EP4652758A1 - Procédés de signature de données, de fourniture de données signées, terminal et serveur associés - Google Patents
Procédés de signature de données, de fourniture de données signées, terminal et serveur associésInfo
- Publication number
- EP4652758A1 EP4652758A1 EP23837661.0A EP23837661A EP4652758A1 EP 4652758 A1 EP4652758 A1 EP 4652758A1 EP 23837661 A EP23837661 A EP 23837661A EP 4652758 A1 EP4652758 A1 EP 4652758A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- terminal
- key
- trmu
- signature
- data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/106—Packet or message integrity
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
- G06F21/645—Protecting data integrity, e.g. using checksums, certificates or signatures using a third party
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/322—Aspects of commerce using mobile devices [M-devices]
- G06Q20/3227—Aspects of commerce using mobile devices [M-devices] using secure elements embedded in M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/322—Aspects of commerce using mobile devices [M-devices]
- G06Q20/3229—Use of the SIM of a M-device as secure element
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/36—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes
- G06Q20/367—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes
- G06Q20/3674—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using electronic wallets or electronic money safes involving electronic purses or money safes involving authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3823—Payment protocols; Details thereof insuring higher security of transaction combining multiple encryption tools for a transaction
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3825—Use of electronic signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/382—Payment protocols; Details thereof insuring higher security of transaction
- G06Q20/3829—Payment protocols; Details thereof insuring higher security of transaction involving key management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0877—Generation of secret information including derivation or calculation of cryptographic keys or passwords using additional device, e.g. trusted platform module [TPM], smartcard, USB or hardware security module [HSM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
- H04L9/0897—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage involving additional devices, e.g. trusted platform module [TPM], smartcard or USB
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3297—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving time stamps, e.g. generation of time stamps
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/069—Authentication using certificates or pre-shared keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/40—Security arrangements using identity modules
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/61—Time-dependent
Definitions
- the present invention lies in the field of providing data in a telecommunications network and more precisely in that of providing signed data.
- the European Union has established an elDAS (Electronic IDentification Authentication and trust Services) regulation on electronic identification and trust services for electronic transactions.
- elDAS Electronic IDentification Authentication and trust Services
- Certain provisions of this regulation for example, impose a level of security which can only be obtained with mobile terminals containing certified hardware security elements, for example a SIM card (Subscriber Identity Module) or TEE card (Trusted Execution). Environment) certified up to a level resistant to an AVA_VAN.5 level evaluation system as defined by “Common Criteria for Information Technology Security Evaluation - Part 3: Security assurance components. (CCMB-2017-04-003)”.
- a solution proposed, for example to provide personal identification data with such a level of security, is to use external secure elements, for example a sovereign identity card with a biometric module and an NFC chip (in English Near Field Communication), and place this card on the back of the mobile terminal to carry out a transaction.
- external secure elements for example a sovereign identity card with a biometric module and an NFC chip (in English Near Field Communication), and place this card on the back of the mobile terminal to carry out a transaction.
- the invention relates to a data signing method implemented by a server and comprising steps of:
- the invention relates to a data signature server comprising:
- - a module for receiving a signature request for at least one piece of data sent by a terminal via a network
- a secure element configured to obtain a signature of said at least one piece of data using a private key associated with the terminal
- the invention relates to a method for providing signed data implemented by a terminal and comprising steps of:
- the invention relates to a terminal comprising:
- - a module for sending a signature request for at least one piece of data to a server via a network
- the invention also relates to a system for providing signed data comprising at least one terminal and at least one server as mentioned above.
- the invention proposes a solution in which data intended to be transmitted to a third party by a terminal as part of a transaction, are previously signed by a server with a secure element complying with the security level required for this transaction.
- this secure element is an HSM component (in English Hardware Security Module), namely an electronic module offering a security service consisting in particular of generating, storing and protecting cryptographic keys.
- This component can be a PCI (Peripheral Component Interconnect) plug-in electronic card on a computer or an external SCSI/IP (Small Computer System Interface/Internet Protocol) box for example.
- PCI Peripheral Component Interconnect
- SCSI/IP Small Computer System Interface/Internet Protocol
- the HSM component complies with the AVA.VAN5 security level for the protection of the user's signature keys.
- the signature obtained by this secure element is encrypted by an entanglement of several keys including at least one key for reauthentication of the terminal with the network.
- the re-authentication key used is the current key and the server does not specifically trigger re-authentication of the terminal to force regeneration of the key.
- the server forces reauthentication of the terminal to regenerate the reauthentication key just before calculating the signature.
- the server forces the reauthentication of the terminal to regenerate the reauthentication key after a relatively short delay, for example thirty seconds after sending the signature.
- the re-authentication key is obtained by a method of re-authentication of a SIM card of the terminal with the home mobile network and triggered by said server.
- This embodiment also makes it possible to ensure that only the user and the terminal coupled with this SIM card will be able to access the signed data to share it with the third party.
- the server triggers a reauthentication of the terminal with the network to regenerate the reauthentication key after sending the encrypted signature to the terminal, for example thirty seconds after this sending.
- this re-authentication method is an EAP-AKA (Extensible Authentication Protocol- Authentication and Key Agreement) type method.
- This embodiment is particularly advantageous because the EAP-AKA mechanism ensures that the re-authentication key (CK, IK) known in itself to those skilled in the art, then shared by the terminal and the server, has been regenerated substantially at the time of signing (just before or just after) and that it will only be valid for a short period.
- the server can even possibly re-trigger a new re-authentication of the terminal with the network, giving it a predetermined time to complete its transaction, for example one minute, so as to overwrite the re-authentication key used by the server to encrypt the signature and by the terminal to decrypt the signature.
- the signature comprises:
- This other encryption function for example, implements an RSA type mechanism (in English Rivest-Shamir-Adleman).
- timestamp data offers an additional level of security since it allows the third party to verify the time at which the signature it receives has been calculated by the server. If receipt of the signature by the third party is too late compared to this calculation time, he can then reject the transaction.
- This so-called anti-replay mechanism is known to those skilled in the art and can be achieved by several other techniques, such as for example replacing or supplementing this timestamp with a transaction serial number coupled or not to data. random.
- the transport key is calculated from a key calculated using a derivation function shared between the terminal and the server and a personal service code of a terminal user.
- This embodiment also makes it possible to ensure that only the user of the terminal will be able to access the signed data to share it with the third party.
- the transport key is calculated from a key calculated using a derivation function shared between the terminal and the server and a key from a security application. a secure electronic wallet of the terminal.
- the calculation and composition of the plurality of these different session keys makes it possible to ensure that these three elements are present at the user terminal and that the latter is able to reconstruct the transport key.
- This intertwining of factors of possession (SIM card, electronic wallet application) and knowledge (service code), combined with the lifespan of ephemeral elements (reauthentication key, timestamp data) makes it possible to drastically reduce the surface area of attack the proposed solution.
- This embodiment also makes it possible to ensure that only the user and the terminal who use this specific electronic wallet application will be able to access the signed data to share it with the third party.
- At least one of these keys can be replaced or supplemented by another key accessible either by the terminal or by the user of the terminal, as long as this new key, or a diversification of this key, is known to the server.
- the different stages of the data signing method or of the signed data supply method are determined by computer program instructions or are implemented by a silicon chip which comprises transistors adapted to constitute logic gates of non-programmable hardwired logic.
- the invention also relates to a computer program on an information medium, this program being capable of being implemented in a controller computer, this program comprising instructions adapted to the implementation of the steps of a data signing method or a method of providing signed data as described above.
- This program may use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable shape.
- the invention also relates to an information medium readable by a computer, and comprising instructions for a computer program as mentioned above.
- the information carrier can be any entity or device capable of storing the program.
- the medium may include a storage means, such as a ROM, a non-volatile memory of the flash type or even a magnetic recording means, for example a hard disk.
- the information carrier may be a transmissible medium such as an electrical or optical signal, which may be carried via an electrical or optical cable, by radio or by other means.
- the program according to the invention can in particular be downloaded onto an Internet-type network.
- the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in executing the method in question.
- One of the advantages of the invention is that the use of a server connected to the user's home mobile network allows said server to benefit from all the behavior analysis and anti-fraud services of said operators. mobile. Brief description of the designs:
- Figure 1 schematically represents a signed data supply system conforming to a particular embodiment of the invention
- Figure 2 illustrates an example of a schematic representation of a terminal conforming to a particular embodiment of the invention
- Figure 3 illustrates an example of a schematic representation of a server conforming to a particular embodiment of the invention
- Figure 4 illustrates an example of a user enrollment phase with a digital identity provider
- Figure 5 illustrates an example of an enrollment phase of an application of the terminal of the figure with the server of Figure 3;
- Figure 6 represents in flowchart form the main steps of a method of providing signed data and of a method of signing data conforming to a particular embodiment of the invention
- Figure 7 represents the hardware architecture of a terminal conforming to a particular embodiment of the invention.
- Figure 8 represents the hardware architecture of a server conforming to a particular embodiment of the invention.
- Figure 1 schematically represents a signed data supply system conforming to a particular embodiment of the invention.
- This system allows a user U to send, using their TRMu terminal, signed data to a 3RDP third party.
- This data is, for example, personal data provided by a digital identity provider FIN.
- the terminal TRMu is in this example a mobile terminal TRMu attached to a mobile network by a home network NET.
- Figure 2 schematically represents the terminal TRMu of a user U in one embodiment of the invention.
- Figure 3 schematically represents the SRV server in one embodiment of the invention.
- the user's TRMu terminal comprises a TCOM communication module on the mobile network and a SIMu SIM card, the user U being able to authenticate with the SIMu card using a PIN code (in English PIN code) as is known. , Personal Identification Number) PIN c u.
- PIN code in English PIN code
- PIN c u Personal Identification Number
- the SRV server includes a SCOM communication module and a secure element constituted here by an HSM component.
- the TRMu terminal includes a secure element SE.
- a secure element is a separate chip that contains a secure processor, tamper-proof storage, and runtime memory. This processor, different from the host processor of the TRMu terminal, allows signed transactions to be carried out.
- the TRMu terminal includes a secure electronic wallet application ID_ W associated with an application key Kw.
- This key Kw can for example be stored in a register of the ID_W application or in the secure element SE of the mobile terminal TRMu.
- the SRV server comprises a cryptographic module MCRY comprising a first encryption function chiffi and four key derivation functions fctA, fctB, fctc and fctr hereinafter called respectively first, second, third and fourth functions key derivation. These functions are shared with the ID_W application.
- the HSM component comprises a timestamping module MH, a hash function H and a second encryption function ch iffi.
- the hash function H and the second encryption function chiff2 are shared with the third party 3RDP.
- the method of providing signed data comprises a first enrollment phase, to enroll the user U with a digital entity provider FIN.
- This first enrollment phase is illustrated in Figure 4 in a particular embodiment of the invention.
- the digital entity provider FIN produces and provides (step RIO) to the user U, a pair consisting of a public key K PUB u and an associated private key K ⁇ u.
- This pair of keys can be used in asymmetric cryptography mechanisms known to those skilled in the art implementing, for example, RSA type and elliptic curve algorithms.
- this pair of keys is stored in the secure element SE of the terminal TRMu. Alternatively, it can be stored in a memory register of the ID_W application.
- the digital identity provider FIN provides the user (step R20) with data capable of being shared by the user with at least one 3RDP third party.
- these data are ATTu attributes linked to the identity of the user U, for example his name N, his first name PN, his date of birth DN and his address ADD and are recorded in application memory registers ID_W as shown in Figure 2.
- Figure 5 illustrates a second enrollment phase making it possible to enroll the ID_W application with the SRV server in a particular embodiment of the invention.
- the application ID_W provides (step R30) to the SRV server a profile Pu of the user U including the key application Kw, its private key K SEC u obtained from the digital identity provider FIN and a personal service code PIN s u.
- the SRV server upon receipt of the profile Pu of the user U the SRV server generates the key pair (private key K ⁇ u, public key private key K PUB u) within the HSM and returns the generated public key to the FIN digital identity provider and the ID_W application.
- the key pair of the user U then being stored encrypted locally at the SRV server, the SRV server knowing at any time to restore the key context and the profile Pu of the user U to process any future signature request from the user via their ID_W application.
- this personal service code PIN s u is different from the personal code PIN c u of the SIMu SIM card.
- the personal service code subsequently used during the secure data provision process is either this personal service code provided by the user or a service code derived from this personal service code.
- This personal service code represents a phase of conscious acceptance, via an active approach, by the user of the transaction carried out.
- this personal service code PIN s u can be stored, directly or in a diverse manner depending on the state of the art, in the secure element SE of the mobile terminal TRMu or directly in the associated memory to the ID_W application as shown in Figure 2.
- the SRV server stores the profile Pu of the user U in a database BD as illustrated in Figure 4.
- Figure 6 represents in flowchart form the main steps of the signed data supply process and the data signing process implemented when the user U wishes to share an ATTu attribute, for example his ADD address with a third party 3RDP.
- the user U uses an HMI interface of his application ID_W to select an ATTu attribute and a 3RDP third party to whom he wishes to provide this attribute.
- the ATTu attribute must be signed with the private key K SEC u allocated to the user U by the identity provider FIN and kept secret by the HSM component of the SRV server.
- the application ID_W of the user U sends an RS signature request to the SRV server to ask it to sign this ATTu attribute.
- the ATT attribute to be signed is not sent “in the clear” to the SRV server, but sent encrypted with a key specific to the HSM component and unknown to the SRV server.
- the SRV server then transfers this encrypted attribute to be signed to the HSM which can then find the plain value of the attribute.
- the SRV server downloads into the HSM component, the profile Pu of the user U stored in the database BD.
- This profile Pu includes in particular the private key K SEC u allocated to the user U by the identity provider.
- the SRV server asks the HSM component to sign the ATTu attribute of the user U with the private key K SEC u allocated to the user U.
- the HSM component determines a timestamp data Horo(t), of the current instant t, calculates, using the hash function H, a hash Hu of the concatenated set (ATTu attribute , timestamp Horo(t)) and encrypts this hash Hu with the private key K SEC u allocated to the user U using the second encryption function chifTi.
- the HSM component responds to the signature request (step E40) by sending back to the SRV server a SIG signature comprising the timestamp data Horo(t), the attribute ATTu and the result (Hu) * Hu hash encryption.
- the SRV server forces a re-authentication of the TRMu terminal of the user U at the level of the home mobile network NET.
- this forced re-authentication step E70 comprises the following steps E71 to E74.
- the SRV server sends to the mobile network NET a request from the EAP-AKA family, or one of its extensions, for reauthentication of the SIMu SIM card of the user U.
- EAP-AKA Authentication and Key Agreement
- UMTS and CDMA2000 3rd generation mobile telephone networks
- RFC 4187 multiple variants exist depending on the generation of the mobile network targeted and the capabilities of the terminals.
- EAP protocol family is a network communication protocol embedding multiple authentication methods, which can be used on point-to-point links (RFC 22841), wired networks and wireless networks (RFC 37482, RFC 52473) such as Wi-Fi networks.
- the home network NET sends, during a step E72, a challenge DF to the terminal TRMu to which the SIM card SIMu responds with a response RP (step E73) after having locally generated a key ⁇ CK, IK ⁇ known to those skilled in the art.
- re-authentication key CKIK either a key ⁇ CK, IK ⁇ OR one of its derivations or any secret element intrinsic to the EAP-AKA exchange and shared at least between which SIMu SIM card NET home network and potentially the TRMu terminal.
- the mobile network NET checks the response RP and if the SIMu SIM card is reauthenticated, it sends back to the SRV server a CROK response and the reauthentication key CKIK.
- a result of this E70 re-authentication procedure is to make available to the SRV server the CKIK re-authentication key available after the re-authentication procedure at the SIMu SIM card of the terminal.
- the SRV server calculates a derived key CKIK* from the re-authentication key CKIK using the first key derivation function fctA shared with the application ID_W of the TRMu terminal.
- the SRV server calculates a key KPIN derived from the personal service code PIN s u of the user U obtained during the enrollment phase (step R30) using the second key derivation function fctB shared with the ID_W application of the TRMu terminal.
- the SRV server calculates a key KAPP derived from the application key Kw obtained during the enrollment phase (step R30) using the third derivation function of fctc key shared with the TRMu terminal ID_W application.
- the SRV server calculates a transport key KT from:
- step E100 the KAPP key derived from the application key Kw in step E100; using the fourth key derivation function fctr shared with the TRMu terminal ID_W application.
- the SRV server calculates the transport key KT from:
- step E90 the key KPIN derived from the personal service code PIN s u in step E90; and using the fourth key derivation function fctr shared with the TRMu terminal ID_W application.
- the SRV server calculates the transport key KT from:
- the SRV server encrypts the SIG signature received from the HSM component in step E60 with the first encryption function encrypted using the transport key KT.
- the SRV server sends this encrypted signature SIG* to the ID_W application during a step E130 in response to the RS signature request received in step E20.
- the application ID_W uses the first encryption function chiffi to decrypt the encrypted signature SIG* received in step E130 using the transport key KT and obtains the signature SIG comprising the timestamp data horo(t), the ATTu attribute of the user and the result (Hu)* of the encryption of the hash H of this information with the private key K SEC u allocated to the user U.
- this decryption could be carried out by a decryption module of the TRMu terminal independent of the ID_W application.
- the application ID_W sends to the third party 3RDP a message M comprising the SIG signature and a complement C comprising the public key K PUB u allocated to the user U by the FIN identity provider.
- the SIG signature includes in this example the timestamp Horo(t), the attribute ATTu, a hash (Hu)* of this data encrypted with the private key K ⁇ u allocated to the user U by the provider
- the FIN identity is kept secret by the HSM component.
- the third party 3RDP is thus autonomous in verifying the SIG signature thanks to receiving the user's public key and its knowledge of the hash function H and the second encryption function chifTi.
- FIG. 7 represents the hardware architecture of a TRMu terminal conforming to a particular embodiment of the invention.
- This terminal includes:
- processing unit or processor 701, or CPU intended to load instructions into memory, to execute them, to perform operations
- the storage memory 703 is arranged to store a PGF software module for providing signed data which includes code instructions for implementing the steps of the method for providing signed data as described above.
- FIG. 8 represents the hardware architecture of an SRV server conforming to a particular embodiment of the invention.
- This server includes:
- processor 801 intended to load instructions into memory, to execute them, to perform operations
- the storage memory 803 is arranged to store a PGS signature software module which includes code instructions for implementing the steps of the signature process as described above.
- the signed data are attributes linked to the identity of the user.
- signed data can be a combination of attributes.
- the invention can be used to provide a cryptographic derivation of this attribute, for example using a zero-knowledge proof algorithm.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Signal Processing (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Finance (AREA)
- Bioethics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Storage Device Security (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR2300436A FR3145074A1 (fr) | 2023-01-17 | 2023-01-17 | Procédés de signature de données, de fourniture de données signées, terminal et serveur associés |
| PCT/EP2023/087477 WO2024153437A1 (fr) | 2023-01-17 | 2023-12-21 | Procédés de signature de données, de fourniture de données signées, terminal et serveur associés |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4652758A1 true EP4652758A1 (fr) | 2025-11-26 |
Family
ID=87280540
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23837661.0A Pending EP4652758A1 (fr) | 2023-01-17 | 2023-12-21 | Procédés de signature de données, de fourniture de données signées, terminal et serveur associés |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP4652758A1 (fr) |
| CN (1) | CN120500871A (fr) |
| FR (1) | FR3145074A1 (fr) |
| WO (1) | WO2024153437A1 (fr) |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102015208088A1 (de) * | 2015-04-30 | 2016-11-03 | Bundesdruckerei Gmbh | Verfahren zur Erzeugung einer elektronischen Signatur |
| KR101863953B1 (ko) * | 2016-06-16 | 2018-06-29 | 주식회사 티모넷 | 전자 서명 서비스 시스템 및 방법 |
| JP2021040278A (ja) * | 2019-09-05 | 2021-03-11 | ジーエムオーグローバルサイン ピーティーイー リミテッド | 鍵管理システム、署名装置、鍵管理方法及びプログラム |
-
2023
- 2023-01-17 FR FR2300436A patent/FR3145074A1/fr not_active Withdrawn
- 2023-12-21 WO PCT/EP2023/087477 patent/WO2024153437A1/fr not_active Ceased
- 2023-12-21 EP EP23837661.0A patent/EP4652758A1/fr active Pending
- 2023-12-21 CN CN202380090941.6A patent/CN120500871A/zh active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| CN120500871A (zh) | 2025-08-15 |
| WO2024153437A1 (fr) | 2024-07-25 |
| FR3145074A1 (fr) | 2024-07-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1427231B1 (fr) | Procédé d'établissement et de gestion d'un modèle de confiance entre une carte à puce et un terminal radio | |
| EP1022922B1 (fr) | Procédé d'authentification, avec établissement d'un canal sécurise, entre un abonné et un fournisseur de services accessible via un opérateur de télécommunications | |
| EP3446436B1 (fr) | Procédé d'obtention par un terminal mobile d'un jeton de sécurité | |
| WO2006021661A2 (fr) | Procede d'authentification securisee pour la mise en œuvre de services sur un reseau de transmission de donnees | |
| EP4268109B1 (fr) | Procédé et dispositif de contrôle de l'accès à un service utilisant une chaîne de blocs | |
| EP1400056B1 (fr) | Procede d'authentification cryptographique | |
| WO2015059389A1 (fr) | Procede d'execution d'une transaction entre un premier terminal et un deuxieme terminal | |
| WO2003107587A1 (fr) | Procede et dispositif d’interface pour echanger de maniere protegee des donnees de contenu en ligne | |
| EP3673633B1 (fr) | Procédé d'authentification d'un utilisateur auprès d'un serveur d'authentification | |
| FR3116133A1 (fr) | Procédé de délégation d’accès à une chaîne de blocs | |
| EP4652758A1 (fr) | Procédés de signature de données, de fourniture de données signées, terminal et serveur associés | |
| FR2975518A1 (fr) | Procede de securisation d'une architecture d'authentification, dispositifs materiels et logiciels correspondants | |
| EP1400090B1 (fr) | Procede et dispositif de securisation des communications dans un reseau informatique | |
| FR3028369A1 (fr) | Procede et systeme de gestion d'identites d'utilisateurs destine a etre mis en oeuvre lors d'une communication entre deux navigateurs web | |
| EP3729720A1 (fr) | Procédé cryptographique de signature de groupe | |
| FR3141021A1 (fr) | Procédé de mise en œuvre d’un service d’une chaîne de services et dispositif électronique associé | |
| WO2021074527A1 (fr) | Procede de gestion d'une base de donnees de cles publiques, procede d'authentification de cles publiques, et dispositifs serveur et client mettant en oeuvre ces procedes | |
| WO1998010563A2 (fr) | Instrument de securisation d'echanges de donnees | |
| EP3785403A1 (fr) | Procédé d'élaboration de données d'utilisation de relais utilisés au cours d'une communication entre deux appareils, de recherche desdites données, et appareils associés | |
| WO2025119852A1 (fr) | Procédé génération d'un jeton d'authentification d'un terminal utilisateur auprès d'un réseau cœur reposant sur l'utilisation d'une chaine de blocs et procédé d'authentification du terminal utilisateur correspondant | |
| FR3128089A1 (fr) | Procédé et dispositif de sélection d’une station de base | |
| WO2023062095A1 (fr) | Procédé et dispositif de transfert d'une communication d'une station de base à une autre | |
| FR3141020A1 (fr) | Procédé de mise en œuvre d’un service d’une chaîne de services et dispositif électronique associé | |
| FR3043232A1 (fr) | Procede de verification d'identite lors d'une virtualisation | |
| WO2021165625A1 (fr) | Procede de calcul d'une cle de session, procede de recuperation d'une telle cle de session |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20250721 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |