EP2025119A1 - Authentisierung für entfernte funktionsaufrufe - Google Patents
Authentisierung für entfernte funktionsaufrufeInfo
- Publication number
- EP2025119A1 EP2025119A1 EP07725303A EP07725303A EP2025119A1 EP 2025119 A1 EP2025119 A1 EP 2025119A1 EP 07725303 A EP07725303 A EP 07725303A EP 07725303 A EP07725303 A EP 07725303A EP 2025119 A1 EP2025119 A1 EP 2025119A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- rpc
- command
- secure
- secure messaging
- data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0853—Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/357—Cards having a plurality of specified features
- G06Q20/3574—Multiple applications on card
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1016—Devices or methods for securing the PIN and other transaction-data, e.g. by encryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the invention relates to a method for the secure exchange of data between at least two instances, inter alia, exchanging their data via so-called remote function calls or remote procedure calls (hereinafter referred to as RPC commands for short), wherein in the exchange of RPC commands an additional safety mechanism is provided.
- a chip card can serve as a data storage as well as authorization for certain information and / or for the execution of certain commands in addition to the function.
- An important aspect of data transfer therefore, is to ensure the integrity and authenticity of messages to be transmitted and, where appropriate, the confidentiality and binding nature of the messages.
- the purpose of verifying authenticity is, on the one hand, to ensure an unambiguous association between sender and recipient of the message and, on the other hand, to prove that a message received from the recipient has not been changed during its transmission.
- the verification of authenticity plays an essential role in the context of an authentication.
- the purpose of an authentication is to verify the identity and authenticity of a communication partner during data transmission.
- a variety of methods and mechanisms have been developed in this context to increase the overall security of data transmission in connection with smart cards. These mechanisms and procedures fall under the generic term "Secure Messaging".
- Secure Messaging When applying secure messaging methods to chip card technology, it must be taken into consideration that the computing power of at least one of the two communication partners and / or the transmission speed between the two communication partners may be subject to restrictions.
- a secure messaging technique has been standardized in ISO / IEC 7816-4 and advanced features have been standardized in ISO / IEC standard 7816-8.
- remote procedure calls also referred to as RPC for short.
- RPC remote procedure calls
- the present invention has therefore set itself the task of providing a way to remote function calls (Remote Procedure Calls), which are executed directly on the mobile disk - especially on the smart card - to combine with an additional security mechanism, while the resources the instances involved are claimed to the least extent possible.
- remote function calls Remote Procedure Calls
- the flexibility and performance of using RPC commands on a mobile data carrier should be increased without sacrificing security.
- the above-mentioned limitations and disadvantages of the prior art are to be overcome.
- This object is achieved according to the invention by a method for authentication between at least two instances which are assigned to a mobile data carrier, in particular a chip card, wherein an execution of RPC commands in connection with the mobile data carrier is supported by a calling entity authorizing the RPC request. Sends a command to a called instance for execution, and wherein the method is based on security mechanisms, in particular secure messaging, which ensure at least the authenticity and, if necessary, the confidentiality of the data to be transferred or parts thereof, with the following method steps:
- the secure data transfer is a
- Data transmission that takes into account security mechanisms.
- the mechanisms and procedures applicable in this context may also be referred to as secure messaging. This includes procedures that determine the authenticity of a communication partner, the identity of a Communication partners, the confidentiality of the data to be transmitted and / or the liability of the data to be transmitted and / or the confidentiality of the data to be transmitted.
- the term "liability" of the data transmitted in this context should be understood as the possibility of the sender to check whether a particular recipient has received a message. A denial of the receipt of a message is no longer possible with a binding data transmission.
- a secure channel is set up for secure messaging, via which the data to be transmitted is exchanged.
- An important advantage of the solution according to the invention is the fact that it is sufficient to provide a secure channel for data transmission, via which an access of possibly different instances then takes place in a secure manner. It is therefore not necessary that a separate, separate secure channel must be set up for each instance (accessing remote or "foreign" data records), which can significantly save the resources of the entire system.
- “Secure messaging records” in the context of this invention are records that are relevant in the context of a security mechanism for data transmission. According to the invention, however, different security mechanisms can be used, so that the content of the secure messaging data records can be designed differently in content.
- the secure messaging record usually includes one Authentication information.
- the secure messaging record additionally comprises confidentiality information. This feature is optional. Purpose of the authentication is the verification of the authenticity and / or the identity of the respective partner instance. The authentication information thus serves in particular to determine whether the card or the terminal is actually a real card or a true terminal. The authentication information or the authentication record thus clearly refers to an instance or a person.
- identity is encompassed by the term "authentication”.
- a mobile data carrier may be a smart card, a smartcard or other card with a microprocessor, or it may also be a complex electronic component or device, such as e.g. a security token or other mobile bearer of digital data, each equipped with appropriate interfaces for data communication.
- an "instance” is to be understood as meaning all units or modules which are involved in a data transmission.
- a calling entity that requests data from another entity and is destined to receive that data.
- There is also a called instance that receives a particular command and is destined to execute that command. After executing the command on the called instance, the result of the command is returned to the calling entity.
- the calling entity is for issuing an RPC command and the called entity is for executing the RPC command and outputting a result.
- An instance can be functions, procedures or more complex program parts or programs, but also separate electronic devices or components.
- An instance can run directly or directly on the mobile disk. Moreover, it is possible that an instance does not run directly on the mobile volume, but is assigned to it only indirectly, by running on an external unit that is in communication with the mobile volume. there can it be z. For example, a chip card terminal or another back office act.
- RPC commands are used as the communication mechanism.
- only RPC commands are used for the entire data exchange.
- other communication structures may be provided in other embodiments.
- the RPC client and / or the RPC server can thus be provided on the same or another mobile data carrier or in a (smart card) terminal.
- RPC commands are executed directly on the chip card.
- certain Web services should be mentioned, which allow access to various services via Internet-based protocols.
- it is necessary to provide additional safety Mechar ⁇ smen even if previously a secure channel has been established.
- Messaging data in particular the authentication information, in relation to the participating entities.
- the authentication information is provided and / or generated.
- the authentication information is specified by the calling entity.
- the authentication information is not provided by the calling entity, but is automatically generated by a middleware.
- a “middleware” is to be understood as a technology which is application-independent and offers different services for switching between separate applications. It is, so to speak, one of the Actual application decoupled platform to mediate function calls between individual instances and organizes the transport of complex data. It is thus possible to handle remote procedure calls via middleware.
- the authentication information is transmitted in combination with the transmission of the parameters for the remote function call, ie the RPC command.
- different options are provided for this.
- the authentication information is preferably linked to the transmission of the parameters of a function call to the chip card.
- the authentication information may be particularly involved in marshaling (where "marshaling" means receiving and converting a set of structured data elements into a format required to send the data elements in a message to a recipient).
- the authentication information is tied to the smart card's response to the RPC command.
- the "result" of the RPC command is here to be understood to mean all return values to the RPC command which, if appropriate, are sent back next to the actual response.
- the authentication information can also be done after the transmission of the actual RPC command, in particular in a credits after the RPC sequence.
- the method comprises a check of the authentication information.
- different variants are also provided according to the invention.
- the check is made directly on the smart card or on the security device to which the RPC command has been addressed.
- it may also be provided to have the verification of the authentication carried out in other instances or on an external module.
- Protocol can then be set the format for the authentication record dynamically.
- At least one of the two communication instances runs on the mobile data carrier, in particular on the chip card. Usually, this is the called instance used to execute the RPC command. If it is a multi-application system, the other instance, ie the calling entity, can be assigned to another application on the same chip card. For an operating system that supports only a single application at a time, the calling instance may be associated with an external environment.
- the external environment may be any other instance that is in communication with the smart card.
- web services are to be mentioned here, which are based on data transmission over the Internet. This feature mainly affects networkable internet smart cards.
- Another task solution consists in a mobile data carrier, in particular in a chip card, in a security token or in a chip card module according to claim 12, in a more complex device, which is equipped with such a mobile data carrier, according to patent claim 13.
- the device it can be any electronic device, preferably a portable device such as a cell phone or a PDA equipped with a mobile data carrier.
- Other task solutions can be seen in a system according to claim 14 and in a computer program product according to claim 15.
- An alternative task solution provides an interface with respect to a mobile data carrier which is controlled and / or operated according to the method described above.
- FIG. 1 is a schematic representation of transmitted remote procedure calls according to a preferred embodiment of the invention
- Fig. 2 is a schematic representation of a protocol stack, which is used in a preferred embodiment of the invention and used
- FIG. 3 shows an overview of modules according to a preferred embodiment of the invention.
- the invention relates to a method for secure data transmission between multiple instances Ri, Gi, wherein at least one called instance Gi runs on a mobile data carrier, in particular on a chip card C.
- the data transmission may include execution of remote function calls, namely remote procedure calls RPC-B, RPC-E.
- FIG. 3 the data transmission according to the invention is shown schematically.
- An RPC command structure is based on a client-server approach and is usually handled synchronously. This means that a calling party Ri sets an RPC command RPC-B and waits until it receives the corresponding result RPC-E from the called instance Gi on the RPC command RPC-B. While the calling entity Ri is waiting, the called entity Gi processes the RPC command.
- the authentication information A is combined with parameters that are transmitted in connection with the function call RPC-B.
- the response from the chip card C ie the result RPC-E of the RPC command RPC-B, be provided with an authentication information A.
- the authentication information A is checked.
- the check can either be on the smart card C or on another unit to which the RPC command RPC-B has been addressed.
- the data exchange between the participating entities Ri and Gi is handled via a so-called middleware, which implements the corresponding commands.
- the RPC data including the necessary parameters and the authentication information A may also be transmitted separately. If a protocol according to the ISO / IEC 7816-4 standard is used as the transmission protocol, then the
- APDU Application Protocol Data Unit
- the RPC data with the authentication information A can be transmitted in several different APDU sequences.
- the authentication information A is a plurality of data units to be transmitted
- FIG. 1 shows the case that there are two calling entities Ri and R 2 which transmit corresponding RPC commands RPC-B to the chip card C. After execution of the RPC command on the chip card C can be transmitted from this, the answer or a result RPC-E back to the calling entity Ri.
- the authentication information A is transmitted with the RPC request RPC-B and / or with the RPC response RPC-E.
- a particular advantage of the solution according to the invention is therefore too see that the transmission according to the invention can be dynamically configured.
- appropriate settings can be made via configuration parameters that z. B. specify which RPC protocol is used, in which format the authentication record A should be present, whether the authentication information A all or only part of the parameters to be transmitted, whether the authentication information A with the RPC command RPC-B and / or to be transmitted with the RPC result RPC-E and / or on which instance Ri, Gi a check of the authentication is to take place.
- inventive method can be dynamically adapted to the particular application. According to the invention, therefore, flexible authentications of different entities Ri, Gi can be connected, independently of the secure channel over which the function calls RPC-B, RPC-E are handled.
- a network layer can be arranged as an optional feature, for.
- a TCP / IP layer Over the network layer can also be formed as an optional element, a backup layer. This can be based on SSL or SECM protocols or other protocols.
- the uppermost layer is the application layer, which according to the invention is designed on a modified application protocol for the transmission of RPC commands RPC-B, RPC-E with authentication data A.
- the invention relates to an additional functionality for forming a corresponding interface for communication with a mobile data carrier C and different instances Ri, Gi.
- the modification relates to the combined transmission of RPC commands RPC-B, RPC-E and authentication information A.
- the interface according to the invention is controlled and / or operated by the method described above.
- the interface Due to the flexible configurability of the interface according to the invention, it can be optimally designed for the respective application. In particular, it is adjustable which security mechanisms are to be used, for. As a backup against tampering with the Authentic-Verf ears and / or against interception by appropriate Encryption mechanisms, in particular by means of the combined method.
- RMI remote method invocation
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Physics & Mathematics (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Signal Processing (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Accounting & Taxation (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE200610023436 DE102006023436A1 (de) | 2006-05-18 | 2006-05-18 | Authentisierung für entfernte Funktionsaufrufe |
| PCT/EP2007/004388 WO2007134784A1 (de) | 2006-05-18 | 2007-05-16 | Authentisierung für entfernte funktionsaufrufe |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2025119A1 true EP2025119A1 (de) | 2009-02-18 |
Family
ID=38458165
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP07725303A Ceased EP2025119A1 (de) | 2006-05-18 | 2007-05-16 | Authentisierung für entfernte funktionsaufrufe |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP2025119A1 (de) |
| DE (1) | DE102006023436A1 (de) |
| WO (1) | WO2007134784A1 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11729178B2 (en) | 2021-02-05 | 2023-08-15 | Shopify Inc. | Systems and methods for generating account permissions based on application programming interface interactions |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE69714752C5 (de) * | 1996-10-25 | 2015-08-13 | Gemalto Sa | Verwendung einer hohen programmiersprache in einem mikrokontroller |
| US6547150B1 (en) * | 1999-05-11 | 2003-04-15 | Microsoft Corporation | Smart card application development system and method |
| US20040123138A1 (en) * | 2002-12-18 | 2004-06-24 | Eric Le Saint | Uniform security token authentication, authorization and accounting framework |
| US20080245860A1 (en) * | 2003-09-09 | 2008-10-09 | Marco Polano | Method and System for Remote Card Access, Computer Program Product Therefor |
-
2006
- 2006-05-18 DE DE200610023436 patent/DE102006023436A1/de not_active Withdrawn
-
2007
- 2007-05-16 EP EP07725303A patent/EP2025119A1/de not_active Ceased
- 2007-05-16 WO PCT/EP2007/004388 patent/WO2007134784A1/de not_active Ceased
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2007134784A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2007134784A1 (de) | 2007-11-29 |
| DE102006023436A1 (de) | 2007-11-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2417550B1 (de) | Verfahren zur durchführung einer applikation mit hilfe eines tragbaren datenträgers | |
| DE60315552T2 (de) | IC-Karte und Methode zur Authentisierung in einem elektronischen Ticket-Verteiler-System | |
| DE69534181T2 (de) | System mit Endgerät und Karte, Karte und Endgerät | |
| EP2415228B1 (de) | Verfahren zum lesen von attributen aus einem id-token über eine mobilfunkverbindung | |
| EP2567345B1 (de) | Verfahren zum lesen eines rfid-tokens, rfid-karte und elektronisches gerät | |
| WO2011006791A1 (de) | Verfahren zum lesen von attributen aus einem id-token | |
| EP3748521B1 (de) | Verfahren zum lesen von attributen aus einem id-token | |
| EP3271855B1 (de) | Verfahren zur erzeugung eines zertifikats für einen sicherheitstoken | |
| DE102008042582A1 (de) | Telekommunikationsverfahren, Computerprogrammprodukt und Computersystem | |
| EP2932446A1 (de) | Reputationssystem und verfahren | |
| EP1222563A2 (de) | System zur ausführung einer transaktion | |
| WO2007134784A1 (de) | Authentisierung für entfernte funktionsaufrufe | |
| EP2752785B1 (de) | Verfahren zur Personalisierung eines Secure Elements (SE) und Computersystem | |
| EP3244331B1 (de) | Verfahren zum lesen von attributen aus einem id-token | |
| EP2923264B1 (de) | Verfahren und system zur applikationsinstallation in einem sicherheitselement | |
| EP2169579A1 (de) | Verfahren und Vorrichtung zum Zugriff auf ein maschinenlesbares Dokument | |
| EP3367285B1 (de) | Terminal, id-token, computerprogramm und entsprechende verfahren zur authentisierung einer zugangsberechtigung | |
| EP3107029A1 (de) | Verfahren und vorrichtung zum personalisierten elektronischen signieren eines dokuments und computerprogrammprodukt | |
| EP2740070B1 (de) | Mechanismus zur kommunikation zwischen zwei applikationen auf einem sicherheitsmodul | |
| WO2014037136A1 (de) | Verfahren zur personalisierung eines secure elements (se) und computersystem | |
| DE10136384C2 (de) | Vorrichtung zum rechnergesteuerten Erzeugen einer Vielzahl von Datensätzen | |
| DE102004058020A1 (de) | Verfahren zur Personalisierung von Chipkarten | |
| DE102016123019A1 (de) | Verfahren zum elektronischen Initiieren einer Aktion und elektronisches System zum elektronischen Initiieren einer Aktion | |
| DE102020104646A1 (de) | Browserbasierter Fernzugriff auf Hardware-Sicherheitsmodul | |
| DE10219731A1 (de) | Verfahren zur Ausführung einer Datentransaktion mittels einer aus einer Haupt- und einer trennbaren Hilfskomponente bestehenden Transaktionsvorrichtung |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20081218 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA HR MK RS |
|
| 17Q | First examination report despatched |
Effective date: 20090709 |
|
| APBK | Appeal reference recorded |
Free format text: ORIGINAL CODE: EPIDOSNREFNE |
|
| APBN | Date of receipt of notice of appeal recorded |
Free format text: ORIGINAL CODE: EPIDOSNNOA2E |
|
| APBR | Date of receipt of statement of grounds of appeal recorded |
Free format text: ORIGINAL CODE: EPIDOSNNOA3E |
|
| APAF | Appeal reference modified |
Free format text: ORIGINAL CODE: EPIDOSCREFNE |
|
| DAX | Request for extension of the european patent (deleted) | ||
| APAF | Appeal reference modified |
Free format text: ORIGINAL CODE: EPIDOSCREFNE |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| APBT | Appeal procedure closed |
Free format text: ORIGINAL CODE: EPIDOSNNOA9E |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20140128 |