Method for securing data and progam code of an electronic franking machine
Abstract
A summation is used for a starting check (1020) in the frame of the starting and initialisation routine (101) that runs before the printed date routine (1040) and the following system routine (200) for validating the programme code and certain data. The appropriate MAC is entered and the above routine is performed using a summation testing method from the OTP processor, with its algorithm and key. The franking machine is run in the same routine (200) of a similar validation is made, and the process is repeated for various manipulation or handling modes.

Term
Term ended
Projected expiry passed 6 September 2016, 10 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
15 claims: 7 independent, 8 dependent
- 1Verfahren zur Absicherung von Daten und Programmcode einer elektronischen Frankiermaschine mit einem Mikroprozessor in einer Steuereinrichtung der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, wobei in den Schritten für die Start- und Initialisierungsroutine ein Übertragen eines extern gespeicherten vorbestimmten MAC-Wertes und ausgewählter Daten eines zu prüfenden Speicherinhaltes in einen Speicher der Frankiermaschine, ein Bilden einer MAC-Prüfsumme im OTP-Prozessor über den Inhalt desjenigen externen Speichers, welchem der MAC zugeordnet ist, eine Überprüfung auf Gültigkeit der Daten mittels eines ausgewählten Prüfsummenverfahrens innerhalb eines Prozessors durchgeführt wird, um bei Gültigkeit ein Frankieren zu erlauben, gekennzeichnet durch a) Übertragen eines extern gespeicherten vorbestimmten MAC-Wertes und ausgewählter Daten und Programmcode eines zu prüfenden Speicherinhaltes in den internen OTP-RAM zur flüchtigen Speicherung und ein Bilden einer MAC-Prüfsumme im OTP-Prozessor über den Inhalt desjenigen externen Speichers, welchem der MAC zugeordnet ist, für eine Startsicherheitsüberprüfung (1020) im Rahmen der Start- und Initialisierungsroutine (101), welche abläuft vor einer sicheren Druckdatenaufrufroutine (1040) und der nachfolgenden Systemroutine (200), zur Feststellung der Gültigkeit eines gültigen Programm-Code und von gültigen Daten im vorbestimmten Speicherplatz, wobei ein zugehöriger MAC (MESSAGE AUTHENTIFICATION CODE) im selben Speichermittel gespeichert vorliegt und wobei die Überprüfung auf gültigen Programm-Code und auf Gültigkeit der Daten mittels eines ausgewählten Prüfsummenverfahrens innerhalb eines OTP-Prozessors (ONE TIME PROGRAMMABLE) durchgeführt wird, der intern die entsprechenden Programmteile, einen Verschlüsselungs-Algorithmus und einem zugehörigen Schlüssel enthält und b) Überführung der Frankiermaschine in die vorgenannte Systemroutine (200) und Übertragen eines extern gespeicherten vorbestimmten MAC-Wertes und ausgewählter Daten und Programmcode eines zu prüfenden Speicherinhaltes in den internen OTP-RAM zur flüchtigen Speicherung und ein Bilden einer MAC-Prüfsumme im OTP-Prozessor über den Inhalt desjenigen externen Speichers, welchem der MAC zugeordnet ist, für eine kontinuierliche Überprüfung in jedem Durchlauf der Betriebsprogrammschleife, wobei vorschreitend über jeweils eine größere Anzahl von Programmspeicherzellen mittels eines kryptographischen Prüfsummenverfahrens ein relevanter MAC gebildet und mit dem jeweiligen gespeicherten, zum Zeitpunkt T1 gebildeten MAC verglichen werden kann, c) Ablaufen von Programmen, wobei alle wesentlichen Programmabläufe in das Innere des OTP-Prozessors verlegt ablaufen, wobei ein Überführung der Frankiermaschine in einen ersten Modus, wenn mindestens ein überprüftes Programm ungültig ist bzw. ein spezifisches Manipulationskriterium erfüllt ist, durch Schritte zum Verhindern des Frankierens bzw. Sperrens der Frankiermaschine und/oder Schritte zum Verhindern einer weiteren Programmausführung bzw. einer vom OTP-Prozessor nach extern führenden Programmverzweigung im Rahmen vorgenannter Systemroutine (200), und d) Wiederholung der Prüfung der Frankiermaschine auf Vorliegen einer Manipulation im Rahmen vorgenannter Systemroutine (200).
- 2Verfahren, nach Anspruch 1, dadurch gekennzeichnet , daß als ein spezifisches Manipulationskriterium das Intervall zwischen den Prüfsummenvergleichen mit einer zeitlichen Überwachung verknüpft wird, so daß ein Anhalten des Programms erkannt wird.
- 3Verfahren nach den Ansprüchen 1 bis 2, dadurch gekennzeichnet , daß die Frankiermaschine nach Zeitablauf ohne Frankierauslösung und/oder nach einer Anzahl von Programmschleifen-Durchläufen ohne Eingabe im Standby-Modus betrieben wird, wobei im Standby-Modus Sicherheitsüberprüfungen sicherheitsrelevanter Daten und Programme durchgeführt werden und im Fehlerfall eine Protokollierung und anschließende Blockierung der Frankiermaschine erfolgt.
- 4Verfahren nach einem der vorgenannten Ansprüche 1 bis 3, dadurch gekennzeichnet , daß eine Authentizitätsprüfung von mindestens den wesentlichsten Teilen des Programmcodes und den wesentlichsten Daten in Speicherbereichen eines Klischee-EPROM oder eines anderen externen EPROMs durchgeführt wird.
- 5Verfahren, nach Anspruch 1, dadurch gekennzeichnet , daß nach einer Gültigkeitsprüfung die Frankiermaschine in einen zweiten Modus überführt wird, wenn ein spezifisches Kriterium erfüllt ist, wobei die Schritte (201 bis 206), die nach dem Beginnpunkt s der Systemroutine (200) und vor dem Punkt t ablaufen, umfassend:- einen Schritt (201) zum Aufruf aktueller Daten - einen Schritt (202) zur Überprüfung der Daten mittels eines Entscheidungskriteriums und Eintritt bei Erfüllung des Kriteriums in den zweiten Modus (Schritte 203-206), um an den Benutzer der Frankiermaschine eine Warnung und Aufforderung zur Kommunikation mit der Datenzentrale abzugeben sowie gekennzeichnet durch eine Durchführung von Authentizitätsprüfungen in mindestens einem weiteren Modus, wobei zur Bildung des MAC ein im internen OTP-ROM sicher gespeicherter DES-Algorithmus zur Verschlüsselung verwendet wird und daß zugehörige Schlüssel im internen OTP-ROM sicher gespeichert vorliegen, wobei ein Schlüssel für die Absicherung aller Speicherinhalte oder eine Anzahl verschiedener Schlüssel für die Absicherung der unterschiedlichen Speicherinhalte verwendet wird.
- 6Verfahren, nach Anspruch 5, dadurch gekennzeichnet , daß der zweite Modus (Sleeping-Mode) eine Warnung vor der bevorstehenden automatischen Durchführung einer Kommunikation mit der Datenzentrale umfaßt und daß eine Authentizitätsprüfung von Registerwerten aus den Speicherbereichen eines nichtflüchtigen Speichers (NVRAM, EEPROM) bei der Startsicherheitsüberprüfung (1020) und im Frankiermodus durchgeführt wird.
- 7Verfahren, nach Anspruch 6, dadurch gekennzeichnet , daß für die Kommunikation mit einer Datenzentrale ein geheimer erster Schlüssel eingesetzt wird, der im nichtflüchtigen Speicher extern vom OTP-Prozessor in verschlüsselter Form gespeichert vorliegt, der mittels eines internen zweiten Schlüssels innerhalb des OTP-Prozessors entschlüsselt wird, daß der verschlüsselte erste Schlüssel in Verbindung mit dem DES-Algorithmus und dem vorgenannten zweiten Schlüssel entschlüsselt wird, welche im internen OTP-ROM sicher gespeichert vorliegen, daß der entschlüsselte erste Schlüssel in Verbindung mit dem DES-Algorithmus zur Sicherung der Kommunikation der Frankiermaschine mit der Datenzentrale eingesetzt wird.
- 8Verfahren nach Anspruch 7, gekennzeichnet dadurch , daß während der Kommunikation Transaktionen mit verschlüsselten Meldungen durchgeführt werden, um ein Guthaben und/oder weitere aktuelle Daten in die Frankiermaschine zu laden, sowie daß die Transaktionsdaten einzeln und seriell übertragen und durch einen MESSAGE AUTHENTIFICATION CODE (MAC) gesichert werden, wobei die MAC-Bildung intern im OTP-Prozessor erfolgt.
- 9Verfahren, nach Anspruch 8, dadurch gekennzeichnet , daß eine während der Kommunikation mit verschlüsselten Meldungen durchgeführte Transaktion einen Vorgabewert für einen Guthabennachladewert umfaßt, welcher der entfernten Datenzentrale übermittelt wird.
- 10Verfahren, nach Anspruch 8, dadurch gekennzeichnet , daß eine während der Kommunikation mit verschlüsselten Meldungen durchgeführte Transaktion eine spezifische Stückzahl S' für den Sleeping-Mode umfaßt.
- 11Verfahren nach einem der vorgenannten Ansprüche 1 bis 10, dadurch gekennzeichnet , daß im Betriebsmodus (290) ein Schritt (214) für eine Umschaltung in einen Anzeigemodus (215) zur Anzeige von Registerwerten zum Zwecke Ihrer Überprüfung vorgesehen ist, wobei zu Kontrollzwecken wahlweise Registerwerte mit dem frankiermaschinen-internen Drucker ausgedruckt werden können.
- 12Verfahren nach einem der vorgenannten Ansprüche 1 bis 11, dadurch gekennzeichnet , daß alle wesentlichen Programmabläufe in das Innere des OTP-Prozessors verlegt ablaufen und daß die Frankiermaschine auf Vorliegen einer Manipulation wiederholt geprüft wird.
- 13Verfahren zur Absicherung von Daten und Programmcode einer elektronischen Frankiermaschine gegen Manipulation mit einem Mikroprozessor in einer Steuereinheit der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch a) eine Startsicherheitsüberprüfung (1020) im Rahmen einer Start- und Initialisierungsroutine (101), welche abläuft vor einer sicheren Druckdatenaufrufroutine (1040) und der nachfolgenden Systemroutine (200), zur Feststellung der Gültigkeit eines Programm-Codes und/oder von Daten im vorbestimmten Speicherplatz und eines zugehörigen MAC (MESSAGE AUTHENTIFICATION CODE), welche im selben Speichermittel gespeichert vorliegen, wobei die Überprüfung auf gültigen Programm-Code und/oder auf gültige Daten mittels eines ausgewählten Prüfsummenverfahrens innerhalb eines OTP-Prozessors (ONE TIME PROGRAMMABLE) durchgeführt wird, der intern die entsprechenden Programmteile enthält und b) Überführung der Frankiermaschine in die vorgenannte Systemroutine (200) bei Gültigkeit der Daten oder Überführung der Frankiermaschine in einen ersten Modus, wenn die Daten ungültig sind bzw. ein spezifisches Manipulationskriterium erfüllt ist, durch Schritte zum Verhindern des Frankierens bzw. Sperrens der Frankiermaschine (1030) und/oder Schritte zum Verhindern einer weiteren Programmausführung bzw. einer vom OTP-Prozessor nach extern führenden Programmverzweigung im Rahmen vorgenannter Systemroutine (200). c) Durchführung von Authentizitätsprüfungen im Ergebnis der Druckdateneingabe in der Druckdatenaufrufroutine (1040) für Rahmen und/oder Fensterdaten während der Start- und Initialisierungsroutine (101) und im Schritt (209) für sicherheitsrelevante Fensterdaten, welche bei der Druckdateneingabe geändert wurden, wobei bei fehlender Authentizität Schritte zum Verhindern einer weiteren Programmausführung bzw. einer vom OTP-Prozessor nach extern führenden Programmverzweigung im Rahmen vorgenannter Systemroutine (200) und wobei bei bestehender Authentizität Schritte zur weiteren Programmausführung im Rahmen vorgenannter Systemroutine (200) durchgeführt werden.
- 14Verfahren zur Absicherung von Daten und Programmcode einer elektronischen Frankiermaschine gegen Manipulation mit einem Mikroprozessor in einer Steuereinheit der Frankiermaschine zur Ausführung von Schritten für eine Start- und Initialisierungsroutine und nachfolgender Systemroutine mit einer Möglichkeit in einen Kommunikationsmodus mit einer entfernten Datenzentrale einzutreten sowie weiteren Eingabeschritten, um in einen Frankiermodus einzutreten von dem nach Ausführung einer Abrechnungs- und Druckroutine in die Systemroutine zurückverzweigt wird, gekennzeichnet durch a) eine Startsicherheitsüberprüfung (1020) im Rahmen einer Start- und Initialisierungsroutine (101), welche abläuft vor einer sicheren Druckdatenaufrufroutine (1040) und der nachfolgenden Systemroutine (200), zur Feststellung der Gültigkeit eines Programm-Codes und/oder von Daten im vorbestimmten Speicherplatz, b) Überführung der Frankiermaschine in die vorgenannte Systemroutine (200) bei Gültigkeit der Daten oder Überführung der Frankiermaschine in einen ersten Modus, wenn die Daten ungültig sind bzw. ein spezifisches Manipulationskriterium erfüllt ist, c) kontinuierliche Programmüberwachung innerhalb der Systemroutine (200) und Überführung der Frankiermaschine in den ersten Modus, wenn die Daten ungültig sind bzw. ein spezifisches Manipulationskriterium erfüllt ist, wobei über jeden der Subblöcke SB eines Blocks B eine Prüfsumme oder MAC inkrementell berechnet wird, wobei eine kumulierte Prüfsumme bzw. MAC gebildet und ein Vergleich mit einem früher gespeicherten Wert für vorgenannte Prüfsumme bzw. MAC vorgenommen wird, um die Authentizität der Programmteile voranschreitend festzustellen.
- 15Verfahren, nach Anspruch 14, gekennzeichnet durch die Schritte:- Aufrufen der Codewörter des jeweiligen Subblocks SB des aktuellen Blocks B im Schritt (210-1), um darüber insgesamt eine Prüfsumme oder mittels DES-Verschlüssellung einen MAC zu bilden, wobei die Prüfsummen- bzw. die MAC-Berechnung für einen ganzen Block unterbrochen und im nächsten Durchlauf weitergeführt wird und wobei die Prüfsumme bei jedem Durchlauf kumuliert und dann gegebenenfalls wieder der inkrementell MAC gebildet wird, - Vorsehen eines Schrittes (210-2) zum Inkrementieren des Subblockzählers, um fortschreitend im nächsten Durchlauf wieder im Schritt (210-1) kumulieren zu können und um dann den jeweiligen inkrementellen MAC zu bilden, wobei nach dem Schritt (210-2) zum Inkrementieren des Subblockzählers über einen Prüfschritt (210-3) zum Punkt e der Systemroutine verzweigt wird, wenn der maximale Subblockzählerstand SBZmax noch nicht erreicht ist, oder wobei, wenn Endstand bei der Prüfsummenbildung bzw. bei der MAC-Bildung erreicht ist, nach dem Prüfschritt (210-3) in einem weiterem Schritt (210-4) die vorgenannte kumulierte Prüfsumme bzw. der MAC mit einem zugehörig gespeicherten Wert verglichen wird, wobei im nachfolgenden Prüfschritt (210-5) festgestellt wird, ob eine Identität oder ein Fehler vorliegt, - Verzweigen im Fehlerfall, wobei Flag gesetzt, welches in einem Schritt (409) des Frankiermodus (400) ausgewertet wird, oder - Abschluß der Autentifizierung und Durchführung eines Schrittes (210-6) zur Blockinkrementation und eines Schrittes (210-7) zur Rücksetzung des Subblockzählerstandes (SBZ := 0) und der Prüfsumme auf den Wert Null, Prüfen im Schritt (210-8), ob alle Blöcke abgearbeitetet wurden, um den Blockzähler im Schritt (210-9) wieder auf den ersten Block zu setzten (BZ := 0) und Verzweigung auf den Punkt e zur weiteren Abarbeitung der Systemroutine.
Independent claims15
159 paragraphs, as filed
0001The invention relates to a method for securing data and program code of an electronic franking machine in the manner specified in the preamble of claims 1 and 13, respectively. This method improves the security of franking machines.
0002A franking machine generally creates an imprint in a form agreed with the post right-aligned, parallel to the upper edge of the mail item, beginning with the content of the postage in the postmark, the date in the day stamp and stamp imprints for advertising slogans and, if applicable, the type of shipment in the election print stamp. The post value, the date and the type of shipment form the variable information to be entered in accordance with the piece of mail. The postage value is usually the transport fee prepaid by the sender, which is taken from a refillable credit register and used to clear the postal item. In contrast, in the current account procedure, a register is only counted up depending on the frankings made with the postage value and is read at regular intervals by a postal inspector.
0003In principle, every franking made must be accounted for and any manipulation that leads to franking that has not been invoiced must be prevented.
0004A known franking machine is equipped with at least one input means, an output means, an input / output control module, a program, data and in particular storage device carrying the accounting register, a control device and a printer module. In the case of a printer module with a printing mechanism, measures must also be taken so that the printing mechanism cannot be misused for unpredictable impressions when it is switched off.
0005The invention relates in particular to franking machines which provide a fully electronic impression for franking mail, including an advertisement slogan. The result of this is that a valid franking that has not been invoiced must only be prevented when it is switched on.
0006In the case of a franking machine known from US Pat. No. 4,746,234, fixed and variable information is stored in storage means (ROM, RAM) in order to read it out by means of a microprocessor when a letter actuates a microswitch on the transport path in front of the printing position and to send a print control signal form. Both are then electronically assembled into a print image and can be printed out on an envelope to be franked using thermal transfer printing media.
0007A method for controlling the column-by-column printing of a postage stamp image in a franking machine has also already been proposed EP 578 042 A2, which separately composes fixed and variable data converted into graphic pixel image data during column-by-column printing. It would therefore be difficult to manipulate the print control signal without high and expensive effort when printing at a high speed.
0008In the usual way, the memory device comprises at least one non-volatile memory module, which contains the currently remaining remaining credit, which results from the fact that the respective postage value to be printed is subtracted from a credit previously loaded into the franking machine. The franking machine blocks when the remaining credit is zero.
0009Known franking machines contain in three memories at least three relevant post registers for the total value used (increasing register), remaining credit remaining (falling register) and registers for a checksum. The checksum is compared with the sum of the total value used and the available credit. A check for correct billing is already possible with this.
0010Furthermore, it is also possible to transmit recharge information to the franking machine from a data center via a remote value specification in order to reload a credit into the register for the remaining credit (residual value). It goes without saying that suitable security measures must be taken for this so that the credit stored in the franking machine cannot be topped up in an unauthorized manner. Protecting the aforementioned solutions against misuse and attempts at counterfeiting requires additional material and time.
0011From US 4,864,506 it is known that communication to the remote data center is started by the franking machine when the value of the credit in the falling register is below a threshold value and a predetermined time has been reached.
0012From the above-mentioned patent it is also known that the data center for receiving register data and for checking whether the franking machine is still connected to a specific telephone number - connects to the franking machine after a defined period of time and the franking machine only responds at predetermined times.
0013According to the above-mentioned patent, it is also provided to query the identity number of the franking machine and the values in the falling and rising register for authorization by the data center before reloading the credit into the franking machine.
0014Furthermore, it is known from the above-mentioned patent that the communication of the data center with the franking machine need not be limited to the mere transfer of credit into the franking machine. Rather, if the franking machine is deregistered, the communication between the data center and the franking machine is used to transfer the remaining credit of the franking machine to the data center. The value in the falling post register of the franking machine is then zero, which effectively puts the franking machine out of operation.
0015A security housing for franking machines, which has internal sensors, is known from DE 41 29 302 A1. The sensors are, in particular, switches connected to a battery, which are activated when the security housing is opened in order to delete a memory (falling postal register) storing the residual value credit by interrupting the energy supply. As is known, however, it is not possible to predict the state of a de-energized memory chip when the voltage returns. This could result in an unpaid higher remaining balance. On the other hand, it cannot be ruled out that the residual value credit will at least partially discharge in the manner mentioned above. However, this would be disadvantageous during an inspection, since the residual value credit, which had been paid by the franking machine user, must also be reloaded, but the amount of this residual credit may be falsified by the above-mentioned influences. Finally, the description does not show how a manipulator can be prevented from restoring an unpaid remaining balance.
0016In known franking machines, further security measures such as breakaway screws and encapsulated, shielded security housing are already known. Keys and a combination lock are also common to make access to the franking machine more difficult.
0017In US Pat. No. 4,812,994, unauthorized access to the use of the franking machine is also to be prevented by blocking the franking machine if a predetermined password is entered incorrectly.
0018In addition, the franking machine can be set by means of a password and corresponding input on the keyboard so that franking is only possible during a predetermined time interval or times of day.
0019The password can be entered by a personal computer via MODEM, by a chip card or manually in the franking machine. After a positive comparison with a password stored in the franking machine, the franking machine is released. A security module (EPROM) is integrated in the control module of the accounting unit. As a further security measure, an encryption module (separate microprocessor or program for FM CPU based on DES or RSA code) is provided, which generates an identification number in the franking stamp that includes the postage value, the subscriber number, a transaction number and the like. If there is enough criminal energy, a password could also be researched and, together with the franking machine, brought into the possession of a manipulator.
0020A remote inspection system for franking machines has already been proposed in US Pat. No. 4,812,965, which is based on special messages in the printing of mail pieces that have to be sent to the central office, or on a remote query via MODEM. Sensors within the postage meter machine are intended to detect any counterfeiting act that has been carried out, so that a flag can be set in associated memories if the postage meter machine has been tampered with for manipulation purposes. Such an intervention could take place in order to load an unpaid credit into the register.
0021If tampering is detected, the franking machine is blocked by a signal from the data center during remote inspection via modem. A clever manipulation could, on the other hand, consist in returning the flag and the registers to their original state after franking imprints have not been billed. Such manipulation would not be recognizable via remote inspection by the data center if this reversed manipulation was prior to the remote inspection. Receiving the postcard from the data center, on which franking is to be carried out for inspection purposes, also allows the manipulator to reset the franking machine to its original state in sufficient time. This means that no higher security can yet be achieved.
0022The disadvantage of such a system is that a sufficiently qualified manipulator who breaks into the franking machine cannot be prevented from subsequently removing its traces by deleting the flags. It also cannot prevent the impression itself from being manipulated, which is produced by a properly operated machine. In known machines there is the possibility of producing impressions with the postage value zero. Zero frankings of this kind are required for test purposes and could also be falsified subsequently by simulating a postage value greater than zero.
0023A security imprint in accordance with FP's own European patent application EP 576 113 A2 provides symbols in a marking field in the franking stamp which contain cryptified information. This allows the postal authority, which interacts with the data center, to identify manipulation of the franking machine from the respective security imprint at any time. It is technically possible to continuously check such pieces of mail provided with a security imprint by means of appropriate security markings in the stamp image, but this means additional effort in the post office. In the case of a control based on random samples, however, manipulation is usually only detected late.
0024On the other hand, an additional evaluation can be carried out in the data center with regard to a user of a franking machine that was continued to be operated by the user beyond the inspection date. However, it has not yet been possible to conclude from this information that manipulation was carried out with the intention of forgery.
0025In US 4,251,874 a mechanical printing unit, which has to be preset for printing, is used with a detector device in order to monitor the presetting. Means are also provided in the electronic accounting system for determining errors in data and control signals. If this number of errors reaches a predetermined value, the further operation of the franking machine is interrupted. However, the sudden failure of the franking machine is disadvantageous for the franking machine user. With a non-mechanical printing principle, on the other hand, such internal errors are hardly to be expected, and in the case of a serious error, the franking machine must be switched off immediately anyway. In addition, the security against manipulation of the postage meter machine is hardly increased by the postage meter machine being switched off after a predetermined number of errors.
0026A franking machine with program sequence monitoring is known from US Pat. No. 4,785,417. The correct execution of a larger program section is checked by means of a special code assigned to each program section, which code is stored in a specific memory cell in RAM when the program section is called up. It is now checked whether the code stored in the aforementioned memory cell is still present in the program section currently running. If, during manipulation, the run of a program section was interrupted and another program section was running, an error can be determined by such a control question. Such monitoring of the execution of all program parts is based on the difference in the code, and if the number of program parts is very high, the length of the code word must also be correspondingly greater. A comparison of such code words is of course more time-consuming, which causes an additional cost for a faster processor for fast franking machines. In the event of manipulation by means of such error-free program parts from the franking machine, which were put together to form a manipulated program piece, no error would be ascertained, since program branches cannot determine which program branch was executed and how often.
0027Another type of expected manipulation is the reloading of the franking machine registers with an unpaid credit value. This results in the need for secure reloading. According to US Pat. No. 4,549,281, an additional security measure is the comparison of an internal fixed combination stored in a non-volatile register with an input external combination, after a number of failed attempts, ie Non-identity of the combinations, the franking machine is locked by means of escapement electronics. According to US 4,835,697, the combination can be changed in principle to prevent unauthorized access to the franking machine. A method for changing the configuration of the franking machine is also known from US Pat. No. 5,077,660, wherein the franking machine can be switched from the operating mode to a configuration mode by means of a suitable input via a keyboard, and a new meter type number can be entered which corresponds to the desired number of features. The franking machine generates a code for communication with the computer of the data center and the input of the identification data and the new meter type number in the aforementioned computer, which also generates a corresponding code for transmission and input into the franking machine, in which the two codes are compared. If both codes match, the franking machine is configured and switched to the operating mode. As a result, the data center always has exact records of the meter type set for the corresponding franking machine. However, security depends solely on the encryption of the transmitted code.
0028In addition, EP 388 840 A2 discloses a comparable security technique for setting a franking machine in order to clean it of data without the franking machine having to be transported to the manufacturer. Here too, security depends solely on the encryption of the transmitted code.
0029In US 3,255,439, the secure reloading of a franking machine with a credit was on the one hand associated with an automatic signal transmission from the franking machine to the data center whenever a predetermined sum of funds that was franked or the number of processed mail pieces or a predetermined time period was reached. Alternatively, a signal corresponding to the sum of funds, number of pieces or time period can be transmitted. Communication takes place by means of binary signals via converters connected to one another via a telephone line. The machine receives an equally secured reload in accordance with the credit balance and blocks if no credit is replenished.
0030From US 4,811,234 it is known to carry out the transactions in encrypted form and in the process to query the registers of the franking machine and to transmit the register data to the data center in order to indicate a temporal reference to the reduction in the amount authorized to dispose stored in the register. On the one hand, the franking machine identifies itself at the data center by means of its encrypted register content when a presettable threshold value has been reached. On the other hand, the data center modifies the desired franking amount up to which franking can be carried out by means of corresponding authorization signals. Encryption is therefore the only security against manipulation of the register status. If a manipulator always loads the same amount at the same time intervals, but in the meantime franked a much higher amount with the manipulated franking machine than he paid, the data center cannot detect any manipulation.
0031From EP 516 403 A2 it is known to regularly transmit the errors of the postage meter machine that were logged in the past and stored in a memory to a remote error analysis computer for evaluation. Such a remote inspection allows an early warning of an occurring error and enables further measures (service) to be taken. This alone does not offer a sufficient criterion for manipulation.
0032According to GB 22 33 937 A and US 5 181 245, the franking machine periodically communicates with the data center. A blocking means allows the franking machine to block after a predetermined time or after a predetermined number of operation cycles and provides a warning to the user. To unlock, an encrypted code must be entered from the outside, which is compared with an internally generated encrypted code. In order to prevent incorrect billing data from being sent to the data center, the billing data are included in the encryption of the aforementioned code. It is disadvantageous that the warning occurs at the same time as the franking machine is blocked, without the user being able to change his behavior accordingly in good time.
0033A franking machine is known from US Pat. No. 5,243,654, where the current time data supplied by the clock / date module are compared with stored decommissioning time data. If the stored shutdown time is reached by the current time, the franking machine is deactivated, that is to say printing is prevented. When a connection is established with a data center that reads the accounting data from the rising register, the franking machine is transmitted an encrypted combination value and a new period is set, which makes the franking machine operational again. The total amount of consumption, which contains the total postage used and is read by the data center, is also part of the encrypted combination value. After decoding the combination value, the amount of consumption sum is separated and compared with the amount of consumption amount stored in the franking machine. If the comparison is positive, the franking machine is automatically blocked. This solution ensures that the franking machine periodically reports to the data center in order to transmit accounting data. However, use cases are quite conceivable where the amount of mail to be franked fluctuates (seasonal operation). In these cases, the franking machine would disadvantageously be blocked unnecessarily often.
0034The task was to solve the disadvantages of the prior art and to achieve a significant increase in safety without an extraordinary inspection on site. In this case, a manipulation carried out with the intention of falsification is to be recognized and the data security is to be increased without a special mechanical encapsulation or without a sensor being required to detect the opened housing. The safety housing is to be replaced by a housing which improves the accessibility to individual electronic components for the service technician. In addition, a processor without an internal NV-RAM should be used. Another object is to improve the security of the keys in the franking machine that are required for communication with the data center when data is being transmitted.
0035The object is achieved with the characterizing features of claims 1, 13 and 14, respectively.
0036The invention is based on a processor that can only be programmed once.
0037Increased security can be achieved, for example, with a mask-programmed microprocessor that ports to the outside<i>'</i>s and an internal bus structure, an internal ROM, an internal RAM for safety-relevant processes. Safety-related data and routines are burned into the internal Rome during production.
0038A preferred variant is based on a postage meter machine with a microprocessor in which the microprocessor contains an internal ROM which does not allow the program code contained therein to be read out. This can be a commercially available OTP processor (ONE TIME PROGRAMMABLE), which is set to such a state after the programming process by setting / burning a readout lock.
0039The franking machine can also be equipped with an OTP type that allows security-relevant data and programs to be read out in encrypted form (encryption table). This has the advantage that it is possible to check whether the data has been saved properly.
0040The invention has the advantage that program code and constant security-relevant data cannot be changed, cannot be skipped and cannot be spied on. This means that the program execution of program parts that are executed in the internal OTP-ROM cannot be manipulated. As long as there is no program branching, there is secure protection against fraudulent manipulation. According to the invention, the program parts that are executed in the internal OTP-ROM also enable protection of externally stored program parts that are stored, for example, in an EPROM. According to the invention, a multiplicity of keys and an encryption algorithm are also stored in the OTP-ROM, which are used in the execution of programs for security-relevant transactions and in the external storage of security-relevant data.
0041The EPROM takes up most of the program code and provides the microprocessor with an external program code via the microprocessor bus. However, since the program variables are also stored in the internal OTP-RAM, a safety-relevant encapsulation of the program execution is achieved. With an OTP processor, program executions can be realized in different security levels. A faulty or manipulated franking machine remains completely in the OTP-ROM with its program execution and cannot be forced into other operating modes.
0042The solution according to the invention also assumes that the funds stored in the franking machine must be protected against unauthorized access. The falsification of data stored in the franking machine is made so difficult that the effort for a manipulator is no longer worthwhile.
0043Commercial OTP processors (ONE TIME PROGRAMMABLE) can contain all security-relevant program parts inside the processor housing, as well as the code for forming the message authentication code (MAC). The latter is an encrypted checksum that is attached to information. For example, Data Encryption Standard (DES) is suitable as the crypto-algorithm. This allows MAC information to be attached to the security-relevant register data and thus increases the difficulty of manipulating the postal registers to a maximum.
0044These safety-relevant program parts also include program parts for a flow control that monitors the number of program parts that have expired. Malfunctions of the microprocessor or manipulations carried out with the intention of forgery can thus be detected. Specific arithmetic operations allow checking which program parts have been used and how often.
0045Another security measure that can run in addition to the error handling (kill mode) of the start security check is to monitor the program runtime of selected security-relevant programs or program parts in a time supervision mode (kill mode 1). If the runtime of programs or program parts deviates from a predetermined runtime, as occurs when manipulating or monitoring the program sequence using an emulator, the machine is inhibited. Such a program part concerns the communication mode. A secret key for encrypted communication is stored outside the OTP in encrypted form. From this, the OTP can recover the actual key by decryption, which is required for transactions between the franking machine and the data center.
0046The franking machine can enter the second mode from the system routine using a decision criterion in order to issue a warning and request to the user of the franking machine to communicate with the data center. At the same time, the data center also monitors the behavior of the franking machine user on the basis of previous data transmitted during communication.
0047It is provided in the franking machine that a special sleeping mode counter is set to a specific number of pieces each time it communicates with the data center and is prompted to continue counting each franking, ie in the course of a billing and printing routine, until a certain number is reached. The specific number of pieces can be calculated in the franking machine, as well as calculated in the data center and transmitted to the franking machine via a communication link.
0048Starting from the consideration of using only one microprocessor and a suitable program of a franking machine to create a method for improving the security of franking machines, user-specific information about the credit consumption that is present in the data center at the same time forms a first calculation basis in order to store the credit consumption data stored in the data center. and check credit reload date data for plausibility. Another inventive calculation basis based on further data, in particular in connection with the number of pieces since the last communication, allows an extraordinary inspection of the postage meter machine that is considered suspect at the data center.
0049The franking machine, which receives a regular credit recharge and is inspected in the process, can be classified as unsuspicious. However, the franking machine that continues to operate without an inspection over a predetermined inspection date does not necessarily have to be manipulated. Rather, the mail volume to be processed by the franking machine may have decreased above average. If there is still sufficient residual credit available in the franking machine, you can of course continue to frank. In this case, only an extraordinary inspection on site can clarify whether there is any manipulation. To check suspect franking machines, the data center of the postal authority or the institute commissioned with the check transmits the associated franking machine serial number. With this information, the occurrence of mail pieces (letters) from certain senders can be monitored by counting their number in the time interval, for example of 90 days.
0050In the event of an inspection or repair or by on-site service, it may be necessary to intervene in the franking machine. To prepare for the intervention, the registers of the franking machine are queried or printed out in order to determine the type of intervention required. After an authorized intervention in the franking machine has taken place, the original operating state is restored by means of data entered in a special suitable manner.
0051However, if a manipulator performs an unauthorized intervention, the franking machine is effectively put out of operation by switching the franking machine into the first mode (error handling) after being switched on.
0052Another safety measure that can be carried out in the second mode in addition to or instead of a sleeping mode variant is the error overflow mode. This extends the response time of the postage meter machine when a predetermined number of errors is exceeded and reports this status to the operator of the postage meter machine via the display. If the state of exceeding the number of errors is not eliminated, for example in the course of an inspection by a service provider or by resetting during communication with the data center, the reaction time can be increased further to make any manipulation more difficult.
0053The method for securing data and program code of an electronic postage meter machine which is capable of communicating with a remote data center and has an OTP processor in a control device of the postage meter machine also comprises the transfer of an externally stored predetermined MAC value into the internal OTP-RAM and forming a checksum in the OTP processor about the content of the external memory to which the MAC is assigned, and a comparison of the result with the predetermined value of the MAC stored volatile in the internal OTP-RAM before and / or after expiry of the franking mode or operating mode, and thus also after initialization (ie when the franking machine is operated), or in times, in which no printing takes place (i.e. when the franking machine is operated in standby mode). In the event of an error, the franking machine is then logged and subsequently blocked.
0054The invention further comprises carrying out authenticity checks as a result of the print data input for frames and / or window data during the start and initialization routine 101 and an input, display and check routine for security-relevant window data which were changed during the print data input. If there is no authenticity, steps to prevent further program execution or a program branch leading externally from the OTP processor as part of the aforementioned system routine. If there is authenticity, steps for further program execution are carried out as part of the aforementioned system routine.
0055According to the invention, a method is provided, comprising<ul id="ul0001" list-style="none" compact="compact"><li>a) a start security check as part of a start and initialization routine, which takes place before a secure print data call routine and the subsequent system routine, to determine the validity of a program code and / or data in the predetermined storage space,</li><li>b) transfer of the postage meter machine into the aforementioned system routine when the data is valid or transfer of the postage meter machine into a first mode if the data is invalid or a specific manipulation criterion is met,</li><li>c) continuous program monitoring within the system routine and transfer of the postage meter machine into the first mode if the data is invalid or a specific manipulation criterion is fulfilled, a checksum or MAC being calculated incrementally over each of the subblocks of a block, an accumulated checksum or MAC formed and a comparison with a previously stored value for the aforementioned checksum or MAC is carried out to determine the authenticity of the program parts progressively.</li></ul>
0056Advantageous developments of the invention are characterized in the subclaims or are shown below together with the description of the preferred embodiment of the invention with reference to the figures. Show it:<dl id="dl0001"><dt>Figure 1,</dt><dd>Block diagram of a franking machine with increased security according to the invention,</dd><dt>Figure 2,</dt><dd>Variant with OTP in the control device of the franking machine,</dd><dt>Figure 3,</dt><dd>Overall flow chart for the franking machine according to the solution according to the invention,</dd><dt>Figure 4,</dt><dd>Flow chart for the start and initialization routine,</dd><dt>Figure 5,</dt><dd>Schedule for franking mode,</dd><dt>Figure 6,</dt><dd>Formation of a MAC checksum by means of encryption for an external program EPROM,</dd><dt>Figure 7,</dt><dd>Flow chart for testing an external program EPROM<i>'</i>s,</dd><dt>Figure 8,</dt><dd>Formation of a MAC checksum using encryption for an external cliché EPROM,</dd><dt>Figure 9,</dt><dd>Flow chart for testing an external cliché EPROM<i>'</i>s,</dd><dt>Figure 10,</dt><dd>Flowchart for securing selected register data,</dd><dt>Figure 11,</dt><dd>Flow chart for checking selected register data,</dd><dt>Figure 12,</dt><dd>Flow chart for the input encryption of the keys that are used for the secure transmission of data between the franking machine and the data center,</dd><dt>Figure 13,</dt><dd>Flow chart for decrypting the keys for the remote value specification</dd><dt>Figure 14,</dt><dd>Schedule for securing security-relevant data in a freely accessible memory</dd><dt>Figure 15,</dt><dd>Test step in the schedule for securing security-relevant data</dd><dt>Figure 16,</dt><dd>Allocation of the EPROM memory areas</dd><dt>Figure 17,</dt><dd>Schedule for continuous program monitoring</dd></dl>
00571 shows a block diagram of the franking machine according to the invention with a printer module 1 for a fully electronically generated franking image, with at least one input means 2 having a plurality of actuating elements, a display unit 3, a MODEM 23 establishing communication with a data center, further input means 21 or scales 22 which are coupled to a control device 6 via an input / output control module 4 and are connected to non-volatile memories 5a, 5b or 9, 10 and 11 for data or programs which include the variable or the constant parts of the franking image.
0058A character memory 9 supplies the necessary print data for the variable parts of the franking image to a volatile working memory 7. The control device 6 has a microprocessor μP which is connected to the input / output control module 4, to the character memory 9, to the volatile working memory 7 and non-volatile working memories 5a, 5b, which comprise a cost center memory, with a program memory 11, with the motor of a transport or feed device, if necessary with stripe release 12, an encoder (coding disc) 13 and with a clock / date module 8 is connected. The individual memories can be implemented in a plurality of physically separate or combined in a few modules in a manner not shown. The memory module which comprises the non-volatile main memory 5b can be, for example, an EEPROM which is secured against removal by at least one additional measure, for example gluing on the printed circuit board, sealing or potting with epoxy resin.
0059FIG. 1 shows a block diagram of an electronic franking machine with increased security according to the invention. The invention is based on a postage meter machine with a microprocessor which contains an internal OTP-ROM which does not allow the program code contained therein to be read out. Security-related data is also stored in the internal OTP-ROM. To prevent reading by an external intervention, corresponding security bits can be set in the microprocessor during the manufacture of the franking machine. This can be a commercially available OTP processor, which is put into such a state after the programming process by setting / burning a readout lock, or it can be a microprocessor with mask-programmable ROM which, after the manufacturing process, no longer allows the program code to be read out or only read out the program code and the data in encrypted form.
0060FIG. 2 shows a detail of the block diagram of the electronic franking machine for a variant with OTP in the control device. With this basic arrangement in FIG. 2, sensors and actuators, such as the encoders 13 and motor 12 shown in FIG. 1, can be connected to the OTP either directly or via I / O ports.
0061A preferred variant of a microprocessor is an 8051 processor with a 16 kbyte on-chip EPROM (Philips 87C51FB). Such an OTP type (One Time Programmable) cannot be deleted by UV light because it does not have a window suitable for UV light passage . Therefore an OTP can only be programmed once. The internal OTP-RAM has a memory area of 256 bytes.
0062The invention further assumes that the entire program code required to operate a postage meter machine does not fit into the microprocessor-internal ROM, that is, an additional memory (EPROM) is required which holds the greater part of the program code and which is available to the microprocessor via the microprocessor bus program code poses. An arrangement can advantageously be used which divides the program memory into memory segments, so-called memory banks, which allow the program memory area to be enlarged as desired via the address area of the microprocessor by using microprocessor port lines.
0063FIG. 3 shows an overall flowchart for a franking machine with increased security according to the invention, while FIG. 4 shows an inventive detail from it, namely a flowchart for the start and initialization routine.
0064It can be seen from FIGS. 3 and 4 that the franking machine is switched on in step 100 and that a function test with subsequent initialization is then carried out within a start routine 101 and a branch to a system routine 200 is made later.
0065A program code in the non-readable internal OTP-ROM now allows several advantageous start security check routines but at least those as they are named in FIG. 4 and are explained in more detail in connection with FIGS. 7, 9 and 11.
0066These routines relate to the method for securing data and program code of an electronic postage meter and serve to improve the security of this electronic postage meter as part of a start security check in connection with its initialization.
0067After the start, a start routine and an initialization of the franking machine take place in step 101. Such routines initialize the hardware and display in the usual way and start a timer and / or. Interrupt. According to the invention, step 101 includes a start security check 1020. A start security check routine, which uses its program code to check the most important externally held franking machine data and external program code completely encapsulated in the internal ROM and RAM area of the OTP, can detect manipulations that are intentional in the event of manipulation and detect manipulations that occur during the shutdown State of the franking machine has been carried out and then effectively block further operation of the franking machine, if the check routines are not run correctly. In this case, the program flow remains in an endless loop in the OTP-ROM (error handling 1030). Only after the checks have been carried out without errors, the external storage media are used by the microprocessor (read EPROM, write RAM) and the system routine 200 is reached.
0068FIG. 4 shows the schematic program flow chart of all functions that are carried out in the OTP-ROM during the start security check of the franking machine. According to the invention, the start security check of the franking machine comprises a large number of routines, in addition to routine 1026 for securing the external program memory. For example, routine 1021, which is not described in detail, denotes a check of the internal OTP-RAM with regard to its operability. Routines 1022 and 1023 compare the program version numbers, ie determine whether the burned OTP forms a set of complete program code with the EPROM or whether another EPROM belongs to the OTP. Routine 1024 uses the data specified by the cliché EPROM to check whether a valid or the above-mentioned Set of associated cliché EPROM is in the base. It should be mentioned as an advantage that the cliché EPROM may not only be inserted or replaced by the service technician, but also by any other authorized person. Special driver circuits (buffers), which are connected between the bus and EPROM socket (Fig. 2), prevent the reading of data inside the postage meter machine from the outside. On the other hand, data can be entered into the franking machine at any time via the base.
0069While routine 1026 concerns the protection of the external program memory and routine 1025 the protection of the externally accessible EPROM and the data stored therein from manipulation by means of security checks, routines 1027 and 1028 perform a first check of security-relevant or postal register data in the external NVRAM and EEPROM made. Routine 1029 determines invalid or repairable data copies and, if necessary, eliminates the error. In step 1029, as is explained in more detail in the European application EP 615 211 A1, at least one register check of the data structure of the postal register is carried out in order to log the errors. There, a method for correcting the storage of security-relevant data in a postage meter machine is proposed, redundantly stored data being compared with one another in order to reload a memory area with incorrect data with error-free data. However, this is no longer possible with a sixth type of error, because all redundantly stored data now have different errors which can no longer be corrected automatically. Only a service technician could reconstruct the data in a predetermined manner, which has to be done after each authorized opening before the franking machine is started up again. Measures are therefore also taken in step 1030 in order to lock the franking machine in the event of register data structure errors.
0070The routine 1026 for protecting the external program memory described in more detail below is based on the storage of a MAC in the memory module to be protected in each case. In addition to maintaining data security, this has the particular advantage of exchangeability of a faulty program EPROM<i>'</i>s without having to replace the associated OTP at the same time.
0071To secure the external program memory, the MAC method is used in step 1026 to check the integrity of the program code of external bus-coupled memories (EPROMs) before the processor accesses the bus and while the program is running. Advantageously, a secret key that is hidden in the internal program memory so that it cannot be read out can be used to implement secure cryptographic functions, the security of which is based on the use of this secret key. If data relating to a checksum (eg CRC) about the memory content (block 70) of the program memory with a cryptographic function (block 60), such as Data encryption standard (DES), encrypted using these secret keys (block 61), a cryptographic checksum is obtained, the so-called message authentication code (MAC), which contains a checksum (eg CRC) about the memory content (block 70). depicts. According to the invention, this MAC is activated once at a time T<sub>1</sub> formed, to which manipulations are excluded and stored in a non-volatile memory area (block 71) of the external program memory of the microprocessor system. This time T1 is reached only by the franking machine manufacturer, this MAC (T1), for example during program code data creation in the personal computer, using the cryptographic checksum method (for example DES algorithm) and embedded in a defined memory area in the Eprom source data. The above-mentioned data are burned into the EPROM during programming.
0072FIG. 6 shows such a formation of a MAC checksum using the DES method via external program EPROMs, the MAC being embedded in the memory area which is assigned to the memory area to be protected.
0073A start routine and initialization of an electronic franking machine has already been proposed (without explaining this in more detail) in EP 660269, FIG. 2a (step 101). Furthermore, a routine for the initialization has been proposed, in which a security-relevant program code is stored in the OTP and in which a check sum is made in the OTP about the content of the external program memory and a comparison is made. However, the MAC was saved in a special OTP with internal NVRAM. In addition, no measures have been communicated which prevent that, as soon as the microprocessor with a<i><b>Jump</b></i> or <i><b>Call command</b></i> leaves the internal ROM area, a manipulator can take control of the microprocessor with its own program code in the external EPROM and can, for example, skip security check routines that should actually be carried out afterwards in the OTP-ROM. Furthermore, no measures have been communicated which prevent that, as soon as the microprocessor describes the external RAM serving as a data store for its program code to be executed, it can be changed by a manipulator, which can change or disrupt the program sequence.
0074FIG. 7 shows a sequence for checking an external program EPROM using MAC checksum methods for manipulations. At runtime of the postage meter machine, the microprocessor system can use the same cryptographic (step 1026.2) checksum method over the memory area to be checked (step 1026.1) the MAC (in step 1026.2) at time T<sub>2</sub> and later (T<sub>2 + n</sub>) with the help of the same secret key (step 1026.3) and this MAC (T<sub>2 + n</sub>) with the MAC taken from the EPROM (in step 1026.5) (T<sub>1</sub>) compare (see step 1026.6). With such a comparison, the data integrity can be checked and manipulations of the memory contents can be recognized in a step 210 even during the running time of the franking machine. In the event of a negative comparison (as determined in step 1026.7), corresponding measures can then be taken which prevent further operation of the franking machine (as in step 1030) or make manipulation more difficult or indicate such by taking suitable measures.
0075The continuous MAC formation takes place - as shown in step 210 of FIG. 3 - after the start security check 1020 taking place in step 101 in each run of the operating program loop, so that a relevant MAC is formed and progressing over a larger number of program memory cells by means of the cryptographic checksum method can be compared with the respective stored MAC formed at time T1.
0076To explain the continuous program monitoring, reference should be made to a division of the EPROM memory areas with MAC assignment shown in FIG. 16. Since it would take too long to check the entire memory area, the memory is divided into blocks and sub-blocks. For each block B there is an associated MAC, which ensures the validity of the block. For example, one block is 4 KB. With a 128 KB EPROM there are 32 blocks and MAC checksums. Each block B is divided into several sub-blocks SB. These subblocks SB have a size of preferably 16 code words.
0077The continuous program monitoring is explained in more detail using a flow chart shown in FIG. 17. A MAC is not calculated over the entire block during a run, as this would take too long. According to the invention, the MAC is calculated incrementally over each of the subblocks SB of a block B. The 16 code words of the respective sub-block SB are called up in the current block B in step 210-1 in order to use them to form a total checksum (checksum) and, if appropriate, subsequently to form a MAC therefrom using DES encryption. At the beginning, the checksum is still zero. The block counter and the sub-block counter are also set to zero during the start routine. The checksum or According to the invention, the MAC calculation for an entire block is interrupted and continued in the next run. For example, the checksum is accumulated with each run and then the MAC is formed if necessary. The sub-block counter SBZ is incremented in step 210-2 in order to be able to accumulate again in step 210-1 in the next run and then to form the respective incremental MAC. After step 210-2 for incrementing the sub-block counter, a branch is made via a test step 210-3 to point e of the system routine if the maximum sub-block counter SBZmax has not yet been reached. Otherwise all sub-blocks of a block have been run through and the final status for the formation of the checksum or the MAC formation has been reached. Now, in a further step 210-4, the aforementioned cumulative checksum or the MAC can be compared with an associated stored value. The associated stored value is a checksum or a MAC, which authenticates the subblock. The associated stored value can have been stored in the same EPROM to be checked or in another memory, for example in the internal OTP-ROM, at time T1, preferably at the franking machine manufacturer when programming the OTP.
0078If it is determined in the subsequent step 210-5 that there is no identity and thus an error, a branch is made to an error routine (not shown). For example, a flag is set, which is evaluated in step 409 of the franking mode 400 (FIG. 5). Otherwise, in the case of identity, the authentication has been successfully completed and step 210-6 for block incrementation and step 210-7 for resetting the sub-block counter status and the checksum to the value zero are achieved.
0079The current block B is determined by the block counter status BZ of a block counter, which can be implemented in hardware or software. Likewise, the current sub-block SB is determined by the sub-block counter reading SBZ of a block counter, which can also be implemented in hardware or software. Then the next subblock
0080With each pass, an incremental checksum is formed over the 16 code words of a sub-block. When the respective block end is reached (in the aforementioned case after 4096/16 = 256 runs through the system routine), the accumulated checksum with the associated value or the MAC<i>'</i>s compared. If there is a match, the block counter is again set in step 210-6 to the following block (BZ: = BZ + 1) and the sub-block counter is set to the beginning of the new block (SBZ: = 0). The checksum is also zero again. It is then checked in step 210-8 whether all blocks have been processed. If the last block has been processed, the block counter is reset to the first block (BZ: = 0) and then branched to point e. The system is thus continuously checked.
0081The proposed embodiment is adaptable to any system. Depending on the system used, it may make sense to choose the block size and the sub-block size differently. Too small a block size has the disadvantage that the number of MAC checksums increases and thus more memory space is used. A too small sub-block size means that checksums are computed very often and queries are made so that the time required increases again.
0082As a result of the test proceeding over a larger number of program memory cells, the time until a MAC checksum comparison across the entire memory content is relatively short. The interval between the checksum comparisons can also be linked with a time monitoring (not shown), so that a stop of the program is recognized and leads to the same error handling as with a negative MAC comparison.
0083FIG. 8 shows the formation of a MAC checksum using the DES method via EPROMs in the base of the open mail flap. This is a further advantageous application of the MAC method for checking the integrity of the data and the program code of Eproms, which are used in a franking machine with an open mail flap in the externally accessible base.
0084In EP 660 269 a franking machine is also assumed which has a closable and sealed flap which only allows access to the hardware behind it (EPROM socket) to a limited, specially trustworthy group of people. Here it could be assumed that these people did not manipulate the franking machine. A solution has now been found that security can be maintained for a franking machine that has a partially opened mail flap. This has the advantage that the user has access to the cliché EPROM socket and can change the cliché EPROM independently. As can be seen in FIG. 2, this base is connected to the microprocessor bus, ie manipulation could take place in such a way that a manipulator uses a manipulated program EPROM which, like a RESET eprom, takes control of the microprocessor system and thus specifically changes monetary values, entries or security entries in the franking machine or that it uses a manipulated cliché eprom, that contains changed print data of the value stamp (place of sender, postal code of the sender) and would result in manipulation of the value stamp.
0085Figure 8 shows the protection of another external EPROM<i>'</i>s. The above-mentioned principle of MAC security via the memory areas can also be used here, since with a secret key which is hidden in the internal program memory (OTP-ROM) and cannot be read out, secure cryptographic functions can be implemented, the security of which is based on the use of this secret key . If a checksum of these data areas (block 40) is encrypted with a cryptographic function (block 60), for example DES using these secret keys (block 40) creates a cryptographic checksum which maps the memory content. This MAC must once at a time T<sub>1</sub> are formed, for which manipulations are excluded, and is stored (block 41) in the relevant eprom that is used in the cliché base (cliché eprom, RESET-eprom). This MAC (T<sub>1</sub>) is formed, for example, during the program code data creation of the RESET EPROM in the personal computer and during the creation of clichés using the cryptographic checksum method (e.g. DES algorithm) and embedded in a defined memory area in the EPROM source data.
0086FIG. 9 shows the testing of an EPROM in the cliché base using MAC checksum methods for manipulation. At runtime of the postage meter machine, the microprocessor system can use the same cryptographic checksum method (step 1025.2) to use the memory area to be checked (step 1025.1) to determine the MAC at time T<sub>2</sub> the start security check with the help (step 1025.3) of the same secret key and this MAC (T<sub>2</sub>) extracted with the EPROM (step 1025.5) MAC (T<sub>1</sub>) compare (step 1025.6). This comparison (step 1025.6) makes it possible to check the data integrity of the stamp data and to identify tampering with the program code (step 1025.7). In the event of a negative comparison, appropriate measures can then be taken to prevent the franking machine from continuing to operate (error handling 1030).
0087FIG. 11 relates to checking selected postal data values in an electronic franking machine that are secured with a MAC. Such a check is carried out, for example, in step 1027 during the start and initialization routine, in communication mode 300 and in franking mode 400.
0088The start security check in the start and initialization routine is therefore carried out using a selected checksum procedure within an OTP processor (ONE TIME PROGRAMMABLE), which internally contains the corresponding program parts and also the code for forming a MAC (MESSAGE AUTHENTIFICATION CODE), which is why the manipulator cannot understand the type of checksum procedure. Other security-relevant key data and processes are also stored exclusively inside the OTP processor in order to place a MAC protection over the postal register.
0089In EP 660 269 the register values R1, R2, R3, which are stored in a non-volatile NVRAM (see FIG. 1), have already been secured with a MAC. The following version extends this register protection in order to achieve an even higher level of security for the franking machine. Additional cases should also be covered:<ul id="ul0002" list-style="none"><li>1. Piece counter register R4, with which the following security relevant checks are carried out:<ul id="ul0003" list-style="bullet" compact="compact"><li>Suspicious fashion</li><li>Imprint of the R4 value in the franking stamp image for visual post control</li><li>Sleeping mode</li></ul> A manipulation of R4 would question these listed security checks and therefore R4 is included in the subsequent MAC protection of registers.</li><li>2nd Serial number with which the use of NVRAM<i>'</i>s from other franking machines can be prevented. The proposal is based on a postage meter machine that holds the register data, the serial number and other security-relevant data (e.g. code word Y, flags) that can be changed during the runtime of the postage meter machine in an NVRAM (see FIG. 1) that is not soldered onto the control unit, but in one commercially available socket is inserted so that this NVRAM can be pulled out in the event of service and read out with a special service computer, for example to read out register data.</li></ul>
0090A manipulator could open the franking machine and make copies of this NVRAM or that of another franking machine that contains a consistent data set (monetary values, register values, MACs, security data, FLAGs). Now he specifically carries out manipulations on the data record, for example by reducing the billed franking value. During an inspection or the next remote value specification, this manipulation would be noticed, for example, by checking the suspicous mode.
0091If you include the serial number, which is a unique identification of an individual franking machine, i.e. also the unique identification of the data record of the franking machine, in the MAC protection of register data, a data record in NVRAM from another franking machine cannot be used because the serial number is also stored in another non-volatile memory (e.g. EEPROM) that cannot be removed from the franking machine.
0092If the differently stored serial numbers were compared, the manipulation would be recognized and the franking machine would be blocked. To achieve this increased security, the following registers are secured with a MAC and are therefore protected against manipulation:<ul id="ul0004" list-style="bullet" compact="compact"><li>Residual total register R1</li><li>Standard total register R3</li><li>Quantity register R4</li><li>Machine number</li></ul>
0093The principle of this MAC generation is shown in FIG. 10. After each change in the register, for example franking, the MAC is recalculated in which the register with the cryptographic function (block 60)<b>D</b>ata-<b>E</b>ncryption-<b>S</b>standard (<b>OF</b>), using (block 63) the secret key <b>K</b><sub><b>reg</b></sub> be encrypted. The result of the encryption, the<b>MAC</b>, is stored in the reserved data area 50a in NVRAM. The register MAC, like the other post registers, is stored several times in the NVRAM and is stored in the EEPROM for certain events, since this only allows a limited number of memory cycles. FIG. 11 shows the basic sequence of a check with the franking machine switched on. At runtime of the postage meter machine, the microprocessor system can use the same cryptographic checksum method (step 1027.2) via the memory area 50a to be checked (step 1027.1), the MAC (step 1027.4) at the time of the start security check 1020, before each franking (franking mode 400) and before each remote value specification ( Communication mode 300) using the same secret key (block 63, (Step 1027.3) and compare these generated MAC's (Step 1027.4) with the extracted (Step 1027.5) MAC (T1) in Step 1027.6). In the event of a negative comparison (step 1027.7), appropriate measures (step 1030) can then be taken to prevent the franking machine from continuing to operate.
0094FIG. 5 shows the flowchart for a franking mode with test steps integrated according to the invention, which are carried out before printing. These also include the protection of selected postal data values in an electronic franking machine with a MAC, which is explained in more detail in FIGS. 10 and 11.
0095The processes according to the franking mode - shown in FIG. 5 - are explained in conjunction with the block diagrams or processes shown in FIGS. 1, 2 and 3, 4.
0096The invention is based on the fact that after switching on, the postage value in the value print corresponding to the last entry before switching off the franking machine and the date in the day stamp corresponding to the current date are automatically specified that the variable data in the fixed data for the frame for the print and be electronically embedded for all associated data that remain unchanged. These variable data of the window contents are referred to below as window data and all fixed data for the value stamp, the day stamp and the advertising slogan stamp as framework data. The frame data can be taken from a first memory area of a read-only memory (ROM), which also serves as a program memory 11. The window data are taken from a second memory area and corresponding to the input in memory areas B<sub>j</sub> of the non-volatile working memory 5 is stored. A step 1040, shown in FIG. 4, is provided for such plate and / or franking image processing. This step includes an automatic routine for the call of pixel files, the assignment and embedding of pixel image data of the fixed and semi-variable as well as variable print image data. The associated program is stored in the program EPROM and / or in the internal OTP-ROM. Since there is no program branching to program parts stored in the external program EPROM until step 1040, no manipulation of the print image creation can take place. Of course, they can also be found in the aforementioned memories at any time during the running time of the franking machine for the purpose of a new assembly to form an overall representation of a franking image. In a preferred variant, it is provided that the hexadecimal window data in run-length-coded form into the respectively separate memory areas B<sub>1</sub> till B<sub>4</sub> the non-volatile working memory 5a to transfer and store there. In addition, the time in the clock / date module 8 continues to run even when the franking machine is switched off. If step 401 is thus reached in franking mode 400, data that has already been stored may have been used without manual or renewed external data input after the franking machine has been switched on. This setting affects in particular the last setting of the postage meter with regard to the postage value, which is displayed in step 209 before the print data is prepared. The current variable pixel image data (date and postage value) are embedded in the fixed frame pixel image data. Then in step 301 of communication mode 300 or in further steps, such as in step 401 of the franking mode 400, a query of the input means for possible further inputs.
0097In step 209, the data from the aforementioned memory areas are assembled in accordance with a predetermined assignment to a pixel print image even before printing. The variable information in the window provided can be supplemented and modified later. In order to save time, only those parts of a graphic representation that are actually changed are stored in the non-volatile working memory when a change is made. A first memory area A is located in the program memory 11 (for the data of the constant parts of the franking image, among other things), and a further memory area A is located in the cliché EPROM<sub>Ai</sub> (for the advertising slogan frame). The sub memory areas A<sub>i</sub>, A<sub>Ai</sub> frame or fixed data are provided for i = 1 to m, an assigned index i identifying the respective frame, which is preferably assigned to a specific cost center. The corresponding assignment of the respective cost center to the framework data is automatically queried after switching on. In a variant proposed in EP 658 861 A1, after each selection of a user-specific cliché, the cost center can be automatically assigned by entering a cliché number and entered in the memory area C. In another variant (not shown), the cost center must be re-entered in the memory area C after each switch-on during the start routine.
0098All alphanumeric characters or symbols are stored in pixel memory 9 as binary data. The data for alphanumeric characters or symbols are stored in compressed form in the non-volatile working memory 5 in the form of hexadecimal numbers. As soon as the number of the cost center entered is stored in the memory area C, the compressed data from the program memory 11 are converted with the aid of the character memory 9 into a print image having binary pixel data, which is stored in decompressed form in the volatile main memory 7. Working memories 7a, 7b and pixel memory 7c are used below to explain the invention, although this is physically preferably a single memory. For security reasons, the essential image generation program steps will take place in the internal OTP-RAM and are therefore not manipulable.
0099The memory areas in the non-volatile working memory 5 can contain a large number of sub-memory areas, under which the respective data are stored in data records. The sub memory areas B<sub>j</sub> are provided for j = 1 to n window data, different assignments between the sub-storage areas of the different storage areas being stored in a predetermined manner.
0100In each data record of a sub memory area A<sub>i</sub> A<sub>Ai</sub>, B<sub>j</sub> control code and run length-coded frame or window data are contained alternately one after the other. Before printing, in step 209 the respective selected fixed data are transferred from the non-volatile program memory (PSP) 11 into first registers 701, 711, 721, ..., of the volatile working memory 7a, control codes being decoded during the transfer and in a separate memory area of the working memory 7b can be stored. Likewise, the respective selected window data for the postmark and the postage stamp are loaded into second registers 702, 712, 722, .... The registers of sub-memory areas are preferably formed in the memory area of the main memory 7a. In the preferred variant, these aforementioned registers are part of the microprocessor control 6. By decompression, the run-length-coded hexadecimal data are converted into corresponding binary pixel data.
0101The invention furthermore consists in carrying out authenticity checks as a result of the print data input in step 1040 for frames and / or window data during the start and initialization routine 101 and in step 209 for security-relevant window data which were changed during the print data input, steps being taken if there is no authenticity Prevent further program execution or a program branch leading externally from the OTP processor as part of the aforementioned system routine (200) and, if there is authenticity, steps are carried out for further program execution as part of the aforementioned system routine (200).
0102FIG. 14 shows a flowchart for securing security-relevant data in a freely accessible memory in an electronic franking machine. In step 209-1, an entry is made for changing window data. The input is displayed in step 209-2 and then branches to a first test step 209-3 from a number of test steps 209-3 to 209-12. The external program memory (EPROM) also contains, for example, print data of the value stamp and other data, such as, for example, the sender's location, the postal code of the sender, etc., which are to be protected against manipulation by the method explained with reference to FIG. The test steps allow a branching to one of the steps 209-4 to 209-11, if a different value, slogan, cliché or other data was selected when entering. The method described thus has sufficient security, even though the MAC is only formed over the subarea in the EPROM that contains data corresponding to the selection. The process then branches back to step 209-1 via a step 209-20 for resetting the loop counter. If all test steps 209-3 to 209-12 have been carried out without changing or selecting a new value or data, point e is reached.
0103The method disclosed in EP 0 660 269 A2, in which the program is checked by means of MAC only once at the start of the franking machine's runtime, is improved according to the invention by additional security checks of the individually subsequently changed window data. A subsequent exchange of the EPROM data can now advantageously be recognized during the running time of the franking machine in operation. This makes it impossible to tamper with or manipulate manipulated data at the moment when the data is to be read in.
0104Steps 209-10 and 209-11 are explained in more detail in FIG. If no new entry is recognized (step 2090), a branch is made back to step 209-20. Before the MAC is used, the external EPROM data to be secured are completely loaded into the memory of the postage meter machine (step 2091) and a MAC is then formed via this RAM area (step 2092). This MAC is compared in step 2094 with a pre-calculated MAC (step 2093), which is stored at a suitable location, preferably in the external EPROM. The advantage of this variant is that only those data are used in the franking machine that have passed the security check, since the externally accessible EPROM and thus the data for checking and further processing are only read once. This procedure prevents the data from being manipulated later (e.g. by switching the external EPROM), since this only serves to form the MAC and to further process the data <b>once</b> to be read. If the comparison of the formed MAC and the reference MAC, which is preferably located in the external ROM, turns out to be negative, suitable measures can be taken. For the purpose of error evaluation and display, step 209-13 is preferably branched to step 209-14.
0105In the external EPROM, the external data can be stored in memory areas divided into data records that are not required in the franking machine at the same time. This procedure allows one<b>Time saving</b> when checking the external data, because only one <b>Subarea</b> a MAC is formed and must be compared with that stored in the EPROM. The memory required for checking the MAC in the franking machine is thereby reduced. Do z. B. five external data areas (advertising clichés, election prints, etc.), for example, only 1/5 of the total amount of data needs to be transferred to the internal memory (less memory requirement) and also for forming the MAC only about 1/5 of the time is required. There is therefore no need to perform a check on all four data areas that are not required. Depending on the number of data areas to be protected, the same number of reference MACs is also in the external memory (EPROM or ROM).
0106In other variants, the MACs can also be located in the NV-RAM of the franking machine or even in the internal ROM of the franking machine. If the MACs are stored in the internal NV-RAM, this also has the advantage that an unsecured external EPROM or ROM is also authorized by entering a code in the franking machine. As a result, no fixed keys need to be used when generating the external ROMs; each franking machine can have its own key for generating the MACs.
0107The security of this new method is now based on the fact that one or more inaccessible methods (e.g. DES) and / or one or more inaccessible keys are used in the internal OTP-ROM of the postage meter machine, which are used for forming the MAC. The same keys or the same methods have also been used for the MACs stored in the ROM when the ROM was created.
0108When using this method to protect compressed cliché data, the MAC is formed from the unpacked data in RAM. This results in an additional saving of storage space, since compressed and decompressed data do not have to be stored in the franking machine's memory at the same time.
0109In another variant, the external data can also be present in uncompressed form, the data then being taken over directly into the internal memory and the MAC then being formed via the internal memory or parts thereof. The separate safeguarding of the individual cliché parts also has the advantage that the time required for checking the MAC when selecting a cliché remains low, since only the cliché parts that are currently needed are checked. Therefore, not only a MAC is provided for checking the data in a cliché memory (e.g. ROM), but each individual cliché (advertising cliché, election prints or slogan or other parts, such as the "paid fee" bar) has its own MAC.
0110In addition to cliché data, other data to be inserted into the franking machine can also be secured using this method. These data can be located in an external ROM, in an external RAM, in an external NV-RAM, also on a chip card or in a combination of the aforementioned. The check in turn is only carried out after the data has been transferred to the internal memory of the franking machine.
0111If it is determined in step 209-11 that the MACs are not identical, the error can be displayed as in the present case in step 209-14 and the machine can then be blocked. Another possibility, e.g. B. when securing cliché data is to print a standard cliché for this case, which indicates manipulation. This cliché can be printed instead of the manipulated cliché or additionally. It is also possible to change another cliché (eg date, value) so that manipulation can be recognized.
0112The constant parts of the franking image, once called up, are constantly decoded available in the pixel memory area I in the volatile pixel memory 7c. For a quick change of the window data, there is a second memory area B in the non-volatile working memory 5.
0113The number strings (sTrings), which are entered for the generation of the input data with a keyboard 2 or via an electronic balance 22 connected to the input / output device 4 and calculating the postage value, are automatically stored in the memory area D of the non-volatile working memory 5. In addition, data records of the sub-storage areas remain, for example B<sub>j</sub>, C etc. received. This ensures that the last input values are retained even when the franking machine is switched off, so that after switching on the postage value in the value print corresponding to the last entry before switching off the franking machine and the date in the day stamp according to the current date is automatically specified. If a scale 22 is connected, the postage value is taken from the storage area D. In step 401 it is checked whether there is an input. If a new input request is made in step 401, the process branches back to step 209.
0114Otherwise, steps 402 and 404 branch to step 405 to increase a pass counter and to check the number of passes in order to wait for the print output request. The letter to be franked is detected by a letter sensor and thus a print request is triggered. It is thus possible to branch to the accounting and printing routine in step 406. If there is no print output request (step 405), the process branches back to step 209 (point t).
0115If, according to the preferred variant - shown in FIG. 5 - now branches back to point t and step 301 is reached, a communication request can be made at any time or another input can be made in accordance with the steps for data change 209, test request 212, register check 214 and input request 401. Steps 401 to 404, as shown in the variant according to FIG. 5, are carried out again. In the case of a predetermined number of runs, a branch is made from step 404 to step 408. The alternative query criterion can be queried in step 404 in order to set a standby flag in step 408 if there is still no print output request after a predetermined time. As already explained above, the standby flag can be queried in step 211 following communication mode 300. This does not branch to franking mode 400 until the checksum check has shown that all or at least selected programs are complete.
0116If a print output request is recognized in step 405, further queries are made in subsequent steps 409 and 410 and in step 406. For example, in step 409 the presence of authentic register values (FIG. 11), in step 410 the achievement of a further quantity criterion and in step 406 the register data collected for billing in a known manner are queried. In addition, as already explained with reference to FIG. 10, selected registers in the NVRAM of the postage meter machine are protected by MAC formation. If the number of items predetermined for franking was used up in the previous franking, ie number of items equal to zero, step 410 automatically branches to point e in order to enter communication mode 300 so that a new predetermined number of items S is again credited by the data center. However, if the predetermined number of pieces had not yet been used, the process branches from step 410 to the billing and printing routine in step 406. A special sleeping mode counter is prompted in step 406, that is to say during the accounting routine which takes place immediately before printing, to continue counting. Likewise, the number of printed letters and the current values in the mail registers are registered in the non-volatile memories 5a, 5b of the franking machine in the accounting routine 406 in accordance with the entered cost center and are available for later evaluation.
0117If necessary, the register values can be queried in display mode 215. It is also provided that the register values or other service data are printed out with the print head of the franking machine for billing or control purposes. This can be done, for example, in the same way as normal printing of the franking image, but initially another frame for fixed image data is selected, into which the variable data corresponds to that in the non-volatile memory NVM 5 or Register values stored in the cost center memory are inserted, similar to that already in columns 1 to 2 or in claim 9, in German laid-open specification DE 42 24 955, for formation and display in three multi-line information groups or for a necessary switchover to a corresponding one Mode is executed in principle. If a rotated representation is required, contrary to the special explanations in German laid-open specification DE 42 24 955 A1, the data can already be stored rotated in the volatile memory as it is needed for printing. The time-consuming routine of rotating the print data is carried out only once for an additional pixel file when programming the EPROM at the manufacturer, which only requires more storage space but does not tie up any computing power in the franking machine.
0118In another variant, it is also provided that variable pixel image data are also embedded in the remaining pixel image data during printing. According to the position report provided by the encoder 13 about the feed of the postal items or Strip of paper in relation to the printer module 1, the compressed data are read from the working memories 5a, 5b and converted with the aid of the character memory 9 into a printed image having binary pixel data, which is also stored in such a decompressed form in the volatile working memory 7. Further details can be found in European applications EP 576 113 A2 and EP 578 042 A2.
0119The pixel memory area in the pixel memory 7c is therefore provided for the selected decompressed data of the fixed parts of the franking image and for the selected decompressed data of the variable parts of the franking image. After billing, the actual printing routine takes place (in step 406).
0120As can be seen from FIG. 1, the working memory 7b and the pixel memory 7c are connected to the printer module 1 via a print register (P<sub>Reg</sub>) 15 and a printer controller 14 having output logic. The pixel memory 7c is connected on the output side to a first input of the printer controller 14, at the other control inputs of which output signals from the microprocessor control device 6 are applied.
0121If all columns of a print image have been printed, the system routine 200 branches back.
0122When changing to the system routine 200 - as shown in FIG. 3 - after a further step 201 for calling up data, in particular sleeping mode quantity data, a check is first made in step 202 as to whether the criteria for entering sleeping mode are met . If this is the case, a branch is made to step 203 in order to display at least one warning by means of the display unit 3. In this case, further steps 204 to 206 can be run through before branching to step 209. If this is not the case, a branch is also made to step 209. After the steps, point t is reached in any case.
0123After the new entry and input / display routine with print data compilation and call of the required pixel files in step 209, the point e, ie the start of a communication mode 300, is now reached, provided that no relevant defects have been found. For this purpose, a query is made in step 301 as to whether there is a transaction request. If this is not the case, communication mode 300 is exited and point f, ie operating mode 290, is reached. If relevant data were transmitted in communication mode, branch to step 213 for data evaluation. Or otherwise, if the non-transmission is determined in step 211, branch to step 212. It is now checked whether corresponding entries have been made in order to go to test mode 216 when test request 212 is made, otherwise to go to display mode 215 when register status check 214 is intended. If this is not the case, point d, ie franking mode 400, is reached automatically.
0124According to the invention, it is further provided that a statistical and / or error evaluation is carried out in step 213 in order to obtain further current data, which can also be called up in step 201 after branching to the system routine 200. If point e, ie the beginning of the communication mode 300 explained below, is reached, a query is made in step 301 as to whether there is a transaction request. Such can be provided, for example, for reloading credit and quantity or updating other relevant data.
0125The user selects the communication or remote value default mode of the franking machine by entering the identification number (eight-digit postage request number) and by pressing the predetermined T key. If the desired input parameter is displayed correctly, this is confirmed by pressing the predetermined T key of the input means 2 again. The input parameter is edited if necessary. A display corresponding to the input then appears in the display unit 3.
0126By pressing the predetermined T key, the transmission of the input parameter via the MODEM connection is started and the input is checked. The rest of the process runs automatically, with the process being accompanied by a corresponding display.
0127To do this, the franking machine checks whether a MODEM is connected and ready for operation. If this is not the case, the process branches to step 310 to indicate that the transaction request must be repeated. Otherwise, the franking machine reads the dialing parameters, consisting of the dial-out parameters (main / extension, etc.) and the telephone number from an NVRAM memory area F and sends them to the modem 23 with a dial request command. The connection required for communication is then established via the MODEM 23 with the data center. After a predetermined number n of unsuccessful redials for the purpose of establishing the connection, a branch is made back to point e via a display step 310. It is provided that a transaction carried out during the communication with encrypted messages comprises a default value for a credit reload value which is transmitted to the remote data center and / or that another transaction carried out during the communication with encrypted messages contains a specific quantity S 'for a sleeping Fashion includes.
0128One of the transaction requests leads to a specially secured credit recharge in the franking machine. The postal registers which are present in the cost center memory outside the processor are preferably also secured by means of a time control during the credit reload. If, for example, the franking machine is observed with an emulator / debugger, then it is likely that the communication and accounting routines will not run within a predetermined time. If this is the case, ie the routines require considerably more time, this would be recognized in the postage meter machine and, as a result, critical memory areas are irretrievably deleted. This prevents the franking machine from continuing to operate.
0129Relevant keys (crypto keys) are required for the transmission of the data required for a credit and / or quantity reload, which have been stored in the memory in cryptified form. The principle of the security concept is shown in FIGS. 12 and 13.
0130The DES algorithm is preferably applied to the keys required for the remote value specification in order to store them in cryptified form. The data transmission from the franking machine to the data center is also secured in communication mode 300 with a DES algorithm, for which a secret DES key is required. This secret DES key is formed in communication mode 300 by the encrypted keys during the running time of the franking machine, ie are decrypted in the OTP during the communication mode 300 in order to load a secret key KAct into the internal OTP-RAM.
0131FIG. 12 shows the input encryption of the remote value specification DES key K.<sub>fix</sub> to secure the remote value specification DES key K<sub>Fix.</sub> before manipulation.
0132During manufacture or by the service technician, each franking machine receives a fixed remote value default key K via its user interface 2, 3<sub>fix</sub>, which in principle must be kept hidden in NVRAM. For this purpose, the remote value specification key is encrypted in step 60 with the cryptographic function,<b>D</b>ata-<b>E</b>ncryption-<b>S</b>standard (<b>OF</b>) using the secret key stored in the OTP-ROM (step 64) <b>K</b><sub><b>Kfix</b></sub> encrypted. The encrypted secret key<b>K</b><sub><b>fix</b></sub> is now stored in the external data memory (NVRAM).
0133FIG. 13 shows which steps have to be carried out for a remote value specification at runtime of the franking machine, so that the encrypted K<sub>fix</sub>-Value in the external NVRAM the DES key <i>CAct</i> is formed, which is held in the processor-internal RAM for the time of the remote value specification procedure. The secret key K<sub>Kfix</sub> is the internal OTP-ROM (block 64) and encrypted key Crypt K<sub>fix</sub> is taken from the NVRAM. Block 60 of FIG. 13 shows the decryption of DES key K.<sub>fix</sub> and storage in the internal OTP-RAM for the remote value specification in block 65.
0134The franking machine carries out the register check regularly and / or when it is switched on and can thus recognize the missing information if the machine had been opened without authorization. The franking machine is then blocked.
0135The potential manipulator of a franking machine has to overcome several thresholds, which of course takes a certain amount of time. If there is no connection from the franking machine to the data center at certain time intervals, the franking machine becomes suspect. It can be assumed that those who tamper with the franking machine will hardly report to the data center again.
0136The control device 6 has a microprocessor or an OTP. In addition to a microprocessor, the OTP also houses non-volatile memories and other circuits in a common housing. The internal non-volatile memory includes, for example, program memory and in particular also the possibility of setting save bits which prevent the internal non-volatile memory from being read from the outside. These security bits are set in the OTP during the manufacture of the franking machine. Observing such security-relevant routines, such as billing routines, with an emulator / debugger would also lead to a changed time sequence, which can be determined by the OTP. This also includes a clock generator / counter circuit for specifying time intervals or clock cycles, for example for time-out generation or printer control. When a certain time has elapsed and the expected event has not occurred, the clock / counter circuit generates an interrupt which reports to the microprocessor that the time has elapsed without success, whereupon the microprocessor takes further measures. According to the clock generator / counter circuit is used for program runtime monitoring. A known number of clock cycles for the program execution of predetermined program parts is assumed. Before starting the routine, the counter of the clock / counter circuit is preset or reset in a predetermined manner. After the start of the program routine, the counter status is continuously changed in accordance with the clock pulses of the clock generator. After the critical predetermined program parts have been processed, the state of the counter is queried by the microprocessor and compared with the expected value. If a predetermined deviation in the running time of critical or security-relevant program parts is exceeded, the franking machine can therefore no longer be operated for franking (kill mode 1). If a manipulator carries out an unauthorized intervention, the franking machine is effectively put out of operation during the runtime by switching to the first mode.
0137The register status is checked during an inspection. If necessary, a test impression with the value 0 can be made. In the event of a repair by the on-site service, the franking machine may have to be accessed. The error registers can be read out, for example, with the help of a special service EPROM, which is inserted in the place of the advert EPROM. If the processor does not access this EPROM slot, access to the data lines is usually prevented by special driver circuits (buffers) shown in FIG. 2. The data lines, which can be reached here through an unsealed housing door, cannot be contacted without authorization. Another variant is the reading out of error register data by a service computer connected via an interface, the interface then having to have appropriate security measures.
0138It is also provided at times when there is no printing (standby mode) that a query regarding manipulation attempts is made and / or the checksum of the register statuses and / or the content of the program memory PSP 11 is formed. To improve the security against manipulation, the check sum for the kill mode 2 is formed in the OTP via the content of the external program memory PSP 11 and the result is compared with a predetermined value stored in the OTP. This is preferably done in step 101 when the postage meter machine is started, or in step 213 when the postage meter machine is operated in standby mode. Standby mode is reached if there is no input or Print request is made. The latter is the case if a letter sensor known per se - not shown in detail - does not determine the next envelope to be franked. Step 405 in franking mode 400, shown in FIG. 5, therefore includes a further query for a timeout, which ultimately leads back to point t and thus to the input routine according to step 209 if the time is exceeded. If the query criterion is met, a standby flag is set as in step 408 and a branch is made back directly to point s to system routine 200 or point t without the billing and printing routine being executed in step 406. The standby flag is queried later in step 211 and reset after the checksum check in step 213 if no attempted manipulation is detected.
0139To this end, the query criterion in step 211 is expanded to include the question of whether the standby flag is set, ie whether the standby mode has been reached. In this case, a branch is also made to step 213. The advantage of this method in connection with the first mode is that the manipulation attempt is statistically recorded in step 213.
0140In order to further increase security against manipulation, a flow control is used according to the invention, which is explained below. Such a flow control is carried out by changing a count value in a memory at at least one point during the execution of the program routine. After execution of the program routine, the changed count value is compared with a predetermined count value assigned to this program routine. If branches are run through during program execution, different count values can result. In a subsequent evaluation, a plausibility test is carried out or it can be determined which branches have been run through. This is possible because the change in the count value takes place by multiplication by a specific prime number assigned to the respective program part. In a later evaluation, only a prime number decomposition then has to be carried out.
0141In another variant, where only such program parts without branches are taken into account or no tracing of the program branches that have been run through is necessary, an incrementing of the count value and a final comparison with at least one predetermined numerical value is sufficient.
0142The overall flowchart for a security system shown in FIG. 3 has steps 201 to 206 for monitoring further criteria. If one of the security criteria is violated, the franking machine enters a sleeping mode, for example if a connection to the data center has not yet been established after the consumption of a predetermined number of pieces.
0143The franking machine and the data center each agree on a predetermined number of items S, ie the amount that can be franked until the next connection is established. If communication fails (quantity control), the franking machine slows down its mode of operation (sleeping mode variant 1).
0144Another variant issues a constant warning that the franking function is about to go to sleep in step 203, which must now be run through in step 202 before the step 205 is reached due to the fulfilled query criterion. It is further provided that step 203 comprises a sub-step for error statistics in accordance with the statistics and error evaluation mode 213.
0145The franking machine requires a connection to the data center in the manner known from US Pat. No. 3,255,439. If the connection is established, the data center checks the register status. If the reload cannot be carried out, the data center prevents it from further operation by means of a signal transmitted to the franking machine. If the connection was established shortly after the signaling performed by the franking machine and the register statuses are not criticized, the franking machine can be switched back to the operating mode without any further extraordinary inspection. For this purpose, new current data are transmitted, for example for a credit and for the permitted number of pieces, which can be franked until the next connection is established.
0146The data center can differentiate between automatic and normal communication based on the transmitted signaling code. The former will always take place if the user of the franking machine has overlooked or ignored the requests for communication and has omitted appropriate input actions. In the event of repetition, if a manipulation is suspected, a special inspection can be arranged.
0147The franking mode can then be branched back directly to the communication mode 300 point e. This means that other inputs can also be made, for example in accordance with the steps of test request 212 or register check 214. Only if a branch is made to franking mode 400 is it then determined again in step 410 according to the decision criterion whether automatic communication is required. This is preferably the case if the predetermined number of pieces has been used up.
0148If the communication was successful and data was transmitted (queried in step 211), step 213 is also reached. In step 213, the current data are determined or loaded, which are called in step 201 and then required again in the comparison in step 202. The transmitted decision criterion is preferably the new number S '.
0149An alternative variant consists in that the decision criterion is the new credit transmitted for franking and in evaluation mode 213 the new number S 'is determined internally in the franking machine. In this case, communication with the data center no longer includes the new number S ', but is only required to trigger the calculation in evaluation mode 213. The calculation is carried out internally in the franking machine and at the same time in parallel in the data center using the same methods based on the transmitted register data.
0150The franking machine can transmit register values to the data center before reloading the credit:<ul id="ul0005" list-style="none" compact="compact"><li>R1 (descending register) remaining amount in the franking machine,</li><li>R2 (ascending register) amount of consumption in the franking machine,</li><li>R3 (total resetting) the total sum of all remote values,</li><li>R4 (piece count Σprinting with value = / = O) number of valid prints,</li><li>R8 (R4 + piece count Σprinting with value = O) Number of all prints follows:<maths id="math0001" num="(1)"><math display="block"><mrow><mtext>R3 = R2 + R1</mtext></mrow></math><img file="EP0762338A2_D0001.tif" /></maths></li></ul>
0151With each remote value specification, R1 can be queried and statistically evaluated. If R1 becomes larger and larger, the same reload amount can be reloaded in ever larger reloading periods, or the number of pieces that can be franked until the next communication is set.
0152A franking machine profile can be created on the basis of the franking machine-specific data. This franking machine profile provides information as to whether a customer was able to carry out the determined number of frankings with the reloading processes carried out. There are two levels within Suspicious Mode:<ul id="ul0006" list-style="none" compact="compact"><li>1. Franking machine is suspicious and</li><li>2nd Franking machine must have been manipulated.</li></ul>
0153A plausibility check of all franking machines in use is carried out in the data center at regular intervals. In this process, the machines are identified and reported to the postal authority whose franking behavior appears suspicious or has been manipulated. Another security measure (error overflow mode) may be provided in the franking machine. In the second mode, this can be carried out in addition to or instead of sleeping mode variant 1 or sleeping mode variant 2. If the query criterion in step 202 is met, ie if a predetermined number of errors are exceeded, the response time of the postage meter machine slows down in step 203, this status being simultaneously reported to the operator of the postage meter machine via the display. In the further steps, the procedure can be similar to that already explained in connection with FIGS. 2 and 5. The postage meter machine stores both internal and operating errors and manipulation attempts in an error register for protocol purposes, for example up to the number 999. If the state of exceeding the number of errors is not eliminated, for example in the course of an inspection by a service provider or by resetting during communication with the data center, the reaction time can be increased further to make any manipulation more difficult. The number of errors is then logged, ie again up to a predetermined number, for example in step 213.
0154A first variant provides for the reaction time, for example the time until the start of printing, to be increased linearly with the number of errors. The execution of the program is neither modified nor prevented, but only delayed. In particular, such non-critical program parts that are not monitored by time supervision (kill mode 1) or flow control are called several times, such as the error display. This means that the effectiveness of the program remains essentially unchanged.
0155In a second variant, the reaction time is increased by one level, whereby the levels can relate to seconds, minutes, hours, days, ... etc.
0156In a modification or in combination with the aforementioned variants, an increase in the response time can also be provided for each incorrect operation. In one embodiment, an electronic time lock is actuated for this purpose. A progressive increase in the response time is preferably provided in the operating program in order to make manipulation more difficult.
0157It is provided that step 213 is partially or completely called up as a sub-step in connection with other steps. For example, the statistics and error mode is part of step 203 and the billing and printing routine according to step 406 in franking mode 400, which is shown in more detail in FIGS. 3 and 5. If a severe accounting error occurs, the machine is blocked in step 406. However, if an error occurs during the initialization phase in step 101, the machine stops and displays a specific error code.
0158On the other hand, there are serious errors that can only be remedied by an authorized person on the next inspection on site. Such an error, for example if the processor cannot access the main memory, ie can neither read nor change the data content of the RAM, is eliminated, for example, by inserting a special RESET EPROM. For this, the sealing of the flap and the franking machine must be opened. The RESET EPROM contains the necessary data, for example the corresponding key, and special programs to restore the franking machine function. For example, such a program can undo a reduction in redundancy. The logging of the errors, which takes place during the operation of the franking machine in the statistics and error evaluation mode (step 213) separately according to the types of errors, is checked by the authorized person to determine whether a manipulation attempt has been made.
0159The invention is not limited to the present embodiments. Rather, a number of variants are conceivable which make use of the solution shown, even in the case of fundamentally different types.
14 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0908852A3 | Cited by | European Patent Office (EPO) | Search report |
| US6362724B1 | Cited by | United States of America | Applicant |
| EP0927968A3 | Cited by | European Patent Office (EPO) | Search report |
| EP1095343A4 | Cited by | European Patent Office (EPO) | Search report |
| EP0927969A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0927970A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0927969A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0927968A2 | Cited by | European Patent Office (EPO) | Search report |
| EP1202223A3 | Cited by | European Patent Office (EPO) | Search report |
| EP1095343A1 | Cited by | European Patent Office (EPO) | Search report |
| EP1063619A1 | Cited by | European Patent Office (EPO) | Applicant |
| US6199752B1 | Cited by | United States of America | Applicant |
| EP0927971A3 | Cited by | European Patent Office (EPO) | Search report |
| EP0930586A2 | Cited by | European Patent Office (EPO) | Search report |
| US7974927B2 | Cited by | United States of America | Applicant |
| EP1202223A2 | Cited by | European Patent Office (EPO) | Applicant |
| EP1063619A1 | Cited by | European Patent Office (EPO) | Search report |
| EP0927971A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0927970A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0908852A2 | Cited by | European Patent Office (EPO) | Search report |
| EP1069492A2 | Cited by | European Patent Office (EPO) | Search report |
| EP0930586A3 | Cited by | European Patent Office (EPO) | Search report |
| US6418422B1 | Cited by | United States of America | Applicant |
| EP1069492A3 | Cited by | European Patent Office (EPO) | Search report |
| EP1063619A1 | Cited by | European Patent Office (EPO) | Search report |
| US6295523B1 | Cited by | United States of America | Applicant |
| EP0281225A2 | Cites | European Patent Office (EPO) | Search report |
| DE4129302A1 | Cites | Germany | Search report |
| DE4344476A1 | Cites | Germany | Search report |
| US4726025A | Cites | United States of America | Search report |
4 priority claims, no other members on record
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 19534530 | Germany | A | |
| 19534530 | Germany | – | |
| DE1995134530 | – | – | – |
| 19534530 | – | – | – |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application refused18R | 18R | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN REFUSEDSTAA | STAA | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| First examination report despatched17Q | 17Q | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 0762338
- Publication, DOCDB
- 0762338
- Publication, EPODOC
- EP0762338
- Application
- 96250192
- Application, DOCDB
- 96250192
- Application, EPODOC
- EP19960250192
Titles3
- German
- Verfahren zur Absicherung von Daten und Programmcode einer elektronischen Frankiermaschine
- English
- Method for securing data and progam code of an electronic franking machine
- French
- Procédé pour sécuriser les données et le code de programme d'une machine d'affranchissement
Classification
- CPC, 3
- G07B17/00733
- G07B2017/00774
- G07B2017/00951
- IPC, 1
- G07B17 00
Designated states6
- Contracting states, 6
- Switzerland
- Germany
- France
- United Kingdom
- Italy
- Liechtenstein