CA2400440C

Field programmable smart card terminal and token device

Abstract

The invention defines a digital programmable smart card terminal device (100) and token collectively known as the token device (100). The token device comprises a field programmable token device which accepts a users' smart card (105). The combination of token device and smart card may then be used for a variety of applications (138) that include user authentication, secure access, and encryption. The token device can be used both in connected and unconnected modes. In one embodiment, the invention comprises a field programmable electronic smart card terminal for allowing secure communication between a user and a host service, service provider, or application, comprising a token personality logic; and a smart card reader adapted to receive and communicate with a smart card having stored thereon a user identification data.

CA2400440C, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Expired 20 February 2021, 5.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

23 claims: 16 independent, 7 dependent

  1. 1
    CA 02400440 2015-10-13 What is claimed is:1. A portable handheld smart card terminal device for use with a smart card, the portable handheld smart card terminal device comprising: a memory;a smart card reading component adapted to receive and communicate with the smart card having the dimensions of a standard credit card, the smart card including a smart card secret and a cryptographic engine;a data processing component adapted to: obtain a secret device key from the smart card when received by said smart card reading component by submitting to the smart card an input value for processing by the cryptographic engine using the smart card secret to derive the secret device key, store the secret device key in said memory, and calculate a signature using the stored secret device key as a secret cryptographic signature key for parameterizing a cryptographic signature algorithm, the signature to be used by the user to secure communication between the user and a service or application;and a display for displaying data to the user.
  2. 3
    The device of any one of claims 1 and 2 further adapted to support DES (Data Encryption Standard) based calculations.
  3. 4
    The device of any one of claims 1 to 3 further adapted so that the secret device key is erased if the smart card is removed.
  4. 5
    The device of any one of claims 1 to 4 further comprising a keypad adapted for the user’s entering data.
  5. 6
    The device of any one of claims 1 to 5 further adapted to allow the user to enter a PIN. CA 02400440 2015-10-13
  6. 7
    The device of any one of claims 1 to 6 in which a PIN is associated with the smart card.
  7. 8
    The device of any one of claims 1 to 7 further adapted to receive via said keypad a PIN from the user to be handled by the smart card.
  8. 9
    The device of any one of claims 1 to 8 having a length that is less than 150% of the length of a standard credit card and a width that is less than 140% of the width of a standard credit card.
  9. 10
    The device of any one of claims 1 to 9 further comprising a USB (Universal Serial Bus) connector.
  10. 14
    The device of any one of claims 1 to 13 in which the inserted smart card is a personal smart card that has been issued by a financial institution.
  11. 15
    The device of any one of claims 1 to 14 in which the service or application comprises an internet banking service.
  12. 16
    The device of any one of claims 1 to 15 further adapted to support smart cards that are compliant with the EMV (Europay-Mastercard-VISA) standard.
  13. 17
    A portable handheld smart card terminal device for use with a smart card, the portable handheld smart card terminal device comprising:a memory;CA 02400440 2015-10-13 a smart card reading component adapted to receive and communicate with the smart card, the smart card including a smart card secret and a cryptographic engine and having the dimensions of a standard credit card;a data processing component adapted to: support cryptographic calculations, obtain a secret device key from the smart card when received by said smart card reading component by submitting to the smart card an input value for processing by the cryptographic engine using the smart card secret to derive the secret device key, the input value comprising a predefined value, store the secret device key in said memory, calculate a signature using the stored secret device key as a secret cryptographic signature key for parameterizing a cryptographic signature algorithm, the signature to be used by a user to secure communication between the user and a financial service or application, and erase the secret device key if the smart card is removed;a keypad adapted for the user’s entering data, the data entered on the keypad comprising a PIN;and a display for displaying the signature to the user;the device having a length that is less than 150% of the length of a standard credit card and a width that is less than 140% of the width of a standard credit card.
  14. 20
    The device of any one of claims 17,18 and 19 in which the service or application comprises an internet banking service and in which the smart card comprises a personal smart card issued by a financial institution to the user. CA 02400440 2015-10-13
  15. 21
    The device of any one of claims 17, 18, 19 and 20 further adapted to support smart cards that are compliant with the EMV (Europay-Mastercard-VISA) standard.
  16. 22
    The device of any one of claims 1 to 21 which furthermore does not comprise any personalized data prior to the user inserting a smart card.