Electronic information storage medium, IC chip, IC card, public key storage method, and program
The described solution for IC cards addresses memory shortages and efficiency issues by using separate storage areas for public key certificates and public keys, allowing for efficient signature verification and storage of necessary public keys.
Patent Information
- Application Number
- JP2023204654
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-16
AI Technical Summary
IC cards with smaller memory capacity and lower processing power face memory shortages and efficiency issues when verifying multiple signatures for chained public key certificates.
An electronic information storage medium with a memory having separate storage areas for public key certificates and public keys, which determines whether received certificates can be stored based on size constraints, and performs signature verification only when storage is not possible, storing the extracted public key instead.
This approach prevents memory shortages during signature verification and enhances efficiency by storing only the necessary public keys, allowing for secure and efficient handling of chained public key certificates.
Smart Images

Figure 2025089789000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of IC (Integrated Circuit) cards having a verification function for public key certificates and the like.
Background Art
[0002] In recent years, the applications of IC cards have expanded and they have become an essential component for storing confidential information. To protect such confidential information, IC cards are equipped with functions such as encrypting data for transmission and reception in communication with external terminals. For such encrypted communication, for example, as disclosed in Patent Document 1, PKI (Public Key Infrastructure) is used, and an IC card can confirm whether an external terminal is trusted by a certification authority by verifying the signature of a public key certificate issued by the certification authority. In a PKI system, public key certificates may have a chained structure (hierarchical structure), and in this case, the IC card has to verify the signatures of multiple public key certificates. In the IC card disclosed in Patent Document 1, for a public key certificate for which signature verification has been successful once, the public key certificate itself is saved, and thereafter, only comparison between the received public key certificate and the saved information is performed and the signature verification process is not executed again, so that the time required for the signature verification process can be made efficient without sacrificing security.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] By the way, when verifying multiple signatures, in an IC card with a smaller memory capacity and lower processing power compared to a PC or smartphone, if all the public key certificates chained in multiple layers are received and then verified, the memory will be insufficient. Also, if verification is performed every time a certificate is received, the efficiency will be poor and the convenience will be impaired.
[0005] Therefore, the present invention has been made in view of such points, and an object of the present invention is to provide an electronic information storage medium, an IC chip, an IC card, a public key storage method, and a program that do not suffer from memory shortages in signature verification of public key certificates and can efficiently perform signature verification.
Means for Solving the Problems
[0006] In order to solve the above problems, the invention according to claim 1 is an electronic information storage medium including a memory including a first storage area for storing a public key certificate and a second storage area for storing a public key, a receiving means for sequentially receiving a plurality of chained public key certificates from an external terminal, and when any one of the plurality of chained public key certificates is received, a first determination means for determining whether the received public key certificate can be stored in the first storage area based on the size of the received public key certificate and the set capacity of the first storage area, and when it is determined by the first determination means that storage is possible, storing the received public key certificate in the first storage area, while when it is determined by the first determination means that storage is not possible, executing signature verification of the received public key certificate and, when the signature verification is successful, storing the public key extracted from the received public key certificate in the second storage area, characterized by comprising processing means.
[0007] The invention according to claim 2 is the electronic information storage medium according to claim 1, wherein the processing means transmits information indicating which position from the head of the plurality of chained public key certificates the public key certificate that failed in the signature verification corresponds to, to the external terminal when the signature verification fails.
[0008] The invention according to claim 3 is the electronic information storage medium according to claim 1, wherein the processing means executes signature verification of the received public key certificate using a public key extracted from the immediately received public key certificate among the plurality of chained public key certificates and stored in the second storage area.
[0009] The invention according to claim 4 is the electronic information storage medium according to any one of claims 1 to 3, wherein when the signature verification is successful and the public key extracted from the immediately received public key certificate among the plurality of chained public key certificates is stored in the second storage area, the processing means stores the public key extracted from the received public key certificate in the second storage area instead of the stored public key.
[0010] The invention according to claim 5 is the electronic information storage medium according to claim 4, wherein the processing means erases the public key certificate from the first storage area.
[0011] The invention according to claim 6 is an IC chip including a memory having a first storage area for storing public key certificates and a second storage area for storing public keys, a receiving means for sequentially receiving a plurality of chained public key certificates from an external terminal, and a first determination means for determining whether the received public key certificate can be stored in the first storage area based on the size of the received public key certificate and the set capacity of the first storage area when any one of the plurality of chained public key certificates is received, and a processing means for storing the received public key certificate in the first storage area when determined to be storable by the first determination means, and when determined not to be storable by the first determination means, executing signature verification of the received public key certificate and storing the public key extracted from the received public key certificate in the second storage area when the signature verification is successful.
[0012] The invention according to claim 7 is an IC card including a memory having a first storage area for storing public key certificates and a second storage area for storing public keys, the IC card comprising: receiving means for sequentially receiving a plurality of chained public key certificates from an external terminal; first determination means for determining, when any one of the plurality of chained public key certificates is received, whether the received public key certificate can be stored in the first storage area based on the size of the received public key certificate and the set capacity of the first storage area; processing means for storing the received public key certificate in the first storage area when determined by the first determination means to be storable, and when determined by the first determination means not to be storable, executing signature verification of the received public key certificate and storing the public key extracted from the received public key certificate in the second storage area when the signature verification is successful.
[0013] The invention according to claim 8 is a public key storage method executed by an electronic information storage medium including a memory having a first storage area for storing public key certificates and a second storage area for storing public keys, the method comprising: sequentially receiving a plurality of chained public key certificates from an external terminal; determining, when any one of the plurality of chained public key certificates is received, whether the received public key certificate can be stored in the first storage area based on the size of the received public key certificate and the set capacity of the first storage area; storing the received public key certificate in the first storage area when determined to be storable, and when determined not to be storable, executing signature verification of the received public key certificate and storing the public key extracted from the received public key certificate in the second storage area when the signature verification is successful.
[0014] The invention according to claim 9 is a computer included in an electronic information storage medium having a memory including a first storage area for storing a public key certificate and a second storage area for storing a public key, the computer performing the steps of sequentially receiving a plurality of chained public key certificates from an external terminal, and when any one of the plurality of chained public key certificates is received, determining whether the received public key certificate can be stored in the first storage area based on the size of the received public key certificate and the set capacity of the first storage area, and when it is determined that the received public key certificate can be stored, storing the received public key certificate in the first storage area, while when it is determined that the received public key certificate cannot be stored, performing signature verification of the received public key certificate and storing the public key extracted from the received public key certificate in the second storage area when the signature verification is successful.
Effect of the Invention
[0015] According to the present invention, there is no shortage of memory in signature verification of a public key certificate, and signature verification can be efficiently performed.
Brief Description of the Drawings
[0016]
Figure 1
Figure 2
Figure 3
Embodiments for Carrying Out the Invention
[0017] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0018] [1. Configuration and Function of IC Chip 1] First, with reference to FIG. 1, the configuration and functions of the IC chip 1 according to this embodiment will be described. The IC chip 1 is an example of the electronic information storage medium of the present invention. The IC chip 1 is mounted on, for example, an IC card such as a credit card, a cash card, or a my number card, or a mobile device such as a smartphone. In the case of a mobile device such as a smartphone, the IC chip 1 may be mounted on a small IC card that is detachable from the mobile device, or may be mounted on an embedded substrate so that it cannot be easily removed or replaced from the mobile device as an eUICC (Embedded Universal Integrated Circuit Card).
[0019] FIG. 1 is a diagram showing an example of the hardware configuration of the IC chip 1. As shown in FIG. 1, the IC chip 1 includes an I / O circuit 11, a RAM (Random Access Memory) 12 (volatile memory), an NVM (Nonvolatile Memory) 13 (nonvolatile memory), a ROM (Read Only Memory) 14, a CPU (Central Processing Unit) 15 (an example of a computer), and a coprocessor 16 that performs cryptographic operations, etc. The I / O circuit 11 serves as an interface with the external terminal 2.
[0020] Note that the communication (cryptographic communication based on PKI) between the IC chip 1 and the external terminal 2 may be non-contact communication or contact communication. In the case of non-contact communication, for example, communication between the IC chip 1 and the external terminal 2 is performed via an antenna (not shown) mounted on the IC card or the mobile device. As an example of the external terminal 2, an OCE (Off Card Entity) capable of sequentially transmitting a plurality of chained public key certificates (Certificates) by a plurality of commands is assumed. The chain of a plurality of public key certificates is called a "certificate chain". The public key certificate includes a signature by a certification authority (CA), the content to be certified, etc.
[0021] FIG. 2 is a diagram showing an example of a memory map in the RAM 12. As shown in FIG. 2, the RAM 12 includes a work area R1 used when the CPU 15 performs some processing, a certificate storage area R2 (an example of a first storage area) for storing public key certificates, and a public key storage area R3 (an example of a second storage area) for storing public keys. A plurality of public key certificates received from the external terminal 2 can be stored in the certificate storage area R2, but the total size of the public key certificates to be stored is controlled so as not to exceed the set capacity (predetermined bytes) of the certificate storage area R2. Such a capacity may be arbitrarily set.
[0022] When a public key is extracted from the received public key certificate, the extracted public key is stored in the public key storage area R3. Note that the public key stored in the public key storage area R3 may be overwritten by the public key extracted from a later-received public key certificate among a plurality of chained public key certificates. That is, it is desirable that the public key extracted from a later-received public key certificate be stored (overwritten and stored) instead of the public key stored in the public key storage area R3. Thereby, it is possible to efficiently avoid a shortage of memory.
[0023] For example, a flash memory is applied to the NVM 13. Note that the NVM 13 may be an “Electrically Erasable Programmable Read-Only Memory”. Various programs such as an OS (Operating System), an SD (Security Domain), and an application (including the program of the present invention) are stored in the NVM 13 or the ROM 14. The SD is a management program for managing applications.
[0024] The SD is for causing the CPU 15 to implement functions such as installing a new application under its own management or opening a secure channel (encrypted communication path) for an application under its own management. The applications include, for example, a public key management application and a payment application. Further, a root public key (the topmost public key) is pre-stored in the NVM 13. The root public key is the public key that serves as the basis of the certificate chain.
[0025] The CPU 15 (an example of a computer) functions as receiving means, first determination means, second determination means, processing means, etc. in the present invention according to the SD and the public key management application. Specifically, the CPU 15 sequentially receives a plurality of chained public key certificates from the external terminal 2 by, for example, a PERFORM SECURITY OPERATION command (other commands may also be used). The PERFORM SECURITY OPERATION command is, for example, a command APDU (Application Protocol Data Unit) defined in "GlobalPlatform Technology Secure Channel Protocol '11' Card Specification v2.3 - Amendment F Version 1.2". The format of the command APDU is defined in ISO / IEC 7816 - 3. The PERFORM SECURITY OPERATION command is required as a prerequisite for starting a secure channel between the OCE and the SD, for example, according to SCP (Secure Channel Protocol) 11a or SCP11c.
[0026] The PERFORM SECURITY OPERATION command consists of a header part composed of a CLA indicating the command class, an INS indicating the command code, and P1 and P2 indicating the command parameters, and a body part including Lc and Data. There are cases where a certificate chain is used and cases where a certificate chain is not used in the PERFORM SECURITY OPERATION command. When a certificate chain is used, a plurality of PERFORM SECURITY OPERATION commands are sequentially transmitted from the external terminal 2 to the IC chip 1. In P2 of the header part of the PERFORM SECURITY OPERATION command, a flag indicating whether it is the last public key certificate and the key identifier of the root public key are stored (that is, assigned to any of the 8 bits).
[0027] One public key certificate is stored in the Data (Data field) of one PERFORM SECURITY OPERATION command, and the data length (size) of the Data is stored in Lc (Lc field). Also, the body part of the PERFORM SECURITY OPERATION command may include Le (Le field). Le stores the data length of the DATA (DATA field) that can be included in the response APDU for the PERFORM SECURITY OPERATION command. Note that the response APDU includes SW1 and SW2 indicating the status word (normal completion or error (abnormal completion)). Further, the response APDU may include the above DATA.
[0028] When a PERFORM SECURITY OPERATION command including any one of a plurality of chained public key certificates is received via the I / O circuit 11, the CPU 15 determines whether the received public key certificate can be stored in the certificate storage area R2 based on the size (in bytes) of the received public key certificate and the set capacity of the certificate storage area R2. Then, when the CPU 15 determines that the received public key certificate can be stored in the certificate storage area R2, it stores the received public key certificate in the certificate storage area R2 and transmits a response APDU including SW1 and SW2 indicating normal termination to the external terminal 2 via the I / O circuit 11.
[0029] On the other hand, when the CPU 15 determines that the received public key certificate cannot be stored in the certificate storage area R2, it performs signature verification of the received public key certificate. Then, when the signature verification is successful, the CPU 15 stores the public key extracted from the received public key certificate in the public key storage area R3 and transmits a response APDU including SW1 and SW2 indicating normal termination to the external terminal 2 via the I / O circuit 11.
[0030] Note that for signature verification of the first received public key certificate, for example, the root public key specified from the NVM 13 by the key identifier stored in P2 of the header part of the PERFORM SECURITY OPERATION command is used. Also, for signature verification of the public key certificate received following the first received public key certificate, the public key extracted from the immediately preceding received public key certificate and stored in the public key storage area R3 is used.
[0031] On the other hand, when the signature verification fails, the CPU 15 transmits a response APDU including SW1 and SW2 indicating an error to the external terminal 2 via the I / O circuit 11. At this time, the CPU 15 may store, in the DATA of the response APDU, information indicating which position from the top of the plurality of public key certificates the public key certificate that failed the signature verification corresponds to. Thereby, on the external terminal 2 side, the public key certificate that failed the signature verification can be specified more quickly and appropriate measures can be taken.
[0032] [2. Operation of IC Chip 1] Next, with reference to FIG. 3, the operation of the IC chip 1 according to the present embodiment will be described. FIG. 3 is a flowchart showing an example of public key storage processing executed by the CPU 15 (for example, SD or public key management application) of the IC chip 1. The processing shown in FIG. 3 is started, for example, when a PERFORM SECURITY OPERATION command including a public key certificate is received from the external terminal 2.
[0033] When the processing shown in FIG. 3 is started, the CPU 15 determines whether there is a public key certificate following the received public key certificate (step S1). For example, when a flag indicating that it is not the last public key certificate is stored in P2 of the header part of the PERFORM SECURITY OPERATION command (that is, when the certificate chain continues), it is determined that there is a public key certificate following the received public key certificate (step S1: YES), and the processing proceeds to step S2.
[0034] On the other hand, when a flag indicating that it is the last public key certificate is stored in P2 of the header part of the PERFORM SECURITY OPERATION command (that is, when the certificate chain ends or the certificate chain is not used), it is determined that there is no public key certificate following the received public key certificate (step S1: NO), and the processing proceeds to step S12.
[0035] In step S2, the CPU 15 determines whether the received public key certificate can be stored in the certificate storage area R2 based on the size of the received public key certificate and the set capacity of the certificate storage area R2. For example, when a public key certificate is already stored in the certificate storage area R2 and the size of the received public key certificate exceeds the capacity (free capacity) obtained by subtracting the size of the already stored public key certificate from the set capacity of the certificate storage area R2, it is determined that the received public key certificate cannot be stored in the certificate storage area R2 (step S2: NO), and the process proceeds to step S4.
[0036] On the other hand, when the size of the received public key certificate does not exceed the capacity obtained by subtracting the size of the already stored public key certificate from the set capacity of the certificate storage area R2, it is determined that the received public key certificate can be stored in the certificate storage area R2 (step S2: YES), and the process proceeds to step S3. Note that when no public key certificate is yet stored in the certificate storage area R2, it is determined that the received public key certificate can be stored in the certificate storage area R2.
[0037] In step S3, the CPU 15 stores the received public key certificate in the certificate storage area R2 and advances the process to step S10. On the other hand, in step S4, the CPU 15 determines whether a public key (referred to as the "intermediate public key") extracted from the immediately preceding received public key certificate among a plurality of chained public key certificates is stored in the public key storage area R3. When it is determined that the intermediate public key is stored in the public key storage area R3 (step S4: YES), the process proceeds to step S5. On the other hand, when it is determined that the intermediate public key is not stored in the public key storage area R3 (step S4: NO), the process proceeds to step S6.
[0038] In step S5, the CPU 15 acquires the intermediate public key stored in the public key storage area R3 from the public key storage area R3, uses the acquired intermediate public key to execute signature verification of the received public key certificate, and advances the process to step S7. On the other hand, in step S6, the CPU 15 acquires the root public key from the NVM 13, uses the acquired root public key to execute signature verification of the received public key certificate, and advances the process to step S7. That is, the CPU 15 performs signature verification using the public key at the top of the hierarchical structure of the public key certificate. At this time, if the public key certificate is stored in the certificate storage area R2, signature verification and public key extraction are repeated in order from the upper public key certificate.
[0039] In step S7, the CPU 15 determines whether the signature verification executed in step S5 or step S6 was successful. For example, if it is determined that the signature verification was successful because the signature included in the public key certificate was successfully decrypted by the public key (step S7: YES), the process proceeds to step S8. On the other hand, if it is determined that the signature verification was not successful (failed) (step S7: NO), the process proceeds to step S11.
[0040] In step S8, the CPU 15 extracts the public key as an intermediate public key from the received public key certificate (that is, the public key certificate for which the signature verification was successful), and stores the extracted intermediate public key in the public key storage area R3. At this time, if the intermediate public key extracted from the immediately received public key certificate is already stored in the public key storage area R3, it is preferable that the intermediate public key extracted from the received public key certificate overwrite and be stored in the public key storage area R3 instead of the stored intermediate public key.
[0041] Next, the CPU 15 deletes (that is, clears) the public key certificate from the certificate storage area R2 (step S9), and advances the process to step S10. Thereby, it is possible to efficiently avoid a shortage of memory. If the public key certificate has already been deleted from the certificate storage area R2, the process of step S9 does not need to be performed.
[0042] In step S10, the CPU 15 transmits a response APDU including SW1 and SW2 indicating normal completion to the external terminal 2 (responds with normal completion), and waits for the reception of the next PERFORM SECURITY OPERATION command. On the other hand, in step S11, the CPU 15 transmits a response APDU including SW1 and SW2 indicating an error (abnormal completion) to the external terminal 2 (responds with an error). Here, in addition to SW1 and SW2 indicating an error, the CPU 15 may transmit a response APDU including information (e.g., 0x02) indicating which position from the head of the plurality of public key certificates the public key certificate that failed signature verification corresponds to, to the external terminal 2.
[0043] In step S12, the CPU 15 determines whether the intermediate public key is stored in the public key storage area R3. If it is determined that the intermediate public key is stored in the public key storage area R3 (step S12: YES), the process proceeds to step S13. On the other hand, if it is determined that the intermediate public key is not stored in the public key storage area R3 (step S13: NO), the process proceeds to step S14.
[0044] In step S13, the CPU 15 acquires the intermediate public key from the public key storage area R3, performs signature verification of the received public key certificate using the acquired intermediate public key, and advances the process to step S15. On the other hand, in step S14, the CPU 15 acquires the root public key from the NVM 13, performs signature verification of the received public key certificate using the acquired root public key, and advances the process to step S15.
[0045] In step S15, the CPU 15 determines whether the signature verification executed in step S13 or step S14 was successful. If it is determined that the signature verification was successful (step S15: YES), the process proceeds to step S16. On the other hand, if it is determined that the signature verification was not successful (failed) (step S15: NO), the process proceeds to step S19.
[0046] In step S16, the CPU 15 extracts the lowest-order public key from the received public key certificate (i.e., the public key certificate for which signature verification has succeeded), and causes the extracted lowest-order public key to be stored in the public key storage area R3. At this time, if an intermediate public key is stored in the public key storage area R3, the lowest-order public key extracted from the received public key certificate may be overwritten and stored in the public key storage area R3 instead of the intermediate public key. In this way, the stored lowest-order public key is used in the secure channel session between the IC chip 1 and the external terminal 2.
[0047] Next, the CPU 15 deletes (i.e., clears) the public key certificate from the certificate storage area R2 (step S17), and proceeds with the process to step S18. Note that if the public key certificate has already been deleted from the certificate storage area R2, or if the public key certificate has not yet been stored in the certificate storage area R2, the process of step S17 does not have to be performed. Alternatively, in step S16, instead of extracting the lowest-order public key, the received public key certificate may be stored in the certificate storage area R2 (in this case, the process of step S17 is not performed).
[0048] In step S18, the CPU 15 transmits a response APDU including SW1 and SW2 indicating normal termination to the external terminal 2 (responding with normal termination). On the other hand, in step S19, the CPU 15 transmits a response APDU including SW1 and SW2 indicating an error (abnormal termination) to the external terminal 2 (responding with an error). Here, in addition to SW1 and SW2 indicating an error, the CPU 15 may transmit a response APDU to the external terminal 2 including information (e.g., 0x02) indicating which position from the top the public key certificate for which signature verification has failed corresponds to among the plurality of public key certificates.
[0049] As described above, according to the above embodiment, the IC chip 1 determines whether the received public key certificate can be stored in the certificate storage area R2 based on the size of the public key certificate received from the external terminal 2 and the set capacity of the certificate storage area R2. When it is determined that the public key certificate can be stored in the certificate storage area R2, the public key certificate is stored in the certificate storage area R2. On the other hand, when it is determined that the public key certificate cannot be stored in the certificate storage area R2, the signature verification of the public key certificate is executed, and when the signature verification is successful, the public key extracted from the public key certificate is stored in the public key storage area R3. Therefore, there is no shortage of memory in the signature verification of the public key certificate, and the signature verification can be efficiently performed.
[0050] In the above embodiment, the certificate storage area R2 and the public key storage area R3 are configured to be provided in the RAM 12. However, both or either one of the certificate storage area R2 and the public key storage area R3 may be configured to be provided in the NVM 13.
Explanation of Signs
[0051] 1 IC chip 2 External terminal 11 I / O circuit 12 RAM 13 NVM 14 ROM 15 CPU 16 Coprocessor
Claims
1. An electronic information storage medium comprising a memory including a first storage area for storing public key certificates and a second storage area for storing public keys, receiving means for sequentially receiving a plurality of chained public key certificates from an external terminal, first determination means for determining whether the received public key certificate can be stored in the first storage area based on the size of the received public key certificate and the set capacity of the first storage area when any one of the plurality of chained public key certificates is received, processing means for storing the received public key certificate in the first storage area when determined to be storable by the first determination means, and for executing signature verification of the received public key certificate when determined not to be storable by the first determination means and storing the public key extracted from the received public key certificate in the second storage area when the signature verification is successful, An electronic information storage medium characterized by comprising the above.
2. The electronic information storage medium according to claim 1, wherein when the signature verification fails, the processing means transmits information indicating which position from the head of the plurality of chained public key certificates the public key certificate that failed the signature verification corresponds to, to the external terminal.
3. The electronic information storage medium according to claim 1, wherein the processing means executes signature verification of the received public key certificate using the public key stored in the second storage area, which is the public key extracted from the immediately preceding received public key certificate among the plurality of chained public key certificates.
4. When the signature verification is successful and the public key extracted from the immediately received public key certificate among the plurality of chained public key certificates is stored in the second storage area, the processing means stores the public key extracted from the received public key certificate in the second storage area instead of the stored public key. The electronic information storage medium according to any one of claims 1 to 3, characterized in that.
5. The processing means erases the public key certificate from the first storage area. The electronic information storage medium according to claim 4, characterized in that.
6. An IC chip including a memory including a first storage area for storing a public key certificate and a second storage area for storing a public key, Receiving means for sequentially receiving a plurality of chained public key certificates from an external terminal, When any one of the plurality of chained public key certificates is received, based on the size of the received public key certificate and the set capacity of the first storage area, it is determined whether the received public key certificate can be stored in the first storage area. First determination means for determining whether or not, When it is determined by the first determination means that storage is possible, the received public key certificate is stored in the first storage area, while when it is determined by the first determination means that storage is not possible, the signature verification of the received public key certificate is executed, and when the signature verification is successful, the public key extracted from the received public key certificate is stored in the second storage area. Processing means for storing, An IC chip, characterized in that it comprises.
7. An IC card including a memory including a first storage area for storing a public key certificate and a second storage area for storing a public key, Receiving means for sequentially receiving a plurality of chained public key certificates from an external terminal, When any one of the chained plurality of public key certificates is received, based on the size of the received public key certificate and the set capacity of the first storage area, first determination means for determining whether the received public key certificate can be stored in the first storage area; When it is determined by the first determination means that storage is possible, the received public key certificate is stored in the first storage area, while when it is determined by the first determination means that storage is not possible, signature verification of the received public key certificate is executed, and when the signature verification is successful, processing means for storing the public key extracted from the received public key certificate in the second storage area; An IC card characterized by comprising: **Claim 8** A public key storage method executed by an electronic information storage medium including a memory including a first storage area for storing a public key certificate and a second storage area for storing a public key, comprising: Sequentially receiving a plurality of chained public key certificates from an external terminal; When any one of the chained plurality of public key certificates is received, based on the size of the received public key certificate and the set capacity of the first storage area, determining whether the received public key certificate can be stored in the first storage area; When it is determined that the received public key certificate can be stored, storing the received public key certificate in the first storage area, while when it is determined that the received public key certificate cannot be stored, executing signature verification of the received public key certificate, and when the signature verification is successful, storing the public key extracted from the received public key certificate in the second storage area; A public key storage method characterized by including: **Claim 9** In a computer included in an electronic information storage medium including a memory including a first storage area for storing a public key certificate and a second storage area for storing a public key, Sequentially receiving a plurality of chained public key certificates from an external terminal; When any one of the plurality of chained public key certificates is received, based on the size of the received public key certificate and the set capacity of the first storage area, determining whether the received public key certificate can be stored in the first storage area; When it is determined that the received public key certificate can be stored, storing the received public key certificate in the first storage area, while when it is determined that the received public key certificate cannot be stored, performing signature verification on the received public key certificate, and when the signature verification is successful, storing the public key extracted from the received public key certificate in the second storage area; A program characterized by causing the above to be executed.
Citation Information
Patent Citations
Information process system
JP1979059845A