JPH0253154A - Portable electronic equipment - Google Patents

Portable electronic equipment

Info

Publication number
JPH0253154A
JPH0253154A JP63204334A JP20433488A JPH0253154A JP H0253154 A JPH0253154 A JP H0253154A JP 63204334 A JP63204334 A JP 63204334A JP 20433488 A JP20433488 A JP 20433488A JP H0253154 A JPH0253154 A JP H0253154A
Authority
JP
Japan
Prior art keywords
area
command
data
key
card
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
JP63204334A
Other languages
Japanese (ja)
Inventor
Tetsuo Tateno
舘野 哲夫
Takashi Niimura
新村 貴志
Ryoichi Kuriyama
量一 栗山
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Toshiba Corp
Toshiba Intelligent Technology Co Ltd
Original Assignee
Toshiba Corp
Toshiba Intelligent Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Toshiba Corp, Toshiba Intelligent Technology Co Ltd filed Critical Toshiba Corp
Priority to JP63204334A priority Critical patent/JPH0253154A/en
Publication of JPH0253154A publication Critical patent/JPH0253154A/en
Pending legal-status Critical Current

Links

Landscapes

  • Storage Device Security (AREA)

Abstract

PURPOSE:To secure the different access conditions for the same area according to the commands by performing the access actions in response to the area access control condition information showing the collation conditions of identification number keys for each command instructing an access action. CONSTITUTION:An IC card 1 includes a control element (CPU) 15, a nonvolatile data memory 16 whose contents can be erased, and a contact part 18 where an electrical contact is secured between a program memory 17 and a card reader/writer 2. The memory 16 is divided into plural areas including an identification information area 16a where the registering state is identified for a data area, a control condition area 16b where the area access control condition information is stored for each command of the data area, and plural data areas 16c. The area 16b is set for each command of each area and contains the identification number key collation propriety conditions and the designated identification number key collation conditions for execution of the collation.

Description

【発明の詳細な説明】 [発明の目的] (産業上の利用分野) この発明は、たとえば不揮発性のデータメモリおよびC
PUなどの制御素子を有するICチップを内蔵したいわ
ゆるICカードと称される携帯可能電子装置に関する。
[Detailed Description of the Invention] [Object of the Invention] (Industrial Application Field) The present invention is applicable to, for example, non-volatile data memory and C
The present invention relates to a portable electronic device called an IC card that has a built-in IC chip having a control element such as a PU.

(従来Q技術) 最近、新たな携帯可能なデータ記憶媒体として、不揮発
性のデータメモリおよびCPU (セントラル・プロセ
ッシング・ユニット)などの制御素子を有するICチッ
プを内蔵したICカードが開発されている。この種のI
Cカードは、内蔵する制御素子によって内蔵するデータ
メモリをアクセスし、外部装置からの要求に応じて必要
なブタの入出力を行うものである。また、データメモリ
はファイルの概念に似たエリアによって定義され、この
エリアをアクセス単位としている。
(Conventional Q Technology) Recently, as a new portable data storage medium, an IC card containing a built-in IC chip having a nonvolatile data memory and a control element such as a CPU (central processing unit) has been developed. This kind of I
The C card accesses a built-in data memory using a built-in control element, and performs necessary input/output in response to a request from an external device. Further, data memory is defined by an area similar to the concept of a file, and this area is used as an access unit.

このようなICカードのデータメモリに対して外部から
アクセスを行う際、コマンドを用いて行う方法がとられ
ている。つまり、ICカードに対して、所定の動作を実
行させたい場合、アクセスするエリアの指定とその動作
に該当するコマンドを用いて、所定のエリアへのアクセ
スを行う。
When accessing the data memory of such an IC card from the outside, a method is used that uses commands. That is, when the IC card is desired to perform a predetermined operation, the predetermined area is accessed by specifying the area to be accessed and using a command corresponding to the operation.

また、ICカードは、アクセスを行うエリアに対して、
暗証キー(暗証番号)の照合が必要か否かの制御条件を
チエツクする。この制御条件は、たとえばエリアをアク
セスするための条件であり、カード使用者に対してカー
ドを提供するもの(カード発行者)により予めカード内
に設定されている。上記制御条件のチエツクにより、制
御条件が「必要」と設定、されていれば、入力されたコ
マンドの種別をチエツクする処理に移る。このチエツク
により、暗証キーがどのような条件で設定されていなけ
ればならないのか、例えば複数の暗証キーを全て照合さ
れなければならない、または1つ以上照合されていれば
良いという設定条件のもとで、ICカードが判断する。
In addition, the IC card is used for the area to be accessed.
Check the control conditions to determine whether or not verification of the PIN key (PIN number) is required. This control condition is, for example, a condition for accessing an area, and is set in advance in the card by the entity (card issuer) that provides the card to the card user. As a result of checking the control conditions, if the control conditions are set as "necessary", the process moves on to checking the type of the input command. This check determines under what conditions the PIN keys must be set. For example, under the setting conditions that all multiple PIN keys must be verified, or only one or more must be verified. , determined by the IC card.

この設定条件も、上記制御条件の中に定義されている。This setting condition is also defined in the above control conditions.

この設定条件に従い、ICカードは暗証キーの照合のチ
エツクを行い、このチエツクが正常であれば、上記指定
されたエリアにおいて、上記コマンドに対応した処理を
実行する。
According to the setting conditions, the IC card checks the verification of the password, and if the check is normal, executes the process corresponding to the command in the specified area.

また、異常であれば、所定のキー照合がされていないと
いうことで、外部に対してエラーを出力し、当コマンド
の実行が中止される。
Furthermore, if there is an abnormality, it means that the predetermined key verification has not been performed, and an error is output to the outside, and the execution of this command is aborted.

また、上記エリアをアクセスするための制御条件におい
て、エリアアクセスのための暗証キーが「不要」と定義
されていれば、そのエリアに対して直ちに上記コマンド
に対応した処理が実行される。
Furthermore, in the control conditions for accessing the area, if the password key for accessing the area is defined as "unnecessary", the process corresponding to the command is immediately executed for the area.

しかし、上記のように、初めにエリアアクセスのための
暗証キーの照合が必要か否かをチエツクしているので、
暗証キーの必要/不要条件を定義する際、「必要」とす
るところ、メモリセル不良で「不要」となってしまった
り、故意に「不要」とすると、そのエリアに対してどの
コマンドが入力されてもアクセスしてしまう恐れがあっ
た。
However, as mentioned above, since we first check whether or not it is necessary to verify the PIN for area access,
When defining the necessary/unnecessary conditions for a PIN key, if it becomes "unnecessary" due to a memory cell failure or is intentionally set as "unnecessary", what commands will be entered for that area? However, there was a risk that it could be accessed.

したがって、エリア内のデータを保護できない場合が生
じるという欠点があった。また、同一エリアに対してコ
マンドによってアクセスの条件を異ならせることができ
るものが要望されていた。
Therefore, there is a drawback that data within the area may not be protected. Additionally, there was a demand for something that could change the access conditions for the same area depending on the command.

(発明が解決しようとする課題) 上記したように、エリア内のデータを保護できない場合
が生じるという欠点を除去し、また同一エリアに対して
コマンドによってアクセスの条件を異ならせることがで
きるものが要望されているもので、エリア内のデータを
確実に保護することができ、また同一エリアに対し′て
コマンドによってアクセスの条件を異ならせることがで
き、アクセス制御においても運用し易くすることができ
る携帯可能電子装置を提供することを目的とする。
(Problems to be Solved by the Invention) As mentioned above, there is a desire for something that can eliminate the disadvantage that data within an area may not be protected, and that can also set different access conditions for the same area depending on the command. It is a mobile phone that can reliably protect data within an area, and also allows access conditions to be varied based on commands for the same area, making access control easier to operate. The purpose is to provide a capable electronic device.

[発明の構成] (課題を解決するための手段) この発明の携帯可能電子装置は、複数のエリアに分割さ
れているデータメモリ部と、このデータメモリに対して
データの読出しおよび書込みを行うための制御素子を有
し、選択的に外部からの入出力を行う手段を具備するも
のにおいて、上記データメモリの所定のエリアに対する
アクセスを行う際、アクセス動作を行うコマンド毎の暗
証キーの照合条件を示すエリアアクセス制御条件情報に
応じてアクセス動作を行う制御手段を設けたものである
[Structure of the Invention] (Means for Solving the Problems) A portable electronic device of the present invention includes a data memory section divided into a plurality of areas, and a device for reading and writing data to the data memory. When accessing a predetermined area of the data memory, a code key matching condition is set for each command to perform an access operation. A control means for performing an access operation according to area access control condition information shown is provided.

(作用) この発明は、データメモリの所定のエリアに対するアク
セスを行う際、アクセス動作を行うコマンド毎の暗証キ
ーの照合条件を示すエリアアクセス制御条件情報に応じ
てアクセス動作を行うようにしたものである。
(Function) In the present invention, when accessing a predetermined area of a data memory, the access operation is performed in accordance with area access control condition information indicating the verification condition of a password for each command that performs the access operation. be.

(実施例) 以下、この発明の一実施例について図面を参照して説明
する。
(Example) Hereinafter, an example of the present invention will be described with reference to the drawings.

第2図はこの発明の携帯可能電子装置としてのICカー
ドが適用される、たとえばホームバンキングシステムあ
るいはショッピングシステムなどの端末装置として用い
られるカード取扱装置の構成例を示すものである。すな
わち、この装置は、ICカード1をカード処理装置とし
てのカードリーダ・ライタ2を介してCPUなどからな
る制御部3と接続可能にするとともに、制御部3にキー
ボード4、CRTデイスプレィ装置5、プリンタ6およ
びフロッピーディスク装置7を接続して構成される。
FIG. 2 shows an example of the configuration of a card handling device used as a terminal device in, for example, a home banking system or a shopping system, to which an IC card as a portable electronic device of the present invention is applied. That is, this device enables an IC card 1 to be connected to a control section 3 consisting of a CPU, etc. via a card reader/writer 2 as a card processing device, and also connects the control section 3 with a keyboard 4, a CRT display device 5, and a printer. 6 and a floppy disk device 7 are connected.

上記ICカード1は、ユーザが保持し、たとえば商品購
入などの際にユーザのみが知得している暗証番号の参照
や必要データの蓄積などを行うもので、第3図にその機
能ブロックを示すように、リード・ライト部11、暗証
設定・暗証照合部12、および暗号化・復号化部13な
どの基本機能を実行する部分と、これらの基本機能を管
理するスーパバイザ14とで構成されている。リード・
ライト部11は、カードリーグ・ライタ2との間でデー
タを読出し、書込み、あるいは消去を行う機能である。
The IC card 1 is held by the user and is used to refer to a personal identification number known only to the user when purchasing a product, for example, and to store necessary data.The functional blocks of the IC card 1 are shown in Fig. 3. As shown in FIG. 2, it consists of parts that execute basic functions such as a read/write section 11, a password setting/password verification section 12, and an encryption/decryption section 13, and a supervisor 14 that manages these basic functions. . Lead
The write unit 11 has a function of reading, writing, or erasing data with the card league writer 2.

暗証設定・暗証照合部12は、ユーザが設定した暗証番
号の記憶および読出禁止処理を行うとともに、暗証番号
の設定後にその暗証番号の照合を行ない、以後の処理の
許可を与える機能である。暗号化・復号化部13は、た
とえば通信回線を介して制御部3から他の端末装置へデ
ータを送信する場合の通信データの漏洩、偽造を防止す
るための暗号化や暗号化されたデータの復号化を行うも
のであり、たとえばDES(D a t e  E n
cryptlon  S tandard)など、充分
な暗号強度を有する暗号化アルゴリズムにしたがってデ
ータ処理を行う機能である。スーパバイザ14は、カー
ドリーダ・ライタ2から入力された機能コードもしくは
データの付加された機能コードを解読し、前記基本機能
のうち必要な機能を選択して実行させる機能である。
The password setting/password verification unit 12 has the function of storing the password set by the user and prohibiting reading of the password, as well as verifying the password after setting the password and granting permission for subsequent processing. The encryption/decryption unit 13 performs encryption and encryption of encrypted data to prevent leakage and forgery of communication data when transmitting data from the control unit 3 to another terminal device via a communication line, for example. It performs decoding, for example DES (D a te E n
This is a function that processes data according to an encryption algorithm that has sufficient cryptographic strength, such as Cryptlon Standard. The supervisor 14 has the function of decoding the function code input from the card reader/writer 2 or the function code to which data is added, and selecting and executing a necessary function among the basic functions.

これらの諸機能を発揮させるために、ICカード1は例
えば第4図に示すように、制御素子(たとえばCPU)
15、記憶内容が消去可能な不揮発性のデータメモリ1
6、プログラムメモリ17、およびカードリーグ・ライ
タ2との電気的接触を得るためのコンタクト部18によ
って構成されており、これらのうち破線内の部分(制御
素子15、データメモリ16、プログラムメモリ17)
は1つのICチップで構成されている。プログラムメモ
リ17は、たとえばマスクROMで構成されており、前
記各基本機能を実現するサブルーチンを備えた制御素子
15の制御プログラムを記憶するものである。データメ
モリ16は各種データの記憶に使用され、たとえばEE
PROMで構成されている。
In order to perform these various functions, the IC card 1 has a control element (for example, a CPU) as shown in FIG.
15. Nonvolatile data memory whose memory contents can be erased 1
6. Consists of a program memory 17 and a contact part 18 for obtaining electrical contact with the card league writer 2, of which the part within the broken line (control element 15, data memory 16, program memory 17)
is composed of one IC chip. The program memory 17 is composed of, for example, a mask ROM, and stores a control program for the control element 15, which includes subroutines for realizing each of the basic functions. The data memory 16 is used to store various data, such as EE
It is composed of PROM.

上記データメモリ16は、複数のエリアに分割されてい
て、第5図に示すようなデータエリアの登録状態を識別
する識別情報エリア16aと、第6図に示すようなデー
タエリアのコマンド毎のエリアアクセス制御条件情報(
暗証キーの照合条件)を記憶する制御条件エリア16b
と、第7図に示すような複数のデータエリア16cとか
ら構成されており、それぞれのエリアにはエリア番号r
00−FFJが与えられている。
The data memory 16 is divided into a plurality of areas, including an identification information area 16a for identifying the registration status of the data area as shown in FIG. 5, and an area for each command in the data area as shown in FIG. Access control condition information (
control condition area 16b for storing personal identification key verification conditions)
and a plurality of data areas 16c as shown in FIG. 7, and each area has an area number r.
00-FFJ is given.

制御条件エリア16bに記憶されるエリアアクセス制御
条件情報は、各エリアの各コマンド情報毎に設定されて
おり、暗証キー照合必要/不要条件、指定暗証キー照合
条件から構成されている。
The area access control condition information stored in the control condition area 16b is set for each command information of each area, and is composed of a password key verification necessary/unnecessary condition and a specified password key verification condition.

コマンド情報としては、たとえばコマンド情報1がデー
タの書込み、コマンド情報2がデータの読出しとなって
いる。暗証キー照合必要/不要条件は、暗証キーの照合
が必要か不要かを示すものであり、暗証キーの照合が必
要な場合「1」、不要な場合「0」となっている。指定
暗証キー照合条件は、照合完全一致(全て照合)か1つ
以上一致か、照合完全一致の場合のキー1、キー2の照
合条件とから構成されるもので、照合完全一致の場合「
1」、1つ以上一致の場合「0」となっており、照合完
全一致でキー1、キー2の照合条件がrOlOJの場合
、アクセス不可を意味し、「o。
As command information, for example, command information 1 is for writing data, and command information 2 is for reading data. The PIN key verification necessary/unnecessary condition indicates whether PIN key verification is necessary or not, and is set to "1" if PIN key verification is required, and "0" if not required. The specified PIN key verification conditions consist of a complete match (all matches), one or more matches, and the match conditions for key 1 and key 2 in the case of a complete match.
1", if one or more matches, it is "0", and if there is a complete match and the matching conditions of key 1 and key 2 are rOlOJ, it means that access is not possible, and "o.

1」の場合、午−2のみの照合済で可を意味し、「1.
0」の場合、キー1のみの照合済で可を意味し、「1.
1」の場合、キー1、キー2両方の照合済で可を意味し
ており、1つ以上一致でキー1、キー2の照合条件が「
0.0」の場合、アクセス不可を意味し、「0.1」の
場合、キー2の照合済で可を意味し、「1、Q」の場合
、キー1の照合済で可を意味し、「1.1」の場合、キ
ー1、又はキー2の照合済で可を意味している。
1", it means that only pm-2 has been verified, and "1.
0" means that only key 1 has been verified, and "1.
1", it means that both key 1 and key 2 have been verified, and if one or more matches, the matching condition of key 1 and key 2 is "
0.0" means access is not possible, "0.1" means OK if key 2 has been verified, and "1,Q" means access is possible if key 1 has been verified. , "1.1" means that key 1 or key 2 has been verified and is acceptable.

各データエリアは、第8図に示すように、複数のレコー
ド(レコード単位に細分割)から構成されるようになっ
ている。このデータエリアには、書込みポインタが設け
られ、この書込みポインタのアドレス値に応じて順次未
書込みエリアにデータが書込まれるようになっている。
As shown in FIG. 8, each data area is composed of a plurality of records (subdivided into record units). A write pointer is provided in this data area, and data is sequentially written into the unwritten area according to the address value of this write pointer.

カードリーダ・ライタ2は、ICカード1と制御部3と
の間で機能コードやデータの授受を行うものである。具
体的には、第9図に示すように、図示しないカード挿入
口に挿入されたICカード1を所定の位置まで搬送する
搬送機構21、所定の位置にセットされたICカード1
のコンタクト部18に電気的に接触されるコンタクト部
22、全体の制御を司るCPUなどからなる制御回路2
3、制御回路23と制御部3との間で命令データや応答
データの授受を行うための入出力インターフェース回路
24、およびデータを記憶するデータメモリ25などか
ら構成されている。
The card reader/writer 2 is used to exchange function codes and data between the IC card 1 and the control section 3. Specifically, as shown in FIG. 9, there is a transport mechanism 21 that transports the IC card 1 inserted into a card insertion slot (not shown) to a predetermined position, and a transport mechanism 21 that transports the IC card 1 inserted into a card insertion slot (not shown) to a predetermined position.
A control circuit 2 consisting of a contact portion 22 that is electrically contacted with the contact portion 18 of the controller, and a CPU that controls the entire control circuit.
3. It is composed of an input/output interface circuit 24 for exchanging command data and response data between the control circuit 23 and the control section 3, and a data memory 25 for storing data.

次に、上記制御素子15のエリアアクセス制御条件情報
に応じたアクセス動作について、第1図に示すフローチ
ャートを参照しつつ説明する。まず、供給されるコマン
ドがコマンド情報1かコマンド情報2かをチエツクする
(STI、2)。コマンド情報1の場合、暗証キー必要
/不要条件が必要か不要かをチエツクする(Sr1)。
Next, the access operation of the control element 15 according to the area access control condition information will be explained with reference to the flowchart shown in FIG. First, it is checked whether the supplied command is command information 1 or command information 2 (STI, 2). In the case of command information 1, it is checked whether the PIN key required/unnecessary condition is necessary or not (Sr1).

このチエツクの結果、不要の場合、そのコマンド情報1
に対応する処理を実行する。上記チエツクの結果、必要
の場合、指定暗証キー照合条件に対応した処理を行う(
Sr1.5.6)。
As a result of this check, if it is unnecessary, the command information 1
Execute the corresponding process. As a result of the above check, if necessary, perform processing corresponding to the specified PIN verification conditions (
Sr1.5.6).

すなわち、指定暗証キーが完全一致か、1つ以上一致か
をチエツクし、それぞれの場合に、キー1、キー2の照
合条件に対応して照合チエツクを行う。
That is, it is checked whether the designated password keys match completely or whether one or more matches, and in each case, a verification check is performed in accordance with the verification conditions of key 1 and key 2.

また、ステップ2で、コマンド情報2が判断された場合
、暗証キー必要/不要条件が必要か不要かをチエツクす
る(Sr1)。このチエツクの結果、不要の場合、その
コマンド情報2に対応する処理を実行する。上記チエツ
クの結果、必要の場合、指定暗証キー照合条件に対応し
た処理を行う(Sr1.9.10)。
Further, if command information 2 is determined in step 2, it is checked whether the PIN key necessity/unnecessity condition is necessary or not (Sr1). As a result of this check, if the command information 2 is unnecessary, the process corresponding to the command information 2 is executed. As a result of the above check, if necessary, a process corresponding to the specified password key verification condition is performed (Sr1.9.10).

すなわち、指定暗証キーが完全一致か、1つ以上一致か
をチエツクし、それぞれの場合に、キー1、キー2の照
合条件に対応して照合チエツクを行う。
That is, it is checked whether the designated password keys match completely or whether one or more matches, and in each case, a verification check is performed in accordance with the verification conditions of key 1 and key 2.

また、ステップ2でコマンド情報2が判定されなかった
場合、該当コマンドなしを判定する。
Further, if command information 2 is not determined in step 2, it is determined that there is no corresponding command.

次に、このような構成において動作を説明する。Next, the operation in such a configuration will be explained.

まず、定常状態では、ICカード1はカードリーダ・ラ
イタ2からのコマンド情報待ち状態となっており、この
とき、制御部3からカードリーダ・ライタ2を介して制
御素子15にコマンド情報として「00」エリアにおけ
るデータの書込みを示すコマンド(戸マント情報1)が
入力されると、制御素子15はまず入力されたコマンド
の種類をチエツクする。ついで、制御素子15は上記エ
リアのコマンドの種類に対するデータメモリ16内の制
御条件エリア16bのエリアアクセス制御条件情報を読
出す。この場合、暗証キーの照合が必要であり、キー1
、キー2の両方の照合で上記コマンドに対する処理が許
可されるものである。
First, in a steady state, the IC card 1 is in a state of waiting for command information from the card reader/writer 2. At this time, the control unit 3 sends command information to the control element 15 via the card reader/writer 2 as "00". When a command (door mantle information 1) indicating writing of data in the ``area'' is input, the control element 15 first checks the type of the input command. Next, the control element 15 reads out area access control condition information in the control condition area 16b in the data memory 16 for the type of command in the area. In this case, it is necessary to verify the password, and the key 1
, key 2, processing for the above command is permitted.

これにより、制御素子15はカードリーダ・ライタ2を
介して制御部3ヘキー1、キー2の両方の暗証投入を指
示する。制御部3はCRTデイスプレィ装置5でキー1
、キー2の両方の暗証投入をオペレータに指示する。こ
の指示により、オペレータはキーボード4により、キー
1、キー2に対応する暗証を投入する。この暗証の投入
により、制御部3はキー1、キー2に対応する暗証をカ
ードリーダ・ライタ2を介してICカード1内の制御素
子15に供給する。これにより、制御素子15はその供
給された2つの暗証とデータメモリ16内に記憶されて
いるキー1、キー2に対応する暗証とを暗証設定・暗証
照合部12によってそれぞれ照合チエツクを行う。この
照合の結果、キー1、キー2に対応する両方の暗証が一
致した場合、制御素子15は上記コマンドに応じた処理
を実行する。すなわち、エリア「00」に対するデータ
の書込みを実行する。上記照合の結果、キー】1、キー
2に対応する両方の暗証が一致しない場合、一方の暗証
しか一致しない場合、制御素子15はカードリーダ・ラ
イタ2を介して制御部3にキー未照合というエラー出力
を行い、コマンド情報1に対する処理は中止され、終了
する。
Thereby, the control element 15 instructs the control unit 3 via the card reader/writer 2 to input the passwords of both keys 1 and 2. The control unit 3 uses the key 1 on the CRT display device 5.
, and instructs the operator to input the passwords for both keys. In response to this instruction, the operator uses the keyboard 4 to input the passwords corresponding to keys 1 and 2. By inputting the password, the control unit 3 supplies the password corresponding to the key 1 and the key 2 to the control element 15 in the IC card 1 via the card reader/writer 2. Thereby, the control element 15 performs a verification check between the two supplied passwords and the passwords corresponding to the keys 1 and 2 stored in the data memory 16 by the password setting/password collation section 12, respectively. As a result of this verification, if both passwords corresponding to keys 1 and 2 match, the control element 15 executes processing according to the above command. That is, data is written to area "00". As a result of the above verification, if both passwords corresponding to keys 1 and 2 do not match, or if only one password matches, the control element 15 sends a message to the control unit 3 via the card reader/writer 2 that the keys are not verified. An error is output, processing for command information 1 is stopped, and the process ends.

また、制御部3からカードリーダ・ライタ2を介して制
御素子15にコマンド情報として「00」エリアにおけ
るデータの読出しを示すコマンド(コマンド情報2)が
入力されると、制御素子15はまず入力されたコマンド
の種類をチエツクする。ついで、制御素子15は上記エ
リアのコマンドの種類に対するデータメモリ16内の制
御条件エリア16bのエリアアクセス制御条件情報を読
出す。この場合、暗証キーの照合が必要であり、キー1
、キー、2のいずれか一゛方の照合で上記コマンドに対
する処理が許可されるものである。
Further, when a command (command information 2) indicating reading of data in the "00" area is input as command information to the control element 15 from the control unit 3 via the card reader/writer 2, the control element 15 first receives the input. Check the type of command. Next, the control element 15 reads out area access control condition information in the control condition area 16b in the data memory 16 for the type of command in the area. In this case, it is necessary to verify the password, and the key 1
, key, 2, processing for the above command is permitted.

これにより、制御素子15はカードリーダ・ライタ2を
介して制御部3ヘキー1、キー2のいずれか一方の暗証
投入を指示する。制御部3はCRTデイスプレィ装置5
でキー1、キー2のいずれか一方の暗証投入をオペレー
タに指示する。
Thereby, the control element 15 instructs the control unit 3 via the card reader/writer 2 to input the password of either the key 1 or the key 2. The control unit 3 is a CRT display device 5
Instructs the operator to input the password for either key 1 or key 2.

この指示により、オペレータはキーボード4により、キ
ー1、あるいはキー2に対応する暗証を投入する。この
暗証の投入により、制御部3はキー1、あるいはキー2
に対応する暗証をカードリーダ・ライタ2を介してIC
カード1内の制御素子15に供給する。これにより、制
御索子15はその供給された暗証とデータメモリ16内
に記憶されているキー1、キー2に対応する暗証とを暗
証設定・暗証照合部12によって照合チエツクを行う。
In response to this instruction, the operator uses the keyboard 4 to input the password corresponding to key 1 or key 2. By inputting this password, the control unit 3 selects key 1 or key 2.
The corresponding PIN is sent to the IC via card reader/writer 2.
It is supplied to the control element 15 in the card 1. Thereby, the control code 15 performs a verification check between the supplied password and the passwords corresponding to the keys 1 and 2 stored in the data memory 16 by the password setting/password matching section 12.

この照合の結果、キー1、あるいはキー2に対応する暗
証と一致した場合、制御素子15は上記コマンドに応じ
た処理を実行する。すなわち、エリア「00」に対する
データの読出しを実行する。上記照合の結果、キー1、
キー2に対応する両方の暗証が一致しない場合、制御素
子15はカードリーダ・ライタ2を介して制御部3にキ
ー未照合というエラー出力を行い、コマンド情報2に対
する処理は中止され、終了する。
As a result of this verification, if the password matches the password corresponding to key 1 or key 2, control element 15 executes processing according to the above command. That is, reading data from area "00" is executed. As a result of the above verification, key 1,
If both passwords corresponding to the key 2 do not match, the control element 15 outputs an error indicating that the key has not been verified to the control unit 3 via the card reader/writer 2, and the processing for the command information 2 is stopped and ends.

また、制御部3からカードリーダ・ライタ2を介して制
御索子15にコマンド情報として「01」エリアにおけ
るデータの書込みを示すコマンド(コマンド情報1)が
入力されると、制御素子15はまず入力されたコマンド
の種類をチエツクする。ついで、制御素子15は上記エ
リアのコマンドの種類に対するデータメモリ16内の制
御条件エリア16bのエリアアクセス制御条件情報を読
出す。この場合、暗証キーの照合が必要であり、キー2
の照合で上記コマンドに対する処理が許可されるもので
ある。
Further, when a command (command information 1) indicating writing of data in the "01" area is input as command information to the control element 15 from the control unit 3 via the card reader/writer 2, the control element 15 first inputs the Check the type of command issued. Next, the control element 15 reads out area access control condition information in the control condition area 16b in the data memory 16 for the type of command in the area. In this case, it is necessary to verify the password, and the key 2
Processing for the above command is permitted by checking the above.

これにより、制御素子〕−5はカードリーダ・ライタ2
を介して制御部3ヘキー2の暗証投入を指示する。制御
部3はCRTデイスプレィ装置5でキー2の暗証投入を
オペレータに指示する。この指示により、オペレータは
キーボード4により、キー2に対応する暗証を投入する
。この暗証の投入により、制御部3はキー2に対応する
暗証をカードリーダ・ライタ2を介してICカード1内
の制御素子15に供給する。これにより、制御素子15
はその供給された暗証とデータメモリ16内に記憶され
ているキー2に対応する暗証とを暗証設定・暗証照合部
12によって照合チエツクを行う。この照合の結果、キ
ー2に対応する暗証が一致した場合、制御素子15は上
記コマンドに応じた処理を実行する。すなわち、エリア
「01」に対するデータの書込みを実行する。上記照合
の結果、キー2に対応する暗証が一致しない場合、制御
素子15はカードリーダ・ライタ2を介して制御部3に
キー未照合というエラー出力を行い、コマンド情報1に
対する処理は中止され、終了する。
As a result, the control element]-5 is connected to the card reader/writer 2.
The controller 3 instructs the controller 3 to input the password via the key 2. The control unit 3 instructs the operator to input the password of the key 2 on the CRT display device 5. In response to this instruction, the operator inputs the password corresponding to the key 2 using the keyboard 4. By inputting this password, the control section 3 supplies the password corresponding to the key 2 to the control element 15 in the IC card 1 via the card reader/writer 2. As a result, the control element 15
The password setting/password verification section 12 checks the supplied password against the password corresponding to the key 2 stored in the data memory 16. As a result of this verification, if the passwords corresponding to the keys 2 match, the control element 15 executes processing according to the above command. That is, data is written to area "01". As a result of the above verification, if the passwords corresponding to the keys 2 do not match, the control element 15 outputs an error message indicating that the keys have not been verified to the control unit 3 via the card reader/writer 2, and the processing for the command information 1 is canceled. finish.

また、制御部3からカードリーダ・ライタ2を介して制
御素子15にコマンド情報として「01」エリアにおけ
るデータの読出しを示すコマンド(コマンド情報1)が
入力されると、制御素子15はまず入力されたコマンド
の種類をチエツクする。ついで、制御素子15は上記エ
リアのコマンドの種類に対するデータメモリ16内の制
御条件エリア16bのエリアアクセス制御条件情報を読
出す。この場合、暗証キーの照合が不要であり、キーの
照合を行わずに上記コマンドに対する処理が許可される
ものであり、制御素子15は上記コマンドに応じた処理
を実行する。すなわち、エリア「01」に対するデータ
の読出しを寒行する。
Further, when a command (command information 1) indicating reading of data in the "01" area is input as command information to the control element 15 from the control unit 3 via the card reader/writer 2, the control element 15 first receives the input. Check the type of command. Next, the control element 15 reads out area access control condition information in the control condition area 16b in the data memory 16 for the type of command in the area. In this case, there is no need to verify the password, processing for the above command is permitted without performing key verification, and the control element 15 executes processing according to the command. That is, data reading for area "01" is suspended.

上記したように、データメモリの所定のエリアに対する
アクセスを行う際、アクセス動作を行うコマンド毎の、
暗証キーの照合が必要であるか否かを示す、あるいは暗
証キーの指定条件を示すエリアアクセス制御条件情報に
応じてアクセス動作を行うようにしたので、エリア内の
データを確実に保護することができる。
As mentioned above, when accessing a predetermined area of data memory, each command that performs an access operation
Since the access operation is performed according to the area access control condition information indicating whether or not verification of the PIN key is required or the conditions for specifying the PIN key, data in the area can be reliably protected. can.

また、所定のエリアに対してアクセスを行う場合に、コ
マンドごとに着圧キーの有無をのチエツクを具備し、同
一エリアに対してコマンドによってアクセスの条件を異
ならせることができ、アクセス制御においても運用し易
くすることができる。
In addition, when accessing a predetermined area, it is equipped with a check for the presence or absence of a pressurized key for each command, and the access conditions for the same area can be varied depending on the command. It can be made easier to operate.

なお、前記実施例は、携帯可能電子装置としてICカー
ドを例示したが、カード状のものに限定されるものでは
なく、たとえばブロック状あるいはペンシル状のもので
も良い。
In the above embodiments, an IC card is used as an example of the portable electronic device, but the portable electronic device is not limited to a card-shaped device, and may be a block-shaped or pencil-shaped device, for example.

[発明の効果] 以上詳述したようにこの発明によれば、エリア内のデー
タを確実に保護することができ、また同一エリアに対し
てコマンドによってアクセスの条件を異ならせることが
でき、アクセス制御においても運用し易くすることがで
きる携帯可能電子装置を提供できる。
[Effects of the Invention] As detailed above, according to the present invention, it is possible to reliably protect data within an area, and the access conditions for the same area can be varied depending on commands, thereby improving access control. It is possible to provide a portable electronic device that can be easily operated even in

【図面の簡単な説明】[Brief explanation of the drawing]

図面はこの発明の一実施例を説明するためのもので、第
1図はエリアアクセス制御条件情報に応じたアクセス動
作を説明するためのフローチャート、第2図はカード取
扱装贋の構成を示すブロック図、第3図はICカードの
機能ブロックを示す図、第4図はICカードに内蔵する
ICチップの構成を示すブロック図、第5図はデータメ
モリの識別情報エリアの記憶例を示す図、第6図はデー
タメモリの制御条件エリアの記憶例を示す図、第7図は
データメモリのデータエリアの記憶例を示す図、第8図
はデータメモリの構成例を説明するための図、第9図は
カードリーダ・ライタの構成を示すブロック図である。 1・・・ICカード(携帯可能電子装置)、2・・・カ
ードリーダ・ライタ、3・・・制御部、15・・・制御
素子(CPU) 、16・・・データメモリ、16a・
・・識別情報エリア、16b・・・制御条件エリア、1
6c・・・データエリア、23・・・制御回路。 出願人代理人 弁理士 鈴 江 武 彦第 図 第 図 箪 図 第 図
The drawings are for explaining one embodiment of the present invention, and FIG. 1 is a flowchart for explaining access operations according to area access control condition information, and FIG. 2 is a block diagram showing the configuration of card handling equipment. 3 is a diagram showing the functional blocks of the IC card, FIG. 4 is a block diagram showing the configuration of the IC chip built into the IC card, and FIG. 5 is a diagram showing a storage example of the identification information area of the data memory. FIG. 6 is a diagram showing a storage example of the control condition area of the data memory, FIG. 7 is a diagram showing a storage example of the data area of the data memory, FIG. 8 is a diagram for explaining an example of the configuration of the data memory, and FIG. FIG. 9 is a block diagram showing the configuration of the card reader/writer. DESCRIPTION OF SYMBOLS 1... IC card (portable electronic device), 2... Card reader/writer, 3... Control unit, 15... Control element (CPU), 16... Data memory, 16a.
...Identification information area, 16b...Control condition area, 1
6c...Data area, 23...Control circuit. Applicant's Representative Patent Attorney Takehiko Suzue

Claims (1)

【特許請求の範囲】  複数のエリアに分割されているデータメモリと、この
データメモリに対してデータの読出しおよび書込みを行
うための制御素子を有し、選択的に外部からの入出力を
行う手段を具備する携帯可能電子装置において、 上記データメモリの所定のエリアに対するアクセスを行
う際、アクセス動作を行うコマンド毎の暗証キーの照合
条件を示すエリアアクセス制御条件情報に応じてアクセ
ス動作を行う制御手段を設けたことを特徴とする携帯可
能電子装置。
[Claims] Means for selectively inputting and outputting data from the outside, comprising a data memory divided into a plurality of areas and a control element for reading and writing data to the data memory. In a portable electronic device, when accessing a predetermined area of the data memory, a control means performs an access operation in accordance with area access control condition information indicating a verification condition for a password for each command to perform an access operation. A portable electronic device characterized by being provided with.
JP63204334A 1988-08-17 1988-08-17 Portable electronic equipment Pending JPH0253154A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP63204334A JPH0253154A (en) 1988-08-17 1988-08-17 Portable electronic equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP63204334A JPH0253154A (en) 1988-08-17 1988-08-17 Portable electronic equipment

Publications (1)

Publication Number Publication Date
JPH0253154A true JPH0253154A (en) 1990-02-22

Family

ID=16488779

Family Applications (1)

Application Number Title Priority Date Filing Date
JP63204334A Pending JPH0253154A (en) 1988-08-17 1988-08-17 Portable electronic equipment

Country Status (1)

Country Link
JP (1) JPH0253154A (en)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPS6380982A (en) * 1986-09-22 1988-04-11 Ohara Kinzoku Kogyo Kk Controller for welding machine
WO1994010655A1 (en) * 1992-11-04 1994-05-11 Fujitsu Limited Ic card
FR2799021A1 (en) * 1999-09-27 2001-03-30 Schlumberger Systems & Service Method of management of commands in a smart card, received from different types of card reader, allowing differentiation between contact and non-contact readers
US7054990B1 (en) * 1999-08-11 2006-05-30 Renesas Technology Corp. External storage device using non-volatile semiconductor memory
US7356659B2 (en) 2000-06-02 2008-04-08 Renesas Technology Corp. Nonvolatile semiconductor memory and method of managing information in information distribution system

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPS6380982A (en) * 1986-09-22 1988-04-11 Ohara Kinzoku Kogyo Kk Controller for welding machine
WO1994010655A1 (en) * 1992-11-04 1994-05-11 Fujitsu Limited Ic card
US7054990B1 (en) * 1999-08-11 2006-05-30 Renesas Technology Corp. External storage device using non-volatile semiconductor memory
FR2799021A1 (en) * 1999-09-27 2001-03-30 Schlumberger Systems & Service Method of management of commands in a smart card, received from different types of card reader, allowing differentiation between contact and non-contact readers
US7356659B2 (en) 2000-06-02 2008-04-08 Renesas Technology Corp. Nonvolatile semiconductor memory and method of managing information in information distribution system

Similar Documents

Publication Publication Date Title
KR950007895B1 (en) Portable electronic apparatus
JP4405568B2 (en) Multi-application IC card system
JP2831660B2 (en) Portable electronic devices
JPS63201748A (en) Portable electronic equipment
JPH0440587A (en) Portable electronic equipment
JP3178881B2 (en) Portable electronic devices
JPH0416834B2 (en)
JPS62190585A (en) Portable electronic device
JPH01217689A (en) Portable electronic equipment
JPH0416832B2 (en)
JP3302348B2 (en) Portable electronic device and key matching method
JP3251579B2 (en) Portable electronic devices
JPH01194093A (en) Portable electronic device
JPH01205397A (en) Ic card
JPS63228282A (en) Portable electronic equipment
JPH03224047A (en) Portable electronic device
JPS63228283A (en) Portable electronic equipment
JPS63192180A (en) Portable electronic equipment
JPS6383894A (en) Portable electronic device
JPS63220386A (en) Portable electronic device
JPH03175596A (en) Portable electronic equipment
JPH03224082A (en) Portable electronic device
JPS63181088A (en) Portable electronic equipment
JPS62197848A (en) Portable electronic equipment system
JPH01147687A (en) Ic card