Method for verifying execution trail of protective storage processing section, program therefor and execution trail verification device for protective storage processing section

The method verifies execution trails of protected memory processing units through a blind signature process, ensuring security and anonymity in digital currency transactions by confirming legitimacy without direct access, addressing tampering concerns.

JP2025167171APending Publication Date: 2025-11-07SAKURA INFORMATION SYST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024071543
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-25
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing methods fail to safely guarantee that observer programs in protected memory processing units have not been tampered with and ensure the anonymity of transactions, particularly in digital currency systems.

Method used

A method involving a user terminal sending a first execution trail and public key to a trusted authority terminal for verification, followed by a blind signature process to authenticate a second execution trail with certification information, allowing a verifier terminal to confirm legitimacy without directly accessing the protected memory processing unit.

Benefits of technology

Ensures the security and anonymity of transactions by verifying the execution trail indirectly, preventing tampering and maintaining transaction privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025167171000001_ABST
    Figure 2025167171000001_ABST
Patent Text Reader

Abstract

To provide a method for verifying an execution trail of a protective storage processing section which is appropriate for utilization as a settlement processing method for digital currency and a system therefor, a program therefor and an execution trail verification device for a protective storage processing section.SOLUTION: When a verification of a first execution trail of an observer program transmitted from a user terminal 1 and installed in a protective storage processing section 2 is made successful, in a second execution trail including a blind signature which is performed on a public key transmitted from the user terminal 1 and certification information transmitted from the protective storage processing section 2 to the user terminal 1 and certifying that a private key corresponding to the public key is owned, the blind signature and the certification information are received by a reliable facility terminal 3 and it is confirmed that the blind signature and the certification information are authentic, thereby verifying that the second execution trail transmitted from the protective storage processing section 2 is authenticated.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a method for verifying the execution trail of a protected memory processing unit, a program for the method, and an execution trail verification device for a protected memory processing unit, and more particularly to a method for verifying the execution trail of a protected memory processing unit that is suitable for use, for example, in a digital currency payment processing method and system, a program for the method, and an execution trail verification device for a protected memory processing unit. [Background technology]

[0002] For example, an ideal digital currency (e-cash) system, especially a central bank digital currency (CBDC), needs to satisfy the properties of anonymity, unforgeability, and transparency to prevent criminal activities from exploiting anonymity. [Prior art documents] [Non-patent literature]

[0003] Research Trends in Tamper-Resistant Digital Currency Wallets: Aiming for Both Anonymity and Transparency (https: / / www.imes.boj.or.jp / research / abstracts / japanese / 22-J-09.html) Summary of the Invention [Problem to be solved by the invention]

[0004] There is a need for a method that can more safely guarantee that the observer program installed in the protected memory processing unit has not been tampered with, and that can more safely guarantee the results of its execution, while also better guaranteeing the anonymity of transactions. The present invention has been made in consideration of such problems, and its main purpose is to provide a method for verifying the execution trail of a protected memory processing unit, a program for the method, and an execution trail verification device for a protected memory processing unit, which can further guarantee security and ensure the anonymity of transactions. [Means for solving the problem]

[0005] In order to achieve the above-mentioned object, the method of verifying the execution trail of a protected memory processing unit of the present invention is characterized in that a user terminal sends a first execution trail and public key of an observer program installed in the protected memory processing unit of the user terminal to a trusted authority terminal, and when the trusted authority terminal successfully verifies the execution trail using the first execution trail, it blindly signs the public key and sends it to the user terminal, the user terminal sends the public key to the protected memory processing unit, and the protected memory processing unit sends to the user terminal a second execution trail including certification information proving that it possesses a private key corresponding to the public key, the user terminal sends the blind signature and the certification information to a verifier terminal, and the verifier terminal verifies that the blind signature and the certification information are authentic, thereby enabling the verifier terminal to verify that the second execution trail sent from the protected memory processing unit is legitimate.

[0006] In this invention, the trusted institution terminal may be provided in a bank, the verifier terminal may be provided in a store, and digital currency settlement may be processed by verifying the execution trail.

[0007] In addition, the program for verifying the execution trail of the protected memory processing unit of the present invention is characterized in that it causes a computer to execute a process in which a user terminal sends a first execution trail and public key of an observer program installed in the protected memory processing unit of the user terminal to a trusted authority terminal, and when the trusted authority terminal successfully verifies the execution trail using the first execution trail, it blindly signs the public key and sends it to the user terminal, the user terminal sends the public key to the protected memory processing unit, and the protected memory processing unit sends to the user terminal a second execution trail including proof information that proves that it possesses the private key corresponding to the public key, the user terminal sends the blind signature and the proof information to a verifier terminal, and the verifier terminal verifies that the blind signature and the proof information are authentic, thereby enabling the verifier terminal to verify that the second execution trail sent from the protected memory processing unit is legitimate.

[0008] In this invention, the trusted institution terminal may be provided in a bank, the verifier terminal may be provided in a store, and the program may process digital currency payments.

[0009] Furthermore, the execution trail verification device for the protected memory processing unit of the present invention is characterized in that, when a trusted authority terminal successfully verifies a first execution trail of an observer program sent from a user terminal and installed in the protected memory processing unit of the user terminal, it receives the blind signature and certification information of a second execution trail including a blind signature made on the public key sent from the user terminal and certification information sent from the protected memory processing unit to the user terminal and proving possession of the private key corresponding to the public key, and confirms that the blind signature and certification information are authentic, thereby being able to verify that the second execution trail sent from the protected memory processing unit is legitimate.

[0010] In this invention, the trusted institution terminal may be provided in a bank, the verifier terminal may be provided in a store, and the program may process digital currency payments.

[0011] Furthermore, the execution trail verification program of the protected memory processing unit of the present invention is characterized in that, when a trusted authority terminal successfully verifies a first execution trail of an observer program transmitted from a user terminal and installed in the protected memory processing unit of the user terminal, the program causes a computer to execute a process to receive a second execution trail including a blind signature made on the public key transmitted from the user terminal and certification information transmitted from the protected memory processing unit to the user terminal and proving possession of the private key corresponding to the public key, and to confirm that the blind signature and certification information are authentic, thereby verifying that the second execution trail transmitted from the protected memory processing unit is legitimate.

[0012] In this invention, the trusted institution terminal may be provided in a bank, the verifier terminal may be provided in a store, and the program may process digital currency payments. [Effects of the Invention]

[0013] According to the present invention, the verifier terminal can indirectly verify that the second execution trail is legitimate by verifying the blind signature by the trusted authority terminal and the certification information by the protected storage processor included therein, without directly verifying the second execution trail transmitted from the protected storage processor, thereby ensuring that the observer program installed in the protected storage processor has not been tampered with and can guarantee its execution results.Furthermore, since the verifier terminal does not directly verify the second execution trail transmitted from the protected storage processor, the anonymity of the transaction is guaranteed. [Brief explanation of the drawings]

[0014] [Figure 1] 1 is a basic flowchart illustrating a method for verifying execution trails of a protected storage processor according to the present invention; [Figure 2] 10 is a flowchart illustrating an embodiment of a method for verifying an execution trail of a protected storage processing unit according to the present invention when an account is opened. [Figure 3] 10 is a flowchart showing a coin withdrawal process in an embodiment of a method for verifying an execution trail of a protected storage processing unit according to the present invention. [Figure 4] 10 is a flowchart illustrating an embodiment of a method for verifying an execution trail of a protected storage processing unit according to the present invention at the time of payment at a store. DETAILED DESCRIPTION OF THE INVENTION

[0015] Hereinafter, an embodiment of the present invention will be described. 1 is a basic flowchart showing a method for verifying the execution trail of a protected storage processor according to the present invention. The method according to the present invention is executed by transmitting and receiving data between a user terminal 1, a protected storage processor 2 provided inside or outside the user terminal 1 in correspondence with the user terminal 1, a trusted authority terminal 3, and a verifier terminal 4, and processing the data among them.

[0016] As shown in Figure 1, the user terminal 1 sends the first execution trail and public key of the observer program installed in the protected memory processing unit 2 to the trusted authority terminal 3 (step S11), the trusted authority terminal 3 verifies the execution trail using the first execution trail (step S12), and if the verification is successful, blind signs the public key and sends it to the user terminal 1 (step S13), the user terminal 1 sends the public key to the protected memory processing unit 2 (step S14), the protected memory processing unit 2 sends the second execution trail to the user terminal 1, including proof information proving that it possesses the private key corresponding to the public key (step S15), the user terminal 1 sends the blind signature and the proof information to the verifier terminal 4 (step S16), the verifier terminal 4 verifies that the blind signature and the proof information are authentic (step S17), thereby enabling the verifier terminal 4 to verify that the second execution trail sent from the protected memory processing unit 2 is legitimate (step S18).

[0017] Here, it goes without saying that the user terminal 1, the protected memory processing unit 2, the trusted authority terminal 3, and the verifier terminal 4 each include a processor for executing various programs, a memory unit such as ROM, RAM, flash memory, or a hard disk (HDD), and a transceiver unit for transmitting and receiving data via wired or wireless connections. The user terminal 1 may be, for example, a mobile terminal such as a smartphone or a mobile phone. The protected memory processing unit 2 is a highly secure IC chip or its area provided within the user terminal 1 or externally in correspondence with the user terminal 1, and is typified by a secure element (a tamper-resistant device, i.e., a device whose internal information cannot be extracted using semiconductor testing techniques, etc.). The trusted authority terminal 3 and the verifier terminal 4 are information processing devices (computers) and may be mobile terminals such as smartphones and mobile phones.

[0018] In this invention, an execution trail (attestation) is data that guarantees that a program has been executed correctly without being tampered with, and is typically a set of data unique to each process, including the program's own hash value, the transaction processing results, and a device-wide electronic signature.

[0019] Furthermore, any known method can be used for the blind signature, and for example, a public key cryptosystem based on the Schnorr blind signature scheme can be used. 2 to 4, an embodiment in which the protected storage processing unit 2 is a secure element 2A, the trusted institution terminal 3 is a bank terminal 3A provided in a bank or an issuer of digital currency such as coins, and the verifier terminal 4 is a store terminal 4A provided in a store, and the present invention processes payments using digital currency (electronic money), will be described in detail. According to this embodiment, a system can be constructed in which coins issued by the bank terminal 3A and blind-signed can be returned to the bank, user, store, or bank in a blind-signed state in cooperation with the secure element 2A, i.e., anonymously. The verifier terminal 4 may be provided in a bank or the issuer.

[0020] 2 is a flowchart showing the process of opening an account in an embodiment of the method for verifying the execution trail of a protected storage processing unit according to the present invention. When opening an account, user terminal 1 transmits a first execution trail ATT1 of an observer program installed in secure element 2A and public key Ao to banking terminal 3A, and banking terminal 3 verifies the execution trail using first execution trail ATT1. If the verification is successful, banking terminal 3 blind-signs public key Ao and transmits it to user terminal 1.

[0021] The observer program is designed to individually monitor digital currency payments between user terminals, banks, and stores, and can enforce compliance with bank regulations. The observer program is a downloadable applet stored and executed in a secure element, published and distributed by the bank or a third party authorized by the bank through any method, such as open source. It has functions such as enforcing compliance with payment rules, such as legal regulations, and preventing double spending. It is preferable that the applet can be called from a wallet app installed on the user terminal, and that users who wish to use the applet can install it in their secure element at their discretion. Even if the observer program is open source, this is not a problem because the receiving side (bank terminal 3A, store terminal 4A) can verify which programs were executed by the secure element 2A using the execution trail. Furthermore, while the observer program is stored in the secure element associated with the user terminal 1, the user cannot alter the execution trail (tamper with the observer program) through the user terminal 1. Furthermore, the wallet app is preferably developed by the bank or a third party authorized by the bank.

[0022] Here, the digital currency may be a central bank digital currency (CBDC), and the present invention is suitable for use in processing payments in CBDC.

[0023] An example of the process when opening an account is as follows: First, as shown in Fig. 2, the secure element 2A generates a random number o1 as a private key, calculates a paired public key Ao, and outputs the public key Ao and the execution trail ATT1 (step S21). ATT1 is transmitted to the user terminal 1 (step S22).

[0024] Based on the public key Ao and the execution trail ATT1 received from the secure element 2A, the user terminal 1 generates a random number U as a user terminal ID, which is used as a private key, and generates a new public key gl based on this and the public key Ao (step S23).The user terminal 1 then transmits the public key gl, the public key Ao, and the execution trail ATT1 to the bank terminal 3A (step S24).The bank terminal 3A verifies whether the hash value portion of the execution trail is in the authorized list, and if so, performs subsequent processing; if not, it aborts (step S25).After that, the bank terminal 3A sets the random number w3 as a private key unique to the user, and issues a blind signature h based on this and the public key gl (step S26).The blind signature h is transmitted to the user terminal 1 (step S27).The user terminal 1 then stores the information Ao, gl, h, and U (step S28).

[0025] As described above, when user terminal 1 obtains information based on random number w3, which is a private key unique to the user, from bank terminal 3A, this means that an account is opened at the bank.

[0026] 3 is a flowchart showing the process of withdrawing coins in the embodiment of the method for verifying the execution trail of the protected storage processing unit according to the present invention. After the account is opened as described above, an example of the process of withdrawing coins is as follows.

[0027] 3, secure element 2A generates random number o2 as a private key, generates public key Bo based on the random number, outputs public key Bo and execution trail ATT2-1 (step S31), and transmits public key Bo and execution trail ATT2-1 to user terminal 1 (step S32). Banking terminal 3A also generates random numbers (v1, v2, v3) as a private key, generates blind signatures (V1, V2) that serve as coin information based on the random numbers (step S33), and transmits these blind signatures (V1, V2) to user terminal 1 (step S34). Private key o2 is set for each coin (for example, a unit of 100,000 yen or 1 million yen), and blind signatures (V1, V2) are also generated for each coin. This means that banking terminal 3A signs the coin and issues it to user terminal 1. The reason three random numbers (V1, V2, V3) are generated as the private key is to increase security (anonymity, impossibility of forgery).

[0028] User terminal 1 generates random numbers (r'1, z'1, z'2, z'3) as a private key and uses this value to calculate (V~1, V~2) from (V1, V2) (step S35). This calculation of (V~1, V~2) is blinding. User terminal 1 then generates random numbers (s, k, e, bl, b2) as a private key and uses this value to calculate blinded proof information (h~, gl~, m) that includes a value m calculated from user information Ao and coin information Bo (step S36). Next, user terminal 1 calculates hash value r~ using the information (m, h~, gl~, V1~, V2~) and a set of public parameters as input values ​​for a hash function, and calculates challenge r from hash value r~ and r' (step S37). At this point, banking terminal 3A cannot identify user terminal 1 from the coin information alone.

[0029] The user terminal 1 sends the challenge r to the bank terminal 3A (step S38), and the bank terminal 3A generates random numbers (v1, v2, v3) for the zero-knowledge proof for the secret information (wl, w2, w3), calculates the response (zl, z2, z3) from (r, wl, w2, w3) (step S39), and sends the response (zl, z2, z3) to the user terminal 1 (step S40).

[0030] The user terminal 1 verifies the received value using the verification formula, and if the verification fails, it aborts the process (step S41), but if not, it blinds the received response (zl, z2, z3) using the random numbers (k, s, z'1, z'2, z'3, r~) (step S42).

[0031] 4 is a flowchart showing a method for verifying the execution trail of a protected storage processing unit according to an embodiment of the present invention when making a payment at a store. When making a payment at a store, the user terminal 1 transmits the public key Bo to the secure element 2A, the secure element 2A transmits the second execution trail ATT2 (including proof information p1' proving possession of the secret key corresponding to the public key Bo and the execution trail ATT2-2) to the user terminal 1, the user terminal 1 transmits the blind signature and the proof information to the store terminal 4A, and the store terminal 4A verifies that the blind signature and the proof information are authentic, thereby enabling the store terminal 4A to verify that the second execution trail ATT2 transmitted from the secure element 2A is legitimate.

[0032] The user terminal 1 transmits the blind signatures corresponding to (g1~,m) and V1 and V2 to the shop terminal 4A (step S43), and the shop terminal 4A inputs the gl~,m, the shop ID, and the timestamp into a hash function to calculate the payment address pid (step S44), and transmits this payment address pid to the user terminal 1 (step S45). In other words, this means that the user specifies the coins they wish to pay.

[0033] Next, the user terminal 1 calculates pid0 by blinding the payment destination address pid with the random numbers (s, e) (step S46), and transmits this pid0 and the public key Bo to the secure element 2A (step S47). Since pid0 is a value calculated based on a random value for each coin that is known only to the user terminal 1, the observer program does not know about transactions with a specific store terminal 4A.

[0034] The secure element 2A searches the secure storage for the private key o2 that pairs with the public key Bo, and if it is not found, it aborts the processing (step S48). It also performs a determination process to determine whether the transaction of payment complies with the rules, and if there is a problem, it aborts the processing (step S49). If not, it extracts the private key o2 and deletes the private key o2 from the secure storage (step S50), calculates proof information pl' from the private keys o1 and o2, outputs it together with the execution trail ATT2-2 (step S51), and transmits the proof information pl' and the execution trail ATT2-2 to the user terminal 1 (step S52). Deleting the private key o2 from the secure storage means that the coins are paid out, which means that the private key o2 is generated from the list of unpaid coins.

[0035] The user terminal 1 verifies whether the proof information pl' includes information corresponding to the user ID and coins, and whether it corresponds to the correct payee, and if there is a problem, it aborts the process (step S53); if not, it calculates proof information (p1, p2) that conceals the proof information pl' using the random numbers (bl, b2, s) (step S54), and sends the proof information (pl, p2) to the shop terminal 4A (step S55).

[0036] The shop terminal 4A verifies that the bank's signature and the user terminal ID are correct using the verification formula (step S56).

[0037] As described above, according to this embodiment, the following advantageous effects are achieved. The store terminal 4A can indirectly verify that the second execution trail ATT2 sent from the secure element 2A is legitimate by verifying the blind signature by the bank terminal 3A and the certification information by the secure element 2A included therein, without directly verifying the second execution trail ATT2 sent from the secure element 2A, thereby ensuring that the observer program installed in the secure element 2A has not been tampered with and can guarantee the execution results.In addition, because the store terminal 4A does not directly verify the second execution trail sent from the secure element 2A, the anonymity of the digital currency payment transaction is guaranteed.

[0038] Without the intervention of information transmitted from the secure element 2A, i.e., without the involvement of the observer program, the user cannot open an account at the bank or make payments at the store, which makes it possible to force the bank to comply with legal regulations when implementing this payment method.

[0039] The observer installed in secure element 2A has private key o1, user terminal 1 has private key U, and bank terminal 3A has private key W3, and each terminal uses these private keys to send and receive data, ensuring the security of digital currency payments. Since neither the observer program nor bank terminal 3A knows at which store coins withdrawn from bank terminal 3A were spent, privacy is protected.

[0040] In this embodiment, if a double spend occurs, there will be two payment information pieces for one coin information. In this case, and only in this case, the equation consisting of two payment information pieces and one coin information piece can be solved, so the user ID U can be calculated, and the bank can identify the person who made the double spend.

[0041] Furthermore, when opening an account, withdrawing coins, or making a payment at a store, if the processing is not performed properly, the processing is suspended (steps S25, S40, S46, S47), which ensures the security of digital currency payments. In this embodiment, mathematical processing can be added at any point to make counterfeiting impossible.

[0042] Needless to say, the present invention is not limited to the above-described embodiment. [Industrial Applicability]

[0043] The present invention can be used, for example, as a digital currency payment processing method, its program and execution trail verification device for a protected memory processing unit, a secure personal authentication method, a token distribution method in a blockchain, its program and execution trail verification device for a protected memory processing unit, and so on. [Explanation of symbols]

[0044] 1. User terminal 2 Protected Memory Processor 2A Secure Element 3 Trusted Authority Terminal 3A Banking Terminal 4 Verifier terminal 4A Store terminal

Claims

1. The user terminal transmits a first execution trail and a public key of the observer program installed in the protected storage processor of the user terminal to the trust authority terminal; when the trusted authority terminal has successfully verified the execution trail using the first execution trail, it blind-signs the public key and transmits it to the user terminal; the user terminal transmits the public key to the protected storage processor; The protected storage processor transmits a second execution trail to the user terminal, the second execution trail including certification information that proves that the protected storage processor possesses a private key corresponding to the public key; The user terminal transmits the blind signature and the proof information to a verifier terminal; A method for verifying the execution trail of a protected memory processing unit, characterized in that the verifier terminal is able to verify that the second execution trail sent from the protected memory processing unit is legitimate by verifying that the blind signature and the certification information are authentic.

2. A method for verifying the execution trail of a protected memory processing unit as described in claim 1, characterized in that the trusted institution terminal is installed in a bank and processes digital currency payments by verifying the execution trail.

3. The user terminal transmits to the trusted authority terminal a first execution trail and a public key of the observer program installed in the protected storage processor of the user terminal; When the trusted authority terminal has successfully verified the execution trail using the first execution trail, it blind-signs the public key and transmits it to the user terminal; the user terminal transmits the public key to the protected storage processor; The protected storage processor transmits a second execution trail to the user terminal, the second execution trail including certification information that proves that the protected storage processor possesses a private key corresponding to the public key; The user terminal transmits the blind signature and the proof information to a verifier terminal; A program for verifying the execution trail of a protected memory processing unit, characterized in that the verifier terminal verifies that the blind signature and the certification information are authentic, thereby causing a computer to execute a process that enables the verifier terminal to verify that the second execution trail sent from the protected memory processing unit is legitimate.

4. 4. The program for verifying the execution trail of a protected memory processing unit according to claim 3, wherein the trusted institution terminal is provided in a bank, and the program processes digital currency settlements.

5. a blind signature performed by the trusted authority terminal on the public key transmitted from the user terminal when the trusted authority terminal has successfully verified the first execution trail of the observer program transmitted from the user terminal and installed in the protected storage processing unit of the user terminal; a second execution trail transmitted from the protected storage processor to the user terminal, the second execution trail including proof information proving possession of a private key corresponding to the public key; An execution trail verification device for a protected memory processing unit, characterized in that it is possible to verify that the second execution trail sent from the protected memory processing unit is legitimate by receiving the blind signature and the certification information and confirming that the blind signature and certification information are authentic.

6. 6. The execution trail verification device of the protected memory processing unit according to claim 5, wherein the trusted institution terminal is provided in a bank, and the program processes digital currency settlements.

7. a blind signature performed by the trusted authority terminal on the public key transmitted from the user terminal when the trusted authority terminal has successfully verified the first execution trail of the observer program transmitted from the user terminal and installed in the protected storage processing unit of the user terminal; a second execution trail transmitted from the protected storage processor to the user terminal, the second execution trail including proof information proving possession of a private key corresponding to the public key; An execution trail verification program for a protected memory processing unit, characterized in that it causes a computer to execute a process that receives the blind signature and the certification information, and confirms that the blind signature and certification information are authentic, thereby verifying that the second execution trail sent from the protected memory processing unit is legitimate.

8. 8. The execution trail verification program of claim 7, wherein the trusted institution terminal is provided in a bank, and the program processes digital currency settlements.