Sign In to Follow Application
View All Documents & Correspondence

Information Processing Device, Information Processing Method, Program, And Information Processing System

Abstract: [Problem] To provide an information processing device, an information processing method, a program, and an information processing system that are capable of ensuring security related to data readout while reducing processing time related to the readout. [Solution] Provided is an information processing device equipped with a processing unit which, upon acquiring a readout request including a data readout command and information indicating a region of a recording medium from which data are to be read out, encrypts data corresponding to the region indicated by the readout request using an encryption key corresponding to the region indicated by the readout request, and causes the encrypted data to be transmitted.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
30 July 2020
Publication Number
38/2020
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
mahua.ray@remfry.com
Parent Application
Patent Number
Legal Status
Grant Date
2024-06-27
Renewal Date

Applicants

SONY CORPORATION
1-7-1, Konan, Minato-ku, Tokyo 1080075

Inventors

1. NAKATSURU, Tsutomu
c/o SONY IMAGING PRODUCTS & SOLUTIONS INC., 1-7-1, Konan, Minato-ku, Tokyo 1080075
2. SHIMOJI, Katsuya
c/o SONY IMAGING PRODUCTS & SOLUTIONS INC., 1-7-1, Konan, Minato-ku, Tokyo 1080075
3. TAKEMURA, Toshiharu
c/o SONY IMAGING PRODUCTS & SOLUTIONS INC., 1-7-1, Konan, Minato-ku, Tokyo 1080075
4. WANG, Yuhu
c/o SONY IMAGING PRODUCTS & SOLUTIONS INC., 1-7-1, Konan, Minato-ku, Tokyo 1080075

Specification

Title of invention: Information processing device, information processing method, program, and information processing system
Technical field
[0001]
 The present disclosure relates to information processing devices, information processing methods, programs, and information processing systems.
Background technology
[0002]
 Technologies have been developed to more efficiently control devices connected via networks. Examples of the above-mentioned technique include the techniques described in Patent Document 1 below.
Prior art literature
Patent documents
[0003]
Patent Document 1: Japanese Unexamined Patent Publication No. 2004-186883
Outline of the invention
Problems to be solved by the invention
[0004]
 For example, when another device reads data stored in one device that requires permission to read, authentication is performed between one device and the other device, and the data is read after the authentication is completed. Is done.
[0005]
 Here, for example, when the technique described in Patent Document 1 is used, a plurality of instructions are collectively transmitted in one communication. Therefore, when the technique described in Patent Document 1 is used, it is possible to reduce the number of communications between devices connected via a network. However, for example, the technique described in Patent Document 1 simply transmits a plurality of transmitted instructions in a single communication. Therefore, for example, even if the technique described in Patent Document 1 is used, "authentication related to reading data that requires authority for reading" cannot be omitted from the viewpoint of safety, and the processing time related to reading cannot be omitted. Is difficult to reduce.
[0006]
 The present disclosure proposes new and improved information processing devices, information processing methods, programs, and information processing systems that can reduce the processing time related to reading while ensuring the safety related to reading data. To do.
Means to solve problems
[0007]
 According to the present disclosure, when a read request including a data read command and information indicating an area of ​​a recording medium for reading the data is acquired, the read request indicates the data corresponding to the area indicated by the read request. Provided is an information processing apparatus including a processing unit that encrypts with an encryption key corresponding to the above area and transmits the encrypted data.
[0008]
 Further, according to the present disclosure, when the acquired encrypted data is decrypted with a predetermined encryption key and the decrypted data is the first identification information, the first identification information is different. An information processing device including a processing unit that converts the identification information into the second identification information and transmits the second identification information to an external device corresponding to the second identification information is provided.
[0009]
 Further, according to the present disclosure, when a read request including a data read instruction and information indicating an area of ​​a recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is requested to be read. An information processing method executed by an information processing apparatus is provided, which comprises a step of encrypting with an encryption key corresponding to the above-mentioned area indicated by the above and a step of transmitting encrypted data.
[0010]
 Further, according to the present disclosure, there is a step of decrypting the acquired encrypted data with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is described above. An information processing method executed by an information processing device, which comprises a step of converting the second identification information into different second identification information and a step of transmitting the second identification information to an external device corresponding to the second identification information. Is provided.
[0011]
 Further, according to the present disclosure, when a read request including a data read command and information indicating an area of ​​a recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is requested to be read. A program for causing a computer to execute a step of encrypting with an encryption key corresponding to the above-mentioned area and a step of transmitting encrypted data are provided.
[0012]
 Further, according to the present disclosure, the step of decrypting the acquired encrypted data with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is used. A program is provided for causing a computer to perform a step of converting into different second identification information and a step of transmitting the second identification information to an external device corresponding to the second identification information.
[0013]
 Further, according to the present disclosure, the first information processing apparatus has a first information processing apparatus and a second information processing apparatus, and the first information processing apparatus includes a data read instruction and a region of a recording medium for reading data. When a read request including the indicated information is acquired, the data corresponding to the area indicated by the read request is encrypted with the encryption key corresponding to the area indicated by the read request, and the encrypted data is transmitted. The second information processing apparatus including a processing unit decrypts the acquired encrypted data with a predetermined encryption key, and when the decrypted data is the first identification information, the first An information processing system is provided that includes a processing unit that converts the identification information of the above into a different second identification information and transmits the second identification information to an external device corresponding to the second identification information.
Effect of the invention
[0014]
 According to the present disclosure, it is possible to reduce the processing time related to reading while ensuring the safety related to reading data.
[0015]
 It should be noted that the above effects are not necessarily limited, and either in combination with or in place of the above effects, any of the effects shown herein, or any other effect that can be ascertained from this specification. May be played.
A brief description of the drawing
[0016]
FIG. 1 is an explanatory diagram showing an example of a configuration of an information processing system according to the present embodiment.
FIG. 2 is a functional block diagram showing an example of the configuration of the information processing device (first information processing device) according to the present embodiment.
FIG. 3 is an explanatory diagram showing an example of a hardware configuration of the information processing device (first information processing device) according to the present embodiment.
FIG. 4 is an explanatory diagram showing an example of the configuration of the IC chip and the antenna shown in FIG.
FIG. 5 is a functional block diagram showing an example of a reader / writer (relay device) configuration according to the present embodiment.
FIG. 6 is an explanatory diagram showing an example of a hardware configuration of a reader / writer (relay device) according to the present embodiment.
FIG. 7 is a functional block diagram showing an example of a configuration of a server (second information processing device) according to the present embodiment.
FIG. 8 is an explanatory diagram showing an example of a hardware configuration of a server (second information processing device) according to the present embodiment.
[Fig. 9] Fig. 9 is an explanatory diagram showing an example of communication related to data reading using authentication by an existing challenge / response method.
FIG. 10 is an explanatory diagram showing an outline of settings defined by the setting information according to the present embodiment.
FIG. 11 is an explanatory diagram showing an example of processing in the information processing system according to the first embodiment.
FIG. 12 is an explanatory diagram showing an example of processing in a reader / writer (relay device) included in the information processing system according to the first embodiment.
FIG. 13 is an explanatory diagram for explaining an example of processing in the information processing system according to the first embodiment.
FIG. 14 is an explanatory diagram for explaining an example of a read request according to the present embodiment.
FIG. 15 is a flow chart showing an example of processing in the information processing apparatus according to the first embodiment.
FIG. 16 is an explanatory diagram showing an example of a case that may occur when it is not possible to specify when the data corresponds to the read request transmitted by the server.
FIG. 17 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus according to the second embodiment.
FIG. 18 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus according to the second embodiment.
FIG. 19 is an explanatory diagram showing an example of processing in the information processing system according to the second embodiment.
FIG. 20 is an explanatory diagram for explaining an example of processing in the information processing system according to the second embodiment.
FIG. 21 is an explanatory diagram showing an example of a case where communication from a reader / writer to an information processing device is tampered with.
FIG. 22 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus according to the third embodiment.
FIG. 23 is an explanatory diagram showing an example of processing in the information processing system according to the third embodiment.
FIG. 24 is an explanatory diagram showing an example of a case where encrypted data transmitted from an information processing device to a reader / writer is observed by a third party.
FIG. 25 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus according to the fourth embodiment.
FIG. 26 is an explanatory diagram showing an example of processing in the information processing system according to the fourth embodiment.
FIG. 27 is an explanatory diagram showing an example of a case in which data transmitted from an information processing device to a reader / writer is observed by a third party and an error is determined to have occurred.
FIG. 28 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus according to the fifth embodiment.
FIG. 29 is an explanatory diagram showing an example of a case where the identification information stored in the information processing apparatus is used by a plurality of businesses.
FIG. 30 is an explanatory diagram showing an example of a use case to which the information processing system according to the sixth embodiment is applied.
FIG. 31 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus according to the sixth embodiment.
FIG. 32 is an explanatory diagram showing an example of processing in the information processing system according to the sixth embodiment.
Mode for carrying out the invention
[0017]
 Preferred embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. In the present specification and the drawings, components having substantially the same functional configuration are designated by the same reference numerals, so that duplicate description will be omitted.
[0018]
 In addition, the following description will be given in the order shown below.
  1. 1. Information processing system according to this embodiment and information processing method according to
  this embodiment [1] Configuration of information processing system according to this embodiment
   [1-1] Information processing device 100 (first information processing device)
   [1 -2] Reader / Writer 200 (relay device)
   [1-3] Server 300 (second information processing device)
   [1-4] Application example of each device constituting the information processing system according to the present embodiment
  [2] Processing related to the information processing method according to the present embodiment
   [2-1] Information processing method according to the first embodiment
   [2-2] Information processing method according to the second embodiment
   [2-3] Third embodiment Information processing method according to
   the fourth embodiment [2-4] Information processing method according to the fourth embodiment
   [2-5] Information processing method according to the fifth embodiment
   [2-6] Information processing according to the sixth embodiment Method
   [2-7] Information processing method according to another embodiment
  2. Program related to this embodiment
[0019]
(Information processing system according to the present embodiment and information processing method according to
 the present embodiment ) Hereinafter, an example of the information processing system according to the present embodiment will be described first, and then applied to the information processing system according to the present embodiment. The information processing method according to the present embodiment will be described by taking a case as an example.
[0020]
[1] Configuration of the information processing system according
 to the present embodiment FIG. 1 is an explanatory diagram showing an example of the configuration of the information processing system 1000 according to the present embodiment. The information processing system 1000 includes, for example, an information processing device 100 (first information processing device), a reader / writer 200 (relay device), and a server 300 (second information processing device).
[0021]
 The configuration of the information processing system according to this embodiment is not limited to the example shown in FIG. For example, the information processing system according to the present embodiment may have a plurality of information processing devices 100. Further, the information processing system according to the present embodiment may have a plurality of readers / writers 200, or may have a plurality of servers 300.
[0022]
 The information processing device 100 and the reader / writer 200 communicate with each other by, for example, near field communication (NFC) such as Type-A, Type-B, or Type-F.
[0023]
 In the information processing system according to the present embodiment, the information processing device 100 and the reader / writer 200 are, for example, wireless communication using IEEE802.5.1 such as "BLE (Bluetooth Low Energy)" or IEEE802.11. By "wireless communication of any communication method such as wireless communication and infrared communication using Bluetooth" or "wired communication using communication via USB (Universal Serial Bus) or communication interface based on ISO7816 standard" Communication may be performed.
[0024]
 The server 300 and the reader / writer 200 are connected wirelessly or by wire via a network, and communicate with each other by communication via the network (hereinafter, referred to as “network communication”). Examples of the network according to the present embodiment include a wired network such as LAN (Local Area Network) and WAN (Wide Area Network), a wireless network such as WLAN (Wireless Local Area Network), or TCP / IP (Transmission Control Protocol). / Internet Protocol) and other communication protocols such as the Internet.
[0025]
 In the information processing system according to the present embodiment, the server 300 and the reader / writer 200 can directly communicate with each other without going through a network.
[0026]
 The server 300 and the information processing device 100 communicate with each other via the reader / writer 200. That is, in the information processing system 1000, the reader / writer 200 serves as a relay device that relays communication between the server 300 and the information processing device 100.
[0027]
 In the information processing system according to the present embodiment, the server 300 and the information processing device 100 can directly communicate with each other without going through the reader / writer 200. When the information processing system according to the present embodiment is "a configuration in which the server 300 and the information processing device 100 directly communicate with each other without going through the reader / writer 200", for example, the server 300 is the reader / writer 200. It may be a configuration having the function of. That is, the information processing system according to the present embodiment does not have to have a device that functions as a relay device such as a reader / writer 200.
[0028]
 In the following, as shown in FIG. 1, "a case where the information processing device 100 and the reader / writer 200 communicate with each other by NFC and the server 300 and the reader / writer 200 communicate with each other by network communication" will be given as an example. .. As described above, the example of communication in the information processing system according to the present embodiment is not limited to the example shown in FIG.
[0029]
[1-1] Information Processing Device 100 (First Information Processing Device)
 FIG. 2 is a functional block diagram showing an example of the configuration of the information processing device 100 (first information processing device) according to the present embodiment.
[0030]
 The information processing device 100 includes, for example, a first communication unit 102, a second communication unit 104, and a control unit 106.
[0031]
 Further, the information processing device 100 is, for example, a ROM (Read Only Memory, not shown), a RAM (Random Access Memory, not shown), or an operation unit (not shown) that can be operated by the user of the information processing device 100. ), A display unit (not shown) that displays various screens on the display screen may be provided. The information processing device 100 connects each of the above components by, for example, a bus as a data transmission path.
[0032]
 The ROM (not shown) stores control data such as programs and calculation parameters used by the control unit 106. The RAM (not shown) temporarily stores a program or the like executed by the control unit 106.
[0033]
 Examples of the operation unit (not shown) include an operation input device shown in a hardware configuration example of the information processing device 100 described later. Further, as a display unit (not shown), a display device shown in a hardware configuration example of the information processing device 100 described later can be mentioned.
[0034]
[Example of Hardware Configuration of Information Processing Device 100]
 FIG. 3 is an explanatory diagram showing an example of a hardware configuration of the information processing device 100 (first information processing device) according to the present embodiment. FIG. 3 shows an example of the hardware configuration of the information processing apparatus 100 when communicating with the reader / writer 200 by NFC.
[0035]
 The information processing device 100 includes, for example, an MPU 150, a ROM 152, a RAM 154, a recording medium 156, an input / output interface 158, an operation input device 160, a display device 162, a communication interface 164, an IC chip 166, and an antenna. It is equipped with 168. Further, the information processing apparatus 100 connects each component by, for example, a bus 170 as a data transmission path. Further, the information processing device 100 is driven by, for example, electric power supplied from an internal power source such as a battery included in the information processing device 100, or electric power supplied from a connected external power source.
[0036]
 The MPU 150 is composed of one or more processors composed of arithmetic circuits such as an MPU (Micro Processing Unit), various processing circuits, and the like, and functions as a control unit 106 that controls the entire information processing apparatus 100. .. Further, the MPU 150 serves as, for example, a processing unit 110 described later in the information processing apparatus 100.
[0037]
 The ROM 152 stores control data such as programs and calculation parameters used by the MPU 150. The RAM 154 temporarily stores, for example, a program executed by the MPU 150.
[0038]
 The recording medium 156 is a recording medium that functions as a storage unit (not shown). The recording medium 156 stores various data such as various applications. Here, examples of the recording medium 156 include a magnetic recording medium such as a hard disk and a non-volatile memory such as a flash memory. Further, the recording medium 156 may be detachable from the information processing device 100.
[0039]
 The input / output interface 158 connects, for example, an operation input device 160 and a display device 162. The operation input device 160 functions as an operation unit (not shown), and the display device 162 functions as a display unit (not shown). Here, examples of the input / output interface 158 include a USB (Universal Serial Bus) terminal, a DVI (Digital Visual Interface) terminal, an HDMI (High-Definition Multimedia Interface) (registered trademark) terminal, and various processing circuits. ..
[0040]
 Further, the operation input device 160 is provided on the information processing device 100, for example, and is connected to the input / output interface 158 inside the information processing device 100. Examples of the operation input device 160 include buttons, direction keys, rotary selectors such as a jog dial, and combinations thereof.
[0041]
 Further, the display device 162 is provided on the information processing device 100, for example, and is connected to the input / output interface 158 inside the information processing device 100. Examples of the display device 162 include a liquid crystal display and an organic EL display.
[0042]
 Needless to say, the input / output interface 158 can be connected to an external device such as an external operation input device (for example, a keyboard or a mouse) or an external display device as an external device of the information processing device 100. No. Further, the display device 162 may be a device capable of displaying and operating the user, such as a touch screen.
[0043]
 The communication interface 164 is a communication means for performing communication of one communication method included in the information processing device 100, and functions as a first communication unit 102. Here, the communication interface 164 includes, for example, a communication antenna and an RF (Radio Frequency) circuit (wireless communication), an IEEE802.5.1 port and a transmission / reception circuit (wireless communication), an IEEE802.11 port and a transmission / reception circuit (wireless communication). ), Or a LAN terminal and a transmission / reception circuit (wired communication).
[0044]
 The IC chip 166 and the antenna 168 are communication means for performing communication of other communication methods included in the information processing device 100, and function as a second communication unit 104. The IC chip 166 and the antenna 168 communicate by NFC with an external device having a reader / writer function such as a reader / writer 200 by a carrier wave having a predetermined frequency such as 13.56 [MHz].
[0045]
 The antenna 168 serves to receive the carrier wave and transmit the response signal. Further, the IC chip 166 demodulates and processes a carrier wave signal transmitted from an external device such as a reader / writer 200 based on the received carrier wave, and transmits a response signal by load modulation.
[0046]
 FIG. 4 is an explanatory diagram showing an example of the configuration of the IC chip 166 and the antenna 168 shown in FIG. The information processing device 100 does not have to include, for example, the configuration of the IC chip 166 shown in FIG. 3 in the form of an IC chip.
[0047]
 The antenna 168 is composed of, for example, a resonance circuit including a coil (inductor) L1 having a predetermined inductance and a capacitor C1 having a predetermined capacitance, and generates an induced voltage by electromagnetic induction in response to reception of a carrier. .. Then, the antenna 168 outputs a reception voltage obtained by resonating the induced voltage at a predetermined resonance frequency. Here, the resonance frequency of the antenna 168 is set according to the frequency of the carrier wave, for example, 13.56 [MHz]. The antenna 168 receives the carrier wave according to the above configuration, and also transmits the response signal by the load modulation performed in the load modulation circuit 182 included in the IC chip 166.
[0048]
 The IC chip 166 includes, for example, a carrier detection circuit 172, a detection circuit 174, a regulator 176, a demodulation circuit 178, an MPU 180, and a load modulation circuit 182. Although not shown in FIG. 4, the IC chip 166 may further include, for example, a protection circuit (not shown) for preventing an overvoltage or an overcurrent from being applied to the MPU 180. Here, examples of the protection circuit (not shown) include a clamp circuit composed of a diode or the like.
[0049]
 Further, the IC chip 166 includes, for example, a ROM 184, a RAM 186, and a non-volatile memory 188. The MPU 180, ROM 184, RAM 186, and non-volatile memory 188 are connected by, for example, a bus 190 as a data transmission line. Further, the bus 190 is connected to the bus 170.
[0050]
 The ROM 184 stores control data such as programs and calculation parameters used by the MPU 180. The RAM 186 temporarily stores the program executed by the MPU 180, the calculation result, the execution state, and the like.
[0051]
 The non-volatile memory 188 is another recording medium that functions as a storage unit (not shown). The non-volatile memory 188 includes, for example, "key information indicating an encryption key used for processing related to arbitrary encryption and decryption in authentication in communication of a communication method such as NFC" and setting information (described later). , Data related to the information processing method in the information processing device 100, electronic value (data having a value equivalent to money or money), arbitrary identification information such as the ID of the information processing device 100 and the ID of the service, and various services. Stores various data such as data to be processed and various applications. Examples of the encryption key indicated by the key information include an encryption key corresponding to an arbitrary encryption method such as a common key encryption method and a public key encryption method. Here, examples of the non-volatile memory 188 include EEPROM (Electrically Erasable and Programmable Read Only Memory) and flash memory. The non-volatile memory 188 is, for example, tamper resistant and corresponds to an example of a secure recording medium.
[0052]
 The carrier detection circuit 172 generates, for example, a rectangular detection signal based on the reception voltage transmitted from the antenna 168, and transmits the detection signal to the MPU 180. Further, the MPU 180 uses the transmitted detection signal as, for example, a processing clock for data processing. Here, since the detection signal is based on the reception voltage transmitted from the antenna 168, it is synchronized with the frequency of the carrier wave transmitted from an external device such as the reader / writer 200. Therefore, by including the carrier detection circuit 172, the IC chip 166 can perform processing with an external device such as a reader / writer 200 in synchronization with the external device.
[0053]
 The detection circuit 174 rectifies the received voltage output from the antenna 168. Here, the detection circuit 174 is composed of, for example, a diode D1 and a capacitor C2.
[0054]
 The regulator 176 smoothes the received voltage, makes it a constant voltage, and outputs the drive voltage to the MPU 180. Here, the regulator 176 uses the DC component of the received voltage as the drive voltage.
[0055]
 The demodulation circuit 178 demodulates the carrier wave signal based on the received voltage, and outputs data corresponding to the carrier wave signal included in the carrier wave (for example, a binarized data signal of high level and low level). Here, the demodulation circuit 178 outputs the AC component of the received voltage as data.
[0056]
 The MPU 180 drives the drive voltage output from the regulator 176 as a power source, and processes the demodulated data in the demodulation circuit 178. Here, the MPU 180 is composed of, for example, one or more processors composed of arithmetic circuits such as MPU, various processing circuits, and the like.
[0057]
 Further, the MPU 180 generates a control signal for controlling the load modulation related to the response to the external device such as the reader / writer 200 according to the processing result. Then, the MPU 180 outputs the control signal to the load modulation circuit 182.
[0058]
 The load modulation circuit 182 includes, for example, a load Z and a switch SW1, and performs load modulation by selectively connecting (activating) the load Z according to a control signal transmitted from the MPU 180. Here, the load Z is composed of, for example, a resistor having a predetermined resistance value. Further, the switch SW1 is composed of, for example, a p-channel type MOSFET (Metal Oxide Semiconductor Field effect transistor) and an n-channel type MOSFET.
[0059]
 The IC chip 166 processes the carrier signal received by the antenna 168 according to the above configuration, and causes the antenna 168 to transmit a response signal by load modulation.
[0060]
 By having the configuration shown in FIG. 4, for example, the IC chip 166 and the antenna 168 communicate with an external device such as a reader / writer 200 by NFC using a carrier wave having a predetermined frequency. Needless to say, the configurations of the IC chip 166 and the antenna 168 according to the present embodiment are not limited to the example shown in FIG.
[0061]
 The information processing device 100 communicates with an external device such as a reader / writer 200 according to the hardware configuration shown in FIG. 3, for example. Further, the information processing device 100 performs processing related to the information processing method in the information processing device 100, which will be described later, according to the hardware configuration shown in FIG. 3, for example. The hardware configuration of the information processing device 100 according to the present embodiment is not limited to the configuration shown in FIG.
[0062]
 For example, when communicating with an external device via an external communication device having the same function and configuration as the communication interface 164, or when the configuration does not perform communication of the above-mentioned one communication method, information processing is performed. The device 100 does not have to include the communication interface 164.
[0063]
 Further, for example, when communicating with an external device via an external communication device having the same functions and configurations as the IC chip 166 and the antenna 168, the information processing device 100 includes the IC chip 166 and the antenna 168. It does not have to be.
[0064]
 Further, the information processing device 100 does not have to include the IC chip 166 and the antenna 168 when communicating with an external device by a communication method other than NFC, such as wireless communication using IEEE802.5.1. .. In the above case, the information processing device 100 communicates with the external device by providing a communication device corresponding to a communication method other than NFC or by an external communication device corresponding to a communication method other than NFC.
[0065]
 Further, the information processing device 100 may be configured not to include, for example, a part or all of the recording medium 156, the operation input device 160, and the display device 162.
[0066]
 Further, the information processing apparatus 100 can have a hardware configuration according to an application example of the information processing apparatus 100 described later, for example. For example, when the information processing device 100 is an IC card, the information processing device 100 may be composed of an IC chip 166 and an antenna 168. When the information processing device 100 is an IC card, for example, the MPU 180 constituting the IC chip 166 performs processing related to the information processing method in the information processing device 100 described later.
[0067]
 Further, for example, the configuration shown in FIG. 3 (or the configuration according to the modified example) may be realized by one or two or more ICs (Integrated Circuits).
[0068]
 An example of the configuration of the information processing apparatus 100 will be described with reference to FIG. 2 again. The first communication unit 102 communicates with the external device by the communication of one communication method. The communication in the first communication unit 102 is controlled by, for example, the control unit 106.
[0069]
 Here, as the first communication unit 102, for example, a communication antenna and an RF circuit (wireless communication), an IEEE802.5.1 port and a transmission / reception circuit (wireless communication), an IEEE802.11 port and a transmission / reception circuit (wireless communication), and the like. Alternatively, a LAN terminal and a transmission / reception circuit (wired communication) may be mentioned.
[0070]
 The second communication unit 104 communicates with the external device by communication of another communication method. The communication in the second communication unit 104 is controlled by, for example, the control unit 106.
[0071]
 Here, as the second communication unit 104, for example, a communication device corresponding to NFC such as the IC chip 166 and the antenna 168 shown in FIG. 3 can be mentioned. As described above, the second communication unit 104 may be a communication device corresponding to a communication method other than NFC, such as wireless communication using IEEE802.5.1.
[0072]
 The control unit 106 is composed of, for example, an MPU or the like, and serves to control the entire information processing apparatus 100. Further, the control unit 106 includes, for example, a processing unit 110, and plays a role of leading the processing related to the information processing method in the information processing apparatus 100 described later.
[0073]
 The processing unit 110 plays a role of leading the processing related to the information processing method in the information processing apparatus 100. An example of processing related to the information processing method in the information processing apparatus 100 will be shown in each embodiment described later.
[0074]
 The configuration of the information processing device (first information processing device) according to the present embodiment is not limited to the configuration shown in FIG.
[0075]
 For example, the information processing apparatus according to the present embodiment can include the processing unit 110 shown in FIG. 2 separately from the control unit 106 (for example, it can be realized by another processing circuit).
[0076]
 Further, the configuration of the information processing apparatus according to the present embodiment is not limited to the configuration shown in FIG. 2, and it is possible to adopt a configuration according to a method of dividing the processing related to the information processing method in the information processing apparatus 100 described later. ..
[0077]
 Further, for example, when communicating with an external device via an external communication device having the same function and configuration as the first communication unit 102, or when the configuration does not perform communication of the above-mentioned one communication method. The information processing apparatus according to the present embodiment does not have to include the first communication unit 102.
[0078]
 Further, for example, when communicating with an external device via an external communication device having the same function and configuration as the second communication unit 104, the information processing device according to the present embodiment uses the second communication unit 104. It does not have to be prepared.
[0079]
[1-2] Reader / Writer 200 (Relay Device)
 FIG. 5 is a functional block diagram showing an example of the configuration of the reader / writer 200 (relay device) according to the present embodiment.
[0080]
 The reader / writer 200 includes, for example, a first communication unit 202, a second communication unit 204, and a control unit 206.
[0081]
 Further, the reader / writer 200 may display, for example, a ROM (not shown), a RAM (not shown), a storage unit (not shown), a user-operable operation unit (not shown), and various screens. A display unit (not shown) or the like to be displayed on the display screen may be provided. The reader / writer 200 connects each of the above components by, for example, a bus as a data transmission path.
[0082]
 The ROM (not shown) stores control data such as programs and calculation parameters used by the control unit 206. The RAM (not shown) temporarily stores a program or the like executed by the control unit 206.
[0083]
 The storage unit (not shown) is a storage means included in the reader / writer 200, and stores various data such as various applications. Here, examples of the storage unit (not shown) include a magnetic recording medium such as a hard disk, a non-volatile memory such as a flash memory, and the like. Further, the storage unit (not shown) may be detachable from the reader / writer 200.
[0084]
 Examples of the operation unit (not shown) include an operation input device similar to the operation input device 160 shown in FIG. Further, as the display unit (not shown), a display device similar to the display device 162 shown in FIG. 3 can be mentioned.
[0085]
[Hardware Configuration Example of Reader / Writer 200]
 FIG. 6 is an explanatory diagram showing an example of a hardware configuration of the reader / writer 200 (relay device) according to the present embodiment.
[0086]
 The reader / writer 200 includes, for example, an MPU 250, a ROM 252, a RAM 254, a recording medium 256, a communication interface 258, a carrier wave transmission circuit 260, and an antenna 262. Further, the reader / writer 200 connects each component with, for example, a bus 264 as a data transmission path. Further, the reader / writer 200 is driven by, for example, electric power supplied from an internal power source such as a battery included in the reader / writer 200, or electric power supplied from a connected external power source.
[0087]
 The MPU 250 is composed of, for example, one or more processors composed of arithmetic circuits such as MPU, various processing circuits, and the like, and functions as a control unit 206 that controls the entire reader / writer 200. Further, the MPU 250 serves as, for example, a processing unit 210 described later in the reader / writer 200.
[0088]
 The ROM 252 stores control data such as programs and calculation parameters used by the MPU 250. The RAM 254 temporarily stores, for example, a program executed by the MPU 250.
[0089]
 The recording medium 256 functions as a storage unit (not shown) and stores various data such as various applications. Here, examples of the recording medium 256 include a magnetic recording medium such as a hard disk and a non-volatile memory such as a flash memory. Further, the recording medium 256 may be detachable from the reader / writer 200.
[0090]
 The communication interface 258 is a communication means for performing communication of one communication method included in the reader / writer 200, and is wirelessly or wired with an external device such as a server 300 via a network (or directly). It functions as a first communication unit 202 for communicating with the user. Here, examples of the communication interface 258 include a communication antenna and an RF circuit (wireless communication), an IEEE802.5.1 port and a transmission / reception circuit (wireless communication), an IEEE802.11 port and a transmission / reception circuit (wireless communication), or a LAN. Examples include terminals and transmission / reception circuits (wired communication). Further, the communication interface 258 may have an arbitrary configuration corresponding to the network according to the present embodiment.
[0091]
 The carrier wave transmission circuit 260 and the antenna 262 are communication means for communicating with other communication methods included in the reader / writer 200, and for communicating wirelessly or by wire with an external device such as the information processing device 100. It functions as the second communication unit 204.
[0092]
 The antenna 262 is composed of, for example, a resonance circuit including a coil having a predetermined inductance as a transmission / reception antenna and a capacitor having a predetermined capacitance, and a demodulation circuit. Then, the antenna 262 demodulates data transmitted by load modulation or the like from an external device such as the information processing device 100 by receiving a carrier wave having a predetermined frequency such as 13.56 [MHz]. In addition, for example, when the carrier wave transmission circuit 260 includes a demodulation circuit, the antenna 262 may be composed of a resonance circuit.
[0093]
 The carrier wave transmission circuit 260 includes, for example, a modulation circuit that performs modulation such as ASK (Amplitude Shift Keying) and an amplifier circuit that amplifies the output of the modulation circuit, and carries a carrier wave on which a carrier wave signal is placed from the transmission / reception antenna of the antenna 262. Send it. Further, the carrier wave transmission circuit 260 may include, for example, a demodulation circuit that demodulates the signal received by the antenna 262. The demodulation circuit was received by the antenna 262, for example, by envelope-detecting the change in voltage amplitude between the modulation circuit (or amplification circuit) and the resonant circuit of the antenna 262 and binarizing the detected signal. Demodulate the signal. The demodulation circuit can also demodulate the signal received by the antenna 262 by using, for example, the phase change of the voltage between the modulation circuit (or the amplifier circuit) and the resonance circuit of the antenna 262.
[0094]
 By providing the carrier wave transmission circuit 260, the reader / writer 200 has an initiator function in NFC and serves as a so-called reader / writer. Here, examples of the carrier wave signal transmitted by the carrier wave transmission circuit 260 from the antenna 262 include various signals such as a polling signal and a signal indicating a read request described later. Further, in the carrier wave transmission circuit 260, for example, the carrier wave transmission is controlled by the MPU 250.
[0095]
 The reader / writer 200 serves as a relay device by having the hardware configuration shown in FIG. 6, for example. The hardware configuration of the reader / writer 200 according to this embodiment is not limited to the configuration shown in FIG.
[0096]
 For example, the reader / writer 200 does not have to include the communication interface 258 when communicating with an external device via an external communication device having the same function as the communication interface 258.
[0097]
 Further, when the reader / writer 200 communicates with an external device via an external communication device having the same function as the carrier wave transmission circuit 260 and the antenna 262, the reader / writer 200 does not include the carrier wave transmission circuit 260 and the antenna 262. May be good.
[0098]
 Further, when the reader / writer 200 communicates with an external device by a communication method other than NFC such as wireless communication using IEEE802.5.1, the reader / writer 200 does not have to have the carrier wave transmission circuit 260 and the antenna 262. Good. In the above case, the reader / writer 200 communicates with the external device by providing a communication device corresponding to a communication method other than NFC, or by an external communication device corresponding to a communication method other than NFC.
[0099]
 Further, the reader / writer 200 can be configured not to include, for example, a recording medium 256.
[0100]
 Further, the reader / writer 200 can have a hardware configuration according to an application example of the reader / writer 200 described later, for example.
[0101]
 Further, for example, the configuration shown in FIG. 6 (or the configuration according to the modified example) may be realized by one or two or more ICs.
[0102]
 An example of the configuration of the reader / writer 200 will be described with reference to FIG. 5 again.
[0103]
 The first communication unit 202 communicates with the external device by the communication of one communication method. The communication of one communication method in the first communication unit 202 is controlled by, for example, the control unit 206.
[0104]
 Here, as the first communication unit 202, for example, a communication antenna and an RF circuit (wireless communication), an IEEE802.5.1 port and a transmission / reception circuit (wireless communication), an IEEE802.11 port and a transmission / reception circuit (wireless communication), and the like. Alternatively, a LAN terminal and a transmission / reception circuit (wired communication) may be mentioned.
[0105]
 The second communication unit 204 communicates with the external device by communication of another communication method. Communication of other communication methods in the second communication unit 204 is controlled by, for example, the control unit 206.
[0106]
 Here, examples of the second communication unit 204 include communication devices corresponding to NFC, such as the carrier wave transmission circuit 260 and the antenna 262 shown in FIG. As described above, the second communication unit 204 may be a communication device corresponding to a communication method other than NFC, such as wireless communication using IEEE802.5.1.
[0107]
 The control unit 206 is composed of, for example, an MPU or the like, and serves to control the entire reader / writer 200. Further, the control unit 206 may include a processing unit 210 capable of performing arbitrary processing such as communication control processing and settlement processing, for example.
[0108]
 The configuration of the reader / writer (relay device) according to the present embodiment is not limited to the configuration shown in FIG.
[0109]
 For example, the reader / writer according to the present embodiment can include the processing unit 210 shown in FIG. 5 separately from the control unit 206 (for example, it can be realized by another processing circuit).
[0110]
 Further, for example, when communicating with an external device via an external communication device having the same function and configuration as the first communication unit 202, the reader / writer according to the present embodiment uses the first communication unit 202. It does not have to be prepared.
[0111]
 Further, for example, when communicating with an external device via an external communication device having the same function and configuration as the second communication unit 204, the reader / writer according to the present embodiment uses the second communication unit 204. It does not have to be prepared.
[0112]
[1-3] Server 300 (Second Information Processing Device)
 FIG. 7 is a functional block diagram showing an example of the configuration of the server 300 (second information processing device) according to the present embodiment. The server 300 includes, for example, a communication unit 302 and a control unit 304.
[0113]
 Further, the server 300 includes, for example, a ROM (not shown), a RAM (not shown), a storage unit (not shown), an operation unit that can be operated by the user of the server 300 (not shown), and various other types. A display unit (not shown) for displaying the screen on the display screen may be provided. The server 300 connects each of the above components by, for example, a bus as a data transmission path.
[0114]
 The ROM (not shown) stores control data such as programs and calculation parameters used by the control unit 304. The RAM (not shown) temporarily stores a program or the like executed by the control unit 304.
[0115]
 The storage unit (not shown) is a storage means included in the server 300, and stores various data such as data related to an information processing method in the server 300 and various applications. Here, examples of the storage unit (not shown) include a magnetic recording medium such as a hard disk, a non-volatile memory such as a flash memory, and the like. Further, the storage unit (not shown) may be detachable from the server 300.
[0116]
 Examples of the operation unit (not shown) include an operation input device shown in a hardware configuration example of the server 300 described later. Further, as a display unit (not shown), a display device shown in a hardware configuration example of the server 300 described later can be mentioned.
[0117]
[Hardware Configuration Example of Server 300]
 FIG. 8 is an explanatory diagram showing an example of the hardware configuration of the server 300 (second information processing apparatus) according to the present embodiment. The server 300 includes, for example, an MPU 350, a ROM 352, a RAM 354, a recording medium 356, an input / output interface 358, an operation input device 360, a display device 362, and a communication interface 364. Further, the server 300 connects each component with, for example, a bus 366 as a data transmission path. Further, the server 300 is driven by, for example, electric power supplied from an internal power source such as a battery included in the server 300, or electric power supplied from an external power source connected to the server 300.
[0118]
 The MPU 350 is composed of one or more processors composed of arithmetic circuits such as MPU, various processing circuits, and the like, and functions as a control unit 304 that controls the entire server 300. Further, the MPU 350 serves as, for example, a processing unit 310 described later in the server 300. The processing unit 310 may be composed of a dedicated (or general-purpose) circuit (for example, a processor separate from the MPU 350).
[0119]
 The ROM 352 stores control data such as programs and calculation parameters used by the MPU 350. The RAM 354 temporarily stores, for example, a program executed by the MPU 350.
[0120]
 The recording medium 356 functions as a storage unit (not shown), and stores various data such as data related to an information processing method in the server 300 and various applications. Here, examples of the recording medium 356 include a magnetic recording medium such as a hard disk and a non-volatile memory such as a flash memory. Further, the recording medium 356 may be detachable from the server 300.
[0121]
 The input / output interface 358 connects, for example, an operation input device 360 ​​and a display device 362. The operation input device 360 ​​functions as an operation unit (not shown), and the display device 362 functions as a display unit (not shown). Here, examples of the input / output interface 358 include a USB terminal, a DVI terminal, an HDMI (registered trademark) terminal, and various processing circuits.
[0122]
 Further, the operation input device 360 ​​is provided on the server 300, for example, and is connected to the input / output interface 358 inside the server 300. Examples of the operation input device 360 ​​include buttons, direction keys, rotary selectors such as a jog dial, and combinations thereof.
[0123]
 Further, the display device 362 is provided on the server 300, for example, and is connected to the input / output interface 358 inside the server 300. Examples of the display device 362 include a liquid crystal display and an organic EL display.
[0124]
 Needless to say, the input / output interface 358 can be connected to an external device such as an external operation input device (for example, a keyboard or mouse) or an external display device of the server 300. Further, the display device 362 may be a device capable of displaying and operating the user, such as a touch panel.
[0125]
 The communication interface 364 is a communication means included in the server 300, and is a communication unit for wirelessly or wired communication with an external device such as a reader / writer 200 via a network (or directly). Functions as 302. Here, examples of the communication interface 364 include a communication antenna and RF circuit (wireless communication), an IEEE802.5.1 port and a transmission / reception circuit (wireless communication), an IEEE802.11 port and a transmission / reception circuit (wireless communication), or a LAN. Examples include terminals and transmission / reception circuits (wired communication). Further, the communication interface 364 may have an arbitrary configuration corresponding to the network according to the present embodiment.
[0126]
 The server 300 performs processing related to the information processing method in the server 300, which will be described later, according to the hardware configuration shown in FIG. 8, for example. The hardware configuration of the server 300 according to this embodiment is not limited to the configuration shown in FIG.
[0127]
 For example, the server 300 does not have to include the communication interface 364 when communicating with an external device or the like via a connected external communication device. Further, the communication interface 364 may have a configuration capable of communicating with one or more external devices or the like by a plurality of communication methods.
[0128]
 Further, the server 300 can be configured not to include, for example, a recording medium 356, an operation input device 360, and a part or all of the display device 362.
[0129]
 Further, the server 300 can have, for example, a hardware configuration according to an application example of the server 300 described later.
[0130]
 Further, for example, a part or all of the hardware configuration (or the configuration according to the modification) shown in FIG. 8 may be realized by one or two or more ICs.
[0131]
 An example of the configuration of the server 300 will be described with reference to FIG. 7 again. The communication unit 302 is a communication means included in the server 300, and communicates wirelessly or by wire with an external device such as a reader / writer 200 via a network (or directly). In addition, the communication unit 302 is controlled by, for example, the control unit 304.
[0132]
 Here, examples of the communication unit 302 include a communication antenna and an RF circuit, a LAN terminal, a transmission / reception circuit, and the like, but the configuration of the communication unit 302 is not limited to the above. For example, the communication unit 302 can have a configuration corresponding to an arbitrary standard capable of performing communication such as a USB terminal and a transmission / reception circuit, or an arbitrary configuration capable of communicating with an external device via a network. Further, the communication unit 302 may have a configuration capable of communicating with one or more external devices or the like by a plurality of communication methods.
[0133]
 The control unit 304 is composed of, for example, an MPU or the like, and serves to control the entire server 300. Further, the control unit 304 includes, for example, a processing unit 310, and plays a role of leading the processing related to the information processing method in the server 300 described later.
[0134]
 The processing unit 310 plays a role of leading the processing related to the information processing method according to the present embodiment on the server 300. An example of processing related to the information processing method according to the present embodiment in the server 300 will be described later.
[0135]
 The configuration of the server (second information processing device) according to the present embodiment is not limited to the configuration shown in FIG. 7.
[0136]
 For example, the server according to the present embodiment can include the processing unit 310 shown in FIG. 7 separately from the control unit 304 (for example, it can be realized by another processing circuit).
[0137]
 Further, the configuration of the server according to the present embodiment is not limited to the configuration shown in FIG. 7, and it is possible to adopt a configuration according to the method of dividing the processing related to the information processing method in the server 300 described later.
[0138]
 Further, for example, when communicating with an external device via an external communication device having the same function and configuration as the communication unit 302, the server according to the present embodiment does not have to include the communication unit 302. ..
[0139]
[1-4] Application Examples of Each Device Constituting the Information Processing System
 According to the Present Embodiment The information processing device 100 (first information processing device) is mentioned as a component of the information processing system according to the present embodiment. However, the present embodiment is not limited to such an embodiment. In this embodiment, for example, processing related to an information processing method in the information processing device 100 described later, such as a "communication device such as a smart phone", an "IC card", a "tablet type device", and a "game machine", is performed. It can be applied to various devices that can be used. The present embodiment can also be applied to, for example, a processing IC that can be incorporated into the above-mentioned equipment.
[0140]
 Further, although the reader / writer 200 (relay device) has been described as a component of the information processing system according to the present embodiment, the present embodiment is not limited to this embodiment. In this embodiment, for example, a device such as a "reader / writer", a "device having a reader / writer function", and a "communication device that communicates by wireless communication using IEEE802.5.1 such as BLE". It can be applied to any device having a function of relaying communication between them. The present embodiment can also be applied to, for example, a processing IC that can be incorporated into the above-mentioned equipment.
[0141]
 Further, although the server 300 (second information processing apparatus) has been described as a component of the information processing system according to the present embodiment, the present embodiment is not limited to such an embodiment. In this embodiment, for example,
information on a server 300 described later, such as a "computer such as a PC (Personal Computer) or a server", a "tablet type device", a "communication device such as a smart phone", or a "game machine". It can be applied to various devices capable of performing processing related to the processing method. The present embodiment can also be applied to, for example, a processing IC that can be incorporated into the above-mentioned equipment.
[0142]
 Further, the server according to the present embodiment may be applied to a processing system premised on connection to a network (or communication between devices) such as cloud computing. As an example of the above processing system, for example, "a part of the processing related to the information processing method in the server 300 described later is performed by one device constituting the processing system, and another device constituting the processing system performs some processing. Among the processes related to the information processing method in the server 300, a "system in which processes other than the partial processes are performed" and the like can be mentioned.
[0143]
[2] Information Processing Method According to the Present Embodiment
 Next, the information processing method according to the present embodiment will be described by taking the information processing system 1000 shown in FIG. 1 as an example.
[0144]
[2-1] Information processing method according to the first embodiment
[2-1-1] Outline of the information processing system 1000 to which the information processing method according to the first embodiment is applied
 As described above, for example, When another device reads data stored in the device that requires permission to read, authentication is performed between one device and the other device, and the data is read after the authentication is completed. That is, the data that requires the authority to be read is read by another device after the authentication of the authority is completed.
[0145]
 Here, in the authentication of authority, for example, "the above-mentioned one device transmits a value called a random challenge (hereinafter referred to as" random challenge "), and the above-mentioned other device transmits an authentication key (authentication) for the value. The calculation is performed using the encryption key used for), and the calculation result is transmitted to the above-mentioned one device ”(challenge response method).
[0146]
 FIG. 9 is an explanatory diagram showing an example of communication related to data reading using authentication by the existing challenge / response method. FIG. 9 shows an example of communication using NFC communication in an information processing system having the same configuration as the information processing system 1000 shown in FIG. That is, in the example shown in FIG. 9, NFC communication is performed between the information processing device 10 and the reader / writer 20, and network communication is performed between the reader / writer 20 and the server 30.
[0147]
 The information processing device 10 transmits a random challenge to the reader / writer 20 (S10). The reader / writer 20 that has received the random challenge transmitted from the information processing device 10 in step S10 transmits the received random challenge to the server 30 (S12).
[0148]
 The server 30 that has received the random challenge performs a predetermined calculation using the authentication key (S14), and transmits the calculation result to the reader / writer 20 (S16). The predetermined operation includes a process of encrypting a random challenge using an authentication key. Further, the calculation result transmitted by the server 30 in step S16 corresponds to an encrypted random challenge.
[0149]
 The reader / writer 20 that has received the calculation result transmitted from the server 30 in step S16 transmits the received calculation result to the information processing device 10 (S18).
[0150]
 The information processing apparatus 10 that has received the calculation result transmitted from the reader / writer 20 in step S18 verifies the received calculation result (S20). As the verification in step S20, for example, "decrypting the received calculation result with a predetermined encryption key and verifying whether the decrypted value matches the random challenge" or "in the information processing apparatus 10 in step S14". Performing the same operation as above, and verifying whether the operation result matches the received operation result ”.
[0151]
 If it is determined in step S20 that the verification result is normal, the information processing device 10 authenticates the server 30 as a device having authority to read. That is, the processes in steps S10 to S20 correspond to the authentication process. Hereinafter, an example of processing when authentication is normally completed in step S20 will be described.
[0152]
 The server 30 that has transmitted the calculation result in step S16 transmits a read request (S22). The read request is, for example, data including a data read instruction and information indicating an area of ​​a recording medium for reading the data.
[0153]
 The reader / writer 20 that has received the read request transmitted from the server 30 in step S22 transmits the received read request to the information processing device 10 (S24).
[0154]
 The information processing apparatus 10 that has received the read request transmitted from the reader / writer 20 in step S26 reads data from the area of ​​the recording medium indicated by the read request, and transmits the read data (S26). The reader / writer 20 that has received the data transmitted from the information processing device 10 in step S26 transmits the received data to the server 30 (S28).
[0155]
 Reading data using authentication by the existing challenge-response method is performed, for example, as shown in FIG.
[0156]
 When the authentication by the existing challenge response method is used, as shown in FIG. 9, the communication related to the reading of the data is performed after the communication related to the authentication by the challenge response method is performed. Therefore, when the existing challenge / response method authentication is used, the security related to data reading can be ensured.
[0157]
 However, when the authentication by the existing challenge / response method is used, the communication related to the reading of the data is performed after the communication related to the authentication by the challenge response method is performed, so that the communication time becomes long. The processing time of the entire system is also long.
[0158]
 Therefore, in the information processing system 1000 to which the information processing method according to the first embodiment is applied (hereinafter, may be referred to as "information processing system 1000 according to the first embodiment"), the existing challenge response Both authentication and data reading are performed by communication related to data reading without performing authentication by the method.
[0159]
 In the information processing system 1000 according to the first embodiment, the information processing device 100 performs the following processing (processing related to the information processing method in the information processing device 100), so that "both authentication and data reading" are performed. Is done by communication related to data reading "is realized.
[0160]
[2-1-2] Processing related to the information processing method in the information processing system 1000 according to
 the first embodiment Next, an example of processing related to the information processing method in the information processing system 1000 according to the first embodiment will be described. To do.
[0161]
 When the read request is acquired, the information processing apparatus 100 encrypts the data corresponding to the area of ​​the recording medium indicated by the read request with the encryption key corresponding to the area indicated by the read request. The information processing apparatus 100 encrypts data by performing an operation of an arbitrary encryption method such as DES (Data Encryption Standard) or AES (Advanced Encryption Standard). Examples of the recording medium from which the information processing apparatus 100 reads data include a recording medium having tamper resistance such as the non-volatile memory 188 of FIG. Then, the information processing device 100 transmits the encrypted data.
[0162]
 In the information processing device 100, for example, the processing unit 110 reads data corresponding to a read request from a recording medium, encrypts the read data, causes the communication device to transmit the encrypted data, and the like. The processing related to the information processing method in the information processing apparatus 100 is performed (the same applies to other embodiments).
[0163]
 The read request according to the present embodiment is, for example, data including a data read instruction and information indicating an area of ​​a recording medium for reading the data.
[0164]
 The read request may include a plurality of information indicating the area, and the information indicating the area may indicate a plurality of areas. That is, one or more data can be read from one area or a plurality of areas according to the read request according to the present embodiment.
[0165]
 The read request according to the present embodiment is not limited to the example shown above. For example, the read request according to the present embodiment may include other information such as information related to encryption. As the information related to the encryption according to the present embodiment, for example, one or both of the data indicating whether or not to encrypt the data read from the area indicated by the information indicating the area and the data specifying the encryption key. However, it can be mentioned. Further, as shown in the information processing method according to the fourth embodiment described later, the information regarding the encryption according to the present embodiment includes data indicating whether or not to generate an "encryption key corresponding to the read request". , May be further included.
[0166]
 More specifically, the information processing apparatus 100 reads data from an area indicated by information indicating an area included in the read request. Then, the information processing apparatus 100 encrypts the read data with an encryption key corresponding to the area indicated by the read request.
[0167]
 When the read request indicates a plurality of areas, the information processing apparatus 100 reads data from each of the plurality of areas. Then, the information processing apparatus 100 encrypts the data read for each area indicated by the read request with the encryption key corresponding to the area indicated by the read request.
[0168]
 The information processing device 100 identifies the encryption key corresponding to the area indicated by the read request, for example, based on the setting information associated with the area of ​​the recording medium. Then, the information processing apparatus 100 encrypts the read data (data corresponding to the area indicated by the read request) with the specified encryption key.
[0169]
 The setting information according to the present embodiment is data indicating a setting related to encryption of an area of ​​a recording medium.
[0170]
 Examples of the setting information include "a table (or database) in which an address indicating an area of ​​a recording medium and an encryption key are recorded in association with each area". Further, the setting information may be further associated with information defining whether or not to perform encryption (hereinafter, referred to as “encryption necessity information”) for each area. Examples of the encryption necessity information include data indicating either "always encrypted", "always plaintext" (always not encrypted), or "following a read request". The setting information according to the present embodiment is not limited to the table (or database) as shown above, and may be data in any format such as data for each area.
[0171]
 When the encryption necessity information is included in the setting information, the information processing apparatus 100 determines whether or not to encrypt the data corresponding to the area indicated by the read request based on the setting information. Then, the information processing apparatus 100 selectively encrypts the data corresponding to the area indicated by the read request according to the determination result. To give a specific example, the information processing apparatus 100 encrypts the data corresponding to the area indicated by the read request when it is determined to encrypt the data corresponding to the area indicated by the read request. Further, the information processing apparatus 100 does not encrypt the data corresponding to the area indicated by the read request when it is not determined to encrypt the data corresponding to the area indicated by the read request.
[0172]
 The setting information according to this embodiment is not limited to the example shown above.
[0173]
 For example, as shown in the information processing method according to the fourth embodiment described later, the setting information includes information that defines whether to generate an "encryption key corresponding to a read request" (hereinafter, "encryption key generation required". "No information") may be further associated with each area. As the encryption key generation necessity information, for example, "always generate an" encryption key corresponding to a read request "", "do not always generate an" encryption key corresponding to a read request "", or "read". Data indicating any of the "comply with requirements" can be mentioned.
[0174]
 FIG. 10 is an explanatory diagram showing an outline of the setting defined by the setting information according to the present embodiment, and shows an example of the setting in the area A. In FIG. 10, the encryption key is shown as a “key” (the same applies to other figures).
[0175]
 As shown in FIG. 10, in the information processing apparatus 100, the area, the encryption key, and the necessity of encryption (whether or not to perform encryption) are defined by the setting information. The information processing apparatus 100 refers to the setting information corresponding to the area indicated by the read request, and identifies the encryption key corresponding to the area indicated by the read request. Further, the information processing apparatus 100 refers to the setting information corresponding to the area indicated by the read request, and specifies whether or not to encrypt the data read from the area.
[0176]
 As described above, in the setting information, the necessity of encryption may not be associated with the area. Further, in the setting information, the encryption key may not be associated with the area to which the encryption necessity information indicating that the encryption is not performed is associated.
[0177]
 When the encryption key corresponding to the area indicated by the read request is not specified, or when the encryption necessity information included in the setting information indicates that the encryption is not performed, the information processing apparatus 100 sets the area indicated by the read request. Send the corresponding data unencrypted.
[0178]
 FIG. 11 is an explanatory diagram showing an example of processing in the information processing system 1000 according to the first embodiment. In FIG. 11, the encrypted data is shown as “encrypted data” (the same applies to other figures).
[0179]
 The server 300 transmits a read request (S100).
[0180]
 The reader / writer 200 that has received the read request transmitted from the server 300 in step S100 transmits the received read request to the information processing device 100 (S102).
[0181]
 Here, when the reader / writer 200 stores the setting information in the recording medium, the reader / writer 200 encrypts a part of the read request received by the encryption key corresponding to the area indicated by the read request. , The encrypted read request may be transmitted to the information processing apparatus 100.
[0182]
 FIG. 12 is an explanatory diagram showing an example of processing in the reader / writer 200 (relay device) included in the information processing system 1000 according to the first embodiment. A of FIG. 12 shows an example of a read request transmitted from the server 300, and B of FIG. 12 shows an outline of the setting defined by the setting information as in FIG. 10. C in FIG. 12 shows an example of a read request encrypted by the reader / writer 200.
[0183]
 For example, as shown in FIG. 12, when the reader / writer 200 encrypts the read request received by the encryption key corresponding to the area indicated by the read request, the information processing device 100 that receives the encrypted read request A partially encrypted read request is decrypted with an encryption key corresponding to the area indicated by the read request and processed.
[0184]
 An example of processing in the information processing system 1000 according to the first embodiment will be described with reference to FIG. 11 again. The information processing apparatus 100 that has received the read request transmitted from the reader / writer 200 in step S102 encrypts the data corresponding to the area indicated by the read request with the encryption key corresponding to the area indicated by the read request (S104). .. Then, the information processing device 100 transmits the encrypted data (S106).
[0185]
 FIG. 13 is an explanatory diagram for explaining an example of processing in the information processing system 1000 according to the first embodiment. A of FIG. 13 schematically shows an example of a read request transmitted from the server 300, and B of FIG. 13 shows an example of encrypted data transmitted by the information processing apparatus 100.
[0186]
 As shown in A of FIG. 13, the read request may specify the read of data from a plurality of areas. As described above, when the read request indicates a plurality of areas, the information processing apparatus 100 puts the data read for each area indicated by the read request into the area indicated by the read request, as shown in B of FIG. Encrypt with the corresponding encryption key.
[0187]
 An example of processing in the information processing system 1000 according to the first embodiment will be described with reference to FIG. 11 again. The reader / writer 200 that has received the encrypted data transmitted from the information processing apparatus 100 in step S106 transmits the received encrypted data to the server 300 (S108).
[0188]
 The server 300 that has received the encrypted data transmitted from the reader / writer 200 in step S108 decrypts the received encrypted data with the encryption key corresponding to the area indicated by the read request transmitted in step S100. (S110). In the server 300, the decrypted data can be used for arbitrary processing according to, for example, a service provided by the server 300.
[0189]
 In the information processing system 1000 according to the first embodiment, for example, by performing the process shown in FIG. 11, the server 300 can read data from the information processing device 100.
[0190]
 Here, tentatively, a device other than a device having a legitimate encryption key such as the server 300 (hereinafter, referred to as a “third-party device”) acquires the encrypted data transmitted from the information processing device 100. Even so, the third party device cannot decrypt the encrypted data. Therefore, in the information processing system 1000 according to the first embodiment, the safety of reading data that requires authority to read is ensured.
[0191]
 Further, a
comparison between the communication in the information processing system 1000 according to the first embodiment shown in FIG. 11 and the communication related to data reading using the authentication by the existing challenge / response method shown in FIG. 9 is shown in FIG. The number of communications shown is smaller. That is, in the information processing system 1000 according to the first embodiment, the communication time is shorter and the processing time of the entire system is shorter than when the authentication by the existing challenge / response method is used.
[0192]
 Therefore, in the information processing system 1000 having the information processing device 100 according to the first embodiment, it is realized that the processing time related to reading can be reduced while ensuring the safety related to reading data.
[0193]
 The processing in the information processing apparatus 100 according to the first embodiment is not limited to the example shown above.
[0194]
 As mentioned above, the read request may include information about encryption. FIG. 14 is an explanatory diagram for explaining an example of a read request according to the present embodiment, and shows an example of a read request including information related to encryption. The “encryption request” shown in FIG. 14 corresponds to the information related to encryption.
[0195]
 As shown in FIG. 14, when the read request includes information related to encryption and it is not determined to encrypt the data corresponding to the area indicated by the read request based on the setting information, the information processing apparatus 100 is included in the read request. The data corresponding to the area indicated by the read request may be selectively encrypted based on the information regarding the encryption. Here, for selective encryption based on information on encryption, "whether or not to perform encryption" or "whether or not to perform encryption, and which encryption key is used when performing encryption". "Is included.
[0196]
 To give a specific example, when the information processing apparatus 100 indicates that the information related to encryption included in the read request is to be encrypted, the information processing apparatus 100 encrypts the data corresponding to the area indicated by the read request. At this time, the information processing apparatus 100 may perform encryption using the encryption key specified by the information related to encryption. Further, the information processing apparatus 100 does not encrypt the data corresponding to the area indicated by the read request when the information related to the encryption included in the read request does not indicate that the information is encrypted.
[0197]
 That is, when the processing is performed based on the encryption-related information included in the read request, the information processing device 100 transmits the data corresponding to the area indicated by the read request or the encrypted data. ..
[0198]
 FIG. 15 is a flow chart showing an example of processing in the information processing apparatus 100 according to the first embodiment. FIG. 15 shows an example of processing in the information processing apparatus 100 after receiving a read request including information related to encryption. In FIG. 15, the area indicated by the read request is referred to as a “read target area”.
[0199]
 The information processing device 100 determines whether or not the setting of the area indicated by the read request is "always encrypted" (S200). The information processing device 100 determines in step S200 by referring to the encryption necessity information included in the setting information.
[0200]
 When it is determined in step S200 that the data is "always encrypted", the information processing apparatus 100 performs the process of step S208 described later.
[0201]
 If it is not determined in step S200 that it is "always encrypted", the information processing apparatus 100 determines whether or not the setting of the area indicated by the read request is "always plain text" (S202). The information processing device 100 determines in step S202 by referring to the encryption necessity information included in the setting information.
[0202]
 When it is determined in step S202 that the text is "always plain text", the information processing apparatus 100 performs the process of step S206 described later.
[0203]
 If it is not determined in step S200 that the text is "always plain text", the information processing apparatus 100 determines whether or not the encryption-related information included in the read request requires encryption (S204).
[0204]
 If it is not determined in step S204 that encryption is requested, or if it is determined in step S202 that it is "always plaintext", the information processing apparatus 100 outputs data corresponding to the area indicated by the read request. Do not encrypt (S206). In this case, the information processing apparatus 100 transmits the data corresponding to the area indicated by the read request.
[0205]
 Further, when it is determined in step S204 that encryption is requested, or when it is determined in step S200 that "always encrypted", the information processing apparatus 100 is placed in the area indicated by the read request. Encrypt the corresponding data (S208). In this case, the information processing device 100 will transmit the encrypted data.
[0206]
 When the read request including the information related to the encryption is received, the information processing apparatus 100 performs the process shown in FIG. 15, for example. Needless to say, the processing of the information processing apparatus 100 when a read request including information related to encryption is received is not limited to the example shown in FIG.
[0207]
[2-1-3] Operations and Effects of
 the Information Processing System 1000 According to the First Embodiment In the first information processing system 1000, for example, the following operations are realized, and the first information processing system 1000 By using, for example, the following effects are produced. Needless to say, the operation of the information processing system 1000 according to the first embodiment and the effect produced by using the information processing system according to the first embodiment are not limited to the examples shown below. No.
  -Reading can be performed without authenticating the authority. The information processing device 100 encrypts the data with the key associated with the area and returns the encrypted data in response to the read request (command). The encrypted data is decrypted by a device having a key (server 300, reader / writer 200, etc.).
  -When a read request is acquired, whether or not the information processing device 100 encrypts and returns the data, and which key is used for encryption when a plurality of keys are linked to the area is determined by the area. The information processing apparatus 100 makes a determination with reference to the setting information set in advance.
  -For the area set as "may or may not be encrypted", it is possible to specify whether or not to encrypt the area by using the read request parameter (an example of information related to encryption). In addition, which key is used for the area set as "may or may not be encrypted" can also be specified by a read request parameter (an example of information related to encryption).
  When one read request includes reading of a plurality of areas, the information processing apparatus 100 encrypts the data read from each area with a key associated with each area.
  -The reader / writer 200 may encrypt the read request parameter with the key associated with the area as shown in FIG. 12 in order to prevent eavesdropping.
[0208]
[2-2] Information processing method according to the second embodiment
[2-2-1] Outline of the information processing system 1000 to which the information processing method according to the second embodiment is applied
 For example, the first information processing system described above. By using 1000, it is possible to reduce the processing time related to reading while ensuring the safety related to reading data.
[0209]
 However, in the first information processing system 1000, the server 300 cannot specify from the acquired data when the acquired data corresponds to the read request transmitted.
[0210]
 As described above, when the server 300 cannot specify when the data corresponds to the read request transmitted, some processing is performed on the decrypted data of the acquired data. As a result, something undesired can occur.
[0211]
 FIG. 16 is an explanatory diagram showing an example of a case that may occur when it is not possible to specify when the data corresponds to the read request transmitted by the server 300. FIG. 16 shows an example of processing in an information processing system having an information processing device 100, a server 300, and a reader / writer 20. In the example shown in FIG. 16, NFC communication is performed between the information processing device 100 and the reader / writer 20, and network communication is performed between the reader / writer 20 and the server 300.
[0212]
 The reader / writer 20 transmits a read request (S30) in the same manner as in step S102 of FIG. The information processing apparatus 100 that has received the read request transmitted from the reader / writer 20 in step S30 transmits the encrypted data in the same manner as in step S106 of FIG. 11 (S32).
[0213]
 The reader / writer 20 that has received the encrypted data transmitted from the information processing apparatus 100 in step S32 records the received encrypted data on an arbitrary recording medium (S34).
[0214]
 The server 300 transmits a read request to the reader / writer 20 (S36).
[0215]
 The reader / writer 20 that has received the read request transmitted from the server 300 in step S36 reads the encrypted data recorded on the recording medium in step S34 (S38) and transmits it to the server 300 (S40).
[0216]
 For example, when the process shown in FIG. 16 is performed, the server 300 processes the encrypted data transmitted from the reader / writer 20 in step S40 as data corresponding to the read request transmitted in step S36. It will be. Therefore, in the example shown in FIG. 16, as a result of the server 300 performing some processing on the acquired data (or the data obtained by decrypting the acquired encrypted data), some undesired situation occurs. It can occur.
[0217]
 The case that can occur when the server 300 cannot specify when the data corresponds to the read request transmitted is not limited to the example shown in FIG. For example, when the information processing system according to the first embodiment has a configuration in which the information processing device 100 and the server 300 directly communicate with each other (including a configuration in which the server 300 functions as a reader / writer 200), information is provided. Similarly, when an intermediate attack is made on the communication between the processing device 100 and the server 300, some undesired situation may occur.
[0218]
 Therefore, in the information processing system 1000 according to the second embodiment, the server 300 transmits information indicating a value together with a read request. “Sending information indicating a value together with a read request” according to the present embodiment means “transmitting a read request including information indicating a value” or “transmitting information indicating a value as data different from the read request”. It means "to do". The same applies when the data transmitted together with the read request is data other than the information indicating the value.
[0219]
 Examples of the value indicated by the information indicating the value according to the present embodiment include a numerical value, a character string, or a combination thereof. The value indicated by the information indicating the value is generated, for example, by the server 300 generating a random number, or is specified by the server 300 reading the value of the counter circuit or the clock included in the server 300. The value indicated by the information indicating the value serves as a parameter of the read request, for example. In the following, a case where the value indicated by the information indicating the value according to the present embodiment is a random number will be given as an example.
[0220]
 In the information processing system 1000 according to the second embodiment, the reader / writer 200 that has received the read request transmitted from the server 300 transmits the information indicating the value to the information processing device 100 together with the received read request. You may. In this case, the value indicated by the information indicating the value is generated by, for example, the reader / writer 200 generating a random number. Further, the reader / writer 200 transmits information indicating the value to the server 300.
[0221]
 When the information indicating the value is acquired together with the read request, the information processing apparatus 100 performs the following processing. The information processing device 100 may perform the following processing in addition to the processing related to the information processing method according to the first embodiment.
[0222]
 The information processing apparatus 100 generates an electronic signature from the data corresponding to the area indicated by the read request, the value indicated by the information indicating the value, and the encryption key corresponding to the area indicated by the read request. Then, the information processing apparatus 100 transmits the generated electronic signature together with the data corresponding to the area indicated by the read request. Here, the data transmitted by the information processing device 100 may or may not be encrypted.
[0223]
 FIG. 17 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus 100 according to the second embodiment, and shows an example of generating an electronic signature. In FIG. 17, the electronic signature is shown as a “signature” (the same applies to other figures).
[0224]
 As shown in FIG. 17, the information processing apparatus 100 uses data corresponding to the area indicated by the read request, a random number (an example of the value indicated by the information indicating the value), and an encryption key corresponding to the area indicated by the read request. , "Sha-256 With RSA Encryption" or any other algorithm to generate a digital signature.
[0225]
 When the information processing method according to the second embodiment is combined with the information processing method according to another embodiment described later, the information processing apparatus 100 may generate an electronic signature using further other information. It is possible. That is, the information processing apparatus 100 according to the second embodiment has at least the data corresponding to the area indicated by the read request, the value indicated by the information indicating the value, and the encryption key corresponding to the area indicated by the read request. Generate a digital signature.
[0226]
 The processing in the information processing apparatus 100 is not limited to the example shown above.
[0227]
 For example, when the read request indicates a plurality of areas, the information processing apparatus 100 generates an electronic signature for each area indicated by the read request, as in the example shown in FIG. Then, the information processing apparatus 100 further transmits the electronic signature for each generated area together with the data corresponding to the area indicated by the read request.
[0228]
 When the read request indicates a plurality of areas, the information processing apparatus 100 generates a signature encryption key based on the encryption key corresponding to the plurality of areas indicated by the read request. The signing encryption key is generated, for example, by degenerating a plurality of encryption keys (combining a plurality of encryption keys).
[0229]
 When the signature encryption key is generated, the information processing apparatus 100 electronically uses the data corresponding to the plurality of areas indicated by the read request, the value indicated by the information indicating the value, and the signature encryption key in the same manner as in the example shown in FIG. Generate a signature. Then, the information processing apparatus 100 transmits the generated electronic signature together with the data corresponding to the area indicated by the read request.
[0230]
 FIG. 18 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus 100 according to the second embodiment, and shows another example of generating an electronic signature. FIG. 18A shows an example in which an electronic signature is generated for each region indicated by the read request, as in the example shown in FIG. FIG. 18B shows an example in which an electronic signature is generated from the data corresponding to the plurality of areas indicated by the read request, the value indicated by the information indicating the value, and the signature encryption key in the same manner as in the example shown in FIG. ing.
[0231]
 Further, when the common key cryptosystem is used and the information indicating the value is acquired together with the read request, the information processing apparatus 100 generates a MAC (Message Authentication Code) based on the information indicating the value and generates it. The MAC may be transmitted together with the data corresponding to the area indicated by the read request. Here, the data transmitted by the information processing device 100 may or may not be encrypted. Hereinafter, in other embodiments as well, the electronic signature can be replaced with a MAC.
[0232]
 The server 300 that has acquired the data transmitted from the information processing device 100 and the electronic signature (or MAC; the same shall apply hereinafter) verifies the acquired electronic signature. The verification of the electronic signature may be performed by the reader / writer 200. Then, when the verification result is normal, the server 300 uses the acquired data (or the data obtained by decoding the acquired data) for arbitrary processing. Further, when the verification result is not normal, the server 300 does not use the acquired data (or the decrypted data of the acquired data) for arbitrary processing. For example, the server 300 compares the value obtained by decoding the acquired electronic signature with the value indicated by the information indicating the value transmitted together with the read request, and if these values ​​match, it is said that the server 300 has been successfully verified. judge.
[0233]
 In the information processing system 1000 according to the second embodiment, as described above, the server 300 can verify the data using the electronic signature, so that the server 300 responds to the read request transmitted by the acquired data. It is possible to identify whether the data is to be processed from the acquired data.
[0234]
[2-2-2] Processing related to the information processing method in the information processing system 1000 according to
 the second embodiment Next, an example of processing related to the information processing method in the information processing system 1000 according to the second embodiment will be described. To do.
[0235]
 FIG. 19 is an explanatory diagram showing an example of processing in the information processing system 1000 according to the second embodiment.
[0236]
 The server 300 transmits a random number (an example of information indicating a value; the same applies hereinafter) together with a read request (S300).
[0237]
 The reader / writer 200 that has received the read request and the random number transmitted from the server 300 in step S300 transmits the received read request and the random number to the information processing apparatus 100 (S302). As in step S102 of FIG. 11, the reader / writer 200 may encrypt the read request or the read request and the random number.
[0238]
 The information processing apparatus 100 that receives the read request and the random number transmitted from the reader / writer 200 in step S302 generates an electronic signature (S304). Then, the information processing apparatus 100 transmits an electronic signature together with the data corresponding to the area indicated by the read request (S306). The information processing apparatus 100 may encrypt the data corresponding to the area indicated by the read request with the encryption key corresponding to the area indicated by the read request, as in step S104 of FIG.
[0239]
 FIG. 20 is an explanatory diagram for explaining an example of processing in the information processing system 1000 according to the second embodiment, and shows an example of data transmitted by the information processing apparatus 100 in step S306 of FIG.
[0240]
 For example, as shown in FIG. 20, the information processing apparatus 100 transmits the data corresponding to the area indicated by the read request and the electronic signature as one data. The information processing device 100 may transmit the data corresponding to the area indicated by the read request and the electronic signature as separate data.
[0241]
 An example of processing in the information processing system 1000 according to the second embodiment will be described with reference to FIG. 19 again. In step S306, the reader / writer 200 that has received the data transmitted from the information processing apparatus 100 (for example, the data corresponding to the area indicated by the read request and the data including the electronic signature as shown in FIG. 20) receives the received data. It is transmitted to the server 300 (S308).
[0242]
 The server 300 that receives the data transmitted from the reader / writer 200 in step S308 (for example, the data corresponding to the area indicated by the read request and the data including the electronic signature as shown in FIG. 20) verifies the electronic signature (as shown in FIG. 20). S310).
[0243]
 Then, when the verification result is normal, the server 300 uses the acquired data (or the data obtained by decoding the acquired data) for arbitrary processing. Further, when the verification result is not normal, the server 300 does not use the acquired data (or the decrypted data of the acquired data) for arbitrary processing.
[0244]
 In the information processing system 1000 according to the second embodiment, for example, by performing the process shown in FIG. 19, the server 300 has acquired whether the acquired data is the data corresponding to the transmitted read request. It can be identified from the data.
[0245]
 Further, in the information processing system 1000 according to the second embodiment, the same processing as that of the information processing system 1000 according to the first embodiment may be further performed. Therefore, the information processing system 1000 according to the second embodiment can exert the effect produced by the information processing system 1000 according to the first embodiment.
[0246]
[2-2-3] Operations and effects of
 the information processing system 1000 according to the second embodiment In the second information processing system 1000, for example, the following operations are realized, and the second information processing system 1000 By using, for example, the following effects are produced. Needless to say, the operation of the information processing system 1000 according to the second embodiment and the effect produced by using the information processing system according to the second embodiment are not limited to the examples shown below. No.
  A value (for example, a random number) generated by the server 300 is passed to the information processing device 100 as a parameter of the read request. Further, as a parameter of the read request, a value (for example, a random number) generated by the reader / writer 200 may be passed to the information processing apparatus 100.
  The information processing device 100 generates an electronic signature (MAC when a common key cryptosystem is used) for the data to be read (data before encryption or data after encryption) and a random number, and reads the data together with the data. / Send to writer 200.
  -The information processing device 100 generates an electronic signature using, for example, a key associated with an area.
  -The server 300 (or reader / writer 200) can determine whether the data is read this time by verifying the electronic signature, and can also detect falsification of the read data.
[0247]
[2-3] Information processing method according to the third embodiment
[2-3-1] Outline of the information processing system 1000 to which the information processing method according to the third embodiment is applied
 For example, information on the configuration shown in FIG. In the processing system 1000, the communication from the reader / writer 200 to the information processing device 100 may be tampered with by a method such as an intermediate attack. As an example of falsification, the area to be read indicated by the information indicating the area included in the read request may be rewritten.
[0248]
 FIG. 21 is an explanatory diagram showing an example of a case where the communication from the reader / writer 200 to the information processing device 100 is falsified. In FIG. 21, a device that falsifies the communication from the reader / writer 200 to the information processing device 100 by a man-in-the-middle attack or the like is shown as “attacker X”.
[0249]
 The reader / writer 200 transmits a read request to the information processing device 100 (S50) in the same manner as in step S102 shown in FIG.
[0250]
 Upon receiving the read request transmitted from the reader / writer 200 in step S50, the attacker X falsifies the read target area indicated by the information indicating the area included in the read request (S52). Then, the attacker X transmits the falsified read request to the information processing device 100 (S54).
[0251]
 The information processing device 100 that has received the read request transmitted from the attacker X in step S54 encrypts and encrypts the data corresponding to the area indicated by the read request, similarly to steps S104 and S106 shown in FIG. Data is transmitted (S56).
[0252]
 For example, in the example shown in FIG. 21, the information processing apparatus 100 reads data from an area different from the area indicated by the read request transmitted from the reader / writer 200 in step S50 (data read from an erroneous area). ) Will be sent.
[0253]
 Therefore, in the information processing system 1000 according to the third embodiment, the information processing device 100 uses the data corresponding to the area indicated by the read request, the information included in the read request, and the encryption key corresponding to the area indicated by the read request. From, the electronic signature is generated. Examples of the information included in the read request according to the present embodiment include read request parameters such as information indicating an area. Then, the information processing apparatus 100 transmits the generated electronic signature together with the data corresponding to the area indicated by the read request. Here, the data transmitted by the information processing device 100 may or may not be encrypted.
[0254]
 FIG. 22 is an explanatory diagram for explaining an example of processing related to the information processing method in the information processing apparatus 100 according to the third embodiment, and shows an example of generating an electronic signature. The example of generating an electronic signature shown in FIG. 22 is an example of generating an electronic signature when the information processing method according to the second embodiment and the information processing method according to the third embodiment are combined.
[0255]
 As shown in FIG. 22, the information processing apparatus 100 includes, for example, data corresponding to the region indicated by the read request, a random number (an example of a value indicated by the information indicating the value), and a read request parameter (information included in the read request). , And the encryption key corresponding to the area indicated by the read request is used to generate an electronic signature by performing an operation of an arbitrary algorithm.
[0256]
 When the electronic signature is generated only by the information processing method according to the third embodiment, the information processing device 100 does not have to generate the electronic signature by using the random numbers shown in FIG. That is, the information processing apparatus 100 according to the third embodiment has at least electronic data from the data corresponding to the area indicated by the read request, the information included in the read request, and the encryption key corresponding to the area indicated by the read request. Generate a signature.
[0257]
 The processing in the information processing apparatus 100 is not limited to the example shown above.
[0258]
 For example, when the common key cryptosystem is used and information indicating a value is acquired together with the read request, the information processing apparatus 100 generates a MAC based on the read request parameter (information included in the read request). , The generated MAC may be transmitted together with the data corresponding to the area indicated by the read request. Here, the data transmitted by the information processing device 100 may or may not be encrypted.
[0259]
 The server 300 that has acquired the data transmitted from the information processing device 100 and the electronic signature (or MAC) verifies the acquired electronic signature. The verification of the electronic signature may be performed by the reader / writer 200. By verifying the electronic signature, the information processing system 1000 according to the third embodiment can confirm whether the read request has been tampered with.
[0260]
 Further, in the information processing system 1000 according to the third embodiment, the same processing as one or both of the information processing system 1000 according to the first embodiment and the information processing system 1000 according to the second embodiment can be performed. Further may be done. Therefore, the information processing system 1000 according to the third embodiment has an effect produced by one or both of the information processing system 1000 according to the first embodiment and the information processing system 1000 according to the second embodiment. It is possible to play.
[0261]
[2-3-2] Processing related to the information processing method in the information processing system 1000 according to
 the third embodiment Next, an example of processing related to the information processing method in the information processing system 1000 according to the third embodiment will be described. To do.
[0262]
 FIG. 23 is an explanatory diagram showing an example of processing in the information processing system 1000 according to the third embodiment. FIG. 23 shows an example of processing when the information processing method according to the first embodiment to the information processing method according to the third embodiment are combined.
[0263]
 The server 300 transmits a random number together with the read request (S400) in the same manner as in step S300 of FIG. If the processing related to the information processing method according to the second embodiment is not performed, the server 300 does not have to transmit the random number.
[0264]
 The reader / writer 200 that has received the read request and the random number transmitted from the server 300 in step S400 transmits the received read request and the random number to the information processing device 100 in the same manner as in step S300 of FIG. 19 (S402).
[0265]
 The information processing apparatus 100 that receives the read request and the random number transmitted from the reader / writer 200 in step S402 generates an electronic signature in the same manner as in FIG. 22 (S404). Then, the information processing apparatus 100 transmits an electronic signature together with the data corresponding to the area indicated by the read request (S406).
[0266]
 The reader / writer 200 that has received the data transmitted from the information processing device 100 in step S406 transmits the received data to the server 300 (S408).
[0267]
 The server 300 that has received the data transmitted from the reader / writer 200 in step S408 verifies the electronic signature (S410).
[0268]
 Then, when the verification result is normal, the server 300 determines that the read request has not been tampered with. Then, the server 300 decrypts the acquired encrypted data and uses the decrypted data for arbitrary processing.
[0269]
 Further, when the verification result is not normal, the server 300 does not process the acquired encrypted data, assuming that the read request has been tampered with.
[0270]
 In the information processing system 1000 according to the third embodiment, for example, by performing the process shown in FIG. 23, the server 300 can confirm whether the read request has been tampered with.
[0271]
[2-3-3] Operation and effect of
 the information processing system 1000 according to the third embodiment In the third information processing system 1000, for example, the following operations are realized, and the third information processing system 1000 is also realized. By using, for example, the following effects are produced. Needless to say, the operation of the information processing system 1000 according to the third embodiment and the effect produced by using the information processing system according to the third embodiment are not limited to the examples shown below. No.
  In response to the read request, the information processing apparatus 100 digitally signs (common key encryption) the data to be read (data before encryption or data after encryption) and the parameters of the read request (for example, designation of the read destination). If the method is used, MAC) is generated and transmitted to the reader / writer 200 together with the data.
  -The information processing device 100 generates an electronic signature using, for example, a key associated with an area.
  -The server 300 (or reader / writer 200) can confirm that the parameters of the read request have not been tampered with by verifying the electronic signature.
[0272]
[2-4] Information processing method according to the fourth embodiment
[2-4-1] Outline of the information processing system 1000 to which the information processing method according to the fourth embodiment is applied
 For example, information on the configuration shown in FIG. In the processing system 1000, the encrypted data transmitted from the information processing device 100 to the reader / writer 200 is observed by a third party, so that the encrypted data can be obtained even if the content of the data is unknown. There is a possibility that a third party can determine whether or not the data is the same.
[0273]
 FIG. 24 is an explanatory diagram showing an example of a case where the encrypted data transmitted from the information processing device 100 to the reader / writer 200 is observed by a third party. FIG. 24 shows readers / writers 200A and 200B having the same functions as the reader / writer 200 shown in FIG.
[0274]
 The reader / writer 200A transmits a read request to the information processing device 100 (S60) in the same manner as in step S102 shown in FIG.
[0275]
 The information processing apparatus 100 that received the read request transmitted from the reader / writer 200A in step S60 encrypts the data corresponding to the area indicated by the read request and encrypts the data, as in steps S104 and S106 shown in FIG. The data is transmitted (S62).
[0276]
 The reader / writer 200B transmits a read request to the information processing device 100 (S64) in the same manner as in step S102 shown in FIG.
[0277]
 The information processing apparatus 100 that has received the read request transmitted from the reader / writer 200B in step S64 encrypts the data corresponding to the area indicated by the read request and encrypts the data, as in steps S104 and S106 shown in FIG. The data is transmitted (S66).
[0278]
 For example, in the example shown in FIG. 24, the observer compares the encrypted data transmitted in step S62 with the encrypted data transmitted in step S66 to obtain unencrypted data (plaintext). ) Are the same or not.
[0279]
 Therefore, in the information processing system 1000 according to the fourth embodiment, the information processing device 100 generates, for example, an encryption key corresponding to the read request for each acquired read request. The information processing device 100 generates an encryption key corresponding to the read request based on the encryption key corresponding to the area indicated by the acquired read request and the value corresponding to the read request different for each acquired read request. .. The encryption key corresponding to the read request is generated by performing an operation of an arbitrary encryption key generation algorithm using the encryption key corresponding to the area indicated by the read request and the value corresponding to the read request.
[0280]
 The value corresponding to the read request according to the present embodiment is generated, for example, by the information processing device 100 generating a random number, or by the information processing device 100 reading the value of the counter circuit included in the information processing device 100. Be identified.
[0281]
 In the following, in order to distinguish between the encryption key corresponding to the read request and the encryption key corresponding to the area indicated by the read request, the encryption key corresponding to the read request may be referred to as an “encryption key”.
[0282]
 The encryption key is generated by generating an encryption key (encryption key corresponding to the read request) using the encryption key corresponding to the area indicated by the read request and the value corresponding to the read request different for each read request. , The encryption key is different for each read request.
[0283]
 Therefore, even if the data before encryption is the same, the data encrypted based on the read request is different for each read request acquired by the information processing apparatus 100.
[0284]
 Further, the information processing apparatus 100 may use the generated encryption key as a signature encryption key used for generating an electronic signature according to the information processing method according to the present embodiment described above.
[0285]
 FIG. 25 is an explanatory diagram for explaining an example of processing related to the information processing method in the information processing apparatus 100 according to the fourth embodiment, and shows an example of an encryption key (encryption key corresponding to a read request). ing.
[0286]
 Further, FIG. 25 shows an example in which the encryption key is also used as the signature encryption key. Similar to FIG. 22, the electronic signature generation example shown in FIG. 25 is an electronic signature when the information processing method according to the second embodiment and the information processing method according to the third embodiment are combined. Is an example of generation.
[0287]
 As shown in FIG. 25, the information processing apparatus 100 generates an encryption key from, for example, an encryption key corresponding to an area indicated by a read request and a random number C (an example of a value corresponding to the read request). Then, the information processing apparatus 100 encrypts the plaintext data (data corresponding to the area indicated by the read request) by using the generated encryption key. Further, the information processing apparatus 100 uses the generated encryption key instead of the encryption key corresponding to the area indicated by the read request to generate an electronic signature as in FIG. 22.
[0288]
 The information processing device 100 transmits data encrypted using the generated encryption key and a value corresponding to the read request used for generating the encryption key. Further, when the electronic signature is generated as shown in FIG. 25, the information processing apparatus 100 may further transmit the generated electronic signature.
[0289]
 A legitimate encryption key such as the server 300 by "the information processing apparatus 100 transmits the data encrypted by using the encryption key and the value corresponding to the read request used for generating the encryption key". The device having the above can decrypt the encrypted data.
[0290]
 The processing in the information processing apparatus 100 is not limited to the example shown above.
[0291]
 For example, the information processing apparatus 100 generates an encryption key corresponding to the area indicated by the read request and an encryption key (encryption key corresponding to the read request) based on the setting information associated with the area of ​​the recording medium. Identify if you want to.
[0292]
 Whether to generate the encryption key is specified, for example, by referring to the encryption key generation necessity information included in the setting information.
[0293]
 For example, when the encryption key generation necessity information indicates "always generate an encryption key corresponding to a read request", the information processing apparatus 100 generates an encryption key as shown in FIG. 25. , Encrypt the data corresponding to the area indicated by the read request with the encryption key. Further, for example, when the encryption key generation necessity information indicates that "the encryption key corresponding to the read request is not always generated", the information processing apparatus 100 reads the data corresponding to the area indicated by the read request. Encrypt with the encryption key corresponding to the area indicated by the request.
[0294]
 Further, for example, when the encryption key generation necessity information indicates "according to the read request", the information processing apparatus 100 determines whether or not to generate the "encryption key corresponding to the read request" included in the read request. An encryption key is selectively generated according to the data shown (an example of information on encryption). In this case, the information processing apparatus 100 encrypts the data corresponding to the area indicated by the read request with the encryption key corresponding to the area indicated by the read request or the generated encryption key.
[0295]
 As described above, in the information processing system 1000 according to the fourth embodiment, the information processing device 100 encrypts the data with the encryption key, so that even if the data before encryption is the same, a read request is made. The data encrypted based on the above is different for each read request acquired by the information processing apparatus 100.
[0296]
 Therefore, in the information processing system 1000 according to the fourth embodiment, "a third party can determine whether or not the encrypted data is the same data" is prevented.
[0297]
 Further, in the information processing system 1000 according to the fourth embodiment, the same processing as one or more of the information processing system 1000 according to the first embodiment to the information processing system 1000 according to the third embodiment is further performed. It may be done. Therefore, the information processing system 1000 according to the fourth embodiment has the effect of being exerted by one or more of the information processing system 1000 according to the first embodiment to the information processing system 1000 according to the third embodiment. , It is possible to play.
[0298]
[2-4-2] Processing related to the information processing method in the information processing system 1000 according to
 the fourth embodiment Next, an example of processing related to the information processing method in the information processing system 1000 according to the fourth embodiment will be described. To do.
[0299]
 FIG. 26 is an explanatory diagram showing an example of processing in the information processing system 1000 according to the fourth embodiment. FIG. 26 shows an example of processing when the information processing method according to the first embodiment to the information processing method according to the third embodiment are combined.
[0300]
 The server 300 transmits the random number R together with the read request (S500) in the same manner as in step S300 of FIG. If the processing related to the information processing method according to the second embodiment is not performed, the server 300 does not have to transmit the random number.
[0301]
 The reader / writer 200 that has received the read request and the random number R transmitted from the server 300 in step S500 transmits the received read request and the random number R to the information processing device 100 in the same manner as in step S300 of FIG. 19 (S502). ).
[0302]
 The information processing apparatus 100 that has received the read request and the random number R transmitted from the reader / writer 200 in step S502 encrypts the data corresponding to the area indicated by the read request and generates an electronic signature (as in FIG. 25). S504). Then, the information processing apparatus 100 transmits a random number C (an example of a value corresponding to the read request) and an electronic signature together with the encrypted data (S506).
[0303]
 The reader / writer 200 that has received the data transmitted from the information processing apparatus 100 in step S506 transmits the received data to the server 300 (S508).
[0304]
 The server 300, which has received the data transmitted from the reader / writer 200 in step S508, decrypts the encrypted data and verifies the electronic signature (S510).
[0305]
 Then, when the verification result is normal, the server 300 uses the decoded data for arbitrary processing. Further, the server 300 does not use the decoded data for arbitrary processing when the verification result is not normal.
[0306]
 In the information processing system 1000 according to the fourth embodiment, for example, by performing the process shown in FIG. 26, "a third party can determine whether or not the encrypted data is the same data." "Is prevented.
[0307]
[2-4-3] Operations and Effects of
 the Information Processing System 1000 According to the Fourth Embodiment In the fourth information processing system 1000, for example, the following operations are realized, and the fourth information processing system 1000 is also realized. By using, for example, the following effects are produced. Needless to say, the operation of the information processing system 1000 according to the fourth embodiment and the effect produced by using the information processing system according to the fourth embodiment are not limited to the examples shown below. No.
  The information processing device 100 generates different values ​​(random numbers, counter values ​​held in the information processing device 100, etc.) for each read request.
  When the information processing device 100 encrypts the data to be read, it encrypts the data with an encryption key generated from a different value for each read request.
  The information processing device 100 transmits the encrypted data and a different value for each read request to the reader / writer 200.
  Whether or not the information processing device 100 generates an encryption key from a different value for each read request, and which key is used to generate the encryption key when a plurality of keys are linked to the area. , Determined based on the setting information preset in the area.
  -For the area set as "It is not necessary to generate the encryption key", whether or not to generate the encryption key is also determined by the read request parameter (an example of information related to encryption). Can be specified. In addition, which key is used for the area set as "an encryption key may or may not be generated" can also be specified by a read request parameter (an example of information on encryption). ..
[0308]
[2-5] Information processing method according to the fifth embodiment
[2-5-1] Outline of the information processing system 1000 to which the information processing method according to the fifth embodiment is applied
 For example, information on the configuration shown in FIG. In the processing system 1000, when the information processing device 100 fails to read the data in response to the read request and the information processing device 100 transmits error information indicating an error, the information processing device 100 sends the reader / writer 200 to the reader / writer 200. By observing the transmitted data by a third party, it may be possible for the third party to determine that an error has occurred. For example, when the data length of the error information is determined by the standard or the like, the error occurs regardless of the presence or absence of encryption depending on the data length of the data transmitted from the information processing device 100 to the reader / writer 200. There is a possibility that a third party can determine.
[0309]
 FIG. 27 is an explanatory diagram showing an example of a case in which data transmitted from the information processing device 100 to the reader / writer 200 is observed by a third party and it is determined that an error has occurred.
[0310]
 The reader / writer 200 transmits a read request to the information processing device 100 (S70) in the same manner as in step S102 shown in FIG.
[0311]
 The information processing apparatus 100 that has received the read request transmitted from the reader / writer 200 in step S70 transmits error information when the area indicated by the read request does not exist (S72).
[0312]
 For example, in the example shown in FIG. 27, the observer may be able to determine that an error has occurred regardless of the presence or absence of encryption, depending on the data length of the data transmitted in step S72. Further, in the example shown in FIG. 27, the observer may identify the cause of the error, such as the area indicated by the read request does not exist.
[0313]
 Therefore, in the information processing system 1000 according to the fifth embodiment, the information processing apparatus 100 uses a predetermined encryption key to obtain error information and dummy data, for example, when data cannot be read from the area indicated by the read request. Encrypt.
[0314]
 Examples of the dummy data according to the present embodiment include random number data and all-zero data. For example, if the data length when the data is normally read in response to the read request is determined by the standard, the data length of the dummy data is "subtract the data length of the error information from the determined data length. It may be the "data length".
[0315]
 As the predetermined encryption key according to the fifth embodiment, for example, the encryption key corresponding to the area indicated by the read request or the encryption key (encryption key corresponding to the read request) shown in the fourth embodiment is used. , Can be mentioned.
[0316]
 FIG. 28 is an explanatory diagram for explaining an example of processing related to an information processing method in the information processing apparatus 100 according to the fifth embodiment. FIG. 28 shows an example in which error information and dummy data are encrypted using an encryption key (an encryption key corresponding to a read request). Further, FIG. 28 shows an example in which the encryption key is also used as the signature encryption key, as in FIG. 25.
[0317]
 As shown in FIG. 28, similarly to FIG. 25, the information processing apparatus 100 uses an encryption key corresponding to the area indicated by the read request and a random number C (an example of a value corresponding to the read request) to obtain an encryption key. Generate. Then, the information processing apparatus 100 encrypts the error information and the dummy data by using the generated encryption key. Further, the information processing apparatus 100 generates an electronic signature as in FIG. 25.
[0318]
 When the error information and the dummy data are encrypted, the information processing apparatus 100 transmits the encrypted data. That is, the encrypted data transmitted by the information processing device 100 is different from the data in which the error information is simply encrypted.
[0319]
 Therefore, in the information processing system 1000 according to the fifth embodiment, even if the data transmitted from the information processing device 100 to the reader / writer 200 is observed by a third party, an error has occurred. It is difficult for a third party to determine.
[0320]
[2-5-2] Processing related to the information processing method in the information processing system 1000 according to
 the fifth embodiment Next, an example of processing related to the information processing method in the information processing system 1000 according to the fifth embodiment will be described. To do.
[0321]
 In the information processing system 1000 according to the fifth embodiment, basically, the process shown in FIG. 11 (process related to the information processing method in the information processing system 1000 according to the first embodiment) and the process shown in FIG. 19 (the first). The process related to the information processing method in the information processing system 1000 according to the second embodiment), the process shown in FIG. 23 (the process related to the information processing method in the information processing system 1000 according to the third embodiment), and FIG. 26. It is possible to perform the same processing as the processing (processing related to the information processing method in the information processing system 1000 according to the fourth embodiment). The difference from these processes is that the information processing apparatus 100 according to the fifth embodiment uses a predetermined encryption key to obtain error information and dummy data when data cannot be read from the area indicated by the read request. The point is to encrypt with and send the encrypted data.
[0322]
[2-5-3] Operations and Effects of
 the Information Processing System 1000 According to the Fifth Embodiment In the fifth information processing system 1000, for example, the following operations are realized, and the fifth information processing system 1000 is also realized. By using, for example, the following effects are produced. Needless to say, the operation of the information processing system 1000 according to the fifth embodiment and the effect produced by using the information processing system according to the fifth embodiment are not limited to the examples shown below. No.
  When an error occurs, the information processing device 100 transmits error information and dummy data (for example, random number data or all-zero data) to the reader / writer 200. The information processing device 100 encrypts the dummy data and the error information.
[0323]
[2-6] Information processing method according to the sixth embodiment
[2-6-1] Outline of the information processing system 1000 to which the information processing method according to the sixth embodiment is applied
 For example, identification information such as an ID is provided. When stored in the information processing device 100, the external device of the information processing device 100 such as the server 300 and the reader / writer 200 performs various processes using the identification information stored in the information processing device 100. Is possible.
[0324]
 Here, assuming a use case in which the identification information stored in the information processing apparatus 100 is used by a plurality of businesses, there are the following concerns.
  -If one business operator links the identification information to important information, there is a possibility that the important information can be reached from the identification information read by another business operator. For example, "The national number (an example of identification information) read from the reader / writer of a general store is linked to the national number by being passed to a person who has access authority to the national number database. It is conceivable that the tax payment information (an example of important information) that is attached will be referred to.
  -If the identification information can be read without authentication, there is a possibility that a third party may reach the above important information from the identification information.
  -If the identification information can be read only after authentication, the authentication encryption key for reading the identification information is also used by a plurality of businesses, so that the risk of leakage of the authentication encryption key increases.
[0325]
 FIG. 29 is an explanatory diagram showing an example of a case where the identification information stored in the information processing device is used by a plurality of businesses. In FIG. 29, the ID is shown as the identification information.
[0326]
 As shown in FIG. 29, the ID stored in the information processing apparatus may be managed by a database managed by a plurality of businesses. As shown in FIG. 29, when the business operator A causes the business operator B to use the ID stored in the information processing device, there is a risk as in the above-mentioned concern.
[0327]
 Therefore, in the information processing system 1000 according to the sixth embodiment, the information processing apparatus 100 uses the processing related to the information processing method according to the first embodiment to the processing related to the information processing method according to the fifth embodiment. By performing the above, the data corresponding to the area indicated by the read request is transmitted.
[0328]
 Further, in the information processing system 1000 according to the sixth embodiment, when the data acquired from the information processing apparatus 100 includes the first identification information, the server 300 distinguishes the first identification information into a different second identification. Convert to information.
[0329]
 Examples of the first identification information include arbitrary IDs such as the ID of the information processing device 100 and the ID of the service. Further, as the second identification information, an arbitrary ID different from the first identification information, such as an ID of a service different from the service to which the first identification information corresponds, can be mentioned.
[0330]
 The server 300 obtains the first identification information by referring to, for example, "a table (or database) in which the first identification information, the second identification information, and the conversion destination identification information are associated". Convert to the second identification information. Data indicating a destination for transmitting the second identification information (for example, data indicating an IP (Internet Protocol) address, an e-mail address, or the like) may be further associated with the table. In the following, the above table will be referred to as a “conversion table”.
[0331]
 Here, the conversion destination identification information is data for uniquely identifying the second identification information associated with the first identification information. The conversion destination identification information includes, for example, an ID of a reader / writer (an example of a relay device) that relays data transmitted from the information processing device 100, an ID of a device that requests the server 300 to transmit a read request, and the like. , Arbitrary data that can identify the target (such as a business operator) for which the second identification information is provided.
[0332]
 The server 300 converts the first identification information into the second identification information by performing an arbitrary algorithm processing capable of converting the first identification information into the second identification information. May be good.
[0333]
 When the first identification information is converted into the second identification information, the server 300 transmits the second identification information to the external device corresponding to the second identification information.
[0334]
 In the information processing system 1000 according to the sixth embodiment, the server 300 converts the first identification information into the second identification information and sends the second identification information to the external device corresponding to the second identification information. To send.
[0335]
 Therefore, in the information processing system 1000 according to the sixth embodiment, "the identification information stored in the information processing device 100 is not shared by a plurality of business operators, and each business operator provides a service based on the identification information. "To do" is realized. That is, in the information processing system 1000 according to the sixth embodiment, the above-mentioned concern does not occur.
[0336]
[2-6-2] Processing related to the information processing method in the information processing system 1000 according to
 the sixth embodiment Next, an example of processing related to the information processing method in the information processing system 1000 according to the sixth embodiment will be described. To do.
[0337]
 FIG. 30 is an explanatory diagram showing an example of a use case to which the information processing system 1000 according to the sixth embodiment is applied. In FIG. 30, the information processing device 100 corresponding to the business operator A is shown as "information processing device 100A". Further, in FIG. 30, the reader / writer 200 corresponding to the business operator B is shown as “leader / writer 200B”. Further, in FIG. 30, the server 300 corresponding to the business operator A is referred to as “server 300A”, and the server 300 corresponding to the business operator B is referred to as “server 300B”.
[0338]
 When the data corresponding to the area indicated by the read request is ID A (an example of the first identification information), the information processing apparatus 100A encrypts the ID A. In the following, the encrypted ID will be referred to as an “anonymized ID”. Examples of the anonymization ID include a value generated by a reversible operation from a secret key value.
[0339]
 FIG. 31 is an explanatory diagram for explaining an example of processing related to the information processing method in the information processing apparatus 100A according to the sixth embodiment. FIG. 31 shows an example in which the information processing apparatus 100A encrypts the ID A and generates an electronic signature as in FIG. 25 .
[0340]
 The information processing device 100A transmits data including an anonymization ID to the reader / writer 200.
[0341]
 The reader / writer 200B that has received the data including the anonymization ID transmits the data including the received anonymization ID to the server 300A. The transmission destination to which the reader / writer 200B transmits data may be set in advance, or may be determined by the data included in the read request or the like.
[0342]
 The server 300A that has received the data including the anonymization ID decodes the anonymization ID and acquires the ID A. When the ID A is acquired, the server 300A converts the ID A into the ID B (second identification information).
[0343]
 Then, the server 300A transmits the ID B to the server 300B. The server 300A identifies the destination to which the ID B is transmitted , for example, by referring to the data indicating the destination recorded in the conversion table .
[0344]
 ID B server 300B that has received the received ID B identify and points associated with the (one example of data associated with the second identification information), to any processing identified points Use.
[0345]
 FIG. 32 is an explanatory diagram showing an example of processing in the information processing system 1000 according to the sixth embodiment, and shows an example of processing corresponding to the use case shown in FIG. FIG. 32 shows an example of processing when the information processing method according to the first embodiment to the information processing method according to the third embodiment are combined as in FIG. 26. Further, in FIG. 32, it is assumed that the read request is a read request for reading ID A.
[0346]
 The server 300A transmits the random number R together with the read request (S600) in the same manner as in step S300 of FIG.
[0347]
 The reader / writer 200B that has received the read request and the random number R transmitted from the server 300A in step S600 transmits the received read request and the random number R to the information processing device 100A in the same manner as in step S300 of FIG. 19 (S602). ). The read request and the random number R received by the reader / writer 200B do not have to be transmitted from the server 300A.
[0348]
 The information processing apparatus 100A that has received the read request and the random number R transmitted from the reader / writer 200B in step S602 generates an anonymization ID and an electronic signature as in FIG. 31 (S604). Then, the information processing apparatus 100A transmits a random number C (an example of a value corresponding to the read request) and an electronic signature together with the anonymization ID (S606).
[0349]
 The reader / writer 200B that has received the data transmitted from the information processing apparatus 100A in step S606 transmits the received data to the server 300A (S608).
[0350]
 The server 300A that has received the data transmitted from the reader / writer 200B in step S608 verifies the electronic signature, decodes the anonymized ID, and converts the decrypted ID A (S610).
[0351]
 The server 300A transmits the ID B whose ID A has been converted in step S610 to the server 300B (S612). The destination of the ID B is not limited to the server 300B, but may be another device such as a reader / writer 200B.
[0352]
 For example, the process shown in FIG. 31 realizes the use case described with reference to FIG. Needless to say, the process of realizing the use case described with reference to FIG. 30 is not limited to the example shown in FIG. 31.
[0353]
[2-6-3] Operations and Effects of
 the Information Processing System 1000 According to the Sixth Embodiment In the sixth information processing system 1000, for example, the following operations are realized, and the sixth information processing system 1000 By using, for example, the following effects are produced. Needless to say, the operation of the information processing system 1000 according to the sixth embodiment and the effect produced by using the information processing system according to the sixth embodiment are not limited to the examples shown below. No.
  When the ID is read from the information processing device 100, the information processing device 100 is not the ID itself, but the ID, the random number generated by the information processing device 100, and the anonymized ID (for example, generated by a reversible operation from a secret key value). The value) is transmitted to the reader / writer 200.
  -The reader / writer 200 transmits the anonymization ID to the server 300.
  -The server 300 obtains the original ID from the anonymized ID by an inverse calculation. Further, the server 300 converts the obtained ID into another ID used by another device.
  -The ID stored in the information processing device 100 is not disclosed to anyone other than the server 300.
[0354]
[2-7] Information Processing Method Related to Other Embodiments The processing related to the information processing method according to the
 present embodiment relates to the processing related to the information processing method according to the first embodiment to the sixth embodiment. It is not limited to the processing related to the information processing method.
[0355]
 For example, the process related to the information processing method according to the present embodiment includes two or more of the processes related to the information processing method according to the first embodiment to the processes related to the information processing method according to the sixth embodiment. It may be a combination of processes.
[0356]
(Program according to the present embodiment)
[I] Program for functioning as the information processing device (first information processing device) according
 to the present embodiment To function the computer system as the information processing device according to the present embodiment. When a program (for example, a program capable of realizing the function of the processing unit 110 shown in FIG. 2) is executed by a processor or the like in a computer system, "reading while ensuring safety related to reading data" is performed. An information processing system capable of reducing the processing time related to the above is realized. Here, examples of the computer system according to the present embodiment include a single computer or a plurality of computers. A series of processes is performed by the computer system according to the present embodiment.
[0357]
 Further, a program for causing the computer system to function as the information processing device according to the present embodiment is executed by a processor or the like in the computer system, and is played by the processing related to the information processing method according to each of the above-described embodiments. The effect can be achieved.
[0358]
[II] Program for functioning as a server (second information processing apparatus) according
 to the present embodiment A program for functioning the computer system as a server according to the present embodiment (for example, the processing unit 310 shown in FIG. 7). By executing a program that can realize a function) by a processor or the like in a computer system, "information that can reduce the processing time related to reading while ensuring the safety related to reading data". "Processing system" is realized.
[0359]
 Further, when the program for causing the computer system to function as the server according to the present embodiment is executed by a processor or the like in the computer system, the effect achieved by the processing related to the information processing method according to each of the above-described embodiments. Can be played.
[0360]
 Although the preferred embodiments of the present disclosure have been described in detail with reference to the accompanying drawings, the technical scope of the present disclosure is not limited to such examples. It is clear that a person having ordinary knowledge in the technical field of the present disclosure can come up with various modifications or modifications within the scope of the technical ideas described in the claims. Of course, it is understood that the above also belongs to the technical scope of the present disclosure.
[0361]
 For example, in the above, a program (computer program) for making the computer system function as an information processing device according to the present embodiment and a program (computer program) for making the computer system function as a server according to the present embodiment are provided. Although it has been shown that, the present embodiment can also provide a recording medium in which the above programs are stored, or a recording medium in which the above programs are stored together.
[0362]
 The configuration described above is an example of the present embodiment and, of course, belongs to the technical scope of the present disclosure.
[0363]
 In addition, the effects described herein are merely explanatory or exemplary and are not limited. That is, the techniques according to the present disclosure may exhibit other effects apparent to those skilled in the art from the description herein, in addition to or in place of the above effects.
[0364]
 The following configurations also belong to the technical scope of the present disclosure.
(1) When
 a read request including a data read command and information indicating an area of ​​the recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is transferred to the area indicated by the read request. An information processing device including a processing unit that encrypts data with a corresponding encryption key and transmits the encrypted data.
(2) The
 processing unit identifies the encryption key corresponding to the area indicated by the read request based on the setting information associated with the area of ​​the recording medium, and corresponds to the area indicated by the read request. The information processing device according to (1), which encrypts data with a specified encryption key.
(3)
 When the encryption key corresponding to the area indicated by the read request is not specified, the processing unit causes the data corresponding to the area indicated by the read request to be transmitted without encryption. The information processing device described.
(4) The
 processing unit
 determines whether or not to encrypt the data corresponding to the area indicated by the read request based on the setting information,
 and determines the data corresponding to the area indicated by the read request as a determination result. The information processing apparatus according to (2) or (3), which selectively encrypts data according to the above.
(5)
 When it is not determined that the data corresponding to the area indicated by the read request is encrypted, the
 processing unit performs the processing unit.
 Based on the encryption information included in the read request, the data corresponding to the area indicated by the read request is selectively encrypted, and
 the data corresponding to the area indicated by the read request or encrypted. The information processing apparatus according to (4), which transmits data.
(6)
 When the read request indicates a plurality of the regions, the processing unit encrypts each of the regions indicated by the read request with an encryption key corresponding to the region indicated by the read request (1). The information processing apparatus according to any one of (5).
(7)
 When the information indicating the value is acquired together with the read request, the
 processing unit has
 at least the data corresponding to the area indicated by the read request, the value indicated by the information indicating the value, and the read.
 The information processing apparatus according to any one of (1) to (6), wherein an electronic signature is generated from the encryption key corresponding to the area indicated by the request, and the generated electronic signature is further transmitted.
(8)
 When the read request indicates a plurality of the regions, the
 processing unit
 generates the electronic signature for each of the regions indicated by the read request, or
 corresponds to the plurality of the regions indicated by the read request. The electronic signature is generated from the data, the value indicated by the information indicating the value, and the signature encryption key generated based on the encryption key corresponding to the plurality of the regions indicated by the read request, according to (7). Information processing device.
(9) The
 processing unit
 signs an electronic signature from at least the data corresponding to the area indicated by the read request, the information included in the read request, and the encryption key corresponding to the area indicated by the read request.
 The information processing apparatus according to any one of (1) to (7), which is generated and further transmits the generated electronic signature.
(10) The
 processing unit
 generates an encryption key corresponding to the read request based on the encryption key corresponding to the area indicated by the read request and the value corresponding to the read request, and responds to the
 read request. When the corresponding encryption key is generated, the data corresponding to the area indicated by the read request is encrypted with the encrypted key corresponding to the generated read request, and the encrypted data and the read request are encrypted. The information processing apparatus according to any one of (1) to (9), which transmits a value corresponding to.
(11)  Whether the processing unit generates an encryption key corresponding to the area indicated by the read request and an encryption key corresponding to the read request based on the setting information associated with the area of
 the
recording medium. And
 , based on the specific result, the encryption key corresponding to the area indicated by the read request or the generated encryption key corresponding to the read request is used to correspond to the area indicated by the read request. The information processing apparatus according to (10), which encrypts data.
(12)
 When the data cannot be read from the area indicated by the read request, the
 processing unit encrypts the error information indicating the error and the dummy data with the encryption key corresponding to the area indicated by the read request. The information processing apparatus according to any one of 1) to (11).
(13) The
 acquired encrypted data is decrypted with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is changed to a different second identification information. An information processing device including a processing unit that converts and transmits the second identification information to an external device corresponding to the second identification information.
(14) When
 a read request including a data read command and information indicating an area of ​​the recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is transferred to the area indicated by the read request.  An information processing method executed by an information processing apparatus
 ,
which comprises a step of encrypting with a corresponding encryption key and a step of transmitting encrypted data .
(15) A second step
 in which the acquired encrypted data is decrypted with a predetermined encryption key and
 the first identification information is different from the first identification information when the decrypted data is the first identification information. An information  processing method executed by an information processing apparatus
 ,
which comprises a step of converting into identification information and a step of transmitting the second identification information to an external device corresponding to the second identification information .
(16) When
 a read request including a data read command and information indicating an area of ​​the recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is transferred to the area indicated by the read request.  A program that allows a computer to perform the steps of encrypting with the corresponding encryption key
 and sending the encrypted data
.
(17)
 A step of
 decrypting the acquired encrypted data with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is different from the second identification.  A program for causing a computer to perform a step of converting into information and a step
 of transmitting the second identification information to an external device corresponding to the second identification information
.
(18)
 and the first information processing apparatus,
 a second information processing apparatus,
 comprising a
 first information processing apparatus,
 including the information indicating the area of the recording medium to read the read instructions and data of the data When a read request is acquired, the data corresponding to the area indicated by the read request is encrypted with an encryption key corresponding to the area indicated by the read request, and a processing unit for transmitting the encrypted data is provided.
 The second information processing device is
 The acquired encrypted data is decrypted with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is converted into a different second identification information. An information processing system including a processing unit for transmitting the second identification information to an external device corresponding to the second identification information.
Code description
[0365]
 10, 100,
 100A Information processing device 20, 200, 200A, 200B Reader / writer
 30, 300, 300A, 300B Server
 102, 202 First communication unit
 104, 204 Second communication unit
 106, 206, 304 Control unit
 110, 210 , 310 Processing unit
 1000 Information processing system
The scope of the claims
[Claim 1]
 When a read request including a data read instruction and information indicating an area of ​​a recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is encrypted according to the area indicated by the read request. An information processing device including a processing unit that encrypts with a key and transmits the encrypted data.
[Claim 2]
 The processing unit identifies the encryption key corresponding to the area indicated by the read request based on the setting information associated with the area of ​​the recording medium, and obtains the data corresponding to the area indicated by the read request. The information processing device according to claim 1, which encrypts with the specified encryption key.
[Claim 3]
 The information according to claim 2, wherein when the encryption key corresponding to the area indicated by the read request is not specified, the processing unit transmits the data corresponding to the area indicated by the read request without encryption. Processing equipment.
[Claim 4]
 The processing unit
 determines whether or not to encrypt the data corresponding to the area indicated by the read request based on the setting information,
 and determines the data corresponding to the area indicated by the read request according to the determination result. The information processing apparatus according to claim 2, which selectively encrypts data.
[Claim 5]
 When it is not determined that the data corresponding to the area indicated by the read request is encrypted, the
 processing unit
 obtains the data corresponding to the area indicated by the read request based on the encryption information included in the read request.
 The information processing apparatus according to claim 4, wherein the information processing apparatus according to claim 4 is selectively encrypted to transmit data corresponding to the area indicated by the read request or encrypted data.
[Claim 6]
 The first aspect of the present invention, wherein when the read request indicates a plurality of the regions, the processing unit encrypts each of the regions indicated by the read request with an encryption key corresponding to the region indicated by the read request. Information processing device.
[Claim 7]
 When the information indicating the value is acquired together with the read request, the
 processing unit indicates
 at least the data corresponding to the region indicated by the read request, the value indicated by the information indicating the value, and the read request.
 The information processing apparatus according to claim 1, wherein an electronic signature is generated from the encryption key corresponding to the area, and the generated electronic signature is further transmitted.
[Claim 8]
 When the read request indicates a plurality of the regions, the
 processing unit
 generates the electronic signature for each of the regions indicated by the read request, or
 the data corresponding to the plurality of the regions indicated by the read request, said. The information processing apparatus according to claim 7, wherein the electronic signature is generated from the value indicated by the information indicating the value and the signature encryption key generated based on the encryption key corresponding to the plurality of the regions indicated by the read request. ..
[Claim 9]
 The processing unit
 generates an electronic signature from at least the data corresponding to the area indicated by the read request, the information included in the read request, and the encryption key corresponding to the area indicated by the read request.
 The information processing apparatus according to claim 1, wherein the generated electronic signature is further transmitted.
[Claim 10]
 The processing unit
 generates an encryption key corresponding to the read request based on the encryption key corresponding to the area indicated by the read request and the value corresponding to the
 read request, and the encryption corresponding to the read request. When the key is generated, the data corresponding to the area indicated by the read request is encrypted with the encryption key corresponding to the generated read request to correspond to the encrypted data and the read request. The information processing apparatus according to claim 1, wherein a value and a value are transmitted.
[Claim 11]
 The processing unit
 specifies whether to generate an encryption key corresponding to the area indicated by the read request and an encryption key corresponding to the read request based on the setting information associated with the area of the recording medium. ,
 Based on the specific result, the data corresponding to the area indicated by the read request is encrypted by using the encryption key corresponding to the area indicated by the read request or the generated encryption key corresponding to the read request. The information processing apparatus according to claim 10.
[Claim 12]
 When the data cannot be read from the area indicated by the read request, the
 processing unit encrypts the error information indicating the error and the dummy data with the encryption key corresponding to the area indicated by the read request. Item 1. The information processing apparatus according to item 1.
[Claim 13]
 The acquired encrypted data is decrypted with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is converted into a different second identification information. An information processing device including a processing unit that transmits the second identification information to an external device corresponding to the second identification information.
[Claim 14]
 When a read request including a data read instruction and information indicating an area of ​​a recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is encrypted according to the area indicated by the read request.  An information processing method executed by an information processing apparatus
 ,
which comprises a step of encrypting with a key and a step of transmitting encrypted data .
[Claim 15]
 The step of decrypting the acquired encrypted data with a predetermined encryption key, and when the
 decrypted data is the first identification information, the first identification information is changed to a different second identification information.  An information processing method executed by an information processing device ,
 comprising a step of converting and a step of transmitting the second identification information to an external device corresponding to the second identification information
.
[Claim 16]
 When a read request including a data read instruction and information indicating an area of ​​a recording medium for reading the data is acquired, the data corresponding to the area indicated by the read request is encrypted according to the area indicated by the read request.  A program that allows a computer to perform the steps of encrypting with a key
 and sending encrypted data
.
[Claim 17]
 A step of
 decrypting the acquired encrypted data with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is converted into a different second identification information. A  program for causing a computer to perform
 a step of transmitting the second identification information to an external device corresponding to the second identification information
.
[Claim 18]
 A first information processing apparatus,
 a second information processing apparatus,
 comprising a
 first information processing apparatus,
 the read request including the information indicating the area of the recording medium to read the read instructions and data of the data When acquired,
 the second unit includes a processing unit that encrypts the data corresponding to the area indicated by the read request with the encryption key corresponding to the area indicated by the read request and transmits the encrypted data . The information processing apparatus of
 the above decrypts the acquired encrypted data with a predetermined encryption key, and when the decrypted data is the first identification information, the first identification information is different from the second identification information. An information processing system including a processing unit that converts the second identification information into the identification information and transmits the second identification information to an external device corresponding to the second identification information.

Documents

Application Documents

# Name Date
1 202017032702-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [30-07-2020(online)].pdf 2020-07-30
2 202017032702-STATEMENT OF UNDERTAKING (FORM 3) [30-07-2020(online)].pdf 2020-07-30
3 202017032702-PRIORITY DOCUMENTS [30-07-2020(online)].pdf 2020-07-30
4 202017032702-POWER OF AUTHORITY [30-07-2020(online)].pdf 2020-07-30
5 202017032702-FORM 1 [30-07-2020(online)].pdf 2020-07-30
6 202017032702-DRAWINGS [30-07-2020(online)].pdf 2020-07-30
7 202017032702-DECLARATION OF INVENTORSHIP (FORM 5) [30-07-2020(online)].pdf 2020-07-30
8 202017032702-COMPLETE SPECIFICATION [30-07-2020(online)].pdf 2020-07-30
9 202017032702-Proof of Right [12-11-2020(online)].pdf 2020-11-12
10 202017032702.pdf 2021-10-19
11 202017032702-FORM 18 [09-12-2021(online)].pdf 2021-12-09
12 202017032702-FER.pdf 2022-05-31
13 202017032702-PETITION UNDER RULE 137 [30-11-2022(online)].pdf 2022-11-30
14 202017032702-OTHERS [30-11-2022(online)].pdf 2022-11-30
15 202017032702-FER_SER_REPLY [30-11-2022(online)].pdf 2022-11-30
16 202017032702-DRAWING [30-11-2022(online)].pdf 2022-11-30
17 202017032702-CORRESPONDENCE [30-11-2022(online)].pdf 2022-11-30
18 202017032702-COMPLETE SPECIFICATION [30-11-2022(online)].pdf 2022-11-30
19 202017032702-CLAIMS [30-11-2022(online)].pdf 2022-11-30
20 202017032702-ABSTRACT [30-11-2022(online)].pdf 2022-11-30
21 202017032702-US(14)-HearingNotice-(HearingDate-21-05-2024).pdf 2024-04-17
22 202017032702-Correspondence to notify the Controller [20-05-2024(online)].pdf 2024-05-20
23 202017032702-Written submissions and relevant documents [05-06-2024(online)].pdf 2024-06-05
24 202017032702-PatentCertificate27-06-2024.pdf 2024-06-27
25 202017032702-IntimationOfGrant27-06-2024.pdf 2024-06-27

Search Strategy

1 SearchE_28-05-2022.pdf

ERegister / Renewals

3rd: 16 Aug 2024

From 22/01/2021 - To 22/01/2022

4th: 16 Aug 2024

From 22/01/2022 - To 22/01/2023

5th: 16 Aug 2024

From 22/01/2023 - To 22/01/2024

6th: 16 Aug 2024

From 22/01/2024 - To 22/01/2025

7th: 16 Aug 2024

From 22/01/2025 - To 22/01/2026