Method and device for enhancing manipulation-proof of critical data
Abstract
The control unit (6) has a microprocessor or an OTP (one-time programmable) processor that has, in addition to CPU (6a), other units in common housing, forming the OTP ROM (6b), and OTP ROM (6c) and acting as a security unit against unauthorised manipulation. The first non-volatile memory (NVM 20) is an EEPROM, serving as a second line of defence against manipulation. There is also an external non-volatile memory (NUM 25) acting in the same way connected to the processor (6) through an input/output control module (4), particularly against taking information out.

Term
Term ended
Projected expiry passed 6 September 2016, 10 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
29 claims: 29 independent, 0 dependent
- 1Methods for increasing the security against manipulation of critical data, in particular register data in franking machines, featured, through the steps:Loading a number or a pointer which is assigned to a code word into a first non-volatile memory (20 or 6d) which is secured against removal and manipulation,Loading a code word into second non-volatile memory (NVM 5a, 5b) containing the post register data, the code word being assigned to the last operating state of the postage meter machine or selected accordingly by the processor (6, 6a),- validity check of the code word at least at the time the franking machine is switched on and subsequently based on an event,- Replace the old code word with a predetermined new code word if the processor, after checking the validity with reference to the code word selected from a list of stored code words in accordance with the number or the position of the pointer in its internal processor memory (NVM 6c), the validity of the old code word acknowledges or- Blocking of the franking machine after the franking machine is switched on when the processor, after checking the validity with reference to the selected code word stored in the aforementioned list, revokes the validity of the old code word. Verfahren zur Erhöhung der Manipulationssicherheit von kritischen Daten, insbesondere von Registerdaten in Frankiermaschinen, gekennzeichnet, durch die Schritte: - Laden einer Zahl oder eines Zeigers, welcher einem Codewortes zugeordnet ist, in einen ersten nichtflüchtigen Speicher (20 bzw 6d), der gegen Herausnahme und Manipulation abgesichert ist,- Laden eines Codewortes in zweite die Postregisterdaten enthaltenden nichtflüchtigen Speicher (NVM 5a, 5b), wobei das Codewort dem letzten Betriebszustand der Frankiermaschine zugeordnet ist bzw. vom Prozessor (6, 6a) entsprechend ausgewählt worden ist,- Gültigkeitsprüfung des Codewortes mindestens zum Zeitpunkt des Einschaltens der Frankiermaschine und nachfolgend aufgrund eines Ereignisses,- Ersetzen des alten Codewortes durch ein vorbestimmtes neues Codewort, wenn der Prozessor, nach Gültigkeitsprüfung mit Bezug auf das in seinem internen Prozessorspeicher (NVM 6c) aus einer Liste mit gespeicherten Codewörten entsprechend der Zahl bzw. der Zeigerstellung ausgewählte Codewort, die Gültigkeit des alten Codewortes anerkennt oder- Blockierung der Frankiermaschine nach dem Zeitpunkt des Einschaltens der Frankiermaschine, wenn der Prozessor nach Gültigkeitsprüfung mit Bezug auf das ausgewählte in vorgenannter Liste gespeicherte Codewort die Gültigkeit des alten Codewortes aberkennt.
- 2Method according to claim 1, characterizedthat a last operating state of the postage meter machine corresponding to the code word means a state as a result of the manufacture or a reloading of the postage meter machine or as a result of the formation of a pseudo random sequence or a state before the franking machine is switched off or a state before a power failure or before a standstill or. before program interruption and that the validity check of the code word is carried out at least at the time the franking machine is switched on and subsequently at least on the basis of a pseudo-random sequence. Verfahren, nach Anspruch 1, dadurch gekennzeichnet, daß ein dem Codewort entsprechender letzter Betriebszustand der Frankiermaschine einen Zustand im Ergebnis der Herstellung oder einer Nachladung der Frankiermaschine oder im Ergebnis der Bildung einer Pseudozufallsfolge oder einen Zustand vor dem Ausschalten der Frankiermaschine oder einen Zustand vor einem Spannungsausfall oder vor einer Stillstandszeit (Stand by) bzw. vor Programmunterbrechung einschließt und daß die Gültigkeitsprüfung des Codewortes mindestens zum Zeitpunkt des Einschaltens der Frankiermaschine und nachfolgend mindestens aufgrund einer Pseudozufallsfolge in Abständen durchgeführt wird.
- 3Process according to claims 1 to 2, characterizedthat a new code word is loaded into the non-volatile memory (NVM 5a, 5b) to be protected, the program for calculating the pointer position or the formation of the respective new code word being stored in the program memory (PSP 11). Verfahren, nach den Ansprüchen 1 bis 2, dadurch gekennzeichnet, daß ein Laden eines neuen Codewortes in zu schützende nichtflüchtige Speicher (NVM 5a, 5b), erfolgt, wobei das Programm für die Berechnung der Zeigerstellung bzw. Bildung des jeweils neuen Codewortes im Programmspeicher (PSP 11) gespeichert ist.
- 4Process according to claims 1 to 3, characterizedthat the pointer outside the releasably installed non-volatile memory (NVM 5a, 5b) to be checked in the permanently installed and / or during the running time of the franking machine with its processor system in communication connection and secured against removal and manipulation during the running time of the franking machine is stored non-volatile and that the selection of the new code word depends on the previous one. Verfahren, nach den Ansprüchen 1 bis 3, dadurch gekennzeichnet, daß der Zeiger außerhalb des jeweils zu überprüfenden lösbar eingebauten nichtflüchtigen Speichers (NVM 5a, 5b) in dem ständig eingebauten und/oder während der Laufzeit der Frankiermaschine mit ihrem Prozessorsystem in Kommunikationsverbindung stehenden und gegen Herausnahme und Manipulation während der Laufzeit der Frankiermaschine abgesicherten ersten Sicherheitsspeicher nichtflüchtig gespeichert wird und daß die Auswahl des neuen Codewortes vom vorherigen abhängig ist.
- 5Process according to claims 1 to 4, characterizedthat the reload with a monetary credit, quantity S and / or other data takes place in a communication mode (300), that the number of formation of new code words is counted from a predetermined point in time and is stored non-volatile in the processor and at the time of communication with the data center the aforementioned number of code words formed in the past and the currently valid code word are queried, to overcome an unintentional blocking of the franking machine due to invalid code words or, if necessary, the subsequent restoration of the old state by appropriate data transmission from the data center to the franking machine. Verfahren, nach den Ansprüchen 1 bis 4, dadurch gekennzeichnet, daß die Nachladung mit einem monetären Guthaben, Stückzahl S und/oder anderen Daten in einem Kommunikationsmodus (300) erfolgt, daß die Anzahl der Bildung von neuen Codewörtern ab einem vorbestimmten Zeitpunkt gezählt und nichtflüchtig prozessorintern gespeichert wird und zum Zeitpunkt einer Kommunikation mit der Datenzentrale die vorgenannte Anzahl an in der Vergangenheit gebildeten Codewörtern und das aktuell gültige Codewort abgefragt wird, zum Überwinden einer unabsichtlichen Blockierung der Frankiermaschine aufgrund ungültiger Codewörter bzw. bei Bedarf die nachträgliche Wiederherstellung des alten Zustandes durch entsprechende Datenübermittlung seitens der Datenzentrale an die Frankiermaschine.
- 6Process according to claims 1 to 5, characterizedthat further criteria are monitored and such aforementioned last operating states occur in that the franking machine switches to a corresponding mode in the event of a violation of one of the security criteria, that the franking machine entered into a corresponding mode carries out steps (106 to 109) in additional corresponding subroutines of the method for increasing the security against manipulation of critical register data. Verfahren, nach den Ansprüchen 1 bis 5, dadurch gekennzeichnet, daß eine Überwachung weiterer Kriterien erfolgt und solche vorgenannten letzten Betriebszustände eintreten, indem die Frankiermaschine zu einem entsprechenden Modus bei einer Verletzung eines der Sicherheitskriterien übergeht, daß die in einen entsprechenden Modus eingetretene Frankiermaschine in zusätzlichen entsprechenden Subroutinen die Schritte (106 bis 109) zur Durchführung des Verfahrens zur Erhöhung der Manipulationssicherheit von kritischen Registerdaten ausführt.
- 7Process according to claims 1 to 6, characterizedthat a separate code word is assigned to each non-volatile memory or memory area, at least one of the aforementioned separate code words having been stored in a non-volatile manner in a further internal memory of a processor system, a chip card and / or a similar system, which is in communication connection with the processor system of the postage meter machine during the runtime of the postage meter machine and is secured against removal and manipulation during the runtime of the postage meter machine and that formation of new code words from a predetermined event and then storage of the new code words in the non-volatile memory to be protected and is made in the further non-volatile memories. Verfahren, nach den Ansprüchen 1 bis 6, dadurch gekennzeichnet, daß jedem nichtflüchtigem Speicher oder Speicherbereich ein separates Codewort zugeordnet wird, wobei mindestens eines der vorgenannten separaten Codeworte in einem weiteren internen Speicher eines Prozessorsystems, einer Chipkarte und/oder eines ähnlichen Systems nichtflüchtig gespeichert worden ist, welches während der Laufzeit der Frankiermaschine mit dem Prozessorsystem der Frankiermaschine in Kommunikationsverbindung steht und gegen Herausnahme und Manipulation während der Laufzeit der Frankiermaschine abgesichert ist und daß eine Bildung von neuen Codewörtern ab einem vorbestimmten Ereignis und danach eine Einspeicherung der neuen Codewörter in die zu schützenden nichtflüchtigen Speicher und in die weiteren nichtflüchtigen Speicher vorgenommen wird.
- 8Methods for increasing the security against manipulation of critical data, in particular register data in franking machines, featured, through the steps:Loading a code word into a first internal processor memory (NVM 6d) for non-volatile storage and into a second non-volatile memory (NVM 5a, 5b) containing the postal register data, the code word corresponding to the last operating state of the franking machine,- validity check of the code word at least at the time the franking machine is switched on and subsequently based on an event,- Replacing the old code word with a predetermined new code word if the processor recognizes the validity of the old code word after validity check with reference to the code word stored in its first non-volatile internal processor memory (NVM 6d) or- Blocking of the franking machine after the franking machine is switched on when the processor, after checking the validity with reference to the code word stored in its first non-volatile internal processor memory (NVM 6d), revokes the validity of the old code word. Verfahren zur Erhöhung der Manipulationssicherheit von kritischen Daten, insbesondere von Registerdaten in Frankiermaschinen, gekennzeichnet, durch die Schritte: - Laden eines Codewortes in einen ersten internen Prozessorspeicher (NVM 6d) zur nichtflüchtigen Speicherung und in zweite die Postregisterdaten enthaltenen nichtflüchtigen Speicher (NVM 5a, 5b), wobei das Codewort dem letzten Betriebszustand der Frankiermaschine entspricht,- Gültigkeitsprüfung des Codewortes mindestens zum Zeitpunkt des Einschaltens der Frankiermaschine und nachfolgend aufgrund eines Ereignisses,- Ersetzen des alten Codewortes durch ein vorbestimmtes neues Codewort, wenn der Prozessor nach Gültigkeitsprüfung mit Bezug auf das in seinem ersten nichtflüchtigen internen Prozessorspeicher (NVM 6d) gespeicherte Codewort die Gültigkeit des alten Codewortes anerkennt oder- Blockierung der Frankiermaschine nach dem Zeitpunkt des Einschaltens der Frankiermaschine, wenn der Prozessor nach Gültigkeitsprüfung mit Bezug auf das in seinem ersten nichtflüchtigen internen Prozessorspeicher (NVM 6d) gespeicherte Codewort die Gültigkeit des alten Codewortes aberkennt.
- 9Method according to claim 8, characterizedthat a last operating state of the postage meter machine corresponding to the code word means a state as a result of the manufacture or a reloading of the postage meter machine or as a result of the formation of a pseudo random sequence or a state before the franking machine is switched off or a state before a power failure or before a standstill or. before program interruption and that the validity check of the code word is carried out at least at the time the franking machine is switched on and subsequently at least on the basis of a pseudo-random sequence. Verfahren, nach Anspruch 8, dadurch gekennzeichnet, daß ein dem Codewort entsprechender letzter Betriebszustand der Frankiermaschine einen Zustand im Ergebnis der Herstellung oder einer Nachladung der Frankiermaschine oder im Ergebnis der Bildung einer Pseudozufallsfolge oder einen Zustand vor dem Ausschalten der Frankiermaschine oder einen Zustand vor einem Spannungsausfall oder vor einer Stillstandszeit (Stand by) bzw. vor Programmunterbrechung einschließt und daß die Gültigkeitsprüfung des Codewortes mindestens zum Zeitpunkt des Einschaltens der Frankiermaschine und nachfolgend mindestens aufgrund einer Pseudozufallsfolge in Abständen durchgeführt wird.
- 10Method according to claim 9, characterizedthat the reload with a monetary credit, quantity S and / or other data takes place in a communication mode (300), that the number of formation of new code words is counted from a predetermined point in time and is stored non-volatile in the processor and at the time of communication with the data center the aforementioned number of code words formed in the past and the currently valid code word are queried, to overcome an unintentional blocking of the franking machine due to invalid code words or, if necessary, the subsequent restoration of the old state by appropriate data transmission from the data center to the franking machine. Verfahren, nach Anspruch 9, dadurch gekennzeichnet, daß die Nachladung mit einem monetären Guthaben, Stückzahl S und/oder anderen Daten in einem Kommunikationsmodus (300) erfolgt, daß die Anzahl der Bildung von neuen Codewörtern ab einem vorbestimmten Zeitpunkt gezählt und nichtflüchtig prozessorintern gespeichert wird und zum Zeitpunkt einer Kommunikation mit der Datenzentrale die vorgenannte Anzahl an in der Vergangenheit gebildeten Codewörtern und das aktuell gültige Codewort abgefragt wird, zum Überwinden einer unabsichtlichen Blockierung der Frankiermaschine aufgrund ungültiger Codewörter bzw. bei Bedarf die nachträgliche Wiederherstellung des alten Zustandes durch entsprechende Datenübermittlung seitens der Datenzentrale an die Frankiermaschine.
- 11Method according to claim 9, characterizedthat further criteria are monitored and such aforementioned last operating states occur in that the franking machine switches to a corresponding mode in the event of a violation of one of the security criteria, that the franking machine entered into a corresponding mode carries out steps (106 to 109) in additional corresponding subroutines of the method for increasing the security against manipulation of critical register data. Verfahren, nach Anspruch 9, dadurch gekennzeichnet, daß eine Überwachung weiterer Kriterien erfolgt und solche vorgenannten letzten Betriebszustände eintreten, indem die Frankiermaschine zu einem entsprechenden Modus bei einer Verletzung eines der Sicherheitskriterien übergeht, daß die in einen entsprechenden Modus eingetretene Frankiermaschine in zusätzlichen entsprechenden Subroutinen die Schritte (106 bis 109) zur Durchführung des Verfahrens zur Erhöhung der Manipulationssicherheit von kritischen Registerdaten ausführt.
- 12Method according to claim 8, characterizedLoading a code word into the first internal processor memory (NVM 6d) for non-volatile storage and into a large number of second non-volatile memories (NVM 5a, 5b) containing the data to be assured, the old code word corresponding to the penultimate operating state of the franking machine for the large number of non-volatile memories (NVM 6d, NVM 5a and NVM 5b) is checked in step 107 and before the corresponding change of code words V and U a new code word W 'is first formed in step 108 and then a code word T' for the second processor-internal non-volatile memory (NVM 6d) the equations:(1)W ': = f {P1} and(2)T ': = f {P2} where P1 and P2 are different monotonously continuously changeable parameters, for example the current time, number of program interruptions or other program, time or physical parameters. Verfahren, nach Anspruch 8, dadurch gekennzeichnet, Laden eines Codewortes in den ersten internen Prozessorspeicher (NVM 6d) zur nichtflüchtigen Speicherung und in eine Vielzahl an zweiten die zusichernden Daten enthaltenen nichtflüchtigen Speichern (NVM 5a, 5b), wobei das alte Codewort dem vorletzten Betriebszustand der Frankiermaschine entsprechend für die Vielzahl nichtflüchtiger Speicher (NVM 6d, NVM 5a und NVM 5b) im Schritt 107 überprüft wird und vor der entsprechenden Veränderung von Codewörtern V und U zunächst im Schritt 108 ein neues Codewort W' und dannach ein Codewort T' für den zweiten prozessorinternen nichtflüchtigen Speicher (NVM 6d) gebildet wird, nach den Gleichungen:(1)W' := f {P1} und(2)T' := f {P2} wobei P1 und P2 verschiedene monoton stetig veränderbare Parameter sind, beispielsweise die aktuelle Zeit, Anzahl von Programmunterbrechungen bzw. andere Programm-, Zeit- oder pysikalische Parameter.
- 13Method according to claim 12, characterizedthat before a new code word is loaded, a count is incremented and then the new code word (W ', T', U ', V') is calculated. Verfahren, nach Anspruch 12, dadurch gekennzeichnet, daß vor dem Laden eines neuen Codewortes ein Zählwert inkrementiert und dann das neue Codewort (W', T', U', V') berechnet wird.
- 14Method according to claim 8, characterizedthat the formation of the new code word depends on the previous one, with NVM (6d, 20, 25 and 5a, 5b) for a first and second non-volatile memory after checking the old code word in step 107 and before the corresponding change of code words V and U first in step 108 a new code word W 'and then a code word T' is formed, according to the equations:(1)W ': = F {P1} and(2)T ': = F {P2}, where P1 and P2 are listed code words. Verfahren, nach Anspruch 8, dadurch gekennzeichnet, daß die Bildung des neuen Codewort vom vorherigen abhängig ist, wobei für einen ersten und zweiten nichtflüchtige Speicher NVM (6d, 20, 25 und 5a, 5b) nach Uberprüfung des alten Codewortes im Schritt 107 und vor der entsprechenden Veränderung von Codewötern V und U zunächst im Schritt 108 ein neues Codewort W' und dannach ein Codewort T' gebildet wird, nach den Gleichungen:(1)W' := F {P1} und(2)T' := F {P2}, wobei P1 und P2 gelistete Codewörter sind.
- 15Method according to claim 8, characterizedthat a new code word is loaded, the program for calculating the new code word being stored in the program memory (PSP 11). Verfahren, nach Anspruch 8, dadurch gekennzeichnet, daß ein Laden eines neuen Codewortes erfolgt, wobei das Programm für die Berechnung des jeweils neuen Codewortes im Programmspeicher (PSP 11 ) gespeichert ist.
- 16Method according to claim 15, characterizedthat a ROM or EPROM is used as the program memory. Verfahren, nach Anspruch 15, dadurch gekennzeichnet, daß als Programmspeicher ein ROM bzw. EPROM verwendet wird.
- 17Methods to increase the security against manipulation of critical data, characterizedthat a separate code word is assigned to each non-volatile memory or memory area, with (before or at the same time) at least one of the aforementioned separate code words being stored in the internal processor memory in a non-volatile manner, that a change of the code word from a predetermined event and then the new code words being stored in the non-volatile memory to be protected is made, the change being made, after the validity of the code word has been determined, or otherwise the machine is blocked if it is invalid. Verfahren zur Erhöhung der Manipulationssicherheit von kritischen Daten, dadurch gekennzeichnet, daß jedem nichtflüchtigem Speicher oder Speicherbereich ein separates Codewort zugeordnet wird, wobei (vorher oder gleichzeitig) mindestens eines der vorgenannten separaten Codeworte im internem Prozessorspeicher nichtflüchtig gespeichert worden ist, daß ein Wechsel des Codewortes ab einem vorbestimmten Ereignis und danach eine Einspeicherung der neuen Codewörter in die zu schützenden nichtflüchtigen Speicher vorgenommen wird, wobei der Wechsel vorgenommen wird, nach dem die Gültigkeit des Codewortes festgestellt worden ist, oder anderenfalls bei Ungültigkeit die Maschine gesperrt wird.
- 18Method according to claim 17, characterizedthat the code word is changed at intervals or in number and that the formation of the new code word is dependent on the previous one. Verfahren, nach Anspruch 17, dadurch gekennzeichnet, daß das Codewort in zeitlichen oder stückzahlmäßigen Abständen gewechselt wird und daß die Bildung des neuen Codewortes vom vorherigen abhängig ist.
- 19Method according to claim 17, characterizedthat in a step (108) for forming a new, changeable first code word (T ', W'), the formation of the new second code word (V ', U') is also identical to the formation of the new first code word (T ', W') takes place in order to load an identical new second code word (V ', U') into the non-volatile memories (NVMs 5a, 5b) to be protected. Verfahren, nach Anspruch 17, dadurch gekennzeichnet, daß in einem Schritt (108) zur Bildung eines neuen veränderbaren ersten Codewortes (T', W') auch die Bildung des neuen zweiten Codewortes (V', U') identisch zur Bildung des neuen ersten Codewortes (T', W') erfolgt, um ein identisches neues zweites Codewort (V', U') in die zu schützenden nichtflüchtigen Speicher (NVMs 5a, 5b) zu laden.
- 20Method according to claim 17, characterizedthat in a step (108) to form a new changeable first code word (T ', W') also the formation of the new second code word (V '', U '') as a complementary shadow (V '', U '') to the new first code word (T ', W') in order to load a complementary new second code word (V ', U') into the non-volatile memories (NVMs 5a, 5b) to be protected. Verfahren, nach Anspruch 17, dadurch gekennzeichnet, daß in einem Schritt (108) zur Bildung eines neuen veränderbares ersten Codewortes (T', W') auch die Bildung des neuen zweiten Codewortes (V'', U'') als komplementärer Schatten (V'', U'' ) zum neuen ersten Codewortes (T', W') erfolgt, um ein komplementäres neues zweites Codewort (V', U') in die zu schützenden nichtflüchtigen Speicher (NVMs 5a, 5b) zu laden.
- 21Method according to claim 17, characterizedthat in a step (108) to form a new changeable first code word (T ', W') also the formation of the new second code word (V ', U' ') as a code word identical to the changeable new first code word (W') (V ') and as a complementary shadow (U' ') to the new first code word (T') in order to insert at least one new second code word (V ', U' ') into the non-volatile memories (NVMs 5a, 5b) or that, when protecting a corresponding memory (NVM's), the complementary shadow (V '' or U '') is also used in at least one of the memory areas. Verfahren, nach Anspruch 17, dadurch gekennzeichnet, daß in einem Schritt (108) zur Bildung eines neuen veränderbares ersten Codewortes (T', W') auch die Bildung des neuen zweiten Codewortes (V',U'') als zu dem veränderbaren neuen ersten Codewort (W') identischen Codewort (V') und als komplementärer Schatten (U'' ) zum neuen ersten Codewortes (T') erfolgt, um mindestens ein neues zweites Codewort (V', U'') in die zu schützenden nichtflüchtigen Speicher (NVMs 5a, 5b) zu laden oder daß beim Schutz eines entsprechenden Speichers (NVM's) in mindestens einem der Speicherbereiche auch mit dem komplementären Schatten (V'' oder U'' ) gearbeitet wird.
- 22Process for increasing the security against manipulation of critical register data by the steps:- Loading an authentication code (MACn), which is assigned to the code word which encrypts accounting data, into a first non-volatile memory (20 or 25) which is secured against removal and manipulation during the running time of the machine,- Loading the accounting data and the aforementioned authentication code (MACn) into second non-volatile memories NVM (5a, 5b) to be protected which contain the postal register data, the code word being assigned to the last operating state of the machine,- Validation of the authentication code (MACn), which is assigned to the code word, at least at the time the machine is switched on and subsequently due to an event,- Replace the old code word with a predetermined new code word to form another authentication code (MACn + 1), which is assigned to the new code word, which encrypts accounting data when the processor recognizes the validity of the old code word or- Blocking of the machine after it is switched on if the processor, after checking the validity, confirms the validity of the authentication code (MACn) denies. Verfahren zur Erhöhung der Manipulationssicherheit von kritischen Registerdaten gekennzeichnet durch die Schritte: - Laden eines mittels einem Codewort erzeugten Autentifikationscodes (MACn), welcher dem Codewort zugeordnet ist, welches Abrechnungsdaten verschlüsselt, in einen ersten nichtflüchtigen Speicher (20 oder 25), der während der Laufdauer der Maschine gegen eine Herausnahme und Manipulation gesichert ist,- Laden der Abrechnungsdaten und des vorgenannten Autentifikationscodes (MACn) in zweite die Postregisterdaten enthaltende zu schützende nichtflüchtige Speicher NVM (5a, 5b), wobei das Codewort dem letzten Betriebszustand der Maschine zugeordnet ist,- Gültigkeitsprüfung des Autentifikationscodes (MACn), welcher dem Codewort zugeordnet ist, mindestens zum Zeitpunkt des Einschaltens der Maschine und nachfolgend aufgrund eines Ereignisses,- Ersetzen des alten Codewortes durch ein vorbestimmtes neues Codewort zur Bildung eines weiteren Autentifikationscodes (MACn+1), welcher dem neuen Codewort zugeordnet ist, welches Abrechnungsdaten verschlüsselt, wenn der Prozessor die Gültigkeit des alten Codewortes anerkennt oder- Blockierung der Maschine nach dem Zeitpunkt ihres Einschaltens, wenn der Prozessor nach Gültigkeitsprüfung die Gültigkeit des anhand des alten Codewortes geprüften Autentifikationscodes (MACn) aberkennt.
- 23Method according to claim 22, characterizedthat the intervals for loading an authentication code (MAC) after the time the franking machine is switched on are intervals in terms of time or quantity and / or intervals that are determined at least on the basis of a pseudo-random sequence. Verfahren, nach Anspruch 22, dadurch gekennzeichnet, daß die Abstände für das Laden eines Autentifikationscodes (MAC) nach dem Zeitpunkt des Einschaltens der Frankiermaschine zeitliche oder stückzahlmäßige Abstände und/oder solche mindestens aufgrund einer Pseudozufallsfolge bestimmten Abständen sind.
- 24Methods to increase the security against manipulation of critical data, characterizedthat in each non-volatile memory or memory area, an authentication code (MACn) is stored, with at least one of the aforementioned identification codes (MACn) and separate code words have been stored in a non-volatile manner in a first internal memory of a processor system, a chip card and / or a similar system, which is in communication with the processor system during the running time of the machine and is secured against removal and manipulation during the running time of the machine and that new code words are formed from a predetermined event and then the authentication codes generated by the new code words (MACn + 1) into the non-volatile memories to be protected and into the first non-volatile memories. Verfahren zur Erhöhung der Manipulationssicherheit von kritischen Daten, dadurch gekennzeichnet, daß in jedem nichtflüchtigem Speicher oder Speicherbereich ein mittels einem separaten Codewort erzeugter Autentifikationscodes (MACn) gespeichert wird, wobei mindestens eines der vorgenannten Autentifikationscodes (MACn) und separaten Codeworte in einem ersten internen Speicher eines Prozessorsystems, einer Chipkarte und/oder eines ähnlichen Systems nichtflüchtig gespeichert worden ist, welches während der Laufzeit der Maschine mit ihrem Prozessorsystem in Kommunikationsverbindung steht und gegen Herausnahme und Manipulation während der Laufzeit der Maschine abgesichert ist und daß eine Bildung von neuen Codewörtern ab einem vorbestimmten Ereignis und danach eine Einspeicherung der mittels der neuen Codewörter erzeugten Autentifikationscodes (MACn+1) in die zu schützenden nichtflüchtigen Speicher und in die ersten nichtflüchtigen Speicher vorgenommen wird.
- 25Anordnung zur Erhöhung der Manipulationssicherheit von kritischen Daten, insbesondere von Registerdaten in Frankiermaschinen mit Eingabe- und Ausgabemitteln, einer Steuereinrichtung und Speichern, dadurch gekennzeichnet, daß die Steuereinrichtung (6) einen Mikroprozessor oder einen OTP-Prozessor (ONE TIME PROGRAMMABLE) aufweist, in welchem neben einem Mikroprozessor CPU (6a) auch weitere Schaltungen und/oder Programme bzw. Daten im internen OTP-ROM (6c) bzw. im internen OTP-RAM (6b) in einem gemeinsamen Bauelementgehäuse untergebracht sind, welche ein erstes Sicherheitsmittel gegen unbefugte Manipulation bilden, daß ein erster und ein zweiter nichtflüchtiger Speicher mit der Steuereinrichtung (6) verbunden ist, wobei der erste nichtflüchtige Speicher NVM (6d, 20, 25) ein zweites Sicherheitsmittel gegen unbefugte Manipulation bildet und gegen Herausnahme gesichert ist. Arrangement for increasing the security against manipulation of critical data, in particular register data in franking machines with input and output means, a control device and memories, characterizedthat the control device (6) has a microprocessor or an OTP processor (ONE TIME PROGRAMMABLE), in which in addition to a microprocessor CPU (6a) also further circuits and / or programs or data in the internal OTP-ROM (6c) or are housed in the internal OTP-RAM (6b) in a common component housing, which form a first security means against unauthorized manipulation, that a first and a second non-volatile memory are connected to the control device (6), the first non-volatile memory NVM (6d, 20, 25) forms a second security means against unauthorized manipulation and is secured against removal.
- 26Anordnung, nach Anspruch 25, dadurch gekennzeichnet, daß der erste nichtflüchtige Speicher als interner Prozessorspeicher (NVM 6d) zur nichtflüchtigen Speicherung im Prozessor (6) realisiert ist oder als externer nichtflüchtiger Speicher NVM (20, 25) am Prozessor (6) angeschlossen ist. Arrangement according to claim 25, characterizedthat the first non-volatile memory is implemented as an internal processor memory (NVM 6d) for non-volatile storage in the processor (6) or as an external non-volatile memory NVM (20, 25) is connected to the processor (6).
- 27Anordnung, nach den Ansprüchen 25 bis 26, dadurch gekennzeichnet, daß der externe nichtflüchtiger Speicher NVM (25) über einen Ein/Ausgabe-Steuermodul (4) am Prozessor (6) angeschlossen ist und während der Laufzeit der Frankiermaschine gegen Herausnahme gesichert ist. Arrangement, according to claims 25 to 26, characterizedthat the external non-volatile memory NVM (25) is connected to the processor (6) via an input / output control module (4) and is secured against removal during the running time of the franking machine.
- 28Anordnung, nach Anspruch 27, dadurch gekennzeichnet, daß der externe nichtflüchtiger Speicher NVM (25) Bestandteil einer Chipkarte ist und über eine Chipkarten-Schreib/Leseeinheit (21) am Ein/Ausgabe-Steuermodul (4) angeschlossen ist. Arrangement according to claim 27, characterizedthat the external non-volatile memory NVM (25) is part of a chip card and is connected via a chip card read / write unit (21) to the input / output control module (4).
- 29Anordnung, nach Anspruch 25, dadurch gekennzeichnet, daß der Programmspeicher ein EPROM ist. Arrangement according to claim 25, characterizedthat the program memory is an EPROM.
Independent claims29
148 paragraphs, as filed
The invention relates to a method and arrangement for increasing the security against manipulation of critical data, which must be protected against manipulation in information processing devices, in particular critical register data in electronic franking machines or in another electronic device in which security-relevant data are traded or in which a settlement of monetary data is carried out.
Postage meter machines are equipped with at least one input means, a control module, a storage means and a printer module. Data which are necessary for the operation of the franking machine and data which correspond to funds are stored in a non-volatile manner.
The franking machine types differ in shape and equipment according to the amount of mail to be processed. However, if different types of franking machines are to be produced, then a large number of circuits (ASICs and / or other components) must be provided. The large number of components and circuits in particular offers starting points for manipulation if no alternative effort is made or a safety housing is used.
An ASIC is known from EP 465 236 A2, which comprises a circuit for pressure control for motor control and for billing. The circuit for pressure control comprises a memory for fixed and another for variable data, which are overlaid with the fixed data. A motor controller is provided for actuating a motor drive depending on the mail item feed. One advantage is undoubtedly the high level of security against manipulation due to the use of a single ASIC, ie as a result of the limited number of starting points for manipulation. A disadvantage of the use of a single ASIC is the poor usability for different franking machines, which have a different printer and control module depending on the type of franking machine system or postal route implemented.
A modular system for a franking machine with meter / base separation is known from US Pat. No. 4,858,138, a security module (meter) being coupled to a pressure control module (base). The security module can take the form of a credit card. A high-speed communication bus designed as a parallel CPU interface serves as the electrical connection device to the pressure control module. The print control module has a high speed printer. Postage entered from the keyboard of the print control module is transferred to the security module. The security module provides a digital representation of the fixed part of the postage stamp and an encrypted validity number. The validity number includes the postage amount and possibly other information such as the franking machine serial number and the date. The encrypted validity number is suitable to detect illegal printing of an amount of money that has not been calculated. Counterfeit protection is based on encryption of a validity number, which is carried out in a security logic and is transmitted via a CPU interface. However, this solution has no advantage in the case of manipulations which are carried out in the security module or on the bus between the postal value stores and the security logic. A disadvantage here is that only the safety housing of the safety module is provided as the only protection. Another disadvantage is the high number of lines of the meter / base connection at the interface to the base and that an expensive high-speed interface is required.
A further manipulation possibility exists during the data entry when reloading the franking machine with a credit. In a conventional manner, a credit is loaded from a data center or from a memory of a transmission means, preferably a chip card. The postage amounts used by the franking machine are debited from this.
As security against fraudulent manipulation, it is already known from DE 38 23 719 to print out a representative character pattern from a certain date. When checking the post, the date of printing and the sign are compared in the post office with the sample that is authorized for this date. An authorization device, which has a storage device for storing a number of character pattern and date data, is used for printing. The data which assign the representative character pattern to a defined date are updated via a remote value specification by means of an external selection device when the users of the franking machines look for a credit. The security of the data is based on checking the data in the data center before reloading and checking the franking imprints on the part of the postal authority. The data center thus contributes to increasing the security against manipulation of critical register data. However, this security system is limited to fixed networks and cannot be used for portable franking machines that are carried from one place to another (mobile office). A self-check on the part of the franking machine for manipulation is not provided.
A postage calculator, which determines the valid postage amount from the weight of the mail piece, is usually already integrated in the scale connected to the franking machine. However, solutions with a postage calculator integrated in the franking machine have also been proposed. The postage fee required for the item of mail can be found in a postage fee table.
For example, a transportable franking machine known from DE 42 13 278 A1 has storage means and receiving means connected thereto for data that can be transmitted via a transmission means. The storage means of the franking machine has sections that can be updated for tables linked to specific conditions, for example for at least one current postage fee table, on the basis of which the respective postage fee is determined. In the control module, the franking machine has first means which, when the franking machine is started up, load at least one postage fee table for the franking machine from the memory of the transmission means via the receiving means into a predetermined memory space of the storage means. It contains second means in the control module, which are determined by means of the conditions entered via third means based on the country of dispatch already entered or - Select the current postage fee table in force for the place and date in order to load it. In terms of hardware and / or software, these first and second means are designed as a fixed or freely programmable logic module or program of a microprocessor control and each time the device is switched on they establish a connection to the external memory.
Such updatable sections of the storage means are also provided for other information and / or additional information. In particular, the security against fraudulent manipulations can be increased by the fact that during the update a number of functions assigned to the update date can be loaded into the postage meter machine and the further triggerable functions to be loaded are predefined in a variety of ways and not selectable. To protect against fraudulent manipulation, the national postal authority to which the respective sending location belongs can provide a printout that can only be machine-read by the respective national postal authority. This printout can be, for example, the transaction number for an authorization check in the form of a barcode or another agreed symbol which is printed on the mail item at a defined position using the same or a further printer.
Such security measures are suitable to prevent the use of a color copier for the unauthorized duplication of a franking imprint. However, you cannot increase the security against manipulation of the data in the franking machine.
Some of the postal authorities require redundant storage of accounting data in stores of different technologies. Every technology has specific advantages and disadvantages. Some semiconductor memories do not require a battery to store a charge for many years. But you don't have enough storage capacity. Electrically programmable non-volatile memories that have no limitations due to limited battery life are, for example, E<sup>2</sup>PROM<i>'</i>s. The disadvantage of the E<sup>2</sup>PROM<i>'</i>s consists of the limited number of permissible read / write cycles. If the permissible number of read / write cycles is exceeded, errors can occur in a used memory area.
In EP 457 114 B1 a franking machine with non-volatile storage of billing data was proposed, each billing data record containing an initial section with piece number data. The current data record can be determined via the initial sections. In the event of an error in a memory area used, a switch is made to another previously unused memory area in order to save the data record. An EPROM can therefore be used the longer the more unused memory areas are still available in the memory. However, this limits the number of data to be saved.
Battery-backed CMOS RAM are usually used in franking machines<i>'</i>s used to save the accounting data in the mail registers in a non-volatile manner. The billing data can only be saved as often as you like, due to the limited battery life. If a battery for CMOS RAM<i>'</i>s must be changed, the data must be copied to another memory, for example on another battery-backed CMOS RAM. This copying of all data from one memory to another memory is also called cloning. The new battery-backed CMOS-RAM or the old battery-backed CMOS-RAM with a replaced or renewed battery can both be fully used if all the data is identical in their memory areas. With the housing open, unauthorized persons could clone any number of memories with identical data content by cloning.
So that the contents of the memory are not cloned and reused without authorization, the accounting unit would have to be equipped with a security housing again. On the other hand, the replacement of defective components is still made more difficult.
In EP 560 714 A2, the assembly units are encapsulated by a safety housing. For the tamper-proof transmission of accounting data from a memory in a defective assembly unit to the memory of an assembly unit newly inserted in the franking machine, each assembly unit is equipped with two plug units. First, the data flow is looped through a special transmission line of a first connector unit, but the loop is removed on the same first connector unit of the old assembly unit and the normal data flow is interrupted and redirected. From the memory of the old assembly unit, the data flow is redirected to the new assembly unit via the latter connector unit and by means of a second connector unit of the new assembly unit. Mechanical locking members are provided which are operatively connected to a switch which sets an electronic identification mark (flag) and which is actuated when the defective assembly unit is removed. After the data have been transferred to the new assembly unit, a second indelible flag is set, so that a second data transfer is impossible. The security is essentially based on the encapsulation of CPU and non-volatile memory on the mounting unit and the aforementioned switch for setting the flags. With knowledge of the position or arrangement of the switch, intrusion and tampering cannot be prevented.
DE 41 29 302 A1 discloses the use of a sensor which deletes the postal registers when the franking machine housing is opened. However, this cannot prevent new data from being written into the postal register by a skilled manipulator once the housing is opened.
EP 231 452 A2 discloses the periodic polling of sensors according to a software routine of a CPU. The disadvantage of this solution is a high computing time due to the periodic scanning of the sensors. This disadvantage is further increased if the query is particularly time-critical. In order to be able to react to a change of state as quickly as possible, the polling frequency must be set high. The microprocessor therefore spends a large proportion of its computing time on the query. In particular, the manipulation of a machine that is switched off cannot be prevented. EP 231 452 A2 also assumes a redundant storage of accounting data. Since checking the stored register values does not allow all errors to be determined, separate address and data lines were used for two redundant memories. This reduces the occurrence of previously undetectable error conditions that can arise due to machine malfunctions or power failures. Falsifications due to unauthorized manipulation, ie if the billing data are copied from the original when cloning the postal register, but cannot be determined by the aforementioned measures, because the copy and original are indistinguishable from one another.
A method for operating a data processing system with a first non-volatile memory, a status memory and a second non-volatile memory has already been proposed in DE 42 17 830 A1. A module identifier enables the program to be continued and a status identifier enables the processing and continuation of the program section in which a program interruption occurred, ie if necessary the correction of incorrectly registered data in one NVM due to redundant data in the other NVM. However, this solution cannot check the data content for manipulation. When memory content is cloned, correct data is transferred to external storage. When transferring this memory content or when these external memories are used in the postage meter machine at a later point in time, a state which was once recognized as incorrect by the postage meter machine itself and which was correct at an earlier point in time is restored.
A method for improving the security of franking machines has already been proposed (DE 43 44 476 A2) in which the franking machine can distinguish between authorized and unauthorized intervention or opening of its housing. However, the method presupposes that the franking machine is continuously supplied with energy for self-checking. In this case, no security-relevant data can be unauthorized downloaded, accepted or fed from the franking machine without this being noticed during the self-check. However, additional housings, seals and / or further safety measures are required to protect the machine when it is switched off.
In many cases, the demand is made that the memory modules are easily interchangeable for repair purposes, that is to say neither encapsulated nor firmly soldered but socketed. Now, however, it would not be possible to protect the portable franking machines, ie the franking machines that are not permanently installed via a telephone network, against fraudulent manipulations when switched off. In the interest of manipulation security of critical register data, improvements to the service for the machine have so far been dispensed with.
The object of the invention is to develop a method for increasing the security against manipulation of critical register data, which avoids the disadvantages of the prior art and can be implemented inexpensively for a large number of franking machine variants without reducing the security against manipulation.
Another object is to provide security against fraudulent manipulation of any kind and franking according to valid postal tariffs depending on the weight and format of the mail item that can be entered in an arrangement for franking mail, preferably a portable franking machine of the type mentioned that can be operated independently of location. Even when the franking machine is switched off and without a power supply, the internal security circuit for postage register data and other security-relevant data should be effective.
The object is achieved with the features of claims 1, 8, 22, 24 and 25, respectively.
The invention is based on the fact that a duplication or cloning of the non-volatile memory NVM to be protected need not be prevented, but also a duplicate of the memory content, which is exchanged for the memory content of the original, can continue to be used. In the event of repairs, the contents of the memory must often be copied and exchanged, although it is assumed that no valid frankings are made in the meantime.
According to the invention, an internal processor memory is used to store a code word in a non-volatile manner. It is provided that a separate code word is assigned to each non-volatile memory or memory area to be protected, at least one of the aforementioned separate code words in a further internal memory of a processor system, a chip card and / or in a similar system has been stored in a non-volatile manner and that new code words are formed from a predetermined point in time and then the new code words are stored in the aforementioned non-volatile memories.
The solution according to the invention therefore does not prevent the postal registers, including their contents, from being removed in order to make any number of copies, but rather prevents postal items from being franked with the aid of these copies, without adequate billing at the data center or payment at the post becomes. An encapsulation of the components for the removable NV-RAMs storing the postal registers with a security housing or the provision of other additional measures for protection against removal, such as sticking to the printed circuit board, sealing or potting with epoxy resin, are now no longer necessary.
The internal postage meter security circuit for postal register data and other security-relevant data is based on non-volatile memory modules. The data remains saved when the franking machine is switched off or the power supply fails. Such CMOS SRAMs, supported for example with a lithium battery, can be written to as often as desired during their service life of approximately 10 years. The battery cannot be recharged or discharged without destroying the memory module. It is assumed that up to 150,000 impressions are possible in the life of a franking machine and that the lithium battery does not have to be replaced during this time.
Storage devices from other storage technology can likewise be appropriately protected against misuse by the security circuit if security-relevant data are stored in these non-volatile memories for predetermined events.
The non-volatile memory modules (Bat-NV-CMOS-SRAM's and E<sup>2</sup>PROM) a code word is stored, which is assigned to a predetermined franking machine. The code word may initially include, for example, the serial number of the franking machine or may be part of another number. In addition, the register memory locations are preset with initial values by the manufacturer.
The solution according to the invention prevents the non-volatile memories (NV-RAMs, E<sup>2</sup>PROMs) could be used with the intention of forgery, which were exchanged and cloned in order to later with the cloned or exchanged NV-RAMs or E<sup>2</sup>PROMs to operate the FM franking machine. The invention is based on an OTP processor with an internal OPT-ROM and internal OTP-RAM. A list of code words is stored in the internal OPT-ROM, with each code word being active temporarily and possibly only once. The code word is selected independently of the memory content of the NV-RAMs from the table - which is stored in the internal ROM area of the OTP, which is not accessible from the outside.
The new code word is taken from the internal OTP table at least when the franking machine is switched on and stored in the non-volatile memories (NV-RAMs, E<sup>2</sup>PROMs) saved if the old one in the list was the respective previous code word.
For example, an E<sup>2</sup>PROM is the only non-volatile memory that, together with the OTP processor, is permanently attached to the circuit board. In a preferred variant, a random number is generated during the operation of the franking machine before each impression and thus before each new number of franking imprints to be registered on the basis of the previous number of pieces and, if appropriate, the current time supplied by the clock / date module. For this purpose, a pseudo-random generator can be implemented in terms of hardware and / or software. At least one of the large number of possible random words that can be generated is stored in the internal OPT-ROM of the OTP processor. After a comparison within the OTP processor, if there is a match, redundant storage of the new code word is stored once in the removable non-volatile memories (NVRAMs) and, according to the invention, also in the aforementioned non-volatile memories permanently attached to the circuit board (E<sup>2</sup>PROM). The permissible number of read / write cycles for the E<sup>2</sup>PROM is not exceeded if, for example, the average non-volatile memory (E<sup>2</sup>PROM and NVRAMs) are redundantly described with a new code word.
In addition, the non-volatile memories (E<sup>2</sup>PROM and NVRAMs) redundantly described with a new code word even in another last operating state of the franking machine, which is assigned to predetermined states, such as the result of the manufacture or reloading of the franking machine or switching off or before a power failure or a standstill (stand by) or program interruption and according to other events.
The code words listed in the internal OPT-ROM are switched on via flags or pointers which are stored in the non-volatile memory which is permanently installed. The pointer is stored non-volatilely outside the releasably installed non-volatile memory (NV-RAMs) to be checked in the permanently installed and / or during the runtime of the postage meter machine in communication communication with its processor system and secured against removal during the runtime of the postage meter machine. To prevent tampering with the intention of falsifying the above-mentioned permanently installed security memory which is secured against removal, these flags or pointers should be stored in a MAC-secured manner.
In a preferred variant, the method for increasing the security against manipulation of critical register data comprises the following steps:<ul id="ul0001" list-style="dash" compact="compact"><li>Loading a number or a pointer which is assigned to a code word into a first non-volatile memory which is secured against removal and manipulation,</li><li>Loading a code word into second non-volatile memory (NVM) containing the post register data, the code word being assigned to the last operating state of the postage meter machine or being selected accordingly by the processor,</li><li>Validity check of the code word at least at the time the franking machine is switched on and subsequently based on an event,</li><li>Replacing the old code word with a predetermined new code word if the processor, after checking the validity with reference to the code word selected from a list of stored code words in its internal processor memory in accordance with the number or the position of the pointer, recognizes the validity of the old code word or</li><li>The franking machine is blocked after the franking machine is switched on when the processor, after checking the validity with reference to the selected code word stored in the aforementioned list, revokes the validity of the old code word.</li></ul>
The program for the selection of the new code word is stored in the internal program memory (internal OTP-ROM or OTP-EPROM). The selection of the new code word is carried out depending on the previous and / or on the state of the franking machine at a predetermined point in time or at a predetermined number of pieces. A separate code word can be assigned to each non-volatile memory or memory area that must be protected. In the franking machine, this can make it possible to carry out an automatic analysis of which memory module has been removed from a large number of memory modules.
The aforementioned last operating state of the franking machine, which corresponds to the code word, corresponds in particular to a state as a result of the manufacture or reloading of the franking machine or as a result of the formation of a pseudorandom sequence or a state before the franking machine was switched off or a state before a power failure or before a standstill (stand by ) or before the program is interrupted. It is provided that the validity check of the code word is carried out at least at the time the franking machine is switched on and subsequently at least on the basis of a pseudo random sequence.
For an arrangement to increase the security against manipulation of critical data, in particular of register data in franking machines with input and display means, a control device and memories, it is provided that the control device has a microprocessor or an OTP processor (ONE TIME PROGRAMMABLE). In addition to a microprocessor CPU, the OTP also contains other circuits and / or programs or data in the internal OTP-ROM or housed in the internal OTP-RAM in a common component housing, which form a first security measure against unauthorized manipulation. It is provided that a first and a second non-volatile memory are connected to the control device, the first non-volatile memory NVM forming a second security means against unauthorized manipulation and being secured against removal.
In a variant it is provided that the first non-volatile memory is implemented as an internal processor memory for non-volatile storage in the processor and is thus secured against removal and manipulation.
In another variant, the first non-volatile memory, as an external non-volatile memory NVM, is electrically and mechanically non-detachably connected to the processor via a printed circuit board.
In a further variant, the external non-volatile memory NVM is connected to the processor via an input / output control module and is secured against removal during the running time of the franking machine. It is also provided that the external non-volatile memory NVM is part of a chip card and is connected to the input / output control module via a chip card read / write unit.
An alternative method is based on a special formation of code words in the OTP-CPU. A listing of code words in the internal OTP-ROM is then unnecessary. The procedure for increasing the security against manipulation of critical register data comprises the steps:<ul id="ul0002" list-style="dash" compact="compact"><li>Loading a code word into a first internal processor memory for non-volatile storage and into a second non-volatile memory (NVM) containing the postal register data, the code word corresponding to the last operating state of the franking machine,</li><li>Validity check of the code word at least at the time the franking machine is switched on and subsequently based on an event,</li><li>Replacing the old code word with a predetermined new code word if the processor recognizes the validity of the old code word after validity check with reference to the code word stored in its first first non-volatile internal processor memory (NVM) or</li><li>The franking machine is blocked after the franking machine is switched on when the processor, after checking the validity with regard to the code word stored in its first non-volatile internal processor memory (NVM), revokes the validity of the old code word.</li></ul>
The program for the formation of the new code word is stored in the program memory (internal ROM or EPROM). The formation of the new code word depends on the previous one. A separate code word can be assigned to each non-volatile memory or memory area, wherein (before or simultaneously) at least one of the aforementioned code words has been stored in a non-volatile manner according to the invention in the internal processor memory.
It is also provided as an alternative to the abovementioned code word listing that in a step to form a new, changeable, unique first code word, the formation of the new second code word takes place identically to the formation of the new first code word in order to add an identical new second code word to the non-volatile memories to be protected load.
Alternatively, it is provided in a further variant that in a step to form a new, changeable, unique first code word, the formation of the new second code word takes place as a complementary shadow to the new first code word in order to load a complementary new second code word into the non-volatile memories to be protected .
Another variant provides that in a step to form a new, changeable, unique first code word, the formation of the new second code word also takes place as a code word identical to the new, changeable, unique first code word and as a complementary shadow to the new first code word, in order to load at least one new second code word into the non-volatile memories to be protected, or to use the complementary shadow when protecting a corresponding memory in at least one of the memory areas.
In a further development of the invention, the aforementioned code word, which is changed at intervals in terms of time or quantity, can also be used for MAC protection of the postal register data. The MAC is then stored in the non-volatile memories to be protected instead of the code word. Such a method for increasing the security against manipulation of critical register data is characterized<b>by</b> the steps:<ul id="ul0003" list-style="dash" compact="compact"><li>Loading an authentication code (MAC.) Generated using a code word<sub>n</sub>), which is assigned to the code word which encrypts accounting data, into a first non-volatile memory which is secured against removal and manipulation during the running time of the machine,</li><li>Loading the accounting data and the aforementioned authentication code (MAC<sub>n</sub>into second non-volatile memories NVM to be protected, which contain the postal register data, the code word being assigned to the last operating state of the machine,</li><li>Validation of the authentication code (MAC<sub>n</sub>), which is assigned to the code word, at least at the time the machine is switched on and subsequently due to an event,</li><li>Replace the old code word with a predetermined new code word to form another authentication code (MAC<sub>n + 1</sub>), which is assigned to the new code word, which encrypts accounting data when the processor recognizes the validity of the old code word or</li><li>The machine is blocked after it has been switched on, if the processor, after checking the validity, confirms the validity of the authentication code (MAC<sub>n</sub>) denies.</li></ul>
The intervals for loading a MESSAGE AUTHENTIFICATION CODE (MAC) after the franking machine has been switched on are intervals in terms of time or quantity and / or intervals determined at least on the basis of a pseudo-random sequence.
Advantageous developments of the invention are characterized in the subclaims or are shown below together with the description of the preferred embodiment of the invention with reference to the figures. Show it:<dl id="dl0001"><dt>Figure 1a,</dt><dd>Block diagram of a franking machine with increased security according to the invention according to a first variant with E.<sup>2</sup>PROM,</dd><dt>Figure 1b,</dt><dd>Block diagram of a franking machine with increased security according to the invention according to a second variant with OTP internal E<sup>2</sup>PROM,</dd><dt>Figure 2a,</dt><dd>Variant with OTP processor without internal E<sup>2</sup>PROM after the first variant,</dd><dt>Figure 2b,</dt><dd>Variant with OTP processor with internal E<sup>2</sup>PROM after the first variant,</dd><dt>Figure 3,</dt><dd>Overall schedule for the franking machine,</dd><dt>Figure 4,</dt><dd>Details of the flow chart according to FIG. 3,</dd><dt>Figure 5,</dt><dd>Schedule for franking mode,</dd><dt>Figure 6,</dt><dd>Details of the flow chart according to FIG. 4,</dd><dt>Figure 7,</dt><dd>Flow chart for the method according to the invention for increasing manipulation security,</dd><dt>8a to c,</dt><dd>Pointer positions according to the inventive method of the first variant.</dd></dl>
FIG. 1a shows a block diagram of the franking machine according to the invention with a printer module 1 for a fully electronically generated franking image, with at least one input means 2 having a plurality of actuating elements, a display unit 3, a MODEM 23 establishing communication with a data center, which via an input / output control module 4 are coupled to a control device 6 and to at least one non-volatile memory 5a or 5b for the variable and a memory 10, 11 for the constant parts of the franking image.
A character memory 9 supplies the necessary print data for a volatile working memory 7. The volatile working memory 7 comprises, for example, an external RAM in conjunction with an internal RAM 6b arranged in the processor. The control device 6 has a correspondingly designed microprocessor μP and is with the input / output control module 4, the character memory 9, the volatile working memory 7, with a non-volatile cost center memory NVM 5a and with a non-volatile working memory NVM 5b, with an application-specific program memory ASP 10 (Cliché EPROM), a program memory PSP 11 (program EPROM), with the motor of a transport or feed device, if necessary connected to a strip release 12, an encoder (coding disk) 13, a letter sensor 16 and a clock / date module 8. A corresponding method for controlling the printing of a postage stamp image in columns is described in more detail, for example, in EP 578 042 A2 or in EP 576 133 A2.
In the block diagram of a franking machine shown in FIG. 1a, the increased security according to the invention in connection with an E<sup>2</sup>PROM 20, which is external to the microprocessor housing. Both are permanently attached to the board.
The control device 6 - shown in more detail in FIG. 2a - has a microprocessor or an OTP processor (ONE TIME PROGRAMMABLE). In addition to a microprocessor CPU 6a, the OTP also houses other circuits in a common component housing. These further circuits and / or programs or data in the internal OTP-ROM 6c or in the internal OTP-RAM 6b in the common processor housing form a safety circuit or a first security measure against unauthorized manipulation. The first non-volatile memory NVM 20 is an E, for example<sup>2</sup>PROM and serves as a second security measure against unauthorized manipulation.
It is also provided that an external non-volatile memory NVM 25 forms a second security means against unauthorized manipulation and is connected to the processor 6 via an input / output control module 4 and is secured against removal during the running time of the franking machine.
The remaining individual memories can be implemented in a plurality of physically separate modules or combined in a few modules as shown in FIG. 2a. The read-only memories CSP 9 and PSP 11 are preferably combined in an EPROM and the non-volatile memories NVM 5a and 5b to be protected are combined in a postal register memory. The latter is preferably duplicated and is redundantly written with data in its memory areas. A method for storing security-relevant data is described in more detail, for example, in EP 615 211 A1.
According to the invention, the block diagram of a franking machine shown in FIG. 1b achieves increased security with an OTP-internal non-volatile memory (NVM), preferably an E.<sup>2</sup>PROM 6d.
The control device 6 - shown in more detail in FIG. 2b - has a microprocessor or an OTP processor (ONE TIME PROGRAMMABLE). In addition to a microprocessor CPU 6a, internal non-volatile memories NVM 6d and further circuits are accommodated in a common component housing in the OTP. The aforementioned internal non-volatile memory NVM 6d and further circuits and / or programs or data in the internal OTP-ROM 6c or internal OTP-RAM 6b in the common processor housing again form a security circuit or a security means against unauthorized manipulation.
An internal non-volatile memory NVM 6d in the security means of the OTP processor (CPU) 6 works together with the program memory 6c (internal EPROM or ROM) and volatile data memory RAM 6b. Reading out the internal non-volatile memory can be prevented by the possibility of setting security bits (with internal EPROM) or with mask programming during manufacture (with internal ROM).
In the solution according to the first variant shown in FIG. 1 a - with non-volatile memory NVM 20 external to the OTP processor 6, the latter forms a second security means against unauthorized manipulation. In the preferred variant, the external non-volatile memory NVM 20 - as shown in FIG. 1a - is a component of the processor system of the franking machine and works together with the program memory 6c (internal EPROM or ROM) and volatile data memory RAM 6b.
A chip card read / write unit 21 is also shown in the aforementioned block diagram of the franking machine 1 according to the invention. This is connected via a bus 11 to a processor 6 directly or via input / output means (I / O ports) 4. Furthermore, a connection of a MODEM 23 via the BUS 11 directly or via the aforementioned input / output means 4 is provided, which is not shown in more detail in FIG. 1a. The chip card, which must be inserted into the chip card read / write unit 21, includes an external non-volatile memory 25. Such a non-volatile memory can also be present in a similar system.
As already mentioned, the possibility to set security bits (for internal EPROM) or to carry out mask programming (for internal ROM) during production prevents reading of the internal program memory from the outside. The security bits are set by programming the internal EPROM during the manufacture of the franking machine in the OTP processor. Observing such security-relevant routines, such as billing routines, with an emulator / debugger would also lead to a changed time sequence, which can be determined by the OTP. This also includes a clock generator / counter circuit for specifying time intervals or clock cycles, for example for time-out generation or printer control. The clock generator / counter circuit is advantageously used for program runtime monitoring, which is described in more detail in application EP 660 269 A2. When a certain time has elapsed and the expected event has not occurred, the clock / counter circuit generates an interrupt which reports to the microprocessor that the time has elapsed without success, whereupon the microprocessor initiates further measures. The monitoring function is carried out in the aforementioned manner by the aforementioned first security means, which is part of the processor (OTP) and which is effective in connection with appropriate software during the operation of the franking machine. In an advantageous further variant of the time control, a code word in the external NVM 5a, 5b or 25 is deleted. This can be done by overwriting with a predetermined other word, for example 0000. The advantage is in particular that the safety circuit reacts to manipulation by unauthorized intervention in the franking machine during operation.
The monitoring function is also carried out in the second variant - shown in FIGS. 1b and 2b - in the aforementioned manner by the safety circuit formed by means 6a and 6d, which is part of the processor (OTP) and which is used in conjunction with appropriate software takes effect during the operation of the franking machine. A CMOS single-chip 8-bit microcontroller Philips 80C851 or 83C851 with a non-volatile 256x8-bit E<sup>2</sup>PROM can be used as internal processor memory. The code word can be stored in the above-mentioned internal processor memory more than 50,000 times in a non-volatile manner. Data retention is also guaranteed for 10 years. Another suitable processor is, for example, the TMS 370C010 from Texas Instruments, which also has an internal 256 byte E.<sup>2</sup>PROM has.
The internal franking machine security circuit for postal register data and other security-relevant data protects the data content of non-volatile memories, for example CMOS-SRAMs supported by a lithium battery, against the use of illegally cloned copies without billing.
The aforementioned lithium battery-supported CMOS SRAMs have a lifespan of at least 10 years. A non-volatile memory device is available from Dallas Semiconductor for the DS1230Y / AB, for example, a memory area of 256 K or a memory area of 1024 K for an NV-SRAM for the DS1245Y / AB.
The clock / date module 8 can also be protected using the same method . This module is a non-volatile timer RAM and also contains a lithium battery for at least 10 years. The DS 1642 from Dallas Semiconductor has a 2K x 8 NV-SRAM.
In addition, storage media from other storage technology can also be used according to their service life. The safety circuit stores in this non-volatile memory, for example, only data at the time the franking machine is switched on or put back into operation after a standby operation, that is to say at times when there is no billing requirement and no franking takes place. Normal E<sup>2</sup>PROM memories, in particular of the 28256 type, do not require an internal battery and allow at least 10,000 to 100,000 read / write cycles. The internal postage meter security circuit for postal register data and other security-relevant data accordingly controls the aforementioned non-volatile memory modules so that the service life is increased or sufficient.
If, in addition to a code word, the data content of the postal register is stored in encrypted form as a checksum in the non-volatile memories 5a, 5b, manipulation of the postal register can be effectively prevented from the start. For example, an OTP processor (ONE TIME PROGRAMMABLE) is used which has an algorithm stored in the internal ROM for such a checksum method. Set flags prevent the safety-relevant data from being read out of the processor. A known checksum method is based on a MAC (MESSAGE AUTHENTIFICATION CODE) which is attached to the data to be backed up. Such MAC protection is advantageously placed over the postal register data. In a further development of the invention, the aforementioned code word, which is changed at intervals in terms of time or quantity, can also be used for MAC protection of the postal register data. As a rule, a stored code word, which is changed at intervals, is sufficient to guarantee security.
The monitoring function is also implemented in the processor in the first variant — shown in FIGS. 1a and 2a. For example, an 8051 processor with a 16 kbyte on-chip EPROM can be used as internal program memory. The internal OTP-RAM has a memory area of 256 bytes.
According to the invention, it is now provided that the non-volatile memories containing the postal register data, in particular battery-backed CMOS-RAMs (Bat-NV-CMOS-RAMs), contain a code word which indicates the last operating state of the postage meter before switching off or power failure or before a certain downtime (status by) or was selected accordingly before the program was interrupted and that the old code word was replaced by a predetermined new code word at least at the time the franking machine was switched on.
According to the invention, the code word for predetermined events is therefore automatically changed by the operational franking machine in all non-volatile memories which deal with security-relevant data. Such a measure prevents a cloned memory content of a non-volatile memory (Bat-NV-CMOS-RAM's) from being used more than once because the code word is changed in the non-volatile internal processor memory and in the post register (Bat-NV-CMOS-RAM's). as soon as a predetermined operating state of the franking machine after the machine is switched on or after voltage recovery after a failure, after leaving the communication mode or Reloading the franking machine with a credit or after a certain downtime (stand by) or after another program interruption.
A duplication or cloning of a Bat-NV-CMOS-RAM or other NVRAM is not prevented by the above-mentioned measure. A duplicate of the memory content, which is exchanged for the memory content of the original, can also be used. In this case, the original code word becomes invalid later, ie the processor would notice that the memory contents would be exchanged due to the code word in the non-volatile internal processor memory, which has also been changed in the meantime.
The code words cannot be changed by the manipulator without the knowledge of the key and the parameter data if the data content of the memory has remained the same if the algorithm for forming the new code word was known. Therefore, a known encryption method, such as DES, can be used.
The method for increasing the security against manipulation of critical register data comprises further security steps, which are shown in FIG.
In step 106, the code words stored in the non-volatile memories to be protected are read in succession and then transmitted to the processor. The processor carries out a security step 107 for checking the previously valid code word and a step 108 for correspondingly changing the code word if the check has shown the correspondence or freedom from errors. Otherwise, a branch is made from step 107 to step 109 in order to set a number which identifies the kill mode or at least a MAC-secured kill mode flag in the permanently installed non-volatile external security memory.
FIGS. 8a to c show pointer positions using the method according to the invention. FIG. 8a shows an initial state presetting. Such a step is required in step 107 (FIG. 7) in order to determine the correct old code word from the stored list. When the machine is initialized for the first time in the manufacturing plant, the pointer stands on a number 1. Alternatively, the serial number of the franking machine can also form a starting number. The pointer position (number 1 or Initial number) is saved. A corresponding first code, which is at a first position in the list, is then stored in the NVM 5a or 5b to be protected. The franking machine leaves the manufacturer's plant set to a number 1 or initial number. The franking machine is now switched on or switched on again at the dealer or at the customer (FIG. 8b). The first code is read from the list according to the position of the pointer and with the NVM 5a or 5b stored compared first code. This first phase corresponds to step 107 in FIG. 7, in which it is determined whether a memory has in the meantime been removed without being charged and replaced by another and has now been used again with the old data. If the codes are the same, the pointer position is switched to a second code word in the list in accordance with FIG. 8c, which can be gathered from step 108 in FIG. The pointer position is changed in a predetermined manner. In the simplest case, the pointer position is incremented or decremented. The first code in the NVM 5a or 5b to be protected is now replaced by the second code, ie overwritten. If the postage meter machine is now switched on or switched on again after switching off, a check is carried out on the basis of the current code in a manner analogous to that shown in FIGS. 8b and 7, step 107.
In the preferred exemplary embodiment, for two non-volatile memories NVM 6d and NVM 5a in step 107, a separate code word W (-1), T (-) is provided for each physical memory chip in order to check the previously valid code word V (-1), U (-1). 1) used.
For two non-volatile memories NVM 20 and NVM 5a, after checking the old code word in step 107 and before the corresponding change of code words V and U, first a new code word W 'and then a code word T' is formed in step 108, according to the equations:<maths id="math0001" num=""><math display="block"><mrow><mtable><mtr><mtd><mrow><mtable><mtr><mtd><mrow><mtable><mlabeledtr><mtext>(1)</mtext><mtd><mrow><mtext>W ': = F {P1} and</mtext></mrow></mtd></mlabeledtr></mtable></mrow></mtd></mtr><mtr><mtd><mrow><mtable><mlabeledtr><mtext>(2)</mtext><mtd><mrow><mtext>T ': = F {P2}, </mtext></mrow></mtd></mlabeledtr></mtable></mrow></mtd></mtr></mtable></mrow></mtd></mtr></mtable></mrow></math><img file="EP0762337A2_D0001.tif" /></maths> where P1 and P2 are listed code words.
In a variant, with the listed code words and with internal data according to an internal program, a new code word is generated by means of such a mathematical function F, which makes the external replication of code words considerably more difficult, so that manipulation with the intention of forgery is made practically impossible.
In the simplest case, a count value is incremented in the internal NVM 20 before a new code word (W ', T', U ', V') is formed. For example, a cryptographic function can be used as the mathematical function F, which is stored as an algorithm or program in the internal OTP-ROM. For example, the DES algorithm (Data Encryption Standard) or a random function can be used, for example to determine the new pointer in accordance with F.
The aforementioned formation of code words includes the calculation and / or selection from a list of code words which is stored in the internal OTP-ROM. Ideally, each code word should only be used once to protect the external non-volatile read / write memory. However, this requires a large number of code words, which are stored in the internal OTP-ROM.
Only the pointer position or number that indicates the position of the respective code word in the list stored in OTP-ROM must be stored particularly securely externally by the OTP processor and externally by the non-volatile read / write memories NVM 5a and 5b. This securing of the second security means 20 against removal from the processor system can be ensured by sticking or securely encapsulating the aforementioned security memory together with the processor.
In the variants according to the invention with storage in the chip card, there is no need to glue on or secure encapsulate at least one of the external non-volatile read / write memories.
These variants are based on the premise that the memory of the chip card cannot be manipulated or cloned. A manipulator must not be able to query the new code word to be formed before switching it on in order to equip its cloned memory. The pointer position or number can be encrypted using DES when it is transferred to the chip card. Alternatively, the code word is transmitted, or only the instruction to restore it or essential parts of the instruction. The transmission is again encrypted or as MAC-secured data. Such a method has the advantage that one can do without the above-mentioned special processor and that all post-register NVRAMs are still socketed and are therefore easily interchangeable.
Alternatively, it is also possible that a code word stored in the list can be read out in encrypted form if a special processor is present. The code words from the memory to be protected and the code word from the aforementioned list to which the pointer points are transmitted in encrypted form to the chip card, which also has a processor which can also carry out a comparison for the purpose of security checking.
In a further variant, the code word is transmitted from the franking machine to the memory of a remote similar processor system. Each time the franking machine is switched on, a connection to the memory of the remote similar processor system is established. The absence of errors is determined by comparing the code word stored externally in the remote similar processor system with the code word stored in the post register NVRAM, in order then to form a new code word and to store it in the NVRAM of the remote similar processor system and in the post register NVRAM. The comparison of the unique code words is carried out in the franking machine.
An expedient variant consists in storing the unique code word formed according to an algorithm in a more specific transmission means (eg chip card). A communication link to the remote similar processor system would not be a prerequisite for commissioning the franking machine if the chip card was inserted at the beginning, which was also inserted the last time, ie in the case of previous frankings. A corresponding communication mode 300 is of course provided after switching on during the running time of the franking machine.
In the second variant - shown in FIGS. 1b and 2b - in step 106 the code words stored in the non-volatile memories to be protected are read in succession and then transmitted to the processor. The processor carries out a security step 107 for checking the previously valid code word and a step 108 for correspondingly changing the code word if the check has shown the correspondence or freedom from errors. Otherwise, a branch is made from step 107 to step 109 in order to delete a code word Y or to set at least one kill mode flag in the non-volatile memory 6d in the processor.
For two non-volatile memories NVM 6d and NVM 5a, after checking the old code word in step 107 and before the corresponding change of code words V and U, first a new code word W 'and then a code word T' for the second processor-internal NVM 6d is formed in step 108 , according to the equations:<maths id="math0002" num=""><math display="block"><mrow><mtable><mtr><mtd><mrow><mtable><mtr><mtd><mrow><mtable><mlabeledtr><mtext>(1)</mtext><mtd><mrow><mtext>W ': = F {P1} and</mtext></mrow></mtd></mlabeledtr></mtable></mrow></mtd></mtr><mtr><mtd><mrow><mtable><mlabeledtr><mtext>(2)</mtext><mtd><mrow><mtext>T ': = F {P2}, </mtext></mrow></mtd></mlabeledtr></mtable></mrow></mtd></mtr></mtable></mrow></mtd></mtr></mtable></mrow></math><img file="EP0762337A2_D0002.tif" /></maths> where P1 and P2 are different monotonously continuously changeable parameters, for example the current time, number of program interruptions or other program, time or physical parameters or listed code. In a variant, a new code word is generated again with internal data and according to an internal program by means of such a mathematical function F, which makes the external replication of code words considerably more difficult, so that manipulation with the intention of forgery is made practically impossible.
In the case of the second variant according to the invention, the inclusion of postal register values as a test characteristic value and gluing or secure encapsulation of at least one of the external non-volatile read / write memories can be dispensed with. Only later, for example in franking mode 400 (FIG. 5), is the data content checked during billing whether the register value sum R3 is equal to the sum of ascending register R1 (residual value) and descending register R2 and / or whether the post register values are valid (e.g. through authenticity checks, plausibility checks and similar checks).
The method according to the invention is integrated in an overall flow chart of the franking machine, shown in FIG. 3. After the start 100, measures for the security check and for restoring a defined initial state are carried out in a step 101 comprising the start routine and initialization.
The further steps 102 to 105 optionally take place to restore operational readiness, for example after the franking machine has been repaired, and are shown in more detail in FIG.
In steps 106 to 109, the old code words read are checked and exchanged for new code words. The new code word is then also transferred to the NV-RAMs NVM 5a and NVM 5b, where it forms a corresponding code word (V ', U'). Step 108 also includes checking that the code words (U ', V' or W ', T') have been correctly stored. If a non-plausible deviation is found when checking the previously valid code word, a branch is made to a step 109, which includes measures which ultimately prevent further franking with the franking machine. For example, a third code word Y specified by a data center can be deleted, the absence of which proves the manipulation. The system routine (point s) is then followed.
The overall flowchart for the franking machine shown in FIG. 3 has steps 201 to 206 and 207 to 208 for monitoring further criteria. If, for example, a security criterion checked in step 207 is violated, the franking machine enters a corresponding kill mode (step 208). The franking machine enters a sleeping (warning) mode (203-206) based on a security criterion checked in step 202 , if a connection to the data center has not yet been established after the consumption of a predetermined number of pieces.
The franking machine and the data center each agree on a predetermined number of items S, ie the amount that can be franked until the next connection is established. If communication does not take place (quantity control), the franking machine slows down its mode of operation (sleeping mode variant 1), so that it is possible to continue working until the next quantity limit without displaying a warning. However, it is possible at increasingly shorter intervals, ie after a predetermined number of frankings, to issue a new warning, which thus more and more urgently draws attention to the need for communication with the data center (sleeping mode variant 2). Finally, it is possible (Sleeping Mode Variant 3) to issue a permanent warning that the franking function is about to go to sleep in step 203 if, due to the fulfilled query criterion, it has to be continuously run through in step 202 before step 205 is reached. It is further provided that step 203 comprises a sub-step for error statistics in accordance with the statistics and error evaluation mode 213. This variant does not require the aforementioned step 204. Franking is not affected by Sleeping Mode. As long as the check in step 205 shows that the number of pieces S is even greater than zero, step 207 is reached. Only the warning appears more and more often in the display. Otherwise, a branch is made to step 206, for example setting a FLAG which is queried later in step 301 and evaluated as a communication request. In step 206, an additional indication can also be given that the communication is now taking place automatically and until the franking function is at rest until the communication has been successfully completed. Of course, the franking machine user can call up the communication mode 300 at any time beforehand. In a step 207 preceding communication mode 300, further criteria relevant to security against manipulation are checked. If the machine is tampered with and has been tampered with, it is directed to step 208 in order to prevent franking with the tampered with machine. In such a case, the machine would enter kill mode. If the franking machine is only in sleeping mode, franking is not prevented.
After checking the criteria for the kill mode (steps 207 to 208) and for the sleeping mode (steps 202 to 206), a point t shown in FIG. 3 is reached. In step 209, entries can be made before point e is reached.
Upon entering communication mode 300, the user has the possibility of establishing communication with the data center, or communication with the data center is automatically established, if necessary, in accordance with the overall flowchart shown in FIG. 3.
If the communication was successful, a query is made in step 211 as to whether data have been transmitted. Step 213 is then reached. In step 213, the current data are determined or loaded, which are called in step 201 and then required again in the comparison in step 202. The transmitted decision criterion is preferably the new number S '.
According to the invention, the evaluation mode in step 213 also includes the formation of new code words U ', V' for the non-volatile memories to be protected as a result of a reloading process which was carried out in communication with a data center. Steps 106 to 109 shown by way of example for code word Y in FIG. 7 also run analogously for code words U ', V'.
If authorization to intervene for the franking machine has previously been requested from the data center, a new third code word Y 'specified by the data center is loaded, which can replace the old third code word Y. For repair purposes, opening the franking machine and replacing defective components may be unavoidable. Therefore, previous measures to obtain authorization to intervene are required, which allow the franking machine to be operated after it has been repaired. An unauthorized opening of the franking machine is excluded. When the postage meter machine is put into operation again after the intervention, the new third code word Y 'specified by a data center can replace the old third code word Y due to the authorization to intervene for the postage meter machine, as was proposed, for example, in the application DE 43 44 476 A1.
If the old third code word Y specified by a data center were to be deleted because the memories have been completely replaced and their changeable code word (V, U) is not present or does not match the one stored internally, the franking machine could continue to be operated. The franking machine can continue to be operated because a new third code word Y 'is used, branching to step 108, as shown in FIG. 7, in order to form a new changeable code word (T', W ') and as Load code word (V ', U') into the NV-RAMs.
In a - compared to the flowchart shown in FIG. 7 - modified flowchart variant, instead of using a codeword (V, U) that is identical to the changeable codeword (W, T), the complementary shadow (V ″, U ″) can also be used in at least one of the memory areas or NVRAMs can be worked. Correspondingly, the form of checking the previously valid code words and replacing them with new code words in one of the memory areas of the non-volatile memory NVM 5a, 5b also change according to steps 102 to 105 shown in FIGS. 3 and 5. After verifying the new code words V ', U' and / or Y 'that may be stored in a memory area E of the NVM 5a, 5b, the old code words are deleted and the new code words are addressed accordingly. This can advantageously be done analogously to the sequence - as shown in FIG. 7 in DE 43 44 476 A1 - in that the new code words V ', U' and / or Y 'relate to the address of the old code words V, U and / or Y can be set.
After a preceding event or a program interruption (standby), a point p is reached and according to the details of the flowchart shown in FIG. 4, a first saving step 106 of the flowchart of the method according to the invention shown in FIG. 7 is carried out via steps 102 to 105 reached.
Only when starting up or after a power failure, after an initialization in a step 1050 upstream of the aforementioned point p, is the current program module PM first called up, the sections of which are then to be processed further. Step 101 shown in FIG. 3 comprises several sub-steps, which are explained in more detail below with reference to FIG. 4.
The usual hardware and display initialization routines first run in step 1010 before a step 1011 for timer and interrupt start is reached. The internal program then starts with security checks. Advantageously, it can already be checked here in step 1020 whether a code word or memory content is valid. Then, if valid, step 1040 for automatic input of stored data with print data preparation and embedding of the image data is reached.
After calling the flag or pointer in step 1051, a further step 1052 tests whether the program module has to be processed further. If this is not the case, the next program module PM (+1) is called in step 1054. Otherwise it is checked in a step 1053 whether program sections of a previous program module PM (-1) have to be finished and branches to a step 1056 or a step 1055 if a program section of the current program module PM has to be processed further. After determining the current program module in accordance with steps 1054, 1055 or 1056, a branch is made to point p.
For processing critical and non-critical program sections within this program module, markers, for example a phase identifier, as is known from DE 42 17 830 A1, or pointers are set, which, after a power failure and being switched on again, enable a reconstruction of defined states for further program execution.
According to FIG. 3, after execution of steps 102 to 105 and 106 to 109, point s and thus system routine 200 are reached. In addition, the point s is reached after the steps for a test mode 216, for a display mode 215 and for a franking mode 400 have been carried out.
The processes according to the franking mode 400 shown in FIG. 5 are explained in connection with the block diagram shown in FIG. 1a and in the overall flowchart of the electronic franking machine shown in FIG.
The invention is based on the fact that, after switching on, the postage value in the value print corresponding to the last entry before switching off the franking machine and the date in the day stamp corresponding to the current date are automatically specified that the variable data in the fixed data for the frame are to be printed and are electronically embedded for all associated data that remain unchanged (FIG. 4, step 1040).
In addition, the time in the battery-assisted clock / date module 8 continues to run even when the franking machine is switched off and is constantly stored at least as a date and is embedded in the initialization routine 101 in step 1040 of FIG. 4.
If step 401 is thus reached in franking mode 400 after the franking machine has been switched on, after the system routine 200 has been carried out and during the operating mode, data that has already been stored can also be accessed without input. This setting relates in particular to the last setting of the postage meter with regard to the postage value, which is displayed in step 209, before a new entry, display and print data preparation is carried out, if necessary. The current variable pixel image data (date and postage value) are embedded in the fixed frame pixel image data. Subsequently, in step 401, the input means are queried for any further inputs. If there are further entries, a loop counter is reset in step 403 and branched back to point t (FIG. 3).
The input data, which are entered with a keyboard 2 or via an electronic scale 22 connected to the input / output device 4 and calculating the postage value, are automatically stored in the memory area D of the non-volatile working memory NVM 5. In addition, there are also data records of the sub memory areas, for example B<sub>j</sub>, C etc., stored non-volatile. This ensures that the last input values are retained even when the franking machine is switched off, so that after switching on the postage value in the value print corresponding to the last entry before switching off the franking machine and the date in the day stamp according to the current date is automatically specified. In step 209, the possible entry of new values is queried. If, for example, no new postage value has been entered, the previous postage value stored in the memory area is used and point e (FIG. 3) is reached in order to query further entries before franking mode 400 (FIG. 5) is reached.
If a new input request is found in step 401, the process branches back to step 209 via step 403. Otherwise, a branch is made to step 402 in order to increment the loop counter. Via step 404, in which the number of loops passed through is checked, step 405 is reached in order to wait for the print output request. A letter is detected by a letter sensor and is to be franked. This generates a signal for the print output request.
In step 405, the print output request is awaited, in order to then branch via steps 407, 409 and 410 to the accounting and printing routine in step 406. If there is no print output request (step 405), the process branches back to step 209 (point t) and, if there is no communication request, via steps 211, 212 and 214 to step 401 of franking mode 400, according to the overall flow chart shown in FIG. 3.
If, in the manner shown in FIG. 5, the method now branches back to point t and step 301 is reached after step 209, a communication request can be made at any time by manual input or another input can be made in accordance with the steps test request 212 and register check 214. Step 401 is reached again. If no input request is recognized, further steps 402 and 404 - as shown in FIG. 5 - are carried out. A further query criterion can be queried in a step 404 in order to set a standby flag in step 408 if, after a number of loops that have been run through, no input has been made and there has been no print output request.
In another variant, the standby mode is also achieved if a letter sensor 16 known per se - shown in FIG. 1a - does not determine a next envelope in a predetermined time which is to be franked. Step 404 in franking mode 400, shown in FIG. 4, comprises either a query for a timeout or for the number of passes through the program loop, which ultimately leads back to the input routine in accordance with step 401. If the query criterion is met, a standby flag is set in step 408 and the system routine 200 branches directly to point p or alternatively to point s without the billing and printing routine being executed in step 406. When branching to point p, an additional change of the code words can be achieved during the standby mode. In the case of a variant (not shown in FIG. 5) with a branching to point s, however, only a change in the code words can only be achieved after switching on.
The standby flag is queried during the system routine 200 in step 211 and, if necessary, is reset after the checksum check in step 213 if no attempted manipulation is detected.
For this purpose, the query criterion in step 211 is expanded to include the question of whether the standby flag is set, ie whether the standby mode has been reached. In this case, a branch is made to step 213. A preferred variant with manipulation monitoring during the standby mode is to delete a code word Y in the manner already described if a manipulation attempt in the standby mode has been determined in step 213 in the aforementioned manner. The absence of code word Y is recognized in step 207 and then branched to step 208. The advantage of this method in connection with the first mode is that the manipulation attempt is statistically recorded in step 213.
The standby flag can thus be queried in step 211 following communication mode 300. This does not branch to franking mode 400 until the checksum check has shown that all or at least some selected security-relevant programs are complete and valid.
If a print output request is recognized in step 405, further queries are made in subsequent steps 409 and 410 and in step 406. For example, in step 407 a check of the register values and additionally the code word Y can be carried out and in step 409 the validity and additionally the presence of a kill mode flag set in step 208 (FIG. 3) is determined in order to proceed to step 410 branch. Otherwise, a branch is made to step 413 for statistical and / or error evaluation and step 415 for displaying the error if the register values were not authentic.
In step 410, the achievement of a further quantity criterion is queried. If the number of items predetermined for franking was used up in the previous franking, ie number of items equal to zero, the system automatically branches to point e in order to enter communication mode 300 so that a new predetermined number of items S is again credited by the data center. However, if the predetermined number of pieces had not yet been used, steps 410, 4060, 4061 and 4062 and 4063 branches to the accounting and printing routine in step 406.
In step 4060, a pseudo-random sequence is generated during the operation of the franking machine before each print and thus before each new number of franking imprints to be registered on the basis of the previous number of pieces and, if appropriate, the current time supplied by the clock / date module. For this purpose, a pseudo-random generator is provided with appropriate hardware (not shown) or with a program stored in the internal OPT-ROM of the OTP processor. At least one of the large number of possible random words that can be generated is stored in the internal OPT-ROM of the OTP processor. After a comparison in step 4061 and a subsequent authenticity check of the MAC in step 4062 within the OTP processor, if there is a match, redundant storage of the new code word is stuck once in the non-volatile memories (NVRAMs) and, according to the invention, in the aforementioned non-detachably firmly onto the circuit board non-volatile memory (E<sup>2</sup>PROM) 20 or in the internal OTP-NVM 6d or in the external memory 25. In sub-steps to step 4061 (not shown in any more detail), a large number of stored further conditions can also be queried, the arrival of which results in the storage of a new code word in a non-volatile memory 20, 25 or in the internal OTP memory 6d. Here is an E<sup>2</sup>PROM can be used. The permitted number of read / write cycles for an E<sup>2</sup>PROM is not exceeded if, for example, the average non-volatile memory (E<sup>2</sup>PROM and NVRAMs) are redundantly described with a new code word.
If a code word is used to encrypt accounting data, a so-called MAC is created. In order to store accounting data with an attached MAC in the non-volatile memories 5a and 5b to be protected with each accounting, there is an irregular storage of accounting data with an attached MAC in parallel in the respective non-volatile memory, preferably an E, which serves as second security means against unauthorized manipulation<sup>2</sup>PROM 20 or 25. Before the next billing, in step 406, the billing data in the non-volatile memories 5a and 5b to be protected are usually stored using the attached MAC<i>'</i>s checked. But in the event of a next event arriving in step 4061, the billing data record is transmitted to the OTP 6 in sub-steps of step 4062 (not shown in more detail) in order to use the MAC on the basis of the MAC<i>'</i>s or code word to be checked, which is stored in the non-volatile memory, which serves as a second security means against unauthorized manipulation. The accounting data record is encrypted to a MAC using the code word. The MAC formed in this way is compared with the MAC attached to the accounting data record in the non-volatile memory 5a and 5b to be protected. The comparison can also be made in a crosswise comparison. With authentic MAC<i>'</i>Is branched to step 4063.
In step 4063, provision is made to at least prepare both the formation of the new code word and the storage of billing data before branching to the billing and printing routine in step 406. In the event of a detected error or if the MACs do not match, step 4062 branches back to step 413 for statistical and error evaluation.
Otherwise, if in step 4060 an incorrect pseudo random number Z<sub>is</sub> is generated before each impression during the operation of the franking machine, ie a pseudo random number Z<sub>is</sub>which, in the comparison in step 4061, does not match the at least one random number Z stored in the internal OPT-ROM of the OTP processor<sub>should</sub> results, the system branches to the accounting and printing routine in step 406 without forming a new code word. The MAC formation is then carried out using the previously valid code word.
The invention avoids that if the postal register and its contents are removed without authorization in order to make any number of copies, that mail items can then be franked without billing at the data center or payment at the post office if cloned memory contents are used. It is not necessary to encapsulate the NVRAM components for the postal register with a security housing. If a potential manipulator, for example from the 1st to the 23rd Franking with cloned memories (battery-backed CMOS RAMs) works, this can be determined automatically by means of a self-check by the franking machine if a code word has been changed in between.
It is envisaged that the data contained in the postal register - in particular in the battery-backed CMOS NVRAMs - determined in accordance with a random or pseudo-random sequence number of frankings also in the E<sup>2</sup>PROM 20, 25 or in the internal OTP memory 6d are stored non-volatile.
A potential violator cannot predict when this will happen. This results in an average storage of, for example, 24 frankings, so that the service life of the E<sup>2</sup>PROMs are not reduced compared to the previous solution.
A code is assumed that is saved before each (in vor approx. After the 24th posting) in the E<sup>2</sup>PROM is checked by the processor (in step 4062, Fig. 5) and which for each new storage in the E<sup>2</sup>PROM is changed (in step 4063, Fig. 5). This check code is stored in a kth register of the NVRAMs and can at the same time form a checksum, for example a MAC protection for the register values. The checksum or MAC protection for the register values is done by changing and for NVRAM and E<sup>2</sup>PROM different algorithms and keys formed, which are stored in an OTP-ROM of an OTP processor. This is a copy of the E<sup>2</sup>PROM memory content on the NVRAM is useless if different test codes secure different memories with related or related memory contents.
In a simple variant, an encrypted check code is made from the register values for each quantity for checking <maths id="math0003" num=""><math display="inline"><mrow><msub><mrow><mtext>n = i</mtext></mrow><mrow><mtext>-1</mtext></mrow></msub></mrow></math><img file="EP0762337A2_D0003.tif" /></maths> formed and with the in the E<sup>2</sup>PROM stored MAC compared. In case of equality, there is a number<maths id="math0004" num=""><math display="inline"><mrow><mtext>n = m</mtext></mrow></math><img file="EP0762337A2_D0004.tif" /></maths> , in which in NVRAM and in E<sup>2</sup>PROM data was saved accordingly. The individual register values form for a number<maths id="math0005" num=""><math display="inline"><mrow><mtext>n = z</mtext></mrow></math><img file="EP0762337A2_D0005.tif" /></maths> Franking a table, which includes a line for the quantity m, for which the check code in the E<sup>2</sup>PROM was saved as a MAC. This results in a historical sequence of data for a limited number of z. For a redundant storage of the register values, each individual register value can be encrypted in the E<sup>2</sup>PROM can be saved. An advantage of the invention, however, is that this does not have to be done with every settlement. Nor does each individual register value in the E<sup>2</sup>PROM can be saved redundantly. A potential manipulator cannot restore the data to a row in the table itself. Which keys and algorithms are used where is listed in the OTP-ROM.
A pointer whose data is encrypted or MAC-secured in the E<sup>2</sup>PROM are saved, points to corresponding positions in the list in the OTP-ROM (see Fig. 8). For this purpose, a counter can be decremented or incremented to form the pointer.
When a pseudorandom number is reached (in step 4061, Figure 5) and the MACs are checked by the NVRAM and the E<sup>2</sup>PROM an authenticity of the data resulted, in a preferred variant, billing is carried out and a CRC checksum is formed over all register values at the point in time immediately before franking or before step 406 for the customary billing and printing routine and differently encoded to the NVRAM in the E<sup>2</sup>PROM saved (in step 4063, Fig. 5). If the process then branches to step 406, (FIG. 5), only the print routine needs to be carried out, as is carried out, for example, in EP 576 113 A2, in step 49 of FIG. 6. Otherwise, a branch is made from step 4061 to the normal billing and printing routine (in step 406, FIG. 5) and the billing is carried out in step 406 before printing takes place.
The solution according to the invention is based on an expansion security of the processor with internal or external E<sup>2</sup>PROM with an unsolvable E<sup>2</sup>PROM mounting on the processor circuit board. Before each new number of franking imprints to be registered, a random number is generated on the basis of the previous number of pieces and, if applicable, the current time supplied by the clock / date module. Such electronic counters can also be implemented by means of the battery-supported clock / date module 8. The clock / date module cannot be set to a previous date before the current date. The running time is measured and entered into a random algorithm to form a number. If a predetermined number is reached, redundant storage in the E<sup>2</sup>PROM and NVRAM in the above-mentioned manner are carried out with appropriate security.
In another variant, a pseudo-random algorithm is generated in terms of hardware by means of a bit pattern generator. This is an n-fold shift register with special feedback, which can preferably be part of an ASIC.
In the aforementioned ASIC, E<sup>2</sup>PROM and processor must be implemented with at least their safety-relevant parts.
The pseudo-random algorithm results in an average value of approximately 24 frankings, in which the data is saved redundantly. An E<sup>2</sup>PROM (approx.10,000 cycles) could therefore last 24 * 10,000 = 240,000 frankings.
A non-volatile memory in the OTP or (expanded) E arranged safely to the OTP is advantageous<sup>2</sup>PROM to ensure tamper-proof security against cloned content. In this case, storage is not only dependent on specific times, such as when switching on and / or transition to standby mode, in order to ensure manipulation security in relation to cloned memory contents (branching to point p, FIG. 3), but the aforementioned time is now randomly granted. The time of saving can thus no longer be logically derived or foreseen by a potential counterfeiter, but can only be determined retrospectively in relation to the number of pieces.
In step 406, the content of the register data which has been used for billing in a known manner is checked and changed accordingly, if necessary. For example, with a valid franking with a value> 0, the piece counter R4 is incremented. The register value R1 is reduced and the register value R2 is increased accordingly, so that the register value R3 remains constant. A checksum (for example CRC) is then formed over each of the register values and stored in the NVM 5a and / or NVM 5b together with the associated register values. Such a safeguard, which was placed over the individual register data in order to prevent manipulation, reducing R2 (consumption sum) and increasing R1 (residual value) while R3 remains the same during ongoing operation, has already been proposed in application DE 43 44 476 A1. The MAC (Message Authentication Code) is an encrypted checksum which is appended to the register value when billing in step 406 (FIG. 4). DES encryption is suitable, for example. In franking mode 400 (FIG. 4), the data content can also be checked during billing whether the register value sum R3 is equal to the sum of the ascending register R1 (residual value) and the descending register R2. Due to the security with the encrypted checksums, a content check can be completely dispensed with, especially since the data center carries out such checks each time the franking machine communicates. If all columns of a print image have been printed, the system routine 200 branches back.
In addition to the aforementioned formation of new code words by means of a pseudo random sequence, the non-volatile memories (E<sup>2</sup>PROM and NVRAMs) redundantly described with a new code word. Such another last operating state is associated with predetermined states, as described above.
The number of printed letters and the current values in the postal registers are registered in accordance with the entered cost center in the non-volatile memory 5a of the franking machine during the accounting routine 406 and are available for later evaluation. A special sleeping mode counter is caused to continue counting during the accounting routine which takes place immediately before printing. If required, the register values can be queried in display mode 215 (FIG. 3). This then branches back to the system routine 200.
The TMS370 C010 from the processor family of Texas Instrument is suitable for the postage meter internal safety circuit. This has an internal E<sup>2</sup>PROM of 256 bytes as NVM.
In one variant, the non-volatile internal processor memory and the non-volatile postal register memory (Bat-NV-CMOS-RAM's) to be protected do not contain the identical, but one of the two the complementary code word. The processor internal code word cannot be queried from the outside.
In another variant, different code words are assigned to individual memories, the different code words, however, having a common stem from which they were formed and the common stem being reconstructed by the processor in order to check the validity of the individual code words.
The routine for the code word comparison or for the validity check is queried in the processor each time it is switched on or when the program is continued. If a discrepancy is found in the comparison, the franking machine is blocked for further operation.
It is further provided that the number of new code words formed is counted from a predetermined point in time and is stored in the non-volatile memory in the processor. At the time of communication with the data center, the aforementioned number of code words formed in the past and the currently valid code word are queried. If the franking machine is blocked unintentionally due to invalid code words, this then allows the old state to be restored afterwards by appropriate data transmission from the data center to the franking machine.
It is provided that a last operating state of the franking machine corresponding to the code word is a state as a result of the manufacture or reloading of the franking machine or a state before the franking machine is switched off or a state before a power failure or before a standstill or before a program interruption includes. Such last operating states can also occur when monitoring further criteria, in that the franking machine switches to a corresponding mode. The overall flow chart for the franking machine shown in FIG. 3 has such steps 202 and 207 for monitoring further criteria. If one of the security criteria is violated, the franking machine enters a corresponding mode and additionally executes steps 106 to 109 according to the invention - shown in FIG. 7 - in corresponding subroutines. If, for example, the franking machine enters a sleeping mode when a connection to the data center has not yet been established after a predetermined number of pieces has been consumed, and if communication is not triggered manually by the user, automatic communication with the data center and one takes place when the number of pieces credit is exhausted Implementation of the procedure to increase the security against manipulation of critical register data.
The invention is not limited to the present embodiment, since it is evident that further other arrangements or implementations of the method can be developed or used for other information processing devices, which, starting from the same basic idea of the invention, are encompassed by the appended claims.
16 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| FR2758033A1 | Cited by | France | Search report |
| EP1811460A1 | Cited by | European Patent Office (EPO) | Search report |
| DE19755796B4 | Cited by | Germany | Search report |
| GB2121569A | Cites | United Kingdom | Search report |
| DE4344476A1 | Cites | Germany | Search report |
| US4606003A | Cites | United States of America | Search report |
| US5124926A | Cites | United States of America | Search report |
8 members in 3 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 19534527 | Germany | A | |
| 19534527 | Germany | – | |
| 19534529 | Germany | A | |
| 19534529 | Germany | – | |
| 19534527 | – | – | – |
| 19534529 | – | – | – |
| DE1995134527 | – | – | – |
| DE1995134529 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| EP0762337A2This record | European Patent Office (EPO) | A2 | |
| DE19534527A1 | Germany | A1 | |
| DE19534529A1 | Germany | A1 | |
| US5771348A | United States of America | A | |
| DE19534527C2 | Germany | C2 | |
| DE29522056U1 | Germany | U1 | |
| EP0762337A3 | European Patent Office (EPO) | A3 | |
| DE19534529C2 | Germany | C2 |
10 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Search report despatchedPUAL | PUAL | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phasePUAI | PUAI |
Numbers
- Publication
- 0762337
- Publication, DOCDB
- 0762337
- Publication, EPODOC
- EP0762337
- Application
- 96250191
- Application, DOCDB
- 96250191
- Application, EPODOC
- EP19960250191
Titles3
- German
- Verfahren und Anordnung zur Erhöhung der Manipulationssicherheit von kritischen Daten
- English
- Method and device for enhancing manipulation-proof of critical data
- French
- Procédé et dispositif pour augmenter la protection contre la manipulation de données critiques
Classification
- CPC, 5
- G07B17/00362
- G07B2017/00395
- G07B2017/00403
- G07B2017/00411
- G07B2017/00427
- IPC, 1
- G07B17 00
Designated states6
- Contracting states, 6
- Switzerland
- Germany
- France
- United Kingdom
- Italy
- Liechtenstein