EP0807907A1

System for securely accessing data from smart cards

Abstract

A card-enabled processing system comprises a security module (120) for securely exchanging data with cards, such as smart cards, and an application module (150) for processing data from the smart cards. The security module (120) encrypts and decrypts data using keys, which are securely stored in a secure memory. The security module (120) also validates the cards before processing by the application module (150) occurs and assists the card in validating the system. The application module provides a common platform in which different types of smart cards can be processed.

EP0807907A1, drawing sheet 1
Sheet 1 of 75

Term

Term ended

Projected expiry passed 13 May 2016, 10.4 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

25 claims: 12 independent, 13 dependent

  1. 1
    A system for controlling requests from portable electronic cards of differing in-card electronic processing capabilities, and including a central processing module, associated memory, and an operating system, comprising:a plurality of card units into which data cards and cards having internal data processing may be inserted;security module means for authenticating cards inserted into the plurality of card units and for securely exchanging data with the authenticated cards;and means, separate from the security module means, for processing data received from the security module in accordance with an application program.
  2. 4
    The system according to any of claims 1 to 3, wherein the processing means comprises:means for transferring data to and from files that relate to an application program of a particular card through the security module.
  3. 5
    The system according to any of the preceding claims, wherein the security module comprises:means for validating a plurality of properties of the card, including validating an internal key.
  4. 6
    The system according to any of the preceding claims, wherein the security module includes a secure microprocessor for encrypting and decrypting data.
  5. 9
    A method of securely exchanging data between a data-carrying card and a processing system, comprising the steps of:validating the authenticity of a data-carrying card at a security module of the processing system;providing data from the authenticated data-carrying card to the security module of the processing system;processing the data at the security module;providing the processed data from the security module to an application module;and processing the data at the application module.
  6. 13
    The method according to any of claims 9 to 12, further comprising the steps of:verifying that a user is authorized to use the card.
  7. 14
    The method according to any of claims 9 to 13, wherein the step of processing the data at the security module includes the step of decrypting the data using decryption keys.
  8. 15
    The method according to any of claims 9 to 14, further comprising the steps of:providing the data from the application module to the security module;processing the data at the security module;and storing the processed data on the data card.
  9. 17
    A system for providing secure exchange of data with data-carrying cards, comprising:a first processor programmed to encrypt and decrypt data, the first processor being a secure processor;a secure memory connected to the secure processor for storing a security program and encryption and decryption keys;a second processor programmed to execute an application program in accordance with data received from the first processor,
  10. 20
    A security module, comprising:an input/output interface from which data can be received and transmitted;data-encryption means for encrypting data in accordance with an encryption technique using encryption keys;a memory for securely storing the encryption keys;and means for securely managing the encryption keys stored in the memory.
  11. 24
    The security module according to any of claims 21 to 23, further comprising means for verifying that a user is authorized to use a card inserted into the card reader.
  12. 25
    The security module according to any of claims 20 to 24, further comprising means for authenticating data received from the input/output interface.