JPH11345286A - Access control device, authentication system and recording medium - Google Patents

Access control device, authentication system and recording medium

Info

Publication number
JPH11345286A
JPH11345286A JP10150188A JP15018898A JPH11345286A JP H11345286 A JPH11345286 A JP H11345286A JP 10150188 A JP10150188 A JP 10150188A JP 15018898 A JP15018898 A JP 15018898A JP H11345286 A JPH11345286 A JP H11345286A
Authority
JP
Japan
Prior art keywords
command
access
data
password
unit
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
JP10150188A
Other languages
Japanese (ja)
Other versions
JP3825917B2 (en
Inventor
Teruhiro Kawashima
輝洋 川島
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tokyo Electron Ltd
Original Assignee
Tokyo Electron Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tokyo Electron Ltd filed Critical Tokyo Electron Ltd
Priority to JP15018898A priority Critical patent/JP3825917B2/en
Publication of JPH11345286A publication Critical patent/JPH11345286A/en
Application granted granted Critical
Publication of JP3825917B2 publication Critical patent/JP3825917B2/en
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Abstract

(57)【要約】 【課題】 記憶装置に格納されたデータを、その譲渡の
容易さを確保しつつ秘匿する簡便な認証システムを提供
することである。 【解決手段】 コンピュータ2にメモリカード1が装着
されると、コンピュータ2がイネーブルコマンドとパス
ワードをコントローラ12に供給する。コントローラ1
2は、供給されたイネーブルコマンドとパスワードがフ
ラッシュメモリ11に格納されているものと同じであれ
ばアクセスコマンドを受け付け、異なっていれば拒絶す
る。アクセスコマンドを受け付けているとき、コンピュ
ータ2がセットパスワードコマンド、新イネーブルコマ
ンド及び新パスワードをコントローラ12に供給する
と、コントローラ12はイネーブルコマンドとパスワー
ドを更新する。アクセスコマンドを受け付けていると
き、コンピュータ2が正しいイネーブルコマンド及び誤
ったパスワードをコントローラ12に供給すると、コン
トローラ12はアクセスコマンドを拒絶する。
(57) [Problem] To provide a simple authentication system for concealing data stored in a storage device while ensuring ease of transfer. When a memory card is inserted into a computer, the computer supplies an enable command and a password to a controller. Controller 1
2 accepts an access command if the supplied enable command and password are the same as those stored in the flash memory 11, and rejects the access command if they are different. When the computer 2 supplies the set password command, the new enable command, and the new password to the controller 12 while receiving the access command, the controller 12 updates the enable command and the password. When the computer 2 supplies a correct enable command and an incorrect password to the controller 12 while receiving the access command, the controller 12 rejects the access command.

Description

【発明の詳細な説明】DETAILED DESCRIPTION OF THE INVENTION

【0001】[0001]

【発明の属する技術分野】本発明は、認証システム及び
アクセス制御装置、特に、記憶装置の記憶内容の守秘を
図るための認証システム及びアクセス制御装置に関す
る。
BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to an authentication system and an access control device, and more particularly to an authentication system and an access control device for confidentially storing contents of a storage device.

【0002】[0002]

【従来の技術】近年、可搬性の不揮発性の記憶媒体、特
に携帯情報端末用の記憶媒体として、フラッシュメモリ
を備えたメモリカードなどが用いられるようになってい
る。メモリカードは、通常、例えばPCMCIAバスを
介してコンピュータ等と接続され、該コンピュータ等の
アクセスに応答して、該コンピュータ等より供給された
データを記憶したり、記憶しているデータを該コンピュ
ータ等に供給したりする。
2. Description of the Related Art In recent years, a memory card equipped with a flash memory has been used as a portable non-volatile storage medium, particularly as a storage medium for a portable information terminal. The memory card is generally connected to a computer or the like via, for example, a PCMCIA bus, and stores data supplied from the computer or the like in response to access from the computer or the like, or stores stored data in the computer or the like. Or to supply.

【0003】[0003]

【発明が解決しようとする課題】しかし、上述のメモリ
カードに格納されたデータは、そのメモリカードの所有
者以外の者によって、例えば他のコンピュータに接続さ
れることにより、その記憶内容が容易に漏洩する危険性
を有する。この危険性は、携帯性に優れたメモリカード
においては、特に大きい。
However, the data stored in the above-mentioned memory card can be easily stored by a person other than the owner of the memory card, for example, by being connected to another computer. Risk of leakage. This danger is particularly great in a memory card excellent in portability.

【0004】この問題を解決する手法としては、メモリ
カードに格納するデータを暗号化する手法が考えられ
る。しかし、データの暗号化や復号化を行うためのソフ
トウェアは、暗号化や復号化を行う数学的処理が膨大と
なるため実行時間が増大し、この結果、メモリカードを
快適に利用することが困難になる。また、データの暗号
化や復号化を行うためのソフトウェアは、上述の数学的
処理の煩雑さのために開発が困難である。
As a method of solving this problem, a method of encrypting data stored in a memory card can be considered. However, software for encrypting and decrypting data requires a large amount of mathematical processing to perform encryption and decryption, which increases execution time, and as a result, it is difficult to use a memory card comfortably. become. Also, software for encrypting and decrypting data is difficult to develop because of the complicated mathematical processing described above.

【0005】また、メモリカードの所有者等が、他の者
にデータを与えたい場合、暗号化されたデータは、一旦
コンピュータ等によりすべて復号化してからでないと、
相手方にとっては無意味なデータしか与えられない。こ
のため、データの譲渡や交換が煩雑になる。
When the owner of a memory card or the like wants to give data to another person, all the encrypted data must be once decrypted by a computer or the like.
Only meaningless data is given to the other party. For this reason, transfer and exchange of data become complicated.

【0006】この発明は上記実状に鑑みてなされたもの
で、記憶装置に格納されたデータを、その譲渡の容易さ
を確保しつつ秘匿する簡便な認証システムを提供するこ
とを目的とする。
The present invention has been made in view of the above circumstances, and has as its object to provide a simple authentication system for concealing data stored in a storage device while ensuring ease of transfer.

【0007】[0007]

【課題を解決するための手段】上記目的を達成するた
め、本発明の第1の観点にかかるアクセス制御装置(1
2)は、アクセスに応答してデータの格納及び供給を行
い、認証用データを書き換え可能に記憶する記憶領域を
有する記憶装置(11)と、操作者の指示に従って入力
データを取得する手段と、前記記憶装置(11)にアク
セスするためのコマンドを出力して、前記コマンドに応
答して供給された読み出しデータを取得する手段と、を
備えるアクセス装置(2)と、に接続されたアクセス制
御装置(12)であって、コマンド実行手段(121)
と、許可手段(121)と、を備え、前記許可手段(1
21)は、前記アクセス装置(2)が取得した前記入力
データが所定の認証用データと実質的に一致するか否か
を判別し、一致すると判別したとき、前記コマンド実行
手段(121)が前記アクセス装置(2)より前記コマ
ンドを受信することを許可する手段を備え、前記コマン
ド実行手段(121)は、前記許可手段が許可している
とき前記アクセス装置(2)が出力した前記コマンドを
受信し、受信した前記コマンドが所定のアクセスコマン
ドを表すとき、受信した前記コマンドに応答して前記記
憶装置(11)にアクセスし、当該アクセスによって前
記記憶装置(11)より取得した前記読み出しデータを
前記アクセス装置(2)に供給する手段を備え、前記コ
マンド実行手段(121)は、前記アクセス装置(2)
より受信したコマンドが所定の設定変更コマンドを表す
とき、前記アクセス装置(2)より新たな前記認証用デ
ータを取得して、取得した前記認証用データを、前記記
憶装置(11)の前記記憶領域に格納する更新手段(1
21)を備える、ことを特徴とする。
In order to achieve the above object, an access control apparatus (1) according to a first aspect of the present invention is provided.
2) a storage device (11) that stores and supplies data in response to access and has a storage area for rewritably storing authentication data, and a unit that obtains input data according to an instruction of an operator; Means for outputting a command for accessing the storage device (11) and obtaining read data supplied in response to the command, the access control device being connected to the access control device (2). (12) Command execution means (121)
And permission means (121).
21) determines whether or not the input data obtained by the access device (2) substantially matches predetermined authentication data. When it is determined that the input data matches, the command execution means (121) determines whether Means for permitting reception of the command from the access device (2), wherein the command execution means (121) receives the command output by the access device (2) when the permission means permits. Then, when the received command represents a predetermined access command, the storage device (11) is accessed in response to the received command, and the read data acquired from the storage device (11) by the access is written to the storage device (11). Means for supplying to the access device (2), wherein the command execution means (121) comprises:
When the received command indicates a predetermined setting change command, new authentication data is obtained from the access device (2), and the obtained authentication data is stored in the storage area of the storage device (11). Update means (1
21).

【0008】このようなアクセス制御装置に接続された
記憶装置は、アクセス装置から正しい認証用データが供
給された場合に、コマンド実行手段によるアクセスを受
ける。このため、記憶装置に格納されたデータが秘匿さ
れる。また、認証用データの発給を行うソフトウェア
は、暗号化や復号化を行うソフトウェアに比べて処理の
内容が簡便であって、開発も容易であり、またメモリ等
の記憶装置の快適な使用を妨げない。
[0008] A storage device connected to such an access control device is accessed by the command execution means when correct authentication data is supplied from the access device. Therefore, the data stored in the storage device is kept secret. In addition, software that issues authentication data has simpler processing contents than software that performs encryption and decryption, is easier to develop, and hinders comfortable use of storage devices such as memories. Absent.

【0009】なお、記憶装置へのアクセスの動作には、
記憶装置に格納されているデータの読み出しに限られ
ず、記憶装置へのデータの書き込みも含まれる。従っ
て、前記アクセス装置(2)は、前記記憶装置(11)
に格納するための書き込みデータを出力する手段を備え
るものであって、前記許可手段(121)は、前記アク
セス装置(2)が取得した前記入力データが前記認証用
データと実質的に一致するか否かを判別し、一致すると
判別したとき、前記コマンド実行手段(121)が前記
書き込みデータを受信することを許可する手段を備え、
前記コマンド実行手段(121)は、前記許可手段が許
可しているとき前記書き込みデータを受信する手段と、
受信した前記コマンドが前記書き込みデータの書き込み
を指示する前記アクセスコマンドを表すとき、受信した
前記コマンドに応答して前記記憶装置(11)の前記記
憶領域に前記書き込みデータを書き込む手段と、を備え
るものであってもよい。
The operation of accessing the storage device includes:
It is not limited to reading data stored in the storage device, but also includes writing data to the storage device. Therefore, the access device (2) is provided in the storage device (11).
Means for outputting write data to be stored in the access device, wherein the permission means (121) determines whether the input data acquired by the access device (2) substantially matches the authentication data. Means for permitting the command execution means (121) to receive the write data,
Means for receiving the write data when the permission means permits the command execution means;
Means for writing the write data to the storage area of the storage device (11) in response to the received command when the received command indicates the access command instructing writing of the write data. It may be.

【0010】前記認証用データは、例えば、イネーブル
コマンド及びパスワードからなり、前記許可手段(12
1)は、前記コマンド実行手段(121)が前記アクセ
ス装置(2)より前記コマンドを受信することを許可し
ていないとき、前記アクセス装置(2)が取得した前記
入力データが前記イネーブルコマンド及び前記パスワー
ドを実質的に含むか否かを判別し、両者を含むと判別し
たとき、前記コマンド実行手段(121)が前記コマン
ドを受信することを許可する手段(121)を備えるも
のであってもよい。
The authentication data comprises, for example, an enable command and a password.
1) when the command executing means (121) does not permit receiving the command from the access device (2), the input data acquired by the access device (2) is the enable command and the It may be provided with a means (121) for judging whether or not the password is substantially included and, when judging that both are included, permitting the command execution means (121) to receive the command. .

【0011】前記認証用データがイネーブルコマンド及
びパスワードからなる場合、前記許可手段は、前記コマ
ンド実行手段(121)が前記アクセス装置(2)より
前記コマンドを受信することを許可しているとき、前記
アクセス装置(2)が取得した前記入力データが前記イ
ネーブルコマンド及び前記バスワードを実質的に含むか
否かを判別し、前記イネーブルコマンドを含み、且つ前
記パスワードを含まないと判別したとき、前記コマンド
実行手段(121)が前記コマンドを受信することを禁
止する手段(121)と、を備えるものであってもよ
い。
When the authentication data is composed of an enable command and a password, the permitting means, when permitting the command executing means (121) to receive the command from the access device (2), Determining whether the input data acquired by the access device (2) substantially includes the enable command and the password, and determining that the input data includes the enable command and does not include the password; Means (121) for prohibiting the execution means (121) from receiving the command.

【0012】これにより、記憶装置に格納されているデ
ータは、記憶装置の使用中であっても、他の者が読み出
せないような状態に変更される。従って、例えば記憶装
置のユーザが一時的に記憶装置のある場所を離れるよう
な場合であっても、記憶装置に格納されているデータは
確実に秘匿される。
As a result, the data stored in the storage device is changed to a state in which the data cannot be read by another person even while the storage device is being used. Therefore, for example, even when the user of the storage device temporarily leaves the location of the storage device, the data stored in the storage device is securely concealed.

【0013】前記イネーブルコマンド及び前記パスワー
ドは互いに対応付けられて対をなしており、前記許可手
段(121)は、前記コマンド実行手段(121)が前
記アクセス装置(2)より前記コマンドを受信すること
を許可していないとき、前記アクセス装置(2)が取得
した前記入力データが前記イネーブルコマンド及び前記
バスワードの対を実質的に含んでいるか否かを判別し、
その対を含んでいると判別したとき、前記コマンド実行
手段(121)が前記コマンドを受信することを許可す
る手段(121)と、前記コマンド実行手段(121)
が前記アクセス装置(2)より前記コマンドを受信する
ことを許可しているとき、前記アクセス装置(2)が取
得した前記入力データが前記イネーブルコマンド及びそ
のイネーブルコマンドと対をなす前記バスワードを実質
的に含んでいるか否かを判別し、前記イネーブルコマン
ドを含み、且つそのイネーブルコマンドと対をなす前記
パスワードを含まないと判別したとき、前記コマンド実
行手段(121)が前記コマンドを受信することを禁止
する手段(121)と、を備えるものであってもよい。
この場合、イネーブルコマンド及びパスワードは複数設
定可能となる。
[0013] The enable command and the password are associated with each other to form a pair, and the permission means (121) determines that the command execution means (121) receives the command from the access device (2). And determining whether the input data obtained by the access device (2) substantially includes the pair of the enable command and the password,
A means (121) for permitting the command execution means (121) to receive the command when it is determined that the command execution means includes the pair, and a command execution means (121)
Is permitted to receive the command from the access device (2), the input data obtained by the access device (2) substantially converts the enable command and the password that forms a pair with the enable command. If the command execution means (121) receives the enable command and determines that the password does not include the password corresponding to the enable command, the command execution means (121) receives the command. Prohibition means (121).
In this case, a plurality of enable commands and passwords can be set.

【0014】前記許可手段(121)は、前記パスワー
ドが所定のデータを含むとき、前記アクセス装置(2)
が取得した前記入力データが前記イネーブルコマンド及
び前記バスワードを含むか否かに関わらず、前記コマン
ド実行手段(121)が前記コマンドを受信することを
許可する手段(121)を備えるものであってもよい。
これにより、記憶装置に格納されているデータは、認証
を要せずに読み出すことが可能な状態とされる。このた
め、記憶装置に格納されているデータは、復号化等を逐
一受けることなく、他の者に譲渡される。
When the password includes predetermined data, the permitting means (121) sets the access device (2)
Irrespective of whether or not the input data obtained by the command execution means includes the enable command and the password, comprises means (121) for permitting the command execution means (121) to receive the command. Is also good.
Thus, the data stored in the storage device can be read out without requiring authentication. For this reason, the data stored in the storage device is transferred to another person without being subjected to decryption or the like.

【0015】前記許可手段(121)は、前記アクセス
装置(2)が取得した前記入力データが所定の保守用コ
マンドを実質的に含むか否かを判別し、含むと判別した
とき、前記コマンド実行手段(121)が前記アクセス
装置(2)より前記コマンドを受信することを許可する
手段(121)を備えるものであってもよい。これによ
り、ユーザが認証用データを忘れた等の事態が起きて
も、記憶装置のデータの取得が可能になる。そして、保
守用コマンドは、前記アクセス制御装置の製造者等、限
られた者のみが知るようにすれば、記憶装置に格納され
たデータの秘匿性が実質的に低下することはない。
The permitting means (121) determines whether or not the input data obtained by the access device (2) substantially includes a predetermined maintenance command. The means (121) may include means (121) for permitting reception of the command from the access device (2). Thus, even if a situation such as the user forgetting the authentication data occurs, the data in the storage device can be obtained. If only a limited person such as the manufacturer of the access control device knows the maintenance command, the confidentiality of the data stored in the storage device does not substantially decrease.

【0016】また、本発明の第2の観点にかかる認証シ
ステム(1、2)は、記憶手段(11)と、アクセス手
段(2)と、許可手段(121)と、コマンド実行手段
(121)と、を備え、前記記憶手段(11)は、アク
セスに応答してデータの格納及び供給を行い、認証用デ
ータを書き換え可能に記憶する記憶領域を有しており、
前記アクセス手段(2)は、操作者の指示に従って入力
データを取得する入力手段と、前記記憶手段(11)に
アクセスするためのコマンドを出力して、前記コマンド
に応答して供給された読み出しデータを取得するコマン
ド供給手段と、を備え、前記許可手段(121)は、前
記アクセス手段(2)が取得した前記入力データが所定
の認証用データと実質的に一致するか否かを判別して、
一致すると判別したとき、前記コマンド実行手段(12
1)が前記アクセス手段(2)より前記コマンドを受信
することを許可し、前記コマンド実行手段(121)
は、前記許可手段が許可しているとき前記アクセス手段
(2)が出力した前記コマンドを受信して、受信した前
記コマンドが所定のアクセスコマンドを表すとき、受信
した前記コマンドに応答して前記記憶手段(11)にア
クセスし、当該アクセスによって前記記憶手段(11)
より取得した前記読み出しデータを前記アクセス手段
(2)に供給し、前記コマンド実行手段(121)は更
に、前記アクセス手段(2)より受信したコマンドが所
定の設定変更コマンドを表すとき、前記アクセス手段
(2)より新たな前記認証用データを取得して、取得し
た前記認証用データを、前記記憶手段(11)の前記記
憶領域に格納する更新手段(121)を備える、ことを
特徴とする。
An authentication system (1, 2) according to a second aspect of the present invention comprises a storage unit (11), an access unit (2), a permission unit (121), and a command execution unit (121). Wherein the storage means (11) stores and supplies data in response to access, and has a storage area for storing rewritable authentication data.
The access means (2) outputs an input means for acquiring input data in accordance with an instruction of an operator, and a command for accessing the storage means (11), and reads out read data supplied in response to the command. And a command supply unit for acquiring the authentication data. The permission unit (121) determines whether or not the input data acquired by the access unit (2) substantially matches predetermined authentication data. ,
If it is determined that they match, the command execution means (12
1) is permitted to receive the command from the access means (2), and the command execution means (121)
Receiving the command output by the access means (2) when the permission means permits, and when the received command represents a predetermined access command, responding to the received command, the storage means Means (11) for accessing said storage means (11).
The command execution means (121) further supplies the read data acquired from the access means (2) to the access means (2). When the command received from the access means (2) represents a predetermined setting change command, (2) An update unit (121) that acquires newer authentication data and stores the acquired authentication data in the storage area of the storage unit (11).

【0017】このような認証システムによれば、記憶手
段の記憶領域は、入力手段から正しい認証用データが供
給された場合にアクセスを受ける。このため、記憶手段
の記憶領域に格納されたデータが秘匿される。また、認
証用データの発給を行うソフトウェアは、暗号化や復号
化を行うソフトウェアに比べて処理の内容が簡便であっ
て、開発も容易であり、またメモリ等の記憶装置の快適
な使用を妨げない。
According to such an authentication system, the storage area of the storage means is accessed when correct authentication data is supplied from the input means. For this reason, the data stored in the storage area of the storage unit is kept secret. In addition, software that issues authentication data has simpler processing contents than software that performs encryption and decryption, is easier to develop, and hinders comfortable use of storage devices such as memories. Absent.

【0018】また、本発明の第3の観点にかかるコンピ
ュータ読み取り可能な記録媒体は、コンピュータ(1、
2)を、記憶手段(11)と、アクセス手段(2)と、
許可手段(121)と、コマンド実行手段(121)と
して機能させ、前記記憶手段(11)を、アクセスに応
答してデータの格納及び供給を行い、認証用データを書
き換え可能に記憶する記憶領域を有するものとして機能
させ、前記アクセス手段(2)を、操作者の指示に従っ
て入力データを取得する入力手段と、前記記憶手段(1
1)にアクセスするためのコマンドを出力して、前記コ
マンドに応答して供給された読み出しデータを取得する
コマンド供給手段として機能させ、前記許可手段(12
1)を、前記アクセス手段(2)が取得した前記入力デ
ータが所定の認証用データと実質的に一致するか否かを
判別して、一致すると判別したとき、前記コマンド実行
手段(121)が前記アクセス手段(2)より前記コマ
ンドを受信することを許可する手段として機能させ、前
記コマンド実行手段(121)を、前記許可手段が許可
しているとき前記アクセス手段(2)が出力した前記コ
マンドを受信して、受信した前記コマンドが所定のアク
セスコマンドを表すとき、受信した前記コマンドに応答
して前記記憶手段(11)にアクセスし、当該アクセス
によって前記記憶手段(11)より取得した前記読み出
しデータを前記アクセス手段(2)に供給する手段とし
て機能させ、前記コマンド実行手段(121)を更に、
前記アクセス手段(2)より受信したコマンドが所定の
設定変更コマンドを表すとき、前記アクセス手段(2)
より新たな前記認証用データを取得して、取得した前記
認証用データを、前記記憶手段(11)の前記記憶領域
に格納する更新手段(121)として機能させる、ため
のプログラムを記憶したことを特徴とする。
A computer-readable recording medium according to a third aspect of the present invention includes a computer (1,
2) as storage means (11), access means (2),
A storage area that functions as a permission unit (121) and a command execution unit (121), stores and supplies data in response to an access, and stores the authentication data in a rewritable manner. The access means (2) to obtain input data in accordance with an instruction of an operator; and the storage means (1).
1) to output a command to access the data, and to function as command supply means for acquiring read data supplied in response to the command;
It is determined whether or not the input data acquired by the access means (2) substantially matches predetermined authentication data. The command output means (121) outputs the command output by the access means (2) when the permission means permits the command execution means (121) to function as a means for permitting reception of the command from the access means (2). When the received command represents a predetermined access command, the storage unit (11) is accessed in response to the received command, and the read obtained from the storage unit (11) by the access is performed. Functioning as a means for supplying data to the access means (2); and further comprising the command execution means (121).
When the command received from the access means (2) represents a predetermined setting change command, the access means (2)
A program for acquiring newer authentication data and causing the acquired authentication data to function as an updating unit (121) for storing the acquired authentication data in the storage area of the storage unit (11). Features.

【0019】このような記録媒体に記憶されたプログラ
ムを実行するコンピュータによれば、記憶手段の記憶領
域は、入力手段から正しい認証用データが供給された場
合にアクセスを受ける。このため、記憶手段の記憶領域
に格納されたデータが秘匿される。また、認証用データ
の発給を行うソフトウェアは、暗号化や復号化を行うソ
フトウェアに比べて処理の内容が簡便であって、開発も
容易であり、またメモリ等の記憶装置の快適な使用を妨
げない。
According to the computer that executes the program stored in such a recording medium, the storage area of the storage unit is accessed when correct authentication data is supplied from the input unit. For this reason, the data stored in the storage area of the storage unit is kept secret. In addition, software that issues authentication data has simpler processing contents than software that performs encryption and decryption, is easier to develop, and hinders comfortable use of storage devices such as memories. Absent.

【0020】なお、括弧内に付した番号は、実施の形態
中の対応する構成の参照番号であり、参考のためのみに
使用されるべきものであり、この発明を限定するもので
はない。
The numbers in parentheses are the reference numbers of the corresponding components in the embodiment, and should be used for reference only, and do not limit the present invention.

【0021】[0021]

【発明の実施の形態】以下、この発明の実施の形態を、
メモリカード及びコンピュータからなる認証システムを
例とし、図面を参照して説明する。
DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, embodiments of the present invention will be described.
An authentication system including a memory card and a computer will be described as an example with reference to the drawings.

【0022】図1は、この発明の実施の形態にかかる認
証システムの物理的構成を示すブロック図である。図示
するように、この認証システムは、メモリカード1と、
コンピュータ2とから構成されている。メモリカード1
は、コンピュータ2が備えるスロットを介して、コンピ
ュータ2に着脱可能に装着されている。コンピュータ2
が備えるスロットは、例えば、PCMCIAバスを中継
するためのPCMCIAスロットからなる。
FIG. 1 is a block diagram showing a physical configuration of an authentication system according to an embodiment of the present invention. As shown, the authentication system includes a memory card 1 and
And a computer 2. Memory card 1
Is detachably mounted on the computer 2 via a slot provided in the computer 2. Computer 2
Comprises a PCMCIA slot for relaying a PCMCIA bus, for example.

【0023】メモリカード1は、フラッシュメモリ11
と、コントローラ12とからなる。
The memory card 1 has a flash memory 11
And the controller 12.

【0024】フラッシュメモリ11は、記憶装置あるい
は記憶手段を構成するものであり、フラッシュメモリ1
1は、EEPROM(Electrically Erasable/Programa
bleRead Only Memory)等からなる。フラッシュメモリ
11は、コントローラ12が行うアクセスに応答し、コ
ンピュータ2から供給されたデータの記憶と、記憶して
いるデータのコンピュータ2への供給と、記憶している
データの消去とを行う。
The flash memory 11 constitutes a storage device or storage means.
1 is an EEPROM (Electrically Erasable / Programmable
bleRead Only Memory). The flash memory 11 responds to an access made by the controller 12, stores the data supplied from the computer 2, supplies the stored data to the computer 2, and erases the stored data.

【0025】フラッシュメモリ11が有する記憶領域に
はアドレスが割り当てられており、先頭のアドレスより
512バイト分の記憶領域は、図2に示すように認証情
報記憶エリアを形成する。図2に示すように、認証情報
記憶エリアのうち、先頭の510バイトの記憶領域は、
後述するパスワードを記憶するためのパスワードエリア
を形成し、残る2バイトの記憶領域は、後述するイネー
ブルコマンドを示すコードを記憶するためのコマンドコ
ードエリアを形成する。また、フラッシュメモリ11
は、自らの記憶領域のデータ構造を示すデータからなる
FAT(File Allocation Table)を記憶している。
An address is assigned to a storage area of the flash memory 11, and a storage area of 512 bytes from the first address forms an authentication information storage area as shown in FIG. As shown in FIG. 2, the first 510-byte storage area in the authentication information storage area is:
A password area for storing a password described later is formed, and the remaining two-byte storage area forms a command code area for storing a code indicating an enable command described later. Also, the flash memory 11
Stores a FAT (File Allocation Table) composed of data indicating the data structure of its own storage area.

【0026】コントローラ12は、アクセス制御装置を
構成するものであり、図3に示すように、CPU(Cent
ral Processing Unit)121と、CPU121が実行
する動作プログラムを格納するROM(Read Only Memo
ry)122とを備えている。CPU121は、ROM1
22及びフラッシュメモリ11に接続され、コンピュー
タ2が備えるPCMCIAスロットを介してコンピュー
タ2に着脱可能に接続されている。また、CPU121
はステータスレジスタを備える。
The controller 12 constitutes an access control device, and as shown in FIG.
ral processing unit (121) and a ROM (Read Only Memory) for storing an operation program executed by the CPU 121.
ry) 122. The CPU 121 has a ROM 1
22 and the flash memory 11, and is detachably connected to the computer 2 via a PCMCIA slot provided in the computer 2. Also, the CPU 121
Has a status register.

【0027】CPU121は、ROM122に格納され
ている上述の動作プログラムを実行することにより、後
述するコマンド実行手段、許可手段及び更新手段の機能
を行うものである。
The CPU 121 executes the above-described operation program stored in the ROM 122 to perform the functions of a command execution unit, a permission unit, and an update unit, which will be described later.

【0028】CPU121は、アクセス装置を構成する
コンピュータ2から供給されるコマンドデータを取得
し、そのコマンドデータが所定の命令を表すものである
場合、その命令に従った動作を行う。CPU121が従
う命令には、イネーブルコマンド、製造者識別コマン
ド、セットパスワードコマンド及びアクセスコマンドの
4種が含まれる。
The CPU 121 acquires command data supplied from the computer 2 constituting the access device, and if the command data represents a predetermined command, performs an operation according to the command. The instructions to be followed by the CPU 121 include four types of enable command, manufacturer identification command, set password command, and access command.

【0029】イネーブルコマンドは、フラッシュメモリ
11へのアクセスの許可をコンピュータ2に与えること
を指示する命令である。イネーブルコマンドを示すコー
ドは、上述の通り、フラッシュメモリ11のコマンドコ
ードエリアに格納されている。
The enable command is a command for instructing the computer 2 to grant access to the flash memory 11. The code indicating the enable command is stored in the command code area of the flash memory 11 as described above.

【0030】CPU121は、コンピュータ2よりイネ
ーブルコマンドを供給されると、後述する処理に従っ
て、コンピュータ2から供給される後述のアクセスコマ
ンドを受け付けるか否かを決定し、決定結果に従って、
アクセスコマンドの受け付け及び拒絶を行う。
Upon receiving the enable command from the computer 2, the CPU 121 determines whether or not to receive an access command, which will be described later, supplied from the computer 2 according to a process described later.
Accepts and rejects access commands.

【0031】すなわち、CPU121は、コンピュータ
2から供給されたコマンドデータがイネーブルコマンド
であるとき、コンピュータ2が供給するアクセスコマン
ドを受信することをCPU121自身に許可する。従っ
て、CPU121は、許可手段としての機能を行う。
That is, when the command data supplied from the computer 2 is an enable command, the CPU 121 permits the CPU 121 itself to receive the access command supplied from the computer 2. Therefore, the CPU 121 performs a function as a permission unit.

【0032】ただし、CPU121は、フラッシュメモ
リ11のパスワードエリアに格納されているデータの内
容が所定の条件に合致しているとき(例えば、パスワー
ドエリア内のすべてのビットが「1」である場合)、コ
ンピュータ2から供給されるアクセスコマンドを無条件
に受け付けることを決定する。
However, when the content of the data stored in the password area of the flash memory 11 meets a predetermined condition (for example, when all the bits in the password area are "1"), , The access command supplied from the computer 2 is unconditionally accepted.

【0033】また、CPU121は、コンピュータ2か
ら所定の製造者識別コマンドが供給されたときも、コン
ピュータ2から供給されるアクセスコマンドを無条件に
受け付けることを決定する。製造者識別コマンドは、ユ
ーザがイネーブルコマンドやパスワードを忘れた等の非
常の場合に、製造者等がフラッシュメモリ11に記憶さ
れているデータを読み出すための保守用のコマンドであ
って、製造者識別コマンドを示すコードは、CPU12
1の製造者等により予め指定されている。
Further, even when a predetermined manufacturer identification command is supplied from the computer 2, the CPU 121 determines that the access command supplied from the computer 2 is unconditionally accepted. The manufacturer identification command is a maintenance command for the manufacturer or the like to read data stored in the flash memory 11 in an emergency such as when the user forgets the enable command or the password. The code indicating the command is
1 is specified in advance by the manufacturer or the like.

【0034】なお、CPU121は、コンピュータ2か
ら供給されるアクセスコマンドを受け付けると決定した
場合、例えば自らが備える上述のステータスレジスタを
セットし、このステータスレジスタの状態をコンピュー
タ2に通知することにより、アクセスコマンドを受け付
ける旨を通知する。また、アクセスを拒絶すると決定し
た場合は、ステータスレジスタをリセットすることによ
り、拒絶する旨をコンピュータ2に通知する。
When the CPU 121 determines to accept the access command supplied from the computer 2, for example, it sets the above-mentioned status register provided by itself, and notifies the computer 2 of the status of this status register, thereby providing access to the computer 2. Notifies that command is accepted. If it is determined that access is rejected, the status register is reset to notify the computer 2 of the rejection.

【0035】セットパスワードコマンドは、イネーブル
コマンド及びパスワードの変更を指示する命令である。
セットパスワードコマンドを示すコードは、コントロー
ラ12の製造者等により予め指定されている。CPU1
21は、アクセスコマンドを受け付けている状態でコン
ピュータ2よりセットパスワードコマンドを供給される
と、後述する処理に従って、フラッシュメモリ11の認
証情報記憶エリアに格納されているイネーブルコマンド
のコード及びパスワードを更新する。すなわち、CPU
121は、更新手段の機能を行う。
The set password command is an enable command and a command for changing a password.
The code indicating the set password command is specified in advance by the manufacturer of the controller 12 or the like. CPU1
When the set password command is supplied from the computer 2 in a state where the access command is received, the code 21 and the password of the enable command stored in the authentication information storage area of the flash memory 11 are updated in accordance with the processing described later. . That is, CPU
Reference numeral 121 performs a function of an updating unit.

【0036】アクセスコマンドは、フラッシュメモリ1
1へのアクセスをCPU121に指示する命令である。
アクセスコマンドは、例えばATAコマンド等の既存の
コマンドセットに準拠して、製造者等により予め指定さ
れている。
The access command is transmitted to the flash memory 1
1 is an instruction for instructing the CPU 121 to access 1.
The access command is specified in advance by a manufacturer or the like based on an existing command set such as an ATA command.

【0037】CPU121は、アクセスコマンドを受け
付けている状態でコンピュータ2よりアクセスコマンド
を供給されると、供給されたアクセスコマンドが示す内
容に従って、フラッシュメモリ11へのアクセスを行
う。具体的には、CPU121は、コンピュータ2から
供給される、フラッシュメモリ11に書き込む対象のデ
ータをフラッシュメモリ11に格納したり、フラッシュ
メモリ11に格納されているデータを読み出してコンピ
ュータ2に供給したりする。すなわち、CPU121
は、コンピュータ2から供給されたアクセスコマンドに
従った動作を行うとき、コマンド実行手段の機能を行
う。
When the CPU 121 receives an access command from the computer 2 while receiving the access command, the CPU 121 accesses the flash memory 11 in accordance with the contents indicated by the supplied access command. Specifically, the CPU 121 stores data to be written to the flash memory 11 supplied from the computer 2 in the flash memory 11, reads data stored in the flash memory 11, and supplies the data to the computer 2. I do. That is, the CPU 121
Performs the function of a command execution unit when performing an operation according to the access command supplied from the computer 2.

【0038】また、CPU121は、コンピュータ2の
要求に応答して、自らが属するメモリカード1を識別す
る属性情報を、コンピュータ2に供給する。
In response to a request from the computer 2, the CPU 121 supplies the computer 2 with attribute information for identifying the memory card 1 to which the CPU 121 belongs.

【0039】コンピュータ2は、アクセス装置あるいは
アクセス手段を構成するものであり、入力手段と、コマ
ンド供給手段とを含むものである。コンピュータ2はパ
ーソナルコンピュータ等からなり、PCMCIAスロッ
トを備え、オペレーティングシステム(OS)、ドライ
バ及び認証プログラムを記憶する。
The computer 2 constitutes an access device or access means, and includes input means and command supply means. The computer 2 includes a personal computer or the like, has a PCMCIA slot, and stores an operating system (OS), a driver, and an authentication program.

【0040】コンピュータ2はOSを実行し、OSの処
理に従い、PCMCIAスロットにメモリカード1が装
着されたことを検知して、ドライバを起動する。一方で
コンピュータ2は、OSの制御の下にユーザの操作に従
って認証プログラムを起動し、認証プログラムの処理に
従い、後述の通りにして、コントローラ12に自らが供
給するアクセスコマンドを受け付けるよう要求する。
The computer 2 executes the OS, detects that the memory card 1 is inserted in the PCMCIA slot, and starts the driver according to the processing of the OS. On the other hand, the computer 2 starts the authentication program according to the user's operation under the control of the OS, and requests the controller 12 to accept the access command supplied by the controller 12 as described later according to the processing of the authentication program.

【0041】アクセスコマンドが受け付けられるように
なった状態において、コンピュータ2は、ドライバの処
理に従って、コントローラ12にアクセスコマンドやフ
ラッシュメモリ11に書き込む対象のデータを供給する
ことにより、CPU121に、フラッシュメモリ11へ
のアクセスを行わせる。そして、自らが供給したアクセ
スコマンドに従ってCPU121がフラッシュメモリ1
1から読み出して自らに供給したデータを、CPU12
1より取得する。
In the state where the access command is accepted, the computer 2 supplies the controller 12 with the access command and the data to be written to the flash memory 11 in accordance with the processing of the driver. Have access to. Then, according to the access command supplied by itself, the CPU 121
1 and supplies the data read to itself to the CPU 12
Obtain from 1.

【0042】(動作)次に、この認証システムの動作
を、図4〜図6を参照して説明する。図4(a)及び
(b)は、初期処理を示すフローチャートである。図5
(a)及び(b)は、認証処理を示すフローチャートで
ある。図6(a)及び(b)は、パスワードロックをか
ける処理を示すフローチャートである。
(Operation) Next, the operation of the authentication system will be described with reference to FIGS. FIGS. 4A and 4B are flowcharts showing the initial processing. FIG.
(A) and (b) are flowcharts showing an authentication process. FIGS. 6A and 6B are flowcharts showing a process for setting a password lock.

【0043】(初期処理)コンピュータ2に電源が投入
されると、コンピュータ2は、図4(a)に示す初期処
理を行い、一方、メモリカード1は、図4(b)に示す
初期処理を行う。
(Initial Processing) When the power of the computer 2 is turned on, the computer 2 performs the initial processing shown in FIG. 4A, while the memory card 1 executes the initial processing shown in FIG. Do.

【0044】すなわち、まずコンピュータ2に電源が投
入されると、コンピュータ2はOSの処理を実行し(ス
テップS001)、OSの処理に従い、メモリカード1
がPCMCIAスロットに装着されたか否かの検知を行
う。
That is, when the power of the computer 2 is first turned on, the computer 2 executes the processing of the OS (step S001), and according to the processing of the OS, the memory card 1
Is detected in the PCMCIA slot.

【0045】メモリカード1がPCMCIAスロットに
挿入されると、コンピュータ2は、ハードウェアの挿入
を検出し(ステップS002)、メモリカード1のコン
トローラ12にアクセスして、属性情報の供給を要求す
る。コントローラ12のCPU121は属性情報をコン
ピュータ2に供給し、コンピュータ2は属性情報を取得
する(ステップS003)。
When the memory card 1 is inserted into the PCMCIA slot, the computer 2 detects the insertion of the hardware (step S002), accesses the controller 12 of the memory card 1, and requests the supply of the attribute information. The CPU 121 of the controller 12 supplies the attribute information to the computer 2, and the computer 2 acquires the attribute information (Step S003).

【0046】次に、コンピュータ2は、取得した属性情
報が、メモリカード1を表すものであるか否かを判別す
る(ステップS004)。具体的には、例えば、取得し
た属性情報が、製造者によって所定の規格に合致するメ
モリカードに予め割り当てられている属性情報に合致す
るか否かをを判別する。
Next, the computer 2 determines whether or not the acquired attribute information indicates the memory card 1 (step S004). Specifically, for example, it is determined whether or not the acquired attribute information matches the attribute information assigned in advance by the manufacturer to a memory card that conforms to a predetermined standard.

【0047】コンピュータ2は、メモリカード1を表す
ものでないと判別すると、処理をステップS002に戻
す。ただし、属性情報が他の利用可能な装置を表すもの
であればその装置が装着されたことを認識し、その装置
を利用するために行うべき所定の処理を行うようにす
る。
If the computer 2 determines that it does not represent the memory card 1, the process returns to step S002. However, if the attribute information indicates another available device, it is recognized that the device is mounted, and a predetermined process to be performed to use the device is performed.

【0048】ステップS004で、属性情報がメモリカ
ード1を表すと判別すると、コンピュータ2は、ドライ
バを起動する(ステップS005)。
If it is determined in step S004 that the attribute information indicates the memory card 1, the computer 2 activates the driver (step S005).

【0049】一方、メモリカード1のコントローラ12
のCPU121は、メモリカード1がPCMCIAスロ
ットに装着されると、フラッシュメモリ1のパスワード
エリアの内容を読み込み、その内容が、アクセスコマン
ドを無条件に受け付けるための所定の条件に合致するか
否かを判別する(ステップS011)。
On the other hand, the controller 12 of the memory card 1
When the memory card 1 is inserted into the PCMCIA slot, the CPU 121 reads the contents of the password area of the flash memory 1 and determines whether or not the contents match a predetermined condition for unconditionally receiving an access command. It is determined (step S011).

【0050】合致すると判別されると、CPU121は
コンピュータ2から供給されるアクセスコマンドを受け
付ける状態に移り(ステップS012)、メモリカード
1の側での初期処理を終了して、コンピュータ2からア
クセスコマンド等のデータが供給されるのを待機する。
合致しないと判別されると、コンピュータ2から供給さ
れるアクセスコマンドを拒絶する状態に移り(ステップ
S013)、メモリカード1の側での初期処理を終了す
る。
If it is determined that they match, the CPU 121 shifts to a state of receiving an access command supplied from the computer 2 (step S012), completes the initial processing on the memory card 1 side, Wait for data to be supplied.
If it is determined that they do not match, the state shifts to a state in which the access command supplied from the computer 2 is rejected (step S013), and the initial processing on the memory card 1 side ends.

【0051】ステップS012で、CPU121がアク
セスコマンドを受け付ける状態に移ると、コンピュータ
2は、CPU121に、FATの内容の読み出しを指示
するアクセスコマンドを供給する。CPU121は、供
給されたアクセスコマンドに応答してフラッシュメモリ
11に記憶されたFATの内容を読み出し、コンピュー
タ2に供給する。コンピュータ2は、CPU121から
供給されたFATの内容を取得し、フラッシュメモリ1
1の記憶領域のデータ構造を把握する(ステップS00
6)。
In step S012, when the CPU 121 shifts to a state of receiving an access command, the computer 2 supplies the CPU 121 with an access command instructing reading of the contents of the FAT. The CPU 121 reads the contents of the FAT stored in the flash memory 11 in response to the supplied access command, and supplies the read FAT to the computer 2. The computer 2 acquires the contents of the FAT supplied from the CPU 121, and
Grasp the data structure of the first storage area (step S00
6).

【0052】そして、コンピュータ2は、フラッシュメ
モリ11が、コンピュータ2から供給されるアクセスコ
マンドに従ってアクセスされる状態となったことを示す
アイコンを表示して(ステップS007)、コンピュー
タ2の側での初期処理を終了する。
Then, the computer 2 displays an icon indicating that the flash memory 11 has been accessed according to the access command supplied from the computer 2 (step S 007). The process ends.

【0053】該アイコンを表示して以降、コンピュータ
2は、ユーザの操作や、コンピュータ2が実行するアプ
リケーションプログラムの処理に従って、コントローラ
12にアクセスコマンド等を供給することにより、コン
トローラ12にフラッシュメモリ11へのアクセスを行
わせることが可能な状態となる。
After displaying the icon, the computer 2 supplies an access command or the like to the controller 12 in accordance with a user's operation or processing of an application program executed by the computer 2, so that the controller 12 sends the command to the flash memory 11. Can be accessed.

【0054】(認証処理)一方、コンピュータ2は、ド
ライバの起動後、ユーザの操作に従って、認証プログラ
ムを起動する。以下では、メモリカード1のコントロー
ラ12のCPU121がコンピュータ2から供給される
アクセスコマンドを拒絶している場合における認証プロ
グラムの処理(認証処理)と、コンピュータ2が認証プ
ログラムの処理を実行している間におけるメモリカード
1の動作とを、図5(a)及び(b)を参照して説明す
る。
(Authentication Processing) On the other hand, after the driver starts, the computer 2 starts the authentication program according to the operation of the user. Hereinafter, the processing of the authentication program (authentication processing) when the CPU 121 of the controller 12 of the memory card 1 rejects the access command supplied from the computer 2 and the processing while the computer 2 executes the processing of the authentication program Will be described with reference to FIGS. 5A and 5B.

【0055】コンピュータ2は、認証プログラムの処理
を開始すると、例えばイネーブルコマンド及びパスワー
ドを書き込むためのテキストボックスを表示するなどし
て、ユーザに、イネーブルコマンド及びパスワードの入
力を促す(ステップS101)。
When the processing of the authentication program is started, the computer 2 prompts the user to input an enable command and a password by, for example, displaying a text box for writing an enable command and a password (step S101).

【0056】イネーブルコマンド及びパスワードを表す
データが入力されると、コンピュータ2は、ドライバの
処理に従って、イネーブルコマンド及びパスワードとし
て入力されたデータをメモリカード1のコントローラ1
2に供給し(ステップS102)処理を終える。
When the data indicating the enable command and the password is input, the computer 2 sends the data input as the enable command and the password to the controller 1 of the memory card 1 according to the processing of the driver.
2 (step S102), and the process ends.

【0057】メモリカード1は、コンピュータ2よりデ
ータが供給されるのを待機する(ステップS201)。
そして、データが供給されると、メモリカード1のコン
トローラ12のCPU121は、そのデータのうちイネ
ーブルコマンドを表す部分が、フラッシュメモリ11の
コマンドコードエリアに記憶されているイネーブルコマ
ンドのコードに合致するか否かを判別する(ステップS
202)。そして、合致しないと判別した場合、供給さ
れたデータを無視して、処理をステップS201に戻
す。
The memory card 1 waits for data to be supplied from the computer 2 (step S201).
Then, when the data is supplied, the CPU 121 of the controller 12 of the memory card 1 checks whether the portion representing the enable command in the data matches the code of the enable command stored in the command code area of the flash memory 11. Is determined (step S
202). If it is determined that they do not match, the supplied data is ignored, and the process returns to step S201.

【0058】ステップS202で、供給されたデータが
イネーブルコマンドに合致すると判別した場合、CPU
121は、コンピュータ2より供給されたデータのうち
パスワードを表す部分が、フラッシュメモリ11のパス
ワードエリアに記憶されているパスワードに合致するか
否かを判別する(ステップS203)。
If it is determined in step S202 that the supplied data matches the enable command, the CPU
The control unit 121 determines whether or not the portion representing the password in the data supplied from the computer 2 matches the password stored in the password area of the flash memory 11 (step S203).

【0059】該データがパスワードに合致しないと判別
した場合、CPU121は、該データを無視して、処理
をステップS201に戻す。この結果、CPU121
は、コンピュータ2から供給されるアクセスコマンドを
拒絶したままとなる。
If it is determined that the data does not match the password, the CPU 121 ignores the data and returns the process to step S201. As a result, the CPU 121
Refuse the access command supplied from the computer 2.

【0060】一方、合致すると判別した場合、CPU1
21は、コンピュータ2から供給されるアクセスコマン
ドを受け付ける状態に移り(ステップS204)、認証
処理を終了し、コンピュータ2からアクセスコマンド等
のデータが供給されるのを待機する。
On the other hand, if it is determined that they match, the CPU 1
The control unit 21 shifts to a state of receiving an access command supplied from the computer 2 (step S204), ends the authentication process, and waits for data such as an access command to be supplied from the computer 2.

【0061】コンピュータ2は、CPU121がステッ
プS204でアクセスコマンドを受け付ける状態に移る
と、ステップS006及びS007と実質的に同一の処
理を行う。すなわち、FATの内容を取得してフラッシ
ュメモリ11の記憶領域のデータ構造を把握し、フラッ
シュメモリ11が、コンピュータ2から供給されるアク
セスコマンドに従ってアクセスされる状態となったこと
を示すアイコンを表示する。以上のようにして、コンピ
ュータ2は、CPU121にフラッシュメモリ11への
アクセスを行わせることが可能な状態となる。
When the CPU 121 shifts to the state of receiving the access command in step S204, the computer 2 performs substantially the same processing as in steps S006 and S007. In other words, the contents of the FAT are acquired, the data structure of the storage area of the flash memory 11 is grasped, and an icon indicating that the flash memory 11 has been accessed according to the access command supplied from the computer 2 is displayed. . As described above, the computer 2 is in a state where the CPU 121 can access the flash memory 11.

【0062】(イネーブルコマンド及びパスワードを変
更する処理)コンピュータ2は、コントローラ12のC
PU121がアクセスコマンドを受け付けている状態
で、例えば認証プログラムの処理に従って、コントロー
ラ12にセットパスワードコマンドを供給することによ
り、イネーブルコマンド及びパスワードの変更を指示す
る。コントローラ12のCPU121は、指示に従って
イネーブルコマンド及びパスワードを変更する。
(Process for Changing Enable Command and Password) The computer 2
While the PU 121 is receiving the access command, the PU 121 supplies a set password command to the controller 12 in accordance with, for example, the processing of an authentication program, thereby instructing an enable command and a password change. The CPU 121 of the controller 12 changes the enable command and the password according to the instruction.

【0063】具体的には、認証プログラム等の処理を実
行するコンピュータ2は、例えば、新たなイネーブルコ
マンド及びパスワードを書き込むためのテキストボック
スを表示するなどして、新たなイネーブルコマンド及び
新たなパスワードの入力をユーザに促す。ユーザが新た
なイネーブルコマンド及び新たなパスワードを入力する
と、コンピュータ2は、コントローラ12に、セットパ
スワードコマンドと、新たなイネーブルコマンド及び新
たなパスワードとを供給する。
More specifically, the computer 2 executing the processing such as the authentication program displays a new enable command and a new password by displaying a text box for writing a new enable command and a new password. Prompt the user for input. When the user inputs a new enable command and a new password, the computer 2 supplies the controller 12 with a set password command and a new enable command and a new password.

【0064】コントローラ12のCPU121は、セッ
トパスワードコマンド、新たなイネーブルコマンド及び
新たなパスワードを供給されると、新たなイネーブルコ
マンドをフラッシュメモリ11のコマンドコードエリア
に書き込み、新たなパスワードを、フラッシュメモリ1
1のパスワードエリアに書き込む。以上説明した処理に
より、イネーブルコマンド及びパスワードが更新され
る。
When supplied with the set password command, the new enable command and the new password, the CPU 121 of the controller 12 writes the new enable command into the command code area of the flash memory 11 and writes the new password into the flash memory 1.
Write in the password area of No. 1. Through the processing described above, the enable command and the password are updated.

【0065】なお、以上説明した処理によって、パスワ
ードを、コンピュータ2から供給されるアクセスコマン
ドが無条件に受け付けられる条件に合致するよう更新す
れば、フラッシュメモリ11に格納されたデータは、ユ
ーザの認証を要せずに読み出されることが可能な状態に
なる。従って、メモリカード1を、イネーブルコマンド
を知らない他の者に引き渡しても、その者はフラッシュ
メモリ11に格納されているデータを、コンピュータ2
のみならず他のコンピュータ等を用いて読み出すことが
できる。
If the password is updated by the processing described above so that the access command supplied from the computer 2 is unconditionally accepted, the data stored in the flash memory 11 can be used to authenticate the user. Can be read out without the need for. Therefore, even if the memory card 1 is handed over to another person who does not know the enable command, the person can transfer the data stored in the flash memory 11 to the computer 2.
In addition, the information can be read using another computer or the like.

【0066】(パスワードロックをかける処理)コンピ
ュータ2は、コントローラ12のCPU121がアクセ
スコマンドを受け付けている場合であっても、認証プロ
グラムの処理に従い、CPU121にイネーブルコマン
ド及びパスワードを供給することができる。この場合、
ユーザは、コンピュータ2を操作して、正しいイネーブ
ルコマンド及び誤ったパスワードを意図的に入力するこ
とにより、CPU121を、コンピュータ2から供給さ
れるアクセスコマンドを拒絶した状態にさせることがで
きる。従って、CPU121を、再びアクセスコマンド
を受け付ける状態にさせるためには、正しいイネーブル
コマンド及びパスワードの入力が必要となる(すなわ
ち、パスワードロックがかかる)。これにより、ユーザ
が一時的にコンピュータ2の設置場所を離れた場合など
に、フラッシュメモリ11に格納されたデータが他の者
に取得される事態が防止され、データの守秘が行われ
る。以下では、フラッシュメモリ11にパスワードロッ
クをかけるためのパスワードロック処理を、図6(a)
及び(b)を参照して説明する。
(Password Locking Process) The computer 2 can supply the enable command and the password to the CPU 121 according to the process of the authentication program, even when the CPU 121 of the controller 12 receives the access command. in this case,
By operating the computer 2 and intentionally inputting a correct enable command and an incorrect password, the user can cause the CPU 121 to reject an access command supplied from the computer 2. Therefore, in order to make the CPU 121 accept the access command again, it is necessary to input a correct enable command and a correct password (that is, the password is locked). This prevents data stored in the flash memory 11 from being acquired by another person, for example, when the user temporarily leaves the place where the computer 2 is installed, and the data is kept confidential. In the following, a password lock process for locking the password on the flash memory 11 is described with reference to FIG.
This will be described with reference to FIGS.

【0067】まず、コンピュータ2は、上述のステップ
S101及びS102と実質的に同一の処理を行い、ユ
ーザが入力したイネーブルコマンド及びパスワードを含
むデータをメモリカード1のコントローラ12に供給す
る(ステップS301)。
First, the computer 2 performs substantially the same processing as the above-described steps S101 and S102, and supplies data including the enable command and the password input by the user to the controller 12 of the memory card 1 (step S301). .

【0068】コントローラ12のCPU121は、コン
ピュータ2よりデータが供給されると、ステップS20
2と実質的に同一の処理を行い、該データが示すイネー
ブルコマンドがフラッシュメモリ11に格納されている
ものに合致するか否かを判別する(ステップS40
1)。そして、合致しないと判別した場合、CPU12
1は、該データを無視して処理を終了し、コンピュータ
2から他のデータが供給されるのを待機する。
When the data is supplied from the computer 2, the CPU 121 of the controller 12 proceeds to step S20.
2 to determine whether the enable command indicated by the data matches the enable command stored in the flash memory 11 (step S40).
1). If it is determined that they do not match, the CPU 12
1 terminates the processing ignoring the data and waits for another data to be supplied from the computer 2.

【0069】合致すると判別した場合、メモリカード1
は、ステップS203と実質的に同一の処理を行い、コ
ンピュータ2より供給されたデータが示すパスワード
が、フラッシュメモリ11に格納されているものに合致
するか否かを判別する(ステップS402)。
If it is determined that they match, the memory card 1
Performs substantially the same processing as in step S203, and determines whether the password indicated by the data supplied from the computer 2 matches the password stored in the flash memory 11 (step S402).

【0070】そして、合致すると判別した場合は、コン
ピュータ2から供給されたデータを無視して処理を終了
し、コンピュータ2から他のデータが供給されるのを待
機する。一方、合致しないと判別した場合、CPU12
1は、フラッシュメモリ11に格納されているパスワー
ドが、コンピュータ2から供給されるアクセスコマンド
を無条件で受け付けるための条件に合致しているか否か
を判別する(ステップS403)
If it is determined that they match, the process is terminated ignoring the data supplied from the computer 2 and the process waits for another data to be supplied from the computer 2. On the other hand, if it is determined that they do not match, the CPU 12
1 determines whether the password stored in the flash memory 11 meets the condition for unconditionally receiving the access command supplied from the computer 2 (step S403).

【0071】条件に合致していると判別されると、CP
U121はコンピュータ2より供給されたデータを無視
して処理を終了し、コンピュータ2から他のデータが供
給されるのを待機する。
If it is determined that the condition is met, the CP
U121 ignores the data supplied from the computer 2 and ends the process, and waits for another data to be supplied from the computer 2.

【0072】条件に合致しないと判別した場合、CPU
121は、コンピュータ2から供給されるアクセスコマ
ンドを拒絶する状態に移り(ステップS404)、処理
を終了して、コンピュータ2から他のデータが供給され
るのを待機する。
If it is determined that the condition is not met, the CPU
The control unit 121 shifts to a state in which the access command supplied from the computer 2 is rejected (step S404), terminates the process, and waits for another data to be supplied from the computer 2.

【0073】以上説明した処理により、フラッシュメモ
リ11にパスワードロックがかかり、フラッシュメモリ
11に格納されたデータが他の者に取得される事態が防
止される。
By the processing described above, the password lock is applied to the flash memory 11 and the situation where the data stored in the flash memory 11 is obtained by another person is prevented.

【0074】なお、この認証システムの構成は上述のも
のである必要はない。例えば、フラッシュメモリ11は
EEPROMである必要はなく、CPU121やその他
任意の装置からのアクセスに応答してデータを書き換え
可能に記憶したり、記憶している内容を出力したりする
ものである限り、任意の記憶装置であってよい。また、
メモリカード1は、物理的に破壊された場合に、フラッ
シュメモリ11に格納されているデータが失われるよう
な、いわゆるタンパフリー構造を有するものであれば、
データの守秘はより確実に行われる。
The configuration of the authentication system need not be as described above. For example, the flash memory 11 does not need to be an EEPROM, and as long as it can store data in a rewritable manner or output stored contents in response to access from the CPU 121 or any other device. Any storage device may be used. Also,
If the memory card 1 has a so-called tamper-free structure in which data stored in the flash memory 11 is lost when physically destroyed,
Data confidentiality is ensured.

【0075】また、イネーブルコマンド及びパスワード
は、フラッシュメモリの記憶領域のうち、任意のアドレ
スにあたる位置に格納されていてよく、この場合、例え
ば、コントローラ12が、イネーブルコマンド及びパス
ワードが記憶されている位置のアドレスを記憶するよう
にすればよい。また、イネーブルコマンド及びパスワー
ドのデータ長は、いずれも任意である。
The enable command and the password may be stored at a position corresponding to an arbitrary address in the storage area of the flash memory. In this case, for example, the controller 12 determines whether the enable command and the password are stored at the position where the enable command and the password are stored. May be stored. In addition, the data lengths of the enable command and the password are both arbitrary.

【0076】また、フラッシュメモリ11が記憶するイ
ネーブルコマンド及びパスワードは一つずつである必要
はなく、例えば、イネーブルコマンド及びパスワードの
ペアを複数記憶していてもよい。この場合、上述の認証
処理においては、ユーザにより入力されたイネーブルコ
マンド及びパスワードに合致するイネーブルコマンド及
びパスワードが、上述のペアをなしてフラッシュメモリ
11に記憶されている場合に限り、コンピュータ2から
供給されるアクセスコマンドを受け付けることを決定す
るものとしてもよい。
The flash memory 11 need not store only one enable command and one password. For example, a plurality of enable command and password pairs may be stored. In this case, in the above-described authentication processing, only when the enable command and the password that match the enable command and the password input by the user are stored in the flash memory 11 in a pair as described above, the enable command and the password are supplied from the computer 2. May be determined to receive the access command to be performed.

【0077】また、コンピュータ2が備えるスロット
は、コンピュータ2に着脱可能に装着されるようにして
もよい。
The slots provided in the computer 2 may be detachably mounted on the computer 2.

【0078】以上、この発明の実施の形態を説明した
が、この発明の認証システムは、専用のシステムによら
ず、通常のコンピュータシステムを用いて実現可能であ
る。例えば、外部記憶装置を備えるコンピュータに上述
の動作を実行するためのプログラムを格納した媒体(フ
ロッピーディスク、CD−ROM等)から該プログラム
をインストールすることにより、上述の処理を実行する
認証システムを構成することができる。
Although the embodiment of the present invention has been described above, the authentication system of the present invention can be realized by using a general computer system without using a dedicated system. For example, an authentication system that executes the above-described processing is configured by installing the program for executing the above-described operation from a medium (a floppy disk, a CD-ROM, or the like) storing the program in a computer having an external storage device. can do.

【0079】また、コンピュータにプログラムを供給す
るための媒体は、通信媒体(通信回線、通信ネットワー
ク、通信システムのように、一時的且つ流動的にプログ
ラムを保持する媒体)でも良い。例えば、通信ネットワ
ークの掲示板(BBS)に該プログラムを掲示し、これ
をネットワークを介して配信してもよい。そして、この
プログラムを起動し、OSの制御下に、他のアプリケー
ションプログラムと同様に実行することにより、上述の
処理を実行することができる。
The medium for supplying the program to the computer may be a communication medium (a medium that temporarily and fluidly stores the program, such as a communication line, a communication network, or a communication system). For example, the program may be posted on a bulletin board (BBS) of a communication network and distributed via the network. Then, by starting this program and executing it in the same manner as other application programs under the control of the OS, the above-described processing can be executed.

【0080】なお、OSが処理の一部を分担する場合、
あるいは、OSが本願発明の1つの構成要素の一部を構
成するような場合には、記録媒体には、その部分をのぞ
いたプログラムを格納してもよい。この場合も、この発
明では、その記録媒体には、コンピュータが実行する各
機能又はステップを実行するためのプログラムが格納さ
れているものとする。
When the OS shares part of the processing,
Alternatively, when the OS constitutes a part of one component of the present invention, a program excluding the part may be stored in the recording medium. Also in this case, in the present invention, it is assumed that the recording medium stores a program for executing each function or step executed by the computer.

【0081】[0081]

【発明の効果】以上説明したように、この発明によれ
ば、記憶装置に格納されたデータを、その譲渡の容易さ
を確保しつつ秘匿する簡便な認証システムが実現され
る。
As described above, according to the present invention, a simple authentication system for concealing data stored in a storage device while ensuring the ease of transfer is realized.

【図面の簡単な説明】[Brief description of the drawings]

【図1】本発明の実施の形態にかかる認証システムの構
成を示すブロック図である。
FIG. 1 is a block diagram showing a configuration of an authentication system according to an embodiment of the present invention.

【図2】フラッシュメモリのデータ構造を模式的に示す
図である。
FIG. 2 is a diagram schematically showing a data structure of a flash memory.

【図3】コントローラの構成を示すブロック図である。FIG. 3 is a block diagram illustrating a configuration of a controller.

【図4】(a)は、コンピュータの側での初期処理を示
すフローチャートであり、(b)は、メモリカードの側
での初期処理を示すフローチャートである。
FIG. 4A is a flowchart illustrating an initial process on a computer side, and FIG. 4B is a flowchart illustrating an initial process on a memory card side.

【図5】(a)は、コンピュータの側での認証処理を示
すフローチャートであり、(b)は、メモリカードの側
での認証処理を示すフローチャートである。
FIG. 5A is a flowchart showing an authentication process on the computer side, and FIG. 5B is a flowchart showing an authentication process on the memory card side.

【図6】(a)は、コンピュータの側における、パスワ
ードロックをかける処理を示すフローチャートであり、
(b)は、メモリカードの側における、パスワードロッ
クをかける処理を示すフローチャートである。
FIG. 6A is a flowchart showing a process for locking a password on a computer side;
FIG. 4B is a flowchart illustrating a process for locking a password on the memory card side.

【符号の説明】[Explanation of symbols]

1 メモリカード 11 フラッシュメモリ 12 コントローラ 121 CPU 122 ROM 2 コンピュータ DESCRIPTION OF SYMBOLS 1 Memory card 11 Flash memory 12 Controller 121 CPU 122 ROM 2 Computer

Claims (9)

【特許請求の範囲】[Claims] 【請求項1】アクセスに応答してデータの格納及び供給
を行い、認証用データを書き換え可能に記憶する記憶領
域を有する記憶装置と、 操作者の指示に従って入力データを取得する手段と、前
記記憶装置にアクセスするためのコマンドを出力して、
前記コマンドに応答して供給された読み出しデータを取
得する手段と、を備えるアクセス装置と、に接続された
アクセス制御装置であって、 コマンド実行手段と、許可手段と、を備え、 前記許可手段は、前記アクセス装置が取得した前記入力
データが所定の認証用データと実質的に一致するか否か
を判別し、一致すると判別したとき、前記コマンド実行
手段が前記アクセス装置より前記コマンドを受信するこ
とを許可する手段を備え、 前記コマンド実行手段は、前記許可手段が許可している
とき前記アクセス装置が出力した前記コマンドを受信
し、受信した前記コマンドが所定のアクセスコマンドを
表すとき、受信した前記コマンドに応答して前記記憶装
置にアクセスし、当該アクセスによって前記記憶装置よ
り取得した前記読み出しデータを前記アクセス装置に供
給する手段を備え、 前記コマンド実行手段は、前記アクセス装置より受信し
たコマンドが所定の設定変更コマンドを表すとき、前記
アクセス装置より新たな前記認証用データを取得して、
取得した前記認証用データを、前記記憶装置の前記記憶
領域に格納する更新手段を備える、 ことを特徴とするアクセス制御装置。
1. A storage device having a storage area for storing and supplying data in response to an access and storing rewritable authentication data, means for acquiring input data in accordance with an instruction of an operator, and the storage Output a command to access the device,
An access device connected to an access device including: a unit that obtains read data supplied in response to the command; anda command execution unit; and a permission unit. Determining whether or not the input data acquired by the access device substantially matches predetermined authentication data; and when determining that the input data matches, the command execution means receives the command from the access device. The command execution means receives the command output by the access device when the permission means permits, and when the received command represents a predetermined access command, the received command execution means, Accessing the storage device in response to a command, and reading the read data acquired from the storage device by the access. The comprises means for supplying to said access device, said command executing means, when the command received from the access device representing a predetermined setting change command, to obtain a new said authentication data from said access device,
An access control device, comprising: updating means for storing the acquired authentication data in the storage area of the storage device.
【請求項2】前記アクセス装置は、前記記憶装置に格納
するための書き込みデータを出力する手段を備えるもの
であって、 前記許可手段は、前記アクセス装置が取得した前記入力
データが前記認証用データと実質的に一致するか否かを
判別し、一致すると判別したとき、前記コマンド実行手
段が前記書き込みデータを受信することを許可する手段
を備え、 前記コマンド実行手段は、前記許可手段が許可している
とき前記書き込みデータを受信する手段と、受信した前
記コマンドが前記書き込みデータの書き込みを指示する
前記アクセスコマンドを表すとき、受信した前記コマン
ドに応答して前記記憶装置の前記記憶領域に前記書き込
みデータを書き込む手段と、を備える、 ことを特徴とする請求項1に記載のアクセス制御装置。
2. The access device includes means for outputting write data to be stored in the storage device, wherein the permission means is configured to determine that the input data acquired by the access device is the authentication data. Determining whether or not the command execution means substantially matches, and when determining that the command execution means, the command execution means includes means for permitting the reception of the write data. Means for receiving the write data, and when the received command indicates the access command instructing the writing of the write data, the writing to the storage area of the storage device in response to the received command. The access control device according to claim 1, further comprising: means for writing data.
【請求項3】前記認証用データは、イネーブルコマンド
及びパスワードからなり、 前記許可手段は、 前記コマンド実行手段が前記アクセス装置より前記コマ
ンドを受信することを許可していないとき、前記アクセ
ス装置が取得した前記入力データが前記イネーブルコマ
ンド及び前記パスワードを実質的に含むか否かを判別
し、両者を含むと判別したとき、前記コマンド実行手段
が前記コマンドを受信することを許可する手段を備え
る、 ことを特徴とする請求項1又は2に記載のアクセス制御
装置。
3. The data for authentication comprises an enable command and a password, and the permission means acquires the command when the access device does not permit the command execution device to receive the command from the access device. Determining whether or not the input data substantially includes the enable command and the password, and determining that the input data includes both the enable command and the password, and permitting the command execution means to receive the command. The access control device according to claim 1 or 2, wherein:
【請求項4】前記許可手段は、前記コマンド実行手段が
前記アクセス装置より前記コマンドを受信することを許
可しているとき、前記アクセス装置が取得した前記入力
データが前記イネーブルコマンド及び前記バスワードを
実質的に含むか否かを判別し、前記イネーブルコマンド
を含み、且つ前記パスワードを含まないと判別したと
き、前記コマンド実行手段が前記コマンドを受信するこ
とを禁止する手段と、を備える、 ことを特徴とする請求項3に記載のアクセス制御装置。
4. The input device according to claim 1, wherein the input data acquired by the access device includes the enable command and the password when the command execution device is permitted to receive the command from the access device. Means for substantially determining whether or not to include the enable command, and when determining that the password does not include the password, means for inhibiting the command execution means from receiving the command. The access control device according to claim 3, characterized in that:
【請求項5】前記イネーブルコマンド及び前記パスワー
ドは互いに対応付けられて対をなしており、 前記許可手段は、 前記コマンド実行手段が前記アクセス装置より前記コマ
ンドを受信することを許可していないとき、前記アクセ
ス装置が取得した前記入力データが前記イネーブルコマ
ンド及び前記バスワードの対を実質的に含んでいるか否
かを判別し、その対を含んでいると判別したとき、前記
コマンド実行手段が前記コマンドを受信することを許可
する手段と、 前記コマンド実行手段が前記アクセス装置より前記コマ
ンドを受信することを許可しているとき、前記アクセス
装置が取得した前記入力データが前記イネーブルコマン
ド及びそのイネーブルコマンドと対をなす前記バスワー
ドを実質的に含んでいるか否かを判別し、前記イネーブ
ルコマンドを含み、且つそのイネーブルコマンドと対を
なす前記パスワードを含まないと判別したとき、前記コ
マンド実行手段が前記コマンドを受信することを禁止す
る手段と、を備える、 ことを特徴とする請求項3又は4に記載のアクセス制御
装置。
5. The method according to claim 1, wherein the enable command and the password are associated with each other and form a pair. When the permission unit does not permit the command execution unit to receive the command from the access device, It is determined whether or not the input data obtained by the access device substantially includes the pair of the enable command and the password, and when it is determined that the pair includes the pair, the command execution means sets the command to Means for allowing the access device to receive the command from the access device, the input data acquired by the access device is the enable command and its enable command. Determining whether or not the pair substantially includes the password; Means for prohibiting the command execution means from receiving the command when it is determined that the command execution means does not include the password paired with the enable command. 5. The access control device according to 3 or 4.
【請求項6】前記許可手段は、前記パスワードが所定の
データを含むとき、前記アクセス装置が取得した前記入
力データが前記イネーブルコマンド及び前記バスワード
を含むか否かに関わらず、前記コマンド実行手段が前記
コマンドを受信することを許可する手段を備える、 ことを特徴とする請求項3、4又は5に記載のアクセス
制御装置。
6. The command execution means when the password includes predetermined data, irrespective of whether or not the input data obtained by the access device includes the enable command and the password. The access control device according to claim 3, further comprising: a unit that permits receiving the command.
【請求項7】前記許可手段は、前記アクセス装置が取得
した前記入力データが所定の保守用コマンドを実質的に
含むか否かを判別し、含むと判別したとき、前記コマン
ド実行手段が前記アクセス装置より前記コマンドを受信
することを許可する手段を備える、 ことを特徴とする請求項1乃至6のいずれか1項に記載
のアクセス制御装置。
7. The permission means determines whether or not the input data acquired by the access device substantially includes a predetermined maintenance command. The access control device according to any one of claims 1 to 6, further comprising: means for permitting reception of the command from the device.
【請求項8】記憶手段と、アクセス手段と、許可手段
と、コマンド実行手段と、を備え、 前記記憶手段は、アクセスに応答してデータの格納及び
供給を行い、認証用データを書き換え可能に記憶する記
憶領域を有しており、 前記アクセス手段は、操作者の指示に従って入力データ
を取得する入力手段と、前記記憶手段にアクセスするた
めのコマンドを出力して、前記コマンドに応答して供給
された読み出しデータを取得するコマンド供給手段と、
を備え、 前記許可手段は、前記アクセス手段が取得した前記入力
データが所定の認証用データと実質的に一致するか否か
を判別して、一致すると判別したとき、前記コマンド実
行手段が前記アクセス手段より前記コマンドを受信する
ことを許可し、 前記コマンド実行手段は、前記許可手段が許可している
とき前記アクセス手段が出力した前記コマンドを受信し
て、受信した前記コマンドが所定のアクセスコマンドを
表すとき、受信した前記コマンドに応答して前記記憶手
段にアクセスし、当該アクセスによって前記記憶手段よ
り取得した前記読み出しデータを前記アクセス手段に供
給し、 前記コマンド実行手段は更に、前記アクセス手段より受
信したコマンドが所定の設定変更コマンドを表すとき、
前記アクセス手段より新たな前記認証用データを取得し
て、取得した前記認証用データを、前記記憶手段の前記
記憶領域に格納する更新手段を備える、 ことを特徴とする認証システム。
8. A storage unit, an access unit, a permission unit, and a command execution unit, wherein the storage unit stores and supplies data in response to an access, and rewrites authentication data. A storage area for storing, wherein the access means outputs input commands for obtaining input data according to an instruction of an operator, and a command for accessing the storage means, and supplies the command in response to the command Command supply means for obtaining the read data obtained,
The permission means determines whether or not the input data obtained by the access means substantially matches predetermined authentication data. Means for receiving the command from the means, the command execution means receives the command output by the access means when the permission means permits, the received command is a predetermined access command When representing, the storage means is accessed in response to the received command, and the read data acquired from the storage means by the access is supplied to the access means, and the command execution means further receives from the access means. When the given command represents a predetermined setting change command,
An authentication system, comprising: updating means for acquiring new authentication data from the access means and storing the acquired authentication data in the storage area of the storage means.
【請求項9】コンピュータを、 記憶手段と、アクセス手段と、許可手段と、コマンド実
行手段として機能させ、 前記記憶手段を、アクセスに応答してデータの格納及び
供給を行い、認証用データを書き換え可能に記憶する記
憶領域を有するものとして機能させ、 前記アクセス手段を、操作者の指示に従って入力データ
を取得する入力手段と、前記記憶手段にアクセスするた
めのコマンドを出力して、前記コマンドに応答して供給
された読み出しデータを取得するコマンド供給手段とし
て機能させ、 前記許可手段を、前記アクセス手段が取得した前記入力
データが所定の認証用データと実質的に一致するか否か
を判別して、一致すると判別したとき、前記コマンド実
行手段が前記アクセス手段より前記コマンドを受信する
ことを許可する手段として機能させ、 前記コマンド実行手段を、前記許可手段が許可している
とき前記アクセス手段が出力した前記コマンドを受信し
て、受信した前記コマンドが所定のアクセスコマンドを
表すとき、受信した前記コマンドに応答して前記記憶手
段にアクセスし、当該アクセスによって前記記憶手段よ
り取得した前記読み出しデータを前記アクセス手段に供
給する手段として機能させ、 前記コマンド実行手段を更に、前記アクセス手段より受
信したコマンドが所定の設定変更コマンドを表すとき、
前記アクセス手段より新たな前記認証用データを取得し
て、取得した前記認証用データを、前記記憶手段の前記
記憶領域に格納する更新手段として機能させる、 ためのプログラムを記憶したコンピュータ読み取り可能
な記録媒体。
9. A computer functioning as a storage unit, an access unit, a permission unit, and a command execution unit, wherein the storage unit stores and supplies data in response to access, and rewrites authentication data. Functioning as having a storage area for storing the data, the input means for acquiring input data in accordance with an instruction of an operator, and a command for accessing the storage means, and responding to the command. Functioning as command supply means for acquiring the supplied read data, and determining whether the input data acquired by the access means substantially matches predetermined authentication data. Means for permitting the command execution means to receive the command from the access means when it is determined that they match. The command execution unit receives the command output by the access unit when the permission unit permits, and when the received command represents a predetermined access command, the command execution unit receives the command. In response, the storage unit is accessed, and the read data obtained from the storage unit by the access is made to function as a unit that supplies the access unit. The command execution unit further includes a command received from the access unit. When expressing the setting change command of
A computer-readable recording storing a program for acquiring new authentication data from the access unit and causing the acquired authentication data to function as an updating unit that stores the acquired authentication data in the storage area of the storage unit. Medium.
JP15018898A 1998-05-29 1998-05-29 Access control device Expired - Fee Related JP3825917B2 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
JP15018898A JP3825917B2 (en) 1998-05-29 1998-05-29 Access control device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
JP15018898A JP3825917B2 (en) 1998-05-29 1998-05-29 Access control device

Publications (2)

Publication Number Publication Date
JPH11345286A true JPH11345286A (en) 1999-12-14
JP3825917B2 JP3825917B2 (en) 2006-09-27

Family

ID=15491447

Family Applications (1)

Application Number Title Priority Date Filing Date
JP15018898A Expired - Fee Related JP3825917B2 (en) 1998-05-29 1998-05-29 Access control device

Country Status (1)

Country Link
JP (1) JP3825917B2 (en)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2003044730A1 (en) * 2001-11-19 2003-05-30 Hoarton, Lloyd, Douglas, Charles A security system
US6757832B1 (en) 2000-02-15 2004-06-29 Silverbrook Research Pty Ltd Unauthorized modification of values in flash memory
US6932459B2 (en) 1997-07-15 2005-08-23 Silverbrook Research Pty Ltd Ink jet printhead
JP2006073021A (en) * 2005-09-12 2006-03-16 Hitachi Ltd Biometric authentication system
WO2007052677A1 (en) * 2005-11-02 2007-05-10 Sharp Kabushiki Kaisha Image processing apparatus
US7457442B2 (en) 2000-05-31 2008-11-25 Hitachi, Ltd. Authentication system by fingerprint

Cited By (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7284834B2 (en) 1997-07-15 2007-10-23 Silverbrook Research Pty Ltd Closure member for an ink passage in an ink jet printhead
US6932459B2 (en) 1997-07-15 2005-08-23 Silverbrook Research Pty Ltd Ink jet printhead
US7032998B2 (en) 1997-07-15 2006-04-25 Silverbrook Research Pty Ltd Ink jet printhead chip that incorporates through-wafer ink ejection mechanisms
US7097285B2 (en) 1997-07-15 2006-08-29 Silverbrook Research Pty Ltd Printhead chip incorporating electro-magnetically operable ink ejection mechanisms
US7182435B2 (en) 1997-07-15 2007-02-27 Silverbrook Research Pty Ltd Printhead chip incorporating laterally displaceable ink flow control mechanisms
US7207657B2 (en) 1997-07-15 2007-04-24 Silverbrook Research Pty Ltd Ink jet printhead nozzle arrangement with actuated nozzle chamber closure
US7549728B2 (en) 1997-07-15 2009-06-23 Silverbrook Research Pty Ltd Micro-electromechanical ink ejection mechanism utilizing through-wafer ink ejection
US6757832B1 (en) 2000-02-15 2004-06-29 Silverbrook Research Pty Ltd Unauthorized modification of values in flash memory
US7093139B2 (en) 2000-02-15 2006-08-15 Silverbrook Research Pty Ltd Unauthorized modification of values stored in flash memory
US7457442B2 (en) 2000-05-31 2008-11-25 Hitachi, Ltd. Authentication system by fingerprint
WO2003044730A1 (en) * 2001-11-19 2003-05-30 Hoarton, Lloyd, Douglas, Charles A security system
JP2006073021A (en) * 2005-09-12 2006-03-16 Hitachi Ltd Biometric authentication system
JP2007129488A (en) * 2005-11-02 2007-05-24 Sharp Corp Image processing device
WO2007052677A1 (en) * 2005-11-02 2007-05-10 Sharp Kabushiki Kaisha Image processing apparatus

Also Published As

Publication number Publication date
JP3825917B2 (en) 2006-09-27

Similar Documents

Publication Publication Date Title
EP2164020B1 (en) Apparatus for controlling processor execution in a secure environment
JP4707069B2 (en) Apparatus and method for controlling use of a memory card
JP3638770B2 (en) Storage device with test function
US20080320317A1 (en) Electronic device and information processing method
EP2482220A1 (en) Multi-enclave token
JP2004021755A (en) Storage device
JP3931959B2 (en) Programmable controller or programmable display and user authentication method thereof
CN101187903A (en) external storage device
JP3825917B2 (en) Access control device
JPWO2008068908A1 (en) Information processing apparatus and information management program
US20060214006A1 (en) Tamper resistant device and file generation method
JP2008022525A (en) COMMUNICATION SYSTEM, TERMINAL DEVICE, AND ITS CONTROL METHOD
JP5154646B2 (en) System and method for unauthorized use prevention control
JPH11265318A (en) Mutual certification system, its method and recording medium
JP7020969B2 (en) Portable electronic devices and IC cards
JPH10334197A (en) Simple password input device
US20090187898A1 (en) Method for securely updating an autorun program and portable electronic entity executing it
JP2008148851A (en) Game machine control chip and its ROM writer
JP7073733B2 (en) Control device, data writing method and program
JP4634924B2 (en) Authentication method, authentication program, authentication system, and memory card
JP2000259273A (en) Portable information terminal, user authenticating method and power feeding device
JP5454230B2 (en) Information processing system, program, and authentication transfer method
JP2000194604A (en) Storage device with unauthorized access prevention function, data processing device, and data processing system
JP3641382B2 (en) Security system and security method
JPH11272563A (en) Information processing apparatus security system and information processing apparatus security method

Legal Events

Date Code Title Description
A02 Decision of refusal

Free format text: JAPANESE INTERMEDIATE CODE: A02

Effective date: 20040511

A521 Written amendment

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20040705

A911 Transfer of reconsideration by examiner before appeal (zenchi)

Free format text: JAPANESE INTERMEDIATE CODE: A911

Effective date: 20040708

A912 Removal of reconsideration by examiner before appeal (zenchi)

Free format text: JAPANESE INTERMEDIATE CODE: A912

Effective date: 20040730

A521 Written amendment

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20060403

A521 Written amendment

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20060518

A61 First payment of annual fees (during grant procedure)

Free format text: JAPANESE INTERMEDIATE CODE: A61

Effective date: 20060703

R150 Certificate of patent or registration of utility model

Free format text: JAPANESE INTERMEDIATE CODE: R150

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20090707

Year of fee payment: 3

S531 Written request for registration of change of domicile

Free format text: JAPANESE INTERMEDIATE CODE: R313531

FPAY Renewal fee payment (event date is renewal date of database)

Free format text: PAYMENT UNTIL: 20090707

Year of fee payment: 3

R350 Written notification of registration of transfer

Free format text: JAPANESE INTERMEDIATE CODE: R350

LAPS Cancellation because of no payment of annual fees