Abstract: [Problem] It is desirable to provide a technology for enabling authentication even at a terminal that cannot perform RF communication. [Solution] Provided is an information processing device provided with: a code generation unit that generates a code in which a part of information required for authentication and identification information are embedded; a display control unit that controls display of the code; and an authentication unit that, after a part of authentication is performed on the basis of the part of information required for authentication and connection based on the identification information included in the code is established, performs the remaining part of authentication by using the established connection.
Title of invention: Information processing device, information processing system and program
Technical field
[0001]
The present disclosure relates to an information processing device, an information processing system, and a program.
Background technology
[0002]
In recent years, an RF communication function such as a communication function by NFC (Near Field Communication) may be used for communication with a reader/writer for a reading process or a writing process for a non-contact IC card. However, in some regions, many mobile terminals that do not have the RF communication function (for example, terminals that do not have a CLF (Contact Less Frontend) chip) are sold. Such an actual situation may be an obstacle to improving the mounting rate of the non-contact IC card function in the mobile terminal.
[0003]
On the other hand, as an alternative to the communication using the RF communication function, it is assumed that the communication between the non-contact IC card and the reader/writer is performed on the P2P communication path generated by the connection establishment using the two-dimensional code. For example, a technique for exchanging information necessary for connection between devices by a barcode is disclosed (for example, refer to Patent Document 1). In addition, a technique for realizing payment by wireless communication by exchanging image information in which address information is embedded is disclosed (for example, see Patent Document 2).
Prior art documents
Patent literature
[0004]
Patent Document 1: Japanese Patent Application Laid-Open No. 2002-063652
Patent Document 2: Japanese Patent Application Laid-Open No. 2002-251653
Summary of the invention
Problems to be Solved by the Invention
[0005]
As described above, there are portable terminals that do not have the RF communication function (for example, terminals that do not have a CLF chip). In such a terminal, RF communication is impossible. Therefore, it is desirable to provide a technique that enables authentication even in a terminal that cannot perform RF communication.
Means for solving the problem
[0006]
According to the present disclosure, a code generation unit that generates a code in which a part of the information necessary for authentication and the identification information are embedded, a display control unit that controls the display of the code, and the information necessary for the authentication. A part of the authentication is performed based on the part, and after the connection based on the identification information included in the code is established, an authentication unit that performs the rest of the authentication using the established connection, An information processing device is provided.
[0007]
According to the present disclosure, a code generation unit that generates a code in which a part of the information necessary for authentication and the identification information are embedded, a display control unit that controls the display of the code, and the information necessary for the authentication. A part of the authentication is performed based on the part, and after the connection based on the identification information included in the code is established, an authentication unit that performs the rest of the authentication using the established connection, A second information processing device that includes a first information processing device, a code acquisition unit that acquires the code, and an authentication processing unit that performs a part of the authentication based on a part of the information necessary for the authentication. An information processing system including an information processing device is provided.
[0008]
According to the present disclosure, a computer is required for the authentication, a code generation unit that generates a code in which a part of the information necessary for the authentication and the identification information are embedded, a display control unit that controls the display of the code. Part of the authentication is performed based on a part of the information, and after the connection based on the identification information included in the code is established, the authentication part that performs the rest of the authentication using the established connection And a code acquisition unit that acquires the code, and an authentication processing unit that performs a part of the authentication based on a part of the information required for the authentication, and a program for functioning as an information processing system is provided. R.
Effect of the invention
[0009]
As described above, according to the present disclosure, there is provided a technique capable of accelerating the timing of starting communication after establishing a connection. Note that the above effects are not necessarily limited, and in addition to or in place of the above effects, any of the effects shown in this specification, or other effects that can be grasped from this specification. May be played.
Brief description of the drawings
[0010]
FIG. 1 is a diagram showing a configuration example of an information processing system according to an embodiment of the present disclosure.
FIG. 2 is a block diagram showing a hardware configuration example of a mobile terminal according to the present embodiment.
FIG. 3 is a diagram showing a functional configuration example of a mobile terminal according to an embodiment of the present disclosure.
FIG. 4 is a block diagram showing a hardware configuration example of a reader/writer according to the present embodiment.
FIG. 5 is a diagram showing a functional configuration example of a reader/writer according to an embodiment of the present disclosure.
FIG. 6 is a flowchart showing a flow of connection processing and authentication processing when P2P connection information is embedded in a code.
FIG. 7 is a flowchart showing a flow of connection processing and authentication processing according to the present embodiment.
FIG. 8 is a flowchart showing details of connection processing and authentication processing according to the present embodiment.
FIG. 9 is a flowchart showing details of connection processing and authentication processing according to the present embodiment.
FIG. 10 is a flowchart showing details of connection processing and authentication processing according to the present embodiment.
MODE FOR CARRYING OUT THE INVENTION
[0011]
Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. In this specification and the drawings, components having substantially the same functional configuration are designated by the same reference numerals, and duplicate description will be omitted.
[0012]
In addition, in the present specification and the drawings, a plurality of constituent elements having substantially the same or similar functional configuration may be distinguished by attaching different numbers after the same reference numerals. However, when it is not necessary to specifically distinguish each of the plurality of constituent elements having substantially the same or similar functional configuration, only the same reference numeral is given. In addition, similar components of different embodiments may be distinguished by attaching different alphabets after the same reference numerals. However, when it is not necessary to distinguish between similar components, only the same reference numerals are given.
[0013]
The description will be given in the following order.
1. Details of Embodiment
1.1. System configuration example
1.2. Example of hardware configuration of mobile terminal
1.3. Example of functional configuration of mobile terminal
1.4. Example of hardware configuration of reader/writer
1.5. Example of functional configuration of reader/writer
1.6. General connection process and authentication process
1.7. Connection process and authentication process according to the present embodiment
1.8. Details of connection processing and authentication processing
2. Conclusion
[0014]
<1. Details of Embodiment>
Hereinafter, details of an embodiment of the present disclosure will be described.
[0015]
[1.1. System Configuration Example]
First, a configuration example of the information processing system according to the embodiment of the present disclosure will be described.
[0016]
FIG. 1 is a diagram illustrating a configuration example of an information processing system according to an embodiment of the present disclosure. In the example illustrated in FIG. 1, the information processing system 1 includes a first information processing device (hereinafter, also referred to as “mobile terminal”) 10 and a second information processing device (hereinafter, also referred to as “reader/writer”). )20 and the 3rd information processing apparatus 30.
[0017]
The mobile terminal 10 includes an IC chip described later. The IC chip has a memory area described later. Authentication must be performed before accessing the memory area. Non-contact communication (P2P wireless communication) is possible between the mobile terminal 10 and the reader/writer 20. Examples of P2P wireless communication include communication using Bluetooth (registered trademark) and communication using Wi-Fi (registered trademark). The third information processing device 30 provides a service that uses the memory area of the IC chip by non-contact communication.
[0018]
[1.2. Hardware Configuration Example of Mobile Terminal]
Next, a hardware configuration example of the mobile terminal 10 according to the embodiment of the present disclosure will be described. FIG. 2 is a block diagram showing a hardware configuration example of the mobile terminal 10 according to the present embodiment.
[0019]
In the example illustrated in FIG. 2, the mobile terminal 10 includes a communication device 810, a display device 820, an input device 830, a storage device 840, a CPU (Central Processing Unit) 850, and a ROM (Read Only Memory) 860. , RAM (Random Access Memory) 870 and an IC chip 160. Further, the mobile terminal 10 is configured by a bus, a bridge, an interface, etc. other than the one shown in FIG.
[0020]
The CPU 850 functions, for example, as an arithmetic processing unit or a control unit, and based on various programs recorded in the storage device 840, ROM 860, RAM 870, or removable recording medium (not shown), the overall operation of each component or one of the operations. Control the department.
[0021]
The ROM 860 stores, for example, programs read by the CPU 850, data used for calculation, and the like. The RAM 870 temporarily or permanently stores, for example, a program read by the CPU 850 and various parameters that change appropriately when the program is executed.
[0022]
The storage device 840 is a device for storing various kinds of data, and is configured by, for example, a magnetic storage device such as a hard disk drive (HDD; Hard Disk Drive), a semiconductor storage device, an optical storage device, or a magneto-optical storage device. To be done.
[0023]
The communication device 810 wirelessly transmits and receives radio waves to and from the reader/writer 20, for example.
[0024]
The display device 820 is, for example, a display device such as an LCD (Liquid Crystal Display) or an ELD (Electro-Luminescence Display).
[0025]
The input device 830 mainly includes a microphone and an input key. A microphone is a device mainly for inputting voice. Microphones are used, for example, for telephone calls. The input keys are a numeric keypad, a power key, a call key, and the like. The input key is used, for example, to input the telephone number of the other party of the call and to compose an electronic mail. Further, the input device may be remote control means (so-called remote controller) capable of transmitting a control signal using infrared rays or other radio waves. The input device 830 is composed of an input control circuit or the like for transmitting the information input using the above-mentioned operating means to the CPU 850 as an input signal.
[0026]
The IC chip 160 mainly includes a CPU (not shown), a ROM (not shown), a RAM (not shown), a storage device (not shown), and a non-contact communication device (not shown). With. The CPU (not shown) functions as an arithmetic processing unit or a control unit, for example, based on various programs recorded in a ROM (not shown), a RAM (not shown), and a storage device (not shown). .. In the present embodiment, the mobile terminal 10 is a mobile phone capable of non-contact communication, and the CPU (not shown) mainly performs part or all of the operation of the non-contact communication device (not shown). Control.
[0027]
The ROM (not shown) stores, for example, a program read by a CPU (not shown), data used for calculation, and the like. The RAM (not shown) temporarily or permanently stores, for example, a program read by a CPU (not shown) and various parameters that change appropriately when the program is executed.
[0028]
The hardware configuration example of the mobile terminal according to the embodiment of the present disclosure has been described above.
[0029]
[1.3. Functional Configuration Example of Mobile Terminal]
Next, a functional configuration example of the mobile terminal 10 will be described.
[0030]
FIG. 3 is a diagram illustrating a functional configuration example of the mobile terminal 10 according to the embodiment of the present disclosure. As shown in FIG. 3, the mobile terminal 10 includes an input unit 110, a control unit 120, a communication unit 130, a storage unit 140, a display unit 150, and an IC chip 160. Hereinafter, these functional blocks included in the mobile terminal 10 will be described.
[0031]
The input unit 110 has a function of accepting an operation input by a user. In the embodiment of the present disclosure, it is mainly assumed that the input unit 110 includes a touch panel. However, the input unit 110 may include a button, a mouse, a keyboard, a switch, a lever, or the like. The input unit 110 may also include a microphone that detects the voice of the user.
[0032]
The control unit 120 may be configured by a processing device such as one or a plurality of CPUs (Central Processing Units). When these blocks are configured by a processing device such as a CPU, the processing device may be configured by an electronic circuit. The control unit 120 can be realized by executing a program by the processing device. The control unit 120 has an application execution unit 121, and the application execution unit 121 includes a code generation unit 122, a display control unit 123, a connection control unit 124, and a communication control unit 125. Each of these functions will be described later.
[0033]
The communication unit 130 is configured to include a communication circuit and has a function of communicating with another device. For example, when the connection with the reader/writer 20 is established, the communication unit 130 performs P2P wireless communication with the reader/writer 20 using the communication path with which the connection is established. As described above, examples of P2P wireless communication include communication using Bluetooth (registered trademark) and communication using Wi-Fi (registered trademark). For example, the communication unit 130 includes a communication interface.
[0034]
The storage unit 140 is a recording medium that is configured to include a memory and stores a program executed by the control unit 120 and stores data necessary for executing the program. The storage unit 140 also temporarily stores data for the calculation by the control unit 120. For example, the storage unit 140 is composed of a magnetic storage unit device, a semiconductor storage device, an optical storage device, or a magneto-optical storage device.
[0035]
The display unit 150 outputs various kinds of information. For example, the display unit 150 may include a display capable of providing a display that can be visually recognized by the user. At this time, the display may be a liquid crystal display or an organic EL (Electro-Luminescence) display.
[0036]
The IC chip 160 has a processing unit 161, a storage unit 162, and a communication unit 163.
[0037]
The processing unit 161 may be configured by a processing device such as one or a plurality of CPUs, for example. When these blocks are configured by a processing device such as a CPU, the processing device may be configured by an electronic circuit. The processing unit 161 can be realized by executing a program by the processing device.
[0038]
The communication unit 163 is configured to include a communication circuit and has a function of communicating with the control unit 120. For example, the communication unit 163 has a function of acquiring data from the control unit 120 and providing the data to the other device.
[0039]
The storage unit 162 is a recording medium that is configured to include a memory and stores a program executed by the processing unit 161 and stores data necessary for executing the program. The storage unit 162 also temporarily stores data for the calculation by the processing unit 161. For example, the storage unit 162 is composed of a semiconductor storage device.
[0040]
The example of the functional configuration of the mobile terminal 10 according to the embodiment of the present disclosure has been described above.
[0041]
[1.4. Example Hardware Configuration of Reader/Writer]
Next, an example hardware configuration of the reader/writer 20 according to the embodiment of the present disclosure will be described. FIG. 4 is a block diagram showing a hardware configuration example of the reader/writer 20 according to the present embodiment.
[0042]
In the example illustrated in FIG. 4, the reader/writer 20 includes a communication device 910, an input device 920, a storage device 940, a CPU (Central Processing Unit) 950, a ROM (Read Only Memory) 960, and a RAM (Random Access). A memory) 970 and an imaging device 980. Further, the reader/writer 20 is configured by a bus, a bridge, an interface, etc. other than the one shown in FIG.
[0043]
The CPU 950 functions as, for example, an arithmetic processing unit or a control unit, and based on various programs recorded in the storage device 940, the ROM 960, the RAM 970, or a removable recording medium (not shown), the overall operation of each component or one of the operations. Control the department.
[0044]
The ROM 960 stores, for example, programs read by the CPU 950, data used for calculation, and the like. The RAM 970 temporarily or permanently stores, for example, a program read by the CPU 950 and various parameters that change appropriately when the program is executed.
[0045]
The storage device 940 is a device for storing various types of data, and is configured by, for example, a magnetic storage device such as a hard disk drive (HDD; Hard Disk Drive), a semiconductor storage device, an optical storage device, or a magneto-optical storage device. To be done.
[0046]
The communication device 910 wirelessly transmits and receives radio waves to and from the mobile terminal 10.
[0047]
The input device 920 is mainly composed of input buttons. Further, the input device 920 may be a remote control means (so-called remote controller) capable of transmitting a control signal using infrared rays or other radio waves. The input device 920 is composed of an input control circuit or the like for transmitting the information input using the above-mentioned operating means to the CPU 950 as an input signal.
[0048]
The image pickup device 980 uses, for example, various members such as an image pickup element such as a CCD (Charge Coupled Device) or a CMOS (Complementary Metal Oxide Semiconductor), and a lens for controlling the formation of a subject image on the image pickup element. It is a device that images a real space and generates a captured image. The image capturing device 980 may capture a still image or may capture a moving image.
[0049]
The hardware configuration example of the reader/writer 20 according to the embodiment of the present disclosure has been described above.
[0050]
[1.5. Functional configuration example of reader/writer]
Next, a functional configuration example of the reader/writer 20 according to the embodiment of the present disclosure will be described. FIG. 5 is a diagram illustrating a functional configuration example of the reader/writer 20 according to the embodiment of the present disclosure. As shown in FIG. 5, the reader/writer 20 includes an input unit 210, a control unit 220, a communication unit 230, a storage unit 240, and an imaging unit 260.
[0051]
The input unit 210 has a function of accepting an operation input by a user. In the embodiment of the present disclosure, it is mainly assumed that the input unit 210 includes a button. However, the input unit 210 may include a touch panel, a mouse, a keyboard, a switch, a lever, or the like. The input unit 210 may also include a microphone that detects the voice of the user.
[0052]
The control unit 220 executes control of each unit of the reader/writer 20. The control unit 220 may be configured with, for example, a CPU (Central Processing Unit). When the control unit 220 is configured by a processing device such as a CPU, the processing device may be configured by an electronic circuit. The control unit 220 can be realized by executing a program by the processing device. The control unit 220 includes a code acquisition unit 221, an authentication processing unit 222, a connection control unit 223, and a communication control unit 224. Each of these functions will be described later.
[0053]
The storage unit 240 is a recording medium configured to include a memory and stores a program executed by the control unit 220 and data necessary for executing the program. The storage unit 240 also temporarily stores data for the calculation by the control unit 220. For example, the storage unit 240 is composed of a magnetic storage unit device, a semiconductor storage device, an optical storage device, or a magneto-optical storage device.
[0054]
The communication unit 230 includes a communication circuit and has a function of communicating with other devices. For example, when the connection with the mobile terminal 10 is established, the communication unit 230 performs P2P wireless communication with the mobile terminal 10 using the communication path with which the connection is established. For example, the communication unit 230 includes a communication interface.
[0055]
The image capturing unit 260 captures an image under the control of the control unit 220. Specifically, the image capturing unit 260 captures an image of a subject around the reader/writer 20 under the control of the control unit 220. For example, the image capturing unit 260 captures an image when receiving an image capturing instruction from the control unit 220. Then, the image capturing unit 260 provides the image data obtained by the image capturing to the control unit 220. The image pickup unit 260 may include an image pickup optical system such as an image pickup lens and a zoom lens for condensing, and a signal conversion element such as a CCD (Charge Coupled Device) or a CMOS (Complementary Metal Oxide Semiconductor).
[0056]
The example of the functional configuration of the reader/writer 20 according to the embodiment of the present disclosure has been described above.
[0057]
[1.6. General Connection Process and Authentication Process]
Here, the connection process and the authentication when the information necessary for the connection between the reader/writer 20 and the mobile terminal 10 (hereinafter, also referred to as “P2P connection information”) is embedded in the code. The processing will be described. The case where a two-dimensional code is used as the code will be described below as an example, but the type of code is not limited to the two-dimensional code. A QR code (registered trademark) can be used as a typical example of the two-dimensional code. The P2P connection information may correspond to an example of “identification information”. For example, the P2P connection information may be address information used for communication between the reader/writer 20 and the mobile terminal 10.
[0058]
FIG. 6 is a flowchart showing a flow of connection processing and authentication processing when P2P connection information is embedded in a code. As shown in FIG. 6, the mobile terminal 10 generates a two-dimensional code in which the P2P connection information is embedded (S11). Then, the mobile terminal 10 transmits the two-dimensional code to the reader/writer 20 (S12). The reader/writer 20 and the mobile terminal 10 establish a connection (establish a P2P connection) based on the P2P connection information (S13).
[0059]
Then, polling is transmitted from the reader/writer 20 to the mobile terminal 10, and as a response to the polling, the card ID is returned from the mobile terminal 10 to the reader/writer 20 (S15). Then, the reader/writer 20 makes an authentication key version transmission request to the mobile terminal 10 (S16), and the mobile terminal 10 returns the authentication key version to the reader/writer 20 as a response to the authentication key version transmission request (S16). S17).
[0060]
The reader/writer 20 performs authentication based on the card ID and the authentication key version, and if the authentication is successful, secure communication is started between the reader/writer 20 and the mobile terminal 10 (S18).
[0061]
When the connection process and the authentication process are performed as shown in FIG. 6, the P2P connection information is exchanged, the connection is established based on the P2P connection information, and then the information necessary for the authentication (for example, the card ID). , Authentication key version, etc.) and the authentication is performed based on the information required for the authentication, so that the timing of starting communication after the connection is established is delayed. Therefore, in the present embodiment, a technique that enables the timing of starting communication after the connection is established will be mainly described.
[0062]
Further, when the two-dimensional code is used for authentication, the two-dimensional code may be generated in the server in order to reduce the risk of the two-dimensional code being stolen. That is, the mobile terminal 10 needs to be connected to the network (although it needs to be online), but it is difficult to bring the mobile terminal 10 online in an area where the infrastructure is insufficient. There are some cases. Therefore, in the present embodiment, a technique that enables authentication even when the mobile terminal 10 is offline will be described.
[0063]
The flow of connection processing and authentication processing when embedding P2P connection information in a code has been described above.
[0064]
[1.7. Connection Process and Authentication Process
According to Present Embodiment ] Next, the connection process and the authentication process according to the present embodiment will be described. FIG. 7 is a flowchart showing the flow of connection processing and authentication processing according to this embodiment. As shown in FIG. 7, inside the mobile terminal 10, polling is transmitted, a card ID is acquired as a response to the polling (S14), an authentication key version transmission request is transmitted, and authentication is performed as a response to the authentication key version transmission request. Get the key version.
[0065]
Next, the mobile terminal 10 generates a two-dimensional code in which not only the P2P connection information but also the card ID and the authentication key version are embedded (S11). Then, the mobile terminal 10 transmits the two-dimensional code to the reader/writer 20 (S12). The reader/writer 20 and the mobile terminal 10 establish a connection (establish a P2P connection) based on the P2P connection information (S13).
[0066]
In the reader/writer 20, the authentication based on the card ID and the authentication key version (a part of the information necessary for the authentication) is performed, and if the authentication is successful, secure communication is performed between the reader/writer 20 and the mobile terminal 10. It is started (S18). The predecessor relation between the connection establishment based on the P2P connection information and the authentication based on the card ID and the authentication key version is not particularly limited.
[0067]
When the connection process and the authentication process are performed as illustrated in FIG. 7, the P2P connection information and the information necessary for the authentication (for example, the card ID, the authentication key version, etc.) are simultaneously exchanged using the code. Therefore, the time for exchanging the information necessary for authentication is reduced, so that it is possible to accelerate the communication start timing after the connection is established.
[0068]
Further, in the present embodiment, it is possible to perform authentication even when the mobile terminal 10 is offline.
[0069]
The connection processing and the authentication processing according to this embodiment have been described above.
[0070]
[1.8. Details of Connection Process and Authentication Process]
Next , details of the connection process and the authentication process according to the present embodiment will be described. 8 to 10 are flowcharts showing details of the connection process and the authentication process according to the present embodiment. As shown in FIG. 8, when a process start request is input to the application execution unit 121 by a user action in the mobile terminal 10 (S21), the application execution unit 121 transmits polling to the IC chip 160 (S14). ). Then, the application execution unit 121 acquires the card ID as a response to polling (S22).
[0071]
Subsequently, the application execution unit 121 transmits an authentication key version transmission request to the IC chip 160 (S16). Then, the application execution unit 121 acquires the authentication key version as a response to the authentication key version transmission request (S23).
[0072]
Then, the application execution part 121 produces|generates a random challenge (challenge value) based on the time information of the portable terminal 10 (S24). Then, the application execution unit 121 generates a Card Authentication command (authentication command) and transmits it to the IC chip 160 (S25). The Card Authentication command includes a random challenge generated immediately before, information indicating an area of the storage unit 162 (memory area) of the IC chip 160 that requires access permission during encrypted communication, and part of encrypted communication session information. May be included.
[0073]
As a response to the Card Authentication command, the IC chip 160 generates a Card Authentication response (authentication response) based on the random challenge, the card ID, and the authentication key version, and sends it to the application execution unit 121 (S26). The Card Authentication response may include a challenge response (response value) for a random challenge, a random challenge (challenge value) for the reader/writer 20, and a part of session information for encrypted communication.
[0074]
Subsequently, in the mobile terminal 10, the code generation unit 122 generates a two-dimensional code in which not only the P2P connection information but also the card ID, the authentication key version, the Card Authentication command, and the Card Authentication response are embedded (S27). Then, in the mobile terminal 10, the display control unit 123 controls the display of the two-dimensional code on the display unit 150. In the reader/writer 20, the imaging unit 260 images the two-dimensional code. As a result, the two-dimensional code is transmitted from the mobile terminal 10 to the reader/writer 20 (S12).
[0075]
In the reader/writer 20, when the two-dimensional code is acquired by the code acquisition unit 221, the authentication processing unit 222 performs the authentication process. Specifically, the authentication processing unit 222 extracts the P2P connection information, the card ID, the authentication key version, the Card Authentication command and the Card Authentication response from the two-dimensional code, and the card ID, the authentication key version, the Card Authentication command, and the Card Authentication command. Card authentication (part of authentication) is performed based on the response (S28).
[0076]
At this time, the authentication processing unit 222 compares the time information in the reader/writer 20 with the time information acquired from the random challenge extracted from the Card Authentication command to obtain a comparison result. The authentication processing unit 222 performs card authentication (a part of the authentication) based on the comparison result and a part of the information necessary for the authentication. More specifically, the authentication processing unit 222, when the time information in the reader/writer 20 and the time information acquired from the random challenge match, and based on a part of the information necessary for the authentication (authentication Part) is successful, the operation is shifted to the P2P connection establishment in S13. The communication control unit 224 permits the reader/writer 20 to access the memory area of the storage unit 162. This makes it possible to prevent spoofing by stealing the two-dimensional code.
[0077]
As shown in FIG. 9, the connection control unit 223 in the reader/writer 20 and the connection control unit 124 in the mobile terminal 10 establish a P2P connection (establish a connection based on P2P connection information) (S13). The communication control unit 224 generates a challenge response from the random challenge included in the Card Authentication response (S31), and sends the RW Authentication command including the generated challenge response to the communication unit 230, using the established P2P connection. It is transmitted to the IC chip 160 via the application execution unit 121 (S32, S33). The IC chip 160 (authentication unit) performs R/W authentication (remaining authentication) based on the RW Authentication command (S34), and returns the authentication result to the reader/writer 20 via the communication unit 130 in the mobile terminal 10. (S36, S37). When the R/W authentication (remaining authentication) is successful, the communication control unit 125 permits the reader/writer 20 to access the memory area of the storage unit 162.
[0078]
At the time of reading data, in the reader/writer 20, the communication control unit 224 transmits a Read command to the IC chip 160 via the communication unit 230 (S41, S42). In the mobile terminal 10, the communication control unit 125 uses the session information to encrypt the data in the area where the reader/writer 20 is permitted to access the memory area of the storage unit 162, and the encrypted data is transferred to the communication unit. It is transmitted to the reader/writer 20 via 130 (S44, S45). In the reader/writer 20, when the communication unit 230 receives the encrypted data, the communication control unit 224 decrypts the data (S46).
[0079]
At the time of writing the data, the communication control unit 224 in the reader/writer 20 encrypts the data using the session information, and transmits a Write command including the encrypted data to the IC chip 160 via the communication unit 230 ( S51, S52). In the mobile terminal 10, the communication control unit 125 decrypts the encrypted data using the session information (S53), and writes the decrypted data in the area of the storage unit 162 that is permitted to access the memory area (S54). ). The communication control unit 125 transmits the processing result to the reader/writer 20 via the communication unit 130 (S55, S56).
[0080]
The details of the connection process and the authentication process according to the present embodiment have been described above.
[0081]
<2. Conclusion> As
described above, according to the embodiment of the present disclosure, a code generation unit that generates a code in which a part of the information necessary for authentication and the identification information are embedded, and a display that controls the display of the code. An information processing apparatus comprising: a control unit, a connection is established based on the identification information included in the code, and authentication is performed based on a part of the information required for the authentication.
[0082]
According to such a configuration, the time required for exchanging information necessary for authentication is reduced, so that it is possible to accelerate the communication start timing after the connection is established. Furthermore, according to such a configuration, it is possible to perform authentication even when the information processing device is offline.
[0083]
The preferred embodiments of the present disclosure have been described above in detail with reference to the accompanying drawings, but the technical scope of the present disclosure is not limited to such examples. It is obvious that a person having ordinary knowledge in the technical field of the present disclosure can come up with various changes or modifications within the scope of the technical idea described in the claims. Of course, it is understood that the invention also belongs to the technical scope of the present disclosure.
[0084]
For example, it is possible to create a program for causing hardware such as a CPU, a ROM, and a RAM included in a computer to exhibit the same function as the function of the control unit 120 described above. A computer-readable recording medium recording the program may be provided. Further, for example, it is possible to create a program for causing hardware such as a CPU, a ROM, and a RAM built in the computer to exhibit the same function as the function of the control unit 220 described above. A computer-readable recording medium recording the program may be provided.
[0085]
Further, the effects described in the present specification are merely illustrative or exemplary, and are not limitative. That is, the technique according to the present disclosure may have other effects that are apparent to those skilled in the art from the description of the present specification, in addition to or instead of the above effects.
[0086]
The following configurations also belong to the technical scope of the present disclosure.
(1)
A code generation unit that generates a code in which a part of the information necessary for authentication and the identification information are embedded, a
display control unit that controls the display of the code, and
a part of the information necessary for the authentication. A part of authentication based on the identification information included in the code is established based on the identification information included in the code, and an authentication unit that performs the rest of the authentication by using the established connection
; Processing equipment.
(2) The
access to the memory area is permitted when a part of the authentication based on a part of the information necessary for the authentication is successful, and when the rest of the authentication is successful, in
(1) above. Information processing equipment.
(3) The information processing device according to (1) or (2)
,
wherein a part of the information necessary for the authentication includes an authentication command .
(4) The
information processing device according to (3), wherein the authentication command includes a challenge value generated based on time information in
the information processing device.
(5) In the
information processing device, a part of the authentication is performed based on a comparison result of the time information in the reader that reads the code and the time information acquired from the challenge value and a part of the information necessary for the authentication. Done,
The information processing device according to (4).
(6)
When the time information in the reader that reads the code and the time information acquired from the challenge value match, the information processing device performs the authentication based on a part of the information necessary for the authentication. The information processing apparatus according to
(5) , wherein when the copy is successful, and when the remaining authentication is successful, another information processing apparatus is permitted to access the memory area .
(7) The information processing device according to any one of (3) to (6)
, wherein a part of the information necessary for the authentication includes an authentication response to the authentication command
.
(8) The information processing device according to (7),
wherein the authentication response includes a response value based on a challenge value, a card ID, and an authentication key version
.
(9) The information processing device according to any one of (1) to (8)
,
wherein a part of the information required for the authentication includes a card ID .
(10) The information processing device according to any one of (1) to (9)
,
wherein a part of the information required for the authentication includes an authentication key version .
(11) The
code is a two-dimensional code,
The information processing apparatus according to any one of (1) to (10) above.
(12) The
information processing device stores a memory in another information processing device when a part of the authentication based on a part of the information necessary for the authentication is successful and the rest of the authentication is successful.
The information processing apparatus according to any one of (3) to (8), further including a communication control unit that permits access to the area .
(13) The information processing device according to any one of (3) to (8),
wherein the authentication command includes information indicating an area requesting access permission in the memory area
.
(14) The
information processing device according to
any one of (1) to (11), wherein the identification information includes address information used for communication with another information processing device.
(15)
A code generation unit that generates a code in which a part of the information necessary for authentication and the identification information are embedded, a
display control unit that controls the display of the code, and
a part of the information necessary for the authentication. A part of authentication based on the identification information included in the code is established after the authentication is performed based on the identification information included in the code, and an authenticating unit that performs the rest of the authentication using the established connection
, 1, an information processing device, and
a code acquisition unit that acquires the code,
An information processing system
,
comprising: a second information processing device; and an authentication processing unit that performs a part of the authentication based on a part of the information necessary for the authentication .
(16) A
computer
includes a code generation unit that generates a code in which a part of the information necessary for authentication and identification information are embedded, a
display control unit that controls the display of the code, and the
information necessary for the authentication. part is part of the authentication is performed on the basis of, after the connection based on the identification information included in the code is established, an authentication unit which by utilizing the established the connection do the rest of the authentication,
the A program for functioning as an information processing system including a code acquisition unit that acquires a code
and an authentication processing unit that performs a part of the authentication based on a part of the information necessary for the authentication
.
Explanation of symbols
[0087]
1 information processing system
10 mobile terminal
110 input unit
120 control unit
121 application execution unit
122 code generation unit
123 display control unit
124 connection control unit
125 communication control unit
130 communication unit
140 storage unit
150 display unit
160 IC chip
161 processing unit
162 storage Unit
163 Communication unit
20 Reader/writer
210 Input unit
220 Control unit
221 Code acquisition unit
222 Authentication processing unit
223 Connection control unit
224 Communication control unit
230 Communication unit
240 Storage unit
260 Imaging unit
30 Third information processing device
The scope of the claims
[Claim 1]
A code generation unit that generates a code in which a part of the information necessary for the authentication and the identification information are embedded, a
display control unit that controls the display of the code, and an
authentication based on a part of the information necessary for the authentication. And a connection based on the identification information included in the code is established, and an authentication unit that performs the rest of the authentication by using the established connection
.
[Claim 2]
The information processing apparatus according to claim 1 , wherein access to the memory area is permitted when a part of the authentication based on a part of the information necessary for the authentication is successful and when the rest of the authentication is successful. .
[Claim 3]
The information processing apparatus according to claim 1, wherein a part of the information necessary for the authentication includes an authentication command .
[Claim 4]
The information processing apparatus according to
claim 3, wherein the authentication command includes a challenge value generated based on time information in the information processing apparatus.
[Claim 5]
The information processing device, a part of the authentication is performed based on a part of a comparison result of the time information in the reader that reads the code and the time information acquired from the challenge value and a part of the information necessary for the authentication,
The information processing apparatus according to claim 4.
[Claim 6]
When the time information in the reader that reads the code and the time information acquired from the challenge value match, the information processing device succeeds in a part of the authentication based on a part of the information necessary for the authentication. The information processing apparatus according to
claim 5 , wherein when the authentication is successful, and when the remaining authentication is successful, another information processing apparatus is permitted to access the memory area .
[Claim 7]
The information processing apparatus according to claim 3 , wherein a part of the information necessary for the authentication includes an authentication response to the authentication command .
[Claim 8]
The information processing apparatus according to claim 7, wherein the authentication response includes a response value based on a challenge value, a card ID, and an authentication key version .
[Claim 9]
The information processing apparatus according to claim 1, wherein a part of the information required for the authentication includes a card ID .
[Claim 10]
The information processing apparatus according to claim 1, wherein a part of the information necessary for the authentication includes an authentication key version .
[Claim 11]
The information processing apparatus according to claim 1 , wherein the code is a two-dimensional code .
[Claim 12]
The information processing apparatus accesses the memory area to another information processing apparatus when a part of the authentication based on a part of the information necessary for the authentication is successful and when the rest of the authentication is successful.
The information processing apparatus according to claim 3, further comprising a communication control unit that permits the .
[Claim 13]
The information processing apparatus according to claim 3, wherein the authentication command includes information indicating an area requesting access permission in the memory area .
[Claim 14]
The information processing apparatus according to
claim 1, wherein the identification information includes address information used for communication with another information processing apparatus.
[Claim 15]
A code generation unit that generates a code in which a part of the information necessary for the authentication and the identification information are embedded, a
display control unit that controls the display of the code, and an
authentication based on a part of the information necessary for the authentication. Part is performed, and after the connection based on the identification information included in the code is established, an authentication unit that performs the rest of the authentication using the established connection
, the first information. a processing unit,
a code acquiring unit for acquiring the code,
an authentication processing unit that performs a portion of said authentication based on a part of the information required for the authentication
and a second information processing apparatus,
the An information processing system having.
[Claim 16]
The computer is
provided with a code generation unit that generates a code in which a part of the information necessary for authentication and the identification information are embedded, a
display control unit that controls the display of the code, and
a part of the information necessary for the authentication. Based on the identification information included in the code, a part of the authentication is performed based on the authentication information, and then the authentication unit that performs the rest of the authentication by using the established connection and the
code are acquired. A program for functioning as an information processing system ,
comprising: a code acquisition unit that performs the authentication; and an authentication processing unit that performs a part of the authentication based on a part of the information necessary for the authentication
.
| # | Name | Date |
|---|---|---|
| 1 | 202017016902-TRANSLATIOIN OF PRIOIRTY DOCUMENTS ETC. [20-04-2020(online)].pdf | 2020-04-20 |
| 2 | 202017016902-STATEMENT OF UNDERTAKING (FORM 3) [20-04-2020(online)].pdf | 2020-04-20 |
| 3 | 202017016902-PRIORITY DOCUMENTS [20-04-2020(online)].pdf | 2020-04-20 |
| 4 | 202017016902-POWER OF AUTHORITY [20-04-2020(online)].pdf | 2020-04-20 |
| 5 | 202017016902-FORM 1 [20-04-2020(online)].pdf | 2020-04-20 |
| 6 | 202017016902-DRAWINGS [20-04-2020(online)].pdf | 2020-04-20 |
| 7 | 202017016902-DECLARATION OF INVENTORSHIP (FORM 5) [20-04-2020(online)].pdf | 2020-04-20 |
| 8 | 202017016902-COMPLETE SPECIFICATION [20-04-2020(online)].pdf | 2020-04-20 |
| 9 | 202017016902-Proof of Right [12-06-2020(online)].pdf | 2020-06-12 |
| 10 | 202017016902-Proof of Right [24-07-2020(online)].pdf | 2020-07-24 |
| 11 | 202017016902-FORM 18 [10-09-2021(online)].pdf | 2021-09-10 |
| 12 | 202017016902.pdf | 2021-10-19 |
| 13 | 202017016902-FER.pdf | 2022-03-11 |
| 14 | 202017016902-Others-060622.pdf | 2022-06-14 |
| 15 | 202017016902-Correspondence-060622.pdf | 2022-06-14 |
| 16 | 202017016902-PETITION UNDER RULE 137 [09-09-2022(online)].pdf | 2022-09-09 |
| 17 | 202017016902-OTHERS [09-09-2022(online)].pdf | 2022-09-09 |
| 18 | 202017016902-FORM-26 [09-09-2022(online)].pdf | 2022-09-09 |
| 19 | 202017016902-FER_SER_REPLY [09-09-2022(online)].pdf | 2022-09-09 |
| 20 | 202017016902-DRAWING [09-09-2022(online)].pdf | 2022-09-09 |
| 21 | 202017016902-CORRESPONDENCE [09-09-2022(online)].pdf | 2022-09-09 |
| 22 | 202017016902-COMPLETE SPECIFICATION [09-09-2022(online)].pdf | 2022-09-09 |
| 23 | 202017016902-CLAIMS [09-09-2022(online)].pdf | 2022-09-09 |
| 24 | 202017016902-ABSTRACT [09-09-2022(online)].pdf | 2022-09-09 |
| 25 | 202017016902-PatentCertificate31-10-2025.pdf | 2025-10-31 |
| 26 | 202017016902-IntimationOfGrant31-10-2025.pdf | 2025-10-31 |
| 1 | SEARCHSTRATEGYE_08-03-2022.pdf |