that a request to access the normal area <b>123</b> of the storage medium <b>121</b> has been issued (S<b>146</b>: YES), the storage medium normal area control unit <b>209</b> performs reset processing of the normal resource <b>212</b> which accesses the storage medium <b>121</b> (S<b>711</b>). Thereby, the set values set for the registers of the normal resource <b>212</b> by the storage medium normal area control unit <b>209</b> in advance are cleared. Then, the storage medium normal area control unit <b>209</b> sets the set values used to access the storage medium <b>121</b> for the registers of the normal resource <b>212</b> (S<b>711</b>). Then, the flow proceeds to S<b>152</b> where data is sent and received to and from the storage medium <b>121</b> on the basis of the set values set for the registers of the normal resource <b>212</b>.
0277As described above, according to the fifth embodiment, each of the storage medium normal area control unit <b>209</b> and the storage medium authentication area control unit <b>204</b> resets the registers of the normal resource <b>212</b> and sets the set values for the registers before accessing the storage medium <b>121</b>, in addition to the operation and the advantages of the embodiments described above. Therefore, the storage medium authentication area control unit <b>204</b> can access the storage medium <b>121</b> without depending on the set values of the normal resource <b>212</b> set by the storage medium normal area control unit <b>209</b>, and the storage medium normal area control unit <b>209</b> can access the storage medium <b>121</b> without depending on the set values of the normal resource <b>212</b> set by the storage medium authentication area control unit <b>204</b>.
(First Modification)
0278In the storage medium control system according to the fifth embodiment, independence of the set values of the normal mode and the secure mode may be secured by backing up the set values of the registers of the normal resource <b>212</b> used by the normal mode at the time of transition to the secure mode and restoring the backed-up set values on the registers at the time of exiting the secure mode.
0279That is, the storage medium control system according to the fifth embodiment may perform the processings shown in <figref idref="DRAWINGS">FIGS. 5A</figref>, <b>12</b> and <b>5</b>C instead of the processings shown in <figref idref="DRAWINGS">FIGS. 5A</figref>, <b>11</b>A and <b>11</b>B.
0280With reference to <figref idref="DRAWINGS">FIG. 12</figref>, when a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b>, and it is confirmed that a request to access the authentication area <b>124</b> of the storage medium <b>121</b> has been issued (S<b>104</b>: YES), the mode immediately transitions to the secure mode (S<b>106</b>).
0281When a transition to the secure mode is normally executed (S<b>108</b>: YES), the storage medium authentication area control unit <b>204</b> backs up, in a particular memory area, all the current set values of the registers for which the setting is to be changed, among the registers of the normal resource <b>212</b> which accesses the storage medium <b>121</b> (S<b>804</b>). Then, the storage medium authentication area control unit <b>204</b> sets the set values for the registers of the normal resource <b>212</b> to be used for access to the storage medium <b>121</b> (S<b>804</b>). Then, the flow proceeds to S<b>112</b> where data is sent and received to and from the storage medium <b>121</b> on the basis of the set values set for the registers of the storage medium <b>121</b>.
0282After that, when it is judged that there is not any other data to be processed that is stored in the authentication area <b>124</b> of the storage medium <b>121</b> (S<b>144</b>: YES), the storage medium authentication area control unit <b>204</b> reads the set values backed up in the particular memory area at S<b>804</b> and re-sets the set values for the registers of the normal resource <b>212</b> used to access the storage medium <b>121</b> (S<b>809</b>).
0283According to the first modification, it is not necessary to modify an existing storage medium normal area control unit <b>209</b>.
(Second Modification)
0284In the storage medium control system according to the fifth embodiment, the normal resource may automatically switch the set values when the mode is switched.
0285<figref idref="DRAWINGS">FIG. 13</figref> is a functional block diagram showing a configuration of a storage medium control system according to the second modification.
0286The storage medium control system is provided with a storage medium control apparatus <b>300</b> and a storage medium <b>121</b>.
0287The storage medium <b>121</b> is similar to what is shown in the first embodiment. Therefore, a detailed description thereof is not repeated here.
0288As for the storage medium control apparatus <b>300</b>, a description will be made mainly on differing points from the storage medium control apparatus <b>200</b> shown in <figref idref="DRAWINGS">FIG. 4</figref>. That is, the storage medium control apparatus <b>300</b> uses a data sending/receiving control device <b>310</b> instead of the data sending/receiving control device <b>210</b> of the storage medium control apparatus <b>200</b>. Other components are similar to those of the storage medium control apparatus <b>200</b>.
0289The data sending/receiving control device <b>310</b> is provided with a secure resource <b>211</b>, a normal resource <b>312</b>, and a set value storage unit <b>313</b>.
0290The set value storage unit <b>313</b> is a storage unit which stores set values to be used by the normal resource <b>312</b> to access the storage medium <b>121</b>.
0291The normal resource <b>312</b> performs a processing similar to that of the normal resource <b>212</b>. However, it is different in that it sets the set values stored in the set value storage unit <b>313</b> for its own registers when the mode is switched.
0292A method for controlling the storage medium <b>121</b> by the storage medium control apparatus <b>300</b> according to the second modification will be described below.
0293<figref idref="DRAWINGS">FIGS. 5A</figref>, <b>14</b>A and <b>14</b>B are flowcharts showing the control processing for the storage medium <b>121</b> performed by both the secure mode unit <b>201</b> and the normal mode unit <b>206</b>.
0294Hereinafter, a description will be made below mainly on the different processings.
0295Since the processing in <figref idref="DRAWINGS">FIG. 5A</figref> is as described above, a description thereof is not repeated.
0296With reference to <figref idref="DRAWINGS">FIG. 14A</figref>, when a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b>, and it is confirmed that a request to access the authentication area <b>124</b> of the storage medium <b>121</b> has been issued (S<b>104</b>: YES), the storage medium authentication area control unit <b>204</b> registers the registers of the normal resource <b>312</b> to be used for access to the storage medium <b>121</b> with the set value storage unit <b>313</b> (S<b>903</b>).
0297When the registers of the normal resource <b>212</b> are registered with the set value storage unit <b>313</b> in transitioning to the secure mode at S<b>106</b> (S<b>904</b>: YES), the normal resource <b>312</b> acquires the current set values of the registers from the normal resource <b>312</b>, and backs up and stores them in the set value storage unit <b>313</b> (S<b>905</b>). When the registers of the normal resource <b>312</b> are not registered with the set value storage unit <b>313</b> (S<b>904</b>: NO), the normal resource <b>312</b> does not have to perform any processing.
0298With reference to <figref idref="DRAWINGS">FIG. 14B</figref>, when it is subsequently judged that there is not any other data to be processed that is stored in the authentication area <b>124</b> of the storage medium <b>121</b> (S<b>144</b>: NO), the following processing is performed in returning to the normal mode at S<b>148</b>. That is, when the current set values of the registers of the storage medium <b>121</b> are backed up in the set value storage unit <b>313</b> (S<b>906</b>: YES), the normal resource <b>312</b> re-sets the set values stored in the set value storage unit <b>313</b> for the normal resource <b>312</b> (S<b>907</b>). When no data is backed up in the set value storage unit <b>313</b> (S<b>906</b>: NO), the normal resource <b>312</b> does not have to perform any processing.
0299According to the second modification, the normal resource <b>312</b>, which is hardware, performs backup and restoration of the set values when the mode is switched. Therefore, it is possible to make change in the set values accompanying switching of the mode, at a high speed.
Sixth Embodiment
0300A storage medium control system according to a sixth embodiment of the present invention will be described with reference to drawings.
0301A configuration of the storage medium control system in the sixth embodiment is the same as that of the storage medium control system according to the second embodiment shown in <figref idref="DRAWINGS">FIG. 4</figref>. Therefore, a detailed description thereof is not repeated here.
0302Next, a method for controlling a storage medium <b>121</b> by both a secure mode unit <b>201</b> and a normal mode unit <b>206</b> will be described.
0303<figref idref="DRAWINGS">FIGS. 15A</figref>, <b>15</b>B and <b>5</b>C are flowcharts showing a control processing of the storage medium <b>121</b> performed by both the secure mode unit <b>201</b> and the normal mode unit <b>206</b>.
0304Though a basic processing is similar to that of the second embodiment, the present embodiment differs from the second embodiment in that the processing can be speeded up while cooperation is performed between access to an authentication area <b>124</b> from the secure mode unit <b>201</b> and access to a normal area <b>123</b> from the normal mode unit <b>206</b>.
0305Hereinafter, a description will be made mainly on different points.
0306Here, a storage medium control apparatus <b>200</b> the power to which is repeatedly turned on and off by a power-saving mechanism or the like is assumed here. Note that it does not matter if the storage medium control apparatus <b>200</b> is an apparatus by which a reset processing of a storage medium is performed, specifically such an apparatus that insertion/removal of a storage medium occurs or an apparatus which performs resetting in the case of occurrence of an abnormal state. Furthermore, it is assumed that, as a method for a storage medium authentication area control unit <b>204</b> to acquire the storage medium access information, only storage medium access information is handed from the normal mode unit <b>206</b> to the secure mode unit <b>201</b> via a shared memory. Thereby, the access to the authentication area <b>124</b> is speeded up. Note that the “storage medium access information” is identification information identifying the storage medium <b>121</b> among storage medium information.
0307With reference to <figref idref="DRAWINGS">FIG. 15A</figref>, when a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b> (S<b>102</b>: YES), a storage medium normal area processing unit <b>208</b> confirms whether the access is the first access to the storage medium <b>121</b> after power is on, the power to the storage medium having been turned off by the power-saving mechanism of the storage medium control apparatus <b>200</b> (S<b>1017</b>). When the power has not been especially turned on or off (S<b>1017</b>: NO), a flow proceeds to S<b>104</b> in <figref idref="DRAWINGS">FIG. 15B</figref>, and issuance of a request to access the authentication area <b>124</b> is confirmed as usual.
0308When it is confirmed that the access is the first access to the storage medium <b>121</b> after the power is on (S<b>1017</b>: YES), it is confirmed whether or not the storage medium <b>121</b> has been initialized (S<b>202</b>). When the storage medium <b>121</b> has been initialized (S<b>202</b>: YES), the flow proceeds to S<b>104</b>, and the issuance of a request to access the authentication is confirmed as usual. Note that, though the judgment criteria is whether the access is the first access after the power is on here, “after the power is on” means “after the storage medium is reset.” Similar processing is also possible after the storage medium is reset by insertion/removal thereof or occurrence of an abnormal state.
0309When the storage medium <b>121</b> has not been initialized (S<b>202</b>: NO), the storage medium normal area control unit <b>209</b> performs an initialization processing for the storage medium <b>121</b> (S<b>203</b>). Furthermore, in the case where any of the storage medium information has been notified to the storage medium authentication area control unit <b>204</b> via the shared memory at least once, it is not necessary to set all the storage medium information for the shared memory. Only such storage medium access information as may be changed by re-initialization of the storage medium <b>121</b> is set for the shared memory (S<b>1004</b>).
0310With reference to <figref idref="DRAWINGS">FIG. 15B</figref>, when it is confirmed that a request to access the authentication area <b>124</b> of the storage medium <b>121</b> is issued (S<b>104</b>: YES), the mode immediately transitions to the secure mode (S<b>106</b>).
0311When transition to the secure mode is normally executed (S<b>108</b>: YES), the storage medium authentication area control unit <b>204</b> acquires, from the shared memory, the storage medium access information for accessing the storage medium <b>121</b> which has been set at S<b>1004</b> (S<b>1007</b>). Then, the flow proceeds to S<b>112</b>, and data is sent and received to and from the storage medium <b>121</b> using the storage medium access information.
0312As described above, according to the sixth embodiment, when the mode is switched, instead of notifying the storage medium information to the storage medium authentication area control unit <b>204</b>, it is sufficient to notify only the storage medium access information, in addition to the operation and advantages of the embodiments described above. Thereby, the processing by the storage medium authentication area control unit <b>204</b> can be speeded up.
(First Modification)
0313According to the storage medium control system of the sixth embodiment, it is also possible to speed up the access to the authentication area <b>124</b> by simplifying the mutual authentication process by the storage medium authentication area processing unit <b>203</b> in the storage medium control apparatus <b>200</b> where the power thereto is repeatedly turned on and off by a power-saving mechanism or the like.
0314That is, the storage medium control system according to the sixth embodiment may perform the processings shown in <figref idref="DRAWINGS">FIGS. 15A</figref>, <b>16</b>A, <b>16</b>B and <b>5</b>C instead of the processings shown in <figref idref="DRAWINGS">FIGS. 15A</figref>, <b>15</b>B and <b>5</b>C.
0315With reference to <figref idref="DRAWINGS">FIG. 16A</figref>, when it is confirmed by the storage medium authentication area processing unit <b>203</b> that mutual authentication has been succeeded at least once between the storage medium control apparatus <b>200</b> and the storage medium <b>121</b> after the storage medium access information is acquired at S<b>1007</b> (S<b>1118</b>: YES), key information which has been already calculated is re-set for the secure resource, and skip-reading of authentication data from the storage medium <b>121</b> is performed once using the storage medium authentication area control unit <b>204</b> (S<b>1119</b>).
0316When the confirmation is not received (S<b>1118</b>: NO), the mutual authentication process is performed again between the storage medium control apparatus <b>200</b> and the storage medium <b>121</b>.
0317Then, the flow proceeds to S<b>126</b> shown in <figref idref="DRAWINGS">FIG. 16B</figref>, and the data is sent to or received from the storage medium <b>121</b>.
0318According to the first modification, it is possible to omit the second and subsequent mutual authentication processings. Thereby, the processing can be speeded up.
(Second Modification)
0319According to the storage medium control system of the sixth embodiment, it is also possible to speed up the access to the authentication area <b>124</b> by simplifying confirmation about whether or not the storage medium <b>121</b> has been initialized in the storage medium control apparatus <b>200</b> where the power thereto is repeatedly turned on and off by a power-saving mechanism or the like.
0320That is, the storage medium control system according to the sixth embodiment may perform the processings shown in <figref idref="DRAWINGS">FIGS. 17</figref>, <b>15</b>B and <b>5</b>C instead of the processings shown in <figref idref="DRAWINGS">FIGS. 15A</figref>, <b>15</b>B and <b>5</b>C.
0321With reference to <figref idref="DRAWINGS">FIG. 17</figref>, when a request to access the storage medium <b>121</b> is issued by the storage medium control apparatus <b>200</b> (S<b>102</b>: YES), an initialization processing of the storage medium <b>121</b> is immediately performed (S<b>203</b>), irrespective of whether or not the access is the first access to the storage medium <b>121</b> after the power is on and whether or not the storage medium <b>121</b> has been initialized. Furthermore, only the storage medium access information which may be changed by re-initialization of the storage medium <b>121</b> is set for the shared memory (S<b>204</b>).
0322According to the second modification, the storage medium normal area control unit <b>209</b> can always start processing when the power is on, and on the other hand, the storage medium authentication area control unit <b>204</b> can always start processing on the assumption that the power is on. Therefore, the processing can be speeded up by reduction of the power on/off judgment processing.
Seventh Embodiment
0323The storage medium control apparatuses according to the embodiments described above are applicable to various equipment. In a seventh embodiment, the storage medium control system is applied to a system for reproducing video and audio contents.
0324<figref idref="DRAWINGS">FIG. 18</figref> is a diagram showing a configuration of a storage medium video and audio reproduction system according to the seventh embodiment.
0325A storage medium video and audio reproduction system <b>450</b> according to the seventh embodiment is a system for reproducing video and audio contents stored in a storage medium <b>121</b>, and it is provided with a storage medium control device <b>400</b>, a data sending/receiving control device <b>210</b>, an encoded data transfer device <b>440</b>, and a video and audio data reproduction device <b>430</b>.
0326Components similar to the components in the embodiments described above are given the same reference numerals and names. Therefore, a detailed description thereof is not repeated here.
0327A normal resource <b>212</b> of the data sending/receiving control device <b>210</b> is connected to the storage medium <b>121</b> in which the video and audio contents are stored.
0328The storage medium control device <b>400</b> is provided with a secure mode unit <b>201</b> and a normal mode unit <b>206</b>.
0329The encoded data transfer device <b>440</b> is provided with an encoding processing unit <b>442</b> and a video and audio reproduction unit <b>441</b>.
0330The encoding processing unit <b>442</b> is a processing unit which analyzes an encoding format of the video and audio contents received from a storage medium normal area control unit <b>209</b>, decodes the video and audio contents, and sends the video and audio data to the video and audio reproduction unit <b>441</b> in a particular data unit.
0331The video and audio reproduction unit <b>441</b> is a processing unit which receives the video and audio data from the encoding processing unit <b>442</b> in the particular data unit and reproduces the data.
0332The video and audio data reproduction device <b>430</b> is provided with a video and audio output unit <b>431</b>.
0333The video and audio output unit <b>431</b> is a processing unit which outputs the video and audio data reproduced by the video and audio reproduction unit <b>441</b>, and it is specifically a display device, a speaker, and the like.
0334The processings performed by the storage medium video and audio reproduction system <b>450</b> are similar to those described in the embodiments described above.
Eighth Embodiment
0335The storage medium control apparatuses according to the embodiments described above are applicable to various equipment. In an eighth embodiment, the storage medium control system is applied to a system for recording video and audio contents.
0336<figref idref="DRAWINGS">FIG. 19</figref> is a diagram showing a configuration of a system for recording video and audio in a storage medium according to the eighth embodiment.
0337A system for recording video and audio in a storage medium <b>550</b> according to the eighth embodiment is a system for recording video and audio contents stored in a storage medium <b>121</b>, and it is provided with a storage medium control device <b>500</b>, a data sending/receiving control device <b>210</b>, an encoded data transfer device <b>540</b>, and a video and audio data receiving device <b>530</b>.
0338Components similar to the components in the embodiments described above are given the same reference numerals and names. Therefore, a detailed description thereof is not repeated here.
0339A normal resource <b>212</b> of the data sending/receiving control device <b>210</b> is connected to the storage medium <b>121</b> in which the video and audio contents are stored.
0340The storage medium control device <b>500</b> is provided with a secure mode unit <b>201</b> and a normal mode unit <b>206</b>.
0341The video and audio data receiving device <b>530</b> is provided with a video and audio input unit <b>531</b>. The video and audio input unit <b>531</b> is a processing unit which receives, from other equipment or broadcast waves, video and audio data to be recorded.
0342The encoded data transfer device <b>540</b> is provided with a video and audio recording unit <b>541</b> and an encoding processing unit <b>542</b>.
0343The video and audio recording unit <b>541</b> is a processing unit which receives the video and audio data from the video and audio input unit <b>531</b> for every particular data unit.
0344The encoding processing unit <b>542</b> is a processing unit which encodes the video and audio data received by the video and audio recording unit <b>541</b> on the basis of a particular encoding format.
0345The processings performed by the system for recording the video and audio in the storage medium <b>550</b> are similar to those described in the embodiments described above.
0346Although only some exemplary embodiments of this invention have been described in detail above, those skilled in the art will readily appreciate that many modifications are possible in the exemplary embodiments without materially departing from the novel teachings and advantages of this invention. Accordingly, all such modifications are intended to be included within the scope of this invention.
INDUSTRIAL APPLICABILITY
0347The present invention is applicable to a system for reproducing or recording video and audio contents, and the like.
Contents5
32 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2015304329A1 | Cited by | United States of America | Pre-grant |
| US10581807B2 | Cited by | United States of America | Search report |
| US2009327697A1 | Cited by | United States of America | Pre-grant |
| US8898803B1 | Cited by | United States of America | Applicant |
| US2010153705A1 | Cited by | United States of America | Pre-grant |
| US9081726B2 | Cited by | United States of America | Applicant |
| US8261097B2 | Cited by | United States of America | Search report |
| US7559090B2 | Cited by | United States of America | Search report |
| US2005246546A1 | Cited by | United States of America | Pre-grant |
| US2014123320A1 | Cited by | United States of America | Pre-grant |
| US8775827B2 | Cited by | United States of America | Search report |
| US2011197131A1 | Cited by | United States of America | Pre-grant |
| US8949879B2 | Cited by | United States of America | Applicant |
| US9411984B2 | Cited by | United States of America | Search report |
| US8266422B2 | Cited by | United States of America | Applicant |
| US8745749B2 | Cited by | United States of America | Applicant |
| CN107102925A | Cited by | China | Search report |
| US2011093622A1 | Cited by | United States of America | Pre-grant |
| US9552307B2 | Cited by | United States of America | Search report |
| US8171284B2 | Cited by | United States of America | Applicant |
| US2015310230A1 | Cited by | United States of America | Pre-grant |
| US2012254629A1 | Cited by | United States of America | Pre-grant |
| US2015304329A1 | Cited by | United States of America | Search report |
| US2008162945A1 | Cited by | United States of America | Pre-grant |
| US2015089246A1 | Cited by | United States of America | Pre-grant |
| US2011202564A1 | Cited by | United States of America | Pre-grant |
| US10120984B2 | Cited by | United States of America | Search report |
| US8977783B2 | Cited by | United States of America | Applicant |
| US2015304329A1 | Cited by | United States of America | Search report |
| US2013132719A1 | Cited by | United States of America | Pre-grant |
| US9595300B2 | Cited by | United States of America | Applicant |
| US2003041253A1 | Cites | United States of America | Pre-grant |
| US2004143720A1 | Cites | United States of America | Pre-grant |
| US2005071662A1 | Cites | United States of America | Pre-grant |
| US2005198522A1 | Cites | United States of America | Pre-grant |
| US2005246546A1 | Cites | United States of America | Pre-grant |
| US2006117013A1 | Cites | United States of America | Pre-grant |
| US2007113079A1 | Cites | United States of America | Pre-grant |
| US6662020B1 | Cites | United States of America | Pre-grant |
| US6889299B1 | Cites | United States of America | Pre-grant |
3 members in 3 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 2006284373 | Japan | – | |
| 2006284373 | Japan | A | |
| 2006284373 | Japan | A | |
| 2007129806 | Japan | – | |
| 2007129806 | Japan | A | |
| 2007129806 | Japan | A | |
| 2006284373 | – | – | – |
| 2007129806 | – | – | – |
| JP20060284373 | – | – | – |
| JP20070129806 | – | – | – |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| CN101165668A | China | A | |
| US2008098239A1 | United States of America | A1 | |
| JP2008123482A | Japan | A |
42 transactions on the USPTO file
Abandoned after 1 non-final rejection and 1 final rejection.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Email NotificationEML_NTR | EML_NTR | |
| Mail Abandonment for Failure to Respond to Office ActionAbandonedMABN2 | MABN2 | |
| Aband. for Failure to Respond to O. A.AbandonedABN2 | ABN2 | |
| Interview Summary - Examiner InitiatedEXIE | EXIE | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| Cleared by OIPE CSRL194 | L194 | |
| Request from applicant for the USPTO to retrieve the Priority DocumentPDREQUST | PDREQUST | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 20080098239
- Publication, DOCDB
- 2008098239
- Publication, EPODOC
- US2008098239
- Application
- 11871486
- Application, DOCDB
- 87148607
- Application, EPODOC
- US20070871486
Titles
- English
- STORAGE MEDIUM CONTROL METHOD
Classification
- CPC, 3
- H04L9/3273
- G11B20/00086
- H04L2209/603
- IPC, 4
- H04L9 32
- G06F21 62
- G06F21 60
- G06F21 74
- USPC, 1
- 713193000