A smartcard and a method of operating a smartcard
Abstract
A smart card (200), comprising - a processor (202) in a security portion of the smart card (200); - a read / write device interface (213) designed for communication between the processor (202) and at least one external read / write device (208); and - at least one user input and / or output unit (212) to receive at least user commands and designed to initiate a communication between a user and the processor (202), - characterized in that the communication between a user and the processor (202) is through the read / write device interface (213) and why the communication protocol for communication between the processor and the read / write device (208) is the same as the communication protocol for communication between the user input / output unit and the processor.

Term
Term ended
Projected expiry passed 14 February 2026, 0.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
13 claims: 2 independent, 11 dependent
- 1ES 2 581 561 T3 ES 2 581 561 T3 CLAIMS REIVINDICACIONES 1. A smart card (200), comprising 1. Una tarjeta inteligente (200), que comprende - a processor (202) in a security portion of the smart card (200);- un procesador (202) en una porción de seguridad de la tarjeta inteligente (200);- a read / write device interface (213) designed for communication between the processor (202) and at least one external read / write device (208);Y - una interfaz de dispositivo de lectura/grabación (213) diseñada para una comunicación entre el procesador (202) y al menos un dispositivo externo de lectura/grabación (208);y - al menos una unidad de entrada y/o salida de usuario (212) para recibir al menos comandos del usuario y diseñada para iniciar una comunicación entre un usuario y el procesador (202), - at least one user input and / or output unit (212) to receive at least commands from the user and designed to initiate communication between a user and the processor (202), - caracterizada por que la comunicación entre un usuario y el procesador (202) es a través de la interfaz de dispositivo de lectura/grabación (213) y por que el protocolo de comunicación para la comunicación entre el procesador y el dispositivo de lectura/grabación (208) es el mismo que el protocolo de comunicación para la comunicación entre la unidad de entrada/salida de usuario y el procesador. - characterized in that the communication between a user and the processor (202) is through the interface of the reading / writing device (213) and that the communication protocol for the communication between the processor and the reading / writing device (208) is the same as the communication protocol for communication between the user input / output unit and the processor.
- 13A smart card operation procedure (200), in which the procedure comprises the steps of:13. Un procedimiento de operación de una tarjeta inteligente (200), en el que el procedimiento comprende las etapas de: - operar un procesador (202) de la tarjeta inteligente (203);- operating a processor (202) of the smart card (203);- allow communication between the processor (202) and an external read / write device (208), through a read / write device interface (213) of the smart card (200);- permitir una comunicación entre el procesador (202) y un dispositivo de lectura/grabación externo (208), a través de una interfaz de dispositivo de lectura/grabación (213) de la tarjeta inteligente (200);- caracterizado por que el procedimiento comprende iniciar, por medio de una unidad de entrada y/o salida de 10 usuario (212) que es al menos para recibir comandos del usuario, una comunicación entre un usuario y el procesador (202) a través de la interfaz de dispositivo de lectura/grabación (213), y por que el protocolo de comunicación para la comunicación entre el procesador y el dispositivo de lectura/grabación (208) es el mismo que el protocolo de comunicación para la comunicación entre la unidad de entrada y/o salida de usuario y el procesador. - characterized in that the method comprises initiating, by means of a user input and / or output unit (212) that is at least to receive commands from the user, a communication between a user and the processor (202) through the read / write device interface (213), and because the communication protocol for communication between the processor and the read / write device (208) is the same as the communication protocol for communication between the user input and / or output unit and the processor. 15 14. El procedimiento de acuerdo con la reivindicación 13, en el que la comunicación entre el usuario y el procesador (202) a través de la interfaz de dispositivo de lectura/grabación (213) se inicia por medio de una unidad de entrada/salida de usuario (212) que se dispone en la tarjeta inteligente (200). fifteen The method according to claim 13, wherein the communication between the user and the processor (202) via the read / write device interface (213) is initiated by means of an input / output unit number (212) that is provided on the smart card (200).
Independent claims2
121 paragraphs in 11 sections, as filed
ES 2 581 561 T3
DESCRIPTION
A smart card and a smart card operation procedure
FIELD OF THE INVENTION
The invention relates to a smart card, as well as to a smart card operation method.
BACKGROUND OF THE INVENTION
A smart card or chip card can be a small secure cryptoprocessor embedded in a card the size of a credit card or in an even smaller card, such as a SIM card for mobile phones. A smart card does not usually contain a battery, but rather the power is supplied by a card reader / writer, that is, by a reading and / or writing device to control the function of the smart card by reading data from the smart card or writing data to the smart card.
A smart card device is commonly used in the areas of finance, security access, and transportation. Smart cards usually contain highly secure processors that function as a secure storage medium for data such as cardholder data (eg name, account number or number of loyalty points accumulated). Access to this data is only possible when the card is inserted into a read / write terminal.
It is a difficult task to allow the integration of a user interface function directly on smart cards. For example, a screen can be integrated into a smart card to display information to a user. Or buttons can be included on the smart card to allow a user to enter data.
Smart cards were consciously designed without a human-machine interface to provide user interaction capabilities. The lack of support for user interaction is reflected in the hardware design and the software (operating system) design of known smart cards.
This conscious choice has been driven by the lack of technology for thin and flexible displays and the strict security requirements posed by smart cards. Today, as technology for thin and flexible displays is available, strict security regulations and procedures make it difficult to implement user interaction. The introduction of the API (application programming interface) known from consumer electronic devices and personal computing devices is difficult, since security regulations require that each component of the system has to be developed under the observation of procedures For example, with regard to safety and reliability. This requires, when developing or changing any chip card processor component or any software component, a lengthy certification procedure followed by a lengthy industry acceptance process.
In the following, referring to Fig. 1, a smart card with the integrated display function according to the prior art will be described.
The smart card 100 comprises a plastic substrate 101 on which an integrated circuit is formed, which provides the smart card function.
In a security domain or processor 102 (a secure IC processor) of the smart card 100, in which a high level of security is provided, a card manager unit 103 (which may be a logical unit, a procedure software that runs when an Application Protocol Data Unit (APDU) is received that is adapted to communicate with a plurality of application units 104, each of which contains data and commands necessary for the service of different applications. An operating system 105 is provided that contains software for operating the smart card 100. In addition, a plurality of drive units 106 are provided, each used to drive an associated hardware unit 107.
The smart card 100 is designed to communicate with a smart card reading and writing terminal 108 as a master. The communication between the terminal 108 and the smart card 100 is done through the exchange of Application Protocol Data Units (APDUs) in accordance with the ISO 7816 standard. The card manager unit 103 exchanges the APDUs with a particular one of the application units 104 to carry out a corresponding one of the applications.
The internal structure of the smart card 100 is similar to a standard architecture (such as a personal computer), which can be described, in the well known layered model. As for the hardware units 107, these units can include processors, memories, peripherals, and various encryption / decryption coprocessors that work directly with low-level actuators. The drive units 106 are part of the Operating System Layer (OSL). OSL provides an abstraction of functions in hardware to
ES 2 581 561 T3 applications and provides additional functions often reused by applications. The operating system 105 is also responsible for initializing the chip during power-up.
On top of the operating system, the vendor-specific applications shown schematically in Fig. 1 can be run as application units 104. As smart cards like smart card 100 are commonly used with terminals like reader terminal and smart card recording 108, a master-slave is displayed as communication behavior. This means that the terminal 108 initiates communication with the smart card 100 which sends Application Protocol Data Units (APDUs) to the processor 102. The card manager 103 using the address field in the APDU can recognize which unit of application 104 must be submitted. The targeted application, after receiving that information, executes the requested action and, in return, responds with status / data to terminal 108. This communication scheme requires that, for complex applications, terminal 108 and smart card 100 have to store the actual communication state. In addition to the components described and their function, the smart card 100 comprises extensions to allow a user interface function of the smart card 100.
For this purpose, on a portion of the smart card 100, which is not related to the processor 102 (secure domain), buttons 112 and a screen 113 are provided. In order to allow a user to interact with the smart card 100 through the input of commands via the buttons 112 and through the production of information on the screen 113, there is a connection between the buttons 112, the screen 113 and a button / display interface unit 111 arranged at the level of hardware units 107. Furthermore, a button / display actuation unit 110 is provided at the level of actuation units 106 to allow a user to visually perceive the data that is displayed on the screen 113. On the smart card 100 shown in Fig. 1 , a display function or user interface is provided by the screen 113 and by the buttons 112. In addition, an extension or adaptation of the operating system 105 is required, which is shown schematically as an extension of the operating system 109 in FIG. 1.
While the standard blocks of the smart card 100 are shown with solid lines, the additional blocks, which are required for the input / output function, are marked with dotted lines. It can be seen that the button / display actuation unit 110, the button / display interface unit 111, the buttons 112 and the display 113 have been added, as well as the extension of the operating system 109, and the operating system 105 has been added. extended with functions to provide the API of the display function to the applications made in accordance with the application units 104.
However, the implementation of the smart card 100 according to Fig. 1 has some drawbacks. First, the operating system 105 requires modification in the form of an extension of the operating system 109. This causes development costs and certification costs. Additionally, due to modifications that interfere with the processor 102 (the secure domain) of the smart card 100, there are potential security risks.
Second, in addition to additions to the hardware drivers, an additional mode of use has to be defined for the smart card 100, which differs from the native master-slave mode. This additional mode can be used when the smart card 100 is started outside the terminal (the so-called stand-alone mode) to respond to a user pressing buttons 112 and to display the information. This affects the system architecture of the smart card 100 and brings an additional security threat, requiring additional qualification.
Third, the application units 104 need to be modified to incorporate an input / output function. This is difficult to achieve by established and accepted standards known as EMV (Europay, Mastercard, VISA, a standard for financial credit / debit card applications) or CEPS (Common Electronic Wallet Specification, a standard for electronic wallet applications. ) and would require a re-standardization. Fourth, the smart card (chip) device requires additionally having a hardware interface, specifically the button / display interface 111, to communicate with the buttons 112 / display 113 and with the button / display actuator 110, respectively. Such an interface may not be desired due to security threats.
JP 2001-331771 discloses an IC card with automatic display function, in which a signal line for a communication between a reader / writer and a microcontroller is used in common as a signal line for transferring data to a drive actuator. screen from the microcontroller. According to JP 2001-331771, an additional clock line (indicated as CLK2) is provided between the display and the secure microcontroller, where the additional clock line is not brought to the outside. In other words, according to JP 2001-331771, the microcontroller controls the communication with the display. However, this has the disadvantage that security problems can occur when operating the IC card. Furthermore, in JP 2001-331771, writing on the screen is only possible when the card is in a read / write device.
Document US 2003/0140221 discloses a portable data carrier having a processor, a smart card interface and a keyboard that is an integral part of the data carrier, for user input.
ES 2 581 561 T3
EP 1 004 980 discloses a smart card in which a user's pin can be inserted directly into the smart card when the smart card is presented to a reader.
OBJECT AND SUMMARY OF THE INVENTION
An object of the invention is to operate a smart card in a secure manner.
In order to achieve the object defined above, a smart card and a smart card operation method are provided according to the independent claims.
In accordance with an exemplary embodiment of the invention, a smart card is provided comprising a processor. The smart card further comprises a read / write device interface designed for communication between the processor and a read and / or write device and a user input and / or output unit designed to initiate communication between a user and the processor via read and / or write device interface
Furthermore, in accordance with another exemplary embodiment of the invention, a method of operating a smart card is provided. The method comprises the steps of operating a smart card processor, allowing communication between the processor and a read / write device through a smart card read and / or write device interface, and initiate, by means of a user input and / or output unit, a communication between a user and the processor through the read and / or write device interface. It should be noted that the steps mentioned above do not necessarily have to be carried out in the order given.
The term "smart card" can particularly indicate a contact-type smart card or a contactless smart card, which can comprise a secure processor to provide one or more applications.
The term "processor" particularly indicates a control unit or a smart card management unit, such as a microprocessor or a central processing unit (CPU). Such a processor was perhaps manufactured as a monolithically integrated circuit, for example produced with semiconductor technology (particularly in silicon).
The term "read / write device" particularly indicates an external device (with respect to the smart card) for controlling the function of the smart card by reading data from the smart card and / or writing data to the smart card.
The term user input and / or output unit particularly indicates a device that can be at least partially provided on the smart card and that allows a user to interact with the smart card. In particular, said user input and / or output unit can allow a user to transmit data unidirectionally or bi-directionally and / or receive data from the processor, which can be related to a particular application provided by the smart card.
An interface can particularly provide a connection or an access to a particular component of a communication system.
The smart card according to the invention may be capable of providing an application and the processor of the smart card may be designed to be operated to provide the application. The term application indicates any function or service, which is provided by the smart card, in which the processor can provide the computational resources to carry out said application.
The characteristic features according to the invention particularly have the advantage that a smart card is provided which, in addition to optionally carrying out at least one particular application, provides a user interface (for example a screen and / or keyboard) that is connected to a processor via the same signal path as that used for a connection from the processor to a read and / or write device for read information from the smart card and / or to write information to the smart card. Communication between a user on the one hand (interactively using the user input / output unit as a user interface) and the processor on the other hand can be initiated via the read and / or write device interface. In other words, the communication between the user interface and the processor can be controlled from the user side, rather than from the processor side. As a consequence, from the point of view of the processor (which can be located in a secure portion of the smart card), a communication with a read / write (master) terminal can be performed in a similar or identical way to a communication with the unit. (master) user input / output. Therefore, the smart card processor according to the described embodiment of the invention can act as a slave in the communication channels with the read and / or write terminal and the communication channels with the unit (master) user input and / or output. Therefore, this communication keeps the secure portion that houses the processor unchanged, thus providing a high level of security.
ES 2 581 561 T3
In fundamental contrast to known concepts (for example, according to JP 2001-331771), the smart card according to the described exemplary embodiment of the invention does not use the processor to control the input / output means (for example keyboard or screen). Instead, the input / output means themselves actively initiate communication with the processor, if desired by a user. In other words, the input / output means according to the invention functions as a master node and the processor functions as a slave node in this communication channel. Indeed, the input / output means emulate a terminal or a reading and / or writing device.
As the communication between the reading and / or writing device on the one hand and the smart card on the other hand is normally initialized (for example in a Bancomat application) by the reading and / or writing device, the smart card essentially does not recognize the difference between a communication with a reading and / or writing terminal or a communication with a user interface (such as a keyboard or a screen). This has the advantage that all the security elements that are (already) provided for communication between the read and / or write interface on the one hand and the smart card on the other hand, are also usable for communication between the smart card. (or rather between the smart card processor) and the user input and / or output unit. Therefore, expensive certification of the modified smart card according to the invention can be dispensed with.
The system according to the invention makes it possible to couple one or more user input and / or output units, such as a keyboard or a screen, to the processor of a smart card in a simple but very efficient way. According to the architecture described, the processor is firmly protected against tampering, so that critical security applications (eg credit cards or electronic wallet) can be reliably performed with this smart card. Additionally, user input and / or output applications can therefore be carried out without security risks. The invention allows a user input and / or output unit to be coupled to a processor without weakening its security mechanisms. Since the provision of a user interface according to the invention does not require modifications in most of the existing smart cards, the smart card according to the invention can be built with little effort.
According to one aspect of the invention, an external interface of a smart card, which normally provides communication between a smart card and a terminal, is used simultaneously for the integration of additional components, such as a screen or a keyboard, in a smart card. . A communication between the existing parts located in the secure area and the new parts, which can be provided outside the secure area, can take place through an external that is part of the smart card, but that is located outside the safe area.
Therefore, large parts (for example a high-security heir application) of an existing smart card can remain unchanged, since a communication protocol for a communication between the processor and the user interface can be the same as the one used. for communication between the processor and the terminal.
Advantageously, the system according to the invention allows a rapid integration of, for example, the display function in existing smart card systems without affecting the overall security of the system. In addition, backward compatibility with existing systems is possible.
According to one aspect of the invention, a method is provided for integrating the user interaction function in a smart card. For this purpose, the external interface of a smart card, which normally allows data communication between the smart card and a read / write terminal, is used for the connection of additional components to the smart card.
According to one aspect of the invention, a display drive unit can take the role of master device in communication, emulating an ordinary terminal of the ISO 7816 standard. The display controller according to the invention can communicate with the integrated circuit secure (CI) or processor in a standard way using higher-level protocol APDUs (Application Protocol Data Units). Therefore, the display controller is considered, by the secure IC, as an ordinary terminal. Therefore, the system according to the invention provides a very safe way to connect the display to a safe integrated circuit, since no modification of the hardware of the secure integrated circuit or of the software (low-level) of the integrated circuit is required. insurance.
In contrast to the system according to the invention, the IC card according to JP 2001331771 requires an additional clock line from the secure IC to the display controller. Furthermore, a proprietary protocol is necessary for communication between the secure IC and the display controller according to JP 2001-331771. The system according to JP 2001-331771 is based on the assumption that either the terminal or the secure IC is a master in communication and the display controller is always a slave (i.e. it does not initiate communication ).
ES 2 581 561 T3
The smart card according to the invention can be implemented according to an architecture in which the communication between the user interaction device and the processor is a master-slave architecture. Within the framework of said communication, the user interaction device can take the role of master (that is, it can initiate a communication by sending a corresponding message to the processor) and the processor can take the role of slave (that is, it can send a response to the user interaction device only in the case of a message previously sent from the user interaction device).
The smart card according to the invention can be operated in a so-called stand-alone mode, that is, it can also be operated in the absence of a read / write terminal. In this standalone mode, a user can use the user interaction device to communicate with the processor regardless of the presence or absence of a read / write terminal. In addition, standard known development tools (SDEs) can be used for application development.
It is mentioned that the smart card according to the invention can include one or more user input and / or output units and can be adapted for communication between the processor and one or more reading and / or writing devices.
With reference to the dependent claims, further exemplary embodiments of the invention will be described below. These embodiments also apply to the method of operating a smart card.
The smart card may be designed so that a communication protocol for a communication between a reading and / or writing device and the processor is the same as a communication protocol for a communication between a user and the processor. In other words, the input and / or output means can be arranged to communicate with the processor in essentially the same way as the terminal. This allows the processor to be built in a very simple way, since implementing a single communication protocol is enough to communicate with a reading and / or writing terminal on the one hand and a user through an input and / or output unit. user on the other hand.
The smart card can comprise at least one cable connection element connecting a reading and / or writing device with the processor, in which at least a part of at least one cable connection element can form a connection (exclusively or not exclusively) of the user input / output unit with the processor. According to the described embodiment, the same conductors or cables or contacts can be used to connect the reading and / or writing device with the processor, and to connect the user interface with the processor. By taking this measure, a simple and space-saving construction of the smart card is possible due to a synergistic use of cabling. However, additionally or alternatively to the provision of a wired connection element, contactless operation between the safe IC and the intelligent display controller according to the invention is also possible.
The smart card may be designed in such a way that communication can be performed between the user input and / or output unit and the processor in accordance with ISO 7816. Particular reference is made in this regard to the parts of the ISO standard. 7816 that relate to the definition and use of Application Protocol Data Units (APDUs). The series or ISO 7816 standard not only defines the physical shapes of the smart card and the positions and shapes of its electrical connectors, but also the communication protocols and power voltages to be applied to those connectors, a function and a format of the commands sent to the smart card and of the response returned by the smart card. The communication between the reading and / or writing device on the one hand and the processor on the other hand can be carried out, according to this embodiment, according to the same industrial standard as the communication between the input / output unit user on the one hand and the processor on the other hand, which requires a simple communication architecture.
Furthermore, the smart card may be designed for communication between the user input / output unit and the processor by means of a transmission of at least one Application Protocol Data Unit (APDU). An Application Protocol Data Unit can be defined as a communication unit between a chip card and a read / write device in accordance with the ISO 7816 standard. There are command APDUs, which transmit commands between two entities, and response APDUs, which transmit a response to a command. The communication scheme of the APDUs is related to the well-known OSI (Open Systems Interconnection) model and, specifically for smart cards, the concept of APDUs is described in the ISO 7816-4 standard, which is explicitly referred to in This document.
The smart card can be divided into a security portion, in which a security function is provided, and a remaining portion, in which the security portion includes the processor and in which the remaining portion includes the input unit and / or user exit. The security portion may be a portion of the smart card in which the components of the smart card are arranged that contain data that are fundamental aspects of relative security. The processor, according to the described embodiment, resides in this security portion. However, placing the input and / or output unit in the remaining portion
ES 2 581 561 T3 (not having, or at a lower level, security measures), the processor is provided in a secure area and the input and / or output means are provided in a less secure area. By taking this measure, the overall security is improved, since a user's access through the user input and / or output unit does not influence the security within the secure portion.
The user input and / or output unit may include at least one of the group consisting of a display, a keyboard, a button, an acoustic input and / or output means, and a user identification sensor. In general, the user input and / or output unit may include any element that enables a human user to influence the function of the smart card or to be informed in a perceptible way about said function. In particular, the user input and / or output unit may include means that allow a user to provide data or commands or messages to the processor, thereby controlling the function of the application (s) being executed (n ) on the smart card. On the other hand, this also includes providing data or messages or the information from the processor to the user to inform the user about a status of an application running on the smart card.
For example, a user can identify himself by entering a password using a keyboard or button. Or a remaining payment or credit card can be displayed to a user through a screen.
The user input and / or output unit may include any type of suitable display means. For example, a flexible display in accordance with Philips Flexible Display Systems technology can be implemented with a smart card. The user interface may then consist of a small screen and several buttons, which allow for simple user menu-based interaction with the applications residing on the smart card.
Furthermore, a keyboard may be provided on the smart card through which a user can enter commands or messages to be sent to the processor. A similar result can be achieved by providing one or more buttons on the smart card. In particular, a keyboard can be realized as a plurality of buttons.
It is also possible that an acoustic sensor such as a microphone, in particular a MEMS microphone, is provided on the smart card allowing a user to provide the smart card with acoustic commands such as display my current credit! (if necessary or desired within the framework of a speech recognition system). Furthermore, an acoustic output unit, in particular a MEMS loudspeaker, can be provided on the smart card so that, for example, a human voice will produce requested information from a user audibly, as their current credit is € 100.
Furthermore, the user input and / or output unit may include a user identification sensor, that is, a sensor that allows the smart card to decide whether a user is authorized to access the smart card or not. Said identification sensor can be a fingerprint sensor, a retina sensor, a DNA sensor, or the like.
The user input and / or output unit can be realized in software and / or hardware. The user input and / or output function according to the invention can therefore be carried out by means of a computer program, i.e. by software, or by using one or more special electronic optimization circuits, i.e. in hardware, or in hybrid form, that is, by means of software components and hardware components.
In general terms, the user input and / or output unit may comprise elements that allow a user to perceive data, which is provided by the smart card. On the other hand, the user input and / or output unit may include elements that allow a user to translate human commands in electronic form.
The smart card according to the invention may further comprise at least one application unit capable of providing the data relating to a corresponding application, but unable to provide the data relating to the corresponding application in a format that is producible (for example displayable) by the user input and / or output unit (for example a screen). The smart card may further comprise a user interaction application unit (which could also be referred to as an application data conversion unit) that is at least capable of converting the data provided by the application unit into a format that is producible by the user input and / or output unit. A communication between the application unit and the user interaction application unit can be mediated by the user input and / or output unit, then acting as a data mirror. This embodiment makes it possible to extend an already existing application unit, which can be located in the security portion but which is incapable of providing the displayable data. The extension is the user interaction application unit (or application data conversion unit), which can fulfill the function of converting the data provided by the application unit into a displayable format. Also, the application data conversion unit can be provided in the secure portion. In addition to the conversion function, the user interaction application unit may optionally fulfill one or more additional functions, that is, it is not limited to converting data into a displayable format.
ES 2 581 561 T3
The smart card user interaction application unit can be adapted to take the role of teacher in connection with a communication with the application unit. In other words, when the user interaction application unit communicates with the application unit, then the user interaction application unit can control this communication with the slave-like application unit, and can particularly initiate such communication. .
A communication between the application unit and the user interaction application unit can be advantageously carried out using the user input and / or output unit, which can be located outside the secure portion. In other words, the user input and / or output unit can function as a mirror by simply sending data from the application unit to the application data conversion unit, or vice versa.
The smart card can be adapted so that a message transmitted between the application unit and the user interaction application unit is encrypted. Taking this measure, a very secure communication system is obtained, since, even when a message is mediated through an insecure area, encryption ensures that a high level of security is maintained.
The user input and / or output unit mediating a message transmitted between the application unit and the user interaction application unit may be unable to decrypt the message. As a consequence, a high level of security is maintained, as the mediation medium lacks any ability to decrypt mediated messages.
The application unit can contain code that relates to a so-called legacy application. This term particularly indicates an application that was developed before the display function was available. Such applications are considered to be well established and standardized (such as EMV or CEPS), but they do not provide the display function. Said use of the legacy application is combined, according to the described embodiment, with a screen application, which can also be located in the secure area, such as the legacy application. An intelligent display controller of the user input and / or output unit can be considered as external in the communication scheme, mediating between the legacy application and the display application.
For example, the display application can send data (as well as a request to send data to the legacy application) to the smart display controller. The smart display controller can transmit the data as requested. The legacy application can respond in a usual way, such as by communicating with a terminal. The smart display controller can send the response to the display app. The display application can then request the smart display controller to display the received data.
The application unit and the user interaction application unit (application data conversion unit) can be located in the secure portion. According to such an arrangement, data is transmitted from the application unit in the secure domain through the smart display controller located in the non-secure domain to the user interaction application unit located in the secure portion, or vice versa. However, the user input and / or output unit only reflects the data from one of the described units to the other without processing it, so there is no security problem. The fact is that the data can be sent in an encrypted way, and no decryption of the data is carried out by the smart display controller.
Communication between the application unit and the user interaction application unit may include the transmission of at least one Application Protocol Data Unit (APDU). Therefore, the communication protocol for this mirror function can be the same as for the communication between the user input and / or output unit and the processor or between the reading and / or writing device and the processor.
In particular, the application unit may be a legacy application unit, that is, an application unit that only provides the application without providing a sophisticated display function.
Exemplary applications of the smart card according to the invention include use as a credit card, as a SIM card for a mobile phone, as an authorization card for pay television, as an identification and access control card, like a public transport ticket, etc.
The smart card according to the invention can be realized as a contact type smart card or as a contactless smart card. In a contact-type smart card, an integrated circuit or semiconductor chip that includes the processor can be recognized by the electrically conductive contacts. In a smart card of the contactless type, which can also be referred to as a contactless smart card, the chip can communicate with the card reader / writer via wireless self-powered induction technology (particularly by exchanging electromagnetic waves, for example in the domain frequency, between the card reader / writer and the smart card). Contactless smart card technology from
ES 2 581 561 T3 according to the invention can be realized or combined with RFID technology (radio frequency identification).
Next, an exemplary embodiment of the smart card operating method will be described. This embodiment also applies to the smart card according to the invention.
The communication between the user and the processor through the interface of the reading and / or writing device can be initiated by means of the user input and / or output unit provided on the smart card. According to this embodiment, the user input and / or output unit is located on the smart card.
Aspects defined above and additional aspects of the invention are apparent from the exemplary embodiments to be described below and explained with reference to these exemplary embodiments.
BRIEF DESCRIPTION OF THE DRAWINGS
The invention will be described in more detail below with reference to exemplary embodiments, but to which the invention is not limited.
Fig. 1 shows a smart card according to the prior art,
Fig. 2 shows a smart card according to another embodiment of the invention,
Fig. 3 shows a smart card according to another embodiment of the invention,
Fig. 4 shows a part of a smart card according to an exemplary embodiment of the invention illustrating a mirror function of a user input and / or output unit.
DESCRIPTION OF THE MODES OF IMPLEMENTATION
The illustration in the drawing is schematic. In different drawings, similar or identical elements are provided with the same reference signs.
In the following, with reference to Fig. 2, a smart card 200 according to an exemplary embodiment of the invention will be described in detail. As for similar components as used in Fig. 1, reference is also made to the above description of Fig. 1.
The various components of the smart card 200 are provided on and / or on a plastic substrate 201. The size of the smart card 200 can be that of a conventional credit card. The smart card 200 shown in Fig. 2 is capable of providing a plurality of applications (each relating to a particular one of the application units 204). The smart card 200 comprises a microprocessor 202, which is designed to carry out calculations and control functions within the framework of the service of the different applications.
A card reading and writing terminal 208 (also indicated as a card reader / writer) is provided to read the information stored or generated on the smart card 200 or to program, or enter, input data externally on the smart card 200. . A reader and writer interface 213 of the smart card 200 is designed for bi-directional communication between the smart card reader and writer 208 and the microprocessor 202.
In addition, a user input and output unit 212 (I / O unit) is provided on the smart card. User input and output unit 212 can actively initiate communication between a human user (not shown) and microprocessor 202 via smart card 213 read and write device interface. Therefore, within the framework of a communication between the user input and output unit 212 on the one hand and the microprocessor 202 on the other hand, the user input and output unit 212 plays the role of master and the microprocessor 202 plays the role of slave. This function assignment is atypical, since, in the field of electronics, it is usually a microcontroller that plays the role of master. However, this role assignment has the fundamental advantage that it improves the security of the data transfer between the different components of the smart card 200.
The user input and output unit 212 comprises an intelligent display controller 211 which is implemented, according to the embodiment described, in the hardware, and which coordinates the communication between the processor 202 on the one hand and the display hardware 210 and buttons 209 (as additional components of user input and output unit 212) on the other hand.
A user can use buttons 209 to enter commands to be conveyed, through smart display controller 211 and interface 213, to processor 203 for further processing thereof in
ES 2 581 561 T3 the context of one of the applications assigned to the application units 204. For example, an application may be a financial credit / debit card application, or the like. In addition, data related to an application performed by smart card 200 can be transmitted from processor 202 through interface 213 and smart display controller 211 to display hardware 210 that displays audio and / or video information. corresponding to a human user.
As can be seen in Fig. 2, the smart card 200 is divided into a security or processor portion 202 and a non-security portion - remainder -. The microprocessor 202 that includes the plurality of application units 204 resides in the security portion. In addition, an operating system 205 is provided, which may comprise software components for operating the smart card 200. In addition, a plurality of drive units 206 and a plurality of hardware units 207 are provided. Each of the hardware units 207 may include components such as a subprocessor, memory, peripheral, or encryption / decryption subprocessor.
The communication protocol used for a communication between the smart card reading and writing terminal 208 and the microprocessor 202 is the same as a communication protocol for a communication between a user (not shown) operating the input / output unit. user 212 and microprocessor 202. Both communication channels are carried out through an exchange of Application Protocol Data Units (APDU) and in accordance with the industrial standard ISO 7816.
The user input and output unit 212 includes the display 210 (which can be realized based on Philips Flexible Display Systems technology) and the buttons 209. According to the embodiment shown in Fig. 2, the user input and output unit 212 is realized as a hardware unit.
The smart card 200 is a high-speed, secure, and low-cost device in which the high-security world of smart card devices and associated software remains essentially unchanged (and therefore secure and invulnerable to attack). potential), but said smart card has included a possibility for the card application that allows user interaction through the existing security infrastructure. Although the embodiment shown in Fig. 2 focuses on a screen 210 and on the buttons 209 connected to the hardware of the smart card 200, the system according to the invention can also be connected to other electronic devices on the card, such as for example fingerprint readers, or the like.
In the following, the hardware / software connection of the display function via existing physical and logical interfaces will be described. Fig. 2 shows an extension of a smart card system with display function. In smart card 200, the smart card processor system (hardware and software) remains essentially unchanged and therefore remains secure. In Fig. 2, the I / O function is added as user independent input and output unit 212 next to the processor or secure domain 202 of the smart card 200.
The smart display controller 211 communicates with the smart card applications (or rather with the microprocessor 202) using an interface 213 of the ISO 7816 standard and exchanging the APDUs with the microprocessor 202. The communication between the input and output unit user 212 and microprocessor 202 is performed in the same way as communication with smart card reading and writing terminal 208. Through the interface 213, the smart display controller 211 can inform an application unit 204, by means of a corresponding message, that a button 209 has been pressed by a user and asks the respective application unit for the data that should be displayed on screen 210. The security of the system is not affected by the addition of the user input and output unit 212, since the only change is in applications that need to understand the protocol to actuate data on the screen 210. No modifications are required in other components of the system.
The intelligent display controller 211 can be implemented in hardware and software, both embodiments being conceptually the same.
The smart card 200 shows an embodiment of the smart display controller 211 in hardware. This requires the implementation of the functional block in the display controller and the ISO 7816 contact connections to that controller. The embodiment of Fig. 2 is very flexible, since the display function only depends on an application developer. In such a scenario, no additional hardware interface is needed on microprocessor 202.
In the following, with reference to FIG. 3, a smart card 300 according to another exemplary embodiment of the invention will be described.
In the embodiment shown in Fig. 3, the intelligent display controller 211 is implemented in software. Therefore, the smart display controller 211 of the user input and output unit 302 resides in a software block 304 of the smart card 300. The smart display controller 211 further contains the
ES 2 581 561 T3 buttons 209 and display hardware 210. A receiver / transmitter buffer 303 (RX / TX buffer) and a firewall unit 301 also reside in the software block 304.
Realizing the smart display controller 211 in the software means that there is a function to send and receive the APDUs to the card manager 203 of the microprocessor 202 in the form of software via function call, for example via the receiver buffer. / transmitter 303. The smart display controller 211 is operated based on software commands as well. It runs in a card controller firewall region, completely separate from secure domain 202 (similar to a Philips Mifare emulation on Philips smart card processors). It operates the display hardware 210 and buttons 209 through a dedicated interface, for example through a serial interface. That embodiment of Fig. 3 does not need, or only a little, certification.
In the following, referring to Fig. 4, a portion 400 of a smart card according to yet another embodiment of the invention in which a data mirroring function of the smart display controller is implemented will be described. Fig. 4 illustrates a concept for adding display functionality to legacy applications.
As seen in Fig. 4, portion 400 comprises a display application unit 401 that resides in the security portion or processor 202 and a legacy application unit 402 that also resides in the security portion or processor 202 Apart from the screen application unit 401 and the legacy application unit 402, additional application units 204 are provided in the security portion 202. As will be described below, a communication between the display application unit 401 and the legacy application unit 402 is performed through a plurality of transmission channels 403 to 407 and is mediated by the intelligent display controller 211 which acts as a data mirror.
The embodiment shown in Fig. 4 solves the problem of displaying information from well established and standardized legacy applications (such as that included in the legacy application unit 402), for example the electronic wallet (CEPS, Geldkarte, Chipknip) . In many cases, these existing applications are not designed to display information, such as an amount stored in the electronic wallet, on a screen.
A clear solution to this problem would be to add a display function for the application units. However, this approach would require a significant development effort, followed by certifications and a long period of time to achieve industrial acceptance.
Another possible solution could be an implementation of the terminal emulation function in the smart display controller 211. Such an emulated terminal would be able to read required data (for example an amount from the electronic wallet) from the legacy application, to format it and to display it. on the screen. However, such a solution would have several disadvantages. For example, the smart display controller 211 would have to implement the full terminal function with protocols for different application standards (eg Geldkarte for Germany, Chipknip for the Netherlands, or CEPS for the new cards). That would result in a complicated and expensive block of hardware and / or software.
In addition, communication with the legacy application unit 402 is often encrypted. This implementation would therefore require encryption keys to be stored in the smart display controller 211 during a card completion process (which is high-intensity). cost and complex). It would also require the implementation of cryptographic algorithms in the smart display controller 211. Furthermore, there would be no customization facility for the information displayed on the smart card, since the smart display controller 211 would have to format the content of the screen.
The solution according to Fig. 4 is an implementation of the mirroring function for APDU packets in the smart display controller 211 with a separate display application unit 401. This display application unit 401 is capable of recovering the information needed to format a screen content using a standard legacy application known protocol. Any communication messages transmitted between the display application unit 401 and the display application conversion unit 402 are reflected through the intelligent display controller 211 as illustrated in Fig. 4. In Fig. 4, only some of the relevant components of a smart card are shown as portion 400. Communication arrows 403 to 407 symbolize the master-slave data exchange principle of the ISO 7816 protocols to simplify the picture.
The application components are encapsulated in the secure domain 202 of a smart card IC. In the implementation of Fig. 4, there is a display application unit 401 which is a special application designed to retrieve, interpret and display the data from one or more legacy application units given 401 through the intelligent display controller 211.
The communication works as follows: The display application unit 401 sends a request to the intelligent display controller 211 to mirror (i.e., to send) communication messages to the display unit.
ES 2 581 561 T3 destination legacy application 402. Along with the request, the display application unit 401 sends an encapsulated APDU, to be sent to the legacy application unit 402, see the first transmission arrow 403.
Subsequently, the smart display controller 211 sends (ie, reflects) the requested APDU to the legacy application unit 401, see second transmission arrow 404.
The legacy application unit 402 responds in a usual way (as in a communication with a terminal) by transmitting data / status to the intelligent display controller 211, see third transmission arrow 405.
The smart display controller 211 reflects the response back to the display application unit 401, see the fourth transmission arrow 406.
Then, the display application unit 401 may provide the content of the display to the intelligent display controller 211, see the fifth transmission arrow 407, based on the data received from the legacy application unit 402.
A significant advantage of this procedure is safety. Since the smart display controller 211 does not need to interpret the mirrored data, the data can be encrypted via cryptographic keys without leaving the secure domain 202. This means that the display application unit 401 can safely obtain information from the legacy application unit 402 (and vice versa) and extract information that could be displayed on the screen and then send it to the intelligent display controller 211. Thus, the display application unit 401 and the legacy application unit 402, which are both part of a secure domain, can communicate through the intelligent display controller 211, which is outside the secure domain, in a secure manner. .
Another benefit of that solution is that a service provider is able to customize the display application unit 401 (i.e., change the way data is displayed, for example) and remains independent of the card or the system. used operating. Such a solution can even add the identification of the user via, for example, the PIN code to the display application unit 401 to ensure access to personal data in the legacy application unit 402. The mirroring function can be easily implemented on the 211 Smart Display Controller.
The system according to the invention can be used in multi-component smart cards, especially smart cards with a display. The invention enables rapid integration of the display function into existing smart card systems without affecting overall system security and provides a solution for backward compatibility. The system according to the invention provides, through the use of existing standards such as ISO 7816, a high degree of simplicity in use for potential customers.
The inventive smart card 200 can also be used to display data, which is received from the read and / or write device interface 213. In one embodiment, said data is transferred directly (without using the processor 202) to the recording unit. input and / or output 212 through the reading and / or writing device interface 213. In this case, the input and / or output unit 212 acts as a slave. However, processor 202 may be involved in this data display operation as well.
It should be noted that the term comprising does not exclude other elements or stages and that the use of the indeterminate article one or one does not exclude a plurality. Elements described may also be combined in association with different embodiments.
It should also be noted that the reference signs in the claims are not to be considered as limiting the scope of the invention.
Contents11
2 sheets
Sheet 1 Sheet 2
20 members in 7 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 05101208 | European Patent Office (EPO) | A | |
| 05101208 | European Patent Office (EPO) | – | |
| 2006050473 | International Bureau of the World Intellectual Property Organization (WIPO) | W |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| WO2006087657A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006087673A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1854040A1 | European Patent Office (EPO) | A1 | |
| EP1854053A1 | European Patent Office (EPO) | A1 | |
| CN101120354A | China | A | |
| CN101120364A | China | A | |
| US2008149734A1 | United States of America | A1 | |
| US2008163247A1 | United States of America | A1 | |
| JP2008530702A | Japan | A | |
| JP2008530936A | Japan | A | |
| CN101120354B | China | B | |
| US7913916B2 | United States of America | B2 | |
| CN101120364B | China | B | |
| JP5069569B2 | Japan | B2 | |
| JP5124288B2 | Japan | B2 | |
| US8719840B2 | United States of America | B2 | |
| EP3009966A1 | European Patent Office (EPO) | A1 | |
| EP1854053B1 | European Patent Office (EPO) | B1 | |
| ES2581561T3This record | Spain | T3 | |
| PL1854053T3 | Poland | T3 |
Numbers
- Publication
- 2581561
- Application
- 6710896
Titles2
- Spanish
- Una tarjeta inteligente y un procedimiento de operación de una tarjeta inteligente
- English
- A smart card and a smart card operation procedure
Classification
- CPC, 5
- G06K19/072
- G06K19/0719
- G06K19/077
- G06K7/10297
- G06K19/07309
- IPC, 1
- G06K19 077