Arrangement for the protection of a security module
Abstract
The method involves monitoring the state of the use or exchange of the security module using at least two functional units, such as a microprocessor (120), a monitoring unit (12) and a detection unit (13). The state is signaled using the microprocessor. Sensitive data are erased by the monitoring unit when improper use or exchange is detected. The monitoring unit may monitor the correct installation or state of a battery (134). The detection unit may block the functionality on the basis of an exchange of the security module or a destruction condition. An Independent claim is included for an apparatus for performing the method.

Term
Term ended
Projected expiry passed 25 February 2020, 6.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
16 claims: 3 independent, 13 dependent
- 1Method of protecting a security module, comprising the following steps:• monitoring the state, the proper use or replacement of the safety module at least by means of two functional units (120, 12, 13), Signaling at least one state (220, 230, 240, 250, 260, 270, 280, 290) controlled by means of a first functional unit (120) and • Deletion of sensitive data due to improper use or replacement at least by means of a second functional unit (12).
- 2Proceeding, according to Ansprunch 1, characterized by in that a time sequence is detected by means of the first functional unit (120) and that another sequence of procedures is carried out to restore the functions, with the fonts:• Reinitialize by means of the first functional unit (120) of previously deleted sensitive data after proper use or replacement of the safety module, and • Recommissioning by activating the functional units (12, 13) of the safety module (100).
- 13Arrangement according to claims 10 to 12, characterized by . in that the processor (120) stores (122, 124), to which an operating voltage Ub + is conducted by a voltage monitoring unit (12) via the line (138), the processor (120) is supplied with system voltage Us + and has a fourth connection (pin 4), to reset the state of latching of the detection unit (13) via the line (137) and a fifth terminal (pin 5), to which the line (139) is connected, to query the state of the detection unit (13).
Independent claims3
56 paragraphs, as filed
The invention relates to a method for protecting a security module, according to the type specified in the preamble of claim 1, and an arrangement for carrying out the method, according to the type specified in the preamble of claim 10. Such a postal security module is in particular for use in a franking machine Mailing machine or computer with mail processing function suitable.
Modern franking machines, such as the thermal transfer franking machine known from US 4,746,234, employ a fully electronic digital printing device. Thus, it is possible in principle to print any text and special characters in the franking stamp printing area and any or a cost center associated advertising clause. For example, Applicants' T1000 meter has a microprocessor surrounded by a secure housing having an opening for delivering a letter. In a letter feeder, a mechanical letter sensor (microswitch) sends a print request signal to the microprocessor. The franking imprint includes previously entered and stored postal information for conveying the letter. The control unit of the franking machine performs a billing software, performs a monitoring function, if necessary Regarding the conditions for a data update and controls the reloading of a port value credit.
For the abovementioned thermal transfer franking machine, a data input option by means of chip cards has already been proposed in US Pat. No. 5,606,508 (DE 42 13 278 B1) and in US Pat. No. 5,490,077. One of the smart cards loads new data into the postage meter machine and a set of further smart cards allows a setting to be made according to stored data by inserting a chip card. The data loading and the setting of the franking machine can thus be more convenient and faster than by keyboard input. A franking machine for franking mail is provided with a printer for printing the postage stamp on the mail, a controller for controlling the printing and peripheral components of the postage meter, a bill unit for settling postage, at least one nonvolatile memory for storing postage data , equipped with at least one non-volatile memory for storing safety-relevant data and with a calendar / clock. The non-volatile memory of the safety-related data and / or the calender / clock is usually powered by a battery. In known franking machines, security-relevant data (cryptographic keys and the like) are saved in nonvolatile memories. These memories are EEPROM, FRAM or battery backed SRAM. Known franking machines often also have an internal real time clock (RTC), which is powered by a battery. For example, are known potted modules containing integrated circuits and a lithium battery. These modules must be replaced and disposed of at the end of the life of the battery as a whole. From an economic and ecological point of view, it is better if only the battery needs to be replaced. For this purpose, however, the security case must be opened and then closed again and sealed, because the security against fraud is essentially based on the secure housing, which encloses the entire machine. The Applicant has already proposed in EP 660 269 A2 (US Pat. No. 5,671,146) a suitable method for improving the safety of franking machines, in which a distinction is made between an authorized and unauthorized opening of the security housing.
Any required repair of a franking machine is then difficult on site, if the access to the components is difficult or limited. In the case of larger mail processing machines or so-called PC frankers, the secured housing will in future be reduced to the so-called postal security module, which can improve the accessibility to the other components. To economically replace the battery of the security module, it would also be desirable that they be relatively simple can be replaced. For this purpose, the battery must be outside the security range of the franking machine. However, when the battery terminals are accessed from the outside, a potential attacker is able to manipulate the battery voltage. Known battery powered SRAM and RTC have respect. their required operating voltage different requirements. The voltage required to hold data from SRAM is below the required voltage for operating RTC. This means that decreasing the voltage below a certain threshold will result in undesired behavior of the components: the RTC will stop, the time stored in SRAM cells, and the memory contents of the SRAM will be preserved. At least one of the security measures, for example long-time watchdogs, would then be ineffective on the franking machine side. Under Long Time Watchdogs the following is understood: The enifernte data center gives a time credit or a period of time, in particular a number of days, or a certain day before, to which the franking device can report by communication link. After unsuccessful expiration of the time credit or the deadline, franking is prevented. In EP 660 270 A2 (US Pat. No. 5,680,463), a method has already been proposed under the title: Method and Arrangement for Generating and Verifying a Security Imprint to determine the probable period of time until the next credit recharge, whereby the one franking machine is considered suspicious by a data center does not report in due time. Suspended franking machines are communicated to the postal authority, which monitors the mail flow for letters franked by suspect franking machines. A lapse of the time credit or the deadline is already determined by the franking device. The user is prompted to perform the overdue communication. However, this franking device does not have a separate security module.
Security modules are already known from electronic data processing systems ago. For protection against burglary in an electronic system, a barrier is already proposed in EP 417 447 B1, which includes power supply and signal detection means and shielding in the housing. The shielding means is made of encapsulating material and conductive means to which the power supply and signal detection means are connected. The latter responds to a change in the line resistance of the line means. In addition, the security module contains an internal battery, a voltage switch from system voltage to battery voltage, a power gate and a short-circuit transistor as well as other sensors. When the voltage falls below a certain limit, the Power Gate responds. If the line resistance, temperature or radiation is changed, the logic will react. By means of the power gate or by means of the logic, the output of the short-circuit transistor is switched to L level, whereby a memory stored in the cryptographic key is deleted. However, the life of the non-replaceable battery and thus the security module for use in franking devices or Mail processing machines too small.
A larger mail processing machine is, for example, the JetMail®. A franking print is here produced by means of a stationary ink jet printhead in a non-horizontal approximately vertical letter transport. A suitable design for a printing device has already been proposed in DE 196 05 015 C1. The mailing machine has a meter and a base. If the meter is to be equipped with a housing so that components are more easily accessible, then it must be protected by a postal security module fraud attempts, which at least performs the settlement of postal fees. In order to exclude influences on the course of the program, it has already been proposed in EP 789 333 A2 under the title: Postage meter machine to equip a security module with an application specific integrated circuit (ASIC) which has a hardware accounting unit. The user circuit also controls the print data transfer to the print head.
The latter would only be required if unique items were created for each item of mail. A suitable method and arrangement for producing and checking a security impression has been proposed, for example, in US Pat. Nos. 5,680,463, 5,712,916 and 5,734,723. A special security marking is generated electronically and embedded in the printed image.
Further measures for the protection of a security module against an attack on the data stored in it were also proposed in the non-prepublished German applications 198 16 572.2 and 198 16 571.4. With a large number of sensors, the power consumption increases and a safety module, which is not always supplied by a system voltage, then draws the current required for the sensors from its internal battery, which also depletes the latter at an early stage. The capacity of the battery and the power consumption thus limit the life of a security module.
Like many other products, franking machines are also modular. This modularity allows the exchange of modules and components for various reasons. So can eg defective modules are replaced and replaced by checked, repaired or new modules. Since the utmost care is required when exchanging assemblies containing safety-relevant data, the replacement usually requires the use of a service technician and measures which, if used improperly or Unauthorized replacement of a security module to prevent its functioning. The latter is very expensive.
The invention has for its object, with little effort to ensure protection against an unauthorized manipulated security module when the security module is arranged interchangeable. The exchange should be possible by anyone in the simplest possible way.
The object is achieved with the features of the method according to claim 1 and with the features of the arrangement according to claim 10.
The invention is based on functional units to determine the exchange, manipulation and use of a security module of a postage meter, mail processing device or similar device to provide the users of the various devices a warranty on the correct operation of the security module and thus the entire device. Exchanging or damaging the safety module is at least detected and, if necessary, subsequently signaled as a condition when the safety module is plugged in again and supplied with a system voltage. The changes in the state of the security module are detected by means of a first functional unit and by means of a detection unit, which has a resettable latching and is powered by a battery. The first functional unit can evaluate the respective state when it is supplied with system voltage again. The advantages are a quick response to changes in the state of the security module and a low battery power consumption of the detection unit even during the non-supply of the system voltage.
A second functional unit may optionally monitor the battery voltage to see if its capacity has been exhausted. A required battery change is signaled, of course, a supply must be backed up by the system voltage. It is to be assumed at least then of an improper use of a security module in the exchange, in which not only the system voltage is missing, but also the interchangeable battery is removed. So that the replacement of the lowest possible qualified personnel and in the future can even be performed by the user, the second functional unit monitors the power failure when replacing the battery, the first functional unit, if necessary, first deletes sensitive data and thus restricts the further use of the security module or even prevented. After an on-site inspection of the security module by a service, the original functionality can be restored with the housing intact. The first functional unit enforces a later re-commissioning contact the security module with a remote data center to unlock at least one functional unit. If the entire security module has been exchanged without changing the battery, sensitive data is also first deleted by the second functional unit, but the sensitive data can be reinitialized during the restart. To establish contact methods with a digital or analog transmission link can be used. Also, an inspection of the security module is then prompted by a service. The safety module can signal different states. For example, a distinction can be made as to whether the last contact with the data center was made so long ago that it already seems suspicious or long that reinitialization is no longer permitted. The first functional unit is constantly evaluating a first day loan. When the latter is exhausted, the suspicious condition is signaled. By contacting the data center, the normal working condition can be restored without requiring an on-site inspection by a service. The time credit can be variable and vary from security device to security device. The time credit can be specified by the data center and loaded during installation into a memory of the security device. The first functional unit constantly evaluates a second daily loan. When the latter is exhausted, the condition becomes <img file="EP1035518A2_D0001.tif" />In the latter case, an inspection of the safety module by an on-site service is also required.
The procedure for protecting a security module involves the following steps:<ul id="ul0001" list-style="bullet" compact="compact"><li>Monitoring of the state, the proper use or replacement of the safety module at least by means of two functional units,</li><li>Signaling at least one state controlled by means of a first functional unit,</li><li>Deletion of sensitive data due to improper use or replacement at least by means of a second functional unit.</li></ul>
Then another procedure follows with the steps:<ul id="ul0002" list-style="bullet" compact="compact"><li>Reinitialization by means of the first functional unit of previously deleted sensitive data after proper use or replacement of the security module,</li><li>Recommissioning by unlocking the functional units of the safety module.</li></ul>
If necessary, an exchange of the safety module must be made. By means of a third functional unit, both an exchange state and a state of destruction after a mechanical or chemical attack can be detected, with the step:<ul id="ul0003" list-style="bullet" compact="compact"><li>Locking the functionality by means of the third functional unit due to an exchange of the security module or due to a state of destruction after an attack.</li></ul>
It is envisaged that the reinitialization in connection with a communication by means of a remote data center will be performed by the first functional unit after a dynamic plug-in detection has been successfully carried out, during which information is exchanged during the detection by the first functional unit via a current loop of the interface unit, whose error-free transmission proves the correct installation of the safety module. The activation of functional units of the safety module is done by resetting them. The first functional unit is a processor connected to the other functional units which is programmed to determine the respective status. The second functional unit is a resettable latch voltage monitoring unit and the third functional unit is a resettable latching detection circuit capable of detecting a previous unplugged condition as well as a destructive condition following a mechanical or chemical attack. For this static detection, the potting compound is equipped with additional means which warn the security module in the event of an attack and, if necessary, protect.
The arrangement for carrying out the method has a safety module, with logic with means for supplying the safety module with a system voltage or with a voltage from a battery and with a number of monitoring means. It is characterized by at least one first and second functional unit and by means for loading at least one time credit specified by the data center and by a signaling means, which is connected to a first functional unit, wherein loading is done during installation and reloading into a memory of the security device, and wherein the first functional unit evaluates a daily credit over time and activates the signal means, at least to signal the passage of time and by means of the second functional unit for deleting sensitive data in the memory due to improper use or replacement of the security module.
Advantageous developments of the invention are characterized in the subclaims or are presented in more detail below together with the description of the preferred embodiment of the invention with reference to FIGS. Show it:<ul id="ul0004" list-style="none"><li>FIG. 1, block diagram and interface of the security module,</li><li>FIG. 2, block diagram of the franking machine,</li><li>3, perspective view of the franking machine from behind,</li><li>FIG. 4, block diagram of the security module (second variant),</li><li>FIG. 5, circuit diagram of the detection unit,</li><li>6, side view of the security module (1 .Variant),</li><li>FIG. 7, top view of the security module (1st variant),</li><li>FIG. 8a, view of the security module from the right (1st variant),</li><li>Figure 8b, view of the safety module from the left (1st variant),</li><li>FIG. 9, table for status signaling,</li><li>FIG. 10, representation of the tests in the system for static and dynamically changeable states,</li><li>FIG. 11, side view of the security module (2nd variant),</li><li>FIG. 12, top view of the security module (2nd variant),</li><li>FIG. 13a, view of the security module from the right (2nd variant),</li><li>Figure 13b, view of the safety module from the left (2nd variant).</li></ul>
FIG. 1 shows a block diagram of the security module 100 with the contact groups 101, 102 for connection to an interface 8 and with the battery contact terminals 103 and 104 of a battery interface for a battery 134. Although the security module 100 is potted with a hard potting compound, the battery 134 of the security module 100 is interchangeably disposed outside of the potting compound on a printed circuit board. The circuit board carries the battery contact terminals 103 and 104 for connecting the poles of the battery 134. By means of the contact groups 101, 102, the security module 100 is plugged into a corresponding interface 8 of the mainboard (motherboard) 9. The first contact group 101 communicates with the system bus of a control device and the second contact group 102 serves to supply the security module 100 with the system voltage. Via pins P3, P5-P19 of contact group 101, address and data lines 117, 118 and control lines 115 run. The first and / or second contact group 101 and / or 102 are / is designed for static and dynamic monitoring of the plugged-in of the security module 100. About the pins P23 and P25 of the contact group 102, the supply of the security module 100 is realized with the system voltage of the motherboard 9 and via the pins P1, P2 or P4, a dynamic and static unplugged detection by the security module 100 is realized. The latter requires a detection unit 13, which is connected via a conductor loop 192, 194 to the pin P4 of the contact group 102. The conductor loop may be formed as part of the particular secure part of the security module 100 and embedded in sealing compound so that in a mechanical or chemical attack on the aforementioned part of the security module 100, the contact with the pin P4 is interrupted. The security module 100 has, in a manner known per se, a microprocessor 120 which contains an integrated read-only memory (internal ROM) with the special application program (not shown), which is required for the postage meter by the postal authority. is authorized by the respective postal carrier. Alternatively, a conventional read-only memory ROM or FLASH memory can be connected to the internal data bus 126. The security module 100 has, in a manner known per se, a reset circuit unit 130, a user circuit ASIC 150 and a logic PAL 160 which serves as the control signal generator for the ASIC. The reset circuit unit 130 or the user circuit ASIC 150 and the logic PAL 160 as well as possibly further - not shown - memory via the lines 191 and 129 supplied with system voltage Us +, which is supplied from the motherboard 9 with the franking device turned on. In EP 789 333 A2, the essential parts of a postal security module PSM have already been explained which implement the functions of billing and securing postage fee data.
The system voltage Us + is also applied via a diode 181 and the line 136 at the input of the voltage monitoring unit 12. At the output of the voltage monitoring unit 12, a second operating voltage Ub + is supplied, which is available via the line 138. When the franking device is switched off, not the system voltage Us +, but only the battery voltage Ub + is available. The negative terminal battery contact terminal 104 is connected to ground. From the battery contact terminal 103 lying on the positive pole, battery voltage is supplied via a line 193, via a second diode 182 and the line 136 to the input of the voltage monitoring unit. As an alternative to the two diodes 181, 182, a commercial circuit can be used as a voltage switch 180.
The output of the voltage monitoring unit 12 is connected via a line 138 to an input for this second operating voltage U<sub>b +</sub> connected to the processor 120, which leads at least to a RAM memory area 122, 124 and there guarantees non-volatile storage as long as the second operating voltage U<sub>b +</sub> at the required height. The processor 120 preferably includes an internal RAM 124 and a real-time clock (RTC) 122.
The voltage monitoring unit 12 in the security module has a resettable latching, which can be queried by the processor 120 via a line 164 and reset via a line 135. For a reset of the latching, the voltage monitoring unit 12 has circuit means. The reset can only be triggered when the battery voltage has risen above the predetermined threshold. The lines 135 and 164 are each connected to a pin (pins 1 and 2) of the processor 120. Line 164 provides a status signal to processor 120, and line 135 provides a control signal to voltage monitoring unit 12.
The line 136 at the input of the voltage monitoring unit 12 also supplies an unplugged detection unit 13 with operating or battery voltage. The unplugged detection unit 13 outputs on the line 139 a status signal to a pin 5 of the processor 120, which gives an indication of the state of the circuit. The processor 120 queries the state of the unplugged detection unit 13 via the line 139. The processor may reset the unplugged detection unit 13 with a signal output from the pin 4 of the processor 120 via the lead 137. After setting, a static check is made for connection. For this purpose, ground potential is queried via a line 192, which is present at the connection P4 of the interface 8 of the postal security module PSM 100 and can only be interrogated if the security module 100 is inserted properly. When plugged security module 100 ground potential of the negative pole 104 of the battery 134 of the postal security module PSM 100 is placed on the port P23 of the interface 8 and is thus interrogated at port P4 of the interface 8 via the line 192 of the unplugged detection unit 13.
At the pins 6 and 7 of the processor 120 is a line loop, which is looped back to the processor 120 via the pins P1 and P2 of the contact group 102 of the interface 8. For dynamic testing of the connectedness of the postal security module PSM 100 to the motherboard 9, the processor 120 generates alternating signal levels at quite irregular time intervals at the pins 6, 7 and looping them back through the loop. The postal security module PSM 100 is equipped with a long-live battery, which also allows monitoring of the use without the security module is connected to a system voltage of a postal processing facility. Proper use, operation, installation or installation in the appropriate environment are those characteristics to be tested by the functional units of the safety module. An initial installation is made by the manufacturer of the postal security module. Thus, after this initial installation, it is only necessary to check whether the postal security module is disconnected from its field of application (post-processing device), this usually taking place during an exchange. The monitoring of this condition is performed by the unplugged detection unit 13. In this case, a voltage level is monitored via the ground connection at the pin 4 of the interface unit 8. When replacing the functional unit, this ground connection is interrupted and the unplugged detection unit 13 registers this process as information. Since in a mechanical or chemical attack on the security module 100 and for each separation of the security module 100 from the interface unit 8, the storage of this information by the special battery-powered circuitry is ensured, an evaluation of this information can be done at any time, if a restart is desired , The regular evaluation of this separation or Unmatched signal on line 139 of detection unit 13 allows processor 120 to erase sensitive data without, however, altering the accounting and customer data in NVRAM memories. The current state of the postal security module with the deleted sensitive data can be understood as a maintenance condition, in which usually the replacement, repair or otherwise is made. Since the sensitive data of the functional unit are deleted, an error due to improper handling of the postal security module is excluded. The sensitive data are, for example, cryptographic keys. The processor 120 prevents in the maintenance state a core functionality of the postal security module, which consists for example in the billing and / or calculation of a security code for the security marking in a security print.
For recommissioning the postal security module PSM is first inserted and electrically connected to the corresponding interface unit 8 of a mail processing device. Then the device is switched on and thus the postal security module is again supplied with system voltage Us +. Due to the special condition, the proper installation of the postal security module must now be rechecked by its functional unit. For this purpose, a second stage of a test (dynamic plug-in detection) is provided. By means of an operative connection established between the first functional unit (processor 120) and the current loop 18 of the interface unit 8, information is exchanged whose error-free transmission provides proof of the proper installation. This is a prerequisite for a successful restart.
For the state change to the normal operating state, a reinitialization of the sensitive data is now required. A communication is made between the postal security module and a third entity, the latter transmitting this sensitive data. Upon successful transmission, the untagged detection unit 13 is reset and the postal security module returns to its normal operating state. The restart is complete.
FIG. 2 shows a block diagram of a postage meter machine equipped with a chip card write / read unit 70 for reloading change data by chip card and with a printing device 2 which is controlled by a control device 1. The control device 1 has a motherboard 9 equipped with a microprocessor 91 with associated memories 92, 93, 94, 95.
The program memory 92 contains an operating program for at least printing and at least safety-related components of the program for a predetermined format change of a portion of the user data. The RAM RAM 93 is used for volatile intermediate storage of intermediate results. NVM 94 non-volatile memory is used for non-volatile caching of data, such as statistical data organized by cost center. The calendar / clock module 95 also contains addressable but non-volatile memory areas for the non-volatile intermediate storage of intermediate results or also known program parts (for example for the DES algorithm). It is provided that the control device 1 is connected to the chip card write / read unit 70, wherein the microprocessor 91 of the control device 1 is programmed, for example, to load the payload N from the memory area of a chip card 49 for their application in corresponding memory areas of the franking machine , A first chip card 49 inserted in a slot 72 of the chip card write / read unit 70 allows reloading of a record in the postage meter machine for at least one application. The chip card 49 contains, for example, the postage for all the usual postal carrier services according to the tariff of the postal authority and a post carrier code to generate a stamp image with the franking machine and to stamp the postal items according to the tariff of the postal authority.
The control device 1 forms the actual meter with the means 91 to 95 of the aforementioned motherboard 9 and also includes a keyboard 88, a display unit 89 and an application-specific circuit ASIC 90 and the interface 8 for the postal security module PSM 100th The safety module PSM 100 is connected via a control bus with the aforementioned ASIC 90 and the microprocessor 91 and via the parallel μC bus at least with the means 91 to 95 of the motherboard 9 and the display unit 89. The control bus carries lines for the signals CE, RD and WR between the safety module PSM 100 and the aforementioned ASIC 90. The microprocessor 91 preferably has a pin for an output from the security module PSM 100 interrupt signal i, further connections for the keyboard 88, a serial interface SI-1 for the connection of the smart card write / read unit 70 and a serial interface SI-2 for the optional By connecting a MODEM by means of the MODEM, for example, the credit stored in the non-volatile memory of the postal security device PSM 100 can be increased.
The postal security device PSM 100 is surrounded by a secured housing. Before each franking imprint, a hardware settlement is carried out in the postal security module PSM 100. Billing is independent of cost centers. The postal security agent PSM 100 can be designed internally as described in detail in the European application EP 789 333 A3. It is contemplated that the ASIC 90 may include a serial interface circuit 98 to a post-stream powered device, a serial interface circuit 96 to the sensors and actuators of the printing device 2, a serial interface circuit 97 to the print control electronics 16 for the printhead 4, and a serial interface circuit 99 to one has the printing device 20 in the post-stream downstream device. DE 197 11 997 a variant for the peripheral interface is removable, which is suitable for multiple peripheral devices (stations). It is entitled: Arrangement for communication between a base station and other stations of a mailing machine and their emergency shutdown.
The interface circuit 96 coupled to the machine base interface circuit 14 provides at least one connection to the sensors 6, 7, 17 and to the actors, for example to the drive motor 15 for the roller 11 and to a cleaning and sealing station RDS 40 for the inkjet printhead 4, and to the label dispenser 50 in the machine base. The basic arrangement and the interaction between the inkjet printhead 4 and the RDS 40 can be found in DE 197 26 642 C2. entitled: Arrangement for positioning an ink jet printhead and a cleaning and sealing device. One of the arranged in the guide plate 20 sensors 7, 17 is the sensor 17 and is used to prepare the pressure release during letter transport. The sensor 7 is used for initial letter recognition for the purpose of triggering the letter transport. The transport device consists of a conveyor belt 10 and two rollers 11,11 '. One of the rollers is equipped with a motor 15 drive roller 11, another is the follower tension roller 11 '. Preferably, the drive roller 11 is designed as a toothed roller, according to the conveyor belt 10 is designed as a toothed belt, which ensures the unambiguous power transmission. An encoder 5, 6 is coupled to one of the rollers 11, 11 '. Preferably, the drive roller 11 is firmly seated with an incremental encoder 5 on an axis. The incremental encoder 5 is designed for example as a slotted disk, which cooperates with a light barrier 6, and outputs via the line 19 an encoder signal to the motherboard 9 from. It is envisaged that the individual printing elements of the print head are connected within its housing with a print head electronics and that the print head for a purely electronic pressure can be controlled. The pressure control is based on the path control, whereby the selected stamp offset is taken into account, which is entered by keyboard 88 or if necessary by chip card and stored in memory NVM 94 non-volatile. A planned imprint thus results from stamp offset (without printing), the franking print image and possibly further print images for advertising clichés, shipping information (optional prints) and additional editable messages. The nonvolatile memory NVM 94 has a plurality of memory areas. These include those which save the loaded postage fee tables non-volatile. The smart card write / read unit 70 consists of an associated mechanical carrier for the microprocessor card and contacting unit 74. The latter allows a secure mechanical support of the chip card in the read position and clear signaling of reaching the reading position of the chip card in the contacting unit. The microprocessor card with the microprocessor 75 has a programmed read capability for all types of memory cards or Chip cards. The interface to the franking machine is a serial interface in accordance with the RS232 standard. The data transfer rate is min. 1.2 K baud. The switching on of the power supply takes place by means of a switch 71 connected to the mainboard. After switching on the power supply, a self-test function with ready message takes place.
FIG. 3 shows a perspective view of the franking machine from the rear. The franking machine consists of a meter 1 and a base 2. The latter is equipped with a smart card write / read unit 70, which is arranged behind the guide plate 20 and accessible from the housing upper edge 22. After switching on the franking machine by means of the switch 71, a chip card 49 is inserted from top to bottom in the insertion slot 72. A supplied standing on the edge letter 3, which rests with its surface to be printed on the guide plate is then printed according to the input data with a franking stamp 31. The letter feeding opening is bounded laterally by a transparent plate 21 and the guide plate 20. The status display of the security module 100 inserted on the motherboard 9 of the meter 1 is visible from the outside through an opening 109.
FIG. 4 shows a block diagram of the postal security module PSM 100 in a preferred variant. The negative pole of the battery 134 is connected to ground and a pin P23 of the contact group 102. The positive pole of the battery 134 is connected to the one input of the voltage changeover switch 180 via the line 193, and the system voltage leading line 191 is connected to the other input of the voltage changeover switch 180. The battery 134 is the SL389 / P for a life of up to 3.5 years or the SL-386 / P for a life of up to 6 years with a maximum power consumption by the PSM 100. As voltage switch 180, a commercial circuit of the type ADM 8693ARN can be used. The output of the voltage changeover switch 180 is connected via the line 136 to the battery monitoring unit 12 and the detection unit 13. The battery monitoring unit 12 and the detection unit 13 communicate with the pins 1, 2, 4 and 5 of the processor 120 via the lines 135, 164 and 137, 139 in communication. The output of the voltage changeover switch 180 is also connected via the line 136 to the supply input of a first memory SRAM, which becomes the non-volatile memory NVRAM of the first technology by the existing battery 134. The security module communicates with the postage meter via the system bus 115, 117, 118. The processor 120 may communicate via the system bus and a modem 83 in communication with a remote data center. The billing is performed by the ASIC 150 and checked by the processor 120. The postal billing data is stored in non-volatile memory of different technology. The system voltage is applied to the supply input of a second memory NV-RAM 114. The latter is a nonvolatile NVRAM of a second technology, (SHADOWRAM). This second technology preferably comprises a RAM and an EEPROM, the latter automatically assuming the data contents in the event of system voltage failure. The NVRAM 114 of the second technology is connected to the corresponding address and data inputs of the ASIC 150 via an internal address and data bus 112, 113.
The ASIC 150 contains at least one hardware abort unit for the calculation of the postal data to be stored. Programmable Array Logic (PAL) 160 accommodates access logic to ASIC 150. The ASIC 150 is controlled by the PAL 160 logic. An address and control bus 117, 115 from the motherboard 9 is connected to respective pins of the PAL 160 logic and the PAL 160 generates at least one control signal for the ASIC 150 and a control signal 119 for the program memory FLASH 128. The processor 120 executes a program stored in the FLASH 128. Processor 120, FLASH 28, ASIC 150, and PAL 160 are interconnected via a module-internal system bus that includes lines 110, 11, 12, 126, 119 for data, address, and control signals. The processor 120 of the security module 100 is connected via a module-internal data bus 126 to a FLASH 128 and to the ASIC 150. The FLASH 128 is supplied with system voltage Us +. For example, it is a 128 Kbyte FLASH memory type AM29F0I0-45EC. The ASIC 150 of the postal security module 100 delivers the addresses 0 to 7 to the corresponding address inputs of the FLASH 128 via a module-internal address bus 110. The processor 120 of the security module 100 provides via an internal address bus 111 the addresses 8 to 15 to the corresponding address inputs of the FLASH 128. The ASIC 150 of the security module 100 is connected via the contact group 101 of the interface 8 with the data bus 118, with the address bus 117 and the control bus 115 of the motherboard 9 in communication.
It is envisaged that the processor 120 has memory 122, 124 to which an operating voltage Ub + from a voltage monitoring unit 12 is supplied via the line 138. In particular, a real-time clock RTC 122 and the memory RAM 124 are supplied by an operating voltage via the line 138. The voltage monitor (Battery Observer) 12 also provides a status signal 164 and responds to a control signal 135. Voltage selector 180, as the output voltage on line 136 for battery observer 12 and memory 116, supplies that of its input voltages as the supply voltage which is greater than the other. Due to the possibility of automatically feeding the described circuit as a function of the magnitude of the voltages Us + and Ub + with the larger of the two, during normal operation the battery 134 can be exchanged without loss of data.
The battery 134 of the security module 100 feeds in the rest periods outside normal operation in the aforementioned manner the real-time clock (RTC) 122 with date and / or time registers and / or the static RAM (SRAM) 124, which holds security-relevant data. If the voltage of the battery drops below a certain limit during battery operation, the voltage monitoring unit 12 connects the feed point for the RTC and SRAM to ground until reset. The voltage at the RTC and SRAM is then at 0V. This causes the SRAM 124, the example contains important cryptographic keys, is deleted very quickly. At the same time, the registers of RTC 122 are cleared and the current time and date are lost. This action prevents a potential attacker from stopping the postage meter internal clock 122 by manipulating the battery voltage without losing any security related data. This prevents the attacker from circumventing security measures such as long time timers or watchdogs. The aforementioned safety measures are explained in detail with reference to FIGS. 9 and 10.
The RESET unit 130 is connected via the line 131 to the pin 3 of the processor 120 and to a pin of the ASIC 150. The processor 120 and the ASIC 150 are reset by a reset generation in the RESET unit 130 when the supply voltage drops.
Simultaneously with the indication of the undervoltage of the battery, the described circuit changes into a self-holding state in which it remains even when subsequently increasing the voltage. The next time the module is switched on, the processor can query the state of the circuit (status signal) and thus and / or via the evaluation of the contents of the erased memory, conclude that the battery voltage has in the meantime fallen below a certain value. The processor can reset the monitoring circuit, ie make a fad.
The unplugged detection unit 13 has to measure the input voltage line 192, which is connected via the plug of the security module and interface 8, preferably via a socket on the motherboard 9 of the postage meter to ground. This measurement is used for static monitoring of the arrangement and forms the basis for monitoring at a first stage. It is contemplated that the unplugged detection unit 13 comprises resettable latching means, the latching being triggered when the voltage level on a sense voltage line 192 deviates from a predetermined potential. At the same time, the evaluation logic includes the processor 120 connected to the other functional units, which is programmed to detect and change the respective state of the security module 100. The state of latching can be queried via the line 139 from the processor 120 of the security module 100. The measuring voltage potential on the line 192 corresponds to ground potential when the security module 100 is properly inserted. On line 139 is operating voltage potential. Ground voltage potential is present on the line 139 when the security module 100 is unplugged. The processor 120 has a fifth pin 5, to which the line 139 is connected in order to query the state of the unplugged detection unit 13, whether it is switched to ground potential with latching. In order to reset the state of latching of the unplugged detection unit 13 via the line 137, the processor 120 has a fourth pin 4.
Furthermore, a current loop 18 is provided which also connects the pins 6 and 7 of the processor 120 via the plug of the security module and via the socket on the motherboard 9 of the postage meter machine. The lines on the pins 6 and 7 of the processor 120 are closed only to a current loop 18 at a plugged into the motherboard 9 PSM 100. This loop forms the basis for a dynamic monitoring of the plugged-in safety module on a second level.
The processor 120 internally comprises a processing unit CPU 121, a real-time clock RTC 122, a RAM unit 124 and an input / output unit 125. The processor 120 is equipped with pins 8, 9 for outputting at least one signal for signaling the status of the security module 100 , At the pins 8 and 9 are I / O ports of the input / output unit 125 to which module-internal signaling means are connected, for example, colored light emitting diode LED's 107, 108, which signal the state of the security module 100. The safety modules can assume different states in their life cycle. So must eg to detect whether the module contains valid cryptographic keys. Furthermore, it is also important to distinguish whether the module is working or is defective. The exact type and number of module states depends on the implemented functions in the module and on the implementation.
The circuit diagram of the detection unit 13 will be explained with reference to FIG. It is provided that the unplugged detection unit 13 has a voltage divider, which consists of a series circuit of resistors 1310, 1312, 1314 and between a tapped by a capacitor 1371 supply voltage potential and a Meßspannungspotential on the line 192 is placed. The circuit is supplied via line 136 with the system or battery voltage. The respective supply voltage from the line 136 passes through a diode 1369 to the capacitor 1371 of the circuit. On the output side of the circuit is an inverter 1320, 1398. In the normal state, the transistor 1320 of the inverter is turned off and the supply voltage is applied via the resistor 1398 on the line 139, which therefore is logically '1', ie H level in the normal state leads. An L level on line 139 is advantageous as a status signal for unplug because then no current flows into pin 5 of processor 120, increasing battery life. The diode 1369, preferably in conjunction with an electrolytic capacitor 1371, ensures that the circuit upstream of the inverter is supplied with a voltage over a relatively long period of time (> 2 sec), in which its function is ensured, even though the voltage on the line 136 is already high was turned off. The voltage divider 1310, 1312, 1314 has a tap 1304 to which a capacitor 1306 and the noninverting input of a comparator 1300 are connected. The inverting input of the comparator 1300 is connected to a reference voltage source 1302. The output of the comparator 1300 is connected on the one hand via the negator 1324.1398 to the line 139 and on the other hand to the control input of a switching means 1322 for latching. The switching means 1322 is connected in parallel with the resistor 1310 of the voltage divider, and the latching switching means 1316 is connected between the tap 1304 and ground. The tap 1304 of the voltage divider is at the junction of resistors 1312 and 1314. The capacitor 1306 connected between the tap 1304 and ground prevents vibrations. The voltage at tap 1304 of the voltage divider is compared in comparator 1300 with the reference voltage of source 1302. If the voltage to be compared at tap 1304 is less than the reference voltage of source 1302, 50, the comparator output remains switched low and transistor 1320 of the inverter is disabled. As a result, the line 139 now receives operating voltage potential and the status signal leads logically '1'. The voltage divider is dimensioned so that at ground potential on the line 192, the tap 1304 performs a voltage which is safely below the switching threshold of the comparator 1300. If the connection is interrupted and the line 192 is no longer connected to ground, because the security module 100 from the socket on the motherboard 9 or Interface unit 8 of the franking machine has been solved, the voltage at the tap 1304 is pulled over the voltage of the reference voltage source 1302 and the comparator 1300 switches over. The comparator output is switched to H level, and thus the transistor 1320 is turned on. As a result, the line 139 is connected to ground potential and the status signal logic '0. By means of a transistor 1322, which is connected in parallel with the resistor 1310 of the voltage divider, a self-holding circuit of the unplugged detection unit 13 is realized. The control input of transistor 1322 is switched to the H level by the comparator output. As a result, the transistor 1322 turns on and bridges the resistor 1310. As a result, the voltage divider is formed only by the resistors 1312 and 1314. As a result, the switching threshold is increased so much that the comparator remains in the switched state when the line 192 again ground potential, because the security module was plugged again. The state of the circuit can be queried via the signal on line 139 from the processor 120. It is contemplated that the unplugged detection unit 13 as circuit means comprises a line 137 and a latching resetting means 1316, the reset being triggerable by the processor 120 via a signal on the line 137. The processor 120 can at any time via a user circuit ASIC 150, via a first contact group 101, via a system bus of the controller 1 and for example via the microprocessor 91 via modem 83 to contact a remote data center, which checks the billing data and optionally other data to the Processor 120 transmitted. The user circuit ASIC 150 of the security module 100 is connected to the processor 120 via a module-internal data bus 126. The processor 120 may be the Un reset the unplugged detection unit when reinitialization has been successfully completed by the transmitted data. For this purpose, transistor 1316 is turned on via the reset signal on line 137, thus pulling the voltage at tap 1304 below the reference voltage of source 1302 and blocking transistors 1320 and 1322. When transistor 1322 is normally off, resistors 1310 and 1312 in series form the upper part of the above voltage divider and the switching threshold is lowered back to the original state.
FIG. 6 shows a side view of the mechanical structure of the security module. The security module is designed as a multi-chip module, ie several functional units are interconnected on a printed circuit board 106. The security module 100 is potted with a hard potting compound 105, wherein the battery 134 of the security module 100 is arranged outside of the potting compound 105 on a printed circuit board 106 interchangeable. For example, it is potted with a potting material 105 that signal means 107, 108 protrude from the potting material at a first location and that the circuit board 106 protrudes laterally with the inserted battery 134 a second location. The circuit board 106 also has battery contact terminals 103 and 104 for connecting the poles of the battery 134, preferably on the component side above the circuit board 106th It is envisaged that for the attachment of the postal security module PSM 100 on the motherboard of the meter 1, the contact groups 101 and 102 below the circuit board 106 (trace side) of the security module 100 are arranged. The user circuit ASIC 150 is via the first contact group 101 - in a manner not shown - in communication with the system bus of a control device 1 and the second contact group 102 serves to supply the security module 100 with the system voltage. If the security module is plugged onto the motherboard, then it is preferably arranged within the meter housing in such a way that the signal means 107, 108 near an opening 109 or projects into this. The meter housing is thus advantageously designed so that the user can still see the status of the security module from the outside. The two light emitting diodes 107 and 108 of the signal means are controlled via two output signals of the I / O ports to the pin 8, 9 of the processor 120. Both light-emitting diodes are housed in a common component housing (bi-polar LED), which is why the dimensions or the diameter of the opening can remain relatively small and is of the order of magnitude of the signal means. In principle, three different colors can be displayed (red, green, orange). To distinguish the state of the LEDs are also used flashing, so that 8 different state groups can be distinguished, which are characterized by the following LED states: green LED, red LED, orange orange, red LED flashing, green LED flashing, orange LED flashing , Red LED flashing and orange flashing, green LED flashing and orange flashing.
FIG. 7 shows a plan view of the postal security module.
Figures 8a and 8b show a view of the security module respectively from the right and from the left. The position of the contact groups 101 and 102 below the printed circuit board 106 is apparent from FIGS. 8a and 8b in conjunction with FIG.
According to a self-explanatory table for status signaling shown in FIG. 9, a large number of possible status indications emerge. A green LED 107 signals an OK state 220, but a lit LED 108 signals an error state 230 as a result of an at least static self-test. The result of such a known self-test can not be falsified because of the direct signaling via the LEDs 107,108. For example, in the event that, in the meantime, the keys stored in the security module have been lost, the ongoing check in dynamic mode would detect the error and signal it as state 240 with orange LEDs. After switching off / on, booting is required, otherwise no other operation can be performed. The case where the installation of a key has been forgotten during manufacture is signaled as state 260, for example with a green blinking LED 107. The first functional unit is the processor 120. This constantly evaluates a second daily loan to see if the latter is exhausted. That's the case where a long time timer has expired. The long time timer has expired if the data center has not been contacted for too long, for example to recharge a credit. For example, 90 days can be specified by the data center as a time credit and loaded into a memory 124 of the security device during installation or during reloading. After this 90 days will be one <img file="EP1035518A2_D0002.tif" />LOST "state 250 is signaled by a flashing red LED The long time timer is preferably a down counter that is implemented in processor 120. As the count reaches zero over time, state 250 also remains when the security module is disconnected from the meter , after the <img file="EP1035518A2_D0003.tif" />If the last contact with the data center has been made so long that it already appears suspicious, then the suspect state 270 is signaled, preferably a backward counter, also implemented in the processor 120, which constantly provides a first daily credit of, say, 30 days evaluates whether the latter is exhausted.
Other status indications for states 280 and 290 are optionally provided for various further tests. For this purpose, further functional units, in particular a temperature sensor, may be provided in the security module. If, for example, a temperature was exceeded which could lead to damage in the safety module, then this state 280 can be signaled with the LEDs 107, 108, which light up red and flash orange, and thus produce the overall effect of the alternating red / orange flashing. The second functional unit may optionally monitor the battery voltage to see if its capacity has been exhausted. Advantageously, a state 290 for a required battery change can be signaled with the LEDs 107, 108, which light up green and flash orange, thus causing the overall effect of the alternating green / orange flashing.
FIG. 10 shows a representation of the tests in the system for statically and dynamically changeable states. A deactivated system in state 200, after being switched on, transitions via transition Start 201 into state 210, in which a static self-test is performed by the safety module as soon as the operating voltage is present. In the transition 202, in which the self-test results in an OK result, the state 220 with LED 107 is reached in green. Starting from the latter state, if necessary, a repeated static self-test, a dynamic duration test, at least one periodic time credit test and other tests are feasible. Transition 203 illustrating such tests returns to state 220 LED green at OK. A transition 206 leads to state 240 and the LEDs light orange at an error detected during the dynamic self-test. The latter is possibly due to a Recover attempt. by switching off (transition 211) and restarting the device (transition 201) can be corrected. Static errors are not recoverable. From state 210, in which the powered-on device is performing a static self-test, if there is a fault, a transition 204 to state 230 occurs and LED 108 lights up red. At any time, when the device is in state 220 (LED green), an on-demand static self-test can, in the event of a fault, transition to state 230 (LED red) via a transition 205. Starting from state 220 (LED green), further transitions 207, 208, 209 lead to the further states 270, 250, 260. In state 270 is signaled with orange flashing LED's 107, 108 that the connection to the data center should be recorded, since the security device is already considered suspect. Via the transition 212, which results in the reloading, the state 210 is reached again. In state 250, with the red flashing LED 108, the state <img file="EP1035518A2_D0004.tif" />LOST "signals. At transition 209, where another self-test of processor 120 results in a need to reload a key, state 260 is reached blinking green LED 107. Starting from state 220 (LED 107 green), optional further transitions may lead either to the further state 280 with red flashing / orange flashing LEDs or state 290 to green flashing / orange flashing LEDs. At the first optional transition, a temperature measurement will result in a need to swap the entire security module. In the latter transition, capacitance measurement of the battery results in a need for battery replacement.
FIG. 11 shows the mechanical structure of the security module according to a second variant in a side view. The security module is again designed as a multi-chip module and potted with a hard potting compound 105, wherein the battery 134 of the security module 100 is arranged outside of the potting compound 105 on a printed circuit board 106 interchangeable. For cost reasons, the potting is performed at a first location with a potting material 105 that the signal means 107, 108 and the inserted battery 134 are mounted externally from the potting material at a second location on the top of the circuit board 106. The circuit board 106 has again battery contact terminals 103 and 104 for connecting the poles of the battery 134, preferably on the component side above the circuit board 106th The two light-emitting diodes 107 and 108 of the signal means are separate components in this variant. The two light emitting diodes 107 and 108 of the signal means are controlled via two output signals of the I / O ports to the pin 8, 9 of the processor 120. In order to distinguish the state, the LEDs can in turn also be controlled in a flashing manner so that different status groups can be distinguished. The meter housing is also designed again so that the user can see the status display of the security module from the outside, for example through a viewing window or opening 109. It is also envisaged that for the attachment of the postal security module PSM 100 on the motherboard of the meter 1, the contact groups 101 and 102 are arranged below the circuit board 106 of the security module 100. Advantageously, a connector 127 includes the contact groups 101 and 102, wherein a connector 127 is disposed on the wiring side of the circuit board 106.
FIG. 12 shows a plan view of the postal security module of the second variant. The potting compound 105 surrounds the first part of the circuit board 106 in a cuboid, while the second part of the circuit board 106 for the two light emitting diodes 107 and 108, the interchangeably arranged battery 134 and the connector 127 (not visible here) remains free of potting compound. The battery contact terminals 103 and 104 are covered by the battery in FIG. 12, but like the connector 127 are visible in the side view of FIG. 13a.
The potting of the first part of the circuit board 106 shows neither openings nor elevations and thus offers fewer points of attack for manipulation in criminal intent. The potting material 105 is preferably a two-component epoxy resin or polymer or Plastic. Suitable is a potting compound from STYCAST®2651-40 FR from EMERSON & CUMING with preferably CATALYST 9 as the second component. In the production of the encapsulation, both components are mixed and applied to both sides of the circuit board 106 in the first part. The latter can be done for example by immersion in the fresh mixture. Now, a protective and / or sensor layer, which is not visible from the outside after a final external encapsulation, can be attached, which forms a firm connection with the latter during hardening of the encapsulation material 105. After the final external encapsulation, the potting compound hardens to the solid opaque potting material 105.
Figures 13a and 13b show a view of the security module of the second variant respectively from the right and from the left. The position of the connector 127 with the contact groups 101 and 102 below the circuit board 106 is more clearly visible from Figures 13a and 13b in conjunction with Figure 12. Alternatively, for example, a connector 127 may be mounted on top of the second part of the circuit board 106, not shown.
In principle, of course, another signal means can be used in conjunction with a postal device. According to the invention, the postal device, in particular a franking machine. The security module can then be approved as a postal security device PSD (POSTAL SECURITY DEVICE) by the respective postal authority.
The security module or PSD also have a different design, which makes it possible that it can be plugged, for example, on the motherboard of a personal computer that drives a commercial printer as a PC meter.
The invention is not limited to the present embodiment, since obviously other other arrangements or embodiments of the invention can be developed or used, which - based on the same basic idea of the invention - are encompassed by the appended claims.
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7222238B2 | Cited by | United States of America | Applicant |
| DE10116703A1 | Cited by | Germany | Search report |
| DE10136608B4 | Cited by | Germany | Search report |
| US6512376B2 | Cited by | United States of America | Applicant |
| EP1209631A1 | Cited by | European Patent Office (EPO) | Search report |
| US7610501B2 | Cited by | United States of America | Applicant |
| EP1967976A2 | Cited by | European Patent Office (EPO) | Applicant |
| DE102007011309A1 | Cited by | Germany | Applicant |
| EP0417447B1 | Cites | European Patent Office (EPO) | Applicant |
| EP0660269A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0660270A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0789333A2 | Cites | European Patent Office (EPO) | Applicant |
| DE19605015C1 | Cites | Germany | Applicant |
| GB2303173A | Cites | United Kingdom | Search report |
| US4575621A | Cites | United States of America | Search report |
| US4746234A | Cites | United States of America | Applicant |
| US5097253A | Cites | United States of America | Search report |
| US5353350A | Cites | United States of America | Search report |
| US5490077A | Cites | United States of America | Applicant |
| US5515540A | Cites | United States of America | Search report |
| US5606508A | Cites | United States of America | Applicant |
| WO9820461A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
25 members in 5 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 19912781 | Germany | A | |
| 19912781 | Germany | – | |
| 19928057 | Germany | A | |
| 19928057 | Germany | – | |
| 19912781 | – | – | – |
| 19928057 | – | – | – |
| DE1999112781 | – | – | – |
| DE1999128057 | – | – | – |
Members25
| Document | Office | Kind | |
|---|---|---|---|
| EP1035517A2 | European Patent Office (EPO) | A2 | |
| EP1035518A2This record | European Patent Office (EPO) | A2 | |
| AU2080500A | Australia | A | |
| AU2081100A | Australia | A | |
| CN1271145A | China | A | |
| DE19912781A1 | Germany | A1 | |
| CN1276579A | China | A | |
| EP1035517A3 | European Patent Office (EPO) | A3 | |
| EP1035518A3 | European Patent Office (EPO) | A3 | |
| EP1063619A1 | European Patent Office (EPO) | A1 | |
| DE19928057A1 | Germany | A1 | |
| US6362724B1 | United States of America | B1 | |
| US2002194017A1 | United States of America | A1 | |
| CN1156800C | China | C | |
| CN1156801C | China | C | |
| US6952777B1 | United States of America | B1 | |
| US6954149B2 | United States of America | B2 | |
| DE19928057B4 | Germany | B4 | |
| EP1063619B1 | European Patent Office (EPO) | B1 | |
| US7194443B1 | United States of America | B1 | |
| DE50014030D1 | Germany | D1 | |
| EP1035518B1 | European Patent Office (EPO) | B1 | |
| DE50015220D1 | Germany | D1 | |
| EP1035517B1 | European Patent Office (EPO) | B1 | |
| DE50015314D1 | Germany | D1 |
36 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Patent ceasedCeasedPL | PL | CH | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Change of applicant/patenteeR081 | R081 | DE | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Corresponds to:REF | REF | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Title (correction)ARRANGEMENT FOR THE PROTECTION OF A SECURITY MODULERTI1 | RTI1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Designation fees paidCH DE FR GB IT LIAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Information provided on ipc code assigned before grant7G 07B 17/00 A, 7G 07B 17/04 BRIC1 | RIC1 | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1035518
- Publication, DOCDB
- 1035518
- Publication, EPODOC
- EP1035518
- Application
- 250065
- Application, DOCDB
- 00250065
- Application, EPODOC
- EP20000250065
Titles6
- German
- Anordnung zum Schutz eines Sicherheitsmoduls
- English
- Arrangement for the protection of a security module
- French
- Ensemble de protection d'un module de sécurité
- German
- Verfahren zum Schutz eines Sicherheitsmoduls und Anordnung zur Durchführung des Verfahrens
- English
- Method for the protection of a security module and arrangement for implementing said method
- French
- Procédé de protection d'un module de sécurité et ensemble pour mettre en oeuvre ledit procédé
Classification
- CPC, 7
- G07B17/00733
- G07B2017/00233
- G07B2017/00298
- G07B2017/00306
- G07B2017/00346
- G07B2017/00403
- G07B2017/00967
- IPC, 1
- G07B17 00
Designated states3
- Contracting states, 2
- Liechtenstein
- Sweden
- Extension states, 1
- Slovenia