Method for protecting a chip card terminal against unauthorized use
The described method ensures secure communication between chip cards and terminals by using symmetric keys and cryptographic information to establish protected channels, addressing the need for mutual authentication and preventing unauthorized access.
Patent Information
- Application Number
- DE102011079441
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2011-07-19
- Publication Date
- 2025-07-31
- Estimated Expiration
- 2031-07-19
AI Technical Summary
Existing methods for protecting chip card terminals against unauthorized use are inadequate, particularly in scenarios where user authentication is required but not limited to physical access to the terminal, and there is a need for mutual authentication between the chip card and the terminal.
A method involving the generation of a cipher using a first symmetric key derived from a first identifier on the chip card, transmitted to the terminal, which is decrypted using a second symmetric key to establish a protected communication channel only if the identifiers match, utilizing cryptographic information like public keys and discrete logarithmic cryptography to ensure secure communication.
This method provides robust protection against unauthorized use by ensuring secure, authenticated communication between the chip card and terminal, preventing unauthorized access by establishing distinct communication channels based on matching identifiers, thus enhancing security and integrity.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for protecting a chip card terminal against unauthorized use, a chip card terminal, a chip card, a computer program product and a signal sequence.
[0002] To activate a chip card function, prior user identification to the chip card may be required, as is well known in the art. The most common form of user identification is the entry of a secret code, generally referred to as a PIN (Personal Identification Number) or CHV (Card Holder Verification). Such codes generally consist of a numeric or alphanumeric character string. For user identification, the code is entered by the user on the keyboard of a chip card terminal or a computer connected to a chip card reader, and then sent to the chip card. The chip card compares the entered code with the stored code and then communicates the result to the terminal or computer by issuing a corresponding signal.
[0003] PINs can be divided into static and changeable PINs. A static PIN cannot be changed by the user and must be memorized. If the PIN is discovered, the card user must destroy their chip card to prevent unauthorized use and obtain a new chip card with a different static PIN. Likewise, the user needs a new chip card if they forget their static PIN.
[0004] A changeable PIN can be changed by the user at will. For security reasons, the currently valid PIN must always be provided when changing the PIN, as otherwise an attacker could replace any existing PIN with their own.
[0005] The situation is different with so-called super PINs or PUKs (Personal Unlocking Keys). These usually have more digits than the actual PIN and are used to reset a PIN's maximum entry counter (also known as a "misoperation counter"). The PUK also transfers a new PIN to the chip card, because a reset misoperation counter is of little use if you've forgotten your PIN. And this is usually the case when the misoperation counter has reached its maximum.
[0006] There are also applications that use transport PINs. The chip card is personalized with a random PIN, which the card user receives in a PIN letter. However, upon first entry, the chip card prompts the user to replace the personalized PIN with their own. In a similar procedure, called the "zero PIN procedure," the chip card is pre-assigned a trivial PIN, such as "0000," and the chip card also forces a change upon first use (see also DE 35 23 237 A1, DE 195 07 043 A1, DE 195 07 044 C2, DE 198 50 307 C2, EP 0 730 253 B1). Such procedures provide a so-called first-user function, which reassures the authorized user that no unauthorized third party has used the chip card prior to its initial use.
[0007] DE 198 50 307 C2 discloses a method for protecting chip cards against misuse. The chip card has a first-time user function that requires the user to enter a freely selectable personal identification number (PIN) upon initial use of the chip card's data and / or functions. Entering the PIN sets the chip card's data and / or functions to a used status. A subsequent change of the PIN is enabled by a higher-level unlock code.
[0008] State-of-the-art methods for verifying an identifier have also been disclosed that do not require the transmission of the identifier itself, such as Strong Password Only Authentication Key Exchange (SPEKE), Diffie-Hellman Encrypted Key Exchange (DH-EKE), Bellovin-Merritt protocol, or Password Authenticated Connection Establishment (PACE). The SPEKE protocol, for example, is known from www.jablon.org / speke97.html, US 6,792,533 B2, and US 7,139,917 B2. The DH-EKE protocol is also known from www.jablon.org / speke97.html, among others. The Bellovin-Merritt protocol is known from US 5,241,599, among others. The PACE protocol, which is particularly suitable for elliptic curve cryptography, is known from www.heise.de / security / news / meldung / 85024.
[0009] The use of PIN authentication is only suitable if a user actually has access to the chip card terminal, either via a PIN pad or a keypad. Thus, the chip card terminal ultimately authenticates itself to the card. However, there is also a need for either the chip card to authenticate itself to the terminal and / or for mutual authentication between the terminal and chip card.
[0010] DE 10 2007 000 589 B9 discloses a method for protecting a chip card against unauthorized use, comprising the following steps: - entering a first identifier into a chip card terminal, - generating an encrypted message from at least one first communication parameter using a first symmetric key derived from the first identifier, wherein a protected first communication channel between the chip card terminal and the chip card can be defined using the communication parameter, - transmitting the encrypted message via a predefined communication channel from the chip card terminal to the chip card, - attempting to decrypt the encrypted message using a second symmetric key by the chip card, wherein the result of the decryption is only the first communication parameter if the first symmetric key is equal to the second symmetric key,so that the protected first communication channel can only be defined between the chip card terminal and the chip card if the first identifier is correct.
[0011] DE 692 32 369 T2 discloses a mechanism for establishing confidential and authenticated communication between participants who share only a relatively insecure secret. A common secret authentication signal (e.g., a password) is used to encrypt at least part of one or more messages exchanged in a public key distribution system. To independently generate cryptographic keys, the participants use various signals derived from other signals, which are transmitted to the other participant in encrypted form using symmetric keys.
[0012] DE 198 50 308 A1 discloses a method for protecting chip cards from misuse in third-party devices, wherein a code is stored in each device, and the chip card is equipped with a first-time user function by which, when the chip card is used for the first time, the code is read from the device currently in use and stored as a reference code on the chip card, whereby the chip card is firmly bound to the device and can subsequently only be used together with it, wherein the code is then used either directly as an authentication code or indirectly as a key for an encryption and / or decryption function for authenticating the device to the chip card.
[0013] In contrast, the invention is based on the object of creating an improved method for protecting a chip card terminal against unauthorized use. The invention is further based on the object of creating an improved chip card terminal and an improved chip card, as well as a computer program product and a signal sequence.
[0014] The objects underlying the invention are achieved by the features of the independent patent claims. Preferred embodiments are specified in the dependent patent claims.
[0015] According to the invention, a method for protecting a chip card terminal against unauthorized use is provided. The method involves a chip card in addition to the chip card terminal itself.
[0016] A method is provided for the mutual protection of a chip card and at least one environment of the chip card against unauthorized use, wherein the environment comprises a chip card terminal, wherein the chip card has a first identifier, wherein the method comprises the following steps of an environment authentication: - generating a ciphertext from at least one first communication parameter using a first symmetric key derived from the first identifier, wherein a protected first communication channel between the chip card terminal and the chip card can be defined using the communication parameter, - Transmission of the ciphertext via a predefined communication channel from the chip card to the chip card terminal, - attempt to decrypt the ciphertext using a second symmetric key by the chip card terminal, whereby the result of the decryption is only the first communication parameter if the first symmetric key is equal to the second symmetric key, so that the protection of the first communication channel can only be defined between the chip card terminal and the chip card if the first identifier is correct, whereby the first communication parameter comprises cryptographic information, e.g. a public key of the chip card, whereby the chip card terminal, in the event that the decryption of the ciphertext is successful, can use the cryptographic information, e.g.derives a further symmetric key for encrypting the communication between the chip card terminal and the chip card according to the DiffieHellman (DH) method, whereby the encryption with the further symmetric key successfully authenticates the chip card to the environment.
[0017] A "chip card terminal" is defined here as any device designed to communicate with a chip card, for example, to send chip card commands to the chip card and receive corresponding responses from the chip card. Communication between the chip card and the chip card terminal can be contact-based, wireless, for example, via an RFID method, or either contact-based or wireless, particularly via a so-called dual-mode interface. The chip card terminal can be a so-called Class 1, 2, or 3 chip card reader with or without its own keyboard, or a computer to which a chip card reader is connected.The chip card terminal can also be a terminal designed for a specific purpose, such as a bank terminal for processing banking transactions, a payment terminal, for example, for purchasing electronic tickets, or an access terminal for granting access to a restricted area. Furthermore, the terminal can be used, for example, to control access to a ski lift or ski area, or to control access to a hotel room.
[0018] The term "protection of a chip card" here refers to the protection of the chip card as a whole or the protection of one or more of its functions. For example, the invention protects a chip card function that is particularly worthy of protection, such as a signature function for generating an electronic signature, a payment function, an authentication function, or the like.
[0019] The chip card thus generates an encrypted message from at least one first communication parameter using a first symmetric key. The first symmetric key can be the identifier itself or a symmetric key derived from the identifier. For example, the identifier serves as a so-called seed value for the chip card to generate the first symmetric key.
[0020] The at least one communication parameter is designed in such a way that it can be used to define the protection of the first communication channel between the chip card and the chip card terminal. In order to establish this protected first communication channel between the chip card terminal and the chip card, the ciphertext of the first communication parameter obtained using the first symmetric key is first transmitted from the chip card to the chip card terminal via a predefined communication channel. This predefined communication channel is therefore defined for establishing initial communication between the chip card and the chip card terminal. For example, during initial contact between the chip card and the terminal, the predefined communication channel can be negotiated and / or the communication channel is set and predefined by default.
[0021] After the encrypted data is transmitted from the chip card to the chip card terminal via this predefined communication channel, the chip card terminal attempts to decrypt this encrypted data using a second symmetric key. This decryption is only successful if the second symmetric key is identical to the first key.
[0022] Establishing a communication connection via the protected first communication channel is therefore only possible if the first identifier is "correct," i.e., if the first symmetric key is identical to the second symmetric key. In this case, the chip card and terminal are coordinated, since only in this case does the chip card terminal gain knowledge of the first communication parameter, which can be used to define the first communication channel.
[0023] If the first identifier is "not applicable", ie if the first symmetric key does not correspond to the second symmetric key, the result is that the decryption of the ciphertext received from the chip card by the chip card terminal using the second key does not produce the first communication parameter, but for example a second communication parameter which differs from the first communication parameter.
[0024] The second communication parameter can define a second communication channel that differs from the first communication channel, i.e., the protection of the second communication channel differs from that of the first communication channel. However, if the chip card terminal receives a signal on the first communication channel, it is ignored because the chip card terminal expects a signal on the second communication channel. As a result, no communication takes place between the chip card and the chip card terminal because the two communication channels use different protection, i.e., different encryption methods for communication.
[0025] According to the invention, the first communication parameter comprises cryptographic information, such as a domain parameter or a public key of an asymmetric key pair of the chip card. However, the first communication parameter can also comprise further information that specifies the physical and logical properties of the communication channel to be used for communication.
[0026] This may, for example, involve specifying a transmission frequency, a frequency hopping scheme, a coding method and / or a modulation method.
[0027] According to one embodiment of the invention, in order to define a symmetric key for communication between the chip card and the chip card terminal, for example according to the Diffie-Hellman method, the cryptographic information such as the public key of the chip card is encrypted with the first symmetric key obtained from the first identifier and sent to the chip card terminal via the predefined communication channel.
[0028] Only if the first symmetric key matches the second symmetric key does the chip card terminal receive the correct cryptographic information from the chip card. The chip card generates a third key from the cryptographic information of the chip card, e.g., using the Diffie-Hellman method. If the cryptographic information includes a public key, the chip card terminal generates a fourth key from the private key and the ciphertext decrypted using the second symmetric key, also using, e.g., the Diffie-Hellman method. The fourth key is only the same as the third key if the first symmetric key matches the second symmetric key.
[0029] The third and the identical fourth symmetric key are used to encrypt signals, in particular chip card commands and responses to such chip card commands, that are exchanged between the chip card and the chip card terminal via the first communication channel. This first communication channel is defined with regard to the data encryption to be used by the third key, which is used to encrypt communication via the first communication channel using a symmetric encryption method.
[0030] According to one embodiment of the invention, a method of discrete logarithmic cryptography (DLC) is used for generating a third key by the chip card and a fourth key by the chip card terminal, wherein the fourth key is only equal to the third key if the first symmetric key corresponds to the second symmetric key, ie the identifier is "correct".
[0031] In principle, any discrete logarithmic cryptography method can be used to determine the third key, such as those described in the National Institute of Standards and Technology (NIST) standard, NIST Special Publication 800-56A, March 2007, and in Standards for Efficient Cryptography, SEC1: Elliptic Curve Cryptography, Certicom Research, September 20, 2000, Version 1.0. Such methods require the generation of so-called domain parameters for the purpose of generating the identical third and fourth keys by the chip card.
[0032] According to one embodiment of the invention, a method of elliptic curve cryptography (ECC), in particular Elliptic Curve Diffie-Hellman (ECDH), is used as DLC.
[0033] According to one embodiment of the invention, the first identifier is used as a so-called seed value for deriving the first symmetric key. This generates a key of a longer length than would be the case if the first identifier were used directly as the key.
[0034] According to one embodiment of the invention, a second identifier is stored on the chip card terminal, from which the second key for decrypting the ciphertext initially received by the chip card can be derived. The second identifier can be used as a seed value to derive the second key from the second identifier.
[0035] According to one embodiment of the invention, the second identifier itself is not stored in the chip card terminal, but only the second key. The second key is preferably stored in a non-volatile, protected memory area of the chip card terminal.
[0036] In a further aspect, the invention relates to a chip card terminal having an interface for communication via a predefined communication channel and a plurality of further communication channels with a chip card, wherein the chip card terminal is assigned to at least one environment. Furthermore, the terminal comprises means for decrypting a ciphertext received on the predefined channel, which is encrypted using a first symmetric key, using a second symmetric key, wherein the decryption yields at least one communication parameter if a first identifier stored on the chip card is correct, wherein the communication parameter uniquely defines one of the further communication channels for the protected communication between the chip card and the chip card terminal of the environment.
[0037] According to one embodiment of the invention, the first communication parameter specifies cryptographic information, e.g., a public key or a domain parameter, and the terminal comprises means for performing a Diffie-Hellman method for deriving a further symmetric key using the cryptographic information.
[0038] According to one embodiment of the invention, the terminal further comprises means for carrying out a discrete logarithmic encryption method for generating the further symmetric key (S4), wherein the further symmetric key is provided for symmetric encryption of the communication between the chip card terminal and the chip card via the specified communication channel.
[0039] According to one embodiment of the invention, the terminal further comprises a non-volatile protected memory area for storing a second identifier from which the second key can be derived.
[0040] According to one embodiment of the invention, the terminal further comprises a protected non-volatile memory area for storing the second key.
[0041] In a further aspect, the invention relates to a chip card related to at least one environment of a chip card terminal, having a first identifier and means for generating an encrypted message from at least one first communication parameter using a first environment-related symmetric key derived from the first identifier, wherein a protected first communication channel can be defined between the chip card terminal and the chip card of the environment using the communication parameter, wherein the chip card has a first identifier stored for each environment, from which the first environment-related symmetric key can be derived. Furthermore, the chip card comprises means for sending the encrypted message to the chip card terminal via a predefined communication channel.
[0042] According to one embodiment of the invention, the chip card further comprises a memory area for blocking data, wherein the chip card is blocked if the blocking data has a predefined value, wherein the chip card is designed to receive the blocking data from the chip card terminal.
[0043] According to one embodiment of the invention, the chip card is a document, in particular a valuable or security document, an identification card, a means of payment, a signature card, a ski lift card, a hotel card or the like.
[0044] In a further aspect, the invention relates to a chip card terminal with a chip card terminal with an interface for communication via a predefined communication channel and a plurality of further communication channels with a chip card, means for decrypting a ciphertext received on the predefined channel, which is encrypted using a first symmetric key, using a second symmetric key, wherein the decryption results in at least one communication parameter if a first identifier previously entered into the chip card is correct, wherein one of the further communication channels for the protected communication between the chip card terminal and the chip card is uniquely defined by the communication parameter.
[0045] According to one embodiment of the invention, the chip card has a first-time user function. The unused chip card is in its first-time use state, in which a specific communication parameter is defined for the initial selection of the first communication channel. The chip card transitions from its first-time use state to a used state when it receives a chip card command on this first communication channel for the first time. For further use of the chip card, a different communication parameter must then be selected by the chip card terminal.
[0046] With a suitably selected first and second symmetric key, the method can be used for mutual authentication of the environment and cards. The cards issued for access to a specific environment (company, secure area, ski lift, etc.) contain a first symmetric key, which preferably cannot be read from the card and is known only to the environment's backend system.
[0047] A background system is understood to be a system to which a chip card terminal described above is connected. In this case, the process steps described with regard to the terminal can be performed entirely or partially by the background system, e.g., a computer system.
[0048] For example, if a person wants to access the environment to which the chip card terminal is assigned, they must authenticate themselves against the environment using the chip card. The described procedure is then executed between the card and the backend system. If the procedure is successfully completed, the card and system are mutually authenticated and thus authorized for access.
[0049] According to one embodiment of the invention, several first symmetric keys can be used in one card for different environments with chip card terminals. Such an environment can be spatially limited, e.g., a hotel room or a ski lift. A temporal limitation is also possible. For example, access is granted or denied depending on the current time.
[0050] According to one embodiment of the invention, the chip card terminal can read specific data stored on the card via the cryptographically secured channel established by the aforementioned method, for example, to verify or log individual data. Unauthorized systems cannot read such data because they do not know the second symmetric key required for this purpose.
[0051] According to one embodiment of the invention, the chip cards are contactless chip cards. These chip cards preferably support the PACE protocol according to TR-03110, V 2.05, of the BSI.
[0052] According to one embodiment of the invention, the card profile of the chip cards can support multiple PACE keys, ie multiple first symmetric keys for different environments.
[0053] According to one embodiment of the invention, a background system generates PACE keys for a specific environment, i.e., first symmetric keys for chip cards with a high entropy, such that the first symmetric key cannot be guessed with almost absolute probability. Systems are possible in which all access cards receive the same first symmetric key, and systems in which individual access cards receive individual first symmetric keys based on a (system) master key and a unique card characteristic (e.g., card number).
[0054] The generated first symmetric key is inserted into the cards for the aforementioned environment. According to one embodiment of the invention, the cards may contain data groups in which characteristics of the cards or cardholders are stored and which can only be read after successful execution of the aforementioned method with the aforementioned first symmetric key.
[0055] In the operational application, for example, a user can gain access to the environment by holding their chip card in the form of an access card against a card reader, i.e., a chip card terminal of the background system. Ideally, no user input is required. The background system initiates the execution of the above-mentioned procedure, e.g., using the PACE protocol with the corresponding first symmetric key.
[0056] If card-specific first symmetric keys are used, e.g. a unique card characteristic (optical or electronic) must be communicated between the terminal and the chip card, which enables the background system to calculate the individual first symmetric key and then apply it.
[0057] Using the above-mentioned procedure, not only can the card check whether the backend system was in possession of the correct first symmetric key, which might be necessary, for example, for data protection reasons for optionally stored data on the card, but the backend system can also check whether the card was in possession of the correct first symmetric key. If only the presentation of a suitable card is required for access, the validation check is already completed with the successful completion of the above-mentioned procedure.
[0058] The described procedure also establishes a cryptographic channel between the backend system and the card. If additional individual data needs to be used to verify access to the system, this data can be read from the card via this channel, for example. Since the card was authenticated before the data was read, this data can be considered trustworthy.
[0059] During normal operation of an access system, it may also be necessary to block cards. In environments with an individual first symmetric key, according to one embodiment of the invention, the cards can be blocked in the background system using the unique identifier.
[0060] According to a further embodiment of the invention, even with a uniform first symmetric key, cards with optional additional data can be easily blocked by the background system by denying access to certain data values. In environments with a uniform first symmetric key where no additional data is evaluated, the key must be changed in such a case, and all still valid cards must be written with the new first symmetric key.
[0061] The invention has the advantage that semiconductors and operating systems for German identity cards implement the PACE protocol and are thus certified. By applying the above-mentioned method, access cards for various purposes can be created on such cards by appropriately designing the file system. The protocols and security features can be disclosed to the customers. Background systems could be implemented by the customers themselves.
[0062] In a further aspect, the invention relates to a computer program product with instructions executable by a processor for carrying out the steps according to the described method.
[0063] In a further aspect, the invention relates to a signal sequence which, when stored in a computer, represents a sequence of instructions which, when executed on this computer, carries out the method described above.
[0064] Embodiments of the invention will be explained in more detail below with reference to the drawings. They show: Fig. 1 a block diagram of a chip card terminal and a chip card, Fig. 2 a flowchart of a communication process, Fig. 3 a block diagram of a chip card terminal and a chip card, Fig. 4 a flowchart of the communication process.
[0065] In the following figures, corresponding elements of the various embodiments are marked with the same reference numerals.
[0066] The Fig. Figure 1 shows a block diagram of a chip card 100. Chip card 100 has an interface 102 for communication with a chip card terminal 104, which has a corresponding interface 106. Interfaces 102 and 106 are preferably configured for wireless communication, for example, via radio, in particular using an RFID method.
[0067] For example, interfaces 102 and 106 are configured such that different communication channels can be established between interfaces 102 and 106, whereby these communication channels differ from one another on a physical and / or logical level. For example, communication channels with different transmission frequencies can be established. Communication channels can also be established based on different frequency hopping schemes. "Frequency hopping" here refers to frequency hopping methods, according to which the frequencies used for data transmission are continuously changed according to a defined scheme.
[0068] The interfaces 102, 106 can also be configured to establish different communication channels using different coding and / or modulation methods, such as frequency modulation, amplitude modulation, phase modulation, pulse width modulation, or other modulation methods. Communication channels can also generally differ with regard to the encryption used for communication on a physical channel.
[0069] The various communication channels that can be established between interfaces 102 and 106 are hereinafter referred to as the “set of communication channels”.
[0070] One of the communication channels 108 from the set of communication channels is predefined for the initial communication between the chip card 100 and the chip card terminal 104. For example, the communication channel is predefined with regard to its transmission frequency as well as the modulation and coding methods to be used.
[0071] The predefined communication channel serves to transmit a ciphertext 110 of the at least one communication parameter K1 from the chip card 100 to the chip card terminal 104 in order to inform the chip card terminal 104 which of the communication channels 112 of the set of communication channels is to be used for the subsequent communication with the chip card 100.
[0072] The communication parameter K1 thus contains information that uniquely specifies this communication channel 112. This information can be in the form of a code word. A so-called lookup table can be stored in a non-volatile memory in the chip card terminal 104, in which a specification of one of the communication channels from the set of communication channels is assigned to each possible code word. According to the invention, the communication parameter K1 comprises, for example, a public key of an asymmetric key pair of the chip card 100. In the embodiment shown, the communication parameter K1 therefore also comprises the public key of the chip card in addition to channel information in the form of, for example, a code word.
[0073] For selecting a communication channel from the set of communication channels, all possible communication channels that can be established between the interfaces 102, 106 or a selection thereof can be available, wherein each of the communication channels of the set of communication channels that can actually be used for communication between the interfaces 102, 106 is then assigned a unique code word, which can be transmitted as communication parameter 110 from the chip card 100 to the chip card terminal 104.
[0074] The chip card has a memory area in which an identifier 116 is located.
[0075] The terminal 104 has at least one processor 132 for executing an application program 124. The application program 124 can initiate the generation of a chip card command 122 to call a specific chip card function 120 on the chip card. For example, the application program 124 requires the chip card function 120 for an authenticity check, for generating a digital signature, for verifying an authorization, in particular an access authorization, for carrying out a financial transaction, or the like.
[0076] The processor 118 of the chip card 100 is used to execute the program instructions of a communication module 126, which is used to select the communication channel 112 from the set of communication channels and thus to select the communication parameter 110. The selection of the communication parameter 110 can be made according to a predetermined scheme or randomly, in particular pseudo-randomly. For example, a list of various communication parameters 110 is stored in the communication module 126 and is processed cyclically.
[0077] The processor 118 also serves to execute program instructions 128 for symmetric encryption of the communication parameters 110. The encryption is performed using the identifier 116. For this purpose, the program instructions 128 can contain a key generator 130.
[0078] The key generator 130 can be configured to generate a first symmetric key, referred to below as S1, from the identifier 116 as a seed value. The key S1 is used for the symmetric encryption of the communication parameter K1 selected by the communication module 126. The ciphertext of the communication parameter K1 resulting from the symmetric encryption with the key S1 is transmitted from the interface 102 to the interface 106 via the predefined communication channel 108.
[0079] The chip card terminal 104 has a processor 132, which serves to execute the program instructions of a communication module 134. The communication module 134 is designed to process the communication parameter K1 received from the chip card 100. The communication module 134 can, for example, use the communication parameter K1 as a key to access an assignment table, in particular a lookup table, in order to query the parameters of the communication channel 112 selected by the chip card 100, such as its transmission frequency and / or the coding and modulation methods to be used.
[0080] The processor 132 also serves to execute program instructions 136 for the symmetric decryption of the ciphertext 110 that the chip card terminal 104 has received from the chip card 100. For example, the chip card terminal 104 has a protected memory area 138 in which a second identifier 140 is stored.
[0081] The program instructions 136 may include a key generator 142 that uses the second identifier as a so-called seed value to derive a second key. This symmetric second key is referred to below as S2.
[0082] Alternatively, the key S2 can be stored in the protected memory area 138 of the chip card terminal 104 instead of the second identifier 140. The key generator 142 and storage of the second identifier 140 in the chip card terminal 104 are then unnecessary. In contrast to the prior art, the second identifier 140 does not necessarily have to be stored on the chip card terminal 104 as a reference value for verifying the correctness of the first identifier 116.
[0083] The chip card 100 may further include a first-use function. For example, the first-use status is defined by a specific communication parameter that specifies one of the communication channels of the set that must be used for the first use by the chip card.
[0084] Implementing the method according to the invention initially requires the following steps: Based on the identifier 116, the communication module 126 selects a first of the possible communication parameters, for example, from the predefined list of communication parameters, i.e., the communication parameter K1. In addition to physical and logical channel information, the communication parameter K1 also contains the public key of the chip card.
[0085] However, it should be noted that the physical and logical channel information is optional. The procedure can also be implemented using only the public key as the communication parameter K1 by means of a predefined fixed channel specification.
[0086] The key generator 130 generates the key S1 from the identifier 116. The communication parameter K1 is then encrypted by executing the program instructions 128 using the symmetric key S1. The resulting ciphertext 110 of the communication parameter K1 is then sent via the predefined communication channel 108 from the interface 102 to the interface 106 of the chip card terminal 104.
[0087] If necessary, the chip card terminal 104 derives the key S2 from the identifier 140 or directly accesses the key S2 in the protected memory area 138. Using the key S2, the chip card terminal 104 attempts to decrypt the ciphertext 110 of the communication parameter K1 received from the chip card 100 by executing the program instructions 136.
[0088] The result of this decryption attempt is a second communication parameter, referred to as K2 below, which is passed to the communication module 134. This communication parameter K2 is only identical to the communication parameter K1 if the condition identifier 140 = identifier 116 is met, since only then can the key S1 used for the symmetric encryption be equal to the key S2 used for the symmetric decryption of the ciphertext of the communication parameter K1.
[0089] A second communication channel 146 can be defined by the communication parameter K2, namely by the communication module 134 accessing its assignment table using the communication parameter K2. This second communication channel 146 is, in turn, only identical to the first communication channel 112 if the condition identifier 140 = identifier 116 is met.
[0090] After the transmission of the ciphertext of the communication parameter K1 via the predefined communication channel 108, the chip card terminal 104 generates the chip card command 122, which is sent from the interface 106 to the interface 102 via the first communication channel 112.
[0091] If the second communication channel 146 matches the first communication channel 112, the chip card command 122 is processed by the chip card and the chip card function 120 is called. As a result, the chip card 100 generates a response to the chip card command 122 and transmits this response back to the chip card terminal 100 via the first communication channel 112.
[0092] However, if the second communication channel 146 is not identical to the first communication channel 112, the chip card ignores the chip card command received on the first communication channel 112.
[0093] For example, communication channel 108 is defined by a transmission frequency of 9 GHz, communication channel 112 by a transmission frequency of 10 GHz, and communication channel 146 by a transmission frequency of 11 GHz. The transmission frequencies of communication channels 112 and 146 differ because identifiers 140 and 112 do not match. In this case, if chip card terminal 104 receives a signal at the frequency 10 GHz from chip card terminal 100, even though it expected reception at the frequency 11 GHz, this signal is ignored. This provides an implicit check of identifier 116 without the need to directly compare identifier 116 with identifier 140, and without the need for identifier 140 to be stored in the chip card terminal.
[0094] The Fig. Figure 2 shows a corresponding flowchart. In step 200, the identifier 116 in the chip card is read. Subsequently, in step 202, the chip card 100 sets the communication parameter K1 to select one of the communication channels from the set of communication channels. In step 204, the communication parameter K1 is symmetrically encrypted using the identifier 116. This can be done by deriving the symmetric key S1 from the identifier 116 using a key generator, which key is then used to encrypt the communication parameter K1.
[0095] In step 206, the ciphertext of the communication parameter K1 generated using the key S1 is transmitted from the chip card to the chip card terminal via a predefined communication channel.
[0096] In step 208, the chip card terminal 104 attempts to decrypt the communication parameter K1 based on the identifier 140. The relevant identifier 140 may be stored in a protected memory area of the chip card terminal and is used to derive a symmetric key S2.
[0097] Alternatively, the key S2 can be stored directly in the protected memory area of the chip card terminal.
[0098] Decrypting the ciphertext of communication parameter K1 with key S2 results in a communication parameter K2. This communication parameter K2 can be used to define a second communication channel in the set. Only if identifier 116 applies, i.e., if the condition identifier 116 = identifier 140 is met, are the communication channels specified by communication parameters K1 and K2 identical.
[0099] In step 210, the terminal generates a chip card command and sends it to the chip card via the first communication channel specified by the communication parameter K2 (step 212). In step 214, the chip card can only receive the chip card command if the second communication channel, which the chip card terminal is configured to receive, is identical to the first communication channel, i.e., if the condition identifier 116 = identifier 140 is met. Otherwise, the chip card ignores the ciphertext received on the first communication channel.
[0100] The communication parameter K1 comprises a public key of the chip card. The ciphertext of this public key, which has been generated using key S1 through symmetric encryption, is transmitted from the chip card to the chip card terminal. The chip card terminal only receives the correct public key of the chip card if the condition identifier 116 = identifier 140 is met, since only then can the ciphertext be decrypted using key S2 (compare the embodiment of the Fig. 1).
[0101] It should be noted here that the communication parameter can comprise a single encrypted data packet or a collection of several individually encrypted data packets with S1. In the latter case, these can contain individually encrypted physical and logical channel information, as well as the public key or general cryptographic information.
[0102] From the chip card's private key and the chip card terminal's public key, the chip card can derive a symmetric key S3, for example, using the Diffie-Hellman method. Accordingly, the chip card terminal can derive a symmetric key S4 from the chip card's public key and its private key, also using the Diffie-Hellman method. Keys S3 and S4 are identical if the condition identifier 116 = identifier 140 is met.
[0103] The first communication channel (compare communication channel 112 of the Fig. 1) is additionally defined according to the invention using the symmetric keys S3 = S4, in that subsequent communication between the chip card and the terminal is encrypted with these keys. The physical and logical channel information specified in the communication parameter K1 can be used in this case.
[0104] The chip card command sent from the chip card to the chip card terminal is encrypted with the symmetric key S3 and can only be decrypted, i.e., received, by the chip card terminal if the chip card command can be decrypted using the key S4. Otherwise, the chip card command is ignored.
[0105] The Fig. 3 shows a chip card terminal and a chip card, wherein, for example, a method for discrete logarithmic cryptography is used to generate the keys S3 and S4, respectively, wherein the cryptographic information is domain parameters.
[0106] In addition to the embodiment according to Fig. 1, the processor 118 is used to execute program instructions 148, which provide a so-called key establishment scheme for generating the symmetric key S3.
[0107] The key establishment scheme operates according to a discrete logarithmic cryptography (DLC) method, in particular elliptic curve cryptography (EEC), preferably an elliptic curve Diffie-Hellman (ECDH) method. To generate the symmetric key S3, program instructions 148 first generate initial domain parameters, referred to below as D1.
[0108] In addition, the communication module 126 can generate a first channel parameter KA1 or read it from a predefined list, which, for example, specifies the physical properties of the first communication channel. The first channel parameter KA1 corresponds to the channel parameter K1 in the embodiment of the Fig. 1.
[0109] The domain parameters D1 and the channel parameter(s) KA1 are encrypted using the key S1 by the program instructions 128. The ciphertext 110 obtained from KA1, D1 using the key S1 is transmitted from the interface 102 to the interface 106 via the predefined communication channel 108.
[0110] The chip card terminal 104 decrypts the ciphertext 110 using the symmetric key S2. As a result of the decryption, the chip card terminal 104 receives the second channel parameter KA2, which corresponds to the communication parameter K2 in the embodiment of the Fig. 1. Furthermore, the chip card terminal receives the domain parameter(s) D2. The channel parameter KA2 is processed by the communication module 134, for example, to determine the physical specification of the second communication channel 146.
[0111] The chip card terminal 104 has, in addition to the embodiment of the Fig. 1 program instructions 150, which correspond in functionality to the program instructions 148, and by which the key establishment scheme is implemented on the chip card side.
[0112] By executing the program instructions 148 on the chip card, the symmetric key S3 is derived from the domain parameters D1, which is stored in a memory 152 of the chip card 100. Accordingly, by executing the program instructions 150 on the chip card terminal 104, a symmetric key S4 is derived from the domain parameters D2, which is stored in a memory 154 of the chip card terminal 104.
[0113] The chip card command 122 is encrypted with the symmetric key S4 before being sent by the terminal and then transmitted over the communication channel specified by the channel parameter KA2. Receipt of the chip card command 122 by the chip card 100 is only possible if both KA2 = KA1 and D2 = D1, which in turn is only possible if the condition identifier 116 = identifier 140 is met.
[0114] A particular advantage here is that the transmission of the domain parameters D1 via the predefined communication channel 108 cannot be spied on by a third party, since the transmission of the domain parameters D1 takes place in an encrypted form.
[0115] The Fig. Figure 4 shows a corresponding flowchart. In step 400, the symmetric key S1 is derived from a first identifier.
[0116] In step 402, the key establishment scheme is started. Subsequently, in step 404, a set of domain parameters D1 is generated. Using the domain parameters D1, the symmetric key S3 is generated by the chip card. Furthermore, in step 406, the channel parameter KA1 is generated by the chip card or read from a predefined list.
[0117] In step 408, the domain parameters D1 and / or the channel parameters KA1 are encrypted with the key S1. For example, the domain parameters D1 and the channel parameters KA1 are concatenated, resulting in a single communication parameter, which is then encrypted with the key S1. Alternatively, only the domain parameters D1 or only the channel parameters KA1 or a respective subset of the domain and / or channel parameters are encrypted with the key S1. The ciphertext resulting from the encryption with the key S1, as well as any remaining unencrypted domain and / or channel parameters, are transmitted in step 410 from the chip card to the chip card terminal via the predefined channel (compare communication channel 108 of the Fig. 1 and Fig. 3) transferred.
[0118] In step 412, the chip card terminal attempts to decrypt the ciphertext using key S2. From this, chip card terminal 104 obtains channel parameters KA2 and domain parameters D2. Chip card terminal 104 derives key S4 from domain parameters D2.
[0119] In step 414, the terminal 104 generates a chip card command, which is encrypted with the key S4 (step 416) in order to transmit it via the first communication channel defined by the channel parameters KA2 (compare communication channel 112 in the embodiments of the Fig. 1 and Fig. 3). The terminal sends the chip card command in step 418.
[0120] Correct reception of this ciphertext by the chip card in step 420 is only possible if the second communication channel 146 matches the first communication channel 112, ie, if KA2 = KA1, and if, in addition, decryption of the chip card command is possible with the key S4, ie, if S4 = S3. However, the conditions KA2 = KA1 and S4 = S3 can only be met if identifier 116 = identifier 140.
[0121] There are various access or identification systems based on contactless cards, such as Legic, Mifare, and Hitag. Although these systems are widely used, the specifications of their functionality and thus their security are proprietary secrets of the manufacturers. With the introduction of the PACE (Password Authentication Connection Establishment) protocol in the German identity card and electronic residence permit, there is a publicly known protocol for authenticating an environment (a background system with card readers for contactless cards) against a contactless card, which is also implemented in semiconductors and card operating systems.
[0122] Currently, PACE is used only one-way to authenticate the environment against the card. The key for the PACE protocol is derived from a PACE password, which must be entered by a participating person as consent for authentication.
[0123] The process described above creates a publicly known and tested method that offers an alternative to the proprietary methods of the aforementioned manufacturers. This makes it possible to offer certified products for access and identification with contactless cards. List of reference symbols 100 chip cards 102 Interface 104 Chip card 106 Interface 108 predefined communication channels 110 communication parameters 112 first communication channel 116 Identification 118 processor 120 chip card function 122 Chip card command 124 application program 126 Communication module 128 program instructions 130 Key Generator 132 processor 134 Communication module 136 program instructions 138 protected memory area 140 Identification 142 Key Generator 146 second communication channel 148 program instructions 150 program instructions 152 memory 154 memory
Claims
[1] Method for mutually protecting a chip card (100) and at least one environment of the chip card (100) against unauthorized use, wherein the environment comprises a chip card terminal (104), wherein the chip card has a first identifier (116), wherein the method comprises the following steps of an environment authentication: - generating a ciphertext from at least one first communication parameter (K1; KA1, D1) using a first symmetric key (S1) derived from the first identifier, wherein a protected first communication channel (112) between the chip card terminal and the chip card can be defined using the communication parameter, - transmission of the ciphertext via a predefined communication channel (108) from the chip card to the chip card terminal, - attempting to decrypt the ciphertext using a second symmetric key (S2) by the chip card terminal (104), wherein the result of the decryption is only the first communication parameter if the first symmetric key is equal to the second symmetric key, so that the protected first communication channel can only be defined between the chip card terminal and the chip card if the first identifier (116) is correct, wherein the first communication parameter (K1;KA1, D1) comprises cryptographic information of the chip card, wherein, in the event that the ciphertext is successfully decrypted, the chip card terminal derives from the cryptographic information a further symmetric key (S4) for encrypting the communication between the chip card terminal and the chip card, wherein the encryption with the further symmetric key (S4) results in successful authentication of the chip card to the environment. [2] Method according to claim 1, wherein the cryptographic information comprises a first domain parameter (D1) for performing a discrete logarithmic cryptographic method for generating a third symmetric key (S3) by the chip card and the fourth symmetric key (S4) by the chip card terminal, wherein the third and fourth keys are identical if the first identifier is correct, wherein the third and fourth symmetric keys are provided for encrypting the communication between the chip card terminal and the chip card via the protected first communication channel. [3] The method of claim 2, wherein the discrete logarithmic cryptographic method is an elliptic curve cryptographic method [4] A method according to claim 2 or 3, wherein the discrete logarithmic cryptographic method is an elliptic curve DiffieHellman method. [5] Method according to one of the preceding claims, wherein a second identifier (140) is stored on the chip card terminal, from which the second key (S2) can be derived. [6] Method according to one of the preceding claims, wherein the second key (S2) is stored in a protected non-volatile memory area of the chip card terminal. [7] Chip card terminal (104), with - an interface (106) for communication via a predefined communication channel (108) and several further communication channels (112, 146, ...) with a chip card (100), wherein the chip card terminal (104) is assigned to at least one environment, - means (132, 136) for decrypting a ciphertext received on the predefined channel (108), which is encrypted using a first symmetric key (S1), using a second symmetric key (S2), the decryption yielding at least one communication parameter (K2; KA2, D2) if a first identifier (116) stored on the chip card is correct, the communication parameter uniquely defining one of the further communication channels for the protected communication between the chip card and the chip card terminal in the environment. [8] Chip card terminal (104) according to claim 7, wherein the first communication parameter comprises a public key and / or a domain parameter, and with means (132) for performing a Diffie-Hellman method for deriving a further symmetric key (S4) with the aid of the public key and / or the domain parameter. [9] Chip card terminal (104) according to claim 7 or 8, comprising means (150) for carrying out a discrete logarithmic encryption method for generating the further symmetric key (S4), wherein the further symmetric key is provided for symmetric encryption of the communication between the chip card terminal and the chip card via the defined communication channel (112). [10] Chip card terminal (104) according to one of the preceding claims 7 to 9, with a non-volatile protected memory area for storing a second identifier (140) from which the second key can be derived. [11] Chip card terminal (104) according to one of the preceding claims 7 to 10, with a protected non-volatile memory area for storing the second key. [12] Chip card (100) related to at least one environment of a chip card terminal (104) with a first identifier (116), and - means for generating a ciphertext from at least one first communication parameter (K1; KA 1, 01) with the aid of a first environment-related symmetric key (S1) derived from the first identifier, wherein with the aid of the communication parameter a protected first communication channel (112) can be defined between the chip card terminal and the chip card (100) of the environment, wherein the chip card has stored a first identifier (116) for each environment, from which the first environment-related symmetric key (S1) can be derived, - means for sending the ciphertext to the chip card terminal via a predefined communication channel (108). [13] Chip card (100) according to claim 12, further comprising a storage area for blocking data, wherein the chip card is blocked if the blocking data has a predefined value, wherein the chip card is configured to receive the blocking data from the chip card terminal. [14] Chip card according to one of the preceding claims 12 to 13, wherein the chip card is a document, in particular a valuable or security document, an identity card, a means of payment, a signature card, a ski lift card, a hotel card or the like. [15] A computer program product comprising processor-executable instructions for performing the steps according to the method of any one of the preceding claims 1 to 6. [16] A signal sequence which, when stored in a computer, represents a sequence of instructions which, when executed on that computer, carries out the method according to any one of the preceding claims 1 to 6.
Citation Information
Patent Citations
Methods for protecting a chip card against unauthorized use, chip card and chip card terminal
DE102007000589B9
procedure to protect chip cards from improper use in third-party devices
DE19850308A1
secret transmission protocol for secure communication
DE69232369T2