Information processing apparatus and information processing method, and computer program

The information processing device addresses the challenge of notifying SP applications of secure element transactions by implementing a detection, acquisition, and verification system, ensuring secure and timely data delivery to authorized apps, thus enhancing transaction information management.

JP7836315B2Active Publication Date: 2026-03-26FELICA NETWORKS INC
View PDF 9 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-01
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Existing information processing devices struggle to notify service provider applications (SP apps) of transaction information between secure elements and external devices without requiring manual intervention, leading to security risks and inefficient data access.

Method used

An information processing device with a detection unit to identify transactions, an acquisition unit to analyze and verify legitimate SP applications, and a notification unit to inform only verified applications of transaction data, ensuring secure and timely information delivery.

Benefits of technology

Enables secure and real-time notification of transaction information to authorized SP applications, reducing security risks and processing overhead, while maintaining efficient data access and reducing server load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007836315000001
    Figure 0007836315000001
  • Figure 0007836315000002
    Figure 0007836315000002
  • Figure 0007836315000003
    Figure 0007836315000003
Patent Text Reader

Abstract

Provided is an information processing apparatus equipped with a secure element. In the present invention, an external information processing apparatus is provided with: a detection unit that detects when a transaction occurs between a device mounted on a main body and an external apparatus; an acquisition unit that acquires data from the device in response to the detection of the occurrence of the transaction by the detection unit; a determination unit that analyzes the data acquired by the acquisition unit to determine applications to be notified; a verification unit that verifies the validity of the applications to be notified; and a notification unit that notifies an appropriate application that is among the applications to be notified and the validity of which has been confirmed, of the data acquired by the acquisition unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology disclosed in this specification (hereinafter referred to as "the present disclosure") relates to an information processing apparatus and an information processing method equipped with a device that performs a transaction with an external device, and a computer program.

Background Art

[0002] Services using secure elements (SEs) such as IC (Integrated Circuit) chips, RFID (Radio Frequency Identification) tags, and IC cards have become widespread. A secure element is a device protected by tamper-resistant hardware, and secure contactless communication is possible between the reader / writer using mutual authentication and encryption. For contactless communication, a communication method conforming to a short-range wireless communication standard such as NFC (Near Field Communication) can be used, but detailed description thereof is omitted in this specification.

[0003] Recently, information terminals such as smartphones equipped with secure elements have been increasing. When this type of information terminal is held near a reader / writer, a transaction (such as reading and writing data to the memory in the secure element) is performed between the secure element in the information terminal and the reader / writer, thereby realizing service functions using secure elements (hereinafter also simply referred to as "service functions") such as a ticket function for public transportation, an electronic money or payment function, a credit card function, a ticket function for entertainment facilities such as movies and theaters, and a personal authentication function.

[0004] On the information terminal, an application program (hereinafter also called "SP app") distributed by the provider (service provider: SP) that provides each service function is installed, and by launching the SP app, procedures with the service provider related to the relevant service function (such as charging electronic money) and operations on the service function (such as displaying usage history and balance) can be performed. On the other hand, transactions between the secure element and the reader / writer within the information terminal occur through manual operations, such as the user holding the information terminal over the reader / writer, and in such cases, launching the SP app is not required, nor is the SP app notified. Therefore, in order for the SP app to display the balance, etc., the SP app needs to know the information of the transaction that took place between the secure element and the reader / writer.

[0005] For example, an information processing device has been proposed in which transaction information is stored in a second memory unit within the secure element, and the data acquisition unit on the information processing device side analyzes the location and surrounding conditions of the device, the user, the operation of the device, and the user's actions at the time the transaction was executed based on the information read from the second memory unit (see Patent Document 1). However, it is thought that the transaction information analysis processing performed in the data acquisition unit is carried out by middleware, and the SP application cannot grasp the transaction information that took place between the secure element and the reader / writer on this information processing device. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] WO2019 / 123851 [Overview of the project] [Problems that the invention aims to solve]

[0007] The purpose of this disclosure is to provide an information processing device and information processing method, as well as a computer program, for processing information related to transactions performed between a device within the main unit and an external device. [Means for solving the problem]

[0008] This disclosure has been made in consideration of the above issues, and its first aspect is an information processing device equipped with a device that performs transactions with an external device, A detection unit that detects when a transaction has occurred between the device and the external device, In response to the detection unit detecting the occurrence of the transaction, an acquisition unit acquires data from the device, The acquisition unit analyzes the data acquired and determines the application to be notified, A verification unit that verifies the legitimacy of the application to be notified, A notification unit that notifies the appropriate applications among the notification targets whose legitimacy has been confirmed, of the data acquired by the acquisition unit, It is an information processing device equipped with the following features.

[0009] The acquisition unit acquires the data to be processed by the transaction and data related to the processing of the transaction. The determination unit identifies the service ID related to the transaction based on the data acquired by the acquisition unit and determines the application to be notified based on the service ID.

[0010] The verification unit verifies the legitimacy of the application based on the application verification information obtained from the server and the application information obtained from the operating system. The verification information includes the application's package name and signature value.

[0011] The notification unit sends notifications to the appropriate applications based on application-specific information obtained from the server. The application-specific information obtained from the server includes at least one of the following: notification priority, notification deadline, and action to be taken when the notification deadline is exceeded.

[0012] Furthermore, a second aspect of this disclosure is an information processing method in a device equipped with a device that performs transactions with an external device, A detection step that detects that a transaction has occurred between the device and the external device, In response to detecting the occurrence of the transaction in the detection step, an acquisition step is performed to acquire data from the device, A determination step involves analyzing the data acquired in the acquisition step to determine the application to be notified, A verification step to verify the legitimacy of the application to be notified, A notification step in which the data acquired in the acquisition is notified to the appropriate application whose legitimacy has been confirmed among the notification targets, This is an information processing method that possesses the following properties.

[0013] Furthermore, a third aspect of this disclosure is an information processing device that incorporates a device for performing transactions with an external device, A detection unit that detects when a transaction has occurred between the external devices of the aforementioned device, In response to the detection unit detecting the occurrence of the transaction, an acquisition unit acquires data from the device. The acquisition unit analyzes the data acquired and determines the application to be notified. A verification unit that verifies the legitimacy of the application to be notified, A notification unit notifies the appropriate application whose legitimacy has been confirmed among the notification targets of the acquisition unit of the data acquired by the acquisition unit. It is a computer program written in a computer-readable format so that it can function as such.

[0014] A computer program according to a third aspect of the present disclosure defines a computer program described in a computer-readable format so as to implement a predetermined process on a computer. In other words, by installing the computer program according to the third aspect of the present disclosure on a computer, a collaborative effect is exerted on the computer, and the same operational effects as those of the information processing apparatus according to the first aspect of the present disclosure can be obtained.

[0015] Further, a fourth aspect of the present disclosure is an information processing apparatus equipped with a device for performing a transaction with an external device and installed with an application for providing a service related to the transaction, a notification unit that notifies the application of data to be processed in the transaction, and a presentation unit that presents the information regarding the data to be processed received by the application. The information processing apparatus includes these components.

[0016] Further, a fifth aspect of the present disclosure is an information processing method executed by an application in a device equipped with a device for performing a transaction with an external device and installed with an application for providing a service related to the transaction, a receiving step of receiving data to be processed in the transaction, and a presenting step of presenting information regarding the received data to be processed. The information processing method includes these steps.

[0017] Further, a sixth aspect of the present disclosure is an information processing apparatus equipped with a device for performing a transaction with an external device and installed with an application for providing a service related to the transaction, a receiving unit that receives data to be processed in the transaction, and a presenting unit that presents information regarding the received data to be processed. A computer program described in a computer-readable format so as to function as such.

Advantages of the Invention

[0018] According to the present disclosure, it is possible to provide an information processing apparatus, an information processing method, and a computer program that notify appropriate applications of information regarding transactions executed between devices within the main body and external devices.

[0019] Note that the effects described in this specification are merely examples, and the effects brought about by the present disclosure are not limited thereto. Further, the present disclosure may have additional effects other than the above effects.

[0020] Still other objects, features, and advantages of the present disclosure will become apparent from more detailed descriptions based on the embodiments described later and the attached drawings.

Brief Description of the Drawings

[0021] [Figure 1] FIG. 1 is a diagram showing an example of the hardware configuration of the information processing apparatus 100. [Figure 2] FIG. 2 is a diagram showing the internal configuration of the secure element unit 114. [Figure 3] FIG. 3 is a diagram showing a data structure for storing transaction processing target data in the memory 204 within the secure element unit 114. [Figure 4] FIG. 4 is a diagram showing an example of the configuration of data related to transaction processing. [Figure 5] FIG. 5 is a diagram showing the stack structure of software operating on the information processing apparatus 100. [Figure 6] FIG. 6 is a diagram showing an example of operations between software layers when notifying the SP application of transaction information. [Figure 7]Figure 7 is a flowchart showing the processing procedure for notifying the SP application of transaction information between the secure element unit 114 and the reader / writer 120. [Figure 8] Figure 8 shows a schematic example of the operation between software layers when verifying the legitimacy of an SP application. [Figure 9] Figure 9 shows an example of a processing sequence for verifying the legitimacy of an SP application that has been notified of a transaction. [Figure 10] Figure 10 shows the data structure of SP application attribute information obtained from the SIM server. [Figure 11] Figure 11 shows the data structure of the header portion that identifies the uniqueness of a transaction. [Figure 12] Figure 12 shows the data structure of the payload information for a payment transaction. [Figure 13] Figure 13 shows the data structure of the payload information for transactions other than payments. [Figure 14] Figure 14 shows an example of how the screen is updated in response to the occurrence of a transaction. [Figure 15] Figure 15 shows another example of updating the screen in response to a transaction. [Modes for carrying out the invention]

[0022] The present disclosure will be described below in the following order, with reference to the drawings.

[0023] A. Equipment configuration B. Functional Configuration of Secure Elements C. Software Configuration D. Transaction notification function Verification process for the legitimacy of E.SP applications F. effect

[0024] A. Equipment configuration Figure 1 schematically shows an example of the hardware configuration of the information processing device 100 to which this disclosure applies. While the information processing device 100 is assumed to be a multi-functional information terminal such as a smartphone or tablet equipped with a secure element, other types of information devices such as personal computers (PCs) may also be used.

[0025] The illustrated information processing device 100 includes a CPU (Central Processing Unit) 101, a ROM (Read Only Memory) 102, a RAM (Random Access Memory) 103, a host bus 104, a bridge 105, an expansion bus 106, an interface unit 107, an input unit 108, an output unit 109, a storage unit 110, a drive 111, a communication unit 113, and a secure element (SE) unit 114.

[0026] The CPU 101 functions as an arithmetic processing unit and control unit, and controls the overall operation of the information processing unit 100 according to various programs. The ROM 102 non-volatilely stores programs used by the CPU 101 (such as the basic input / output system) and arithmetic parameters. The RAM 103 is used to load programs used in the execution of the CPU 101 and to temporarily store parameters such as work data that change as needed during program execution. Programs loaded into the RAM 103 and executed by the CPU 101 include, for example, various application programs, operating systems (OS), and middleware (MW).

[0027] The CPU 101, ROM 102, and RAM 103 are interconnected by a host bus 104, which consists of a CPU bus and other components. Through the collaborative operation of ROM 102 and RAM 103, the CPU 101 can execute various application programs within the execution environment provided by the OS, thereby realizing a variety of functions and services. If the information processing device 100 is a smartphone or tablet, the OS is, for example, Google's Android. Furthermore, the application programs include SP applications distributed by an SP provider related to the service functions of the secure element.

[0028] The host bus 104 is connected to the expansion bus 106 via the bridge 105. However, the information processing device 100 does not need to be configured in a way that isolates its circuit components from the host bus 104, bridge 105, and expansion bus 106; it may be implemented in a way that almost all circuit components are interconnected by a single bus (not shown).

[0029] The interface unit 107 connects peripheral devices such as the input unit 108, output unit 109, storage unit 110, drive 111, communication unit 113, and secure element (SE) unit 114 in accordance with the standards of the expansion bus 106. However, not all of the peripheral devices shown in Figure 1 are necessarily required for the information processing device 100 to operate as an information terminal such as a smartphone or tablet, and the information processing device 100 may include additional peripheral devices not shown. Furthermore, the peripheral devices may be built into the main body of the information processing device 100, or some peripheral devices may be externally connected to the main body of the information processing device 100.

[0030] The input unit 108 consists of an input control circuit and the like that generates an input signal based on user input and outputs it to the CPU 101. If the information processing device 100 is an information terminal such as a smartphone or tablet, the input unit 108 may be, for example, a touch panel or a microphone, but it may also include other mechanical controls such as buttons. Furthermore, if the information processing device 100 is an information terminal such as a smartphone or tablet, the input unit 108 may also include a camera mounted on the information terminal.

[0031] The output unit 109 includes, for example, a liquid crystal display (LCD) device, an organic EL (Electro-Luminescence) display device, and an LED (Light Emitting Diode) display device, and displays various data such as video data as images or text, or displays a GUI (Graphical User Interface) screen. The output unit 109 also includes audio output devices such as speakers and headphones, and converts audio data and other data into audio and outputs it.

[0032] The storage unit 110 stores files such as programs (applications, OS, middleware, etc.) and various data executed by the CPU 101. The storage unit 110 is composed of a large-capacity storage device such as an SSD (Solid State Drive), but may also include an external storage device such as an HDD (Hard Disk Drive).

[0033] The removable storage medium 112 is a storage medium configured in a cartridge format, such as a microSD card. The drive 111 performs read and write operations on the inserted removable storage medium 113. The drive 111 outputs data (such as still images or videos) read from the removable storage medium 112 to the RAM 103, and writes data on the RAM 103 to the removable storage medium 112.

[0034] The communication unit 113 is a device that performs wireless communication such as cellular communication networks like 4G and 5G, or Wi-Fi® and Bluetooth®. Furthermore, the communication unit 113 may also be equipped with terminals such as HDMI® (High-Definition Multimedia Interface) and may have a function to perform HDMI® communication with a display or the like.

[0035] The secure element (SE) unit 114 is a device protected by tamper-resistant hardware, known as an IC chip or RFID tag. Tamper resistance means that internal analysis (reverse engineering) and modification are extremely difficult, and this is achieved through logical means such as obfuscation to prevent analysis, or physical means such as destroying the circuit if the protective layer is removed. The secure element unit 114 also enables secure contactless communication with the reader / writer 120 using mutual authentication and encryption. Contactless communication is performed using electromagnetic waves emitted from the reader / writer 120. The communication is symmetrical communication that does not use subcarriers, and is performed at a speed of 212kbps / 424kbps using the 13.56MHz frequency band.

[0036] B. Functional Configuration of Secure Elements The secure element unit 114 can manage multipurpose data within a single secure element module. Individual access rights can be set for each piece of data in the memory within the secure element unit 114, thereby enabling secure interoperability between applications.

[0037] When the information processing device 100 is held over the reader / writer 120, and the secure element unit 114 enters the range of the carrier wave from the reader / writer 120, a transaction is performed between the secure element unit 114 and the reader / writer 120 asynchronously with the operation of the main unit of the information processing device 100 (or without requiring application startup and without prior notice). The transaction referred to here is the processing related to various service functions such as credit card function, ticket function, personal authentication function, train ticket function, electronic money, or payment function. Transactions can be performed securely by utilizing the tamper resistance of the secure element unit 114.

[0038] Within the secure element unit 114, transaction data (such as electronic money) is stored in a secure memory area (described later) that prevents data tampering, data leakage, and unauthorized use by eliminating direct external access. Furthermore, in this embodiment, transaction processing data is also stored within the secure element unit 114. Transaction processing data includes information that allows recognition of "processing of service ID XX has occurred" (e.g., "processing of service ID XX has occurred").

[0039] Figure 2 schematically shows the internal configuration of the secure element unit 114. The secure element unit 114 consists of an antenna unit 201, an analog unit 202 connected to the antenna unit 201, a digital control unit 203, a memory 204, and an external interface (external IF) 205, and is mounted on the information processing device 100. The secure element unit 114 may be configured as a single-chip semiconductor integrated circuit, or it may be configured as a two-chip semiconductor integrated circuit by separating the RF analog front end and the logic circuit unit.

[0040] The antenna unit 201 and the analog unit 202 constitute a contactless interface between the secure element unit 114 and the reader / writer 120. The antenna unit 201 transmits and receives contactless data with the reader / writer 120. The analog unit 202 processes the analog signals transmitted and received from the antenna unit 201, including detection, modulation / demodulation, and clock extraction. The reader / writer 120 transmits a modulated carrier wave containing a data read request or data write request, and an unmodulated carrier wave for reply from the secure element unit 114. The analog unit 202 reflects and transmits a carrier wave with the reply data superimposed on the unmodulated carrier wave from the antenna unit 201. For contactless communication with the reader / writer 120, for example, an NFC communication method is used. Furthermore, secure contactless communication is possible with the reader / writer 120 using mutual authentication and encryption.

[0041] The digital control unit 203 comprehensively controls the processing of data transmitted and received between the reader / writer 120 and other operations within the secure element unit 114. The digital control unit 203 also has a locally connected addressable memory 204. The memory 204 is composed of a non-volatile storage device such as an EEPROM (Electrically Erasable Programmable Read Only Memory) and is used to store data related to various service functions (i.e., data subject to transaction processing) such as ticket functions, electronic money or payment functions, credit card functions, ticket functions, and personal authentication functions. The digital control unit 203 constructs a hierarchical structure (see Figure 3) in the memory space of the memory 204 to store the data subject to transaction processing. Furthermore, in this embodiment, data related to transaction processing (see Figure 4) is also stored in the memory 204. The memory 204 may also be used to write program code executed by the digital control unit 203 or to save working data during program execution.

[0042] The external interface 205 is a functional module that allows the digital control unit 203 to connect to the main body of the information processing device 100 via a wired connection, in accordance with the interface protocol for connecting to the interface unit 107 on the information processing device 100 side. Data written to the memory 204 can be transferred to the main body of the information processing device 100 (CPU 101 or RAM 103) via the external interface 205. In addition, the information processing device 100 side (for example, a software program executed by the CPU 101) can perform operations such as reading and writing data to the memory 204 via the external interface 205 and the digital control unit 203.

[0043] Figure 3 schematically shows the data structure in the memory area that stores transaction processing target data, which is constructed in the memory 204 within the secure element unit 114. This memory area is accessible under the control of the digital control unit 203 and is a secure memory area that prevents data tampering, data leakage, and unauthorized use by eliminating direct access from the outside. In the illustrated memory area, data is managed in a hierarchical structure using units called "area," "service," and "user block data."

[0044] An "area" corresponds to a "directory" or "folder," and it is possible to create further areas hierarchically under an area. Areas are formed, for example, on a per-service provider basis, but if the secure element unit 114 supports multiple service providers, multiple areas may be formed within the memory 204. Of course, multiple areas may be formed for a single service provider, and a single area may be shared by multiple service providers.

[0045] A "service" is a concept that manages access rights or encryption methods for data. Specifically, data stored under a service is controlled based on the access rights or encryption methods defined for that service. For example, suppose service A in Figure 3 stores unencrypted data, and service B stores data encrypted using a predetermined encryption method. In this case, user block data A-1 and user block data A-2, which are relatively less important data, can be stored under service A without encryption. On the other hand, user block data B-1, which is relatively more important data, can be encrypted using the encryption method defined by service B and stored under service B. Multiple services can exist in each hierarchical structure.

[0046] "User block data" refers to a storage area or the data itself that stores data used in processing the secure element section 114 (i.e., data to be processed), and multiple instances may exist for each hierarchical structure.

[0047] In this embodiment, transaction processing data (see Figure 4) is also stored in memory 204. Figure 4 shows an example of the configuration of transaction processing data.

[0048] In the example shown in Figure 4, the data for each transaction process includes the path to the data to be processed in the memory area (see Figure 3), the data to be processed itself, and the hash value of the data to be processed.

[0049] When the digital control unit 203 performs a transaction with the reader / writer 120, it stores the data to be processed and the path to the data to be processed in the memory area (see Figure 3) as data related to the processing of that transaction. Furthermore, the digital control unit 203 calculates the hash value of the data to be processed and stores that hash value together with the data related to the processing of that transaction.

[0050] The digital control unit 203 may add data other than the data shown in Figure 4 as appropriate. For example, the digital control unit 203 may add data related to the attributes of the data to be processed (e.g., content, type, or importance). The digital control unit 203 may also replace the data shown in Figure 4 with other equivalent data. For example, the digital control unit 203 may replace the path of the data to be processed with any data that can identify the data to be processed. The digital control unit 203 may also calculate a hash value that includes not only the data to be processed but also data other than the data to be processed (e.g., the path of the data to be processed). This allows the main body of the information processing device 100 to verify the integrity of the data, including not only the data to be processed but also data other than the data to be processed.

[0051] C. Software Configuration Figure 5 schematically shows the software stack structure running on the information processing device 100. The software stack consists of, from the bottom layer upwards, a device driver layer, an OS layer, a middleware layer, and an application layer.

[0052] Device driver layer: The lowest level device driver layer consists of a collection of device drivers that individually control each piece of hardware included in the information processing device 100. Here, "hardware" refers to each individual hardware component that makes up the input unit 108, output unit 109, storage unit 110, drive 111, communication unit 113, etc., each equipped with a device driver for drive control. In this embodiment, a device driver for the secure element unit 114 (indicated as "SE driver" in Figure 5) is also provided. However, device drivers other than the SE driver are general and not directly related to this disclosure, so only a minimal explanation is provided herein.

[0053] A device driver has the function of notifying the OS of an event when an event occurs in the corresponding device. Event notification is performed, for example, by processes such as interrupt generation or polling. In the case of an SE driver, for example, the occurrence of an event can be detected by receiving an interrupt signal from the external interface unit 205 in the secure element unit 114 or by polling the status register in the external interface unit 205. Specifically, the SE driver, using the function of the "contactless communication applet," notifies the OS when it detects the start and end of contactless communication between the secure element unit 114 and the reader / writer 120 (or the on and off events of the carrier wave from the reader / writer 120 when the secure element unit 114 receives it).

[0054] Furthermore, the device driver controls device-specific hardware operations, such as data input / output operations and device driving operations for the corresponding device. For example, the SE driver has the function of performing transactions such as reading data and writing data to memory 204 through the external interface unit 205 within the secure element unit 114 in response to access requests from higher layers to the secure element unit 114 (specifically, access requests from applications (SP apps) via middleware). This function is implemented by a "transaction applet". The OS and middleware can access the transaction applet via OMAPI (Open mobile API). The transaction applet stores the data to be processed by the transaction. The data to be processed by the transaction is handled in units called APDUs (Application Protocol Data Units).

[0055] The structure of the memory space that stores the data to be processed by a transaction in the memory 204 within the secure element unit 114 is as already described with reference to Figure 3. In this embodiment, a mechanism is introduced that allows the content of the process (for example, "processing for service ID XX has occurred") to be recognized when a write operation occurs from the reader / writer 120 to the memory 204.

[0056] OS layer: An operating system (OS) provides an execution environment for applications, consisting of functions commonly used by many applications and basic hardware control functions. For example, if the information processing device 100 is an information terminal such as a smartphone or tablet, then Google's Android would be the OS. If the OS is Android, information related to the entire system, such as event notifications from the device driver, is transmitted to all applications using a mechanism called "BroadcastIntent." An Intent is a message object exchanged between one or more activities or services included in an application running on Android.

[0057] Middleware layer: Middleware sits between the OS and applications, providing functions that are commonly used by various software. For example, specific or individual functions limited to a particular field or application are provided by middleware rather than the OS. Since not all information terminals such as smartphones and tablets are equipped with secure elements, in this embodiment, functions related to the use of the secure element unit 114 are provided as middleware. GUI functions, etc., are also provided as middleware. However, middleware functions unrelated to the secure element unit 114 are not directly relevant to this disclosure, and are therefore described only briefly in this specification.

[0058] In this embodiment, the functions related to the use of the secure element unit 114 provided by the middleware include an "SE access client" and a "service integration client". The "SE access client" is a function that performs access operations to the secure element unit 114. The "service integration client" is a function that manages information about services being used in the secure element unit 114 in cooperation with a server (hereinafter referred to as the "service integration server") (not shown in Figure 5).

[0059] Application layer: The top-level application layer consists of a collection of application software used according to their respective work purposes. Each application software achieves its respective work purpose using functions provided by the OS and middleware. For example, it is assumed that application software such as telephone, email, camera, and calendar / schedule management are installed on the information processing device 100. These common application software are not directly related to this disclosure and are therefore described only briefly in this specification.

[0060] Furthermore, in this embodiment, it is assumed that one or more SP applications that provide service functions (such as ticketing functions, electronic money or payment functions, credit card functions, ticketing functions, and personal authentication functions) using the secure element unit 114 are installed on the information processing device 100. The information processing device 100 on which such SP applications are installed can operate as an IC card that provides the corresponding service functions. The service integration client manages a service ID that identifies the service to be used and a card ID (CID) that identifies the card that can be referenced from the SP application for each SP application installed on the information processing device 100.

[0061] When an SP application actively accesses information within the secure element unit 114, the SP application must acquire exclusive access rights to the secure element unit 114. Generally, the SP application submits an access request procedure to the service integration client, and the service integration client queries the service integration server to verify the legitimacy (identity) of the SP application and to perform operations on secure elements permitted to the SP application, after which the SP application acquires exclusive access rights to the secure element unit 114. Therefore, when an SP application attempts to access the secure element unit 114, it requires processing time, network load, and server load associated with acquiring access rights to the secure element unit 114.

[0062] An SP application that has acquired exclusive access rights to the secure element unit 114 can access the secure element unit 114 through the SE access client, which is a middleware function, and perform data read or write operations to the memory 204 within the secure element unit 114.

[0063] Furthermore, to ensure the security of the secure element 114, it is undesirable for SP applications to have unlimited access. Therefore, the SE access client is designed to verify SP applications that request access to the secure element 114 and to restrict access by prohibiting simultaneous access to the secure element 114 by multiple SP applications.

[0064] D. Transaction notification function The information processing device 100, on which the SP application is installed, can operate as an IC card that provides the corresponding service function. For example, a transaction occurs between the secure element unit 114 installed in the information processing device 100 and the reader / writer 120 through a manual operation by the user, such as holding the information processing device 100 over the reader / writer 120.

[0065] Such transactions occur without requiring the SP application to be launched and without prior notification to the SP application. Therefore, in order for the SP application to display the balance, etc., the SP application needs to know the latest information stored in the memory 204 within the secure element unit 114.

[0066] As explained in section C above, the SE access client within the middleware restricts access to the secure element section 114 to ensure security (such as verifying SP applications and prohibiting simultaneous access by multiple SP applications). Under these access restrictions, if each SP application attempts to periodically and proactively access the memory 204 within the secure element section 114 to obtain the latest information, a problem arises where conflicts in access from multiple SP applications are likely to occur.

[0067] Furthermore, since the SP application only accesses the memory 204 periodically, it cannot immediately detect changes in the information that occur without prior notice, resulting in a lack of real-time information acquisition by the SP application from the memory 204. Moreover, even if no changes occur in the information in the memory 204, the SP application needs to access it periodically, resulting in unnecessary processing. When the SP application accesses the secure element unit 114, the service integration client needs to access the service integration server to verify the legitimacy of the SP application and obtain a list of cards that can be referenced by the SP application. This results in a processing load on the information processing device 100 due to network connectivity, and also increases the server load.

[0068] Therefore, this disclosure proposes a method for providing a function that notifies the necessary SP application of transaction information, primarily through the functions of the service integration client within the middleware, when a transaction occurs between the secure element unit 114 and the reader / writer 120. Simply adding a notification function would risk notifying fraudulent or unrelated SP applications, potentially leading to the leakage of sensitive payment information. Therefore, this disclosure combines the determination of which SP applications require notification with verification of the legitimacy of the SP applications before notifying them of the transaction information.

[0069] Figure 6 shows an example of software layer operation when transaction information between the secure element unit 114 and the reader / writer 120 is notified to the SP application.

[0070] First, a transaction occurs between the secure element unit 114 mounted on the information processing device 100 and the reader / writer 120 through a manual operation by the user, where the user holds the information processing device 100 over the reader / writer 120 (S601). Such a transaction occurs without prior notice to the related SP application. During the transaction, a carrier wave is transmitted from the reader / writer 120. The carrier wave includes a modulated carrier wave containing a data read request or data write request from the reader / writer 120, and an unmodulated carrier wave for the reply from the secure element unit 114. At that time, the transaction data is stored in a transaction applet.

[0071] When the SE driver's contactless communication applet detects that a transaction has occurred between the secure element unit 114 and the reader / writer 120, it notifies the OS of an event (S602). Upon detecting the event, the OS sends a broadcast to notify the higher layer that the system state has changed (S603).

[0072] When the service integration client within the middleware receives a Broadcast from the OS notifying it of an event, it accesses the transaction applet via OMAPI. The service integration client then retrieves the data to be processed for the relevant transaction (APDU) from the secure element unit 114 through the transaction applet (S604). At the same time, the service integration client retrieves data related to the transaction processing along with the data to be processed for the transaction.

[0073] Next, the service integration client analyzes the acquired data for each SP (Service Provider) to determine which SP applications need to be notified of transaction information (S605). The data related to transaction processing, acquired along with the data to be processed by the transaction, contains information that allows recognition such as "processing occurred for service ID XX." Therefore, by analyzing the data related to transaction processing, the service integration client can identify the service ID associated with that transaction and determine which SP applications need to be notified based on that service ID.

[0074] Next, the service integration client verifies the legitimacy of each SP application determined to be subject to notification (S606). The service integration client verifies the legitimacy of the SP application based on verification information obtained in advance from the server. Specifically, the package name and signature value of the SP application are used as verification information. The Service Information Management (SIM) server manages information including verification information for each SP application. Details of the verification process for the legitimacy of notification-submitted SP applications will be described later.

[0075] The service integration client then notifies the appropriate SP application, whose legitimacy has been verified, of the transaction information (S607). Details of the transaction information notified to the SP application will be discussed later.

[0076] Furthermore, when sending notifications to multiple SP apps, information should be sent between SP apps at predetermined time intervals. This is because an SP app may initiate access to the secure element 114 upon receiving notification of transaction information. Possible causes of access include automatic charging due to a decrease in balance after a transaction, and the process of reading the point balance associated with payment.

[0077] Figure 7 shows a flowchart illustrating the processing procedure for notifying the SP application of transaction information performed between the secure element unit 114 and the reader / writer 120 within the information processing device 100. The illustrated processing procedure is primarily implemented by the service integration client included in the middleware layer.

[0078] The service integration client is notified via the OS of an event indicating that a transaction has been executed between the secure element unit 114 and the reader / writer 120 (Yes in step S701).

[0079] In response to this event notification, the service integration client accesses the transaction applet in the SE driver via OMAPI to retrieve the data to be processed by the transaction and data related to the transaction processing (step S702).

[0080] Next, the service integration client analyzes the acquired data for each SP (Service Provider) to determine which SP applications need to be notified of transaction information (step S703). Since the data related to transaction processing includes information that allows recognition such as "processing occurred for service ID XX," the service integration client can identify the corresponding service ID through data analysis and determine which SP applications should be notified based on that service ID.

[0081] Next, the service integration client verifies the legitimacy of each SP app determined to be subject to notification, based on the verification information for each SP app obtained in advance from the SIM server (step S704). Details of the verification process for the legitimacy of notification-submitted SP apps will be described later.

[0082] The service integration client then notifies the appropriate SP application, whose legitimacy has been verified, of the transaction information (step S705). Details of the transaction information notified to the SP application will be described later.

[0083] Verification process for the legitimacy of E.SP applications Section E provides a detailed explanation of the verification process for the legitimacy of an SP application, which is performed when the SP application to be notified is determined in the transaction notification function described in Section D above.

[0084] Figure 8 shows a schematic example of the inter-software layer operations when verifying the legitimacy of an SP application that has been notified of a transaction.

[0085] As a preprocessing step, the service integration client obtains verification information for each SP application installed on the information processing device 100 from the SIM server in advance (S801). The verification information consists of information that uniquely identifies the SP application, such as the package name, and the SP application signature value (such as the application signer certificate hash).

[0086] Subsequently, when a transaction occurs between the secure element unit 114 and the reader / writer 120, the service integration client can detect the event by receiving a broadcast from the OS.

[0087] The service integration client analyzes the data obtained through the transaction applet for each service provider (SP) to determine which SP applications will receive notification of the transaction information. Then, it uses verification information previously obtained from the SIM server to verify the legitimacy of each SP application to be notified (S802). Finally, the service integration client notifies each SP application that has successfully passed the legitimacy verification of the transaction information.

[0088] The SP app can quickly display information that has changed due to a transaction, such as the balance, using transaction information notified from the service integration client. The SP app also works in conjunction with the SP server to send user notifications and access the secure element unit 114 (S803). Specifically, the SP app works in conjunction with the SP server to access the secure element unit 114 and perform procedures with the service provider regarding the relevant service functions, such as auto-charging due to a decrease in the balance after a transaction and reading the point balance associated with payment.

[0089] Figure 9 shows an example of a processing sequence between software modules to verify the legitimacy of the SP application that was notified of a transaction. Due to space limitations, Figure 9 only shows two applications, SP application A and SP application B, as recipients of the transaction notification. Also, for the sake of simplicity, it is assumed that both SP application A and SP application B successfully pass the legitimacy verification.

[0090] The service integration client requests attribute information for each SP application installed on the information processing device 100 from the SIM server (SEQ901). In response, the SIM server returns the requested attribute information for each SP application (SEQ902). The attribute information for each SP application includes verification information, and obtaining attribute information from the SIM server is a pre-processing step to verify the legitimacy of the SP application. For example, each time the middleware is started, the service integration client periodically checks the SIM server for update information and obtains the latest attribute information for each installed SP application in advance.

[0091] Figure 10 shows, for reference, an example of the data structure of SP application attribute information obtained by the service integration client from the SIM server. More precisely, the service integration client obtains a list of data like the one shown in Figure 10 for each SP application from the SIM server. The following explains each piece of data.

[0092] The "Service ID" consists of a value that uniquely represents the service performed by the SP application. For example, if the SP application performs payments, the Service ID would be a value that uniquely represents the payment service. Generally, the Service ID is an alphanumeric string such as "SV123456" issued by the middleware developer (the platform provider that provides the secure element).

[0093] "Information that uniquely identifies an SP app" is the package name of the SP app, such as "com.spapp.app". "Signature value" is, for example, a hexadecimal hash of the SP app's signer certificate. The legitimacy of the SP app can be verified by obtaining the SP app's signer certificate from the OS, calculating the hash value, and comparing that hash value with the signature value included in the SP app's attribute information.

[0094] "Priority," "Notification Deadline," and "Action on Notification Deadline Exceeded" are parameters that define the notification behavior when multiple SP applications are legitimate notification targets. "Priority" indicates the priority for notifying transaction information, with a value from 1 to 10. If multiple SP applications are legitimate notification targets, transaction information will be notified in order from the SP application with the highest priority. "Notification Deadline" indicates the amount of time the SP application is allowed to delay notification, with a value from 0 to 3. "Action on Notification Deadline Exceeded" indicates, with a value of 0 or 1, whether to abandon notification or proceed with notification when the delay time specified in "Notification Deadline" is exceeded.

[0095] Referring again to Figure 9, we will explain the processing sequence for verifying the legitimacy of the SP application.

[0096] Subsequently, when a transaction occurs between the secure element unit 114 and the reader / writer 120, the service integration client identifies the SP applications to be notified and performs a verification process to confirm the legitimacy of each SP application to be notified (in the example shown in Figure 9, SP applications A and B).

[0097] In this legitimacy verification process, the service integration client first identifies the SP applications to be notified. The service integration client analyzes the transaction processing data to identify the service ID, and then compares it with the attribute information of each SP application obtained in advance during preprocessing (see Figure 10) to identify the SP applications with matching service IDs as those to be notified. In the example processing sequence shown in Figure 9, two applications, SP application A and SP application B, are identified as those to be notified.

[0098] Next, the service integration client requests verification information for each SP application to be notified by each SP (SEQ903), and the OS replies with the verification information for each SP application (SEQ904). Smartphone operating systems such as Google's Android obtain the verification information for each SP application through mutual authentication procedures performed during application installation. Therefore, the service integration client can obtain the verification information for each SP application to be notified by querying the OS.

[0099] Next, the service integration client verifies the legitimacy of each SP application targeted for notification (SEQ905). The service integration client verifies the legitimacy of each SP application by comparing the verification information contained in the attribute information of each SP application targeted for notification with the verification information of the corresponding SP application obtained from the OS. If they match, the SP application can be determined to be legitimacy. In the example processing sequence shown in Figure 9, the legitimacy of both SP applications A and B, which were identified as targets for notification, has been confirmed.

[0100] For example, smartphones using Android as their operating system can install applications from sources other than the official app store. In such cases, a user may mistakenly install an application that has been created to look and sound like a genuine application, believing it to be legitimate. As a result, there is a risk that information within the secure element unit 114 may be leaked, misused, or altered through the application. In contrast, this embodiment verifies the legitimacy of an SP application using verification information that combines the SP application's package name and signature value. This eliminates malicious SP applications and prevents information within the secure element unit 114 from being leaked, misused, or altered.

[0101] The service integration client then notifies the SP applications whose legitimacy has been confirmed of the transaction data. In the example processing sequence shown in Figure 9, since legitimacy has been confirmed for both SP application A and SP application B, the notification process is first performed on SP application A (SEQ906), and then on SP application B (SEQ907).

[0102] When sending notifications to multiple SP apps, notifications are sent in order of priority, based on the attribute information of each SP app. In the example shown in Figure 9, SP app A has a higher priority than SP app B.

[0103] Furthermore, after performing notification processing (SEQ906) on SP app A, a predetermined time interval (T) is set before performing notification processing (SEQ907) on SP app B. This is because both SP app A and SP app B, upon receiving the notification, may receive the transaction information and initiate access to the secure element unit 114. Possible causes of access include auto-charging due to a decrease in balance after a transaction, and the process of reading the point balance associated with payment. If the time interval between notifications between SP apps is not sufficiently long, there is a risk that processes such as access to the secure element unit 114 may conflict between SP app A and SP app B, which received notifications before and after each other.

[0104] If a conflict occurs between SP apps that receive notifications one after the other, the processing of the SP app that received the notification first will be completed before the processing of the next SP app begins. In this case, a notification delay will occur for the SP app that receives the notification later. For notification deadlines that allow for delays, or for cases where the notification deadline has been exceeded, the parameters included in the attribute information of each SP (see Figure 10) may be used.

[0105] Next, we will explain the data structure of transaction information that is notified from the service integration client to the SP application. This data structure consists of a header portion that identifies the uniqueness of the transaction and a payload corresponding to the type of transaction.

[0106] Figure 11 shows the data structure of the header portion that identifies the uniqueness of a transaction. The header portion that identifies the uniqueness of a transaction is a common data structure that does not depend on the type of transaction (settlement or non-settlement).

[0107] The Service ID is an identifier that uniquely identifies the service processed by the transaction (for example, the service for which payment was made). The CID is an identifier used to identify the card. The R / W ID is an identifier unique to the reader / writer that was the counterparty to the transaction. The location where it was used can be identified based on the R / W ID. The R / W usage date and time is the date and time the reader / writer was used (or the date and time the transaction was executed). The R / W transaction ID is an identifier for the transaction that occurred on the reader / writer. The usage type indicates the type of transaction, such as payment, charge, stamp, coupon, or ticket. The payload consists of a data structure corresponding to the usage type.

[0108] Figure 12 shows an example of the payload data structure for a payment transaction, illustrating the data structure of the payload information for a payment transaction. In the case of a payment, the payload includes data that is updated by the transaction, such as the amount used, balance, point increase / decrease, and point balance.

[0109] Figure 13 shows another example of a payload data structure depending on the type of transaction, specifically the payload data structure for transactions other than payments. In this case, the payload includes a service-specific ID and ticket / design information. The service-specific ID is a unique ID that can be defined by the service provider, such as a ticket ID or coupon ID. The ticket / design information defines the stamp and ticket design, such as an ID used in part of the trading partner's URL (Uniform Resource Locator). Note that the payload for payment-related transaction information may also include a service-specific ID and ticket / design information.

[0110] F. effect (1) Transactions are generated by a manual operation, such as holding the information processing device 100 over the reader / writer 120, and do not require the SP application to be launched or notified to the SP application. Conventionally, SP applications had to actively access the secure element unit 114 to obtain the latest data (such as usage amount, balance, point increase / decrease, and point balance) that had changed due to the transaction. In contrast, with the transaction information notification function related to this disclosure, all related SP applications can immediately detect that the data in the secure element unit 114 has changed due to a transaction. Specifically, this notification function to SP applications is realized by implementing the function shown in Figure 6 in the service integration client within the middleware. Therefore, with the notification function related to this disclosure, SP applications can grasp transaction information without accessing the secure element unit 114 and promptly present the latest information that has changed due to the transaction, such as balance display.

[0111] Furthermore, the transaction information notification function related to this disclosure minimizes the number of times SP applications access the secure element section 114, which is expected to shorten application startup time and reduce the rate of access conflicts among multiple SP applications. Suppressing access conflicts is particularly effective in situations where simultaneous access to the secure element section 114 by multiple SP applications is prohibited. Minimizing the number of accesses to the secure element section 114 eliminates the need for SP applications to apply to the service integration client and query the service integration server to monopolize the right to use the secure element section 114, thus reducing network and server load.

[0112] According to the transaction information notification function related to this disclosure, when data in the secure element unit 114 changes due to a transaction such as charging, the relevant SP application can immediately update information such as the balance, and always display the latest information on the screen of the information processing device 100.

[0113] Figure 14 shows an example of updating the screen in response to a change in data within the secure element unit 114 due to a transaction. Specifically, Figure 14 shows how the balance of the electronic money displayed on the smartphone screen is immediately updated to the latest information when a transaction (such as payment or charge) occurs.

[0114] When the information processing device 100 (smartphone) is held over the reader / writer 120 and a transaction such as payment or charging occurs, the information in the secure element unit 114 changes. Through the notification function related to this disclosure, the SP application to be notified is identified and its legitimacy is verified, and the latest information in the secure element unit 114 is notified to the SP application to be notified. As a result, as shown in Figure 14 (right), the SP application to be notified can immediately update and display the electronic money balance on the screen from the amount before the transaction (1,234 yen) to the amount after the transaction (5,678 yen). When updating the displayed amount, no user operation such as launching the SP application or exclusive use of the secure element unit 114 by the SP application is required.

[0115] Figure 15 also shows another example of updating the screen in response to changes in data within the secure element unit 114 due to a transaction. Specifically, Figure 15 shows how the balance of some electronic money changes immediately in the integrated balance display screen of a Wallet app that can use multiple types of electronic money due to a transaction (such as payment or charge).

[0116] When the information processing device 100 (smartphone) is held over the reader / writer 120 and a transaction such as payment or charging using electronic money C occurs, the information of electronic money C changes within the secure element unit 114. The notification function described in this disclosure determines that an SP app related to the electronic money C service is a notification target, and after verifying the legitimacy of that SP app, the latest information of electronic money C within the secure element unit 114 is notified to the notification target SP app. As a result, as shown in Figure 15 (right), the integrated balance display screen of the Wallet app can instantly update and display the balance of electronic money C. When updating the displayed amount, user operation such as launching the SP app corresponding to electronic money C, or the SP app occupying the right to use the secure element unit 114, is not required. Furthermore, the SP app that receives the notification can, in the background of the screen update process, acquire and display coupons based on the usage information of electronic money C, or even encourage the user to launch the SP app, thereby realizing a UX (User Experience).

[0117] Incidentally, when an SP application actively retrieves information from the secure element unit 114 as before, the SP application generally submits an application to the service integration client, and after the service integration client verifies the legitimacy (identity) of the SP application and requests operations on the secure element permitted to the SP application, the SP application gains exclusive use rights to the secure element unit 114. Therefore, if the SP application is launched and attempts to present the latest data from the secure element unit 114 (such as balance information) as before, it requires processing time, network load, and server load due to the exclusive use rights to the secure element unit 114.

[0118] (2) The transaction information notification function relating to this disclosure allows information such as the data to be processed in a transaction to be notified to multiple related SP applications. Specifically, this simultaneous notification function to multiple SP applications is realized by implementing the data analysis and SP determination functions shown in Figure 6 in the service integration client within the middleware. As a result of being able to notify multiple SP applications of transaction information, for example, multiple SP applications using the same electronic money can each update their information.

[0119] The transaction information notification function related to this disclosure can also be said to be able to control which SP applications receive notifications. Even if a transaction occurs between the secure element unit 114 and the reader / writer 120, it is possible to determine that only SP applications that need the resulting changed information should be notified, and information should not be notified to SP applications that should not receive notifications.

[0120] (3) The transaction information notification function related to this disclosure allows for verification of the legitimacy of SP applications that have been determined to be subject to notification, preventing transaction information from being passed to malicious applications. For example, malicious SP applications may be created that disguise their appearance and package name to resemble genuine ones. This disclosure verifies the legitimacy of SP applications using verification information that combines the SP application's package name and the SP application's signature value, thereby eliminating malicious SP applications and preventing information within the secure element section 114 from being leaked, misused, or altered. [Industrial applicability]

[0121] The present disclosure has been described in detail above with reference to specific embodiments. However, it will be obvious that those skilled in the art can modify or substitute these embodiments without departing from the gist of the present disclosure.

[0122] This specification has primarily described embodiments in which the Disclosure is applied to smartphones equipped with secure elements such as IC chips for contactless communication, but the gist of the Disclosure is not limited thereto. The Disclosure can also be applied to various types of information processing devices equipped with devices that perform transactions with external devices via wireless or wired means other than contactless communication, so that information about transactions performed between the device and the external device can be notified to the appropriate application.

[0123] In short, this disclosure has been explained in the form of examples, and the contents of this specification should not be interpreted restrictively. The claims should be considered in order to determine the gist of this disclosure.

[0124] Furthermore, this disclosure may also take the following form.

[0125] (1) An information processing device equipped with a device that performs transactions with an external device, A detection unit that detects when a transaction has occurred between the device and the external device, In response to the detection unit detecting the occurrence of the transaction, an acquisition unit acquires data from the device, The acquisition unit analyzes the data acquired and determines the application to be notified, A verification unit that verifies the legitimacy of the application to be notified, A notification unit that notifies the appropriate applications among the notification targets whose legitimacy has been confirmed, of the data acquired by the acquisition unit, An information processing device equipped with the following.

[0126] (2) The detection unit detects the occurrence of the transaction based on a signal from the operating system. The information processing device described in (1) above.

[0127] (3) The acquisition unit acquires data from the device via OMAPI. The information processing device described in either (1) or (2) above.

[0128] (4) The acquisition unit acquires the data to be processed by the transaction and the data related to the processing of the transaction. An information processing device as described in any of (1) to (3) above.

[0129] (5) The determination unit identifies the service ID related to the transaction based on the data acquired by the acquisition unit, and determines the application to be notified based on the service ID. Information processing as described in any of (1) to (4) above

[0130] (6) The determination unit analyzes the data relating to the processing of the transaction acquired by the acquisition unit to identify the service ID associated with the transaction. The information processing device described in (5) above.

[0131] (7) The verification unit verifies the validity of the application based on the application verification information obtained from the server and the application information obtained from the operating system. An information processing device as described in any of (1) to (6) above.

[0132] (8) Verification information includes the application's package name and signature value, The information processing device described in (7) above.

[0133] (9) The notification unit notifies the appropriate application of the data to be processed by the transaction. An information processing device as described in any of (1) to (8) above.

[0134] (10) If there are multiple suitable applications, the notification unit will send notifications between the applications at predetermined time intervals. An information processing device as described in any of (1) to (9) above.

[0135] (11) The notification unit provides notifications to the appropriate application based on application-specific information obtained from the server. An information processing device as described in any of (1) to (10) above.

[0136] (12) The information obtained from the server for each application includes at least one of the following: notification priority, notification deadline, and action to be taken when the notification deadline is exceeded. The information processing device described in (11) above.

[0137] (13) The device performs transactions with the external device via contactless communication. An information processing device as described in any of (1) to (12) above.

[0138] (13-1) The aforementioned contactless communication is a communication that performs mutual authentication and encryption. The information processing device described in (13) above.

[0139] (14) The transaction occurs without prior notice and does not require the startup of the application installed on the information processing device. An information processing device as described in any of (1) through (13) above.

[0140] (15) An information processing method in a device equipped with a device that performs transactions with an external device, A detection step that detects that a transaction has occurred between the device and the external device, In response to detecting the occurrence of the transaction in the detection step, an acquisition step is performed to acquire data from the device, A determination step involves analyzing the data acquired in the acquisition step to determine the application to be notified, A verification step to verify the legitimacy of the application to be notified, A notification step in which the data acquired in the acquisition is notified to the appropriate application whose legitimacy has been confirmed among the notification targets, An information processing method having

[0141] (16) An information processing device equipped with a device that performs transactions with an external device, A detection unit that detects when a transaction has occurred between the external devices of the aforementioned device, In response to the detection unit detecting the occurrence of the transaction, an acquisition unit acquires data from the device. The acquisition unit analyzes the data acquired and determines the application to be notified. A verification unit that verifies the legitimacy of the application to be notified, A notification unit notifies the appropriate application whose legitimacy has been confirmed among the notification targets of the acquisition unit of the data acquired by the acquisition unit. A computer program written in a computer-readable format to function as such.

[0142] (17) An information processing device equipped with a device that performs transactions with an external device and has an application installed that provides services related to the transaction, A notification unit that notifies the application of the data to be processed by the transaction, A display unit that displays the information regarding the data to be processed received by the application, An information processing device equipped with the following.

[0143] (18) The application and the server further provide an access unit that accesses the secure element through cooperation between the application and the server, The information processing device described in (17) above.

[0144] (19) An information processing method performed by an application in a device that is equipped with a device for performing transactions with an external device and has an application installed that provides services related to the transaction, A receiving step of receiving the data to be processed for the transaction, A presentation step in which information regarding the received data to be processed is presented, An information processing method having

[0145] (20) An information processing device equipped with a device that performs transactions with an external device and has an application installed that provides services related to the transaction, A receiving unit that receives the data to be processed for the aforementioned transaction, A display unit that displays information regarding the received data to be processed. A computer program written in a computer-readable format to function as such. [Explanation of Symbols]

[0146] 100... Information Processing Unit, 101... CPU, 102... ROM 103...RAM, 104...Host bus, 105...Bridge 106...Expansion bus, 107...Interface section, 108...Input section, 109…Output section, 110…Storage section, 111…Drive 112... Removable recording medium, 113... Communications section 114...Secure element section, 120...Reader / writer 201…Antenna section, 202…Analog section, 203…Digital section 204...Memory, 205...External Interface (External IF)

Claims

1. An information processing device equipped with a device that performs transactions with external devices, A detection unit that detects when a transaction has occurred between the device and the external device, In response to the detection unit detecting the occurrence of the transaction, an acquisition unit acquires data from the device, The acquisition unit analyzes the data acquired and determines the application to be notified, A verification unit verifies the legitimacy of the application to be notified based on application verification information obtained from a server that manages verification information for each application and application information obtained from the operating system. A notification unit that notifies the appropriate applications among the notification targets whose legitimacy has been confirmed, of the data acquired by the acquisition unit, An information processing device equipped with the following.

2. The detection unit detects the occurrence of the transaction based on an indication from the operating system. The information processing apparatus according to claim 1.

3. The acquisition unit acquires data from the device via OMAPI (Open Mobile API). The information processing apparatus according to claim 1.

4. The acquisition unit acquires the data to be processed by the transaction and the data related to the processing of the transaction. The information processing apparatus according to any one of claims 1 to 3.

5. The determination unit identifies the service ID related to the transaction based on the data acquired by the acquisition unit, and determines the application to be notified based on the service ID. Information processing according to claim 1

6. The determination unit analyzes the data related to the processing of the transaction acquired by the acquisition unit to identify the service ID associated with the transaction. The information processing apparatus according to claim 5.

7. Verification information includes the application's package name and signature value, The information processing apparatus according to claim 1.

8. The notification unit notifies the appropriate application of the data to be processed by the transaction. The information processing apparatus according to claim 1.

9. If there are multiple suitable applications, the notification unit shall provide notifications between the applications at predetermined time intervals. The information processing apparatus according to claim 1.

10. The notification unit provides notifications to the appropriate application based on application-specific information obtained from the server. The information processing apparatus according to claim 1.

11. The information for each application obtained from the server includes at least one of the following: notification priority, notification deadline, and action to be taken when the notification deadline is exceeded. The information processing apparatus according to claim 10.

12. The device performs transactions with the external device via contactless communication. The information processing apparatus according to claim 1.

13. The transaction occurs without prior notice and without requiring the startup of an application installed on the information processing device. The information processing apparatus according to claim 1.

14. An information processing method in a device equipped with a device that performs transactions with an external device, A detection step that detects that a transaction has occurred between the device and the external device, In response to detecting the occurrence of the transaction in the detection step, an acquisition step is performed to acquire data from the device, A determination step involves analyzing the data acquired in the acquisition step to determine the application to be notified, A verification step that verifies the legitimacy of the application to be notified based on application verification information obtained from a server that manages verification information for each application and application information obtained from the operating system, A notification step in which the data acquired in the acquisition is notified to the appropriate application whose legitimacy has been confirmed among the notification targets, An information processing method having

15. An information processing device equipped with a device that performs transactions with an external device, A detection unit that detects when a transaction has occurred between the external devices of the aforementioned device, In response to the detection unit detecting the occurrence of the transaction, an acquisition unit acquires data from the device. The acquisition unit analyzes the data acquired and determines the application to be notified. A verification unit verifies the legitimacy of the application to be notified based on application verification information obtained from a server that manages verification information for each application and application information obtained from the operating system. A notification unit notifies the appropriate application whose legitimacy has been confirmed among the notification targets of the acquisition unit of the data acquired by the acquisition unit. A computer program written in a computer-readable format to function as such.

Citation Information

Patent Citations

  • High-security verification method and high-security verification system for embedded devices

    CN103455750A

  • A method and apparatus for adapting a secure element access interface protocol.

    CN110557395B

  • IC module, IC card, portable terminal, and service processing method

    JP2005050262A

  • Information communication terminal, information processing method, and program

    JP2009049454A

  • Information processor and control method thereof

    JP2009199530A