Device and procedure for manipulation of a memory device
Abstract
Die Erfindung schafft eine Adapter-Vorrichtung und ein Verfahren zum Manipulieren des Speicherbausteins (4) einer Chip-Karte (1). Der für den Zugriff auf die Chip-Karte (1) erforderliche Schlüssel ist nur in der Adapter-Vorrichtung (2) abgelegt, und Dritten unzugänglich gemacht. Hierdurch ist erstmals ermöglicht, daß eine unbegrenzt große Anzahl von Akzeptanzstellen eine Chip-Karte zum Abspeichern spezifischer Informationen nutzen kann, wobei weder hinzukommende Anbieter von dem Zugriff auf bestehende Chip-Karten ausgeschlossen werden noch Anbieter die Möglichkeit haben, Daten der Wettbewerber anzusehen oder zu manipulieren.

Term
Term ended
Projected expiry passed 17 April 2017, 9.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
23 claims: 2 independent, 21 dependent
- 1Adapter-Vorrichtung zum Manipulieren eines Speicherbausteins (4) einer Chip-Karte (1), und die als Einsatz in einem Terminal (16) für elektronische Zahlkartensysteme geeignet ist, umfassend - Mittel (12) zur Herstellung einer Datenaustausch-Verbindung mit dem Speicherbaustein (4);- ein Speicherelement (20), in dem ein Prozessor-Programm abgelegt ist;und - eine Spannungsversorgung (Ue), gekennzeichnet durch - mindestens einen im Speicherelement (20) abgelegten Schlüssel, mit dem auf zugeordnete, innerhalb des Speicherbausteins (4) der Chip-Karte (1) an speicherplatzmäßig nicht vorausbestimmten Stellen sowie möglicherweise nur vorübergehend enthaltene bzw. belegte Speichermittel zugegriffen werden kann.
- 2Adapter-Vorrichtung nach Anspruch 1, mit - Mitteln zum Lesen von im Speicherbaustein (4) gespeicherten Inhalten;und - Mitteln zum Schreiben von Inhalten in den oder zum Löschen von Inhalten aus dem Speicherbaustein (4).
- 3Adapter-Vorrichtung nach Anspruch 1 oder 2, bei der die Verbindungsherstellmittel eine berührende Datenaustausch-Verbindung mit den Kontaktierungsflächen (6) der Chip-Karte (1) definieren.
- 4Adapter-Vorrichtung nach einem der Ansprüche 1 bis 3, bei der die Verbindungsherstellmittel mit einer Antenne einen berührungslosen Datenaustausch ermöglichen.
- 5Adapter-Vorrichtung nach einem der Ansprüche 1 bis 4, bei der ein unterbrechbarer Sicherheitsschaltkreis (Ui, D, S1, S2, Z, A) vorgesehen ist, der von der Spannungsversorgung (Ue) gepuffert ist, und der nach einer Unterbrechung den Zugang zu dem Schlüssel im Speicherelement (20) außer Betrieb setzt.
- 6Adapter-Vorrichtung nach Anspruch 5, soweit auf Anspruch 2 rückbezogen, bei der nach einer Unterbrechung der Spannungsversorgung auch die Mittel zum Lesen und/oder die Mittel zum Schreiben oder Löschen außer Betrieb gesetzt werden.
- 7Adapter-Vorrichtung nach Anspruch 5 oder 6, bei der das Außerbetriebsetzen durch ein externes Kommando aufhebbar ist.
- 8Adapter-Vorrichtung nach einem der Ansprüche 5 bis 7, bei der der Sicherheitsschaltkreis eine interne Spanungsversorgung (Ui) aufweist, die mittels eines zeitgesteuerten Schalters (S2) abschaltbar ist.
- 9Adapter-Vorichtung nach Anspruch 8, bei der die innere Spannungsversorgung ein Akkumulator (A) ist.
- 10Adapter-Vorrichtung nach Anspruch 8, bei der die innere Spannungsversorgung eine Batterie ist.
- 11Adapter-Vorrichtung nach einem der Ansprüche 1 bis 10, bei der von dem Terminal (16) über eine Datenaustausch-Verbindung vorgegeben wird, welche Operationen Mittel zum Lesen oder Mittel zum Schreiben oder Mittel zum Löschen ausführen sollen, und die Operationen nur ausgeführt werden, wenn sie nach einer im Speicherelement (20) abgelegten Tabelle auch zulässig sind.
- 12Adapter-Vorrichtung nach Anspruch 11, gekennzeichnet durch - Komparatormittel mit einem ersten und einem zweiten Eingang, wobei dem ersten Eingang eine Abfragekennung zuführbar ist, und dem zweiten Eingang über die Kontaktierungsmittel und die Mittel zum Lesen eine Speicherkennung zuführbar ist, und mit einem Ausgang, der ein logisches JA-Signal abgibt, wenn eine Speicherkennung und die Abfragekennung übereinstimmen.
- 13Adapter-Vorrichtung nach Anspruch 12, dadurch gekennzeichnet, daß die Abfragekennung und Speicherkennung als Binärzahlen dargestellt sind, und daß ein Vergleich jeder Stelle der Binärzahl vorgenommen wird.
- 14Adapter-Vorrichtung nach Anspruch 12, dadurch gekennzeichnet, daß die Abfragekennung und Speicherkennung als Binärzahlen dargestellt sind, und daß ein Vergleich nur einiger der Stellen der Binärzahl vorgenommen wird.
- 15Adapter-Vorrichtung nach einem der Ansprüche 1 bis 14, bei der ein Zeit-Komparatormittel vorgesehen ist mit einem ersten und einem zweiten Eingang, wobei dem ersten Eingang eine Real-Zeit zugeführt wird und dem zweiten Eingang der Inhalt eines Verfallsdatums-Feldes aus dem Speicherbaustein zugeführt wird, der eine Information über einen Verfallszeitpunkt enthält, und mit einem Ausgang, der ein JA-Signal abgibt, wenn der Verfallszeitpunkt vor der Real-Zeit liegt.
- 16Adapter-Vorrichtung nach einem der Ansprüche 1 bis 15, dadurch gekennzeichnet, daß sie an eine Wiedergabeeinheit angeschlossen ist, und daß ausgewählte Bereiche des Speicherbausteins (4) der Chip-Karte (1) von der Wiedergabeeinheit angezeigt werden.
- 17Adapter-Vorrichtung nach einem der Ansprüche 1 bis 16, dadurch gekennzeichnet, daß Mittel zur Speicherung eines für die Änderung der Belegung des Speicherplatzes der Chip-Karten (1) repräsentativen Wertes vorgesehen sind.
- 18Adapter-Vorrichtung nach Anspruch 17, bei der die Belegung des Speicherplatzes als Produkt der Länge eines neuen Datensatzes und des Zeitraums der Gültigkeit des Datensatzes berechnet wird.
- 19Anbieterterminal für Erwerb von Waren und/oder Dienstleistungen mittels einer elektronischen Geldbörse (1), die zusätzlich zu dem Bonitätsspeichermitteln Zusatz-Speichermittel für andere Daten aufweist, mit einer Adapter-Vorrichtung (2) nach einem der Ansprüche 1 bis 18, die in Datenaustauschverbindung mit den Zusatz-Speichermitteln bringbar ist und mit Mitteln zum Lesen, Löschen und Schreiben des Zusatzspeichers, wobei der Adapter (2) jedoch so programmiert ist, daß in Abhängigkeit von der Art des Terminals nur ausgewählte dieser Mittel und nur bezüglich ausgewählter Speicherplätze im Zusatzspeicher aktivierbar sind.
- 20Verfahren zum Manipulieren eines Speicherbausteins (4) mit beschreibbaren Speichermitteln einer Chip-Karte (1) mit einer die Information adressierenden Kennung, gekennzeichnet durch die folgenden Schritte:(a) Prüfen, ob Informationen mit der Kennung bereits in den Speichermitteln gespeichert sind;(b) Falls das Prüfungsergebnis positiv ist: Lesen der Informationen, Berechnen einer resultierenden Information, Überschreiben der unter der Kennung gespeicherten Information durch die resultierende Information.
- 21Verfahren nach Anspruch 20, gekennzeichnet durch die folgenden Schritte im Anschluß an Schritt (b):(c) Prüfen, ob die Speichermittel ausreichend Platz zum Schreiben einer weiteren Information aufweisen;(d) Falls der Platz ausreicht, Speichern der Information in dem ersten freien Speicherplatz.
- 22Verfahren nach Anspruch 20 oder 21, gekennzeichnet durch die folgenden Schritte vor einem der Schritte (a) bis (d):(e) Lesen und Vergleich eines in jeder Information gespeicherten Verfallszeitpunkts mit der Real-Zeit;(f) Löschen aller Information, deren Verfallsdatum überschritten ist.
- 23Verfahren nach Anspruch 21, gekennzeichnet durch die folgenden Schritte im Anschluß an Schritt (c):(g) Falls der Platz zum Schreiben nicht ausreicht, Löschen von Informationen mit überschrittenem Verfallsdatum, bis der Platz zum Schreiben ausreicht.
Independent claims23
67 paragraphs, as filed
The present invention relates to an adapter device and a method for manipulating the memory chip of a chip card, in particular for the purpose of establishing a data exchange connection.
A large number of chip cards from the prior art each require adapted devices for contacting the same. Chip cards are known from practice which have a memory module connected to a card and which can be contacted via contacting areas. The memory module for a telephone card, for example, comprises a number of registers, the assignment of which represents a binary numerical value which expresses the telephone units available or the corresponding amount of money.
Chip cards are also used for banking services, one of the embodiments being referred to as an "electronic wallet". With such a chip card (or smart card) it is possible to open or close a certain amount of money at an electronic "petrol station". which is then available for the cashless payment of goods or services. When the loaded amount of money has been used up, the wallet is empty and, as with the non-electronic namesake, must first be refilled. In order to improve the acceptance of electronic wallets, it has been proposed to provide, in addition to the function as an electronic wallet for the chip card, so-called additional applications which access reserved memory spaces in another area within the same memory module.
In order to ensure a certain protection against misuse, it is provided that a so-called personal identification number (PIN) must be entered into a terminal when the chip card is being charged, but generally not for paying with the chip card. A comparator integrated in the bank terminal then compares the entered PIN with a secret number stored in the memory module, the result of the comparison - possibly among other criteria - decides whether to accept or reject the transaction. The secret number must be stored in a protected memory area in order to prevent it from being overwritten by another known number or from being read out without authorization. This procedure is essential to protect the authorized person for transactions such as loading money, but for applications in which the acceptance points or your data should be protected, not practically transferable. Because if the secret number or a corresponding key is known, each acceptance point could access any application, but this should be rejected because of the mutual protection of competitors and other participants.
An improved method uses a security application module (SAM) provided in the terminal, which is also referred to as a "dealer card". First, the terminal reads the freely accessible chip card content (data) and sends the data to the SAM. To check the chip card, the SAM generates a random number and sends it via the terminal to a processor area of the chip card's memory module. On the basis of the random number, processors in the chip card and SAM independently calculate an outcome value using an algorithm, which is compared by a comparator provided in the SAM, the result of the comparison serving to accept or reject the card. This solution not only requires the algorithm to be stored in the ROM memory of each chip card, it is also not possible to selectively design access to individual applications, since a successful comparison makes all applications accessible.
A chip card known from practice has, for a finite number of additional applications, in the memory module, in addition to the wallet, also a finite number of physical data storage areas, each taking up a previously defined storage space and being called "elementary files" be designated. Each data storage area includes a key storage area, also called a "dedicated file", which can contain a secret key, and a "master file" that is superior to all files. This chip card cannot be used flexibly because the dedicated files once assigned to an additional application (e.g. student ID card) can no longer be used for another additional application (e.g. student ID card). Furthermore, the rigid principle of this card is inherent as a disadvantage that usually only reserved occupancy is possible for reserved applications (e.g. electronic tickets), so that it is not possible to save tickets from several different providers simultaneously or in succession. Furthermore, there is no possibility to communicate cross-wise between the applications, for example if a parking garage wants to grant a discount on the parking fee when shopping in a particular department store. Because this requires knowledge of the "key" of the respective partner and its storage in the operating software of the terminal; the subsequent use or misuse with such shared access can then no longer be undone. However, these restrictions lead to a low level of acceptance of the card as a whole, in particular also because applications that have not yet been recognized remain excluded for the time being. Furthermore, this card has the crucial disadvantage that it is not easily possible for its holder to look at the contents of the card that concern him. Since every provider of an additional application wants to keep the key of his own elementary files secret, the cardholder can only find out anything about his status - if at all - at the providers' terminals. It would be desirable if this were possible in the form of a list for all or at least many applications.
From a completely different field of technology it is known in practice to install decoder devices between so-called pay-TV applications between the cable connection and the television set, which are intended to ensure that only customers of the pay-TV provider can transmit the originally encrypted signal get the decoder decrypted.
It is the object of the invention to propose a technique which enables an improved use of chip cards by creating an adapter device or a method for manipulating (processing) the information stored on the chip card.
This object is achieved according to the invention by the features of patent claim 1.
The adapter device according to the invention improves the options for operating a chip card. Such an adapter device is independently interconnectable with the chip card, and data exchange is only provided with the dealer terminal via interfaces of data lines. The dealer terminal can thus be built according to the requirements of the dealer, e.g. integrated solutions for the cash register and terminal, ticket machine and terminal, etc. Access to the adapter device is generally denied to unauthorized persons, so that the key stored in the storage element is made available to a large number of acceptance points in distributed operation without being accessible to them. It is economical if the adapter device only provides the key in the manner of an interface, and the terminal with the means for writing / reading / erasing which it already has, for example are available for the operations of an electronic wallet that carries out writing or reading processes. Compared to known systems, the adapter device also enables access to storage means which are not originally present in the memory module of the chip card and / or are present at a specific location. This gives the Adater device a high degree of flexibility, which also permits "retrofitting" with one or more keys. Furthermore, resource-saving, dynamic, demand-dependent use of the available memory space of the memory module is made possible.
Preferably, however, the adapter device has the means for reading, writing and deleting information in the memory chip of the chip card itself, which reduces the possibilities for misuse of a chip card by unauthorized manipulation, and also more space on the chip. Card for additional applications remains, or the technology of the terminal is simplified. If it is necessary to make improvements in the operating system or in the application, it is easier to access the permanently installed adapter devices than to call back all chip cards. In the case of terminals which are only intended for displaying the content of individual chip cards, the means for writing and deleting can of course be dispensed with.
It is possible to design the adapter device in such a way that it can only enter into a data exchange connection with the chip card, or in such a way that it can establish a data exchange connection without contact. The adapter device is advantageously designed in such a way that it can manipulate hybrid card systems with both options for data exchange on an equal basis.
The security circuit also ensures that when the adapter device is removed from a terminal, the adapter device is no longer ready for use after a certain time, as a result of which narrow limits are set on misuse. The adapter device can only be programmed by an authorized body, which limits the access options of the terminal to very specific applications when reading and writing to the chip card.
The safety circuit comprises, for example, an accumulator and a consumer, which are adjusted to one another in such a way that disconnection of the accumulator from the mains supply causes a discharge within a predetermined period of time, and that the reactivation of the circuit is only possible by entering a password or by certain physical interventions .
A particularly preferred development of the invention not only allows the adapter device to deliver the key to the storage means, but also decides on the basis of a table stored in the storage element whether or not each individual access to each individual identifier for carrying out each individual operation is permitted. Since the adapter is not accessible to third parties anyway, this important test function can be advantageously integrated. It is suitably provided for this that the adapter device is equipped with comparator means which trigger an actuation of the adapter device in a first processing mode when a predefined identifier on the chip card matches a predefined identifier, and which actuate the device trigger in a second processing mode if no identifier on the chip card matches the specified identifier. The first processing mode is expediently to delete or overwrite the data belonging to the identifier, while the second processing mode is to create a data record with the identifier. According to a suitable development, the comparator means can also be designed in the manner of a filter in such a way that the result of the comparison can only be generated as a function of a partial agreement of the identifiers. In this way, for example, a user can have several identifiers with a common core for similar or similar additional applications or applications shared with other users, which he processes according to his own ranking of priorities. A parking garage operator would query all "parking garage identifications" and then first check whether a long-term parking permit (e.g. Monthly parking ticket), then whether a valid "voucher" from a partner company has been saved on the chip card, then whether there is a wholesale discount for this customer, and finally whether the parking time has already been bought and credited in advance. Ultimately, the customer can still pay with the electronic wallet.
In particular, it is possible to equip the adapter device with a time comparator means which compares an expiry date of a data record on the chip card with the real time and, depending on the result of the comparison, deletes or leaves the data record in question intact. This surprisingly simple measure means that, according to a particularly preferred method, "file corpses" can be regularly removed from the second memory means of the chip card independently of the identifiers; however, it is also possible to carry out this comparison operation only when space is required.
Means are preferably provided in the storage element which serve to store a value which is representative of the newly occupied storage space consumption by measuring the actually used resource and assuming that it remains in the storage means until the expiry date. Further means which serve to store a credit of data records deleted before the expiry date in the storage means can also be provided. The total values or the balances can be forwarded to a central billing center via a data line and billed to the acceptance points.
Chip card and adapter device can be ideally combined to form a circuit in which means for writing and reading the adapter device interact with the memory chip of the chip card. The adapter device is installed in or at the terminal, and the latter are interconnected via interfaces. The terminal is preferably a terminal that is suitable for processing payment transactions with the electronic wallet mentioned at the beginning.
It is clear to the person skilled in the art that the technology according to the invention can also be used for chip cards which use other cashless payment methods than the electronic wallet, for example credit cards or debit cards.
The method according to the invention enables a memory card-efficient use of a chip card. Compared to methods from the prior art, in which an additional application is either already provided when the card is issued or is not possible, applications can be created and deleted again with chip cards with freely addressable storage means. It is therefore necessary to propose an adapted method according to which it is advantageously ensured that an identical application identified by its identifier is not saved multiple times.
A method step is preferably provided which makes it possible to delete obsolete information according to a time criterion, by reading an expiry date stored with the information for each data record and comparing it with real time, and deleting the data record when the expiry date is exceeded. It is particularly advantageous if the information about the expiry date is processed with the identifier in order to minimize the search effort. In addition to this "automatic" deletion of applications that have exceeded their expiry date, it is possible to delete applications completely or partially, for example as a result of the consumption of a credit.
Alternatively, it is also possible to search for expired entries that are ready for deletion only when there is really a need for storage space, so that there are not unexpectedly long waiting times.
The invention is explained below using an exemplary embodiment with reference to the drawings, in which<ul id="ul0001" list-style="none" compact="compact"><li>Fig. 1 shows a section through part of a chip card which is inserted into an adapter;</li><li>FIG. 2 shows a schematic illustration of a memory chip of the chip card from FIG. 1;</li><li>3 (a) to (e) are schematic representations of memory organizations of the non-volatile memory of the memory chip from FIG. 2;</li><li>4 shows a schematic illustration of an adapter according to the invention in longitudinal section;</li><li>FIG. 5 shows a schematic illustration of a safety circuit for an adapter from FIG. 4; and</li><li>6 illustrates a specific application.</li></ul>
Fig. 1 shows a chip card 1 and an adapter 2, which are in engagement with each other. The chip card 1 consists of the card body 3 made of plastic, into which a memory module 4 is integrated. The memory module 4 is fixed in the body 3 by means of an adhesive 5. Several, for example six, flat metal contact surfaces 6, which can also be fixed by the adhesive composition 5, are arranged in the body 3 in a planar manner. There is no line contact between the adjacent contact surfaces 6. The contacting surfaces 6 are arranged essentially in a star shape and are connected to the memory module 4 via gold wires 7, which are embedded in the adhesive mass 5. The adhesive mass 5 is an electrical insulator. A central contacting area can be located directly above the memory module 4 and cover it completely.
The adapter 2 has a slot-shaped card holder 8, which is dimensioned such that it can accommodate a chip card 1 in the longitudinal direction at least to the extent that the contacting areas 6 of the chip card 1 are completely received. The receptacle 8 is preferably provided with a slightly conical shape in order to ensure an essentially self-centering axial guidance and to avoid tilting when the chip card 1 is inserted. The bottom region 9 of the receptacle 8 is biased by springs 10 in the direction of the opposite top 11. Instead of springs, other pressing means can also be provided. The pretension is released as long as the card 1 is in the region of the inlet opening 8a of the receptacle 8, and only presses the card 1 towards the top 11 when the contacting surfaces 6 are below conductor pins or pins 12. The pins 12 are arranged on the upper side 11 of the receptacle 8 such that each pin 12 permanently contacts a contacting surface 6 for producing an electrical contact. The receptacle 8 has eight pins 12. However, it is possible to provide recordings which have fewer pins 12 than the associated card contacting areas 6. 6 of the 8 individual contacts are actually used (1 for clock input, 1 for data input / output, 1 for reset, 2 for supply voltage potentials, 1 for zero potential). Communication between card 1 and adapter 2 takes place via commands that originate from the latter, card 1 reacting “passively”, ie giving answers. Different functions, in particular the storage means, are accessed using different commands issued by card 1 (or the program included) can be interpreted accordingly. A line 13, which can also be designed as a conductor track in a circuit board, leads from each pin 12. It is also possible to also slightly bias the individual pins 12.
The division of the memory module 4 is explained in more detail with reference to FIG. 2. The memory chip comprises a ROM area which is non-volatile and can only be read; The processor program of the electronic wallet is stored in this ROM area, and also the programs which enable the search in the EEPROM memory area. The EEPROM area is a non-volatile memory that can be read, erased and written to. Information about the wallet function is partially stored here, for example information about the date of the last cash withdrawal and other information that may also be specific to the issuing financial institution. Unless originally provided with data from the financial institution, this area, or a certain part of it, can be described with additional applications. Finally, the volatile RAM memory is used for calculations, the results of which should or should only be recorded for a short time, which is mostly done in the field of wallet applications. The ROM and EEPROM areas occupied by the wallet application form the first storage means, which can only be accessed with the knowledge of a PIN. The rest of the area, including some "free" functions in the ROM area, forms second storage means, although other storage means can of course also be provided in addition to the second storage means. In order to be able to access the second storage means, the key thereof must be able to be specified.
The figures 3 (a), (b) and (c) illustrate the possible file organizations in data records within the EEPROM. The data records can have a fixed, stepped or variable length. Variable or stepped lengths adapt to the respective requirements of the application and take up only or approximately as much space as the application requires.
Storage and management are preferably carried out as data records with a graduated length. On the one hand, they adapt well in length to the need; on the other hand, the removal and re-entry of sentences requires only a short amount of time, so that rapid processing at the terminal is ensured. The EEPROM area consists of a sequence of data fields of the same length, adjacent to each other; A data record then takes up one or more data fields that are linked together (1 header field and subsequent fields). A separate table of contents contains the identifiers K of the existing data records, the associated expiry dates V and a series of pointers to the occupied fields, cf. Fig. 3 (d).
A modified structure does not need a separate table of contents. Here, the identifier K and the expiry date V are in the data records (or header areas) themselves; in addition, each data field contains a header H, which indicates whether the field is free or occupied, and which may contain a reference (pointer) to the data field with which it is linked to form a complete data set, cf. Fig. 3 (e).
It is clear that access to data fields is only "free" if the correct key has previously been transmitted by adapter 2.
The chip card 1 has in its memory module 4 first and second memory means, both of which can be contacted via the contact areas 6, the access to the first memory means taking place in accordance with the known access to an electronic wallet, ie a secret number is required for filling while paying can be done anonymously. On the other hand, access to the second storage medium is always possible anonymously (even if anonymity is not always intended). Thus, provided that the key in adapter 2 is accessed, the entire memory area can be read, whereby the information can be stored in encrypted form and the code on which the encryption is based is only known to the provider of the additional application or his business partners. In this way, plain text information can also be stored, which is available to all readers of the chip card. This is explained in more detail below.
The storage space available in the second storage means for general information (part of the storage space is required by the wallet functions) can be used universally, ie it is in principle available for applications of all types and therefore for data records of any structure and scope. Accordingly, it is not necessary to create data records from the start (e.g. during the production or initialization of the card), but this is only necessary when it is actually needed, which increases flexibility in production and advantageously ensures the permanent expandability of the user group.
Each type of data record of a specific application can be added according to its specific application, whereby it can be identified by the identifier and structured according to the application.
4 shows the adapter 2 with its components. The adapter consists of the receptacle 8, on the top 11 of which a printed circuit board 14 is arranged. The adapter 2 is fastened to the housing 15 of a terminal 16 by means of screws, at the same time covering the inlet opening 8a of the receptacle 8. It is possible to provide locks or the like so that the card 1 or the adapter 2 cannot be manipulated, in particular during operation. Terminal 16 is a sales terminal where tickets for a trade fair are sold.
The semiconductor board 14 is provided with a memory element 20 which is active, ie it can execute commands for reading or writing the chip card by means of a program stored in the memory element 20. An important role of the adapter 2 is that it at least partially realizes a physical separation between the terminal 16 and the chip card 2, and in this way acts as a separation or as a buffer.
The key for accessing the second storage means of the chip card 1 is stored (hidden) in the storage element 20. In this way, it is withdrawn from the access of the terminal operator, so that advantageously the resource storage space can be divided among an unlimited number of acceptance points and application providers.
In part of the memory element 20, a table is also stored, in which it is noted for the specific terminal 16 which identifiers K it is permitted to access (each divided into reading, writing, deleting). For security reasons, this function is stored in the adapter 2, so that each user can have a terminal manufactured according to his wishes, in which only the adapter 2 has to be installed. But even if, for example if the theft of an adapter disappears, it cannot be reprogrammed without detailed knowledge of the memory element 20, so that only the functions from the terminal 16 are available to the thief. This is a fundamental improvement over known security modules, in which any application is possible after overcoming secret code locks. The read, write or delete request is passed from the terminal 16 to the adapter 2, which initiates an admissibility check and only allows the request to be carried out if the access is authorized.
The power supply of the adapter 2 takes place via the terminal 16 (not shown). It is fundamentally possible to provide the adapter 2 with its own transformer in order to achieve the required power supply, but this is better provided elsewhere in the terminal 16 for reasons of space and cooling. In the event of a power failure, buffering can be provided via a time-limited battery operation. It is possible to provide the adapter 2 with a motor which triggers the retraction and return of the chip card 1 via wheels or the like.
The active memory element 20 can access the various memory areas of the memory module 4 via the contacting areas 6 and the pins 12 and lines 13. However, it is alternatively possible to implement these functions with a contactless chip card.
The adapter 2 also has an abuse lock which prevents the adapter 2 from being removed from the terminal 16 and being misused in another terminal. 5, the abuse lock includes a circuit which will be explained in more detail below. In the event of (also brief) failure of the external supply voltage Ue (also in particular by removing the adapter 2 from the terminal 16), the battery A decoupled via the diode D continues to take over the internal voltage supply Ui. The switch S1, however, switches off immediately, whereupon a timer Z starts, which in turn switches off a second switch S2 after a time t, which disconnects the internal voltage supply Ui and thereby kills the entire adapter. It can only be put into operation again when switch S1 is reinitialized via an external, encrypted signal; the decryption is carried out by a corresponding circuit E. It goes without saying that the circuit E can be stored in the memory element 20.
The mode of operation of the invention is explained in more detail below using an example.
The holder of a chip card 1 functioning as an electronic wallet (hereinafter: the customer) intends to visit a trade fair. In advance sales, the exhibition company will use vending machines to offer tickets for the trade fairs taking place in the next six months, which are, for example, the following: car (takes place in the first calendar week); Boat (2nd week); Chemistry (2nd and 3rd KW); Kite (4th week); Email (5th KW); Fish (6th week); Garden (7th week); and hotel (9 KW). The trade fair company has a unique numerical identifier that can be represented as a binary number.
The customer would like to visit the two fairs boat and chemistry. He pays for the two tickets with purse 1; the admission tickets are stored in the memory module 4 under the trade fair identifier.
There is a public transport company at the trade fair location. It sells two types of tickets via its machines against payment with the electronic wallet. Type I is a single ticket, the cost of which is proportional to the number of sections traveled. So if the customer wants to get out after 5 stations, he has to pay 5 monetary units. Type II is a long-term ticket, in which a flat rate must be paid to use the entire local transport network.
There is also a university at the trade fair site that issues a student ID for its students, which is valid for one semester and is extended upon payment of the semester fee in advance. Another requirement is that the student has health insurance.
The trade fair company has a cooperation agreement with the operator of the public transport company to the effect that a trade fair visitor can use a shuttle bus from a trade fair car park P to the trade fair site M and back free of charge, the parking permit being valid as a ticket. Furthermore, the admission ticket on the day of the visit to the trade fair is valid as a voucher for 10 stations by public transport.
The university has a cooperation agreement with the operator of the public transport company in that a student (of course only this university) receives a free season ticket during the semester.
The trade fair company reduces the entrance fee for students by 20%.
If a customer C1, who is also a student, now wants to buy a trade fair admission ticket at a sales terminal 16, the following steps are carried out:<ul id="ul0002" list-style="none" compact="compact"><li>(1) The customer C1 enters his purchase request via an input device, for example a student admission ticket for the Boot trade fair;</li><li>(2) <ul id="ul0003" list-style="none" compact="compact"><li>(a) Customer C1 is prompted via an on-screen display to insert his electronic student ID;</li><li>(b) after this has been done, an adapter 2 integrated in the terminal performs a reading function in which all the identifiers which express a student ID application are compared;</li><li>(c) if there is a student ID application, the expiry date entered in the data field is compared with the current date; if the expiry date has passed, it is optionally possible to delete the record;</li><li>(d) If a valid student ID is not present, the sale of a reduced admission ticket will be refused;</li></ul></li><li>(3) If a valid student ID is available, various cases can be considered:<ul id="ul0004" list-style="none" compact="compact"><li>(3.1) Customer C1 would like to pay 1 with the same electronic wallet; then the debit is made from wallet 1 and the admission ticket is written in its EEPROM.</li><li>(3.2) The customer would like to pay with an external (or own, second) electronic wallet 1 ';</li><li>(3.2.1) If the terminal still has a second inlet (only) for an electronic wallet 1 ', the wallet 1' is inserted into the second inlet, the amount is debited, the entry card is written on the first card 1, both cards 1 , 1 'output;</li><li>(3.2.2) If the terminal does not have a second entrance, either the student ID can be issued again, the second card 1 'inserted and written if the stored and freely readable personal data are identical; or, if the data are not identical, the electronic student ID 1 must then be reinserted to credit the reduced admission ticket;</li><li>(3.3) like (3.1) or (3.2), but the EEPROM area is full and does not allow any further labeling; then you can optionally search whether expired (comparison expiry date) fields can be deleted to make room; or an (optionally personalized) entry ticket is printed out from the terminal;</li></ul></li><li>(4) If the amount of money on the electronic wallet 1 or 1 'is insufficient, this is indicated and a sale does not take place;</li><li>(5) Finally, card (s) 1 and 1 'are returned.</li></ul>
This procedure ensures in a particularly advantageous manner that customers who are entitled to a discount can only benefit from the discount themselves. A transfer to an unauthorized person is largely avoided. It is also possible to check the expiry date of a student's eligibility, regardless of the university at which he is enrolled.
Optionally, for example, in step (2) it can also be checked whether student ID 1 will still be valid at the time of the fair. If a full-paying customer C2 buys a trade fair card, steps (2) and (3.2.2) are essentially superfluous.
The date of expiry after the purchase of the admission ticket is first noted in the data record on the last day of the trade fair (the general terms and conditions of the trade fair company stipulate that reimbursement of the entry price upon cancellation of the visit after the trade fair has expired).
Customers C2 (full payer) and C1 (student) now both have an admission ticket stored on their electronic wallet 1. You both get on the bus line to the exhibition center M at the bus stop B near a parking lot P + R. From there there are 8 stations.
There is a terminal 16 'in the bus, but optionally also at the bus stop, which can read the electronic wallet 1. The terminal also has an input peripheral device, for example a keyboard or a touch screen monitor, in which the passengers enter their destination. This serves on the one hand to pay the fare, but on the other hand also for statistical purposes: For example, the average traffic load, waiting times, etc. are determined, and these are further differentiated according to passenger types.
The terminal 16 'is provided with an adapter device 2 which, in addition to handling a pure payment function, reads all identifiers K which have a zero at a specific point in the identifier. This includes the applications of the local transport company, but also other applications shared with third parties, in the present case the exhibition company.
The processor is therefore authorized to access the "trade fair" data record. Information is preferably stored which contains information about the earliest day of the fair. If the terminal is "fed" with the chip card on a trade fair day, a dialog develops, for example on a screen of Terminal T:<dl id="dl0001" compact="compact"><dt>T:</dt><dd>Do you want to visit the Chemistry Fair today?</dd><dt>C1:</dt><dd>No</dd><dt>T:</dt><dd>Do you want to visit the Boot fair today?</dd><dt>C1:</dt><dd>YES</dd></dl>
The adapter device 2 now debits the credit from 10 stations 8 and overwrites the corresponding field with the balance of 2 remaining stations. On the return trip, the 2 stations are initially billed, then 6 stations must be paid for. Furthermore, the validity of the trade fair admission ticket is advantageously changed to the day itself, so that the trade show card can already be deleted the next day.
If several trade fairs take place at the same time and several tickets are booked, measures such as the dialog must be taken so that the booking is made correctly.
Basically, it is only necessary to provide storage space for the bus tickets in the EEPROM on the day of the visit to the fair. However, it is preferably provided that a field is reserved for the bus ticket when the exhibition ticket is purchased. This can, for example by the fact that when purchasing a trade fair card, several (linked) fields are used by the application, which can be divided into a bus ticket and a day visitor ticket on the day of the visit, so that it is ensured that chip card 1 has space when boarding the bus for storing the remaining credit balance (e.g. 2 free stations above). Optionally, this measure can be dropped on a student card if it is ensured that the student is studying at the university that works with the local transport company, ie is not a student from outside the country. Regardless of this, either when the chip card is full or with each application, it can be checked whether "old" data records that are ready for deletion can be removed to create free storage space.
If a student from the local university takes the bus, it must of course be ensured that the free ride is taken into account first.
The sequence of steps explained above can generally be used when tempering and debiting a chip card.
It is possible to partially or completely block the EEPROM memory space available when the chip card is issued by assigning "dummies". This happens, for example, with certain field sizes, which are then sold to users. In fact, the bank, for example, stores its own data record, the expiry date of which is long. If she wants to make this space available to a contract partner, she can pass on (sell) the identifier, in which case the purchaser of the identifier independently accesses the storage space according to his own application, and preferably deletes the old identifier and writes data records with his own identifier.
The memory space on the chip card 1 is a valuable resource, so that preferably the person who uses it or uses it should pay compensation: For this purpose, the adapter 2 will record a record of length L (measured e.g. in byte) generated with the key K and the expiry date V, an allocation amount in a register of the adapter 2 <maths id="math0001"><math display="inline"><mrow><mtext>BB (K) = L * (VD)</mtext></mrow></math><img file="EP0803838A2_D0001.tif" /></maths> determines where D stands for the current date. The occupancy amounts BB (K) are collected over a period of time and accumulated in a total memory SBB (K). The content of the total memory is queried, processed and reset on a regular basis and serves as a measure of the effective storage space occupancy on the entirety of the circulating chip cards 1. If a data record is deliberately deleted before the expiry date, adapter 2 calculates an early removal amount <maths id="math0002"><math display="inline"><mrow><mtext>BE (K) = L * (VD)</mtext></mrow></math><img file="EP0803838A2_D0002.tif" /></maths> instead, which is also stored in a sum memory SBE (K), and is also queried and processed. The balance of the two total memories, which is preferably only calculated after being called up, then reflects a fair evaluation of the actual occupancy of the chip cards.
It goes without saying that all previous vending machines and supplier terminals that operate on the basis of coin insertion or payment by credit cards can be equipped with an adapter according to the invention.
A special terminal in this sense is a so-called wallet, in which the card holder can view a certain, freely visible part of the stored data unhindered or after entering a password or PIN (in principle, this is only a means of Read content required). The background is as follows: On the one hand, the cardholder has the right to be informed at any time about the data relevant to him, which are stored on the card. As described above, there are often even monetary claims, such as the bus ticket, or bonuses for loyalty functions in retail or a status that distinguishes it (student, student, disabled person, resident, etc.). He must be able to read and preferably also print out these data either at erected info terminals or at portable readers, the wallets, or else on the personal computer, which is provided with an adapter according to the invention, and, if possible, in an understandable plain text. On the other hand, the other data that does not concern the holder of a card (or any third party) should not be legible.
This special problem is solved in that the plain text data is first of all specially marked when it is stored in the data record. A plain text field could, for example, be separated from the other data by special characters at the beginning and end; alternatively, it would be possible to display the length and position of the plain text using an index in the data field. By means of a circuit provided in adapter 2, it is possible to display all plain text fields, regardless of the underlying identifier, via a display unit, for example a screen. It would be possible, for example, to equip such a terminal with a printer and, if desired, to trigger a fee-based printout. It is easiest to output the plain text contents of the second storage means of a chip card 1 in the order in which they are physically stored. Due to the greater ease of use, however, it is preferred to list the data in the order of their expiry dates and to provide corresponding procedural steps in the manipulation of the memory chip.
In conclusion, it should be noted that in addition to chip cards with contacting surfaces, there are also those which can communicate wirelessly with the adapter device 2 via an inserted antenna, which then naturally does not require an inlet opening 8a, and thus can communicate with a terminal. In principle, it is also possible to design or operate such cards or adapters in the manner according to the invention; the equivalents required for this are known to the person skilled in the art.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0545675A1 | Cites | European Patent Office (EPO) | Search report |
| FR2676291A1 | Cites | France | Examiner |
| DE4126213A1 | Cites | Germany | Examiner |
| US4882779A | Cites | United States of America | Examiner |
| US5296692A | Cites | United States of America | Search report |
| WO9500928A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
5 priority claims, no other members on record
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19616943 | Germany | A | |
| 19616943 | Germany | A | |
| 19616943 | Germany | – | |
| 19616943 | – | – | – |
| DE1996116943 | – | – | – |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Main classification (correction)RHK1 | RHK1 | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Designated contracting statesAK | AK | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 0803838
- Publication, DOCDB
- 0803838
- Publication, EPODOC
- EP0803838
- Application
- 97106353
- Application, DOCDB
- 97106353
- Application, EPODOC
- EP19970106353
Titles3
- German
- Vorrichtung und Verfahren zum Manipulieren eines Speicherbausteins
- English
- Device and procedure for manipulation of a memory device
- French
- Dispositif et procédé pour manipuler un élément de mémoire
Classification
- CPC, 8
- G07F7/1008
- G06K7/0021
- G06K19/07745
- G06Q20/341
- G06Q20/4097
- G07B15/00
- G07F7/082
- H10W72/5522
- IPC, 4
- G06K7 00
- G06K19 077
- G07B15 00
- G07F7 10
Designated states1
- Contracting states, 1
- Netherlands (Kingdom of the)