Methods, devices and system for transmitting and acquiring an item of data
The method addresses the insecurity and unreliability of existing data transmission methods by establishing a secure wireless communication channel and using encryption and authentication signatures to ensure the integrity and authenticity of data transmitted between user and receiver devices.
Patent Information
- Application Number
- PCT/EP2024/083186
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-22
- Filing Date
- 2024-11-21
- Publication Date
- 2025-05-30
AI Technical Summary
Existing data transmission methods lack security and reliability, particularly when transmitting personal or confidential data, as they do not adequately prevent interception by malicious third parties and cannot guarantee the integrity and authenticity of the data.
A method involving a user device and a receiver device that establishes a wireless communication channel, obtains and verifies information identifying required data, and securely transmits data using encryption and authentication signatures, ensuring the data's integrity and authenticity.
The method ensures secure and reliable data transmission by preventing unauthorized access and verifying the authenticity of the data, thus protecting sensitive information during transfer.
Smart Images

Figure EP2024083186_30052025_PF_FP_ABST
Abstract
Description
[0001] Title of the invention: Methods, devices and system for transmitting and acquiring data
[0002] The present invention relates to a secure and reliable manner of carrying out a transmission of one or more data from a user device to a receiver device and a reception by the receiver device of the data transmitted by the user device. In particular, the invention relates to a method of transmitting data from a user device to a receiver device implemented in a user device, a method of receiving data by a receiver device from a user device, implemented in a receiver device, the associated user device and the receiver device as well as the system comprising the user device and the receiver device. The transmission of data from a user device to a receiver device is critical, especially when the data is personal or confidential data, for several reasons.First, it is necessary that this data cannot be acquired during the transfer by a third party, especially a malicious third party. In addition, the receiving device must be certain of the veracity of the received data.
[0003] This is particularly the case, for example, when the data is personal data such as a dematerialized identity card and the receiving device is a device capable of verifying the identity of a person carrying a user device storing the digital identity.
[0004] The aim of the invention is to enable the transmission of data in a reliable and secure manner and to guarantee to the receiving device that the data received is not corrupted and is the true data stored in the user device.
[0005] This object is achieved by a method for transmitting data from a user device to a receiver device, the user device having data capable of being transmitted. The method implemented in the user device comprises the following steps: establishing a wireless communication channel between the user device and the receiver device; sending from the user device to the receiver device via the wireless communication channel, a command to obtain information identifying data required by the receiver device and obtaining by the user device the information identifying required data; and sending from the user device to the receiver device via the wireless communication channel, a command comprising the data capable of being transmitted corresponding to the information identifying required data in order to transmit the data capable of being transmitted to the receiver device.
[0006] The information identifying a required data item obtained may be signed, the method then further comprising a step of verifying the signature of the information identifying a required data item obtained signed.
[0007] Prior to sending the command comprising the data capable of being transmitted, the method may comprise a step of encrypting the data capable of being transmitted.
[0008] The user device can further obtain a key attestation from the receiving device.
[0009] The receiving device's key attestation may include a public signature cryptographic key of the receiving device.
[0010] The method may further comprise: a step of generating a first random number; a step of sending from the user device to the receiver device, a command comprising the first random number and obtaining by the user device an authentication signature of the receiver device; a step of verifying the authentication signature of the receiver device obtained by means of the public signature cryptographic key of the receiver device obtained and the first random number. The verification of the signature of the information identifying a required data obtained may be carried out by means of the public signature cryptographic key of the receiver device obtained.
[0011] The receiving device's key attestation may include a public encryption cryptographic key of the receiving device.
[0012] The step of encrypting the data capable of being transmitted can be carried out using the public encryption cryptographic key obtained from the receiving device.
[0013] The information identifying an obtained required data may be encrypted, and the method may then comprise a step of decrypting the information identifying an obtained required data.
[0014] Prior to sending the data capable of being transmitted, the method may comprise a step of signing the data capable of being transmitted.
[0015] The user device may include a cryptographic signature key pair including a private signature cryptographic key and a public signature cryptographic key, the method may then further include sending from the user device to the receiving device a command including a key attestation of the user device, the key attestation of the user device including the public signature cryptographic key of the user device.
[0016] The user device can further obtain from the receiving device a second random number. The method can then comprise a step of generating an authentication signature of the user device to be transmitted, the authentication signature being generated from the second random number obtained and the private signature cryptographic key of the user device; and sending from the user device (102) to the receiving device (104) a command comprising the generated authentication signature of the user device to be transmitted.
[0017] Decryption of the information identifying a requested data obtained may be performed using a private encryption cryptographic key of the user device.
[0018] The signature of the data capable of being transmitted can be signed using the private signature cryptographic key of the user device.
[0019] The method may further comprise the following steps: sending from the user device to the receiving device, at least one identifier of a cryptographic algorithm supported by the user device and obtaining at least one identifier of a cryptographic algorithm supported by the receiving device; determining a cryptographic algorithm supported by the user device and the receiving device and encrypting the data capable of being transmitted corresponding to the information identifying a required data item obtained using the determined cryptographic algorithm.
[0020] The step of sending from the user device to the receiving device a command comprising the data capable of being transmitted corresponding to the information identifying a required data item may be preceded by a step of obtaining agreement by the user of the user device for sending the data capable of being transmitted.
[0021] The wireless communication channel can be a communication channel compliant with the NFC standard, the Bluetooth standard, or the WiFi standard.
[0022] The aim is also achieved by a method of receiving data by a receiving device from a user device, implemented in the receiving device, the receiving device comprising information identifying data required by the receiving device.The method implemented in the receiver device comprises the following steps: establishing a wireless communication channel between the user device and the receiver device; receiving via the wireless communication channel, a command from the user device, to obtain information identifying data required by the receiver device and responding by providing the information identifying data required by the receiver device; and receiving via the wireless communication channel, a command from the user device, comprising transmitted data corresponding to the information identifying data required by the receiver device.
[0023] Prior to providing the information identifying data required by the receiving device, the method may further comprise a step of encrypting the information identifying data required by the receiving device.
[0024] The transmitted data received may be signed, the method may then further comprise a step of verifying the signature of the transmitted data received.
[0025] The receiving device may further receive a key attestation from the user device.
[0026] The user device key attestation may include a public signing cryptographic key of the user device.
[0027] The method may further comprise: a step of generating a second random number, a step of making the second random number available to the user device, a step of receiving an authentication signature from the user device, a step of verifying the authentication signature of the user device received using the public signature cryptographic key of the user device obtained and the second random number.
[0028] Verification of the signature of the received transmitted data can be carried out using the obtained public signature cryptographic key of the user device.
[0029] The key attestation of the user device may comprise a public encryption cryptographic key of the user device. The step of encrypting the information identifying a data item required by the receiving device may be performed using the public encryption cryptographic key of the user device.
[0030] The received transmitted data may be encrypted, and the method may then comprise a step of decrypting the received transmitted data.
[0031] The method may further comprise a step of signing the information identifying data required by the receiving device.
[0032] The receiving device may include a cryptographic signature key pair including a private cryptographic signature key and a public cryptographic signature key. The method may then further include providing from the receiving device to the user device a key attestation of the receiving device, the key attestation of the receiving device including the public cryptographic signature key of the receiving device.
[0033] The receiving device may further receive a first random number from the user device. The method may then comprise a step of generating an authentication signature of the receiving device to be made available to the user device, the authentication signature being generated from the first random number received and the private signature cryptographic key of the receiving device; and making the authentication signature of the receiving device to be transmitted generated by the receiving device to the user device.
[0034] Decryption of the transmitted data can be carried out using a private cryptographic encryption key of the receiving device.
[0035] The information identifying a requested data obtained can be signed using the private signature cryptographic key of the receiving device.
[0036] The method may further comprise the following steps: receiving from the user device at least one cryptographic algorithm identifier supported by the user device and responding by providing at least one cryptographic algorithm identifier supported by the receiving device; determining a cryptographic algorithm supported by the user device and the receiving device and decrypting the transmitted data corresponding to the information identifying a data item required by the receiving device using the determined cryptographic algorithm. The wireless communication channel may be a communication channel compliant with the NFC standard, the Bluetooth standard or the WiFi standard.
[0037] The invention also relates to a device configured to implement one of the methods described above.
[0038] The invention also relates to a system comprising a user device and a receiver device, the user device and the receiver device respectively implementing the methods described above.
[0039] We will now describe examples of embodiments of the present invention with reference to the appended figures where the same references designate identical or functionally similar elements from one figure to another:
[0040] FIG. 1 is a block diagram of an exemplary system in accordance with the invention. FIG. 2 illustrates an embodiment of the method of transmitting data implemented in the user device and of the method of receiving data implemented in the receiver device in accordance with the invention.
[0041] According to the present invention, the user device has data that it wishes to transmit to a receiving device which wishes to obtain the information from the user device, in particular via a communication channel, for example a short distance one.
[0042] The present invention relates in a first aspect to a secure and reliable manner of transmitting data from a user device to a receiving device, the user device having data capable of being transmitted.
[0043] The present invention relates according to a second aspect to a secure and reliable manner of receiving data between a user device and a receiving device, the receiving device having information identifying data required by the receiving device in order to obtain data from the user device corresponding to the information identifying data required by the receiving device.
[0044] Figure 1 is a block diagram of an example system 100 allowing transmission of one or more data between two devices in a secure and reliable manner while ensuring the veracity of the transmitted information. For example, the system 100 may be a system comprising two different computing devices, including a user device 102 and a receiver device 104. These computing devices can communicate with each other via a wireless communication channel 106. The communication channel is for example compliant with a short-distance communication protocol (for example, a connection compliant with the NFC standard, a connection compliant with the Wi-Fi standard, a connection compliant with the Bluetooth standard, etc.). The communication channel will allow data to be transmitted and obtained from one device to the other device.
[0045] The user device 102 may be a mobile device, such as a laptop, smartphone, tablet, or wearable device. Wearable devices may include smartwatches or any other type of portable computing device. In some implementations, the user device 102 may be a desktop computer or another type of non-portable device, such as a kiosk.
[0046] The user device 102 comprises a hardware and software platform on which software executes, this software being either directly executable or interpreted on a virtual machine.
[0047] The user device comprises a display device 106, a processing unit 108, such as a processor, capable of executing instructions and a storage memory 110. The display device 106 comprises in particular a human-machine communication interface for displaying data and receiving data from the user. This human-machine communication interface comprises for example a screen and a keyboard, or a touch screen.
[0048] The processing unit 108 is capable of executing an operating system which may be, for example, any type of operating system on the market. The processing unit 108 may comprise means for executing at least one cryptographic algorithm.
[0049] The storage memory 110 is capable of storing user data, in particular confidential data or personal data of the user. The storage memory 110 may include in particular a secure memory for storing the confidential or personal data of the user. The storage memory, in particular the secure memory, may further be used to store cryptographic keys.
[0050] User data includes, for example, payment, digital identity, show ticketing or transport data.
[0051] The storage memory 110 can further store applications capable of being executed by the processing unit 108 of the user device 102.
[0052] The user device 102 may further comprise communication means 112 capable of communicating with another device, for example a receiver device 104. The communication means 112 comprise in particular a function for establishing a secure communication channel, allowing the creation of a secure channel 122 between the user device 102 and a receiver device 104. The communication means 112 allow network-type connectivity, either via a wired connection or via a wireless connection (for example, compliant with the Bluetooth standard, the NFC standard, the WIFI standard (for example, Wi-Di (or Wi-Fi Direct)) or the PC / SC standard). The communication means 112 comprise in particular a module allowing communication based on a proximity connection.
[0053] The receiving device 104 may be a mobile device, such as a laptop, smartphone, tablet, or wearable device. Wearable devices may include smartwatches or any other type of portable computing device. In some implementations, the receiving device 104 may be a desktop computer or another type of non-portable device, such as a kiosk.
[0054] The receiving device 104 comprises a hardware and software platform on which software is executed, this software being either directly executable or interpreted on a virtual machine.
[0055] The receiving device comprises a display device 114, a processing unit 116, such as a processor, capable of executing instructions and a storage memory 118.
[0056] The display device 114 comprises in particular a human-machine communication interface for displaying data and receiving data from the user. This human-machine communication interface comprises, for example, a screen and a keyboard, or a touch screen.
[0057] The processing unit 116 is capable of executing an operating system which may be, for example, any type of operating system on the market. The processing unit 116 may comprise means for executing at least one cryptographic algorithm.
[0058] The storage memory 118 can further store applications capable of being executed by the processing unit 116 of the receiving device 104. The storage memory 118 can notably comprise a secure memory for storing cryptographic keys.
[0059] The receiving device 104 may further comprise communication means 120 capable of communicating with another device, for example a user device 102. The communication means 120 comprise in particular a function for establishing a secure communication channel, allowing the creation of a secure channel 122 between the receiving device 104 and a user device 102. The communication means 122 allow network-type connectivity, either via a wired connection or via a wireless connection (for example, compliant with the Bluetooth standard, the NFC standard, the RFID standard, the WIFI standard (for example, Wi-Di (or Wi-Fi Direct)) or the PC / SC standard). The communication means 120 comprise in particular a module allowing communication based on a proximity connection.
[0060] According to a particular example of implementation, the communication channel 122 complies with the NFC standard. According to this standard, several operating modes can be used, including card emulation mode, reader mode and peer-to-peer mode. In the card emulation mode, called passive, the device behaves like a contactless smart card. In the case where the device is for example a mobile telephone, the operator's SIM card can be used as a security element by storing encrypted information. In the reader mode, the device becomes a reader of contactless cards (active mode) or "radio-tags" (electronic tags). The peer-to-peer mode, for its part, allows two devices to exchange information.
[0061] According to the present invention, the receiving device 104 is used in card emulation mode. In other words, the receiving device does not initiate the communication relating to the exchange of one or more data with the user device while it wishes to obtain data from the user device. It is the user device which will transmit the commands to the receiving device for the transmission of data.
[0062] Therefore, there is no need for the receiving device to have any special service, thus simplifying the receiving device. In addition, no special permissions need to be declared by the receiving device. This mode of operation also reduces possible attacks on the user device because there is no communication with the operating system. Indeed, no card emulator in the user device that can be corrupted is used.
[0063] Figure 2 illustrates an embodiment of the method for transmitting data implemented in the user device 102 and of the method for receiving data implemented in the receiver device 104 in accordance with the invention.
[0064] The user device 102 comprises data capable of being transmitted and the receiving device 104 comprises information identifying data required by the receiving device.
[0065] The information identifying a required data item is, for example, information relating to the user's dematerialized identity, or information relating to the user's banking data, payment data, show or transport ticketing data, or information relating to any other data, such as the user's surname, first name, address, date of birth. The data that can be transmitted is, for example, a digital identity card, data relating to a bank account, and any other personal data, whether confidential or not.
[0066] By way of example, it will be considered below that the information identifying a required data item is the “digital identity card” information and that the data item capable of being transmitted is the identity card of the user of the user device 102.
[0067] The method illustrated in Figure 2 begins with a first step of establishing a wireless communication channel 204 between the user device 102 and the receiver device 104. The communication channel is in particular a secure communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.
[0068] The receiving device does not initiate the communication relating to the exchange of data while it wishes to obtain data from the user device, the latter will initiate the communication to transmit at least one data item, by sending a command 206 via the wireless communication channel established to the receiving device 104.
[0069] Command 206 is issued to the receiving device to obtain information identifying a data item required by the receiving device. The command may be issued to obtain more than one piece of information relating to more than one required data item.
[0070] The receiving device 104 being, in this exchange, a passive device, the command will consist, for the user device 102, on the one hand, of writing, in particular in a memory space of the receiving device, the command and on the other hand of reading, in particular in a memory space, in the receiving device, the information identifying data required by the latter.
[0071] The result of this command consists of the user device 102 obtaining the information identifying a piece of data required 210 by the receiving device. In the example of FIG. 2, the information identifying a piece of data required 210 is the "digital identity card" information.
[0072] Indeed, upon receipt of a command from the user device, to obtain information identifying data required by the receiving device, the receiving device will respond by providing the information identifying data required by the receiving device.
[0073] Upon receipt of the command 206 from the user device, the receiving device 104 will make available the information identifying a required data item, namely according to this example, the information "digital identity card", during step 208. During this step, other operations can be carried out which will be detailed below. Following receipt by the user device of the information identifying a required data item, the latter will determine the data item suitable for transmission corresponding to the information identifying a required data item obtained during step 212. According to the example of FIG. 2, the data item suitable for transmission is the identity card of the user of the user device 102. During this step, other operations can be carried out which will be detailed below.
[0074] The user device 102 will then send to the receiver device 104 via the established wireless communication channel, a command comprising the data capable of being transmitted corresponding to the information identifying a required data item obtained in order to transmit the data capable of being transmitted to the receiver device, during step 216. The receiver device will then receive the command from the user device, comprising the transmitted data item corresponding to the information identifying a data item required by the receiver device.
[0075] This command will consist, for the user device, of writing into the receiving device the data capable of being transmitted corresponding to the information identifying a data item required by the receiving device. The receiving device will thus receive the data item transmitted by the user device that it wishes to obtain, namely, in the example of Figure 2, the identity card of the user of the user device 102.
[0076] Step 216 may be preceded by a step 214 during which the user device 102 will send to the receiver device 104 via the established wireless communication channel, a command in order to inform the receiver device of the size of the data capable of being transmitted that the user device will transmit to the receiver device.
[0077] Step 216 is followed by a step 218 of processing the data received by the receiving device. During this step, other operations can be carried out which will be detailed below.
[0078] The method of transmitting data implemented in the user device 102 and the method of receiving data implemented in the receiver device 104 in accordance with the invention described in FIG. 2 may also comprise one or more characteristics described below.
[0079] In particular, the user device 102 and the receiver device 104 may run on the same type of operating system or on a different type of operating system.
[0080] The user device 102 and the receiver device 104 may respectively comprise a pair of cryptographic signature keys comprising a private cryptographic signature key and a public cryptographic signature key and / or a pair of cryptographic encryption keys comprising a private cryptographic encryption key and a public cryptographic encryption key.
[0081] The user device 102 and the receiver device 104 may each further comprise a set of parameters. One of the parameters may be the name of the application requiring data exchange between the user device and the receiver device. The name of the application is, for example, unique.
[0082] One of the parameters may include the operating mode of the device. The operating mode includes, for example, whether the exchange of the data will be done without the user's consent or with the user's consent. Other operating modes may be used.
[0083] The user device 102 and the receiving device 104 may also include a parameter indicating whether they respectively wish the devices to be authenticated prior to the data exchange. One of the parameters may further include the cryptographic algorithm(s) capable of being implemented in the device.
[0084] Further, one of the parameters of the user device 102 may comprise a first random number, generated for example by the user device. The first random number may be a random number or a pseudo-random number. The length of the first random number is for example 32 bytes.
[0085] According to a particular embodiment, the user device 102 can send to the receiving device, either in the command to obtain information identifying data required during step 206, or in a new command, at least one parameter of the user device 102. Said at least one parameter can be the first random number, the name of the application of the user device, the operating mode of the device, the information according to which the user device 102 wishes the devices to be authenticated prior to the exchange of data, and / or the list of cryptographic algorithms supported by the user device 102.
[0086] Following receipt of the command by the receiving device, the latter may generate an attestation, in particular in step 208 which precedes step 210. The attestation may comprise an authentication signature of the receiving device, the authentication signature of the receiving device being able to be generated by the signature of the first random number received (for example with the command sent during step 206) from the user device with the private signature cryptographic key of the receiving device. The attestation may further comprise a key attestation of the receiving device in order to demonstrate the origin of the keys of the receiving device, the key attestation of the receiving device comprising in particular the public encryption cryptographic key of the receiving device and / or the public signature cryptographic key of the receiving device.The key attestation of the receiving device may further include a type of attestation, in particular enabling the format of the attestation to be identified, and a validity period of the key attestation.
[0087] The attestation may also comprise a second random number generated by the receiving device and / or at least one parameter of the receiving device, namely the name of the application of the receiving device, the operating mode of the device, the information according to which the receiving device 104 wishes the devices to be authenticated prior to the exchange of data, and / or the list of cryptographic algorithms supported by the receiving device 104. The length of the second random number is for example 32 bytes.
[0088] This certificate is made available to the user device so that the latter can obtain it in response to the command issued.
[0089] The user device can then obtain, at step 210, the certification of the receiving device as well as the information identifying a required data item.
[0090] After obtaining the attestation from the receiving device, the user device can verify the received attestation. The verification can, for example, be carried out during step 212 illustrated in Figure 2. The verification can consist of verifying the authentication signature of the receiving device. The verification of the authentication signature is, for example, carried out from the public signature cryptographic key of the receiving device which was received in particular by means of the key attestation of the receiving device.
[0091] Verification of the received attestation may also consist of verifying the key attestation of the receiving device received, making it possible to verify the origin of the key(s) received as well as the legitimacy of the application communicating with the user device and of the receiving device. Similarly, the validity period of the key attestation may be verified. According to a particular embodiment, prior to making available the information identifying a data item required by the receiving device to the user device, the information may be signed, for example during step 208 by the receiving device with the private cryptographic signature key of the receiving device and / or encrypted by the receiving device with a public cryptographic encryption key of the user device that the receiving device will have previously received.After the user device has obtained the information identifying a required signed data item, it will verify, for example during step 212, the signature of the information identifying a required data item obtained from the public encryption cryptographic key of the receiving device which was received in particular by means of the key attestation of the receiving device.
[0092] If the information identifying a requested data item obtained by the user device has been encrypted by the receiving device, then the information is decrypted from the user device's private encryption cryptographic key.
[0093] Prior to sending from the user device 102 to the receiver device 104 via the wireless communication channel, a command comprising the data capable of being transmitted corresponding to the information identifying a required data item obtained, the user device 102 can generate a certificate, for example during step 212.
[0094] The user device attestation may include an authentication signature of the user device, wherein the user device authentication signature may be generated by signing the second received random number generated by the receiving device and obtained by the user device, with the user device's private signature cryptographic key.
[0095] The attestation may further comprise a user device key attestation to demonstrate the origin of the user device keys, the user device key attestation including in particular a public encryption cryptographic key of the user device and / or a public signature cryptographic key of the user device. The user device key attestation may further comprise a type of attestation, in particular making it possible to identify the format of the attestation, and a validity period of the key attestation.
[0096] The command comprising the data capable of being transmitted corresponding to the information identifying a required data obtained may also comprise the attestation generated by the user device.
[0097] The data capable of being transmitted corresponding to the information identifying a required data item obtained can be signed using the private signature cryptographic key of the user device and / or encrypted using the public encryption cryptographic key of the receiving device previously obtained using the key attestation of the receiving device, in particular during step 212.
[0098] From the attestation sent by the user device 102 to the receiving device 104, the latter can verify the attestation received, in particular during step 218. The verification can consist of verifying the authentication signature of the user device. The verification of the authentication signature is for example carried out from the public signature cryptographic key of the user device which was received in particular by means of the key attestation of the user device.
[0099] Verification of the received attestation may also consist of verifying the received key attestation of the user device, enabling the origin of the received key(s) to be verified. This is carried out using at least one key attestation provided by the operating system of the user device. Similarly, the validity period of the key attestation may be verified.
[0100] If the transmitted data received by the receiving device corresponding to the information identifying a required data item has been signed, then the signature is verified by the receiving device using the public cryptographic signature key of the user device previously obtained, during step 218.
[0101] Furthermore, if the transmitted data received by the receiving device corresponding to the information identifying a required data has been encrypted, then it is decrypted using the private encryption cryptographic key of the receiving device, during step 218.
[0102] According to a particular embodiment, the user device sends to the receiving device at least one cryptographic algorithm identifier supported by the user device via, for example, the command to obtain information identifying a required data item or a new command and obtains at least one cryptographic algorithm identifier supported by the receiving device. In this embodiment, the user device determines a cryptographic algorithm supported by the user device and the receiving device and encrypts the data item capable of being transmitted corresponding to the information identifying a required data item obtained using the determined cryptographic algorithm. The algorithm is, for example, the SHA256 algorithm with ECDSA.According to this embodiment, the receiving device receives from the user device a command comprising at least one cryptographic algorithm identifier supported by the user device and responds by providing at least one cryptographic algorithm identifier supported by the receiving device. Furthermore, the receiving device determines a cryptographic algorithm supported by the user device and the receiving device and decrypts the received encrypted transmitted data corresponding to the information identifying a required data item using the determined cryptographic algorithm. According to a particular embodiment, the user device informs the receiving device of its mode of operation, namely, whether the exchange of the data item(s) will be done without the user's consent or with the user's consent. Other modes of operation may be used.In the event that the operating mode of the user device requires the user's consent, prior to sending the command comprising the data capable of being transmitted corresponding to the information identifying a required data item, obtaining consent from the user of the user device for sending the data capable of being transmitted will be performed. Obtaining will be carried out by displaying a confirmation request for sending the data capable of being transmitted on the display device of the user device. After confirmation by the user of the user device, the command comprising the data capable of being transmitted corresponding to the information identifying a required data item will be sent.
[0103] Since the data capable of being transmitted may be of a significant size, prior to its transmission, the user device 102 can send a command to the receiving device 104 comprising the size of the data capable of being transmitted, during step 214 illustrated in Figure 2. Thus, the receiving device can display on the screen of the device an animation showing the duration for the latter to obtain the transmitted data.
Claims
Claims 1. A method for transmitting data from a user device (102) to a receiver device (104), the user device (102) having data capable of being transmitted, the method implemented in the user device (102) comprises the following steps: establishing a wireless communication channel between the user device (102) and the receiver device (104); sending from the user device (102) to the receiver device (104) via the wireless communication channel, a command to obtain information identifying data required by the receiver device (104) and obtaining by the user device (102) the information identifying data required by the receiver device;and sending from the user device (102) to the receiver device (104) via the wireless communication channel, a command comprising the transmittable data corresponding to the information identifying a data item required in order to transmit the transmittable data item to the receiver device.; 2. Method according to the preceding claim, in which the information identifying a required data item obtained is signed, the method further comprising a step of verifying the signature of the information identifying a required data item obtained signed.
3. Method according to any one of the preceding claims, in which prior to sending the command comprising the data capable of being transmitted, the method comprises a step of encrypting the data capable of being transmitted.
4. Method according to any one of the preceding claims, in which the user device (102) further obtains a key attestation from the receiving device.
5. Method according to the preceding claim, in which the key attestation of the receiving device comprises a public signature cryptographic key of the receiving device.
6. Method according to the preceding claim, wherein the method further comprises: a step of generating a first random number; a step of sending from the user device (102) to the receiver device (104), a command comprising the first random number and obtaining by the user device (102) an authentication signature of the receiver device; a step of verifying the authentication signature of the receiver device obtained by means of the public signature cryptographic key of the receiver device obtained and the first random number.
7. Method according to claim 2 and claim 5, wherein the verification of the signature of the information identifying a required data obtained is carried out by means of the public signature cryptographic key of the receiving device obtained.
8. Method according to any one of claims 4 to 7, wherein the key attestation of the receiving device comprises a public encryption cryptographic key of the receiving device.
9. Method according to claim 3 and claim 8, in which the step of encrypting the data capable of being transmitted is carried out using the public encryption cryptographic key obtained from the receiving device.
10. A method according to any preceding claim, wherein the information identifying an obtained required data item is encrypted, and the method comprises a step of decrypting the information identifying an obtained required data item.
11. Method according to any one of the preceding claims, in which prior to sending the data capable of being transmitted, the method comprises a step of signing the data capable of being transmitted.
12. A method according to any preceding claim, wherein the user device (102) comprises a pair of cryptographic signature keys comprising a private cryptographic signature key and a public cryptographic signature key, wherein the method further comprises sending from the user device (102) to the receiving device (104) a command comprising a key attestation of the user device, the key attestation of the user device comprising the public cryptographic signature key of the user device (102).
13. Method according to the preceding claim, in which the user device (102) further obtains from the receiving device (104) a second random number, and in that the method comprises a step of generating an authentication signature of the user device to be transmitted, the authentication signature being generated from the second random number obtained and the private signature cryptographic key of the user device (102); and sending from the user device (102) to the receiving device (104) a command comprising the generated authentication signature of the user device to be transmitted.
14. The method of claim 10, wherein the decryption of the information identifying a required data obtained is performed using a private encryption cryptographic key of the user device (102).
15. Method according to claim 11 and claim 12, in which the signature of the data capable of being transmitted is signed by means of the private signature cryptographic key of the user device (102).
16. A method according to any preceding claim, the method further comprising the following steps: sending from the user device (102) to the receiving device, at least one identifier of a cryptographic algorithm supported by the user device and obtaining at least one identifier of a cryptographic algorithm supported by the receiving device; determining a cryptographic algorithm supported by the user device and the receiving device and encrypting the data capable of being transmitted corresponding to the information identifying a required data item obtained using the determined cryptographic algorithm.
17. Method according to any one of the preceding claims, in which the step of sending from the user device (102) to the receiving device (104) a command comprising the data capable of being transmitted corresponding to the information identifying a required data is preceded by a step of obtaining an agreement by the user of the user device for sending the data capable of being transmitted.
18. Method according to any one of the preceding claims, wherein the wireless communication channel is a communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.
19. A method of receiving data by a receiver device (104) from a user device (102), the receiver device (104) comprising information identifying data required by the receiver device, the method implemented in the receiver device (104) comprises the following steps: establishing a wireless communication channel between the user device and the receiver device; receiving via the wireless communication channel, a command from the user device, to obtain information identifying data required by the receiver device and responding by providing the information identifying data required by the receiver device; and receiving via the wireless communication channel, a command from the user device, comprising data transmitted corresponding to the information identifying data required by the receiving device.
20. Method according to the preceding claim, in which prior to providing the information identifying data required by the receiving device, the method further comprises a step of encrypting the information identifying data required by the receiving device.
21. Method according to any one of claims 19 to 20, in which the transmitted data received is signed, the method further comprising a step of verifying the signature of the transmitted data received.
22. The method of any one of claims 19 to 21, wherein the receiving device (104) further receives a key attestation from the user device.
23. Method according to the preceding claim, in which the key attestation of the user device comprises a public signature cryptographic key of the user device.
24. Method according to the preceding claim, in which the method further comprises: a step of generating a second random number, a step of making the second random number available to the user device, a step of receiving an authentication signature from the user device, a step of verifying the authentication signature of the user device received by means of the public signature cryptographic key of the user device obtained and the second random number.
25. Method according to claim 21 and claim 23, wherein the verification of the signature of the received transmitted data is carried out by means of the public signature cryptographic key of the user device obtained.
26. The method of any one of claims 22 to 25, wherein the key attestation of the user device comprises a public encryption cryptographic key of the user device.
27. Method according to claims 20 and 26, wherein the step of encrypting the information identifying a data item required by the receiving device is carried out using the public encryption cryptographic key of the user device.
28. Method according to any one of claims 19 to 27, in which the received transmitted data is encrypted, and the method comprises a step of decrypting the received transmitted data.
29. Method according to any one of claims 19 to 28, in which the method further comprises a step of signing the information identifying data required by the receiving device.
30. The method of any one of claims 19 to 30, wherein the receiving device comprises a pair of cryptographic signature keys comprising a private cryptographic signature key and a public cryptographic signature key, wherein the method further comprises providing from the receiving device to the user device a key attestation of the receiving device, the key attestation of the receiving device comprising the public cryptographic signature key of the receiving device.
31. Method according to the preceding claim, in which the receiving device further receives from the user device a first random number, and in that the method comprises a step of generating an authentication signature of the receiving device to be made available to the user device, the authentication signature being generated from the first random number received and the private signature cryptographic key of the receiving device; and making available from the receiving device (104) to the user device (102), the authentication signature of the receiving device to be transmitted generated.
32. Method according to claim 28, in which the decryption of the transmitted data is carried out by means of a private cryptographic encryption key of the receiving device.
33. The method of claim 29 and claim 30, wherein the information identifying a required data item obtained is signed using the private signature cryptographic key of the receiving device.
34. The method of any one of claims 19 to 33, the method further comprising the following steps: receiving from the user device (102) at least one cryptographic algorithm identifier supported by the user device and responding by providing at least one cryptographic algorithm identifier supported by the receiving device; determining a cryptographic algorithm supported by the user device and the receiving device and decrypting the transmitted data corresponding to the information identifying a data item required by the receiving device using the determined cryptographic algorithm.
35. Method according to any one of claims 19 to 34, wherein the wireless communication channel is a communication channel conforming to the NFC standard, the Bluetooth standard or the WiFi standard.
36. Device configured to implement the method according to any one of claims 1 to 18 or according to any one of claims 19 to 35.
37. A system comprising a user device and a receiver device, the user device implementing the method according to any one of claims 1 to 18 and the receiver device implementing the method according to any one of claims 19 to 35.
Citation Information
Patent Citations
Secure method of loading data to access a service in an NFC chipset
EP2007106A1
System access using a mobile device
WO2018160863A1