EP3140951A1 - Entité électronique et procédé de génération de clé de session - Google Patents
Entité électronique et procédé de génération de clé de sessionInfo
- Publication number
- EP3140951A1 EP3140951A1 EP15724344.5A EP15724344A EP3140951A1 EP 3140951 A1 EP3140951 A1 EP 3140951A1 EP 15724344 A EP15724344 A EP 15724344A EP 3140951 A1 EP3140951 A1 EP 3140951A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- electronic entity
- prm
- counter
- verification word
- sqc
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
- H04L9/3273—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response for mutual authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0838—Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0869—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
Definitions
- the present invention relates to the exchange of data between electronic entities.
- It relates more particularly to an electronic entity and a method of generating a session key.
- the invention applies particularly advantageously in the case where a session key is generated by the electronic entities on the basis of a pseudo-random value, such as the value of a counter of one of the electronic entities.
- session keys to secure the exchange of data between two electronic entities.
- These session keys are for example derived from a cryptographic key known only from the two electronic entities. So that these keys are different for each exchange session between the two electronic entities, it is expected that they are further calculated on the basis of random values generated by the electronic entities.
- random values can also be used, during a mutual authentication process, as a challenge (or "challenge” according to the Anglo-Saxon name) transmitted from one electronic entity to the other electronic entity so that the latter proves its knowledge of a shared secret (generally a cryptographic key, for example one of the session keys) by returning in response the result of a calculation combining the shared secret and the random value received.
- a challenge or "challenge” according to the Anglo-Saxon name
- a shared secret generally a cryptographic key, for example one of the session keys
- slave it has been planned to use, in place of the value random generated by this electronic entity, a so-called “pseudo-random" value, based for example on the value of a counter of this electronic entity.
- the other electronic entity (hereinafter referred to as the "master” or “host”), which is also aware of the value of the counter, can thus prepare in advance the data to be sent (typically in the form of commands to the user). slave electronic entity), by encrypting this data by means of the session key obtained in particular according to the value of the counter, and transmitting them in batches.
- This technique is used for example for the personalization of secure electronic entities (such as microcircuit cards or secure integrated circuits) but can also be used in other contexts.
- secure electronic entities such as microcircuit cards or secure integrated circuits
- the counter of the slave electronic entity is incremented as soon as the opening of a new session is requested by the master electronic entity and when a mutual authentication procedure must be initiated (INITIALIZE UPDATE command).
- the logon request is earlier than the mutual authentication procedure, it can not be guaranteed that it does not come from a malicious third party. In such a case, even if the attempt of the malicious third party is doomed to failure since it will not be able to authenticate itself, the request of logon leads to the incrementation of the counter (necessary to the implementation of the process mutual authentication), unexpected increment for the master electronic entity.
- the present invention proposes an electronic entity designed to exchange data with another electronic entity, characterized in that it comprises means for receiving a first verification word from the other electronic entity, means for determining a second verification word, means for incrementing a counter of the electronic entity only in case of equality between the first verification word and the second verification word and means for generating a session key according to the value of the counter .
- the counter is incremented only when the electronic entity has been able to verify the value of the verification word received from the other electronic entity, which makes it possible to ensure that the latter is the expected partner of the entity. and not a malicious third party.
- the second verification word is determined as a function of a counter value of the electronic entity. This ensures that the other electronic entity is aware of this counter value and can successfully complete the next steps of the mutual authentication process.
- the electronic entity comprises a rewritable non-volatile memory designed to store the second verification word.
- the electronic entity may comprise means for comparing the first verification word and the second verification word stored in the rewritable non-volatile memory; the means for incrementing the counter are then for example designed to increment the counter in case of a positive comparison by the comparison means. Since the second verification word is read in the rewritable non-volatile memory (where it has for example been stored in a previous session as indicated below), it avoids the implementation of the determination of the second word of verification at the time of comparison with the first verification word received.
- the means for generating the session key are designed to generate the session key according to the first word verification, as explained in the following description.
- the means for generating the session key may be designed to generate the session key, during a session, before incrementing the counter by the means for incrementing the counter, as is the case for example for the channel protocol secure SCP02.
- the means for generating the session key may be designed to generate the session key, during a session, after incrementing the counter by the means for incrementing the counter, as is the case for example for the secure channel protocol SCP03.
- the invention also proposes a method for generating a session key for a secure exchange of data between a first electronic entity and a second electronic entity, characterized by the following steps:
- the first verification word such as the second verification word
- the first verification word can be determined according to a counter value of the electronic entity.
- the method may in fact comprise, during a previous session, a step of determining the second verification word and a step of storing the second verification word determined in the rewritable non-volatile memory.
- the method comprises for example the following steps:
- FIG. 1 represents the main steps of a first example of data exchange between a first electronic entity and a second electronic entity in accordance with the teachings of the invention
- FIG. 2 represents the main steps of a second example of data exchange between a first electronic entity and a second electronic entity in accordance with the teachings of the invention
- FIG. 3 presents a first example of a method for determining a pseudo-random word
- FIG. 4 presents a second example of a method for determining a pseudo-random word.
- FIG. 1 represents a first example of data exchange between a first electronic entity and a second electronic entity in accordance with the teachings of the invention.
- Each of the first and second electronic entities comprises a communication interface by means of which the relevant electronic entity can transmit and / or receive data on a communication medium, where the data is represented by signals, for example electrical signals or optics.
- the first electronic entity and the second electronic entity can thus exchange data either directly (their respective communication interfaces being connected to one another) or via one or more other electronic entities (for example computers), possibly connected to each other and to the first and second electronic entities by means of a computer network.
- Each of the first and second electronic entities is for example an electronic device which comprises, in addition to the communication interface mentioned above, a processor and at least one memory capable of storing the data received and manipulated by the electronic entity.
- This memory also stores computer program instructions which, when executed, enable the electronic entity to implement the methods described below.
- at least one of the electronic entities could be implemented in the form of a specific application integrated circuit (or ASIC according to the English acronym).
- the first electronic entity is a terminal H and the second electronic entity is a microcircuit card C (or ICC for "Integrated Circuit Card”).
- the first entity could be a remote server connected to the second electronic entity through a wireless connection, or a server directly connected to the second entity through a wired connection.
- the second electronic entity may be a secure integrated circuit (or SE for "Secure Element"), an eSE ("embedded secure element” for embedded security element) or an eUICC ("embedded Universal Integrated Circuit Card” for universal and embedded IC card).
- a secure element includes a processor of its own, different from the processor of the host electronic device in which it is embedded or embedded, and includes a non-volatile memory for storing computer programs executable by the processor.
- the secure element is, for example, in accordance with ISO / IEC 7816 standards, Common Criteria standards and / or GlobalPIatform Card Specification v 2.2.1.
- the terminal H During a step E2, the terminal H generates a host challenge HCH formed of a random word RAND (length M bytes), obtained by random draw within the terminal H, and a pseudo-random word PRM (length N bytes) determined in particular according to the current value of a counter managed by the microcircuit card C, as explained below.
- the value of the counter is known by the terminal H thanks to the preceding exchanges or, in the case of a first exchange, to the value zero or has a value predetermined shared by both entities. It may optionally be provided in addition that the terminal H can issue a command (for example of the GET DATA type) in order to obtain in response (from the microcircuit card C) the current value of the counter.
- the size of the 8-byte host challenge should not be considered as a limiting example.
- the terminal H then transmits (step E4) to the card C an initialization command of the mutual authentication process, for example a command of the type INITALIZE UPDATE, accompanied by the host challenge HCH.
- an initialization command of the mutual authentication process for example a command of the type INITALIZE UPDATE, accompanied by the host challenge HCH.
- this command can be transmitted directly from the terminal H to the microcircuit card C (the communication interfaces being for example respectively a card reader equipping the terminal H and the contacts of the microcircuit card C), or by intermediary of one or more other electronic entities.
- Card C receives the initialization command and the HCH host challenge at step E6.
- the card C can thus extract the pseudo-random word received PRM.
- the microcircuit card C During a step E8, the microcircuit card C generates on its side a pseudo-random word PRM * using the same process and the same data (in particular the current value of the counter managed by the microcircuit card C) that during the determination of the pseudo-random word carried out in step E2 by the terminal H.
- the microcircuit card compares in step E10 the received pseudo-random word PRM and the calculated pseudo-random word PRM * -
- step E14 In case of equality (which should be the case in normal operation since the two words are calculated with the same processes and from the same data), the operation continues in step E14 described below.
- the emitter of the initialization command does not have a correct knowledge of the data used for the generation of the pseudo-random word PRM and will therefore probably not be able to authenticate correctly.
- the mutual authentication process (step E12) is therefore terminated without having incremented the counter.
- the microcircuit card C may optionally in this case return to the terminal H an error value or failure of the initialization of the mutual authentication process.
- step E10 if the initialization command comes from a malicious third party, as is generally the case when a difference is detected in step E10, the counter will not be incremented and the two electronic entities (terminal H and card C) will remain synchronized.
- step E10 When the verification of step E10 is positive (equality between the received pseudo-random word PRM and the calculated pseudo-random word PRM * ), the counter is incremented in step E14. A new counter value must be used to generate new session keys as explained below.
- Step E14 is followed by step E16 at which a pseudo-random value CCH is generated (for example by means of a key derivation process) as a function, in particular, of the current value of the counter (value after incrementation of the step E14), as well as possibly other data (eg a cryptographic key stored in the microcircuit card).
- the generation of the pseudo-random value CCH is for example carried out in accordance with the section "6.2.2.1 Card Challenge” in the document "GlobalPIatform Card Technology - Secure Channel Protocol 03 - Card Specification v 2.2 Amendment D" already mentioned. .
- the pseudo-random value CCH is used as a challenge of the card to the terminal H (see below the transmission step E30).
- each session key SK is generated, by means of a key derivation process, on the basis of a cryptographic key (called static key) K memorized in the microcircuit card C, of the host challenge HCH (received in step E6) and the pseudo-random value CCH (generated at step E16).
- static key a cryptographic key
- the generation of the session keys SK is performed in accordance with the "6.2.1 AES Session Keys" clause in the "GlobalPIatform Card Technology - Secure Channel Protocol 03 - Card Specification v 2.2 Amendment D" document already mentioned.
- the session keys are similarly generated by the terminal H. They are intended to be used as secret keys for symmetric encryption of the data to be exchanged during the session initiated by the mutual authentication process described here.
- the microcircuit card C determines in step E20 the authentication cryptogram of the card CAC, by means of a key derivation process, on the basis of one of the session keys SK, of the challenge of host HCH (received in step E6) and the pseudo-random value CCH (generated in step E16).
- the identification of the authentication cryptogram of the CAC card is, for example, carried out in accordance with the section "6.2.2.2 Card Authentication Cryptogram" in the "GlobalPIatform Card Technology - Secure Channel Protocol 03 - Card Specification v 2.2 Amendment D" document. "already mentioned.
- the microcircuit card C then emits in step E22 its response to the initialization command (see steps E4 and E6 above), which includes the pseudo-random value CCH determined in step E16 (challenge of the card), the CAC cryptogram determined in step E20 and the current value of the SQC counter.
- the terminal H receives this response in step E24, which completes the initialization phase of the mutual authentication process; the mutual authentication process can then continue, for example by sending an EXTERNAL AUTHENTICATE command.
- This authentication process includes the verification, by the terminal H, the CAC cryptogram received in step E22. To do this, the terminal H determines on its side the cryptogram of the card (by means of the same process and the same data as those used by the microcircuit card C in step E20) and compares the cryptogram thus determined to the cryptogram CAC received in step E22.
- FIG. 2 represents a second example of data exchange between a first electronic entity and a second electronic entity according to to the teachings of the invention.
- These electronic entities are for example of the same type as that envisaged above with reference to FIG.
- the at least one second electronic entity here a microcircuit card C
- the at least one second electronic entity is equipped with a random access memory and a non-volatile rewritable memory, in each of which the processor of the second electronic entity can read or write data.
- the steps of FIG. 2 correspond to the launch phase of a mutual authentication process between the two electronic entities, at the initiative of the terminal H, which here acts as the master electronic entity or host.
- the terminal H generates a host challenge HCH formed of a random word RAND, obtained by random draw within the terminal H, and a pseudo-random word PRM determined in particular according to the previous value (at the index i-1, that is to say immediately before the current value of index i) of a counter managed by the microcircuit card C, as explained below.
- This step may possibly be carried out at the beginning of the previous session of exchanges between the terminal H and the microcircuit card C; indeed, at the beginning of the previous session (before incrementing the counter during the previous session, to the index i-1), the counter managed by the microcircuit card C presented this previous value, immediately prior to the value that present the counter at the beginning of the current session (at index i).
- the terminal H transmits during a step E104 an initialization command of the mutual authentication process to the card C, for example a command of the type INITALIZE UPDATE, accompanied by the challenge of host HCH.
- the microcircuit card C receives the initialization command and the HCH host challenge at the step E106 and can therefore extract the received pseudo-random word PRM-
- step E106 is followed by the step E108, during which the processor of the microcircuit card C reads in the non-volatile memory of the microcircuit card C the pseudo-random word PRM * stored in this non-volatile memory. volatile during the previous session of exchanges between the terminal H and the microcircuit card C, as explained below for the current exchange session (see steps E1 14 and E1 16).
- the counter value is zero or has a predetermined value.
- the microcircuit card C (in practice its processor) then compares in step E1 10 the pseudo-random word PRM received in step E106 and the pseudo-random word PRM * read in the non-volatile memory in step E108.
- step E1 14 described more low.
- step E1 12 the mutual authentication process (step E1 12) is therefore terminated without having incremented the counter.
- the step of generating the pseudo-random word PRM * by the microcircuit card C is not performed when the equality of the step E1 10 is not verified, this which avoids processing that could slow down the operation of the microcircuit card C (especially when the initialization request of the authentication process is performed by an attacker).
- the microcircuit card C When the verification of the step E1 is positive (equality between the received pseudo-random word PRM and the pseudo-random word PRM * ), the microcircuit card C generates on its side in the step E1 14 a new word pseudo-random PRM * using the same process as the terminal H in step E102, but with the current value of the counter.
- the new pseudo-random word PRM * thus determined is then temporarily stored in RAM in step E1 16.
- the microcircuit card C then proceeds, during an atomic operation E1 18 (that is to say an operation which can only be totally realized or not performed as a whole, and which an attacker will not be able to force the partial realization), the incrementation of the counter and the writing of the new pseudo-random word PRM * in non-volatile memory (for example by copying it to from the RAM area where it was stored in step E1 16).
- An atomic operation E1 18 that is to say an operation which can only be totally realized or not performed as a whole, and which an attacker will not be able to force the partial realization
- the incrementation of the counter and the writing of the new pseudo-random word PRM * in non-volatile memory (for example by copying it to from the RAM area where it was stored in step E1 16).
- the article "An overview of the Arjuna distributed programming system" by SKshrivastava, GN Dixon, & GD Parrington published in IEEE Software, 8 (1), pages 66-73 (1991) describes a method for rendering
- the pseudo-random value PRM * stored in non-volatile memory can thus be used during the next initialization of a mutual authentication process (see steps E108 and E1 10 described above).
- the step E1 18 is followed by the step E120 to which is generated (for example by means of a key derivation process) a pseudo-random value CCH as a function in particular of the current value of the counter (value after incrementing the step E1 18), as well as possibly other data (eg a cryptographic key stored in the microcircuit card). It is furthermore provided that the pseudo-random value CCH is used as a challenge of the card to the terminal H.
- step E122 the microcircuit card generates different session keys SK.
- each session key SK is generated, by means of a key derivation process, on the basis of a cryptographic key (called static key) K memorized in the microcircuit card C, of the host challenge HCH (received in step E106) and the pseudo-random value CCH (generated in step E120).
- static key a cryptographic key (called static key) K memorized in the microcircuit card C, of the host challenge HCH (received in step E106) and the pseudo-random value CCH (generated in step E120).
- the microcircuit card C determines in step E124 the authentication cryptogram of the card CAC, by means of a process of key derivation, based on one of the SK session keys, the HCH host challenge (received in step E106) and the pseudo-random value CCH (generated in step E120).
- the generation of the pseudo-random value CCH, the generation of the session keys SK and the determination of the authentication cryptogram of the card CAC are for example carried out according to what is provided. in the document "GlobalPIatform Card Technology - Secure Channel Protocol 03 - Card Specification v 2.2 Amendment D" already mentioned.
- the microcircuit card C then emits at step E126 its response to the initialization command (see steps E104 and E106 above), which includes the pseudo-random value CCH determined in step E120 (challenge of the card), the CAC cryptogram determined in step E124 and the current value of the SQC counter.
- the terminal H receives this response in step E128, which completes the initialization phase of the mutual authentication process; the mutual authentication process can then continue, for example by sending an EXTERNAL AUTHENTICATE command.
- FIG. 3 presents a first example that can be envisaged for a method for determining a pseudo-random word as implemented above in steps E2, E8, E102 and E14.
- an authentication message calculation function is implemented by using as input the value of the counter SQC to be considered and a cryptographic key K, which makes it possible to obtain a piece of data (in instance an authentication code) MAC.
- the authentication message calculation function is for example a hash function for calculating authentication code with key (in English "keyed-hash message authentication code function" or simply "HASH-MAC function"), such as that complies with FIPS 198-1.
- it could be a symmetric cipher-based function, such as CBC-MAC or CMAC (as defined in NIST SP800-38B).
- CBC-MAC symmetric cipher-based function
- CMAC as defined in NIST SP800-38B
- a hash function of the SHA-256 or SHA-3 type is used.
- the cryptographic key K is a secret key stored in each of the two electronic entities (the terminal H and the microcircuit card C in the examples above) and which is therefore known only from these two electronic entities.
- the pseudo-random word PRM, PRM * is then obtained by extracting N bytes from the MAC data, for example the leftmost N bytes (that is to say the N most significant bytes).
- FIG. 4 presents a second example that can be envisaged for a method for determining a pseudo-random word as implemented above in steps E2, E8, E102 and E1 14.
- the pseudo-random word PRM (Î-1), PRM * (Î-1) determined during the previous session and the SQC value of the counter to be considered, for example by concatenation, are combined.
- the value of the counter SQC is null or has a predetermined value and the pseudo-random word of the preceding session is for example replaced by a specific initial value previously exchanged between the two electronic entities, for example a random value generated by the terminal H and transmitted securely to the microcircuit card C during its first initialization.
- the value of the pseudo-random word is, for example, a function of the serial number of the microcircuit card C which is received by the terminal H when the microcircuit C is first powered up. Note that this value, as well as all the subsequent counter values must remain secret to prevent an attacker from successfully completing the mutual authentication step.
- the combination is then applied with a one-way function, for example a hash function such as the SHA-256 function, in order to obtain a digest (or "digest" according to the English name). ). N bytes of the digest are then extracted (for example the N bytes of left) in order to obtain the pseudo-random word PRM (Î), PRM * ( ⁇ ) -
- a one-way function for example a hash function such as the SHA-256 function
- the terminal H stores the previous values of the pseudo-random word so that in case of loss of synchronization with the microcircuit card C, it may possibly reuse the previous values stored to calculate new pseudo-random words in a resynchronization phase.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR1454191A FR3020909B1 (fr) | 2014-05-09 | 2014-05-09 | Entite electronique et procede de generation de cle de session |
| PCT/FR2015/051207 WO2015170057A1 (fr) | 2014-05-09 | 2015-05-06 | Entité électronique et procédé de génération de clé de session |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3140951A1 true EP3140951A1 (fr) | 2017-03-15 |
Family
ID=51830388
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP15724344.5A Withdrawn EP3140951A1 (fr) | 2014-05-09 | 2015-05-06 | Entité électronique et procédé de génération de clé de session |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP3140951A1 (fr) |
| FR (1) | FR3020909B1 (fr) |
| WO (1) | WO2015170057A1 (fr) |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080034216A1 (en) * | 2006-08-03 | 2008-02-07 | Eric Chun Wah Law | Mutual authentication and secure channel establishment between two parties using consecutive one-time passwords |
-
2014
- 2014-05-09 FR FR1454191A patent/FR3020909B1/fr active Active
-
2015
- 2015-05-06 EP EP15724344.5A patent/EP3140951A1/fr not_active Withdrawn
- 2015-05-06 WO PCT/FR2015/051207 patent/WO2015170057A1/fr not_active Ceased
Non-Patent Citations (2)
| Title |
|---|
| None * |
| See also references of WO2015170057A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| FR3020909A1 (fr) | 2015-11-13 |
| FR3020909B1 (fr) | 2017-10-13 |
| WO2015170057A1 (fr) | 2015-11-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3152860B1 (fr) | Procédé d'authentification d'une première entité électronique par une seconde entité électronique et entité électronique mettant en oeuvre un tel procédé | |
| EP1529369B1 (fr) | Proc d d' change s curis d'informations entre deux dispositifs | |
| EP3010175B1 (fr) | Rejeu d'un batch de commandes sécurisees dans un canal sécurisé | |
| WO2016102833A1 (fr) | Entité électronique sécurisée, appareil électronique et procédé de vérification de l'intégrité de données mémorisées dans une telle entité électronique sécurisée | |
| EP3308564B1 (fr) | Procédé de chargement d'une clé virtuelle et terminal utilisateur associé | |
| FR3067829B1 (fr) | Procede d'authentification par defi-reponse d'un element securise (se) aupres d'un microcontroleur | |
| WO2019145620A1 (fr) | Système sécurisé de transactions entre terminaux | |
| EP3732849B1 (fr) | Procédé et système d'identification de terminal d'utilisateur pour la réception de contenus multimédia protégés et fournis en continu | |
| FR3046000A1 (fr) | Procede de reception de donnees au sein d'une entite electronique et entite electronique associee | |
| EP3136283B1 (fr) | Dispositif et procédé sécurisation de commandes échangées entre un terminal et circuit intégré | |
| EP2919412B1 (fr) | Procédé et système de chiffrement/déchiffrement de données à clé distante et vérification préalable de jeton | |
| WO2016102834A1 (fr) | Procédé d'authentification d'un utilisateur et d'un module sécurisé, appareil électronique et système associes | |
| EP3140951A1 (fr) | Entité électronique et procédé de génération de clé de session | |
| FR3116133A1 (fr) | Procédé de délégation d’accès à une chaîne de blocs | |
| FR3025631A1 (fr) | Selection securisee d'une application dans une carte a puce ou equivalent | |
| FR3022716A1 (fr) | Procede de partage de fichiers numeriques entre plusieurs ordinateurs, et ordinateur, ensemble de stockage de donnees et systeme de partage de fichiers numeriques associes | |
| WO2016102832A1 (fr) | Procédé d'authentification d'une application, appareil électronique et programme d'ordinateur associés | |
| FR3032846A1 (fr) | Procede de communication securisee entre un systeme d'exploitation d'un terminal et un dispositif distinct du terminal | |
| FR3086417A1 (fr) | Procede cryptographique de comparaison securisee de deux donnees secretes x et y | |
| EP3021515B1 (fr) | Amélioration de l'intégrité authentique de données à l'aide du dernier bloc chiffrant ces données en mode cbc | |
| WO2025083096A1 (fr) | Protocole niable a apport de connaissance nulle | |
| FR3154209A1 (fr) | Procédé de mise en œuvre d’une transaction entre un premier équipement de preuve et un deuxième équipement de vérification. | |
| WO2025109113A1 (fr) | Procédés, dispositifs et système de transmission et d'acquisition d'une donnée | |
| EP4652758A1 (fr) | Procédés de signature de données, de fourniture de données signées, terminal et serveur associés | |
| WO2016034812A1 (fr) | Sécurisation de clés de cryptage pour transaction sur un dispositif dépourvu de module sécurisé |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20161208 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: IDEMIA FRANCE |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: IDEMIA FRANCE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20191125 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
| INTG | Intention to grant announced |
Effective date: 20220110 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN WITHDRAWN |
|
| 18W | Application withdrawn |
Effective date: 20220216 |