EP4062584A1 - Procede securise d'echange de donnees entre un terminal et un serveur - Google Patents
Procede securise d'echange de donnees entre un terminal et un serveurInfo
- Publication number
- EP4062584A1 EP4062584A1 EP20821347.0A EP20821347A EP4062584A1 EP 4062584 A1 EP4062584 A1 EP 4062584A1 EP 20821347 A EP20821347 A EP 20821347A EP 4062584 A1 EP4062584 A1 EP 4062584A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- terminal
- message
- cryptographic module
- white box
- challenge
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
- 238000000034 method Methods 0.000 title claims abstract description 47
- 230000004044 response Effects 0.000 claims abstract description 86
- 238000004590 computer program Methods 0.000 claims description 11
- DCVQOLOVXUUDBR-XOBNHNQQSA-N 2-butyl-1-[(e)-[(1e)-1-[(n'-butylcarbamimidoyl)hydrazinylidene]propan-2-ylidene]amino]guanidine Chemical compound CCCCN=C(N)N\N=C\C(\C)=N\NC(N)=NCCCC DCVQOLOVXUUDBR-XOBNHNQQSA-N 0.000 claims description 3
- 238000004519 manufacturing process Methods 0.000 claims description 2
- 238000002716 delivery method Methods 0.000 claims 1
- 230000006870 function Effects 0.000 description 21
- 230000003863 physical function Effects 0.000 description 12
- 230000007246 mechanism Effects 0.000 description 8
- 238000010367 cloning Methods 0.000 description 2
- 230000003287 optical effect Effects 0.000 description 2
- 230000008569 process Effects 0.000 description 2
- 241001074639 Eucalyptus albens Species 0.000 description 1
- 241000700605 Viruses Species 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 238000004377 microelectronic Methods 0.000 description 1
- 238000012544 monitoring process Methods 0.000 description 1
- NQLVQOSNDJXLKG-UHFFFAOYSA-N prosulfocarb Chemical compound CCCN(CCC)C(=O)SCC1=CC=CC=C1 NQLVQOSNDJXLKG-UHFFFAOYSA-N 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0435—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply symmetric encryption, i.e. same key used for encryption and decryption
-
- G—PHYSICS
- G09—EDUCATION; CRYPTOGRAPHY; DISPLAY; ADVERTISING; SEALS
- G09C—CIPHERING OR DECIPHERING APPARATUS FOR CRYPTOGRAPHIC OR OTHER PURPOSES INVOLVING THE NEED FOR SECRECY
- G09C1/00—Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/0618—Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
- H04L9/0637—Modes of operation, e.g. cipher block chaining [CBC], electronic codebook [ECB] or Galois/counter mode [GCM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
- H04L9/3278—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response using physically unclonable functions [PUF]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/16—Obfuscation or hiding, e.g. involving white box
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
Definitions
- the present invention relates to the field of secure data exchange in a telecommunications network.
- the invention is aimed at a secure method of exchanging data that is less vulnerable than those of the prior art.
- the invention therefore aims at a new secure mechanism for exchanging data between two pieces of equipment.
- the invention relates to a method for providing a cryptographic module in a white box.
- This method is implemented by a server comprising a cryptographic module configured to encrypt or decrypt a message from input parameters comprising said message, a symmetric key and a response to a challenge.
- Said process comprises:
- said white box cryptographic module being a white box implementation of the server's cryptographic module for said symmetric key obtained for this terminal, said white box cryptographic module being configured to encrypt or decrypt a message from said symmetric key embedded in this module and from input parameters comprising a message and a response to a challenge;
- the invention relates to a server comprising: - a cryptographic module configured to encrypt or decrypt a message from input parameters comprising said message, a response to a challenge and a symmetric key,
- a module for obtaining a symmetric key for a terminal a module for generating a white box cryptographic module, said white box cryptographic module being a white box implementation of said server cryptographic module for said symmetric key obtained for this terminal, said white box cryptographic module being configured to encrypt or decrypt a message from said symmetric key embedded in this module and from input parameters comprising a message and a response to a challenge, and
- the invention relates to a method for obtaining a white box cryptographic module.
- This method is implemented by a terminal. It comprises :
- a white box cryptographic module constituting a white box implementation of the cryptographic module of said server for said symmetric key
- said white box cryptographic module being configured to encrypt or decrypt a message from said embedded symmetric key in this module and input parameters including a message and a response to a challenge.
- the invention relates to a terminal comprising:
- a module for sending a terminal identifier to a server comprising a cryptographic module configured to encrypt or decrypt a message from input parameters comprising said message, a response to a challenge and a symmetric key;
- the invention thus proposes a secure mechanism for exchanging data between a server and a terminal in which the cryptographic functions of encryption and / or decryption of the terminal are implemented according to a white box cryptography mechanism.
- the symmetric key used by the terminal for the implementation of the cryptographic functions of encryption and / or decryption is not stored in a memory of the terminal but hidden in the code of the white box cryptographic module generated by the server for this terminal.
- the symmetric key cannot therefore be obtained by a malicious third party who would attack or spy on the terminal during its execution.
- the invention is therefore particularly suitable when the terminals are mobile terminals, connected objects or any device vulnerable to attacks, in particular to viruses.
- white box cryptography those skilled in the art can refer to the document “Understanding White Box Cryptography, White Paper”, published at the address: https://www2.gemalto.com / email / 2012 / SRM / whitebox / public / pdf / WP_Whitebox_Cryptograph y _ FR _ A4 _ v4_web_ 1 _.pdf.
- the cryptographic module implemented by the server is not implemented in a white box, such a server being sufficiently secure and less exposed to attacks aimed at fraudulently obtaining the symmetric key.
- This server is said to be trusted. This feature allows faster execution of server-side cryptographic functions.
- the method for obtaining a white box cryptographic module implemented by the terminal further comprises:
- the method of supplying a white box cryptographic module implemented by the server comprises a step of receiving and recording at least one challenge / response pair coming from said terminal .
- a non-clonable physical function of the terminal is a characteristic of a hardware component of the terminal which makes it possible to uniquely differentiate an instance of a terminal among other terminals of the same brand, of the same model, produced in the same way. same time. It is indeed difficult to manufacture a terminal having the same characteristics as another terminal.
- the non-cloning physical function of a terminal can consist of a camera of the terminal.
- a camera in fact necessarily induces imperfections or noise in the images it produces, due to the characteristics of the sensor, for example the photodiodes of this sensor.
- the terminal can be considered.
- other sensors of the terminal than the camera can be used, such as a gyroscope, an accelerometer, a microphone, etc.
- this non-cloning physical function can be implemented by an electronic chip integrated into the terminal.
- non-clonable physical function is attached to the characteristics of the terminal and is specific to the terminal.
- the invention thus proposes to use a non-clonable function of the terminal to generate challenge / response pairs, these pairs in particular allowing the terminal to provide the server with proof that it is indeed a terminal known to the server.
- the answer to the challenge is a secret shared between the enrolled terminal and the server and only the enrolled terminal is able to determine it based on a challenge.
- the invention also proposes to use the defi / response pairs thus obtained in the cryptographic mechanisms for encryption / decryption of the messages exchanged between the terminal and the server.
- the invention thus relates to a method for encrypting a message implemented by a terminal, this method comprising:
- a white box cryptographic module from a server, said white box cryptographic module being configured to encrypt or decrypt a message from a symmetric key specific to the terminal and embedded in this module and input parameters comprising a message and a response to a challenge
- the invention relates to a method for decrypting an encrypted message received from a terminal, this method being implemented by a server and comprising:
- a decryption step implemented by providing said symmetric key, the response to the challenge and the encrypted message as input to the cryptographic module of said server, the result of said decryption step comprising a clear message.
- the invention also relates to a method of encrypting a message implemented by a server, said encrypted message being intended to be sent to a terminal, this method comprising:
- a data encryption step comprising obtaining a symmetrical key of said terminal and a response to a challenge, received from said terminal during a terminal enrollment phase, during which the server generated and supplied to the terminal a white box cryptographic module, said white box cryptographic module being a white box implementation of a server cryptographic module for said symmetric key, said module white box cryptographic being configured to encrypt or decrypt a message from input parameters comprising a message, a response to a challenge, and said symmetric key embedded in said white box cryptographic module, said response received from the corresponding terminal to a response from a challenge / response pair;
- an encryption step implemented by providing as input to the cryptographic module of said server said symmetric key, said response and said message;
- the invention also relates to a method for decrypting an encrypted message implemented by a terminal, this method comprising:
- a white box cryptographic module from a server, said white box cryptographic module being configured to encrypt or decrypt a message from a symmetric key specific to the terminal and embedded in this module and input parameters comprising a message and a response to a challenge
- the invention is also aimed at a computer program on an information medium, this program being capable of being implemented in a server or more generally in a computer, this program comprising instructions adapted to the implementation. implementation of the steps of a method of supplying a cryptographic module in a white box as presented above.
- the invention also relates to a computer program on an information medium, this program being capable of being implemented in a terminal or more generally in a computer, this program comprising instructions adapted to the implementation of the steps of a method for obtaining a cryptographic module in a white box as presented above.
- the invention also relates to a computer program on an information medium, this program being capable of being implemented in a server, in a terminal or more generally in a computer, this program comprising instructions adapted to the setting. implementing the steps of an encryption method or of a decryption method as presented above.
- These programs can use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other. desirable shape.
- the invention also relates to an information or recording medium readable by a computer, and comprising instructions of a computer program as mentioned above.
- the information or recording medium can be any entity or device capable of storing the program.
- the medium may comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or else a magnetic recording means, for example a hard disk.
- the information or recording medium can be a transmissible medium such as an electrical or optical signal, which can be conveyed via an electrical or optical cable, by radio or by other means.
- the program according to the invention can in particular be downloaded from an Internet type network.
- the information or recording medium can be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the method in question.
- FIG. 1 shows a terminal and a server according to the invention, in their environment
- FIG. 2 functionally shows a server according to a particular embodiment of the invention
- FIG. 3A shows a first use of a cryptographic module that can be implemented in the server of Figure 2;
- FIG. 3B shows a second use of a cryptographic module that can be implemented in the server of Figure 2;
- FIG. 4 functionally shows a terminal according to a particular embodiment of the invention
- FIG. 5A shows a first use of a white box cryptographic module that can be implemented in the terminal of Figure 4;
- FIG. 5B shows a second use of a white box cryptographic module that can be implemented in the terminal of Figure 4;
- FIG. 6 represents an example of a probabilistic module comprising a non-clonable function and which can be implemented in the terminal of FIG. 4;
- - Figure 7 shows in the form of a flowchart of the encryption and decryption methods a method that can be implemented by the terminal of Figure 4 and by the server of Figure 2, these methods conforming to particular embodiments of the invention;
- FIG. 8A is a physical representation of a terminal according to a particular embodiment of the invention.
- FIG. 8B is a hardware representation of a server according to a particular embodiment of the invention.
- FIG. 1 represents a TRM terminal conforming to a particular embodiment of the invention and an SRV server conforming to a particular embodiment of the invention in their environment, able to communicate by a NET telecommunications network, to exchange each other. messages in a secure manner, using a symmetric key cryptographic mechanism.
- the SRV server comprises a COM communication module and a CRY cryptographic module.
- the cryptographic module CRY of the SRV server comprises:
- an ENC encryption module configured to obtain a response to this challenge as a function of a challenge and to encrypt with a symmetric key Ku received at the input of this module, a plain msg message received at the input of this module, and the response to the challenge, the encrypted message being noted [msg];
- a decryption module DEC configured to obtain a response to this challenge as a function of a challenge and to decrypt with the symmetric key Ku received at the input of this module, an encrypted message [msg] received at the input of this module, the decrypted message being noted msg.
- the cryptographic module CRY could be configured to implement only decryption functions or only encryption functions and only include the corresponding DEC or ENC module.
- the TRM terminal comprises:
- the CRYBBu cryptographic module in white box of the TRM terminal comprises: - a white box encryption ENCBBu module, to obtain a response to this challenge as a function of a challenge and to encrypt, as a function of the response to the challenge and the symmetric key Ku, an msg message received at the input of this module , the encrypted message being noted [msg]; and
- DECBBu white box decryption module to obtain a response to this challenge as a function of a challenge and to decrypt with the symmetric key Ku and the response to the challenge an encrypted message [msg] received at the input of this module, the decrypted message being noted msg.
- the symmetric key Ku is not received at the input of the CRYBBu cryptographic module but is secretly buried in this module.
- secretly buried we mean that this symmetric key is not accessible by a malicious third party who would attack or spy on the terminal while performing encryption or decryption operations.
- the CRYBBu cryptographic module constitutes a white box implementation of the CRY cryptographic module of the SRV server, for the symmetric key Ku.
- the CRYBBu cryptographic module constitutes a white box implementation of the CRY cryptographic module of the SRV server, for the symmetric key Ku.
- the CRYBBu white box cryptographic module could be configured to implement only decryption functions or only encryption functions and include only the corresponding DECBBu or ENCBBu white box module.
- the communication means COM of the SRV server and of the TRM terminal are adapted to allow the TRM terminal to send an identifier u from this terminal to the SRV server to authenticate itself with this server.
- the SRV server comprises an MGBB module configured for:
- the COM communication means of the SRV server and of the TRM terminal are adapted to allow the SRV terminal to send the cryptographic module in the CRYBBu white box to the TRM terminal, either as is or integrated into an APP application.
- the TRM terminal includes an MI installation module configured to be able to install the CRYBBu cryptographic module or the APP application in a rewritable non-volatile memory of this terminal.
- the TRM terminal comprises a probabilistic module MPROB which will now be described with reference to FIG. 6.
- This MPROB probabilistic module includes a non-clonable PUF physical function.
- this MPROB probabilistic module is configured for:
- variable parameter that is to say a challenge xi
- this physical function is a camera of the terminal. It has hardware characteristics specific to the TRM terminal.
- this MPROB probabilistic module is configured for:
- variable parameter for example an exposure duration xi corresponding to the challenge
- the MPROB probabilistic module comprises a corrective filter FC configured to generate a signature yi, that is to say a response to the challenge xi, from the noisy signature y'i, this signature yi being identical for noisy signatures y'ij obtained for the same exposure time xi.
- this FC filter is secret and specific to the TRM terminal.
- the MPROB probabilistic module is configured to output the non-noisy signature yi, as a response to the challenge xi.
- the noisy signature y’i is an imprint of a darkness signal known per se by those skilled in the art of photographic sensors.
- the noisy signature yi is obtained by projecting the noisy signature y’i onto a binary sequence, as in a manner known to a person skilled in the art of coding.
- terminals can be considered. For example, this involves using other sensors of a terminal, such as a gyroscope, an accelerometer, a microphone, etc. It may also be an electronic chip integrated into the terminal implementing this function. non-clonable physical.
- non-clonable physical function is attached to the characteristics of the terminal and is specific to the terminal.
- the terminal TRM registers with the server SRV by providing it with its identifier u. This identifier is received by the server SRV during a step F 10.
- the SRV server authenticates the user during a step F20.
- the SRV server If the authentication is successful, during a step F30, the SRV server:
- the SRV server which acts as a trusted third party, obtains a set of challenges xi at random.
- the SRV server sends the application APP and the set of challenges xi to the TRM terminal during the same step F40.
- the TRM terminal receives them during a step E20.
- the TRM terminal During a step E30, the TRM terminal generates a response yi for each challenge xi received from the trusted third-party SRV server using the probabilistic function MPROB. It thus forms challenge / response pairs ⁇ xi, yi ⁇ .
- a response yi is obtained as a function of the challenge, the associated response yi being the noiseless signature obtained by the probabilistic module MPROB for this input parameter xi.
- the TRM terminal sends the ⁇ challenge, response ⁇ pairs to the SRV server during this same step E30. They are received by the SRV server and recorded in the BDS database during a step F50.
- Steps E10 to E30 and F10 to F50 constitute an enrollment phase referenced ENR in Figure 7.
- this operation consists in taking an image with the exposure time xi, calculate a noisy signature y'i of the dark signal of this image, and obtain the challenge yi by projecting the noisy signature y'i onto a binary chain;
- challenge xi is not sent to the SRV server.
- the SRV server obtains the symmetric key Ku in its BDS database from the identifier u. It obtains from its BDS database the response yi corresponding to challenge xi. It decrypts the encrypted message [msg] using its decryption module DEC as a function of the symmetric key Ku and the response yi and retrieves a message. If yi does correspond to the value used by the terminal, then the message retrieved corresponds to the plain msg message.
- the SRV server wishes to send an msg message to the TRM terminal in a secure manner.
- the SRV server During a step F80, the SRV server:
- the TRM terminal During a step E60, the TRM terminal:
- MPROB probabilistic module
- the decrypted message corresponds to the plain msg message.
- Figure 8A shows the TRM terminal of Figure 1.
- this TRM terminal has the architecture of a computer. It comprises in particular a processor 10, a random access memory of the RAM 11 type, a read-only memory of the ROM 12 type, a rewritable non-volatile memory of the FLASH type 13 and communication means COM.
- the application APP is recorded in the non-volatile memory 13.
- the instructions of this application and in particular those of the CRYBBu cryptographic module in white box are executed by the processor 10.
- the non-volatile memory 13 also stores the identifier u of the terminal.
- ROM 12 constitutes a recording medium according to the invention. It includes a PGT computer program according to the invention. This PGT program comprises in particular instructions for, when they are executed by the processor 10:
- Figure 8B shows the SRV server of Figure 1.
- this SRV server has the architecture of a computer. It comprises in particular a processor 20, a random access memory of the RAM 21 type, a read-only memory of the ROM type 22, a rewritable non-volatile memory of the FLASH type 23 and communication means COM.
- the non-volatile memory 23 also stores the BDS database.
- ROM 22 constitutes a recording medium according to the invention. It includes a PGS computer program according to the invention. This PGS program comprises in particular instructions for, when they are executed by the processor 20:
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR1913104A FR3103591A1 (fr) | 2019-11-22 | 2019-11-22 | Procédé sécurisé d’échange de données entre un terminal et un serveur |
| PCT/FR2020/052130 WO2021099744A1 (fr) | 2019-11-22 | 2020-11-19 | Procede securise d'echange de donnees entre un terminal et un serveur |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4062584A1 true EP4062584A1 (fr) | 2022-09-28 |
Family
ID=69903322
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP20821347.0A Pending EP4062584A1 (fr) | 2019-11-22 | 2020-11-19 | Procede securise d'echange de donnees entre un terminal et un serveur |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20230025166A1 (fr) |
| EP (1) | EP4062584A1 (fr) |
| FR (1) | FR3103591A1 (fr) |
| WO (1) | WO2021099744A1 (fr) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR3121525B1 (fr) * | 2021-04-02 | 2023-06-23 | Idemia France | Authentification d’un dispositif par un traitement cryptographique |
| CN113722741A (zh) * | 2021-09-07 | 2021-11-30 | 浙江大华技术股份有限公司 | 数据加密方法及装置、数据解密方法及装置 |
Family Cites Families (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP5249053B2 (ja) * | 2006-03-10 | 2013-07-31 | イルデト・コーポレート・ビー・ヴイ | データ処理システムの完全性 |
| EP2326043A1 (fr) * | 2009-11-18 | 2011-05-25 | Irdeto Access B.V. | Prévention du clonage de récepteurs de messages cryptés |
| US8751807B2 (en) * | 2011-06-23 | 2014-06-10 | Azuki Systems Inc. | Method and system for secure over-the-top live video delivery |
| US9953166B2 (en) * | 2013-07-04 | 2018-04-24 | Microsemi SoC Corporation | Method for securely booting target processor in target system using a secure root of trust to verify a returned message authentication code recreated by the target processor |
| DE102013227087A1 (de) * | 2013-12-23 | 2015-06-25 | Siemens Aktiengesellschaft | Gesichertes Bereitstellen eines Schlüssels |
| KR20150129459A (ko) * | 2014-05-12 | 2015-11-20 | 한국전자통신연구원 | 화이트 박스 암호화 장치 및 그 방법 |
| KR101933649B1 (ko) * | 2016-05-27 | 2018-12-28 | 삼성에스디에스 주식회사 | 화이트박스 암호 알고리즘을 이용한 공개키 암호화를 위한 장치 및 방법 |
| EP3552340A2 (fr) * | 2016-12-12 | 2019-10-16 | ARRIS Enterprises LLC | Cryptographie en boîte blanche forte |
| US10511436B1 (en) * | 2017-07-31 | 2019-12-17 | EMC IP Holding Company LLC | Protecting key material using white-box cryptography and split key techniques |
| US10812269B2 (en) * | 2017-11-07 | 2020-10-20 | Arris Enterprises Llc | Advanced crypto token authentication |
| US10140612B1 (en) * | 2017-12-15 | 2018-11-27 | Clover Network, Inc. | POS system with white box encryption key sharing |
| FR3079653B1 (fr) * | 2018-03-29 | 2022-12-30 | Airtag | Procede de verification d'une authentification biometrique |
| KR102364652B1 (ko) * | 2019-08-01 | 2022-02-21 | 한국전자통신연구원 | 화이트박스 암호화를 이용한 puf 기반 사물인터넷 디바이스 인증 장치 및 방법 |
-
2019
- 2019-11-22 FR FR1913104A patent/FR3103591A1/fr not_active Withdrawn
-
2020
- 2020-11-19 US US17/777,906 patent/US20230025166A1/en active Pending
- 2020-11-19 WO PCT/FR2020/052130 patent/WO2021099744A1/fr not_active Ceased
- 2020-11-19 EP EP20821347.0A patent/EP4062584A1/fr active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| US20230025166A1 (en) | 2023-01-26 |
| WO2021099744A1 (fr) | 2021-05-27 |
| FR3103591A1 (fr) | 2021-05-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3238200A1 (fr) | Entité électronique sécurisée, appareil électronique et procédé de vérification de l'intégrité de données mémorisées dans une telle entité électronique sécurisée | |
| WO2021099744A1 (fr) | Procede securise d'echange de donnees entre un terminal et un serveur | |
| EP3917073A1 (fr) | Établissement efficace de sessions sécurisées pour l'anonymat dans les réseaux 5g | |
| EP4241416B1 (fr) | Procede de delegation d'acces a une chaine de blocs | |
| EP3219077B1 (fr) | Procédé et système de gestion d'identités d'utilisateurs destiné à être mis en oeuvre lors d'une communication entre deux navigateurs web | |
| EP3789898B1 (fr) | Procédé de génération d'une clé | |
| FR3057122A1 (fr) | Procede et dispositif de detection d'intrusions sur un reseau utilisant un algorithme de chiffrement homomorphe | |
| EP4068679B1 (fr) | Authentification d'un dispositif par un traitement cryptographique | |
| WO2021074527A1 (fr) | Procede de gestion d'une base de donnees de cles publiques, procede d'authentification de cles publiques, et dispositifs serveur et client mettant en oeuvre ces procedes | |
| FR3141021A1 (fr) | Procédé de mise en œuvre d’un service d’une chaîne de services et dispositif électronique associé | |
| EP4128700A1 (fr) | Procede et dispositif d'authentification d'un utilisateur aupres d'une application | |
| EP3340096B1 (fr) | Procédé de configuration d'un programme cryptographique destiné à être exécuté par un terminal | |
| WO2023041863A1 (fr) | Procedes et dispositifs d'authentification et de verification de non-revocation | |
| WO2023062095A1 (fr) | Procédé et dispositif de transfert d'une communication d'une station de base à une autre | |
| FR3128089A1 (fr) | Procédé et dispositif de sélection d’une station de base | |
| EP4652758A1 (fr) | Procédés de signature de données, de fourniture de données signées, terminal et serveur associés | |
| WO2025021489A1 (fr) | Procédés et dispositifs pour authentifier des données | |
| FR3141020A1 (fr) | Procédé de mise en œuvre d’un service d’une chaîne de services et dispositif électronique associé | |
| FR3107414A1 (fr) | Procédé de calcul d’une clé de session, procédé de récupération d’une telle clé de session | |
| WO2010133459A1 (fr) | Procede de chiffrement de parties particulieres d' un document pour les utilisateurs privileges | |
| FR3108816A1 (fr) | Procédé de délégation d’une fonction de résolution d’identifiants de nommage | |
| FR2898448A1 (fr) | Authentification d'un dispositif informatique au niveau utilisateur | |
| FR3093882A1 (fr) | Procédé de configuration d’un objet communicant dans un réseau de communication, terminal utilisateur, procédé de connexion d’un objet communicant au réseau, équipement d’accès et programmes d’ordinateur correspondants. | |
| WO2017089710A1 (fr) | Procédé de distribution de droits sur un service et plateforme de service | |
| FR2982724A1 (fr) | Communication securisee |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20220615 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20241018 |