Methods, devices and systems for transmitting and acquiring data

The method addresses the insecurity and unreliability of existing data transmission methods by establishing a secure wireless communication channel and using cryptographic techniques to authenticate and encrypt data, ensuring secure and reliable transmission of personal or confidential data.

FR3155672A1Active Publication Date: 2025-05-23IDAKTO
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
FR2023012879
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-22
Publication Date
2025-05-23
Estimated Expiration
2043-11-22

AI Technical Summary

Technical Problem

Existing data transmission methods lack security and reliability, particularly when transmitting personal or confidential data, as they fail to prevent interception by malicious third parties and ensure data integrity.

Method used

A method involving a user device and a receiver device that establishes a wireless communication channel, obtains and verifies information identifying required data items, and encrypts and authenticates data transmission using cryptographic keys and random numbers.

Benefits of technology

Ensures secure and reliable data transmission by preventing unauthorized access and ensuring data integrity, thus guaranteeing that the received data is true and uncorrupted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for exchanging data between a user device (102) and a receiving device (104), the receiving device comprising information identifying data required by the receiving device and the user device having data capable of being transmitted.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Methods, devices and system for transmitting and acquiring data

[0001] The present invention relates to a secure and reliable manner of carrying out a transmission of one or more data from a user device to a receiver device and a reception by the receiver device of the data transmitted by the user device. In particular, the invention relates to a method of transmitting data from a user device to a receiver device implemented in a user device, a method of receiving data by a receiver device from a user device, implemented in a receiver device, the user device and the receiver device associated as well as the system comprising the user device and the receiver device.

[0002] The transmission of data from a user device to a receiving device is critical, especially when the data is personal or confidential data, for several reasons. First, it is necessary that this data cannot be acquired during the transfer by a third party, especially a malicious third party. In addition, the receiving device must be certain of the veracity of the received data.

[0003] This is particularly the case, for example, when the data is personal data such as a dematerialized identity card and the receiving device is a device capable of verifying the identity of a person carrying a user device storing the digital identity.

[0004] The aim of the invention is to enable the transmission of data in a reliable and secure manner and to guarantee to the receiving device that the data received is not corrupted and is the true data stored in the user device.

[0005] This object is achieved by a method of transmitting data from a user device to a receiving device, the user device having data capable of being transmitted. The method implemented in the user device comprises the following steps: - establishing a wireless communication channel between the user device and the receiving device; - sending from the user device to the receiving device via the wireless communication channel, a command to obtain information identifying a data item required by the receiving device and obtaining by the user device the information identifying a required data item; and - sending from the user device to the receiving device via the wireless communication channel, a command comprising the data capable of being transmitted corresponding to the information identifying a data item required in order to transmit the data capable of being transmitted to the receiving device.

[0006] The information identifying a required data item obtained may be signed, the method then further comprising a step of verifying the signature of the information identifying a required data item obtained signed.

[0007] Prior to sending the command comprising the data capable of being transmitted, the method may comprise a step of encrypting the data capable of being transmitted.

[0008] The user device may further obtain a key attestation from the receiving device.

[0009] The key attestation of the receiving device may include a public signature cryptographic key of the receiving device.

[0010] The method may further comprise: - a step of generating a first random number; - a step of sending from the user device to the receiving device, a command comprising the first random number and obtaining by the user device an authentication signature of the receiving device; - a step of verifying the authentication signature of the receiving device obtained by means of the public signature cryptographic key of the receiving device obtained and the first random number.

[0011] Verification of the signature of the information identifying a required data item obtained can be carried out by means of the public signature cryptographic key of the receiving device obtained.

[0012] The key attestation of the receiving device may include a public encryption cryptographic key of the receiving device.

[0013] The step of encrypting the data capable of being transmitted can be carried out using the public encryption cryptographic key obtained from the receiving device.

[0014] The information identifying a required data item obtained may be encrypted, and the method may then comprise a step of decrypting the information identifying a required data item obtained.

[0015] Prior to sending the data capable of being transmitted, the method may comprise a step of signing the data capable of being transmitted.

[0016] The user device may include a pair of cryptographic signature keys including a private cryptographic signature key and a public cryptographic signature key, the method may then further include sending from the user device to the receiving device a command including a user device key attestation, the user device key attestation including the user device's public signing cryptographic key.

[0017] The user device can further obtain from the receiving device a second random number. The method can then comprise a step of generating an authentication signature of the user device to be transmitted, the authentication signature being generated from the second random number obtained and the private signature cryptographic key of the user device; and sending from the user device (102) to the receiving device (104) a command comprising the generated authentication signature of the user device to be transmitted.

[0018] Decryption of the information identifying a requested data obtained can be carried out by means of a private encryption cryptographic key of the user device.

[0019] The signature of the data capable of being transmitted can be signed using the private cryptographic signature key of the user device.

[0020] The method may further comprise the following steps: - sending from the user device to the receiving device, at least one cryptographic algorithm identifier supported by the user device and obtaining at least one cryptographic algorithm identifier supported by the receiving device; - determination of a cryptographic algorithm supported by the user device and the receiving device and - encryption of the data capable of being transmitted corresponding to the information identifying a required data item obtained using the determined cryptographic algorithm.

[0021] The step of sending from the user device to the receiving device a command comprising the data capable of being transmitted corresponding to the information identifying a required data item may be preceded by a step of obtaining agreement by the user of the user device for sending the data capable of being transmitted.

[0022] The wireless communication channel may be a communication channel compliant with the NFC standard, the Bluetooth standard or the WiFi standard.

[0023] The aim is also achieved by a method for receiving data by a receiving device from a user device, implemented in the receiving device, the receiving device comprising information identifying data required by the receiving device. The method implemented in the receiving device comprises the following steps: - establishing a wireless communication channel between the user device and the receiving device; - receiving via the wireless communication channel, a command from the user device, to obtain information identifying data required by the receiving device and responding by providing the information identifying data required by the receiving device; and - receiving via the wireless communication channel, a command from the user device, comprising transmitted data corresponding to the information identifying data required by the receiving device.

[0024] Prior to providing the information identifying data required by the receiving device, the method may further comprise a step of encrypting the information identifying data required by the receiving device.

[0025] The transmitted data received may be signed, the method may then further comprise a step of verifying the signature of the transmitted data received.

[0026] The receiving device may further receive a key attestation from the user device.

[0027] The user device key attestation may include a public signature cryptographic key of the user device.

[0028] The method may further comprise: - a step of generating a second random number, - a step of making the second random number available to the user device, - a step of receiving an authentication signature from the user device, - a step of verifying the authentication signature of the user device received by means of the public signature cryptographic key of the user device obtained and the second random number.

[0029] The verification of the signature of the received transmitted data can be carried out by means of the public signature cryptographic key of the user device obtained.

[0030] The user device key attestation may include a public encryption cryptographic key of the user device.

[0031] The step of encrypting the information identifying data required by the receiving device can be carried out using the public encryption cryptographic key of the user device.

[0032] The transmitted data received may be encrypted, and the method may then comprise a step of decrypting the transmitted data received.

[0033] The method may further comprise a step of signing the information identifying data required by the receiving device.

[0034] The receiving device may include a cryptographic signature key pair including a private signature cryptographic key and a public signature cryptographic key. The method may then further include providing the receiving device to the user device with a key attestation of the receiving device, the key attestation of the receiving device including the public signature cryptographic key of the receiving device.

[0035] The receiving device may further receive a first random number from the user device. The method may then comprise a step of generating an authentication signature of the receiving device to be made available to the user device, the authentication signature being generated from the first random number received and the private signature cryptographic key of the receiving device; and making the authentication signature of the receiving device to be transmitted generated available from the receiving device to the user device.

[0036] The decryption of the transmitted data can be carried out using a private cryptographic encryption key of the receiving device.

[0037] The information identifying a required data obtained can be signed using the private signature cryptographic key of the receiving device.

[0038] The method may further comprise the following steps: - receiving from the user device at least one cryptographic algorithm identifier supported by the user device and responding by providing at least one cryptographic algorithm identifier supported by the receiving device; - determination of a cryptographic algorithm supported by the user device and the receiving device and - decryption of the transmitted data corresponding to the information identifying data required by the receiving device using the determined cryptographic algorithm.

[0039] The wireless communication channel may be a communication channel compliant with the NFC standard, the Bluetooth standard or the WiFi standard.

[0040] The invention also relates to a device configured to implement one of the methods described above.

[0041] The invention also relates to a system comprising a user device and a receiver device, the user device and the receiver device respectively implementing the methods described above.

[0042] We will now describe examples of embodiments of the present invention with reference to the appended figures where the same references designate from one figure to another identical or functionally similar elements:

[0043] [Fig.l] is a functional diagram of an exemplary system in accordance with the invention.

[0044] [Fig.2] illustrates an embodiment of the method for transmitting data implemented in the user device and of the method for receiving data implemented in the receiver device in accordance with the invention.

[0045] According to the present invention, the user device has data that it wishes to transmit to a receiving device which wishes to obtain the information from the user device, in particular via a communication channel, for example a short distance one.

[0046] The present invention relates according to a first aspect, to a secure and reliable manner of transmitting data from a user device to a receiving device, the user device having data capable of being transmitted.

[0047] The present invention relates according to a second aspect to a secure and reliable manner of receiving data between a user device and a receiver device, the receiver device having information identifying data required by the receiver device in order to obtain data from the user device corresponding to the information identifying data required by the receiver device.

[0048] [Fig.l] is a functional diagram of an example system 100 enabling transmission of one or more data between two devices in a secure and reliable manner while ensuring the veracity of the transmitted information. For example, the system 100 may be a system comprising two different computing devices, including a user device 102 and a receiver device 104. These computing devices may communicate with each other via a wireless communication channel 106. The communication channel is for example compliant with a short-distance communication protocol (for example, a connection compliant with the NFC standard, a connection compliant with the Wifi standard, a connection compliant with the Bluetooth standard, etc.). The communication channel will enable data to be transmitted and obtained from one device to the other device.

[0049] The user device 102 may be a mobile device, such as a laptop, smartphone, tablet, or wearable device. Wearable devices may include smartwatches or any other type of portable computing device. In some implementations, the user device 102 may be a desktop computer or another type of non-portable device, such as a kiosk.

[0050] The user device 102 comprises a hardware and software platform on which software is executed, this software being either directly executable or interpreted on a virtual machine.

[0051] The user device comprises a display device 106, a processing unit 108, such as a processor, capable of executing instructions and a storage memory 110.

[0052] The display device 106 comprises in particular a human-machine communication interface for displaying data and receiving data from the user. This human-machine communication interface comprises for example a screen and a keyboard, or a touch screen.

[0053] The processing unit 108 is capable of executing an operating system which may be, for example, any type of operating system on the market. The processing unit 108 may comprise means for executing at least one cryptographic algorithm.

[0054] The storage memory 110 is capable of storing user data, in particular confidential data or personal data of the user. The storage memory 110 may include in particular a secure memory for storing the confidential or personal data of the user. The storage memory, in particular the secure memory, may further be used to store cryptographic keys.

[0055] User data includes, for example, payment, digital identity, show ticketing or transport data.

[0056] The storage memory 110 can further store applications capable of being executed by the processing unit 108 of the user device 102.

[0057] The user device 102 may further comprise communication means 112 capable of communicating with another device, for example a receiver device 104. The communication means 112 comprise in particular a function for establishing a secure communication channel, allowing the creation of a secure channel 122 between the user device 102 and a receiver device 104. The communication means 112 allow network-type connectivity, either via a wired connection or via a wireless connection (for example, compliant with the Bluetooth standard, the NFC standard, the WIFI standard (for example, Wi-Di (or Wi-Fi Direct)) or the PC / SC standard). The communication means 112 comprise in particular a module allowing communication based on a proximity connection.

[0058] The receiving device 104 may be a mobile device, such as a laptop, smartphone, tablet, or wearable device. Wearable devices may include smartwatches or any other type of portable computing device. In some implementations, the receiving device 104 may be a desktop computer or another type of non-portable device, such as a kiosk.

[0059] The receiving device 104 comprises a hardware and software platform on which software is executed, this software being either directly executable or interpreted on a virtual machine.

[0060] The receiving device comprises a display device 114, a processing unit 116, such as a processor, capable of executing instructions and a storage memory 118.

[0061] The display device 114 comprises in particular a human-machine communication interface for displaying data and receiving data from the user. This human-machine communication interface comprises for example a screen and a keyboard, or a touch screen.

[0062] The processing unit 116 is capable of executing an operating system which may be, for example, any type of operating system on the market. The processing unit 116 may comprise means for executing at least one cryptographic algorithm.

[0063] The storage memory 118 can further store applications capable of being executed by the processing unit 116 of the receiving device 104. The storage memory 118 can notably comprise a secure memory for storing cryptographic keys.

[0064] The receiving device 104 may further comprise communication means 120 capable of communicating with another device, for example a user device 102. The communication means 120 comprise in particular a function for establishing a secure communication channel, allowing the creation of a secure channel 122 between the receiving device 104 and a user device 102. The communication means 122 allow network-type connectivity, either via a wired connection or via a wireless connection (for example, compliant with the Bluetooth standard, the NFC standard, the RFID standard, the WIFI standard (for example, Wi-Di (or Wi-Fi Direct)) or the PC / SC standard). The communication means 120 comprise in particular a module allowing communication based on a proximity connection.

[0065] According to a particular example of implementation, the communication channel 122 complies with the NFC standard. According to this standard, several operating modes can be used, in particular the card emulation mode, the reader mode and the peer-to-peer mode.

[0066] In the card emulation mode, called passive, the device behaves like a contactless smart card. In the case where the device is for example a mobile phone, the operator's SIM card can be used as a security element by storing encrypted information. In the reader mode, the device becomes a reader of contactless cards (active mode) or "radio-tags" (tags Peer-to-peer mode, on the other hand, allows two devices to exchange information.

[0067] According to the present invention, the receiving device 104 is used in card emulation mode. In other words, the receiving device does not initiate the communication relating to the exchange of one or more data with the user device while it wishes to obtain data from the user device. It is the user device which will transmit the commands to the receiving device for the transmission of data.

[0068] It is therefore not necessary for the receiving device to have any particular service, thus simplifying the receiving device. In addition, no special permissions need to be declared by the receiving device. This mode of operation also reduces possible attacks on the user device because there is no communication with the operating system. Indeed, no card emulator in the user device that can be corrupted is used.

[0069] [Fig.2] illustrates an embodiment of the method for transmitting data implemented in the user device 102 and of the method for receiving data implemented in the receiver device 104 in accordance with the invention.

[0070] The user device 102 comprises data capable of being transmitted and the receiving device 104 comprises information identifying data required by the receiving device.

[0071] The information identifying a required data item is for example information relating to the dematerialized identity of the user, or information relating to the user's banking data, payment data, show or transport ticketing data, or information relating to any other data, such as the user's surname, first name, address, date of birth.

[0072] The data capable of being transmitted is, for example, a digital identity card, data relating to a bank account, and any other data of a personal nature, confidential or not.

[0073] By way of example, it will be considered hereinafter that the information identifying a required data item is the “digital identity card” information and that the data item capable of being transmitted is the identity card of the user of the user device 102.

[0074] The method illustrated in [Fig.2] begins with a first step of establishing a wireless communication channel 204 between the user device 102 and the receiver device 104. The communication channel is in particular a secure communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.

[0075] The receiving device does not initiate the communication relating to the exchange of data while it wishes to obtain data from the user device, the latter will initiate the communication to transmit at least one data item, by sending a command 206 via the wireless communication channel established at the receiving device 104.

[0076] Command 206 is issued to the receiving device to obtain information identifying a data item required by the latter. The command may be issued to obtain more than one information item relating to more than one required data item.

[0077] The receiving device 104 being, in this exchange, a passive device, the command will consist, for the user device 102, on the one hand, of writing, in particular in a memory space of the receiving device, the command and on the other hand of reading, in particular in a memory space, in the receiving device, the information identifying data required by the latter.

[0078] The result of this command consists of the user device 102 obtaining the information identifying a piece of data required 210 by the receiving device. In the example of [Fig.2], the information identifying a piece of data required 210 is the "digital identity card" information.

[0079] Indeed, upon receipt of a command from the user device, to obtain information identifying data required by the receiving device, the receiving device will respond by providing the information identifying data required by the receiving device.

[0080] Upon receipt of the command 206 from the user device, the receiving device 104 will make available the information identifying a required data item, namely according to this example, the information "digital identity card", during step 208. During this step, other operations can be carried out which will be detailed below.

[0081] Following receipt by the user device of the information identifying a required data item, the latter will determine the data item capable of being transmitted corresponding to the information identifying a required data item obtained during step 212. According to the example of [Fig.2], the data item capable of being transmitted is the identity card of the user of the user device 102. During this step, other operations can be carried out which will be detailed below.

[0082] The user device 102 will then send to the receiver device 104 via the established wireless communication channel, a command comprising the data capable of being transmitted corresponding to the information identifying a required data item obtained in order to transmit the data capable of being transmitted to the receiver device, during step 216. The receiver device will then receive the command from the user device, comprising the transmitted data item corresponding to the information identifying a data item required by the receiver device.

[0083] This command will consist, for the user device, in writing into the receiving device the data capable of being transmitted corresponding to the information identifying a data required by the receiving device. The receiving device will thus receive the data transmitted by the user device that it wishes to obtain, namely, in the example of [Fig.2], the identity card of the user of the user device 102.

[0084] Step 216 may be preceded by a step 214 during which the user device 102 will send to the receiver device 104 via the established wireless communication channel, a command in order to inform the receiver device of the size of the data capable of being transmitted that the user device will transmit to the receiver device.

[0085] Step 216 is followed by a step 218 of processing the data received by the receiving device. During this step, other operations can be carried out which will be detailed below.

[0086] The method for transmitting data implemented in the user device 102 and the method for receiving data implemented in the receiver device 104 in accordance with the invention described in [Fig.2] may also comprise one or more characteristics described below.

[0087] In particular, the user device 102 and the receiver device 104 may run on the same type of operating system or on an operating system of a different type.

[0088] The user device 102 and the receiver device 104 may respectively comprise a pair of cryptographic signature keys comprising a private cryptographic signature key and a public cryptographic signature key and / or a pair of cryptographic encryption keys comprising a private cryptographic encryption key and a public cryptographic encryption key.

[0089] The user device 102 and the receiver device 104 may each further comprise a set of parameters. One of the parameters may be the name of the application requiring data exchange between the user device and the receiver device. The name of the application is, for example, unique.

[0090] One of the parameters may include the operating mode of the device. The operating mode includes, for example, indicating whether the exchange of the data(s) will be done without the user's consent or with the user's consent. Other operating modes may be used.

[0091] The user device 102 and the receiver device 104 may also include a parameter indicating whether they respectively wish the devices to be authenticated prior to the data exchange. One of the parameters may further include the cryptographic algorithm(s) capable of being implemented in the device.

[0092] Further, one of the parameters of the user device 102 may comprise a first random number, generated for example by the user device. The first random number may be a random number or a pseudo-random number. The length of the first random number is for example 32 bytes.

[0093] According to a particular embodiment, the user device 102 can send to the receiving device, either in the command to obtain information identifying data required during step 206, or in a new command, at least one parameter of the user device 102. Said at least one parameter can be the first random number, the name of the application of the user device, the operating mode of the device, the information according to which the user device 102 wishes the devices to be authenticated prior to the exchange of data, and / or the list of cryptographic algorithms supported by the user device 102.

[0094] Following receipt of the command by the receiving device, the latter may generate a certificate, in particular in step 208 which precedes step 210. The certificate may comprise an authentication signature of the receiving device, the authentication signature of the receiving device being able to be generated by the signature of the first random number received (for example with the command sent during step 206) from the user device with the private signature cryptographic key of the receiving device.

[0095] The attestation may further comprise a key attestation of the receiving device in order to demonstrate the origin of the keys of the receiving device, the key attestation of the receiving device including in particular the public encryption cryptographic key of the receiving device and / or the public signature cryptographic key of the receiving device. The key attestation of the receiving device may further comprise a type of attestation, making it possible in particular to identify the format of the attestation, and a validity period of the key attestation.

[0096] The attestation may also comprise a second random number generated by the receiving device and / or at least one parameter of the receiving device, namely the name of the application of the receiving device, the operating mode of the device, the information according to which the receiving device 104 wishes the devices to be authenticated prior to the exchange of data, and / or the list of cryptographic algorithms supported by the receiving device 104. The length of the second random number is for example 32 bytes.

[0097] This certificate is made available to the user device so that the latter can obtain it in response to the command issued.

[0098] The user device can then obtain, at step 210, the certification of the receiving device as well as the information identifying a required data item.

[0099] After obtaining the attestation from the receiving device, the user device can verify the received attestation. The verification can for example be carried out during step 212 illustrated in [Fig.2]. The verification can consist of verifying the authentication signature of the receiving device. The verification of the authentication signature is for example carried out from the public signature cryptographic key of the receiving device which was received in particular by means of the key attestation of the receiving device.

[0100] Verification of the received attestation may also consist of verifying the key attestation of the receiving device received, making it possible to verify the origin of the key(s) received as well as the legitimacy of the application communicating with the user device and of the receiving device. Similarly, the validity period of the key attestation may be verified.

[0101] According to a particular embodiment, prior to making available the information identifying a data item required by the receiving device to the user device, the information may be signed, for example during step 208 by the receiving device with the private cryptographic signature key of the receiving device and / or encrypted by the receiving device with a public cryptographic encryption key of the user device that the receiving device will have previously received.

[0102] After the user device has obtained the information identifying a required signed data item, the latter will verify, for example during step 212, the signature of the information identifying a required data item obtained from the public cryptographic encryption key of the receiving device which was received in particular by means of the key attestation of the receiving device.

[0103] If the information identifying a requested data item obtained by the user device has been encrypted by the receiving device, the information is then decrypted from the user device's private encryption cryptographic key.

[0104] Prior to sending from the user device 102 to the receiver device 104 via the wireless communication channel, a command comprising the data capable of being transmitted corresponding to the information identifying a required data item obtained, the user device 102 can generate a certificate, for example during step 212.

[0105] The attestation of the user device may comprise an authentication signature of the user device, the authentication signature of the user device may be generated by signing the second received random number generated by the receiving device and obtained by the user device, with the private signature cryptographic key of the user device.

[0106] The attestation may further comprise a key attestation of the user device to demonstrate the provenance of the keys of the user device, the key attestation of the user device including in particular a public encryption cryptographic key of the user device and / or a public signature cryptographic key of the user device. The key attestation of the user device may further include a type of attestation, making it possible in particular to identify the format of the attestation, and a validity period of the key attestation.

[0107] The command comprising the data capable of being transmitted corresponding to the information identifying a required data item obtained may also comprise the certificate generated by the user device.

[0108] The data capable of being transmitted corresponding to the information identifying a required data item obtained can be signed using the private signature cryptographic key of the user device and / or encrypted using the public encryption cryptographic key of the receiving device previously obtained using the key attestation of the receiving device, in particular during step 212.

[0109] From the certificate sent by the user device 102 to the receiving device 104, the latter can verify the certificate received, in particular during step 218.

[0110] The verification may consist of verifying the authentication signature of the user device. The verification of the authentication signature is for example carried out from the public signature cryptographic key of the user device which was received in particular by means of the key attestation of the user device.

[0111] Verification of the received attestation may also consist of verifying the key attestation of the received user device making it possible to verify the origin of the received key(s). The latter is carried out at least from key attestations provided by the operating system of the user device. Similarly, the validity period of the key attestation may be verified.

[0112] If the transmitted data received by the receiving device corresponding to the information identifying a required data item has been signed, then the signature is verified by the receiving device by means of the public signature cryptographic key of the user device previously obtained, during step 218.

[0113] Furthermore, if the transmitted data received by the receiving device corresponding to the information identifying a required data has been encrypted, then it is decrypted using the private encryption cryptographic key of the receiving device, during step 218.

[0114] According to a particular embodiment, the user device sends to the receiving device at least one cryptographic algorithm identifier supported by the user device via, for example, the command to obtain information identifying a required data item or a new command and obtains at least one cryptographic algorithm identifier supported by the receiving device. In this embodiment, the user device determines a cryptographic algorithm supported by the user device and the receiving device and encrypts the data capable of being transmitted corresponding to the information identifying a required data item obtained using the determined cryptographic algorithm. The algorithm is for example the SHA256 algorithm with ECDSA. According to this embodiment, the receiving device receives from the user device, a command comprising at least one cryptographic algorithm identifier supported by the user device and responds by providing at least one cryptographic algorithm identifier supported by the receiving device.Further, the receiving device determines a cryptographic algorithm supported by the user device and the receiving device and decrypts the received encrypted transmitted data corresponding to the information identifying a required data using the determined cryptographic algorithm.

[0115] According to a particular embodiment, the user device informs the receiving device of its mode of operation, namely, whether the exchange of the data(s) will be done without the user's consent or with the user's consent. Other modes of operation may be used.

[0116] In the case where the operating mode of the user device requires the consent of the user, prior to sending the command comprising the data capable of being transmitted corresponding to the information identifying a required data item, obtaining an agreement by the user of the user device for sending the data capable of being transmitted will be executed. The obtaining will be carried out by displaying a confirmation request for sending the data capable of being transmitted on the display device of the user device. After confirmation by the user of the user device, the command comprising the data capable of being transmitted corresponding to the information identifying a required data item will be sent.

[0117] Since the data capable of being transmitted may be of a large size, prior to its transmission, the user device 102 can send a command to the receiving device 104 comprising the size of the data capable of being transmitted, during step 214 illustrated in [Fig.2]. Thus, the receiving device can display on the screen of the device an animation showing the duration for the latter to obtain the transmitted data.

Claims

Claims

1. A method of transmitting data from a user device (102) to a receiver device (104), the user device (102) having data capable of being transmitted, the method implemented in the user device (102) comprises the following steps: - establishing a wireless communication channel between the user device (102) and the receiver device (104); - sending from the user device (102) to the receiver device (104) via the wireless communication channel, a command to obtain information identifying data required by the receiver device (104) and obtaining by the user device (102) the information identifying data required by the receiver device;and - sending from the user device (102) to the receiver device (104) via the wireless communication channel, a command comprising the data capable of being transmitted corresponding to the information identifying a data item required in order to transmit the data item capable of being transmitted to the receiver device.;

2. Method according to the preceding claim, in which the information identifying a required data item obtained is signed, the method further comprising a step of verifying the signature of the information identifying a required data item obtained signed.

3. Method according to any one of the preceding claims, in which prior to sending the command comprising the data capable of being transmitted, the method comprises a step of encrypting the data capable of being transmitted.

4. A method according to any preceding claim, wherein the user device (102) further obtains a key attestation from the receiving device.

5. Method according to the preceding claim, in which the key attestation of the receiving device comprises a public signature cryptographic key of the receiving device.

6. A method according to the preceding claim, wherein the method further comprises: - a step of generating a first random number; - a step of sending from the user device (102) to the receiver device (104), a command comprising the first random number and obtaining by the user device (102) an authentication signature of the receiver device; - a step of verifying the authentication signature of the receiver device obtained by means of the public signature cryptographic key of the receiver device obtained and the first random number.

7. Method according to claim 2 and claim 5, wherein the verification of the signature of the information identifying a required data obtained is carried out by means of the public signature cryptographic key of the receiving device obtained.

8. A method according to any one of claims 4 to 7, wherein the key attestation of the receiving device comprises a public encryption cryptographic key of the receiving device.

9. Method according to claim 3 and claim 8, wherein the step of encrypting the data capable of being transmitted is carried out by means of the public encryption cryptographic key obtained from the receiving device.

10. A method according to any preceding claim, wherein the information identifying an obtained required data is encrypted, and the method comprises a step of decrypting the information identifying an obtained required data.

11. Method according to any one of the preceding claims, in which prior to sending the data capable of being transmitted, the method comprises a step of signing the data capable of being transmitted.

12. A method according to any preceding claim, wherein the user device (102) comprises a pair of cryptographic signature keys comprising a private cryptographic signature key and a public cryptographic signature key, wherein the method further comprises sending from the user device (102) to the receiving device (104) a command comprising an attestation of keys of the user device, the user device key attestation comprising the user device's public signature cryptographic key (102).

13. Method according to the preceding claim, in which the user device (102) further obtains from the receiver device (104) a second random number, and in that the method comprises a step of generating an authentication signature of the user device to be transmitted, the authentication signature being generated from the second random number obtained and the private signature cryptographic key of the user device (102); and sending from the user device (102) to the receiver device (104) a command comprising the generated authentication signature of the user device to be transmitted.

14. The method of claim 10, wherein the decryption of the information identifying a required data obtained is performed using a private encryption cryptographic key of the user device (102).

15. Method according to claim 11 and claim 12, wherein the signature of the data capable of being transmitted is signed by means of the private signature cryptographic key of the user device (102).

16. Method according to any one of the preceding claims, the method further comprising the following steps: - sending from the user device (102) to the receiving device, at least one identifier of a cryptographic algorithm supported by the user device and obtaining at least one identifier of a cryptographic algorithm supported by the receiving device; - determining a cryptographic algorithm supported by the user device and the receiving device and - encrypting the data capable of being transmitted corresponding to the information identifying a required data obtained using the determined cryptographic algorithm.

17. A method according to any preceding claim, wherein the step of sending from the user device (102) to the receiver device (104) a command comprising the transmittable data corresponding to the information identifying a The required data is preceded by a step of obtaining agreement from the user of the user device for sending the data capable of being transmitted.

18. A method according to any preceding claim, wherein the wireless communication channel is a communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.

19. A method of receiving data by a receiver device (104) from a user device (102), the receiver device (104) comprising information identifying data required by the receiver device, the method implemented in the receiver device (104) comprises the following steps: - establishing a wireless communication channel between the user device and the receiver device; - receiving via the wireless communication channel, a command from the user device, to obtain information identifying data required by the receiver device and responding by providing the information identifying data required by the receiver device; and - receiving via the wireless communication channel, a command from the user device, comprising transmitted data corresponding to the information identifying data required by the receiver device.

20. Method according to the preceding claim, in which prior to providing the information identifying data required by the receiving device, the method further comprises a step of encrypting the information identifying data required by the receiving device.

21. Method according to any one of claims 19 to 20, in which the received transmitted data is signed, the method further comprising a step of verifying the signature of the received transmitted data.

22. A method according to any one of claims 19 to 21, wherein the receiving device (104) further receives a key attestation from the user device.

23. Method according to the preceding claim, in which the key attestation of the user device comprises a public signature cryptographic key of the user device.

24. Method according to the preceding claim, in which the method further comprises: - a step of generating a second random number, - a step of making the second random number available to the user device, - a step of receiving an authentication signature from the user device, - a step of verifying the authentication signature of the user device received by means of the public signature cryptographic key of the user device obtained and the second random number.

25. Method according to claim 21 and claim 23, wherein the verification of the signature of the received transmitted data is carried out by means of the obtained public signature cryptographic key of the user device.

26. The method of any one of claims 22 to 25, wherein the key attestation of the user device comprises a public encryption cryptographic key of the user device.

27. ​​The method of claims 20 and 26, wherein the step of encrypting the information identifying a data item required by the receiving device is performed using the public encryption cryptographic key of the user device.

28. A method according to any one of claims 19 to 27, wherein the received transmitted data is encrypted, and the method comprises a step of decrypting the received transmitted data.

29. A method according to any one of claims 19 to 28, wherein the method further comprises a step of signing the information identifying data required by the receiving device.

30. A method according to any one of claims 19 to 29, wherein the receiving device comprises a cryptographic signature key pair comprising a private cryptographic signature key and a public cryptographic signature key, wherein the method further comprises providing from the receiving device to the user device, a key attestation of the receiving device, the key attestation of the receiving device including the public signature cryptographic key of the receiving device.

31. Method according to the preceding claim, in which the receiving device further receives from the user device a first random number, and in that the method comprises a step of generating an authentication signature of the receiving device to be made available to the user device, the authentication signature being generated from the first random number received and the private signature cryptographic key of the receiving device; and making available from the receiving device (104) to the user device (102), the authentication signature of the receiving device to be transmitted generated.

32. Method according to claim 28, in which the decryption of the transmitted data is carried out by means of a private cryptographic encryption key of the receiving device.

33. A method according to claim 29 and claim 30, wherein the information identifying an obtained required data is signed using the private signature cryptographic key of the receiving device.

34. Method according to any one of claims 19 to 33, the method further comprising the following steps: - receiving from the user device (102), at least one cryptographic algorithm identifier supported by the user device and responding by providing at least one cryptographic algorithm identifier supported by the receiving device; - determining a cryptographic algorithm supported by the user device and the receiving device and - decrypting the transmitted data corresponding to the information identifying a data item required by the receiving device using the determined cryptographic algorithm.

35. A method according to any one of claims 19 to 34, wherein the wireless communication channel is a communication compliant with NFC standard, Bluetooth standard or WiFi standard.

36. Device configured to implement the method according to any one of claims 1 to 18 or according to any one of claims 19 to 35.

37. A system comprising a user device and a receiver device, the user device implementing the method according to any one of claims 1 to 18 and the receiver device implementing the method according to any one of claims 19 to 35.

Citation Information

Patent Citations

  • Secure method of loading data to access a service in an NFC chipset

    EP2007106A1

  • System access using a mobile device

    WO2018160863A1