System for secure data storage on cd-rom
Abstract
A system for effectively protecting confidential encrypted data stored on a CD-ROM by using a decryption key which is never accessible in unscrambled form to the user. In addition to the CD-ROM (1) on which the data at least partially encrypted by means of an encryption algorithm having a decryption key (K) is stored, and a CD-ROM player, the system comprises an electronic decryption microcircuit (13) embedded in said CD-ROM (1); means for data communication between the CD-ROM player (2) and the electronic decryption microcircuit (13) embedded in the CD-ROM (1); a smart card (3) containing at least one portion (K1) of the decryption key (K), the optional remaining portion (K2) of the decryption key (K) being included in the electronic decryption microcircuit (13) embedded in the CD-ROM (1); and means for secure data communication between the smart card (3) and the electronic microcircuit (13) embedded in the CD-ROM (1). For decryption, the encrypted data read out of the CD-ROM (1) is input into the electronic decryption microcircuit (13) embedded in the CD-ROM (1), which temporarily and transiently stores a decryption key received from the smart card (3) by secure transmission at the start of the read-out process, and uses it to decrypt the data before restoring the decrypted data for use.

Term
Term ended
Projected expiry passed 26 July 2016, 10.2 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
6 claims: 1 independent, 5 dependent
- 1CLAIMS REVENDICATIONS 1. Secure data storage system on CD-Rom comprising a CD-Rom (1) on which are stored data encrypted at least in part with a cryptographic algorithm having a decryption key K and a CD-Rom reader (2) characterized in that it further comprises;1. Système de stockage sécurisé de données sur CD-Rom comportant un CD-Rom (1) sur lequel sont stockées des données cryptées au moins en partie avec un algorithme cryptographique ayant une clé de décryptage K et un lecteur de CD-Rom (2) caractérisé en ce qu'il comporte en outre ;- an electronic decryption microcircuit (13) embedded in said CD-Rom (1), - un microcircuit électronique de décryptage (13) enrobé dans ledit CD-Rom (1), - des moyens d'échange d'informations entre ledit lecteur de CDRom (2) et ledit microcircuit électronique de décryptage (13) enrobé dans ledit CD-Rom (1), - means for exchanging information between said CDRom reader (2) and said electronic decryption microcircuit (13) embedded in said CD-Rom (1), - a smart card (3) containing at least a part K ·] of the decryption key K, the possible remaining part K2 of the decryption key K appearing in said electronic decryption microcircuit (13) embedded in said CD-Rom (1) and - une carte à puce (3) renfermant au moins une partie K·] de la clé de décryptage K, la partie restante éventuelle K2 de la clé de décryptage K figurant dans ledit microcircuit électronique de décryptage (13) enrobé dans ledit CD-Rom (1) et - des moyens sécurisés d'échange d'informations entre ladite carte à puce (3) et ledit microcircuit électronique (13) enrobé dans ledit CDRom (1). - secure means for exchanging information between said smart card (3) and said electronic microcircuit (13) embedded in said CDRom (1).
46 paragraphs in 1 section, as filed
The present invention relates to the protection of the confidentiality of data stored on a CD-Rom.
The only possibility to safeguard the confidentiality of data stored on a CD-Rom is encryption. However, this protection is only really satisfactory insofar as the decryption key remains inaccessible to the user, which is not the case when the decryption key is stored on the CD-Rom or provided to the user. user in another way. In addition, there is often a significant risk of the decryption key being pirated at the level of the electronic decryption circuit itself, whether it is located in the CD-Rom reader or downstream.
The object of the present invention is to remedy this drawback and to ensure effective protection of the confidentiality of data stored on a CD-Rom.
It relates to a secure data storage system on CD-Rom comprising a CD-Rom on which are stored data encrypted at least in part with a cryptographic algorithm having a decryption key K and a CD-Rom reader. This secure data storage system is remarkable in that it further comprises:
- an electronic decryption microcircuit embedded in said
CD-ROM,
- means for exchanging information between the CDRom reader and the electronic decryption microcircuit embedded in the CD-Rom,
- a smart card containing at least a part K) of the decryption key K, the possible remaining part K<sub>2</sub> the decryption key K contained in the electronic decryption microcircuit embedded in the CDRom and
- secure means for exchanging information between the smart card and the electronic microcircuit embedded in the CD-Rom.
Thanks to this system, the confidentiality of the data stored on CD-Rom is ensured by means of an encryption whose decryption key is never accessible in clear to the user, which greatly reduces the risk of fraud.
The electronic decryption microcircuit embedded in the CDRom is advantageously provided with an inductive or capacitive antenna making it possible to ensure from outside the CD-Rom, in the absence of any contact, both its power supply and exchanges of data. 'information.
The CD-Rom reader is advantageously provided with a smart card connector and an electronic circuit ensuring, in addition to reading the CD-Rom, the management of the information exchange links between itself, the microcircuit. electronic encased in the CD-Rom and the smart card.
The smart card is advantageously provided with an identification code of its owner which must be sent to it at the start of the session for it to agree to communicate with the outside, while the CD-Rom reader is equipped with means monitoring the uninterrupted presence of a smart card in its smart card connector throughout a decryption performed by the electronic microcircuit embedded in the CD-Rom.
Other characteristics and advantages of the invention will emerge from the following description of an embodiment of the invention given by way of example. This description will be given with reference to the drawing in which the single figure illustrates, schematically, the architecture of the secure data storage system on CD-Rom according to the invention.
This figure shows a CD-Rom 1 placed on a CD-Rom reader 2 equipped with a smart card connector 23 into which a smart card 3 is inserted.
The CD-Rom 1 has, like any conventional CD-Rom, an engraved annular area 10 where the data is stored, a centering hole 11 and, around this centering hole 11, a central area 12 allowing it to be gripped and driven. rotating by the mechanism of a CD-Rom reader. It differs from conventional CD-Roms by the fact that the data that it stores are encrypted by a key K algorithm and therefore not directly exploitable, and that it has an electronic decryption microcircuit 13 with an inductive antenna 14 embedded in the plastic of its central area 12. The electronic decryption microcircuit 13 and its inductive antenna 14 are, by design, the contactless chip card technique. The antenna 14, which could also be capacitive, allows both the power supply to the electronic decryption microcircuit 13 and the exchange of information with this electronic decryption microcircuit 13 from outside the CD-Rom. The electronic decryption microcircuit 13 comprises a microcontroller provided with an input / output serial port connected to the antenna 14 and random access memories of RAM and ROM type and possibly EEPROM. It is programmed to claim the decryption key K or the part that it lacks Kj of this cié as soon as it is powered on, receive it in a secure form, put it in RAM memory, receive the encrypted data, decrypt them with the key of K encryption obtained stored in RAM memory and return the decrypted data for use. It will not be described in detail as it comes within the usual practice for a technician of data encryption and decryption.
The CD-Rom reader 2 comprises the usual elements of a CD-Rom reader, including the drive motor in rotation of the CD-Rom read, the optical reading head 20 with laser diode and photodetector mounted on a mobile unit. moving according to a radius of the read CD-Rom and an electronic circuit 21 ensuring the management of the movements of the moving equipment of its reading head 20 and shaping of the signals coming from this reading head. In addition to these elements, it is provided with a sensor 22 cooperating with the antenna 14 of the electronic decryption circuit 13 embedded in the CD-Rom 1, the smart card connector 23, an external communication connector 24 , a display 25 and a keyboard 26. Its electronic circuit 21 provides, in addition to the usual tasks of reading a CDRom;
- the management of the sensor 22 cooperating with the antenna 14 of the electronic decryption circuit 13 embedded in the CD-Rom 1 to ensure the supply and the exchange of information with this last decryption circuit 13,
the management of the smart card connector 23 so as to supply power to a connected smart card 3 and the exchange of information with the latter,
- the management of the external communication connector 24 in order to deliver, to a remote processing system, exploitable data read on the CD-Rom 1 and decrypted by the electronic decryption microcircuit 13 embedded in the CD-Rom 1, with the using a decryption key provided by the smart card 3,
- management of display 25, and
- keyboard management 26.
The smart card 3 comprises a plasticized support card 30 provided with a set of contacts 31 connected to an electronic microcircuit 32 which is represented, for convenience, in the middle of the card but which is in fact buried under the contacts 31. The microcircuit 32 mainly contains a microcontroller (CPU) in connection with an input-output serial port (SIO) connected to the contacts 31 and with part RAM and part permanent memory, both non-rewritable dead type (ROM) and rewritable dead type (EEPROM) intended for the storage of at least part Kj of the decryption key and of a program managing the communication protocol in a secure form of the part Kj of the encryption key residing in the smart card 3.
When reading encrypted data on the CD-Rom 1 is started, the CD-Rom reader 2 supplies the electronic decryption microcircuit 13 embedded in the CD-Rom 1 which then requests the encryption key K or its missing part K ·). In response, the CD-Rom reader 2 puts the electronic decryption microcircuit 13 embedded in the CD-Rom 1 in communication with the smart card 3. The latter requests an identification code from the operator before it 'accept the dialogue. If his complaint is positively satisfied by the operator who types his identification code on the keyboard 26, the smart card 3 transfers at the request of the electronic decryption microcircuit 13 embedded in the CD-Rom 1 and communicates to it, in secure form. , the encryption key K or its missing part Kp The electronic decryption microcircuit 13 embedded in the CD-Rom 1 then places the complete encryption key K in its RAM and informs the CD-Rom reader 2 that it is close to decryption. The CD-Rom reader 2 then establishes an upward and downward communication with the electronic decryption microcircuit 13 embedded in the CD-Rom 1. During this communication, the CD-Rom reader 2 sends to the electronic decryption microcircuit 13 embedded in the CD-Rom 1 the encrypted data that it reads in the CD-Rom 1. The electronic decryption microcircuit 13 embedded in the CD-Rom 1 decrypts the data received using the decryption key K present in its random access memory and returns them in clear to the CD-Rom reader 2 which directs them to its external communication connector 24 so that they are exploited. Simultaneously with the establishment of any communication link with the CD-Rom reader 2, the decryption circuit 13 embedded in the CD-Rom 1 tests the actual presence of the smart card 3 in its connector 23 and interrupts its operation by case of withdrawal of the smart card, which causes the loss of the decryption key K by the decryption microcircuit 13 embedded in the CD-Rom 1 and prevents further decryption after removal of the smart card.
The procedure for authenticating the holder of the smart card prior to any dialogue with the latter which is carried out by requesting a secret code or PIN CODE to be typed on the keyboard followed by verification of this secret code is a standard procedure used. with smart cards used for transactions and will not be detailed here.
The secure transfer of all or part of the decryption key K in the random access memory of the decryption microcircuit 13 embedded in the CDRom 1 can be done according to the following protocol:
During a first step, the decryption microcircuit 13 embedded in the CD-Rom 1 issues a request for the exchange of information to the chip card 3.
- During a second step, the smart card 3, after a favorable progress of the bearer identification procedure, responds with an acknowledgment signal.
-During a third step, the decryption microcircuit 13 detects the acknowledgment signal from the smart card, generates a random A (random binary number) that it encodes with an encryption-decryption key Ci of a asymmetric cryptographic algorithm intended for securing the transmission and sends to the smart card 3 in the form of an encrypted message Cj (A).
- During a fourth step, the smart card 3 receives this encrypted message, ie decrypts using another key, in its possession, of C2 encryption-decryption of the asymmetric transmission cryptographic algorithm used by the decryption microcircuit 13, and obtains the random random:
VS<sub>2</sub>(VS<sub>1</sub>(A)) = A
- During a fifth step, the smart card 3 performs a logical operation of or exclusive between the random A received from the decryption microcircuit 13 and the decryption key K of the data of the CD-Rom 1, or a part Kj of this key missing from the decryption microcircuit and known only to the smart card 3. To simplify, it is assumed here that all of the key K is missing from the decryption microcircuit 13 so that the smart card performs the operation:
A®K = D
- During a sixth step, the smart card 3 encodes the result of this logical operation with the transmission encryption-decryption key C<sub>2</sub> in its possession and transmits it to the decryption microcircuit 3 in the form;
VS<sub>2</sub>(D) = C<sub>2</sub>(A © K)
- During a seventh step, the decryption microcircuit 13 receives this message, decrypts it with its encryption-decryption key Ci and obtains the message:
Ci (C<sub>2</sub>(D)) = D
- During an eighth and final step, the decryption microcircuit 13 recovers the decryption key K of the data of the CD-Rom 1 by submitting the message received from the smart card 3 and decrypted to a logical operation of or exclusive ' with the hazard A that it generated at the start;
D®A = (A®K) © A = K
The procedure for transferring information from the smart card 3 to the decryption microcircuit 13 which has just been described is secure not only because the information is not transferred in the clear but also because the encryption of the transmission is shared between the two speakers and depends on a hazard that changes at each session.
Of course, the secure communication protocol between the electronic decryption microcircuit 13 embedded in the CD-Rom 1 and the smart card 3 which has just been described, is only an example and can be replaced by others. protocol using more complex encryption algorithms like RSA, DSA, etc ...
The exchanges of information with the smart card 3 are carried out, according to the protocol defined in the ISO 7816/4 standard, by means of an execute command when it concerns a transmission towards the smart card. , and a get challenge command in the case of a transmission from the smart card.
One way of verifying the presence of the smart card 3 in the smart card connector 23 of the smart card reader 2 throughout an operation of reading and decrypting the data of the CD-Rom 1 consists in periodically generating hazards in the decryption microcircuit 13, to send them to the smart card 3 so that it signs them, that is to say that it encrypts them with the encryption-decryption key C<sub>2</sub> transmission in its possession, then returns them, to decrypt the signatures of the smart card 3 with the encryption-decryption key C-, of transmission in the possession of the electronic decryption microcircuit 13 embedded in the CD-Rom 1 and to verify that they correspond to the random sent. As hazards used during this procedure for verifying the presence of the smart card 3, the decryption microcircuit 13 embedded in the CD-Rom 1 can use the result of a logical operation of type or exclusive 'between the encrypted data and the decrypted data it is manipulating.
With the secure data storage system on CD-Rom which has just been described, the simple availability of the CD-Rom and its specialized reader no longer makes it possible to exploit the data outside of a conventional cryptographic attack, the difficulty of which is depends on the chosen encryption algorithm. In fact, the key or part of the decryption key is missing, which is stored within the smart card and which is never accessible in clear for the user. The fact of having the chip card in addition is not sufficient since it is also necessary to know the identification code or PIN CODE to start the decryption operations, whether or not it has remained in the CD reader. -Rom during a previous session.
Various additional precautions can be taken, such as the regular change of the identification code of the holder of the smart card or PIN CODE or the limitation of the number of unsuccessful attempts to use the smart card thanks to an auto2751767 inhibition process. of the latter. In addition, an initialization procedure can be provided during a first reading of the CD-Rom, when the latter and its data decryption key chip card have not yet been personalized. When reading the CD-Rom for the first time, with the smart card inserted, the smart card asks the user to choose an identification code that it memorizes permanently. It then dialogues with the electronic microcircuit embedded in the CD-Rom to choose the encryption-decryption keys for their transmission link and to distribute them among them. From this moment, the secrets distributed between the electronic decryption microcircuit embedded in the CD-Rom, the data decryption key chip card and the user make the operation of the system impossible in the absence of the one of its elements and knowledge of the user's identification code.
The system which has just been described is particularly interesting, for protecting sensitive data concerning the activity of a company, stored on a CD-Rom with a view to their use on portable personal computers by authorized personnel required to travel. frequent.
Of course, the present invention is not limited to the example described, but it is susceptible of numerous variations arising from the current practice of a person skilled in the art.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| FR2829603A1 | Cited by | France | – | Search report | – |
| US6831982B1 | Cited by | United States of America | – | Applicant | – |
| WO0172107A2 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO0172107A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| EP1291868A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| EP1291868A1 | Cited by | European Patent Office (EPO) | – | Search report | – |
| FR2829603A1 | Cited by | France | – | Search report | – |
| WO0137478A2 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO0137478A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| FR2794276A1 | Cited by | France | – | Search report | – |
| FR2643475A1 | Cites | France | A | Search report | 1 |
| DE4307395A1 | Cites | Germany | YA | Search report | 1 |
| WO8912890A1 | Cites | World Intellectual Property Organization (WIPO) | Y | Search report | 1 |
16 members in 11 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 9609443 | France | A | |
| FR19960009443 | – | – | – |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| FR2751767A1This record | France | A1 | |
| CA2261629A1 | Canada | A1 | |
| WO9804966A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2751767B1 | France | B1 | |
| EP0912920A1 | European Patent Office (EPO) | A1 | |
| EP0912920B1 | European Patent Office (EPO) | B1 | |
| AT193384T | Austria | T | |
| ATE193384T1 | Austria | T1 | |
| DE69702135D1 | Germany | D1 | |
| ES2147016T3 | Spain | T3 | |
| DK0912920T3 | Denmark | T3 | |
| DE69702135T2 | Germany | T2 | |
| GR3034219T3 | Greece | T3 | |
| JP2001502102A | Japan | A | |
| US6357005B1 | United States of America | B1 | |
| CA2261629C | Canada | C |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Notification of lapseLapsedST | ST | |
| Lien (pledge) cancelledRG | RG | |
| Change of name or company nameCD | CD | |
| Lien (pledge) constitutedGC | GC | |
| Transmission of propertyTP | TP |
Numbers
- Publication
- 2751767
- Publication, DOCDB
- 2751767
- Publication, EPODOC
- FR2751767
- Application
- 9609443
- Application, DOCDB
- 9609443
- Application, EPODOC
- FR19960009443
Titles2
- French
- SYSTEME DE STOCKAGE SECURISE DE DONNEES SUR CD-ROM
- English
- SECURE DATA STORAGE SYSTEM ON CD-ROM
Classification
- CPC, 7
- G11B20/00086
- G06F21/80
- G06F2211/007
- G06F2221/2121
- G06K19/045
- G11B20/0021
- G11B20/00876
- IPC, 8
- G06F1 00
- G06F3 06
- G06F21 80
- G09C1 00
- G06F12 14
- G11B20 00
- G11B20 10
- H04L9 10