Reader application device

The communication system with a reader application card facilitates secure and adaptable data transfer, addressing the challenge of upgrading security levels in reader devices by enabling flexible security adjustments without hardware modifications.

DE102009009049B4Active Publication Date: 2025-12-11INFINEON TECHNOLOGIES AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102009009049
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2008-03-10
Filing Date
2009-02-17
Publication Date
2025-12-11
Estimated Expiration
2029-02-17

AI Technical Summary

Technical Problem

Existing reader devices face challenges in upgrading security levels due to hardware changes and certification requirements, making it difficult to meet varying security needs without overequipping or underequipping for specific applications.

Method used

A communication system with a reader application device that includes a reader application card, allowing seamless data transfer and control between the reader and user card, enabling easy upgrading of security levels without hardware modifications.

Benefits of technology

Enables flexible and secure data transfer with adaptable security levels, allowing readers to meet varying application requirements without hardware changes, enhancing security and cost-effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Communication system (100A) which includes the following features: a reader (110A); characterized by a reader application device (130A) with a reader application; wherein the reader (110A) is configured to operate under the control of the reader application to enable data to be transferred via the reader (110A) between the reader application device (130A) and a user device (120A); where a level of security of the data transmission is determined at least partially on the reader application device (130A).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Using contact-based and contactless read and / or write devices, commonly referred to as readers, that communicate with user cards, various applications are performed. These applications include banking applications, such as credit card processing, and identification applications, such as an electronic identity card (e-passport). Each application requires a certain degree or level of security against tampering and attacks, ranging from insecure, as in the case of near-field communication applications, to a high level of security, as in the case of banking applications.

[0002] To implement highly secure applications, there must be a high level of resistance to attacks not only by the user card but also by the reader.

[0003] Upgrading a reader's security level is difficult, if not impossible, for at least two reasons. First, an upgrade often requires a hardware change. Second, the upgraded reader must be customized and certified; since this is often not feasible in a secure environment, existing readers cannot be upgraded on-site. The result is a manufacturer's choice between equipping the reader with a lower security level, risking that the reader will not meet future higher security requirements, or equipping the reader with the highest possible security level, risking that the initial version of the reader is more expensive than necessary for applications requiring a lower security level.

[0004] German patent DE 198 45 582 A1 describes a smart card and a method for operating a computer program, wherein a background program in an end device reads a card configuration from the smart card and loads a card application into the memory of the end device according to the read configuration. The card application is loaded from the address specified for the respective card application, which can be a local or remote address.

[0005] DE 696 11 613 T3 describes a card reader / writer and a method for connecting a host application program to a data storage card with an associated card application.

[0006] DE 698 29 684 T2 describes a payment system and a system for loading credit values ​​onto a chip card using an open network with security card and credit card.

[0007] The object of the present invention is to create a communication system, a reader application device, a reader and a communication method with improved characteristics.

[0008] This task is solved by the characteristics of independent claims. Further details can be found in dependent claims.

[0009] One aspect of the present invention provides a communication system comprising a reader application device with a reader application and a reader configured to operate under the control of the reader application to enable data to be transmitted via the reader between the reader application device and a user device.

[0010] Preferred embodiments of the present invention are explained in more detail below with reference to the accompanying drawings. These show: Fig. 1A a contactless communication system with a reader application card according to an embodiment of the present invention; Fig. 1B a contact-based communication system with a reader application card according to a further embodiment of the present invention; and Fig. 2 a communication method according to an embodiment of the present invention.

[0011] The present invention provides a communication system with a reader that communicates with a user card. A separate reader application card with a reader application can be connected to the contactless or contact-based reader. Under the control of the reader application, the reader essentially acts as a data switch between the reader application card and the user card.

[0012] Fig. 1A is a contactless communication system 100A according to an embodiment of the present invention.

[0013] As it is in Fig. As shown in Figure 1A, the contactless card 120A, also known as a chip card, smart card, RFID identifier, or proximity IC card (PICC), operates on the basis of communication through an electromagnetic field with a read and / or write query device, commonly referred to as a proximity-coupled device (PCD) or reader 110A. The reader has a background system 140A for processing data that is read or written by the reader 110A.

[0014] The 110A reader typically transmits an electromagnetic carrier wave. This transmitted carrier wave serves two purposes: firstly, to power the 120A contactless card by inducing the energy required for its operation, and secondly, to initiate communication between the 120A card and the 110A reader according to a defined communication protocol. Communication protocols between the 120A contactless card and the 110A reader are described, for example, in ISO standards 14443 A / B, 15693, and / or 18000.

[0015] The 100A contactless communication system additionally includes a 130A reader application card with a reader application. The reader application can be, for example, an e-passport application, a near-field communication application, a banking application, a security feature, or any application based on radio frequency (RF) communication, etc. The 110A reader and the 130A reader application card communicate with each other in a similar way to how the 110A reader communicates with the 120A contactless card, i.e., using electromagnetic transmissions. The 130A reader application card can alternatively be self-powered.

[0016] When the reader application card 130A enters a query field of the reader 100A, the reader 100A operates under the control of the reader application, i.e., as a data switch or in a transparent mode, to allow data to be transferred via the reader 110A between the reader application card 130 and the user card 120A. Thus, the reader application in the reader application card 130 not only provides access to the user card 120A via the reader 110A, but also controls the reader 110A. The reader 100A can also operate under the control of the reader application to allow data to be transferred via the reader 110A between the reader application card 130, the user card 120A, and the background system 140A of the reader 110A.

[0017] The term "data" is not intended to be limiting. Data can encompass any form of commands and / or information.

[0018] The reader 110A can additionally have a selector 112A to select between multiple reader applications. The selection can be between an internal reader application of the reader 110A and an external reader application stored in the reader application card 130A. Alternatively, the selection can be between several reader applications stored on the same reader application card 130A, or on more than one reader application card 130A. A more detailed explanation follows.

[0019] If a reader application card 130A is not within a query field of the reader 100A, the reader 110A can operate according to an internal reader application, which is generally installed during manufacturing, but not necessarily. If the reader application card 130A enters a query field of the reader 100A, the selector 112A can choose between the internal reader application of the reader 110A and a reader application stored in a nearby reader application card 130A. If the selector 112A selects the reader application of the nearby reader application card 130A, the reader 110A begins to operate according to this external reader application. In other words, the reader 110A acts as a data switch under the control of the external reader application to allow data to be transferred via the reader 110A, at least between the reader application card 130A and the contactless user card 120A.

[0020] The reader application card 130A is not limited to having a single reader application, but can alternatively have multiple reader applications. When a reader application card 130A containing multiple reader applications is entered into a query field of reader 100A, selector 112A can either choose between the internal reader application of reader 110A and one of the multiple external reader applications stored in the nearby reader application card 130A, or alternatively, it can choose only between the multiple external reader applications. If selector 112A selects one of the external reader applications, reader 110A begins operating under the control of the selected external reader application to allow data to be transferred between reader application card 130A and contactless user card 120A via reader 110A.

[0021] There can also be more than one reader application card 130A near the reader 110A. In such a case, the selector 112A either chooses between the internal reader application of reader 110A and one of the external reader applications stored in the nearby reader application cards 130A, or alternatively, it can choose only between the external reader applications.

[0022] Alternatively, reader 110A may not have an internal reader application. In such a case, selector 112A selects only from all reader applications stored in each reader application card 130A located near reader 110A.

[0023] The selection of the reader application could be based, at least in part, on an application requirement of a user card 120A. For example, if a user card 120A is an ATM card, the selector 112A would select a reader application that is a high-security banking application, or possibly just a high-security application for the reader 110A, so that the reader 110A can be used with a banking application provided by a background system 140A of the reader 110A.

[0024] The reader application card 130A can include a display 132A and / or an input device 134A for displaying and / or entering any type of information, such as a login, password, application selection, etc. The display 132A and the input device 134A can be any type of known device suitable for the intended purposes. Although the display 132A and the input device 134A are shown as separate components, they can also be combined in a single device, such as a touchscreen display.

[0025] The 130A reader application card can provide the same level of security as the 110A reader. If the 130A reader application card is used for a banking application, the security level should be high. If the 130A reader application card is used for a near-field communication (NFC) application, the security level only needs to be low. Some applications do not require any security. However, it should be noted that a specific application is not necessarily tied to a particular security level. For example, the NFC application can have a high security level. The 130A reader application card of the present invention is advantageous because the 110A reader can be easily upgraded at the point of use without requiring any hardware modifications.

[0026] The 100A communication system is not limited to any specific form of contactless or electromagnetic communication and / or connection. For example, the contactless connection between the 110A reader and each of the 120A user card and the 130A reader application card can be based on radio waves, microwaves, terahertz radiation, infrared radiation, visible light, ultraviolet radiation, X-rays, gamma rays, Bluetooth, or any other form of contactless connection suitable for the intended purpose.

[0027] Fig. 1B is a contact-based communication system 100B according to a further embodiment of the present invention.

[0028] The contact-based communication system 100B is similar to the contactless communication system 100A described above, except that the reader 110B, the user card 120B, and the reader application card 130B are connected via a contact connection rather than a contactless connection. The contact connection can be, for example, a USB port, a serial port, a card reader, or any other contact connection suitable for the intended purpose.

[0029] The contact-based communication system 100B is otherwise similar to the contactless communication system 100A. Since an average expert in this field could recognize how such a contact-based communication system 100B would function from the description of the contactless communication system 100A, a description is omitted here for the sake of brevity.

[0030] Furthermore, the reader 110 is not limited to communicating only in either a contactless or contact-based manner. The reader 110 can communicate with either the user card 120 or the reader application card 130 in a contactless manner and with the other in a contact-based manner.

[0031] Although the application of the communication system 100 with the user card 120 and the reader application card 130 has been described, the application is not limited to these devices being in card form. The user card 120 can be any form of user device suitable for the intended purpose. Similarly, the reader application card 130 can be any form of reader application device suitable for the intended purpose.

[0032] One possible application of this invention is to enable a laptop, which initially has low security, to process credit card transactions requiring high security. More precisely, the reader 110A can be located in a laptop that has no security or a low level of security. When the reader application card 130A comes near the reader 110A, the laptop operates according to a high-security credit card application located in the reader application card 130A.

[0033] Another possible application is upgrading a wireless communication device, such as an NFC-enabled mobile phone or personal digital assistant (NFC = near field communication), into a secure device. More precisely, the non-secure wireless communication device is implemented in the 110A reader. When the 130A reader application card, running a high-security application, comes into proximity with the 110A reader, which incorporates the wireless communication device, the 110A reader operates transparently according to the high-security application's instructions. This allows data to be transmitted between the 130A application card, the 120A user card, and a background system 140A of the 110A reader. It should be noted that the background system 140A can be the reader 110A's own operating system or a system running on an external computer or server.

[0034] Fig.2 is a communication method according to an embodiment of the present invention.

[0035] When the user card 120 is connected to the reader 100, either contactlessly or via a contact-based connection, the reader 110 receives card data from the user card 120 (step 210).

[0036] When the reader application card 130 is connected to the reader 100, either contactlessly or via a contact-based connection, the reader 110 receives application data from the reader application card 130 (step 220). This application data causes the reader 110 to recognize the reader application card 130.

[0037] Reader 110 then begins to operate according to the selected reader application stored in reader application card 130, enabling data to be transferred via reader 110 between reader application card 130 and user card 120 (step 240). Data can also be transferred via reader 110 between reader application card 130, user card 120, and the reader's background system 140. Again, "data" is not meant to be limiting and can include all commands and / or information.

[0038] The invention is limited to the fact that the reader 110 receives map data from the user card 120 before receiving application data from the reader application card 130. The reader 110 can receive map data from the user card 120 after it has received application data from the reader application card 130.

[0039] Optionally, selector 112 can select one of a plurality of external reader applications from one or more reader application cards 130, or it can choose between an internal reader application and one or more external reader applications, as described above (step 230). This selection can be based on the received card data, as also described above.

[0040] Although specific embodiments have been presented and described herein, it is clear to those skilled in the art that a multitude of alternative and / or equivalent implementations can be used for the specific embodiments shown and described without departing from the scope of protection of the present invention. This application is intended to cover all adaptations or variations of the specific embodiments discussed herein. Therefore, this invention is limited only by the claims and their equivalents.

Claims

[1] Communication system (100A) comprising the following features: a reader (110A); characterized by a reader application device (130A) with a reader application; wherein the reader (110A) is configured to operate under the control of the reader application to enable data to be transferred via the reader (110A) between the reader application device (130A) and a user device (120A); where a level of security of the data transmission is determined at least partially on the reader application device (130A). [2] Communication system (100A) according to claim 1, wherein the reader application device (130A) is coupled to the reader (110A). [3] Communication system (100A) according to claim 2, wherein the coupling is contactless. [4] Communication system (100A) according to one of claims 1 to 3, wherein the user device (120A) is coupled to the reader (110A). [5] Communication system (100A) according to claim 4, wherein the coupling is contactless. [6] Communication system (100A) according to any one of claims 1 to 5, wherein the reader (110A) is further configured to operate under the control of the reader application to enable data to be transmitted via the reader (110A) between the reader application device (130A), the user device (120A) and a background system (140A) of the reader (110A). [7] Communication system (100A) according to claim 1, wherein the reader application device (130A) comprises a banking application. [8] Communication system (100A) according to claim 1, wherein the reader application device (130A) comprises a near field communication application. [9] Communication system (100A) according to any one of claims 1 to 8, wherein there is no security. [10] Communication system (100A) according to any one of claims 1 to 9, wherein the reader application device (130A) comprises a display (132A) and / or an input device (134A). [11] Communication system (100A) according to any one of claims 1 to 10, wherein the reader (110A) is a wireless communication device. [12] Communication system (100A) according to claim 11, wherein the wireless communication device is a mobile phone configured to communicate using near field communication. [13] Communication system (100A) according to one of claims 1 to 12, further comprising a plurality of reader application devices (130A). [14] Communication system (100A) according to claim 13, further comprising a selector (112A) configured to select a reader application device (130A) from the plurality of reader application devices (130A), at least partially based on an application requirement of the user device (120A). [15] Reader application device (130A), characterized by , that the reader application device (130A) is configured to provide a reader (110A) with a reader application to control the reader (110A) to enable data to be transferred via the reader (110A) between the reader application device (130A) and a user device (120A), wherein a level of security of the data transmission is determined at least partially on the reader application device (130A). [16] Reader application device (130A) according to claim 15, wherein the reader (110A) is further configured to operate under the control of the reader application to enable data to be transferred via the reader (110A) between the reader application device (130A), the user device (120A) and a background system (140A) of the reader (110A). [17] Readers (110A) characterized by , that the reader (110A) is configured to communicate with a reader application device (130A) which provides the reader (110A) with a reader application to control the reader (110A) to enable data to be transferred via the reader (110A) between the reader application device (130A) and a user device (120A), whereby a level of security of the data transmission is determined at least partially on the reader application device (130A). [18] Reader (110A) according to claim 17, which further comprises the following features: an internal reader application; and a selector (112A) configured to select between the internal reader application and the reader application of the reader application device (130A), wherein the selector (112A) selects the reader application of the reader application device (130A) when the reader application device (130A) is detected. [19] Reader (110A) according to claim 17 or 18, further comprising the following features: an internal reader application; and a selector (112A) configured to select between the internal reader application and the reader application device (130A), wherein the selector (112A) selects the reader application of the reader application device (130A) at least partially based on the user device (120A). [20] Communication system (100A) with a reader (110A) according to one of claims 17 to 19, wherein the reader application device (130A) is coupled to the reader (110A) without contact. [21] Communication system (100A) with a reader (110A) according to one of claims 17 to 20, wherein the user device (120A) is coupled to the reader (110A) without contact. [22] Communication procedure which includes the following steps: Receiving initial data from a user device (S210); characterized by the following steps: Receiving second data from a reader application device that includes a reader application (S220); and Transfer of the first data via a reader between the reader application device and the user device under the control of the reader application (S240); where the security level of the data transmission is determined at least partially on the reader application device. [23] Communication method according to claim 22, further comprising the transmission of the first data via the reader between the reader application device, the user device and a background system of the reader, under the control of the reader application.

Citation Information

Patent Citations

  • Chip card with stored information and a method for operating a chip card application

    DE19845582A1

  • interface FOR A MEMORY CARD

    DE69611613T3

  • Chip card-based system for paying and charging on the internet

    DE69829684T2

  • Secure device and mobile terminal which carry out data exchange between card applications

    US20050173518A1