Method and postal apparatus with a chipcard read/write unit for reloading change data into a chipcard
Abstract
Usage data (N) are uploaded from a first chip card (49) into the postage meter, data (N') from the loaded usage data are modified in the postage meter in a predetermined way, and data (KC) changed in a predetermined way are written into the chip card in response to the first upload. Automatic type recognition and a further data upload are performed after an insertion of a second chip card. The method involves updating data in non-volatile memories of a postal instrument by device of a chip card, whereby an automatic type recognition is performed after a first insertion of a first chip card (49) in a chip card writing/reading unit of a postage meter. Usage data (N) are uploaded from the first chip card into the postage meter, data (N') from the loaded usage data are modified in the postage meter in a predetermined way, and data (KC) changed in a predetermined way are written into the chip card in response to the first upload. An automatic type recognition is performed after an insertion of a second chip card, data are uploaded from the second chip card into the postage meter, and an automatic type recognition with a renewed data loading in the postage meter is performed at a later repeated insertion of the first chip card.

Term
Term ended
Projected expiry passed 23 November 2018, 7.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
9 claims: 2 independent, 7 dependent
- 1Method for reloading change data by chip card in non-volatile memory of a postal device, beginning with automatic type identification after the first insertion of a first chip card (49) in a chip card write / read unit (70) of the postal device, with a reloading of payload data (N) from the first chip card (49) into the postal device, with a change of data (N ') from the loaded user data (N) in the postal device in a predetermined manner, with a writing of the data changed in a predetermined manner as a crypto-code (KC) into the chip card (49) as a result of the first after loading, with an automatic type recognition after the insertion of a second chip card (47, 48) into the smart card write / read unit, with a loading of data from the second chip card (47, 48) in the postal device, as well as with an automatic type recognition during later repeated insertion of the first chip card (49), with a new data loading into the postal device, wherein the smart card (49) provides usable data only for the same postal device.
Independent claims2
75 paragraphs, as filed
The invention relates to a method and a postal device, in particular a franking machine, with a chip card read / write unit for reloading change data by chip card in a franking machine or in a balance, according to the type specified in the preamble of claims 1 and 4. When the chip card is inserted for the first time, a registered letter is also added to the chip card after the first reload. In this case, data in the chip card are changed in a predetermined manner, so that load at a repeated data, the smart card only in derselbem device or Postage meter provides useful data. The change data relates to the postal carrier identifier and tariff changes to a postage fee table.
The reloading of postage fee tables by chip card per se via a chip card read / write unit in a franking machine is already known for franking machines from US 5,606,508 as well as for scales from US 5,710,706. The control unit of the postage meter thereby performs a monitoring function with respect to the conditions for a data update and controls the reloading.
Modern franking machines, such as the thermal transfer franking machine known from US 4,746,234, employ a fully electronic digital printing device. Thus, it is possible in principle to print any text and special characters in the franking stamp printing area and any or a cost center associated advertising clause. For example, Applicants' T1000 meter has a microprocessor surrounded by a secure housing having an opening for delivering a letter. In a letter feeder, a mechanical letter sensor (microswitch) sends a print request signal to the microprocessor. The franking imprint includes previously entered and stored postal information for conveying the letter. For the abovementioned thermal transfer franking machine, a data input option by means of chip cards has been proposed in US Pat. No. 5,606,508 (DE 42 13 278 B1) and in US Pat. No. 5,490,077. One of the smart cards loads new data into the postage meter machine and a set of further smart cards allows a setting to be made according to stored data by inserting a chip card. The data load and the setting of the franking machine should thus be more convenient and faster than by keyboard input possible. The postage meter keyboard remains small and clear because no additional keys are required to load or set additional functions. On the back side of the postage meter machine there is an insertion slot of a chip card write / read unit, in which the respective chip card is to be inserted by the customer within a time window. Because of the lack of direct visual contact succeeds an untrained user not always immediately after the other to insert the required smart card, which then leads to unwanted delays. The insertion slot of a chip card read / write unit is easily accessible only when the user bends over the machine. For larger machines, the problems grow to make eye contact. Often, the user has a variety of other pluggable smart cards. A chip card type, for example telephone cards, credit cards, etc., are admitted by the franking machine but not accepted. Without visual contact, the error is not immediately obvious. The postage meter works only with relatively expensive chip cards, which are themselves equipped with a microprocessor and are thus able to check whether the franking machine transmits a valid data word to the chip card before a reply is sent to the postage meter machine. But if no answer or
User identification, this is registered as an error in the postage meter and displayed before a request is displayed in the display to remove the smart card. On the one hand, it seems inappropriate to mistakenly insert another card, for example a telephone card, as a scam. On the other hand, it appears to be too high a security requirement to deliver the reloading card for postage rates personalized for each franking machine. This results in a relatively high administrative burden on the manufacturer side.
A modified proposal for scales has already been made in US 5,710,706. In this case, the chip card read / write unit of the franking machine is simply shared in order to load new postage fee tables in the corresponding non-volatile memory of the scale. Here also the different tariff structures and tariffs can be loaded by further post carriers. Since the space available on a smart card is limited, all necessary data is sequentially loaded into the balance via a series of smart cards to be inserted in succession via the postage meter machine.
As an alternative way to solve the above-mentioned problem, according to which the space available on a chip card is limited, it is proposed in US Pat. No. 4,802,218 to use a plurality of chip cards simultaneously, which are plugged into a plurality of write-read units. In addition to a USER chip card for the balance and for the billing, whereby the postage fee value to be printed is subtracted from the balance, a master card and another rate chip card is also inserted with a stored postage fee table. By accessing a postage fee table, a postage value can be determined according to the entered weight and shipping destination without loading an entire table into the machine. But since each chip card ever a read-write unit is required, the device is too big and expensive. In addition, a separate recharge terminal is required to replenish the balance in the USER smart card, with this recharge function authorized by a master card. A super-visor card has access to all master cards. Different security levels are accessed through associated key codes. Such a system with multiple slots for smart cards is very complicated on the whole.
In DE 196 05 015 C1, an embodiment for a printing device (JetMail®) has already been proposed which, in the case of a non-horizontal, approximately vertical letter transport, carries out a franking printing by means of an inkjet printhead stationarily arranged behind a guide plate in a recess. A pressure sensor is arranged for Briefanfangserkennung just before the recess for the inkjet printhead and cooperates with an incremental encoder. By arranged on the conveyor pressure elements of the letter transport is slip-free and derived during transport Inkrementalgebersignal affects the print quality image positive. Such a machine can work with an integrated scale or for larger mail items with an external scale. In such a franking machine, which has higher dimensions, a smart card write / read unit must be arranged and operated so that it can be used easily with sequentially pluggable smart cards. This is especially appropriate if the scope of the change data is too large for only one chip card or if an adapted for such a data volume chip card would be more expensive than several low-priced chip cards with small data volume. The chip cards are usually initialized by the chip card manufacturer and postage meter manufacturer. However, it is expensive for the franking machine manufacturer to generate special customer chip cards. Although information on postage charges adapted to current tariffs must be provided to the individual user of a franking machine, this applies to all users of franking machines. A non-personalized chip card would have the advantage of a short-term feasible mass production immediately before a tariff change. However, in the case of an over-the-counter non-personalized reloading card, there is the possibility that users of postage meters have received the reload information from other users without adequately remunerating the actual service provider. On the one hand, the obligation to buy reloading cards can not be enforced because the user would be expected to buy information that he does not need at all. This is especially the case if the reload information has only been changed in details that are not relevant to all users. Finally, it is technically unnecessary to exchange a whole table only because of some changed details. On the other hand, there are already commercially available programming devices with which chip cards can be burned. Finally, a database with expensive database maintenance would be necessary only to prevent abuse.
For some specific smart card applications, there is only a severely mitigated security concern for protection or the utilization of the data available on the chip card. Thus, in principle for each application an estimate of the attacker potential or The attacker classes are required to achieve the desired level of security with appropriate, cost-effective measures. The motto is: "as much as necessary, as little as possible". An enrolled meter usage number would obviously reveal the user ID to an attacker. Thus, a certain inhibition threshold for pirates must be established.
Smart cards often only have a very limited storage space. This is especially true for the cheap chip cards. So memory cards are usually designed with only a few hundred bits of memory size. This space is not enough to collect tariff-specific data in its entirety. For the protection of data contents and unauthorized use of smart cards, there are numerous security methods that are based in part on access-protected physical areas of the smart cards and partly on different cryptographic security algorithms. Disadvantage of this method is that a high initialization z. B. for the individualization of the cards by means of PIN assignment or key management in cryptographic procedures must be driven. Known security methods are unsuitable in that they require a lot of additional storage space on the smart card. The erasure of the data on the smart card after its one-time use does not require any additional memory space on the smart card, but it must nevertheless be disregarded because the method would preclude repeated use of the reload card on the same postage meter. Reuse of the reloading card on the same franking machine is required for recovery in the event of an error if the relevant data in the franking machine has been lost and must be restored. Repeated use of the reload card on the same postage meter may be required if necessary for the purpose of pre-dating mail, in particular if a fare change becomes valid in the period between normal-dated mail and post-dated mail.
In the case of pre-registration of mail for a future date, which is to be conveyed by a selected mail carrier, mail is already mass-mailed several weeks or days before being transported and stored in a storage warehouse until the date of the transport. A corresponding carrier related smart card loads carrier related reload data into the postage meter. After the completion of a franking task, a new franking task has to be completed. For this purpose, another carrier related smart card may load carrier related reload data into the postage meter. Because the postage meter machine can not load and stock all the data of all carriers, repeated use of the reload card is required to alternately perform post-dated postprocessing.
The invention has for its object to provide a fraud-proof method and a postage meter with a chip card read / write unit for reloading collectively modified data by chip card in a postage meter or in a balance. On the one hand, an easily accessible chip card read / write unit and an associated controller are to be used in the postage meter machine and the user to be provided with a set of non-personalized chip cards which can be used to reload information for executing postage meter functions or for their combined use as often as necessary. On the other hand, a protection against multiple use of one and the same chip card in other franking machines should be provided when the used chip card is passed on.
The object is solved with the features of claims 1 and 4.
According to the invention, a postal device, in particular a franking machine, changes the same data with the aid of a specific crypto-algorithm and its own device-specific first key prior to the utilization of the data stored on a first chip card in such a way that the data is decrypted only with the aid of this key can be. The user data are stored in a first memory area of the aforementioned chip card and include the remaining payload and variable data or after first use a crypto code. A repeatedly used chip card provides usable data only for the same device, which has carried out their personalization on initial insertion of unpersonalized smart card.
It is envisaged that in the case of a new data loading from the first chip card in the postal device, in particular in the franking machine, also an additional writing of data in a predetermined manner in the postal device, in particular in the franking machine, changed data in the smart card as a result Reloading is performed. It is further contemplated that in a repeated use of the first smart card, the changed data depending on the number of uses differ, with a re-data loading in the postal device, in particular in the franking machine, and an additional writing of in another predetermined manner in the postal device, in particular in the franking machine, changed data in the smart card takes place. The change only affects the form of the data and their storage in memory locations. However, it does not affect the content of the rechargeable information. The original information can be reconstructed by the postal device independently of the encrypted / unencrypted form. The mode of change is predetermined by the stored program. Preferably, a reversible encryption algorithm is used, such as DES (Data Encryption Standard). Alternatively, sub-data of the same or at least derived functions may be changed from these data or sub-data in a predetermined manner in order to re-write them as code in a memory area. The writing of an output data-based code into the smart card may be used in its repeated insertion in addition to the purpose of verifying the authenticity of the smart card data before the smart card data is used once more in the franking machine. In a second memory area of the chip card is for the authorization of the user data, a code or saved after first use another code. A second key is stored in hidden form in the chip card. In all franking machines, an identical second key is also stored read-only. For example, the second key can be scrambled or functionally linked to the data checksum in a predetermined manner, so that the key also has a different appearance with each new rate table. Each franking machine has a third key which has a predetermined relationship to the second key.
According to the invention, this second key is coded by the third key, similar to a recursive method, whereby the verification process for authenticity in a secured (franking machine) device environment takes place without the second key leaving the postage meter during the process or removing its stealth. Device internally takes place now after decoding the data, or data parts or data functions, the verification of data authenticity at least due to the verification of a predetermined ratio between the hidden second key of the smart card and the third key of the franking machine. In addition, the checksum formed via the uncoded chip card data can also be used for authenticity checking in a form modified in a predetermined manner with the second key. This requires a nested check of interdependent data that has a predetermined relationship to each other. After use of the chip card, the data remain according to the invention in a form modified by the first franking machine-specific key, which precludes meaningful data usage on further use of the chip card on another franking machine and, on the other hand, when attempting to block the chip card or the postage meter leads.
The invention provides in particular a chip card / franking machine system so that an automatic reloading of a franking machine on the one hand after the insertion of a recognizable in terms of their type reload chip card can be achieved in a chip card read / write unit without the same chip card after plugging in a Chip card read / write unit of another franking machine there also caused a reload. It is envisaged that the crypto code is calculated in the franking machine and written into the chip card, so that the chip card delivers usable data only for the same franking machine. It is further provided that a MAC backup method is used, which requires little storage space on the chip card and yet allows to verify the authenticity of the chip card data by machine. The chip card / franking machine system is advantageous expandable or modifiable. Another inserted chip card type can be recognized by the franking machine and evaluated accordingly. The postage meter machine can thus be advantageously operated with the least expensive type of chip card per application.
A arranged behind the guide plate chip card read / write unit is also sufficiently accessible. During the insertion process, the chip card is clearly visible and the type of chip card to be inserted can thus easily be determined by the user by means of a corresponding identification. For a data update application in the franking machine sector, on the one hand, a delivery of identical non-personalized chip cards can be made as a mass product, whereby it is up to the deliverer to take measures to protect the original chip cards against unauthorized copying until the first reloading. A certain inhibition threshold for pirates is further built up by the fact that a special, in particular rare and thus difficult to obtain, card type is used. On the other hand, however, it is ensured that after first use of the card by a franking machine the same can only be used on this specific device and that a data usage on other franking machines is no longer possible. The transfer of the data content of a once used for reloading chip card for multiple use on other franking machines is thus prevented.
Advantageous developments of the invention are characterized in the subclaims or are presented in more detail below together with the description of the preferred embodiment of the invention with reference to FIGS. Show it:<dl id="dl0001"><dt>FIG. 1a,</dt><dd>Details of the storage areas of the non-personalized chip card,</dd><dt>FIG. 1b,</dt><dd>Set of smart cards of different types,</dd><dt>FIG. 2,</dt><dd>Block diagram of the franking machine,</dd><dt>FIG. 3,</dt><dd>Perspective view of the franking machine from behind,</dd><dt>FIG. 4a,</dt><dd>Presentation of the data structure before the initial recharge,</dd><dt>FIG. 4b,</dt><dd>Representation of the data structure after the initial charge,</dd><dt>FIG. 5a, b,</dt><dd>Flowchart for control by the microprocessor during data reloading by means of a chip card,</dd></dl>
FIG. 1 a shows a chip card 49 with a contact pad. Under the latter is known to be the memory chip whose memory area is divided into unprotected and protected areas. The user data is in the unprotected area and a message authentication code MAC is stored in the protected area. This chip card 49 belongs to the type b. There are other smart cards belonging to other types for use in the postal device, in particular in a franking machine, provided. The postage meter machine is therefore provided with a corresponding smart card write / read unit for a variety of types.
The method for reloading change data by chip card in a postage meter machine, begins with a first insertion of a first chip card 49 in a chip card read / write unit, automatic Typerkennung and reloading of payload data from the first smart card 49 in the postage meter. In the franking machine, data is changed from the loaded user data in a predetermined manner. As a result of the first reloading, a writing of data changed in a predetermined manner in the franking machine into the chip card 49 takes place. When inserting a second chip card 47 into the chip card read / write unit, automatic re-loading of data from the second chip card 47 into the franking machine also takes place. In some cases, data is overwritten or deleted. This has the following background: The postal authority can provide the wide range of services itself or subcontractors or commission private mail carriers to carry mail, such as courier mail. The mail collection and / or their express delivery is now carried out by the subcontracting company, which consequently also requires reimbursement according to its own tariffs for this particular service. Postal mail may be issued upon re-loading of the postal carrier's registration number and the corresponding postage of the subcontractor or private postal carrier then continue to be franked with franking machines.
The aforementioned first smart card 49 contains, for all other postal carrier services, the postage charges according to the tariff of the postal authority and a mail carrier identification. When later repeated insertion of the first smart card 49 is an automatic type recognition and a load data from the smart card 49 in the postage meter. The recharging concerns the charges according to the valid tariff for this special service of the mail carrier and it concerns data or the number of the postal carrier code. Thus, the original data can be reconstructed to then again, as at the beginning, with the franking machine with the stamp image and according to the tariff of the postal authority to stamp the mail pieces. Such mail can still be posted in any post office. In this later repeated insertion, a subsequent writing of data changed in a predetermined manner in the postage meter machine is again provided in the chip card, which consequently continues to supply useful data only for the same franking machine.
At least one application of possible operating functions of a franking machine is provided for each type of chip card and the microprocessor is programmed to distinguish the type of application on the type of chip card. For a number of type a chip cards, there is a hierarchical structure which, as shown in FIG. 1 b, can be arbitrarily extended and changed starting from a first chip card by the postage meter user. The first chip card 50 is at the highest hierarchical level and is referred to below as a master card. The second chip cards designated in the group 51 stand on the first hierarchy level, the further chip cards designated in the group 52 are at the second hierarchy level, the following smart cards designated in group 53 are at the third hierarchical level, etc, where such cards from these groups of smart cards are also referred to as succession cards, for which the functions application authorization is selectively limited in a selectable manner and stored in tabular form. The cards of the lowest hierarchy level are the most limited in the feature application scope. Each card contains a sequential number to which feature application programs are stored in the postage meter machine, the assignment being freely programmable for the authorized user. The protection of the cards from reading the serial number is possible in a known manner by PIN or other security algorithms. In the event of loss of the master card, substitution is only possible by way of information from the franking machine manufacturer and with corresponding proof of authenticity. The locking or the release of all other cards is possible through the master card. Further security in the initialization of the system by means of the master card is possible in that only physically existing cards are initializable, thereby protecting the secret consecutive numbers of the cards. In the event of a follow-up card loss, a blocking of the corresponding storage area in the franking machine can take place.
The chip cards of type b are used for reloading table data, in particular tariff change data. A smart card 49 may contain the current version and a smart card 48 may contain predetermined change data for a future valid version of a postage fee table. The future valid version may be required when franking mail pieces to produce post-dated mailpieces. Thereafter, the change by means of the smart card 48 by loading by means of the smart card 49 can be undone again. Advantageously, therefore, the storage space in the postage meter for postage fee tables does not need to be extended, but can be limited to an optimal size. This is particularly advantageous for a multi-carrier franking machine, which have the tariffs of several mail carriers available or should take into account. There are more smart cards 47, with data corresponding to the other tariff structure of other postal carriers, etc. for the carrier-related reloading of tariff change data. According to the invention, the postal device, in particular a franking machine, is equipped with a chip card read / write unit 70 for reloading change data by chip card and with a printing device 20, which is controlled by a control device 1. A first chip card 49 inserted into a slot 72 of the chip card write / read unit 70 allows reloading of a record CK into the postage meter for at least one application. The control device 1 has a control unit 90 equipped with a microprocessor 91 with associated memories 92, 93, 94, 95. The program memory 92 contains the operating program and at least safety-related components of the program for the predetermined shape change of a portion of the user data. The main memory RAM 93 is used for volatile intermediate storage of intermediate results. The clock / date module also contains addressable but non-volatile memory areas nonvolatile intermediate storage of intermediate results or known program parts (for example, for the DES algorithm). It is envisaged that the franking machine control unit 90 is connected to the chip card write / read unit 70, the microprocessor 91 of the control unit 90 being programmed,<ul id="ul0001" list-style="none" compact="compact"><li>a) access first and second memory areas C1 and C2 of the nonvolatile memory 94, 95 of the control unit 90, in which the data record CK loaded from the chip card and the data record CK 'to be newly loaded into the chip card are stored,</li><li>b) to apply a special arithmetic operation or mask to the payload data N contained in the loaded data record CK in order to carry out a data removal from the memory area C1 with separation of the predetermined payload data N 'from the residual payload data N *,</li><li>c) to access the memory areas C3 and C4 of the non-volatile memory 94, 95 of the control unit 90, in which at least one first key K1 and an encryption algorithm are stored protected against unauthorized read-out,</li><li>d) to encrypt the predetermined user data N 'with the first key K1 into a crypto code KC and store it in the second memory area C2 and to form the new data record CK' using the remaining payload data N *,</li><li>e) to load the formed new record CK 'into the chip card as well</li><li>f) to load the user data N from the memory area C1 for their application in corresponding memory areas.</li></ul>
It is further contemplated that the microprocessor is programmed to distinguish the smart card type applications, with at least one application of possible operating functions of a postage meter being provided for each smart card type. In an extended embodiment, the microprocessor is programmed to reload and modify data N 'from the loaded payload N and to verify the authorization of the payload, the payload being stored in a first memory area CC1 of the smart card and the remaining payload N * and variable Data N 'or after the first use comprise a crypto-code KC, wherein in a second memory area CC2 of the chip card for authorization of the user data, a code MAC2 or after the first use another code MAC1 is stored. In the memory areas C3 and C4 of the nonvolatile memory 94, 95 of the control unit 90, a third key K3 and an encryption algorithm protected against unauthorized reading are stored for this purpose. The crypto-code KC is calculated in the postage meter machine and written into the chip card, so that the chip card only supplies usable data for the same franking machine.
FIG. 2 shows a block diagram for setting the function of the postage meter machine and for controlling the printing device 20 with a chip card write / read unit 70 and with the control device 1 of the postage meter machine. The control device 1 forms the actual meter and comprises a first control unit 90, a keyboard 88 and a display unit 89 and a first and second application-specific circuit ASIC 87 and 97. The first controller 90 includes a first microprocessor 91 and memory means 92, 93, 94 known per se, and a clock / date circuit 95. The nonvolatile memory 94 is provided with areas for storing the accounting data associated with the cost centers.
The first application specific circuit ASIC 87 together with a second microprocessor 85 and a nonvolatile memory 84 form a postal security means PSM 86. The postal security agent PSM 86 is enclosed by a secure housing and has a fast serial interface to the printer controller 16. Prior to each franking imprint, hardware is billed in the first application-specific ASIC 87 circuit. Billing is independent of cost centers. The second microprocessor 85 contains an integrated read-only memory (internal ROM) with the special application program (not shown), which is used for the postage meter by the postal authority. is authorized by the respective postal carrier. The postal security agent PSM 86 can be designed as described in detail in the European application EP 789 333 A3.
Both aforementioned ASICs are at least connected to the control unit 90 and the display unit 89 via the parallel μC bus . The first microprocessor 91 preferably has connections for the keyboard 88, a serial interface SI-1 for the connection of the chip card write / read unit 70 and a serial interface SI-2 for the optional connection of a MODEM. By means of the MODEM, the credit stored in the non-volatile memory 84 of the postal security means PSM 86 can be increased.
It is envisaged that the second ASIC 97 has a serial interface circuit 98 to a device 13 connected upstream in the mail stream, a serial interface circuit 96 to the printing device 20 and a serial interface circuit 99 to a device 18 downstream of the printing device 20. The non-prepublished German application 197 11 997.2 is a variant for the peripheral interface can be removed, which is suitable for multiple peripheral devices (stations). It is entitled: Arrangement for communication between a base station and other stations of a mailing machine and their emergency shutdown.
The interface circuit 96 coupled to the machine base interface circuit 14 provides at least one connection to the sensors 6, 7, 17 and to the actuators, for example to the drive motor 15 for the roller 11 and to a cleaning and sealing station RDS for the ink jet printhead 4, and to the inkjet printhead 4 of the machine base. The basic arrangement and the interaction between the ink jet print head and the RDS are the non-prepublished German application 197 26 642.8 removable, entitled: Arrangement for positioning an ink jet print head and a cleaning and sealing device.
One of the arranged in the guide plate 2 sensors 7, 17 is the sensor 17 and is used to prepare the pressure release during letter transport. The sensor 7 is used for initial letter recognition for the purpose of triggering the letter transport. The transport device consists of a conveyor belt 10 and two rollers 11,11 '. One of the rollers is equipped with a motor 15 drive roller 11, another is the follower tension roller 11 '. Preferably, the drive roller 11 is designed as a toothed roller, according to the conveyor belt 10 is designed as a toothed belt, which ensures the unambiguous power transmission. An encoder 5, 6 is coupled to one of the rollers 11, 11 '. Preferably, the drive roller 11 is firmly seated with an incremental encoder 5 on an axis. The incremental encoder 5 is designed, for example, as a slotted disk, which interacts with a light barrier 6.
It is envisaged that the individual printing elements of the print head are connected within its housing with a print head electronics and that the print head for a purely electronic pressure can be controlled. The pressure control is based on the path control, whereby the selected stamp offset is taken into account, which is entered by keyboard 88 or if necessary by chip card and stored in memory NVM 94 non-volatile. A planned imprint thus results from stamp offset (without printing), the franking print image and possibly further print images for advertising clichés, shipping information (optional prints) and additional editable messages. The nonvolatile memory NVM 94 has a plurality of memory areas. These include those which save the loaded postage fee tables non-volatile.
The smart card write / read unit 70 consists of an associated mechanical carrier for the microprocessor card and contacting unit 74. The latter allows secure mechanical retention of the chip card in the read position and clear signaling of reaching the read position of the chip card in the contacting unit, For example, tactile signaled by pressure point according to the push / push principle, Eject button or display / beeper message of the franking machine, Reliable electrical contacting of contact-type chip cards according to ISO 7816 for at least 100,000 contacting cycles and easy usability when inserting and removing the chip card. The microprocessor card with the microprocessor 75 has a programmed read capability for all types of memory cards or Chip cards. The interface to the FM is a serial interface according to RS232 standard. The data transfer rate is min. 1.2 K baud. A self-test function with ready message is automatically executed by switching on the power supply by means of switch 71.
FIG. 3 shows a perspective view of the franking machine from the rear. The franking machine is equipped with a chip card read / write unit 70, which is arranged behind the guide plate 2 and accessible from the housing upper edge 22. After switching on the franking machine by means of the switch 71, a chip card 49 is inserted from top to bottom in the insertion slot 72. A supplied standing on the edge letter 3, which rests with its surface to be printed on the guide plate is then printed according to the input data with a franking stamp 31. The letter feeding opening is bounded laterally by a transparent plate 21 and the guide plate 2.
With the insertion of a chip card 50 of type a, which has been delivered together with the franking machine, a predetermined cost center is set. For example, the cost center 1 is preset to which the booking is made when no other predetermined inputs are made by keyboard to gain access to other cost centers. The postage meter machine contains in its program memory 92 a corresponding application program, so that a chip card 50 inserted into the chip card read / write unit 70 permits setting of the postage meter machine for at least one function application on the highest hierarchical level. Such a chip card of the type a with little storage space is inexpensive. For example, a 256-byte memory card according to ISO7816, in particular OMC240SP from Orga, can be used.
Another chip card with a lot of storage space is referred to below as type b. For example, an I<sup>2</sup>CBus memory card with 32 Kbytes according to ISO7816, in particular AM2C256 from the company AMMI. This contains a chip AT24C256 from Atmel. Further chip cards are referred to below as type n. For example, an 8 Kbyte chip card having a microprocessor may be used. The further chip cards of types b to n relate, for example, to the following functional applications:<ul id="ul0002" list-style="dash" compact="compact"><li>Reload option of postage fee tables via chip card 49.</li><li>Cliché recharge via chip cards (individually or in a block)</li><li>Stamp imitations via chip cards (day stamp).</li><li>Smart cards with time-limited function application.</li><li>Chip cards with PIN authorization of functions.</li><li>Chip cards for setting the peripheral device function.</li><li>Chip cards for setting the system configuration.</li><li>Chip cards for activating programmed print images.</li></ul>
FIG. 4 a shows the data structure in state A of the data storage in the memory areas CC 1 and CC 2 of the chip card before the first recharging. The user data N stored in the unprotected area CC1 preferably concern a tariff table.
Part of the user data always remains unencrypted. These data are hereinafter referred to as remaining payload N *. Another part N 'of the payload is unencrypted only before the first reload. This part is subsequently replaced, for example, by coded data or a crypto-code KC, so that with respect to the data structure a state B according to FIG. 4b results. In this case, the data in the memory area CC1 of the chip card are changed in a predetermined manner by writing a new data record CK 'into the chip card. The new data record CK 'now includes a crypto code KC in the memory area CC1 of the chip card. Thus, with each repeated data load, the smart card only supplies useful data when it is plugged into the read / write unit of the same franking machine. A message authentication code MAC2 is stored in the protected memory area CC2 of the chip card and contains a data part encrypted with a second key K2. The latter comprises the CRC checksum of selected user data N 'and the code of the second key K2, wherein CRC checksum of the selected user data N' and the aforementioned message authentication code are linked in a predetermined manner with a suitable arithmetic operation, which is symbolized by the semicolon. The data compiled into a data record CK from the chip card storage areas CC1 and CC2 of the chip card 49 inserted in the insertion slot 72 are loaded and processed, which is explained in more detail with reference to FIGS. 5a and b.
The state B of the data storage of a new data set CK 'in the chip card shown in FIG. 4b relates to a data structure newly loaded into the chip card after the initial recharging and stored in the previous chip card storage areas CC1, CC2. The residual user data N * stored in the first area CC1 preferably relate to parts of a tariff table. In addition there are scrambled inserted data parts. When scrambling, the data parts encrypted with a first key K1 to form a crypto code KC are hidden between the remaining payload data. They are thus distributed to the chip card storage area CC1. In the protected area CC2 new message authentication code MACI is stored. The latter is formed by encrypting the previously stored message authentication code MAC2. The encryption takes place with the first key K1 in the franking machine before loading and storing in the chip card.
FIG. 5 a shows a flowchart for a control by the microprocessor of the postage meter machine during data retrieval by means of a chip card. After switching on a power supply of the franking machine (not shown) with the switch 71, which is registered by the microprocessor 91 of the franking machine in step 100, a microprocessor 75 connected to a contacting device 74 of the smart card write / read unit 70 signals the microprocessor 91 of the franking machine. when a smart card is inserted into the insertion slot 72, which is registered in step 101 by the microprocessor 91 of the franking machine. Between the chip card write / read unit 70 and the chip card, a communication then takes place according to a first predetermined protocol and an evaluation in step 102 as to whether the chip card is readable as type a. If this is the case, the branching step 103 branches to a step 111 in order to load a part I of an identification string into the non-volatile memory 94 of the postage meter machine, wherein the microprocessor 91 of the postage meter machine performs an evaluation of the company identification number (company ID) becomes. After a conditional access check, the applications are then released (steps 111-121 and 125-127). If, however, the chip card is not readable as type a, a branch is made from inquiry step 103 to step 104 in order to carry out a communication according to a second predetermined protocol and an evaluation in step 104 as to whether the chip card is readable as type b. If, therefore, the chip card is readable as type b, the query step 105 branches to a step 106 for further data processing by the microprocessor 91 of the franking machine. In a similar manner, if necessary, further protocols are run through (step 107) to determine in inquiry step 108 whether the smart card is readable as type n, then to load data and branch to a corresponding step 109 for further data processing by the microprocessor 91 of the postage meter , Otherwise, if the type of chip card is not recognized, after an error message in step 110, a branch back to step 101.
Compared to the prior art results in a better adaptation to the particular application. In contrast, in the solution according to US Pat. No. 5,606,508 (DE 42 13 278 B1) or US Pat. No. 5,490,077 there are no type differences, ie The chip cards are all technically and functionally the same and a Zeiffenster for the insertion of a chip card is a fixed fixed period of time. In contrast to US Pat. No. 5,606,508 or US Pat. No. 5,490,077, in which the sequence is fixed and a chip card A is to be inserted in front of a chip card B for loading postage, which sets a cost center, for example, the order for sequentially inserting a number of chip cards is arbitrary.
The flowchart according to the invention according to FIG. 5a thus allows the franking machine to make a distinction according to different chip card types. An expensive chip card type must therefore only be used in cases where there is no alternative. Advantageously, according to the type of application suitable chip card type is selected. If the data processing is carried out by the microprocessor 91 of the postage meter machine in the manner predetermined by the chip card type, monitoring is carried out according to specific criteria and the occurring errors (steps 122-124, 128-130, 154) before stopping the postage meter (step 131).
When branching from the inquiry step 105 to a step 106, a smart card type b is used. This is provided in order to load the data record CK stored in the chip card 49 into a first memory area C1 of the non-volatile memory 94 of the postage meter machine. The data set CK can be represented as follows:<maths id="math0001" num="(1)"><math display="block"><mrow><mtext>CK: = N; MAC2</mtext></mrow></math><img file="EP0927971A2_D0001.tif" /></maths>
The unencrypted part of the data record CK contains the new user data N to be loaded. The encrypted part of the data record CK is a message authentication code MAC2, which is also loaded into the franking machine. The semicolon between both in above Equation (1) corresponds to a special link. Only in the simplest case, both parts hang together. For example, a franking machine, which is enclosed by a protective housing, has stored in the memory area C3 of the nonvolatile memory 94 a third key K3, which can decrypt the message authentication code. The encryption algorithm may be stored in a further memory area C4 of the non-volatile memory 94 of the protected postage meter machine. The third key K3 and the encryption algorithm can be saved read-only. The microprocessor 91 is preferably an OTP (One Time Programmable) type.
In a particularly secure embodiment variant, the first and third keys K1, K3 and the encryption algorithm are stored in the nonvolatile memory 84 of the postal security means PSM86. The required arithmetic operations, such as encryption and decryption, takes place in the postal security means PSM the microprocessor 85. This can also be an OTP type (One Time Programmable). The algorithm and the keys can be stored read-only in the OTP-internal read-only memory.
The further sequence is shown in FIG. 5b. In a first step 141, a counter is reset Z: = 0. The counter is a separate round counting block or is realized in memory cells preferably of the clock / date block 95, wherein the memory cells are correspondingly logically linked and programmable.
In the second step 142, the user data N from the first memory area CC1 and an encrypted data record part are taken from the second memory area CC2 of the chip card memory. A corresponding program in the read-only memory 92 controls the data loading and the subsequent further arithmetic operations. The state A of the storage of data in a smart card is present only before the first reloading of data in the postage meter. The payload data includes residual payload data N * and special payload data N 'according to equation (2):<maths id="math0002" num="(2)"><math display="block"><mrow><mtext>N: = N *; N '</mtext></mrow></math><img file="EP0927971A2_D0002.tif" /></maths>
The special user data N 'selected according to the program by the microprocessor are encrypted with a first key K1 to the crypto code KC (3):<maths id="math0003" num="(3)"><math display="block"><mrow><mtext>K1 [N '] = KC</mtext></mrow></math><img file="EP0927971A2_D0003.tif" /></maths>
The encrypted record part MAC2 is preferably a data part M2 encrypted with a second key K2 and is written as in (4):<maths id="math0004" num="(4)"><math display="block"><mrow><mtext>MAC2: = K2 [M2] = K2 [K2; CRC (N ')]</mtext></mrow></math><img file="EP0927971A2_D0004.tif" /></maths>
The encrypted record part MAC2 is also encrypted with the first key K1 to a MAC1 (5):<maths id="math0005" num="(5)"><math display="block"><mrow><mtext>K1 [MAC2] = MAC1</mtext></mrow></math><img file="EP0927971A2_D0005.tif" /></maths>
Finally, in the second step 142, the payload data N and, according to Equation (4) and (5), encrypted data record parts are copied from the memory area C1 into a memory area C2 of the nonvolatile memory 94.
In the third step 143, the count of the lap counter is incremented to Z: = Z + 1.
In the fourth step 144, a decryption attempt is made by means of the third key K3 stored in the franking machine as part of a reversible encryption process. For this purpose, the data record part MAC2, which has been previously loaded from the second chip card memory area, is taken from the memory area C1. This record part MAC2 according to state A is encrypted with the second key K2. With a reversible third key K3, the encrypted data record part MAC2 can be decrypted to the decrypted data part M2. The decrypted record part is buffered in the RAM. In a reversible encryption algorithm, the second key K2 may be identical to the third key K3. Preferably, a secret intermediate result in the OTP-internal random access memory RAM is read-buffered. For the decrypted data part M2, (3) thus results:<maths id="math0006" num="(6)"><math display="block"><mrow><mtext>M2: = K2; CRC (N ')</mtext></mrow></math><img file="EP0927971A2_D0006.tif" /></maths>
The latter comprises the CRC checksum of specially selected user data N 'and the code of the second key K2. The semicolon between the two stands for a specific arithmetic operation for linking both. The microprocessor 91 or 85 is programmed to carry out the aforementioned arithmetic operation and to perform a corresponding inverse arithmetic operation.
The unencrypted part of the stored data record CK in the memory area C1 of the non-volatile memory 94 of the franking machine is accessed in the fifth step 145. In this case, predetermined special user data N 'are selected by means of a mask or by means of the corresponding calculation rule, and thereafter the selected user data N' is processed to form a CRC checksum.
In the sixth step 146, the checksum CRC (N ') is now separated from the data part M2 by the corresponding inverse arithmetic operation. For example, the calculated checksum CRC (N ') can be subtracted from the data part M2 for separation if the second key K2 and the original checksum CRC (N') were additively linked in the data part M2 (7):<maths id="math0007" num="(7)"><math display="block"><mrow><mtext>M2 - CRC (N ') = K</mtext><mspace linebreak="newline" /><mtext> {K2 + CRC (N ')} - CRC (N') = K</mtext></mrow></math><img file="EP0927971A2_D0007.tif" /></maths>
In the seventh step 147, the remainder K is compared with the franking machine internally stored third key K3. It can be determined whether both keys have a predetermined relationship to each other. Only in the simplest case will equality be tested (8):<maths id="math0008" num="(8)"><math display="block"><mrow><mtext>K3 = K?</mtext></mrow></math><img file="EP0927971A2_D0008.tif" /></maths>
If a predetermined ratio has been established, in the above-mentioned case the rest is therefore identical to the second key K2 and equal to the key K3 stored internally in the franking machine, branching is made via step 150 to step 151 in order to form a new data record CK '. A chip card with data in state A (FIG. 4 a) could thus already be recognized in the first pass in the seventh step 147.
Otherwise, it is checked in the eighth step 148 whether the count of the counter has already reached the value two. This is not the case in the first run. In order to achieve a second pass, a second step 149, in which the memory contents of the memory area C1 are changed over, branches back to the aforementioned second step 142. By changing the memory contents, a data state is reached in the memory area C1, as if a data structure had existed in the chip card in accordance with the state A of the data storage shown in FIG. 4a and as if the first pass had yet to begin. Actually, however, a second pass begins, which will be explained in more detail below.
However, if a predetermined ratio has already been determined in the first pass in the seventh step 147 for a valid chip card inserted for the first time, then the second internal memory area C2 is accessed in step 150 to form the new data record CK '. For the new record CK 'applies (9:<maths id="math0009" num="(9)"><math display="block"><mrow><mtext>CK ': = N *; KC; MAC1</mtext></mrow></math><img file="EP0927971A2_D0009.tif" /></maths>
This can now be loaded into the chip card in step 151, ie stored non-volatile in the chip card internal memory and at the same time represents the state B in Figure 4b. In step 152, the user data N from the first internal memory area C1 is then taken over into the working memory or into another non-volatile memory of the franking machine in accordance with the respective application. Subsequently, in step 153, the message about the successful updating is given, for example in the form of a display or signaled by a beeper.
The state B shown in Figure 4b is present at each further reloading.
The unencrypted part of the record CK 'contains residual payload N *, ie the new payload N without the predetermined payload N '. This residual user data N * are supplemented by encrypted user data of the crypto code KC and then stored together in the memory area CC1 of the chip card 49. In some way, the encrypted payload of the crypto code KC is scrambled into the remaining payload. For this a special arithmetic operation or mask is used. The special arithmetic operation is again symbolized by a semicolon in the new data set CK 'and executed, for example, in such a way as to produce a scrambled data part. The remaining payload data N * in the new data set CK 'are necessary but not sufficient for franking according to valid postage fee tariffs.
Thus, the next time the card is inserted, a scrambled data portion must be descrambled to obtain the crypto code KC. From the latter, the unencrypted predetermined user data can then be recovered by decryption. The predetermined user data N 'recovered using the first key K1 by decrypting the crypto code KC can now be stored in the postage meter machine and used accordingly.
The encrypted part of the new data record CK 'contains a further message authentication code MAC1. The latter is stored in memory area CC2 after the first use of the card. By means of this message authentication code, the chip card, in conjunction with the status of the lap counter and with the authenticity check, can also be checked for the presence of state A or B.
In the case of an inserted chip card with a data record in accordance with state B, subsequent arithmetic operations are carried out in the first pass. In the second step 142:<maths id="math0010" num="(10)"><math display="block"><mrow><mtext>K1 [KC] = N '</mtext></mrow></math><img file="EP0927971A2_D0010.tif" /></maths><maths id="math0011" num="(11)"><math display="block"><mrow><mtext>K1 [MAC1] = MAC2</mtext></mrow></math><img file="EP0927971A2_D0011.tif" /></maths> with storage in memory area C2. After incrementing the lap counter in the third step 144, the following operations are performed, in the fourth step 144:<maths id="math0012" num="(12)"><math display="block"><mrow><mtext>K3 [MAC1] = M1</mtext></mrow></math><img file="EP0927971A2_D0012.tif" /></maths>
In the fifth and sixth steps 145 and 146:<maths id="math0013" num="(13)"><math display="block"><mrow><mtext>M1-CRC (CK) = K</mtext></mrow></math><img file="EP0927971A2_D0013.tif" /></maths>
Since a predetermined relationship to K3 has not been determined in the seventh step 147, for a second pass in the ninth step 149, the data N *, N ', MAC2 stored in the memory area C2 are copied into the memory area C1. For the second pass, therefore, there are equivalent data as in state A, and subsequent arithmetic operations are performed. In the second step 142:<maths id="math0014" num="(14)"><math display="block"><mrow><mtext>K1 [N '] = KC</mtext></mrow></math><img file="EP0927971A2_D0014.tif" /></maths><maths id="math0015" num="(15)"><math display="block"><mrow><mtext>K1 [MAC2] = MAC1</mtext></mrow></math><img file="EP0927971A2_D0015.tif" /></maths> with storage in memory area C2. In the fourth step 144, due to equation (6) and K3 reversible to K2, we get:<maths id="math0016" num="(16)"><math display="block"><mrow><mtext>K3 [MAC2] = M2</mtext></mrow></math><img file="EP0927971A2_D0016.tif" /></maths>
In the fifth and sixth steps 145 and 146:<maths id="math0017" num="(17)"><math display="block"><mrow><mtext>M2CRC (N ') = K</mtext></mrow></math><img file="EP0927971A2_D0017.tif" /></maths>
In the seventh step 147, a predetermined ratio of the value K to K3 is now determined. In a simplified embodiment, the equality of the keys K2 = K3 is provided, then K = K2 = K3. Thus, only after a - in the first round - made the conversion of the MAC1 in a MAC2, in the second round, the authenticity can be checked. Will also after going through the second round, ie again in the seventh step 147, the authenticity is not detected and the lap counter has reached a count = 2, then the chip card is detected as invalid and it is in step 154, an error message: "invalid card". It is thus provided that after passing through two rounds, the authenticity or non-authenticity of the user data can be definitively determined. The second round is therefore required for a present in the chip card state B, in order to be able to form the code MAC1 again in step 142 and then again to form the new data record CK 'in step 150, in order to be able to load the latter into the chip card in step 151 as well as with the predetermined user data N 'decrypted in the first round in step 142 from the crypto-code KC and stored in the first memory area C1 in step 149 in conjunction with the remaining payload N * to be able to work (step 152). In a further embodiment variant, the data of the data set CK 'may differ from one another depending on the number of uses, if a changed code is used for the first key. Before an error message in step 154 then further steps are to be carried out, which is a decryption of the crypto code or Try the authentication with the help of other code.
With the new user data N of the smart card 49, the non-volatile user data of the postage meter machine can be updated. The latter can be stored in the memory area C1 at step 152 at least one of the further memory areas Cn of the non-volatile memory 94 of the franking machine after being taken over from the memory area C1 and present there for further use. In this case, with the part of the loaded user data N characterizing the mail carrier, the stamp image can be changed specifically for the carrier and the stored postage fee tables can be completely or partially updated with the tariff part of the loaded user data N. Likewise, with the tariff part of the new user data N of the chip card 47, 48 or 49, the non-volatilely stored user data of a balance can be updated under the control of the franking machine, as has already been described in principle in the European application EP 724 1441 A1. The upstream of the postage meter in the mail stream device 13 (Figure 2) is in this case a postage calculating balance. The latter contains a built-in postage calculator with non-volatile memories for updateable storage of multicarrier postage fee tables. The updating is then part of the step 152 for taking over the user data shown in FIG. 5b. The microprocessor is programmed to load the tariff part of the user data N from the memory area C1 for its application into corresponding memory areas of a postage calculating scale 13.
A postal device is - as shown in FIG. 2 - equipped with at least one control device 1, with a chip card write / read unit 70 and with a postal security means 86. Preferably, a computer retrofittable with corresponding inserts can be retrofitted to the postal device. Printing is then done with a standard printer.
An alternative embodiment may include a computer retrofitted as above and a dedicated dedicated postage printer. In the non-prepublished German application 197 11 997.2 a suitable embodiment has been proposed, with the title: mail processing system with a computer-controlled printing machine base station.
The personal computer would only have to be equipped with smart card write / read unit 70 and a corresponding application program. For this purpose, for example, the slot could be used for the modem. The postal device is equipped with a smart card write / read unit 70 for reloading change data by chip card and with a control device 1, to which a printing device 20 is connected, which is controlled by the control device 1. The inserted into a slot 72 of the smart card write / read unit 70 first smart card 49 allows the reloading of a record CK in the postal device for at least one application. The control device 1 has a microprocessor 91 with associated memories 92, 93, 94, 95. It is envisaged that the control device 1 of the postal device is connected to the smart card write / read unit 70 and to a postal security means 86, the postal security means 86 having an application specific circuit ASIC 87, a nonvolatile memory 84 and a microprocessor 85 wherein the microprocessor 85 of the postal security means 86 is programmed,<ul id="ul0003" list-style="none" compact="compact"><li>a) access first and second memory areas (C1) and (C2) of the non-volatile memory (84) of the postal security means (86), in which the data loaded from the smart card (CK) and the new to be loaded into the smart card record (CK ') is stored,</li><li>b) to apply a special arithmetic operation or mask to the payload data (CK) contained in the loaded data record (C) in order to carry out a data removal from the memory area (C1) with separation of the predetermined payload data (N ') from the remaining payload data (N *),</li><li>c) to access the memory areas (C3) and (C4) of the non-volatile memory (84) of the postal security means (86) in which a first key (K1) and third key (K3) and an encryption algorithm protected against unauthorized reading are stored .</li><li>d) encrypting the predetermined user data (N ') with the first key (K1) to form a crypto code (KC) and storing it in the second memory area (C2) and using the remaining useful data (N *) the new data record (CK') ) to build,</li><li>e) to load the newly formed data set (CK ') into the chip card as well as</li><li>f) to load the user data (N) from the memory area (C1) for their application in corresponding memory areas.</li></ul>
The control device 1 of the postal device is, for example, the control device of a franking machine or a computer, which is correspondingly converted and connected to a franking machine. To the above Conversion of a franking machine or a computer is provided that the control device 1 of the postal device is connected to the chip card write / read unit 70 and to a postal security means 86, wherein the postal security means 86 comprises an application-specific circuit ASIC 87, a nonvolatile memory 84 and a microprocessor 85, wherein the microprocessor 85 of the postal security means 86 is programmed, accessing first and second memory areas (C1) and (C2) of the non-volatile memory (84) of the postal security device (86), in which the loaded from the chip card record (CK) and the newly loaded into the chip card data set (CK ') is stored.
The invention is not limited to the present embodiment, since obviously other other arrangements or embodiments of the invention can be developed or used, which - based on the same basic idea of the invention - are encompassed by the appended claims.
23 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0762338A2 | Cites | European Patent Office (EPO) | Search report |
| EP0789333A2 | Cites | European Patent Office (EPO) | Search report |
| DE19605015C1 | Cites | Germany | Applicant |
| DE4213278A1 | Cites | Germany | Applicant |
| US4802218A | Cites | United States of America | Search report |
| US4802218A | Cites | United States of America | Applicant |
| US5490077A | Cites | United States of America | Search report |
| US5490077A | Cites | United States of America | Applicant |
| US5606508A | Cites | United States of America | Applicant |
| US5710706A | Cites | United States of America | Applicant |
7 members in 3 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19757653 | Germany | A | |
| 19757653 | Germany | A | |
| 19757653 | Germany | – | |
| 19757653 | – | – | – |
| DE1997157653 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| DE19757653A1 | Germany | A1 | |
| EP0927971A2This record | European Patent Office (EPO) | A2 | |
| EP0927971A3 | European Patent Office (EPO) | A3 | |
| US6477511B1 | United States of America | B1 | |
| DE19757653C2 | Germany | C2 | |
| EP0927971B1 | European Patent Office (EPO) | B1 | |
| DE59813416D1 | Germany | D1 |
41 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Name/firm changedPFA | PFA | CH | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| Corresponds to:REF | REF | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| New agentNV | NV | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Designation fees paidCH DE FR GB IT LIAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Information provided on ipc code assigned before grant7G 07B 17/00 ARIC1 | RIC1 | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0927971
- Publication, DOCDB
- 0927971
- Publication, EPODOC
- EP0927971
- Application
- 98250409
- Application, DOCDB
- 98250409
- Application, EPODOC
- EP19980250409
Titles3
- German
- Verfahren und postalisches Gerät mit einer Chipkarten-Schreib/Leseeinheit zum Nachladen von Änderungsdaten per Chipkarte
- English
- Method and postal apparatus with a chipcard read/write unit for reloading change data into a chipcard
- French
- Procédé et dispositif postal avec une unité de lecture/écriture de cartes à puce pour le rechargement de données de changement dans une carte à puce
Classification
- CPC, 8
- G06K13/0825
- G06K7/0008
- G07B17/0008
- G07B17/00733
- G07B2017/00169
- G07B2017/00177
- G07B2017/00774
- G07F15/08
- IPC, 3
- G06K7 00
- G07B17 00
- G07F15 08
Designated states2
- Contracting states, 1
- Sweden
- Extension states, 1
- Slovenia