Method of granting right of IC card, method of controlling IC card, and IC card

The method allows IC cards to grant selective administrator commands to newly added elements, addressing the limitations of existing IC card specifications by enabling secure and controlled operation through stored authority information and execution conditions.

JP2025078425APending Publication Date: 2025-05-20TOPPAN HOLDINGS INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023190981
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-08
Publication Date
2025-05-20

AI Technical Summary

Technical Problem

Existing IC card specifications, particularly those adhering to the Global Platform standard, do not allow for granting specific administrator commands to application-specific elements, limiting the full adaptation of new applications due to hierarchical and command execution authority constraints.

Method used

A method is introduced to install a second element and a third element under a first element in the IC card, with authority information stored to grant the second element the ability to execute administrator commands, allowing selective command execution based on predefined conditions.

Benefits of technology

Enables the granting of administrator commands to newly added elements, ensuring secure and controlled operation of IC cards by allowing selective command execution and authentication, thus facilitating the integration of new applications without altering the administrator hierarchy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025078425000001_ABST
    Figure 2025078425000001_ABST
Patent Text Reader

Abstract

To grant a right to execute an administrator command to a new element added to an IC card.SOLUTION: A method of granting a right of an IC card includes: a step of installing a second element (AP) and a third element (EF) under the second element, under a first element (SSD1) set to an IC card; and a step of storing, in a storage unit of the IC card, right information to grant a right to execute an administrator command for the second element to manage the second element.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an IC card authorization method, an IC card control method, and an IC card. [Background technology]

[0002] Traditionally, the main commands used in IC (Integrated Circuit) cards have been specified as an international standard by ISO / IEC7816-4 (hereinafter referred to as the ISO standard). In addition, Global Platform (hereinafter referred to as GP) exists as a standard for safely managing and operating multiple APs (applications) that are assumed to be installed in an IC card. "Card Specification Version 2.3.1" specified by GP includes commands for loading and installing APs in IC cards, as well as mutual authentication commands for building a secure channel.

[0003] FIG. 12 is a diagram showing an example of the internal structure of an IC card according to the ISO standard, and FIG. 13 is a diagram showing an example of the internal structure of an IC card according to the GP specification. In the ISO standard, the information organization structure in an IC card is made up of three elements: MF (Master file), DF (Dedicated file), and EF (Elementary file). In computer science, MF is equivalent to the root directory, DF is a folder, and EF is a data file.

[0004] In contrast, the GP specification has a concept called SD (Security Domain), which implements secure management of the entire or divided areas of an IC card. SD consists of ISD (Issuer Security Domain) and SSD (Supplementary Security Domains). Only one ISD can exist in an IC card, but multiple SSDs can exist in an IC card.

[0005] 12 and 13, the MF in the ISO standard corresponds to the ISD in the GP specification, and the DF in the ISO standard corresponds to the SSD or AP in the GP specification. In the GP specification, the AP is installed under each SD (ISD or SSD), and the AP is managed for each SD.

[0006] Techniques for granting authority to elements in such IC cards include those described in Patent Documents 1 and 2, for example. Patent Document 1 describes a method for changing the authorized person of an IC card online. In this method, in addition to an authorized person device that has the authority to issue, manage, and operate cards, multiple authorized person candidate devices are prepared, and access rights are set so that the IC card cannot execute all or some of the commands without the signature of the new authorized person device. Patent document 2 describes that if there is information to inherit a key used for secure messaging from a first folder to a second folder, the key used for secure messaging established while the first folder is selected is also inherited by the second folder. [Prior art documents] [Patent documents]

[0007] [Patent Document 1] JP 2004-015598 A [Patent Document 2] JP 2016-027505 A Summary of the Invention [Problem to be solved by the invention]

[0008] A multi-application IC card that complies with the GP specifications is configured as shown in Figure 13. The commands that can be used by the SD and the commands that can be used by APs installed under the SD and managed by the SD are often different. This is to ensure safe operation by clearly separating the administrator (SD) and user (AP) in the IC card so that only the appropriate administrator can load, delete, disable, etc. APs.

[0009] However, depending on the operation method, some installed APs may want to execute administrator commands such as disablement by themselves, but the existing GP specifications do not take into consideration granting APs the authority to use administrator commands. Therefore, when installing a new AP on an IC card, if some of the commands defined in the original AP specifications correspond to administrator commands in the specifications of the installed IC card, the specifications of the original AP cannot be fully adapted in the IC card.

[0010] In response to this, it is possible in practice to give the authority of administrator commands to an AP by applying the method described in Patent Document 1. However, since the method described in Patent Document 1 is a technology that assumes that the administrator will be changed, it is not possible to give the authority of only some commands to an AP without changing the administrator.

[0011] In addition, in the technology described in Patent Document 2, the security status established in the DF (AP) can be inherited to a higher hierarchy or the same hierarchy, but it is not targeted at commands. In addition, in the technology described in Patent Document 2, the hierarchical relationship between the first folder and the second folder is not specified.

[0012] The present disclosure has been made in view of the above circumstances, and aims to provide an authority granting method for an IC card that can grant authority to execute administrator commands to an element newly added to the IC card. The present disclosure also aims to provide an IC card control method that can control an element newly added to the IC card using administrator commands. Furthermore, the present disclosure also aims to provide an IC card that grants authority to execute administrator commands to a newly added element and can control the element newly added to the IC card using administrator commands. [Means for solving the problem]

[0013] The present disclosure has been made to solve the above-mentioned problems, and one aspect of the present disclosure is a method for granting authority to an IC card, comprising the steps of installing a second element and a third element under a first element set in the IC card, and storing authority information in a memory section of the IC card that grants the second element authority to execute administrator commands that manage the second element.

[0014] Another aspect of the present disclosure is a method for controlling an IC card having a second element and a third element installed under a first element, the method including the steps of accepting an administrator command for managing the second element, and executing the administrator command by the second element if authority to execute the accepted administrator command is granted by authority information stored in a memory unit of the IC card.

[0015] Another aspect of the present disclosure is an IC card comprising: a first element that outputs a first administrator command; a second element that is installed under the first element and performs processing based on the first administrator command output from the first element and outputs a second administrator command; a third element that is installed under the first element together with the second element and performs processing based on the second administrator command output from the second element; and a memory unit that stores authority information that grants execution authority for a third administrator command that manages the second element, wherein the second element performs processing based on the authority information stored in the memory unit. Effect of the Invention

[0016] According to one aspect of the present invention, it is possible to grant authority to execute administrator commands from the higher level to the lower level in the elements in the IC card. Also, an element newly added to the IC card can be controlled using the administrator command. Furthermore, authority to execute administrator commands is granted to the newly added element, and the newly added element can be controlled using the administrator command. [Brief description of the drawings]

[0017] [Figure 1] FIG. 13 is a diagram illustrating the integration of multiple IC cards in an embodiment. [Diagram 2] (A) is a diagram showing an example of the functional configuration of IC card A in an embodiment, and (B) is a diagram showing an example of functional elements when the functions of IC card B are installed in IC card A. [Diagram 3] 4 is a diagram for explaining authority information stored in an IC card in the embodiment. FIG. [Figure 4] 1A and 1B are diagrams showing an example of authority information in an embodiment, in which (A) is an explanatory diagram of authority information, and (B) is a diagram showing a plurality of administrator commands and user commands set in AP2. [Diagram 5] FIG. 2 is a diagram illustrating a relationship between an SSD, an AP, and an EF according to an embodiment. [Figure 6] 4 is a diagram for explaining execution condition information stored in an IC card in the embodiment. FIG. [Figure 7] FIG. 4 is a diagram showing an example of execution condition information according to the embodiment. [Figure 8] 1 is a block diagram showing an example of a configuration of an IC card 100 according to an embodiment. [Figure 9] FIG. 4 is a diagram illustrating an example of a command format according to the embodiment. [Figure 10] 10 is a flowchart showing an example of a process for setting authority information and execution condition information of an AP in the IC card 100 according to the embodiment. [Figure 11] 10 is a flowchart showing an example of a process for using an administrator command by an AP of the IC card 100 in the embodiment. [Figure 12] FIG. 1 is a diagram showing an example of the internal structure of an IC card in accordance with the ISO standard. [Figure 13] FIG. 2 is a diagram showing an example of the internal configuration of an IC card in accordance with the GP specifications. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0018] Hereinafter, an IC card authorization method, an IC card control method, and an IC card to which the present invention is applied will be described with reference to the drawings.

[0019] FIG. 1 is a diagram for explaining how a plurality of IC cards are integrated together in an embodiment. Figure 2 (A) is a diagram showing an example of the functional configuration of IC card A in an embodiment, and (B) is a diagram showing an example of functional elements when the functions of IC card B are installed in IC card A. As shown in Fig. 1, there are cases where it is desired to integrate the functions of IC cards B, C, and D into IC card A. Examples of IC cards include credit cards, cash cards, prepaid cards, commuter passes, passenger tickets, student ID cards, point cards, and personal identification cards such as driver's licenses. For example, as shown in Fig. 2(A), IC card A is equipped with ISD, AP1, EF1-1, EF1-2, SSD1, and EF2-1 as elements for functioning as IC card A.

[0020] ISD (Issuer Security Domain) is the security domain of the card issuer. SSD (Supplementary Security Domain) is the security domain of an application provider other than the card issuer. AP is an application function provided by an application provider other than the card issuer. The ISD and SSD manage the elements under them by having elements set under them and outputting administrator commands to the elements. Administrator commands are commands that manage the operation of elements, such as deleting an element, enabling an element, or disabling an element. The AP is an element that executes the IC card, and outputs user commands to the EF under it. The EF has the function of storing data.

[0021] For example, when installing the function of IC card B in IC card A, the elements for realizing the function of IC card B are installed under SSD1 as shown in Fig. 2(B). The elements for realizing the function of IC card B include, for example, AP2, EF3-1, and EF3-2. As a result, when using the function of IC card B using IC card A, the function of IC card B can be realized by selecting AP2 and performing processing by AP2.

[0022] In the embodiment, the installation of functions of IC card B into IC card A will be described, but when installing functions of other IC cards into IC card A, they will also be installed under the ISD or SSD of IC card A, just like IC card B.

[0023] FIG. 3 is a diagram for explaining authority information stored in an IC card in the embodiment. The IC card stores management information of AP2 newly installed in the IC card and data of AP2. The data of AP2 is, for example, data (entity) representing an element (EF) installed under AP2. The management information of AP2 is, for example, attribute information of AP2, an ID of AP2, and a data size of AP2. The IC card stores authority information as management information of AP2. The authority information is information for granting the second element (AP2) authority to execute an administrator command that manages the second element.

[0024] When there are multiple administrator commands set in the second element, the authority information may be information indicating administrator commands for which execution authority has been granted by the second element among the multiple administrator commands set in the second element. The multiple administrator commands set in AP2 are administrator commands for realizing the functions of IC card B. The multiple administrator commands set in AP2 may be multiple administrator commands that are executable when AP2 is implemented as an ISD or SSD in IC card B.

[0025] 4 is a diagram showing an example of authority information in an embodiment, where (A) is an explanatory diagram of the authority information, and (B) is a diagram showing a plurality of administrator commands and user commands set in AP 2. In Fig. 4, hexadecimal numbers are represented using the prefix "0x", and binary numbers (bit notation) are represented using the prefix "0b".

[0026] The authority information is written as, for example, "0x42" in hexadecimal and converted to "0100 0010" in binary. The binary "0100 0010" is assigned to administrator commands #1 to #8 set in AP2. Administrator commands corresponding to "1" in binary are administrator commands that AP2 is authorized to execute, and administrator commands corresponding to "0" in binary are administrator commands that AP2 is authorized to execute. In the example of FIG. 4(A), AP2 is granted the authority to execute administrator commands #2 and #7 in FIG. 4(B).

[0027] In the example shown in Figure 4, the authority information is 1 byte (8 bits) and there are 8 administrator commands, but this is not limited to this and the authority information may have a greater number of bits. For example, if there are 16 types of administrator commands, 2 bytes of authority information are required.

[0028] FIG. 5 is a diagram showing the relationship between SSDs, APs, and EFs in the embodiment. When AP2 and EF3-1 are installed in IC card A to realize the functions of IC card B, AP2 is given the authority to execute administrator commands #2 and #7 out of administrator commands #1 to #8 that AP2 had authority to execute when implemented in IC card B. AP2 can perform processes based on administrator commands received from SSD1, processes based on administrator commands #2 and #7 for which it has been given authority to execute, and processes to output user commands to subordinate EF3-1.

[0029] 6 is a diagram for explaining execution condition information stored in an IC card in an embodiment. In the IC card, execution condition information may be stored in addition to authority information as management information for an AP 2 newly installed in the IC card.

[0030] FIG. 7 is a diagram illustrating an example of execution condition information according to the embodiment. The execution condition information is information indicating the execution conditions of an administrator command for which execution authority has been granted by the authority information. The execution condition information makes it possible to permit execution of a management command when the execution condition of the management command is satisfied. The execution condition information is stored as management information of AP2. The execution condition information may be set for each administrator command for which execution authority has been granted by the authority information. The execution condition information indicates, for example, the correspondence between values ​​and the execution conditions of administrator commands. For example, the value "0xA1" corresponds to password authentication, the value "0xB2" corresponds to signature verification using RSA encryption, the value "0xC3" corresponds to signature verification using elliptic curve encryption, and the value "0xD4" corresponds to mutual authentication using common key encryption. For example, when the value "0xB2" is transmitted from the reader / writer, the IC card performs processing with signature verification using RSA encryption as the execution condition.

[0031] The method of specifying the file required for authentication may be any existing method, such as storing information dedicated to file specification, specification by a selection command, implicit specification (no specification), etc. Also, the execution condition information is one byte, but may have multiple bytes of information according to the operational policy.

[0032] FIG. 8 is a block diagram showing an example of a configuration of an IC card 100 according to the embodiment. The IC card 100 includes, for example, a CPU 110 (Central Processing Unit), an I / O 120, a ROM 130 (Read Only Memory), a RAM 140 (Random Access Memory), and an EEPROM 150 (Electrically Erasable Programmable Read Only Memory).

[0033] The I / O 120 communicates with external devices such as a reader / writer 200. The reader / writer 200 communicates with the IC card 100 under the control of an information processing device, for example. The I / O 120 receives, for example, an administrator command or a user command from the reader / writer 200. The communication between the I / O 120 and the reader / writer 200 may be of a contact type or a contactless type. That is, the I / O 120 may have only a configuration corresponding to the contact type as a configuration of the physical layer, or may have only a configuration corresponding to the contactless type as a configuration of the physical layer. Furthermore, the I / O 120 may have both a configuration corresponding to the contact type and a configuration corresponding to the contactless type as a configuration of the physical layer.

[0034] The CPU 110 includes a register 112, a processing unit 114, and a control unit 116. The register 112 is a storage device built into the CPU. The register 112 temporarily stores data related to the processing of the CPU 110, for example. The processing unit 114 executes programs stored in the ROM 130 and the EEPROM 150, and performs various processes in the IC card 100. For example, the processing unit 114 executes command processing according to a command received from the reader / writer 200 via the I / O 120. The control unit 116 performs processes such as communication control of the I / O 120, reading data from the ROM 130, and writing and reading data to and from the RAM 140 and the EEPROM 150.

[0035] The ROM 130 is, for example, a non-writable non-volatile memory, and stores programs and data for executing various processes in the IC card 100. The ROM 130 is incorporated in the IC card 100 in a state in which the programs and data are stored during the manufacturing stage. The RAM 140 is, for example, a non-writable volatile memory, and temporarily stores data used when performing various processes in the IC card 100. The EEPROM 150 is, for example, an electrically rewritable non-volatile memory. The EEPROM 150 stores, for example, control programs, control data, applications, personal information, security information such as encryption keys, data used in applications, and the like.

[0036] Fig. 9 is a diagram showing an example of a command format in the embodiment. The command format in Fig. 9 may be compliant with, for example, the international standard ISO / IEC7816-4. The command format shown in Fig. 9(A) includes, for example, a CLA section, an INS section, a parameter P1 section, and a parameter P2 section. The CLA section is called a class byte. The INS section is called a command byte and includes an instruction code corresponding to the command. The parameter P1 section and the parameter P2 section include parameters specified in the command. 9B includes a CLA section, an INS section, a parameter P1 section, a parameter P2 section, and an Le section. The Le section indicates that a data field is requested as a response to the command. The command format shown in Fig. 9(C) includes a CLA section, an INS section, a parameter P1 section, a parameter P2 section, an Lc section, and a data field DF section. The Lc section indicates the length of the data field DF section. The data field DF section includes data used in processing the command. The data used in processing the command is, for example, a parameter related to management information of the AP. The data field DF section of the INSTALL command can store the above-mentioned authority information (1 byte) and execution condition information (1 byte). The command format shown in FIG. 9(D) includes a CLA portion, an INS portion, a parameter P1 portion, a parameter P2 portion, an Lc portion, and a data field DF portion, and an Le portion.

[0037] For example, the CPU 110 uses a LOAD command or an INSTALL command when installing an AP compatible with IC card B in IC card A. At this time, the CPU 110 uses the command format shown in Fig. 9(D), and depending on the specifications, the command format in Fig. 9(C) is used.

[0038] FIG. 10 is a flowchart showing an example of a process for setting the authority information and execution condition information of an AP in the IC card 100 according to the embodiment. First, it is assumed that, for example, AP2, EF3-1, and EF3-2 are installed under SSD1 as new functions in IC card 100 as shown in FIG. 2(B).

[0039] The reader / writer 200 sets the AP parameter #1 in the LOAD command of the AP (step S100), and transmits the LOAD command of the AP (step S102). The IC card 100 receives the AP LOAD command from the reader / writer 200 (step S200) and checks for errors in the LOAD command (step S202). The IC card 100 determines whether there is an error in the LOAD command (step S204), and if there is an error (step S204: NO), it performs error processing (step S208) and transmits a status word: NG (step S210). If there is no error in the LOAD command (step S204: YES), the IC card 100 stores the AP parameter #1 in, for example, the EEPROM 150 (step S206), and transmits a status word: OK (step S210).

[0040] The reader / writer 200 receives the status word from the IC card 100 (step S104), sets the AP parameter #2 in the AP INSTALL command (step S106), and transmits the AP INSTALL command (step S108).

[0041] The IC card 100 receives the INSTALL command from the reader / writer 200 (step S212) and checks for errors in the INSTALL command (step S214). The IC card 100 determines whether there is an error in the INSTALL command (step S216), and if there is an error (step S216: NO), it performs error processing (step S220) and transmits a status word: NG (step S222). If there is no error in the INSTALL command (step S216: YES), the IC card 100 stores AP parameter #2 in, for example, the EEPROM 150 (step S218), and transmits a status word: OK (step S222). The reader / writer 200 receives the status word from the IC card 100 (step S110).

[0042] The IC card 100 can obtain the authority information and execution condition information stored in the data field DF of the AP parameter #1 of the LOAD command or the AP parameter #2 of the INSTALL command, and store it as management information for the AP.

[0043] FIG. 11 is a flowchart showing an example of a process for using an administrator command by the AP of the IC card 100 in the embodiment. First, the reader / writer 200 transmits an authentication command suitable for the execution conditions of the administrator command (step S120). The authentication command is an execution condition corresponding to the administrator command shown in Fig. 7. For example, it is signature verification by RSA encryption shown in Fig. 7.

[0044] The IC card 100 receives an authentication command from the reader / writer 200 (step S230) and performs an authentication check (step S232). The IC card 100 determines whether the authentication is successful or not by the authentication check (step S234). If the authentication is unsuccessful (step S234: NO), the IC card 100 performs error processing (step S238) and transmits a status word: NG (step S240). If the authentication is successful (step S234: YES), the IC card 100 enables (ON) an administrator command execution permission flag (step S236) and transmits a status word: OK (step S240). The administrator command execution permission flag is stored in the register 112.

[0045] The reader / writer 200 receives a status word from the IC card 100 (step S122), and transmits an administrator command #N (N is a natural number) (step S124).

[0046] The IC card 100 receives the administrator command #N from the reader / writer 200 (step S242) and checks whether the received administrator command #N is an administrator command to which authority is to be granted based on the authority information (step ST246). At this time, the IC card 100 checks whether the received administrator command #N is an administrator command assigned to the bit "1" as the authority information shown in FIG. 4(a).

[0047] If the received administrator command #N is not an administrator command to be authorized (step S246: NO), the IC card 100 performs error processing (step S254) and transmits a status word: NG (step S256). If the received administrator command #N is an administrator command to be authorized (step S246: YES), the IC card 100 checks whether the execution permission flag of the administrator command is enabled (ON) or not (step S248). If the execution permission flag of the administrator command is not enabled (ON) (step S250: NO), the IC card 100 performs error processing (step S254) and transmits a status word: NG (step S256). If the execution permission flag of the administrator command is enabled (ON) (step S250: YES), the IC card 100 processes the administrator command #N (step S252) and transmits a status word: OK (step S256). The reader / writer 200 receives the status word from the IC card 100 (step S126).

[0048] (Effects of the embodiment) As described above, according to the embodiment, it is possible to realize an authority granting method for an IC card, which includes the steps of installing a second element (AP) and a third element (EF) under the second element (AP) under a first element (SSD) set in IC card 100 as shown in Fig. 2, and storing authority information in a storage unit (150) of IC card 100, which grants the second element (AP) authority to execute administrator commands that manage the second element (AP), as shown in Fig. 10. According to this embodiment, it is possible to grant authority to execute administrator commands to an element newly added to IC card 100.

[0049] According to the embodiment, a method for controlling an IC card 100 in which a second element (AP) and a third element (EF) under the second element are installed under a first element (SSD) can be realized, the method including the steps of accepting an administrator command for managing the second element, and executing the administrator command by the second element when the authority to execute the accepted administrator command is granted by the authority information stored in the storage unit of the IC card. According to this embodiment, an element newly added to the IC card 100 can be controlled using the administrator command.

[0050] According to the embodiment, an IC card can be realized that includes a first element (SSD) that outputs a first administrator command, a second element (AP) that is installed under the first element and performs processing based on the first administrator command output from the first element and outputs a second administrator command, a third element (EF) that is installed under the first element together with the second element and performs processing based on the second administrator command output from the second element, and a storage unit (150) that stores authority information that grants execution authority of a third administrator command that manages the second element, and the second element performs management processing based on the authority information stored in the storage unit. According to this embodiment, an authority to execute administrator commands is granted to an element newly added to the IC card, and the newly added element can be controlled using the administrator command.

[0051] Furthermore, according to the embodiment, the authority information indicating an administrator command to which execution authority has been granted by the second element among a plurality of administrator commands (a plurality of third administrator commands) set in the second element can be used to grant authority to selectively execute a specific command among the administrator commands originally set in the second element.

[0052] Furthermore, according to the embodiment, execution condition information indicating the execution conditions of an administrator command for which execution authority has been granted by the authority information is stored, so that it is possible to verify that the person is a legitimate administrator of the second element (AP) and execute the administrator command for which authority has been granted.

[0053] Although each embodiment and variant example has been described, these are merely examples and are not intended to be limiting. For example, any of the embodiments or variant examples, or a part of each embodiment or a part of each variant example, may be combined with one or more other embodiments or one or more other variant examples to realize one aspect of the present invention. [Explanation of symbols]

[0054] 100... IC card, 110... CPU, 112... register, 114... processing unit, 116... control unit, 150... EEPROM, 200... reader / writer

Claims

1. installing a second element and a third element under the second element under the first element set in the IC card; storing authority information for granting the second element authority to execute an administrator command that manages the second element in a storage unit of the IC card; 2. A method for authorizing an IC card, comprising:

2. The IC card authorization method according to claim 1 , wherein the authority information is information indicating an administrator command among a plurality of administrator commands set in the second element, the administrator command being granted execution authority by the second element.

3. 3. The IC card authorization method according to claim 2, further comprising the step of: storing, in said storage unit, execution condition information indicating execution conditions of an administrator command for which execution authority has been granted by said authority information.

4. A method for controlling an IC card in which a second element and a third element subordinate to the second element are installed under a first element, the method comprising the steps of: accepting an administrator command to manage the second factor; executing the administrator command by the second element when the execution authority of the received administrator command is granted by the authority information stored in the storage unit of the IC card; A method for controlling an IC card, comprising:

5. The IC card control method according to claim 4 , wherein the authority information is information indicating an administrator command among a plurality of administrator commands set in the second element, the administrator command being granted execution authority by the second element.

6. the storage unit stores condition information indicating execution conditions of an administrator command for which execution authority is granted by the authority information; when execution authority for the administrator command is granted by the authority information stored in the storage unit of the IC card and an execution condition for the administrator command is satisfied, the administrator command is executed by the second element. A method for controlling an IC card according to claim 4.

7. a first element for outputting a first administrator command; a second element that is installed under the first element, performs processing based on the first administrator command output from the first element, and outputs a second administrator command; a third element that is installed under the first element together with the second element and performs processing based on the second administrator command output from the second element; a storage unit that stores authority information that grants execution authority of a third administrator command that manages the second element, The second element is an IC card that performs processing based on the authority information stored in the storage unit.

8. The IC card according to claim 7, wherein the authority information is information indicating a third administrator command among a plurality of third administrator commands set in the second element, the third administrator command being granted execution authority by the second element.

9. the storage unit stores condition information indicating an execution condition of a third administrator command for which execution authority is granted by the authority information; the second element performs a process based on the third administrator command when an execution condition indicated by the condition information is satisfied; 9. The IC card according to claim 8.

Citation Information

Patent Citations

  • Method and system for changing authorized person of IC card on-line

    JP2004015598A

  • IC card, portable electronic device, and IC card control method

    JP2016027505A