Terminal and method
The terminal with an isolated secure storage area and user-authenticated access control system addresses the issue of multiple issuer permissions, allowing easy and secure access to isolated storage, enhancing application distribution and management.
Patent Information
- Application Number
- PCT/JP2024/002909
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-30
- Publication Date
- 2025-08-07
AI Technical Summary
Existing secure storage areas, such as those in secure elements and Trusted Execution Environments (TEE), cannot be accessed without permission from multiple issuers, hindering wide-area distribution of applications.
A terminal with a second memory unit having a secure storage area logically or physically isolated from a first memory unit, equipped with an authentication key management unit and an access control unit that manages and controls access using user-specific authentication keys, allowing access without issuer permission.
Enables easy and secure access to isolated storage areas, facilitating the use of secure elements and TEEs by users, enabling dynamic application installation and management, and overcoming storage capacity limitations.
Smart Images

Figure JP2024002909_07082025_PF_FP_ABST
Abstract
Description
Terminal and method
[0001] One aspect of the present disclosure relates to a terminal and a method.
[0002] A secure element (see, for example, Patent Document 1) is known that can securely store or process applications or data and is made up of a tamper-resistant IC chip. The secure element includes a storage area and an interface that executes encryption processing, etc. A terminal equipped with the secure element enables, for example, secure electronic payments.
[0003] Japanese Patent Application Laid-Open No. 2021-100227
[0004] However, the storage area of a secure element cannot be accessed without a key issued by a server operated by the issuer of the secure element (hereinafter simply referred to as the issuer). Therefore, businesses and other entities that wish to use a secure element must request permission to use it from the issuer. However, there are many issuers, and it is not realistic to request permission to use it from each issuer, for example, when wide-area distribution of an application that uses a secure element is desired. Furthermore, this problem is not limited to secure elements, but also exists in storage that has a memory area that is logically or physically isolated from the outside, such as a Trusted Execution Environment (TEE).
[0005] Therefore, an object of one aspect of the present invention is to provide a terminal and a method that can easily use a secure storage area that is logically or physically isolated.
[0006] A terminal according to one aspect of the present disclosure includes a second memory unit having a secure memory area logically or physically isolated from a first memory unit, an authentication key management unit that manages an authentication key generated based on first information that authenticates access to the terminal or second information about a user, and an access control unit that controls access to the second memory unit based on the result of an authentication process that uses the authentication key managed by the authentication key management unit.
[0007] According to one aspect of the present disclosure, it is possible to easily use a secure storage area that is logically or physically isolated.
[0008] Fig. 1 is a diagram showing an example of the functional configuration of a terminal according to an embodiment. Fig. 2 is a diagram showing an example of a usage mode of a terminal according to an embodiment. Fig. 3 is a flowchart showing an example of a method for generating an authentication key for a secure element. Fig. 4 is a diagram showing an example of a screen of a management application. Fig. 5 is a diagram showing another example of a screen of a management application. Fig. 6 is a flowchart showing an example of a process when installing an application in a second area of a secure element. Fig. 7 is a diagram showing an example of the hardware configuration of a terminal according to an embodiment.
[0009] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the description of the drawings, the same elements are designated by the same reference numerals, and duplicate explanations will be omitted. Furthermore, the embodiments of the present disclosure in the following description are specific examples of the present invention, and the present invention is not limited to these embodiments unless otherwise specified to limit the present invention.
[0010] The terminal 1 is a mobile communication terminal that performs mobile communication in a mobile communication network (by connecting to the mobile communication network). In this embodiment, the terminal 1 is assumed to be a smartphone, but may also be a mobile communication terminal such as a tablet terminal other than a smartphone or a personal computer.
[0011] Fig. 1 is a diagram showing an example of the functional configuration of a terminal 1 according to an embodiment. As shown in Fig. 1, the terminal 1 is configured to include a first storage unit 11, a display operation unit 13, a second storage unit 21, a management unit 31, and an access control unit 33. The functional blocks in the terminal 1 do not have to be configured as shown in Fig. 1; some functional blocks may be missing, multiple functional blocks may be integrated into one functional block, or one functional block may be separated into multiple functional blocks.
[0012] Hereinafter, each function of the terminal 1 shown in FIG. 1 will be described.
[0013] The first storage unit 11 stores various data handled by the terminal 1. Examples of the data include an operating system (OS) program, various application programs, and files such as images, videos, text, documents, and audio. The display operation unit 13 notifies the operator of various information and accepts input of various information from the operator.
[0014] The second storage unit 21 has a secure storage area that is logically or physically isolated from the first storage unit 11. The second storage unit 21 of this embodiment is a secure element that is physically isolated from the first storage unit 11. The secure element is configured as hardware such as a tamper-resistant IC chip (semiconductor product) or as an operating system (software) in a logically or physically isolated secure storage area. A secure element configured as hardware may be directly incorporated into the terminal 1, incorporated via a Universal Integrated Circuit Card (UICC) or a so-called Subscriber Identity Module Card (SIM card), incorporated via a Secure Digital (SD) card, or incorporated via a Near Field Communication (NFC) terminal, for example.
[0015] The second memory unit 21, which is configured by a secure element, has a first area (storage area) 23 and a second area (storage area) 25. In the following description, simply referring to the second memory unit 21 refers to the secure element. The first area 23 and the second area 25 are areas to which access is controlled by an access control unit 33, which will be described in detail later. The first area 23 is, for example, an ISD (Issuer Secure Domain), and is an area managed by the issuer of the secure element. The ISD is an area for storing private keys and management applications for the secure element. The management application will be described in detail later. In this way, the first area 23 is an area used for managing and controlling the secure element. The second area 25 is, for example, an APSD (Application Secure Domain), and is an area where applications (applets) that use the secure mechanism of the secure element are installed.
[0016] FIG. 2 illustrates an example of how a terminal according to an embodiment is used. As illustrated in FIG. 2 , the terminal 1, a TSM (Trusted Service Manager) server 3, and a management server 5 managed by a carrier are connected to each other via a network such as a mobile communication network and can transmit and receive information to and from each other. The TSM server 3 is a server managed by a secure element issuer and directly or indirectly manages the secure elements, for example, by issuing authentication keys required for accessing the secure elements. The management server 5 is a server managed by a carrier such as a transportation IC card carrier, a point card carrier, an electronic payment carrier, a My Number Portal administrator, a Taspo card or its successor, a driver's license management carrier, or an insurance card management carrier. The management server 5 distributes applications issued by each carrier to the terminal 1 and exchanges information with the applications to provide various services to the user of the terminal 1.
[0017] The management unit 31 manages and controls the secure element. The management unit 31 is configured as a management application installed in the first area 23 of the secure element. The management application may function as an interface (API: Application Programming Interface) or applet that controls access to the first area 23 and the second area 25 and performs encryption processing and the like using a private key stored in the first area 23. The management application will be described in detail later.
[0018] The management unit 31 displays a list screen SC1 for selecting applications that use the secure element, as shown in Fig. 4, for example. The applications displayed on the list screen SC1 are applications installed in the second area 25. Also, for example, the balances of Card A and Card B shown in Fig. 4 are information that can be obtained from the applications corresponding to Card A and Card B installed in the second area 25. Also, the points of Card C are information that can be obtained from the application corresponding to Card C installed in the second area 25.
[0019] The access control unit 33 controls access to the second storage unit 21 based on the result of authentication processing using an authentication key issued by the communicatively connected TSM server 3 (see FIG. 2 ). When the access control unit 33 detects access to the second storage unit 21, it requests input of an authentication key, and starts authentication processing when the authentication key is input. That is, in this embodiment, even if an attempt is made to access the second storage unit 21, input of an authentication key is requested, and therefore access to the second storage unit 21 is not possible. As such, the first area 23 and the second area 25 of the secure element cannot be accessed without an authentication key issued by the TSM server 3. To have an authentication key issued by the TSM server 3, permission must be obtained from the issuer that issues the secure element (who manages the TSM server 3).
[0020] The access control unit 33 of this embodiment can control access to the second storage unit 21 based on the result of authentication processing using the authentication key managed by the management unit 31. That is, the access control unit 33 of this embodiment is configured to be able to execute authentication processing using the authentication key managed by the management unit 31, in addition to authentication processing using the authentication key issued by the TSM server 3. As a result, even if there is no authentication key issued by the TSM server 3, access to the second storage unit 21 is possible as long as there is an authentication key managed by the management unit 31.
[0021] The authentication key managed by the management unit 31 is generated by the management unit 31. The management unit 31 generates the authentication key based on first information that authenticates access to the terminal 1 itself or second information related to the user. The management unit 31 manages the authentication key generated in this manner. Examples of the first information used when generating the authentication key include a password, a PIN code, a secret question, a one-time password, and biometric information (face, fingerprint, vein, etc.). Examples of the second information, like the examples of the first information, include a password, a PIN code, a secret question, a one-time password, and biometric information (face, fingerprint, vein, etc.). Here, an example will be described in which the first information and the second information are biometric information of the user who is the owner of the terminal 1.
[0022] Here, the procedure by which the management unit 31 generates and manages an authentication key will be described. As shown in FIG. 3 , the management unit 31 performs authentication processing using the user's biometric information (step S1). The authentication processing in step S1 may be authentication for enabling operation of the terminal 1 (i.e., login authentication to the terminal 1), or authentication when starting a management application constituting the management unit 31. The authentication processing in step S1 may also be authentication when using the second storage unit 21 as a secure element for the first time. When authentication is performed in step S1 (S2: YES) and the management unit 31 accepts generation of an authentication key (step S3), the management unit 31 generates an authentication key (step S4). At this time, the management unit 31 may generate the authentication key based on a hash value of the user's biometric information, for example. The management unit 31 stores the authentication key generated in step S4, for example, in the second storage unit 21 (first area 23 of the secure element) (step S5).
[0023] Next, other functions of the management unit 31 will be described. As shown in Fig. 5, the management unit 31 causes the display operation unit 13 to display a display screen SC2 that displays information regarding at least one of the free space in the storage area of the second storage unit 21 (second area 25), the types of applications stored in the second storage unit 21, and the storage capacity of the applications stored in the second storage unit 21. Furthermore, the management unit 31 may display not only the current state of the second storage unit 21, but also information such as how many applications are likely to be installed before the capacity of the second area 25 is exceeded or that the CPU is likely to be strained.
[0024] The management unit 31 also accepts installation and uninstallation of applications in the second storage unit 21 from the user of the terminal 1. That is, the management unit 31 accepts installation of applications that utilize the secure mechanism of the secure element. For example, the management unit 31 accesses the management server 5 managed by the operator and downloads an application. After the above-mentioned authentication, the management unit 31 installs the application downloaded from the management server 5 in the second area 25. After the above-mentioned authentication, the management unit 31 also uninstalls the application from the second area 25. From the perspective of the user of the terminal 1, the application is installed in or uninstalled from the second area 25 via the management application.
[0025] Furthermore, when the capacity of the second area 25 is exceeded when a new application is installed, the management unit 31 may acquire CPU usage information for each application and display a display screen SC2 such as that shown in Fig. 5 on the display operation unit 13. This allows the user to delete unnecessary (malicious) applications at their discretion.
[0026] Furthermore, when the storage capacity of the second storage unit 21 exceeds a threshold, the management unit 31 may delete the oldest installed application, the application with the largest storage capacity, or the application that consumes the most CPU utilization rate when in use from the plurality of applications stored in the second storage unit 21. Furthermore, when the storage capacity of the second storage unit 21 exceeds a threshold, the management unit 31 may delete the oldest installed application, the application with the largest storage capacity, or the application that consumes the most CPU utilization rate when in use from the plurality of applications stored in the second storage unit 21, and save the application to the first storage unit 11. Furthermore, the management unit 31 may store the application in cloud storage instead of saving it from the second storage unit 21 to the first storage unit 11. In a management unit 31 configured in this manner, the management unit 31 may reinstall an application saved from the second storage unit 21 to the first storage unit 11 (or cloud storage) to the second storage unit 21 based on an operation from an operator.
[0027] Here, an example of the procedure when the management unit 31 installs an application in the second area 25 serving as an APSD will be described. As shown in Fig. 6, when the management unit 31 (management application) receives a request to install an application (step S11), it executes an authentication process using the user's biometric information (step S12). If the user is authenticated in step S11 (S13: YES), the management unit 31 determines whether the application can be installed (S14). Specifically, the management unit 31 determines whether there is enough free space in the second area 25 serving as an APSD to store the application to be installed.
[0028] If the management unit 31 determines that there is insufficient free space in the second area 25 (S14: NO), it deletes the application from the second area 25 (step S15). Next, the management unit 31 performs authentication processing on the second area 25 using the above-mentioned authentication key managed by the management unit 31. If the authentication processing is successful, it reserves an area in the second area 25 and installs the application in the reserved second area 25 (step S16). Note that if the management unit 31 determines in step S14 that there is sufficient free space in the second area 25 (S14: YES), it omits step S15 and installs the application in the second area 25 using the above-mentioned authentication key managed by the management unit 31 in the same procedure as step S16 (step S16).
[0029] Next, the effects of the terminal 1 according to the embodiment will be described.
[0030] According to the terminal 1 and terminal control method of the above embodiment, conventionally, only businesses that have an authentication key issued by an issuer of a secure element could use the second storage unit 21 as a secure element. In this embodiment, access to the second storage unit 21 as a secure element becomes possible through user authentication by the user of the terminal 1. As a result, businesses of any application can easily use the second storage unit 21 as a secure element (i.e., a logically or physically isolated secure storage area).
[0031] The second memory unit 21 may be a secure element, and the memory area may be a storage area in the secure element. With this configuration, it is possible to easily use the secure memory area of the secure element that is logically or physically isolated.
[0032] The second information may be biometric information of the user. With this configuration, an authentication key with excellent security can be easily generated.
[0033] The access control unit 33 may request input of second information when detecting access to the second storage unit 21, and may start authentication processing when the second information is input. With this configuration, access control to the second storage unit 21 can be executed in a simpler manner.
[0034] The management unit 31 may cause the display operation unit 13 to display information regarding at least one of the free capacity of the storage area in the second storage unit 21, the types of applications stored in the second storage unit 21, and the storage capacity of the applications stored in the second storage unit 21. In this configuration, the status of the second storage unit 21 can be easily checked.
[0035] The management unit 31 may accept installation and uninstallation of applications in the second storage unit 21. This configuration enables installation and uninstallation of applications in the secure second storage unit 21. This enables dynamic installation and uninstallation of applications in the second area 25, which has not been possible in the past, and allows the second area 25 to be used effectively, for example.
[0036] When the storage capacity of the second storage unit 21 exceeds a threshold, the management unit 31 may delete the oldest installed application, the application with the largest storage capacity, or the application that puts the most strain on CPU usage when in use from the multiple applications stored in the second storage unit 21. This configuration can avoid the problem of not being able to install a desired application due to insufficient storage capacity.
[0037] When the storage capacity of the second storage unit 21 exceeds a threshold, the management unit 31 may delete the oldest installed application, the application with the largest storage capacity, or the application that puts the most strain on CPU usage when in use from the multiple applications stored in the second storage unit 21, and save the deleted applications to the first storage unit 11. This configuration can avoid the problem of not being able to install a desired application due to insufficient storage capacity, and can save the deleted applications.
[0038] The management unit 31 may, based on an operation by the operator, reinstall an application that has been saved from the second storage unit 21 to the first storage unit 11 in the second storage unit 21. In this configuration, a deleted application can be restored and used again.
[0039] The terminal of the present disclosure may have the following configuration.
[0040] [1] A terminal comprising: a second storage unit having a secure storage area logically or physically isolated from a first storage unit; a management unit that manages an authentication key generated based on first information that authenticates access to the terminal or second information related to a user; and an access control unit that controls access to the second storage unit based on the result of an authentication process that uses the authentication key managed by the management unit.
[0041] [2] The terminal according to [1], wherein the second storage unit is a secure element, and the storage area is a storage area in the secure element.
[0042] [3] The terminal according to [1] or [2], wherein the second information is biometric information of the user.
[0043] [4] The terminal according to any one of [1] to [3], wherein the access control unit requests input of the second information when it detects access to the second storage unit, and starts the authentication process when the second information is input.
[0044] [5] The terminal according to any one of [1] to [4], wherein the management unit causes a display unit to display information regarding at least one of the free space in the storage area in the second storage unit, the types of applications stored in the second storage unit, and the storage capacity of the applications stored in the second storage unit.
[0045] [6] The terminal according to any one of [1] to [5], wherein the management unit accepts installation and uninstallation of applications to the second storage unit.
[0046] [7] The terminal according to any one of [1] to [6], wherein when the storage capacity of the second storage unit exceeds a threshold, the management unit deletes, from the plurality of applications stored in the second storage unit, the application that was installed the oldest, the application with the largest storage capacity, or the application that puts the most strain on CPU usage when in use.
[0047] [8] The terminal according to any one of [1] to [7], wherein when the storage capacity of the second storage unit exceeds a threshold, the management unit deletes the application that was installed the oldest, the application with the largest storage capacity, or the application that puts the most strain on CPU usage when in use from the plurality of applications stored in the second storage unit, and saves the application to the first storage unit.
[0048] [9] The terminal according to [8], wherein the management unit reinstalls the application that was saved from the second storage unit to the first storage unit into the second storage unit based on an operation from an operator.
[0049]
[10] A method for accessing a second storage unit in a terminal equipped with the second storage unit having a storage area logically or physically isolated from a first storage unit, the method comprising: a management step in which the computer manages an authentication key generated based on first information for authenticating access to the terminal or second information related to a user; and an access control step in which the computer controls access to the second storage unit based on a result of an authentication process using the authentication key managed by the management step.
[0050]
[11] A program for accessing a second storage unit in a terminal equipped with a second storage unit having a storage area logically or physically isolated from a first storage unit, the program causing a computer to execute: a management step of managing an authentication key generated based on first information for authenticating access to the terminal or second information related to a user; and an access control step of controlling access to the second storage unit based on a result of authentication processing using the authentication key managed by the management step.
[0051] Although one embodiment has been described above, one aspect of the present disclosure is not limited to the above embodiment, and various modifications are possible without departing from the spirit of the present disclosure.
[0052] In the above embodiment, a secure element was used as an example of the secure second memory unit 21, but the technology disclosed herein can also be applied to storage that has a memory area that is logically or physically isolated from the outside, such as a TEE (Trusted Execution Environment).
[0053] The block diagrams used to explain the above embodiments show functional blocks. These functional blocks (components) are realized by any combination of at least one of hardware and software. Furthermore, the method for realizing each functional block is not particularly limited. That is, each functional block may be realized using a single device that is physically or logically coupled, or may be realized using two or more physically or logically separated devices that are directly or indirectly connected (for example, using wires, wirelessly, etc.) and these multiple devices. The functional block may also be realized by combining software with the single device or the multiple devices.
[0054] Functions include, but are not limited to, judgment, determination, judgment, calculation, computation, processing, derivation, investigation, search, confirmation, reception, transmission, output, access, resolution, selection, election, establishment, comparison, assumption, expectation, regard, broadcasting, notifying, communicating, forwarding, configuring, reconfiguring, allocating, mapping, and assignment. For example, a functional block (component) that performs transmission is called a transmitting unit or transmitter. As mentioned above, there are no particular limitations on how these functions are implemented.
[0055] For example, the terminal 1 according to an embodiment of the present disclosure may function as a computer that performs processing of the terminal control method of the present disclosure. Fig. 7 is a diagram illustrating an example of the hardware configuration of the terminal 1 according to an embodiment of the present disclosure. The terminal 1 described above may be physically configured as a computer device including a processor 1001, a memory 1002, a storage 1003, a communication device 1004, an input device 1005, an output device 1006, a bus 1007, etc.
[0056] In the following description, the term "device" can be interpreted as a circuit, a device, a unit, etc. The hardware configuration of the terminal 1 may be configured to include one or more of the devices shown in the figure, or may be configured to exclude some of the devices.
[0057] Each function in terminal 1 is realized by loading specified software (programs) onto hardware such as processor 1001, memory 1002, etc., so that processor 1001 performs calculations, controls communication via communication device 1004, and controls at least one of reading and writing data in memory 1002 and storage 1003.
[0058] The processor 1001 controls the entire computer by running, for example, an operating system. The processor 1001 may be configured by a central processing unit (CPU) including an interface with peripheral devices, a control unit, an arithmetic unit, a register, etc. For example, the above-mentioned management unit 31 and access control unit 33 may be realized by including the processor 1001.
[0059] The processor 1001 also reads programs (program codes), software modules, data, etc. from at least one of the storage 1003 and the communication device 1004 into the memory 1002 and executes various processes in accordance with these. The programs used are those that cause a computer to execute at least some of the operations described in the above-described embodiments. For example, the management unit 31 and the access control unit 33 may be implemented by a control program stored in the memory 1002 and running on the processor 1001, and similar implementations may be made for other functional blocks. While the above-described various processes have been described as being executed by one processor 1001, they may also be executed simultaneously or sequentially by two or more processors 1001. The processor 1001 may be implemented by one or more chips. The programs may also be transmitted from a network via a telecommunications line.
[0060] The program executed by the processor 1001 may be a program for accessing the second memory unit 21 in a terminal 1 equipped with a second memory unit 21 having a memory area logically or physically isolated from the first memory unit 11, and may include a management step for managing an authentication key generated based on first information for authenticating access to the terminal 1 or second information about the user, and an access control step for controlling access to the second memory unit 21 based on the result of authentication processing using the authentication key managed by the management step.
[0061] The memory 1002 is a computer-readable recording medium and may be configured, for example, by at least one of a ROM (Read Only Memory), an EPROM (Erasable Programmable ROM), an EEPROM (Electrically Erasable Programmable ROM), a RAM (Random Access Memory), etc. The memory 1002 may also be called a register, a cache, a main memory (primary storage device), etc. The memory 1002 can store executable programs (program codes), software modules, etc. for implementing a terminal selection method according to an embodiment of the present disclosure.
[0062] Storage 1003 is a computer-readable recording medium, and may be composed of at least one of an optical disk such as a CD-ROM (Compact Disc ROM), a hard disk drive, a flexible disk, a magneto-optical disk (e.g., a compact disk, a digital versatile disk, a Blu-ray (registered trademark) disk), a smart card, a flash memory (e.g., a card, a stick, a key drive), a floppy (registered trademark) disk, a magnetic strip, etc. Storage 1003 may also be referred to as an auxiliary storage device. The above-mentioned storage medium may be, for example, a database, a server, or other appropriate medium including at least one of memory 1002 and storage 1003. For example, the above-mentioned first storage unit 11 and second storage unit 21 may be realized by including storage 1003.
[0063] The communication device 1004 is hardware (transmission / reception device) for communicating between computers via at least one of a wired network and a wireless network, and is also referred to as, for example, a network device, a network controller, a network card, a communication module, etc. The communication device 1004 may be configured to include a high-frequency switch, a duplexer, a filter, a frequency synthesizer, etc. to realize at least one of frequency division duplex (FDD) and time division duplex (TDD). For example, the above-mentioned first memory unit 11, display operation unit 13, second memory unit 21, management unit 31, access control unit 33, etc. may be realized by including the communication device 1004.
[0064] The input device 1005 is an input device (e.g., a keyboard, a mouse, a microphone, a switch, a button, a sensor, etc.) that receives input from the outside. The output device 1006 is an output device (e.g., a display, a speaker, an LED lamp, etc.) that outputs to the outside. Note that the input device 1005 and the output device 1006 may be integrated into one device (e.g., a touch panel).
[0065] Furthermore, each device, such as the processor 1001 and the memory 1002, is connected by a bus 1007 for communicating information. The bus 1007 may be configured using a single bus, or may be configured using different buses between each device.
[0066] The terminal 1 may also be configured to include hardware such as a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a programmable logic device (PLD), or a field programmable gate array (FPGA), and some or all of the functional blocks may be realized by the hardware. For example, the processor 1001 may be implemented using at least one of these pieces of hardware.
[0067] The notification of information is not limited to the aspects / embodiments described in the present disclosure and may be performed using other methods. For example, the notification of information may be performed by physical layer signaling (e.g., Downlink Control Information (DCI) and Uplink Control Information (UCI)), higher layer signaling (e.g., Radio Resource Control (RRC) signaling, Medium Access Control (MAC) signaling, broadcast information (Master Information Block (MIB) and System Information Block (SIB))), other signals, or a combination thereof. Furthermore, the RRC signaling may be referred to as an RRC message, and may be, for example, an RRC Connection Setup message, an RRC Connection Reconfiguration message, or the like.
[0068] Each aspect / embodiment described in the present disclosure may be applied to at least one of systems using LTE (Long Term Evolution), LTE-Advanced (LTE-A), SUPER 3G, IMT-Advanced, 4G (4th generation mobile communication system), 5G (5th generation mobile communication system), FRA (Future Radio Access), NR (New Radio), W-CDMA (registered trademark), GSM (registered trademark), CDMA2000, UMB (Ultra Mobile Broadband), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, UWB (Ultra-Wide Band), Bluetooth (registered trademark), or other suitable systems, and next-generation systems enhanced based on these. Furthermore, a combination of multiple systems (e.g., a combination of at least one of LTE and LTE-A with 5G, etc.) may also be applied.
[0069] The order of the procedures, sequences, flowcharts, etc. of each aspect / embodiment described in this disclosure may be changed unless it is consistent. For example, the methods described in this disclosure present elements of various steps using an example order, and are not limited to the particular order presented.
[0070] Input and output information may be stored in a specific location (for example, memory) or may be managed using a management table. Input and output information may be overwritten, updated, or added to. Output information may be deleted. Input information may be sent to another device.
[0071] The determination may be made based on a value represented by one bit (0 or 1), a Boolean value (true or false), or a numerical comparison (e.g., comparison with a predetermined value).
[0072] The aspects / embodiments described in this disclosure may be used alone, in combination, or switched depending on the implementation. Notification of predetermined information (e.g., notification that "X is true") is not limited to explicit notification, but may be implicit (e.g., not notifying the predetermined information).
[0073] Although the present disclosure has been described in detail above, it is clear to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented in modified and altered forms without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description of the present disclosure is intended to be illustrative and does not have any limiting meaning on the present disclosure.
[0074] Software shall be construed broadly to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc., whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise.
[0075] Software, instructions, information, etc. may also be transmitted or received over a transmission medium. For example, if software is transmitted from a website, server, or other remote source using wired technologies (such as coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL)), and / or wireless technologies (such as infrared, microwave), then these wired and / or wireless technologies are included within the definition of transmission media.
[0076] The information, signals, etc. described in this disclosure may be represented using any of a variety of different technologies. For example, data, instructions, commands, information, signals, bits, symbols, chips, etc. that may be referred to throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or magnetic particles, optical fields or photons, or any combination thereof.
[0077] In addition, terms explained in this disclosure and terms necessary for understanding this disclosure may be replaced with terms having the same or similar meanings.
[0078] As used in this disclosure, the terms "system" and "network" are used interchangeably.
[0079] Similarly, the user terminal in the present disclosure may be read as a base station, in which case the base station may be configured to have the functions of the terminal 1 described above.
[0080] As used in this disclosure, the terms "determining" and "determining" may encompass a wide variety of actions. "Determining" and "determining" may include, for example, judging, calculating, computing, processing, deriving, investigating, looking up, searching, inquiring (e.g., searching a table, database, or other data structure), ascertaining, and the like. "Determining" and "determining" may also include receiving (e.g., receiving information), transmitting (e.g., sending information), input, output, accessing (e.g., accessing data in memory), and the like, all of which are considered to be "determining." "Determining" and "determining" may also include resolving, selecting, choosing, establishing, comparing, and the like, all of which are considered to be "determining." In other words, "judgment" and "decision" can include regarding some action as having been "judged" or "decided." Also, "judgment (decision)" can be interpreted as "assuming," "expecting," "considering," etc.
[0081] The terms "connected," "coupled," or any variation thereof, refer to any direct or indirect connection or coupling between two or more elements, and may include the presence of one or more intermediate elements between two elements that are "connected" or "coupled" to each other. The coupling or connection between elements may be physical, logical, or a combination thereof. For example, "connected" may be read as "access." As used in this disclosure, two elements may be considered to be "connected" or "coupled" to each other using one or more wires, cables, and / or printed electrical connections, as well as electromagnetic energy having wavelengths in the radio frequency range, microwave range, and optical (both visible and invisible) range, as some non-limiting and non-exhaustive examples.
[0082] As used in this disclosure, the phrase "based on" does not mean "based only on," unless expressly stated otherwise. In other words, the phrase "based on" means both "based only on" and "based at least on."
[0083] As used in this disclosure, any reference to an element using a designation such as "first," "second," etc. does not generally limit the quantity or order of those elements. These designations may be used in this disclosure as a convenient method of distinguishing between two or more elements. Thus, a reference to a first and a second element does not imply that only two elements may be employed or that the first element must in some way precede the second element.
[0084] When the terms "include," "including," and variations thereof are used in this disclosure, these terms are intended to be inclusive, similar to the term "comprising." Furthermore, when the term "or" is used in this disclosure, it is not intended to be an exclusive or.
[0085] In this disclosure, where articles are added by translation, such as a, an, and the in English, the disclosure may include that the nouns following these articles are in the plural form.
[0086] In the present disclosure, the term "A and B are different" may mean "A and B are different from each other." The term may also mean "A and B are each different from C." Terms such as "separate" and "coupled" may also be interpreted in the same way as "different."
[0087] 1...terminal, 3...TSM server, 5...management server, 11...first memory unit, 13...display operation unit, 21...second memory unit, 23...first area, 25...second area, 31...management unit, 33...access control unit, 1001...processor, 1002...memory, 1003...storage, 1004...communication device, 1005...input device, 1006...output device, 1007...bus.
Claims
1. A terminal comprising: a second memory unit having a secure memory area logically or physically isolated from a first memory unit; a management unit that manages an authentication key generated based on first information that authenticates access to the terminal or second information related to the user; and an access control unit that controls access to the second memory unit based on the result of an authentication process using the authentication key managed by the management unit.
2. The terminal according to claim 1, wherein the second memory unit is a secure element, and the memory area is a storage area in the secure element.
3. The terminal according to claim 1, wherein the second information is biometric information of the user.
4. The terminal according to claim 1, wherein the access control unit requests input of the second information when it detects an access to the second storage unit, and starts the authentication process when the second information is input.
5. The terminal of claim 1, wherein the management unit causes a display unit to display information regarding at least one of the free space in the storage area of the second storage unit, the type of application stored in the second storage unit, and the storage capacity of the application stored in the second storage unit.
6. The terminal according to claim 1, wherein the management unit accepts installation and uninstallation of applications to and from the second storage unit.
7. The terminal according to claim 1, wherein the management unit deletes, from the plurality of applications stored in the second storage unit, the application that was installed the oldest, the application with the largest storage capacity, or the application that places the greatest strain on CPU usage when in use, when the storage capacity of the second storage unit exceeds a threshold value.
8. The terminal according to claim 1, wherein when the storage capacity of the second storage unit exceeds a threshold, the management unit deletes from the plurality of applications stored in the second storage unit the application that was installed the oldest, the application with the largest storage capacity, or the application that puts the greatest strain on CPU usage when in use, and saves the application in the first storage unit.
9. The terminal according to claim 8, wherein the management unit reinstalls the application, which has been saved from the second storage unit to the first storage unit, into the second storage unit based on an operation by an operator.
10. A method for accessing a second storage unit in a terminal having a storage area logically or physically isolated from a first storage unit, the method comprising: a management step in which the terminal manages an authentication key generated based on first information for authenticating access to the terminal or second information related to the user; and an access control step in which the terminal controls access to the second storage unit based on the result of authentication processing using the authentication key managed by the management step.
Citation Information
Patent Citations
Capacity management system and capacity managing method
JP1998260873A
Computer system capable of moving overflow data to network storage
JP2001184239A
Data management system, data management apparatus and data management program
JP2017215763A
Storage device capable of fingerprint identification
US20160259927A1
Memory controller, storage device including the same, and operating method of the memory controller
US20210157747A1