EP3887989A1 - Sicheres element als aktualisierbares trusted platform module - Google Patents
Sicheres element als aktualisierbares trusted platform moduleInfo
- Publication number
- EP3887989A1 EP3887989A1 EP19817137.3A EP19817137A EP3887989A1 EP 3887989 A1 EP3887989 A1 EP 3887989A1 EP 19817137 A EP19817137 A EP 19817137A EP 3887989 A1 EP3887989 A1 EP 3887989A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- control commands
- terminal
- secure element
- platform module
- trusted platform
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/575—Secure boot
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/77—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in smart cards
Definitions
- the present invention is directed to a method for the safe operation of a terminal with updatable security software, which enables hardware structures to be provided which, on the one hand, allow data to be processed in a trustworthy manner and, on the other hand, can also be updated.
- the corresponding security software can be adapted to current threats.
- the present invention is also directed to a correspondingly configured secure element for use in the method and to a system arrangement which is set up to carry out the proposed method.
- a computer program product is proposed with control commands which execute the method or operate the proposed system arrangement.
- WO 2018/103 883 A1 shows a memory arrangement for secure authentication, comprising a mass data memory and a security element.
- DE 10 2014002 603 A1 shows a method and a system for remotely managing a data element stored on a security element.
- US 2016/0 275 461 A1 shows a computer-implemented method for checking an integrity using a block chain. For this purpose, aspects related to the so-called Trusted Platform Module are discussed.
- Trusted Platform Module is a hardware module that restricts or monitors the functionality of a computing unit. For example, it is possible that software can only be executed on a certain dedicated computer. This is intended to prevent the execution of malware.
- a disadvantage here is that the control commands held are hard-coded in such a way that they cannot be overwritten. Consequently, the control commands themselves are safeguarded and protected against manipulation, and the desired updating of such control commands must also be avoided in a disadvantageous manner.
- the so-called Internet of Things is known, which is also referred to as the Internet of Things IoT.
- IoT Internet of Things
- BIOS Basic Input / Output System BIOS.
- These are control commands that are used at the hardware level and mediate between the physical hardware components and higher application levels.
- the hardware structure of the computing unit is initialized when a computing unit is started, also referred to as the boot process.
- TPM Trusted Platform Modules
- Version 2.0 is currently not backwards compatible.
- Recently TPM chips have also been used in industry and mechanical engineering.
- TPM is to be used as a security anchor specifically for IoT and Industry 4.0 applications.
- the lifespan of a TPM follows the IT product lifecycle of three years.
- Cryptography technologies are also considered obsolete and insecure after three years.
- significantly longer life cycles are necessary.
- a TPM is static, i.e. not updateable. This goes up to the pin incompatibility of the chip generations.
- the TPM security level is therefore static and not very forward-looking.
- IT hardware anchors should be updateable, i.e. upgradeable, since crypto technology is faster-lived than the life cycle of IT hardware anchors in IT security devices or even machines.
- the cryptographic algorithms should be replaced every three years, or longer ones Keys are used. With a TPM chip, this can only be done by replacing the chip itself.
- TPM Today's IT security concepts and products such as a TPM are unusable for such industrial applications and the associated very long life cycle. Standard hardware products last a maximum of three years. A TPM that was specified in 2014 and will be available in 2016 is already considered unsafe from 2017 (BSI). The standard is to replace the cryptographic processes every three years.
- TPM smart cards have not been used in an industrial environment or as a TPM replacement. The reasons are, on the one hand, contacting via card reader or USB, or, in the case of TPM, because old BIOS or newer EFI / UEFI cannot yet address the smart card, or simply no focus has been placed on the industrial / machine or PC market.
- a TPM has a static security level by design, and the versions are not backwards compatible and cannot be updated.
- the secure element in chip form should act as a TPM with the appropriate applet and be used, among other things, for secure booting via EFI / UEFI.
- the system identity and the "secret” to system integrity and communication is stored.
- the SE can be managed centrally and, if necessary, supplied with updates to applets, cryptography and OS levels.
- existing end devices should be able to be adapted and the control commands used should be updateable if necessary and still be protected by hardware.
- it is an object of the present invention to propose a correspondingly configured secure element and a system arrangement which is designed analogously to the proposed method.
- it is an object of the present invention to propose a computer program product with control commands which execute the method or operate the proposed system arrangement.
- a method for the safe operation of a terminal with updatable security software comprising providing control commands that implement a trusted platform module functionality, storing the provided control commands a secure element, communicative coupling of the secure element with the terminal to be operated securely, execution of at least part of the control commands and adaptation of the control commands on the secure element by the terminal.
- control commands can thus be made available iteratively and after a control command has been provided, it can be stored. Further control commands can then be provided and also stored. The adjustment of the control commands can also be carried out repeatedly.
- the proposed method enables a terminal to be operated safely since the functionality of the so-called Trusted Platform Module TPM is provided.
- This is a functionality that is used for the safe processing of control commands.
- cryptographic functions are provided that secure data communication and data processing.
- the security function can relate, among other things, to which software can be executed on the corresponding end device and which cannot.
- communication with hardware components can be restricted.
- various software-related precautions have been taken to ensure the confidentiality of data by means of encryption. It is also provided that the data to be processed cannot be manipulated. This relates in particular to cryptographic keys, which are used to encrypt and decrypt data communication. These become special secured so that they cannot be read out or manipulated.
- the underlying security software can be updated because it is stored on the secure element, which has a persistent memory that can be rewritten.
- the security software is the control commands that implement a Trusted Platform Module functionality. Consequently, as is shown in the state of the art, a physical trusted platform module is not provided, but rather only the control commands which emulate a so-called trusted platform module are used. As a result, the functionality of this module is provided without the hardware structure of the Trusted Platform Module having to be used. Protection is ensured by the fact that the control commands are managed by the secure element and, if necessary, executed.
- the secure element can provide specially secured hardware or software measures. This makes it possible to implement separate memories so that sensitive data cannot be accessed.
- the secure element can be secured using special software technology using cryptographic methods.
- the secure element thus represents an extension to the end device, which is particularly secured. In this way, the end device can outsource particularly sensitive data to the secure element.
- the secure element on the other hand, can hold the control commands and execute them or transmit them to the terminal for execution.
- Control commands which implement a trusted platform module functionality, can be provided in such a way that an existing Module is read out and the control commands are then stored on the secure element.
- the control commands can be provided by means of an interface, for which purpose, for example, a manufacturer provides corresponding implementations.
- the control commands implement the functionality and hold source code, for example. It is also possible that the control commands are already compiled. For this purpose, it is advantageous to provide a so-called image, which is then stored persistently on the secure element.
- the secure element has a separate memory, which is consequently separated from the memory of the terminal.
- This implements a security functionality and, in addition, at least some of the control commands provided can be cryptographically secured. It is therefore advantageous to encrypt the control commands together with other parameters.
- Such parameters can be keys or other confidential information.
- the communicative coupling of the secure element with the terminal device to be operated safely can take place via a conventional interface. It is possible that the secure element is removably connected to the operable terminal or that the secure element is molded in one piece with the terminal to be operated. Communicative coupling can also be a logical measure, such that an interface is operated and the secure element identifies itself to the end device. Consequently, communicative coupling is the establishment of a communication line between the secure element and the terminal in such a way that control commands can be exchanged.
- the end device is preferably a computing unit such as a server or a server. conventional personal computer. This terminal can provide an interface with which the secure element is connected to the terminal. A plug connection is given here only by way of example, so that the secure element can be plugged into a connection of the terminal.
- control commands are executed.
- the secure element can have a processing unit ready, which reads out the control commands from the data memory and then executes them. If the control commands are carried out by the terminal, this implies that the control commands are transmitted from the secure element to the terminal via the interface.
- the control commands are manipulated on the terminal, and it can therefore be advantageous to leave the control commands on the safe terminal and to execute them there. It is thus possible for the terminal to be started in such a way that the control commands on the secure terminal initialize the hardware of the terminal or for an operating system to be started and possibly loaded using the control commands.
- control commands are adapted according to the invention, which is done by the secure terminal.
- the control commands can thus be downloaded from the terminal and then provided to the secure element. Since the secure element has a writable memory, the control commands can then be right element.
- the same steps can be carried out as are carried out when control commands are made available.
- the adaptation of the control commands can thus branch out again the provision of control commands and updated control commands can be stored on the safe element.
- the adaptation of the control commands is an update of the control commands, which relates to all control commands or at least a part thereof. In this way, new application scenarios can be taken into account and the control commands can prevent new attacks.
- the trusted platform module functionality is provided in accordance with the specifications of the trusted computing group. This has the advantage that clearly specified control commands can be used that provide security functionality. Existing control commands can thus be reused and a system which has already been tested can advantageously be used in a new context. Corresponding specifications can u. a. on the Trusted Computing Group website at
- the trusted platform module functionality is provided in accordance with the specification “TPM Main Specification Level 2 Version 1.2, Revision 116”. This has the advantage that the trusted platform module functionality is clearly defined for the person skilled in the art and there are extensive specifications available. In general it is possible to use the Trusted Platform Module functionality to design a further specification of the Trusted Computing Group, only one specification being mentioned here by way of example.
- control commands are executed by the terminal and / or by the secure element.
- the communicative coupling takes place by means of a contact-based interface, such as e.g. Serial Peripheral Interface SPI, Universal Serial Bus USB, I2C, GPIO, ISO interface, etc. or a contactless interface, e.g. NFC, BLE, SWP, etc.
- a contact-based interface such as e.g. Serial Peripheral Interface SPI, Universal Serial Bus USB, I2C, GPIO, ISO interface, etc. or a contactless interface, e.g. NFC, BLE, SWP, etc.
- the interfaces are used in parallel or pseudo-parallel and, if necessary, simultaneously or simultaneously. This has the advantage of accelerated data transfer.
- at least some of the control commands are loaded onto the terminal. This has the advantage that the terminal can select individual control commands and can save them for further processing or execution.
- the adaptation of the control commands comprises updating, overwriting, supplementing, deleting and / or changing the control commands.
- a driver, middleware and / or a further software component is provided for executing at least some of the control commands.
- This has the advantage that all levels of the end device are addressed. For example, it is possible to execute the control commands close to the hardware or to provide a software component at the application level.
- the communicative coupling comprises providing an interface, a Unified Extensible Firmware Interface UEFI, an Extensible Firmware Interface EFI and / or a switching component.
- the secure element performs cryptographic functions. This has the advantage that not only can the control commands be secured, but rather communication with the terminal can also be secured. The proposed method is therefore particularly secure against manipulation and data is also treated confidentially.
- the execution of at least some of the control commands comprises starting the terminal.
- a boot method can also be carried out using the proposed method.
- the terminal it is possible for the terminal to be started on the basis of the control commands provided, and the underlying hardware components can be initialized.
- the object is also achieved by a secure element for use in the proposed method.
- the secure element stores the control commands that implement a trusted platform module functionality.
- the Trusted Platform Module represents an independent hardware component. It is disadvantageous in the prior art that the so-called trusted platform module is provided as read-only memory, which is prevented according to the invention in that the secure element has a rewritable data memory.
- the secure element is in the form of a Universal Integrated Circuit Card UICC or an embedded Universal Integrated Circuit Card eUICC or an embedded Secure Element eSE.
- a system arrangement for the safe operation of a terminal with updatable security software comprising an interface unit set up to provide control commands that implement a trusted platform module functionality, a storage unit set up to store the control commands provided on a secure element, a coupling unit set up for communicative coupling of the secure element with the end device to be operated securely, an execution unit set up for executing at least part of the control commands, and an update unit configured to adapt the control commands on the secure element by the terminal.
- individual units can be provided as a structural unit which provides logically different functionality.
- some of the units can be implemented as interfaces, which can be implemented as separate interfaces or as a single interface.
- the proposed system arrangement can include the secure element and the terminal.
- network technology components can be provided to ensure communication between the secure element and the end device.
- the task is also solved by a computer program product, e.g. software, middleware, an application, etc., with control commands which implement the method or operate the proposed system arrangement.
- a computer program product e.g. software, middleware, an application, etc.
- the method maintains process steps that can be functionally simulated by structural features of the system arrangement.
- the system arrangement is also suitable for carrying out the proposed method.
- procedural steps are proposed which can be reproduced structurally by the system arrangement and the structural features of the system arrangement can be implemented functionally by means of method steps. Further advantageous embodiments are explained in more detail with reference to the attached figure. It shows:
- Fig. 1 a schematic flow diagram of a method for secure
- FIG. 1 shows the proposed method for the safe operation of a terminal with updatable security software, comprising providing 100 of control commands that implement a trusted platform module functionality, storing 101 of the 100 control commands provided on a secure element, communicative coupling 102 of the secure element with the terminal to be operated safely, executing 103 at least a part of the control commands, and adapting 104 the control commands on the secure element by the terminal.
- a smart card in chip design (eg Sm @ rtCafe Expert, SkySIM "Hercules", these are registered trademarks) can be inventively used via a standard interface (eg SPI, USB, ISO, I2C, GPIO etc. ), possibly also contactless interfaces (eg NFC, BLE, SWI, SWP etc.) can be connected to the system.
- An applet is loaded, which takes over the TPM function.
- the appropriate "driver” in the EFI / UEFI BIOS the system can interact with the smart card.
- drivers and middleware can access and interact with the other functions that are loaded as applets. This also includes the update function.
- All smart cards, their content and security can be managed centrally via a management platform, similar to subscription management.
- a management platform Similar to subscription management.
- the long lifecycle in the industrial environment prohibits fast-moving IT standard technology like a TPM.
- a smart card in chip design (eg Sm @ rtCafe Expert, SkySIM “Herkules”", these are registered trademarks) can be updated, can perform various functions via applets and has a standard interface (SPI, USB “ISO” and is available for a long time
- SPI standard interface
- ISO USB
- the biggest advantage is the central manageability of such a smart card solution.
- "Security by Design” can also be used in machine building for industrial IoT and Industry 4.0 use cases can be realized.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102018009365.5A DE102018009365A1 (de) | 2018-11-29 | 2018-11-29 | Sicheres Element als aktualisierbares Trusted Platform Module |
| PCT/EP2019/025397 WO2020108797A1 (de) | 2018-11-29 | 2019-11-14 | Sicheres element als aktualisierbares trusted platform module |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3887989A1 true EP3887989A1 (de) | 2021-10-06 |
Family
ID=68835136
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19817137.3A Pending EP3887989A1 (de) | 2018-11-29 | 2019-11-14 | Sicheres element als aktualisierbares trusted platform module |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP3887989A1 (de) |
| DE (1) | DE102018009365A1 (de) |
| WO (1) | WO2020108797A1 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12567962B2 (en) | 2023-03-14 | 2026-03-03 | Nxp B.V. | Method for post-quantum secure in-the-field trust provisioning |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2595420A1 (de) * | 2011-11-18 | 2013-05-22 | Gemalto SA | Verfahren zum Senden einer Nachricht an ein sicheres Element |
Family Cites Families (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE19945861A1 (de) * | 1999-09-24 | 2001-03-29 | Ibm | Hardwarenahe Konfiguration und Verriegelung von Geräten |
| DE10006062C2 (de) * | 2000-02-10 | 2002-03-07 | Excelsis Informationssysteme G | Tastaturschlüssel |
| EP1867190B1 (de) * | 2005-04-07 | 2009-08-19 | France Telecom | Verwaltung des zugangs zu multimedia-inhalten |
| DE102008050441A1 (de) * | 2008-10-08 | 2010-04-15 | Straub, Tobias | Autonome Vorrichtung zum Schutz der Authentizität von in digitaler Form vorliegenden Daten |
| EP2579175A1 (de) * | 2011-10-03 | 2013-04-10 | Gemalto SA | Sicheres Element mit getrennten Behältern und entsprechendes Verfahren |
| EP2584755A1 (de) * | 2011-10-19 | 2013-04-24 | Gemalto SA | Verfahren zum Senden eines Befehls an ein sicheres Element |
| DE102014002603A1 (de) | 2014-02-24 | 2015-08-27 | Giesecke & Devrient Gmbh | Verfahren zum entfernten Verwalten eines auf einem Sicherheitselement gespeicherten Datenelements |
| FR3024915B1 (fr) * | 2014-08-18 | 2016-09-09 | Proton World Int Nv | Dispositif et procede pour assurer des services de module de plateforme securisee |
| US9628445B2 (en) * | 2014-10-31 | 2017-04-18 | Ncr Corporation | Trusted device control messages |
| RU2673842C1 (ru) | 2015-03-20 | 2018-11-30 | Ривец Корп. | Автоматическая аттестация сохранности устройства с применением цепочки блоков |
| CA2982785C (en) * | 2015-04-14 | 2023-08-08 | Capital One Services, Llc | Systems and methods for secure firmware validation |
| AU2017370818B2 (en) * | 2016-12-09 | 2022-09-29 | Secunet Security Networks Aktiengesellschaft | Secure storage device |
-
2018
- 2018-11-29 DE DE102018009365.5A patent/DE102018009365A1/de active Pending
-
2019
- 2019-11-14 EP EP19817137.3A patent/EP3887989A1/de active Pending
- 2019-11-14 WO PCT/EP2019/025397 patent/WO2020108797A1/de not_active Ceased
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2595420A1 (de) * | 2011-11-18 | 2013-05-22 | Gemalto SA | Verfahren zum Senden einer Nachricht an ein sicheres Element |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2020108797A1 (de) | 2020-06-04 |
| DE102018009365A1 (de) | 2020-06-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE102009013384B4 (de) | System und Verfahren zur Bereitstellung einer sicheren Anwendungsfragmentierungsumgebung | |
| DE102021127242B4 (de) | System und Verfahren zum Signieren und Verriegeln einer Boot-Informationsdatei für ein Host-Computersystem | |
| EP3337085B1 (de) | Nachladen kryptographischer programminstruktionen | |
| DE102011081421A1 (de) | System zur sicheren Übertragung von Daten und Verfahren | |
| EP3204850A1 (de) | Verfahren zum laden von ausführbaren programminstruktionen in eine chipkarte im wirkbetrieb | |
| EP3286872B1 (de) | Bereitstellen eines gerätespezifischen kryptographischen schlüssels aus einem systemübergreifenden schlüssel für ein gerät | |
| EP3887989A1 (de) | Sicheres element als aktualisierbares trusted platform module | |
| EP3224756B1 (de) | Verfahren zum nachladen von software auf eine chipkarte durch einen nachladeautomaten | |
| EP2524333B1 (de) | Verfahren zum bereitstellen eines sicheren zählers auf einem endgerät | |
| DE102009048756B4 (de) | Verfahren und Schlüsselgerät zur Verbesserung der Sicherheit eines verschlüsselten Datenspeichers, von dem ein Computer bootet | |
| EP3329415B1 (de) | Chipkarte mit hauptapplikation und persistenzapplikation erlaubt hauptapplikationupdate ohne die benutzerdaten im persistenzapplikation zu ändern | |
| EP3552142A1 (de) | Sichere speicheranordnung | |
| EP2465067B1 (de) | Verfahren und vorrichtung zum ausführen von anwendungen in einer sicheren, autonomen umgebung | |
| DE102014209037B4 (de) | Vorrichtung und Verfahren zum Schutz der Integrität von Betriebssysteminstanzen | |
| DE102021126509A1 (de) | Tragbare Chipvorrichtung und Verfahren zum Ausführen eines Softwaremodul-Updates in einer tragbaren Chipvorrichtung | |
| DE102015207004A1 (de) | Verfahren zum geschützten Zugriff auf Sicherheitsfunktionen eines Sicherheitsmoduls eines Hostsystems | |
| DE102023102191A1 (de) | Installieren eines Betriebssystems in einer Prozessoreinrichtung, insbesondere einem Sicherheitsmodul | |
| WO2023051950A1 (de) | Universal integrated chip card, uicc, zum verwalten von profilen, sowie verfahren | |
| DE102005059248A1 (de) | Erzeugung von Programmcode für einen tragbaren Datenträger | |
| WO2011023453A1 (de) | Vorrichtungen und verfahren zum konfigurieren eines geräts eines eingebetteten systems |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20210629 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: GIESECKE+DEVRIENT MOBILE SECURITY GMBH |
|
| P01 | Opt-out of the competence of the unified patent court (upc) registered |
Effective date: 20230519 |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: GIESECKE+DEVRIENT EPAYMENTS GMBH |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: GIESECKE+DEVRIENT MOBILE SECURITY GERMANY GMBH |
|
| 17Q | First examination report despatched |
Effective date: 20240123 |