Information Processing Apparatus for Secure Cryptographic Operations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic money systems face challenges in performing cryptographic operations across different environments securely, particularly when a tamper-resistant module is used, as it restricts flexible operations from apparatuses in environments other than its own, leading to potential fraudulent activities.

Innovation Solution

An information processing apparatus and method that manages types of cryptographic processing requests and performs authorized operations, allowing secure cryptographic processing even across different environments by authenticating and managing access to integrated circuit chips.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a tamper-resistant module is used to ensure security, then security is improved, but flexibility of operations from apparatuses in different environments deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility of operations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a server as an intermediary between the tamper-resistant module and external apparatuses. The server receives requests from apparatuses in different environments, authenticates them, and forwards authorized requests to the tamper-resistant module. This mediator enables secure cryptographic operations across diverse environments without compromising the security isolation of the tamper-resistant module.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server is designed to handle requests from multiple types of apparatuses (mobile phones, personal computers, other terminals) and perform various cryptographic operations (encryption, decryption, key management). This universal interface allows the tamper-resistant module to serve diverse clients while maintaining its security properties.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If cryptographic processing is restricted to same-environment apparatuses, then security is improved, but adaptability to different environments deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability to different environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The server acts as a trusted intermediary that bridges the gap between different environments and the tamper-resistant module. It authenticates requests from various environments and forwards them appropriately, enabling the system to adapt to different client types while maintaining security through the server's authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access control is tightened to prevent fraudulent activities, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The server handles the complex authentication and access control logic centrally. From the perspective of client apparatuses, the operation remains simple (just send a request to the server), while the server performs the necessary security checks, key authentication, and request forwarding. This separates the simplicity of client operations from the complexity of security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7707225B2Information processing apparatus, information processing method, and program
Publication Date: 2010.04.27 FELICA NETWORKS INC
  • US7707225B2 patent drawing
  • US7707225B2 patent drawing
  • US7707225B2 patent drawing

AI summary

An information processing apparatus configured to perform cryptographic processing in response to a request from a server transmitting encrypted information to control an integrated circuit chip includes a managing unit managing types of the cryptographic processing granted in accordance with requests; and an output unit performing predetermined cryptographic processing requested from a predetermined server succeeding in authentication, when the requested predetermined cryptographic processing has a granted type managed by the managing unit, to supply information concerning the processing result to the predetermined server as information to be transmitted to the integrated circuit chip to be controlled.