Enhanced security method for establishing a connection with password authentication

By integrating symmetric encryption using identification data-derived keys to protect ephemeral public keys and nonces, the PACE protocol is fortified against quantum attacks, ensuring secure electronic chip communications.

FR3158166A1Pending Publication Date: 2025-07-11IDEMIA IDENTITY & SECURITY FRANCE SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2024000198
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-09
Publication Date
2025-07-11

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for establishing a connection with password authentication between an electronic chip (10) of a person's identification data carrier and a control terminal (20). This method implements, in addition to the symmetric encryption of a nonce s using a symmetric encryption key, an additional transformation using a further encryption key derived from identification data carried by the person's identification data carrier. Figure for abstract: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Enhanced security method for establishing a connection with password authentication Technical field

[0001] The field of the invention is that of establishing a connection with password authentication between an electronic chip of a person's identification data medium and a control terminal. The invention finds particular application in carrying out a control of the person by interaction of the identification data medium with the control terminal. Prior art

[0002] A contactless chip can be protected to deny access to its contents unless a controlling terminal can prove that it is authorized to access the contactless chip. This proof is given via the presentation of a password by the terminal. In order to ensure the confidentiality of the password, this presentation is done through an authentication protocol that does not reveal the latter. Furthermore, the nature of the password differs depending on the use case.

[0003] In the case of an electronic (e-) machine-readable travel document (MRTD), the password consists of data printed or displayed on the document, in particular data from a Machine Readable Zone (MRZ) of the document or data from a Card Access Number (CAN) carried by the document. Presentation of the password demonstrates that the document is presented by its bearer and that the control terminal is authorized to read it.

[0004] In other use cases, a secret PIN (Personal Identification Number) can be used to unlock access to resources on the chip (such as a signature key, for example). The bearer then presents his or her PIN to the control terminal, which uses it to access the chip. The use of the authentic PIN guarantees to the chip that the terminal is acting on behalf of a legitimate bearer.

[0005] ICAO (International Civil Aviation Organization) document 9303 "Machine Readable Travel Documents" specifies in part 11 cryptographic protocols for eMRTDs with access to a contactless chip. These protocols are intended in particular to prevent unauthorized reading (skimming) of data contained in the contactless chip and to prevent illicit interception of communications between the contactless chip and a control terminal.

[0006] Two chip access control mechanisms are specified: - Basic Access Control (BAC), based purely on symmetric cryptography; and - Password Authenticated Connection Establishment (PACE), which uses asymmetric cryptography to provide higher-entropy session keys.

[0007] PACE uses Kir keys calculated from passwords with a KDFir key calculation function. The following two passwords and corresponding keys are available: - ZLA: the Kir key defined by Kir = KDFir(ZLA) is calculated from the machine readable zone (ZLA), i.e. calculated from the document number, the date of birth and the expiry date; - CAN: the Kir key defined by Kir = KDFir(CAN) is calculated from the card access number (CAN). The CAN is a number printed on the document, chosen randomly or pseudo-randomly.

[0008] [Fig.l] illustrates the main steps of the PACE protocol.

[0009] In a first step, the DVLM-e chip (designated IC or CI in [Fig.l]) randomly chooses a nonce s, encrypts the nonce to obtain z= E (Kir,s), where Kir=KDFjr (ji) is calculated from the shared password ir and where E(K, S) denotes the encryption of a plaintext S with a symmetric key K. The DVLM-e chip then sends the encrypted nonce z to the control terminal.

[0010] During a second step, the control terminal (also called inspection system and designated by IFD in [Fig.l]) finds the plain nonce s= D (Kir,z) using the shared password ji, D(K,C) designating the decryption of a ciphertext C with a symmetric key K.

[0011] The DVLM-e chip and the control terminal then perform the following steps

[0012] a) They exchange additional data required for nonce mapping:

[0013] i) for a so-called generic mapping, the DVLM-e chip and the inspection system exchange ephemeral public keys;

[0014] ii) for a so-called integrated mapping, the inspection system sends an additional nonce to the e-DVLM chip.

[0015] b) They calculate ephemeral domain parameters D = Map(Dlc,s,...) from the nonce s, static domain parameters D1C and the additional mapping data mentioned above.

[0016] c) They perform a Diffie-Hellman key agreement based on the ephemeral domain parameters D and asymmetric key pairs (SKDHjic, PKDHjic), (SKDHjifd, PKDh,ifd) and generate the shared secret K = KA(SKdh,ic, PKdh.ifd, D) = KA(SKdh,ifd, PK DH,IC, D).

[0017] d) They calculate session keys KSMAc = KDFmaC(K) and KSEnc = KDFEnc(K) using the shared secret K;

[0018] e) They exchange and verify an authentication token T1ED = MAC(KSmac, PKdh,ic) and T1C = MAC(KSmac, PKdh,ifd)

[0019] Conditionally, the e-DVLM chip calculates CA1C chip authentication data, encrypts it as A1C = E(KSEnc, CA1C) and sends it to the inspection system. The inspection system decrypts A1C and verifies the authenticity of the chip using the obtained CA1C chip authentication data.

[0020] The security of the PACE protocol relies on the secrecy of the ephemeral domain parameters used to generate the session keys.

[0021] However, a careful analysis of the risks raised by quantum computing shows that the contribution of asymmetric cryptography to ephemeral domain parameters might no longer remain secret, because the asymmetric cryptography would be broken. The only secret would result from the nonce generated by the e-MRTD chip and shared with the control terminal, encrypted using a symmetric algorithm with a symmetric key derived from an entry printed on the document (typically CAN or ZLA).

[0022] However, this symmetric algorithm is also threatened by the advent of the quantum computer. Thanks to Grover's algorithm, for example, the number of attempts required to carry out a brute force attack on a symmetric key would in fact be halved, going from 2128 attempts to 264 attempts for the 128-bit AES ("Advanced Encryption Standard") encryption standard. Statement of the invention

[0023] The invention aims to increase the resistance of the PACE protocol to attacks carried out by a quantum computer. The invention aims more particularly to provide solutions to this problem which are not only effective but also easy to implement within the framework of the existing protocol so that they can be deployed in the short term.

[0024] For this purpose, the invention proposes a method for establishing a connection with password authentication between a first device among an electronic chip of a person's identification data carrier and a control terminal and a second device different from the first device among the electronic chip and the control terminal, said connection establishment comprising the execution of a Diffie-Hellman key agreement by means of static or ephemeral domain parameters. Said execution comprises the implementation of the following steps by the first device: - encrypting a first ephemeral public key of the first device using a first symmetric encryption key derived from the identification data; and - transmission to the second device of the first encrypted ephemeral public key of the first device.

[0025] Some preferred but non-limiting aspects of this method are as follows: - it also includes the implementation of the following steps by the first device: • receiving a first ephemeral public key from the second device encrypted using a second symmetric encryption key identical to or different from the first symmetric encryption key; and • decrypting, using the second symmetric encryption key, the first encrypted ephemeral public key of the second device; - it further comprises the calculation, by the first device, of a secret shared with the second device, the calculation of the shared secret being carried out by means of the static or ephemeral domain parameters, the first ephemeral public key of the second device and a first ephemeral private key of the first device; - the Diffie-Hellman key agreement is performed using the static domain parameters, the first device performs a generic mapping of a nonce to determine the ephemeral domain parameters and the calculation of the shared secret is performed during said generic mapping when performing the Diffie-Hellman key agreement using the static domain parameters, the first ephemeral public key of the second device and the first ephemeral private key of the first device; - the Diffie-Hellman key agreement is performed using the ephemeral domain parameters, the first device performs a mapping of a nonce to determine the ephemeral domain parameters and the calculation of the shared secret is performed following said mapping when performing the Diffie-Hellman key agreement using the ephemeral domain parameters, the first ephemeral public key of the second device and the first ephemeral private key of the first device; - it further comprises, by the electronic chip, the encryption of a nonce by means of a symmetric encryption key derived from the identification data different from the first symmetric encryption key and the transmission of the encrypted nonce to the control terminal.

[0026] Alternatively and / or in addition, the invention proposes a method for establishing a connection with password authentication between a first device among an electronic chip of a person's identification data carrier and a control terminal and a second device different from the first device among the electronic chip and the control terminal. This method comprises the implementation of the following steps by the first device: - using a first symmetric encryption key derived from the identification data to encrypt a first nonce before transmitting the encrypted first nonce to the second device or to decrypt a first nonce after receiving the encrypted first nonce from the second device; - using a second symmetric encryption key derived from the identification data to encrypt a second nonce before transmitting the encrypted second nonce to the second device or to decrypt a second nonce after receiving the encrypted second nonce from the second device; - determination of ephemeral domain parameters of a Diffie-Hellman key agreement using static domain parameters, the first nonce and the second nonce.

[0027] Some preferred but non-limiting aspects of this method are as follows: - the determination of the ephemeral domain parameters is carried out by means of a mapping function having as parameters the static domain parameters and a concatenation of the first nonce and the second nonce; - the first and second nonce have the same nonce size and the determination of the ephemeral domain parameters is performed by means of a mapping function having as parameters the static domain parameters and a third nonce resulting from a mixture of the first nonce and the second nonce having the same nonce size as the first and second nonce.

[0028] Alternatively and / or in addition, the invention proposes a method for establishing a connection with password authentication between a first device among an electronic chip of a person's identification data carrier and a control terminal and a second device different from the first device among the electronic chip and the control terminal. This method comprises the determination, by the first device, of ephemeral domain parameters of a Diffie-Hellman key agreement from static domain parameters and a transformed nonce resulting from a transformation of a nonce using a first symmetric encryption key derived from the identification data.

[0029] Some preferred but non-limiting aspects of this method are as follows: - it further comprises the use, by the first device, of a second symmetric encryption key derived from the identification data to encrypt the nonce and provide a nonce ciphertext before transmitting the nonce ciphertext to the second device or to, after receiving a nonce ciphertext from the second device, decrypt the nonce ciphertext and obtain the nonce; - it further comprises the use, by the first device, of a second symmetric encryption key derived from the identification data to encrypt the transformed nonce and provide a ciphertext of the transformed nonce before transmitting to the second device the ciphertext of the transformed nonce or to decrypt a ciphertext of the transformed nonce after receiving the ciphertext of the transformed nonce from the second device and obtaining the transformed nonce; - the transformation of the nonce using the first symmetric encryption key is carried out by the electronic chip;

[0030] In each of these methods, the first symmetric encryption key may be derived from a first subset of the identification data, the second symmetric encryption key may be derived from a second subset of the identification data, the first subset and the second subset may be different, preferably disjoint.

[0031] According to other aspects, the invention provides a device comprising a processor configured to implement one and / or the other of these different methods and a computer program product comprising instructions which, when executed by a processor, lead the processor to implement one and / or the other of the different methods. Brief description of the drawings

[0032] Other aspects, aims, advantages and characteristics of the invention will appear better on reading the following detailed description of preferred embodiments thereof, given by way of non-limiting example, and made with reference to the appended drawings in which:

[0033] - [Fig.l], already presented previously, illustrates the main stages of the protocol PACE;

[0034] - [Fig.2] illustrates a first method according to the invention carrying out a sy encryption metric of public keys exchanged during a Diffie-Hellman key agreement executed within the framework of the PACE protocol;

[0035] - [Fig.3] illustrates a second method according to the invention using two nonces to generate the ephemeral domain parameters used during a Diffie-Hellman key agreement performed under the PACE protocol;

[0036] - [Fig.4] illustrates a first variant of a third method according to the invention performing a mapping of a nonce transformed by a transformation exploiting a symmetric encryption key;

[0037] - [Fig.5] illustrates a second variant of the third method according to the invention performing a mapping of a nonce transformed by a transformation exploiting a symmetric encryption key.

[0038] DETAILED DESCRIPTION OF PARTICULAR EMBODIMENTS

[0039] The invention relates to a method for establishing a connection with password authentication between an electronic chip of a person's identification data carrier and a control terminal, the password being derived from the identification data. The invention finds application in carrying out a control of the person to authorize or prohibit access to a secure area or service, for example before boarding an airplane or before crossing the border of a country or before authorizing access to resources contained in the electronic chip (such as for example a key used for electronic signature purposes).

[0040] According to a possible embodiment, the person's identification data carrier is a physical document (such as a passport, a residence permit or an identity card, or even a smart card) equipped with an electronic chip. The identification data are recorded in the electronic chip of the carrier. Furthermore, the identification data can be printed on the carrier or displayed by it. They can be read optically by the control terminal or alternatively be entered manually into the control terminal by an inspector or by the person themselves. These data can in particular correspond to the ZTA or the CAN mentioned above. Alternatively, they can correspond to a PIN code recorded in the electronic chip, this PIN code being able to be entered by the person or by an inspector in the control terminal.

[0041] According to another possible embodiment, the identification data support is a user terminal, such as a multifunction mobile or a connected watch, which carries a dematerialized identity document. The user terminal can be controlled to display the identification data on an interface of the user terminal, the control terminal then being able to proceed to optically read them.

[0042] It will be understood that whatever its format, the support for the person's identification data comprises an electronic chip and identification data whether these are displayed or physically printed on the support (for example in the form of a bar code), or even recorded in the chip.

[0043] The control terminal comprises a processor, a contact and / or contactless communication interface with the electronic chip and potentially a device for reading the identification data, for example a reading device optical and / or a human-machine interface.

[0044] In this context, the invention provides different solutions for increasing the resistance of the PACE protocol to quantum attacks. These different solutions can be implemented in isolation or, on the contrary, by being combined with each other in any possible form of combination. These different solutions to the same problem are based on the same concept consisting of modifying the PACE protocol to implement, in addition to the symmetric encryption of the nonce s using the Kir encryption key, an additional transformation (for example an encryption) by means of a Kir' symmetric encryption key derived from identification data carried by the person's identification data medium. It will be noted that symmetric encryption has the advantage of being more robust than standard asymmetric encryption to quantum attacks.

[0045] The advantages of these solutions are as follows. First, the PACE protocol is barely modified. Second, they are easy to implement. Finally, they are effective measures that can be quickly implemented, without having to wait for the design of a new protocol.

[0046] In a preferred embodiment, the Kir' key used to perform the additional encryption is derived from identification data carried by the person's identification data carrier that are different from the identification data (the shared password ir mentioned above) used to derive the Kir symmetric key used to perform the encryption / decryption of the nonce. In other words, the first Kir symmetric encryption key is derived from a first subset of the identification data (i.e., derived from a first password that typically corresponds to the data of this first subset of the identification data), the second Kir' symmetric encryption key is derived from a second subset of the identification data (i.e.,, derived from a second password that typically corresponds to the data of this second subset of the identification data), the first subset and the second subset being different. By different, it is meant here that the first subset and the second subset may have a partial overlap. In a preferred embodiment making it possible to increase the entropy of the two symmetric keys, the first subset and the second subset are disjoint. As a non-limiting example, if Kir = KDFir(ZLA) we can for example provide Kir' = KDFir(CAN) (ie, the shared password for this second key is the CAN number while the shared password for the first key is ZLA).

[0047] In the following, and with reference to Figures 2-5, it is considered that one of the electronic chip 10 of the person's identification data support and the control terminal 20 constitutes a first device while the other of the electronic chip electronics 10 and the control terminal 20 constitutes a second device different from the first device. Public key protection

[0048] As seen previously, the connection establishment according to PACE comprises the execution of a Diffie-Hellman key agreement using static domain parameters D1C or ephemeral domain parameters D. In particular, a Diffie-Hellman key agreement is executed using the static domain parameters D1C when a generic mapping of the nonce is implemented. Furthermore, we always find the execution of a Diffie-Hellman key agreement using the ephemeral domain parameters D to calculate the shared secret K allowing the session keys KSmac and KSEnc to be developed.

[0049] The execution of such a Diffie-Hellman key agreement follows the encryption by the electronic chip 10 of a nonce s by means of a symmetric encryption key Kir derived from the identification data, the transmission of the encrypted nonce to the control terminal 20 and the decryption of the encrypted nonce by the control terminal.

[0050] As shown in [Fig.2], the execution of such a Diffie-Hellman key agreement comprises the generation, by each of the first devices 10 or 20, of a pair of asymmetric ephemeral keys (PKI, SKI) or (PK2, SK2) during a step E10 or E20, the pair comprising a public key PKI or PK2 and a private key SKI or SK2. The execution of this agreement further comprises the transmission by each of the first and second devices to the other device of the ephemeral public key PKI, PK2 of its pair of asymmetric keys. Taking the example of [Fig.l] where the execution of a Diffie-Hellman key agreement is illustrated by means of the ephemeral domain parameters D, the ephemeral public keys PKDHjic and PKDHjifd are thus exchanged.

[0051] A first solution proposed by the invention consists of encrypting these ephemeral public keys by means of a symmetric encryption key Kir' derived from the identification data. A first method according to the invention then comprises the implementation of the following steps by each of the first and second devices during the execution of a Diffie-Hellman key agreement by means of the static or ephemeral domain parameters: the encryption during a step E11, E22 of its ephemeral public key PKI, PK2 by means of a symmetric encryption key derived from the identification data Kir' and the transmission during a step E12, E22 to the other device of its encrypted ephemeral public key cPK1=E(Kir', PKI), cPK2=E(Kir', PK2). Optionally, this encryption can also include integrity and authenticity protection (for example, using AES with the GCM operating mode for “Galois / Counter Mode”).

[0052] This method may further comprise implementing the following steps by each of the first and second devices: receiving the ephemeral public key of the other device encrypted using said symmetric encryption key cPK2=E(Kir', PK2), cPKl=E(Kir', PKI) and decrypting during a step E13, E23, using said symmetric encryption key Kir', the encrypted ephemeral public key of the other device PK2=D(Kir', cPK2), PK1= D(Kir', cPKl). Optionally, the devices 10 and 20, when decrypting the public keys cPK2 and cPKl during steps E13 and E23, can also verify their integrity and authenticity.

[0053] This method is completed by the calculation, by each of the first and second devices, of a shared secret K with the other device during a step E14, E24. The calculation of the shared secret K is carried out using the static domain parameters D 1C or ephemeral D, the ephemeral public key PK2, PKI of the other device and its ephemeral private key SKI, SK2 according to K = KA(SK1, PK2, D1C or D) or K = KA(SK2, PK1, D1C or D).

[0054] Whereas the Diffie-Hellman key agreement referred to here is that performed using the static domain parameters D1C, each of the first and second devices performs a generic mapping of the nonce s. The calculation of the shared secret by each of the first and second devices is then performed during said generic mapping when performing the Diffie-Hellman key agreement using the static domain parameters D1C, the ephemeral public key PK2, PKI of the other device and its ephemeral private key SKI, SK2. Each device, after obtaining the shared secret, then combines it with the nonce s to obtain the ephemeral domain parameters D.

[0055] Alternatively, considering that the Diffie-Hellman key agreement referred to here is that executed using the ephemeral domain parameters D, each of the first and second devices performs a mapping of the nonce s to determine the ephemeral domain parameters. The calculation of the secret shared by each of the first and second devices is then performed following said mapping when executing the Diffie-Hellman key agreement using the ephemeral domain parameters D, the ephemeral public key PK2, PKI of the other device and its ephemeral private key SKI, SK2.

[0056] In a possible embodiment, each of the Diffie-Helman key agreements (that of the generic mapping of the nonce with the static domain parameters and that allowing the generation of the session keys with the ephemeral domain parameters) implements a symmetric encryption of the public keys exchanged between the first and the second device. The method then comprises, in addition to the encryption of a first ephemeral public key of the first device by means of a first symmetric encryption key derived from the identification data and its transmission to the second device (during the first agreement), the encryption of a second ephemeral public key of the first device by means of a second symmetric encryption key derived from the identification data and its transmission to the second device (during the second approval).

[0057] In the above, each of the first and second devices uses the same symmetric encryption key Kir' to encrypt its public key PKI, PK2. The invention is however not limited to this exemplary embodiment, but actually extends to the use of multiple symmetric encryption keys derived from the identification data for the encryption of these public keys PKI, PK2, making it possible for example to use one symmetric encryption key per public key (i.e., a first symmetric encryption key to encrypt / decrypt the public key of the first device and a second symmetric encryption key to encrypt / decrypt the public key of the second device).

[0058] Thus, in a first variant embodiment, the same subset of the identification data jt' can be used to derive, by means of two different key calculation functions, a first symmetric encryption key Kir' and a second symmetric encryption key K'ir'. The first symmetric encryption key Kir' is used to encrypt / decrypt the public key PKI of the electronic chip 10 (which can be the first or the second device) and the second symmetric encryption key K'ir' is used to encrypt / decrypt the public key PK2 of the control terminal 20 (which can be the second or the first device). In this variant, we therefore have cPKl=E(Kir', PKI), PK1=D(Kir', cPKl), cPK2=E(K'ir', PK2) and PK2=D(K'ir', cPK2).

[0059] In a second embodiment, different subsets of the identification data jt', ir1' are used to derive respectively a first symmetric encryption key Kir' and a second symmetric encryption key Kir”. The first symmetric encryption key Kir' is used to encrypt / decrypt the public key PKI of the electronic chip 10 (which may be the first or the second device) and the second symmetric encryption key Kir” is used to encrypt / decrypt the public key PK2 of the control terminal (which may be the second or the first device). In this embodiment, we therefore have cPKl=E(Kir', PKI), PK1= D(Kir', cPKl), cPK2=E(Kir”, PK2) and PK2= D(Kir”, cPK2).

[0060] These two variants can of course be combined by using both two different key calculation functions and two different subsets of the identification data to derive keys Kir' and K'ir1'.

[0061] As indicated previously, preferably the symmetric encryption key(s) Kir', K'ir', Kir” and K'n:” used to encrypt the PKI public keys, PK2 is (are) derived from a first subset of the identification data, the symmetric encryption key Kir used to encrypt the nonce is derived from a second subset of the identification data, the first subset and the second subset being different, preferably disjoint. Nonce protection

[0062] The confidentiality of the nonce s that is used to generate the ephemeral domain parameters D is compromised by the Grover algorithm, thanks to which an attacker can break the only symmetric key Kir for encrypting / decrypting the nonce s and thus recover the nonce. A second method proposed by the invention makes it possible to strengthen security by using a second symmetric key Kir' also derived from the identification data to encrypt / decrypt a second nonce s'. The two nonces can also be used to generate the ephemeral domain parameters D.

[0063] With reference to [Fig.3], this second method comprises, during a step E15, the random drawing of two nonces s, s' by the electronic chip.

[0064] This method further comprises the implementation of the following steps by the first device 10 or 20: - use of a first symmetric encryption key Kir derived from the identification data to encrypt during a step El6 (when the first device is the electronic chip, referenced 10 in [Fig.3]) the first nonce s before transmission during a step E17 of the first encrypted nonce z= E(Kir,s) to the second device 20 or to decrypt during a step E27 (when the first device is the control terminal, referenced 20 in [Fig.3]) the first nonce s= D(Kir,z) after reception during a step E17 of the first encrypted nonce z from the second device; - use of a second symmetric encryption key Kir' derived from the identification data to encrypt during step E16 (when the first device is the electronic chip 10) the second nonce s' before transmission of the second encrypted nonce z' =E(Kjt',s') to the second device or to decrypt during step E27 (when the first device is the control terminal 20) the second nonce s'=D(Kir',z') after reception during step E17 of the second encrypted nonce z' from the second device; - determination during a step E18 (when the first device is the electronic chip 10) or during a step E28 (when the first device is the control terminal 20) of ephemeral domain parameters D of a Diffie-Hellman key agreement by means of static domain parameters D1C, of the first nonce s and of the second nonce s'.

[0065] It will be noted that step E17 may further comprise the transmission of the static domain parameters Dicde from the electronic chip to the control terminal. However, the latter may be transmitted in a step prior to carrying out this protocol.

[0066] In one possible embodiment, the determination of the ephemeral domain parameters is performed by means of a mapping function, possibly similar to that implemented for the generic mapping, having as parameters the static domain parameters D1C and a concatenation of the first nonce s and the second nonce s'.

[0067] In another possible embodiment allowing to use the mapping function specified in the PACE protocol, without modification, the first and the second nonce have the same nonce size and the determination of the ephemeral domain parameters is carried out by means of a mapping function, possibly similar to that implemented for the generic or integrated mapping, having as parameters the static domain parameters and a third nonce resulting from a mixture of the first nonce and the second nonce having the same nonce size as the first and the second nonce. The mixture of two nonces corresponds for example to a sum, an exclusive or XOR or a multiplication (and modular reduction) of the two nonces, or to a hash of the concatenation of the two nonces.

[0068] As indicated previously, here also preferably the first symmetric encryption key Kir is derived from a first subset of the identification data, the second symmetric encryption key Kir' is derived from a second subset of the identification data, the first subset and the second subset being different, preferably disjoint.

[0069] Protection of the calculation of ephemeral domain parameters

[0070] With reference to Figures 4 and 5, according to a third method proposed by the invention, the first device 10 or 20 performs the determination during a step F13, F18 or F23, F28 of ephemeral domain parameters of a Diffie-Hellman key agreement from static domain parameters D1C and a transformed nonce u, v resulting from a transformation of a nonce s carried out by means of a first symmetric encryption key Kir' derived from the identification data. The transformation of the nonce s may be an encryption of the nonce by means of the first symmetric encryption key Kir'. In another example, the transformation of the nonce corresponds to a mixture of the nonce s with the first symmetric encryption key Kir' by a sum, by an exclusive or XOR or by a multiplication (and modular reduction). In yet another example, the transformation of the nonce s can be a hash of the concatenation of the nonce with the first symmetric encryption key Kir'.

[0071] [Fig.4] illustrates a first possible embodiment of this third method which follows the performance by the electronic chip 10 of the drawing of a nonce s during a step F10. It comprises the implementation of the following steps by the first device 10 or 20: - use, when the first device is the electronic chip 10, of the first symmetric encryption key Kir' derived from the identification data during a Fil step to transform the nonce and provide a transformed nonce u=T(Kir',s); - use of a second symmetric encryption key Kir derived from the identification data to encrypt the nonce s during step E1 1 (when the first device is the electronic chip 10) and provide a nonce ciphertext z=E(Kir,s) before transmission during a step F12 of the nonce ciphertext to the second device or (when the first device is the control terminal 20) to, after receiving a nonce ciphertext z from the second device, decrypt during a step F22 the nonce ciphertext z and obtain the nonce s=D(Kir,z). The transmission during step F12 of the nonce ciphertext z may be accompanied by the transmission of the static domain parameters D1C to the control terminal. However, the static domain parameters may be transmitted in a step prior to the implementation of this protocol; - use, when the first device is the control terminal 20, during step F22 of the first symmetric encryption key Kir' derived from the identification data to transform the nonce and provide the transformed nonce u=T(Kir',s); - determination of the ephemeral domain parameters D during a step F13 or F23 from the static domain parameters D1C and the transformed nonce u.

[0072] [Fig.5] illustrates a second possible embodiment of this third method which also follows the performance by the electronic chip 10 of the drawing of a nonce s during a step F15. It comprises the implementation of the following steps by the first device 10 or 20: - use, when the first device is the electronic chip 10, of the first symmetric encryption key Kir' derived from the identification data during a step F16 to transform the nonce and provide a transformed nonce v=T(Kir',s); - use of a second symmetric encryption key Kir derived from the identification data to encrypt the transformed nonce during step F16 (when the first device is the electronic chip 10) and provide a transformed nonce ciphertext z=E(Kir,v) before transmission during a step F17 of the transformed nonce ciphertext to the second device or (when the first device is the control terminal 20) to, after receiving a transformed nonce ciphertext z from the second device, decrypt during a step F27 the transformed nonce ciphertext z and obtain the transformed nonce v=D (Kir,z). The transmission during step F17 of the transformed nonce ciphertext z may be accompanied by the transmission of the static domain parameters D1C to the control terminal. However, the static domain parameters may be transmitted in a step prior to the implementation of this protocol; - determination of the ephemeral domain parameters D during a step Fl8 or F28 from the static domain parameters D1C and the transformed nonce v.

[0073] As for the other methods described previously, preferably the first symmetric encryption key Kir' is derived from a first subset of the identification data, the second symmetric encryption key Kir is derived from a second subset of the identification data, the first subset and the second subset being different, preferably disjoint.

[0074] The invention is not limited to the methods previously described but also extends to a device (for example an electronic chip or a control terminal) comprising a processor configured to implement the steps of one and / or the other of these different methods. The invention also relates to a computer program product comprising instructions which, when executed by a processor, lead the processor to implement the steps of one and / or the other of the different methods as well as a computer-readable data medium on which such a computer program product is recorded.

Claims

Claims

1. Method for establishing a connection with password authentication between a first device among an electronic chip (10) of a person's identification data carrier and a control terminal (20) and a second device different from the first device among the electronic chip (10) and the control terminal (20), said connection establishment comprising the execution of a Diffie-Hellman key agreement by means of static (D1C) or ephemeral (D) domain parameters, said execution comprising the implementation of the following steps by the first device: - the encryption (E11, E21) of a first ephemeral public key (PKI, PK2) of the first device by means of a first symmetric encryption key (Kir') derived from the identification data; and - the transmission (E12, E22) to the second device of the encrypted first ephemeral public key of the first device (cPKl, cPK2).

2. The method of claim 1, further comprising the implementation of the following steps by the first device: - receiving (E22, El2) a first ephemeral public key of the second device encrypted (cPK2, cPKl) by means of a second symmetric encryption key identical to or different from the first symmetric encryption key; and - decrypting (E13, E23), by means of the second symmetric encryption key, the first encrypted ephemeral public key of the second device.

3. The method of claim 2, further comprising calculating (E14, E24), by the first device, a shared secret (K) with the second device, the calculation of the shared secret being performed using the static (D1C) or ephemeral (D) domain parameters, the first ephemeral public key (PK2, PKI) of the second device and a first ephemeral private key (SKI, SK2) of the first device.

4. The method of claim 3, wherein the Diffie-Hellman key agreement is performed using static domain parameters (D1C ), wherein the first device performs a generic mapping of a nonce to determine the ephemeral domain parameters (D) and wherein the calculation of the shared secret is performed during said generic mapping when performing the Diffie-Hellman key agreement using the static domain parameters (D1C), the first ephemeral public key (PK2, PKI) of the second device and the first ephemeral private key (SKI, SK2) of the first device.

5. The method of claim 3, wherein the Diffie-Hellman key agreement is performed using the ephemeral domain parameters (D), wherein the first device performs a mapping of a nonce to determine the ephemeral domain parameters (D), and wherein the calculation of the shared secret is performed following said mapping when performing the Diffie-Hellman key agreement using the ephemeral domain parameters (D), the first ephemeral public key (PK2, PKI) of the second device, and the first ephemeral private key (SKI, SKI) of the first device.

6. The method of claim 1, further comprising, by the electronic chip (10), encrypting a nonce using a symmetric encryption key (Kir) derived from the identification data different from the first symmetric encryption key and transmitting the encrypted nonce to the control terminal (20).

7. Method for establishing a connection with password authentication between a first device among an electronic chip (10) of a person's identification data carrier and a control terminal (20) and a second device different from the first device among the electronic chip (10) and the control terminal (20), said method comprising the implementation of the following steps by the first device: - using a first symmetric encryption key (Kir) derived from the identification data to encrypt (El6) a first nonce (s) before transmission (E17) of the first encrypted nonce (z) to the second device or to decrypt (E27) a first nonce (s) after reception of the first encrypted nonce (z) from the second device; - using a second symmetric encryption key (Kir') derived from the identification data to encrypt (El6) a second nonce (s') before transmission (E17) of the second encrypted nonce (z') to the second device or to decrypt (E27) a second nonce (s') after receiving the second encrypted nonce (z') from the second device; - determining (El8, E28) ephemeral domain parameters (D) of a Diffie-Hellman key agreement by means of static domain parameters (D1C), the first nonce (s) and the second nonce (s').

8. The method of claim 7, wherein the determination (El8, E28) of the ephemeral domain parameters is performed by means of a mapping function having as parameters the static domain parameters and a concatenation of the first nonce and the second nonce.

9. The method of claim 7, wherein the first and second nonce have the same nonce size and wherein the determination (El8, E28) of the ephemeral domain parameters is performed by means of a mapping function having as parameters the static domain parameters and a third nonce resulting from a mixture of the first nonce and the second nonce having the same nonce size as the first and second nonce.

10. Method for establishing a connection with password authentication between a first device among an electronic chip (10) of a person's identification data carrier and a control terminal (20) and a second device different from the first device among the electronic chip (10) and the control terminal (20), said method comprising the determination (F13, F18), by the first device, of ephemeral domain parameters of a Diffie-Hellman key agreement from static domain parameters (D1C) and a transformed nonce (u, v) resulting from a transformation of a nonce (s) exploiting a first symmetric encryption key (Kir') derived from the identification data.

11. The method of claim 11, further comprising using, by the first device, a second symmetric encryption key (Kir) derived from the identification data to encrypt (Fl 1) the nonce(s) and provide a nonce ciphertext (z) before transmitting (F12) the nonce ciphertext to the second device or to, after receiving a nonce ciphertext from the second device, decrypt (F22) the nonce ciphertext and obtain the nonce(s).

12. The method of claim 11, further comprising using, by the first device, a second symmetric encryption key (Kir) derived from the identification data to encrypt (F 16) the transformed nonce and provide a ciphertext of the transformed nonce (z) before transmitting (F17) to the second device the ciphertext of the transformed nonce or to decrypt (F27) a ciphertext of the transformed nonce after receiving the ciphertext of the transformed nonce from the second device and obtain the transformed nonce (v).

13. Method according to one of claims 10 to 12, in which the transformation of the nonce using the first symmetric encryption key (Kir') is carried out by the electronic chip (10).

14. Method according to one of claims 6-9 and 11-13, wherein the first symmetric encryption key is derived from a first subset of the identification data, the second symmetric encryption key is derived from a second subset of the identification data, the first subset and the second subset being different, preferably disjoint.

15. Device (10, 20) comprising a processor configured to implement the steps of the method according to one of claims 1 to 14.

16. A computer program product comprising instructions which, when executed by a processor, cause the processor to implement the steps of the method according to one of claims 1 to 14.