IC card, management server, electronic information storage medium, data processing method, and program
The IC card facilitates the sharing of control data with user terminals and controllers by incorporating communication and verification mechanisms, addressing the lack of input and connection functions in traditional IC cards to control objects like vehicle doors and engines.
Patent Information
- Application Number
- JP2024032370
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-04
- Publication Date
- 2025-09-17
AI Technical Summary
IC cards lack input and connection functions, making it difficult to share control data with user terminals and controllers, which are typically used to control objects like vehicle doors and engines.
An IC card equipped with receiving, writing, matching, and transmitting means to facilitate communication with user terminals and controllers, enabling the sharing of control data and verification processes through a management server.
Enables easy sharing of control data between IC cards and controllers, allowing seamless control of objects such as vehicle doors and engines.
Smart Images

Figure 2025134453000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to the technical field of IC (Integrated Circuit) cards and the like that are capable of contactless communication with user terminals. [Background technology]
[0002] Conventionally, digital keys having an IC tag that stores access rights to a storage unit have been known, as disclosed in Patent Document 1, for example. In Patent Document 1, when the digital key is inserted into a storage unit keyhole of a lock attached to a storage box of the storage unit, the access rights of the digital key are confirmed by a storage unit control device, thereby unlocking the lock, and the door of the storage box is then opened by rotating the digital key. In other words, the digital key is used to have the control device control the storage unit door (door mechanism). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6762552 Summary of the Invention [Problem to be solved by the invention]
[0004] In recent years, user terminals such as smartphones have begun to be used instead of digital keys to allow controllers to control control objects such as the aforementioned storage door, vehicle doors, and engines. In such cases, the user terminal typically has an input function for receiving input directly from the user and a connection function for connecting to a network such as the Internet, making it easy to perform in advance the process for sharing control data used to control the control object. Meanwhile, there is also a need to use so-called IC cards instead of digital keys. However, IC cards typically do not have the input and connection functions described above, making it difficult to share control data between the IC card and the controller of the control object.
[0005] Therefore, the present invention has been made in consideration of these points and has as one example an objective thereof to provide an IC card, a management server, an electronic information storage medium, a data processing method, a program, etc. that enable the process of sharing control data between the controller of the controlled object to be easily carried out. [Means for solving the problem]
[0006] In order to solve the above problem, the invention described in claim 1 is an IC card capable of communicating between a user terminal used by a user and a controller used by the user to control a controlled object, and is characterized in that it comprises: a first receiving means for receiving a first command including first matching data from the user terminal; a first writing means for writing the first matching data included in the first command to a setting area of a non-volatile memory in the IC card in response to the first command received by the first receiving means; a second receiving means for receiving a second command from the controller including second matching data and control data used when controlling the controlled object; a matching means for matching the first matching data written to the setting area with the second matching data included in the second command in response to the second command received by the second receiving means; and a second writing means for writing the control data included in the second command to a storage area of the non-volatile memory if the matching is successful.
[0007] The invention described in claim 2 is characterized in that, in the IC card described in claim 1, it is provided with a transmitting means for transmitting the control data written in the storage area to the controller in order to have the controller control the controlled object.
[0008] The invention described in claim 3 is the IC card described in claim 1, characterized in that the controller stores a key pair unique to the controller, the key pair including a first private key and a first public key, the control data being the first public key, and the IC card further comprises: a third receiving means for receiving from the controller a third command including first signature data generated by the controller using the first private key; a verification means for verifying the signature data included in the third command using the first public key written to the storage area in response to the third command received by the third receiving means; and a first transmitting means for transmitting to the controller a response indicating that the verification was successful if the verification was successful.
[0009] The invention described in claim 4 is the IC card described in claim 3, characterized in that the IC card stores a key pair unique to the IC card, the key pair including a second private key and a second public key, and is equipped with: second transmitting means for transmitting a response including the second public key to the controller if the matching is successful; fourth receiving means for receiving a fourth command from the controller after transmitting the response indicating that the verification is successful; generation means for generating second signature data using the second private key in response to the fourth command received by the fourth receiving means; and third transmitting means for transmitting a response including the second signature data generated by the generation means to the controller.
[0010] The invention described in claim 5 is an IC card described in any one of claims 1 to 4, characterized in that the first matching data is a matching password input by the user to the user terminal, and the second matching data is a matching password input by the user to the controller.
[0011] The invention described in claim 6 is a management server in a communication system comprising a user terminal used by a user, a controller used by the user to control a controlled object, and an IC card capable of communicating between the user terminal and the controller, which corresponds an identifier unique to the user with an identifier unique to the IC card and registers them in a database, wherein the IC card receives first matching data from the user terminal and writes it to a non-volatile memory, and when it receives second matching data and control data used to control the controlled object from the controller, it compares the first matching data with the second matching data and writes the control data to the non-volatile memory if the comparison is successful, and the management server is characterized in comprising: a fifth receiving means for receiving from the controller a registration request including pairing information that corresponds an identifier unique to the IC card with an identifier unique to the controller after the control data has been written to the non-volatile memory, and a registration means for registering the pairing information in the database in correspondence with the identifier unique to the user based on the pairing information included in the registration request received by the fifth receiving means.
[0012] The invention described in claim 7 is the management server described in claim 6, characterized in that it comprises a sixth receiving means for receiving a deletion request including the pairing information from the controller, and a deletion means for deleting the pairing information from the database based on the pairing information included in the deletion request received by the sixth receiving means.
[0013] The invention described in claim 8 is the management server described in claim 6, characterized in that it comprises a sixth receiving means for receiving a deletion request including the pairing information from the controller, an identification means for identifying an identifier unique to the user of the user terminal that corresponds to the pairing information included in the deletion request received by the sixth receiving means, and a deletion control means for deleting the control data from the storage area of the non-volatile memory by sending a deletion command for the control data to the IC card via the user terminal of the user corresponding to the identifier identified by the identification means.
[0014] The invention described in claim 9 is an electronic information storage medium capable of communicating between a user terminal used by a user and a controller used by the user to control a controlled object, comprising: a first receiving means for receiving a first command including first matching data from the user terminal; a first writing means for writing the first matching data included in the first command to a setting area of a non-volatile memory in the electronic information storage medium in response to the first command received by the first receiving means; a second receiving means for receiving a second command from the controller including second matching data and control data used when controlling the controlled object; a matching means for matching the first matching data written to the setting area with the second matching data included in the second command in response to the second command received by the second receiving means; and a second writing means for writing the control data included in the second command to a storage area of the non-volatile memory if the matching is successful.
[0015] The invention described in claim 10 is a data processing method executed by an IC card capable of communicating between a user terminal used by a user and a controller used by the user to control a controlled object, comprising the steps of: receiving a first command including first matching data from the user terminal; writing the first matching data included in the first command to a setting area of a non-volatile memory in the IC card in accordance with the received first command; receiving a second command from the controller including second matching data and control data used when controlling the controlled object; comparing the first matching data written to the setting area with the second matching data included in the second command in accordance with the received second command; and, if the matching is successful, writing the control data included in the second command to a storage area of the non-volatile memory.
[0016] The invention described in claim 11 is characterized in that a computer included in an IC card capable of communicating between a user terminal used by a user and a controller used by the user that controls a controlled object executes the following steps: receiving a first command including first matching data from the user terminal; writing the first matching data included in the first command to a setting area of a non-volatile memory in the IC card in response to the received first command; receiving a second command from the controller including second matching data and control data used when controlling the controlled object; comparing the first matching data written to the setting area with the second matching data included in the second command in response to the received second command; and, if the matching is successful, writing the control data included in the second command to a storage area of the non-volatile memory. [Effects of the Invention]
[0017] According to the present invention, it is possible to easily carry out the process of sharing control data with the controller of the controlled object. [Brief explanation of the drawings]
[0018] [Figure 1] FIG. 1 is a diagram illustrating an example of a schematic configuration of a communication system S. [Figure 2] FIG. 2 is a diagram illustrating an example of a schematic configuration of a user terminal 1. [Figure 3] FIG. 2 is a diagram illustrating an example of a schematic configuration of an IC card 2. [Figure 4] (A) is an example showing the contents of a SET PASSWORD command, and (B) is an example showing the contents of a PAIRING command. [Figure 5] FIG. 2 is a diagram illustrating an example of a schematic configuration of a controller 3. [Figure 6] FIG. 2 is a diagram illustrating an example of a schematic configuration of a management server 4. [Figure 7] 10 is a sequence diagram showing an example of an operation for setting a verification password to the IC card 2. FIG. [Figure 8] 10 is a sequence diagram showing an example of a pairing operation between the IC card 2 and the controller 3. FIG. [Figure 9] 10 is a sequence diagram showing an example of a control operation of a controlled object O. FIG. [Figure 10] FIG. 10 is a sequence diagram illustrating an example of a control data deletion operation. DETAILED DESCRIPTION OF THE INVENTION
[0019] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. The embodiment described below is an embodiment in which the present invention is applied to an IC card capable of contact or contactless communication with a control device that controls (mainly by electrical signals) a control object provided in a vehicle (e.g., a gasoline-powered vehicle or an electric vehicle), a storage facility, or a building (e.g., a house). Examples of the control object include a door, a light, an audio speaker, a display, and a drive mechanism (e.g., an engine or a motor). For example, a door is controlled to lock / unlock, a light is controlled to turn on / off, an audio speaker is controlled to output / stop audio, a display is controlled to output / stop image (video), and an engine or motor is controlled to start / stop.
[0020] [1. Overview of Communication System S] First, a schematic configuration of a communication system S according to this embodiment will be described with reference to Fig. 1 and other figures. Fig. 1 is a diagram showing an example of the schematic configuration of the communication system S. As shown in Fig. 1, the communication system S is configured to include a user terminal 1, an IC card 2, a controller 3, and a management server 4. Here, the user terminal 1, the IC card 2, the controller 3, and a control target O controlled by the controller 3 are used by a user. The user terminal 1 and the controller 3 have an input function for receiving input directly from the user. Furthermore, the user terminal 1, the controller 3, and the management server 4 have a connection function for connecting to a communication network NW such as the Internet and a mobile communication network.
[0021] The IC card 2 is an example of an electronic information storage medium and has a communication function for contact or contactless communication between the user terminal 1 and the controller 3, but does not have the input function and the connection function that the user terminal 1 and the like have. Examples of contactless communication include near-field communication (NFC), Bluetooth (registered trademark), and short-range wireless communication using UWB (Ultra Wide Band) technology. For example, the IC card 2 is an authentication card held by the user and used by the user to allow the controller 3 to control the controlled object O. The IC card 2 may be an employee card, student card, or My Number card distributed to the user in advance.
[0022] [2-1. Configuration and Functions of User Terminal 1] Fig. 2 is a diagram showing an example of the schematic configuration of the user terminal 1. As shown in Fig. 2, the user terminal 1 is configured to include a communication unit 11, a short-range wireless communication unit 12, a storage unit 13, an operation / display unit 14, and a control unit 15. The user terminal 1 may be, for example, a smartphone. The communication unit 11 is connected to a communication network NW and controls communication with the management server 4. The short-range wireless communication unit 12 controls the short-range wireless communication with the IC card 2. The storage unit 13 is configured from a non-volatile memory or the like and stores various programs such as an OS (Operating System) and applications.
[0023] Such applications include a web browser, a session establishment application (for terminal), and a password setting application (for terminal). The session establishment application (for terminal) is a program for establishing (opening) a secure session (i.e., encrypted communication using a session key) with the IC card 2. The password setting application (for terminal) is a program for setting a verification password (an example of first verification data) in the IC card 2. The verification password is a password used for verification to share control data, which will be described later, and may be deleted after the sharing of the control data is completed. The storage unit 13 also stores a secure session establishment key (e.g., a MAC (Message Authentication Code) key, etc.) for establishing a secure session with the IC card 2.
[0024] The operation and display unit 14 includes, for example, an input function (including operation buttons) for receiving input directly from the user, and a display (for example, a touch panel) for displaying various information. The verification password is a character string arbitrarily determined by the user, and is input to the control unit 15 via the operation and display unit 14. Such a character string is composed of at least one element selected from the group consisting of numbers, symbols, and letters.
[0025] The control unit 15 is configured to include a CPU (Central Processing Unit), RAM (Random Access Memory), and ROM (Read Only Memory). In response to an operational input (instruction) from the user, the control unit 15 accesses the management server 4 via the communication unit 11 using a web browser and transmits a login request including pre-registered account information to the management server 4. This allows the management server 4 to identify the user (i.e., log in) through a login process on the management server 4. The account information includes a UID, which is an identifier unique to the user, and a login password. The login password may be the same as or different from the verification password.
[0026] Furthermore, the control unit 15 executes processing (for example, mutual authentication) to establish a secure session with the IC card 2 according to the session establishment application (for terminal) in response to operation input (instructions) from the user, and executes processing to set a matching password in the IC card 2 according to the password setting application (for terminal). Alternatively, after transmitting a login request to the management server 4, the control unit 15 may cause the management server 4 to set the matching password in the IC card 2 by transmitting a setting request including the matching password to the management server 4 in response to operation input (instructions) from the logged-in user.
[0027] [2-2. IC Card 2 Configuration and Functions] Fig. 3 is a diagram showing an example of the schematic configuration of the IC card 2. As shown in Fig. 3, the IC card 2 is equipped with an IC chip including an I / O circuit 21, a RAM 22, an NVM (Nonvolatile Memory) 23, a ROM 24, a CPU 25, and a coprocessor 26 that performs cryptographic operations. The I / O circuit 21 serves as an interface between the user terminal 1 and the controller 3. That is, the IC card 2 can perform contact communication or contactless communication between the user terminal 1 and the controller 3 via the I / O circuit 21. In the case of contactless communication, communication between the user terminal 1 and the controller 3 is performed, for example, via an antenna (not shown) mounted on the IC card 2.
[0028] The IC card 2 receives a command APDU (Application Protocol Data Unit) from the user terminal 1 or the controller 3 in contact or contactless communication via the I / O circuit 21, and returns a response APDU to the user terminal 1 or the controller 3 in response to the command APDU. The formats of the command APDU and the response APDU are defined in ISO / IEC 7816-3. The command APDU used in this embodiment is composed of a header section including a CLA (command class), an INS (command code), P1 and P2 (parameters), and a body section including Data. On the other hand, the response APDU used in this embodiment includes SW1 and SW2, which indicate status words (normal completion or error (abnormal completion)). Furthermore, the response APDU may also include Data.
[0029] The NVM 23 may be, for example, a flash memory. The NVM 23 may be an "Electrically Erasable Programmable Read-Only Memory." The NVM 23 or the ROM 24 stores various programs such as an OS, a security domain (SD), and applications (including the program of the present invention). The SD is a management program for managing applications. The SD enables the CPU 25 to implement functions such as installing new applications under its management and establishing secure sessions for applications under its management.
[0030] Such applications include a session establishment application (for card), a password setting application (for card), a pairing application (for card), and an object control application (for card). The session establishment application (for card) is a program for establishing a secure session with the user terminal 1, the controller 3, or the management server 4. The password setting application (for card) is a program for setting a verification password in the IC card 2 in response to a SET PASSWORD command (an example of a first command) from the user terminal 1. The verification password is set by being written to a setting area allocated to the NVM 23.
[0031] The pairing application (for card) is a program for sharing control data with the controller 3 in response to a PAIRING command (an example of a second command) from the controller 3. The control data is data used when controlling the control target O, and is shared by being written to a storage area allocated in the NVM 23. Examples of the control data include a control execution message for the controller 3 and a public key (first public key) included in a key pair unique to the controller 3. The control execution message describes a command to execute control. Furthermore, when the control target O and the controller 3 are installed in a vehicle, the control execution message may include data indicating a seat position in the vehicle. The key pair unique to the controller 3 (hereinafter referred to as the "key pair of the controller 3") includes a private key (first private key) and a public key (first public key). The control data may be key generation data used to generate a common key between the IC card 2 and the controller 3. The object control application (for card) is a program for causing the controller 3 to control the control target O using the shared control data.
[0032] Furthermore, the NVM 23 or the ROM 24 stores in advance a CID, which is an identifier unique to the IC card 2. The NVM 23 or the ROM 24 also stores a secure session establishment key for establishing a secure session with the user terminal 1, the controller 3, or the management server 4. Furthermore, the NVM 23 or the ROM 24 stores a key pair unique to the IC card 2, which includes a private key (second private key) and a public key (second public key) (hereinafter referred to as the "key pair of the IC card 2").
[0033] The CPU 25 (an example of a computer) executes a process for establishing a secure session with the user terminal 1, the controller 3, or the management server 4 in accordance with the session establishment application (for cards). In this process, for example, mutual authentication is performed using the INITALIZE UPDATE command, the EXTERNAL AUTHENTICATE command, and a secure session establishment key, etc., which are specified in the international standard ISO / IEC 7816-3, and a session key is generated.
[0034] Furthermore, the CPU 25 executes a process of setting a verification password in the IC card 2 in response to a SET PASSWORD command from the user terminal 1 in accordance with the password setting application (for card). In this process, the CPU 25 functions as the first receiving means and the first writing means, etc., of the present invention. As an example of this process, the CPU 25 receives a SET PASSWORD command including a verification password from the user terminal 1 (or receives it from the management server 4 via the user terminal 1) in a secure session established with the user terminal 1 (or the management server 4 via the user terminal 1), and sets the verification password by writing the verification password included in the SET PASSWORD command into a setting area of the NVM 23 in the IC card 2 in response to the received SET PASSWORD command.
[0035] Fig. 4(A) is an example showing the contents of a SET PASSWORD command. As shown in Fig. 4(A), the Data in the body of the SET PASSWORD command contains a verification password to be set in the IC card 2. The SET PASSWORD command is a command APDU not specified in ISO / IEC 7816-3 (i.e., a command APDU devised in this embodiment). The response (APDU) to the SET PASSWORD command contains SW1 and SW2, which indicate successful completion or an error.
[0036] Furthermore, the CPU 25 executes a process of sharing control data with the controller 3 in accordance with a PAIRING command (an example of a second command) from the controller 3 in accordance with the pairing application (for card). In this process, the CPU 25 functions as the second receiving means, the verifying means, the second writing means, the second transmitting means, and the like of the present invention. As an example of this process, the CPU 25 receives a PAIRING command from the controller 3, including a verification password (an example of second verification data) and control data, and in accordance with the received PAIRING command, verifies the verification password set by the password setting application (for card) with the verification password included in the PAIRING command. If the verification is successful (for example, if both verification passwords match), the CPU 25 writes the control data included in the PAIRING command to a storage area of the NVM 23 in the IC card 2, thereby sharing the control data with the controller 3. This completes pairing between the IC card 2 and the controller 3. If the verification fails a predetermined number of times, the CPU 25 starts over by inputting the verification password again.
[0037] FIG. 4B shows an example of the contents of the PAIRING command. As shown in FIG. 4B, the Data in the body of the PAIRING command contains data for pairing in TLV format. The data for pairing includes a verification password and control data. The data for pairing may further include the KID of the controller 3. In this case, the KID is associated with the control data and written to the storage area of the NVM 23. Like the SET PASSWORD command, the PAIRING command is a command APDU not specified in ISO / IEC 7816-3. The response (APDU) to the PAIRING command includes SW1 and SW2, which indicate successful completion or an error. If the response includes SW1 and SW2, which indicate successful completion, the response may further include the CID of the IC card 2. If the control data included in the PAIRING command is the public key of the controller 3, the DATA in the response to the PAIRING command (including SW1 and SW2, which indicate successful completion) includes the public key of the IC card 2.
[0038] Furthermore, the CPU 25 executes a process for causing the controller 3 to control the control object O in accordance with the object control application (for card). In this process, the CPU 25 functions as a transmitting means, a first transmitting means, a third transmitting means, a third receiving means, a fourth receiving means, a verifying means, a generating means, etc., of the present invention. As an example of this process, the CPU 25 transmits a control execution message (an example of control data) written in a storage area of the NVM 23 to the controller 3 in order to cause the controller 3 to control the control object O. When the control object O and the controller 3 are mounted in a vehicle, the control execution message may include data indicating a seat position in the vehicle. This allows the controller 3 to control the control object O (e.g., a door, a light, an audio speaker) corresponding to the seat position.
[0039] As another example of a process for causing the controller 3 to control the controlled object O, the CPU 25 receives from the controller 3 an EXTERNAL AUTHENTICATE command (an example of a third command) including signature data (first signature data) generated by the controller 3 using the private key of the controller 3 (i.e., included in Data in the body portion). Such signature data (first signature data) is generated, for example, by performing a cryptographic operation using the private key of the controller 3 as input data for a random number generated by the controller 3. Note that the EXTERNAL AUTHENTICATE command may include the random number generated by the controller 3 in addition to the signature data.
[0040] Then, in response to the received EXTERNAL AUTHENTICATE command, the CPU 25 verifies the signature data included in the EXTERNAL AUTHENTICATE command (i.e., performs signature verification) using the public key of the controller 3 (a public key written in a storage area of the NVM 23, which is an example of control data). If the signature verification is successful, the CPU 25 transmits a response indicating that the signature verification is successful (i.e., including SW1 and SW2 indicating normal completion) to the controller 3. Here, a successful signature verification corresponds to, for example, a case where a random number is successfully extracted from the signature data (e.g., extracted by a decryption operation) or a case where the random number extracted from the signature data matches the random number included in the EXTERNAL AUTHENTICATE command.
[0041] After transmitting a response indicating that signature verification was successful, if an INTERNAL AUTHENTICATE command (an example of a fourth command) is received from the controller 3, the CPU 25 generates signature data (second signature data) using the private key of the IC card 2 in response to the received INTERNAL AUTHENTICATE command. Here, the INTERNAL AUTHENTICATE command is a command APDU defined in ISO / IEC 7816-3, and, for example, Data in the body portion thereof contains a random number generated by the controller 3. The signature data (second signature data) is generated, for example, by performing a cryptographic operation using the private key of the IC card 2 with the random number included in the INTERNAL AUTHENTICATE command as input data. Then, the CPU 25 transmits a response to the controller 3 that includes the generated signature data and SW1 and SW2 indicating successful completion.
[0042] [2-3. Configuration and Function of Controller 3] FIG. 5 is a diagram showing an example of a schematic configuration of the controller 3. As shown in FIG. 5, the controller 3 is configured to include a communication unit 31, a short-range wireless communication unit 32, a memory unit 33, an operation / display unit 34, a control unit 35, and an I / F (interface) unit 36 with the controlled object O. The communication unit 31 is connected to the communication network NW and controls communication with the management server 4. The short-range wireless communication unit 32 controls the short-range wireless communication with the IC card 2. The memory unit 33 is configured from a non-volatile memory or the like and stores various programs such as an OS and applications. When the controlled object O and the controller 3 are mounted in a vehicle, the memory unit 33 may be configured from, for example, an embedded secure element (eSE).
[0043] Such applications include a session establishment application (for controller), a password setting application (for controller), a pairing application (for controller), a pairing information management application (for controller), and an object control application (for controller). The session establishment application (for controller) is a program for establishing a secure session with the IC card 2. The password setting application (for controller) is a program for causing the controller 3 to set a verification password (an example of second verification data). The pairing application (for controller) is a program for sharing control data with the IC card 2. The pairing information management application (for controller) is a program for managing (registering and deleting) pairing information that associates the CID of the IC card 2 with the KID of the controller 3. The object control application (for controller) is a program for controlling the controlled object O.
[0044] The storage unit 33 also stores in advance a KID, which is an identifier unique to the controller 3. The storage unit 33 also stores a secure session establishment key for establishing a secure session with the IC card 2 or the management server 4. The storage unit 33 also stores a key pair of the controller 3's private key (first private key) and public key (first public key). Here, the public key of the controller 3 is an example of control data, as described above. The storage unit 33 may also store control execution messages for the controller 3 as control data. The operation and display unit 34 includes, for example, an input function for receiving input directly from the user and a display (for example, a touch panel) for displaying various information. The verification password is input to the control unit 35 via the operation and display unit 34.
[0045] The control unit 35 is configured to include a CPU, RAM, ROM, etc. When the controlled object O and the controller 3 are mounted on a vehicle, the control unit 35 is configured from an ECU (Electronic Control Unit). The control unit 35 executes a process of establishing a secure session with the IC card 2 in accordance with a session establishment application (for controller). The control unit 35 also executes a process of inputting and setting a verification password from the user via the operation / display unit 34 in accordance with a password setting application (for controller). The verification password is set, for example, by being written to a setting area in the storage unit 33.
[0046] Furthermore, the control unit 35 executes a process of sharing control data with the IC card 2 in accordance with the pairing application (for controller). In this process, the control unit 35 transmits a PAIRING command including a verification password (i.e., a password set by the password setting application (for controller)) and control data to the IC card 2 in a secure session established with the IC card 2. The control unit 35 then receives a response to the PAIRING command from the IC card 2. If the response includes the CID of the IC card 2, the control unit 35 writes the CID into a storage area of the storage unit 33. If the response includes a public key of the IC card 2, the control unit 35 writes the public key into a storage area of the storage unit 33.
[0047] When the control data is shared in this manner, the control unit 35, in accordance with the pairing information management application (for controller), sends a registration request including pairing information that associates the KID of the controller 3 with the CID of the IC card 2 to the management server 4, thereby registering the pairing information in the management server 4. Note that the pairing information may include the control data. Furthermore, in response to an operation input (instruction) from the user, the control unit 35, in accordance with the pairing information management application (for controller), sends a deletion request including pairing information that associates the KID of the controller 3 with the CID of the IC card 2 to the management server 4, thereby causing the management server 4 to delete the pairing information.
[0048] The control unit 35 also executes processing to control the control object O in accordance with the object control application (for controller). In this processing, the control unit 35 outputs a control command to the control object O in response to a control execution message from the IC card 2. This controls the control object O. Alternatively, the control unit 35 generates signature data using the private key of the controller 3 and a random number, and transmits an EXTERNAL AUTHENTICATE command including the generated signature data to the IC card 2. Then, when the control unit 35 receives a response to the EXTERNAL AUTHENTICATE command from the IC card 2, the response including SW1 and SW2 indicating successful completion, the control unit 35 transmits an INTERNAL AUTHENTICATE command including a random number to the IC card 2. Then, when the control unit 35 receives a response to the INTERNAL AUTHENTICATE command from the IC card 2, the response including the signature data and SW1 and SW2 indicating successful completion, the control unit 35 verifies the signature data included in the response. If the signature verification is successful, the control unit 35 outputs a control command to the control object O. This controls the control object O.
[0049] [2-4. Configuration and Functions of Management Server 4] FIG. 6 is a diagram illustrating an example of a schematic configuration of the management server 4. As illustrated in FIG. 6, the management server 4 includes a communication unit 41, a storage unit 42, a control unit 43, and the like. The communication unit 41 is connected to the communication network NW and controls communication between the management server 4 and the user terminal 1 or the controller 3. The storage unit 42 is configured with a hard disk drive (HDD) or a solid state drive (SSD), and stores various programs such as an OS and applications. These applications include a session establishment application (for server), a password setting application (for server), and a pairing information management application (for server). The session establishment application (for server) is a program for establishing a secure session with the IC card 2 via the user terminal 1. The password setting application (for server) is a program for setting a verification password in the IC card 2 via the user terminal 1. The pairing information management application (for server) is a program for managing (registering and deleting) pairing information that associates the CID of the IC card 2 with the KID of the controller 3.
[0050] The storage unit 42 also stores a secure session establishment key for establishing a secure session with the IC card 2. The storage unit 42 is further provided with a user information database 421. The user information database 421 registers (stores) user account information and information about the user terminal 1 (for example, a telephone number, an email address, an AID that is an identifier unique to a notification app installed on the user terminal 1, etc.) in association with each user. As described above, when a verification password is set in a user's IC card 2, the CID of the user's IC card 2 is registered in association with the user's account information. Furthermore, when control data is shared between the user's IC card 2 and the controller 3, the KID of the controller 3 is registered in association with the CID of the IC card 2 (that is, pairing information is registered).
[0051] The control unit 43 is configured to include a CPU, RAM, ROM, etc. The control unit 43 performs login processing in response to a login request (including account information) from a user terminal 1 that has accessed the management server 4, and identifies the user based on the account information (i.e., the user logs in). Then, when the control unit 43 receives a setting request including a verification password from the user terminal 1 of the logged-in user, the control unit 43 executes processing to establish a secure session with the IC card 2 via the user terminal 1 of the user in accordance with the session establishment application (for server), and executes processing to set the verification password in the IC card 2 via the user terminal 1 of the user in accordance with the password setting application (for server).
[0052] Furthermore, the control unit 43 executes a process of managing (registering and deleting) pairing information in accordance with a pairing information management application (for server). In this process, the control unit 43 functions as a fifth receiving means, a registering means, a sixth receiving means, a deleting means, an identifying means, a deletion control means, and the like of the present invention. As an example of this process, when the control unit 43 receives a registration request including the pairing information from the controller 3 that has accessed the management server 4 after control data has been written to the storage area of the NVM 23 of the IC card 2 in response to the PAIRING command, the control unit 43 associates the pairing information with the account information of the user of the user terminal 1 (i.e., the account information associated with the CID of the IC card 2) and registers the pairing information in the user information database 421 based on the pairing information included in the received registration request.
[0053] Then, when the control unit 43 receives a deletion request including the pairing information from the controller 3 that has accessed the management server 4, it deletes the pairing information from the user information database 421 based on the pairing information included in the received deletion request. Furthermore, the control unit 43 identifies the "UID of the user of the user terminal 1" associated with the pairing information included in the received deletion request, and deletes the control data (control data associated with the KID of the controller 3) from the storage area of the NVM 23 by sending a control data deletion command to the IC card 2 via the user terminal 1 of the user corresponding to the identified UID (for example, by push distribution to a notification app running on the user terminal 1). This causes the pairing between the IC card 2 and the controller 3 to be released.
[0054] [2. Operation of communication system S] Next, the operation of the communication system S according to this embodiment will be described.
[0055] [2-1. Setting a password for verification on IC card 2] First, the operation of setting a verification password to the IC card 2 will be described with reference to Fig. 7. Fig. 7 is a sequence diagram showing an example of the operation of setting a verification password to the IC card 2. Note that the operation of setting a verification password to the IC card 2 is premised on the assumption that the user terminal 1 accesses (is network connected to) the management server 4 via the communication network NW and the user has logged in by issuing a login request.
[0056] When the user holds the IC card 2 over the user terminal 1, short-range wireless communication is initiated between the user terminal 1 and the IC card 2. After an initial response is transmitted from the IC card 2 to the user terminal 1, the IC card 2 selects a session establishment application (for card) in response to a SELECT command from the user terminal 1. The user terminal 1 then transmits a setting request including the verification password entered by the user to the management server 4 (step S1). Next, upon receiving the setting request from the user terminal 1, the management server 4 initiates processing to establish a secure session with the IC card 2 in accordance with the session establishment application (for server), and transmits an INITALIZE UPDATE command including a random number RS generated by the control unit 43 to the user terminal 1 (step S2). Next, upon receiving the INITALIZE UPDATE command from the management server 4, the user terminal 1 performs protocol conversion of the INITALIZE UPDATE command and transmits it to the IC card 2 (step S3).
[0057] Next, upon receiving the INITALIZE UPDATE command from the user terminal 1, the IC card 2 starts processing to establish a secure session with the management server 4 in accordance with the session establishment application (for card), and generates a random number RC, a session key, and ciphertext CC (step S4). Here, the session key is generated, for example, based on the random number RS included in the INITALIZE UPDATE command, the random number RC generated in step S4, and the secure session establishment key. The ciphertext CC is generated, for example, by encrypting data obtained by concatenating the random number RS included in the INITALIZE UPDATE command and the random number RC generated in step S4 in accordance with the first rule (IC card 2-side rule) using the session key generated in step S4. Next, the IC card 2 transmits a response to the user terminal 1 that includes the random number RC and ciphertext CC generated in step S4, as well as SW1 and SW2 indicating successful completion (step S5). Next, upon receiving the response from the IC card 2, the user terminal 1 converts the protocol of the response and transmits it to the management server 4 (step S6).
[0058] Next, upon receiving a response from the user terminal 1, the management server 4 generates a session key and ciphertext CC (based on the above-mentioned first rule) in the same manner as the IC card 2 (step S7). Next, the management server 4 verifies the authenticity of the IC card 2 by comparing the ciphertext CC included in the response with the ciphertext CC generated in step S7 (step S8). Next, if the management server 4 successfully verifies the authenticity of the IC card 2, it generates ciphertext CS by encrypting data obtained by concatenating the random numbers RS and RC according to the second rule (the rule on the management server 4 side) with the session key generated in step S7 (step S9). Next, the management server 4 transmits an EXTERNAL AUTHENTICATE command including the ciphertext CS generated in step S9 to the user terminal 1 (step S10). Next, upon receiving the EXTERNAL AUTHENTICATE command from the management server 4, the user terminal 1 converts the protocol of the EXTERNAL AUTHENTICATE command and transmits it to the IC card 2 (step S11).
[0059] Next, upon receiving the EXTERNAL AUTHENTICATE command from the user terminal 1, the IC card 2 generates a ciphertext CS (based on the above-mentioned second rule) using the same method as the management server 4 (step S12). Next, the IC card 2 verifies the legitimacy of the management server 4 by comparing the ciphertext CS included in the EXTERNAL AUTHENTICATE command with the ciphertext CS generated in step S12 (step S13). Next, if the IC card 2 successfully verifies the legitimacy of the management server 4, it sends a response including SW1 and SW2 indicating normal completion to the user terminal 1 (step S14) and selects the password setting application (for card). Next, upon receiving the response from the IC card 2, the user terminal 1 performs protocol conversion of the response and sends it to the management server 4 (step S15).
[0060] Next, when the management server 4 receives a response from the user terminal 1, mutual authentication between the IC card 2 and the management server 4 is successful, and a secure session is initiated. When the secure session between the IC card 2 and the management server 4 is initiated, the management server 4 sends a SET PASSWORD command including the verification password included in the setting request to the user terminal 1 in accordance with the password setting application (for server) (step S16). Next, when the user terminal 1 receives the SET PASSWORD command from the management server 4, it performs protocol conversion of the SET PASSWORD command and transmits it to the IC card 2 (step S17).
[0061] Next, when the IC card 2 receives the SET PASSWORD command from the user terminal 1, it writes the verification password included in the SET PASSWORD command to the setting area of NVM 23 in the IC card 2 in accordance with the password setting application (for card) (step S18). This sets the verification password. Next, the IC card 2 transmits a response including SW1 and SW2 indicating successful completion to the user terminal 1 (step S19). Next, when the user terminal 1 receives the response from the IC card 2, it converts the protocol of the response and transmits it to the management server 4 (step S20).
[0062] As described above, the verification password is set in the IC card 2. Note that in the above verification password setting operation, an example has been described in which the verification password is set in the IC card 2 by the SET PASSWORD command from the management server 4 in a secure session between the management server 4 and the IC card 2 via the user terminal 1. However, as another example, the verification password may be set in the IC card 2 by the SET PASSWORD command from the user terminal 1 in a secure session between the user terminal 1 and the IC card 2.
[0063] [2-2. Pairing operation between IC card 2 and controller 3] Next, with reference to Fig. 8, the pairing operation between the IC card 2 and the controller 3 will be described taking as an example a case where the control data is the public key of the controller 3. Fig. 8 is a sequence diagram showing an example of the pairing operation between the IC card 2 and the controller 3. Note that, as a prerequisite for the pairing operation between the IC card 2 and the controller 3, it is assumed that a verification password input by the user is set in the controller 3.
[0064] When the user brings the IC card 2 close to the controller 3, short-range wireless communication is initiated between the IC card 2 and the controller 3, and after the IC card 2 transmits an initial response to the controller 3, the IC card 2 selects a pairing application (for card) in response to a SELECT command from the controller 3. Then, in accordance with the pairing application (for controller), the controller 3 transmits a PAIRING command to the IC card 2, including the verification password input to the controller 3, the public key of the controller 3, and the KID of the controller 3 (step S21).
[0065] Here, the PAIRING command may be sent to the IC card 2 in a secure session that is started by performing a process for establishing a secure session between the IC card 2 and the controller 3. Note that the process for establishing a secure session between the IC card 2 and the controller 3 is performed using an INITALIZE UPDATE command and an EXTERNAL AUTHENTICATE command, as shown in FIG. 7 , similar to the process for establishing a secure session between the IC card 2 and the management server 4.
[0066] Next, upon receiving the PAIRING command from the controller 3, the IC card 2 compares the verification password set in step S18 with the verification password included in the PAIRING command in accordance with the pairing application (for card) (step S22). If the comparison is successful (for example, if both verification passwords match), the IC card 2 associates the public key of the controller 3 included in the PAIRING command with the KID of the controller 3 and writes them to the storage area of the NVM 23 (step S23). This causes the public key of the controller 3 to be shared with the controller 3. Once pairing is completed in this way, the verification password is no longer necessary, so it may be deleted from the setting area of the NVM 23 in the IC card 2. Note that if the pairing is canceled, the operation of setting the verification password in the IC card 2 is started again. Next, the IC card 2 transmits a response to the controller 3, including the public key of the IC card 2, the CID of the IC card 2, and SW1 and SW2 indicating successful completion (step S24).
[0067] Next, when the control device 3 receives a response from the IC card 2, the control device 3 associates the public key of the IC card 2 included in the response with the CID of the IC card 2 and writes the associated public key to the storage area of the storage unit 33 (step S25). This allows the public key to be shared between the control device 3 and the IC card 2. Next, the control device 3 accesses the management server 4 and, in accordance with the pairing information management application (for controller), transmits a registration request including pairing information that associates the KID of the control device 3 with the CID of the IC card 2 to the management server 4 (step S26). Next, when the management server 4 receives the registration request from the controller 3, the management server 4 associates the pairing information included in the received registration request with the account information of the user of the user terminal 1 and registers it in the user information database 421 (step S27) in accordance with the pairing information management application (for server).
[0068] [2-3. Control operation of controlled object O] Next, referring to Fig. 9, a control operation of the controlled object O will be described taking as an example a case where the control data is the public key of the controller 3. Fig. 9 is a sequence diagram showing an example of the control operation of the controlled object O. When a user brings the IC card 2 close to the controller 3, short-range wireless communication with the controller 3 is initiated. After an initial response is transmitted from the IC card 2 to the controller 3, the IC card 2 selects the object control application (for card) by a SELECT command from the controller 3. Then, the controller 3 generates a random number in accordance with the object control application (for controller) (step S31), generates signature data using the generated random number and the private key of the controller 3 (step S32), and transmits an EXTERNAL AUTHENTICATE command including the generated random number and signature data to the IC card 2 (step S33).
[0069] Next, upon receiving the EXTERNAL AUTHENTICATE command from the controller 3, the IC card 2 verifies the signature data included in the EXTERNAL AUTHENTICATE command (signature verification) using the random number included in the EXTERNAL AUTHENTICATE command and the public key of the controller 3 in accordance with the object control application (for card) (step S34). Next, if the signature verification is successful, the IC card 2 transmits a response including SW1 and SW2 indicating normal completion to the controller 3 (step S35). Next, upon receiving the response from the IC card 2, the controller 3 generates a random number (step S36) and transmits an INTERNAL AUTHENTICATE command including the generated random number to the IC card 2 (step S37).
[0070] Next, upon receiving the INTERNAL AUTHENTICATE command from the controller 3, the IC card 2 generates signature data using the random number included in the INTERNAL AUTHENTICATE command and the private key of the IC card 2 (step S38), and transmits a response including the generated signature data and SW1 and SW2 indicating successful completion to the controller 3 (step S39). Next, upon receiving the response from the IC card 2, the controller 3 verifies the signature data included in the response (signature verification) (step S40). Next, if the signature verification is successful, the controller 3 outputs a control command to the controlled object O (step S41). This controls the controlled object O.
[0071] [2-4. Control data deletion operation] Next, the control data deletion operation will be described with reference to Fig. 10. Fig. 10 is a sequence diagram showing an example of the control data deletion operation. In response to an operation input (instruction) from the user, the controller 3 transmits a deletion request including pairing information that associates the KID of the controller 3 with the CID of the IC card 2 to the management server 4 in accordance with the pairing information management application (for controller) (step S51).
[0072] Next, upon receiving the deletion request from the controller 3, the management server 4 deletes the pairing information from the user information database 421 based on the pairing information included in the received deletion request (step S52). For example, the management server 4 searches the user information database 421 for account information associated with the CID included in the received pairing information, and deletes from the user information database 421 the pairing information associated with the searched account information.
[0073] Next, the management server 4 identifies the "UID of the user of the user terminal 1" associated with the pairing information included in the received deletion request, and transmits a control data deletion command (including the KID of the controller 3) to the user terminal 1 by push distribution to a notification app running on the user terminal 1 of the user corresponding to the identified UID (step S53). The deletion command may be transmitted from the management server 4 to the user terminal 1 as an SMS (Short Message Service) message based on the user's telephone number. Alternatively, the deletion command may be received by the user terminal 1 by being transmitted by email from the management server 4 to the user's email address.
[0074] Next, upon receiving the delete command from the management server 4, the user terminal 1 converts the protocol of the delete command and transmits it to the IC card 2 (step S54). Next, upon receiving the delete command from the user terminal 1, the IC card 2 deletes the control data associated with the KID included in the delete command from the storage area of the NVM 23 (step S55). This allows the control data stored in the IC card 2 to be quickly deleted in conjunction with the deletion of the pairing information registered in the management server 4 (in other words, the cancellation of the pairing), thereby enabling the pairing between the IC card 2 and the controller 3 to be quickly canceled.
[0075] As described above, according to the above embodiment, the IC card 2 receives a SET PASSWORD command including a verification password from the user terminal 1, and in response to the SET PASSWORD command, writes the verification password included in the SET PASSWORD command to a setting area of NVM 23 in the IC card 2. Thereafter, the IC card 2 receives a PAIRING command including the verification password and control data from the controller 3, and in response to the PAIRING command, compares the written verification password with the verification password included in the PAIRING command. If the comparison is successful, the IC card 2 writes the control data included in the PAIRING command to a storage area of NVM 23 in the IC card 2. Therefore, even if the IC card 2 does not have the input function and the connection function that the user terminal 1 and the like have, the process of sharing control data with the controller 3 of the controlled object O can be easily performed. Furthermore, the IC card 2 can easily cancel pairing with the controller 3 using the user terminal 1 and the management server 4. [Explanation of symbols]
[0076] 1. User terminal 2. IC card 3 Controller 4 Management Server 11 Communications Department 12 Near Field Wireless Communication Department 13 Storage section 14 Operation / display section 15 Control Unit 21 I / O circuit 22 RAM 23 NVM 24 ROM 25 CPU 26 Coprocessors 31 Communications Department 32 Near Field Wireless Communication Department 33 Storage section 34 Operation / display section 35 Control Unit 41 Communications Department 42 Storage section 43 Control Unit S Communication System
Claims
1. An IC card capable of communicating between a user terminal used by a user and a controller that controls a controlled object used by the user, a first receiving means for receiving a first command including first verification data from the user terminal; a first writing means for writing first verification data included in the first command received by the first receiving means into a setting area of a nonvolatile memory in the IC card in response to the first command; a second receiving means for receiving from the controller a second command including second verification data and control data used when controlling the controlled object; a verification means for verifying, in response to the second command received by the second receiving means, the first verification data written in the setting area with the second verification data included in the second command; a second writing means for writing the control data included in the second command to a storage area of the nonvolatile memory when the verification is successful; An IC card comprising:
2. 2. The IC card according to claim 1, further comprising a transmitting means for transmitting the control data written in the storage area to the controller in order to have the controller control the controlled object.
3. the controller stores a key pair unique to the controller, the key pair including a first private key and a first public key; the control data is the first public key, a third receiving means for receiving, from the controller, a third command including first signature data generated by the controller using the first private key; a verification means for verifying signature data included in the third command by using the first public key written in the storage area in response to the third command received by the third reception means; a first transmitting means for transmitting a response indicating that the verification has been successful to the controller when the verification has been successful; 2. The IC card according to claim 1, further comprising:
4. the IC card stores a key pair unique to the IC card, the key pair including a second private key and a second public key; a second transmitting means for transmitting a response including the second public key to the controller if the verification is successful; a fourth receiving means for receiving a fourth command from the controller after transmitting a response indicating that the verification has been successful; generating means for generating second signature data using the second private key in response to the fourth command received by the fourth receiving means; a third transmission means for transmitting a response including the second signature data generated by the generation means to the controller; 4. The IC card according to claim 3, further comprising:
5. the first verification data is a verification password input by the user to the user terminal, 5. The IC card according to claim 1, wherein the second verification data is a verification password input by the user to the controller.
6. 1. A management server in a communication system including a user terminal used by a user, a controller that controls a controlled object used by the user, and an IC card that can communicate between the user terminal and the controller, which associates an identifier unique to the user with an identifier unique to the IC card and registers them in a database, the IC card receives first matching data from the user terminal and writes it into a non-volatile memory, and when it receives second matching data and control data used in controlling the controlled object from the controller, it matches the first matching data with the second matching data, and when the matching is successful, it writes the control data into the non-volatile memory; The management server a fifth receiving means for receiving, after the control data is written to the nonvolatile memory, from the controller, a registration request including pairing information that associates an identifier unique to the IC card with an identifier unique to the controller; a registration means for registering the pairing information in the database in association with an identifier unique to the user, based on the pairing information included in the registration request received by the fifth receiving means; A management server comprising:
7. a sixth receiving means for receiving a deletion request including the pairing information from the controller; a deletion means for deleting the pairing information from the database based on the pairing information included in the deletion request received by the sixth receiving means; 7. The management server according to claim 6, further comprising:
8. a sixth receiving means for receiving a deletion request including the pairing information from the controller; a specifying means for specifying an identifier unique to the user of the user terminal, which is associated with the pairing information included in the deletion request received by the sixth receiving means; a deletion control means for transmitting a deletion command for the control data to the IC card via a user terminal of a user corresponding to the identifier identified by the identification means, thereby deleting the control data from the storage area of the nonvolatile memory; 7. The management server according to claim 6, further comprising:
9. An electronic information storage medium capable of communicating between a user terminal used by a user and a controller that controls a control target used by the user, a first receiving means for receiving a first command including first verification data from the user terminal; a first writing means for writing first verification data included in the first command received by the first receiving means into a setting area of a nonvolatile memory in the electronic information storage medium; a second receiving means for receiving from the controller a second command including second verification data and control data used when controlling the controlled object; a verification means for verifying, in response to the second command received by the second receiving means, the first verification data written in the setting area with the second verification data included in the second command; a second writing means for writing the control data included in the second command to a storage area of the nonvolatile memory when the verification is successful; An electronic information storage medium comprising:
10. A data processing method executed by an IC card capable of communicating between a user terminal used by a user and a controller that controls a controlled object used by the user, comprising: receiving a first command including first verification data from the user terminal; writing first verification data included in the received first command into a setting area of a nonvolatile memory in the IC card in response to the received first command; receiving, from the controller, a second command including second verification data and control data used when controlling the controlled object; a step of comparing the first verification data written in the setting area with the second verification data included in the second command in response to the received second command; If the verification is successful, writing the control data included in the second command to a storage area of the nonvolatile memory; A data processing method comprising:
11. A computer included in an IC card capable of communicating between a user terminal used by a user and a controller used by the user to control a controlled object, receiving a first command including first verification data from the user terminal; writing first verification data included in the received first command into a setting area of a nonvolatile memory in the IC card in response to the received first command; receiving, from the controller, a second command including second verification data and control data used when controlling the controlled object; a step of comparing the first verification data written in the setting area with the second verification data included in the second command in response to the received second command; If the verification is successful, writing the control data included in the second command to a storage area of the nonvolatile memory; A program characterized by executing the following.
Citation Information
Patent Citations
Electronic Lock System
JP6762552B2