Secure boot terminal, secure boot method, secure boot program, recording medium, and integrated circuit
    2.
    发明授权
    Secure boot terminal, secure boot method, secure boot program, recording medium, and integrated circuit 有权
    安全引导终端,安全引导方法,安全引导程序,记录介质和集成电路

    公开(公告)号:US08555049B2

    公开(公告)日:2013-10-08

    申请号:US12676960

    申请日:2008-09-30

    IPC分类号: G06F15/177

    CPC分类号: G06F21/575

    摘要: A terminal that performs secure boot processing when booting, thereby booting reliably even if, during updating of a software module, the power is cut off or the update is otherwise interrupted. The terminal comprises a CPU, a software module storage unit, a certificate storage unit, an updating unit for updating the software module and certificate, a security device provided with a configuration information storage unit for storing the configuration information of the software module, an alternate configuration information storage unit for storing the configuration information of a software module in the configuration before the update, and a boot control unit for verifying and executing the software module by using the certificate. The terminal verifies the certificate of the software module by comparing the configuration information stored by the configuration information storage unit with the configuration information stored by the alternate configuration information storage unit.

    摘要翻译: 在启动时执行安全引导处理的终端,即使在更新软件模块期间断电或更新被中断的情况下也可以可靠地引导。 终端包括CPU,软件模块存储单元,证书存储单元,用于更新软件模块和证书的更新单元,设置有用于存储软件模块的配置信息的配置信息存储单元的安全设备, 配置信息存储单元,用于存储在更新之前的配置中的软件模块的配置信息;以及引导控制单元,用于通过使用证书来验证和执行软件模块。 终端通过将由配置信息存储单元存储的配置信息与备用配置信息存储单元存储的配置信息进行比较来验证软件模块的证书。

    Method and device for speeding up key use in key management software with tree structure
    5.
    发明授权
    Method and device for speeding up key use in key management software with tree structure 有权
    用于树结构的密钥管理软件中加密密钥使用的方法和装置

    公开(公告)号:US08223972B2

    公开(公告)日:2012-07-17

    申请号:US12146255

    申请日:2008-06-25

    IPC分类号: H04L9/00

    CPC分类号: H04L9/0836 H04L9/088

    摘要: In the key management software having a key database with a tree structure, a high-speed data encryption/decryption process is achieved by changing the tree structure without reducing the security strength when deleting or adding a key from/to the tree structure. The key management software having the key database with the tree structure, when deleting or adding a key from/to the tree structure, refers to the encryption strength comparison table and the process time comparison table to change the tree structure without reducing the security strength. This reduces the number of times an encrypted key is loaded onto the encryption/decryption processing device during the data encryption/decryption process, thus achieving a high-speed data encryption/decryption.

    摘要翻译: 在具有树结构的密钥数据库的密钥管理软件中,通过在从树结构中删除或添加密钥时改变树结构而不降低安全强度来实现高速数据加密/解密处理。 具有树结构的密钥数据库的密钥管理软件在从树结构中删除或添加密钥时,参考加密强度比较表和处理时间比较表来改变树结构而不降低安全强度。 这减少了在数据加密/解密处理期间将加密密钥加载到加密/解密处理设备上的次数,从而实现高速数据加密/解密。

    Mobile electronic commerce system
    7.
    发明授权
    Mobile electronic commerce system 有权
    移动电子商务系统

    公开(公告)号:US07991694B2

    公开(公告)日:2011-08-02

    申请号:US12318419

    申请日:2008-12-29

    申请人: Hisashi Takayama

    发明人: Hisashi Takayama

    IPC分类号: G06Q40/00

    摘要: The objective of the present invention is to provide a mobile electronic commerce system that is superior in safety and usability. The mobile electronic commerce system comprises an electronic wallet 100, supply sides 101, 102, 103, 104 and 105, and a service providing means 110 that is connected by communication means. The service providing means installs a program for an electronic ticket, an electronic payment card, or an electronic telephone card. The electronic wallet employs the installed card to obtain a product or a service or entrance permission. The settlement process is performed by the electronic wallet and the supply side via the communication means, and data obtained during the settlement process are managed by being transmitted to the service providing means at a specific time. A negotiable card can be easily obtained, and when the negotiable card is used the settlement process can be quickly and precisely performed.

    摘要翻译: 本发明的目的是提供一种安全性和可用性优异的移动电子商务系统。 移动电子商务系统包括电子钱包100,供应侧101,102,103,104和105以及通过通信装置连接的服务提供装置110。 服务提供装置安装电子票,电子支付卡或电子电话卡的程序。 电子钱包使用已安装的卡获取产品或服务或入场许可。 通过通信装置由电子钱包和供应方执行结算处理,并且在结算处理期间获得的数据通过在特定时间被发送到服务提供装置来管理。 可以容易地获得可转让卡,当使用可转让卡时,可以快速,精确地执行结算处理。

    KEY MIGRATION DEVICE
    8.
    发明申请
    KEY MIGRATION DEVICE 审中-公开
    主要移动设备

    公开(公告)号:US20110081017A1

    公开(公告)日:2011-04-07

    申请号:US12993931

    申请日:2009-05-25

    IPC分类号: H04L9/00

    CPC分类号: H04L9/0836 H04L9/088

    摘要: Provided is a key migration device which can securely and reliably control the migration of keys. A migration authority (101) fetches a generation level which is the security level of a first electronic terminal (3011) and an output destination level which is the security level of a third electronic terminal (3013), decides whether the relationship between the generation level and the output destination level satisfies a predetermined condition when a request for fetching a collection of keys is received from the third electronic terminal (3013), outputs the key generated by the first electronic terminal (3011) among the collection of keys to the third electronic terminal (3013) if the predetermined condition is fulfilled, and restricts output to the third electronic terminal (3013) of the key generated by the first electronic terminal (3011) among the collection of keys if the predetermined condition is not fulfilled.

    摘要翻译: 提供了一种可以安全可靠地控制密钥迁移的密钥迁移设备。 移动机构(101)取出作为第一电子终端(3011)的安全级别的生成级别和作为第三电子终端(3013)的安全级别的输出目的地级别,决定生成级别 并且当从第三电子终端(3013)接收到提取密钥集合的请求时,输出目的地级别满足预定条件,将由第一电子终端(3011)生成的密钥输出到第三电子邮件集合 如果满足预定条件,并且如果不满足预定条件,则在密钥集合中限制由第一电子终端(3011)生成的密钥的输出到第三电子终端(3013)的终端(3013)。

    INFORMATION PROCESSING DEVICE, AUTHENTICATION SYSTEM, AUTHENTICATION DEVICE, INFORMATION PROCESSING METHOD, INFORMATION PROCESSING PROGRAM, RECORDING MEDIUM, AND INTEGRATED CIRCUIT
    9.
    发明申请
    INFORMATION PROCESSING DEVICE, AUTHENTICATION SYSTEM, AUTHENTICATION DEVICE, INFORMATION PROCESSING METHOD, INFORMATION PROCESSING PROGRAM, RECORDING MEDIUM, AND INTEGRATED CIRCUIT 有权
    信息处理设备,认证系统,认证设备,信息处理方法,信息处理程序,记录介质和集成电路

    公开(公告)号:US20110072266A1

    公开(公告)日:2011-03-24

    申请号:US12992699

    申请日:2009-10-09

    IPC分类号: G06F21/22

    摘要: The present invention provides an information processing device, an authentication system, etc. that save a server the trouble of updating a database, etc., even when a software module in a client device is updated, and that are capable of verifying whether software modules that have been started in the client device are valid. The terminal device A100 holds private keys 1 and 2, and performs authentication processing with the terminal device B101 using the private key 2. The private key 1 has been encrypted such that the private key 1 is decryptable only when secure boot is completed. The private key 2 has been encrypted such that the private key 2 is decryptable using the private key 1 only when the application module X that has been started is valid. When the authentication processing is successful, the terminal device B101 verifies that the terminal device A100 has completed secure boot and the application module X that has been started in the terminal device A100 is valid. Also, the terminal device B101 performs the authentication processing using the same private key 2, regardless of whether a program pertaining to the secure boot of the terminal device A100 is updated or not.

    摘要翻译: 本发明提供一种信息处理装置,认证系统等,其即使在客户端装置中的软件模块被更新时也能够保存服务器更新数据库等的故障,并且能够验证软件模块 已经在客户端设备中启动的是有效的。 终端装置A100保持私有密钥1和2,并使用专用密钥2对终端装置B101进行认证处理。专用密钥1已被加密,使得专用密钥1仅在安全引导完成时被解密。 专用密钥2已经被加密,使得仅当已经启动的应用模块X有效时,私钥2可以使用专用密钥1被解密。 当认证处理成功时,终端装置B101验证终端装置A100是否已经完成安全引导,并且已经在终端装置A100中启动的应用模块X有效。 此外,终端装置B101使用相同的私钥2执行认证处理,而不管终端装置A100的安全引导有关的程序是否被更新。

    Private electronic value bank system
    10.
    发明授权
    Private electronic value bank system 有权
    私人电子价值银行系统

    公开(公告)号:US07865431B2

    公开(公告)日:2011-01-04

    申请号:US10416065

    申请日:2001-11-07

    IPC分类号: G06Q40/00

    摘要: To make an electronic value usable for both service on a network and service in the real world while ensuring security, convenience and economical efficiency, the electronic value issued for a user is controlled on an electronic wallet of a private electronic value bank, the electronic value controlled on the electronic wallet of a bank is cached in a mobile electronic wallet on a smart card of a user's portable terminal 5, and the electronic wallet is linked such that it is operated via the network when the mobile electronic wallet is operated. When the electronic value on the smart card is used for the service provided in a real environment such as a ticket gate of a train station, on-line transaction does not occur every time it is used, but the electronic wallet of the bank is updated when the portable terminal and the bank communicate later.

    摘要翻译: 为确保安全性,便利性和经济效益,在现实世界中为网络服务和服务提供电子价值,为用户发行的电子价值控制在私人电子价值银行的电子钱包上,电子价值 控制在银行的电子钱包上的用户便携式终端5的智能卡上的移动电子钱包中被缓存,电子钱包被链接,使得当移动电子钱包被操作时通过网络进行操作。 当智能卡上的电子价值用于在诸如火车站的门票的真实环境中提供的服务时,每次使用时不会发生在线交易,而是更新银行的电子钱包 当便携式终端和银行后来通信时。