Electronic information storage medium, IC chip, IC card, secure channel establishment method, and program

The IC chip or card adapts to switched secure channel protocols by storing multiple key data and identifying them based on received commands, ensuring secure channel establishment without reissue or distribution procedures.

JP2025110134AActive Publication Date: 2025-07-28DAI NIPPON PRINTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024003895
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-15
Publication Date
2025-07-28
Estimated Expiration
2044-01-15

AI Technical Summary

Technical Problem

IC cards requiring a reissue and distribution procedures when the secure channel protocol is switched due to system specification changes, and the challenge of selecting appropriate key data for multiple key lengths post-switch.

Method used

An IC chip or card that stores multiple key data with different lengths for various secure channel protocols, identifies the protocol and key data based on received commands, and executes secure channel opening processes without reissue procedures.

Benefits of technology

Enables seamless adaptation to switched secure channel protocols without reissue or distribution, facilitating secure channel establishment with appropriate key data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025110134000001_ABST
    Figure 2025110134000001_ABST
Patent Text Reader

Abstract

To provide an electronic information storage medium, an IC chip, an IC card, a secure channel establishment method, and a program that can appropriately handle a secure channel protocol after switching without requiring reissuing and a distribution procedure even when the secure channel protocol is switched due to a specification change of a system.SOLUTION: An IC chip 1 executes processing for: receiving a command APDU that includes an SCPID and a key attribute of an SCP which should be selected by an SD from an external device 2 for establishing a secure channel with the external device 2; identifying the SCP on the basis of the SCPID included in the received command APDU; identifying key data on the basis of the key attribute included in the command APDU; and establishing a secure channel with the external device 2 using the identified key data according to the identified SCP.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of IC (Integrated Circuit) cards and the like capable of opening a secure channel with an external device.

Background Art

[0002] Conventionally, in IC cards compliant with specifications such as GlobalPlatform (registered trademark), a secure channel is opened with an external device for secure communication. As a secure channel protocol (encryption protocol) for opening such a secure channel, for example, as disclosed in Patent Document 1, SCP (Secure Channel Protocol) 01, SCP02, SCP03, etc. have been conventionally used. In recent years, SCP10 using the RSA (Rivest Shamir Adleman asymmetric algorithm) encryption method (encryption algorithm) has become popular. Furthermore, in recent years, as an encryption method with higher security than the RSA encryption method, the ECC (Elliptic Curve Cryptography) encryption method has attracted attention, and SCP11 using the ECC encryption method is defined in GlobalPlatform Technology Secure Channel Protocol 11 Card Specification v2.3 - Amendment F Version 1.2.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] By the way, in actual operation, for example, when the secure channel protocol to be used is switched due to a system specification change, an IC card that supports only one secure channel protocol needs to be reissued to support the secure channel protocol after the switch, and there is a problem that time and labor are required for the reissue and distribution procedures. Furthermore, there may be a case where a plurality of key data with different key lengths can be used according to the secure channel protocol after the switch, and there is also a problem of which key data to use to open a secure channel.

[0005] Therefore, the present invention has been made in view of such points, and for example, even when the secure channel protocol is switched due to a system specification change, it is possible to appropriately respond to the secure channel protocol after the switch without requiring reissue and distribution procedures. An example of the problem is to provide an electronic information storage medium, an IC chip, an IC card, a secure channel opening method, and a program.

Means for Solving the Problem

[0006] In order to solve the above problems, the invention according to claim 1 is an electronic information storage medium that stores a plurality of key data used by each of a plurality of secure channel protocols for opening a secure channel with an external device, the plurality of key data having different key lengths, and receives from the external device a command including an identifier of a secure channel protocol to be selected and at least a key attribute indicating an identifier and a key length of the key data for opening a secure channel with the external device. Receiving means, first specifying means for specifying a secure channel protocol based on the identifier included in the command received by the receiving means, second specifying means for specifying key data based on the key attribute included in the command received by the receiving means, and the first And channel opening means for executing a process for opening a secure channel with the external device using the key data specified by the second specifying means according to the secure channel protocol specified by the specifying means.

[0007] The invention according to claim 2 is the electronic information storage medium according to claim 1, wherein the electronic information storage medium stores a plurality of key data with different key lengths used by the same type of secure channel protocol, and the identifier and key version of each of the key data are the same.

[0008] The invention according to claim 3 is the electronic information storage medium according to claim 1 or 2, wherein the electronic information storage medium stores the expiration date of each of the key data in association with the key data, and when the key data is specified by the second specifying means, further includes transmission means for transmitting a response including the expiration date to the external device.

[0009] The invention according to claim 4 is an IC chip that stores a plurality of key data with different key lengths, which are key data used by each of a plurality of secure channel protocols for opening a secure channel with an external device, and receives from the external device a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier and a key length of the key data for opening a secure channel with the external device, a first specifying means for specifying a secure channel protocol based on the identifier included in the command received by the receiving means, a second specifying means for specifying key data based on the key attribute included in the command received by the receiving means, and channel opening means for executing a process for opening a secure channel with the external device using the key data specified by the second specifying means according to the secure channel protocol specified by the first specifying means.

[0010] The invention according to claim 5 is an IC card that stores key data used by each of a plurality of secure channel protocols for opening a secure channel with an external device, the key data being a plurality of key data having different key lengths, and includes receiving means for receiving, from the external device, a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of the key data and the key length, first specifying means for specifying a secure channel protocol based on the identifier included in the command received by the receiving means, second specifying means for specifying key data based on the key attribute included in the command received by the receiving means, and channel opening means for executing a process for opening a secure channel with the external device using the key data specified by the second specifying means according to the secure channel protocol specified by the first specifying means.

[0011] The invention according to claim 6 is a secure channel opening method executed by an electronic information storage medium that stores key data used by each of a plurality of secure channel protocols for opening a secure channel with an external device, the key data being a plurality of key data having different key lengths, and includes receiving a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of the key data and the key length from the external device for opening a secure channel with the external device, specifying a secure channel protocol based on the identifier included in the received command, specifying key data based on the key attribute included in the received command, and executing a process for opening a secure channel with the external device using the specified key data according to the specified secure channel protocol.

[0012] The invention according to claim 7 is a computer included in an electronic information storage medium that stores a plurality of key data having different key lengths, which is key data used by each of a plurality of secure channel protocols for opening a secure channel with an external device. The computer receives, from the external device, a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of key data and a key length in order to open a secure channel with the external device; a step of specifying a secure channel protocol based on the identifier included in the received command; a step of specifying key data based on the key attribute included in the received command; and a step of executing a process for opening a secure channel with the external device using the specified key data according to the specified secure channel protocol.

Advantages of the Invention

[0013] According to the present invention, even when the secure channel protocol is switched due to, for example, a change in the system specification, it is possible to appropriately respond to the secure channel protocol after the switch without requiring a reissue and distribution procedure.

Brief Description of the Drawings

[0014]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Embodiments for Carrying Out the Invention

[0015] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.

[0016] [1. Configuration and Functions of IC Chip 1] First, with reference to FIG. 1, the configuration and functions of the IC chip 1 according to the present embodiment will be described. The IC chip 1 according to the present embodiment is a secure element that supports a plurality of secure channel protocols (hereinafter referred to as "SCP"), and is an example of the electronic information storage medium of the present invention. The IC chip 1 is mounted on, for example, an IC card such as a credit card, a cash card, or a my number card, or a mobile device such as a smartphone. In the case of a mobile device such as a smartphone, the IC chip 1 may be mounted on a small IC card that is detachable from the mobile device, or may be mounted on an embedded substrate so that it cannot be easily removed or replaced from the mobile device as an eUICC (Embedded Universal Integrated Circuit Card).

[0017] FIG. 1 is a diagram showing an example of the hardware configuration of the IC chip 1. As shown in FIG. 1, the IC chip 1 includes an I / O circuit 11, a RAM (Random Access Memory) 12, an NVM (Nonvolatile Memory) 13, a ROM (Read Only Memory) 14, a CPU (Central Processing Unit) 15 (an example of a computer), and a coprocessor 16 that performs cryptographic operations. The I / O circuit 11 serves as an interface with the external device 2. Note that the communication between the IC chip 1 and the external device 2 may be non-contact communication or contact communication. In the case of non-contact communication, for example, communication between the IC chip 1 and the external device 2 is performed via an antenna (not shown) mounted on an IC card or a mobile device. Note that the example of the external device 2 is not particularly limited, but an OCE (Off Card Entity) may be mentioned.

[0018] For example, a flash memory is applied to the NVM 13. Note that the NVM 13 may be an “Electrically Erasable Programmable Read-Only Memory”. Various programs such as an OS (Operating System), an SD (Security Domain), and an application (including the program of the present invention) are stored in the NVM 13 or the ROM 14. The SD is a management program for managing applications. The SD is for causing the CPU 15 to realize functions such as installing a new application under its control (management) or establishing a secure channel (encrypted communication path) for an application under its control. Note that the application includes, for example, a payment application.

[0019] In addition, the SD supports a plurality of SCPs for opening a secure channel with the external device 2 and has key data used by each of the plurality of SCPs under its control. In the present embodiment, SCP10 and SCP11a are taken as examples of the SCPs. Each key data is stored (saved) in the secure storage area of the NVM13. For example, the SD manages a key storage (logical key space) in which each key data is stored by information related to the key data. That is, the key data is managed in association with the information related to the key data. The information related to the key data includes a key ID (identifier of the key data), a key version, a cipher type, a key usage (key type), an SCPID (an example of an identifier of a secure channel protocol), and an expiration date, etc., and is stored in the NVM13 separately for each key data.

[0020] Here, the cipher type indicates a cipher algorithm (for example, RSA cipher method or ECC cipher method) and a key length. The key usage indicates a TP public key or an SD secret key. The TP public key is the public key of a certification authority. The SD secret key is a secret key unique to the SD and forms a key pair with the SD public key. The SCPID “10” is the identifier of the SCP10, and the SCPID “11” is the identifier of the SCP11a. The expiration date associated with the SD secret key is also the expiration date of the SD public key that forms a key pair with the SD secret key. The NVM13 stores an SD public key certificate including the SD public key and the signature (signature data) of the certification authority. Note that the SD public key certificate is stored separately for each of the plurality of SCPs (for example, SCP10 and SCP11a).

[0021] FIG. 2 is a diagram showing an example of information regarding a plurality of key data stored in the secure storage area of the NVM 13. In the example of FIG. 2, the encryption type "RSA2048" indicates the RSA encryption method and a key length of 2048 bits. On the other hand, the encryption type "ECC256" indicates the ECC encryption method and a key length of 256 bits, and the encryption type "ECC384" indicates the ECC encryption method and a key length of 384 bits. The key data of "ECC256" and the key data of "ECC384" are both key data used by the SCP 11a. That is, in the secure storage area of the NVM 13, a plurality of key data with different key lengths (that is, key data with the same key usage) used by the same type of SCP are stored, and the key ID and key version of each key data (for example, the SD secret key) are the same.

[0022] The CPU 15 (SD as software) functions as receiving means, first specifying means, second specifying means, channel opening means, transmitting means, etc. in the present invention. Specifically, the CPU 15 receives, from the external device 2, a command including the SCPID and key attributes of the SCP to be selected by the SD in order to open a secure channel with the external device 2. Such a command is, for example, the MANAGE SECURITY ENVIRONMENT command defined in the Global Platform Card Specification, and is composed of a command APDU (Application Protocol Data Unit) including a header part consisting of CLA, INS, P1, and P2 and a body part consisting of Lc, Data, and Le. Here, the SCPID and key attributes are set in the Data. The key attribute is also referred to as a key reference and is information necessary for specifying the key data used by the SCP for opening a secure channel with the external device 2.

[0023] FIG. 3 is a diagram showing an example of the format of Data included in the body part of the MANAGE SECURITY ENVIRONMENT command. The Data shown in FIG. 3 is configured in the TLV format. In the Value field corresponding to Tag “80”, the SCPID and Parameter “i” are stored. In the Value field corresponding to Tag “83”, the key attributes of the SD public key and the TP public key are stored. In the Value field corresponding to Tag “84”, the key attributes of the SD private key are stored. Here, the key attributes indicate, for example, the key ID, the key version, the encryption type, and the key usage. In order to identify the key data used by SCP11a from among the above-described plurality of key data, not only the key ID and the key version but also the key length indicated by the encryption type are required.

[0024] Then, the CPU 15 identifies the SCP based on the SCPID included in the received command APDU, and identifies the key data based on the key attributes included in the command APDU. According to the identified SCP, the CPU 15 executes a process (hereinafter referred to as “secure channel opening process”) for opening a secure channel with the external device 2 using the identified key data. When the key data is identified as described above, the CPU 15 may transmit a response APDU including the expiration date (for example, the expiration date of the SD public key) associated with the key data to the external device 2. Thereby, the external device 2 refers to the current time (including year, month, and day) to determine whether the expiration date of the key data has passed. If the expiration date has passed, the external device 2 does not start the secure channel opening process. As another example, when the key data is identified as described above, before the secure channel opening process is executed, the CPU 15 acquires time data indicating the current time from the external device 2, and based on the acquired time data, determines whether the expiration date associated with the identified key data has passed. If it is determined that the expiration date has passed, the CPU 15 may transmit a response APDU indicating an error to the external device 2.

[0025] [2. Operations Performed by the IC Chip 1 and the External Device 2] Next, with reference to FIGS. 4 to 6, the operations performed by the IC chip 1 and the external device 2 will be described. FIG. 4 is a sequence diagram showing an example of the processing until the secure channel opening process is started between the IC chip 1 (SD) and the external device 2 (OCE). FIG. 5 is a sequence diagram showing an example of the secure channel opening process when the SCP10 is specified by the external device 2. FIG. 6 is a sequence diagram showing an example of the secure channel opening process when the SCP11a is specified by the external device 2.

[0026] (2.1. Processing until the secure channel opening process is started) First, in the processing until the secure channel opening process is started, as shown in FIG. 4, the external device 2 transmits a MANAGE SECURITY ENVIRONMENT command including the SCPID and key attributes of the SCP (that is, the SCP to be selected by the SD) specified for the SD to open a secure channel with the IC chip 1 to the IC chip 1 (step S1). It is assumed that the SCP to be specified is SCP10 or SCP11a.

[0027] Next, when the IC chip 1 receives the MANAGE SECURITY ENVIRONMENT command from the external device 2, it acquires the SCPID and key attributes from the MANAGE SECURITY ENVIRONMENT command (step S2). Next, the IC chip 1 identifies the SCP based on the SCPID acquired in step S2 (step S3). Next, the IC chip 1 identifies the key data from the secure storage area of the NVM13 by the SD based on the key attributes acquired in step S2 (step S4). The key data identified here includes, in addition to the TP public key and the SD secret key, the SD public key obtained from the SD public key certificate. When the SCP and the key data are thus identified, the IC chip 1 transmits a response APDU indicating normal termination to the external device 2 (step S5). Here, the response APDU may include an expiration date associated with the identified key data.

[0028] Next, when the external device 2 receives the response APDU from the IC chip 1, it starts the secure channel establishment process according to the specified SCP (step S6). If the response APDU contains the expiration date of the key data, it refers to the current time to determine whether the expiration date of the key data has passed, and starts the secure channel establishment process only if the expiration date has not passed.

[0029] (2.2. Secure Channel Establishment Process When SCP10 is Specified) Next, in the secure channel establishment process when SCP10 is specified, as shown in FIG. 5, the external device 2 transmits a PERFORM SECURITY OPERATION command to the IC chip 1 (step S11). The PERFORM SECURITY OPERATION command is, for example, a command APDU defined in the Global Platform Card Specification, and the OCE public key certificate for SCP10 is set in the Data included in its body part. The OCE public key certificate includes the OCE public key for SCP10 unique to the OCE and the signature of the certification authority.

[0030] Next, when the IC chip 1 receives the PERFORM SECURITY OPERATION command from the external device 2, it obtains the OCE public key certificate from the PERFORM SECURITY OPERATION command (step S12). Next, the IC chip 1 verifies (signature verification) the OCE public key certificate obtained in step S12 using the TP public key for SCP10 specified in step S4 (step S13). Next, when the verification of the OCE public key certificate is successful, the IC chip 1 obtains the OCE public key for SCP10 from the OCE public key certificate (step S14) and transmits a response APDU indicating normal termination to the external device 2 (step S15). If the verification of the OCE public key certificate fails, a response APDU indicating an error is transmitted to the external device 2.

[0031] Next, when the external device 2 receives the response APDU from the IC chip 1, it transmits a GET DATA command to the IC chip 1 (step S16). The GET DATA command is, for example, a command APDU defined in the Global Platform Card Specification and is a command for acquiring the SD public key certificate for SCP10.

[0032] Next, when the IC chip 1 receives the GET DATA command from the external device 2, it acquires the SD public key certificate of the SD public key for SCP10 specified in step S4 from the NVM 13 (step S17). Next, the IC chip 1 transmits a response APDU that includes the SD public key certificate acquired in step S17 and indicates normal termination to the external device 2 (step S18).

[0033] Next, when the external device 2 receives the response APDU from the IC chip 1, it acquires the SD public key certificate for SCP10 from the response APDU (step S19). Next, the external device 2 verifies (signature verification) the SD public key certificate acquired in step S19 using the TP public key for SCP10 (step S20). Next, when the verification of the SD public key certificate is successful, the external device 2 acquires the SD public key for SCP10 from the SD public key certificate (step S21) and transmits an EXTERNAL AUTHENTICATE command to the IC chip 1 (step S22). The EXTERNAL AUTHENTICATE command is, for example, a command APDU defined in the Global Platform Card Specification, and in the Data included in its body part, for example, a signature (signature data) generated using the OCE secret key for SCP10 is set. For example, the signature is generated by performing a cryptographic operation using the OCE secret key with a random number generated by the external device 2 as input data. Note that the Data may include the signature of the OCE and the random number.

[0034] Next, when the IC chip 1 receives the EXTERNAL AUTHENTICATE command from the external device 2, it obtains a signature from the EXTERNAL AUTHENTICATE command (step S23). Next, the IC chip 1 verifies (signature verification) the signature obtained in step S23 using the OCE public key obtained in step S14 (step S24). Next, when the verification in step S24 is successful, the IC chip 1 transmits a response APDU indicating normal termination to the external device 2 (step S25). If the verification of the signature fails, a response APDU indicating an error is transmitted to the external device 2.

[0035] Next, when the external device 2 receives the response APDU from the IC chip 1, it transmits an INTERNAL AUTHENTICATE command to the IC chip 1 (step S26). The INTERNAL AUTHENTICATE command is, for example, a command APDU defined in the Global Platform Card Specification, and a random number generated by the external device 2 is set in the Data included in the body part thereof.

[0036] Next, when the IC chip 1 receives the INTERNAL AUTHENTICATE command from the external device 2, it obtains a random number from the INTERNAL AUTHENTICATE command (step S27). Next, the IC chip 1 generates a signature by performing a cryptographic operation using the SD secret key for SCP10 specified in step S4 with the random number obtained in step S27 as input data (step S28), and transmits a response APDU including the generated signature and indicating normal termination to the external device 2 (step S29).

[0037] Next, when the external device 2 receives the response APDU from the IC chip 1, it obtains a signature from the response APDU (step S30). Next, the external device 2 verifies (signature verification) the signature obtained in step S30 using the SD public key obtained in step S21 (step S31). Then, when the verification is successful in step S31, a secure channel is established between the external device 2 and the IC chip 1 (step S32).

[0038] (Secure Channel Establishment Process When SCP11a is Specified) Next, in the secure channel establishment process when SCP11a is specified, as shown in FIG. 6, the external device 2 transmits a GET DATA command to the IC chip 1 (step S41). The GET DATA command is, for example, a command APDU defined in the Global Platform Card Specification and is a command for obtaining an SD public key certificate (CERT.SD.ECKA) for SCP11a.

[0039] Next, when the IC chip 1 receives the GET DATA command from the external device 2, it obtains the SD public key certificate of the SD public key for SCP11a specified in step S4 from the NVM 13 (step S42). Next, the IC chip 1 transmits a response APDU including the SD public key certificate obtained in step S42 and indicating normal termination to the external device 2 (step S43).

[0040] Next, when the external device 2 receives the response APDU from the IC chip 1, it acquires the SD public key certificate for SCP11a from the response APDU (step S44). Next, the external device 2 verifies (signature verification) the SD public key certificate acquired in step S44 using the TP public key for SCP11a specified in step S4 (step S45). Next, when the verification of the SD public key certificate is successful, the external device 2 acquires the SD public key (PK.SD.ECKA) for SCP11a from the SD public key certificate (step S46) and transmits a PERFORM SECURITY OPERATION command to the IC chip 1 (step S47). The OCE public key certificate (CERT.OCE.ECKA) for SCP11a is set in the Data included in the body part of the PERFORM SECURITY OPERATION command. The OCE public key certificate includes the OCE public key (PK.OCE.ECKA) for SCP11a unique to OCE and the signature of the certification authority.

[0041] Next, when the IC chip 1 receives the PERFORM SECURITY OPERATION command from the external device 2, it acquires the OCE public key certificate from the PERFORM SECURITY OPERATION command (step S48). Next, the IC chip 1 verifies (signature verification) the OCE public key certificate acquired in step S48 using the TP public key for SCP11a specified in step S4 (step S49). Next, when the verification of the OCE public key certificate is successful, the IC chip 1 acquires the OCE public key for SCP11a from the OCE public key certificate (step S50) and transmits a response APDU indicating normal termination to the external device 2 (step S51). When the verification of the OCE public key certificate fails, a response APDU indicating an error is transmitted to the external device 2.

[0042] Next, when the external device 2 receives the response APDU from the IC chip 1, it transmits a MUTUAL AUTHENTICATE command to the IC chip 1 (step S52). The MUTUAL AUTHENTICATE command is, for example, a command APDU defined in the Global Platform Card Specification, and in the Data included in its body part, for example, a temporary public key (ePK.OCE.ECKA) generated by the external device 2 is set.

[0043] Next, when the IC chip 1 receives the MUTUAL AUTHENTICATE command from the external device 2, it acquires the temporary public key from the MUTUAL AUTHENTICATE command (step S53). Next, the IC chip 1 generates a session key for use in the secure channel session for use in the secure channel according to a predetermined algorithm (step S54). For example, the IC chip 1 generates a temporary key pair of a temporary secret key (eSK.SD.ECKA) and a temporary public key (ePK.SD.ECKA) unique to the SD, and calculates a shared secret (ShSss) from the SD public key and the SD secret key for SCP11a. Then, the IC chip 1 calculates a temporary shared secret (ShSee) from the temporary public key (ePK.OCE.ECKA) acquired in step S53 and the generated temporary secret key (eSK.SD.ECKA), and generates a session key from the generated shared secret (ShSss) and the generated temporary shared secret (ShSee). Next, the IC chip 1 transmits a response APDU including the generated temporary public key (ePK.SD.ECKA) and indicating normal termination to the external device 2 (step S55).

[0044] Next, when the external device 2 receives the response APDU from the IC chip 1, it acquires the temporary public key (ePK.SD.ECKA) from the response APDU (step S56), and generates a session key common to the IC chip 1 by the same algorithm as the IC chip 1 (step S57). Thereby, a secure channel is established between the external device 2 and the IC chip 1 (step S58).

[0045] As described above, according to the above embodiment, the IC chip 1 receives, from the external device 2, a command APDU including the SCPID and key attributes of the SCP to be selected by the SD in order to open a secure channel with the external device 2, identifies the SCP based on the SCPID included in the received command APDU, and identifies the key data based on the key attributes included in the command APDU. According to the identified SCP, the IC chip 1 is configured to execute a process for opening a secure channel with the external device 2 using the identified key data. Therefore, even when the SCP is switched due to a change in the system specification, for example, it is possible to appropriately respond to the switched SCP without requiring reissuance and distribution procedures. Further, according to the above embodiment, even when a plurality of key data having different key lengths (for example, key data of "ECC256" and key data of "ECC384") such as SCP11a can be used, it is possible to identify appropriate key data and open a secure channel.

[0046] In the above embodiment, as examples of a plurality of SCPs, SCP10 and SCP11a are described as examples. However, the present invention is applicable to a plurality of currently available SCPs other than these (for example, SCP02, SCP03, SCP11b, SCP11c, etc.) and SCPs that may be defined in the future.

Explanation of Reference Numerals

[0047] 1 IC chip 2 External device 11 I / O circuit 12 RAM( 13 NVM 14 ROM 15 CPU 16 Coprocessor

Claims

1. An electronic information storage medium that stores a plurality of key data with different key lengths, which are key data used by each of a plurality of secure channel protocols for opening a secure channel with an external device, Receiving means for receiving, from the external device, a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of the key data and the key length, in order to open a secure channel with the external device; First specifying means for specifying a secure channel protocol based on the identifier included in the command received by the receiving means; Second specifying means for specifying key data based on the key attribute included in the command received by the receiving means; Channel opening means for executing a process for opening a secure channel with the external device using the key data specified by the second specifying means in accordance with the secure channel protocol specified by the first specifying means; An electronic information storage medium, characterized by comprising the above.

2. The electronic information storage medium stores a plurality of key data with different key lengths, which are used by the same type of secure channel protocol, The electronic information storage medium according to claim 1, characterized in that the identifier and key version of each of the key data are the same.

3. The electronic information storage medium stores an expiration date of the key data in association with each of the key data, The electronic information storage medium according to claim 1 or 2, further comprising transmitting means for transmitting a response including the expiration date to the external device when the key data is specified by the second specifying means.

4. An IC chip that stores a plurality of key data with different key lengths, which are key data used by each of a plurality of secure channel protocols for opening a secure channel with an external device, Receiving means for receiving, from the external device, a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of the key data and the key length, in order to open a secure channel with the external device; First specifying means for specifying a secure channel protocol based on the identifier included in the command received by the receiving means; Second specifying means for specifying key data based on the key attributes included in the command received by the receiving means; Channel opening means for executing a process for opening a secure channel with the external device by using the key data specified by the second specifying means in accordance with the secure channel protocol specified by the first specifying means; An IC chip characterized by comprising the same. **Claim 5** An IC card that stores a plurality of key data having different key lengths, which are key data used by respective ones of a plurality of secure channel protocols for opening a secure channel with an external device, Receiving means for receiving, from the external device, a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of key data and a key length, for opening a secure channel with the external device; First specifying means for specifying a secure channel protocol based on the identifier included in the command received by the receiving means; Second specifying means for specifying key data based on the key attribute included in the command received by the receiving means; Channel opening means for executing a process for opening a secure channel with the external device by using the key data specified by the second specifying means in accordance with the secure channel protocol specified by the first specifying means; An IC card characterized by comprising the same. **Claim 6** A secure channel opening method executed by an electronic information storage medium that stores a plurality of key data having different key lengths, which are key data used by respective ones of a plurality of secure channel protocols for opening a secure channel with an external device, Receiving, from the external device, a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of key data and a key length, for opening a secure channel with the external device; Specifying a secure channel protocol based on the identifier included in the received command; Specifying key data based on the key attribute included in the received command; Executing a process for opening a secure channel with the external device by using the specified key data in accordance with the specified secure channel protocol; A secure channel establishment method characterized by including [

7. ] On a computer included in an electronic information storage medium that stores a plurality of key data with different key lengths, which is key data used by each of a plurality of secure channel protocols for establishing a secure channel with an external device, Receiving, from the external device, a command including an identifier of a secure channel protocol to be selected and a key attribute indicating at least an identifier of key data and a key length, in order to establish a secure channel with the external device; Identifying a secure channel protocol based on the identifier included in the received command; Identifying key data based on the key attribute included in the received command; Executing a process for establishing a secure channel with the external device using the identified key data in accordance with the identified secure channel protocol; A program characterized by causing the above to be executed.

Citation Information

Patent Citations

  • Computer program

    JP2020036370A