Method for server controlled security management of yieldable services and arrangement for providing data according to a security management for a franking system
Abstract
The method involves transmitting data record between a franking system and a data center (3) over a communication interface when a desired service is requested. The record has service and security data, and is stored in a post security device of the franking system. A logical connection to a franking machine via a server of the center and the reception of relative operation that has been issued by the machine are cutback. An independent claim is also included for a system for allocation of data according to security management for a franking system.

Term
Term ended
Projected expiry passed 23 February 2025, 1.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
15 claims: 15 independent, 0 dependent
- 1Method for a server-controlled security management of deliverable services, marked by the steps:A) Call acceptance for communication connection between franking machine (2) or -system (1) and data center (3) with automatic dial-in by the postage meter machine (2) or system (1) into the data center (3) and receiving the request for a desired service service by means of a server (30) of the data center (3),B) Determining the security data and security category associated with this service in the database management system (32) of the data center (3), controlling a selector (341) of the server (30) according to the respective security category and generating a data record with service data and security data by the server (30),C) Selection of the relevant logical channel controlled by the selector (341) of the server (30) of the data center and transmitting the data set according to the desired service via the already established communication connection between postage meter (2) or -system (1) and data center (3),D) Dismantling the logical connection to the franking machine by a server (30) of the data center (3) as soon as the service is completed and receipt of a corresponding acknowledgment issued by the postage meter machine (2) or system (1) andE) waiting for the receipt of another service request by the server (30) or the termination of the communication connection, the termination by the franking machine (2) or system (1) takes place. Verfahren für ein servergesteuertes Sicherheitsmanagement von erbringbaren Dienstleistungen, gekennzeichnet durch die Schritte: A) Rufannahme bei Kommunikationsverbindung zwischen Frankiermaschine (2) bzw. -system (1) und Datenzentrum (3) mit automatischer Einwahl durch die Frankiermaschine (2) bzw. -system (1) in das Datenzentrum (3) und Empfangen der Anforderung einer gewünschten Dienstleistung Dienstleistung mittels eines Servers (30) des Datenzentrums (3),B) Ermitteln der dieser Dienstleistung zugeordneten Sicherheitsdaten und Sicherheitskategorie im Datenbankmanagementsystem (32) des Datenzentrums (3), Steuerung eines Selectors (341) des Servers (30) entsprechend der jeweiligen Sicherheitskategorie und Generierung eines Datensatzes mit Dienstleistungsdaten und Sicherheitsdaten durch den Server (30),C) Auswahl des betreffenden logischen Kanals gesteuert durch den Selector (341) des Servers (30) des Datenzentrums und Übermitteln des Datensatzes entsprechend der gewünschten Dienstleistung über die bereits aufgebaute Kommunikationsverbindung zwischen Frankiermaschine (2) bzw. -system (1) und Datenzentrum (3),D) Abbau der logischen Verbindung zur Frankiermaschine durch einen Server (30) des Datenzentrums (3), sobald die Dienstleistung beendet ist und Empfang einer entsprechenden von der Frankiermaschine (2) bzw. -system (1) ausgegebenen Bestätigung undE) Warten auf den Empfang einer weiteren Dienstleistungsanforderung mittels des Servers (30) oder auf die Beendigung der Kommunikationsverbindung, wobei die Beendigung durch die Frankiermaschine (2) bzw. -system (1) erfolgt.
- 2Method according to claim 1, characterized in that in connection with a remote service for a franking system (1) data is exchanged and remotely transmitted from or to the data center (3), which can optionally be addressed by specifying a security category, which storage location for a desired record inside or outside the PSD (23) of the franking system (1) should be used. Verfahren, nach Anspruch 1, dadurch gekennzeichnet, dass in Verbindung mit einer Ferndienstleistung für ein Frankiersystem (1) Daten ausgetauscht und vom oder zum Datenzentrum (3) fernübertragen werden, wobei durch Angabe einer Sicherheitskategorie wahlweise adressiert werden kann, welcher Speicherort für einen gewünschten Datensatz innerhalb oder außerhalb des PSD's (23) des Frankiersystems (1) verwendet werden soll.
- 3Method according to claim 1, characterized in that in connection with a remote service for a franking system (1), data is exchanged and transmitted remotely from or to the data center (3), whereby by specifying a security category it can optionally be addressed in which way the transmitted data is saved during the data exchange. Verfahren, nach Anspruch 1, dadurch gekennzeichnet, dass in Verbindung mit einer Ferndienstleistung für ein Frankiersystem (1) Daten ausgetauscht und vom oder zum Datenzentrum (3) fernübertragen werden, wobei durch Angabe einer Sicherheitskategorie wahlweise adressiert werden kann, auf welche Weise die übertragenen Daten beim Datenaustausch gesichert werden.
- 4Method according to claim 1, characterized in that in connection with a remote service for a franking system (1), data is exchanged and transmitted remotely from or to the data center (3), whereby by specifying a security category it can optionally be addressed which elements of the franking system are influenced by the transmitted data. Verfahren, nach Anspruch 1, dadurch gekennzeichnet, dass in Verbindung mit einer Ferndienstleistung für ein Frankiersystem (1) Daten ausgetauscht und vom oder zum Datenzentrum (3) fernübertragen werden, wobei durch Angabe einer Sicherheitskategorie wahlweise adressiert werden kann, welche Elemente des Frankiersystems durch die übertragenen Daten beeinflusst werden.
- 5Anordnung zur Bereitstellung von Daten nach einem Sicherheitsmanagement für ein Frankiersystem (1), wobei ein entferntes Datenzentrum (3) die vom Frankiersystem (1) angeforderten Datensätze bereitstellt, welche Anwendungsdaten (AD) und Daten (SD) zu Sicherheitsinformationen enthalten, dadurch gekennzeichnet, dass das Datenzentrum (3) einen Server (30) umfaßt, der mindestens mit einem Server-Kommunikationsmittel (31) und mit einem Datenbankmanagementsystem (32) in betriebsmäßiger Verbindung steht, dass die angeforderten Datensätze Daten (SC) für eine Sicherheitskategorie enthalten, wobei letztere mindestens Informationen zur Sicherheitsmaßnahme für einen Datenaustausch zwischen dem Frankiersystem und Datenzentrum (3) und/oder zum Ort der Speicherung im Frankiersystem (1) umfaßt, die vom Datenbankmanagementsystem (32) des Datenzentrums (3) gemäß einer hinterlegten Sicherheitspolitik erfasst, verarbeitet, übertragen und bereitgestellt werden, dass das Frankiersystem (1) einen Mikroprozessor (242) aufweist, der mindestens mit einem postalischen Sicherheitsgerät (23) einem ersten nichtflüchtigen Speicher (241) und einem Kommunikationsmittel (21) zum Empfang der angeforderten Datensätze verbunden ist, wobei der Mikroprozessor programmiert ist, die Daten (SC) für eine Sicherheitskategorie auszuwerten, um einen entsprechenden logischen Kanal zu bilden und den Ort der Speicherung der Anwendungsdaten (AD) im Frankiersystem (1) festzustellen. Arrangement for providing data for a security management system for a franking system (1), wherein a remote data center (3) provides the data records requested by the franking system (1), which contain application data (AD) and data (SD) for security information, characterized in that the data center (3) comprises a server (30), which is in operative connection with at least one server communication means (31) and with a database management system (32), that the requested records contain data (SC) for a security category, the latter comprising at least information on the security measure for a data exchange between the franking system and the data center (3) and / or the location of the storage in the franking system (1), recorded by the database management system (32) of the data center (3) in accordance with a security policy, processed be transferred and provided, the franking system (1) has a microprocessor (242), at least one postal security device (23) is connected to a first non-volatile memory (241) and a communication means (21) for receiving the requested data records, the microprocessor being programmed, evaluate the data (SC) for a safety category, to form a corresponding logical channel and to determine the location of the storage of the application data (AD) in the franking system (1).
- 6Anordnung, nach Anspruch 5, dadurch gekennzeichnet, dass der der Mikroprozessor zur Speicherung der Anwendungsdaten (AD) programmiert ist und der erste nichtflüchtige Speicher (241) oder ein zweiter nichtflüchtiger Speicher (232) zur Speicherung der Anwendungsdaten (AD) ausgebildet ist, wobei nur der zweite nichtflüchtige Speicher (232) Bestandteil des postalischen Sicherheitsgeräts (23) ist. Arrangement according to Claim 5, characterized in that the microprocessor is programmed to store the application data (AD) and the first nonvolatile memory (241) or a second nonvolatile memory (232) is designed to store the application data (AD), wherein only the second nonvolatile memory (232) is part of the postal Safety device (23) is.
- 7Anordnung, nach den Ansprüchen 5 bis 7, dadurch gekennzeichnet, dass ein dritter nichtflüchtiger Speicher extern der Frankiermaschine in einem anderen mit der Frankiermaschine verbundenen Postgerät angeordnet und zur Speicherung der Anwendungsdaten (AD) ausgebildet ist. Arrangement according to claims 5 to 7, characterized in that a third nonvolatile memory is arranged externally of the postage meter machine in another mailing device connected to the postage meter machine and designed to store the application data (AD).
- 8Anordnung, nach Anspruch 5, dadurch gekennzeichnet, dass eine Steuereinheit (34) des Servers (30) mit einem Selector (341) und mit einem Mikroprozessor (342) ausgestattet ist, der mit einem Serversicherheitsmodul (33), dem Selector (341) und dem Server-Kommunikationsmittel (31) in betriebsmäßiger Verbindung steht, wobei die Liste in einer Datenbank des Datenbankmanagementsystems (32) gespeichert in der Form vorliegt, dass jedem Datensatz eine Sicherheitskategorie zugeordnet ist, wobei die Sicherheitspolitik für jede Sicherheitskategorie definiert, ob der betreffende Datensatz zum Frankiersystems (1) übertragen und im postalischen Sicherheitsgerät (23) des Frankiersystems (1) gespeichert wird oder zum Frankiersystem (1) übertragen und dort aber außerhalb des postalischen Sicherheitsgeräts (23) gespeichert wird. Arrangement according to Claim 5, characterized in that a control unit (34) of the server (30) is equipped with a selector (341) and with a microprocessor (342), with a server security module (33), the selector (341) and the server communication means (31) is in operative connection, the list being stored in a database of the database management system (32) in the form that each record is assigned a security category, where the security policy defines for each security category, Whether the relevant data record is transmitted to the franking system (1) and stored in the postal security device (23) of the franking system (1) or transferred to the franking system (1) and stored there outside the postal security device (23).
- 9Anordnung, nach Anspruch 8, dadurch gekennzeichnet, dass das Server-Kommunikationsmittel (31) Bestandteil eines Kommunikations-Servers ist, der eine Vielzahl an separaten Anschlüssen an ein Netz (12) ermöglicht und dass zwischen dem Datenzentrum (3) und dem Frankiersystem (1) das Server-Kommunikationsmittel (31) und ein weiteres Übertragungsmittel (21) angeordnet sind, über welche ein mit betreffender Sicherheitskategorie ausgestatteter Datensatz bei Bedarf übermittelbar ist. Arrangement according to claim 8, characterized in that the server communication means (31) is part of a communication server, which allows a plurality of separate connections to a network (12) and that between the data center (3) and the franking system (1) the server communication means (31) and a further transmission means (21) are arranged, via which a data set equipped with the relevant security category can be transmitted if necessary.
- 10Anordnung, nach Anspruch 9, dadurch gekennzeichnet, dass das Server-Kommunikationsmittel (31) und das Übertragungsmittel (21) des Frankiersystems (1) ein drahtlos arbeitendes Übertragungsmittel ist. Arrangement according to claim 9, characterized in that the server communication means (31) and the transmission means (21) of the franking system (1) is a wireless transmission means.
- 11Anordnung, nach Anspruch 9, dadurch gekennzeichnet, dass das Server-Kommunikationsmittel (31) und das Übertragungsmittel (21) des Frankiersystems (1) ein Modem ist. Arrangement according to claim 9, characterized in that the server communication means (31) and the transmission means (21) of the franking system (1) is a modem.
- 12Anordnung, nach Anspruch 8, dadurch gekennzeichnet, dass das Datenbankmanagementsystem (32) in einem separaten Server realisiert ist. Arrangement according to claim 8, characterized in that the database management system (32) is implemented in a separate server.
- 13Anordnung, nach Anspruch 8, dadurch gekennzeichnet, dass das Datenbankmanagementsystem (32) innerhalb des bestehenden Servers (30) realisiert ist. Arrangement according to claim 8, characterized in that the database management system (32) is implemented within the existing server (30).
- 14Anordnung, nach Anspruch 8, dadurch gekennzeichnet, dass der Selector (341) hardware- und/oder softwaremäßig realisiert ist. Arrangement according to claim 8, characterized in that the selector (341) is hardware and / or software implemented.
- 15Anordnung, nach Anspruch 14, dadurch gekennzeichnet, dass der Selector (341) als Bestandteil des Mikroprozessors (342) ausgeführt ist. Arrangement according to claim 14, characterized in that the selector (341) is embodied as part of the microprocessor (342).
Independent claims15
53 paragraphs in 1 section, as filed
The invention relates to a method for a server-controlled security management of deliverable services according to the preamble of claim 1 and an arrangement for providing data for a security management for a franking system according to the preamble of claim 5. The invention applies to franking machines and to other mail processing devices and their peripherals used, which use a service of a remote data center.
Applicant's JetMail® franking machine is equipped with a base and a detachable meter. The latter is operatively connected to a built-in base housing static balance and is among others also used for postage calculation. No special security measures are taken in connection with a service of reloading a postage rate table, although the correctness of the postage calculation is based on the aforementioned table and although the meter contains a security module, the security module is equipped with a cryptographic unit in addition to a bill unit. The latter only serves to secure the postage fee data to be printed. The meter also includes a controller for controlling printing and controlling peripheral components of the postage meter. The base includes a mail transport device and an ink jet printing device for printing the postage stamp on the mail. Replacing the printhead is unnecessary because the ink tank is separated from the printhead and can be replaced. Also, no special security measures have to be taken for the printhead or for protection of the drive and data signals when printing with a special piezo inkjet printhead a security imprint with a mark permitting verification of the authenticity of the security imprint (US 6,041,704). In addition to the service of reloading a postage rate table and a known service of a teleportation data center, such as the reloading (US 5699415 or EP 689170 A2) of a credit, from which the prepaid postage value is debited in each case prior to printing, a further service may exist in the base tracking. To prevent possible falsification by manipulation by means of the printing unit, ie in particular, if the base with the printing unit is detachable from the meter, the postal authority is interested in information about the location of the printing unit when the base is operated again by one meter. In base tracking, only the printing unit is released, which can be identified by an identification code from the data center (EP 1154381 A1).
In franking machines of the Applicant - for example in the mymail® and ultimail® - bubble jet printing heads are also used in the printing module. The ink tank and bubble-jet printhead are integrated into a replaceable ink cartridge, as it is already known from the ½ inch ink cartridges from Hewlet Packard (HP). The contacting of the electrical contacts of the print head of the replaceable ink cartridge can be done via a connector of a commercial Pen Driver Board's company HP. Both the postal authority and the customer have an increased interest in high evaluation security of the mark printed on the mail piece. Another service of the data center can therefore consist of piracy protection. Via the connector, additional pirate protection enabling data, for example, a code of the printhead can be queried and sent via modem to the data center. The data center then performs a code comparison with a reference code stored in a database and transmits a message to the postage meter machine about the result of the check (EP 1103924 A2). The security module participates in such services in different ways, but at least when security-relevant data has to be exchanged with a remote data center via an unsecured data transmission path during the communication. On the one hand, the meter housing or the housing of a franking machine a first protection against manipulation in fake intention. Enclosing the safety module with a special housing provides additional mechanical protection. Such an encapsulated security module corresponds to the current postal requirements and is also referred to below as a post-security device (PSD). The credit recharge in some countries requires security measures that only one PSD can deliver. The applicant's franking machines are connected to a teleportation data center in a manner known per se for telephone credit recharge and can be expanded with other devices to form a franking system.
In addition to the positive Fernwertvorgabe in the above-mentioned credit recharge and a negative Fernwertvorgabe in the repayment of the remaining credit balance of the customer is known (EP 717379 B1 or US 6587843 B1).
From US Pat. No. 5,233,657 a loading of data that does not serve a credit debit is also known prior to putting a postage meter into operation.
EP 1037172 A2 discloses the provision and transmission of a machine and customer-specific data record from a data center to a franking device. The data record includes data that is valid at least temporarily and locally at the franking location and that is stored in the data center in a database that is assigned to a number code in a retrievable manner. The customer who has purchased a pre-initialized franking device via a dealer distribution is thus to be put in the position to take the franking device completely into operation without a customer service or service technician must be called and without a visit to the post office. The data stored in the data center are all subject to the same security measure. Regardless of this, the graphic data are stored in the postage meter machine without further security measures in a memory of the motherboard of the franking machine. The graphics data may relate to a stamp image, for example the city stamp.
For the exchange of advertising clichés, a telephone communication is already proposed in US 4,831,554.
In US 4,933,849 a date-dependent change of stamp images (with city stamp and with value stamp) is already communicated, which were loaded at an earlier date by modem.
According to EP 780 803 A2, after an initialization, the possibility is provided for news or carrier-specific advertising to be provided by a data center if there is an order in the data center for this purpose. The customer must have previously concluded a contract with the service provider or operator of the data center.
From EP 1067482 it is already known to assign different levels of security to the elements of a printed image to be printed. These different levels of security correspond to the differently assignable privilege to change each of the elements. To authorize and reload the elements for changing the printed image chip cards are used, which make the elements valid according to a special hierarchy.
Another service of a mail carrier is associated with a statistical collection of franked mail according to statistical classes (EP 892368 A2). For storing data on the use of a terminal, solutions are also known from EP 992947 A2 and EP 101383 A2, according to which the entries are stored according to statistical classes (Class of Mail) until the remote data center accesses them in order to query the user profile or to investigate.
It is also known that a remote data center via modem can exchange security data with a postage meter system that includes a post security device (PSD). Such postage meter systems of the applicant are known, for example, under the brand name jetmail® and ultimail®.
The object of the invention is to develop an arrangement and a method which ensures that both the franking system and the postal security device can store and process security data.
The object is achieved with the features of the method according to claim 1 and the features of the arrangement according to claim 5.
The invention is based on the assumption that a data center operated by the manufacturer in an authorized manner is the safest against manipulation and thus also provides security for remote services which a franking system can use. For the future, it can not be ruled out that in addition to a franking machine, further or other devices of a franking system will also use services of a remote data center. Now, when talking about security information that is to be stored and processed in the form of datasets, it should be included and taken into account that the security requirements for each country's telecoms services are very different or even absent.
It is suggested that a remote data center have a list of records containing security information and an associated security category. The latter concerns information that is collected, processed, transmitted and provided by the data center's security management system in accordance with a security policy, at least for security measures and / or the location of the storage system in the franking system. Both information is typically stored in a database of a database management system (DBMS). The security policy defines for each security category:<ul id="ul0001" list-style="none" compact="compact"><li>a) that a storage location for a desired data record is used inside or outside the PSD of the franking system,</li><li>b) the way in which the transmitted data is saved during data exchange, and / or</li><li>c) which elements of the franking system are influenced by the transmitted data.</li></ul>
The data record can be transmitted as a result of the request for a service from the remote data center to the franking system and contains in its header the information about the associated security policy. A desired data set equipped with a head section associated with the respective security category can be transmitted by the data center from the franking system by means of transmission means, for example wirelessly or via modem, and stored there internally or externally by the PSD in the PSD.
A method for server-controlled security management of deliverable services is characterized by the following steps:<ul id="ul0002" list-style="none" compact="compact"><li>A) call acceptance in the case of a communication connection between the franking machine or data center and the automatic dial-in by the franking machine or system into the data center and reception of the request for a desired service by means of a server of the data center,</li><li>B) determining the security data and security category associated with this service in the database management system of the data center, controlling a selector of the server according to the respective security category and generating a data record with service data and security data by the server,</li><li>C) selection of the relevant logical channel controlled by the selector of the server of the data center and transmitting the record according to the desired service on the already established communication link between postage meter or system and data center,</li><li>D) removal of the logical connection to the franking machine by the server of the data center as soon as the service has ended and receipt of a corresponding acknowledgment issued by the franking machine or system</li><li>E) Waiting for the receipt of another service request by means of the server or on the termination of the communication connection, wherein the termination by the postage meter or -system takes place.</li></ul>
As a logical channel, either an unsecured channel or a secure channel is automatically formed to communicate a selected data set to the postage meter or system.
The relevant data record can also be called or read again during operation of the franking system. By specifying a security category, it can be addressed whether the desired data record from the franking system is read from inside or outside the PSD.
The arrangement for providing data for security management for a mailing system assumes that a remote data center provides the data records requested by the mailing system containing application data and security information. According to the invention, it is provided that the data center includes a server, which is in operative connection with at least one server communication means and with a database management system, that the requested records contain data for a security category, the latter comprising at least information on the security measure for an exchange of data between the franking system and the data center and / or the location of the storage in the franking system, recorded by the database management system of the data center according to a security policy, processed be transferred and provided, that the franking system has a microprocessor, at least with a postal security device, is connected to a first nonvolatile memory and to a communication means for receiving the requested data sets, the microprocessor being programmed, evaluate the data for a safety category, to form a corresponding logical channel and to determine the location of the storage of the application data in the franking system.
It is further contemplated that the microprocessor is programmed to store the application data and the first non-volatile memory or a second non-volatile memory for storing the application data is formed, wherein only the second non-volatile memory is part of the postal security device (PSD). In addition, a third non-volatile memory may be located externally of the postage meter machine in another mailing machine connected to the postage meter, which is designed to store the application data.
Advantageous developments of the invention are characterized in the subclaims or are presented in more detail below together with the description of the preferred embodiment of the invention with reference to FIGS. Show it:<dl id="dl0001"><dt>FIG. 1,</dt><dd>Block diagram with components of a known franking system,</dd><dt>FIG. 2,</dt><dd>Block diagram for an arrangement for providing data for a security management for a franking system,</dd><dt>FIG. 3,</dt><dd>Franking imprint according to DPAG requirements,</dd><dt>FIG. 4,</dt><dd>Flowchart for server-controlled security management,</dd><dt>FIG. 5,</dt><dd>Detail of the block diagram of the server control unit.</dd></dl>
FIG. 1 shows a block diagram with components of a known franking system 1, comprising a franking machine 2, to which a storage box 4 is connected downstream of the downstream post and an automatic supply station 7 is connected upstream. In the case of the Jetmail® type of franking system, a stack 6 is fed on edge-mounted mail items. The storage box 4 is a stack 5 can be removed to lying mailpieces. To a first and second interface of the franking machine 2, the automatic feed station 7 and a personal computer 9 are electrically connected via cables 71 and 91. The franking machine 2 can be communicatively connected to a remote teleportation data center 8 for the purpose of credit recharging and to a remote service center 11. The franking machine 2 has an internal static balance 22 and is equipped with means for postage calculation. From the remote service center 11, a current postage fee table to the franking machine 2 or are transmitted to the franking system 1. The franking system may optionally have a - not shown - dynamic balance, which can be arranged between the automatic feed station 7 and the franking machine 2. Another known franking system of the type ultimail® corresponds in principle likewise to the block diagram shown in FIG. 1, with the difference that the stack 6 is fed to horizontal mail pieces of the automatic feed station 7 and no dynamic scale can be retrofitted.
While according to the known solution (Figure 1), the selected data center can provide only one service or only a minimum number of services without security feature, with a data center according to the invention, a number of services with security feature available. Another advantage is the avoidance of multiple calls at different data centers with different phone numbers.
FIG. 2 shows a block diagram of an arrangement for providing data in accordance with a security management for a franking system. In addition to the assemblies of a remote data center 3, the assemblies of a franking system 1 are shown, which has at least one franking machine 2 and optionally a static balance 22. Also, if necessary further - not shown - mail processing stations connected, for which also services on the franking machine 2 can be provided. The static balance 22 is preferably an optional component of the franking machine 2. The franking machine 2 comprises a postal meter 20 which has at least one communication means 21, a mainboard 24 and a postal security device (PSD) 23. The motherboard 24 is provided with a first nonvolatile memory 241 and a microprocessor 242 in operative communication with the PSD 23, the memory 241 and the communication means 21. The communication means 21 is, for example, a modem which can be communicated via a telephone network 12 to a modem 31 of the data center 3 in terms of communication. However, this is intended to mean other means of communication, such as wireless transmitter / receiver devices, mobile devices, Bluetooth, WAN, LAN and others Communication devices and other networks, such as the Internet, Ethernet and others not be excluded. Rather, a variety of communication means and networks for data transmission come into consideration. The PSD 23 is - not shown - connected via an interface on the motherboard 24 and contains, inter alia a second non-volatile storage 232 for reservation data and security-related data for secure communication with the remote data center. Further details on the PSD can be found in the publications EP 789333 B1, EP 1035513 A1, EP 1035516 A1, EP 1035517 A1, EP 1035518 A1, EP 1063619 A1, EP 1069492 A1 and EP 1278164 A1. The data center 3 comprises a server 30 which is in operative connection with at least the one server communication means 31 and with a database management system (DBMS) 32. The server communication means 31 is in a - not shown - variant part of a communication server that allows a variety of separate connections to the network 12. Also, the database management system 32 may be implemented in a separate server or within the existing server 30. A control unit 34 of the server 30 is provided with a selector 341 and a microprocessor 342 in operative communication with the server security module (SSM) 33, the selector 341, and the at least one server communication means 31. The selector 341 is hardware and / or software implemented. The plurality of separate connections of the communication server to the network 12 allows the connection of several franking machines 2 or Franking systems 1 with the data center 3 to a security management system 10th
Data center 3 has a list of records containing security information and related security policy information. Both information is typically stored in a database of a database management system (DBMS) 32. Each record containing the security information is assigned a security category, for example a number on the scale 1 to 10. By specifying the security category, it can optionally be addressed whether the desired data set is exchanged with the franking system 1 from inside or outside the PSD 23, in which way the transmitted data is saved during the data exchange, or which elements of the franking system influence the transmitted data. The security policy defines, for example, which elements of the franking imprint are influenced by the transmitted data.
It is provided that the desired data record is stored in a non-volatile memory of a franking machine of the franking system arranged inside or outside the PSD. In connection with a remote service, it may be necessary for data to be read from the franking system 1 and remotely transmitted to the data center 3. So reads the data center 3, the security data from the franking system 1, it can also be addressed by specifying a security category, whether the desired record from the franking system 1 is read from within or outside of the PSD 23. The control unit 34 of the data center 3 ensures that records are communicated, stored and processed according to their security category. The control unit uses selector 341 for this purpose. The latter offers the possibility to choose one of two logical communication channels to address a memory of the franking system inside or outside the PSD. Each logical communication channel is protected by individual security mechanisms and parameters applied by a component of the control unit 34. This component of the control unit 34 is also referred to as server security module (SSM) 33. The security category of a data record is also taken into account for its control. The record contains in its header at least the information on the associated security policy. In addition to the addressing in the franking system, the control unit can also use this information for the associated security policy to select a suitable security mechanism for protection during the communication and / or during the subsequent storage. This will be shown below with some examples.
FIG. 3 shows a franking imprint according to the Frankit requirements of Deutsche Post AG. The franking imprint has on the left a one-dimensional bar code (1 D barcode) 15 for an identcode, which will be explained below. In addition, the franking imprint in the value imprint has a two-dimensional barcode (2D barcode) 17 for verifying the proper payment of the mailpiece transportation fee.
FIG. 4 shows a flowchart for a server-controlled security management. The data center 3 waits in step A to receive a service request. For processing a remote service (remote service) dials the franking machine in data center and requests the desired remote service. After receiving the service request, the data center in step B determines the security features to be selected in the security policy of this remote service. In step C, a selection of the logical channel and a record transmission from the data center 3 to the franking machine 2 or to the franking system 1. In this case, the logical channel is selected to the memory I of the mainboard or to the memory II of the PSD. The data record transmission takes place via the already established modem connection from the data center 3 to the franking machine 2 or to the franking system 1. In step D, the end of the requested service is determined. As soon as the remote service is terminated, the server removes the logical connection to the franking machine again and gives the franking machine a corresponding confirmation. In step E it is determined whether the communication link has been terminated by the postage meter. If that is the case, then the point e is reached. Otherwise, it branches back to a starting point a before the first step A, to receive another service request.
Examples of security categories are shown in the following table: <tables id="tabl0001" num="0001"><table frame="all"><tgroup cols="6" colsep="1" rowsep="1"><colspec colnum="1" colname="col1" colwidth="26.25mm" /><colspec colnum="2" colname="col2" colwidth="26.25mm" /><colspec colnum="3" colname="col3" colwidth="26.25mm" /><colspec colnum="4" colname="col4" colwidth="26.25mm" /><colspec colnum="5" colname="col5" colwidth="26.25mm" /><colspec colnum="6" colname="col6" colwidth="26.25mm" /><thead valign="top"><row><entry namest="col1" nameend="col1" align="right"><b>safety category</b></entry><entry namest="col2" nameend="col2" align="center"><b>protection target</b></entry><entry namest="col3" nameend="col3" align="center"><b>Logical channel</b></entry><entry namest="col4" nameend="col4" align="center"><b>Memory place</b></entry><entry namest="col5" nameend="col5" align="center"><b>Components of the franking system</b></entry><entry namest="col6" nameend="col6" align="center"><b>Place in the impression</b></entry></row></thead><tbody valign="top"><row><entry namest="col1" nameend="col1" align="right">identcodes</entry><entry namest="col2" nameend="col2" align="center">Uniqueness / uniqueness</entry><entry namest="col3" nameend="col3" align="center">Plain Session</entry><entry namest="col4" nameend="col4" align="center">Motherboard NVM</entry><entry namest="col5" nameend="col5" align="center">printer control</entry><entry namest="col6" nameend="col6" align="center">1D barcode outside value impression</entry></row><row><entry namest="col1" nameend="col1" align="right">Price / Product Table (PPT)</entry><entry namest="col2" nameend="col2" align="center">Data Integrity / Origin Authentication / Timeliness</entry><entry namest="col3" nameend="col3" align="center">Plain Session</entry><entry namest="col4" nameend="col4" align="center">Motherboard NVM</entry><entry namest="col5" nameend="col5" align="center">Price calculation module</entry><entry namest="col6" nameend="col6" align="center">---</entry></row><row><entry namest="col1" nameend="col1" align="right">User profile of origin authentication</entry><entry namest="col2" nameend="col2" align="center">Data Integrity /</entry><entry namest="col3" nameend="col3" align="center">Plain Session</entry><entry namest="col4" nameend="col4" align="center">Motherboard NVM</entry><entry namest="col5" nameend="col5" align="center">Recording in the NVM</entry><entry namest="col6" nameend="col6" align="center">---</entry></row><row><entry namest="col1" nameend="col1" align="right">PVD</entry><entry namest="col2" nameend="col2" align="center">Protection of Remuneration / Data Integrity / Source Authentication / Receiver Data Protection</entry><entry namest="col3" nameend="col3" align="center">Secure Session</entry><entry namest="col4" nameend="col4" align="center">PSD NVM</entry><entry namest="col5" nameend="col5" align="center">printer control</entry><entry namest="col6" nameend="col6" align="center">2D barcode in the value impression</entry></row><row><entry namest="col1" nameend="col1" align="right">withdraw</entry><entry namest="col2" nameend="col2" align="center">Protection of the remaining balance</entry><entry namest="col3" nameend="col3" align="center">Secure Session</entry><entry namest="col4" nameend="col4" align="center">PSD NVM</entry><entry namest="col5" nameend="col5" align="center">Postal registers,</entry><entry namest="col6" nameend="col6" align="center">---</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="right">MAC key</entry><entry namest="col2" nameend="col2" align="center">encryption</entry><entry namest="col3" nameend="col3" align="center">Secure Session</entry><entry namest="col4" nameend="col4" align="center">PSD NVM</entry><entry namest="col5" nameend="col5" align="center">Keystore, and Klicheé exam and generation</entry><entry namest="col6" nameend="col6" align="center">---</entry></row></tbody></tgroup></table></tables>
The table columns Protection Objective and Logical Channel describe, for each of the security categories mentioned in the first column, how the transmitted data is backed up during data exchange. The remaining table columns indicate the storage location, the affected components of the franking system and where the impression becomes visible in the impression.
identcodes
IdentCodes are reference numbers that uniquely identify mailpieces as long as they have not been successfully delivered. A piece of mail can be clearly recognized in a letter distribution center or at delivery on the basis of its IdentCode. The IdentCode can be used to provide tracking information about mail pieces and to make them queryable for the sender. Each IdentCode may only be assigned at most once (uniqueness) for at most one postal item (uniqueness) during its validity period. The storage location used is the non-volatile memory on the motherboard of the franking machine.
Price product table
The transmitted data influences a price calculation module and the impression. A price-product table (resp. Postage rate table) has a validity date from which it is valid. The entries of a price-product table should be protected against manipulation (data integrity). The source of a price-product table should be authorized (original authentication), and a price-product table should be provided at the latest on its validity date (timeliness). The storage location used is the non-volatile memory on the motherboard of the franking machine.
user profile
The user profiles are passively recorded in the machine and transmitted to the data center. The entries of a user profile should be protected against manipulation (data integrity). Alternatively, an integrity protection of the total volume of a user profile is sufficient. In addition, the origin should be authenticated (original authentication). This is a special booking value that can be transmitted to the data center as part of a special service (Class of Mail). This particular posting value is a usually non-printable MAC-secured totals value of all accumulated post values franked during a payroll period. If the above value is printed on a postcard, then one speaks of a billing franking. The aforementioned MAC (Message Authorization Code) is preferably implemented in the form of a CryptoTag. The storage location used is the non-volatile memory on the motherboard of the franking machine. After transferring the CoM data to the data center, the nonvolatile memory is cleared to make room for newly recorded data.
PVD
The data that is transferred during a postage value download is partially relevant to the fee. That means if, for example, an amount of 50<img file="EP1577840A2_D0001.tif" /> is requested and recorded and confirmed in the data center, then only 50 are allowed in the security module <img file="EP1577840A2_D0002.tif" /> more credits are available. Would there be 100<img file="EP1577840A2_D0003.tif" /> In addition, the deliverer would be (ie, for example, a postal authority) to the difference of 50 <img file="EP1577840A2_D0004.tif" /> cheated. Therefore, the messages transmitted in a postage value download must be protected against tampering and their respective data origin must be authenticated. In addition, the privacy of the recipient can be a protection goal here. It should for outsiders eg can not be seen, which amount a customer currently loads from the data center. To achieve this protection goal, certain messages between the data center and the security module are encrypted. The storage location is the non-volatile memory of the PSD. The affected components of the franking system are the PSD and its postal registers.
withdraw
The repayment (withdraw) of the remaining credit of the customer is an essential protection goal when returning a machine. The storage location is the non-volatile memory of the PSD. The affected components of the franking system are the PSD and its postal registers.
Mackey
The main protection goal when transferring the MACKeys is to keep the key secret from outsiders (including the user of the franking machine). Therefore, this key is encrypted before transmission and decrypted only in the security module. The storage location is the non-volatile memory of the PSD. The transferred data influences components of the franking system, such as PSD, keystore, cliché checking and generation in the franking machine.
As a logical channel, for example, only one plain text session is distinguished from a secure session. Simplified a plain text session is a reliable data connection over a telephone network, in which the data is transmitted without cryptographic security. If necessary, error-correcting codes can be used to improve the reliability of the transmission link. Because of the general notoriety, it is not necessary to take a closer look at the characteristics of a plaintext channel. A security text session is a reliable data connection over a telephone network where the data is transmitted cryptographically secured. If necessary, error-correcting codes can also be used here in order to improve the reliability of the transmission path. The selector controls the selection of the channel (secure / unsecured), for example, based on a decision matrix that holds the appropriate treatment for, for example, the requested service or a pending message to be pending. For example, the decision matrix may be in the form of one or more database tables, so that channel assignment changes can be made dynamically during operation of the server.
FIG. 5 shows a detail of the block diagram of the control unit 34 of the server. The selector 341 is, for example, a hardware and / or software component intended to store a data set D1 ... Dn to Dx to be taken from a memory 321 of the database management system 32 and at least partially buffered until the processing of the data set is completed by the microprocessor 342 operatively connected to the selector 341. The record D1 ... Dn to Dx comprises at least first data, ie an addressable data part of the assigned application data and / or comprises application data AD directly. The data record further comprises assigned security data SD and an assignment rule which is based on further steps, data tables or data tables. refers to a decision matrix, which enables the micro-processor to ultimately produce a selected logical channel. This assignment rule is also referred to as security category SC of a security policy. The micro-processor 342 accesses a program stored in a program memory 343 and executes the program and the desired protocols. The first data is application data AD of the addressed data set D1 and is transmitted via a bus to the micro-processor 342 or at the smallest level of the security categories directly to the input / output unit 344. A modem can be connected to the latter, for example. At a higher level of the security categories, when the selector caches further security data SD and security category SC data indicating a predetermined security policy, an interrupt I or control signal is generated for the micro-processor 342 based on the second data CD provided by the selector to the micro-processor determines the type of further data processing. The first data transmitted to the micro-processor 342 can be further processed and thereby, for example, encrypted, ie be further processed in accordance with the kind which communicates the transferred second (control) data CD. The data set D1 shown in FIG. 5 contains data AD, SD and SC, the sequence of which can be realized differently than was drawn. Preferably, a record Dn contains in its header at least the security category SC, ie Information about the associated security policy. The selector can be addressed by the microprocessor, for example via an address bus ADD-BUS 345, and the second (control) data CD transferred from the selector can thus be interrogated repeatedly by the microprocessor. In addition to the requested first data, the data on the security category SC can also be output by the microprocessor via the input / output unit 344 in order to identify the location of the storage in the franking system 1. With the comments on Figure 5, only one embodiment variant is explained, however, can not be ruled out that the control unit 34 of the server is partially realized in other ways. Alternatively, the selector 341 may be implemented as part of the microprocessor 342 hardware and / or software.
The selector controls the logical channel by the use of cryptographic methods on messages or submessages (or their omission); ie to the methods of technical transport of the information, for example by a transmission via modem or via another suitable server communication means 31, mathematical methods of cryptography are applied. Another possibility is to link the allocation of the channel firmly at the time of development to the services or data fields, ie hard to code which channel to use. In this case, the selector is a logical component of the sequence program in the server.
In general, secure channels are characterized by authentication of messages or partial messages by means of Message Authentication Codes (MAC) containing a typically encrypted (cryptographic) checksum. Methods such as HMAC-SHA1 accomplish this. Furthermore, messages or sub-messages can be encrypted using the encryption method (3DES, AES). The key material used for the authentication and encryption is statically selected and, for example, impressed on the service device during production or regenerated based on a key exchange procedure for each session.
The identity of the two communication partners can be securely determined, for example, by digital signatures, which are linked together in the sense of a common public key hierarchy. Both entities have their own key identity in this case.
The cryptographic features of a secure channel are described in detail, for example, in the non-prepublished German patent application 10 2004 032 057.8 under the title: Method and apparatus for generating a secret session key, in particular with reference to FIGS. 3 and 4.
The security information provided by the data center as part of a remote service can be used both by the franking machine and by other devices of a franking system.
A franking system can also be understood as meaning a so-called PC meter, which consists of at least one personal computer with PSD and a commercial office printer.
In another variant - not shown in FIG. 2 - the database management system (DBMS) 32 is implemented within the server 30. In addition, it is provided that the selector 341 is designed as part of the microprocessor 342 hardware and / or software.
The invention is not limited to the present embodiment, as obviously other other arrangements or embodiments of the invention can be developed or used, which - based on the same basic idea of the invention - are encompassed by the appended claims.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0948158A2 | Cites | European Patent Office (EPO) | Search report |
| EP0986028A2 | Cites | European Patent Office (EPO) | Search report |
| EP1244064A1 | Cites | European Patent Office (EPO) | Search report |
| DE19830055A1 | Cites | Germany | Search report |
| US2002083020A1 | Cites | United States of America | Search report |
| WO2004001617A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO9948053A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
5 members in 3 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 102004014427 | Germany | A | |
| 102004014427 | Germany | – | |
| 102004014427 | – | – | – |
| DE20041014427 | – | – | – |
Members5
| Document | Office | Kind | |
|---|---|---|---|
| EP1577840A2This record | European Patent Office (EPO) | A2 | |
| US2005209875A1 | United States of America | A1 | |
| DE102004014427A1 | Germany | A1 | |
| EP1577840A3 | European Patent Office (EPO) | A3 | |
| US7996884B2 | United States of America | B2 |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application refused18R | 18R | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN REFUSEDSTAA | STAA | |
| Designation fees paidAKX | AKX | |
| First examination report despatched17Q | 17Q | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1577840
- Publication, DOCDB
- 1577840
- Publication, EPODOC
- EP1577840
- Application
- 5003805
- Application, DOCDB
- 05003805
- Application, EPODOC
- EP20050003805
Titles3
- German
- Verfahren für ein servergesteuertes Sicherheitsmanagement von erbringbaren Dienstleistungen und Anordnung zur Bereitstellung von Daten nach einem Sicherheitsmanagement für ein Frankiersystem
- English
- Method for server controlled security management of yieldable services and arrangement for providing data according to a security management for a franking system
- French
- Procédé de gestion à l'aide d'un serveur pour le contrôle de la sécurité des services et dispositif pour fournir des données en fonction de la gestion de la sécurité dans un système d'affranchissement
Classification
- CPC, 4
- G07B17/0008
- G06Q20/206
- G07B2017/00169
- G07B2017/00967
- IPC, 2
- G07B17 00
- G07B17 04
Designated states36
- Contracting states, 30
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Poland
and 6 moreShow fewer
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
- Extension states, 6
- Albania
- Bosnia and Herzegovina
- Croatia
- Latvia
- North Macedonia
- Yugoslavia, later Serbia and Montenegro (until 2006)