Method and apparatus for generating different cryptographic secure procedures concerning messages in a host device
Abstract
Verfahren und Anordnung zur unterschiedlichen Erzeugung kryptographischer Sicherungen von Mitteilungen in einem Hostgerät, wobei zur kryptographischen Sicherung einer Mitteilung für einen ersten Zweck eine erste Signatur zur kryptographischen Sicherung einer Mitteilung für einen zweiten Zweck eine zweite Signatur eingesetzt wird, wobei sich die Signaturen in der Art ihrer Erzeugung unterscheiden. Eine Cryptologik (20) weist eine Anzahl an Logikschaltungen (21, 22, 23) und einen Umschalter (24, 26) auf und ist extern vom postalischen Sicherheitsgerät (10) angeordnet und mindestens mit ihrem Ausgang (d) mit einem Informationseingang (i) des postalischen Sicherheitsgerätes (10) verbunden, das eine Logikschaltung (12) aufweist, die einen digitalen Signaturalgorithmus auf das vom Ausgang (d) gelieferte Ausgangssignal anwendet, um Daten für eine Signatur zu erzeugen.

Term
Term ended
Projected expiry passed 6 November 2023, 2.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
17 claims: 8 independent, 9 dependent
- 1Method for differently generating cryptographic backups of messages in a host device, a first signature being used for cryptographically securing a message for a first purpose and a second signature for cryptographically securing a message for a second purpose, characterized in that the signatures differ in the way they are generated.
- 5Arrangement for the different generation of cryptographic backups of messages in a host device, at least with a postal security device (10), characterized in that a cryptology (20) is arranged externally from the postal security device (10) and at least its output (d) is connected to an information input (i) of the postal security device (10) and that the postal security device (10) has a logic circuit (12) which applies a digital signature algorithm to the output signal provided by output (d) to generate data for a signature.
- 8Arrangement, according to claims 5 to 7, characterized in that a first logic circuit (21) for a first crypto-algorithm and a second logic circuit (22) for a second crypto-algorithm are connected on the input side and lead on the output side to contacts (I and II) of the switch (24), the latter on the output side at the input of the second logic circuit ( 12) that generates the signature. (Fig.2)
- 9Arrangement, according to claims 5 to 7, characterized in that the postal security device (10) has a first logic circuit (11) for a first crypto-algorithm and a second logic circuit (12) which generates data for a signature that the host-controlled cryptology (20) has a second and third logic circuit (22) and (23) and a changeover switch (24), wherein the first logic circuit (11) of the postal security device (10) and the second and third logic circuits (22) and (23) are connected on the output side to the information input (i) of the postal security device (10), the information input (i) being connected to the second logic circuit (12) is connected on the input side, and that the changeover switch (24) has an input for a message (m) and contacts (I, II and III), each at the input (e 1 , e 2 , e 3 ) of the logic circuits (11, 22, 23). (Fig.5a)
- 10Arrangement, according to claims 5 to 7, characterized in that a first logic circuit (21) for a first crypto-algorithm has an input (e 1 ) for a message (m) and an exit (a 1 ) which has an input (e 3 ) for a further logic circuit (23) for a further crypto-algorithm, the output (a 3 ) is present at the information input (i) of a second logic circuit (12) of the postal security device (10), the second logic circuit (12) generating the signature.
- 12Arrangement according to claims 10 to 11, characterized in that a first and a second switch (24, 26) are provided in the host-controlled cryptology (20), the switch (24 and 26) being connected to a control data input (c 1 , c 2 ) are controllable by a host, contacts (I and II) of the switch (24) with the outputs (a 1 ) and (a 3 ) of the first and third logic circuits (21) and (23) and that the second switch (24) on the output side forms the output (d) which is connected to the information input (i) of the postal security device (10). (Fig.9)
- 13Arrangement, according to claims 5 and 6, characterized in that the postal security device (10) and the crypto logic (20) each have at least one logic circuit (11) and (23) and that the crypto logic (20) has a first host-controlled changeover switch (26) which has a key (k1, k2) for the further crypto-algorithm of the further logic circuit (23) switches over that a second PSD-controlled switch (14) is provided in the postal security device (10), contacts (I or II) of the second switch (14) with the outputs (a 1 or a 3 ) of the first and third logic circuits (11) and (23) are connected. (Fig. 10)
Independent claims8
28 paragraphs, as filed
The invention relates to a method and an arrangement for the different generation of cryptographic backups of messages in a host device, according to the preamble of claims 1 and 5. The invention is suitable for mail processing devices with a security module, which has a corresponding cryptographic backup differently depending on one in the mail processing device set message type. It is used in particular in franking machines, addressing machines and other mail processing devices.
A franking imprint contains a message with a previously entered and stored postal information including the postage data for the transportation of the letter. Modern franking machines allow a special marking to be printed in addition to the aforementioned message. For example, a message authentication code is generated from the aforementioned message and then a barcode is formed as a marker. If a security imprint is printed with such a marking, this makes it possible to check the authenticity of the security imprint, for example in the post office (US 5,953,426).
The applicant's JetMail® franking machine is equipped with a base and a removable meter. The latter includes a security module which, for example, generates a digital signature for a security imprint of the franking machine (US 6,041,704).
It is also known to cryptographically secure the data exchange between a franking machine and a remote data center when a credit value is reloaded. A security module can have a hardware accounting unit and a unit for securing the printing of the postage fee data (EP 789 333 A2). The hardware accounting unit was implemented with an ASIC user circuit and the other unit with an OTP processor (One Time Programmable). This means that the billing process cannot be manipulated by a program change and, in addition, any cryptographic algorithm can be stored in the read-only memory for the OTP processor to be called up. An internal OTP memory stores read-out-sensitive data (including cryptographic keys) that are required, for example, to reload a credit or to generate a cryptographic backup of a message from the franking machine. A known encryption algorithm, for example Data Encryption Standard (DES), can thus be used for the formation of MACs for messages of different types, a predetermined cryptographic key being agreed for each type. A security housing of the security module offers external protection against espionage of the cryptographic keys (DE 201 12 350 U1). Franking machines are usually only developed for a single purpose, namely to print postage indicia. Here, expensive cryptotechnology is used. If it were possible to open up further possible applications, using the approved signature algorithms without the risk of confusion with the postal franking, this would expand the functionality of the device.
In the US Pat. No. 6058384 with the title: Method for Removing Funds from a Postal Security Device, it has already been proposed to generate a signature for a reloading stamp (Refund Indicium), an invalid ZIP code being used, for example 00000-0000. This is to prevent a fraudulent user from maliciously using the signature for an ordinary postage indicium.
Another way of compiling the data used for processing with the cryptographic algorithm depending on the message type in a special way or by choosing the message format for a reloading stamp different from the message format of a conventional postage stamp, for example completely without ZIP, etc., is due to the very different provisions of national postal authorities or private mail carriers are not always feasible.
The invention is based on the object of developing a method and an arrangement for differently generating cryptographic backups of messages in a host device, the different generation being controlled as a function of a respectively set type of message.
The object is achieved with the features of the method according to claim 1 and with the features of the arrangement according to claim 5.
A signature is used to cryptographically secure a message, the signatures differing in the way they are generated when messages are used for different purposes. The cryptographic algorithms for generating signatures can be implemented separately or together in logic in accordance with hardware or program in the read-only memory of a postal security device PSD. Based on the consideration that the storage of different programs in the above-mentioned read-only memory, each program serving to execute a specific cryptographic algorithm, enables any combination of signature algorithms and hash algorithms for a message type, a logic is additionally connected to a postal security device. The logic, alone or in conjunction with programs in the read-only memory of the postal security device and possibly additionally with programs in the read-only memory of the host device, executes at least one specific algorithm from the large number of cryptographic algorithms, the execution being controlled as a function of a message type set in each case. On the output side, the cryptology has at least one output which is connected directly or indirectly to the input of a second logic circuit in the interior of the postal security device. The crypto algorithms can be implemented outside the PSD's in cryptology and / or within the PSD's. The inputs or outputs of logic circuits or parameters of hash functions can be switched by a logic circuit by means of change-over switches, the logic circuits using crypto algorithms of identical and different structure. A switch can be implemented in the PSD and / or outside the PSD and triggered by the PSD or host. The less the host application and the more the PSD application should determine the generation of a signature, the more suitable are variants in which the switch is implemented in the PSD. In the other case, if the host application should make the decision, the more suitable are variants in which the switch is implemented outside the PSD. This results in a multitude of variants of the structure or structure implemented in the interior of the cryptology and the PSD. the operational interconnection of the two so that signatures can be generated which are invalid for franking mail but are suitable or valid for other purposes. Other possible uses in the field of mail processing are special franking marks such as postage correction indicia, or military mail or embassy mail. In addition, there are non-postal applications in the area of ticketing and valuable documents, for which the same approved signature algorithms are now usefully used without the risk of confusion with postal franking. This allows further application possibilities to be developed, which extends the functionality of franking machines, for example.
Advantageous developments of the invention are characterized in the subclaims or are shown below together with the description of the preferred embodiment of the invention with reference to the figures. Show it:<dl id="dl0001"><dt>Figure 1,</dt><dd>simplified representation of the generation of a signature by means of a known postal security device (priort art),</dd><dt>Figure 2,</dt><dd>Host-controlled switchover of the crypto algorithms for generating a signature using the postal security device (variant 1),</dd><dt>Figure 3,</dt><dd>4, representation of the structures of a crypto algorithm,</dd><dt>Figure 5a,</dt><dd>second variant of a host-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device,</dd><dt>Figure 5b,</dt><dd>PSD-controlled switching of the crypto algorithms for generating a signature using the postal security device (variant 1),</dd><dt>Figure 6,</dt><dd>second variant of a PSD-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device,</dd><dt>Figure 7,</dt><dd>third variant of a PSD-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device,</dd><dt>Figure 8,</dt><dd>third variant of a host-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device,</dd><dt>Figure 9,</dt><dd>fourth variant of a host-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device,</dd><dt>Figure 10,</dt><dd>Host and PSD-controlled switching of the crypto algorithms for generating a signature using the postal security device,</dd><dt>Figure 11,</dt><dd>Block circuit of a host device.</dd></dl>
FIG. 1 shows a simplified illustration of the generation of a signature using a known postal security device (PSD). Via an input e of the PSD 10, a message m is applied to a first logic circuit 11, which applies a first crypto-algorithm to the message m. The output a of the first logic circuit 11 is present at the input of a second logic circuit 12, which applies a digital signature algorithm (DAS) to the output signal a in order to generate data for a signature. The logic circuits can include a software or hardware module that executes the corresponding algorithm in software or hardware. For example, the digital signature algorithm (DAS) known from US Pat. No. 5,231,668 or a comparable standard algorithm is implemented in software by the second logic circuit. A corresponding program that can be processed by a microprocessor (not shown) is implemented in the read-only memory (not shown) of the second logic circuit of the security module. In contrast to the known variant, the first crypto algorithm is now implemented in terms of hardware and externally of the PSD 10 by means of the first logic circuit. In a first variant, the first logic circuit is implemented in a switchable manner. In order to generate signatures for different purposes, an arrangement has been created that uses two different permitted hash functions in the same signature algorithm.
FIG. 2 shows a host-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device. In this first variant, the logic circuit 21 for the crypto-algorithm 1 and the logic circuit 22 for the crypto-algorithm 2 are connected on the input side and lead on the output side to contacts I and II of a changeover switch 24, the latter on the output side being connected to the input of the second logic circuit 12 which opens the DAS uses the output signal to generate data for a signature. The two logic circuits 21 and 22 and the changeover switch 24 form a host-controlled crypto logic 20 which has a control data input c and whose output d is connected to the information input i of the PSD 10.
The usable algorithms specified in the US Postal Service's IBI program are RSA (Rivest, Shamir, Adleman), DAS (Digital Signature Algorithm), and ECDSA (Elliptic Curve Digital Signature Algorithm), each with the SHA-1 (Secure Hash Algorithm ) can be limited.
Assuming that a signature key sk of a postal security device (PSD) is used for a message m for a first purpose, for example for calculating an ordinary free stamp (49 bytes), in order to calculate the signature for the message m as follows :<maths id="math0001" num="(1)"><math display="block"><mrow><mtext>sig = DSAsign (sk, SHA-1 (m))</mtext></mrow></math><img file="EP1432170A2_D0001.tif" /></maths>
The second message M is intended for a second purpose. In contrast to equation (1) used for a first purpose, the signature is calculated for a second purpose, for example for a reloading free stamp, as follows:<maths id="math0002" num="(2)"><math display="block"><mrow><mtext>SIG = DSAsign (sk, SHA-1 (SHA-1 (M))),</mtext></mrow></math><img file="EP1432170A2_D0002.tif" /></maths>
By using SHA-1 twice instead of using SHA-1 once, a signature calculated for a second purpose can be prevented from being output as applicable for a first purpose. A security assessment shows that in this way a fraudulent user by-product has an ordinary signature on the message:<maths id="math0003" num="(3)"><math display="block"><mrow><mtext>m '= SHA-1 (M).</mtext></mrow></math><img file="EP1432170A2_D0003.tif" /></maths> receives what is not helpful for reuse, because the data record of this message has a length of 160 bits = 20 bytes, while to "reuse" a signature a message should have a data record with a length of 49 bytes. In practice, knowing any 49-byte record is not sufficient for fraud. In order for the fraud to work, the fraudster should be able to select the data record for the most part.
FIG. 3 shows a combination of the same crypto-algorithms 221 and 222 within the logic circuit 22. It is provided that the latter differs from the logic circuit 21 in that it uses a different crypto-algorithm or in that it uses the same crypto-algorithm twice.
There are a variety of other possible combinations for forming a crypto-algorithm. FIG. 4 shows simple structures of such crypto algorithms, the logic circuit 22 differing from the logic circuit 21 by the additional application of a further crypto algorithm. It is known to form an HMAC, which is based on a known hash function SHA-1. In addition to the message m, an H-MAC also requires a key k as input. It is envisaged that the latter differs from the logic circuit 21 by the additional use of a different crypto algorithm or by the use of different keys in the same crypto algorithm. Two publicly known parameters could be agreed as the key, for example 1010 for ordinary franking and 0101 for reloading franking. The parameters must be publicly known, because the recipient of the postage stamp also needs the latter for checking. With this variant, the problem does not arise, which was described in the above-mentioned security considerations for reloading postage stamps, because a reloading postage stamp is formed with the same signing key, but with a different combination of signing and hash algorithms, than ordinary postage stamps. In addition, you can reload through an online transaction directly with the manufacturer infrastructure, in a similar way to reloading credit. To authenticate the corresponding message from the PSD, use a different signing key than that for ordinary franking. In this way, the resulting signatures can never be misused for franking purposes.
FIG. 5a shows a second variant of a host-controlled switchover of the crypto-algorithms for generating a signature by means of the postal security device. A conventional postal security device PSD 10 is interconnected with cryptology 20 and its functionality is expanded so that signatures can be formed for three different purposes. The usual PSD 10 again has two logic circuits 11 and 12, which can contain a software or hardware module. The cryptology 20 has a host-controlled input-side switch 24 for the message m. The contacts I, II and III of the changeover switch 24 are each present at the input e1, e2, e3 of one of the logic circuits 11, 22, 23, the logic circuits 22 and 23 being arranged in the cryptology 20. On the output side, the cryptology 20 has an interconnection of the outputs a2, a3 of the logic circuit 22 and 23 and a connection of the output d to the information input i of the PSD 10. The output a1 of the logic circuit 11 is also connected to the information input i of the PSD 10. The information input i of the PSD 10 is connected on the input side to the second logic circuit 12, which uses a further algorithm, for example a DAS, on the output signal in order to generate data for a signature.
FIG. 5b shows a PSD-controlled switchover of the crypto algorithms for generating a signature using the postal security device according to a first variant. The PSD has an internal logic circuit 11 for a first crypto-algorithm and a second logic circuit 12 to generate the data for a signature. The cryptology 20 has logic circuits for a second and third crypto-algorithm 22 and 23 and does not require a switch on the input side. For this purpose, a PSD-controlled input-side switch 14 for the message m is provided in the PSD 10. The contacts I, II and III of the switch 14 are in each case at the input e1, e2, e3 of one of the logic circuits 11, 22, 23, the logic circuits 22 and 23 being arranged in the cryptology 20 and associated inputs e2 and e3 being provided. On the output side, the crypto logic 20 has a connection d for connecting the outputs a2, a3 of the logic circuit 22 and 23 to the information input i of the PSD 10.
FIG. 6 shows a second variant of a PSD-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device. There is no switch on the input side for the message m, but the latter is located at the input e<sub>1</sub> a first logic circuit 21 for a first crypto-algorithm. Their exit a<sub>1</sub> is applied to the first contact I of a changeover switch 14 within the PSD 10. The exit a<sub>1</sub> is also located at the entrance e<sub>2</sub> a first logic circuit 11 inside the PSD 10. Its output a<sub>2</sub> lies on the second contact II of the switch 14 within the PSD 10. Both respective first logic circuits 21 and 11 can have the same crypto-algorithm and are run through in succession by the message when the contact II of the switch 14 is selected by the PSD via a control data input c. The exit a<sub>1</sub> the first logic circuit 21 is also at the input e<sub>3</sub> a third logic circuit 23 of the cryptology 20, ie externally from the PSD 10. Its output a<sub>3</sub> lies on the third contact III of the switch 14 within the PSD 10. In this second variant of a PSD-controlled switchover, the switchover between the first logic circuit 21 and the third logic circuit 23, both of which are arranged externally from the PSD 10, and the first logic circuit 11, which is arranged internally in the PSD 10, takes place immediately before passing through the second logic circuit 12 which is arranged internally in the PSD 10.
FIG. 7 shows a PSD-controlled changeover of the crypto algorithms for generating a signature by means of the postal security device according to variant 3. A first logic circuit 21 for a first crypto algorithm has an input e<sub>1</sub> for a message m and an exit a<sub>1</sub> on the one with an entrance e<sub>2</sub> for a second logic circuit 23 for a second crypto-algorithm, the output of which a<sub>2</sub> with an entrance e<sub>3</sub> for a third logic circuit 23 for a third crypto-algorithm, the output of which is a<sub>3</sub> is present at the information input i of the postal security device 10. The cryptology 20 is connected on the output side to the postal security device 10, the output a<sub>1</sub> the first logic circuit 21 at a first contact I, the output a<sub>2</sub> the second logic circuit 22 at a second contact II and the output a<sub>3</sub> the further logic circuit 23 is connected to a third contact III of a PSD-controlled switch 14 within the postal security device 10. The switch 14 is coupled on the output side to a second logic circuit 12 within the postal security device 10, which generates the signature.
FIG. 8 shows a third variant of a host-controlled switchover of the crypto-algorithms for generating a signature by means of the postal security device. A cryptology 20 arranged externally by the postal security device 10 is connected at least with its output d to an information input i of the postal security device 10. The postal security device 10 internally has a logic circuit 12 which applies a digital signature algorithm to the output signal provided by the output d in order to generate data for a signature. The cryptology 20 has a number of logic circuits 21, 23 and a changeover switch 26 which has a control data input c<sub>2</sub> has, for control by a - not shown - host. The switch 26 is connected to the further logic circuit 23 and switches over a key k1, k2 for the further crypto-algorithm. A first logic circuit 21 for a first crypto-algorithm has an input e<sub>1</sub> for a message m and an exit a<sub>1</sub> on the one with an entrance e<sub>3</sub> is connected for a further logic circuit 23 for a further crypto-algorithm, its output a<sub>3</sub> is present at the information input i of the second logic circuit 12, which generates the signature.
FIG. 9 shows a fourth variant of a host-controlled switchover of the crypto-algorithms for generating a signature by means of the postal security device. In addition to the circuit of the third variant, which has a first switch 26 that switches a key k1, k2 for the further crypto-algorithm of the further logic circuit 23, a second switch 24 is provided in the host-controlled cryptology 20, contacts I and II of the Switch 24 with the outputs a<sub>1</sub> and a<sub>3</sub> the first and third logic circuits 21 and 23 are connected. The switch 24 forms the output d on the output side, which is connected to the information input i of the postal security device 10. It is provided that the changeover switches 24 and 26 have a control data input c<sub>1</sub>, c<sub>2</sub> controlled by a host (not shown).
FIG. 10 shows a host and PSD-controlled switchover of the crypto algorithms for generating a signature by means of the postal security device. The postal security device 10 has at least one logic circuit 11 and the cryptology 20 has at least one logic circuit 23. The crypto logic 20 has a first host-controlled changeover switch 26, which switches over a key k1, k2 for the further crypto-algorithm of the further logic circuit 23. To switch between the outputs a<sub>1</sub> or a<sub>3</sub> the first and third logic circuits 11 and 23, a second PSD-controlled switch 14 is provided in the postal security device 10, contacts I and II of the switch 14 with the outputs a<sub>1</sub> or a<sub>3</sub> the first and third logic circuits 11 and 23 are connected.
FIG. 11 shows a block circuit of a host device. The postal security device 10 and the cryptology 20 are operatively connected by means of interfaces i, d via an internal bus 37. A hardware and interface circuit 13 of the postal security device 10 for the interface i can be implemented, for example, with an application-specific circuit (ASIC). The latter is connected to a data processing unit 16 for carrying out the aforementioned cryptographic functions and to non-volatile memories 15 for carrying out further functions. The data processing unit 16 has a microprocessor (μP) with a real time clock (RTC), FLASH memory and working memory (SRAM). The safety device 10 has internal monitoring units 17 and 19 and an internal BUS 19. The host device 1 also has a non-volatile memory 35, microprocessor 36, read-only memory 33, working memory 34 and a modem 32, keyboard 39 and display controller 38 with a display unit (not shown). The host device 1 can be connected to a remote data center 5 via a communication link 2. The data center 5 has, for example, a modem 52, a server 53 and a database 54. The host device 1 can be connected — in a manner not shown — to a further device, for example a printing device, via a communication link or interface.
The invention is not limited to the present or those embodiments in which at least two different hash functions permitted by an authority are used in the same signing algorithm. Alternatively, the same hash function can be used with two different approved signature algorithms. The cryptology 20 is then also connected to the PSD 10. The various approved signature algorithms and their switching are carried out in software. The crypto logic 20 contains only one logic circuit 21 for a crypto algorithm, for example a known hash function.
A large number of alternative combinations within the scope of the claims are conceivable, which are designed differently. Obviously, further other embodiments of the invention can be developed or used, starting from the same basic idea of the invention, which are encompassed by the appended claims.
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2002108042A1 | Cites | United States of America | Search report |
| US5742684A | Cites | United States of America | Search report |
9 members in 3 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 10260406 | Germany | A | |
| 10260406 | Germany | – | |
| 10260406 | – | – | – |
| DE2002160406 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| US2004117314A1 | United States of America | A1 | |
| EP1432170A2This record | European Patent Office (EPO) | A2 | |
| DE10260406A1 | Germany | A1 | |
| EP1432170A3 | European Patent Office (EPO) | A3 | |
| DE10260406B4 | Germany | B4 | |
| US2008010210A1 | United States of America | A1 | |
| US7610247B2 | United States of America | B2 | |
| US8099367B2 | United States of America | B2 | |
| EP1432170B1 | European Patent Office (EPO) | B1 |
75 legal events, as 9 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | NL | |
| Ep patent has lapsedLapsedEUG | EUG | SE | |
| Patent ceasedCeasedPL | PL | CH | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Change of applicant/patenteeR081 | R081 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Translation of granted ep patentGrantedTRGR | TRGR | SE | |
| Translation files for an european patent granted for nl, confirming art. 52 par. 1 or 6 of the patents act 1995GrantedT3 | T3 | NL | |
| Party data changed (patent owner data changed or rights of a patent transferred)RAP2 | RAP2 | EP | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Reference to at number (ep patent enters austrian national phase)REF | REF | AT | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04L0009320000R079 | R079 | DE | |
| Designation fees paidAKX | AKX | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1432170
- Publication, DOCDB
- 1432170
- Publication, EPODOC
- EP1432170
- Application
- 3025254
- Application, DOCDB
- 03025254
- Application, EPODOC
- EP20030025254
Titles3
- German
- Verfahren und Anordnung zur unterschiedlichen Erzeugung kryptographischer Sicherungen von Mitteilungen in einem Hostgerät
- English
- Method and apparatus for generating different cryptographic secure procedures concerning messages in a host device
- French
- Procédé et dispositif de génération de sécurités cryptographiques différentes pour des messages dans un dispositif hôte
Classification
- CPC, 3
- H04L9/3252
- G06Q50/06
- H04L2209/12
- IPC, 2
- G06Q50 06
- H04L9 32
Designated states2
- Contracting states, 1
- Türkiye
- Extension states, 1
- North Macedonia