摘要 |
An arithmetic unit and an arithmetic method that output no information necessary for decryption or encryption to the outside and can perform a self-protecting function when an illegal attack is made. A command monitoring part (44) monitors input command sequences. In a first sequence, a process key in a first stage is calculated from a hardware key (Khd) and is then written to a key storing part (47). In each of the following sequences, a process key in a next stage is calculated from a process key stored in the key storing part (47). When commands of predetermined contents are inputted in predetermined order, a content key is calculated and then written to the key storing part (47). Encrypted data is decrypted with the content key, and the result is outputted from data output means (63). When an illegal attack is made, initialization is performed by selecting fixed value data (Kf) as key data (Ksl) and selecting fixed value data (Df) as input data (Ein). |