INITIALIZE APPLICATION-SPECIFIC CRYPTOGRAMPICAL SECURITY FUNCTIONS

DE502022006785D1Active Publication Date: 2026-02-12BUNDESDRUCKEREI GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502022006785
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-02-19
Filing Date
2022-02-17
Publication Date
2026-02-12
Estimated Expiration
2042-02-17

AI Technical Summary

Technical Problem

Implementing uniform security standards across mobile devices from different manufacturers is challenging due to the difficulty in managing diverse security elements and cryptographic functions, especially when devices transition from secure production environments to user-controlled operation.

Method used

A method for initializing application-specific cryptographic security functions on mobile devices by installing a local security management program module, selecting and initializing security elements through an encrypted channel using a cryptographic key, and establishing cryptographic coupling with applets to provide application-specific security functions.

Benefits of technology

Enables secure implementation of cryptographic security functions across diverse mobile devices, allowing selection of suitable security elements based on application needs and use cases, ensuring uniform security standards despite manufacturer diversity and user control.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for initializing application-specific cryptographic security functions for a mobile application on a mobile device, a corresponding mobile device, and a system comprising a corresponding mobile device and one or more servers of one or more security management services for managing one or more security elements of the mobile device.

[0002] Mobile devices, such as smartphones, are ubiquitous. They are used in many areas of life and situations to perform a wide variety of tasks in the digital realm or with the aid of digital tools. The same mobile devices are used in environments with both low and high security requirements. Therefore, these devices must be able to meet even the most stringent security demands. The security of mobile devices, such as smartphones, has thus become a crucial requirement for device manufacturers, developers of the software installed on the devices, and providers of services that can be used with these devices.From the perspective of software manufacturers and service providers, implementing a uniformly high security standard for devices from different manufacturers is particularly difficult.

[0003] EP 3 048 553 A1 describes a method, a system, and units for distributing applets. The method includes the certification of an applet by a stakeholder. Certification involves a developer submitting the applet and an applet policy to the stakeholder for certification, the stakeholder generating an applet key, certifying the applet, and storing the applet key and the certified applet. The method further includes installing the applet in a secure environment that can be connected to a host.Installing the applet involves the host sending a security environment identifier and an applet identifier to the stakeholder, and the host requesting a token from the stakeholder, where the token is encrypted using a security environment key and the encrypted token includes at least the applet key, the host receiving the token, the host sending the certified applet and the token to the security environment, and the security environment installing the certified applet in the security environment using information extracted from the token.

[0004] EP 3 304 847 A1 describes a method for managing a secure channel between a server and a security element embedded in a first device. A user agent embedded in a second device establishes an HTTPS session with the server and retrieves a web application from the server. The method includes the steps of sending an application certificate to the web application, which is associated with specific data reflecting the server's identity; the security element receiving the application certificate and the specific data; the security element verifying the validity of the application certificate and consistently linking the application certificate with the specific data; and, upon successful verification, the security element and the server generating an ephemeral session key and using the ephemeral session key to open a secure channel.

[0005] US 2012 / 291095 A1 describes an independent security element manager that forwards secure payloads without modifying the secure payloads and without knowledge of the encryption keys used to encrypt them. Secure payloads from multiple issuers and multiple TSMs can coexist within one or more security elements due to the control exerted by the security element manager.

[0006] The invention is based on the objective of creating an improved method for initializing application-specific cryptographic security functions.

[0007] The problem underlying the invention is solved by the features of the independent claims. Embodiments of the invention are specified in the dependent claims.

[0008] Implementations include a method for initializing application-specific cryptographic security functions for a mobile application on a mobile device. The mobile device comprises a plurality of security elements usable for providing the application-specific cryptographic security functions for the mobile application, each managed by an external security management service. A local security management program module is installed on the mobile device for each of the multiple external security management services.

[0009] The procedure includes: Installing the mobile application on the mobile device, identifying the plurality of security elements available on the mobile device and usable for providing the application-specific cryptographic security functions for the mobile application, and the security management services managing the respective security elements, selecting at least one security element from the identified plurality of security elements and the at least one security management service managing the selected security element, sending an initial initialization request from the application to the at least one security management program module of the selected security management service installed on the mobile device to implement the application-specific cryptographic security functions for the application in the selected security element.Sending a second initialization request from the security management program module receiving the first initialization request over a network to a server of the selected security management service to implement the application-specific cryptographic security functions for the application on the selected security element; establishing a first encrypted channel between the selected security element and the server of the selected security management service using a cryptographic key of the security management service, wherein the cryptographic key of the security management service proves write access to the security element managed by the security management service that is reserved to the security management service.The installation of an application-specific applet associated with the application in the selected security element by the server of the selected security management service via the encrypted first channel, wherein the applet provides the application-specific cryptographic security functions for the application, cryptographically coupling the application with the installed applet to enable use of the application-specific cryptographic security functions provided by the applet for the application.

[0010] Implementation methods can offer the advantage that a multitude of security elements can be made available for use by applications on the mobile device. In particular, for example, a multitude of security elements can be provided that are not under the control of the mobile device manufacturer. This allows, for instance, the implementation of uniform security standards across mobile devices from different manufacturers.

[0011] For example, security functions can be securely implemented on a mobile device for use by an application. Such applications are generally installed while the mobile device is in operation. In this scenario, the mobile device is within a user's control and is generally already personalized, meaning it is assigned to that specific user. Therefore, the mobile device is no longer in a secure production environment, i.e., the manufacturer's security domain, which allows the manufacturer to implement security functions while excluding and / or minimizing the possibility of manipulation by third parties. If security functions are to be provided to an application under these conditions—i.e., during operation—this should be done in a way that effectively prevents manipulation.Implementation methods can have the advantage of enabling the secure implementation of security functions on the mobile device for use by an application during live operation.

[0012] Furthermore, a selection of security elements can be provided for an application, from which the user can choose which security element to employ. Thus, it is not only possible to provide different security elements for different applications, but also to provide several different security elements for one and the same application. This allows the selection of the most suitable security element for the application and / or its intended use.

[0013] For example, different security levels can be implemented for one and the same application by selecting different security elements, e.g., due to different cryptographic security functions with varying security levels. For instance, different security levels are assigned to the various security elements available for the application. Thus, different security requirements for the application can be met by selecting the appropriate security element(s).

[0014] Security requirements for an application can depend not only on generic properties and uses, but also on the specific use case of the application instance installed on the mobile device. For example, an application might be a digital ID application for identifying and / or authenticating the user of the mobile device, or an online banking application for conducting bank transactions, both of which generally require high security. Furthermore, the specific use case on the mobile device can be relevant to the security requirements an application must meet.For example, an application may have to meet higher security requirements if it is installed in a work environment on a work device, such as a work mobile phone, compared to installing the application for private purposes on a private mobile device.

[0015] First, a mobile application is installed on the mobile device. For example, the mobile application includes definitions specifying the requirements that security elements must meet to be used to provide application-specific cryptographic security functions for the installed mobile application. The installed application checks which security elements or security management services are available on the mobile device and selects at least one security element and at least one security management service to manage that security element. For example, the installed application can also select multiple security elements and their associated security management services. Selecting multiple security elements can have the advantage of providing fallback options in case problems arise with one security element or service.an administrative service.

[0016] The application sends an initialization request to each of the security management program modules of the selected security management services. Upon receiving these initialization requests, the security management program modules each send an initialization request over a network to servers of their assigned security management services. In response to these initialization requests, the respective servers establish an encrypted channel between the security management service and the security element of the mobile device managed by that security management service. For this purpose, each security management service uses an assigned cryptographic key to prove its reserved write access to the security elements.In other words, only the security management services have write access to the security elements. To establish a connection between the selected security elements of the application installed on the mobile device, the servers of the selected security management services install an application-specific applet for each of the corresponding applications within the security elements they manage on the mobile device. They do this, for example, using the previously established encrypted channels to the security elements. The installed applets provide, for example, the application-specific cryptographic security functions for the application on the security elements. Finally, a cryptographic connection is established between the application and each of the installed applets.The corresponding cryptographic coupling enables the application to use the application-specific cryptographic security functions provided by the applets.

[0017] Authentication refers to the verification of a claimed attribute of an entity, such as a user of a mobile device. During authentication, for example, corresponding evidence provided by the user is verified. The entity performs authentication by contributing to the process, i.e., by providing appropriate evidence such as authentication data or authentication factors for verification.

[0018] Authenticating a user with regard to the claimed property of authenticity, such as the authenticity of their person or identity, allows the authenticated user to perform further actions. For example, the user is granted access rights. A successfully authenticated user is considered authentic. Final confirmation of authentication can include authorization.

[0019] The user can authenticate themselves in various ways. For example, they can provide proof of knowledge, such as a PIN or password; proof of possession, such as a cryptographic key, certificate, or electronic device; and / or proof of personal characteristics, such as biometric features or behavioral traits.

[0020] A mobile device is understood to be a portable mobile communication device, such as a smartphone, a tablet or a smartwatch.

[0021] An authentication sensor is a sensor used to capture user authentication data for a mobile device. This authentication data can include, for example, the user's biometric data. The authentication sensor can be configured to capture this biometric data. Examples of biometric data include: fingerprint data, body geometry / anthropometric data such as facial, hand, and ear geometry, palmar ridge structure data, vein structure data such as hand vein structure data, iris data, retinal data, voice recognition data, and nail bed patterns. The authentication data can also include user-specific information such as a PIN or password. The authentication sensor can include an input device for entering authentication data, such as a PIN or password. This input device can include, for example, a keyboard and / or a touchscreen.

[0022] A challenge-response process provides a secure, knowledge-based authentication method between a first instance and a second instance. For example, the first security element is authenticated by the security applet of the second security element using a challenge-response process. Simultaneously, the response confirms successful user authentication, provided it is only generated if the first security element has successfully authenticated the user. Thus, in the case of a successful challenge-response process, the security applet knows not only that user authentication has been confirmed, but also that it was confirmed by the first security element and is therefore valid.

[0023] In a challenge-response process, a first instance presents a second instance with a task ("challenge"), for which the second instance must provide a correct answer ("response"). By providing the correct answer, the second instance proves that it knows a specific piece of information, which is a shared secret. The advantage of this method is that the shared secret is not transmitted and therefore cannot be compromised during the data exchange of the challenge-response process.

[0024] For example, the first instance generates a random number ("nonce") and sends it to the second instance. The second instance uses the shared secret for a cryptographic transformation of the nonce and sends the result as a response to the first instance for authentication purposes. For example, the nonce is combined with the shared secret, and a cryptographic hash function or encryption is applied to this combination. Furthermore, the shared secret, such as a symmetric cryptographic key, can be used to encrypt the nonce. The first instance, which knows both the nonce and the shared secret, can, for example, perform the same computation as the second instance and / or perform an inverse computation, such as decrypting the encrypted nonce using the shared secret.If the result of the first instance's calculation matches the result of the second instance's calculation or the challenge itself, the challenge-response procedure is successful and the second instance is successfully authenticated. Furthermore, a challenge-response procedure can also be based on an asymmetric cryptosystem and serve to prove to the first instance that the second instance possesses a private, and therefore secret, cryptographic key. Only the second instance knows the corresponding private cryptographic key, which it uses for a cryptographic transformation of the challenge, e.g., a nonce. This cryptographic transformation could, for example, involve digital signing.The first instance can use a public cryptographic key associated with the private cryptographic key to check, based on the response, whether the second instance actually has knowledge of the private cryptographic key, without the first instance itself gaining knowledge of the private cryptographic key during the check.

[0025] A secure element, also known as a "Secure Element" or "SE," is a protected component of a mobile device that provides cryptographic means. These cryptographic means are protected against manipulation and are accessible only to authorized services and applications, for example, via cryptographic keys. Specifically, the cryptographic means can only be added to, supplemented, modified, and / or deleted from the secure element by authorized services and applications.A security element thus provides a tamper-proof platform, for example implemented in the form of a secure single-chip microcontroller, on which applets and / or confidential and / or cryptographic data can be stored according to predefined rules and security requirements by reliably identified trusted entities and thus made available to authorized application programs and / or operating systems. A security element can be embedded or integrated, for example, non-destructively removable or permanently attached, i.e., not non-destructively removable. The security element can, for example, include a SIM, UICC, SmartMicroSD, smartcard, eSE, eSIM, or eUICC. For example, cryptographic keys are stored on a security element; that is, the security element includes a data vault for cryptographic keys or a "key store." Such a key store or key store...A security element can also be implemented as part of the main processor, for example, in a Trusted Execution Environment (TEE). For instance, the first security element can be implemented using a TEE. Security elements are implemented as hardware and / or firmware. Depending on the implementation, security elements or key stores can also be implemented as software. Two security elements are independent of each other, for example, if there is no common instance that has access rights to both.

[0026] An application program, also called an application or app for short, refers to a computer program that does not provide, support and / or enable the processing of system-related functionality.

[0027] An applet is a computer program that is not run as a standalone application. The term "applet" is a combination of the English words "application" and "snippet."

[0028] An operating system is a computer program or a collection of computer programs that provides, supports, and / or enables the processing of system functionalities. An operating system provides system resources. System resources are system elements or hardware components of a computer that are required by processes for correct execution.

[0029] A computer or computer system can be, for example, a stationary computer such as a personal computer (PC), service terminal, or server, or a mobile portable computer such as a laptop, tablet, smartphone, or other smart device. The computer may include an interface for connecting to a network, which can be a private or public network, in particular the internet. Depending on the design, this connection can also be established via a mobile network.

[0030] In this context, a "user computer system" refers to a computer system to which the user has access. This could be, for example, a desktop computer (PC), a service terminal, or a mobile portable communication device such as a laptop, tablet, smartphone, or other smart device.

[0031] In this context, a "service server" is understood to be a server or computer system on which a server program is executed and which provides the possibility to initiate, use, and / or execute an offered service via a network.

[0032] The term "program" or "program instructions" here refers without restriction to any type of computer program that includes machine-readable instructions for controlling a functionality of the computer.

[0033] In this and the following text, a "processor" is understood to be a logic circuit used to execute program instructions. The logic circuit can be implemented on one or more discrete components, particularly on a chip. Specifically, a "processor" is understood to be a microprocessor or a microprocessor system consisting of multiple processor cores and / or multiple microprocessors.

[0034] The term "storage" here refers to both volatile and non-volatile electronic storage media or digital storage media.

[0035] In this context, "non-volatile memory" refers to electronic storage for the permanent storage of data, particularly static cryptographic keys, attributes, or identifiers. Non-volatile memory can be configured as immutable memory, also known as Read-Only Memory (ROM), or as modifiable memory, also known as Non-Volatile Memory (NVM). Specifically, it can be an EEPROM, for example, a Flash EEPROM, or simply Flash. A key characteristic of non-volatile memory is that the data stored on it is retained even after the power supply is switched off.

[0036] In this context, an "interface" or "communication interface" refers to an interface through which data can be received and sent. This interface can be configured to be either contact-based or contactless. For example, a communication interface can enable communication over a network. Depending on its configuration, a communication interface can provide wireless communication using a mobile communication standard, Bluetooth, RFID, Wi-Fi, and / or NFC. Depending on its configuration, a communication interface can also provide wired communication. The communication interface can be internal or external.

[0037] Encrypted communication channels include, for example, encrypted end-to-end connections. An "encrypted end-to-end connection" or "encrypted end-to-end transmission channel" refers to a connection between a sender and a receiver with end-to-end encryption, where data to be transmitted is encrypted by the sender and only decrypted by the receiver. The encryption of transmitted data thus occurs across all transmission stations, so that intermediate stations cannot gain knowledge of the content of the transmitted data due to the encryption. The connection is cryptographically secured by encryption to prevent eavesdropping and / or manipulation of the transmission, for which a so-called secure messaging method can be used.End-to-end encryption, for example, relies on two symmetric cryptographic keys. One symmetric key is used to encrypt messages, and the other is used to authenticate the sender, for instance, using Message Authentication Code (MAC) algorithms. For example, during the setup of an encrypted communication channel, ephemeral keys are negotiated for encryption. These keys become invalid when the communication channel is terminated. Using different ephemeral keys for different communication channels allows for the parallel operation of multiple communication channels.

[0038] An encrypted communication channel can be established, for example, using the Transport Layer Security (TLS) protocol, such as part of the Hypertext Transfer Protocol Secure (HTTP) protocol.

[0039] Asymmetric key pairs are used in a variety of cryptosystems and play a crucial role in the secure transmission of electronic data. An asymmetric key pair consists of a public key, which is used to encrypt and / or decrypt data and may be shared with third parties, such as a sender or recipient of data, and a private key, which is used for encryption and / or decryption as well as for signing data and must generally be kept secret. The public key allows anyone to encrypt data for the owner of the private key or to verify digital signatures created with the private key. A private key allows its owner to decrypt data encrypted with the public key or to create digital signatures of data.

[0040] A digital signature of data involves, for example, generating a verification value of the data, such as a hash value, which is encrypted using a private cryptographic key from an asymmetric key pair that serves as the signature key. In the case of a signature, only the signer knows the private cryptographic key used to create the signature, i.e., the signature key, of the asymmetric key pair used for the signature. The signature recipient only possesses the public key, i.e., the signature verification key, of the asymmetric key pair used for the signature. The signature recipient can therefore verify the signature, but cannot calculate it themselves. For signature verification, the signature recipient calculates, for example, the verification value of the signed data and compares it with the result of decrypting the signature using the signature verification key.If the calculated hash value matches the decryption result, the signature is correct. Furthermore, if the authenticity of the signature verification key is confirmed, for example by a certificate, especially a PKI certificate, the signature is valid.

[0041] Here, a "certificate" refers to a digital certificate, also known as a public-key certificate (PKI certificate). A certificate consists of structured data used to associate a public key of an asymmetric cryptosystem with an identity, such as a person, institution, or device. For cryptographic security and to verify the authenticity of the certificate's data, it is signed by a certificate issuer. PKI certificates, which are based on asymmetric key pairs and, with the exception of a root certificate, are each signed by a certificate issuer with a signature key whose corresponding signature verification key is assigned to the certificate issuer via a PKI certificate from that issuer, constitute a Public Key Infrastructure (PKI). For example, the certificate can conform to the X standard.It must comply with 509 or another standard. For example, the certificate could be a Card Verifiable Certificate (CVC). An authorization certificate includes structured data that additionally defines the rights of the identity.

[0042] The PKI provides a system for issuing, distributing, and verifying digital certificates. In an asymmetric cryptosystem, a digital certificate can confirm the authenticity of a public cryptographic key and its permissible scope and application. The digital certificate itself is protected by a digital signature, the authenticity of which can be verified using the issuer's public key. To verify the authenticity of the issuer's key, another digital certificate is used. In this way, a chain of digital certificates can be built, each confirming the authenticity of the public key used to verify the preceding certificate. Such a chain of certificates forms a so-called validation path or certification path.Participants in the PKI must be able to rely on the authenticity of the last certificate, the so-called root certificate, and the key it certifies, without needing any further certificates. The root certificate is managed by a so-called root certification authority, whose assumed authenticity underpins the authenticity of all certificates in the PKI.

[0043] Digital certificates are verified, for example, by an independent, trusted authority (certification service provider / CSP or trust service provider / TSP), i.e., the certification authority that issues the certificate. Certificates can be made available to a broad range of people to enable them to verify the authenticity and validity of electronic signatures. A certificate can be associated with an electronic signature and provide a signature verification key in the form of the public key if the private key belonging to the signature verification key was used as the signature key. By making a certificate associated with a public key available to the public, a CSP / TSP enables users of asymmetric cryptosystems to associate the public key with an identity, such as a person, an organization, or a computer system.

[0044] Depending on the specific implementation, the electronic identity can include an officially recognized identity, such as an electronic identity created on the basis of an official identification document, such as a national identity card or passport.

[0045] A user's electronic identity is unique, meaning it is unambiguous and distinctive. It is defined based on characteristics known as identity attributes. An electronic identity includes, for example, personal data. Personal data refers to data that enables the identification of a person or can be attributed to a person to whom the personal data relates.

[0046] A user can have multiple different, application-specific electronic identities. These electronic identities can meet different security requirements.

[0047] According to some embodiments, an electronic identity stored on the mobile device and provided or managed by the ID application program can be used to identify and authenticate the user of the mobile device without additional hardware alongside the mobile device.

[0048] Identity attributes are requested, for example, by service providers for online services. In some implementations, the identity attributes required by a service provider for its online service are transmitted in encrypted and authentic form. For example, authorization certificates are used to regulate who is permitted to access or read which identity attributes. For instance, the required identity attributes are read by an ID provider authorized by means of an authorization certificate and made available to the requesting service provider. In some implementations, the ID provider only provides the requesting service provider with confirmation of the requested identity attribute(s).

[0049] User consent to the use of identity attributes and / or user authentication is carried out, for example, by checking one or more authentication factors, such as password, PIN, fingerprint or facial recognition.

[0050] According to embodiments, several security elements are selected from the identified plurality of security elements, along with their respective associated security management services that manage the multiple selected security elements.

[0051] Implementations can offer the advantage that multiple security elements can be used to initialize application-specific cryptographic security functions. This can, for example, provide fallback options in case problems occur with one of the security elements.

[0052] In some implementations, the multiple selected security elements are each managed by the same security management service.

[0053] According to some embodiments, at least some of the several selected security elements are managed by different security management services.

[0054] Depending on the implementation, all selected security elements are managed by different security management services.

[0055] In some implementations, the application sends initial initialization requests for all selected security elements to the security management program module of each selected security management service to implement the application-specific cryptographic security functions for the application in the respective selected security element. Second initialization requests are sent by the corresponding security management program modules of the selected security management services over a network to servers of the selected security management services.Between each of the selected security elements and the server of the respective security management service that manages that selected security element, an initial encrypted channel is established using a cryptographic key of the corresponding security management service. The server of the corresponding security management service then installs an application-specific applet associated with the application within the selected security element via this channel. The application is cryptographically linked to each of the installed applets to enable the application to use the application-specific cryptographic security functions provided by the respective applet.

[0056] Summarizing the initialization requests by the application can have the advantage of enabling more efficient communication.

[0057] According to some embodiments, the initial initialization requests for security elements managed by the same security management service are aggregated by the application and sent to the security management program module associated with the corresponding security management service.

[0058] According to embodiments, the first initialization requests for security elements managed by the same security management service are each sent individually from the application to the security management program module associated with the corresponding security management service.

[0059] According to embodiments, the second initialization requests for security elements managed by the same security management service are aggregated by the security management program module of the corresponding security management service and sent to the corresponding security management service.

[0060] Summarizing the initialization requests by the security management program module can have the advantage of enabling more efficient communication between the security management program module and the security management service.

[0061] According to embodiments, the second initialization requests for security elements managed by the same security management service are each sent individually from the security management program module of the corresponding security management service to the corresponding security management service.

[0062] If it is determined that no security management program modules of the security management services managing the corresponding security elements are installed on the security element for one or more of the selected security elements of the terminal, the corresponding security management program module(s) are installed on the mobile terminal according to the implementation.

[0063] Some implementations offer the advantage that security management program modules for the selected security elements can be installed subsequently, if necessary. This ensures that security management program modules are available on the mobile device for all selected security elements.

[0064] If it is determined that no security management program modules of the security management service(s) managing the security elements are installed on the security element for one or more of the terminal's security elements, the corresponding security management program module(s) are installed on the mobile terminal according to the implementation.

[0065] Some implementations offer the advantage that security management program modules for the selected security elements can be installed subsequently, if necessary. This ensures that security management program modules are available on the mobile device for all selected security elements.

[0066] According to embodiments, the selection of the one or more security elements and security management services that manage the corresponding security elements is made using a predefined compilation of application-compatible combinations of security elements and associated security management services, which have application-specific applets assigned to the application for installation in the corresponding security element.

[0067] Implementations can offer the advantage of providing a predefined set of security elements and security management services for selection. This predefined set allows for the identification of compatible combinations of security elements and their associated security management services. For example, the application includes the corresponding predefined set.

[0068] According to embodiments, the compilation is provided in the form of a list of combinations of a security element and a security management service that manages the corresponding security element.

[0069] According to embodiments, the selection of one or more security elements and security management services further includes: Outputting the identified security elements and security management services, which are compatible according to the predefined compilation, on a display device of the terminal device; receiving a user input with a selection via an input device of the terminal device, wherein the selection chooses one or more security elements and security management services from the output security elements and security management services.

[0070] Implementations can offer the advantage of allowing the user to select the security elements and security management services to be used and / or to confirm a suggested selection. For example, the identified security elements and security management services are displayed on a screen of the terminal device. The user can then confirm the displayed information. Alternatively, the user may be provided with options to select one or more of the security elements and security management services shown on the display. Using these options, the user can select the desired security elements and security management services.

[0071] According to embodiments, a ranking is defined for the combinations of compatible security elements and security management services, and the selection is made taking into account the corresponding ranking.

[0072] Implementation methods can have the advantage that preferences in the selection of security elements and security management services can be implemented through the predefined composition.

[0073] According to some embodiments, the compilation is provided in the form of a list, which defines a rank for each of the combinations of security element and security management service it includes.

[0074] According to embodiments, the selection includes at least the identified combination of compatible security element and security management service, which of the identified combinations is assigned the highest rank according to the ranking.

[0075] Implementations can have the advantage of ensuring that security elements and security management services that meet a predefined criterion, or that the fulfillment of this criterion, are selected with certainty.

[0076] According to embodiments, the selection comprises a predefined number of identified combinations of compatible security elements and security management services, to which the highest ranks of the ranking are assigned from among the identified combinations.

[0077] Design options can have the advantage of ensuring that the identified combinations with the highest ranks are selected.

[0078] According to embodiments, the method further comprises: Displaying the identified security elements and security management services that are compatible according to the predefined compilation on a display device of the terminal, the output showing the selection for review by a user; upon receipt of user input with confirmation of the selection, using the selection; upon receipt of user input with a change to the selection, using the changed selection.

[0079] Some implementations offer the advantage of allowing the user to either confirm a predefined selection or make changes to it. Confirmation uses the predefined selection, while changes result in the modified selection being used.

[0080] According to embodiments, the modification includes deleting one or more selected combinations or adding one or more of the identified combinations to the selection.

[0081] According to embodiments, the selection necessarily includes the identified combination of compatible security element and security management service, which of the identified combinations is assigned the highest rank according to the ranking.

[0082] According to embodiments, the selection necessarily includes the determined combination of compatible security element and security management service, which of the determined combinations is assigned the highest rank according to the ranking, regardless of user input.

[0083] According to embodiments, the selection necessarily includes at least two security elements that are managed by two different security management services, and / or at least two security elements that are managed by the same security management service.

[0084] Implementation methods can have the advantage of ensuring that different security management services are used. If one of the security management services fails, it can thus be ensured that another is available as a fallback.

[0085] By using at least two security elements that are managed by the same security management service, it can be ensured that in case of problems with one of the two security elements, at least the other security element is available, and thus the corresponding security management service.

[0086] According to some embodiments, the selection necessarily includes at least two security elements, which are managed by two different security management services, independent of user input.

[0087] According to some embodiments, the selection necessarily includes at least two security elements, which are managed by the same security management service, regardless of user input.

[0088] According to some embodiments, cryptographic coupling includes an initial authentication of the installed applet by the application.

[0089] Implementation methods can have the advantage that by authenticating the installed applet, the application can ensure that the installed applet is valid. For example, the initial authentication is performed using a challenge-response procedure.

[0090] According to embodiments, the method comprises generating an asymmetric key pair for the application, wherein the asymmetric key pair of the application comprises a public cryptographic key and a private cryptographic key of the application.

[0091] Some embodiments have the advantage that an asymmetric key pair is available to the application.

[0092] In some embodiments, the application's asymmetric key pair is generated locally on the mobile device. In others, the application generates the asymmetric key pair. In still others, a key generation and management program, such as a key store, generates the asymmetric key pair. For example, the key generation and management program is provided by the device's operating system.

[0093] According to some embodiments, the application is assigned a unique identifier. According to other embodiments, the installed application includes this unique identifier.

[0094] Design features can have the advantage that the application can be uniquely identified using the unique identifier.

[0095] In some embodiments, the application generates a unique identifier, for example during installation. In other embodiments, the application sends this generated unique identifier to a management server for registration, for example during installation, to manage the application.

[0096] In some implementations, the application receives the unique identifier from an administration server for managing the application, for example during installation.

[0097] According to embodiments, the method further comprises providing a certificate of the application, wherein the certificate of the application contains the public cryptographic key of the application and a unique identifier of the application.

[0098] Implementation methods can have the advantage that the application can be provided with the public cryptographic key and the unique identifier through the certificate.

[0099] In some implementations, the application's certificate is provided by an administration server for managing the application. For example, the administration server, acting as a certification server, generates the application's certificate. Alternatively, the administration server provides the certificate generated by a certification server to the application.

[0100] Depending on the specific implementation, providing the application certificate includes: Sending a certificate request from the application over the network to an administration server for managing the application, wherein the certificate request includes the application's public cryptographic key and the application's unique identifier; in response to the certificate request, receiving the application's certificate from the certificate server by the application.

[0101] In some implementations, the certificate request and / or the response are sent via an encrypted channel between the application and the management server.

[0102] According to some embodiments, the method further includes establishing the encrypted channel between the application and the certification server. In these embodiments, the encrypted channel is encrypted using TLS (Transport Layer Security) encryption. For example, TLS encryption is used in conjunction with HTTPS.

[0103] According to embodiments, the cryptographic coupling of the application with the installed applet includes: Sending an initial pairing request from the application to the security management program module of the selected security management service; sending a second pairing request from the security management program module receiving the first pairing request over the network to the server of the selected security management service; establishing a second encrypted channel between the selected security element and the server of the selected security management service using the cryptographic key of the security management service; writing the application's public cryptographic key to a memory area of ​​the selected security element allocated to the application-specific applet by the server of the selected security management service via the second encrypted channel.

[0104] Implementations can offer the advantage that the application's public cryptographic key can be stored in a memory area of ​​the selected security element assigned to the application-specific applet, i.e., a sub-security domain of the corresponding applet. Using the application's public cryptographic key, information encrypted with the application's private cryptographic key can be uniquely attributed to the application by the security element.

[0105] According to alternative embodiments, a symmetric key of the application can be used instead of the asymmetric public cryptographic key pair of the application.

[0106] A corresponding verification key can be provided, for example, by a root certificate. For instance, a certificate chain is provided in which each certificate includes a cryptographic key as a signature verification key, in particular a public cryptographic key, which can be used to verify a signature in the signature chain leading to the application's certificate.

[0107] According to embodiments, the first coupling request includes the application's public cryptographic key and / or the application's unique identifier.

[0108] According to embodiments, the second coupling request includes the application's public cryptographic key and / or the application's unique identifier.

[0109] According to embodiments, the cryptographic coupling further includes writing one or more verification keys to verify a signature of the application's certificate into the selected security element by the server of the selected security management service via the second encrypted channel.

[0110] According to embodiments, the cryptographic coupling further includes writing the unique identifier of the application to the selected security element by the server of the selected security management service via the second encrypted channel.

[0111] According to embodiments, the cryptographic coupling further comprises writing an initial asymmetric key pair of the application-specific applet to the memory area of ​​the selected security element allocated to the application-specific applet by the server of the selected security management service via the second encrypted channel, wherein the initial asymmetric key pair of the applet comprises an initial public cryptographic key and an initial private cryptographic key.

[0112] Implementations can have the advantage that the security management service provides the initial asymmetric key pair for the security element.

[0113] In some embodiments, the initial asymmetric key pair of the applet is generated by the management server for administering the application. In other embodiments, the server of the selected security management service sends a key request to the management server for administering the application. In other embodiments, the management server validates the key request. In other embodiments, the key request includes the application's public cryptographic key and / or its unique identifier. In other embodiments, validating the key request includes validating the application's public cryptographic key and / or its unique identifier. In other embodiments, the server of the selected security management service receives the initial asymmetric key pair of the applet from the management server in response to the key request.

[0114] In some implementations, the security management program module of the selected security management service receives the initial public key of the applet from the server of the selected security management service.

[0115] According to embodiments, the initialization of the cryptographic coupling further comprises generating the initial asymmetric key pair of the application-specific applet with the initial public cryptographic key and the initial private cryptographic key by the applet.

[0116] Implementations can have the advantage that the initial asymmetric key pair will generate the application-specific applet through the applet itself, i.e., in the security element.

[0117] In some embodiments, the applet sends its generated initial public key to the server of the selected security management service. In other embodiments, the security management program module of the selected security management service receives the applet's initial public key from the server of the selected security management service.

[0118] According to embodiments, the method further comprises receiving the initial public cryptographic key of the application-specific applet by the application from the security management program module.

[0119] Implementations can offer the advantage that the security management program module only needs to provide the application with the initial public cryptographic key of the application-specific applet. Using this initial public cryptographic key, the application can validate the applet's signatures. The security management program module receives the initial public cryptographic key, for example, from the security management service server and forwards it to the application.

[0120] According to some embodiments, the initial authentication of the applet by the application includes: The applet calculates a shared secret using its initial private cryptographic key and the application's public cryptographic key; the application calculates the shared secret using its private cryptographic key and the applet's initial public cryptographic key; the applet generates a random number; the applet generates a shared authentication key to authenticate information during communication between the application and the applet using the shared secret and the generated random number; the applet generates an authentication token using its authentication key and the application's public cryptographic key to authenticate the applet to the application.Sending the random number along with the authentication token from the applet to the application, the application generating the shared authentication key using the shared secret and the received random number, and authenticating the received random number and the applet by verifying the received authentication token using the generated shared authentication key and the application's public cryptographic key.

[0121] Implementation methods can have the advantage that an effective procedure for the initial authentication of the applet by the application can be provided.

[0122] In some embodiments, the authentication key is a key for generating a Message Authentication Code (MAC code). In other embodiments, the authentication token is a random number MAC code generated using the authentication key.

[0123] The authenticity of the transmitted identity attributes can be ensured, for example, by using a Message Authentication Code (MAC). A MAC is calculated using a MAC algorithm, which is provided with the data to be protected (i.e., the identity attributes) and a cryptographic key, such as a symmetric cryptographic key, as input data. Using this input data, the MAC algorithm calculates a checksum, which serves as the MAC. Block ciphers or hash functions, for example, can be used to calculate MACs. A Keyed-Hash Message Authentication Code (HMAC) can be used as the MAC, for which a cryptographic hash function, such as the Secure Hash Algorithm (SHA), and a secret cryptographic key, such as a symmetric cryptographic key, are used.

[0124] To secure data transmission, such as the transmission of identity attributes, a cryptographic key, for example a symmetric cryptographic key, is agreed upon between the sender (e.g., the applet) and the receiver (e.g., a reading computer system). The sender uses this cryptographic key to calculate a MAC (Mixed Authentication Key) for the data to be transmitted and sends the calculated MAC along with the data to the receiver. The receiver, in turn, calculates a MAC for the received data using the cryptographic key and compares the result with the received MAC. If the calculated MAC matches the received MAC, the integrity check is successful, and the received data is considered authentic.

[0125] In the case of a MAC (Mutual Authentication Key), both the sender and receiver must know the cryptographic key used, unlike when using pure hash functions or signatures. Pure hash functions, for example, do not use cryptographic keys. If the hash functions are public, anyone can calculate the hash value, especially for manipulated messages. In the case of a signature, only the signer knows the private cryptographic key used to create the signature, i.e., the signature key, of an asymmetric key pair used for the signature. The signature receiver only has the public key, i.e., the signature verification key, of the asymmetric key pair used for the signature. The signature receiver can therefore verify the signature using the signature verification key, but cannot calculate it themselves.

[0126] According to some embodiments, the verification of the received authentication token by the application includes: The application generates an authentication token using the shared authentication key generated by the application and the application's public cryptographic key, compares the authentication token generated by the application with the authentication token received by the applet, and if the two authentication tokens match, the verification is considered successful and the applet is thus considered successfully authenticated.

[0127] According to embodiments, the cryptographic coupling further comprises the generation of a common symmetric cryptographic key by the applet and by the application for encrypting the communication between the application and the applet using the shared secret and the random number.

[0128] Implementations can have the advantage that communication between the applet and the application can be encrypted effectively and efficiently using the shared symmetric cryptographic key.

[0129] In some embodiments, the common symmetric cryptographic key is calculated by the applet and by the application, each together with the common authentication key.

[0130] Implementations can have the advantage that, using the common authentication key, the authenticity of messages exchanged between the application and the applet can be validated.

[0131] Embodiments comprise a mobile terminal comprising a processor, a communication interface for communication over a network, and a plurality of security elements, wherein the security elements are each usable for providing the application-specific cryptographic security functions for mobile applications and are each managed by an external security management service. wherein a local security management program module is installed on the mobile device for each of the multiple external security management services, wherein the processor is configured to execute a procedure for initializing application-specific cryptographic security functions for a mobile application on a mobile device, which includes: installing the mobile application on the mobile device, determining the multiple security elements available on the mobile device and usable for providing the application-specific cryptographic security functions for the mobile application, and the security management services managing the respective security elements by the installed application.Selection of at least one security element from the identified plurality of security elements and the at least one security management service that manages the selected security element; sending an initial initialization request from the application to the at least one security management program module of the selected security management service installed on the mobile device to implement the application-specific cryptographic security functions for the application in the selected security element; sending a second initialization request from the security management program module receiving the first initialization request over a network to a server of the selected security management service to implement the application-specific cryptographic security functions for the application on the selected security element.Establishing a first encrypted channel between the selected security element and the server of the selected security management service using a cryptographic key of the security management service, wherein the cryptographic key of the security management service proves write access to the security element managed by the security management service that is reserved to the security management service; installing an application-specific applet associated with the application in the selected security element by the server of the selected security management service via the encrypted first channel, wherein the applet provides the application-specific cryptographic security functions for the application.Cryptographic coupling of the application with the installed applet to enable the use of the application-specific cryptographic security features provided by the applet for the application.

[0132] According to embodiments, the mobile device is configured to execute each of the previously described embodiments of the method for initializing application-specific cryptographic security functions.

[0133] Embodiments further include a system comprising a mobile terminal according to the embodiments described above and one or more servers of the one or more selected security management services for managing the selected one or more security elements of the mobile terminal.

[0134] According to embodiments, the system is configured to execute each of the previously described embodiments of the method for initializing application-specific cryptographic security functions.

[0135] In some embodiments, the system also includes an administration server for managing the application.

[0136] According to embodiments, the system is configured to execute each of the previously described embodiments of the method for initializing application-specific cryptographic security functions, which includes a management server.

[0137] Embodiments of the invention will now be explained in more detail with reference to the drawings. These show: Figure 1 is a schematic diagram of an exemplary mobile device, Figure 2 is a schematic diagram of an exemplary security management service server, Figure 3 is a flowchart of an exemplary procedure for initializing application-specific cryptographic security functions, Figure 4 is a flowchart of an exemplary procedure for cryptographically coupling an applet with an application, Figure 5 is a flowchart of an exemplary procedure for cryptographically coupling an applet with an application, Figure 6 is a schematic diagram of an exemplary mobile device, and Figure 7 is a schematic diagram of an exemplary system.

[0138] Elements of the following embodiments that correspond to each other are marked with the same reference numerals.

[0139] Figure 1Figure 100 shows an exemplary mobile device 100, for example a smartphone, which includes a memory 104 containing program instructions that are executed by a processor 102. The program instructions can, for example, be an operating system 106 installed on the mobile device 100. Furthermore, applications or application programs 108 can be installed on the mobile device 100. For example, the mobile device 100 includes a security element 110, which is assigned to the operating system 106 and provides cryptographic means for it, such as cryptographic keys, cryptographic functions, and / or cryptographic protocols. The security element 110 of the operating system 106, for example, represents a key store or...Key storage is provided for storing cryptographic keys, such as symmetric, public, and / or private cryptographic keys, and certificates, such as authorization certificates, public-key certificates, and / or attribute certificates. The cryptographic means provided by the first security element 110 enable the operating system 106, for example, to encrypt and / or decrypt data, as well as to create and / or verify signatures. For example, the cryptographic means provided by the first security element 110 enable the operating system 106 to execute or participate in challenge-response procedures.

[0140] For example, the mobile device 100 includes additional security elements 112, 116. These security elements 112, 116 can provide cryptographic security functions for applications 108 stored on the mobile device 100. For this purpose, applets 114 can be installed on the security elements 112, 116, each assigned to one of the applications 108 and providing application-specific cryptographic security functions for that application. The applications 108 are, for example, applications that manage electronic identities, for whose secure use the cryptographic security functions provided by the respective application 108's applet 114 can be used. For example, an application 108 can use different applets 114 for different electronic identities.Applets 114 enable applications 108 to provide application-specific cryptographic means for each application 108. Applets 114 provide these application-specific cryptographic means for the respective applications. For example, the application-specific cryptographic means include cryptographic keys, cryptographic functions, and / or cryptographic protocols.

[0141] Applets 114 and the corresponding storage areas of security elements 112 and 116, respectively, each provide a key store for storing cryptographic keys for their individually assigned application 108, such as symmetric, public, and / or private cryptographic keys, and certificates, such as authorization certificates, public-key certificates, and / or attribute certificates. The application-specific cryptographic means provided enable applications 108, for example, to encrypt and / or decrypt data, such as data of the electronic identities they manage (e.g., identity attributes), as well as to create and / or verify signatures.For example, the provided application-specific cryptographic means enable applications 108 to execute or participate in challenge-response procedures. The security elements 110, 112, and 116 can, for example, each be implemented as an eSIM and / or eUICC.

[0142] Security elements 112 and 116, for example, are each managed by an external security management service. These security management services are configured to initialize application-specific cryptographic security functions for applications 108 installed on the mobile device on the security elements 112 and 116 they manage. To do this, the security management services install applets 114 for the corresponding applications 108 on the security elements 112 and 116 they manage. These applets are then coupled with the applications 108 and provide application-specific cryptographic security functions for them.For communication with the security management services, the mobile device 100 includes, for example, security management program modules 109 and 111, each of which is assigned to one of the security management services that manage one of the security elements 112 and 116 of the mobile device 100. Using the security management program modules 109 and 111, the installation of applets 114 in the security elements 112 and 116 can be initiated for applications 108 installed on the mobile device 100, thereby providing application-specific cryptographic security functions. For example, an applet 114 of an application 108 can be installed on a security element 112 or 116.For example, an applet 114 of an application 108 can also be installed in a plurality of security elements 112, 116, so that the application 108 is enabled to use several security elements 112, 116 and the application-specific cryptographic security functions provided by them to the application 108 via the applet 114.

[0143] Furthermore, the mobile device 100 includes a user interface 118, which, for example, comprises a display, in particular a touchscreen. Using the user interface 118, the user can interact with the mobile device 100. For example, the user may be prompted to provide authentication data or authentication characteristics. To capture user authentication data, the mobile device 100 includes a sensor or authentication sensor 120, which, for example, can be integrated into the user interface 118 or implemented as a standalone component. The authentication data can include, for example, biometric data of the user, such as: fingerprint data, body geometry data / anthropometry data, such as facial, hand, and ear geometry data, palmar ridge structure data, vein structure data, such as hand vein structure data, iris data, retina data, voice recognition data, and nail bed patterns.Authentication data can include user-specific information such as a PIN or password. Furthermore, it can encompass user behavioral characteristics or data, such as movement data from the mobile device (100), generated by the user's gross and / or fine motor movements while carrying and / or using the device. Such user authentication can be a prerequisite for releasing identity attributes of the electronic identity for reading by a computer system. Appropriate user authentication ensures that the mobile device (100) is being used by an authorized user.Secondly, the provision of authentication data by the user can constitute the user's consent to the reading of the identity attributes of the electronic identity by the reading computer system. Finally, the mobile device 100 includes a communication interface 122, such as an antenna, which is configured for contactless or contact-based communication with the reading computer system. For example, communication with the reading computer system can take place via a network, such as an intranet or the internet.

[0144] Figure 2Figure 240 shows an exemplary server 240 of a security management service. The security management service server 240 comprises a processor 202, a memory 204, and a communication interface 210. Memory 204 stores program instructions 208 for managing a security element managed by the security management service on a mobile device. When the program instructions 208 are executed, the processor 202 directs the security management service server 240, for example, to initialize an application-specific applet 114 for an application installed on the mobile device within the security element managed by the security management service on that mobile device. To prove write authorization to install the applet 114 on the security element, the security management service server 240 uses, for example, a cryptographic key.Security Management Service server 240, for example, has multiple applets 114 and 117 for various applications, which are provided to the Security Management Service by the publishers of the respective applications. When an application is installed on a mobile device with a security element managed by the Security Management Service, Security Management Service server 240 can install the application's corresponding applet 114 on the security element to provide the application with application-specific cryptographic security features.

[0145] This cryptographic key 206 can, for example, be a symmetric or a private cryptographic key of an asymmetric key pair. For example, the security element used to validate the write authorization of the security management service also has the symmetric cryptographic key or a public cryptographic key of the asymmetric key pair. For example, the security management service server 240 uses an authorization certificate to verify write authorization. For example, the security element has means to validate the authorization certificate, such as a signature verification key, e.g., a public cryptographic key, to verify the signature of the authorization certificate. The signature verification key can, for example, be included in a root certificate stored in the security element.The means for validating the write authorization of the security management service are, for example, already incorporated into the security element during the manufacturing of the security element and / or the mobile device.

[0146] Figure 3 This document demonstrates an exemplary procedure for initializing application-specific cryptographic security functions for a mobile application on a mobile device. The mobile device comprises, for example, a plurality of security elements that can be used to provide the application-specific cryptographic security functions for the mobile application. Each individual security element is managed by an external security management service. For each of these external security management services, a local security management program module is installed on the mobile device.

[0147] In Block 300, a mobile application is installed on the mobile device. In Block 302, the installed application determines which of the security elements available on the mobile device can be used to provide application-specific cryptographic security functions for the mobile application. In Block 304, at least one of the determined security elements is selected. For example, several of the determined security elements may be selected. The selection can be made automatically. For example, a selection proposal can be generated and displayed to the user of the mobile device. The user can, for example, accept or modify the proposal. According to some implementations, part of the proposal is mandatory and cannot be changed by the user, while another part is optional and can be modified by the user.The selected security elements are each managed by a security management service. A security management program module is installed on the mobile device for each of these security management services. If a security management program module is missing for one of the security management services, it can be installed during the procedure. For example, the following is executed for each of the selected security elements: In block 306, an initialization request is sent from the installed application to the security management program module of the security management service that manages the selected security element, which is installed on the mobile device.The initialization request requests the implementation of application-specific cryptographic security features for the application in the selected security element, which is managed by the corresponding security management service. In block 308, the security management program module sends an initialization request over a network to a server of the selected security management service, requesting that the security management service implement the application-specific cryptographic security features for the installed application on the selected security element.

[0148] Block 310 establishes an encrypted channel between the selected security element and the server of the selected security management service. This is achieved, for example, by using a cryptographic key belonging to the security management service. This cryptographic key, for instance, proves that the security management service has write access to the security element it manages. Block 312 uses this encrypted channel to install an application-specific applet, associated with the application, within the selected security element by the server of the selected security management service. The installed applet provides application-specific cryptographic security functions for the application.In block 314, the application is cryptographically coupled with the installed applet, thereby enabling the application to use the application-specific cryptographic security functions provided by the applet. The applet is further equipped, for example, with an initial asymmetric key pair. This initial asymmetric key pair is injected, for instance, by the server of the selected security management service into the memory area of ​​the selected security element allocated to the application-specific applet via the encrypted channel. Alternatively, the initial asymmetric key pair is generated by the application-specific applet and stored in the memory area of ​​the selected security element allocated to the application-specific applet.For example, a public cryptographic key of the initial asymmetric key pair is provided to the application by the server of the selected security management service via the security management program module of that service. The public cryptographic key of the initial asymmetric key pair is sent to the server of the selected security management service. The public cryptographic key of the initial asymmetric key pair is provided to the application by the server of the selected security management service via the security management program module of that service.

[0149] Figure 4This section demonstrates an exemplary procedure for cryptographically coupling the application with the installed applet. In block 320, for example, a coupling request is sent from the application to the security management program module of the selected security management service. In block 322, the security management program module sends a coupling request over the network to the server of the selected security management service. In block 324, an encrypted channel is established between the selected security element and the server of the selected security management service. For this purpose, the cryptographic key of the security management service is used, for example.In block 326, the server of the selected security management service writes the application's public cryptographic key via the second encrypted channel to a memory area of ​​the selected security element that is allocated to the application-specific applet. Using the application's public cryptographic key, the application-specific applet can verify and associate signatures with the application. Thus, a cryptographic coupling between the application and the installed applet can be implemented.

[0150] Figure 5This shows a procedure for the initial authentication of applet 114 in security element 112 by application 108. In step 400, applet 114 calculates a shared secret S using applet 114's initial private cryptographic key K1 PR and application 108's public, for example, ephemeral public cryptographic key K2 PU. In step 402, application 108 also calculates the shared secret S. For this, application 108 uses, for example, applet 114's initial public cryptographic key K1 PU and application 108's private, for example, ephemeral private cryptographic key K2 PR. In step 404, applet 114 generates a random number RN. In step 406, applet 114 generates an authentication key K MAC, e.g., a key to generate a MAC code, as well as a symmetric cryptographic key K SYM.The keys K SYM and K MAC can be used, for example, to encrypt and authenticate data. In step 408, applet 114 generates an authentication token T using the authentication key K MAC and the ephemeral public cryptographic key K2 PU. In step 410, the authentication token T, along with the random number RN generated in step 402, is sent to application 108. In step 410, application 108 uses the received random number RN, together with the shared secret S calculated in step 402, to calculate the authentication key K MAC (e.g., a key for generating a MAC code) and the symmetric cryptographic key K SYM. In step 412, the received authentication token T is finally validated by application 108 using the key K MAC and the ephemeral public cryptographic key K2 PU.For example, application 108 also calculates the authentication token T and compares the result with the received authentication token T. If both match, the applet is authenticated.

[0151] Figure 6Figure 1 shows an exemplary mobile device 100 on which one or more application programs 108 are stored, which are, for example, ID application programs. An ID application program 108 manages, for example, one or more electronic identities with identity attributes assigned to the user. For this purpose, it includes, for example, an ID management module 107 with one or more identities or ID profiles 113. Each of the electronic identities 113 is, for example, assigned an independent security applet 114 in a security element 112 of the mobile device 100. For example, one or more of the identities 113 are assigned security applets 117 in further security elements 112 of the mobile device 100, meaning that these electronic identities 113 can access application-specific cryptographic security functions of different security elements 112, 116.Each of the electronic identities 113 is assigned a set of one or more identity attributes. These identity attributes are, for example, each encrypted and stored in a memory of the mobile device 100. The cryptographic keys for decrypting the encrypted identity attributes are, in this case, for example, stored in the corresponding security applets 114 and 117. The ID application program 108 also includes, for example, an ID client module 105, through which the ID application program 108 can, for example, receive requests for identity attributes of one of the ID profiles 113 from a reading computer system.In response to a request, for example from an ID provider service over a network, the ID application program 108 can provide the requested identity attributes after successful central authentication of the reading computer system, provided the user consents. This may require user authentication with the ID application program 108, or proof of successful user authentication by the ID application program 108 via a challenge-response procedure may be necessary. For this purpose, a security element 110 assigned to the operating system 106 is used. This element, for example, performs user authentication with an authentication sensor of the mobile device 100 and confirms the successful user authentication to the security element 112. This confirmation is also considered, for example, the user's consent to the reading of the requested identity attributes.For example, the user may have the option to influence the selection of identity attributes made available for reading via a user interface, e.g. to change them.

[0152] Figure 7Figure 170 shows an exemplary system, which includes, for example, a mobile device 100 connected via a network 150 (e.g., the internet) to a plurality of security management service servers 240, 241, a personalization server 220, an administration server 280, an ID provider server 200, and / or a service provider server 260. For example, system 170 includes a plurality of security management service servers 240, 241. Each of the security management service servers 240, 241 manages, for example, one of the security elements 112, 116 of the mobile device 100. For example, security management service server 240 manages security element 112 of the mobile device 100. Security management service server 240 is associated, for example, with the security management program module 109 of the mobile device 100.If an applet for application 108 is to be installed in security element 112, this is done, for example, via security management program module 109 using security management service server 240. For example, security management service server 241 manages security element 116 of mobile device 100. Security management service server 241 is associated, for example, with security management program module 111 of mobile device 100. If an applet for application 108 is to be installed in security element 116, this is done, for example, via security management program module 111 using security management service server 241. Security management service servers 240 and 241 each include, for example, a processor 202 or 203, memory 204 or 205, and a communication interface 210 or 211.Memory locations 204 and 205 contain program instructions 208 and 209. When executed, these instructions instruct the processor 202 and 203 to control the security management service server 240 and 241 to initialize an applet in the security element 112 and 113 of the mobile device 100, which is managed by the corresponding security management service. The applet is associated, for example, with an application 108 of the mobile device or with an electronic identity managed by the corresponding application. To verify write authorization for installing the applet, the security management service server 240 and 241 uses, for example, a security management service-specific cryptographic key 206 and 207.

[0153] The management server 280 for managing application 108 includes, for example, a processor 282, a memory 284, and a communication interface 290. Program instructions 288 are stored in the memory 284. When executed, the processor 282 uses the management server 280 to manage application 108. Managing application 108 includes, for example, issuing a certificate 286 for application 108, which contains a public cryptographic key for application 108 and, for example, a unique identifier for application 108. For example, the management server 280 receives a certificate request from application 108 via network 150. The certificate request includes, for example, the public cryptographic key and the unique identifier of application 108.For example, the management server 280 submits a certificate request to a certification server or is itself configured as a certification server. In response to the certificate request from management server 280, the certification server generates certificate 286 for application 108. This certificate is then provided to application 108 by the certification server. To do this, the certification server sends certificate 286 to the requesting management server 280, which in turn sends certificate 286 to application 108 in response to the application's certificate request.

[0154] The personalization server 220 comprises, for example, a processor 222, a memory 224, and a communication interface 230. Program instructions 228 are stored in the memory 224. When executed, the processor 222 controls the personalization server 220 to provide a symmetric key for a challenge-response procedure between the security elements 110 and 112, 116 of the mobile device 100. Thus, the initialized applet can be linked to the security element 110, which performs user authentication using the sensor 120, and therefore to the user of the mobile device 100. To prove write authorization to write the symmetric key to a memory area of ​​the security element 112 of the mobile device 100 assigned to the applet—i.e., the sub-security domain of the applet—the personalization server 220 uses, for example, the authorization certificate 226.

[0155] The service provider server 260 comprises, for example, a processor 262, a memory 264, and a communication interface 270. Program instructions 268 are stored in the memory 264. When executed, these instructions control the service provider server 260 to provide services that can be requested and / or used, for example, by the mobile device 100 via the network 150. Using services from the service provider server 260 requires, for example, providing and / or verifying one or more identity attributes of the user. Upon a request for a service from the service provider server 260 by the mobile device 100, the service provider server 260 sends an identity attribute request to an ID provider server 200 to retrieve the identity attributes of the user of the mobile device 100.The identity attribute request can be sent from the service provider server 260, for example, directly or via the mobile device 100 to the ID provider server 200. The identity attributes to be read include, for example, the identity attributes of various electronic identities stored on the mobile device 100.

[0156] The ID provider server 200 comprises, for example, a processor 242, a memory 244, and a communication interface 250. Program instructions 248 are stored in the memory 244. When executed, the processor 242 instructs the service provider server 260 to read the identity attributes specified in the identity attribute request from the memory of the mobile device 100. For this purpose, the ID provider server 200 establishes a cryptographically secured communication channel with the mobile device 100. This cryptographically secured communication channel can, for example, be an end-to-end encrypted communication channel. This requires, for instance, mutual authentication between the ID provider server 200 as the reading computer system and the applications 108 managing the electronic identities, or the corresponding electronic identities themselves.To access the identity attributes to be read, the ID provider server 200 uses the applications 108 on the mobile device 100, which manages the electronic identities with the identity attributes to be read. The ID provider server 200, as the reading computer system, sends a corresponding access request to the mobile device 100. The ID provider server 200 proves its read authorization to access the identity attributes specified in the identity attribute request, for example, with the authorization certificate 246. The ID provider server 200 sends the authorization certificate 246, for example, along with the access request. The received authorization certificate 246 is validated by the mobile device 100, for example, as part of a central authentication process.Furthermore, read access by the ID provider server 200 to the identity attributes specified in the identity attribute request requires, for example, the consent of the user of the mobile device 100. For this to occur, the user must successfully authenticate themselves to the ID application program 108. The mobile device 100 authenticates the user, for example, using the sensor 120 and the security element 110 of the operating system 106. The security element 110 confirms the successful authentication of the user to the security element 112 and the applets it encompasses. This can be done, for example, using a challenge-response procedure. For instance, the user is shown, via a display device of the user interface 118, which identity attributes are to be sent to the ID provider server 200, and the user is allowed to edit this selection.For example, the user can select which of the requested identity attributes are actually sent. Upon successful verification of read authorization or authentication of the ID provider server 200 and successful user authentication, the released identity attributes are sent to the ID provider server 200. The ID provider server 200 then signs the received identity attributes and sends them to the service provider server 260. Reference symbol list

[0157] 100 Mobile Device 102 Processor 104 Memory 105 ID Client 106 Operating System 107 ID Management Module 108 Application 109 Security Management Program Module 110 Security Element 111 Security Management Program Module 112 Security Element 114 Applet 116 Security Element 117 Applet 118 User Interface 120 Authentication Sensor 122 Communication Interface 150 Network 170 System 200 Security Management Service Server 202 Processor 203 Processor 204 Memory 205 Memory 206 Cryptographic Key 207 Cryptographic Key 208 Program Instructions 209 Program Instructions 210 Communication Interface 211 Communication Interface 220 Personalization Server 222 Processor 224 Memory 226 Authorization Certificate 228 Program instructions 230 Communication interface 240 Security management service server 241 Security management service server 242 Processor 244 Memory 246 Authorization certificate 248 Program instructions 250 Communication interface 260 Service provider server262 Processor 264 Memory 266 Program instructions 270 Communication interface 280 Management server 282 Processor 284 Memory 286 Certificate 288 Program instructions 290 Communication interface

Claims

1. A method for initializing application-specific cryptographic security functions for a mobile application (108) on a mobile terminal device (100), wherein the mobile terminal device (100) comprises a plurality of security elements (112, 116) which can be used to provide the application-specific cryptographic security functions for the mobile application (108) and are each managed by an external security management service, wherein, for each of the external security management services of the plurality of security management services, a local security management program module (109, 111) is installed on the mobile terminal device (100), wherein the method comprises: • installing the mobile application (108) on the mobile terminal device (100), • identifying, by means of the installed application (108), the plurality of security elements (112, 116) which are available on the mobile terminal device (100) and can be used to provide the application-specific cryptographic security functions for the mobile application (108) and identifying the security management services which each manage the corresponding security elements (112, 116), • selecting at least one security element (112, 116) from the identified plurality of security elements (112, 116) and the at least one security management service which manages the selected security element (112, 116), • sending a first initialization request from the application (108) to the at least one security management program module (109, 111), installed on the mobile terminal device (100), of the selected security management service for the implementation of the application-specific cryptographic security functions for the application (108) in the selected security element (112, 116), • sending a second initialization request from the security management program module (109, 111) receiving the first initialization request to a server (240, 241) of the selected security management service, over a network (150), for the implementation of the application-specific cryptographic security functions for the application (108) in the selected security element (112, 116), • establishing a first encrypted channel between the selected security element (112, 116) and the server (240, 241) of the selected security management service using a cryptographic key of the security management service, wherein the cryptographic key of the security management service verifies that write access to the security element (112, 116) managed by the security management service is reserved for the security management service, • installing an application-specific applet (114, 117) associated with the application (108) in the selected security element (112, 116) by means of the server (240, 241) of the selected security management service over the encrypted first channel, wherein the applet (114, 117) provides the application-specific cryptographic security functions for the application (108), • cryptographically coupling the application (108) to the installed applet (114, 117) in order to enable use of the application-specific cryptographic security functions for the application (108) which are provided by the applet (114, 117).

2. The method according to claim 1, wherein a plurality of security elements (112, 116) are selected from the identified plurality of security elements (112, 116) and the respectively associated security management services which manage the plurality of selected security elements (112, 116), wherein the plurality of selected security elements (112, 116) are each managed by the same security management service, for example, or wherein, for example, at least some of the plurality of selected security elements are managed by different security management services.

3. The method according to claim 2, wherein first initialization requests for all the selected security elements (112, 116) are each sent by the application (108) to the security management program module (109, 111) of each selected security management service for the implementation of the application-specific cryptographic security functions for the application (108) in the respective selected security element (112, 116), wherein second initialization requests are sent by the corresponding security management program modules (109, 111) of the selected security management services over a network (150) to servers (240, 241) of the selected security management services, wherein a first encrypted channel is set up between each of the selected security elements (112, 116) and the server (240, 241) of the respective security management service which manages the corresponding selected security elements (112, 116), in each case using a cryptographic key of the corresponding security management service, and an application-specific applet (114, 117) associated with the application (108) is installed in the corresponding selected security element (112, 116) by the server (240, 241) of the corresponding security management service over the corresponding channel, wherein the application (108) is cryptographically coupled to each of the installed applets (114, 117) to enable use of the application-specific cryptographic security functions for the application (108) which are provided by the corresponding applet (114, 117).

4. The method according to any one of the preceding claims, wherein the one or more security elements (112, 116) and security management services which manage the corresponding security elements (112, 116) are selected using a predefined set of combinations of security elements (112, 116) and associated security management services that are compatible with the application (108), which services have application-specific applets (114, 117) associated with the application (108) for installation in the corresponding security element (112, 116).

5. The method according to claim 4, wherein the selection of the one or more security elements (112, 116) and security management services further comprises: • outputting the identified security elements (112, 116) and security management services which are compatible in accordance with the predefined set on a display device of the terminal device (100), • receiving a user input with the selection via an input device of the terminal device (100), wherein the selection selects one or more security elements (112, 116) and security management services from the outputting security elements (112, 116) and security management services, and / or wherein the set defines a rule of precedence for the combinations of compatible security elements (112, 116) and security management services and the selection is made taking into account the corresponding rule of precedence, wherein the selection for example comprises at least the identified combination of a compatible security element (112, 116) and security management service with which the highest level of precedence in accordance with the rule of precedence is associated out of the identified combinations, and / or wherein the selection compulsorily comprises at least two security elements (112, 116) which are managed by two different security management services, and / or at least two security elements (112, 116) which are managed by the same security management service.

6. The method according to any one of the preceding claims, wherein the cryptographic coupling comprises initial authentication of the installed applet (114, 117) by the application (108).

7. The method according to claim 6, wherein the method comprises generating an asymmetric key pair for the application (108), wherein the asymmetric key pair of the application (108) comprises a public cryptographic key and a private cryptographic key of the application (108).

8. The method according to claim 7, wherein the method further comprises providing a certificate (286) of the application (108), wherein the certificate (286) of the application (108) comprises the public cryptographic key of the application (108) and a unique identifier of the application (108), wherein providing the certificate of the application (108) for example comprises: • sending a certificate request from the application (108) over the network (150) to a management server (280) for managing the application (108), wherein the certificate request comprises the public cryptographic key of the application (108) and the unique identifier of the application (108), • in response to the certificate request, receiving the certificate (286) of the application (108) from the certification server by means of the application (108).

9. The method according to any one of claims 7 to 8, wherein the cryptographic coupling of the application (108) to the installed applet (114, 117) comprises: • sending a first coupling request from the application (108) to the security management program module (109, 111) of the selected security management service, • sending a second coupling request from the security management program module (109, 111) receiving the first coupling request to the server (240, 241) of the selected security management service, over the network (150), • establishing a second encrypted channel between the selected security element (112, 116) and the server (240, 241) of the selected security management service using the cryptographic key of the security management service, • writing the public cryptographic key of the application (108) to a memory region, associated with the application-specific applet (114, 117), of the selected security element (112, 116) by means of the server (240, 241) of the selected security management service over the second encrypted channel.

10. The method according to claim 9, wherein the cryptographic coupling further comprises writing an initial asymmetric key pair of the application-specific applet (114, 117) to the memory region, associated with the application-specific applet (114, 117), of the selected security element (112, 116) by means of the server (240, 241) of the selected security management service over the second encrypted channel, wherein the initial asymmetric key pair of the applet (114, 117) comprises an initial public cryptographic key and an initial private cryptographic key, or wherein the initialization of the cryptographic coupling further comprises generating the initial asymmetric key pair of the application-specific applet (114, 117) using the initial public cryptographic key and the initial private cryptographic key by means of the applet (114, 117).

11. The method according to claim 10, wherein the method further comprises receiving the initial public cryptographic key of the application-specific applet (114, 117) by means of the application (108) from the security management program module (109, 111).

12. The method according to any one of claims 6 to 11, wherein the initial authentication of the applet (114, 117) by the application (108) comprises: • calculating a shared secret by means of the applet (114, 117) using the initial private cryptographic key of the applet (114, 117) and the public cryptographic key of the application (108), • calculating the shared secret by means of the application (108) using the private cryptographic key of the application (108) and the initial public cryptographic key of the applet (114, 117), • generating a random number by means of the applet (114, 117), • generating a common authentication key to authenticate information as part of the communication between the application (108) and the applet (114, 117) by means of the applet (114, 117) using the shared secret and the generated random number, • generating an authentication token by means of the applet (114, 117) using the authentication key and the public cryptographic key of the application (108) to authenticate the applet (114, 117) to the application (108), • sending the random number together with the authentication token from the applet (114, 117) to the application (108), • generating the common authentication key by means of the application (108) using the shared secret and the received random number, • authenticating the received random number and the applet (114, 117) by verifying the received authentication token by means of the application (108) using the generated common authentication key and the public cryptographic key of the application (108), wherein the cryptographic coupling for example further comprises generating a common symmetric cryptographic key by means of the applet (114, 117) and by means of the application (108) to encrypt the communication between the application (108) and the applet (114, 117) using the shared secret and the generated random number.

13. A mobile terminal device (100) comprising a processor (102), a communication interface (122) for communication over a network (150), and a plurality of security elements (112, 116), wherein the security elements (112, 116) can each be used to provide the application-specific cryptographic security functions for the mobile application (108) and are each managed by an external security management service, wherein, for each of the external security management services of the plurality of security management services, a local security management program module (109, 111) is installed on the mobile terminal device (100), wherein the processor (102) is configured to carry out a method for initializing application-specific cryptographic security functions for a mobile application (108) on a mobile terminal device (100), which comprises: • installing the mobile application (108) on the mobile terminal device (100), • identifying, by means of the installed application (108), the plurality of security elements (112, 116) which are available on the mobile terminal device (100) and can be used to provide the application-specific cryptographic security functions for the mobile application (108) and identifying the security management services which each manage the corresponding security elements (112, 116), • selecting at least one security element (112, 116) from the identified plurality of security elements (112, 116) and the at least one security management service which manages the selected security element (112, 116), • sending a first initialization request from the application (108) to the at least one security management program module (109, 111), installed on the mobile terminal device (100), of the selected security management service for the implementation of the application-specific cryptographic security functions for the application (108) in the selected security element (112, 116), • sending a second initialization request from the security management program module (109, 111) receiving the first initialization request to a server (240, 241) of the selected security management service, over a network (150), for the implementation of the application-specific cryptographic security functions for the application (108) in the selected security element (112, 116), • establishing a first encrypted channel between the selected security element (112, 116) and the server (240, 241) of the selected security management service using a cryptographic key of the security management service, wherein the cryptographic key of the security management service verifies that write access to the security element (112, 116) managed by the security management service is reserved for the security management service, • installing an application-specific applet (114, 117) associated with the application (108) in the selected security element (112, 116) by means of the server (240, 241) of the selected security management service over the encrypted first channel, wherein the applet (114, 117) provides the application-specific cryptographic security functions for the application (108), • cryptographically coupling the application (108) to the installed applet (114, 117) in order to enable use of the application-specific cryptographic security functions for the application (108) which are provided by the applet (114, 117).

14. A system (170) comprising a mobile terminal device (100) according to claim 13 and one or more servers (240, 241) of the one or more selected security management services for managing the selected one or more security elements (112, 116) of the mobile terminal device (100).

15. The system (170) according to claim 14, wherein the system (170) further comprises a management server (280) for managing the application (108).