Method and system for the distributed creation of a program for a programmable portable data carrier
Abstract
The invention relates to a method for the distributed creation of a program for a programmable portable data carrier (10), for example, a chip card. To this end, program source text (Q) is created on a user computer (20), compiled and linked to executable program code (C) on a spatially separate compiler server (30), and the executable program code (C) is loaded into the data carrier (10) once again via the user computer (20). A secure end-to-end link is established for conducting an exchange of data between the data carrier (10) and the compiler server (30). To this end, the data carrier (10) is provided, in a pre-completion step, with software tools for final processing, which permit a transport code (U, Cssl, UCSM) provided in a transition format to be converted into executable program code (C). The transport code (U, Cssl, UCSM) is secured by encoding mechanisms. The transmission of the executable program code (C), which is generated by the compiler server (30), ensues in the transition format (U, Cssl, UCSM).

Term
Term ended
Projected expiry passed 22 February 2021, 5.6 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
20 claims: 20 independent, 0 dependent
- 1A method for distributed creation of an executable program for a programmable portable data carrier, wherein the creation a program source code on a first in a user befindli chen computer, compiling and linking the source code program to an executable program code to transfer to a two th, located with the issuer of the data carrier computer, and the Download the executable program code in the disk to return transmission reverts to the first computer, marked by distinguishedthatin a Vorkomplettierungsschritt on disk (10) software tools are applied for finishing, which allow from egg nem present in a transitional format transport code (U, UCSM. TCSSL,) To get an executable program code (C)in said second computer (30) Generated, executable program code (C) for retransmitted in transport code (U, UCSM, CSSL,) converted is, andto the first computer (20) For introduction into the data carrier (10) back of transmitted transport code (U, UCSM, TCSSL,) By means of software tools will be converted back into executable code (C). 1. Verfahren zur verteilten Erstellung eines ausführbaren Programmes für einen programmierbaren, tragbaren Datenträger, wobei die Erstellung eines Programmquelltextes auf einem ersten, bei einem Nutzer befindli chen Computer, Compilieren und Linken des Programmquelltextes zu einem ausführbaren Programmcode nach Übertragung auf einem zwei ten, beim Herausgeber des Datenträgers befindlichen Computer, und das Laden des ausführbaren Programmcodes in den Datenträger nach Rück übertragung wieder über den ersten Computer erfolgt, dadurch gekenn zeichnet, daß in einem Vorkomplettierungsschritt auf dem Datenträger (10) Software werkzeuge zur Endbearbeitung angelegt werden, die es erlauben, aus ei nem in einem Übergangsformat vorliegenden Transportcode (U, UCSM, TCSSL,) einen ausführbaren Programmcode (C) zu gewinnen, im zweiten Computer (30) erzeugter, ausführbarer Programmcode (C) für die Rückübertragung in Transportcode (U, UCSM, CSSL,) umgewandelt wird, und an den ersten Computer (20) zur Einbringung in den Datenträger (10) rückübertragener Transportscode (U, UCSM, TCSSL,) mittels der Software werkzeuge in ausführbaren Programmcode (C) rückgewandelt wird. 1. Verfahren zur verteilten Erstellung eines ausführbaren Programmes für einen programmierbaren, tragbaren Datenträger, wobei die Erstellung eines Programmquelltextes auf einem ersten, bei einem Nutzer befindlichen Computer, Compilieren und Linken des Programmquelltextes zu einem ausführbaren Programmcode nach Übertragung auf einem zweiten, beim Herausgeber des Datenträgers befindlichen Computer, und das Laden des ausführbaren Programmcodes in den Datenträger nach Rückübertragung wieder über den ersten Computer erfolgt, dadurch gekennzeichnet , daß in einem Vorkomplettierungsschritt auf dem Datenträger ( 10 ) Softwarewerkzeuge zur Endbearbeitung angelegt werden, die es erlauben, aus einem in einem Übergangsformat vorliegenden Transportcode (U, UCSM, TCSSL,) einen ausführbaren Programmcode (C) zu gewinnen, im zweiten Computer ( 30 ) erzeugter, ausführbarer Programmcode (C) für die Rückübertragung in Transportcode (U, UCSM, CSSL,) umgewandelt wird, und an den ersten Computer ( 20 ) zur Einbringung in den Datenträger ( 10 ) rückübertragener Transportscode (U, UCSM, TCSSL,) mittels der Softwarewerkzeuge in ausführbaren Programmcode (C) rückgewandelt wird.
- 2The method according to claim 1, characterized in that the on the first computer (20) Created program source (Q) for transmission to the second computer (30) Receives a transport security by ver is encrypted. 2. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß der auf dem ersten Computer (20) erstellte Programmquelltext (Q) für die Übertragung zum zweiten Computer (30) eine Transportsicherung erhält, indem er ver schlüsselt wird. 2. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß der auf dem ersten Computer ( 20 ) erstellte Programmquelltext (Q) für die Übertragung zum zweiten Computer ( 30 ) eine Transportsicherung erhält, indem er verschlüsselt wird.
- 3The method according to claim 1, characterized in that the software tools a storage media (10) Designating ID Informa tion (114) As well as a signature key (124) Include. 3. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die Softwarewerkzeuge eine einen Datenträger ( 10 ) bezeichnende Identifikationinformation ( 114 ) sowie einen Signaturschlüssel ( 124 ) beinhalten. 3. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die Software werkzeuge eine einen Datenträger (10) bezeichnende Identifikationinforma tion (114) sowie einen Signaturschlüssel (124) beinhalten.
- 4The method according to claim 1, characterized in that the software tools, a program for performing an SSL handshake Protocol (122) And / or a program for the implementation of Secure- messaging (120) Include. 4. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die Softwarewerkzeuge ein Programm zur Durchführung eines SSL-Handshake- Protokolls ( 122 ) und/oder ein Programm zur Durchführung von Secure- Messaging ( 120 ) beinhalten. 4. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die Software werkzeuge ein Programm zur Durchführung eines SSL-Handshake- Protokolls (122) und/oder ein Programm zur Durchführung von Secure- Messaging (120) beinhalten.
- 5The method according to claim 1, characterized in that the software tools a private media key (130) And a program for verification of a signature with the public key (128) Of two th computer (30) Include. 5. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die Softwarewerkzeuge einen privaten Datenträgerschlüssel ( 130 ) sowie ein Programm zur Prüfung einer Signatur mit dem öffentlichen Schlüssel ( 128 ) eines zweiten Computers ( 30 ) beinhalten. 5. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß die Software werkzeuge einen privaten Datenträgerschlüssel (130) sowie ein Programm zur Prüfung einer Signatur mit dem öffentlichen Schlüssel (128) eines zwei ten Computers (30) beinhalten.
- 6The method according to claim 1, characterized in that in the portable pe ren disk (10) To be loaded, executable program code (C) Inclusion of the second computer (30) Is carried out to potential to detect errors. 6. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß in den tragbaren Datenträger ( 10 ) zu ladender, ausführbarer Programmcode (C) unter Einbeziehung des zweiten Computers ( 30 ) ausgeführt wird, um mögliche Fehler zu ermitteln. 6. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß in den tragba ren Datenträger (10) zu ladender, ausführbarer Programmcode (C) unter Einbeziehung des zweiten Computers (30) ausgeführt wird, um mögliche Fehler zu ermitteln.
- 7The method according to claim 6, characterized in that in the portable pe ren disk (10) To be loaded, executable program code (C) on the second computer (30) Including the first computer (20) out lead is. 7. Verfahren nach Anspruch 6, dadurch gekennzeichnet, daß in den tragbaren Datenträger ( 10 ) zu ladender, ausführbarer Programmcode (C) auf dem zweiten Computer ( 30 ) unter Einbeziehung des ersten Computers ( 20 ) ausgeführt wird. 7. Verfahren nach Anspruch 6, dadurch gekennzeichnet, daß in den tragba ren Datenträger (10) zu ladender, ausführbarer Programmcode (C) auf dem zweiten Computer (30) unter Einbeziehung des ersten Computers (20) ausge führt wird.
- 8The method according to claim 1, characterized in that the ausführba re program code (C) in the memory (113) Of the data carrier (10) Is stored. 8. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß der ausführbare Programmcode (C) im Speicher ( 113 ) des Datenträgers ( 10 ) abgelegt wird. 8. Verfahren nach Anspruch 1, dadurch gekennzeichnet, daß der ausführba re Programmcode (C) im Speicher (113) des Datenträgers (10) abgelegt wird.
- 9Programmable portable data carrier with an integrated circuit circle, which includes a processor and a memory for recording having by the processor executable program code, thereby ge indicates that in the integrated circuit (12) Software tools are applied for finishing, which make it one in an over gang format supplied transport code (U, UCSM, TCSSL) Into executable Program code (C) to transfer. 9. Programmierbarer tragbarer Datenträger mit einem integrierten Schaltkreis, welcher einen Prozessor sowie einen Speicher zur Aufnahme von durch den Prozessor ausführbarem Programmcode aufweist, dadurch gekennzeichnet, daß in dem integrierten Schaltkreis ( 12 ) Softwarewerkzeuge zur Endbearbeitung angelegt sind, die es ermöglichen, einen in einem Übergangsformat zugeführten Transportcode (U, UCSM, TCSSL) in ausführbaren Programmcode (C) zu überführen. 9. Programmierbarer tragbarer Datenträger mit einem integrierten Schalt kreis, welcher einen Prozessor sowie einen Speicher zur Aufnahme von durch den Prozessor ausführbarem Programmcode aufweist, dadurch ge kennzeichnet, daß in dem integrierten Schaltkreis (12) Softwarewerkzeuge zur Endbearbeitung angelegt sind, die es ermöglichen, einen in einem Über gangsformat zugeführten Transportcode (U, UCSM, TCSSL) in ausführbaren Programmcode (C) zu überführen.
- 10A data carrier according to claim 9, characterized in that it has little least one sequence counter (136) Has. 10. Datenträger nach Anspruch 9, dadurch gekennzeichnet, daß er wenigstens einen Sequenzzähler ( 136 ) aufweist. 10. Datenträger nach Anspruch 9, dadurch gekennzeichnet, daß er wenig stens einen Sequenzzähler (136) aufweist.
- 11A data carrier according to claim 9, characterized in that it comprises a the disk (10) Designating identification information (114) And a key (124) Includes the formation of a data protection code, which it a defined second computer (30) assign. 11. Datenträger nach Anspruch 9, dadurch gekennzeichnet, daß er eine den Datenträger (10) bezeichnende Identifikationsinformation (114) sowie einen Schlüssel (124) zur Bildung eines Datensicherungscodes enthält, welche ihn einem definierten zweiten Computer (30) zuordnen. 11. Datenträger nach Anspruch 9, dadurch gekennzeichnet, daß er eine den Datenträger ( 10 ) bezeichnende Identifikationsinformation ( 114 ) sowie einen Schlüssel ( 124 ) zur Bildung eines Datensicherungscodes enthält, welche ihn einem definierten zweiten Computer ( 30 ) zuordnen.
- 12Computer zur Durchführung einer verteilten Erstellung eines ausführbaren Programmes für einen programmierbaren, tragbaren Datenträger, enthaltend zumindest ein Compilierungsprogramm sowie ein Linkprogramm ( 312 ), dadurch gekennzeichnet, daß er über Mittel verfügt, um aus einen zugegangenen, in einem Übergangsformat vorliegenden Transportcode (T, TQ, TQSSL,) einen Programmquelltext (Q) rückzugewinnen. 12. Computer zur Durchführung einer verteilten Erstellung eines ausführba ren Programmes für einen programmierbaren, tragbaren Datenträger, ent haltend zumindest ein Compilierungsprogramm sowie ein Linkprogramm (312), dadurch gekennzeichnet, daß er über Mittel verfügt, um aus einen zugegangenen, in einem Übergangsformat vorliegenden Transportcode (T, TQ, TQSSL,) einen Programmquelltext (Q) rückzugewinnen. 12. computer to perform a distributed creating a ausführba ren program for a programmable portable data carrier, ent holding at least one Compilierungsprogramm and a link program (312), Characterized in that it has means of a information received, present in a transitional format Transport Code (T, TQ, TQSSL,) A program code (Q) recover.
- 13Computer nach Anspruch 12, dadurch gekennzeichnet, daß er Mittel aufweist, um die Identität eines zu programmierenden Datenträgers (10) festzustellen und zu überprüfen. 13. Computer nach Anspruch 12, dadurch gekennzeichnet, daß er Mittel aufweist, um die Identität eines zu programmierenden Datenträgers ( 10 ) festzustellen und zu überprüfen. 13. The computer of claim 12, characterized in that it comprises means having to determine the identity of a data carrier to be programmed (10) ascertain and verify.
- 14A computer according to claim 12, characterized in that it comprises a Ta belle (340) Leads, in the for each portable data carrier (10), Which by means of the computer (30is) programmed, a disk characteristic Identification information (114) Is stored. 14. Computer nach Anspruch 12, dadurch gekennzeichnet, daß er eine Tabelle ( 340 ) führt, in der für jeden tragbaren Datenträger ( 10 ), der mittels des Computers ( 30 ) programmierbar ist, eine den Datenträger bezeichnende Identifikationsinformation ( 114 ) abgelegt ist. 14. Computer nach Anspruch 12, dadurch gekennzeichnet, daß er eine Ta belle (340) führt, in der für jeden tragbaren Datenträger (10), der mittels des Computers (30) programmierbar ist, eine den Datenträger bezeichnende Identifikationsinformation (114) abgelegt ist.
- 15Computer nach Anspruch 12, dadurch gekennzeichnet, daß er über Mittel ( 321 ) zur formalen Verifikation eines durch Compilierung erzeugten Programmcodes (C) aufweist. 15. Computer nach Anspruch 12, dadurch gekennzeichnet, daß er über Mit tel (321) zur formalen Verifikation eines durch Compilierung erzeugten Pro grammcodes (C) aufweist. 15. The computer of claim 12, characterized in that he With tel (321) For formal verification of a Pro produced by compilation program code (C).
- 16Computer nach Anspruch 12, dadurch gekennzeichnet, daß er über Mittel ( 316 ) verfügt, um einen erzeugten Programmcode (C) durch unmittelbare Ausführung darauf zu prüfen, ob er Fehler enthält. 16. Computer nach Anspruch 12, dadurch gekennzeichnet, daß er über Mit tel (316) verfügt, um einen erzeugten Programmcode (C) durch unmittelbare Ausführung darauf zu prüfen, ob er Fehler enthält. 16. The computer of claim 12, characterized in that he With tel (316) Has to a code generated (C) by direct to consider execution of whether it contains errors.
- 1717 computer to perform a distributed creating a ausführba ren program for a programmable portable data carrier, ent holding at least a first interface for data exchange with egg nem data carrier and a second interface to a data link, characterized in thatit comprises means to an editing program (22) To create a by the computer (20) Itself is not executable source code (Q) execute,and in that it comprises means on the first and the second interface (24. 26) A direct data transfer between a portable data carriers (10) And via the data link (28) Connected, second computer (39) Allow. 17. Computer zur Durchführung einer verteilten Erstellung eines ausführbaren Programmes für einen programmierbaren, tragbaren Datenträger, enthaltend zumindest eine erste Schnittstelle für einen Datenaustausch mit einem Datenträger sowie eine zweite Schnittstelle zu einer Datenverbindung, dadurch gekennzeichnet, daß er Mittel aufweist, um ein Editierungsprogramm ( 22 ) zur Erstellung eines durch den Computer ( 20 ) selbst nicht ausführbaren Programmquelltextes (Q) auszuführen, und daß er Mittel aufweist, um über die erste und die zweite Schnittstelle ( 24 , 26 ) eine direkte Datenübertragung zwischen einem tragbaren Datenträger ( 10 ) und einem über die Datenverbindung ( 28 ) angeschlossenen, zweiten Computer ( 39 ) zu ermöglichen. 17. Computer zur Durchführung einer verteilten Erstellung eines ausführba ren Programmes für einen programmierbaren, tragbaren Datenträger, ent haltend zumindest eine erste Schnittstelle für einen Datenaustausch mit ei nem Datenträger sowie eine zweite Schnittstelle zu einer Datenverbindung, dadurch gekennzeichnet, daß er Mittel aufweist, um ein Editierungsprogramm (22) zur Erstellung eines durch den Computer (20) selbst nicht ausführbaren Programmquelltextes (Q) auszuführen, und daß er Mittel aufweist, um über die erste und die zweite Schnittstelle (24, 26) eine direkte Datenübertragung zwischen einem tragbaren Daten träger (10) und einem über die Datenverbindung (28) angeschlossenen, zweiten Computer (39) zu ermöglichen.
- 18A computer according to claim 17, characterized in that it comprises means having to run an SSL protocol. 18. Computer nach Anspruch 17, dadurch gekennzeichnet, daß er Mittel aufweist, um ein SSL-Protokoll auszuführen. 18. Computer nach Anspruch 17, dadurch gekennzeichnet, daß er Mittel aufweist, um ein SSL-Protokoll auszuführen.
- 19A system for distributed creation of an executable program for egg NEN programmable portable data carrier, including a contract Baren data carrier according to claim 9 and a computer according to Claim 12th 19. System zur verteilten Erstellung eines ausführbaren Programmes für einen programmierbaren, tragbaren Datenträger, beinhaltend einen tragbaren Datenträger gemäß Anspruch 9 sowie einem Computer gemäß Anspruch 12. 19. System zur verteilten Erstellung eines ausführbaren Programmes für ei nen programmierbaren, tragbaren Datenträger, beinhaltend einen trag baren Datenträger gemäß Anspruch 9 sowie einem Computer gemäß Anspruch 12.
- 20System according to claim 20, characterized in that it further comprises a computer according to claim 17 comprising. 20. System nach Anspruch 20, dadurch gekennzeichnet, daß es weiterhin einen Computer gemäß Anspruch 17 umfaßt. 20. System nach Anspruch 20, dadurch gekennzeichnet, daß es weiterhin einen Computer gemäß Anspruch 17 umfaßt.
Independent claims20
89 paragraphs, as filed
The invention relates to the tamper-resistant creating ausführba rem code for programmable portable data carrier, preferably , in the form of smart cards.
From US-A-6,023,565 is a method for distributed creation of Pro grammes known for a programmable logic circuit. a Users who for using a computer located at his program wants to create such a circuit, after which the manufacturer the circuits which permit easy user interface provided. This describes the user at his computer for the logic circuit circle desired functionality. The description will be driven menu Entry forms by means of which prepared parameters are set. Of the resulting, the desired circuit functionality descriptive Para meter data set is over a data network to a computer of the circuit manufacturer sent. This compiles the parameter data set and generates an executable program with the functionality desired by the user. The executable program sends the manufacturer back to the computer of the User, which converts it into a programming command sequence, and this transmits to the logic circuit. By creating the program on the Conversational inputting parameters is reduced, allowing the Kon concept also users without extensive programming knowledge the Erstel development of programs for logic circuits. A program creation is this possible without the user has a compiler software. The concept aims to increase the ease of use of a structure conditionally to improve difficult to handle technical system. In front ausgetau precautions to protect the computers involved between specific data from manipulation are not taken. The concept is therefore not suitable for applications where there is a particularly Protection of program data generated against scrutinizing and Manipulati on arrives. In particular, it is not in the form described to create programs for chip cards by means of which sicherheitsre levante transactions as banking services, to be executed.
Smart cards, which allow the downloading of executable code, and the collection reloaded program code in chip cards z. B. in "Smart Card Handbook" by W. Rankl, W. Effing, Hansa Verlag Munich, 3rd edition describes. Program generation is thereafter completely to a background system. The created executable Pro program code is processed via, eg., by a mutual authentication transmitted secured interface to the smart card. Off Security Green the carried out the transfer of the executable program code on the chip map preferably online after previously an unambiguous identification and allocation of background system, interfaces, Kartenbetriebssy system and microprocessor cards is done. In order while maintaining a highly possible security manageability of the Identifikationsinformatio NEN databases containing the background systems to ensure be the authorizations to create executable Pro program code on background systems of the card issuers only un ter conditions issued and listed the licenses issued. The in principle created possibility, executable program code for create smart card itself, is thereby limited.
To secure a run over an open data network data exchange between two computers, a number of on different Ver encryption techniques based methods known, including the SSL (Secure Socket Layer) protocol, PGP (Pretty Good Privacy), the Secure Messaging or SMIME protocol. Methods of this kind are also to the described below, used methods of the invention, but are to not the subject of the invention. The finishing details a Finally, the cryptologic realization is therefore generally to the varied available descriptions of the methods in a relevant literature and referenced on the Internet. The same applies to the übli chen means used in connection with data backup methods such as the encryption according to the 3DES process or the formation of Message Authentication Codes (MAC).
The invention has for its object to provide a process which makes it permitted while maintaining maximum security against data manipulation, for a broad range of users to create executable to allow programs for programmable portable data carrier. On gift of invention, it is necessary for carrying out the method nö specify term system components.
The object is achieved by a method having the features of Main claim. According to a user be a program editor for creating program source code and a vorkomplettierter portable data carrier provided over the software tools finishing features, which the conversion of in an over gang format present transport code in executable code allow. Creating an executable program for the Datenträ ger occurs distributed. With the program editor, the user creates a Pro program quelltext the below via a secure connection to a received from the publisher of the data carrier located computer becomes. The secure connection can be made by a Program source code of the precompleted media itself to a Transport code is encrypted and is protected against change that only a certain, be a case of a publisher of the data carrier sensitive computer-addressed receiver the transport code entschlüs may review clauses and integrity.
From the received program source generates the publisher the data carrier located computer by compiling and linking egg nen executable code. Part of compiling and Linkvor ganges is a formal verification of the generated code, by the particular aggressive code is detected. The verified, from executable program code consists of the editor of the volume be Computer-sensitive in a transitional format and transmits this via the user's computer to the precompleted, portable Datenträ ger. This converted him using the Endbearbeitungsoftwarewerkzeuge back into executable code and accepts this in its Memory.
Preferably, the safety-related parts of Endbearbeitungssoft ware in precompleted disks contain. To be expedient larly in precompleted media itself in particular the decisions ment and / or the determination of the authenticity and / or integrity performed a transport code program code containing before If no errors occur, the resulting executable program code in the Storage of the data carrier is stored.
The method creates a secure "end-to end" - Connection between a located at a publisher computer and a disk over a located at a user computer. By designing the Vorkomplettierung and the choice of software tools leaves it lightly against the type and technical options adjust speeds of each given volume. Are the media only for the execution of a symmetric encryption methods directed the preparation of a secured done "end-to-end" - Compound expediently by using a symmetischen kartenin vidual key one hand, and a superimposed, simplified asymmetric encryption on the data connection between the The user's computer and the editor of the volume be sensitive computer on the other. In an alternative embodiment carried to secure the data transmission between the user's computer and located with the issuer of the data carrier a computer asymmetric encryption with mutual authentication and is the trusted "end-to-end" connection between the at Her spender located computer and the disk with the mechanisms men of secure messaging set up.
Are the volumes of the implementation of asymmetric closures regulatory procedure set up, is suitably between when removing encoder of the data carrier located computer and the disk directly a secured by asymmetric encryption "end-to-end" - Compound formed. The computer of the user acts only as a mediator.
The inventive method has the advantage that the preparation of executables basically any for a data carrier can be left to users, without the user's identity Festge represents and should be managed. As the editor of the media in any programming is involved, safety is generated Programs and about the entire system always guaranteed. Because in particular, the compiler functionality with the publisher of the media remains important and safety-relevant know-how does not have to Users can be passed.
By designing the compiler functionality such that direct, straight encrypted access to native source code or program by users generated executable codes are blocked, can be reversed ensure that application-specific know-how of the user before Publisher is protected. Suitably, this where when removing encoder located computer used a hardware security module, in the compiler functionality, the encryption / decryption of Program men, the test / production of signatures and the authentication be executed. erschei Outside of Hardware Security Modules NEN program source code or executable code only in ver encrypted form.
Through the formal verification of newly created programs with the publisher, ie in a safe environment, may also very reliable transfers aggressive program codes into usable through a medium systems be prevented. In addition, the advantage that all the created results from compiled executable programs with the most current compiler will. The inventive method can either online or offline be executed. For the editors of volumes that opens it inventive method even the possibility of the preparation of each desired executable application programs entirely to the users left and the media at all, only in the form vorkomplettierter extradite. The always enforced by the distributed program creation Involvement of the editor in a programming allows the Furthermore, the introduction of user methods that fee models use, which, for. example number or the type of a data carrier accommodated executable programs are based.
An embodiment of the invention will be described below Bezugnah me explained to the drawing.
Show it:
<b>Fig.</b> 1 shows a system for executing a program creation,
<b>Fig.</b> 2, the structure of the integrated circuit of a programming ble, portable data carrier,
<b>Fig.</b> 3 shows the structure of a second computer,
<b>Fig.</b> 4 the basic sequence of a distributed Programmerstel ment,
<b>Fig.</b> 5 to 7 are flowcharts showing the sequence of a Program creation,
<b>Fig.</b> 8 the principle of online verification of a program started runnability.
<b>Fig.</b> 1 illustrates distributing the basic structure of a system for time creation of a program for a programmable portable Disk. A first, for a data exchange with a portable Da tenträger <b>10</b> trained computer <b>20</b> is through a data connection <b>28</b> with a second computer <b>30</b> connected.
The first computer <b>20</b> is located at a user, such as a bank, an insurance, a retailer, a medical facility or the like or with a service provider who commissioned one of the called institutions created programs. He has a first, PLEASE CONTACT rend or contactless interface <b>24</b>, The z. B. the contact field, can be realized in the form of a coil or as an optical signal transmitter and the data exchange with a portable data carrier <b>10</b> allows. Via a further interface <b>26</b> He is on a data connection <b>28</b> is closed. About both interfaces<b>24</b>. <b>26</b> connects the user computer <b>20</b> the disk <b>10</b> with the data connection <b>28</b>, The user computer<b>20</b> provides disk <b>10</b> Registered willing additional functions. In particular ge He equips the operation of, listed below briefly editor Editie insurance program <b>22</b>That the creation of program source for a data carrier <b>10</b> allowed.
For the programmable portable data carrier <b>10</b> will then The form of a chip card based. In this aspect, it is but in no way limited. The disk<b>10</b> rather may adapted to the particular use, also be designed differently, for instance in the form of a Watch, as a write means, etc. Regardless of its actual publication form has the portable data carrier <b>10</b> each one for interface <b>24</b> of user computer <b>20</b> corresponding interface <b>14</b>Which a Da exchange with a user computer <b>20</b> allows. Further features the portable data carrier <b>10</b> an integrated circuit <b>12</b>Which has a central processing unit and a memory for receiving the Pro program codes of at least one of the central processing unit Execute having ble application program.
The second computer <b>30</b> is typically at a Publisher of portable data carriers <b>10</b> or an authorized operator of the here described method. Usually he has to a relative of the user computer <b>20</b> or the portable data carrier <b>10</b> essential greater computing power. The second computer<b>30</b> must not present as BAULI che unit be realized. Instead, it can spread as a system with Components to be executed, which ver about a particular data network connected are. To save or to perform safety-critical Functions can be used Hardware Security Modules. Over a interface <b>34</b> is the second computer <b>30</b> to the data connection <b>28</b> is closed. The second computer<b>30</b> is particular to formed a compile program <b>310</b> to implement a program in a high-level language source code present program in machine language out; it is therefore referred to as compiler server.
The data connection <b>28</b> usually has the form of a data network and may in particular be realized by the Internet. Although in<b>Fig.</b> 1 only a connection between two components <b>20</b>. <b>30</b> is shown, on the below-mentioned data network data connection <b>28</b> also several re user computer <b>20</b> with one or several servers Compiler <b>30</b> be connected.
<b>Fig.</b> 2 shows the structure of the integrated circuit <b>12</b> a smart card <b>10</b> with applied as Vorkomplettierung software tools. The inte grated circuit <b>12</b> has a typical smart card processors Archi architecture and includes a central processing unit <b>100</b>, A volatile working memory <b>102</b>And a nonvolatile memory device <b>104</b> on the latter consisting of a non-volatile read-only memory as well as a non- volatile rewritable memory. Typically, the volatile random access memory <b>102</b> a RAM memory, the non-volatile read-only memory a ROM memory and non-volatile, rewritable memory is an EEPROM memory. Besides these mentioned, any other, the same functionality having memory types are used. The central processing unit <b>100</b> is further connected to the interface <b>14</b> connected.
In the nonvolatile memory device <b>104</b> There is a number of the use of the data carrier <b>10</b> required software tools, which in a Vorkomplettierungsphase before handing over the data carrier <b>10</b> at one Users can be created. Among software tools in this case are not all changeable by a user program, routine, or records be understood that each specific as needed for execution are data processing tasks used. In the context of Vorkomplet applied orientation is on the one hand a version independent, always similar maps basic equipment <b>110</b>, It includes at least the Be operating system <b>111</b>, A basic program code <b>112</b> for the realization of at applications that are already in handing over to the user on the smart card <b>10</b> are, as well as a storage area <b>113</b> for later Low nachgeladenem, executable program code.
Secondly, one on each selected variant is abge agreed selection of the following software tools created: one for the integrated circuit <b>12</b>, And thus for the chip card <b>10</b>, Individual and unique identification information <b>114</b>, Z. B. a serial number, a Pro gram <b>116</b> for performing asymmetric cryptographic algorithmic men, a program <b>118</b> for performing symmetrical kryptographi cal algorithms, a program <b>120</b> for guiding a data exchange according to the principle of Secure messaging, a program <b>122</b> to imple tion of a data exchange over the data network <b>28</b> according to the SSL Protocol, a smart card individual signature key <b>124</b>, A Chipkar tenindividueller symmetric key <b>126</b>, The public key <b>128</b> one of the chip card <b>10</b> associated compiler server <b>30</b>, A private Kar tenschlüssel <b>130</b> for use in an asymmetrical closures regulatory procedure, a certificate <b>132</b>That the solidarity between rule public card keys and identification information with a signature publisher confirms storage space for receiving a Sitzungssschlüssel <b>134</b> - This is in contrast to the vorgenann ten keys in the recording of a data exchange with a compiler lerserver <b>30</b> each newly generated, and a sequence counter <b>136</b>, All genann th software tools can also be present more than once each. The especially for the listed keys, certificates, and the sequence counter.
<b>Fig.</b> 3 illustrates the structure of a compiler server <b>30</b> with in the Performing a programming software used and Software tools. Core of compiler server<b>30</b> forms a central Pro processor unit <b>300</b>Which via an interface <b>34</b> to the data network <b>28</b> is connected to over a data exchange with a Nutzercompu ter <b>20</b> and also with a smart card <b>10</b> to lead. Next are the zen tral processing unit <b>300</b> a volatile RAM <b>302</b>, Usually in Shape of a RAM, and a nonvolatile memory device <b>304</b> assigned, which is usually a read only memory ROM, and a mass storage device, such as a hard disk comprises.
In the memory array <b>304</b> are followed for the implementation of the pre-strike NEN process required software tools stored. <b>Fig.</b> 3 shows the A simplicity for an overview of all in connection with this Description eligible software tools. The selection of actually required software tools depends, as in the smart card <b>10</b>. execution of the actually chosen for implementing the method form. In general, in the memory array <b>304</b> to software tools are: A, in <b>Fig.</b> 3 compiler called Compilierungspro gram <b>310</b> the implementation of code into a program code, one, in <b>Fig.</b> 3 linker called Link program <b>312</b> for integration of be already started the program code in the context of a newly created Pro grammes, a code library <b>318</b> EXISTING already with the program code ferent programs and program components, a database <b>320</b> to store certain users associated program code, a debug program <b>316</b> for testing a program created to runnability, a Pro gram <b>321</b> for formal verification of the generated programs and / or Source code, one or more master keys <b>324</b>Which to the one or more smart card individual symmetric keys <b>126</b> correspond, a or more master key <b>326</b>Which to the individual smart cards keys <b>124</b> the formation of backup codes, especially MACs correspond, one or more public server key <b>328</b> to Implementation of asymmetric cryptographic algorithms, a or more corresponding private server key <b>330</b>, One or several public card key <b>332</b> for performing asymmetric Algorithms, one or more server certificates <b>334</b>, One or more Se quenzzähler <b>338</b>And a list of certificates in the production the precompleted smart card <b>10</b> were formed and in the smart card <b>10</b> in the area <b>132</b> get saved. Furthermore includes the memory arrangement <b>304</b> a user list <b>340</b> with identification information allow a precise identification of a smart card; ID Case the entire map for the identification of chip cards <b>10</b> can example , be their serial numbers.
Suitably, in a compiler server <b>30</b> in the practical order tion of the method of the aforementioned software tools only actually needed, that do not required in each case omitted.
Meaning and use of precompleted in the smart card <b>10</b> or the compiler server <b>30</b> are existing software tools below with reference to <b>Fig.</b> 4, the basic sequence of a distributing th programming shows, as well as the <b>Fig.</b> 5 to 7 explained the three From embodiments of a distributed program creation illustrate.
<b>Fig.</b> 4 first shows the basic sequence of a distributed Pro program development. In a preparatory phase a user be a by application of software tools vorkomplettierte chip card <b>10</b> and an editor <b>22</b> provided, step <b>400</b>, By Editor<b>22</b> he created on the user computer <b>20</b> a program source text Q, Step <b>402</b>, By employing a suitable encryption technique, the ser provided with a transport lock, step <b>404</b>, And in a Trans port code T, TQ, TQ<sub>SSL</sub> transferred, step <b>406</b>, The transport code T, TQ, TQ<sub>SSL</sub> is at the compiler server <b>30</b> transmitted; step<b>408</b>,
The compiler Server <b>30</b> raises by decrypting the transport safety on, step <b>410</b>, And wins in the transport code T, TQ, TQ<sub>SSL</sub> contained requested program source text Q back, step <b>412</b>, The program source text Q compiles, binds, and he verified subsequently, step <b>414</b>, The result is an executable program code C, step <b>416</b>Which subsequently turn will shrink cap, step <b>418</b>, It is this application by ge appropriated encryption mechanisms that do not match the previously on pages the user computer <b>20</b> must match applied, in a Transitional format U, U<sub>SM</sub>, U<sub>SSL</sub> transferred, step <b>420</b>, In this transitional format it is on the user computer <b>20</b> to the smart card <b>10</b> transmitted, step <b>422</b>,
Those determined using the scale at the Vorkomplettierung Software tools from the user computer <b>20</b> received Trans port code U, U<sub>SM</sub>, U<sub>SSL</sub> by decrypting again runnable Pro program code C and finally loads this in his memory.
<b>Fig.</b> 5 shows a distributed program creation in which the data security by use of the chip card <b>10</b> prepared agents in exchange effective with the compiler server <b>30</b> is achieved. In the<b>Fig.</b> 5 shown Embodiment is particularly suitable for systems in which the USAGE Deten smart cards <b>10</b> only symmetric encryption techniques beherr rule.
<b>Fig.</b> 6 shows an embodiment in which the user computer between <b>20</b> and compiler server <b>30</b> over the data network <b>28</b> successful data transmission is secured by a SSL protocol, while directly between smart card <b>10</b> and compiler server <b>30</b> takes place in accordance with the Data Transport Secure messaging mechanism is executed. The embodiment is also suitable for systems in which the used chip cards <b>10</b> only symmetric encryption techniques allow.
<b>Fig.</b> 7 illustrates an embodiment in which the user computer <b>20</b> essentially only as an intermediary between the smart card <b>10</b> and Compilerser ver <b>30</b> acts. Securing between the smart card<b>10</b> and compiler server <b>30</b> transported data is carried out by between compiler server <b>30</b> and smart card <b>10</b> using the SSL protocol directly secure "End-to-end" connection is established.
Table 1 illustrates the applicability of the systematic three successor quietly on the basis of <b>Fig.</b> 5, 6, 7 described embodiments in depen ing on the implementation of the data transfer, the Ausstattungsan demands on the chip card <b>10</b> and the type of transport fuse.
<imgref idrefs="15/1" />Table 1
The left column in the <b>Fig.</b> 5, 6, 7 each shows the activities of the compiler servers <b>30</b>That right the activities of the users computer <b>20</b> or smart card <b>10</b>Wherein "N" the user computer <b>20</b> designated "K", the chip map <b>10</b>,
The in <b>Fig.</b> 5 programming shown is preceded by a prepara reitungsphase. Therein the user by the publisher before a completed smart card <b>10</b>, Step <b>500</b>And an editor <b>22</b> establishing on his computer <b>20</b>, Step <b>502</b>, provided. On the vorkomplettier th chip card <b>10</b> are or are in addition to the basic equipment <b>113</b> furnishings: identification information ID in the storage area <b>114</b>, on program <b>118</b> for performing symmetric crypto algorithms about the "3DES" algorithm, at least one individual key cards K<sub>MAC</sub> to form a data protection code, preferably in the form of a MACs, in the memory area <b>124</b>, At least one key K<sub>ENC</sub> to symmetri rule encryption in the storage area <b>126</b>And space <b>134</b> to Receiving at least two session key SK<sub>ENC</sub>, SK<sub>MAC</sub>, further, on the chip card precompleted <b>10</b> at least two sequence counters <b>136</b> with values SEQ<sub>C</sub>, SEQ<sub>H</sub> furnished. The sequence counter SEQ<sub>C</sub> serves to calculate the session key SK<sub>ENC</sub>, SK<sub>MAC</sub> which to secure About transmission of program source code Q from the user computer <b>20</b> for Compi lerserver <b>30</b> are used, the sequence counter SEQ<sub>H</sub> used to calculate session keys SK<sub>ENC</sub>, SK<sub>MAC</sub> Which for the secure transmission of Program code C compiler Server <b>30</b> the user computer <b>20</b> used will.
On the compiler server <b>30</b> be for each issued smart card <b>10</b> two sequence counter <b>338</b> with values SEQ<sub>C</sub>, SEQ<sub>H</sub> furnished. The values SEQ<sub>C</sub>, SEQ<sub>H</sub> vote for the compiler server <b>30</b> by the same Re chenvorschrift as the chip card <b>10</b> used, the session key SK<sub>ENC</sub>, SK<sub>MAC</sub> can calculate, always with the values of the corresponding sequence counter <b>136</b> the associated smart card <b>10</b> agreement. to increase the security at each transmission of program source code Q or program code C other session key SK<sub>ENC</sub>, SK<sub>MAC</sub> used. increase for this purpose smart card <b>10</b> and compiler server <b>30</b> each before calculating Sitzungssschlüssel SK<sub>ENC</sub>, SK<sub>MAC</sub> the values SEQ<sub>C</sub> or. SEQ<sub>H</sub> The sequence counter <b>136</b>. <b>338</b>,
The Editor <b>22</b> allows the creation of program source text Q, z. B. in a High-level programming language. Preferably, it supports program creation by graphically underlaid, dialogue-controlled input guide and provides directly usable development tools such as a syntax check or the integration of program interfaces to the code library.
Standing smart card <b>10</b> in vorkomplettierter form and user computer <b>20</b> be riding, the user created using the editor <b>22</b> the Pro program quelltext Q a for insertion into a smart card <b>10</b> certain Program, step <b>504</b>, Preferably the preparation is carried out in a Pro ming up language, but generally any other format is possible. Is a program source text Q created, the user instructs the smart card <b>10</b> from the editor <b>22</b> by means of a corresponding command, the Pro program quelltext encrypt Q and with a MAC against Variegated securing tion. These increases chip card<b>10</b> initially the sequence counter value SEQ<sub>C</sub> and generates the Sitzungssschlüssel SK<sub>ENC</sub> and SK<sub>MAC</sub> , Z. B. with the symmetric 3DES algorithm, step <b>506</b>, then ver down it to the editor of <b>22</b> via the interfaces <b>24</b>. <b>14</b> obtained Program source Q with the session key SK<sub>ENC</sub> to form an intermediate code Q 'and calculates the session key SK<sub>MAC </sub>a MAC over Q ', Step <b>508</b>, Intermediate code Q 'and MAC transfers the chip card<b>10</b> so then via the interfaces <b>24</b>.<b>14</b> back to the editor <b>22</b>,
This determined further that in the storage area <b>114</b> the chip card <b>10</b> scale card identification ID, step <b>509</b>, And it adds to the Zwi rule code Q 'and the MAC to a transport code T together. The thus formed transport code T transmits the user computer <b>20</b> about the data network <b>28</b> the compiler server <b>30</b>, Step <b>510</b>, The transfer Medium done. For example, the transport code T as an e-mail on sent wear or on diskette by mail to the editor. in addition , the transport code T also online via the data network <b>28</b> to the compiler Server <b>30</b> sent. Confidentiality and integrity of the transmitted transport code T are encryption and MAC calculation by the smart card <b>10</b> guaranteed.
When compiler server <b>30</b> received, this first checking step <b>512</b>, if the identification information contained in transport code T ID in the in compiler server <b>30</b> guided Identifikafionsliste <b>340</b> is contained, the preferably a customer list forms. If this is true, it passes from first the in the memory areas <b>324</b>. <b>326</b> located master keys MK<sub>ENC</sub> and MK<sub>MAC</sub> using the identification information ID associated card-specific key K<sub>ENC</sub> and K<sub>MAC</sub> from step <b>514</b>, From these Keys and the incremented sequence counter SEQ<sub>C</sub> calculates the compiler Server <b>30</b> then the session key SK<sub>ENC</sub> and SK<sub>MAC</sub> after same calculation rule, previously the smart card <b>10</b> has used. With the Session key SK<sub>MAC</sub> calculates the compiler server <b>30</b> then was nerseits a MAC ', Step <b>516</b>, And compares it with the one in the Trans port code T contained MAC. If they match, the compiler recognizes lerserver <b>30</b> the transport code T as being authentic, that is, from the smart card <b>10</b> with the identification information ID coming, and with integrity, ie not at the transmission changed.
If the compiler server <b>30</b> a transport code T recognized as authentic, decrypting the program code contained in the transport code T Q ' by means of the session key SK<sub>ENC</sub>, Due to the previously established in integrity of the transport code T agrees the resulting decrypted For mat with on the user computer <b>20</b> originally created Pro program quelltext Q coincide.
The recovered program source text Q transferred the Compilerser ver <b>30</b> using the Kompilierungsprogrammes <b>310</b> in an interim rule format, which he then using the Link Program <b>312</b> under Access to the code library <b>318</b> with existing code bases connects, step <b>518</b>,
compile program <b>310</b> and Link Program <b>312</b> are in a purpose be modest design in the form of a Hardware Security Modules leads which the Compilier- and Link functionality, the development and Ver encryption of the edited program data, testing and preparation includes signatures and authentication. All processed Pro program data, in particular incoming program source texts Q and generated executable program code C then appear outside the hardware Security Modules in encrypted form only. This can be safely make that application-specific know-how of the user from view and access via the compiler server <b>30</b> is protected.
Appropriately, the compiler server <b>30</b> further restricting the Your access to the code library <b>318</b> be set up which z. B. the A bond existing program code into a newly created by the Link Program <b>312</b> limited.
The resulting after compilation and linking program code C is by means of the verification program <b>321</b> formally verified. In this case, the Program code C checked for obvious errors, such as to comply with the Address space, in compliance with the specified storage sizes on Type injury or aggressiveness, step <b>520</b>,
If the code C generated from the program code then Q usable form, ie by the chip card <b>10</b> executable, it is for the Retransfer converted into a transport code U. For this purpose, to next the sequence counter value SEQ<sub>H</sub> elevated. With the increased sequence counter value SEQ<sub>H</sub> then from the master keys MK<sub>ENC</sub> or MK<sub>MAC</sub> and the identification information ID is the card-specific key K<sub>ENC</sub> and K<sub>MAC</sub> derived and in turn session key SK<sub>ENC</sub> and SK<sub>MAC</sub> calculated step <b>522</b>, The calculation of Sitzungsschlüs sel SK<sub>ENC</sub>, SK<sub>MAC</sub> by the compiler server <b>30</b> is carried out in the same manner as previously, in step <b>506</b>, From the user computer <b>20</b> was made, wherein only instead of the sequence counter value SEQ<sub>C</sub> The sequence counter worth SEQ<sub>H</sub> is used.
Subsequently, with the session key SK<sub>ENC</sub> the program code C 'Encrypted and the intermediate code C' to an intermediate code C with means of the session key SK<sub>MAC</sub> continue a MAC "calculated step <b>524</b>, Intermediate code C 'and MAC "are then to a transport code U together, the compiler server <b>30</b> to the user computer <b>20</b> transmits, step <b>526</b>, can for sending the transport code U as in the case of the transport codes T any, in particular also a be insecure transmission medium such as a floppy disk or the shipping are elected by e-mail. Of course, next to the groove tion of an online connection via a data network <b>28</b> possible. If a Online connection used, it is possible for an order, ie the dispatch of a program source code contained in a transport textes Q at a compiler <b>30</b>, In a single online session also Ie a transport code U with the program code to C Sustainer result ' th.
The user computer <b>20</b> passes the received transport code U on interfaces <b>24</b>. <b>14</b> Next to the smart card <b>10</b>, Step <b>528</b>, Those increases SEQ value<sub>H</sub> of the sequence counter <b>136</b>Generated thereby in the same manner as previously the compiler server <b>30</b> in step <b>522</b> the Sitzungssschlüssel SK<sub>ENC</sub> or SK<sub>MAC</sub> and checks whether the submitted with transport code U MAC " identical to the MAC is to the smart card <b>10</b> even by means of the key SK<sub>MAC</sub> can be calculated from U-section <b>530</b>, Votes MAC "and MAC over one, the MAC "from U is successfully verified. Since except the chip card <b>10</b> even just the compiler server <b>30</b> has the possibility of the key SK<sub>MAC</sub> use, is by decrypting the in the transport code U transmitted program code C 'gewonnenene program code C authentic, that he was the compiler server <b>30</b> from one of the same smart card <b>10</b> transport secured program code Q generated. The as authentically recognized program code C is of the smart card <b>10</b> in the memory Cards <b>113</b> loaded section <b>532</b>,
<b>Fig.</b> 6 is a flowchart showing an embodiment of a distributed Pro program development, in which between user computer <b>20</b> and compiler server <b>30</b> over the data network <b>28</b> successful data transmission using SSL is secured, while the direct transport of data between the smart card <b>10</b> and compiler server <b>30</b> out using the secure messaging mechanism lead is. The embodiment is as in<b>Fig.</b> 5 shown Embodiment particularly for online execution in systems which the chip cards used <b>10</b> only symmetric encryption techniques allow.
A for performing the second embodiment vorkomplettierte smart card <b>10</b> includes in addition to the basic equipment <b>110</b> with operating system <b>111</b>, Basic program code <b>112</b> and storage space <b>113</b> for completion program code, a routine <b>120</b> implementing the Secure messaging, a card private key <b>130</b> and a public key server <b>128</b>, The user computer<b>20</b> also has the program functionality for performing the SSL protocol without authentication smart cards.
The implementation of a program creation in the second execution form initially corresponds to the first embodiment of <b>Fig.</b> 5 and to summarizes the steps <b>500</b> to <b>504</b>,
If there is a program source code Q, the user is directed via the data network <b>28</b> a connection between his computer <b>20</b> and the compiler server <b>30</b> the publisher a step <b>600</b>,
If the physical connection to the server compiler <b>30</b> will be produced between user computer <b>20</b> and compiler server <b>30</b> ge SSL protocol starts. user computer<b>20</b> and compiler server <b>30</b> determine in each case a session key SK<sub>SSL</sub>, steps <b>601</b>. <b>602</b>, Then within the SSL protocol a so-called IP tunnel between compiler server <b>30</b> and smart card <b>10</b> the implementation of the Secure messaging furnishings, step <b>604</b>, In user computer<b>20</b> is in this case that of the chip card <b>10</b> performed protocol of the Secure messaging in that only between groove zercomputer <b>20</b> and compiler server <b>30</b> eingebet used SSL protocol tet. In the IP tunnels are below smartcard specific records, preferably in the form of APDUs (Application Protocol Data Unit) directly between chip card <b>10</b> and compiler server <b>30</b> transported. In relation to the secure messaging functions the user computer <b>20</b> purely as a mediator.
According to the Secure Messaging lead smart card <b>10</b> and compiler server <b>30</b> then mutual authentication, with the first map <b>10</b> opposite the compiler server <b>30</b> authenticated, step <b>606</b>, at closing the compiler server <b>30</b> respect to the card <b>10</b>, Step <b>608</b>, Ver running the mutual authentication between the smart card <b>10</b> and Com pilerserver <b>30</b> successful, the use of all functions of the compiler servers <b>30</b> by the user computer <b>20</b> released, step <b>610</b>,
If there is the use of release, encrypts the user computer <b>20</b> the created program source Q with the predetermined Sitzungsschlüs sel SK<sub>SES</sub> and transmits the resulting transport code TQ the compiler server <b>30</b>, Step <b>612</b>,
In compiler server <b>30</b> the transport code TQ is received using the previously in compiler server <b>30</b> generated session key SK<sub>SSL</sub> again ent down, step <b>614</b>, And in the in the user computer <b>20</b> created Source Q transferred. Advisably follow the steps<b>610</b>. <b>612</b>. <b>614</b> in the form of a continuous data exchange between users computer <b>20</b> and compiler server <b>30</b>So that the restoration of the Source code Q in compiler server <b>30</b> Immediately upon receipt of the final ver encrypted source data set from the user computer <b>20</b> completed becomes.
From the source Q, the compiler generates Server <b>30</b> then by Ausfüh tion of the reference to the <b>Fig.</b> 5 steps <b>518</b> and <b>520</b> one from executable program code C.
The executable program code C converts the compiler server <b>30</b> by Application of secure messaging mechanisms in secured Pro program code C<sub>SM</sub>, Step <b>620</b>, The secure program code C<sub>SM</sub> converted He then by encrypting using the session key SK<sub>SES</sub> in a present in a transitional format transport code UC<sub>SM</sub>. step <b>622</b>, The encryption with the session key SK<sub>SES</sub> becomes of, typically in the form of APDUs present, secured Pro program code C<sub>SM</sub> in a backup of the data transmission over the data network <b>28</b> between compiler server <b>30</b> and computer users <b>20</b> embedded.
The present in Übergagsformat transport code UC<sub>SM</sub> received the compiler Server <b>30</b> to the user computer <b>20</b>, This decrypted UC<sub>SM</sub> by means of Sitzungssschlüssels SK<sub>SES</sub>, Step <b>626</b>Thereby to protect the data transmission between compiler server <b>30</b> and computer users <b>20</b> Inappropriate fuse is removed. The then present ent encrypted, backed up in the secure messaging program code C<sub>SM</sub> passes the user computer <b>20</b> to the smart card <b>10</b>, Step <b>624</b>,
In the smart card <b>10</b> is the secure program code C<sub>SM</sub> by applica tion of reversing the secure messaging mechanisms back to Execute ble program code C is returned, step <b>628</b>, And finally into the memory array <b>104</b> in there to accommodate Komplettierungs program code prepared area <b>113</b> loaded, step <b>630</b>,
For the sake of clarity has been described above in the <b>Fig.</b> 6 Ver shown process sequence described as a sequential series of separate steps. In practice include between chip card <b>10</b>, User computer <b>20</b> and compiler Server <b>30</b> occurring data transfers usually a Da data exchange in both directions respectively. It makes sense also, procedural rensschritte for which this is possible, in the form of a continuous, quasi- parallel data exchange and processing process run, in the compiler server <b>30</b> and computer users <b>20</b> or chip card <b>10</b> proceedings rensschritte run temporally superimposed. Suitably this is z. B. for steps <b>620</b> to <b>630</b>: They are preferably in the form of a kontinuierli chen data exchange between compiler server <b>30</b> and computer users <b>20</b> executed in which a transfer of data records the transport code UC<sub>SM</sub> the user computer <b>20</b> already taking place, while in the Compi lerserver <b>30</b> nor the implementation of the program code C according to the Secure- Messaging is performed, and in which the compiler server <b>30</b> on the user computer <b>20</b> to the smart card <b>10</b> data records transferred by this un indirectly before loading into the storage space <b>113</b>, Ie without Zwischenspei insurance are up to complete input, decrypted.
<b>Fig.</b> 7 illustrates a further embodiment the reference to the <b>Fig.</b> 4 described programming, in which the user computer <b>20</b> in we sentlichen only as an intermediary between the smart card <b>10</b> and compiler server <b>30</b> acts. Securing between the smart card<b>10</b> and compiler server <b>30</b> transported data is carried out by between compiler server <b>30</b> and chip map <b>10</b> using the SSL protocol secure, direct "En de-to-end "is set up connection.
The Vorkomplettierung one to carry this variant suitable smart card <b>10</b> includes not only the means of Grundausstat tion <b>110</b> with operating system <b>111</b>, Basic program code <b>112</b> and Speicherbe rich for completion program code <b>113</b> the creation of a Program mes <b>122</b> the implementation of the SSL protocol, the deposit of a certifi cate <b>132</b>, The deposit of the private card key <b>130</b> and Hin deposit of the public server key <b>128</b>,
The implementation of the method according <b>Fig.</b> 7 initially corresponds to hand of <b>Fig.</b> 5-described embodiment, and comprises the steps of <b>500</b> to <b>504</b>, They are followed by the establishment of a connection between the chip card <b>10</b> and a compiler server <b>30</b> on the user computer <b>20</b>, Step <b>700</b>,
smart card <b>10</b> and compiler server <b>30</b> Now perform a full SSL Log. Within the handshake procedure in this case there is a confusion selseitige authentication by the one the compiler server certificate <b>332</b> by the chip card <b>10</b> is checked, step <b>701</b>, On the other hand, the in smart card <b>10</b> scale certificate <b>132</b> by the compiler server <b>30</b>, Step <b>702</b>, If, after the mutual certification exam a continuation of the Datenaustauches possible generate smart card <b>10</b> and compiler server <b>30</b> each a session key step <b>704</b> or. <b>706</b>,
In the <b>Fig.</b> 7 illustrated embodiment is particularly suitable for Online implementation. After establishing a secure data connection between chip card <b>10</b> and compiler server <b>30</b> can therefore provided be that of the user under a choice of several possible Betriebsop tions for further processing must make a choice. In this case, sen det of compiler server <b>30</b> after establishing the secure data connection a Anbietungsmitteilung of the possible operating options to the user computer <b>20</b>, Step <b>708</b>, From the information communicated Options selects the Users on the user computer <b>20</b> desired from such a pro program development with online translation, step <b>710</b>, Or a debug Mode in which on the feasibility of a program code newly generated line is determined.
To increase the security of data transmission to compiler server <b>30</b> can optionally follow a signature of the program source code by Q the chip card <b>10</b> be provided, step <b>711</b>, The signature is in itself known manner by the smart card <b>10</b> about the source of Q a hash forms and these private with the key <b>130</b> the smart card ver encrypted. The hash value can, especially when not suffi relevant hardware resources of a smart card <b>10</b>, By the Nutzercom computer <b>20</b> done.
The optionally signed program source code encrypts smart card <b>10</b> with the previously determined session key SK<sub>SSL</sub> to a Transport code TQ<sub>SSL</sub>, Step <b>712</b>She subsequently the Nutzercom computer <b>20</b> the compiler server <b>30</b> sends, step <b>714</b>,
That decrypts the received transport code TQ<sub>SSL</sub> again with the Session key SK<sub>SES</sub>, Step <b>716</b>To the program source text Q again produce. If a signature is not present, it checks by renewed Bil tion of the hash value using the public key cards <b>332</b> their accuracy.
From the recovered program source code, the compiler generates Q server <b>30</b> then by carrying out steps <b>518</b>. <b>520</b> one from executable program code C.
The program code C generated provides the compiler server <b>30</b> with a Signature that he the by forming a hash value and encrypting Hash value with the private key <b>330</b> the compiler server <b>30</b> generated. encrypts the resultant, then signed code to the public areas chen key <b>332</b> the chip card <b>10</b>, Step <b>718</b>, The then present Cipher transferred the compiler server <b>30</b> subsequently by encrypting with the session key SK<sub>SES</sub> in a transitional format C<sub>SSL</sub>, Step <b>720</b>. which he described as transport code finally to the user computer <b>20</b> transmitted, step <b>722</b>,
This passes the received transport code C<sub>SSL</sub> to the smart card <b>10</b> wei ter, step <b>724</b> which it through decryption with the session key SK<sub>SES</sub> again the cipher of the executable program code generator ured, step <b>725</b>, If the program code C compiler server<b>30</b> signed was decrypts the chip card <b>10</b> the cipher continues with the private key <b>130</b> the chip card <b>10</b> and analyzed the then present signature with the public key <b>128</b> the compiler server <b>30</b>, Step <b>726</b>, is the result of the signature check is positive, invites the smart card <b>10</b> the thus this executable program code C in the Speicheranordung <b>104</b> in held for receiving completion program code Spei cherraum <b>113</b>, Step <b>728</b>,
As in the embodiment according to <b>Fig.</b> 5 was in <b>Fig.</b> 7 shown Procedure of clarity described for sequentially. Practically, it is However, process steps, for that is reasonably possible, quasi parallel run by compiler server <b>30</b> and smart card <b>10</b> they Überla time hesitantly run. This applies, for. Example for the steps<b>712</b> to <b>716</b>Ie the Chipkar tenseitige encryption and compiler server-side recovery the program source code Q. You expediently be done in the form of a conti ous, quasi-parallel data exchange and processing process, so that the program source text Q almost immediately after sending the letz th data set by the smart card <b>10</b> in compiler server <b>30</b> present. A Caching to complete input of the program source text Q does not occur. Further, provides a realization in the form of a con ous, quasi-parallel data exchange and processing process Also the steps of <b>718</b> to <b>728</b> , ie for the server-side compiler Ver encryption of the executable program code C and its chipkartenseiti ge recovery and loading into the storage space <b>113</b> on the smart card <b>10</b>, The execution of these steps by compiler server<b>30</b> and smart card <b>10</b> is advantageously carried out without intermediate storage directly record at a time, so that the executable program code C substantially immediately after sending the last data set by Transport Code the compiler server <b>30</b> in the memory of the chip card <b>10</b> present.
As part of a program creation according to one of the above be described embodiments, the implementation of a debug be provided routine. This is a by the compiler server<b>30</b> he imputed program code C prior to loading on a smart card <b>10</b> on Lauffä ability tested. The principle of such a debugging routine is in<b>Fig.</b> 8 veran illustrates, whereby to simplify the description the purpose of assuring Data transmission directed measures, ie mainly the various NEN encryption are not shown.
The debug routine is as a program <b>316</b> in compiler server <b>30</b> created and is also performed there. In addition, or as part of the Programme<b>316</b> includes them an a disk simulating hardware Simu lation and / or a software-based simulation of a data carrier for Emulation of a generated program on the server compiler <b>30</b> under existing on the disk technical constraints. Ge controls will, after setting an appropriate mode of operation in compiler Server <b>30</b>, Via the editor <b>22</b> the user computer <b>20</b>, The operation unit setting can eg. as in the context of the selection of an operational option in steps <b>708</b> and <b>710</b> done when creating the program in accordance with the in <b>Fig.</b> 6 embodiment illustrated is carried out. The De bug-mode allows, among other things, from the user computer <b>20</b> from an in compiler Server <b>30</b> Run generated program to set stop marks, display memory areas and read variables and set.
For the execution of the debug routine, first in the usual manner created program source text Q, Step <b>504</b>And a connection to the Com pilerserver <b>30</b> constructed, step <b>700</b>, Subsequently, the source Q is according to one of the embodiments described above, the compiler server <b>30</b> transmitted, step <b>800</b>,
If the code Q received, provides the compiler server <b>30</b> the user the generation of a program code C in debug mode on, step <b>802</b>, A user may the mode it on the user computer<b>20</b> out choose Step <b>804</b>, If the debug mode is selected, create the compiler Server <b>30</b> from the received program source text Q by Execution of steps <b>526</b>. <b>528</b> a preliminary program code C<sub>V</sub>, of the at the compiler server <b>30</b> existing simulation and / or Emulati is onsumgebung run. The preliminary program code C<sub>V</sub> stores the compiler Server <b>30</b> in a buffer, step <b>806</b>, subsequently he sent to the user computer <b>20</b> a creation message, step <b>808</b>. this will bring for display, step <b>810</b>,
The user can program code Q Now use the Nutzercompu ters <b>20</b> provided with debug statements, ie stop sentinels put that off implementing a program in single steps or displaying Varia ble cause, step <b>812</b>, The debug statements are the Com pilerserver <b>30</b> notified.
Subsequently, on the user computer <b>20</b> of the execution the preliminary program code C<sub>V</sub> realized program on the Com pilerserver <b>30</b> be triggered, step <b>814</b>, The compiler Server<b>30</b> leads on the program taking into account the previously communicated debug Instructions, step <b>816</b>, After each execution of the De bug statements specified program section, he received a Result message to the user computer <b>20</b>, Step <b>818</b>That this to On show brings, step <b>820</b>, Depending passed by the debug Instructions can on an intervention of a user in the Program mouse be provided guidance, for example by entering variables or by set zen new debug instructions, step <b>822</b>, Optionally made Interventions in the program source text Q or new debug instructions, transmits the user computer <b>20</b> the compiler server <b>30</b>, If a debug Instructions finally processed, transmitted to the user computer <b>20</b> the compiler Server <b>30</b> a continuation signal, step <b>824</b>Toward which those by repeating step <b>814</b> the execution of the next Pro gram portion causes. He eventually considered vorgenom mene interventions in the program source text Q or new debug Instructions. The steps<b>814</b> to <b>824</b> are repeated until the compiler server <b>30</b> a by a preliminary program code C<sub>V</sub> Unrealised Pro program has completed.
Finally, the program proves to be error free run, causing the Users on the user computer <b>20</b> a change in the operating mode in the default mode, step <b>826</b>, The compiler Server<b>30</b> then generates from the then current program source text Q a executable program code C and transmits it as the basis of the <b>Fig.</b> 4 to 6 described on the user computer <b>20</b> to the smart card <b>10</b>, Step <b>828</b>, Furthermore, it deletes the cached, provisional Pro program code C<sub>V</sub>, Step <b>830</b>
The series of embodiments described above is in each case as to understand the basis for a concrete procedure realization. While maintaining the basic approach for achieving a safe Program merstellung vorkomplettierte to use disks that are Ausfüh The exemplary embodiments ausgestaltbar each within a wide range. This applies to particular for the execution of the structural elements, ie the smart card, the User computer, the data network and the compiler server. further, said encryption and authentication procedures themselves are naturally replaced by others with the same safety effect. All described embodiments can be particularly through the Using another key, sequence counters or other kryptografi bring shear algorithms on an even higher level of security. Out technical or safety reasons can also Umformatie ments be provided. Thus it is in particular in programmable chip cards with regard to their limited space usual one on one compiler Server <b>30</b> generated executable program code before or during La the once speicheroptimierend reformat in the smart card, in the example symbolic references through absolute addresses be replaced. For reasons of clarity were also each only Gutfälle described. The handling of error cases can be from However, derived using known standard solutions.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP1457937A1 | Cited by | European Patent Office (EPO) | Search report |
| DE102010013201A1 | Cited by | Germany | Search report |
| EP0892519A2 | Cites | European Patent Office (EPO) | Search report |
| US6005942A | Cites | United States of America | Search report |
| WO9912307A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| EP892519A2 | Cites | European Patent Office (EPO) | Search report |
| WO1999012307A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
12 members in 8 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 10108487 | Germany | A | |
| DE2001108487 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO02069118A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2002253025A1 | Australia | A1 | |
| DE10108487A1This record | Germany | A1 | |
| WO02069118A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1393146A2 | European Patent Office (EPO) | A2 | |
| US2004148502A1 | United States of America | A1 | |
| JP2004528632A | Japan | A | |
| RU2003127366A | Russian Federation | A | |
| RU2289157C2 | Russian Federation | C2 | |
| EP1393146B1 | European Patent Office (EPO) | B1 | |
| AT350697T | Austria | T | |
| DE50209173D1 | Germany | D1 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Rejection8131 | 8131 | |
| Request for examination as to paragraph 44 patent lawOP8 | OP8 |
Numbers
- Publication
- 10108487
- Publication, DOCDB
- 10108487
- Publication, EPODOC
- DE10108487
- Application
- 10108487
- Application, DOCDB
- 10108487
- Application, EPODOC
- DE2001108487
Titles2
- English
- Method and system for distributed creation of a program for a programmable portable data carrier
- German
- Verfahren und System zur verteilten Erstellung eines Programms für einen programmierbaren, tragbaren Datenträger
Classification
- CPC, 8
- G06F8/41
- G06F21/572
- G06F21/604
- G06F21/606
- G06F21/64
- G06F21/71
- G06F21/79
- G06F2221/2153
- IPC, 11
- G06K19 07
- G06F1 00
- G06F8 41
- G06F9 44
- G06F9 45
- G06F21 57
- G06F21 60
- G06F21 64
- G06F21 71
- G06F21 79
- G06K17 00