System, server device, installation method, secure method, and program
The system addresses unauthorized data installation in currency processing devices by employing cloud-based secure processing and authentication, ensuring data integrity and robust key management, thereby enhancing security.
Patent Information
- Application Number
- PCT/JP2024/019592
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-28
- Publication Date
- 2025-12-04
AI Technical Summary
Existing currency processing devices face challenges in preventing the unauthorized use and leakage of authorization codes, leading to potential installation of unauthorized data, compromising security.
A system with cloud-based secure processing and authentication functions that manage keys and authorization separately, using encryption and electronic signatures to ensure data integrity and authenticity, and authenticate maintenance personnel and administrators.
Enhances security by preventing unauthorized data installation and key theft, ensuring data confidentiality and integrity, and robustly managing keys and information, thus improving the security of currency processing devices.
Smart Images

Figure JP2024019592_04122025_PF_FP_ABST
Abstract
Description
System, server device, installation method, secure method, and program
[0001] The present disclosure relates to a system, a server device, an installation method, a secure method, and a program.
[0002] 2. Description of the Related Art Conventionally, there have been known currency processing devices that accept currency, identify the accepted currency, and process the currency. For example, Patent Literature 1 discloses a technology for preventing fraudulent use of an update program for updating an identification program that identifies currency in the currency processing device described above.
[0003] In the technology disclosed in Patent Document 1, the manufacturer encrypts the update program with an authorization code and stores it on an SD card. The manufacturer also encrypts the authorization code with the device code of the currency identification device to generate a PIN code, and distributes the PIN code along with the SD card. Furthermore, in the technology disclosed in Patent Document 1, when the distributed SD card is inserted into a target currency identification device and the distributed PIN code is entered, the authorization code is decrypted using the device code of the currency identification device, and the update program is decrypted from the SD card using the authorization code. Therefore, the technology disclosed in Patent Document 1 can prevent the unauthorized use of the update program on other currency identification devices.
[0004] JP 2011-14080 A
[0005] Generally, it is difficult to completely prevent the leakage of authorization codes, device codes, etc., and this may lead to the installation of unauthorized data or the unauthorized use of installation data.
[0006] The present disclosure aims to provide a system, a server device, an update method, a secure method, and a program that can increase security in the process of installing data in a currency processing device.
[0007] A system according to one aspect of the present disclosure is a system including a currency processing device that processes currency, wherein the currency processing device includes: a receiving unit that receives second data obtained by securely processing first data from a server device that provides a secure processing service on a first cloud; a decryption unit that decrypts the second data into the first data; and an installation unit that installs the decrypted first data in the currency processing device. The first data may be data to be installed in the currency processing device. The receiving unit may receive the second data via a maintenance terminal. The maintenance terminal may transmit the first data to the server device.
[0008] In a system according to one aspect of the present disclosure, the currency processing device further includes a currency identification unit that performs an identification process of the type of currency, including at least one of the denomination, authenticity, and fitness of the currency, and the first data may be data used in the identification process.
[0009] In a system according to one aspect of the present disclosure, the first data may include a threshold value that is compared with a detection value detected from the currency in the identification process.
[0010] In the system according to one aspect of the present disclosure, the secure processing may include an encryption process using a first key, the currency processing device may further include a storage unit that stores a second key, and the decryption unit may decrypt the second data into the first data using the second key. The first key and the second key may be a common key.
[0011] In a system according to one aspect of the present disclosure, the secure processing may include an electronic signature process for generating an electronic signature for the first data using a third key, the second data may include the electronic signature, the currency processing device may use the electronic signature to determine whether the integrity of the first data is guaranteed, and the installation unit may install the first data into the currency processing device if the integrity of the first data is guaranteed. The currency processing device may further include a storage unit that stores a fourth key that pairs with the third key. The decryption unit may decrypt the first data and the electronic signature from the second data, and determine whether the integrity of the decrypted first data is guaranteed using the decrypted first data, the decrypted electronic signature, and the fourth key.
[0012] In a system according to one aspect of the present disclosure, the memory unit may be at least one of a memory in a safe provided in the currency processing device and a TPM (Trusted Platform Module).
[0013] In a system according to an aspect of the present disclosure, the system may further include a server device, wherein the server device includes a data receiving unit that receives the first data, a secure processing unit that performs the secure processing on the first data to generate the second data, and a first transmitting unit that transmits the second data to an external device. The data receiving unit may receive the first data from the maintenance terminal used for maintenance of the currency processing device. The first transmitting unit may transmit the second data to the maintenance terminal.
[0014] In a system according to one aspect of the present disclosure, the server device may further include an authentication information receiving unit that receives maintenance staff authentication information for authenticating a maintenance staff member performing maintenance on the currency processing device, and an authentication control unit that controls authentication of the maintenance staff using the maintenance staff authentication information and a first authentication service, and the secure processing unit may generate the second data if authentication of the maintenance staff is successful. The maintenance staff may be a person who performs maintenance on the currency processing device using a maintenance terminal. The authentication information receiving unit may receive the maintenance staff authentication information from the maintenance terminal. The first authentication service may be provided on a second cloud different from the first cloud.
[0015] In a system according to one aspect of the present disclosure, the server device may further include a key storage unit that stores a key, the secure processing unit may perform the secure processing on the first data using the key, and the first authentication service may be an authentication service that uses a maintenance personnel database managed within the second cloud.
[0016] In a system according to one aspect of the present disclosure, the key may include a first key that is common to a second key managed by the currency processing device, and the secure processing may include an encryption process that performs encryption using the first key.
[0017] In a system according to one aspect of the present disclosure, the key may include a third key that pairs with a fourth key managed by the currency processing device, the secure processing may include an electronic signature processing that generates an electronic signature of the first data using the third key, and the second data may include the electronic signature.
[0018] In a system according to one aspect of the present disclosure, the authentication information receiving unit may further receive administrator authentication information for authenticating an administrator who manages the keys, and the authentication control unit may control authentication of the administrator using the administrator authentication information and a second authentication service. The administrator may be a person who manages the keys using a management terminal. The authentication information receiving unit may receive the administrator authentication information from the management terminal. The second authentication service may be an authentication service using an administrator database managed in the second cloud.
[0019] In a system according to an aspect of the present disclosure, it may be possible to determine whether the first authentication service or the second authentication service is to be used for authentication based on either the maintenance staff authentication information or the administrator authentication information. The maintenance staff authentication information and the administrator authentication information may include first authentication information. The first authentication information included in the maintenance staff authentication information is information that identifies the maintenance staff. The first authentication information included in the administrator authentication information is information that identifies the administrator.
[0020] In a system according to one aspect of the present disclosure, when the authentication control unit determines to use the second authentication service for authentication, the authentication control unit may use the first authentication information and the second authentication service included in the administrator authentication information to control authentication of whether the administrator has key management authority.
[0021] In a system according to one aspect of the present disclosure, the maintenance personnel authentication information is information that identifies the maintenance personnel and further includes second authentication information that is different from the first authentication information, and when the authentication control unit decides to use the first authentication service for authentication, it may use the second authentication information and the first authentication service to control authentication of whether the maintenance personnel has maintenance authority over the currency processing device.
[0022] In a system according to one aspect of the present disclosure, the maintenance personnel authentication information may further include third authentication information that identifies the maintenance personnel and is different from the first authentication information and the second authentication information, and the authentication control unit may further control authentication of the legitimacy of the maintenance personnel using the third authentication information.
[0023] The system according to one aspect of the present disclosure may further include the maintenance terminal, wherein the maintenance terminal includes an authentication unit that authenticates the legitimacy of the maintenance personnel and a second transmission unit that transmits the maintenance personnel authentication information to the server device if the authentication is successful. The authentication unit may authenticate the legitimacy of the maintenance personnel using a hardware key carried by the maintenance personnel. The maintenance terminal may include a data generation unit that generates the first data. The data generation unit may generate the first data based on data indicating a flow test result received from the currency processing device connected to the maintenance terminal. The flow test result may be, for example, a result of identifying a test banknote by the currency identification unit.
[0024] In the system according to an aspect of the present disclosure, the second authentication information may be information for identifying a hardware key possessed by the maintenance personnel, and the third authentication information may be a one-time password based on the hardware key possessed by the maintenance personnel.
[0025] In a system according to one aspect of the present disclosure, the authentication control unit may issue a JWT (JSON Web Token) when the maintenance person is authenticated, and the first transmission unit may transmit the JWT to an external device. The data receiving unit may receive the first data and the JWT from an external device, and the secure processing unit may authenticate the JWT and determine whether or not the secure processing can be performed on the first data. The authentication control unit may issue a JWT when at least one of the maintenance person's legitimacy and the maintenance authority is authenticated. The authentication control unit may issue a JWT when both the maintenance person's legitimacy and the maintenance authority are authenticated. The first transmission unit may transmit the JWT to the maintenance terminal. The data receiving unit may receive the first data and the JWT from the maintenance terminal.
[0026] A server device according to one aspect of the present disclosure provides a secure processing service on a first cloud, and includes: a data receiving unit that receives first data from an external device to be installed in the currency processing device; a secure processing unit that performs secure processing on the first data to generate second data; and a transmitting unit that transmits the second data to an external device. The data receiving unit may receive the first data from a maintenance terminal used for maintaining the currency processing device. The transmitting unit may transmit the second data to the maintenance terminal.
[0027] A server device according to one aspect of the present disclosure may further include an authentication information receiving unit that receives maintenance staff authentication information for authenticating a maintenance staff member performing maintenance on the currency processing device, and an authentication control unit that controls authentication of the maintenance staff using the maintenance staff authentication information and a first authentication service, wherein the secure processing unit may generate the second data if authentication of the maintenance staff is successful. The maintenance staff may be a person who performs maintenance on the currency processing device using a maintenance terminal. The authentication information receiving unit may receive the maintenance staff authentication information from the maintenance terminal. The first authentication service may be provided on a second cloud different from the first cloud.
[0028] In one aspect of the present disclosure, a server device may further include a key storage unit that stores a key, wherein the secure processing unit performs the secure processing on the first data using the key, and the first authentication service may be an authentication service using a maintenance personnel database managed within the second cloud.
[0029] In a server device according to one embodiment of the present disclosure, the key may include a first key that is common to a second key managed by the currency processing device, and the secure processing may include an encryption process that performs encryption using the first key.
[0030] In a server device according to one embodiment of the present disclosure, the key may include a third key that pairs with a fourth key managed by the currency processing device, the secure processing may include an electronic signature processing that generates an electronic signature of the first data using the third key, and the second data may include the electronic signature.
[0031] In the server device according to one aspect of the present disclosure, the authentication information receiving unit may further receive administrator authentication information for authenticating an administrator who manages the keys, and the authentication control unit may control authentication of the administrator using the administrator authentication information and a second authentication service. The administrator may be a person who manages the keys using a management terminal. The authentication information receiving unit may receive the administrator authentication information from the management terminal. The second authentication service may be an authentication service using an administrator database managed in the second cloud.
[0032] In a server device according to an aspect of the present disclosure, it may be possible to determine whether the first authentication service or the second authentication service is to be used for authentication based on either the maintenance staff authentication information or the administrator authentication information. The maintenance staff authentication information and the administrator authentication information may include first authentication information. The first authentication information included in the maintenance staff authentication information is information that identifies the maintenance staff. The first authentication information included in the administrator authentication information is information that identifies the administrator.
[0033] In a server device according to one aspect of the present disclosure, when the authentication control unit determines to use the second authentication service for authentication, the authentication control unit may use the first authentication information and the second authentication service included in the administrator authentication information to control authentication of whether the administrator has key management authority.
[0034] In a server device according to one aspect of the present disclosure, the maintenance personnel authentication information is information that identifies the maintenance personnel and further includes second authentication information that is different from the first authentication information, and when the authentication control unit decides to use the first authentication service for authentication, it may use the second authentication information and the first authentication service to control authentication of whether the maintenance personnel has maintenance authority over the currency processing device.
[0035] In a server device according to one aspect of the present disclosure, the maintenance personnel authentication information may further include third authentication information that identifies the maintenance personnel and is different from the first authentication information and the second authentication information, and the authentication control unit may further control authentication of the legitimacy of the maintenance personnel using the third authentication information.
[0036] In the server device according to an aspect of the present disclosure, the second authentication information may be information for identifying a hardware key possessed by the maintenance staff, and the third authentication information may be a one-time password based on the hardware key possessed by the maintenance staff.
[0037] In a server device according to an aspect of the present disclosure, the authentication control unit may issue a JWT (JSON Web Token) when the maintenance personnel is authenticated, and the first transmission unit may transmit the JWT to an external device. The data receiving unit may receive the first data and the JWT from an external device, and the secure processing unit may determine whether or not to execute the secure processing on the first data based on the JWT. The authentication control unit may issue a JWT when at least one of the maintenance personnel's legitimacy and the maintenance authority is authenticated. The authentication control unit may issue a JWT when both the maintenance personnel's legitimacy and the maintenance authority are authenticated. The first transmission unit may transmit the JWT to the maintenance terminal. The data receiving unit may receive the first data and the JWT from the maintenance terminal.
[0038] An installation method according to one aspect of the present disclosure is an installation method executed in a currency processing device that processes currency, and includes a receiving step in which a server device that provides a secure processing service on a first cloud receives second data obtained by performing secure processing on first data, a decrypting step in which the second data is decrypted into the first data, and an installing step in which the decrypted first data is installed in the currency processing device. The first data may be data to be installed in the currency processing device. The receiving step may receive the second data via a maintenance terminal. The maintenance terminal may transmit the first data to the server device.
[0039] A secure method according to one aspect of the present disclosure is a secure method executed by a server device that provides a secure processing service on a first cloud, and includes: a data receiving step of receiving first data to be installed in the currency processing device; a secure processing step of performing secure processing on the first data to generate second data; and a transmission step of transmitting the second data to the maintenance terminal. The data receiving step may receive the first data from a maintenance terminal used for maintaining the currency processing device. The transmission step may transmit the second data to the maintenance terminal.
[0040] A program according to one aspect of the present disclosure is a program executed in a currency processing device that processes currency, and causes a computer of the currency processing device to execute the following steps: a receiving step in which a server device that provides a secure processing service on a first cloud receives second data obtained by performing secure processing on first data; a decrypting step in which the second data is decrypted into the first data; and an installing step in which the decrypted first data is installed in the currency processing device. The first data may be data to be installed in the currency processing device. The receiving step may receive the second data via a maintenance terminal. The maintenance terminal may transmit the first data to the server device.
[0041] A program according to one aspect of the present disclosure is a program executed on a server device that provides a secure processing service on a first cloud, and causes a computer of the server device to execute the following steps: a data receiving step of receiving first data to be installed in the currency processing device from an external device; a secure processing step of performing secure processing on the first data to generate second data; and a transmission step of transmitting the second data to an external device. The data receiving step may receive the first data from a maintenance terminal used for maintaining the currency processing device. The transmission step may transmit the second data to the maintenance terminal.
[0042] FIG. 1 is a block diagram showing an example of the configuration of a system according to this embodiment. FIG. 2 is a block diagram showing an example of the hardware configuration of a maintenance terminal according to this embodiment. FIG. 3 is a block diagram showing an example of the hardware configuration of a server device according to this embodiment. FIG. 4 is a schematic diagram showing an example of the mechanical configuration of a currency processing device according to this embodiment. FIG. 5 is a block diagram showing an example of the hardware configuration of a main board according to this embodiment. FIG. 6 is a block diagram showing an example of the functional configuration of a maintenance terminal, a server device, and a currency processing device according to this embodiment. FIG. 7 is a sequence diagram showing an example of a maintenance staff authentication process performed in the system according to this embodiment. FIG. 8 is a flowchart showing an example of an authority authentication process for a maintenance staff and a first manager performed in the system according to this embodiment. FIG. 9 is a diagram showing an example of information stored in an authentication destination DB according to this embodiment. FIG. 10 is a diagram showing an example of information stored in a maintenance staff DB according to this embodiment. FIG. 11 is a diagram showing an example of information stored in an manager DB according to this embodiment. FIG. 12 is a sequence diagram showing an example of an installation process performed in the system according to this embodiment. FIG. 13 is a diagram showing an example of installation data generated by a data generation unit according to this embodiment. FIG. 14 is a diagram showing an example of information stored in a key storage unit according to this embodiment.
[0043] Hereinafter, an embodiment of the present disclosure (hereinafter simply referred to as "the present embodiment") will be described in detail with reference to the drawings. Note that the present disclosure is not limited to the following embodiment. Furthermore, the following embodiment and modified examples can be combined as appropriate.
[0044] The system of this embodiment is a system that enhances security in the process for installing data in a currency processing device.
[0045] Specifically, in the system of this embodiment, a secure processing function that performs secure processing on data installed in the currency processing device is cloud-based. This allows the system of this embodiment to manage keys used for secure processing on the cloud, thereby improving the security (e.g., confidentiality and integrity) of the installed data itself and preventing key theft and loss of keys by maintenance personnel who generate the installed data. In the following embodiment, the secure processing will be described using an example in which encryption processing and electronic signature processing are used. However, the secure processing is not limited to these, and may be either encryption processing or electronic signature processing.
[0046] In addition, in the system of this embodiment, the authorization authentication function for authenticating maintenance authority for the currency processing device, such as installing data in the currency processing device, is also cloud-based and realized as a cloud service separate from the secure processing function. As a result, in the system of this embodiment, the keys used for secure processing and the information used for authorization authentication can be managed in separate cloud environments, preventing unauthorized installation in the currency processing device by unauthorized persons and increasing the robustness of the system against leaks of the keys and information.
[0047] The configuration and operation of the system of this embodiment will be specifically described below.
[0048] 1 is a block diagram showing an example of the configuration of a system 1 according to this embodiment. As shown in FIG. 1, the system 1 includes a maintenance terminal 10, a hardware key 20, a first management terminal 30, a first cloud 40, a second cloud 60, a second management terminal 70, and a currency processing device 80.
[0049] The maintenance terminal 10 is a terminal device used by a maintenance technician when maintaining the currency processing device 80, and may be, for example, a personal computer (PC) on which a maintenance program is installed. The maintenance terminal 10 may be connected to the currency processing device 80 via a network such as a local area network (LAN), or may be directly connected to the currency processing device 80 via a communication cable or the like. The maintenance terminal 10 is also connected to the first cloud 40 via a public network such as the Internet.
[0050] Once a maintenance program is installed on the maintenance terminal 10, maintenance software based on the maintenance program can be executed. The maintenance software is used to generate and read data to be installed in the currency processing device 80. The maintenance software is also used to request the first cloud 40 to authenticate whether or not the maintenance personnel has the authority to maintain the currency processing device, such as installing data in the currency processing device 80. The maintenance software is also used to request the first cloud 40 to perform secure processing on the data to be installed in the currency processing device 80. The maintenance software is also used to transmit the securely processed installation data to the currency processing device 80.
[0051] The hardware key 20 is a hardware device used to control the use of maintenance software. In this embodiment, a hardware key 20 is distributed to each maintenance technician. When the maintenance technician connects his or her hardware key 20 to the maintenance terminal 10 and is successfully authenticated, the maintenance software becomes available. In this embodiment, the hardware key 20 is described as a dongle in the form of a Universal Serial Bus (USB) memory, but the hardware key 20 is not limited to the USB memory format or the dongle. The hardware key 20 may be, for example, a smart card (IC card), a hardware security module (HSM), or a security token.
[0052] The first management terminal 30 is a terminal device, such as a PC, used by the first administrator to manage keys used in the secure processing service provided as a cloud service by the first cloud 40. The first management terminal 30 is connected to the first cloud 40 via a public network such as the Internet. The first management terminal 30 is used to request authentication from the first cloud 40 as to whether the first administrator has the authority to manage keys. The first management terminal 30 also accesses the first cloud 40 and is used by the first administrator to register, modify, delete, and so on various keys managed by the first cloud 40.
[0053] The first cloud 40 is a cloud service that provides a secure processing service. The first cloud 40 includes a firewall 41, an authentication destination DB (DataBase) 43, and a server device 50. The server device 50 is connected to the firewall 41 and the authentication destination DB 43 via a network such as a LAN. The first cloud 40 (server device 50) is also connected to the second cloud 60 via a public network such as the Internet.
[0054] The firewall 41 is for preventing unauthorized access to the first cloud 40, and may be, for example, a network device such as a router or a dedicated device for a standalone firewall. The firewall 41 filters access from external environments including, for example, the maintenance terminal 10 and the first management terminal 30.
[0055] The authentication destination DB 43 is a database used to determine which of a plurality of authentication services provided as cloud services by the second cloud 60 should be used to process an authentication request made to the first cloud 40 .
[0056] The server device 50 is for providing a secure processing service on the first cloud 40, and may be a server computer or the like. The server device 50 may be realized by a single computer or by multiple computers.
[0057] The server device 50 controls authentication requests to the first cloud 40 from the maintenance terminal 10 and the first management terminal 30. For example, the server device 50 authenticates the legitimacy of the maintenance personnel by itself. For example, when authenticating the authority of the first administrator to manage keys or the authority of the maintenance personnel to perform maintenance, the server device 50 refers to the authentication destination DB 43 and determines an authentication service to process the authentication from among multiple authentication services provided by the second cloud 60. Once the server device 50 determines the authentication service to process the authentication, it performs the authentication process using the authentication service.
[0058] The server device 50 also stores a key for performing secure processing on the installation data transmitted from the maintenance terminal 10. In this embodiment, for example, the installation data is subjected to encryption processing and digital signature processing as the secure processing, so the server device 50 stores a key for the encryption processing and a key for the digital signature processing. Note that the secure processing may be processing other than encryption processing and digital signature processing, or may be either encryption processing or digital signature processing, so the server device 50 only needs to store a key according to the secure processing.
[0059] Furthermore, although any cryptographic method may be used for the encryption process and the digital signature process, the present embodiment will be described taking as an example a case where a common key cryptographic method is used for the encryption process and a public key cryptographic method is used for the digital signature process. Therefore, in the present embodiment, the server device 50 stores a common key as the key for the encryption process and a private key as the key for the digital signature process, but the keys stored in the server device 50 are not limited to these.
[0060] When the server device 50 receives the installation data from the maintenance terminal 10, it performs secure processing using the stored key. Specifically, the server device 50 encrypts the installation data using the stored common key. The server device 50 also calculates a hash value from the installation data using a hash function, encrypts the hash value using the stored private key, and generates a digital signature for the installation data.
[0061] The server device 50 transmits the installation data that has been subjected to the secure processing to the maintenance terminal 10. Specifically, the server device 50 attaches the generated digital signature to the installation data that has been subjected to the encryption processing, and transmits the data to the maintenance terminal 10.
[0062] The second cloud 60 is a cloud service that provides multiple authentication services. The second cloud 60 includes a firewall 61, a maintenance staff DB 63, an administrator DB 65, and an administrator authentication device 67. The firewall 61 and the maintenance staff DB 63 are connected via a network such as a LAN, and the administrator DB 65 and the administrator authentication device 67 are connected via a network such as a LAN.
[0063] The firewall 61 is for preventing unauthorized access to the maintenance staff DB 63, and may be, for example, a network device such as a router, or a dedicated device that is a standalone firewall. The firewall 61 filters access from external environments including, for example, the server device 50 of the first cloud 40.
[0064] The maintenance staff DB 63 is a database that manages maintenance staff and their maintenance authority. As one of its authentication services, the second cloud 60 provides a maintenance staff authentication service that allows an authentication source outside the second cloud 60 to use the maintenance staff DB 63. For example, when the server device 50 of the first cloud 40 processes an authentication request from the maintenance terminal 10 using the maintenance staff authentication service of the second cloud 60, the server device 50 accesses the maintenance staff DB 63 via the firewall 61 and authenticates the maintenance authority of the maintenance staff.
[0065] The administrator DB 65 is a database that manages the first administrator and the first administrator's key management authority. The administrator authentication device 67 uses the administrator DB 65 to authenticate the first administrator's key management authority, and may be, for example, one or more computers used as a server.
[0066] As one of its authentication services, the second cloud 60 provides a first administrator authentication service by an administrator authentication device 67 using an administrator DB 65. For example, when the server device 50 of the first cloud 40 processes an authentication request from the first management terminal 30 using the first administrator authentication service of the second cloud 60, the server device 50 transmits the authentication request to the administrator authentication device 67 and receives an authentication result from the administrator authentication device 67.
[0067] The second management terminal 70 is a terminal device, such as a PC, used by the second administrator to manage the maintenance staff DB 63 and the administrator DB 65 included in the second cloud 60. The second management terminal 70 is connected to the second cloud 60 via a public network such as the Internet. The second management terminal 70 is used to access the second cloud 60 to register maintenance staff managed in the maintenance staff DB 63, modify and delete maintenance authority, etc. The second management terminal 70 is also used to access the second cloud 60 to register first administrators managed in the administrator DB 65, modify and delete key management authority, etc. The second management terminal 70 may be the same terminal device as the first management terminal 30.
[0068] The currency processing device 80 processes currency, takes in currency, and performs various processes on the taken-in currency. Currency includes, but is not limited to, at least one of banknotes and coins. Currency may also include various types of securities such as checks, gift certificates, or stock certificates.
[0069] Examples of various processes related to currency include, but are not limited to, an identification process for identifying and processing the denomination, authenticity, fitness, etc. of currency. Note that the currency identification process typically uses identification data (settings file) that defines thresholds, etc. for identifying the denomination, authenticity, fitness, etc. of each currency type.
[0070] In this embodiment, we will explain the example where the data installed in the currency processing device 80 is the above-mentioned identification data, but the data installed in the currency processing device 80 is not limited to this.
[0071] When the currency processing device 80 receives securely processed installation data from the maintenance terminal 10, it decrypts the installation data. The currency processing device 80 manages a common key that is common to the common key for encryption processing stored in the server device 50, and a public key that pairs with the private key for electronic signature processing stored in the server device 50. Therefore, the currency processing device 80 extracts the electronic signature from the securely processed installation data and decrypts the hash value using the public key. The currency processing device 80 also uses the common key to decrypt the installation data (plain text) from the securely processed installation data. The currency processing device 80 also uses a hash function to calculate a hash value from the decrypted installation data and determines whether it matches the decrypted hash value. If the two hash values match and the integrity of the installation data is guaranteed, the currency processing device 80 installs the decrypted installation data to update the identification data (configuration file) used in the currency processing device 80.
[0072] 1 illustrates an example in which the maintenance terminal 10 and the currency handling device 80 are located at site A, the first management terminal 30 is located at site B, and the second management terminal 70 is located at site C. However, the location of each terminal and device is not limited to this. For example, the first management terminal 30 and the second management terminal 70 may be located at the same site.
[0073] Examples of site A include, but are not limited to, at least one of various stores such as banks and retail stores where currency handling devices 80 are used, and public facilities such as train stations. Examples of site B include, but are not limited to, a branch office or sales office of the manufacturer of currency handling devices 80 that manages maintenance of currency handling devices 80. Examples of site C include, but are not limited to, a site where the manufacturer's system management office is located, such as the head office of the manufacturer of currency handling devices 80.
[0074] Examples of maintenance personnel include, but are not limited to, employees of contractors contracted to perform maintenance work by the manufacturer of currency handling device 80, and employees of the manufacturer of currency handling device 80. Examples of first managers include, but are not limited to, employees of the manufacturer of currency handling device 80 who are responsible for maintenance management work for currency handling device 80 or employees who have been granted maintenance management authority. Examples of second managers include, but are not limited to, employees assigned to the system management office of the manufacturer of currency handling device 80.
[0075] The second cloud 60 may be a cloud service newly developed for the system 1, or may be a cloud service having functions such as a directory service that the manufacturer of the currency handling device 80 originally had for purposes such as employee management. By utilizing an existing cloud service in the latter case, the development costs and running costs of the system 1 can be reduced.
[0076] 2 is a block diagram showing an example of the hardware configuration of the maintenance terminal 10 of this embodiment. As shown in Fig. 2, the maintenance terminal 10 includes a control device 11, a main memory device 12, an auxiliary memory device 13, a display device 14, an input device 15, a communication device 16, a reader device 17, and various buses 18. The control device 11, the main memory device 12, the auxiliary memory device 13, the display device 14, the input device 15, the communication device 16, and the reader device 17 are connected via the various buses 18. As such, the maintenance terminal 10 of this embodiment has a general hardware configuration using a normal computer.
[0077] The control device 11 controls the overall operation of the maintenance terminal 10. Examples of the control device 11 include at least one of a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit), but are not limited to these. There may be any number of CPUs or GPUs as long as there is one or more, and they may be single-core or multi-core.
[0078] Examples of the main storage device 12 include, but are not limited to, a ROM (Read Only Memory) and a RAM (Random Access Memory). The ROM stores various programs, such as a program for controlling the maintenance terminal 10 and the maintenance program of this embodiment. The RAM is used as a work area when the control device 11 performs various controls based on the programs stored in the ROM.
[0079] The auxiliary storage device 13 stores the various programs and data described above. The various programs described above may be stored in at least one of the main storage device 12 and the auxiliary storage device 13. Examples of the auxiliary storage device 13 include, but are not limited to, existing storage devices capable of magnetic, electrical, or optical storage, such as a hard disk drive (HDD), a solid state drive (SSD), and a digital versatile disc (DVD). The auxiliary storage device 13 may be built into the maintenance terminal 10 or may be externally attached to the maintenance terminal 10 via an interface such as a universal serial bus (USB). The auxiliary storage device 13 may also be a network-attached storage (NAS) connected via a network such as a LAN or a wide area network (WAN).
[0080] The display device 14 displays various screens when using the maintenance software and serves as a user interface with the user (maintenance personnel). Examples of the display device 14 include, but are not limited to, various displays such as a liquid crystal display, an organic electroluminescence (EL) display, and a touch panel display. The display device 14 may be a built-in display built into the maintenance terminal 10, or an external display connected to the maintenance terminal 10 via a display interface such as HDMI (registered trademark).
[0081] The input device 15 is used for various inputs when using the maintenance software, and serves as a user interface with the user (maintenance personnel). Examples of the input device 15 include, but are not limited to, a keyboard, a mouse, and a touch panel. The input device 15 may be built into the maintenance terminal 10 or may be externally attached to the maintenance terminal 10 via an interface such as a USB.
[0082] Examples of the communication device 16 include, but are not limited to, a communication device for a wired LAN and a wireless communication device for a wireless LAN. The communication device 16 may be used to obtain the maintenance program and data of this embodiment from an external device.
[0083] The reader device 17 may be, for example, a device that reads data from an external device connected to a port such as a USB port, but is not limited to this. In this embodiment, the reader device 17 is used to read information from the hardware key 20.
[0084] In addition to the above configuration, the maintenance terminal 10 may further include hardwired circuits such as an IC (Integrated Circuit), an ASIC (Application Specific Integrated Circuit), and an FPGA (Field-Programmable Gate Array) that are specific to the maintenance terminal 10.
[0085] Fig. 3 is a block diagram showing an example of the hardware configuration of the server device 50 of this embodiment. As shown in Fig. 3, the server device 50 includes a control device 51, a main memory device 52, an auxiliary memory device 53, a communication device 56, and various buses 58. The control device 51, the main memory device 52, the auxiliary memory device 53, and the communication device 56 are connected via the various buses 58. As such, the server device 50 of this embodiment has a general hardware configuration using a normal computer.
[0086] The control device 51 controls the overall operation of the server device 50. The method of realizing the control device 51 is similar to that of the control device 11, and therefore a detailed description thereof will be omitted.
[0087] The ROM of the main memory device 52 stores various programs such as a program for controlling the server device 50, a program for performing secure processing, a program for controlling authentication processing, etc. The method for realizing the main memory device 52 is the same as that of the main memory device 12, and therefore a detailed description thereof will be omitted.
[0088] The auxiliary storage device 53 stores the various programs and data described above. The various programs described above may be stored in at least one of the main storage device 52 and the auxiliary storage device 53. The method for realizing the auxiliary storage device 53 is the same as that for the auxiliary storage device 13, and therefore a detailed description thereof will be omitted.
[0089] The method for realizing the communication device 56 is similar to that of the communication device 16, and therefore a detailed description thereof will be omitted.
[0090] In addition to the above configuration, the server device 50 may further include hardwired circuits such as ICs, ASICs, and FPGAs that are specific to the server device 50 .
[0091] 4 is a schematic diagram showing an example of the mechanical configuration of the currency handling device 80 of this embodiment. In the following description, the side on which the first door 823 (described later) is provided may be referred to as the front, and the side opposite to the side on which the first door 823 is provided may be referred to as the rear.
[0092] In the example shown in Fig. 4, the currency handling device 80 processes loose banknotes. The currency handling device 80 has an upper processing unit 81 and a lower safe 82. The safe 82 has a first safe unit 821 and a second safe unit 822.
[0093] The processing section 81 has an upper housing 811. Inside the upper housing 811, a deposit section 812, a withdrawal section 813, a recognition section 814, and part of the transport path are arranged.
[0094] The interior of safe 82 is divided into two areas. Inside safe 82, there are a storage section 83, a part of the transport path, and a main board 855, which will be described later. Safe 82 protects storage section 83 and main board 855 at a security level equal to or higher than a predetermined level. The security level of safe 82 is higher than that of upper housing 811.
[0095] The safe 82 has a first door 823 and a second door 824. The first door 823 is provided with an electronic lock 825. The electronic lock 825 is normally locked. When the first manager unlocks the electronic lock 825, the first door 823 becomes openable. With the first door 823 open, the storage section 83 of the first safe section 821 is pulled out to the front of the currency handling device 80.
[0096] The second door 824 is provided with an electronic lock 826. The electronic lock 826 is normally locked. When the first manager unlocks the electronic lock 826, the second door 824 becomes openable. With the second door 824 open, the storage section 83 of the second safe section 822 is pulled out to the front of the currency handling device 80.
[0097] A first administrator with special authority can unlock the electronic locks 825 and 826. The authority required to unlock the electronic lock 825 and the authority required to unlock the electronic lock 826 do not have to be the same.
[0098] The deposit unit 812 is a section into which banknotes to be deposited are inserted, for example, during a deposit process in which the banknotes are deposited into a storage unit described below. The deposit unit 812 holds multiple banknotes in a stacked state. The deposit unit 812 has a mechanism for taking in the banknotes one by one into the device.
[0099] The dispensing unit 813 is a unit that holds banknotes to be dispensed, for example, during a dispensing process in which banknotes are dispensed from a storage unit described below. The dispensing unit 813 holds multiple banknotes in a stacked state. A user of the currency handling device 80 can manually remove banknotes from the dispensing unit 813. Note that the user of the currency handling device 80 includes not only the first manager, but also general users such as maintenance personnel and customers of the store where the currency handling device 80 is installed.
[0100] The recognition unit 814 is provided on a looped conveyance path 841, which will be described later. The recognition unit 814 detects banknotes conveyed along the looped conveyance path 841. The recognition unit 814 acquires an image of each detected banknote. The recognition unit 814 uses the acquired images to identify at least whether the banknote is genuine, counterfeit, denomination, and fitness. The recognition unit 814 acquires the serial number of the banknote.
[0101] The storage unit 83 stores banknotes. The storage unit 83 stores banknotes, for example, in a stack format (where banknotes are stacked) or a tape format (where banknotes are wound up together with tape).
[0102] The multiple storage units 83 are each provided inside the first safe unit 821 or the second safe unit 822. The multiple storage units 83 may include storage cassettes that are detachable from the currency handling device 80. At least one of the storage units 83 provided in the first safe unit 821 is supported by a support unit 827. The support unit 827 has, for example, a rail structure, and can move forward while supporting the storage units 83 when the first door 823 is open. This allows the storage units 83 of the first safe unit 821 to be pulled out toward the front of the currency handling device 80.
[0103] A sensor that detects the passage of banknotes is attached to the banknote entrance / exit of storage unit 83. Based on the detection signal of the sensor, storage unit board 854, which will be described later, counts the number of banknotes that have entered storage unit 83 and the number of banknotes that have left storage unit 83. Based on the counted number, storage unit board 854 manages the number of banknotes stored in storage unit 83.
[0104] The transport unit 84 transports banknotes within the currency handling device 80. The transport unit 84 has a transport path. Although not shown, the transport path is composed of a combination of a large number of rollers, a plurality of belts, motors that drive these, and a plurality of guides. The transport unit 84 transports banknotes one by one along the transport path, for example, with the long edges of the banknotes facing forward, with a gap between each banknote. The transport unit 84 may also transport banknotes with the short edges facing forward.
[0105] The transport unit 84 has a loop transport path 841. The loop transport path 841 is provided inside the upper housing 811. The transport unit 84 transports banknotes along the loop transport path 841 in the clockwise and counterclockwise directions in FIG. 2 .
[0106] The deposit unit 812 is connected to the loop conveyance path 841 via a connection path 842. The withdrawal unit 813 is connected to the loop conveyance path 841 via a connection path 843.
[0107] The storage units 83 are each connected to the loop conveying path 841 via a connecting path 844. The connecting paths 844 extend in the vertical direction so as to straddle the processing unit 81 and the first safe unit 821. A portion of the connecting path 844 extends in the vertical direction so as to straddle the processing unit 81, the first safe unit 821, and the second safe unit 822. The conveying unit 84 conveys banknotes from the loop conveying path 841 to each of the storage units 83 via the connecting path 844. The conveying unit 84 conveys banknotes from each of the storage units 83 to the loop conveying path 841 via the connecting path 844.
[0108] The upper housing 811 is provided with an escrow unit 86. The escrow unit 86 temporarily stores banknotes. The escrow unit 86 can be used for a variety of purposes. The escrow unit 86 is disposed at a front position within the upper housing 811. The escrow unit 86 is connected to the loop conveying path 841 via a connection path 845.
[0109] An external safe storage unit 840 can be attached to the currency handling device 80. The external safe storage unit 840 can be detached from the currency handling device 80. The external safe storage unit 840 is a detachable storage unit. The external safe storage unit 840 is connected to the loop transport path 841 via a connection path 846.
[0110] The currency handling device 80 includes an identification board 851, an upper board 852, a lower board 853, a storage board 854, and a main board 855. Each board includes a memory device, a processor, and a communication interface. The memory device is composed of semiconductor memory such as RAM, ROM, eMMC (embedded Multi Media Card), or SSD. Various data and software are stored in the memory device. The processor reads and executes various software from the memory device. The communication interface communicates based on a predetermined communication standard such as USB or RS-422.
[0111] In the currency handling apparatus 80, the main board 855 performs the security management function in the currency handling apparatus 80. The main board 855 has a distinctive hardware configuration in order to realize the security management function.
[0112] 5 is a block diagram showing an example of the hardware configuration of the main board 855 of this embodiment. The main board 855 includes a processor 870, a storage device 871, a communication interface 872, and a security chip 880 (an example of a storage unit).
[0113] The processor 870, like the processors (microcomputers) on other boards, executes software in the storage device 871. Code that can be executed by the processor 870 itself (hereinafter referred to as internal code) is embedded in the processor 870. The processor 870 is configured so that the internal code cannot be changed. In other words, a third party cannot tamper with the internal code. The processor 870 executes the internal code when the processor 870 is started up.
[0114] The processor 870 is provided with a memory area 873 that holds predetermined information (digital data). The memory area 873 is configured so that once information is written, it cannot be changed. It is impossible to tamper with the information in the memory area 873. The manufacturer of the currency handling device 80 writes information into the memory area 873 before the currency handling device 80 is shipped (for example, during the manufacture of the currency handling device 80).
[0115] The security chip 880 is a tamper-resistant semiconductor device. Tamper resistance refers to the property of making it difficult for data stored inside to be analyzed, read, or altered from the outside. The security chip 880 may be a security chip (TPM: Trusted Platform Module) that complies with security specifications defined by the TCG (Trusted Computing Group). The security chip 880 is provided with a storage device 881 that stores predetermined information (digital data).
[0116] The security chip 880 is connected to the processor 870 via a bus 856. In order for the processor 870 to access (write or read) the security chip 880, a predetermined authentication code is required.
[0117] The security chip 880 has a function of storing the above-mentioned common key and public key. The security chip 880 may also have a function of calculating a hash value. The storage device 881 may store data for authenticating the software in the storage device 871. The data for authenticating the software is, for example, a hash value of the software.
[0118] The storage device 871 has the same configuration as the storage devices provided on other boards. The storage device 871 may be configured with multiple types of devices (e.g., eMMC and ROM). In this embodiment, the storage device 871 on the main board 855 includes an eMMC. The storage device 871 stores basic software and application software.
[0119] The communication interface 872 has the same configuration as the communication interfaces provided on the other boards.
[0120] 4, the description will be continued. The identification board 851 and the upper board 852 are provided in the upper housing 811.
[0121] The identification board 851 controls the recognition unit 814 and outputs the recognition result by the processor executing predetermined software. For example, the identification board 851 identifies the authenticity, denomination, and fitness of a banknote based on an image of the banknote. The identification board 851 is connected to the upper board 852 via a communication interface. The identification board 851 outputs the recognition result to the upper board 852 via the communication interface.
[0122] The upper substrate 852 controls the operations of the deposit unit 812, the withdrawal unit 813, the transport unit 84, the temporary holding unit 86, etc. by the processor executing predetermined software. For example, the upper substrate 852 controls the drive mechanisms (motors) provided in the transport unit 84, etc.
[0123] The lower board 853, storage unit board 854, and main board 855 are provided inside the safe 82. More specifically, the lower board 853 and main board 855 are provided inside the first safe unit 821. In other words, the main board 855 is installed in a location where it is necessary to unlock the electronic lock 825. The storage unit board 854 is provided in each of the storage units 83.
[0124] A storage unit board 854 is provided for each storage unit 83. The storage unit board 854 has a memory device that stores the ID and door opening / closing log of the corresponding storage unit 83. These memory devices may also store at least one of the type and number of banknotes stored.
[0125] The storage section board 854 is connected to the lower board 853 via a communication interface. In response to a request from the lower board 853, the storage section board 854 transmits information on the ID and door opening / closing log to the lower board 853 via the communication interface.
[0126] The processor of the lower board 853 executes predetermined software to control each storage unit 83 and the transport unit 84. The lower board 853 collects IDs and log data of the storage units 83.
[0127] The lower substrate 853 is connected to the upper substrate 852 via a communication interface. When controlling the transport unit 84, the lower substrate 853 sends a predetermined signal (command) to the upper substrate 852 via the communication interface.
[0128] The main board 855 is responsible for starting up the currency handling device 80, communicating with the outside of the currency handling device 80, and managing various software by having the processor execute predetermined software. The memory device 871 of the main board 855 is equipped with basic software (OS: Operating System).
[0129] In the currency processing device 80, the main board 855 is provided inside the first safe section 821, and therefore a third party cannot access the main board 855. Therefore, a third party cannot access the common key and the public key stored in the security chip 880.
[0130] The main board 855 is connected to the lower board 853 via a communication interface 872. Log data, update files, and the like are transmitted and received between the main board 855 and the lower board 853.
[0131] The main board 855 is connected to the identification board 851 via the communication interface 872. The main board 855 transmits identification data to the identification board 851 and receives banknote image data from the identification board 851. As described above, the identification data is data for identifying the authenticity, denomination, and fitness of banknotes. The banknote image data is image data of banknotes acquired by the identification board 851.
[0132] The currency handling device 80 has a user interface (UI) unit (not shown). The UI unit includes an operation unit (keyboard, trackball, touch panel, etc.). A user can give various instructions to the currency handling device 80 by operating the operation unit.
[0133] The upper substrate 852 receives a user instruction via the UI unit, and if the instruction is not one that the upper substrate 852 can handle, it transfers the received instruction to the corresponding substrate. As a result, the substrate that handles the instruction outputs a signal to at least one of the deposit unit 812, withdrawal unit 813, recognition unit 814, storage unit 83, transport unit 84, temporary holding unit 86, and external safe storage unit 840 so as to execute the process corresponding to the instruction.
[0134] FIG. 6 is a block diagram illustrating an example of the functional configuration of the maintenance terminal 10, server device 50, and currency processing device 80 according to this embodiment. As shown in FIG. 6, the maintenance terminal 10 includes an authentication unit 101, a transmission unit 103 (an example of a second transmission unit), a reception unit 105, and a data generation unit 107. The authentication unit 101, transmission unit 103, reception unit 105, and data generation unit 107 can be realized, for example, by the control device 11, main memory device 12, communication device 16, and reader device 17 described in FIG. 2 . For example, the control device 11 reads the maintenance program according to this embodiment stored in the main memory device 12 (ROM) or the auxiliary memory device 13 and loads it into the main memory device 12 (RAM). The control device 11 executes various processes according to the loaded program, thereby implementing the above-described functional units as maintenance software. Furthermore, at least one of the authentication unit 101, transmission unit 103, reception unit 105, and data generation unit 107 may be a dedicated circuit for executing various processes.
[0135] As shown in FIG. 6 , the server device 50 includes an authentication information receiving unit 501, an authentication control unit 503, a transmission unit 505 (an example of a first transmission unit), a data receiving unit 507, a secure processing unit 509, and a key storage unit 511. The authentication information receiving unit 501, the authentication control unit 503, the transmission unit 505, the data receiving unit 507, and the secure processing unit 509 can be realized, for example, by the control device 51, the main storage device 52, and the communication device 56 described in FIG. 3 . For example, the control device 51 reads out a program for performing the secure processing and a program for controlling the authentication processing of this embodiment stored in the main storage device 52 (ROM) or the auxiliary storage device 53, and loads them into the main storage device 52 (RAM). The control device 51 executes various processes in accordance with the loaded programs to realize the above-mentioned functional units. The key storage unit 511 can be realized, for example, by the auxiliary storage device 53 described in FIG. 3 . At least one of the authentication information receiving unit 501, the authentication control unit 503, the transmitting unit 505, the data receiving unit 507, and the secure processing unit 509 may be a dedicated circuit for executing various processes.
[0136] As shown in FIG. 6 , the currency handling device 80 includes a receiving unit 891, a decryption unit 893, an installation unit 895, and a currency identification unit 897. The receiving unit 891, the decryption unit 893, and the installation unit 895 can be realized, for example, by the main board 855 described in FIG. 5 , and the currency identification unit 897 can be realized, for example, by the identification board 851 described in FIG. 5 . For example, the board realizes each of the above-mentioned functional units by executing a program stored thereon. At least one of the receiving unit 891, the decryption unit 893, and the installation unit 895 may be a dedicated circuit for executing various processes.
[0137] Below, we will explain each functional part of the maintenance terminal 10, server device 50, and currency processing device 80 of this embodiment, with appropriate reference to sequence diagrams and flowcharts.
[0138] FIG. 7 is a sequence diagram showing an example of a maintenance personnel authentication process performed in the system 1 of this embodiment.
[0139] The authentication unit 101 of the maintenance terminal 10 authenticates the legitimacy of the maintenance personnel using the hardware key 20, which is a dongle carried by the maintenance personnel (step S101). In this embodiment, the authentication of the maintenance personnel using the hardware key 20 is two-factor authentication, and the authentication unit 101 performs the first factor authentication, but the authentication method for the maintenance personnel is not limited to this. The hardware key 20 stores, for example, a password, a certificate for two-factor authentication, and a private key. The certificate may include, for example, information defining a dongle identification (ID) that identifies the hardware key 20 and a user ID that identifies the maintenance personnel carrying the hardware key 20.
[0140] For example, a maintenance technician logs in to the maintenance terminal 10, connects the hardware key 20 to the maintenance terminal 10, starts up the maintenance software, and enters a password. The authentication unit 101 accepts the password entered by the maintenance technician, reads the password stored in the hardware key 20 connected to the maintenance terminal 10, and compares the two passwords. If the password comparison is successful, the authentication unit 101 determines that the first element of authentication of the maintenance technician's legitimacy has been successful, and if the password comparison is unsuccessful, it determines that authentication of the maintenance technician has failed.
[0141] However, the first element of authentication is not limited to the password matching described above. For example, the person possessing the hardware key 20 may be considered to be a legitimate maintenance person, and the authentication unit 101 may determine that the first element of authentication has been successful by determining that the hardware key 20 is connected to the maintenance terminal 10.
[0142] If the authentication by the authentication unit 101 is successful, the transmission unit 103 of the maintenance terminal 10 transmits maintenance staff authentication information to the server device 50 to authenticate the maintenance staff who will be performing maintenance on the currency handling device 80 using the maintenance terminal 10 (step S103). Note that if the authentication of the maintenance staff fails in step S101, the processing from step S103 onwards is not performed.
[0143] The maintenance staff authentication information includes at least the certificate stored in the hardware key 20. In this embodiment, since the second element authentication is performed using a challenge-response method, the maintenance staff authentication information further includes a one-time password based on the hardware key 20, but is not limited to this.
[0144] That is, in this embodiment, the maintenance personnel authentication information includes the user ID of the maintenance personnel, the dongle ID of the hardware key 20 held by the maintenance personnel, and a one-time password based on the hardware key 20 held by the maintenance personnel. The user ID of the maintenance personnel, the dongle ID of the hardware key 20, and the one-time password based on the hardware key 20 are all information that identifies the maintenance personnel, but are different from each other. The user ID of the maintenance personnel is an example of first authentication information, the dongle ID of the hardware key 20 is an example of second authentication information, and the one-time password based on the hardware key 20 is an example of third authentication information.
[0145] Specifically, prior to transmitting the maintenance personnel authentication information, the transmitting unit 103 requests a challenge from the server device 50. The authentication information receiving unit 501 of the server device 50 receives the challenge request from the maintenance terminal 10, the authentication control unit 503 of the server device 50 generates the challenge, and the transmitting unit 505 of the server device 50 transmits the generated challenge to the maintenance terminal 10. The receiving unit 105 of the maintenance terminal 10 receives the challenge from the server device 50.
[0146] The transmission unit 103 of the maintenance terminal 10 uses a hash function to calculate a hash value of the challenge received from the server device 50, and encrypts the hash value using the private key stored in the hardware key 20. The hash value of the challenge is an example of a one-time password based on the hardware key 20. The transmission unit 103 generates maintenance staff authentication information including the encrypted hash value of the challenge and the certificate stored in the hardware key 20, and transmits the information to the server device 50.
[0147] The authentication information receiving unit 501 of the server device 50 receives the maintenance personnel authentication information from the maintenance terminal 10 (step S103). The authentication control unit 503 of the server device 50 obtains a hash value of the encrypted challenge from the received maintenance personnel authentication information, and controls authentication of the legitimacy of the maintenance personnel using the hash value of the encrypted challenge (step S105).
[0148] Specifically, the authentication control unit 503 decrypts the hash value of the encrypted challenge using a public key that is paired with the private key stored in the hardware key 20. Note that the public key is stored in a key storage unit 511 (described later) in association with, for example, a dongle ID, and therefore the authentication control unit 503 can obtain the public key from the key storage unit 511 using the dongle ID as a key. The authentication control unit 503 also calculates a hash value of the generated challenge using a hash function and compares it with the decrypted hash value. If the hash value comparison is successful, the authentication control unit 503 determines that the second factor of authentication of the legitimacy of the maintenance person has been successful, and if the hash value comparison is unsuccessful, the authentication control unit 503 determines that the authentication of the maintenance person has failed.
[0149] In addition to comparing the hash value, the authentication control unit 503 may also perform a second factor of authentication of the maintenance personnel by taking into account factors such as whether the comparison was performed within the validity period of the hash value and the legitimacy of the certificate included in the maintenance personnel authentication information.
[0150] The authentication control unit 503 also controls the authentication of the maintenance personnel using the maintenance personnel authentication information and a first authentication service provided on a second cloud 60 that is different from the first cloud 40. The first authentication service is, for example, an authentication service that uses a maintenance personnel DB 63 managed within the second cloud 60, and the authentication control unit 503 controls the authentication of whether or not the maintenance personnel has maintenance authority over the currency processing device 80.
[0151] The authentication information receiving unit 501 also receives, from the first management terminal 30 used to manage keys stored in the key storage unit 511 (described later), administrator authentication information for authenticating a first administrator (an example of an administrator) using the first management terminal 30. In this case, the authentication control unit 503 controls authentication processing of the first administrator using the administrator authentication information and a second authentication service provided on the second cloud 60. The administrator authentication information includes at least a user ID that identifies the first administrator. The user ID of the first administrator is an example of first authentication information. The second authentication service is, for example, an authentication service that uses an administrator DB 65 managed in the second cloud 60, and the authentication control unit 503 controls authentication to determine whether the first administrator has authority to manage keys.
[0152] In step S105, if the authentication control unit 503 successfully authenticates the legitimacy of the maintenance person, it controls authentication to determine whether the maintenance person has maintenance authority over the currency processing device 80 (step S107). Note that if authentication of the maintenance person fails in step S105, the processing from step S107 onwards is not performed. Furthermore, the authentication control to determine whether the maintenance person has maintenance authority has much in common with the authentication control to determine whether the first manager has key management authority, and therefore will be explained together using the flowchart shown in Figure 8.
[0153] FIG. 8 is a flowchart showing an example of the authority authentication process for the maintenance personnel and the first administrator performed in the system 1 of this embodiment.
[0154] The authentication control unit 503 determines whether the first authentication service or the second authentication service is to be used for authentication based on the user ID included in the maintenance staff authentication information or the administrator authentication information. Specifically, the authentication control unit 503 determines whether the first authentication service or the second authentication service is to be used for authentication by referencing the user ID and the authentication destination DB 43. The authentication control unit 503 may also determine whether the first authentication service or the second authentication service is to be used for authentication based on the sender of the authentication information. Specifically, the authentication control unit 503 may determine to use the first authentication service when the sender of the authentication information is the maintenance terminal 10 or the maintenance software, and to use the second authentication service when the sender of the authentication information is the first management terminal 30 or the management software running on the first management terminal 30.
[0155] 9 is a diagram showing an example of information stored in the authentication destination DB 43 of this embodiment. As shown in Fig. 9, the authentication destination DB 43 stores user IDs in association with authentication destination information. In the example shown in Fig. 9, the user ID indicating the first manager is associated with the manager DB 65 as authentication destination information, and the user ID indicating the maintenance worker is associated with the maintenance worker DB 63 as authentication destination information.
[0156] The authentication control unit 503 uses the user ID as a key to acquire authentication destination information associated with the user ID from the authentication destination DB 43 (step S201). The authentication control unit 503 determines to use an authentication service that uses the DB indicated by the acquired authentication destination information for authentication. Specifically, if the acquired authentication destination information indicates the maintenance staff DB 63 (Yes in step S203), the authentication control unit 503 determines to use the first authentication service (step S205). Therefore, in step S107 of the sequence diagram shown in FIG. 7 , the authentication control unit 503 determines to use the first authentication service for authentication of the maintenance staff's maintenance authority using the maintenance staff authentication information.
[0157] When the authentication control unit 503 determines to use the first authentication service for authentication, it uses the dongle ID (more specifically, the dongle ID defined in the certificate) included in the maintenance staff authentication information and the first authentication service to control authentication of whether the maintenance staff has maintenance authority over the currency processing device 80. Specifically, the authentication control unit 503 refers to the dongle ID and the maintenance staff DB 63 to authenticate the maintenance staff's maintenance authority over the currency processing device 80.
[0158] Figure 10 is a diagram showing an example of information stored in the maintenance staff DB 63 of this embodiment. As shown in Figure 10, the maintenance staff DB 63 stores a user ID, a dongle ID, and the device ID of a currency processing device for which the maintenance staff has authority, in association with each other. In the example shown in Figure 10, the device ID "currency processing device A" indicates currency processing device 80.
[0159] The authentication control unit 503 uses the dongle ID as a key to obtain the device ID associated with the dongle ID from the maintenance staff DB 63, and authenticates whether or not the maintenance staff A has maintenance authority for the currency handling device indicated by the device ID (step S207). Therefore, in the example shown in FIG. 10 , if the dongle ID indicates maintenance staff A, the authentication control unit 503 obtains the device ID "currency handling device A" indicating the currency handling device 80, and therefore authenticates that maintenance staff A has maintenance authority for the currency handling device 80. On the other hand, if the dongle ID indicates maintenance staff B, the authentication control unit 503 obtains the device ID "currency handling device B" indicating a currency handling device 80 other than the currency handling device 80, and therefore authenticates that maintenance staff B does not have maintenance authority for the currency handling device 80. Note that in step S107 of the sequence diagram shown in FIG. 7 , the dongle ID indicates maintenance staff A, and therefore the authentication control unit 503 authenticates that maintenance staff A has maintenance authority for the currency handling device 80.
[0160] In this embodiment, the maintenance authority of the maintenance personnel is set on a device-by-device basis, but this is not limited thereto, and the maintenance authority may be set on a device-by-device basis. In this way, the maintenance authority of the maintenance personnel can be flexibly set, for example, by granting authority for simple maintenance of currency processing devices to a wide range of maintenance personnel, and granting authority for important maintenance such as installation authority to a limited number of maintenance personnel.
[0161] In this embodiment, a dongle ID is used to authenticate maintenance authority in order to enhance security, but this is not limiting and a user ID may be used instead. Note that the dongle ID is stored in the hardware key 20 and is less likely to be seen by others, so it is more confidential than a user ID and therefore provides higher security.
[0162] On the other hand, if the acquired authentication destination information indicates the administrator DB 65 (No in step S203), the authentication control unit 503 determines to use the second authentication service (step S209). Therefore, in this embodiment, the authentication control unit 503 determines to use the second authentication service for authentication of the first administrator's key management authority using the administrator authentication information.
[0163] When the authentication control unit 503 determines to use the second authentication service for authentication, it controls authentication of whether the first administrator has key management authority by using the user ID and the second authentication service included in the administrator authentication information. Specifically, the authentication control unit 503 notifies the administrator authentication device 67 of the user ID and obtains the authentication result of the first administrator's key management authority, which the administrator authentication device 67 performs using the administrator DB 65.
[0164] 11 is a diagram showing an example of information stored in the administrator DB 65 of this embodiment. As shown in Fig. 11, the administrator DB 65 stores user IDs and key management authority information in association with each other.
[0165] The authentication control unit 503 notifies the administrator authentication device 67 of the user ID (step S211). The administrator authentication device 67 uses the user ID notified from the authentication control unit 503 as a key to obtain key management authority information associated with the user ID from the administrator DB 65, authenticates the key management authority of the first administrator (step S213), and notifies the authentication control unit 503 of the authentication result (step S215). Therefore, in the example shown in Figure 11, when the user ID indicates administrator A, key management authority "Yes" is obtained, and the authentication control unit 503 obtains an authentication result that administrator A has key management authority. On the other hand, when the user ID indicates administrator B, key management authority "No" is obtained, and the authentication control unit 503 obtains an authentication result that administrator B does not have key management authority.
[0166] In this embodiment, we have taken the example of a case where the first administrator's key management authority is simply set to yes or no, but this is not limited to this, and key management authority may also be set on a device-by-device basis for currency processing devices.
[0167] Returning to FIG. 7 , the explanation will be continued. If the authentication control unit 503 authenticates in step S107 that the maintenance personnel has maintenance authority over the currency processing device 80, it issues a JWT (JSON Web Token) (step S109). The JWT is, for example, a token that proves that the maintenance personnel is authenticated as having the legitimacy and maintenance authority. The JWT is used, for example, to omit subsequent authentication, such as authentication when the secure processing unit 509 (described later) performs secure processing on installation data. Note that if the maintenance personnel is authenticated in step S107 as not having maintenance authority, the processing from step S109 onward is not performed.
[0168] The transmitting unit 505 of the server device 50 transmits the JWT issued by the authentication control unit 503 to the maintenance terminal 10 as an authentication result using the maintenance personnel authentication information by the authentication control unit 503 (step S111). Note that if authentication of the maintenance personnel fails in step S105 or if the maintenance personnel is authenticated as not having maintenance authority in step S107, the transmitting unit 505 transmits an authentication result indicating authentication failure to the maintenance terminal 10. In addition, the transmitting unit 505 transmits the authentication result using the administrator authentication information by the authentication control unit 503 to the first management terminal 30.
[0169] FIG. 12 is a sequence diagram showing an example of an installation process performed in the system 1 of this embodiment.
[0170] When the receiving unit 105 of the maintenance terminal 10 receives the authentication result using the maintenance personnel authentication information from the server device 50, the authentication unit 101 of the maintenance terminal 10 performs control according to the authentication result. For example, if the authentication result indicates authentication failure, the authentication unit 101 terminates the maintenance software. Also, for example, if the authentication result is JWT, the authentication unit 101 makes the functions of the maintenance software, such as generating installation data, available. Note that if authentication of maintenance authority is performed on a function-by-function basis, control may be performed so that functions for which the maintenance personnel have authority are available.
[0171] In response to an operation input from a maintenance technician, the data generation unit 107 generates installation data, which is data (an example of first data) to be installed in the currency processing device 80 (step S301). In this embodiment, as described above, the installation data is used as identification data to identify currency, but the present invention is not limited to this.
[0172] Fig. 13 is a diagram showing an example of installation data generated by the data generation unit 107 of this embodiment. The installation data shown in Fig. 13 is data in which new thresholds are defined for updating various thresholds of the identification data currently being used in the currency handling device 80. In the installation data shown in Fig. 13, thresholds for determining the authenticity of banknotes based on the output of the infrared sensor are defined for each denomination and transport direction of the banknote.
[0173] Although not shown in Fig. 13, the installation data shown in Fig. 13 defines thresholds for determining authenticity not only for the infrared sensor but also for each sensor such as the magnetic sensor and thickness detection sensor. Similarly, although not shown in Fig. 13, the installation data shown in Fig. 13 defines thresholds for determining the denomination not only for authenticity determination but also for denomination determination, and also defines thresholds for determining fitness determination. Note that the installation data does not need to include new thresholds, and may include thresholds that are the same as the thresholds of the identification data currently being used.
[0174] For example, the maintenance technician generates installation data using the data generation unit 107 while conducting a flow test using currency that is actually used. The data generation unit 107 may receive data indicating the results of the flow test from the currency processing device 80 connected to the maintenance terminal 10 and generate the installation data. The results of the flow test may be, for example, the results of identifying test banknotes by the currency identification unit 897. Note that in this embodiment, the generation of installation data by the data generation unit 107 also includes loading installation data previously generated by the maintenance technician into the maintenance software.
[0175] The transmitting unit 103 of the maintenance terminal 10 transmits the installation data generated by the data generating unit 107, the device ID of the currency processing device 80, and the JWT to the server device 50, and requests secure processing (step S303). The data receiving unit 507 of the server device 50 receives the installation data, the device ID of the currency processing device 80, and the JWT from the maintenance terminal 10 (step S303).
[0176] The secure processing unit 509 of the server device 50 performs secure processing on the installation data received by the data receiving unit 507 to generate secured installation data (an example of second data). Specifically, the secure processing unit 509 authenticates the JWT received by the data receiving unit 507 and determines whether secure processing can be performed on the installation data (step S305). For example, if the JWT authenticates the legitimacy of the maintenance personnel and that the maintenance personnel has maintenance authority, the secure processing unit 509 determines that secure processing can be performed on the installation data. In other words, if the authentication control unit 503 successfully authenticates the maintenance personnel, the secure processing unit 509 generates secured update data.
[0177] The secure processing unit 509 performs secure processing on the installation data using a key stored in the key storage unit 511. In this embodiment, the secure processing unit 509 performs encryption processing and digital signature processing as described above. Therefore, the key storage unit 511 stores a common key (an example of a first key) as a key for encryption processing and a private key (an example of a third key) as a key for digital signature processing. While this embodiment describes an example in which the common key and the private key are prepared for each currency processing device, this is not limiting. For example, at least one of the common key and the private key may be prepared for each group of currency processing devices. The key storage unit 511 may also store a public key (a public key for decrypting the hash value of the encrypted challenge) used for the second element of authentication of the legitimacy of the maintenance personnel described above.
[0178] Figure 14 is a diagram showing an example of information stored in the key storage unit 511 of this embodiment. As shown in Figure 14, the key storage unit 511 stores IDs and various keys in association with each other. In the example shown in Figure 14, as described above, the key storage unit 511 stores not only the common key and private key used for secure processing, but also the public key used for authenticating the first element of the legitimacy of the maintenance personnel. For the keys used for secure processing, the key storage unit 511 stores the common key and private key in association with the device ID of the currency processing device. Furthermore, for the key used for authenticating the first element of the legitimacy of the maintenance personnel, the key storage unit 511 stores the public key in association with the dongle ID.
[0179] The secure processing unit 509 uses the device ID received by the data receiving unit 507 as a key to obtain the common key and private key associated with the device ID from the key storage unit 511. The secure processing unit 509 generates a digital signature for the installation data using the obtained private key and performs encryption processing to encrypt the installation data using the obtained common key. Specifically, the secure processing unit 509 calculates a hash value from the installation data using a hash function, encrypts the hash value using the obtained private key, and generates a digital signature for the installation data (step S307). The secure processing unit 509 also encrypts the installation data using the obtained common key (step S309). The secure processing unit 509 assigns a digital signature to the encrypted installation data to create secured installation data.
[0180] The transmitting unit 505 of the server device 50 transmits the secured installation data to the maintenance terminal 10, and the receiving unit 105 of the maintenance terminal 10 receives the secured installation data (step S311).
[0181] The transmitting unit 103 of the maintenance terminal 10 transmits the received secured installation data to the currency processing device 80 in response to operational input from the maintenance personnel in order to install the secured installation data in the currency processing device 80 (step S313). The receiving unit 891 of the currency processing device 80 receives the secured installation data from the maintenance terminal 10 (step S313).
[0182] The decryption unit 893 of the currency processing device 80 decrypts the secured installation data received by the receiving unit 891 into installation data. In this embodiment, as described above, the security chip 880 of the currency processing device 80 stores a common key (an example of a second key) that is common to the common key for encryption processing stored in the server device 50, and a public key (an example of a fourth key) that pairs with the private key for electronic signature processing stored in the server device 50. Therefore, the decryption unit 893 obtains the common key and public key from the security chip 880.
[0183] The decryption unit 893 uses the acquired common key to decrypt the secured installation data into installation data. The decryption unit 893 also acquires a digital signature from the secured installation data, and determines whether the integrity of the decrypted installation data is guaranteed using the decrypted installation data, the digital signature, and the acquired public key. Specifically, the decryption unit 893 decrypts the encrypted installation data using the acquired common key (step S315). The decryption unit 893 also decrypts a hash value from the digital signature using the acquired public key, calculates a hash value from the decrypted installation data using a hash function, and determines whether the two hash values match, thereby authenticating the integrity of the decrypted installation data (step S317).
[0184] The installation unit 895 of the currency processing device 80 installs the decrypted installation data in the currency processing device 80 (step S319). Specifically, if the integrity of the decrypted installation data is guaranteed by the decryption unit 893, the installation unit 895 installs the decrypted installation data in the currency processing device 80.
[0185] The currency identification unit 897 of the currency handling device 80 uses the above-mentioned identification data (setting file) to perform a process of identifying the type of currency, including at least one of the currency denomination, authenticity, and fitness. As described above, the identification data defines various thresholds, and the currency identification unit 897 performs the identification process by comparing the detection value detected from the currency with the various thresholds.
[0186] As described above, this embodiment is described by taking as an example a case where the installation data installed in the currency handling device 80 is identification data (setting file) used in the above-mentioned identification process. Therefore, when the installation data is installed in the currency handling device 80 by the installation unit 895, the above-mentioned identification data (setting file) is updated, and the currency identification unit 897 performs the identification process using the updated identification data (setting file).
[0187] However, the installation of installation data is not limited to updating data, but may be updating a program, or setting new data or a program in the currency processing device 80. Furthermore, the installation of installation data may simply involve placing the data or program in a predetermined location, or may include adding or changing OS settings.
[0188] As described above, in this embodiment, the secure processing function for performing secure processing on data installed in the currency processing device is cloud-based. Therefore, the keys used for the secure processing can be managed on the cloud, which increases the security (e.g., confidentiality and integrity) of the installed data itself and prevents leakage of keys via maintenance personnel who generate the installed data.
[0189] For example, if the data installed in a currency processing device is identification data used to identify currency, maintenance personnel must be able to maintain (update, etc.) the above-mentioned identification data in order to maintain the currency processing device. On the other hand, if a key is embedded in the maintenance software and secure processing is performed on a maintenance terminal, there is a risk that the key may be leaked if the maintenance software is analyzed. In contrast, in this embodiment, the secure processing function is cloud-based as described above, which not only increases the security of the installed data and prevents key leakage via maintenance personnel, but also maintains the availability of maintenance work by maintenance personnel. Therefore, this embodiment can improve security in the process of installing data in a currency processing device.
[0190] In addition, in this embodiment, the authorization authentication function for authenticating maintenance authority for the currency processing device, such as installing data in the currency processing device, is also cloud-based and realized as a cloud service separate from the secure processing function. As a result, in the system of this embodiment, the keys used for secure processing and the information used for authorization authentication can be managed in separate cloud environments, preventing unauthorized installation of data in the currency processing device by unauthorized persons while increasing the robustness of the system against leaks of the keys and information.
[0191] In addition, in this embodiment, two-factor authentication is used for authority authentication, which further enhances security in the process of installing data in a currency processing device.
[0192] In addition, in this embodiment, the currency processing device also manages the keys for decrypting secure processing in the memory or TPM within the safe, thereby increasing the security (e.g., confidentiality and integrity) of the data being installed and preventing key leakage.
[0193] (Variation 1) In the above embodiment, a case has been described in which the common key and public key are stored in the security chip 880 of the currency processing device 80, and the common key and public key are stored in the memory and TPM within the safe 82 provided in the currency processing device 80. However, the manner in which the common key and public key are managed by the currency processing device 80 is not limited to this, and for example, the common key and public key may be stored either in the memory or TPM within the safe 82 provided in the currency processing device 80. Furthermore, it is not necessary to store both the common key and the public key in the same storage unit, and for example, one of the keys may be stored in the memory within the safe 82 or the TPM.
[0194] Generally, the importance of confidentiality of the public key tends to be lower than that of the common key. In this embodiment, the public key is used to authenticate the integrity of the installation data, so even if the public key is leaked from the currency processing device 80, it is unlikely that unauthorized data will be installed as a result. For this reason, the common key may be stored in the memory or TPM within the safe 82, and the public key may be stored in a storage unit other than the memory or TPM within the safe 82.
[0195] (Program) The programs executed by each device and each terminal in the above embodiment and modified example are provided as files in an installable or executable format stored on a computer-readable storage medium such as a CD-ROM, CD-R, memory card, DVD, or flexible disk (FD).
[0196] Furthermore, the programs executed by each device and each terminal of the above-described embodiment and modified example may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network. Furthermore, the programs executed by each device and each terminal of the above-described embodiment and modified example may be provided or distributed via a network such as the Internet. Furthermore, the programs executed by each device and each terminal of the above-described embodiment and modified example may be provided by being pre-installed in a ROM or the like.
[0197] The programs executed by each device and each terminal in the above-described embodiment and modified example have a modular configuration for implementing the above-described units on a computer. In actual hardware, for example, the CPU reads the learning program from the HDD onto the RAM and executes it, thereby implementing the above-described units on the computer.
[0198] As described above, according to the above embodiment and the above modified example, it is possible to improve security in the process of installing data in a currency processing device.
[0199] The above-described embodiment and modifications merely illustrate examples of specific embodiments of the present disclosure, and the technical scope of the present disclosure should not be construed as being limited by these. Therefore, the present disclosure can be implemented in various forms without departing from the spirit or main features thereof. For example, the above-described embodiment and modifications may be appropriately combined in their respective constituent units. Furthermore, for example, some components may be deleted from all components in the above-described embodiment and modifications.
[0200] REFERENCE SIGNS LIST 1 System 10 Maintenance terminal 20 Hardware key 30 First management terminal 40 First cloud 41 Firewall 43 Authentication destination DB 50 Server device 60 Second cloud 61 Firewall 63 Maintenance staff DB 65 Administrator DB 67 Administrator authentication device 70 Second management terminal 80 Currency processing device 82 Safe 101 Authentication unit 103 Transmission unit 105 Reception unit 107 Data generation unit 501 Authentication information reception unit 503 Authentication control unit 505 Transmission unit 507 Data reception unit 509 Secure processing unit 511 Key storage unit 821 First safe unit 822 Second safe unit 851 Identification board 855 Main board 871 Storage device 880 Security chip 881 Storage device 891 Reception unit 893 Decryption unit 895 Installation unit 897 Currency Identification Department
Claims
1. A system including a currency processing device that processes currency, wherein the currency processing device comprises: a receiving unit that receives second data obtained by securely processing first data installed in the currency processing device via a maintenance terminal that transmits the first data to a server device that provides a secure processing service on a first cloud; a decryption unit that decrypts the second data into the first data; and an installation unit that installs the decrypted first data in the currency processing device.
2. A system as described in claim 1, wherein the currency processing device further comprises a currency identification unit that performs an identification process of the type of currency, including at least one of the denomination, authenticity, and fitness of the currency, and the first data is data used in the identification process.
3. A system according to claim 2, wherein the first data includes a threshold value that is compared with a detection value detected from the currency in the identification process.
4. A system as claimed in any one of claims 1 to 3, wherein the secure processing includes an encryption process using a first key, the currency processing device further comprises a memory unit that stores a second key that is common to the first key, and the decryption unit uses the second key to decrypt the second data into the first data.
5. A system as claimed in any one of claims 1 to 4, wherein the secure processing includes an electronic signature process for generating an electronic signature for the first data using a third key, the second data includes the electronic signature, the currency processing device further includes a memory unit for storing a fourth key that pairs with the third key, the decryption unit decrypts the first data and the electronic signature from the second data, and determines whether the integrity of the decrypted first data is guaranteed using the decrypted first data, the decrypted electronic signature, and the fourth key, and the installation unit installs the first data into the currency processing device if the integrity of the decrypted first data is guaranteed.
6. A system as claimed in claim 4 or 5, wherein the storage unit is at least one of a memory in a safe provided in the currency processing device and a TPM (Trusted Platform Module).
7. A system as described in any one of claims 1 to 6, further comprising the server device, wherein the server device comprises: a data receiving unit that receives the first data from the maintenance terminal used for maintaining the currency processing device; a secure processing unit that applies the secure processing to the first data to generate the second data; and a first transmitting unit that transmits the second data to the maintenance terminal.
8. A system as described in claim 7, wherein the server device further comprises: an authentication information receiving unit that receives, from the maintenance terminal, maintenance staff authentication information for authenticating a maintenance staff member who will be performing maintenance on the currency processing device using the maintenance terminal; and an authentication control unit that controls authentication of the maintenance staff using the maintenance staff authentication information and a first authentication service provided on a second cloud different from the first cloud; and the secure processing unit generates the second data if authentication of the maintenance staff is successful.
9. A system as described in claim 8, wherein the server device further includes a key storage unit that stores a key, the secure processing unit performs the secure processing on the first data using the key, and the first authentication service is an authentication service that uses a maintenance personnel database managed within the second cloud.
10. A system as described in claim 9, wherein the key includes a first key that is common to a second key managed by the currency processing device, and the secure processing includes an encryption process that performs encryption using the first key.
11. A system as described in claim 9 or 10, wherein the key includes a third key that pairs with a fourth key managed by the currency processing device, the secure processing includes an electronic signature process that generates an electronic signature of the first data using the third key, and the second data includes the electronic signature.
12. A system according to any one of claims 9 to 11, wherein the authentication information receiving unit further receives, from a management terminal used to manage the keys, administrator authentication information for authenticating an administrator using the management terminal, and the authentication control unit controls authentication of the administrator using a second authentication service, which is an authentication service using the administrator authentication information and an administrator database managed within the second cloud.
13. A system as described in claim 12, wherein the maintenance staff authentication information and the administrator authentication information include first authentication information, the first authentication information included in the maintenance staff authentication information is information that identifies the maintenance staff, and the first authentication information included in the administrator authentication information is information that identifies the administrator, and the authentication control unit determines whether the first authentication service or the second authentication service will be used for authentication based on the first authentication information.
14. A system as described in claim 13, wherein, when the authentication control unit decides to use the second authentication service for authentication, it controls authentication of whether the administrator has key management authority using the first authentication information and the second authentication service included in the administrator authentication information.
15. A system as described in claim 13 or 14, wherein the maintenance personnel authentication information is information that identifies the maintenance personnel and further includes second authentication information different from the first authentication information, and when the authentication control unit decides to use the first authentication service for authentication, it uses the second authentication information and the first authentication service to control authentication of whether the maintenance personnel has maintenance authority over the currency processing device.
16. A system as described in claim 15, wherein the maintenance personnel authentication information is information for identifying the maintenance personnel and further includes third authentication information different from the first authentication information and the second authentication information, and the authentication control unit further controls authentication of the legitimacy of the maintenance personnel using the third authentication information.
17. A system as described in claim 16, further comprising the maintenance terminal, wherein the maintenance terminal comprises: an authentication unit that authenticates the legitimacy of the maintenance personnel using a hardware key held by the maintenance personnel; and a second transmission unit that transmits the maintenance personnel authentication information to the server device if the authentication is successful.
18. A system as described in claim 16 or 17, wherein the second authentication information is information identifying a hardware key held by the maintenance personnel, and the third authentication information is a one-time password based on the hardware key held by the maintenance personnel.
19. A system as described in claim 18, wherein the authentication control unit issues a JWT (JSON Web Token) when the legitimacy of the maintenance personnel and the maintenance authority are authenticated; the first transmission unit transmits the JWT to the maintenance terminal; the data receiving unit receives the first data and the JWT from the maintenance terminal; and the secure processing unit authenticates the JWT and determines whether or not the secure processing can be performed on the first data.
20. A server device that provides secure processing services on a first cloud, comprising: a data receiving unit that receives first data to be installed in a currency processing device from a maintenance terminal used for maintaining the currency processing device; a secure processing unit that performs secure processing on the first data to generate second data; and a transmitting unit that transmits the second data to the maintenance terminal.
21. A server device as described in claim 20, further comprising: an authentication information receiving unit that receives, from the maintenance terminal, maintenance staff authentication information for authenticating a maintenance staff member who will be performing maintenance on the currency processing device using the maintenance terminal; and an authentication control unit that controls authentication of the maintenance staff using the maintenance staff authentication information and a first authentication service provided on a second cloud different from the first cloud, wherein the secure processing unit generates the second data if authentication of the maintenance staff is successful.
22. A server device as described in claim 21, further comprising a key storage unit for storing a key, wherein the secure processing unit performs the secure processing on the first data using the key, and the first authentication service is an authentication service using a maintenance personnel database managed within the second cloud.
23. A server device as described in claim 22, wherein the key includes a first key that is common to a second key managed by the currency processing device, and the secure processing includes an encryption process that performs encryption using the first key.
24. A server device as described in claim 22 or 23, wherein the key includes a third key that pairs with a fourth key managed by the currency processing device, the secure processing includes an electronic signature process that generates an electronic signature for the first data using the third key, and the second data includes the electronic signature.
25. A server device as described in any one of claims 22 to 24, wherein the authentication information receiving unit further receives, from a management terminal used to manage the keys, administrator authentication information for authenticating an administrator using the management terminal, and the authentication control unit controls authentication of the administrator using a second authentication service, which is an authentication service using the administrator authentication information and an administrator database managed within the second cloud.
26. A server device as described in claim 25, wherein the maintenance staff authentication information and the administrator authentication information include first authentication information, the first authentication information included in the maintenance staff authentication information is information that identifies the maintenance staff, and the first authentication information included in the administrator authentication information is information that identifies the administrator, and the authentication control unit determines whether the first authentication service or the second authentication service will be used for authentication based on the first authentication information.
27. A server device as described in claim 26, wherein, when the authentication control unit determines to use the second authentication service for authentication, it controls authentication of whether the administrator has key management authority using the first authentication information and the second authentication service included in the administrator authentication information.
28. A server device as described in claim 26 or 27, wherein the maintenance personnel authentication information is information that identifies the maintenance personnel and further includes second authentication information different from the first authentication information, and when the authentication control unit decides to use the first authentication service for authentication, it uses the second authentication information and the first authentication service to control authentication of whether the maintenance personnel has maintenance authority over the currency processing device.
29. A server device as described in claim 28, wherein the maintenance personnel authentication information is information for identifying the maintenance personnel and further includes third authentication information different from the first authentication information and the second authentication information, and the authentication control unit further controls authentication of the legitimacy of the maintenance personnel using the third authentication information.
30. A server device as described in claim 29, wherein the second authentication information is information identifying a hardware key possessed by the maintenance personnel, and the third authentication information is a one-time password based on the hardware key possessed by the maintenance personnel.
31. A server device as described in claim 30, wherein the authentication control unit issues a JWT (JSON Web Token) when the legitimacy of the maintenance personnel and the maintenance authority are authenticated; the first transmission unit transmits the JWT to the maintenance terminal; the data receiving unit receives the first data and the JWT from the maintenance terminal; and the secure processing unit determines whether or not to perform the secure processing on the first data based on the JWT.
32. An installation method executed in a currency processing device that processes currency, comprising: a receiving step in which the server device receives second data obtained by performing secure processing on first data to be installed in the currency processing device via a maintenance terminal that transmits the first data to a server device that provides a secure processing service on a first cloud; a decryption step in which the second data is decrypted into the first data; and an installation step in which the decrypted first data is installed in the currency processing device.
33. A secure method executed on a server device that provides secure processing services on a first cloud, comprising: a data receiving step of receiving first data to be installed in a currency processing device from a maintenance terminal used for maintaining the currency processing device; a secure processing step of performing secure processing on the first data to generate second data; and a transmission step of transmitting the second data to the maintenance terminal.
34. A program executed by a currency processing device that processes currency, which causes a computer of the currency processing device to execute the following steps: a receiving step in which first data installed in the currency processing device is transmitted to a server device that provides a secure processing service on a first cloud, and the server device receives second data that has been securely processed from the first data; a decryption step in which the second data is decrypted into the first data; and an installation step in which the decrypted first data is installed in the currency processing device.
35. A program executed on a server device that provides secure processing services on a first cloud, the program causing a computer of the server device to execute the following steps: a data receiving step of receiving first data to be installed in the currency processing device from a maintenance terminal used for maintaining the currency processing device; a secure processing step of performing secure processing on the first data to generate second data; and a transmission step of transmitting the second data to the maintenance terminal.
Citation Information
Patent Citations
Paper sheet processing system
JP2005339049A
Authentication device, electronic equipment, and program for authentication
JP2007316694A
Program updating system for money identification device, and program updating method for money identification device
JP2011014080A
Systems and methods for secure software updates
JP2014505318A
Digital signature terminal and secure communication method
US20210385093A1