Method for enhancing franking machines security.
Abstract
The method includes applying for an authorised opening of a franking machine for the purpose of an inspection, an opening application being made after entry into the communication mode (300) at a remote data centre and, in response to the opening application made, a new code word Y' being sent from the data centre to the franking machine which, if it is lacking (step 207), sets the franking machine to a first mode (208) and thus effectively disables it. The franking machine can enter a second mode (steps 203-206) by means of a decision criterion (step 202) in the system routine (200) in order to output a warning and request for communication with the data centre to the user of the franking machine. The data centre monitors the behaviour of the user of the franking machine on the basis of data transmitted during the communication.

Term
Term ended
Projected expiry passed 9 September 2014, 12 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
74 claims: 40 independent, 34 dependent
- 1Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen gegen Manipulation mit einem Mikroprozessor in einer Steuereinheit der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch ein Unterscheiden zwischen autorisiertem Öffnen (Service, Inspektion) und unautorisiertem Öffnen (Manipulationsabsicht) mittels der Steuereinheit der Frankiermaschine in Verbindung mit den von der Datenzentrale übermittelten Daten und einem über einen Sensor (21) detektierten Signal.
- 2Verfahren nach Anspruch 1, gekennzeichnet durch die Schritte:a) Anmelden einer autorisierten Öffnung der Frankiermaschine zum Zwecke einer Inspektion, wobei nach Eintritt in den Kommunikationsmodus (300) bei einer entfernten Datenzentrale ein Öffnungsgesuch gestellt wird und b) Übermitteln eines neuen Codewort Y' zur Frankiermaschine von der Datenzentrale, in Erwiderung auf das gestellte Öffnungsgesuch, c) Überführen der Frankiermaschine in den ersten Modus, um sie damit wirksam außer Betrieb zu setzen, wenn bei Ausführung eines Schrittes (210) das richtige Codewort fehlt, weil die Frankiermaschine geöffnet wurde.
- 3Verfahren nach den Ansprüchen 1 bis 2, dadurch gekennzeichnet , - daß in dem Schritt (210), um in einen ersten Modus einzutreten, wenn die Frankiermaschine geöffnet wird, das Codewort Y gelöscht wird, - daß nach der Initialisierung (101) der Frankiermaschine ein vorhandenes neues Codewort Y' als Codewort Y weiterverwendet wird und nachfolgend, während des Betriebes der Frankiermaschine laufend in einem Schritt (207) zur Überprüfung das Vorhandenseins des gültigen Codewortes Y abgefragt wird, - daß für den Fall, daß kein neues gültiges Codewort Y' übermittelt wurde, im Schritt (207) das Fehlen eines gültigen Codewortes Y festgestellt wird, die Schritte zum Verhindern des Frankierens bzw. Sperrens der Frankiermaschine (208) und/oder Schritte im Statistik- und Fehlerauswertungsmodus (213) und Anzeigemodus (215) durchlaufen werden, um die Aufrechterhaltung, Auswertung und Anzeige des vorgenannten ersten Modus zu sichern und um anschließend wieder zum Beginnpunkt s der Systemroutine (200) zurückzuverzweigen.
- 4Verfahren nach den Ansprüchen 1 bis 3, dadurch gekennzeichnet, daß während der Kommunikation Transaktionen mit verschlüsselten Meldungen durchgeführt werden, um ein neues Codewort Y' und/oder weitere aktuelle Daten in die Frankiermaschine zu laden.
- 5Verfahren, nach Anspruch 4, dadurch gekennzeichnet , daß eine während der Kommunikation mit verschlüsselten Meldungen durchgeführte Transaktion einen Guthabennachladewert umfaßt.
- 6Verfahren nach den Ansprüchen 4 bis 5, dadurch gekennzeichnet, daß eine während der Kommunikation mit verschlüsselten Meldungen durchgeführte Transaktion einen Vorgabewert für einen Guthabennachladewert umfaßt, welcher der entfernten Datenzentrale übermittelt wird.
- 7Verfahren nach Anspruch 4, dadurch gekennzeichnet, daß während der Kommunikation mit einer unverschlüsselten Meldung eine Transaktion durchgeführt wird, um eine neue Telefonnummer zur Verbindungsaufnahme mit der Datenzentrale in die Frankiermaschine zu laden.
- 8Verfahren nach einem der vorgenannten Ansprüche 1 bis 7, dadurch gekennzeichnet , daß die Transaktionsdaten einzeln und seriell übertragen und durch einen MESSAGE AUTHENTIFICATION CODE (MAC) gesichert werden.
- 9Verfahren nach den Ansprüchen 1 bis 3, dadurch gekennzeichnet , daß, um in einen ersten Modus einzutreten, wenn die Frankiermaschine geöffnet wird, in dem Schritt (210) das Codewort Y gelöscht wird, indem mittels des Sensors (21), der an die Detektoreinrichtung (20) gekoppelt ist, direkt oder indirekt eine Verbindung unterbrochen wird, welche direkt und/oder indirekt über den Verlust einer weiteren Information zum Verlust des Codewortes Y führt, ohne die die Frankiermaschine nicht zum Frankieren betrieben werden kann.
- 10Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen mit einem Mikroprozessor in einer Steuereinrichtung der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch a) Anmelden einer autorisierten Öffnung der Frankiermaschine zum Zwecke einer Inspektion, wobei nach Eintritt in den Kommunikationsmodus (300) bei einer entfernten Datenzentrale ein Öffnungsgesuch gestellt wird und b) Übermitteln eines neuen Codewort Y' zur Frankiermaschine von der Datenzentrale, in Erwiderung auf das gestellte Öffnungsgesuch, c) Überführen der Frankiermaschine in den ersten Modus, um sie damit wirksam außer Betrieb setzen, wenn bei Ausführung eines Schrittes (210) das richtige Codewort fehlt, weil die Frankiermaschine geöffnet wurde, umfassend die Schritte:- Löschen des Codewortes Y, wenn die Frankiermaschine geöffnet wird, - Weiterverwenden eines vorhandenen neuen Codewortes Y' als Codewort Y nach der Initialisierung (101) und - laufende Abfrage eines Schrittes (207) zur Überprüfung des Vorhandenseins des gültigen Codewortes Y, während des Betriebes der Frankiermaschine, - Feststellen des Fehlens eines gültigen Codewortes Y im Schritt (207) für den Fall, daß kein neues gültiges Codewort Y' übermittelt wurde, und Schritte zum Verhindern des Frankierens bzw. Sperrens der Frankiermaschine (208) und/oder Schritte im Statistik- und Fehlerauswertungsmodus (213) und Anzeigemodus (215), welche durchlaufen werden, um die Aufrechterhaltung, Auswertung und Anzeige des vorgenannten ersten Modus zu sichern und um anschließend wieder zum Beginnpunkt s der Systemroutine (200) zurückzuverzweigen. d) Überführung der Frankiermaschine in einen zweiten Modus, wenn ein spezifisches Kriterium erfüllt ist, durch Schritte (201 bis 206), die nach dem Beginnpunkt s der Systemroutine (200) und vor dem Punkt t vor dem Schritt (207) ablaufen, umfassend: - einen Schritt (201) zum Aufruf aktueller Daten - einen Schritt (202) zur Überprüfung der Daten mittels eines Entscheidungskriteriums und Eintritt bei Erfüllung des Kriteriums in den zweiten Modus (Schritte 203-206), um an den Benutzer der Frankiermaschine eine Warnung und Aufforderung zur Kommunikation mit der Datenzentrale abzugeben.
- 11Verfahren nach Anspruch 10, dadurch gekennzeichnet, daß während der Kommunikation Transaktionen mit verschlüsselten Meldungen durchgeführt werden, um ein neues Codewort Y' und/oder weitere aktuelle Daten in die Frankiermaschine zu laden.
- 12Verfahren nach den Ansprüchen 10 bis 11, dadurch gekennzeichnet , daß die während der Kommunikation mit verschlüsselten Meldungen durchgeführte Transaktion einen Guthabennachladewert umfaßt.
- 13Verfahren nach den Ansprüchen 10 bis 12, dadurch gekennzeichnet, daß eine während der Kommunikation mit verschlüsselten Meldungen durchgeführte Transaktion einen Vorgabewert für einen Guthabennachladewert umfaßt, welcher der entfernten Datenzentrale übermittelt wird.
- 14Verfahren nach Anspruch 11, dadurch gekennzeichnet, daß während der Kommunikation mit einer unverschlüsselten Meldung eine Transaktion durchgeführt wird, um eine neue Telefonnummer zur Verbindungsaufnahme mit der Datenzentrale in die Frankiermaschine zu laden.
- 15Verfahren nach den Ansprüchen 10 bis 11, dadurch gekennzeichnet , daß eine während der Kommunikation mit verschlüsselten Meldungen durchgeführte Transaktion eine spezifische Stückzahl S' für einen Sleeping-Mode umfaßt.
- 16Verfahren nach den Ansprüchen 10 bis 11, dadurch gekennzeichnet, daß eine Kommunikation mit unverschlüsselten oder verschlüsselten Meldungen vorgenommen wird, daß im Schritt (213), eine Berechnung der spezifischen Stückzahl S' vorgenommen wird und nach Anzeige (215) und Rückkehr zum Beginnpunkt s der Systemroutine (200) die spezifische Stückzahl S' als Stückzahl S in dem Schritt (201) zum Aufruf aktueller Daten zugeführt wird.
- 17Verfahren nach Anspruch 16, dadurch gekennzeichnet , daß die Berechnung der erreichbaren spezifischen Stückzahl S', parallel in der Frankiermaschine und in der Datenzentrale nach der gleichen Methode vorgenommen wird.
- 18Verfahren nach einem der vorgenannten Ansprüche 10 bis 17, dadurch gekennzeichnet , daß die Transaktionsdaten einzeln und seriell übertragen und durch einen MESSAGE AUTHENTIFICATION CODE (MAC) gesichert werden.
- 19Verfahren nach einem der vorgenannten Ansprüche 10 bis 18, dadurch gekennzeichnet , daß der bei Erfüllung des Kriteriums, welches im Schritt (202) abgefragt wird, daß der für den zweiten Modus folgende Schritt (203) eine Warnung umfaßt, welche für die Zeitdauer t n sichtbar ist und eine Frankier-Verzögerung (Alert-Modus) bewirkt.
- 20Verfahren nach Anspruch 19, dadurch gekennzeichnet , daß im zweiten Modus eine Frankier-Verzögerung um die Zeitdauer t n schrittweise steigend wirksam wird, wobei zur Inkrementierung der Zeitdauer t n und zur Dekrementierung einer Vergleichsstückzahl S ref um eine vorbestimmte Stückzahl n ein nachfolgender Schritt (204) vorgesehen ist, daß beim folgenden Durchlauf durch die Systemroutine (200) die laufend bei jeder Frankierung dekrementierte Stückzahl S und die dekrementierten Vergleichsstückzahl S ref im Schritt (201) als aktuelle Daten aufgerufen und anschließend im Schritt (202) miteinander verglichen werden, daß bei Erfüllung des Kriteriums, indem die Stückzahl S die Vergleichsstückzahl S ref unterschreitet, der Schritt (203) der Warnung erneut, aber mit einer um die Zeitdauer t k verlängerten Zeitdauer durchlaufen wird und daß anschließend und bei Nichterfüllung des vorgenannten Kriteriums der Schritt (207) zur Überprüfung des Vorhandenseins des gültigen Codewortes Y erreicht wird.
- 21Verfahren nach einem der vorgenannten Ansprüche 10 bis 18, dadurch gekennzeichnet , daß der bei Erfüllung des Kriteriums (202) für den zweiten Modus folgende Schritt (203) eine Warnung umfaßt, welche für die Zeitdauer t n sichtbar ist und im nachfolgenden Schritt (204) eine neue Vergleichsstückzahl gebildet wird, indem die maximale Stückzahl S max durch eine vorbestimmte Zahl m dividiert wird.
- 22Verfahren nach den Ansprüchen 15 oder 21, dadurch gekennzeichnet , daß die im Schritt (201) aufgerufenen aktuellen Daten unmittelbar nach einer Kommunikation die berechnete bzw. übermittelte spezifische Stückzahl S' als Stückzahl S und die maximale Stückzahl S max umfassen, daß die Vergleichsstückzahl S ref der durch die Zahl k dividierten berechneten bzw. übermittelten maximalen Stückzahl S max entspricht.
- 23Verfahren nach den Ansprüchen 10, 11, 19 und 20 oder 10, 11, 21 und 22, dadurch gekennzeichnet , daß ein auf den Schritt (204) nachfolgender Schritt (205) vorgesehen ist, um festzustellen, daß die Stückzahl S größer als Null ist, um zum Schritt (207) zur Überprüfung des Vorhandenseins des gültigen Codewortes Y zu verzweigen und daß anderenfalls ein Schritt (206) zum Setzen eines FLAG's für ein Kommunikationsersuchen der Frankiermaschine erreicht wird.
- 24Verfahren nach Anspruch 23, dadurch gekennzeichnet , daß der Schritt (203) für die Anzeige einer Warnung und/oder Schritt (206) für das Setzen eines FLAG's für ein Kommunikationsersuchen zusätzlich einen Subschritt zur Fehlerstatistik umfaßt sowie daß das FLAG zurückgesetzt wird, indem eine Kommunikation erfolgt.
- 25Verfahren nach einem der vorhergenannten Ansprüche 15 bis 24, dadurch gekennzeichnet , daß die Stückzahl S' aus der Durchschnittstückzahl S o , der eine spezifische Dispositionsstückzahl S x hinzuaddiert wird, ermittelt wird, wobei gilt:S' = S o + S x (2) wobei der abgefragte Registerwert R 2alt dem Ascending-Register und R 2neu , gemäß einem Vorgabewunsch, dem zukünftigen Wert des Ascending-Registers sowie R 4alt bzw. R 8alt der Anzahl gültiger Drucke bzw. der Anzahl aller Drucke entsprechen.
- 26Verfahren nach einem der vorhergenannten Ansprüche 15 bis 25, dadurch gekennzeichnet , daß die spezifische Dispositionsstückzahl S x ermittelt wird aus der Formel:S x = α x * R 8alt * R 1alt /R 2alt (5) bzw. S x = α x * R 4alt * R 1alt /R 2alt (6) wobei α x die Einstufung des Frankiermaschinen-Nutzers als A-, B- oder C-Kunden kennzeichnet und die abgefragten Registerwerte R 1alt dem Descending-Register und R 2alt dem Ascending-Register sowie R 4alt bzw. R 8alt der Anzahl gültiger Drucke bzw. der Anzahl aller Drucke entsprechen.
- 27Verfahren nach einem der vorhergenannten Ansprüche 15 bis 26, dadurch gekennzeichnet , daß ein spezieller Sleepingmodezähler bei jeder Kommunikation mit der Datenzentrale auf eine errechnete spezifische Stückzahl gesetzt wird und bei jeder Frankierung, d.h. im Verlauf einer Abrechnungs- und Druckroutine (406), zur Weiterzählung veranlaßt wird, bis die Stückzahl Null erreicht wird.
- 28Verfahren nach Anspruch 10, gekennzeichnet durch den Schritt c) mit einer Überprüfung bezüglich, ob ein gültiger Code Y im vorbestimmten Speicherplatz vorliegt, wobei die Überprüfung auf gültigen Code Y mittels einem ausgewählten Prüfsummenverfahren innerhalb eines OTP-Prozessors (ONE TIME PROGRAMMABLE) durchgeführt wird, der intern die entsprechenden Programmteile und MAC (MESSAGE AUTHENTIFICATION CODE) gespeichert enthält.
- 29Verfahren nach Anspruch 28, dadurch gekennzeichnet , daß weitere sicherheitsrelevante Schlüsseldaten und Abläufe im Inneren des OTP-Prozessors gespeichert sind, um eine MAC-Absicherung über die Postregister zu legen.
- 30Verfahren nach Anspruch 10, gekennzeichnet durch den Schritt c) mit einer Überprüfung bezüglich, ob ein gültiger Code Y im vorbestimmten Speicherplatz vorliegt, wobei die Überprüfung auf gültigen Code Y mittels einem ausgewählten Prüfsummenverfahren unter Verwendung eines kodierten Schlüssels durchgeführt wird, der in unterschiedlichen Speicherbereichen partiell abgelegt ist.
- 31Verfahren nach einem der vorhergenannten Ansprüche 28 bis 30, dadurch gekennzeichnet , daß das Sperren der Frankiermaschine erfolgt, indem die Verzweigung auf den Frankiermodus (400) nicht mehr ausgeführt wird.
- 32Verfahren nach einem der vorhergenannten Ansprüche 28 bis 31, dadurch gekennzeichnet , daß im Schritt (208), wo der Killmode erreicht und die Frankiermaschine gesperrt ist, die Postregister in vorbestimmter Weise teilweise gelöscht werden, danach über den Schritt (213) für einen Statistik- und Fehler-Auswertungsmodus der Anzeigemodus (215) erreicht und dann zur Systemroutine zurückverzweigt wird.
- 33Verfahren nach Anspruch 32, dadurch gekennzeichnet , daß wie an das gespeicherte Codewort Y auch an jede Information in den sicherheitsrelevanten Postregistern MAC angehängt werden, eine Manipulation der Registerdaten durch Kontrolle über den MAC erkannt wird, wobei diese Routine im Rahmen einer Abrechnungs- und Druckroutine (406) im Frankiermodus (400) erfolgt.
- 34Verfahren nach einem der vorhergenannten Ansprüche 32 bis 33, dadurch gekennzeichnet , daß Postregisterstände redundant gespeichert vorliegen und zur Realisierung des Kill-Modus beim teilweisen Löschen der Postregisterstände zielgerichtet in vorbestimmter Weise die Redundanz verringert wird, wobei die dieses Verringern der Redundanz von anderen Datenfehlern, die von der Frankiermaschine selbsttätig behoben werden können, dadurch unterscheidet, daß dieser Fehlertyp von der Frankiermaschine nicht selbsttätig behoben werden kann, weil alle redundant gespeicherten Daten nun unterschiedliche Fehler haben, welche nicht mehr automatisch korrigiert werden können.
- 35Verfahren nach einem der vorhergenannten Ansprüche 32 bis 34, dadurch gekennzeichnet , daß durch MAC-Absicherung die Schwierigkeit der Manipulation an den Postregistern maximal erhöht ist und die im Killmode verringerte Redundanz erlaubt, die Registerstände zu rekonstruieren, wobei nur eine eingeweihte Person (Servicetechniker) die Daten nach einer vorbestimmten Weise rekonstruieren kann, was ebenfalls nach jedem autorisiertem Öffnen vor erneuter Inbetriebnahme der Frankiermaschine zu geschehen hat.
- 36Verfahren nach Anspruch 10, gekennzeichnet durch Schritte zum Überwachen der Transportgeschwindigkeit der Poststücke bzw. der Druckgeschwindigkeit insbesondere Bandgeschwindigkeit bei einem Thermotransferdrucker, damit der Druckkopf nicht benutzt werden kann, um einen unabgerechneten Frankierstempel zu erzeugen.
- 37Verfahren nach Anspruch 36, dadurch gekennzeichnet , daß bei einem Thermotransferdrucker die Bandgeschwindigkeit des Farbbandes, welche bereits über einen Encoder gemessen wird, ausgewertet wird, wobei die Encoderimpulse innerhalb eines Zeitfensters gezählt werden, welches vom Uhren/Datums-Baustein (8) geliefert oder aus dem Systemtakt der Steuereinrichtung (6) abgeleitet wird, wobei der Systemtakt mittels eines quarzgesteuerten Taktgebers erzeugt und der Motor 12 entsprechend nachgesteuert wird, wenn die Anzahl an Encoder-Impulsen von einer Sollanzahl abweicht.
- 38Verfahren nach einem der vorhergenannten Ansprüche 36 und 37, dadurch gekennzeichnet , daß ein Fehler festgestellt wird, wenn die Soll/Ist-Abweichung über ein zulässiges Maß hinaus angestiegen ist, daß der Fehler protokolliert wird und gegebenenfalls zum Außerbetriebsetzen der Frankiermaschine führt.
- 39Verfahren nach einem der vorhergenannten Ansprüche 36 bis 38, dadurch gekennzeichnet , daß im Schritt (202) zur Überprüfung des Kriteriums festgestellt wird, ob die Druckgeschwindigkeit eingehalten wird bzw. ob diese vom zulässigen Wert abweicht, daß im Falle daß dieses Kriterium erfüllt ist, eine entsprechende Warnung in der Anzeige erscheint, welche bei Nichtbeachtung letztlich zur Blockierung der Frankiermaschine führt.
- 40Verfahren nach einem der vorhergenannten Ansprüche 10 und 36, dadurch gekennzeichnet , daß die Steuereinheit der Frankiermaschine den Zeitablauf beim spaltenweisen Druck, durch Vergleich der Zeitdauer für den Druck der einzelnen Spalten, in welchen variable Daten vorkommen, überprüft, wobei die Anzahl von Taktimpulsen des quarzgesteuerten Taktgebers zwischen den einzelnen Encoderimpulsen gezählt werden und daß nach dem Schritt (207) zur Überprüfung des Kriteriums, ob der Zeitablauf eingehalten wurde bzw. ob er vom zulässigen Zeitablauf abweicht ein weiterer Schritt (208) für eine Maßnahme zur Blockierung der Frankiermaschine erfolgt, wenn das Kriterium erfüllt ist.
- 41Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen mit einem Mikroprozessor in einer Steuereinrichtung der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit automatisch in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten, wobei die Datenzentrale die Registerstände prüft und die Frankiermaschine nachlädt, wenn die Registerstände nicht bemängelt werden, oder am weiteren Betrieb hindert sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch a) Feststellen der Nichterfüllung eines gültigen Kriteriums im Schritt (207) bezogen auf vorbestimmte interne Frankiermaschinenabläufe während des Betriebes der Frankiermaschine für einen ersten Modus, und Schritte zum Verhindern des Frankierens bzw. zum Sperren der Frankiermaschine (208) und/oder Schritte im Statistik- und Fehlerauswertungsmodus (213) und Anzeigemodus (215), welche durchlaufen werden, um die Aufrechterhaltung, Auswertung und Anzeige des vorgenannten ersten Modus zu sichern und um anschließend wieder zum Beginnpunkt s der Systemroutine (200) zurückzuverzweigen. b) Überführung der Frankiermaschine in einen zweiten Modus, wenn ein spezifisches Kriterium erfüllt ist, durch Schritte (201 bis 206), die nach dem Beginnpunkt s der Systemroutine (200) und vor dem Punkt t vor dem Schritt (207) ablaufen, umfassend:- einen Schritt (201) zum Aufruf aktueller Daten - einen Schritt (202) zur Überprüfung der Daten mittels eines Entscheidungskriteriums und Eintritt bei Erfüllung des Kriteriums in den zweiten Modus (Schritte 203-206), um an den Benutzer der Frankiermaschine mindestens eine Warnung und Aufforderung zur Kommunikation mit der Datenzentrale abzugeben.
- 42Verfahren nach Anspruch 41, dadurch gekennzeichnet , daß die im Schritt (201) aufgerufenen aktuellen Daten unmittelbar nach einer Kommunikation eine berechnete bzw. übermittelte spezifische Stückzahl S' als Stückzahl S und eine maximale Stückzahl S max umfassen, daß die Vergleichsstückzahl S ref für ein erstes Stückzahlkriterium der durch die Zahl k dividierten berechneten bzw. übermittelten maximalen Stückzahl S max entspricht, daß bei Erfüllung des im Schritt (202) abgefragten ersten Stückzahlkriteriums für den zweiten Modus der folgende Schritt (203) eine ständige Warnung für ein bevorstehendes Schlafenlegen der Frankiermaschinenfunktion bzw. eine Aufforderung zur erneuten Kommunikation mit der Datenzentrale umfaßt, bevor Schritt (205) zur Überprüfung der Daten mittels eines weiteren Stückzahlkriteriums erreicht wird, daß bei Nichterfüllung des weiteren Stückzahlkriteriums ein Schritt (206) zum automatischen Kommunikationsersuchen der Frankiermaschine erreicht wird, daß während einer Kommunikation mit der Datenzentrale Transaktionsdaten einzeln und seriell übertragen werden und mindestens ein durch einen MAC abgesichertes Entscheidungskriterium umfassen, wodurch das automatische Kommunikationsersuchen aufgehoben wird, falls die Transaktion erfolgreich durchgeführt wurde.
- 43Verfahren nach Anspruch 41, dadurch gekennzeichnet , daß während einer Routine im Frankiermodus (400) ein Schritt (410) zur Abfrage des Erreichens eines weiteren Stückzahlkriteriums für die verbleibende Stückzahl S vorgesehen ist und bei Erreichen des weiteren Stückzahlkriteriums automatisch zum Kommunikationsmodus (300) verzweigt wird.
- 44Verfahren nach den Ansprüchen 41 bis 43, dadurch gekennzeichnet , daß der Schritt (203) einen Subschritt zur Fehlerstatistik entsprechend dem Statistik- und Fehlerauswertungsmodus (213) und der Schritt (205) zur Abfrage des Erreichens eines weiteren Stückzahlkriteriums durch die verbleibende Stückzahl S während der Systemroutine (200) oder der Schritt (410) zur Abfrage des Erreichens eines weiteren Stückzahlkriteriums durch die verbleibende Stückzahl S während einer Routine im Frankiermodus (400) als Entscheidungskriterium die Stückzahl Null umfaßt.
- 45Verfahren nach Anspruch 41, dadurch gekennzeichnet , daß für eine Sicherheitsmaßnahme (Error Overflow Mode) die im Schritt (201) aufgerufenen aktuellen Daten die Anzahl protokollierter interner Fehler, Bedienungsfehler und Manipulationsversuchen entsprechenden Fehler umfassen, daß bei Erfüllung des im Schritt (202) abgefragten Kriteriums für einen Fehlerüberlaufmode der Eintritt in einen zweiten Modus mit dem folgenden Schritt (203) für eine ständige Signalisierung einer Überschreitung einer vorbestimmten Fehleranzahl erfolgt und die Fehleranzahl weiter protokolliert wird bis ein Rücksetzen der Fehlerregister im Rahmen einer Kommunikation mit der Datenzentrale oder einer Inspektion durch einen Servicedienst vorgenommen wird.
- 46Verfahren nach Anspruch 45, dadurch gekennzeichnet , daß in der Frankiermaschine die Sicherheitsmaßnahme (Error Overflow Mode) im zweiten Modus neben oder anstatt einer Sleeping-Mode-Variante durchgeführt wird und daß sich bei Erfüllung des Abfragekriteriums im Schritt (202), d.h. bei Überschreitung einer vorbestimmten Anzahl an Fehlern, die Reaktionszeitdauer der Frankiermaschine im Schritt (203), in welchem dieser Zustand an den Bediener der Frankiermaschine gemeldet wird, verlangsamt.
- 47Verfahren nach den Ansprüchen 45 bis 46, dadurch gekennzeichnet , daß im Schritt (203) die Reaktionszeitdauer, beispielsweise die Zeitdauer bis zum Beginn des Druckbetriebes, linear mit der Anzahl der Fehler erhöht wird, indem die Ausführung des Programmes verzögert wird oder unkritische Programmteile, wie beispielsweise die Fehleranzeige, mehrfach aufgerufen werden.
- 48Verfahren nach den Ansprüchen 45 bis 46, dadurch gekennzeichnet , daß im vorgenannten Schritt (203) die Reaktionszeitdauer jeweils um eine Stufe erhöht wird, wobei die Stufen Sekunden, Minuten, Stunden, Tage, ... usw. betreffen können, oder eine progressive Steigerung der Reaktionszeitdauer im Betriebsprogramm vorgesehen ist, um eine Manipulation zu erschweren.
- 49Verfahren nach den Ansprüchen 47 oder 48, dadurch gekennzeichnet , daß im Schritt (203) in Abänderung oder in Kombination mit vorgenannten Varianten ein elektronisches Zeitschloß bei einer Fehlbedienung betätigt wird und eine Erhöhung der Reaktionszeitdauer bei jeder Fehlbedienung vorgesehen ist.
- 50Verfahren nach Anspruch 41, dadurch gekennzeichnet , daß in der Frankiermaschine bei der Feststellung der Nichterfüllung eines gültigen Kriteriums im Schritt (207) während des Betriebes der Frankiermaschine für einen ersten Modus schwere Fehler festgestellt werden, um Schritte zum Verhindern des Frankierens bzw. Sperrens der Frankiermaschine (208) und Schritte im Statistik- und Fehlerauswertungsmodus (213) und Anzeigemodus (215) auszulösen, welche durchlaufen werden, um die Aufrechterhaltung, Auswertung und Anzeige des vorgenannten ersten Modus zu sichern.
- 51Verfahren nach Anspruch 41, dadurch gekennzeichnet , daß bei der Erfüllung des Kriteriums, welches im Schritt (202) abgefragt wird, eine erste Stückzahlschwelle erreicht ist, um in den zweiten Modus einzutreten, daß der für den zweiten Modus folgende Schritt (203) eine Warnung umfaßt, welche für die Zeitdauer t n sichtbar ist und eine Frankier-Verzögerung (Alert-Modus) bewirkt.
- 52Verfahren nach Anspruch 51, dadurch gekennzeichnet , daß im zweiten Modus eine Frankier-Verzögerung um die Zeitdauer t n schrittweise steigend wirksam wird, wobei zur Inkrementierung der Zeitdauer t n und zur Dekrementierung einer Vergleichsstückzahl S ref um eine vorbestimmte Stückzahl n ein nachfolgender Schritt (204) vorgesehen ist, daß beim folgenden Durchlauf durch die Systemroutine (200) die laufend bei jeder Frankierung dekrementierte Stückzahl S und die dekrementierten Vergleichsstückzahl S ref im Schritt (201) als aktuelle Daten aufgerufen und anschließend im Schritt (202) miteinander verglichen werden, daß bei Erfüllung des Kriteriums, indem die Stückzahl S die Vergleichsstückzahl S ref unterschreitet, der Schritt (203) der Warnung erneut, aber mit einer um die Zeitdauer t k verlängerten Zeitdauer durchlaufen wird und daß anschließend und bei Nichterfüllung des vorgenannten Kriteriums der Schritt (207) zur Überprüfung des Vorhandenseins des gültigen Codewortes Y erreicht wird.
- 53Verfahren nach einem der vorgenannten Ansprüche 51 bis 52, dadurch gekennzeichnet , daß der bei Erfüllung des Kriteriums (202) für den zweiten Modus folgende Schritt (203) eine Warnung umfaßt, welche für die Zeitdauer t n sichtbar ist und im nachfolgenden Schritt (204) eine neue Vergleichsstückzahl gebildet wird, indem die maximale Stückzahl S max durch eine vorbestimmte Zahl m dividiert wird.
- 54Verfahren nach den Ansprüchen 51 bis 53, dadurch gekennzeichnet , daß die im Schritt (201) aufgerufenen aktuellen Daten unmittelbar nach einer Kommunikation die berechnete bzw. übermittelte spezifische Stückzahl S' als Stückzahl S und die maximale Stückzahl S max umfassen, daß die Vergleichsstückzahl S ref der durch die Zahl k dividierten berechneten bzw. übermittelten maximalen Stückzahl S max entspricht.
- 55Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen mit einem Mikroprozessor in einer Steuereinrichtung der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch , Unterscheiden zwischen nichtmanipuliertem und manipuliertem Betrieb einer Frankiermaschine mittels der Steuereinrichtung (6), indem während eines Betriebsmodus (290) und/oder Kommunikationsmodus (300) eine Überwachung der Zeitdauer des Ablaufes von Programmen, Programmteilen bzw. sicherheitsrelevanter Routinen vorgenommen wird und durch einen nach Ablauf von Programmen, Programmteilen bzw. sicherheitsrelevanten Routinen anschließenden Vergleich der gemessenen Laufzeit mit einer vorgegebenen Laufzeit.
- 56Verfahren nach Anspruch 55, dadurch gekennzeichnet , daß im Fehlerfall die Zeitdauer des ablaufenden Programms bzw. die Zeitdauer der durch ein entsprechendes Programm verursachten Transportgeschwindigkeit eines Poststückes in der Frankiermaschine bzw. die Druckgeschwindigkeit oder die Soll/Ist-Abweichung protokolliert, der Fehlerfall signalisiert und ggf. die Frankiermaschine blockiert wird.
- 57Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen mit einem Mikroprozessor in einer Steuereinrichtung der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch , ein Verändern eines Zählwertes während der Ausführung einer Programmroutine und Vergleich des vorgenannten Zählwertes mit mindestens einem vorbestimmten Zählwert nach Ausführung der Programmroutine.
- 58Verfahren nach Anspruch 57, dadurch gekennzeichnet , daß zur Erhöhung der Sicherheit gegenüber in Fälschungsabsicht vorgenommene Manipulationen in der Frankiermaschine eine solche Flußkontrolle eingesetzt wird, mit welcher nachträglich festgestellt werden kann, welche Verzweigungen durchlaufen wurden, und umfassend die Schritte:- Verändern eines Zählwertes in einem Speicher an mindestens einem Punkt während der Ausführung der Programmroutine durch eine Multiplikation mit einer bestimmten dem jeweiligen Programmteil zugeordneten Primzahl, - Vergleich des veränderten Zählwertes mit mindestens einem dieser Programmroutine zugeordneten vorbestimmten Zählwert und/oder Plausibilitätstest von sich während der Programmausführung beim Durchlauf von Verzweigungen ergebenden unterschiedlichen Zählwerten mittels vorbestimmten Zählwerten nach Ausführung der Programmroutine und Protokollierung im Fehlerfall für ggf. eine spätere Auswertung, wobei bei der späteren Auswertung eine Primzahlzerlegung durchgeführt wird.
- 59Verfahren nach Anspruch 57, dadurch gekennzeichnet , daß in der Frankiermaschine in einer anderen Variante, nur solche Programmteile ohne Verzweigungen berücksichtigt werden, wobei keine Rückverfolgung der durchlaufenen Programmzweige erforderlich wird, daß ein Inkrementieren des Zählwertes zum Verändern desselben und ein Vergleich mit einem vorbestimmten dem Durchlauf der Programmteile entsprechenden Zählwert sowie daß eine Protokollierung im Fehlerfall ggf. für eine spätere Auswertung erfolgt.
- 60Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen mit einem Mikroprozessor in einer Steuereinrichtung der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch die Schritte:a) Übermitteln von Daten von einer Datenzentrale zur Frankiermaschine entsprechend einem beantragten autorisierten Eingriff in die Frankiermaschine, welcher als erlaubter Eingriff protokolliert wird, b) Unterscheiden zwischen beantragten autorisierten und unautorisierten Eingriff in die Frankiermaschine mittels der Steuereinheit der Frankiermaschine in Verbindung mit den von der Datenzentrale übermittelten Daten, wobei bei unautorisierten Eingriff in die Frankiermaschine dieser Eingriff als Fehlerfall protokolliert wird, aber nach einem erfolgten autorisierten Eingriff in die Frankiermaschine der ursprüngliche Betriebszustand mittels den vorgenannten übermittelten Daten wiederhergestellt wird, c) Überführen der Frankiermaschine in den ersten Modus (Kill Mode 1), um sie wirksam außer Betrieb zu setzen, wenn die richtigen Daten fehlen, weil in die Frankiermaschine unautorisiert eingegriffen wurde.
- 61Verfahren nach Anspruch 60, gekennzeichnet , durch ein Unterscheiden gemäß Merkmal b) aufgrund einer Kombination mindestens von Merkmalen der vorgenannten Ansprüche 55 und 56 zur Kontrolle des Zeitablaufes mit den Merkmalen der vorgenannten Ansprüche 57 bis 59 zur Flußkontrolle, wobei in der Frankiermaschine im Fehlerfall, insbesondere bei Abweichung in der Laufzeit kritischer bzw. sicherheitsrelevanter Programmteile (Time Supervision Mode) und/oder bei Abweichung vom vorgegeben Zählwert (Flow Control) ein Flag in einem Speicher gesetzt wird, welches im Schritt (207) abgefragt wird und daß bei Vorliegen dieses Abfragekriteriums auf den Schritt (208) verzweigt wird und die Frankiermaschine somit nicht weiter zum Frankieren betrieben werden kann (Kill Mode 1).
- 62Verfahren nach Anspruch 60, gekennzeichnet , durch ein Unterscheiden gemäß Merkmal b) aufgrund einer Kombination von Merkmalen der vorgenannten Ansprüche 55 und 56 zur Kontrolle des Zeitablaufes in Verbindung mit Merkmalen der vorgenannten Ansprüche 57 bis 59 zur Flußkontrolle, wobei in der Frankiermaschine im Fehlerfall, insbesondere bei Abweichung in der Laufzeit kritischer bzw. sicherheitsrelevanter Programmteile (Time Supervision Mode) und/oder bei Abweichung vom vorgegeben Zählwert (Flow Control) das Codewort Y im SRAM (24) einer Detektoreinrichtung (20) über die Steuerleitung C gelöscht wird, indem in Verbindung mit der Adressenleitung A und der Datenleitung D ein Überschreiben mit einem vorbestimmten anderen Wort, beispielsweise 0000 erfolgt, welches im Schritt (207) abgefragt wird und daß bei Vorliegen dieses Abfragekriteriums auf den Schritt (208) verzweigt wird und die Frankiermaschine somit nicht weiter zum Frankieren betrieben werden kann (Kill Mode 1).
- 63Verfahren nach Anspruch 60, gekennzeichnet , durch ein Unterscheiden gemäß Merkmal b) aufgrund einer Kombination von Merkmalen der vorgenannten Ansprüche 55 und 56 zur Kontrolle des Zeitablaufes in Verbindung mit Merkmalen der vorgenannten Ansprüche 57 bis 59 zur Flußkontrolle, wobei in der Frankiermaschine im Fehlerfall, insbesondere bei Abweichung in der Laufzeit kritischer bzw. sicherheitsrelevanter Programmteile (Time Supervision Mode) und/oder bei Abweichung vom vorgegeben Zählwert (Flow Control) in Kombination mit einem Abfragekriterium entsprechend anderer Varianten zur Verbesserung der Sicherheit, wie beispielsweise das Löschen eines Teils des DES-Schlüssel oder der redundanten Registerstände bzw. Löschen anderer Daten oder Schlüssel, welche für die Datenzentrale bei einer Transaktion Bedeutung haben, verfahren wird, wobei das Abfragekriterium im Schritt (207) abgefragt wird und daß bei Vorliegen dieses Abfragekriteriums auf den Schritt (208) verzweigt wird und die Frankiermaschine somit nicht weiter zum Frankieren betrieben werden kann (Kill Mode 1).
- 64Verfahren nach den Ansprüchen 55, 56 oder 57 bis 59 oder 60 bis 63, gekennzeichnet durch ein Unterscheiden gemäß Merkmal b) aufgrund einer Kombination mindestens von Merkmalen der vorgenannten Ansprüche für einen Kill Mode 1 mit Merkmalen des vorgenannten Anspruchs 1 für einen Kill Mode beim Öffnen der Frankiermaschine unter Verwendung eines Sensors (21).
- 65Verfahren nach den Ansprüchen 51 bis 54, 55 bis 56 oder 57 bis 59 oder 60 bis 63, gekennzeichnet durch eine Kombination von Merkmalen der vorgenannten Ansprüche für einen Kill Mode 1 mit Merkmalen des vorgenannten Anspruchs 41 bis 44 oder 51 bis 54 für eine Variante des Sleeping Mode, mit Merkmalen der Ansprüche 45 bis 49 für den Error Overflow Mode und/oder Merkmalen des Anspruchs 50 für das Blockieren der Frankiermaschine bei einem schweren Fehler.
- 66Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen mit einem Mikroprozessor in einer Steuereinrichtung der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch , ein Bilden einer Checksumme im OTP-Prozessor über den Inhalt des externen Programmspeichers PSP (11) und Vergleich des Ergebnises mit einem im OTP-Prozessor gespeicherten vorbestimmten Wert vor und/oder nach Ablauf des Frankiermodus (400) bzw. Betriebsmodus (290), insbesondere während der Initialisierung im Schritt (101), wenn die Frankiermaschine gestartet wird, oder in Zeiten, in welchen nicht gedruckt wird, im Schritt (213), wenn die Frankiermaschine im Standby-Modus betrieben wird, Protokollierung im Fehlerfall und anschließende Blockierung der Frankiermaschine.
- 67Verfahren nach Anspruch 66, dadurch gekennzeichnet , daß zur Verbesserung der Manipulationssicherheit in einem Kill-Mode 2 die Checksumme über den Inhalt des Programmspeichers (PSP 11) und/oder die Checksumme der Registerstände gebildet wird und/oder eine Abfrage hinsichtlich Manipulationsversuche im Standby Modus vorgesehen ist
- 68Verfahren nach Anspruch 66, dadurch gekennzeichnet , daß der Frankiermodus (400) einen Schritt (405) zur Abfrage einer Druckausgabeanforderung und einer weiteren Abfrage nach der Anzahl an Durchläufen durch die Programmschleife umfaßt, welche letztendlich wieder auf die Eingaberoutine gemäß Schritt (401) des Frankiermodus (400) direkt (Punkt d) oder indirekt (Punkt e) über den Schritt (301) des Kommunikationsmodus (300) auf den Betriebsmodus (290) einschließlich Frankiermodus (400) führt, daß bei Erfüllung des Abfragekriteriums, wobei eine vorbestimmte Zeit keine Eingabeanforderung vorliegt oder durch einen Briefsensor kein nachfolgendes zu frankierendes Poststück ermittelt wird und somit keine Druckanforderung erfolgt, ein Flag gesetzt und direkt auf den Punkt s zur Systemroutine (200) zurückverzweigt wird, ohne daß die Abrechnungs- und Druckroutine im Schritt (406) durchlaufen wird, daß im Schritt (211) des Betriebsmodus (290) eine Abfrage erfolgt, ob das Flag gesetzt ist, und bei Vorliegen des Abfragekriteriums in Schritt (211) der Standby Modus erreicht ist, daß im Statistik- und Fehlerauswertungsmodus gemäß Schritt (213) die Checksumme über den Inhalt des Programmspeichers (PSP 11) gebildet und daß nach der Checksummenprüfung das im Schritt (211) abgefragte Flag zurückgesetzt oder im Fehlerfall eine Maßnahme ergriffen wird, die direkt zum Blockieren der Frankiermaschine führt oder daß die Maßnahme indirekt im Schritt (207) erkannt wird, um dann auf den Schritt (208) zu verzweigen, um die Frankiermaschine zu sperren.
- 69Verfahren nach Anspruch 68, dadurch gekennzeichnet , daß im Schritt (213) das Codeword Y gelöscht wird, wenn ein Manipulationsversuch im Standby Modus durch Checksummenprüfung im Schritt (213) festgestellt worden ist.
- 70Verfahren nach einem der vorgenannten Ansprüche 66 bis 69, gekennzeichnet durch eine Kombination von Merkmalen der vorgenannten Ansprüche 66 bis 69 für eine Checksummenbildung (Kill Mode 2) mit Merkmalen der vorgenannten Ansprüche 41 bis 44 für eine Variante des Sleeping Mode, Anprüche 45 bis 49 für den Error Overflow Mode und/oder Anspruch 50 für das Blockieren der Frankiermaschine bei einem schweren Fehler und/oder der vorgenannten Ansprüche 55 bis 56 für den Time Supervision Mode und/oder der vorgenannten Ansprüche 57 bis 59 für einen Flow Control Mode.
- 71Anordnung zur Verbesserung der Sicherheit von Frankiermaschinen mit Ein- und Ausgabemitteln, Speichermitteln und einer Steuereinrichtung, dadurch gekennzeichnet , daß die Steuereinrichtung (6) einen Prozessor, interne nichtflüchtige Speicher und Taktgeber/Zählerschaltungen enthält, wobei entsprechende Sicherungsbits während der Herstellung der Frankiermaschine gesetzt werden, welche das Auslesen der in der Steuereinrichtung gespeicherten Daten und Programme von außen verhindern, daß der vorgenannte interne nichtflüchtige Speicher als Programmspeicher für sicherheitsrelevante Routinen bzw. Programme und daß die vorgenannten Taktgeber/Zählerschaltungen für eine Laufzeitüberwachung der sicherheitsrelevanten Routinen bzw. Programmteile einerseits und für das Verändern eines Zählwertes entsprechend der durchlaufenen Programmteile und/oder Verzweigungen während der Programmausführung andererseits und daß der Prozessor für eine nach Ausführung der jeweiligen Routinen, Programme bzw. Programmteile erfolgende Auswertung ausgebildet ist.
- 72Anordnung nach Anspruch 71, dadurch gekennzeichnet , daß die Steuereinrichtung (6) der Frankiermaschine als OTP-Prozessor ausgebildet ist, welcher eine Einrichtung (20) mit einem nichtflüchtigen Speicher zur Einspeicherung eines Codewortes Y aufweist, mit welcher während des Betriebes der Frankiermaschine in der Systemroutine Manipulationsversuche festgestellt werden.
- 73Anordnung nach Anspruch 71, dadurch gekennzeichnet , daß die Steuereinrichtung (6) der Frankiermaschine als OTP-Prozessor ausgebildet ist, an welchem eine Detektoreinrichtung (20) angeschlossen ist, mit welcher während des Betriebes der Frankiermaschine in der Systemroutine Manipulationsversuche festgestellt werden.
- 74Anordnung nach den Ansprüchen 72 bis 73, dadurch gekennzeichnet , daß an der Detektoreinrichtung (20) ein Sensor (21) zur Feststellung eines Öffnens der Frankiermaschine angeschlossen ist, um beim Öffnen das Codewort Y zu löschen.
Independent claims74
177 paragraphs, as filed
The invention relates to a method for improving the security of franking machines, in the type specified in the preamble of claim 1.
A franking machine generally creates an imprint in a form agreed with the post right-aligned, parallel to the upper edge of the mail item, beginning with the content of the postage in the postmark, the date in the day stamp and stamp imprints for advertising slogans and, if applicable, the type of shipment in the election print stamp. The post value, the date and the type of shipment form the variable information to be entered in accordance with the piece of mail.
The postage value is usually the transport fee prepaid by the sender, which is taken from a refillable credit register and used to clear the postal item. In contrast, in the current account procedure, a register is only counted up depending on the frankings made with the postage value and is read at regular intervals by a postal inspector. In principle, every franking made must be accounted for and any manipulation that leads to franking that has not been invoiced must be prevented.
A known franking machine is equipped with at least one input means, an output means, an input / output control module, a program, data and in particular storage device carrying the accounting register, a control device and a printer module. In the case of a printer module with a printing mechanism, measures must also be taken so that the printing mechanism cannot be misused for unpredictable impressions when it is switched off.
The invention relates in particular to franking machines which provide a fully electronic impression for franking mail, including an advertisement slogan. The result of this is that a valid franking that has not been invoiced must only be prevented when it is switched on.
In the case of a franking machine known from US Pat. No. 4,746,234, fixed and variable information is stored in storage means (ROM, RAM) in order to read it out by means of a microprocessor when a letter actuates a microswitch on the transport path in front of the printing position and to send a print control signal form. Both are electronically assembled into a print image and are printed out on an envelope to be franked using thermal transfer printing media.
A method for controlling the column-by-column printing of a postage stamp image in a franking machine has also already been proposed EP 578 042 A2, which separately composes fixed and variable data converted into graphic pixel image data during column-by-column printing. It would therefore be difficult to manipulate the print control signal without high and expensive effort when printing at a high speed.
On the other hand, the memory device comprises at least one non-volatile memory module which contains the currently remaining credit balance, which results from the fact that the respective postage value to be printed is subtracted from a credit previously loaded into the franking machine. The franking machine blocks when the remaining credit is zero.
Known franking machines contain in three memories at least three relevant post registers for the total value used (increasing register), remaining credit remaining (falling register) and registers for a checksum. The checksum is compared with the sum of the total value used and the available credit. A check for correct billing is already possible with this.
In US 4,251,874 a mechanical printing unit, which has to be preset for printing, is used with a detector device in order to monitor the presetting. Means are also provided in the electronic accounting system for determining errors in data and control signals. If this number of errors reaches a predetermined value, the further operation of the franking machine is interrupted. However, the sudden failure of the franking machine is disadvantageous for the franking machine user. With a non-mechanical printing principle, on the other hand, such internal errors are hardly to be expected, and in the case of a serious error, the franking machine must be switched off immediately anyway. In addition, the security against manipulation of the postage meter machine is hardly increased by the postage meter machine being switched off after a predetermined number of errors.
A franking machine with program sequence monitoring is known from US Pat. No. 4,785,417. The correct execution of a larger program section is checked by means of a special code assigned to each program section, which code is stored in a specific memory cell in RAM when the program section is called up. It is now checked whether the code stored in the aforementioned memory cell is still present in the program section currently running. If, during manipulation, the run of a program section was interrupted and another program section was running, an error can be determined by such a control question. The comparison can only be carried out in the main process. Auxiliary processes, for example safety-relevant calculations, which are used by several main processes, cannot be checked by monitoring the execution of the program part because the program control takes place independently of the program process. If manipulations were made on the basis of permitted program parts and secondary processes in such a way that secondary processes were additionally incorporated into main processes or omitted from the latter or branched to secondary processes, then no error would be determined, since neither the length of the program part can be determined nor which one can be determined Program branch how often was run.
In known franking machines, further security measures, such as breakaway screws and encapsulated, shielded security housings, are already customary to protect against the unauthorized opening of the security housing.
A security housing for franking machines, which has internal sensors, is known from DE 41 29 302 A1. The sensors are switches connected to a battery, which become active when the safety housing is opened in order to erase a memory (falling postal register) storing the residual value credit by interrupting the energy supply. As is known, however, it is not possible to predict the state of a de-energized memory chip when the voltage returns. This could result in an unpaid higher remaining balance. On the other hand, it cannot be ruled out that the residual value credit will at least partially discharge in the manner mentioned above. However, this would be disadvantageous during an inspection, since the residual value credit, which had been paid by the franking machine user, must also be reloaded, but the amount of this residual credit may be falsified by the above-mentioned influences. Finally, the description does not show how a manipulator can be prevented from restoring an unpaid remaining balance.
A remote inspection system for franking machines has already been proposed in US Pat. No. 4,812,965, which is based on special messages in the printing of mail pieces which have to be sent to the central office, or on a remote query via MODEM. Sensors within the postage meter machine are intended to detect any counterfeiting act that has been carried out, so that a flag can be set in associated memories if the postage meter machine has been tampered with for manipulation purposes. Such an intervention could take place in order to load an unpaid credit into the register.
If tampering is detected, the franking machine is blocked by a signal from the data center during remote inspection via modem.
A clever manipulation could, on the other hand, consist in returning the flag and the registers to their original state after franking imprints have not been billed. Such manipulation would not be recognizable via remote inspection by the data center if this reversed manipulation was prior to the remote inspection. Receiving the postcard from the data center, on which franking is to be carried out for inspection purposes, also allows the manipulator to reset the franking machine to its original state in sufficient time. This means that no higher security can yet be achieved.
The disadvantage of such a system is that a sufficiently qualified manipulator who breaks into the franking machine cannot be prevented from subsequently removing its traces by deleting the flags. No error or attempted manipulation can then be determined during a later remote inspection.
Furthermore, it is known in connection with the remote interrogation of register statuses to transmit recharge information to the franking machine from a data center via a remote value specification in order to reload a credit into the register for the remaining credit (residual value). It goes without saying that suitable security measures must be taken for this so that the credit stored in the franking machine cannot be topped up in an unauthorized manner. Protecting the aforementioned solutions against misuse and attempts at counterfeiting requires additional material and time.
Keys and a combination lock are also common to make access to the franking machine more difficult.
A corresponding security measure is also known from US Pat. No. 4,549,281. Here, a comparison is made of an internal fixed combination stored in a non-volatile register with an input external combination, the postage meter machine being blocked by means of escapement electronics after a number of failed attempts, ie non-identity of the combinations.
According to US 4,835,697, a combination can in principle be changed to prevent unauthorized access to the franking machine.
In US Pat. No. 4,812,994, unauthorized access to the use of the franking machine is also to be prevented by blocking the franking machine if a predetermined password is entered incorrectly. In addition, the franking machine can be set by means of a password and corresponding input on the keyboard so that franking is only possible during a predetermined time interval or times of day.
The password can be entered by a personal computer via MODEM, by a chip card or manually in the franking machine. After a positive comparison with a password stored in the franking machine, the franking machine is released. A security module (EPROM) is integrated in the control module of the accounting unit. As a further security measure, an encryption module (separate microprocessor or program for FM-CPU based on DES or RSA code) is provided, which generates an identification number in the franking stamp that includes the postage value, the subscriber number, a transaction number and the like. If there is enough criminal energy, a password could also be researched and, together with the franking machine, brought into the possession of a manipulator.
From US 4,864,506 it is known that if the value of the credit in the falling register is below a threshold value and a predetermined time has been reached, communication to the remote data center is started by the franking machine. It is provided that the data center for receiving register data and for checking whether the franking machine is still connected to a specific telephone number, connects to the franking machine after a defined period of time and the franking machine responds only at predetermined times. In addition, provision is made to query the identity number of the franking machine and the values in the falling and rising register before authorization is loaded into the franking machine for authorization by the data center.
Furthermore, it is known from the above-mentioned patent that the communication of the data center with the franking machine need not be limited to the mere transfer of credit into the franking machine. Rather, if the franking machine is deregistered, the communication between the data center and the franking machine is used to transfer the remaining credit of the franking machine to the data center. The value in the falling post register of the franking machine is then zero, which effectively puts the franking machine out of operation.
In addition, EP 388 840 A2 discloses a comparable security technique for setting a franking machine in order to clean it of data without the franking machine having to be transported to the manufacturer. Here too, security depends solely on the encryption of the transmitted code.
From US 5 077 660 a method for changing the configuration of the franking machine is also known, wherein the franking machine can be switched from the operating mode to a configuration mode by means of a suitable input via a keyboard and a new meter type number can be entered which corresponds to the desired number of features. The franking machine generates a code for communication with the computer of the data center and the input of the identification data and the new meter type number in the aforementioned computer, which also generates a corresponding code for transmission and input into the franking machine, in which the two codes are compared. If both codes match, the franking machine is configured and switched to the operating mode. As a result, the data center always has exact records of the meter type set for the corresponding franking machine. However, security depends solely on the encryption of the transmitted code.
From EP 516 403 A2 it is known to regularly transmit the errors of the postage meter machine that were logged in the past and stored in a memory to a remote error analysis computer for evaluation. Such a remote inspection allows an early warning of an occurring error and enables further measures (service) to be taken.
This alone does not offer a sufficient criterion for manipulation. Even if an additional determination regarding a user of a franking machine were carried out in the data center, which the user continued to operate beyond the inspection date, it could not be concluded from this information that manipulation was carried out with the intention of forgery if the franking machine does not report regularly. A fluctuating amount of mail can also be a cause of irregular reporting to the data center.
From US 4,811,234 it is known to carry out the transactions in encrypted form and in the process to query the registers of the franking machine and to transmit the register data to the data center in order to indicate a temporal reference to the reduction in the amount authorized to dispose stored in the register. On the one hand, the franking machine identifies itself at the data center by means of its encrypted register content when a presettable threshold value has been reached.
On the other hand, the data center modifies the desired franking amount up to which franking can be carried out by means of corresponding authorization signals. Encryption is therefore the only security against manipulation of the register status. If a manipulator always loads the same amount at the same time intervals, but in the meantime franked a much higher amount with the manipulated franking machine than he paid, the data center cannot detect any manipulation.
In US 3,255,439, the secure reloading of a franking machine with a credit was on the one hand associated with an automatic signal transmission from the franking machine to the data center whenever a predetermined sum of funds that was franked or the number of processed mail pieces or a predetermined time period was reached.
Alternatively, a signal corresponding to the sum of funds, number of pieces or time period can be transmitted. Communication takes place by means of binary signals via converters connected to one another via a telephone line. The machine receives an equally secured reload in accordance with the credit balance and blocks if no credit is replenished. Appropriate encryption is required to transmit the data. However, this solution alone cannot meet an increased need for security in relation to manipulation of the franking machine.
According to GB 22 33 937 A and US 5 181 245, the franking machine periodically communicates with the data center. A blocking means allows the franking machine to block after a predetermined time or after a predetermined number of operation cycles and provides a warning to the user. To unlock, an encrypted code must be entered from the outside, which is compared with an internally generated encrypted code. In order to prevent incorrect billing data from being delivered to the data center, the billing data are included in the encryption of the aforementioned code. It is disadvantageous that the warning occurs at the same time as the franking machine is blocked, without the user being able to change his behavior accordingly in good time and to call the data center beforehand.
A franking machine is known from US Pat. No. 5,243,654, where the current time data supplied by the clock / date module are compared with stored decommissioning time data. If the stored shutdown time is reached by the current time, the franking machine is deactivated, that is to say printing is prevented.
When a connection is established with a data center that reads the accounting data from the rising register, the franking machine is transmitted an encrypted combination value and a new period is set, which makes the franking machine operational again. The total amount of consumption, which contains the total postage used and is read by the data center, is also part of the encrypted combination value. After decoding the combination value, the amount of consumption sum is separated and compared with the amount of consumption amount stored in the franking machine. If the comparison is positive, the franking machine is automatically blocked.
This solution ensures that the franking machine periodically reports to the data center in order to transmit accounting data. However, use cases are quite conceivable where the amount of mail to be franked fluctuates (seasonal operation). In these cases, the franking machine would disadvantageously be blocked unnecessarily often.
The task was to solve the disadvantages of the prior art and to achieve a significant increase in safety without an extraordinary inspection on site. A distinction should be made between authorized opening (service, inspection) and unauthorized opening (intention to manipulate) and the security against manipulation should be increased. Another task is to improve security when communicating with the data center when data is transmitted in both directions.
The object is achieved with the characterizing features of claim 1.
The solution according to the invention is based on the one hand on the knowledge that only data stored centrally in a data center can be adequately protected against manipulation. A significant increase in security is achieved by reporting each time the franking machine is opened. Likewise, reporting at more or less large intervals, in particular for reloading a credit in conjunction with the above-mentioned logging, increases security against misuse. The data to be stored centrally include at least the date, time, franking machine serial number (or ID number) and the type of data (register values, parameters) when the franking machine starts communication with the data center.
On the other hand, the franking machine has two special modes for solving the task. A first mode to block the franking machine for further use (kill mode). This blocking can be lifted by an authorized person on the next inspection on site. It has a second mode in order to induce the franking machine to communicate with the data center when selected criteria are met (sleeping mode).
According to the invention, the control unit of the franking machine can distinguish between authorized opening (service, inspection) and unauthorized opening (intention to manipulate) in connection with the data transmitted by the data center and a signal detected by a sensor.
The procedure for improving the security of franking machines comprises the steps:<ul id="ul0001" list-style="none"><li>a) registering an authorized opening of the franking machine for the purpose of an inspection, an opening request being made after entering the communication mode at a remote data center, and</li><li>b) transmitting a new code word to the franking machine from the data center, in response to the request for opening,</li><li>c) Transfer of the franking machine into the first mode in order to effectively put it out of operation if the correct code word is missing because the franking machine has been opened.</li></ul>
The solution according to the invention also assumes that the funds stored in the franking machine must be protected against unauthorized access. The falsification of data stored in the franking machine is made so difficult that the effort for a manipulator is no longer worthwhile.
Commercial OTP processors (ONE TIME PROGRAMMABLE) can contain all security-relevant program parts inside the processor housing, as well as the code for forming the message authentication code (MAC). The latter is an encrypted checksum that is attached to information. For example, Data Encryption Standard (DES) is suitable as the crypto-algorithm. This allows MAC information to be attached to the security-relevant register data and thus increases the difficulty of manipulating the postal registers to a maximum.
These safety-relevant program parts also include program parts for a flow control that monitors the number of program parts that have expired. Malfunctions of the microprocessor or manipulations carried out with the intention of forgery can thus be detected. Specific arithmetic operations allow checking which program parts have been used and how often.
Another security measure that can take place in the first mode in addition to or instead of distinguishing between unauthorized and authorized opening of the franking machine by means of opening authorization (kill mode 0) is to monitor the program runtime of selected security-relevant programs or program parts in a time supervision mode (kill mode 1). . If the runtime of programs or program parts deviates from a predetermined runtime, as is the case with manipulation or If the program is monitored using an emulator, the machine is inhibited. In one embodiment variant, the code word Y stored in a non-volatile memory is deleted by the microprocessor or OTP.
Based on the fact that the printhead cannot be used without a transport device to generate an unpaid franking stamp, the transport speed or the printing speed is monitored. With the thermal transfer printer, the transport speed of the mail item is proportional to the ribbon speed of the ribbon, which is measured via an encoder. The print speed is determined by the required system routine or Time period for securing the franking machine in the operating mode was hardly reduced. This is achieved by opening up a time reserve during printing by the microprocessor of the control device, which carries out the columnar embedding of window data. However, the method according to the invention is not limited to such fast franking machines. It is crucial to monitor the printing speed for any deviations in the course of time that may have been caused by manipulation, in order to prevent manipulation of the pressure control signal in addition to the other security measures already taken.
The franking machine can enter the second mode from the system routine using a decision criterion in order to issue a warning and request to the user of the franking machine to communicate with the data center. At the same time, the data center also monitors the behavior of the franking machine user on the basis of previous data transmitted during communication.
It is provided in the franking machine that a special sleeping mode counter is set to a specific number of pieces each time it communicates with the data center and is prompted to continue counting each franking, ie in the course of a billing and printing routine, until a certain number is reached. The specific number of pieces can be calculated in the franking machine, as well as calculated in the data center and transmitted to the franking machine via a communication link.
Starting from the consideration of using only one microprocessor and a suitable program of a franking machine to create a method for improving the security of franking machines, user-specific information about the credit consumption that is present in the data center at the same time forms a first calculation basis in order to store the credit consumption data stored in the data center. and check credit reload date data for plausibility. Another inventive calculation basis based on further data, in particular in connection with the number of pieces since the last communication, allows an extraordinary inspection of the postage meter machine that is considered suspect at the data center.
The franking machine, which receives a regular credit recharge and is inspected in the process, can be classified as unsuspicious. However, the franking machine that continues to operate without an inspection over a predetermined inspection date does not necessarily have to be manipulated. Rather, the mail volume to be processed by the franking machine may have decreased above average. If there is still sufficient residual credit available in the franking machine, you can of course continue to frank. In this case, only an extraordinary inspection on site can clarify whether there is any manipulation.
To check suspect franking machines, the data center of the postal authority or the institute commissioned with the check transmits the associated franking machine serial number. With this information, the occurrence of mail pieces (letters) from certain senders can be monitored by counting their number in the time interval, for example of 90 days.
During an inspection, the seal of the franking machine is checked for integrity and then the machine itself. In the event of a repair or by on-site service, intervention may have to be made in the franking machine. In preparation for the intervention, the registers of the franking machine are queried in order to determine the type of intervention required. The type of intervention and the register data are then communicated to the data center and data is transmitted from a data center to the franking machine in accordance with a requested authorized intervention in the franking machine, which is logged as an allowed intervention. The franking machine is able to differentiate between requested and unauthorized intervention in the franking machine by means of the control unit of the franking machine in connection with the data transmitted by the data center, this intervention being logged as an error in the event of unauthorized intervention in the franking machine. but after an authorized intervention in the franking machine, the original operating state is restored using the aforementioned transmitted data.
If the franking machine has been tampered with without authorization, this leads to the loss of predetermined data. If a manipulator therefore carries out an unauthorized intervention, the franking machine is effectively put out of operation by transferring the franking machine to the first mode.
Another safety measure that can be carried out in the second mode in addition to or instead of a sleeping mode variant is the error overflow mode. This extends the response time of the postage meter machine when a predetermined number of errors is exceeded and reports this status to the operator of the postage meter machine via the display. If the state of exceeding the number of errors is not eliminated, for example in the course of an inspection by a service provider or by resetting during communication with the data center, the reaction time can be increased further to make any manipulation more difficult.
The method for improving the security of a postage meter machine which is capable of communicating with a remote data center and has a microprocessor in a control device of the postage meter machine also comprises forming a checksum in the OTP processor about the content of the external program memory and comparing the result with one Predetermined value stored in the OTP processor before and / or after the franking mode or Operating mode, in particular during initialization (ie when the postage meter machine is started) or at times when printing is not taking place (ie when the postage meter machine is operated in standby mode). In the event of an error, the franking machine is then logged and subsequently blocked.
Advantageous developments of the invention are characterized in the subclaims or are shown below together with the description of the preferred embodiment of the invention with reference to the figures. Show it:<dl id="dl0001"><dt>Figures 1a and 1b,</dt><dd>Block diagram of a franking machine with increased security according to the invention</dd><dt>Figure 1c,</dt><dd>Circuit diagram of a detector device for determining an opening in the housing</dd><dt>Figure 2a,</dt><dd>Flow chart according to the solution according to the invention in a first variant</dd><dt>Figure 2b,</dt><dd>Flow chart according to the solution according to the invention according to a second variant</dd><dt>3a and 3b,</dt><dd>Representation of the security processes of the franking machine and data center in communication mode</dd><dt>Figure 4a,</dt><dd>Flow chart for the franking mode according to a first variant</dd><dt>Figure 4b,</dt><dd>Flow chart for the franking mode according to a second variant</dd><dt>Figure 5,</dt><dd>Schedule for a first sleeping mode variant</dd><dt>Figure 6,</dt><dd>Schedule for a second sleeping mode variant</dd><dt>Figure 7,</dt><dd>Flow chart for the introduction of code words according to the solution according to the invention</dd></dl> FIGS. 1a and 1b each show a block diagram of the franking machine according to the invention with a printer module 1 for a fully electronically generated franking image, with at least one input means 2 having a plurality of actuating elements, a display unit 3, a sensor 21 that detects attempts to open, and a MODEM 23 that establishes communication with a data center , which are coupled via an input / output control module 4 to a control device 6 and to a non-volatile memory 5 or 11 for the variable or the constant parts of the franking image.
A character memory 9 supplies the necessary print data for a volatile working memory 7. The control device 6 has a microprocessor μP, which with the input / output control module 4, with the character memory 9, with the volatile working memory 7 and with the non-volatile working memory 5 a cost center memory 10, with a program memory 11, with the motor of a transport or feed device, if necessary with stripe release 12, an encoder (coding disc) 13 and with a clock / date module 8 is connected. The individual memories can be implemented in a plurality of physically separate or, in a manner not shown, combined in a few building blocks, which are secured against removal by at least one additional measure, for example gluing on the circuit board, sealing or potting with epoxy resin.
In FIG. 1a, the sensor 21 acts on a detector device 20, which is loaded via the input / output control module 4 after the franking machine is switched on with a code word Y under predetermined conditions, which is read out during operation of the franking machine and checked for validity . How the detector device 20 is loaded with a code word Y is explained below with reference to FIG. 1c in conjunction with the explanations for FIG. 2.
FIG. 1 c shows a circuit diagram of a detector device 20 for determining an opening in the housing. This detector device 20 comprises at least one static memory module 24 (SRAM) for the code word Y, a changeover switch 25 and a primary battery 26, in particular a lithium cell.
The switch 25 connects a power supply output voltage <maths id="math0001" num=""><math display="inline"><mrow><msub><mrow><mtext>V</mtext></mrow><mrow><mtext>cc</mtext></mrow></msub><mtext>= + 5V</mtext></mrow></math><img file="EP0660269A2_D0001.tif" /></maths> with the SRAM 24 when the franking machine is operated on. If the franking machine is switched off or the power supply is interrupted, the SRAM 24 is supplied from the primary battery 26, preferably with a voltage of + 3V. The memory content in the SRAM is thus retained until the supply is set via the sensor 21 or the primary battery 26.
In a preferred variant, such a sensor is an electrically conductive strip which establishes the contact between the long-term battery (lithium battery) and the devices 25 or 24 to be supplied, which is designed as a memory module (CMOS-SRAM) for the code word Y. A switch 27 is connected to the supply voltage supplied by the switching device 25 via a resistor R and to ground potential.
The tap between the resistor R and the switch 27 leads to the reset input of the memory chip 24 for the code word Y. The switch 27 can be, for example, an npn transistor which is connected to the reset input with its collector and is at ground potential with its emitter . Its base is connected via an impedance converter to the BC input of the switching device 25, which is connected to the + pole of the battery 26 via the sensor 21. The impedance converter is a negator using CMOS 3V technology. The switching device 25, for which the module bq 2201 is preferably used, supplies a power supply voltage during the operation of the franking machine<maths id="math0002" num=""><math display="inline"><mrow><msub><mrow><mtext>V</mtext></mrow><mrow><mtext>cc</mtext></mrow></msub><mtext> = +5 V</mtext></mrow></math><img file="EP0660269A2_D0002.tif" /></maths> and a battery voltage of +3 V during non-operation to maintain the memory content. If the sensor 21 is activated during the non-operation, the memory maintenance voltage is missing. However, if the sensor 21 is activated during operation, the memory content is deleted via the reset input.
In a modified variant — not shown in FIG. 1c — another connection can also be interrupted by means of the sensor 21, to which the detector device 20 reacts. Such an electrically conductive strip can be manually laid differently for each machine. It is essential here that any opening of the housing moves the strip and thus interrupts the aforementioned contact.
The strip is, for example, initially laid loosely during assembly and is only pulled taut after assembly or shortly before the housing shells are finally closed, ie the aforementioned contact is made.
An advantageous further sensor variant consists in the design of the housing shells as a safety capsule.
The safety capsule is formed with meandering conductor tracks through which a low monitoring current or charge maintenance current for a CMOS RAM flows. Every opening leads to a power cut. This means that information is lost that the manipulator cannot replace. After the housing is closed, the system routine prevents the machine from entering franking mode.
FIG. 1b shows a second variant with device 20 coupled directly to the microprocessor of the control device, which device 20 can also be influenced by a sensor 21. The sensor 21 and the detector device can be implemented in different ways.
Another variant of the detector device 20 uses a programmable logic array which can be influenced by the sensor 21. The sensor effects another program branch during the execution of the system routine via the device. After the housing has been closed, the system routine again prevents the machine from entering franking mode.
FIG. 2a shows a flow chart for a franking machine with a security system according to a first variant of the solution according to the invention. According to the invention, a step 210 is continuously provided when the postage meter machine is operating and not in operation if an opening of the postage meter machine is detected by a sensor 21.
After the franking machine has been switched on in step 100, a function test with subsequent initialization is then carried out within a start routine 101.
In the subsequent step - comprising a number of sub-steps 102 to 105, shown in more detail in FIG. 7 - a new code word Y '- but only if, according to step 102, one exists in another predetermined memory location E of the non-volatile memory 5 - into the memory location of the old code word Y copied (step 103) if there is no longer a valid code word Y stored there. The latter applies equally to the case of an authorized and unauthorized opening, because the old code word Y is deleted each time the housing is opened. If not opened, no copying takes place and after step 104 the old code word is retained in the memory 20. The system routine 200 is now reached at point s. This comprises several steps 201 to 215 of the security system. Current data is called in step 201, which is explained in more detail below in connection with the explanation of FIGS. 5 and 6 for the sleeping mode.
Subsequently, as shown in FIG. 2a, step 202 checks whether the criteria for entering sleeping mode are met. If this is the case, a branch is made to step 203 in order to display at least one warning by means of the display unit 3. Further steps 204 to 206 can be carried out before branching to step 207. If this is not the case, a branch is also made to step 207. After the above steps, point t is reached in any case.
In step 207 - as is explained in more detail in the European application with the official file number 93103951.5 - at least one register check of the data structure of the postal register is carried out in order to log the errors. In step 208 measures are also taken to block the franking machine in the event of register data structure errors.
Of course, a fraudster who breaks into the franking machine could carry out such manipulation in order to change the postal registers correctly. This manipulation could only be revealed in connection with the data from the data center the next time the registers were accessed remotely, if it was not undone beforehand, because a manipulator tries to cover up its tracks. It is therefore provided according to the invention that at least one check is carried out to determine whether a valid code Y is present in the predetermined memory location of the unit 20. If this is not the case, the process branches to step 208.
The check for valid code Y is carried out, for example, using a selected checksum procedure within an OTP processor (ONE TIME PROGRAMMABLE), which internally contains the corresponding program parts and also the code for forming a MAC (MESSAGE AUTHENTIFICATION CODE), which is why the manipulator has the type cannot understand the checksum procedure. Other security-relevant key data and processes are also stored exclusively inside the OTP processor in order to place a MAC protection over the postal register.
A further security variant which does not require an OTP processor consists in making it difficult to find the key by coding it and partially storing it in different memory areas. Again, MACs are appended to every piece of information in the security-related registers. Manipulation of the register data can be recognized by checking the MAC. This routine takes place in step 406 in the franking mode, which is shown in FIG. This increases the difficulty of manipulating the postal registers as much as possible.
With step 208, the kill mode is reached and the franking machine is locked. In step 208, the postal registers are preferably partially deleted in a predetermined manner. The display mode 215 is reached via step 213 and then branched back to the system routine. The blocking can advantageously take place in that the branching to the franking mode 400 is no longer carried out.
If the check in step 207 has been carried out without any relevant deficiencies having been found, point e, ie the start of a communication mode 300, is reached and a step 301 - shown in FIGS. 2 and 3a - asks whether there is a transaction request. If this is not the case, communication mode 300 is exited and point f, ie operating mode 290, is reached. If relevant data were transmitted in communication mode, branch to step 213 for data evaluation. Or otherwise, if the non-transmission is determined in step 211, branch to step 212. It is now checked whether corresponding entries have been made in order to go to test mode 216 when test request 212 is made, otherwise to go to display mode 215 when register status check 214 is intended. If this is not the case, point d, ie franking mode 400, is reached automatically.
According to the invention, it is further provided that a statistical and error evaluation is carried out in step 213 in order to obtain further current data, which can also be called up in step 201 after branching to the system routine 200.
If the franking machine housing is opened by authorized persons, a written or telephonic registration in the data center for the authorized opening is required, which indicates the opening date and time for the approximate opening. Before the franking machine can then actually be opened, communication with the data center must be established via MODEM in order to request authorization to open it and to load a new future code Y 'which can replace the old one.
FIGS. 3a and 3b show the security processes of the franking machine in communication mode on the one hand and the security processes of the data center in communication mode on the other hand.
If point e, ie the beginning of the communication mode 300 explained below, is reached in a step 301 - shown in FIGS. 2 and 3a - it is queried whether there is a transaction request. Such can be provided, for example, for reloading credit, changing telephone numbers, etc.
The user selects the communication or remote value default mode of the franking machine by entering the identification number (eight-digit postage request number). It is now assumed, for example, that communication is to take place in order to load a new future code Y 'which can replace the old one. If only such a transaction request is made, the default amount must be changed to zero, because in this case, of course, the credit in the franking machine does not have to be increased.
In step 302, the identification number (ID number) and the intended input parameters can be entered in the following manner. With the ID no. it can be the serial number of the franking machine, a PIN or PAN (postage retrieval number), which is acknowledged by actuation by means of a predetermined T key on the input means 2. The input parameter (default value) used in the last remote value specification (reloading) appears in the display unit 3 and is now overwritten or retained by the input of the desired input parameter. The input parameter is a combination of numbers which is understood in the data center as a request to transmit a new code word Y 'if an opening authorization has previously been obtained. If the aforementioned input parameter is entered incorrectly, the display can be cleared by pressing a C key.
For example, a change is entered to load a zero-value credit in a transaction, but no opening authorization is obtained beforehand. The input parameter is therefore only used as a new default value. In this case, however, the credit for frankings is not increased in value if the input parameter has the value zero, and a new code word is not loaded. However, a number S 'can be transmitted for each communication.
It is only through the previous logon, for example by means of a separate call to the data center or another form of communication, that the data center is informed that a new code word Y 'is to be transmitted to the franking machine if the franking machine then carries out a transaction for the value within a predetermined period of time Zero is started. The request for opening is only deemed to have been made if the franking machine enters the communication mode agreed upon after registering an authorized opening.
If, however, any other input parameter is agreed with the data center beforehand, when this input parameter is entered, in addition to reloading the credit according to the default value entered by the input parameter, a new future code Y 'is reloaded during an additional transaction.
If an input parameter other than the agreed one is entered, the result is only a reload in the amount of the selected new default amount.
If the desired input parameter is displayed correctly, this is confirmed by pressing the predetermined T key of the input means 2 again. A display corresponding to an input parameter change or to the non-change (old default value) then appears in the display unit 3.
By pressing the predetermined T key, the change of the input parameter is started via the MODEM connection. The input is checked (step 303) and the further process runs automatically, the process being accompanied by a corresponding display.
To do this, the franking machine checks whether a MODEM is connected and ready for operation. If this is not the case, the process branches to step 310 to indicate that the transaction request must be repeated. Otherwise, the franking machine reads the dialing parameters, consisting of the dial-out parameters (main / extension, etc.) and the telephone number from the NVRAM memory area F and sends them to the Modern 23 with a dial request command. The connection set-up required for communication is then carried out via the MODEM 23 with the data center in a step 304.
In FIG. 3a, the parallel process in the data center, which is necessary for communication, is also shown on the left half. Step 501 continuously checks whether a call has been made to the data center. If this is the case and the MODEM 23 has dialed the opposite side, the connection is established in parallel in the data center in step 502. And in step 503, it is constantly monitored whether the connection to the data center has been released. If this is the case, after an error message in step 513 there is a branch back to step 501.
In parallel, the franking machine monitors in step 305 whether communication errors have occurred and, if necessary, branches back to step 304 in order to be re-established by the franking machine. After a predetermined number n of unsuccessful redials for the purpose of establishing a connection, a branch is made back to point e via a display step 310. If there was no error that could be determined in step 305, the franking machine determines in step 306 that the connection has been established and that a transaction is still to be carried out, branching to step 307 in order to receive an opening message or identification, pretensioning or To send register data. In the following step 308, the same check as in step 305 is carried out, ie if a communication error has occurred, the method branches back to step 304. Otherwise, an opening message was sent from the franking machine to the data center. This includes, among other things, the postage call number for the announcement of the caller, ie the franking machine, at the data center.
This opening message is checked in the data center in step 504 for plausibility and further evaluated by subsequently checking in step 505 whether the data has been transmitted without errors. If this is not the case, the error message branches back to step 513. If, on the other hand, the data are error-free and it is recognized in the data center that the franking machine has made an opening request and is requesting a new code word Y ', in step 506 a reply message to the franking machine is sent as a header. In step 507, it is checked whether the leader message including the end of the leader has been sent in step 506. If this is not the case, the process branches back to step 513.
In the franking machine it is checked in step 309 whether a header has now been sent or received as a reply message by the data center. If this is not the case, the method branches back to step 310 for display and a transaction request is then queried again in step 301. If a header has been received and the franking machine has received an OK message, the header parameters are checked in step 311 with regard to a telephone number change. If an encrypted parameter has been transmitted, there is no change in the telephone number and a branch is made to step 313 in FIG. 3b.
FIG. 3b shows the security processes of the franking machine in communication mode and, in parallel, that of the data center.
In step 313, the franking machine sends an encrypted start message to the data center. In step 314, the message is checked for communication errors. If there is a communication error, the method branches back to step 304 and an attempt is made again to establish the connection to the data center in order to send the start message encrypted.
This encrypted start message is received by the data center if the header message had been sent completely in step 506 and the header end was transmitted in step 507. In step 508 it is checked in the data center whether it has received the start message and whether the data is OK. If this is not the case, step 509 checks whether the error can be remedied. If the error cannot be remedied, a branch is made to step 513. Otherwise, error handling is carried out in step 510 and branching to step 507. If the receipt of correct data is determined in step 508, the data center begins a transaction in step 511. In the aforementioned example, a new code word Y 'is transmitted in encrypted form to the franking machine, which receives the transaction data in step 315.
In the following step 316, the data is checked. If there is an error, the method branches back to step 310. Otherwise, the end message is waited for, which the data center sends encrypted to the franking machine in step 512. After receiving this end message in step 317, the transaction is also carried out in step 318 in the franking machine. A new code word Y 'is now stored in the franking machine and the process branches back to step 305. If no further transaction is to take place, step 310 and then step 301 are reached for display.
If no transaction request is now made, it is checked in step 211 whether data have been transmitted. If data has been transmitted, step 213 is reached. In accordance with the input request, the franking machine places the new code word Y ', for example, in the memory area E of the non-volatile memory 5.
If, however, a number combination other than zero is entered as input parameter in step 302 and the input was OK (step 303), a connection is established (step 304). And if there is a connection established without error (step 305) (step 306), an identification and header message is sent to the data center. In this opening message is again among others also contain the postage call-off number PAN for identifying the franking machine at the data center. If the data is correct (step 505), the data center recognizes from the combination of numbers entered that a credit has been added to the franking machine, for example, but no new code word Y 'is to be transmitted.
If the current telephone number of the data center has changed in the meantime, measures must be taken to save it in the franking machine. In step 506, the data center then sends a reply message with the elements change of the telephone number and current telephone number in unencrypted form. The franking machine receiving this message recognizes in step 311 that the telephone number should be changed. The process now branches to step 312 in order to save the current telephone number. The method then branches back to step 304. If the connection is still established and there is no communication error (305), a check is then carried out in step 306 as to whether another transaction should take place. If this is not the case, step 310 branches to step 301.
After the current telephone number has been saved, the franking machine automatically establishes a new connection to the data center with the aid of the new telephone number. The actual transaction intended by the user, a remote value specification of the new code word Y 'or a reload credit is thus carried out automatically, ie without any further intervention by the user of the franking machine. A corresponding message appears in the display that the connection is automatically re-established due to the change in the telephone number.
It is provided that after opening the housing, ie after an intervention, the housing of the postage meter machine is closed and that after the housing is closed, the postage meter machine is controlled in communication mode 300. The authorized person can also notify the data center of the completed check.
A communication can include a telephone number storage as well as a credit reload. This means that several transactions can be carried out without interrupting communication. If the amount of the credit to be topped up remains the same as for the last credit reload, only one transaction is necessary. This is done in the same way as when reloading a new code word Y '. If the amount of the credit to be reloaded is to be changed, two transactions are required. Both transactions take place in the same way as when reloading the new code word Y '. A message is sent during a transaction. Each transmitted message is encrypted individually. A successful transaction runs as follows: The franking machine sends its ID number and a default value for the amount of the reload credit requested, together with a MAC, to the data center. The latter checks such a transmitted message against the MAC in order to then send an OK message, which is also MAC-secured, to the franking machine. The OK message no longer contains the default value.
It is envisaged that the transmission of a new code word Y ', a change in the amount of credit reloading and a new credit to be reloaded in encrypted form, but the transmission of telephone number in unencrypted form. If it is determined in the data center that the connection to the franking machine has been terminated (step 503) or that there are faulty data (505) or unrecoverable errors (509) or that no leader has been sent (507), the communication is ended. After an error message, the communication connection is released, the transmitted data is saved and evaluated in step 513 by the data center.
A transaction request leads to a specially secured credit reload in the franking machine. The postal registers present outside the processor in the cost center memory 10 are preferably also secured by means of a time control during the credit reload. If, for example, the franking machine is observed with an emulator / debugger, then it is likely that the communication and accounting routines will not run within a predetermined time. If this is the case, ie the routines take considerably more time, part of the DES key is changed. The data center can determine this modified key during a communication routine and then report the franking machine as suspect as soon as a start message is encrypted in accordance with step 313.
In the data center, step 509 determines that the error cannot be remedied. The data center cannot then carry out a transaction (step 511) because the process branches back to step 513. Since no data was received in the franking machine in step 315, the transaction was not carried out without errors (step 316). The system then branches back to step 301 via step 310 in order to check again after a display whether a transaction request is still being made.
If this is not the case, communication mode 300 is exited and point f, ie operating mode 290, is reached. Thus, in the case discussed above, no data could be transmitted using modified DES keys (step 211). It is also assumed that neither a test request (step 212) nor a register call (step 214) has been initiated in order to check the remaining credit. But then the franking mode 400 is reached.
In another variant, the keys (crypto keys) relevant for the transmission of the data required for a credit reload, which have been stored in the memory in cryptified form, are also completely deleted if there is an unauthorized intervention in the franking machine. As has already been explained in connection with FIG. 7, the authorization to open can be obtained after an opening request by reloading a new code word Y '. FIG. 7 shows a corresponding flow chart for the introduction of code words according to the solution according to the invention.
Another way to implement the kill mode is to partially delete the postal registers, which are stored in redundant form. The redundancy is specifically reduced in a predetermined manner. This reduction in redundancy should differ from other data errors that can be remedied automatically by the franking machine, as is explained in more detail in the pending European application with the official file number 93 103 951.5. There, a method for correcting the storage of security-relevant data in a postage meter machine is proposed, redundantly stored data being compared with one another in order to reload a memory area with incorrect data with error-free data. However, this is no longer possible with a sixth type of error, because all redundantly stored data now have different errors which can no longer be corrected automatically. Only a service technician could reconstruct the data in a predetermined manner, which has to be done after each authorized opening before the franking machine is started up again.
The franking machine hardware is also accessible in a known manner through a lockable flap which must be opened using a security key. A further threshold for manipulation is the seal to be broken or the seal number to be overcome, which is also stored outside the franking machine in the data center. The data center provides feedback information to the post office or the inspector, who visually checks the seal on site and compares it with the internally stored seal number displayed.
Security requires the authorized opening, the reliability of the authorized person (service, inspector) and the poss checking their presence. The control of the seal and the control of the register status during an inspection of the franking machine and regardless of the data in the data center then results in the security of the verification. The control of the franked mail, including a security imprint, provides additional security.
The franking machine carries out the register check regularly and / or when it is switched on and can thus recognize the missing information if the machine had been opened without authorization. The franking machine is then blocked. Without the invention in connection with a code word Y, the manipulator would easily overcome the blocking. However, the code word is lost and it would take too much time and effort for the manipulator to determine the valid code word by trials. In the meantime, the franking machine would have long been registered as suspect in the data center.
The potential manipulator of a franking machine has to overcome several thresholds, which of course takes a certain amount of time. If there is no connection from the franking machine to the data center at certain time intervals, the franking machine becomes suspect. It can be assumed that those who tamper with the franking machine will hardly report to the data center again.
According to the invention, a potential fraudster who cannot access the stored data for the reasons mentioned above is additionally prevented from manipulating the print control signal to the print head. He might be tempted to inject variable pixel image data manipulated during column printing into the print control signal. The franking machine is usually operated at high to maximum printing speeds. A manipulation of the print control signal for the printhead results in a changed timing that could only be simulated comparably at a lower printing speed.
The printhead is arranged in the franking machine in such a way that it cannot be used without a transport device in order to generate an unpaid franking stamp. Such an arrangement can be seen, for example, from US 4,705,417. However, other arrangements with print heads based on a different printing principle are also conceivable, which cannot be used without the transport device.
Since the print head cannot be used without a transport device in order to generate an unpaid franking stamp, the transport speed or the printing speed is monitored. If a thermal transfer printer is used, it is sufficient to evaluate the ribbon speed of the ribbon, which is already measured using an encoder. The encoder pulses are counted within a time window which is supplied by the clock / date module 8 or is derived from the system clock of the control device 6. The system clock is generated by means of a quartz-controlled clock generator (not shown in FIGS. 1a and 1b). If the number of encoder pulses deviates from a target number, the motor 12 is readjusted accordingly. If the target / actual deviation has increased beyond a permissible level, there is an error. This error is logged and may result in the franking machine being shut down.
In step 202 of the flow chart - shown in FIG. 2a - it can then be checked whether the printing speed is maintained or whether it deviates from the permissible value. If this criterion is met, a corresponding warning is given in the display, which ultimately leads to the franking machine being blocked if it is not observed.
Another variant checks the passage of time in column-by-column printing by comparing the time period for printing the individual columns in which variable data occur. In particular, the number of clock pulses of the quartz-controlled clock generator can be counted between the individual encoder pulses. In a step 207 it can then be checked whether the time lapse has been observed or whether it deviates from the permissible time lapse. If this criterion is met, a measure for blocking the franking machine is carried out in a further step 208. The printing speed is hardly reduced by the system routine or time required to secure the franking machine in the operating mode.
By tapping all the time reserves during printing, through the microprocessor of the control device, which embeds window data column by column, there is hardly any space or time left for manipulation. However, the method according to the invention is not limited to such fast franking machines. It is crucial to monitor the printing speed for any deviations in the course of time that may have been caused by manipulation, in order to prevent manipulation of the pressure control signal in addition to the other security measures already taken.
The control device 6 has a microprocessor or an OTP. In addition to a microprocessor, the OTP also houses non-volatile memories and other circuits in a common housing. The internal non-volatile memory includes, for example, program memories and other data memories, in particular also the possibility of setting save bits which prevent the internal non-volatile memory from being read from the outside. These security bits are set in the OTP during the manufacture of the franking machine. Observing such security-relevant routines, such as billing routines, with an emulator / debugger would also lead to a changed time sequence, which can be determined by the OTP. This also includes a clock generator / counter circuit for specifying time intervals or clock cycles, for example for time-out generation or printer control. When a certain time has elapsed and the expected event has not occurred, the clock / counter circuit generates an interrupt which reports to the microprocessor that the time has elapsed without success, whereupon the microprocessor takes further measures. According to the clock generator / counter circuit is used for program runtime monitoring. A known number of clock cycles for the program execution of predetermined program parts is assumed. Before starting the routine, the counter of the clock / counter circuit is preset or reset in a predetermined manner. After the start of the program routine, the counter status is continuously changed in accordance with the clock pulses of the clock generator. After the critical predetermined program parts have been processed, the state of the counter is queried by the microprocessor and compared with the expected value.
If there is a predetermined deviation in the runtime of critical or safety-relevant program parts, a flag is set in a memory, which is queried in step 207. If this query criterion is present, a branch is made to step 208. The franking machine can therefore no longer be operated for franking (kill mode 1).
In an advantageous further variant of the time control, the code word Y in the SRAM 24 is deleted via the control line C. This can be done in connection with the address line A and the data line D by overwriting with a predetermined other word, for example 0000. The advantage is in particular that even without a sensor 21 or if for some reason the sensor 21 was ineffective, the detector device 20 still responds to manipulation, which of course must have been preceded by unauthorized opening.
Other variants or a combination with other variants, such as, for example, deleting a part of the DES key or the redundant register status or deleting other data or keys which are of importance for the data center in a transaction, are included in the inventive concept. It is essential that critical program parts are stored in the OTP and the program runtime monitoring means are software and / or hardware components of the OTP. With these program parts, the critical programs stored externally by the OTP in the program memory PSP 11 can be monitored. The advantage is that the monitoring program itself cannot be observed or manipulated, since it remains in the OTP and cannot be read out. In combination with the sensor 21, higher security is thus achieved.
In a disassembled variant, the sensor 21 is saved because the housing is otherwise adequately secured and the monitoring function is performed in the aforementioned manner by the detector device 20 which is effective in conjunction with appropriate software. In a variant not shown in FIG. 1b, the detector device 20 can also be part of the processor (OTP). This device 20 is preferably designed as a non-volatile memory that cannot be read externally. A suitable processor type is, for example, the TMS 370 C010 from Texas Instruments, which has a 256 bytes E²PROM. If a manipulator carries out an unauthorized intervention, the franking machine is effectively put out of operation by being switched to the first mode.
During an inspection, the seal of the franking machine is first checked for integrity and then the register status. If necessary, a test impression with the value 0 can be made. In the event of a repair by the on-site service, the franking machine may have to be accessed. The error registers can be read out, for example, with the help of a special service EPROM, which is inserted in the place of the advert EPROM. If the processor does not access this EPROM slot, access to the data lines is usually prevented by special driver circuits (not shown in FIGS. 1a and 1b). The data lines, which can be reached here through a sealed housing door, cannot be contacted without authorization. Another variant is the reading out of error register data by a service computer connected via an interface. In preparation for the intervention, the registers of the franking machine are queried in order to determine the type of intervention required. Before intervening in the franking machine and opening the housing, a separate call is made to the data center. If the default value is then changed to zero within a predetermined period of time and transmitted to the data center as part of a transaction, ie the type of intervention and the register data were communicated to the data center, data is transmitted from a data center to the franking machine in accordance with a requested authorized intervention in the franking machine, which is logged as an allowed intervention.
However, if the default value is changed to a value other than zero within a predetermined period of time and transmitted to the data center as part of a transaction, a previous call to the data center remains without consequences, ie an application to open is deemed not to have been made and an authorization to intervene (authorization to open) The franking machine is not issued and consequently no new code word Y 'is transmitted.
The franking machine is able to distinguish between requested and unauthorized intervention in the franking machine by means of the control unit of the franking machine in connection with the data transmitted by the data center, this intervention being logged as an error in the event of unauthorized intervention in the franking machine. but after authorized intervention in the franking machine, the original operating state is restored using the aforementioned transmitted data.
It is also provided at times when there is no printing (standby mode) that a query regarding manipulation attempts is made and / or the checksum of the register statuses and / or the content of the program memory PSP 11 is formed. To improve the security against manipulation, the check sum for the kill mode 2 is formed in the OTP via the content of the external program memory PSP 11 and the result is compared with a predetermined value stored in the OTP. This is preferably done in step 101 when the postage meter machine is started, or in step 213 when the postage meter machine is operated in standby mode. Standby mode is reached if there is no input or Print request is made. The latter is the case when a letter sensor known per se - not shown in detail - does not determine the next envelope to be franked. The step 405 in the franking mode 400, shown in FIG. 4b, therefore includes a further query for a time lapse or for the number of passes through the program loop, which ultimately leads back to the input routine according to step 401. If the query criterion is met, a standby flag is set in step 408 and a branch is made back directly to the point s to the system routine 200, without the billing and printing routine being executed in step 406. The standby flag is queried later in step 211 and reset after the checksum check in step 213 if no attempted manipulation is detected.
To this end, the query criterion in step 211 is expanded to include the question of whether the standby flag is set, ie whether the standby mode has been reached. In this case, a branch is also made to step 213. A preferred variant consists in deleting the code word Y in a manner already described if a manipulation attempt in standby mode has been determined in step 213 in the aforementioned manner. The absence of code word Y is recognized in step 207 and then branched to step 208. The advantage of this method in connection with the first mode is that the manipulation attempt is statistically recorded in step 213.
In order to further increase security against manipulation, a flow control is used according to the invention, which is explained below. Such a flow control is carried out by changing a count value in a memory at at least one point during the execution of the program routine. After execution of the program routine, the changed count value is compared with a predetermined count value assigned to this program routine. If branches are run through during program execution, different count values can result. In a subsequent evaluation, a plausibility test is carried out or it can be determined which branches have been run through. This is possible because the change in the count value takes place by multiplication by a specific prime number assigned to the respective program part. In a later evaluation, only a prime number decomposition then has to be carried out.
In another variant, where only such program parts without branches are taken into account or no tracing of the program branches that have been run through is necessary, an incrementing of the count value and a final comparison with at least one predetermined numerical value is sufficient.
The processes according to the franking mode shown in FIG. 4a are explained in connection with the block diagram shown in FIG. 1a.
The invention is based on the fact that, after switching on, the postage value in the value print corresponding to the last entry before switching off the franking machine and the date in the day stamp corresponding to the current date are automatically specified that the variable data in the fixed data for the frame are to be printed and be electronically embedded for all associated data that remain unchanged. These variable data of the window contents are referred to below as window data and all fixed data for the value stamp, the day stamp and the advertising slogan stamp as framework data. The frame data can be taken from a first memory area of a read-only memory (ROM), which also serves as a program memory 11. The window data are taken from a second memory area and correspond to the input in memory areas B.<sub>j</sub> of the non-volatile working memory 5 is stored. They can be removed at any time for the purpose of assembling them into an overall representation of a franking image. It is provided that the hexadecimal window data in run-length-coded form in the separate memory areas B₁ to B₄ of the non-volatile working memory 5 to transfer and store there. In addition, the time in the clock / date module continues to run even when the franking machine is switched off. If step 401 is thus reached in franking mode 400, data that has already been stored can be accessed even without input after the franking machine has been switched on. This setting relates in particular to the last setting of the postage meter with regard to the postage value, which is displayed in step 402 before the print data preparation takes place in step 403. The current variable pixel image data (date and postage value) are embedded in the fixed frame pixel image data. The input means are then queried in step 404 for any further inputs.
According to the invention, the data from the two memory areas are combined into a pixel print image in accordance with a predetermined assignment before printing. The variable information in the window provided can be supplemented and modified later. In order to save time, only those parts of a graphic representation that are actually changed are stored in the non-volatile working memory when a change is made. In the program memory 11 there is a first memory area A (for the data of the constant parts of the franking image, among other things, the advertising slogan frame). The sub memory areas A<sub>i</sub> frame or fixed data are provided for i = 1 to m, an assigned index i identifying the respective frame, which is preferably assigned to a specific cost center. The corresponding assignment of the respective cost center to the framework data is automatically queried after switching on. In another variant, the cost center must be re-entered into the memory area C each time it is switched on during the start routine, while it is retained in the event of brief interruptions in the operating voltage.
All alphanumeric characters or symbols are stored in pixel memory 9 as binary data. Data for alphanumeric characters or symbols are stored in compressed form in the non-volatile working memory 5 in the form of a hexadecimal number. As soon as the number of the cost center entered is stored in the memory area C, the compressed data from the program memory 11 are converted with the aid of the character memory 9 into a print image having binary pixel data, which is stored in such a decompressed form in the volatile main memory 7 (step 403). Working memories 7a, 7b and pixel memory 7c are used below to explain the invention, although this is physically preferably a single memory chip.
The memory areas in the non-volatile working memory 5 can contain a large number of sub-memory areas, under which the respective data are stored in data records. The sub memory areas B<sub>j</sub> are provided for j = 1 to n window data, different assignments between the sub-storage areas of the different storage areas being stored in a predetermined manner.
In each data record of a sub memory area A<sub>i</sub>, B<sub>j</sub> control code and run length-coded frame or window data are contained alternately one after the other. Before printing, in step 403 the respective selected fixed data are transferred from the non-volatile program memory (PSP) 11 into the registers 100, 110, 120, ..., of a volatile working memory 7a, control code being decoded during the transfer and in a separate memory area of the working memory 7b. The respective selected window data for the postmark and the postage stamp are also loaded into registers 200, 210, 220, .... The registers of sub-memory areas are preferably formed in the memory area of the main memory 7a. In another variant, these aforementioned registers are part of the microprocessor control 6. By decompression, the run-length-coded hexadecimal data are converted into corresponding binary pixel data.
The constant parts of the franking image, once called up, are constantly decoded available in the pixel memory area I in the volatile pixel memory 7c. For a quick change of the window data, there is a second memory area B in the non-volatile working memory 5.
The number strings (sTrings), which are entered for the generation of the input data with a keyboard 2 or via an electronic balance 22 connected to the input / output device 4 and calculating the postage value, are automatically stored in the memory area D of the non-volatile working memory 5. In addition, data records of the sub-storage areas remain, for example B<sub>j</sub>, C etc. received. This ensures that the last input values are retained even when the franking machine is switched off, so that after switching on the postage value in the value print corresponding to the last entry before switching off the franking machine and the date in the day stamp according to the current date is automatically specified. If a scale 22 is connected, the postage value is taken from the storage area D. In step 404, it is waited until there is one currently stored. If the input request is repeated in step 404, the process branches back to step 401. Otherwise, the process branches to step 405 to await the print output request. The letter to be franked is detected by a letter sensor and thus a print request is triggered. It is thus possible to branch to the accounting and printing routine in step 406. If there is no print output request (step 405), the process branches back to step 401 (point d) or - according to a variant shown in FIG. 4b - to step 301 (point e).
If, according to the other variant - shown in FIG. 4b - instead of point d instead of point d and step 301 is reached, a communication request can be made at any time or another input can be made in accordance with the steps test request 212, register check 214, input routine 401 . Further steps 401 to 404 are carried out, as in the variant according to FIG. 4a. A further query criterion can be queried in the subsequent step 405 in order to set a standby flag in step 408 if there is still no print output request after a predetermined time. As already explained above, the standby flag can be queried in step 211 following communication mode 300. This does not branch to franking mode 400 until the checksum check has shown that all or at least selected programs are complete.
If a print output request is recognized in step 405, further queries are made in the subsequent optional steps 409 and 410 and in step 406. For example, in step 409 the presence of a kill mode flag set in step 208 (FIG. 2b), in step 410 the achievement of a further quantity criterion and / or in step 406 the register data which has been drawn in for billing in a known manner. If the number of items predetermined for franking was used up in the previous franking, ie number of items equal to zero, the system automatically branches to point e in order to enter communication mode 300 so that a new predetermined number of items S is again credited by the data center. However, if the predetermined number of pieces had not yet been used, the process branches from step 410 to the billing and printing routine in step 406.
The number of printed letters and the current values in the mail registers are registered in a non-volatile memory 10 of the franking machine in accordance with the entered cost center in a billing routine 406 and are available for later evaluation. A special sleeping mode counter is caused to continue counting during the accounting routine which takes place immediately before printing.
If necessary, the register values can be queried in display mode 215. It is also provided that the register values are printed out with the print head of the franking machine for billing purposes. This can be done, for example, in the same way as is already explained in more detail in German Offenlegungsschrift P 42 24 955 A1.
In another variant, it is also provided that variable pixel image data are also embedded in the remaining pixel image data during printing. According to the position report provided by the encoder 13 about the feed of the postal items or Strip of paper in relation to the printer module 1, the compressed data are read from the main memory 5 and converted with the aid of the character memory 9 into a printed image having binary pixel data, which is also stored in such a decompressed form in the volatile main memory 7. Further details can be found in European applications EP 576 113 A2 and EP 578 042 A2.
The pixel memory area in the pixel memory 7c is therefore provided for the selected decompressed data of the fixed parts of the franking image and for the selected decompressed data of the variable parts of the franking image. After billing, the actual printing routine takes place (in step 406).
As can be seen from FIGS. 1a and 1b, the main memory 7b and the pixel memory 7c are connected to the printer module 1 via a printer controller 14 which has a print register (DR) 15 and output logic. The pixel memory 7c is connected on the output side to a first input of the printer controller 14, at whose further control inputs there are output signals from the microprocessor control device 6.
If all columns of a print image have been printed, the system routine 200 branches back.
The flowchart for a security system shown in FIG. 2a has steps 201 to 206 for monitoring further criteria. If one of the security criteria is violated, the franking machine enters a sleeping mode, for example if a connection to the data center has not yet been established after the consumption of a predetermined number of pieces. A detail of the flowchart for a first sleeping mode variant is explained on the basis of FIG. Starting from the system routine 200, the franking machine enters a step 201 in which current data S and S<sub>ref</sub> be called. The franking machine contains a permanently stored quantity comparison value S<sub>ref</sub>. In accordance with the amount of credit currently topped up during communication, a sleeping mode quantity S was calculated internally, which is subsequently decremented with each franking. This continues until the quantity comparison value S<sub>ref</sub> is reached. If this is determined in step 202, a warning, for example "TELESET", is given in step 203 in order to request the user of the franking machine to communicate with the data center. This display results in a delay t<sub>n</sub> in the operation of the franking machine. In the subsequent step 204, the delay for a next display with the duration t<sub>k</sub> but increments the piece number comparison value by the value n before branching to step 207. This ensures that the request to establish communication with the data center becomes more and more urgent, because the franking machine lingers longer and longer in step 203. However, if communication 300 was carried out, data was transmitted (step 211) and stored in area G of the non-volatile memory 5 of the postage meter machine during the statistics and error evaluation mode.
The franking machine and the data center each agree on a predetermined number of items S, ie the amount that can be franked until the next connection is established. If communication fails (quantity control), the franking machine slows down its mode of operation (sleeping mode variant 1). In step 201, the reset variables t are thus the current data<sub>n</sub> or values S and S<sub>ref</sub> called. If it is determined in the data center which number of items is to be franked until the next connection, saved historical data on the reloading or franking behavior (number of items of mail with average postage) must be used. The transmission of a new number of pieces S 'can then take place in the same manner as has already been explained in connection with the transmission of the new code word Y'. In the case of communication in accordance with FIGS. 3a and 3b, a new predetermined number of items S 'is then transmitted and decremented as number of items S with franking in progress. The new predetermined number of items S 'becomes the comparison item S internally<sub>ref</sub> calculated (step 213).
FIG. 6 shows the modified schedule for a second sleeping mode variant. Steps 100 to 105 and 210 have not been shown. After calling up the transmitted current data in step 201, the piece number S to be decremented is compared in step 202 with a comparison piece number. The comparison piece number is determined by dividing a maximum piece number S<sub>Max</sub> by a number k. If the criterion is met, step 203 is displayed again, which briefly displays the warning, for example “CALL FP”. Then in step 204 the new maximum number of pieces S<sub>Max</sub> formed by a division with a further number m, which would be necessary for the next comparison in step 202 if there is no communication with the data center or no credit reloading. This means that you can continue working until the next quantity limit without displaying a warning. However, it is possible at increasingly shorter intervals, ie after a predetermined number of frankings, issue a renewed warning, which thus more and more urgently draws attention to the need for communication with the data center. Franking is not affected. As long as the check in step 205 shows that the number of pieces S is even greater than zero, step 207 is reached. Only the warning appears more and more often in the display. Otherwise, a branch is made to step 206, for example setting a FLAG which is queried later in step 301 and evaluated as a communication request. In step 206, an additional indication can also be given that the communication is now taking place automatically and until the franking function is at rest until the communication has been successfully completed. The franking machine user can of course call up the communication mode at any time beforehand.
Another variant does not require step 204 shown in FIG. 6. A permanent warning for an impending bedding of the franking function is issued in step 203, because it must now be run through in step 202 due to the fulfilled query criterion before step 205 is reached. It is further provided that step 203 comprises a sub-step for error statistics in accordance with the statistics and error evaluation mode 213.
The franking machine requires a connection to the data center in the manner known from US Pat. No. 3,255,439. If the connection is established, the data center checks the register status. If the reload cannot be carried out, the data center prevents it from further operation by means of a signal transmitted to the franking machine. If the connection was established shortly after the signaling carried out by the franking machine and the register readings were not criticized, the franking machine can be switched back into the operating mode without any further extraordinary inspection. For this purpose, new current data are transmitted, for example for a credit and for the permitted number of pieces, which can be franked until the next connection is established.
The data center can differentiate between automatic and normal communication based on the transmitted signaling code. The former will always take place if the user of the franking machine has overlooked or ignored the requests for communication and has omitted appropriate input actions. In the event of repetition, if a manipulation is suspected, a special inspection can be arranged.
It is provided that the current data called up in step 201 immediately after communication has a calculated or transmitted specific number S 'as number S and a maximum number S<sub>Max</sub> include. The comparison piece number S<sub>ref</sub> for a first piece number criterion corresponds to the calculated or transmitted maximum piece number S divided by the number k<sub>Max</sub>. If the first quantity criterion for the second mode queried in step 202 is branched to the following step 203, which includes a constant warning that the franking machine function is about to go to sleep or a request to communicate again with the data center, before step 205 to check the data is achieved by means of a further quantity criterion. If the further quantity criterion is not met, a step 206 is carried out to automatically request the franking machine to communicate. During a communication with the data center, the transaction data are transmitted individually and serially, which comprise at least one decision criterion secured by a MAC, whereby the automatic communication request is canceled if the transaction was successfully carried out. Previously, in step 306 of the communication mode 300 - shown in FIG. 3a - it was determined that no further transaction is required and, after display (step 310), the user is returned to point e. If no further transaction requests are then entered manually, the method branches from step 301 to the operating mode (point f).
If communication has not yet been established after a predetermined time or, for example, the data center is busy, ie no line is free, this is evaluated in step 305 as a communication error. The process then branches back to step 304 and a redial is made up to a predetermined number. If this predetermined number has been reached, the system branches back from step 305 to point e via display step 310. In addition, in step 305, if n redial attempts were unsuccessful, a communication flag which may have been set can be reset, so that in step 301 no further transaction requests are recognized in this regard. In addition, a standby flag can be set at the same time, which is recognized again in step 211. Thus, the content of the program memory (PSP) 11 is checked in step 213 for statistical and error evaluation on the basis of a checksum or other tests are carried out. After these tests, the standby flag is reset and branched back to the system routine 200 points.
If, according to FIG. 4b, the other variant is used for the franking mode 400, which includes a step 410, then no standby flag needs to be set. The franking mode can then be branched back directly to the communication mode 300 point e. This means that other inputs can also be made, for example in accordance with the steps of test request 212 or register check 214. Only if a branch is made to franking mode 400 is it then determined again in step 410 according to the decision criterion whether automatic communication is required. This is preferably the case if the predetermined number of pieces has been used up.
If the communication was successful and data was transmitted (queried in step 211), step 213 is also reached. In step 213, the current data are determined or loaded, which are called in step 201 and then required again in the comparison in step 202. The transmitted decision criterion is preferably the new number S '.
An alternative variant consists in that the decision criterion is the new credit transmitted for franking and in evaluation mode 213 the new number S 'is determined internally in the franking machine. In this case, communication with the data center no longer includes the new number S ', but is only required to trigger the calculation in evaluation mode 213. The calculation is carried out internally in the franking machine and at the same time in parallel in the data center using the same methods based on the transmitted register data.
The franking machine can transmit register values to the data center before reloading the credit: R1 (descending register) remaining amount in the franking machine, R2 (ascending register) amount of consumption in the franking machine, R3 (total resetting) the total sum of all remote values, R4 (piece count printing with value <img file="EP0660269A2_D0003.tif" /> O) number of valid prints, R8 (R4 + piece count Σprinting with value = O) Number of all prints it follows:<maths id="math0003" num=""><math display="inline"><mrow><mtext>R3 = R2 + R1 (1)</mtext></mrow></math><img file="EP0660269A2_D0004.tif" /></maths> With each remote value specification, R1 can be queried and statistically evaluated. If R1 becomes larger and larger, the same reload amount can be reloaded in ever larger reloading periods, or the number of pieces that can be franked until the next communication is set.
The quantity can be calculated from the average quantity S<sub>O</sub>which has a disposition quantity S<sub>x</sub> added is determined. The following applies:<maths id="math0004" num=""><math display="inline"><mrow><msub><mrow><mtext>S '= S</mtext></mrow><mrow><mtext>O</mtext></mrow></msub><msub><mrow><mtext> + S</mtext></mrow><mrow><mtext>x</mtext></mrow></msub><mtext> (2)</mtext></mrow></math><img file="EP0660269A2_D0005.tif" /></maths><maths id="math0005" num=""><img file="EP0660269A2_D0006.tif" /></maths> The queried register values are provided with the index "old". A value R taken from the ascending register<sub>2old</sub> corresponds to the current query value. The future value R results in accordance with a default request that must be added to the current query value<sub>2 new</sub>. The disposition quantity S<sub>x</sub> depends on the classification of the franking machine user as an A, B or C customer.
In a further variant, the disposition quantity S<sub>x</sub> depending on the classification α<sub>x</sub> of the franking machine user as an A, B or C customer and additionally determined depending on their franking behavior<maths id="math0006" num=""><math display="inline"><mrow><msub><mrow><mtext>S</mtext></mrow><mrow><mtext>x</mtext></mrow></msub><msub><mrow><mtext> = α</mtext></mrow><mrow><mtext>x</mtext></mrow></msub><msub><mrow><mtext> * R</mtext></mrow><mrow><mtext>8old</mtext></mrow></msub><msub><mrow><mtext> * R</mtext></mrow><mrow><mtext>1old</mtext></mrow></msub><msub><mrow><mtext>/ R</mtext></mrow><mrow><mtext>2old</mtext></mrow></msub><mtext> (5</mtext></mrow></math><img file="EP0660269A2_D0007.tif" /></maths> ) or.<maths id="math0007" num=""><math display="inline"><mrow><msub><mrow><mtext>S</mtext></mrow><mrow><mtext>x</mtext></mrow></msub><msub><mrow><mtext> = α</mtext></mrow><mrow><mtext>x</mtext></mrow></msub><msub><mrow><mtext> * R</mtext></mrow><mrow><mtext>4old</mtext></mrow></msub><msub><mrow><mtext> * R</mtext></mrow><mrow><mtext>1old</mtext></mrow></msub><msub><mrow><mtext>/ R</mtext></mrow><mrow><mtext>2old</mtext></mrow></msub><mtext> (6)</mtext></mrow></math><img file="EP0660269A2_D0008.tif" /></maths> The behavior of the franking machine user is monitored by the data center on the basis of data transmitted during the communication in order to identify suspicious franking machines. A corresponding suspicious mode can only be activated by the data center, with no direct effects on the franking machine.
A franking machine profile can be created on the basis of the franking machine-specific data. This franking machine profile provides information as to whether a customer was able to carry out the determined number of frankings with the reloading processes carried out. There are two levels within Suspicious Mode:<ul id="ul0002" list-style="none"><li>1. Franking machine is suspicious and</li><li>2nd Franking machine must have been manipulated.</li></ul>
Various franking machine-specific data can flow into the calculation for determining the franking machine profile. In the range between a minimum franking value F<sub>min</sub> and a maximum franking value F<sub>Max</sub> the franking machine permits valid prints which are registered in the register for R4. A zero value franking can also be made. The following formulas are used one after the other:<maths id="math0008" num=""><img file="EP0660269A2_D0009.tif" /></maths> and also if R1old <img file="EP0660269A2_D0003.tif" /> R1 new<maths id="math0009" num=""><img file="EP0660269A2_D0010.tif" /></maths><dl id="dl0002"><dt>R1<sub>old</sub>:</dt><dd>R1 according to nth remote value specification</dd><dt>R1<sub>New</sub>:</dt><dd>R1 before n + 1st remote value specification</dd><dt>V<sub>susp</sub>:</dt><dd>heuristic value that provides information about the state of the franking machine</dd><dt>F<sub>min</sub>:</dt><dd>minimum franking value</dd></dl> With a minimum franking value of e.g. F<sub>min</sub> = 20 currency units results in the following case distinction: V<sub>susp1</sub> <5 okay (okay) V<sub>susp1</sub> = 5..100 suspicious V<sub>susp1</sub> > 100 manipulated A plausibility check of all franking machines in use is carried out in the data center at regular intervals. In this process, the machines are identified and reported to the postal authority whose franking behavior appears suspicious or has been manipulated.
Another security measure (error overflow mode) may be provided in the franking machine. In the second mode, this can be carried out in addition to or instead of sleeping mode variant 1 or sleeping mode variant 2. If the query criterion in step 202 is met, ie if a predetermined number of errors is exceeded, the reaction time of the postage meter machine slows down in step 203, this status being simultaneously reported to the operator of the postage meter machine via the display. In the further steps, the procedure can be similar to that already explained in connection with FIGS. 2 and 5. The postage meter machine stores both internal and operating errors and attempts at manipulation in an error register for logging purposes, for example up to the number 999. If the condition in which the number of errors has been exceeded is not eliminated, for example as part of an inspection by a service provider or by resetting during communication with the data center , the response time can be increased further to make any manipulation more difficult. The number of errors is then logged, ie again up to a predetermined number, for example in step 213.
A first variant provides for the reaction time, for example the time until the start of printing, to be increased linearly with the number of errors. The execution of the program is neither modified nor prevented, but only delayed. In particular, such non-critical program parts that are not monitored by time supervision (kill mode 1) or flow control are called several times, such as the error display. This means that the effectiveness of the program remains essentially unchanged.
In a second variant, the reaction time is increased by one level, whereby the levels can relate to seconds, minutes, hours, days, ... etc.
In a modification or in combination with the aforementioned variants, an increase in the response time can also be provided for each incorrect operation. In one embodiment, an electronic time lock is actuated for this purpose. A progressive increase in the response time is preferably provided in the operating program in order to make manipulation more difficult.
It is provided that step 213 is partially or completely called up as a sub-step in connection with other steps. For example, the statistics and error mode is part of step 203 and the billing and printing routine according to step 406 in franking mode 400, which is shown in more detail in FIGS. 4a and 4b. If a severe accounting error occurs, the machine is blocked in step 406 or step 208. However, if an error occurs during the initialization phase in step 101, the machine stops and displays a specific error code.
FIG. 2b shows a second variant for the flow chart according to the solution according to the invention. In step 207, not only is the structure check of the register data carried out, but step 207 also includes a check of the register contents. If the query criterion for a correct state does not match, a kill mode flag is set in step 208 to block the franking machine and then branched to point e. Therefore, even if the franking machine is blocked, all desired entries, communications with the data center, register displays or tests can be carried out further.
The kill mode flag is only queried in franking mode - in the manner shown in FIG. 4b - in step 409 before the actual billing and printing routine (step 406). If the kill mode flag is set, the statistics and error evaluation mode (step 213) and the display mode (step 215) are run through and then branched back to the system routine (point s).
The franking machine thus remains locked. On the one hand, the franking machine becomes operational again without activation if the error has been eliminated, ie if, for example, a letter jam has been cleared or a credit has been topped up.
On the other hand, there are serious errors that can only be remedied by an authorized person on the next inspection on site. Such an error, for example if the processor cannot access the main memory, ie can neither read nor change the data content of the RAM, is eliminated, for example, by inserting a special RESET EPROM. For this, the sealing of the flap and the franking machine must be opened. The RESET EPROM contains the necessary data, for example the aforementioned Y code, and special programs for restoring the franking machine function. For example, such a program can undo a reduction in redundancy. The logging of the errors, which takes place during the operation of the franking machine in the statistics and error evaluation mode (step 213) separately according to the types of errors, is checked by the authorized person to determine whether a manipulation attempt has been made.
The invention is not limited to the present embodiments. Rather, a number of variants are conceivable which make use of the solution shown, even in the case of fundamentally different types.
25 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0773517A2 | Cited by | European Patent Office (EPO) | Applicant |
| EP1035517A2 | Cited by | European Patent Office (EPO) | Applicant |
| EP1035516A2 | Cited by | European Patent Office (EPO) | Applicant |
| EP0779601A2 | Cited by | European Patent Office (EPO) | Applicant |
| EP1035518A2 | Cited by | European Patent Office (EPO) | Applicant |
| US5734571A | Cited by | United States of America | Search report |
| EP0773517A3 | Cited by | European Patent Office (EPO) | Search report |
| US6148292A | Cited by | United States of America | Search report |
| EP0780803A2 | Cited by | European Patent Office (EPO) | Applicant |
| US5926506A | Cited by | United States of America | Search report |
| EP0779601A2 | Cited by | European Patent Office (EPO) | Applicant |
| EP0194660A2 | Cites | European Patent Office (EPO) | Search report |
| GB2233937A | Cites | United Kingdom | Search report |
| US4347506A | Cites | United States of America | Search report |
| US4549281A | Cites | United States of America | Search report |
| US4812965A | Cites | United States of America | Search report |
16 members in 3 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 4344476 | Germany | A | |
| 4344476 | Germany | – | |
| 4344476 | – | – | – |
| DE19934344476 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| DE4344476A1 | Germany | A1 | |
| EP0660269A2This record | European Patent Office (EPO) | A2 | |
| EP0660269A3 | European Patent Office (EPO) | A3 | |
| US5671146A | United States of America | A | |
| US5805711A | United States of America | A | |
| EP0969421A2 | European Patent Office (EPO) | A2 | |
| EP0969422A2 | European Patent Office (EPO) | A2 | |
| EP0969423A2 | European Patent Office (EPO) | A2 | |
| EP0969421A3 | European Patent Office (EPO) | A3 | |
| EP0969422A3 | European Patent Office (EPO) | A3 | |
| EP0969423A3 | European Patent Office (EPO) | A3 | |
| EP0660269B1 | European Patent Office (EPO) | B1 | |
| EP0969421B1 | European Patent Office (EPO) | B1 | |
| EP0969422B1 | European Patent Office (EPO) | B1 | |
| DE59410432D1 | Germany | D1 | |
| DE59410433D1 | Germany | D1 |
41 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Name/firm changedPFA | PFA | CH | |
| European patent in force as of 2002-01-01IF02 | IF02 | GB | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| Fr: translation filedET | ET | EP | |
| Corresponds to:REF | REF | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| New agentNV | NV | CH | |
| Designated contracting statesAK | AK | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0660269
- Publication, DOCDB
- 0660269
- Publication, EPODOC
- EP0660269
- Application
- 94250223
- Application, DOCDB
- 94250223
- Application, EPODOC
- EP19940250223
Titles6
- German
- Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen
- English
- Method for enhancing franking machines security
- French
- Procédé pour améliorer la sécurité de machines à affrauchir
- German
- Verfahren zur Verbesserung der Sicherheit von Frankiermaschinen.
- English
- Method for enhancing franking machines security.
- French
- Procédé pour améliorer la sécurité de machines à affrauchir.
Classification
- CPC, 21
- G06F21/52
- G06F21/575
- G06F21/64
- G07B17/00
- G07B17/0008
- G07B17/00193
- G07B17/00733
- G07B2017/00096
- G07B2017/00169
- G07B2017/00233
- G07B2017/00258
- G07B2017/0033
- G07B2017/00338
- G07B2017/00346
- G07B2017/00403
- G07B2017/00419
- G07B2017/00427
- G07B2017/0075
- G07B2017/00774
- G07B2017/00935
- G07B2017/00951
- IPC, 5
- G06F21 52
- G06F21 57
- G06F21 64
- G07B17 00
- G07B17 04
Designated states1
- Contracting states, 1
- Liechtenstein