Secure communication with a keyboard
Abstract
This record has no abstract on file.
Term
Term ended
Projected expiry passed 29 April 2024, 2.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
1 claim: 1 independent, 0 dependent
- 1Patent claims Zastrzeżenia patentowe 1. Communication methods and keypad1l62) including:1. Sposóbkomunikacj iz klawiaturą1l62)obejmujący: odbiór przez komponent pierwszej wartości „nonae” z klawiatury;wysłanie z komponentu (202) drugiej wartości „nonae” (412) do klawiatury;the component receiving the first "nonae" value from the keyboard;sending from component (202) a second value "nonae" (412) to the keyboard;creating the first initial value and the second initial value by using the triple DES and cipher block chain creation mode to a combination of the first "nonce" value and the second "nonce" value, using the key and the third initial value that is known to both the keyboard and the component;the component receives multiple data that has been encrypted using the triple DES and cipher block chain creation mode, using the key and the first initial value from the keyboard, where each separate keystroke received from the keyboard is included as one of many separate data, wherein each of these many separate data is encrypted using a separate triple DES block and cipher block chain creation mode;utworzenie pierwszej wartości początkowej i drugiej wartości początkowej poprzez zastosowanie potrójnego DES i trybu tworzenia łańcuchów bloków szyfru do kombinacji pierwszej wartości „nonce” i drugiej wartości „nonce”, przy wykorzystaniu klucza i trzeciej wartości początkowej, która jest znana zarówno klawiaturze, jak i komponentowi;odbiór przez komponent wielu danych, które zostały zaszyfrowane za pomocą potrójnego DES i trybu tworzenia łańcuchów bloków szyfru, przy wykorzystaniu klucza i pierwszej wartości początkowej z klawiatury, przy czym każde odrębne naciśnięcie klawiszy odebrane od klawiatury jest zawarte jako jedna z wielu odrębnych danych, przy czym każda z tych wielu odrębnych danych jest szyfrowana przy użyciu odrębnego bloku potrójnego DES i trybu tworzenia łańcuchów bloków szyfru;deciphering many data based on the first initial value and the key. rozszyfrowanie wielu danych w oparciu o pierwszą wartość początkową i klucz. 2. Way throught. ) οΐ ^ ηη ^ ϋγ in addition: 2. Sposóbwedtugaaatrz . ) οΐ^ηη^ϋγ ponadto: odbiór przez komponent (202) wielu kodów uwierzytelnienia wiadomości odpowiadających wielu danym z klawiatury (162), przy czym kody uwierzytelnienia są tworzone za pomocą potrójnego DES i trybu tworzenia łańcuchów bloków szyfru, przy wykorzystaniu klucza i drugiej wartości początkowej różnej od pierwszej wartości początkowej, przy czym druga wartość początkowa jest znana zarówno klawiaturze, jak i komponentowi;the component receiving (202) a plurality of message authentication codes corresponding to a plurality of data from the keyboard (162), wherein the authentication codes are created using a triple DES and cipher block chain creation mode, using a key and a second initial value different from the first initial value, with what the second initial value is known to both the keyboard and the component;EP 1 473 615 verification of multiple data using multiple message authentication codes. EP 1 473 615 weryfikację wielu danych przy wykorzystaniu wielu kodów uwierzytelnienia wiadomości. 3. The method according to v. 2, in which the first initial residual value and the second initial value are formed, further includes: 3. Sposóbwedługaattrz .2 , we którym utworeenie piewsszej wattosci pozzątkowej i drugiej wartości początkowej obejmuje ponadto: creating the first initial value by using the triple DES and cipher block chain mode to combine the first "nonce" value and the second "nonce" value, using the key and the third initial value that is known to both the keyboard and component;utworzenie pierwszej wartości początkowej poprzez zastosowanie potrójnego DES i trybu tworzenia łańcuchów bloków szyfru do kombinacji pierwszej wartości „nonce” i drugiej wartości „nonce”, przy wykorzystaniu klucza i trzeciej wartości początkowej, która jest znana zarówno klawiaturze, jak i komponentowi;creating a second initial value by using the triple DES and cipher block chain mode to combine the first "nonce" value and the second "nonce" value, using the key and the fourth initial value that is known to both the keyboard and the component. utworzenie drugiej wartości początkowej poprzez zastosowanie potrójnego DES i trybu tworzenia łańcuchów bloków szyfru do kombinacji pierwszej wartości „nonce” i drugiej wartości „nonce”, przy wykorzystaniu klucza i czwartej wartości początkowej, która jest znana zarówno klawiaturze, jak i komponentowi. 4. Take the assEz. 1, in accordance with the lower jssj received through a channel whose operational integrity the component does not trust. 4. Spoóób wdduug assEz . 1 , w bomn wede dnnych jssj odbierenych poprze kanał, którego integralności operacyjnej komponent nie dowierza. 5. Take care of astRz. 4, in bomn Κί ^ ητροη ^ Ε (202j aawiere pedestrian operating system, which is implemented on a computing device next to the second operating system, whereby the first operating system does not trust at least in some respects the operation of the second operating system, with the keyboard communicating with the first operating system using a drive controlled by the second operating system. 5. Spoóób wdduug astRz . 4, w bomn Κί^ητροη^Ε (202j aawiere pienyszy sysjem operacyjny, który jest realizowany na urządzeniu obliczeniowym obok drugiego systemu operacyjnego, przy czym pierwszy system operacyjny nie dowierza co najmniej pod pewnymi względami operacji drugiego systemu operacyjnego, przy czym klawiatura komunikuje się z pierwszym systemem operacyjnym za pomocą napędu sterowanego przez drugi system operacyjny. 6. Way according to ,, you k ^ imm keyboard, οΒζίιηυί, the klwwiakira LSB. 6. Sposóbwedług zst^ . , , wy k^imm klawiakira οΒζίιηυί, klwwiakirę LSB. 7. Take care of astRz. 6, in hen ροη'οίην Df.S j Ryle I create ańt ^ cucl ^ t ^ in cipher blocks encrypt data in blocks of a predetermined size and in which the keyboard communicates data in blocks of that predetermined size. 7. Spoóób wdduug astRz . 6, w kurnym ροη'οίην Df.S j Ryle tworzeme ańt^cucl^t^w bloków szyfru szyfrują dane w blokach posiadających wcześniej określony rozmiar i w którym klawiatura komunikuje dane w blokach o tym wcześniej określonym rozmiarze. 8. The method according to claim The process of claim 1, wherein each of the plurality of data is generated based on the individual keystroke received by the keyboard. 8. Sposób według zastrz. 1, w którym każda z wielu danych jest generowana w oparciu o indywidualne naciśnięcie klawiszy odebrane przez klawiaturę. EP 1 473 615 EP 1 473 615 9. A computer-readable medium with recorded instructions implemented on a computer for calculating the method of the current reception of input signals on a software component (202) from a keyboard (162), in which the method includes: 9. Nośnik odczytywalny komputerowo z zapisanymi instrukcjami realizowanymi na komputerze do eezliczcCi sposobu becaieccaego odbioru sygnałów wejściowych na programowym komponencie (202) od klawiatury (162), w którym sposób obejmuje: odbiór prcec programowy komponent pierwszej wartości „nonce” (412) c klawiatury;receive program component first key value nonce (412) c keyboard;sending the c program component of the second "nonce" value (414) to the keyboard;wysłanie c programowego komponentu drugiej wartości „nonce” (414) do klawiatury;to create the first set point value and the second set point value, castosize the triple DES and the mode of creating scramble block chains to a combination of the first "nonce" value and the second "nonce" value, for the use of the key and the third set value, which is cut on the keyboard and the keyboard;receiving a program component of many data that has been decrypted by means of a triple DES and the mode of creating scramble block chains, the use of a key and the first c-terminal value of the keyboard, which performs each separate keystroke received from the keyboard is as one of many separate data, every c of these many separate data is digitized using a separate DES triple block and the mode of creating the scramble block chains;orac roccryption prcec a software component of many data based on the perfect value of the key and the key. utworcenie pierwscej wartości poccątkowej i drugiej wartości poccątkowej poprcec castosowanie potrójnego DES i trybu tworcenia łańcuchów bloków scyfru do kombinacji pierwscej wartości „nonce” i drugiej wartości „nonce”, prcy wykorcystaniu klucca i trceciej wartości poccątkowej, która jest cnana carówno klawiaturce, jak i komponentowi;odbiór prcec programowy komponent wielu danych, które costały cascyfrowane ca pomocą potrójnego DES i trybu tworcenia łańcuchów bloków scyfru, prcy wykorcystaniu klucca i pierwscej wartości poccątkowej c klawiatury, prcy ccym każde odrębne naciśnięcie klawiscy odebrane od klawiatury jest cawarte jako jedna c wielu odrębnych danych, prcy ccym każda c tych wielu odrębnych danych jest scyfrowana prcy użyciu odrębnego bloku potrójnego DES i trybu tworcenia łańcuchów bloków scyfru;orac rocscyfrowanie prcec programowy komponent wielu danych w oparciu o piefwscą wartość poccątkową i klucc. 10. Nośnik odccytywalny komputerowo według castrc. 9, w którym programowy komponent (202) cawiera pierwscy system operacyjny, który jest realicowany na urcądceniu oblicceniowym obok drugiego systemu operacyjnego, prcy ccym pierwscy system operacyjny nie dowierca, co najmniej pod pewnymi wcględami, pracy drugiego systemu operacyjnego, prcy ccym klawiatura komunikuje się c pierwscym systemem operacyjnym ca pomocą napędu sterowanego prcec drugi system operacyjny. Of 10. Computer detectable carrier according to castrc. 9, in which the software component (202) contains the first operating system, which is implemented at a calculating charge next to the second operating system, which operates the first operating system without a commander, at least in some respects, the work of the second operating system, and the working keyboard communicates first operating system using a prcec controlled drive second operating system. EP 1 473 615 EP 1 473 615 11. A computer readable medium according to claim 9. In which the method further comprises: 11. Nośnik odczytywalny komputerowo według zastrz. 9, w którym sposób obejmuje ponadto: odbiór przez programowy komponent (202) wielu kodów uwierzytelnienia wiadomości odpowiadających wielu danym z klawiatury (162), przy czym kody uwierzytelnienia są tworzone za pomocą potrójnego DES i trybu tworzenia łańcuchów bloków szyfru, przy wykorzystaniu klucza i drugiej wartości początkowej różnej od pierwszej wartości początkowej, przy czym druga wartość początkowa jest znana zarówno programowemu komponentowi, jak i klawiaturze;weryfikację wielu danych przy wykorzystaniu wielu kodów uwierzytelnienia wiadomości. the software component (202) receiving multiple message authentication codes corresponding to many from keyboard data (162), with the authentication codes being created using triple DES and the cipher block chain creation mode, using a key and a second initial value different from the first initial value, the second initial value being known to both the software component and the keyboard;verification of multiple data using multiple message authentication codes. 12. A computer readable medium according to claim The method of claim 11, wherein the creation of the first initial value and the second initial value further includes: 12. Nośnik odczytywalny komputerowo według zastrz. 11, w którym utworzenie pierwszej wartości początkowej i drugiej wartości początkowej obejmuje ponadto: creating the first initial value by using the triple DES and cipher block chain mode to combine the first "nonce" value (412) and the second "nonce" value (414) using the key and the third initial value that is known to both the keyboard and software component (202);and creating a second initial value by using the triple DES and cipher block chain mode to combine the first "nonce" value and the second "nonce" value using the key and the fourth initial value that is known to both the keyboard and the software component. utworzenie pierwszej wartości początkowej poprzez zastosowanie potrójnego DES i trybu tworzenia łańcuchów bloków szyfru do kombinacji pierwszej wartości „nonce” (412) i drugiej wartości „nonce” (414) przy wykorzystaniu klucza i trzeciej wartości początkowej, która jest znana zarówno klawiaturze, jak i programowemu komponentowi (202);oraz utworzenie drugiej wartości początkowej poprzez zastosowanie potrójnego DES i trybu tworzenia łańcuchów bloków szyfru do kombinacji pierwszej wartości „nonce” i drugiej wartości „nonce” przy wykorzystaniu klucza i czwartej wartości początkowej, która jest znana zarówno klawiaturze, jak i programowemu komponentowi. 13. A computer readable medium according to claim 9, in which the triple DES and cipher block chain creation mode encrypt data in blocks having a predetermined size and in which the keyboard communicates data in blocks of a predetermined size. 13. Nośnik odczytywalny komputerowo według zastrz. 9, w którym potrójny DES i tryb tworzenia łańcuchów bloków szyfru szyfrują dane w blokach posiadających wcześniej określony rozmiar i w którym klawiatura komunikuje dane w blokach o tym wcześniej określonym rozmiarze. 14. Keyboard (162) comprising: 14. Klawiatura (162) obejmująca: EP 1 473 615 jedną lub większą liczbę miejsc pamięciowych, które przechowują pierwszą wartość początkową i klucz;One or more memory locations that store the first initial value and the key;szyfrujący komponent (202), przystosowany do odbioru pierwszej wartości „nonce” (412) od odbiorcy poprzez interfejs komunikacyjny i do wysłania drugiej wartości „nonce” (414) do odbiorcy poprzez interfejs komunikacyjny oraz do utworzenia pierwszej wartości początkowej poprzez zastosowanie potrójnego DES i trybu tworzenia łańcuchów bloków szyfru do kombinacji pierwszej wartości „nonce” i drugiej wartości „nonce” przy wykorzystaniu klucza i drugiej wartości początkowej, która jest znana zarówno klawiaturze, jak i komponentowi, przy czym szyfrujący komponent szyfruje dane wejściowe otrzymane na klawiaturze za pomocą potrójnego DES i trybu tworzenia łańcuchów bloków szyfru przy wykorzystaniu klucza i pierwszej wartości początkowej, przy czym szyfrowane dane są tworzone w oparciu o dane wejściowe, przy czym każde odrębne dane wejściowe są reprezentowane przez odrębne naciśnięcie klawiszy odebrane przez klawiaturę, przy czym każda z tych wielu odrębnych danych wejściowych jest szyfrowana przy użyciu odrębnego bloku potrójnego DES i trybu tworzenia łańcuchów bloków szyfru;oraz interfejs komunikacyjny, który przekazuje zaszyfrowane dane do urządzenia zewnętrznego względem klawiatury, przy czym zaszyfrowane dane są przeznaczone dla odbiorcy, który zna pierwszą wartość początkową i klucz. the encryption component (202), adapted to receive the first "nonce" value (412) from the recipient via a communication interface and to send a second "nonce" value (414) to the recipient via a communication interface, and to create the first initial value by using the triple DES and mode creating cipher block chains for a combination of the first "nonce" value and the second "nonce" value using the key and the second initial value, which is known to both the keyboard and the component, whereby the encrypting component encrypts the input received on the keyboard using triple DES and the mode of creating cipher block chains using the key and the first initial value, with the encrypted data being created based on the input data, each separate input is represented by a separate keystroke received by the keyboard, each of these many separate input data is encrypted using a separate triple DES block and cipher block chain mode;and a communication interface that transmits the encrypted data to a device external to the keyboard, the encrypted data being intended for a recipient who knows the first initial value and the key. 15. Keyboard (162) according to claim The encoding component of claim 14, wherein the encryption component creates a plurality of message authentication codes corresponding to the encrypted data or input, wherein the authentication codes are created using a triple DES and a cipher block chain creation mode using a key and an initial value different from the initial initial value. 15. Klawiatura (162) według zastrz. 14, w której szyfrujący komponent tworzy wiele kodów uwierzytelnienia wiadomości odpowiadających zaszyfrowanym danym lub danym wejściowym, przy czym kody uwierzytelnienia są tworzone za pomocą potrójnego DES i trybu tworzenia łańcuchów bloków szyfru przy wykorzystaniu klucza i wartości początkowej różnej od pierwszej wartości początkowej. 16. Keyboard (162) according to claim 15. The keyboard of claim 14, wherein the keyboard includes a USB keyboard. 16. Klawiatura (162) według zastrz. 14, w której klawiatura obejmuje klawiaturę USB. EP 1 473 615 EP 1 473 615 17. Keyboard (162) according to claim 14. The method of claim 14, wherein the communication interface communicates the encrypted data to a drive controlled by the first operating system that is implemented on the computing device, whenever the encrypted data is transferred to the recipient, the recipient being the second operating system that is implemented on this computing device, or a program , which is implemented in the second operating system, and the second operating system does not trust, at least in some respects, work of the first operating system. 17. Klawiatura (162) według zastrz. 14, w której interfejs komunikacyjny komunikuje zaszyfrowane dane do napędu sterowanego przez pierwszy system operacyjny, który jest realizowany na urządzeniu obliczeniowym, kiedykolwiek zaszyfrowane dane są przekazywane do odbiorcy, przy czym odbiorcą jest drugi system operacyjny, który jest realizowany na tym urządzeniu obliczeniowym, lub program, który jest realizowany w drugim systemie operacyjnym, przy czym drugi system operacyjny nie dowierza, co najmniej pod pewnymi względami, pracy pierwszego systemu operacyjnego. Pełnomocnik: Proxy: Ewa Grenda, patent attorney Ewa Grenda, rzecznik patentowy EP 1 473 615 EP 1 473 615 1/4 1/4 COMPUTER ENVIRONMENT 100 ŚRODOWISKO KOMPUTEROWE 100 ΕΡ 1 473 615 ΕΡ 1 473 615 ΚΟΜΡΐ TER 11θ ΚΟΜΡΐ TER 11θ Nonce 412 Nonce 412 Nonce 414 Nonce 414 FIG.4 FIG.4 ΕΡ 1 473 615 ΕΡ 1 473 615 502 502 3/4 3/4 504 504 506 506 508 508 510 510 512 512 FIG. 5 FIG. 5 514 514 ΕΡ 1 473 615 ΕΡ 1 473 615 4/4 <© ΐ 4/4 <© ΐ
70 paragraphs in 4 sections, as filed
[0001] The present invention relates generally to the field of computer security. In particular, the present invention relates to the safe use of the keyboard in a communication channel that can be subjected to interception or other manipulation.
BACKGROUND ART [0002] The keyboard transmits user input to an electronic device such as a computer. When the user presses the keyboard key, the keyboard generates data representative of the particular key pressed (e.g., the ASCII code for the letter "e"), and this data is received by the appropriate computer component, such as the drive of the device. This drive then transfers this data to the active program that is currently receiving the input (e.g. by placing this data in the input buffer of a given active application program).
[0003] One problem arises when using the keyboard to receive data when it is sensitive data or data that for other reasons must be kept secret. For example, a secure application (or secure operating system service) may ask the user to enter a password, which should generally not be disclosed publicly. However, the path from the keyboard to the software component that receives this data is not secure because there are several ways to capture this data. For example, this data often goes through a bus that can be tapped and then handled by a device drive that can be manipulated (or the operating system allows the drive to be replaced by an unsecured drive that stores and discloses information passing through that drive) . In other words, there are several options for observing or manipulating sensitive data as they travel from the keyboard to the destination.
[0004] In general, it is possible to encode data for transmission between two components that are connected by an unsecured channel. Many, however
EP 1 473 615 coding techniques cannot easily be applied to the keyboard due to a variety of factors, such as key control issues, the possibility of repetitive attacks, and the fact that the relatively small range of data that can be generated using the keyboard makes normal code used for keyboard communication would be relatively easy to break when capturing a sample of coded text of moderate size.
[0005] Accordingly, there is a need for a technique to facilitate secure communication using a keyboard.
[0006] EP-A-1 286 242 discloses an encryption device incorporated between an input device and an input device decoder. The encryption device can be controlled to operate in a normal mode in which the data passes unchanged, and in a secure mode in which the data is encrypted. The use case disclosed by this document concerned the PIN (Personal Identification Number) entry.
[<sup>0007</sup>] <sup>P</sup>at<sup>blik</sup>ation G. Treat: "Ke<sup>yb</sup>oar<sup>d</sup> encrvption " <sup>IEEE P.</sup>otentials, vol <sup>21,</sup> No. 3<sup>, </sup>August 2002 - September 2002, pp. 40-42, concerns the encoding of keyboard data by means of a device connected between the keyboard and the computer or by using a modified microcontroller in the keyboard and decoding software loaded onto the existing computer BIOS chip.
SUMMARY OF THE INVENTION [0008] The object of the present invention is to avoid repetitive attacks in the encoded communication channel between the keyboard and the computer program component.
[0009] This object has been achieved by the nature of the independent claims.
[0010] Preferred embodiments are defined in the dependent claims.
[0011] The present invention provides a technique for secure communication between two components via an unsecured channel. This technique uses a coding scheme that is particularly well suited to the keyboard and that addresses the problems that would occur when using a standard coding scheme for the keyboard.
[0012] The keyboard of the present invention stores a key and a fixed value that is used to initialize the coding scheme. Component
EP 1 473 615 (e.g. an active program application on a computer) stores the same key and the same constant value that are stored on the keyboard. To initiate a secure session between this component and the keyboard, each one generates a "nonce" (one-time random number) and then exchanges it with the other unit so that both the keyboard and the component have both "nonce" values. The keyboard and component then calculate two initial values, each of which is based on these two nonce values, which are the key and constant value. For example, the first initial value can be created using the CBC-3DESMAC algorithm, where CBC-3DESMAC uses the stored constant value as its initial key and applies that key to a message created based on two "nonce" values. (CBC-3DESMAC refers to the use of triple coding according to the DES (Data Encryption Standard) algorithm with encryption in the mode of creating cipher block chains and the use of the final block of encrypted text to create a MAC (Message Authentification Code) .) Preferably, the second initial value is created by inverting the bits in the first initial value (i.e. performing an "exclusive or" XOR operation between the first initial value and the Oxfffffffffffff number). Because the keyboard and component calculate the first and second initial values in the same way, they have the same two initial values.
[0013] In a preferred alternative embodiment, both the keyboard and the component are equipped with two fixed values, and the first and second initial values can be created by applying CBC-3DESMAC to a message that is based on two "nonce" values, the first a constant value is used to create the first initial value and a second constant value is used to create the second initial value.
[0014] After creating the first and second initial values, the keyboard is ready to transfer encrypted data, and the component is ready to decrypt and verify the data. When data is entered on the keyboard, the keyboard will encrypt this data based on the first initial value and key. Preferably, the keyboard encrypts data using the above-mentioned key using CBC-3DES (triple DES with cipher block chain creation mode), where the first initial value is used to initialize the block chain
EP 1 473 615 cipher. In addition, the keyboard preferably creates a MAC for each data set using CBC-3DESMAC, where CBC-3DESMAC uses the above-mentioned key and uses the second initial value to initialize the cipher block chain. Preferably, each keystroke is encrypted in a separate cipher block, and the entire data stream generated on the keyboard during the session is a cipher block chain, since this technique allows the same keystroke (e.g. the letter 'e') to appear as different encrypted text, depending on from the previous key press.
[0015] After receiving the encrypted data and MAC (s) by the receiving component, this receiving component uses the above-mentioned key and the first and second initial values to decrypt and verify the received data.
[0016] Other features of the present invention are described below.
Brief Description of the Drawings [0017] Both the essence of the invention given above and the description of preferred embodiments given below are better understood in connection with the accompanying drawings. An exemplary structure according to the invention is shown in the drawings to illustrate the present invention. However, the present invention is not limited to the individual methods and instrumentation disclosed in the drawings, in which: [0018] Fig. 1 is a block diagram of an exemplary computer environment in which aspects of the present invention may be implemented;
[0019] Fig. 2 is a block diagram of a first exemplary computer environment in which communication between a keyboard and a component can occur via an unsecured channel;
[0020] Fig. 3 is a block diagram of a second exemplary computer environment in which communication between a keyboard and a component can occur via an unsecured channel;
[0021] Fig. 4 is a block diagram of a keyboard and component that has been configured for secure communication according to aspects of the present invention and which exchange "nonce" values;
[0022] Fig. 5 is a flowchart of the process of engaging in a secure session between the keyboard and component; and
[0023] Fig. 6 is a block diagram of a first exemplary computer environment in which keyboards and components can be distributed to engage in secure communication according to aspects of the present invention.
DETAILED DESCRIPTION OF THE INVENTION
Exemplary computer system [0024] Fig. 1 shows an exemplary computer environment in which aspects of the present invention may be implemented. The environment in the form of the computer system 100 is only one example of a suitable computer environment and is not intended to suggest any limitation of the scope of application or operation of the present invention. Also, computer system 100 should not be interpreted as dependent or imposing requirements on any or a combination of components illustrated in exemplary computer system 100.
[0025] The present invention may work with a number of other general or special purpose computing environments of various configurations. Examples of well-known computer systems, environments or configurations include, but are not limited to, personal computers, servers, mobile and laptop devices, multiprocessor systems, microprocessor systems, set-top boxes (Set Top Box), programmable consumer electronics, personal computer network, minicomputers, mainframes, embedded systems, distributed computing environments, which include any of the above systems or devices, and the like.
[0026] The present invention may be described in the general context of computer-implemented instructions, such as program modules, implemented by a computer. Generally, program modules include standard programs, programs, objects, components, data structures etc. that perform specific tasks or implement abstract data of certain types. The present invention can also be practiced in a distributed computing environment where tasks are performed by remote processing devices that are connected to each other via a communication network or other data transmission medium. In diffuse
In a computer environment, program modules and other data may be located in both local and remote storage media, including storage devices.
[0027] Referring to Fig. 1, an exemplary system for implementing the present invention includes a general-purpose computer device in the form of a computer 110. Computer components 110 may include, but are not limited to, processing unit 120, system memory 130, and system bus 121, which connects various components, including system memory, to the processing unit 120. The system bus 121 may have any of several types of system bus structure, including a memory bus or memory controller, a peripheral bus or a local bus, using any of many architectures. For example, but not as a limitation, such architectures include the ISA bus (Industry Standard Architecture), MCA bus (Micro Channel Architecture), EISA bus (Enhanced Industry Standard Architecture), local VESA bus (Video Electronics Standards Association) and PCI bus (Peripheral Component Interconnect) (also known as the Mezzanine bus (inter-story architecture)). System bus 121 may also be implemented as a point-to-point connection, switch material, or the like among communication devices.
[0028] Computer 110 typically includes various computer-readable media. Computer-readable media can be any commercially available media that computer 110 can connect to, and includes both non-durable and durable media, removable and non-removable media, used in any method or information storage technology, such as computer-readable instructions , data structures, program modules or other data. Storage computer media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CDROM, digital universal discs (DVD) or other optical media, cassette tapes, magnetic tape, magnetic discs or other magnetic storage devices, or any other media that can be used to store the desired information and that can communicate with the computer 110. Communication media usually includes computer readable instructions, data structures, modules
EP 1 473 615 program or other data in a modulated data signal, such as a carrier wave or other transfer mechanisms, and includes any information carriers. The term "modulated data signal" means a signal that has one or more of its characteristics set or changed in such a way as to encode information in that signal. For example, and not as a limitation, communication media include cable media such as a cable network, direct cable connection, and wireless media such as acoustic, RF, infrared and other wireless media. Any combination of the above is also included in the scope of the term "computer readable media".
[0029] The system memory 130 includes computer storage media in the form of non-durable and / or permanent memory, such as Read Only Memory 131 and Random Access Memory 132 (RAM). Basic input system Basic Input / Output System (BIOS) containing standard programs that help transfer information between components in a computer 110, for example during startup, is usually stored in ROM 131. RAM 132 typically contains data and / or program modules that are immediately available and / or currently supported by processing unit 120. For example, and not as a limitation, Fig. 1 shows operating system 134, application programs 135, other program modules 136 and program data 137.
[0030] Computer 110 may also contain other removable / non-removable, permanent / non-durable storage media. For example, only 1 illustrates a hard disk drive 141 that reads or writes on a non-removable, permanent magnetic medium, a magnetic disk drive 151 that reads or writes on a removable, permanent magnetic disk 152, an optical disk drive 155 that reads or writes on a removable, permanent an optical disc 156, such as a CD-ROM or other optical media. Other removable / non-removable, permanent / non-durable computer storage media that can be used in this exemplary operating environment include, but are not limited to, magnetic tape cassettes, flash cards, digital universal disks, digital video tapes, RAM chips, ROM chips and the like. Hard disk drive 141 is typically connected to system bus 121 via a non-removable memory interface, such as interface 140, and magnetic disk drive 151 and
The optical disk drive 155 is usually connected to the system bus 121 via a removable memory interface such as interface 150.
[0031] The drives and associated computer storage media discussed above and illustrated in Fig. 1 provide storage of computer readable instructions, data structures, program modules, and other data for computer 110. In Fig. 1, for example, hard disk drive 141 is shown as storing operating system 144, application programs 145, other program modules 146 and program data 147. It should be noted that these components may be the same as or other than the operating system 134, application programs 135, other program modules 136 and program data 137. Operating system 144, application programs 145, other program modules 146 and program data 147 have separate reference numbers to illustrate that they are at least separate copies. The user can enter commands and information into the computer 20 using input devices such as a keyboard 162 and pointing device 161 commonly known as a mouse, ball manipulator or touch pad. Other input devices (not shown) may include a microphone, joystick, game console, satellite dish, scanner and the like. These and other input devices are often connected to the processing unit via a user input interface 160 that is connected to the system bus, but can be connected via an interface and a bus with a different structure, such as parallel input, game input or universal serial bus USB (Universal Serial Bus). Monitor 191 or other display device is also connected to system bus 121 via an interface such as video interface 190. In addition to the monitor, computers may also contain other peripherals such as 197 speakers and a 196 printer that can be connected via the 190 peripheral output interface.
[0032] Computer 110 may operate in a network environment using logical connections to one or more remote computers, such as remote computer 180. The remote computer 180 may be a personal computer, server, router, PC network, peer device, or other typical network node and typically includes all or many of the elements described above with respect to computer 110, although only storage device 181 is shown in Fig. 1. The logical connections shown in Fig. 1 include LAN 171 (Local Area Network) and WAN 173 (Wide Area Network), but they may
EP 1 473 615 also includes other networks. Such network environments are common in offices, enterprise computer networks, intranets and the Internet.
[0033] When used in a LAN environment, the computer 110 is connected to LAN 171 via a network interface or snap-in 170. When used in a WAN environment, the computer 110 typically includes a modem 172 or other means to establish communication on the WAN 173, such as the Internet. Modem 172, which can be internal or external, can be connected to the system bus via user input interface 160 or other suitable mechanism. In a network environment, the program modules shown in relation to computer 110 or parts thereof may be stored in a remote storage device. For example, and not as a limitation, Fig. 1 illustrates remote application programs 185 as being located in storage device 181. It should be noted that the network connections shown are exemplary and other means may be used to establish a communication link between computers.
Security of communication between the keyboard and the component [0034] The present invention addresses the problem of how a keyboard can be used to securely communicate with a component that requires a keyboard input. Fig. 2 shows an example scenario of such communication. In Fig. 2, the keyboard 162 communicates with the component 204. The component 204 can be any type of component - e.g., a program that is implemented on a computer, an item of equipment, etc. Communication from the keyboard 162 to the component 202 passes through a communication channel that includes at least one insecure portion 204. Thus, when data representing key presses pass through some channel in its path from the keyboard 162 to the component 202, there may be an opportunity to intercept them or manipulation by third parties. This interception or manipulation can be a problem if, for example, information that is entered through the keyboard 162 is a secret password that should not be disclosed publicly.
[0035] Fig. 3 shows a specific scenario in which secure communication between the keyboard and the component is desired. In Fig. 3, the keyboard 162 is used to provide input to software that is implemented in
EP 1 473 615 computer 110. In the example of Fig. 3, the keyboard 162 is a keyboard adapted to be used with the universal USB 302 serial bus. (For brevity, such a keyboard should be referred to as a USB keyboard.) The keyboard 162 receives key presses and places the bits representing those presses in USB 302, where these bits are taken by drive 304. Then drive 304 forwards these bits to their destination, which in the example illustrated in Fig. 3 is software 306. Software 306 is, for example, component 204 (shown in Fig. 2).
[0036] In the example in Fig. 3, there are two operating systems 134 (1) and 134 (2) running on computer 110. The operating system 134 (1) is a typical operating system such as MICROSOFT WINDOWS XP, Unix, Linux, Solaris etc. Operating system 134 (2) is the "high certainty" operating system that is used for confidential applications. For example, the 134 (2) operating system may be associated with "obstructed" memory that is not available outside of the 134 (2) operating system, while the 134 (2) operating system may store confidential information (e.g., cryptographic keys, passwords, etc.) ) in this "obstructed" memory so that only specially trusted applications that have permission to work in the 134 (2) system can read this confidential information. The 134 (2) operating system is a "high certainty" system in the sense that users have a very high degree of certainty that this system will properly perform its functions, ie as far as protecting confidential information is one of the intended tasks of the 134 (2) operating system , users are entitled to a very high degree of certainty that the 134 (2) operating system will not disclose this confidential information. Some options for protecting confidential information may include being able to receive secret information entered into the keyboard (e.g., passwords) without disclosing that information to the outside. The 134 (2) operating system may not trust the 304 drive to handle such secret information because the 304 drive is under the control of the 134 (1) operating system (and the 134 (1) operating system may allow a hacker to read information directly from USB 302 or to plant "Fake" drive that will store and disclose secret information). Thus, operating system 134 (2) needs a way of receiving information from the keyboard 162 through the operating system 134 (1) without fear that this secret information will be disclosed as a result of operations occurring in the operating system 134 (1).
[0037] It should be understood that although the example in Fig. 3 shows the keyboard 162 as communicating with the computer 110 via universal serial bus 302, the scenario described above applies regardless of the exact means by which the keyboard 162 communicates with computer 110, so the present invention is not limited to USB keyboards.
[0038] Fig. 4 shows how the keyboard 162 and component 202 can be configured to participate in secure communication over an unsecured channel. Both the keyboard 162 and component 202 store a copy of the cryptographic key 402. Both the keyboard 162 and component 202 also preferably store a fixed value 404, which is used as an initial value in a particularly preferred cryptographic technique as described in more detail below. In a further preferred embodiment, the keyboard 162 and component 202 may store (in addition to the key) two constant values instead of one. These two fixed values can be used in cryptographic technique as described below. For example, the keyboard 162 may include a built-in solid semiconductor that stores the key 402 or has an input that receives the removed storage medium on which the key 402 and constant 404 are stored. In the case where component 202 is a software component, key 402 and constant 404 may be stored in component data space 202. However, it should be understood that the present invention is not limited to any particular method of storing key 402 and 404.
[0039] At the beginning of secure communication between the keyboard 162 and component 202, the keyboard 162 and component 202 may generate and exchange "nonce" values. That is, keyboard 162 generates "nonce" 412 and sends "nonce" 412 to component 202. Component 202 generates "nonce" 414 and sends "nonce" 414 to keyboard 162. As is known in this field, "nonce" is a data element used in cryptographic applications - often for cryptographic authentication of the whole or for initiating a cryptographic session, an element that is not easy to reproduce, on which encryption can be made. The nonce values 412 and 414 can be used to create initial values to encrypt and authenticate data transmitted between the keyboard 162 and component 202, as described in more detail below.
EP 1 473 615
Process of secure data transfer from keyboard to component [0040] Fig. 5 illustrates the process by which the keyboard 162 and component 202 can engage in a session in which component 202 securely receives data from the keyboard 162. The process shown in Fig. 5 provides both encryption (which protects against interception of transmitted data), like authentication (which protects against modification of transmitted data). However, it should be understood that both encryption and authentication can be used alone, depending on the security requirements of the transmission. For example, if data modification can be tolerated but not intercepted, then only encryption can be used. On the contrary, if the interception of data can be tolerated, but modification of this data cannot be tolerated, authentication alone can be used.
[0041] Initially, the keyboard 162 and component 202 exchange "nonce" values in operation 502. For example, as described above with reference to Fig. 4, the keyboard 162 may generate "nonce" 412 and send it to component 202, and component 202 may generate "nonce" 414 and send it to keyboard 162. Techniques for generating "nonce" values are known in the art and will therefore not be described in detail here. For example, the "nonce" values 412 and 414 can be generated based on a random number, content of some memory area, time, temperature, moon phase etc. or any other factor that changes frequently and has a sufficient range to make it unlikely that keyboard 162 or component 202 has generated the same "nonce" value twice.
[0042] After exchanging the "nonce" values 412 and 414 in operation 502, both the keyboard 162 and component 202 have both "nonce" values. Then, keyboard 162 and component 202 use a jointly agreed formula for calculating in operation 504 two initial values IV_c and IV_m as a function of both "nonce" and key 402. So, if K = key 402, N1 = "nonce" 412, and N2 = "Nonce" 414, then
IV_c = f (K, Ni, N2);
IV_m = g (K, N1, N2).
The functions of fig can be any functions. In a preferred embodiment,
EP 1 473 615 f (K, Ni, N<sub>2</sub>) = CBC-3DESMACK (constant_IV, Ni | N<sub>2</sub>);
ag (K, N1, N<sub>2</sub>) = f (K, N1, N<sub>2</sub>) xor 0xffffffffffffffff, where constant_IV is equal to the constant value 404 (shown in Fig. 4). In a further preferred embodiment, in which the keyboard and component have jointly two constant values (e.g. constant_IV_1 and constant_IV_2), the functions of fig can alternatively be calculated as follows:
f (K, N1, N2) = CBC-3DESMACK (constant_IV_1, N1IN2);
ag (K, N1, N2) = CBC-3DESMACK (constant_IV_2, N1IN2).
(The operator "|" means concatenation such that N1N2 is the value resulting from the concatenation of N1 and N2. The value "xor" is the bit operation of the exclusion alternative, so that A xor B is the value resulting from setting "1" to any bit that is " 1 "in A or in B, but not in both, and setting the other bits to" 0 ".) CBC3DESMACK (constant_IV, N1N2) is a cryptographic function whose meaning is known in the art and described in detail below.
[0043] After calculating IV_c and IV_m, communication between the keyboard 162 and component 202 may begin. The keypad 162 receives the key press, i.e. the operator presses one of the keys such as <SHIFT> and "A" or <CTRL> and "A" (operation 506). Then the keyboard encrypts the key press in operation 508; encryption is preferably based on key 402 and IV_c. In a preferred embodiment, the keystrokes are encrypted using CBC-3DES with the key 402 as the key and with IV_c as the initial value. CBC-3DES is a cryptographic algorithm known in the art and described in detail below. Furthermore, in operation 510, the keyboard 162 calculates the MAC message authentication code for a given key press, preferably based on key 402 and IV_m. In a preferred embodiment, the message authentication code is created using CBC-3DESMAC with the key 402 as the key and IV_m as the initial value. As indicated above, CBC3DESMAC is known in the art and described in detail below.
[0044] After the keyboard has created both the encrypted data from the key press and the MAC, the component 202 receives from the keyboard 162 in operation 512 the encrypted data from the key press and the MAC. Then component 202 decrypts data using key 402 and IV_c, and also verifies data using key 402 and IV_m (operation 514). The process then returns to operation 506 to receive the next keypad entry.
CBC-3DES and CBC-3DESMAC cryptographic functions [0045] CBC-3DES is a cryptographic function that combines the Data Encryption Standard (DES) with the Cipher Block Chaining (CBC) mode. "3DES" means that the DES encoding algorithm is applied to a given data block three times ("triple DES"). DES encrypts data by applying a key to the data in a known manner. DES encrypts a long message by splitting that message into smaller blocks and encrypting individual blocks. (When "triple DES" is used, the DES algorithm is applied to each block three times to create encrypted text for that block.) DES (and triple DES) can encrypt each block of data using only the key. However, when the cipher block chain mode is used, one block encryption is based not only on the key, but also on the encrypted text that was created by encrypting the previous block. Thus, the encryption of a given block is based on two inputs: the key and the encrypted text that is the result of encrypting the previous block. Because the first block of encrypted data does not have a "previous" block, the process of creating cipher block chains must be initiated with the "initial value" - ie the first block of data is encrypted based on a key and some initial value. This initial value is not used when encrypting subsequent blocks, but it may indirectly affect how these blocks are encrypted (since the encrypted text of the first block is based on the initial value, the encrypted text of the second block is based on the encrypted text of the first block and so on) .
[0046] In the light of the above discussion, the phrase "CBC-3DESk (IV, message)" means to encrypt "messages" using the K key using the triple DES and
EP 1 473 615 the mode of cipher block chain creation, where IV is the initial value for the cipher block chain.
[0047] CBC-3DESMAC is; s<sup>p</sup>oso<sup>b</sup>em usable with CBC-3DES <sup>d</sup>o trust <sup>k</sup>about<sup>d</sup>authentication (MAC). In particular, the phrase "CBC-3DESMACk (IV, message)" means that the "message" is encrypted using the K key, using the triple DES and cipher block chain creation mode, where IV is the initial value for the cipher block chain. However, because the purpose of CBC-3DESMAC is only to create a MAC for a given message instead of the complicated encrypted text for that message, only the last block of encrypted text is kept, and the remaining blocks of encrypted text are discarded. This last block of encrypted text can be used as a MAC because, even with a constant key and constant IV, it is unlikely that different messages will lead to the same last block (or, more precisely, if each block can represent 2 "different values , there is only one chance for 2 "that any two messages will have the same last block).
[0048] It should be noted that the particular selection of CBC-3DES, as well as the way it is used, is particularly advantageous for encrypted keyboard information. Because the domain of the messages to be encrypted is small (e.g., in the order of 128 different ASCII characters), the mode of creating cipher block chains is particularly useful for protecting the cipher from being broken. If simple encryption (i.e. without creating strings), then in a given session each character would be encrypted into the same encrypted text every time it was pressed - e.g. pressing 'e' each time would produce that encrypted text. Through the so-called "Intelligent guessing" (e.g. by considering the fact that "e" is the most common letter in English) someone could very easily break such a cipher. Creating a chain of all entries in the session makes this cipher harder to break by ensuring that the same data can appear as different encrypted text depending on where it appears in the input stream (e.g. "e" does not always lead to the same encrypted text). In addition, changing the encryption for each session by creating a new initial value based on "nonce" values does not allow observers to detect usage patterns that they could use to break the security (e.g. if the first text entered in each session is a password, the observer could capture
EP 1 473 615 encrypted text for the password and implement a repetitive attack). In addition, the cipher block size used by DES is particularly useful because DES operates on eight-bit blocks, and most keyboard protocols transmit data in blocks that can fit in that size (e.g., the USB standard also uses eight-bit blocks, so any USB block can fit into one DES block without wasting space). However, it should be understood that any other block cipher can be used, and concepts similar to the mode of cipher block chain creation can be applied to such a block cipher.
[0049] It should further be noted that because the encryption scheme described herein is particularly well suited to the keyboard, this encryption scheme is also well suited to other types of input devices, such as a mouse (or other pointing device). These input devices have various features in common with the keyboard, such as a small dictionary and limited ability to use complex encryption algorithms.
Exemplary use of data encryption keyboard [0050] Fig. 6 shows an exemplary environment in which a keyboard that performs secure communication can be used with components that require secure communication. In the example in Fig. 6, manufacturer 602 manufactures keyboards 162 (1), 162 (2), ... 162 (n) and distributes these keyboards for public use. Each of the keyboards 162 (1), 162 (2) ... 162 (n) contains a key 402 and a fixed value 404 (shown in Fig. 4) (or contains means by which the key 402 and a fixed value 404 can be obtained from outside, for example, input for semiconductor memory) Manufacturer 604 manufactures components 202 (1), 202 (2), .., 202 (n) that use secure communication with the keyboard. Each of the components 202 (1), 202 (2), .., 202 (n) has a key 402 and a fixed value of 404 (or is able to obtain a key and a fixed value). Components 202 (1), 202 (2), .. , 202 (n) can now receive input signals from keyboards 162 (1), 162 (2) .... 162 (n) using the techniques described above.
[0051] Manufacturer 602 may have prior contacts with manufacturer 604 so that both manufacturers can agree on a key 402 and constant 404 to be incorporated for secure communication. In one example, the producer
EP 1 473 615
602 and producer 604 are the same company. In another example, manufacturer 604 is a manufacturer of components 202 (1), 202 (2),. , .202 (n), who would like these components to be able to receive data from secure keyboards, and the 602 manufacturer is a manufacturer of keyboards that the 604 manufacturer has found trustworthy enough to entrust him with the production of keyboards for secure communication with 202 components (1) , 202 (2), .., 002 (n) and store key 402 and / or constant 404.
[0052] It should be noted that the above examples are provided for the purpose of explanation only and cannot in any way be construed as limiting the present invention. While the present invention has been described with reference to various embodiments, it is understood that the vocabulary used is for explanation and illustration, and not for limiting its scope. In addition, although the present invention has been described herein with reference to specific means, materials and embodiments, this invention is not intended to be limited to the details disclosed herein. The present invention extends to all functionally equivalent structures, methods and uses, such as are within the scope of the appended claims. Those skilled in the art who have the advantage of specialized education can implement numerous modifications and changes without departing from the scope and spirit of the present invention in its aspects.
EP 1 473 615
Contents4
5 priority claims, no other members on record
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 42867503 | United States of America | A | |
| 42867503 | United States of America | A | |
| 04010225 | European Patent Office (EPO) | A | |
| EP20040010225 | – | – | – |
| US20030428675 | – | – | – |
Numbers
- Publication, DOCDB
- 1473615
- Publication, EPODOC
- PL1473615T
- Application
- 10225
- Application, DOCDB
- 04010225
- Application, EPODOC
- PL20040010225T
Titles2
- English
- Secure communication with a keyboard
- Polish
- Bezpieczna komunikacja za pomocą klawiatury
Classification
- CPC, 12
- G06F21/83
- H04M1/72569
- H04M1/72454
- A61P31/04
- G06F2221/2107
- G08B21/0407
- H04M2250/12
- H04M1/72572
- H04M2201/34
- H04M2201/36
- H04M2250/10
- H04M1/72457
- IPC, 5
- G06F3 02
- G06F1 00
- G06F21 04
- G06F21 00
- G09C1 00