Method for authenticating access to a secured chip by a test device
Abstract
This record has no abstract on file.
Term
3.6 yearsto projected expiry
Projected expiry 11 May 2030, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
1 claim: 1 independent, 0 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A secure integrated circuit (SC) access authentication method used by the testing device (TD), wherein the testing device stores at least one common key (CK) and one test key (TK), and the protected integrated circuit (SC) stores the same ordinary key (CK) and the abbreviation F (TK) of reference resulting from the cryptographic function on the test key (TK), the method comprising the following steps:1. Sposób uwierzytelniania dostępu do zabezpieczonego układu scalonego (SC) stosowany przez testujące urządzenie (TD), przy czym to testujące urządzenie przechowuje co najmniej jeden zwykły klucz (CK) i jeden testowy klucz (TK), a zabezpieczony układ scalony (SC) przechowuje ten sam zwykły klucz (CK) i skrót F(TK) odniesienia wynikające z funkcji kryptograficznej na testowym kluczu (TK), przy czym sposób ten obejmuje następujące etapy: - odebranie przez testujące urządzenie (TD) wywołania (R) wytworzonego przez zabezpieczony układ scalony (SC), - receiving by the testing device (TD) the call (R) generated by the protected integrated circuit (SC), - connecting the received call by the testing device (TD) - łączenie przez testujące urządzenie (TD) odebranego wywołania - sending the CK ciphertext (TK op R) to the protected integrated circuit (SC), - wysłanie szyfrogramu CK(TK op R) do zabezpieczonego układu scalonego (SC), - decryption by the secured integrated circuit (SC) of the CK ciphertext (TK op R) with a common key (CK) to obtain the mapped key (TK ') representing the test key (TK) by using with call (R) operations (op-1) inverse to the mathematical operation (op) previously used by the test device (TD), - deszyfrowanie przez zabezpieczony układ scalony (SC) szyfrogramu CK(TK op R) za pomocą zwykłego klucza (CK), aby otrzymać odwzorowany klucz (TK') reprezentujący testowy klucz (TK) przez zastosowanie z wywołaniem (R) operacji (op-1) odwrotnej w stosunku do matematycznej operacji (op) poprzednio wykorzystanej przez testowe urządzenie (TD), - calculation of the expected F (TK ') hashed key (TK') using a one-way cryptographic function, - obliczanie oczekiwanego skrótu F(TK') odwzorowanego klucza (TK') za pomocą jednokierunkowej funkcji kryptograficznej, - sprawdzenie ważności przez porównanie oczekiwanego skrótu F(TK') ze skrótem F(TK) odniesienia, - validity check by comparing the expected F (TK ') hash with the F (TK) reference, 1411-PAT-EP-PL PAT-1411-EP-E - 18 EP2430583 - EP2430583 - providing a secured integrated circuit in the testing mode (TD) in testing mode, if the result of the comparison between the abbreviation F (TK ') of the mapped key (TK') and the abbreviation F (TK) is positive. - udostępnienie poprzez testujące urządzenie (TD) zabezpieczonego układu scalonego w trybie testowania, jeżeli wynik porównania pomiędzy skrótem F(TK') odwzorowanego klucza (TK') a skrótem F(TK) odniesienia jest pozytywny. 2. The method according to claim The method of claim 1, wherein the expected hash is obtained by applying a hash function (F) to the mapped key (TK '). 2. Sposób według zastrz. 1, znamienny tym, że oczekiwany skrót otrzymywany jest przez zastosowanie mieszającej funkcji (F) wobec odwzorowanego klucza (TK'). 3. The method according to claim The method of claim 1, wherein the abbreviation F (TK) of the reference contains an unencrypted data set (PD) and an encrypted data set (CD), the mapped key (TK ') being used as the key to the cryptographic module (CM) in which the unencrypted set data (PD) is used to obtain the result set (CD ') of encrypted mapped data, and further, a comparison is made between the set (CD) of encrypted mapped F reference data (TK) and the set (CD ') of encrypted mapped data calculated. 3. Sposób według zastrz. 1, znamienny tym, że skrót F(TK) odniesienia zawiera nieszyfrowany zbiór danych (PD) i szyfrowany zbiór (CD) danych, przy czym odwzorowany klucz (TK') wykorzystywany jest jako klucz do kryptograficznego modułu (CM), w którym nieszyfrowany zbiór danych (PD) jest wykorzystywany w celu uzyskania wynikowego zbioru (CD') zaszyfrowanych odwzorowanych danych, a ponadto przeprowadzane jest porównanie pomiędzy zbiorem (CD) zaszyfrowanych odwzorowanych danych skrótu F(TK) odniesienia a zbiorem (CD') obliczonych zaszyfrowanych odwzorowanych danych . 4. The method according to claim The process of claim 1, wherein the receiving (R) call by the testing device is carried out as follows: 4. Sposób według zastrz. 1, znamienny tym, że odbieranie wywołania (R) przez urządzenie testujące przeprowadzane jest następująco: - przez testujące urządzenie (TD) wysyłane jest żądanie (RQ) uwierzytelnienia do zabezpieczonego układu scalonego (SC), który zwraca wywołanie (R) do testującego urządzenia (TD) przy odebraniu wymienionego żądania (RQ). - the authentication request (RQ) is sent by the testing device (TD) to the secured integrated circuit (SC), which returns the call (R) to the testing device (TD) when said request (RQ) is received. 1411-PAT-EP-PL PAT-1411-EP-E - 19 EP2430583 - 19 EP2430583 5. The method according to any of claims 1 to 4, characterized in that the secure integrated circuit (SC) returns a response message (M) indicating to the testing device (TD) the result of the comparison between the F (TK ') key (TK') of the mapping and the F (TK) reference abbreviation. 5. Sposób według któregokolwiek z zastrz. od 1 do 4, znamienny tym, że bezpieczny układ scalony (SC) zwraca komunikat (M) odpowiedzi wskazujący testującemu urządzeniu (TD) wynik porównania pomiędzy skrótem F(TK') klucza (TK') odwzorowania a skrótem odniesienia F(TK). 6. The method according to any of claims 1 to 5, characterized in that the call (R) is generated by a protected integrated circuit (SC) by a hardware pseudo-random number generator or by an algorithm implemented in a stored program of memory. 6. Sposób według któregokolwiek z zastrz. od 1 do 5, znamienny tym, że wywołanie (R) jest wytwarzane przez zabezpieczony układ scalony (SC) poprzez sprzętowy generator liczb pseudoprzypadkowych albo przez algorytm realizowany w zapisanym w pamięci programie wytwarzania. 7. The method according to any of claims 1 to 5, characterized in that the call (R) is carried out by a meter that performs increasing or decreasing from a given initial value each time the test device (TD) is connected to a protected integrated circuit (SC) or every test request sent to said protected integrated circuit (SC). 7. Sposób według któregokolwiek z zastrz. od 1 do 5, znamienny tym, że wywołanie (R) przeprowadzane jest przez licznik, który przeprowadza zwiększanie lub zmniejszanie od danej wartości początkowej przy każdym połączeniu testującego urządzenia (TD) z zabezpieczonym układem scalonym (SC) lub przy każdym żądaniu testowania wysyłanym do wymienionego zabezpieczonego układu scalonego (SC). 8. The method according to any of claims from 1 to 7, characterized in that the call (R) contains a time stamp with the current date and time given with specified accuracy. 8. Sposób według któregokolwiek z zastrz. od 1 do 7, znamienny tym, że wywołanie (R) zawiera pieczęć czasową z aktualną datą i godziną podanymi z określoną dokładnością. 9. The method according to any of claims 1 to 8, characterized in that the testing device (TD) and the protected integrated circuit (SC) store many common keys (CK) in memory. 9. Sposób według któregokolwiek z zastrz. od 1 do 8, znamienny tym, że testujące urządzenie (TD) i zabezpieczony układ scalony (SC) przechowują w pamięci wiele zwykłych kluczy (CK). 1411-PAT-EP-PL PAT-1411-EP-E - 20 EP2430583 - EP2430583 10. The method according to any of claims from 1 to 9, characterized in that the testing device (TD) stores multiple testing keys (TK) in memory, and the secured integrated circuit (SC) stores many F (TK) abbreviations in memory, each of which is calculated using the appropriate test key (TK) stored in the testing device (TD). 10. Sposób według któregokolwiek z zastrz. od 1 do 9, znamienny tym, że testujące urządzenie (TD) przechowuje w pamięci wiele testujących kluczy (TK), a ponadto zabezpieczony układ scalony (SC) przechowuje w pamięci wiele skrótów F(TK), z których każdy jest obliczony przy użyciu odpowiedniego testowego klucza (TK) zapisanego w testującym urządzeniu (TD). 11. The method according to claim 9 - 10, characterized in that the ordinary key (CK) stored in the testing device (TD) and in the protected integrated circuit (SC) and each test key (TK) stored in the testing device (TD) and also the corresponding abbreviations F (TK) saved the secured integrated circuit (SC) is accompanied by an index (I, J) for selecting a specific test key (TK), common key (CK) and hash F (TK) during the authentication process. 11. Sposób według zastrz. 9 - 10, znamienny tym, że zwykłemu kluczowi (CK) zapisanemu w testującym urządzeniu (TD) i w zabezpieczonym układzie scalonym (SC) oraz każdemu testowemu kluczowi (TK) zapisanemu w testującym urządzeniu (TD) i ponadto odpowiednim skrótom F(TK) zapisanym w zabezpieczonym układzie scalonym (SC) towarzyszy indeks (I, J) do wybierania specyficznego testowego klucza (TK), zwykłego klucza (CK) i skrótu F(TK) podczas procesu uwierzytelnienia. 12. The method according to claim 11, characterized in that the CK ciphertext (TK op R) sent by the testing device (TD) to the protected integrated circuit (SC) is accompanied by the index (I, J) of the corresponding test and the common key (TK, CK) used in the said CK ciphertext ( TK op R). 12. Sposób według zastrz. 11, znamienny tym, że szyfrogramowi CK(TK op R) wysłanemu przez testujące urządzenie (TD) do zabezpieczonego układu scalonego (SC) towarzyszą indeks (I, J) odpowiedniego testu i zwykły klucz (TK, CK) wykorzystywany w wymienionym szyfrogramie CK(TK op R). 13. The method according to claim 11, characterized in that the protected integrated circuit (SC) selects the received index (J) to designate the ordinary key (CK) to be used when decrypting the CK ciphertext (TK op R) and the index (I) of the abbreviation F (TK ), which is used to check the validity of the test key (TK) determined from the CK ciphertext (TK op R). 13. Sposób według zastrz. 11, znamienny tym, że zabezpieczony układ scalony (SC) wybiera odebrany indeks (J) w celu oznaczenia nim zwykłego klucza (CK), który ma być używany przy deszyfrowaniu szyfrogramu CK(TK op R) oraz indeks (I) skrótu F(TK), który służy do sprawdzenia ważności testowego klucza (TK) wyznaczonego z szyfrogramu CK(TK op R). 1411-PAT-EP-PL PAT-1411-EP-E - 21 EP2430583 - EP2430583 14. The method according to claim 12, characterized in that the index (I) of the test key (TK) used in the CKj ciphertext (TKi op R) is encrypted using a common key (CK) corresponding to the index (J) sent with the CK ciphertext (TK op R). 14. Sposób według zastrz. 12, znamienny tym, że indeks (I) testowego klucza (TK) stosowanego w szyfrogramie CKj(TKi op R) jest szyfrowany przy użyciu zwykłego klucza (CK) odpowiadającego indeksowi (J) wysyłanemu z szyfrogramem CK(TK op R). 15. The method according to claim 14. A method according to claim 14, characterized in that the protected integrated circuit (SC) decrypts the index (I) of the test key (TK) using the common key (CK) determined by the index (J) accompanying the CK cryptogram (TK op R), said decrypted index ( I) is used to select the appropriate shortcut F (TK) to check the validity of the test key (TK) specified from the CK ciphertext (TK op R). 15. Sposób według zastrz. 14, znamienny tym, że zabezpieczony układ scalony (SC) deszyfruje indeks (I) testowego klucza (TK) przy użyciu zwykłego klucza (CK) wyznaczonego przez indeks (J) towarzyszący kryptogramowi CK (TK op R), przy czym wymieniony odszyfrowany indeks (I) jest wykorzystywany do wybierania odpowiedniego skrótu F(TK) w celu sprawdzenia ważności testowego klucza (TK) określonego z szyfrogramu CK(TK op R). 1411-PAT-EP-PL PAT-1411-EP-E - 22 EP2430583 - EP2430583 1411-PAT-EP-PL PAT-1411-EP-E - 23 EP2430583 - EP2430583
76 paragraphs in 19 sections, as filed
[0001] The invention of this protected testing circuit by operations on integrated data.
refers to the field of integrated access protection, especially with the device preventing unauthorized storage of such a system
Background Art [0002] Protected integrated circuits are generally used in the production of magnetic cards, security modules, identification devices and other integrated circuits used in applications requiring a high level of security.
[0003] Secure access to the device or to the remote device may be authorized using preferably a one-time password entered into the terminal device in response to a call sent by the device or remote unit. For example, publication W02005125078 describes a method of secure communication between the control panel and at least one dependent device, including: creating an initial secret item and storing it in the control panel; creating a set of one-time passwords, each of which is associated with a certain index; storing a subset of this one-time password collection at the dependent station; sending a call from the control panel to the dependent station, the said call being an item in the mentioned subset belonging to the set of one-time passwords and sending from the dependent station to the control panel a one-time password related to this index.
PAT-1411-EP-E
EP2430583 [0004] Publication EP1392052 describes methods of controlling access to device functions including the steps of receiving a request to access the device properties; determining whether this property is disabled; determining whether this property can be enabled through authorization; determining whether the requester is authorized to enable such device property. When all these conditions are met by the device and the requester, such a property can be activated. Authorization can be obtained by generating the call value by the device, remembering the call value, sending this value to the requester, encrypting the call value by the requester, sending the encrypted call value back to the device, decrypting the encrypted call value by the device and comparing the stored call value with the decrypted call value . If these two invocation values are the same, authorization is given to enable the property.
[0005] EP1441313 relates to an asymmetric cryptographic method for protecting a hardware-connected electronic logic integrated circuit against fraud in transactions between an electronic logic integrated circuit and an application program comprising calculating values based on an integrated circuit.
the following steps: the integrated circuit generating a random transaction-specific number; sending to the application program the first parameter calculated by this application program before the transaction, associated with a random number by some mathematical relationship and stored in the input parameters memory. This method includes electronic identification
PAT-1411-EP-E
- EP2430583 integrated circuit data; the IC's calculation of the second parameter of the identification value by means of a serial function whose input parameters are at least a transaction-specific random number, and a secret key belonging to an pair of asymmetric keys; sending this identification value to the application program and verification of the said identification value by means of a verification function whose input parameters are composed solely of public parameters including at least one public key.
[0006] EP1983466 describes a method and apparatus for reliable identification for an integrated circuit (SoC) system. This system on an integrated circuit can identify an external object attempting to access a function or system. Such an integrated system and identified external object may also know hidden data before attempting the identification process and may also send data during the identification process. Using similar data, the system on the integrated circuit and the external unit may be able to generate the same password and gain access to the system. The uniqueness of passwords can be ensured in two ways. For example, by operation and by a device with a system on integrated circuits. A system on an integrated circuit having its own random number generator may allow changing passwords for each iteration of the identification process. Whenever a system on an integrated circuit has its own secret word, passwords can be unique for each device.
[0007] In addition, several secure identification methods are described in Chapter 10: Identifying and Checking the Identity of an Entity
PAT-1411-EP-E
EP2430583 (Identification and Entity Authentication) in the Handbook of Applied Cryptography; ed .; Menezes A, Oorschot van P; Vanstone S.
[0008] The security of prior art access authentication methods may be compromised either by reverse engineering techniques, or by obtaining the keys of a protected integrated circuit, or by eavesdropping on the communication between the accessing device and the integrated circuit. In fact, several known attacks, such as violent force attacks, signal analysis, physical chip examination, etc., allow you to discover encryption keys and deduce call signals or other parameters used to create one-time passwords.
In some other cases, the device identity verification process produces data sets sent from the device to the integrated circuit and vice versa, which can reveal important security parameters if captured and analyzed using third party devices.
SUMMARY OF THE INVENTION [0009] The object of the invention is to grant access to a protected integrated circuit by a testing device with a maximum level of security using a fast, efficient and attack-proof process. For example, obtaining a key from a testing device or from an integrated circuit does not provide sufficient results in accessing the integrated circuit. In addition, data sets captured during authorization will not reveal any key or cryptogram
PAT-1411-EP-E
- EP2430583 suitable for use in simulating authorization for access to an integrated circuit.
[0010] This object is achieved by a method of authenticating access to a secured integrated circuit used by a testing device that stores at least one common key and one test key, the same integrated key and reference abbreviation resulting from use being stored in the protected integrated circuit. cryptographic function against the test key, the method comprising the following steps:
- the receiving device receiving calls made by a protected integrated circuit,
- connecting this test device to the received call with the test key by using a two-way mathematical operation, encrypting the result with a simple key and obtaining a cryptogram;
- sending this cryptogram to a secured integrated circuit,
- decryption by the cryptogram secured integrated circuit with a simple key, obtaining a mapped key representing the test key by applying by calling the reverse operation to the mathematical operation previously used by the testing device,
- calculating the expected hash of a mapped key using a one-way cryptographic function,
- checking validity by comparing the expected hash with the reference abbreviation;
- provision by the testing device of a safe integrated circuit in testing mode if the result of the comparison between
PAT-1411-EP-E
- EP2430583 hash of the mapped key and the reference hash is positive.
[0011] Before being placed on the market or for maintenance, the various functionalities of such a protected integrated circuit are checked by means of a testing device that accesses the integrated circuit in a secure manner. After the testing device has been authorized by the integrated circuit, i.e. after successfully checking the exchange of control data between the testing device and the integrated circuit, various functional tests or simulations are carried out regarding the functions of the hardware and software and / or programs installed in the integrated circuit. The testing device may also include integrated circuit configuration and customization functionalities to enable, disable or program various properties as required by the application programs provided for the integrated circuit.
[0012] The subject of the invention is a method of protection against invasive attack on an integrated circuit or against such attack as wiretapping, but not against both attacks connected together.
[0013] An invasive attack is a physical attack on an integrated circuit that causes destruction and leaves detectable traces. Such an attack allows access to signals inside the integrated circuit with data output using reverse engineering, observation through a microscope and the use of tools such as cutters or laser drills, needles and electron beam probe.
[0014] Eavesdropping is a non-destructive data mining technique that gives unauthorized access to data not necessarily when sending data to devices
PAT-1411-EP-E
- 7 EP2430583 external. This technique may also include observing data changes by remotely monitoring the operation of the computer, for example over a network.
[0015] According to a preferred embodiment, the advantage of this method is the minimization of data transfer between the testing device and the protected integrated circuit. In response to a call from the integrated circuit, the testing device sends a cryptogram that will be analyzed and checked by the integrated circuit before allowing the testing device to perform tests on that integrated circuit. [0016] The call may be generated accidentally by devices based on a generator integrated in the integrated circuit. In one embodiment, the integrated circuit may store a disposable call list. In another embodiment, the call may be in the form of a number used only once or generated once by uniformly increasing or decreasing the counter from a predetermined value.
[0017] Interception of the call and / or ciphertext by a third party device will not allow to find the test key necessary for verification by comparison with the hash stored in the integrated circuit assuming that a one-way function is known. Indeed, the cryptogram obtained by encrypting the message with a test key requires knowledge of the general key, the test key requires knowledge of the general key, test key and two-way operation or mathematical function and its inverse, respectively.
PAT-1411-EP-E
[0018] If a common key can be obtained by interfering with the protected integrated circuit, reproduction of the ciphertext will be rather difficult, since it requires knowledge of the test key. Unlike a regular key, the test key is not stored in the non-volatile memory of the protected integrated circuit.
Brief Description of the Drawings [0019] The invention will be better understood from the following detailed description, which refers to the accompanying drawings, which illustrate non-limiting examples.
Fig. 1 is a block diagram of a testing device attached to a protected integrated circuit with its respective stored keys, abbreviations and functions. The cryptogram sent by the testing device in response to the received call allows access to the secured integrated circuit.
Fig. 2 shows the block diagram of Fig. 1 with additional data flowing between the testing device and the protected integrated circuit in the form of a test request message and a response message.
Fig. 3 shows the block diagram of Fig. 1 containing additional test and common keys, each of which has its own index.
Fig. 4 is a block diagram of the hash calculation process using a mapped test key encrypting a standard reference data set, the resulting set
PAT-1411-EP-E
EP2430583 mapped encryption data is compared to a set of reference encryption data.
Detailed description of the invention [0020] The testing TD device shown in Fig. 1 stores in non-volatile memory identification data including a TK test key, a common CK key and a program suitable for combining input data with a test TK key. This program includes a two-way (inverse) and bi-directional mathematical operation or op function for use with an R call received by a testing TD device from an SC protected integrated circuit attached to a testing TD device. A function is bijective, or with one-to-one correspondence, if it is both injective (no two values are associated with the same value) and surjective (for each element of the mapped domain there is some element of the initial domain that is associated with it). In other words, there is exactly one element of the initial domain that is associated with each element of the mapped domain.
[0021] The protected integrated circuit SC stores in non-volatile memory:
- regular CK key,
- the F (TK) abbreviation of the TK test key obtained using the cryptographic one-way F function,
- and a program suitable for use with the inverse of op-<sup>1</sup> operation or op function contained in the program saved in the test device (TD).
PAT-1411-EP-E
EP2430583 [0022] Such data was, among others, entered into the protected integrated circuit during the personalization steps at the end of its manufacture. The TD test device is then adapted to the integrated circuits available for testing that contains all the data needed to identify with integrated circuits.
[0023] The abbreviation can be defined as the result obtained by calculation by means of a cryptographic function applied to the data set using the key, i.e. the test TK key. In addition, the protected integrated circuit preferably includes a random generator for generating an R call to be sent to the TD test device, and means for processing the ciphertext received from the test device to perform the verification necessary for authenticating the test device. Authentication means that only the test device, thanks to the necessary keys and programs, is authorized to access the secured integrated circuit. Others having compatible data excluded and not capable of non-identifying devices are carrying out tests.
[0024] In the first step (1), the testing device TD receives an R call from the secured IC, which is attached to the TK test key due to the op operation carried out by the stored program. The result (TK op R) thus obtained is encrypted using a common CK key to produce the CK ciphertext (TK op R). In the second stage (2), the testing TD device sends the CK ciphertext (TK op R) to the protected SC chip for processing.
PAT-1411-EP-E
A protected SC chip decrypts this CK ciphertext (TK op R) using a regular CK key and obtains the result of the TK op R. op-<sup>1</sup> used with the R call to the TK op R result to get the TK mapping of the test key:
TK op R op-<sup>1</sup> R gives TK op I = TK, where I is an identification element or a neutral element for op and op-<sup>1</sup>. [0026] In another example, this operation may consist of adding the R call to the TK test key, and the result after inversion will be subtracted from the R call to obtain the TK key.
[0027] TK + R - R gives TK + 0 = TK, with 0 being a neutral element of the addition and subtraction operations. Similar reasoning can be performed with multiplication and division operations, where the neutral element is 1.
[0028] In a particular case, the op operation may be an XOR operation whose inverse op<sup>1</sup> is the same XOR operation.
[0029] The test key obtained initially represents the TK mapping of the actual TK test key before performing verification.
[0030] According to a first embodiment, the cryptographic one-way function F, such as the SHA256 hash function, is for example used for the TK 'mapping. The resulting F (TK ') hash is compared to the saved F (TK) hash previously calculated using the same unidirectional F-type hash function when personalizing the protected integrated circuit. When the compared values of the stored F (TK) hash and F (TK ') hash are the same, the test key
PAT-1411-EP-E
- EP2430583
The CT is valid and the TD testing device is treated as authorized by the protected integrated circuit, as a result of which access for testing purposes is allowed.
[0031] According to a second embodiment, the abbreviation F (TK) of the reference stored in the secured integrated circuit comprises the PD file of unencrypted data and the CD file of encrypted data. The TK 'mapping key is used as the key in the CM cryptographic module in which the PD unencrypted data set is used to obtain the CD' mapped encrypted data set. A comparison is then made between the CD set of reference encrypted data and the abbreviation F (TK) of the reference and the calculated set of CD 'mapped encrypted data, as schematically shown in Fig. 4.
[0032] Hereinafter, the abbreviation may be of any type, as mentioned in the two previous embodiments. [0033] According to the embodiment shown in Fig. 2 the method of the invention may include the initial step (1) of sending a request (RQ) for the authentication of the SC integrated circuit. After the RQ receives a request for the integrated chip, it sends a R request to the testing TD device in step (2) and receives the CK ciphertext (TK op R ) from the testing device TD in step (3).
[0034] Optionally, a response M message may be sent back in step (4) to the testing TD device after the secured SC chip has verified the CK ciphertext verification (TK op R). The message M indicates whether the identification was carried out successfully or not, i.e. whether the values of the compared abbreviations are the same F (TK ') = F (TK) or
PAT-1411-EP-E
EP2430583 also different F (TK ') / F (TK). In the latter case, access to the protected integrated circuit is blocked and, according to the example, a limited number of further identification attempts can be made before the integrated circuit is completely turned off.
[0035] This method may include one or two additional steps (1) or (4) of Fig. 2.
[0036] The R call created by the protected integrated circuit can be generated by the hardware pseudo-random number generator or by the algorithm installed in the saved generation program.
[0037] In a further embodiment, this call can be made by a counter that increases or decreases starting from a given initial value each time the test device is connected to a protected integrated circuit or each test request sent to said protected integrated circuit.
[0038] In a further embodiment, the call may include a time stamp with the current date and clock time, given with a specified accuracy (1 second, 100 milliseconds, 10 ms, 1 ms, etc.).
[0039] A combination of two or more previous embodiments may also be possible to generate a call.
[0040] It should be noted that the test keys and / or common keys (TK, CK) used according to this method can be symmetrical or asymmetrical.
[0041] In another embodiment, the test key may be derived from the unique identifier of the testing device
PAT-1411-EP-E
- EP2430583
TD, while the ordinary key may be derived from the unique identifier of the protected SC chip.
[0042] In a further embodiment, the testing device and the protected integrated circuit store a plurality of common keys. The testing device can also store multiple test keys, and the protected integrated circuit stores many hashes, each of which is calculated using the appropriate test key stored in the testing device.
[0043] Preferably, each test and ordinary key may be rewritten a certain index to prevent systematic attempting of all stored keys to decrypt and check operations with a hash. Such attempts could undesirably slow down the authentication process, especially when the keys and abbreviations are numeric.
[0044] The index may be a register character or memory address indicating where the common key and test key are stored. Such an index can also be a key class number in a set of keys stored in non-volatile memory. The testing device determines whether to select the index automatically or in the order specified by the program or based on the commands entered by the user.
[0045] Fig. 3 shows an embodiment where the testing TD device stores three test keys (TK1, TK2, TK3) and two common keys (CK1, CK2). Test keys and common keys are preferably associated each with an appropriate index (11, 12, 13), (J1, J2) used to designate the specific key to be selected for processing authentication.
PAT-1411-EP-E
The protected integrated circuit SC stores three hashes of the test keys F (TK1), F (TK2) and F (TK3) with the indexes (I1, I2, I3) assigned to the respective test keys. Common keys (CK1, CK2) are also stored with their index (J1, J2) as in the test TD device.
[0047] The CK1 (TK3 op R) ciphertext sent from the testing device in response to a received R call is accompanied by an index (I, J) of the keys used in it. In the example of Fig. 3, the CK1 ciphertext (TK3 op R) is sent with index 13 for the test key TK3 and index J1 for the ordinary key CK1.
[0048] When the CK1 ciphertext (TK3 op R) is received by the SC protected chip, the index J1 is read first to select the correct CK1 common key to use when decrypting the CK1 ciphertext (TK3 op R). After receiving the TK3 test key when using the reverse operation op-<sup>1</sup> and calculating the mapping hash F (TK3 ') the protected integrated circuit selects the stored reference hash F (TK3) determined by the received index I3. Then a comparison is made between the mapping and the reference F (TK3 ') F (TK3) corresponding to the third TK3 test key to grant access to the protected SC chip by the testing TD device if the values of both hashes are equal.
[0049] It should be noted that the keys and the corresponding abbreviation may be stored in any number in the testing device and in the protected integrated circuit.
[0050] According to an embodiment, the index of the I TK test key transmitted with the CK1 ciphertext (TK3 op R) can be encrypted with
PAT-1411-EP-E
EP2430583 using a regular CK key that encrypts the TK op R result obtained using the op operation with an R call on the TK test key.
[0051] In this example, the data transmitted by the testing TD device will therefore be: cipher program CK1 (TK3 op R), CK1 (I3), J1, where CK1 (I3) is the index of the test key TK3 encrypted using the ordinary key CK1. Upon receipt, the test device decrypts the I3 index using a standard CK1 key marked with the J1 index. After decrypting the CK1 ciphertext (TK3 op R) using a regular CK1 key and after specifying the TK3 test key, the previous decrypted I3 index is then used to select the appropriate F (TK3) hash to check the validity of the TK3 test key.
PAT-1411-EP-E
- EP2430583
Contents19
20 members in 12 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 09160096 | European Patent Office (EPO) | A | |
| 09160096 | European Patent Office (EPO) | A | |
| 10721754 | European Patent Office (EPO) | A | |
| 2010056409 | European Patent Office (EPO) | W | |
| 2010056409 | European Patent Office (EPO) | W | |
| EP20090160096 | – | – | – |
| EP20100721754 | – | – | – |
| WO2010EP56409 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| EP2251813A1 | European Patent Office (EPO) | A1 | |
| WO2010130709A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201108027A | Taiwan Province of China | A | |
| EP2430583A1 | European Patent Office (EPO) | A1 | |
| KR20120027215A | Republic of Korea | A | |
| US2012069991A1 | United States of America | A1 | |
| CN102422296A | China | A | |
| JP2012527141A | Japan | A | |
| HK1166528A1 | Hong Kong, China | A1 | |
| EP2430583B1 | European Patent Office (EPO) | B1 | |
| PT2430583E | Portugal | E | |
| ES2403233T3 | Spain | T3 | |
| PL2430583T3This record | Poland | T3 | |
| US8595498B2 | United States of America | B2 | |
| JP5563067B2 | Japan | B2 | |
| CN102422296B | China | B | |
| TWI503688B | Taiwan Province of China | B | |
| KR101659110B1 | Republic of Korea | B1 | |
| BRPI1011378A2 | Brazil | A2 | |
| BRPI1011378B1 | Brazil | B1 |
Numbers
- Publication, DOCDB
- 2430583
- Publication, EPODOC
- PL2430583T
- Application
- 721754
- Application, DOCDB
- 10721754
- Application, EPODOC
- PL20100721754T
Titles2
- English
- Method for authenticating access to a secured chip by a test device
- Polish
- Sposób uwierzytelniania dostępu do zabezpieczonego układu scalonego przez urządzenie testujące
Classification
- CPC, 4
- G06F21/445
- G06F2221/2103
- G06F7/58
- G06F21/60
- IPC, 1
- G06F21 44