Electronic devices, IC cards, secure elements, methods for determining the revocation of electronic certificates, and computer programs

Electronic devices with internal CRL storage and verification units can determine and update certificate revocation status offline, addressing the challenge of verifying electronic certificates without network connectivity.

JP2026136975APending Publication Date: 2026-08-26DAI NIPPON PRINTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025022867
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2026-08-26

AI Technical Summary

Technical Problem

Electronic devices without network connectivity, such as IC cards, cannot verify the revocation status of electronic certificates when offline due to the inability to access the latest Certificate Revocation List (CRL) published by certification authorities.

Method used

Incorporating a storage unit to store a CRL and a certificate verification unit that determines the revocation status of electronic certificates using the stored CRL, and notifying the terminal device of the revocation determination, even in offline environments.

Benefits of technology

Enables electronic devices to determine the revocation of electronic certificates offline by using an internal CRL, ensuring secure verification and updating of certificate revocation lists.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026136975000001_ABST
    Figure 2026136975000001_ABST
Patent Text Reader

Abstract

This will enable electronic devices such as IC cards to determine the revocation of electronic certificates even in offline environments. [Solution] The electronic device 1 includes a storage unit 11 that stores a certificate revocation list 110 containing the numbers of revoked electronic certificates, and a certificate verification unit 10 that, when verifying an electronic certificate 30 received from a terminal device 3, refers to the certificate revocation list 110 stored in the storage unit 11, performs a process to determine the revocation of the electronic certificate 30 based on the numbers registered in the certificate revocation list 110, and notifies the terminal device 3 that, in addition to the verification result of the electronic certificate 30, the revocation determination was not performed using the certificate revocation list 110 obtained online.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0002] , , , , ,

[0003]

[0001] This application relates to a technique for verifying electronic certificates.

Background Art

[0002] Electronic certificates play an important role in the field of information security. Although electronic certificates used in the field of information security are provided with an expiration date, even within the expiration date, the electronic certificate may become invalid for some reason. Reasons for the invalidation of an electronic certificate include, for example, leakage of the private key corresponding to the public key described in the electronic certificate and changes in the description items of the electronic certificate. An electronic certificate that has become invalid before the expiration date is registered with the certification authority that issued the electronic certificate. The certification authority regularly publishes online a certificate revocation list that lists the invalidated electronic certificates. The certificate revocation list issued by the certification authority is called a CRL (Certificate Revocation List). By referring to this certificate revocation list, it is possible to determine whether the electronic certificate to be verified has become invalid (for example, Patent Document 1).

[0003] When verifying an electronic certificate, it is sufficient to obtain the latest certificate revocation list online, but there may be cases where the latest certificate revocation list cannot be obtained online. In order to obtain the latest certificate revocation list, it is necessary to access online the certificate revocation list published by the certification authority. However, among the electronic devices used in the field of information security, there are some that do not have a network connection function. As an example of an electronic device without a network connection function, there is an IC card. Even for an electronic device without a network connection function, if the terminal device connected to the electronic device is connected to the network, the electronic device can obtain the latest certificate revocation list using the terminal device. However, when an electronic device is used in an environment where connection to an external network is prohibited (for example, a facility with strict security), even an electronic device with a network connection function cannot obtain the latest CRL.

Prior Art Documents

[0004] [Patent Document 1] Japanese Patent Publication No. 2006-287567 [Overview of the project] [Problems that the invention aims to solve]

[0005] Therefore, this application aims to enable electronic devices such as IC cards to determine the revocation of electronic certificates even in offline environments where network connectivity is unavailable. Furthermore, this application also aims to enable updates to the certificate revocation list used for determining the revocation of electronic certificates. [Means for solving the problem]

[0006] The first invention, which solves the problems of the present application, is an electronic device comprising: a storage unit that stores a certificate revocation list containing the numbers of revoked electronic certificates; and a certificate verification unit that, as one of the processes for verifying an electronic certificate received from a terminal device, refers to the certificate revocation list stored in the storage unit, performs a process to determine the revocation of the electronic certificate based on the number registered in the certificate revocation list, and notifies the terminal device that the revocation determination was made using the stored certificate revocation list in addition to the verification result of the electronic certificate. In the first invention, a CRL (Certificate Revocation List) issued by a certification authority can be used as the certificate revocation list.

[0007] The second invention, which solves the problems of the present application, is an IC card comprising: a storage unit that stores a certificate revocation list containing the numbers of revoked electronic certificates; and a certificate verification unit that, as one of the processes for verifying an electronic certificate received from a terminal device, refers to the certificate revocation list stored in the storage unit, determines the revocation of the electronic certificate based on the number registered in the certificate revocation list, and notifies the terminal device that the revocation determination was made using the stored certificate revocation list in addition to the verification result of the electronic certificate. In the second invention, a Certificate Revocation List (CRL) issued by a certification authority can be used as the certificate revocation list.

[0008] The third invention, which solves the problems of the present application, is a secure element comprising: a storage unit that stores a certificate revocation list containing the numbers of revoked electronic certificates; and a certificate verification unit that, as one of the processes for verifying an electronic certificate received from a terminal device, refers to the certificate revocation list stored in the storage unit, performs a process to determine the revocation of the electronic certificate based on the number registered in the certificate revocation list, and notifies the terminal device that the revocation determination was made using the stored certificate revocation list in addition to the verification result of the electronic certificate. In the third invention, a Certificate Revocation List (CRL) issued by a certification authority can be used as the certificate revocation list.

[0009] The fourth invention, which solves the problems of the present application, is a method for determining the revocation of an electronic certificate, in which a secure element that stores a certificate revocation list containing the numbers of revoked electronic certificates performs, as one of the processes for verifying an electronic certificate received from a terminal device, the secure element refers to the certificate revocation list stored by the secure element and determines the revocation of the electronic certificate based on the numbers registered in the certificate revocation list; and the secure element notifies the terminal device that, in addition to the verification result of the electronic certificate, a revocation determination has been made using the stored certificate revocation list. In the fourth invention, a Certificate Revocation List (CRL) issued by a certification authority can be used as the certificate revocation list.

[0010] The fifth invention, which solves the problems of the present application, is a computer program that causes a secure element that stores a certificate revocation list containing the numbers of revoked electronic certificates to perform the following steps as one of the processes for verifying an electronic certificate received from a terminal device: step a, which refers to the certificate revocation list stored by the secure element and determines that the electronic certificate with a number registered in the certificate revocation list is invalid; and step b, which notifies the terminal device that, in addition to the verification result of the electronic certificate, a revocation determination has been made using the stored certificate revocation list. In the fifth invention, a CRL (Certificate Revocation List) issued by a certification authority can be used as the certificate revocation list. [Effects of the Invention]

[0011] To enable electronic devices to determine the revocation of electronic certificates even in offline environments where they cannot connect to a network, the electronic device according to this application is configured to determine the revocation of electronic certificates using a certificate revocation list stored internally within the electronic device, and to notify terminal devices that the revocation determination has not been performed using a certificate revocation list obtained online. [Brief explanation of the drawing]

[0012] [Figure 1] A diagram showing an example of an electronic device. [Figure 2] A diagram showing the hardware configuration of the secure element. [Figure 3] Block diagram of an electronic device. [Figure 4] A diagram showing the structure of an X.509 format digital certificate. [Figure 5] A diagram showing the structure of a Certificate Revocation List (CRL), which is a list of certificates in X.509 format. [Figure 6] A diagram illustrating how an electronic device verifies an electronic certificate. [Figure 7] A diagram illustrating how an electronic device updates the certificate revocation list. [Modes for carrying out the invention]

[0013] The embodiments of the present invention will now be described. These embodiments are provided to facilitate understanding of the present invention, and the present invention is not limited to these embodiments. Unless otherwise specified, the drawings are schematic diagrams drawn to facilitate understanding of the present invention.

[0014] Figure 1 shows an example of electronic device 1. Electronic device 1 according to this embodiment is a device that implements a secure element 2. The secure element 2 is a highly secure semiconductor integrated circuit that protects confidential information and performs cryptographic calculations.

[0015] Figure 1 illustrates the electronic device 1, which incorporates the secure element 2 according to this embodiment, as a contact-type IC card that reads and writes data through metal contacts visible on the card surface. In Figure 1, the secure element 2 is mounted on the back surface of the contact terminal substrate 1a. A contact-type IC card without network connectivity is only one example of the electronic device 1. The electronic device 1 may be a contactless IC card that reads and writes data using wireless communication, or a dual-interface IC card that has characteristics of both contact and contactless types. Furthermore, the electronic device 1 may be a device with network connectivity, such as a notebook personal computer or a tablet computer.

[0016] Figure 2 shows the hardware configuration of the secure element 2 to be implemented on the electronic device 1. The secure element 2 includes a CPU 20 (Central Processing Unit), RAM 21 (Random Access Memory), ROM 22 (Read Only Memory), NVM 23 (Non-volatile memory), a coprocessor 24 (RNG: Random Number Generator), and a UART 25 (Universal Asynchronous Receiver-Transmitter). Although not shown in the figure, the secure element 2 also includes circuits necessary for its operation, such as a clock generation circuit, a reset circuit for reset processing, and a pseudo-random number generation circuit.

[0017] The CPU 20 is an arithmetic circuit that executes a computer program to perform predetermined processing. The RAM 21, ROM 22, and NVM 23 are memories. The RAM 21 is a volatile memory that cannot permanently store data but can be rewritten at high speed. The ROM 22 is a non-volatile memory that can permanently store data and is electrically non-rewritable. The NVM 23 is a non-volatile memory that can permanently store data and is electrically rewritable. The coprocessor 24 is an arithmetic circuit designed to efficiently perform specific cryptographic operations. The UART 25 is a circuit for communicating with the terminal device 3. In the case of a contact-type IC card, the UART 25 complies with ISO / IEC 7816 part3.

[0018] Figure 3 shows a block diagram of the electronic device 1. As shown in Figure 3, the electronic device 1 includes a certificate verification unit 10, a revocation list update unit 12, and a storage unit 11. These functions of the electronic device 1 are functions of the secure element 2 implemented in the electronic device 1. Each of the certificate verification unit 10 and the revocation list update unit 12 is a function realized by the CPU 20 of the secure element 2 and a computer program that operates the CPU 20. The storage unit 11 is a function realized by the NVM 23 of the secure element 2.

[0019] The storage unit 11 of the electronic device 1 stores a certification authority certificate 111, which is an electronic certificate 30 of a certification authority (CA: Certification Authority), and a certificate revocation list 110 in which a list of invalidated electronic certificates is described. An invalidated electronic certificate means an electronic certificate 30 that has been invalidated before its expiration date for some reason. The certificate verification unit 10 provided in the electronic device 1 is a function for verifying the electronic certificate 30 received from the terminal device 3. When verifying the electronic certificate 30 received from the terminal device 3, the certificate verification unit 10 provided in the electronic device 1 uses the certificate revocation list 110 stored in the storage unit 11 to determine the invalidation of the electronic certificate 30 received from the terminal device 3. The revocation list update unit 12 provided in the electronic device 1 is a function for updating the certificate revocation list 110 stored in the storage unit 11 using the latest certificate revocation list 31 received from the terminal device 3.

[0020] The certificate revocation list 110 stored in the storage unit 11 of the electronic device 1 describes a list of invalidated electronic certificates, which are electronic certificates 30 invalidated by the certification authority. In the present embodiment, the electronic certificate 30, the certification authority certificate 111, and the certificate revocation list 110 received from the terminal device 3 comply with the format of X.509 Public Key Infrastructure Certificate and Certificate Revocation List Profile defined by the IEFT (Internet Engineering Task Force).

[0021] First, let's describe the X.509 format digital certificate 30. Figure 4 shows the structure of the X.509 format digital certificate 30. The X.509 format digital certificate 30 includes the certificate to be signed information 300 (tbsCertificate: To Be Signed Certificate) and the digital signature information 301. The certificate to be signed information 300 includes the X.509 format version 300a, the digital certificate number 300b, the signature algorithm 300c, the issuer name of the digital certificate 30 300d, the expiration date of the digital certificate 30 300e, the name of the subject who owns the digital certificate 30 300f, the public key algorithm 300g, and the subject's public key 300h. The digital signature information 301 includes the signature algorithm 301a and the signature value 301b. The signature algorithm 301a is information indicating the algorithm used by the issuer (certification authority) when signing the certificate to be signed information 300. The signature value 301b is the hash value of the certificate information 300 to be signed, encrypted with the private key of the issuer (certification authority) of the digital certificate 30.

[0022] Next, we will describe the X.509 format certificate revocation list 110. The X.509 format certificate revocation list 110 is called a CRL (Certificate Revocation List). Figure 5 shows the structure of the X.509 format certificate revocation list 110. The X.509 format certificate revocation list 110 includes the To Be Signed Certificate List information 1100 (tbsCertList: To Be Signed Certificate List) and the digital signature information 1101. The To Be Signed Certificate List information 1100 includes the X.509 format version 1100a, the signature algorithm 1100b, the issuer name of the certificate revocation list 110 1100c, the issue date of the certificate revocation list 110 1100d, the scheduled issue date of the next certificate revocation list 110 1100e, and one or more revoked digital certificate information 1100f. The revoked digital certificate information 1100f includes the revoked digital certificate number and the revocation date. The digital signature information 1101 includes a signature algorithm 1101a and a signature value 1101b. The signature algorithm 1101a is information indicating the algorithm used by the issuer (certification authority) when signing the certificate list information 1100. The signature value 1101b is the hash value of the certificate list information 1100 encrypted with the issuer's (certification authority's) private key.

[0023] In this embodiment, the certificate revocation list 110 stored in the storage unit 11 of the electronic device 1 is defined as the Certificate Revocation List (CRL). However, the certificate revocation list 110 stored in the storage unit 11 of the electronic device 1 does not have to be the CRL itself, as long as it can indicate the revoked electronic certificate. For example, the certificate revocation list 110 stored in the storage unit 11 of the electronic device 1 may be a list that only contains the numbers of the revoked electronic certificates registered in the CRL.

[0024] The Certificate Revocation List (CRL), which is a Certificate Revocation List 110 in X.509 format, is updated according to the scheduled issuance date 1100e. Therefore, the electronic device 1 according to this embodiment needs a function to update the Certificate Revocation List 110 stored in the storage unit 11. Accordingly, the electronic device 1 according to this embodiment includes a revocation list update unit 12 that updates the Certificate Revocation List 110 stored in the storage unit 11 using the latest Certificate Revocation List 31 received from the terminal device 3.

[0025] Next, we will explain the operation of electronic device 1 when it verifies the electronic certificate 30. Figure 6 is a diagram showing the operation of electronic device 1 when it verifies the electronic certificate 30. The explanation referring to Figure 6 also serves as an explanation of the revocation determination method related to this application.

[0026] When verifying the digital certificate 30, the electronic device 1 receives a certificate verification command to verify the digital certificate 30 from the terminal device 3 (step S1). The certificate verification command to verify the digital certificate 30 is, for example, the VERIFY_CERTIFICATE command described in "JICSAPIC Card Specification V2.0 (Part 3 Common Commands)". The command message of the certificate verification command contains the digital certificate 30 to be verified.

[0027] When a certificate verification command is received from terminal device 3, the certificate verification unit 10 of electronic device 1 is activated. First, the certificate verification unit 10 of electronic device 1 determines whether the issuer of the electronic certificate 30 received from terminal device 3 is a trustworthy person (step S2). The certificate verification unit 10 determines whether the issuer of the electronic certificate 30 received from terminal device 3 is a trustworthy person by checking whether the subject name 300f (which will be the name of the certification authority) of the certification authority certificate 111 stored in the storage unit 11 matches the issuer name 300d (which will be the name of the certification authority) of the electronic certificate 30 received from terminal device 3. If the subject name 300f of the certification authority certificate 111 and the issuer name 300d of the digital certificate 30 match, the digital certificate 30 received from the terminal device 3 becomes a digital certificate 30 issued by the certification authority that is the subject of the certification authority certificate 111. Therefore, the certificate verification unit 10 determines the issuer determination result as successful. If the subject name 300f of the certification authority certificate 111 and the issuer name 300d of the digital certificate 30 do not match, the issuer determination result is deemed unsuccessful.

[0028] If the certificate verification unit 10 determines that it has failed to verify the issuer, it proceeds to step S6 in Figure 6, sends an abnormal termination response to the terminal device 3 indicating that the verification of the electronic certificate 30 has failed, and the procedure in Figure 6 ends.

[0029] If the certificate verification unit 10 determines that it has succeeded in determining the issuer, it verifies the digital signature of the digital certificate 30 received from the terminal device 3 (step S3). The certificate verification unit 10 compares the hash value obtained by decrypting the signature value 301b of the digital certificate 30 received from the terminal device 3 using the public key 300h of the certification authority certificate 111 stored in the storage unit 11 with the hash value calculated from the signature target certificate information 300 in the digital certificate 30 received from the terminal device 3. If the two hash values ​​match, the certificate verification unit 10 determines that it has succeeded in verifying the digital signature of the digital certificate 30, and if the two hash values ​​do not match, it determines that it has failed to verify the digital signature of the digital certificate 30.

[0030] If the certificate verification unit 10 determines that it has failed to verify the electronic signature of the electronic certificate 30, it proceeds to step S6 in Figure 6, sends an abnormal termination response to the terminal device 3 indicating that the verification of the electronic certificate 30 has failed, and the procedure in Figure 6 ends.

[0031] If the certificate verification unit 10 of the electronic device 1 determines that it has successfully verified the electronic signature of the electronic certificate 30, it determines that the electronic certificate 30 has expired (step S4). The certificate verification unit 10 refers to the certificate revocation list 110 stored in the storage unit 11 and determines that the electronic certificate 30 received from the terminal device 3 has expired based on the number of the revoked electronic certificate registered in the certificate revocation list 110. Specifically, the certificate verification unit 10 determines that the electronic certificate 30 has expired by checking whether the revoked electronic certificate information 1100f, which includes the number 300b of the electronic certificate 30, is registered in the certificate revocation list 110 stored in the storage unit 11. If the electronic certificate 30 received from the terminal device 3 has expired, the number 300b of the electronic certificate 30 is registered in the certificate revocation list 110. The certificate verification unit 10 of the electronic device 1 determines that the electronic certificate 30 received from the terminal device 3 is not revoked if the number 300b of the electronic certificate 30 received from the terminal device 3 is not registered in the certificate revocation list 110 stored in the storage unit 11, and determines that the electronic certificate 30 received from the terminal device 3 is revoked if it is registered in the certificate revocation list 110.

[0032] If the certificate verification unit 10 determines that the electronic certificate 30 has not expired, it proceeds to step S5 in Figure 6 and sends a successful completion response to the terminal device 3 indicating that the verification of the electronic certificate 30 was successful, and the procedure in Figure 6 ends. If the certificate verification unit 10 determines that the electronic certificate 30 has expired, it proceeds to step S6 in Figure 6 and sends an abnormal completion response to the terminal device 3 indicating that the verification of the electronic certificate 30 failed, and the procedure in Figure 6 ends.

[0033] In order for the electronic device 1 to be able to determine the revocation of the electronic certificate 30 even in an offline environment where it cannot connect to a network, the electronic device 1 must not only determine the revocation of the electronic certificate 30 using the certificate revocation list 110 stored in the storage unit 11, but also be able to respond to updates to the certificate revocation list 110 stored in the storage unit 11. Therefore, in this embodiment, in addition to the verification result of the electronic certificate 30, information indicating that the revocation determination was not made using the certificate revocation list 110 obtained online, that is, that the revocation determination was made using the certificate revocation list 110 stored in the storage unit 11, is included in the response of the certificate verification command, and this fact is notified to the terminal device 3.

[0034] If the response to the certificate verification command includes information indicating that a revocation determination was made using the certificate revocation list 110 stored in the storage unit 11, the terminal device 3 can understand this and execute the process related to updating the certificate revocation list 110 stored in the electronic device 1. If the terminal device 3 cannot connect to the network, it will display a message prompting it to update the certificate revocation list 110. If the terminal device 3 can connect to the network, it will access the latest CRL and update the certificate revocation list 110 stored in the electronic device 1. Preferably, the information indicating that a revocation determination was made using the certificate revocation list 110 stored in the storage unit 11 includes the issue date 1100d of the certificate revocation list 110 stored in the electronic device 1. This allows the terminal device 3 to determine from the response to the certificate verification command whether the certificate revocation list 110 stored in the electronic device 1 is the latest version.

[0035] The following describes how electronic device 1 updates the certificate revocation list 110. Figure 7 shows the operation in which electronic device 1 updates the certificate revocation list 110. When updating the certificate revocation list 110, electronic device 1 receives a revocation list update command from terminal device 3 to update the certificate revocation list 110 (step S10). For example, the revocation list update command to update the certificate revocation list 110 is the UPDATE_BINARY command described in "JICSAPIC Card Specification V2.0 (Part 3 Common Commands)". The command message of the revocation list update command contains the latest certificate revocation list 31 to be used for the update.

[0036] When the revocation list update command is received from terminal device 3, the revocation list update unit 12 is activated, and the revocation list update unit 12 determines whether the issuer of the certificate revocation list 110 included in the revocation list update command received from terminal device 3 is a trustworthy person (step S11). The revocation list update unit 12 determines whether the issuer of the digital certificate 30 received from terminal device 3 is a trustworthy person by checking whether the subject name 300f of the certification authority certificate 111 stored in the storage unit 11 matches the issuer name 1100c of the latest certificate revocation list 31 received from terminal device 3. If the subject name 300f of the certification authority certificate 111 matches the issuer name 1100c of the latest certificate revocation list 31, the revocation list update unit 12 determines the issuer determination result as a success, and if the subject name 300f of the certification authority certificate 111 matches the issuer name 1100c of the latest certificate revocation list 31, the issuer determination result as a failure.

[0037] If the revocation list update unit 12 determines that it has failed to determine the issuer, it proceeds to step S15 in Figure 7, sends an abnormal termination response to the terminal device 3 indicating that the revocation list update command failed, and the procedure in Figure 7 ends.

[0038] If the revocation list update unit 12 determines that it has succeeded in determining the issuer, it verifies the digital signature of the certificate revocation list 110 received from the terminal device 3 (step S12). The revocation list update unit 12 compares the hash value obtained by decrypting the signature value 1101b of the latest certificate revocation list 31 received from the terminal device 3 using the public key 300h of the certification authority certificate 111 stored in the storage unit 11 with the hash value calculated from the signature target certificate list information 1100 in the latest certificate revocation list 31 received from the terminal device 3. If the two hash values ​​match, the revocation list update unit 12 determines that it has succeeded in verifying the digital signature of the certificate revocation list 110, and if the two hash values ​​do not match, it determines that it has failed to verify the digital signature of the certificate revocation list 110.

[0039] If the revocation list update unit 12 determines that it has failed to verify the electronic signature, it proceeds to step S15 in Figure 7, sends an abnormal termination response to the terminal device 3 indicating that the revocation list update command failed, and the procedure in Figure 7 ends. If the revocation list update unit 12 determines that it has succeeded in verifying the electronic signature, it updates the certificate revocation list 110 stored in the storage unit 11 with the latest certificate revocation list 31 included in the revocation list update command (step S13), and then sends a normal termination response to the terminal device 3 indicating that the revocation list update command was successful (step S14), and the procedure in Figure 7 ends.

[0040] Furthermore, in order to enhance security regarding the updating of the certificate revocation list 110, it is desirable that the certificate verification unit 10 of the electronic device 1 be configured to update the certificate revocation list 110 only if it has successfully verified the electronic certificate 30 received from the terminal device 3. [Explanation of Symbols]

[0041] 1. Electronic devices 10 Certificate Verification Section 11 Storage section 110 Certificate Revocation List 111 Certificate Authority Certificate 12. Expiry List Update Section 2 Secure Elements 3 Terminal devices 30. Electronic Certificates 31 Latest Certificate Revocation List

Claims

1. A storage unit that stores a certificate revocation list containing the numbers of revoked electronic certificates, As one of the processes for verifying an electronic certificate received from a terminal device, the certificate verification unit refers to the certificate revocation list stored in the storage unit, performs a process to determine the revocation of the electronic certificate based on the number registered in the certificate revocation list, and notifies the terminal device that a revocation determination has been made using the stored certificate revocation list in addition to the verification result of the electronic certificate. An electronic device equipped with [a specific feature / ability].

2. The electronic device according to claim 1, characterized in that a Certificate Revocation List (CRL) issued by a certification authority is stored in the storage unit as the certificate revocation list.

3. A storage unit that stores a certificate revocation list containing the numbers of revoked electronic certificates, As one of the processes for verifying an electronic certificate received from a terminal device, the certificate verification unit refers to the certificate revocation list stored in the storage unit, performs a process to determine the revocation of the electronic certificate based on the number registered in the certificate revocation list, and notifies the terminal device that a revocation determination has been made using the stored certificate revocation list in addition to the verification result of the electronic certificate. An IC card equipped with this feature.

4. The IC card according to claim 3, characterized in that the Certificate Revocation List (CRL) issued by a certification authority is stored in the storage unit as the certificate revocation list.

5. A storage unit that stores a certificate revocation list containing the numbers of revoked electronic certificates, As one of the processes for verifying an electronic certificate received from a terminal device, the certificate verification unit refers to the certificate revocation list stored in the storage unit, performs a process to determine the revocation of the electronic certificate based on the number registered in the certificate revocation list, and notifies the terminal device that a revocation determination has been made using the stored certificate revocation list in addition to the verification result of the electronic certificate. Equipped with a secure element.

6. The secure element according to claim 5, characterized in that a Certificate Revocation List (CRL) issued by a certification authority is stored in the storage unit as the certificate revocation list.

7. A secure element that stores a certificate revocation list containing the numbers of revoked digital certificates, As one of the processes for verifying the electronic certificate received from the terminal device, step a refers to the certificate revocation list stored in the secure element and determines the revocation of the electronic certificate based on the number registered in the certificate revocation list, Step b involves notifying the terminal device that, in addition to the verification results of the aforementioned electronic certificate, a revocation determination has been made using the stored certificate revocation list. A method for determining the revocation of an electronic certificate.

8. The method for determining the revocation of an electronic certificate according to claim 7, characterized in that the aforementioned certificate revocation list is a Certificate Revocation List (CRL) issued by a certification authority.

9. In the secure element that stores the certificate revocation list containing the numbers of revoked digital certificates, As one of the processes for verifying the electronic certificate received from the terminal device, step a refers to the certificate revocation list stored in the secure element and determines the revocation of the electronic certificate based on the number registered in the certificate revocation list, Step b involves notifying the terminal device that, in addition to the verification results of the aforementioned electronic certificate, a revocation determination has been made using the stored certificate revocation list. A computer program that executes an action.

10. The computer program according to claim 9, characterized in that the aforementioned certificate revocation list is a Certificate Revocation List (CRL) issued by a certification authority.

Citation Information

Patent Citations

  • Information processor

    JP2006287567A