Method for the preparation of a chip card for electronic signature services
Abstract
This record has no abstract on file.
Term
0.2 yearsto projected expiry
Projected expiry 8 December 2026, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
12 claims: 9 independent, 3 dependent
- 1Patent claims Zastrzeżenia patentowe 1. The method of preparing the smart card (11) for electronic signature services, in which information is exchanged between the smart card user and the signature portal (10), characterized by the following stages:1. Sposób przygotowania karty inteligentnej (11) dla usług podpisu elektronicznego, w którym wymieniane są informacje między użytkownikiem karty inteligentnej a portalem (10) podpisu, znamienny tym, że obejmuje etapy: - logging the user into the signature portal (10);- zalogowania użytkownika w portalu (10) podpisu;- generating the token assigned to the user by the signature portal (10) and saving the token in the signature portal (10);- wygenerowania przypisanego do uż ytkownika tokena przez portal (10) podpisu i zapisanie tokena w portalu (10) podpisu;- przesł ania tokena z portalu (10) podpisu do użytkownika;- sending the token from the signature portal (10) to the user;- generating a pair of asymmetric keys, consisting of a public key and secret key and signature PIN number, assigned to the pair of asymmetric keys, using the application (11a) of the software executed in the smart card (11) and using a token;- wygenerowania pary asymetrycznych kluczy, złożonej z klucza publicznego i klucza tajnego i numeru PIN podpisu, przypisanego parze asymetrycznych kluczy, za pomocą aplikacji (11a) oprogramowania wykonywanej w karcie inteligentnej (11) i przy wykorzystaniu tokena;- communicating the signature PIN to the user by a smart card;- zakomunikowania uż ytkownikowi numeru PIN podpisu przez kartę inteligentną ;- przesł ania klucza publicznego i podpisu z karty inteligentnej do portalu (10) podpisu;- sending the public key and signature from the smart card to the signature portal (10);- registering the user's public key together with the token assigned to the user in the signature portal. - zarejestrowania publicznego klucza uż ytkownika wraz z przypisanym do użytkownika tokenem w portalu podpisu.
- 3Method according to one of the preceding claims, characterized in that the signature comprises a token and optionally 3. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że podpis zawiera token i opcjonalnie -11 additional data used to identify the user, whereby the token and additional data are encrypted using the user's secret key. -11dodatkowe dane, służące do identyfikacji użytkownika, przy czym token i dodatkowe dane są szyfrowane za pomocą tajnego klucza użytkownika.
- 4The method according to one of the preceding claims, characterized in that the token is sent from the signature portal to the user in a non-electronic way. 4. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że token jest przesyłany z portalu podpisu do użytkownika w sposób nie elektroniczny.
- 5The method according to one of the preceding claims, characterized in that the user and his public key are authenticated by the signature portal based on the signature. 5. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że użytkownik i jego klucz publiczny są uwierzytelniane przez portal podpisu w oparciu o podpis.
- 6The method according to one of the preceding claims, characterized in that the random number generated by the signature portal is used as a token. 6. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że liczba losowa wygenerowana przez portal podpisu jest wykorzystywana jako token.
- 7The method according to one of the preceding claims, characterized in that the terminal (12) is used for communication between the smart card (11) and the user. 7. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że terminal (12) jest wykorzystywany do komunikacji między kartą inteligentną (11) a użytkownikiem.
- 8The method according to one of the preceding claims, characterized in that the terminal (12) compatible with the mobile communication system is used for communication between the smart card (11) and the signature portal (10), 8. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że terminal (12) kompatybilny z systemem łączności mobilnej jest wykorzystywany do komunikacji między kartą inteligentną (11) a portalem (10) podpisu ,.
- 9Method according to one of the preceding claims, characterized in that the terminal (12) is used as a data input device, a data output device and as a communication device for exchanging data between the smart card (11) and the signature portal (10). 9. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że terminal (12) jest wykorzystywany jako urządzenie do wprowadzania danych, urządzenie do wyprowadzania danych i jako urządzenie komunikacyjne, służące do wymiany danych między kartą inteligentną (11) a portalem (10) podpisu.
- 10The method according to one of the preceding claims, characterized in that the terminal (12) is a cellular telephone. 10. Sposób według jednego z poprzednich zastrzeżeń, znamienny tym, że terminal (12) jest telefonem komórkowym. -1210 -1210
Independent claims9
40 paragraphs in 1 section, as filed
[0001] The invention relates to a method of preparing a smart card for electronic signature services.
In particular, the invention relates to the preparation of subscriber identification cards, so-called SIM cards, for electronic signature services in mobile telephony.
[0002] Electronic signature is electronic data that confirms the authenticity and integrity of electronic information, mainly an electronic document. To this end, the electronic signature should guarantee the identity of the signer. These features should also be verifiable by means of an electronic signature. Thanks to these features, an electronic signature should be the electronic equivalent of a handwritten signature. These desired properties of the electronic signature are obtained in accordance with the signature technology used, the existing application scenario, as well as the applicable legal provisions.
[0003] The electronic signature is mainly based on asymmetric cryptographic methods. A known public key, the so-called "public key" of the signer, allows you to check his signature, which is created using his secret key, the so-called "private key". However, unlike qualified signatures, in the case of advanced signatures, the secret and public key need not be assigned to the signer. Thus, although the authenticity and integrity of the signed data can be checked, it is not possible to identify the signer with a certificate. In this case, for example, biometric methods, such as a handwritten signature, which can be obtained when signing and is introduced into the identification, can contribute to identification.
-3dokumentu. To secure biometric data, it is additionally entered into the hash value (checksum). When checking the signature, in addition to the signed data, the authenticity and integrity of the identification markings are also checked.
[0004] To identify the signer and unlock the signature service, for example, a secret number (PIN) is used. The PIN is generated by the service provider, then it is uniquely assigned to the (personalized) user and, along with the signature key, is sent via communication, for example, in a letter to the user. In this method, there is a risk that by tracing the signature data and PIN number, the third party may use the data in an undesirable way and pretend to be the signer. In addition, basically by generating a PIN, some costs arise.
[0005] Document US 2002/00 42879 A1 describes an electronic signature system in which an intelligent electronic signature card is used, with which information can be exchanged between the user of the intelligent electronic signature card and the signature portal. The signature data is saved on the smart electronic signature card. The user may, by providing a secret number (PIN) or biometric data, confirm his identity with respect to the smart electronic signature card. If the identity has been successfully confirmed, the smart electronic signature card generates an authorization key, which is sent to the signature portal, which then issues the electronic signature and the authentication number.
[0006] Document US 200210023217 A1 describes a method of making electronic devices for producing digital signatures. In a safe environment
- a pair of asymmetric keys is produced, which is, along with other information, stored in an electronic device.
[0007] A method of preparing a smart card for electronic signature services is not given in the prior art described above.
[0008] The object of the invention is to provide a method of preparing a smart card for an electronic signature service that is simple to implement and offers good security against burglary.
[0009] This task is accomplished by a method with the features set out in claim 1.
[0010] According to the invention, a method has been proposed in which information is exchanged between a smart card user and a signature portal, where the asymmetric key pair and the signature PIN assigned to the pair of asymmetric keys are generated directly on the smart card by means of a software application that is executed in the smart card.
[0011] Thus, a simple method of preparing a smart card application for signature services is provided. The smart card application generates a pair of asymmetric keys inside the card, i.e. one public key and one secret key as well as the signature PIN and sends the public key to the signature portal for registration. User identification, for example, a mobile number and a so-called token, for example, a random number, are used to identify and authenticate the user against the signature portal or smart card. The method according to the invention is distinguished, inter alia, in that
A -5PIN signature is generated inside the smart card then it is delivered to the user. Costly personalization of the user is thus avoided; - is not forwarding the number
The PIN needed a special device to implement the method: all cell phones adapted to the SIM-Application-Toolkit are sufficient.
[0012] The signature portal may then allow transactions to be signed from the smart card. Therefore, the certificate is no longer necessary.
[0013] An advantage of the invention is that the personalized and relatively expensive personalization of the PIN number of the signature in the signature portal and the transfer to the user is avoided. Because you avoid generating the signature PIN by the next page and passing the signature PIN to the user, the risk of tracking and unwanted use of this data is reduced. Another advantage is that the signature PIN is provided to the user from the smart card and hence the "secure / random" signature PIN is automatically selected.
[0014] Preferred embodiments and extensions of the invention are set out in the dependent claims.
[0015] Based on Figure 1, the simplified course of the method according to the invention will now be explained.
[0016] According to the invention, a signature portal 10 is established that coordinates the performance of electronic signature services and registers and manages users who want to use electronic signature services. Users who want to use the electronic signature service must have an electronic card
- Smart 11, in which the appropriate software application is installed, used to prepare and perform services related to electronic signature. To enter data into and output data from a smart card 11, you need a terminal 12 that can read data from a smart card and can write data to a smart card, and has data entry and exit devices such as a keyboard and display. In addition, communication means are needed by which terminal 12 and the smart card 11 cooperating with the terminal can communicate with the signature server 10. In a preferred case, a modern mobile phone can be used as terminal 12 because it has the appropriate input and output devices and a relatively strong data processing unit. In addition, the mobile phone can be directly used as a means of communication to create a communication connection between the smart card 11 and the signature portal 10. However, it can also serve as a terminal, for example, a personal computer that is connected to the signature portal via the Internet. The following example describes the use of a mobile phone as a terminal. It has been assumed that the user is at the same time a subscriber to the mobile telephony network in which the terminal can be registered.
Step 1 [0017] The user who has already signed using is known in the portal of his terminal 12 to connect to the signature portal 10 in which he logs in using the user identifier.
depending on the user identification used, it is transmitted
-7 by the user, if the signature portal cannot obtain it automatically. For example, you can use the user's mobile number, which is automatically sent to the signature portal (CLIP function) as the user designation. As soon as the user connects to the signature portal 10, he activates the function of generating a new key pair in smart card 11 in the signature portal 10.
Stage 2:
[0018] The signature portal 10 produces a token for this purpose, e.g. a long number in the form of a random number, and stores it in an appropriate user-assigned data set. The token is then sent to the user in another way, e.g. in a letter.
Stage 3:
[0019] The user confirms receipt of the token, for example, by his own signature.
Stage 4:
[0020] In the smart card 11 a corresponding software application 11a is installed, which can now be started by the user. The user can do it e.g. after receiving a short message (SMS) from the signature portal (trigger), or it can be done automatically, using OTA-SMS.
-8 Stage 5:
[0021] The software application 11a requests the user to enter the received token, e.g. by using the active UICC "GET INPUT" command. The user enters the token using the terminal keyboard 12. The software application 11a generates a new pair of asymmetric keys. The existing key pair, if any, is deleted, e.g. when the user wants to renew a key pair or the associated PIN number of the signature.
Stage 6:
[0022] The software application 11a generates a signature PIN using a token and communicates it to the user on the display of terminal 12, e.g. using the active UICC "DISPLAY TEXT" command. Thanks to this, the signature PIN, apart from smart card 11, is known only to the user and is chosen randomly.
Stage 7:
[0023] The software application 11a registers the public key in the signature portal 10. In addition, the application, created with the help of a newly generated secret (private) key, creates a signature for the data structure, which contains at least the public key and token, as well as, in a given case, user identification. The signature and public key, as well as the user identification in this case, are sent by the software applications 11a to the signature portal 10. The transfer can be done via SMS of the mobile network. If this data is sent via SMS, phone number
-9 can be used as user identification, because in SMS transmission the sender's number is automatically provided to the recipient (here: to the portal 10 signature). Thus, the signature portal 10 can uniquely assign an SMS to the user.
[0024] The signature portal 10, which has generated the token and therefore knows it, verifies the signature and authenticates the user. The signature serves the portal 10 signature as an indication that the user has a private key associated with it.
[0025] The signature for the data structure, which includes the token, authenticates the user against the signature portal. Hacking is the more difficult the more digits the token contains. In addition, the signature portal can enter the user's fingerprint in the public key, which also the software application 11a on the smart card 11 can calculate and show, and which the user verifies himself and in this case must confirm the signature in the portal 10. [0026] If the user has forgotten his signature PIN, he can restart the described procedure at any time to generate a new key pair and the assigned signature PIN. In this case, the existing key pair in the signature portal must be deleted. The smart card application also deletes the existing key pair and re-generates both the key and the PIN.
53 / 57P28022PL00
10 members in 7 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 102005062307 | Germany | A | |
| 102005062307 | Germany | A | |
| 06829408 | European Patent Office (EPO) | A | |
| 2006011796 | European Patent Office (EPO) | W | |
| 2006011796 | European Patent Office (EPO) | W | |
| DE20051062307 | – | – | – |
| EP20060829408 | – | – | – |
| WO2006EP11796 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| DE102005062307A1 | Germany | A1 | |
| WO2007073842A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1964042A1 | European Patent Office (EPO) | A1 | |
| US2009077382A1 | United States of America | A1 | |
| EP1964042B1 | European Patent Office (EPO) | B1 | |
| ATE496352T1 | Austria | T1 | |
| DE502006008781D1 | Germany | D1 | |
| ES2359881T3 | Spain | T3 | |
| PL1964042T3This record | Poland | T3 | |
| US8601270B2 | United States of America | B2 |
Numbers
- Publication, DOCDB
- 1964042
- Publication, EPODOC
- PL1964042T
- Application
- 829408
- Application, DOCDB
- 06829408
- Application, EPODOC
- PL20060829408T
Titles2
- English
- METHOD FOR THE PREPARATION OF A CHIP CARD FOR ELECTRONIC SIGNATURE SERVICES
- Polish
- Sposób przygotowania karty inteligentnej dla usług podpisu elektronicznego
Classification
- CPC, 4
- G07F7/1008
- G06Q20/341
- G06Q20/40975
- G07F7/1016
- IPC, 5
- G06Q20 00
- G06F7 00
- G06Q20 34
- G06Q20 40
- H04L9 32