Device for using encrypted data and method thereto
Abstract
The present invention relates to a corresponding method using a device (DEV) and encrypted data (DATenc) stored in a first memory (MEM1) of the device (DEV). The device (DEV) further includes a second memory (MEM2) having a higher tamper resistance. The encrypted data (DATenc) is read from the first memory (MEM1), the encrypted data (DATenc) is decrypted by the associated key (K), and the decrypted data (DAT) is in the second memory (MEM2). It will be remembered. Therefore, the encrypted data (DATenc) stored on the device (DEV) can be used in the decrypted format without permitting the owner of the device (DEV) to access the decrypted data (DAT). One application is the emulation of many smart card applications on mobile devices.
Term
Term ended
Projected expiry passed 23 June 2025, 1.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
14 claims: 2 independent, 12 dependent
- 1装置であって、 第1のメモリと、 耐タンパリング性が更に高い第2のメモリと、 暗号化デ―タを前記第1のメモリから読み取る手段と、 前記暗号化データを、関連した鍵によって復号する手段と、前記復号データを前記第2のメモリに記憶する手段とを備えることを特徴とする装置。
- 2請求項1記載の装置であって、前記第2のメモリ及び前記復号する手段は、NFCインタフェースの一部であることを特徴とする装置。
- 3請求項1記載の装置であって、前記第1のメモリは、前記装置を動作させる機能を記憶するよう更に形成されることを特徴とする装置。
- 4請求項1乃至3の何れかに記載の装置であって、前記第2のメモリは、前記鍵を記憶するよう形成されることを特徴とする装置。
- 5装置の第1のメモリに記憶された暗号化データを用いる方法であって、前記装置は、耐タンパリング性が更に高い第2のメモリを更に備え、前記方法は、 前記暗号化データを前記第1のメモリから読み取る工程と、 前記暗号化データを、関連した鍵によって復号する工程と、 復号データを前記第2のメモリに記憶する工程とを備えることを特徴とする方法。
- 6請求項5記載の方法であって、データはもう用いられず、 前記データを前記第2のメモリから読み取る工程と、 前記データを、前記関連した鍵によって暗号化する工程と、 暗号化データを前記第1のメモリに記憶する工程が行われることを特徴とする方法。
- 7請求項5記載の方法であって、前記鍵が遠隔装置によって供給されることを特徴とする方法。
- 8請求項5記載の方法であって、前記暗号化データを構成する多数の暗号化データ組のうちの1つを用いるために、 a)乱数を生成する工程と、 b)暗号化データ組に関連した鍵によって前記乱数を暗号化し、該暗号化結果を遠隔装置に送信する工程と、 c)復号された数を前記遠隔装置から受信する工程と、 d)前記生成された乱数を前記復号された受信数と比較する工程と、 e)前記暗号化データ組を前記関連した鍵によって復号し、前記比較の結果が真の場合に前記復号データ組を前記第2のメモリに記憶し、前記結果が偽の場合に、更なる暗号化データ組に関連した鍵によって工程a)乃至e)を行う工程が行われることを特徴とする方法。
- 9請求項5記載の方法であって、前記暗号化データを構成する多数の暗号化データ組のうちの1つを用いるために、 a)乱数を生成し、該生成の結果を遠隔装置に送信する工程と、 b)暗号化された数を前記遠隔装置から受信する工程と、 c)前記暗号化された数を、暗号化データ組に関連した鍵によって復号する工程と、 d)前記生成された乱数を、前記復号された受信数と比較する工程と、 e)前記比較の結果が真の場合に、前記暗号化データ組を前記関連した鍵によって復号し、前記復号データ組を前記第2のメモリに記憶し、前記結果が偽の場合に、更なる暗号化データ組に関連した鍵によって工程c)乃至e)を行う工程が行われることを特徴とする方法。
- 10請求項5記載の方法であって、前記暗号化データを構成する多数の暗号化データ組のうちの1つを用いるために、 前記装置の位置を判定する工程と、 前記位置に関連した暗号化データ組を判定する工程と、 前記暗号化データ組を関連した鍵によって復号し、前記復号データ組を前記第2のメモリに記憶する工程が行われることを特徴とする方法。
- 11請求項5記載の方法であって、前記暗号化データを構成する多数の暗号化データ組のうちの1つを用いるために、 識別情報を遠隔装置から受信する工程と、 前記識別情報に関連した暗号化データ組を判定する工程と、 前記暗号化データ組を関連した鍵によって復号し、前記復号データ組を前記第2のメモリに記憶する工程が行われることを特徴とする方法。
- 12請求項5乃至11の何れかに記載の方法であって、 前記暗号化データを前記第1のメモリに記憶する初期工程と、 前記暗号化データを復号するための鍵を前記第2のメモリに記憶する初期工程とを備えることを特徴とする方法。
- 13請求項5乃至11の何れかに記載の方法であって、 復号形式におけるデータを遠隔装置から受信する初期工程と、 前記装置においてランダム鍵を生成する初期工程と、 前記データを前記鍵によって暗号化し、前記暗号化データを前記第1のメモリに記憶する初期工程と、 前記鍵を前記第2のメモリに記憶する初期工程とを備えることを特徴とする方法。
- 14請求項5乃至11の何れかに記載の方法であって、 前記暗号化データを遠隔装置から受信する初期工程と、 耐タンパリング性が高い通信チャネルを介して前記鍵を受信する初期工程と、 前記暗号化データを前記第1のメモリに記憶する初期工程と、 前記鍵を前記第2のメモリに記憶する初期工程とを備えることを特徴とする方法。
Independent claims14
37 paragraphs, as filed
The present invention relates to a device including a first memory and a second memory having higher tamper resistance. Furthermore, the present invention relates to a method of using encrypted data stored in a first memory.
Allowing access to sensitive data only to authorized individuals is a well-known challenge in the prior art. One solution is to store sensitive data in a tamper resistant area (ie, in a memory that is virtually unreadable). The aforementioned areas include, for example, smart cards. Smart cards are widely used, especially for sensitive data in financial applications. Here, the owner of the data carrier is not the owner of the data itself. This data is, for example, owned by a bank. Smart cards and the aforementioned memories are relatively expensive because many technical features are required to make the memory highly tamper resistant. Therefore, it is not economical to store a large amount of data in a very secure memory.
For the applications described above, the solution may be to store the encrypted data on a mass storage device and provide the authorized individual with the relevant key. In general, separate data storage means are used for this reason. Thus, the key can be supplied, for example, in the form of an electronic access card. Alternatively, the keys are supplied on a floppy (registered trademark) disk or simply printed on paper, while the encrypted data is stored, for example, on a publicly accessible server. If the above key is out of the hands of the criminal, the data is secure.
Under certain circumstances, it is useful that the data on the storage device is accessible in decryption format, while the owner of the data carrier is not authorized to modify or read the data. That is also not authorized. One example is an executable encryption code that must be decrypted before it can be executed. However, this entails security risks. This is because the data has been decrypted. Further, for example, it is extremely impossible to increase the tampering resistance of a hard disk. Thus, the data carrier owner, who cannot have access, can access the data. Therefore, in this case, a secure memory (for example, a smart card) is selected as the data carrier. This is because the data (for example, a coded instruction) can be stored as it is and is secure anyway. On the other hand, further increase in data capacity increases technical labor and production cost of large-capacity memory having high tamper resistance.
<p> Here, the subject of the present invention solves the above-mentioned drawbacks, and it is possible to use the encrypted data stored on the device in a decryption format without allowing the owner of the device to access the decrypted data. To provide equipment and methods.</p>
<p> An object of the present invention is a first memory, a second memory having higher tamper resistance, a means for reading encrypted data from the first memory, and a means for decrypting encrypted data with an associated key. , Solved by a device comprising means of storing the decrypted data in a second memory.</p><p> The above problem is further solved by a method using encrypted data stored in the first memory of the apparatus. The device further comprises a second memory with even higher tamper resistance, the method comprising reading the encrypted data from the first memory and decrypting the encrypted data with the associated key. It includes a step of storing the decrypted data in the second memory.</p><p> In this way, it is possible to solve the restrictions of the prior art. On the other hand, it uses a large, inexpensive (and insecure) first memory that permanently stores encrypted data, and temporarily stores decrypted data when it is planned to be used, with a small capacity. It is possible to use an inexpensive (and secure) second memory. This second memory can be shared by several applications, thereby reducing technical effort and cost.</p><p> This is effective when the second memory and decryption means are part of the NFC interface. NFC (Near Field Communication) technology has evolved from a combination of contactless identification (ie, RFID technology) and interconnect technology. NFC typically operates over distances of several centimeters in the 13.56MHz frequency domain, but engineers are also working on systems that operate over longer distances (up to 1m). NFC technology is standardized in ISO18092, ECMA340 and ETSI TS102190. NFC also complies with the contactless smart card infrastructure loosely defined under ISO 14443. NFC interfaces are widely used today in mobile phones and other mobile devices. The aforementioned interface is usually already equipped with tamper resistant memory and an encryption / decryption module. Therefore, it is preferable to use the above-mentioned module in the present invention.</p><p> One of the potential applications of the present invention is a device that emulates several smart cards. The above-mentioned devices are generally known, for example, by International Publication No. 01/93212 and International Publication No. 04/57890. When the smart card data to be used is supplied to the NFC interface, the device can communicate with a reader (a power receiving reader for NFC / RFID communication, which usually also writes data). .. According to the present invention, the encrypted data representing the smart card application is decrypted here and effectively loaded into the second memory of the NFC interface.</p><p> It is even more effective when the first memory is further formed to store the function of operating the device. A device typically includes insecure main memory that stores the device's operating system. In this embodiment, the encrypted data and functions of the operating system are stored in the first memory. Therefore, the first memory is used collaboratively.</p><p> Finally, it is effective when a second memory is formed to store the above key. For some applications, it is advantageous if the key to decrypt the encrypted data is stored in the device itself. In this case, the key should be stored in a second memory with high tamper resistance to prevent misuse of the encrypted data.</p><p> An effective embodiment of the method of the present invention is further illustrated. In this embodiment, the step of reading the data from the second memory, the step of encrypting the data with the associated key, and the step of storing the encrypted data in the first memory when the data is no longer in use. The process is carried out.</p><p> Here, the modified data can be stored for later use. So read the data from the second memory, encrypt it, write it to the first memory again, on the one hand freeing the second memory for another application, and on the other hand, permanently the modified data. Remember in.</p><p> It is also advantageous when the key is supplied by a remote device. In this case, the device only stores encrypted data such as encrypted smart card applications. If the encrypted data is to be used, the associated key is sent from the reader to the device and used there to decrypt the encrypted data.</p><p> Effective examples of the present invention are represented by methods. In this method, the following steps are performed in order to use one of a large number of encrypted data sets that make up the encrypted data.</p><p> a) the process of generating a random number, b) the process of encrypting a random number with a key associated with an encrypted data set and sending it to a remote device, c) the process of receiving the decrypted number from the remote device, and d. ) The process of comparing the generated random number with the number of decrypted receptions, and e) Decrypting the encrypted data set with the above related key, and if the comparison result is true, put the decrypted data set in the second memory. If the result of the comparison is false, the steps a) to e) are performed with the key associated with the further encrypted data set.</p><p> For example, in the case of a large number of data sets representing multiple smart card applications, which of the encrypted data sets should be used (ie, which smart card application should be presented to the reader). You need to decide. Assuming that the key associated with the cryptographic data set is stored in the device and also in the reader (and assuming symmetric cryptography), the above procedure chooses which cryptographic data set to choose. This is an advantageous procedure for determining whether or not to use. When using asymmetric cryptography, the private key and public key must be used instead of the same key. Therefore, the random number can be encrypted with the private key, decrypted with the public key, and vice versa. The advantage of this procedure is that the key does not appear in wireless communication at all. Otherwise, in theory, it is possible to squeeze out.</p><p> A very similar example is represented by the method. In this method, the following steps are performed in order to use one of a large number of encrypted data sets that make up the encrypted data.</p><p> a) the process of generating a random number and sending it to the remote device, b) the process of receiving the encrypted number from the remote device, and c) the number encrypted by the key associated with the encrypted data set. The step of decrypting, d) the step of comparing the generated random number with the number of decrypted received numbers, and e) the encrypted data set is decrypted with the above-mentioned related key, and if the comparison result is true, the decrypted data The step of storing the set in the second memory, and if the result of the comparison is false, performing steps c) to e) with the key associated with the further encrypted data set.</p><p> Simply put, the location of random number encryption and the location of random number decryption are different. In this case, the random number is encrypted in the reader and decrypted again in the device. On the other hand, in the above embodiment, the random number is encrypted in the device and decrypted again in the reader. Random numbers are encrypted only once here, so there is an advantage in processing speed. If y is an integer indicating the number of cycles required to find a suitable key, then in this case y + 1 encryption or decryption steps are present, but the preceding method is used. , 2y steps are required.</p><p> As another effective embodiment, there is a method in which the following steps are performed in order to use one of a large number of encrypted data sets constituting the encrypted data.</p><p> The process of determining the position of the device, the process of determining the encrypted data set related to this position, and the process of decrypting the encrypted data set with the related key and storing the decrypted data set in the second memory.</p><p> Here, the geographical location of the device is responsible for determining the encrypted data set to be used. The means for determining the position is, for example, a GPS receiver. In addition, cell identification of GSM or UMTS networks can be used to determine the location of the device if the resulting larger area is still sufficient for a particular application. Finally, it is possible to evaluate the strength of the radio signals from some base stations to determine the position more accurately. A preferred embodiment comprises a table in which the required information is linked to each other.</p><p> More effective is a method in which the following steps are performed in order to use one of a large number of encrypted data sets constituting the encrypted data.</p><p> The process of receiving the identification information from the remote device, the process of determining the encrypted data set related to the identification information, the process of decrypting the encrypted data set with the related key, and storing the decrypted data set in the second memory. Process.</p><p> There is a further possibility of selecting a particular encrypted data set by simply sending the identification information of the encrypted data set from the reader to the device. If the public transport service were to be called the "London Underground," this information would be sent to the device. The table makes it easy to find the appropriate encrypted data set.</p><p> It is even more advantageous when the method of the present invention comprises the following initial steps.</p><p> The process of storing the encrypted data in the first memory and the process of storing the key for decrypting the encryption key in the second memory.</p><p> Encrypted data is transmitted from the remote device to the device and stored in the first memory in order to set the service. Encrypted data usually has no security risk and can be transmitted over an insecure connection (eg, over an insecure internet connection). GPRS download is also applicable. The key can be supplied at the service provider's store. Returning to the "London Underground," this would mean that customers would bring their equipment to the store, where London Underground employees would store the keys in the equipment. Therefore, unauthorized use of encrypted data is almost impossible.</p><p> A more advantageous method comprises the following initial steps.</p><p> An initial process of receiving data in a decryption format from a remote device, an initial process of generating a random key in the device, an initial process of encrypting data with the above key and storing the encrypted data in the first memory, and the above key. The initial process of storing in the second memory.</p><p> In this case, the data needs to be sent over a secure connection. This is because the data is not encrypted. Possible possibilities include secure internet connection and short-range communication. Further conceivable is the service initialization in the store as described above. When the data is received, it is encrypted with a random key. After that, the encrypted data is stored in the first memory, the key is stored in the second memory, and the service initialization is completed.</p><p> Finally, it is effective that the method of the present invention includes the following initial steps.</p><p> The initial process of receiving encrypted data from a remote device, the initial process of receiving a key via a communication channel with high tamper resistance, the initial process of storing encrypted data in the first memory, and the key. The initial process of storing in the memory of 2.</p><p> As mentioned above, it is possible to send encrypted data over an insecure connection. In contrast, the associated key should be sent over a secure connection and later stored in a secure second memory. Therefore, short-range wireless communication, which cannot be easily squeezed out, is preferable because the range of the above-mentioned connection is limited. The encryption key is sent to the device, where it is decrypted by a secret algorithm (especially further by user input). Thus, it is possible to send the code to the customer by "normal" mail. The customer can then download the encrypted data and the encryption key. The encryption key and code are entered into a secret algorithm that cannot be squeezed out because it is executed in an area with high tamper resistance. The result of this decryption is the key to decrypt the encrypted data, which is later stored in a second memory.</p><p> When the key of the encrypted data set is stored in the second memory, updating the encrypted data set is easy. If the London Underground upgrades its software, the customer will download the updated encrypted data over an insecure connection without having to bring their device back to the service provider's store. Is possible.</p>
The present invention will then be described in more detail with reference to the accompanying drawings showing effective embodiments of the invention. The examples described in the present application do not play a role in narrowing the wide range of the present invention.
FIG. 1 shows an arrangement with a device DEV and two remote devices consisting of a server SER and a reader RD. The device DEV is a mobile phone or PDA in this example, and includes a first memory MEM1, a second memory MEM2 with higher tamper resistance, and an encryption / decryption module ENC / DEC. The first memory MEM1 is assumed in this example to be the memory for the operating system and other data required to utilize the device DEV. Since there is usually no or only minor procedure to protect the main memory of the device DEV from misuse, it is usually quite easy to modify the data stored in the memory described above. Thus, sensitive data (eg, in the case of mobile phones, the IMSI (International Mobile Subscriber Identity)) is stored in a tamper resistant memory (eg, SIM (Subscriber Identification Module)). Smart cards that are becoming more and more part of the mobile phone and those emulated by the mobile phone. In this sense, for interfaces that operate according to the short-range communication (NFC) standard. It must also be mentioned that this interface achieves short-range communication with the reader RD and typically also includes tamper resistant memory and means of encryption and decryption, thus in this example the second memory MEM2. And the encryption / decryption module ENC / DEC is part of the NFC (short-range communication) interface INT.
The placement function is as follows. In the first step, the reader RD can also communicate according to the NFC standard and sends the encrypted data DA Tenc to the device DEV (solid line). In this case, the encrypted data DA Tenc represents a ticket-selling application in public transport that must be installed on device DEV before it is ready for use. Upon receipt, the encrypted data DA Tenc is therefore stored in the first memory MEM1.
Alternatively, the encrypted data DA Tenc can also be supplied by the server SER. This is indicated by a dashed line from the server SER to the device DEV. In this case, it is assumed that the server SER is a part of the Internet and holds the above-mentioned application. Upon request, it can be downloaded over a relatively fast (and insecure) internet connection. The above request can be sent to the server SER directly by the device DEV or by the reader RD.
Basically, the device DEV can already be used. Therefore, when the device DEV is near the reader RD, the key K is sent from the reader RD to the device DEV in the second step (solid line). In the third step, the encrypted data DA Tenc is read from the first memory MEM1 and decrypted by the encryption / decryption module ENC / DEC and the key K received from the reader RD. In the fourth step, the data DAT resulting from this decoding is stored in the second memory MEM2. Here, communication between the device DEV and the reader RD can be performed because it is known from the system of the prior art. The data DAT may also include variables and codes.
In another embodiment, the key K is stored in device DEV during service initialization (ie, when encrypted data DATAenc is received from the reader RD or server SER). The encrypted data DATAenc can be transmitted via the insecure communication channels described above. The only constraint is to keep the key K secret. Therefore, the small-capacity key K is transmitted via low-speed but secure short-range communication (broken line) and stored in the second memory MEM2.
Basically, the device DEV can still be used. This procedure can be initiated manually, for example, instead of being initiated remotely by the reader RD. Further, in contrast to the method described above, the key K is not received from the reader RD but is transmitted from the second memory MEM2 to the encryption / decryption module ENC / DEC. Again, the encrypted data DATenc is decrypted, and the data DAT that is the result of this decryption is stored in the second memory MEM2. Communication between the device DEV and the reader RD can take place as described above.
The communication channel between the device DEV and the reader RD shall be secure. Further, the second memory MEM2 has tampering resistance as described above. Therefore, it is not possible to fraudulently use the key K to use the encrypted data DATAenc unnecessarily, for example, to purchase a ticket without paying. The advantage of this method is that applications that use a large amount of memory space can generally be stored in cheap standard memory and are temporarily loaded into the expensive second memory MEM2, which is tamper resistant. To. In this way, sharing between several services is possible, as described in more detail below.
FIG. 2 also shows another embodiment of the device DEV of the present invention, which is also shown in combination with two remote devices composed of a server SER and a reader RD. In addition to FIG. 1, the device DEV includes a random number generator RAND that is part of the NFC interface INT.
The functions of the arrangement shown in Fig. 2 are as follows. First, the unencrypted data DAT is transmitted from the reader RD to the device DEV via short-range communication (solid line) and stored in the second memory MEM2. In the second step, the random key K is generated by the random number generator RAND, stored in the second memory MEM2, and further sent to the encryption / decryption module ENC / DEC. In the third step, the data DAT is encrypted by the key K and by the encryption / decryption modules ENC / DEC. Finally, as a result of this step, the encrypted data DA Tenc is stored in the first memory MEM1 in the fourth step.
Again, the data DAT can also be sent by the server SER (dashed line). In contrast to the embodiment of FIG. 1, here a secure communication channel should exist between the server SER and the device DEV. This is because the data DAT is not encrypted. The data DAT may also be sent from the server SER to the reader RD (dashed line) over the tamper resistant communication channel (eg, by the corporate network) and then to the device DEV over the short-range wireless communication link. It is possible to imagine.
Finally, FIG. 3 shows a method in which an encrypted data set (DS1enc .. DSxenc) can be used. In this example, the encrypted data DATenc represents several ciphers that represent separate smart card applications (ie, one for public transportation, one for movie ticket sales, one for corporate smart card, etc.). It shall be divided into a cryptographic data set (DS1enc..DSnenc). These encrypted data sets (DS1enc..DSnenc) are stored in advance in the initialization routine shown in FIG. 1 or 2. It is possible that the application is stored in another way (eg, directly by the provider of the device DEV (eg, mobile phone)). Each encrypted data set (DS1enc..DSnenc) has an associated key K1..Kn stored in the second memory MEM2. In contrast to FIG. 2, the device DEV further comprises a comparator COMP and the reader RD further comprises an encryption / decryption module ENC / DEC'.
The functions of the arrangement shown in Fig. 3 are as follows. The device DEV must determine which of the applications represented by the encrypted data set (DS1enc..DSnenc) should be selected if it is near the reader RD. This can be done by manual selection. However, in order to ease the user of the device DEV, the following procedure is proposed.
In the first step, the random number R is generated by the random number generator RAND. In the second step, this random number R is encrypted by the key Kx. This key Kx is also used to decrypt the associated encrypted data set DSx. Later, the encrypted random number Renc is sent to the reader in a third step. In the fourth step, the encrypted random number Renc is decrypted by the reader key Krd and by the encryption / decryption module ENC / DEC'. As a result of this processing, in the fifth step, the reader random number Rrd is then sent to the device DEV again and compared with the original random number R by the comparator COMP.
If the result of the comparison is true (ie, the random number R and the reader random number Rrd are the same), the correct key Kx is found (correct processing assumes symmetric encryption and the same dark keys Kx and Krd). To do). Then, in the sixth step, the encrypted data set Dsxenc related to the key Kx is decrypted by the encryption / decryption module ENC / DEC and the key Kx. In the seventh step, the decoding result (data DSx) is stored in the second memory MEM2 (broken line). Here, the device DEV can be used, for example, in public transportation.
If the result of the comparison is false (random number R and reader random number Rrd are not the same), a new random number R is generated and the cycle is also by the next cryptographic data set DSx + 1enc and the next associated key Kx + 1. It will be started. The cycle is recursive until the result of the above comparison is true.
It is not mandatory that the keys (K1..Kn) be tried in the order stored in the second memory MEM2. It is also possible to allow the keys K1..Kn to have different weights depending on how often they are used, thereby reducing search time. Here, the search is initiated by the key Kx, which is most likely to be correct.
It is also possible to assume that a key other than the key Kx for decrypting the associated encryption data set DSx will be used to select the appropriate application. Thus, each encrypted data set DSx is associated with two keys (one for decryption and one that is identical to the reader key Krd).
Moreover, it is not necessary to use symmetric encryption. It is also possible to assume that asymmetric encryption using a public key and a private key will be used.
It can also be seen that the encryption / decryption modules ENC / DEC, random number generator RAND and comparator COMP do not have to be part of the NFC interface INT. In any case, the above arrangement is preferred because the NFC interface INT as a whole is tamper resistant or at least more tamper resistant than the rest of the device DEV.
Furthermore, the random number R is sent directly to the reader RD and is encrypted by the encryption / decryption module ENC / DEC'and the reader key Krd. Later, the encryption reader random number Rrd is sent again to the device DEV. In device DEV, it is decrypted by the key Kx associated with the encrypted data set DSxenc. If the original random number R and the decryption reader random number Rrd are the same, then again the appropriate encrypted data set DSxenc is found.
Finally, the identification ID can be sent from the reader device RD to the device RD to select one of a large number of encrypted data sets (DS1enc..DSnenc) (dotted line). The device DEV receives the identification ID and determines the associated encrypted data set DSx and the associated key Kx. The encrypted data set DSx is loaded into the second memory MEM2 as described above for use.
In the final example, choosing an application is done in a different way. Here, the (geographical) position of the device DEV is determined in the first step. This can be achieved by using cell identification in the case of mobile phones and by using latitude and longitude when GPS receivers are available. In the second step, the encrypted data set DSxenc associated with the above position is determined, and in the third step, the encrypted data set DSxenc is decrypted by the associated key Kx. Finally, the decrypted data DSx is also stored in the second memory MEM2.
Preferably, the table is stored in a device DEV that includes all of the aforementioned links. So there are three fields in the table (ie each line representing a separate application): one for the link to the encrypted data set DSx, one for the key Kx, and one for the location. ). Time-dependent execution of the application can also be assumed (the method shown in Fig. 3 is also possible).
Next, Figure 4 shows the identification ID of the service, the address ADDR of the encrypted data set DSx (emulated smart card) in the first memory MEM1, the key K, the cell identification ID of the wireless network, the latitude LAT and the longitude. An exemplary table with LON, as well as time range TIM is shown. Two applications are currently stored, one for public transport and one for movie ticket sales. The table has a key K, which is preferable. It is stored in the second memory MEM2. In any case, the table can be separated into two parts (unimportant data is stored in the first memory MEM1 and sensitive data is stored in the second memory MEM2).
The first row of the table contains data for the subway operator "London Underground". The address ADDR of the appropriate encrypted data set DSxenc in the first memory MEM1 is "0F01", and the key K for decrypting the encrypted data set DSxenc is "A15B", both of which are in hexadecimal format. For the London Underground, application selection shall be made by the GPS receiver. Therefore, the cell identification ID is omitted. The location where the application is selected is instead indicated by latitude LAT 0 ° 12'10'' and longitude LON 85 ° 52'60''. Figure 4 only shows a simplified table. In general, there will be more lines indicating different subway stations. Alternatively, the latitude LAT and longitude LON ranges can be associated with a particular application. The London Underground is open all day, so the time range TIM field is omitted. Therefore, each time the device DEV comes to the above-mentioned location, the associated encrypted data set DSxenc is decrypted and stored in the second memory MEM2. This can happen due to a change of location or at the request of the associated leader RD.
The second row of the table has data from the movie company "Universal Pictures". The address ADDR of the appropriate encrypted data set DSxenc in the first memory MEM1 is "0FFA", and the key K for decrypting the encrypted data set DSxenc is "3421", both of which are in hexadecimal format. .. In this case, the cell identification of the mobile network is evaluated. Therefore, the field cell identification ID indicates the cell ID 06 of British Telecom, a network provider. Therefore, latitude LAT and longitude LON are omitted. In contrast to the service on line 1, Universal Pictures applications are selected only during business hours from 19:00 to 24:00. In short, the associated encrypted data set DSxenc is decrypted and stored in the second memory MEM2 when the device DEV is in cell ID 06 between 19:00 and 24:00.
It can be seen that the selection of the encrypted data set DSx can also be performed manually. This is a valuable additional possibility, especially if it is not possible to automatically select the appropriate data set DSx.
Furthermore, it is further stated that the present invention is not limited to smart card applications. Rather, a device that must decrypt the encrypted data, especially a particular compatible PC with a secure second memory, is appropriate. It is not necessary for device DEV to communicate with reader RD. It can be assumed that communication will occur between two similar device DEVs (eg, two NFC-compatible mobile phones). An application can be the exchange of (digital) money between two phones, each with an encrypted account.
It should be noted that the above embodiments are more exemplary than limiting the invention, and many other embodiments could be conceived by those skilled in the art without departing from the scope of the claims. In the claims, none of the reference symbols in parentheses shall be construed as limiting the scope of the claims. The terms "comprising", "comprises", and similar terms do not preclude the existence of components or steps other than those described in the claims or the entire specification. The description of the singular form of a component does not exclude the description of the plural form of the component described above, and vice versa. In a device claim enumerating several means, some of these means can be implemented by the same hardware or software item. The fact that specific measures are described in separate dependent claims does not indicate that a combination of these measures cannot be used.
<figref num="1">It is a figure which shows the service initialization, and the use of the encrypted data.</figref><figref num="2">It is a figure which shows another embodiment for setting a service.</figref><figref num="3">It is a figure which shows the method of choosing one of a large number of encrypted data sets.</figref><figref num="4">It is a figure which shows the table which assigns the encrypted data set to a specific place.</figref>
11 members in 5 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 0414648 | United Kingdom | A | |
| 0414648 | United Kingdom | A | |
| 04146486 | United Kingdom | – | |
| 04106887 | European Patent Office (EPO) | A | |
| 04106887 | European Patent Office (EPO) | A | |
| 041068875 | European Patent Office (EPO) | – | |
| 2005052062 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 2005052062 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 200404106887 | – | – | – |
| 2004200414648 | – | – | – |
| 2005052062 | – | – | – |
| EP20040106887 | – | – | – |
| GB20040014648 | – | – | – |
| WO2005IB52062 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| WO2006003558A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006003562A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006003558A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20070030231A | Republic of Korea | A | |
| KR20070030237A | Republic of Korea | A | |
| EP1763718A2 | European Patent Office (EPO) | A2 | |
| EP1763936A1 | European Patent Office (EPO) | A1 | |
| CN1981474A | China | A | |
| CN1981475A | China | A | |
| JP2008504787AThis record | Japan | A | |
| JP2008504788A | Japan | A |
Numbers
- Publication
- 2008504787
- Publication, DOCDB
- 2008504787
- Publication, EPODOC
- JP2008504787
- Application
- 2007518756
- Application, DOCDB
- 2007518756
- Application, EPODOC
- JP20070518756
Titles2
- Japanese
- 暗号化データを用いる装置及び方法
- English
- Devices and methods that use encrypted data
Classification
- CPC, 4
- G06F21/6245
- H04L9/00
- G06F21/00
- G06F15/00
- IPC, 3
- H04L9 10
- G06F21 62
- H04L9 00
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo