Method of choosing one of a multitude of data sets being registered with a device and corresponding device
Abstract
A method of selecting one of a large number of datasets DS1enc to DSnenc registered in the device DEV is provided. Each dataset DS1enc to DSnenc is associated with a particular key K1 to Kn. The exchange information R is encrypted by the device DEV using one key Kx of the keys K1 to Kn. The encrypted exchange information Renc is transmitted to the remote device RD and decrypted using the key Krd stored in the remote device RD. The decrypted exchange information Rrd is returned to the device DEV. Subsequently, the exchange information R is compared with the decrypted exchange information Rrd. If the two are equal, the appropriate dataset DSx is found, otherwise the cycle is restarted with a different key. The roles of device DEV and remote device RD may be modified so that the cycle begins at remote device RD. The present invention also relates to a device that provides a remote device with one of a number of datasets registered in the device.
Term
Term ended
Projected expiry passed 23 June 2025, 1.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
13 claims: 5 independent, 8 dependent
- 1装置に登録されている多数のデータセットの1つの選択後に前記1つのデータセットが前記装置によって遠隔装置に与えられ、且つ各データセットが特定のキーに関連付けられているところの、装置に登録されている多数のデータセットの1つを選択する方法であって:a)交換情報を暗号化するステップであり、 a1)前記装置にて、データセットに関連付けられたキー群の1つのキーを用いて暗号化し、且つ暗号化された交換情報を前記遠隔装置に送信するステップ、又は a2)前記遠隔装置にて、前記遠隔装置に格納されたキーを用いて暗号化し、且つ暗号化された交換情報を前記装置に送信するステップ、 b)暗号化された交換情報を解読するステップであり、 b1)ステップa1)に続く場合に、前記遠隔装置にて、前記遠隔装置に格納されたキーを用いて解読するステップ、又は b2)ステップa2)に続く場合に、前記装置にて、データセットに関連付けられたキー群の1つのキーを用いて解読するステップ、 c)前記交換情報をステップb)に従って解読された交換情報と比較するステップ、及び d)前記比較の結果が真の場合、前記装置によって、データセットを前記遠隔装置に与え、前記比較の結果が偽の場合、ステップa1)若しくはステップb2)にて更なるデータセットに関連付けられたキーを用いてステップa)からd)を実行するステップ を有する方法。
- 2前記装置によって:- 交換情報を生成するステップ、 - ステップa1)に従って前記交換情報を暗号化するステップ、 - 前記遠隔装置から解読された交換情報を受信するステップ、 - ステップc)に従って前記交換情報を比較するステップ、及び - 前記比較の結果が真の場合、データセットを前記遠隔装置に与え、前記比較の結果が偽の場合、ステップa1)にて更なるデータセットに関連付けられたキーを用いて前記生成するステップ又は暗号化するステップを再開するステップ、 が実行される請求項1に記載の方法。
- 3前記装置によって:- 交換情報を生成し、且つそれを前記遠隔装置に送信するステップ、 - 前記遠隔装置から暗号化された交換情報を受信するステップ、 - ステップb2)に従って前記暗号化された交換情報を解読するステップ、 - ステップc)に従って前記交換情報を比較するステップ、及び - 前記比較の結果が真の場合、データセットを前記遠隔装置に与え、前記比較の結果が偽の場合、ステップb2)にて更なるデータセットに関連付けられたキーを用いて前記生成するステップ又は解読するステップを再開するステップ、 が実行される請求項1に記載の方法。
- 4前記交換情報が乱数である請求項1乃至3の何れか1項に記載の方法。
- 5前記データセットが前記装置内の第1のメモリに暗号化された形態で格納されており、ステップd)に従って選択された暗号化データセットが関連するキーを用いて解読され、且つ解読されたデータセットが前記装置内のより改ざんしにくい第2のメモリに格納される請求項1に記載の方法。
- 6多数のデータセットの1つを遠隔装置に与える装置であって、前記多数のデータセットが当該装置に登録されており、各データセットが特定のキーに関連付けられており、且つ当該装置が、データセットに関連付けられたキー群の1つのキーを用いて交換情報を暗号化する手段、暗号化された交換情報を前記遠隔装置に送信する手段、解読された交換情報を前記遠隔装置から受信する手段、前記交換情報を前記解読された交換情報と比較する手段、及び前記比較手段と相互作用して前記1つのデータセットを選択する手段を有する装置。
- 7多数のデータセットの1つを遠隔装置に与える装置であって、前記多数のデータセットが当該装置に登録されており、各データセットが特定のキーに関連付けられており、且つ当該装置が、交換情報を生成する手段、前記交換情報を前記遠隔装置に送信する手段、前記遠隔装置から暗号化された交換情報を受信する手段、データセットに関連付けられたキー群の1つのキーを用いて前記暗号化された交換情報を解読する手段、前記交換情報を前記解読された交換情報と比較する手段、及び前記比較手段と相互作用して前記1つのデータセットを選択する手段を有する装置。
- 8- 第1のメモリ、 - より改ざんしにくい第2のメモリ、 - 暗号化されたデータを前記第1のメモリから読み取る手段、 - 前記暗号化されたデータを関連するキーを用いて解読する手段、及び - 解読されたデータを前記第2のメモリに格納する手段、 を有する請求項6又は7に記載の装置。
- 9前記第2のメモリ及び/又は前記解読手段がNFCインターフェースの部分である請求項8に記載の装置。
- 10前記第1のメモリが、当該装置を動作させる機能を格納するように更に構成されている請求項8に記載の装置。
- 11前記第2のメモリが前記キーを格納するように構成されている請求項8に記載の装置。
- 12装置との通信のために設けられた遠隔装置であって、前記装置が該装置に登録されている多数のデータセットの1つを当該遠隔装置に与えるように構成されており、当該遠隔装置が、交換情報を生成する手段、前記交換情報を前記装置に送信する手段、前記装置から暗号化された交換情報を受信する手段、当該遠隔装置に格納されたキーを用いて前記暗号化された交換情報を解読する手段、前記交換情報を前記解読された交換情報と比較する手段、及び前記比較手段の結果を前記装置に送信する手段を有する遠隔装置。
- 13装置との通信のために設けられた遠隔装置であって、前記装置が該装置に登録されている多数のデータセットの1つを当該遠隔装置に与えるように構成されており、当該遠隔装置が、当該遠隔装置に格納されたキーを用いて交換情報を暗号化する手段、暗号化された交換情報を前記装置に送信する手段、前記装置から解読された交換情報を受信する手段、前記交換情報を前記解読された交換情報と比較する手段、及び前記比較手段の結果を前記装置に送信する手段を有する遠隔装置。
Independent claims13
58 paragraphs, as filed
The present invention relates to one method of selecting a large number of datasets registered in an apparatus. The present invention further relates to a device and a remote device that provide the remote device with one of a number of datasets registered in the device.
For example, authentication products such as smart cards and radio frequency identification (RFID) tags include transportation (ticketing, road tolls, baggage tagging), finance (David and credit cards, electronic wallets, commercial cards). ), Communication (SIM card of GSM phone) and tracking (access management, inventory management, asset management), etc. are widely used. The international standard ISO14443A is an industrial standard for contactless smart cards. Products such as MIFARE®, which comply with ISO14443A, provide RF communication technology for data transmission between a card or tag and a reader. For example, in electronic ticketing for public transportation, travelers can benefit from the improved convenience and speed of ticketing by simply swinging the card above the turntile ticket gate or the reader at the entrance. .. Such products are about to become the key to future personal mobility, supporting numerous uses, including road tolls, airline tickets, access control and many more.
Near Field Communication evolved from the combination of contactless authentication and networking technology Communication; NFC) is a very short-range short-range wireless technology measured in centimeters that enables easy-to-understand, easy, and secure communication between various devices without the need for user configuration. Optimized for. To communicate with the two devices, the user holds them close to each other, or even brings them into contact. The NFC interface of the device automatically connects and configures them to form a peer-to-pear network. NFC can also boot other protocols such as Bluetooth® or Wireless Ethernet® (WiFi) by exchanging configuration and session data. NFC is compatible with contactless smart card platforms. This allows NFC devices to read information from these cards, making contactless smart cards an ideal solution for bringing information and warranty to the NFC world. NFC interfaces have been widely used in mobile phones and other mobile devices in recent years.
The above-mentioned devices capable of emulating a number of smart cards are known by Patent Documents 1 and 2. When a particular application should be used, for example for subway ticketing, this application may be given to the corresponding reader by the device. Thus, for example, consumers can use mobile phones to replace all of these contactless smart cards, which will become a common key and wallet. However, in order to select an application, the device user needs to choose which card must be emulated on the device. This is not user-friendly and may be the main barrier to acceptance of devices that can emulate some smart cards.<patcit num="1"><text>International Publication No. 01/93212 Pamphlet</text></patcit><patcit num="2"><text>International Publication No. 04/57890 Pamphlet</text></patcit>
<p> The present invention provides methods, devices and remote devices of the form defined in the background art that can automatically feed applications to remote devices such as readers without the need for user intervention. The purpose is.</p>
<p> In view of the above problems, in the method of selecting one of a large number of data sets registered in the device according to one aspect of the present invention, after the selection, the one data set is remoted by the device. Given to the device, and each dataset is associated with a particular key, the method is: a) It is a step of encrypting the exchange information. A1) The device encrypts the exchange information using one key of the key group associated with the data set, and transmits the encrypted exchange information to the remote device. Step, or a2) the remote device encrypts using the key stored in the remote device and sends the encrypted exchange information to the device, b) the encrypted exchange information. It is a step of decoding, and b1) the step of decoding using the key stored in the remote device at the remote device when following step a1), or b2) the step of decoding using the key stored in the remote device, or b2) the device when following step a2). In, the step of decrypting using one key of the key group associated with the data set, and c) the step of comparing the exchange information with the exchange information decrypted according to step b), d) the result of the comparison. If true, the device provides the data set to the remote device, and if the result of the comparison is false, step a) using the key associated with the further data set in step a1) or step b2). Has steps to perform from d).</p><p> In view of the above problems, in a device for giving one of a large number of data sets to a remote device according to one aspect of the present invention, the large number of data sets are registered in the device, and each data set is A means of encrypting exchange information using one of the keys associated with a particular key and associated with the dataset, a means of transmitting the encrypted exchange information to the remote device, It has means for receiving the decoded exchange information from the remote device, means for comparing the exchange information with the decoded exchange information, and means for interacting with the comparison means to select the one data set.</p><p> Further, in view of the above problems, in the device for giving one of a large number of data sets to the remote device according to one aspect of the present invention, the large number of data sets are registered in the device and each data. A set is associated with a particular key, and the device is a means of generating exchange information, a means of transmitting the exchange information to the remote device, a means of receiving encrypted exchange information from the remote device, Means for decrypting the encrypted exchange information using one of the keys associated with the dataset, means for comparing the exchange information with the decrypted exchange information, and interacting with the comparison means. It has a means of selecting one dataset.</p><p> In view of the above problems, in the remote device provided for communication with the device according to one aspect of the present invention, the device uses one of a large number of data sets registered in the device. It is configured to give to a remote device, which is a means of generating exchange information, a means of transmitting the exchange information to the device, a means of receiving encrypted exchange information from the device, the remote. A means for decrypting the encrypted exchange information using a key stored in the device, a means for comparing the exchange information with the decrypted exchange information, and a means for transmitting the result of the comparison means to the device. Have.</p><p> Further, in view of the above problems, in the remote device provided for communication with the device according to one aspect of the present invention, the device is one of a large number of data sets registered in the device. The remote device is configured to provide the remote device with a means for encrypting exchange information using a key stored in the remote device, and a means for transmitting the encrypted exchange information to the device. It has means for receiving the exchange information decoded from the device, means for comparing the exchange information with the decoded exchange information, and means for transmitting the result of the comparison means to the device.</p><p> The characteristics according to the present invention provide the advantage that the user does not have to manually select the application of the device. This is because the proposed communication between the device and the remote device automatically determines which application or which data corresponding to the particular application must be given to the remote device. is there.</p><p> An important advantage of the proposed method and device is that the key never appears in wireless communication, otherwise it is avoided where the key could theoretically be sought.</p><p> In the first embodiment of the method according to the invention, the device: --the step of generating the exchange information, --the step of encrypting the exchange information according to step a1), --the exchange information decrypted from the remote device. If the result of the comparison is true, the data set is given to the remote device, and if the result of the comparison is false, step a1). At, the step of resuming the generation or encryption step is performed using the key associated with the further dataset.</p><p> These means have the advantage that the exchange information is generated by the device, which can reduce communication between the device and the remote device, helping to save time and improve security. I will provide a. However, in principle, exchange information can also be generated by a remote device.</p><p> In a more preferred embodiment of the method according to the invention, by the device:-a step of generating exchange information and transmitting it to the remote device-receiving encrypted exchange information from the remote device. Steps to decrypt the encrypted exchange information according to --step b2), --to compare the exchange information according to step c), and-if the result of the comparison is true, the data set is to the remote device. If the result of the comparison is false, the step of resuming the generation step or the decoding step is executed using the key associated with the further data set in step b2).</p><p> This embodiment of the present invention provides the additional advantage that communication between the device and the remote device must occur only once. This is because subsequent decryption using different keys is only done within the device.</p><p> When the exchange information is a random number, the security of communication between the device and the remote device can be improved. The use of random numbers as exchange information has the advantage of making so-called "replay-attacks" impossible.</p><p> Different datasets are "registered" on the device according to a particular application set. The term "registration" means that the datasets do not necessarily have to be stored directly in the device, and the (further) remote device from which this dataset is retrieved after selecting the required dataset, for example a remote server. It means that it may be stored in etc. Furthermore, it is possible that the keys associated with the datasets are not stored in the device, but are downloaded when needed.</p><p> However, in an advantageous embodiment of the invention, a large number of datasets and / or associated key sets are stored in the device.</p><p> By using these means, the proposed interaction between the device and the remote device has the advantage that it begins immediately when both devices are brought into contact. And there is no need to make a sometimes slow and unstable connection to a remote server. Furthermore, under certain circumstances (subway, aircraft, etc.), it may not be possible to establish a connection to a remote server because the network is not available. Therefore, it is particularly advantageous that both the dataset and the corresponding key are stored in the device.</p><p> As mentioned above, the advantage of the proposed method and device is that the key never appears in wireless communication with a remote device, otherwise it is avoided where the key could theoretically be sought. However, it is advantageous for the data to be stored in the device in a secure manner in order to further improve security, for example to prevent unauthorized access to the data by the user or other users.</p><p> In particular, the data set is stored in a first memory in the device in encrypted form, and the encrypted data set selected according to step d) is decrypted and decrypted using the associated key. A particular solution strategy is that the set is stored in a second memory that is more resistant to tampering within the device, while a large, cheaper first memory is used to permanently store the encrypted data. The advantage is that a small amount of expensive second memory can be used to temporarily store the decrypted data when it should be used. This second memory can be shared by several applications, reducing technical effort and cost.</p><p> According to the present invention, in this case, the encrypted data representing the smart card application is decrypted and effectively loaded into a second memory.</p><p> The above-mentioned encryption process may use asymmetric encryption in which the private key and the public key must always be used. Therefore, the exchanged information can be encrypted using the private key and decrypted using the public key, and vice versa. Symmetrical encryption is also applicable.</p><p> However, the policy that the key stored in the remote device is the same as one of the keys stored in the device is such that well-known communication between the reader and the tag is used for the purposes of the present invention. It brings the advantage of gaining. That is, less changes than asymmetric encryption need to be performed, and usually provides the advantage that state-of-the-art readers can be used for the purposes of the present invention.</p><p> It is advantageous that the second memory and / or decoding means described above is part of the NFC interface. As mentioned above, NFC technology evolved from contactless authentication, the combination of RFID technology and interconnect technology. NFC typically operates in the 13.56MHz frequency band over distances of a few centimeters, but engineers are also working on systems that operate at longer distances of up to 1m. NFC technology is standardized by ISO18092, ECMA340 and ETSI TS102190. NFC is also compatible with the widely built ISO14443 contactless smart card infrastructure. The NFC interface usually already has tamper-proof memory and an encryption / decryption module. Therefore, it is preferable to use these modules in the present invention.</p><p> It is further advantageous that the first memory is further configured to store a function for operating the device. The device usually has unguaranteed main memory to store the operating system. In this embodiment, the encrypted data and the function of the operating system are stored in the first memory. Therefore, the first memory is used to work together.</p><p> Finally, it is advantageous that the second memory is configured to store the key. For some applications, it is advantageous that the key to decrypt the encrypted data is stored in the device itself. In this case, this key should be stored in a second memory with tamper protection to avoid unauthorized use of the encrypted data.</p>
The above-mentioned aspects and further aspects of the present invention are clear from the examples of the following embodiments, and these aspects will be described with reference to the examples of these embodiments. The present invention will be described in detail with reference to the drawings showing its effective embodiments. It should be noted that the examples do not narrow the broad scope of the present invention.
Figures 1 and 2 show a device and method in which the encrypted data (DATenc) stored in the device DEV can be used in the decrypted format without providing access to the decrypted data DAT to the owner of the device DEV. Is shown. Such a device DEV can be used advantageously for the invention described. Specifically, FIG. 1 shows a configuration having two remote devices formed by a device DEV, a server SER, and a reader RD. In this embodiment, the device DEV, which is a mobile phone or PDA, has a first memory MEM1, a second memory MEM2 that is more difficult to tamper with, and an encryption / decryption module ENC / DEC. It is assumed that the first memory MEM1 in this embodiment is the memory for the operating system and other data required for the use of the device DEV. Since there are usually no or only minor steps to protect the main memory of the device DEV against unauthorized use, it is very easy to change the data stored in such memory. Therefore, for example, in the case of a mobile phone, confidential data such as the international mobile phone subscriber identification number (IMSI) is stored in a tamper-resistant memory such as a subscriber identification module (SIM). A further example is a smart card, more of which is either part of the mobile phone or emulated by the mobile phone. In this regard, it is also necessary to mention interfaces that operate according to the Near Field Communication (NFC) standard. This interface realizes short-range communication with a reader, and usually has a memory with a tamper-proof function together with an encryption and decryption means. Therefore, in this example, it is assumed that the second memory MEM2 and the encryption / decryption module ENC / DEC are part of the NFC interface INT.
The functions of this configuration are as follows. In the first stage, the reader RD, which can also communicate according to the NFC standard, transmits the encrypted data DA Tenc to the device DEV (solid line). In this case, the encrypted data DA Tenc represents a public transport ticketing application that should be installed on the device DEV before it becomes available. Upon receipt, therefore, the encrypted data DA Tenc is stored in the first memory MEM1.
Alternatively, the encrypted data DA Tenc can also be provided by the server SER. This is illustrated by the dashed line from the server SER to the device DEV. In this case, it is assumed that the server SER is part of the Internet and holds the aforementioned application. Upon request, the encrypted data DA Tenc can be downloaded over a commensurately fast (non-guaranteed) internet connection. This request can be sent to the server SER either directly by the device DEV or by the reader RD.
In principle, the device DEV is no longer ready for use. Therefore, when the device DEV is in the vicinity of the reader RD, the key K is transmitted from the reader RD to the device DEV in the second stage (solid line). In the third stage, the encrypted data DA Tenc is read from the first memory MEM1 and decrypted by the encryption / decryption module ENC / DEC and the key K received from the reader RD. In the fourth stage, this decoding result, that is, the data DAT is stored in the second memory MEM2. In this case, communication between the device DEV and the reader RD can be as known in conventional systems. The data DAT can contain variables and codes.
In an alternative embodiment, the key K is stored in device DEV during service initialization, i.e., when encrypted data DA Tenc is received from the reader RD or server SER. The encrypted data DA Tenc can be transmitted over a non-guaranteed communication channel as described above. The only restriction is that the key K is kept secret. Therefore, the small key K is transmitted via slow but secure short-range communication (dashed line) and stored in the second memory MEM2.
In principle, the device DEV is also ready to be used in this case as well, for example, instead of the procedure being initiated remotely by the reader RD, the procedure can be initiated manually. Further, in contrast to the method described above, the key K is not received from the reader RD but is transmitted from the second memory MEM2 to the encryption / decryption module ENC / DEC. In this case as well, the encrypted data DATenc is decrypted, and the data DAT that is the decryption result is stored in the second memory MEM2. Communication between the device DEV and the reader RD can be performed as described above.
The communication channel between device DEV and reader RD is assumed to be secure. Further, it is assumed that the second memory MEM2 has a tamper-proof function as described above. Therefore, it is not possible to abuse the key K to tamper with the encrypted data DA Tenc, for example to purchase a ticket without payment. The advantage of this method is that applications that typically use a large amount of memory space can be stored in cheap standard memory and temporarily loaded into a second memory, MEM2, with expensive tamper protection. In this way, the second memory MEM2 can be shared among a number of services, as will be described in detail later.
FIG. 2 shows an alternative embodiment of the device DEV according to the present invention. The device DEV is again shown in combination with two remote devices formed by the server SER and the reader RD. In addition to FIG. 1, this device DEV has a random number generator RAND that is a part of the NFC interface INT.
The functions of this configuration are as follows. First, the unencrypted data DAT is transmitted from the reader RD to the device DEV via short-range communication and stored in the second memory MEM2 (solid line). In the second stage, the random key K is generated by the random number generator RAND, stored in the second memory MEM2, and sent to the encryption / decryption module ENC / DEC. In the third stage, the data DAT is encrypted by the encryption / decryption module ENC / DEC using the above key. Finally, the encrypted data DA Tenc as a result of this stage is stored in the first memory MEM1 in the fourth stage.
Again, the data DAT can also be sent by the server SER (dashed line). In contrast to the embodiment of FIG. 1, since the data DAT is not encrypted, there should be a secure communication channel between the server SER and the device DEV. The data DAT is transmitted from the server SER to the reader RD (dashed line) via the tamper-proof communication channel (for example, by the corporate network) and then to the device DEV via the short-range wireless communication link. Is also possible.
Subsequent FIGS. 3-10 show other embodiments of the method of feeding one of a number of applications registered, especially stored in the device DEV, to the reader RD.
Figures 1 and 2 show the device DEV that can be used in a way to feed one of many applications to the reader RD. Further, FIGS. 1 and 2 show how the encrypted data DATenc was decrypted into such a device DEV without providing the owner (or anyone else) of the device DEV with access to the decrypted data DAT. Explains whether it can be stored in a format. For this reason, it is advantageous to use such an original device DEV in a method according to the invention as described in the claims and described below (FIGS. 3-6).
However, it should be noted that the method according to the invention described below is, in principle, the first and second memories MEM1 and MEM2, such as the device DEV described above in FIGS. 1 and 2. It is also applicable to use a device that does not have.
Further, in principle, it is not always necessary to use the encrypted data DA Tenc or the dataset DS1enc, ..., DSnenc described below, and the method according to the invention is also encrypted on the device DEV. It can also be applied to data (sets) that are stored without. However, for the reasons mentioned above regarding the secure storage of encrypted data DA Tenc, it is advantageous that the data (set) used in this method is in encrypted form. The method according to the present invention described in the claims is therefore described below using the encrypted data DA Tenc. However, the scope of the present invention is not limited to the use of encrypted datasets DA1enc to DAnenc.
FIG. 3 shows a first embodiment of a method according to the present invention of how a particular application can be provided here to a remote device in the form of a reader RD. In this example, it is assumed that the encrypted data DA Tenc is divided into several encrypted data sets DA1enc to DAnenc that represent different smart card applications. That is, the encrypted datasets DA1enc to DAnenc are one for public transportation, one for movie ticketing, one for in-house identification, and so on. These encrypted datasets DA1enc to DAnenc are already stored when the initialization routine shown in Figure 1 or 2 is performed. The application can also be stored in different ways, for example directly by the supplier of the device DEV (eg, mobile phone). Each encrypted data set DA1enc to DAnenc has an association key K1 to Kn stored in the second memory MEM2. Unlike FIG. 2, the device DEV further has a comparator COMP, and the reader RD also has an encryption / decryption module ENC / DEC'.
The functions of the configuration shown in Fig. 3 are as follows. When the device DEV is in close proximity to the reader RD, it must always be determined which of the applications represented by the encrypted datasets DA1enc to DAnenc must be selected.
In the first stage, the device DEV generates exchange information. It is advantageous that the exchange information is a random number R generated by the random number generator RAND.
In the second stage, this random number R is encrypted by the device DEV using one of the many keys K1 to Kn, Kx. This key Kx is also for encrypting the associated encrypted dataset DSx. Subsequently, in the third stage, the encrypted random number Renc is transmitted to the reader RD. In the fourth stage, the encrypted random number Renc is decrypted by the encryption / decryption module ENC / DEC'of the reader RD using the reader key Krd. In the fifth stage, the reader random number Rrd, which is the result of this processing, is returned to the device DEV and compared with the original random number R by the comparator COMP.
If the result of this comparison is true, it means that the random number R and the reader random number Rrd are the same and the appropriate key Kx has been found (symmetrical encryption for proper processing). Assuming). Then, in the sixth stage, the encrypted data set DSxenc associated with the key Kx is decrypted by the encryption / decryption module ENC / DEC using the key Kx. In the seventh stage, the data DSx that is the result of decoding is stored in the second memory MEM2 (broken line). The device DEV is now ready for use, for example, in public transport.
If the random number comparison is true, the key Kx associated with the encrypted dataset DSxenc in the device DEV to encrypt the random number R and the reader RD to decrypt the encrypted random number R The key Krd is the same, that is, Kx = Krd. This means that the appropriate application or dataset DSxenc has been found.
If the above comparison result is false, that is, if the random number R and the reader random number Rrd are not the same, the key Kx used in the device DEV and the key Krd used in the reader RD are not the same and are appropriate. Dataset / suitable application has not been found yet. A new cycle starts and a new random number is generated, or the same random number R that was already generated in the first cycle is used and the random number R is encrypted with the new key of the device DEV. .. The encrypted random number is transmitted to a remote reader RD or the like. This cycle is recursively executed until the above comparison result is true.
FIG. 4 shows a further embodiment of the method according to the present invention of how a particular application can be given to the reader RD. Again, assume that the encrypted data DA Tenc is divided into several encrypted data sets DA1enc through DAnenc that represent different smart card applications. That is, the encrypted datasets DA1enc to DAnenc are one for public transportation, one for movie ticketing, one for in-house identification, and so on. These encrypted datasets DA1enc to DAnenc are already stored when the initialization routine shown in Figure 1 or 2 is performed. The application can also be stored in different ways, as described above, for example directly by the supplier of the device DEV (eg, mobile phone).
Again, each encrypted dataset DA1enc to DAnenc has associated keys K1 to Kn stored in the second memory MEM2. Unlike FIG. 2, the device DEV further has a comparator COMP, and the reader RD also has an encryption / decryption module ENC / DEC'.
The functions of the configuration shown in FIG. 4 are as follows. When the device DEV is in close proximity to the reader RD, it must always be determined which of the applications represented by the encrypted datasets DA1enc to DAnenc must be selected.
In the first stage, the device DEV generates exchange information. Again, it is advantageous that the exchange information is a random number R generated by the random number generator RAND. In the second stage, this random number R is transmitted to the reader RD by the device DEV. In the third stage, this random number R is encrypted by the reader RD using the key Krd stored in the reader RD. In the fourth stage, the encrypted random number Renc'is returned to the device DEV by the reader RD. In the fifth stage, this encrypted random number Renc'is decrypted by the device DEV encryption / decryption module ENC / DEC using one of the keys K1 to Kn stored in the device DEV. , In the sixth stage, the obtained random number R'is compared with the original random number R by the comparator COMP.
If the result of this comparison is true, that is, if the original random number R and the random number R'received by decrypting the encrypted random number Renc'are the same, for decryption on the device DEV. The key Kx and the key Krd for encryption on the reader RD are the same. This means that the appropriate application or dataset DSxenc given to the reader RD has been found. Then, in the seventh stage, the encrypted data set DSxenc associated with the key Kx is decrypted by the encryption / decryption module ENC / DEC using the key Kx in the device DEV. In the eighth stage, the data DSx that is the result of decoding is stored in the second memory MEM2 (broken line). The device DEV is now ready for use, for example, in public transport.
As mentioned above, if the random number comparison is true, then the key Kx used in the device DEV to decrypt the encrypted random number Renc'and the reader RD to encrypt the original random number R. It is the same as the key Krd used in, that is, Kx = Krd. This means that the appropriate application or encrypted dataset DSxenc has been found.
If the above comparison result is false, that is, if the random numbers R and R'are not the same, the key Kx used in the device DEV and the key Krd used in the reader RD are not the same and appropriate data. It means that the set / suitable application has not been found yet. In this case, another key stored in the device DEV is used to decrypt the encrypted random number Renc', and the obtained random number is compared with the original random number R. This procedure is repeated until the random numbers R and R'are the same and a suitable application is found.
Methods such as those described in connection with FIG. 4 include encryption of the random number R into an encrypted random number Enc'and communication between the device DEV and the reader RD (random number R and the encrypted random number). The fact that Renc's transmission) must be done has the advantage of being done only once, as subsequent decryption using various keys is done only within the device DEV. In contrast, the method described in Figure 3 requires re-two-way communication between the device DEV and the reader RD if the appropriate application cannot be found in the first cycle. And.
The method described in FIG. 4 will be further described with reference to FIGS. 5 and 6. FIG. 5 shows, for example, well-known communication between a repeater, which is an RFID tag TRA, and a reader RD, where the RFID tag TRA stores data for one application and a corresponding key K. In general, RFID tags require authentication before any communication takes place. Figure 5 shows the interaction at this time. The mutual authentication procedure begins with the reader RD sending a GET_CHALLENGE command to tag TRA. Then, a random number R is generated in the tag TRA and returned to the reader RD. The reader RD uses its own private key Krd stored in the reader and a shared algorithm to calculate the encrypted data block TK1 containing the encrypted random number Renc'and additional control data. , Send it back to the tag TRA. The received encrypted data block TK1 is decrypted by the tag TRA, and the random number R'contained in the data block TK1 is compared with the previously transmitted random number R. If the two match, the tag TRA detects that the same key K = Krd was used. Then, the tag TRA encrypts the control data transmitted by the reader RD and returns it together with the second encrypted data block TK2. The encrypted data block TK2 is for allowing the reader RD to similarly confirm that the same key K = Krd is being used. Assuming that the reader RD also detects that the same key K = Krd is being used, finally a data exchange between the tag TRA and the reader RD can take place.
This authentication process between the reader RD and the tag TRA is also used in the method according to the invention as shown in FIG. In FIG. 6, the tag TRA of FIG. 5 is replaced by a device DEV, such as a mobile phone or PDA as described in FIG. Different tags such as subway tickets, movie tickets, etc. are registered in the device DEV. This registration includes the encrypted datasets DS1enc to DSnenc and keys K1 to Kn used for authentication. The encrypted data sets DS1enc to DSnenc are stored in the database CDB in the secure memory MEM1 as described above in FIG. The keys K1 to Kn are stored in the key database KDB in the memory MEM2 of the device DEV, which is more difficult to tamper with.
When the device DEV is presented to the reader RD, the basic dialogue as described with reference to FIG. 5 is initially used. After receiving the encrypted data block TK1, this dialogue branches into a scheme as shown in Figure 6.
When the reader RD responds with the encrypted data block TK1 as shown in Figure 5, the device DEV retrieves the key Kx from the key database KDB and uses this key to decrypt the encrypted data block TK1. The device DEV tries the keys one after another until the appropriate key is found, and presents the appropriate data set DSxenc (DSx) to the reader RD, as described in detail in FIG.
In the description of FIGS. 3-6, it is assumed that the various applications, namely the encrypted datasets DS1enc-DSnenc and the corresponding keys K1-Kn, are already stored in the device DEV. However, the application may simply be registered in the device DEV. In such cases, the (encrypted) datasets DS1enc to DSnenc are not stored directly in the device DEV, but in, for example, the server SER, from which, as needed, as described, for example, in FIGS. One of the encrypted datasets DS1enc to DSnenc may be downloaded by the device DEV. After being downloaded, the downloaded dataset DSxenc is stored in device DEV and can be presented to remote device RD by device DEV.
If the device DEV is a (mobile) phone, the device DEV can retrieve the dataset associated with a particular application from the remote database CDB of the registered application (tag). This dataset is then loaded into the NFC hardware's arithmetic memory. Since the device DEV emulates a single tag TRA, the dialogue can no longer be continued in standard operating mode.
It is not necessary to try the keys K1 through Kn in the order in which they are stored in the second memory MEM2. The keys K1 through Kn can also have different weights, depending on how often they are used, thereby reducing search time. In this case, the search starts with the key Kx, which has the highest possibility of being the correct key.
It is possible that a key different from the key Kx for decrypting the associated encrypted dataset DSx may be used to select the appropriate application. Therefore, each of the encrypted dataset DSx is associated with two keys. One for decryption and one for the same reader key Krd.
Moreover, symmetric encryption need not be used. Asymmetric cryptography with public and private keys may be used.
Also, the encryption / decryption module ENC / DEC, the random number generator RAND, and the comparator COMP do not necessarily have to be part of the NFC interface INT. However, the configuration shown is preferred because it is assumed that the NFC interface INT as a whole is resistant to tampering or is less likely to be tampered with than the rest of the device DEV.
It should be further noted that the present invention is not limited to smart card applications. Rather, it is suitable for any device where the encrypted data must be decrypted, especially for adaptive PCs with a secure second memory. It is not always necessary for the device DEV to communicate with the reader RD. Communication may occur between two similar device DEVs (eg, two NFC-compliant mobile phones). One of the possible applications is the (digital) money exchange between two phones, each with an encrypted account.
The method described with reference to FIGS. 4 and 6 is the most advantageous modification according to the present invention. This is because this method uses the standard RFID tag authentication procedure as described in Figure 5. Further, as described above, this variant of the method according to the invention is fast and reliable, as this embodiment requires little communication between the remote device RD and the device DEV.
However, as described with reference to FIG. 3, in principle other embodiments of the invention are possible and may be advantageous in certain circumstances.
The following summarizes possible embodiments of the method according to the present invention.
FIG. 7 outlines the method shown in FIG. The device DEV generates a random number R, encrypts this random number R using one of the keys K1 to Kn stored in the device DEV, and further transmits the encrypted random number Renc to the reader RD. .. The reader RD decodes the number Renc using the reader key Krd stored in the reader RD (the reader key Krd is the same as any one of the keys K1 to Kn stored in the device DEV). This decrypted number of readers Rrd is returned to the device DEV, where the original random number R is compared to the number of readers Rrd to identify the appropriate application.
FIG. 8 outlines the methods of FIGS. 4 and 6, in which the random number R generated by the device DEV is transmitted to the reader RD. The reader RD encrypts the random number R into the number of encrypted readers Renc'using the reader key Krd, and returns this number Renc'to the device DEV. The device DEV decrypts this encrypted number Renc'using one of the keys K1 to Kn stored in the device DEV, and compares the obtained number R'with the original random number R. The process of decrypting the encrypted number Renc'using the keys K1 to Kn stored in the device DEV is repeated until a suitable application is found.
In a further embodiment according to FIG. 9, exchange information, which is usually a random number R, is generated by the reader RD. The random number R is sent to the device DEV, where it is encrypted into the number Renc encrypted using one of the keys K1 to Kn, Kx. This number Renc is sent back to the reader RD, where it is decrypted by the reader key Krd. The obtained number R'is compared with the original random number R. If the original random number R and the decrypted number R'are the same, the right key / right application is found. If the comparison is not true, the device DEV encrypts the random number R using another key and sends it to the reader RD or the like. In this case, the reader RD can send a random number R to the device DEV so that the device DEV can detect that further encryption is needed, otherwise specific specific information is given to the device DEV. Will be sent to.
As mentioned above, this comparison is made on the reader RD. However, in principle, it is also possible to send a random number Rrd from the reader RD to the device DEV, and the device DEV compares two random numbers R and Rrd.
A further embodiment is shown in FIG. In this case, the reader RD generates a random number, the random number R is encrypted using the reader key Krd, and the encrypted number Renc'is transmitted to the device DEV. The device DEV decrypts the encrypted number Renc'by one of the keys K1 to Kn, Kx.
The obtained number R'is preferably compared to the original random number R by the reader RD as illustrated. However, it is also possible for the device DEV to perform the comparison by further transmitting the original random number R to the device DEV by the reader RD.
Finally, the embodiments described above are exemplary, but not limited to, the present invention. One of ordinary skill in the art can design a number of alternative embodiments without departing from the scope of the invention as defined by the appended claims. Specifically, in the claims and drawings, the selection of datasets is primarily concerned with encrypted datasets, but this is not considered essential to the present invention. Rather, the invention also relates to selecting one of many unencrypted datasets. Terms such as "have" and "have" do not preclude the existence of any element or step other than those listed throughout the claim or specification. A singular reference to an element does not preclude a multiple reference to this element, and vice versa. In a device claim that lists several means, some of these means may be embodied by one and the same hardware or software item. The mere fact that certain means are listed in different dependent claims does not indicate that a combination of these means cannot be used in an advantageous manner.
<figref num="1">It is a figure which shows the initialization of a service and the use of encrypted data.</figref><figref num="2">It is a figure which shows the alternative embodiment which sets a service.</figref><figref num="3">It is a figure which shows the 1st Embodiment of the method of selecting one of a large number of encrypted data sets according to this invention.</figref><figref num="4">It is a figure which shows the 2nd Embodiment of the method of selecting one of a large number of encrypted data sets according to this invention.</figref><figref num="5">It is a figure which shows the standard authentication procedure between an RFID tag and a reader.</figref><figref num="6">It is a diagram again showing the second embodiment of the method as shown in FIG. 4 and is based on the standard authentication of RFID tags according to FIG.</figref><figref num="7">It is the figure which overviewed the modification of the method according to this invention.</figref><figref num="8">It is the figure which overviewed the modification of the method according to this invention.</figref><figref num="9">It is the figure which overviewed the modification of the method according to this invention.</figref><figref num="10">It is the figure which overviewed the modification of the method according to this invention.</figref>
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2011507318A | Cited by | Japan | Examiner |
| JP2012511761A | Cited by | Japan | Search report |
| JP2011507318A | Cited by | Japan | Search report |
| JP2017500813A | Cited by | Japan | Search report |
| JP2012527190A | Cited by | Japan | Search report |
| US8515073B2 | Cited by | United States of America | Applicant |
11 members in 5 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 0414648 | United Kingdom | A | |
| 0414648 | United Kingdom | A | |
| 04146486 | United Kingdom | – | |
| 04106893 | European Patent Office (EPO) | A | |
| 04106893 | European Patent Office (EPO) | A | |
| 041068933 | European Patent Office (EPO) | – | |
| 2005052066 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 2005052066 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 200404106893 | – | – | – |
| 2004200414648 | – | – | – |
| 2005052066 | – | – | – |
| EP20040106893 | – | – | – |
| GB20040014648 | – | – | – |
| WO2005IB52066 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| WO2006003558A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006003562A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006003558A3 | World Intellectual Property Organization (WIPO) | A3 | |
| KR20070030231A | Republic of Korea | A | |
| KR20070030237A | Republic of Korea | A | |
| EP1763718A2 | European Patent Office (EPO) | A2 | |
| EP1763936A1 | European Patent Office (EPO) | A1 | |
| CN1981474A | China | A | |
| CN1981475A | China | A | |
| JP2008504787A | Japan | A | |
| JP2008504788AThis record | Japan | A |
Numbers
- Publication
- 2008504788
- Publication, DOCDB
- 2008504788
- Publication, EPODOC
- JP2008504788
- Application
- 2007518758
- Application, DOCDB
- 2007518758
- Application, EPODOC
- JP20070518758
Titles2
- Japanese
- 装置に登録されている多数のデータセットの1つの選択方法及び対応装置
- English
- One selection method and corresponding device for many data sets registered in the device
Classification
- CPC, 3
- H04L9/0844
- H04L9/32
- H04L2209/805
- IPC, 11
- H04L9 14
- G06F21 24
- G06K17 00
- G06K19 073
- G06F21 20
- G06F21 00
- G06F21 44
- G06F21 60
- G06F21 62
- H04L9 08
- H04Q7 38
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo