Method for secure storage of sensitive data in a silicon chip integrated system storage, in particular a smart card, and integrated system therefor
Abstract
This record has no abstract on file.
Term
Term ended
Expired 8 June 2021, 5.3 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
2 claims: 1 independent, 1 dependent
- 1物理的に区別された少なくとも2つのメモリ装置を備える、電子チップ搭載システムのメモリ内への敏感データの安全化された記録方法であって、 敏感データを、定められた論理コンフィギュレーションによって、少なくとも2つの部分に分割し、 前記電子チップ搭載システム内で前記敏感データの再構成を必要とするように、分割された前記部分を、物理的に区別された前記の少なくとも2つのメモリ装置のそれぞれのものの中に記録し、 前記敏感データが、定められたオクテット数に等しい長さの二進ワードであり、前記敏感データの第1の部分が、前記の敏感データと同じ長さのオクテットのブロックで構成された第1の二進ワードを含み、前記第1の部分が、あらかじめ設定されたコンフィギュレーションによって前記第1の二進ワード内に配分された、正確なオクテットと改ざんされたオクテットの列を備え、前記敏感データの第2の部分は、前記改ざんされたオクテットを補正することができ、前記の第1の部分および第2の部分から前記敏感データを再構成することができるように、前記改ざんされたオクテット数に等しい長さを有し、前記改ざんされたオクテットと1対1に対応するオクテットで構成される第2の二進ワードを含む、方法。
- 2前記の敏感データが暗号鍵である請求項1に記載の方法。
Independent claims2
55 paragraphs, as filed
[0001] The present invention relates to a secure recording method for sensitive data in the memory of an electronic chip-mounted system.
[0002] The present invention is particularly applicable to chip cards.
[0003] The present invention also relates to an on-board system for practicing this method.
[0004] In the framework of the present invention, the term "onboard system" has in common the fact that electronic chips with memory means and data processing, generally composed of microcompressors or microcontrollers, are free to use. Means various systems or devices. Such an on-board system can be configured specifically with a chip card.
[0005] Similarly, the term "sensitive" must be understood in its most general sense. The term refers to any kind of secret or at least confidential data stored in one or more types of memory on a chip card, in particular encryption algorithms, encryption private keys, identification data or It is related to information that has a secret character. This type of data is collectively referred to below as "secret" data.
[0006] The present invention also applies, but not exclusively, to the storage of stored private keys, as it is used, among other things, for secure pre-initialization of chip cards. In fact, it is well known that security features are assigned to chip cards. Again, the term safety must be understood in a broad sense. The term actually covers various concepts such as confidentiality, authentication and the like.
[0007] In the following, for the sake of clarity, the scope of the present invention is by no means limited, and preferable application examples of the present invention are shown unless otherwise stated.
[0008] Normally, in the conventional technique, the secret contained in the chip card is stored linearly in the same memory zone. Among other things, the secret is read-only fixed memory (ROM) or semi-fixed memory, that is, a type called EEPROM (electrically erasable and programmable read-only memory), for example. Stored in reprogrammable memory by electrical erasure. By the way, electronic chip memory is a target of fraudsters, and the number of intrusions that can be revealed is gradually increasing and becoming more sophisticated.
[0009] Above all, "dumping" ("empting" or copying memory) of "ROM" memory has always been a concern for chip cards.
Conventionally, "EEPROM" type memory containing data called sensitive is vulnerable to most of the currently known attacks.
[0011] An object of the present invention is to eliminate the inconvenience of the apparatus of the prior art, which has given some examples above.
[0012] The present invention aims at a secure storage method of sensitive data in the memory of a chip card, more generally an electronic chip-mounted system.
[0013] The present invention also relates to an electronic chip mounting system for carrying out the method. Electronic chips generally include memory and data processing means under the command of the operating system (or "OS").
[0014] Therefore, according to an advantageous feature, the secret is physically and logically "split" into a plurality of memory means provided in the electronic chip.
[0015] In an advantageous embodiment, the memory of the electronic chip is divided into two distinct parts, the first part being a "ROM" type memory, more generally a read-only fixed memory. The second part is composed of "EEPROM" type memory, more generally reprogrammable semi-fixed memory.
[0016] According to a first variant of the method of the invention, the same secret is "split" between two or more physically distinct memory sections.
[0017] In particular, in a preferred field of application of the present invention, if no data is contained in the "EEPROM" type memory portion, except for data programmed by an entity hereinafter referred to as "manufacturer". This method enables authentication of the chip card at the pre-initialization stage.
[0018] In the framework of the present invention, the term "preliminary initialization" is understood to have a general meaning. It specifically relates to a conventional chip card manufacturing stage or a stage prior to a chip card initialization stage called an open type.
[0019] According to a more advantageous embodiment, most of the data constituting the secret is stored in "ROM" memory. A small portion of this data is stored in "EEPROM" memory.
[0020] According to this additional feature of the present invention, the private key thus has its very large portion contained within a portion of "ROM" type memory. To allow the operating system described above to fully use the private key, the manufacturer only needs to write a smaller portion of the private key within a portion of "EEPROM" type memory. Due to its unique storage, the private key can be divided into two parts and sent to the manufacturer who provides the two distinct services, thus reducing the risk of fraud when transferring the secret. Attention is paid to what can be done.
[0021] Thus, this unique storage has the advantage of minimizing the number of octets programmed under probe by the manufacturer, resulting in reduced manufacturing costs. In fact, the keys currently in use are very long to ensure high security. Therefore, by transferring most of the "ROM", it is possible to mitigate the very long storage of these keys that is normally performed in the "EEPROM".
[0022] According to a second variant, the first secret is stored within the first portion of memory, and one or more other secrets derived from the first secret may be direct or indirect. It is stored in at least the other portion of the physically distinct memory. This additional secret can advantageously be obtained by encryption.
[0023] By way of example, in the usual application of the method according to the invention, the (symmetrical) encryption key resides in the first memory zone of a "ROM" type chip card when masking the chip card. Confidential information is stored in a second memory zone of type "EEPROM" when using the chip card. This information is encrypted (eg, using an algorithm called a "DES" triple) with the above-mentioned encryption key residing in the "ROM" zone. This method has great advantages. This is because, in addition to protecting memory from "dumping", information is also found to be protected when written into a chip card. The entity that "writes" the key doesn't even know it.
[0024] From the above, the secret is completely known even if the unauthorized intrusion into any part of the memory is successful regardless of the embodiment or the corresponding modification of those embodiments. The result is that it cannot be done. In reality, as long as the allocation of secret elements between different parts of memory is done reasonably well, the illegally obtained partial knowledge of the secret, for example, deduces the complete secret of the above partial knowledge. Even considering the deciphering of ciphertext using appropriate mathematical processing, it is never possible to know the secret completely after that. This reasonable allocation is itself possible by one of ordinary skill in the art. Therefore, it is considered that the intrusion will eventually fail.
Further, as shown in more detail below, the methods of the invention can be combined with verification, authentication and / or cryptographic measures known per se, but the security gained is Further enhanced by measures specific to the present invention.
[0026] Therefore, the present invention is a secure recording method of data called sensitivity in the memory of an electronic chip-mounted system having at least two physically distinguished memory means, wherein the sensitive data is described. A method characterized in that it is divided into at least two parts by a defined logical configuration, and each of the two parts is recorded in one of the physically distinct memory means. Is the main target.
[0027] The present invention also covers electronic chip-mounted systems for carrying out this method.
[0028] According to a unique embodiment, this method divides the sensitive data into first (d) and second (d') parts, each of which is physically distinct first (1). ) And the operation associated with the recording of the first part (d), which is recorded in the memory means of the second (2) and is called a checksum for the sensitive data, and the result is that of the information data. Appearing in the form, the information data is further recorded in the first memory means (1), and then reading the information data, adding a checksum to the sensitive data, and the sensitivity. Each time the data is used, it is characterized by including a comparison of the read information data with the result of the additional checksum control operation so that its completeness can be proved.
[0029] According to another proprietary embodiment, the method divides the sensitive data into a first portion (d) and a second portion (d'), each physically distinguished. It is recorded in the memory means of the first (1) and the second (2), and an operation accompanying the recording of the first part (d) called the hash of the sensitive data is performed, and the result is information data. Appearing in the form of (H), the information data (H) is further recorded in the first memory means (1), further reading the information data (H), adding a hash of the sensitive data. It is characterized by including an operation and a comparison of the read information data with the result of the additional hash operation so that the integrity of the sensitive data can be proved each time it is used.
[0030] Here, the present invention will be described in more detail with reference to the accompanying drawings.
As described at the beginning of the present specification, a preferred application of the present invention, that is, a case of security in the initialization stage of the chip card, will be described below.
More precisely, the method according to the invention in the application to the storage of an asymmetric private key with the reference symbol d below will be described here. This key d allows the chip card to create a ciphertext with an appropriate asymmetric algorithm. When this ciphertext is returned to the authentication terminal of the chip card, it can be used for the authentication.
FIG. 1 schematically shows an architectural example of a chip card CP. This chip card has a memory M, which in the example shown is a type of random access memory 3 called "RAM (random access memory)" and a "ROM" type fixed portion 1. It consists of a non-volatile memory having a semi-fixed portion 2 or a similar portion called "EEPROM". The chip card CP further comprises a data processing unit, eg, a CPU and a reference-coded microprocessor that works with operating system 4. The operating system is a piece of software consisting of a series of microinstructions that can store all or part of it in "ROM" zone 1 and / or "EPROM" zone 2 of memory M.
[0034] According to the features of the present invention, the storage of the key d takes place within at least two physically distinct parts of memory M. More precisely, in the example illustrated here, the storage of this key d is the non-volatile part of memory M, i.e. part 1 of "ROM" type fixed memory and "EEPROM" type semi-fixed memory. Executed in some or similar memory 2 of.
[0035] Therefore, the private key d exists during an operation in "ROM" 1 and called "under probe" by the manufacturer in "EEPROM" 2, which exists before arriving at an entity called "manufacturer". It consists of the part written in. The octets programmed in "EEPROM" 2 are extremely sensitive data processed as safety octets. That, of course, assumes that the private key d is already known at the time of masking.
[0036] As an example, for the sake of clarity, let's look at the case of a 1024-bit (ie, 128 octets) private key d below.
[0037] In a preferred embodiment of the method of the invention, the key d is entirely present in "ROM" 1, but certain octets are false or tampered with. As an example, suppose one octet is false for every 16 octets of block, and the wrong value is spontaneously written into the "ROM" code.
[0038] In FIG. 1, reference symbol B<sub>1</sub>From B<sub>8</sub>Various blocks of key d in are shown. Reference symbol O for incorrect octets<sub>1</sub>From O<sub>8</sub>Is attached. Reference symbol O'<sub>1</sub>From O'<sub>8</sub>The correct value of the octet marked with is stored in "EEPROM" 2 in the form of the corresponding 8 octets. These octets O'<sub>1</sub>From O'<sub>8</sub>Form a partial key d'.
[0039] Therefore, in this example, 8 octets (ie 128/16 = 8) must be programmed in "EEPROM" 2. However, saving to "EEPROM" 2 can be optional, and operating system 4 working with the data processing unit CPU can be called "d" when used with the exact and complete key "RAM". It must be well understood to undertake the reconstruction to 3. This reconstruction is simply the wrong octet O in the example already described.<sub>1</sub>From O<sub>8</sub>The correct octet O'<sub>1</sub>From O'<sub>8</sub>It is done by replacing with.
Therefore, whatever the means, in particular, to infer the "whole secret", i.e. the perfectly correct key d, from knowing one of the keys d or d'by the above-mentioned "dumping" fraudulent operation. It is admitted that it cannot be done.
[0041] As already mentioned, for good security, the key is generally as long as 128 octets or 1024 bits, as mentioned above. In addition to the degree of security, the method according to the invention can allow only a very small portion of the entire key d, namely 8 octets or 64 bits, to be recorded in "EEPROM" 2. This is a great advantage as only this part of the key has to be written by the manufacturer under the "probe" and this operation is time consuming and costly.
It must be well understood that there are many other allocation configurations of keys between two types of memory, "ROM" 1 and "EEPROM" 2. Two rows of octets should simply have a one-to-one correspondence. However, one of ordinary skill in the art knows that this allocation has the same length as the two partial keys d (fully exact key d "but is partially" tampered with ") or d'and is mathematical. It should be noted that it is not possible in any other way to deduce the entire key from this partial knowledge. The allocation described above with reference to Figure 1 meets this requirement for the key length in question.
[0043] In the additional modification embodiment of the method of the present invention for further enhancing the obtained security, the integrity of the private key d can be guaranteed, and the memories of "ROM" 1 and "EEPROM" 2 can be guaranteed. It is conceivable to store information data in "ROM" 1 that makes it possible to maintain the integrity of the data for a long period of time. This data could take the form of a checksum calculation for the private key, known under the name "checksum". This data can also be obtained using this "hash" feature of the same key. Therefore, in the latter case, the type of algorithm known favorably by the abbreviation "SHA-1" is used. Therefore, this unique algorithm must be inserted inside the chip card. The result of this hash function is 160 bits long. The first operation from which the data can be obtained accompanies the recording of key d in "ROM" 1.
[0044] The "checksum" or "hash" is executed each time the private key is used and is compared with the information data recorded in the "ROM" 1 memory.
FIG. 2 schematically illustrates the architecture of a chip card CP that stores such "hash" data in memory "ROM" 1. Elements common to Figure 1 have the same reference numbers and will only be described again when necessary.
[0046] Data H is stored in "ROM" 1 and is checked each time the key is used to maintain the integrity of the "ROM" 1 and "EEPROM" 2 memory zones. This confirmation is performed under the command of the data processing unit CPU and the program recorded in the memory.
Up to this stage of explanation, it has been speculated, at least implicitly, that the secret data distributed between the two physically distinct parts of memory M constitutes the same and only one secret.
[0048] In the additional modification embodiment of the method according to the present invention, the secret data stored in the "ROM" 1 memory can constitute the first secret. The second secret data derived from the first secret data can constitute the second secret. According to one of the features according to the invention, these data are thus stored in a physically distinct second portion of memory M, for example in "EEPROM" 2. These data can advantageously be obtained from the encryption of the first data by using some suitable algorithm of symmetric or asymmetric type. The secret is "divided" or "divided" in the sense of the method according to the invention and can be considered incapable of deducing from the knowledge of only one part of memory M.
[0049] From the above, it is easily recognized that the present invention properly achieves the defined object.
[0050] The present invention, such as a key or the like, by physically allocating within at least two physically distinct parts of the memory of a chip card, more generally an electronic chip-mounted system. Allows a high level of safety for the storage of sensitive data.
[0051] However, it must be made clear that the present invention is not particularly limited to the embodiments that have been articulated with reference to FIGS. 1 and 2.
[0052] In particular, secret data can be distributed within two or more physically distinct parts of memory. Similarly, the number of secrets derived from the first can be greater than one if the distributed data do not show the same and single secret. Similarly, secrets can be derived in succession and recorded separately within physically distinct parts of memory.
[0053] The present invention is not limited to the application of authentication in the pre-initialization stage of the chip card described in more detail above. It can also be applied to sensitive data, encryption keys and anything else that must be stored in the onboard system's memory.
BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 is a diagram schematically showing an example of a memory configuration of a chip card according to an aspect of the present invention in order to apply this method to recording a private key.
FIG. 2 is a diagram schematically showing a modified embodiment of the memory configuration of the chip card of FIG.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2006048704A | Cited by | Japan | Examiner |
| JP2000155819A | Cites | Japan | – |
| US05623546A | Cites | United States of America | – |
| US05150407A | Cites | United States of America | – |
| JP07013873A | Cites | Japan | – |
| JP2000134195A | Cites | Japan | – |
12 members in 6 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 0007318 | France | – | |
| 0007318 | France | A | |
| 0007318 | France | A | |
| 0101773 | France | W | |
| 0101773 | France | W | |
| 2000200007318 | – | – | – |
| 2001001773 | – | – | – |
| FR20000007318 | – | – | – |
| WO2001FR01773 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| WO0195273A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2810138A1 | France | A1 | |
| US2002108051A1 | United States of America | A1 | |
| EP1247263A1 | European Patent Office (EPO) | A1 | |
| CN1386250A | China | A | |
| JP2003536154A | Japan | A | |
| FR2810138B1 | France | B1 | |
| CN1193320C | China | C | |
| JP3734473B2This record | Japan | B2 | |
| JP2006048704A | Japan | A | |
| US7260727B2 | United States of America | B2 | |
| JP5082046B2 | Japan | B2 |
24 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313111S111 | S111 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 3734473
- Publication, DOCDB
- 3734473
- Publication, EPODOC
- JP3734473B
- Application
- 2002502734
- Application, DOCDB
- 2002502734
- Application, EPODOC
- JP20020502734
Titles2
- Japanese
- 電子チップ搭載システム、特にチップカードのメモリ内での敏感データの安全化保存方法と、その方法を実施する搭載システム
- English
- An electronic chip-mounted system, especially a secure storage method for sensitive data in the memory of a chip card, and an on-board system that implements the method.
Classification
- CPC, 3
- G07F7/1008
- G06Q20/341
- G07F7/082
- IPC, 5
- G06K19 07
- G06K19 10
- H04L9 10
- G06K19 073
- G07F7 10