Secure element, method for generating key, and program

The secure element checks key generation support information to prevent malfunctions by verifying key length and elliptic curve parameters, ensuring reliable key generation in elliptic curve cryptography.

JP2025171643APending Publication Date: 2025-11-20TOPPAN HOLDINGS INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024077199
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-10
Publication Date
2025-11-20

AI Technical Summary

Technical Problem

Malfunctions occur during key generation in secure elements using elliptic curve cryptography when arbitrary values not supported by the secure element or library are set as elliptic curve parameters.

Method used

A secure element with a memory unit to store key generation support information and a control unit to check if the key generation information is supported before proceeding with the generation process, ensuring compatibility with recommended elliptic curve parameters.

Benefits of technology

Prevents malfunctions in key generation by verifying the compatibility of key length and elliptic curve parameters, ensuring accurate and reliable key generation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025171643000001_ABST
    Figure 2025171643000001_ABST
Patent Text Reader

Abstract

To provide a secure element, a method for generating a key, and a program that are capable of preventing malfunctions in key generation using elliptic-curve cryptography.SOLUTION: A secure element includes: a storage unit for storing key-generation support information indicating information supported as information used for key generation using elliptic-curve cryptography; and a control unit for confirming, before the key generation, whether key-generation information acquired as information to be used for the key generation is supported information, on the basis of the key-generation support information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a secure element, a key generation method, and a program. [Background technology]

[0002] Devices such as IoT (Internet of Things) equipment, mobile terminals, and personal computers use tamper-resistant secure elements (SEs) such as IC (Integrated Circuit) chips, IC cards, and USIM (Universal Subscriber Identity Module) cards. As a public key cryptography method used in these secure elements, elliptic curve cryptography (ECC), as disclosed in Patent Document 1 below, for example, has attracted attention.

[0003] In key generation using elliptic curve cryptography, a key is generated by elliptic curve cryptography calculations using elliptic curve parameters. The elliptic curve parameters used in elliptic curve cryptography calculations generally use values ​​recommended by public institutions or industry groups (e.g., NIST P-256, secp256kl, etc.), but APIs (Application Programming Interfaces) are created so that any value other than the recommended values ​​can be set as the elliptic curve parameters. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2000-181351 Summary of the Invention [Problem to be solved by the invention]

[0005] However, when an arbitrary value is set as an elliptic curve parameter used in an elliptic curve cryptography operation, if the set value is not supported by the secure element or library, a malfunction occurs during key generation.

[0006] In view of the above-mentioned problems, an object of the present invention is to provide a secure element, a key generation method, and a program that can prevent malfunctions in key generation using elliptic curve cryptography. [Means for solving the problem]

[0007] In order to solve the above-mentioned problems, a secure element according to one embodiment of the present invention is a secure element that includes: a memory unit that stores key generation support information indicating information that is supported as information to be used for key generation using elliptic curve cryptography; and a control unit that, prior to the key generation, checks, based on the key generation support information, whether the key generation information obtained as information to be used for the key generation is supported information.

[0008] A key generation method according to one aspect of the present invention is a computer-executed key generation method including: a storage process for storing key generation support information indicating information supported as information to be used for key generation using elliptic curve cryptography in a secure element; and a control process for confirming, prior to the key generation in the secure element, based on the key generation support information, whether or not key generation information obtained as information to be used for the key generation is supported information.

[0009] A program according to one aspect of the present invention is a program for causing a secure element computer to function as: a storage means for storing key generation support information indicating information supported as information to be used for key generation using elliptic curve cryptography in the secure element; and a control means for confirming, prior to the key generation in the secure element, based on the key generation support information, whether the key generation information obtained as information to be used for the key generation is supported information. [Effects of the Invention]

[0010] According to the present invention, it is possible to prevent malfunctions in key generation using elliptic curve cryptography. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a block diagram showing an example of the configuration of a secure element according to a first embodiment. [Figure 2] FIG. 4 is a sequence diagram showing an example of an operation example of the secure element according to the first embodiment. [Figure 3] FIG. 4 is a sequence diagram showing details of a key length confirmation process in an operation example of the secure element according to the first embodiment. [Figure 4] FIG. 10 is a sequence diagram showing details of an elliptic curve parameter confirmation process in an operation example of the secure element according to the first embodiment. [Figure 5] FIG. 10 is a block diagram showing an example of the configuration of a secure element and an electronic device according to a second embodiment. [Figure 6] FIG. 10 is a sequence diagram showing an example of an operation example of the secure element and the electronic device according to the second embodiment. [Figure 7] FIG. 10 is a sequence diagram showing details of a key generation request process in an example of operation of a secure element and an electronic device according to the second embodiment. [Figure 8] FIG. 10 is a sequence diagram showing an example of an operation example of a secure element and an electronic device in a modified example of the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0013] <<1. First Embodiment>> A first embodiment will be described with reference to Figures 1 to 4. In the first embodiment, the embodiment will be described taking as an example an example in which an application in a secure element (SE) holds elliptic curve parameters.

[0014] <1-1.Configuration example> The configuration of a secure element 10 according to the first embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing an example of the configuration of a secure element 10 according to the first embodiment.

[0015] 1 is, for example, a tamper-resistant IC (Integrated Circuit) chip, an IC card, a USIM (Universal Subscriber Identity Module) card, etc. As shown in FIG. 1, the secure element 10 includes a control unit 11 and a storage unit 12.

[0016] (1) Control unit 11 The control unit 11 has a function of controlling the overall operation of the secure element 10. For example, the control unit 11 controls operations related to key generation using Elliptic Curve Cryptography (ECC) in the secure element 10. In key generation using ECC, a key is generated by elliptic curve cryptography calculations using elliptic curve parameters.

[0017] Elliptic curve parameters are parameters required for elliptic curve cryptography calculations to generate keys using elliptic curve cryptography. For example, y 2 =x 3 +ax+b or y 2 +xy=x 3 +ax 2In an elliptic curve expressed by the formula p + b, the parameters are the coefficient a (an integer in the range 0≦a≦p-1), the coefficient b (an integer in the range 0≦b≦p-1), the fixed point G (coordinate) on the elliptic curve, the order n, the cofactor h, etc. The elliptic curve parameters can be set to values ​​recommended by public institutions or industry groups (e.g., NIST P-256, secp256kl, etc.), or any other value than these recommended values.

[0018] The control unit 11 performs key generation using elliptic curve cryptography calculations based on key generation information 121 and key generation support information 1221 stored in the storage unit 12. The key generation information 121 indicates information used for key generation using elliptic curve cryptography. The key generation support information 1221 indicates information supported for use in key generation using elliptic curve cryptography. The information used for key generation includes information indicating the key length of the key to be generated and information indicating elliptic curve parameters required for the elliptic curve cryptography calculations.

[0019] Before generating a key by elliptic curve cryptography, the control unit 11 checks, based on the key generation support information 1221, whether or not the key generation information 121 obtained as information used for key generation is supported information.

[0020] First, the control unit 11 checks whether the key length is supported information. Specifically, before generating a key, the control unit 11 checks whether the key length indicated by the key generation support information 1221 matches the key length indicated by the key generation information 121. If the key lengths do not match, the control unit 11 decides not to perform key generation.

[0021] If the key lengths match, the control unit 11 checks whether the elliptic curve parameters are supported information. If there are multiple elliptic curve parameters to be checked, the control unit 11 checks whether each of the elliptic curve parameters is supported information. Specifically, before key generation, the control unit 11 checks whether the elliptic curve parameters indicated by the key generation support information 1221 match the elliptic curve parameters indicated by the key generation information 121. If the check results show that even one of the elliptic curve parameters do not match, the control unit 11 decides not to perform key generation.

[0022] If the verification results for all elliptic curve parameters match, the control unit 11 decides to execute key generation. That is, if all of the key lengths and elliptic curve parameters are supported information, the control unit 11 decides to execute key generation. On the other hand, if any of the key lengths and elliptic curve parameters contains unsupported information, the control unit 11 decides not to execute key generation.

[0023] Control unit 11 includes a general-purpose processor such as a CPU (Central Processing Unit), a communication interface with other devices, and reads and executes programs from storage unit 12. Control unit 11 may function as applet unit 111 and OS (Operating System) unit 112 by executing programs corresponding to each of applet unit 111 and OS unit 112.

[0024] The applet section 111 specifies the key length and sets the elliptic curve parameters to the OS section 112 based on the key generation information 121 stored in the storage section 12, and the specifications are to be checked to see if the information is supported.

[0025] The OS unit 112 checks whether the key length and the elliptic curve parameters specified by the applet unit 111 are supported based on the key generation support information 1221 stored in the storage unit 12. The OS unit 112 returns the check result indicating whether the information is supported to the applet unit 111.

[0026] (2) Storage section 12 1, the storage unit 12 stores key generation information 121, a communication driver 122, and a cryptographic library 123. Furthermore, the storage unit 12 statically stores key generation support information 1221 in the communication driver 122.

[0027] The communication driver 122 is a program that needs to be implemented for each secure element 10. For this reason, there are cases where a certain communication driver 122 is implemented in one secure element 10, and a different communication driver 122 is implemented in another secure element 10. In this case, if the key generation support information 1221 is provided in the layer of the OS unit 112, there is a possibility that the work required to update the OS unit 112 will increase. For example, suppose that there is information that is not supported in a certain secure element 10, and the key generation support information provided in the OS unit 112 is adapted to that certain secure element 10. In this case, if the amount of information supported by another successor secure element 10 increases, the OS unit 112 will also need to be updated each time. Therefore, by storing the key generation support information 1221 in the communication driver 122, it becomes unnecessary to update the OS unit 112, thereby reducing the amount of work required. This also makes it easy to port the OS to another secure element 10.

[0028] The storage unit 12 stores programs (not shown) corresponding to each of the applet unit 111 and the OS unit 112. The program corresponding to the OS unit 112 holds information indicating the key length from among the key generation support information.

[0029] <1-2. Example of operation> The configuration of the secure element 10 according to the first embodiment has been described above. Next, an example of operation according to the first embodiment will be described with reference to Figures 2 to 4. In the following, the example of operation will be described taking as an example a case where the OS unit 112 of the secure element 10 is JavaCardOS and the applet unit 111 is an applet that runs on JavaCardOS.

[0030] (1) Example of Secure Element 10 operation An example of operation of the secure element 10 according to the first embodiment will be described with reference to Fig. 2. Fig. 2 is a sequence diagram showing an example of operation of the secure element 10 according to the first embodiment.

[0031] As shown in FIG. 2, first, the applet unit 111 generates an instance (step S101). Next, the applet section 111, the OS section 112, and the communication driver 122 cooperate with each other to perform a key length confirmation process (step S102). The key length confirmation process will be described in detail later. Next, the applet section 111 checks whether the key length is supported or not based on the result of the key length confirmation process (step S103). If the key length is supported (step S103 / YES), the process proceeds to step S104. On the other hand, if the key length is not supported (step S103 / NO), the process proceeds to connector A and ends.

[0032] When the process proceeds to step S104, the applet section 111, the OS section 112, and the communication driver 122 cooperate with each other to perform an elliptic curve parameter confirmation process (step S104). The elliptic curve parameter confirmation process will be described in detail later. Next, based on the result of the elliptic curve parameter confirmation process, applet unit 111 checks whether the elliptic curve parameters are supported (step S105). If the elliptic curve parameters are supported (step S105 / YES), the process proceeds to step S106. On the other hand, if the elliptic curve parameters are not supported (step S105 / NO), the process proceeds to connector A and ends.

[0033] If the process proceeds to step S106, the applet unit 111 checks whether or not checking of all elliptic curve parameters has been completed (step S106). If it has been completed (step S106 / YES), the process proceeds to step S107. On the other hand, if it has not been completed (step S106 / NO), the process proceeds to connector B and repeats from step S104.

[0034] If the process proceeds to step S107, the applet unit 111, the OS unit 112, the communication driver 122, and the cryptographic library 123 cooperate with each other to perform key generation processing (step S107). Every time the OS unit 112 successfully confirms in steps S104 and S105 that each elliptic curve parameter is supported, the OS unit 112 stores the elliptic curve parameters passed via the API in its internal memory (which may be either volatile or nonvolatile). The elliptic curve parameters are stored in a data structure that handles elliptic curve keys and is shared by the OS unit 112 and the communication driver 122. In addition to the elliptic curve parameters, the data structure that handles the elliptic curve key can also be provided with a public key and / or a private key from the applet unit 111. In this case, the key generation process is completed when the validity of all the elliptic curve parameters has been confirmed. On the other hand, when only elliptic curve parameters are provided to the data structure that handles elliptic curve keys and a key pair of a private key and a public key is generated using the cryptographic library 123, the OS unit 112 confirms that all elliptic curve information is set in the data structure, and then passes the data structure to the cryptographic library 123 via the communication driver 122. The cryptographic library 123 calculates a supported elliptic curve from the passed elliptic curve information and generates a private key and a public key pair. The communication driver 122 sets the key information generated by the cryptographic library 123 in the data structure that handles elliptic curve keys, and completes the key generation process.

[0035] (2) Details of the key length confirmation process in the operation example of the secure element 10 Details of the key length confirmation process in an operation example of the secure element 10 according to the first embodiment will be described with reference to Fig. 3. Fig. 3 is a sequence diagram showing details of the key length confirmation process in an operation example of the secure element 10 according to the first embodiment.

[0036] 3, first, the applet section 111 specifies a key length to the OS section 112 (step S201). The key length is information indicated by the key generation information 121 stored in the storage section 12.

[0037] Next, the OS unit 112 and the communication driver 122 confirm whether or not the key length specified by the applet unit 111 is supported information (step S202). First, the OS unit 112 confirms whether or not the specified key length is supported information based on information indicating the key length in the key generation support information held by the program corresponding to the OS unit 112 in the storage unit 12. If it is confirmed that the specified key length is supported information by the OS unit 112, the communication driver 122 confirms whether or not the specified key length is supported information based on the information indicating the key length in the key generation support information held by itself. If the specified key length is supported by the OS unit 112 and the communication driver 122 (step S203 / YES), the process proceeds to step S204. On the other hand, if the specified key length is not supported by at least one of the OS unit 112 and the communication driver 122 (step S203 / NO), the process proceeds to step S205.

[0038] If the process proceeds to step S204, the OS unit 112 reserves memory for key data (step S204). After the memory is reserved, the process proceeds to step S205. If the process proceeds to step S205, the OS section 112 transmits the result of checking whether the key length is supported to the applet section 111 (step S205).

[0039] The applet section 111 checks the check result received from the OS section 112 (step S206). After checking, the process proceeds to step S103 in FIG.

[0040] (3) Details of the elliptic curve parameter confirmation process in the operation example of the secure element 10 Details of the elliptic curve parameter confirmation process in an operation example of the secure element 10 according to the first embodiment will be described with reference to Fig. 4. Fig. 4 is a sequence diagram showing details of the elliptic curve parameter confirmation process in an operation example of the secure element 10 according to the first embodiment.

[0041] 4, first, the applet unit 111 sets one of the elliptic curve parameters included in the key generation information 121 to the OS unit 112 (step S301). The elliptic curve parameter is information indicated by the key generation information 121 stored in the storage unit 12.

[0042] Next, the OS unit 112 acquires elliptic curve parameters corresponding to the elliptic curve parameters received from the applet unit 111 from the communication driver 122 (step S302). At this time, the OS unit 112 acquires elliptic curve parameters supported by the key length specified by the applet unit 111 from key generation support information 1221 held in the communication driver 122. In response to a request from the OS unit 112, the communication driver 122 returns one or more elliptic curve parameters (step S303).

[0043] Next, the OS unit 112 checks whether the elliptic curve parameters set by the applet unit 111 are supported information, based on the elliptic curve parameters acquired from the communication driver 122 (step S304). If the set elliptic curve parameters are supported (step S305 / YES), the process proceeds to step S306. On the other hand, if the set elliptic curve parameters are not supported (step S305 / NO), the process proceeds to step S307.

[0044] If the process proceeds to step S306, the OS unit 112 stores the elliptic curve parameters that have been confirmed to be supported information in the memory for key data (step S306). After storing the elliptic curve parameters, the process proceeds to step S307. If the process proceeds to step S307, the OS unit 112 transmits the support confirmation result of the elliptic curve parameters to the applet unit 111 (step S307).

[0045] The applet section 111 checks the check result received from the OS section 112 (step S308). After checking, the process proceeds to step S105 in FIG.

[0046] An example of operation according to the first embodiment has been described above. As described above, the secure element 10 according to the first embodiment includes a memory unit 12 that stores key generation support information indicating information that is supported as information to be used for key generation using elliptic curve cryptography, and a control unit 11 that, prior to key generation, checks, based on the key generation support information, whether or not the key generation information obtained as information to be used for key generation is supported information.

[0047] With this configuration, by checking the elliptic curve parameters before actually generating a key, it is possible to prevent a key from being generated using incorrect data that is not supported. Therefore, the secure element 10 according to the first embodiment can prevent malfunctions in key generation using elliptic curve cryptography.

[0048] <<2. Second Embodiment>> The first embodiment has been described above. Next, a second embodiment will be described with reference to Fig. 5 to Fig. 8. In the second embodiment, an example will be described in which an application outside a secure element holds elliptic curve parameters. The application in question is, for example, an application installed in an electronic device capable of communicating with a secure element.

[0049] <2-1.Configuration example> The configurations of the secure element 10a and the electronic device 20 according to the second embodiment will be described with reference to Fig. 5. Fig. 5 is a block diagram showing an example of the configurations of the secure element 10a and the electronic device 20 according to the second embodiment.

[0050] (1) Secure Element 10a Similar to the secure element 10 according to the first embodiment, the secure element 10a shown in Fig. 5 is a tamper-resistant IC chip, IC card, USIM card, etc. As shown in Fig. 5, the secure element 10a includes a control unit 11a and a storage unit 12a.

[0051] The control unit 11a includes an applet unit 111a and an OS unit 112a. The applet unit 111a differs from the applet unit 111 according to the first embodiment in that it further has a function of cooperating with the electronic device 20. The OS unit 112a has the same function as the OS unit 112a according to the first embodiment.

[0052] The storage unit 12a stores a communication driver 122a and a cryptographic library 123a. Furthermore, the storage unit 12a statically holds key generation support information 1221a in the communication driver 122a. The storage unit 12a differs from the storage unit 12 according to the first embodiment in that it does not store key generation information.

[0053] (2)Electronic equipment 20 5 is, for example, an IoT (Internet of Things) device, a mobile terminal such as a smartphone or a tablet terminal, or a personal computer (PC). As shown in Fig. 5, the electronic device 20 includes a control unit 21 and a storage unit 22. The control unit 21 includes an application unit 211. The storage unit 22 stores key generation information 221.

[0054] (2-1) Control unit 21 The control unit 21 has a function of controlling the overall operation of the electronic device 20. The control unit 11a of the secure element 10a and the control unit 21 of the electronic device 20 are communicably connected. As a result, the control unit 21 transmits a key generation request and elliptic curve parameters included in the key generation information 221 to the secure element 10a.

[0055] The control unit 11a and the control unit 210 may be communicatively connected by inserting the secure element 10a into a socket provided in the electronic device 20, for example, or may be communicatively connected via wireless communication when the secure element 10a is placed near the electronic device 20. Also, although the secure element 10a is placed outside the electronic device 20 in Fig. 5, the electronic device 20 may include the secure element 10a and be communicatively connected via an I2C bus or the like.

[0056] Control unit 21 includes a general-purpose processor such as a CPU, a communication interface with other devices, and reads and executes a program from storage unit 22. Control unit 21 may function as application unit 211 by executing a program corresponding to application unit 211.

[0057] Based on the key generation information 221 stored in the storage unit 22, the application unit 211 specifies the key length and sets the elliptic curve parameters for the secure element 10a, which are to be confirmed as supported information.

[0058] (2-2) Storage section 22 The storage unit 22 has a function of storing various types of information. The storage unit 22 is configured by a storage medium provided as hardware in the electronic device 20, such as a hard disk drive (HDD), a solid state drive (SSD), a flash memory, an electrically erasable programmable read-only memory (EEPROM), a random access read / write memory (RAM), a read-only memory (ROM), or any combination of these storage media. 5, the storage unit 22 stores key generation information 221. The key generation information 221 is the same information as the key generation information 121 according to the first embodiment.

[0059] <2-2. Example of operation> The above has described the configurations of the secure element 10a and the electronic device 20 according to the second embodiment. Next, an operation example according to the second embodiment will be described with reference to Figs.

[0060] (1) Example of operation of the secure element 10a and the electronic device 20 An example of the operation of the secure element 10a and the electronic device 20 according to the second embodiment will be described with reference to Fig. 6. Fig. 6 is a sequence diagram showing an example of the operation of the secure element 10a and the electronic device 20 according to the second embodiment.

[0061] 6, first, the application unit 211 of the electronic device 20 and the applet unit 111a of the secure element 10a cooperate with each other to perform a key generation request process (step S401). The key generation request process will be described in detail later. The processing from step S402 to step S407 after the key generation request processing is the same as the processing from step S102 to step S107 described with reference to FIG. 2 in the first embodiment, and therefore the description thereof will be omitted.

[0062] (2) Details of the Key Length Verification Process in the Operational Example of the Secure Element 10a and the Electronic Device 20 Details of the key generation request processing in an example of operation of the secure element 10a and the electronic device 20 according to the second embodiment will be described with reference to Fig. 7. Fig. 7 is a sequence diagram showing details of the key generation request processing in an example of operation of the secure element 10a and the electronic device 20 according to the second embodiment.

[0063] As shown in FIG. 7, first, the application unit 211 of the electronic device 20 transmits a key generation request to the applet unit 111a of the secure element 10a (step S501). Next, the applet section 111a performs data processing related to the key generation request received from the application section 211 (step S502). After processing the data, the applet section 111a transmits the result of receiving the key generation request to the application section 211 (step S503).

[0064] Next, the application unit 211 sets one of the elliptic curve parameters included in the key generation information 221 to the applet unit 111a (step S504). The elliptic curve parameter is information indicated by the key generation information 221 stored in the storage unit 22 of the electronic device 20. Next, the applet section 111a performs data processing on the elliptic curve parameters received from the application section 211 (step S505). After the data processing, the applet section 111a transmits the reception result of the elliptic curve parameters to the application section 211 (step S506).

[0065] After transmitting the reception results of the elliptic curve parameters, the applet unit 111a checks whether all the elliptic curve parameters have been received (step S507). If all the elliptic curve parameters have not been received (step S507 / NO), the process proceeds to step S508. On the other hand, if all the elliptic curve parameters have been received (step S507 / YES), the process proceeds to step S402 in FIG. 6.

[0066] If the process proceeds to step S508, the applet section 111a requests the next elliptic curve parameter from the application section 211 (step S508). After the request, the process repeats from step S504.

[0067] An example of operation according to the second embodiment has been described above. As described above, the secure element 10a according to the second embodiment includes a storage unit 12a that stores key generation support information indicating information supported as information to be used for key generation using elliptic curve cryptography, and a control unit 11a that, prior to key generation, checks, based on the key generation support information, whether or not key generation information obtained as information to be used for key generation is supported information.

[0068] With this configuration, by checking the elliptic curve parameters before actually generating a key, it is possible to prevent a key from being generated using incorrect data that is not supported. Therefore, the secure element 10a according to the second embodiment can prevent malfunctions in key generation using elliptic curve cryptography.

[0069] <2-3. Modifications> The second embodiment has been described above. Next, modified examples of the second embodiment will be described. The modified examples described below may be applied to the second embodiment alone or in combination with each other. Furthermore, the modified examples may be applied in place of the configuration described in the second embodiment, or may be applied in addition to the configuration described in the second embodiment.

[0070] In the second embodiment described above, an example has been described in which the applet unit 111a of the secure element 10a, after receiving all data to be checked from the electronic device 20, links the data to the OS unit 112a and executes the processing from step S402 to step S407 shown in Fig. 6, but the example is not limited to this. For example, every time the applet unit 111a of the secure element 10a receives data to be checked from the electronic device 20, it may link the data to the OS unit 112a and execute processing similar to step S402 to step S407 shown in Fig. 6. This allows the secure element 10a to make comparisons on a parameter-by-parameter basis, making it possible to detect an error at the timing when incorrect data is set, and making it possible to notice the error earlier than if a key were generated after all data had been received.

[0071] An example of the operation of the secure element 10a and the electronic device 20 in the modified example of the second embodiment will now be described with reference to Fig. 8. Fig. 8 is a sequence diagram showing an example of the operation of the secure element 10a and the electronic device 20 in the modified example of the second embodiment.

[0072] As shown in FIG. 8, first, the application unit 211 of the electronic device 20 transmits a key generation request to the applet unit 111a of the secure element 10a (step S601). Next, the applet section 111a performs data processing related to the key generation request received from the application section 211 (step S602). After the data processing, the applet section 111a, the OS section 112a, and the communication driver 122a cooperate with each other to perform a key length confirmation process (step S603). The details of the key length confirmation process are the same as those described with reference to FIG. 3, and therefore will not be described again.

[0073] After the key length confirmation process, the applet section 111a transmits the result of the key length confirmation process to the application section 211 (step S604). Next, the application unit 211 checks whether the key length is supported based on the result of the key length confirmation process (step S605). If the key length is supported (step S605 / YES), the process proceeds to step S606. On the other hand, if the key length is not supported (step S605 / NO), the process proceeds to connector A and ends.

[0074] If the process proceeds to step S606, the application unit 211 sets one of the elliptic curve parameters included in the key generation information 221 to the applet unit 111a (step S606). The elliptic curve parameter is information indicated by the key generation information 221 stored in the storage unit 22 of the electronic device 20. Next, the applet section 111a performs data processing on the elliptic curve parameters received from the application section 211 (step S607). After the data processing, the applet unit 111a, the OS unit 112a, and the communication driver 122a cooperate with each other to perform the elliptic curve parameter confirmation process (step S608). The details of the elliptic curve parameter confirmation process are the same as those described with reference to FIG. 3, and therefore will not be described again.

[0075] After the elliptic curve parameter confirmation process, the applet unit 111a transmits the result of the elliptic curve parameter confirmation process to the application unit 211 (step S609). Next, the application unit 211 checks whether the elliptic curve parameters are supported based on the result of the elliptic curve parameter confirmation process (step S610). If the elliptic curve parameters are supported (step S610 / YES), the process proceeds to step S611. On the other hand, if the elliptic curve parameters are not supported (step S610 / NO), the process proceeds to connector A and ends.

[0076] If the process proceeds to step S611, the application unit 211 checks whether or not confirmation of all elliptic curve parameters has been completed (step S611). If it has been completed (step S611 / YES), the process proceeds to step S612. On the other hand, if it has not been completed (step S612 / NO), the process proceeds to connector B and repeats from step S606.

[0077] If the process proceeds to step S612, the application unit 211, applet unit 111a, OS unit 112a, communication driver 122a, and cryptographic library 123a cooperate to perform key generation processing (step S612). The application unit 211 requests the applet unit 111a to execute the key generation processing. The applet unit 111a, OS unit 112a, communication driver 122a, and cryptographic library 123a execute the key generation processing in the same manner as in step S107. After the key generation, the process ends.

[0078] The second embodiment has been described above. Note that the secure element 10, the secure element 10a, and the electronic device 20 in each of the above-described embodiments may be partly or entirely implemented by a computer. In this case, a program for implementing this function may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed to implement the function. Note that the term "computer system" here includes hardware such as an OS and peripheral devices. Additionally, "computer-readable recording media" refers to portable media such as flexible disks, optical magnetic disks, ROMs, CD-ROMs, etc., and storage devices such as hard disks built into computer systems. Furthermore, "computer-readable recording media" may also include devices that dynamically store programs for a short period of time, such as communication lines when transmitting programs via networks such as the Internet or communication lines such as telephone lines, and devices that store programs for a certain period of time, such as volatile memory within computer systems that serve as servers or clients in such cases. Furthermore, the above program may be one that realizes part of the above-mentioned functions, or may be one that can realize the above-mentioned functions in combination with a program already recorded in a computer system, or may be one that is realized using a programmable logic device such as an FPGA (Field Programmable Gate Array).

[0079] The embodiments of the present invention have been described in detail above with reference to the drawings, but the specific configuration is not limited to that described above, and various design changes can be made within the scope of the gist of the present invention. [Explanation of symbols]

[0080] 10, 10a... Secure element, 11, 11a... Control unit, 12, 12a... Storage unit, 20... Electronic device, 21... Control unit, 22... Storage unit, 111, 111a... Applet unit, 112, 112a... OS unit, 121... Key generation information, 122, 122a... Communication driver, 123, 123a... Encryption library, 210... Control unit, 211... Application unit, 221... Key generation information, 1221, 1221a... Key generation support information

Claims

1. a storage unit that stores key generation support information indicating information that is supported as information used for key generation using elliptic curve cryptography; a control unit that, before the key generation, confirms whether or not key generation information acquired as information used in the key generation is supported information based on the key generation support information; A secure element comprising:

2. the information used for key generation includes information indicating a key length of a key to be generated, the control unit, before the key generation, checks whether the key length indicated by the key generation support information matches the key length indicated by the key generation information, and does not perform the key generation if they do not match. The secure element of claim 1 .

3. the information used for key generation includes information indicating elliptic curve parameters necessary for elliptic curve cryptography; the control unit, before the key generation, checks whether the elliptic curve parameters indicated by the key generation support information match the elliptic curve parameters indicated by the key generation information, and does not perform the key generation if they do not match. The secure element according to claim 1 or 2.

4. the storage unit further stores a communication driver, and statically holds the key generation support information in the communication driver. The secure element of claim 1 .

5. a storage step of storing key generation support information indicating information supported as information used for key generation using elliptic curve cryptography in the secure element; a control step of confirming, before the key generation in the secure element, whether or not key generation information acquired as information used in the key generation is supported information, based on the key generation support information; 1. A computer-implemented key generation method comprising:

6. Secure Element computers, a storage means for storing key generation support information indicating information supported as information used for key generation using elliptic curve cryptography in the secure element; a control means for confirming, before the key generation in the secure element, whether or not key generation information acquired as information used in the key generation is supported information, based on the key generation support information; A program to function as a

Citation Information

Patent Citations

  • Key forming method of elliptic curve cipher and its apparatus

    JP2000181351A