EP1455311A2 - Verfahren zum sicheren Datenaustausch - Google Patents
Verfahren zum sicheren Datenaustausch Download PDFInfo
- Publication number
- EP1455311A2 EP1455311A2 EP04090094A EP04090094A EP1455311A2 EP 1455311 A2 EP1455311 A2 EP 1455311A2 EP 04090094 A EP04090094 A EP 04090094A EP 04090094 A EP04090094 A EP 04090094A EP 1455311 A2 EP1455311 A2 EP 1455311A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- processing unit
- data processing
- message
- key
- integrity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Images
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00016—Relations between apparatus, e.g. franking machine at customer or apparatus at post office, in a franking system
- G07B17/0008—Communication details outside or between apparatus
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00016—Relations between apparatus, e.g. franking machine at customer or apparatus at post office, in a franking system
- G07B17/00024—Physical or organizational aspects of franking systems
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00016—Relations between apparatus, e.g. franking machine at customer or apparatus at post office, in a franking system
- G07B17/0008—Communication details outside or between apparatus
- G07B2017/00137—In a LAN
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07B—TICKET-ISSUING APPARATUS; FARE-REGISTERING APPARATUS; FRANKING APPARATUS
- G07B17/00—Franking apparatus
- G07B17/00733—Cryptography or similar special procedures in a franking system
- G07B2017/00741—Cryptography or similar special procedures in a franking system using specific cryptographic algorithms or functions
Definitions
- the present invention relates to a method for secure data exchange between a first data processing unit and a second data processing unit, at a secure communication channel between in a communication setup step the first data processing unit and the second data processing unit and in a data transmission step over the secure communication channel a first message from the second data processing unit to the first data processing unit is sent. It also relates to an arrangement for implementation of the method according to the invention is suitable.
- the latest version of such service data is usually provided by the provider of the Service itself or a third party. It is often the case here that the service data in a second data processing unit, usually in the form of a data center or the like can be provided for download.
- a second data processing unit usually in the form of a data center or the like
- the fee tables are known in this context for franking machines to send along with a digital signature using the fee table to be sent has been created.
- To create the digital Signature is the fee table or a predetermined part of the fee table in the Data center initially has a so-called hash algorithm, for example the Secure Hash algorithm (SHA), with which a so-called message core is generated becomes.
- This message core is then encrypted with a secret key.
- the the encrypted message core then forms the digital signature.
- SHA Secure Hash algorithm
- the digital signature is decrypted to the message core to obtain.
- the fee table sent or the predetermined part of the fee table with the same hash algorithm a new message core calculates and checks whether the new message core comes from the digital Signature obtained message core corresponds. Because such hash algorithms have the property have that an extremely small change in the input information a strong deviation in the result of the calculation is in agreement of the two message cores assume that no manipulation has taken place and the fee schedule can be used accordingly.
- From EP 0 969 420 A2 is in connection with the update of fee tables still known in franking machines to check the integrity of the a so-called MAC (Message Authentication Code) to use.
- the fee table is used in the franking machine by means of a predetermined checksum algorithm, first a checksum generated, which is then encrypted with a secret key to form the MAC.
- This MAC is sent back to the data center.
- the data center generates from the previously sent a fee table with the same checksum algorithm new checksum, which is then encrypted with the secret key to create a new one MAC 'form. Does this new MAC match the one sent by the franking machine MAC matches, it is assumed that the transmission took place without manipulation and a corresponding message is sent to a postage meter which shows the fee table then accepted.
- This variant also has the problem that it is comparatively complex, on the one hand there is a corresponding checksum algorithm in both data processing units must be present. The other is a series of communication steps is required to complete the update of the service data. Bid here again a number of manipulation possibilities, of which the corresponding measures must be counteracted.
- the present invention is therefore based on the object of a method or a method To provide an arrangement of the type mentioned, which or which does not have the disadvantages mentioned above, or at least to a lesser extent, and in particular ensures simple and reliable secure data exchange.
- the present invention solves this problem on the basis of a method according to the Preamble of claim 1 by those specified in the characterizing part of claim 1 Characteristics. It continues to accomplish this task based on an arrangement the preamble of claim 15 by the in the characterizing part of claim 15 specified characteristics.
- the present invention is based on the technical teaching that a simple and can reliably ensure secure data exchange when in the data transmission step a second message in the second data processing unit is generated by attaching a predefined attachment to the first message becomes. Then a third message is generated by placing the second message under Encrypted using a secret key that is only in the first data processing unit and the second data processing unit is present. Finally the third message is sent to the first data processing unit.
- the encryption of the second message with the secret key ensures that the data cannot be manipulated during transmission.
- the attachment to the First message provides a simple, additional way to manipulate recognize without the need for complex test algorithms.
- the first Message is sent to the first data processing unit. Only that is preferred third message sent to the first data processing unit, since this is the first message contains. This first message can then be easily decrypted and a simple further separation can be isolated from the third message.
- the first data processing unit contains one later integrity check just a simple encryption or decryption and a simple comparison of the data thus obtained is required.
- the third message is preferably in the first data processing unit decrypted using the secret key and the second message is checked for integrity in a subsequent integrity check step.
- the first message together with the third message it should be provided that, first, the first message of the default attachment is added to form a new second message.
- this new second message is then transmitted by decrypting the third one Message matched second message, it is assumed that no tampering occurred during the transfer.
- the attachment can in principle be any attachment, which is present in both data processing units. To increase security, this attachment is preferably replaced from time to time, for example in fixed predetermined intervals or also at randomly determined intervals. To each to keep the amount of data to be stored in the data processing units small the attachment preferably at least part of the secret key. What part of the secret key it can be fixed, and also here the specified part can vary from time to time. It can also be provided that the specified part with a fixed or randomly determined number of data exchange processes varied. In particular, it can be provided that it interacts with each data exchange process changes.
- the secret key can in principle be any one for such cryptographic applications act appropriate key. It just has to be ensured be in a correspondingly secure manner in the two data processing units was introduced to ensure a sufficient level of security. The secure insertion of cryptographic keys in data processing units well known, so that this will not be discussed in more detail.
- the security is thereby increases that the secret key is a secret session key used in the communication establishment step is generated. This makes the possibility of manipulation significantly restricted because the secret key does not exist before communication is established is known and therefore cannot be compromised in advance.
- the secret key can basically in any suitable manner according to any well-known methods for generating such cryptographic Keys are generated.
- the secret key is preferably generated by generates a first partial key in the first data processing unit and sends it to the second data processing unit is sent.
- the second is a second subkey generated in the second data processing unit and to the first data processing unit sent.
- the secret key is in the first data processing unit and in the second data processing unit from the first partial key and generated the second subkey according to a predefinable key generation scheme.
- the key generation scheme can be any predefinable algorithm act.
- the secret key becomes simple composed of the first partial key and the second partial key.
- the secret key can be used permanently once it has been generated. In order to increase security, however, it is preferably provided that the secret Key is a temporary key that is only used temporarily and as above described after a certain period of time.
- an error mode can also be provided be, for example, the second data processing unit for a given one Number of attempts to repeat the previous steps, especially to send the previously sent data again to ensure an error-free transmission of the to try first message. Receives the second data processing unit after predetermined number of attempts no positive confirmation message, it breaks the Communication with the first data processing unit. At least preferably in the case of such errors that force the execution of predetermined error routines, all steps of the respective data processing unit for later use logged and saved.
- the secure communication channel at least after receiving the positive confirmation message closed by the second data processing unit in a communication termination step is and the secret key in both the first data processing unit and is also destroyed in the second data processing unit. The same thing happens preferentially if the predetermined number of failed attempts in the failure mode described above was achieved.
- the first data processing unit has a first processing module and comprises an associated security module, the decryption step being performed by the security module is carried out.
- the integrity checking step is therefore also preferred and additionally or alternatively the confirmation step by the security module carried out.
- the processing module upon detection of the Integrity of the second message at least part of the first message for further Stores use in a memory connected to the processing module. at The processing module switches ascertaining the integrity of the second message and additionally or alternatively, however, the safety module in a fault mode. In one Such an error mode can be used by the corresponding device for further operation be locked. Furthermore, a corresponding error message or a corresponding one Error signal output to the user of the first data processing unit to inform him of the fault condition. It can also be provided that automatically a corresponding error message to the second data processing unit or transmitted to other third party facilities. In the case of a franking machine This can be the manufacturer's data center, for example, but also the data center of an affected postal carrier.
- the first message contains information and a digital signature of the second data processing unit above the first information included.
- a digital signature offers the possibility of ensuring the integrity of the data processing unit data used not only in the integrity check step immediately after the data transfer but also to check at a later time if the digital signature is stored in the first data processing unit.
- the integrity check step at least partially predeterminable times is repeated. This can be the case, for example, after a certain period Usage time of the first data processing unit after a certain number of uses of the first data processing unit or after a certain number of switching on the first data processing unit, in particular with each Switch on the first data processing unit, the case.
- the digital signature can be made in any suitable manner using well-known signature algorithms generated and verified in the integrity check step.
- signature algorithms can be used with message recovery that are available at the verification of the signature restore the message on which the signature is based and compare it with the sent message.
- An example of one Message recovery signature algorithm is the RSA signature algorithm.
- signature algorithms are preferred without message recovery application where it is under the Verification of the signature does not result in a reconstruction of the message, that of the signature underlying.
- Examples of such signature algorithms without message recovery are ElGamal and its modifications (e.g. Schnorr signatures), DSA, Gost, ECDSA, ESIGN and GMR.
- Such signature algorithms without message recovery offer, moreover, already in the application in the context of the known methods described with a reduction in the calculation effort Benefit from an additional increase in security, since it is not possible for them to Reconstruct the underlying message.
- the present invention further relates to an arrangement for secure data exchange with a first data processing unit and a second data processing unit, to establish a secure communication channel and to transmit a first one Message from the second data processing unit to the first data processing unit are trained over the secure communication channel.
- Secret key provided, which is only in the first data processing unit and is stored in the second data processing unit. It is also provided that that the second data processing unit for generating a second message Attaching a predetermined attachment to the first message is formed. Farther it is for generating a third message by encrypting the second message trained using the secret key. After all, it is for sending the third message to the first data processing unit via the secure communication channel educated.
- the arrangement according to the invention is suitable for carrying out the arrangement according to the invention Process. With it, the advantages and functions of the invention described above Realize the procedure in the same way, so that at this point the Reference is made to the above statements.
- ASIC application-specific configured integrated circuits
- the first data processing unit is preferably for decrypting the third message using the secret key and performing an integrity check trained on the second message. To the integrity check described above To be able to carry out, the first data processing unit is preferred to Isolate the attachment from the second message and compare the attachment to a given attachment.
- the secret key is preferably a secret session key that preferably only generated for the current session, used and after termination the meeting is destroyed.
- the session key can be generated in the first data processing unit and also in the second data processing unit, accordingly, each for generating the secret key and to send the generated session key to the other data processing unit is trained.
- a corresponding key generation algorithm is stored, on which the respective Data processing unit then uses.
- the secret session key is preferably used using both data processing units generated without it as a whole between the two data processing units is exchanged.
- the first data processing unit is Generate a first partial key and send the first partial key to the second data processing unit is formed.
- the second data processing unit is to generate a second partial key and to transmit the second partial key to the first data processing unit.
- a corresponding key generation scheme exists, according to the respective data processing unit receives the secret key from the first partial key and the second subkey is generated.
- the first data processing unit is used to carry out the integrity check educated. In this case, it is also preferred for sending a positive confirmation message to the second data processing unit if the Integrity of the second message is formed. Additionally or alternatively, it can be sent a negative confirmation message to the second data processing unit in the case the determination of missing integrity of the second message.
- the second data processing unit is also preferably designed so that it is the secure communication channel closes at least after receiving the positive confirmation message. Becomes If the communication channel is closed, then both the first data processing unit is destroyed and the second data processing unit the secret session key.
- the arrangement according to the invention can in principle be constructed in any suitable manner his.
- the functions of the method according to the invention described above can thereby in any suitable way by suitably configured according to the application Hardware or realized by standard components and application-specific software become.
- the first data processing unit preferably comprises a first processing module and an associated security module, at least for decrypting the third message is formed.
- the security module is preferably also for Execution of the integrity check and additionally or alternatively also for sending a confirmation message depending on the result of the integrity check.
- the processing module to store at least a portion of the first message when integrity is determined the second message.
- the first message is used for further use stored in a memory connected to the processing module.
- the processing module and additionally or alternatively, the security module for switching to one already detailed above described failure mode.
- the second data processing unit is to create a first digital signature over a first piece of information and to create the first message from the first information and the first digital Signature trained. This makes it possible, as mentioned, even at later times check the integrity of the data used. This is the first data processing unit for at least partial repetition of the integrity check to be specified Times trained.
- the invention can be used in connection with any application which data in a correspondingly secure manner from a first data processing unit must be transmitted to a second data processing unit. in this connection As mentioned, it can be used in connection with any service that be carried out with the help of data processing units and where it is required is, in the first data processing unit, always the most current version of the version to be carried out of the service necessary service data available.
- the application of the invention is Constellations of particular advantage in which a central second data processing unit, for example a remote data center, several first data processing units must provide appropriate service data.
- a central second data processing unit for example a remote data center
- several first data processing units must provide appropriate service data.
- the invention can be used in connection with franking machines.
- the first data processing unit is therefore a franking machine.
- the present invention further relates to a data processing unit which Features of the first data processing unit or the one described above second data processing unit of the arrangement according to the invention.
- FIG. 1 shows a schematic representation of a preferred embodiment of the invention Arrangement for performing the method according to the invention.
- the arrangement comprises a first data processing unit in the form of a franking machine 1 and a second data processing unit in the form of a remote data center 2 which with the franking machine 1 by means of - not shown for reasons of clarity - Communication means connected via a communication link 3 for data exchange can be.
- the franking machine 1 comprises a processing module 4 and an associated security module 5, which security-related processes in the franking machine 1.
- This first message contains first information in the form of a fee table, which the franking machine 1 when calculating the Postage value used for the transport of a certain piece of mail by a mail carrier is required. If the fee schedule was transferred intact, it will be saved in a fee table memory 6 connected to the processing module 4.
- the processing module determines the required postage for a specific mail item 4 with access to the fee table memory 6 depending on the weight of the item of mail and the user's input for the type of dispatch etc.
- the weight of the mail item is connected to the processing module 4 Scale 7 determined.
- the user inputs are made via an input device 8, which is also connected to the processing module 4.
- the data center 2 can be used to add more Franking machines 9 and 10 are connected, which are designed in the same manner like franking machine 1.
- the transmission of the fee table can be done either by the data center 2 Connection establishment with the franking machine 1 be initiated as soon as a new version the fee table is available in data center 2. However, it is also possible that the new fee table is sent as soon as the franking machine 1 receives the Data center 2 contacted.
- FIGS. 1 and 2 the sequence of the invention is described below Process explained with the arrangement according to the invention from Figure 1.
- a tamper-proof transmission of the first message with the fee table To ensure, is first in a communication setup step 20 via the communication link 3 between the franking machine 1 and the data center 2 secure communication channel established.
- the establishment of a secure communication channel takes place in a well-known manner by the security module 5 and the data center 2 with the interposition of the processing module 4 using cryptographic Mutually authenticate means.
- the first processing unit 5.1 of the security module 5 during mutual authentication accesses a first memory 5.2, in which in addition to the required encryption and Verification algorithms as well as the public key and the secret key of the security module 5 also the public key of the data center 2 and corresponding ones Certificates are saved.
- the second one is used Processing unit 2.1 to a second memory 2.2, in which in addition to the required Encryption and verification algorithms as well as the public key and the secret key of the data center 2 also the public key of the security module 5 and corresponding certificates are stored.
- a key generation step 21 in the franking machine 1 and the data center 2 the generation a secret key in the form of a secret session key that is exclusive is present in the franking machine 1 and the data center 2.
- the key generation step 21 first of all in a partial step 21.1 in the first processing unit 5.1 a first partial key generated and a second partial key generated in the second processing unit 2.1.
- the first processing unit 5.1 accesses a third memory 5.3, the one contains corresponding key generation algorithm.
- the second processing unit 2.1 accesses a fourth memory 2.3, which also has a corresponding one Contains key generation algorithm. It goes without saying that generating the partial key in other variants of the invention even before the manufacture of the secure communication channel can take place.
- a sub-step 21.2 the two sub-keys are transferred via the secure one Communication channel exchanged by the first subkey to the second processing unit 2.1 and the second partial key are sent to the first processing unit 5.1 becomes.
- the secret session key is both in the franking machine 1 as well as in the data center 2 according to a predetermined key generation scheme generated from the two partial keys and in the third memory 5.3 of the security module 5 or the fourth memory 2.3 of the data center 2.
- the key generation scheme is also in the third memory 5.3 of the security module 5 or the fourth memory 2.3 of the data center 2.
- the key generation scheme is just that the second Subkey is appended to the first subkey.
- the secret session keys in other variants of the invention also after any other Schemes can be generated from the first and second subkeys.
- the key generation step 21 is followed by a data transmission step 22, in which the fee table from the data center 2 via the secure Communication channel is sent to the franking machine 1.
- the data center is initially in a sub-step 22.1 2 generates a first message by the second processing unit 2.1, which contains first information in the form of the fee table to be sent.
- the first message also contains a first digital signature, that of the second processing unit 2.1 with access to the second memory 2.2 in well-known way generated above the first information, ie the fee table has been. It uses a digital signature algorithm without message recovery used. However, it is understood that in other variants of the invention, one such a digital signature above the first information may also be missing.
- the first message becomes a second in the data center 2 Message generated by the second processing unit 2.1 to the first message extended an attachment.
- the annex is the one in fourth memory 2.3 stored secret session key.
- the second message becomes a third in the data center 2 Message generated by the second processing unit 2.1 under the second message Encrypted using the secret session key.
- the second processing unit 2.1 accesses a corresponding encryption algorithm, which is described in a fifth memory 2.4 of the data center 2 is stored.
- the third message is then sent from the data center 2 transmitted to the franking machine 1 via the secure communication channel.
- the attachment in the present case is the secret session key.
- the attachment also act as a predetermined part of the secret session key. Around Which part of the secret session key it is, for example in advance as part of a communication, especially via the secure communication channel, agreed or specified between the franking machine and the data center have been. This specification can also be carried out simultaneously with or after the transmission the third message.
- a decryption step 23 takes place in the security module 5 of the franking machine 1 a decryption of the third message, so that the second message is then present in the security module 5.
- the first processing unit is used for this 5.1 of the security module on the third memory 5.3, in which the secret Session key is stored, and a sixth memory 5.4 to one contains the corresponding decryption algorithm.
- an integrity check step 24 in the security module 5 of the franking machine 1 an integrity check, in which the second message their integrity is checked.
- the first processing unit 5.1 accesses an integrity check algorithm to that in a seventh memory 5.5 of the security module 5 is filed.
- a confirmation step 25 a corresponding confirmation message from the franking machine 1 to the Data center 2 sent.
- the integrity check step 24 there is initially one Sub-step 24.1 by the first processing unit 5.1, both the appendix from the second Message isolated as well as the first message.
- the first processing unit solves 5.1 in the present example, a bit sequence with a given position and length from the second message.
- this attachment which is extracted from the second message, is executed the first processing unit 5.1 compared with a given attachment, so here with the secret session key stored in the third memory 5.3.
- the first processing unit 5.1 solves in the present example again corresponding bit sequences with a given position and length from the first Message.
- the first digital signature is then verified in a sub-step 24.4.
- the first processing unit 5.1 takes effect in addition to the first information and the first digital signature to an appropriate verification algorithm without message recovery as well as the public key of the data center 2, both in the first memory 5.2 are saved.
- both in the first memory 5.2 are saved.
- the first digital signature is missing, and sub-steps 24.3 and 24.4 may also be missing.
- the data center 2 Upon receipt of the positive confirmation message, the data center 2 ends in a communication termination step 26 the communication with the franking machine 1, as shown in FIG 2 can be seen.
- the data center 2 initially logs the successful completion the transmission of the fee table in a sub-step 26.1 in an eighth Memory 2.5, which is connected to the second processing unit 2.1.
- a sub-step 26.2 the secure communication channel is then started from the data center 2 closed and the connection with the franking machine 1 disconnected.
- the secret session key is then in a sub-step 26.3 in the data center 2 destroyed by the corresponding memory area of the fourth memory 2.3 is overwritten by the second processing unit 2.1. On the part of the franking machine 1 is also followed after the communication with the data center is terminated 2 was found. In sub-step 26.3 it is also in the security module 5 the secret session key is destroyed by the corresponding memory area of the third memory 5.3 is overwritten by the first processing unit 5.1. Herewith the process is then ended.
- the first negative confirmation message becomes sub-step 22.4 of the data transmission step 24 repeated, i.e. H. the data center 2 sends the third message again. This is indicated in FIGS. 2, 2B and 2C by the connecting point 27.
- the security module 5 is switched to an error mode in which the franking machine 1 cannot make frankings. This is the user the franking machine by means of a corresponding acoustic signal and / or a corresponding one optical signal informed.
- the integrity check was therefore unsuccessful, i. H. the missing Integrity of the second message determined.
- a sub-step 25.3 of the confirmation step 25 accordingly becomes a second negative confirmation message from the security module 5 sent to the data center 2.
- the communication termination step 26 becomes as described above carried out.
- sub-step 24.4 of the integrity check step described above 24 is repeated by verifying the first digital signature.
- the result of the verification in substep 24.4 is positive, d. H. corresponds to the first digital Signature of the first information, the franking machine 1 can continue to be operated.
- the result of the verification in sub-step 24.4 becomes negative, the franking machine becomes 1 switched to an error mode, as described above in connection with substep 24.7 of the integrity check step 24 has been described.
- the fee table is still going to that effect checks whether a validity date associated with the fee table has passed was or not. If this is the case, the franking machine 1 is also described in FIGS Error mode switched.
- the memories described above are does not necessarily have to be separate memory modules. Rather you can one in the security module 5 and one in the data center 2 or more memory modules can be provided, with individual memory modules different Have memory areas that form the different memories.
- the security module 5 has a has first working memory 5.6 connected to the first processing unit 5.1, in which stores all the data required for the current process step. The same applies to the data center 2, one with the second processing unit 2.1 connected second working memory 2.6.
- the present invention has also been described above by way of example only described in the field of franking machines. However, it is understood that the present invention can also be used in other areas in which it on the secure transmission of service data between a first data processing unit and a second data processing unit arrives.
Landscapes
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
- Devices For Checking Fares Or Tickets At Control Points (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
- Figur 1
- eine schematische Darstellung einer bevorzugten Ausführungsform der erfindungsgemäßen Anordnung zur Durchführung des erfindungsgemäßen Verfahrens;
- Figur 2
- ein schematisches Ablaufdiagramm des erfindungsgemäßen Verfahrens bei der Anordnung aus Figur 1;
- Figur 2A
- ein erstes Detail des Ablaufdiagramms aus Figur 2;
- Figur 2B
- ein zweites Detail des Ablaufdiagramms aus Figur 2;
- Figur 2C
- ein drittes Detail des Ablaufdiagramms aus Figur 2.
Claims (30)
- Verfahren zum sicheren Datenaustausch zwischen einer ersten Datenverarbeitungseinheit (1) und einer zweiten Datenverarbeitungseinheit (2), bei dem in einem Kommunikationsaufbauschritt (20) ein sicherer Kommunikationskanal zwischen der ersten Datenverarbeitungseinheit (1) und der zweiten Datenverarbeitungseinheit (2) hergestellt wird und in einem Datenübermittlungsschritt (22) über den sicheren Kommunikationskanal eine erste Nachricht von der zweiten Datenverarbeitungseinheit (2) an die erste Datenverarbeitungseinheit (1) übersandt wird, dadurch gekennzeichnet, dass in dem Datenübermittlungsschritt (22)in der zweiten Datenverarbeitungseinheit (2) eine zweite Nachricht generiert wird, indem ein vorgegebener Anhang an die erste Nachricht angehängt wird,eine dritte Nachricht generiert wird, indem die zweite Nachricht unter Verwendung eines geheimen Schlüssels verschlüsselt wird, der nur in der ersten Datenverarbeitungseinheit (1) und der zweiten Datenverarbeitungseinheit (2) vorhanden ist, unddie dritte Nachricht an die erste Datenverarbeitungseinheit (1) übersandt wird.
- Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass in einem Entschlüsselungsschritt (23) die dritte Nachricht in der ersten Datenverarbeitungseinheit (1) unter Verwendung des geheimen Schlüssels entschlüsselt wird und die zweite Nachricht in einem Integritätsprüfungsschritt (24) auf ihre Integrität überprüft wird.
- Verfahren nach Anspruch 2, dadurch gekennzeichnet, dass zur Integritätsprüfung in dem Integritätsprüfungsschritt (24) der Anhang aus der zweiten Nachricht isoliert wird und überprüft wird, ob der Anhang einem vorgegebenen Anhang entspricht.
- Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der Anhang zumindest ein, insbesondere vorgebbarer, Teil des geheimen Schlüssels ist.
- Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der geheime Schlüssel ein geheimer Sitzungsschlüssel ist, der in dem Kommunikationsaufbauschritt (20) oder nach dem Kommunikationsaufbauschritt (20) generiert wird.
- Verfahren nach Anspruch 5, dadurch gekennzeichnet, dass der geheime Schlüssel generiert wird, indemein erster Teilschlüssel in der ersten Datenverarbeitungseinheit (1) generiert und an die zweite Datenverarbeitungseinheit (2) gesandt wird,ein zweiter Teilschlüssel in der zweiten Datenverarbeitungseinheit (2) generiert und an die erste Datenverarbeitungseinheit (1) gesandt wird undder geheime Schlüssel in der ersten Datenverarbeitungseinheit (1) und in der zweiten Datenverarbeitungseinheit (2) aus dem ersten Teilschlüssel und dem zweiten Teilschlüssel nach einem vorgebbaren Schlüsselerzeugungsschema generiert wird, insbesondere aus dem ersten Teilschlüssel und dem zweiten Teilschlüssel zusammengesetzt wird.
- Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der geheime Schlüssel ein temporärer Schlüssel ist, der nur vorübergehend verwendet wird.
- Verfahren nach einem der Ansprüche 2 bis 7, dadurch gekennzeichnet, dass in einem Bestätigungsschritt (25)im Fall der Feststellung der Integrität der zweiten Nachricht im Integritätsprüfungsschritt (24) eine positive Bestätigungsnachricht, die insbesondere die erste Nachricht enthält, von der ersten Datenverarbeitungseinheit (1) an die zweite Datenverarbeitungseinheit (2) gesandt wird und/oderim Fall der Feststellung fehlender Integrität der zweiten Nachricht im Integritätsprüfungsschritt (24) eine negative Bestätigungsnachricht von der ersten Datenverarbeitungseinheit (1) an die zweite Datenverarbeitungseinheit (2) gesandt wird.
- Verfahren nach Anspruch 8, dadurch gekennzeichnet, dass der sichere Kommunikationskanal zumindest nach Erhalt der positiven Bestätigungsnachricht durch die zweite Datenverarbeitungseinheit (2) in einem Kommunikationsabbruchschritt (26) geschlossen wird und der geheime Schlüssel sowohl in der ersten Datenverarbeitungseinheit (1) als auch in der zweiten Datenverarbeitungseinheit (2) vernichtet wird.
- Verfahren nach einem der Ansprüche 2 bis 9, dadurch gekennzeichnet, dass die erste Datenverarbeitungseinheit (1) ein erstes Verarbeitungsmodul (4) und ein damit verbundenes Sicherheitsmodul (5) umfasst, wobei der Entschlüsselungsschritt (23) durch das Sicherheitsmodul (5) durchgeführt wird.
- Verfahren nach Anspruch 10, dadurch gekennzeichnet, dass der Integritätsprüfungsschritt (24) und/oder der Bestätigungsschritt (25) durch das Sicherheitsmodul (5) durchgeführt wird.
- Verfahren nach Anspruch 10 oder 11, dadurch gekennzeichnet, dassdas Verarbeitungsmodul (4) bei Feststellung der Integrität der zweiten Nachricht zumindest einen Teil der ersten Nachricht zur weiteren Verwendung in einem mit dem Verarbeitungsmodul (4) verbundenen Speicher (6) ablegt unddas Verarbeitungsmodul (4) und/oder das Sicherheitsmodul (5) bei Feststellung fehlender Integrität der zweiten Nachricht in einen Fehlermodus schaltet.
- Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass die erste Nachricht eine Information und eine digitale Signatur der zweiten Datenverarbeitungseinheit (2) über der ersten Information umfasst.
- Verfahren nach Anspruch 12 und 13, dadurch gekennzeichnet, dass der Integritätsprüfungsschritt (24) zu vorgebbaren Zeitpunkten zumindest teilweise wiederholt wird.
- Anordnung zum sicheren Datenaustausch mit einer ersten Datenverarbeitungseinheit (1) und einer zweiten Datenverarbeitungseinheit (2), die zum Aufbau eines sicheren Kommunikationskanals und zur Übermittlung einer ersten Nachricht von der zweiten Datenverarbeitungseinheit (2) an die erste Datenverarbeitungseinheit (1) über den sicheren Kommunikationskanal ausgebildet sind, dadurch gekennzeichnet, dass ein geheimer Schlüssel vorgesehen ist, der ausschließlich in der ersten Datenverarbeitungseinheit (1) und in der zweiten Datenverarbeitungseinheit (2) gespeichert ist, und dass die zweite Datenverarbeitungseinheit (2)zum Generieren einer zweiten Nachricht durch Anhängen eines vorgegebenen Anhangs an die erste Nachricht ausgebildet ist,zum Generieren einer dritten Nachricht durch Verschlüsselung der zweiten Nachricht unter Verwendung des geheimen Schlüssels ausgebildet ist, undzum Übersenden der dritten Nachricht an die erste Datenverarbeitungseinheit (1) über den sicheren Kommunikationskanal ausgebildet ist.
- Anordnung nach Anspruch 15, dadurch gekennzeichnet, dass die erste Datenverarbeitungseinheit (1) zum Entschlüsseln der dritten Nachricht unter Verwendung des geheimen Schlüssels und zur Durchführung einer Integritätsprüfung an der zweiten Nachricht ausgebildet ist.
- Anordnung nach Anspruch 16, dadurch gekennzeichnet, dass zur Integritätsprüfung die erste Datenverarbeitungseinheit (1) zum Isolieren des Anhangs aus der zweiten Nachricht und zum Vergleich des Anhangs mit einem vorgegebenen Anhang ausgebildet ist.
- Anordnung nach einem der Ansprüche 15 bis 17, dadurch gekennzeichnet, dass der Anhang zumindest ein, insbesondere vorgebbarer, Teil des geheimen Schlüssels ist.
- Anordnung nach einem der Ansprüche 15 bis 18, dadurch gekennzeichnet, dass der geheime Schlüssel ein geheimer Sitzungsschlüssel ist und dass die erste Datenverarbeitungseinheit (1) und/oder die zweite Datenverarbeitungseinheit (2) zum Generieren des geheimen Schlüssels ausgebildet ist.
- Anordnung nach Anspruch 19, dadurch gekennzeichnet, dass zum Generieren des geheimen Schlüsselsdie erste Datenverarbeitungseinheit (1) zum Generieren eines ersten Teilschlüssels und zum Übersenden des ersten Teilschlüssels an die zweite Datenverarbeitungseinheit (2) ausgebildet ist,die zweite Datenverarbeitungseinheit (2) zum Generieren eines zweiten Teilschlüssels und zum Übersenden des zweiten Teilschlüssels an die erste Datenverarbeitungseinheit (1) ausgebildet ist, unddie erste Datenverarbeitungseinheit (1) und die zweite Datenverarbeitungseinheit (2) zum Generieren des geheimen Schlüssels aus dem ersten Teilschlüssel und dem zweiten Teilschlüssel nach einem vorgebbaren Schlüsselerzeugungsschema, insbesondere zum Zusammensetzen des ersten Schlüssels aus dem ersten Teilschlüssel und dem zweiten Teilschlüssel, ausgebildet sind.
- Anordnung nach einem der Ansprüche 15 bis 20, dadurch gekennzeichnet, dass der geheime Schlüssel ein temporärer Schlüssel mit begrenzter Gültigkeitsdauer ist.
- Anordnung nach einem der Ansprüche 16 bis 21, dadurch gekennzeichnet, dass die erste Datenverarbeitungseinheit (1)zum Übersenden einer positiven Bestätigungsnachricht, die insbesondere die erste Nachricht enthält, an die zweite Datenverarbeitungseinheit (2) im Fall der Feststellung der Integrität der zweiten Nachricht ausgebildet ist und/oderzum Übersenden einer negativen Bestätigungsnachricht an die zweite Datenverarbeitungseinheit (2) im Fall der Feststellung fehlender Integrität der zweiten Nachricht ausgebildet ist.
- Anordnung nach Anspruch 22, dadurch gekennzeichnet, dass die zweite Datenverarbeitungseinheit (2) zum Schließen des sicheren Kommunikationskanals zumindest nach Erhalt der positiven Bestätigungsnachricht ausgebildet ist und dass die erste Datenverarbeitungseinheit (1) und die zweite Datenverarbeitungseinheit (2) zum Vernichten des geheimen Schlüssels nach Schließen des sicheren Kommunikationskanals ausgebildet sind.
- Anordnung nach einem der Ansprüche 16 bis 23, dadurch gekennzeichnet, dass die erste Datenverarbeitungseinheit (1) ein erstes Verarbeitungsmodul (4) und ein damit verbundenes Sicherheitsmodul (5) umfasst, das zum Entschlüsseln der dritten Nachricht ausgebildet ist.
- Anordnung nach Anspruch 24, dadurch gekennzeichnet, dass das Sicherheitsmodul (5) zur Durchführung der Integritätsprüfung und/oder zum Übersenden einer Bestätigungsnachricht in Abhängigkeit vom Ergebnis der Integritätsprüfung ausgebildet ist.
- Anordnung nach Anspruch 24 oder 25, dadurch gekennzeichnet, dassdas Verarbeitungsmodul (4) zum Speichern zumindest eines Teils der ersten Nachricht bei Feststellung der Integrität der zweiten Nachricht zur weiteren Verwendung in einem mit dem Verarbeitungsmodul (4) verbundenen Speicher (6) ausgebildet ist unddas Verarbeitungsmodul (4) und/oder das Sicherheitsmodul (5) zum Umschalten in einen Fehlermodus bei Feststellung fehlender Integrität der zweiten Nachricht ausgebildet ist.
- Anordnung nach einem der Ansprüche 15 bis 26, dadurch gekennzeichnet, dass die zweite Datenverarbeitungseinheit (2) zum Erstellen einer ersten digitalen Signatur über einer ersten Information und zum Erstellen der ersten Nachricht aus der ersten Information und der ersten digitalen Signatur ausgebildet ist.
- Anordnung nach Anspruch 26 und 27, dadurch gekennzeichnet, dass die erste Datenverarbeitungseinheit (1) zur zumindest teilweisen Wiederholung der Integritätsprüfung zu vorgebbaren Zeitpunkten ausgebildet ist.
- Anordnung nach einem der Ansprüche 15 bis 28, dadurch gekennzeichnet, dass die erste Datenverarbeitungseinheit eine Frankiermaschine (1) ist und/oder die zweite Datenverarbeitungseinheit eine entfernte Datenzentrale (2) ist.
- Datenverarbeitungseinheit, dadurch gekennzeichnet, dass sie wie die erste Datenverarbeitungseinheit (1) oder die zweite Datenverarbeitungseinheit (2) nach einem der Ansprüche 16 bis 29 ausgebildet ist.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE10309817 | 2003-03-05 | ||
| DE10309817A DE10309817A1 (de) | 2003-03-05 | 2003-03-05 | Verfahren zum sicheren Datenaustausch |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP1455311A2 true EP1455311A2 (de) | 2004-09-08 |
| EP1455311A3 EP1455311A3 (de) | 2006-06-21 |
Family
ID=32797843
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP04090094A Withdrawn EP1455311A3 (de) | 2003-03-05 | 2004-03-05 | Verfahren zum sicheren Datenaustausch |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US7437756B2 (de) |
| EP (1) | EP1455311A3 (de) |
| DE (1) | DE10309817A1 (de) |
Families Citing this family (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8539608B1 (en) * | 2004-03-25 | 2013-09-17 | Verizon Corporate Services Group Inc. | Integrity checking at high data rates |
| DE102007011309B4 (de) * | 2007-03-06 | 2008-11-20 | Francotyp-Postalia Gmbh | Verfahren zur authentisierten Übermittlung eines personalisierten Datensatzes oder Programms an ein Hardware-Sicherheitsmodul, insbesondere einer Frankiermaschine |
| US8079081B1 (en) * | 2008-06-27 | 2011-12-13 | Alert Logic, Inc. | Systems and methods for automated log event normalization using three-staged regular expressions |
| US20120303533A1 (en) * | 2011-05-26 | 2012-11-29 | Michael Collins Pinkus | System and method for securing, distributing and enforcing for-hire vehicle operating parameters |
| US20130060721A1 (en) | 2011-09-02 | 2013-03-07 | Frias Transportation Infrastructure, Llc | Systems and methods for pairing of for-hire vehicle meters and medallions |
| US9135460B2 (en) * | 2011-12-22 | 2015-09-15 | Microsoft Technology Licensing, Llc | Techniques to store secret information for global data centers |
| US20130253999A1 (en) | 2012-03-22 | 2013-09-26 | Frias Transportation Infrastructure Llc | Transaction and communication system and method for vendors and promoters |
| US20140298479A1 (en) * | 2013-04-02 | 2014-10-02 | Ayu Technology Solutions Llc | Secure data transfer for chat systems |
| US10819418B2 (en) * | 2016-04-29 | 2020-10-27 | Honeywell International Inc. | Systems and methods for secure communications over broadband datalinks |
| US10715511B2 (en) | 2018-05-03 | 2020-07-14 | Honeywell International Inc. | Systems and methods for a secure subscription based vehicle data service |
| US10819689B2 (en) | 2018-05-03 | 2020-10-27 | Honeywell International Inc. | Systems and methods for encrypted vehicle data service exchanges |
| US11201856B2 (en) * | 2019-08-20 | 2021-12-14 | International Business Machines Corporation | Message security |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5448641A (en) * | 1993-10-08 | 1995-09-05 | Pitney Bowes Inc. | Postal rating system with verifiable integrity |
| US5799290A (en) * | 1995-12-27 | 1998-08-25 | Pitney Bowes Inc. | Method and apparatus for securely authorizing performance of a function in a distributed system such as a postage meter |
| US5969826A (en) * | 1997-01-21 | 1999-10-19 | Xerox Corporation | Auto-function switching process for a multi-functional machine |
| DE19830055B4 (de) * | 1998-06-29 | 2005-10-13 | Francotyp-Postalia Ag & Co. Kg | Verfahren zur sicheren Übertragung von Dienstdaten an ein Endgerät und Anordnung zur Durchführung des Verfahrens |
-
2003
- 2003-03-05 DE DE10309817A patent/DE10309817A1/de not_active Ceased
-
2004
- 2004-03-05 EP EP04090094A patent/EP1455311A3/de not_active Withdrawn
- 2004-03-05 US US10/794,754 patent/US7437756B2/en not_active Expired - Lifetime
Also Published As
| Publication number | Publication date |
|---|---|
| EP1455311A3 (de) | 2006-06-21 |
| US7437756B2 (en) | 2008-10-14 |
| US20040230798A1 (en) | 2004-11-18 |
| DE10309817A1 (de) | 2004-09-23 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE68922847T2 (de) | Übertragungsvorrichtung. | |
| DE3303846C2 (de) | ||
| DE602005002652T2 (de) | System und Verfahren für das Erneuern von Schlüsseln, welche in Public-Key Kryptographie genutzt werden | |
| DE69333068T2 (de) | Verfahren zur ausdehnung der gültigkeit eines kryptographischen zertifikats | |
| EP1615173A2 (de) | Verfahren und Anordnung zum Generieren eines geheimen Sitzungsschlüssels | |
| DE19744786B4 (de) | Digitalsignatur-Protokoll | |
| DE69128981T2 (de) | Geheimübertragungsverfahren und Geheimübertragungseinrichtung | |
| DE69332396T2 (de) | Paketempfänger in einem Rechnernetz und Rechnernetz mit modifizierten Krypto-Schlüsseln zwischen Rechnerpaaren sowie jeweilige Verfahren | |
| DE102013206185A1 (de) | Verfahren zur Erkennung einer Manipulation eines Sensors und/oder von Sensordaten des Sensors | |
| DE102005018676B4 (de) | Verfahren zur Schlüsselverwaltung für Kryptographiemodule | |
| WO1991014980A1 (de) | Verfahren zur authentifizierung eines eine datenstation benutzenden anwenders | |
| DE102009000869A1 (de) | Verfahren und Vorrichtung zur manipulationssicheren Übertragung von Daten | |
| EP1278332B1 (de) | Verfahren und System zur Echtzeitaufzeichnung mit Sicherheitsmodul | |
| WO2009095286A2 (de) | Datenübertragungsverfahren und tachographensystem | |
| EP1455311A2 (de) | Verfahren zum sicheren Datenaustausch | |
| WO1998026962A1 (de) | Verfahren zur sicherung der datenübertragung | |
| WO2002073374A2 (de) | Verfahren zur authentikation | |
| DE102017219661A1 (de) | Verfahren zum Betreiben eines Steuergeräts | |
| WO2017162386A1 (de) | Verfahren zum übertragen von nachrichten in einem eisenbahnsystem sowie eisenbahnsystem | |
| EP0948158A2 (de) | Verfahren zur sicheren Schlüsselverteilung | |
| EP3412018A1 (de) | Verfahren zum austausch von nachrichten zwischen sicherheitsrelevanten vorrichtungen | |
| DE10305730B4 (de) | Verfahren zum Überprüfen der Gültigkeit von digitalen Freimachungsvermerken | |
| DE102016222599A1 (de) | Verfahren zur Absicherung der Datenübertragung in einem Datenbus | |
| EP4503502A1 (de) | Verfahren zur lokalen erzeugung quantensicherer schlüssel in einem netzwerk | |
| DE102023115999A1 (de) | Verfahren, Vorrichtung, System und Computerprogrammprodukt zur PQ-sicheren Aktualisierung einer Datenverarbeitungseinheit |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL HR LT LV MK |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: FRANCOTYP-POSTALIA GMBH |
|
| PUAL | Search report despatched |
Free format text: ORIGINAL CODE: 0009013 |
|
| AK | Designated contracting states |
Kind code of ref document: A3 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL LT LV MK |
|
| 17P | Request for examination filed |
Effective date: 20060708 |
|
| AKX | Designation fees paid |
Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LI LU MC NL PL PT RO SE SI SK TR |
|
| 17Q | First examination report despatched |
Effective date: 20070808 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: G07B 17/00 20060101AFI20120120BHEP |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20130221 |