Method for protecting a chip card against unauthorised use, chip card and chip cards terminal
Abstract
Procedure for the protection of a chip card (104) against unauthorized use, with the following steps: - introduction of a first identification (116) into a chip card terminal (100), - generation of encrypted text from at least a first communication parameter (K1; KA1, D1) with the aid of a first symmetric key (S1) derived from the first identification, a first protected communication channel (112) can be defined with the aid of the communication parameter between the chip card terminal and the chip card , - transmission of encrypted text through a predefined communication channel (108) from the chip card terminal to the chip card, - attempt to decrypt the encrypted text with the help of a second symmetric key (S2) by the chip card, so that the result of decryption is only the first communication parameter when the first symmetric key is equal to the second key symmetric, so that the first protected communication channel can only be defined between the chip card terminal and the chip card when the first identification is correct.
Term
2.1 yearsto projected expiry
Projected expiry 20 October 2028, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 8 independent, 7 dependent
- 15 10 15 20 25 30 35 40 45 50 REIVINDICACIONES 1. Procedimiento para la protección de una tarjeta de chip (104) frente a un uso no autorizado, con las siguientes etapas:- introducción de una primera identificación (116) en un terminal de tarjetas de chip (100), - generación de un texto cifrado a partir de al menos un primer parámetro de comunicación (K1;KA1, D1) con ayuda de una primera clave simétrica (S1) derivada de la primera identificación, pudiendo ser definido con ayuda del parámetro de comunicación un primer canal de comunicación protegido (112) entre el terminal de tarjetas de chip y la tarjeta de chip, - transmisión del texto cifrado a través de un canal de comunicación predefinido (108) desde el terminal de tarjetas de chip a la tarjeta de chip, - intento de desencriptación del texto cifrado con ayuda de una segunda clave simétrica (S2) por la tarjeta de chip, de modo que entonces el resultado de la desencriptación solo es el primer parámetro de comunicación cuando la primera clave simétrica es igual a la segunda clave simétrica, de modo que el primer canal de comunicación protegido solo puede ser definido entre el terminal de tarjetas de chip y la tarjeta de chip cuando la primera identificación es correcta.
- 2Procedimiento según la reivindicación 1, en el que en cuanto al primer parámetro de comunicación se trata de la indicación de una frecuencia de transmisión, de un esquema de salto en frecuencia, de un procedimiento de codificación y/o de un procedimiento de modulación.
- 3Procedimiento según la reivindicación 1 o 2, en el que en cuanto al primer parámetro de comunicación se trata de una clave pública del terminal de tarjetas de chip, de modo que en el caso de que la desencriptación del texto cifrado tenga éxito, la tarjeta de chip deriva a partir de la clave pública de acuerdo con el método de Diffie-Hellman (DH) otra clave simétrica (S4) para encriptar la comunicación entre el terminal de tarjetas de chip y la tarjeta de chip, en el que el terminal de tarjetas de chip determina una clave pública de la tarjeta de chip y a partir de la clave pública de la tarjeta de chip deriva otra clave simétrica (S3) para encriptar la comunicación entre el terminal de tarjetas de chip y la tarjeta de chip de acuerdo con el método de Diffie-Hellman (DH), en el que el primer canal de comunicación está definido por la encriptación con las otras claves simétricas (S3, S4).
- 4Procedimiento según la reivindicación 1 o 2, en el que en cuanto al primer parámetro de comunicación se trata de un primer parámetro de dominio (D1) para la ejecución de un procedimiento criptográfico de logaritmo discreto para la generación de una tercera clave simétrica (S3) por el terminal de tarjetas de chip y de una cuarta clave simétrica (S4) por la tarjeta de chip, en el que la tercera y cuarta claves simétricas son idénticas cuando la primera identificación es correcta, estando previstas la tercera y la cuarta clave simétrica para la encriptación de la comunicación entre el terminal de tarjetas de chip y la tarjeta de chip a través del primer canal de comunicación protegido.
- 5Procedimiento según una de las reivindicaciones anteriores, en el que el resultado de la desencriptación es un segundo parámetro de comunicación (K2; D2, KA2) no correcto cuando la primera identificación no es correcta, en el que un segundo canal de comunicación (146) no correcto puede ser definido por la tarjeta de chip mediante el segundo parámetro de comunicación, con las siguientes etapas adicionales:- envío de un comando de tarjeta de chip (122) desde el terminal de tarjetas de chip a la tarjeta de chip a través del primer canal de comunicación protegido, - la tarjeta de chip ignora el comando de tarjeta de chip y se reduce el número de intentos erróneos restantes, de modo que la tarjeta de chip o una función de tarjeta de chip de la tarjeta de chip es bloqueada cuando se sobrepasa un número de intentos erróneos predeterminado.
- 6Tarjeta de chip con:- una interfaz (106) para la comunicación a través de un canal de comunicación predefinido (108) y varios canales de comunicación adicionales (112, 146, ...) con un terminal de tarjetas de chip (100), - medios (132, 136) para la desencriptación, con ayuda de una segunda clave simétrica (S2), de un texto cifrado recibido en el canal predefinido que está encriptado con ayuda de una primera clave simétrica, de modo que la desencriptación da como resultado al menos un parámetro de comunicación (K2;KA2, D2 ) si una primera identificación (116) introducida previamente en el terminal de tarjetas de chip es correcta, siendo fijado unívocamente por el parámetro de comunicación uno de los otros canales de comunicación para la comunicación protegida entre la tarjeta de chip y el terminal de tarjetas de chip, - una función de primer usuario, de modo que en un estado de primer uso está fijado un determinado parámetro de comunicación para una primera elección del primer canal de comunicación, y en el que la tarjeta de chip 5 10 15 20 25 30 35 pasa de su estado de primer uso a un estado de uso cuando recibe por primera vez un comando de tarjeta de chip (122) en este primer canal de comunicación.
- 7Tarjeta de chip según la reivindicación 6, en la que en cuanto al primer parámetro de comunicación se trata de la indicación de una frecuencia de transmisión, de un esquema de salto en frecuencia, de un procedimiento de codificación y/o de un procedimiento de modulación.
- 8Tarjeta de chip según la reivindicación 6 o 7, en la que por el primer parámetro de comunicación es indicada una clave pública y con medios (132) para la ejecución de un método de Diffie-Hellman para la derivación de otra clave simétrica (S4) con ayuda de la clave pública.
- 9Tarjeta de chip según la reivindicación 6, 7 u 8, con medios (150) para la ejecución de un procedimiento criptográfico de logaritmo discreto para la generación de la otra clave simétrica (S4), en el que la otra clave simétrica está prevista para la encriptación simétrica de la comunicación entre el terminal de tarjetas de chip y la tarjeta de chip a través del canal de comunicación definido (112).
- 10Tarjeta de chip según una de las reivindicaciones anteriores 6 a 9, con una zona de memoria no volátil protegida para almacenar una segunda identificación (140) a partir de la cual puede ser derivada la segunda clave.
- 11Tarjeta de chip según una de las reivindicaciones anteriores 6 a 10, con una zona de memoria no volátil protegida para el almacenamiento de la segunda clave.
- 12Tarjeta de chip según una de las reivindicaciones anteriores 6 a 11, con un contador de intentos erróneos (144) para el bloqueo de la tarjeta de chip si el número de intentos erróneos ha alcanzado un valor umbral predeterminado, en la que un mensaje recibido por la tarjeta de chip que es enviado a la tarjeta de chip por uno de los otros canales de comunicación que no son el canal de comunicación definido, se cuenta como intento erróneo.
- 13Tarjeta de chip según una de las reivindicaciones anteriores 6 a 12, en la que se trata de un documento, en particular de un documento de valor o de seguridad, un carnet, unos medios de pago, una tarjeta de firma o similar.
- 14Terminal de tarjetas de chip con:- medios (114) para la introducción de una primera identificación (116), - medios para la generación de un texto cifrado a partir de al menos un primer parámetro de comunicación (K1;KA1, D1) con ayuda de una primera clave simétrica (S1) derivada de la primera identificación, en el que con ayuda del parámetro de comunicación puede ser definido un primer canal de comunicación protegido (112) entre el terminal de tarjetas de chip y la tarjeta de chip (104), - medios para el envío del texto cifrado a la tarjeta de chip a través de un canal de comunicación predefinido (108).
- 15Terminal de tarjetas de chip según la reivindicación 14, con medios (148) para la generación de parámetros de dominio (D1) para la ejecución de un procedimiento criptográfico de logaritmo discreto para derivar una clave simétrica adicional (S3) para la encriptación de la comunicación entre el terminal de tarjetas de chip y la tarjeta de chip, de modo que el primer parámetro de comunicación indica los parámetros de dominio.
Independent claims15
231 paragraphs in 3 sections, as filed
5
10
15
20
25
30
35
40
45
50
55
DESCRIPTION
Procedure to protect a chip card against unauthorized use, chip card and chip card terminal
The invention relates to a method for the protection of a chip card against unauthorized use, a chip card and a chip card terminal.
For the activation of a chip card function, it may be necessary to previously identify the user with respect to the chip card, as is known per se by the prior art. The most common user identification is the introduction of a secret identification, which in general is designated as a PIN (“Personal Identification Number”) or as CHV (“Card Holder Verification”, verification of the cardholder) . Such identifications are generally composed of a string of numeric or alphanumeric characters. For user identification, the identification is entered by the user through the keypad of a chip card terminal or a computer to which a chip card reader is connected and then sent to the chip card. It compares the entered identification with the stored identification and then notifies the result to the terminal or the computer by issuing a corresponding signal.
As for the types of PIN, you can distinguish between fixed and variable. A fixed PIN cannot be modified by the user and must be learned by heart from it. If disclosed, then the card user must destroy his chip card to avoid misuse by unauthorized persons, and get a new chip card with another fixed PIN. Similarly, the user needs a new chip card if he or she has forgotten the fixed PIN.
A variable PIN can be modified at the user's discretion. To change the PIN for security reasons it is always necessary to give the valid PIN at that time, since otherwise an attacker could replace any existing PIN with his own.
The situation is different with the so-called SUPERPIN or PUK ("Personal Unlocking Key"). As a rule, these have more digits than the PIN itself, and are used to reset an erroneous entry counter (also called a "failed attempt counter") that is at its maximum value. With the PUK, a new PIN is also immediately transferred to the chip card, because a reset failed attempt counter is worthless if the PIN has been forgotten. And this is usually the case when the erroneous attempts counter has reached its maximum value.
There are also applications that use provisional PINs. The chip card is personalized with a random PIN that the card user receives in a PIN letter. However, at the first introduction the card requires you to replace the personalized PIN with your own. In a similar procedure called "PIN procedure with no attributed value", the chip card is reassigned a trivial PIN, such as "0000", and also in the first use it is forced by the chip card to change ( see also documents DE 35 23 237 A1, DE 195 07 043 A1, DE 195 07 044 C2, DE 198 50 307 C2, EP 0 730 253 B1). By such procedures there is a so-called first user function that provides the authorized user with the assurance that no unauthorized use of the chip card by a third party has taken place before its first use.
A procedure for protection against unauthorized use is known from DE 198 50 307 C2
of chip cards. The chip card has a first user function, which when the data and / or the functions of the chip card are used for the first time requires the specification of a personal secret number (PIN), which can be chosen at the discretion by the user, so that by entering the personal secret number the data and / or the functions of the chip card are put into the state of use. A subsequent variation of the personal secret number is possible by a higher order unlock code.
Due to the state of the art, procedures for the verification of a
identification in which the transmission of the identification itself is not necessary, such as Strong
Password Only Authentication Key Exchange (SPEKE), Diffie-Hellman Encripted Key Exchange (DH-EKE), Bellovin-Merritt protocol or Password Authenticated Connection Establishment (PACE). The SPEKE protocol is disclosed, for example at www.iablon.org/speke97.html, documents US 6,792,533 B2 and US 7,139,917 B2. Among others, the DH-EKE protocol is also known through www.jablon.org/speke97.html. Among others, the Bellovin-Merritt protocol is known from US 5,241,599. The PACE protocol is known by www.heise.de/security/news/meldung/85024, which is especially suitable for cryptography of elliptical curves.
An overview of the basics of symmetric encryption can be obtained, for example, from the "Applied Cryptography" document by Bruce Schneier (1996), published by John Wiley and Sons.
In addition, the document "Kryptographie und elliptische Kurven" by Christian Hainz (2001-04-01, pages 2-14) gives an overview on the use of elliptic curves in cryptography, for example in the context of a procedure for the exchange of Diffie-Hellman keys.
5
10
15
20
25
30
35
40
45
50
55
Document DE 103 38 643 A1 discloses a procedure for the safe identification of objects, which can be used for example for friend-enemy identification. To this end, the emission frequencies used for the transmission of a sequence of partial messages are varied, the frequency series used by a user and communicated to the second user by a secure route being set.
Document DE 198 50 308 A1 also describes a procedure for the protection of chip cards against improper use in non-system devices. Thus, for example, in the context of a challenge-response procedure an identification of a terminal is requested by the chip card and compared with the identification that is stored in the chip card.
From EP 1 552 484 A0 a computer is known to which a subscriber identity module (SIM) is associated as used in a GSM mobile phone. The SIM can be authenticated through the telephone network, in the same way as the SIM for telephone headset users in a network and can also authenticate a user from a personal computer or the personal computer itself.
EP 1 909 431 A1 discloses a procedure comprising the connection of a main processor (HP2) to a controller by means of a connection unit (C1) and the transmission of secret data, that is, of a public encryption key , to a control, the data being stored by the control.
In this regard the object of the invention is to provide an improved method for the protection of a chip card against unauthorized use. The object of the invention is also to provide an improved chip card and an improved chip card terminal.
The objects underlying the invention are resolved, respectively, with the characteristics of the independent claims. Preferred embodiments are specified in the dependent claims.
According to the invention there is provided a method for the protection of a chip card against unauthorized use. The procedure involves, in addition to the chip card itself, a chip card terminal.
By "chip card terminal" is meant here any device that is made for communication with a chip card for, for example, directing chip card commands to the chip card and receiving corresponding responses from the chip card. The communication between the chip card and the chip card terminal may in this case be: with contact, wirelessly, for example through an RFID procedure, or selectively with contact or wirelessly, in particular through of an interface called dual mode. As for the chip card terminal, it may be a chip card reader device called class 1, 2 or 3, with or without its own keyboard or a computer to which a chip card reader device is connected. As for the chip card terminal, it may also be a terminal intended for a certain purpose, such as a bank terminal for conducting bank transactions, a payment terminal, for example for buying electronic tickets, or a terminal access to free access to a protected area.
The term "protection of a chip card" means the protection of the chip card as a whole or the protection of one or more of the functions of the chip card. For example, according to the invention, a chip card function that is especially worth protecting is protected, such as a signature function for the generation of an electronic signature, a payment function, an authentication function or the like.
According to an embodiment of the method according to the invention, the authorized user receives a secret identification from the issuing center of the chip card, which in general is called a PIN. To use the chip card, you must first enter an identification in the chip card terminal, which in the following is designated by PIN '. Only when the PIN 'is identical to the PIN should it be possible to use the chip card or the protected chip card function.
For this, the chip card terminal generates an encrypted text from at least a first communication parameter with the help of a first symmetric key. As for the first symmetric key, it can be the PIN itself or a symmetric key derived from the PIN. For example, the PIN 'serves as a so-called seed value ("seed") for the generation of the first symmetric key by the chip card terminal.
The at least one communication parameter is provided so that a first protected communication channel between the chip card terminal and the chip card can be defined by it. In order to form this first protected communication channel between the chip card and the chip card terminal, first the encrypted text of the first communication parameter, obtained with the help of the first symmetric key, is transmitted through a channel predefined communication from the chip card terminal to the chip card. Therefore, this predefined communication channel is defined as standard to establish initial communication between the chip card terminal and the chip card.
After the transfer of the encrypted text through this predefined communication channel from the chip card terminal to the chip card, an attempt is made by the chip card to decrypt this
5
10
15
20
25
30
35
40
45
50
55
Encrypted text with the help of a second symmetric key. This decryption is achieved only when the second symmetric key is equal to the first key, that is, if the PIN '= PIN condition is satisfied.
Therefore, the establishment of a communication connection through the first protected communication channel is only possible if the PIN '= PIN condition is satisfied, since the chip card only in this case is aware of the first communication parameter by the which can be set the first protected communication channel.
As regards the first communication parameter, it can be, for example, the indication of a transmission frequency, a frequency hopping scheme, a coding procedure and / or a modulation procedure.
If on the contrary the condition PIN '= PIN is not satisfied, then the first key derived from the PIN' does not match the second key of the chip card. This has the consequence that the decryption of the encrypted text received from the chip card terminal by the chip card with the help of the second key does not produce the first communication parameter, but for example, a second communication parameter that differs from the first parameter Communication.
By means of the second communication parameter a second communication channel can be defined that is different from the first communication channel. When the chip card receives a signal through the first communication channel, it is, however, ignored since the chip card waits for a signal through the second communication channel. As a result, there is no communication between the chip card terminal and the chip card when the PIN '= PIN condition is not met.
According to an embodiment of the invention, as regards the communication parameter, it may be a public key of a pair of asymmetric keys of the chip card terminal. For the establishment of a symmetric key for communication between the chip card terminal and the chip card, for example according to the Diffie-Hellman method, the public key of the chip card terminal is decrypted with the first key symmetric obtained from the first identification and sent to the chip card through the predefined communication channel.
Only when the PIN '= PIN condition is satisfied, the chip card receives the correct public key from the chip card terminal. The chip card terminal, based on the public key of the chip card, which is for example consulted from a key server, generates the third key according to the Diffie-Hellman method, while the chip card a from its private key and the encrypted text decrypted with the help of the second symmetric key generates a fourth key equally according to the Diffie-Hellman method, so that the fourth key is only equal to the third key, if the PIN condition is met '= PIN.
The third and fourth identical symmetric keys are used for signal encryption, in particular chip card commands and responses to such chip card commands that are exchanged between the chip card terminal and the chip card through the first communication channel. This first communication channel is defined at least by the third key, with the help of which the communication is encrypted through the first communication channel with a symmetric encryption method.
According to an embodiment of the invention, a discrete logarithm cryptography (DLC) method is used for the generation of a third key by the chip card terminal and a fourth key by the chip card, so that The fourth key is only equal to the third key when the PIN condition is satisfied '= PIN.
For the establishment of the third key, any discrete logarithm cryptography procedures can be used in principle as described, for example, in the National Institute of Standars and Technology (NIST) standard, NIST Special Publication 800-56A, March 2007 , as well as in Standards for Efficient Cryptography, SEC1: Elliptic Curve Cryptography, Certicon Research, September 20, 2000, version 1.0. Such procedures require the generation of so-called domain parameters for the generation of the third and fourth identical keys by the chip card terminal or the chip card.
According to an embodiment of the invention, an elliptic curve cryptography (ECC) method, in particular Diffie-Hellman elliptic curve (ECDH), is used as DLC.
According to an embodiment of the invention, the first identification, that is the PIN 'that is introduced in the chip card terminal, is used as a so-called seed value for the derivation of the first symmetric key. In this way a key of greater length is generated than would be the case with the use of the first identification directly as a key.
According to an embodiment of the invention, a second identification, ie the PIN, is stored on the chip card, from which the second key for decryption of the encrypted text initially received from the chip card terminal can be derived. For the derivation of the second key from the second identification, the second identification can be used as the seed value.
5
10
15
20
25
30
35
40
45
50
According to an embodiment of the invention, the PIN itself is not stored on the chip card, but only the second key. The second key is preferably stored in a protected non-volatile memory area of the chip card. Thus, unlike the prior art, it is not necessary to store the PIN as a reference value in the chip card.
According to an embodiment of the invention, the chip card has an erroneous attempt counter. If the first and second communication channels do not match due to an incorrect PIN entry, then the chip card increases or decreases the counter of erroneous attempts with each message received by the chip card in another communication channel other than the second or the predefined one. Those messages that the chip card receives on another communication channel than the second or the predefined one are otherwise ignored by the chip card. If the number of erroneous attempts exceeds a predetermined threshold value, then the whole chip card or a certain function of the chip card is reversibly or irreversibly blocked.
According to an embodiment of the invention, the chip card has a first user function. The unused chip card is in its first use state, in which a determined communication parameter is set for a first choice of the first communication channel. The chip card passes from its first use state to a use state when it first receives a chip card command on this first communication channel. To continue using the chip card, another communication parameter must be chosen by the chip card terminal.
In another aspect, the invention relates to a chip card with an interface for communication with a chip card terminal through a predefined communication channel, and several other communication channels, means for decryption with the aid of a second symmetric key of an encrypted text received in the predefined channel that is encrypted with the help of a first symmetric key, so that the decryption results in at least one communication parameter if a first identification previously entered in the chip card terminal is correct, one of the other communication channels for protected communication being uniquely set by the communication parameter Between the chip card and the chip card terminal.
In another aspect, the invention relates to a chip card terminal with means for entering a first identification, means for generating an encrypted text from at least a first communication parameter with the aid of a first symmetric key derived from the first identification. , so that with the help of the communication parameter a first protected communication channel can be defined between the chip card terminal and the chip card, and means to send the encrypted text to the chip card through a predefined communication channel.
In another aspect, the invention relates to a method in which the cryptography method of elliptic curves is a cryptographic method of discrete logarithm.
In another aspect, the invention relates to a method in which the Diffie-Hellman method of elliptic curves is a method of discrete logarithm cryptography.
In another aspect the invention relates to a method in which the first identification is used as a seed value for the derivation of the first symmetric key by the chip card terminal.
In another aspect, the invention relates to a method in which a second identification (140) is stored on the chip card, from which the second key can be derived.
In another aspect the invention relates to a method in which the second key is stored in a protected non-volatile memory area of the chip card.
In another aspect the invention relates to a chip card terminal, in which as regards the first communication parameter it is the indication of a transmission frequency, a frequency hopping scheme, a coding procedure and / or a modulation procedure.
Embodiments of the invention will now be explained in detail with reference to the drawings. They show:
Figure 1, a block diagram of a first embodiment of a chip card according to the invention and of a chip card terminal,
Figure 2, a flow chart of an embodiment of a method according to the invention,
Figure 3, a block diagram of another embodiment of a chip card according to the invention and of a
chip card terminal, and
Figure 4, a flow chart of another embodiment of a method according to the invention.
In the following figures, the corresponding elements of the different embodiments are characterized by the same reference symbols.
5
10
15
20
25
30
35
40
45
50
Figure 1 shows a block diagram of a chip card terminal 100. The chip card terminal 100 has an interface 102 for communication with a chip card 104 having a corresponding interface 106. Preferably, interfaces 102 and 106 are made for wireless communication, for example by radio, in particular by an RFID procedure.
The interfaces 102 and 106 are constituted, for example, in such a way that between the interfaces 102, 106 different communication channels can be formed, these communication channels being differentiated from each other in a physical and / or logical plane. For example, communication channels of different transmission frequencies can be formed. Communication channels can also be formed based on different frequency hopping schemes. By "frequency hopping" are understood here frequency hopping procedures according to which the frequencies used for data transmission are continuously modified according to a defined scheme.
The interfaces 102, 106 can also be realized in such a way that different communication channels can be formed with the help of different coding methods and / or modulation methods, such as frequency modulation, amplitude modulation, phase modulation, modulation Pulse width or other modulation methods.
The different communication channels that can be established between interfaces 102 and 106 are designated in the following as the "set of communication channels".
One of the communication channels 108 of the set of communication channels is predefined for initial communication between the chip card terminal 100 and the chip card 104. For example, the communication channel is predefined with respect to its transmission frequency , as well as the method of modulation and coding to be used.
The predefined communication channel serves for the transmission of an encrypted text 110 of the at least one communication parameter K1 from the chip card terminal 100 to the chip card 104 to communicate to the chip card 104, which of the channels of Communication 112 of the set of communication channels must be used for subsequent communication with the chip card terminal 100.
Therefore, the communication parameter K1 includes a data that uniquely specifies this communication channel 112. This data can take the form of a code word. In the chip card 104, a so-called query table may be stored in a non-volatile memory in which the possible code words are assigned, respectively, a specification of one of the communication channels of the set of communication channels.
For the selection of a communication channel from the set of communication channels, all possible available communication channels that can be formed between the interfaces 102, 106 or a selection thereof can be used, so that then each of the communication channels of the set of communication channels, which can really be used for communication between interfaces 102, 106, a unique code word is assigned that can be transmitted as communication parameter 110 from the chip card terminal 100 to the chip card 104.
The chip card terminal 100 has a user interface 114, for example a keyboard or a graphical user interface, by means of which a first identification 116 can be entered. This first identification will be designated in the following as PIN 'without limitation of generality.
The chip card terminal 100 has at least one processor 118 for the execution of an application program 120. The application program 120 can cause the generation of a chip card command 122 to invoke a certain chip card function 124 of chip card 104. For example, the application program 120 needs the chip card function 124 for an authenticity check, for the generation of a digital signature, for the verification of an authorization, in particular an access authorization, the execution of a transaction Financial or similar.
The processor 118 also serves to execute the program instructions of a communication module 126, which serves to select the communication channel 112 from the set of communication channels and thereby to select the communication parameter 110. The parameter selection Communication 110 can be performed according to a predetermined scheme, or randomly, in particular pseudorandomly. For example, a list of different communication parameters 110 is stored in the communication module 126, which is cyclically processed.
The processor 118 also serves to execute program instructions 128 for a symmetric encryption of the communication parameters 110. The encryption is carried out with the help of the PIN '. For this, program instructions 128 may include a key generator 130.
5
10
15
20
25
30
35
40
45
50
55
The key generator 130 can be realized in such a way that from the PIN 'as seed value it generates a first symmetric key, which is designated in what follows as S1. The key S1 is used for symmetric encryption of the communication parameter K1 selected by the communication module 126.
The encrypted text of the communication parameter K1 resulting from symmetric encryption with the key S1 is transmitted through the predefined communication channel 108 from interface 102 to interface 106.
The chip card 104 has a processor 132 which is used to execute the program instructions of a communication module 134. The communication module 134 is made for the processing of the communication parameter K1 eventually received from the chip card terminal 100 . The communication module 134 can access, for example with the communication parameter K1 as a key, an allocation table, in particular a query table, to search for the parameters of the communication channel 112 selected by the chip card terminal 100 , such as its transmission frequency and / or the coding and modulation method to be used.
The processor 132 also serves to execute program instructions 136 for the symmetric decryption of the encrypted text 110 received by the chip card 104 of the chip card terminal 100. For example, the chip card 104 has a memory area protected 138, in which a second identification 140 is stored. The second identification is hereinafter referred to as PIN without limitation of generality. The PIN is communicated to the authorized user of the chip card with the delivery of the chip card 104 separately, for example in the form of a so-called PIN letter.
Program instructions 136 may include a key generator 142, which uses the PIN as the so-called seed value to derive from it a second key. This second key is designated in what follows by S2.
Alternatively, the second key S2 may be stored in the protected memory zone 138 of the chip card 104 instead of the PIN 140. Then the key generator 142 is unnecessary, as well as a storage of the PIN 140 on the chip card 104 In contrast to the state of the art, PIN 140 does not necessarily have to be stored as the reference value 140 for checking the correctness of the '116 PIN.
The chip card 104 may also have an erroneous attempt counter 144. The erroneous attempt counter 144 is made such that each erroneous attempt of the chip card 104 is counted. The number of erroneous attempts is compared to a predetermined threshold value. . When this threshold value is reached, at least the chip card function 124 that is associated with the erroneous attempt counter 144, is reversibly or irreversibly blocked.
Chip card 104 may also have a first use function. For example, the first use state of the chip card 104 can be defined by a particular communication parameter, which specifies one of the communication channels of the set that must be used for the first use of the chip card.
To use the chip card 104, proceed as follows: a user enters the PIN '116 in the chip card terminal 100 through the user interface 114. This can be done by a corresponding demand of the application program 120. The communication module 126 then selects a first communication parameter of the possible communication parameters, for example from the predetermined list of communication parameters, that is, the communication parameter K1.
The key generator 130 generates the key S1 from the PIN '. The communication parameter K1 is then encrypted by the execution of program instructions 128 with the aid of the symmetric key S1. The encrypted text 110 of the communication parameter K1 resulting therefrom is then sent through the predefined communication channel 108 from the interface 102 to the interface 106 of the chip card 104.
If necessary, the chip card 104 derives the S2 key from the PIN or directly accesses the protected memory zone 138 by means of the S2 key. With the help of the key S2, an attempt is made to decrypt the encrypted text 110 of the communication parameter K1 received from the chip card terminal 100 by executing the program instructions 136 by the chip card 104.
The result of this decryption attempt is a second communication parameter that is designated in the following by K2, and which is transferred to the communication module 134. This communication parameter K2 is only identical to the communication parameter K1 if the condition PIN '= PIN is met, since only then the key S1, which has been used for symmetric encryption, can be equal to the key S2 that was used for the symmetric decryption of the encrypted text of the communication parameter K1.
Through the communication parameter K2, a second communication channel 146 can be defined, specifically so that the communication module 134 accesses the assignment table with the communication parameter K2. This second communication channel 146 is again identical to the first communication channel 112, only if the condition PIN '= PIN is met.
5
10
15
20
25
30
35
40
45
50
55
After the transfer of the encrypted text of the communication parameter K1 through the predefined communication channel 108, the chip card terminal 100 generates the chip card command 122 which is sent through the first communication channel 112 from the interface 102 to interface 106. The chip card 104 or its communication module 134 is set for reception on the second communication channel 146 due to the communication parameter K2.
When the second communication channel 146 coincides with the first communication channel 112, then the chip card command 122 is processed by the chip card 104 and the chip card function 124. is invoked. As a result, the chip card 104 generates a response to the chip card command 122 and transmits this response through the first communication channel 112 back to the chip card terminal 100.
51 on the contrary, the second communication channel 146 is not identical to the first communication channel 112, then the chip card 104 ignores the chip card command received in the first communication channel 112 and increases the counter of wrong attempts 144.
For example, the communication channel 108 is defined by a transmission frequency of 9 GHz, the communication channel 112 by a transmission frequency of 10 GHz and the communication channel 146 by a transmission frequency of 11 GHz, so that the transmission frequencies of the communication channels 112 and 146 differ from each other, since the PIN 'entered in the chip card terminal 100 is not equal to the PIN. When the chip card 104 receives in this case a signal at the frequency of 10 GHz from the chip card terminal 100, although it has waited for a reception at the frequency of 11 GHz, this signal is ignored and the counter of erroneous attempts is increases In this way there is an implicit verification of the PIN 'without the PIN' having to be compared directly with the PIN, and without the PIN being stored on the chip card.
Figure 2 shows a corresponding flow chart. In step 200, the PIN 'is entered in the chip card terminal. Then, in step 202, by the chip card terminal 100, the communication parameter K1 is set to select one of the communication channels of the communication channel set. In step 204, the communication parameter K1 is symmetrically encrypted with the help of the PIN '. This can be done so that from the PIN 'with the help of a key generator the symmetric key S1 is derived, which then serves to encrypt the communication parameter K1.
In step 206, the encrypted text of the communication parameter K1 generated with the aid of the key S1 is transmitted through a predefined communication channel from the chip card terminal to the chip card.
The chip card 104 undertakes in step 208, the attempt to decrypt the communication parameter K1 based on the PIN. The correct PIN can be stored in a protected memory area of the chip card, and is used to derive a symmetric S2 key. Alternatively, the S2 key can also be stored directly in the protected memory area of the chip card.
The decryption of the encrypted text of the communication parameter K1 with the key S2 results in a communication parameter K2. By this communication parameter K2 a second communication channel of the set can be defined. Only if the PIN 'is correct, that is, if the PIN condition is met' = PIN, the communication channels specified by the communication parameters K1 and K2 are identical
In step 210, the chip card terminal generates a chip card command and sends this to the chip card through the first communication channel specified by the communication parameter K1 (step 212). In step 214, the chip card can only receive the chip card command, if the second communication channel, to which the chip card adapted for reception, is identical to the first communication channel, that is, if meets the PIN condition '= PIN. In the opposite case, the chip card ignores the encrypted text received in the first communication channel and increases its counter of erroneous attempts.
As regards the communication parameter K1, a public key of the chip card terminal can be treated in an embodiment of the invention. The encrypted text of this public key, which has been generated by symmetric encryption with the help of the S1 key, is transmitted from the chip card terminal to the chip card. The chip card receives only then the correct public key from the chip card terminal, when the PIN '= PIN condition is satisfied, since only then can decryption of the encrypted text be achieved with the help of the key
52 (see the embodiment of Figure 1). The public key of the chip card can be consulted, for example, from an external key server through a network, in particular the internet.
From the private key of the chip card terminal and the public key of the chip card, the chip card terminal can derive a symmetric key S3 according to the Diffie-Hellman method. Consequently, the chip card from the public key of the chip card terminal and its private key can also derive a symmetric key S4 according to the Diffie-Hellman method. The keys S3 and S4 are identical, if the condition PIN '= PIN is met.
In this embodiment, the first communication channel (see communication channel 112 of Figure 1) is defined at least in a complementary manner by the symmetric key S3 = S4. The chip card command
5
10
15
20
25
30
35
40
45
50
sent to the chip card by the chip card terminal is specifically encrypted with the symmetric key S3, and then it can only be decrypted, that is, received by the chip card, when the chip card command can be decrypted with help of the S4 key. Otherwise, the chip card command is ignored and the erroneous attempt counter is incremented.
Figure 3 shows an embodiment of a chip card according to the invention and a chip card terminal according to the invention, in which a discrete logarithm cryptography method is used for the generation of the S3 or S4 keys. In addition, in the embodiment according to Figure 1, the processor 118 serves for the execution of program instructions 148, through which there is a so-called key setting scheme for the generation of the symmetric key S3.
The key setting scheme works according to a discrete logarithm cryptography (DLC) procedure, in particular elliptic curve cryptography (ECC), preferably according to an elliptic curve Diffie-Hellman (ECDH) method. To generate the symmetric key S3, the program instructions 148 first produce a first domain parameter that is referred to as D1.
In addition, the communication module 126 can generate a first channel parameter KA1 or read it from a predetermined list, which for example specifies the physical properties of the first communication channel. The first channel parameter KA1 corresponds to the channel parameter K1 in the embodiment of Figure 1.
The domain parameters D1 and the channel parameter (s) KA1 are encrypted with the aid of the S1 key by the program instructions 128. The encrypted text 110 obtained from KA1, D1 with the aid of the S1 key is transmitted through the predefined communication channel 108 from interface 102 to interface 106.
The chip card 104 decrypts the encrypted text 110 with the help of the symmetric key S2. As a result of the decryption, the chip card 104 receives the second channel parameter KA2, which corresponds to the communication parameter K2 in the embodiment of Figure 1. In addition, the chip card receives the domain parameter D2. The channel parameter KA2 is processed by the communication module 134 to determine, for example, the physical specification of the second communication channel 146.
The chip card 104 also has in the embodiment of Figure 1 program instructions 150, corresponding in its functionality to the program instructions 148, and by which the scheme of the chip card is implemented on the side of the chip card key setting
On the side of the chip card terminal by executing the program instructions 148 from the domain parameters D1, the symmetric key S3 is derived, which is stored in a memory 152 of the chip card terminal 100. Accordingly, by executing the program instructions 150 on the side of the chip card 104 from the domain parameters D2, a symmetric key S4 is derived that is stored in a memory 154 of the chip card 104.
The chip card command 122 is encrypted with the symmetric key S3 before it is sent by the chip card terminal and is then transmitted through the first communication channel 112 specified by the channel parameter KA1. The reception of the chip card command 122 by the chip card 104 is only possible if both KA2 = KA1 and D2 = D1 are available, which in turn is only possible when the PIN '= PIN condition is met.
It is particularly advantageous in this embodiment that the transfer of domain parameters D1 through the predefined communication channel 108 cannot be spied on by a third party, since the transmission of domain parameters D1 is done in encrypted form.
Figure 4 shows a corresponding flow chart. In step 400, a PIN 'is entered in the chip card terminal by a user. The symmetric key S1 is derived from the PIN '.
In step 402 the key setting scheme is started. Next, in step 404 a set of domain parameters D1 is generated. With the help of domain parameters D1, the symmetric key S3 is generated by the chip card terminal. In addition, in step 406 by the chip card terminal the channel parameter KA1 is generated or read from a predetermined list.
In step 408, domain parameters D1 and / or channel parameters KA1 are encrypted with the key S1. For example, domain parameters D1 and channel parameter KA1 can be concatenated, resulting in a single communication parameter, which is then encrypted with the key S1. Alternatively, only the domain parameters D1 or only the channel parameter KA1 or a respective subset of the domain and / or channel parameters are encrypted with the key S1. The encrypted text resulting from the encryption with the S1 key, as well as the remaining domain and / or unencrypted channel parameters, are transmitted in step 410 from the chip card terminal to the chip card through the predefined channel (see communication channel 108 of figures 1 and 3).
5
10
15
20
25
30
35
40
In step 412, the chip card attempts to decrypt the encrypted text with the help of the S2 key. In this way the chip card 104 obtains the channel parameters KA2 and the domain parameters D2. From the domain parameters D2 the chip card 104 derives the key S4.
In step 414, the chip card terminal 100 generates a chip card command, which is encrypted with the key S3 (step 416) to transmit this through the first communication channel defined by the channel parameter KA1 (see communication channel 112 in the embodiments of figures 1 and 3). The chip card terminal 100 sends the chip card command in step 418.
Correct reception of this text encrypted by the chip card in step 420 is only possible when the second communication channel 146 coincides with the first communication channel 112, that is, when KA2 = KA1, and when it is also possible to decrypt the Chip card command with the S4 key, that is, when S4 = S3. The conditions KA2 = KA1 and S4 = S3 can only be met if the correct PIN 'has been entered by the user in the chip card terminal, that is, if PIN' = PIN.
List of reference symbols
100 chip card terminal
102 Interface
104 chip card
106 Interface
108 predefined communication channel 110 communication parameter
112 first communication channel
114 user interface
116 PIN '
118 processor
120 application program
122 chip card command
124 chip card function
126 communication module
128 program instructions
130 key generator
132 processor
134 communication module
136 program instructions
138 protected memory zone
140 PIN
142 key generator
144 counter of erroneous attempts
146 second communication channel
148 program instructions
150 program instructions
152 memory
154 memory
Contents3
1 priority claim, no other members on record
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 102007000589 | Germany | A |
Numbers
- Publication
- 2690366
- Application
- 13155103
Titles2
- Spanish
- Procedimiento para proteger una tarjeta de chip frente a un uso no autorizado, tarjeta de chip y terminal de tarjetas de chip
- English
- Procedure to protect a chip card against unauthorized use, chip card and chip card terminal
Classification
- CPC, 7
- G06F21/77
- H04L9/3013
- H04L9/3066
- H04L9/3215
- H04L9/3226
- H04L2209/56
- H04L2209/805
- IPC, 3
- G06F21 77
- H04L9 30
- H04L9 32