Electronic card authentication system, electronic card authentication device, electronic card authentication method, and program
The electronic card authentication system improves authenticity confirmation and convenience by generating a certificate based on verified key generation information, addressing vulnerabilities in existing systems.
Patent Information
- Application Number
- JP2023205984
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-06
- Publication Date
- 2025-06-18
AI Technical Summary
Existing electronic card authentication systems lack sufficient authenticity confirmation, making them vulnerable to unauthorized use when a third party obtains the electronic card.
An electronic card authentication system that includes an input reception unit for receiving key generation information, a verification unit for verifying this information, a key generation unit for generating a key pair of public and private keys based on the verification result, and a certificate generation unit for creating a certificate based on the public key.
This solution enhances the convenience and authenticity verification accuracy by confirming the authenticity of the electronic card owner based on the generated certificate, thereby reducing the risk of unauthorized use.
Smart Images

Figure 2025091029000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an electronic card authentication system, an electronic card authentication device, an electronic card authentication method, and a program.
Background Art
[0002] There is a technology for personal authentication using an electronic card. For example, Patent Document 1 discloses an authentication information signature system including a signature value generation unit that receives a signature request together with authentication information from a signature request user who requests a signature, and an authentication information verification unit that verifies the authentication information. When the verification by the authentication information verification unit is successful, the signature value generation unit generates a signature value by signing with a user signature key that is a secret key for signature of the signature request user.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, even when using Patent Document 1 for authentication by an electronic card, there is a concern of unauthorized use, for example, when a third party illegally obtains the electronic card, and there is a problem that the authenticity confirmation of the electronic card owner is not sufficient.
[0005] The present invention has been made in view of such circumstances, and an object thereof is to provide an electronic card authentication system, an electronic card authentication device, an electronic card authentication method, and a program that can improve convenience and authenticity confirmation accuracy when confirming the authenticity of an owner.
Means for Solving the Problems
[0006] To solve the above-described problems, one aspect of the present invention is an electronic card authentication system, comprising: an input reception unit that receives an input of key generation information by an owner of an electronic card; a verification unit that verifies the key generation information; a key generation unit that generates a key pair of a public key and a private key according to a verification result of the key generation information; and a certificate generation unit that generates a certificate based on the public key.
[0007] Also, one aspect of the present invention is an electronic card authentication device, comprising: an input reception unit that receives an input of key generation information by an owner of an electronic card; a verification unit that verifies the key generation information; a key generation unit that generates a key pair of a public key and a private key according to a verification result of the key generation information; and a certificate generation unit that generates a certificate based on the public key.
[0008] Also, one aspect of the present invention is an electronic card authentication method executed by a computer of an electronic card authentication device, comprising: an input reception process that receives an input of key generation information by an owner of an electronic card; a verification process that verifies the key generation information; a key generation process that generates a key pair of a public key and a private key according to a verification result of the key generation information; and a certificate generation process that generates a certificate based on the public key.
[0009] Also, one aspect of the present invention is a program for causing a computer of an electronic card authentication device to execute: an input reception step that receives an input of key generation information by an owner of an electronic card; a verification step that verifies the key generation information; a key generation step that generates a key pair of a public key and a private key according to a verification result of the key generation information; and a certificate generation step that generates a certificate based on the public key.
Advantages of the Invention
[0010] As described above, according to this invention, convenience and authenticity verification accuracy can be improved when verifying the authenticity of an owner.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Mode for Carrying Out the Invention
[0012] (First Embodiment) Hereinafter, an electronic card authentication system SYS according to the first embodiment of the present invention will be described with reference to the drawings. FIG. 1 is a system configuration diagram showing an example of the configuration of an electronic card authentication system SYS according to the first embodiment of the present invention. The electronic card authentication system SYS receives an input of key generation information from the owner of the electronic card, verifies the key generation information, and generates a key pair of a public key and a private key according to the verification result of the key generation information. And the electronic card authentication system SYS is an electronic card authentication system that generates a certificate based on the public key.
[0013] By doing so, the electronic card authentication system SYS can improve the convenience and the verification accuracy of authenticity when verifying the authenticity of the owner. Specifically, since the electronic card authentication system SYS can verify the authenticity of the owner of the electronic card based on the generated certificate, the convenience of the owner can be improved.
[0014] The electronic card authentication system SYS is composed of an electronic card 100, an electronic card authentication device 200, and an authentication device 300. The electronic card 100 includes an owner who owns the electronic card 100, a user terminal device used by the owner, an electronic card reader device connected to or mounted on the user terminal device, etc. The electronic card 100, the electronic card authentication device 200, and the authentication device 300 are connected to be communicable with each other.
[0015] The electronic card 100 is a card with an IC chip embedded therein. Key generation information used for generating a key pair of a secret key and a public key is preset in the electronic card. The key generation information is information such as a PIN code used for PIN code authentication, a password used for password authentication, and biometric information used for biometric authentication.
[0016] The electronic card 100 is read by a user terminal device or the like used by the owner who owns the electronic card, and acquires the key generation information required by the electronic card authentication device 200 from the owner. The electronic card 100 transmits the key generation information input by the owner to the electronic card authentication device 200. The electronic card 100 holds the certificate granted by the electronic card authentication device 200.
[0017] When performing electronic card authentication, the electronic card 100 performs electronic card authentication using the held certificate. Here, the certificate granted to the electronic card 100 by the electronic card authentication device 200 is either a certificate based on the public key of the key pair generated in response to successful verification of the key generation information input by the owner, or a dummy certificate based on the public key of the key pair generated in response to failed verification of the key generation information input by the owner. That is, regardless of whether the owner's input is correct or incorrect, the electronic card 100 generates a key pair and holds either a certificate corresponding to the public key of the key pair or a dummy certificate.
[0018] The electronic card authentication device 200 is a server device that issues a certificate based on a public key. The electronic card authentication device 200 obtains the public key generated from the key generation information input by the owner of the electronic card 100 from the electronic card 100. The electronic card authentication device 200 generates a Certificate Signing Request (CSR) corresponding to the public key of the key pair generated based on the fact that the key generation information that could be input by the owner of the electronic card 100 is correct, and transmits the generated CSR to the authentication device 300. Also, the electronic card authentication device 200 generates a CSR corresponding to the public key of the key pair generated based on the fact that the key generation information that could be input by the owner of the electronic card 100 is incorrect, and transmits the generated CSR to the authentication device 300.
[0019] The electronic card authentication device 200 obtains the certificate generated based on the CSR from the authentication device 300. The electronic card authentication device 200 assigns the obtained certificate to the electronic card 100.
[0020] Note that instead of generating a CSR corresponding to the public key of the key pair generated based on the fact that the key generation information that could be input by the owner of the electronic card 100 is incorrect, the electronic card authentication device 200 may assign a pre-prepared dummy certificate to the electronic card 100.
[0021] The authentication device 300 is a server device that generates a certificate corresponding to the CSR. The authentication device 300 transmits the generated certificate to the electronic card authentication device 200.
[0022] Note that the electronic card authentication device 200 and the authentication device 300 may be configured as an integrated device. Also, the electronic card authentication device 200 and the authentication device 300 may implement the functions of part or all of the functional configurations of one or both of the electronic card authentication device 200 and the authentication device 300 by a plurality of devices.
[0023] Note that the generation of the key pair based on the key generation information by the owner of the electronic card 100 may be executed in the electronic card 100 or may be executed in the electronic card authentication device 200. When generating the key pair in the electronic card authentication device 200, the private key in the generated key pair may be given to the electronic card 100.
[0024] Next, the configuration of the electronic card authentication device 200 will be described.
[0025] FIG. 2 is a block diagram showing an example of the configuration of the electronic card authentication device 200 according to the present embodiment. The electronic card authentication device 200 includes a communication unit 21, a storage unit 22, an input unit 23, an output unit 24, and a control unit 25.
[0026] The communication unit 21 has a function of communicating with the electronic card 100 and the authentication device 300 by wire or wirelessly. The communication unit 21 outputs various information such as key generation information and public keys received from the electronic card 100 to the control unit 25. Further, the communication unit 21 transmits various information such as certificates output from the control unit 25 to the electronic card 100 based on the instructions of the control unit 25. Further, the communication unit 21 outputs the certificate received from the authentication device 300 to the control unit 25. Further, the communication unit 21 transmits the CSR output from the control unit 25 to the authentication device 300 based on the instructions of the control unit 25.
[0027] The storage unit 22 is composed of a storage medium, for example, an HDD (Hard Disk Drive), a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), a RAM (Random Access read / write Memory), a ROM (Read Only Memory), or an arbitrary combination of these storage media. For example, a non-volatile memory can be used for this storage unit 22.
[0028] The input unit 23 is an input device such as a mouse or a keyboard connected to the electronic card authentication device 200. The input unit 23 receives an operation input from the outside. The input unit 23 outputs an operation signal corresponding to the operation input to the control unit 25.
[0029] The output unit 24 is an output device such as a display device. The output unit 24 outputs a display image or the like output from the control unit 25 to the output device.
[0030] The control unit 25 has a function of controlling each part of the electronic card authentication device 200. The control unit 25 includes a public key acquisition unit 251, a verification unit 252, a CSR generation unit 253, a CSR transmission unit 254, a certificate acquisition unit 255, and a certificate granting unit 256.
[0031] Based on the connection of the electronic card 100 to the reading device, the public key acquisition unit 251 receives an input of key generation information by the owner. The public key acquisition unit 251 transmits the key generation information to the electronic card 100. Here, the key generation information transmitted to the electronic card 100 may be the value input by the owner as it is, or may be transmitted after being converted into a value returned by a function such as a hash function for which the value is uniquely determined. The public key acquisition unit 251 acquires the public key among the key pairs generated by the electronic card 100.
[0032] When the key generation information is input by the owner, the verification unit 252 verifies the key generation information. Specifically, the verification unit 252 verifies whether the key generation information is correct. When the key generation information is correct, the verification unit 252 outputs information indicating that the verification of the key generation information has succeeded to the CSR generation unit 253. On the other hand, when the key generation information is incorrect, the verification unit 252 outputs information indicating that the verification of the key generation information has failed to the CSR generation unit 253.
[0033] The CSR generation unit 253 generates a CSR according to the information indicating successful verification of the key generation information. The CSR generation unit 253 outputs the generated CSR to the CSR transmission unit 254. Also, the CSR generation unit generates a CSR according to the information indicating failure in verifying the key generation information. The CSR generation unit 253 outputs the generated CSR to the CSR transmission unit 254. Here, the CSR contains the public key of the electronic card 100.
[0034] The CSR transmission unit 254 transmits to the authentication device 300 a CSR according to the information indicating successful verification of the key generation information or a CSR according to the information indicating failure in verifying the key generation information.
[0035] The certificate acquisition unit 255 acquires from the authentication device 300 the certificate generated based on the CSR. The certificate acquisition unit 255 outputs the acquired certificate to the certificate granting unit 256. Here, the certificate is generated based on the CSR according to the information indicating successful verification of the key generation information, and a dummy certificate is generated based on the CSR according to the information indicating failure in verifying the key generation information.
[0036] The certificate granting unit 256 grants the certificate to the electronic card 100.
[0037] Next, the flow of the certificate generation process in the electronic card authentication system SYS will be described.
[0038] FIG. 3 is a sequence diagram showing an example of the flow of the certificate generation process in the electronic card authentication system SYS according to the present embodiment.
[0039] In step ST101, the electronic card authentication device 200 reads the electronic card 100 and accepts the input of the key generation information by the owner of the electronic card 100. Thereafter, the electronic card authentication device 200 executes the process in step ST102.
[0040] In step ST102, the electronic card authentication device 200 transmits key generation information to the electronic card 100. Thereafter, the electronic card 100 executes the process of step ST103.
[0041] In step ST103, the electronic card 100 generates a key pair of a private key and a public key based on the key generation information. Thereafter, the electronic card 100 executes the process of step ST104.
[0042] In step ST104, the electronic card 100 transmits the public key to the electronic card authentication device 200. Thereafter, the electronic card authentication device 200 executes the process of step ST105.
[0043] In step ST105, the electronic card authentication device 200 generates a CSR according to the verification result of the key generation information. Thereafter, the electronic card authentication device 200 executes the process of step ST106.
[0044] In step ST106, the electronic card authentication device 200 transmits the CSR to the authentication device 300. Thereafter, the authentication device 300 executes the process of step ST107.
[0045] In step ST107, the authentication device 300 generates a certificate according to the CSR. Thereafter, the authentication device 300 executes the process of step ST108.
[0046] In step ST108, the authentication device 300 transmits the certificate to the electronic card authentication device 200. Thereafter, the electronic card authentication device 200 executes the process of step ST109.
[0047] In step ST109, the electronic card authentication device 200 grants the certificate to the electronic card 100. Thereafter, the electronic card authentication system SYS ends the process according to FIG. 3.
[0048] Next, the certificate generation process in the electronic card authentication device 200 will be described.
[0049] Figure 4 is a flowchart showing an example of the certificate generation process in the electronic card authentication device 200 according to the present embodiment.
[0050] In step S101, the electronic card authentication device 200 reads the electronic card 100 based on the connection of the electronic card 100 to the reading device. Thereafter, the electronic card authentication device 200 executes the process of step S102.
[0051] In step S102, the electronic card authentication device 200 receives key generation information as an input by the owner of the electronic card 100. The electronic card authentication device 200 transmits the key generation information to 100. Also, the electronic card authentication device 200 verifies the key generation information. Thereafter, the electronic card authentication device 200 executes the process of step S103.
[0052] In step S103, the electronic card authentication device 200 obtains the public key among the key pairs generated by the electronic card 100 based on the key generation information. Thereafter, the electronic card authentication device 200 executes the process of step S104.
[0053] In step S104, the electronic card authentication device 200 generates a CSR according to the verification result of the key generation information. Thereafter, the electronic card authentication device 200 executes the process of step ST105.
[0054] In step S105, the electronic card authentication device 200 transmits the CSR to the authentication device 300. Thereafter, the process of step S106 is executed.
[0055] In step S106, the electronic card authentication device 200 obtains a certificate from the authentication device 300. Thereafter, the electronic card authentication device 200 executes the process of step S107.
[0056] In step S107, the electronic card authentication device 200 assigns a certificate to the electronic card 100. Thereafter, the electronic card authentication device 200 ends the process according to FIG. 4.
[0057] Next, an example of the authentication process of the electronic card in the electronic card authentication system SYS will be described.
[0058] FIG. 5 is a sequence diagram showing an example of the authentication process of the electronic card 100 in the electronic card authentication system SYS according to the present embodiment. Here, the client CL is, for example, the electronic card 100. Also, the server SV is a server device that performs TLS (Transport Layer Security) authentication.
[0059] In step S201, the client CL sends a Client Hello indicating the start of a handshake to the server SV. Thereafter, the server SV executes the process of step S202.
[0060] In step S202, the server SV sends a Serveer Hello, which is a response message to the Client Hello, to the CL. Thereafter, the server SV executes the process of step S203.
[0061] In step S203, the server SV sends the server certificate to the client CL as a Certificate. Thereafter, the server SV executes the process of step S204.
[0062] In step S204, when the public key is not included in the server certificate, the server SV sends a public key for exchanging a common key to the client CL as Server Key Exchange. Thereafter, the server SV executes the process of step S205.
[0063] In step S205, the server SV requests the client CL to send a certificate for client authentication as a Certificate Request. After that, the server SV executes the process of step S206.
[0064] In step S206, the server SV notifies the client CL as Server Hello Done that the above-mentioned message starting from Server Hello in step S202 has been completed. After that, the client CL executes the process of step S207.
[0065] In step S207, when the client CL receives a Certificate Request message from the server SV as a Certificate, the client CL sends a client certificate to the server SV. In this case, the client CL also sends a certificate list (certificate chain) up to the root certificate to the server SV.
[0066] In step S207, the client certificate is, for example, the certificate of the electronic card 100. The electronic card authentication device 200 receives the input of the key generation information of the electronic card 100 and sends the key generation information to the electronic card 100. The electronic card 100 regenerates a key pair and updates the key pair stored inside. After that, the client CL executes the process of step S208.
[0067] In step S208, the client CL generates random information called a pre-master secret for generating a common key. The client CL encrypts the generated pre-master secret using the public key of the server SV and sends it to the server SV. After that, the client CL executes the process of step S209.
[0068] In step S209, when the client CL has sent the Certificate message to the server SV in step S207, the client CL sends the message as Certificate Verify to the server SV as signature data for the client certificate.
[0069] The signature data for the client certificate in step S209 is generated using the private key corresponding to the public key included in the certificate held by the electronic card 100. Here, if the input of the key generation information by the owner of the electronic card 100 is incorrect, the public key generated and held in the electronic card 100 is not correctly generated. Therefore, the server SV fails to verify the signature data and does not perform the subsequent authentication process. For this reason, since the electronic card authentication system SYS can perform multi-factor authentication only using the electronic card 100, the convenience of the user can be improved. After that, the client CL executes the process of step S210.
[0070] In step S210, the client CL generates a master secret using a random number and a pre-master secret. Then, the client CL generates a common key from the master secret. The client CL then sends a Change Cipher Spec to the server SV in order to notify the server SV that it will perform encrypted communication using the generated common key. After that, the client CL executes the process of step S211.
[0071] In step S211, the client CL notifies the server SV that it has successfully authenticated the server and can share the common key. After that, the server SV executes the process of step S212.
[0072] In step S212, the server SV generates a master secret based on the pre-master secret and the random number received from the client CL, and generates a common key. The server SV notifies the client CL of the generation of the common key by means of a Change Cipher Spec. Thereafter, the server SV executes the process of step S213.
[0073] In step S213, the server SV notifies the client CL that it has successfully authenticated the client and can share the common key as Finished. Thereafter, the electronic card authentication system SYS ends the process according to FIG. 5.
[0074] As described above, the electronic card authentication system SYS according to the present embodiment includes an input reception unit (public key acquisition unit 251) that receives input of key generation information by the owner of the electronic card 100, a verification unit 252 that verifies the key generation information, and a key generation unit (electronic card 100) that generates a key pair of a public key and a private key according to the verification result of the key generation information, and a certificate generation unit (authentication device 300) that generates a certificate based on the public key.
[0075] Thereby, the electronic card authentication system SYS can improve the convenience and the confirmation accuracy of authenticity when confirming the authenticity of the owner. Specifically, since the electronic card authentication system SYS can confirm the authenticity of the owner of the electronic card based on the generated certificate, the convenience of the owner can be improved.
[0076] As described above, the embodiments of the present invention have been described in detail with reference to the drawings. However, the specific configuration is not limited to the above, and various design changes and the like can be made without departing from the gist of the present invention.
[0077] For example, in the above-described embodiment, an example configured by the electronic card authentication device 200 has been described. However, one aspect of the present invention may be realized by a plurality of devices including the electronic card authentication device 200 and other devices capable of realizing a part thereof.
[0078] Note that the program operating in the electronic card authentication device 200 according to one aspect of the present invention may be a program (a program that causes a computer to function) that controls one or more processors such as a CPU (Central Processing Unit) so as to realize the functions shown in each of the above-described embodiments and modified examples related to one aspect of the present invention. Here, the computer includes a quantum computer. And the information handled by these respective devices is temporarily stored in a RAM (Random Access Memory) during its processing, and then stored in various storages such as a flash memory and an HDD (Hard Disk Drive), and may be read by a CPU or the like as necessary and corrected or written.
[0079] Note that part or all of the electronic card authentication device 200 in each of the above-described embodiments and modified examples may be realized by a computer having one or more processors. In that case, a program for realizing this control function may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed to realize it.
[0080] Note that the "computer system" referred to here is a computer system built in the electronic card authentication device 200 and includes hardware such as an OS and peripheral devices. Also, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, a magneto-optical disk, a ROM, a CD-ROM, or a storage device such as a hard disk built in a computer system.
[0081] Furthermore, the "computer-readable recording medium" may include those that hold a program dynamically for a short time, such as a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, and those that hold a program for a certain period of time, such as volatile memory inside a computer system serving as a server or client in that case. Also, the above program may be for realizing a part of the aforementioned functions, and furthermore, it may be for realizing the aforementioned functions in combination with a program already recorded in the computer system.
[0082] Also, a part or all of the electronic card authentication device 200 in each of the above-described embodiments and modification examples may typically be realized as an LSI, which is an integrated circuit, or as a chipset. Also, each functional block of the electronic card authentication device 200 in each of the above-described embodiments and modification examples may be individually chipized, or a part or all of them may be integrated and chipized. Also, the method of integration is not limited to LSI and may be realized by a dedicated circuit and / or a general-purpose processor. Also, when an integration technology that replaces LSI appears due to the progress of semiconductor technology, it is also possible to use an integrated circuit based on that technology.
[0083] As described above, as one aspect of the present invention, each embodiment and modification example has been described in detail with reference to the drawings. However, the specific configuration is not limited to each embodiment and modification example, and design changes and the like within the scope not departing from the gist of the present invention are also included. Also, one aspect of the present invention can be variously modified within the scope shown in the claims, and embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention. Also, a configuration in which elements described in each of the above embodiments and modification examples and elements having the same effect are replaced with each other is also included.
Explanation of Reference Numerals
[0084] SYS Electronic card authentication system 100 Electronic card 200 Electronic card authentication device 21 Communication Unit 22 Memory Unit 23 Input Unit 24 Output Unit 25 Control Unit 251 Public Key Acquisition Unit 252 Verification Unit 253 CSR Generation Unit 254 CSR Transmission Unit 255 Certificate Acquisition Unit 256 Certificate Granting Unit 300 Authentication Device CL Client SV Server
Claims
1. An input receiving unit that receives an input of key generation information by the owner of an electronic card, A verification unit that verifies the key generation information, A key generation unit that generates a key pair of a public key and a private key according to the verification result of the key generation information, A certificate generation unit that generates a certificate based on the public key, comprising An electronic card authentication system.
2. The key generation unit generates the key pair regardless of whether the verification of the key generation information is successful or failed, The electronic card authentication system according to Claim 1.
3. The certificate generation unit generates a certificate based on the public key generated based on the successful verification of the key generation information, and generates a dummy certificate, which is a dummy certificate, based on the public key generated based on the failed verification of the key generation information, The electronic card authentication system according to Claim 2.
4. An input receiving unit that receives an input of key generation information by the owner of an electronic card, A verification unit that verifies the key generation information, A key generation unit that generates a key pair of a public key and a private key according to the verification result of the key generation information, A certificate generation unit that generates a certificate based on the public key, comprising An electronic card authentication device.
5. An electronic card authentication method executed by a computer of an electronic card authentication device, An input receiving process that receives an input of key generation information by the owner of an electronic card, A verification process that verifies the key generation information, A key generation process that generates a key pair of a public key and a private key according to the verification result of the key generation information, A certificate generation process that generates a certificate based on the public key, having Electronic card authentication method.
6. A program for causing a computer of an electronic card authentication device to execute, An input reception step for receiving input of key generation information by the owner of the electronic card, A verification step for verifying the key generation information, A key generation step for generating a key pair of a public key and a private key according to the verification result of the key generation information, A certificate generation step for generating a certificate based on the public key, A program for causing the above to execute.
Citation Information
Patent Citations
Authentication information signature system, authentication device, authentication information signature program, and authentication information signature method
JP2023132934A