EP1766495A2 - Verfahren und speichermedium zum sicheren austausch und nutzen von informationen in einem kommunikationsnetz - Google Patents
Verfahren und speichermedium zum sicheren austausch und nutzen von informationen in einem kommunikationsnetzInfo
- Publication number
- EP1766495A2 EP1766495A2 EP05769980A EP05769980A EP1766495A2 EP 1766495 A2 EP1766495 A2 EP 1766495A2 EP 05769980 A EP05769980 A EP 05769980A EP 05769980 A EP05769980 A EP 05769980A EP 1766495 A2 EP1766495 A2 EP 1766495A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- depot
- storage medium
- user
- platform
- content
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/10—Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6245—Protecting personal data, e.g. for financial or medical purposes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2153—Using hardware token as a secondary aspect
Definitions
- IT information and communication technology
- this development is characterized, above all, by the provision of communication channels with ever greater capacities, which, in line with growing demand, may be adapted to the data volumes to be transmitted.
- Linked to this development is a unification of the transmission protocols used, with the intention of being able to serve all possible types of service types in the future via a uniform transport network.
- DCM defined user group
- a platform is a technical device that provides active functionality through hardware and software. Primitive platforms have a very limited scope of functions and can only be used for a very specific task (telephone, monitor, etc.), complex platforms, like e.g. a PC, however, are able to provide different applications. In this sense, any device of a communication network can also be referred to as a platform.
- a trusted platform we mean a device whose functionality is known exactly and can not be manipulated without the user's knowledge.
- the Trusted Computing Group (TCG) formerly known as the Trusted Computing Platform Alliance (TCPA) proposes in its standards that each "trusted platform" manufacture is a single, globally unique asymmetric one Key pair receives. The secret key remains within the platform and is used for encryption or signature of data, the public key is published. The trustworthiness of the platform is guaranteed by certifying its public key by a trustworthy body (for example the manufacturer).
- 3 shows the general symbol for a platform, wherein the background hidden key is to indicate that in this case it is a trusted platform having the secret key of an asymmetrical key pair.
- this identity can be clearly identified by means of an identity card and is authenticated to the network, for example on the basis of - a smartcard (possession),
- FIG. 4 shows the general symbol for an identity, whereby it should be made clear by the black color of the "photo” and the "P" as a signature that this is a "genuine” (primary) identity
- This symbol is clarified by the ' hidden (secret) key ver ⁇ that this is a "trustworthy” identity that can build a protected Medunikations ⁇ connection to technical facilities.
- this key is securely stored on a smart card, which itself may contain active components such as a processor, and thus is also considered to be a trusted platform in the above sense.
- TCG Trusted Computing Group
- TPM Trusted Platform Module
- a special processor that can generate asymmetric keys (RSA), realizes encryption and decryption of data, and calculates hash functions (SHA-I) that are required for signing.
- RSA asymmetric keys
- SHA-I hash functions
- Asymmetrical key pair that is unique to each TPM.
- the secret share always remains in the TPM and is therefore based on the trustworthiness of the TPM.
- a "trusted authority" certifies a platform, such as a PC, as trustworthy It can then be verified by external communication partners so that a secure communication relationship can be established Data can be safely stored on the platform itself and applications can safely operate on it without running the risk of causing harm or self-harm
- a platform could be used by providers of digital content, for example to allow music or films to be played back on a (secure) PC, without the user being able to copy this content (DRM) trustworthy platforms, it is possible for communication partners to convince themselves of this that no unauthorized manipulation has been carried out on a particular platform. This function is thus of particular interest to the operators of company networks who would like to securely integrate PCs of employees at home
- the underlying role model is shown in FIG.
- the TCG model does not distinguish between the individual (user) and the platform. Although a digital content can be bound to an individual, he is bound to a platform according to TCG ideas. It is not sufficiently clear today what should happen if a user wants to change his platform and wants to take protected content to the new platform (DRM).
- DRM new platform
- TPM defective TPM can lead to the loss of all data on a platform.
- the subject of backup copies on other platforms is highly explosive and still under discussion.
- the "Endorsement Key” forms the basis for all the confidentiality of the TPM and is generated by a manufacturer-specific process during manufacture and programmed into the module, only if it is ensured that the module is able to handle the EK self-generating and programming is given the confidentiality of the TPM.
- the TPM has the option of relying on so-called "Attestation Identity Keys” (AIK) for communication with external partners, ie the use of secondary identities that are used as pseudonyms for the EC It is relevant to data protection because it prevents the communication behavior of a user from being reproduced by linking it to a specific ID (such as the EC.)
- AIK Automated Identity Keys
- Sensitive in this context are all sites that are considered to be sensitive Since at least one entity has to certify the confidentiality of the AIK, at least this CA is able to perform such an ap- proach.
- the migration process i. Mechanisms for transferring data from one platform to another are insufficiently clarified today. Here the user is still attached to the support of the manufacturer of the platform.
- VE verification entity
- the user wishes to access a specific content, he makes a request to the VE and then receives the necessary means, for example in the form of a key, for the access.
- the VE can thus check a wide range of conditions for accessing the content and for the first time unblocks the relationship between the user and the platform.
- the VE plays a central role. It checks and distributes zenzen on request to the terminals (platforms). The behavior of these platforms can thus be controlled indirectly via the licenses distributed by the VE.
- the weak point of the approach is thus the dominant role of the VE.
- the user is permanently dependent on their "good will.” It also remains unclear to what extent the user's privacy is preserved when dealing with the VE.
- the object of the invention is thus to improve the exchange and / or use of trustworthy information.
- the object is achieved according to the features of patent claims 1 and 9 "
- At least one storage medium which can be assigned to at least one user is set up in a communication network.
- trustworthy functions are provided, by means of which associated properties information is stored and / or processed securely in the storage medium and at least trustworthy communication means are assigned to the at least one storage medium.
- the information is processed as a function of the respective assigned properties and as a function of the at least one assigned, trustworthy communication device.
- the essential advantage of the method according to the invention lies in the provision of trustworthy functions which enable the secure storage and processing of information, whereby the privacy of the owner is extended into the communication network and thus data protection reservations with regard to the use of user-related information be solved.
- At least one pseudo-identity is set up and administered by the trustworthy functions, by means of which at least one trustworthy communication relationship can be set up from and to the storage medium.
- Claim 3 The trusted functions ensure that information can be exchanged between communication partners without them being able to gain direct access to the information themselves.
- the storage medium or e-depot according to the invention is a technical device which, within a communication network, mediates between the interests of the communication partners involved and thus contributes to interference-free communication. It largely builds on the TCG mechanisms proposed to date, but adds a significant contribution to it by bringing the communication infrastructure itself into play rather than limiting itself to the communication endpoints.
- the E-Depot can best be compared to a bank account or a securities deposit managed by a neutral, third party (the bank) and the transfer and trustworthy safekeeping of precious things (money or shares). allows.
- the depot itself is opened (or rented) by the user, who retains all rights and uses it in addition to the pure storage especially for the exchange of deposited contents (deposit, payment or transfer).
- Particularly interesting in this context is the comparison with the stock portfolio, since the user is not concerned with holding the actual paper in his hands, but rather with trad- ing in it or with the associated advantages such as dividends consume.
- the e-depot itself is a (technical) device that provides a secure environment to "mediate” in the traffic between communication partners, that is, it provides functionality to securely store user-related digital content and enables it like an account In addition, it also offers other communication partners the possibility to "pay in” (ie transfer) or "debit” (ie download) data as long as they do so
- the E-Depot itself is provided and operated by a third party, the "Operator", who has a neutral role within the communications relationship.
- the operator provides the owner with a facility that extends the privacy of the owner into part of the communication network.
- the owner alone has the e-depot, the data stored on it and the access rights of other parties - see FIG. 6.
- the E-Depot is able to solve this problem by taking over the "agent function" between identities and platforms belonging to the same owner.To the communication partner, the E-Depot represents itself as one of several possible identities.
- the owner communicates with the TMD through one of several possible platforms, and the relationship between the two groups is left to the owner alone, who can freely dispose of it within the framework of previously defined rules.
- An essential feature of the E-Depot is that it controls not only the secure storage of data or contents but also their further use. That it also provides functions that allow contents entrusted to it to be handled specifically according to the wishes of the communication partners. This is achieved by implementing the e-depot itself as a trusted platform. Its scope of functions is clearly defined and known to every user who transfers their contents to the e-depot in a "package" together with a so-called “license file”. This license contains all the necessary information which the e-depot requires in order to be able to subsequently treat the contents in the sense of the user.
- the most important feature here is that the E-Depot is able to carry out internally cryptographic operations on the digital content without the actual contents ever leaving the E-Depot unencrypted. This functionality is equivalent to comparing it with the "stock” that is safely held in the vault without the owner even having access to the actual paper, taking the e-vault one step further and ensuring that even the operator does not is able to access the content without authorization.
- the user rents the e-depot to an operator.
- the e-depot itself has no identification data and the new owner can configure it so that it only manages it and can be used.
- the owner first registers his platforms with the e-depot by, inter alia, transmitting their public key.
- the E-Depot is able to establish a secure connection to each of these platforms and exchange data afterwards.
- the owner may cause the e-depot to generate secondary identities. For this, the E-Depot generates a new asymmetric key pair.
- the secret portion remains within the e-depot and the public portion can subsequently be used for communication with an external partner or group - see FIG. 7.
- Each platform managed by an e-depot must be trusted by the TCG. However, since the e-depot itself is a trustworthy platform that "belongs" to the user, he should not have a problem with it if he synchronizes his platforms periodically with the e-depot. Exchanging content between them.
- a platform is characterized by certain properties, such as possible input / output methods, characterized be certified by the manufacturer or another CA.
- the communication partner receives, in addition to the key, further attributes which characterize the communication relationship and which are involved by both TMDs can be interpreted. These attributes include, for example:
- the e-depot After the e-depot has received such a packaged data packet, it first checks the communication attributes of the relevant secondary identity and will then decrypt the packet using the secret key of the identity used. Of course, the e-depot can also check the authenticity of the sender and the integrity of the data in question. Both the content and the license are then re-encrypted and stored by the e-depot with its own secret memory key. The owner of the E-Depot can at any time have a directory of the data stored in the E-Depot displayed. Instead of the actual content, he can access the license and read it.
- the license contains a collection of attributes which can be interpreted by the e-depot and which can thus control the further handling of the associated content. It contains e.g. Information on whether the use of the content is tied to specific platforms, whether the number of platforms is limited, whether the content may be passed on to another e-depot or which Certified authorities (CA) the provider trusts ,
- CA Certified authorities
- the license contains a series of instructions and attributes which are comparable to a program code which controls further methods of the e-depot with respect to a content.
- the e-vault will use the license, which can not be changed by anyone, and will copy the content to one or more of the owner's sites, provided that they are trusted by the license , If an attribute contradicts an order of the owner, for example if he is still too young for a particular content, this can be taken into account by the e-depot and the order is not carried out. If a provider only wants to offer content as a sample, this can also be noted in the license. Then the e-depot only provides the content for a certain duration (eg only the first 10 minutes of a movie) before the attribution by the e-depot is automatically interrupted.
- a certain duration eg only the first 10 minutes of a movie
- a special case is the saving or passing on (migrating) of contents. Also this case, which is still not solved satisfactorily today by the TCG, can be steered with the help of the license:
- the user can acquire his own platform, which acts as a trustworthy storage medium, logging on and transferring all the data there. Since he will continue to have no access to the platform, this possibility should not be ruled out in any license. If a user wishes to pass on or resell a certain content, then this is also possible if the license permits this. Since the E-Depot itself is a trusted platform, it can even be registered with another E-Depot. The basis for this is a log file, which is created by the E-Depot with each new content and then maintained.
- the E-Depot can e.g. Determine on which platforms a specific content has already been transferred. Before the contents are migrated, the content could thus be "recalled" by the e-depot and subsequently released.To prevent possible manipulation by the owner, he may only have reading rights to the log himself.Put the case, the e-depot would be destroyed, all information stored in it could be retrieved with a combination of a backup of the E-Depot and the log stored at the operator.
- Each content within the e-depot is represented by the following four components, collectively referred to as an "entry.” These include: the encrypted content, the license, the log, and a link to a memory location. As will be explained below, the storage of the content is not locally tied to the E-Depot itself, but it is sufficient if the ⁇ -Depot can use the link to access the data record within the network.
- TMD Trusted Mediation Device
- TPM Trusted Platform Module
- TEM Trusted Encryption Module
- TMC Trusted E-Depot Controller
- TMD Trusted E-Depot Operating System
- RTC real-time clock
- ⁇ - A communication interface through which external identities (owner, operator or communication partner) contact the E-Depot.
- ⁇ - One (or more distributed) storage media (media, e.g., hard disk) for storage of content.
- TMD In order to ensure the trustworthiness of the TMD, its internal structure, its functioning and thus its operating system (TMOS) should be made public.
- TMOS operating system
- the user turns to an op- erator of their choice and identifies himself here with his ID card in accordance with an account opening at a bank. In doing so, he hands the operator a public key that represents his identity. The operator programs this public key and, if necessary, additional person-specific data, e.g. Name and date of birth, in the FLASH of the TMD and informs the future owner of the successful opening by handing him a currently valid public key of the TMD.
- additional person-specific data e.g. Name and date of birth
- a reset of the TMD causes the following operations: '
- the TMD continues in its original condition, ie it deletes all information except for the ge Items ⁇ in memory th data of the owner:
- the owner can freely dispose of the TMD. So probably the owner as well as the TMD possess from now on a secret communication relation, on the basis of which the further safe use of the TMD can take place.
- Essential components of the configuration include the registration of platforms and the generation of secondary identities.
- the owner requests the TMD to create a new "identity object," including a new asymmetric key pair used for the communication relationships of that identity, and a new network address provided by the operator.
- a secondary identity can also inherit properties of the owner, such as his age, if this should play a role in the transactions.
- the information within the TMD appears merely as a further file system within a platform of the owner.
- the operator provides the TMD and integrates it into its communication network. Depending on the application, he can TMD certain properties, such. the maximum number
- the owner of the TMD can at any time make backups of his local data and save them securely on the TMD.
- the spatial separation between two storage locations alone is helpful, for example. in the case of a haverie in one place, to restore the data to the other ("money that is on the bank can not be lost at home.”).
- the provider of a content can use the associated license to achieve that the content can be consumed at previously specified conditions "for the sample.” Possible conditions for this can be, for example, the duration or the number of uses. In this case, the TMD does not transmit the relevant content as a whole but only transfers part of the content to the relevant platform.
- the owner of a TDM may freely dispose of the use of content, as long as this component is part of the license. That He can consume a once acquired content on several platforms, but also give it away or sell it.
- the TMD ensures that the content has previously been deleted on all relevant platforms of the owner before it releases the content for forwarding to another TMD. Due to the fixed connection between content and license, the author can be sure that the contents are not copied inappropriately.
- the owner may also grant his communication partners access to content residing in his e-depot.
- the partner is able to download current contents from this e-depot as needed.
- the TMD is online 24 hours a day (contrary to the computer technology of most users). Since it itself has its own processor, it is also conceivable that it performs certain services for the user around the clock. It is conceivable that it reacts to certain events and automatically sends a message to a platform (eg mobile phone) or that this processor is instructed by the user to initiate active processes in the network, such as the continent. Continuous acquisition of measured values.
- a platform eg mobile phone
- new business models can be developed with the help of the e-depot, which should in particular be of interest to the operator.
- the user pays with his credit card, passes his credit card number and registers his platform (terminal or smartcard) with the provider.
- the provider (or his deputy) encrypts the content platform-specific (with the public key of the platform) and transmits the encrypted content together with a license file * '(rights object) to the user.
- the user's access to the content is tied to his "ownership of a registered platform". If the user wants to port the content to another platform, he must first register it with the provider and then have the content re-encrypted.
- the user orders a film from the internet provider by using a pseudo-identity which he himself previously created in the ⁇ -depot.
- the user contacts the provider's e-depot and transfers necessary data, such as credit card number and identification data of the pseudo identity (public key). It is important that this data can be provided by the user himself with a license with which he can control, for example, that his credit card number is used by the e-depot of the provider only for an account debit (trust controlled operation controlled as a license). and not to the provider itself!
- the provider himself can convince himself of the trusted data of the user (or his E-Depots) based on the transferred data and encrypt the film only after a successful payment, which is made and confirmed by his own e-depot, with the public key and issue. This means that the provider is only informed about the result of an operation and not about the data used by the operation (credit card number) of the user.
- the E-Depot itself constitutes a trustworthy platform, which itself has a TPM and is certificated by a CA (eg by the manufacturer). This requirement is an important part of this concept.
- the following "Chain of Trust" makes this connection clear: a) The TCG defines general mechanisms for the realization of trustworthy platforms Affected platforms are certified by a CA, thus the user of it can be assumed to function in accordance with its intended purpose.
- the TMD itself can be realized as such a platform whose functionality is clearly defined.
- the CA confirms this with a certificate and the users (i.e., owners and communication partners) can trust it.
- any secondary identity can also be certified representative of the CA by the TMD.
- the TMD would have to contain a secret key of the CA (for example of the manufacturer), which can be used in this case. However, this should not be a problem, as the manufacturer should trust his platform, which he underlines by this measure only once again.
- the relationship shown solves a privacy problem in a very elegant way because the TMD owner does not have to make a new request to the CA for each secondary identity.
- the TMD itself is rela ⁇ tively small. It could, for example, be an integrated circuit which, similar to the TPM, contains all security-relevant functions (functionalities of the TMD)
- the TMD would still need to have access to at least one memory (eg hard disk) on which the contents are stored Since data is stored encrypted on the storage medium, its position in the system is "uncritical" and a hard disk could even be split between several TMDs Some contents could be stored at distributed locations in the network, others could be safely stored even by the user In such a scenario, it would be up to the TMD to provide a list of links manage, in which the addresses of the respective Speicherbe ⁇ rich are listed.
- this arrangement consisting of TMD and storage medium (or media) could be placed at any point within a communication network if only sufficient transport routes to the users are provided.
- this arrangement it is advisable to place this arrangement as close as possible to the owner, since he practically uses his TMD as
- the TMD would be defined as part of an access network.
- FIG. 10 shows an example of such a realization within an Ethernet-based DSLAM.
- another component could be installed in the future, including several TMDs
- 25 modules and possibly the associated storage medium could contain.
- the user could then easily record a direct, unprotected connection to the network (path 1), or access his TMD (path 2). Here he could either directly access its contents or by means of a secondary
- TMD module within a network termination device (for example an xDSL modem) is conceivable, which is installed locally at the user but nevertheless counted to the area of jurisdiction of the network operator
- the invention relates to the idea of a new technical device with the name "E-Depot", which is to be used within the 'infrastructure of a communications network and realizes there a trustworthy intermediary function between the interests of communication partners is a trusted one
- Platform used for secure storage of digital content (documents, applications, media, etc.). It provides trustworthy operations which ensure that these contents can be exchanged between the communication partners without them themselves gaining direct access to the contents.
- each content is provided by the author with a license that controls all other operations of the E-Depot with respect to this content. can.
- An important operation in this case is a trustworthy, combined decryption and encryption of a content in which the content itself remains untouched.
- the e-depot offers operations that extend the privacy of the owner into the communications network, thereby solving privacy-related reservations with regard to the use of user-related digital content.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- Technology Law (AREA)
- Multimedia (AREA)
- General Health & Medical Sciences (AREA)
- Bioethics (AREA)
- Databases & Information Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Medical Informatics (AREA)
- Storage Device Security (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102004034294 | 2004-07-15 | ||
| PCT/EP2005/053355 WO2006005763A2 (de) | 2004-07-15 | 2005-07-13 | Verfahren und speichermedium zum sicheren austausch und nutzen von informationen in einem kommunikationsnetz |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1766495A2 true EP1766495A2 (de) | 2007-03-28 |
Family
ID=35542937
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP05769980A Withdrawn EP1766495A2 (de) | 2004-07-15 | 2005-07-13 | Verfahren und speichermedium zum sicheren austausch und nutzen von informationen in einem kommunikationsnetz |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP1766495A2 (de) |
| WO (1) | WO2006005763A2 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102013106053A1 (de) | 2013-06-11 | 2014-12-11 | Das Forum GmbH | Verfahren zur Aufbewahrung und Herausgabe von zumindest einem Datensatz |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1312549C (zh) * | 1995-02-13 | 2007-04-25 | 英特特拉斯特技术公司 | 用于安全交易管理和电子权利保护的系统和方法 |
| US6223291B1 (en) * | 1999-03-26 | 2001-04-24 | Motorola, Inc. | Secure wireless electronic-commerce system with digital product certificates and digital license certificates |
| US6904417B2 (en) * | 2000-01-06 | 2005-06-07 | Jefferson Data Strategies, Llc | Policy notice method and system |
| US6865555B2 (en) * | 2001-11-21 | 2005-03-08 | Digeo, Inc. | System and method for providing conditional access to digital content |
-
2005
- 2005-07-13 WO PCT/EP2005/053355 patent/WO2006005763A2/de not_active Ceased
- 2005-07-13 EP EP05769980A patent/EP1766495A2/de not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2006005763A3 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2006005763A3 (de) | 2006-07-13 |
| WO2006005763A2 (de) | 2006-01-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE69521413T2 (de) | Verschlüsselungseinrichtung und verfahren mit möglichkeit zur gesicherten zentralen schlüsselablage | |
| DE69900934T2 (de) | Terminal und system zur durchführung von gesicherten elektronischen transaktionen | |
| TWI720596B (zh) | 區塊鏈存證方法、裝置和電腦設備 | |
| DE69534490T2 (de) | Verfahren zur sicheren anwendung digitaler unterschriften in einem kommerziellen verschlüsselungssystem | |
| EP2585963B1 (de) | Verfahren zur erzeugung eines zertifikats | |
| EP2513833B1 (de) | Überprüfbare verlässlichkeit für daten durch wrapper-struktur | |
| EP2454704B1 (de) | Verfahren zum lesen von attributen aus einem id-token | |
| DE102018122997A1 (de) | Blockkettenentität, kettenexterne entität, zertifizierungsvorrichtung für blockkettenoperationen und verfahren zum durchführen einer kooperation zwischen einer blockkettenentität und einer kettenexternen entität | |
| EP4254234B1 (de) | Ausstellen eines digitalen credentials für eine entität | |
| EP4092958B1 (de) | Ausstellen eines digitalen verifizierbaren credentials | |
| DE102004025084A1 (de) | Personen-Authentifizierungs-Vorrichtung und Personen-Authentifizierungs-System und Personen-Authentifizierungs-Verfahren | |
| CZ78798A3 (cs) | Systém a způsob prokázání pravosti dokumentů | |
| EP1209579A1 (de) | System zur automatisierten Abwicklung von Transaktionen durch aktives Identitätsmanagement | |
| WO2022008320A1 (de) | Bezahlsystem, münzregister, teilnehmereinheit, transaktionsregister, überwachungsregister und verfahren zum bezahlen mit elektronischen münzdatensätzen | |
| DE10125017A1 (de) | Verfahren zum Erbringen von Diensten in einem Datenübertragungsnetz und zugehörige Komponenten | |
| CN107742085A (zh) | 一种数据保全系统 | |
| Borselius | Multi-agent system security for mobile communication | |
| EP3939226A1 (de) | Verfahren zum authentifizieren eines computersystems | |
| WO2006005763A2 (de) | Verfahren und speichermedium zum sicheren austausch und nutzen von informationen in einem kommunikationsnetz | |
| US10454972B2 (en) | Method for protecting intangible assets in telecommunications networks | |
| DE102021129047B4 (de) | Selektiv anonymisierende Überweisung einer Kryptowährung | |
| DE102012106081A1 (de) | Verfahren zur verschlüsselten und anonymisierten Verwahrung und Verwaltung von personenbezogenen Daten oder Dateien | |
| EP1248432B1 (de) | Verfahren und System zum Abfragen von Zertifikatsinformationen unter Verwendung von dynamischen Zertifikatsreferenzen | |
| EP4703938A1 (de) | System, verfahren und computerprogrammprodukt zur sicheren kommunikation zwischen zwei akteuren | |
| DE102006006489A1 (de) | Verfahren zur Durchführung eines Schreibzugriffs, Computerprogrammprodukt, Computersystem und Chipkarte |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20070103 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: NOKIA SIEMENS NETWORKS GMBH & CO. KG |
|
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: NOKIA SIEMENS NETWORKS S.P.A. |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: NOKIA SIEMENS NETWORKS GMBH & CO. KG |
|
| 17Q | First examination report despatched |
Effective date: 20080811 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20081223 |