Digital certificate generating device, electronic information storage medium, digital certificate generating method, digital certificate acquiring method, processing result responding method, and program

The digital certificate generation device and electronic information storage medium address the challenge of combining current and new encryption methods in IC card and IFD systems by generating hybrid digital certificates, thereby improving security and compatibility.

JP2025095842APending Publication Date: 2025-06-26DAI NIPPON PRINTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023212168
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-15
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

In an encryption system using IC cards and IFDs, the combination of current and new encryption methods poses challenges in interpreting digital certificates and determining which encryption method to select, leading to potential errors and process stops.

Method used

A digital certificate generation device and electronic information storage medium that acquire and manage control reference information, including an encryption method information storage area and an arbitrary area for storing information freely defined by an application provider, to generate hybrid digital certificates that include signatures from both current and new encryption methods.

Benefits of technology

This solution enhances security while maintaining compatibility in the cryptographic system by ensuring seamless operation with both current and new encryption methods, reducing the risk of errors and process stops.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025095842000001_ABST
    Figure 2025095842000001_ABST
Patent Text Reader

Abstract

To provide a digital certificate generating device, an electronic information storage medium, a digital certificate generating method, a digital certificate acquiring method, a processing result responding method, and a program capable of improving security while maintaining compatibility in a cryptographic system in which a current specification cryptographic method and a new specification cryptographic method are used together.SOLUTION: An IFD 23 obtains, from an IC card 1n, a CRT including an encryption method information storage area for storing information indicating a current specification public key encryption method, determines whether the CRT includes an arbitrary area, determines whether information indicating a new specification public key encryption method is stored in the arbitrary area when it is determined that the CRT includes an arbitrary area, generates the above-mentioned hybrid digital certificate when it is determined that information indicating the new specification public key encryption method is stored in the arbitrary area, and transmits the generated hybrid digital certificate to the IC card 1n.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of IC (Integrated Circuit) cards and the like used in an encryption system in which an encryption method of a current specification and an encryption method of a new specification are used in combination.

Background Art

[0002] Conventionally, an encryption system including an IC card and an IFD (Interface Device) that performs encrypted communication with the IC card has become obsolete mainly due to the evolution of the encryption analysis environment for side-channel attacks. Therefore, the encryption system is continuously operated while updating the hardware and the accompanying software. For example, it is common to update the IC card every 3 to 5 years for a credit card and every 10 years for a My Number card. However, even if the encryption method (encryption algorithm) is endangered, as long as the impact is not fatal, the old and new encryption methods are used in combination without switching the entire encryption system all at once, and the use of the encryption method of the current specification (old specification) is gradually reduced in accordance with the migration plan while taking time, and a migration method to the encryption method of the new specification is adopted. This is an effective means in terms of smoothing the total replacement cost of the IC card and the IFD that occurs when switching the encryption method all at once, and avoiding a fatal situation where the service stops due to problems that may occur with the change of the encryption method. Note that the IFD is composed of, for example, a host and a reader / writer.

[0003] By the way, when cryptanalysis technology advances and the encryption methods implemented in the IC card and the IFD become obsolete or endangered, the encryption system adopting the IC card and the IFD needs to set a migration plan to update the encryption method. The migration plan has different properties depending on the encryption method newly adopted by the encryption system. For example, when the DES encryption is endangered and migrates to the AES encryption, or when the RSA encryption is endangered and migrates to the elliptic curve (ECC) encryption, sufficient time is spent on verifying the encryption method after migration, and the possibility of security threats is extremely low. Therefore, a migration plan as shown in Figure 1 is set. Figure 1 is a diagram showing an example of a migration plan to a sufficiently verified encryption method.

[0004] In Figure 1, first, determine the time to remove the IC card corresponding to (in other words, compliant with, or supporting) the encryption method of the current specification from the market, and define the period T11 as the switching period towards it. When the IC card reaches its expiration date within the period T11 shown in Figure 1, it switches to an IC card corresponding to both encryption methods (that is, both the encryption method of the current specification and the new specification). Next, determine the time to remove the IFD corresponding to the encryption method of the current specification from the market, and define the period T12 as the switching period towards it. Each individual IFD needs to be made compatible with the encryption method of the new specification within the period T12, and all IFDs must complete the modification work within the period T12. Finally, determine the time to make all IC cards and IFDs in the market compatible with the new specification, and define the period T13 as the switching period towards it. The IC cards that reach their expiration date within the period T13 will sequentially switch to IC cards corresponding to the encryption method of the new specification. IC cards corresponding to both encryption methods have a large amount of software to be implemented, require a large amount of memory capacity to store their program codes, and need to evaluate both encryption methods to ensure operation. Therefore, the costs involved in development and manufacturing increase compared to IC cards corresponding to a single-specification encryption method. Therefore, there is a tendency to migrate to IC cards corresponding only to the encryption method of the new specification as early as possible.

[0005] On the one hand, in recent years, the feasibility of quantum computers has advanced rapidly, and in a situation where the current public-key cryptosystems (asymmetric cryptosystems) such as RSA cryptography and elliptic curve cryptography are at risk, a shift to post-quantum computer (PQC) cryptography is being considered. However, when shifting to a cryptosystem that has not been given sufficient time for security verification, such as post-quantum computer cryptography, after it actually begins to be widely used, it is conceivable that, for example, attack methods and vulnerabilities may be found in unexpected places like the Rainbow cryptography, rendering it unusable. Therefore, a hybrid method is adopted that combines the current specification cryptosystem and the new specification cryptosystem, expecting that security will be ensured as long as at least one of them is secure. For example, a migration plan as shown in FIG. 2 is set. FIG. 2 is a diagram showing an example of a migration plan to a cryptosystem that cannot be said to have sufficient verification.

[0006] In FIG. 2, first, the expiration date of the current specification cryptosystem is determined, and T21, which is the switching period towards it, is defined. The expiration dates of the IFD and the IC card do not necessarily have to match, but the period T22 shown in FIG. 2 corresponds to both cryptosystems for both the IFD and the IC card. If vulnerabilities of the new specification cryptosystem are discovered during the period T22, the IFD is immediately reverted to the current specification cryptosystem, and the IC card is reverted to the current specification cryptosystem when it is updated due to the expiration date or the like. After the security of the new specification cryptosystem is confirmed, the IC card issuance period T23 corresponding to both cryptosystems is defined, and at the same time, IC cards corresponding only to the new specification cryptosystem can be put on the market. As a result, with the arrival of the expiration date following the issuable expiration date of the IC card corresponding to both cryptosystems, the switch is sequentially made to the IC card corresponding to the new specification cryptosystem. Then, after there are no IC cards corresponding to both cryptosystems in the market, the market launch of the IFD corresponding to the new specification cryptosystem is started in the period T24.

[0007] Patent Document 1 discloses a technique for generating a hybrid digital certificate used in a step-by-step method of gradually starting operation of a new cryptographic system when upgrading components of a cryptographic system (such as digital signatures, public keys, etc.) to support the new cryptographic system. The hybrid digital certificate disclosed in Patent Document 1 includes a public key field containing a first public key related to a first cryptographic system and a signature value field containing a first digital signature of a certification authority, and further includes an extension area containing a second public key related to a second cryptographic system and a second digital signature of the certification authority.

Prior Art Documents

Patent Documents

[0008]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0009] However, for example, when an IC card that supports only the current specification's cryptographic method receives a hybrid digital certificate as disclosed in Patent Document 1 from an IFD that supports both specifications' cryptographic methods, there is a possibility that the structure of the digital certificate cannot be interpreted, and even if it can be interpreted, it is impossible to determine which of the current specification's cryptographic method and the new specification's cryptographic method to select, so there is a problem that the process stops due to, for example, an error.

[0010] Therefore, in view of the above problems and the like, the present invention has been made, and an object of the present invention is to provide a digital certificate generation device, an electronic information storage medium, a digital certificate generation method, a digital certificate acquisition method, a processing result response method, and a program that can improve security while maintaining compatibility in a cryptographic system in which the cryptographic method of the current specification and the cryptographic method of the new specification are used in combination.

Means for Solving the Problems

[0011] In order to solve the above problems, the invention according to claim 1 is a digital certificate generation device capable of communicating with an electronic information storage medium, comprising: an acquisition means for acquiring control reference information including an encryption method information storage area for storing information indicating a first public key encryption method from the electronic information storage medium; a first determination means for determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; a second determination means for determining whether information indicating a second public key encryption method is stored in the arbitrary area when it is determined by the first determination means that the arbitrary area is included in the control reference information; a generation means for generating a digital certificate including a first storage area for storing a first digital signature generated by the first public key encryption method using a first secret key and a first predetermined data, and public key information of a first public key forming a key pair with the first secret key, and a second storage area for storing a second digital signature generated by the second public key encryption method using a second secret key and a second predetermined data, and public key information of a second public key forming a key pair with the second secret key; and a transmission means for transmitting the digital certificate generated by the generation means to the electronic information storage medium.

[0012] The invention according to claim 2 is the digital certificate generation device according to claim 1, characterized in that the second predetermined data is the first digital signature.

[0013] The invention according to claim 3 is the digital certificate generation device according to claim 1 or 2, characterized in that when it is determined by the first determination means that the arbitrary area is not included in the control reference information, or when it is determined by the second determination means that information indicating the second public key encryption method is not stored in the arbitrary area, the generation means generates a digital certificate including the first storage area and not including the second storage area.

[0014] The invention according to claim 4 is characterized in that, in the digital certificate generation device according to claim 1 or 2, the second storage area is an arbitrary area for storing information freely defined by an application provider.

[0015] The invention according to claim 5 is an electronic information storage medium capable of communicating with a digital certificate generation device, and includes a cryptographic method information storage area for storing information indicating a first public key cryptographic method, and an arbitrary area for storing information freely defined by an application provider. The storage means stores the control reference information in which information indicating a second public key cryptographic method is stored in the arbitrary area. The first transmission means reads out the control reference information in response to a read instruction from the digital certificate generation device and transmits it to the digital certificate generation device. The digital certificate generated by the digital certificate generation device based on the control reference information includes a first digital signature generated by the first public key cryptographic method using a first private key and first predetermined data, and public key information of a first public key forming a key pair with the first private key. The first storage area stores the first digital signature and the public key information of the first public key. The second storage area stores a second digital signature generated by the second public key cryptographic method using a second private key and second predetermined data, and public key information of a second public key forming a key pair with the second private key. The receiving means receives the digital certificate from the digital certificate generation device.

[0016] The invention according to claim 6 is characterized in that, in the electronic information storage medium according to claim 5, the second predetermined data is the first digital signature.

[0017] The invention according to claim 7 is the electronic information storage medium according to claim 5 or 6, further comprising: first signature verification means for verifying the first digital signature by the first public key cryptosystem using the first public key; second signature verification means for verifying the second digital signature by the second public key cryptosystem using the second public key; and second transmission means for transmitting at least one of the verification result of the first digital signature and the verification result of the second digital signature to the digital certificate generation device.

[0018] The invention according to claim 8 is the electronic information storage medium according to claim 5 or 6, wherein the second storage area is an arbitrary area for storing information freely defined by the application provider.

[0019] The invention according to claim 9 is a digital certificate generation device capable of communicating with an electronic information storage medium, comprising: a control reference information including an encryption method information storage area for storing information indicating a first public key cryptosystem, and an arbitrary area for storing information freely defined by an application provider, wherein the control reference information is set such that information indicating a second public key cryptosystem is stored in the arbitrary area; first transmission means for transmitting the setting instruction of the control reference information to the electronic information storage medium; a first storage area for storing a first digital signature generated by the first public key cryptosystem using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key, when a processing result indicating normal termination is received from the electronic information storage medium in response to the setting instruction; a second storage area for storing a second digital signature generated by the second public key cryptosystem using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key; generation means for generating the digital certificate including the first storage area and the second storage area; and second transmission means for transmitting the digital certificate generated by the generation means to the electronic information storage medium.

[0020] The invention according to claim 10 is the digital certificate generation device according to claim 9, wherein the second predetermined data is the first digital signature.

[0021] The invention according to claim 11 is the digital certificate generation device according to claim 9, wherein when a processing result indicating the end of a warning is received from the electronic information storage medium according to the setting instruction, the generation means generates a digital certificate including the first storage area and not including the second storage area.

[0022] The invention according to claim 12 is the digital certificate generation device according to claim 9 or 10, wherein the second storage area is an arbitrary area for storing information freely defined by the application provider.

[0023] The invention according to claim 13 is the digital certificate generation device according to claim 9 or 10, further comprising third transmission means for transmitting control reference information including an encryption method information storage area for storing information indicating the second public key encryption method to the electronic information storage medium when a processing result indicating an error is received from the electronic information storage medium according to the setting instruction.

[0024] The invention according to claim 14 is an electronic information storage medium capable of communicating with a digital certificate generation device, comprising a receiving means for receiving a setting instruction including control reference information including an encryption method information storage area for storing information indicating a first public key encryption method from the digital certificate generation device, a first determination means for determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information, a second determination means for determining whether information indicating a second public key encryption method is stored in the arbitrary area when the first determination means determines that the arbitrary area is included in the control reference information, a third determination means for determining whether the electronic information storage medium corresponds to the second public key encryption method when the second determination means determines that information indicating the second public key encryption method is stored in the arbitrary area, and a response means for responding to the digital certificate generation device with a processing result indicating normal termination according to the setting instruction when the third determination means determines that the electronic information storage medium corresponds to the second public key encryption method.

[0025] The invention according to claim 15 is the electronic information storage medium according to claim 14, wherein when the third determination means determines that the electronic information storage medium does not correspond to the second public key encryption method, the response means responds to the digital certificate generation device with a processing result indicating warning termination according to the setting instruction.

[0026] The invention according to claim 16 is the electronic information storage medium according to claim 14, wherein when the first determination means determines that the arbitrary area is not included in the control reference information, or when the second determination means determines that information indicating the second public key encryption method is not stored in the arbitrary area, the response means responds to the digital certificate generation device with a processing result indicating normal termination according to the setting instruction.

[0027] The invention according to claim 17 is the electronic information storage medium according to claim 14, further comprising fourth determination means for determining whether the electronic information storage medium supports the first public key cryptosystem, and when the fourth determination means determines that the electronic information storage medium does not support the first public key cryptosystem, the response means responds to the digital certificate generation device with a processing result indicating an error in response to the setting instruction.

[0028] The invention according to claim 18 is a digital certificate generation method executed by a digital certificate generation device capable of communicating with an electronic information storage medium, comprising the steps of: obtaining control reference information including an encryption method information storage area storing information indicating a first public key cryptosystem from the electronic information storage medium; determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; when it is determined that the arbitrary area is included in the control reference information, determining whether information indicating a second public key cryptosystem is stored in the arbitrary area; when it is determined that the information indicating the second public key cryptosystem is stored in the arbitrary area, generating a digital certificate including a first storage area storing a first digital signature generated by the first public key cryptosystem using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key, and a second storage area storing a second digital signature generated by the second public key cryptosystem using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key; and transmitting the generated digital certificate to the electronic information storage medium.

[0029] The invention according to claim 19 is a digital certificate acquisition method executed by an electronic information storage medium capable of communicating with a digital certificate generation device, the method comprising: a step of storing control reference information including a cryptographic method information storage area for storing information indicating a first public key cryptographic method and an arbitrary area for storing information freely defined by an application provider, and storing, in a storage means, the control reference information in which information indicating a second public key cryptographic method is stored in the arbitrary area; a step of reading out the control reference information in response to a read instruction from the digital certificate generation device and transmitting the control reference information to the digital certificate generation device; and a step of acquiring, from the digital certificate generation device, the digital certificate generated by the digital certificate generation device based on the control reference information, the digital certificate including: a first storage area for storing a first digital signature generated by the first public key cryptographic method using a first secret key and a first predetermined data, and public key information of a first public key forming a key pair with the first secret key; and a second storage area for storing a second digital signature generated by the second public key cryptographic method using a second secret key and a second predetermined data, and public key information of a second public key forming a key pair with the second secret key.

[0030] The invention according to claim 20 is a digital certificate generation method executed by a digital certificate generation device capable of communicating with an electronic information storage medium, comprising a control reference information including a cryptographic method information storage area for storing information indicating a first public key cryptographic method and an arbitrary area for storing information freely defined by an application provider, and transmitting a setting instruction of the control reference information in which information indicating a second public key cryptographic method is stored in the arbitrary area to the electronic information storage medium; when a processing result indicating normal termination is received from the electronic information storage medium in response to the setting instruction, a first storage area for storing a first digital signature generated by the first public key cryptographic method using a first secret key and a first predetermined data, and public key information of a first public key forming a key pair with the first secret key; and a second storage area for storing a second digital signature generated by the second public key cryptographic method using a second secret key and a second predetermined data, and public key information of a second public key forming a key pair with the second secret key, and generating the digital certificate including the first and second storage areas; and transmitting the generated digital certificate to the electronic information storage medium.

[0031] The invention according to claim 21 is a processing result response method executed by an electronic information storage medium capable of communicating with a digital certificate generation device, comprising receiving a setting instruction including control reference information including a cryptographic method information storage area for storing information indicating a first public key cryptographic method from the digital certificate generation device; determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; when it is determined that the arbitrary area is included in the control reference information, determining whether information indicating a second public key cryptographic method is stored in the arbitrary area; when it is determined that information indicating a second public key cryptographic method is stored in the arbitrary area, determining whether the electronic information storage medium supports the second public key cryptographic method; and when it is determined that the electronic information storage medium supports the second public key cryptographic method, responding to the digital certificate generation device with a processing result indicating normal termination in response to the setting instruction.

[0032] The invention according to claim 22 causes a computer included in a digital certificate generation device capable of communicating with an electronic information storage medium to acquire control reference information including an encryption method information storage area for storing information indicating a first public key encryption method from the electronic information storage medium, determine whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information, determine whether information indicating a second public key encryption method is stored in the arbitrary area when it is determined that the arbitrary area is included in the control reference information, and when it is determined that the information indicating the second public key encryption method is stored in the arbitrary area, a first storage area for storing a first digital signature generated by the first public key encryption method using a first private key and first predetermined data, and public key information of a first public key forming a key pair with the first private key, a second storage area for storing a second digital signature generated by the second public key encryption method using a second private key and second predetermined data, and public key information of a second public key forming a key pair with the second private key, generate a digital certificate including the above, and transmit the generated digital certificate to the electronic information storage medium.

[0033] The invention according to claim 23 causes a computer included in an electronic information storage medium capable of communicating with a digital certificate generation device to store, in an encryption method information storage area, information indicating a first public key encryption method, and control reference information including an arbitrary area for storing information freely defined by an application provider, the control reference information having information indicating a second public key encryption method stored in the arbitrary area, in a storage means; read out the control reference information in response to a read instruction from the digital certificate generation device and transmit the control reference information to the digital certificate generation device; and acquire from the digital certificate generation device a digital certificate generated by the digital certificate generation device based on the control reference information, the digital certificate including a first storage area storing a first digital signature generated by the first public key encryption method using a first private key and first predetermined data, and public key information of a first public key forming a key pair with the first private key, and a second storage area storing a second digital signature generated by the second public key encryption method using a second private key and second predetermined data, and public key information of a second public key forming a key pair with the second private key.

[0034] The invention according to claim 24 is a control reference information including an encryption method information storage area for storing information indicating a first public key encryption method and an arbitrary area for storing information freely defined by an application provider in a computer included in a digital certificate generation device capable of communicating with an electronic information storage medium. The method includes transmitting, to the electronic information storage medium, a setting instruction of the control reference information in which information indicating a second public key encryption method is stored in the arbitrary area; and when a processing result indicating normal termination is received from the electronic information storage medium in response to the setting instruction, storing a first digital signature generated by the first public key encryption method using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key in a first storage area; and storing a second digital signature generated by the second public key encryption method using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key in a second storage area, and generating the digital certificate including the above; and transmitting the generated digital certificate to the electronic information storage medium.

[0035] The invention according to claim 25 is a method including receiving, by a computer included in an electronic information storage medium capable of communicating with a digital certificate generation device, a setting instruction including control reference information including an encryption method information storage area for storing information indicating a first public key encryption method; determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; when it is determined that the arbitrary area is included in the control reference information, determining whether information indicating a second public key encryption method is stored in the arbitrary area; when it is determined that the information indicating the second public key encryption method is stored in the arbitrary area, determining whether the electronic information storage medium supports the second public key encryption method; and when it is determined that the electronic information storage medium supports the second public key encryption method, responding to the digital certificate generation device with a processing result indicating normal termination in response to the setting instruction.

Advantages of the Invention

[0036] According to the present invention, in an encryption system in which an encryption method of a current specification and an encryption method of a new specification are used in combination, it is possible to improve security while maintaining compatibility.

Brief Description of Drawings

[0037]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Mode for Carrying Out the Invention

[0038] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. The embodiments described below are embodiments when the present invention is applied to an encryption system including an IC card and an IFD.

[0039] 1. Configuration and Function of Encryption System S ​​First, referring to FIG. 3, the configuration and functions of the encryption system S will be described. FIG. 3 is a diagram showing a schematic configuration example of the encryption system S. As shown in FIG. 3, the encryption system S is configured to include IC cards 1n (n = 1, 2, 3 ···), IFDs 2m (m = 1, 2, 3 ···), etc. The IC card 1n and the IFD 2m can communicate with each other in a contact or non-contact manner. Each IC card 1n is equipped with an IC chip Cn and is used by the user Un. For example, the IC chip Cn is mounted on a credit card, a cash card, a transportation card, or a My Number card. Further, the IC chip Cn may be mounted on a small IC card that is detachable from a mobile device, or may be mounted on an embedded substrate so that it cannot be easily removed or replaced from the mobile device as an eUICC (Embedded Universal Integrated Circuit Card). Each IFD 2m includes a host Hm and a reader / writer RWm and is used in the facility Tm. Here, examples of the facility Tm include commercial facilities such as stores, transportation facilities including gates of trains and highways, and public facilities such as government offices.

[0040] In the following description, it is assumed that the IC card 11 (IC chip C1) supports only the public key encryption method of the current specification, the IC card 12 (IC chip C2) supports only the public key encryption method of the new specification, and the IC card 13 (IC chip C3) supports both public key encryption methods (both the current specification and the new specification). The IC card 13 (IC chip C3) is an example of the electronic information storage medium of the present invention. On the other hand, it is assumed that the IFD 21 (host H1) supports only the public key encryption method of the current specification, the IFD 22 (host H2) supports only the public key encryption method of the new specification, and the IFD 23 (host H3) supports both public key encryption methods. The IFD 23 (host H3) is an example of the digital certificate generation device of the present invention. For the public key encryption method of the current specification, for example, the RSA encryption algorithm or the elliptic curve encryption algorithm is applied, and for the public key encryption method of the new specification, for example, the post-quantum computer (PQC) encryption algorithm is applied.

[0041] 1-1. Configuration and Function of IC Card 1n Next, with reference to FIG. 4, the configuration and functions of the IC card 1n will be described. FIG. 4 is a diagram showing an example of the hardware configuration of the IC chip 1n. As shown in FIG. 4, an IC chip Cn is mounted on the IC card 1n. The IC chip Cn includes an I / O circuit 101, a RAM (Random Access Memory) 102, an NVM (Nonvolatile Memory) 103, a ROM (Read Only Memory) 104, a CPU (Central Processing Unit) 105 (an example of a computer), a coprocessor 106 that performs cryptographic operations, and the like. The I / O circuit 101 serves as an interface with the IFD 2m (reader / writer RWm). Note that the communication between the IC chip Cn and the IFD 2m (reader / writer RWm) may be non-contact communication or contact communication. In the case of non-contact communication, for example, communication between the IC chip Cn and the IFD 2m (reader / writer RWm) is performed via an antenna (not shown) mounted on the IC card 1n or a mobile device. In the communication between the IC chip Cn and the IFD 2m (reader / writer RWm), commands (APDUs (Application Protocol Data Units)) and responses (APDUs) defined in international standard specifications such as ISO / IEC 7816-4 are exchanged.

[0042] ​​For NVM103 (an example of a memory means), for example, a flash memory is applied. Note that NVM103 may be an "Electrically Erasable Programmable Read-Only Memory". Various programs such as an OS (Operating System) and applications installed in the IC chip Cn (including the program of the present invention) are stored in NVM103 or ROM104. Examples of applications include a transaction application used for settlement of a transaction target, an authentication application used for operating a gate, etc. The application includes a program that defines various encryption algorithms. When an application is installed in the IC chip Cn, a plurality of files having a hierarchical structure (defined in ISO / IEC 7816-4, etc.) composed of an MF (Master File), a DF (Dedicated File), an EF (Elementary File), etc. are stored (created) in NVM103. Each file is assigned a unique file ID.

[0043] FIG. 5 is a diagram showing a configuration example of each file stored in NVM103. In the example of FIG. 5, DF#1 is located under the MF. DF#1 is an application DF (dedicated file), and the DF name of DF#1 is stored. Under DF#1, EF#1 is located. In EF#1, protected target information (for example, highly confidential information, personal information, etc.) is stored. An access right is set for EF#1, and when authentication (signature verification) by an encryption method (in other words, a signature method) indicated by a Security environment (security environment, hereinafter referred to as "SE") is successful, external access (for example, reading) to the protected target information stored in EF#1 becomes possible. Although not shown, under DF#1, there is an IEF (Internal Elementary File) that stores a PIN and a key pair (private key and public key) of the IC chip 1n.

[0044] In addition, in DF#1, a Control parameter (control parameter, hereinafter referred to as "CP") and SE managed by an OS or an application are associated and stored. The CP includes a Control parameter template (control parameter template, hereinafter referred to as "CPT"). The SE includes a Control reference template (control reference template, hereinafter referred to as "CRT"). The CRT is an example of control reference information. There are several types of CRTs. In this embodiment, as the CRT, a CRT for digital signature (also referred to as DST) is applied. Note that the CRT may be stored in the SE when an application is installed in the IC chip Cn, or may be stored in the SE in response to a CRT setting instruction from the IFD2m after the application is installed.

[0045] FIG. 6 is a diagram showing an example of the structure of the CPT. As shown in FIG. 6, the CPT5 is configured in a TLV format, and a Security attribute template in expanded format (security attribute template in expanded format, hereinafter referred to as "SAT") 51 is stored in the Value field of the CPT5 in a TLV format. Further, in the Value field of the SAT51, an Access mode field 511 and a Security condition byte 512 are stored in a TLV format. The Security condition byte 512 includes an SEID (Security Environment IDentifier). Here, the SEID is an identifier for specifying the SE.

[0046] FIG. 7 is a diagram showing an example of the structure of the CRT stored in the NVM 103 in the IC chip C1 or the IC chip C2. As shown in FIG. 7, the CRT 6a is configured in the TLV format, and in the Value field of the CRT 6a, a Cryptographic mechanism reference 61a and a Reference of a public key 62a are stored in the TLV format. The Cryptographic mechanism reference 61a includes an OID (Object IDentifier), which is an identifier for specifying the public key cryptosystem (in other words, the signature system) of the current specification (in the case of the IC chip C1) or the new specification (in the case of the IC chip C2).

[0047] On the one hand, FIG. 8 is a diagram showing an example of the structure of the CRT stored in the NVM 103 of the IC chip C3. As shown in FIG. 8, the CRT 6b is configured in the TLV format. In the Value field of the CRT 6b, in addition to the Cryptographic mechanism reference 61b and the Reference of a public key 62b similar to those of the CRT 6a shown in FIG. 7, a Discretionary data template 63b is stored in the TLV format. The Cryptographic mechanism reference 61b includes an OID (an example of information indicating the first public key cryptosystem), which is an identifier for specifying the public key cryptosystem of the current specification. Note that the area where the Cryptographic mechanism reference 61b and the Reference of a public key 62b are stored corresponds to the cryptosystem information storage area. In the Value field of the Discretionary data template 63b, a Cryptographic mechanism reference 631 and a Reference of a public key 632 are stored in the TLV format. The Cryptographic mechanism reference 631 includes an OID (an example of information indicating the second public key cryptosystem), which is an identifier for specifying the public key cryptosystem of the new specification.

[0048] Note that the Discretionary data template 63b is also called a Discretionary template as defined in ISO / IEC 7816-4 or the like. In the Value field of the CRT 6b shown in FIG. 8, the area where the Discretionary data template 63b is stored corresponds to an arbitrary area for storing information freely defined by the application provider. Here, "arbitrary" means that it is arbitrary to interpret the information stored here. For example, the IC card 11 and the IFD 21 that only support the public key cryptosystem of the current specification cannot interpret the Discretionary data template 63b and thus proceed with the process while ignoring it (that is, no error occurs) (the same applies to the IC card 12 and the IFD 22).

[0049] The CPU 105 executes various processes according to the OS or the application. For example, when the CPU 105 receives a command (APDU) from the IFD 2m via the I / O circuit 101, it executes a process corresponding to the command (APDU) and returns a response (APDU) including the result of the process to the IFD 2m. In particular, the CPU 105 of the IC chip C3 functions as the first transmission means, the second transmission means, the first signature verification means, the second signature verification means, and the reception means in the present invention as Example 1 and executes the processes described later. Also, the CPU 105 of the IC chip C3 functions as the reception means, the first determination means, the second determination means, the third determination means, the fourth determination means, and the response means in the present invention as Example 2 and executes the processes described later.

[0050] 1-2. Configuration and Function of IFD 2m ​​Next, with reference to FIG. 9, the configuration and functions of the IFD2m will be described. FIG. 9 is a diagram showing an example of the hardware configuration of the IFD2m. As shown in FIG. 9, the IFD2m includes a host Hm, a reader / writer RWm, etc., and the host Hm and the reader / writer RWm are connected by wire or wirelessly. The host Hm includes a communication unit 201, a storage unit 202, a control unit 203, etc. Note that although not shown, the reader / writer RWm includes an I / O circuit, a RAM, an NVM, a ROM, a CPU, etc., and communicates with the communication unit 201 and the IC card 1n (I / O circuit 101).

[0051] The storage unit 202 is composed of, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), etc., and stores various programs such as the OS and applications installed in the host Hm (including the program of the present invention). Examples of applications include a transaction application used for settlement of a transaction target, an authentication application used for operating a gate, etc. The application includes a program that defines various encryption algorithms.

[0052] Also, the storage unit 202 stores a key pair (private key and public key) of the host Hm, which is a key pair corresponding to the public key cryptosystem of various specifications (i.e., the current specification, the new specification, or both specifications). For example, the storage unit 202 of the host H3 stores a key pair (first private key and first public key) corresponding to the public key cryptosystem of the current specification and a key pair (second private key and second public key) corresponding to the public key cryptosystem of the new specification. Further, the storage unit 202 stores a CRT corresponding to the public key cryptosystem of various specifications and a digital certificate corresponding to the public key cryptosystem of various specifications. For example, the storage unit 202 of the host H3 stores a digital certificate generated based on the CRT, which is a digital certificate corresponding to the public key cryptosystem of the current specification, the new specification, or both specifications. Here, the digital certificate corresponding to the public key cryptosystem of both specifications is hereinafter referred to as a "hybrid digital certificate". Such a hybrid digital certificate has a different structure from the conventional one.

[0053] FIG. 10 is a diagram showing an example of the structure of a digital certificate stored in the storage unit 202 of the host H1 or the host H2. As shown in FIG. 10, the digital certificate (Card verifiable certificate) 7a is configured in the TLV format, and in the Value field of the digital certificate 7a, a Certificate content template (certification content template) 71a and a Digital signature 72a are stored in the TLV format. Here, the Digital signature 72a is a digital signature generated using a private key by a public key cryptosystem of the current specification (in the case of the host H1) or the new specification (in the case of the host H2). In the Value field of the Certificate content template 71a, a Certificate authority reference 711a, a Public key 712a, and a Certificate expiration date 713a are stored in the TLV format. Here, the Public key 712a is a public key used in the public key cryptosystem of the current specification (in the case of the host H1) or the new specification (in the case of the host H2).

[0054] On the one hand, FIG. 11 is a diagram showing an example of the structure of a hybrid digital certificate stored in the storage unit 202 of the host H3. As shown in FIG. 11, the digital certificate 7b is configured in the TLV format. In the Value field of the digital certificate 7b, in addition to the Certificate content template 71b and the Digital signature 72b, the Certificate extension 73b is stored in the TLV format. Here, the Digital signature 72b is a digital signature (hereinafter referred to as "first digital signature") generated using the first private key by the public key cryptosystem of the current specification. In the Value field of the Certificate content template 71b, the Certificate authority reference 711b, the Public key 712b, and the Certificate expiration date 713b are stored in the TLV format. Here, the Public key 712b is the first public key (an example of the public key information of the first public key) used in the public key cryptosystem of the current specification. Note that the area where the Certificate content template 71b and the Digital signature 72b are stored is an example of the first storage area.

[0055] In the Value field of the Certificate extension 73b, the Discretionary data template 731b is stored in TLV format. Furthermore, in the Value field of the Discretionary data template 731b, the Object identifier 7311 and the Certificate content template 7312 are stored in TLV format. Here, the Object identifier 7311 is an OID for specifying the public key cryptosystem of the new specification. In the Value field of the Certificate content template 7312, the Public key 73121 and the Digital signature 73122 are stored in TLV format. Here, the Public key 73121 is the second public key (an example of the public key information of the second public key) used in the public key cryptosystem of the new specification. The Digital signature 73122 is a digital signature (hereinafter referred to as the "second digital signature") generated using the second private key by the public key cryptosystem of the new specification.

[0056] Note that the Discretionary data template 731b is also called a Discretionary template, similar to the CRT6b shown in Figure 8. In the Value field of the digital certificate 7b shown in Figure 11, the area where the Discretionary data template 731b is stored corresponds to an arbitrary area (an example of the second storage area) for storing information freely defined by the application provider. For example, the IC card 11 and the IFD 21 that support only the public key cryptosystem of the current specification cannot interpret the content (the inside) of the Discretionary data template 731b, so they will proceed with the process while ignoring it (that is, no error will occur) (the same applies to the IC card 12 and the IFD 22).

[0057] The control unit 203 (an example of a computer) includes a RAM, a ROM, a CPU, etc., and executes various processes according to an OS or an application. For example, the control unit 203 transmits a command (APDU) to the IC card 1n via the communication unit 201 and the reader / writer RWm, receives a response (APDU) returned from the IC card 1n, and executes a process according to the response (APDU). In particular, the control unit 203 of the host H3 functions as an acquisition means, a first determination means, a second determination means, a generation means, a transmission means, etc. in the present invention as Example 1, and executes the processes described later. Further, the control unit 203 of the host H3 functions as a reception means, a first determination means, a second determination means, a third determination means, a fourth determination means, a transmission means, etc. in the present invention as Example 2, and executes the processes described later. Note that the reader / writer RWm may substitute for the function of the control unit 203. For example, it may transmit a default-set command (APDU) to the IC card 1n, receive a response (APDU) returned from the IC card 1n, and execute a process according to the response (APDU).

[0058] [2. Operation of the encryption system S] Next, regarding the operation of the encryption system S according to the present embodiment, it will be described separately for Example 1 and Example 2. It is desirable that an SE (Security environment) be set in the IC card 1n as a premise for the operation of the encryption system S according to Example 1 and Example 2. First, with reference to FIG. 12, the SE setting operation performed between the IC card 1n and the IFD2m will be described. FIG. 12 is a diagram showing an example of a sequence of the SE setting operation performed between the IC card 1n and the IFD2m. The SE setting sequence shown in FIG. 12 is performed when the SE is not associated with the DF#1.

[0059] First, IFD2m sends a DF#1 selection instruction including the DF name of DF#1 to IC card 1n (step S1). Such a DF#1 selection instruction is, for example, a SELECT command (APDU) for selecting DF#1. When IC card 1n receives the DF#1 selection instruction from IFD2m, it interprets the DF name obtained from the DF#1 selection instruction, searches for and selects the corresponding DF#1 (step S2). Then, when the selection of DF#1 is successful, IC card 1n responds to IFD2m with the processing result (selection successful: normal completion) (step S3). Such a processing result is, for example, a response (APDU) including a status word (9000(h)) indicating normal completion. That is, the response (APDU) is sent (returned) to IFD2m.

[0060] Next, when IFD2m receives the processing result (normal completion) from IC card 1n, it sends a CP read instruction to IC card 1n (step S4). Such a CP read instruction is, for example, a READ BINARY command (APDU) or a GET DATA command (APDU) for reading the CP associated with the selected DF#1. When IC card 1n receives the CP read instruction from IFD2m, it reads the CP associated with the currently selected DF#1 (step S5). Then, when the reading of the CP is successful, IC card 1n responds to IFD2m with the processing result (reading successful: normal completion) including the said CP (step S6). Such a processing result is, for example, a response (APDU) including a status word (9000(h)) indicating normal completion and the CPT in the CP.

[0061] Next, when IFD2m receives a processing result (normal completion) including CP from IC card 1n, it interprets, for example, CPT obtained from the processing result, and acquires a SEID for specifying an authentication method acting under the selected DF# (step S7). Here, the authentication method is a method indicating how authentication (signature verification) is performed. Next, IFD2m transmits a SE setting instruction including the acquired SEID to IC card 1n (step S8). When IC card 1n receives the SE setting instruction from IFD2m, it sets the SE specified by the SEID to an executable state (active) (step S9). Then, when the setting of the SE is successful, IC card 1n responds to IFD2m with the processing result (setting successful: normal completion) (step S10). Such a processing result is, for example, a response (APDU) including a status word (9000(h)) indicating normal completion. Thereby, the authentication operation is entered.

[0062] In addition, when a SE is associated with DF#1 in IC card 1n, when IC card 1n receives a DF#1 selection instruction from IFD2m, it interprets the DF name obtained from the DF#1 selection instruction, searches for and selects the corresponding DF#1, and automatically sets the SE associated with the selected DF#1 to a default executable state, and responds to IFD2m with the processing result (setting successful) in the same manner as above.

[0063] (Example 1) Next, with reference to FIGS. 13 and 14, the authentication operation performed between IC card 1n and IFD2m in Example 1 will be described. Example 1 is an example in the case of using a CRT stored in IC chip C1. FIG. 13 is a diagram showing an example of a sequence of an authentication operation performed between IC card 1n and IFD2m. FIG. 14 is a flowchart showing an example of an encryption method determination process executed by host H3 (control unit 203) of IFD23 in step S15 of FIG. 13.

[0064] When the SE is set in the IC card 1n, the IFD 2m sends a CRT read instruction to the IC card 1n (step S11). Such a CRT read instruction is, for example, a READ BINARY command (APDU), a READ RECORD command (APDU), a GET DATA command (APDU), or a GET CRT operation (APDU) of the MANAGE SECURITY ENVIRONMENT command for reading the CRT included in the set SE. When the IC card 1n receives the CRT read instruction from the IFD 2m, it reads the CRT included in the SE being set (step S12). Then, when the reading of the CRT is successful, the IC card 1n responds to the IFD 2m with the processing result (read success: normal termination) including the said CRT (that is, transmits in response to the CRT read instruction) (step S13). Such a processing result is, for example, a status word (9000(h)) indicating normal termination and a response (APDU) including the CRT.

[0065] Next, when the IFD 2m receives the processing result (normal termination) including the CRT from the IC card 1n, it specifies the authentication method based on the Cryptographic mechanism reference included in the received CRT (step S14). Next, the IFD 2m determines the public key cryptosystem (in other words, the signature system) based on the said processing result (that is, the CRT obtained from the said processing result) (step S15). For example, when the IFD 21 obtains the CRT 6a with the structure shown in FIG. 7 from the IC card 11, the public key cryptosystem of the current specification is determined. Also, when the IFD 22 obtains the CRT 6a with the structure shown in FIG. 7 from the IC card 12, the public key cryptosystem of the new specification is determined.

[0066] On the other hand, when the IFD 23 obtains the CRT 6a with the structure shown in FIG. 7 (or a CRT having an unexpected structure) from the IC card 11 or the IC card 12, or obtains the CRT 6b with the structure shown in FIG. 8 (or a CRT having an unexpected structure) from the IC card 13, in step S15, it executes the cipher system determination process shown in FIG. 14.

[0067] In the encryption method determination process shown in FIG. 14, host H3 determines whether the acquired CRT includes an encryption method information storage area for storing information indicating the public key encryption method of the current specification or the new specification (step S151). If it is determined that the CRT does not include an encryption method information storage area (that is, the CRT has an unexpected structure) (step S151: NO), for example, an error message is notified to the administrator of host H3 (step S152).

[0068] In step S151, when there is no data (Cryptographic mechanism reference) with Tag "80(h)" and no data (Reference of a public key) with Tag "83(h)" at the beginning of the CRT, it may be determined that the CRT does not include an encryption method information storage area (that is, determined based on the Tag value).

[0069] On the other hand, if it is determined that the CRT includes an encryption method information storage area (step S151: YES), the public key encryption method (the public key encryption method of the current specification or the new specification) in the encryption method information storage area is temporarily stored as the public key encryption method α (step S153). Next, host H3 determines whether the CRT includes an arbitrary area (step S154). If it is determined that the CRT does not include an arbitrary area (step S154: NO), the public key encryption method α temporarily stored in step S153 is determined (step S155).

[0070] In step S154, for example, when there is no data (Discretionary data template) with Tag "73(h)" following the data with Tag "83(h)" in the CRT, it may be determined that the CRT does not include an arbitrary area (that is, determined based on the Tag value).

[0071] On the other hand, when it is determined that the CRT includes an arbitrary area (step S154: YES), the host H3 determines whether information indicating a public key cryptosystem of a new specification is stored in the arbitrary area (step S156). When it is determined that information indicating a public key cryptosystem of a new specification is not stored in the arbitrary area (step S156: NO), the public key cryptosystem α temporarily stored in step S153 is determined (step S155). On the other hand, when it is determined that information indicating a public key cryptosystem of a new specification is stored in the arbitrary area (step S156: YES), since the public key cryptosystem α is the public key cryptosystem of the current specification, the public key cryptosystems of both specifications (that is, both the public key cryptosystems of the current specification and the new specification) are determined (step S157).

[0072] Note that in step S156, for example, when data (Cryptographic mechanism reference) having Tag “80(h)” and data (Reference of a public key) having Tag “83(h)” are not present in the Value field of the Discretionary data template, it may be determined that information indicating a public key cryptosystem of a new specification is not stored in the arbitrary area (that is, determined based on the Tag value). At this time, it may also be determined whether an OID, which is an identifier for specifying a public key cryptosystem of a new specification, is included in the Cryptographic mechanism reference.

[0073] Return to the process shown in FIG. 13. IFD2m starts an authentication process according to the authentication method specified in step S14 and sends a random number generation instruction to IC card 1n (step S16). Such a random number generation instruction is, for example, a GET CHALLENGE command (APDU). When IC card 1n receives the random number generation instruction from IFD2m, it generates a random number (step S17). Then, upon successful generation of the random number, IC card 1n responds to IFD2m with a processing result (generation successful: normal termination) including the random number (step S18). Such a processing result is, for example, a status word (9000(h)) indicating normal termination and a response (APDU) including the random number.

[0074] Next, when IFD2m receives the processing result (normal termination) including the random number from IC card 1n, it generates a digital certificate according to the public key cryptosystem determined in step S15 using the random number obtained from the processing result (step S19). For example, as shown in FIG. 10, IFD21 generates a digital certificate 7a according to the public key cryptosystem of the current specification. On the other hand, as shown in FIG. 10, IFD22 generates a digital certificate 7a according to the public key cryptosystem of the new specification. On the other hand, as shown in FIG. 10, IFD23 generates a digital certificate according to the current specification or the new specification, or as shown in FIG. 11, a digital certificate according to both specifications (i.e., a hybrid digital certificate).

[0075] For example, host H3 generates a hybrid digital certificate including a first storage area that stores a first digital signature generated by a public key cryptosystem (cryptographic algorithm) of the current specification using the first secret key and first predetermined data stored in the storage unit 202, and a first public key that forms a key pair with the first secret key, and a second storage area that stores a second digital signature generated by a public key cryptosystem of the new specification using the second secret key and second predetermined data, and a second public key that forms a key pair with the second secret key. Here, the first predetermined data and the second predetermined data may be, for example, random numbers obtained from the above processing results. Alternatively, it is even better that the first predetermined data is a random number obtained from the above processing results and the second predetermined data is the first digital signature. Thereby, security can be improved.

[0076] FIG. 15 is a conceptual diagram showing an example of generating a hybrid digital certificate. For example, as shown in FIG. 15, host H3 generates a first digital signature by signature method 1 (public key cryptosystem of the current specification) using the first secret key stored in the storage unit 202 and a random number (input information) obtained from the above processing results, and sets (stores) the first public key that forms a key pair with the first secret key and the generated first digital signature in the first storage area (cryptographic method information storage area). Then, host H3 generates a second digital signature by signature method 2 (public key cryptosystem of the new specification) using the second secret key stored in the storage unit 202 and the generated first digital signature, and generates a hybrid digital certificate by setting (storing) the second public key that forms a key pair with the second secret key and the generated second digital signature in the second storage area (arbitrary area).

[0077] Note that in the cryptographic method determination process shown in FIG. 14, if it is determined that the CRT does not include an arbitrary area, or if it is determined that information indicating the public key cryptosystem of the new specification is not stored in the arbitrary area, host H3 may generate a digital certificate including the first storage area that stores the first digital signature and the first public key and not including the second storage area (that is, a digital certificate according to the current specification or the new specification).

[0078] Next, IFD2m transmits a signature verification instruction including the digital certificate generated in step S19 to IC card 1n (step S20). Such a signature verification instruction is, for example, an EXTERNAL AUTHENTICATE command (APDU), a GENERAL AUTHENTICATE command (APDU), or a PERFORM SECURITY OPERATION command (APDU). Here, IFD23 will transmit a signature verification instruction including a hybrid digital certificate to IC card 13. Note that IFD23 may transmit a signature verification instruction including a hybrid digital certificate to IC card 11. When IC card 1n receives the signature verification instruction from IFD2m, it verifies the digital signature using the public key in the digital certificate obtained from the signature verification instruction (step S21), and responds to IFD2m with the verification result (verification success or verification failure) (step S22). Such a verification result (verification success) is, for example, a response (APDU) including a status word (9000(h)) indicating normal completion.

[0079] For example, when IC card 13 receives a signature verification instruction including a hybrid digital certificate from IFD23, it first verifies the first digital signature in the hybrid digital certificate using the first public key by the public key cryptosystem of the current specification, and then verifies the second digital signature in the hybrid digital certificate using the second public key by the second public key cryptosystem of the new specification. Here, in the first verification, for example, when the first digital signature is correctly calculated by the first public key and the data extracted by the calculation matches the value based on the random number generated in step S17 above, the result of the first verification is a verification success. In the second verification, for example, when the second digital signature is correctly calculated by the second public key and the data extracted by the calculation matches the value based on the random number (or the first digital signature) generated in step S17 above, the result of the second verification is a verification success. Then, IC card 13 responds (transmits) either both or any one of the verification result of the first digital signature (the result of the first verification) and the verification result of the second digital signature (the result of the second verification) to IFD23.

[0080] Next, when IFD2m receives the verification result from IC card 1n, it analyzes the verification result (step S23). If the verification result indicates successful verification, it sends an EF#1 read instruction to IC card 1n (step S24). Such an EF#1 read instruction is, for example, a READ RECORD command (APDU) or a GET DATA command (APDU) for reading the protected target information stored in EF#1.

[0081] For example, in step S23, if either or both of the verification result of the first digital signature (the result of the first verification) and the verification result of the second digital signature (the result of the second verification) indicate successful verification, an EF#1 read instruction is sent to IC card 1n. Thereby, security can be improved, and even if either the public key cryptosystem of the current specification or the public key cryptosystem of the new specification is jeopardized, IFD23 can proceed with the process trusting the verification result by the other public key cryptosystem.

[0082] Next, when IC card 1n receives the EF#1 read instruction from IFD2m, it reads the protected target information from EF#1 (step S25). And when the reading of the protected target information is successful, IC card 1n responds to IFD2m with a processing result (successful reading: normal termination) including the protected target information (step S26). Such a processing result is, for example, a status word (9000(h)) indicating normal termination and a response (APDU) including the protected target information. In this way, IFD2m can acquire the protected target information from IC card 1n.

[0083] As described above, according to the above-described First Embodiment, the IFD 23 acquires from the IC card 1n a CRT including an encryption method information storage area that stores information indicating the public key encryption method of the current specification, determines whether an arbitrary area is included in the CRT, and if it is determined that an arbitrary area is included in the CRT, determines whether information indicating the public key encryption method of the new specification is stored in the arbitrary area. If it is determined that information indicating the public key encryption method of the new specification is stored in the arbitrary area, the above-described hybrid digital certificate is generated and transmitted to the IC card 1n. Therefore, in an encryption system that uses both the encryption method of the current specification and the encryption method of the new specification, it is possible to improve security while maintaining compatibility. Further, the IC card 13 stores in advance a CRT including an encryption method information storage area that stores information indicating the public key encryption method of the current specification and an arbitrary area that stores information indicating the public key encryption method of the new specification, reads out the CRT in response to a CRT read instruction from the IFD 2m, and transmits it to the IFD 2m. In particular, since the IFD 23 is configured to be able to acquire a hybrid digital certificate, in an encryption system that uses both the encryption method of the current specification and the encryption method of the new specification, it is possible to improve security while maintaining compatibility.

[0084] (Second Embodiment) Next, with reference to FIGS. 16 to 19, the authentication operation performed between the IC card 1n and the IFD 2m in the second embodiment will be described. The second embodiment is an example in the case of using the CRT managed within the IFD 2m. In this case, even if the CRT is already stored in the IC card 1n, the CRT managed within the IFD 2m is used. FIG. 16 is a diagram showing an example of the sequence of the authentication operation performed between the IC card 1n and the IFD 2m. FIG. 17 is a flowchart showing an example of the CRT setting process executed by the IC chip C3 (CPU 105) of the IC card 13 in step S32 of FIG. 16. FIG. 18 is a flowchart showing an example of the encryption method determination process executed by the host H3 (control unit 203) of the IFD 23 in step S35 of FIG. 16. FIG. 19 is a flowchart showing an example of the CRT setting re-instruction process executed by the host H3 (control unit 203) of the IFD 23 in step S355 of FIG. 18.

[0085] When the SE is set in the IC card 1n, the IFD 2m transmits a CRT setting instruction including the CRT managed within the IFD 2m to the IC card 1n (step S31). Such a CRT setting instruction is, for example, a MANAGE SECURITY ENVIRONMENT command (APDU) for setting a new CRT. For example, the IFD 23 will transmit the CRT 6b having the structure shown in FIG. 8 (or a CRT having an unexpected structure) to the IC card 11, the IC card 12, or the IC card 13. When the IC card 1n receives the CRT setting instruction from the IFD 2m, it analyzes the CRT obtained from the CRT setting instruction and attempts to set the CRT (step S32), and responds to the IFD 2m with the processing result (that is, responds with the processing result according to the CRT setting instruction) (step S33). For example, when the IC card 13 receives the CRT 6a having the structure shown in FIG. 7 (or a CRT having an unexpected structure) from the IFD 21 or the IFD 22, or receives the CRT 6b having the structure shown in FIG. 8 (or a CRT having an unexpected structure) from the IFD 23, in step S32, it executes the CRT setting process shown in FIG. 17.

[0086] In the CRT setting process shown in FIG. 17, the IC chip C3 of the IC card 13 determines whether the CRT obtained from the CRT setting instruction includes an encryption method information storage area for storing information indicating the public key encryption method of the current specification or the new specification (step S321). If it is determined that the CRT does not include an encryption method information storage area (that is, the CRT has an unexpected structure) (step S321: NO), an error is set as the processing result (step S322), the process returns to the process shown in FIG. 16, and the processing result indicating the error is responded to the IFD2m (step S33). Such a processing result is, for example, a response (APDU) including a status word (for example, 6400(h)) indicating an error.

[0087] Note that in step S321, when there is no data (Cryptographic mechanism reference) having the Tag “80(h)” and data (Reference of a public key) having the Tag “83(h)” at the head of the CRT, it may be determined that the CRT does not include an encryption method information storage area (that is, determination is made based on the Tag value).

[0088] On the other hand, if it is determined that the CRT includes an encryption method information storage area (step S321: YES), the public key encryption method (the public key encryption method of the current specification or the new specification) in the encryption method information storage area is temporarily stored as the public key encryption method α (step S323). Next, the IC chip C3 determines whether the IC chip C3 corresponds to the public key encryption method α (that is, supports the public key encryption method α). If it is determined that the IC chip C3 does not correspond to the public key encryption method α (step S324: NO), an error is set as the processing result (step S322), the process returns to the process shown in FIG. 16, and the processing result indicating the error is responded to the IFD2m (step S33).

[0089] On the other hand, when it is determined that the IC chip C3 supports the public key cryptosystem α (step S324: YES), the IC chip C3 determines whether the CRT contains an arbitrary area (step S325). When it is determined that the CRT does not contain an arbitrary area (step S325: NO), normal termination is set as the processing result (step S328), the process returns to the process shown in FIG. 16, and the processing result indicating the normal termination is responded to the IFD2m (step S33). Such a processing result is, for example, a response (APDU) including a status word (9000(h)) indicating normal termination.

[0090] In step S325, for example, when there is no data (Discretionary data template) having Tag “73(h)” following the data having Tag “83(h)” in the CRT, it may be determined that the CRT does not contain an arbitrary area (that is, determined based on the Tag value).

[0091] On the other hand, when it is determined that the CRT contains an arbitrary area (step S325: YES), the IC chip C3 determines whether information indicating a new specification of the public key cryptosystem is stored in the arbitrary area (step S326). When it is determined that information indicating a new specification of the public key cryptosystem is not stored in the arbitrary area (step S326: NO), normal termination is set as the processing result (step S328), the process returns to the process shown in FIG. 16, and the processing result indicating the normal termination is responded to the IFD2m (step S33).

[0092] In step S326, for example, when there is no data with Tag “80(h)” (Cryptographic mechanism reference) and data with Tag “83(h)” (Reference of a public key) in the Value field of the Discretionary data template, it may be determined (i.e., determined based on the Tag value) that information indicating the new public key cryptosystem is not stored in the arbitrary area. At this time, it may also be determined whether the OID, which is an identifier for specifying the new public key cryptosystem, is included in the Cryptographic mechanism reference.

[0093] On the other hand, when it is determined that information indicating the new public key cryptosystem is stored in the arbitrary area (step S326: YES), the IC chip C3 determines whether the IC chip C3 corresponds to the new public key cryptosystem (i.e., supports the public key cryptosystem) (step S327).

[0094] When it is determined that the IC chip C3 corresponds to the new public key cryptosystem (step S327: YES), normal termination is set as the processing result (step S328), the process returns to the process shown in FIG. 16, and the processing result indicating the normal termination is responded to the IFD2m (step S33). On the other hand, when it is determined that the IC chip C3 does not correspond to the new public key cryptosystem (step S327: NO), warning termination is set as the processing result (step S329), the process returns to the process shown in FIG. 16, and the processing result indicating the warning termination is responded to the IFD2m (step S33). Such a processing result is, for example, a response (APDU) including a status word (e.g., 6283(h)) indicating warning termination.

[0095] Next, when IFD2m receives the processing result from IC card 1n, it specifies the authentication method based on the SEID acquired in step S7 (step S34). Next, IFD2m determines the public key cryptosystem (in other words, the signature system) based on the said processing result (step S35). For example, IFD23 executes the encryption method determination process shown in FIG. 18 based on the processing results received from IC cards 11, 12, and 13.

[0096] In the encryption method determination process shown in FIG. 18, host H3 determines whether the received processing result indicates an error (step S351). If it is determined that the received processing result does not indicate an error (step S351: NO), the process proceeds to step S352. On the other hand, if it is determined that the received processing result indicates an error (step S351: YES), the process proceeds to step S355.

[0097] In step S352, host H3 determines whether the received processing result indicates a warning end. If it is determined that the received processing result does not indicate a warning end (that is, it indicates a normal end) (step S352: NO), the public key cryptosystems of both specifications are determined (step S353). On the other hand, if it is determined that the received processing result indicates a warning end (step S352: YES), the public key cryptosystem of the current specification is determined (step S354).

[0098] In step S355, host H3 executes the CRT setting re-instruction process shown in FIG. 19. Through such CRT setting re-instruction process, IFD23 can determine whether it is the IC card 12 that sent the processing result indicating an error, or an unexpected IC card 1n or the like. That is, for example, when a CRT setting instruction including CRT6b with the structure shown in FIG. 8 is sent from IFD23 to the IC card 12 that only supports the public key cryptosystem of the new specification, since the public key cryptosystem of the current specification is stored in the cryptographic mechanism information storage area of CRT6b, a processing result indicating an error will be sent from the IC card 12. On the other hand, when a CRT setting instruction including CRT6b with the structure shown in FIG. 8 is sent from IFD23 to the unexpected IC card 1n that does not support either the public key cryptosystem of the current specification or the new specification, a processing result indicating an error will also be sent from the IC card 1n.

[0099] In the CRT setting re-instruction process shown in FIG. 19, host H3 sends a CRT re-setting instruction including a CRT having a cryptographic mechanism information storage area for storing information indicating the public key cryptosystem of the new specification to the IC card 1n that sent the processing result indicating an error (step S3551). Here, the CRT having a cryptographic mechanism information storage area for storing information indicating the public key cryptosystem of the new specification may be CRT6a with the structure shown in FIG. 7, or may be CRT6b with the structure shown in FIG. 8. In the latter case, in CRT6b with the structure shown in FIG. 8, Cryptographic mechanism reference61b and Reference of a public key62b may be overwritten by Cryptographic mechanism reference631 and Reference of a public key632.

[0100] Then, when host H3 receives the processing result from IC card 1n that has received the CRT reset instruction (step S3552), it determines whether the received processing result indicates normal completion (step S3553). If it is determined that the received processing result indicates normal completion (step S3553: YES), a public key cryptosystem of the new specification is determined (step S3554). In this case, since it can be determined that it is a response from IC card 12, the processing time required for the authentication operation performed between IC card 12 and IFD23 can be shortened. On the other hand, if it is determined that the received processing result does not indicate normal completion (step S3553: NO), the process ends. In this case, it is determined that it is an unexpected response from IC card 1n.

[0101] Returning to the process shown in FIG. 16, IFD2m starts the authentication process according to the authentication method specified in step S34, and as in the first embodiment, sends a random number generation instruction to IC card 1n (step S36). When IC card 1n receives the random number generation instruction from IFD2m, it generates a random number (step S37). Then, when the generation of the random number is successful, IC card 1n responds to IFD2m with the processing result (generation successful: normal completion) including the random number (step S38). Next, when IFD2m receives the processing result (normal completion) including the random number from IC card 1n, it generates a digital certificate according to the public key cryptosystem determined in step S35 (in the case of IFD23, the public key cryptosystem determined by the cryptosystem determination process shown in FIG. 18) using the random number obtained from the processing result (step S39). For example, as shown in FIG. 10, IFD23 generates a digital certificate according to the current specification or the new specification, or as shown in FIG. 11, a digital certificate according to both specifications (that is, a hybrid digital certificate). The method for generating such a hybrid digital certificate is the same as in the first embodiment. Note that the processes of steps S40 to S46 shown in FIG. 16 are the same as the processes of steps S20 to S26 shown in FIG. 13.

[0102] As described above, according to the above-described second embodiment, the IFD 23 transmits a CRT setting instruction including a CRT including an encryption method information storage area for storing information indicating the public key encryption method of the current specification and an arbitrary area for storing information indicating the public key encryption method of the new specification to the IC card 1n, and appropriately generates either a normal digital certificate or a hybrid digital certificate according to the processing result responded from the IC card 1n and transmits it to the IC card 1n. Therefore, in an encryption system in which the encryption method of the current specification and the encryption method of the new specification are used in combination, it is possible to improve security while maintaining compatibility. Further, when the IC card 13 receives a CRT setting instruction including a CRT from the IFD 2m, it determines whether or not an arbitrary area is included in the CRT. When it is determined that the arbitrary area is included in the CRT, it determines whether or not information indicating the public key encryption method of the new specification is stored in the arbitrary area. When it is determined that information indicating the public key encryption method of the new specification is stored in the arbitrary area, it determines whether or not the IC card 13 supports the public key encryption method of the new specification. When it is determined that the IC card 13 supports the public key encryption method of the new specification, it is configured to respond with a processing result indicating normal termination to the IFD 2m. Therefore, in an encryption system in which the encryption method of the current specification and the encryption method of the new specification are used in combination, it is possible to improve security while maintaining compatibility.

[0103] In the above-described embodiment, the case where the first public key cryptosystem is the public key cryptosystem of the current specification and the second public key cryptosystem is the public key cryptosystem of the new specification has been described as an example. However, the present invention can also be applied to the case where the first public key cryptosystem is the public key cryptosystem of the new specification and the second public key cryptosystem is the public key cryptosystem of the current specification. In this case, for example, in the CRT6b having the structure shown in FIG. 8, information indicating the public key cryptosystem of the new specification is stored in the cryptosystem information storage area, and information indicating the public key cryptosystem of the current specification is stored in an arbitrary area. Further, in the above-described embodiment, the digital certificate is configured such that the public key itself is stored as the public key information of the public key forming a key pair with the secret key. However, as another example, the digital certificate may be configured such that the location information of the public key (for example, link information such as a URL or a blockchain address) is stored as the public key information of the public key forming a key pair with the secret key. In this case, the public key is acquired based on the location information.

Explanation of Signs

[0104] 11, 12, 13, 1n IC card 21, 22, 23, 2m IFD C1, C2, C3, Cn IC chip H1, H2, H3, Hm Host 101 I / O circuit 102 RAM 103 NVM 104 ROM 105 CPU 106 Coprocessor 201 Communication unit 202 Storage unit 203 Control unit S Encryption system

Claims

1. A digital certificate generation device capable of communicating with an electronic information storage medium, comprising: an acquisition means for acquiring control reference information including an encryption method information storage area storing information indicating a first public key encryption method from the electronic information storage medium; a first determination means for determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; a second determination means for determining whether information indicating a second public key encryption method is stored in the arbitrary area when it is determined by the first determination means that the arbitrary area is included in the control reference information; a generation means for generating a digital certificate including a first storage area for storing a first digital signature generated by the first public key encryption method using a first private key and first predetermined data, and public key information of a first public key forming a key pair with the first private key, and a second storage area for storing a second digital signature generated by the second public key encryption method using a second private key and second predetermined data, and public key information of a second public key forming a key pair with the second private key when it is determined by the second determination means that the information indicating the second public key encryption method is stored in the arbitrary area; a transmission means for transmitting the digital certificate generated by the generation means to the electronic information storage medium; A digital certificate generation device characterized by comprising the above.

2. The digital certificate generation device according to claim 1, wherein the second predetermined data is the first digital signature.

3. When it is determined by the first determination means that the arbitrary area is not included in the control reference information, or when it is determined by the second determination means that the information indicating the second public key encryption method is not stored in the arbitrary area, the generation means generates a digital certificate including the first storage area and not including the second storage area. The digital certificate generation device according to claim 1 or 2.

4. The digital certificate generation device according to claim 1 or 2, wherein the second storage area is an arbitrary area for storing information freely defined by an application provider.

5. An electronic information storage medium capable of communicating with a digital certificate generation device, Control reference information including a cryptographic method information storage area for storing information indicating a first public key cryptographic method and an arbitrary area for storing information freely defined by an application provider, and storage means for storing the control reference information in which information indicating a second public key cryptographic method is stored in the arbitrary area. First transmission means for reading the control reference information in response to a read instruction from the digital certificate generation device and transmitting it to the digital certificate generation device. A digital certificate generated by the digital certificate generation device based on the control reference information, including a first digital signature generated by the first public key cryptographic method using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key, stored in a first storage area, a second digital signature generated by the second public key cryptographic method using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key, stored in a second storage area, and receiving means for receiving the digital certificate from the digital certificate generation device. An electronic information storage medium characterized by comprising the above.

6. The electronic information storage medium according to claim 5, wherein the second predetermined data is the first digital signature.

7. First signature verification means for verifying the first digital signature by the first public key cryptographic method using the first public key. Second signature verification means for verifying the second digital signature by the second public key cryptographic method using the second public key. Second transmission means for transmitting at least one of the verification result of the first digital signature and the verification result of the second digital signature to the digital certificate generation device. The electronic information storage medium according to claim 5 or 6, characterized by comprising the above.

8. The electronic information storage medium according to claim 5 or 6, wherein the second storage area is an arbitrary area for storing information freely defined by the application provider.

9. A digital certificate generation device capable of communicating with an electronic information storage medium. Control reference information including an encryption method information storage area for storing information indicating the first public key encryption method and an arbitrary area for storing information freely defined by an application provider, and a first transmission means for transmitting to the electronic information storage medium a setting instruction of the control reference information in which information indicating the second public key encryption method is stored in the arbitrary area. When a processing result indicating normal termination is received from the electronic information storage medium in response to the setting instruction, a first digital signature generated by the first public key encryption method using the first secret key and the first predetermined data, and a public key information of the first public key forming a key pair with the first secret key are stored in a first storage area, a second digital signature generated by the second public key encryption method using the second secret key and the second predetermined data, and a public key information of the second public key forming a key pair with the second secret key are stored in a second storage area, and a generation means for generating the digital certificate including the second storage area. A second transmission means for transmitting the digital certificate generated by the generation means to the electronic information storage medium. A digital certificate generation device characterized by comprising the above.

10. The digital certificate generation device according to claim 9, wherein the second predetermined data is the first digital signature.

11. When a processing result indicating warning termination is received from the electronic information storage medium in response to the setting instruction, the generation means generates a digital certificate including the first storage area and not including the second storage area. The digital certificate generation device according to claim 9.

12. The digital certificate generation device according to claim 9 or 10, wherein the second storage area is an arbitrary area for storing information freely defined by the application provider.

13. The digital certificate generation device according to claim 9 or 10, further comprising a third transmission means for transmitting to the electronic information storage medium control reference information including an encryption method information storage area for storing information indicating the second public key encryption method when an error indicating processing result is received from the electronic information storage medium in response to the setting instruction.

14. An electronic information storage medium capable of communicating with a digital certificate generation device, Receiving means for receiving from the digital certificate generation device a setting instruction including control reference information including an encryption method information storage area for storing information indicating the first public key encryption method. First determination means for determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; Second determination means for determining whether information indicating a second public key cryptosystem is stored in the arbitrary area when it is determined by the first determination means that the arbitrary area is included in the control reference information; Third determination means for determining whether the electronic information storage medium corresponds to the second public key cryptosystem when it is determined by the second determination means that information indicating the second public key cryptosystem is stored in the arbitrary area; Response means for responding to the digital certificate generation device with a processing result indicating normal termination according to the setting instruction when it is determined by the third determination means that the electronic information storage medium corresponds to the second public key cryptosystem; An electronic information storage medium, characterized by comprising the above.

15. The electronic information storage medium according to claim 14, wherein when it is determined by the third determination means that the electronic information storage medium does not correspond to the second public key cryptosystem, the response means responds to the digital certificate generation device with a processing result indicating warning termination according to the setting instruction.

16. The electronic information storage medium according to claim 14, wherein when it is determined by the first determination means that the arbitrary area is not included in the control reference information, or when it is determined by the second determination means that information indicating the second public key cryptosystem is not stored in the arbitrary area, the response means responds to the digital certificate generation device with a processing result indicating normal termination according to the setting instruction.

17. Further comprising fourth determination means for determining whether the electronic information storage medium corresponds to the first public key cryptosystem; The electronic information storage medium according to claim 14, wherein when it is determined by the fourth determination means that the electronic information storage medium does not correspond to the first public key cryptosystem, the response means responds to the digital certificate generation device with a processing result indicating an error according to the setting instruction.

18. A digital certificate generation method executed by a digital certificate generation device capable of communicating with an electronic information storage medium, comprising: Obtaining control reference information including an encryption method information storage area for storing information indicating a first public key cryptosystem from the electronic information storage medium; Determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; When it is determined that the arbitrary area is included in the control reference information, determining whether information indicating the second public key cryptosystem is stored in the arbitrary area; When it is determined that the information indicating the second public key cryptosystem is stored in the arbitrary area, a first storage area for storing a first digital signature generated by the first public key cryptosystem using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key, and a second storage area for storing a second digital signature generated by the second public key cryptosystem using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key, generating a digital certificate including the above; Transmitting the generated digital certificate to the electronic information storage medium; A digital certificate generation method characterized by including the above.

19. A digital certificate acquisition method executed by an electronic information storage medium capable of communicating with a digital certificate generation device, Storing in a storage means control reference information including an encryption method information storage area for storing information indicating a first public key cryptosystem and an arbitrary area for storing information freely defined by an application provider, wherein the information indicating the second public key cryptosystem is stored in the arbitrary area; In response to a read instruction from the digital certificate generation device, reading the control reference information and transmitting it to the digital certificate generation device; Obtaining from the digital certificate generation device a digital certificate generated by the digital certificate generation device based on the control reference information, the digital certificate including a first storage area for storing a first digital signature generated by the first public key cryptosystem using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key, and a second storage area for storing a second digital signature generated by the second public key cryptosystem using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key; A digital certificate acquisition method characterized by including the above.

20. A digital certificate generation method executed by a digital certificate generation device capable of communicating with an electronic information storage medium, a control reference information including an encryption method information storage area for storing information indicating a first public key encryption method and an arbitrary area for storing information freely defined by an application provider, and transmitting a setting instruction of the control reference information in which information indicating a second public key encryption method is stored in the arbitrary area to the electronic information storage medium; when a processing result indicating normal termination is received from the electronic information storage medium in response to the setting instruction, a first storage area for storing a first digital signature generated by the first public key encryption method using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key, a second storage area for storing a second digital signature generated by the second public key encryption method using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key, and generating the digital certificate including the second storage area; transmitting the generated digital certificate to the electronic information storage medium; A digital certificate generation method characterized by including the above steps.

21. A processing result response method executed by an electronic information storage medium capable of communicating with a digital certificate generation device, receiving a setting instruction including control reference information including an encryption method information storage area for storing information indicating a first public key encryption method from the digital certificate generation device; determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; when it is determined that the arbitrary area is included in the control reference information, determining whether information indicating a second public key encryption method is stored in the arbitrary area; when it is determined that information indicating a second public key encryption method is stored in the arbitrary area, determining whether the electronic information storage medium supports the second public key encryption method; when it is determined that the electronic information storage medium supports the second public key encryption method, responding to the digital certificate generation device with a processing result indicating normal termination in response to the setting instruction; A processing result response method characterized by including the above steps.

22. In a computer included in a digital certificate generation device capable of communicating with an electronic information storage medium, A step of obtaining control reference information including an encryption method information storage area for storing information indicating a first public key encryption method from an electronic information storage medium; A step of determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; When it is determined that the arbitrary area is included in the control reference information, a step of determining whether information indicating a second public key encryption method is stored in the arbitrary area; When it is determined that the information indicating the second public key encryption method is stored in the arbitrary area, a first digital signature generated by the first public key encryption method using a first secret key and first predetermined data, and a public key information of a first public key forming a key pair with the first secret key are stored in a first storage area; a second digital signature generated by the second public key encryption method using a second secret key and second predetermined data, and a public key information of a second public key forming a key pair with the second secret key are stored in a second storage area; and a step of generating a digital certificate including the second storage area; A step of transmitting the generated digital certificate to the electronic information storage medium; A program characterized by causing the above to be executed.

23. On a computer included in an electronic information storage medium capable of communicating with a digital certificate generation device, A control reference information including an encryption method information storage area for storing information indicating a first public key encryption method and an arbitrary area for storing information freely defined by an application provider, and storing the control reference information in which information indicating a second public key encryption method is stored in the arbitrary area in a storage means; A step of reading out the control reference information in response to a read instruction from the digital certificate generation device and transmitting it to the digital certificate generation device; A digital certificate generated by the digital certificate generation device based on the control reference information, including a first digital signature generated by the first public key encryption method using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key stored in a first storage area; a second digital signature generated by the second public key encryption method using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key stored in a second storage area; and a step of obtaining the digital certificate from the digital certificate generation device; A program characterized by causing [the following steps to be] executed.

24. In a computer included in a digital certificate generation device capable of communicating with an electronic information storage medium, a control reference information including a cryptographic method information storage area for storing information indicating a first public key cryptography method, and an arbitrary area for storing information freely defined by an application provider, and transmitting a setting instruction of the control reference information in which information indicating a second public key cryptography method is stored in the arbitrary area to the electronic information storage medium; when a processing result indicating normal termination is received from the electronic information storage medium in response to the setting instruction, a first storage area for storing a first digital signature generated by the first public key cryptography method using a first secret key and first predetermined data, and public key information of a first public key forming a key pair with the first secret key; and a second storage area for storing a second digital signature generated by the second public key cryptography method using a second secret key and second predetermined data, and public key information of a second public key forming a key pair with the second secret key, and generating the digital certificate including the same; transmitting the generated digital certificate to the electronic information storage medium; A program characterized by causing [the following steps to be] executed.

25. In a computer included in an electronic information storage medium capable of communicating with a digital certificate generation device, receiving, from the digital certificate generation device, a setting instruction including control reference information including a cryptographic method information storage area for storing information indicating a first public key cryptography method; determining whether an arbitrary area for storing information freely defined by an application provider is included in the control reference information; when it is determined that the arbitrary area is included in the control reference information, determining whether information indicating a second public key cryptography method is stored in the arbitrary area; when it is determined that information indicating a second public key cryptography method is stored in the arbitrary area, determining whether the electronic information storage medium supports the second public key cryptography method; when it is determined that the electronic information storage medium supports the second public key cryptography method, responding to the digital certificate generation device with a processing result indicating normal termination in response to the setting instruction; A program characterized by causing [the following steps to be] executed.

Citation Information

Patent Citations

  • Using Digital Certificates with Multiple Cryptosystems

    JP2019509652A