Valuable medium processing device, valuable medium processing system, and processing method
The secure boot function and multi-layered authentication process in valuable medium processing devices enhance security by preventing unauthorized software execution and ensuring secure communication, addressing vulnerabilities in existing systems.
Patent Information
- Application Number
- JP2024054511
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-10-10
Smart Images

Figure 2025152565000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a valuable medium processing device, a valuable medium processing system, and a processing method. [Background technology]
[0002] In valuable medium processing devices that handle valuable media such as banknotes and securities, it is important to improve the security of the software that executes various processes. One example of a technology for improving the security of software that runs in valuable medium processing devices is disclosed in Patent Document 1. Patent Document 1 discloses a valuable medium processing device that performs security management using security management information stored in a highly tamper-resistant security chip when the software is started up and when the software is updated. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent Publication No. 2021-99693 Summary of the Invention [Problem to be solved by the invention]
[0004] In facilities (such as banks) that use valuable medium processing devices for business purposes, multiple devices, each having software that executes operations, may be connected to each other so that they can communicate with each other. Also, multiple devices, each having software that executes different operations, may work together to perform a series of processes. Furthermore, a single device may have multiple units, each having software that executes different operations, and these units may work together to perform a series of processes.
[0005] In a system or device that executes various processes using multiple pieces of software, it is important to ensure the security of each piece of software.
[0006] The present disclosure aims to improve security in a valuable medium processing device or system that executes various processes using multiple pieces of software. [Means for solving the problem]
[0007] A valuable medium processing device according to one embodiment of the present disclosure is a valuable medium processing device that has a secure boot function and performs first media processing related to valuable media, and includes: a safe having a storage unit for storing valuable media located inside; and a board located inside the safe that is equipped with a processor that performs an execution prohibition process that sends a prohibition command to an execution device that performs second media processing related to valuable media, prohibiting the execution of the second media processing, and that performs a prohibition release process that releases the prohibition command when the legitimacy of the execution device is recognized.
[0008] A valuable medium processing system according to one embodiment of the present disclosure comprises a valuable medium processing device having a secure boot function and performing first media processing related to valuable media, an execution device performing second media processing related to valuable media, and a verification device, wherein the valuable medium processing device, after starting up using the secure boot function, performs a first authentication process to authenticate the verification device, and if the first authentication process is successful, the verification device starts a second authentication process to authenticate the execution device.
[0009] A valuable medium processing method according to one embodiment of the present disclosure is a processing method for a valuable medium processing system that includes a valuable medium processing device having a secure boot function and performing first media processing related to valuable media, an execution device that performs second media processing related to valuable media, and a verification device, wherein the valuable medium processing device, after starting up using the secure boot function, performs a first authentication process to authenticate the verification device, and if the first authentication process is successful, the verification device starts a second authentication process to authenticate the execution device. [Effects of the Invention]
[0010] According to the present disclosure, it is possible to improve security in a valuable medium processing device or system that executes various processes using multiple pieces of software. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a block diagram showing an example of the configuration of a valuable medium processing system according to a first embodiment. [Figure 2] FIG. 1 is a diagram showing an example of the configuration of a valuable medium processing device according to a first embodiment. [Figure 3] A block diagram showing an example of the functional configuration of a valuable medium processing device. [Figure 4] Schematic diagram showing a circuit board included in a valuable medium processing device [Figure 5] Block diagram showing the hardware configuration of the main board [Figure 6] FIG. 1 is a block diagram illustrating an example of a functional configuration of a verification device. [Figure 7] FIG. 1 is a block diagram illustrating an example of the functional configuration of an execution device. [Figure 8] Flowchart for explaining an example of operation of a valuable medium processing system [Figure 9] FIG. 10 is a diagram showing an example of whether or not the function of each device is prohibited depending on the type of abnormality in the operation prohibition process. [Figure 10] FIG. 10 is a block diagram showing an example of the functional configuration of a valuable medium processing device according to a second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, each embodiment of the present disclosure will be described in detail with reference to the drawings. However, more detailed explanation than necessary, for example, detailed explanation of already well-known matters or redundant explanation of substantially the same configuration, may be omitted.
[0013] First Embodiment [System Configuration] In the first embodiment, a valuable medium processing system 100 will be described as an example of a valuable medium processing system according to the present disclosure.
[0014] Fig. 1 is a block diagram showing an example of the configuration of a valuable medium processing system 100 according to the first embodiment. The valuable medium processing system 100 includes a valuable medium processing device 10, a verification device 20, and an execution device 30. In the example shown in Fig. 1, the valuable medium processing system 100 includes three execution devices 30.
[0015] The valuable medium processing device 10 and the verification device 20, the valuable medium processing device 10 and each execution device 30, and the verification device 20 and each execution device 30 are communicatively connected to one another. The valuable medium processing device 10 and each execution device 30 may be indirectly connected via the verification device 20. The valuable medium processing device 10 is also connected to an external public network (e.g., the Internet) via the verification device 20. In other words, the valuable medium processing device 10 is not connected to a public network without going through the verification device 20.
[0016] In this disclosure, a valuable medium refers to any medium that has value. Examples of valuable medium include banknotes, coins, and various securities. Examples of securities include checks, gift certificates, and stock certificates.
[0017] The valuable medium processing device 10 is a device that performs various processes related to valuable media. In the present embodiment, as an example, the valuable medium processing device 10 performs processes related to banknotes. In the following description, processes related to valuable media may be referred to as media processing. Media processing by the valuable medium processing device 10 is an example of the first media processing of the present disclosure.
[0018] The valuable medium processing device 10 may be, for example, a change dispenser, etc. The valuable medium processing device 10 may be installed in various stores such as retail stores, train stations, banks, or public facilities.
[0019] Examples of medium processing performed by the valuable medium processing device 10 include a deposit process for depositing banknotes into the valuable medium processing device 10 and a withdrawal process for withdrawing banknotes from the valuable medium processing device 10.
[0020] The valuable medium processing device 10 has a secure boot function, which prevents unauthorized software from being executed at startup (boot) and ensures safe startup.
[0021] After starting up in a secure state using the secure boot function, the valuable medium processing device 10 executes a first authentication process to authenticate the verification device 20. The first authentication process is a process to verify the legitimacy of the target verification device 20. The first authentication process may be a mutual authentication process in which the valuable medium processing device 10 and the verification device 20 authenticate each other. Furthermore, after starting up in a secure state using the secure boot function, the valuable medium processing device 10 executes an execution prohibition process to prohibit the execution of processing on the execution device 30. The execution prohibition process continues until authentication of the verification device 20 is successful in the first authentication process and until authentication of the execution device is completed in the second authentication process described below.
[0022] The verification device 20 is a device that executes a second authentication process to authenticate the execution device 30. The second authentication process is a process that verifies the legitimacy of the target execution device 30. The verification device 20 may be an example of a verification unit of the present disclosure. The verification device 20 may be installed, for example, in a system management room that is easily accessible to a system administrator of the valuable medium processing system 100. The verification device 20 may be a valuable medium processing device that executes media processing related to valuable media. The media processing executed by the verification device 20 is an example of the second media processing of the present disclosure.
[0023] After the valuable medium processing device 10 executes the first authentication process, the verification device 20 performs a second authentication process on the execution device 30 if the authentication is successful. The second authentication process may be a mutual authentication process in which the verification device 20 and the execution device 30 authenticate each other. The second authentication process may also include verification of vulnerabilities of software executed on the execution device 30. More specifically, the second authentication process may include verification of the version of the software executed on the execution device 30. The second authentication process may also include verification of software vulnerabilities based on vulnerability information obtained during verification from a vulnerability information database external to the system via a public network. As the second authentication process, the verification device 20 may perform both or only one of verification of the version of the software executed on the execution device 30 and verification of software vulnerabilities based on vulnerability information obtained during verification from the vulnerability information database via a public network.
[0024] The execution device 30 may be a valuable medium processing device that executes medium processing related to valuable media. The medium processing by the execution device 30 is an example of a second medium processing of the present disclosure. The execution device 30 may be an example of an execution unit of the present disclosure. Examples of medium processing executed by the execution device 30 include a deposit process for depositing banknotes into the execution device 30, a withdrawal process for withdrawing banknotes from the execution device 30, a withdrawal instruction process for instructing the valuable medium processing device 10 to withdraw banknotes, a display process for displaying information related to valuable media, and an input process for accepting operational input related to valuable media.
[0025] Specific examples of the execution device 30 include other valuable medium processing devices independent of the valuable medium processing device 10, a management device that instructs the valuable medium processing device 10 to execute media processing, or peripheral devices including a card reader that reads and writes various information about valuable media to a card-type memory, a display device that displays various information about valuable media, a printer device that prints various information about valuable media, or an operating device that accepts user operations.
[0026] The execution device 30 may be installed in various stores or public facilities, for example, similar to the valuable medium processing device 10.
[0027] A plurality of execution devices 30 may be provided in the valuable medium processing system 100. The plurality of execution devices 30 may be different devices and may each perform a different type of medium processing. Each of the plurality of execution devices 30 may perform medium processing related to a different type of medium from the valuable medium processing device 10. As a specific example, the valuable medium processing device 10 may perform medium processing related to banknotes, one of the execution devices 30 may perform medium processing related to coins, and another execution device 30 may perform medium processing related to checks.
[0028] The valuable medium processing device 10, the verification device 20, and the execution device 30 may be independent devices. Alternatively, the valuable medium processing device 10, the verification device 20, and the execution device 30 may be integrated into one unit to form a system such as an ATM (Automatic Teller Machine).
[0029] As described above, the execution prohibition process of the valuable medium processing device 10 prohibits the execution of medium processing on the execution device 30 from immediately after the execution device 30 starts up until the second authentication process by the verification device 20 is completed. While the execution prohibition process does not limit the types of medium processing prohibited, withdrawal processing is particularly strongly prohibited. This prevents the execution device 30 from performing medium processing using valuable media without confirming that it has started up in a secure state, thereby preventing the fraudulent withdrawal of valuable media.
[0030] [Valuable media processing device 10] 2 is a diagram showing an example of the configuration of the valuable medium processing device 10. In the following description, the side where the first door 123 (described later) is provided may be referred to as the front, and the side opposite the side where the first door 123 is provided may be referred to as the rear.
[0031] 2, the valuable medium processing device 10 performs medium processing on loose banknotes. The valuable medium processing device 10 has an upper processing unit 11 and a lower safe 12. The safe 12 has a first safe unit 121 and a second safe unit 122.
[0032] The processing section 11 has an upper housing 111. Inside the upper housing 111, a deposit section 112, a withdrawal section 113, a recognition section 114, and part of the transport path are arranged.
[0033] The interior of safe 12 is divided into two areas. Inside safe 12, there are storage section 13, part of the transport path, and main board 155, which will be described later. Safe 12 protects storage section 13 and main board 155 at a security level equal to or higher than a predetermined level. The security level of safe 12 is higher than that of upper housing 111.
[0034] The safe 12 has a first door 123 and a second door 124. The first door 123 is provided with an electronic lock 125. The electronic lock 125 is normally locked. When the system administrator unlocks the electronic lock 125, the first door 123 becomes openable. With the first door 123 open, the storage section 13 of the first safe section 121 is pulled out to the front of the valuable medium processing device 10.
[0035] The second door 124 is provided with an electronic lock 126. The electronic lock 126 is normally locked. When the system administrator unlocks the electronic lock 126, the second door 124 becomes openable. With the second door 124 open, the storage section 13 of the second safe section 122 is pulled out to the front of the valuable medium processing device 10.
[0036] A system administrator with special authority can unlock electronic lock 125 and electronic lock 126. The authority required to unlock electronic lock 125 and the authority required to unlock electronic lock 126 do not have to be the same.
[0037] The deposit unit 112 is a section into which banknotes to be deposited are inserted, for example, during a deposit process in which the banknotes are deposited into a storage unit described below. The deposit unit 112 holds multiple banknotes in a stacked state. The deposit unit 112 has a mechanism for taking in the banknotes one by one into the device.
[0038] The dispensing unit 113 is a unit that holds banknotes to be dispensed, for example, during a dispensing process in which banknotes are dispensed from a storage unit described below. The dispensing unit 113 holds multiple banknotes in a stacked state. A user of the valuable medium processing device 10 can manually remove banknotes from the dispensing unit 113. Note that the user of the valuable medium processing device 10 includes not only the system administrator but also general users such as customers of the store where the valuable medium processing device 10 is installed.
[0039] The recognition unit 114 is provided on a looped conveyance path 141, which will be described later. The recognition unit 114 detects banknotes conveyed along the looped conveyance path 141. The recognition unit 114 acquires an image of each detected banknote. The recognition unit 114 uses the acquired images to identify at least whether the banknote is genuine, counterfeit, denomination, and fitness. The recognition unit 114 acquires the serial number of the banknote.
[0040] The storage unit 13 stores banknotes. The storage unit 13 stores banknotes, for example, in a stack format (where banknotes are stacked) or a tape format (where banknotes are wound up together with tape).
[0041] The multiple storage units 13 are each provided inside the first safe unit 121 or the second safe unit 122 of the safe 12. The multiple storage units 13 may include storage cassettes that are detachable from the valuable medium processing device 10. At least one of the storage units 13 provided in the first safe unit 121 is supported by a support unit 127. The support unit 127 has, for example, a rail structure, and can move forward while supporting the storage unit 13 when the first door 123 is open. This allows the storage unit 13 of the first safe unit 121 to be pulled out toward the front of the valuable medium processing device 10.
[0042] A sensor that detects the passage of banknotes is attached to the banknote entrance / exit of storage unit 13. Based on the detection signal of the sensor, control unit 15, which will be described later, counts the number of banknotes that have entered storage unit 13 and the number of banknotes that have left storage unit 13. Based on the counted number, control unit 15 manages the number of banknotes stored in storage unit 13.
[0043] The transport unit 14 transports banknotes within the valuable medium processing device 10. The transport unit 14 has a transport path. Although not shown, the transport path is composed of a combination of numerous rollers, multiple belts, motors that drive these, and multiple guides. The transport unit 14 transports banknotes one by one along the transport path, for example, with the long edge of the banknotes facing forward, leaving a gap between each banknote. The transport unit 14 may also transport banknotes with the short edge facing forward.
[0044] The transport unit 14 has a loop transport path 141. The loop transport path 141 is provided inside the upper housing 111. The transport unit 14 transports banknotes along the loop transport path 141 in the clockwise and counterclockwise directions in FIG.
[0045] The deposit unit 112 is connected to the loop conveyance path 141 via a connection path 142. The withdrawal unit 113 is connected to the loop conveyance path 141 via a connection path 143.
[0046] Each storage unit 13 is connected to the loop conveying path 141 via a connecting path 144. Each connecting path 144 extends in the vertical direction so as to straddle the processing unit 11 and the first safe unit 121. A portion of the connecting path 144 extends in the vertical direction so as to straddle the processing unit 11, the first safe unit 121, and the second safe unit 122. The conveying unit 14 conveys banknotes from the loop conveying path 141 to each storage unit 13 via the connecting path 144. The conveying unit 14 conveys banknotes from each storage unit 13 to the loop conveying path 141 via the connecting path 144.
[0047] The upper housing 111 is provided with an escrow unit 16. The escrow unit 16 temporarily stores banknotes. The escrow unit 16 can be used for a variety of purposes. The escrow unit 16 is disposed at a front position in the upper housing 111. The escrow unit 16 is connected to the loop conveying path 141 via a connection path 145.
[0048] An external safe storage unit 40 can be attached to the valuable medium processing device 10. The external safe storage unit 40 can be removed from the valuable medium processing device 10. The external safe storage unit 40 is a removable storage unit. The external safe storage unit 40 is connected to the loop conveying path 141 via a connecting path 146.
[0049] The valuable medium processing device 10 has a user interface (UI) unit. The UI unit includes an operation unit (keyboard, trackball, touch panel, etc.). A user can give various instructions to the valuable medium processing device 10 by operating the operation unit.
[0050] The valuable medium processing device 10 is equipped with a control unit 15. Figure 3 is a block diagram showing an example of the functional configuration of the valuable medium processing device 10. The control unit 15 is connected to the deposit unit 112, the withdrawal unit 113, the recognition unit 114, the storage unit 13, the transport unit 14, and the temporary holding unit 16. When an external safe storage unit 40 is attached to the valuable medium processing device 10, the external safe storage unit 40 may be connected to the control unit 15.
[0051] For example, when a user instructs the execution of various media processes through the UI unit, the control unit 15 outputs a signal to at least one of the deposit unit 112, withdrawal unit 113, recognition unit 114, storage unit 13, transport unit 14, temporary holding unit 16, and external safe storage unit 40 to execute the process corresponding to the instruction.
[0052] (Hardware configuration of control unit 15) The control unit 15 is implemented by multiple processors that execute various software programs. In the valuable medium processing device 10, these processors are implemented on five separate boards. Figure 4 is a schematic diagram showing the boards included in the valuable medium processing device 10.
[0053] 4, the valuable medium processing device 10 includes an identification board 151, an upper board 152, a lower board 153, a storage section board 154, and a main board 155. The main board 155 may be an example of a board of the present disclosure.
[0054] The identification board 151 and the upper board 152 are provided in the upper housing 111 .
[0055] The lower board 153, the storage unit board 154, and the main board 155 are provided in the safe 12. More specifically, the lower board 153 and the main board 155 are provided in the first safe unit 121. In other words, the main board 155 is installed in a location where it is necessary to unlock the electronic lock 125 in order to access the main board 155. The storage unit board 154 is provided in each of the storage units 13.
[0056] Each board is equipped with a storage device, a processor, and a communication interface. The storage device is composed of semiconductor memory such as RAM (Random Access Memory), ROM (Read Only Memory), eMMC (embedded Multi Media Card), and SSD (Solid State Drive). Various data and software are stored in the storage device. The processor reads and executes various software from the storage device.
[0057] The communication interface performs communication based on a predetermined communication standard such as USB (Universal Serial Bus) or RS-422.
[0058] In the valuable medium processing device 10, the main board 155 performs the security management function in the valuable medium processing device 10. The main board 155 has a distinctive hardware configuration in order to realize the security management function.
[0059] (Hardware configuration of main board 155) 5 is a block diagram showing a schematic diagram of the hardware configuration of the main board 155. The main board 155 includes a processor 170, a storage device 171, a communication interface 172, and a security chip 180.
[0060] The processor 170 executes software in the storage device 171, similar to processors (microcomputers) on other boards. Code executable by the processor 170 itself (hereinafter referred to as internal code) is embedded in the processor 170. The processor 170 is configured so that the internal code cannot be changed. In other words, a third party cannot tamper with the internal code. The processor 170 executes the internal code when the processor 170 is started up.
[0061] The processor 170 is provided with a memory area 173 that holds predetermined information (digital data). The memory area 173 is configured so that once data is written, the contents cannot be changed. It is impossible to tamper with the information in the memory area 173.
[0062] The manufacturer of the valuable medium processing device 10 writes information to the memory area 173 before the valuable medium processing device 10 is shipped (for example, when the valuable medium processing device 10 is manufactured). The information written to the memory area 173 and how that information is used will be described later.
[0063] The security chip 180 is a tamper-resistant semiconductor device. Tamper resistance refers to the property that data recorded inside is difficult to analyze, read, or alter from the outside. A security chip (TPM: Trusted Platform Module) that complies with security specifications defined by the TCG (Trusted Computing Group) can be used as the security chip 180. The security chip 180 is provided with a storage device 181 as a first storage unit that stores predetermined information (digital data).
[0064] The security chip 180 is connected to the processor 170 via the bus 156. In order for the processor 170 to access (write or read) the security chip 180, a predetermined authentication code is required.
[0065] The security chip 180 has a function of storing multiple encryption keys. The security chip 180 also has a function of calculating hash values. The storage device 181 serving as the first storage unit may store data for authenticating software in the storage device 171. The data for authenticating the software is, for example, a hash value of the software.
[0066] The storage device 171 has the same configuration as the storage devices provided on other boards. The storage device 171 may be configured with multiple types of devices (e.g., eMMC and ROM). In this embodiment, the storage device 171 on the main board 155 includes an eMMC. The storage device 171 stores basic software and application software.
[0067] The communication interface 172 has the same configuration as the communication interfaces provided on the other boards.
[0068] (Functional configuration of control unit 15) In the valuable medium processing device 10, the processors on each board execute various software programs, thereby realizing various functions of the control unit 15.
[0069] The recognition board 151 controls the recognition unit 114 and outputs the recognition result by the processor executing predetermined software. For example, the recognition board 151 recognizes the authenticity, denomination, and fitness of a banknote based on an image of the banknote. The recognition board 151 is connected to the upper board 152 via a communication interface. The recognition board 151 outputs the recognition result to the upper board 152 via the communication interface.
[0070] The upper substrate 152 controls the operations of the deposit unit 112, the withdrawal unit 113, the transport unit 14, the temporary holding unit 16, etc., by the processor executing predetermined software. For example, the upper substrate 152 controls the drive mechanisms (motors) provided in the transport unit 14, etc. The upper substrate 152 also receives instructions from the user via the UI unit.
[0071] A storage unit board 154 is provided for each storage unit 13. The storage device of each storage unit board 154 stores the ID of the corresponding storage unit 13 and a door opening / closing log. These storage devices may store at least one of the type and number of banknotes stored.
[0072] The storage section board 154 is connected to the lower board 153 via a communication interface. In response to a request from the lower board 153, the storage section board 154 transmits the ID and door opening / closing log information to the lower board 153 via the communication interface.
[0073] The processor of the lower board 153 executes predetermined software to control each storage unit 13 and the transport unit 14. The lower board 153 collects IDs and log data of the storage units 13.
[0074] The lower substrate 153 is connected to the upper substrate 152 via a communication interface. When controlling the transport unit 14, the lower substrate 153 sends a predetermined signal (command) to the upper substrate 152 via the communication interface.
[0075] The main board 155 is responsible for starting up the valuable medium processing device 10, communicating with the outside world of the valuable medium processing device 10, and managing various software programs by having the processor execute predetermined software. The storage device 171 of the main board 155 is equipped with basic software (so-called OS (Operating System)).
[0076] The main board 155 uses startup data stored in the tamper-resistant security chip 180 to implement a secure boot function that starts the operating system of the valuable medium processing device 10 in a secure state. The startup data is, for example, a hash value of the operating system and is used as an authentication value for verifying the authenticity of the operating system. The startup data may also include a value that counts the number of authorized accesses to the security chip 180. Specifically, when a system administrator turns on the power button or other function of the valuable medium processing device 10, the main board 155 executes a startup process using the secure boot function. Once startup is complete, the main board 155 becomes able to execute various subsequent processes in the valuable medium processing device 10.
[0077] In the valuable medium processing device 10, the main board 155 is located inside the first safe 121, so a third party cannot access the main board 155. This prevents a third party from rewriting the startup data required to execute the secure boot function, nor from performing any operations on the processor 170 that executes the secure boot function. The main board 155 starts up the basic software of the valuable medium processing device 10 by the secure boot function using the startup data stored in the storage device 181 of the tamper-resistant security chip 180, so the valuable medium processing device 10 can be started up in a secure state.
[0078] The main board 155 is connected to the lower board 153 via a communication interface 172. Log data, update files, and the like are transmitted and received between the main board 155 and the lower board 153.
[0079] The main board 155 is connected to the identification board 151 via the communication interface 172. The main board 155 transmits identification data to the identification board 151 and receives banknote image data from the identification board 151. The identification data is data for identifying the authenticity, denomination, and fitness of a banknote. The banknote image data is image data of a banknote acquired by the identification board 151.
[0080] The main board 155 is connected to the verification device 20 and the execution device 30 via the communication interface 172. The main board 155 is connected to a public network such as the Internet via the verification device 20. In other words, the main board 155 cannot communicate with the public network without going through the verification device 20.
[0081] After starting up using the secure boot function, the main board 155 executes an execution prohibition process for prohibiting the started execution device 30 from executing media processing.
[0082] After starting up using the secure boot function, the main board 155 executes a first authentication process to authenticate the verification device 20. As the first authentication process, mutual authentication between the valuable medium processing device 10 and the verification device 20 may be performed. One example of the first authentication process is TLS mutual authentication using the TLS (Transport Layer Security) protocol. TLS mutual authentication is an authentication method in which the valuable medium processing device 10 and the verification device 20 perform mutual authentication by comparing pre-issued digital certificates. The digital certificate may be stored in the storage device 181, which serves as the first storage unit.
[0083] As an example of the first authentication process, the verification device 20 may be authenticated by checking a hash value of predetermined data, for example, a predetermined image file. The hash value may be stored in the storage device 181 serving as the first storage unit.
[0084] After the first authentication process for the verification device 20 is completed and it is confirmed that the verification device 20 is in a secure state, the main board 155 executes a prohibition release process for the execution device 30 to release the prohibition on the execution of media processing when the second authentication process for the execution device 30 by the verification device 20 is completed.
[0085] [Verification Device 20] The verification device 20 is a computer such as a PC, a workstation, or a tablet terminal. Fig. 6 is a block diagram showing an example of the functional configuration of the verification device 20. The verification device 20 includes a communication unit 21, an authentication processing unit 22, and a verification unit 23. The verification device 20 may also be a valuable medium processing device equipped with a computer.
[0086] The communication unit 21 is a communication interface that transmits and receives various information between the valuable medium processing device 10, the execution device 30, and the public network.
[0087] On the condition that the verification device 20 has been authenticated by the first authentication process of the valuable medium processing device 10 activated by the secure boot function, the authentication processing unit 22 of the verification device 20 executes a second authentication process for the execution device 30. The second authentication process is performed using, for example, TLS mutual authentication, similar to the first authentication process. The authentication processing unit 22 may execute the second authentication process for each of the multiple execution devices 30. The authentication processing unit 22 transmits the authentication result for the execution device 30 to the valuable medium processing device 10 via the communication unit 21.
[0088] The second authentication process may include verification of vulnerabilities of the execution device 30 by the verification unit 23. The verification unit 23 may verify vulnerabilities of the execution device 30 following the authentication process by the authentication processing unit 22 or in parallel with the authentication process by the authentication processing unit 22.
[0089] Verification of vulnerabilities of execution device 30 by verification unit 23 is, for example, verification of vulnerabilities in software (e.g., firmware or applications) executed by execution device 30. Verification unit 23 obtains version information regarding the version of firmware executed by execution device 30, for example, via a public network such as the Internet, and determines that execution device 30 is not vulnerable if it is confirmed that the version of firmware currently being used by execution device 30 is newer than a predetermined version. Version information about the firmware executed by execution device 30 is made public by, for example, the manufacturer of execution device 30, and verification unit 23 can simply obtain this version information via the Internet.
[0090] Alternatively, verification unit 23 may verify the vulnerability of execution device 30 based on vulnerability information obtained from a vulnerability information database published on the Internet. Verification unit 23 compares SBOM (Software Bill of Materials) information of the software executed by execution device 30 with the vulnerability information obtained from the vulnerability information database, and verifies whether the software executed by execution device 30 has a vulnerability. An example of a vulnerability information database is the National Vulnerability Database (NVD) managed by NIST (National Institute of Standards and Technology).
[0091] The verification unit 23 may verify the vulnerability of each of the multiple execution devices 30. The verification unit 23 transmits an authentication result including the vulnerability verification result for each execution device 30 to the valuable medium processing device 10 via the communication unit 21. The verification unit 23 may also verify the vulnerability of the valuable medium processing device 10.
[0092] [Executing Device 30] The execution device 30 is a device that executes media processing related to valuable media. The execution device 30 may include, for example, a user interface used by a user of the valuable media processing system.
[0093] Examples of media processing include deposit or withdrawal processing of valuable media, writing or reading various information related to valuable media, displaying various information related to valuable media, and operation acceptance processing that accepts user operations and outputs control signals to control valuable media processing device 10, etc.
[0094] When the valuable medium processing system 100 includes multiple execution devices 30, the multiple execution devices 30 may each perform different types of medium processing. In particular, when the execution device 30 is a valuable medium processing device other than the valuable medium processing device 10, the execution device 30 may perform medium processing using a different type of valuable medium from that of the valuable medium processing device 10. As a specific example, when the valuable medium processing device 10 performs medium processing related to banknotes, the execution device 30 may perform medium processing related to coins.
[0095] 7 is a block diagram showing an example of the functional configuration of the execution device 30. The execution device 30 includes a communication unit 31 and a medium processing execution unit 32.
[0096] The communication unit 31 is a communication interface that transmits and receives various information between the valuable medium processing device 10 and the verification device 20. At least one of the execution devices 30 may be connected to a public network such as the Internet without going through the verification device 20.
[0097] The medium processing execution unit 32 executes a predetermined type of media processing for each execution device 30. After the execution device 30 is started, the medium processing execution unit 32 is prevented from executing media processing due to the execution prohibition process performed by the valuable medium processing device 10 until the second authentication process by the verification device 20 is completed and the execution device 30 is authenticated. The medium processing execution unit 32 will be able to execute media processing after the execution device 30 is authenticated by the verification device 20 and the prohibition release process by the valuable medium processing device 10 is executed. The medium processing execution unit 32 may not release the execution prohibition process until the above-mentioned vulnerability verification is completed in addition to the authentication by the second authentication process. For example, when the medium processing execution unit 32 receives an execution prohibition command from the valuable medium processing device 10 via the communication unit 31, it does not execute the subsequent media processing, but when it receives a prohibition release command from the valuable medium processing device 10, it executes the subsequent media processing.
[0098] [Example of operation of valuable medium processing system 100] Fig. 8 is a flowchart for explaining an example of the operation of the valuable medium processing system 100. At the start of Fig. 8, all devices included in the valuable medium processing system 100 are in a non-activated state (shut down state).
[0099] In step S1, each device included in the valuable medium processing system 100 is started up. Each device is started up, for example, by a system administrator pressing a power button on each device. As described above, the valuable medium processing device 10 is started up in a secure state using the secure boot function. Alternatively, each device may be started up automatically using a timer or the like. Alternatively, each device may be started up automatically when the valuable medium processing device 10 is started up.
[0100] If the valuable medium processing device 10 cannot be started up using the secure boot function in step S1, the process may end without performing any of the processes from step S2 onwards, or may proceed to the process of step S8.
[0101] In step S2, immediately after startup, the valuable medium processing device 10 executes an execution prohibition process to prohibit the execution devices 30 from processing media. Specifically, the valuable medium processing device 10 sends an execution prohibition command to each execution device 30 to prohibit media processing. This prevents the execution devices 30 from performing media processing.
[0102] In step S3, the valuable medium processing device 10 performs authentication processing (first authentication processing) of the verification device 20. The first authentication processing by the valuable medium processing device 10 to the verification device 20 is, as described above, authentication processing using, for example, TLS mutual authentication.
[0103] In step S4, if the first authentication process in step S3 is successful (step S4: Y), the process proceeds to step S5. If the first authentication process is not successful (step S4: N), the process proceeds to step S8.
[0104] In step S5, the verification device 20 performs authentication processing (second authentication processing) for the execution device 30. As described above, the second authentication processing for the execution device 30 may include verification of vulnerabilities of the execution device 30 by the verification device 20. The verification of vulnerabilities of the execution device 30 is verification of vulnerabilities of software executed by the execution device 30. The verification device 20 transmits the result of the authentication to the valuable medium processing device 10.
[0105] In step S6, if the second authentication process in step S5 is successful (step S6: Y), the process proceeds to step S7. If the second authentication process for any of the execution devices 30 is not successful (step S6: N), the process proceeds to step S8.
[0106] In step S7, the valuable medium processing device 10 executes a prohibition release process to release the execution prohibition process. Specifically, the valuable medium processing device 10 sends a prohibition release command to each execution device 30. This allows the execution device 30 to subsequently execute medium processing in response to user operations, etc.
[0107] In step S8, the valuable medium processing device 10 executes an abnormality response process. The abnormality response process includes at least one of a notification process and an operation prohibition process. An abnormality includes three types of events: the valuable medium processing device 10 cannot be started, the authentication process of the verification device 20 has failed, or the authentication process of one of the execution devices 30 has failed.
[0108] (Notification processing) The notification process is a process in which at least one of the devices included in the valuable medium processing system 100 that has been confirmed to be legitimate notifies the system administrator that an unauthorized device has been detected. "Inauthentic" means that the valuable medium processing device 10 cannot be started using the secure boot function, that the verification device 20 or the execution device 30 has been tampered with by a third party, that the verification device 20 or the execution device 30 may have been spoofed, or that the software running on the execution device 30 has a vulnerability (does not have sufficient security).
[0109] In the notification process, for example, the valuable medium processing device 10 notifies a system administrator using a UI unit or an external notification device. Alternatively, the verification device 20, which has been successfully authenticated by the valuable medium processing device 10, or the execution device 30, which has been successfully authenticated by the verification device 20, may issue the notification. The content of the notification may include, for example, information identifying the device in which the abnormality occurred (device ID, installation location, etc.), information about the time when the abnormality was detected (date and time, etc.), and information about the nature of the abnormality (such as the valuable medium processing device 10 cannot be started, authentication of the verification device 20 or the execution device 30 has failed, or a vulnerability in the execution device 30 has been confirmed). The notification may be issued by various methods, such as displaying the information on a display device, sounding an audio output device, or sending an email to a system administrator or an external management device.
[0110] For example, if authentication by the verification device 20 is successful but a vulnerability is found in a certain execution device 30, the verification device 20, which is easily accessible to the system administrator, may notify the system administrator. In this case, general users are not notified, so the system administrator can take action without general users knowing that a vulnerability has been found in the execution device 30.
[0111] (Operation prohibition processing) The operation prohibition process is a process for prohibiting each device included in the valuable medium processing system 100 from operating thereafter.
[0112] The valuable medium processing system 100 may prohibit the operation of all devices regardless of the type of abnormality detected. Alternatively, the valuable medium processing system 100 may determine which devices to prohibit from operating depending on the type of abnormality. Alternatively, the valuable medium processing system 100 may determine which devices to prohibit from operating based on the nature of the abnormality.
[0113] For example, if the valuable medium processing device 10 fails to start up, the valuable medium processing system 100 prohibits further operation of all devices.
[0114] If the valuable medium processing device 10 fails to authenticate the verification device 20 in the first authentication process, the valuable medium processing system 100 may prohibit further operation of all devices, or may prohibit operation of devices other than the valuable medium processing device 10, i.e., the verification device 20 and all execution devices 30.
[0115] If any of the execution devices 30 fails authentication in the second authentication process for the execution devices 30 by the verification device 20, the valuable medium processing system 100 may prohibit further operation of all devices, may prohibit operation of all execution devices 30, or may prohibit operation of only the execution device 30 that failed authentication.
[0116] When the verification device 20 verifies the vulnerability of the execution devices 30 and finds that one of the execution devices 30 is vulnerable, it may prohibit further operation of all devices, or it may prohibit operation of all execution devices 30, or it may prohibit operation of only the execution device 30 that is found to be vulnerable.
[0117] The valuable medium processing system 100 may determine to prohibit the execution of an operation or function of a device that requires higher security based on a combination of two factors: the type of device and the function of the device.
[0118] In terms of the type of device as an element, the device that directly handles valuable media requires higher security. In other words, the valuable medium processing device 10 and the execution device 30 as another valuable medium processing device are the devices that require the highest security. The execution device 30 as an operation reception device that can send withdrawal instructions to the valuable medium processing device 10 is the device that requires the next highest security. The verification device 20 and the execution device 30 that can connect to a public network are the devices that require the next highest security. The execution device 30 as an operation device that accepts input such as a card reader or PIN number, which may handle confidential information such as personal information, is the device that requires the next highest security. The execution device 30 as other peripheral devices (display device, printer, etc.) is a device that does not require relatively high security.
[0119] In terms of the device functions as elements, the more the valuable medium is discharged from the device, the higher the security required for the valuable medium processing device 10 and the execution device 30 as another valuable medium processing device. In other words, the withdrawal or recovery process by the valuable medium processing device 10 as a banknote processing device and the sending process of valuable media by the execution device 30 as another valuable medium processing device are the functions that require the highest security. The deposit or replenishment process by the valuable medium processing device 10 as a banknote processing device and the receiving process of valuable media by the execution device 30 as another valuable medium processing device are the functions that require the next highest security. The maintenance function, which includes data collection processes such as inspection and identification of received valuable media, is the function that requires the next highest security.
[0120] 9 shows an example of whether or not the functions of each device are prohibited depending on the type of abnormality during the operation prohibition process. In the example shown in FIG. 9, if startup using the secure boot function of the valuable medium processing device 10 fails, all functions that the valuable medium processing device 10 and the execution device 30 may have are prohibited. Furthermore, if authentication by the verification device 20 fails, operation is prohibited except for some functions that require relatively low security. Furthermore, when the verification device 20 verifies the vulnerability of the execution device 30, operation of more functions is permitted if the software version does not meet the conditions (for example, the version is old) or if the software matches vulnerability information obtained from the vulnerability information database.
[0121] In this way, when an abnormality is detected, higher security can be ensured for the entire system by prohibiting all or part of the functions of each device in valuable medium processing system 100. Furthermore, by changing the prohibited devices or functions based on the type of abnormality, flexible measures can be taken according to the required security level.
[0122] [Action, effect] As described above, the valuable medium processing system 100 according to the first embodiment of the present disclosure includes a valuable medium processing device 10 having a secure boot function and performing first media processing related to valuable media, an execution device 30 performing second media processing, and a verification device 20. After starting up using the secure boot function, the valuable medium processing device 10 performs a first authentication process to authenticate the verification device 20, and if the first authentication process is successful, the verification device 20 starts a second authentication process to authenticate the execution device.
[0123] If all devices included in the system had a secure boot function, the security of the entire system could be improved, but the installation costs of the system would increase. According to the valuable medium processing system 100 of the present disclosure, of the multiple devices included in the system, only the valuable medium processing device 10 has the secure boot function, so the increase in the cost of the entire system can be suppressed. In addition, in the valuable medium processing system 100 in which different software runs on each of the multiple devices included in the system, the secure boot function ensures security at the time of startup of the valuable medium processing device 10, the authentication process ensures security of the verification device 20, and the authentication process by the verification device 20 ensures security of the execution device 30, thereby significantly improving the security of the multiple software running in the system.
[0124] Furthermore, according to the valuable medium processing system 100 relating to the first embodiment of the present disclosure, when the execution device 30 is authenticated by the verification device 20 that has been successfully authenticated in the authentication process, a prohibition release process is executed to release the prohibition command.
[0125] With this configuration, the valuable medium processing device 10, which is started in a secure state, authenticates the verification device 20, and if the authentication is successful, the verification device 20 further authenticates the execution device 30, thereby significantly improving security compared to when multiple stages of security checks are not performed.
[0126] Furthermore, according to the valuable medium processing system 100 according to the first embodiment of the present disclosure, the main board 155 required to execute the secure boot function is provided inside the safe 12 in the valuable medium processing device 10. This configuration prevents a third party from accessing the main board 155, rewriting the basic software or startup data required to execute the secure boot function, or performing any operations on the processor 170 that executes the secure boot function. This ensures high security when the valuable medium processing device 10 is started up using the secure boot function.
[0127] <Second embodiment> In the first embodiment described above, a valuable medium processing system 100 including a valuable medium processing device 10, a verification device 20, and an execution device 30 as independent devices was described. In the second embodiment described below, a case where a verification unit and an execution unit are integrated into a valuable medium processing device will be described. The valuable medium processing device has a secure boot function. The execution unit executes media processing related to valuable media. The verification unit verifies the vulnerability of the execution unit.
[0128] 10 is a block diagram showing an example of the functional configuration of a valuable medium processing device 200 according to the second embodiment. The valuable medium processing device 200 includes a safe 210, a board 220 on which a processor 221 that executes various processes is mounted, a verification unit 230, and an execution unit 240.
[0129] 10, the valuable medium processing device 200 may further include a processing unit 250. In the example shown in FIG. 10, the components of the valuable medium processing device 200 other than the safe 210, the board 220, the processor 221, the verification unit, and the execution unit 240 are collectively shown as the processing unit 250.
[0130] A storage section for storing valuable media is arranged inside safe 210. A board 220 is provided inside safe 210. Safe 210 protects board 220 at a security level equal to or higher than a predetermined level.
[0131] The board 220 is equipped with a processor 221 that executes the secure boot function of the valuable medium processing device 200, the authentication process of the verification unit 230, the execution prohibition process of the execution unit 240, and the prohibition release process of the execution unit 240.
[0132] The verification unit 230 has a function of authenticating the execution unit 240 when authentication is successful in the authentication process of the verification unit 230 by the processor 221. The authentication of the execution unit 240 by the verification unit 230 is similar to the second authentication process of the execution device 30 by the verification device 20 in the first embodiment.
[0133] 10 shows only one execution unit 240, the valuable medium processing device 200 may have multiple execution units 240. The execution unit 240 has the function of executing various media processes. Furthermore, when the execution unit 240 receives an execution prohibition command associated with the execution prohibition process by the processor 221, it prohibits the execution of the media process. Furthermore, when the execution unit 240 receives an prohibition release command associated with the prohibition release process by the processor 221, it thereafter executes the media process based on user operations, etc.
[0134] The execution unit 240 may have functions as a UI unit of the valuable medium processing device 200, ie, functions to accept operations by users or system administrators, display various types of information, and the like.
[0135] The processing unit 250 is a unit that executes processes in the valuable medium processing device 200 other than the secure boot function, the authentication process of the verification unit 230, the execution prohibition process of the execution unit 240, and the prohibition release process of the execution unit 240. The processing unit 250 may include components other than the safe 12 and the main board 155 of the components of the valuable medium processing device 10 of the first embodiment.
[0136] For example, if the processing unit 250 has a function to execute media processing for banknotes among valuable media, the execution unit 240 may have a function to execute media processing for valuable media other than banknotes. For example, the valuable medium processing device 200 may have an execution unit 240 that has a function to execute media processing for coins and an execution unit 240 that executes media processing for checks.
[0137] In this way, even in a configuration in which a single valuable medium processing device 200 is equipped with a board 220, a verification unit 230, and an execution unit 240 installed inside a safe 210, the processor 221 mounted on the board 220 has the function of executing the secure boot function of the valuable medium processing device 200, the authentication processing of the verification unit 230, the execution prohibition processing of the execution unit 240, and the prohibition release processing of the execution unit 240, thereby significantly improving the security of multiple software programs running in the system. [Industrial Applicability]
[0138] The present disclosure is useful for improving security in valuable medium processing systems or valuable medium processing devices. [Explanation of symbols]
[0139] 100 Valuable media processing system 10 Valuable media processing equipment 11 Processing section 111 Upper housing 112 Deposit Department 113 Withdrawal Department 114 Identification unit 12 Safe 121 First Vault 122 Second Vault 123 Door 1 124 Door 2 125 Electronic Lock 126 Electronic Lock 127 Support part 13 Storage area 13 Each storage section 13 Storage area 14 Conveying section 141 Loop conveyor 142, 143, 144, 145, 146 Connecting roads 15 Control Unit 151 Identification board 152 Upper board 153 Lower board 154 Storage unit board 155 Main board 156 Bus 16 Temporary Holding Department 170 processors 171 Storage device 172 Communication Interface 173 Storage area (1st storage) 180 Security Chip 181 Storage device (second storage unit) 20 Verification Device 21 Communications Department 22 Authentication processing section 23 Verification Department 30 Execution Device 31 Communications Department 32 Media processing execution unit 200 Valuable media processing equipment 210 Safe 220 board 221 processor 230 Verification Unit 240 execution units 250 processing units
Claims
1. A valuable medium processing device that has a secure boot function and executes first medium processing on a valuable medium, a safe having a storage section for storing valuable media disposed therein; a circuit board located inside the safe, the circuit board including a processor that executes an execution prohibition process to send a prohibition command to an execution device that executes a second medium process related to a valuable medium, prohibiting the execution of the second medium process, and that executes a prohibition release process to release the prohibition command when the legitimacy of the execution device is confirmed; A valuable medium processing device comprising:
2. The processor further executes a first authentication process for authenticating a verification device, and verifies the legitimacy of the execution device based on a result of a second authentication process for the execution device, the second authentication process being executed by the verification device that has been successfully authenticated in the first authentication process. The valuable medium processing device according to claim 1 .
3. the authentication of the verification device in the first authentication process is performed using a digital certificate; The valuable medium processing device according to claim 2 .
4. authentication of the verification device in the first authentication process is performed by TLS (Transport Layer Security) mutual authentication; The valuable medium processing device according to claim 2 or 3.
5. the authentication of the verification device in the first authentication process is performed using a hash value of predetermined data; The valuable medium processing device according to any one of claims 2 to 4.
6. the processor executes a notification process to notify the user that an abnormality has occurred in the verification when the authenticity of the execution device is not recognized by the verification of the verification device that has succeeded in the first authentication process. The valuable medium processing device according to any one of claims 2 to 5.
7. the processor causes the verification device to execute at least one of the execution prohibition process and the prohibition release process; The valuable medium processing device according to any one of claims 2 to 6.
8. the board further includes a tamper-resistant first storage unit that stores boot data used to execute the secure boot function; The valuable medium processing device according to any one of claims 1 to 7.
9. a valuable medium processing device having a secure boot function and executing a first medium process related to a valuable medium; an execution device that executes a second medium process related to the valuable medium; A verification device; Equipped with the valuable medium processing device, after starting up using the secure boot function, executes a first authentication process to authenticate the verification device; If the first authentication process is successful, the verification device starts a second authentication process to authenticate the execution device. Valuable media processing system.
10. the valuable medium processing device executes an execution prohibition process to prohibit the execution device from executing the medium processing until the second authentication process by the verification device is completed. The valuable medium processing system according to claim 9.
11. the verification device performs, as the second authentication process, verification of vulnerabilities in the software executed on the execution device; 11. The valuable medium processing system according to claim 9 or 10.
12. the verification device verifies the version of the software as the verification of the vulnerability of the software; The valuable media processing system according to claim 11.
13. the verification device verifies the vulnerability of the software based on vulnerability information acquired via a public network; 13. The valuable medium processing system according to claim 11 or 12.
14. the valuable medium processing device is connected to the public network via the verification device; The valuable media processing system according to claim 13.
15. the second medium processing executed by the execution device is processing related to a valuable medium of a different type from that of the valuable medium processing device; The valuable medium processing system according to any one of claims 9 to 14.
16. the execution device includes a user interface used by a user of the valuable media processing system; The valuable medium processing system according to any one of claims 9 to 15.
17. the medium processing includes a process of withdrawing the valuable medium from the valuable medium processing device or the execution device; The valuable medium processing system according to any one of claims 9 to 16.
18. the verification device performs a third medium process on the valuable medium; The valuable medium processing system according to any one of claims 9 to 17.
19. A processing method for a valuable medium processing system including a valuable medium processing device having a secure boot function and performing a first medium process on a valuable medium, an execution device performing a second medium process on the valuable medium, and a verification device, comprising: the valuable medium processing device executes a first authentication process for authenticating the verification device after starting up using the secure boot function; If the first authentication process is successful, the verification device starts a second authentication process to authenticate the execution device. Processing method.
Citation Information
Patent Citations
Valuable medium processor
JP2021099693A