PL2430583T3

Method for authenticating access to a secured chip by a test device

Abstract

This record has no abstract on file.

Term

3.6 yearsto projected expiry

Projected expiry 11 May 2030, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

1 claim: 1 independent, 0 dependent

  1. 1
    Patent claims Zastrzeżenia patentowe 1. A secure integrated circuit (SC) access authentication method used by the testing device (TD), wherein the testing device stores at least one common key (CK) and one test key (TK), and the protected integrated circuit (SC) stores the same ordinary key (CK) and the abbreviation F (TK) of reference resulting from the cryptographic function on the test key (TK), the method comprising the following steps:1. Sposób uwierzytelniania dostępu do zabezpieczonego układu scalonego (SC) stosowany przez testujące urządzenie (TD), przy czym to testujące urządzenie przechowuje co najmniej jeden zwykły klucz (CK) i jeden testowy klucz (TK), a zabezpieczony układ scalony (SC) przechowuje ten sam zwykły klucz (CK) i skrót F(TK) odniesienia wynikające z funkcji kryptograficznej na testowym kluczu (TK), przy czym sposób ten obejmuje następujące etapy: - odebranie przez testujące urządzenie (TD) wywołania (R) wytworzonego przez zabezpieczony układ scalony (SC), - receiving by the testing device (TD) the call (R) generated by the protected integrated circuit (SC), - connecting the received call by the testing device (TD) - łączenie przez testujące urządzenie (TD) odebranego wywołania - sending the CK ciphertext (TK op R) to the protected integrated circuit (SC), - wysłanie szyfrogramu CK(TK op R) do zabezpieczonego układu scalonego (SC), - decryption by the secured integrated circuit (SC) of the CK ciphertext (TK op R) with a common key (CK) to obtain the mapped key (TK ') representing the test key (TK) by using with call (R) operations (op-1) inverse to the mathematical operation (op) previously used by the test device (TD), - deszyfrowanie przez zabezpieczony układ scalony (SC) szyfrogramu CK(TK op R) za pomocą zwykłego klucza (CK), aby otrzymać odwzorowany klucz (TK') reprezentujący testowy klucz (TK) przez zastosowanie z wywołaniem (R) operacji (op-1) odwrotnej w stosunku do matematycznej operacji (op) poprzednio wykorzystanej przez testowe urządzenie (TD), - calculation of the expected F (TK ') hashed key (TK') using a one-way cryptographic function, - obliczanie oczekiwanego skrótu F(TK') odwzorowanego klucza (TK') za pomocą jednokierunkowej funkcji kryptograficznej, - sprawdzenie ważności przez porównanie oczekiwanego skrótu F(TK') ze skrótem F(TK) odniesienia, - validity check by comparing the expected F (TK ') hash with the F (TK) reference, 1411-PAT-EP-PL PAT-1411-EP-E - 18 EP2430583 - EP2430583 - providing a secured integrated circuit in the testing mode (TD) in testing mode, if the result of the comparison between the abbreviation F (TK ') of the mapped key (TK') and the abbreviation F (TK) is positive. - udostępnienie poprzez testujące urządzenie (TD) zabezpieczonego układu scalonego w trybie testowania, jeżeli wynik porównania pomiędzy skrótem F(TK') odwzorowanego klucza (TK') a skrótem F(TK) odniesienia jest pozytywny. 2. The method according to claim The method of claim 1, wherein the expected hash is obtained by applying a hash function (F) to the mapped key (TK '). 2. Sposób według zastrz. 1, znamienny tym, że oczekiwany skrót otrzymywany jest przez zastosowanie mieszającej funkcji (F) wobec odwzorowanego klucza (TK'). 3. The method according to claim The method of claim 1, wherein the abbreviation F (TK) of the reference contains an unencrypted data set (PD) and an encrypted data set (CD), the mapped key (TK ') being used as the key to the cryptographic module (CM) in which the unencrypted set data (PD) is used to obtain the result set (CD ') of encrypted mapped data, and further, a comparison is made between the set (CD) of encrypted mapped F reference data (TK) and the set (CD ') of encrypted mapped data calculated. 3. Sposób według zastrz. 1, znamienny tym, że skrót F(TK) odniesienia zawiera nieszyfrowany zbiór danych (PD) i szyfrowany zbiór (CD) danych, przy czym odwzorowany klucz (TK') wykorzystywany jest jako klucz do kryptograficznego modułu (CM), w którym nieszyfrowany zbiór danych (PD) jest wykorzystywany w celu uzyskania wynikowego zbioru (CD') zaszyfrowanych odwzorowanych danych, a ponadto przeprowadzane jest porównanie pomiędzy zbiorem (CD) zaszyfrowanych odwzorowanych danych skrótu F(TK) odniesienia a zbiorem (CD') obliczonych zaszyfrowanych odwzorowanych danych . 4. The method according to claim The process of claim 1, wherein the receiving (R) call by the testing device is carried out as follows: 4. Sposób według zastrz. 1, znamienny tym, że odbieranie wywołania (R) przez urządzenie testujące przeprowadzane jest następująco: - przez testujące urządzenie (TD) wysyłane jest żądanie (RQ) uwierzytelnienia do zabezpieczonego układu scalonego (SC), który zwraca wywołanie (R) do testującego urządzenia (TD) przy odebraniu wymienionego żądania (RQ). - the authentication request (RQ) is sent by the testing device (TD) to the secured integrated circuit (SC), which returns the call (R) to the testing device (TD) when said request (RQ) is received. 1411-PAT-EP-PL PAT-1411-EP-E - 19 EP2430583 - 19 EP2430583 5. The method according to any of claims 1 to 4, characterized in that the secure integrated circuit (SC) returns a response message (M) indicating to the testing device (TD) the result of the comparison between the F (TK ') key (TK') of the mapping and the F (TK) reference abbreviation. 5. Sposób według któregokolwiek z zastrz. od 1 do 4, znamienny tym, że bezpieczny układ scalony (SC) zwraca komunikat (M) odpowiedzi wskazujący testującemu urządzeniu (TD) wynik porównania pomiędzy skrótem F(TK') klucza (TK') odwzorowania a skrótem odniesienia F(TK). 6. The method according to any of claims 1 to 5, characterized in that the call (R) is generated by a protected integrated circuit (SC) by a hardware pseudo-random number generator or by an algorithm implemented in a stored program of memory. 6. Sposób według któregokolwiek z zastrz. od 1 do 5, znamienny tym, że wywołanie (R) jest wytwarzane przez zabezpieczony układ scalony (SC) poprzez sprzętowy generator liczb pseudoprzypadkowych albo przez algorytm realizowany w zapisanym w pamięci programie wytwarzania. 7. The method according to any of claims 1 to 5, characterized in that the call (R) is carried out by a meter that performs increasing or decreasing from a given initial value each time the test device (TD) is connected to a protected integrated circuit (SC) or every test request sent to said protected integrated circuit (SC). 7. Sposób według któregokolwiek z zastrz. od 1 do 5, znamienny tym, że wywołanie (R) przeprowadzane jest przez licznik, który przeprowadza zwiększanie lub zmniejszanie od danej wartości początkowej przy każdym połączeniu testującego urządzenia (TD) z zabezpieczonym układem scalonym (SC) lub przy każdym żądaniu testowania wysyłanym do wymienionego zabezpieczonego układu scalonego (SC). 8. The method according to any of claims from 1 to 7, characterized in that the call (R) contains a time stamp with the current date and time given with specified accuracy. 8. Sposób według któregokolwiek z zastrz. od 1 do 7, znamienny tym, że wywołanie (R) zawiera pieczęć czasową z aktualną datą i godziną podanymi z określoną dokładnością. 9. The method according to any of claims 1 to 8, characterized in that the testing device (TD) and the protected integrated circuit (SC) store many common keys (CK) in memory. 9. Sposób według któregokolwiek z zastrz. od 1 do 8, znamienny tym, że testujące urządzenie (TD) i zabezpieczony układ scalony (SC) przechowują w pamięci wiele zwykłych kluczy (CK). 1411-PAT-EP-PL PAT-1411-EP-E - 20 EP2430583 - EP2430583 10. The method according to any of claims from 1 to 9, characterized in that the testing device (TD) stores multiple testing keys (TK) in memory, and the secured integrated circuit (SC) stores many F (TK) abbreviations in memory, each of which is calculated using the appropriate test key (TK) stored in the testing device (TD). 10. Sposób według któregokolwiek z zastrz. od 1 do 9, znamienny tym, że testujące urządzenie (TD) przechowuje w pamięci wiele testujących kluczy (TK), a ponadto zabezpieczony układ scalony (SC) przechowuje w pamięci wiele skrótów F(TK), z których każdy jest obliczony przy użyciu odpowiedniego testowego klucza (TK) zapisanego w testującym urządzeniu (TD). 11. The method according to claim 9 - 10, characterized in that the ordinary key (CK) stored in the testing device (TD) and in the protected integrated circuit (SC) and each test key (TK) stored in the testing device (TD) and also the corresponding abbreviations F (TK) saved the secured integrated circuit (SC) is accompanied by an index (I, J) for selecting a specific test key (TK), common key (CK) and hash F (TK) during the authentication process. 11. Sposób według zastrz. 9 - 10, znamienny tym, że zwykłemu kluczowi (CK) zapisanemu w testującym urządzeniu (TD) i w zabezpieczonym układzie scalonym (SC) oraz każdemu testowemu kluczowi (TK) zapisanemu w testującym urządzeniu (TD) i ponadto odpowiednim skrótom F(TK) zapisanym w zabezpieczonym układzie scalonym (SC) towarzyszy indeks (I, J) do wybierania specyficznego testowego klucza (TK), zwykłego klucza (CK) i skrótu F(TK) podczas procesu uwierzytelnienia. 12. The method according to claim 11, characterized in that the CK ciphertext (TK op R) sent by the testing device (TD) to the protected integrated circuit (SC) is accompanied by the index (I, J) of the corresponding test and the common key (TK, CK) used in the said CK ciphertext ( TK op R). 12. Sposób według zastrz. 11, znamienny tym, że szyfrogramowi CK(TK op R) wysłanemu przez testujące urządzenie (TD) do zabezpieczonego układu scalonego (SC) towarzyszą indeks (I, J) odpowiedniego testu i zwykły klucz (TK, CK) wykorzystywany w wymienionym szyfrogramie CK(TK op R). 13. The method according to claim 11, characterized in that the protected integrated circuit (SC) selects the received index (J) to designate the ordinary key (CK) to be used when decrypting the CK ciphertext (TK op R) and the index (I) of the abbreviation F (TK ), which is used to check the validity of the test key (TK) determined from the CK ciphertext (TK op R). 13. Sposób według zastrz. 11, znamienny tym, że zabezpieczony układ scalony (SC) wybiera odebrany indeks (J) w celu oznaczenia nim zwykłego klucza (CK), który ma być używany przy deszyfrowaniu szyfrogramu CK(TK op R) oraz indeks (I) skrótu F(TK), który służy do sprawdzenia ważności testowego klucza (TK) wyznaczonego z szyfrogramu CK(TK op R). 1411-PAT-EP-PL PAT-1411-EP-E - 21 EP2430583 - EP2430583 14. The method according to claim 12, characterized in that the index (I) of the test key (TK) used in the CKj ciphertext (TKi op R) is encrypted using a common key (CK) corresponding to the index (J) sent with the CK ciphertext (TK op R). 14. Sposób według zastrz. 12, znamienny tym, że indeks (I) testowego klucza (TK) stosowanego w szyfrogramie CKj(TKi op R) jest szyfrowany przy użyciu zwykłego klucza (CK) odpowiadającego indeksowi (J) wysyłanemu z szyfrogramem CK(TK op R). 15. The method according to claim 14. A method according to claim 14, characterized in that the protected integrated circuit (SC) decrypts the index (I) of the test key (TK) using the common key (CK) determined by the index (J) accompanying the CK cryptogram (TK op R), said decrypted index ( I) is used to select the appropriate shortcut F (TK) to check the validity of the test key (TK) specified from the CK ciphertext (TK op R). 15. Sposób według zastrz. 14, znamienny tym, że zabezpieczony układ scalony (SC) deszyfruje indeks (I) testowego klucza (TK) przy użyciu zwykłego klucza (CK) wyznaczonego przez indeks (J) towarzyszący kryptogramowi CK (TK op R), przy czym wymieniony odszyfrowany indeks (I) jest wykorzystywany do wybierania odpowiedniego skrótu F(TK) w celu sprawdzenia ważności testowego klucza (TK) określonego z szyfrogramu CK(TK op R). 1411-PAT-EP-PL PAT-1411-EP-E - 22 EP2430583 - EP2430583 1411-PAT-EP-PL PAT-1411-EP-E - 23 EP2430583 - EP2430583