Method and system for establishing a secure messaging channel between a smart card and a terminal device
A method using a PIN and key derivation functions on smartcards and devices creates secure messaging channels, addressing the inadequacies of existing methods by protecting against active attacks and ensuring data security and integrity.
Patent Information
- Application Number
- PCT/EP2025/078934
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-10-10
- Filing Date
- 2025-10-08
- Publication Date
- 2026-04-16
AI Technical Summary
Existing methods for securing communication links between smartcards and devices are inadequate, particularly against active attacks, and lack a flexible, easy-to-implement, and low-cost solution that protects against both passive and active threats.
A method involving a Personal Identification Number (PIN), a first key derivation function, and a communication channel establishment protocol is used to create and derive secure messaging channel keys on both the smartcard and end device, utilizing a nonce value and encryption to establish a secure connection.
This approach provides a simple, cost-effective, and practical method to protect against active attacks, enhancing data security and ensuring confidentiality and integrity of the communication channel.
Smart Images

Figure EP2025078934_16042026_PF_FP_ABST
Abstract
Description
-1- Description Title: Method and system for establishing a secure messaging channel between a smartcard and an end device CROSS-REFERENCE TO OTHER REGISTRATION
[0001] This application claims priority from German patent application DE 10 2024 129 366.7, which was filed on October 10, 2024. The full disclosure of German patent application DE 10 2024 129 366.7 is hereby incorporated by reference. TECHNICAL AREA OF INVENTION
[0002] The present invention relates to a method for establishing a secure messaging channel between a smartcard and an end device. The present invention also relates to a system for such a method. The present invention also relates to a use of such a method. BACKGROUND OF THE INVENTION
[0003] Advances in communication technology, increasing digitalization, and growing connectivity are leading to a greater exchange of data. The exchange of data via a communication link must be secured through appropriate measures to prevent, hinder, or avoid eavesdropping, interception, and / or manipulation of the data during transmission.
[0004] When protecting a communication link, a distinction is made between passive and active attacks. Passive attacks include eavesdropping on or reading information, whereas active attacks also aim to manipulate the data or information.
[0005] The communication link for data exchange between smart cards and other devices is particularly vulnerable to these risks today. Smart cards with contactless communication often still lack these features. -2- Encryption measures are in place, resulting in open communication which can be exploited by individuals to read and / or manipulate sensitive data.
[0006] Therefore, there is an interest in securing communication links by ensuring a secure connection between smart cards and devices. Additionally, there are regulations governing the exchange of certain data, specifying how this data must be protected and what security requirements must be met for a connection used to exchange such data, for example, in the case of classified information.
[0007] One method of securing communication connections is the approach of so-called "secure messaging". This involves establishing a secure messaging channel for exchanging data, which, however, often only protects against passive attacks.
[0008] To ensure protection against active attacks, a pre-shared secret is required on both sides. This pre-shared secret comprises, for example, symmetric keys, also known as pre-shared keys. However, distributing these keys beforehand is complex, inconvenient, impractical, and involves increased administrative overhead, potentially requiring updates. Furthermore, such keys are also generated outside the smart card, increasing the risk of misuse or other security vulnerabilities. If the keys are to vary for different smart cards, increased administrative overhead is also to be expected.
[0009] The current state of the art therefore lacks a secure, flexible, easy-to-implement and low-cost method for establishing a secure messaging channel between a smartcard and an end device, which also protects against active attacks.
[0010] Against this background, the technical object of the present invention is to provide an improved method for establishing a secure messaging channel between a smartcard and an end device, as well as a system and use for such a method. -3- SUMMARY OF THE INVENTION
[0011] This problem is solved by a method having the features of main claim 1. This problem is further solved by a system having the features of dependent claim 8. This problem is further solved by a processor unit having the features of dependent claim 13. This problem is further solved by a computer program product having the features of dependent claim 14. This problem is further solved by a computer-readable storage medium having the features of dependent claim 15. This problem is further solved by a use having the features of dependent claim 16. Advantageous embodiments and improvements of the present invention are the subject of the dependent claims.
[0012] A method for establishing a secure messaging channel between a smartcard and an end device is disclosed in this document. In accordance with a first aspect, a Personal Identification Number (PIN), a first key derivation function, and a communication channel establishment protocol are provided on the smartcard. The PIN, the first key derivation function, and the communication channel establishment protocol are provided on the end device. The method comprises the following steps: creating a first key on the smartcard and on the end device based on the PIN and the first key derivation function; creating a nonce value, wherein the creation of the nonce value further comprises the following steps: generating the nonce value on a device stored on either the smartcard or the end device; and encrypting the nonce value with the first key.Sending the encrypted nonce value to the other end device or smartcard and decrypting the encrypted nonce value with the first key, executing the communication channel establishment protocol on the smartcard and on the end device based on the generated nonce value to generate a second key on the smartcard and on the end device, first deriving a first Secure Messaging Channel key on the smartcard and on the end device based on the second key, and second deriving a second Secure Messaging Channel key on the smartcard and on the end device based on the second key. -4-
[0013] This method offers the possibility of establishing a secure messaging channel based on a shared secret derived from a user's PIN. This provides a simple, cost-effective, and practical measure to protect against active attacks on the communication between the smartcard and the end device, thereby increasing data security. The use of the nonce value allows for further enhancement of communication connection security for data exchange, thus increasing data security.
[0014] In another aspect, the smartcard includes a chip card. In yet another aspect, the chip card is preferably a plastic card with an integrated circuit or circuits.
[0015] In another aspect, however, the chip card can also be made of materials other than plastic, for example, but not limited to, metals, alloys, wood or other natural materials, composite materials, and combinations of different materials. It is understood that, within the scope of this invention, any material suitable for manufacturing a chip card is conceivable; therefore, the chip card is not limited to one or more specific materials for use according to the invention. The mention of materials is therefore only to be considered exemplary.
[0016] In another aspect, the integrated circuit(s) can be implemented passively as a storage medium for information and / or actively with a processor (for example, a central processing unit, CPU) for more complex tasks / functions.
[0017] In another aspect, the smartcard can also be referred to as a key card, the chip card mentioned above, or an Integrated Circuit Card (ICC), or it can include such things.
[0018] In another aspect, a smartcard is preferably a plastic card with an integrated circuit (chip) or integrated circuits (chip) that includes hardware logic, non-volatile EPROM or EEPROM memory, and a microprocessor. Furthermore, smartcards can be accessed, for example, by special card readers.
[0019] In another aspect, the smartcard or chip card includes a transmission technology. In yet another aspect, the transmission technology of the chip card is differentiated, for example, between contactless and contact-based transmission. -5- Chip cards are differentiated. Contactless chip cards, also known as smart cards, can also be called transponder cards or RFID (radio-frequency identification) cards, and data transmission is preferably contactless. The chip in such chip cards or smart cards is preferably not visible externally, and these cards are typically made of plastic. RFID refers to a technology for transmitter-receiver systems for the automatic and contactless identification of objects—in this case, contactless smart cards or chip cards—using radio waves. Contact-based chip cards or smart cards require physical contact between the chip module and, for example, a chip card reader or a chip card encoding unit.With these cards, a chip is preferably visible on one surface of the chip card or smartcard.
[0020] In accordance with another aspect, the communication channel establishment protocol includes a Password-Authenticated Connection Establishment (PACE) protocol. Preferably, the PACE protocol further includes an Elliptic Curve Diffie-Hellman (ECDH) method. Preferably, the ECDH method uses the Elliptic Curve (EC)-384 standard. Preferably, the first Secure Messaging Channel key for encryption conforms to an Advanced Encryption Standard (AES). More preferably, the AES is AES-256. Preferably, the second Secure Messaging Channel key for Message Authentication Code (MAC) protection conforms to an Advanced Encryption Standard (AES). More preferably, the AES is AES-256.
[0021] The use of the PACE protocol, the ECDH method, the EC-384 standard, and the Advanced Encryption Standard contributes to increased data security through improved protection of the communication connection via the corresponding secure messaging channel. The first secure messaging channel key provides encryption for data confidentiality. The second secure messaging channel key ensures data integrity, guaranteeing that transmitted data has not been altered.
[0022] In another aspect, AES is AES-128. In another aspect, AES is AES-512. The AES-128 key could enable faster data transmission. The AES-512 key could enable an even more secure communication connection via the Secure Messaging Channel. -6-
[0023] In accordance with another aspect, the execution of the process for generating the second key on the smartcard and on the terminal device further includes counting incorrect operations based on an incorrect operation counter. Preferably, the execution also includes terminating the communication channel establishment protocol in a case where a predetermined value corresponds to an incorrect operation counter value.
[0024] The incorrect operation counter protects against unauthorized access to or use of the connection between the smartcard and the terminal device by an unauthorized user. To protect the data, the communication channel establishment protocol is terminated if an impermissible number of incorrect operations occur, thus further increasing data security.
[0025] In accordance with another aspect, the first and second derivations are repeated based on a repetition condition. Preferably, the repetition condition includes a time interval and / or a data set.
[0026] By repeating the first derivation and the second derivation via the once established secure messaging channel, the first secure messaging channel key and the second secure messaging channel key can be renewed cyclically or regularly, leading to increased security of the communication connection.
[0027] In accordance with another aspect, the PIN includes at least one user PIN or administrator PIN. Preferably, the PIN has a length of at least 6 digits.
[0028] Using the user PIN and / or the administrator PIN provides a simple and low-effort way to access a shared secret of the smartcard and the terminal device.
[0029] In accordance with another aspect, the secure messaging channel is established for a radio connection between the smartcard and the terminal device (210). Preferably, the radio connection features near-field communication (NFC).
[0030] Wireless connectivity enables simple and user-friendly data exchange, as the smartcard does not need to be in direct contact with a device by the user. Implementations of wireless connections are further supported by... -7- in addition, often space-saving. The wireless connection via NFC is an established technology.
[0031] In accordance with another aspect, at least one of the PIN, the first key derivation function and the communication channel establishment protocol is provided in encrypted form.
[0032] The encrypted provision of at least one of the PIN, the first key derivation function and the communication channel establishment protocol further increases data security through improved communication protection.
[0033] A system for establishing a secure messaging channel is disclosed in this document. In accordance with a further aspect, the system comprises an end device, including a Personal Identification Number (PIN), a first key derivation function, and a communication channel establishment protocol, and a smart card, including the PIN of the end device, the first key derivation function of the end device, and the communication channel establishment protocol of the end device. The end device and the smart card are configured to establish a communication link via a wired and / or wireless connection. The end device and the smart card have a first key, which is generated based on the PIN and the first key derivation function, and a nonce value, which is exchanged based on the first key.
[0034] The system for establishing a secure messaging channel for transmitting data via the secure messaging channel offers the possibility of implementing a secure messaging channel based on a shared secret based on a user's PIN, which provides a simple, low-effort and practical measure to protect against active attacks on the communication between the smartcard and the end device, thereby increasing data security as a result of improved communication security.
[0035] In accordance with another aspect, at least one of the PIN, the first key derivation function and the communication channel establishment protocol is / are encrypted and provided on the terminal device and / or on the smartcard.
[0036] The encrypted provision of at least one of the PIN, the first key derivation function and the communication channel establishment protocol further increases data security as a result of improved communication security. -8-
[0037] In accordance with another aspect, the system also includes a processor unit. The processor unit is configured to carry out the procedure according to one of the preceding aspects in order to establish the secure messaging channel.
[0038] The installed processor unit contributes to increased data security and improved communication security by carrying out the procedure according to one of the preceding aspects.
[0039] In accordance with another aspect, the radio connection features Near-Field Communication (NFC).
[0040] Wireless connectivity enables simple and user-friendly data exchange, as the smartcard does not need to be in direct contact with a device by the user. Furthermore, wireless implementations are often space-saving. Wireless connectivity via NFC is an established technology.
[0041] In accordance with another aspect, the end device further comprises a user interaction device. Preferably, the user interaction device is a card reader. Preferably, the card reader further comprises a user control panel.
[0042] The user interaction device serves to provide simple and user-friendly interaction with the user, thereby enabling further functions, processes and / or procedures.
[0043] A processor unit is disclosed in this document. In accordance with a further aspect, the processor unit is configured to perform the procedure according to one of the preceding aspects.
[0044] The installed processor unit contributes to increased data security and improved communication security by carrying out the procedure according to one of the preceding aspects.
[0045] A computer program product is disclosed in this document. In accordance with a further aspect, the computer program product includes instructions which, when the program is executed by a processor unit, cause the processor unit to perform the procedure according to one of the preceding aspects. -9-
[0046] The use of the computer program product allows for the implementation of the procedure for automatic execution by the processor unit.
[0047] A computer-readable storage medium is disclosed in this document. In accordance with a further aspect, the computer-readable storage medium has stored the computer program product according to one of the preceding aspects.
[0048] The use of the computer-readable storage medium allows for flexible storage of the computer program product.
[0049] One use of the method is disclosed in this document. In accordance with a further aspect, the use of the method, as described in one of the preceding aspects, is to establish a secure messaging channel for the transmission of data, where the data includes classified information.
[0050] The method is therefore suitable for establishing a secure messaging channel for transmitting confidential data, whereby the transmitted data may include classified information. BRIEF DESCRIPTION OF THE FIGURES
[0051] FIG. 1 shows a flowchart of a method for establishing a secure messaging channel between a smartcard and an end device according to a first aspect.
[0052] FIG. 2 shows a schematic representation of a system for establishing a secure messaging channel for transmitting data over a communication link according to another aspect. DETAILED DESCRIPTION OF THE INVENTION
[0053] The invention will now be described based on the figures. It is assumed that the aspects of the invention described here are only examples and do not in any way limit the scope of protection of the claims. The invention is defined by the claims and their equivalents. It is assumed that features -10- one aspect of the invention can be combined with a feature of another aspect or aspects of the invention.
[0054] Unless otherwise indicated, elements that are identical or functionally similar are marked with the same reference symbols in the figures. It should also be noted that the representations in the figures are not necessarily to scale.
[0055] Fig. 1 shows a flowchart of a method S for establishing a secure messaging channel between a smartcard 220 and a terminal device 210. The method S comprises the smartcard 220 and the terminal device 210. A personal identification number (PIN), a first key derivation function KDFI, and a communication channel establishment protocol KCP are provided on the smartcard 220. The PIN, the first key derivation function KDFI, and the communication channel establishment protocol KCP are provided on the terminal device 210. The method S comprises the following steps: creating S100 a first key Kl on the smartcard 220 and on the terminal device 210 based on the PIN and the first key derivation function KDFI; creating S110 a nonce value, wherein the creation of S110 further comprises the following steps: generating the nonce value on a device provided by the smartcard 220 or the terminal device 210.Encrypting the nonce value with the first key Kl, sending the encrypted nonce value to the other from terminal device 210 or smartcard 220, and decrypting the encrypted nonce value with the first key Kl, executing S120 of the communication channel establishment protocol KCP on smartcard 220 and on terminal device 210 based on the created nonce value to create a second key K2 on smartcard 220 and on terminal device 210, first derivation S130 of a first secure messaging channel key Kenc on smartcard 220 and on terminal device 210 based on the second key K2, and second derivation S140 of a second secure messaging channel key Kmac on smartcard 220 and on terminal device 210 based on the second key K2.
[0056] The S method allows the derivation of the first Secure Messaging Channel key Kenc, thereby achieving, in one aspect, encryption of the confidentiality of the data.
[0057] The S procedure allows the derivation of the second Secure Messaging Channel key Kmac, which in a further aspect provides integrity protection, ensuring that transmitted data has not been altered. -11-
[0058] In another aspect, the first derivation S130 includes a second key derivation function. In yet another aspect, the second derivation S140 includes a third key derivation function.
[0059] The method S can further comprise a further step S150. Step S150 comprises a repetition S150 of the first derivation S130 and the second derivation S140. The repetition S150 is performed based on a repetition condition. Preferably, the repetition condition comprises a time interval and / or a data quantity. The time interval can, in one example, be a number of minutes, hours, or days. It is understood that the time interval can also include other units of time, such as seconds or weeks. In another example, the time interval of the repetition condition can be 0.5 hours. The data quantity can, in another example, comprise a cumulative amount of transferred data. The cumulative amount of transferred data can be in the range of kilobytes, megabytes, or gigabytes. It is understood that the transferred data quantity can also include other data quantities in the range of bytes or terabytes.In another example, the repetition condition includes both a time interval and a data set, with the repetition condition being considered fulfilled as soon as one of the time interval or the data set is reached.
[0060] In procedure S, if desired and / or necessary, at least one of the PIN, the first key derivation function KDFI, and the communication channel establishment protocol KCP can be provided in encrypted form. It is understood, therefore, that encrypted provision / storage of at least one of the PIN, the first key derivation function KDFI, and the communication channel establishment protocol KCP is not necessarily required.
[0061] Creating a nonce value (S110) involves generating the nonce value. The nonce value includes, in one aspect, a random value.
[0062] The execution of S 120 of the communication channel establishment protocol KCP on the smartcard 220 and on the terminal device 210 can include an initiator of the communication channel establishment protocol KCP. In one aspect, the terminal device 210 is the initiator of the communication channel establishment protocol KCP. The terminal device 210 can, for example, be a host system. In one aspect, the -12- Smartcard 220 as a corresponding receiver for the initiation of the communication channel establishment protocol KCP by the terminal device 210.
[0063] FIG. 2 shows a schematic representation of a system 200 for establishing a secure messaging channel for transmitting data via a communication link 230. The system 200 comprises an end device 210 and a smart card 220. A communication link 230 is shown schematically between the end device 210 and the smart card 220. The system 200 further comprises a processor unit 240.
[0064] In one example, the Smartcard 220 is a physical card and uses Java Card technology.
[0065] In another aspect, the smartcard 220 can comprise a chip card. In one example, the smartcard 220 is a chip card and is preferably a plastic card or a plastic card with an integrated circuit or integrated circuits. It is understood, however, that the smartcard 220 can also be made of materials other than plastic, for example, metals, alloys, wood or other natural materials, composite materials, or combinations of different materials. It is also understood that, within the scope of this invention, any material suitable for manufacturing the smartcard 220 is conceivable; therefore, the smartcard 220 is not limited to one material or specific materials for use according to the invention, and the mention of the material or materials is therefore only to be understood as an example.
[0066] In another aspect, the integrated circuit(s) of the Smartcard 220 can be implemented / formed, for example, passively as storage for information) and / or actively with a processor (a CPU) for more complex tasks.
[0067] The Smartcard 220 can also be referred to as a key card, as mentioned above, a chip card, or an Integrated Circuit Card (ICC), or it can incorporate such components. In another example, the Smartcard 220 is preferably a plastic card with an embedded integrated circuit (chip) comprising hardware logic, non-volatile EPROM or EEPROM memory, and a microprocessor. Furthermore, the Smartcard 220 can be accessed, for example, by special card readers. -13-
[0068] In another aspect, the Smartcard 220 can incorporate a transmission technology. Regarding the transmission technology of the Smartcard 220, a distinction can be made, for example, between a contactless Smartcard 220 and a contact-based Smartcard 220. Furthermore, the contactless Smartcard 220 can also be referred to as a transponder card or RFID (radio-frequency identification) card, and data transmission preferably occurs without contact. A chip in such a contactless Smartcard 220, which is preferably a plastic card, is preferably not externally visible. RFID refers to a technology for transmitter-receiver systems for the automatic and contactless identification of objects—in this case, the contactless Smartcard 220—using radio waves.The contact-based Smartcard 220 requires physical contact between the chip module and, for example, a chip card reader or a chip card encoding unit. With the contact-based Smartcard 220, a chip is preferably visible on one surface of the Smartcard 220.
[0069] With System 200, if desired and / or required, at least one of the PIN, an administrator PIN, the first key derivation function KDFI, and the communication channel establishment protocol KCP can be provided in encrypted form on the terminal device 210 and / or on the smartcard 220. It is understood, therefore, that the encrypted provision / storage of at least one of the PIN, the administrator PIN, the first key derivation function KDFI, and the communication channel establishment protocol KCP is not necessarily required.
[0070] In another aspect, the KCP communication channel establishment protocol includes a Password-Authenticated Connection Establishment (PACE) protocol. It goes without saying that other protocols can also be used to establish a communication channel.
[0071] In another aspect, the PACE protocol includes an Elliptic Curve Diffie-Hellman (ECDH) method for negotiating parameters between the smartcard 220 and the terminal device 210. Furthermore, parameters of the PACE protocol and / or the ECDH method are, if desired and / or required, encrypted and provided on the smartcard 220 and / or the terminal device 210.
[0072] In one example, the end device 210 can be a host system. -14-
[0073] In one example, data exchange takes place via communication link 230 by establishing a secure messaging channel. In this example, the secure messaging channel is established based on the PIN and the PACE protocol using the ECDH method or ECDH protocol. The established secure messaging channel protects against both passive and active attacks and enables a high level of data communication security due to improved communication link protection. -15- REFERENCE MARK LIST S procedure SI 00 Process step "Create" S110 Process step "Create" S120 Procedure step "Execute" S130 Procedure step "first derivation" S140 Procedure step "second derivation" S150 Procedure step "Repeat" 200 System 210 End device 220 Smartcard 230 Communication connection 240 Processor unit
Claims
-16- Claims 1. Method (S) for establishing a secure messaging channel between a smartcard (220) and an end device (210), wherein the smartcard (220) provides a Personal Identification Number (PIN), a First Key Derivation Function (KDFI) and a Communication Channel Establishment Protocol (KCP), and wherein the PIN, the First Key Derivation Function (KDFI) and the Communication Channel Establishment Protocol (KCP) are provided on the end device (210), the method (S) comprises the following steps: - Creating (S100) a first key (Kl) on the smartcard (220) and on the terminal device (210) based on the PIN and the first key derivation function (KDFI); - Creating (S110) a nonce value, wherein creating (S110) further includes the following steps: - Generating the nonce value on a device from the smartcard (220) or the terminal device (210); - Encrypting the nonce value with the first key (Kl); - Sending the encrypted nonce value to the other from the terminal device (210) or smartcard (220); and - Decrypting the encrypted nonce value with the first key (Kl); - Execute (S120) the Communication Channel Establishment Protocol (KCP) on the smartcard (220) and on the terminal device (210) based on the generated nonce value to generate a second key (K2) on the smartcard (220) and on the terminal device (210); - first derivation (S130) of a first Secure Messaging Channel key (Kenc) on the smartcard (220) and on the terminal device (210) based on the second key (K2); and - second derivation (S140) of a second Secure Messaging Channel key (Kmac) on the smartcard (220) and on the terminal device (210) based on the second key (K2). -17- 2. Method (S) according to claim 1, wherein the communication channel establishment protocol (KCP) comprises a Password-Authenticated Connection Establishment (PACE) protocol, preferably the PACE protocol further comprises an Elliptic Curve Diffie-Hellman (ECDH) method, preferably the ECDH method uses an Elliptic Curve (EC)-384 standard, preferably the first Secure Messaging Channel key (Kenc) conforms to an Advanced Encryption Standard (AES), more preferably the AES is AES-256, more preferably the second Secure Messaging Channel key (Kmac) conforms to an Advanced Encryption Standard (AES), more preferably the AES is AES-256.
3. Method (S) according to claim 1 or 2, wherein the execution (S120) to create the second key (K2) on the smartcard (220) and on the end device (210) further comprises counting incorrect operations based on an incorrect operation counter, preferably the execution (S120) further comprises terminating the communication channel establishment protocol (KCP) in a case where a predetermined value corresponds to an incorrect operation counter value.
4. Method (S) according to one of the preceding claims, in which a repetition (S150) of the first derivation (S130) and the second derivation (S140) is carried out based on a repetition condition, preferably the repetition condition comprising a time interval and / or a data set.
5. Method (S) according to one of the preceding claims, wherein the PIN comprises at least one user PIN or administrator PIN, preferably comprising a length of at least 6 digits. -18- 6. Method (S) according to one of the preceding claims, in which the secure messaging channel is established for a radio connection between the smartcard (220) and the end device (210), preferably the radio connection has a near-field communication (NFC).
7. Method (S) according to any of the preceding claims, wherein at least one of the PIN, the first key derivation function (KDFI) and the communication channel establishment protocol (KCP) is provided in encrypted form.
8. System (200) for establishing a secure messaging channel, comprising: an end device (210) comprising a Personal Identification Number (PIN), a first key derivation function (KDFI) and a communication channel establishment protocol (KCP); and a smart card (220) comprising the PIN of the end device (210), the first key derivation function (KDFI) of the end device (210) and the communication channel establishment protocol (KCP) of the end device (210), wherein the end device (210) and the smart card (220) are configured to establish a communication link (230) via a wired connection and / or a wireless connection, wherein the end device (210) and the smart card (220) have a first key (Kl) which is created / is created based on the PIN and the first key derivation function (KDFI), and have a nonce value which is exchanged based on the first key (Kl).
9. System (200) according to claim 8, wherein at least one of the PIN, the first key derivation function (KDFI) and the communication channel establishment protocol (KCP) is / are provided in encrypted form on the end device (210) and / or on the smartcard (220).
10. System (200) according to claim 8 or 9, further comprising a processor unit (240), wherein the processor unit (240) is configured to execute the method (S) according to a -19- to carry out the requirements of claims 1 to 7 in order to establish the Secure Messaging Channel.
11. System (200) according to one of claims 8 to 10, wherein the radio connection comprises Near-Field Communication (NFC).
12. System (200) according to one of claims 8 to 11, wherein the end device (210) further comprises a user interaction device, preferably the user interaction device is a card reader, preferably the card reader further comprises a control panel for a user.
13. Processor unit configured to perform the method (S) according to any one of claims 1 to 7.
14. Computer program product comprising instructions which, when the program is executed by a processor unit (240), cause the processor unit (240) to perform the method (S) according to any one of claims 1 to 7.
15. Computer-readable storage medium that has stored the computer program product according to claim 14.
16. Use of the method (S) according to any one of claims 1 to 7 for establishing a secure messaging channel for transmitting data, wherein the data comprises classified information.
Citation Information
Patent Citations
Method and system for establishing a secure messaging channel between a smartcard and an end device
DE102024129366A1
Method and arrangement for secure communication between network units in a communication network
EP2891266B1
System and method for protecting unauthorized access to data contents
US5594227A