Protectedly reading out an enciphered, cryptographic key
Abstract
Method and apparatuses for protectedly reading out an enciphered, cryptographic key (Ksec) stored in a first memory (2) of a first communication apparatus (8; 8'), comprising the following steps:a. making available a first predetermined number (PW; X) by the first communication apparatus (8; 8');b. receiving the first predetermined number (PW; X) by the second communication apparatus;c. calculating a Message Authentication Code (MAC) by the second communication apparatus on a second predetermined number, using the first predetermined number (PW; X), and with the aid of a predetermined key (Kicc);d. making available the Message Authentication Code by the second communication apparatus (6; 13);e. deciphering the cryptographic key by the first communication apparatus (8; 8'), using the Message Authentication Code as a deciphering key.

Term
Term ended
Expired 7 November 2017, 8.9 years ago.
- Priority and filed
- Granted
- Expired
- Today
16 claims: 7 independent, 9 dependent
- 1CONCLUSIES CONCLUSIONS 1. Method for securely reading an encrypted cryptographic data stored in a first memory (2) of a first communication device (8; 8') 1. Werkwijze voor het beveiligd uitlezen van een in een eerste geheugen (2) van een eerste communicatieapparaat (8; 8’) opgeslagen vercijferde, cryptografische 5 key (Ksec), comprising the following steps:5 sleutel (Ksec), omvattende de volgende stappen: a. het beschikbaar stellen van een eerste vooraf bepaald getal (PW;X) door het eerste communicatieapparaat (8;8’) voor een tweede communicatieapparaat (6;13);a. making a first predetermined number (PW;X) available by the first communication device (8;8') to a second communication device (6;13);b. het ontvangen van het eerste vooraf bepaalde getal (PW;X) door het tweede b. receiving the first predetermined number (PW;X) by the second 10 communication device;10 communicatieapparaat;c. calculating a Message Authentication Code (MAC) by the second communication device over a second predetermined number using the first predetermined number (PW;X) and using a predetermined key (Kicc);c. het berekenen van een Message Authentication Code (MAC) door het tweede communicatieapparaat over een tweede vooraf bepaald getal onder gebruikmaking van het eerste vooraf bepaalde getal (PW;X) en met behulp van een vooraf bepaalde sleutel (Kicc);15 d. making the Message Authentication Code available by the second communication device (6;13) to the first communication device (8;8');15 d. het beschikbaar stellen van de Message Authentication Code door het tweede communicatieapparaat (6;13) voor het eerste communicatieapparaat (8;8’);e. het ontvangen van de Message Authentication Code door het eerste communicatieapparaat (8;8’);e. receiving the Message Authentication Code by the first communication device (8;8');f. decrypting the cryptographic key by the first communication device (8;8') using the Message Authentication Code as the decryption key. f. het ontcijferen van de cryptografische sleutel door het eerste communicatie20 apparaat (8;8’) onder gebruikmaking van de Message Authentication Code als ontcijfersleutel.
- 66;13) een tweede persoonsgebonden wachtwoord van een gebruiker heeft ontvangen (stap 303). 6;13) has received a second personal password from a user (step 303). 15 Method according to one of the preceding claims, characterized in that the second predetermined number is equal to the first predetermined number. 15 6. Werkwijze volgens een van de voorgaande conclusies gekenmerkt doordat het tweede vooraf bepaalde getal gelijk is aan het eerste vooraf bepaalde getal.
- 8Method for setting digital signatures using a method according to one of the preceding claims, characterized in that after step f the cryptographic key thus deciphered is used for setting a 8. Werkwijze voor het zetten van digitale handtekeningen met gebruik van een werkwijze volgens een van de voorgaande conclusies gekenmerkt doordat na stap f de aldus ontcijferde cryptografische sleutel wordt gebruikt voor het zetten van een 25 digital signature. 25 digitale handtekening.
- 9Communication device (8; 8') provided with a memory (2) containing at least one encrypted cryptographic key (K .)scc), a processor (1) connected to the memory and means (5; 12) for providing 9. Communicatieapparaat (8; 8’) voorzien van een geheugen (2) met daarin opgeslagen tenminste een vercijferde, cryptografische sleutel (Kscc), een met het geheugen verbonden processor (1) en middelen (5; 12) voor het beschikbaar stellen 30 of information, the processor (1) being arranged to perform the following steps:30 van informatie, waarbij de processor (1) is ingericht voor het uitvoeren van de volgende stappen: a. het beschikbaar stellen van een eerste vooraf bepaald getal (PW;X);a. providing a first predetermined number (PW;X);b. het ontvangen van een Message Authentication Code (MAC), die door een tweede communicatieapparaat is berekend over een tweede vooraf bepaald getal onder gebruikmaking van het eerste vooraf bepaalde getal (PW;X) en met behulp van een vooraf bepaalde sleutel (Kicc);b. receiving a Message Authentication Code (MAC) calculated by a second communication device over a second predetermined number using the first predetermined number (PW;X) and using a predetermined key (Kicc);5 c. decrypting the cryptographic key using the received Message Authentication Code as the decryption key. 5 c. het ontcijferen van de cryptografische sleutel onder gebruikmaking van de ontvangen Message Authentication Code als ontcijfersleutel.
- 12Communication device according to one of claims 9, 10 or 11, characterized in that the communication device (8) further comprises a card reader (5) connected to the processor (1) for providing the first pre 12. Communicatieapparaat volgens een van de conclusies 9, 10 of 11, gekenmerkt doordat het communicatieapparaat (8) verder is voorzien van een met de processor (1) verbonden kaartleeseenheid (5) voor het beschikbaar stellen van het eerste vooraf 25 determined number (PW;X) and receiving a Message Authentication Code (MAC) from a chip card (6). 25 bepaald getal (PW;X) en het ontvangen van een Message Authentication Code (MAC) van een chipkaart (6).
- 13Communication device according to one of claims 9, 10 or 11, characterized in that the communication device (8') further comprises a processor 13. Communicatieapparaat volgens een van de conclusies 9, 10 of 11, gekenmerkt doordat het communicatieapparaat (8’) verder is voorzien van een met de processor 30 (1) connected monitor (12) for providing the first predetermined number (PW;X) and an input unit (3) for receiving a Message Authentication Code (MAC) from a chip card (6). 30 (1) verbonden monitor (12) voor het beschikbaar stellen van het eerste vooraf bepaald getal (PW;X) en van een invoereenheid (3) voor het ontvangen van een Message Authentication Code (MAC) van een chipkaart (6).
- 14Communication device (6; 13) comprising a memory (11; 17), a processor (10; 15) connected to the memory and means (9; 14) for receiving information, the processor (10; 15) being arranged to perform the following steps:14. Communicatieapparaat (6;13) voorzien van een geheugen (11;17), een met het geheugen verbonden processor (10;15) en middelen (9;14) voor het ontvangen van informatie, waarbij de processor (10;15) is ingericht voor het uitvoeren van de volgende stappen: 5 a. receiving a first predetermined number (PW;X);5 a. het ontvangen van een eerste vooraf bepaald getal (PW;X);b. calculating a Message Authentication Code (MAC) over a second predetermined number using the first predetermined number (PW;X) and using a predetermined key (Kicc);b. het berekenen van een Message Authentication Code (MAC) over een tweede vooraf bepaald getal onder gebruikmaking van het eerste vooraf bepaalde getal (PW;X) en met behulp van een vooraf bepaalde sleutel (Kicc);c. het beschikbaar stellen van de Message Authentication Code. c. making the Message Authentication Code available.
Independent claims7
86 paragraphs in 1 section, as filed
<img file="NL1007495C2_D0001.tif" />
Office for Industrial Property The Netherlands © 1007495 © C OCTROOI<sup>20</sup>
<td>© Patent application: 1007495 © Filed: 07.11.97</td><td>© Int.CI.<sup>6</sup>G07F7 / 10, H04L9 / 32</td>
<td>© Registered:</td><td>(© Patent holder (s):</td>
<td> 12.05.99</td><td>Koninklijke KPN NV in Groningen.</td>
<td>© Date:</td><td>© Inventor (s):</td>
<td> 12.05.99</td><td>Frank Fransen in Groningen</td>
<td>© Published:</td><td>Jeroen Dóll in Leiden Reinder Wolthuis in Haren</td>
<td>01.07.99 IE 99/07</td><td>© Authorized representative: Ir. LC de Bruijn cs at 2517 KZ The Hague.</td>
Method for securely reading an encrypted, stored cryptographic key and communication devices therefor.
Method and devices for securely reading an encrypted cryptographic key (K; stored in a first memory (2) of a first communication device (8; 8 ')<sub>sec</sub>), comprising the following steps:
a. providing a first predetermined number (PW; X) by the first communication device (8; 8 ');
b. receiving the first predetermined number (PW; X) by the second communication device (6; 13)
c. calculating a Message Authentication Code (MAC) by the second communication device over a second predetermined number using the first predetermined number (PW; X) and using a predetermined key (K<sub>ICC</sub>);
d. providing the Message Authentication Code by the second communication device (6; 13);
e. decrypting the cryptographi c key by the first communication device (8; 8 ') using the Message Authentication Code as the decryption key.
NL C 1007495
<img file="NL1007495C2_D0002.tif" />
The contents of this patent correspond to the original filed description with claim (s) and any drawings.
Method for securely reading an encrypted, stored cryptographic key and communication devices therefor.
The present invention relates to the secure reading of an encrypted, stored cryptographic key.
Currently, a secret key K is used for several telecommunication services<sub>sec</sub> stored by a user encrypted on the hard disk of a user's computer. The secret key is then stored in the so-called key store. To open the keystore, or in other words to decrypt the secret key K ^., Another key K<sub>key</sub> used. This other key K<sub>key </sub>is in practice derived from a user-entered password. Then the secret key is secured by the password, in other words by something a user weaves. It is the object of the present invention to increase the security of the secret key.
European patent application 0 225 010 discloses a terminal for a system in which users can communicate in a secure manner with another party, for instance a bank. This system ensures that the user can identify himself securely. To this end, the user enters his personal identification number PIN at the terminal. Moreover, the user allows the terminal to read a chip card of his own. The terminal reads a chip card key from the chip card. The PIN is encrypted with said chip card key as well as with a terminal key. The PIN thus encrypted is sent to the bank. Further security takes place because a message authentication code MAC is calculated over the total message to be sent. The MAC is used in this document as a cryptographic checksum of the message and is generated using the chip card key and the terminal key. Thus, in this prior art system, a message is sent using a terminal key stored on the terminal. In the prior art system, the chip card is not used to additionally secure access to the terminal key. In addition, no use is made of the chip card's ability to process data.
European patent application 0 246 823 relates to a system in which a user can communicate via a terminal with, for example, a bank computer. In this system, each user has a personal calculation unit, for example a hand-held generator for generating a dynamic password, better known as a token. The method disclosed in this document includes the following steps. A MAC is calculated over a message to be sent by the terminal using a first cryptographic key stored in the terminal. The end result of the MAC is shown to the user on a display. The end result is a number that is entered manually by the user on his personal unit of account. The personal calculator calculates a new value from the entered MAC using a second key. The second key is stored in the personal computer memory and can only be accessed after entering a PIN by the user on the personal computer. The personal calculation unit then shows the number calculated thereby to the user on a display. The user enters this new number on the terminal. The terminal's computer then calculates a new MAC over the message to be sent using the new number entered by the user. This final MAC is sent together with the message to the computer of the bank. The final MAC thus functions as a digital signature over the message sent. In this known system, the first key, which is stored on the terminal, is not extra secure. This can be read directly for calculating the former MAC.
The aforementioned object, namely to increase the security of the secret key, is achieved according to the invention with a method for securely reading an encrypted cryptographic key stored in a first memory of a first communication device, comprising the following steps:
a. making a first predetermined number available by the first communication device for a second communication device; b receiving the first predetermined number by the second communication device;
c. calculating a Message Authentication Code by the second communication device over a second predetermined number using the first predetermined number and using a predetermined key;
d. the provision of the Message Authentication Code by the second communication device for the first communication device;
e. receiving the Message Authentication Code by the first communication device;
f. decrypting the cryptographic key by the first communication device using the Message Authentication Code as the decryption key.
Due to the method according to the invention, the cryptographic key stored in the first memory of the first communication device can only be read with the aid of a MAC calculated by the second communication device. In that regard, access to the cryptographic key is further secured by using the computing capacity of the second communication device.
In a first embodiment of the method according to the invention, the second communication device is a contacted chip card, the first communication device is provided with a card reader and the provision and receipt of the first predetermined number and the provision and reception of the Message Authentication Code via a physical communication link between the card reader and the contact surfaces of the chip card. The advantage of this first embodiment is that it can be easily implemented, because more and more people are carrying a chip card. Moreover, in this first embodiment no mistakes can be made, because the communication between the chip card and the first communication device is fully automatic.
In an alternative embodiment of the method according to the invention, the second communication device is an input unit provided with an input unit for receiving the first predetermined number by the second communication device and the second communication device also comprises a monitor for making the Message available. Authentication Code.
In the second embodiment, the second communication device is therefore not a chip card but a token, which is available in a small format and can therefore be easily carried. However, the disadvantage compared to a chip card is that this token has to be taken separately, while most people already have a chip card in their pocket.
In the above-defined method, in step a. A first predetermined number is made available by the first communication device. In an embodiment of the invention, this first predetermined number is equal to a first personal password entered by the user in the first communication device. In such an embodiment, access to the cryptographic key is thus further secured with the user's first personal password.
In an embodiment according to the invention, the above-mentioned step c.
only after the user has entered a second personal password into the second communication device. This further step can take place both in the variant that the user has entered a first personal password on the first communication device, and in the main variant according to the invention, in which no first personal password is used.
The method according to the invention can be advantageously used in the setting of digital signatures. Therefore, the invention also relates to the use of any of the above-defined methods, wherein after step f. the cryptographic key thus deciphered is used for setting a digital signature. Of course, the cryptographic key thus read can also be used for other purposes.
For carrying out the method according to the invention, the invention provides a communication device comprising a memory with at least one encrypted cryptographic key stored therein, a processor connected to the memory and means for making information available, the processor being adapted for perform the following steps:
a. providing a first predetermined number;
b. receiving a Message Authentication Code calculated by a second communication device over a second predetermined number using the first predetermined number and using a predetermined key;
c. decrypting the cryptographic key using the received Message Authentication Code as the decryption key.
Such a communication device can for instance be a personal computer of a user.
The above-defined communication device must be able to communicate with a further communication device, which is also part of the present invention, to perform the above-defined method. Therefore, the present invention also relates to a communication device comprising a memory, a processor connected to the memory and means for receiving information, the processor being arranged to perform the following steps:
a. receiving a first predetermined number;
b. calculating a Message Authentication Code over a second predetermined number using the first predetermined number and using a predetermined key;
c. making the Message Authentication Code available.
This further communication device is, for example, a chip card, but can also be a token.
The present invention will be explained below with reference to some figures which are not intended to limit the invention, but only to illustrate it.
Fig. 1a shows a system of a first communication device and a chip card which can communicate with each other;
Fig. 1b shows a system of a first communication device and a token, which can jointly carry out the method of the invention;
Fig. 2 and 3 show examples of methods in accordance with the present invention.
Fig. 1a shows a communication device 8, which is, for example, a personal computer. However, the communication device 8 can be any terminal in a telecommunication system. The communication device 8 can even be a stand-alone device, which has no other communication possibilities than with a chip card, which is here referenced 6.
The communication device 8 comprises a processor 1, which is connected to a memory 2, a first input unit 3 and a card reader unit 5. In the case shown in FIG. 1a, the card reader 5 is connected to a second input unit 4, the function of which will be explained in more detail below. Although in FIG. If two separate input units 3 and 4 are drawn, it is possible to combine them.
Furthermore, in FIG. 1a shows a chip card 6, which is provided with a processor 10, connecting surfaces 9 connected to the processor 10 and a memory 11 connected to the processor 10. The chip card 6 can be contacted in the usual manner with the card reader 5, which subsequently known manner can make electrical contact with the connecting surfaces 9 of the chip card 6.
As will be further explained below, the communication device 8 during operation will send a predetermined value X or a password-derived value PW to the chip card 6 and the chip card 6 will later send a
Send MAC to the communication device 8.
Finally, the communication device 8 can be provided with a connection 7 for communication with other communication devices. The connection 7 is of course intended schematically: it can indicate any form of a communication channel, either via a cable or wireless.
In the memory 2 of the communication device 8 is a secret key K.<sub>sec</sub> saved. In accordance with the invention, this secret key K<sub>sec </sub>can only be read in a safe way.
Figure 1b shows an assembly of a communication device 8 'and a communication device 13. The same reference numerals in Figure 1b refer to the same parts as in Figure 1a. The difference between the communication devices 8 and 8 'is the application of a monitor 12 to the communication device 8', which is connected to the processor 1.
In the example according to the invention, the communication device 13 is a token, ie a hand-held unit which, after entering a certain number, will generate another number derived from it and display it on its monitor 16. The token 13 comprises a processor 15, which is connected to a monitor 16, an input unit 14 and a memory 17. The communication devices 8 'and 13 are not arranged for direct communication with each other. For communication, use i ü07495
Ί be made from a user who reads a number from the monitor 12 and inputs that number to the communication device 13 via input unit 14, and reads a number from the monitor 16 and inputs that number to the communication device 8 'via input unit 3. This will explained in more detail below.
Fig. 2 shows a first method in accordance with the invention for reading the key. Fig. 2 contains a flow chart on the left and a flow chart on the right. The flowchart on the left belongs to method steps, which will be executed via software by the processor 1 of the communication device 8, 8 'during operation. The flow chart on the right in fig.
2 belongs to software that the processor 10, 15 on the chip card 6 resp. will be executed on token 13 during operation.
During operation, the processor 1 will wait for a password to be received by the user; step 201. For entering the password, the user can use the first input unit 3. The first input unit 3 can for instance be a keyboard or the like. The password can consist of any string of letters and / or numbers, but can also be derived from a signal from a sensor (not shown) with which a biological recognition, for example fingerprint, iris pattern, etc., can take place.
Once the user has entered his password, the processor 1 in step 202 sends a value PW derived from the received password to the chip card 6 via the card reader 5. In the arrangement according to figure 1b, the processor 1 shows the value PW on the monitor 12, after which the user enters it at the token 13 via input unit 14.
The processor 10, 15 waits in step 203 until the value PW derived from the password is received. If this has happened, the processor 10, 15 in step 204 reads out the file contents of a preselected file in the memory 11, 17. In step 205, the value PW is used with the aid of a key K stored in memory 11, 17<sub>icc</sub> a MAC calculated. The MAC calculation may also contain the contents of a fixed value of a memory location in memory
11, 17 are included. This value can be, for example, an identification number.
In step 206, the processor 10 of the chip card 6 sends the MAC thus calculated back to the processor 1 of the communication device 8 via the card reader 100749595. In the embodiment of Figure 1b, the processor 15 sends the calculated MAC to the monitor 16, so that the user can read the MAC and enter it via the input unit 3 at the communication device 8 '.
Step 207 indicates that the processor 1 of the communication device 8, 8 'waits after step 202 until the MAC is received.
Once this is the case, the processor 1 of the communication device 8, 8 'uses the received MAC as a decryption key for the secure reading of the secret key from the memory 2.
The secret key K ^, thus read out. is available for any desired purpose after step 208. Fig. 2 shows an example, namely that the secret key K<sub>sec</sub> is used to put a digital signature on a message to be sent by the communication device 8. The placing of digital signatures is known in the state of the art and requires no further explanation here.
Fig. 3 shows an alternative method in accordance with the present invention. Again, in the left section of Fig. 3 a flow chart is drawn, which can be implemented, for example, via software on the processor 1 of the communication device 8, 8 '. In the right part of Fig. 3, a flow chart is shown which, with the aid of software in the processor 10, 15 of the chip card 6, respectively. the token 13 can be implemented.
In step 301, the processor 1 of the communication device 8, 8 'waits until it has received an instruction to make a predetermined value X available. For example, the instruction to do so is given to the user with the aid of the input unit 3. As soon as the processor 1 has received this instruction, the processor 1 in step 302 will send such a predetermined value X. The predetermined value X will then be read from a fixed memory location with a fixed content. In the embodiment of Figure 1a, the value will be sent directly to the chip card 6. In the embodiment of Figure 1b, the value of X will be displayed on monitor 12, after which the user must enter the displayed value at token 13 through input unit 14.
In step 303, the processor 10, 15 waits from the chip card 6, respectively. the token 13 until it has received a chip card / token code from the user. In FIG. 1a is a schematic representation that the user can enter such a chip card code via the card reader 5 with the second input unit 4. The position of the
007495 however, second input unit 4 is not essential to the invention. Any location for such an input unit 4 is suitable. The chip card 6 can for instance be replaced by any other communication device, which itself has its own input unit, with which the user can enter such a code, which is supplied to the processor 10. The function of the chip card code is only around the processor 10 of the chip card 6 to be released for use. In the embodiment of Figure 1b, the user enters the token code via input unit 14.
Once the chip card code / token code has been received, the processor 10, 15 proceeds to step 304, in which the processor 10, 15 tests whether the predetermined value X has already been received. If so, the processor 10, 15 proceeds to step 305, in which the processor 10, 15 reads out the file contents of a preselected file in the memory 11, 17.
It is noted that in principle steps 303 and 304 can also be reversed. The function of supplying the chip card code / token code by the user is only to release the chip card 6 for use.
After step 305, in step 306, the processor 10, 15 transfers the value X with the aid of a key K stored in memory 11, 17<sub>jcc</sub> a MAC calculated. The MAC calculation may optionally also include the contents of a fixed value of a memory location in memory 11, 17. The MAC thus calculated is made available in step 307. In the arrangement according to figure 1a, the MAC is directly supplied to the processor 1 of the communication device 8 via the card reader 5. In the arrangement according to Figure 1b, the value of the MAC is shown on monitor 16, after which the user must enter this value via input unit 3 at the communication device 8 '.
Steps 308, 309 and 310 in FIG. 3 correspond to steps 207,
208, resp. 209 in FIG. 2 and need no further explanation here.
An important difference between the method according to Fig. 3 and that according to
Fig. 2 is that in the method as described above with reference to
Fig. 3 the user does not have to supply a password to his personal computer, ie the communication device 8. Since in many cases other people also have access to the use of a personal computer, it is safer to only work by supplying a chip card code / token code to the chip card 6, respectively. the token 13.
It is also possible to use the methods described above with reference to Figs. 2 and 3. In that case the user supplies both a password PW to the processor 1 of the communication device 8, 8 'and a chip card code / token code to the processor 10, 15 of a chip card 6, respectively. the token 13. In step 301 (Fig. 3), the predetermined value X then becomes the entered password PW. Although this requires the input of two numbers for the user, such a combination may be desirable from a security point of view.
It will be clear to the skilled person that the above-described methods are intended only as an example of the invention. Essential to the invention is to use the computing capacity of a second communication device, for example the chip card 6 or the token 13, to calculate a MAC over a predetermined number or word, which MAC is then used to securely encrypt an encrypted stored cryptographic key K.<sub>sec</sub> read out from the memory of a first communication device 8.
ύ 0 7 4 9 5
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| EP0225010A1 | Cites | European Patent Office (EPO) | AD | Applicant | 1-16 |
| EP0225010A1 | Cites | European Patent Office (EPO) | AD | Search report | 1-16 |
| EP0246823A2 | Cites | European Patent Office (EPO) | AD | Applicant | 1-16 |
| EP0246823A2 | Cites | European Patent Office (EPO) | AD | Search report | 1-16 |
| EP0500245A2 | Cites | European Patent Office (EPO) | A | Search report | 1-16 |
| EP0621569A1 | Cites | European Patent Office (EPO) | A | Search report | 1-16 |
| EP0782115A2 | Cites | European Patent Office (EPO) | A | Search report | 1-16 |
| DE4119924A1 | Cites | Germany | A | Search report | 1-16 |
20 members in 12 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 1007495 | Netherlands (Kingdom of the) | A | |
| NL19971007495 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| NL1007495C2This record | Netherlands (Kingdom of the) | C2 | |
| CA2309435A1 | Canada | A1 | |
| WO9924943A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2049099A | Australia | A | |
| WO9924943A3 | World Intellectual Property Organization (WIPO) | A3 | |
| NO20002184D0 | Norway | D0 | |
| NO20002184L | Norway | L | |
| EP1036382A2 | European Patent Office (EPO) | A2 | |
| EP1036382B1 | European Patent Office (EPO) | B1 | |
| AT218234T | Austria | T | |
| ATE218234T1 | Austria | T1 | |
| DE69805650D1 | Germany | D1 | |
| AU751214B2 | Australia | B2 | |
| DK1036382T3 | Denmark | T3 | |
| PT1036382E | Portugal | E | |
| ES2177125T3 | Spain | T3 | |
| DE69805650T2 | Germany | T2 | |
| CA2309435C | Canada | C | |
| US6775773B1 | United States of America | B1 | |
| NO319813B1 | Norway | B1 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to non-payment of the annual feeLapsedVD1 | VD1 | |
| A search report has been drawn upPD2B | PD2B |
Numbers
- Publication, DOCDB
- 1007495
- Publication, EPODOC
- NL1007495C
- Application
- 1007495
- Application, DOCDB
- 1007495
- Application, EPODOC
- NL19971007495
Titles2
- Dutch
- Werkwijze voor het beveiligd uitlezen van een vercijferd, opgeslagen cryptografische sleutel en communicatieapparaten daarvoor.
- English
- Method for securely reading an encrypted, stored cryptographic key and communication devices therefor.
Classification
- CPC, 3
- G07F7/1008
- G06Q20/341
- G06Q20/40975
- IPC, 1
- G07F7 10