EP2050080A2 - Personalisierung von tragbaren datenträgern - Google Patents
Personalisierung von tragbaren datenträgernInfo
- Publication number
- EP2050080A2 EP2050080A2 EP07786301A EP07786301A EP2050080A2 EP 2050080 A2 EP2050080 A2 EP 2050080A2 EP 07786301 A EP07786301 A EP 07786301A EP 07786301 A EP07786301 A EP 07786301A EP 2050080 A2 EP2050080 A2 EP 2050080A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- data
- personalization
- memory
- virtual
- data carrier
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/355—Personalisation of cards for use
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/355—Personalisation of cards for use
- G06Q20/3552—Downloading or loading of personalisation data
Definitions
- the present invention relates to the personalization of portable data carriers, such as smart cards, mobile communication cards and the like, by providing the data carriers with digital data, in particular by introducing the data into nonvolatile memory, also known as NVM (Non Volatile Memory) memory, such as EEPROM - or flash memory.
- NVM Non Volatile Memory
- the process of electrical personalization can be divided into two sections.
- the initialization the volume is given general data that is identical for all volumes of the same type. This type of personalization data is called initialization data below.
- the individualization each data carrier is provided with individual data, for example containing data that adapt the individual data carrier to the end customer. This type of personalization data is referred to below as customization data.
- the process of personalizing disks is a critical step in the entire disk production process because the time it takes to write to the non-volatile memory of the personalization data media is comparatively high and the pro- production costs.
- the step of initialization can be accelerated by initially initializing only a single data carrier conventionally by means of logical commands. Thereafter, a memory dump of the entire memory of this volume is generated and used to initialize the other volumes using the physical memory addresses.
- Such a memory image is also called Image.
- an image refers to an exact, bit-accurate image of the original and thus contains much more information than just the files stored on the original volume, including the structure of the file system and the like. This makes it possible to quickly produce an exact, bit-precise reproduction of the data carrier, because it can be used directly for hardware functions and physical memory addresses. It is also possible to only part of the whole
- Memory to generate a memory image and bring this directly into unused corresponding memory areas of another disk or bring only parts of a memory image of an entire memory in another disk.
- data carriers can also be personalized that do not yet have any structure in the memory area to be described and on which no file system is yet available.
- a reconversion routine is then carried out for each further data carrier initialized by a memory image for the purpose of reconverting the nonvolatile memory loaded with the memory image.
- the reconversion comprises, for example, that previously based on a random number Zl disguised data, such as key, based on a data carrier-individual random number Z2 disguised data.
- US 6 202155 Bl describes a system for personalizing transaction cards.
- the system receives the necessary information for personalization and forms a virtual map.
- Virtual devices in this system control real, physical personalization engines, which then fabricate the real transaction card based on the virtual card data.
- Information about the technical implementation of the individual personalization steps, in particular the introduction of the data into the cards, is not provided there.
- US 6729549 B2 describes a system for personalizing smart cards.
- the smart cards are initially generated virtually by means of a control program.
- the personalization of a real smart card is then carried out by means of a personalization program by accessing the virtual smart card.
- the smart cards to be personalized are already partly pre-initialized, in particular they already have a defined file structure, which is already modeled when the virtual smart card is generated.
- the personalization data is written by the personalization program by means of smart card specific logical commands in the real smart card.
- the object of the present invention is to shorten the production time of the data carrier by accelerating the personalization process and thereby to reduce the production costs.
- the invention is based on the basic idea that the personalization of each data carrier is first made individually as a virtual personalization of a virtual data carrier.
- the virtual data carrier is set up to emulate all the features of the real data carrier, in particular also its hardware features.
- a memory image is then generated.
- the memory image is then introduced directly into a corresponding memory of the real data carrier, the personalization data generated by the virtual personalization also including the individualization data in addition to the initialization data. All structure information about the file system and the like are thus transmitted by the memory image. It is therefore possible to combine the previously separate production steps of initialization and individualization by virtualization in one step.
- a data carrier-specific memory image can be generated which can be quickly introduced into the data carrier, which significantly reduces the production time: once by requiring only one production step for introducing the initialization data and the individualization data, and furthermore by that now also the individualization data can be introduced faster with the aid of physical memory addresses in the disk.
- the step of the initialization which has hitherto been carried out separately and first according to the prior art, is also performed virtually as described.
- the personalization data generated by the virtual personalization generally also contain the identical initialisation.
- insurance data This can also be application data, in particular Java packages and Java applets.
- the virtual personalization can be performed on a standard commercial personal computer. Special personalization devices are not necessary.
- the virtual personalization can take place, for example, by means of a JavaCard simulator or a comparable simulation software.
- the personalization data generated by the virtual personalization can be encrypted on the virtual volume. This guarantees a secure introduction of the data in the form of the memory image into the real data carrier. After introducing the personalization data into the real data carrier, they can be decrypted again on the real data carrier.
- the introduction of the personalization data generated by the virtual personalization into the real disk does not necessarily have to be done directly during the production of the disk. It is possible to introduce the data into the data carrier only at the point issuing the data carrier and thus to personalize it, that is, for example, at a bank, a supermarket or the like. It is also conceivable to introduce the data at the end customer, for example via the Internet. In this way, the production time of the disk can be further reduced.
- the data medium can be preinitialized to the extent that it contains enough data to be able to communicate with a personalization server of a personaliser. re connection, for example, via the Internet, to be there to authenticate and thereby initiate a secure transfer of the data to be introduced in the form of the previously created by the virtual personalization memory image, without the need for further action of the issuing entity or the end customer.
- the personalization data are introduced into memory areas of the data carrier which are not affected by the pre-initialization and therefore have no structure up to now, in particular have no file system or the like.
- the data introduced at the point issuing the data carrier or at the end customer is only a part of the personalization data, the other part already being introduced into the data carrier during the production of the data carrier, preferably directly as Image of a virtual memory.
- a part of the personalization data introduced into the data carrier is intended for data introduced into the ROM memory of the data carrier during the production of the data carrier, which after delivery of the data carrier to the user into the non-volatile EEPROM or Flash Memory are to be written, since, for example, between the production of the ROM mask and the delivery of the disk even smaller changes have been made in the corresponding data.
- the portable data carrier may in particular be a chip card or a mobile communication card.
- FIG. 1 shows a schematic sequence of a virtual personalization process
- FIG. 2 schematically shows the generation of a memory image of a personalized virtual data carrier and its introduction into a nonvolatile memory of a real data carrier.
- FIG. 1 schematically shows a sequence of a virtual personalization process 1000 according to the invention.
- the entire process 1000 may take place on a standard personal computer (PC).
- a simulation program 70 preferably JavaCard simulator or a comparable software or software / hardware combination, can completely simulate a personal data medium to be personalized, including all hardware features.
- the simulation program 70 is set up to communicate with virtual readers 50 via a virtual PC / SC interface 60, which in turn can communicate with a personalization software 20, as has hitherto been used in the personalization of real data carriers.
- a plurality of virtual data carriers 500, 501, 502 can be personalized in parallel on a PC, depending on the requirements and performance of the PC 20 to 100 pieces.
- the virtual data carriers are equipped with personalization data 100, 101, 102, each composed of identical initialization data 90 and data carrier-specific individualization data 110, 111, 112.
- FIG. 2 schematically shows the generation of a bit-precise memory image 250 of the simulated nonvolatile memory 150 of a virtual data carrier 500.
- the memory image 250 further information, such as the structure of the file system.
- the memory image 250 has for each memory content the exact physical address in the corresponding memory, whereby also in the case of the virtual data carrier one speaks of physical addresses which exist there in a simulated way.
- the memory image 250 generated by means of the virtual data carrier 500 can now be introduced directly into a nonvolatile memory 350 of a physical data carrier 700 which has been simulated by the virtual data carrier 500.
- Corresponding data, such as personalization data 100 are at exactly the same memory addresses as in the virtual data carrier 500. This is illustrated by means of the memory addresses 0, X and Y.
- the introduction of a memory image 250 with the aid of the physical addresses can be performed much faster than the introduction of the corresponding data by means of logical commands, since it can be used directly on hardware functions.
- the data medium 700 to be personalized does not have to be pre-initialized in any way, ie in particular does not yet contain a file system.
- pre-initialization does not disturb the process if the pre-initialization concerns only those memory areas which are different from those in which the memory image for personalization is introduced.
- the personalization data 100, 101, 102 incorporated into the real data carrier 700 by means of the memory image 250 contain individualization data 110, 111, 112 and initialization data 90.
- the latter may in particular comprise application data, such as Java packages and Java applets.
- the personalization data 100, 101, 102 is encoded in the real volume 700 is introduced and decrypted on this again.
- the insertion of the memory image 250 into a real data carrier 700 is not during the production of the data carrier 700, but only later, for example at a place issuing the data carrier 700, such as a bank or a supermarket, or at the end customer himself, takes place. The latter case will be described in more detail below.
- the real data carrier 700 In the production of the real data carrier 700, only a small part of the personalization data 100, 101, 102 to be introduced is introduced into the nonvolatile memory 350 of the data carrier 700, namely essentially only initialization data 90, and only just so much that the data carrier subsequently, for example via the Internet can establish a secure connection with the site from which the further personalization proceeds.
- the data carrier ewa is a mobile communication card
- only boot loaders, basic GSM functions and the necessary ones are expedient Keys and algorithms for encryption and authentication in the data carrier 700, preferably by memory image introduced.
- the volume 700 is output to the end customer. The following further steps are carried out to completely personalize the data carrier 700 below.
- the end customer connects the data carrier 700 with a PC by means of suitable hardware.
- the end user establishes a connection via the Internet with the person- nel personalizing the data carrier 700, in the case of a mobile radio card, for example via the mobile radio provider, directly to the data center of the corresponding personalizing body.
- An application for example a Java Applet running in an Internet browser, establishes a connection between the data carrier 700 and the point personalizing the data carrier 700. Interaction of the end customer is not required.
- the volume 700 authenticates to this location and transmits data such as e.g. Version number, card type, and the like; and such data as is suitable for negotiating a session key for subsequent data transfer between the volume 700 and the personalizing entity, for example, a public key.
- data such as e.g. Version number, card type, and the like; and such data as is suitable for negotiating a session key for subsequent data transfer between the volume 700 and the personalizing entity, for example, a public key.
- the personalizing entity identifies the volume 700 based on the obtained individual data of the volume 700 and identifies the storage image to be provided for that volume 700. 6. At the personalizing point, enter as described above
- Memory image 250 of the personalization data 100 which are not yet present on the volume to be personalized 700 created; the memory image 250 may already be ready. 7.
- the memory image 250 is encrypted on a data carrier-specific basis and di- Signed in gold.
- the application transfers the memory image 250 via the existing Internet connection to the data carrier 700, where it is introduced directly into a non-volatile memory 350 at the corresponding addresses.
- the proportion of personalization data that is introduced into the data carrier only after production at a point issuing the data carrier or at the end customer can be varied depending on the type of data carrier 700 to be personalized.
- the data carrier is, for example, a mobile communication card, then this can be pre-personalized to the extent that the end customer can at least telephone and send and receive SMS. Further functionalities can then be introduced into the data carrier 700 in a manner initiated by the end customer in a manner described above.
- a data carrier 700 with ROM and EEPROM during production still free memory in the ROM can be described with so-called standard data.
- These are data which are to be subsequently stored in the EEPROM in at least a similar manner when using the data carrier 700, but possibly still have to undergo some changes that take place between the production of the ROM mask and the output of the data carrier 700.
- the information In the production of the data carrier 700, only the part of the personalization data 100 is then introduced into the data carrier 700, the information contain information about how to update the standard data written by the ROM in the EEPROM and subsequently initiated by the end user.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Computer Networks & Wireless Communication (AREA)
- Accounting & Taxation (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Theoretical Computer Science (AREA)
- Storage Device Security (AREA)
- Techniques For Improving Reliability Of Storages (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102006034375A DE102006034375A1 (de) | 2006-07-25 | 2006-07-25 | Personalisierung von tragbaren Datenträgern |
| PCT/EP2007/006575 WO2008012069A2 (de) | 2006-07-25 | 2007-07-24 | Personalisierung von tragbaren datenträgern |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2050080A2 true EP2050080A2 (de) | 2009-04-22 |
Family
ID=38859252
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP07786301A Ceased EP2050080A2 (de) | 2006-07-25 | 2007-07-24 | Personalisierung von tragbaren datenträgern |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US8433928B2 (de) |
| EP (1) | EP2050080A2 (de) |
| DE (1) | DE102006034375A1 (de) |
| WO (1) | WO2008012069A2 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8453232B1 (en) * | 2010-09-30 | 2013-05-28 | Emc Corporation | Virtual smart card through a PC/SC interface |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE19536548A1 (de) * | 1995-09-29 | 1997-04-03 | Ibm | Vorrichtung und Verfahren zur vereinfachten Erzeugung von Werkzeugen zur Initialisierung und Personalisierung von und zur Kommunikation mit einer Chipkarte |
| US6202155B1 (en) * | 1996-11-22 | 2001-03-13 | Ubiq Incorporated | Virtual card personalization system |
| DE19858343A1 (de) * | 1998-12-17 | 2000-06-21 | Giesecke & Devrient Gmbh | Verfahren und Vorrichtung zum Herstellen von personalisierten Chipkarten |
| DE19939280A1 (de) * | 1999-08-19 | 2001-02-22 | Ibm | Sicheres Personalisieren von Chipkarten |
| GB0001230D0 (en) * | 2000-01-19 | 2000-03-08 | Softcard Solutions Ltd | Smart card application builder system |
| US6729549B2 (en) * | 2000-12-19 | 2004-05-04 | International Business Machines Corporation | System and method for personalization of smart cards |
| US7850066B2 (en) * | 2001-12-07 | 2010-12-14 | Ecebs Limited | Smartcard system |
| DE10320062A1 (de) * | 2003-05-06 | 2004-12-16 | Giesecke & Devrient Gmbh | Speicherverwaltung bei einem tragbaren Datenträger |
| US7364087B2 (en) * | 2004-06-24 | 2008-04-29 | Intel Corporation | Virtual firmware smart card |
| EP1622098A1 (de) * | 2004-07-30 | 2006-02-01 | ST Incard S.r.l. | Verfahren zur gesicherten Personalisierung einer IC-Karte |
| US20070265855A1 (en) * | 2006-05-09 | 2007-11-15 | Nokia Corporation | mCARD USED FOR SHARING MEDIA-RELATED INFORMATION |
-
2006
- 2006-07-25 DE DE102006034375A patent/DE102006034375A1/de not_active Withdrawn
-
2007
- 2007-07-24 WO PCT/EP2007/006575 patent/WO2008012069A2/de not_active Ceased
- 2007-07-24 US US12/374,915 patent/US8433928B2/en not_active Expired - Fee Related
- 2007-07-24 EP EP07786301A patent/EP2050080A2/de not_active Ceased
Non-Patent Citations (1)
| Title |
|---|
| None * |
Also Published As
| Publication number | Publication date |
|---|---|
| US8433928B2 (en) | 2013-04-30 |
| US20090327587A1 (en) | 2009-12-31 |
| WO2008012069A2 (de) | 2008-01-31 |
| WO2008012069A3 (de) | 2008-05-22 |
| DE102006034375A1 (de) | 2008-01-31 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE69720181T2 (de) | System und verfahren zum laden von mehrfachen anwendungen in eine chipkarte | |
| DE69127641T2 (de) | Vorrichtung und Verfahren zum Verwalten von Chipkartentransaktionen | |
| DE19839847A1 (de) | Speichern von Datenobjekten im Speicher einer Chipkarte | |
| DE102008027043B4 (de) | Verfahren zum Personalisieren eines Sicherheitselements eines mobilen Endgeräts | |
| EP1192607B1 (de) | Mobiltelefon | |
| DE69911174T2 (de) | System und verfahren zur kontrolle des zugangs zu dem computercode in einer chipkarte | |
| EP2673731B1 (de) | Verfahren zur programmierung eines mobilendgeräte-chips | |
| DE60013518T2 (de) | Versicherte Personalisierung von Chipkarten | |
| EP1883906B1 (de) | Tragbarer datenträger mit sicherer datenverarbeitung | |
| WO2008012069A2 (de) | Personalisierung von tragbaren datenträgern | |
| DE19932149A1 (de) | System zur Ausführung von Transaktionen | |
| EP1634252B1 (de) | Verfahren zum laden von tragbaren datenträgern mit daten | |
| DE19716015A1 (de) | Einbringen von Information auf einer Chipkarte | |
| DE102009018222A1 (de) | Schreibzugriff auf einen portablen Datenträger | |
| EP4040324A1 (de) | Chip-initialisierung mit betriebssystemladen | |
| EP2210210B1 (de) | Verfahren zum laden von initialisierungs- und/oder personalisierungsdaten auf einen tragbaren datenträger | |
| EP0847031B1 (de) | Verfahren zum gesicherten nachträglichen Programmieren einer Mikroprozessorkarte für eine zusätzliche Anwendung | |
| DE102013006621A1 (de) | Verfahren zum Bereitstellen einer Applikation auf einem Sicherheitsmodul sowie ein solches Sicherheitsmodul | |
| DE60316183T2 (de) | Verfahren und vorrichtung zur abwechselnden aktivierung einer austauschbaren hardwareeinheit | |
| WO2002039236A2 (de) | Verfahren und anordnung für ein rechte-ticket-system zur erhöhung der sicherheit bei der zugangskontrolle zu rechnerrecourcen | |
| DE102017005057A1 (de) | Personalisieren eines Halbleiterelements | |
| DE10328238B4 (de) | Verfahren zum Laden von Chipkarten mit Initialisierungs- und/oder Personalisierungsdaten | |
| DE102006021382A1 (de) | Personalisierung von portablen Datenträgern | |
| DE69832785T2 (de) | Verfahren zum beglaubugen einer gesamtsumme in einem leser | |
| EP2486489A1 (de) | Portabler datenträger mit zusatzfunktionalität |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20090225 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA HR MK RS |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: EBNER, CLAUS Inventor name: RANKL, WOLFGANG Inventor name: KITZMANN, ANDREAS Inventor name: GREBE, ALEXANDER |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20100930 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20170228 |