Method for protecting a chip card against unauthorised use, chip card and chip cards terminal
Abstract
Die Erfindung betrifft ein Verfahren zum Schutz einer Chipkarte (104) gegen unberechtigte Benutzung mit folgenden Schritten: - Eingabe einer ersten Kennung (116) in einen Chipkarten-Terminal (100), - Erzeugung eines Chiffrats aus zumindest einem ersten Kommunikationsparameter (K1; KA1, D1) mit Hilfe eines aus der ersten Kennung abgeleifieten ersten symmetrischen Schlüssels (S1), wobei mit Hilfe des Kommunikationsparameters ein geschützter erster Kommunikationskanal (112) zwischen dem Chipkarten-Terminal und der Chipkarte definierbar ist, - Übertragung des Chiffrats über einen vordefinierten Kommunikationskanal (108) von dem Chipkarten-Terminal an die Chipkarte, - Versuch einer Entschlüsselung des Chiffrats mit Hilfe eines zweiten symmetrischen Schlüssels (S2) durch die Chipkarte, wobei das Resultat der Entschlüsselung nur dann der erste Kommunikationsparameter ist, wenn der erste symmetrische Schlüssel dem zweiten symmetrischen Schlüssel gleicht, sodass der geschützte erste Kommunikationskanal nur dann zwischen dem Chipkarten-Terminal und der Chipkarte definierbar ist, wenn die erste Kennung zutreffend ist.

Term
2.1 yearsto projected expiry
Projected expiry 20 October 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 9 independent, 6 dependent
- 1Verfahren zum Schutz einer Chipkarte (104) gegen unberechtigte Benutzung mit folgenden Schritten:- Eingabe einer ersten Kennung (116) in einen Chipkarten-Terminal (100), - Erzeugung eines Chiffrats aus zumindest einem ersten Kommunikationsparameter (K1;KA1, D1) mit Hilfe eines aus der ersten Kennung abgeleiteten ersten symmetrischen Schlüssels (S1), wobei mit Hilfe des Kommunikationsparameters ein geschützter erster Kommunikationskanal (112) zwischen dem Chipkarten-Terminal und der Chipkarte definierbar ist, - Übertragung des Chiffrats über einen vordefinierten Kommunikationskanal (108) von dem Chipkarten-Terminal an die Chipkarte, - Versuch einer Entschlüsselung des Chiffrats mit Hilfe eines zweiten symmetrischen Schlüssels (S2) durch die Chipkarte, wobei das Resultat der Entschlüsselung nur dann der erste Kommunikationsparameter ist, wenn der erste symmetrische Schlüssel dem zweiten symmetrischen Schlüssel gleicht, sodass der geschützte erste Kommunikationskanal nur dann zwischen dem Chipkarten-Terminal und der Chipkarte definierbar ist, wenn die erste Kennung zutreffend ist, wobei es sich bei dem ersten Kommunikationsparameter um einen öffentlichen Schlüssel des Chipkarten-Terminals handelt, wobei die Chipkarte im Fall, dass die Entschlüsselung des Chiffrats gelingt, aus dem öffentlichen Schlüssel nach dem Diffie-Hellman (DH)-Verfahren einen weiteren symmetrischen Schlüssel (S4) zur Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte ableitet, wobei durch die Verschlüsselung mit dem weiteren symmetrischen Schlüssel der erste Kommunikationskanal definiert ist.
- 2Verfahren nach Anspruch 1, wobei es sich bei dem ersten Kommunikationsparameter um die Angabe einer Übertragungsfrequenz, eines Frequenz-Hopping-Schemas, eines Codierungsverfahrens und/oder eines Modulationsverfahrens handelt.
- 3Verfahren nach Anspruch 1 oder 2, wobei es sich bei dem ersten Kommunikationsparameter um einen ersten Domainparameter (D1) für die Durchführung eines diskreten logarithmischen kryptographischen Verfahrens zur Erzeugung eines dritten symmetrischen Schlüssels (S3) durch das Chipkarten-Terminal eines vierten symmetrischen Schlüssels (S4) durch die Chipkarte und handelt, wobei die dritten und vierten Schlüssel identisch sind, wenn die erste Kennung zutreffend ist, wobei die dritten und vierten symmetrische Schlüssel zur Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte über den geschützten ersten Kommunikationskanal vorgesehen sind.
- 4Verfahren nach Anspruch 3, wobei es sich bei dem diskreten logarithmischen kryptographischen Verfahren um ein elliptische Kurven kryptographisches Verfahren handelt.
- 5Verfahren nach Anspruch 3 oder 4, wobei es sich bei dem diskreten logarithmischen kryptographischen Verfahren um ein elliptisches Kurven Diffie-Hellman-Verfahren handelt.
- 6Verfahren nach einem der vorhergehenden Ansprüche, wobei die erste Kennung als Seed Value für die Ableitung des ersten symmetrischen Schlüssels durch das Chipkarten-Terminal verwendet wird.
- 7Verfahren nach einem der vorhergehenden Ansprüche, wobei auf der Chipkarte eine zweite Kennung (140) gespeichert ist, aus der der zweite Schlüssel ableitbar ist.
- 8Verfahren nach einem der vorhergehenden Ansprüche, wobei der zweite Schlüssel in einem geschützten nicht-volatilen Speicherbereich der Chipkarte gespeichert ist.
- 9Verfahren nach einem der vorhergehenden Ansprüche, wobei das Resultat der Entschlüsselung ein nicht zutreffender zweiter Kommunikationsparameter (K2; D2, KA2) ist, wenn die erste Kennung nicht zutreffend ist, wobei durch den zweiten Kommunikationsparameter ein nicht zutreffender zweiter Kommunikationskanal (146) durch die Chipkarte definierbar ist, mit folgenden weiteren Schritten:- Sendung eines Chipkarten-Kommandos (122) von dem Chipkarten-Terminal an die Chipkarte auf dem geschützten ersten Kommunikationskanal, - Ignorierung des Chipkarten-Kommandos durch die Chipkarte und Reduzierung der Anzahl der verbleibenden Fehlbedienungen, wobei die Chipkarte oder eine Chipkartenfunktion der Chipkarte bei Überschreitung einer vorgegebenen Anzahl von Fehlbedienungen gesperrt wird.
- 10Chipkarte mit - einer Schnittstelle (106) zur Kommunikation über einen vordefinierten Kommunikationskanal (108) und mehreren weiteren Kommunikationskanälen (112, 146,...) mit einem Chipkarten-Terminal (100), - Mitteln (132, 136) zur Entschlüsselung eines auf dem vordefinierten Kanal empfangenen Chiffrats, welches mit Hilfe eines ersten symmetrischen Schlüssel verschlüsselt ist, mit Hilfe eines zweiten symmetrischen Schlüssels (S2), wobei die Entschlüsselung zumindest einen Kommunikationsparameter ergibt (K2;KA2, D2), wenn eine zuvor in den Chipkarten-Terminal eingegebene erste Kennung (116) zutreffend ist, wobei durch den Kommunikationsparameter einer der weiteren Kommunikationskanäle für die geschützte Kommunikation zwischen der Chipkarte und dem Chipkarten-Terminal eindeutig festgelegt ist,wobei durch den ersten Kommunikationsparameter ein öffentlchen Schlüssel angegeben wird, und mit Mitteln (132) zur Durchführung eines Diffie-Hellman-Verfahrens zur Ableitung eines weiteren symmetrischen Schlüssels (S4) mit Hilfe des öffentlichen Schlüssels.
- 11Chipkarte nach Anspruch 10, mit Mitteln (150) zur Durchführung eines diskreten logarithmischen Verschlüsselungsverfahrens zur Erzeugung des weiteren symmetrischen Schlüssels (S4), wobei der weitere symmetrische Schlüssel zur symmetrischen Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte über den festgelegten Kommunikationskanal (112) vorgesehen ist.
- 12Chipkarte nach einem der vorhergehenden Ansprüche 10 oder 11, mit einem nicht flüchtigen geschützten Speicherbereich zur Speicherung einer zweiten Kennung (140), aus der der zweite Schlüssel ableitbar ist.
- 13Chipkarte nach einem der vorhergehenden Ansprüche 10 bis 12, mit einem Fehlbedienungs-Zähler (144) zur Sperrung der Chipkarte, wenn die Anzahl der Fehlbedienungen einen vorgegebenen Schwellwert erreicht hat, wobei eine von der Chipkarte empfangene Nachricht, die auf einem der weiteren Kommunikationskanäle, welcher nicht der festgelegt Kommunikationskanal ist, an die Chipkarte gesendet wird, als Fehlbedienung gezählt wird.
- 14Chipkarte nach einem der vorhergehenden Ansprüche 10 bis 13, mit einer Erstbenutzerfunktion, wobei in einem Erstbenutzungszustand, ein bestimmter Kommunikationsparameter für eine erste Wahl des ersten Kommunikationskanals festgelegt ist, und wobei die Chipkarte aus ihrem Erstbenutzungszustand in einen Benutztzustand übergeht, wenn sie zum ersten Mal ein Chipkartenkommando (122) auf diesem ersten Kommunikationskanal empfängt.
- 15Chipkarten-Terminal mit - Mitteln (114) zur Eingabe einer ersten Kennung (116), - Mitteln zur Erzeugung eines Chiffrats aus zumindest einem ersten Kommunikationsparameter (K1;KA1, D1) mit Hilfe eines aus der ersten Kennung abgeleiteten ersten symmetrischen Schlüssels (S1), wobei mit Hilfe des Kommunikationsparameters ein geschützter erster Kommunikationskanal (112) zwischen dem Chipkarten-Terminal und der Chipkarte (104) definierbar ist, - Mitteln zum Senden des Chiffrats über einen vordefinierten Kommunikationskanal (108) an die Chipkarte, - Mitteln (148) zur Erzeugung von Domainparametern (D1) für die Durchführung eines diskreten logarithmischen kryptographischen Verfahrens für die Ableitung eines weiteren symmetrischen Schlüssels (S3) zur Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte, wobei der erste Kommunikationsparameter die Domainparameter angibt.
Independent claims15
93 paragraphs in 1 section, as filed
p0001The invention relates to a method for protecting a smart card against unauthorized use, a smart card and a smart card terminal.
p0002For the activation of a smart card feature can provide a user identification FUJIFILM's prior towards the smart card may be required, as is known from the prior art per se. The most common user identification is typing secret code, which is generally a PIN (Personal Identification Number) or CHV (Card Holder Verification) is referred to. Such tags generally consist of a numeric or alphanumeric character string. Needed to identify the identifier of the user on the keyboard of a smart card terminal or a computer to which a chip card reader is connected, is entered, and then sent to the smart card. This compares the entered identifier with the stored identifier, and then divides the result of the terminal or the computer by outputting a corresponding signal.
p0003The PINs can be made between static and changeable pins. A static PIN is user no longer be changed and must be learned by heart from this. If they become known, then the card user has to destroy his chip card, to prevent misuse by unauthorized persons, and get a new smart card with another static PIN. Likewise, the user needs a new chip card if he or she has forgotten the static PIN.
p0004A changeable PIN can be changed to suit the user. To change the PIN, it is always necessary for safety reasons, to pass the currently valid PIN with, otherwise any existing PIN could be replaced by an attacker with his own.
p0005The situation is different with the Super-PIN or PUK (Personal Unlocking Key) called. These usually have more points than the actual PIN, and be used, one standing at its maximum value incorrect entry counter (also referred to as "error counter") to reset a PIN again. The PUK is a new PIN is also equally passed to the smart card, because a recessed retry counter of little use if you forget your PIN. And this is indeed usually the case, when the retry counter has reached its maximum value.
p0006There are also applications that use transport PINs. The chip card is personalized with a random PIN, which is replaced by the card user in a PIN letter. When first entering but he will be asked by the smart card to replace the personalized PIN by its own. In a similar process, "zero-PIN-procedure", the smart card is a trivial PIN such as "0000" preset, and it is also from the smart card during the first use, a change enforced (see. This also<patcit id="pcit0001" dnum="DE3523237A1"><text>DE 35 23 237 A1</text></patcit>. <patcit id="pcit0002" dnum="DE19507043A1"><text>DE 195 07 043 A1</text></patcit>. <patcit id="pcit0003" dnum="DE19507044C2"><text>DE 195 07 044 C2</text></patcit>. <patcit id="pcit0004" dnum="DE19850307C2"><text>DE 198 50 307 C2</text></patcit>. <patcit id="pcit0005" dnum="EP0730253B1"><text>EP 730 253 B1 0</text></patcit>). By such methods, a so-called. Erstbenutzerfunktion is given which provides the authorized user assurance that prior to its heritage use has taken place through a third party any unauthorized use of the smart card.
p0007From the <patcit id="pcit0006" dnum="DE19850307C2"><text>DE 198 50 307 C2</text></patcit> discloses a method to protect against abuse in smart cards. The smart card has a first user function, which in the first use of the data and / or functions of the chip card specifying an arbitrarily selectable, personal user identification number (PIN) calls, where in by entering the personal identification number data and / or functions of the chip card a uses status are set. A subsequent amendment to the personal identification number is made possible by a parent unlock.
p0008Method for checking an identifier The prior art also already become known in which the transmission of the identification itself is not required, such as Strong Password Only Authentication Key Exchange (SPEKE), Diffie-Hellman encripted Key Exchange (DH-EKE ), Bellovin-Merritt protocol or Password Authenticated Connection establishment (PACE). The SPEKE protocol is for example known<u>www.jablon.org/speke97.html,</u><patcit id="pcit0007" dnum="US6792533B2"><text>US 6,792,533 B2</text></patcit> and <patcit id="pcit0008" dnum="US7139917B2"><text>US 7,139,917 B2</text></patcit>, Among other things also made<u>www.jablon.orq / speke97.html</u> is aware of the DH-EKE protocol. inter alia<patcit id="pcit0009" dnum="US5241599A"><text>US 5,241,599</text></patcit> is known the Bellovin-Merritt protocol. Out<u>www.heise.de/security/news/meldung/85024</u> the PACE protocol known which particular suitable for elliptic curve cryptography.
p0009In contrast, the present invention seeks to provide an improved method for protecting a smart card against unauthorized use. The invention further has for its object to provide an improved chip card and an improved chip card terminal.
p0010The invention of the underlying objects are achieved with each of the features of the independent claims. Preferred embodiments are specified in the dependent claims.
p0011According to a method for protecting a smart card is provided against unauthorized use. The method involves addition to the chip card itself, a chip card terminal,
p0012Under "chip card terminal" here refers to any device that is configured to communicate with a smart card to be sent, for example, smart card commands to the smart card and receive corresponding responses from the smart card. The communication between the smart card and smart card terminal can with contact, wireless, for example via an RFID process, or alternatively with contact or wirelessly, in particular a so-called dual-mode interface. In the smart card terminal may be a so-called Class 1, 2 or 3 smart card reader with or without its own keyboard or a computer to which a smart card reader is connected. In the smart card terminal, it may also be an intended for a particular purpose terminal, such as a bank terminal for banking transactions, a payment terminal, for example, to buy electronic tickets, or an access terminal to enable access to a protected area.
p0013Under the term "protection of a chip card" is understood one or more smart card functions of the chip card Here the protection of the chip card or the total protection. For example, the smart card is protected according to the invention a particularly sensitive chip card function, such as a signature function to generate an electronic signature, a payment function, an authentication function or the like.
p0014According to one embodiment of the inventive method, the authorized user receives from the smart card issuing institution a secret identifier, which is generally referred to as PIN. To use the chip card a first identifier in the smart card terminal must be entered, which is referred to as PIN 'in the following. Only when the PIN 'is identical to the PIN, should be possible to use the smart card or the protected smart card function.
p0015For this purpose, the chip card terminal generates a cryptogram from at least a first communication parameter using a first symmetric key. In the first symmetric key may 'act itself or by one of the PIN' to the PIN derived symmetric key. For example, the PIN 'as a so called seed value used for generating the first symmetric key by the smart card terminal.
p0016The at least one communications parameter is such that by it a protected first communication channel between the smart card terminal and the chip card can be defined. In order to build these protected first communication channel between the smart card and the smart card terminal, the recovered with the aid of the first symmetric key cipher of the first communication parameter over a pre-defined communication channel from the smart card terminal is first transferred to the chip card. This predefined communications channel is thus defined by default to establish an initial communication between the smart card terminal and the IC card.
p0017After the transfer of the cipher on this predefined communication channel from the smart card terminal to the IC card the attempt of a decryption cipher this with the aid of a second symmetric key is made by the smart card. This decryption is successful only when the second symmetric key is equal to the first key, that is, if the condition PIN 'is = PIN met.
p0018The establishment of a communication connection through the protected first communication channel is thus only possible when the condition PIN '= PIN is satisfied, because the smart card only in this case obtains knowledge of the first communication parameter by which the protected first communication channel is fixed.
p0019In the first communication parameter can be for example, specifying a transmission frequency, a Freciuenz hopping scheme, a coding method and / or a modulation method.
p0020If the condition PIN '= PIN is not been met, so does the PIN from the' derived first key does not match the second key of the smart card. This has the result that the decoding of the data received from the smart card terminal cipher does not produce the first communication parameters by the chip card using the second key, but for example, a second communication parameter that differs from the first communication parameter.
p0021By the second communication parameter, a second communication channel may be defined which is different from the first communication channel. When the IC card receives a signal on the first communication channel, so this is ignored, however, since the chip card a signal on the second communication channel expected. As a result, therefore, is no communication between the chip card terminal and the chip card if the condition PIN '- PIN is not satisfied.
p0022According to one embodiment of the invention may be in the communication parameters for a public key of an asymmetric key pair of smart card terminals. For establishing a symmetric key for the communication between the chip card terminal and the IC card, for example according to the Diffie-Hellman method, the public key of the smart card terminals is encrypted with the obtained from the first identifier first symmetric key and predefined via the communication channel is sent to the chip card.
p0023Only if the condition PIN 'is = PIN fulfilled, the smart card receives the correct public key of the smart card terminals. The chip card terminal generated from the public key of the smart card, which is for example retrieved from a key server, according to the Diffie-Hellman Verfiahren the third key, whereas the smart card from their private key and decrypted using the second symmetric key cipher a fourth key also generated by the Diffie-Hellman method, the fourth key only equal to the third key, if the condition PIN 'is = PIN met.
p0024The third and fourth identical symmetric keys used for encryption of signals, in particular chip card commands and replies to such chip card commands that are exchanged between the chip card terminal and the chip card via the first communication channel. This first communication channel is defined at least in addition via the third key by means of which the communication via the first communication channel with a symmetric encryption method is encrypted.
p0025According to one embodiment of the invention, a process of the discrete logarithm cryptography (DLC) is used for the generation of a third key by the smart card terminal and a fourth key by the smart card, the fourth key only then is equal to the third key, if the condition PIN 'is = PIN met.
p0026For the determination of the third key any methods of discrete logarithmic cryptography are in principle to apply, such as those in the standard National Institute of Standards and Technology (NIST), NIST Special Publication 800-56A, March, 2007, and in Standards for Efficient Cryptography , SEC1: Elliptic Curve Cryptography, Certicom Research, September 20, 2000, version 1.0, are described. Such methods require the generation of so-called domain parameters for the purpose of generating the identical third and fourth key by the smart card terminal or smart card.
p0027According to one embodiment of the invention, a method of elliptic curve cryptography (ECC) is used as DLC, especially Elliptic Curve Diffie-Hellman (ECDH).
p0028According to one embodiment of the invention the first identifier, that is, the PIN 'which is input to the chip card terminal is used as a so-called seed value for the derivative of the first symmetric key. Characterized a key a greater length is generated than would be the case with use of the first identifier directly as a key.
p0029According to one embodiment of the invention, on the smart card a second identifier, that is, the PIN, stored, from the second key for decryption of the initial data received from the smart card terminal cipher is derivable. For the derivation of the second key from the second identifier, the second identifier may be used as a seed value.
p0030According to one embodiment of the invention is not the PIN stored in the smart card itself, but only the second key. The second key is preferably stored in a non-volatile protected memory area of the chip card. In contrast to the prior art, therefore, the storage of the PIN as a reference value in the smart card is not required.
p0031According to one embodiment of the invention, the chip card has a miss-service counter. If due to incorrect entry of the PIN 'the first and second communication channels do not match, so will increment or decrement the smart card the wrong-service counters with each message receives the smart card on another as the second or the predefined communication channel. Such messages, which receives the chip card to another than the second or the predefined communication channel, are ignored by the smart card otherwise. If the number of incorrect operation exceeds a predetermined threshold value, then the smart card as a whole or a particular chip card function, reversibly or irreversibly blocked.
p0032According to one embodiment of the invention, the chip card has a Erstbenutzerfunktion. The unused chip card is in its Erstbenutzungszustand, in which a particular communication parameter is set for a first election of the first communication channel. The smart card is transferred from their Erstbenutzungszustand in a Uses state when a chip card command receives for the first time on this first communication channel. then another communication parameters must be selected for further use of the smart card by the chip card terminals.
p0033In another aspect, the invention relates to a chip card with a chip card with an interface for communication over a predefined communication channel, and a plurality of further communication channels with a chip card terminal, means for decryption of a received on the predefined channel ciphertext, which is encrypted using a first symmetric key , with the aid of a second symmetric key, wherein the decrypting at least provides a communication parameter if a previously entered in the smart card terminal first identifier is applicable, wherein by the communication parameter is one of further communication channels for the protected communication between the chip card and the chip card terminal is clearly defined.
p0034In another aspect, the invention relates to a chip card terminal with means for entering a first identifier, means for generating a cipher from at least a first communication parameters using a signal derived from the first identifier first symmetric key, wherein by means of the communication parameter a protected first communication channel between the smart card terminal and the chip card can be defined, and means for transmitting the ciphertext over a predefined communication channel to the smart card.
p0035In another aspect, the invention relates to a chip card, wherein it is at the first communication parameter to the specification of a transmission frequency, a frequency hopping scheme, an encoding method and / or a modulation method.
p0036In another aspect, the invention relates to a chip card, with a protected non-volatile memory area for storing the second key.
p0037In another aspect, the invention relates to a chip card, which is a document, in particular a value or security document in order is an identification card, a cash, a signature card or the like.
p0038In another aspect, the invention relates to a chip card terminal, wherein it is at the first communication parameter to the specification of a transmission frequency, a frequency hopping scheme, an encoding method and / or a modulation method.
p0039In further embodiments of the invention with reference to the drawings in more detail. Show it:<dl id="dl0001"><dt>figure 1</dt><dd>a block diagram of a first embodiment of an inventive chip card and a chip card terminal,</dd><dt>figure 2</dt><dd>a flowchart of an embodiment of a method according to the invention, </dd><dt>figure 3</dt><dd>a block diagram of another embodiment of an inventive chip card and a chip card terminal,</dd><dt>figure 4</dt><dd>a flow diagram of another embodiment of a method according to the invention.</dd></dl>
p0040In the subsequent Figures, corresponding elements of the various embodiments are identified by the same reference numerals to each other.
p0041The <figref idrefs="f0001">figure 1</figref> shows a block diagram of a smart card terminals 100. The smart card terminal 100 has an interface 102 for communication with a chip card 104, which has a corresponding interface 106th Preferably, the interfaces 102 and 106 configured for wireless communication, for example via radio, in particular by an RFID method.
p0042The interfaces 102 and 106 are, for example, such that between the interfaces 102, 106 various communication channels may be constructed wherein these communication channels differ from each other on a physical and / or logical level. For example, communication channels of different transmission frequencies can be constructed. It is also possible communication channels based on different frequency hopping patterns are established. Under "frequency hopping" are here frequency hopping understood that the frequencies used for data transmission are continuously changed according to a defined scheme.
p0043The interfaces 102, 106 may also be configured such that different communication channels using different coding schemes and / or modulation method such as frequency modulation, amplitude modulation, phase modulation, pulse width modulation or other modulation methods to be established.
p0044The various communication channels that can be set up between the interfaces 102 and 106 are referred to as the "amount of the communication channels".
p0045One of the communication channels 108 from the set of communication channels is predefined for the initial communication between the smart card terminal 100 and the smart card 104th For example, the communication channel with respect to its transmission frequency as well as to be used modulation and coding scheme is predefined.
p0046The predefined communications channel is used to transmit a cipher 110 of the at least one communication parameter K1 of the chip card terminal 100 to the smart card 104 to be notified to the IC card 104, the communication channels 112, the amount of communication channels for subsequent communication with the smart card terminal which 100 should be used.
p0047The communication parameters K1 therefore includes a statement which clearly specifies this communication channel 112th This information may take the form of a code word. In the smart card 104 may be stored in a nonvolatile memory a so-called lookup table in which the possible code words are each assigned a specification of one of the communication channels of the set of communication channels.
p0048For the selection of a communication channel from the set of communication channels can all possible, between the interfaces 102, 106 erecting communication channels are available or a selection of them, in which case each of the communication channels of the amount of communication channels, the actual communication between the interface 102, 106 can be used, is assigned a unique code word which can be transmitted as a communication parameter 110 from the smart card terminal 100 to the smart card 104th
p0049The smart card terminal 100 has a user interface 114, such as a keyboard or a graphical user interface can be inputted via the a first identifier 116th This first identifier is referred to as PIN 'in addition, without limiting the generality.
p0050The smart card terminal 100 has at least one processor 118 for executing an application program 120. The application program 120 may cause the generation of a smart card commands 122 to enter a specific chip card function 124 of the chip card 104th For example, requires the application program 120, the chip card function 124 like for an authenticity check, for generating a digital signature, for verifying an entitlement, in particular a right of access, the application of a financial transaction or.
p0051The processor 118 also is used to execute the program instructions of a communication module 126, which is used to select the communication channel 112 from the set of communication channels and thus to select the communication parameter 110th The selection of the communication parameter 110 can be performed according to a predetermined scheme, or randomly, in particular pseudo-randomly. For example, a list of various communication parameters 110 is stored in the communication module 126, which is processed cyclically.
p0052The processor 118 also serves the execution of program instructions 128 for a symmetric encryption of the communication parameters 110. Encryption is performed using the PIN '. To this end, the program instructions 128 may include a key generator 130th
p0053The key generator 130 may be designed such that it acts as a seed value generated from the PIN 'a first symmetric key, which is hereafter referred to as S1. The key S1 is used for the symmetric encryption of the selected by the communication module 126 communication parameter K1. That from the symmetric encryption resultant with the key S1 cipher the communication parameter K1 is transmitted via the predefined communication channel 108 from the interface 102 to the interface 106th
p0054The smart card 104 has a processor 132, which is used for executing the program instructions of a communication module 134th The communication module 134 is configured for processing the by the smart card terminal 100 optionally received communication parameter K1. The communication module 134 may, for example, with the communication parameters K1 as the key to an allocation table, in particular a lookup table, zugreiben to retrieve the parameters from the smart card terminal 100 the selected communication channel 112, such as its transmission frequency and / or the to be used coding and modulation method.
p0055The processor 132 also is used to execute program instructions 136 for the symmetrical decrypting the cipher 110 that the smart card has 104 received from the chip card terminal 100th For example, the smart card 104 has a protected memory area 138, in which a second identifier 140 is stored. The second identifier is referred to below without loss of generality as a PIN. The PIN is the authorized user of the chip card with the handing over of the smart card 104 separately notified, for example in the form of a so-called PIN-letter.
p0056The program instructions 136 may include a key generator 142, which uses the PIN as a so-called seed value to derive a second key. This symmetrical second key is referred to as S2.
p0057Alternatively it can be stored in the protected memory area 138 of the chip card 104 instead of the PIN 140 is the key S2. The key generator 142 and a storage of the PIN 140 in the IC card 104 are unnecessary then. Unlike the prior art, the PIN must be 140 stored as a reference for testing the correctness of the PIN '116 on the chip card 104 is not necessarily.
p0058The smart card 104 may further comprise a failure counter-service 144th The error-service counter 144 is so formed that any incorrect operation of the chip card is counted 104th The number of operating errors is compared with a predetermined threshold value. If this threshold is reached, at least the chip card function 124, which is assigned to the 144-service failure counter, reversibly or irreversibly blocked.
p0059The smart card 104 may further include a Erstbenutzungsfunktion. For example, the first use of the smart card 104 through a particular communication parameter is defined, which specifies one of the communication channels of the amount that must be used for the first use of the chip card.
p0060To use the smart card 104, it is proceeded as follows: A user enters the PIN '116 via the user interface 114 in the smart card terminal 100 a. This can be done through a corresponding request of the application program 120th The communication module 126 then selects a first of the possible communication parameters, for example, from the predetermined list of communication parameters, ie the communication parameter K1.
p0061The key generator 130 generated from the PIN 'the key S1. The communication parameter K1 is then encrypted by executing the program instructions 128 using the symmetric key S1. The resulting cipher 110 of the communication parameter K1 is then sent via the predefined communication channel 108 from the interface 102 to the interface 106 of the smart card 104th
p0062The smart card 104 forwards if necessary around the key S2 of the PIN or directly accesses the key S2 in the protected memory area 138th With
p0063Using the key S2 an attempt at deciphering the 100 received from the chip card terminal cipher 110 of the communication parameter K1 by executing the program instructions 136 is made from the smart card 104th
p0064The result of this decryption trial is a second communication parameter is hereinafter referred to as K2, and is given to the communication module 134th This communication parameter K2 is only the same as the communication parameter K1, if the condition PIN 'is = PIN satisfied because only the key S1, which has been used for symmetric encryption, may be equal to the key S2, which for the symmetrical decryption the cipher of the communication parameter K1 was used.
p0065By the communication parameter K2 is a second communication channel 146 may be defined, namely by the communication module 134 accesses the communication parameter K2 on its mapping table. This second communication passage 146 is again only be identical to the first communication channel 112, if the condition PIN 'is = PIN met.
p0066After the transfer of the cipher communication of the parameter K1 via the predefined communications channel 108 generates the chip card terminal 100 the chip-card command 122, which is sent via the first communication channel 112 from the interface 102 to the interface 106th The chip card 104 and the communication module 134 are set to receive on the second communication channel 146 due to the communication parameter K2.
p0067When the second communication channel 146 corresponds to the first communication channel 112, so the chip-card command 122 is processed by the smart card 104 and the smart card function 124 is called. As a result, generates the chip card 104, a response to the chip-card command 122, and transmits this response via the first communication channel 112 back to the IC card 100th
p0068In contrast, when the second communication channel 146 is not identical to the first communication channel 112, so the smart card 104 ignores the received on the first communication channel 112 smart card command and increments the failure counter-service 144th
p0069For example, the communication channel 108 is defined by a transmission frequency of 9 GHz, the communication channel 112 by a transmission frequency of 11GHz, the Übertragungsfrequnzen of the communication channels 112 and 146 differ from each other since the input by a transmission frequency of 10 GHz and the communication channel 146 in the smart card terminal 100 PIN 'is not equal to the PIN. If the smart card 104 a signal on the amount of frequency 10 GHz in this case receives from the smart card terminal 100, although it has a expected reception at the frequency 11 GHz, this signal is ignored and the retry counter is incremented. This is an implicit verification of the PIN is 'given without the PIN' should be compared directly with the PIN, and without requiring a PIN must be stored in the smart card.
p0070The <figref idrefs="f0002">figure 2</figref> shows a corresponding flow chart. In step 200, the PIN 'in the chip card terminal is inputted. Then, set in the step 202 by the smart card terminal 100 of the communication parameters K1 for selecting one of the communication channels from the set of communication channels. In step 204, the communication parameter K1 is encrypted using the PIN 'symmetrical. This can be done so that from the PIN 'by means of a key generator, the symmetric key is derived S1, which is then used to encrypt the communication parameter K1.
p0071In step 206, the generated ciphertext using the key S1 of the communication parameter K1 is transmitted to the smart card via a predefined communication channel from the smart card terminal.
p0072The chip card 104 takes in step 208, the attempt of a decryption of the communication parameter K1 based on the PIN. The correct PIN may be stored in a protected memory area of the chip card, and is used to derive a symmetric key S2. Alternatively it can be stored in the protected memory area of the chip card also directly the key S2.
p0073The decryption of the cipher the communication parameter K1 with the key S2 has a communication parameter K2 to the result. Through this communication parameter K2, a second communication channel of the amount can be defined. Only if the PIN 'is true, that if the condition PIN' = PIN is satisfied, the communication parameters specified by the K1 and K2 communication channels are identical.
p0074In step 210, the smart card terminal generates a chip-card command and sends this via the first, specified by the communication parameters K1 communication channel to the smart card (step 212). In step 214, the smart card may receive the chip-card command only when the second communication channel to which the smart card is adapted to receive, identical to the first communication channel, that is, if the condition PIN 'is = PIN met. In the opposite case, the chip card ignores the received on the first communication channel cipher and increments the failure-service counter.
p0075In the communication parameter K1 may be in one embodiment of the invention, a public key of the smart card terminals. The cipher of this public key, which has been generated using the key S1 by symmetric encryption is transmitted from the smart card terminal to the IC card. The smart card receives only the correct public key of the Chipkartert terminals, if the condition in turn PIN 'is = PIN fulfilled because only then manages the decryption of the ciphertext using the key S2 (cf. the embodiment of the<figref idrefs="f0001">figure 1</figref>). The public key of the smart card, for example, from an external key server over a network, especially the Internet, query the smart card terminal.
p0076From the private key of the smart card terminals and the public key of the smart card, the smart card terminal may derive a symmetric key S3 after the Diffie-Hellman method. Accordingly, the chip card from the public key of the smart card terminals and its private key can also be a symmetric key derived S4 after the Diffie-Hellman method. The key S3 and S4 are the same, if the condition PIN 'is = PIN met.
p0077The first communication channel (compare 112 of the communication channel <figref idrefs="f0001">figure 1</figref>) Is at least complementary defined S3 = S4 in this embodiment on the symmetric key. The transmitted from the chip card terminal to the chip card chip card command is namely encrypted using the symmetric key S3, and can only be decrypted by the smart card, ie received when the chip card command can be decrypted using the key S4. Otherwise, the smart card command is ignored and the false-service counter is incremented.
p0078The <figref idrefs="f0003">figure 3</figref> shows an embodiment of an inventive chip card and a chip card terminal according to the invention, wherein a process for the discrete logarithm cryptography to generate the key S3 or S4 is applied. In addition according to the embodiment<figref idrefs="f0001">figure 1</figref> serves the processor 118 for executing program instructions 148, through which a so-called Key Establishment Scheme is given for generating the symmetric key S3.
p0079The Key Establishment Scheme works by a process of the discrete logarithm cryptography (DLC), in particular of the elliptic curve cryptography (EEC), preferably according to one elliptic curve Diffie-Heflman method (ECDH). To generate the symmetric key S3, the program instructions generate 148 first first Domain parameter, referred to as D1.
p0080In addition, the communication module 126 may generate a first channel parameter KA1 or to select from a predefined list, which, for example, specifies the physical properties of the first communication channel. The first channel parameter KA1 corresponding to the channel parameters K1 in the embodiment of<figref idrefs="f0001">figure 1</figref>,
p0081The domain parameters D1 and or the channel parameters KA1 are encrypted using the key S1 by the program instructions 128th Consisting of KA1, D1 obtained with the aid of the key S1 cipher text 110 is transmitted via the predetermined communication channel 108 from the interface 102 to the interface 106th
p0082The smart card 104 decrypts the ciphertext 110 using the symmetric key S2. As a result of decoding the chip card 104 obtains the second channel parameter KA2, the communication parameter K2 in the embodiment<figref idrefs="f0001">figure 1</figref> equivalent. Further, the IC card receives the domain parameters D2. The channel parameter KA2 is processed by the communication module 134 to determine, for example, the physical specification of the second communication channel 146th
p0083The smart card 104 has in addition to the embodiment of the <figref idrefs="f0001">figure 1</figref> Program instructions 150 that the program instructions 148 correspond in their functionality, and is implemented by the chip on the card side, the Key Establishment Scheme.
p0084On the part of the chip card terminal is derived by executing the program instructions 148 from the domain parameters D1, the symmetric key S3, which is stored in a memory 152 of the smart card terminals 100th Accordingly, the part of the chip card 104 is derived by executing the program instructions 150 from the domain parameters D2 a symmetric key S4, which is stored in a memory 154 of the smart card 104th
p0085The chip-card command 122 is encrypted before it is sent through the smart card terminal with the symmetric key S3 and then transmitted over the specified by the channel parameter KA1 first communication channel 112th A receiving the chip-card command 122 by the smart card 104 is only possible if both KA2 = KA1 and D2 = D1, which in turn is only possible, if the condition PIN 'is = PIN met.
p0086Of particular advantage in this embodiment is that the transfer of the domain parameters D1 via the predefined communication channel 108 by a third party can not be spied on, since the transfer of the domain parameters D1 takes place in an encrypted form.
p0087The <figref idrefs="f0004">figure 4</figref> shows a corresponding flow chart. In step 400, a PIN 'in the chip card terminal is input by a user. From PIN 'the symmetric key S1 is derived.
p0088In step 402, the Key Establishment Scheme is started. Then a set of domain parameters D1 generated in the step 404th With the help of the domain parameters D1, the symmetric key S3 is generated by the smart card terminal. Further generated KA1 in step 406 by the smart card terminal of the channel parameters, or read from a predetermined list.
p0089In step 408, the domain parameters D1 and / or the channel parameters KA1 encrypted with the key S1. For example, the domain parameters D1 and the channel parameters KA1 to chain together, resulting in a single communication parameters results, which is then encrypted with the key S1. Alternatively, only the domain parameters D1 or only the channel parameters KA1 or a respective subset of the domain and / or channel parameters are encrypted with the key S1. The encryption with the key from the S1 resulting cipher text as well as any remaining unencrypted domain and / or channel parameters are stored in step 410 of the chip-card terminal to the IC card via the predefined channel (compare 108 of the communication channel<figref idrefs="f0001">figures 1</figref> and <figref idrefs="f0003">3</figref>) transfer.
p0090In step 412, the smart card tries to decrypt the ciphertext using the key S2. It receives the smart card 104, the channel parameter KA2 and the domain parameters D2. From the domain parameters D2 manages the smart card 104 the key S4.
p0091In step 414, the smart card terminal 100 generates a chip-card command, which is encrypted with the key S3 (step 416) for this to be transmitted through the defined by the channel parameter KA1 first communication channel (see communication channel 112 in the embodiments of <figref idrefs="f0001">figures 1</figref> and <figref idrefs="f0003">3</figref>). The smart card terminal 100 sends the smart card command in step 418th
p0092Correct reception of this cipher by the chip card is in the step 420 only possible when the second communication channel 146 corresponds to the first communication channel 112, that is, when KA2 = is KA1, and further when a decoding of the chip card commands with the key S4 possible that is, when S4 is = S3. The conditions KA2 = KA1 and S4 = S3 but can only be met if the correct PIN 'has been entered by the user in the chip card terminal, ie if PIN' = PIN is.
LIST OF REFERENCE NUMBERS
p0093<dl id="dl0002" compact="compact"><dt>100</dt><dd>Chip card terminal</dd><dt>102</dt><dd>interface</dd><dt>104</dt><dd>smart card</dd><dt>106</dt><dd>interface</dd><dt>108</dt><dd>predefined communication channel</dd><dt>110</dt><dd>communication parameters</dd><dt>112</dt><dd>first Kommurtikatianskanal</dd><dt>114</dt><dd>User interface</dd><dt>116</dt><dd>PIN CODE'</dd><dt>118</dt><dd>processor</dd><dt>120</dt><dd>application program</dd><dt>122</dt><dd>Smart card command</dd><dt>124</dt><dd>Chip card function</dd><dt>126</dt><dd>communication module</dd><dt>128</dt><dd>program instructions</dd><dt>130</dt><dd>key generator</dd><dt>132</dt><dd>processor</dd><dt>134</dt><dd>communication module</dd><dt>136</dt><dd>program instructions</dd><dt>138</dt><dd>protected memory area</dd><dt>140</dt><dd>pin code</dd><dt>142</dt><dd>key generator</dd><dt>144</dt><dd>False-service counter</dd><dt>146</dt><dd>second communication channel</dd><dt>148</dt><dd>program instructions</dd><dt>150</dt><dd>program instructions</dd><dt>152</dt><dd>memory</dd><dt>154</dt><dd>memory</dd></dl>
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0730253B1 | Cites | European Patent Office (EPO) | Applicant |
| EP1752937A1 | Cites | European Patent Office (EPO) | Search report |
| EP1752937A1 | Cites | European Patent Office (EPO) | Search report |
| DE19507043A1 | Cites | Germany | Applicant |
| DE19507044C2 | Cites | Germany | Applicant |
| DE19850307C2 | Cites | Germany | Applicant |
| US2002129247A1 | Cites | United States of America | Search report |
| US2002129247A1 | Cites | United States of America | Search report |
| DE3523237A1 | Cites | Germany | Applicant |
| US5241599A | Cites | United States of America | Applicant |
| US6792533B2 | Cites | United States of America | Applicant |
| US7139917B2 | Cites | United States of America | Applicant |
| "Applied Cryptography, Protocols, Algorithms, and Source Code in C", 1 January 1996, JOHN WILEY & SONS, New York, article BRUCE SCHNEIER: "Applied Cryptography, Protocols, Algorithms, and Source Code in C", pages: 513 - 525, XP055056127 | Non-patent | – | Search report |
| CHRISTIAN HAINZ: "Kryptographie und elliptische Kurven", 1 April 2001 (2001-04-01), pages 2 - 14, XP055056091, Retrieved from the Internet <URL:http://homepages.thm.de/~hg10013/Lehre/MMS/SS01_WS0102/Elyps/index.html> [retrieved on 20130312] | Non-patent | – | Search report |
| BRUCE SCHNEIER: "Applied Cryptography", 1996, JOHN WILEY AND SONS, XP002520924 | Non-patent | – | Search report |
| STANDARDS FOR EFFICIENT CRYPTOGRAPHY, SEC1: ELLIPTIC CURVE CRYPTOGRAPHY, CERTICOM RESEARCH, 20 September 2000 (2000-09-20) | Non-patent | – | Applicant |
21 members in 7 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 102007000589 | Germany | – | |
| 102007000589 | Germany | A | |
| 08845554 | European Patent Office (EPO) | A |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| WO2009056463A2 | World Intellectual Property Organization (WIPO) | A2 | |
| DE102007000589B3 | Germany | B3 | |
| WO2009056463A3 | World Intellectual Property Organization (WIPO) | A3 | |
| DE102007000589B9 | Germany | B9 | |
| EP2218028A2 | European Patent Office (EPO) | A2 | |
| US2010223479A1 | United States of America | A1 | |
| CN101842792A | China | A | |
| US8353054B2 | United States of America | B2 | |
| EP2595083A1This record | European Patent Office (EPO) | A1 | |
| EP2595085A2 | European Patent Office (EPO) | A2 | |
| CN101842792B | China | B | |
| CN103258169A | China | A | |
| EP2595085A3 | European Patent Office (EPO) | A3 | |
| EP2218028B1 | European Patent Office (EPO) | B1 | |
| EP2595083B1 | European Patent Office (EPO) | B1 | |
| CN103258169B | China | B | |
| ES2635616T3 | Spain | T3 | |
| PL2595083T3 | Poland | T3 | |
| EP2595085B1 | European Patent Office (EPO) | B1 | |
| ES2690366T3 | Spain | T3 | |
| PL2595085T3 | Poland | T3 |
67 legal events, as 11 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Full renewal or maintenance fee paidST27 STATUS EVENT CODE: U-0-0-U10-U11 (AS PROVIDED BY THE NATIONAL OFFICE)U11 | U11 | CH | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidated european patentMG4D | MG4D | LT | |
| Fee paymentPLFP | PLFP | FR | |
| Definitive protectionFG2A | FG2A | ES | |
| Translation for ep filed (entry of ep into country)FP | FP | NL | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2595083
- Application
- 131550972
Titles3
- German
- Verfahren zum Schutz einer Chipkarte gegen unberechtigte Benutzung, Chipkarte und Chipkarten-Terminal
- English
- Method for protecting a chip card against unauthorised use, chip card and chip cards terminal
- French
- Procédé destiné à protéger une carte à puce contre les utilisations non autorisées, carte à puce et terminal de carte à puce
Classification
- CPC, 7
- G06F21/77
- H04L9/3013
- H04L9/3066
- H04L9/3215
- H04L9/3226
- H04L2209/56
- H04L2209/805
- IPC, 4
- G06F21 30
- G06F21 77
- H04L9 30
- H04L9 32
Designated states1
- Contracting states, 1
- Türkiye