CN101379759B - 在包括芯片卡的装载计算机系统上生成安全计数器的方法 - Google Patents

在包括芯片卡的装载计算机系统上生成安全计数器的方法 Download PDF

Info

Publication number
CN101379759B
CN101379759B CN2006800525130A CN200680052513A CN101379759B CN 101379759 B CN101379759 B CN 101379759B CN 2006800525130 A CN2006800525130 A CN 2006800525130A CN 200680052513 A CN200680052513 A CN 200680052513A CN 101379759 B CN101379759 B CN 101379759B
Authority
CN
China
Prior art keywords
counter
request
public key
computer system
signature
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN2006800525130A
Other languages
English (en)
Other versions
CN101379759A (zh
Inventor
A·弗瑞
D·博利戈纳诺
A·阿普弗里勒
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Fidelity logic Mobile Corporation
Original Assignee
Trusted Logic SAS
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Trusted Logic SAS filed Critical Trusted Logic SAS
Publication of CN101379759A publication Critical patent/CN101379759A/zh
Application granted granted Critical
Publication of CN101379759B publication Critical patent/CN101379759B/zh
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K19/00Record carriers for use with machines and with at least a part designed to carry digital markings
    • G06K19/06Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
    • G06K19/067Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
    • G06K19/07Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/60Digital content management, e.g. content distribution
    • H04L2209/603Digital right managament [DRM]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless

Abstract

根据本发明的方法,计数功能(FC)、计数器(Cpt)和储存于存储器区的只-写部分的专用钥(Cf)存储于芯片卡永久存储器中,计数器和专用钥(Cf)只由计数功能(FC)访问。当芯片卡接收到由请求实体(ER)发出的计数器请求时,计数功能(FC)执行计数器(Cpt)的修改和签名的计算,并发送回复给请求实体(ER)。当装载系统接收到计数器请求的回复时,包含于回复中的签名被验证。

Description

在包括芯片卡的装载计算机系统上生成安全计数器的方法
技术领域
本发明涉及在包括芯片卡的装载计算机系统上获取安全计数器的方法。
其目的尤其是提供一种带有到设于芯片卡上的单调计数器的通道的装载环境(特别是移动电话),该计数器不能伪造。
背景技术
一般地,已知单调计数器是一种保证其值随着每个通话而变化的计数器,即它决不会两次给出相同值。所述计数器在计算机系统中非常有用,例如用于生成独特标识符、以及与所谓的“重放”安全攻击进行斗争(在时间t识别授权值的攻击者可以在时间t+Δ,“重放”,即给出先前检测值期望也被该系统授权)。
单调计数器大多数是递增的,因为这不增加任何具体实施的困难。在这种情况下,计数器也提供在每一个通话中给出比先前通话更高的值的保证。时间例如是一个通用的递增源。递增的单调计数器对于彼此相关的顺序事件具有特别意义。例如,在某些时间-注明系统中仅仅期望知道文件A在文件B前归档。而不是采用内部时钟(一般昂贵、不精确并且不安全——即攻击者可能随意改变时间),计算机系统常常采用递增的单调计数器。
递增的单调计数器在数据权限管理(DRM)领域也有高的期望,特别是要控制一旦相关的权限过期先前播放的音乐就不再播放。
在本说明书的其余部分中,递增的单调计数器称为“单调计数器”。
虽然在个人电脑(PC)上的单调计数器不引起任何真正麻烦,但是其在装载环境(特别是移动电话)中的集成是一件非常复杂的事情。为了生产单调计数器,永久性存储区域需要具有几次再-写机会(当供电不足时用于储存计数器的值)。可再写的永久性存储器在装载环境中的整合势必需要不可忽视的经济成本,意图大规模配置的相关设备(例如数百万的移动电话的附加费用)越多,经济成本就越高。而装载环境——象其他计算机系统一样——却需要单调计数器,市场需求无疑根据DRM更高(便携式视频控制台的游戏、在移动电话和iPod(商标)上听音乐,等)。
发明内容
本发明的目的更加特别的是提供一种可靠的低成本的解决方案以制造单调计数器,用于装载环境具有智能卡的场合(特别是对于具有SIM卡的移动电话的场合)。
为了这个目的,提出了包括以下操作阶段的方法:
(i)在所述芯片卡的永久存储器中储存:
a、计数功能FC
b、计数器Cpt
c、储存于存储区的读-保护部分内的专用钥Cf,
所述计数器Cpt和所述专用钥Cf仅可被所述计数功能FC访问;
(ii)所述芯片卡一接到由所谓“请求”实体ER发出的“计数器请求”,就执行以下操作:
a、通过所述计数功能FC修改所述计数器Cpt,确保在对给定请求的回复中给出的计数器值的唯一性;
b、采用如在步骤(a)被修改的所述计数器Cpt的值以及所述专用钥Cf,通过所述计数功能FC计算签名;
c、通过所述计数功能FC发送回复给所述请求实体ER,所述回复包括如在步骤(a)被修改的所述计数器Cpt的值以及在步骤(b)计算的签名;
(iii)所述装载系统一接到所述计数器请求的回复,就执行包含在这个回复内的签名的验证。
作为一般规则,请求实体ER可以充当系统或自然人的另一个应用程序的代表,与装载系统交互。
有利的是,在计数器请求的执行阶段中计算签名的步骤,请求实体ER预先被鉴认(authentifiée)。因此计数器请求只有成功鉴认才执行。
相似地,包含于对所述计数器请求的回复中的签名的验证(verification)采用储存于装载系统的永久存储器中的公用钥CP进行。
根据该方法,单调计数器以运行于智能卡(配备有微处理器)内部的应用的程序形式制成。这个应用程序可以是本地的(即直接运行于微处理器)或可被解释引擎解释(如虚拟的JAVA机、脚本解释器)。它具有以下优点:
●芯片卡的物质抵抗力(关于安全)。例如相对于在PC母板上,用显微镜观察芯片卡的内容或企图改变其值(通过激光等)更加困难;
●在存储器(EEPROM)上芯片卡保存可再写的永久数据的能力;
●在大多数芯片卡上展示的密码功能,这些功能一般用于存储密钥。
这样产生的应用程序:
●提供了安全的单调计数器(它决不会两次给出相同值);
●从物理角度看难以攻击;
●可选地被鉴认(呼叫者确信该值的确由单调计数器给出)。
附图说明
以下通过非限制性的例子参考附图描述本发明的一个实施例,其中:
唯一的图是示出了在公用钥位于装载系统的情况下,单调计数器的详细功能的概要图。
具体实施方式
在该实施例中,装载系统(模块1)具有芯片卡(模块2),该芯片卡包括存储有计数器Cpt的专用永久存储器(模块3)、存储于专用永久存储区域(模块3)内的可再-写区域的读-保护的专用钥Cf、以及计数功能FC。
计数器Cpt和专用钥Cf只可被计数功能FC访问。由计数功能FC进行的计数器Cpt的修改包括+1递增。
在芯片卡(模块2)上还有一个单调的应用程序(模块5)。这个采用了专用钥Cf的应用程序可随着卡2被供电而自动启动、或被卡2的所有者通过手动操作而启动。它回复由呼叫者从卡以外发出的请求。
装载系统1也包括存储于公用永久存储器(模块6)例如一次可编程存储器(OTP)的公用钥Cp(或公用钥证书Ccp)(理想的是整体保护的,即它不可不正当地修改),因为所述存储器不会带来任何特别的集成或经济上的困难(例如它们提供于移动电话上)。对应于唯一附图所示的方案的这个解决方案,在攻击者企图以另外一对钥建立错误的单调计数器应用程序并以该错误应用程序的公用钥替换鉴认的公用钥的所有情况下,都能够对其进行控制。
可替换地,公用钥Cp可存储于:
■芯片卡(模块2)上:对于装载系统(模块1)不具有(或没有足够的)OTP存储器的情况,公用钥Cp可存储于芯片卡(模块2)的永久存储器(模块3)上。为了确保其集成,芯片卡(模块2)必须保证除了单调计数器应用程序之外其他应用程序均不可写/修改这个区域。
■装载系统以外:公用钥Cp也可由装载系统通过其他方式如通过专用PKI结构(公用钥基础设施)而获取。
在后两种情况下——其中公用钥Cp未存储于装载系统(模块1)的存储器内——也建议存储要用于装载系统的公用钥Cp的印记。这可确保攻击者没有以另一个芯片卡替换芯片卡(模块2),或者没有模仿非法PKI的行为。
公用钥Cp也可中权威机构认证以证明公用钥Cp的确对应于单调计数器应用程序5。在这种情况下,储存包含公用钥Cp的Ccp认证就足够了。公用钥Cp用于验证计数器的签名。
为了获取单调计数器的值,请求实体ER首先发出单调计数器请求给位于芯片卡(模块2)的应用程序5。可选地,可以通过请求请求实体ER提供一个芯片卡已知的秘密数据项而对其进行鉴认。这个秘密数据项可以例如是PIN(个人识别码)、上述两个实体已知的口令或密钥。请求实体ER的鉴认确保请求体ER的确被授权请求单调计数器的值,因此避免了由服务拒绝带来的攻击,其中攻击者不停地请求一个值而致使服务对于其他(合法)呼叫者不可用。
接着,应用程序5递增其内部计数器。这个计数器保存于芯片卡(模块2)的永久存储器(模块3)内并仅可由单调计数器应用程序5访问。可选地,该计数器可保持(被该应用程序的公用钥)编码。这防止了非授权的实体知道单调计数器的当前值。特别是,在非常近的视觉仔细检查的条件下,所显露出的值被编码因此不可用。计数器的当前值然后被该应用程序中的专用钥签名,而计数器值+签名的数据项返回到请求实体ER。
最后,请求实体ER收集该应用程序中的公用钥Cp。根据情况,公用钥Cp可被收集于芯片卡(模块2)上、装载系统(模块1)或外部的存储器内。在后两个情况中,公用钥Cp的印记(如果有的话)然后计数器的签名必须被验证。如果签名吻合,呼叫者确信计数器的值是可信的。它是可用的。
要注意的是在不太敏感的环境或相反在高警戒环境下,也可以设计不签名(以及不验证)单调计数器的值。缺点是明显的,呼叫者不再确信其真实性:值可能是由攻击者提供的。在这种情况下储存一对钥就不再有用了。
从实现角度看,单调计数器应用程序5可很容易实施,不管是作为本地应用程序(假设到永久存储器和密码功能的访问是可能的)还是作为解释的应用程序。在后一种情况下,应用程序5可作为JAVA卡(注册商标)内的小应用程序执行。

Claims (9)

1.一种在具有芯片卡的装载计算机系统上提供安全计数器的方法,其特征在于包括下列操作阶段:
(i)在所述芯片卡的永久存储器中存储:
a、计数功能FC,
b、计数器Cpt,
c、存储于存储区的读-保护部分内的专用钥Cf,
所述计数器Cpt和所述专用钥Cf只可被所述计数功能FC访问;
(ii)所述芯片卡一接到由所谓“请求”实体ER发出的“计数器请求”,就执行以下操作:
a、通过所述计数功能FC修改所述计数器Cpt,确保在对给定请求的回复中给出的计数器值的唯一性;
b、利用所述计数器Cpt的如在步骤(a)被修改的值以及所述专用钥Cf,通过所述计数功能FC计算签名;
c、通过所述计数功能FC发送回复给所述请求实体ER,所述回复包括所述计数器Cpt的如在步骤(a)被修改的值和在步骤(b)计算的签名;
(iii)所述装载计算机系统一接到对所述计数器请求的回复,就执行对包含在这个回复内的签名的验证。
2.如权利要求1所述的方法,其特征在于:在所述计数器请求的执行阶段的所述计算签名的步骤,所述请求实体ER被事先鉴认,并且只有鉴认成功时所述计数器请求才执行。
3.如权利要求1所述的方法,其特征在于:所述计数器Cpt被编码地存储。
4.如权利要求1所述的方法,其特征在于:通过所述计数功能FC的计数器Cpt修改由这个计数器的递增构成。
5.如权利要求1所述的方法,其特征在于:包含在对所述计数器请求的回复中的签名的验证是利用存储于所述装载计算机系统的永久存 储器(模块6)中的公用钥Cp进行的。
6.如权利要求1所述的方法,其特征在于:包含在对所述计数器请求的回复中的签名的验证是利用公用钥Cp执行的,并且所述公用钥Cp或相关联的公用钥证书Ccp存储在所述芯片卡的永久存储器中并在装载计算机系统的请求下返回到所述装载计算机系统。
7.如权利要求1所述的方法,其特征在于:包含在对所述计数器请求的回复中的签名的验证是利用公用钥Cp进行的,并且所述公用钥Cp或相关联的公用钥证书Ccp由公用钥基础设施提供并在装载计算机系统的请求下返回到所述装载计算机系统。
8.如权利要求6或7所述的方法,其特征在于:所述公用钥Cp或所述相关联的公用钥证书Ccp作为保护的整体被存储。
9.如权利要求6或7所述的方法,其特征在于:所述公用钥Cp的印记存储在所述装载计算机系统中。 
CN2006800525130A 2005-12-23 2006-12-14 在包括芯片卡的装载计算机系统上生成安全计数器的方法 Active CN101379759B (zh)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
FR0513241 2005-12-23
FR0513241A FR2895608B1 (fr) 2005-12-23 2005-12-23 Procede pour la realisation d'un compteur securise sur un systeme informatique embarque disposant d'une carte a puce
PCT/FR2006/002766 WO2007080289A1 (fr) 2005-12-23 2006-12-14 Procede pour la realisation d'un compteur securise sur un systeme informatique embarque disposant d'une carte a puce.

Publications (2)

Publication Number Publication Date
CN101379759A CN101379759A (zh) 2009-03-04
CN101379759B true CN101379759B (zh) 2012-03-14

Family

ID=36729349

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2006800525130A Active CN101379759B (zh) 2005-12-23 2006-12-14 在包括芯片卡的装载计算机系统上生成安全计数器的方法

Country Status (7)

Country Link
US (1) US8082450B2 (zh)
EP (1) EP1964307B8 (zh)
JP (1) JP5046165B2 (zh)
KR (1) KR101395749B1 (zh)
CN (1) CN101379759B (zh)
FR (1) FR2895608B1 (zh)
WO (1) WO2007080289A1 (zh)

Families Citing this family (109)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100488099C (zh) 2007-11-08 2009-05-13 西安西电捷通无线网络通信有限公司 一种双向接入认证方法
US9455992B2 (en) * 2009-06-12 2016-09-27 Microsoft Technology Licensing, Llc Trusted hardware component for distributed systems
US9465933B2 (en) * 2012-11-30 2016-10-11 Intel Corporation Virtualizing a hardware monotonic counter
CN103247613B (zh) * 2013-04-09 2016-03-30 北京兆易创新科技股份有限公司 增强型Flash的多芯片的封装芯片、通信方法和封装方法
US8930274B1 (en) * 2013-10-30 2015-01-06 Google Inc. Securing payment transactions with rotating application transaction counters
CN104484624B (zh) * 2014-12-15 2018-08-28 上海新储集成电路有限公司 一种单调计数器及单调计数的方法
US10592435B2 (en) * 2016-07-14 2020-03-17 Intel Corporation System, apparatus and method for secure monotonic counter operations in a processor
DE102016213104A1 (de) * 2016-07-18 2018-01-18 bitagentur GmbH & Co. KG Token-basiertes Authentisieren mit signierter Nachricht
US10546444B2 (en) 2018-06-21 2020-01-28 Capital One Services, Llc Systems and methods for secure read-only authentication
DE102018115758A1 (de) * 2018-06-29 2020-01-02 Infineon Technologies Ag Sicherheit von Java-Card-Schlüsselobjekten
US10542036B1 (en) 2018-10-02 2020-01-21 Capital One Services, Llc Systems and methods for signaling an attack on contactless cards
WO2020072537A1 (en) 2018-10-02 2020-04-09 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10771253B2 (en) 2018-10-02 2020-09-08 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
WO2020072552A1 (en) 2018-10-02 2020-04-09 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10949520B2 (en) 2018-10-02 2021-03-16 Capital One Services, Llc Systems and methods for cross coupling risk analytics and one-time-passcodes
US10733645B2 (en) 2018-10-02 2020-08-04 Capital One Services, Llc Systems and methods for establishing identity for order pick up
US10909527B2 (en) 2018-10-02 2021-02-02 Capital One Services, Llc Systems and methods for performing a reissue of a contactless card
US10565587B1 (en) 2018-10-02 2020-02-18 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
KR20210069033A (ko) 2018-10-02 2021-06-10 캐피탈 원 서비시즈, 엘엘씨 비접촉식 카드의 암호화 인증을 위한 시스템 및 방법
US10489781B1 (en) 2018-10-02 2019-11-26 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10771254B2 (en) 2018-10-02 2020-09-08 Capital One Services, Llc Systems and methods for email-based card activation
SG11202101171VA (en) 2018-10-02 2021-03-30 Capital One Services Llc Systems and methods for cryptographic authentication of contactless cards
US10505738B1 (en) 2018-10-02 2019-12-10 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
WO2020072413A1 (en) 2018-10-02 2020-04-09 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US11210664B2 (en) 2018-10-02 2021-12-28 Capital One Services, Llc Systems and methods for amplifying the strength of cryptographic algorithms
WO2020072687A1 (en) 2018-10-02 2020-04-09 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10581611B1 (en) 2018-10-02 2020-03-03 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10554411B1 (en) 2018-10-02 2020-02-04 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10511443B1 (en) 2018-10-02 2019-12-17 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10592710B1 (en) 2018-10-02 2020-03-17 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10582386B1 (en) 2018-10-02 2020-03-03 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
BR112021004710A2 (pt) 2018-10-02 2021-06-08 Capital One Services, Llc sistema e método para transmitir dados
WO2020072474A1 (en) 2018-10-02 2020-04-09 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10607214B1 (en) 2018-10-02 2020-03-31 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
WO2020072440A1 (en) 2018-10-02 2020-04-09 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10783519B2 (en) 2018-10-02 2020-09-22 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
SG11202103249VA (en) 2018-10-02 2021-04-29 Capital One Services Llc Systems and methods for cryptographic authentication of contactless cards
WO2020072550A1 (en) 2018-10-02 2020-04-09 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10748138B2 (en) 2018-10-02 2020-08-18 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US10579998B1 (en) 2018-10-02 2020-03-03 Capital One Services, Llc Systems and methods for cryptographic authentication of contactless cards
US20200226581A1 (en) 2019-01-11 2020-07-16 Capital One Services, Llc Systems and methods for touch screen interface interaction using a card overlay
US11037136B2 (en) 2019-01-24 2021-06-15 Capital One Services, Llc Tap to autofill card data
US10467622B1 (en) 2019-02-01 2019-11-05 Capital One Services, Llc Using on-demand applications to generate virtual numbers for a contactless card to securely autofill forms
US10510074B1 (en) 2019-02-01 2019-12-17 Capital One Services, Llc One-tap payment using a contactless card
US11120453B2 (en) 2019-02-01 2021-09-14 Capital One Services, Llc Tap card to securely generate card data to copy to clipboard
US10425129B1 (en) 2019-02-27 2019-09-24 Capital One Services, Llc Techniques to reduce power consumption in near field communication systems
US10523708B1 (en) 2019-03-18 2019-12-31 Capital One Services, Llc System and method for second factor authentication of customer support calls
US10438437B1 (en) 2019-03-20 2019-10-08 Capital One Services, Llc Tap to copy data to clipboard via NFC
US10643420B1 (en) 2019-03-20 2020-05-05 Capital One Services, Llc Contextual tapping engine
US10984416B2 (en) 2019-03-20 2021-04-20 Capital One Services, Llc NFC mobile currency transfer
US10535062B1 (en) 2019-03-20 2020-01-14 Capital One Services, Llc Using a contactless card to securely share personal data stored in a blockchain
US10970712B2 (en) 2019-03-21 2021-04-06 Capital One Services, Llc Delegated administration of permissions using a contactless card
US10467445B1 (en) 2019-03-28 2019-11-05 Capital One Services, Llc Devices and methods for contactless card alignment with a foldable mobile device
US11521262B2 (en) 2019-05-28 2022-12-06 Capital One Services, Llc NFC enhanced augmented reality information overlays
US10516447B1 (en) 2019-06-17 2019-12-24 Capital One Services, Llc Dynamic power levels in NFC card communications
US11694187B2 (en) 2019-07-03 2023-07-04 Capital One Services, Llc Constraining transactional capabilities for contactless cards
US10871958B1 (en) 2019-07-03 2020-12-22 Capital One Services, Llc Techniques to perform applet programming
US11392933B2 (en) 2019-07-03 2022-07-19 Capital One Services, Llc Systems and methods for providing online and hybridcard interactions
US10713649B1 (en) 2019-07-09 2020-07-14 Capital One Services, Llc System and method enabling mobile near-field communication to update display on a payment card
US10498401B1 (en) 2019-07-15 2019-12-03 Capital One Services, Llc System and method for guiding card positioning using phone sensors
US10885514B1 (en) 2019-07-15 2021-01-05 Capital One Services, Llc System and method for using image data to trigger contactless card transactions
US10832271B1 (en) 2019-07-17 2020-11-10 Capital One Services, Llc Verified reviews using a contactless card
US11182771B2 (en) 2019-07-17 2021-11-23 Capital One Services, Llc System for value loading onto in-vehicle device
US10733601B1 (en) 2019-07-17 2020-08-04 Capital One Services, Llc Body area network facilitated authentication or payment authorization
US11521213B2 (en) 2019-07-18 2022-12-06 Capital One Services, Llc Continuous authentication for digital services based on contactless card positioning
US10506426B1 (en) 2019-07-19 2019-12-10 Capital One Services, Llc Techniques for call authentication
US10541995B1 (en) 2019-07-23 2020-01-21 Capital One Services, Llc First factor contactless card authentication system and method
AU2019469080A1 (en) 2019-10-02 2022-04-21 Capital One Services, Llc Client device authentication using contactless legacy magnetic stripe data
US11113685B2 (en) 2019-12-23 2021-09-07 Capital One Services, Llc Card issuing with restricted virtual numbers
US10733283B1 (en) 2019-12-23 2020-08-04 Capital One Services, Llc Secure password generation and management using NFC and contactless smart cards
US11651361B2 (en) 2019-12-23 2023-05-16 Capital One Services, Llc Secure authentication based on passport data stored in a contactless card
US11615395B2 (en) 2019-12-23 2023-03-28 Capital One Services, Llc Authentication for third party digital wallet provisioning
US10862540B1 (en) 2019-12-23 2020-12-08 Capital One Services, Llc Method for mapping NFC field strength and location on mobile devices
US10657754B1 (en) 2019-12-23 2020-05-19 Capital One Services, Llc Contactless card and personal identification system
US10885410B1 (en) 2019-12-23 2021-01-05 Capital One Services, Llc Generating barcodes utilizing cryptographic techniques
US11200563B2 (en) 2019-12-24 2021-12-14 Capital One Services, Llc Account registration using a contactless card
US10664941B1 (en) 2019-12-24 2020-05-26 Capital One Services, Llc Steganographic image encoding of biometric template information on a card
US10853795B1 (en) 2019-12-24 2020-12-01 Capital One Services, Llc Secure authentication based on identity data stored in a contactless card
US10757574B1 (en) 2019-12-26 2020-08-25 Capital One Services, Llc Multi-factor authentication providing a credential via a contactless card for secure messaging
US10909544B1 (en) 2019-12-26 2021-02-02 Capital One Services, Llc Accessing and utilizing multiple loyalty point accounts
US11038688B1 (en) 2019-12-30 2021-06-15 Capital One Services, Llc Techniques to control applets for contactless cards
US10860914B1 (en) 2019-12-31 2020-12-08 Capital One Services, Llc Contactless card and method of assembly
US11455620B2 (en) 2019-12-31 2022-09-27 Capital One Services, Llc Tapping a contactless card to a computing device to provision a virtual number
US11210656B2 (en) 2020-04-13 2021-12-28 Capital One Services, Llc Determining specific terms for contactless card activation
US11030339B1 (en) 2020-04-30 2021-06-08 Capital One Services, Llc Systems and methods for data access control of personal user data using a short-range transceiver
US10915888B1 (en) 2020-04-30 2021-02-09 Capital One Services, Llc Contactless card with multiple rotating security keys
US11823175B2 (en) 2020-04-30 2023-11-21 Capital One Services, Llc Intelligent card unlock
US11222342B2 (en) 2020-04-30 2022-01-11 Capital One Services, Llc Accurate images in graphical user interfaces to enable data transfer
US10861006B1 (en) 2020-04-30 2020-12-08 Capital One Services, Llc Systems and methods for data access control using a short-range transceiver
US10963865B1 (en) 2020-05-12 2021-03-30 Capital One Services, Llc Augmented reality card activation experience
US11063979B1 (en) 2020-05-18 2021-07-13 Capital One Services, Llc Enabling communications between applications in a mobile operating system
US11100511B1 (en) 2020-05-18 2021-08-24 Capital One Services, Llc Application-based point of sale system in mobile operating systems
US11062098B1 (en) 2020-08-11 2021-07-13 Capital One Services, Llc Augmented reality information display and interaction via NFC based authentication
US11165586B1 (en) 2020-10-30 2021-11-02 Capital One Services, Llc Call center web-based authentication using a contactless card
US11482312B2 (en) 2020-10-30 2022-10-25 Capital One Services, Llc Secure verification of medical status using a contactless card
US11373169B2 (en) 2020-11-03 2022-06-28 Capital One Services, Llc Web-based activation of contactless cards
US11216799B1 (en) 2021-01-04 2022-01-04 Capital One Services, Llc Secure generation of one-time passcodes using a contactless card
US11682012B2 (en) 2021-01-27 2023-06-20 Capital One Services, Llc Contactless delivery systems and methods
US11687930B2 (en) 2021-01-28 2023-06-27 Capital One Services, Llc Systems and methods for authentication of access tokens
US11792001B2 (en) 2021-01-28 2023-10-17 Capital One Services, Llc Systems and methods for secure reprovisioning
US11562358B2 (en) 2021-01-28 2023-01-24 Capital One Services, Llc Systems and methods for near field contactless card communication and cryptographic authentication
US11438329B2 (en) 2021-01-29 2022-09-06 Capital One Services, Llc Systems and methods for authenticated peer-to-peer data transfer using resource locators
US11777933B2 (en) 2021-02-03 2023-10-03 Capital One Services, Llc URL-based authentication for payment cards
US11637826B2 (en) 2021-02-24 2023-04-25 Capital One Services, Llc Establishing authentication persistence
US11245438B1 (en) 2021-03-26 2022-02-08 Capital One Services, Llc Network-enabled smart apparatus and systems and methods for activating and provisioning same
US11961089B2 (en) 2021-04-20 2024-04-16 Capital One Services, Llc On-demand applications to extend web services
US11935035B2 (en) 2021-04-20 2024-03-19 Capital One Services, Llc Techniques to utilize resource locators by a contactless card to perform a sequence of operations
US11902442B2 (en) 2021-04-22 2024-02-13 Capital One Services, Llc Secure management of accounts on display devices using a contactless card
US11354555B1 (en) 2021-05-04 2022-06-07 Capital One Services, Llc Methods, mediums, and systems for applying a display to a transaction card

Family Cites Families (24)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2206431B (en) * 1987-06-30 1991-05-29 Motorola Inc Data card circuits
US5434919A (en) * 1994-01-11 1995-07-18 Chaum; David Compact endorsement signature systems
FR2733615B1 (fr) * 1995-04-26 1997-06-06 France Telecom Carte a memoire et procede de mise en oeuvre d'une telle carte
JPH09284272A (ja) * 1996-04-19 1997-10-31 Canon Inc エンティティの属性情報に基づく暗号化方式、署名方式、鍵共有方式、身元確認方式およびこれらの方式用装置
KR100213188B1 (ko) * 1996-10-05 1999-08-02 윤종용 사용자 인증 장치 및 방법
EP0932865B1 (en) * 1996-10-25 2002-08-14 SCHLUMBERGER Systèmes Using a high level programming language with a microcontroller
FR2762424B1 (fr) * 1997-04-17 2003-01-10 Gemplus Card Int Carte a puce avec compteur, notamment compteur d'unite ou de gratifications, et procede de mise en oeuvre
US6085321A (en) * 1998-08-14 2000-07-04 Omnipoint Corporation Unique digital signature
US6539480B1 (en) * 1998-12-31 2003-03-25 Intel Corporation Secure transfer of trust in a computing system
US6836853B1 (en) * 1999-12-31 2004-12-28 Intel Corporation Non-volatile memory based monotonic counter
US20020043566A1 (en) * 2000-07-14 2002-04-18 Alan Goodman Transaction card and method for reducing frauds
CA2417922C (en) * 2000-08-04 2013-03-12 Lynn Henry Wheeler Person-centric account-based digital signature system
US7165178B2 (en) * 2000-08-14 2007-01-16 Identrus Llc System and method for facilitating signing by buyers in electronic commerce
US7350083B2 (en) * 2000-12-29 2008-03-25 Intel Corporation Integrated circuit chip having firmware and hardware security primitive device(s)
FR2834841B1 (fr) * 2002-01-17 2004-05-28 France Telecom Procede cryptographique de revocation a l'aide d'une carte a puce
FR2840748B1 (fr) * 2002-06-05 2004-08-27 France Telecom Procede et systeme de verification de signatures electroniques et carte a microcircuit pour la mise en oeuvre du procede
US7421579B2 (en) 2002-06-28 2008-09-02 Microsoft Corporation Multiplexing a secure counter to implement second level secure counters
US20040054901A1 (en) * 2002-09-17 2004-03-18 Microsoft Corporation Creating and verifying a sequence of consecutive data
JP3967269B2 (ja) * 2003-02-18 2007-08-29 大日本印刷株式会社 Icカード、携帯通信端末、課金システム、icカードプログラム及びプログラム。
US7472285B2 (en) * 2003-06-25 2008-12-30 Intel Corporation Apparatus and method for memory encryption with reduced decryption latency
EP1530392A1 (fr) * 2003-11-04 2005-05-11 Nagracard S.A. Méthode de gestion de la sécurité d'applications avec un module de sécurité
US20060198515A1 (en) * 2005-03-03 2006-09-07 Seagate Technology Llc Secure disc drive electronics implementation
US7809957B2 (en) * 2005-09-29 2010-10-05 Intel Corporation Trusted platform module for generating sealed data
US7681050B2 (en) * 2005-12-01 2010-03-16 Telefonaktiebolaget L M Ericsson (Publ) Secure and replay protected memory storage

Also Published As

Publication number Publication date
CN101379759A (zh) 2009-03-04
FR2895608A1 (fr) 2007-06-29
JP2009521032A (ja) 2009-05-28
WO2007080289A1 (fr) 2007-07-19
KR20080091347A (ko) 2008-10-10
JP5046165B2 (ja) 2012-10-10
EP1964307A1 (fr) 2008-09-03
US20080320315A1 (en) 2008-12-25
EP1964307B1 (fr) 2019-01-23
US8082450B2 (en) 2011-12-20
EP1964307B8 (fr) 2019-03-20
FR2895608B1 (fr) 2008-03-21
KR101395749B1 (ko) 2014-05-16

Similar Documents

Publication Publication Date Title
CN101379759B (zh) 在包括芯片卡的装载计算机系统上生成安全计数器的方法
US9596089B2 (en) Method for generating a certificate
US8417946B2 (en) Method and apparatus for accessing an electronic device by a data terminal
US8607044B2 (en) Privacy enhanced identity scheme using an un-linkable identifier
US8447991B2 (en) Card authentication system
JP2009521032A5 (zh)
US20100268649A1 (en) Method and Apparatus for Electronic Ticket Processing
JP2002101092A (ja) 個人認証装置、個人認証情報記憶媒体、個人認証システム、個人認証方法、個人認証プログラムを記憶した媒体、個人認証情報登録方法および個人認証情報認証方法
KR100939725B1 (ko) 모바일 단말기 인증 방법
US20130339747A1 (en) Secure Identification Card (SID-C) System
US8931080B2 (en) Method and system for controlling the execution of a function protected by authentification of a user, in particular for the access to a resource
JP5183517B2 (ja) 情報処理装置及びプログラム
WO2018156384A1 (en) Determining legitimate conditions at a computing device
JP2000215280A (ja) 本人認証システム
JP2004533730A (ja) 実世界の応用のためにディジタル署名および公開鍵基盤のセキュリティを改善するプロセスおよび装置
US8870067B2 (en) Identification device having electronic key stored in a memory
JP5489913B2 (ja) 携帯型情報装置及び暗号化通信プログラム
JP4760124B2 (ja) 認証装置、登録装置、登録方法及び認証方法
Bar-El Intra-vehicle information security framework
US20240129139A1 (en) User authentication using two independent security elements
JP5386860B2 (ja) 決済システム、決済処理装置、正当性検証装置、正当性検証要求処理プログラム、正当性検証処理プログラム、及び正当性検証方法
KR101480035B1 (ko) 금융 서비스 제공을 위한 인증 장치
CN103403727A (zh) 附加功能单元的启用/禁用方法、其系统、其程序以及附加功能单元
Hyppönen et al. Transforming Mobile Platform with KI-SIM Card into an Open Mobile Identity Tool
EVANGELISTA Security Target Lite SOMA801NXP Electronic Passport

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
ASS Succession or assignment of patent right

Owner name: XINCHENG LOGIC MOBILE CO., LTD.

Free format text: FORMER OWNER: TRUSTED LOGIC

Effective date: 20120724

C41 Transfer of patent application or patent right or utility model
TR01 Transfer of patent right

Effective date of registration: 20120724

Address after: French Meudon

Patentee after: Fidelity logic Mobile Corporation

Address before: French Meudon

Patentee before: Trusted Logic

CP03 Change of name, title or address

Address after: Fa Guofanboen

Patentee after: Xintani company

Address before: Fa Guomodong

Patentee before: Fidelity logic Mobile Corporation

CP03 Change of name, title or address