Method and system for verifying the validity of digital content - Patents.com
Patent Information
- Application Number
- JP2024513213
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-09-01
- Filing Date
- 2022-08-31
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2042-08-31
AI Technical Summary
Existing digital data validation and authentication systems lack sufficient security and reliability, particularly in untrusted environments, making it difficult to verify the authenticity of digital signatures and the authority of the signing entity, and are costly and difficult to implement across various communication protocols.
A system and method for validating digital content using a forgery-proof digital file with aggregated digital signatures computed by a one-way accumulator, allowing devices to verify the authenticity of digital messages without identifying the signing entity, using a one-way function to calculate and match candidate signatures with stored aggregated signatures.
Enhances the certainty of digital content validation, ensuring the authenticity of digital messages and the authority of the signing entity, while avoiding the need for biometric data and maintaining privacy, and allowing offline operations.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001]
[0001] The present invention relates to the technical field of validation and authentication of digital data, such as digital documents. In particular, the present invention relates to the technical field of validation of the digital content of digital messages, such as operations authenticated by an entity authorized by a controller to perform said operations. Background of the invention
[0002]
[0002] The problems of counterfeiting and falsification of digital data are well known and are increasing every day. With regard to the industrial sector, the digitalization of several processes is usually very vulnerable to cyber attacks. When one computer interacts with another computer, the predefined security protocols are hardly sufficient against the techniques of hackers. Furthermore, since there are so many industries and so many protocols for computers to communicate between each other, the prior art solutions to these problems are very difficult to implement, cost a lot of money and have to be adapted according to each situation. Thus, there is an urgent need for a solution to ensure the integrity of processes in untrusted environments, for example when several devices need to exchange data or perform, for example, authorized tasks.
[0003]
[0003] It is therefore now more essential than ever to be able to verify and authenticate, with a high degree of security, the validity of operators presenting digital data or such digital documents containing such digital data, and at the same time it is essential to find low-cost solutions that can be easily and quickly implemented.
[0004] Indeed, how can a computer, a robot, or a citizen today reliably identify that an operator or employee who digitally signs a digital document has the legitimacy to sign and validate such a document on behalf of the entity that the signature represents?
[0005]
[0005] In a more general way, how can a computer or robot be sure that the computer or robot behind this digital signature is the correct computer or robot, and that this entity is authorized to sign such documents on behalf of an organization?
[0006]
[0006] In essence, how can an entity trust digitally signed data and the entity that signed the data?
[0007]
[0007] In the physical world, what gives a paper document its authenticity is the signature, and especially the stamp or seal, of the authority that issued the document. In the digital world, this situation needs to be replaced.
[0008]
[0008] In the digital world, trust is mainly conferred by digital signatures that are authenticated by a chain of certificates. For example, those skilled in the art know solutions for protecting digital files against forgery, such as the solution described in the document US 2021 / 258168 A1. However, this solution lacks significant security and does not guarantee with a high degree of certainty that the signer, on behalf of the institution that the signature represents, had the authority and right to sign the type of document in question on that particular date.
[0009]
[0009] It is therefore an object of the present invention to be able to verify with greater certainty the validity of digital data or digital documents and thus to authenticate the operator presenting said digital data or said digital documents to a recipient. Summary of the Invention
[0010] According to one aspect, the invention relates to a method for validation of the digital content of a digital message M, preferably in the form of a forgery proof digital file received by a device DB controlled by a controller B via a communications network CN, comprising: a device DA controlled by a controller A, comprising a processing unit CPU(A) having a memory storing a digital message M, and a communication module CM(A) adapted to send and receive data via a communication network CN, the device DB comprises a processing unit CPU(B) having a memory storing an aggregate digital signature ADS, and a communication module CM(B) adapted to transmit and receive data via a communication network CN, said aggregate digital signature ADS being preferably calculated by applying a one-way accumulator to a number of digital signatures, said number of digital signatures including a digital signature x(A) of the authorization data AD(A) calculated by a one-way function, Preferably, the digital message M contains authorization data AD(A) indicating that a controller A of a device DA is authorized by a controller C to perform an operation Op using the controller of the device receiving said digital message M, the digital message M being authenticated by the controller C, the digital message M also contains a verification key VK(A) attributable to the controller C, said verification key VK(A) together with the authorization data AD(A) making it possible to retrieve an aggregate digital signature ADS stored in a memory of a processing unit CPU(B) of the device DB, said verification key VK(A) together with the authorization data AD(A) is preferably used to calculate a candidate aggregate digital signature cADS, said processing unit CPU(B) being configured to compare said candidate aggregate digital signature cADS with the aggregate digital signature ADS stored in the memory of the processing unit CPU(B) of the device DB, This method is a step in which a communication module CM(B) of the device DB receives a digital message M, the communication module CM(B) of the device DB preferably receiving the digital message M for example from a communication module CM(A) and / or from a controller C and / or from a server comprising a database, Preferably, a processing unit CPU (B) of the device DB verifies that the digital message M is authenticated by the controller C; and a step in which the processing unit CPU(B) of the device DB extracts the authorization data AD(A) contained in the digital message M, preferably only in case of a positive verification that the digital message M is authenticated by the controller C, a communication module CM(B) of the device DB receiving an authorized SA from a communication module CM(A) of the device DA; a processing unit CPU(B) of the device DB verifying the certified SA; The processing unit CPU(B) of the device DB is Extracting a verification key VK(A) contained in a digital message M; - calculating a candidate digital signature cx(A) of the authorization data AD(A) by means of a one-way function programmed in a processing unit CPU(B); calculating a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A); and The method includes a step in which the processing unit CPU(B) of the device DB checks whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory, and only in case of positive verification of the certified SA data and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) of the device DB sends, via the communication module CM(B), an indication to the controller B that the controller A is indeed authorized by the controller C to perform the operation Op.
[0011]
[0011] The present invention allows a recipient to verify the validity of a particular digital content with greater certainty than prior art solutions. Indeed, the present invention allows a controller B to verify the validity of the digital content of a digital message M with greater certainty than prior art solutions.
[0012]
[0012] Furthermore, the present invention allows the device DB to control authentication information linked to this digital content in order to check whether this digital content is valid.
[0013]
[0013] The present invention allows controller B to verify the validity of a particular digital content based on controller A's public key without needing to identify controller A.
[0014]
[0014] According to this system, as long as controller B contains the aggregate digital signature ADS, controller A and controller B do not need to query controller C or access controller C's database for controller B to verify the validity of the digital content of digital message M.
[0015] According to an embodiment, the memory of the processing unit CPU(A) of the device DA stores a private key PrK(A), preferably stored in a protected enclave in the memory of the processing unit CPU(A), the processing unit CPU(A) is configured to sign data using the private key PrK(A), the processing unit CPU(B) of the device DB is configured by the communication module CM(B) to verify the signed data using the corresponding public key, and the digital message M is a control key corresponding to the private key PrK(A). The digital message M further includes a public key PuK(A) that has been certified by the controller C as being owned by the roller A, and the certified SA is certified data signed using the private key PrK(A), and prior to the step of verifying said certified SA by the processing unit CPU(B) of the device DB, the processing unit CPU(B) of the device DB extracts the public key PuK(A) from the digital message M, and the step of verifying said certified SA includes verifying the certified SA by the processing unit CPU(B) of the device DB using said public key PuK(A).
[0016]
[0016] This allows controller B to verify that controller A who signed the certification data is in fact the same controller A mentioned in the digital message M.
[0017]
[0017] According to an embodiment, the digital message M is authenticated by the controller C and the aforementioned method comprises, prior to the step of extracting, by the processing unit CPU(B) of the device DB, the authorization data AD(A) contained in the digital message M, a step of verifying, by the processing unit CPU(B) of the device DB, that the digital message M has been authenticated by the controller C, and only in case of a positive verification that the digital message M has been authenticated by the controller C, the processing unit CPU(B) of the device DB extracts the authorization data AD(A) contained in the digital message M.
[0018]
[0018] This makes it possible to verify that the digital message M has been legitimately issued by the controller C. According to an example, the step of verifying by the processing unit CPU(B) that the digital message M has been authenticated by the controller C can be performed, for example, using a cryptographic process or a cryptographic signature.
[0019] According to another aspect, the invention relates to a system for validation of the digital content of a digital message M received by a device DB controlled by a controller B through a communications network CN, the system comprising: a device DA controlled by a controller A, comprising a processing unit CPU(A) having a memory storing a digital message M and a communication module CM(A) adapted to send and receive data via a communication network CN, the device DB comprises a processing unit CPU(B) having a memory storing an aggregate digital signature ADS and a communication module CM(B) adapted to transmit and receive data via a communication network CN, said aggregate digital signature ADS being calculated by applying a one-way accumulator to a plurality of digital signatures, said plurality of digital signatures comprising a digital signature x(A) of the authorization data AD(A) calculated by a one-way function, Preferably, the digital message M contains authorization data AD(A) indicating that a controller A of a device DA is authorized by a controller C to perform an operation Op using the controller of the device receiving said digital message M, the digital message M being authenticated by the controller C, the digital message M also contains a verification key VK(A) attributable to the controller C, said verification key VK(A) together with the authorization data AD(A) making it possible to retrieve an aggregate digital signature ADS stored in a memory of a processing unit CPU(B) of the device DB, said verification key VK(A) together with the authorization data AD(A) is preferably used to calculate a candidate aggregate digital signature cADS, said processing unit CPU(B) being configured to compare said candidate aggregate digital signature cADS with the aggregate digital signature ADS stored in the memory of the processing unit CPU(B) of the device DB, a communication module CM(B) of the device DB is arranged to receive a digital message M, the communication module CM(B) of the device DB being preferably arranged to receive the digital message M, for example from the communication module CM(A) and / or from the controller C and / or from a server comprising a database, Preferably, the processing unit CPU(B) of the device DB is configured to verify that the digital message M is authenticated by the controller C; a processing unit CPU(B) of the device DB is adapted to extract the authorization data AD(A) contained in the digital message M, said extraction preferably only taking place in case of a positive verification that the digital message M is authenticated by the controller C, The communication module CM(B) of the device DB is configured to receive the certified SA from the communication module CM(A) of the device DA; A processing unit CPU(B) of the device DB is configured to validate the certified SA; The processing unit CPU(B) of the device DB is Extracting a verification key VK(A) contained in a digital message M; - calculating a candidate digital signature cx(A) of the authorization data AD(A) by means of a one-way function programmed in a processing unit CPU(B); and calculating a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A), A processing unit CPU(B) of the device DB is configured to check whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory, and only in case of positive verification of the certified SA data and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) of the device DB is configured to send, via the communication module CM(B), an indication to the controller B that the controller A is indeed authorized by the controller C to perform the operation Op.
[0020]
[0020] For example, the invention allows a controller A, e.g. a robot, to identify itself using only the certified SA and authentication information, said authentication information being in a digital message M and authenticated by a forgery-proof digital file issued by a controller C. Advantageously, the digital message M contains or is the forgery-proof digital file issued by the controller C. A controller B, e.g. another robot, can fully trust the validity of the presented authentication information.
[0021]
[0021] It should be noted that the present invention avoids the use of biometric data, for example in the case where controller A is a human. The authentication information and the authorized SA of controller A are sufficient to give full trust to the recipient, here controller B, which can be for example a robot, a computer or another human. The present invention advantageously avoids the disclosure of any biometric data, biometrics or personal information.
[0022]
[0022] According to an embodiment of the invention, controller A may have a private key which it may use in relation to said certified SA to identify itself, for example by means of a challenge. Said private key is associated with a public key. Advantageously, controller C, which issued the forgery-proof digital file, has authenticated said public key, allowing the recipient, and therefore controller B, to check the validity of said certified SA.
[0023]
[0023] Furthermore, the recipient, i.e., controller B, maintains a counterfeit-proof digital file, i.e., digital message M, and in case of any problem, such as accusations regarding the actions of the controller and / or any industrial incident, can use the digital message M to contact the issuer, i.e., controller C, and ask him to identify controller A. However, controller A can remain anonymous to the recipient, and controller A is the only issuer of the counterfeit-proof digital file that can identify controller A.
[0024]
[0024] According to another aspect, the invention relates to the use of a system for validation of the digital content of a digital message M according to the invention for validating, by a device DB, the execution of an operation Op, said operation being executed by a device DA, A device DB is provided in and controlled by a storage room B, a device DA is provided in and controlled by a robot A, and an operation Op is related to the robot A fetching a particular product placed inside the storage room B, or the device DB is provided on and controlled by a computer B, the device DA is provided on and controlled by a smartphone A, and the operation Op relates to the smartphone A sending a set of data SeD(A) to the computer B, or A device DB is provided on and controlled by a medical device B, a device DA is provided on and controlled by a nurse A, and an operation Op relates to the nurse A injecting a particular drug into a particular patient using said medical device B; or A device DB is provided to and controlled by Citizen B, a device DA is provided to and controlled by Officer A, and an operation Op relates to Officer A entering the home of Citizen B to search for evidence; or A device DB is provided to and controlled by a citizen B, a device DA is provided to and controlled by a civil servant A, and operations Op relate to the civil servant issuing and signing official digital documents.
[0025] Before a detailed review of the embodiments of the present invention is provided below, some optional features that may be used in conjunction with or as alternatives are listed below.
[0026]
[0026] According to an example, the memory of a processing unit CPU(A) of the device DA stores a private key PrK(A), preferably stored in a protected enclave in the memory of the processing unit CPU(A), and the processing unit CPU(A) is configured to sign data using the private key PrK(A).
[0027] According to an example, the processing unit CPU(B) of the device DB is configured to verify data signed by the communication module CM(B) using the corresponding public key.
[0028] According to an example, the digital message M further comprises a public key PuK(A) that corresponds to the private key PrK(A) and that is certified by the controller C as being owned by the controller A.
[0029] According to an example, the certificate SA is a certificate data signed using the private key PrK(A).
[0030] According to an example, before the step of verifying said certified SA by the processing unit CPU(B) of the device DB, the processing unit CPU(B) of the device DB extracts the public key PuK(A) from the digital message M.
[0031] According to an example, the step of verifying said certified SA comprises verifying said certified SA by the processing unit CPU(B) of the device DB using said public key PuK(A).
[0032]
[0032] According to an example, the communications network CN includes a short range wireless communications network NFCN.
[0033]
[0033] According to an example, the communication module CM(A) is configured to transmit and receive data via a short-range wireless communication network NFCN, and the communication module CM(B) is configured to transmit and receive data via the short-range wireless communication network NFCN, which preferably enables communication between the communication modules CM(A) and CM(B) when the distance between the communication modules CM(A) and CM(B) is less than 50 cm, which distance is preferably less than 25 cm and advantageously less than 10 cm.
[0034]
[0034] According to an example, the device DA comprises a display module DD(A) and an optical reader module OR(A), and the device DB comprises a display module DD(B) and an optical reader module OR(B).
[0035]
[0035] According to an example, the step of receiving the digital message M by the communication module CM(B) of the device DB comprises a step of reading, by the optical reader module OR(B), an optically readable representation of a graphical data block GDB displayed by the display module DD(A), said graphical data block GDB comprising a digital mark DM.
[0036]
[0036] According to an example, said digital mark DM comprises an encoded version EAD(A) of said authorization data AD(A) and an encoded version EVK(A) of said verification key VK(A).
[0037] According to an example, the extraction of the authorization data AD(A) comprises decoding said encoded authorization data EAD(A).
[0038] According to an example, the extraction of the verification key VK(A) comprises decoding said encoded verification key EVK(A).
[0039]
[0039] According to an example, the optically readable representation of the graphical data block GDB comprises a digital representation of a graphical symbol from a specific finite set of graphical symbols, the digital representation of the graphical symbol being configured to encode the digital mark MD and a machine-readable error correction data block.
[0040]
[0040] According to an example, the memory of the device DB stores a private key Prk(B), preferably within a protected enclave in the memory of a processing unit CPU(B), certified by controller C as owned by controller B, and a corresponding public key PuK(B), the processing unit CPU(B) of the device DB being configured to sign data using said private key PrK(B).
[0041]
[0041] According to an example, the processing unit CPU(A) of the device DA is configured to verify data signed by the communication module CM(A) using the corresponding public key.
[0042]
[0042] According to an example, the method comprises a step, prior to the step of receiving, by the communications module CM(B), from the communications module CM(A), of transmitting, preferably at a specific moment, from the communications module CM(B) to the communications module CM(A), a secret generated by the device DB, said secret being adapted to generate said certified SA.
[0043] According to an example, said secret is arranged to be signed by the processing unit CPU(A) using the private key PrK(A) in order to generate said certified SA.
[0044]
[0044] According to an example, the said step of transmitting said secret comprises a step of displaying, by a display module DD(B), an optically readable representation of a graphical element encoding said secret and configured to be read by an optical reader module OR(A).
[0045] According to an example, before or after receiving the digital message M, the controller B receives the digital document.
[0046]
[0046] According to an example, the certified SA comprises a signature of the content of said digital document, said signature being generated by the processing unit CPU(A) by signing said content using a private key PrK(A), and preferably the certified SA comprises a signature of a hash of at least a part of the content of said digital document, said signature being generated by the processing unit CPU(A) using the private key PrK(A) and said hash being calculated by a one-way function programmed in the processing unit CPU(A).
[0047] According to an example, a digital message M is authenticated by a controller C.
[0048]
[0048] According to an example, the method comprises, prior to the step of extracting, by the processing unit CPU(B) of the device DB, the authorization data AD(A) contained in the digital message M, a step of verifying, by the processing unit CPU(B), that the digital message M has been authenticated by the controller C, and only in case of a positive verification that the digital message M has been authenticated by the controller C, the processing unit CPU(B) of the device DB extracts the authorization data AD(A) contained in the digital message M.
[0049]
[0049] According to an example, the memory of a processing unit CPU(A) of the device DA is configured to store a private key PrK(A), preferably in a protected enclave in the memory of the processing unit CPU(A), and the processing unit CPU(A) is configured to sign data using the private key PrK(A).
[0050]
[0050] According to an example, the processing unit CPU(B) of the device DB is configured to verify data signed by the communication module CM(B) using the corresponding public key.
[0051] According to an example, the digital message M further comprises a public key PuK(A) that corresponds to the private key PrK(A) and that is certified by the controller C as being owned by the controller A.
[0052] According to an example, the certificate SA is a certificate data signed using the private key PrK(A).
[0053] According to an example, the processing unit CPU(B) of the device DB is adapted to extract the public key PuK(A) from the digital message M.
[0054] According to an example, the processing unit CPU(B) of the device DB is configured to verify said certified SA using said public key PuK(A).
[0055]
[0055] According to an example, the device DB comprises a secret generator module SGB(B) configured to generate a secret, preferably configured to generate the secret at a particular moment, said secret being configured to be transmitted by the communication module CM(B) of the device DB to the communication module CM(A) of the device DA.
[0056] According to an example, the processing unit CPU(A) of the device DA is configured to generate the aforementioned certified SA using the aforementioned secret.
[0057] According to an example, the processing unit CPU(A) of the device DA is configured to sign said secret using the private key PrK(A) to generate said certified SA.
[0058]
[0058] According to an example, the device DA comprises a display module DD(A) and an optical reader module OR(A), and the device DB comprises a display module DD(B) and an optical reader module OR(B).
[0059]
[0059] According to an example, the display module DD(A) of the device DA is adapted to display an optically readable representation of the graphical data block GDB.
[0060]
[0060] According to an example, the optical reader module OR(B) of the device DB is configured to read said optically readable representation of a graphical data block GDB, said graphical data block GDB including a digital mark DM.
[0061]
[0061] According to an example, said digital mark DM comprises an encoded version EAD(A) of said authorization data AD(A) and an encoded version EVK(A) of said verification key VK(A).
[0062]
[0062] According to an example, the processing unit CPU(B) of the device DB is adapted to extract the authorization data AD(A) by decoding the aforementioned encoded authorization data EAD(A).
[0063] According to an example, the processing unit CPU(B) of the device DB is configured to extract the verification key VK(A) by decoding the aforementioned encoded verification key EVK(A).
[0064]
[0064] According to an example, a device DB is provided for and controlled by a storage room B, a device DA is provided for and controlled by a robot A, and an operation Op relates to the robot A retrieving a particular product placed inside the storage room B.
[0065]
[0065] According to an example, a device DB is provided on and controlled by a computer B, a device DA is provided on and controlled by a smartphone A, and an operation Op relates to the smartphone A sending a set of data SeD(A) to the computer B.
[0066]
[0066] According to an example, a device DB is provided on and controlled by a medical device B, a device DA is provided on and controlled by a nurse A, and an operation Op relates to nurse A injecting a particular drug into a particular patient using said medical device B.
[0067]
[0067] According to an example, a device DB is provided to and controlled by a citizen B, a device DA is provided to and controlled by a police officer A, and an action Op relates to the police officer A entering the house of the citizen B to search for evidence.
[0068]
[0068] According to an example, a device DB is provided to and controlled by a citizen B, a device DA is provided to and controlled by a civil servant A, and an operation Op relates to the civil servant A issuing and signing an official digital document.
[0069]
[0069] According to an example, the verification key VK is configured to calculate at least one candidate aggregate digital signature cADS using a candidate digital signature cx of the authorization data AD, said candidate digital signature cx of the authorization data AD being calculated using a one-way function programmed in the processing unit CPU(B), and said processing unit CPU(B) is configured to compare said candidate aggregate digital signature cADS with the aggregate digital signature ADS stored in the memory of the processing unit CPU(B) of the device DB.
[0070]
[0070] According to an example, the verification key comprises a sequence of digital signature values structured according to a data structure corresponding to a tree, these digital signature values corresponding to the node values and leaf values of said tree.
[0071]
[0071] According to an example, a candidate aggregate digital signature cADS can be calculated using a verification key VK containing a sequence of node values corresponding to the digital signature value and using a calculated candidate digital signature cx of the authorization data AD, said calculated candidate digital signature cx being calculated using a one-way function programmed in the processing unit CPU(B).
[0072] According to an example, the verification key VK comprises a sequence of node values structured according to a tree structure, said node values corresponding to digital signature values, the calculated candidate digital signature cx of the authorization data AD is calculated using a one-way function programmed in the processing unit CPU(B), and the calculation of the candidate aggregate digital signature cADS is a. extracting from the sequence of node values in the verification key VK, other than the node value of the particular leaf node corresponding to the calculated candidate digital signature cx of the authorization data AD, the node values (i.e. digital signature values) of all other leaf nodes of the tree having the same parent node, and computing the digital signatures of the particular node value and the concatenation of the extracted node values of all said other leaf nodes according to the ordering of the nodes in the tree and the tree concatenation ordering, respectively, thus obtaining the digital signatures of said same parent node of the particular leaf node; b. At each successive level in the tree, down to the penultimate node level, c. Extracting from the sequence of node values of the verification key VK the node values (i.e., digital signature values) of all other non-leaf nodes of the tree having the same parent node, other than the node value of the previous same parent node considered in the preceding step; and d. calculating a digital signature of the concatenation of the node values of every other non-leaf node and the obtained digital signature of the previous same parent node according to the ordering of the nodes in the tree and the tree concatenation ordering, thus obtaining the node value of the previous same parent node of the previous same parent node; and e. Computing a digital signature of the concatenation of the obtained node values of the non-leaf nodes corresponding to the penultimate node level of the tree according to the ordering of the nodes in the tree and the tree concatenation ordering, thus obtaining a root digital signature of the root node of the tree, said root digital signature corresponding to the candidate aggregate digital signature cADS. [Brief description of the drawings]
[0073]
[0073] The goals, objectives, and technical features and advantages of the present invention will become more apparent from the detailed description of the embodiments of the present invention, as illustrated by the following figures. [Figure 1] FIG. 1 is a general schematic diagram of an embodiment of the present invention. [Diagram 2] FIG. 2 is a schematic diagram of an embodiment of the present invention according to a first use case. [Diagram 3] FIG. 2 is a schematic diagram of an embodiment of the present invention according to a second use case. [Figure 4] FIG. 11 is a schematic diagram of an embodiment of the present invention according to a third use case. [Diagram 5] FIG. 11 is a schematic diagram of an embodiment of the present invention according to a fourth use case. [Figure 6] FIG. 13 is a schematic diagram of an embodiment of the present invention according to a fifth use case. [Figure 7] 1 is a schematic diagram of a method for protecting the content of a digital message according to an embodiment of the present invention. [Figure 8] 2 is a schematic diagram of a device DA and a device DB according to an embodiment of the present invention. Detailed Description
[0074]
[0074] The drawings are provided as examples and are not limiting of the present invention. The drawings constitute representations of principles intended to facilitate understanding of the present invention, and are not necessarily at the scale of practical application.
[0075]
[0075] The present disclosure is described in detail herein with reference to non-limiting embodiments illustrated in the drawings.
[0076]
[0076] The present invention relates to a system and method for validation of the digital content of a digital message M. As will be explained below, the digital message M is advantageously a counterfeit-proof digital file. In one embodiment, said digital message M may have been generated from a non-digital message, e.g. a handwritten or printed message, and is preferably generated using handwritten-to-digital and / or printed-to-digital conversion, e.g. using a scanner and / or a camera.
[0077]
[0077] According to an embodiment, the aforementioned digital message M may contain multiple types of data, such as authentication information of the device or of the controller, instructions for the controller's mission to perform the operation Op, and data regarding the authority that distributed the aforementioned authentication information.
[0078]
[0078] According to a preferred embodiment, the digital message M comprises authorization data AD. Said authorization data AD is configured to indicate that a controller of the device is authorized by another controller to carry out an operation Op, preferably using another controller of the device which has received said digital message M. The digital message M can preferably also contain a digital mark DM, which will be explained later. In a more general way, this digital message M can take any kind of form, such as a graphic representation, a set of data, an electromagnetic wave, etc.
[0079]
[0079] For example, the digital message M may contain authorization data AD(A) indicating that the controller A of the device DA is authorized by the controller C to perform an operation Op using the controller B. Such an operation Op may be, for example, downloading data, uploading data, accessing a database, transferring an instruction, collecting data, collecting goods, distributing data, delivering goods, etc., further examples being described later. Said controller C may be an authority represented by a device, an organization or a human being. Said authority has the ability to authorize a controller to perform some operation with respect to another controller. The controller C is preferably configured to deliver the digital message M in the form of a counterfeit-proof digital file. The digital message M is advantageously authenticated by the controller C.
[0080]
[0080] This digital message M is for example received by a device via a communications network CN, said device being controlled by a controller, said device being configured to verify the validity of the digital content of said digital message M.
[0081]
[0081] According to an embodiment, said communication network CN may comprise a short-range wireless communication network NFCN. Said short-range wireless communication network NFCN is configured to enable communication between at least two devices when the distance between them is less than 50 cm, preferably less than 25 cm, advantageously less than 10 cm. This communication network may comprise wired and / or wireless communication. This communication network may comprise an optical communication network.
[0082]
[0082] According to an embodiment of the present invention, the controller can be a computer, a robot, an Internet of Things (IoT) device, part of a device, a vehicle, a user, and / or a human. In fact, the device can be part of a larger device, such as, for example, a module inside a robot and / or inside a smartphone, or inside any kind of system that can be used by a human. The device is, for example, one of the devices such as a mobile phone, a tablet, a personal computer, a robot, an IoT device, etc.
[0083]
[0083] The aforementioned device comprises at least a processing unit together with a memory. The aforementioned processing unit comprises at least one processor configured to execute at least one sequence of instructions, which are preferably stored by the memory. The aforementioned memory is preferably a non-transient memory. The aforementioned memory advantageously comprises a protected enclave and is preferably configured to store, for example, at least one private key.
[0084]
[0084] According to an embodiment, the digital message M contains a verification key VK(A) originating from the controller C, said verification key VK(A) making it possible to derive, together with the authorization data AD(A), an aggregate digital signature ADS.
[0085]
[0085] According to an embodiment, said verification key VK(A) is a sequence of a number of digital signatures x. This number of digital signatures x can be generated from a number of well-known mechanisms, such as using a Merkle tree. Using this modern mechanism, said verification key VK(A) is a sequence of a number of digital signatures x of all other leaf nodes with the same parent node in the tree, other than the leaf node corresponding to the digital file signature x(A) of said authorization data AD(A), and of all non-leaf nodes with the same parent node in the tree, other than the previous same parent node considered in the preceding level, at each successive next level in the tree, from the leaf node level to the penultimate node level. Further details are explained later in the section "Anti-counterfeiting digital file".
[0086]
[0086] According to an embodiment, the aggregate digital signature ADS is advantageously calculated by applying a one-way accumulator to a plurality of digital signatures, said plurality of digital signatures including a digital signature x(A) of the authorization data AD(A). Said digital signature x(A) of the authorization data AD(A) is preferably calculated via a one-way function. As will be explained later, said aggregate digital signature ADS is designed to be stored in a memory of the device receiving said digital message M.
[0087]
[0087] According to an embodiment, the invention can include a step of verifying that the digital message is duly authenticated by controller C. This verification can preferably be performed by controller A and / or by controller B.
[0088]
[0088] According to an embodiment, the invention may include a challenge step between controller B and controller A. Indeed, controller B may use a challenge to validate controller A, i.e. to authenticate that controller A is in fact the controller mentioned in the digital message M. This challenge may be implemented in different ways. This challenge preferably includes receiving an authorized SA from controller A by controller B, which can then verify the authorized SA to validate that controller A is in fact the controller mentioned in the digital message M. More details regarding this challenge step are given later.
[0089]
[0089] According to an embodiment shown in Fig. 8, the invention comprises the reception by the controller B of an authorized SA from the controller A, preferably by the communication module CM(B) of the device DB and preferably from the communication module CM(A) of the device DA. This authorized SA is designed to be verified by the controller B, advantageously by the processing unit CPU(B) of the device DB. The authorized SA preferably comprises data signed by the controller A. According to an embodiment, the authorized SA is generated from a secret. Said secret is preferably generated by the controller B and / or by the controller C. Said secret is received by the controller A, from the controller C and / or from the controller B, preferably by the communication module CM(A) of the device DA and preferably from the communication module CM(B) of the device DB.
[0090]
[0090] Furthermore, according to an embodiment, the digital message M may contain a public key PuK corresponding to the private key PrK, said public key PuK being certified by the controller C as being owned by the controller A. Thus, according to an embodiment, a challenge step may be initiated between the controller B and the controller A by, for example, a data exchange using the device DB and the device DA and the public and private keys, for example the public key PuK(A) and the corresponding private key PrK(A).
[0091]
[0091] According to an embodiment, controller A comprises a private key PrK(A). Said private key PrK(A) is kept secret by controller A, for example as in a conventional Public Key Infrastructure PKI (Public Key Infrastructure). Said private key PrK(A) has an associated public key PuK(A) designed to be publicly known, said public key PuK(A) designed to be transmitted to another controller, for example to controller B via a communication module CM(B) of the device DB. Said public key PuK(A) is certified by controller C. In fact, controller C (the authority) certifies this public key PuK(A) as being owned by controller A.
[0092]
[0092] The device DA can use this private key PrK(A) to sign data and then send this signed data, for example, to the device DB, which can use the public key PuK(A) to verify said signed data.
[0093]
[0093] According to an embodiment, the device DB can send a message to the device DA, which message can include, for example, a secret, often called a challenge and preferably a one-time secret, preferably generated during operation, i.e. at a specific moment, and for example a random number. The device DA can then sign this message or for example at least said secret using its private key PrK(A) and send the signed message to the device DB in the form of a certified SA. Advantageously, said certified SA includes said signed secret. The device DB can verify said certified SA, i.e. said signed message, using the corresponding public key PuK(A) and the message, i.e. the secret, in particular, for example a random number. This challenge allows the device DB, and therefore the controller B, to verify that this device is indeed the device DA owned by the controller A that is communicating with the controller B, which verification is preferably performed at said specific moment.
[0094]
[0094] According to an embodiment, the certified SA may include a signature of a document and said document, said signature preferably being generated by the processing unit CPU(A) by signing said document using a private key PrK(A).
[0095]
[0095] According to an embodiment, the processing unit CPU(A) of the device DA may be configured to verify signed data received by the communication module CM(A) together with the corresponding public key PuK, for example from the device DB. Indeed, just as the controller A has a private key PrK(A) and an associated public key PuK(A) certified by an authority, for example the controller C, as being owned by the controller A, the controller B may also have a private key Prk(B) associated with a public key PuK(B). Said public key PuK(B) is preferably certified by an authority as being owned by the controller B, preferably by the same authority, such as the controller C.
[0096]
[0096] As in the case of device DA with respect to private key PrK(A), the memory of device DB stores private key Prk(B), preferably stored in a protected enclave of memory, and processing unit CPU(B) is configured to sign data using said private key Prk(B).
[0097]
[0097] According to a preferred embodiment, each communication module CM comprises a display module DD and an optical reader module OR. Said display module DD is adapted to display an optically readable representation of data, preferably an optically readable representation of a graphical data block GDB. Said graphical data block GDB may contain part or the whole of a digital message M. For example, the graphical data block GDB may contain a digital mark DM.
[0098]
[0098] According to embodiments, said digital mark DM can contain an encoded version EAD of said authorization data AD. According to another embodiment, said digital mark DM can contain an encoded version EVK of the verification key VK. According to these embodiments, in order to obtain, for example, the authorization data AD(A) of the controller A, the device DB has to decode the encoded authorization data EAD(A). Similarly, in order to obtain, for example, the verification key VK(A) of the controller A, the device DB has to decode the encoded verification key EVK(A). According to these embodiments, the digital message M can be attached to a digital document and / or can be optically received by the device DB as an optically readable representation of a graphical data block GDB, preferably by a communication module CM(B) of the device DB, advantageously by an optical reader module OR(B) of the communication module CM(B) of the device DB. According to these embodiments, the digital message M can be optically displayed by a display module DD(A) of the communication module CM(A) of the device DA, or the digital message M can be transmitted via the communication network CN or also printed, preferably in the form of the aforementioned graphical data block GDB.
[0099]
[0099] By way of example, said optically readable representation of a graphical data block GDB may comprise a digital representation of a graphical symbol from a particular finite set of graphical symbols, such as for example a QR code. Said digital representation of a graphical symbol is adapted to encode said digital mark MD and is preferably adapted to encode a machine-readable error correction data block. These features are explained in more detail below.
[0100]
[0100] According to a particular embodiment, the secret transmitted from the device DB to the device DA may be transmitted by a step of displaying a graphical representation of said secret by a display module DD(B) of the communication module CM(B) of the device DB and by a step of reading said graphical representation by an optical reader module OR(A) of the communication module (CMA) of the device DA. Then, after signing this secret and thus generating said certified SA, the device DA may display the graphical representation of the certified SA using the display module DD(A). The device DB then reads the graphical representation of the certified SA using the optical reader module OR(B).
[0101]
[0101] According to an embodiment, the invention relates to a system for validation of the digital content of a digital message M received by a device DB controlled by a controller B via a communications network CN.
[0102]
[0102] According to an embodiment, the system preferably comprises: A device DA controlled by a controller A. As indicated before, the device DA comprises a processing unit CPU(A) having a memory storing a digital message M, and a communication module CM(A) configured to send and receive data via a communication network CN. A device DB controlled by the controller B. As indicated before, the device DB comprises a processing unit CPU(B) having a memory storing the aforementioned aggregate digital signature ADS, and a communication module CM(B) configured to send and receive data via the communication network CN. The processing unit CPU(B) of the device DB is advantageously configured to verify the signed data using the corresponding public key. The memory of the processing unit CPU(B) preferably stores the previously described aggregate digital signature ADS.
[0103]
[0103] The system is configured in the following way. The communication module CM(B) of the device DB is adapted to receive a digital message M. The digital message M is preferably authenticated by the controller C, and the processing unit CPU(B) of the device DB is advantageously configured to verify that the digital message M is authenticated by the controller C. The processing unit CPU(B) of the device DB is configured to extract the authorization data AD(A) contained in the digital message M, said extraction preferably occurring only in case of positive verification that the digital message M has been authenticated by the controller C. The communication module CM(B) of the device DB is configured to receive an authorized SA from the communication module CM(A) of the device DA, the authorized SA preferably including data such as a secret signed by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed by the processing unit CPU(A) of the device DA using the private key PrK(A), said secret preferably having been received by the communication module CM(A) of the device DA from the device DB and / or from the controller C. The processing unit CPU(B) of the device DB is configured to verify the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting said public key PuK(A) from the digital message M. The processing unit CPU(B) of the device DB is Extracting a verification key VK(A) contained in a message M; - calculating a candidate digital signature cx(A) of the authorization data AD(A) by means of a one-way function programmed in a processing unit CPU(B); and computing a candidate aggregate digital signature cADS from the verification key VK(A) and a computed candidate digital signature cx(A) of the authorization data AD(A). A processing unit CPU(B) of the device DB is configured to check whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory, and only in case of positive verification of the authorized SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) of the device DB is configured to send, via the communication module CM(B), an indication to the controller B that the controller A is indeed authorized by the controller C to perform the operation Op.
[0104]
[0104] This system allows Controller B to verify the validity of the digital content of the digital message M with higher certainty than in prior art solutions. Moreover, this system allows the device DB to control the authentication information linked to this digital content in order to check if this digital content is valid. This system allows Controller A, for example a robot, to identify itself using only the certification SA and the authentication information present in the digital message M and authenticated by the counterfeit-proof digital file issued by Controller C. This system allows Controller B, for example another robot, to fully trust the validity of the presented authentication information.
[0105]
[0105] It should be noted that, as will be explained later, this system avoids the use of biometric data, for example when controller A is a human. The authentication information and the certified SA of controller A are sufficient to give full trust to the recipient, here controller B, which can be for example a robot, a computer or another human. This system advantageously avoids the disclosure of any biometric data, biometrics or personal information.
[0106]
[0106] According to an embodiment, the memory of the processing unit CPU(A) of the device DA is configured to store the aforementioned private key PrK(A), preferably in a protected enclave of the memory, and the processing unit CPU(A) is configured to sign data using the private key PrK(A).
[0107]
[0107] According to an embodiment, the processing unit CPU(B) of the device DB is configured to verify the signed data using the corresponding public key PuK, which is preferably received by the communication module CM(B).
[0108]
[0108] According to an embodiment, the digital message M further comprises said public key PuK(A) corresponding to said private key PrK(A), said public key PuK(A) being certified by the controller C.
[0109]
[0109] According to an embodiment, the certification SA contains certification data signed using the aforementioned private key PrK(A).
[0110]
[0110] According to an embodiment, the processing unit CPU(B) of the device DB is configured to extract the public key PuK(A) from the digital message M and to verify said certified SA using said public key PuK(A).
[0111]
[0111] According to the embodiment illustrated by Fig. 1, the system is configured to execute a method of validation of the digital content of a digital message M received by a device DB controlled by a controller B through a communications network CN, the method comprising the steps of: A step in which the communication module CM(B) of the device DB receives (200, 100b) a digital message M, said digital message M can be received by the communication module CM(B) of the device DB from the controller C (100b) or from the communication module CM(A) of the device DA (200), the controller C preferably transmitting (100a) the digital message M to the communication module CM(A) of the device DA, The digital message M is preferably authenticated (10) by the controller C, and advantageously the processing unit CPU (B) of the device DB verifies that the digital message M has been authenticated (10) by the controller C; and a step in which the processing unit CPU (B) of the device DB extracts (201) the authorization data AD (A) contained in the digital message M, preferably only in case of a positive verification that the digital message M has been authenticated (10) by the controller C, this digital message M, as indicated before, can originate from a printed and / or handwritten message, which becomes a digital message after a transformation, for example using a scanner and / or a camera, The communication module CM(B) of the device DB receives (400) a certificate SA from the communication module CM(A) of the device DA, the certificate SA being preferably signed using the private key PrK(A), step a processing unit CPU(B) of the device DB verifies (400b) the certified SA, preferably using a public key PuK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M, The processing unit CPU(B) of the device DB is Extracting (204) a verification key VK(A) contained in the digital message M; Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), calculating (205) a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A); and Preferably, the method includes a step in which the processing unit CPU(B) of the device DB checks (207) whether the candidate aggregate digital signature cADS matches an aggregate digital signature ADS stored in its memory, said aggregate digital signature ADS having been, for example, uploaded (101) by the controller C to a server and downloaded (206) by the device DB from said server, and only in case of a positive verification of the signed certified SA data and a positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) of the device DB sends (500) via the communication module CM(B) to the controller B an indication that the controller A is indeed authorized by the controller C to execute (500a) the operation Op.
[0112]
[0112] This method allows Controller B to verify the validity of the digital content of the digital message M with higher certainty than prior art solutions. Moreover, it allows the device DB to control the authentication information linked to this digital content in order to check if this digital content is valid. This method allows Controller A, for example a robot, to identify itself using only the certification SA and the authentication information present in the digital message M and authenticated by the counterfeit-proof digital file issued by Controller C. This method allows Controller B, for example another robot, to fully trust the validity of the presented authentication information.
[0113]
[0113] It should be noted that this method avoids the use of biometric data, for example in the case where controller A is a human, as will be explained later. The authentication information and certified SA of controller A are sufficient to give full trust to the recipient, here controller B, which can be for example a robot, a computer or another human. This method advantageously avoids the disclosure of any biometric data, biometrics or personal information.
[0114]
[0114] According to an embodiment, the device DB can receive the digital message M via the communication module CM(B) in various ways: For example, the digital message M can be received, for example, from the device A via the communication module CM(A) and / or from the controller C and / or from the server.
[0115]
[0115] According to an embodiment, the device DB can receive, via the communication module CM(B), a digital message M, either directly in digital format or first in the form of a paper that is converted into digital format. For example, the communication module CM(B) optically reads, i.e. scans, a piece of paper containing printed and / or handwritten content using the optical reader module OR(B) and converts said printed and / or handwritten content into a digital message M.
[0116]
[0116] According to an embodiment, the communications network CN may include one or more types of communications networks, such as an optical communications network, a wired communications network, a wireless communications network, a radio frequency communications network, and a combination of multiple types of communications networks.
[0117]
[0117] According to an embodiment, as in the case of receiving a digital message M, the public key PuK(A) corresponding to the private key PrK(A) owned by the controller A can be received by the controller B in various ways. For example, the public key PuK(A) can be received, for example, from the controller C and / or from a server and / or advantageously from the digital message M. Indeed, in some embodiments, the controller B can obtain the public key PuK(A) directly from the digital message M using the processing unit CPU(B) and extract the public key PuK(A) from the digital message M. According to another embodiment, the device DB can receive the public key PuK(A) from the controller C via the communication module CM(B).
[0118]
[0118] One way to explain the invention according to an embodiment is as follows: A mission command in the form of a digital message M, to be executed by controller A for the benefit of controller B, is issued and authenticated by controller C. One of the main goals of the invention is to give said controller B the means to verify that said mission command is indeed authentic and issued by said controller C, and that said controller A has been duly commanded by said controller C to execute the particular mission command.
[0119]
[0119] According to an embodiment, controller B receives a digital message M corresponding to or containing said mission command from controller A and / or from controller C or via any other source or route. Controller B then checks that the digital message M, i.e. the mission command, is in fact valid and authentic, has not been tampered with or forged, and that the mission command has been duly issued by controller C.
[0120]
[0120] According to an embodiment, controller B submits a challenge to controller A, which is preferably a one-time challenge. Controller A then advantageously signs the challenge using the private key PrK(A) and sends the signed challenge back to controller B. Controller B then preferably checks that the signature is indeed valid and that it duly corresponds to the public key PuK(A), which is advantageously included in a digital message M, for example in a mission command.
[0121]
[0121] Then, according to a preferred embodiment, if both verifications are positive, controller A can legitimately execute the mission command for the benefit of controller B.
[0122]
[0122] According to an embodiment, the controller A may be selected from a robot, a computer, an Internet of Things device, a smartphone, or a user, etc.
[0123]
[0123] As is clear, the present invention can find applications in many technical areas. To illustrate some types of technical applications, several examples are now described and shown by means of Figures 2 to 7.
[0124] Robots in a secure warehouse
[0124] According to a first example of an application of the present invention illustrated by FIG. 2, the present invention can be implemented to safely enable a robot to pick up high value goods, such as gold bars or jewels, inside a secure warehouse.
[0125]
[0125] According to this example, the controller A is a robot A designed to move inside a secure warehouse to collect and / or deliver goods. The robot A comprises a device DA. This robot A is preferably equipped with a motorized module configured to enable the movement of the robot A at least inside the secure warehouse. The controller A can therefore be equipped with wheels or tracks or any device that allows the controller A to move. The controller A can also be a drone, for example an aerial drone. This robot A is configured to pick up goods from at least one storeroom on the basis of a mission command issued by a logistics center C, which in this use case is a controller C. The controller A, i.e. the robot A, comprises a private key PrK(A), preferably issued by the controller A, said private key PrK(A) being associated with a public key PuK(A), said public key PuK(A) being certified by the controller C, i.e. the logistics center C, as being owned by the controller A.
[0126]
[0126] According to this example, the controller B is a vault B, preferably a smart vault, i.e. a vault equipped with a device DB. The controller B can also be a motorized door of the vault. Said vault B is configured to deliver goods or to allow a robot to access goods and retrieve goods from inside the vault B, when an appropriate mission command is issued to said robot by the logistics center, which in this example plays the role of controller C.
[0127]
[0127] According to this example, controller C is a logistics center C. Said logistics center C is configured to issue (100) a mission command using a digital message M that is sent (100a) to controller A. According to an embodiment, the digital message M is also sent (100b) by controller C to controller B. For example, the digital message M may contain a mission command in the form of a set of data indicating, for example, what controller A needs to do, when controller A needs to do it, and, for example, where controller A needs to do it. In this example, the mission command may contain the following data: Robot A has a public key PuK(A). The verification key VK(A). Action Op: Robot A needs to fetch a particular item, say gold bar number 429, placed inside vault B. Time slot: This action must be performed between 10:25 and 10:30 AM, for example.
[0128]
[0128] According to an embodiment, when the robot A, i.e. the controller A, receives the digital message M, it verifies (10a) using its processing unit CPU(A) that the digital message M has been authenticated (10) by the controller C, and only in case of a positive verification that the digital message M has been authenticated (10) by the controller C, the processing unit CPU(A) of the device DA starts to extract the authorization data AD(A) contained in the digital message M. These authorization data AD(A) preferably contain the data of the mission instructions for the robot A.
[0129]
[0129] According to a preferred embodiment, when the storage room B, i.e. the controller B, receives (200) the digital message M, it verifies (10b) using its processing unit CPU(B) that the digital message M has been authenticated (10) by the controller C, and only in case of a positive verification that the digital message M has been authenticated (10) by the controller C, the processing unit CPU(B) of the device DB initiates the extraction 201 of the authorization data AD(A) contained in the digital message M. These authorization data AD(A) preferably comprise the data of the mission command.
[0130]
[0130] Next, controller B, i.e., storage room B, extracts various data from the digital message M, such as the public key PuK(A) corresponding to the private key PrK(A) of controller A, i.e., robot A, the verification key (A), data related to the operation Op, and, for example, the time slot mentioned in the mission command (202, 204).
[0131]
[0131] According to an embodiment, when controller A, i.e. robot A, is in front of controller B, i.e. storage room B, controller B sends a challenge to controller A (300). For example, this challenge can be a random number generated by the random number generator module GRNM(B) of device DB. According to an embodiment, when controller A receives said challenge via device DA (advantageously via the communication module CM(A) of device DA), controller A signs this challenge using the private key PrK(A), more precisely the processing unit CPU(A) of device DA signs the challenge using the private key PrK(A) generating said certified SA (300a). Controller A then sends the certified SA back to controller B (400).
[0132]
[0132] Next, controller B, i.e. in this example storage room B, checks (400b) the validity of the certified SA using the public key PuK(A), which has been extracted (202) from the digital message M by the processing unit CPU(B) and which is preferably located within the mission command, i.e. the authorization data AD(A).
[0133]
[0133] Afterwards, the processing unit CPU(B) of the device DB calculates (203) a candidate digital signature cx(A) of the authorization data AD(A) by means of a one-way function programmed in the processing unit CPU(B) and calculates (205) a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A), and the processing unit CPU(B) of the device DB checks (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206). According to an embodiment, said aggregate digital signature ADS has been received by the controller B, from the controller C and / or from the server. Afterwards, said aggregate digital signature ADS is stored in the memory of the processing unit CPU(B) of the controller B, i.e. in this example the storage room B (206).
[0134]
[0134] According to an embodiment, the storage room B extracts other data from the digital message M, such as the time slot in which the robot A must operate, in this example 10:25-10:30.
[0135]
[0135] Next, if the time is legitimately between 10:25 and 10:30, the verification 400b of the certified SA is positive and the candidate aggregate digital signature cADS matches the aggregate digital signature ADS (207), then the vault B, i.e., the controller B, receives an indication (500) from the processing unit CPU(B) that the robot A is indeed authorized by the logistics center C to perform (500a) the operation Op mentioned in the mission command contained in the digital message M. Thus, the vault B delivers the gold bar number 429 to the robot A or has the robot A pick up the gold bar number 429.
[0136]
[0136] According to this example of a use case of the present invention, the system preferably comprises: A robot A comprising and controlling a device DA, said robot A being configured to move at least inside a secure warehouse, said warehouse including a logistics center. A storeroom B equipped with and controlling a device DB, said storeroom B being configured to deliver goods to authorized robots and / or to have the robots pick up goods contained therein.
[0137]
[0137] The system is configured in the following way. The communication module CM(B) of the device DB is configured to receive (100b, 200) a digital message M containing a mission command, said mission command comprising the public key PuK(A) possessed by the robot A, authorization data AD(A) indicating that the robot A is authorized by the logistics center C to perform an operation Op using the storage room B, the verification key VK(A), the time slot in which this operation Op has to be performed, etc. The processing unit CPU (B) of the device DB is preferably arranged to verify (10b) that the digital message M is authenticated by the logistics centre C. The processing unit CPU(B) of the device DB is configured to extract (201, 202, 204) the data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A) and the time slot in which this operation Op has to be executed, said extraction preferably being performed only in case of a positive verification that the digital message M has been authenticated by the logistics center C. The communication module CM(B) of the device DB is configured to receive (400) an authorized SA from the communication module CM(A) of the device DA, the authorized SA preferably including data such as a secret signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) of the device DA using the private key PrK(A), said secret preferably being transmitted (300) from the communication module CM(B) of the device DB to the communication module CM(A) of the device DA. The processing unit CPU(B) of the device DB is configured to verify (400b) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M. The processing unit CPU(B) of the device DB is Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), and computing (205) a candidate aggregate digital signature cADS from the verification key VK(A) and a computed candidate digital signature cx(A) of the authorization data AD(A). The processing unit CPU (B) of the device DB is configured to check (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206), and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU (B) of the device DB is configured to send (500) an indication to the storage room that the robot is actually authorized by the logistics center to perform (500a) the operation Op.
[0138]
[0138] This system allows the device DB to verify the validity of the digital content of the digital message M with a higher degree of certainty than in the prior art solutions. Moreover, this system allows the device DB to control the mission command, i.e. the authentication information, linked to this digital content in order to check if this digital content is valid. This system allows the robot A to identify itself using only the certification SA and the digital message M, which is preferably authenticated by a forgery-proof digital file issued by the controller C. This system allows the vault B to fully trust the validity of the presented mission command.
[0139]
[0139] In accordance with this example of a use case of the present invention, the present invention relates to the following method according to an embodiment: A robot A is equipped with and controls a device DA, said robot A being configured to move at least inside a secure warehouse, said warehouse including a logistics center. A storage room B is equipped with and controls a device DB, said storage room B being configured to deliver goods to an authorized robot and / or to cause the robot to pick up goods contained in the storage room.
[0140]
[0140] This method comprises: a step of receiving (100b, 200) a digital message M containing a mission command, said mission command comprising the public key PuK(A) possessed by the robot, authorization data AD(A) indicating that the robot is authorized by the logistics center to use the storage room to perform an operation Op, a verification key VK(A), the time slot in which this operation Op has to be performed, etc., Preferably, a processing unit CPU (B) of the device DB verifies (10b) that the digital message M is authenticated by the warehouse logistics center; and a step in which the processing unit CPU(B) of the device DB extracts (201, 202, 204) the data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A) and the time slot in which this operation Op must be executed, preferably only in case of a positive verification that the digital message M has been authenticated by the logistics center; A communication module CM(B) of the device DB receives (400) an authorized SA from the communication module CM(A) of the device DA, the authorized SA preferably including data such as a secret signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A), said secret preferably being transmitted (300) from the communication module CM(B) of the device DB to the communication module CM(A) of the device DA, step a processing unit CPU(B) of the device DB verifies (400b) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M, The processing unit CPU(B) of the device DB is Extracting (204) a verification key VK(A) contained in the digital message M; Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), calculating (205) a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A); and The method includes a step in which a processing unit CPU (B) of the device DB checks (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206), and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU (B) of the device DB sends (500) an indication to the storage room that the robot is actually authorized by the logistics center to perform (500a) the operation Op.
[0141]
[0141] This system allows the device DB to verify the validity of the digital content of the digital message M with a higher degree of certainty than prior art solutions. Moreover, this system allows the device DB to control the authentication information linked to this digital content in order to check if this digital content is valid. This system allows the robot A to identify itself only using the digital message M that is authenticated by the certification SA and the forgery-proof digital file issued by the controller C. This system allows the vault B to fully trust the validity of the presented mission command.
[0142]
[0142] According to an embodiment, the invention allows the operation Op to be executed by the controller A without needing to contact a central database or a server containing the mission instructions. Indeed, the vault B and the robot A can be in an offline environment, as long as they are able to communicate with each other during the implementation of the method according to an embodiment of the invention, and preferably, as long as the controller B contains the aggregate digital signature ADS previously downloaded, for example, from the controller C or from a server. The transmission of the digital message M to the robot A and to the vault B can advantageously be realized over an unsecured channel.
[0143]
[0143] According to an embodiment, the invention relates to the implementation of the method according to the invention in a secure warehouse equipped with the previous system according to the invention.
[0144]
[0144] According to an embodiment, the present invention can be used to transfer a token from one controller to another, ie from one device to another.
[0145]
[0145] According to an embodiment, Controller B may distribute a certain amount of tokens to Controller A in accordance with Controller B's mission orders and / or Controller A's mission orders, i.e., gold bar number 429 may be replaced with at least one digital asset.
[0146]
[0146] In this embodiment, the device DA can be a smartphone, a smart card, a server, or a computer, the device DB can be a smartphone, a smart card, a server, or a computer, and the controller C can be a financial institution or a bank.
[0147] Internet of Things (IoT) Secure Communications
[0147] According to a second example of application of the present invention illustrated by Fig. 3, the present invention may be implemented in an Internet of Things environment, generally named IoT network, to secure communication between multiple devices, such as Internet of Things devices, named IoT devices. In this example, according to an embodiment of the present invention, a system comprises a controller A, a controller B, and a controller C as previously described. The controller C is, for example, a command center C. The controllers A and B are, for example, computers, servers, robots, and / or smartphones. Each one of the controllers A and B can be a different type of IoT from the other. For example, the controller A can be a smartphone A and the controller B can be a computer B.
[0148]
[0148] Controllers A, B and C preferably communicate together using a communication network CN to form an IoT network.
[0149]
[0149] Advantageously, the controller A is configured to transmit data to at least one other controller, such as, for example, the controller B. For example, a device DA controlled by the controller A is configured to transmit data via a communication module CM(A) to a device DB controlled by the controller B. In this example, the device DB is configured to receive data from the communication module CM(A) of the device DA via the communication module CM(B).
[0150]
[0150] According to a preferred embodiment, the controller A includes a private key PrK(A) issued by the controller A and preferably associated to a public key PuK(A), said public key PuK(A) being certified by the controller C, i.e. for example the command centre C. Said private key PrK(A) is preferably stored in a memory of a processing unit CPU(A) of the device DA controlled by the controller A, preferably in a protected enclave of the memory.
[0151]
[0151] According to an embodiment, controller B is configured to collect data transmitted from said other controller as long as it receives and verifies a mission command issued by controller C indicating that said other controller is authorized to transmit data to controller B, for example during a correct time slot. This mission command may contain a number of other data taken into account by controller B to enable reception of data transmitted by said other controller, as will be explained later.
[0152]
[0152] According to an embodiment, the controller B is configured to transmit data to at least one other controller, such as for example the controller A. For example, a device DB controlled by the controller B is configured to transmit data via a communication module CM(B) to a device DA controlled by the controller A. In this example, the device DA is configured to receive data from the communication module CM(B) of the device DB via the communication module CM(A).
[0153]
[0153] According to an embodiment, the controller B comprises a private key PrK(B) issued by the controller B and preferably associated to a public key PuK(B), said public key PuK(B) being certified by the controller C, i.e. for example the command centre C. Said private key PrK(B) is preferably stored in a memory of a processing unit CPU(B) of the device DB controlled by the controller B, preferably in a protected enclave of the memory.
[0154]
[0154] According to an embodiment, controller A is configured to collect data transmitted from said other controller as long as controller A receives and verifies a mission command issued by controller C indicating that said other controller is authorized to transmit data to controller A, for example during a precise time slot. This mission command may contain a number of other data taken into account by controller A to enable reception of data transmitted by said other controller, as will be explained later.
[0155] According to an embodiment, each of the controllers A and B has the same technical functionality. In this example, each of these controllers can have a mission command issued by a controller C that allows it to perform an operation Op in relation to the other controllers A and B.
[0156]
[0156] According to this example, controller C is a command center C. Said command center C is configured to issue mission orders using digital messages M sent to controllers A and / or B. For example, digital messages M may contain mission orders, for example in the form of a number of data indicating what a particular controller needs to perform and, for example, when this particular controller needs to perform it. In this example, controller C issues two mission orders by means of two digital messages M: a mission order named M(A) for controller A and another mission order named M(B) for controller B.
[0157]
[0157] According to an embodiment, controller A is designed to execute an operation Op(A) associated with controller B only if controller A has a mission command issued by controller C in the form of a digital message M(A) and controller B has verified said digital message M(A) and a number of parameters relating to said controller A before accepting controller A to execute operation Op(A).
[0158]
[0158] According to an embodiment, controller B is designed to execute an operation Op(B) associated with controller A only if controller B has a mission command issued by controller C in the form of a digital message M(B) and controller A verifies said digital message M(B) and a number of parameters relating to said controller B before accepting controller B to execute operation Op(B).
[0159]
[0159] For example, the digital message M(A) may contain a mission command containing the following data: Controller A has a public key PuK(A). The verification key VK(A). Operation Op(A): Controller A is authorized to transmit a set of data SeD(A) to Controller B and is authorized to receive a set of data SeD(B) from Controller B. Time slot: This action may be performed only on June 10, 2021, for example.
[0160]
[0160] For example, the digital message M(B) may include a mission command containing the following data: Controller B has a public key PuK(B). The verification key VK(B). Operation Op(B): Controller B is authorized to transmit a set of data SeD(B) to Controller A and is authorized to receive a set of data SeD(A) from Controller A. Time slot: This action may be performed only on June 10, 2021, for example.
[0161]
[0161] According to a preferred embodiment, when a controller A, such as in this example a smartphone, receives a digital message M(B), it verifies using its processing unit CPU(A) that the digital message M(B) has been authenticated by the controller C, and only in case of a positive verification that the digital message M(B) has been authenticated by the controller C, the processing unit CPU(A) of the device DA controlled by the controller A starts to extract the authorization data AD(B) contained in the digital message M(B). These authorization data AD(B) preferably contain data of a mission command for the controller B.
[0162]
[0162] Next, controller A, i.e., the smartphone, extracts various data from the digital message M(B), such as the public key PuK(B) corresponding to the private key PrK(B) of controller B, i.e., a computer in this example, the verification key VK(B), data related to the operation Op(B), and, for example, the time slot mentioned in the mission command.
[0163]
[0163] According to a preferred embodiment, when a controller B, such as a computer in this example, receives a digital message M(A), it verifies, using its processing unit CPU(B), that the digital message M(A) has been authenticated by the controller C, and only in case of a positive verification that the digital message M(A) has been authenticated by the controller C, the processing unit CPU(B) of the device DB controlled by the controller B starts to extract the authorization data AD(A) contained in the digital message M(A). These authorization data AD(A) preferably contain the data of the mission instructions for the controller A.
[0164]
[0164] Next, controller B, i.e., a computer, extracts various data from the digital message M(A), such as the public key PuK(A) corresponding to the private key PrK(A) of controller A, i.e., in this example, the smartphone, the verification key VK(A), data related to the operation Op(A), and, for example, the time slot mentioned in the mission command.
[0165]
[0165] According to an embodiment, controller A contains a digital message M(A), preferably received from controller C, stored in the memory of a processing unit CPU(A) of device DA. In this example, controller A is a smartphone, which needs to upload a set of data to a computer, namely controller B. In this example, device DA is part of the smartphone.
[0166]
[0166] According to an embodiment, controller B contains a digital message M(B), preferably received from controller C, stored in the memory of a processing unit CPU(A) of device DA. In this example, controller B is a computer that needs to upload a set of data to a smartphone, i.e. controller A. In this example, device DB is part of the computer.
[0167]
[0167] According to an embodiment, to perform operations Op(A) and Op(B), the following is performed: Controller B receives a digital message M(A), preferably from controller C (100b). Controller A receives a digital message M(B), preferably from controller C (100a). Preferably, controller B verifies (10b) using a processing unit CPU(B) that the digital message M(A) has been authenticated by controller C. Preferably, controller A verifies (10a) using a processing unit CPU(A) that the digital message M(B) has been authenticated by controller C. Controller B, i.e. a computer, extracts (201, 202, 204) from the digital message M(A) various data such as the public key PuK(A) corresponding to the private key PrK(A) of controller A, i.e. the smartphone, the verification key (A), data related to the operation Op(A) and for example the time slot mentioned in the mission command of controller A, this extraction preferably only taking place in case of a positive verification that the digital message M(A) has been authenticated by controller C. These authorization data AD(A) preferably include the data of the mission command of controller A. Controller A, i.e. a smartphone, extracts from the digital message M(B) various data such as the public key PuK(B) corresponding to the private key PrK(B) of controller B, i.e. a computer, the verification key (B), data related to the operation Op(B) and for example the time slot mentioned in the mission command of controller B, this extraction preferably only taking place in case of a positive verification that the digital message M(B) has been authenticated by controller C. These authorization data AD(B) preferably contain the data of the mission command of controller B. Preferably, the controller B sends a challenge Ch(B) to the controller A (300a), and the communication module CM(B) of the device DB sends the challenge Ch(B) to the communication module CM(A) of the device DA via the communication network CN (300a), the challenge Ch(B) being configured to enable the device DB to verify that the controller B is indeed communicating with the controller A mentioned in the digital message M(A), said challenge being preferably a one-time secret such as a random number, advantageously generated by a random number generator module GRNM(B) of the device DB. Preferably, the controller A sends a challenge Ch(A) to the controller B, and the communication module CM(A) of the device DA sends the challenge Ch(A) to the communication module CM(B) of the device DB via the communication network CN, the challenge Ch(A) being configured to enable the device DA to verify that the controller A is indeed communicating with the controller B mentioned in the digital message M(B), said challenge being preferably a one-time secret such as a random number, advantageously generated by a random number generator module GRNM(A) of the device DA. A processing unit CPU(A) of the device DA signs (300a) the challenge Ch(B) using a private key PrK(A) to generate an authentication SA(A). A processing unit CPU(B) of the device DB signs (300a) the challenge Ch(A) using a private key PrK(B) to generate a certificate SA(B). Preferably, the controller A sends (400) the authorization SA(A) to the controller B, and the communication module CM(A) of the device DA sends (400) the authorization SA(A) to the communication module CM(B) of the device DB via the communication network CN. Preferably, the controller B sends the authorization SA(B) to the controller A, and the communication module CM(B) of the device DB sends the authorization SA(B) to the communication module CM(A) of the device DA via the communication network CN. Controller B checks (400b) the validity of the certification SA(A) using the public key PuK(A), which has been extracted (202) from the digital message M(A) by the processing unit CPU(B) and is preferably within the mission command of controller A. Controller A checks the validity of certification SA(B) using the public key PuK(B), which has been extracted from the digital message M(B) by the processing unit CPU(A) and is preferably within the mission command of controller B. The processing unit CPU(B) of the device DB calculates (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B) and calculates (205) a candidate aggregate digital signature cADS(A) from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A). The processing unit CPU(A) of the device DA calculates a candidate digital signature cx(B) of the authorization data AD(B) by a one-way function programmed in the processing unit CPU(A), and calculates a candidate aggregate digital signature cADS(B) from the verification key VK(B) and the calculated candidate digital signature cx(B) of the authorization data AD(B). The processing unit CPU(B) of the device DB checks (207) whether the candidate aggregate digital signature cADS(A) matches an aggregate digital signature ADS(A) preferably stored in its memory, and according to an embodiment, said aggregate digital signature ADS(A) has been received by controller B from controller C and / or from the server, after which said aggregate digital signature ADS(A) has been stored in the memory of controller B, i.e. the processing unit CPU(B) of a computer in this example (206). The processing unit CPU(A) of the device DA checks whether the candidate aggregate digital signature cADS(B) matches an aggregate digital signature ADS(B) which is preferably stored in its memory, and according to an embodiment, said aggregate digital signature ADS(B) has been received by the controller A from the controller C and / or from the server, and which has then been stored in the memory of the processing unit CPU(A) of the controller A, i.e. in this example a smartphone. If the date is legitimately the date mentioned in the digital message M(A), for example June 10, 2021, and if the verification of the certified SA(A) is positive and the candidate aggregate digital signature cADS(A) matches the aggregate digital signature ADS(A) (207), then the computer, i.e. controller B, receives an indication from the processing unit CPU(B) that controller A has indeed been authorized by controller C to perform the operation Op(A) mentioned in the mission command contained in the digital message M(A) (500). If the date is legitimately the date mentioned in the digital message M(B), for example June 10, 2021, and if the verification of the certified SA(B) is positive and the candidate aggregate digital signature cADS(B) matches the aggregate digital signature ADS(B), the smartphone, i.e. controller A, receives an indication from the processing unit CPU(A) that controller B has indeed been authorized by controller C to perform the operation Op(B) mentioned in the mission command contained in the digital message M(B). Preferably, the controller B receives the set of data SeD(A) transmitted by the controller A, and the processing unit CPU(B) of the device DB transmits an instruction to the communication module CM(B) of the device DB indicating that the communication module CM(B) is able to receive the set of data SeD(A) transmitted by the communication module CM(A) of the device DA. Preferably, the controller A receives the set of data SeD(B) transmitted (510) by the controller B, and the processing unit CPU(A) of the device DA transmits to the communication module CM(A) of the device DA an instruction indicating that the communication module CM(A) is able to receive the set of data SeD(B) transmitted by the communication module CM(B) of the device DB. Therefore, controller A and controller B can exchange data with each other in complete confidence.
[0168]
[0168] According to an embodiment, the present invention can be used to transfer a token from one controller to another, ie from one device to another.
[0169]
[0169] According to an embodiment, the set of data SeD(A) and / or SeD(B) may include a token, and thus the present invention may be used to transfer the token from one controller to another.
[0170]
[0170] According to an embodiment, controller B may distribute a certain amount of tokens to controller A according to the mission instructions of controller B and / or the mission instructions of controller A.
[0171]
[0171] In another embodiment, controller A may be configured to deliver a certain amount of tokens to controller B according to controller B's mission instructions and / or controller A's mission instructions.
[0172]
[0172] In these embodiments, the device DA can be a smartphone, a smart card, a server, or a computer, the device DB can be a smartphone, a smart card, a server, or a computer, and the controller C can be a financial institution or a bank.
[0173]
[0173] According to this example of a use case of the present invention, the system preferably comprises: A controller A comprising and controlling a device DA, said device DA being configured to transmit and receive data, said device DA being for example a smartphone or being part of the smartphone if the controller A is a smartphone. A controller B that comprises and controls a device DB. Said device DB is configured to transmit and receive data, said device DB can be, for example, a computer or part of a computer if controller B is a computer.
[0174]
[0174] The system is configured in the following way. The communication module CM(B) of the device DB is configured to receive (100b) a digital message M(A) containing a mission command related to a controller A, said mission command comprising a public key PuK(A) possessed by the controller A, authorization data AD(A) indicating that the controller A is authorized by the controller C to perform an operation Op(A) using the controller B, a verification key VK(A), a time slot during which this operation Op(A) may be performed, etc. The communication module CM(A) of the device DA is configured to receive (100a) a digital message M(B) containing a mission command related to a controller B, said mission command comprising a public key PuK(B) possessed by controller B, authorization data AD(B) indicating that controller B is authorized by controller C to perform an operation Op(B) using controller A, a verification key VK(B), a time slot during which this operation Op(B) may be performed, etc. The processing unit CPU (B) of the device DB is preferably arranged to verify (10b) that the digital message M(A) is authenticated by the controller C. Preferably, the processing unit CPU(A) of the device DA is arranged to verify (10a) that the digital message M(B) is authenticated by the controller C. The processing unit CPU(B) of the device DB is configured to extract (201, 202, 204) the data contained in the digital message M(A), such as the public key PuK(A), the authorization data AD(A), the operation Op(A), the verification key VK(A), the time slot in which this operation Op(A) may be executed, said extraction preferably occurring only in case of a positive verification that the digital message M(A) is authenticated by the controller C. The processing unit CPU(A) of the device DA is configured to extract data contained in the digital message M(B), such as the public key PuK(B), the authorization data AD(B), the operation Op(B), the verification key VK(B), the time slot in which this operation Op(B) may be executed, said extraction preferably occurring only in case of positive verification that the digital message M(B) has been authenticated by the controller C. The communication module CM(B) of the device DB is configured to receive (400) an authorized SA(A) from the communication module CM(A) of the device DA, the authorized SA(A) preferably including data such as a secret signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) of the device DA using the private key PrK(A), said secret preferably being transmitted (300) from the communication module CM(B) of the device DB to the communication module CM(A) of the device DA. The communication module CM(A) of the device DA is configured to receive an authorization SA(B) from the communication module CM(B) of the device DB, the authorization SA(B) being preferably signed by the processing unit CPU(B) of the device DB using the private key PrK(B) and / or containing data such as another secret signed by the processing unit CPU(B) of the device DB using the private key PrK(B), said another secret being preferably transmitted from the communication module CM(A) of the device DA to the communication module CM(B) of the device DB. The processing unit CPU(B) of the device DB is configured to verify (400b) the certified SA(A), preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M(A). The processing unit CPU(A) of the device DA is configured to verify the certificate SA(B), preferably using a public key PuK(B) corresponding to said private key PrK(B), advantageously after extracting said public key PuK(B) from the digital message M(B). The processing unit CPU(B) of the device DB is Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), and computing (205) a candidate aggregate digital signature cADS(A) from the verification key VK(A) and the computed candidate digital signature cx(A) of the authorization data AD(A). The processing unit CPU(A) of device DA - calculating a candidate digital signature cx(B) of the authorization data AD(B) by means of a one-way function programmed in a processing unit CPU(A); and computing a candidate aggregate digital signature cADS(B) from the verification key VK(B) and the computed candidate digital signature cx(B) of the authorization data AD(B). The processing unit CPU(B) of the device DB is configured to check (207) whether the candidate aggregate digital signature cADS(A) matches the aggregate digital signature ADS(A) stored in the memory (206), and only in case of positive verification of the authorized SA(A) and positive match of the candidate aggregate digital signature cADS(A) with the aggregate digital signature ADS(A), the processing unit CPU(B) of the device DB is configured to send (500) an indication to the controller B that the controller A is indeed authorized by the controller C to execute (500a) the operation Op(A). The processing unit CPU(A) of the device DA is configured to check whether the candidate aggregate digital signature cADS(B) matches the aggregate digital signature ADS(B) stored in the memory, and only in case of positive verification of the authorized SA(B) and positive match of the candidate aggregate digital signature cADS(B) with the aggregate digital signature ADS(B), the processing unit CPU(A) of the device DA is configured to send an indication to the controller A that the controller B is actually authorized by the controller C to execute (510) the operation Op(B).
[0175]
[0175] This system allows controller B to verify the validity of the digital content of digital message M(A) and controller A to verify the validity of the digital content of digital message M(B) with higher certainty than the prior art solutions. Moreover, this system allows controller B to control the authentication information linked to the digital content of digital message M(A) to check if this digital content is valid, and controller A to control the authentication information linked to the digital content of digital message M(B) to check if this digital content is valid. This system allows controller A to identify itself only using the digital message M(A), which is preferably authenticated by the certified SA(A) and the forgery-proof digital file issued by controller C, and controller B to identify itself only using the digital message M(B), which is preferably authenticated by the certified SA(B) and the forgery-proof digital file issued by controller C. This system allows controller B to fully trust the validity of the presented mission command, and controller A to fully trust the validity of the presented mission command.
[0176]
[0176] In accordance with this example of a use case of the present invention, the present invention relates to the following method according to an embodiment: A controller A comprises and controls a device DA, said device DA being adapted to transmit and receive data. A controller B comprises and controls a device DB, said device DB being configured to transmit and receive data.
[0177]
[0177] This method is receiving (100b) a digital message M(A) containing a mission command related to a controller A, said mission command comprising a public key PuK(A) possessed by controller A, authorization data AD(A) indicating that controller A is authorized by controller C to perform an operation Op(A) using controller B, a verification key VK(A), a time slot in which this operation Op(A) may be performed, etc., receiving (100a) a digital message M(B) containing a mission command related to a controller B, said mission command comprising a public key PuK(B) possessed by controller B, authorization data AD(B) indicating that controller B is authorized by controller C to perform an operation Op(B) using controller A, a verification key VK(B), a time slot in which this operation Op(B) may be performed, etc., Preferably, the processing unit CPU (B) of the device DB verifies (10b) that the digital message M (A) is authenticated by the controller C, step Preferably, a processing unit CPU (A) of the device DA verifies (10a) that the digital message M (B) is authenticated by the controller C, step a step (201, 202, 204) of the processing unit CPU(B) of the device DB extracting data contained in the digital message M(A), such as the public key PuK(A), the authorization data AD(A), the operation Op(A), the verification key VK(A), the time slot in which this operation Op(A) may be executed, said extraction preferably only taking place in case of a positive verification that the digital message M(A) is authenticated by the controller C, a step in which the processing unit CPU(A) of the device DA extracts the data contained in the digital message M(B), such as the public key PuK(B), the authorization data AD(B), the operation Op(B), the verification key VK(B), the time slot in which this operation Op(B) may be executed, said extraction preferably only taking place in case of a positive verification that the digital message M(B) has been authenticated by the controller C, a step of receiving (400) an authorized SA(A) from the communication module CM(A) of the device DA, the authorized SA(A) preferably including data such as a secret signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A), said secret preferably being transmitted (300) from the communication module CM(B) of the device DB to the communication module CM(A) of the device DA, a step of the communication module CM(A) of the device DA receiving an authorization SA(B) from the communication module CM(B) of the device DB, the authorization SA(B) preferably containing data such as a further secret signed by the processing unit CPU(B) of the device DB using the private key PrK(B) and / or signed by the processing unit CPU(B) of the device DB using the private key PrK(B), said further secret preferably having been transmitted from the communication module CM(A) of the device DA to the communication module CM(B) of the device DB, a processing unit CPU(B) of the device DB verifies (400b) the certified SA(A), preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting said public key PuK(A) from the digital message M(A), a processing unit CPU(A) of the device DA verifies the certified SA(B), preferably using a public key PuK(B) corresponding to said private key PrK(B), advantageously after extracting said public key PuK(B) from the digital message M(B), The processing unit CPU(B) of the device DB is Extracting (204) a verification key VK(A) contained in the digital message M(A); Calculating (203) a candidate 205 digital signature cx(A) of the authorization data AD(A) by means of a one-way function programmed in the processing unit CPU(B), and computing a candidate aggregate digital signature cADS(A) from the verification key VK(A) and the computed candidate digital signature cx(A) of the authorization data AD(A), The processing unit CPU(A) of device DA Extracting a verification key VK(B) contained in a digital message M(B); - calculating a candidate digital signature cx(B) of the authorization data AD(B) by means of a one-way function programmed in a processing unit CPU(A); and computing a candidate aggregate digital signature cADS(B) from the verification key VK(B) and the computed candidate digital signature cx(B) of the authorization data AD(B), a processing unit CPU(B) of the device DB checking (207) whether the candidate aggregate digital signature cADS(A) matches the aggregate digital signature ADS(A) stored in the memory (206) and only in case of a positive verification of the authorized SA(A) and a positive match of the candidate aggregate digital signature cADS(A) with the aggregate digital signature ADS(A) the processing unit CPU(B) of the device DB sending (500) an indication to the controller B that the controller A is indeed authorized by the controller C to execute (500a) the operation Op(A), The method includes a step in which a processing unit CPU(A) of the device DA checks whether the candidate aggregate digital signature cADS(B) matches the aggregate digital signature ADS(B) stored in a memory, and only in case of positive verification of the authorized SA(B) and positive match of the candidate aggregate digital signature cADS(B) with the aggregate digital signature ADS(B), the processing unit CPU(A) of the device DA sends an indication to the controller A that the controller B is actually authorized by the controller C to execute (510) the operation Op(B).
[0178]
[0178] This system allows controller B to verify the validity of the digital content of digital message M(A) and controller A to verify the validity of the digital content of digital message M(B) with a higher degree of certainty than the prior art solutions. Moreover, this system allows controller B to control the authentication information linked to the digital content of digital message M(A) in order to check if this digital content is valid, and controller A to control the authentication information linked to the digital content of digital message M(B) in order to check if this digital content is valid. This system allows controller A to identify itself only using the digital message M(A) authenticated by the certified SA(A) and the forgery-proof digital file issued by controller C, and controller B to identify itself only using the digital message M(B) authenticated by the certified SA(B) and the forgery-proof digital file issued by controller C. This system allows controller B to fully trust the validity of the presented mission command, and controller A to fully trust the validity of the presented mission command.
[0179]
[0179] According to an embodiment, the invention allows an operation Op(A) to be executed by controller A and an operation Op(B) to be executed by controller B without the need to contact a central database or a server containing mission instructions. Indeed, controller B and controller A can be in an offline environment as long as they can communicate with each other during the implementation of the method according to an embodiment of the invention, preferably as long as controller A contains an aggregate digital signature ADS(B) previously downloaded, for example, from controller C or from a server, and preferably as long as controller B contains an aggregate digital signature ADS(A) previously downloaded, for example, from controller C or from a server. The transmission of digital messages M(A) and M(B) to controller A and to controller B can advantageously be realized via an unprotected channel.
[0180]
[0180] According to an embodiment, the invention relates to the implementation of the method according to the invention in a communications network CN which is equipped with a previous system according to the invention.
[0181] A nurse interacting with a medical device
[0181] According to a third example of an application of the present invention illustrated by FIG. 4, the present invention may be implemented to safely enable a nurse to inject a particular medication into a particular patient using a medical device.
[0182]
[0182] According to this example, the controller A is a nurse A. The nurse A is equipped with a device DA, which can be for example a smartphone. The nurse A has to attend to several patients and therefore has to inject different medicines according to different task orders, issued for example by at least one doctor and / or one hospital, which in this use case is a controller C. The controller A, i.e. the nurse A, comprises a private key PrK(A) issued by the controller A and preferably associated to a public key PuK(A), said public key PuK(A) being certified by the controller C, i.e. the doctor C and / or the hospital. This private key PrK(A) is stored in the memory of the processing unit CPU(A) of the device DA, i.e. for example the smartphone of the nurse A, and preferably stored in a protected enclave of the memory.
[0183]
[0183] According to this example, the controller B is a medical device B, preferably a smart medical device, i.e. a medical device equipped with a device DB. Said medical device B is configured to deliver or inject a certain amount of a certain drug, when said medical device receives an appropriate mission command indicating that said medical device can perform a certain action Op, such as a certain nurse injecting a drug into a patient, said mission command being issued by a doctor C, who in this example plays the role of controller C, and / or by the hospital.
[0184]
[0184] According to this example, the controller C is a doctor C and / or a medical institution and / or a hospital. Said doctor C issues a task order using a digital message M transmitted to a nurse A via a communication network CN, such as the Internet. According to an embodiment, the digital message M is also transmitted by the doctor C to the medical device B. For example, the digital message M may contain a task order, for example in the form of a set of data indicating what the nurse A needs to do and when the nurse A needs to do it. In this example, the task order may contain the following data: Nurse A has a public key PuK(A). The verification key VK(A). Action Op: Nurse A needs to inject Yml of drug X to patient ABC. Time slot: This action needs to be performed, for example, on June 10, 2021, between 9:30 and 9:45. The location that corresponds to the patient's address.
[0185]
[0185] According to an embodiment, when the nurse, i.e. the controller A, receives the digital message M, he verifies using the processing unit CPU(A) that the digital message M has been authenticated by the doctor C, and only in case of a positive verification that the digital message M has been authenticated by the doctor C, the processing unit CPU(A) of the device DA of the nurse A preferably starts the extraction of the authorization data AD(A) contained in the digital message M. These authorization data AD(A) preferably contain the data of the task orders of the nurse A.
[0186]
[0186] Next, the processing unit CPU(A) of nurse A's device DA, i.e. for example nurse A's smartphone DA, extracts various data from the digital message M, such as data related to the operation Op, as well as, for example, the time slot mentioned in the mission command and / or the location mentioned in the mission command.
[0187]
[0187] According to a preferred embodiment, when the medical device, i.e. the controller B, receives the digital message M, it verifies using its processing unit CPU(B) that the digital message M has been authenticated by the doctor C, and only in case of a positive verification that the digital message M has been authenticated by the doctor C, the processing unit CPU(B) of the device DB of the medical device preferably starts to extract the authorization data AD(A) contained in the digital message M. These authorization data AD(A) preferably comprise the data of the mission order.
[0188]
[0188] Next, controller B, i.e. medical device B, extracts from the digital message M the public key PuK(A) corresponding to nurse A's, i.e. controller A's private key PrK(A), the verification key (A), data related to the operation Op, and various data, such as, for example, the time slot mentioned in the mission command and / or the location mentioned in the mission command.
[0189]
[0189] According to an embodiment, for example, when nurse A arrives in front of medical device B or when nurse A activates medical device B, medical device B preferably sends a challenge to nurse A and the communication module CM(B) of device DB transmits the challenge to the communication module CM(A) of device DA, which in this case is for example nurse A's smartphone.
[0190]
[0190] According to an embodiment, the communication module CM(B) of the device DB controlled by the medical device B comprises a display module DD(B) and preferably an optical reader module OR(B). Said display module DD(B) is adapted to display an optically readable representation of data and preferably an optically readable representation of a graphical data block GDB(B). The graphical data block GDB(B) may contain different types of data, for example the aforementioned challenge. This digital data block GDB(B) may advantageously contain a 2D barcode, also called "QR code".
[0191]
[0191] According to an embodiment, the communication module CM(A) of the smartphone of the nurse A comprises an optical reader module OR(A) and preferably comprises a display module DD(A). Said optical reader module OR(A) is configured to read and decode optically readable representations of data, preferably configured to read and decode optically readable representations of graphical data blocks GDB. The communication module CM(A) is preferably able to extract data, such as for example the aforementioned challenge, from the graphical data blocks GDB.
[0192]
[0192] In this example, medical device B uses a display module to display a QR code QRC(B), which encodes a challenge. Then, nurse A uses nurse A's smartphone to decode said QR code QRC(B) and extracts said challenge using the smartphone's optical reader module OR(A).
[0193]
[0193] Advantageously, this challenge can be a random number generated by the random number generator module GRNM(B) of the device DB. According to an embodiment, when nurse A receives said challenge via her smartphone (advantageously via the communication module CM(A) of her smartphone), the smartphone signs the challenge with the private key PrK(A) of nurse A, more precisely the processing unit CPU(A) of the smartphone signs the challenge with the private key PrK(A) generating said certified SA. The smartphone then preferably sends the certified SA back to the medical device B, which in turn sends said certified SA to the communication module CM(B) of the device DB controlled by the medical device B.
[0194]
[0194] According to an embodiment, the communication module CM(A) of the smartphone displays an optically readable representation of data and preferably displays an optically readable representation of a graphical data block GDB(A) using a display module DD(A), said graphical data block GDB(A) preferably containing an encoded version of the certification SA, for example in the form of one or more QR codes QRC(A).
[0195]
[0195] According to this embodiment, the communication module CM(B) of the device DB controlled by the medical device B reads and decodes this QR code QRC(B) using the optical reader module OR(B) in order to extract the aforementioned certification SA.
[0196]
[0196] Next, the medical device B checks the validity of the certified SA using the public key PuK(A), which has been extracted from the digital message M by the processing unit CPU(B) and is preferably in the mission command, i.e. included in the digital message M.
[0197]
[0197] Afterwards, the processing unit CPU(B) of the device DB of the medical device B calculates a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B) and calculates a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A), and the processing unit CPU(B) of the device DB checks whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory. According to an embodiment, said aggregate digital signature ADS has been received by the medical device B from said doctor C and / or from the server. Then, said aggregate digital signature ADS is stored in the memory of the processing unit CPU(B) of the device DB controlled by the medical device B (206).
[0198]
[0198] According to an embodiment, medical device B extracts other data from digital message M, such as the time slot during which nurse A must operate, in this example, 10 June 2021, 9:30-9:45, and / or the patient's location.
[0199]
[0199] Next, when the nurse is located at the patient's address, if the time corresponds to the time slot contained in the mission order, for example, 06 / 10 / 2021 09:30-09:45, and if the verification of the certified SA is positive and the candidate aggregate digital signature cADS matches the aggregate digital signature ADS, the medical device B receives an indication from the processing unit CPU(B) of the device DB that the nurse A is indeed authorized by the doctor C to perform the action Op mentioned in the mission order contained in the digital message M. Thus, the medical device B authorizes the nurse A to inject Yml of drug X into the patient ABC, and / or according to the investigation of the nurse A, the medical device B injects Yml of drug X into the patient ABC, and / or the medical device B delivers Yml of drug X to the nurse A to be injected into the patient ABC.
[0200]
[0200] According to this example of a use case of the present invention, the system preferably comprises: A smartphone DA of nurse A, said smartphone DA being configured to enable the authentication of nurse A by the medical device B in order to enable nurse A to perform an action Op, said smartphone preferably comprising a communication module CM(A) comprising a display module DD(A) configured to display an optically readable representation of data, advantageously an optically readable representation of a graphical data block GDB(A), said graphical data block GDB(A) comprising encoded data, for example in the form of a QR code. a medical device B comprising and controlling a device DB, said medical device B being configured to check the authorization for a specific nurse to inject a specific amount of a specific medicine to a specific patient, preferably in a specific time slot, and / or for the delivery of a specific amount of a specific medicine to a specific patient according to a survey of a specific nurse, preferably in a specific time slot, said device DB comprising a communication module CM(B) comprising an optical reader module OR(B) advantageously configured to read and decode an optically readable representation of data, preferably an optically readable representation of a graphical data block GDB, and to extract data from the graphical data block GDB;
[0201]
[0201] The system is configured in the following way. The communication module CM(B) of the device DB of the medical device B is configured to receive (200) a digital message M containing a mission command, said mission command comprising a public key PuK(A) owned by the nurse A, authorization data AD(A) indicating that the nurse A has been authorized by the doctor C to perform an action Op, a verification key VK(A), the time slot in which this action Op has to be performed, etc. The processing unit CPU (B) of the device DB is preferably arranged to verify (10b) that the digital message M is authenticated by the doctor C. The processing unit CPU(B) of the device DB is configured to extract (201, 202, 204) the data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A) and the time slot in which this operation Op has to be executed, preferably this extraction being performed only in case of a positive verification that the digital message M has been authenticated by the doctor C. The communication module CM(B) of the device DB is preferably configured to receive (400) the certified SA from the communication module CM(A) of the smartphone DA, and the optical reader module OR(B) of the communication module CM(B) of the device DB is preferably configured to read and decode an optically readable representation of a graphical data block GDB(A) displayed by the display module DD(A) of the smartphone DA, said graphical data block GDB(A) preferably comprising an encoded version of the certified SA, advantageously in the form of a 2d barcode, and said optical reader module OR(B) is configured to decode said encoded version of said certified SA in order to extract the certified SA, said certified SA preferably comprising data such as a secret signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) of the device DA using the private key PrK(A). The processing unit CPU(B) of the device DB is configured to verify (400b) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M. The processing unit CPU(B) of the device DB is Calculating (203) a candidate 205 digital signature cx(A) of the authorization data AD(A) by means of a one-way function programmed in the processing unit CPU(B), and computing a candidate aggregate digital signature cADS from the verification key VK(A) and a computed candidate digital signature cx(A) of the authorization data AD(A). The processing unit CPU (B) of the device DB is configured to check (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206), and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU (B) of the device DB is configured to send (500) an indication to the medical device B that the nurse A is indeed authorized by the doctor C to perform the operation Op (500a).
[0202]
[0202] This system allows medical device B to verify the validity of the digital content of digital message M with a higher degree of certainty than prior art solutions. Moreover, this system allows medical device B to control the authentication information linked to this digital content, i.e. the mission order, in order to check if this digital content is valid. This system allows nurse A to identify herself using only the certification SA and the authentication information present in digital message M and preferably authenticated by a forgery-proof digital file issued by controller C. This system allows medical device B to fully trust the validity of the mission order presented.
[0203]
[0203] It should be noted that this system avoids the use of biometric data of Nurse A. The mission command and the certified SA are sufficient to give full trust to the medical device B. Advantageously, this system avoids the disclosure of any biometric data, biometrics or personal information about Nurse A.
[0204]
[0204] In accordance with this example of a use case of the present invention, the present invention relates to the following method according to an embodiment: The smartphone DA of nurse A is configured to enable authentication of nurse A by the medical device B in order to enable nurse A to perform an action Op, said smartphone DA preferably comprising a communication module CM(A) equipped with a display module DD(A) configured to display an optically readable representation of data, advantageously an optically readable representation of a graphical data block GDB(B), said graphical data block GDB(B) comprising encoded data, for example in the form of a QR code. The medical device B comprises and controls a device DB, said medical device B being configured to check the authorization for a specific nurse to inject a specific amount of a specific medicine to a specific patient, preferably in a specific time slot, and / or for delivery of a specific amount of a specific medicine to a specific patient according to a survey of a specific nurse, preferably in a specific time slot, and the device DB comprises a communication module CM(B) comprising an optical reader module OR(B) advantageously configured to read and decode an optically readable representation of data, preferably an optically readable representation of a graphical data block GDB, and to extract data from the graphical data block GDB.
[0205]
[0205] This method is receiving (200) a digital message M containing a mission command, said mission command comprising a public key PuK(A) owned by nurse A, authorization data AD(A) indicating that nurse A has been authorized by doctor C to perform an action Op, a verification key VK(A), the time slot in which this action Op has to be performed, etc., Preferably, the processing unit CPU (B) of the device DB verifies (10b) that the digital message M is authenticated by the doctor C, step a step in which the processing unit CPU(B) of the device DB extracts (201, 202, 204) the data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A) and the time slot in which this operation Op must be executed, preferably only in case of a positive verification that the digital message M has been authenticated by the doctor C; a step of the communication module CM(B) of the device DB receiving (400) an authorization SA from the communication module CM(A) of the smartphone DA, whereby the optical reader module OR(B) of the communication module CM(B) of the device DB preferably reads and decodes an optically readable representation of a graphical data block GDB(A) displayed by the display module DD(A) of the smartphone DA, said graphical data block GDB(A) preferably comprising an encoded version of the authorization SA, advantageously in the form of a 2d barcode, said optical reader module OR(B) decodes said encoded version of said authorization SA in order to extract said authorization SA, said authorization SA comprising data such as a secret signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) of the device DA using the private key PrK(A), a processing unit CPU(B) of the device DB verifies (400b) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M, The processing unit CPU(B) of the device DB is Extracting (204) a verification key VK(A) contained in the digital message M; Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), calculating (205) a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A); and The method includes a step in which a processing unit CPU (B) of the device DB checks (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory, and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU (B) of the device DB sends (500) an indication to the medical device B that the nurse A is actually authorized by the doctor C to perform the operation Op (500a).
[0206]
[0206] This method allows medical device B to verify the validity of the digital content of digital message M with a higher degree of certainty than prior art solutions. Moreover, it allows medical device B to control the authentication information linked to this digital content, i.e. the mission order, in order to check if this digital content is valid. This method allows nurse A to identify herself using only the certification SA and the authentication information, which is preferably in the digital message M and authenticated by a forgery-proof digital file issued by controller C. This method allows medical device B to fully trust the validity of the mission order presented.
[0207]
[0207] It must be noted that this method avoids the use of biometric data of nurse A. This digital message M and the certification SA are sufficient to give full trust to medical device B. This method advantageously avoids the disclosure of any biometric data, biometrics or personal information of nurse A.
[0208]
[0208] According to an embodiment, the invention allows the operations Op to be executed by the nurse A and the medical device B without the need to contact a central database or a server containing the mission orders. Indeed, the medical device B and the nurse A can be in an offline environment, as long as they can communicate with each other during the implementation of the method according to an embodiment of the invention, and preferably as long as the controller B contains the aggregate digital signature ADS previously downloaded, for example, from the controller C or from the server. The transmission of the digital message M to the nurse A and to the medical device B can advantageously be realized over an unprotected channel.
[0209]
[0209] According to an embodiment, the invention relates to the implementation of the method according to the invention in a medical environment equipped with a previous system according to the invention.
[0210] Search Warrant
[0210] In accordance with a fourth example of the application of the present invention illustrated by FIG. 5, the present invention may be implemented to securely enable police officers to execute search warrants on particular citizens.
[0211] According to this example, the controller A is a police officer A. The police officer A is equipped with a device DA, which can be, for example, a smartphone DA. The police officer A needs to carry out the tasks contained in a warrant, such as, for example, entering a citizen's house to search for evidence of a crime, in this case the warrant is, for example, a search warrant. This warrant has preferably been issued by a judge or a judicial body, said judge or judicial body playing the role of the controller C in this use case. The police officer A, i.e. the controller A, comprises a private key PrK(A), which has been issued by the controller A and is preferably associated with a public key PuK(A), said public key PuK(A) having been certified by the controller C, i.e. for example a judge C. This private key PrK(A) is stored in the memory of the processing unit CPU(A) of the device DA, i.e. for example the smartphone DA of the police officer A, preferably stored in a protected enclave of the memory.
[0212]
[0212] According to this example, Controller B is the citizen mentioned in the above warrant, and in this example, the device DB can be Citizen B's smartphone DB.
[0213]
[0213] According to this example, the controller C is therefore a judge C and / or a judicial body. Said judge C issues a warrant, i.e. a mission order, by means of a digital message M transmitted to the officer A via a communication network CN, for example the Internet. For example, this digital message M can include and / or be in the form of an optically readable representation of a graphical data block GDB(A), said graphical data block GDB(A) advantageously including a 2D barcode, such as for example a QR code QRC(A). According to an embodiment, such a graphical data block GDB(A) can also be called a digital mark DM(A).
[0214]
[0214] According to a preferred embodiment, the digital message M containing the warrant is in a machine-readable form, for example a QR code QRC(A).
[0215]
[0215] For example, the digital message M may include a mission order, for example in the form of a set of data indicating what officer A is authorized to do and when officer A is authorized to do it. In this example, the mission order, i.e., the warrant, may include the following data: Officer A has a public key PuK(A). The verification key VK(A). Action Op: Officer A is authorized to enter the home of Citizen B at address Y to search for evidence. Time slot: This action must be performed, for example, on June 11, 2021 between 15:00 and 18:30 PM.
[0216]
[0216] According to a preferred embodiment, when an officer A, i.e., controller A, receives a digital message M from a judge C, the controller A uses a processing unit CPU(A) to verify that the digital message M has been authenticated by the judge C, i.e., controller C.
[0217]
[0217] For example, once at the door of the house of citizen B, police officer A shows citizen B a digital message M, i.e. the aforementioned QR code QRC(A). According to an embodiment, a smartphone DA, i.e. device DA, comprises a display module DD(A) and preferably comprises an optical reader module OR(B), a communication module CM(A), said display module DD(A) being arranged to display an optically readable representation of data, preferably an optically readable representation of a graphical data block GDB(A), such as the graphical data block GDB(A) containing an encoded version of the warrant, of the digital message M. Thus, according to an embodiment, once at the door of the house of citizen B, police officer A uses said display module DD(A) on his smartphone DA to display the QR code QRC(A) encoding said digital message M.
[0218]
[0218] Next, Citizen B uses his smartphone DB to optically read said QR code QRC(A) displayed on the display module DD(A) of Policeman A's smartphone DA, and then Citizen B uses his smartphone DB to extract a digital message M from said QR code QRC(A). According to an embodiment, Citizen B's smartphone DB comprises an optical reader module OR(B), preferably comprising a display module DD(B), and a communication module CM(B). Said optical reader module OR(B) is configured to read and decode optically readable representations of data, preferably configured to read and decode optically readable representations of graphical data blocks GDB. The communication module CM(B) is preferably able to extract data from the graphical data block GDB, such as for example said digital message M from said QR code QRC(A).
[0219]
[0219] According to an embodiment, the smartphone DB of citizen B may be equipped with specific software, preferably using a processing unit CPU(B), configured to read, decode and extract such a digital message M. When the digital message is received by the communication module CM(B) of the smartphone DB of citizen B, the processing unit CPU(B) checks the validity of the digital message M and its content, i.e. in this example the warrant.
[0220]
[0220] According to a preferred embodiment, when citizen B, i.e. controller B, receives the digital message M, the controller B verifies using the smartphone DB, i.e. processing unit CPU(B), that the digital message M has been authenticated by judge C, i.e. controller C, and only in case of a positive verification that the digital message M has been authenticated by judge C, the processing unit CPU(B) of the smartphone DB, i.e. device DB, starts the extraction of the authorization data AD(A) contained in the digital message M. These authorization data AD(A) preferably comprise the data of the mission order.
[0221]
[0221] According to an embodiment, after verification that the digital message M has been authenticated by judge C, the processing unit CPU(B) extracts various data from the digital message M, such as the public key PuK(A) corresponding to officer A's private key PrK(A), the verification key (A), data related to the operation Op, and, for example, the time slot mentioned in the mission order.
[0222]
[0222] Citizen B then sends a challenge to police officer A. According to an embodiment, this challenge can be a random number, such as a random number invented on the fly by citizen B. The communication module CM(B) of the smartphone DB of citizen B preferably sends the challenge to the communication module CM(A) of the smartphone DA of police officer A.
[0223]
[0223] This challenge can advantageously be a random number generated by the random number generator module GRNM(B) of citizen B's smartphone DB.
[0224]
[0224] According to an embodiment, the communication module CM(B) of the smartphone DB of the citizen B transmits the aforementioned challenge to the communication module CM(A) of the smartphone DA of the police officer A using the communication network CN, preferably using a short-range wireless communication network, for example a Bluetooth communication network.
[0225]
[0225] According to an embodiment, the challenge is transmitted via electromagnetic waves from the communication module CM(B) of the smartphone DB of the citizen B to the communication module CM(A) of the smartphone DA of the police officer A.
[0226]
[0226] According to an embodiment, the challenge is in the form of a data string.
[0227]
[0227] According to an example, this challenge can be encoded in the form of an optically readable representation of a graphical data block GDB(B), said graphical data block GDB(B) can advantageously comprise a 2D barcode, for example a QR code QRC(B). According to an embodiment, such a graphical data block GDB(B) can also be called a digital mark DM(B).
[0228]
[0228] According to an embodiment, the challenge is in a machine-readable form, for example a QR code QRC(B).
[0229]
[0229] According to an embodiment, citizen B shows said QR code QRC(B) to police officer A. According to an embodiment, the communication module CM(B) of citizen B's smartphone DB, i.e. device DB, comprises a display module DD(A), preferably an optical reader module OR(B), said display module DD(B) arranged to display an optically readable representation of data, preferably an optically readable representation of a graphical data block GDB(B), such as a graphical data block GDB(B) containing an encoded version of a challenge, i.e. of a random number, or more generally of a secret. Thus, according to an embodiment, citizen B uses said display module DD(B) on his smartphone to display a QR code QRC(B) encoding said challenge.
[0230]
[0230] Policeman A then uses his smartphone DA to optically read said QR code QRC(B) displayed on the display module DD(B) of citizen B's smartphone DB. Policeman A then uses his smartphone DA to extract a challenge, i.e. a secret or for example a random number, from said QR code QRC(B). According to an embodiment, the communication module CM(A) of policeman A's smartphone DA comprises an optical reader module OR(A) and preferably comprises a display module DD(A). Said optical reader module OR(A) is configured to read and decode optically readable representations of data, preferably configured to read and decode optically readable representations of graphical data blocks GDB. The communication module CM(A) is preferably able to extract data from the graphical data block GDB, such as for example said challenge from said QR code QRC(B).
[0231]
[0231] According to an embodiment, the smartphone DA of the policeman A may be equipped with specific software, preferably using a processing unit CPU(A), configured to read, decode and extract said challenge and preferably configured to sign said challenge. When the challenge is received by the communication module CM(A) of the smartphone DA of the policeman A, the processing unit CPU(A) signs said challenge using the private key PrK(A) of the policeman A. The communication module CM(A) of the smartphone DA of the policeman A then transmits the signed challenge in the form of an authentication SA to the citizen, i.e. to the communication module CM(B) of the smartphone of the citizen B.
[0232]
[0232] According to an embodiment, the communication module CM(A) of the smartphone DA of police officer A transmits said certification SA to the communication module CM(B) of the smartphone DB of citizen B using a communication network CN, preferably using a short-range wireless communication network, such as, for example, a Bluetooth communication network.
[0233]
[0233] According to an embodiment, the certification SA is transmitted via electromagnetic waves from the communication module CM(A) of the smartphone DA of the police officer A to the communication module CM(B) of the smartphone DB of the citizen B.
[0234]
[0234] According to an embodiment, the certified SA is in the form of a data string.
[0235]
[0235] According to an example, this authorization SA can be encoded in the form of an optically readable representation of a graphical data block GDB(A2), said graphical data block GDB(A2) can advantageously comprise a 2D barcode, for example a QR code QRC(A2). According to an embodiment, such a graphical data block GDB(A2) can also be called a digital mark DM(A2).
[0236]
[0236] According to a preferred embodiment, the certification SA is in a machine-readable form, for example a QR code QRC(A2).
[0237]
[0237] According to an embodiment, police officer A shows said QR code QRC(A2) to citizen B. According to an embodiment, police officer A uses said display module DD(A) on his smartphone DA to display the QR code QRC(A2), which encodes said authorization SA.
[0238]
[0238] Citizen B then uses his smartphone DB to optically read said QR code QRC(A2) displayed on the display module DD(A) of Policeman A's smartphone DB. Citizen B then uses the optical reader module OR(B) in his smartphone DB to extract the authentication SA, i.e. the signed challenge, from said QR code QRC(A2). The communication module CM(B) is preferably able to extract data from the graphical data block GDB, for example said authentication SA from said QR code QRC(A2).
[0239]
[0239] According to an embodiment, the communication module CM(B) of citizen B's smartphone DB reads and decodes this QR code QRC(A2) using the optical reader module OR(B) in order to extract the aforementioned certification SA.
[0240]
[0240] According to an embodiment, citizen B's smartphone may be equipped with specific software, preferably using a processing unit CPU(A), configured to read, decode and / or extract said authorization SA. When the authorization SA is received by the communication module CM(B) of citizen B's smartphone DB, the processing unit CPU(B) checks the authorization SA, i.e. the signed challenge, and in particular checks that the challenge has been signed using the private key PrK(A) that corresponds to the public key PuK(A) extracted from the digital message M, i.e. that is located in the warrant.
[0241]
[0241] Then, the processing unit CPU(B) of the smartphone DB of citizen B calculates a candidate digital signature cx(A) for the authorization data AD(A) by means of a one-way function programmed in the processing unit CPU(B) and calculates a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) for the authorization data AD(A), and the processing unit CPU(B) checks whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory. According to an embodiment, said aggregate digital signature ADS has been received by citizen B from said judge C and / or from the server. According to an embodiment, when citizen B reads said QR code QRC(A) using his smartphone DB of citizen B, preferably via a dedicated application, citizen B's smartphone DB contacts the server using the communication module CM(B) and downloads said aggregate digital signature ADS. Then, said aggregate digital signature ADS is stored in the memory of the processing unit CPU(B) of the smartphone DB of citizen B.
[0242]
[0242] According to an embodiment, Citizen B's smartphone DB extracts other data from the digital message M, such as the time slot in which Officer A must operate, in this example, 15:00-18:30 on June 11, 2021.
[0243]
[0243] Next, if the time is within the legitimate time mentioned in the mission order, for example, between 15:00 and 18:30 on June 11, 2021, and if the verification of the certified SA is positive and the candidate aggregate digital signature cADS matches the aggregate digital signature ADS, Citizen B receives an indication from Citizen B's smartphone, preferably from the processing unit CPU(B) of Citizen B's smartphone DB, that Officer A has indeed been authorized by Judge C to perform the action Op mentioned in the warrant contained in the digital message M. Citizen B can therefore authorize Officer A to enter Citizen B's house at address Y to search for evidence.
[0244]
[0244] According to this example of a use case of the present invention, the system preferably comprises: A smartphone DA of a police officer A, said smartphone DA being configured to enable the authentication of police officer A by citizen B in order to enable police officer A to perform an operation Op, said smartphone DA comprising a processing unit CPU(A) and a communication module CM(A) comprising a display module DD(A) and an optical reader module OR(A), said display module DD(A) being configured to display an optically readable representation of data, advantageously configured to display an optically readable representation of a graphical data block GDB(A), said graphical data block GDB(A) comprising encoded data, for example in the form of a QR code, said optical reader module OR(A) being configured to read and decode the optically readable representation of data, preferably configured to read and decode the optically readable representation of the graphical data block GDB and advantageously configured to extract data from the graphical data block GDB. A smartphone DB of a citizen B, said smartphone being configured to check the authorization of a certain officer to perform an operation Op, preferably performed in a certain time slot, said smartphone DB comprising a processing unit CPU(B) and a communication module CM(B) comprising a display module DD(B) and an optical reader module OR(B), said display module DD(B) being configured to display an optically readable representation of data, advantageously configured to display an optically readable representation of a graphical data block GDB(B), said graphical data block GDB(B) comprising encoded data, for example in the form of a QR code, said optical reader module OR(B) being configured to read and decode the optically readable representation of data, preferably configured to read and decode the optically readable representation of the graphical data block GDB, advantageously configured to extract data from the graphical data block GDB.
[0245]
[0245] The system is configured in the following way. A communication module CM(B) is configured to receive (200) a digital message M containing a mission order, said mission order comprising a public key PuK(A) owned by officer A, authorization data AD(A) indicating that officer A has been authorized by judge C to perform an action Op, a verification key VK(A), the time slot in which this action Op has to be performed, etc. The processing unit CPU (B) is preferably arranged to verify (10b) that the digital message M has been authenticated by the judge C. The processing unit CPU(B) is configured to extract (201, 202, 204) data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A), the time slot in which this operation Op has to be executed, said extraction preferably occurring only in case of a positive verification that the digital message M has been authenticated by the judge C. The communication module CM(B) is configured to receive (400) an authorized SA from the communication module CM(A), an optical reader module OR(B) of the communication module CM(B) is preferably configured to read and decode an optically readable representation of a graphical data block GDB(A) displayed by the display module DD(A), said graphical data block GDB(A) preferably comprising an encoded version of the authorized SA, advantageously in the form of a 2d barcode, said optical reader module OR(B) is configured to decode said encoded version of said authorized SA in order to extract the authorized SA, said authorized SA preferably comprising data such as a secret signed (300a) by the processing unit CPU(A) using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) using the private key PrK(A). The processing unit CPU(B) is configured to verify (400b) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M. The processing unit CPU(B) Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), and computing (205) a candidate aggregate digital signature cADS from the verification key VK(A) and a computed candidate digital signature cx(A) of the authorization data AD(A). The processing unit CPU(B) is configured to check (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206), and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) is configured to send (500) an indication to the citizen B that the police officer A is indeed authorized by the judge C to perform the action Op (500a).
[0246]
[0246] This system allows Citizen B to verify the validity of the digital content of digital message M with a higher degree of certainty than in prior art solutions. Moreover, this system allows Citizen B to control the authentication information, i.e. the mission order, linked to this digital content in order to check if this digital content is valid. This system allows Officer A to identify himself using only the certification SA and Officer A's authentication information, which is preferably present in the digital message M and authenticated by a forgery-proof digital file issued by Controller C. This system allows Citizen B to fully trust the validity of the mission order presented to him.
[0247]
[0247] It should be noted that this system avoids the use of biometric data of Officer A. The mission order and certification SA are sufficient to give full trust to Citizen B. Advantageously, this system avoids the disclosure of any biometric data, biometrics or personal information regarding Officer A.
[0248]
[0248] In accordance with this example of a use case of the present invention, the present invention relates to the following method according to an embodiment: A smartphone DA of police officer A is configured to enable authentication of police officer A by citizen B in order to enable police officer A to perform an action Op, said smartphone DA preferably comprising a processing unit CPU(A) and a communication module CM(A) comprising a display module DD(A) and preferably comprising an optical reader module OR(A), said display module DD(A) being configured to display an optically readable representation of data and advantageously configured to display an optically readable representation of a graphical data block GDB(A), said graphical data block GDB(A) comprising encoded data, for example in the form of a QR code, said optical reader module OR(B) being configured to read and decode the optically readable representation of data and preferably configured to read and decode the optically readable representation of the graphical data block GDB and advantageously configured to extract data from the graphical data block GDB. A smartphone DB of a citizen B, said smartphone being configured to check the authorization of a certain officer to perform an operation Op, preferably performed in a certain time slot, said smartphone DB of citizen B comprising a processing unit CPU(B) and a communication module CM(B) comprising an optical reader module OR(B) and preferably comprising a display module DD(B), said optical reader module OR(B) being configured to read and decode an optically readable representation of data, preferably configured to read and decode an optically readable representation of a graphical data block GDB and advantageously configured to extract data from the graphical data block GDB, said display module DD(B) being configured to display an optically readable representation of data, advantageously configured to display an optically readable representation of a graphical data block GDB(B), said graphical data block GDB(B) comprising encoded data, for example in the form of a QR code.
[0249]
[0249] This method is a step of receiving (200) a digital message M containing a mission order, said mission order including the public key PuK(A) owned by the officer A, authorization data AD(A) indicating that the officer A has been authorized by the judge C to perform an action Op, a verification key VK(A), the time slot in which this action Op has to be performed, etc., Preferably, the processing unit CPU (B) verifies (10b) that the digital message M has been authenticated by the judge C, step a step in which the processing unit CPU(B) of the device DB extracts (201, 202, 204) the data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A) and the time slot in which this operation Op must be executed, preferably only in case of a positive verification that the digital message M has been authenticated by the judge C; a step of the communication module CM(B) receiving (400) an authorization SA from the communication module CM(A), whereby an optical reader module OR(B) of the communication module CM(B) of the device DB preferably reads and decodes an optically readable representation of a graphical data block GDB(A) displayed by a display module DD(A), said graphical data block GDB(A) preferably comprising an encoded version of the authorization SA, advantageously in the form of a 2d barcode, said optical reader module OR(B) decodes said encoded version of said authorization SA in order to extract said authorization SA, said authorization SA comprising data such as a secret signed (300a) by the processing unit CPU(A) of the device DA using a private key PrK(A) and / or signed (300a) by the processing unit CPU(A) of the device DA using the private key PrK(A), a processing unit CPU(B) verifies (400b) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M, The processing unit CPU(B) Extracting (204) a verification key VK(A) contained in the digital message M; Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), calculating (205) a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A); and The method includes a step in which the processing unit CPU(B) checks (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206), and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) sends (500) an indication to the smartphone DB of the citizen B that the police officer A is indeed authorized by the judge C to perform the action Op (500a).
[0250]
[0250] This method allows Citizen B to verify the validity of the digital content of digital message M with a higher degree of certainty than prior art solutions. Moreover, it allows Citizen B to control the authentication information, i.e. the mission order, linked to this digital content in order to check if this digital content is valid. This method allows Officer A to identify himself using only the certification SA and his authentication information, which is preferably present in digital message M and authenticated by a forgery-proof digital file issued by controller C. This method allows Citizen B to fully trust the validity of the mission order presented to him.
[0251]
[0251] It should be noted that this method avoids the use of biometric data of Officer A. This digital message M and the authentication SA are sufficient to give full trust to Citizen B. This method advantageously avoids the disclosure of any biometric data, biometrics or personal information of Officer A.
[0252]
[0252] According to an embodiment, the invention enables the actions Op to be executed by officer A and citizen B without the need to contact a central database or a server containing mission orders. Indeed, citizen B and officer A can be in an offline environment, as long as they are able to communicate with each other during the implementation of the method according to an embodiment of the invention, and preferably as long as controller B contains an aggregate digital signature ADS previously downloaded, for example from controller C or from a server. The transmission of digital messages M to officer A and to citizen B can advantageously be realized over an unsecured channel.
[0253]
[0253] According to an embodiment, the invention relates to the implementation of the method according to the invention in a judicial environment equipped with a previous system according to the invention.
[0254] Issuance of official digital documents by civil servants
[0254] According to a fifth example of the application of the present invention illustrated by Fig. 6, the present invention may be implemented to securely authorize a public official to issue an official document, preferably an official digital document such as a digital birth certificate, etc. The present invention preferably allows a person, such as a recipient of this official document, to verify that this official document has been signed by an authorized public official pursuant to an official order from an authority, and to do so in an unquestionable manner.
[0255]
[0255] According to this example, the controller A is a civil servant A. The civil servant A controls and comprises a device DA, which can be for example a computer DA. The civil servant A needs to issue an official digital document, for example a diploma or a birth certificate. This official document is preferably in digital form, for example a PDF document. This official digital document can contain various information, such as name, date, location, signature, etc.
[0256]
[0256] This official digital document is preferably signed by a civil servant A according to an official order from an authority, for example the city's civil registration office. Said authority plays the role of a controller C in this use case. Civil servant A, i.e. controller A, comprises a private key PrK(A), preferably issued by controller A and associated to a public key PuK(A), said public key PuK(A) being certified by controller C, i.e. for example an authority. This private key PrK(A) is stored in the memory of a device DA, i.e. for example a processing unit CPU(A) of the computer DA of civil servant A, preferably stored in a protected enclave of the memory.
[0257] According to this example, Controller B is Citizen B and / or another institution and / or another official who wants to check the validity of this official digital document, i.e., to verify that this official digital document was issued by an authorized official. In this example, the Device DB can be Citizen B's smartphone.
[0258]
[0258] According to this example, the controller C is an authority C. Said authority C delegates the power to sign official digital documents to a certain civil servant. The authority C issues a mission order using a digital message M transmitted to the civil servant A via a communication network CN, for example the Internet. For example, this digital message M may comprise and / or be in the form of an optically readable representation of a graphical data block GDB(A), said graphical data block GDB(A) advantageously comprising a 2D barcode, for example a QR code. According to an embodiment, such a graphical data block GDB(A) may also be referred to as a digital mark DM(A).
[0259]
[0259] According to a preferred embodiment, the digital message M containing the mission instructions is in a machine-readable form, for example as a QR code.
[0260]
[0260] For example, the digital message M may contain a mission order, for example in the form of a set of data indicating what the public official A is authorized to do and when the public official A is authorized to do it. In this example, the mission order may contain the following data: Civil servant A has a public key PuK(A). The verification key VK(A). Action Op: This public official A is authorized to issue and sign official digital documents, such as digital birth certificates, following an official order from, for example, Authority C, on behalf of, for example, the Civil Registration Office of the city of Utopia. Time slot: This action may be performed, for example, during business hours from date 1 to date 2.
[0261]
[0261] According to an embodiment, when a public official A, i.e., controller A, receives a digital message M from an authority C, the controller A uses a computer DA, i.e., a processing unit CPU(A) of the computer DA, to verify that the digital message M has been authenticated by the authority C, i.e., controller C.
[0262]
[0262] For example, when a public servant A issues an official digital document, such as a birth certificate, for example in the form of a PDF document, the public servant A attaches a digital message M to the official digital document, preferably in the form of a QR code QRC(A).
[0263]
[0263] For example, a digital birth certificate is issued by a public official A, containing a QR code QRC(A), said QR code QRC(A) encoding said digital message M.
[0264]
[0264] The public official A preferably signs the official digital document using his private key PrK(A). This digital signature is preferably also attached to the official digital document and acts as an authorized SA. According to an embodiment, the public official A signs a hash of the official digital document using his private key PrK(A), said hash of the official digital document being calculated by a one-way function programmed in the processing unit CPU(A) and applied to at least a part of the content of said official digital document.
[0265]
[0265] When a recipient of said official digital document (named Citizen B) wants to check the validity of said official digital document, Citizen B uses, for example, Citizen B's smartphone DB, which in this example serves as the device DB.
[0266]
[0266] According to an embodiment, citizen B uses his smartphone DB to read and / or decode said digital message M attached and / or bound to said official digital document.
[0267]
[0267] According to an embodiment, citizen B uses his smartphone DB to read the QR code QRC(A) attached and / or linked to said official digital document. According to an embodiment, citizen B uses his smartphone DB to optically read said QR code QRC(A) displayed, for example, on a display module.
[0268]
[0268] Citizen B preferably extracts the digital message M, for example from said QR code QRC(A), using his smartphone DB. According to an embodiment, the smartphone of citizen B comprises a communications module CM(B) designed to receive, read and / or decode said digital message M.
[0269]
[0269] According to an embodiment, the smartphone of citizen B comprises an optical reader module OR(B), preferably comprising a display module DD(B), and a communication module CM(B). Said optical reader module OR(B) is adapted to read and decode optically readable representations of data, preferably adapted to read and decode optically readable representations of graphical data blocks GDB. The communication module CM(B) is preferably able to extract data from the graphical data blocks GDB, such as for example said digital message M from said QR code QRC(A).
[0270]
[0270] According to an embodiment, a public official A sends an official digital document to a citizen B. Said official digital document is preferably sent together with a digital message M and / or may contain said digital message M. According to another embodiment, the official digital document and the digital message M are sent separately by the public official A to the citizen B.
[0271]
[0271] According to an embodiment, the computer DA, ie the device DA, comprises a communications module CM(A) adapted to transmit said official digital document and said digital message M.
[0272]
[0272] According to an embodiment, the smartphone DB of citizen B may be equipped with specific software, preferably using a processing unit CPU(B), configured to read, decode and extract such a digital message M, for example from the QR code QRC(A). When the digital message M is received and / or decoded by the communication module CM(B) of the smartphone DB of citizen B, the processing unit CPU(B) checks the validity of the digital message M and its content, i.e. the mission order in this example.
[0273]
[0273] According to a preferred embodiment, when citizen B, i.e. controller B, receives an official digital document containing a digital message M, citizen B verifies using his smartphone DB, i.e. the processing unit CPU(B) of the smartphone DB of citizen B, that the digital message M has been authenticated by authority C, i.e. controller C, and only in case of a positive verification that the digital message M has been authenticated by authority C, the processing unit CPU(B) of the smartphone DB, i.e. the device DB, preferably starts the extraction of the authorization data AD(A) contained in the digital message M. These authorization data AD(A) preferably contain the data of the mission order.
[0274]
[0274] According to an embodiment, after verification that the digital message M has been authenticated by authority C, the processing unit CPU(B) extracts various data from the digital message M, such as the public key PuK(A) corresponding to the private key PrK(A) of civil servant A, the verification key (A), data related to the operation Op, and, for example, the time slot mentioned in the mission order.
[0275]
[0275] According to an embodiment, when citizen B receives the official digital document containing the digital message M, citizen B also receives an authorized SA. This authorized SA can be included in the official digital document or not in the official digital document. The authorized SA comprises a signature of the official document by public official A using his private key PrK(A). According to a preferred embodiment, the authorized SA comprises a signature of an encoded version of at least a part of the content of the official digital document. Said encoded version of at least a part of the content of the official digital document preferably comprises a hash of the official digital document, calculated by a one-way function programmed in the processing unit CPU(A) and applied to said at least a part of the content of said official digital document.
[0276]
[0276] According to an embodiment, after verification that the digital message M is authenticated by authority C, citizen B verifies the certified SA using a processing unit CPU(B) on citizen B's smartphone DB and preferably checks whether the certified SA, i.e. a hash of at least a part of the content of the official digital document, is signed using the private key PrK(A) corresponding to the public key PuK(A) extracted from the digital message M, and that said hash corresponds to a hash of the official digital document or at least a part of the official digital document calculated by the same one-way function, which one-way function is programmed in the processing unit CPU(B).
[0277]
[0277] According to an embodiment, the smartphone DB checks the certified SA using the processing unit CPU(B) by checking that the hash of the official digital document is signed using the private key PrK(A) corresponding to the public key PuK(A) extracted from the digital message M, and by checking that said hash corresponds to the hash of the official digital document calculated by a one-way function programmed in the processing unit CPU(B) and which is identical to the one-way function programmed in the processing unit CPU(A).
[0278]
[0278] According to an embodiment, the above one-way function has been sent by the controller C to the device DA and to the device DB.
[0279]
[0279] According to an embodiment, the communications module CM(A) transmits said authorization SA to the communications module CM(B) using the communications network CN, preferably using the Internet communications network.
[0280]
[0280] According to an embodiment, the certified SA is transmitted from the communications module CM(A) to the communications module CM(B) via the Internet.
[0281]
[0281] According to an embodiment, the certified SA is in the form of a data string.
[0282]
[0282] According to an example, this authorization SA can be encoded in the form of an optically readable representation of a graphical data block GDB(A2), said graphical data block GDB(A2) can advantageously comprise a 2D barcode, such as for example a QR code QRC(A2). According to an embodiment, such a graphical data block GDB(A2) can also be called a digital mark DM(A2).
[0283]
[0283] According to a preferred embodiment, the certified SA is in a machine-readable form, for example a QR code.
[0284]
[0284] According to an embodiment, citizen B can use his smartphone DB to optically read said QR code QRC(A2) associated with the official digital document. Citizen B then uses the optical reader module OR(B) in his smartphone DB to extract the certification SA from said QR code QRC(A2). The communication module CM(B) is preferably able to extract data from the graphical data block GDB, such as for example said certification SA from said QR code QRC(A2).
[0285]
[0285] According to an embodiment, the communication module CM(B) of citizen B's smartphone DB reads and decodes this QR code QRC(A2) using the optical reader module OR(B) in order to extract the aforementioned certification SA.
[0286]
[0286] According to an embodiment, the smartphone DB of citizen B may be equipped with specific software arranged to read, decode and extract such an authorization SA, this software preferably using a processing unit CPU(A). When the authorization SA is received by the communication module CM(B) of the smartphone DB of citizen B, the processing unit CPU(B) checks the authorization SA, in particular that it is signed with the private key PrK(A) corresponding to the public key PuK(A) extracted from the digital message M, and that the signed hash contained in the authorization SA corresponds to the hash of the official digital document calculated by a one-way function.
[0287]
[0287] Afterwards, the processing unit CPU(B) of citizen B's smartphone DB calculates, by a one-way function programmed in the processing unit CPU(B), a candidate digital signature cx(A) for the authorization data AD(A) and calculates a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) for the authorization data AD(A), and the processing unit CPU(B) checks whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in its memory. According to an embodiment, said aggregate digital signature ADS has been received by citizen B from said authority C and / or from the server.
[0288]
[0288] According to an embodiment, when citizen B receives said digital message M, his smartphone DB contacts the server using the communication module CM(B) and downloads said aggregate digital signature ADS.
[0289]
[0289] According to an embodiment, when citizen B reads the aforementioned QR code QRC(A) using his smartphone DB, preferably via a dedicated application, citizen B's smartphone DB contacts the server using the communication module CM(B) and downloads the aforementioned aggregated digital signature ADS.
[0290]
[0290] The aforementioned aggregate digital signature ADS is preferably stored in the memory of a processing unit CPU(B) of citizen B's smartphone.
[0291]
[0291] According to an embodiment, Citizen B's smartphone DB extracts other data from the digital message M, such as the time slots during which Public Servant A has the authority to operate, in this example, during business hours from date 1 to date 2.
[0292]
[0292] Then, if the verification of the certified SA is positive and the candidate aggregate digital signature cADS matches the aggregate digital signature ADS, when the time corresponds to the time slot mentioned in the mission order, for example the time is legitimately within the business hours from date 1 to date 2, citizen B receives from his smartphone, preferably from the processing unit CPU(B) of citizen B's smartphone, an indication that the civil servant A is indeed authorized by authority C to perform the operation Op mentioned in the mission order contained in the digital message M. This therefore means that the official document has been legitimately issued by the civil servant having the order to issue delivered by authority C.
[0293]
[0293] According to this example of a use case of the present invention, the system preferably comprises: A computer DA of a public official A, said computer DA being configured to issue official digital documents such as birth certificates, for example in the form of PSD documents, to attach a digital message M, optionally in the form of a QR code QRC(A), to said official digital document, and to generate a certified SA by signing said official digital document with a private key PrK(A) of the public official A, preferably by using said private key PrK(A) to sign a fingerprint / hash of said official digital document calculated by a dedicated one-way function programmed in a processing unit CPU(A), said computer DA comprising a communication module CM(A). A smartphone DB of a citizen B, said smartphone configured to verify that a certain official digital document has been duly issued by a civil servant having an issuing order distributed by an authority C, preferably occurring in a certain time slot, said smartphone DB comprising a processing unit CPU(B) and a communication module CM(B), said communication module CM(B) may preferably comprise an optical reader module OR(B) and may preferably comprise a display module DD(B), said optical reader module OR(B) configured to read and decode an optically readable representation of data, preferably configured to read and decode an optically readable representation of a graphical data block GDB and advantageously configured to extract data from the graphical data block GDB.
[0294]
[0294] The system is configured in the following way. Citizen B's smartphone DB is configured to receive an official digital document containing a digital message M, said digital message M containing a mission order, said mission order containing a public key PuK(A) owned by civil servant A, authorization data AD(A) indicating that civil servant A has been authorized by authority C to perform an action Op, a verification key VK(A), a time slot in which this action Op may be performed, etc. The processing unit CPU (B) is preferably arranged to verify (10b) that the digital message M is authenticated by the authority C. The processing unit CPU(B) is configured to extract (201, 202, 204) data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A), the time slot in which this operation Op may be executed, said extraction preferably occurring only in case of a positive verification that the digital message M has been authenticated by the authority C. The communication module CM(B) is configured to receive from the public official A an authentication SA which is preferably attached to the official digital document, said authentication SA corresponding to the signature 300a of the official digital document and which preferably corresponds to a signature by the processing unit CPU(A) using the private key PrK(A) of a hash of at least a part of the content of the official digital document calculated using a one-way function programmed in the processing unit CPU(A). A processing unit CPU(B) is configured to verify (400a) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M, and preferably verifying said hash using said one-way function programmed in the processing unit CPU(B). The processing unit CPU(B) Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), and computing (205) a candidate aggregate digital signature cADS from the verification key VK(A) and a computed candidate digital signature cx(A) of the authorization data AD(A). The processing unit CPU(B) is configured to check (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206), and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) is configured to send (500) an indication to the citizen B that the public official A is indeed authorized by the institution C to perform (500a) the operation Op.
[0295]
[0295] This system allows citizen B to verify the validity of the digital content of digital message M with a higher degree of certainty than in the prior art solutions. Moreover, this system allows citizen B to control the authentication information, i.e. the mission order, linked to this digital content, in order to check whether this digital content is valid, even if civil servant A is far from citizen B. This system allows civil servant A to identify himself using only the certification SA and his authentication information, which is preferably contained in the digital message M and authenticated by a forgery-proof digital file issued by controller C. This system allows citizen B to fully trust the validity of the issued official document.
[0296]
[0296] In accordance with this example of a use case of the present invention, the present invention relates to the following method according to an embodiment: A computer DA of a civil servant A, said computer DA being configured to issue official digital documents such as birth certificates, for example in the form of PDF documents, to attach a digital message M, optionally in the form of a QR code QRC(A), to the official digital document, and to generate a certified SA by signing the official digital document with a private key PrK(A) of the civil servant A, preferably by using the private key PrK(A) to sign a fingerprint / hash of the official digital document calculated by a dedicated one-way function programmed in a processing unit CPU(A), said computer DA comprising a communication module CM(A). A smartphone DB of a citizen B, said smartphone configured to verify that a certain official digital document has been duly issued by a civil servant having an issuing order distributed by an authority C, preferably occurring in a certain time slot, said smartphone DB comprising a processing unit CPU(B) and a communication module CM(B), said communication module CM(B) may preferably comprise an optical reader module OR(B) and may preferably comprise a display module DD(B), said optical reader module OR(B) configured to read and decode an optically readable representation of data, preferably configured to read and decode an optically readable representation of a graphical data block GDB and advantageously configured to extract data from the graphical data block GDB.
[0297]
[0297] This method is a step of receiving (200) an official digital document, by the smartphone DB of citizen B, containing a digital message M, said digital message M containing a mission order, said mission order containing a public key PuK(A) owned by a civil servant A, authorization data AD(A) indicating that the civil servant A is authorized by an authority C to perform an operation Op, a verification key VK(A), a time slot during which this operation Op may be performed, etc.; Preferably, the processing unit CPU (B) verifies (10b) that the digital message M has been authenticated by the authority C, step a step (201, 202, 204) of the processing unit CPU(B) extracting data contained in the digital message M, such as the public key PuK(A), the authorization data AD(A), the operation Op, the verification key VK(A), the time slot in which this operation Op can be executed, said extraction preferably only taking place in case of a positive verification that the digital message M has been authenticated by the authority C, the communication module CM(B) receiving from the civil servant A an authorized SA, which is preferably attached to the official digital document, said authorized SA corresponding to the signature 300a of the official digital document and which preferably corresponds to a signature by the processing unit CPU(A) using the private key PrK(A) of a hash of at least a part of the content of the official digital document calculated using a one-way function programmed in the processing unit CPU(A), a processing unit CPU(B) verifies (400a) the certified SA, preferably using a public key PuK(A) corresponding to said private key PrK(A), advantageously after extracting (202) said public key PuK(A) from the digital message M, and preferably verifying said hash using said one-way function programmed in the processing unit CPU(B), The processing unit CPU(B) Extracting (204) a verification key VK(A) contained in the digital message M; Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by a one-way function programmed in the processing unit CPU(B), calculating (205) a candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A); and The method includes a step in which the processing unit CPU(B) checks (207) whether the candidate aggregate digital signature cADS matches the aggregate digital signature ADS stored in the memory (206), and only in case of positive verification of the certified SA and positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) sends (500) an indication to the citizen B that the public official A is indeed authorized by the agency C to perform the operation Op (500a).
[0298]
[0298] This method allows citizen B to verify the validity of the digital content of digital message M with a higher degree of certainty than the prior art solutions. Moreover, it allows citizen B to control the authentication information, i.e. the mission order, linked to this digital content, in order to check whether this digital content is valid, even if civil servant A is far from citizen B. This method allows civil servant A to identify himself using only the certification SA and his authentication information, which is preferably contained in the digital message M and authenticated by a forgery-proof digital file issued by controller C. This method allows citizen B to fully trust the validity of the issued official document.
[0299]
[0299] According to an embodiment, the invention allows the operations Op to be executed by the civil servant A and the citizen B without the need to contact a central database or a server containing mission orders. Indeed, the citizen B and the civil servant A can be in an offline environment, as long as they can communicate with each other during the implementation of the method according to an embodiment of the invention, and preferably, as long as the controller B contains the aggregate digital signature ADS previously downloaded, for example, from the controller C or from a server. The transmission of the digital message M to the civil servant A and the transmission of the official document to the citizen B can advantageously be realized over an unsecured channel.
[0300]
[0300] According to an embodiment, the invention relates to the implementation of the method according to the invention in an administrative environment equipped with the previous system according to the invention.
[0301] Anti-counterfeit digital files
[0301] As mentioned above, in accordance with a preferred embodiment, controller C is able to issue digital message M in the form of a counterfeit-proof digital file, enabling controller B to have complete confidence in the validity of the presented digital message M.
[0302]
[0302] In order to generate the aforementioned digital message M in the form of a counterfeit-proof digital file, several methods can be used.
[0303]
[0303] According to a preferred embodiment, the invention uses a method for protecting a number of elements and respective associated digital data using a tree of element digital signatures. These elements can be elements of several types, such as authorization data AD, i.e., for example, a mission command. Each associated digital data can contain several types of data, such as, for example, details of the mission command, an identifier of the controller, a public key PuK, details of the operation, and preferably at least one of the elements is a mission command.
[0304]
[0304] Fig. 7 shows a batch of eight elements A1, ..., A8 and illustrates the aforementioned method of generating a digital message M in the form of a forgery-proof digital file by protecting the elements A1, ..., A8 and each associated digital data D1, ..., D8 with a tree of element digital signatures. The protected elements may constitute the digital message M. These elements may for example contain one or more authorization data AD, i.e. mission instructions. According to an embodiment, one of these elements may contain a mission instruction, and said elements, when protected, may form at least a part of said digital message M. Trees associated with digital signatures are well known (binary hash trees, n-ary hash trees or Merkle trees), and these trees generally contain base or leaf nodes, which are used to build the nodes of the next (intermediate) level by digitally signing the concatenation of the digital signatures associated with the leaf nodes according to a particular grouping of the leaf nodes. In the case of a binary tree, the digital signature associated with a node of the first intermediate level is calculated by digitally signing (e.g., using a one-way hash function H or a one-way elliptic curve function, etc.) the concatenation of the digital signatures associated with two successive leaf nodes, respectively. In the case of an n-ary tree, the value of the node of the first intermediate level is obtained by the concatenation of the values of n successive leaf nodes. Trees may have even more complex structures (mixed trees), since the concatenation of leaf nodes may be performed by pairs of successive nodes for a particular leaf node, by triplets of nodes for other successive leaf nodes, etc.
[0305]
[0305] For simplicity, a simple binary tree with eight leaf nodes is shown in Fig. 7, where each value of the eight leaf nodes a(1,1), ..., a(1,8) of the tree corresponds to an elementary digital signature x1 = H(D1), ..., x8 = H(D8), respectively. The first index of all leaf nodes, i.e. a value of "1", indicates the first level (or base level) of the tree, and the second index, which runs from 1 to 8, indicates the ordering of the (leaf) nodes of the tree. The values of the (non-leaf) nodes of the next level, i.e. the four nodes a(2,1), a(2,2), a(2,3), and a(2,4) of level 2, are obtained by digitally signing, here using a hash function, the concatenation (symbolically represented by the operator "+") of the values of pairs of leaf nodes, i.e. pairs of child nodes of the nodes of the next level in the tree. This grouping of child nodes to obtain the values of the nodes of the next level defines the tree concatenation ordering. For ease of notation, the node symbol a(i,j) is also used to represent the associated value (i.e., the associated digital signature). Here, the tree includes only two intermediate levels above the leaf node level, and the root node at the top. The root node level is actually the last non-leaf node level of the tree. Thus, the values of the four non-leaf nodes at the next intermediate levels are: a(2,1)=H(a(1,1)+a(1,2)), i.e. a(2,1)=H(H(D1)+H(H(D2)) (because a(1,1) and a(1,2) are child nodes of node a(2,1)) a(2,2)=H(a(1,3)+a(1,4)) a(2,3)=H(a(1,5)+a(1,6)) a(2,4)=H(a(1,7)+a(1,8)) For the next penultimate node level (here, level 3), there are two node values: a(3,1)=H(a(2,1)+a(2,2)) a(3,2)=H(a(2,3)+a(2,4))
[0306]
[0306] Note that it is possible to choose a different tree concatenation ordering for each non-leaf node. For example, instead of including a(2,4)=H(a(1,7)+a(1,8)), one can define a(2,4)=H(a(1,8)+a(1,7)), which gives a different value node value.
[0307]
[0307] Finally, the value of the root node R of the tree, or the canonical root digital signature (also called the aggregate digital signature ADS as previously explained), is obtained as R = H(a(3,1) + a(3,2)).
[0308]
[0308] Due to the hierarchical connections of the links in the tree, if any bit of the digital data is changed in a node (especially in a leaf node), it is virtually impossible to extract the root value. Moreover, if some specific elements are included in the batch (the digital data of those elements are known only to the system that generated the digital signatures of the leaf nodes of the tree, i.e., only to the controller C), a forger cannot extract the root digital signature even if he knows the digital data of all the elements of the batch.
[0309]
[0309] According to the invention, the reference root digital signature R, i.e. the aggregate digital signature ADS, of a batch of elements is made unalterable and is therefore preferably made unforgivable by being published in a (public) medium accessible by users who need to check the authenticity of the elements, i.e. the authorization data AD (or related data) of the mission order, or stored in a searchable root database accessible by the controller, or in a preferred mode, stored in a blockchain, or in a blockchain-protected database accessible by the controller. The controller may then store the reference values R obtained from these available sources.
[0310]
[0310] Next, batch element A iFor each element, the verification key VK of the corresponding element in the associated tree i (or a verification path) is computed as the sequence of digital signatures, from the leaf node level to the penultimate node level, of all other leaf nodes with the same parent node in the tree, other than the leaf node corresponding to the element's digital signature, and of all non-leaf nodes with the same parent node in the tree, other than the previous same parent node considered at the preceding level, at each successive next level in the tree.
[0311] According to an embodiment, element A i At least one of them includes a mission command, i.e. authorization data AD, which indicates that a controller A of a device DA has been authorized by a controller C to perform an operation Op using a controller of a device receiving said digital message M, e.g. controller B.
[0312]
[0312] Element A i At least one associated digital data D i preferably includes authorization data AD indicating that controller A of device DA is authorized by controller C to perform operation Op using a controller of a device receiving said digital message M, for example controller B.
[0313]
[0313] As will be explained, the present invention enables a controller C to publish a digital message M in the form of a forgery-proof file that contains: The aforementioned permission data AD i , i.e. element A i Authorization Data AD i , i.e. element A i The verification key VK associated with i
[0314]
[0314] The aforementioned verification key VK i Permission data AD iIn conjunction with this, it is advantageous to be able to retrieve an aggregate digital signature ADS which may for example be stored in the memory of a processing unit CPU of the device DB of the controller B.
[0315] According to an embodiment, element A i For each element of a batch of A i Permission data AD i In fact, multiple digital messages M related to different controllers can be handled. i , and therefore, a controller C issuing different mission commands may use multiple authorization data A.D. i This tree can be created using the following: i Any kind of data can be used as long as it is relevant to the
[0316]
[0316] In the example of FIG. 7, there are eight verification keys VK1, ..., VK8 corresponding to eight elements A1, ..., A8 of the batch, respectively, and eight corresponding leaf nodes a(1,1), ..., a(1,8). (1) For the leaf node a(1,1) = x1 = H(D1) corresponding to element A1, the verification key is VK1 = {a(1,2), a(2,2), a(3,2)}, and the root digital signature value R can be derived from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From leaf node a(1,1)=x1 and leaf node a(1,2)=x2 in VK1 (a(1,2) is the other leaf node having the same parent node, i.e., node a(2,1), other than the leaf node corresponding to element digital signature x1, i.e., node a(1,1)), the parent node value a(2,1) is obtained by a(2,1)=H(a(1,1)+a(1,2)) (i.e., a(2,1)=H(x1+x2)). (b) From the obtained a(2,1) and the next node value in VK1, i.e. a(2,2) at the next non-leaf node level which is a non-leaf node having the same parent node in the tree, i.e. node a(3,1), other than the previous same parent node considered at the preceding level, i.e. node a(2,1), the parent node value a(3,1) is obtained by a(3,1) = H(a(2,1) + a(2,2)). (c) From the obtained a(3,1) and the next node value in VK1, i.e. a(3,2) at the penultimate node level which is a non-leaf node having the same parent node in the tree, i.e. the root node, other than the previous same parent node considered at the preceding level, i.e. node a(3,1), the root node value R is obtained by R=H(a(3,1)+a(3,2)). In this example, there are three steps (a), (b), and (c) because the tree contains three levels below the root node level and therefore the verification key contains three node values. Thus, the value of the root node of the tree can be obtained as R=H(H(H(a(1,1)+a(1,2))+a(2,2))+a(3,2)).
[0317] (2) For the leaf node a(1,2) = x2 = H(D2) corresponding to element A2, the verification key is VK2 = {a(1,1), a(2,2), a(3,2)}, and the root value R can be extracted from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From a(1,2)=x2 and a(1,1)=x1 in VK1 (a(1,1) is the other leaf node having the same parent node, i.e., node a(2,1), other than the leaf node corresponding to element digital signature x2, i.e., node a(1,2)), the parent node value a(2,1) is obtained by a(2,1)=H(a(1,1)+a(1,2)). (b) From the obtained a(2,1) and the next node value in VK2, i.e. a(2,2) at the next non-leaf node level which is a non-leaf node having the same parent node in the tree, i.e. anode(3,1), other than the previous same parent node considered at the preceding level, i.e. node a(2,1), the parent node value a(3,1) is obtained by a(3,1) = H(a(2,1) + a(2,2)). (c) From the obtained a(3,1) and the next node value in VK2, i.e. a(3,2) at the penultimate node level which is a non-leaf node having the same parent node in the tree, i.e. the root node, other than the previous same parent node considered at the preceding level, i.e. node a(3,1), the root node value R is obtained by R=H(a(3,1)+a(3,2)). Therefore, the value of the root node of the tree can be obtained as R=H(H(H(a(1,1)+a(1,2))+a(2,2))+a(3,2)).
[0318] (3) For the leaf node a(1,3) = x3 = H(D3) corresponding to element A3, the verification key is VK3 = {a(1,4), a(2,1), a(3,2)}, and the root value R can be extracted from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From a(1,3) = x3 and a(1,4) = x4 in VK3 (where a(1,4) is the other leaf node having the same parent node, i.e., node a(2,2), other than the leaf node corresponding to the element digital signature x3, i.e., node a(1,3)), the parent node value a(2,2) is obtained by a(2,2) = H(a(1,3) + a(1,4)). (b) From the obtained a(2,2) and the next node value in VK3, i.e. a(2,1) at the next non-leaf node level which is a non-leaf node having the same parent node in the tree, i.e. a(3,1), other than the previous same parent node considered at the preceding level, i.e. node a(2,2), the parent node value a(3,1) is obtained by a(3,1) = H(a(2,1) + a(2,2)). (c) From the obtained a(3,1) and the next node value in VK3, i.e. a(3,2) at the penultimate node level which is a non-leaf node having the same parent node in the tree, i.e. the root node, other than the previous same parent node considered at the preceding level, i.e. node a(3,1), the root node value R is obtained by R=H(a(3,1)+a(3,2)). Therefore, the value of the root node of the tree can be obtained as R=H(H(a(2,1)+H(a(1,3)+a(1,4)))+a(3,2)).
[0319] (4) For the leaf node a(1,4) = x4 = H(D4) corresponding to element A4, the verification key is VK4 = {a(1,3), a(2,1), a(3,2)}, and the root value R can be extracted from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From a(1,4) = x4 and a(1,3) = x3 in VK4, the parent node value a(2,2) is obtained by a(2,2) = H(a(1,3) + a(1,4)). (b) From the obtained a(2,2) and the next node value in VK4, i.e., a(2,1) at the next non-leaf node level, the parent node value a(3,1) is obtained by a(3,1) = H(a(2,1) + a(2,2)). (c) From the obtained a(3,1) and the next node value in VK4, i.e., a(3,2) at the penultimate node level, the root node value R is obtained by R=H(a(3,1)+a(3,2)). Therefore, the value of the root node of the tree can be obtained as R=H(H(a(2,1)+H(a(1,3)+a(1,4)))+a(3,2)).
[0320] (5) For node a(1,5)=x5=H(D5) corresponding to element A5, the verification key is VK5={a(1,6), a(2,4), a(3,1)}, and the root value R can be extracted from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From a(1,5) = x5 and a(1,6) = x6 in VK5, the parent node value a(2,3) is obtained by a(2,3) = H(a(1,5) + a(1,6)). (b) From the obtained a(2,3) and the next node value in VK5, i.e., a(2,4) at the next non-leaf node level, the parent node value a(3,2) is obtained by a(3,2) = H(a(2,3) + a(2,4)). (c) From the obtained a(3,2) and the next node value in VK5, i.e., a(3,1) at the penultimate node level, the root node value R is obtained by R=H(a(3,1)+a(3,2)). Therefore, the value of the root node of the tree can be obtained as R=H(a(3,1)+H(H(a(1,5)+a(1,6))+a(2,4))).
[0321] (6) For node a(1,6) = x6 = H(D6) corresponding to element A6, the verification key is k6 = {a(1,5), a(2,4), a(3,1)}, and the root value R can be extracted from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From a(1,6) = x6 and a(1,5) = x5 in VK6, the parent node value a(2,3) is obtained by a(2,3) = H(a(1,5) + a(1,6)). (b) From the obtained a(2,3) and the next node value in VK6, i.e., a(2,4) at the next non-leaf node level, the parent node value a(3,2) is obtained by a(3,2) = H(a(2,3) + a(2,4)). (c) From the obtained a(3,2) and the next node value in VK6, i.e., a(3,1) at the penultimate node level, the root node value R is obtained by R=H(a(3,1)+a(3,2)). Therefore, the value of the root node of the tree can be obtained as R=H(a(3,1)+H(H(a(1,5)+a(1,6))+a(2,4))).
[0322] (7) For node a(1,7)=x7=H(D7) corresponding to element A7, the verification key is k7={a(1,8),a(2,8),a(3,1)}, and the root value R can be extracted from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From a(1,7) = x7 and a(1,8) = x8 in VK7, the parent node value a(2,4) is obtained by a(2,4) = H(a(1,7) + a(1,8)). (b) From the obtained a(2,4) and the next node value in VK7, i.e., a(2,3) at the next non-leaf node level, the parent node value a(3,2) is obtained by a(3,2) = H(a(2,3) + a(2,4)). (c) From the obtained a(3,2) and the next node value in VK7, i.e., a(3,1) at the penultimate node level, the root node value R is obtained by R=H(a(3,1)+a(3,2)). Therefore, the value of the root node of the tree can be obtained as R=H(a(3,1)+H(a(2,3)+H(a(1,7)+a(1,8)))).
[0323] (8) For node a(1,8) = x8 = H(D8) corresponding to element A8, the verification key is k8 = {a(1,7), a(2,3), a(3,1)}, and the root value R can be extracted from this verification key by the following steps (performed according to the node ordering in the tree and the tree concatenation ordering): (a) From a(1,8) = x8 and a(1,7) = x7 in VK8, the parent node value a(2,4) is obtained by a(2,4) = H(a(1,7) + a(1,8)). (b) From the obtained a(2,4) and the next node value in VK8, i.e., a(2,3) at the next non-leaf node level, the parent node value a(3,2) is obtained by a(3,2) = H(a(2,3) + a(2,4)). (c) From the obtained a(3,2) and the next node value in VK8, i.e., a(3,1) at the penultimate node level, the root node value R is obtained by R=H(a(3,1)+a(3,2)). Therefore, the value of the root node of the tree can be obtained as R=H(a(3,1)+H(a(2,3)+H(a(1,7)+a(1,8)))).
[0324] In general, to derive a (candidate) root node value, i.e., a candidate aggregate digital signature cADS, one can start from a particular leaf node value and a node value specified in the verification key associated with said leaf node, extracting, from the sequence of node values in the verification key VK, node values (i.e., digital signature values) of all other leaf nodes in the tree having the same parent node, other than the node value of the particular leaf node, and calculating digital signatures of the particular node value and the concatenation of the extracted node values of all said other leaf nodes according to the ordering of the nodes in the tree and the tree concatenation ordering, respectively, thus obtaining digital signatures of said same parent nodes of the particular leaf node; At each next level in the tree, successively down to the penultimate node level, extracting from the sequence of node values of the verification key VK, the node values of all other non-leaf nodes of the tree having the same parent node, other than the node value of the previous node of the same parent node considered in the preceding step; and calculating a digital signature of the concatenation of the node values of every other non-leaf node and the obtained digital signature of the previous same parent node according to the ordering of the nodes in the tree and the tree concatenation ordering, thus obtaining the node value of the previous same parent node of the previous same parent node; A step is performed of calculating a digital signature of the concatenation of the obtained node values of the non-leaf nodes corresponding to the penultimate node level of the tree according to the ordering of the nodes in the tree and the tree concatenation ordering, thus obtaining a root digital signature of the root node of the tree.
[0325] As is clear from the above example, the root node value R, also called the aggregate digital signature ADS, can be finally derived from any particular leaf node value by digitally signing the concatenation of this leaf node value with only the node values specified in the corresponding verification key. Therefore, the verification information V required to derive the root node value R is i The amount of data in V is clearly much less than the amount of data required to calculate the reference root node value R (i.e., based only on the leaf node values by calculating all non-leaf node values of the intermediate levels of the tree), which is an advantage of the present invention in view of the limited size constraints available for security markings (such as 2D barcodes). According to an embodiment, this verification information V i is digital data D i , i.e., authorization data AD, i.e., mission command data, and the corresponding verification key VK i Includes (V i =(D i ,V.K. i )).
[0326] According to the present invention, a particular element A of a batch of elements i The digital message M corresponding to this verification information V is stored in a memory 1000 MHz to a level that is compatible with the data content of a two-dimensional machine-readable barcode that can be easily read by a conventional reading device, such as by an optical reader module OR. i While maintaining the bit size of the digital representation of i and element A to a particular batch of genuine elements i By providing a unique, unalterable, forgery-proof link between the affiliation of the aforementioned specific element A i Verification information V enabling both online and offline checks of the authenticity of the digital message M, of the suitability of the relevant data with respect to the suitability of the authorization data AD contained in i Includes.
[0327]
[0320] These check operations are performed on the element digital data D i, i.e., the authorization data AD and the corresponding verification key VK i First, read the element digital data D in a machine-readable form, for example, a QR code QRC(A), and then use a one-way function to convert the read element digital data D i Candidate for Digital Signature cx i CX i =H(D i ) and calculate the verification key VK as described above. i According to the sequence of node values shown in i and deriving a canonical root digital signature R, i.e., aggregate digital signature ADS, of the tree associated with the batch, by computing a candidate root digital signature cR, also called candidate aggregate digital signature cADS, from the digital signature of the concatenation of the node values of the tree. This protection scheme, which has the advantage of not requiring encryption of the data, and thus management of encryption / decryption keys (in particular, the encryption keys are not included in the security marking), is much more robust against cryptanalysis attacks compared to conventional encryption of data using a public encryption key and a private decryption key (such as, for example, the RSA "Rivest-Shamir-Adleman" system).
[0328]
[0321] As a result, the size of the digital data represented in the security marking according to the invention is compact, making it possible to use conventional 2D barcodes (e.g. QR codes) and thus conventional barcode reading devices (or simply programmed smartphones including a camera) while providing a very high level of robustness against cryptanalysis attacks. Moreover, this machine-readable form is compatible with both online (via a server communicating with the code reading device) and offline (via a programmed code reading device) checks of the suitability of the data regarding the authenticity of the digital message M and the suitability of the authorization data AD. Also according to the invention, the representation of the digital data Di and the key data VK iThe representation of may differ and the data concatenation scheme and / or one-way function may depend on the node level of the tree, thereby providing an additional level of robustness with respect to cryptanalysis attacks.
[0329]
[0322] To further reduce the size of the digital data contained in machine-readable form (i.e., the verification information V), each original element A of the batch is i Element Digital Data D i are distributed among certain fields that are common to all elements of the batch, the digital data related to these fields is i are not included in the elements, but are clustered into separate fields data blocks FDBs associated with batches of elements, Next, a one-way function H of the concatenation of the corresponding digital data Di and the digital data of the field data block FDB, i.e., xi = H(D i +FDB) to batch element A. i A digital signature xi of is calculated, Preferably, the reference root digital signature R, ie the aggregate digital signature ADS, together with the associated field data blocks FDB (which also renders the field data blocks unalterable) is made available to the controller.
[0330]
[0323] In a variant of the invention, the field data block FDB is made accessible by the controller independently of the reference root digital signature, ie the aggregate digital signature ADS.
[0331]
[0324] There are many known methods for encoding information in a manner that may, for example, be printed on a document, applied to a physical surface, or displayed by a display module DD. Any such method may be used in the implementation of any embodiment of the present invention. One common form of optical machine-readable format is the well-known QR code, as previously described.
[0332]
[0325] As is well known, for a given area, the more data a QR code can encode, the higher the module density it contains (roughly the density of black / white "squares"), and the greater the resolution it requires to print and read. In addition to density (number of modules within a square), QR codes are also roughly classified according to the level of error correction they contain. Currently, four different standard "levels", L, M, Q, and H, respectively, represent the degree of "damage", i.e. data loss, that a QR code image can withstand and recover from. Levels L, M, Q, and H can withstand approximately 7%, 15%, 25%, and 30% damage, respectively.
[0333]
[0326] The following table shows at least approximate values for the different QR code versions: [Table 1]
[0334] However, because some modules are used for scan targets, mask patterns, and error correction modules, not all bits may be used to encode the data "load". Thus, the amount of information that a QR code can encode and the verification information V i There is a trade-off between the amount of information that must be encoded in the
[0335]
[0328] Therefore, for a selected type of optical machine-readable form, such as a QR code, which has a limited encoding capacity, a suitable one-way function H should also be selected. A function with an output that is too large in relation to the required bits may not be usable at all, and a function with a range that is too small may not be secure enough. Furthermore, in many applications, scalability may be an issue. For example, some data security schemes involve signatures that grow as the number of members of a batch increases, which may unacceptably limit the size of the batch in terms of the number of bits that the optical machine-readable form can encode. Therefore, according to a preferred embodiment of the invention, the type of function selected is a one-way hash function of the SHA-2 family.
[0336]
[0329] A calculation module is preferably provided and controlled by the controller C for executing code provided for performing calculations to digitally sign the digital data D of the elements of the batch, for determining verification keys for the different elements and for calculating the reference root digital signature of the corresponding tree.
[0337]
[0330] According to an embodiment, the processing unit of the device controlled by the controller is configured to execute code provided for performing calculations to digitally sign element digital data of the elements of the batch, for determining verification keys for the different elements and for calculating the reference root digital signature of the corresponding tree.
[0338]
[0331] Controller C is a specific element (or elements) A s Digital data D s For example, the batch of elements may include one element containing authorization data AD, and a number of specific elements, to enable the processing unit of the controller C device to execute the invention and to issue said digital message based on said tree.
[0339] For example, wherever an element is created, the raw element data D is sent from that site (or multiple sites) to a controller C via a network. i In order to avoid having to transmit the hash of the element if that is an issue, it is possible to perform the hash calculation associated with the element externally (e.g., on a remote connected server).
[0340]
[0333] For example, mission orders, i.e. authorization data AD i Element A such as i For each, the corresponding validation information V i are compiled and encoded (represented) in some form, e.g., optical machine-readable, and then printed or physically applied or digitally displayed or otherwise associated with each digital message M or document or digital document. For example, at least the verification information V i A digital message M containing M may be encoded in an optically or magnetically readable label, RFID tag, or the like that is attached to a mission order or official digital document, or printed directly on the document.
[0341] Any particular element A s With respect to s =(D s ,k s ) inside element A s The verification information may generally be associated with any element A of a batch of elements. i With respect to the corresponding digital data D i and the corresponding verification key VK i , i.e. V i =(D i ,V.K. i As mentioned above, the digital data D i may contain details of the mission order.
[0342]
[0335] Additional element data may be further associated with the element, including, for example, a batch value, i.e., the reference root digital signature R, or any other information the controller C chooses to include, such as the public key PuK of the particular controller, a time slot for performing the operation Op, an item serial number, a batch ID, date / time information, product name, a URL pointing to something else, online information associated with either the particular controller (such as an image of the controller or of the controller's label) or batch or supplier / manufacturer, a phone number that can be called for verification, etc. The additional element data may be stored in a searchable information database accessible by the controller (via an information database interface).
[0343]
[0336] Element A i Verification key VK i is calculated and the corresponding element digital data D i and once included in a corresponding optical machine-readable form in the digital message M (i.e., included by encoding or any chosen data representation), the resulting digital message M and associated data are effectively protected against forgery and alteration.
[0344]
[0337] The controller, which is the recipient of the digital message M in the form of a QR code, associated with the element A1, may then use the optical reader module OR of the device to scan (or otherwise read) the optical machine-readable form of the digital message M and extract the element digital data D1 and the verification key VK1 (and any other information that may be encoded in the optical machine-readable form as previously explained). For the verification of the digital message M, and therefore of the element A1, the controller must first retrieve the verification information V1 = (D1, VK1) from said QR code and thus calculate the digital signature x1 from the element digital data D1 extracted; to do this, the controller or at least its device must know the one-way function used to calculate the element digital signatures, here the one-way function H() (for example a SHA-256 hash), and then perform the operation x1 = H(D1) to obtain the complete data (x1, VK1) necessary to calculate the corresponding candidate root digital signature cR, i.e. the corresponding candidate aggregate digital signature cADS. The controller may, for example, receive the one-way function securely (e.g., using a private / public key pair), or by requesting the one-way function from the element provider, or from whatever entity created the signature and key, or by having the one-way function already programmed in the processing unit CPU of the controller's device, for example the device DB described above.
[0345]
[0338] Then, to calculate such a candidate root digital signature cR, the controller may further need to know the type of data concatenation scheme (for concatenating the node values by H(a(i,j)+a(i,k)) used for the calculation, and the controller may receive this information in any known manner, securely (for example, using a public / private key pair), or simply by requesting this information from the element provider or from whatever entity created the verification data, i.e., the controller C, or by having this information already programmed in the processing unit CPU of the controller. However, the concatenation scheme may in fact correspond to just a conventional join between the ends of two digital data blocks corresponding respectively to the two node values, in which case no specific scheme has to be transmitted to the controller. In some variants, the concatenation scheme may further insert a concatenation block that can contain data specific to the rank or level of the concatenated digital data blocks in the tree, thus making cryptanalysis attacks even more difficult.
[0346]
[0339] The controller, knowing the concatenation scheme, can then compute (e.g., by a suitably programmed device) a candidate root digital signature cR, i.e., a candidate aggregate digital signature cADS, by digitally signing stepwise the concatenation of element digital signatures x1 and node values according to the sequence of nodes specified by the verification key VK1 associated with node a(1,1) (see item 1 above), performed according to the node ordering in the tree and the tree concatenation ordering, as described above, for example. Here, the candidate root digital signature cR is obtained as cR = H(H(H(a(1,1) + a(1,2)) + a(2,2)) + a(3,2)) (the node ordering in the tree is given by the respective indices (i,j) of the levels and ranks within the levels).
[0347]
[0340] This calculated candidate root digital signature cR should then be equal to the available (or published) reference R value, which may have been obtained beforehand by the controller and / or may already be stored in the memory of the processing unit CPU of said controller's device, or it may also be a value that the controller requests and receives from the controller C in any known manner. If the candidate cR, i.e. cADS, and the available reference root digital signature R, i.e. ADS, match, this calculation verifies the information in the digital message M and confirms that the mission command A1 has been issued by the controller C.
[0348]
[0341] A link for accessing the reference root digital signature R of the batch corresponding to element A1 may be included in the digital mark DM (eg a web address if R can be retrieved at a corresponding website).
[0349] In some implementations, the recipient of a digital message M receives verification information V i may be able to be extracted “visually” directly from the digital message M. For example, the verification information V i may be text such as a serial number, or text in the descriptive text, or somewhere else on the element, some alphanumeric encoding that is human readable from the element itself, or something attached to or contained in the element.
[0350]
[0343] The recipient of the digital message M is asked to enter the data or to optically read the data via a smartphone camera, and then x i =H(D iIt is also possible that suitable software is provided, such as an optical reader module in a device such as a smartphone, which calculates x1 and cR. For example, using an optical machine readable form contained in the digital message M, a standard QR code, associated with the authorization data AD1, the controller can simply obtain the digital data D1 and VK1 with the optical reader module OR by scanning the QR code using a standard QR code reader application running on the device, and then a verification application in the controller's device can calculate x1 and cR and compare this value with an available reference batch value R, as explained above.
[0351]
[0344] The reference route digital signature R, i.e. ADS, is preferably stored in a searchable route database that can be accessed (via a communication link) by the controller using a device equipped with a communication module CM. A controller that needs to verify a digital message M can simply use its smartphone to send a route request to an address in the database via the access interface of the database, which request contains the digital message M (or the calculated digital signature x ) that allows to retrieve the corresponding reference batch value R. i =H(D i The database includes the verification information V1 read in an optical machine-readable form of the reference root digital signature R, and the access interface returns the reference root digital signature R to the smartphone. The database may be secured by a blockchain to enforce the immutability of the stored root digital signature.
[0352]
[0345] According to an embodiment, the content of a digital message M is protected using a method for protecting against counterfeiting or alteration of a particular element comprising said content of said digital message M, said particular element belonging to a batch of a plurality of elements, each element comprising its own associated element data and corresponding element digital data, the method being characterised in that it comprises the following steps: for each element of the batch, calculating an associated element digital signature of the corresponding element digital data by a one-way function; forming a tree based on the plurality of calculated element digital signatures of the original elements of the batch, the tree including nodes arranged according to a particular node ordering in the tree, said tree including node levels from leaf nodes corresponding respectively to the plurality of element digital signatures associated with the plurality of original elements in the batch up to a root node of the tree, every non-leaf node of the tree corresponding to a digital signature using a one-way function of the concatenation of each of the digital signatures of its child nodes according to the tree concatenation ordering, and the root node corresponding to a reference root digital signature, i.e. a digital signature using a one-way function of the concatenation of the digital signatures of the nodes at the penultimate node level in the tree according to said tree concatenation ordering; associating with the particular element a corresponding verification key, which is a sequence of each digital signature of all other leaf nodes having the same parent node in the tree, other than the leaf node corresponding to the element digital signature of the particular element, and of all non-leaf nodes having the same parent node in the tree, other than the previous same parent node considered at the preceding level, at each successively next level in the tree, from the leaf node level to the penultimate node level; making the reference root digital signature of the tree available to the controller; and applying to the particular document, preferably an optical machine-readable form encoding said digital message M and thus containing a representation of said digital data and a corresponding verification key, when said digital message M is to be printed; Thus, a marked document is obtained, preferably including said printed digital message M, the content of which is protected against forgery or alteration.
[0353]
[0346] According to an embodiment, the reference root digital signature of the root node of the tree is preferably published to a medium accessible by the controller, or stored in a searchable root database accessible by the controller, or stored on a blockchain, or stored in a blockchain-protected database accessible by the controller.
[0354]
[0347] According to an embodiment, the digital message M may further include root node access data printed or encoded and containing sufficient information to enable the controller to access the reference root digital signature of the root node of the tree corresponding to the batch of elements, said information being a link to an access interface operable to receive a root request from the controller, obtained from the digital message M containing the digital data or a digital signature of the digital data, or from another printed optical machine-readable form, and to return the reference root digital signature of the corresponding tree, the access interface each enabling access to one of the following: the medium on which the reference root digital signature is published; a searchable root database in which canonical root digital signatures are stored; and A blockchain, or a database secured by a blockchain, in which time-stamped reference root digital signatures are stored.
[0355]
[0348] According to an embodiment, the additional digital data corresponding to the digital data associated with the digital message M is stored in a searchable information database accessible by the controller via an information database interface operable to receive information requests from the controller, including the digital data or a digital signature of the digital data, obtained from the digital message M or from another printed optical machine-readable form, and to return the corresponding additional digital data.
[0356]
[0349] Thus, the present invention enables a recipient to verify the validity of particular digital content with a high degree of certainty.
Claims
1. 1. A method for validation of the digital content of a digital message M received by a device DB controlled by a controller B via a communication network CN, comprising: a device DA controlled by a controller A, comprising a processing unit CPU(A) having a memory storing said digital message M, and a communication module CM(A) adapted to send and receive data via said communication network CN, the device DB comprises a processing unit CPU(B) having a memory storing an aggregate digital signature ADS, and a communication module CM(B) configured to send and receive data via the communication network CN, the aggregate digital signature ADS being calculated by applying a one-way accumulator to a plurality of digital signatures, the plurality of digital signatures including a digital signature x(A) of authorization data AD(A) calculated by a one-way function; the digital message M includes the authorization data AD(A) indicating that the controller A of the device DA is authorized by a controller C to perform an operation Op using a controller of a device receiving the digital message M, the digital message M also includes a verification key VK(A) attributed to the controller C, the verification key VK(A) together with the authorization data AD(A) being used to calculate a candidate aggregate digital signature cADS, and the processing unit CPU(B) is configured to compare the candidate aggregate digital signature cADS with the aggregate digital signature ADS stored in the memory of the processing unit CPU(B) in the device DB, The method comprises: said communication module CM(B) of said device DB receiving (100b, 200) said digital message M; The processing unit CPU (B) of the device DB extracts (201) the authorization data AD (A) contained in the digital message M; said communication module CM(B) of said device DB receiving (400) an authorized SA from said communication module CM(A) of said device DA; The processing unit CPU (B) of the device DB verifies (400b) the certified SA; The processing unit CPU(B) of the device DB extracting (204) the verification key VK(A) contained in the digital message M; Calculating (203) a candidate digital signature cx(A) of the authorization data AD(A) by means of the one-way function programmed in the processing unit CPU(B), calculating (205) the candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A), the processing unit CPU(B) of the device DB checks (207) whether the aggregate digital signature ADS stored in a memory (206) matches the candidate aggregate digital signature cADS, and only in case of a positive verification of the certified SA and a positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) of the device DB sends (500) to the controller B via the communication module CM(B) an indication that the controller A is indeed authorized by the controller C to perform (500a) the operation Op, method.
2. the memory of the processing unit CPU(A) of the device DA stores a private key PrK(A), and the processing unit CPU(A) is configured to sign data using the private key PrK(A), the processing unit CPU(B) of the device DB is configured to verify data signed by the communication module CM(B) using a corresponding public key, the digital message M further includes a public key PuK(A) corresponding to the private key PrK(A) and certified by the controller C as being owned by the controller A; the certified SA is certified data signed using the private key PrK(A), Before the step of verifying the certified SA by the processing unit CPU(B) of the device DB (400b), the processing unit CPU(B) of the device DB extracts the public key PuK(A) from the digital message M (202); said step of verifying (400b) said certified SA comprises said verifying of said certified SA by said processing unit CPU(B) of said device DB using said public key PuK(A); The method of claim 1.
3. the communication network CN includes a short-range wireless communication network NFCN, the communication module CM(A) is configured to send and receive data via the short-range wireless communication network NFCN, the communication module CM(B) is configured to send and receive data via the short-range wireless communication network NFCN, and the short-range wireless communication network NFCN enables communication between the communication module CM(A) and the communication module CM(B) when the distance between the communication module CM(A) and the communication module CM(B) is less than 50 cm; The method of claim 1.
4. the device DA comprises a display module DD(A) and an optical reader module OR(A), the device DB comprises a display module DD(B) and an optical reader module OR(B), the step of receiving the digital message M by the communication module CM(B) of the device DB comprises a step of reading, by the optical reader module OR(B), an optically readable representation of a graphical data block GDB displayed by the display module DD(A), the graphical data block GDB comprises a digital mark DM, the digital mark DM comprising an encoded version EAD(A) of the authorization data AD(A) and an encoded version EVK(A) of the verification key VK(A), the extraction of the authorization data AD(A) comprises decoding the encoded authorization data EAD(A), and the extraction of the verification key VK(A) comprises decoding the encoded verification key EVK(A). The method of claim 1.
5. the optically readable representation of the graphical data block GDB comprises a digital representation of a graphical symbol from a specific finite set of graphical symbols, the digital representation of the graphical symbol being configured to encode the digital mark DM and a machine-readable error correction data block. The method of claim 4.
6. the memory of the device DB stores a private key Prk(B) and a corresponding public key PuK(B) certified by a controller C as being owned by the controller B, the processing unit CPU(B) of the device DB is configured to sign data using the private key PrK(B), and the processing unit CPU(A) of the device DA is configured to verify data signed by the communication module CM(A) using the corresponding public key, The method of claim 1.
7. and, before the step of receiving (400) the certified SA from the communication module CM(A) by the communication module CM(B), a step of transmitting (300) a secret generated by the device DB from the communication module CM(B) to the communication module CM(A), wherein the secret is configured to generate the certified SA. The method of claim 1.
8. The method includes, before the step of receiving (400) the certified SA from the communication module CM(A) by the communication module CM(B), a step of transmitting (300) a secret generated by the device DB from the communication module CM(B) to the communication module CM(A), wherein the secret is configured to generate the certified SA. The method of claim 2.
9. The secret is configured to be signed (300a) by the processing unit CPU(A) using the private key PrK(A) to generate the certified SA. The method of claim 8.
10. wherein said step of transmitting (300) said secret comprises a step of displaying by a display module DD(B) of said device DB an optically readable representation of a graphical element encoding said secret and configured to be read by an optical reader module OR(A) of said device DA, The method of claim 7.
11. Before or after receiving the digital message M, the controller B receives a digital document, the certified SA including a signature of the content of the digital document, the signature being generated by the processing unit CPU(A) by signing the content using a private key PrK(A) stored in the memory of the processing unit CPU(A); The method of claim 1.
12. the digital message M is authenticated by the controller C (10), and the method comprises, before the step of extracting (201) by a processing unit CPU(B) of the device DB the authorization data AD(A) contained in the digital message M, a step of verifying (10b) by the processing unit CPU(B) that the digital message M has been authenticated by the controller C, and only in the case of a positive verification that the digital message M has been authenticated by the controller C (10), the processing unit CPU(B) of the device DB extracts (201) the authorization data AD(A) contained in the digital message M, The method according to any one of claims 1 to 2.
13. A system for validation of the digital content of a digital message M received by a device DB controlled by a controller B via a communication network CN, said system comprising: a device DA controlled by a controller A comprising a processing unit CPU(A) having a memory storing said digital message M, and a communication module CM(A) adapted to send and receive data via said communication network CN, the device DB comprises a processing unit CPU(B) having a memory storing an aggregate digital signature ADS, and a communication module CM(B) configured to send and receive data via the communication network CN, the aggregate digital signature ADS being calculated by applying a one-way accumulator to a plurality of digital signatures, the plurality of digital signatures including a digital signature x(A) of authorization data AD(A) calculated by a one-way function; the digital message M includes the authorization data AD(A) indicating that the controller A of the device DA is authorized by a controller C to perform an operation Op using a controller of a device receiving the digital message M, the digital message M also includes a verification key VK(A) attributed to the controller C, the verification key VK(A) together with the authorization data AD(A) being used to calculate a candidate aggregate digital signature cADS, and the processing unit CPU(B) is configured to compare the candidate aggregate digital signature cADS with the aggregate digital signature ADS stored in the memory of the processing unit CPU(B) in the device DB; the communication module CM(B) of the device DB is configured to receive (100b, 200) the digital message M, the processing unit CPU (B) of the device DB is configured to extract (201) the authorization data AD (A) contained in the digital message M, the communication module CM(B) of the device DB is configured to receive (400) an authorized SA from the communication module CM(A) of the device DA, The processing unit CPU (B) of the device DB is configured to verify (400b) the certified SA; The processing unit CPU(B) of the device DB extracting (204) the verification key VK(A) contained in the digital message M; calculating (203) a candidate digital signature cx(A) of said authorization data AD(A) by said one-way function programmed in said processing unit CPU(B); calculating (205) the candidate aggregate digital signature cADS from the verification key VK(A) and the calculated candidate digital signature cx(A) of the authorization data AD(A), the processing unit CPU(B) of the device DB is configured to check (207) whether the aggregate digital signature ADS stored in a memory (206) matches the candidate aggregate digital signature cADS, and only in case of a positive verification of the certified SA and a positive match of the candidate aggregate digital signature cADS with the aggregate digital signature ADS, the processing unit CPU(B) of the device DB is configured to send (500) to the controller B via the communication module CM(B) an indication that the controller A is indeed authorized by the controller C to perform (500a) the operation Op; system.
14. the memory of the processing unit CPU(A) of the device DA is configured to store a private key PrK(A), and the processing unit CPU(A) is configured to sign data using the private key PrK(A); the processing unit CPU(B) of the device DB is configured to verify data signed by the communication module CM(B) using a corresponding public key, the digital message M further includes a public key PuK(A) corresponding to the private key PrK(A) and certified by the controller C as being owned by the controller A; the certified SA is certified data signed using the private key PrK(A), the processing unit CPU(B) of the device DB is configured to extract (202) the public key PuK(A) from the digital message M, The processing unit CPU(B) of the device DB is configured to verify (400b) the certified SA using the public key PuK(A); The system of claim 13.
15. The device DA comprises a display module DD(A) and an optical reader module OR(A), the device DB comprises a display module DD(B) and an optical reader module OR(B), the display module DD(A) of the device DA is configured to display an optically readable representation of a graphical data block GDB, the optical reader module OR(B) of the device DB is configured to read the optically readable representation of the graphical data block GDB, and the graphical data block GDB is digitally a digital mark DM, the digital mark DM including an encoded version EAD(A) of the authorization data AD(A) and an encoded version EVK(A) of the verification key VK(A), the processing unit CPU(B) of the device DB being configured to extract the authorization data AD(A) by decoding the encoded authorization data EAD(A), and the processing unit CPU(B) of the device DB being configured to extract the verification key VK(A) by decoding the encoded verification key EVK(A). A system according to any one of claims 13 to 14.
16. Use of the system for validation of the digital content of a digital message M according to claim 13 for validating the execution of an operation Op by a device DB, said operation Op being executed by a device DA, The device DB is provided in and controlled by a storage room B, the device DA is provided in and controlled by a robot A, and the operation Op relates to the robot A picking up a specific product placed inside the storage room B, or the device DB is provided on and controlled by a computer B, the device DA is provided on and controlled by a smartphone A, and the operation Op involves the smartphone A sending a set of data SeD(A) to the computer B, or The device DB is provided on and controlled by a medical device B, the device DA is provided on and controlled by a nurse A, and the operation Op is related to the nurse A injecting a specific drug into a specific patient using the medical device B, or The device DB is provided to and controlled by a citizen B, the device DA is provided to and controlled by a police officer A, and the operation Op involves the police officer A entering the home of the citizen B to search for evidence; or The device DB is provided to and controlled by a citizen B, the device DA is provided to and controlled by a public official A, and the operation Op relates to the public official A issuing and signing an official digital document; Use of said system.