Methods, devices and systems for transmitting and acquiring data
A cryptographic method using key attestation and secure communication channels addresses data transmission vulnerabilities, ensuring secure and reliable exchange of personal data by encrypting, decrypting, and verifying data integrity and authenticity.
Patent Information
- Application Number
- FR2023012879
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-11-22
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2043-11-22
AI Technical Summary
The transmission of personal or confidential data from a user device to a receiving device is vulnerable to interception by malicious third parties and requires verification of data integrity and authenticity.
A method involving cryptographic key attestation, random number generation, and cryptographic algorithms is employed to establish a secure wireless communication channel, ensuring data integrity and authenticity through encryption, decryption, and signature verification between user and receiving devices.
Ensures secure and reliable transmission of data by preventing unauthorized access and verifying the authenticity and integrity of data exchanged between user and receiving devices.
Abstract
Description
Title of the invention: Methods, devices and system for transmitting and acquiring data
[0001] The present invention relates to a safe and reliable method for transmitting one or more data points from a user device to a receiving device and for receiving the data transmitted by the user device. In particular, the invention relates to a method for transmitting data from a user device to a receiving device implemented in a user device, a method for receiving data from a user device implemented in a receiving device, the associated user device and receiving device, and the system comprising the user device and the receiving device.
[0002] The transmission of data from a user device to a receiving device is critical, particularly when the data is personal or confidential, for several reasons. First, it is essential that this data cannot be acquired during the transfer by a third party, especially a malicious one. Furthermore, the receiving device must be certain of the veracity of the data received.
[0003] This is particularly the case, for example, when the data are personal data such as a dematerialized identity card and the receiving device is a device capable of verifying the identity of a person carrying a user device storing the digital identity.
[0004] The object of the invention is to enable the transmission of data in a reliable and secure manner and to guarantee to the receiving device that the data received is not corrupted and is the true data stored in the user device.
[0005] This goal is achieved by a method of transmitting data from a user device to a receiving device, the user device having data suitable for transmission. The method implemented in the user device comprises the following steps: - establishment of a wireless communication channel between the user device and the receiving device; - sending a command from the user device to the receiving device via the wireless communication channel, to obtain information identifying data required by the receiving device, and obtaining the information identifying the required data by the user device; and - sending from the user device to the receiving device via the wireless communication channel, a command including the data suitable for transmission corresponding to the information identifying a data required in order to transmit the data suitable for transmission to the receiving device.
[0006] The information identifying a required data obtained may be signed, the process then further comprising a step of verifying the signature of the information identifying a required data obtained signed.
[0007] Prior to sending the command including the data suitable for transmission, the process may include a step of encrypting the data suitable for transmission.
[0008] The user device can also obtain a key attestation from the receiving device.
[0009] The key attestation of the receiving device may include a public signature cryptographic key of the receiving device.
[0010] The method may further include: - a step of generating a first random number; - a step of sending from the user device to the receiving device, a command including the first random number and obtaining by the user device an authentication signature from the receiving device; - a step of verifying the authentication signature of the receiving device obtained using the public signature cryptographic key of the receiving device obtained and the first random number.
[0011] The verification of the signature of the information identifying a required data obtained can be carried out using the cryptographic public signature key of the receiving device obtained.
[0012] The key attestation of the receiving device may include a public cryptographic encryption key of the receiving device.
[0013] The step of encrypting the data ready to be transmitted can be carried out using the public cryptographic encryption key obtained from the receiving device.
[0014] The information identifying a required data obtained can be encrypted, and the process can then include a step of decrypting the information identifying a required data obtained.
[0015] Prior to sending the data ready to be transmitted, the process may include a step of signing the data ready to be transmitted.
[0016] The user device may include a pair of cryptographic signing keys comprising a private signing cryptographic key and a public signing cryptographic key; the method may then further include sending the user device to the receiving device a command comprising a key attestation of the user device, the key attestation of the user device including the public signature cryptographic key of the user device.
[0017] The user device can also obtain a second random number from the receiving device. The method can then include a step of generating an authentication signature of the user device to be transmitted, the authentication signature being generated from the second random number obtained and the private cryptographic signature key of the user device; and sending from the user device (102) to the receiving device (104) a command comprising the generated authentication signature of the user device to be transmitted.
[0018] The decryption of the information identifying a required data obtained can be carried out using a private cryptographic encryption key of the user device.
[0019] The signature of the data ready to be transmitted can be signed using the private signature cryptographic key of the user device.
[0020] The process may further include the following steps: - sending from the user device to the receiving device, at least one cryptographic algorithm identifier supported by the user device and obtaining at least one cryptographic algorithm identifier supported by the receiving device; - determination of a cryptographic algorithm supported by the user device and the receiving device and - encryption of the data suitable for transmission corresponding to the information identifying a required data obtained using the determined cryptographic algorithm.
[0021] The step of sending the user device to the receiving device a command including the data suitable for transmission corresponding to the information identifying a required data may be preceded by a step of obtaining agreement from the user of the user device for sending the data suitable for transmission.
[0022] The wireless communication channel can be a communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.
[0023] The objective is also achieved by a method for receiving data from a user device by a receiving device, implemented in the receiving device, the receiving device comprising information identifying data required by the receiving device. The method implemented in the receiving device comprises the following steps: - establishment of a wireless communication channel between the user device and the receiving device; - receiving, via the wireless communication channel, a command from the user device to obtain information identifying data required by the receiving device, and responding by providing information identifying data required by the receiving device; and - reception via the wireless communication channel, of a command from the user device, including transmitted data corresponding to the information identifying data required by the receiving device.
[0024] Prior to providing the information identifying data required by the receiving device, the method may further include a step of encrypting the information identifying data required by the receiving device.
[0025] The transmitted data received can be signed, the process can then further include a step of verifying the signature of the transmitted data received.
[0026] The receiving device can also receive a key attestation from the user device.
[0027] The user device key attestation may include a public signature cryptographic key for the user device.
[0028] The method may further include: - a step to generate a second random number, - a step of making the second random number available to the user device, - a step involving receiving an authentication signature from the user device, - a step to verify the authentication signature of the user device received using the public signature cryptographic key of the user device obtained and the second random number.
[0029] Verification of the signature of the transmitted received data can be carried out using the public signature cryptographic key of the user device obtained.
[0030] The user device key attestation may include a public cryptographic encryption key for the user device.
[0031] The step of encrypting the information identifying data required by the receiving device can be carried out using the public cryptographic encryption key of the user device.
[0032] The transmitted received data can be encrypted, and the process can then include a step of decrypting the transmitted received data.
[0033] The method may further include a step of signing the information identifying a data required by the receiving device.
[0034] The receiving device may include a pair of cryptographic signing keys comprising a private signing cryptographic key and a public signing cryptographic key. The method may further include making available to the user device, via the receiving device, a key attestation of the receiving device, the key attestation of the receiving device comprising the public signing cryptographic key of the receiving device.
[0035] The receiving device can also receive a first random number from the user device. The method can then include a step of generating an authentication signature of the receiving device to be made available to the user device, the authentication signature being generated from the first random number received and the private cryptographic signature key of the receiving device; and making the generated authentication signature of the receiving device available to the user device.
[0036] The decryption of the transmitted data can be carried out using a private cryptographic encryption key of the receiving device.
[0037] The information identifying a required data obtained can be signed using the private signature cryptographic key of the receiving device.
[0038] The process may further include the following steps: - receiving from the user device at least one cryptographic algorithm identifier supported by the user device and responding by providing at least one cryptographic algorithm identifier supported by the receiving device; - determination of a cryptographic algorithm supported by the user device and the receiving device and - decryption of the transmitted data corresponding to the information identifying a data required by the receiving device using the determined cryptographic algorithm.
[0039] The wireless communication channel can be a communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.
[0040] The invention also relates to a device configured to implement one of the methods described above.
[0041] The invention also relates to a system comprising a user device and a receiver device, the user device and the receiver device respectively implementing the methods described above.
[0042] We will now describe examples of embodiments of the present invention with reference to the attached figures where the same references designate identical or functionally similar elements from one figure to another:
[0043] Fig. 1 is a functional diagram of an example system according to the invention.
[0044] Figure 2 illustrates an embodiment of the data transmission method implemented in the user device and the data reception method implemented in the receiving device according to the invention.
[0045] According to the present invention, the user device has data that it wishes to transmit to a receiving device that wishes to obtain the information from the user device, in particular via a communication channel, for example short distance.
[0046] The present invention relates, according to a first aspect, to a safe and reliable way of transmitting data from a user device to a receiving device, the user device having data suitable for transmission.
[0047] The present invention relates according to a second aspect to a safe and reliable way of receiving data between a user device and a receiver device, the receiver device having information identifying data required by the receiver device in order to obtain data from the user device corresponding to the information identifying data required by the receiver device.
[0048] Figure 1 is a functional diagram of an example of a system 100 enabling the secure and reliable transmission of one or more data points between two devices while ensuring the veracity of the transmitted information. For example, the system 100 may be a system comprising two different computing devices, including a user device 102 and a receiver device 104. These computing devices can communicate with each other via a wireless communication channel 106. The communication channel conforms, for example, to a short-range communication protocol (e.g., a connection conforming to the NFC standard, a connection conforming to the Wi-Fi standard, a connection conforming to the Bluetooth standard, etc.). The communication channel will allow the transmission and retrieval of data from one device to the other.
[0049] The user device 102 may be a mobile device, such as a laptop, smartphone, tablet, or wearable device. Wearable devices may include smartwatches or any other type of portable computing device. In some implementations, the user device 102 may be a desktop computer or another type of non-wearable device, such as a kiosk.
[0050] The user device 102 includes a hardware and software platform on which software runs, this software being either directly executable or interpreted on a virtual machine.
[0051] The user device includes a display device 106, a processing unit 108, such as a processor, capable of executing instructions and a storage memory 110.
[0052] The display device 106 includes, in particular, a human-machine interface for displaying data and receiving data from the user. This human-machine interface includes, for example, a screen and a keyboard, or a touchscreen.
[0053] The processing unit 108 is capable of executing an operating system, which may be, for example, any type of commercially available operating system. The processing unit 108 may include means for executing at least one cryptographic algorithm.
[0054] The storage memory 110 is capable of storing user data, including confidential or personal user data. The storage memory 110 may include, in particular, secure memory for storing confidential or personal user data. The storage memory, including the secure memory, may also be used to store cryptographic keys.
[0055] User data includes, for example, payment data, digital identity, show ticketing or transport data.
[0056] The storage memory 110 can also store applications suitable for execution by the processing unit 108 of the user device 102.
[0057] The user device 102 may further include communication means 112 capable of communicating with another device, for example a receiving device 104. The communication means 112 include, in particular, a function for establishing a secure communication channel, enabling the creation of a secure channel 122 between the user device 102 and a receiving device 104. The communication means 112 allow network-type connectivity, either via a wired connection or via a wireless connection (for example, conforming to the Bluetooth standard, the NFC standard, the Wi-Fi standard (for example, Wi-Fi Direct), or the PC / SC standard). The communication means 112 include, in particular, a module enabling proximity-based communication.
[0058] The receiving device 104 may be a mobile device, such as a laptop, smartphone, tablet, or wearable device. Wearable devices may include smartwatches or any other type of portable computing device. In some implementations, the receiving device 104 may be a desktop computer or another type of non-wearable device, such as a terminal.
[0059] The receiving device 104 includes a hardware and software platform on which software runs, this software being either directly executable or interpreted on a virtual machine.
[0060] The receiving device includes a display device 114, a processing unit 116, such as a processor, capable of executing instructions and a storage memory 118.
[0061] The display device 114 includes in particular a human-machine interface for displaying data and receiving data from the user. This human-machine interface includes, for example, a screen and a keyboard, or a touchscreen.
[0062] The processing unit 116 is capable of executing an operating system, which may be, for example, any type of commercially available operating system. The processing unit 116 may include means for executing at least one cryptographic algorithm.
[0063] The storage memory 118 can also store applications suitable for execution by the processing unit 116 of the receiving device 104. The storage memory 118 can include, in particular, a secure memory for storing cryptographic keys.
[0064] The receiving device 104 may further include communication means 120 capable of communicating with another device, for example, a user device 102. The communication means 120 include, in particular, a function for establishing a secure communication channel, enabling the creation of a secure channel 122 between the receiving device 104 and a user device 102. The communication means 122 allow network-type connectivity, either via a wired connection or via a wireless connection (for example, conforming to the Bluetooth standard, the NFC standard, the RFID standard, the Wi-Fi standard (for example, Wi-Fi Direct), or the PC / SC standard). The communication means 120 include, in particular, a module enabling proximity-based communication.
[0065] According to a particular implementation example, communication channel 122 conforms to the NFC standard. According to this standard, several operating modes can be used, including card emulation mode, reader mode, and peer-to-peer mode.
[0066] In card emulation mode, also known as passive mode, the device behaves like a contactless smart card. If the device is, for example, a mobile phone, the operator's SIM card can be used as a security element by storing encrypted information. In reader mode, the device becomes a contactless card reader (active mode) or a reader of RFID tags. electronics). Peer-to-peer mode, on the other hand, allows two devices to exchange information.
[0067] According to the present invention, the receiver device 104 is used in card emulation mode. In other words, the receiver device does not initiate communication for the exchange of one or more data points with the user device when it wishes to obtain data from the user device. It is the user device that sends the commands to the receiver device for data transmission.
[0068] Therefore, the receiving device does not need to have any special services, thus simplifying the receiving device. Furthermore, no special permissions need to be declared by the receiving device. This mode of operation also reduces potential attacks on the user device because there is no communication with the operating system. Indeed, no card emulator in the user device that could be corrupted is used.
[0069] Fig. 2 illustrates an embodiment of the data transmission method implemented in the user device 102 and the data reception method implemented in the receiver device 104 according to the invention.
[0070] The user device 102 includes data suitable for transmission and the receiving device 104 includes information identifying data required by the receiving device.
[0071] Information identifying required data is, for example, information relating to the user's digital identity, or information relating to the user's bank details, payment details, show or transport ticketing details, or information relating to any other data, such as the user's name, surname, address, date of birth.
[0072] Data suitable for transmission includes, for example, a digital identity card, data relating to a bank account, and any other personal data, whether confidential or not.
[0073] By way of example, it will be considered in the following that the information identifying a required data is the "digital identity card" information and that the data suitable for transmission is the identity card of the user of the user device 102.
[0074] The process illustrated in [Fig.2] begins with a first step of establishing a wireless communication channel 204 between the user device 102 and the receiving device 104. The communication channel is in particular a secure communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.
[0075] Since the receiving device does not initiate the communication relating to the data exchange, even though it wishes to obtain data from the user device, the latter will initiate the communication to transmit at least one piece of data, by sending a command 206 via the wireless communication channel established to the receiving device 104.
[0076] Command 206 is issued to the receiving device to obtain information identifying data required by the latter. The command can be issued to obtain more than one piece of information relating to more than one required data item.
[0077] Since the receiving device 104 is a passive device in this exchange, the command will consist, for the user device 102, on the one hand, of writing the command, in particular in a memory space of the receiving device, and on the other hand, of reading the information identifying a data required by the latter, in particular in a memory space, in the receiving device.
[0078] The result of this command is that the user device 102 obtains the information identifying a data item 210 required by the receiving device. In the example of [Fig.2], the information identifying a data item 210 is the "digital identity card" information.
[0079] Indeed, upon receiving a command from the user device, in order to obtain information identifying data required by the receiving device, the receiving device will respond by providing the information identifying data required by the receiving device.
[0080] Upon receiving the command 206 from the user device, the receiving device 104 will make available the information identifying a required data, namely, in this example, the "digital identity card" information, during step 208. During this step, other operations can be carried out which will be detailed below.
[0081] Following the receipt by the user device of the information identifying a required data, it will determine the data suitable for transmission corresponding to the information identifying a required data obtained during step 212. According to the example in [Fig.2], the data suitable for transmission is the identity card of the user of the user device 102. During this step, other operations can be carried out which will be detailed below.
[0082] The user device 102 will then send to the receiver device 104, via the established wireless communication channel, a command including the data suitable for transmission corresponding to the information identifying a required data obtained in order to transmit the data suitable for transmission to the receiver device, during step 216. The receiver device will then receive the command from the user device, including the transmitted data corresponding to the information identifying a data required by the receiver device.
[0083] This command will consist, for the user device, in writing to the receiving device the data suitable for transmission corresponding to the information identifying a data required by the receiving device. The receiving device will thus receive the data transmitted by the user device that it wishes to obtain, namely, in the example of [Fig.2], the identity card of the user of user device 102.
[0084] Step 216 may be preceded by a step 214 in which the user device 102 will send to the receiver device 104 via the established wireless communication channel, a command in order to inform the receiver device of the size of the data suitable for transmission that the user device will transmit to the receiver device.
[0085] Step 216 is followed by step 218, which processes the data received by the receiving device. During this step, other operations may be performed, which will be detailed below.
[0086] The data transmission method implemented in the user device 102 and the data reception method implemented in the receiver device 104 according to the invention described in [Fig.2] may also include one or more features described below.
[0087] In particular, the user device 102 and the receiver device 104 can run on the same type of operating system or on a different type of operating system.
[0088] The user device 102 and the receiving device 104 may respectively include a pair of cryptographic signature keys comprising a private cryptographic signature key and a public cryptographic signature key and / or a pair of cryptographic encryption keys comprising a private cryptographic encryption key and a public cryptographic encryption key.
[0089] The user device 102 and the receiver device 104 may each further comprise a set of parameters. One of the parameters may be the name of the application requiring data exchange between the user device and the receiver device. The application name is, for example, unique.
[0090] One of the parameters may include the operating mode of the device. The operating mode may, for example, indicate whether the exchange of the data(s) will take place without the user's consent or with the user's consent. Other operating modes may be used.
[0091] The user device 102 and the receiving device 104 may also include a parameter indicating whether they respectively wish the devices to be authenticated prior to the data exchange. One of the parameters may further include the cryptographic algorithm(s) suitable for implementation in the device.
[0092] Furthermore, one of the parameters of the user device 102 may include a first random number, generated, for example, by the user device. The first random number may be a random number or a pseudo-random number. The length of the first random number is, for example, 32 bytes.
[0093] According to a particular embodiment, the user device 102 can send to the receiving device, either in the command to obtain information identifying data required during step 206, or in a new command, at least one parameter of the user device 102. Said at least one parameter can be the first random number, the name of the application of the user device, the operating mode of the device, the information that the user device 102 wishes the devices to be authenticated prior to the exchange of data, and / or the list of cryptographic algorithms supported by the user device 102.
[0094] Following the receipt of the command by the receiving device, the latter can generate an attestation, in particular at step 208 which precedes step 210. The attestation can include an authentication signature of the receiving device, the authentication signature of the receiving device being able to be generated by the signature of the first random number received (for example with the command sent during step 206) from the user device with the private signature cryptographic key of the receiving device.
[0095] The attestation may further include a key attestation of the receiving device to demonstrate the origin of the receiving device's keys, the key attestation of the receiving device including, in particular, the public encryption cryptographic key of the receiving device and / or the public signature cryptographic key of the receiving device. The key attestation of the receiving device may further include an attestation type, allowing, in particular, the identification of the attestation format, and a validity period for the key attestation.
[0096] The attestation may also include a second random number generated by the receiving device and / or at least one parameter of the receiving device, namely the name of the application of the receiving device, the operating mode of the device, the information that the receiving device 104 wishes the devices to be authenticated prior to the exchange of data, and / or the list of cryptographic algorithms supported by the receiving device 104. The length of the second random number is for example 32 bytes.
[0097] This certificate is made available to the user device so that it can obtain it in response to the command issued.
[0098] The user device can then obtain, at step 210, the attestation of the receiving device as well as the information identifying a required data.
[0099] After obtaining the attestation from the receiving device, the user device can verify the received attestation. This verification can, for example, be performed during step 212 illustrated in [Fig. 2]. The verification may consist of checking the authentication signature of the receiving device. The authentication signature verification is performed, for example, using the public signature cryptographic key of the receiving device, which was received, in particular, by means of the key attestation of the receiving device.
[0100] Verification of the received attestation may also consist of verifying the received key attestation of the receiving device, thereby verifying the origin of the received key(s) and the legitimacy of the application communicating with the user device and the receiving device. Similarly, the validity period of the key attestation may be verified.
[0101] According to a particular embodiment, prior to the provision of information identifying data required by the receiving device to the user device, the information may be signed, for example during step 208 by the receiving device with the private signature cryptographic key of the receiving device and / or encrypted by the receiving device with a public encryption cryptographic key of the user device which the receiving device will have previously received.
[0102] After the user device has obtained the information identifying a required signed data, it will verify, for example during step 212, the signature of the information identifying a required data obtained from the public cryptographic encryption key of the receiving device which was received in particular by means of the key attestation of the receiving device.
[0103] If the information identifying required data obtained by the user device has been encrypted by the receiving device, the information is then decrypted from the user device's private encryption cryptographic key.
[0104] Prior to sending the user device 102 to the receiving device 104 via the wireless communication channel, a command including the data suitable for transmission corresponding to the information identifying a required data obtained, the user device 102 can generate an attestation, for example during step 212.
[0105] The user device attestation may include an authentication signature of the user device, the authentication signature of the user device being able to be generated by the signature of the second random number received generated by the receiving device and obtained by the user device, with the private signature cryptographic key of the user device.
[0106] The attestation may further include a key attestation for the user device in order to demonstrate the origin of the user device keys, the key attestation of the user device, including in particular a public cryptographic encryption key for the user device and / or a public cryptographic signature key for the user device. The user device key attestation may also include an attestation type, allowing in particular the identification of the attestation format, and a validity period for the key attestation.
[0107] The command comprising the data suitable for transmission corresponding to the information identifying a required data obtained may also include the attestation generated by the user device.
[0108] The data suitable for transmission corresponding to the information identifying a required data obtained may be signed using the private signature cryptographic key of the user device and / or encrypted using the public encryption cryptographic key of the receiving device previously obtained using the key attestation of the receiving device, in particular during step 212.
[0109] From the certificate sent by the user device 102 to the receiving device 104, the latter can verify the certificate received, in particular during step 218.
[0110] The verification may consist of verifying the authentication signature of the user device. The authentication signature verification is, for example, performed using the public signature cryptographic key of the user device, which was received, in particular, by means of the user device's key attestation.
[0111] Verification of the received attestation may also consist of verifying the received key attestation of the user device, thereby verifying the origin of the received key(s). This verification is performed using at least the number of key attestations provided by the user device's operating system. Similarly, the validity period of the key attestation may be verified.
[0112] If the transmitted data received by the receiving device corresponding to the information identifying a required data has been signed, then the signature is verified by the receiving device using the public signature cryptographic key of the user device previously obtained, during step 218.
[0113] In addition, if the transmitted data received by the receiving device corresponding to the information identifying a required data has been encrypted, then it is decrypted using the private encryption cryptographic key of the receiving device, during step 218.
[0114] According to a particular embodiment, the user device sends to the receiving device at least one cryptographic algorithm identifier supported by the user device via, for example, the command to obtain information identifying required data or a new command, and obtains at least one cryptographic algorithm identifier supported by the receiving device. In this In this embodiment, the user device determines a cryptographic algorithm supported by both the user device and the receiving device, and encrypts the data to be transmitted corresponding to the information identifying the required data obtained using the determined cryptographic algorithm. The algorithm is, for example, SHA256 with ECDSA. According to this embodiment, the receiving device receives a command from the user device containing at least one identifier of a cryptographic algorithm supported by the user device and responds by providing at least one identifier of a cryptographic algorithm supported by the receiving device.Furthermore, the receiving device determines a cryptographic algorithm supported by the user device and the receiving device and decrypts the transmitted encrypted data received corresponding to the information identifying the required data using the determined cryptographic algorithm.
[0115] According to a particular embodiment, the user device informs the receiving device of its operating mode, namely, whether the exchange of the data(s) will take place without the user's consent or with the user's consent. Other operating modes may be used.
[0116] Where the user device's operating mode requires the user's consent prior to sending the command containing the data suitable for transmission corresponding to the information identifying the required data, the user of the user device will be required to obtain their consent to send the data suitable for transmission. This will be done by displaying a confirmation request for sending the data suitable for transmission on the user device's display. After confirmation by the user of the user device, the command containing the data suitable for transmission corresponding to the information identifying the required data will be sent.
[0117] Since the data to be transmitted can be quite large, prior to transmission, the user device 102 can send a command to the receiving device 104 specifying the size of the data to be transmitted, during step 214 illustrated in [Fig. 2]. The receiving device can then display an animation on the receiving device's screen showing the time it takes for the latter to obtain the transmitted data.
Claims
Demands
1. A method for transmitting data from a user device (102) to a receiver device (104), the user device (102) having data capable of being transmitted, the method implemented in the user device (102) comprises the following steps: - establishing a wireless communication channel between the user device (102) and the receiver device (104); - sending from the user device (102) to the receiver device (104) via the wireless communication channel, a command to obtain information identifying data required by the receiver device (104) and obtaining by the user device (102) the information identifying data required by the receiver device;and - sending from the user device (102) to the receiving device (104) via the wireless communication channel, a command including the data suitable for transmission corresponding to the information identifying a data required in order to transmit the data suitable for transmission to the receiving device.
2. A method according to the preceding claim, wherein the information identifying a required data obtained is signed, the method further comprising a step of verifying the signature of the information identifying a required data obtained signed.
3. A method according to any one of the preceding claims, wherein prior to sending the command including the data suitable for transmission, the method includes a step of encrypting the data suitable for transmission.
4. A method according to any one of the preceding claims, wherein the user device (102) further obtains a key attestation from the receiving device.
5. A method according to the preceding claim, wherein the key attestation of the receiving device includes a public signature cryptographic key of the receiving device.
6. A method according to the preceding claim, wherein the method further comprises: - a step of generating a first random number; - a step of sending from the user device (102) to the receiver device (104), a command including the first random number and obtaining by the user device (102) an authentication signature of the receiver device; - a step of verifying the authentication signature of the receiver device obtained using the public signature cryptographic key of the receiver device obtained and the first random number.
7. A method according to claim 2 and claim 5, wherein the verification of the signature of the information identifying a required data obtained is carried out using the cryptographic public signature key of the receiving device obtained.
8. A method according to any one of claims 4 to 7, wherein the key attestation of the receiving device includes a public cryptographic encryption key of the receiving device.
9. A method according to claim 3 and claim 8, wherein the step of encrypting the data suitable for transmission is carried out using the public cryptographic encryption key obtained from the receiving device.
10. A method according to any one of the preceding claims, wherein the information identifying a required data obtained is encrypted, and the method includes a step of decrypting the information identifying a required data obtained.
11. A method according to any one of the preceding claims, wherein prior to sending the data ready to be transmitted, the method includes a step of signing the data ready to be transmitted.
12. A method according to any one of the preceding claims, wherein the user device (102) comprises a pair of cryptographic signing keys including a private signing cryptographic key and a public signing cryptographic key, wherein the method further comprises sending the user device (102) to the receiving device (104) a command including a key attestation of the user device, the user device key attestation including the user device public signature cryptographic key (102).
13. A method according to the preceding claim, wherein the user device (102) further obtains a second random number from the receiving device (104), and in that the method comprises a step of generating an authentication signature of the user device to be transmitted, the authentication signature being generated from the second random number obtained and the private signature cryptographic key of the user device (102); and sending from the user device (102) to the receiving device (104), a command comprising the generated authentication signature of the user device to be transmitted.
14. A method according to claim 10, wherein the decryption of the information identifying a required data obtained is carried out using a private cryptographic encryption key of the user device (102).
15. A method according to claim 11 and claim 12, wherein the signature of the data ready to be transmitted is signed using the private signature cryptographic key of the user device (102).
16. A method according to any one of the preceding claims, the method further comprising the following steps: - sending the user device (102) to the receiving device, at least one cryptographic algorithm identifier supported by the user device and obtaining at least one cryptographic algorithm identifier supported by the receiving device; - determining a cryptographic algorithm supported by the user device and the receiving device and - encrypting the data suitable for transmission corresponding to the information identifying a required data obtained using the determined cryptographic algorithm.
17. A method according to any one of the preceding claims, wherein the step of sending the user device (102) to the receiving device (104) a command comprising the data suitable for transmission corresponding to the information identifying a The required data is preceded by a step of obtaining agreement from the user of the user device for the sending of the data suitable for transmission.
18. A method according to any one of the preceding claims, wherein the wireless communication channel is a communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.
19. A method for receiving data by a receiving device (104) from a user device (102), the receiving device (104) comprising information identifying data required by the receiving device, the method implemented in the receiving device (104) comprises the following steps: - establishing a wireless communication channel between the user device and the receiving device; - receiving, via the wireless communication channel, a command from the user device to obtain information identifying data required by the receiving device and responding by providing the information identifying data required by the receiving device; and - receiving, via the wireless communication channel, a command from the user device comprising transmitted data corresponding to the information identifying data required by the receiving device.
20. A method according to the preceding claim, wherein prior to providing the information identifying data required by the receiving device, the method further comprises a step of encrypting the information identifying data required by the receiving device.
21. A method according to any one of claims 19 to 20, wherein the received transmitted data is signed, the method further comprising a step of verifying the signature of the received transmitted data.
22. A method according to any one of claims 19 to 21, wherein the receiving device (104) further receives a key attestation from the user device.
23. A method according to the preceding claim, wherein the user device key attestation includes a public signature cryptographic key of the user device.
24. A method according to the preceding claim, wherein the method further comprises: - a step of generating a second random number, - a step of making the second random number available to the user device, - a step of receiving an authentication signature from the user device, - a step of verifying the authentication signature of the user device received using the public signature cryptographic key of the user device obtained and the second random number.
25. A method according to claim 21 and claim 23, wherein the verification of the signature of the transmitted received data is carried out using the public signature cryptographic key of the user device obtained.
26. A method according to any one of claims 22 to 25, wherein the user device key attestation includes a public cryptographic encryption key for the user device.
27. A method according to claims 20 and 26, wherein the step of encrypting the information identifying data required by the receiving device is carried out using the public encryption cryptographic key of the user device.
28. A method according to any one of claims 19 to 27, wherein the received transmitted data is encrypted, and the method includes a step of decrypting the received transmitted data.
29. A method according to any one of claims 19 to 28, wherein the method further comprises a step of signing the information identifying data required by the receiving device.
30. A method according to any one of claims 19 to 29, wherein the receiving device comprises a pair of cryptographic signing keys comprising a private signing cryptographic key and a public signing cryptographic key, wherein the method further comprises making available from the receiving device to the user device, a key attestation of the receiving device, the key attestation of the receiving device including the public signature cryptographic key of the receiving device.
31. A method according to the preceding claim, wherein the receiving device further receives from the user device a first random number, and in that the method comprises a step of generating an authentication signature of the receiving device to be made available to the user device, the authentication signature being generated from the first random number received and the private signature cryptographic key of the receiving device; and making available to the receiving device (104) to the user device (102), the generated authentication signature of the receiving device to be transmitted.
32. A method according to claim 28, wherein the decryption of the transmitted data is carried out using a private cryptographic encryption key of the receiving device.
33. A method according to claim 29 and claim 30, wherein the information identifying required data obtained is signed using the private signature cryptographic key of the receiving device.
34. A method according to any one of claims 19 to 33, the method further comprising the following steps: - receiving from the user device (102), at least one cryptographic algorithm identifier supported by the user device and responding by providing at least one cryptographic algorithm identifier supported by the receiving device; - determining a cryptographic algorithm supported by the user device and the receiving device and - decrypting the transmitted data corresponding to the information identifying data required by the receiving device using the determined cryptographic algorithm.
35. A method according to any one of claims 19 to 34, wherein the wireless communication channel is a channel of communication compliant with NFC, Bluetooth or WiFi standards.
36. Device configured to implement the method according to any one of claims 1 to 18 or according to any one of claims 19 to 35.
37. System comprising a user device and a receiver device, the user device implementing the method according to any one of claims 1 to 18 and the receiver device implementing the method according to any one of claims 19 to 35.