FR2740576A1 - Terminal connected by line to central computer to receive down-load programs - Google Patents
Terminal connected by line to central computer to receive down-load programs Download PDFInfo
- Publication number
- FR2740576A1 FR2740576A1 FR9512647A FR9512647A FR2740576A1 FR 2740576 A1 FR2740576 A1 FR 2740576A1 FR 9512647 A FR9512647 A FR 9512647A FR 9512647 A FR9512647 A FR 9512647A FR 2740576 A1 FR2740576 A1 FR 2740576A1
- Authority
- FR
- France
- Prior art keywords
- program
- memory
- terminal
- saved
- partitions
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F12/00—Accessing, addressing or allocating within memory systems or architectures
- G06F12/14—Protection against unauthorised use of memory or access to memory
- G06F12/1416—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights
- G06F12/1425—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights the protection being physical, e.g. cell, word, block
- G06F12/1441—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights the protection being physical, e.g. cell, word, block for a range
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
- G06F21/79—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/355—Personalisation of cards for use
- G06Q20/3552—Downloading or loading of personalisation data
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Business, Economics & Management (AREA)
- General Engineering & Computer Science (AREA)
- Microelectronics & Electronic Packaging (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Accounting & Taxation (AREA)
- Computer Networks & Wireless Communication (AREA)
- Software Systems (AREA)
- Stored Programmes (AREA)
Abstract
Description
SYSTÈME COMPRENANT UN TERMINAL RELIÉ
PAR UNE LIGNE DE TRANSMISSION À UNE UNITÉ
CENTRALE, ET TERMINAL POUVANT RECEVOIR DES
PROGRAMMES TÉLÉDÉCHARGÉS.SYSTEM INCLUDING A CONNECTED TERMINAL
BY A TRANSMISSION LINE TO A UNIT
CENTRAL, AND TERMINAL THAT CAN RECEIVE
DOWNLOADED PROGRAMS.
La présente invention concerne un système comprenant un terminal relié par une ligne de transmission à une unité centrale, le terminal pouvant recevoir des programmes télédéchargés. The present invention relates to a system comprising a terminal connected by a transmission line to a central unit, the terminal being able to receive downloaded programs.
Un tel système est en particulier mis en oeuvre pour des applications monétiques. Les terminaux sont dans ce cas constitués par des terminaux monétiques, par exemple des lecteurs de cartes de crédits ou des lecteurs de cartes bancaires. Les applicatifs chargés dans le terminal sont dans ce cas les programmes de gestion des protocoles de connexion au centre serveur et de traitement des informations monétiques. Such a system is in particular used for electronic payment applications. In this case, the terminals are constituted by electronic payment terminals, for example credit card readers or bank card readers. The applications loaded in the terminal are in this case the programs for managing the protocols for connection to the server center and for processing electronic payment information.
On connaît dans l'état de la technique des systèmes dans lesquels le terminal comporte une mémoire divisée en une mémoire programme et une mémoire de travail du type mémoire vive, la mémoire programme comportant elle-même une mémoire volatile, une mémoire sauvegardée du type EEPROM ou mémoire vive à piles et une mémoire résidente du type mémoire morte ou PROM. La mémoire sauvegardée est segmentée en une pluralité de partition de taille fixe ou variable. Chacune des partitions est destinée à recevoir un applicatif. De tels systèmes sont par exemple décrits dans le brevet français FR263s86g. Le terminal peut recevoir de nouveaux applicatifs tant que la totalité des partitions n est pas occupée. Systems known in the state of the art in which the terminal comprises a memory divided into a program memory and a working memory of the random access memory type, the program memory itself comprising a volatile memory, a saved memory of the EEPROM type or battery-powered random access memory and a resident memory of the ROM or PROM type. The saved memory is segmented into a plurality of partitions of fixed or variable size. Each of the partitions is intended to receive an application. Such systems are for example described in French patent FR263s86g. The terminal can receive new applications until all of the partitions are occupied.
Le problème est que le terminal peut ainsi recevoir des programmes "pirates" qui perturbent son fonctionnement, ou en tout cas interfère avec d'autres applicatifs précédemment télédéchargés par un centre serveur. The problem is that the terminal can thus receive "pirate" programs which disturb its operation, or in any case interfere with other applications previously downloaded by a server center.
Le but de l'invention est d'éviter cet inconvénient en sécurisant les modifications des programmes chargés dans la mémoire sauvegardée. A cet effet, l'invention concerne un système comprenant un terminai relié par une ligne de transmission à une unité centrale, le terminal comportant une mémoire programme sauvegardée fragmentée, par exemple une mémoire de type
EEPROM, RAM à piles, disque dur ou mémoire flash, et une mémoire résidente du type ROM ou PROM dans laquelle est enregistré un programme de télédéchargement et un programme interpréteur entre un programme écrit dans un langage compact évolué et universel et le langage propre au microprocesseur du terminal. Ce programme interpréteur peut accéder aux partitions de la mémoire sauvegardée.L'invention est caractérisé en ce qu'un programme-bouchon télédéchargeable dans l'une des partitions est propre à interdire le télédéchargement d'un programme supplémentaire dans une partition supplémentaire de la mémoire programme sauvegardée.The object of the invention is to avoid this drawback by securing the modifications to the programs loaded in the saved memory. To this end, the invention relates to a system comprising a terminal connected by a transmission line to a central unit, the terminal comprising a fragmented saved program memory, for example a memory of the type
EEPROM, battery-powered RAM, hard disk or flash memory, and a ROM or PROM resident memory in which a download program and an interpreter program are recorded between a program written in an advanced and universal compact language and the language specific to the microprocessor from the terminal. This interpreter program can access the partitions of the saved memory. The invention is characterized in that a downloadable plug-in program in one of the partitions is suitable for prohibiting the downloading of an additional program in an additional memory partition. program saved.
Le programme "bouchon" est un applicatif commandant les fonctionnalités du terminal au même titre que les autres applicatifs susceptibles d'être télédéchargés dans la mémoire partitionnée. Le programme "bouchon" est particulier en ce qu'il commande les fonctionnalités de gestion de la mémoire sauvegardée, de manière à inhiber, une fois qu'il est chargé dans une partition, l'accès aux autres partitions
Ce programme "bouchon" verrouille ainsi la modification du terminal. I1 ne peut être supprimé que par le centre serveur qui l'a télédéchargé dans les terminaux, par des moyens connus tels qu'un code d'accès ou un algorithme de cryptage.The "plug" program is an application controlling the functionality of the terminal in the same way as the other applications capable of being downloaded into the partitioned memory. The "plug" program is particular in that it controls the functions for managing the saved memory, so as to inhibit, once it is loaded into a partition, access to the other partitions
This "plug" program thus locks the modification of the terminal. I1 can only be deleted by the server center which downloaded it to the terminals, by known means such as an access code or an encryption algorithm.
De préférence, les programmes télédéchargeables dans la mémoire sauvegardé sont constitués par des applicatifs propres à commander les fonctionnalités du terminal et par un applicatif propre à inhiber l'accès aux partitions non occupées de la mémoire programme sauvegardée. Preferably, the programs downloadable from the saved memory are made up of applications capable of controlling the functionalities of the terminal and of an application capable of inhibiting access to the unoccupied partitions of the program memory saved.
Selon un mode de mise en oeuvre préféré, les programmes applicatifs télédéchargeables sont constitués par des logiciels bancaires propres à gérer un protocole de paiement électronique spécifique. According to a preferred embodiment, the downloadable application programs consist of banking software capable of managing a specific electronic payment protocol.
L'invention concerne également un procédé pour la formation d'un réseau de terminaux reliés à un centre serveur consistant à télédécharger dans une partition de la mémoire sauvegardée de chaque terminal un programme applicatif spécifique au réseau, caractérisé en ce que l'on télédécharge en outre dans une autre partition de la mémoire sauvegardée de chaque terminal un programme propre à inhiber le chargement de programmes dans les partitions non occupées. The invention also relates to a method for forming a network of terminals connected to a server center, consisting in downloading into a partition of the saved memory of each terminal an application program specific to the network, characterized in that one downloads in in addition to another partition of the saved memory of each terminal, a program capable of inhibiting the loading of programs into unoccupied partitions.
L'invention concerne encore un terminal comportant une mémoire programme sauvegardée fragmentée, par exemple une mémoire de type EEPROM, RAM à piles, disque dur ou mémoire flash, et une mémoire résidente du type ROM ou PROM dans laquelle est enregistrée un programme de télédéchargement et un programme interpréteur entre un programme écrit dans un langage compact évolué et universel et le langage propre au microprocesseur du terminal, ce programme interpréteur pouvant accéder aux partitions de la mémoire sauvegardée, caractérisé en ce qu'un programme-bouchon télédéchargeable dans l'une des partitions est propre à interdire le télédéchargement d'un programme supplémentaire dans une partition supplémentaire de la mémoire programme sauvegardée. The invention also relates to a terminal comprising a fragmented saved program memory, for example a memory of the EEPROM type, battery-powered RAM, hard disk or flash memory, and a resident memory of the ROM or PROM type in which a download program is stored and an interpreter program between a program written in an evolved and universal compact language and the language proper to the terminal microprocessor, this interpreter program being able to access the partitions of the saved memory, characterized in that a plug-in program downloadable in one of the partitions is designed to prohibit the downloading of an additional program to an additional partition of the saved program memory.
L'invention sera mieux comprise à la lecture de la description qui suit, faisant référence à un exemple de réalisation non limitatif. The invention will be better understood on reading the description which follows, referring to a nonlimiting exemplary embodiment.
la figure 1 représente le schéma de principe du système selon l'invention. Le système met en oeuvre un centre serveur (1) relié à un ou plusieurs terminaux (2) par une liaison telle qu'une ligne téléphonique, une ligne numérique RNIS, une ligne spécialisée ou encore une liaison hertzienne. Le terminal (2) comporte de manière connue une interface de communication, par exemple un modem dans le cas d'une liaison téléphonique ou une interface S/O dans le cas d'une liaison de type
RNIS et un microcalculateur apte à gérer les fonctionnalités du terminal, en application de programmes stockés dans un ensemble de mémoire (3).Figure 1 shows the block diagram of the system according to the invention. The system implements a server center (1) connected to one or more terminals (2) by a link such as a telephone line, an ISDN digital line, a dedicated line or even a radio link. The terminal (2) comprises in a known manner a communication interface, for example a modem in the case of a telephone link or an S / O interface in the case of a type of link.
ISDN and a microcomputer capable of managing the functionalities of the terminal, in application of programs stored in a memory assembly (3).
Cet ensemble de mémoire comprend une mémoire volatile (4) constituant la mémoire de travail, une mémoire résidente (4) du type mémoire morte ou PROM dans laquelle est stocké un programme de télédéchargement et un programme interpréteur entre un programme écrit dans un langage compact évolué et universel et le langage propre au microprocesseur du terminal. This memory assembly includes a volatile memory (4) constituting the working memory, a resident memory (4) of the read only memory or PROM type in which is stored a download program and an interpreter program between a program written in an advanced compact language. and universal and the language specific to the terminal microprocessor.
Le programme interpréteur peut accéder aux partitions d'une mémoire sauvegardée (6 à 11). Les partitions (6 à 11) peuvent être de taille fixe ou de taille variable, la taille des partitions pouvant alors être commandée par le calculateur du terminal (2). Dans chacune des partitions (6 à 11) peut être enregistré un programme de personnalisation du terminal (2) télédéchargé par le centre serveur (1). Ces programmes P1 à P4 sont par exemple des programmes de gestion du protocole d'échange avec le centre serveur (1) ou avec un réseau relié au terminal par une liaison téléphonique ou équivalente. The interpreter program can access the partitions of a saved memory (6 to 11). The partitions (6 to 11) can be of fixed size or of variable size, the size of the partitions can then be controlled by the computer of the terminal (2). In each of the partitions (6 to 11) can be saved a program for personalizing the terminal (2) downloaded by the server center (1). These programs P1 to P4 are for example programs for managing the exchange protocol with the server center (1) or with a network connected to the terminal by a telephone or equivalent link.
I1 peut en particulier s'agir de protocoles de paiement bancaire, permettant les échanges monétiques avec un réseau bancaire particulier. It can in particular be bank payment protocols, allowing electronic payment exchanges with a particular banking network.
L'un des programmes PB est un programme particulier enregistré dans l'une des partitions (10). One of the PB programs is a particular program stored in one of the partitions (10).
Ce programme PB a une fonction particulière d'inhiber l'accès aux partitions inoccupées, dans l'exemple décrit, la partition (11).This PB program has a particular function of inhibiting access to unoccupied partitions, in the example described, partition (11).
Ce programme PB modifie le fonctionnement de l'interpréteur pour empêcher le chargement dans les partitions restantes de programmes adressés par un centre serveur (1) quelconque. This PB program modifies the operation of the interpreter to prevent the loading in the remaining partitions of programs addressed by any host (1).
L'invention est décrite dans ce qui précède à titre d'exemple non limitatif. I1 est bien entendu que l'Homme de Métier sera à même de réaliser différentes variantes sans pour autant sortir du cadre de l'invention. The invention is described in the foregoing by way of nonlimiting example. It is understood that the person skilled in the art will be able to produce different variants without departing from the scope of the invention.
Claims (5)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
FR9512647A FR2740576B1 (en) | 1995-10-26 | 1995-10-26 | SYSTEM COMPRISING A TERMINAL CONNECTED BY A TRANSMISSION LINE TO A CENTRAL UNIT, AND TERMINAL WHICH CAN RECEIVE DOWNLOADED PROGRAMS |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
FR9512647A FR2740576B1 (en) | 1995-10-26 | 1995-10-26 | SYSTEM COMPRISING A TERMINAL CONNECTED BY A TRANSMISSION LINE TO A CENTRAL UNIT, AND TERMINAL WHICH CAN RECEIVE DOWNLOADED PROGRAMS |
Publications (2)
Publication Number | Publication Date |
---|---|
FR2740576A1 true FR2740576A1 (en) | 1997-04-30 |
FR2740576B1 FR2740576B1 (en) | 1998-01-23 |
Family
ID=9483948
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
FR9512647A Expired - Fee Related FR2740576B1 (en) | 1995-10-26 | 1995-10-26 | SYSTEM COMPRISING A TERMINAL CONNECTED BY A TRANSMISSION LINE TO A CENTRAL UNIT, AND TERMINAL WHICH CAN RECEIVE DOWNLOADED PROGRAMS |
Country Status (1)
Country | Link |
---|---|
FR (1) | FR2740576B1 (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP0950942A1 (en) * | 1998-04-15 | 1999-10-20 | Bull S.A. | Method of software distribution for a personal computer and apparatus for carrying out the method |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
GB2205667A (en) * | 1987-06-12 | 1988-12-14 | Ncr Co | Method of controlling the operation of security modules |
FR2638868A1 (en) * | 1988-11-09 | 1990-05-11 | Bull Cp8 | SECURE DOWNLOAD SYSTEM FOR A TERMINAL AND METHOD IMPLEMENTED |
EP0540095A1 (en) * | 1991-10-30 | 1993-05-05 | Philips Composants Et Semiconducteurs | Microcircuit for an IC-card with protected programmable memory |
US5287519A (en) * | 1992-09-17 | 1994-02-15 | International Business Machines Corp. | LAN station personal computer system with controlled data access for normal and unauthorized users and method |
-
1995
- 1995-10-26 FR FR9512647A patent/FR2740576B1/en not_active Expired - Fee Related
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
GB2205667A (en) * | 1987-06-12 | 1988-12-14 | Ncr Co | Method of controlling the operation of security modules |
FR2638868A1 (en) * | 1988-11-09 | 1990-05-11 | Bull Cp8 | SECURE DOWNLOAD SYSTEM FOR A TERMINAL AND METHOD IMPLEMENTED |
EP0540095A1 (en) * | 1991-10-30 | 1993-05-05 | Philips Composants Et Semiconducteurs | Microcircuit for an IC-card with protected programmable memory |
US5287519A (en) * | 1992-09-17 | 1994-02-15 | International Business Machines Corp. | LAN station personal computer system with controlled data access for normal and unauthorized users and method |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP0950942A1 (en) * | 1998-04-15 | 1999-10-20 | Bull S.A. | Method of software distribution for a personal computer and apparatus for carrying out the method |
FR2777674A1 (en) * | 1998-04-15 | 1999-10-22 | Bull Sa | SOFTWARE DISTRIBUTION METHOD FOR PERSONAL COMPUTER AND DEVICE FOR CARRYING OUT SAID METHOD |
Also Published As
Publication number | Publication date |
---|---|
FR2740576B1 (en) | 1998-01-23 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
EP0446081B1 (en) | Method for application programm loading in a memory card reader with microprocessor and system for carrying out this method | |
EP1253504B1 (en) | Procedure for use of software and information system for applying this procedure | |
EP1577782B1 (en) | Method and system of external data storage | |
EP0599366A1 (en) | Communication network | |
CA2309293A1 (en) | Method, card and terminals for carrying out transactions in a telecommunication network | |
EP0349413A1 (en) | Accounting system for portable data carriers | |
EP0681242B1 (en) | Secure access method for removable cards for computers | |
US5809241A (en) | System and method for processing long messages in a chip card | |
EP1221681B1 (en) | Application terminal | |
FR2803160A1 (en) | Digital television multiple access interface module having decoder processor inserted having identification/conditional access several areas using memory area. | |
EP0943134B1 (en) | System for managing the transfer of units of recorded value | |
WO2000075882A1 (en) | Preparing and executing a programme in a terminal supplementary chip card | |
FR2740576A1 (en) | Terminal connected by line to central computer to receive down-load programs | |
EP0368752A1 (en) | Protected remote loading system of a terminal, and method used | |
WO2003071400A2 (en) | Device and method for making secure sensitive data, in particular between two parties via a third party entity | |
US6941404B2 (en) | Data transfer device, transaction system and method for exchanging control and I/O data with a data processing system | |
EP2912640A1 (en) | Method for managing identifiers in an integrated circuit board and corresponding integrated circuit board | |
EP1451784B1 (en) | System for controlling access to a network and corresponding access control method | |
EP1713041A1 (en) | Payment system with bank card | |
FR2768004A1 (en) | METHOD AND INSTALLATION FOR DOWNLOADING A USER DECODER PLATFORM | |
EP1217590A1 (en) | Data transfer device, transaction system and method for exchanging control and I/O data with a data processing system | |
FR2786298A1 (en) | ELECTRONIC INFORMATION PROCESSING AND PAYMENT TERMINAL | |
EP1368793A2 (en) | Method for transferring data between service terminals and transactional means | |
EP1358640A1 (en) | Method for creating secure private data files and smart card comprising a secure private file | |
WO2005059847A1 (en) | Microcircuit multi-account card for restricting an account operation and corresponding communication method |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
ST | Notification of lapse |