Method and system for remote activation and management of personal security devices
Abstract
The presentinvention provides a method for activating and/or managing ateast one PSD (2040) with at least a first Remote Computer System (2050) over afirst network (2045) using at least one Client (2010) as a host to said at least onePSD (2040), said method comprising the steps of:-a) establishing at least one communications pipe (2075) over said firstnetwork (2045) between said at least one PSD (2040) and said at least first RemoteComputer system (2050),-b) retrieving proprietary information (1) by said at least first RemoteComputer System (2050) from a remote storage location (2165),-c) transmitting said proprietary information (1) from said at least first RemoteComputer System (2050) to said at least one PSD (2040) through said at least onecommunications pipe (2075), and-d) storing and/or processing said proprietary information (1) in said at leastone PSD (2040).

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
16 claims: 16 independent, 0 dependent
- 21.一種用於致動及/或管理至少一個個人保密裝置(2040)之方法,該個人保密裝置(2040)係具有至少一個第一遠距電腦系統(2050),該方法係透過一個第一網路(2045)使用至少一個客戶(2010)作為一個主機端至該至少一個個人保密裝置(2040),該方法包含下列步驟:a)透過該第一網路(2045),建立該至少一個個人保密裝置(2040)及該至少第一遠距電腦系統(2050)之間之至少一個通訊管路(2075);b)藉由該至少第一遠距電腦系統(2050),由一個遠距儲存位置(2165;2165')取得專有的資訊(1;1');c)由該至少第一遠距電腦系統(2050)透過該至少一個通訊管路(2075)而傳送該專有的資訊(1;1')至該至少一個個人保密裝置(2040);d)儲存及/或處理於該至少一個個人保密裝置(2040)中之該專有資訊(1;1')。
- 32.如申請專利範圍第1項所述之用於致動及/或管理至少一個個人保密裝置(2040)之方法,其進一步包含下列步驟:b1)於步驟b之後及步驟c之前,於該至少第一遠距電腦系統(2050)中編密該專有的資訊(1;1');c1)於步驟c之後及步驟d之前,於該至少一個個人保密裝置(2040)中解密該專有的資訊(1;1')。
- 43.如申請專利範圍第1或2項所述之用於致動及/或管理至少一個個人保密裝置(2040)之方法,其中,該遠距儲存位置(2165)係於該至少第一遠距電腦系統(2050)之中。
- 54.如申請專利範圍第1或2項所述之用於致動及/或管理至少一個個人保密裝置(2040)之方法,其中,該遠距儲存位置(2165')係於一個至少一個後續遠距電腦系統(2150)之中,該至少一個後續遠距電腦系統(2150)係功能上地透過一個第二網路而連接至該至少第一遠距電腦系統(2050),其中,該步驟b)係包含:由該至少一個遠距電腦系統透過該第二通訊網路而由該至少一個後續遠距電腦系統(2150)傳送該專有的資訊(1')至該至少第一遠距電腦系統(2050)。
- 65.如申請專利範圍第4項所述之用於致動及/或管理至少一個個人保密裝置(2040)之方法,其進一步包含下列步驟:於該至少一個後續遠距電腦系統(2150)中編密該專有的資訊(1');及於該至少第一遠距電腦系統(2050)中絕密該專有的資訊(1')。
- 76.如申請專利範圍第1或2項所述之用於致動及/或管理至少一個個人保密裝置(2040)之方法,其進一步包含:於步驟a之後及步驟b之前,透過該通訊管路(2075)而驗證面對該至少第一遠距電腦系統(2050)之該至少第一遠距電腦系統(2050)。
- 87.一種用於致動及/或管理至少一個個人保密裝置(2040)之客戶端(2010),該個人保密裝置(2040)係具有至少一個第一遠距電腦系統(2050),該方法係透過一個第一網路(2045)使用該客戶端(2010)作為一個主機端至該至少一個個人保密裝置(2040),其中,該客戶端(2010)係包含:透過至少一個透過該第一網路(2045)所建立之通訊管路(2075)而於該至少一個個人保密裝置(2040)及該至少第一遠距電腦系統(2050)之間轉移入站及出站之個人保密裝置格式化之訊息的裝置。
- 98.一種用於致動及/或管理至少一個個人保密裝置(2040)之遠距電腦系統(2050),其係透過一個第一網路(2045)使用至少一個客戶(2010)作為一個主機端至該至少一個個人保密裝置(2040),其包含:用於儲存專有的資訊(1;1')之裝置;及用於透過該至少一個通訊管路(2075)傳送該專有的資訊(1;1')至該至少一個個人保密裝置(2040)之裝置。
- 109.如申請專利範圍第8項所述之用於致動及/或管理至少一個個人保密裝置(2040)之遠距電腦系統(2050),其進一步包含:用於透過一個第二網路而接收由至少一個後續遠距電腦系統(2150)而來之該專有的資訊之裝置。
- 1110.如申請專利範圍第8或9項所述之用於致動及/或管理至少一個個人保密裝置(2040)之遠距電腦系統(2050),其進一步包含一密碼裝置,其用於在傳送該專有的資訊至該至少一個個人保密裝置(2040)之前透過該至少一個通訊管路(2075)編密該專有的資訊(1;1')。
- 1211.一種個人保密裝置致動及/或管理之系統,其係包含至少一個根據申請專利範圍第7項之客戶端(2010)及至少一個根據據申請專利範圍第8項之遠距電腦系統(2050),該遠距電腦系統(2050)係透過該至少一個通訊管路(2075)而連接至該至少一個客戶端(2010)。
- 1312.一種個人保密裝置致動及/或管理之系統,其係包含至少一個根,據申請專利範圍第7項之客戶端(2010)及至少一個根據據申請專利範圍第9項之遠距電腦系統(2050),該遠距電腦系統(2050)係透過該至少一個通訊管路(2075)而連接至該至少一個客戶端(2010)。
- 1413.如申請專利範圍第12項所述之個人保密裝置致動及/或管理之系統,其中,該至少一個後續遠距電腦系統(2150)係功能上地透過該第二網路而連接至該至少第一遠距電腦系統(2050),其中,該至少一個後續遠距電腦系統(2150)係包含:透過該第二通訊網路而傳送該專有的資訊至該至少第一遠距電腦系統(2050)之裝置。
- 1514.如申請專利範圍第13項所述之個人保密裝置致動及/或管理之系統,其中,該至少一個後續遠距電腦系統(2150)係包含用於編密該專有的資訊(1')之裝置;且其中,該至少第一遠距電腦系統(2050)係包含用於解密該專有的資訊(1')之裝置。
- 1615.如申請專利範圍第13項所述之個人保密裝置致動及/或管理之系統,其中,該第一及第二網路係形成一個相同的網路(2045)。
Independent claims15
243 paragraphs, as filed
Method and system for remote actuation and management of personal security device
<p>5. . . Hardware device port</p><p>10. . . customer</p><p>15. . . Pipeline customer</p><p>20. . . Personal security device software interface</p><p>25. . . Personal security device hardware device interface</p><p>30. . . connect</p><p>35. . . Non-proprietary built-in information</p><p>40. . . Personal security device</p><p>45. . . Remote communication network</p><p>50. . . Remote computer system</p><p>55. . . Application protocol data unit</p><p>70. . . Pipeline server</p><p>75. . . connect</p><p>80. . . Hardware device</p><p>90. . . Application layer</p><p>100. . . Application programming interface level</p><p>105. . . Communication layer</p><p>105S. . . Communication program</p><p>110. . . Operating system layer</p><p>120. . . Hardware driver layer</p><p>130. . . Physical device layer</p><p>130S. . . Network interface card</p><p>130C. . . Network interface card</p><p>140. . . Network interface card</p><p>220. . . Application protocol data unit format</p><p>230. . . Message packet</p><p>240. . . Message packet</p><p>330. . . Message packet</p><p>340. . . Message packet</p><p>440. . . Hardware security module</p><p>470. . . Software-based cryptographic module</p><p>475. . . Hardware security module software interface</p><p>485. . . Hardware security module hardware interface</p><p>525. . . Security module</p><p>535. . . Message packet</p><p>540. . . Message packet</p><p>635. . . Message packet</p><p>640. . . Message packet</p><p>1005. . . Hardware device port</p><p>1010. . . customer</p><p>1020. . . Personal security device software interface</p><p>1025. . . Personal security device hardware device interface</p><p>1030. . . connect</p><p>1035. . . Non-proprietary built-in information</p><p>1040. . . Personal security device</p><p>1045. . . Remote communication network</p><p>1045A. . . Remote communication network</p><p>1050. . . Remote computer system</p><p>1055. . . Application protocol data unit</p><p>1070. . . Pipeline server</p><p>1075. . . connect</p><p>1095. . . Internal verification module</p><p>1100. . . Application programming interface level</p><p>1105. . . Communication layer</p><p>1105S. . . Communication program</p><p>1110. . . Operating system layer</p><p>1120. . . Hardware driver layer</p><p>1130. . . Physical device layer</p><p>1130S. . . Network interface card</p><p>1130C. . . Network interface card</p><p>1140. . . Network interface card</p><p>1150. . . Follow-up remote computer system</p><p>1220. . . Application protocol data unit format</p><p>1230. . . Message packet</p><p>1240. . . Message packet</p><p>1325. . . Security module</p><p>1330. . . Message packet</p><p>1340. . . Message packet</p><p>1440. . . Hardware security module</p><p>1470. . . Software-based cryptographic module</p><p>1475. . . Hardware security module software interface</p><p>1485. . . Hardware security module hardware interface</p><p>1525. . . Security module</p><p>1535. . . Message packet</p><p>1540. . . Message packet</p><p>1625. . . Security module</p><p>1635. . . Message packet</p><p>1640. . . Message packet</p><p>1005. . . Hardware device port</p><p>2010. . . customer</p><p>2020. . . Personal security device software interface</p><p>2025. . . Personal security device hardware device interface</p><p>2030. . . connect</p><p>2035. . . Non-proprietary built-in information</p><p>2040. . . Personal security device</p><p>2045. . . network</p><p>2050. . . Remote computer system</p><p>2055. . . Application protocol data unit</p><p>2070. . . Pipeline server</p><p>2075. . . Communication pipeline</p><p>2105. . . Communication layer</p><p>2105S. . . Communication program</p><p>2110. . . Operating system layer</p><p>2120. . . Hardware driver layer</p><p>2130. . . Physical device layer</p><p>2130S. . . Network interface card</p><p>2130C. . . Network interface card</p><p>2150. . . Follow-up remote computer system</p><p>2160. . . Storage location</p><p>2165. . . Proprietary information</p><p>2165'. . . Proprietary information</p>
Figure 1 is a generalized system block diagram used to implement a general communication pipeline;
Figure 2 is a detailed block diagram of the initialization of a general communication pipeline;
Figure 3 is a detailed block diagram illustrating the establishment of a general communication pipeline;
Figure 4A is a generalized system block diagram used to implement a secure communication pipeline including a software-based security agency;
Figure 4B is a generalized system block diagram used to implement a secure communication pipeline including a secure organization based on a hardware security module;
Figure 5 is a detailed block diagram illustrating the initiation of a secure communication pipeline;
Figure 6 is a detailed block diagram illustrating the establishment of a secure communication pipeline;
Figure 7 is a general system block diagram used to implement verification of a personal security device relative to at least one remote computer system;
Figure 8 is a detailed block diagram illustrating the initial verification challenge;
Figure 9 is a detailed block diagram illustrating the initial verification response;
Figure 10 is a detailed block diagram illustrating the challenges of remote verification;
Figure 11 is a detailed block diagram illustrating the remote verification response;
Figure 12 is a detailed block diagram illustrating the transfer of authentication certificates;
Figure 13 is a detailed block diagram illustrating the remote verification challenge using the transferred verification certificate;
Figure 14 is a detailed block diagram illustrating the remote verification response using the transferred verification certificate;
Figure 15A is a generalized system block diagram for implementing the present invention using a first remote computer system (first embodiment of the present invention);
Figure 15B is a block diagram of a generalized system for implementing the present invention using a subsequent remote computer system (the second embodiment of the present invention);
Figure 16 is a detailed block diagram illustrating the direct transfer of proprietary information to a personal security device (the first embodiment of the present invention);
Figure 17 is a detailed block diagram illustrating the remote transfer of proprietary information to a personal security device (the second embodiment of the present invention).
Field of invention
The present invention is a data processing method and system for remote activation and management of a personal security device through a network, which is used to obtain services from one or more remote computer systems. Specifically, the present invention relates to a secure single-step method for activating and managing a person's secure device.
Background of the invention
The current technology involving the management of personal security devices such as smart cards requires a multi-step process, in which all the information required to use a personal security device is loaded into the personal security device before distribution, including a The starting personal identification code. Then, the personal security device is sent to an end user, and then a letter is sent, which contains the initial personal identification code that the user must enter when using the personal security device for the first time. Another current alternative is to attach an additional tag containing a phone number to a personal security device before issuing. The mark provides instructions to the end user to activate the personal security device before the device can be used before the device can be used through the telephone as a call center.
The above two methods are to construct a multi-step process, which increases the initial allocation and subsequent management costs of the personal security device. For example, when a smart card is issued, additional equipment, maintenance, labor, and operating costs are required to generate an individual letter containing an initial personal identification code or to generate an attached mark to be placed on the smart card. And used to operate and activate the call center of these smart cards.
Another major disadvantage of the prior art is the lack of management of the information contained in the personal security device after the personal security device is issued. The current personal security device that needs to be changed is either sent back to a central location or just discarded and replaced with a new personal security device. Both are time-consuming and costly.
Summary of the invention
An object of the present invention is to provide a post-issuance method for securely downloading and managing information in the secure domain of a personal secure device.
The purpose is achieved by a method for activating and/or managing at least one personal security device, the personal security device having at least one first remote computer system, and the method uses at least one personal security device via a first network The client serves as a host to the at least one personal security device, and the method includes the following steps: a) establishing at least one of the at least one personal security device and the at least first remote computer system through the first network Communication pipeline; b) obtaining proprietary information from a remote storage location by the at least first remote computer system; c) transmitting the at least one communication pipeline by the at least first remote computer system Proprietary information to the at least one personal security device; d) storing and/or processing the proprietary information in the at least one personal security device.
This improvement over the prior art is to use a communication channel that allows downloading information to a blank personal security device and subsequently processing the information. For the purpose of the present invention, a blank personal security device lacks proprietary algorithms and/or data, but includes a built-in execution time environment and optionally a unique identification code.
In a first embodiment of the method of the present invention, the remote storage location is in the at least first remote computer system.
In a second embodiment of the method of the present invention, the remote storage location is in at least one subsequent remote computer system, and the at least one subsequent remote computer system functionally passes through a second network And connected to the at least the first remote computer system. And the step b) includes: transmitting the proprietary information from the at least one subsequent remote computer system to the at least first remote computer system through the second communication network by the at least one remote computer system.
These embodiments allow the remote computer system to maintain the communication line (the first embodiment) or a subsequent remote computer system to transfer proprietary information such as verification algorithms, encryption keys, certificates, or authentication through the The communication pipeline is directly downloaded to a personal security device connected to a local client without revealing proprietary information to the local client.
One of the main advantages of the method of the present invention is that it allows a large number of blank personal security devices to be issued and activated on a future date without the risk of injury. Because an empty personal security device does not contain proprietary data, the personal security device cannot be used, and therefore cannot obtain access to confidential functions or data.
An example of a blank activation procedure is as follows: an end user who has previously received a blank personal security device connects the personal security device to a local client through a remote computer Access a predetermined location on the network on the system. The remote computer system can optionally implement end-user authentication by certain predetermined methods such as the promotion of social security codes, static personal identification codes, and mother's name. Alternatively, a unique identifier included in the personal security device can be used for verification.
Once the end user is verified as correct or connected to a valid personal security device, a remote computer system forms a communication line, and downloads through the communication line (first embodiment) or leads to a subsequent remote Download (the second embodiment) the necessary information from the computer system to the personal security device. The personal security device can be activated upon completion of the procedure, or as an additional security measure, the end user is motivated to implement and enter a unique personal identification code to further protect the access of the personal security device .
In the two embodiments of the present invention, a device for managing (such as upgrading, changing, deleting) the algorithms and data of personal security devices is obtained by remotely gaining access to these personal security devices and then directly Download these changes to the personal security device and be helped, again without leaving proprietary information on the clients. The necessary changes to the proprietary information can be implemented entirely in the security field of the personal security device.
In the two embodiments of the present invention, all transactions are generated within the security field of a personal security device and a security remote computer system, thus providing end-to-end security.
In the second embodiment of the present invention, a centralized storage for tracking changes of personal security devices is provided, which greatly simplifies the management of a large number of personal security devices.
Another object of the present invention is to provide a system for implementing the above method.
Schematic description
Figure 1 is a generalized system block diagram used to implement a general communication pipeline;
Figure 2 is a detailed block diagram of the initialization of a general communication pipeline;
Figure 3 is a detailed block diagram illustrating the establishment of a general communication pipeline;
Figure 4A is a generalized system block diagram used to implement a secure communication pipeline including a software-based security agency;
Figure 4B is a generalized system block diagram used to implement a secure communication pipeline including a secure organization based on a hardware security module;
Figure 5 is a detailed block diagram illustrating the initiation of a secure communication pipeline;
Figure 6 is a detailed block diagram illustrating the establishment of a secure communication pipeline;
Figure 7 is a general system block diagram used to implement verification of a personal security device relative to at least one remote computer system;
Figure 8 is a detailed block diagram illustrating the initial verification challenge;
Figure 9 is a detailed block diagram illustrating the initial verification response;
Figure 10 is a detailed block diagram illustrating the challenges of remote verification;
Figure 11 is a detailed block diagram illustrating the remote verification response;
Figure 12 is a detailed block diagram illustrating the transfer of authentication certificates;
Figure 13 is a detailed block diagram illustrating the remote verification challenge using the transferred verification certificate;
Figure 14 is a detailed block diagram illustrating the remote verification response using the transferred verification certificate;
Figure 15A is a generalized system block diagram for implementing the present invention using a first remote computer system (first embodiment of the present invention);
Figure 15B is a block diagram of a generalized system for implementing the present invention using a subsequent remote computer system (the second embodiment of the present invention);
Figure 16 is a detailed block diagram illustrating the direct transfer of proprietary information to a personal security device (the first embodiment of the present invention);
Figure 17 is a detailed block diagram illustrating the remote transfer of proprietary information to a personal security device (the second embodiment of the present invention).
Symbol description of main components
5. . . Hardware device port
10. . . customer
15. . . Pipeline customer
20. . . Personal security device software interface
25. . . Personal security device hardware device interface
30. . . connect
35. . . Non-proprietary built-in information
40. . . Personal security device
45. . . Remote communication network
50. . . Remote computer system
55. . . Application protocol data unit
70. . . Pipeline server
75. . . connect
80. . . Hardware device
90. . . Application layer
100. . . Application programming interface level
105. . . Communication layer
105S. . . Communication program
110. . . Operating system layer
120. . . Hardware driver layer
130. . . Physical device layer
130S. . . Network interface card
130C. . . Network interface card
140. . . Network interface card
220. . . Application protocol data unit format
230. . . Message packet
240. . . Message packet
330. . . Message packet
340. . . Message packet
440. . . Hardware security module
470. . . Software-based cryptographic module
475. . . Hardware security module software interface
485. . . Hardware security module hardware interface
525. . . Security module
535. . . Message packet
540. . . Message packet
635. . . Message packet
640. . . Message packet
1005. . . Hardware device port
1010. . . customer
1020. . . Personal security device software interface
1025. . . Personal security device hardware device interface
1030. . . connect
1035. . . Non-proprietary built-in information
1040. . . Personal security device
1045. . . Remote communication network
1045A. . . Remote communication network
1050. . . Remote computer system
1055. . . Application protocol data unit
1070. . . Pipeline server
1075. . . connect
1095. . . Internal verification module
1100. . . Application programming interface level
1105. . . Communication layer
1105S. . . Communication program
1110. . . Operating system layer
1120. . . Hardware driver layer
1130. . . Physical device layer
1130S. . . Network interface card
1130C. . . Network interface card
1140. . . Network interface card
1150. . . Follow-up remote computer system
1220. . . Application protocol data unit format
1230. . . Message packet
1240. . . Message packet
1325. . . Security module
1330. . . Message packet
1340. . . Message packet
1440. . . Hardware security module
1470. . . Software-based cryptographic module
1475. . . Hardware security module software interface
1485. . . Hardware security module hardware interface
1525. . . Security module
1535. . . Message packet
1540. . . Message packet
1625. . . Security module
1635. . . Message packet
1640. . . Message packet
1005. . . Hardware device port
2010. . . customer
2020. . . Personal security device software interface
2025. . . Personal security device hardware device interface
2030. . . connect
2035. . . Non-proprietary built-in information
2040. . . Personal security device
2045. . . network
2050. . . Remote computer system
2055. . . Application protocol data unit
2070. . . Pipeline server
2075. . . Communication pipeline
2105. . . Communication layer
2105S. . . Communication program
2110. . . Operating system layer
2120. . . Hardware driver layer
2130. . . Physical device layer
2130S. . . Network interface card
2130C. . . Network interface card
2150. . . Follow-up remote computer system
2160. . . Storage location
2165. . . Proprietary information
2165'. . . Proprietary information
Detailed description of the invention
In a first part (paragraph 5.1), the detailed description of the present invention will reveal how to establish a general communication line and a secure communication line between a personal security device and a remote computer system.
In a second part (paragraph 5.2), the detailed description of the present invention will reveal how to use the secure communication line to enhance the confidentiality of the verification process of a personal security device facing a remote computer system, and how to use the remote The remote computer system serves as a security center for the verification of the personal security device facing a plurality of subsequent remote computer systems.
In a third part (paragraph 5.3), the detailed description of the present invention will disclose a post-issuance method and system for securely downloading and managing information in the confidential domain of a personal security device.
The detailed description of the second part will be based on the use of a secure communication pipeline, however, the present invention is not limited to such use. The use of a general communication line, that is, a communication line that uses a mechanism that does not involve end-to-end encryption, falls within the scope of the present invention.
It should also be noted that the following description of the present invention will be based on a personal security device that receives and sends messages in the Application Protocol Data Unit (APDU) format.
The signaling format of the application protocol data unit that is familiar to those familiar with this art is a low-level signaling format that allows a personal security device to be compared with the device within the device to which the personal security device is connected. High-level applications.
It must be clear that the present invention is not limited to a signaling format using an application protocol data unit, and any other low-level signaling format that can be processed by the personal security device is within the scope of the present invention.
5.1 Establishment of communication pipeline 5.1.1 General communication pipeline Refer to Figure 1, which is a generalized system block diagram illustrating the structure of a client 10 and a remote computer system. The layers shown are based on the Open System Interconnection (OSI) model. For the sake of simplicity, certain layers that are common to the client and the remote computer system are not shown, and should be considered to be present and integrated in adjacent layers. For a client and remote computer system, the same layers include: an application layer 90, which generally includes higher-level software applications (such as word processors) and a user interface, such as a graphical user Interface (Graphical User Interface, GUI). An Application Programming Interface (API) level layer 100 is used to process and manipulate data used by higher or lower level applications.
A communication layer 105 containing a communication program, which includes a secure communication capability, which enables a client to communicate with a remote computer system to exchange information on an agreed protocol, and vice versa.
An operating system layer 110 or equivalent operating time environment, which controls the allocation and use of hardware resources such as memory, central processing unit time, disk drive space, hardware input/output port designation, Peripheral device management.
A hardware driver layer 120 allows the operating system to communicate with and control the physical device connected to the hardware input/output bus of the client or remote computer system.
And a physical device layer 130, in which the network interface card 140 provides a physical connection to a remote communication network 45. Other hardware devices 80 can also be connected in this layer.
5.1.1.1 Customer-specific features A special program included in the application layer 100 of the client and designated as a pipeline client interacts with the communication program included in the communication layer 105. The function of the pipeline client 15 is to separate the packetized application protocol data unit request from the inbound transmission packet received by a network 45 for processing by a locally connected personal security device 40. Alternatively, the outbound application protocol data unit response generated by a locally connected personal security device 40 is processed by the pipeline client to be packaged in the communication program included in the communication layer 105 In an agreed communication protocol.
A software driver, which is included in the communication layer 105 of the client and is called a personal security device software interface 20, guides the inbound application protocol data unit sent from the pipeline client 15 to the input/output device port The input/output device port connects the personal security device hardware device interface 25 to the locally connected personal security device 40. The application protocol data unit generated by the personal security device communicates with the personal security device software interface 20 through the personal security device hardware device interface 25 and through the input/output device port, and sequentially communicates with the management device. Road customer 15 for communication.
5.1.1.2 The characteristics of the remote specific computer system. The first specialized program, which is included in the application programming interface layer 100 of the remote computer system 50 and is called an application protocol data unit 55, is a twin comparison. The high-level transmission format becomes the low-level transmission format required for communication with a personal security device 40. Or, the application protocol data unit interface 55 converts the inbound application protocol data unit response received by a personal security device 40 into a program in the application programming interface layer 100 and the remote computer system. The higher-level signaling format used by the application layer 90.
A second specialization program included in the application programming interface layer 100 of the remote computer system 50 and called a pipeline server 70 interacts with the communication program included in the communication layer 105 effect. The function of the pipeline server 70 is to separate out the packetized application protocol data unit request from the inbound transmission packet received by a network 45 for processing by the application protocol data unit interface 55 . Alternatively, the outbound application protocol data unit response transferred by the application protocol data unit interface 55 is processed by the pipeline server for packetization by the communication program included in the communication layer 105 In an agreed communication protocol.
5.1.1.3 Other features The connection 30 between the personal security device 40 and the personal security device hardware interface 25 includes but is not limited to traditional electrical or optical fiber connections or wireless devices. The wireless devices include optical, radio frequency, sound, and magnetic Or electrical machinery. Similarly, the connection between the client 10 and the network 45 and the connection 75 between the remote computer system 50 and the network 45 can be done in a similar manner.
The network generally indicated as 45 includes public and private long-distance communication networks connected by traditional electrical, optical, electro-acoustic (such as dual-tone multi-frequency DTMF signals) or other wireless devices. Any mutually agreed communication protocol that can encapsulate the commands of the application protocol data unit can be configured to establish a general communication pipeline that includes an open or confidential communication protocol.
Referring now to FIG. 2, it is an illustration of a general communication pipeline between the initialization of the remote computer system 50 and the personal security device 40 connected to a client 10. In Figure 2, the remote computer system 50 sends a request for non-proprietary built-in information 35 to the personal security device 40. The non-proprietary built-in information 35 is, for example, an identification number. The personal security device 40 uses the personal security device interface 25 to connect to the local client 10. The personal security device interface 25 communicates with the client 10 through the hardware device port 5.
In order to initiate a general communication channel between the remote computer system 50 and the personal security device 40, the remote computer system 50 generates a request 200 through the application programming interface program 100. The applications The programming interface program 100 is converted into the application protocol data unit format 220 by the application protocol data unit interface 55, and sent to the pipeline server 70 for message packet. Then, the application protocol data unit of the packet is sent to the communication program 105S for integration in the outbound message packet 230.
The message packet 230 containing the application protocol data unit of the packet is transmitted 75 via a network interface card (input/output) 130S through the network. The client 10 receives the message packet 240 containing the application protocol data unit of the packet, which is received by the network 45 through a network interface card (input/output) 130C provided on the local client. The incoming message is processed by the communication program 105C of the client and sent 250 to the pipeline client 15 for fetching the application protocol data unit. The retrieved application protocol data unit is sent 260 through the hardware device port 5, and sent 270 to the personal security device interface 25, and sent to the personal security device 40 through the connection 30 for use in the personal security device Processing within the field 35.
In order to form an alternative request for a general communication line 75 between a remote computer system 50 and a personal security device 40, the request can be initiated by the client 10, by connecting a personal security device 40 to the start A request to form a personal security device interface 25 of a general communication line 75, or by requesting access to another remote computer system of the personal security device 40, and requesting access to one or more network connections included Information from local customers.
Referring now to FIG. 3, it illustrates a response of a personal security device that establishes the general communication line between the personal security device 40 and the remote computer system 50. In Figure 3, the previously received request is processed in the personal security device field 35, which generates a response message. The personal security device response is in an application protocol data unit format, and is sent from the personal security device 40 to the personal security device interface 25 through the connection 30. Then, the personal security device response is routed 370 through the hardware device port 5, and sent 360 to the pipeline client 15 for processing and packetization. Then, the resultant message packet is sent 350 to the communication program of the client to be integrated in the outbound message packet 340. The message packet 340 containing the application protocol data unit of the packet is transmitted 75 via the network interface card (input/output) 130C through the network 45.
The remote computer system 50 receives the message packet 330 containing the application protocol data unit of the packet, which is connected to the network 45 through a network interface card (input/output) 130S provided on the remote computer system Come. The incoming message is processed by the communication program 105S on the server side and sent 310 to the pipeline server 70 for fetching the application protocol data unit. The retrieved application protocol data unit is sent 320 to the application protocol data unit interface 55 for processing and conversion into a higher-level format, and sent 300 to the application programming interface layer program 100 for use when needed The personal security device 40 is used for processing and further transactions.
5.1.2 Secure communication pipeline Now please refer to Figure 4A, which shows a general system block diagram of an implementation of a secure communication pipeline. The general system block diagram includes an additional software-based cryptographic module 470 installed on the remote computer system, which is shown in Figure 1 at the end.
Figure 4B shows an alternative way of using a software-based security agency. In this alternative, a hardware security module 440 is used to implement the function of encryption. In order to access the hardware security module 440, a software driver called the hardware security module software interface 475 is included in the application program interface layer 100. The hardware security module software driver communicates with a physical device interface included in the physical device layer 130. The physical device interface is set on the input/output bus of the remote computer system, and is called a hardware security module hardware interface 485. The hardware security module 440 is connected 430 to the hardware security module hardware interface in a manner similar to the previously described connection to the personal security device interface. The technology using the hardware security module provides end-to-end security, which further reduces the possibility of unauthorized disclosure of confidential or sensitive information.
The application protocol data units shown in Figures 4A and 4B are used to generate unsecured security functions and data contained in the security domain of a personal security device, encrypted outbound application protocol data units, and The cryptographic key required for top-secret inbound encrypted application protocol data unit. The security mechanism used to generate a security pipeline can include any combination of synchronous, asynchronous or cryptographic methods.
The confidential communication protocol for communication through a network is completed by the communication program included in the communication layer 105. The cipher used to generate the confidential communication can be used to describe the confidential organization used for application protocol data unit transmission, an individual organization or any combination thereof.
Referring now to FIG. 5, it illustrates the initialization of a security pipeline between the remote computer system 50 and the personal security device 40 connected to a client 10. In Figure 5, the remote computer system 50 sends a confidentiality request for the proprietary built-in information 35 to the personal security device 40. The proprietary built-in information 35 is, for example, an identification code. The personal security device 40 uses the personal security device interface 25 to connect to the local client 10. The personal security device interface 25 communicates with the client 10 through the hardware device port 5.
In order to initiate a secure communication line between the remote computer system 50 and the personal security device 40, the remote computer system 50 generates a request 500 through the application programming interface program 100 to access the Personal security device 40. The application programming interface programs 100 are converted into the application protocol data unit format by the application protocol data unit interface 55. Then, a pre-established cryptographic method is used to transmit 520 the application agreement data unit to a security module 525 for encryption. The appropriate password parameters can be determined by using a look-up table or database, which is a cross-reference to the unique internal identification information of the personal security device and one or more codes required to implement the specified password method.
Then, the encrypted application protocol data unit is sent 510 to the pipeline server 70 for use in message packets. Then, the packaged application protocol data unit is sent 530 to the communication program 105 for processing, using a pre-established confidential communication protocol and integrated in the outbound message packet 535. The secret message packet 535 containing the encrypted and packetized application protocol data unit is transmitted 75 through the network 45 via a network interface card (input/output) 130S.
The client 10 receives the message packet 540, and the message packet 540 contains the encrypted code received by the network through a network interface card (input/output) 130C installed on the local client 10 And the packaged application protocol data unit.
The inbound encrypted message packet is decrypted and processed by the communication program 105C of the client using the pre-established password adopted in the confidential communication protocol. The unencrypted message packet that still contains the encrypted application protocol data unit is sent 550 to the pipeline client 15 for retrieval of the application protocol data unit. The retrieved application protocol data unit is sent 560 through the hardware device port 5, is routed 570 to the personal security device interface 25, and is sent to the personal security device 40 through the connection 30 for use in the personal security device Decryption and processing within 35 of the security domain of 40. Using a pre-established cryptographic method, the inbound secure application protocol data unit is decrypted and requested to be processed.
Referring now to FIG. 6, it illustrates a personal security device security response, which is to establish a security communication pipeline between the remote computer system 50 and the personal security device 40. In Figure 6, the previously received security request is processed in the security area 35 of the personal security device 40, which causes the personal security device to use a pre-established cryptographic method to generate a security response message.
The personal security device response message is in the format of an application protocol data unit, and is sent from the personal security device to the personal security device interface 25 through the connection 30. Then, the privacy response of the personal security device is routed 670 through the hardware device port 5 and sent to the pipeline client 15 for processing and packetization. Then, the resultant message packet is sent 650 to the communication program 105 of the client for processing, encrypted using a pre-established confidential communication protocol, and integrated in the outbound message packet 640. The message packet 640 containing the packetized application protocol data unit is transmitted 75 via the network interface card (input/output) 130C through the network 45.
The remote computer system 50 receives the message packet 635 containing the application protocol data unit of the packet, which is connected to the network through a network interface card (input/output) 130S provided on the remote computer system 50 Coming from 45. The incoming message is processed by the server-side communication program 105 using the pre-established cryptographic method used in the confidential communication protocol and is strictly confidential, and is routed 610 to the pipeline server 70 for confidentiality Retrieve the application protocol data unit. The retrieved secret application protocol data unit is sent 630 to the security module 525 for use in using the pre-established cryptographic method to keep the secret application protocol data unit secret. Then, the decrypted application protocol data unit is routed 620 to the application protocol data unit interface 55 for processing and conversion into a higher-level format, and is sent 600 to the application programming interface layer program 100 for use When necessary, the personal security device 40 is used for processing and further transactions. This step is to establish the confidential "pipeline" to communicate with the personal security device. The confidential pipeline is maintained until the remote computer system notifies the client to close the hardware interface port 5.
The applicant does not intend to limit the number of personal security devices and customers that can communicate with one or more remote computer systems 50, nor does it intend to limit the number of remote accesses that can be used to generate the communication pipeline 75 explained by these diagrams. The number of computer systems 50. Finally, it is not intended to limit the initiation event related to the establishment of a communication pipeline.
5.2 The verification method using a communication pipeline has been described above, and the verification method will be described based on the use of a secure communication pipeline, but the present invention is not limited to such use.
The use of a general communication line falls within the scope of the present invention.
The steps involving verification through a secure communication pipeline are shown in Figures 7-14. Figure 7 is a generalized system block diagram. Figures 8 to 11 illustrate a first variation, in which the verification challenge is generated in the security field of a personal security device. Figures 12 to 14 illustrate a second variation, in which the remote computer system as a security hub provides correct responses to verification challenges, instead of directing the challenges to the verification challenges through the communication channels. Personal security device for processing. A zigzag (such as C') indicated by an apostrophe indicates a copy of the original verification certificate. Other figure details shown on the figure but not described refer to the information described in the previous paragraph 5.1.
Referring now to Figure 7, which illustrates a generalized system block diagram, in which a personal security device 1040 is connected to a client 1010, which itself uses a secure communication line as described in the previous paragraph 5.1.2 , Connect to a remote computer system 1050 through a network 1045. The remote computer system 1050 operates as a security hub after the initial verification, as described below, to serve the verification request sent by the subsequent remote computer system via a network 1045 or 1045A.
The subsequent remote computer system 1150 is an example of a system that needs to be verified when a request for a confidential function or data is sent from the client computer 1010 through the networks 1045 and 1045A. The confidential communication line 1075 is used to verify transactions, but does not restrict or control non-secret transactions generated through the networks 1045 and 1045A.
The networks 1045 and 1045A may be a common network as in a real personal network connection configuration, or separate networks such as a private intranet and a public Internet configuration. These networks 1045 and 1045A are individually described for illustrative purposes only. The applicant does not intend to limit the number of personal security devices and clients that can communicate with one or more security hubs 1050, nor does it intend to limit the subsequent remote computer system 1150 that can be used to generate the verification explained by these diagrams. The number. It is also not intended to restrict transactions that do not involve verification from being restricted to the security hub.
The basic operation of the security hub can be when an end user at a client requests access to security functions or data contained in one or more remote computer systems connected by a network. A secure communication pipeline has been established as described in the previous paragraph 5.1.2. An accessible remote computer system uses the security agency included in the security domain of the personal security device to authenticate the end user and client. Alternatively, an external event such as the need to update information in a personal security device can trigger a subsequent remote computer system to initiate the verification process.
Once an initial client verification has been completed by the available remote computer system, the follow-up verification challenge implemented by the subsequent remote computer system and transmitted via a network 1045 or 1045A is directed to a security hub. The remote computer system 1050 is connected to the personal security device 1040 through the suitable communication pipeline 1075 or directly verified by the remote computer system 1050 according to the adopted variation.
5.2.1 Refer to Figure 8 for the first variation of the verification method. In order to establish a confidential hub, a client 1010 requests access to confidential functions or data through a network 1045, which results in a verification challenge generated by a remote computer Above system 1050. Upon receiving a request from the client 1010, the remote computer system 1050 generates a verification challenge 1205 in a confidential area as a routine 1065 for verification. The verification challenge is handled by an application program interface layer program 1100, and is routed 1200 to an application protocol data unit interface 1055 for conversion into an application protocol data unit format. Then, the application protocol data unit is sent to a security module 1225 for encryption. Then, the encrypted application protocol data unit is routed 1230 to a pipeline server 1070 for use in outbound transmission of packets, and sends 1210 to the communication program 1105S for transmission The communication line 1075 is transmitted, and the network 1045 is transmitted to the network interface 1130C of the client 1010. Then, the inbound message is sent 1260 through a hardware device port 1005 designated to a personal security device interface 1025. The personal security device interface 1015 bypasses the inbound application protocol data unit to the personal security device through a connection 1030, which is later decrypted and processed in its security domain 1035.
After processing, the messages are sent 1250 to a pipeline client 1015 for separating the packetized application protocol data unit. Then, the application protocol data unit is transmitted 1260 through a hardware device port 1005 designated as a personal security device interface 1025. The personal security device interface 1025 bypasses the inbound application protocol data unit to the personal security device 1040 through a connection 1030, which is subsequently decrypted and processed in its security field 1035.
Referring to Figure 9, once the personal security device 1040 has processed the verification challenge within the security domain 1035, it uses a pre-established cryptographic method to generate a verification response message.
The verification response message is in the format of an application protocol data unit, and is sent from the personal security device 1040 to the personal security device interface 1025 through the connection 1030. Then, the personal security device security response is routed 1370 through the hardware device port 1005, and is sent 1360 to the pipeline client 1015 for processing and packet processing. Then, the resultant message packet is sent 1350 to the client's communication program 1105C for processing, encrypted using a pre-established confidential communication protocol, and integrated in the outbound message packet 1340. The message packet 1340 containing the packetized application protocol data unit is transmitted 1075 through the network 1045 via the network interface card (input/output) 1130C.
The remote computer system 1050 receives the message packet 1335 containing the application protocol data unit of the packet, which is connected to the network through a network interface card (input 7 output) 1130S provided on the remote computer system 1050 Coming at 1045. The incoming message is processed and decrypted by the server-side communication program 1105S using the pre-established cryptographic method in the confidential communication protocol, and is routed 1310 to the pipeline server 1070 for confidentiality Retrieve the application protocol data unit. The retrieved secret application protocol data unit is sent 1330 to the security module 1325 for use in using the pre-established cryptographic method to keep the secret application protocol data unit secret. Then, the decrypted application protocol data unit is routed 1320 to the application protocol data unit interface 1055 for processing and conversion into a higher-level format, and sends 1300 to the application programming interface layer program 1100 for useFor processing. To deal with. If the verification is successful, the remote computer system 1050 allows access to confidential functions and data, and establishes itself as a confidential center. If the verification fails, the end user will not be able to access the confidential functions or data.
Referring to Figure 10, once the security hub has been established as previously described, the subsequent remote verification system of the remote computer system can be completed. Remote verification can be initiated by a client's request for access to confidential functions or data or by other remote computer systems performing transactions in the confidential domain of a personal security device.
In order to implement a remote verification, a challenge is issued by a subsequent remote computer system 1150. The challenge is routed to the security hub 1050 through a network 1045. The server-side communication program 1105S uses the pre-established cryptographic method used in the confidential communication protocol to process and decrypt the inbound challenge, and bypasses 1085 to an application program interface layer program 1100, in which, It is processed and routed 1400 to an application protocol data unit interface 1055 for conversion into an application protocol data unit format. Then, the application protocol data unit is sent 1420 to a security module 1425 for encryption. Then, the encrypted application protocol data unit is routed 1430 to a pipeline server 1070 for use in outbound transmission of packets, and 1410 is sent to the communication program 1105S for transmission The communication line 1075 is transmitted, and is transmitted through the network 1045 to the network interface 1130C of the client 1010.
Then, the inbound message is routed 1440 to the communication program 1105C for processing. After processing, the messages are sent 1450 to a pipeline client 1015 for separating the packetized application protocol data unit. Then, the application protocol data unit is sent 1460 through a hardware device port 1005 designated as a personal security device interface 1025. The personal security device interface 1025 bypasses the inbound application protocol data unit to the personal security device 1040 through a connection 1030, which is subsequently decrypted and processed in its security field 1035.
Referring to Figure 11, once the personal security device 1040 has processed the verification challenge within the security domain 1035, it uses a pre-established cryptographic method to generate a verification response message. The verification response message is in the format of an application protocol data unit, and is sent from the personal security device 1040 to the personal security device interface 1025 through the connection 1030. Then, the privacy response of the personal security device is routed 1570 through the hardware device port 1005, and is sent 1560 to the pipeline client 1015 for processing and packetization. Then, the resultant message packet is sent 1550 to the client's communication program 1105C for processing, encrypted using a pre-established confidential communication protocol, and integrated in the outbound message packet 1540. The message packet 1540 containing the packetized application protocol data unit is transmitted 1075 through the network 1045 via the network interface card (input/output) 1130C.
The secure hub 1050 receives the message packet 1535 containing the application protocol data unit of the packet, which comes from the network 1045 through a network interface card (input/output) 1130S. The incoming message is processed by the server-side communication program 1105S using the pre-established cryptographic method used in the confidential communication protocol and is top-secret, and then it is routed 1510 to the pipeline server 1070 for use Retrieve the confidential application agreement data unit. The retrieved confidential application protocol data unit is sent 1530 to the security module 1525 for use in decrypting the confidential application protocol data unit using the pre-established cryptographic method. Then, the decrypted application protocol data unit is routed 1520 to the application protocol data unit interface 1055 for processing and conversion into a higher-level format, and sends 1500 to the application programming interface layer program 1100 for useFor processing. To deal with. The verification module 1065 in the secure hub 1050 remains inactive during the verification information transfer period. Then, the verification response message is routed 1085 to the communication program 1105S, where the response is sent to the subsequent remote computer system 1150 of the challenge via the network 1045 in the form of a pre-established confidential communication protocol.
The inbound response message is top-secret and sent to a verification module 1095. If the verification is successful, the subsequent remote computer system 1150 allows access to confidential functions and data. If the authentication fails, the end user will not be able to access the confidential functions or data.
5.2.2 The second variation of the verification method refers to Figure 12, which illustrates a second variation of the verification method, in which, if there is no certificate of the personal security device on the remote computer system 1050, the The remote computer system 1050 transfers the certificate C1035 of the personal security device. In order to implement the transfer of credentials, an initial verification transaction is implemented by the remote computer system 1050, as described above. After verification, an additional command is sent by the remote computer system 1050 to transfer the specific certificate.
The certificate uses a pre-established cryptographic method and is in the format of an application protocol data unit. The personal security device 1040 is sent to the personal security device interface 1025 through the connection 1030. Then, the personal security device security response is routed 1670 through the hardware device port 1005, and is sent 1660 to the pipeline client 1015 for processing and packetization. Then, the resultant message packet is sent 1650 to the communication program 1105C of the client for processing, encrypted using a pre-established confidential communication protocol, and integrated in the outbound message packet 1640. The message packet 1640 containing the packetized application protocol data unit is transmitted 1075 through the network 1045 via the network interface card (input/output) 1130C.
The remote computer system 1050 receives the message packet 1635 containing the application protocol data unit of the packet, which is connected to the network through a network interface card (input/output) 1130S provided on the remote computer system 1050 Coming at 1045. The incoming message is processed and decrypted by the server-side communication program 1105S using the pre-established cryptographic method in the confidential communication protocol, and is routed 1610 to the pipeline server 1070 for confidentiality Retrieve the application protocol data unit. The retrieved secret application protocol data unit is sent 1630 to the security module 1625 for use in decrypting the secret application protocol data unit using the pre-established cryptographic method. Then, the decrypted application protocol data unit is routed 1620 to the application protocol data unit interface 1055 for processing and conversion into a higher-level format, and sends 1600 to the application programming interface layer program 1100 for use It is processed, and then sent 1605 to the verification security module 1065 for security storage and further use. The verification information of the transfer is shown as C'in Figure 12.
In Figure 13, a verification challenge 1085 is sent by a subsequent remote computer system 1150 through a network 1045. The remote computer system 1050 as a security hub receives the inbound challenge 1085 from the network 1045 through a network interface card (input/output) 1130S installed on the remote computer system 1050 . The incoming challenge 1085 is processed and decrypted by the server-side communication program 1105S using the pre-established cryptographic method in the confidential communication protocol, and is routed to the application programming interface layer program 1100 for use handle. Then, the processed challenge is sent 1705 to the verification module 1065 to use the transferred certificate C'of the personal security device for verification. The communication line 1075 can remain intact during the period when the program allows other transactions to occur.
Referring to Figure 14, the security hub 1050 generates a verification response in the verification module 1065. The verification response is sent 1805 to the application protocol interface layer program 1100 for processing, and then routes 1810 to the verification module 1065. The server-side communication program 1105S is used for processing, encrypting using a pre-established confidential communication protocol, and integrating it into the outbound message packet. The message packet passes through the network 1045 to the subsequent remote computer system 1150 of the challenge. Then, the inbound message is decrypted, and the verification response is processed by an internal verification module 1095. If the verification is successful, the subsequent remote computer system 1150 allows access to confidential functions and data. If the authentication fails, the end user will not be able to access the confidential functions or data.
5.3 Methods and systems for remote actuation and management of personal security devices For sensitive business and government transactions, the need for secure network communication is the most important. The present invention provides an improvement over the prior art by allowing the issuance of a general personal security device that can be activated and customized on a later date.
The steps involved in activating and implementing subsequent information management through a communication channel are shown in Figures 15-17. For the sake of illustration, it should be considered that any local verification between the end user, client, and local network domain has been completed. Preferably, a confidential communication protocol is used on the network between the client and one or more remote computer systems. Those skilled in the art can understand that any of the embodiments of the present invention can be used with or without a confidential communication protocol.
Now referring to Figure 15A, which illustrates a client 2010 and a connected personal security device 2040 through a network 2045 with a remote computer system 2050 using the communication line 2075 as described in the previous paragraph 5.1 of the present invention The first embodiment. The remote computer system 2050 maintains the communication line 2075, and can be used to transfer the proprietary information "1" 2165 to the personal security device 2040 through the communication line 2075.
In Figure 15B, it is the second embodiment of the present invention, in which a first remote computer system 2050 as a security hub as described in paragraph 5.2 provides a connection for connecting 2085 to a network 2045 The organization of the subsequent remote computer system 2150 to transfer the proprietary information "1" 2165 to a personal security device 2040. In the second embodiment of the present invention, the proprietary information 2165' is received and processed by the first remote computer system 2050. Then, the proprietary information 2165' is transmitted by the first remote computer system 2050, and then to the personal security device 2040 through the communication line 2075.
The network 2045 may be a common network as in a real private network configuration or in separate networks such as a private intranet and a public internet connection. The applicant does not intend to limit the number of personal security devices and the number of clients that can communicate with one or more remote computer systems 2050, nor does it intend to limit the use of information that can be used to transfer proprietary information explained by these icons 2165 , 2165' of the remote computer system 2050, the number of 2150.
For the activation of a blank personal security device or for prohibiting a personal security device that has been used, the verification of the end user is one of the selectable options. In the case of wanting to access a previously personalized personal security device, verification of the transaction may be required, as described in paragraph 5.2, to facilitate secure access to the personal security device. Once the verification procedure has been completed, the modification of the proprietary information contained in the privacy field of the personal security device is completed using the same method described for blank card activation.
The proprietary information 2165, 2165' used to store a personal security device can originate from a remote computer system 2050 supporting a communication line (the first embodiment of the present invention) or from a subsequent remote computer system 2150 ( The second embodiment of the present invention), or any combination that originated from a remote computer system.
Refer to Figure 16, which illustrates the use of a remote computer system 2050 that supports the communication pipeline (the first embodiment of the present invention), and transfers proprietary information from a storage location to an individual through a network Security device. This diagram can be used to activate a blank personal security device or change the information in an active personal security device after verification. In the first embodiment of the present invention, the proprietary information is called by the storage location 2160 in the remote computer system 2050.
After being retrieved, the proprietary information 2165 is sent 2206 in the format of the application protocol data unit for processing, and the packet becomes the appropriate communication transmission format 2204, as described in the previous paragraph 5.1. After processing, the communication message 2204 is sent to the communication pipe 2075 via the network 2045 through the network interface 2130S, and is received by the client 2010 through a complementary network interface 2130C.
The inbound communication message is sent 2212 for processing, wherein the information formatted by the application protocol data unit is separated as described in the previous paragraph 5.1. Then, the separated application protocol data unit is routed to 2216 and reaches 2218 to the personal security device interface device 2025 through the hardware device port 2005. Then, the inbound application protocol data unit is routed 2030 to the private security field 2035 of the personal security device. In the security field 2035 of the personal security device, the information is at least one built-in The algorithm is processed and stored.
For a recently issued personal security device that lacks proprietary information, the built-in algorithm is set by the issuer of the personal security device, and it is used as the initial setting for managing proprietary information. For personal security devices that already contain proprietary information, the algorithm can be the same or a different algorithm, which can include the ability to password.
Refer to Figure 17, which illustrates the use of multiple remote computer systems 2050, 2150, and transfer of proprietary information from a remote storage location 2160' to a personal security device 2040 via a network 2045. The second embodiment of the present invention involves obtaining proprietary information 2165' from one or more remote computer systems 2150, and transmitting 2085 the proprietary information through a network 2045, where the proprietary information is Received and processed by a first remote computer system 2050, the first remote computer system 2050 provides a communication line 2075, and transmits the proprietary information to the confidential domain 2035 of the personal security device 2040 middle.
The second embodiment of the present invention can be applied to activate a blank personal security device or change the information in an active personal security device after verification. In the case of verification, the remote computer system that provides the communication line can be operated as a security hub as described in the previous paragraph 5.2.
In the second embodiment of the present invention, the proprietary information 2165' is called by a storage location located in a subsequent remote computer system 2150 or another remote computer system, the other remote computer system It is local to the subsequent remote computer system 2150 and communicates with the subsequent remote computer system 2150. The proprietary information "1" 2165' is obtained through a network 2045 and transmitted 2085, and is transmitted to the remote computer system 2050 provided to the communication line 2075 of the designated personal security device 2040.
The remote computer system 2050 receives the proprietary information through the network interface 2130, and bypasses the inbound proprietary information 2165' to process the proprietary information 2302 and become an application protocol data unit Format, and the packet becomes the appropriate communication format 2304, as described in the previous paragraph 5.1. After processing, the communication message 2304 is sent to the communication pipe 2075 via the network 2045 through the network interface 2130S, and is received by the client 2010 through a complementary network interface 2130C.
The inbound communication message is sent 2312 for processing, in which the information formatted by the application protocol data unit is separated as described in the previous paragraph 5.1. Then, the separated application protocol data unit is routed to 2316, and reaches 2318 to the personal security device interface device 2025 through the hardware device port 2005. Then, the inbound application protocol data unit is routed 2030 to the private security field 2035 of the personal security device 2040. In the security field 2035 of the personal security device, the information is at least one built-in The algorithm is processed and stored.
As mentioned above, for the recently issued personal security device that lacks proprietary information, the built-in algorithm is set by the issuer of the personal security device, and it is used as the initial setting for managing the proprietary information. For personal security devices that already contain proprietary information, the algorithm can be the same or a different algorithm, which can include the ability to password.
The above-mentioned embodiment of the present invention is provided as an illustration and description. It is not intended to limit the invention to the precise form described. In particular, it is considered that the functional implementation of the present invention described herein can be implemented equivalently by hardware, software, firmware, and/or other available functional elements or structural blocks. After viewing the above teachings, other changes and embodiments are possible, and it is not intended that the scope of the present invention is limited by the detailed description herein, but is limited by the scope of the attached patent application.
3 sheets
Sheet 1 Sheet 2 Sheet 3
54 members in 6 offices
Priority claims15
| Document | Office | Kind | Date |
|---|---|---|---|
| 09844246 | United States of America | – | |
| 09844272 | United States of America | – | |
| 09844439 | United States of America | – | |
| 84424601 | United States of America | A | |
| 84424601 | United States of America | A | |
| 84427201 | United States of America | A | |
| 84427201 | United States of America | A | |
| 84443901 | United States of America | A | |
| 84443901 | United States of America | A | |
| 20010844246 | – | – | – |
| 20010844272 | – | – | – |
| 20010844439 | – | – | – |
| US20010844246 | – | – | – |
| US20010844272 | – | – | – |
| US20010844439 | – | – | – |
Members54
| Document | Office | Kind | |
|---|---|---|---|
| US2002162021A1 | United States of America | A1 | |
| US2002162022A1 | United States of America | A1 | |
| US2002162023A1 | United States of America | A1 | |
| WO02089443A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO02089444A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO02091316A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW552786BThis record | Taiwan Province of China | B | |
| EP1384212A1 | European Patent Office (EPO) | A1 | |
| EP1384369A1 | European Patent Office (EPO) | A1 | |
| EP1384370A1 | European Patent Office (EPO) | A1 | |
| US2004143731A1 | United States of America | A1 | |
| US2004143762A1 | United States of America | A1 | |
| US2004148429A1 | United States of America | A1 | |
| EP1384370B1 | European Patent Office (EPO) | B1 | |
| AT291319T | Austria | T | |
| ATE291319T1 | Austria | T1 | |
| DE60203277D1 | Germany | D1 | |
| DE60203277T2 | Germany | T2 | |
| US7225465B2 | United States of America | B2 | |
| EP1384369B1 | European Patent Office (EPO) | B1 | |
| EP1384212B1 | European Patent Office (EPO) | B1 | |
| AT364951T | Austria | T | |
| ATE364951T1 | Austria | T1 | |
| DE60220665D1 | Germany | D1 | |
| AT366968T | Austria | T | |
| ATE366968T1 | Austria | T1 | |
| DE60221113D1 | Germany | D1 | |
| US7316030B2 | United States of America | B2 | |
| DE60220665T2 | Germany | T2 | |
| DE60221113T2 | Germany | T2 | |
| US7363486B2 | United States of America | B2 | |
| EP1384369B2 | European Patent Office (EPO) | B2 | |
| US7853789B2 | United States of America | B2 | |
| US2011119482A1 | United States of America | A1 | |
| DE60220665T3 | Germany | T3 | |
| US8028083B2 | United States of America | B2 | |
| EP1384212B2 | European Patent Office (EPO) | B2 | |
| US8190899B1 | United States of America | B1 | |
| US2012173637A1 | United States of America | A1 | |
| DE60221113T3 | Germany | T3 | |
| US8402275B2 | United States of America | B2 | |
| US8626947B2 | United States of America | B2 | |
| US2014089437A1 | United States of America | A1 | |
| US8892771B2 | United States of America | B2 | |
| US8892891B1 | United States of America | B1 | |
| US2015135273A1 | United States of America | A1 | |
| US2015156275A1 | United States of America | A1 | |
| US9210172B2 | United States of America | B2 | |
| US9282163B2 | United States of America | B2 | |
| US2016197888A1 | United States of America | A1 | |
| US2016234336A1 | United States of America | A1 | |
| US9473469B2 | United States of America | B2 | |
| US2017064553A1 | United States of America | A1 | |
| US9794371B2 | United States of America | B2 |
Numbers
- Publication
- 552786
- Publication, DOCDB
- 552786
- Publication, EPODOC
- TW552786B
- Application
- 91107061
- Application, DOCDB
- 91107061
- Application, EPODOC
- TW20020107061
Titles4
- Chinese
- 個人保密裝置之遠距致動及管理之方法及系統
- English
- METHOD AND SYSTEM FOR REMOTE AcTIVATIONAND MANAGEMENT OF PERSONAL SEcURITYDEVICES
- Unlabeled
- 個人保密裝置之遠距致動及管理之方法及系統
- Unlabeled
- Method and system for remote actuation and management of personal security device
Classification
- CPC, 13
- H04L12/4633
- H04L63/0428
- H04L63/08
- H04L63/0807
- H04L63/0823
- H04L63/0853
- H04L63/20
- H04L69/08
- H04L69/32
- H04L67/60
- H04L51/00
- H04L67/02
- H04L67/025
- IPC, 3
- H04L12 46
- H04L29 06
- H04L29 08