Data exchange system with a plurality of user terminals, each including an IC card reader.
Abstract
A secret key (Ki) identical for all user terminals is formed from two part components (KTi, KT'i), one (KTi) of which is filed in an erasable programmable read-only memory (EEPROM). For the second part component (KT'i), a coded data block (E-KT'i)) is transmitted from outside to a decoding device (DEC) which is provided in the security module and the decoded output signal of which is stored as a second part component (KT'i) in a first part region of a read-write memory (RAM) present in the security module of the user terminal. A secret key (Ki) is calculated from the two part components (KTi, KT'i), and the result is stored in the second part region of the read-write memory (RAM). …<IMAGE>…

Term
Term ended
Projected expiry passed 29 February 2008, 18.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
3 claims: 1 independent, 2 dependent
- c-de-00011. Data exchange system having a plurality of, in each case a chip card reading device containing user terminals, in which in a security module and for all user terminals of the same secret key is stored, characterized, that the secret key (Ki) of two sub-components (KTi, KT'i) is formed, one of which (KTi) in an erasable programmable read only memory (EEPROM) is stored, that for the second Teilkomponete (KT'i) an encrypted data block (E (KT'i )) is transmitted from the outside to a designated in the security module decoder (DEC), the decrypted output signal as the second subcomponent (KT'i) in a first portion of a present in the security module random access memory (RAM) will be saved and that the two subcomponents (KT , KT'i) linked together, and the result as a total key (Ki) in a second partial area of the write-read memory (RAM) is stored.
9 paragraphs, as filed
The invention relates to a data exchange system according to the features of the preamble of claim 1.
In modern data processing and communication systems of data protection plays an increasingly important role. The quality of a system with respect to a sufficient data protection depends crucially on how successfully that the access to the system only authorized persons is possible and vice versa unauthorized persons remain locked out with absolute certainty. A simple though not absolutely reliable way to verify the access authorization for a system are, for example, so-called passwords which are known only to the authorized user and which can be as often changed by the user. Since passwords is a risk that they can be spied on or bugged by unauthorized persons, additional safety measures are indispensable. One of these measures is for example the encryption and decryption of the information transmitted, a measure which can be implemented at Datenverarbeitungssysemen inter alia with the aid of the smart card. With the increasing involvement of the chip card in data processing systems on the other hand arises again an additional security risk because chip cards can be lost relatively easily. It must therefore be absolutely ensured that the smart card is protected in case of loss in any case before any abuse. The smart card is so designed, that can only be accessed on the data stored in a secure chip card when the user in advance a stored only on the smart card identifier, such as a personal identification number, the so called PIN is entered.
Another safety barrier can be constructed using the authentication of the chip card to the system. This authentication prevents an arbitrary subscriber to be authorized by setting, can get to secret information in the system. An essential prerequisite for the authentication is a personal non-copyable feature of the subscriber. This nichtkopierbare feature the subscriber is achieved by means of a secret key for encryption and decryption of the two partners, that is the one part of the chip card and the other part of the system, and although it is known only these two partners.
In a POS banking system on chip card base is, for example, assumed that secret data to the POS terminal are stored in a separate security module, for example in a so-called security chip card. When using a symmetric encryption algorithm must exist in all the terminals of the same secret key terminal. This key is required to calculate from the card identification number of a customer card a common communication key. However, the existence of a universal secret key in the security module or in the secure chip card each POS terminal of an overall system is an extremely critical point and in a sense the vulnerability of the system. There are therefore already several safeguards have been considered, making it difficult to become aware of a secret global key. According to a first protective measure there instead of a single secret key K Global, a series of n different Global keys Kl, ..., Kn, and accordingly unterschiedeliche terminal types. In a possible aware of these key thus not the entire system is at risk. However, a customer card must also contain n different keys KKL ... KKn, of which at a particular terminal, only one single valid. In a second protective measure several key Kl, ..., Kn are also provided, which are changed n certain intervals cyclically. In this way, for example, several terminal key Klp, ..., Knp that are p valid in the time phase result. In a customer smart card, the corresponding customer key KKlp, ..., KKnp must then of course be present.
The present invention is based on the object to be found for securing a global Geheimschlssels offer the best possible approach that makes the scrutinizing of the applicable Global key practically impossible.
The solution of this object, according to the invention by the characterizing features of claim 1. Advantageous developments of the invention are indicated in the dependent claims. By splitting the secret key in two subcomponents, one subcomponent is variable, resulting in regular formation correspondingly different new secret key, so that even in case of scrutinizing a key this out researched key very soon is out of date and thus become unusable.
An embodiment of the invention is explained below with reference to the drawing. show case<ul><li>1 shows a circuit arrangement for generating a secret key from Global two subcomponents</li><li>with respect to a component part 2 shows a variant of the circuit of Fig. 1</li></ul>
The 1 shows the essential for explaining the invention features a security chip card SK in a user terminal. The whole is based on the idea that a global key for safety first should not be completely stored in the terminal. For this reason, a break of the deposited in the security card secret key Ki Global in two terinalspezifische subcomponents KT and KT'i is provided. The first subcomponent KT stands protected in an erasable programmable read only memory EEPROM, while the second subcomponent KT'i is transferred to the security module of the terminal, that is in the security card SK in daily appointment Alan notification procedure. The latter is done in such a way that an encrypted second subcomponent E (KT'i) is supplied to a decoding stage DEC whose decoded output is stored as a second subcomponent KT'i in a first portion of a read-write memory RAM. From the stored in the read only memory EEPROM first subcomponent KTi and transmitted in the read-write memory RAM second subcomponent KT'i the complete secret key Ki is eventually calculated and the result is stored in a second portion of the read-write memory RAM.
The 2 shows a variant of the circuit of Figure 1, in that the first subcomponent KT a priori is not available in the terminal, but will not be generated as part of the initial commissioning of a POS terminal. For this procedure, a so-called Initialisierungschipkarte IK is required. Does the terminal, for example, with a security card SK, so in this case the personalization an auxiliary key Ko is entered. Using this auxiliary key Ko now a so-called pre-key KT i + Ko is calculated and entered into the Initialisierungschipkarte IK. After mutual authentication between the security card SK and IK Initialisierungschipkarte this pre-key KT i + Co will open pass from Initialisierungschipkarte IK to the security card SK. There + Co and the previously stored auxiliary key Ko is finally the first subcomponent KT calculated and entered in the read-only memory EEPROM of the security card SK from the pre-key KT. Whether carried out in this way generating the first subcomponent of KT Global key is actually executed without errors, can then be checked with a test chip card.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| FR2656126A1 | Cited by | France | Search report |
| EP0588339A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0440800A1 | Cited by | European Patent Office (EPO) | Search report |
| WO9837525A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US5533126A | Cited by | United States of America | Search report |
| EP0434551A1 | Cited by | European Patent Office (EPO) | Search report |
| EP0368596A3 | Cited by | European Patent Office (EPO) | Search report |
| FR2656125A1 | Cited by | France | Search report |
| EP0427465A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0856822A3 | Cited by | European Patent Office (EPO) | Search report |
| WO9109381A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| EP0588339A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0856821A2 | Cited by | European Patent Office (EPO) | Search report |
| FR2641885A1 | Cited by | France | Search report |
| EP0427465A2 | Cited by | European Patent Office (EPO) | Search report |
| WO9109382A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| FR2704341A1 | Cited by | France | Search report |
| EP0434550A1 | Cited by | European Patent Office (EPO) | Search report |
| EP1020821A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0368596A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0434551A1 | Cited by | European Patent Office (EPO) | Search report |
| EP0422230A4 | Cited by | European Patent Office (EPO) | Search report |
| EP0856822A2 | Cited by | European Patent Office (EPO) | Search report |
| US5365466A | Cited by | United States of America | Search report |
| EP0856821A3 | Cited by | European Patent Office (EPO) | Search report |
| EP1022696A1 | Cited by | European Patent Office (EPO) | Search report |
| EP0932124A1 | Cited by | European Patent Office (EPO) | Search report |
| US6651170B1 | Cited by | United States of America | Applicant |
| EP0621569A1 | Cited by | European Patent Office (EPO) | Search report |
| EP1020821A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0422230A1 | Cited by | European Patent Office (EPO) | Search report |
| EP1022696A1 | Cited by | European Patent Office (EPO) | Search report |
| FR2759833A1 | Cited by | France | Search report |
| EP0440800A4 | Cited by | European Patent Office (EPO) | Search report |
| US7181602B1 | Cited by | United States of America | Applicant |
| EP0063794A2 | Cites | European Patent Office (EPO) | Search report |
| EP0140388A2 | Cites | European Patent Office (EPO) | Search report |
| EP0166541B1 | Cites | European Patent Office (EPO) | Search report |
| EP0198384A2 | Cites | European Patent Office (EPO) | Search report |
8 members in 6 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 3706958 | Germany | A | |
| 3706958 | Germany | A | |
| 3706958 | Germany | – | |
| DE19873706958 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP0281059A2This record | European Patent Office (EPO) | A2 | |
| JPS63229545A | Japan | A | |
| EP0281059A3 | European Patent Office (EPO) | A3 | |
| US4951247A | United States of America | A | |
| EP0281059B1 | European Patent Office (EPO) | B1 | |
| AT98034T | Austria | T | |
| DE3885916D1 | Germany | D1 | |
| ES2046222T3 | Spain | T3 |
36 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Nl: decision of oppositionOppositionNLR2 | NLR2 | EP | |
| Patent revokedRevoked27W | 27W | EP | |
| Gb: patent revoked under art. 102 of the ep convention designating the uk as contracting stateRevoked960523GBPR | GBPR | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Patent revokedRevokedORIGINAL CODE: 0009271RDAG | RDAG | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: PATENT REVOKEDSTAA | STAA | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Se: european patent in force in swedenEAL | EAL | EP | |
| Nl: opposition has been filed with the epoOppositionNLR1 | NLR1 | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Opposition filedOppositionORIGINAL CODE: 0009260PLBI | PLBI | EP | |
| Fr: translation filedET | ET | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| Corresponds to:REF | REF | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0281059
- Publication, DOCDB
- 0281059
- Publication, EPODOC
- EP0281059
- Application
- 103014
- Application, DOCDB
- 88103014
- Application, EPODOC
- EP19880103014
Titles6
- German
- Datenaustauschsystem mit mehreren jeweils eine Chipkarten-Leseeinrichtung enthaltenden Benutzerterminals
- English
- Data exchange system with a plurality of user terminals, each including an IC card reader
- French
- Système pour l'échange de données avec plusieurs terminaux d'utilisation comportant chacun un dispositif de lecture de cartes à circuit intégré
- German
- Datenaustauschsystem mit mehreren jeweils eine Chipkarten-Leseeinrichtung enthaltenden Benutzerterminals.
- English
- Data exchange system with a plurality of user terminals, each including an IC card reader.
- French
- Système pour l'échange de données avec plusieurs terminaux d'utilisation comportant chacun un dispositif de lecture de cartes à circuit intégré.
Classification
- CPC, 6
- G07F7/1008
- G06Q20/229
- G06Q20/341
- G06Q20/40975
- G06Q20/3578
- H04L9/0877
- IPC, 9
- G06F12 14
- G06F21 34
- G06F21 60
- G06F21 62
- G06K17 00
- G06K19 10
- G07F7 10
- H04L9 00
- H04L9 18
Designated states11
- Contracting states, 11
- Austria
- Belgium
- Switzerland
- Germany
- Spain
- France
- United Kingdom
- Italy
- Liechtenstein
- Netherlands (Kingdom of the)
- Sweden