Security and ticketing system control and management
Abstract
A security device of this invention includes a nonvolatile storage unit 22 for storing a validity check unit including a counter updated every time signature function means 30 is called up, a volatile storage unit 24 for reading and storing a counter array out of an external nonvolatile storage unit storing the counter array, in which the counter array is obtained by coupling a hash value generated for each signature key with a signature number counter for counting the number of signatures performed by use of the signature key, and a hash function unit 28 for reading the counter array out of the volatile storage unit 24 , generating the hash value, and transferring the hash value to the validity check unit for a validity check.
Claims
exact text as granted — not AI-modified1 . A security device for restricting multiple uses of signed data, the security device comprising:
a nonvolatile storage unit for storing a validity check unit including a counter updated every time signature function means is called up; a volatile storage unit for reading and storing a counter array out of an external nonvolatile storage unit storing the counter array, the counter array being obtained by coupling a hash value generated for each signature key with a signature number counter for counting the number of signatures performed by use of the signature key; and a hash function unit for reading the counter array out of the volatile storage unit, generating the hash value, and transferring the hash value to the validity check unit for a validity check.
2 . The security device according to claim 1 ,
wherein the validity check unit further comprises: key means for assuring validity of the security device; and an immediately preceding hash value among hash values generated in the past and sent from the counter array.
3 . The security device according to claim 1 ,
wherein the hash function unit further reads a value in the counter and calculates the hash value which is a concatenated value with a value in the counter array.
4 . The security device according to claim 2 , further comprising:
a unit for comparing the generated hash value with the immediately preceding hash value.
5 . The security device according to claim 1 ,
wherein the security device executes a digital signature in response to a judgment of the validity by the validity check unit, updates a signature number counter, and causes the external nonvolatile storage unit to write an updated value in the signature number counter.
6 . An information processing device having a function for restricting multiple uses of signed data, the information processing device comprising:
the security device according to any one of claims 1 to 5 ; and an interface unit including a nonvolatile storage unit for storing a counter array configured to couple a hash value generated for each signature key with a signature number counter for counting the number of signatures performed by use of the signature key.
7 . A controlling method for controlling a security device for restricting multiple uses of signed data, the controlling method causing the security device to execute the steps of:
reading a counter array out of an external nonvolatile storage unit and storing the counter array in a volatile storage unit, the external nonvolatile storage unit storing the counter array obtained by coupling a hash value generated for each signature key with a signature number counter for counting the number of signatures performed by use of the signature key; reading the stored counter array for generating the hash value, and transferring the hash value to a validity check unit for a validity check, the validity check unit including key means for assuring validity of the security device and the immediately preceding hash value among hash values generated in the past and sent from the counter array; calling up signature function means in response to a judgment of validity by the validity check unit; and updating a counter every time the signature function means is called up.
8 . The controlling method according to claim 7 , further causing the security device to execute the step of:
storing an immediately preceding hash value among the hash values generated in the past and sent from the counter array.
9 . The controlling method according to claim 7 , further causing the security device to execute the step of:
allowing the hash function unit to read a value in the counter and to calculate the hash value which is a concatenated value obtained by coupling the counter value with a value in the counter array.
10 . The controlling method according to claim 8 , further causing the security device to execute the step of:
comparing the generated hash value with the immediately preceding hash value.
11 . The controlling method according to claim 7 , causing the security device to execute the steps of:
executing a digital signature in response to a judgment of the validity by the validity check unit; and updating a signature number counter corresponding to the executing of the digital signature and allowing the external nonvolatile storage unit to write an updated value in the signature number counter.
12 . A controlling method for controlling an information processing device having a function for restricting multiple uses of signed data, the controlling method causing the information processing device to execute the steps of:
executing the processing steps according to any one of claims 7 to 11 ; and transferring a counter array from an interface unit including a storage unit for storing the counter array configured to couple a hash value generated for each signature key with a signature number counter for counting the number of signatures performed by use of the signature key, to a security device.
13 . A program capable of implementing a device for executing the controlling method according to any one of claims 7 to 11 .
14 . A program capable of implementing a device for executing the controlling method according to claim 12 .
15 . A ticketing system using a digital ticket, the ticketing system comprising:
a ticket issuer terminal for issuing a ticket; the information processing device according to claim 8 for storing the issued ticket; a network for interconnecting the ticket issuer terminal and the information processing device; and a service terminal for issuing a ticket use request to the information processing device.
16 . The ticketing system according to claim 15 ,
wherein the information processing device obtains and stores the ticket from another information processing device and accesses the service terminal.
17 . An article of manufacture comprising a computer usable medium having computer readable program code means embodied therein for causing control of a security device, the computer readable program code means in said article of manufacture comprising computer readable program code means for causing a computer to effect at least one of the steps of claim 7 .
18 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform method steps for controlling a security device, said method steps comprising effect at least one of the steps of claim 7 .
19 . A computer program product comprising a computer usable medium having computer readable program code means embodied therein for causing functions of a security device, the computer readable program code means in said computer program product comprising computer readable program code means for causing a computer to effect at least one of the functions of claim 1 .
20 . A computer program product comprising a computer usable medium having computer readable program code means embodied therein for causing functions of an information processing device, the computer readable program code means in said computer program product comprising computer readable program code means for causing a computer to effect at least one of the functions of claim 6.Join the waitlist — get patent alerts
Track US2005204140A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.