Method for generating a random cipher for the cryptographic transmission of data.
Abstract
On the basis of a reciprocal authentication in each case of two subscribers (A, B) in which, with the aid of a secret code (K) and an implemented enciphering algorithm (f), dependent on a random cipher (v1, v2) transmitted in each case from the other subscriber, an authorisation parameter (AP1, AP2) is formed and transmitted for verification purposes to the other subscriber, through logical combination of this authorisation parameter with the old random cipher most recently generated and stored by the subscriber, a new starting value is formed for the dedicated random cipher generator whose new random cipher is both stored and transmitted to the relevant other subscriber. …<IMAGE>…

Term
Term ended
Projected expiry passed 5 March 2010, 16.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
2 claims: 1 independent, 1 dependent
- c-de-00011. A method for generating a random number for the encrypted transmission of data in a working with processor chip cards data exchange system, below using as an input to a random number generator provided, formed by linking with a last stored random number variable start value, characterized, that, starting from a mutual authentication each of two subscribers (A, B), wherein with the aid of a secret key (K) and an implemented ciphering algorithm (f) depending on a the other party transmitted random number (v1, v2), an authorization parameter is (AP1, AP2) formed and transmitted for verification purposes to the other party, by logically combining this authorization parameter with the participants last generated and stored old random number a new start value is formed for its own random number generator, the new random number both stored and on the respective other participants is transmitted.
9 paragraphs, as filed
The invention relates to a method for generating a random number for the encoded transmission of data in accordance with the features of the preamble of claim 1.
In modern data processing and communication systems of data protection plays an increasingly important role. The quality of a system with respect to a sufficient data protection depends crucially on how successfully that the access to the system only authorized persons is possible and vice versa unauthorized persons remain locked with aboluter security. A simple, though not asolut secure way to verify the access authorization to a system, for example, so-called passwords that are only known to the authorized user and which can be as often changed by the user. Since passwords is a risk that they can be spied on or bugged by unauthorized persons, additional safety measures are indispensable. One of these measures is for example the encryption and decryption of the information transmitted, a measure which can be implemented in data processing systems, among other things with the aid of the smart card.
With the increasing integration of the smart card in communication systems on the other hand arises again an additional security risk because chip cards can be lost relatively easily. It must therefore be absolutely ensured that the smart card is protected in case of loss in any case before any abuse. The smart card is so designed, that can only be accessed on the data stored in a secure chip card when users advance a stored only on the smart card identifier, such as a personal identification number, the so-called PIN, entered by Be.
Another safety barrier can be constructed using the authentication of the chip card to the system. This authentication prevents an arbitrary subscriber to be authorized by setting, can get to secret information in the system. An essential prerequisite for the authentication is a personal non-copyable feature of the subscriber. This can not be copied feature the subscriber is achieved by means of a secret key for encryption and decryption of the two partners, that is the one part of the chip card and the other part of the system, and although it is known only these two partners. The safety can be further increased by the fact that in the chip card, including this secret key, a random number is generated, which is transmitted from the smart card to the system. It is conceivable per se to generate these random numbers programmatically. According to security experts random numbers generated in this way are not random enough and ultimately not secure enough.
Therefore, it is already known to increase the "randomness" of a random number in that one makes the generation of random numbers from a variable starting value dependent or even better, by modifying this variable start value with a previously generated random number.
The present invention is an object of the invention to provide a simple and in particular for use in smart cards particularly suitable method for the production of a modified initial value.
The solution of this object, according to the invention by the characterizing features of claim 1.
The inventive method is explained with reference to the accompanying drawings. The starting point of the process is the mutual authentication between two devices A, B according to the so-called "challenge response" method, as shown in FIGS. 1 and 2 Here's a random number, for example, first by the participant B v1 sent to the member A, which encrypts the random number v1 using a key K and a cipher algorithm f and returns the result as authorization parameters AP1 to the subscriber B. Party B performs the same operation and also receives this authorization parameters AP1. By comparing the two authorization parameters may eventually determine the subscriber B whether he actually communicates with the subscriber A. Thus also the subscriber A goes sure that it communicates with the subscriber B, this operation in the opposite direction with the random number and the authorization parameter v2 AP2 is performed (see FIG 2).
This mutually transmitted authorization parameters AP1, AP2 are now, as 3 shows, used advantageously for generating a variable starting value for a new random number. In this example, the f generated at the subscriber A from the transmitted by the subscriber B random number v1, the key K and the cipher authorization parameters AP1 to the one used at the subscriber A in the previous authorization and temporarily stored random number v2 using an exclusive-OR gate XOR for formation of a new start value s interlinked. This modified seed s is used in the subsequent generation of a new random number v2, which in turn is buffered again and transmitted to the subscriber B. Analog runs generating a modified starting value at the subscriber B.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| WO2008022917A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| US9411952B2 | Cited by | United States of America | – | Applicant |
| EP1967423A2 | Cited by | European Patent Office (EPO) | – | Search report |
| EP0683293A1 | Cited by | European Patent Office (EPO) | – | Search report |
| EP0552392A1 | Cited by | European Patent Office (EPO) | – | Search report |
| DE4445615A1 | Cited by | Germany | – | Search report |
| EP1967423A3 | Cited by | European Patent Office (EPO) | – | Search report |
| EP0250309A1 | Cites | European Patent Office (EPO) | A | Search report |
| EP0281057A2 | Cites | European Patent Office (EPO) | A | Search report |
| GB2144546A | Cites | United Kingdom | A | Search report |
6 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 3907527 | Germany | A | |
| 3907527 | Germany | – | |
| DE19893907527 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| EP0388700A1This record | European Patent Office (EPO) | A1 | |
| US5148007A | United States of America | A | |
| EP0388700B1 | European Patent Office (EPO) | B1 | |
| AT99096T | Austria | T | |
| DE59003920D1 | Germany | D1 | |
| ES2047731T3 | Spain | T3 |
46 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Nl: lapsed or anulled due to non-payment of the annual feeLapsedNLV4 | NLV4 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Se: european patent has lapsedLapsedEUG | EUG | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Se: european patent in force in swedenEAL | EAL | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Fr: translation filedET | ET | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| Corresponds to:REF | REF | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0388700
- Publication, DOCDB
- 0388700
- Publication, EPODOC
- EP0388700
- Application
- 104208
- Application, DOCDB
- 90104208
- Application, EPODOC
- EP19900104208
Titles3
- German
- Verfahren zur Generierung einer Zufallszahl für die verschlüsselte Übertragung von Daten.
- English
- Method for generating a random cipher for the cryptographic transmission of data.
- French
- Procédé pour générer un chiffre aléatoire pour la transmission cryptographique de données.
Classification
- CPC, 2
- G07F7/1016
- H04L9/3273
- IPC, 3
- G07F7 10
- H04L9 12
- H04L9 32
Designated states11
- Contracting states, 11
- Austria
- Belgium
- Switzerland
- Germany
- Spain
- France
- United Kingdom
- Italy
- Liechtenstein
- Netherlands (Kingdom of the)
- Sweden