Information processing device, information processing method, program, mobile terminal, and information processing system
The system determines storage locations for service information based on security levels and device capabilities, addressing secure management challenges for contactless card functions on mobile devices, ensuring secure storage for key-based services and flexible management for keyless services.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-25
- Publication Date
- 2026-04-08
AI Technical Summary
Mobile devices without a Secure Element (SE) storage mechanism struggle to securely manage service information for key-based services, while those without SE can insecurely manage keyless services, necessitating a solution for secure and easy implementation of contactless card functions across various mobile devices.
An information processing system determines the storage location for service information based on the security level and storage mechanism of the mobile device, utilizing SE, TEE, and terminal application to securely manage service information.
Enables secure and easy implementation of contactless card functions on diverse mobile devices by appropriately managing service information based on security levels and storage capabilities, ensuring secure storage for key-based services and flexible management for keyless services.
Smart Images

Figure 0007842696000001 
Figure 0007842696000002 
Figure 0007842696000003
Abstract
Description
Technical Field
[0004] , , , , , , ,
[0003]
[0001] The present disclosure relates to an information processing apparatus, an information processing method, a program, a mobile terminal, and an information processing system. In particular, the present disclosure relates to an information processing apparatus, an information processing method, a program, a mobile terminal, and an information processing system that enable various mobile terminals to easily and securely implement functions provided by using a non-contact card.
Background Art
[0002] A short-range wireless communication system using a non-contact card that consists of an IC (Integrated Circuit) card and performs wireless communication non-contact at a short distance is widely used. This non-contact card is well known for use as, for example, an electronic ticket for public transportation or electronic money. Recently, mobile terminals equipped with functions of electronic tickets for public transportation and electronic money by non-contact wireless communication have also become widespread.
[0003] In addition, by executing a terminal application, which is a dedicated application program managed by a non-contact card required for providing a service, on a mobile terminal to emulate a non-contact card function, it is also possible to implement a function provided by a service realized by using a non-contact card on the mobile terminal. These terminal applications reflect the user's intention and use an online server via a wireless LAN such as Wi-Fi defined by IEEE802.11, an online server using a mobile network provided by a mobile carrier, or short-range wireless communication such as Bluetooth (registered trademark) technology to appropriately download from servers and devices around the terminal, or to add to the terminal from an interface such as a USB cable to a personal computer offline. Similarly it is also easy to delete the terminal application according to the user's intention.
[0004] However, the service information managed by contactless cards, which is necessary for receiving services, includes highly confidential information such as key information. This enables authentication with the outside world, and provides a mechanism to access the service information only after successful authentication. Depending on the level of security required for the service information, key information may need to be managed, and if a similar mechanism is implemented, the service information must also be managed securely on the mobile device.
[0005] Therefore, a hardware called SE (Secure Element) has been proposed as a storage mechanism for storing highly confidential information in mobile devices (see Patent Documents 1 and 2). [Prior art documents] [Patent Documents]
[0006] [Patent Document 1] Japanese Patent Publication No. 2005-11469 [Patent Document 2] Japanese Patent Application Publication No. 8-328915 [Overview of the project] [Problems that the invention aims to solve]
[0007] As mentioned above, when implementing a service that utilizes contactless cards on a mobile device, if a key-based service is implemented where key information is essential, a secure storage mechanism such as SE is required on the mobile device, along with the aforementioned terminal application, because it contains highly confidential information such as key information.
[0008] Therefore, mobile terminals that do not have a service information storage mechanism like SE cannot securely manage service information, and thus cannot implement the function of receiving key-based services that are realized by contactless cards.
[0009] On the other hand, when implementing a keyless service that does not require key information used for mutual authentication, it is highly likely that it will not contain highly secure information, as access is possible regardless of the success or failure of mutual authentication. Therefore, management by a storage mechanism like SE may not be necessary. Of course, if the data written is token information that has temporary validity, the security level is high, but it can also be implemented on a keyless service because the impact of a system-wide leak is temporarily mitigated by concepts such as time. Generally, the data written to a keyless service, depending on the service provider's judgment, generally does not require security regarding access to the service itself, and in such cases, a keyless service is used.
[0010] Therefore, even mobile devices that do not have a storage mechanism like SE can implement contactless card-based keyless service functionality using only a terminal application.
[0011] Thus, in order to implement functions that allow users to receive services using contactless cards on a variety of mobile devices, it is necessary to address the security level of the service information and the type of storage mechanism that the mobile device has.
[0012] This disclosure is made in light of these circumstances, and in particular aims to enable the easy and secure implementation of services provided using contactless cards on a variety of mobile devices. [Means for solving the problem]
[0013] An information processing device, program, mobile terminal, and information processing system, as one aspect of this disclosure, is an information processing device, program, mobile terminal, and information processing system comprising a determination unit that determines a storage location for service information, which is information required when a mobile terminal receives services via a network, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal.
[0014] One aspect of this disclosure is an information processing method that includes the step of determining a storage location for service information, which is information required when a mobile terminal receives a service via a network, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal.
[0015] In one aspect of this disclosure, the storage location for service information, which is information required when a mobile terminal receives a service via a network, is determined based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. [Brief explanation of the drawing]
[0016] [Figure 1] This diagram illustrates an example configuration of the information processing system disclosed herein. [Figure 2] Figure 1 is a diagram illustrating the overview of the processing in the information processing system. [Figure 3] This is a diagram illustrating the use of contactless functionality. [Figure 4] This diagram illustrates the types of information that can be registered on a contactless card. [Figure 5] This is a flowchart that explains the details of the information registered on contactless cards. [Figure 6] This is a hardware diagram illustrating an example configuration of a mobile device. [Figure 7] This is a hardware diagram illustrating an example configuration of a service provider's server. [Figure 8] It is a flowchart for explaining a service information management location determination process. [Figure 9] It is a diagram for explaining a process of registering service information in the SE. [Figure 10] It is a diagram for explaining a process of registering service information in the SE. [Figure 11] It is a diagram for explaining a process of registering service information in the TEE. [Figure 12] It is a diagram for explaining a process of registering service information in the terminal app. [Figure 13] It is a diagram for explaining a process of registering HCE. [Figure 14] It is a diagram for explaining the switching of the face value display. [Figure 15] It is a diagram for explaining a configuration example of a general-purpose computer.
Embodiments for Carrying Out the Invention
[0017] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. In the present specification and drawings, components having substantially the same functional configuration are denoted by the same reference numerals, and redundant descriptions are omitted.
[0018] Hereinafter, embodiments for carrying out the present technology will be described. The description will be made in the following order. 1. Preferred Embodiments 2. Examples of Execution by Software
[0019] <<1. Preferred Embodiments>> <Configuration Example of the Information Processing System of the Present Disclosure> The present disclosure appropriately switches the management location of service information that needs to be managed based on the security level of the service information that needs to be managed and the type of storage function provided by the mobile terminal, so that the function of the contactless card can be easily and safely realized on various mobile terminals.
[0020] The technology disclosed herein is implemented by an information processing system 11 comprising, for example, mobile terminals 31-1 to 31-n, a management device 32, a service provider server 33, an eKYC provider server 34, an SE management server 35, an application management server 36, and a network 37, as shown in Figure 1.
[0021] Furthermore, unless otherwise necessary, mobile terminals 31-1 to 31-n will simply be referred to as mobile terminal 31, and the same will apply to other components.
[0022] The mobile terminal 31 is a device owned by the user, such as a smartphone. The mobile terminal 31 exchanges data with a card 21 consisting of a contactless card and a reader / writer (R / W) 22 via contactless communication such as NFC (Near Field Communication) as defined in ISO / IEC 14443 or ISO / IEC 18092.
[0023] Card 21 is a contactless card used to receive various services such as electronic transit passes (electronic tickets) and payments, and stores the user's ID and various information necessary to receive the services. Depending on the business operator, identity verification information such as employee ID or student ID may be printed on the card surface, adding value as a document for verifying the user's identity. In this description, the card is described as having a contactless interface, but there are also cases where the card has a physical contact interface as defined in ISO / IEC 7816 or a contactless interface. In the case of a combination with a tactile interface (supporting both), or if the card has functions such as a fingerprint sensor, facial image camera, or iris scan camera implemented on the mobile device, it is easy to infer that the card also has these functions. Having such functions on the card has the advantage of improving trust by performing a series of identity verifications with the card, which holds security information, regardless of the implementation on the mobile device.
[0024] Hereafter, the various types of information stored in Card 21 that are necessary to receive the services will be collectively referred to as service information.
[0025] Card 21 communicates with the management device 32 via contactless communication through the reader / writer 22, transmits service information to the service provider server 33 via the network 37, and receives service from the service provider server 33.
[0026] More specifically, service information is a data block assigned an identifier called a node code, which allows you to determine whether the target block is a keyed or keyless service. Separate from the service code that stores service information, there is an area code that stores area information, which manages the range of identifiers and the number of blocks allowed. The service code holds data blocks, and each data block is a memory space capable of storing data in 16-byte units. The number of blocks can be increased as long as the area code allows and the memory on the card permits. The area code does not hold data blocks. Keyed services support various cryptographic algorithms, including symmetric-key cryptography algorithms such as DES and AES, and public-key cryptography algorithms such as RSA and Elliptic Curve Cryptography (ECC), which allow for authentication and signing with external parties by holding keys. Verification becomes possible. These node codes, in addition to being used as identifiers, define the processing to be performed on a block. Examples include a random service that stores random data, a cyclic service that shifts the writing destination for log data, and a parsing service that interprets data written in a specific location as a number and performs subtraction from a number written in a specific location.
[0027] For example, when card 21 is used as an electronic transit pass, the reader / writer 22 is installed at station ticket gates, etc. When card 21 is touched (held over) the reader / writer 22 reads the service information stored on card 21 via contactless communication and transmits it to the management device 32. In this case, the data held by the electronic transit pass is generally implemented as a keyed service to counter malicious and unauthorized use, and the reader / writer 22 and card 21 share a key, allowing the data to be read by mutual authentication. In some cases, it may be a one-sided authentication where the reader / writer only authenticates the data read from the card. This is a verification flow that applies when the reader / writer only needs to confirm that the card is correct, and the card does not need to confirm that the reader / writer is correct, and the processing content and authentication content are changed as appropriate based on the service implemented between the electronic transit pass and the reader / writer. By doing so, the required security and processing content can be flexibly changed, which reduces the waiting time during processing on the card reader / writer side for users enjoying the service, leading to smoother payment processing.
[0028] The management device 32 transmits the service information of the card 21 read by the reader / writer 22 to the service provider server 33 via the network 37.
[0029] The service provider server 33 controls the opening and closing of ticket gates based on the service information of the card 21 transmitted via the network 37, and processes fare payments based on information about the station of entry (boarding station) and the station of exit (disembarking station).
[0030] Through this series of processes, users possessing card 21 can receive services related to the opening and closing of the ticket gates and automatic payment of fares simply by holding card 21 over the reader / writer 22 installed at the ticket gate.
[0031] The mobile terminal 31 can read and store the service information necessary to receive the services recorded on the card 21, thereby enabling the user using the card 21 to receive the services that are available to them.
[0032] In order for the mobile terminal 31 to receive the same services as those provided by using card 21, it is necessary to install a terminal application (terminal application software) 41 on the mobile terminal 31. The terminal application 41 is downloaded and installed from the application management server 36 via the network 37.
[0033] The terminal application 41 stores and registers the service information, which is the information necessary to receive the service and is registered on the card 21, within the mobile terminal 31, and by using the registered service information, the user can receive the same service as when the card 21 is presented.
[0034] More specifically, the terminal application 41 transmits the service information registered on the card 21 and the user's identity verification information of the mobile terminal 31 to the service provider server 33 via the network 37, and requests the registration of the service information on the mobile terminal 31 in order to receive the service.
[0035] When the service provider server 33 confirms that the service information transmitted from the terminal application 41 of the mobile terminal 31 and the user's identity verification information of the mobile terminal 31 are legitimate, it authorizes the terminal application 41 to register the service information to the mobile terminal 31.
[0036] Once the service provider server 33 approves the registration of the service information registered on card 21 to the mobile terminal 31, the terminal application 41 registers the service information registered on card 21 to the mobile terminal 31.
[0037] At this time, the terminal application 41 displays on a display unit such as a screen on the mobile terminal 31 card information similar to that on the card 21, indicating the services that can be received when presenting the card 21, corresponding to the registered service information.
[0038] In other words, for example, if card 21 is an electronic transit pass, the terminal application 41 registers the service information as an electronic transit pass with the mobile terminal 31 and displays ticket-like information indicating that the services that can be received are those of an electronic transit pass. If card 21 has the appearance of a student ID or employee ID, the terminal application 41 inherits the function of an identification document by displaying that appearance.
[0039] By displaying the ticket information on the mobile terminal 31 in this way, it becomes possible to receive the same services as when presenting the card 21.
[0040] When the terminal application 41 registers the information stored in the card 21, it also registers information necessary to enable contactless communication. As a result, just like with the card 21, by touching (holding) the mobile terminal 31 to the reader / writer 22, the same service can be provided as when holding the card 21 to the reader / writer 22.
[0041] The service provider server 33 is a server managed and operated by a service provider that provides various services using the card 21. It receives service information from the reader / writer 22 transmitted from the management device 32 via the network 37, reads the card 21 or the mobile terminal 31, and provides various services.
[0042] Furthermore, as described above, when the service provider server 33 receives a request from the terminal application 41 to register service information to the mobile terminal 31, and the service information and the user's identity verification information are genuine, the server 33 causes the service information to be registered on the card 21 to be registered on the mobile terminal 31 so that it can be used by the terminal application 41.
[0043] When the service provider server 33 registers the service information registered on card 21 to the mobile terminal 31 so that it can be used by the terminal application 41, it specifies the storage location (management location) of the service information on the mobile terminal 31 based on the security level of the service information and the capability information of the mobile terminal 31, and registers the service information. The security level of the service information and the capability information of the mobile terminal 31 will be described in detail later.
[0044] The eKYC (electronic Know Your Customer) provider server 34 processes user identity verification. It registers and manages user identification information such as documents and photographs, and enables the authentication process required for electronic processing.
[0045] For example, when a terminal application 41 registers service information registered on card 21 to a mobile terminal 31, the service provider server 33 requests authentication processing based on the user's identity verification information from the eKYC provider server 34. When authentication is approved, the service provider server 33 returns OK to the service provider server, causing the service provider server to register the information from card 21 to the mobile terminal 31.
[0046] If it is specified that the service information be registered and managed by the SE (Secure Element) management server 35 installed in the mobile terminal 31, the SE 72 registers the service information.
[0047] Although the information managed by SE72 can be read and used by the terminal application 41 on the mobile terminal 31, it cannot be registered or deleted. Therefore, the SE management server 35 performs the registration and deletion of the information managed by SE72.
[0048] <Overview of processing implemented by the information processing system> Next, with reference to Figure 2, an overview of the processing realized by the information processing system 11 in Figure 1 will be explained.
[0049] As shown in the upper part of Figure 2, the terminal application 41 used on the mobile terminal 31 is downloaded and installed from the application management server 36.
[0050] Once the terminal application 41 is installed, as shown in the middle of Figure 2, the terminal application 41 is activated when the mobile terminal 31 is operated. The terminal application 41 accepts input of user photo information and personal identification information such as a password, and registers it with the card 21, which consists of a contactless card, via near-field communication such as NFC. Retrieve card information (service information).
[0051] The terminal application 41 then sends the Capability information of the mobile terminal 31, the card reading information (service information) read from the card 21, and the identity verification information to the service provider server 33, requesting that the service information necessary to receive the service be written to the mobile terminal 31.
[0052] Here, the Capability information of the mobile terminal 31 refers to information indicating the type of storage mechanism provided in the mobile terminal 31 that can be used to store information managed by the terminal application 41, and is information such as Device Descriptor / Secure Area Descriptor, which has been discussed in ISO / IEC 23220-3 in recent years.
[0053] More specifically, the types of storage mechanisms provided in the mobile terminal 31 that can be used to store information managed by the terminal application 41 include, for example, an SE (Secure Element) 72 (Figure 3), a TEE (Trusted Execution Environment) 81 (Figure 3), and the terminal application 41. Other options include removable devices and removable media that can be appropriately connected to the mobile terminal, authentication devices that contain an SE, and storage on a server. In this example, we will use the three examples mentioned earlier to illustrate the point.
[0054] SE72 is a storage mechanism consisting of physical hardware chips, and generally has light sensors, temperature sensors, shock sensors, and radio wave detection sensors. It is a chip that detects unauthorized physical access from outside the chip and takes measures such as erasing the chip contents or locking access to prevent processing. It stores service information managed by the terminal application 41 that requires secure management. Of the three configurations managed within the mobile terminal, SE72 (Figure 3), TEE81 (Figure 3), and terminal application 41, SE72 is the most secure. This is the configuration. For this reason, SE72 generally stores service information, which includes highly confidential information such as key information used in key-based services, among the information managed by the terminal application 41.
[0055] TEE81 is a special software execution environment implemented on DH (Device Host) 71 (Figure 3), which consists of an application processor and other components. It monitors and manages the use of CPU and memory within the application processor, and is separate from the normal OS execution to ensure security. It intentionally achieves software tamper resistance, and is a storage mechanism realized by a software program running in this environment, storing service information managed by the terminal application 41 within the program. TEE82 manages SE72( within the mobile terminal) Of the three configurations of Figure 3), TEE81 (Figure 3), and terminal application 41, SE This is the next most secure configuration after 72.
[0056] Therefore, in the case of a mobile terminal 31 that does not have SE72 installed, when secure management is required for the information managed by the terminal application 41, TEE81 will replace SE72. It is more suitable to store the information managed by the terminal application 41.
[0057] The terminal application 41 is an application executed by the DH (Device Host) 71 (Figure 3). This configuration is implemented by application software and performs all processing related to service provision, as well as functioning as a storage mechanism for service information. Of the three configurations described above for storing service information, the terminal application 41 is a configuration that is not securely managed in the sense that it lacks hardware tamper resistance or software tamper resistance. For this reason, the terminal application 41 stores service information that does not require secure management, such as stored data information used in keyless services that do not include key information.
[0058] When the service provider server 33 receives a request from the terminal application 41 to register service information to the mobile terminal 31, it specifies a storage location on the mobile terminal 31 and registers the service information based on the security level of the requested service information and the capability information of the mobile terminal 31.
[0059] In this case, the service provider server 33 accesses the eKYC provider server 34 and verifies the identity of the user of the mobile device 31 that requested registration of service information to the mobile device 31 based on the identity verification information. If the user's identity is confirmed, the service provider server 33 authorizes the registration of service information.
[0060] In other words, for example, if the security level required for the service information to be registered is higher than a predetermined level, and the mobile terminal 31 is equipped with SE72, the service provider server 33 designates SE72 as the storage location and authorizes the registration of the service information.
[0061] For example, service information for key-based services, which use data containing key information with a security level higher than a predetermined level, requires secure management, and therefore may be specified to be managed by SE72.
[0062] Furthermore, for example, if the security level required for service information is higher than a predetermined level, but the mobile terminal 31 does not have SE72 installed, then if it has TEE81... The service provider server 33 then designates TEE81 as the storage location and registers the service information. It may be acceptable to allow the recording.
[0063] Furthermore, for example, if security is not required for the service information, the service provider server 33 does not have cooperation with SE72 or TEE81, and therefore the terminal application cannot be securely managed. You may specify 41 as the storage location and allow the registration of service information.
[0064] For example, service information for a keyless service, which uses data that does not include key information, does not require secure management, so the terminal application 41 may be designated as the storage location.
[0065] However, even for service information of keyless services, if it contains special identification information, it is desirable that it be managed securely, for example, if TEE81 is provided. Sometimes, TEE81 may be designated as the storage location. Of course, SE72 If available, you may designate SE72 as the storage location for more secure management.
[0066] In addition, for example, if a certain level of security is required for the service information, but neither SE72 nor TEE81 is available, the service provider server 33 will... Depending on the security level, or if management by the terminal application 41 is permitted by some regulation, the terminal application 41 will be designated as the storage location and the registration of service information will be permitted.
[0067] Terminal application 41 is SE72, TEE81, and terminal application 41 The mobile terminal 31 stores service information for receiving services provided by the service provider server 33, and when it becomes possible to receive the service, it displays ticket information (ID ticket information) on a display device such as the display of the mobile terminal 31 to indicate that it is possible to receive the service.
[0068] In other words, if the service provided by the service provider is, for example, an electronic transit pass, the display on the mobile terminal 31 shows ticket information indicating a commuter pass or ticket, indicating that it is possible to receive the service as an electronic transit pass.
[0069] Furthermore, if the service provided by the service provider is, for example, an employee ID card, the information on the employee ID card will be displayed on the display of the mobile terminal 31, indicating that it is possible to receive the service as an employee ID card.
[0070] Furthermore, if the service provided by the service provider is, for example, a student ID card, the information on the student ID card will be displayed on the display of the mobile terminal 31, indicating that it is possible to receive the service as a student ID card.
[0071] Furthermore, as shown in the lower part of Figure 2, the service provider server 33 may control the SE management server 35 to register additional information necessary for service provision in the SE 72, such as access control, entry / exit IDs representing facility information and gate information within the company, ID information used for personal identification, and the service provider ID.
[0072] In this case, as shown in Example Ex in the lower left of Figure 2, the information registered in SE72 is transmitted to the reader / writer 22 via the CLF (ContactLess Frontend) 73 (Figure 3) of the mobile terminal 31. Since contact communication becomes possible, it becomes possible to receive services similar to contactless services obtained by holding a contactless card, card 21, over a reader / writer 22. CLF73 is a proximity contactless communication as defined in ISO / IEC 14443 and ISO / IEC 18092. This includes communication methods such as near-field contactless communication as defined by ISO / IEC 15693, and ultra-wideband (UWB) communication. A device equipped with communication functions such as short-range wireless communication, Bluetooth®, etc. It is a tool that performs modulation processing and encoding processing from analog waveforms.
[0073] In other words, if the service provided by the service provider is an electronic transport pass, when using card 21, the service information registered on card 21 is read by holding it contactlessly over the reader / writer 22 installed at the ticket gate, and the service is provided such that the opening and closing of the ticket gate and the payment of fares are controlled based on the read service information.
[0074] In response to this, once service information for receiving services as an electronic transit pass is registered in SE72, by holding the mobile terminal 31 over the reader / writer 22 contactlessly, the service information registered in SE72 is read via CLF73, allowing access to the ticket gate. The gate opening and closing controls and fare payment processing are handled here.
[0075] Furthermore, by integrating the HCE (Host Card Emulation) 82 (Figure 3) into the DH71 (Figure 3), information registered in the TEE 81 and terminal application 41 can be accessed via contactless communication. We can also provide access services. This includes non-contact services such as HCE82 (Figure 3). The configuration for implementing the screw will be described later, with reference to Figure 3.
[0076] <Configuration for realizing contactless services> Next, referring to Figure 3, the configuration of the mobile terminal 31 for realizing contactless services using contactless functionality will be described.
[0077] Figure 3 is a schematic diagram illustrating the functions of a mobile terminal 31, including multiple configurations required to realize contactless services.
[0078] The mobile terminal 31 includes a DH (Device Host) 71, an SE (Secure Element) 72, and a CLF (ContactLess Frontend) 73 as its main hardware components.
[0079] DH71 consists of a so-called application processor and memory, and runs a terminal application 41, which is application software for receiving services from a service provider, on the mobile terminal 31.
[0080] Furthermore, DH71 realizes the storage mechanism of TEE81 described above by executing the software program in an isolated environment within the application processor, and service provider service Stores the service information necessary to receive the services provided by B33.
[0081] SE72 consists of a chip with hardware tamper resistance, and access from terminal applications 41 implemented by DH71 is permitted by access control based on access rules defined in Secure Element Access Control as defined in GlobalPlatform. It stores service information necessary to receive services provided by service providers, which can only be accessed through a terminal application. More specifically, this information is managed by a service called the ARA-M application within Secure Element, which holds and manages rules, and the DH71 accesses it in a predetermined manner and reads the rules into the mobile terminal. It is used in this way. The rules are applied when a device app attempts to access SE72, and access is only permitted if the device app is authorized by the rules and accesses the destinations authorized by the rules.
[0082] More specifically, the mobile terminal 31 is equipped with an SE management application 72a and, in cooperation with the SE management server 35, stores the service information necessary to receive services provided by the service provider server 33 in the SE 72. The SE management server 35 transmits data in accordance with the service information storage protocol supported by the SE 72, confirms the response content from the SE 72, and sequentially stores the service information. By applying the command specifications described in the GlobalPlatform card specification, mechanisms supported by many SE 72s can be applied. In this example, the SE management server 35 is represented by sending commands as needed, but by preparing a series of command data in advance as an encrypted script based on the Secure Element Management Service defined in GlobalPlatform or SCP11c specified in Amendment F, an accompanying document of the card specification, communication between the SE management server 35 and the SE 72 can be simplified. In particular, by reducing the number of communications and thus reducing the time spent managing the state of a single SE 72, the server can dedicate processing time to communicating with other users, enabling more efficient operation.
[0083] The CLF73 enables short-range communication such as NFC with the reader / writer 22, and as shown by the solid line in Figure 3, reads service information necessary to receive services provided by service providers managed by the SE72 from the SE72.
[0084] Furthermore, when the relevant parameters are set and the HCE82 is available from the terminal application 41, the CLF73 can also read the service information necessary to receive services provided by the service provider managed by the terminal application 41, as shown by the dotted line in Figure 3.
[0085] Furthermore, CLF73 is equipped with TEE81, and terminal application 41 is HCE82 When it is available, register with TEE81 as shown by the dotted line in Figure 3. It is also possible to retrieve service information necessary to receive services provided by the service provider.
[0086] In other words, the HCE (Host Card Emulation) 82 is a mechanism implemented by a software program, and service information is stored in the terminal application 41 and TEE 81. Even when service information is stored in SE72, this simulates the functionality of SE72. This allows CLF73 to exchange service information managed by terminal applications 41 and TEE81 with the reader / writer 22 via contactless communication through the functions provided by HCE82. It is possible.
[0087] In Figure 3, an example is shown in which the DH71 of the mobile terminal 31 is configured with the terminal application 41, HCE82, and TEE81, and also includes SE72. However, configurations other than the terminal application 41 may not necessarily be present.
[0088] In other words, if only terminal application 41 is provided and SE72, TEE81 and HCE82 are not provided, and terminal application 41 and SE72 are provided, TEE If 81 is not provided, it is possible that terminal application 41 and TEE81 are provided, but SE72 is not provided.
[0089] Furthermore, if HCE82 is not implemented on the mobile terminal 31, the terminal application 4 When service information is stored in 1 and TEE81, it is transmitted from the reader / writer 22 via contactless communication. You will not be able to receive the service.
[0090] In this case, the service information is registered in the mobile terminal 31, and the ticket information will be the correct information, so the service will be provided by presenting the ticket information.
[0091] In other words, for example, if a user is receiving services as an electronic transport pass using card 21, they cannot use their mobile terminal 31 to receive contactless services at a ticket gate equipped with a reader / writer 22. However, if card 21 has a card face such as a student ID, it can be used as identification by presenting the information on the card face.
[0092] Furthermore, even if HCE82 is not provided, if SE72 is provided, SE72 is... When service information is stored, contactless services can be received.
[0093] Thus, the Capability information of the mobile terminal 31 is information that indicates the type of storage mechanism for the information necessary to receive services provided by a service provider on the mobile terminal 31.
[0094] The service provider server 33 determines the location (management location) where the service information will be stored based on the security level required for the service information and the capability information.
[0095] Furthermore, the service provider server 33 may determine the storage location of the service information based on the security level required for the service information, capability information, and requests from users and service providers regarding the storage location.
[0096] <Service information registered on the card> Next, referring to Figure 4, we will explain the service information for receiving services provided by service providers, which is managed by a card 21 consisting of a contactless card.
[0097] Card 21 is provided with a service information storage area 101, as shown in Figure 4, and includes a basic ID information block 111, a UN (Unique Number) block 112, and additional Service information is stored as information consisting of service-related free blocks 113.
[0098] Basic ID information block 111 and UN (Unique Number) block 112 are basic service This block stores information for receiving bis, and the free block 113 for additional services stores information for receiving additional services.
[0099] The basic ID information stored in the basic ID information block 111 is information such as the ID number and name that identifies the user who possesses the card 21 and receives the service.
[0100] UN (Unique Number) information stored in block 112 is provided by service providers. This is information about a unique ID.
[0101] The free block 113 for additional services consists of multiple blocks that store information for receiving multiple additional services. The information stored in the free block 113 for additional services is information for receiving additional services.
[0102] More specifically, the basic ID information stored in the basic ID information block 111 is the information indicated as ID information #1 (basic ID information) among the information classified as basic services as shown in Figure 5, and consists of information that can be read without key information (keyless read).
[0103] The information shown in ID Information #1 (Basic ID Information) consists of the user's ID number, the user's name, affiliation information, and the expiration date.
[0104] The unique ID information provided by the service provider and stored in UN block 112 is the information indicated as ID information #2(UN) among the information classified as basic services, as shown in Figure 5, and consists of information that can be read without key information (keyless read) and information that can be read with key information (keyed read).
[0105] The information shown in ID Information #2 (UN) consists of the IC card type, issuing company code, and serial number.
[0106] The information for receiving additional services, stored in the free block 113 for additional services, is classified as additional services as shown in Figure 5, and consists of additional usage information, information for services 1 to 4, and information for free services.
[0107] The additional usage information consists of information that can be read with a key (keyed read), and includes information such as a business identification code and service number that identify the business that provides the additional service.
[0108] Information for services 1 through 4 is information related to the information registered in the additional usage information. Of these, information for services 1 through 3 consists of information that can be read with key information (keyed read), and information for service 4 consists of information that can be read without key information (keyless read).
[0109] Free service information is information related to the information registered in the additional usage information, and consists of information that can be read and written without key information (keyless read / write).
[0110] Of the service information shown in Figure 5, the information indicated in range Z1 consists of information that can be read without key information (keyless read), and therefore does not require secure management. When managed by the mobile terminal 31, the terminal application 41, SE72, and TEE81 You may choose to store and manage it in either of the following ways.
[0111] Furthermore, the information shown in range Z2 of Figure 5 consists of information that can be read with key information (key-enabled read), and since secure management is required, when managed on the mobile terminal 31, it needs to be stored and managed in SE72.
[0112] Furthermore, the information shown in range Z3 of Figure 5 consists of information that can be read and written without key information (keyless read / write), eliminating the need for secure management, and is not only readable but also writable. For this reason, when the information in range Z3 is managed on the mobile terminal 31, it may be managed by the terminal application 41 or by the TEE 81, and with the provision of HCE 82, it becomes possible to receive contactless services.
[0113] <Example of mobile device configuration> Next, with reference to Figure 6, an example configuration of the mobile terminal 31 will be described.
[0114] The mobile terminal 31 consists of, for example, a smartphone, and comprises a control unit 121, an input unit 122, an output unit 123, a storage unit 124, a communication unit 125, a drive 126, and a removable storage medium 127, as well as SE72 and CLF73, which communicate with each other via bus 128. They are connected via this, and can send and receive data and programs.
[0115] The control unit 121 consists of a processor and memory and controls the overall operation of the mobile terminal 31. The control unit 121 also includes the terminal application 41 and TEE 81. Yes, they are.
[0116] In other words, the control unit 121 has a configuration corresponding to DH71 in the mobile terminal 31 shown in Figure 3, and by executing a software program, it executes the terminal application 41 including HCE82. This enables the functionality of the TEE81.
[0117] The input unit 122 consists of input devices such as operation buttons and touch panels into which the user inputs operation commands, and supplies various operation signals to the control unit 121 according to the operation input.
[0118] The output unit 123 is controlled by the control unit 121 and displays the supplied operation screen and processing result images on a display consisting of an LCD (Liquid Crystal Display) or an organic EL (Electro Luminescence) display. This is a display unit (display device (including a touch panel)) that presents various information as images. The output unit 53 may be a configuration other than the display unit, as long as it can present various information, for example, a speaker or a light-emitting unit.
[0119] The storage unit 124 consists of an HDD (Hard Disk Drive), SSD (Solid State Drive), or semiconductor memory, and is controlled by the control unit 121 to write or read various data and programs.
[0120] The communication unit 125 is controlled by the control unit 121 and communicates with LAN (Local Area Network) and Blue It transmits and receives various types of data and programs between various devices using technologies such as Tooth®.
[0121] Drive 126 is a removable storage medium that can store magnetic disks (including flexible disks), optical disks (including CD-ROMs (Compact Disc-Read Only Memory) and DVDs (Digital Versatile Discs)), magneto-optical disks (including MDs (Mini Discs)), or semiconductor memory. Read and write data to 127.
[0122] The mobile terminal 31 is the mobile terminal 31 shown in Figure 3, and is equipped with the SE management application 72a. Upon request from the service provider server 33, the management application 72a and the SE management server 35 cooperate to provide service information with a security level higher than a predetermined level to the SE 72 Register it in the memory area.
[0123] The CLF73 enables contactless service by reading and outputting service information registered in the SE72 via short-range communication such as NFC with the reader / writer 22. Furthermore, if the HCE82 is installed in the terminal application 41, the CLF73 enables contactless service by reading and outputting service information managed by the terminal application 41 or TEE81 via short-range communication such as NFC with the reader / writer 22.
[0124] Note that the mobile terminal 31 in Figure 3 is an example configuration equipped with terminal applications 41 including HCE82, TEE81, and SE72, but there are also configurations in which HCE82, TEE81, and SE72 are not provided.
[0125] The terminal application 41 generates information indicating the presence or absence of HCE82, TEE81, and SE72 as Capability information, which indicates the type of storage mechanism for storing service information provided in the mobile terminal 31, and supplies it to the service provider server 33. Based on the security level required for the service information according to the content of the service to be provided and the Capability information, the service provider server 33 determines the storage location (storage mechanism for storing service information) of the service information in the mobile terminal 31 and approves the registration of the service information.
[0126] <Example of service provider server configuration> Next, with reference to Figure 7, an example configuration of the service provider server 33 will be described.
[0127] The service provider server 33 consists of a control unit 131, an input unit 132, an output unit 133, a storage unit 134, a communication unit 135, a drive 136, and a removable storage medium 137, which are connected to each other via a bus 138, enabling the transmission and reception of data and programs. The configuration of the control unit 131, input unit 132, output unit 133, storage unit 134, communication unit 135, drive 136, and removable storage medium 137 is basically the same as the functions of the control unit 121, input unit 122, output unit 123, storage unit 124, communication unit 125, drive 126, and removable storage medium 127 in Figure 6, so their explanation will be omitted.
[0128] However, the control unit 131 is equipped with a service information management unit 141.
[0129] The service information management unit 141 determines the storage location of the service information and approves its registration based on the security level required for the service information corresponding to the service content requested by the mobile terminal 31 and the capability information of the mobile terminal 31.
[0130] The service information management unit 141 provides the corresponding service based on the service information supplied from the mobile terminal 31.
[0131] Furthermore, the configurations of the eKYC provider server 34, SE management server 35, and application management server 36 are basically the same as those of the service provider server 33, so their explanation will be omitted. However, the functions required by each server are realized by processing executed by software programs in each control unit 131.
[0132] <Service Information Management Location Determination Process> Next, the process of determining the service information management location by the service provider server 33 will be explained with reference to the flowchart in Figure 8. This process is performed in response to the terminal application 41 of the mobile terminal 31 requesting the service provider server 33 to register the service information of card 21 to the mobile terminal 31, specifying the service content.
[0133] Here, it is assumed that when the terminal application 41 requests registration of service information to the mobile terminal 31, it transmits the service information registered on the card 21 for providing the corresponding service, as well as the capability information of the mobile terminal 31. Therefore, it is assumed that the service provider server 33 has obtained the service information for which registration has been requested and the capability information of the mobile terminal 31.
[0134] In step S11, the service information management unit 141 of the control unit 131 in the service provider server 33 determines whether the service information requested to be registered to the mobile terminal 31 is a keyed service that handles keyed service information.
[0135] In step S11, if it is not a keyed service, that is, a keyless service that handles service information without a key, the process proceeds to step S12.
[0136] In step S12, the service information management unit 141 checks the contents of the service information registered for the keyless service.
[0137] In step S13, the service information management unit 141 determines whether the keyless service contains special identification information that is desirable to be managed in a secure environment.
[0138] If it is determined in step S13 that special identification information is included, the process proceeds to step S14.
[0139] In step S14, the service information management unit 141 determines whether or not it can confirm the capability information of the mobile terminal 31 that requested the provision of the service. That is, the service information management unit 141 determines whether or not it has already obtained the capability information of the mobile terminal 31 that requested the provision of the service and is in a state where it can be confirmed.
[0140] If, in step S14, it is determined that the Capability information of the mobile terminal 31 that requested the provision of the service has not been obtained, or has been obtained but cannot be properly verified, the process proceeds to step S15.
[0141] In step S15, the service information management unit 141 confirms the management location with the user on the mobile terminal 31 and then determines the management location for the service information.
[0142] In other words, here, the service information of the requested service includes special information that should ideally be managed in a secure environment, but the capability information of the mobile terminal 31 has not been obtained, and the type of storage mechanism capable of storing the service information cannot be identified. Therefore, the mobile terminal 31 is queried, and the storage location is determined based on the user's response to the query.
[0143] On the other hand, if it is determined in step S13 that no special identification information is included, the process proceeds to step S16.
[0144] In step S16, the service information management unit 141 causes the terminal application 41 to manage the service information.
[0145] In other words, since the service information of the requested service does not include any information that is required to be managed in a secure environment, the service information is managed in the terminal application 41, which does not manage the service information in a secure environment.
[0146] Furthermore, if it is determined in step S11 that the service has a key, the process proceeds to step S17.
[0147] In step S17, the service information management unit 141 determines whether or not it has acquired the Capability information of the mobile terminal 31. As mentioned above, it is assumed that the Capability information is transmitted from the mobile terminal 31, but it is confirmed whether or not it has been reliably acquired.
[0148] If the capability information of the mobile terminal 31 is obtained in step S17, the process proceeds to step S20.
[0149] In step S20, the service information management unit 141 determines, based on the Capability information, whether the mobile terminal 31 that requested the provision of the service possesses the SE72.
[0150] If, in step S20, it is determined that the mobile terminal 31 requesting the service possesses SE72, the process proceeds to step S21.
[0151] In step S21, the service information management unit 141 decides to manage the service information using the SE72 of the mobile terminal 31.
[0152] In other words, since the service information here is for a key-based service and requires secure management, if the mobile terminal 31 possesses SE72, the service information will be managed by SE72.
[0153] If it is determined in step S20 that SE72 is not owned, the process proceeds to step S22.
[0154] In step S22, the service information management unit 141 determines whether it is permitted to manage service information in an environment other than the secure SE72. The determination of whether it is permitted to manage service information in an environment other than SE72 is made based on information pre-configured by the service provider that manages and operates the service provider server 33.
[0155] If, in step S22, it is determined that managing service information in an environment other than the secure SE72 is not permitted, the process proceeds to step S23.
[0156] In step S23, the service information management unit 141 decides to manage the service information itself using the service provider server 33.
[0157] In other words, since the management of service information is not permitted except for the SE72 which allows for secure management, mobile terminals 31 that do not possess an SE72 are not allowed to manage service information, and the service provider server 33 manages the service information itself.
[0158] Therefore, in this case, service information will not be managed on the mobile terminal 31. Consequently, if service provision is required, the mobile terminal 31 (or its terminal application 41) must query the service provider server 33 each time. The service provider server will then verify whether the same mobile terminal is accessing the service by assigning an ID from the terminal application or by obtaining the mobile terminal's serial number: IMEI (International Mobile Number). Identity is verified using the Equipment Identity (IMEI), the subscriber identification number (IMEI) held by the SIM card inserted into the mobile device, or account information used for login on Android® or iOS. For this reason, the mobile device 31 cannot receive services in an offline environment where it cannot communicate with the service provider server 33.
[0159] On the other hand, if it is determined in step S22 that it is permitted to manage service information in an environment other than the secure SE72, the process proceeds to step S24.
[0160] In step S24, the service information management unit 141 converts registration data consisting of service information for receiving a key-based service into a token.
[0161] In step S25, the service information management unit 141 determines, based on the Capability information, whether the mobile terminal 31 that requested the provision of the service possesses a TEE81. .
[0162] In step S25, the mobile terminal 31 that requested the provision of the service retains TEE81 If it is determined that the item is present, the process proceeds to step S26.
[0163] In step S26, the service information management unit 141 decides to manage the service information using the TEE81 on the mobile terminal 31.
[0164] In other words, here, even service information related to key-based services is permitted to be managed by something other than SE72, which allows for secure management, so mobile terminal 3 possessing TEE81 In step 1, service information is converted into tokens and then managed by TEE81.
[0165] Meanwhile, in step S26, the mobile terminal 31 that requested the provision of the service is TEE8 If it is determined that item 1 is not possessed, the process proceeds to step S16, where it is decided to manage it in the terminal application 41.
[0166] In other words, in this case, the management of service information is permitted outside of the SE72, which allows for secure management, and in mobile terminals 31 that do not possess a TEE81, the service information is tokenized. It is converted and then managed by the terminal application 41.
[0167] Furthermore, if it is determined in step S14 that the Capability information of the mobile terminal 31 cannot be confirmed, the process proceeds to step S25.
[0168] In other words, although it is service information for a keyless service, it contains special identification information, so if it is possible to check the Capability information, check for the presence of TEE81, and if TEE81 is possessed, it will be managed by TEE81. However, even in this case If TEE81 is not owned, the general keyless service will apply. Like the information, it is managed by the terminal application 41.
[0169] Furthermore, if the Capability information of the mobile terminal 31 is not obtained in step S17, the process proceeds to step S18.
[0170] In step S18, the service information management unit 141 controls the communication unit 135 to query the mobile terminal 31 that requested the provision of the service for capability information.
[0171] In step S19, the service information management unit 141 determines whether or not it was able to obtain capability information from the mobile terminal 31 in response to the inquiry.
[0172] If Capability information is transmitted from the mobile terminal 31 and acquired as a result of the processing in step S18, in step S19 it is determined that Capability information has been acquired from the mobile terminal 31, and the process returns to step S17.
[0173] Furthermore, if it is determined in step S19 that Capability information could not be obtained from the mobile terminal 31, the process proceeds to step S21, and it is decided that the service information will be managed by SE72.
[0174] In other words, since this involves service information related to key-based services that should be managed in a secure environment, if capability information cannot be obtained, it will be managed by SE72 as an emergency measure.
[0175] However, since SE72 may not necessarily be present in the mobile terminal 31, if it is determined in step S19 that Capability information could not be obtained from the mobile terminal 31, the process may proceed to step S15, as shown by the dotted line in Figure 8. In this case, the mobile terminal 31 is inquired about the location where the service information is managed, and the location of the service information is determined based on the user's response to the inquiry.
[0176] Through the above process, it becomes possible to determine the location for managing service information related to the service to be provided, based on security requirements such as whether the service requested by the mobile terminal 31 is a key-protected service, and the capability information of the mobile terminal 31.
[0177] As a result, the location where the service information requiring management is managed can be appropriately switched based on the security level of the service information requiring management and the type of storage mechanism provided in the mobile terminal 31 based on the capability information of the mobile terminal 31.
[0178] As a result, it becomes possible to achieve secure management of service information with easy operation, and to realize the service provision functions realized by the contactless card 21 using a variety of mobile terminals 31.
[0179] <Processing when service information is managed by a system engineer> Next, referring to the flowcharts in Figures 9 and 10, we will explain the process when the information processing system 11 in Figure 1 manages service information using a system engineer (SE).
[0180] In Figures 9 and 10, the operations of the following components are shown from left to right: user, mobile terminal 31, application management server 36, terminal application 41 (also referred to as terminal app in the figures), card 21, service provider server 33, management DB 33a, eKYC provider server 34, SE management server 35, SE management application 72a, and SE 72.
[0181] In step S51 (Figure 9), the user inputs an operation to the input unit 122 instructing the mobile terminal 31 to start up and connect to the network 37, and an operation signal corresponding to the operation is supplied to the mobile terminal 31.
[0182] In step S61, the control unit 121 of the mobile terminal 31 receives an operation signal from the input unit 122, and based on the operation signal, activates the mobile terminal 31, controls the communication unit 125, and connects to the network 37.
[0183] In step S52, the user makes an operation input to the input unit 122 requesting the application management server 36 to download the terminal application 41, and a corresponding operation signal is supplied to the control unit 121 of the mobile terminal 31.
[0184] As a result, the control unit 121 controls the communication unit 125 to access the application management server 36 via the network 37 and request the download of the terminal application 41.
[0185] In step S71, the application management server 36 receives a download request for the terminal application 41 from the mobile terminal 31.
[0186] In step S72, the application management server 36, in response to a download request from the mobile terminal 31, causes the mobile terminal 31 to download a program that will run the terminal application 41.
[0187] In step S62, the control unit 121 of the mobile terminal 31 controls the communication unit 125 to download and acquire the terminal application 41, and then installs the acquired terminal application 41.
[0188] As a result of the processes described so far, the terminal application 41 is downloaded and installed on the mobile terminal 31, and the terminal application 41 becomes available for use on the mobile terminal 31.
[0189] In step S53, when the user inputs an operation to the input unit 122 to instruct the launch of the terminal application 41, an operation signal instructing the launch of the terminal application 41 is output to the control unit 121 of the mobile terminal 31.
[0190] In step S63, the control unit 121 of the mobile terminal 31 acquires an operation signal instructing the launch of the terminal application 41.
[0191] In step S64, the control unit 121 of the mobile terminal 31 starts the terminal application 41 based on an operation signal that instructs the startup of the terminal application 41.
[0192] In response to this, in step S81, the terminal application 41 is launched.
[0193] In step S54, the user inputs user information, such as an ID number and name, into the input unit 122, and user verification information (identity verification information), such as an ID number and name, is supplied to the terminal application 41.
[0194] In step S55, the user touches (holds) their own card 21 to the reader / writer 22, thereby making the service information necessary to receive the service stored in the storage area 101 of the card 21 available for reading under the control of the terminal application 41 in step S111. For some services, if access to a keyed service is required, the necessary encryption commands or scripts may be received via the service provider server 33 or the SE management server 35.
[0195] In step S83, the terminal application 41 sends a Read command to the card 21 instructing it to read the service information stored in the memory area 101 of the card 21. In response, in step S112, the card 21 receives the Read command.
[0196] In step S113, the card 21 reads the service information from the memory area 101 based on the Read command and sends it to the terminal application 41 as response data.
[0197] In step S84, the terminal application 41 obtains service information from the storage area 101 of card 21 as response data supplied from card 21.
[0198] In step S56, the user operates the input section 122 of the mobile terminal 31 and presses the photo-taking button, which takes a photo of the user as personal identification information. At the same time, the user selects an ID to use and is instructed whether or not to use SE72. Operation signals and the captured image corresponding to these operations are supplied to the terminal application 41.
[0199] In step S85, the terminal application 41 acquires the operation signals and captured images transmitted by the processing in step S56.
[0200] In step S86, the terminal application 41 displays the captured image on the display unit of the output unit 123.
[0201] This allows the user to verify the image taken as their personal identification information in step S57.
[0202] In step S87, the terminal application 41 controls the communication unit 125 to send the service provider server 33 via the network 37 a request for the issuance of ID information to receive the service, along with the service information in the memory area 101 of the card 21 which is response data, and an image of itself as identity verification information.
[0203] In step S121, the service information management unit 141 in the control unit 131 of the service provider server 33 obtains the service details of the service to be provided and a request for issuance of ID information to receive that service, along with the service information in the storage area 101 of the card 21, which is the response data, and the user's image as identity verification information.
[0204] In steps S122 and S141, the service information management unit 141 accesses the management DB 33a and verifies the service information in the storage area 101 of the card 21, which is the response data.
[0205] In steps S123 and S142, the service information management unit 141 obtains information that is the result of matching the service information in the storage area 101 of the card 21, which is the response data (information indicating whether the matching is OK or NG).
[0206] In steps S124 and S151, the service information management unit 141 accesses the eKYC provider server 34 and compares the photo data consisting of the user's image as identity verification information with the photo data registered in the eKYC provider server 34.
[0207] In steps S125 and S152, the service information management unit 141 obtains information (information indicating whether the match is OK or NG) that represents the result of comparing the photo data registered in the eKYC provider server 34 with the photo data consisting of the user's image taken for verification.
[0208] Furthermore, the following explanation will proceed on the premise that both the verification results of the service information, which is the response data, and the verification results of the photo data, which is the user's identity verification information, are OK. However, if at least one of the verification results of the service information, which is the response data, or the verification results of the photo data for user identification are NG, the registration process of the service information to the mobile terminal 31 will become impossible, and the process will terminate.
[0209] In step S126, the service information management unit 141 controls the communication unit 135 to issue ID information including the ticket information necessary to receive the requested service, and transmits it to the mobile terminal 31 via the network 37.
[0210] In step S88, the terminal application 41 of the mobile terminal 31 controls the communication unit 125 to obtain ID information, including ticket information necessary to receive the requested service, which is transmitted from the service provider server 33.
[0211] In step S89, the terminal application 41 confirms and registers the ID information necessary to receive the requested service, and displays the ticket information indicating that the service can now be received on the display unit that constitutes the output unit 123.
[0212] In other words, this process causes the ticket information, including the ID information necessary to receive the service, to be displayed on the display unit that constitutes the output unit 123 of the mobile terminal 31. Therefore, by presenting the ticket information, it becomes possible to receive the same services as those provided when the card 21 is presented.
[0213] In step S90, the terminal application 41 sends its Capability information to the service provider server 33 along with a notification indicating that the registration of the ID information required to receive the requested service has been completed.
[0214] In step S127, the service information management unit 141 of the service provider server 33 receives a notification indicating that the registration of the ID information transmitted from the mobile terminal 31 has been completed, and also obtains the capability information of the mobile terminal 31.
[0215] In step S128 (Figure 10), the service information management unit 141 confirms the registered service information and capability information required to provide the registered service, and determines the location for managing the service information.
[0216] In other words, the service information management unit 141 here executes the service information management location determination process, as explained with reference to the flowchart in Figure 8, to determine the management location of the service information. Figures 9 and 10 are flowcharts illustrating the process when it is determined in step S128 that the service information will be stored and managed in SE72.
[0217] Therefore, in step S129, the service information management unit 141 controls the communication unit 135 to send a request to the SE management server 35 to issue a request to the SE 72 (a request to register and manage service information with the SE 72).
[0218] In step S171, the SE management server 35 receives the issuance request to SE72 sent from the service provider server 33.
[0219] In step S172, the SE management server 35 issues a token for access to the SE management server 35 for use by the SE management application 72a. Send to the service provider server 33.
[0220] In step S130, the service information management unit 141 of the service provider server 33 obtains a token for accessing the SE management server 35, which is sent from the SE management server 35.
[0221] In step S131, the service information management unit 141 sends a token to the mobile terminal 31 for access to the SE management server 35.
[0222] In step S91, the terminal application 41 of the mobile terminal 31 obtains a token for accessing the SE management server 35, which is sent from the service provider server 33.
[0223] In step S92, the terminal application 41 supplies a token for accessing the SE management server 35 to the SE management application 72a in the mobile terminal 31.
[0224] In step S191, the SE management application 72a obtains a token for accessing the SE management server 35.
[0225] In steps S192 and S211, the SE management application 72a opens a session with SE72.
[0226] In step S193, the SE management application 72a sends a token to the SE management server 35 for access to the SE management server 35.
[0227] In step S173, the SE management server 35 obtains a token from the SE management application 72a for accessing the SE management server 35.
[0228] As a result, the SE management server 35 recognizes that the token for accessing the SE management server 35 returned from the SE management application 72a matches the one sent in step S172, and therefore recognizes that the token it provided to the service provider requesting service registration with SE72 is a valid request because it was returned from the SE management application 72a, and begins issuing services to SE72.
[0229] Therefore, in step S174, the SE management server 35 sends service information corresponding to the issuance request from the service provider server 33 to the SE 72, and a service registration command instructing the SE 72 to register that service information, to the SE management application 72a.
[0230] In step S194, the SE management application 72a obtains service information corresponding to the issuance request to SE72, and a service registration command that instructs SE72 to register that service information.
[0231] In step S195, the SE management application 72a supplies SE72 with service information corresponding to the issuance request to SE72, and a service registration command instructing SE72 to register that service information.
[0232] In step S212, SE72 obtains service information corresponding to the issuance request and a service registration command that instructs SE72 to register that service information.
[0233] In step S213, SE72 stores and registers the service information corresponding to the issuance request in its storage area based on the service registration command. At this time, SE72 also handles RSA. Alternatively, a key pair may be generated that conforms to the public-key cryptography scheme used by ECC.
[0234] In step S214, SE72 sends response data to SE management application 72a, consisting of information indicating that the registration of service information corresponding to the issuance request has been completed. In some cases, public key information may be extracted from the aforementioned key pair and included in the response information. By returning the public key information to the issuance management server and encrypting subsequent processing with the public key, it is possible to guarantee that communication is being made with the same SE72.
[0235] In step S196, the SE management application 72a obtains response data consisting of information indicating that the registration of service information from SE72 has been completed.
[0236] In step S197, the SE management application 72a sends response data to the SE management server 35, which consists of information indicating that the registration of service information from SE 72 has been completed.
[0237] In step S175, the SE management server 35 obtains response data consisting of information indicating that the registration of service information from SE72 has been completed.
[0238] In step S176, the SE management server 35 supplies a completion notification to the SE management application 72a indicating the completion of the process related to the registration of service information.
[0239] In step S198, the SE management application 72a receives a completion notification from the SE management server 35.
[0240] In steps S199 and S215, SE72 and SE management application 72a mutually close their sessions based on completion notifications.
[0241] In step S200, the SE management application 72a sends a completion notification (registration OK or registration NG) to the terminal application 41 indicating whether the registration of service information to SE72 has been successfully completed.
[0242] In step S93, the terminal application 41 receives a notification that the registration of service information to SE72 is complete.
[0243] In step S94, the terminal application 41 displays information indicating that service information for receiving the service has been registered in SE72, for example, as an image on the display unit that constitutes the output unit 123, and reflects it on the ticket image.
[0244] In step S95, the terminal application 41 sends a notification to the service provider server 33 indicating the completion of registration of service information to SE72.
[0245] In step S132, the service information management unit 141 of the service provider server 33 receives a notification of completion of registration of service information to SE72 transmitted from the mobile terminal 31 and displays it as necessary.
[0246] In step S96, the terminal application 41 presents to the user a notification that the registration of service information to SE72 has been completed.
[0247] As a result, in step S58, the user recognizes that the service information necessary to receive the requested service has been registered in SE72.
[0248] Through the above series of processes, the user can receive services using their own card 21. This process generates the necessary ID information for receiving the service, registers it in the mobile terminal 31, and allows the user to display the card information on the mobile terminal 31 indicating that they are eligible to receive the service. Furthermore, the user can register the necessary service information in the SE 72 of the mobile terminal 31, and based on the service information registered in the SE 72, they can receive the service via contactless service.
[0249] <Processing when managing service information with TEE> Next, referring to the flowchart in Figure 11, we will explain the process when the information processing system 11 in Figure 1 manages service information using the TEE.
[0250] In Figure 11, the operations of the following components are shown from left to right: user, mobile terminal 31, application management server 36, terminal application 41, card 21, service provider server 33, management DB 33a, eKYC provider server 34, and TEE 81.
[0251] Furthermore, the processes in steps S301 to S307, S311 to S314, S321 to S322, S331 to S340, S361 to S363, S371 to S378, S391 to S392, and S401 to S402 in the flowchart of Figure 11 are identical to the processes in steps S51 to S57, S61 to S64, S71 to S72, S81 to S90, S111 to S113, S121 to S128, S141 to S142, and S151 to S152 in the flowcharts of Figures 9 and 10, so their explanation is omitted.
[0252] That is, in step S378, the service information management unit 141 checks the registered content of the service information required to provide the registered service and the Capability information, and determines the management location of the service information.
[0253] That is, here, the service information management unit 141 executes the service information management location determination process described by referring to the flowchart of FIG. 8, and determines the management location of the service information. FIG. 11 is a flowchart for explaining the process when it is determined that the service information is to be managed by the TEE81 in the process of step S378. It is a flowchart for explaining the process when determined.
[0254] Therefore, in step S379, the service information management unit 141 controls the communication unit 135 and notifies the mobile terminal 31 to register the service information using the TEE81. To do.
[0255] In step S341, the terminal application 41 obtains a notification indicating that it manages service information using the TEE81 transmitted from the service provider server 33. To do.
[0256] In steps S342 and S411, the terminal application 41 opens a session with the TEE81. To do.
[0257] In steps S343 and S412, the terminal application 41 registers service information including ID information and the like required to provide the service requested for registration from the service provider server 33 in the TEE81.
[0258] In steps S344 and S413, the terminal application 41 supplies a completion notification indicating the completion of registration of the service information in the TEE81. At this time, the session between the terminal application 41 and the TEE81 is closed.
[0259] In step S345, the terminal application 41 displays, for example, information indicating that service information for receiving a service has been registered in the TEE 81 as an image on a display unit constituting the output unit 123 and reflects it on the ticket surface image.
[0260] In step S346, the terminal application 41 transmits a completion notification of the registration of service information to the TEE 81 to the service provider server 33.
[0261] In step S380, the service information management unit 141 of the service provider server 33 acquires a completion notification of the registration of service information transmitted from the mobile terminal 31 to the TEE 81 and presents it as necessary.
[0262] In step S347, the terminal application 41 presents a completion notification of the registration of service information to the TEE 81.
[0263] As a result, in step S308, the user recognizes that the service information required to receive the service requested for provision has been registered in the TEE 81.
[0264] Through the above series of processes, it becomes possible to register service information required to receive a service provided by the card 21 owned by the user himself / herself in the TEE 81 of the mobile terminal 31. Based on the service information registered in the TEE 81, when the HCE 82 is installed, it becomes possible to receive the provision of services in non-contact services.
[0265] <Processing when managing service information with a terminal application> Next, referring to the flowchart of FIG. 12, the processing when the service information by the information processing system 11 of FIG. 1 is managed by the terminal application 41 will be described.
[0266] In Figure 12, the operations of the following are shown from left to right: user, mobile terminal 31, application management server 36, terminal application 41, card 21, service provider server 33, management DB 33a, and eKYC provider server 34.
[0267] Furthermore, the processes in steps S501 to S507, S521 to S524, S531 to S532, S541 to S550, S561 to S563, S571 to S578, S591 to S592, and S601 to S602 in the flowchart of Figure 12 are identical to the processes in steps S51 to S57, S61 to S64, S71 to S72, S81 to S90, S111 to S113, S121 to S128, S141 to S142, and S151 to S152 in the flowcharts of Figures 9 and 10, so their explanation is omitted.
[0268] In other words, in step S578, the service information management unit 141 confirms the registered service information and capability information necessary to provide the registered service, and determines the location for managing the service information.
[0269] In other words, the service information management unit 141 here executes the service information management location determination process, as explained with reference to the flowchart in Figure 8, to determine the management location of the service information. Figure 12 is a flowchart illustrating the process when it is determined in step S578 that the service information will be managed by the terminal application 41.
[0270] Therefore, in step S579, the service information management unit 141 controls the communication unit 135 to notify the mobile terminal 31 to register service information using the terminal application 41.
[0271] In step S551, the terminal application 41 receives a notification from the service provider server 33 indicating that it will manage service information using the terminal application 41.
[0272] In step S552, the terminal application 41 displays an image on the display unit of the output unit 123 that shows the security level of the service information managed by the terminal application 41 itself and requests confirmation from the user.
[0273] In step S508, the user confirms that there is no problem with the security level of the presented service information being managed by the terminal application 41, which is not in a secure environment.
[0274] In step S509, the user operates the input unit 122 to input information indicating that they have confirmed that service information is managed in a terminal application 41 that is not in a secure environment, and a corresponding operation signal is sent to the terminal application 41.
[0275] In step S553, the terminal application 41 obtains information indicating that it has confirmed that service information is being managed in a terminal application 41 that is not in a secure environment.
[0276] Furthermore, if the user determines that, based on the security level of the service information, it is problematic for it to be managed in the terminal application 41, which is not a secure environment, information indicating that management by the terminal application 41 is not permitted will be entered, preventing the terminal application 41 from managing the service information. In this case, the service information may be managed by a method other than the terminal application 41, for example, by the service provider server 33.
[0277] In step S554, the terminal application 41 registers service information for receiving a service by itself, and displays information indicating that it manages the service information, for example, as an image on a display unit constituting the output unit 123, and reflects it on the ticket surface image.
[0278] In step S555, the terminal application 41 transmits a completion notice indicating that the process of registering the service information by itself has been completed to the service provider server 33.
[0279] In step S580, the service information management unit 141 of the service provider server 33 acquires a completion notice of registration of the service information transmitted from the mobile terminal 31 to the terminal application 41, and presents it as necessary.
[0280] In step S556, the terminal application 41 presents a completion notice of registration of the service information to itself.
[0281] As a result, in step S510, the user recognizes that the service information required to receive the service requested for provision has been registered in the terminal application 41.
[0282] Through the above series of processes, it becomes possible to register information required to receive a service provided by the card 21 possessed by the user himself / herself in the terminal application 41 of the mobile terminal 31. Based on the service information registered in the terminal application 41, when the HCE 82 is installed, a service can be provided by a contactless service. It becomes possible to receive the provision of the service.
[0283] <Registration process of HCE> Next, referring to the flowchart of FIG. 13, even when service information is registered in the terminal application 41 or the TEE 81, the registration of the HCE 82 that realizes the contactless function (contactless service). Even when service information is registered in the terminal application 41 or the TEE 81, the registration of the HCE 82 that realizes the contactless function (contactless service). This section explains the installation process.
[0284] In Figure 13, the operations of the user, mobile terminal 31, terminal application 41, and service provider server 33 are shown from left to right.
[0285] In step S651, when the user makes an operation input to the input unit 122 of the mobile terminal 31 instructing it to start the terminal application 41, an operation signal instructing the start of the terminal application 41 is output to the control unit 121 of the mobile terminal 31.
[0286] In step S661, the control unit 121 of the mobile terminal 31 acquires an operation signal instructing the launch of the terminal application 41.
[0287] In step S662, the control unit 121 of the mobile terminal 31 starts the terminal application 41 based on an operation signal that instructs the startup of the terminal application 41.
[0288] In response to this, in step S671, the terminal application 41 is launched.
[0289] In step S652, the user inputs an operation request to register for the contactless service to the input unit 122 of the mobile terminal 31, thereby supplying a registration (installation) request for the contactless service (HCE82 that implements it) to the terminal application 41.
[0290] In step S672, the terminal application 41 receives a registration (installation) request for the contactless service (HCE82).
[0291] In step S673, the terminal application 41 controls the communication unit 125 to request permission to use the contactless function to realize contactless service, information requesting parameters for using the contactless function, and Device Capability information to the service provider server 3 Send to 3.
[0292] Here, Device Capability information refers to the ability to realize contactless functionality in the mobile terminal 31. This information indicates the physical configuration of the equipment and how data can be safely stored. For example, it shows the location where data from SE72 and TEE81 is stored and whether or not the CLF73, which is a contactless function, is present. The parameters are also relevant parameters needed when configuring HCE82 to drive the CLF73, which is a contactless function, when implementing contactless functionality using the CLF73.
[0293] Specifically, when implementing a contactless function called Type A as defined in ISO / IEC 14443. The UID (Unique Identifier) required to respond to the Request command, called REQA, SAK (Select Acknowledge) and ATQA (Answer To) are used when responding to subsequent commands. Examples include Request acc (Request Account), ATS (Answer To Select Account), FWI (Frame Waiting Time), and SFGI (Start-up Frame Guard Time). Furthermore, when implementing a contactless function called Type F as defined in ISO / IEC 18092, in order to respond to a Polling command called REQF, Examples include IDm (Manufacture ID), System Code, and PMm (Manufacture Parameter).
[0294] Furthermore, Device Capability information includes container issuance information and issuance information held by the SE72 side. Person identification information can also be used. This data can be read using commands such as the GET DATA command specified by the SE72 issuer or GlobalPlatform, and by using this information, it is possible to determine whether contactless communication using CLF is possible.
[0295] Alternatively, the SE management application 72a within the mobile terminal 31 manages terminal identification information. This includes the terminal name operated by the telecommunications carrier, the type of SE72, the CLF model number, version, etc. It stores information related to the system, and by sending this information to the SE management server 35, the mobile terminal 31 can be identified.
[0296] In step S691, the service information management unit 141 of the service provider server 33 obtains information requesting permission to use the contactless function to realize contactless service, parameters for using the contactless function, and device capability information.
[0297] In step S692, the service information management unit 141 confirms the device capability information necessary to realize contactless service.
[0298] In step S693, if the service information management unit 141 confirms that the device has the capability to perform contactless functions, such as CLF73, based on the confirmed Device Capability information, it controls the communication unit 135 to send permission to use the contactless function and the parameters necessary to perform the contactless function to the mobile terminal 31.
[0299] In step S674, the terminal application 41 of the mobile terminal 31 obtains information from the service provider server 33 regarding permission to use the contactless function and the parameters necessary to implement the contactless function.
[0300] In step S675, the terminal application 41 instructs the control unit 121 to implement a function for the CLF73, which is a contactless device in the mobile terminal 31. It provides the parameters and usage requirements for doing so.
[0301] In step S663, the control unit 121 obtains a request from the terminal application 41 to use the contactless function and the parameters for realizing the contactless function, and sets the CLF73, which is the contactless function, to an usable state based on the obtained parameters. Unit 121 uses parameters to install HCE82 in Figure 6, makes it controllable by CLF73, and uses the contactless function to connect to TEE81 and terminal application 41. To enable the provision of services using more managed service information.
[0302] In step S664, the control unit 121 notifies the terminal application 41 that the contactless function is available and that it is now in a state where it can provide contactless services.
[0303] In step S676, the terminal application 41 receives a notification from the control unit 121 indicating that the contactless function has become available and that it is in a state where it can provide contactless services.
[0304] In step S677, the terminal application 41 controls the communication unit 125 to send a completion notification to the service provider server 33 indicating that the contactless function is available and that the system has been set up to provide contactless services.
[0305] In step S694, the service information management unit 141 of the service provider server 33 receives a completion notification from the mobile terminal 31 indicating that the contactless function has become available and the system has been set to a state where contactless services can be provided.
[0306] In step S678, the terminal application 41 displays information indicating that the contactless function has become available and that it is in a state where contactless services can be provided (contactless function ON) as an image on the display unit that constitutes the output unit 123, and reflects this information on the ticket image.
[0307] In step S679, the terminal application 41 presents a notification to the user indicating that the contactless function is available and that contactless services can be provided.
[0308] As a result, in step S653, the user recognizes that the contactless function has become available on the mobile terminal 31 for using the corresponding service, and that the system is in a state where contactless services can be provided.
[0309] Through the above series of processes, the services that the user can receive using the card 21 are managed by the terminal application 41 and TEE81 on the mobile terminal 31. Based on the service information provided, it will be possible to receive services using contactless functionality.
[0310] Furthermore, the above describes an example in which the location for managing service information is determined by the service provider server 33 based on the security level of the service information and the capability information of the mobile terminal 31.
[0311] However, the location for managing service information may be determined by something other than the service provider server 33. For example, the terminal application 41 of the mobile terminal 31 may determine the location based on the security level of the service information and the capability information of the mobile terminal 31.
[0312] <Switching the information displayed on the ticket> The service information, such as the ID information issued to receive the aforementioned services, will be presented as information on the ticket itself. However, there are times when it is not necessary to present all of this information.
[0313] For example, when receiving a service that functions as a student ID, the card information 151 shown in the upper part of Figure 14 is presented.
[0314] In the ticket information 151 shown in the upper part of Figure 14, the top line reads "〇〇〇〇 University," and below that is the affiliation field 161, which in this case reads "Faculty of Environmental Information, Department of Information Media." Further below that is the name field 162, which reads "1234567 Tokyo Hanako." It is written as "".
[0315] Further below, from top to bottom, it reads: "Born October 27, 1991," "This certifies that I am a student of this university," and "Expiration date: March 31, 2018."
[0316] Additionally, on the right side of ticket information 151, below the words "Student ID," a photo of the user is attached.
[0317] By the way, regarding the information that the user wants to prove using the ticket information 151 mentioned above, it may suffice for only some of the information shown in the upper part of Figure 14 to be proven. For example, it may suffice for some of the following to be proven: age, university attended, university location, faculty, or department.
[0318] For example, in cases where it is sufficient to prove that the person is a university student and is 20 years of age or older, it is not necessary to provide information in the affiliation field 161 or the name field 162. In this case, for example, when verifying age at an izakaya (Japanese pub), the terminal application 41 may display an icon such as "Age Verification at Izakaya". By pressing this icon, the user can provide the izakaya staff with information that complies with the law.
[0319] Therefore, in cases where it is sufficient to prove that the person is a university student and is 20 years of age or older, the information may be presented in a hidden state, as shown in the affiliation column 161' and name column 162' in the lower part of Figure 14.
[0320] As shown in the lower section of Figure 14, the identity of the person can be confirmed through the photograph, and since the university name, date of birth, and expiration date are provided, it is possible to prove that the person is a university student and their age.
[0321] In cases where only age needs to be verified, the university name may also be hidden. In this case, for example, terminal application 41 may display an icon such as "student discount at ticket gate." By pressing this icon, the user can show the station attendant at the ticket gate information in accordance with the law. Similarly, by providing icons tailored to the user's lifestyle, such as "student discount at movie theaters," users can provide information while protecting their privacy in a legally compliant manner, without having to consciously think about what information should be hidden or disclosed.
[0322] Furthermore, even without such icons, the terminal application 41 can automatically determine the situation by providing location information and change the verification information displayed on the screen. If there are any deficiencies after the information has been displayed, it is also possible to switch by pressing the aforementioned icons.
[0323] Furthermore, users may be able to arbitrarily set which fields are displayed and which are hidden. In place of hidden data, users could share SNS (Social Network Service) account information, hobbies, club affiliations, or favorite artist names with others. It is also possible to implement services that allow users to register additional information they need themselves, and then use that information to facilitate information exchange as part of their identity verification process.
[0324] By allowing users to customize the information displayed on the ticket, it becomes unnecessary to expose personal information, thus enabling the presentation of identification information while respecting privacy.
[0325] Such personal authentication information is handled by ISO / IEC 18013-5, which defines mobile driver's licenses that have been increasingly developed in recent years, and ISO / IEC 23220, which defines eID, using a verification device called a Verifier. This technology enables contactless communication methods such as NFC, WiFi Direct, and Bluetooth®. A system is constructed that enables the reading of personal information. In this case, the Verifier sends Engagement information, requests the mobile terminal 31 for the information necessary for verification, and the user grants permission to disclose the information to the Verifier. This is a request-and-permission flow. This is a mechanism to eliminate the risk of personal information being read against the user's will. In this embodiment, the above flow is also taken into consideration, and the information displayed on the ticket when the user holds it up to the Verifier is judged to be information that the user has consented to at that time, allowing the permission process to proceed and improving convenience. Of course, depending on the user's settings, it is possible to create a more secure environment for providing personal information by setting it so that it can proceed without final confirmation from the user only when the screen is not locked, or by linking the screen lock and contactless function to create a state where it does not operate even when physically held up to the Verifier.
[0326] <<2. Example of execution by software>> Incidentally, the series of processes described above can be executed by hardware, but they can also be executed by software. When the series of processes are executed by software, the programs that make up the software are installed from a storage medium onto a computer that has dedicated hardware built into it, or onto a general-purpose computer, for example, that can perform various functions by installing various programs.
[0327] Figure 15 shows an example of a general-purpose computer configuration. This personal computer has a built-in CPU (Central Processing Unit) 1001. The CPU 1001 has a bus 100. An input / output interface 1005 is connected via 4. A ROM (Read Only Memory) 1002 and a RAM (Random Access Memory) 1003 are connected to bus 1004.
[0328] The input / output interface 1005 includes an input unit 1006 consisting of input devices such as a keyboard and mouse for the user to input operation commands, an output unit 1007 for outputting images of the processing operation screen and processing results to a display device, a storage unit 1008 consisting of a hard disk drive for storing programs and various data, and a LAN (Local Area Network) adapter. Furthermore, a communication unit 1009 is connected to it, which performs communication processing via a network such as the Internet. In addition, removable memory such as magnetic disks (including flexible disks), optical disks (including CD-ROM (Compact Disc-Read Only Memory) and DVD (Digital Versatile Disc)), magneto-optical disks (including MD (Mini Disc)), or semiconductor memory is connected. A drive 1010 is connected to the storage medium 1011 for reading and writing data.
[0329] The CPU 1001 reads programs stored in the ROM 1002, or from removable storage media 1011 such as magnetic disks, optical disks, magneto-optical disks, or semiconductor memory, and installs them in the storage unit 1008. From the storage unit 1008, it loads data into the RAM 1003. It executes various processes according to the programmed instructions. RAM1003 also stores data necessary for CPU1001 to perform various processes as needed.
[0330] In a computer configured as described above, the CPU 1001, for example, the memory unit 1008 The above-described series of processes are performed by loading the program stored in RAM 1003 via the input / output interface 1005 and bus 1004 and executing it.
[0331] The programs that the computer (CPU1001) runs are, for example, package media. The program can be provided by recording it on a removable storage medium 1011, etc. Furthermore, the program can be provided via wired or wireless transmission media such as a local area network, the internet, or digital satellite broadcasting.
[0332] In a computer, a program can be installed in the storage unit 1008 via the input / output interface 1005 by inserting a removable storage medium 1011 into the drive 1010. Alternatively, a program can be received by the communication unit 1009 via a wired or wireless transmission medium and installed in the storage unit 1008. Furthermore, programs can be pre-installed in the ROM 1002 or the storage unit 1008. can.
[0333] The programs executed by the computer may be programs that are processed chronologically in the order described herein, or they may be programs that are processed in parallel or at necessary times, such as when a call is made.
[0334] Furthermore, the CPU 1001 in Figure 15 corresponds to the control unit 121 of the mobile terminal 31 in Figure 6, and Figure 7 This enables the functionality of the control unit 131 of the service provider server 33.
[0335] Furthermore, in this specification, a system means a collection of multiple components (devices, modules (parts), etc.), regardless of whether all components are located in the same enclosure or not. Therefore, multiple devices housed in separate enclosures and connected via a network, and a single device in which multiple modules are housed in one enclosure, are both considered systems.
[0336] The embodiments described herein are not limited to those described above, and various modifications are possible without departing from the gist of this disclosure.
[0337] For example, this disclosure can take the form of cloud computing, in which a single function is shared and processed collaboratively by multiple devices over a network.
[0338] Furthermore, each step described in the flowchart above can be performed by a single device, or it can be divided and performed by multiple devices.
[0339] Furthermore, if a single step includes multiple processes, those processes can be executed by a single device or shared among multiple devices.
[0340] Furthermore, this disclosure can also be structured as follows:
[0341] <1> A determination unit determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. An information processing device equipped with the following features. <2> The determination unit determines the storage location of the service information in the mobile terminal by selecting the type of storage mechanism for storing the service information provided in the mobile terminal according to the security level of the service information to be stored. <1> The information processing device described above. <3> The determination unit recognizes the type of storage mechanism that stores the service information provided by the mobile terminal, based on the capability information of the mobile terminal. <1> or <2> The information processing device described above. <4> The Capability information of the mobile terminal is information indicating the type of storage mechanism that the mobile terminal has for storing the service information, and that the storage mechanism consists of the mobile terminal's SE (Secure Element), the mobile terminal's TEE (Trusted Execution Environment), and a terminal application which is an application program for receiving the service on the mobile terminal. <3> The information processing device described above. <5> The determination unit determines the security level of the service information based on whether the service information is for a keyed service or for an unkeyed service. <4> The information processing device described above. <6> If the service information is the service information for the keyed service, and the mobile terminal is equipped with the SE, the determination unit determines that the storage location for the service information is the SE. <5> The information processing device described above. <7> If the service information is the service information for the keyed service, and the mobile terminal does not have the SE, and is not permitted to store it in a storage mechanism other than the SE, the determination unit determines the storage location of the service information itself. <5> The information processing device described above. <8> If the service information is the service information for the keyed service, and the mobile terminal does not have the SE and is permitted to store it in a storage mechanism other than the SE, then the determination unit determines the storage location of the service information. The decision is made to use the TEE. <5> The information processing device described above. <9> If the service information is the service information for the keyed service, and the mobile terminal does not have the SE and is permitted to store it in a storage mechanism other than the SE, and does not have the TEE, the determination unit determines the storage location of the service information. The aforementioned terminal application is selected. <5> The information processing device described above. <10> If the service information is the service information for the keyed service, and the mobile terminal does not have the SE, and is permitted to store it in a storage mechanism other than the SE, the determination unit converts the service information into a token and stores it in the determined storage location. <5> The information processing device described above. <11> If the service information is the service information for the keyed service and the Capability information cannot be obtained, the determination unit queries the user of the mobile terminal for the storage location of the service information and determines the storage location according to the response to the query. <5> The information processing device described above. <12> If the service information is the service information for the keyed service and the Capability information cannot be obtained, the determination unit queries the mobile terminal for the Capability information, and if it cannot obtain the Capability information as a response to the query, it queries the user of the mobile terminal for the storage location of the service information and determines the storage location according to the response to the query. <5> The information processing device described above. <13> If the service information is the service information for the keyless service and does not include special identification information, the determination unit determines the storage location of the service information to be the terminal application. <5> The information processing device described above. <14> If the service information is the service information for the keyless service, and the service information includes special identification information, then when the TEE is provided, the determination unit shall The storage location for the service information is determined to be the TEE. <5> The information processing device described above. <15> If the service information is the service information for the keyless service and the service information includes special identification information, then the determination is made when the TEE is not provided. The department determines that the storage location for the service information is the terminal application. <5> The information processing device described above. <16> If the service information is the service information for the keyless service and the service information includes special identification information, and the Capability information cannot be confirmed, the determination unit queries the user of the mobile terminal for the storage location of the service information and determines the storage location according to the response to the query. <5> The information processing device described above. <17> The storage location for service information, which is information required when receiving services via a network using a mobile device, is determined based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile device. An information processing method that includes steps. <18> A determination unit determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. A program that makes a computer function. <19> A determination unit determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. A mobile device equipped with the following features. <20> A determination unit determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. An information processing system equipped with the following features. [Explanation of Symbols]
[0342] 11 Information processing system, 21 Card, 22 Reader / writer, 31, 31-1 to 31-n Mobile terminal, 32 Management device, 33 Service provider server, 34 eKYC provider server, 35 SE management server, 36 Application management server, 41, 41-1 to 41-n Terminal application, 71 DH (Device Host), 72 SE (Secure Element), 73 CLF (ContactLess Frontend), 81 TEE (Trusted Execution Environment), 91 HCE (Host Card Emulation), 141 Service information management unit, 112, 112' Drop event detection processing unit, 113, 113', 113'' Drop location notification signal transmission processing unit, 113, 114' Drop notification processing unit
Claims
1. The mobile terminal includes a determination unit that determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. The aforementioned determination unit, Based on whether the service information is for a keyed service or for an unkeyed service, the security level of the service information is determined. Based on the Capability information of the mobile terminal, which indicates the presence or absence of the storage mechanism consisting of the SE (Secure Element) of the mobile terminal, the TEE (Trusted Execution Environment) of the mobile terminal, and a terminal application which is an application program for receiving the service, the type of storage mechanism for storing the service information provided by the mobile terminal is recognized. The storage location of the service information on the mobile terminal is determined by selecting the storage mechanism based on the security level of the service information and the type of storage mechanism recognized, or by selecting the storage mechanism in response to the user of the mobile terminal or an inquiry to the mobile terminal. When selecting a storage mechanism based on the security level of the service information and the type of storage mechanism recognized, the storage location of the service information on the mobile terminal is determined further, depending on whether storage in the recognized storage mechanism is permitted or whether the service information contains special identification information. Information processing device.
2. If the service information is the service information for the keyed service, and the mobile terminal is equipped with the SE, the determination unit determines that the storage location for the service information is the SE. The information processing apparatus according to claim 1.
3. If the service information is the service information for the keyed service, and the mobile terminal does not have the SE, and is not permitted to store it in a storage mechanism other than the SE, the determination unit determines the storage location of the service information itself. The information processing apparatus according to claim 1.
4. If the service information is the service information for the keyed service, and the mobile terminal does not have the SE and is permitted to store it in a storage mechanism other than the SE, then the determination unit determines that the storage location for the service information is the TEE. The information processing apparatus according to claim 1.
5. If the service information is the service information for the keyed service, and the mobile terminal does not have the SE and is permitted to store it in a storage mechanism other than the SE, and does not have the TEE, the determination unit determines the storage location of the service information to be the terminal application. The information processing apparatus according to claim 1.
6. If the service information is the service information for the keyed service, and the mobile terminal does not have the SE, and is permitted to store it in a storage mechanism other than the SE, the determination unit converts the service information into a token and stores it in the determined storage location. The information processing apparatus according to claim 1.
7. If the service information is the service information for the keyed service and the Capability information cannot be obtained, the determination unit queries the user of the mobile terminal for the storage location of the service information and determines the storage location according to the response to the query. The information processing apparatus according to claim 1.
8. If the service information is the service information for the keyed service and the Capability information cannot be obtained, the determination unit queries the mobile terminal for the Capability information, and if it cannot obtain the Capability information as a response to the query, it queries the user of the mobile terminal for the storage location of the service information and determines the storage location according to the response to the query. The information processing apparatus according to claim 1.
9. If the service information is the service information for the keyless service and does not include special identification information, the determination unit determines the storage location of the service information to be the terminal application. The information processing apparatus according to claim 1.
10. If the service information is the service information for the keyless service and the service information includes special identification information, then when the TEE is provided, the determination unit determines that the storage location for the service information is the TEE. The information processing apparatus according to claim 1.
11. If the service information is the service information for the keyless service and the service information includes special identification information, and the TEE is not provided, the determination unit determines the storage location of the service information to be the terminal application. The information processing apparatus according to claim 1.
12. If the service information is the service information for the keyless service and the service information includes special identification information, and the Capability information cannot be confirmed, the determination unit queries the user of the mobile terminal for the storage location of the service information and determines the storage location according to the response to the query. The information processing apparatus according to claim 1.
13. The process includes determining the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. The aforementioned decision process is, Based on whether the service information is for a keyed service or for an unkeyed service, the security level of the service information is determined. Based on the Capability information of the mobile terminal, which indicates the presence or absence of the storage mechanism consisting of the SE (Secure Element) of the mobile terminal, the TEE (Trusted Execution Environment) of the mobile terminal, and a terminal application which is an application program for receiving the service, the type of storage mechanism for storing the service information provided by the mobile terminal is recognized. The storage location of the service information on the mobile terminal is determined by selecting the storage mechanism based on the security level of the service information and the type of storage mechanism recognized, or by selecting the storage mechanism in response to the user of the mobile terminal or an inquiry to the mobile terminal. When selecting a storage mechanism based on the security level of the service information and the type of storage mechanism recognized, the storage location of the service information on the mobile terminal is determined further, depending on whether storage in the recognized storage mechanism is permitted or whether the service information contains special identification information. Information processing methods.
14. A computer is configured to function as a determination unit that determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. The aforementioned determination unit, Based on whether the service information is for a keyed service or for an unkeyed service, the security level of the service information is determined. Based on the Capability information of the mobile terminal, which indicates the presence or absence of the storage mechanism consisting of the SE (Secure Element) of the mobile terminal, the TEE (Trusted Execution Environment) of the mobile terminal, and a terminal application which is an application program for receiving the service, the type of storage mechanism for storing the service information provided by the mobile terminal is recognized. The storage location of the service information on the mobile terminal is determined by selecting the storage mechanism based on the security level of the service information and the type of storage mechanism recognized, or by selecting the storage mechanism in response to the user of the mobile terminal or an inquiry to the mobile terminal. When selecting a storage mechanism based on the security level of the service information and the type of storage mechanism recognized, the storage location of the service information on the mobile terminal is determined further, depending on whether storage in the recognized storage mechanism is permitted or whether the service information contains special identification information. program.
15. The mobile terminal includes a determination unit that determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. The aforementioned determination unit, Based on whether the service information is for a keyed service or for an unkeyed service, the security level of the service information is determined. Based on the Capability information of the mobile terminal, which indicates the presence or absence of the storage mechanism consisting of the SE (Secure Element) of the mobile terminal, the TEE (Trusted Execution Environment) of the mobile terminal, and a terminal application which is an application program for receiving the service, the type of storage mechanism for storing the service information provided by the mobile terminal is recognized. The storage location of the service information on the mobile terminal is determined by selecting the storage mechanism based on the security level of the service information and the type of storage mechanism recognized, or by selecting the storage mechanism in response to the user of the mobile terminal or an inquiry to the mobile terminal. When selecting a storage mechanism based on the security level of the service information and the type of storage mechanism recognized, the storage location of the service information on the mobile terminal is determined further, depending on whether storage in the recognized storage mechanism is permitted or whether the service information contains special identification information. Mobile device.
16. The mobile terminal includes a determination unit that determines the storage location for service information, which is information required when receiving services via a network using a mobile terminal, based on the security level of the service information and the type of storage mechanism for storing the service information provided by the mobile terminal. The aforementioned determination unit, Based on whether the service information is for a keyed service or for an unkeyed service, the security level of the service information is determined. Based on the Capability information of the mobile terminal, which indicates the presence or absence of the storage mechanism consisting of the SE (Secure Element) of the mobile terminal, the TEE (Trusted Execution Environment) of the mobile terminal, and a terminal application which is an application program for receiving the service, the type of storage mechanism for storing the service information provided by the mobile terminal is recognized. The storage location of the service information on the mobile terminal is determined by selecting the storage mechanism based on the security level of the service information and the type of storage mechanism recognized, or by selecting the storage mechanism in response to the user of the mobile terminal or an inquiry to the mobile terminal. When selecting a storage mechanism based on the security level of the service information and the type of storage mechanism recognized, the storage location of the service information on the mobile terminal is determined further, depending on whether storage in the recognized storage mechanism is permitted or whether the service information contains special identification information. Information processing system.
Citation Information
Patent Citations
Automatic unwanted file erasing device
JP1996328915A
Recording and reproducing device, and automatic file deletion method
JP2005011469A
Information processor and method, setting apparatus and method, and program
JP2007124072A
Terminal device for non-contact IC card and information processing system
JP2013120444A
Data processing system, initializing method for the same, and computer program product
JP2015007978A