Memory card reader
Abstract
Memory card reader (10) comprising a printed circuit (13) in which a memory card connector (12) is mounted, said memory card connector having a slot (12.1) intended to insert a memory card memory and a set of contact points (12.2) that allow an exchange of data between said memory card and a processor mounted on said printed circuit, characterized in that said printed circuit also carries an anti-intrusion device (14) formed and fixed in said printed circuit so that said anti-intrusion device prevents access, from the outside of said reader, at least to a connection portion between the less one of said contact points of said set of contact points and said printed circuit.

Term
3.5 yearsto projected expiry
Projected expiry 12 April 2030, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
8 claims: 1 independent, 7 dependent
- 1REIvINDICaCIoNES 1. Lector de tarjetas de memoria (10) que comprende un circuito impreso (13) en el cual esta montado un conector de tarjetas de memoria (12), presentando el citado conector de tarjetas de memoria una ranura (12.1) destinada a introducir una tarjeta de memoria y un conjunto de puntos de contacto (12.2) que permiten un intercambio de datos entre la citada tarjeta de memoria y un procesador montado en el citado circuito impreso, caracterizado porque el citado circuito impreso lleva ademas un dispositivo antiintrusion (14) formado y fijado en el citado circuito impreso de modo que el citado dispositivo antiintrusion impide el acceso, a partir del exterior del citado lector, al menos a una porcion de conexion entre al menos uno de los citados puntos de contacto del citado conjunto de puntos de contacto y el citado circuito impreso.
- 2Lector de tarjetas de memoria de acuerdo con la reivindicacion 1, caracterizado porque el citado dispositivo antiintrusion tiene sensiblemente la forma de un paralelepipedo rectangulo que comprende, en su cara superior, un saliente de obstruccion (14.1) del acceso a los citados puntos de contacto por la parte superior del citado dispositivo antiintrusion.
- 3Lector de tarjetas de memoria de acuerdo con la reivindicacion 1, caracterizado porque el citado dispositivo antiintrusion comprende al menos un circuito conductor tridimensional y al menos dos elementos de contacto del citado circuito conductor con una banda de conexion del citado dispositivo antiintrusion con el citado circuito impreso.
- 4Lector de tarjetas de memoria de acuerdo con la reivindicacion 1, caracterizado porque el citado circuito impreso comprende una zona destinada a recibir el citado dispositivo antiintrusion, la cual comprende un numero par de bandas de conexion del citado dispositivo antiintrusion.
- 5Lector de tarjetas de memoria de acuerdo con la reivindicacion 4, caracterizado porque las citadas bandas estan constituidas al menos por dos partes separadas un espacio que permite, durante la fijacion del citado dispositivo antiintrusion al citado circuito impreso, una evacuacion de aire que resulta de la citada fijacion.
- 6Dispositivo de captura de codigo confidencial, caracterizado porque comprende un lector de tarjetas de memoria de acuerdo con la reivindicacion 1.
- 7Dispositivo antiintrusion para lector de tarjetas de memoria de acuerdo con una cualquiera de las reivindicaciones 1 a 6, caracterizado porque comprende varias capas de circuito impreso superpuestas y unidas entre si con la ayuda de vias enterradas y porque se presenta en forma de un componente electronico apto para ser conectado electricamente a un circuito impreso al cual este esta fijado.
- 8Procedimiento de aseguramiento de un componente electronico montado en un circuito impreso caracterizado porque comprende una etapa de fijacion, conjuntamente con el citado componente electronico que hay que asegurar, de un dispositivo antiintrusion, de acuerdo con la reivindicacion 7, que comprende varias capas de circuito impreso superpuestas y unidas con la ayuda de vias enterradas apto para ser conectado electricamente a un circuito impreso al cual este esta fijado. Figura 1 Figura 2 Figura 3 Figura 4 Figura 5
Independent claims8
73 paragraphs, as filed
Memory card reader.
1. Field of the invention
The present invention relates to the field of protection of memory card reading devices. Such memory card reading devices are used in numerous devices such as payment terminals, authentication or identification devices or content reading devices.
The present invention relates more particularly to the securing of such memory card reading devices so that it is not possible to capture or monitor signals that are exchanged between a memory card inserted in the device and a secure processor that treats data from this memory card.
two Prior art
Devices that integrate memory card reading devices, such as payment terminals, comprise numerous securing devices and implement numerous methods that ensure that the devices are used in accordance with the purpose for which they have been intended and respected. safety standards that are imposed by certification bodies.
For example, in the field of payment terminals for smart cards, manufacturers have been obliged, from January 1, 2008, to comply with the PCI PED 2.0 (Payment Card Industry Pin Entry Device).
This new security standard consists especially in securing the terminal capture keypad protecting the capture of the confidential code, and in blocking the terminal in case of intrusion (fraudulent or accidental).
A payment terminal is presented in relation to Figure 1. On the part of its constitution, a payment terminal (10) of this type generally presents:
<dl><dt>-</dt><dd> a keyboard (11) on its upper face; </dd></dl>
<dl><dt>-</dt><dd> a memory card connector (12) sometimes placed under the keyboard and that allows you to insert the card and talk with it. This memory card connector (12) is fixed, usually by welding, to a printed circuit (13).</dd></dl>
In order to protect the terminal it has sometimes been considered interesting to combine the securities in these two organs. A first protection consists in adding a protection grid circuit of the memory card connector around it and joining this grid circuit electrically to the electronic card through welds that are not accessible without removing the keyboard. However, the keyboard is in turn protected from fraudulent disassembly by the presence of false keys that detect the withdrawal of this. Therefore, a simple protection (for example with a grid circuit on one side of a flexible printed circuit), provided that it is connected at inaccessible points for a fraudster may be sufficient to protect four faces of five of the connector memory cards (CAM).
Naturally, the last face that is used for the introduction of the customer's card cannot be closed. In this specific case, there is therefore an angle of attack to the fraudster to reach contact points (pins) of the connector, and especially the contact points through which the input / output signals (called I / O) travel.
In effect, the memory card connector, by its implantation in the printed circuit, defines three zones:
<dl><dt>-</dt><dd> a main connection area with the memory card that allows reading the information present on the card; </dd></dl>
<dl><dt>-</dt><dd> a junction zone that is housed in the memory card connector; </dd></dl>
<dl><dt>-</dt><dd> an intermediate zone in which the contact points join the printed circuit. </dd></dl>
It was necessary to prevent fraudulent access to these points of contact. Indeed, it is perfectly possible to imagine connecting, at the level of these contact points, a monitoring device that could be used to register the signals that pass between the processor and the smart card. Such a record could lead to a collection of sensitive data. Thus, these contact points must be protected, at the intermediate zone level, by a system that does not interfere with the functionality of the memory card connector.
An insurance of this type is carried out with the help of several hardware and software technologies.
At the hardware level, certain builders have directly integrated a mask at the memory card connector level. According to the builders, this mask is fixed or detachable. When it is removable, this mask is pivotally mounted to allow maintenance of the device, even if it is taken out of service (the pivot allows it to be "sensitive" to start an assurance procedure when you want to access it). The device is maintained repairable by a qualified person (loss of sensitive information, such as bank information). This, however, is an expensive solution that needs an activation operation. When it is mounted fixed on the memory card connector or when this mask is an integral part of the memory card connector, it is not generally possible to intervene in the memory card connector to perform maintenance of the device. It is then necessary to replace the entire memory card connector. In addition, these connectors need a supplementary stage to activate the protection (mechanical operation).
Furthermore, in the prior art solutions, the masks are generally constituted by a piece of plastic material or resistant material and by a conductive element such as a copper wire. However, the manufacture of a mask of this type, which only measures a few millimeters, while integrating non-conductive elements and conductive elements, is complex.
Thus, it was necessary to find a simple and inexpensive protection solution that allows maintenance of the device without rendering it unusable.
The "ITTMFG ENTREPRISES" document (FR 2 875 036) dated March 10, 2006 has a memory card connector comprising an anti-intrusion device (page 1, lines 5 to 10) that is presented in the form of a metal cage (isolated) surrounding a specific connector to be protected (22, 38). According to this document, the memory card connector comprises at least one signal contact sheet (22a) and one mass contact sheet and comprises at least one metal protection plate (42, 50) that extends in front of a portion with respect to the first signal contact sheet and which is electrically bonded to a mass contact sheet.
3 Summary of the invention
The invention does not present the drawbacks of the prior art. Indeed, the invention concerns a memory card reader, which comprises a printed circuit in which a memory card connector is mounted, said memory card connector having a slot for inserting a memory card and a set of contact points that allow an exchange of data between said memory card and a processor mounted on said printed circuit.
According to the invention, said printed circuit also carries an anti-intrusion device formed and positioned so that said anti-intrusion device prevents access, from outside the said reader, to at least one connection portion between at least one of the said contact points of said set of contact points and said printed circuit.
Thus, it is not possible to access the connector pins to obtain, fraudulently, the signals that transit between the memory card and the processor. Indeed, where the prior art devices proposed solutions consisting of masking the pins directly at the level of the memory card connectors, for example by proposing a plastic mask, the invention proposes a solution based on fixing directly to the printed circuit. , of an anti-intrusion device specifically adapted for the masking function of the contact points of the memory card connector. The invention thus provides a simple solution to implement and little expensive since it is enough to mount and fix the anti-intrusion device in the right place. This operation can be performed even after mounting the memory card connector, for example using a procedure for transferring components in printed circuits in a lead-free procedure.
According to a particular embodiment of the invention, said anti-intrusion device has substantially the shape of a rectangular parallelepiped comprising, on its upper face, a projection of obstruction of access to said contact points by the upper part of said anti-intrusion device In accordance with the invention, the anti-intrusion device is made in accordance with the manufacturing techniques of the printed circuits.
According to a particular embodiment of the invention, said anti-intrusion device comprises at least one three-dimensional conductive circuit and at least two contact elements of said conductive circuit with a connection band of said anti-intrusion device with said printed circuit;
Thus, the anti-intrusion device is inviolable, because an infraction of this implies a short circuit in the grid that it comprises, thus activating a safety action at the processor level.
According to a particular embodiment of the invention, said printed circuit comprises an area intended to receive said anti-intrusion device, which comprises an even number of connection bands of said anti-intrusion device.
Thus, during a microfixation operation, such as welding, of said anti-intrusion device to the printed circuit, the anchoring forces are exerted uniformly between said anti-intrusion device and the printed circuit so that said CMS does not suffer oscillation (movement , displacement) during fixing.
According to a particular feature of the invention, said bands are constituted at least by two separate parts that allow, during the fixing of said anti-intrusion device to said printed circuit, an air evacuation resulting from said fixing.
The invention also concerns a confidential code capture device.
According to the invention, such a device comprises a memory card reader as described above.
The invention also concerns an anti-intrusion device, especially for memory card reader. According to the invention, such a device comprises several layers of printed circuit superimposed and joined together with the aid of buried tracks and which is presented in the form of an electronic component suitable for being electrically connected to a printed circuit in which This is mounted.
According to another aspect, the invention concerns a procedure for securing an electronic component mounted on a printed circuit. According to the invention, such a method comprises a step of placing, together with said electronic component to be ensured, an anti-intrusion device comprising several layers of superimposed printed circuit and joined together with the help of buried tracks. suitable to be electrically connected to a printed circuit in which it is mounted.
Four. List of figures
Other features and advantages of the invention will become clearer with the reading of the description that follows in a preferred embodiment, given by way of illustrative and non-limiting example, and of the accompanying drawings, in which:
<dl><dt>-</dt><dd>Figure 1, already commented, presents a global view of a payment terminal that integrates a memory card reader; </dd></dl>
<dl><dt>-</dt><dd>Figure 2 illustrates a memory card reader according to the invention; </dd></dl>
<dl><dt>-</dt><dd>Figure 3 describes an anti-intrusion device according to the invention; </dd></dl>
<dl><dt>-</dt><dd>Figure 4 describes a printed circuit comprising fixing bands according to the invention; </dd></dl>
<dl><dt>-</dt><dd>Figure 5 describes a fixing band according to the invention. </dd></dl>
5. Detailed Description of the Invention
5.1 Reminder of the principle of the invention
The invention proposes to frontally protect the contact points of the memory card connector, attaching, in the printed circuit, an anti-intrusion device. As the anti-intrusion device is driven in the printed circuit, and not in the memory card connector, it is simpler to assemble. In addition, it is easier to build an anti-intrusion device that is mounted directly on the printed circuit than to build an anti-intrusion device that has to be integrated into the memory card connector itself.
According to the invention, the anti-intrusion device is a surface mounted electronic component (CMS). Thus, the anti-intrusion device can be mounted on the printed circuit at the same time as the other components in the same manufacturing phase as the other components (the order of placement during the design of the device being defined).
In an embodiment of the invention, it is envisaged that the anti-intrusion device of the invention can be shaped in order to receive, within it, an electronic circuit to be protected, thus forming a protective enclosure within which a electronic circuit that you want to protect. Thus, the anti-intrusion device of the invention can be used not only to protect contact points, such as input / output contact points, but also printed circuits in their entirety, thus preventing, for example, any attempt to monitor a processor that is inside the device.
Indeed, according to the invention, the anti-intrusion device comprises several layers of printed circuit superimposed on each other with the help of buried tracks and this is presented in the form of an electronic component. Such a device can be presented in any form. The shape of the device can be adapted depending on the component or printed circuit to be protected.
In accordance with the invention, a protection of an electronic component mounted on a printed circuit is performed by performing a placement step, together with the electronic component to be secured, of an anti-intrusion device. When the anti-intrusion device forms a protective enclosure, this stage of joint placement ensures that it is not possible to alter the electronic component to be secured.
In the following, a mode of realization of a memory card reader device according to the invention is presented. It is clear, however, that the invention is not limited to this particular application, but it can also be implemented in numerous other electronic circuit protection contexts and more generally in all cases where the characteristics listed in The following are interesting.
5.2 Description of a mode of realization
In this embodiment, a memory card reader is presented in accordance with the invention in which an anti-intrusion device has been mounted in the printed circuit in order to prevent access to the contact points, among which the point of contact called "IO" (English "Input / output").
As illustrated in Figure 2, the memory card connector (12) is mounted on the printed circuit (13). The memory card connector has a slot (12.1) into which the card can be inserted. The memory card connector also includes a set of contacts (12.2) that allow a connection of the card, once it is inserted, with a device processor.
These contacts (12.2) have a slight bulge (12.3) at the level of the card connection area, within the memory card connector. The contacts are then formed so that they extend towards the printed circuit (13). These join this at the level of an intermediate zone in which the contact points
(12.4) are attached to the printed circuit (13).
The anti-intrusion device (14) is mounted so as to prevent access to at least certain contact points and especially to the "IO" contact.
In order to prevent access to the contact points by the upper face of the anti-intrusion device (14), the latter may advantageously comprise an obstruction projection (14.1), which is an element whose width
or whose length is respectively greater than the width or length of the body of the anti-intrusion device and which serves to mask the contact points (12.4) of the memory card connector, as shown in Figure 3.
Thus, it is not possible to pass contact elements (such as thin electrical wires or thin conductive films) towards the contact elements of the memory card connector in order to spy the signals exchanged between the memory card and the processor.
In order to prevent perforation of the anti-intrusion device with a view to reaching the contact points, the anti-intrusion device comprises at least one three-dimensional conductor circuit and at least two elements that allow the contact of the three-dimensional conductor circuit with a connection band of the anti-intrusion device with the printed circuit. More particularly, the anti-intrusion device is called a grid since the conductor circuit it contains makes a three-dimensional grid of the volume of the anti-intrusion device.
A grid of this type is made, according to the invention, by placing several layers of printed circuit on top of each other in accordance with the classical technologies so that they form an anti-intrusion device whose volume allows access to contact points to be protected.
In order to allow the tracks of the membranes to come into contact and thus form a true three-dimensional circuit, buried tracks are made between two successive layers. As a reminder, a path is a metallic hole that is intended to electrically connect different layers of the printed circuit.
Thus, there is a three-dimensional electrical circuit whose architecture is such that it is not possible to pierce it without causing a short circuit and activate, according to the invention, an active protection of the apparatus, namely for example a definitive deletion of the memories containing information sensitive, be these memories located on the device itself or on the card that is inserted in it.
The anti-intrusion device, once formed, can also be re-coated with a membrane and thus constitute a surface mounted component that in turn integrates a surface mounted component.
According to the invention, and as illustrated in Figure 4, the anti-intrusion device 14 is mounted on the printed circuit 13. To do this, the printed circuit has, as usual, bands (13.1 to 13.6) that allow the contacting the circuit or conductive circuits of the anti-intrusion device with the circuit or circuits of the printed circuit. However, according to the invention, the printed circuit has, in the mounting area of the anti-intrusion device, an even number of contact bands, the bands being symmetrically arranged along an imaginary positioning axis (13.7 ).
Indeed, the inventors have stressed that during the fixing of surface mounted components in the printed circuit, a lateral force is exerted at the level of the surface mounted component that causes its rotation.
The inventors have discovered that one of the variables that determines the degree of rotation of the surface mounted component once fixed with respect to the mounting position of this same component is the number of fixing bands and their positions relative to each other. Thus, the inventors have discovered that, during the action of the fixing agents, the component, once assembled, has a tendency to adopt a symmetrical position with respect to the fixing bands.
Now, within the framework of the invention, it is important that the position in which the anti-intrusion device is fixed is the position in which the anti-intrusion device is mounted. Indeed, if once fixed, the anti-intrusion device is inclined even if it were only a few degrees with respect to its mounting position, its protective action can be reduced, even completely annulled.
Thus, the inventors have had the idea of placing an even number of fixing bands for the anti-intrusion device, these bands being distributed symmetrically along a positioning axis. Thus, the forces exerted during fixing are identical in all bands and the component is fixed in the same position as that in which it has been mounted.
As a result of these tests, the inventors have also stressed that the phase of fixing the anti-intrusion device to the printed circuit could lead to the formation of tiny air pockets in the weld. However, such bags are not acceptable within the framework of the protection of contact points. Indeed, if an air bag is formed during welding, it would be possible to introduce a minuscule electrode, by perforation, without a short circuit, and consequently, without establishing the procedures for securing the apparatus. In addition, these airbags are very harmful to mechanical resistance, and can even create false welds.
Thus, according to the invention, in relation to Figure 5, the reception bands (13.1 to 13.6) have been separated by a space (13.8) that does not comprise copper. Due to this, the free space in the band allows to receive the air that comes from the fixation and to facilitate a welding perfectly free of air bag. Guard tracks are located around each weld 13.1 to 13.6. These guard tracks allow a short circuit of the contact points by performing a lateral attack. These guard tracks have the shape of a rectangle that surrounds the reception bands and that are electrically connected to the secure processor so that the latter can detect a short circuit.
3 sheets
Sheet 1 Sheet 2 Sheet 3
11 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0952476 | France | A | |
| 0952476 | France | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| CN101866400A | China | A | |
| EP2241997A1 | European Patent Office (EPO) | A1 | |
| US2010265681A1 | United States of America | A1 | |
| FR2944625A1 | France | A1 | |
| FR2944625B1 | France | B1 | |
| EP2241997B1 | European Patent Office (EPO) | B1 | |
| AT553447T | Austria | T | |
| ATE553447T1 | Austria | T1 | |
| ES2385299T3This record | Spain | T3 | |
| US8573989B2 | United States of America | B2 | |
| CN101866400B | China | B |
Numbers
- Publication
- 2385299
- Application
- 10159587
Titles2
- Spanish
- Lector de tarjetas de memoria
- English
- Memory card reader
Classification
- CPC, 3
- G06K7/0021
- G06K7/0091
- H05K1/0275
- IPC, 1
- G06K7 00