EP2427847A1 - Verfahren zum schutz von auf einem tragbaren datenträger gespeicherter software und tragbarer datenträger - Google Patents
Verfahren zum schutz von auf einem tragbaren datenträger gespeicherter software und tragbarer datenträgerInfo
- Publication number
- EP2427847A1 EP2427847A1 EP10721140A EP10721140A EP2427847A1 EP 2427847 A1 EP2427847 A1 EP 2427847A1 EP 10721140 A EP10721140 A EP 10721140A EP 10721140 A EP10721140 A EP 10721140A EP 2427847 A1 EP2427847 A1 EP 2427847A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- software
- program
- portable data
- data carrier
- modified
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/10—Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
- G06F21/12—Protecting executable software
- G06F21/14—Protecting executable software against software analysis or reverse engineering, e.g. by obfuscation
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/10—Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
- G06F21/12—Protecting executable software
- G06F21/121—Restricting unauthorised execution of programs
- G06F21/125—Restricting unauthorised execution of programs by manipulating the program code, e.g. source code, compiled code, interpreted code, machine code
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/77—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in smart cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F8/00—Arrangements for software engineering
- G06F8/70—Software maintenance or management
- G06F8/71—Version control; Configuration management
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/451—Execution arrangements for user interfaces
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/16—Obfuscation or hiding, e.g. involving white box
Definitions
- Code Obfuscation (Code Obfuscation) technology converts readable program code into a more difficult-to-understand version, which makes the analysis of program code by an attacker more complex. This complicates the development of so-called Trojans, which hog into programs and unwanted functions, e.g. spying on secret data. With the help of these obfuscation techniques, the analysis of program code is more difficult, but not impossible. Moreover, obfuscation techniques do not alter the executable software generated from the program code so that a Trojan developed based on the obscured program code poses a threat to all computers on which the software is used.
- the document EP 1 722 336 A2 describes a method for generating initialization data for security data carriers, in which a USB token generates the initialization data with the aid of secret data stored on the token and transmits it to a personal computer.
- the object of the invention is to further improve the protection of software stored on a portable data carrier in comparison to the method known from the prior art.
- the inventive method protects software stored on a portable data carrier.
- the data carrier can be configured as desired, in particular, it can be a smart card, such as a smart card, a token, in particular a USB token, and any other type of portable data carrier.
- the software to be protected is designed in such a way that when the software is called by a Terminal, to which the software is copied or which is contact-bound when contacted with the portable data carrier and possibly also contactless, a program is executed, which generates a user interface on the terminal for entering and optionally outputting data. The user interface is thereby generated on a corresponding output unit, in particular a display, of the terminal with the aid of the software.
- the terminal can also be configured as desired, in particular it may be a personal computer, a mobile phone, a PDA and the like act.
- the creation of the modified software occurs repeatedly at intervals, in particular at predetermined time intervals (eg: hourly, daily, weekly, ...) and / or in response to a predetermined event ((each) call the software, each x- calling the soft- ware, restarting the data carrier, ).
- predetermined time intervals eg: hourly, daily, weekly, .
- the generated modified software can be based both on a previously created modified software and on the original, unmodified software.
- the software is preferably stored in a public storage area of the portable data medium on which devices connected to the data carrier have access.
- the software is modified by a modification program whose software is stored in a secure storage area of the portable data carrier on which devices connected to the data carrier have no access, is stored. In this way one becomes particularly high protection of the software, since the corresponding program for modifying the software can not be easily read and analyzed. This protection can be improved even further by modifying the modification program by a processor of the portable data carrier secured against external accesses.
- a user interface of the user interface of the terminal generated by the software is modified such that the input sequence of data and / or the positioning of one or more input fields is changed.
- this provides protection against Trojans which spy on and / or manipulate a graphical user interface or inputs of the user on the surface, in particular keystrokes, mouse clicks and movements, and possibly time sequences.
- a modified program is executed when the modified software is called, in which one or more internal parameters of the program are changed in comparison with the program executed when the unmodified software is called, while retaining the functionality of the program.
- the internal parameters may in particular relate to internal data structures, such as the storage of data in a memory used by the program, and / or one or more keys for data encryption and / or one or more codes for data encoding and / or the internal timing of the program.
- the program can consist of different parts, with each part being parameterized, in order thereby to allow variable data structures which can be changed by the modification of the software.
- variable data structures can For example, the sequence of the fields of a "typedef" can be varied, for example, the data can also be scattered randomly in the memory used by the program
- the stack layout can also be changed by software modification, which can be done by rearranging / reorganizing the bytecode in bytecode programs.
- the portable data carrier can simply construct the necessary algorithms in the software code, for example in the form of coding or decoding tables and / or parameterizable algorithms or else with the aid of hard-coded algorithms in which the parameters generated during software compilation.
- the protection of the software is further improved because a malicious software for real-time attack is forced to take place during the execution of the program communication between the terminal and the disk.
- the program executed when the software is called in a further embodiment of the invention queries a user identifier and / or a secret code (for example a PIN) via the user interface. Only if the user ID or permissible secret code is permitted will further program execution continue.
- a secret code for example a PIN
- the software is invalidated after a predetermined period of time after its modification. This ensures that software does not remain disproportionately long.
- the software stored on the data carrier for executing a transaction program is used to enter transaction data, in particular banking transaction data.
- the transaction data are entered via the user interface of the program, wherein the entered transaction data are transmitted by the program from the terminal to the portable data carrier.
- the transmitted transaction data is then sent to a server via the transactional program being executed or in a separate transfer step via a secure end-to-end connection between the portable data carrier and the server.
- the data transmission to the server can thus be part of the executed program or be carried out in a separate transmission step.
- the terminal In the secured end-to-end connection, the terminal only takes on a forwarding function and can not manipulate the transmitted data.
- the secure connection is a secure Internet connection.
- the invention further relates to a portable data carrier, in particular a token, for example a USB token, or a chip card, for example a smartcard.
- Software is stored on the data carrier, a program being executed by the terminal when the software is called up, which program generates a user interface on the terminal for inputting data.
- the portable data carrier is designed in such a way that the software is modified in time intervals by the portable data carrier in such a way that a modified program is executed when the modified software is called the user interface on the terminal is changed in comparison to the program executed when the unmodified software is called, while retaining the functionality of the program.
- FIG. 1 shows the sequence of a transaction program for executing a banking transaction, wherein the software of this program is changed based on an embodiment of the method according to the invention.
- a transaction program is carried out which is based on software which is stored in a portable data carrier in the form of a USB token 1.
- the software is stored on the token in a public storage area, which is visible to the user when the token is connected to a corresponding terminal via a file management program.
- the USB token 1 contains a secret memory area which can not be viewed when the token is connected to a terminal.
- This secret storage area contains hidden software in the form of a modification program, which can change the software of the transaction program in the public storage area, as will be explained in more detail below.
- the token 1 includes a processor secured against external access and a corresponding RAM memory with a few kilobytes of storage capacity. The hidden software is executed by the processor.
- the modified software in the form of the new exe file contains a transaction program with the same functionality as the program measured in the old exe file
- a corresponding user ID and a PIN Personal Identification Number
- PIN Personal Identification Number
- the user ID and PIN are entered by the user via an appropriate user interface, which is generated by starting the exe file on the screen of the PC 2.
- the identifier and the PIN are transmitted to the token and compared there with a corresponding identifier and PIN stored in the token. If the identifier and PIN on the token agree with the entered identifier and the entered PIN, the user has successfully authenticated to the token, and in step S8 an authentication confirmation is returned to the PC 2.
- step S9 the user then inputs corresponding transaction data for executing a banking transaction, for example, a bank account and a cash amount for making a transfer.
- the user interface used for input and generated by the transaction program changes after each modification of the exe file.
- an effective protection against malware in the form of Trojans is achieved, which spy on and / or manipulate the user interface and corresponding keystrokes of the user in input fields of the user interface.
- step S10 the entered transaction data is transmitted to the token 1.
- step Sil a secure connection is established between token 1 and a server 3, this server being a bank server for processing corresponding transaction data.
- the establishment of the secure connection takes place via the Internet, for which purpose the PC 2 has a corresponding Internet connection.
- the connection is an encrypted end-to-end connection between token 1 and server 3 via respective protocols, the PC 2 acting as a forwarding node in this connection and being unable to manipulate the transmitted data.
- step S5 After establishing the secure connection in step S5, finally, the transaction data stored on the token is transmitted to the bank server 3 in step S12, which finally executes the transaction for performing the banking in step S13. Subsequently, the execution of the transaction is confirmed by the bank server 3 to the token 1 in step S14, and the confirmed execution of the transaction is reproduced on the user's PC in step S15.
- a communication interface with corresponding session keys for data encryption is provided. used. These keys are changed after each modification of the exe file underlying the program.
- the layout of the data stored by the program or the temporal program sequence can also be changed after each modification. This achieves efficient protection against such Trojans, which plug into the executed program in order to manipulate the data entered or to be output internally, ie directly in the executed exe file.
- by modifying the exe file it can be achieved, for example, that the program logs on to the operating system of the PC after each modification under a different name.
- the partner involved in the transaction which in the example of FIG. 1 is the bank that operates the bank server, neither has to create the issued exe files themselves nor regularly update them or send them to the authorized users. Rather, the issuance of a corresponding token by the bank to authorized users, possibly including customary personalization, possibly with additional keys, ensures that the user has access to the transaction program.
- the transaction program may be made transparent to the user, for example, a startup software installed on the PC may be provided to invoke an exe file to execute the transaction on the USB token.
- a fake exe file is not possible, because the exe file can be designed so that the token only accepts data from this exe file. This can be achieved, for example, by encoded keys, a predefined time behavior of the program expected by the token as well as a predefined format expected by the token data transfer between token and exe file are guaranteed.
- the server uses only key and certificate-secured connections to exchange data between the token and the server.
- the token may also be used on untrusted PCs to perform transactions, as the execution of the transaction is not tied to a particular PC due to the token's provision of the exe file.
- the method can also be used on other terminals than PCs; in particular, the method can also be carried out in a mobile telephone, a PDA and the like.
- a SIM card can be used as a token, which communicates with the mobile phone as a terminal.
Landscapes
- Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Multimedia (AREA)
- Technology Law (AREA)
- Human Computer Interaction (AREA)
- Mathematical Physics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102009019981A DE102009019981A1 (de) | 2009-05-05 | 2009-05-05 | Verfahren zum Schutz von auf einem tragbaren Datenträger gespeicherter Software und tragbarer Datenträger |
| PCT/EP2010/056059 WO2010128060A1 (de) | 2009-05-05 | 2010-05-05 | Verfahren zum schutz von auf einem tragbaren datenträger gespeicherter software und tragbarer datenträger |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2427847A1 true EP2427847A1 (de) | 2012-03-14 |
Family
ID=42646403
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP10721140A Ceased EP2427847A1 (de) | 2009-05-05 | 2010-05-05 | Verfahren zum schutz von auf einem tragbaren datenträger gespeicherter software und tragbarer datenträger |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP2427847A1 (de) |
| DE (1) | DE102009019981A1 (de) |
| WO (1) | WO2010128060A1 (de) |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH08305558A (ja) * | 1995-04-27 | 1996-11-22 | Casio Comput Co Ltd | 暗号化プログラム演算装置 |
| US5969632A (en) * | 1996-11-22 | 1999-10-19 | Diamant; Erez | Information security method and apparatus |
| AU2001269354A1 (en) * | 2000-05-12 | 2001-11-20 | Xtreamlok Pty. Ltd. | Information security method and system |
| CA2327911A1 (en) * | 2000-12-08 | 2002-06-08 | Cloakware Corporation | Obscuring functions in computer software |
| US7373522B2 (en) * | 2003-05-09 | 2008-05-13 | Stmicroelectronics, Inc. | Smart card with enhanced security features and related system, integrated circuit, and methods |
| DE102004011488B4 (de) | 2004-03-09 | 2007-07-05 | Giesecke & Devrient Gmbh | Schutz von Software gegen Angriffe |
| DE102004030263A1 (de) * | 2004-06-23 | 2006-01-19 | Schwenk, Jörg, Prof. Dr. | Schutz von Webbrowsern gegen Visual Spoofing/Phishing |
| DE102005020313A1 (de) | 2005-05-02 | 2006-11-16 | Giesecke & Devrient Gmbh | Vorrichtung und Verfahren zur Erzeugung von Daten für eine Initialisierung von Sicherheitsdatenträgern |
| WO2008034900A1 (en) | 2006-09-21 | 2008-03-27 | Boesgaard Soerensen Hans Marti | Fabrication of computer executable program files from source code |
-
2009
- 2009-05-05 DE DE102009019981A patent/DE102009019981A1/de not_active Withdrawn
-
2010
- 2010-05-05 WO PCT/EP2010/056059 patent/WO2010128060A1/de not_active Ceased
- 2010-05-05 EP EP10721140A patent/EP2427847A1/de not_active Ceased
Non-Patent Citations (2)
| Title |
|---|
| None * |
| See also references of WO2010128060A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2010128060A1 (de) | 2010-11-11 |
| DE102009019981A1 (de) | 2010-11-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2899714B1 (de) | Gesichertes Bereitstellen eines Schlüssels | |
| DE69624501T2 (de) | Personenbezogenes zugangsverwaltungssystem | |
| EP2417550B1 (de) | Verfahren zur durchführung einer applikation mit hilfe eines tragbaren datenträgers | |
| DE102009013384B4 (de) | System und Verfahren zur Bereitstellung einer sicheren Anwendungsfragmentierungsumgebung | |
| EP2137664A2 (de) | Verfahren zur erzeugung bestätigter transaktionsdaten und vorrichtung dazu | |
| WO2012130461A2 (de) | Aktualisierung einer datenträgerapplikation | |
| EP3748521B1 (de) | Verfahren zum lesen von attributen aus einem id-token | |
| WO2008046575A1 (de) | Verfahren zum ausführen einer applikation mit hilfe eines tragbaren datenträgers | |
| DE60221861T2 (de) | Server mit dateiverifikation | |
| EP2434424B1 (de) | Verfahren zur Erhöhung der Sicherheit von sicherheitsrelevanten Online-Diensten | |
| EP2885907B1 (de) | Verfahren zur installation von sicherheitsrelevanten anwendungen in einem sicherheitselement eines endgerät | |
| EP2427847A1 (de) | Verfahren zum schutz von auf einem tragbaren datenträger gespeicherter software und tragbarer datenträger | |
| EP3329415B1 (de) | Chipkarte mit hauptapplikation und persistenzapplikation erlaubt hauptapplikationupdate ohne die benutzerdaten im persistenzapplikation zu ändern | |
| DE102012224083A1 (de) | Verfahren zur Personalisierung eines Secure Elements (SE) und Computersystem | |
| EP1365363B1 (de) | Verfahren zur Ausführung einer Datentransaktion mittels einer aus einer Haupt- und einer trennbaren Hilfskomponente bestehenden Transaktionsvorrichtung | |
| CH712679B1 (de) | Verfahren zur Maskierung und eindeutigen Signierung von Datenbank-Quellcodes. | |
| DE202007002971U1 (de) | Vorrichtung zur Erstellung digitaler Signaturen | |
| EP1722336A2 (de) | Vorrichtung und Verfahren zur Erzeugung von Daten für eine Initialisierung von Sicherheitsdatenträgern | |
| DE102006006489A1 (de) | Verfahren zur Durchführung eines Schreibzugriffs, Computerprogrammprodukt, Computersystem und Chipkarte | |
| DE102005046696A1 (de) | Verfahren zum Erzeugen von geschütztem Programmcode und Verfahren zum Ausführen von Programmcode eines geschützten Computerprogramms sowie Computerprogrammprodukt | |
| DE10006062A1 (de) | Tastaturschlüssel | |
| EP1839136A1 (de) | Erzeugen von programmcode in einem ladeformat und bereitstellen von ausf]hrbarem programmcode | |
| AT503263A2 (de) | Vorrichtung zur erstellung digitaler signaturen | |
| EP1720096B1 (de) | Verfahren zum Hinzufügen einer Funktionalität zu einem ausführbaren ersten Modul eines Programmpakets | |
| AT524619A1 (de) | Computerimplementiertes Verfahren zum autorisierten Ausführen einer Software, System zur Datenverarbeitung, Computerprogrammprodukt und computerlesbares Speichermedium |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20111205 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO SE SI SK SM TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: BELAU, MARKUS |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20160302 |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: GIESECKE+DEVRIENT MOBILE SECURITY GMBH |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| 18R | Application refused |
Effective date: 20180427 |