Data exchange system with a plurality of user terminals, each including an IC card reader.
3 claims: 1 independent, 2 dependent
- 1Datenaustauschsystem mit mehreren, jeweils eine Chipkarten-Leseeinrichtung enthaltenden Benutzerterminals, bei denen in einem Sicherheitsmodul (Sk) ein für alle Benutzerterminals gleicher Geheimschlüssel (Ki) hinterlegt ist, dadurch gekennzeichnet, daß der Geheimschlüssel (Ki) aus zwei Teilkomponenten (KTi, KTʹi) gebildet ist, von denen die eine (KTi) in einem löschbaren programmierbaren Lesespeicher (EEPROM) hinterlegt ist, daß für die zweite Teilkomponete (KTʹi) ein verschlüsselter Datenblock (E(KTʹi)) von außen an eine im Sicherheitsmodul vorgesehene Decodiereinrichtung (DEC) übertragen wird, deren entschlüsseltes Ausgangssignal als zweite Teilkomponente (KTʹi) in einem ersten Teilbereich eines im Sicherheitsmodul vorhandenen Schreib-Lese-Speichers (RAM) abgespeichert wird und daß die beiden Teilkomponenten (KTi, KTʹi) miteinander verknüpft und das Ergebnis als Gesamtschlüssel (Ki) in einem zweiten Teilbereich des Schreib-Lese-Speichers (RAM) abgespeichert wird.
- 2Datenaustauschsystem nach Anspruch 1, dadurch gekennzeichnet, daß zur Generierung der ersten Teilkomponente (KTi) zunächst ein Hilfsschlüssel (Ko) im Sicherheitsmodul abgespeichert wird, daß aus diesem Hilfsschlüssel (Ko) und der ersten Teilkomponente (KTi) ein Prä-Schlüssel (KTi + Ko) errechnet und in eine Initialisierungskarte (IK) eingetragen wird und daß nach gegenseitiger Authentifizierung zwischen dem Sicherheitsmodul und der Initialisierungskarte (IK) und nach Übertragung des Prä-Schlüssels in das Sicherheitsmodul aus dem Prä-Schlüssel (KTi + Ko) und dem Hilfsschlüssel (Ko) die erste Teilkomponente (KTi) errechnet und im löschbaren programmierbaren Lesespeicher (EEPROM) eingetragen wird.
- 3Dastenaustauschsystem nach Anspruch 1 oder 2, dadurch gekennzeichnet, daß das Sicherheitsmodul als steckbare Sicherheitskarte (SK) ausgebildet ist.
Independent claims3
9 paragraphs, as filed
The invention relates to a data exchange system according to the features of the preamble of claim 1.
p0001In modern data processing and communication systems of data protection plays an increasingly important role. The quality of a system with respect to a sufficient data protection depends crucially on how successfully that the access to the system only authorized persons is possible and vice versa unauthorized persons remain locked out with absolute certainty. A simple though not absolutely reliable way to verify the access authorization for a system are, for example, so-called passwords which are known only to the authorized user and which can be as often changed by the user. Since passwords is a risk that they can be spied on or bugged by unauthorized persons, additional safety measures are indispensable. One of these measures is for example the encryption and decryption of the information transmitted, a measure which can be implemented at Datenverarbeitungssysemen inter alia with the aid of the chip card (for example EP-A-63794). With the increasing involvement of the chip card in data processing systems on the other hand arises again an additional security risk because chip cards can be lost relatively easily. It must therefore be absolutely ensured that the smart card is protected in case of loss in any case before any abuse. The smart card is so designed, that can only be accessed on the data stored in a secure chip card when the user in advance a stored only on the smart card identifier, such as a personal identification number, the so-called PIN is entered.
p0002Another safety barrier can be constructed using the authentication of the chip card to the system. This authentication prevents an arbitrary subscriber to be authorized by setting, can get to secret information in the system. An essential prerequisite for the authentication is a personal non-copyable feature of the subscriber. This nichtkopierbare feature the subscriber is achieved by means of a secret key for encryption and decryption of the two partners, that is the one part of the chip card and the other part of the system, and although it is known only these two partners.
p0003In a POS banking system on chip card base is, for example, assumed that secret data to the POS terminal are stored in a separate security module, for example in a so-called security chip card. When using a symmetric encryption algorithm must exist in all the terminals of the same secret key terminal. This key is required to calculate from the card identification number of a customer card a common communication key. However, the existence of a universal secret key in the security module or in the secure chip card each POS terminal of an overall system is an extremely critical point and in a sense the vulnerability of the system. There are therefore already several safeguards have been considered, making it difficult to become aware of a secret global key. According to a first protective measure there instead of a single secret key K Global, a series of n different Global keys Kl, ..., Kn, and accordingly unterschiedeliche terminal types. In a possible aware of these key thus not the entire system is at risk. However, a customer card must also contain n different keys KKL ... KKn, of which at a particular terminal, only one single valid. In a second protective measure several key Kl, ..., Kn are also provided, which are changed n certain intervals cyclically. In this way, for example, several terminal key Klp, ..., Knp that are p valid in the time phase result. In a customer smart card, the corresponding customer key KKlp, ..., KKnp must then of course be present.
p0004The present invention is based on the object to be found for securing a global Geheimschlssels offer the best possible approach that makes the scrutinizing of the applicable Global key practically impossible.
p0005The solution of this object, according to the invention by the characterizing features of claim 1. Advantageous developments of the invention are indicated in the dependent claims. By splitting the secret key in two subcomponents, one subcomponent is variable, resulting in regular formation correspondingly different new secret key, so that even in case of scrutinizing a key this out researched key very soon is out of date and thus become unusable.
p0006An embodiment of the invention is explained below with reference to the drawing. show case<dl id="dl0001"><dt>1 shows</dt><dd>a circuit for generating a secret key from Global two subcomponents</dd><dt>FIG 2</dt><dd>a variant of the circuit of FIG 1 with respect to a subcomponent.</dd></dl>
p0007The 1 shows the essential for explaining the invention features a security chip card SK in a user terminal. The whole is based on the idea that a global key for safety first should not be completely stored in the terminal. For this reason, a break of the deposited in the security card secret key Ki Global in two terminal-specific subcomponents KT and KT'i is provided. The first subcomponent KT stands protected in an erasable programmable read only memory EEPROM, while the second subcomponent KT'i is transferred to the security module of the terminal, that is in the security card SK in daily appointment Alan notification procedure. The latter is done in such a way that an encrypted second subcomponent E (KT'i) is supplied to a decoding stage DEC whose decoded output is stored as a second subcomponent KT'i in a first portion of a read-write memory RAM. From the stored in the read only memory EEPROM first subcomponent KTi and transmitted in the read-write memory RAM second subcomponent KT'i the complete secret key Ki is eventually calculated and the result is stored in a second portion of the read-write memory RAM.
p0008The 2 shows a variant of the circuit of Figure 1, in that the first subcomponent KT a priori is not available in the terminal, but will not be generated as part of the initial commissioning of a POS terminal. For this procedure, a so-called Initialisierungschipkarte IK is required. Does the terminal, for example, with a security card SK, so in this case the personalization an auxiliary key Ko is entered. Using this auxiliary key Ko now a so-called pre-key KT i + Ko is calculated and entered into the Initialisierungschipkarte IK. After mutual authentication between the security card SK and IK Initialisierungschipkarte this pre-key KT i + Co will open pass from Initialisierungschipkarte IK to the security card SK. There + Co and the previously stored auxiliary key Ko is finally the first subcomponent KT calculated and entered in the read-only memory EEPROM of the security card SK from the pre-key KT. Whether carried out in this way generating the first subcomponent of KT Global key is actually executed without errors, can then be checked with a test chip card.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP0063794A | Cites | European Patent Office (EPO) |
| EP0140388A | Cites | European Patent Office (EPO) |
| EP0166541A | Cites | European Patent Office (EPO) |
| EP0198384A | Cites | European Patent Office (EPO) |
8 members in 6 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 3706958 | Germany | A | |
| 3706958 | Germany | A | |
| 3706958 | Germany | – | |
| 3706958 | – | – | – |
| DE19873706958 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP0281059A2 | European Patent Office (EPO) | A2 | |
| JPS63229545A | Japan | A | |
| EP0281059A3 | European Patent Office (EPO) | A3 | |
| US4951247A | United States of America | A | |
| EP0281059B1This record | European Patent Office (EPO) | B1 | |
| AT98034T | Austria | T | |
| DE3885916D1 | Germany | D1 | |
| ES2046222T3 | Spain | T3 |
36 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Nl: decision of oppositionOppositionNLR2 | NLR2 | EP | |
| Patent revokedRevoked27W | 27W | EP | |
| Gb: patent revoked under art. 102 of the ep convention designating the uk as contracting stateRevoked960523GBPR | GBPR | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Patent revokedRevokedORIGINAL CODE: 0009271RDAG | RDAG | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: PATENT REVOKEDSTAA | STAA | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Se: european patent in force in swedenEAL | EAL | EP | |
| Nl: opposition has been filed with the epoOppositionNLR1 | NLR1 | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Opposition filedOppositionORIGINAL CODE: 0009260PLBI | PLBI | EP | |
| Fr: translation filedET | ET | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| Corresponds to:REF | REF | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0281059
- Publication, DOCDB
- 0281059
- Publication, EPODOC
- EP0281059
- Application
- 88103014
- Application, DOCDB
- 88103014
- Application, EPODOC
- EP19880103014
Titles3
- German
- Datenaustauschsystem mit mehreren jeweils eine Chipkarten-Leseeinrichtung enthaltenden Benutzerterminals
- English
- Data exchange system with a plurality of user terminals, each including an IC card reader
- French
- Système pour l'échange de données avec plusieurs terminaux d'utilisation comportant chacun un dispositif de lecture de cartes à circuit intégré
Classification
- CPC, 5
- G07F7/1008
- G06Q20/341
- G06Q20/40975
- H04L9/0877
- G06Q20/229
- IPC, 9
- G06F21 34
- G06F21 60
- G06F12 14
- G06F21 62
- G06K17 00
- G06K19 10
- G07F7 10
- H04L9 00
- H04L9 18
Designated states1
- Contracting states, 1
- Sweden
