Device and value exchange method
Patent Information
- Application Number
- PCT/JP2025/012772
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2026-10-01
Smart Images

Figure JP2025012772_01102026_PF_FP_ABST
Abstract
Description
Apparatus and method of value exchange
[0001] This invention relates to a technology for exchanging value between entities.
[0002] The Fair-Exchange (FE) protocol is a protocol for the fair exchange of value between multiple parties. To maintain fairness, a trusted third party (TTP) is necessary, and the TTP acts as an arbitrator in the event of a dispute between parties. Within the FE protocol, the one that minimizes interaction with the TTP is called the Optimistic Fair-Exchange (OFE) protocol.
[0003] Non-patent document 1 discloses an OFE protocol (hereinafter referred to as the multi-value OFE protocol) that allows the exchange of multiple values in a single transaction, intended for use on smartphones. The advantages of the multi-value OFE protocol include the ability to exchange multiple values in a single transaction and the elimination of the need to issue deletion certificates all at once.
[0004] Misato Nakabayashi, Tetsuya Okuda, "Optimistic Fair Exchange Protocol for Smartphone Environments," Multimedia, Distributed, Cooperative and Mobile (DICOMO2024) Symposium.
[0005] However, the multi-value version of the OFE protocol had the potential to fail to meet certain security requirements depending on the implementation method.
[0006] This invention has been made in view of the above points, and aims to provide a highly secure value exchange technology that allows for the exchange of multiple values in a single transaction and does not require the issuance of deletion certificates all at once.
[0007] According to the disclosed technology, a system is provided comprising a first device having a plurality of first values and a second device having a plurality of second values, wherein the device functions as the first device, the device comprising a secure unit and a processing unit, the secure unit generating a random number and a signature for a transaction ID, the processing unit sending a message to the second device, which includes the random number and the signature and proposes exchanging the plurality of first values for the plurality of second values, the processing unit receiving a deletion certificate from the second device certifying that the plurality of second values have been deleted, and the secure unit deleting the plurality of first values from the processing unit and storing the plurality of second values in the processing unit.
[0008] The disclosed technology provides a highly secure method for value exchange that allows multiple values to be exchanged in a single transaction, eliminating the need to issue a deletion certificate at once.
[0009] This is a diagram illustrating the system configuration in an embodiment of the present invention. This diagram illustrates the operation of the SE. This diagram illustrates the basic protocol. This diagram illustrates the Resolution protocol. This diagram shows an example of the hardware configuration of the device.
[0010] Hereinafter, embodiments of the present invention (this embodiment) will be described with reference to the drawings. The embodiments described below are merely examples, and the embodiments to which the present invention is applied are not limited to the embodiments described below.
[0011] In this embodiment, considering the exchange of value on smartphones and the like, it is desirable to be able to exchange multiple values in a single transaction. Therefore, we will describe a highly secure OFE protocol that allows the exchange of multiple values in a single transaction and does not require the issuance of deletion certificates all at once.
[0012] (Regarding security) The security of the OFE protocol will be explained in detail. Here, we will focus on the security of the following two OFE protocols.
[0013] Fairness: When the protocol ends, one of the following two conditions must be met: (1) The exchange was performed correctly, and each value is stored in the correct party's terminal. (2) No exchange was performed, and each value is stored in the same party's terminal as before the protocol started.
[0014] Exchange Agreement: If the protocol ends in the state described in (1) above, then an agreement regarding the exchange must have been reached between the parties in advance.
[0015] The above explains "fairness" and "agreement on exchange." In the multi-value OFE protocol disclosed in Non-Patent Document 1, if we consider environments where, for example, random number generation is not performed correctly, or if a party can falsely claim to possess a value that they do not, it could lead to the aforementioned security threats. Therefore, in order to ensure security, it was necessary to implement the protocol with careful consideration.
[0016] This embodiment proposes an OFE protocol that covers security solely through the protocol itself, minimizing implementation-level coverage as much as possible. The system configuration and operation of this OFE protocol are described below.
[0017] (System Configuration Example) This embodiment proposes a highly secure OFE protocol that allows for the exchange of multiple values in a single transaction and does not require the issuance of deletion certificates all at once. Specifically, the basic protocol and the resolve protocol will be described. An example of the system configuration in which these protocols are executed is shown in Figure 1. The basic protocol and the resolve protocol may be collectively referred to as the OFE protocol.
[0018] As shown in Figure 1, this system has a terminal 100A of Party A (sometimes referred to as A), a terminal 100B of Party B (sometimes referred to as B), and a TTP 200. A "terminal" may also be referred to as an entity or a party. A terminal is, for example, a smartphone.
[0019] Terminals 100A and 100B exchange their respective multiple values using a basic protocol. However, Party A and Party B may engage in fraudulent activities on their respective terminals. Fraudulent activities include, for example, stopping the protocol midway or sending unauthorized messages.
[0020] In this embodiment, n values vA1, vA2, ..., vAn held by terminal 100A are exchanged with m values vB1, vB2, ..., vBm held by terminal 100B. Note that vA1, vA2, ..., vAn are V A1 , V A2 , ..., V An It is also acceptable to write it as follows. Also, vB1, vB2, ..., vBm are V B1 , V B2 , ..., V Bm It can also be written as follows.
[0021] TTP200 is a trusted third party. More specifically, TTP200 is a device (such as a server or computer) owned by a third party. TTP200 only performs legitimate operations, but retains the information obtained during those operations (referred to as semi-honest TTP). Furthermore, TTP200 only goes online during mediation. TTP200 may also be configured to have a table that manages resolved TIDs.
[0022] As shown in Figure 1, terminal 100A includes an observer A (OA110A) and a secure element A (SEA120A). SEA120A performs functions such as storing value in the terminal (specifically the observer), deleting value from the terminal (specifically the observer), and generating secure random numbers. Note that, as shown in Figure 1, the secure element may be called the secure unit and the observer may be called the processing unit.
[0023] OA110A is a functional unit implemented by a value exchange application installed on terminal 100A. SEA120A is a secure element installed on terminal 100A. SEA120A accepts signature requests only from OA110A and affixes a signature to operations performed by OA110A.
[0024] Furthermore, OA110A has DB111A. DB111A is, for example, non-volatile memory. DB111A may also be called a storage unit. In addition to DB111A (non-volatile memory), OA110A has volatile memory.
[0025] Terminal 100B includes an observer B (OB110B) and a secure element B (SEB120B).
[0026] OB110B is a functional unit implemented by a value exchange application installed on terminal 100B. SEB120B is a secure element installed on terminal 100B. SEB120B accepts signature requests only from OB110B and signs operations performed by OB110B. SEB120B also performs tasks such as storing value in terminals (specifically observers), deleting value from terminals (specifically observers), and generating secure random numbers.
[0027] Furthermore, OB110B has DB111B. DB111B is, for example, non-volatile memory. DB111B may also be called a storage unit. OA110B has volatile memory in addition to DB111B (non-volatile memory).
[0028] The value exchange applications (OA, OB) for terminals 100A and 100B mentioned above are envisioned to be payment and authentication applications that run on mobile TEE, such as Trustzone®. However, the value exchange application is not limited to payment and authentication applications that run on mobile TEE.
[0029] Furthermore, SEA120A and SEB120B are assumed to be secure elements on their respective terminals (e.g., smartphones) (connecting with OA and OB respectively). However, they are not limited to being used as secure elements in the form of SEA120A and SEB120B.
[0030] The communication method between terminals 100 can be any method. For example, the communication method may be wireless LAN, short-range wireless communication, or any other method. Similarly, the communication method between terminal 100 and TTP 200 can be any method, but in this embodiment, it is assumed that the communication method is the Internet.
[0031] As shown in Figure 1, OA110A and SEA120A are connected via an authenticated channel. Similarly, OB110B and SEB120B are connected via an authenticated channel. An authenticated channel is a channel where "eavesdropping is possible, tampering is impossible, and TTP eavesdropping is impossible."
[0032] Terminals 100A and 100B are connected via a normal channel. The normal channel is a channel where "eavesdropping is possible, tampering is possible, and TTP eavesdropping is impossible."
[0033] The connection between TPP200 and terminals 100A / 100B is normally via a TPP leak channel. The TPP leak channel is a channel where "eavesdropping is possible, tampering is possible, and TPP eavesdropping is possible."
[0034] The use of the channels described above is just one example. The technology according to this embodiment is not limited to the use of such channels.
[0035] Here, we will use terminal 100A as an example to explain the functions of OA110A and SEA120A in more detail. The same applies to OB110B and SEB120B in terminal 100B.
[0036] First, let's explain SEA120A. When SEA120A receives a request from OA110A to sign a message, it signs the message and returns it to OA110A. In this embodiment, we assume that the message represents an action performed by OA110A, and that "if SEA120A signs a message m that represents an action on OA110A, then m must have been performed on OA110A."
[0037] For example, in the example shown in Figure 2, when "deletion of vA" is performed on OA110A at 1 / 18 16:30, SEA120A signs the message m, which is "1 / 18 16:30 vA deleted". Note that if vA is not actually deleted, the signature will not be performed.
[0038] While the protocol is running, the SEA120A maintains its operating state. In other words, even if the power is suddenly turned off, the protocol state is retained and can be restarted later.
[0039] Next, I will explain OA110A. OA110A runs applications in an isolated environment. Tampering with these applications is impossible. In addition, OA110A can verify signatures provided by SEB120B.
[0040] (Outline of the Protocol) An overview of the protocol executed in the system described above will be explained. As previously stated, the protocol in this embodiment has a basic protocol and a resolve protocol. In the following description, terminals may be referred to as "parties".
[0041] Terminals 100A and 100B exchange their respective multiple values using a basic protocol. Each terminal 100A and 100B can activate the Resolution protocol only during the period when it is available while the protocol is running.
[0042] If the Resolve protocol is invoked within the activation period, the protocol will be forcibly completed by TTP200.
[0043] During protocol execution, a push is made from TTP200 as a server push. A terminal that receives the server push may return an acknowledgment to TTP200 as an acknowledgment.
[0044] The communication between terminal 100A and terminal 100B may be face-to-face communication or non-face-to-face communication. Furthermore, while this embodiment shows an example where the protocol is executed between terminal 100A and terminal 100B, it is not limited to this. The protocol described in this embodiment may be executed between three or more parties.
[0045] Furthermore, the entity executing the protocol in this embodiment is not limited to a terminal equipped with a SE. For example, a server equipped with an HSM (Hardware Security Module) may execute the protocol in this embodiment.
[0046] Note that both the server and the terminal are examples of "entities." Also, both the SE and HSM may be called the secure section. Furthermore, as mentioned above, the observer (the functional section using the value exchange application) may be called the processing section. Also, terminals 100A, 100B, and TTP200 may be called the first device, second device, and third device, respectively.
[0047] Furthermore, in this embodiment, the following execution environment may be assumed in order to ensure the security of the protocol.
[0048] Notifications from TTP200 are sent via server push, and the notification arrives when the party (terminal) comes online. The nonce is generated within the secure element. The observer also deletes the deletion certificate after the protocol ends. Furthermore, if there is no interaction for a certain period of time, the protocol times out and terminates.
[0049] The following provides a detailed explanation of both the basic protocol and the Resolution protocol.
[0050] (Basic Protocol) The basic protocol executed in the system shown in Figure 1 will be explained with reference to the sequence diagram shown in Figure 3.
[0051] As public information for the execution of the basic protocol, the user ID of terminal 100A and the user ID of terminal 100B are published as A and B respectively, and the signature verification key (public key) is published as spk (each party securely shares this information). That is, spk P is the signature verification key of P. Further, ssk P is the signing private key of P. More specifically, spk A is the signature verification key of A, and spk B is the signature verification key of B. n A , n B are random numbers, respectively.
[0052] For each value v, let DelID v = H(v, n A , H(n B )). DelID A and DelID B are as follows, respectively.
[0053] DelID A = DelID vA1 , ..., DelID vAn DelID B = DelID vB1 , ..., DelID vBm Further, AgrSig A and AgrSig B are as follows, respectively.
[0054] AgrSig A = sign(TID, ssk SEA ) AgrSig B = sign(TID, ssk SEB ) TID, which is the transaction ID, is as follows.
[0055] TID = <DelID A , DelID B , A, B, n A , H(n B )> The signature for each message m sent by party P is as follows.
[0056] msig m = sign(m, ssk P) Note that the message signature itself is not included in the target m. "sign(m, ssk P ) is the private key ssk for m P This is a signature using [a specific method / technique].
[0057] V A , V B These are as follows:
[0058] V A = V A1 , V A2 , ..., V An V B = V B1 , V B2 , ..., V Bm Furthermore, for each value v, DelSig v =sign(DelID v ,ssk SE ) In other words, for each value possessed by the party (user P), DelSig v =sign(DelID v ,ssk SEP This is DelID. v private key SSK SEP This is a signature using DelSig. v DelID is assigned to each value in the secure element. v It is created by sending a document and having the person sign it.
[0059] DelSig A = DelSig vA1 , ..., DelSig vAn And DelSig B = DelSig vB1 , ..., DelSig vBm It is. DelSig A This corresponds to the deletion certificate of A, DelSig B This corresponds to the deletion certificate for B.
[0060] Furthermore, as shown in the diagram, a Resolvable interval is set.
[0061] In step 1 (S1) of Figure 3, OA110B in terminal 100B requests SEB120B to generate a random number. In step 2, SEB120B generates a random number nB is generated.
[0062] In S3, SEB 120B obtains "n B , sign(hash(n B ), ssk SEB )" and transmits it to OB 110B. Note that hash(n B ) may also be written as H(n B ).
[0063] In S4, as preparation, OB 110B transmits, as m0 (message 0) to OA 110A, "hash(n B ), sign(hash(n B ), ssk SEB )".
[0064] In S5, OA 110A obtains hash(n B )'s signature sign(hash(n B ), ssk SEB ) and verifies it. In S6, OA 110A transmits "V A , V B , hash(n B )" to SEA 120A.
[0065] In S7, SEA 120A confirms that A holds V A . In S8, SEA 120A generates a random number n A . In S9, SEA 120A calculates a TID.
[0066] In S10, SEA 120A generates AgrSig A and transmits "n A , AgrSig A " to OA 110A.
[0067] In S11, OA 110A proposes a transaction by transmitting m1: "V A , V B , n A , AgrSig A " to OB 110B. This message m1 is a message proposing an exchange of V A and V B .
[0068] In step S12, OB110B confirms the transaction content, calculates TID in step S13, and checks AgrSig A .
[0069] In step S14, OB110B transmits "V A , V B , n A " to SEB120B. In step S15, SEB120B transmits AgrSig A to OB110B.
[0070] In step S16, OB110B requests deletion of V B1 from SEB120B. In step S17, SEB120B deletes V B1 from OB110B. In step S18, SEB120B returns DelSig vB1 to OB110B. The same process is repeated.
[0071] In step S19, OB110B requests deletion of V Bm from SEB120B. In step S20, SEB120B deletes V Bm from OB110B. In step S21, SEB120B returns DelSig vBm to OB110B.
[0072] In step S22, OB110B accepts the proposal by transmitting m2: "TID, DelSig B , AgrSig B , mSig m2 " to OA110A.
[0073] In step S23, OA110A confirms the signature mSig of m2 m2 , confirms TID and AgrSig in step S24 B , and confirms DelSig in step S25 B . It is assumed that all these confirmations (verifications) are successful.
[0074] In step S26, OA110A requests deletion of V A1 from SEA120A. In step S27, SEA120A deletes V from OA110AA1 Delete. In S28, SEA120A is DelSig vA1 The result is returned to OA110A. The same process is repeated.
[0075] In S29, OA110A is V relative to SEA120A. Am Request the deletion of . In S30, SEA120A is V Am Delete. In S31, SEA120A is DelSig vAm Return it to OA110A.
[0076] In S32, OA110A communicates m3: "TID, DelSig" to OB110B. A ,msig m3 Sending this message confirms receipt.
[0077] OA110B is signed m3 msig in S33 m3 Confirmation, confirm TID in S34, and in S35, DelSig A Verify these points. Assume these verifications (verifications) were successful.
[0078] In S36, OB110B is V relative to SEB120B. A Requests storage of. In S37, SEB120B sends V to OB110B. A Store it.
[0079] In S38, OB110B has a ratio of m4:n with respect to OA110A. B The transaction is confirmed by sending the following. In S39, OA110A is n B The TID is checked using this method. If the check is successful, in S40, OA110A will V B Requests storage of. In S41, SEA120A sends V to OA110A. B Store it.
[0080] <Key Points of the Basic Protocol> Here, we will explain the key points of the basic protocol for solving the problem.
[0081] Point 1: As shown in S8, etc., random numbers are generated within the secure element, thus preventing the reuse or unauthorized generation of random numbers.
[0082] Point 2: As shown in S10, etc., since the creation of AgrSig, i.e., the signing of the TID, is performed by the secure element, the random number used as the hash source when generating the TID is guaranteed by both secure elements, making it possible to prevent tampering with the random number by the party.
[0083] Point 3: As shown in S17, etc., since the secure element handles the storage and deletion of value, it becomes possible to increase the reliability of the value held by the party, as well as the TID and deletion certificate generated based on it.
[0084] (Resolve Protocol) Next, the resolve protocol will be explained with reference to the sequence diagram in Figure 4. The resolve protocol is a protocol for forcing the completion of a transaction. Here, as an example, we will explain the case in which A makes a claim to B (a claim requesting that the transaction be completed).
[0085] TTP200 holds a resolved TID management table. In S101, terminal 100A (OA110A) communicates to TTP200: mr1:<"resolve", A, B, TID, DelSig A , AgrSig B ,msig mr1 Sending > requests the completion of the transaction.
[0086] TTP200 verifies the signature of mr1 in S102 and AgrSig in S103 B The signature is verified. Also, in S104, TTP200 checks the DelID within the TID. A All corresponding deletion certificates are DelSig A Check if it is included, and in S105, DelSig A The signatures are verified, and if these verifications are successful, proceed to S106.
[0087] In S106, TTP200 communicates to OA110A: mr2: <"allow resolve", TID, msig mr2 Sending > authorizes the completion of the transaction.
[0088] In S107, at terminal 100A, SEA120A performs V B This is stored in OA110A. S107 is an action that TTP200 forces on terminal 100A.
[0089] Furthermore, in S108, TTP200 sends a Solve notification to terminal 100B as a server push. The Solve notification is a notification indicating that the transaction has been completed.
[0090] Terminal 100B is V B If you haven't deleted it, then from OB110B to V B Delete (S109) and set V to OB110B A Store (S110).
[0091] (Regarding Use Cases) The application of the protocol group according to this embodiment is not limited to a specific field, but examples of application include e-commerce, PvP payments, DvP payments, and currency exchange. Furthermore, it is possible to handle multiple values from different issuers uniformly within a single transaction.
[0092] (Hardware Configuration Example) Any of the devices described in this embodiment (terminals 100A / 100B, TTP200) can be realized, for example, by having a computer run a program. This computer may be a physical computer or a virtual machine on the cloud.
[0093] In other words, the device can be realized by using hardware resources such as the CPU and memory built into a computer to execute a program corresponding to the processing performed by the device. The program can be recorded on a computer-readable recording medium (such as portable memory), saved, and distributed. It can also be provided via a network, such as the Internet or email.
[0094] Figure 5 shows an example of the hardware configuration of the computer described above. The computer in Figure 5 has a drive device 1000, an auxiliary storage device 1002, a memory device 1003, a CPU 1004, an interface device 1005, a display device 1006, an input device 1007, an output device 1008, etc., all of which are interconnected by bus B. The computer may also be equipped with a GPU.
[0095] The program that enables processing on the computer is provided on a recording medium 1001, such as a CD-ROM or memory card. When the recording medium 1001 containing the program is set in the drive device 1000, the program is installed from the recording medium 1001 to the auxiliary storage device 1002 via the drive device 1000. However, the program does not necessarily have to be installed from the recording medium 1001; it may also be downloaded from another computer via a network. The auxiliary storage device 1002 stores the installed program as well as necessary files and data.
[0096] The memory device 1003 reads and stores a program from the auxiliary storage device 1002 when a program startup command is received. The CPU 1004 implements the functions related to the memory device 1003 according to the program stored in the memory device 1003. The interface device 1005 is used as an interface for connecting to a network, etc. The display device 1006 displays a GUI (Graphical User Interface) etc., based on a program. The input device 1007 consists of a keyboard and mouse, buttons, or a touch panel, etc., and is used to input various operation commands. The output device 1008 outputs the calculation results.
[0097] Furthermore, the functions of the elements disclosed herein may be implemented using circuits or processing circuitry that include general-purpose processors, special-purpose processors, integrated circuits, ASICs (Application Specific Integrated Circuits), FPGAs (Field Programmable Gate Arrays), conventional circuits, and / or combinations thereof that are programmed using one or more programs stored in one or more memories, or otherwise configured to perform the disclosed functions. A processor is considered processing circuitry or circuitry because it includes transistors and other circuits. A processor may be a programmed processor that executes programs stored in memory. In this disclosure, a circuit, unit, or means is hardware that performs the enumerated functions, or hardware programmed to perform the enumerated functions. Hardware may be any hardware disclosed herein that is programmed or configured to perform the enumerated functions.
[0098] The system includes memory for storing computer programs, which include computer instructions. These computer instructions provide logic and routines that enable hardware (e.g., processing circuitry or circuitry) to perform the methods disclosed herein. The computer programs can be implemented in commonly known forms, such as computer-readable storage media, computer program products, memory devices, recording media such as CD-ROMs and DVDs, and / or memory in FPGAs and ASICs.
[0099] (Effects of the Embodiment) By using the protocol described in this embodiment, multiple values can be exchanged in a single transaction using a single terminal (e.g., a smartphone) while maintaining a high level of security.
[0100] Furthermore, because the protocol in this embodiment has high security as a protocol, it requires less ingenuity during implementation compared to the conventional multi-value OFE protocol.
[0101] Furthermore, in this embodiment, following the conventional method, a deletion certificate is designed to be created for each value, so that even if the format and storage method of the value differ, they can be handled uniformly within a single transaction.
[0102] The following additional information is disclosed regarding the embodiments described above.
[0103] <Notes> (Note 1) In a system comprising a first device having a plurality of first values and a second device having a plurality of second values, the device functions as the first device, wherein the device comprises a secure unit and a processing unit, the secure unit generates a random number and generates a signature for a transaction ID, the processing unit sends a message to the second device, which includes the random number and the signature, proposing to exchange the plurality of first values for the plurality of second values, the processing unit receives a deletion certificate from the second device proving that the plurality of second values have been deleted, and the secure unit deletes the plurality of first values from the processing unit and stores the plurality of second values in the processing unit. (Note 2) The device according to Note 1, wherein the transaction ID includes the hash value of the random number generated by the secure unit of the second device. (Appendix 3) In a system comprising a first device having a plurality of first values and a second device having a plurality of second values, a device that functions as the second device, the device comprising a secure unit and a processing unit, the secure unit generating a second random number, the processing unit transmitting a first message including the second random number to the first device, the processing unit receiving a second message from the first device, which includes the first random number generated by the first device and a signature for a transaction ID including the hash value of the second random number, proposing to exchange the plurality of first values for the plurality of second values, and the secure unit deleting the plurality of second values from the processing unit and storing the plurality of first values in the processing unit.(Appendix 4) A value exchange method performed by a device functioning as the first device in a system comprising a first device having a plurality of first values and a second device having a plurality of second values, wherein the device comprises a secure unit and a processing unit, the secure unit generates a random number and generates a signature for a transaction ID, the processing unit sends a message to the second device, which includes the random number and the signature, proposing to exchange the plurality of first values and the plurality of second values, the second device receives a deletion certificate from the second device proving that the plurality of second values have been deleted, and the secure unit deletes the plurality of first values from the processing unit and stores the plurality of second values in the processing unit.
[0104] Although this embodiment has been described above, the present invention is not limited to this specific embodiment, and various modifications and changes are possible within the scope of the gist of the invention as described in the claims.
[0105] 100A, 100B Terminal 110A OA 110B OB 111A, 111B DB 120A SEA 120B SEB 200 TTP 1000 Drive device 1001 Recording medium 1002 Auxiliary storage device 1003 Memory device 1004 CPU 1005 Interface device 1006 Display device 1007 Input device 1008 Output device
Claims
1. In a system comprising a first device having a plurality of first values and a second device having a plurality of second values, the device functions as the first device, wherein the device comprises a secure unit and a processing unit, the secure unit generates a random number and generates a signature for a transaction ID, the processing unit sends a message to the second device, which includes the random number and the signature, proposing to exchange the plurality of first values and the plurality of second values, the processing unit receives a deletion certificate from the second device certifying that the plurality of second values have been deleted, and the secure unit deletes the plurality of first values from the processing unit and stores the plurality of second values in the processing unit.
2. The apparatus according to claim 1, wherein the transaction ID includes a hash value of a random number generated by the secure unit of the second apparatus.
3. In a system comprising a first device having a plurality of first values and a second device having a plurality of second values, the device functions as the second device, wherein the device comprises a secure unit and a processing unit, the secure unit generates a second random number, the processing unit transmits a first message including the second random number to the first device, the device receives a second message from the first device, which includes the first random number generated by the first device and a signature for a transaction ID including the hash value of the second random number, proposing to exchange the plurality of first values for the plurality of second values, and the secure unit deletes the plurality of second values from the processing unit and stores the plurality of first values in the processing unit.
4. A value exchange method performed by a device functioning as the first device in a system comprising a first device having a plurality of first values and a second device having a plurality of second values, wherein the device comprises a secure unit and a processing unit, the secure unit generates a random number and generates a signature for a transaction ID, the processing unit sends a message to the second device, which includes the random number and the signature, proposing to exchange the plurality of first values and the plurality of second values, the processing unit receives a deletion certificate from the second device proving that the plurality of second values have been deleted, and the secure unit deletes the plurality of first values from the processing unit and stores the plurality of second values in the processing unit.