Method for recovering data from electronic information storage media

A recovery information table automates recovery processes for electronic information recording media by recording status flags, anomaly codes, and backup data, addressing inefficiencies and instability in existing methods, allowing for automatic resumption of operations after anomalies.

JP7835013B2Active Publication Date: 2026-03-25TOPPAN HOLDINGS INC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-01-05
Publication Date
2026-03-25

AI Technical Summary

Technical Problem

Existing methods for recovering electronic information recording media, such as IC cards, struggle with inefficient and unstable operations due to difficulties in determining and responding to anomalies during data processing, particularly after momentary power interruptions or external attacks, leading to inaccessible NVM areas and requiring manual intervention.

Method used

A recovery information table is pre-configured to record status flags, anomaly codes, target addresses, and backup data, enabling automatic recovery processes by restarting the medium and executing recovery steps based on the recorded information.

Benefits of technology

Enables stable and efficient recovery by automatically performing recovery processing without manual intervention, ensuring the electronic information recording medium can resume operations after anomalies, maintaining system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007835013000003
    Figure 0007835013000003
  • Figure 0007835013000004
    Figure 0007835013000004
  • Figure 0007835013000005
    Figure 0007835013000005
Patent Text Reader

Abstract

To provide a restoration method that can automatically perform restoration processing when an error occurs during data processing of an electronic information recording medium.SOLUTION: A method includes a status flag by which a restoration information table created in advance, contains at least records whether an end state of data processing was normal or abnormal, an abnormality code that is a code assigned to each type of abnormality, an object address that records an address of the area where the abnormality occurred, and backup data that is data necessary for restoration processing corresponding to the abnormality code, the backup data is either fixed data set in advance or data stored in the object address immediately before the abnormality occurred, when the IC card is restarted by a restart command received from the reader / writer in the event of an abnormality, the IC card reads the recovery information table from the storage area, and if an abnormality is recorded in the status flag, performs the recovery processing corresponding to the recorded abnormality code for the object address.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a recovery processing method when an abnormality occurs in data processing of an electronic information recording medium such as a secure element of an IC card or a smartphone, and particularly to a recovery processing method that automatically performs recovery processing according to the type of abnormality.

Background Art

[0002] When using an electronic information recording medium such as an IC card, for example, when an abnormality occurs during data processing in command processing received from a connected IC card reader / writer, recovery processing is required according to the occurrence abnormality. That is, when a non-volatile memory (NVM, Non-Volatile Memory) is destroyed, initialization of the target area of the NVM, restoration with backup data when the data format is destroyed, etc. are conceivable processing. In that case, by transmitting a recovery command for executing each recovery process in advance from the IC card reader / writer side, recovery can be achieved by executing the recovery process according to the occurrence abnormality. However, it may be difficult for non-manufacturers to make appropriate judgments and responses in cases where it is necessary to determine what kind of abnormality has occurred and procedures such as authentication for the recovery command.

[0003] FIG. 5 is a diagram showing a conventional example of the flow of the NVM update process. When the process is interrupted due to some cause (for example, momentary power failure or external attack) during the process, the state of the NVM becomes an indeterminate state and the area of the NVM may be destroyed, such as becoming inaccessible. When the NVM is destroyed, access to the destroyed area becomes impossible and the IC card cannot be used. In such a case, as shown in FIG. 6, an update command is sent from the IC card reader / writer, and the recovery process is performed by initializing the target area of the NVM. Also, when the data format is destroyed, the recovery process is performed by restoring with backup data. The response of the recovery process from such an abnormality, including the analysis of what kind of error has occurred, will be performed separately.

[0004] ​Patent Document 1 describes an IC card that has a function to save the execution state of the IC card and a function to restore the execution state, and that allows the IC card's processing to be interrupted and resumed from where it left off. It states that the interrupted processing can be resumed by recording the state of registers, volatile memory, etc. after processing execution in the NVM. However, if a momentary power interruption occurs during processing, the contents of a certain area of ​​the NVM may be corrupted and become unreadable or even inaccessible, in which case special recovery work may be required and resuming processing may be difficult.

[0005] Another similar technique is rollback. Rollback is a technique that restores data to its state before the update if an anomaly is detected during or after an update. Therefore, it can be inefficient because the update must be restarted from the beginning, and if NVM memory is corrupted and becomes inaccessible, additional measures may be required.

[0006] In this way, if an anomaly occurs during processing, the NVM can be destroyed, making it impossible to read the contents or even access them at all. Automatic recovery is not possible, and in some cases, it is difficult for anyone other than the IC card manufacturer to make appropriate judgments and take appropriate action, such as determining what kind of anomaly has occurred or requiring authentication procedures for recovery commands. This has been a challenge for the stable operation of IC card systems. [Prior art documents] [Patent Documents]

[0007] [Patent Document 1] Japanese Patent Application No. Hei 8-50641 [Overview of the Initiative] [Problems that the invention aims to solve]

[0008] Therefore, the present invention aims to provide a recovery method for electronic information recording media that enables stable and efficient system operation by automatically performing recovery processing for areas that have become inaccessible, even if the NVM state becomes uncertain or inaccessible due to a momentary power interruption or the like during various data processing of electronic information recording media such as IC cards and secure elements, such as initialization and update processing of NVM, the data can be restored to normal. [Means for solving the problem]

[0009] To solve the above problems, the present invention provides A method for recovering an electronic information recording medium that has stopped operating due to an abnormality that occurred during data processing, A recovery information table is created in advance on the storage area to record information for recovery from an anomaly, and the recovery information table contains at least: A status flag that records whether the completion status of the aforementioned data processing was normal or abnormal, An anomaly code is a code assigned to each type of anomaly, Corresponding to the aforementioned error code The target address to record the address of the region where the anomaly occurred, This includes backup data, which is data necessary for recovery processing corresponding to the aforementioned error code, The backup data consists of pre-configured fixed data or data that was stored at the target address immediately before the anomaly occurred. When an abnormality occurs, the electronic information recording medium is restarted by a restart command received from the reader / writer of the electronic information recording medium. The electronic information recording medium reads the recovery information table from the storage area. If an abnormality is recorded in the status flag, the recovery process corresponding to the recorded abnormality code is performed on the target address. After the recovery process is complete, the reader / writer is notified that the process has finished. This is a method for recovering electronic information recording media, characterized by the following features.

[0010] In the method for recovering an electronic information recording medium, when the abnormality is NVM destruction, the recovery process may be initialization of the area of the target address.

[0011] In the method for recovering an electronic information recording medium, when the abnormality is data format destruction, the recovery process may be updating the area of the target address with the backup data.

[0012] In the method for recovering an electronic information recording medium, when the abnormality is key value verification abnormality, the recovery process may be updating with the default key value stored in the backup data.

[0013] In the method for recovering an electronic information recording medium, Specific steps of each recovery process corresponding to the abnormality code may be recorded in the non-volatile memory area of the electronic information recording medium.

Advantages of the Invention

[0014] According to the method for recovering an electronic information recording medium of the present invention, during data processing in an electronic information recording medium, if the process is interrupted by an abnormal operation such as a momentary interruption and an abnormality that makes normal operation impossible has occurred, the recovery information recorded in advance in the recovery information table can be read out, and a return process according to the recovery information can be automatically performed, enabling stable operation.

Brief Description of the Drawings

[0015] [Figure 1] It is a diagram of the system flow of the NVM update process in the present invention. [Figure 2] It is a diagram of the system flow when restarting an IC card in the present invention. [Figure 3] It is an example diagram of the system flow of the recovery process of an IC card in the present invention. [Figure 4]It is a diagram of another example of the system flow of the recovery process of an IC card in the present invention. [Figure 5] It is a diagram showing an example of the flow of the NVM update process in a conventional IC card. [Figure 6] It is a diagram showing an example of the system flow when restarting a conventional IC card.

Mode for Carrying Out the Invention

[0016] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. Note that the present invention is not limited to the embodiments described below. Also, in the embodiments shown below, technically preferable limitations are imposed for carrying out the invention, but this limitation is not an essential requirement of the present invention.

[0017] In the recovery processing method of the present invention, for various abnormalities that occur during data processing in an electronic information recording medium such as an IC card or a secure element of a smartphone, recovery information necessary for recovery is recorded in a recovery information table before the abnormality occurs, and when an abnormality occurs, the recovery information table is referred to and the recovery process is automatically performed to solve the problem. Hereinafter, the IC card will be specifically described as an example, but since data processing in a secure element or the like is the same, the same recovery method can be applied.

[0018] For example, when an abnormality is detected when the IC card is started up, or when the processing ends due to a momentary power failure during data update, etc., when the operation of the IC card stops, when restarting the IC card, refer to the recovery information table and automatically perform the corresponding recovery process according to the recorded abnormality. As the recovery information table, for example, in the case of the NVM update process, it is described in the format as shown in Table 1.

[0019]

Table 1

[0020] Table 1 shows that the status flags are used to determine whether or not an abnormality has occurred. Here, 00h: Normal 01h: Abnormal Each of these is indicated, and if the status flag is abnormal, an abnormality code corresponding to the type of abnormality is set, and recovery processing corresponding to each abnormality code is performed.

[0021] The error code is used to identify the type of error that has occurred. Examples of error codes are shown in Table 2. For the examples in Table 2, the details of the error and the specific recovery process corresponding to each error code are as follows: 01h: NVM area corruption ⇒ Initialize the affected NVM area and enable re-access. 05h: Data format corrupted ⇒ Restore the NVM target area with backup data. 10h: Key value verification error ⇒ Update to default key value and restore. Examples include these. Other error codes can also be added. Furthermore, the more specific steps of the recovery process can be stored separately in the non-volatile memory that is normally equipped in the IC card.

[0022] The target address is an area for recording the address of the NVM where the anomaly occurred. Therefore, it is initially blank, and when an anomaly occurs, that address is recorded. It will become that.

[0023] If an anomaly occurs, the backup data is recorded in this field beforehand. For example, in the case of a key value verification anomaly mentioned above, if recovery can be achieved by applying a pre-configured default key value as recovery data, that data is recorded in this field. Also, in the case of data format corruption, if the data of the address to be processed is recorded before processing, it will be possible to recover the data from the backup data to the point just before the anomaly occurred if an anomaly occurs during processing.

[0024] The above example illustrates a scenario where an error occurs in the NVM; if an error occurs in a different system, other information may be recorded. The recovery information table is stored, for example, on the non-volatile memory of the IC card.

[0025] [Table 2]

[0026] The following describes an example of a system flow for recovery processing in the event of NVM failure. Figure 1 is a diagram of a system flow assuming NVM update processing. When an NVM update command is sent from the IC card reader / writer (abbreviated as R / W) to the IC card, the IC card side sets the status flag to "abnormal" and then starts the NVM update process. If the update is completed successfully, the status flag, which was temporarily set to "abnormal," is rewritten to "normal" and a normal response is returned to the IC card R / W. The IC card R / W side confirms that the update process has been completed successfully.

[0027] If any failure occurs during the NVM update process described above, the update process will be interrupted. In this case, the recovery information table will record the address where the update process was interrupted, corresponding to the error code of the error that occurred. To record the address where the update process was interrupted, for example, when performing the update process, the address to be updated can be recorded before the process starts. If the update is interrupted, that address will be recorded, and since the address information will not be updated after the interruption, the address where the update process was interrupted will remain recorded. The IC card will then stop working. At this time, the status flag will remain set to "abnormal".

[0028] If the IC card R / W does not receive a response within the specified time, it sends a startup command to restart the IC card, as shown in Figure 2. Upon receiving the startup command, the IC card starts the startup process, and the recovery information table is read first.

[0029] The status flag in the recovery information table is in the "abnormal" state, so by reading the status flag, the abnormality is detected and the recovery process is automatically executed. An example of the system flow of the recovery process is shown in Figure 3. Figure 3 is an example where the NVM is corrupted. When the recovery process starts, the abnormality code is read to determine what kind of abnormality has occurred. To explain using the example shown in Table 2, if the NVM is corrupted, the abnormality code is 01h.

[0030] Next, the target address recorded in response to error code 01h is read, and the address of the corrupted NVM is obtained. Then, the NVM area at that address is initialized to restore it. Once the recovery process is complete, the sequence returns to that shown in Figure 2, the IC card sends an ATR (Answer To Reset) signal to the IC card R / W, and the IC card R / W can determine that the IC card recovery process has been successfully completed.

[0031] Figure 4 shows another example of the system flow for recovery processing, specifically the flow in the case of format corruption. When the recovery process starts, an error code is read to determine what kind of error occurred. Determine if the format is corrupted. Using the example shown in Table 2, if the format is corrupted, the error code is 05h.

[0032] Next, the system reads the target address recorded in response to error code 05h and recovers the data at that address by updating it with backup data. Once the recovery process is complete, the system returns to the sequence shown in Figure 2, the IC card sends an ATR (Answer To Reset) signal to the IC card R / W, and the IC card R / W determines that the IC card recovery process has been successfully completed.

[0033] Similarly, if the key value validation fails, the error code is 10h. Recovery is achieved by updating to the default key value recorded for error code 10h. Subsequent processing is the same as described above.

[0034] As described above, the present invention's method for recovering electronic information recording media allows for automatic recovery processing when an abnormality occurs during data update and the operation of the electronic information recording media stops in an electronic information recording media such as an IC card or secure element. This is achieved by receiving a commonly used startup command for the electronic information recording media, and by referring to a pre-configured recovery information table, the electronic information recording media can be automatically recovered. Therefore, it does not require intervention from manufacturers or other parties, and the operational burden on the system is low.

Claims

1. A method for recovering an electronic information recording medium that has stopped operating due to an abnormality that occurred during data processing, A recovery information table is created in advance on the storage area to record information for recovery from an anomaly, and the recovery information table contains at least: A status flag that records whether the completion status of the aforementioned data processing was normal or abnormal, An anomaly code is a code assigned to each type of anomaly, A target address that records the address of the region where the error corresponding to the aforementioned error code occurred, This includes backup data, which is data necessary for recovery processing corresponding to the aforementioned error code, The backup data consists of pre-configured fixed data or data that was stored at the target address immediately before the anomaly occurred. When an abnormality occurs, the electronic information recording medium is restarted by a restart command received from the reader / writer of the electronic information recording medium. The electronic information recording medium reads the recovery information table from the storage area. If an abnormality is recorded in the status flag, the recovery process corresponding to the recorded abnormality code is performed on the target address. A method for recovering data from an electronic information recording medium, characterized by notifying the reader / writer of the completion of the recovery process after the recovery process is finished.

2. The recovery method for an electronic information recording medium according to claim 1, characterized in that when the abnormality is NVM corruption, the recovery process is initialization of the area of ​​the target address.

3. The recovery method for an electronic information recording medium according to claim 1, characterized in that when the abnormality is data format corruption, the recovery process updates the area of ​​the target address with the backup data.

4. The recovery method for an electronic information recording medium according to claim 1, characterized in that when the abnormality is a key value verification abnormality, the recovery process is an update using the default key value stored in the backup data.

5. The method for recovering an electronic information recording medium according to any one of claims 1 to 4, characterized in that the specific steps of each recovery process corresponding to the aforementioned error code are recorded in the non-volatile storage area of ​​the electronic information recording medium.

Citation Information

Patent Citations

  • Method for initializing non-volatile memory

    JP1993088994A

  • Ic card

    JP1996050641A

  • Communicating method and communicating system device

    JP2001257673A

  • Ic card, data update control method, data / Message restoration control method, and storage medium with control program recorded thereon

    JP2002123806A

  • Proximity communication electronic medium, reader / writer device, and control system

    JP2013015941A