A smartcard and a method of operating a smartcard
Abstract
A smartcard (200) comprises a processor (202), a read and/or write device interface (213) designed for a communication between the processor (202) and a read and/or write device (208), and a user input and/or output unit (212) designed for initiating a communication between a user and the processor (202) via the read and/or write device interface (213).
Term
Term ended
Projected expiry passed 14 February 2026, 0.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
14 claims: 2 independent, 12 dependent
- 1Claims Zastrzeżenia patentowe 1. A smart card (200) containing:1. Karta inteligentna (200) zawierająca: - a processor (202) in the part of the secure smart card (200);- procesor (202) w części bezpiecznej karty inteligentnej (200);- a read / write interface (213) designed to communicate between the processor (202) and at least one external read / write device (208);and - interfejs (213) urządzenia odczytu/zapisu zaprojektowany do komunikacji między procesorem (202) i co najmniej jednym zewnętrznym urządzeniem (208) odczytu/zapisu;i - at least one user input and / or output unit (212) at least for receiving user commands and designed to initiate communication between a user and a processor (202). - co najmniej jedną jednostkę (212) wejścia i/lub wyjścia użytkownika co najmniej dla odbioru poleceń użytkownika i zaprojektowaną do inicjowania komunikacji między użytkownikiem i procesorem (202). - characterized in that the communication between the user and the processor (202) occurs via the interface (213) of the read / write device and that the communication protocol for communication between the processor and the read / write device (208) is the same as the communication protocol for communication between user input and / or output unit and processor. - znamienna tym, że komunikacja między użytkownikiem i procesorem (202) zachodzi poprzez interfejs (213) urządzenia odczytu/zapisu i tym, że protokół komunikacji do komunikacji między procesorem i urządzeniem (208) odczytu/zapisu jest taki sam jak protokół komunikacji do komunikacji między jednostką wejścia i/lub wyjścia użytkownika i procesorem.
- 13A method of operating a smart card (200), the method comprising the steps of:13. Sposób operowania kartą inteligentną (200), przy czym sposób obejmuje etapy: - controlling the processor (202) of the smart card (200);- sterowania procesorem (202) karty inteligentnej (200);- enabling communication between the processor (202) and the external read / write device (208) via the interface (213) of the smart card read / write device (200);- umożliwiania komunikacji między procesorem (202) i zewnętrznym urządzeniem odczytu/zapisu (208), poprzez interfejs (213) urządzenia odczytu/zapisu karty inteligentnej (200);- characterized in that the method comprises initiating, by means of a user input and / or output unit (212), which is at least for receiving user commands, communication between a user and a processor (202) via a read / write device interface (213) and the like;that the communication protocol for communication between the processor and the read / write device (208) is the same as the communication protocol for communication between the user input and / or output unit and the processor. - znamienny tym, że sposób obejmuje inicjowanie, za pomocą jednostki (212) wejścia i/lub wyjścia użytkownika, która jest co najmniej do odbioru poleceń użytkownika, komunikacji między użytkownikiem i procesorem (202) poprzez interfejs (213) urządzenia odczytu/zapisu i tym, że protokół komunikacji do komunikacji między procesorem i urządzeniem (208) odczytu/zapisu jest taki sam jak protokół komunikacji do komunikacji między jednostką wejścia i/lub wyjścia użytkownika i procesorem.
Independent claims2
117 paragraphs, as filed
[0001] The invention relates to a smart card as well as to a method for handling a smartcard.
BACKGROUND OF THE INVENTION [0002] A smart card or chip card may be a tiny crypto processor embedded in a card the size of a credit card or even a smaller card, such as a SIM card for mobile phones. The smart card usually does not contain a battery and the energy is provided by the read / write device, i.e. by a read or write device to control the functions of the smart card by reading data from the smart card or by writing data to the smart card.
[0003] A smart card device is widely used in the fields of finance, secure access and transport. Smart cards usually contain enhanced security processors that act as secure means of data storage, such as the data of the smart card holder (for example, name, account numbers, number of collected loyalty points). Access to this data is possible only when the card is entered into the read / write terminal.
[0004] Enabling the integration of user interface functionality directly in smart cards is a major challenge. For example, the display can be integrated in a smart card for displaying information to the user. Or, in the smart card, buttons may be included to allow the user to enter data.
[0005] Smart cards were intentionally designed without a "human-machine" interface allowing user interaction. Lack of support for user interaction reflects both in hardware design and in the development of software (operating system) of known smart cards.
[0006] This conscious choice was dictated by the lack of technology for thin, flexible displays and strict security requirements imposed on smart cards. Currently, because technology is available for thin, flexible displays, strict security policies and procedures make the implementation of user interaction difficult. The introduction of the API (application programming interface) known from consumer electronics devices and personal computer devices is difficult because security policies require that each system component be developed under the control of special procedures, for example in terms of security and reliability. This requires, when developing or changing any component of the processor chip card or software component, a long certification procedure,
[0007] In the following, referring to Fig. 1, a smart card with integrated functionality according to the prior art will be described.
[0008] The smart card 100 comprises a plastic substrate 101 on which a formed integrated circuit, which provides the functionality of a smart card.
[0009] In the security domain or processor 102 (secure IC processor) of the smartcard 100, in which a high level of security is provided, a card management unit 103 is provided (which may be a logical unit, a program routine operable when an APDU (Application Protocol) is received. Data Unit, data structure in the communication protocol between the reader and the card)), which is adapted to communicate with a plurality of application units 104, each containing data and instructions required to support various applications. 100. In addition, a plurality of controller units 106 are provided, each of which is used to control the associated hardware entity 107.
[0010] The smart card 100 is designed to communicate with the smart card read and write terminal 108 as a master device. The communication between the terminal 108 and the smart card is carried out by exchanging the APDU units in accordance with ISO 7816. The card management unit 103 exchanges the APDU with a specific application unit 104 for implementing the corresponding application.
The internal structure of the smartcard 100 is similar to a standard architecture (such as a personal computer) that can be described using a well-known layered model. Looking at the hardware units 107, these units may include processors, memories, peripherals and several encryption / decryption coprocessors operating directly with the low-level drivers. The controller's units 106 form part of the OSL (Operating System Layer). OSL provides hardware functionality to the application and provides additional features often used again by applications. The operating system 105 is also responsible for the initialisation of integrated circuits during power up.
[0012] The vendor's operating system may operate in a manner that is schematically shown in Fig. 1 as application units 104. Because smart cards, such as smart card 100, are commonly used with terminals such as card reading and writing terminal 108 intelligent, is usedproceed as in the communication of the main unit with the slave device. That is, the terminal 108 initiates communication with the smartcard 100 by sending the APDUs to the processor 102. The card management unit 103, using the address field in the APDU, can recognize which application unit 104 they should be forwarded to. The target application, after receiving this information, performs the requested action and returns responsive with the data / status to the terminal 108. This communication scheme requires that for composite applications, both the terminal 108 and the smart card 100 store the current communication status. In addition to the described components and their function, the smart card 100 includes extensions to provide the functionality of the user interface of the smart card 100.
For this purpose, in the part of the smart card 100 that does not apply to the processor 102 (security domain), keys 112 and display 113 are provided. To enable the user to interact with the smartcard 100 by entering commands with the buttons 112 and by outputting information on the display 113 there is a connection between the keys 112 / display 113 and the button / display interface unit 111 provided at the level of the hardware units 107. Furthermore, the key / display driver unit 110 is provided at the unit level.
106 of the controller to allow the user to visually perceive the data displayed on the display 113. In the smart card 100 shown in Fig. 1, the display functionality or user interface functionality is provided by the display 113 and buttons 112. In addition, it is necessary to extend or adapt the operating system 105, as shown schematically as the operating system extension 109 in Fig. 1.
[0014] The standard blocks of the smart card 100 are shown with solid lines, and the additional blocks that are necessary for the entry / exit functionality are indicated by dashed lines. It can be seen that a key / display driver unit 110 has been added, button / display interface unit 111, keys 112 and display 113, and that the operating system extension 109 and operating system 105 have been extended to provide API display functionality for applications implemented in accordance with with application units 104.
[0015] However, the implementation of the smart card 100 according to Fig. 1 has some disadvantages. First, the operating system 105 needs to be modified in the form of an operating system extension 109. This results in development and certification costs. In addition, due to modifications colliding with the processor 102 (secure domain) of the smart card 100, a potential security risk arises.
[0016] Secondly, in addition to additions to the hardware controllers, an additional use mode must be defined for the smart card 100 that is different from the native mode of the master device and the slave device. An additional mode may be applied when the smart card 100 is running outside the terminal (the so-called stand-alone mode) for the reaction to the user pressing the 112 buttons and for displaying information. This affects the architecture of the smart card system 100 and causes additional security risks that require additional restrictions.
[0017] Thirdly, the application units 104 must be modified to implement the input / output functionality. This is difficult to obtain for well-known, commonly accepted and accepted standards such as EMV ("Europay, MasterCard, VISA", standard for credit / debit card applications) or CEPS ("Common Electronic Purse Specification" standard for e-commerce applications Purse) and would require re-standardization. Fourthly, the smart card device (integrated circuit) requires an additional hardware interface, namely the 111 interface / display interface, respectively, for communication with the 112 / display 113 keys and the 110 keys / display driver. This interface may not be desirable because of security risks.
[0018] JP 2001-331771 discloses an IC card with an auto-display function in which a signal line for communication between a read / write device and a microcontroller is used as a signal line for data transfer to a display controller from a microcontroller. According to JP 2001-331771, an additional clock line (designated CLK2) is provided between the display and the safe microcontroller, wherein an additional clock line is not guided to the outer part. In other words, according to JP 2001-331771, the microcontroller controls communication with the display. However, this has the disadvantage that there are problems when operating the IC card. Additionally, in JP 2001-331771, the display can be saved only when the card is in the read / write device.
[0019] US 2003/0140221 discloses a portable storage medium comprising a processor, a smart card interface and a keypad, which is integral with the data carrier for user input.
[0020] EP 1 004 980 discloses a smart card in which the user PIN can be inserted directly into the smart card when the smart card is presented to the reader.
OBJECT AND SUMMARY OF THE INVENTION [0021] The object of the invention is to operate a smart card in a safe manner.
[0022] In order to achieve the above-defined purpose, a smart card and a method of operating a smart card according to the independent claims are provided.
[0023] According to an illustrative embodiment of the invention, a smart card containing a processor is provided. In addition, the smart card includes a read / write device interface designed for communication between the processor and a read and / or write device and a user input and / or output unit designed to initiate communication between the user and the processor via the read and / or write device interface.
[0024] Furthermore, according to another illustrative embodiment of the invention, a method of operating with a smart card is provided. The method comprises the steps of controlling the smart card processor, allowing communication between the processor and the read / write device via the smart card reading and / or writing device interface and initializing, by means of the user input and / or output unit, communication between the user and the processor via the reading device interface and / or write. It should be noted that the steps mentioned above do not have to be carried out in the order given.
[0025] The term "smart card" in particular may mean a contact processor card or contactless processor card that may comprise a secure processor for delivering one or more applications.
[0026] The term "processor" in particular means a control unit or a smart card management unit, such as a microprocessor or a central processing unit (CPU). Such a processor can be made as a monolithically integrated circuit, e.g. produced in semiconductor technology (in particular silicon).
[0027] The term "read / write device" in particular means an external device (for a smart card) for controlling the functionality of a smart card by reading data from a smart card and / or by writing data on a smart card.
[0028] The term & quot; user input and / or output unit & quot; in particular means a device that can be provided at least partially on a smartcard and which allows the user to interact with the smart card. In particular, such user input and / or output Jecta "may enable the user to either forward or bi-directionally transmit data to and / or receive data from the processor, wherein the data may relate to the particular application provided by the smart card.
[0029] The "interface" may, in particular, provide connection or access to a given communication system component.
[0030] The smart card according to the invention may be capable of delivering the application, and the processor on the smart card may be designed to control it for delivery of the application. The term "application" means a functionality or service that can be provided by a smart card, wherein the processor can provide computing resources for carrying out such an application.
The characteristic features of the invention in particular have the advantage that a smart card is provided which, in addition to the optional implementation of at least one particular application, provides a user interface (e.g. a display and / or keyboard) that is connected to the processor through the same a signal path, which is used to connect the processor to a read and / or write device to read information from the smart card and / or to write information on the smart card. Communication between the user, on the one hand, (interactively using the user input and / or output unit as a user interface) and the processor, on the other hand, can be initiated via the read and / or write device interface. In other words, communication between the user interface and the processor can be controlled by the user instead of the processor side. As a result, from the processor's point of view (which can be located in the part of the secure smart card) communication with the (main) read and / or write terminal can be performed in a similar or identical way as communication with the (main) input and / or output unit user. In this way, the smart card processor according to the described embodiment of the invention can act as a slave device in both communication channels with the reading and / or writing terminal, as well as in communication channels with the user's (main) input and / or output unit. In this way, the communication keeps the unchanged secure part accommodating the processor, thus ensuring a high level of security.
[0032] In a fundamental contrast to known concepts (for example according to JP 2001-331771), the smart card according to the described illustrative embodiment of the invention does not use a processor to control the input / output means (e.g., a keyboard, a display). Instead, the I / O agents themselves actively initiate communication with the processor if the user so wishes. In other words, the input / output means according to the invention acts as a main node and the processor acts as a subordinate node in this communication channel. Effectively, the input / output means emulate a terminal or read and / or write device.
[0033] Since the communication between the reading and / or write device on the one hand and the smart card on the other hand is normally (e.g. in the ATM application) initialized by the read and / or write device, the smart card does not substantially notice the difference between communication with the reading terminal and / or write, and communication with the user interface (e.g. such as a keyboard or display). This has the advantage that all security elements that are (already) provided for communication between the reading and / or write interface on one side and the smart card on the other hand can also be used for communication between the smart card (or rather between the card processor) intelligent) and user input and / or output unit.
The system according to the invention allows connection of one or more user input and / or output units, such as a keyboard or display, to a smart card processor in a simple and very efficient manner. According to the described architecture, the processor is securely protected from tampering, so that security critical applications (e.g. credit card, electronic purse) can be reliably implemented using this smart card. In addition, the implemented user input and / or output applications can thus be implemented without the risk of security risk. The invention allows the user input and / or output unit to be connected to a processor without impairing its security mechanisms.
[0035] According to one aspect of the invention, an external smart card interface that normally provides communication between the smart card and the terminal is used simultaneously to integrate additional components, such as a display or keyboard, into a smart card. Communication between existing parts in the safe area and new parts that can be provided outside the safe area can occur through an independent element that is part of the smart card but is outside the safe area.
[0036] Hence, large parts (e.g. a very secure application inherited) of an existing smart card may remain unchanged, because the communication protocol for communication between the processor and the user interface may be the same as used for communication between the processor and the terminal.
[0037] Preferably, the system according to the invention enables fast integration, for example display functionality, in existing smart card systems without affecting the security of the entire system. In addition, backward compatibility is possible with existing systems.
[0038] According to an aspect of the invention, the smart card provides a method for integrating functionalities of a user's interaction. To this end, an external smart card interface that normally allows data communication between the smart card and the read / write terminal is used to connect additional components to the smart card.
According to an aspect of the invention, in communication the display controller may assume the role of the master device emulating the ISO 7816 terminal. The display controller according to the invention may communicate with a secure integrated circuit (IC) or processor in the usual manner using the higher-level APDU protocol (Application Protocol Data Unit). Therefore, the display driver is seen by the safe IC as a normal terminal. In this way, the system according to the invention provides a very secure way of connecting the display to a secure integrated circuit, since no modification of the hardware safe integrated circuit chip or the program chip of the secure integrated circuit (low level) is required.
[0040] In contrast to the system according to the invention, the IC card according to JP 2001-331771 requires an additional clock line from a safe IC to the display controller. Furthermore, according to JP 2001-331771, a proprietary protocol is necessary for communication between the secure IC and the display controller. The system according to JP 2001-331771 is based on the assumption that either the terminal or the safe IC is the main device in communication and the display controller is always a slave device (i.e., it does not initiate communication).
[0041] The smart card according to the invention may be implemented according to an architecture in which the communication between the user interaction device and the processor is the architecture of the master device - the slave device. As part of such communication, the user interaction device may assume the role of the master device (i.e. it may initiate communication by sending a corresponding message to the processor) and the processor may assume the role of the slave device (i.e. can send a response to the user interaction device only in the case of a previously sent message from the user interaction device).
[0042] The smart card according to the invention can operate in a so-called independent (stand alone) mode, i.e. it can also work in the absence of a read / write terminal. In this independent mode, the user may use the user interaction device to communicate with the processor regardless of the presence or absence of the read / write terminal. In addition, standard known software tools (SDEs) can be used to develop applications.
[0043] It is mentioned that a smart card according to the invention may comprise one or more user input and / or output units and may be adapted for communication between the processor and the read and / or write devices.
[0044] With reference to the independent claims, further exemplary embodiments of the invention will be described below. These embodiments also apply to the method of handling a smart card.
[0045] The smart card may be designed such that the communication protocol for communication between the read and / or write device and the processor is equal to the communication protocol for communication between the user and the processor. In other words, the input and / or output means may be adapted to communicate with the processor in substantially the same manner as the terminal. This makes it possible to construct the processor in a very simple way, since the implementation of one communication protocol is sufficient for communication with both the read and / or write terminal on one side and the user through the user input and / or output unit on the other.
The smartcard may comprise at least one wired connection element capable of connecting the read and / or write device to the processor, wherein at least a portion of the at least one wired connection element may form a connection (exclusively or not exclusively) of the input units and / or user's output from the processor. According to the described embodiment, the same conductors or wires or contacts may be used to connect the reading and / or write device to the processor and to connect the user interface to the processor. Thanks to this, a simple and space-saving design of a smart card is possible thanks to the synergistic use of wires. However, in addition or alternatively,
[0047] The smartcard can be designed in such a way that the communication between the user input and / or output unit and the processor can be performed according to ISO 7816. Particular attention is paid in this regard to parts of ISO 7816 that relate to the definition and use of the APDU ( Application Protocol Data Unit). The ISO 7816 series or standard defines not only the physical shapes of the smart card and the positions and shapes of the electrical connectors, but also the communication and power protocols for use on these connectors as well as the functionality and format of commands sent to the smart card and the responses returned by the smart card. The communication between the reading and / or write device on the one hand and the processor on the other hand may be implemented according to the present embodiment, according to the same industry standards,
[0048] Furthermore, the smart card may be designed for communication between the read and / or write user unit and the processor by means of transmitting at least one APPR (Application Protocol Data Unit). An APDU unit may be defined as a communication unit between the processor card and the read and write device according to ISO 7816. There exist APDU commands that transmit commands between two objects and APDUs that transmit a response to commands. The APDU communication method relates to the well-known OSI model (Open Systems Interconnection), and in particular for smart cards, the APDU concept is described in ISO 7816-4, which is explicitly referenced here.
[0049] The smart card may be divided into a secure part in which a secure function and a remaining part are provided, the safety part comprising the processor and the remaining part comprising the user reading and / or writing unit. The secure part can be part of a smart card in which the components of the smart card are provided, which contain data that is critical in terms of security. The processor, according to the described embodiment, is in this secure part. However, by locating the reading and / or writing unit in the remainder (not including or containing a lower level of security measures), the processor is provided in a secure area, and input and / or output means are provided in a less secure area. Thanks to this, general safety is improved,
[0050] The user input and / or output unit may comprise at least one of a group consisting of a display, a keypad, a button, an input and / or output acoustic means and a user identification sensor. In general, the user input and / or output unit may include any element that allows the human user to influence the functionality of the smart card or to be informed in a noticeable manner of such functionality. In particular, the user input and / or output unit may include means to enable the user to provide data or commands or messages to the processor to thereby control the functionality of the applications running on the smart card. On the other hand, this also includes the provision of data or messages or information from the processor to the user,
[0051] For example, the user can be identified by entering a password using a keyboard or button. Or, the remaining credit on the payment card can be displayed to the user via the display.
[0052] The user input and / or output unit may comprise any type of display means. For example, a flexible display according to Philips Flexible Display Systems technology can be implemented in a smart card. The user interface can then consist of a small display and a few buttons, which enables simple interaction based on the user's menu with the application on the smart card.
[0053] Furthermore, a keyboard may be provided on the smartcard by means of which the user may enter commands or messages to be sent to the processor. Similar results can be obtained by providing one or more buttons on the smart card. In particular, the keyboard can be implemented as a number of buttons.
It is also possible that an intelligent card is provided with an acoustic sensor, such as a microphone, in particular a MEMS microphone, which allows the user to provide the card with intelligent audio commands such as "display my current loan" (if necessary or desirable, as part of the voice recognition system). In addition, an acoustic output unit, in particular a MEMS loudspeaker, can be provided on the smart card, such that for example a human voice can output the desired information to the user in an audible manner, such as "your current loan is 100 €".
[0055] Furthermore, the user input and / or output unit may include a user identification sensor, i.e. a sensor that allows the smart card to decide if the user is authorized to access the smart card or not. Such an identification sensor can be a fingerprint sensor, retinal sensor, DNA sensor, etc.
[0056] The user input and / or output unit may be implemented by software and / or hardware. The user input and / or output functionality of the invention can thus be implemented by a computer program, i.e. by software, or by using one or more electronic optimization circuits, i.e. hardware or in a hybrid form, i.e. by means of software components and components. hardware.
[0057] Generally speaking, the user input and / or output unit may include elements allowing the user to perceive the data that is provided by the smart card. On the other hand, the user input and / or output unit may include elements enabling the user to translate human commands into an electronic form.
The smart card according to the invention may further comprise at least one application unit capable of providing data regarding the respective application but unable to provide data regarding the corresponding application in a format that can be output (e.g. displayed) by the input and / or output unit. user (for example, display). The smart card may further comprise a user interaction entity (which may also be designated as an application data conversion unit) that is at least capable of converting data provided by the application entity to a format that can be output by the user input and / or output unit. Communication between the application unit and the user interaction application unit can be mediated by the user input and / or output unit, then act as data mirroring. This embodiment allows the extension of an already existing application unit that can be located in the secure part, but is not capable of providing data that can be displayed. An extension is a unit of the user interaction application (or application data conversion unit) that can be used to convert the data provided by the application unit to a format suitable for display. Also, the application data conversion unit can be provided in the secure part. In addition to the conversion function,
[0059] The smart card user interaction application unit may be adapted to assume the role of the master device in the context of communication with the application entity. In other words, when the user interaction application unit communicates with the application entity, the user interaction application entity can control this communication with the slave type application unit and in particular can initiate such communication.
[0060] The communication between the application unit and the user interaction application unit may be implemented preferably using an input and / or user output unit that can be located outside of the secure part. In other words, the user input and / or output unit may function as a mirroring device, simply transferring data from the application unit to the application data conversion unit or vice versa.
[0061] The smartcard may be adapted in such a way that a message transmitted between the application unit and the user interaction application unit is encrypted. As a result, a very secure communication system is obtained because, even when the message is agreed via an unsecured area, encryption ensures that an enhanced security standard is maintained.
[0062] The user input and / or output unit mediating the message transmitted between the application entity and the user interaction application unit may not be able to decrypt the message. As a result, a high level of security is maintained, as the reconciliation means have no decoding capability.
[0063] The application unit may comprise a code that relates to the so-called "Inherited application".
The term in particular means an application that was developed before the display functionality was available. Such applications are considered universally accepted and standardized (like EMV or CEPS), but they do not provide display functionality.
Such an inherited application is connected, according to the described embodiment, with a display application that can also be located in a secure area. The smart display driver of the user input and / or output unit can be considered as an independent element in the communication method that mediates between the inherited application and the display application.
[0064] For example, the display application may send data (as well as a request to transfer data to an inherited application) to a smart display driver. The smart display driver can transfer data as requested. An inherited application can respond in the usual way, for example by communicating via a terminal. The smart display driver can relay the response to the display application. Then, the display application may request that the smart display driver display the received data.
[0065] Both the application unit and the user interaction application unit (application data conversion unit) may be located in the secure part. According to such a system, data is sent from an application unit in a secure domain via a smart display driver located in an unsecured domain, to a user interaction application unit located in the secure part, or vice versa. However, the user input and / or output unit only transfers data from one of the described units to another without processing them, so that there is no security problem. In fact, data can be sent in an encrypted manner and no data encryption is implemented by the smart display driver.
[0066] The communication between the application unit and the user interaction application unit may comprise transmission of at least one Application Protocol Data Unit. In this way, the communication protocol for this mirroring function may be the same as for communication between the user input and / or output unit and the processor or between the read and / or write device and the processor.
[0067] In particular, the application unit may be an inherited application unit, i.e. an application only application delivery unit, without providing a sophisticated display functionality.
[0068] The illustrative smart card applications of the invention include using as a credit card as a SIM card for a mobile telephone as an authorization card for pay television as an identification card and access control as a public transport ticket, etc.
[0069] The smart card according to the invention may be implemented as a smart contact card or as a non-contact intelligent card. In a contact type smart card, an integrated circuit or semiconductor chip containing a processor may be recognized by electrically conductive contacts. In a non-contact type smartcard, which can also be marked as a non-contact intelligent card, the integrated circuit can communicate with the card read / write device using wireless induction technology with independent power supply (in particular by electromagnetic wave replacement, for example in the high frequency domain, between the card read / write device and the smart card).
[0070] Next, an exemplary embodiment of the method for operating the smart card will be described. This embodiment also applies to the smartcard of the invention.
[0071] The communication between the user and the processor via the read and / or write device interface may be initiated by means of the user input and / or output unit provided in the smart card. According to this embodiment, the user input and / or output unit is located in the smart card.
[0072] Aspects as defined above and further aspects of the invention are clear from the exemplary embodiments that will be described below and are explained with reference to these exemplary embodiments.
BRIEF DESCRIPTION OF THE DRAWINGS [0073] The invention will be described below in more detail with reference to examples of an embodiment, but to which the invention is not limited,
Fig. 1 shows a smart card according to the prior art,
Fig. 2 shows a smart card according to an illustrative embodiment of the invention.
Fig. 3 shows a smart card according to another illustrative embodiment of the invention,
Fig. 4 shows a part of a smart card according to an illustrative embodiment of the invention, illustrating the mirroring function of the user input and / or output unit.
DESCRIPTION OF EMBODIMENTS [0074] The illustration in the drawing is schematic. In the various drawings similar or identical elements have the same reference numbers.
[0075] In the following, referring to Fig. 2, a smart card 200 according to an exemplary embodiment of the invention will be described in detail. Provided that similar components are used as in Fig. 1, reference should also be made to the above description in Fig. 1.
[0076] The various components of the smart card 200 are provided on and / or in the plastic substrate 201. The size of the smart card 200 can be the size of a conventional credit card. The smart card 200 shown in Fig. 2 is capable of providing a plurality of applications (each of which relates to one specific application unit 204). The smart card 200 includes a microprocessor 202 that is designed to perform calculations and control functions as part of handling various applications.
[0077] The smart card read / write terminal 208 (also referred to as the smart card read / write device) is provided to read information stored or generated in the smart card 200 or to program or input data input from the outside into the smart card 200. Interface 213 the smart card read and write device 200 is designed for bi-directional communication between the smart card read and write device 208 and the microprocessor 202, [0078] Furthermore, a user input and output unit 202 (I / O unit) is provided in the smart card. The user input and output unit 212 may actively initiate communication between a human user (not shown) and a microprocessor 202 via the interface 213 of the smart card read and write device. In this way, as part of the communication between the user input and output unit 212 on one side and the microprocessor 202 on the other hand, the user input and output unit 212 plays the role of the master device, and the microprocessor 202 acts as a slave device. This allocation of functions is not typical, because in the field of electronics usually the microprocessor plays the role of the main device. However, this feature allocation has the key advantage of improving the security of data transfer between the various components of the smart card 200. This allocation of functions is not typical, because in the field of electronics usually the microprocessor plays the role of the main device. However, this feature allocation has the key advantage of improving the security of data transfer between the various components of the smart card 200. This allocation of functions is not typical, because in the field of electronics usually the microprocessor plays the role of the main device. However, this feature allocation has the key advantage of improving the security of data transfer between the various components of the smart card 200.
[0079] The user input and / or output unit 212 includes a smart display controller 211 that is implemented in hardware according to the described embodiment and which coordinates communication between the processor 202 on the one hand and the display device 210 and buttons 209 (as further components of the unit 212). user input and / or output) on the other hand.
The user may use the buttons 209 to enter the commands to be communicated, via the smart display controller 211 and the interface 213, to the processor 203 for their further processing in the context of one of the applications allocated to the application units 204. For example, the application may be an application financial credit / payment card or similar. In addition, application data provided by smart card 200 may be transmitted from processor 202 via interface 213 and smart display controller 211 to display device 210 that displays corresponding video and / or audio information to a human user.
[0081] As can be seen from Fig. 2, the smart card 200 is divided into safety parts or a processor 202 and - the remainder - a non-security portion. A microprocessor 202 containing a plurality of application units 204 is located in the secure part. In addition, an operating system 205 is provided that may include software components for operating the smartcard 200. In addition, a plurality of controller units 206 and a plurality of hardware units 207 are provided. Each hardware entity 207 may include components such as a sub-processor, memory, peripheral device or sub-processor encryption / decryption.
[0082] The communication protocol used for communication between the smart card read and write terminal 208 and microprocessor 202 is equal to the communication protocol between the user (not shown) of the user input and output unit 212 and the microprocessor 202. Both communication channels are implemented by exchanging the APDU units ( Application Protocol Data Unit) and in accordance with the industry standard ISO 7816.
[0083] The user input and / or output unit 212 includes a display 210 (which may be implemented based on Philips Flexible Display Systems technology) and push buttons.
209. According to the embodiment shown in Fig. 2, the user input and / or output unit 212 is implemented as a hardware unit.
[0084] The smart card 200 is a fast, secure and inexpensive device in which the world of enhanced security of smart card devices and corresponding software remains substantially unchanged (and therefore safe and insensitive to potential attacks), but said smart card has the option of implementing a card application that allows user interaction through existing secure infrastructure. Although the embodiment shown in Fig. 2 focuses on the display 210 and the buttons 209 connected to the smart card device hardware device 200, the system according to the invention can also combine other electronics present in the card, such as fingerprint readers, etc.
[0085] The hardware and software connection of the display functionality via the existing physical and logical interfaces will be described below. Fig. 2 shows the expansion of the smart card system with the functionality of the display. In smart card 200, the smart card processor system (hardware and software) generally remains unchanged and therefore remains secure. In Fig. 2, the I / O functionality is added as a separate user input and / or output unit 212 next to the smart card processor or secure domain 202 of the smart card 200.
[0086] The smart display controller 211 communicates with the smart card application (or rather with the microprocessor 202) by using the ISO 7816 interface 213 and by exchanging the APDUs with the microprocessor 202. Communication between the user input and / or output unit 212 and the microprocessor 202 is performed in the same way as communication with the smart card reading and writing terminal 208. Via the interface 213, the smart display controller 211 may inform the application unit 204, by means of a corresponding message, that the button 209 has been pressed by the user and asks the appropriate application unit for data that should be displayed on the display 210. The system entry 212 does not affect system security and / or user's output,
[0087] The smart display driver 211 may be implemented in both hardware and software, with the two realizations being conceptually equal.
[0088] The smartcard 200 represents a hardware embodiment of the smart display controller 211. This requires the implementation of a function block in the display driver and connections from ISO 7816 contacts to this controller. The embodiment of Fig. 2 is very flexible, since the functionality of the display depends only on the application developer. In this situation no additional hardware interface is required in the microprocessor 202.
[0089] In the following, referring to Fig. 3, a smart card 300 will be described in accordance with another illustrative embodiment of the invention.
[0090] In the embodiment shown in Fig. 3, the smart display controller 211 is implemented programmatically. Accordingly, the smart display controller 211 of the user input and / or output unit 302 is located in the program block 304 of the smartcard 300. The smart display controller 211 further includes buttons 209 and a display device 210. Receiver / transmitter buffer 303 (buffer (RX / TX) and firewall unit 301 are also in program block 304.
[0091] The software implementation of the intelligent display controller 211 means that there is functionality to send and receive the APDUs to the management device 203 with the microprocessor card 202 in the form of software by means of a function call, for example with the receiver / transmitter buffer 303. The smart display driver 211 also operates based on program commands. It works in the area of the card driver firewall, completely separated from the secure domain 202 (similar to the Philips Mifare emulation in the Philips smart card processors). It controls from the display device 210 and the buttons 209 through a dedicated interface, for example via a serial interface. This embodiment of Fig. 3 does not require any or requires only a small certification.
[0092] In the following, referring to Fig. 4, part 400 of a smart card will be described in accordance with yet another embodiment of the invention in which the data mirrored functionality of the smart display controller is implemented. Fig. 4 illustrates the concept of adding display functionality to an inherited application.
[0093] As seen in Fig. 4, the portion 400 comprises a display application unit 401 located in the secure processor part 202 and an inherited application unit 402 also in the security portion or processor 202. In addition to the display application unit 401 and the application unit 402 inherited further application units 204 are provided from the secure portion 202. As will be described below, communication between the display application unit 401 and the inherited application entity 402 is performed through multiple transmission channels 403 to 407 and is mediated by the smart display controller 211 performing data mirroring.
[0094] The embodiment shown in Fig. 4 solves the problem of displaying information from commonly accepted and standardized inherited applications (such as contained in the application unit inherited from Fig. 402), for example an electronic purse (CEPS, Geldkarte, Chipknip). In many cases, such existing applications are not designed to display information, such as the amount stored in e-purse, on the display.
[0095] A simple solution to this problem would be to add a display function to the application units. However, this approach would require large expenditures for development and certification and a long period of time for obtaining industry acceptance.
[0096] Another possible solution could be to implement terminal emulation functionality in the smart display controller 211. Such an emulated terminal would be able to read the required data (e.g. amounts in e-purse) from an inherited application, formatting them and displaying them on the display. However, such a solution would have several disadvantages. For example, the intelligent display controller 211 would have to assume full functionality of the terminal with protocols for different application standards (e.g., Geldkarte for Germany, Chipknip for the Netherlands or CEPS for new cards). This would lead to a complicated and expensive hardware and / or software block.
[0097] Furthermore, communication with the inherited entity application 402 is often encrypted. This implementation would therefore require that the encryption keys be stored in the smart display driver 211 during the method of completing the card (which is expensive and complex). This would also require the implementation of cryptology algorithms in the smart display controller 211. In addition, it would not be possible to customize individually the displayed information on the smart card, because the smart display driver 211 would have to format the contents of the display.
[0098] The solution according to Fig. 4 is an implementation of the mirroring functionality for the APDUs in the smart display controller 211 with a separate display application unit 401. This display application unit 401 is capable of receiving information necessary to format the contents of the display using a standard, well-known application protocol inherited. Any communication messages communicated between the display application unit 401 and the display application conversion unit 402 are transmitted by the smart display controller 211 as shown in Fig. 4. In Fig. 4 only some relevant smart card components are shown as part 400. Communication arrows 403 to 407 symbolize the principle of the master device and subordinate data exchange according to the ISO 7816 protocols to simplify the image.
[0099] The application components are housed in the smart card secure domain 202 IC. In the implementation of Fig. 4 there is a display application unit 401, which is a special application designed to receive, interpret and display data of one or more application units 401 inherited by the smart display controller 211.
[0100] The communication operates as follows: the display application unit 401 sends to the smart display controller 211 a request for mirroring (i.e., transmitting) the communication messages to the destination entity 402 of the inherited application. Together with the request, the display application unit 401 sends the encapsulated APDU unit to be forwarded to the application unit 402 inherited, see transmission arrow 403.
[0101] Next, the smart display controller 211 sends (i.e. transmits) the desired APDU to the inherited application unit 401, see transmission arrow 404.
[0102] This in-app unit 402 responds in the usual manner (such as when communicating with the terminal) by transmitting data / status to the smart display controller 211, see transmission arrow 405.
[0103] The smart display controller 211 again transmits the response back to the display application unit 401, see transmission arrow 406.
[0104] Next, the display application unit 401 can provide the display content to the smart display controller 211, see transmission arrow 407, based on data received from the inherited application unit 402.
[0105] An important advantage of this method is security. Because the smart display driver 211 does not need to interpret transmitted data, the data can be encrypted using cryptographic key means without leaving the secure domain 202. This means that the display application unit 401 can securely obtain information from the application unit 402 inherited (and vice versa) and extract information that could be displayed on the screen, and then send it to the smart display driver 211. Thus, the display application entity 401 and the application entity 402 inherited, both of which are part of a secure domain, can communicate via a smart display controller 211 that is outside the secure domain in a secure manner.
[0106] Another advantage of this solution is that the service provider can match the display application unit 401 (i.e., for example, change the display of the data) and remains independent of the card or operating system used. The said solution may even add a user identification, e.g. via a PIN code to the display application unit 401, for secure access to personal data in the inherited application unit 402. The mirroring functionality can easily be implemented in the smart display controller 211.
[0107] The system according to the invention can be used in smart cards with many components, in particular in smart cards with display. The invention enables fast integration of display functionality in existing smart card systems without affecting the security of the entire system, and this offers a solution to the issue of backward compatibility. The system according to the invention provides potential customers by applying existing standards, such as ISO 7816, a high degree of simplicity of use.
[0108] The smartcard 200 according to the invention can also be used for displaying data that is received via the input and / or output device interface 213. In one embodiment, said data is sent directly (without using the processor 202) to the input and / or output unit 212 via the read / write device interface 213. In this case, the input and / or output unit 212 acts as a slave device. However, the processor 202 may also be involved in this data display operation.
[0109] It should be noted that the term "comprising" does not exclude other elements or steps, and the use of the singular does not exclude the plural. Also, the elements described in connection with the various embodiments may have been combined.
[0110] It should be noted that the reference in the claims should not be construed as limiting the scope of the claims.
20 members in 7 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 05101208 | European Patent Office (EPO) | A | |
| 05101208 | European Patent Office (EPO) | A | |
| 06710896 | European Patent Office (EPO) | A | |
| 05101208 | – | – | – |
| 067108969 | – | – | – |
| EP20050101208 | – | – | – |
| EP20060710896 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| WO2006087657A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006087673A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1854040A1 | European Patent Office (EPO) | A1 | |
| EP1854053A1 | European Patent Office (EPO) | A1 | |
| CN101120354A | China | A | |
| CN101120364A | China | A | |
| US2008149734A1 | United States of America | A1 | |
| US2008163247A1 | United States of America | A1 | |
| JP2008530702A | Japan | A | |
| JP2008530936A | Japan | A | |
| CN101120354B | China | B | |
| US7913916B2 | United States of America | B2 | |
| CN101120364B | China | B | |
| JP5069569B2 | Japan | B2 | |
| JP5124288B2 | Japan | B2 | |
| US8719840B2 | United States of America | B2 | |
| EP3009966A1 | European Patent Office (EPO) | A1 | |
| EP1854053B1 | European Patent Office (EPO) | B1 | |
| ES2581561T3 | Spain | T3 | |
| PL1854053T3This record | Poland | T3 |
Numbers
- Publication
- 1854053
- Publication, DOCDB
- 1854053
- Publication, EPODOC
- PL1854053T
- Application
- 6710896
- Application, DOCDB
- 06710896
- Application, EPODOC
- PL19960067108T
Titles2
- English
- A SMARTCARD AND A METHOD OF OPERATING A SMARTCARD
- Polish
- KARTA INTELIGENTA I SPOSÓB OPEROWANIA KARTĄ INTELIGENTNĄ
Classification
- CPC, 5
- G06K19/072
- G06K19/0719
- G06K7/10297
- G06K19/077
- G06K19/07309
- IPC, 1
- G06K19 077