Memory card
Abstract
A memory card has: a flash memory chip for storing digital certificates and a seed of random numbers; a controller chip which can execute a managing process for managing the digital certificates and a random number generating process for generating the pseudo random numbers by using the seed of random numbers; and an IC card chip which can execute an authenticating process for authenticating personal identification information (PIN) inputted from a host apparatus and an encrypting process for encrypting the seed of random numbers. Thus, a processing time of security processes is reduced while assuring safety of the security processes.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A memory card comprising a flash memory, a controller, and an IC card chip, wherein
said flash memory stores a digital certificate necessary for an external host apparatus to obtain data from a server which can communicate with said host apparatus and a seed of random numbers serving as an element of random numbers which are used for mutually exchanging said data between said server and said host apparatus, said controller can execute a managing process for managing said digital certificate and a random number generating process for generating said pseudo random numbers by using said seed of random numbers, and said IC card chip can execute an authenticating process for authenticating personal identification number information inputted from said host apparatus and an encrypting process for encrypting said seed of random numbers by using a key corresponding to a key held by said server.
2 . A card according to claim 1 , wherein
said controller has a register to which an access from said host apparatus is limited, and said controller sets predetermined data into said register on the basis of an authentication result of said personal identification information by said IC card chip before said random number generating process is executed.
3 . A card according to claim 2 , wherein
said IC card chip encrypts the authentication result of said personal identification information by using a common key which is shared between said IC card chip and said controller and outputs the encrypted authentication result of said personal identification information to said controller, and said controller decrypts the encrypted authentication result of said personal identification number information by using said common key and sets said predetermined data into said register on the basis of the decrypted authentication result of said personal identification information.
4 . A card according to claim 2 , wherein
said register abandons said predetermined data set in said register when a supply of a power source to said controller is stopped.
5 . A card according to claim 2 , wherein
said controller starts the execution of said random number generating process if it is determined that said personal identification information has successfully been authenticated with reference to said predetermined data in said register.
6 . A card according to claim 1 , wherein said managing process includes a process for updating or adding said digital certificate.
7 . A card according to claim 1 , wherein said IC card chip has a cryptography coprocessor for encrypting said seed of random numbers.
8 . A memory card according to claim 1 , wherein
tamper-resistant of said IC card chip is higher than that of said controller, and said IC card chip holds reference information which is used for authenticating said personal identification information inputted from said host apparatus and compares said reference information with said personal identification information, thereby authenticating said personal identification information.
9 . A storage device comprising:
a non-volatile memory; a controller for executing a predetermined process in response to a command from an external host apparatus; and an IC for executing a predetermined process in response to a command from said controller, wherein
said controller can executes a part of a series of security processes necessary for exchanging information between a server and said host apparatus via a network, and
said IC executes another part of said series of security processes.
10 . A device according to claim 9 , wherein
a part of said series of security processes includes a random number generating process for generating random numbers for encrypting or decrypting said information, and another part of said series of security processes includes an authenticating process for authenticating said personal identification information inputted from said host apparatus when said series of security processes is started.
11 . A device according to claim 10 , wherein
said IC has a first register for temporarily holding predetermined data, said controller has a second register for temporarily holding predetermined data, said IC can set said predetermined data into said first register when said personal identification information has successfully been authenticated, and executes another part of said series of security processes when said predetermined data has been set in said first register, and said controller can set said predetermined data into said second register when said personal identification information has successfully been authenticated, and executes a part of said series of security processes when said predetermined data has been set in said second register.
12 . A device according to claim 10 , wherein
said non-volatile memory stores a seed of random numbers serving as an element of said random numbers, said random number generating process falsely generates the random numbers by using said seed of random numbers, and another part of said series of security processes includes an encrypting process for encrypting said seed of random numbers by using a key corresponding to a key held in said server.
13 . A device according to claim 10 , wherein
said non-volatile memory stores a digital certificate issued by a certificate authority, and a part of said series of security processes includes a managing process for reading out said digital certificate from said non-volatile memory and outputting it to said host apparatus.
14 . A device according to claim 9 , wherein
said controller converts the command from said host apparatus into a command which can be interpreted by said IC and outputs the converted command to said IC.Join the waitlist — get patent alerts
Track US2004059916A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.