EP1246135A2 - Verfahren zur Aufzeichnung eines Verbrauchswertes und Verbrauchszähler mit einem Messwert - Google Patents
Verfahren zur Aufzeichnung eines Verbrauchswertes und Verbrauchszähler mit einem Messwert Download PDFInfo
- Publication number
- EP1246135A2 EP1246135A2 EP02090093A EP02090093A EP1246135A2 EP 1246135 A2 EP1246135 A2 EP 1246135A2 EP 02090093 A EP02090093 A EP 02090093A EP 02090093 A EP02090093 A EP 02090093A EP 1246135 A2 EP1246135 A2 EP 1246135A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- consumption
- message
- security module
- delivery
- module
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Images
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00733—Cryptography or similar special procedures in a franking system
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F15/00—Coin-freed apparatus with meter-controlled dispensing of liquid, gas or electricity
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00016—Relations between apparatus, e.g. franking machine at customer or apparatus at post office, in a franking system
- G07B17/0008—Communication details outside or between apparatus
- G07B2017/00153—Communication details outside or between apparatus for sending information
- G07B2017/00169—Communication details outside or between apparatus for sending information from a franking apparatus, e.g. for verifying accounting
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00185—Details internally of apparatus in a franking system, e.g. franking machine at customer or apparatus at post office
- G07B17/00193—Constructional details of apparatus in a franking system
- G07B2017/00258—Electronic hardware aspects, e.g. type of circuits used
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00733—Cryptography or similar special procedures in a franking system
- G07B2017/00741—Cryptography or similar special procedures in a franking system using specific cryptographic algorithms or functions
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00733—Cryptography or similar special procedures in a franking system
- G07B2017/00959—Cryptographic modules, e.g. a PC encryption board
Definitions
- the invention relates to a method for recording a consumption value, according to the type specified in the preamble of claim 1 and a consumption meter with a transmitter, according to the in the preamble of claim 10 specified type.
- the consumption meter has a security module to increase security against counterfeiting. On such can be used in consumption meters and similar devices be in a potentially unfriendly environment, for example in mechanical engineering companies, in public or private buildings, work.
- a message authentication code can be generated for data from the above-mentioned DAC or for messages using a symmetrical crypto-algorithm, such codes being used for authentication verification.
- MAC message authentication code
- asymmetric crypto-algorithm The advantage of an asymmetric crypto-algorithm is given by a public key justified.
- a well-known asymmetric crypto algorithm named after its inventors R.Rivest, A.Shamir and L.Adleman named and described in US 4,405,829 is the RSA algorithm.
- the recipient decrypts with a private secret key an encrypted message, which when Sender was encrypted with a public key. The The recipient keeps his private key secret but sends it associated public key to potential senders.
- RSA was that first asymmetric procedure that can be used both for key transmission as well as for creating digital signatures.
- the private key can also be used to generate digital signatures, the public keys being used to authenticate the signature.
- Both RSA and digital signature algorithms use two keys, one of the two keys being public. The keys are used in the reverse order.
- DSS digital signature standard
- DSA digital signature algorithm
- the data processing of a hash function is even two to four orders of magnitude faster than the data processing of the digital signature or asymmetrical encryption.
- the creation of a checksum is a very simple example of a hash function.
- the byte sequence of information is, on the one hand, compressed into a hash value and, on the other hand, the hash value differs from other hash values that were formed from other information.
- the one-way hash functions used in cryptography, it is almost impossible to form another byte sequence that gives the same hash value.
- the one-way hash functions should generally not be reversible.
- a one-way hash function MD5 developed by Ron Rivest in 1991 has a 128-bit hash value but is not supposed to be as secure as MD160 or SHA (Secure Hash Algorithm). The latter two use a 160-bit hash value.
- the SHA was developed by the NIST with the collaboration of the NSA and published in 1994. The SHA is part of the Digital Signature Algorithm (DAS).
- DAS Digital Signature Algorithm
- the collected records can be sent to a third party for inspection.
- a message authentication code (MAC) could be attached to each individual recording. This requires the central storage of a secret key, which is unique for each security module.
- a security module (EP 1.035.513 A2, EP 1.035.516 A2, EP 1.035.517 A2, EP 1.035.518 A2) that uses a symmetrical crypto-algorithm is already used in a franking machine of the JetMail® type.
- a key transmission between the security module and a data center takes place by means of a DES-encrypted data record, which is also MAC-secured.
- the cryptographic calculation is only one of the security measures when billing services and calculating a fee for the delivery of the services and when transmitting the billing result or the booking to a remote data center.
- a security module must also survive a physical or chemical attack. Such an attack can also be detected and recorded.
- EP 504 843 B1 (US 5,243,654) already has a fee entry system with remotely resettable time lock and with one Device proposed to deliver a bookable size (Energy) is equipped, forcing the user of a device to do so is, the data center regularly the state of the accounting register tell.
- the disadvantage is that there is no safety module and that a user must enter a combination into the device.
- the only security measure is a seal or a seal on Consumption meter provided. If this security measure is circumvented can record the consumption value with forgery be manipulated. Through such manipulations (Energy) utilities regularly lose a lot of money. While on the one hand the large customers are offered the opportunity to On the other hand, small customers will save money legally at low tariffs there was no incentive to use discounted tariffs. It is obvious only at peak times of consumption, for example, the energy more expensive or to provide the service more difficult, which of course then Customers of the service or utility company in authorized Way is billed.
- the object is with the features of claim 1 for the method or with the features of claim 10 for the consumption meter solved.
- the latter is equipped with a security module.
- a consumption meter is a device with the supply and discharge of matter, Energy or information by determining a bookable quantity.
- On Security module is a recording module equipped with security means for booking or billing a tax fee and for the formation of a message about the aforementioned record.
- On The consumer pays with a security module and with a means of communication equipped, the latter an automatic and secure communication with a remote server of the service or Utilities allowed.
- the determination of a bookable Size such as the energy in an energy meter, requires an analog / digital conversion of at least one analog Measured variable and a calculation based on a first mathematical Algorithm.
- the safety module has an internal A / D converter and equipped with a microprocessor, which is used for the calculation the first mathematical algorithm is programmed.
- the service or consumption-dependent billing of a tax takes place based on a real time in temporarily different Wise. For example, tariffs for day and night, working days and Weekend, summer and winter are different.
- the security module is with an internal battery powered real time clock and a Accounting unit, for example a hardware accounting unit, fitted. After billing the tax fee according to related Tariff according to the consumption period and the current time formation of a message to record at least the submission fee.
- the record can include consumption, the associated tariff, the consumption period and the current time.
- the recording is secured by an authentication code.
- the time periods are periodically and / or event-based.
- the security module is used to calculate the authentication code programmed a first cryptographic algorithm.
- the security module is equipped with a watchdog timer, which is the means of communication regularly for communication with the remote Unlocks the server. A failed attempt to communicate will occur at intervals repeated until a connection is established or until a credit line is exceeded. In the latter case, the Consumption counter blocked for the delivery of consumption values.
- the server monitors whether the consumption meter of the Customers received a message and whether the latter is authentic.
- the Message contains encrypted and additionally with a digital signature backed up data, which by means of the microprocessor after a second cryptographic algorithm and encrypted after a third cryptographic algorithm.
- the microprocessor monitors whether manipulated on the consumption meter or on the security module has been. For example, a sensor is provided to determine whether the consumption meter is illegally disconnected or bypassed has been.
- the message to the server contains appropriately secured Sensor data.
- the server can submit the consumption value in Block evaluation of the transmitted data.
- An asymmetrical encryption method is used for the message second cryptographic algorithm used to encrypt an Data record with delivery or consumption values, time data, sensor data if necessary keys etc.
- Exchange data For example, is suitable the RSA procedure, whereby a data record with a Public key of the recipient is encrypted. At the recipient the encrypted data record is decrypted with the associated private key of the recipient.
- a digital signature based on a third cryptographic Algorithm is done, for example, with the reverse RSA method, where the sender has a hashed data record with a private key of the Sender is encrypted and at the recipient with the associated one Sender's public key is decrypted.
- the above recovered hashed record is hashed Comparison data set compared.
- the comparison data record is sent to the recipient from the encrypted record by decryption and Application of the same hash function is generated. If they match of the recovered hashed record with the hashed For comparison data record, the message received from the server is considered authentic and the transmitted values are saved.
- An encryption key ek is public and a decryption key dk is private.
- the public encryption key ek, n is transmitted to the subscriber at the place of sending a message.
- an authentic channel or certificate must be used to ensure that the public encryption key is not exchanged between the place of destination and the place of dispatch and is misused as part of a "man in the middle attack”.
- a mathematical operation is provided to encrypt the message m at the sending location for the ciphertext c: c ⁇ encrypt (ek, m)
- the ciphertext c can now be transmitted to the destination via an unsecured channel.
- An operation is provided to decrypt the ciphertext c: m ⁇ decrypt (dk, c)
- the second participant at the destination decrypts the cipher text c with the private decryption key dk for the message: m ' ⁇ c dk (mod n).
- dk the private decryption key
- a public verification key vk, n is transmitted to the second subscriber at the destination, for example secured via an authentic channel or a certificate.
- the message m and the signature can now be transmitted to the second subscriber at the destination via an unsecured channel.
- a mathematical operation is provided to generate a signature sig by the security module at the sending location of a first participant: sig ⁇ sign (sk, m)
- a private signing key sk of the security module and, for example, the so-called modular arithmetic or congruence calculation are used for signing at the sending location of a first participant: sig ⁇ h sk (mod n)
- a public verification key vk the unencrypted message m and a mathematical operation of the type are provided: acc ⁇ verify (vk, m, sig). where the result can be true (valid) or false (invalid).
- the second participant uses the public verification key vk to verify the signature sig for the hash value h ', which, according to the laws of modular arithmetic, matches the hash value h formed from the original message m if h' and sig vk are congruently modulo n.
- h h ' ⁇ sig vk (mod n)
- each communication participant with a Security module or a security box is equipped, which before the communication in which messages are transmitted, Exchange public keys through an authentic channel.
- The can preferably be done at the seller or dealer of the security module or at the manufacturer.
- the key exchange between a security module and a security box is explained in more detail using the illustration shown in FIG. First, a key pair is generated in both.
- the security module SM generates a public encryption key ek SM and a private decryption key dk SM .
- the security module SM also generates a public verification key vk SM and a private signing key sk SM .
- the security box BOX generates a public encryption key ek BOX and a private decryption key dk BOX .
- the security box BOX also generates a public verification key vk BOX and a private signing key sk BOX .
- the public keys are transmitted to the respective communication participant.
- the public encryption key ek BOX and the public verification key vk BOX are transmitted from the security box BOX 200 to the security module SM 100 and stored there.
- the public encryption key ek SM and the public verification key vk SM are transmitted from the security module SM 100 to the security box BOX 200 and stored there.
- FIG. 4 shows a representation of the system for cryptographically secured communication via an unsecured channel.
- the consumption meter 1 is connected to the utility server 2 via ISDN, DECT telephone, Internet, power line or another network.
- the consumption meter 1 has a security module SM 100, which is equipped with a public encryption key ek BOX of the security box BOX 200 for encrypting / decrypting a message m.
- a second cryptographic algorithm based on equations (2) and (5), an encryption text M1 is first formed and a hash function is applied to the message m, the hash value h1 ⁇ hash (m) being produced.
- a signature sig SM ⁇ sign [sk SM , h1] is generated by the security module SM 100.
- the EVU server 2 With its private decryption key dk BOX, the EVU server 2 decrypts the ciphertext M1 for the message m1 and checks its authenticity using the signature.
- the RU server 2 generates a message m2 transmits the message encrypted to the encrypted text M2 to the security module in a data record D2.
- the message m2 can include an activation code for the consumption meter 1.
- the message m1 contains consumption and booking data or delivery values and accounting values, time data and other data. It can be further evaluated by the EVU server in order to generate a bill according to the valid tariff.
- the data record D2 transmitted to the security module SM 100 also contains an encryption text M2 and the digital signature sig BOX . The authenticity of the activation code can be verified by means of the latter. When the cryptographically secured activation code is received in the form of a second data record D2, the change is recorded by resetting the submission fee to zero if the activation code was genuine. Otherwise the consumption meter is blocked.
- FIG. 5 shows an illustration of a consumption meter, for example an electricity or energy meter 1.
- the latter is between a power cable 8 and a house power cable 6 switched and with a display unit 4 for equipped with energy consumption.
- a security housing 10 of the Electricity or energy meter 1 is with a security lock 9 fitted.
- Other special features are a window 7 for an additional one Status display of the security module (not visible) and on optional cable 5 for a communication connection with an EVU server for example via the ISDN telephone network.
- FIG. 6 shows a block diagram of an energy meter 1.
- the latter could replace a conventional household meter (induction meter for single-phase alternating current with a Ferrari measuring mechanism).
- the switch S1 could be connected to the security module, which is also opened when the security housing 10 is opened.
- the status display by means of LEDs 107, 108 signals an unauthorized opening even after the safety housing 10 has been closed again.
- a trigger switch S2 for resetting is connected on the hardware side. It is triggered, for example, when the security lock 9 is switched to a second switching position. Resetting the status of the SM 100 is only permitted to a commissioned inspector who has a corresponding key and initiates communication with the power supply server to register or notify the inspection.
- transducers 104, 105 for current or voltage measurement provide an analog measurement signal i (t), u (t) after full-wave rectification, which is converted into a digital signal by DA converter 102, 103 and then to the data inputs of the SM 100 security module is created.
- the instantaneous values of the rectified voltage u (t), which drops, for example, across a load resistor R or which results from a magnetic induction for an inductance L at a load current i u (t) L ⁇ di / dt, are calculated using a multiplexer Microprocessor of the SM 100 scanned if two data inputs have to be scanned alternately.
- the microprocessor calculates the delivery fee according to the associated tariff in accordance with the consumption period and stores it in separate memory areas of the non-volatile memory together with the associated current consumption value V K.
- User data can be stored further in order to determine user behavior or to derive marketing data.
- V1 K , F1 K , V2 K , F2 K , t j is compiled with further data #K, R, to form a data record:
- INPUT #K, R, V1 K , F1 K , V2 K , F2 K , t j
- #K 13 for a 13th record:
- INPUT '13RTages consumption, Mr.PauschingerTages consumption fee Night consumption, Mr.PauschingerNight consumption fee 8491028108032001
- the authentication code A K is calculated from INPUT by forming the hash value.
- a K '8023024892048398'.
- the resulting authentication code A K is added to the real-time message.
- a data record D1 is transmitted periodically by the security module at the place of dispatch to a security box of an EVU server on Destination.
- a public encryption key ek BOX of the box and a private signing key sk SM of the security module 100 are stored non-volatile in the security module 100.
- the microprocessor of the security module 100 is programmed to work as an authentication machine by a program stored in the internal program memory.
- the digital signature is generated with the sk SM signature key of the SM 100 security module: sig SM ⁇ sign [sk SM , h1]
- the microprocessor of the security module SM 100 encrypts the message m1 with the encryption key ek BOX of the security box for the encryption text M1: M1 ⁇ encrypt [ek BOX , m1]
- Each consumption meter 1 contains a communication unit 101 for communication with the server 2, which has a comparable communication unit (not shown).
- a private decryption key dk BOX of the box and a public verification key vk SM of the security module 100 are stored in a non-volatile manner in the security box 200 of the server 2.
- the microprocessor of the safety box 200 is programmed to work as a verification machine by means of a program stored in the internal program memory.
- the server 2 works adapted to the respective way of generating the record. The analysis of the recording stream retrieved by the server 2 from the security module 100 depends on the corresponding application.
- FIGS. 5 and 6 show an ISDN cable 5 connected to the consumption meter 1.
- the communication device 101 is a modem, preferably an ISDN module, which communicates with the server 2 via a telephone / ISDN network connected is.
- a corresponding communication unit 101 can be supplied with energy from the telephone / ISDN network or via a line 106 from the power supply unit or from the house power cable 6.
- EVU energy supply company
- the communication device 101 is now a power line module, which is communicatively connected to the server 2 via an energy supply network.
- the power line module is designed to transmit a message with transmission rates of up to 1 Mbit / s via a line 106 via power cable 8 to the utility server 2.
- the existing power supply cables are used as a physical carrier medium for a communication network.
- the above-mentioned ISDN cable 5 is omitted.
- Another alternative for avoiding cable connections is provided by a 2.4 GHz Bluetooth radio receiver / transmitter module, which is used as communication device 101. It is provided that the communication device 101 is integrated in the security module 100.
- a blue-tooth module that is to be connected to the server 2 via a wireless connection via a further blue-tooth module, however, can only communicate with the same Bluetooth module over relatively short distances of approximately 10 m, so that the latter can be used again is connected to an ISDN terminal.
- the further blue tooth module is thus communicatively connected to the server 2 again via a telephone network.
- the ISDN network is used again.
- the security module SM 100 can be supplied with energy via the house power cable 6 or the power cable 8 from the energy network.
- This requires a power supply unit N 109, which is preferably connected so that the electricity customer bears the costs.
- the ground connection at pin P23 receives the negative and the operating voltage connection at pin P25 the positive voltage potential.
- An electrolytic capacitor C buffers the operating voltage.
- the consumption meter 1 has a safety housing 10, which encloses the safety module 100, a display unit 4, a feed and delivery device 8, 6 and a communication device 101.
- the safety module 100 is connected to at least one sensor 104, 105, to the display unit 4 for displaying a consumption value and to safety means S1, S2, 18.
- the security module 100 has a non-volatile memory 124, 129 for storing temporarily valid tariffs and is programmed to calculate a delivery fee based on the consumption value based on the tariff and to respond to a response of the security means S1, S2, 18 and to values of the sensors 104, 105 , which signal manipulation with the intention of forgery.
- the safety module internally contains a lithium battery 134 for data retention of the non-volatile stored data in order to enable an emergency supply in the event of a power failure.
- the time is also stored in addition to the cumulative power, so that disconnection from the energy supply network can subsequently be distinguished from the voltage failure in the energy supply network. If there is no system voltage, the SM 100 safety module simply switches to emergency supply via battery 134.
- the safety module 100 functions as a voltage monitor to check whether the counter has been disconnected or not.
- the consumption meter 1 has at least one analog / digital converter 102, 103, which is connected to the at least one sensor 104, 105.
- the security module 100 has an analog / digital converter 127 integrated, which is connected to the sensors 104, 105.
- the security module 100 has a real-time counter 122 and the security module 100 performs the function of a watch dog timer in order to regularly transmit counter readings to a server 2. Because the security module 100 has a real-time counter 122, the microprocessor of the security module 100 can access the temporarily valid tariff, which is stored in the non-volatile memory.
- the microprocessor of the security module 100 is programmed to calculate a delivery fee based on the consumption value depending on the tariff.
- the communication unit 101 can be in the security module SM 100 integrated and possibly implemented as ASIC. This is suitable the modern digital communication technology, for example a Bluetooth module. The latter gives a transmission power of approx. 1mW over a short one Antenna 51 off.
- the integrated real-time clock 122 of the Microprocessor 120 takes over the security functions described above also the timing of the communication.
- the security modules 100 of the consumption meters of different customers can be programmed for different days for communication so that do not call everyone at the same time.
- the EVU server 2 may transmit new current tariffs, including Version number and validity date of the tariffs, for the purpose of storage in the Security module.
- the microprocessor has an internal RAM 124, which is battery powered. If the latter is not enough, another will battery-backed SRAM 129 integrated in the safety module and operates in addition to RAM 124 of microprocessor 120 for the purpose of non-volatile Storage of tariff values in predetermined time ranges are valid.
- the integrated real-time clock 122 provides real-time data.
- the Microprocessor 120 takes over the evaluation of time data for tariff-dependent Determination of at least one consumption value.
- a CPU 121 of the microprocessor 120 picks up events the temporarily valid tariff in SRAM 129, the latter the data for the delivery fee of a data processing unit designed as ASIC 150 passes.
- Billing takes place via ASIC 150 in the non-volatile Save NVRAM 114, 116.
- NVRAMs are off Two different storage technologies are used for security reasons.
- Billing takes place at event and time-determined intervals formation of a message indicating the consumption value, the delivery fee and includes the time data, formation of a verification code and securing the message using the verification code.
- the verification code is calculated by the CPU of the microprocessor 120.
- the ASIV 150 takes formation and recording of a message m1, which contains the message and the verification code.
- securing the Record consumption preferably at the end of each period the period of consumption takes place, the periods being periodic and / or event-based.
- An event is, for example a tariff or load change.
- the microprocessor 120 carries out a cryptographic analysis at larger intervals Securing a message and communicating with one remote server 2 through, for the transmission of the cryptographically secured Message in the form of a first data record D1.
- the security box 200 of server 2 verifies and decrypts the message. Only if a verification of the authenticity of the message is made by the server 2 Activation code generated.
- the security box 200 of the server 2 can Secure the activation code by encrypting and signing.
- the security module 100 of the consumption meter 1 can confirm the authenticity of the activation code verify based on the signature of server 2.
- the consumption meter is a franking machine.
- the bookable size is then the franking value.
- Further versions of other assemblies of the security module are the publications EP 1.035.513 A2, EP 1.035.516 A2, EP 1.035.517 A2, EP 1.035.518 A2, DE 20020635 U1 remove.
- the evaluation of the monitoring functions and cryptographic Calculations are done in the microprocessor.
- the first cryptographic Authentication code generation algorithm for Record data is a hash function, for example. Of course you can instead of the authentication code also a checksum or a MAC formed according to a symmetrical encryption algorithm be used.
- the billing function of the ASIC's 150 are taken over or checked by the microprocessor 120.
Landscapes
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Telephonic Communication Services (AREA)
- Storage Device Security (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
Unter dem Titel: "Methode and arrangement for generating and checking a security imprint" wurde bereits in der US 5.953.426 ein spezielles Secret Key Verfahren vorgeschlagen. Der geheime Schlüssel (Secret Key) wird in einer sicheren Datenbank an der Verifizierungsstelle, typischerweise bei der Postbehörde, aufgehoben und damit geheim gehalten. Aus den Daten einer zu übermittelnden Botschaft wird ein Data Authentication Code (DAC) gebildet, der in eine Markierungssymbolreihe umgesetzt wird, welche dann als sogenannte digitale Unterschrift zur Authentifikationsprüfung der Botschaft verwendet werden kann. Dabei wird der auch aus der US 3,962,539 bekannte Data Encryption Standard (DES)-Algorithmus angewendet. Letzterer ist der bekannteste symmetrische Kryptoalgorithmus. Mit einem symmetrischen Kryptoalgorithmus lassen sich bei Daten des o.g. DAC oder bei Mitteilungen ein Message Authentifications Code (MAC) erzeugen, wobei solche Code zur Authentifikationsprüfung verwendet werden. Beim symmetrischen Kryptoalgorithmus steht dem Vorteil eines relativ kurzen MAC's der Nachteil eines einzigen geheimen Schlüssel gegenüber.
Es wurde schon ein Digital Signatur Standard (DSS) entwickelt, der eine kürzere digitale Unterschrift liefert und zu dem der Digital Signatur Algorithm (DSA) nach US 5,231,668 gehört. Diese Entwicklung erfolgte ausgehend von der Identifikation und Signatur gemäß dem Schnorr-Patent US 4,995,085 und ausgehend vom Schlüsseltausch nach Diffie-Hellman US 4,200,770 bzw. vom ElGamal-Verfahren (El Gamal, Taher, "A Public Key Cryptosystem and a Signatur Scheme Based on Diskrete Logarithms", 1III Transactions and Information Theory, vol. IT-31, No. 4, Jul.1985). Beim asymmetrischen Kryptoalgorithmus steht dem Vorteil des Verwendens eines öffentlichen Schlüssels der Nachteil einer relativ langen digitalen Unterschrift gegenüber.
Bei einer Frankiermaschine vom Typ JetMail® wird bereits ein Sicherheitsmodul (EP 1.035.513 A2, EP 1.035.516 A2, EP 1.035.517 A2, EP 1.035.518 A2) eingesetzt, das einen symmetrischen Kryptoalgorithmus nutzt. Eine Schlüsselübertragung zwischen dem Sicherheitsmodul und einer Datenzentrale erfolgt mittels einem DES-verschlüsselten Datensatz, welcher außerdem MAC-gesichert ist. Die kryptographische Berechnung ist aber nur eine der Sicherheitsmaßnahmen bei einer Abrechnung von Dienstleistungen und Berechnung einer Gebühr für die Abgabe der Dienstleistungen sowie bei einer Übermittung des Abrechnungsergebnisses bzw. der Buchung zu einer entfernten Datenzentrale. Ein Sicherheitsmodul muß auch einen physikalischen oder chemischen Angriff überstehen. Ein solcher Angriff kann ebenfalls detektiert und aufgezeichnet werden.
- Figur 1,
- Darstellung eines bekannten RSA-Verfahrens,
- Figur 2,
- Darstellung eines Signier-Verfahrens unter Anwendung von RSA,
- Figur 3,
- Darstellung des Schlüsseltausches,
- Figur 4,
- Darstellung des Systems für eine kryptigraphisch gesicherte Kommunikation,
- Figur 5,
- Darstellung eines Verbrauchszählers,
- Figur 6,
- Blockschaltbild eines Energieverbrauchszählers,
- Figur 7,
- Blockschaltbild eines Sicherheitsmoduls.
- #K:
- Sequenzzähler ('13'),
- R:
- Typbezeichner der Nachricht ('R' für Realtime),
- V1K:
- Verbrauchs- und Nutzdaten ('Tages-Verbrauch,Mr. Pauschinger'),
- F1K:
- Abgabegebühr nach erstem Tarif ('Tages-Verbrauchsgebühr'),
- V2K:
- Verbrauchs- und Nutzdaten ('Nacht-Verbrauch,Mr. Pauschinger'),
- F2K:
- Abgabegebühr nach zweitem Tarif ('Nacht-Verbrauchsgebühr'),
- tj:
- aktueller Echtzeitwert (dezimalisiert: '8491028108032001') mit fester Länge,
- AK:
- Authentisierungscode (dezimalisiert : '8023024892048398'), i.e. Unterschrift, typischerweise mit fester Länge,
AK = '8023024892048398'.
Alternativ ist es möglich, einen vorhandenen Digital-Powerline-Dienst des Enegieversorgungsunternehmens (EVU) zu nutzen. Die Kommunikationseinrichtung 101 ist nun ein Power-line-Modul, der über ein Enegierversorgungsnetz mit dem Server 2 kommunikativ verbunden ist. Der Power-line-Modul ist entsprechend ausgebildet eine Nachricht mit Übertragungsraten bis zu 1Mbit/s über eine Leitung 106 via Stromkabel 8 zum EVU-Server 2 zu übertragen. Dabei werden die vorhandenen Stromversorgungskabel als physikalisches Trägermedium für ein Kommunikationsnetzwerk genutzt. Dabei entfällt natürlich das o.g. ISDN-Kabel 5.
Eine weitere Alternative zur Vermeidung von Kabelverbindungen bietet ein 2,4 GHz Bluetooth-Funkempfänger/Sender-Baustein, der als Kommunikationseinrichtung 101 eingesetzt wird. Es ist vorgesehen, dass die Kommunikationseinrichtung 101 im Sicherheitsmodul 100 integriert ist. Ein Blue-Tooth-Modul, der drahlos über einen weiteren Blue-Tooth-Modul mit dem Server 2 kommunikativ verbunden werden soll, kann aber nur über relativ kurze Entfernungen ca. 10 m mit einem gleichen Bluetooth-Baustein kommunizieren, so dass letzterer doch wieder an ein ISDN-Endgerät angeschlossen ist. Somit ist der weitere Blue-Tooth-Modul wieder über ein Telefonnetz mit dem Server 2 kommunikativ verbunden. Zum Beispiel wird wieder das ISDN-Netz genutzt.
Das Sicherheitsmodul SM 100 kann über das Hausstromkabel 6 oder das Stromkabel 8 aus dem Energienetz mit Energie versorgt werden. Dazu ist ein Netzteil N 109 erforderlich, welches vorzugsweise so angeschlossen ist, daß der Stromkunde die Kosten trägt. Der Masseanschluß an Pin P23 erhält zum Beispiel das negative und der Betriebsspannungsanschluß an Pin P25 das positive Spannungspotential. Ein Elektrolytkondensator C puffert die Betriebsspannung. An den Anschlüssen P1, P2 liegt eine Leiterschleife, die sich über das gesamte Sicherheitsgehäuse erstreckt und beim Zerstören des Sicherheitsgehäuses 10 unterbrochen wird. Es ist vorgesehen, dass der Verbrauchszähler 1 ein Sicherheitsgehäuse 10 aufweist, welches den Sicherheitsmodul 100, eine Anzeigeeinheit 4 eine Zuführ- und Abgabeeinrichtung 8, 6 und eine Kommunikationseinrichtung 101 umschließt. Der Sicherheitsmodul 100 ist mit mindestens einem Meßwertgeber 104, 105, mit der Anzeigeeinheit 4 zur Anzeige eines Verbrauchswertes sowie mit Sicherheitsmitteln S1, S2, 18 verbunden. Der Sicherheitsmodul 100 weist einen nichtflüchtigen Speicher 124, 129 zur Speicherung temporär gültiger Tarife auf und ist programmiert, eine Abgabegebühr basierend auf dem Verbrauchswert tarifabhängig zu berechnen und auf ein Ansprechen der Sicherheitsmittel S1, S2, 18 sowie auf Werte der Meßwertgeber 104, 105 zu reagieren, welche eine Manipulation in Fälschungsabsicht signalisieren. Das Sicherheitsmodul enthält intern eine Lithium-Batterie 134 zur Datenerhaltung der nichtflüchtig gespeicherten Daten, um eine Notversorgung bei Energieausfall zu ermöglichen. Bei den nichtflüchtig gespeicherten Daten wird zusätzlich zur kumulierten Leistung auch die Zeit gespeichert, so daß eine Abtrennung vom Energieversorgungsnetz nachträglich unterschieden werden kann vom Spannungsausfall im Energieversorgungsnetz. Das Sicherheitsmodul SM 100 schaltet bei fehlender Systemspannung einfach auf Notversorgung via Batterie 134 um.
Der Sicherheitsmodul 100 nimmt die Funktion eines Spannungswächters wahr, um zu überprüfen, ob der Zähler abgeklemmt wurde oder nicht. Der Verbrauchszähler 1 hat mindestens einen Analog/Digital-Wandler 102, 103, der mit dem mindestens einen Meßwertgeber 104, 105 verbunden ist. Alternativ hat der Sicherheitsmodul 100 einen Analog/Digital-Wandler 127 integriert, der mit den Meßwertgebern 104, 105 verbunden ist. Der Sicherheitsmodul 100 weist einen Echtzeitzähler 122 auf und der Sicherheitsmodul 100 nimmt die Funktion eines Watch dog Timers wahr, um regelmäßig Zählerstände an einen Server 2 zu übermitteln. Dadurch dass das Sicherheitsmodul 100 einen Echtzeitzähler 122 aufweist, kann der Mikroprozessor des Sicherheitsmoduls 100 auf den temporär gültigen Tarif zugreifen, der im nichtflüchtigen Speicher gespeichert ist. Der Mikroprozessor des Sicherheitsmoduls 100 ist programmiert, eine Abgabegebühr basierend auf dem Verbrauchswert tarifabhängig zu berechnen.
Als geeigneter Mikroprozessor µP 120 eignet sich der Typ S3C44A0X von Firma Samsung vor. Letzterer weist zusätzlich Analogeingänge für Analogwerte u(t), i(t), einen internen Multiplexer (nicht gezeigt) und einen internen AD-Wandler 127 auf, so dass separate AD-Wandler entfallen können. An den Analogeingängen werden 4 Leitungen für die Analogwerte u(t), i(t) angeschlossen. Außerdem wird mittels integriertem LCD-Controller (nicht gezeigt) eine am Ein/Ausgangsinterface 125 angeschlossene externe LCD-Anzeige 4 unterstützt. Am Ein-/Ausgangsinterface 125 sind externe Leuchtdioden 107, 108 zur Zustandsanzeige angeschlossen. Der Status des Sicherheitsmoduls 100 kann vorteilhaft über eine Bicolor-Leuchtdiode anstelle der Leuchtdioden 107, 108 signalisiert werden. Eine Statusmeldung kann weitere Datenelemente umfassen, zum Beispiel:
- Detektionsdaten einer Manipulation am Gehäuse,
- Detektionsdaten einer Manipulation am Sicherheitsmodul,
- Versionsnummer und Gültigkeitsdatum der Tarife,
- Spitzenlast und Uhrzeit der Spitzenbelastung,
- Nächster Kommunikationstermin usw.
Claims (20)
- Verfahren zur Aufzeichnung eines Verbrauchswertes, der in Auswertung von Meßwerten ermittelt wird, umfassend die Schritte:nichtflüchtige Speicherung von Tarifwerten, die in vorbestimmten Zeitbereichen gültig sind,Liefern und Verarbeitung von Meßwerten über die Zufuhr und Abgabe von Materie, Energie oder Information, wobei deren Verarbeitung nach einem ersten mathematischen Algorithmus erfolgt,Liefern und Auswerten von Zeitdaten zur zeitabhängigen Ermittlung mindestens eines Verbrauchswertes bezogen auf Materie, Energie oder Information,tarifabhängige Ermittlung mindestens einer Abgabegebühr entsprechend des vorgenannten Verbrauchswertes,Bildung einer Nachricht, welche mindestens die Abgabegebühr einschließt,Bildung eines Überprüfungscodes und Sichern der Nachricht mittels des Überprüfungscodes,Bildung und Aufzeichnung einer Mitteilung (m1), welche die Nachricht und den Überprüfungscode enthält,Aufnahme einer Kommunikation mit einem entfernten Server (2), zur Übermittlung der kryptographisch gesicherten Nachricht in Form eines ersten Datensatzes (D1).
- Verfahren, nach Anspruch 1, gekennzeichnet durch Wiederholung der Aufnahme einer Kommunikation mit einem entfernten Server (2), zur Übermittlung der kryptographisch gesicherten Nachricht in Form eines ersten Datensatzes (D1), und bei erfolgloser Wiederholung solange, bis ein Kreditrahmen überschritten ist, sowie Empfangen eines, nach dem Überprüfen der Echtheit des ersten Datensatzes (D1) vom Server (2) übermittelten, kryptographisch gesicherten Freischaltcodes in Form eines zweiten Datensatzes (D2), Überprüfen der Echtheit des Freischaltcodes anhand der Signatur des Servers (2) und Aufzeichnung des Ereignisses.
- Verfahren, nach Anspruch 1, dadurch gekennzeichnet, dass die gebildete Nachricht den Verbrauchswert, die Abgabegebühr und Zeitdaten einschließt, dass die Sicherung der Nachricht und die Aufzeichnung des Verbrauchs vorzugsweise am Ende jedes Zeitabschnittes der Verbrauchszeitdauer erfolgt, wobei die Zeitabschnitte periodisch und/oder ereignisbasierend gebildet werden.
- Verfahren, nach Anspruch 2, dadurch gekennzeichnet, dass beim Empfangen des kryptographisch gesicherten Freischaltcodes eine Aufzeichnung der Änderung der Abgabegebühr durch Rücksetzen auf Null erfolgt, wenn der Freischaltcode echt war sowie dass ein Sperren der Abgabe einer verbuchbaren Größe bzw. des Verbrauches eines Verbrauchswertes vorgenommen wird, wenn der Freischaltcode unecht ist.
- Verfahren, nach Anspruch 1, dadurch gekennzeichnet, dass eine Analog/Digital-Wandlung der Meßwerte vor deren Verarbeitung erfolgt, wobei deren Verarbeitung eine Aufzeichnung einschließt, dass bei einem Ereignis eine Berechnung der Abgabegebühr nach dem zugehörigen Tarif entsprechend der Verbrauchszeitdauer und bei der Aufzeichnung eine Speicherung der Abgabegebühr zusammen mit dem jeweils zugehörigen aktuellen Verbrauchswert VK erfolgt.
- Verfahren, nach Anspruch 5, dadurch gekennzeichnet, dass das Ereignis ein Tarif- oder Lastwechsel ist.
- Verfahren, nach Anspruch 3, dadurch gekennzeichnet, dass bei der Aufzeichnung eine weitere Abspeicherung von Nutzdaten erfolgt, um das Benutzerverhalten zu ermitteln bzw. um Marketingdaten abzuleiten.
- Verfahren, nach Anspruch 1, dadurch gekennzeichnet, dass der Überprüfungscode ein Authentisierungscode ist.
- Verfahren, nach Anspruch 8, dadurch gekennzeichnet, dass der Authentisierungscode ein Hashcode oder ein nach einem symmetrischen Verschlüsselungsalgorithmus gebildeter MAC ist.
- Verbrauchszähler, mit einem Meßwertgeber, dadurch gekennzeichnet, dass der Verbrauchszähler (1) ein Sicherheitsgehäuse (10) aufweist, welches einen Sicherheitsmodul (100), eine Zuführ- und Abgabeeinrichtung (8, 6) und eine Kommunikationseinrichtung (101) umschließt, wobei der Sicherheitsmodul (100) mit mindestens einem Meßwertgeber (104, 105) sowie mit Sicherheitsmitteln (S1, S2, 18) verbunden ist, dass der Sicherheitsmodul (100) einen nichtflüchtigen Speicher (124, 129) zur Speicherung temporär gültiger Tarife aufweist und programmiert ist, eine Abgabegebühr basierend auf dem Verbrauchswert tarifabhängig zu berechnen und auf ein Ansprechen der Sicherheitsmittel (S1, S2, 18) sowie auf Werte der Meßwertgeber (104, 105) zu reagieren, welche eine Manipulation in Fälschungsabsicht signalisieren.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass der Verbrauchszähler (1) mindestens einen Analog/Digital-Wandler (102, 103) aufweist, der mit dem mindestens einen Meßwertgeber (104, 105) verbunden ist und dass der Sicherheitsmodul (100) eine Überwachungsfunktion aufweist, um zu überprüfen, ob der Zähler abgeklemmt wurde oder nicht.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass das Sicherheitsmodul (100) einen Analog/Digital-Wandler (127) aufweist, der mit den Meßwertgebern (104, 105) verbunden ist und dass der Sicherheitsmodul (100) eine Überwachungsfunktion aufweist, um zu überprüfen, ob der Zähler abgeklemmt wurde oder nicht.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass das Sicherheitsmodul (100) einen Echtzeitzähler (122) aufweist und dass der Sicherheitsmodul (100) die Funktion eines Watch dog Timers aufweist, um regelmäßig Zählerstände an einen Server (2) zu übermitteln.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass das Sicherheitsmodul (100) einen Echtzeitzähler (122) aufweist und dass ein Mikroprozessor (120) des Sicherheitsmoduls (100) auf den temporär gültigen Tarif zugreift, der im nichtflüchtigen Speicher (124, 129) gespeichert ist und programmiert ist, eine Abgabegebühr basierend auf dem Verbrauchswert tarifabhängig zu berechnen.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass die Kommunikationseinrichtung (101) ein ISDN-Modul ist, der über ein Telefonnetz mit dem Server (2) kommunikativ verbunden ist.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass die Kommunikationseinrichtung (101) ein Power-line-Modul ist, der über ein Enegierversorgungsnetz mit dem Server (2) kommunikativ verbunden ist.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass die Kommunikationseinrichtung (101) ein Blue-Tooth-Modul ist, der drahlos über einen weiteren Blue-Tooth-Modul mit dem Server (2) kommunikativ verbunden ist.
- Verbrauchszähler, nach Anspruch 17, dadurch gekennzeichnet, dass der Blue-Tooth-Modul drahlos mit einem weiteren Blue-Tooth-Modul verbunden ist, wobei letzterer über ein Telefonnetz mit dem Server (2) kommunikativ verbunden ist.
- Verbrauchszähler, nach Anspruch 10, dadurch gekennzeichnet, dass die Kommunikationseinrichtung (101) im Sicherheitsmodul (100) integriert ist.
- Verbrauchszähler, nach den Ansprüchen 10 bis 19, dadurch gekennzeichnet, dass der Verbrauchszähler (1) eine Frankiermaschine ist.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE10116703 | 2001-03-29 | ||
| DE10116703A DE10116703A1 (de) | 2001-03-29 | 2001-03-29 | Verfahren zur Aufzeichnung eines Verbrauchswertes und Verbrauchszähler mit einem Meßwertgeber |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP1246135A2 true EP1246135A2 (de) | 2002-10-02 |
| EP1246135A3 EP1246135A3 (de) | 2004-01-07 |
Family
ID=7680305
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP02090093A Withdrawn EP1246135A3 (de) | 2001-03-29 | 2002-03-01 | Verfahren zur Aufzeichnung eines Verbrauchswertes und Verbrauchszähler mit einem Messwert |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20020184157A1 (de) |
| EP (1) | EP1246135A3 (de) |
| DE (1) | DE10116703A1 (de) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2012038764A1 (en) * | 2010-09-24 | 2012-03-29 | Onzo Limited | Data transmission method and system |
| CH713130A1 (de) * | 2016-11-24 | 2018-05-31 | Landis & Gyr Ag | Schaltvorrichtung und Messgerät mit selbigem. |
| CN108802463A (zh) * | 2018-04-18 | 2018-11-13 | 怀化建南电子科技有限公司 | 一种用于远程充电装置的直流电能表 |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| AU2003209056A1 (en) * | 2002-02-07 | 2003-09-02 | Invensys Systems, Inc. | System and method for authentication and fail-safe transmission of safety messages |
| DE102009049434A1 (de) * | 2009-10-14 | 2011-04-21 | ITF Fröschl GmbH | Messwertgeber sowie System |
| US10044402B2 (en) | 2010-06-25 | 2018-08-07 | Enmodus Limited | Timing synchronization for wired communications |
| GB2481579B (en) | 2010-06-25 | 2014-11-26 | Enmodus Ltd | Monitoring of power-consumption |
| DE102012203034A1 (de) * | 2012-02-28 | 2013-08-29 | Bundesdruckerei Gmbh | Verfahren zur Personalisierung einer Smart Meter Vorrichtung mit einem Sicherheitsmodul |
| DE102012203518B4 (de) * | 2012-03-06 | 2021-06-17 | Bundesdruckerei Gmbh | Verfahren zur Kommunikation von energieverbrauchsspezifischen Messdatenelementen von einer Smart Meter Vorrichtung an ein Computersystem eines Energieversorgers und/oder Messstellenbetreibers |
Family Cites Families (29)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US3962539A (en) * | 1975-02-24 | 1976-06-08 | International Business Machines Corporation | Product block cipher system for data security |
| US4200770A (en) * | 1977-09-06 | 1980-04-29 | Stanford University | Cryptographic apparatus and method |
| US4405829A (en) * | 1977-12-14 | 1983-09-20 | Massachusetts Institute Of Technology | Cryptographic communications system and method |
| DE3123530A1 (de) * | 1981-06-13 | 1982-12-30 | Karl Dipl.-Phys. 4600 Dortmund Winter | "verfahren und vorrichtung zur herstellung und verdichtung eines inertgases" |
| US4689478A (en) * | 1984-12-24 | 1987-08-25 | Ncr Corporation | System for handling transactions including a portable personal terminal |
| US4812965A (en) * | 1985-08-06 | 1989-03-14 | Pitney Bowes Inc. | Remote postage meter insepction system |
| GB2183852A (en) * | 1985-11-27 | 1987-06-10 | Triad Communications Inc | Utility meter |
| DE3703387A1 (de) * | 1986-02-06 | 1987-08-27 | Gossen Gmbh | Verfahren und vorrichtung zum automatischen erfassen und/oder verteilen und/oder abrechnen und/oder anzeigen von energieverbrauchsdaten bzw. -kosten |
| DE3734946A1 (de) * | 1987-10-15 | 1989-05-03 | Siemens Ag | Hoergeraet mit moeglichkeit zum telefonieren |
| US5243654A (en) * | 1991-03-18 | 1993-09-07 | Pitney Bowes Inc. | Metering system with remotely resettable time lockout |
| US5231668A (en) * | 1991-07-26 | 1993-07-27 | The United States Of America, As Represented By The Secretary Of Commerce | Digital signature algorithm |
| GB9210857D0 (en) * | 1992-05-21 | 1992-07-08 | Siemens Measurement Limited | Improvements in or relating to commodity supply meters |
| DE4243092C2 (de) * | 1992-12-18 | 1996-03-14 | Ludwig Kreuzpaintner | Stromverteilersystem |
| ATE229210T1 (de) * | 1993-03-22 | 2002-12-15 | Kundo Systemtechnik Gmbh | Anlage zur zentralen erfassung von energieverbrauchskosten |
| GB2313201A (en) * | 1996-05-15 | 1997-11-19 | Gen Electric Co Plc | Isolation bypass detector for a commodity supply line |
| US6453327B1 (en) * | 1996-06-10 | 2002-09-17 | Sun Microsystems, Inc. | Method and apparatus for identifying and discarding junk electronic mail |
| US5953426A (en) * | 1997-02-11 | 1999-09-14 | Francotyp-Postalia Ag & Co. | Method and arrangement for generating and checking a security imprint |
| WO1998056138A1 (en) * | 1997-06-03 | 1998-12-10 | Total Metering Limited | Improvements relating to metering systems |
| WO1998057304A1 (en) * | 1997-06-12 | 1998-12-17 | Pitney Bowes Inc. | Virtual postage meter with secure digital signature device |
| SK69898A3 (en) * | 1997-06-13 | 2000-05-16 | Bernina Electronic Ag | Method and device for measuring a consumption |
| DE19748954A1 (de) * | 1997-10-29 | 1999-05-06 | Francotyp Postalia Gmbh | Verfahren für eine digital druckende Frankiermaschine zur Erzeugung und Überprüfung eines Sicherheitsabdruckes |
| DE19754675A1 (de) * | 1997-12-10 | 1999-07-01 | Klaus Dipl Ing Weber | Einrichtung zum kundenseitigen Erfassen und Abrechnen des Haushaltsverbrauchs von Versorgungsgütern |
| US6019281A (en) * | 1997-12-22 | 2000-02-01 | Micro General Corp. | Postal security device with display |
| US6133850A (en) * | 1998-03-16 | 2000-10-17 | Motorola, Inc. | Method and apparatus for reducing channel capacity required to report a billable consumption of a utility commodity |
| DE19912781A1 (de) * | 1999-03-12 | 2000-11-23 | Francotyp Postalia Gmbh | Verfahren zum Schutz eines Sicherheitsmoduls und Anordnung zur Durchführung des Verfahrens |
| DE29905219U1 (de) * | 1999-03-12 | 1999-06-17 | Francotyp-Postalia AG & Co., 16547 Birkenwerder | Sicherheitsmodul mit Statussignalisierung |
| DE19912780A1 (de) * | 1999-03-12 | 2000-09-14 | Francotyp Postalia Gmbh | Anordnung für ein Sicherheitsmodul |
| EP1035518B1 (de) * | 1999-03-12 | 2008-06-25 | Francotyp-Postalia GmbH | Anordnung zum Schutz eines Sicherheitsmoduls |
| US6529883B1 (en) * | 1999-08-20 | 2003-03-04 | Motorola, Inc. | Prepayment energy metering system with two-way smart card communications |
-
2001
- 2001-03-29 DE DE10116703A patent/DE10116703A1/de not_active Ceased
-
2002
- 2002-03-01 EP EP02090093A patent/EP1246135A3/de not_active Withdrawn
- 2002-03-05 US US10/090,997 patent/US20020184157A1/en not_active Abandoned
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2012038764A1 (en) * | 2010-09-24 | 2012-03-29 | Onzo Limited | Data transmission method and system |
| CH713130A1 (de) * | 2016-11-24 | 2018-05-31 | Landis & Gyr Ag | Schaltvorrichtung und Messgerät mit selbigem. |
| CN108802463A (zh) * | 2018-04-18 | 2018-11-13 | 怀化建南电子科技有限公司 | 一种用于远程充电装置的直流电能表 |
Also Published As
| Publication number | Publication date |
|---|---|
| US20020184157A1 (en) | 2002-12-05 |
| DE10116703A1 (de) | 2002-10-10 |
| EP1246135A3 (de) | 2004-01-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2755846B1 (de) | Verfahren und vorrichtung zur zuordnung eines von einer ladestation erfassten messwertes zu einer transaktion | |
| EP2531368B1 (de) | Verfahren und vorrichtung zur zuordnung eines von einer ladestation erfassten messwertes zu einem nutzer | |
| EP1469429B1 (de) | Verfahren zum sicheren elektronischen wählen und kryptographische protokolle und computerprogramme dafür | |
| US6724894B1 (en) | Cryptographic device having reduced vulnerability to side-channel attack and method of operating same | |
| EP1278332B1 (de) | Verfahren und System zur Echtzeitaufzeichnung mit Sicherheitsmodul | |
| CN103827636B (zh) | 管理设施仪表通信的系统和方法 | |
| DE3303846A1 (de) | Verfahren zum "einschreiben" elektronischer post in einem elektronischen kommunikationssystem und anordnung zur durchfuehrung des verfahrens | |
| DE19812903A1 (de) | Frankiereinrichtung und ein Verfahren zur Erzeugung gültiger Daten für Frankierabdrucke | |
| IL139605A (en) | A method for transmitting and storing an electrical value and power meter for storing a value that uses (the same method) it | |
| EP1107502A2 (de) | System und Verfahren zur Vermeidung eines DPA-Angriffs auf eine kryptographische Vorrichtung | |
| CN102377565A (zh) | 一种基于指定验证者的可链接环签名方法 | |
| EP1246135A2 (de) | Verfahren zur Aufzeichnung eines Verbrauchswertes und Verbrauchszähler mit einem Messwert | |
| AU2011268753A1 (en) | Electronic voting apparatus and method | |
| EP2445746B1 (de) | Sicherung der abrechnung von über eine ladestation bezogener energie | |
| US20020035547A1 (en) | Franking method and apparatus | |
| DE102012008519A1 (de) | Sicherung eines Energiemengenzählers gegen unbefugten Zugriff | |
| JP2006527512A (ja) | デジタル料金納付注記の正当性証明の方法およびその実行のための装置 | |
| DE60015907T2 (de) | Verfahren und Vorrichtung zur Erzeugung von Nachrichten welche eine prüfbare Behauptung enthalten dass eine Veränderliche sich innerhalb bestimmter Grenzwerte befindet | |
| DE60031470T2 (de) | Verfahren zur Zertifikation von öffentlichen Schlüsseln, die zum Signieren von Postwertzeichen verwendet werden und derart signierte Postzeichen | |
| GB2211643A (en) | Authentication of a plurality of documents | |
| CN100486156C (zh) | 票据防伪码生成及验证的系统 | |
| EP2439902A2 (de) | Verfahren und Anordnung zum rechtsverbindlichen Senden und Empfangen von vertraulichen elektronischen Mitteilungen | |
| EP1619630A2 (de) | Verfahren und Anordnung zum Erstatten von Porto | |
| RU2323531C2 (ru) | Способ формирования документов, поддающихся проверке и защищенных от подделки, и центр денежных перечислений | |
| EP1857981A2 (de) | Anordnung und Verfahren zum Erstellen eines Frankierabdrucks |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE TR |
|
| AX | Request for extension of the european patent |
Free format text: AL;LT;LV;MK;RO;SI |
|
| PUAL | Search report despatched |
Free format text: ORIGINAL CODE: 0009013 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: 7G 07B 17/04 A Ipc: 7G 07F 15/00 B |
|
| AK | Designated contracting states |
Kind code of ref document: A3 Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE TR |
|
| AX | Request for extension of the european patent |
Extension state: AL LT LV MK RO SI |
|
| 17P | Request for examination filed |
Effective date: 20040202 |
|
| R17P | Request for examination filed (corrected) |
Effective date: 20040202 |
|
| AKX | Designation fees paid |
Designated state(s): CH DE FR GB IT LI |
|
| 17Q | First examination report despatched |
Effective date: 20041227 |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: FRANCOTYP-POSTALIA GMBH |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: FRANCOTYP-POSTALIA GMBH |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| INTG | Intention to grant announced |
Effective date: 20160311 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: G07B 17/00 20060101AFI20160302BHEP Ipc: G07F 15/00 20060101ALI20160302BHEP |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20160722 |