Method for protecting a chip card against unauthorised use, chip card and chip cards terminal
14 claims: 10 independent, 4 dependent
- 1Verfahren zum Schutz einer Chipkarte (104) gegen unberechtigte Benutzung mit folgenden Schritten:- Eingabe einer ersten Kennung (116) in einen Chipkarten-Terminal (100), - Erzeugung eines Chiffrats aus zumindest einem ersten Kommunikationsparameter (K1;KA1, D1) mit Hilfe eines aus der ersten Kennung abgeleiteten ersten symmetrischen Schlüssels (S1), wobei mit Hilfe des Kommunikationsparameters ein geschützter erster Kommunikationskanal (112) zwischen dem Chipkarten-Terminal und der Chipkarte definierbar ist, - Übertragung des Chiffrats über einen vordefinierten Kommunikationskanal (108) von dem Chipkarten-Terminal an die Chipkarte, - Versuch einer Entschlüsselung des Chiffrats mit Hilfe eines zweiten symmetrischen Schlüssels (S2) durch die Chipkarte, wobei das Resultat der Entschlüsselung nur dann der erste Kommunikationsparameter ist, wenn der erste symmetrische Schlüssel dem zweiten symmetrischen Schlüssel gleicht, sodass der geschützte erste Kommunikationskanal nur dann zwischen dem Chipkarten-Terminal und der Chipkarte definierbar ist, wenn die erste Kennung zutreffend ist, dadurch gekennzeichnet, dass es sich bei dem ersten Kommunikationsparameter um einen öffentlichen Schlüssel des Chipkarten-Terminals handelt, wobei die Chipkarte im Fall, dass die Entschlüsselung des Chiffrats gelingt, aus dem öffentlichen Schlüssel nach dem Diffie-Hellman (DH)-Verfahren einen weiteren symmetrischen Schlüssel (S4) zur Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte ableitet, wobei durch die Verschlüsselung mit dem weiteren symmetrischen Schlüssel der erste Kommunikationskanal definiert ist.
- 2Verfahren nach Anspruch 1, wobei es sich bei dem ersten Kommunikationsparameter um einen ersten Domainparameter (D1) für die Durchführung eines diskreten logarithmischen kryptographischen Verfahrens zur Erzeugung eines dritten symmetrischen Schlüssels (S3) durch das Chipkarten-Terminal und eines vierten symmetrischen Schlüssels (S4) durch die Chipkarte und handelt, wobei die dritten und vierten symmetrischen Schlüssel identisch sind, wenn die erste Kennung zutreffend ist, wobei der dritte und vierte symmetrische Schlüssel zur Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte über den geschützten ersten Kommunikationskanal vorgesehen sind.
- 3Verfahren nach Anspruch 2, wobei es sich bei dem diskreten logarithmischen kryptographischen Verfahren um ein elliptische Kurven kryptographisches Verfahren handelt.
- 4Verfahren nach Anspruch 2 oder 3, wobei es sich bei dem diskreten logarithmischen kryptographischen Verfahren um ein elliptisches Kurven Diffie-Hellman-Verfahren handelt.
- 5Verfahren nach einem der vorhergehenden Ansprüche, wobei die erste Kennung als Seed Value für die Ableitung des ersten symmetrischen Schlüssels durch das Chipkarten-Terminal verwendet wird.
- 6Verfahren nach einem der vorhergehenden Ansprüche, wobei auf der Chipkarte eine zweite Kennung (140) gespeichert ist, aus der der zweite symmetrische Schlüssel ableitbar ist.
- 7Verfahren nach einem der vorhergehenden Ansprüche, wobei der zweite symmetrische Schlüssel in einem geschützten nicht-volatilen Speicherbereich der Chipkarte gespeichert ist.
- 8Verfahren nach einem der vorhergehenden Ansprüche, wobei das Resultat der Entschlüsselung ein nicht zutreffender zweiter Kommunikationsparameter (K2; D2, KA2) ist, wenn die erste Kennung nicht zutreffend ist, wobei durch den zweiten Kommunikationsparameter ein nicht zutreffender zweiter Kommunikationskanal (146) durch die Chipkarte definierbar ist, mit folgenden weiteren Schritten:- Sendung eines Chipkarten-Kommandos (122) von dem Chipkarten-Terminal an die Chipkarte auf dem geschützten ersten Kommunikationskanal, - Ignorierung des Chipkarten-Kommandos durch die Chipkarte und Reduzierung der Anzahl der verbleibenden Fehlbedienungen, wobei die Chipkarte oder eine Chipkartenfunktion der Chipkarte bei Überschreitung einer vorgegebenen Anzahl von Fehlbedienungen gesperrt wird.
- 9Chipkarte mit - einer Schnittstelle (106) zur Kommunikation über einen vordefinierten Kommunikationskanal (108) und mehreren weiteren Kommunikationskanälen (112, 146,...) mit einem Chipkarten-Terminal (100), - Mitteln (132, 136) zur Entschlüsselung eines auf dem vordefinierten Kanal empfangenen Chiffrats, welches mit Hilfe eines ersten symmetrischen Schlüssel verschlüsselt ist, der von einer zuvor in den Chipkarten-Terminal eingegebenen ersten Kennung abgeleitet ist, mit Hilfe eines zweiten symmetrischen Schlüssels (S2), wobei die Entschlüsselung zumindest einen Kommunikationsparameter ergibt (K2;KA2, D2), wenn die zuvor in den Chipkarten-Terminal eingegebene erste Kennung (116) zutreffend ist und der erste symmetrische Schlüssel dem zweiten symmetrischen Schlüssel gleicht, wobei durch den Kommunikationsparameter einer der weiteren Kommunikationskanäle für die geschützte Kommunikation zwischen der Chipkarte und dem Chipkarten-Terminal eindeutig festgelegt ist, wobei durch den ersten Kommunikationsparameter ein öffentlicher Schlüssel angegeben wird, und - Mitteln (132) zur Durchführung eines Diffie-Hellman-Verfahrens zur Ableitung eines weiteren symmetrischen Schlüssels (S4) mit Hilfe des öffentlichen Schlüssels.
- 10Chipkarte nach Anspruch 9, mit Mitteln (150) zur Durchführung eines diskreten logarithmischen kryptografischen Verfahrens zur Erzeugung des weiteren symmetrischen Schlüssels (S4) aus Domainparametern, die durch den ersten Kommunikationsparameter angegeben werden, wobei der weitere symmetrische Schlüssel zur symmetrischen Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte über den festgelegten Kommunikationskanal (112) vorgesehen ist.
- 11Chipkarte nach einem der vorhergehenden Ansprüche 9 oder 10, mit einem nicht flüchtigen geschützten Speicherbereich zur Speicherung einer zweiten Kennung (140), aus der der zweite Schlüssel ableitbar ist.
- 12Chipkarte nach einem der vorhergehenden Ansprüche 9 bis 11, mit einem Fehlbedienungs-Zähler (144) zur Sperrung der Chipkarte, wenn die Anzahl der Fehlbedienungen einen vorgegebenen Schwellwert erreicht hat, wobei eine von der Chipkarte empfangene Nachricht, die auf einem der weiteren Kommunikationskanäle, welcher nicht der festgelegt Kommunikationskanal ist, an die Chipkarte gesendet wird, als Fehlbedienung gezählt wird.
- 13Chipkarte nach einem der vorhergehenden Ansprüche 9 bis 12, mit einer Erstbenutzerfunktion, wobei in einem Erstbenutzungszustand, ein bestimmter Kommunikationsparameter für eine erste Wahl des ersten Kommunikationskanals festgelegt ist, und wobei die Chipkarte aus ihrem Erstbenutzungszustand in einen Benutztzustand übergeht, wenn sie zum ersten Mal ein Chipkartenkommando (122) auf diesem ersten Kommunikationskanal empfängt.
- 14Chipkarten-Terminal mit - Mitteln (114) zur Eingabe einer ersten Kennung (116), - Mitteln zur Erzeugung eines Chiffrats aus zumindest einem ersten Kommunikationsparameter (K1;KA1, D1) mit Hilfe eines aus der ersten Kennung abgeleiteten ersten symmetrischen Schlüssels (S1), wobei mit Hilfe des Kommunikationsparameters ein geschützter erster Kommunikationskanal (112) zwischen dem Chipkarten-Terminal und der Chipkarte (104) definierbar ist, - Mitteln zum Senden des Chiffrats über einen vordefinierten Kommunikationskanal (108) an die Chipkarte, - Mitteln (148) zur Erzeugung von Domainparametern (D1) für die Durchführung eines diskreten logarithmischen kryptographischen Verfahrens für die Ableitung eines weiteren symmetrischen Schlüssels (S3) zur Verschlüsselung der Kommunikation zwischen dem Chipkarten-Terminal und der Chipkarte, wobei der erste Kommunikationsparameter die Domainparameter angibt.
Independent claims14
92 paragraphs in 1 section, as filed
0001The invention relates to a method for protecting a chip card against unauthorized use, a chip card and a chip card terminal.
0002For the unblocking of a chip card function, a prior user identification may be required against the chip card, as is known per se from the prior art. The most common user identification is the input of a secret identifier, which is generally referred to as a PIN (Personal Identification Number) or a CHV (Card Holder Verification). Such identifiers generally consist of a numeric or alphanumeric string. For user identification, the identification is entered by the user on the keyboard of a smart card terminal or a computer to which a smart card reader is connected, and then sent to the smart card. This compares the entered ID with the stored ID and then divides the result to the terminal
0003The PINs can be used to distinguish between static and changeable pins. A static PIN can no longer be changed by the user and must be memorized by the user. If it is known, then the card user has to destroy his chip card in order to prevent misuse by unauthorized persons and to obtain a new chip card with a different static PIN. The user also needs a new chip card if he or she has forgotten the static PIN.
0004A changeable PIN can be changed by the user at will. In order to change the PIN, it is always necessary to pass the currently valid PIN, for security reasons, since otherwise an existing PIN could be replaced by an attacker with its own PIN.
0005The situation is different with the so-called super PINs or PUKs (Personal Unlocking Key). These usually have more digits than the actual PIN, and are used to reset a PIN that is at its maximum value (also referred to as a "bad service counter") to a PIN. With the PUK also a new PIN is transferred to the chip card, because a backed maloperation counter is little use, if one has forgotten the PIN. This is usually the case when the malfunction counter reaches its maximum value.
0006There are also applications that use transport PINs. The chip card is personalized with a random PIN which the card user receives in a PIN letter. At the first entry, however, the chip card prompts him to replace the personalized PIN with his own. In a similar method, called a "zero-PIN method", the chip card is pre-assigned with a trivial PIN, such as "0000", and a change is also forced by the chip card during the first use (cf.<patcit id="pcit0001" dnum="DE3523237A1"><text>DE 35 23 237 A1</text></patcit>. <patcit id="pcit0002" dnum="DE19507043A1"><text>DE 195 07 043 A1</text></patcit>. <patcit id="pcit0003" dnum="DE19507044C2"><text>DE 195 07 044 C2</text></patcit>. <patcit id="pcit0004" dnum="DE19850307C2"><text>DE 198 50 307 C2</text></patcit>. <patcit id="pcit0005" dnum="EP0730253B1"><text>EP 0 730 253 B1</text></patcit>). Such a procedure provides a so-called first-user function, which gives the authorized user security that no unauthorized use of the chip card by a third party took place before its initial use.
0007From the <patcit id="pcit0006" dnum="DE19850307C2"><text>DE 198 50 307 C2</text></patcit> A method for protection against misuse of chip cards is known. The chip card has a first user function which, upon the first use of the data and / or functions of the chip card, requires the presetting of a personal secret number (PIN) arbitrarily selectable by the user Used status. A later modification of the personal secret number is made possible by a higher-level unlock code.
0008Prior art has also disclosed methods for verifying an identifier in which the transmission of the identifier itself is not required, such as, for example, Strong Password Only Authentication Key Exchange (SPEKE), Diffie-Hellman Enciphered Key Exchange (DH-EKE ), Bellovin-Merritt Protocol, or Password Authenticated Connection Establishment (PACE). The SPEKE protocol is, for example, known from<u>www.jablon.org/speke97.html,</u><patcit id="pcit0007" dnum="US6792533B2"><text>US 6,792,533 B2</text></patcit> and <patcit id="pcit0008" dnum="US7139917B2"><text>US 7,139,917 B2</text></patcit>, Among other things also from<u>www.jablon.org/speke97.html</u> The DH-EKE protocol is known. Among other things,<patcit id="pcit0009" dnum="US5241599A"><text>US 5,241,599</text></patcit> The Bellovin-Merritt protocol is known. Out<u>www.heise.de/security/news/meldung/85024</u> The PACE protocol, which is particularly suitable for elliptic curve cryptography, is known.
0009On the other hand, the object of the invention is to provide an improved method for protecting a chip card against unauthorized use. The object of the invention is also to provide an improved chip card and an improved chip card terminal.
0010The objects on which the invention is based are in each case solved with the features of the independent patent claims. Preferred embodiments are given in the dependent patent claims.
0011According to the invention, a method for protecting a chip card against unauthorized use is provided. The method involves, in addition to the chip card itself, a chip card terminal.
0012By "chip card terminal" is meant here any device which is designed for communication with a chip card in order, for example, to direct chip card commands to the chip card and to receive corresponding responses from the chip card. The communication between the chip card and the chip card terminal can thereby be contact-based, wireless, for example by means of an RFID method, or selectively contact-controlled or wireless, in particular via a so-called dual-mode interface. The chip card terminal can be a so-called class 1, 2 or 3 chip card reader with or without its own keyboard or a computer to which a chip card reader is connected. The chip card terminal can also be a terminal provided for a specific purpose,
0013The term "protection of a chip card" is understood here to mean the protection of the chip card as a whole or the protection of one or more chip card functions of the chip card. For example, according to the invention, a particularly protective chip card function of the chip card is protected, such as, for example, a signature function for generating an electronic signature, a payment function, an authentication function or the like.
0014According to one embodiment of the method according to the invention, the authorized user receives from the chip card issuing site a secret identifier, which is generally referred to as a PIN. In order to use the chip card, an identification must first be entered into the chip card terminal, which is hereinafter referred to as PIN '. Only if the PIN 'is identical to the PIN is the use of the chip card or the protected chip card function possible.
0015For this purpose, the chip card terminal generates a cipher from at least one first communication parameter by means of a first symmetrical key. The first symmetric key may be the PIN itself, or a symmetric key derived from the PIN. For example, the PIN 'serves as a so-called seed value for the generation of the first symmetric key by the chip card terminal.
0016The at least one communication parameter is such that a protected first communication channel between the chip card terminal and the chip card can be defined. In order to be able to construct this protected first communication channel between the chip card and the chip card terminal, the ciphertext of the first communication parameter obtained with the aid of the first symmetrical key is first transmitted from the chip card terminal to the chip card via a predefined communication channel. This predefined communication channel is thus defined as standard for establishing an initial communication between the chip card terminal and the chip card.
0017After the cipher has been transmitted via this predefined communication channel from the chip card terminal to the chip card, the chip card attempts to decrypt this cipher by means of a second symmetric key. This decryption is successful only if the second symmetric key is equal to the first key, ie if the prerequisite PIN '= PIN is satisfied.
0018The establishment of a communication link via the protected first communication channel is therefore only possible if the condition PIN '= PIN is satisfied, since the chip card only becomes aware of the first communication parameter by which the protected first communication channel can be defined.
0019If, on the other hand, the condition PIN '= PIN is not fulfilled, the first symmetrical key derived from the PIN does not match the second symmetric key of the chip card. The consequence of this is that the deciphering of the ciphertext received by the chip card terminal by the chip card does not produce the first communication parameter by means of the second symmetric key but, for example, a second communication parameter which deviates from the first communication parameter.
0020The second communication parameter can be used to define a second communication channel which differs from the first communication channel. However, when the chip card receives a signal on the first communication channel, it is ignored because the chip card expects a signal on the second communication channel. As a result, there is no communication between the chip card terminal and the chip card if the condition PIN '= PIN is not fulfilled.
0021According to one embodiment of the invention, the communication parameter can be a public key of an asymmetric key pair of the chip card terminal. The public key of the chip card terminal is encrypted with the first symmetric key obtained from the first identifier and is transmitted via the predefined key to determine the symmetric key for the communication between the chip card terminal and the chip card. For example, according to the Diffie-Hellman method Communication channel to the chip card.
0022Only if the condition PIN '= PIN is fulfilled, the chip card receives the correct public key of the chip card terminal. The chip card terminal generates the third symmetric key from the public key of the chip card, which is, for example, interrogated by a key server, according to the Diffie-Hellman method, while the chip card consists of its private key and the decrypted by means of the second symmetric key The fourth symmetric key is equal to the third symmetric key only if the condition PIN '= PIN is satisfied.
0023The third and the identical fourth symmetrical keys are used to encrypt signals, in particular chip card commands and responses to such chip card commands, which are exchanged between the chip card terminal and the chip card via the first communication channel. This first communication channel is at least additionally defined via the third symmetrical key, by means of which the communication via the first communication channel is encrypted using a symmetrical encryption method.
0024According to one embodiment of the invention, a method of discrete logarithmic cryptography (DLC) is used for the generation of a third key by the chip card terminal and a fourth symmetric key by the chip card, the fourth symmetric key being equal to the third symmetric key, If the condition PIN '= PIN is satisfied.
0025For the determination of the third symmetrical key, in principle arbitrary methods of discrete logarithmic cryptography are used as described, for example, in the standard National Institute of Standards and Technology (NIST), NIST Special Publication 800-56A, March 2007 and in Standards for Efficient Cryptography, SEC1: Elliptic Curve Cryptography, Certicom Research, September 20, 2000, version 1.0. Such methods require the generation of so-called domain parameters for the purpose of generating the identical third and fourth symmetric keys through the chip card terminal or the chip card.
0026According to one embodiment of the invention, a method of elliptic curve cryptography (ECC) is used as DLC, in particular Elliptic Curve Diffie-Hellman (ECDH).
0027According to one embodiment of the invention, the first identifier, ie the PIN, which is entered into the chip card terminal, is used as a so-called seed value for the derivation of the first symmetric key. This produces a key with a larger length than would be the case if the first identifier was used directly as a key.
0028According to one embodiment of the invention, a second identifier, ie the PIN, is stored on the chip card, from which the second symmetric key can be derived for the deciphering of the cipher initially received by the chip card terminal. To derive the second symmetric key from the second identifier, the second identifier can be used as a seed value.
0029According to one embodiment of the invention, the PIN itself is not stored in the chip card, but only the second symmetric key. The second symmetric key is preferably stored in a non-volatile protected memory area of the chip card. In contrast to the prior art, the storage of the PIN as a reference value in the chip card is therefore not required.
0030According to one embodiment of the invention, the chip card has an error control counter. If the first and second communication channels do not match because of an error input of the PIN ', the chip card increments or decrements the error control counter with each message that the chip card receives on a channel other than the second or the predefined communication channel. Such messages, which the chip card receives on a channel other than the second or the predefined communication channel, are otherwise ignored by the chip card. If the number of defect operations exceeds a predetermined threshold value, the chip card as a whole or a certain chip card function is reversibly or irreversibly blocked.
0031According to one embodiment of the invention, the chip card has a first user function. The unused chip card is in its initial use state in which a specific communication parameter for a first choice of the first communication channel is established. The chip card changes from its initial use state into a state of use when it first receives a chip card command on this first communication channel. For the further use of the chip card, a different communication parameter must then be selected on the part of the chip card terminal.
0032In a further aspect, the invention relates to a chip card with a chip card with an interface for communication via a predefined communication channel and several further communication channels with a chip card terminal, means for decrypting a ciphertext received on the predefined channel, which is encrypted with the aid of a first symmetrical key , With the aid of a second symmetrical key, the decryption at least providing a communication parameter when a first identifier which has previously been input into the chip card terminal is applicable, wherein one of the further communication channels for the protected communication between the chip card and the chip card terminal is determined by the communication parameter Clearly defined.
0033In a further aspect, the invention relates to a chip card terminal having means for inputting a first identifier, means for generating a ciphertext from at least one first communication parameter by means of a first symmetrical key derived from the first identifier, a protected first communication channel being provided by means of the communication parameter Between the chip card terminal and the chip card, and means for sending the ciphertext to the chip card via a predefined communication channel.
0034In a further aspect, the invention relates to a chip card having a protected non-volatile memory area for storing the second key.
0035In a further aspect, the invention relates to a chip card terminal.
0036Embodiments of the invention will be explained in more detail with reference to the drawings. Show it:<dl id="dl0001"><dt>FIG</dt><dd>A block diagram of a first embodiment of a chip card according to the invention and of a chip card terminal,</dd><dt>FIG</dt><dd>A flowchart of an embodiment of a method according to the invention,</dd></dl>
0037The smart card terminal 100 has a user interface 114 such as a keyboard or a graphical user interface via which a first identifier 116 can be input. This first identifier is hereinafter referred to as PIN 'without limitation to the general public.
0038The chip card terminal 100 has at least one processor 118 for executing an application program 120. The application program 120 can trigger the generation of a chip card command 122 in order to call a particular chip card function 124 of the chip card 104. For example, the application program 120 needs the smart card function 124 for an authenticity check, for generating a digital signature, for verifying an authorization, in particular access authorization, making a financial transaction, or the like.<dl id="dl0002"><dt>FIG</dt><dd>A block diagram of a further embodiment of a chip card according to the invention and a chip card terminal,</dd><dt>FIG</dt><dd>3 shows a flow chart of a further embodiment of a method according to the invention.</dd></dl>
0039In the following figures, corresponding elements of the various embodiments are identified by the same reference symbols.
0040The <figref idrefs="f0001">FIG</figref> 10 shows a block diagram of a chip card terminal 100. The chip card terminal 100 has an interface 102 for communication with a chip card 104 which has a corresponding interface 106. Preferably, the interfaces 102 and 106 are designed for wireless communication, for example via radio, in particular according to an RFID method.
0041The interfaces 102 and 106 are, for example, designed such that different communication channels can be established between the interfaces 102, 106, whereby these communication channels differ from one another on a physical and / or logic level. For example, communication channels of different transmission frequencies can be established. Communication channels can also be established on the basis of different frequency hopping schemes. By "frequency hopping" is meant here frequency hopping methods, according to which the frequencies used for data transmission are continually changed according to a defined scheme.
0042The interfaces 102, 106 can also be designed in such a way that different communication channels are constructed by means of different coding methods and / or modulation methods such as, for example, frequency modulation, amplitude modulation, phase modulation, pulse width modulation or other modulation methods.
0043The various communication channels that can be established between the interfaces 102 and 106 are hereinafter referred to as the "set of communication channels".
0044One of the communication channels 108 from the set of communication channels is predefined for the initial communication between the chip card terminal 100 and the chip card 104. For example, the communication channel is predefined with regard to its transmission frequency and the modulation and coding methods to be used.
0045The predefined communication channel serves for the transmission of a cipher 110 of the at least one communication parameter K1 from the chip card terminal 100 to the chip card 104 in order to notify the chip card 104 of the communication channels 112 of the set of communication channels for the subsequent communication with the chip card terminal 100 Should be used.
0046The communication parameter K1 thus contains an indication which uniquely specifies this communication channel 112. This information can be given in the form of a code word. A so-called look-up table can be stored in the chip card 104 in a non-volatile memory in which a specification of one of the communication channels is assigned to the set of communication channels to the possible code words.
0047For the selection of a communication channel from the set of communication channels, all possible communication channels which can be established between the interfaces 102, 106 can be available or a selection thereof, in which case each of the communication channels of the set of communication channels actually used for the communication between the interface 102, 106 is assigned to a unique code word, which can be transmitted as a communication parameter 110 from the chip card terminal 100 to the chip card 104.
0048The processor 118 also serves to carry out the program formulations of a communication module 126, which is used to select the communication channel 112 from the set of the communication channels and thus for the selection of the communication parameter 110. The selection of the communication parameter 110 can be carried out according to a predetermined scheme or randomly, in particular pseudo-randomly. For example, the communication module 126 stores a list of various communication parameters 110, which are processed cyclically.
0049The processor 118 also serves to execute program instructions 128 for a symmetrical encryption of the communication parameters 110. Encryption is carried out with the aid of the PIN '. To this end, the program interfaces 128 may include a key generator 130.
0050The key generator 130 can be designed such that it generates a first symmetrical key from the PIN 'as a seed value, which is hereinafter referred to as S1. The first symmetrical key S1 is used for the symmetrical encryption of the communication parameter K1 selected by the communication module 126.
0051The ciphertext of the communication parameter K1 resulting from the symmetrical encryption with the first symmetrical key S1 is transmitted from the interface 102 to the interface 106 via the predefined communication channel 108.
0052The chip card 104 has a processor 132, which is used for executing the program instructions of a communication module 134. The communication module 134 is designed for processing the communication parameter K1 received by the chip card terminal 100. The communication module 134 can, for example, access the communication parameter K1 as a key on an allocation table, in particular a lookup table, in order to query the parameters of the communication channel 112 selected by the chip card terminal 100, such as its transmission frequency and / And modulation methods.
0053The processor 132 also serves to execute program versions 136 for symmetrically decrypting the cipher 110 received by the smart card 104 from the smart card terminal 100. For example, the chip card 104 has a protected memory area 138 in which a second identifier 140 is stored. The second identifier is also referred to as a PIN without restriction of generality. The PIN is communicated to the authorized user of the chip card separately with the handing-over of the chip card 104, for example in the form of a so-called PIN letter.
0054The program interfaces 136 may include a key generator 142 that uses the PIN as a so-called seed value to derive a second symmetric key therefrom. This second symmetrical key is hereinafter referred to as S2.
0055Alternatively, the second symmetric key S2 may be stored in the protected memory area 138 of the chip card 104 instead of the PIN 140. The key generator 142 and a storage of the PIN 140 in the chip card 104 are then superfluous. In contrast to the state of the art, the PIN 140 is not necessarily stored on the chip card 104 as a reference value for checking the correctness of the PIN '116.
0056The chip card 104 may further include a mismatch counter 144. The mismanage counter 144 is designed such that any erroneous operation of the smart card 104 is counted. The number of faulty operations is compared with a predetermined threshold value. When this threshold value is reached, at least the chip card function 124 to which the incorrect operation counter 144 is assigned is reversibly or irreversibly blocked.
0057The chip card 104 may also have a first-use function. For example, the initial use status of the chip card 104 is defined by a particular communication parameter that specifies one of the communication channels of the set that must be used for the first use of the chip card.
0058The use of the chip card 104 is carried out as follows: A user enters the PIN '116 into the chip card terminal 100 via the user interface 114. This can be done according to a corresponding requirement of the application program 120. The communication module 126 then selects a first one of the possible communication parameters, for example, from the predefined list of the communication parameters, ie, the communication parameter K1.
0059The key generator 130 generates the first symmetric key S1 from the PIN '. The communication parameter K1 is then encrypted by executing the program instructions 128 using the first symmetric key S1. The resulting cipher 110 of the communication parameter K1 is then sent via the predefined communication channel 108 from the interface 102 to the interface 106 of the chip card 104.
0060The chip card 104, if necessary, derives the second symmetrical key S2 from the PIN or directly accesses the protected memory area 138 via the second symmetrical key S2. With
0061The attempt to decrypt the cipher 110 of the communication parameter K1 received from the chip card terminal 100 by executing the program instructions 136 from the chip card 104 is undertaken.
0062The result of this decryption attempt is a second communication parameter, which is hereinafter referred to as K2, and which is passed to the communication module 134. This communication parameter K2 is identical to the communication parameter K1 only if the condition PIN '= PIN is satisfied, since only then can the first symmetric key S1, which has been used for the symmetrical encryption, be equal to the second symmetrical key S2, which Was used for the symmetrical decryption of the ciphertext of the communication parameter K1.
0063A second communication channel 146 can be defined by the communication parameter K2, since the communication module 134 with the communication parameter K2 accesses its allocation table. This second communication channel 146 is, in turn, identical to the first communication channel 112 only if the condition PIN '= PIN is satisfied.
0064After the transmission of the ciphertext of the communication parameter K1 via the predefined communication channel 108, the chip card terminal 100 generates the chip card command 122, which is sent via the first communication channel 112 from the interface 102 to the interface 106. The chip card 104 or its communication module 134 are set for reception on the second communication channel 146 on the basis of the communication parameter K2.
0065If the second communication channel 146 matches the first communication channel 112, the chip card command 122 is processed by the chip card 104 and the chip card function 124 is called. As a result, the chip card 104 generates a response to the chip card command 122 and transmits this response back to the chip card 100 via the first communication channel 112.
0066If, on the other hand, the second communication channel 146 is not identical to the first communication channel 112, the chip card 104 ignores the chip card command received on the first communication channel 112 and increments the error control counter 144.
0067For example, the communication channel 108 is defined by a transmission frequency of 9 GHz, the communication channel 112 is defined by a transmission frequency of 10 GHz, and the communication channel 146 by a transmission frequency of 11 GHz, the transmission frequencies of the communication channels 112 and 146 being different from each other since the signals transmitted into the chip card terminal 100 Entered PIN 'is not equal to the PIN. If the chip card 104 in this case receives a signal on the frequency 10 GHz from the chip card terminal 100, although it has expected a reception on the frequency 11 GHz, this signal is ignored and the fault control counter is incremented. This implies an implicit verification of the PIN 'without the PIN' having to be directly compared with the PIN,
0068The <figref idrefs="f0002">FIG</figref> 10 shows a corresponding flow chart. At step 200, the PIN 'is entered into the smart card terminal. The communication parameter K1 is then determined in step 202 by the chip card terminal 100 for selecting one of the communication channels from the set of communication channels. In step 204, the communication parameter K1 is encrypted symmetrically using the PIN '. This can be done in such a way that the first symmetrical key S1 is derived from the PIN 'with the aid of a key generator, which is then used to encrypt the communication parameter K1.
0069In step 206, the ciphertext of the communication parameter K1 generated by means of the key S1 is transmitted from the chip card terminal to the chip card via a predefined communication channel.
0070The chip card 104 makes the attempt to decrypt the communication parameter K1 on the basis of the PIN in step 208. The applicable PIN can be stored in a protected memory area of the chip card, and is used to derive a second symmetric key S2. Alternatively, the second symmetrical key S2 can also be stored directly in the protected memory area of the chip card.
0071The deciphering of the ciphertext of the communication parameter K1 with the second symmetric key S2 has a communication parameter K2 as a result. A second communication channel of the set can be defined by this communication parameter K2. The communication channels specified by the communication parameters K1 and K2 are identical only if the PIN 'is true, ie if the condition PIN' = PIN is fulfilled.
0072In step 210, the chip card terminal generates a chip card command and transmits this to the chip card via the first communication channel specified by the communication parameter K1 (step 212). In step 214, the chip card can receive the chip card command only if the second communication channel on which the chip card is set up for reception is identical to the first communication channel, ie if the condition PIN '= PIN is met. On the contrary, the chip card ignores the ciphertext received on the first communication channel and increments its erroneous counter.
0073In one embodiment of the invention, the communication parameter K1 can be a public key of the chip card terminal. The encryption key of this public key which has been generated by means of the first symmetric key S1 by symmetrical encryption is transmitted from the chip card terminal to the chip card. The chip card receives the correct public key of the chip card terminal only if the condition PIN '= PIN is fulfilled, since the decryption of the encrypting code can only be achieved with the aid of the second symmetric key S2 (cf.<figref idrefs="f0001">FIG</figref>). The chip card terminal can, for example, interrogate the chip card terminal's public key from an external key server via a network, in particular the Internet.
0074From the private key of the chip card terminal and the public key of the chip card, the chip card terminal can derive a third symmetrical key S3 according to the Diffie-Hellman method. Accordingly, the chip card from the public key of the chip card terminal and its private key can also derive a fourth symmetrical key S4 according to the Diffie-Hellman method. The third and fourth symmetrical keys S3 and S4 are identical when the condition PIN '= PIN is satisfied.
0075The first communication channel (compare communication channel 112 of FIG <figref idrefs="f0001">FIG</figref>) Is at least complementary to the third and fourth symmetrical keys S3 = S4 in this embodiment. The chip card command transmitted from the chip card terminal to the chip card is encrypted with the third symmetric key S3 and can only be decrypted by the chip card, ie, it can be received if the chip card command can be decrypted using the fourth key S4 , Otherwise, the chip card command is ignored and the fault counter is incremented.
0076The <figref idrefs="f0003">FIG</figref> Shows an embodiment of a chip card according to the invention and a chip card terminal according to the invention, a method for discrete logarithmic cryptography being used for the generation of the third and fourth symmetric keys S3 and S4. In addition to the embodiment according to FIG<figref idrefs="f0001">FIG</figref> The processor 118 is used to execute program instructions 148 through which a so-called key establishment scheme is provided for the generation of the third symmetric key S3.
0077The Key Establishment Scheme operates according to a method of discrete logarithmic cryptography (DLC), in particular elliptic curve cryptography (EEC), preferably according to an elliptic curve Diffie-Hellman method (ECDH). To generate the third symmetric key S3, the program interfaces 148 first generate first domain parameters, which are referred to as D1 later.
0078In addition, the communication module 126 can generate or read out a first channel parameter KA1 from a predefined list, which specifies, for example, the physical properties of the first communication channel. The first channel parameter KA1 corresponds to the channel parameter K1 in the embodiment of FIG<figref idrefs="f0001">FIG</figref>,
0079The domain parameters D1 and the channel parameter KA1 are encrypted by means of the first symmetric key S1 by the program interfaces 128. The cipher 110 obtained from KA1, D1 with the aid of the key S1 is transmitted from the interface 102 to the interface 106 via the predefined communication channel 108.
0080The chip card 104 decrypts the cipher 110 using the second symmetric key S2. As a result of the decryption, the chip card 104 receives the second channel parameter KA2, which corresponds to the communication parameter K2 in the embodiment of FIG<figref idrefs="f0001">FIG</figref> equivalent. The chip card also receives the domain parameter D2. The channel parameter KA2 is processed by the communication module 134 in order, for example, to determine the physical specification of the second communication channel 146.
0081The chip card 104, in addition to the embodiment of FIG <figref idrefs="f0001">FIG</figref> Programminstructions 150 which correspond in their functionality to the program instructions 148, and by which the key establishment scheme is implemented on the chip card side.
0082The third symmetrical key S3, which is stored in a memory 152 of the chip card terminal 100, is derived from the domain parameters D1 by the chip card terminal by execution of the program instructions 148. Accordingly, a fourth symmetrical key S4, which is stored in a memory 154 of the chip card 104, is derived from the domain parameters D2 by the execution of the program instructions 150 from the chip card 104.
0083The chip card command 122 is encrypted with the third symmetrical key S3 before its transmission by the chip card terminal and then transmitted via the first communication channel 112 specified by the channel parameter KA1. A receipt of the chip card command 122 by the chip card 104 is only possible if both KA2 = KA1 and D2 = D1, which is again possible only if the condition PIN` = PIN is fulfilled.
0084It is particularly advantageous in this embodiment that the transmission of the domain parameters D1 via the predefined communication channel 108 can not be spied by a third party since the transmission of the domain parameters D1 takes place in an encrypted form.
0085The <figref idrefs="f0004">FIG</figref> 10 shows a corresponding flow chart. At step 400, a PIN 'is entered into the smart card terminal by a user. The first symmetrical key S1 is derived from the PIN '.
0086In step 402, the Key Establishment Scheme is started. A set of domain parameters D1 is then generated in step 404. With the aid of the domain parameter D1, the third symmetrical key S3 is generated by the chip card terminal. Furthermore, the channel parameters KA1 are generated or read out from a predefined list in the step 406 by the chip card terminal.
0087In step 408, the domain parameters D1 and / or the channel parameters KA1 are encrypted with the first symmetric key S1. For example, the domain parameters D1 and the channel parameters KA1 are connected to one another, from which a single
0088Communication parameter, which is then encrypted with the first symmetric key S1. Alternatively, only the domain parameters D1 or only the channel parameters KA1 or a respective subset of the domain and / or channel parameters are encrypted with the first symmetrical key S1. The ciphertext resulting from the encryption with the first symmetrical key S1 as well as possibly remaining unencrypted domain and / or channel parameters are transmitted in step 410 from the chip card terminal to the chip card via the predefined channel (compare communication channel 108 of the<figref idrefs="f0001">FIGS</figref> and <figref idrefs="f0003">3</figref>) transfer.
0089In step 412, the chip card attempts to decrypt the cipher by means of the second symmetric key S2. The chip card 104 receives the channel parameters KA2 and the domain parameters D2 therefrom. The chip card 104 derives the fourth symmetrical key S4 from the domain parameters D2.
0090In step 414, the chip card terminal 100 generates a chip card command which is encrypted with the third symmetric key S3 (step 416) to transmit it via the first communication channel defined by the channel parameters KA1 (cf. communication channel 112 in the embodiments of the FIG <figref idrefs="f0001">FIGS</figref> and <figref idrefs="f0003">3</figref>). The chip card terminal 100 sends the chip card command in the step 418.
0091Correct reception of this cipher by the chip card is only possible in step 420 when the second communication channel 146 matches the first communication channel 112, ie when KA2 = KA1, and, if moreover, decryption of the chip card command with the fourth symmetric key S4 is possible, ie if S4 = S3. However, the conditions KA2 = KA1 and S4 = S3 can only be fulfilled if the correct PIN 'has been entered into the chip card terminal by the user, ie when PIN' = PIN.
LIST OF REFERENCE NUMBERS
0092<dl id="dl0003" compact="compact"><dt>100</dt><dd>Chip card terminal</dd><dt>102</dt><dd>interface</dd><dt>104</dt><dd>smart card</dd><dt>106</dt><dd>interface</dd><dt>108</dt><dd>Predefined communication channel</dd><dt>110</dt><dd>communication parameters</dd><dt>112</dt><dd>First communication channel</dd><dt>114</dt><dd>User interface</dd><dt>116</dt><dd>PIN CODE'</dd><dt>118</dt><dd>processor</dd><dt>120</dt><dd>application program</dd><dt>122</dt><dd>Chip-card command</dd><dt>124</dt><dd>Chip card function</dd><dt>126</dt><dd>communication module</dd><dt>128</dt><dd>program instructions</dd><dt>130</dt><dd>key generator</dd><dt>132</dt><dd>processor</dd><dt>134</dt><dd>communication module</dd><dt>136</dt><dd>program instructions</dd><dt>138</dt><dd>Protected storage area</dd><dt>140</dt><dd>pin code</dd><dt>142</dt><dd>key generator</dd><dt>144</dt><dd>Error operation count</dd><dt>146</dt><dd>Second communication channel</dd><dt>148</dt><dd>program instructions</dd><dt>150</dt><dd>program instructions</dd><dt>152</dt><dd>Storage</dd><dt>154</dt><dd>Storage</dd></dl>
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP1752937A1 | Cites | European Patent Office (EPO) |
| US2002129247A1 | Cites | United States of America |
| Bruce Schneier: "Applied Cryptography, Protocols, Algorithms, and Source Code in C" In: "Applied Cryptography, Protocols, Algorithms, and Source Code in C", 1. Januar 1996 (1996-01-01), John Wiley & Sons, New York, XP055056127, Seiten 513-525, * Seite 513 - Seite 525 * | Non-patent | – |
| Christian Hainz: "Kryptographie und elliptische Kurven", , 1. April 2001 (2001-04-01), Seiten 2-14, XP055056091, Gefunden im Internet: URL:http://homepages.thm.de/~hg10013/Lehre /MMS/SS01_WS0102/Elyps/index.html [gefunden am 2013-03-12] | Non-patent | – |
| BRUCE SCHNEIER: "Applied Cryptography", 1996, JOHN WILEY AND SONS, XP002520924, * Seite 28, Absatz 1 - Seite 29, Absatz 4 * | Non-patent | – |
21 members in 7 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 102007000589 | Germany | A | |
| 102007000589 | Germany | – | |
| 08845554 | European Patent Office (EPO) | A | |
| DE20071000589 | – | – | – |
| EP20080845554 | – | – | – |
| 102007000589 | – | – | – |
| 088455548 | – | – | – |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| WO2009056463A2 | World Intellectual Property Organization (WIPO) | A2 | |
| DE102007000589B3 | Germany | B3 | |
| WO2009056463A3 | World Intellectual Property Organization (WIPO) | A3 | |
| DE102007000589B9 | Germany | B9 | |
| EP2218028A2 | European Patent Office (EPO) | A2 | |
| US2010223479A1 | United States of America | A1 | |
| CN101842792A | China | A | |
| US8353054B2 | United States of America | B2 | |
| EP2595083A1 | European Patent Office (EPO) | A1 | |
| EP2595085A2 | European Patent Office (EPO) | A2 | |
| CN101842792B | China | B | |
| CN103258169A | China | A | |
| EP2595085A3 | European Patent Office (EPO) | A3 | |
| EP2218028B1 | European Patent Office (EPO) | B1 | |
| EP2595083B1This record | European Patent Office (EPO) | B1 | |
| CN103258169B | China | B | |
| ES2635616T3 | Spain | T3 | |
| PL2595083T3 | Poland | T3 | |
| EP2595085B1 | European Patent Office (EPO) | B1 | |
| ES2690366T3 | Spain | T3 | |
| PL2595085T3 | Poland | T3 |
67 legal events, as 11 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Full renewal or maintenance fee paidST27 STATUS EVENT CODE: U-0-0-U10-U11 (AS PROVIDED BY THE NATIONAL OFFICE)U11 | U11 | CH | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Invalidated european patentMG4D | MG4D | LT | |
| Fee paymentPLFP | PLFP | FR | |
| Definitive protectionFG2A | FG2A | ES | |
| Translation for ep filed (entry of ep into country)FP | FP | NL | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Divisional application: reference to earlier applicationAC | AC | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2595083
- Publication, DOCDB
- 2595083
- Publication, EPODOC
- EP2595083
- Application
- 13155097
- Application, DOCDB
- 13155097
- Application, EPODOC
- EP20130155097
Titles3
- German
- Verfahren zum Schutz einer Chipkarte gegen unberechtigte Benutzung, Chipkarte und Chipkarten-Terminal
- English
- Method for protecting a chip card against unauthorised use, chip card and chip cards terminal
- French
- Procédé destiné à protéger une carte à puce contre les utilisations non autorisées, carte à puce et terminal de carte à puce
Classification
- CPC, 7
- G06F21/77
- H04L9/3013
- H04L9/3066
- H04L9/3215
- H04L9/3226
- H04L2209/56
- H04L2209/805
- IPC, 4
- G06F21 30
- G06F21 77
- H04L9 30
- H04L9 32
Designated states34
- Contracting states, 34
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
and 10 moreShow fewer
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
