Portable electronic device, information processing system, and information processing method

The portable electronic device ensures secure transactions by performing authentication operations and storing execution histories, preventing unauthorized transactions by only transmitting data after successful authentication.

JP2025079134APending Publication Date: 2025-05-21KK TOSHIBA +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023191610
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-09
Publication Date
2025-05-21

AI Technical Summary

Technical Problem

Existing systems for IC passports and information processing devices may fail to identify counterfeit ePassports due to the ability to operate normally even if internal authentication commands are skipped or their execution order is changed, leading to potential unauthorized transactions.

Method used

A portable electronic device equipped with an interface for communication, a processor for executing operations based on commands, and a memory for storing execution histories. The processor performs authentication operations, stores execution histories, and only transmits requested data if the authentication has been successfully executed.

Benefits of technology

Prevents transactions without authenticity verification by ensuring that data is only transmitted after successful authentication, thereby enhancing the security of IC passport systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025079134000001_ABST
    Figure 2025079134000001_ABST
Patent Text Reader

Abstract

To provide a portable electronic device that prevents transactions without authenticity verification.SOLUTION: A portable electronic device according to an embodiment includes an interface for communicating with an information processing device, a processor for executing an operation based on a command, and a memory for storing target data. The processor executes an authentication operation on the basis of an authentication command transmitted from the information processing device, causes the memory to store an execution history indicating the execution of the authentication operation, and, when the execution history is stored, causes the target data requested by a read command transmitted from the information processing device to be transmitted to the information processing device.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] FIELD OF THE DISCLOSURE Embodiments of the present invention relate to portable electronic devices, information processing systems, and information processing methods. [Background technology]

[0002] Security devices such as IC cards equipped with an IC (Integrated Circuit) chip have become widespread and are used as credit cards and IC passports. IC cards are called portable electronic devices because they are carried by users.

[0003] For example, information processing devices that read ePassports perform a process called Active Authentication (AA) to verify the authenticity of the ePassport. This process is realized by an internal authentication command defined in ISO / IEC 7816-4. However, the commands defined in ISO / IEC 7816-4 are often highly independent, and the information processing device may operate normally even if it changes the execution order of the internal authentication commands or skips the execution of the internal authentication commands. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2010-92250 A Summary of the Invention [Problem to be solved by the invention]

[0005] There are several issues regarding the system of IC passports and information processing devices. (1) Since the information processing device operates normally even if the execution of the internal authentication command is skipped, it may not be possible to identify a counterfeit ePassport. (2) Even if the information processing device executes an internal authentication command, it may be unable to identify a counterfeit ePassport because the information processing device may continue processing without verifying the authentication data. (3) The information processing device can use the data read from the ePassport without verifying the authenticity of the ePassport.

[0006] An object of the present invention is to provide a portable electronic device, an information processing system, and an information processing method that prevent transactions without authenticity verification. [Means for solving the problem]

[0007] A portable electronic device according to an embodiment includes an interface for communicating with an information processing device, a processor for executing an operation based on a command, and a memory for storing target data. The processor executes an authentication operation based on an authentication command transmitted from the information processing device, stores an execution history in the memory indicating the execution of the authentication operation, and, if the execution history is stored, transmits the target data requested by a read command transmitted from the information processing device to the information processing device. [Brief description of the drawings]

[0008] [Figure 1] FIG. 1 is a block diagram showing an example of an information processing system including an IC card as a portable electronic device according to an embodiment, and an IC card processing device as an information processing device that communicates with the IC card. [Diagram 2] FIG. 2 is a block diagram illustrating an example of the configuration of an IC card according to the embodiment. [Diagram 3] FIG. 3 is a sequence diagram illustrating an example of the BAC according to the embodiment. [Figure 4A] FIG. 4A is a sequence diagram illustrating an example of a PACE according to the embodiment. [Figure 4B] FIG. 4B is a sequence diagram illustrating an example of a PACE according to the embodiment. [Diagram 5]FIG. 5 is a sequence diagram illustrating an example of the first data read process according to the embodiment. [Figure 6] FIG. 6 is a sequence diagram illustrating an example of the second data read process according to the embodiment. [Figure 7A] FIG. 7A is a sequence diagram showing an example of a third data read process according to the embodiment. [Figure 7B] FIG. 7B is a sequence diagram showing an example of the third data read process according to the embodiment. [Figure 8] FIG. 8 is a sequence diagram showing an example of the fourth data read process according to the embodiment. [Figure 9] FIG. 9 is a sequence diagram illustrating an example of the fifth data read process according to the embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a signature generation algorithm (Sign by Dilithium) in the data read process. [Figure 11] FIG. 11 is a diagram showing an example of a signature verification algorithm in the data reading process (Verify by Dilithium). DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0009] Hereinafter, embodiments will be described with reference to the drawings. FIG. 1 is a block diagram showing an example of an information processing system including an IC card as a portable electronic device according to an embodiment, and an IC card processing device as an information processing device that communicates with the IC card.

[0010] 1, the information processing system includes an IC card processing device 1 and an IC card 2. The IC card processing device 1 is a higher-level device that supplies commands to the IC card 2 and receives responses from the IC card 2.

[0011] In the exemplary configuration shown in FIG. 1, the IC card processing device 1 includes a CPU (Central Processing Unit) 11, a display 12, an operation unit 13, a card reader / writer 14, an OCR (Optical Character Recognition or Optical Character Reader) 15, and a storage unit 16.

[0012] The CPU 11 is a processor that controls the overall operation of the IC card processing device 1. The CPU 11 performs various processes based on the control programs and control data stored in the storage unit 16. For example, the CPU 11 executes a program stored in a memory such as the storage unit 16 to control the operation of the IC card processing device 1 or to perform various processes according to the operating mode of the IC card processing device 1. Note that some of the various functions may be realized by a hardware circuit. In this case, the CPU 11 controls the functions executed by the hardware circuit.

[0013] The display 12 is a display device that displays various information under the control of the CPU 11. The display 12 is, for example, a liquid crystal monitor.

[0014] Various operation instructions and data are input to the operation unit 13 by a user of the IC card processing device 1. The operation unit 13 transmits the input operation instructions and data to the CPU 11. The operation unit 13 is, for example, a keyboard, a numeric keypad, or a touch panel.

[0015] The card reader / writer 14 is an interface that communicates with the IC card 2. The card reader / writer 14 is configured with an interface that complies with a predetermined communication protocol of the IC card 2, etc.

[0016] For example, when the IC card 2 is a contact type IC card, the card reader / writer 14 complies with, for example, ISO / IEC 7816 and is composed of a contact unit for physically and electrically connecting to the contact unit of the IC card 2. When the IC card 2 is a non-contact type IC card, the card reader / writer 14 complies with, for example, ISO / IEC 14443 and is composed of an antenna for wireless communication with the IC card 2, a communication control unit, and the like.

[0017] Furthermore, if the IC card 2 is a dual card that supports both the contact type and the contactless type, the card reader / writer 14 of the IC card processing device 1 is configured to support the dual card. That is, the card reader / writer 14 is configured with a communication control unit and a contact unit for physically and electrically contacting the communication unit 25 of the IC card 2 to transmit and receive signals, and a communication control unit such as a modulation / demodulation circuit for wireless communication with the communication unit 25 of the IC card 2, and an antenna.

[0018] Furthermore, the card reader / writer 14 performs power supply, clock supply, reset control, and data transmission / reception for the IC card 2. For example, the card reader / writer 14 activates (starts up) the IC card 2 under the control of the CPU 11, transmits various commands, and receives responses to the transmitted commands.

[0019] The OCR 15 is an interface that acquires information from the IC card 2. Optically readable information, such as a combination of letters, numbers, and symbols, a barcode, or a QR code (registered trademark), is printed on the IC card 2. The OCR 15 optically reads this information and outputs the read result to the CPU 11.

[0020] The IC card processing device 1 includes a card reader / writer 14 and an OCR 15, and obtains information from the IC card 2 via these two independent paths.

[0021] The storage unit 16 is equipped with non-volatile and volatile memory. The non-volatile memory stores control programs and control data in advance, while the volatile memory temporarily stores data being processed by the CPU 21, and functions as a receiving buffer, a calculation buffer, and a sending buffer.

[0022] Next, the IC card 2 will be described. The IC card 2 is activated and put into an operable state by receiving power and other supplies from a higher-level device such as the IC card processing device 1. For example, when the IC card 2 is connected to the IC card processing device 1 by contact-type communication, that is, when the IC card 2 is configured as a contact-type IC card, the IC card 2 is activated by receiving operating power and an operating clock from the IC card processing device 1 via a contact unit serving as a communication interface.

[0023] In addition, when the IC card 2 is connected to the IC card processing device 1 via a contactless communication method, that is, when the IC card 2 is configured as a contactless IC card, the IC card 2 receives radio waves from the IC card processing device 1 via an antenna and a modulation / demodulation circuit as a communication interface, and activates itself by generating operating power and an operating clock from the radio waves using the power supply unit.

[0024] The IC card 2 also has a Machine Readable Zone (MRZ) 20 on one or both sides of the card, and the MRZ includes optically readable printed information, such as a combination of letters, numbers and symbols, a barcode, or a QR code.

[0025] Next, a configuration example of the IC card 2 will be described. FIG. 2 is a block diagram illustrating an example of the configuration of an IC card according to the embodiment. The IC card 2 has a card-shaped main body C made of plastic or the like. The IC card 2 has a module M built into the main body C. The module M is formed integrally with one or more IC chips Ca and an external interface for communication in a connected state, and is embedded in the main body C of the IC card 2. As shown in Fig. 2, the module M of the IC card 2 includes a CPU 21, a ROM 22, a RAM 23, an NVM 24, and a communication unit 25. These units are connected to each other via a data bus.

[0026] The CPU 21 is a processor that functions as a control unit that controls the entire IC card 2. The CPU 21 performs various processes based on the control programs and control data stored in the ROM 22 or the NVM 24. For example, the CPU 21 executes a program stored in the ROM 22 to control the operation of the IC card 2 or to perform various processes according to the operating mode of the IC card 2. The CPU also performs various processes based on commands from the IC card processing device 1. Note that some of the various functions may be realized by a hardware circuit. In this case, the CPU 21 controls the functions executed by the hardware circuit.

[0027] The ROM 22 is a non-volatile memory that stores control programs, control data, encryption information, card identification information, and the like in advance. The ROM 22 is incorporated into the IC card 2 in a state in which the control programs and control data are stored in the manufacturing stage. That is, the programs, control data, encryption information, and card identification information stored in the ROM 22 are incorporated in advance according to the specifications of the IC card 2. The ROM 22 may be configured with a flash memory, and may be written in the manufacturing stage, or may be written and rewritten in a subsequent phase. Information regarding encryption may be written in the manufacturing stage, or may be written and updated in a subsequent phase.

[0028] The encryption information includes an encryption algorithm and a key length supported by the IC card 2. The card identification information is unique information that can identify the IC card 2. The MRZ20 includes the card identification information as optically readable printed information such as a combination of letters, numbers, and symbols, a barcode, or a QR code. The MRZ20 may include all of the card identification information, or may include a part of the card identification information. The form in which the MRZ20 includes the card identification information may be a form other than printing. For example, if the card identification information is a combination of letters, numbers, and symbols, the MRZ20 may include embossing corresponding to the card identification information. The above encryption algorithm is, for example, post-quantum cryptography (PQC), which is considered difficult to calculate with a quantum computer.

[0029] The RAM 23 is a volatile memory. The RAM 23 temporarily stores data being processed by the CPU 21. For example, the RAM 23 includes a receiving buffer, a calculation buffer, a transmission buffer, and the like. The receiving buffer holds data transmitted from the IC card processing device 1 and received via the communication unit 25. The calculation buffer holds temporary results for the CPU 21 to perform various calculations. The transmission buffer holds data to be transmitted to the IC card processing device 1 via the communication unit 25.

[0030] The NVM 24 is composed of a non-volatile memory such as an EEPROM or a flash ROM to which data can be written and rewritten. The NVM 24 stores control programs, applications, and various data according to the operational use of the IC card 2. For example, program files and data files are created in the NVM 24. The control programs and various data are written into each created file. An example of a data file is an elementary file (EF). The EF includes card identification information, a facial image, an AA public key, and a security object (static certificate). The card identification information printed on the MRZ is the same as the card identification information included in the EF.

[0031] The communication unit 25 communicates with the card reader / writer 14 of the IC card processing device 1 and is composed of an interface according to a predetermined communication protocol, etc. When the IC card 2 is realized as a contact-type IC card, the communication unit 25 is composed of a communication control unit and a contact unit for physically and electrically contacting the card reader / writer 14 of the IC card processing device 1 to transmit and receive signals. When the IC card 2 is realized as a non-contact-type IC card, the communication unit 25 is composed of a communication control unit such as a modulation / demodulation circuit for wireless communication with the card reader / writer 14 of the IC card processing device 1 and an antenna.

[0032] In addition, if the IC card 2 is a dual card that supports both contact and contactless types, the communication unit 25 is composed of a communication control unit and a contact unit for physically and electrically contacting the card reader / writer 14 of the IC card processing device 1 to send and receive signals, and a communication control unit such as a modulation / demodulation circuit and an antenna for performing wireless communication with the card reader / writer 14 of the IC card processing device 1.

[0033] Next, various operations of the information processing system will be described with reference to sequence diagrams. Note that various processes including the generation of information by the IC card processing device 1 in the sequence diagram are executed by the CPU 11, and the transmission / reception, input / output, or reading of information is executed by the card reader / writer 14 or the OCR 15. Also, various processes including the generation of information by the IC card 2 are executed by the CPU 21, but the transmission / reception, input / output, or reading of information is executed by the communication unit 25.

[0034] <BAC(Basic Access Control)> Below is an overview of BAC. In BAC, a session key is shared using common key cryptography. The IC card 2 and IC card processing device 1 exchange random numbers. This random number is used in an external authentication command to verify that the IC card 2 and IC card processing device 1 are correct. The message of the external authentication command is encrypted with a key generated from card identification information optically read from the MRZ. In the external authentication command, random numbers used to generate the key are exchanged between the IC card 2 and IC card processing device 1. A session key is generated from the exclusive OR (XOR) of the exchanged random numbers. Details are as described in ICAO Doc 9303 Part 11.

[0035] FIG. 3 is a sequence diagram illustrating an example of the BAC according to the embodiment. 3, the IC card processing device 1 optically reads card identification information ID1 from the MRZ of the IC card 2 using the OCR 15 (ST1101), and transmits an application selection command to the IC card 2 using the card reader / writer 14 (ST2101). After that, the IC card processing device 1 transmits information via the card reader / writer 14, and also receives information from the IC card 2.

[0036] The IC card 2 receives the application selection command, selects an application based on the application selection command (ST1102), and returns a normal end (ST1103).

[0037] The IC card processing device 1 receives the normal end and transmits a random number request command (ST2102).

[0038] The IC card 2 receives the random number request command, generates a random number R11 based on the random number request command (ST1104), and transmits the random number R11 (ST1105).

[0039] The IC card processing device 1 receives the random number R11, generates a random number R12 (ST2103), generates a random number R13 that becomes the key K11 (ST2104), and generates the key K12 based on the card identification information ID1 read from the MRZ (ST2105). The IC card processing device 1 also encrypts the random numbers R11, R12, and R13 (ST2106). Furthermore, the IC card processing device 1 generates a MAC (Message Authentication Code) 1 (ST2107). The IC card processing device 1 transmits an external authentication command (ST2108). The external authentication command includes the encrypted random numbers R11, R12, R13, MAC1, etc.

[0040] The IC card 2 receives the external authentication command, collates the random number R11 (ST1106), and generates a random number R14 that becomes the key K13 (ST1107). The IC card 2 also encrypts the random numbers R11, R12, and R14 (ST1108). Furthermore, the IC card processing device 1 generates a MAC2 (ST1109). The IC card processing device 1 transmits response data (ST1110). The response data includes the encrypted random numbers R11, R12, R14, MAC2, etc.

[0041] The IC card 2 generates an encrypted session key K14 and a MAC session key K15 from the exclusive OR (XOR) of the random numbers R11 and R12 (ST1111).

[0042] The IC card processing device 1 collates the random number R12 (ST2109), and generates an encrypted session key K14 and a MAC session key K15 from the exclusive OR (XOR) of the random numbers R11 and R12 (ST2110).

[0043] <PACE(Password Authentication Connection Establishment)> An overview of PACE will be given. In PACE, a session key is shared by key sharing using public key cryptography. A key is generated in the IC card 2 and the IC card processing device 1, public keys are exchanged between the IC card 2 and the IC card processing device 1, and shared secret information is generated. The IC card processing device 1 optically reads the card identification information from the MRZ, and the IC card 2 transmits to the IC card 2 a random number encrypted with a key generated from the card identification information read from the storage unit. The IC card 2 performs a mapping process using the random number and the shared secret information. A key is generated again in the IC card 2 and the IC card processing device 1, public keys are exchanged between the IC card 2 and the IC card processing device 1, and mapped shared secret information is generated. A session key is generated using this. Furthermore, the generated session key is verified to be correct by an authentication token.

[0044] 4A and 4B are sequence diagrams showing an example of a PACE according to an embodiment. 4A, the IC card processing device 1 optically reads card identification information ID1 from the MRZ of the IC card 2 using the OCR 15 (ST1201), and transmits a binary read command to the IC card 2 using the card reader / writer 14 (ST2201). After that, the IC card processing device 1 transmits information via the card reader / writer 14, and also receives information from the IC card 2.

[0045] The IC card 2 receives the binary read command and transmits the encryption algorithm that it supports based on the binary read command (ST1202).

[0046] The IC card processing device 1 receives the encryption algorithm and specifies the encryption algorithm (ST2202). The IC card processing device 1 transmits a predetermined command (MSE: Set AT command) (ST2203).

[0047] The IC card 2 returns response data (OK) (ST1203).

[0048] The IC card processing device 1 transmits an authentication command (GENERAL AUTHENTICATE command) (ST2204).

[0049] The IC card 2 generates a random number R21 (ST1204), generates a key K21 based on the card identification information ID2 stored in ROM 22, encrypts the random number R21 with the key K21 (ST1205), and transmits the encrypted random number R21 (ST1206). Note that the card identification information ID2 stored in ROM 22 is the same information as the card identification information ID1 of the MRZ.

[0050] The IC card processing device 1 generates a key K21 based on the card identification information ID1 read from the MRZ, and obtains a random number R21 from a random number R21 encrypted with the generated key K21 (ST2205). The IC card processing device 1 generates a key pair KP21 of a private key K221 and a public key K222 (ST2206), generates an authentication command (GENERAL AUTHENTICATE command) including the public key K222 (ST2207), and transmits the authentication command (ST2208).

[0051] The IC card 2 generates a key pair KP22 of a private key K231 and a public key K232 (ST1207). The IC card 2 generates shared secret information INF21 from the public key K222 and the private key K231 (ST1208), and executes a mapping process using the random number R21 and the supplied information INF21 (ST1209). The IC card 2 transmits the public key K232 (ST1210).

[0052] The IC card processing device 1 receives the public key K232 and generates the shared secret information INF22 from the public key K232 and the private key K221 (ST2209). The IC card processing device 1 executes a mapping process using the random number R21 and the shared secret information INF22 (ST2210). The IC card processing device 1 generates a key pair KP23 of the private key K241 and the public key K242 (ST2211), and transmits an authentication command (GENERAL AUTHENTICATE command) including the public key K242 (ST2212).

[0053] The IC card 2 generates a key pair KP24 of a private key K251 and a public key K252 (ST1211). The IC card 2 generates shared secret information INF23 mapped with the public key K242 and the private key K252 (ST1212). The IC card 2 transmits the public key K252 (ST1213).

[0054] The IC card processing device 1 receives the public key K252 and generates shared secret information INF24 mapped with the public key K252 and the private key K241 (ST2213). The IC card processing device 1 generates an encrypted session key K26 and a MAC session key K27 from the mapped shared secret information INF24 (ST2214). The IC card processing device 1 generates a MAC for the public key K252 (ST2215). The IC card processing device 1 transmits an authentication command (GENERAL AUTHENTICATE command) including an authentication token (ST2216).

[0055] The IC card 2 receives the authentication command and verifies the authentication token included in the authentication command (ST1214). The IC card 2 generates an encrypted session key K26 and a MAC session key K27 from the mapped shared secret information INF23 (ST1215). The IC card 2 generates a MAC for the public key K242 (ST2215). The IC card 2 transmits the authentication token (ST1216).

[0056] The IC card processing device 1 receives the authentication token and verifies the authentication token (ST1217).

[0057] Below, various processes are explained with reference to sequence diagrams. Note that secure messaging in the sequence diagram is a process in which commands are encrypted with an encryption session key and an authenticator is generated with a MAC session key. For details, see ICAO Doc 9303 Part 11 and ISO / IEC 7816-4.

[0058] <First data read process (read process not subject to active authentication)> FIG. 5 is a sequence diagram illustrating an example of the first data read process according to the embodiment. For example, the IC card processing device 1 and the IC card 2 share a session key by the BAC or PACE described above. In the first data read process described here, the target data can be read by executing the target data read process (ST2301, ST1301, ST2302, ST1302) before executing active authentication (ST2303, ST2304, ST1303, ST1304, ST2305).

[0059] First, the target data read process (ST2301, ST1301, ST2302, ST1302) will be described. As shown in FIG. 5, the IC card processing device 1 transmits an application selection command (ST2301).

[0060] The IC card 2 receives the application selection command and transmits a response (normal end) (ST1301).

[0061] The IC card processing device 1 transmits a binary read command (ST2302). The IC card processing device 1 sequentially reads out the EFs in which target data such as card identification information, face image, AA public key, and security object (static certificate) are stored using the binary read command via secure messaging. The card identification information stored in the EFs is the same as the card identification information printed on the MRZ.

[0062] The IC card 2 receives the binary read command and transmits the binary data (ST1302).

[0063] As described above, the IC card processing device 1 repeatedly transmits the binary read command, and the IC card 2 transmits binary data corresponding to the binary read command.

[0064] Next, active authentication (ST2303, ST2304, ST1303, ST1304, ST2305) will be explained. The IC card processing device 1 generates a random number R31 (ST2303). The IC card processing device 1 transmits an internal authentication command including the random number R31, with the random number R31 as the data to be signed (ST2304).

[0065] The IC card 2 generates a signature S31 from a random number R31 based on an AA private key K31 stored in the NVM 24 or the like (ST1303), and transmits the signature S31 (ST1304).

[0066] The IC card processing device 1 receives the signature S31 and verifies the signature S31 (ST2305). That is, the IC card processing device 1 verifies the random number R31 and the signature S31 based on the AA public key K32 stored in the storage unit 16, etc. If the verification result is correct, it is found that the IC card 2 holds the AA private key K31 corresponding to the AA public key K32.

[0067] <Second data read process (read process subject to active authentication)> For example, the second data read process executes active authentication necessary data read processes (ST2401, ST1401, ST1402, ST1403) for implementing active authentication, executes active authentication (ST2402, ST2403, ST1404, ST1405, ST2404), and then executes target data read processes (ST2405, ST1406, ST1407, ST1408) for reading target data from NVM 24. The target data is card identification information, a face image, etc. In other words, the IC card 2 provides a mechanism in which the target data cannot be read unless active authentication is executed.

[0068] The NVM 24 of the IC card 2 stores multiple EFs, and a flag is set for each EF. For example, if the flag is 0, it indicates that active authentication does not need to be performed as a condition for reading the data. On the other hand, if the flag is 1, it indicates that active authentication needs to be performed as a condition for reading the data. An EF is made up of file definition information and data. The file definition information has an area for storing flags. The flag is set when the file is created.

[0069] Furthermore, the RAM 23 of the IC card 2 stores an execution history flag indicating the execution history of active authentication. When the execution history flag is 0, it indicates that active authentication has not been executed, and when the execution history flag is 1, it indicates that active authentication has been executed.

[0070] FIG. 6 is a sequence diagram illustrating an example of the second data read process according to the embodiment. First, the active authentication necessary data read process (ST2401, ST1401, ST1402, ST1403) will be described. 6, the IC card processing device 1 transmits a binary read command (ST2401). The IC card processing device 1 sequentially reads out the EF41 in which the AA public key and the security object (static certificate) are stored by the binary read command through secure messaging.

[0071] The IC card 2 receives the binary read command, acquires the flag set in EF41, checks the flag set in EF41, and also checks the execution history flag indicating the execution history of active authentication stored in RAM 23 (ST1401). For example, if the acquired execution history flag is 0, data can be read without the need to execute active authentication, and the IC card 2 reads the binary data from EF41 (ST1402) and transmits the read binary data (ST1403).

[0072] As described above, the IC card processing device 1 repeatedly transmits the binary read command, and the IC card 2 transmits binary data corresponding to the binary read command.

[0073] Next, active authentication (ST2402, ST2403, ST1404, ST1405, ST2404) will be explained. The IC card processing device 1 generates a random number R41 (ST2402). The IC card processing device 1 transmits an internal authentication command including the random number R41, with the random number R41 as the data to be signed (ST2403).

[0074] The IC card 2 receives the internal authentication command including the random number R41, generates a signature S41 from the random number R41 based on the AA private key K41 stored in the NVM 24 or the like (ST1404), and transmits the signature S41 (ST1405).

[0075] Furthermore, in response to the generation of the signature S41, the IC card 2 updates the execution history flag indicating the execution history of the active authentication. That is, the IC card 2 updates the execution history flag from 0 to 1.

[0076] The IC card processing device 1 receives the signature S41 and verifies the signature S41 (ST2404). That is, the IC card processing device 1 verifies the random number R41 and the signature S41 based on the AA public key K42 stored in the storage unit 16 or the like. If the verification result is correct, it is found that the IC card 2 holds the AA private key K41 corresponding to the AA public key K42.

[0077] Next, the target data read process (ST2405, ST1406, ST1407, ST1408) will be described. The IC card processing device 1, which has successfully verified the signature S41, transmits a binary read command (ST2405). The IC card processing device 1 sequentially reads out the EF42 in which the target data such as the card identification information and the face image is stored using the binary read command via secure messaging.

[0078] The IC card 2 receives the binary read command, obtains the flag set in EF42, checks the flag set in EF42, and also checks the execution history flag indicating the execution history of active authentication stored in RAM 23 (ST1406).For example, if the flag set in EF42 is 1, active authentication needs to be executed to read data, but if the execution history flag indicating the execution history of active authentication is also 1, active authentication has been executed, so the IC card 2 reads binary data from EF42 (ST1407) and transmits the read binary data (ST1408).

[0079] The IC card processing device 1 receives the binary data. In other words, on the condition that active authentication is being executed, the IC card 2 can transmit target data such as card identification information and a face image, and the IC card processing device 1 can receive target data such as card identification information and a face image.

[0080] As described above, when the CPU 21 of the IC card 2 executes an authentication operation based on the authentication command transmitted from the IC card processing device 1, it stores an execution history indicating that the authentication operation has been executed in the RAM 23. If the CPU 21 of the IC card 2 stores an execution history indicating that the authentication operation has been executed, it acquires from the EF the target data requested by the binary read command transmitted from the IC card processing device 1, and transmits the acquired target data to the IC card processing device 1.

[0081] If the CPU 21 of the IC card 2 does not store an execution history indicating that the authentication operation has been executed, the CPU 21 does not acquire, from the EF, the target data requested by the binary read command transmitted from the IC card processing device 1. In other words, the CPU 21 of the IC card 2 does not transmit the target data to the IC card processing device 1 in response to the binary read command.

[0082] In this way, the IC card 2 sets a flag indicating that active authentication is required as a read condition in the EF storing the card identification information and target data such as a facial image. Alternatively, the IC card 2 stores the card identification information and target data such as a facial image in the EF with such a flag set. In this way, the read of data such as the card identification information and the facial image can be made conditional on the execution of active authentication, and transactions without the execution of active authentication can be prevented.

[0083] <Third data reading process (using encrypted random numbers)> Fig. 7A and Fig. 7B are sequence diagrams showing an example of a third data read process according to the embodiment. Fig. 10 is a diagram showing an example of a signature generation algorithm (Sign by Dilithium) in the data read process, and Fig. 11 is a diagram showing an example of a signature verification algorithm (Verify by Dilithium) in the data read process.

[0084] As shown in Figures 7A and 7B, target data read processing (encryption) (ST1501, ST2501, ST1502, ST1503, ST1504), active authentication (ST2502, ST2503, ST2504, ST1505, ST1506, ST2505), key sharing (ST2506, ST2507, ST2508, ST1507, ST1508), and decryption (target data extraction) (ST2509, ST1509, ST1510, ST2510, ST2511) are executed. In order to perform active authentication, the IC card 2 generates a random number R and encrypts all EFs except the necessary EFs with the random number R. For example, the IC card 2 provides the IC card processing device 1 with the random number R encrypted by the PQC standard method (Kyber). In this way, the random number R is shared between the IC card processing device 1 and the IC card 2. The NVM 24 of the IC card 2 stores a plurality of EFs, and a flag is set for each EF. For example, if the flag is 0, it indicates that encryption is not required as a condition for reading data, and if the flag is 1, it indicates that encryption is required as a condition for reading data. 7A and 7B, an example will be described in which a part of Kyber's key sharing algorithm is extracted and used for encryption and decryption, but this embodiment is not limited to this, and Kyber's key sharing algorithm may be used. When using Kyber's key sharing algorithm, the IC card 2 performs key encapsulation using the public key K522, and encrypts the target data with the obtained shared key K. The IC card 2 sends the ciphertext to the IC card processing device 2, and the IC card processing device 1 obtains the common key K using the ciphertext and the private key K521.

[0085] First, the target data read process (encryption) (ST1501, ST2501, ST1502, ST1503, ST1504) will be described. As shown in Fig. 7A, the IC card 2 generates a random number R51 (ST1501). The IC card 2 may generate the random number R51 after receiving a binary read command, or may generate the random number R51 after receiving an application selection command. In the variation using the Kyber key sharing algorithm described above, the random number R51 is not required.

[0086] The IC card processing device 1 transmits a binary read command (ST2501). The IC card processing device 1 sequentially reads out the EF51 in which target data such as card identification information, face image, AA public key, and security object (static certificate) is stored by the binary read command via secure messaging. The card identification information stored in the EF51 is the same information as the card identification information printed on the MRZ.

[0087] The IC card 2 receives the binary read command, acquires the flag set in EF51, and checks the flag set in EF51 (ST1502). For example, if the acquired flag is 1, the IC card 2 encrypts the target data, such as the card identification information, face image, AA public key, and security object, stored in EF51, using the random number R51 (ST1503). The IC card 2 transmits the target data encrypted using the random number R51 (ST1504). In the variation using the Kyber key sharing algorithm described above, a shared key K is used instead of the random number R51.

[0088] As described above, the IC card processing device 1 repeatedly transmits the binary read command, and the IC card 2 transmits binary data corresponding to the binary read command.

[0089] Next, active authentication (ST2502, ST2503, ST2504, ST1505, ST1506, ST2505) will be explained. The IC card processing device 1 generates a random number R52 (ST2502). The IC card processing device 1 transmits an internal authentication command including the random number R52, with the random number R52 as the data to be signed (ST2503).

[0090] The IC card 2 receives the internal authentication command including the random number R52, generates a signature S51 from the random number R52 based on the AA private key K51 stored in the NVM 24 or the like using a signature generation algorithm (ST1505), and transmits the signature S51 (ST1506).

[0091] The IC card processing device 1 receives the signature S51 and verifies the random number R52 and the signature S51 based on the AA public key K52 stored in the storage unit 16 or the like, using a signature verification algorithm (ST2505). If the verification result is correct, it is found that the IC card 2 holds the AA private key K51 corresponding to the AA public key K52.

[0092] Next, key sharing (ST2506, ST2507, ST2508, ST1507, ST1508) will be explained. The IC card processing device 1 generates a key pair KP51 including a private key K521 and a public key K522 by the PQC standard method (Kyber) (ST2506), and transmits an MSE command including the public key K522 (ST2508).

[0093] The IC card 2 receives the MSE command including the public key K522, stores the public key K522 in the NVM 24 or the like (ST1507), and transmits a response (normal completion) (ST1508).

[0094] Next, decryption (extraction of target data) (ST2509, ST1509, ST1510, ST2510, ST2511) will be explained. The IC card processing device 1 transmits a security operation command (SECURITY OPERATION command) and executes an encryption operation (ENCIPHER operation) (ST2509).

[0095] The IC card 2 encrypts the random number R51 using the public key K522 (ST1509) and transmits the encrypted random number R51. In the variation using the Kyber key agreement algorithm described above, key encapsulation is performed using the public key K522 to obtain the shared key K and ciphertext c, and the ciphertext c is transmitted. Since the shared key K is derived, key encapsulation must be performed before the encryption of the target data (the ciphertext c may be transmitted at this timing).

[0096] The IC card processing device 1 decrypts the random number R51 encrypted with the private key K521 and extracts the random number R51 (ST2510). The IC card processing device 1 decrypts the target data encrypted with the random number R51 and acquires the target data (ST2511). In the variation using the Kyber key agreement algorithm described above, key encapsulation is performed with the private key K521 to obtain the shared key K.

[0097] As described above, the CPU 21 of the IC card 2 generates encryption target data by encrypting target data with the random number R51 based on the read command transmitted from the IC card processing device 1, and transmits the encryption target data to the IC card processing device 1. Furthermore, the CPU 21 of the IC card 2 generates a signature from the AA private key K51 stored in the NVM 24 or the like and the random number R52 included in the authentication command, using a signature generation algorithm based on the authentication command transmitted from the IC card processing device 1. Then, the CPU 21 transmits the generated signature to the IC card processing device 1. In addition, the CPU 21 of the IC card 2 encrypts the random number R51 using the public key K522 transmitted from the IC card processing device 1 whose signature has been successfully verified, generates the encrypted random number R51, and transmits the encrypted random number R51 to the IC card processing device 1. Furthermore, the CPU 11 of the IC card processing device 1 decrypts the random number R51 from the random number R51 encrypted with the private key K521, and decrypts the target data encrypted with the random number R51. In this way, the CPU 21 of the IC card 2 can ensure high reliability by transmitting target data encrypted with the random number 51 before active authentication and transmitting the encrypted random number R51 after active authentication.

[0098] <Fourth data read process (using variable data of signature generation algorithm)> FIG. 8 is a sequence diagram showing an example of the fourth data read process according to the embodiment. For example, target data such as personal information transmitted from the IC card 2 to the IC card processing device 1 is encrypted with variable data W1 included in the signature generation algorithm shown in Fig. 10. That is, data other than EF necessary for performing active authentication is encrypted with variable data W1.

[0099] The NVM 24 of the IC card 2 stores multiple EFs, and a first flag is set for each EF, and for example, if the first flag is 0, it indicates that encryption with the variable data W1 is not required as a condition for reading data, and if the first flag is 1, it indicates that encryption with the variable data W1 is required as a condition for reading data.

[0100] In addition, a second flag is set for each EF, and for example, if the second flag is 0, it indicates that active authentication is not required as a condition for reading data, and if the second flag is 1, it indicates that active authentication is required as a condition for reading data.

[0101] As shown in Fig. 10, in the signature generation algorithm, ρ is a fixed part of the public key, and matrix A is used. Since the calculation of matrix A imposes a high load, the calculation of matrix A can be said to be the calculation of Dilithium. After active authentication is performed, it is possible to confirm that active authentication has been verified by using variable data W1 as a session key.

[0102] First, the necessary data reading process (ST2601, ST1601, ST1602, ST1603) will be described. 8, the IC card processing device 1 transmits a binary read command (ST2601). The IC card processing device 1 sequentially reads out the EF61 in which the AA public key and the security object (static certificate) are stored by the binary read command through secure messaging.

[0103] The IC card 2 receives the binary read command, acquires the second flag set in EF 61, checks the second flag set in EF 61, and also checks the execution history flag indicating the execution history of active authentication stored in RAM 23 (ST1601). For example, if the acquired second flag is 0, data can be read without the need to execute active authentication, and the IC card 2 reads the binary data from EF 61 (ST1602) and transmits the read binary data (ST1603).

[0104] As described above, the IC card processing device 1 repeatedly transmits the binary read command, and the IC card 2 transmits binary data corresponding to the binary read command.

[0105] Next, active authentication (ST2602, ST2603, ST1604, ST1605, ST1606, ST2604, ST2605) will be explained. The IC card processing device 1 generates a random number R61 (ST2602). The IC card processing device 1 transmits an internal authentication command including the random number R61, with the random number R61 as the data to be signed (ST2603).

[0106] The IC card 2 receives the internal authentication command including the random number R61, and generates a signature S61 from the random number R61 based on the AA private key K62 stored in the NVM 24 or the like by a signature generation algorithm (ST1604). Then, variable data W1 generated midway through the signature generation algorithm is stored in the NVM 24 or the like for use as the key K61 (ST1605), and the signature S61 is transmitted (ST1606).

[0107] Furthermore, in response to the generation of the signature S61, the IC card 2 updates the execution history flag indicating the execution history of the active authentication. That is, the IC card 2 updates the execution history flag from 0 to 1. The signature generation algorithm is as shown in FIG.

[0108] The IC card processing device 1 receives the signature S61 and verifies the signature S61 (ST2604). That is, the IC card processing device 1 verifies the random number R61 and the signature S61 based on the AA public key K63 stored in the storage unit 16 or the like. If the verification result is correct, it is found that the IC card 2 holds the AA private key K62 corresponding to the AA public key K63. The IC card processing device 1 stores the variable data W1 generated during the calculation for verification in the storage unit 16 for use as the key K61 (ST2605).

[0109] Next, the target data read process (decryption and extraction of target data) (ST2606, ST1607, ST1608, ST1609, ST2607) will be described. The IC card processing device 1, which has successfully verified the signature S41, transmits a binary read command (ST2406). The IC card processing device 1 sequentially reads out the EF62 in which the target data such as the card identification information and the face image is stored using the binary read command via secure messaging.

[0110] The IC card 2 receives the binary read command, acquires the first flag set in EF62, and checks the first flag set in EF62 (ST1607). For example, if the first flag set in EF62 is 1, encryption using the variable data W1 is required to read the data. In this case, the IC card 2 encrypts the target data in EF62 using the variable data W1 (ST1608), and transmits the encrypted target data (ST1609).

[0111] The IC card processing device 1 receives the encrypted target data, decrypts the target data encrypted with the variable data W1, and extracts the target data (ST2607).

[0112] As described above, the CPU21 of the IC card 2 generates a signature from the AA private key K62 and the random number R61 using a signature generation algorithm based on the authentication command transmitted from the IC card processing device 1, and transmits the signature to the IC card processing device 1. The CPU21 of the IC card 2 generates encryption target data by encrypting target data using variable data W1 based on a read command transmitted from the IC card processing device 1 whose signature has been successfully verified using the signature verification algorithm, and transmits the encryption target data to the IC card processing device 1.

[0113] The IC card processing device 1 decrypts the target data from the encrypted target data based on the variable data W1 generated by the signature verification algorithm. In this way, the CPU 21 of the IC card 2 transmits the target data encrypted by the variable data W1, thereby ensuring high reliability.

[0114] <Fifth data read process (using fixed data of signature generation algorithm)> FIG. 9 is a sequence diagram illustrating an example of the fifth data read process according to the embodiment. For example, target data such as personal information transmitted from the IC card 2 to the IC card processing device 1 is encrypted with fixed data A included in the signature generation algorithm shown in Fig. 10. That is, data other than EF necessary for performing active authentication is encrypted with fixed data A. Fixed data A is a part of the public key, and is calculated in advance by the IC card 2 or set when the IC card 2 is issued.

[0115] The NVM 24 of the IC card 2 stores a plurality of EFs, and a flag is set for each EF, and for example, if the flag is 0, it indicates that encryption with fixed data A is not required as a condition for reading data, and if the flag is 1, it indicates that encryption with fixed data A is required as a condition for reading data.

[0116] First, the target data read process (ST1701, ST2701, ST1702, ST1703, ST1704) will be described. 9, the IC card 2 generates fixed data A (ST1701). Note that the fixed data A may be set when the IC card 2 is issued.

[0117] The IC card processing device 1 transmits a binary read command (ST2701). The IC card processing device 1 sequentially reads out the EF71 storing the card identification information, the face image, the AA public key, and the security object (static certificate) by the binary read command through secure messaging.

[0118] The IC card 2 receives the binary read command, acquires the flag set in EF71, and checks the flag set in EF71 (ST1702). For example, if the acquired flag is 1, encryption with fixed data A is required to read the data. The IC card 2 reads the binary data from EF71, and encrypts target data such as card identification information, face image, AA public key, and security object (static certificate) with fixed data A (ST1703). The IC card 2 transmits the encrypted target data (ST1704).

[0119] As described above, the IC card processing device 1 repeatedly transmits the binary read command, and the IC card 2 transmits binary data corresponding to the binary read command.

[0120] Next, active authentication (decryption and retrieval of target data) (ST2702, ST2703, ST1705, ST1706, ST2704, ST2705) will be explained. The IC card processing device 1 generates a random number R71 (ST2702). The IC card processing device 1 transmits an internal authentication command including the random number R71, with the random number R71 as the data to be signed (ST2703).

[0121] The IC card 2 receives the internal authentication command including the random number R71, and generates a signature S71 from the random number R71 based on the AA private key K72 stored in the NVM24 or the like using a signature generation algorithm including the fixed data A (ST1705), and transmits the signature S71 (ST1706).

[0122] The IC card processing device 1 receives the signature S71 and verifies the signature S71 (ST2704). That is, the IC card processing device 1 verifies the random number R71 and the signature S71 based on the AA public key K73 stored in the storage unit 16 or the like. If the verification result is correct, it is found that the IC card 2 holds the AA private key K72 corresponding to the AA public key K73. The IC card processing device 1 decrypts the target data encrypted by the fixed data A and acquires the target data (ST2705).

[0123] As described above, the CPU21 of the IC card 2 generates encryption target data by encrypting target data with fixed data A generated from a part of the public key in a signature generation algorithm based on a read command transmitted from the IC card processing device 1. The CPU21 transmits the generated encryption target data to the IC card processing device 1. Also, the CPU21 of the IC card 2 generates a signature S71 from the AA private key K72 and the random number R71 by a signature generation algorithm based on an authentication command transmitted from the IC card processing device 1. The CPU21 transmits the generated signature S71 to the IC card processing device 1.

[0124] The IC card processing device 1 verifies the signature S71 by a signature verification algorithm, and decrypts the target data from the encrypted target data based on the fixed data A generated by the signature verification algorithm. In this way, the CPU 21 of the IC card 2 transmits the target data encrypted by the fixed data A, thereby ensuring high reliability.

[0125] In the information processing system of this embodiment, the second to fifth read processes described above may be implemented individually, or two or more processes may be implemented.

[0126] The program according to this embodiment may be transferred in a state stored in electronic devices such as the IC card processing device 1 and the IC card 2, or in a state not stored in the electronic device. In the latter case, the program may be transferred via a network, or in a state stored in a storage medium. The storage medium is a non-transient tangible medium. The storage medium is a computer-readable medium. The storage medium may be an optical disk, a memory card, or any other medium capable of storing a program and being readable by a computer, and the form of the storage medium is not important. The electronic device downloads the program transferred (provided) via a network and installs it in memory, or reads the program from the storage medium and installs it in memory.

[0127] Although some embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included in the scope and spirit of the invention, and are included in the scope of the invention and its equivalents described in the claims. [Explanation of symbols]

[0128] 1. IC card processing device 2. IC card 11...CPU 12…Display 13...Operation unit 14...Card reader / writer 15...OCR 16...Storage section 21…CPU 25…Communications Department 24…NVM

Claims

1. An interface for communicating with an information processing device; a processor for executing operations based on the commands; A memory for storing target data; Equipped with The processor, Executing an authentication operation based on an authentication command transmitted from the information processing device; storing an execution history indicating execution of an authentication operation in the memory; If the execution history is stored, the target data requested by a read command transmitted from the information processing device is transmitted to the information processing device. Portable electronic devices.

2. The processor, If the execution history is not stored, the target data requested by the read command transmitted from the information processing device is not transmitted to the information processing device.

2. The portable electronic device of claim 1.

3. The processor, generating a signature from a random number included in the authentication command based on a private key stored in the memory; storing the execution history in the memory in response to generation of the signature; transmitting the signature to the information processing device; 2. The portable electronic device of claim 1.

4. The processor, transmits the target data requested by the read command to the information processing device based on the read command and the execution history transmitted from the information processing device for which the signature has been successfully verified; 4. The portable electronic device of claim 3.

5. an interface for communicating with an information processing device that transmits an authentication command including a first random number and generates a key pair of a first public key and a first private key; a processor for executing operations based on the commands; A memory for storing a second secret key and target data; Equipped with The processor, Generate a second random number; generating encryption target data by encrypting the target data with the second random number based on a read command transmitted from the information processing device, and transmitting the encryption target data to the information processing device; generating a signature from the second private key stored in the memory and the first random number included in the authentication command based on the authentication command transmitted from the information processing device, and transmitting the signature to the information processing device; generating an encrypted random number by encrypting the second random number based on the first public key transmitted from the information processing device that has successfully verified the signature, and transmitting the encrypted random number to the information processing device; The information processing device includes: Decrypting the second random number from the encrypted random number based on the first secret key; decrypting the target data from the encryption target data based on the second random number; Portable electronic devices.

6. an interface for communicating with an information processing device that transmits an authentication command including a random number; a processor for executing operations based on the commands; A memory for storing a private key and target data; Equipped with The processor, generating a signature from the private key stored in the memory and the random number included in the authentication command by a signature generation algorithm based on the authentication command transmitted from the information processing device, and transmitting the signature to the information processing device; generating encryption target data by encrypting the target data with variable data generated by the signature generation algorithm based on a read command transmitted from the information processing device in which the signature has been successfully verified by the signature verification algorithm, and transmitting the encryption target data to the information processing device; The information processing device includes: decrypting the target data from the encrypted target data based on the variable data generated by the signature verification algorithm; Portable electronic devices.

7. an interface for communicating with an information processing device that transmits an authentication command including a random number; a processor for executing operations based on the commands; A memory for storing a private key and target data; Equipped with The processor, generating encryption target data by encrypting the target data with fixed data generated from a part of a public key in a signature generation algorithm based on a read command transmitted from the information processing device, and transmitting the encryption target data to the information processing device; generating a signature from the private key stored in the memory and the random number included in the authentication command by the signature generation algorithm based on the authentication command transmitted from the information processing device, and transmitting the signature to the information processing device; The information processing device includes: verifying the signature using a signature verification algorithm, and decrypting the target data from the encrypted target data based on the fixed data generated by the signature verification algorithm; Portable electronic devices.

8. An information processing system including a portable electronic device and an information processing device, The portable electronic device is a first interface for communicating with an information processing device; a first processor for executing an operation based on the command; A memory for storing target data, The first processor, Executing an authentication operation based on an authentication command transmitted from the information processing device; storing an execution history indicating execution of an authentication operation in the memory; transmits the target data requested by the read command to the information processing device based on the read command and the execution history transmitted from the information processing device; The information processing device includes: a second interface for communicating with the portable electronic device; a second processor that transmits the authentication command and then transmits the read command.

9. An information processing method executed by a portable electronic device and an information processing device, comprising: The information processing device transmits an authentication command to the portable electronic device; the portable electronic device executes an authentication operation based on the authentication command, and stores an execution history indicating the execution of the authentication operation in a memory; The information processing device transmits a read command to the portable electronic device; The portable electronic device transmits target data requested by the read command to the information processing device based on the read command transmitted from the information processing device and the execution history.

Citation Information

Patent Citations

  • Semiconductor element and biometric authentication method, biometric authentication system, and mobile terminal

    JP2010092250A