摘要:
The present invention provides mobile terminals with various types of services such as electronic commerce service, music delivery service, and position information service. User applications required for the electronic commerce service, music delivery service, and position information service are respectively configured as service objects each having a server facility, and further a local gateway is provided, whereby various types of services can be used through a browser.
摘要:
The present invention aims at providing an information processing terminal, a status notification system, and a status notification method that can protect both privacy and security when a status of the information processing terminal is notified to a server. An information processing terminal 10 has a disclosure/nondisclosure determination section 1001 that determines a notifiable server for each entry; a log concealing section 1002 that conceals an entry; a multi-log measurement section 1003 that commands to update hashes as to a plurality of parties; a log configuration section 1004 that configures a log directed at a notified party and that causes performance of signing action; a verification request section 1005 that requests verification; a policy storage section 1006 that stores a policy used for determining a party that can be notified; and a log storage section 1007 for storing the entry. The information processing terminal 10 commands accumulation, into a hash, of entries subjected to processing suitable for each notified party, such as concealing operation.
摘要:
A method to allow a value to be written into one PCR domain, only if values from a second PCR domain are valid, thus ensuring the extension of the chain of trust between domains.
摘要:
For the keys in a key tree group composed of root keys for each of multiple stakeholders, a shared key is generated between the multiple stakeholders, and access restrictions with respect to the generated shared key are flexibly set. A shared key control unit and a tamper-resistant module are provided for each of the multiple stakeholders. The shared key is set based on stakeholder dependency relationships. After the shared key is set, access to the shared key is controlled so that access is not possible by malicious stakeholders, so as to maintain the security level.
摘要:
The present invention provides a migration apparatus that realizes safe migration of data between devise that use different encryption algorithms and different security authentication levels. The fourth electronic terminal device 2502 sends, to the migration authority 2501, a request for migration of a virtual machine to the fifth electronic terminal device 2503. If the fifth electronic terminal device 2503 is not an illegitimate device, the migration authority 2501 sends a migration request to the fifth electronic terminal device 2503. The fifth electronic terminal device 2503 sends, to the migration authority 2501, a digital signature and so on, together with the request. The migration authority 2501 makes a judgment. If the result is “OK”, the migration authority 2501 sends the result “OK” to the fifth electronic terminal device 2503. The fourth electronic terminal device 2502 encrypts a migration package and sends the encrypted migration package to the migration authority 2501, and sends the virtual machine to the fifth electronic terminal device 2503.
摘要:
Provided is a migration system considering security authentication levels and data protection strength levels of the both security devices between which data is migrated.A first terminal 102 includes a mechanism for protecting data by a private key in the public key method held by TPM, and a second terminal 103 includes a key in the private key method encrypted by the private key in the public key method held by TPM and a mechanism for protecting the data by the key. A Migration Authority 101 holds a security policy table describing a security policy and judges whether data movement from the first terminal 102 to the second terminal 103 is enabled according to the security policy table.
摘要:
An information terminal that decrypts sealed data without returning program data after update to the state before update. The information terminal includes update certificate storage unit 102 storing an update certificate for certifying update of the program data to be executed by CPU 101, and a selection unit 103 which, when the CPU 101 is to execute program data, judges whether or not digest of the post-update program data in the update certificate matches digest of the program data to be executed, and selects digest of the pre-update program data in the update certificate when it judges that they match. The CPU 101 executes the post-update program data. The information terminal further includes a security device that stores an extend value of a program data digest when the pre-update program data is executed by the CPU according to a request from the selection unit 103.
摘要翻译:一种信息终端,在更新到更新之前的状态时,将密码数据解密而不返回程序数据。 信息终端包括更新证书存储单元102,存储用于验证要由CPU 101执行的程序数据的更新的更新证书;以及选择单元103,当CPU 101执行程序数据时,判断是否消除 更新证书中的更新后程序数据与要执行的程序数据的摘要相匹配,并且当判断为匹配时,选择更新证书中的更新前程序数据的摘要。 CPU 101执行更新后程序数据。 信息终端还包括安全装置,当根据来自选择单元103的请求由CPU执行预更新程序数据时,存储程序数据摘要的扩展值。
摘要:
The present invention provides mobile terminals with various types of services such as electronic commerce service, music delivery service, and position information service. User applications required for the electronic commerce service, music delivery service, and position information service are respectively configured as service objects each having a server facility, and further a local gateway is provided, whereby various types of services can be used through a browser.
摘要:
A secure device can make contents of terminal application authentication information calculation a different complicated calculation process at each time while suppressing the processing load in the secure device and a card application code size to low values. When issuing of a terminal application (302) is requested from an application loader (301) to an application management unit (1011), an instruction content execution unit (1012) embeds authentication information used for calculation of an authentication key required for authentication with an application causing an information processing terminal (30) to perform a process, into the terminal application (302). A calculation complicating unit (1013) creates a calculation problem having a calculation result as an answer and embeds it as a part of the authentication information calculation into the terminal application (302). An authentication information calculation unit (1014) calculates authentication information with the calculation result to create an authentication key. An authentication processing unit (1032) performs authentication of the terminal application (302) by the authentication key. This does not complicate the calculation process while making the authentication information calculation of the terminal application (302) a different complicated calculation at each time.
摘要:
A ticket management system is provided which can perform adjustments using a ticket to which non-updatable value information is assigned together with an electronic value, according to a payment form. The ticket management system includes an IC tag attached to a money ticket, a money ticket management server and a mobile terminal. The IC tag holds a money ticket ID for identifying the money ticket and reads the money ticket ID. The money ticket management server includes a storage unit, receives the money ticket ID from the mobile terminal and writes a valid money ticket ID to the storage unit. The mobile terminal includes a storage unit, acquires the money ticket ID held in the IC tag, transmits the acquired money ticket ID to the money ticket management server, and writes amount information of the money ticket identified by the valid money ticket ID to the storage unit.