摘要:
An authentication system providing a safety authentication process of electronic values with the use of mobile terminals which do not have a tamper-resistant function. The electronic value including encrypted value authentication information (F(VPW)), wherein an authentication information (VPW) corresponding to an electronic value specified by a user is acquired by the hash calculation, is stored in user's mobile terminal. In the user authentication process; authentication apparatus generates a random number R and transmits it to mobile terminal, mobile terminal generates value authentication information (F(VPW′)) from authentication information (VPW′) corresponding to electronic value input by user, further executes a hash calculation on data wherein value authentication information (F(VPW′)) and the random number R are concatenated, generates authentication information (F(VPW′)∥R), transmits it to the authentication apparatus with the electronic value, authentication apparatus decrypts the received electronic value, extracts the value authentication information (F(VPW)) from the electronic value, executes the hash calculation on data wherein value authentication information (F(VPW)) and the random number R are concatenated, generates the authentication information (F(VPW)∥R), and collates the received authentication information (F(VPW′)∥R) with the authentication information (F(VPW)∥R), so that the user is authenticated.
摘要:
The present invention realizes electronic commerce by providing a reception section that receives product information and service information and a barcode formation section that forms a barcode based on the received information, displaying the barcode formed by the barcode formation section on a display section and allowing a barcode reader provided at a shop terminal, etc. to read this barcode.
摘要:
A secure device comprises a data exchange card application carrying out data exchange between card applications isolated by a fire wall, card application plug-in data defining authentication processing of the data exchange card application, in such a manner that authentication processing between the card application and the data exchange card application is carried out in the same manner as authentication processing between the card application and a dedicated host terminal, and authentication key data used for this authentication processing. Data exchange and tie-up processing between card applications are possible in a secure device, or under the mediation of a mobile terminal, and rapid processing can be done. The card application has only to carry out the same operation as data exchange with a related dedicated host terminal. Also, tie-up processing between card applications can be carried out by only a mobile terminal side in which a secure device is loaded.