Nova Patents
AU711237B2

Method and device for data communication

Abstract

A method and a system for use for safe data transfer between a terminal which is controlled by an IC card (1), and a central unit (3), such as a central computer in a bank. The IC card (1) comprises card-specific program information which is used to control the interaction of the card with the terminal (2) in connection with adopting a safe system mode, and card-specific secret information which is used to cryptographically protect data transfers between the terminal (2) and the central unit (3) in a safe system mode. The card specific secret information is stored in such a manner that no read-out of it can be made from the card. The card-specific program information is transferred from the card to the terminal for the purpose of said control.

AU711237B2, drawing sheet 1
Sheet 1 of 14

Term

Term ended

Expired 31 October 2016, 9.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

19 claims: 13 independent, 6 dependent

  1. 1
    THE CLAIMS DEFINING THE INVENTION ARE AS FOLLOWS:1. A method of transferring data between a user unit including a terminal and an IC card which is placed in communication with the terminal, and a central unit, 5 such as a central computer located at a producer of services, preferably a bank, secret information being used in the user unit and the central unit to protect data transferred between said units, wherein the user unit is made to operate in a safe system mode involving safe data transfer between the user unit and the central unit in the sense that unauthorised persons cannot gain knowledge of the 10 transferred data and/or that it is possible to verify whether transferred data have been distorted or been replaced during the transfer, wherein card-specific program information in the card is used to control the terminal as the latter interacts with the card in connection with the user unit being made to operate in a safe system mode, the card-specific program information being transferred to the 15 terminal to be utilised in connection with said control, and wherein safe data transfers are effected while making use of card-specific secret information in the IC card, the use of the card-specific secret information for cryptographic protection being effected by cryptographic processing in the card in such a manner that the card-specific secret information never leaves the card. 20
  2. 4
    A method as claimed in any one of claims 1-2,
  3. 5
    5 wherein the transfer of the card-specific program information is carried out on the basis of information contained in the terminal and/or the IC card before communication is established therebetween. 5. A method as claimed in any one of claims 1-4, 10 wherein a session key is created in the user unit for use in the transfer of data in a safe system mode, said session key being encrypted or decrypted in the IC card, and wherein said session key is transferred to the central unit in an encrypted or decrypted form. 15
  4. 6
    A method as claimed in any one of claims 1-4, wherein a session key is created in the user unit, said session key being transferred to the central processing unit in cleartext, whereupon said session key is encrypted or decrypted in the central processing unit and the IC 20 card, to be used in an encrypted or decrypted form in the transfer of data in a safe system mode.
  5. 8
    A method as claimed in any one of claims 5-7, wherein the session key in the user unit is erased as soon as connection between the card and the terminal is interrupted.
  6. 9
    A method as claimed in any one of claims 5-7, 30 wherein the session key in the user unit is erased as soon as a new connection is established between the terminal and an IC card.
  7. 10
    A method as claimed in any one of the preceding claims, wherein input of information via a keyboard asso35 dated with the terminal may be effected only in a safe system-operational mode. -1611. A system for transfer of data, including a user unit having an IC card and a terminal and a central unit, said card including card communication means for communication with the terminal, the terminal including terminal communication means for communication with the card, and a terminal communication unit for 5 communication with the central unit, said central unit including a central communication unit for communication with the terminal and the user unit and the central processing unit including secret information that is used to cryptographically protect data transfers between said units, wherein the IC card includes first card memory means for storage of card-specific program 10 information, and second card memory means for storage of card-specific secret information which is used to cryptographically protect data transferred between the user unit and the central unit in a safe system mode, said second card memory means being configured in such a manner that said secret information .····. cannot be read out from the card and wherein the terminal includes terminal read• ft • ft ·· j “.J 15 out means for reading the contents of said first card memory means and program • ft ·;···· executing means arranged, while utilising the read-out card-specific program :information, to control the interaction between the terminal and the IC card in • ft ft · ft ft • *··· order to establish the safe system mode. ft *·’ 12. A system as claimed in claim 11, wherein the user unit comprises key ft··· • β ft ·..· · 20 generating means arranged to generate a session key, and storage means for ft ft ft *:·*.’ storing such a session key, and wherein the IC card comprises processing means • ft ft ’ arranged to cryptographically protect the session key which said terminal communication unit is arranged to transfer to the central unit. • ft
  8. 14
    16. A system as claimed in any one of claims 12-15, wherein the user unit is arranged to erase the session key in the user unit as soon as connection between MJP C:\WINWORD\MARIE\GABNODEU75120C.DOC -17said card communication means and said terminal communication means is interrupted.
  9. 15
    17. A system as claimed in any one of claims 12-15, wherein said user unit is arranged to erase the session key in the user unit as soon as new connection is 5 established between said card communication means and said terminal communication means.
  10. 16
    18. A system as claimed in any one of claims 11-17, wherein the IC card comprises memory means for storage of card-identifying information or a cardidentifying code arranged to be transferred to the central unit, said central unit 10 being arranged, while being guided by said code or information, to instruct the user unit of the manner in which the contents of said first card memory means are to be read out.
  11. 17
    19. A system as claimed in any one of claims 11-18, wherein the user unit comprises a keyboard for input of data into the system, said keyboard being 15 arranged to be operative only when the system is in a safe system mode.
  12. 18
    20. A method of transferring data between a user unit and a central unit substantially as herein described with reference to the accompanying drawings.
  13. 19
    21. A system for transfer of data substantially as herein described with reference to the accompanying drawings.