Access-protected storage of information in a storage module

By pre-treating and continuously transcoding data in electronic memory modules with authorized authentication, the method fortifies encryption against side channel attacks, ensuring secure storage.

DE102015123001B4Active Publication Date: 2025-07-17DEUTSCHE TELEKOM AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
DE102015123001
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2015-12-30
Publication Date
2025-07-17
Estimated Expiration
2035-12-30

AI Technical Summary

Technical Problem

Existing encryption methods in electronic memory modules are vulnerable to side channel attacks, compromising the security of stored information.

Method used

The method involves pre-treating electronically encoded information to increase entropy, followed by continuous transcoding using a deterministic algorithm controlled by a random number generator, and stopping the transcoding only upon presentation of authorized authentication features.

Benefits of technology

Enhances security by making it impossible for unauthorized access to derive the original data from observed data streams, even with side channel attacks, ensuring secure storage of information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for the access-secure storage of electronically coded information in an intelligent electronic storage module, characterized by the method steps a.) Pretreatment of the data set encoding the information to be stored in the memory module to increase the entropy of the information represented by this data set in a uniquely reversible electronic processing step, b.) Transferring the data volume pretreated according to a.) into the memory module, c.) Recoding of the amount of data currently stored in the memory module by means of a deterministic algorithm controlled by a random generator, d.) continuous repetition of step c.) until at least one authentication feature authorising the reading of the information stored in it is presented to the memory module, whereby at an output for outputting the data set encoding the information to be kept secret, data without any information content is output in a constantly changing sequence until this authorising authentication feature is presented, e.) Stopping the random generator-controlled recoding and calculating the pre-processed data set originally transferred to the memory module, f.) Output of the amount of data originally transferred to the memory module, g.) Post-processing of the data output by the memory module by reversing the processing step performed to increase the entropy according to a.).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a solution for the access-protected storage of electronically coded information in an intelligent electronic storage module. It relates to a corresponding method and to an electronic storage module designed to carry out the method. The aim of the presented solution is the reliable and secure storage of secrets associated with the information to be stored in the memory module in an access-protected manner. The corresponding information does not necessarily have to be human-readable information. Rather, it can be information of any type that is electronically coded and digitized for storage and processing by electronic systems.

[0002] Of course, the information can also be statements that can be directly understood or interpreted by a human, such as a text, a design drawing, or another graphic representation. Access-protected storage of such information is understood to mean storage of the information in such a way that it can only be read from the corresponding memory module, which stores it in an access-protected manner, by authorized persons or systems. However, the inventive solution is designed such that the information as such is not directly accessible, i.e., with reference to the example of a text already cited, as plain text, even by a person who supposedly legitimately reads the data encoding it from the memory module.

[0003] As already indicated above, authorized access to a data set encoding the information to be kept secret and stored in the memory module, i.e., the reading of the data set in question, can be carried out directly by a person or by a technical system. With regard to the latter, for example, with regard to a possible embodiment of the invention, according to which access to this data set is possible at a specific time using time data representing this time as an authentication feature, it is conceivable that the data set is automatically read out upon the occurrence of the corresponding time event by an automated system previously coupled to the memory module.In the context of the following explanations of the invention, reference is made exclusively to attempts to access the memory module or authorized access by a person to the data volume originally transferred to it. However, the invention also encompasses access or attempted access by automated technical systems in any case.

[0004] Information that constitutes secrets is stored on a large scale in electronic memory in connection with a wide variety of practical applications. Such information is often stored in memory modules that are part of mobile systems and therefore also carried by people. This includes, for example, electronic devices such as smartphones, but also storage media such as portable hard drives, memory sticks, or smart cards. For example, chip cards, such as those used in payment transactions, store data that should not be accessible to everyone. Therefore, the data that encodes various information is often stored in encrypted form in the memory modules of the type mentioned above.

[0005] Sophisticated encryption methods are used here, which are designed to make it largely impossible for an unauthorized person to gain access to the information encoded in the encrypted data. Decrypting the data in question therefore requires, for example, a password, PIN, or the presentation of an authentication feature that identifies a person or technical system (i.e., an authorized entity as a generic term for person or system) as an authorized identifier, such as a fingerprint or the like, to the memory module.

[0006] However, essentially all encryption methods developed to date have been broken over time. While this does not apply to currently used encryption methods, experience suggests that it is only a matter of time before these, too, are broken. Originally, the methods used by unauthorized persons to break an encryption method or to obtain encrypted information without authorization were purely mathematical. These involved attempting to calculate the key used for encryption using complex procedures or determining it by successively trying out all theoretical possibilities.However, current encryption methods are now generally so strong that the illegal calculation or determination of a key that enables the decryption of correspondingly encrypted information requires a very long time, even when using the most modern computing technology and processing the problem in parallel using a large number of computers.

[0007] Attacks, i.e., attempts at unauthorized access to information, have therefore been known for some time. These attacks combine appropriate mathematical methods with so-called side-channel attacks. These attacks attempt to deduce the key used to encrypt the encrypted data by recording physical quantities or phenomena during an attempt to read the encrypted data. For example, with a bank chip card, on which encoding data is stored in encrypted form, it is possible to measure the currents occurring during the data exchange between the systems and during the encryption and decryption processes at the interface between the chip card and the reading unit of an ATM. Based on these measurements, they can be used to deduce the keys used.Such an attack using a side channel - here the current measurements - is called "Differential Power Analysis" (DPA).

[0008] DE 10 2007 011 309 A1 describes a method for the authenticated transmission of a (personalized) data set to a hardware security module (HSM). According to one embodiment of the described method, to verify the authorization of a write operation for transferring data or programs to the HSM, a so-called rolling code is issued by the HSM to a device (host) used to write the data. If the host converts the rolling code issued by the HSM, using a (secret) fixed code normally known only to the host, into a transformed rolling code that is recognized as correct by the HSM after it has been returned to the HSM, the host is deemed authorized to write data to the HSM. The same rolling code cannot be used again for the purpose of proving authorization to write data to the HSM for a subsequent write operation.Rather, the rolling code is changed for each subsequent authorization verification that always precedes a write operation, i.e., from one authentication process to the next. Data transferred to the HSM's memory, whether encrypted or not, remains unchanged until accessed for its intended use. Thus, apart from any encryption, which can potentially be broken using side-channel attacks, it is not specifically protected against unauthorized access.

[0009] US 2013 / 0332195 A1 describes a solution for storing data in which the data is subjected to preprocessing through encryption before storage. However, even with this solution, the data is no longer modified after being stored in the designated storage.

[0010] The object of the invention is to provide a solution for the reliable and secure storage of information in an electronic memory module, by which the information stored in the memory module is reliably protected against unauthorized access, even with the aid of side-channel attacks. To this end, a method is to be specified and an electronic memory module suitable for its implementation is to be provided.

[0011] This object is achieved by a method having the features of patent claim 1. An electronic memory module that achieves this object is characterized by the first claim. Advantageous embodiments and further developments of the invention are provided by the subclaims.

[0012] The method proposed to solve the problem for access-protected storage of electronically coded information in a memory module assumes that the information in question is stored in an intelligent memory module. Such a memory module has, in particular, a processing unit and a program application processed by this unit to carry out the method. More detailed explanations of the nature of such a memory module will be given later. The term "electronically coded information" in the context of the descriptions of the invention refers to the fact that any information, regardless of whether it is, for example, human-readable text, graphic representations, audio and / or video signals, or physical measured values or status information, is first converted into an electronic form in order to be able to store it.Furthermore, the invention assumes that corresponding information is digitized, i.e., converted into electronic data, during the conversion into electronic form for storage purposes. Under these premises, the proposed method is structured according to the method steps described below. a) First, the data set encoding the information to be stored, consisting of digital electronic data, is pre-processed in a special way. The goal is, in a sense, to "blur" the original structure of the electronic data set encoding the information. The resulting data set should contain as few or, ideally, no structures that could be useful for cryptanalysis. To this end, the entropy of the information represented by the data set is deliberately increased in a uniquely reversible electronic processing step.

[0013] For example, if the data set encodes a textual statement, certain letters typically occur more frequently than others in such a text, depending on the language. For example, the letter "e" occurs in German texts with an average frequency of 17.4%, whereas the average frequency of the letter "p" is only 0.79%. This knowledge can, however, be helpful in deducing the plaintext from an encrypted text using cryptanalysis. In order to deprive potential attackers of the support provided by language in this regard, or to significantly reduce this influence, the entropy of the electronically encoded information is deliberately increased. The same applies to other forms of information and the data set encoding them.To a certain extent, this blurs the information content of the data in question, as the information can no longer be directly extracted from it, or the meaning becomes ambiguity. Possible approaches for preprocessing the data encoding the information with the aim of increasing entropy will be discussed later. However, it should be expressly noted that, according to the method proposed here, the corresponding preprocessing takes place outside the electronic storage module in which the information is to be stored in a secure manner. b) Only in the process step following the previously explained pretreatment is the data volume, pretreated with respect to the entropy of the information encoded by it, transferred to the electronic memory module. This can be achieved, for example, by a temporary, wired connection of the memory module to a system used for pretreating the data volume encoding the information. Of course, other transmission methods known from the prior art are also suitable for this purpose, such as, in particular, radio transmission. c) Preferably, immediately after the completion of the transfer of the preprocessed data to the electronic storage module, this data is transcoded using a deterministic algorithm controlled by a random number generator. Alternatively, to starting immediately after the data transfer, the transcoding can also be initiated by an operator action on a control element of the storage module, if present, or by another trigger signal (e.g., from a technical system temporarily coupled to the storage module). d) The preceding process step c), i.e., the recoding of the data volume currently stored in the electronic memory module, is continuously repeated. This process step is repeated, preferably at very short intervals (e.g., a few milliseconds), until the memory module is presented with an authentication feature authorizing the user to acknowledge the information stored therein, or more precisely, to read the data volume encoding this information. The nature of such an authentication feature will also be discussed later. e) If the permissible authentication feature has been presented to the memory module according to method step d), the continuous recoding controlled by the random number generator is stopped. Furthermore, the aforementioned processing unit of the memory module, using the aforementioned program application, recalculates the amount of data originally transferred to the memory module from the amount of data currently present in the memory module. This is possible directly, depending on the specific design of the algorithm, due to the fact that the previous recoding was performed using a deterministic algorithm. f) The recalculated data set originally transferred to the memory module is then finally output by the module. It should be noted at this point that data output by the memory module or data readout from the memory module may be possible, for example, using side-channel attacks, even if the authentication feature authorizing access to the stored information or the reading of the data set encoding this information has not been presented to the memory module. However, in this case, this will not be the data set originally transferred to the module. Rather, the data read out in this way makes no sense to an attacker, so they cannot deduce the original data set.Furthermore, the attacker cannot determine from the potentially observable data stream whether an authentication feature presented by him was correct and therefore a closer analysis of the data set is worthwhile, or whether the authentication feature was incorrect and therefore the data stream cannot be meaningfully evaluated. g) Finally, the data output or read from the memory module after the presentation of the permissible authentication feature is subjected to post-processing by reversing the processing step performed to increase entropy in process step a). This process step is also performed outside the electronic memory module that stores the information in coded form.

[0014] As already mentioned, various approaches are possible for pretreating the data volume to be stored in the memory module by increasing the entropy of the information or information encoded by this data volume. According to a first possible embodiment of the method according to the invention, the data volume is compressed losslessly. This simultaneously has the advantage of reducing the storage space required to store the data volume.

[0015] Another option is to encrypt the data. This also ensures that the information (or information) originally encoded in the data can no longer be directly extracted from the preprocessed data set. In this context, it should be expressly pointed out again that the first step of preprocessing the data sets encoding the information does not take place within the electronic storage module in which the information to be kept secret is ultimately stored. According to an advantageous variant, a deterministic encryption algorithm is used for preprocessing the data set.

[0016] The continuous, permanent recoding of the data volume originally transferred to the storage module, or of the modified data volume resulting from such a recoding process, as well as the stopping of this ongoing recoding process, can also be carried out according to very different criteria and aspects. In principle, however, the repeated or continued, i.e., continuous recoding of the data volume always takes place using a deterministic algorithm controlled by a random number generator. Furthermore, the recoding can be parameterized using at least one authentication feature representing the stopping of the continued recoding. This means that the relevant feature(s) are incorporated into the actual recoding process.

[0017] The authentication feature can, for example, be a PIN, which is to be entered using a keypad provided for this purpose on the memory module. The program application that effects the ongoing / continuous recoding includes program steps that enable the entry and evaluation of a corresponding PIN between two recoding processes. However, these program steps—in particular, the evaluation of an attempted PIN entry—are preferably only executed when an attempt is made to read the data stored in the memory module.

[0018] In this respect, the possibility of presenting biometric features or their digital images to the memory module is comparable to PIN entry. For example, the memory module can be equipped with a fingerprint sensor, and the method can be designed in such a way that the continuous recoding process is stopped as soon as the finger of an authorized person is placed on it. Depending on the complexity and intended use, the iris of the eye of a person authorized to read the data encoding the information, captured by an optical sensor in the memory module, can also serve as such a biometric feature. Of course, other biometric features can also be used to implement the method.

[0019] With regard to the previously mentioned possibility of designing the method so that stopping the transcoding process is only achieved through a combination of several authentication features, several such biometric features or their digital images can be taken into account if necessary. For example, it is conceivable that reading the memory module is only possible if two or more people authenticate themselves to them using corresponding biometric features. However, it is also conceivable that an authorized person must authenticate themselves, for example, using both their fingerprint and an optical scan of their iris. It should be noted that, in connection with authentication to stop the transcoding process, any combination of the authentication features already mentioned and those mentioned below can be incorporated into the method.

[0020] In addition to or in addition to the aforementioned authentication features, the following features, listed below as examples, may also be considered. For example, it is possible to use the current local location of the memory module as an authentication feature by evaluating data from a GPS receiver, in this case provided in the memory module. This makes it possible to allow access to the data volume encoding the information(s) stored in the memory module only at one or more previously specified locations, which are communicated to the memory module in connection with the transfer of the data volume to the memory module. Another possibility is to consider time data.It can be provided that the reading of the memory module is only possible at certain times or only after a specified period of time has elapsed after the transfer of the amount of data to the memory module.

[0021] Another practical design is that a token must be presented to the memory module to enable access to the originally transferred data set. Such a token can be, for example, a chip card or a stick with a passive transponder, from which an ID serving as an authentication feature can be read wirelessly by an NFC reader provided in or on the memory module, without contact and without the need for a wired connection. However, depending on the token's characteristics and the design of the memory module, a corresponding token can also be connected to the memory module by establishing direct galvanic contact using a connector on the token or via a wired connection.Even the protection of the amount of data stored in the memory module by means of a mechanical key, which in this case represents the authentication feature, is fundamentally possible.

[0022] The outwardly apparent behavior of the memory module can also vary greatly in the event of the failure to present one or more authentication features enabling access to the data set, or in the event of an unauthorized readout attempt. According to one option provided for this purpose, the memory module outputs a constantly changing sequence of data without any information content and, if necessary, with varying length and format at an output enabling the output of the data set encoding the information (or information) to be kept secret. Only in the event of the presentation of one or more permissible authentication features will the data set originally transferred to the memory module be output at the respective output instead.

[0023] This offers the advantage that even a person who has gained unauthorized access to an authentication feature, such as a PIN, may not be able to directly access the actual information stored in the memory module because it is stored in the memory module not in a simply encoded form, but rather in the form of a pre-processed data set, which is indistinguishable to a person gaining illegal access to the data from the data continuously output without any information content. This means that a person gaining illegal access cannot recognize, at the moment the unlawfully acquired authentication feature is presented, that the memory module is outputting a data set which, in order to obtain the information encoded therein, only needs to be further processed to reverse the pre-processing process.In addition to the possibility described in detail above, it is also conceivable that data is only output by the memory module if the correct or permissible authentication feature is presented.

[0024] An intelligent memory module designed to solve the problem and carry out the method described above has at least one processing unit for executing program applications and its own power supply. According to the invention, the memory module is also equipped with a program application executable by the aforementioned processing unit, which continuously recodes the amount of data currently held in the memory module using a deterministic algorithm until one or more authentication features, which stop this process and are also evaluated by the program application, are presented. The program application is further designed to recalculate the amount of data originally transferred to the memory module from the amount of data available after the recoding process has been stopped.The aforementioned independent power supply is required to enable the continued execution of the program application and thus the continuous recoding of the amount of data held in the memory module.

[0025] Depending on how the method according to the invention is implemented in accordance with the respective intended use, the memory module described above with regard to its basic features can be supplemented by various units. The presence of such supplementary units, mentioned below as examples, corresponds in particular to which authentication feature is provided for stopping the process of continuous recoding of the data volume held by the memory module. Accordingly, with reference to the possible authentication features already mentioned in connection with the method, the memory module can be supplemented, for example, with a GPS receiver, a fingerprint sensor, an electronic clock, an NFC reader, or a connector (e.g., USB, mini-USB, or micro-USB). Certainly less relevant in practice, but also conceivable in principle, it is also possible to equip the memory module with a pressure sensor.In this respect, it is conceivable that the amount of data originally transferred to the memory module could only be accessed for reading at a location characterized by its high altitude and thus by particularly low air pressure. In this special case, a GPS module for precise location determination could possibly be dispensed with. However, the given example is only mentioned to indicate the possible range of types of authentication features that could be considered.

[0026] Based on the Fig. 1, an example of the invention is given below. The figure is a schematic representation, which essentially illustrates both a possible process sequence and the inclusion of a correspondingly designed memory module in this process sequence. Accordingly, the starting point is electronically coded information containing secrets, which is stored in the Fig. 1 is referred to as plaintext. In a first step, the data set encoding the information to be kept secret is subjected to pre-treatment in order to deliberately increase the entropy of the information contained therein.

[0027] The corresponding data volume containing the electronically encoded information is processed, for example, using a compression process or subjected to encryption. In the latter case, anyone with the appropriate key can decrypt the pre-processed data volume and thus retrieve the plaintext. This first pre-processing step is performed using a system that is not part of the independent storage module. The storage module is only temporarily connected to the system performing the pre-processing for the subsequent transfer of the pre-processed data volume to the storage module in the second step.

[0028] In the example shown, the memory module has access control. The access control is such that authentication with the memory module is required even for the purpose of transferring the preprocessed data to the memory module. This can be useful, for example, to prevent unintentional overwriting of content that was usually already stored in the memory module or to prevent unauthorized destruction of the information stored in the memory module. After the preprocessed data has been received by the memory module, it is subjected to continuous recoding within the memory module, preferably at very short intervals, using a deterministic algorithm controlled by a random number generator.It is merely a question of design whether the amount of data received by the memory module is recoded immediately at the moment of its receipt, before being stored for the first time in the memory module, or whether it is first temporarily stored in the pre-treated form and then subjected to repeated recoding, for example starting with a start signal triggered by an operating action on an operating element provided for this purpose on the memory module (not shown here).

[0029] The continuous recoding of the data volume transferred to the memory module, or the modified data volume resulting from a respective recoding process, occurs until the memory module is presented with an authentication feature (or a combination of several such features) that enables access to this data volume, namely a verification authentication feature, which matches the authentication feature that enables access to the encoded information, the reference authentication feature. The latter can, for example, be configured as follows: A person in possession of the memory module attempts to read its contents—more precisely, the data volume originally transferred to the memory module, encoding the information to be kept secret.At the moment of attempting to do so, the person in question is prompted, for example, via a display on the memory module (not shown here), to enter a PIN as an authentication feature. The recoding process continues until the PIN is successfully entered using a keypad on the memory module (also not shown). During this time, the person seeking access to the data originally transferred to the memory module is continuously presented with data that, at least for that person, contains no information whatsoever.This data, which is output until a valid authentication feature is presented and which is output via an output of the memory module, such as the display not shown above and / or a connection for connecting the memory module to another technical system, can, for example, be the amount of data currently stored in the memory module, representing the result of the multiple, ongoing recoding, or it can also be a random amount of data that is completely independent of this.

[0030] Only when the person in question has presented the authentication feature allowing access, i.e., entered the required PIN, is the influence of the memory module's random number generator effectively deactivated and the transcoding process stopped. Furthermore, the preprocessed data volume originally transferred to the memory module is calculated from the data volume currently held in the memory module.

[0031] The person gaining access to the information therefore initially only gains access to the data set that has been preprocessed to increase the entropy of the information they have received. From this data set, they can then regenerate the data set encoding the original information through post-processing—namely, by reversing the pre-processing process. This is done with the help of a system independent of the storage module, either by decompressing or decrypting the data set read from the storage module, depending on the type of pre-processing performed before the continuous recoding. As a result, the original plaintext is then preserved.

[0032] The following is a more concrete example of information to be stored in the memory module with secure access. Let's assume the information is a geometric figure, such as a representation of a tetrahedron in three-dimensional space, which is electronically encoded. Various methods exist for this, including Cartesian, polar, or cylindrical coordinates. However, the figure could also represent a much more complex object. Accordingly, it could be, for example, a CAD representation of an engine.

[0033] Some points (for example, three points in three-dimensional space) of the figure (e.g., the tetrahedron) are distinguished. For example, one point determines that a vertex of the tetrahedron in the "plain text" state is located exactly at the origin of the coordinate system. The second and third points determine how the tetrahedron is oriented in space in the "plain text" state, for example, by placing the second point on the x-axis (y- and z-coordinates are 0) and by placing the third point exactly on the y-axis.

[0034] One pretreatment that increases entropy could, for example, consist of transforming the data encoding the information into a tetrahedral representation. For example, the information to be stored (the secret) could be encoded in such a way that the coordinates have a high entropy (e.g., many digits or many decimal places). If, for example, the secret is a password, the password can be represented as a sequence of the ASCII codes of its letters. These ASCII codes can, in turn, be transformed into a single large number using a Gödelization rule and then, if necessary, converted into a fraction, so that, for example, instead of the number "12345678," the fraction "1.2345678" could be used as a coordinate of the tetrahedron.The subsequent recoding then consists in the tetrahedron being constantly shifted and rotated in space, controlled by a random number generator, without changing its size or shape.

[0035] Using the three designated points (coordinates), the tetrahedron can be repeatedly moved back to its original position (to its "plaintext" state) without requiring a counter for the recodings. It is also not necessary to perform the exact same forward movement in reverse; instead, the tetrahedron can be moved directly to the origin of the coordinate system and then (with the first point fixed) rotated and oriented as dictated by the other points.

[0036] The protected secret can, for example, be the location of an optional fourth or fifth distinguished point of the figure after the figure has been returned to its "plaintext" state (moved and rotated). Or it can be the direction in which a part of the figure (for example, the crankshaft in the engine) points in the plaintext state.

[0037] The output consists of the current "image" (a projection of the figure in space) being displayed on a screen in coded form. Something is always being sent (for example, a video signal), but an attacker cannot tell when the video signal is suitable for reading the secret. To do so, the recipient of the message would first have to stop the recoding (the figure is moved in space and rotates randomly).

Claims

[1] Method for the access-protected storage of electronically coded information in an intelligent electronic storage module, characterized by the procedural steps a.) Pretreatment of the data set encoding the information to be stored in the memory module to increase the entropy of the information represented by this data set in a uniquely reversible electronic processing step, b.) Transferring the data volume pretreated according to a.) into the memory module, c.) Recoding of the amount of data currently stored in the memory module by means of a deterministic algorithm controlled by a random generator, d.) continuous repetition of step c.) until at least one authentication feature authorising the reading of the information stored in it is presented to the memory module, whereby at an output for outputting the data set encoding the information to be kept secret, data without any information content is output in a constantly changing sequence until this authorising authentication feature is presented, e.) Stopping the random generator-controlled recoding and calculating the pre-processed data set originally transferred to the memory module, f.) Output of the amount of data originally transferred to the memory module, g.) Post-processing of the data output by the memory module by reversing the processing step performed to increase the entropy according to a.). [2] Method according to claim 1, characterized bythat a compression algorithm is used to pre-treat the amount of data to be transferred to the memory module and encoding the information to be stored. [3] Method according to claim 1, characterized by that the amount of data by which the information to be stored in the memory module is electronically coded is pre-treated by encryption before being transferred to the memory module. [4] Method according to claim 3, characterized by that a deterministic encryption algorithm is used to pretreat the amount of data to be transferred to the storage module. [5] Method according to claim 1, characterized by that a combination of several authentication features must be presented to the memory module to stop the continuous recoding controlled by the random generator. [6] Method according to claim 1 or 5, characterized bythat the deterministic algorithm used for the repeated transcoding of the data volume transferred to the memory module is parameterised by the at least one authentication feature required to stop the transcoding, i.e. the respective result of the transcoding itself depends on this feature. [7] Method according to claim 1 or 5, characterized by that a person wishing to access the amount of data transferred to the storage module after pre-treatment must authenticate himself by means of a PIN, which must be entered using a keypad with which the storage module is equipped. [8] Method according to claim 1 or 5, characterized by that a person wishing to access the amount of data transferred to the storage module after pre-treatment must authenticate himself by means of a biometric feature which must be presented to the storage module by means of at least one sensor with which the storage module is equipped. [9] Method according to claim 1 or 5, characterized by that the data of a GPS receiver are used as an authentication feature, whereby access to the amount of data transferred after pre-treatment to the memory module equipped with the GPS receiver is only possible at one or more locations specified by corresponding geo-coordinates. [10] Method according to claim 1 or 5, characterized by that an electronic ID stored on a token, namely on a passive transponder, is used as an authentication feature, which can be read by means of an NFC reader of the correspondingly equipped memory module. [11] Method according to claim 1 or 5, characterized bythat the data of an electronic clock are used as an authentication feature and that access to the data volume transferred after pre-treatment into the memory module equipped with the electronic clock is only possible at a specified time or within a specified period, whereby the time or period is determined by absolute time specifications or relative time specifications which are related to the time of the pre-treated data volume in the memory module. [12] Method according to claim 1, characterized by that authentication with the storage module is required to transfer the pre-treated data volume to the storage module. [13] Method according to claim 12, characterized bythat the authentication feature(s) used for authentication during the transfer of the pre-treated data set to the storage module and the authentication feature(s) enabling the subsequent reading of this data set from the storage module are part of a public key structure in which the authentication feature(s) used during the transfer of the pre-treated data set to the storage module form a public key and the authentication feature(s) enabling the subsequent reading of this data set from the storage module form a private key. [14] Memory module for the secure storage of electronically coded information, which has a processing unit for executing program applications and is equipped with its own power supply, characterized bythat a program application executable by its processing unit is stored in the memory module, after the start of which a constant recoding of the amount of data currently held in the memory module takes place using a deterministic algorithm and which is designed to - to stop the transcoding process and to calculate the data volume originally transferred to the storage module from the data volume present in the storage module at the moment the transcoding is stopped, and to control its output by the storage module, provided that the storage module is presented with at least one authentication feature authorising access to this data volume, and - to output data without any information content in a constantly changing sequence until the authorising authentication feature is presented at an output intended for outputting the data set encoding the information to be kept secret.

Citation Information

Patent Citations

  • Method for the authenticated transmission of a personalized data set or program to a hardware security module, in particular a franking machine

    DE102007011309A1

  • System and methods for epidemiological data collection, management and display

    US20130332195A1

  • Trust broker authentication method for mobile devices

    WO2015127253A1