Method for pre-controlling a programme contained in a terminal additional chip card
Abstract
This record has no abstract on file.
Term
Term ended
Expired 12 May 2020, 6.4 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
16 claims: 6 independent, 10 dependent
- 1端末(TE)が接続された遠隔通信網(RR)に関連するデータを保存する第一のチップカード(C1)に加えて、端末(TE)内に挿入された第二のチップカード(C2)に保存されたプログラムの実行を事前に検査する方法であって、 第一のチップカードは端末内に含まれ、 端末、第一のチップカード、および第二のチップカードは、少なくとも一つのマイクロプロセッサと、少なくとも一つのメモリを備えており、 端末は第一のチップカード及び第二のチップカードとの入出力インターフェースを備えており、 該方法が以下の過程 を含むことを特徴とする方法。 -第二のチップカードが第一のチップカードを認証し、および/または、 -第一のチップカードが第二のチップカードを認証し、 第二のチップカード及び第一のチップカードによる、第一のチップカードと第二のチップカード(C1,C2)のうち少なくとも一つの認証の成功が、それぞれ、プログラムの実行の条件となる。
- 2認証が、第一 のチップ カード(C1)による第二 のチップ カード(C2)の認証(A1)を有 しており 、以下の過程を含むことを特徴とする、請求項1に記載の方法。―第二 のチップ カードが第一 のチップ カードに伝送するプログラムの識別子(IPA)と鍵(Ka)とを、第一 のチップ カードに保存されたアルゴリズム(AA1a)に適用して(A121)、結果(R1)を生成し、―結果(R1)と、第二 のチップ カードが第一 のチップ カードに伝送する証明書(CERT)とを比較(A123)して、 結果が証明書と一致した 場合にのみ、プログラムの実行を 第一のチップカード、第二のチップカード、または端末が 行う。
- 3認証が、 第二のチップカードから第一のチップカードへと伝送される プログラムの識別子(IPA)に応じて、第一 のチップ カード(C1)に保存された鍵テーブル(TKa)から鍵(Ka)を選定(A120)することを含 み、 前記プログラムの識別子と選定された鍵とが認証アルゴリズムに適用されて、 第一のチップカード内に保存された証明書と比較されるためのものである結果(R1)を生成する ことを特徴とする、請求項1に記載の方法。
- 4認証が、第一 のチップ カード(C1)による第二 のチップ カード(C2)の認証(A1)を有 しており 、以下の過程を含むことを特徴とする、請求項1に記載の方法。―第一 のチップ カード(C1)から第二 のチップ カード(C2)に乱数(NA1)を伝送し(A124)、―第二 のチップ カードに保存されたアルゴリズム(AA1b)に、伝送された乱数と鍵(Kb)とを適用して(A125,A126)、第一 のチップ カード(C1)に伝送する署名(SG2)を生成し、―第一 のチップ カード内に保存されたアルゴリズム(AA1b)に、乱数と鍵(Kb)とを適用して(A128)、結果(R2)を生成し、―その結果を、第一 のチップ カードに伝送された署名と比較(A129)して、 結果が署名と一致した 場合にのみ、プログラムの実行を 第一のチップカード、第二のチップカード、または端末が 行う。
- 5認証は、第二 のチップ カードが第一 のチップ カードに伝送したプログラムの識別子(IPA)に応じて、第一 のチップ カード(C1)に保存された鍵テーブル(TKb)から鍵(Kb)を選定すること(A127)を含むことを特徴とする、請求項4に記載の方法。
- 6認証が、第二 のチップ カード(C2)による第一 のチップ カード(C1)の認証(A2)を有する場合に、以下の過程を含むことを特徴とする、請求項1に記載の方法。―第一 のチップ カード(C1)から第二 のチップ カードに番号(IMSI)の所定のフィールド(MNC)を伝送し(A220)、―第二 のチップ カード内 に保存された番号(MNC2)と前記 所定のフィールド(MNC) を比 較し(A222)、 前記所定のフィールドが該番号と一致した 場合にのみ、プログラムを実行す る。
- 7所定のフィールドが、少なくとも第一 のチップ カードの識別番号(IMSI)に保存された遠隔通信網(RR)の識別符号(MNC)を含むことを特徴とする、請求項6に記載の方法。
- 8認証が、第二 のチップ カード(C2)による第一 のチップ カード(C1)の認証(A2)を有する場合に、以下の過程を含むことを特徴とする、請求項1に記載の方法。―第一 のチップ カード(C1)から第二 のチップ カード(C2)に乱数(NA2)を読み込み(A223,A224)、―第一 のチップ カードに保存されたアルゴリズム(AA2)に、乱数と鍵(C)とを適用し(A226)、第二 のチップ カード(C2)に伝送される署名(SG3)を生成し、―第二 のチップ カードに保存されたアルゴリズム(AA2)に、乱数(NA2)と鍵(C)とを適用して(A228)、結果(R3)を生成し、―その結果を、第二 のチップ カードに伝送される署名と比較し(A229)、 結果が署名と一致した 場合にのみ、プログラムを 第一のチップカード、第二のチップカード、または端末が 実行す る。
- 9認証は、第二 のチップ カードが第一 のチップ カードに伝送したプログラムの識別子(IPA)に応じて、第一 のチップ カード(C1)に保存された鍵テーブル(TC)から鍵(C)を選定(A225)することを含むことを特徴とする、請求項8に記載の方法。
- 10第一 のチップ カード(C1)による第二 のチップ カード(C2)の第一認証(A1)と第二 のチップ カードによる第一 のチップ カードの第二認証(A2)とを含み、該第二認証は、第二 のチップ カードが第一 のチップ カードによって認証されたら、第一認証に続いて行われ、該第二認証の後で、第一 のチップ カードが第二 のチップ カードによって認証されたら、プログラムが実行されるか、あるいは、 第二 のチップ カード(C2)による第一 のチップ カード(C1)の第一認証(A2)と第一 のチップ カードによる第二 のチップ カードの第二認証(A1)とを含み、該第二認証は、第一 のチップ カードが第二 のチップ カードによって認証されたら、第一認証に続いて行われ、該第二認証の後で、第二 のチップ カードが第一 のチップ カードによって認証されたら、プログラムが実行され 、 該プログラムの実行は、第一のチップカード、第二のチップカード、または端末が行う ことを特徴とする、請求項1から9のいずれか一つに記載の方法。
- 11第二 のチップ カード(C2)から第一 のチップ カード(C1)に伝送される認証要求(DA1;DA2)の応答としてのみ、 第二のチップカードによる第一のチップカードの認証、または、一方のチップカードの他方のチップカードによる相互認証 (A1,A2;A2)が実行されることを特徴とする、請求項1から10のいずれか一つに記載の方法。
- 12第一のチップカード及び第二のチップ カードの うち少なくとも一つの 認証(A1,A2)とプログラムの実行(E5)との間で、第二 のチップ カード(C2)から第一 のチップ カード(C1)にプログラム(PA)を遠隔ロードし(E5)、第一 のチップ カード(C1) によって プログラムを実行する(E5)ことを含 み、 第一のチップカードが遠隔ロード及びプログラムの実行を制御する ことを特徴とする、請求項1から1 1 のいずれか一つに記載の方法。
- 13プログラムは、第一 のチップ カード(C1)のコマンドの下で起動(E5)され、第二 のチップ カード(C2) によって 実行され、コマンドと応答の交換を、第二 のチップ カード(C2)と端末(TE)との間で 、 直接、または第一 のチップ カード(C1)を介して行 い、 該交換が第二のチップカード(C2)と端末(TE)との間で直接行なわれる場合には、第一のチップカード(C1)は、該交換の主導権を端末(TE)に委ねる ことを特徴とする、請求項1から1 1 のいずれか一つに記載の方法。
- 14チップ カードの認証(A1,A2)とプログラムの実行(E5)との間で、第二 のチップ カード(C2)から端末(TE)にプログラム(PA)を遠隔ロードし、端末 によって プログラムを実行する(E5)ことを含 み、 端末が遠隔ロード及びプログラムの実行を制御する ことを特徴とする、請求項1から1 1 のいずれか一つに記載の方法。
- 15遠隔通信網は無線電話網(RR)であり、端末は移動無線電話端末(TE)であり、第一のチップカードは加入者の身元識別カード(C1)であることを特徴とする、請求項1から1 4 のいずれか一つに記載の方法。
- 16端末(TE)が接続された遠隔通信網(RR)に関連するデータを保存する第一のチップカード(C1)に加えて、端末(TE)内に挿入された第二のチップカード(C2)に保存されたプログラムの実行を事前に検査するためのシステムであって、 第一のチップカードは端末内に含まれ、 端末、第一のチップカード、および第二のチップカードは、少なくとも一つのマイクロプロセッサと、少なくとも一つのメモリを備えており、 端末は第一のチップカード及び第二のチップカードとの入出力インターフェースを備えており、 -第一のチップカードを認証する為の手段を第二のチップカードが備え、および/または、第二のチップカードを認証する為の手段を第一のチップカードが備え、 第二のチップカード及び第一のチップカードによる、第一のチップカードと第二のチップカード(C1、C2)のうち少なくとも一つの認証の成功が、それぞれ、プログラムの実行の条件となることを特徴とするシステム。
Independent claims16
1 paragraph, as filed
[0001] The present invention relates to the security of an application program supplied by an additional chip card that can be inserted into a telecommunications terminal. In particular, the terminal is a mobile radiotelephone terminal, which includes an additional chip card reader as well as a first card for identifying subscribers and communicating with a remote communication network. [0002] The GSM-type cellular radiotelephone network is prepared to provide subscribers with application services based on running application programs in SIM chip cards. The technology that utilizes these services is standardized and is commonly referred to as the SIM application toolkit. In particular, a feature called pre-activation allows SIM cards to make requests to the outside world, namely terminals, subscribers, and networks, even during the run of a program. [0003] For example, such an application program includes a menu for contacting a bank server and remotely controlling a bank transaction from a terminal. In order to execute the application development of the value-added service in the SIM card, a means for distributing and maintaining these applications is required while the usage contract is in progress. It can be done by personalizing the SIM card with the appropriate program or remotely loading it by wireless means before delivering it to the subscriber, or by loading these programs directly on the SIM card at the point of sale. become. [0004] Prior art also includes an additional chip card, which is separate from the SIM card and can be inserted into the terminal or connected to the terminal of the SIM card by an external reader. It can be done. The second card is controlled by a program that runs inside the SIM card. The role played by the terminal is transparent, it merely transmits the commands generated by the SIM card to the second card. This exchange of commands aims to develop services that utilize all types of chip cards. For example, the second card is a bank card, which provides a remote payment service on a mobile terminal. [0005] The second card is a means of distributing applications, and carries a program that realizes a value-added service that can actually be found in a SIM card. [0006] The drawback of inserting the second card into the terminal is that it is no longer necessarily the network operator who provides the application, so it is spared any inspection of its authenticity. The second card does not contain any means to prove its contents by terminal, first card, or network. [0007] An object of the present invention is to enhance the pre-use and in-use security of an application that is stored on one additional card and can be executed, in particular by the first card of the terminal or the terminal itself. [0008] For that purpose, in addition to the first chip card that stores the data related to the remote communication network to which the terminal is connected, the program stored in the second chip card that is inserted into the terminal is executed in advance. The means of inspection is characterized by including authenticating one of the first and second cards with the other before and during the execution of the program. [0009] Therefore, authentication protects against unauthorized use, hacking, and duplication of one or more application programs on the second card. [0010] In the present invention, the second chip card is any one of a plurality of additional cards for storing various application programs, and one or more programs by the second card. Based on the above, it does not depend on the communication software means between the second card, the first card, and the terminal. [0011] Having multiple second cards allows the operator to propose a new service to his or her subscribers, who inserts the service into the terminal while managing the inspection of the proposed service. It is done in the form of cards through traditional distribution channels. [0012] According to the first mode of implementation, if the authentication involves authenticating the second card with the first card, the following steps can be included: -Generate one result by assigning the identifier of the program transmitted by the second card to the first card and one key to the algorithm stored on the first card, and -Compare the result with the certificate transmitted by the second card to the first card and execute the program only if they match. [0013] In that case, the authentication may include selecting a key from the key table stored on the first card, depending on the identifier of the program. [0014] According to the second embodiment, if the authentication involves authenticating the second card with the first card, the following process can be included: -Transmit random numbers from the first card to the second card, -Apply the transmitted random number and one key to the algorithm stored on the second card to generate the signature transmitted to the first card, -Apply a random number and one key to the algorithm stored on the first card, generate one result, and -Compare the result with the signature transmitted to the first card and execute the program only if they match. [0015] In that case, the authentication may include selecting a key from the key table stored on the first card according to the identifier of the program transmitted from the second card to the first card. [0016] If authenticating the first card with a second card is included in the authentication, then according to the first embodiment, the following steps can be included: -Transmit a given field of one number from the first card to the second card, -Compare a given field with one number in the second card and run the program or load its contents only if they match. [0017] In that case, the predetermined field may include at least the identification code of the remote communication network included in the identification number of the first card. [0018] If authenticating the first card with a second card is included in the authentication, then according to the second embodiment, the following steps can be included: -Read one random number from the first card to the second card, -Apply a random number and one key to one algorithm stored on the first card to generate one signature to be transmitted to the second card, -Apply a random number and one key to one algorithm stored on the second card, generate one result, and -By comparing the result with the signature transmitted to the second card, the program is executed or its contents are read only when they match. [0019] In that case, the authentication may include selecting a key from the key table stored on the first card according to the identifier of the program transmitted from the second card to the first card. [0020] This method is more effective when the first card and the second card mutually authenticate each other. [0021] [0021] The method includes the first authentication of the second card by the first card and the second authentication of the first card by the second card, and the second authentication involves the second card being authenticated by the first card. When it is done after the first authentication and when the first card is authenticated by the second card, the program is executed after the second authentication. [0022] Alternatively, the method includes the first authentication of the first card by the second card and the second authentication of the second card by the first card, in which the first card authenticates by the second card. When it is done, it is done after the first authentication, and when the second card is authenticated by the first card, the program is executed after the second authentication. [0023] Not all of the first cards should be authenticated by the second card, and not all of the second cards should be authenticated by the first card. In particular, at least part of the authentication may be performed only in response to an authentication request transmitted from the second card to the first card. [0024] The first card may not include any hard or soft means to participate in the authentication. In that case, the method may include an authentication process performed by the server of the remote communication network in response to the request from the first card. If at least part of the program is executed on the first card, terminal, or second card, the compatibility of these three components must be verified in advance. Regarding this point, in this method, in response to inserting the second card into the reading means connected to the terminal, the characteristics for executing the program on the second card are read from the first card terminal, and the first It may include analyzing the characteristics of the card and / or the hardware and software capacity of the terminal and rejecting the second card if the characteristics are not compatible with the first card and / or the terminal. [0025] In a preferred embodiment, the remote communication network is a radiotelephone network, the terminal is a mobile radiotelephone terminal, and the first chip card is a subscriber identification card. However, in other variants, the telecommunications network may simply be a telephone network with a switchboard, a digital network with integrated services, or a special or dedicated data transmission telephone network. May be good. [0026] Other features and advantages of the present invention will be further clarified by reading the following description of a number of desirable embodiments of the present invention with reference to the accompanying drawings. -Fig. 1 shows a block diagram of a cellular radiotelephone network with detailed mobile terminals. -Fig. 2 shows the algorithm of the main process of the pre-inspection method of program execution according to the present invention. -Fig. 3 shows the mutual authentication algorithm between the first card and the second card connected to the terminal. -Fig. 4 shows the first authentication algorithm of the second card by the first card according to the first embodiment. -Fig. 5 shows the first authentication algorithm of the second card by the first card according to the second embodiment. -Fig. 6 shows the second card authentication algorithm of the first card by the second card according to the first embodiment. -Fig. 7 shows the second card authentication algorithm of the first card by the second card according to the second embodiment. [0027] The situation of a type of remote communication network such as the GSM type digital cellular telephone network RR as shown in Fig. 1 will be described as an example. Among the mobile radiotelephone terminals TE of the radiotelephone network, there is a first chip card C1 that constitutes a module with a microprocessor that can be removed from the terminal, and a second chip card C2 called an additional application card. The second card is connected to the terminal TE via a card reader different from the terminal, or is housed in the terminal in a removable state. [0028] In FIG. 1, in order to schematically show the network RR, the mobile service exchange station MSC and the base station BTS for the location registration area where the mobile terminal TE exists at a certain time are shown, and the base station is controlled by the base station. What is connected to the exchange MSC by the device BSC is connected to the terminal TE by wireless means. The building blocks MSC, BSC, and BTS mainly constitute a fixed network, and the signals transmitted through the fixed network are, in particular, semaphore channel signals, control signals, data signals, and voice signal messages. Is. The main building block of the network RR, which can interact with the first card in the terminal TE, is the mobile service exchange MSC, which is connected to the visitor location register VLR and is the switched telephone network RTC. Connected to at least one automatic line-connected telephone exchange CAA. The exchange MSC manages the communication for the visitor mobile terminal, which also includes the terminal TE, which is a visitor mobile terminal that exists at a certain point in the location registration area leading to the exchange MSC. The base station controller BSC manages, in particular, the allocation of channels to the visitor mobile terminal, and the base station BTS covers the wireless electric cells that exist at some point in time. [0029] The radiotelephone network RR also includes a home location register HLR for rosters that is connected to register VLR and is similar to a database. The register HLR has an international identification of the IMSI (International Mobile Subscriber Identity) of the first chip card C1 for each radiotelephone terminal, especially called a SIM (Subscriber Identification Module) card. Inside the TE, it is the identification of the subscriber who owns the SIM card, the profile of the subscriber's usage contract, and the number of the register VLR to which the mobile terminal is temporarily connected. [0030] The terminal TE, whose details are shown in FIG. 1, has a wireless interface 30 with the wireless telephone network RR, and the main components of the terminal TE are a transmitter / receiver for a transmission path and a reception path, and a frequency modulation circuit. , Analog-to-digital and digital-to-analog converters, modems, and channel coding and decoding circuits. The terminal TE also includes a voice coding / decoding circuit 31 connected to the microphone 310 and speaker 311, a microcontroller 32 connected to the program's non-volatile memory EEPROM 33 and data memory RAM 34, and chip cards C1 and C2, and a keyboard. There is an input / output interface 35 that leads to 36 and a graphic display 37. The microcontroller 32 is connected to the interface 30, the circuit 31, and the memories 33 and 34 by the bus BU, and is connected to the input / output interface 35 by the other bus BS. Microcontroller 32 manages all baseband data processing received by the terminal, frequency-modulated and transmitted, especially with respect to protocol layers 1, 2 and 3 of the ISO model, with network RR through wireless interface 30. Monitor the exchange of data with the first chip card C1 through the input / output interface 35. [0031] The SIM chip card C1 is connected to an input / output interface 35 that includes at least one card reader in the terminal and a peripheral device attachment port for the mobile terminal. The main ones built into the chip card C1 are microprocessor 10, the card's operating system and communication, and ROM-type memory 11, which contains algorithms for applications and authentication specific to the present invention, related to subscribers. Mainly processes data received from and transmitted through the EEPROM-type non-volatile memory 12 that stores the international identification of IMSI subscribers, the microprocessor 32 in the terminal and the second card C2. It is a RAM type memory 13 for the purpose. [0032] As shown in Figure 1, the authentication server SA is optionally provided as an internal building block of the radiotelephone network PR and is one of the mobile service exchange MSC and visitor location register VLR through the marked network of network RR. Connected to one or more pairs, the server SV address is pre-stored in memory 12 of card C1. [0033] According to the present invention, a number of softwares are in principle remotely loaded into ROM memory 11 and EEPROM memory 12 to manage applications in additional card C2. In particular, the algorithm of the pre-inspection method of the present invention shown in FIG. 2 is implemented in memories 11 and 12. [0034] Like the SIM card C1, the second card C2 also contains a microprocessor 20, the operating system of the card C2, at least a portion of the application program PA, and a ROM memory 21 containing an authentication algorithm specific to the present invention. According to the present invention, an EEPROM-type non-volatile memory 12, a microcontroller 32 and a processor that stores the application program identifier IPA, the characteristic CPA required to execute the program, and one or two authentication requests DA1 and DA2. There is a RAM memory 13 that processes the data received from 10 and. Card C2 may be, for example, a bank card, an electronic wallet card, a game card, or a business card. In this last case, the business card is for inserting the name and phone number of the person who presented the card into the SIM card's phone book and / or for automatically calling that person. [0035] There is communication software in the ROM and EEPROM memories 11, 12, 21 and 22 in cards C1 and C2, on the one hand interacting with the microcontroller 32 on the terminal TE and on the other hand through the terminal TE, i.e. , Interact between processors 10 and 20 through microcontroller 32 and input / output interface 36. [0036] To interact between them, SIM card C1 and additional card C2 are pre-active types, preformatted according to ISO standard 7816-3 protocol "T = 0", and GSM11. 14 (SIM Tool Kit) Use the commands encapsulated by the recommendation to activate the operation in the mobile terminal MS. This recommendation extends the operating system command set stored in memory 11 and 21 of chip cards C1 and C2 to transfer the data transmitted by chip cards C1 and C2 to another card C2, C1. It can be used in. As will be described later, the terminal TE is transparent to some data exchanges between cards C1 and C2, or communicates with another without communicating with one card. be able to. [0037] As shown in Figure 2, the pre-inspection method for the execution of the application program PA stored on the second card C2 is performed by four main processes E1 through E4. First, the pre-inspection method starts at step E0 and, if done manually, is displayed on the screen of the terminal after pressing the given activation key on the keyboard of the terminal TE or after inserting the card C2 into the reader. If you enable the "Enable additional card insertion" instruction, or if it is done automatically by the terminal TE, it will be different from the terminal TE, or like the one on card C1, with the input / output interface 35. It is initiated in response to a message that there is a card transmitted by an integrated reader. At that time, the terminal TE prompts the first card C1 and the SIM card to inquire the second card C2. [0038] According to the embodiment shown in Figure 2, everything is done through the following processes E1 through E4, as if the terminal TE, actually the microcontroller 32 and the I / O interface 35, were between the two cards. It is done to be transparent to data exchange. [0039] In the following process E1, the card C1 reads the service information IS in the EEPROM memory 22 of the card C2 through the terminal TE and stores it in the EEPROM memory 12. The contents of the service information include, first, the identifier IPA of the application program PA, the characteristic CPA required to execute the program, and in many cases the authentication request DA. The characteristic CPA is, in particular, a kind of software environment, which is a hardware parameter of the terminal TE required to execute the memory capacity and the program PA, and further prohibits or prohibits the execution of the program PA outside the second card CA. It is a permit. Therefore, the information IS read into the second card C2 allows the first card C1 to recognize the nature of the application corresponding to the application program stored in the second card. [0040] In the next process E2, if the first card C1 finds that the terminal TE including the SIM card C1 does not match the characteristic CPA of the application program, the card C1 will continue the pre-inspection method in process E21. Reject and notify the terminal TE of the refusal to display the message "Additional card nonconformity". [0041] In the opposite case, card C1 decides whether to continue the pre-inspection method or not in the intermediate process E22. For example, if card C1 does not immediately continue the pre-inspection method due to a call from a terminal, etc., card C1 postpones the pre-inspection and later reverts the program PA or reverts it on card C2. Try to do it. [0042] If, after process E22, the first card C1 continues the pre-inspection method, the first card will be authenticated against at least one of the cards against the characteristic CPA of the application program loaded on the card C2. Verify that process E3 is required by the second card C2. [0043] If there is no certification request, the pre-inspection method moves from process E3 to process E4, where it determines where to run the application program PA. The execution location of the program is selected from three structural units, which are the first card C1 called a SIM card, the second card C2 called an additional card, and the terminal TE. Do this on the terminal using the pre-active commands of the SIM card application toolkit. [0044] According to the first variant, the application program PA is remotely loaded from the second card C2 to the first card C1 via the software means of the application toolkit's multiple card reader (multiple card reader) to program. Make PA run in card C1 in the next process E5. [0045] According to the second variant, the execution of the program PA takes place in process E5, inside the second card C2. The first option is to activate the program PA under the control of the SIM card C1, which then delegates the initiative in exchanging commands and responses to execute the program to the terminal TE. The terminal communicates directly with the second card. As a second option, the program PA is invoked under the control of SIM card C1, and all exchange of commands and responses takes place between the second card C2 and terminal TE via card C1. The card C1 gives the terminal the illusion that the card C1 is storing and executing the program PA by itself. [0046] According to the third variant, the program PA is remotely loaded from the second card C2 to the terminal TE and is therefore executed in process E5 in the execution environment of the software first implemented in the terminal. [0047] After process E4, the program PA loaded on card C2 is executed in process E5. The program responds to the request by displaying a text menu on the display 37, for example, by retrieving the subscriber's data with the SIM card C1, and by sending a request to the network RR or RTC. Serve the subscriber by interpreting. [0048] According to another embodiment, the operations performed in SIM card C1 in processes E1 through E4 are shown on the left side of FIG. 2, apart from mutual authentication, which will be detailed later. The operation is performed at the terminal TE, that is, under the control of the microcontroller 32. Therefore, the terminal reads the service information IS (IPA, CPA, DA) in the process E1 and continues the pre-inspection of the program execution in the processes E2, E3, and E4 by the determination of the terminal itself. [0049] Returning to the process E3 in FIG. 2, if the authentication request DA1 is included in the service information IS read into the card C2 and is stored in the card C1, the first card C1 is the mutual authentication of the cards. To start. Mutual authentication includes the first authentication A1 of the second card C2 by the first card C1 according to the embodiment shown in FIG. 3, and then the second card C2 in response to the authenticity of the second card. Includes the second certification A2 of the first card C1 by. However, according to another embodiment of the invention, the order of certification is reversed. First, the card C2 authenticates the card C1 A2, and then the card C1 authenticates the card C2 A1 in response to the authenticity of the first card. [0050] What is ensured by the first authentication A1 is that an application program stored on an additional card, such as card C2, can only be run if this program is legitimately proven. Certification A1 consists of processes A11 to A15. [0051] In the process A11 following the process E3, it is verified that the first card C1, that is, the SIM card has the first authentication algorithm AA1 which is written and managed in the ROM memory 11 and the EEPROM memory 12 in the card. If it is affirmed, card C1 proceeds to authenticate card C2 in process A12. If card C2 is not authenticated by card C1 in process A11, SIM card C1 transmits the message of the first authentication request to the authentication server SA via the terminal TE, which is the fixed network BTS-BSC-MSC. Through the terminal TE is connected to the temporarily coupled visitor location register VLR. The server SA authenticates card C2 directly on behalf of card C1, which is like following one of the first two authentications described below, for example. In the final process A14 of the first authentication A1 by card C1 or server SA, if card C2 is authenticated, mutual authentication is continued by the second authentication A2. If not authenticated, mutual authentication is stopped, the inspection method ends in process A15, and the SIM card sends a message to the terminal TE that "additional card is not authenticated" and temporarily displays it on the display 37. [0052] According to the first embodiment shown in FIG. 4, the first authentication A12a of the card C2 in the card C1 (or server SA) is pre-transmitted to the service information IS by the card C2 by the card C2 in the process E1. It consists of validating the two-card certificate CERT and basically includes four processes from process A120 to A124. [0053] In the first process A120, the identifier IPA of the application program PA is read out in the EEPROM memory 12 of the card C1. The identifier IPA acts as a read address in the private key table TKa stored in memory 12, from which it reads the program PA or the private key Ka corresponding to the program family containing the program PA. The identifier IPA and the key Ka are applied to the authentication algorithm AA1a, which produces the result R1 in process A121. Algorithm AA1a is, for example, a DES (Data Encryption Standard) type, which is similar to other authentication algorithms cited later. Certificate CERT is read into card C1 in process A122 and compared to result R1 in process A123, which corresponds to process A14. If R1 = CERT, the certificate CERT is certified, card C2 is authenticated by card C1, and authentication of card C1 is performed in process A2. Otherwise, the certification and pre-inspection methods are stopped in process A15. [0054] Another primary authentication A12b of card C2 within card C1 is shown in Figure 5. The authentication involves processes A124 to A129, and the calculation result SG performed in the second card C2 is activated by the card C1 according to the random number NA transmitted by the first card C1. [0055] Following process A11, card C1 selects a pseudo-random number NA1 supplied by a pseudo-random number generator, which is an authentication request transmitted by processor 10 to card C2 via terminal TE in process A124. It is saved for introduction in the message. In response to the authentication request, the second card C2 temporarily stores the transmitted random number NA1 in the memory 23, and in the process A125, reads the private key Kb in the EEPROM memory 22. In process A126, the random number NA1 and the key Kb are applied to the authentication algorithm AA1b, which produces the signature SG2. [0056] In the first card C1, similar processes A127 and A128 are performed almost simultaneously with processes A125 and A126. In process A127, after creating the authentication request message, the random number NA1 is written to RAM memory 13 of card C1, the identifier IPA is read to EEPROM memory 12 of card C1, and the private key Kb table in EEPROM memory 12 Specify the read address. Next, in process A128, the random number NA1 read into memory 13 and the key Kb read into table TKb are similarly applied to the algorithm AA1b implemented in ROM memory 11 and EEPROM memory 12 of card C1. The result R2 is generated by the algorithm AA1b in the card C1. [0057] Finally, in process A129, the second card C2 transmits the signature SG2 to the first card C1 via the terminal TE and compares it with the result R2. In process A129, which corresponds to process A14, if R2 = SG2 then in card C1, card C2 is authenticated to perform process A20, or if R2 is different from SG2, card C2 is rejected. At process E15, the certification and pre-inspection methods are stopped. [0058] [0058] Prior to the processes A120 and A124, in each of the first authentications, the private keys Ka and Kb are the EEPROM memory of the SIM card C1 when the user who owns the card first personalizes the card C1 when concluding a usage contract. Loaded on 12 or remotely loaded while using card C1, eg, to change or complement. [0059] In the third mode of performing the first authentication, in process E1, from the second card to the first card, the application program identifier IPA, the identifier of the second card, that is, the Card Serial Number, typically in English. The serial number CSN, and the number RND according to the IPA and CSN are transmitted. If the first card already has permission for the three elements IPA, CSN, and RDN, the authentication is successful. Instead, if the first card does not yet have permission for these three elements, contact the permission center through a secure channel and contact this permission center with the IPA, CSN, RND three elements, and their CSN or It carries the only number associated with the first card, such as the IMSI. [0060] The authorization center verifies in the database that the three elements IPA, CSN, and RND correspond to the authorized card. If not, the authorization center sends a message to the first card stating that the second card is not authorized. If the three elements correspond to an authorized second card, the authorization center verifies in the database that the second card is not yet tied to another "first" card. .. If so, the authorization center sends a message to the first card indicating an authentication failure. If the second card is not yet tied to the first card, the authorization center changes the database so that the second card is tied to the first card, and then the authorization center successfully authenticates to the first card. Send a message that means. At that time, the first card memorizes the permit and avoids contacting the permit center again at the later stage of authentication. [0061] In the third mode of first authentication, as an option, the second card is no longer limited to just one first card, but is tied to multiple first cards in a group, with a small number of users being the same second. It will also be possible to use the card. [0062] Returning to FIG. 3, the second certification A2 is started if the equation R1 = CERT is satisfied by the certification A12a or the equation RES1 = SG is satisfied by the certification A12b in the process A14. Authentication A2 ensures that the first card C1, the SIM card, is properly qualified by the second card C2 and the application program PA is launched and read on card C2. .. [0063] The second authentication A2 starts by confirming the necessity in advance in the process A20, and searches for the existence of the second authentication request DA2 in the service information IS in the memory 12. If there is no request DA2 and authentication A2 is not performed, the pre-check method goes directly to the specific application program execution location E4. In the opposite case, the steps A21 to A25 of the second certification are carried out in the same manner as in the steps A11 to A15 of the first certification A1, respectively. [0064] In process A21 following process A20, it is verified that card C1 can participate in so-called second authentication. If not possible, the card C1 sends a second authentication request message to the authentication server SA via terminal TE, which in process A23, and in process A22, which will be detailed later. Similarly, it is involved in the second authentication on behalf of card C1. At A24 after A22 or A23, the process of authenticating card C1 with the involvement of card C1 or the involvement of the server SA by card C2, card C1 is authenticated and the pre-inspection method shifts to the location identification process E4. Alternatively, the pre-inspection method ends in process A25 without being authenticated, and the message "SIM card not permitted" is displayed on the display 37 of the terminal TE. [0065] According to the first embodiment shown in FIG. 6, the second certification A22a includes the processes A220 to A222 and is defined by the international mobile subscriber identity (IMSI) of the subscriber who has the SIM card C1. The field is transmitted to the second card C2, and the transmitted field is compared with the number previously stored in the card C2. [0066] In process A220, the predetermined field in the identification number IMSI stored in the memory 12 of the card C1 is read out. A given field is, for example, the 2-bit identification code MNC (Mobile Network Code) of the wireless telephone network RR to which the subscriber is connected, or the identification code MNC and the country to which the network RR belongs. Card C2, which is a set of codes MCC (Mobile Country Code) and is generally issued by a network RR operator, verifies that the SIM card does belong to the operator. According to another variant, the predetermined field is the subscriber number prefix MSIN (Mobile Subscriber Identification Number) that is common to one group of subscribers. [0067] Corresponding number MNC2 in the second card C2, for example in response to a predetermined field of identification code MNC, is read into memory 22 in process A221. In the next process A222, which corresponds to process A24, the numbers MNC and MNC2 are compared, and if they are equal, the pre-inspection method proceeds towards process E4. If they are not equal, the authenticity of card C1 is not recognized by card C2, which prompts terminal TE to display the message of process A25, either directly or via SIM card S1, and the pre-inspection method is It will be stopped. [0068] [0068] According to the second embodiment shown in FIG. 7, the second authentication A22b includes processes A223 to A229 and is performed in the first card C1 according to the random number NA2 requested by the card C1 from the card C2. The calculation result SG3 is to be activated by the card C2. [0069] Following process A21, card C1 sends a message requesting a random number to card C2 via terminal TE in process A223. The card C1 reads the random number NA2 supplied by the processor 20 into the EEPROM memory 22 and transmits it to the card C1 via the terminal TE, and the card C1 temporarily stores it in the process A224. In card C1, the process of requesting a random number is followed by the process A225 of reading the application program identifier IPA in EEPROM memory 12. The identifier serves to specify the read address of the private key table TC and reads the program PA or the key C corresponding to the program family including the program PA. The received random number NA2 and the read key C are applied to the second authentication algorithm AA2 in the card C1, the signature SG3 is calculated in the process A226, and the signature is transmitted to the card C2 via the terminal TE. .. [0070] After the process A224 of selecting random numbers, in card C2, the key C of memory 22 is read with the random number NA2 in process A227 and applied to the algorithm AA2 similarly implemented in memory 21 and 22 of card C2. .. In process A228, algorithm AA2 produces result R3. The signature SG3 received by card C2 is compared to result R3 in process A229, which corresponds to process A24. If SG3 = R3, card C1 is authenticated by card C2 and the pre-inspection method shifts to process E4. If not, that is, SG3 R3, card C2 rejects card C1 in process A25, the SIM card asks terminal TE to display the message "SIM card not allowed", and the pre-inspection method is finish. [0071] In general, if card C2 authenticates card C1, all or part of the programs stored on card C2 remain unreadable and unexecutable. [0072] According to another embodiment of the present invention, the two cards are mutually authenticated prior to the execution of the program of the second card, and then the authentication is performed throughout the entire session of the program execution. .. Initially, each card generates a random number and transmits it to the other card. Based on two random numbers, each card calculates a key called a session key. Each card applies a session key-based encryption algorithm to a known message, like two random numbers, to obtain an encrypted message. Each card transmits the encrypted message to another card and verifies the authenticity of the encrypted message received from the other card. [0073] Execution of the program can continue if the two cards are mutually authenticated. Throughout the entire session of running the program, all messages transmitted from one card to the other are authenticated as follows: An algorithm is applied to a message to be transmitted to obtain an electronic fingerprint of the message. A signature algorithm using a session key is applied to the electronic fingerprint to obtain a signature, and the signature is transmitted with a corresponding message. If one card receives a signed message from the other, the card recalculates its electronic fingerprint and the signature corresponding to the received message, and this signature is the same as the signature received with the message. Verify that. [Simple explanation of drawings] FIG. 1 is a block diagram of a cellular radiotelephone network with detailed mobile terminals. FIG. 2 is an algorithm of the main process of the pre-inspection method for program execution according to the present invention. FIG. 3 is a mutual authentication algorithm between a first card and a second card connected to a terminal. FIG. 4 is a first card authentication algorithm for a second card with a first card according to the first embodiment. FIG. 5 is a second card first authentication algorithm with a first card according to the second embodiment. FIG. 6 is a second card second authentication algorithm with a second card according to the first embodiment. FIG. 7 is a second card second authentication algorithm with a second card according to the second embodiment.
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP08339429A | Cites | Japan |
| JP2002537618A | Cites | Japan |
| JP08505027A | Cites | Japan |
| JP11134189A | Cites | Japan |
| JP11501424A | Cites | Japan |
| JP04083447A | Cites | Japan |
18 members in 10 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 9907059 | France | – | |
| 9907059 | France | A | |
| 9907059 | France | A | |
| 0001285 | France | W | |
| 0001285 | France | W | |
| 19999907059 | – | – | – |
| 2000001285 | – | – | – |
| FR19990007059 | – | – | – |
| WO2000FR01285 | – | – | – |
Members18
| Document | Office | Kind | |
|---|---|---|---|
| FR2794595A1 | France | A1 | |
| WO0075883A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU4575900A | Australia | A | |
| FR2794595B1 | France | B1 | |
| EP1190399A1 | European Patent Office (EPO) | A1 | |
| CN1369084A | China | A | |
| JP2003501759A | Japan | A | |
| EP1190399B1 | European Patent Office (EPO) | B1 | |
| AT260501T | Austria | T | |
| ATE260501T1 | Austria | T1 | |
| DE60008531D1 | Germany | D1 | |
| ES2216886T3 | Spain | T3 | |
| DE60008531T2 | Germany | T2 | |
| US2005105731A1 | United States of America | A1 | |
| US6925560B1 | United States of America | B1 | |
| CN100403343C | China | C | |
| JP4635244B2This record | Japan | B2 | |
| US8015407B2 | United States of America | B2 |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A712A711 | A711 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4635244
- Publication, DOCDB
- 4635244
- Publication, EPODOC
- JP4635244B
- Application
- 2001502080
- Application, DOCDB
- 2001502080
- Application, EPODOC
- JP20010502080
Titles2
- Japanese
- 端末の追加のチップカード内に保存されたプログラムの事前検査方法
- English
- Pre-inspection method for programs stored in the terminal's additional chip card
Classification
- CPC, 9
- H04W12/06
- G06Q20/341
- G06Q20/40975
- G07F7/1008
- H04L63/0853
- H04L63/0869
- H04W88/02
- H04W12/35
- H04W12/72
- IPC, 4
- G06K17 00
- G06K19 07
- G07F7 10
- H04W88 02