Claims (19)
1.ระบบที่อย่างน้อยประกอบด้วย ตัวอ่านบัตร (1)ที่มีเทอร์มิแอลอิเล็กทรอนิกส์ (3) และมอดูลให้ความปลอดภัยอย่าง น้อยที่สุดหนึ่งมอดูล (4) และบัตรไอซีที่บันทึกข้อมูลล่วง หน้า ที่สามารถพกพาได้ (2) ที่มีวงจรรวม (B) พร้อมด้วย ตัวล็อค (9) เพื่อป้องกันการใช้บัตร ไอซี (2) โดยไม่ได้รับ อนุญาต และส่วนหน่วยความจำแบบไม่ลบเลือน (20) เพื่อเก็บมูล ค่า บัตรไอซีที่มีอยู่ (10) พร้อมด้วยวิถีทางเพื่อลดมูลค่า บัตรไอซีที่มีอยู่ลงตามลำดับในระหว่างที่มี รายการเปลี่ยน แปลงที่จุดหน่วยอิสระ (56) ที่ต่อเข้ากับเทอร์มินอล (3) ของตัวอ่านบัตร, (1) และเทอร์มินอล 3 ดังกล่าวจัดให้มีช่อง สื่อสาร (5, 6, 7 ) อยู่ระหว่างบัตรไอซี (2) และ มอดูล ให้ความปลอดภัย (4) โดยมีลักษณะพิเศษอยู่ในลักษณะที่ว่า บัตรไอซี (2) มีวิถีทาง (9, 21, 28, 29) เพื่อให้กำเนิดหมาย เลขสุ่มบัตรและลายเซ็นบัตร และเสนอสิ่งดังกล่าวไปที่มอดูล ให้ความปลอดภัย (4) ซึ่งมอดูลให้ความปลอดภัย (4) ดังกล่าว มีวิถีทาง (11,12) เพื่อให้ กำเนิดหมายเลขสุ่มมอดูลให้ความ ปลอดภัย และสายเซ็นมอดูลให้ความปลอดภัย และเสนอสิ่ง ดัง กล่าวไปที่บัตรไอซี (2) ซึ่งบัตรไอซี (2) มีคีย์สร้างรหัส ลับ K และวิถีทาง (29) สำหรับ สร้างลายเซ็นบัตรโดยตั้งอยู่ ฐานอย่างน้อยที่สุดหมายเลขสุ่มมอดูลให้ความปลอดภัย และ สำหรับถอดถอดรหัสลายเซ็นมอดูลให้ความปลอดภัยเพื่อตรวจ พิสูจน์สภาพการรับรองของมอดูลให้ ความปลอดภัย (4) ซึ่งแอดูล ให้ความปลอดภัย (4) ดังกล่าว คีย์สร้างรหัสลับ K และวิถี ทาง (11) เพื่อสร้างลายเซ็นมอดูล ให้ความปลอดภัยจากอย่างน้อยที่สุดหมายเลขสุ่มบัตรและ เพื่อถอดรหัสลายเซ็นบัตรเพื่อตรวจพิสูจน์สภาพรับรองของบัตร ไอซี (2) ซึ่งวงจรรวม (8) ดังกล่าวอย่างน้อยประกอบด้วย ส่วนหน่วยความจำอเนกประสงค์ (16) ที่มีพื้นที่ (49) ที่ เก็บ อย่างน้อยที่สุดหมายเลขสุ่มและหมายเลขสุ่มมอดูลให้ความ ปลอดภัย และตัวล็อค (9) ซึ่ง สามารถอนุญาตให้มีรายการเปลี่ยนแปลงการจ่ายเงินเกิดขึ้นเมื่อการรับรองซึ่งกันและกันของ บัตรไอซี (2) และมอดูลให้ความปลอดภัย (4) ถูกต้อง1. A system that consists of at least one card reader (1) with electronic terminals (3) and at least one security module (4) and a portable pre-recorded IC card (2) with an integrated circuit (B) with a lock (9) to prevent unauthorized use of the IC card (2) and a non-volatile memory (20) to store the existing IC card value (10) with a means to decrement the existing IC card value sequentially during changes at an independent unit point (56) connected to terminal (3) of the card reader, (1) and such terminal 3 provides communication channels (5, 6, 7) between the IC card (2) and the security module (4) with the special characteristic that the IC card (2) has means (9, 21, 28, 29) to generate random card numbers and card signatures and offer them to the module. Security Module (4) contains the following paths (11,12) to generate a security module random number and a security module signature line and offers these to IC Card (2), which contains the K encryption key and paths (29) to generate the card signature based on at least the security module random number and to decrypt the security module signature to verify the validity of Security Module (4), which contains the K encryption key and paths (11) to generate the security module signature from at least the card random number and to decrypt the card signature to verify the validity of IC Card (2), which contains the following integrated circuit (8) and at least: The multipurpose memory (16) contains space (49) that stores at least a random number and a random number security module and lock (9) which can allow a change of payment entry to occur when the mutual authentication of the IC card (2) and the security module (4) is correct.
2. ระบบตามข้อถือสิทธิ 1 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า บัตรไอซี (2) และมอดูล ให้ความปลอดภัย (4) อย่างน้อยประกอบด้วย วงจรอัลกออลิทิม (29) และหน่วยที-ดีอีเอส (11) ตามลำดับ สำหรับปฏิบัติการแปลงที-ดีอีเอส ด้วยคีย์สร้างรหัสลับ K ที่ข้อมูลที่จะถูกแลก เปลี่ยนและตรวจพิสูจน์ซึ่งกันและกัน2. The system under claim 1 is characterized by the IC card (2) and the security module (4) containing at least one algorithm circuit (29) and a T-DES unit (11), respectively, for performing T-DES conversion operations with a K-key cryptographic key on which data is to be exchanged and verified.
3. ระบบตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 1 หรือ 2 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า มอดูลให้ความปลอดภัย (4) มีวิถีทางทดแทนคีย์รหัสลับที่ล้าสมัย K14 ของบัตรไอซี (2) ด้วยคีย์ สร้างรหัสลับใหม่ K คีย์ช่วย AK ถูกเก็บไว้ในยตำแหน่งหน่วยความจำ (BO) ของบัตไอซี (2) และคีย์ช่วย AK ดังกล่าว ถูกใช้อย่างอิสระเพื่อการถอดรหัสคีย์สร้างสรหัสลับใหม่ K บรรจุเข้า ไปในบัตรไอซี (2)3. A system under one of the claims of claim 1 or 2 is of a special nature in which the security module (4) has a means of replacing the obsolete cryptographic key K14 of the IC card (2) with a new cryptographic key K. An auxiliary key AK is stored in memory location (BO) of the IC card (2) and such auxiliary key AK is independently used to decrypt the new cryptographic key K embedded in the IC card (2).
4. บัตรไอซีที่บันทึกข้อมูลล่วงหน้า (2) พร้อมด้วยวงจรรวม (8) ที่มีตัวล็อค (9) เพื่อ ป้องกันการใช้บัตรไอซี (2) โดยไม่ได้รับอนุญาติ ส่วนหน่วยความจำแบบไม่ลบเลือน (17 ถึง 20) เพื่อเก็บอย่างน้อยที่สุด มูลค่าบัตรไอซีแท้จริง (10) ซึ่งจะถูกลดมูลค่าลงตามลำดับใน ระกว่างที่มีรายการเปลี่ยนแปลงการจ่ายเงิน และช่องสื่อสาร (5, 21) เพื่อเสนอข้อมูลไปยัง โลกภายนอก ส่วนหน่วยความจำที่โปรแกรมข้อมูลแบบไม่ลบเลือน (14, 15) พื้นที่ (80) ของ ส่วนหน่วยความจำอเนกประสงค์ (16) และวงจรตัวให้กำเนิดหมายเลขสุ่มบัตร (28) ที่ให้ กำเนิดหมายเลขสุ่มบัตร โดยมีลักษณะพิเศษอยู่ในลักษณะที่ว่า ส่วนหน่วยความจำอเนกประสงค์ ดังกล่าว (16) อย่างน้อยประกอบด้วย วิถีทางเก็บอย่างน้อยที่สุดหมายเลขสุ่มบัตรชั่วคราว ลายเซ็นบัตร หมายเลขสุ่มมอดูลให้ความปลอดภัย และลายเซ็นมอดูลให้ความปลอดภัย ส่วน หน่วยความจำข้อมูลแบบไม่ลบเลือนดังกล่าว (17, 18, 19, 20) อย่างน้อยประกอบด้วย วิถีทาง เก็บอย่างน้อยที่สุดหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) คีย์สร้างรหัสลับ K และมูลค่าบัตร ไอซีก่อนหน้า (10') ตัวล็อค (9) ดังกล่าวอย่างน้อยประกอบด้วย วิถีทางป้องกันการเข้าถึง บัตร ทั้งนี้ขึ้นอยู่กับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) และมันยังอย่างน้อยประกอบด้วย วิถีทางปรับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยในกรณีที่ความพยายามเขช้าถึงหมด อายุ หน่วยอัลกอลิทึม (29) ที่ใช้คีย์สร้างรหัสลับ K เพื่อเข้ารหัสลายเซ็นบัตรและเพื่อถอดรหัส ลายเซ็นมอดูลให้ความปลอดภัย และมีตัวเปรียบเทียบ (47) เพื่อตรวจพิสูจน์ลายเซ็นมอดูลให้ ความปลอดภัยที่ได้รับ4. Pre-programmed IC cards (2) with integrated circuits (8) with locking (9) to prevent unauthorized use of IC cards (2), non-volatile memory (17 to 20) to store at least the actual IC card value (10) which is depreciated sequentially during payment changes, and communication channels (5, 21) to provide information to the outside world, non-volatile programmed data memory (14, 15), area (80) of the general-purpose memory (16) and random number generator circuit (28) which generates random numbers, with the special characteristic that the general-purpose memory (16) contains at least a path to store at least temporary random numbers, card signatures, and security module random numbers. The security module's signature, and the non-volatile data memory (17, 18, 19, 20), contain at least a path to store at least the defective access number (48), the K cryptographic key, and the previous IC card value (10'). The lock (9) contains at least a path to prevent card access depending on the defective access number (48), and it also contains at least a path to update the defective access number (48) in case the access attempt expires. The algorithm (29) that uses the K cryptographic key to encrypt the card signature and to decrypt the security module's signature contains a comparator (47) to verify the acquired security module's signature.
5. บัตรไอซี (2) ตามข้อถือสิทธิ 4 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า ส่วนหน่วยความ จำข้อมูลแบบไม่ลบเลือน (20) อย่างน้อยประกอบด้วย ส่วนเข้าถึงซึ่งมีข้อบกพร่อง (86) ที่มี หมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) และพื้นที่อนุญาต (87) เป็นตัวชี้ของการเข้าถึงก่อน หน้าที่สิ้นสุดอย่างไม่ปกติ และวงจรรวม (8) ดังกล่าวถูกเตรียมขึ้นโดยมีวิถีทาง (9, 13) เพื่อ จัดให้มีพื้นที่อนุญาต (87) และเพื่อปรับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยใน กรณีที่พื้นที่อนุญาต (87) ชี้บอกการเข้าถึงไม่ปกติ5. The IC card (2) under claim 4 is of a special nature in which the nonvolatile data memory (20) contains at least a defective access area (86) with a defective access number (48) and an authorization area (87) that indicates an abnormally terminated prior access, and such integrated circuit (8) is provided with a means (9, 13) to provide the authorization area (87) and to update the defective access number (48) in the event that the authorization area (87) indicates an abnormal access.
6. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 4 หรือ 5 ที่มีลักษณะพิเศษอนู่ใน ลักษณะที่ว่า ส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือนอย่างน้อยประกอบด้วย พื้นที่ตัวนับสำรอง (74) ที่แบ่งตัวบันทึกตัวนับ (70) อย่างน้อยที่สุดสองตัวแต่ละตัวบันทึกอย่างน้อยประกอบด้วย มูลค่าตัวนับ (76) แทนมูลค่าบัตรไอซีแท้จริง (10) หรืออย่างน้อยที่สุดมูลค่าบัตรไอซีก่อนหน้า (10') และข้อมูลจัดการ (75,77) ที่ชี้บอกคำสั่งของรายการเปลี่ยนแปลงที่เก็บไว้ที่ตัวบันทึก ตัวนับ (70) และวิถีทางทั้งหลายดังกล่าวถูกจัดขึ้นเพื่อปรับข้อมูลจัดการ (75, 77) ของมูลค่า บัตรไอซีแท้จริง (10) ให้ทันสมัย และเพื่อใช้มูค่าบัตรไอซีก่อนหน้า (10') สำหรับรายการ เปลี่ยนแปลงการจ่ายเงิน ถ้าหากข้อมูลจัดการที่ปรับให้ทันสมัยและข้อมูลจัดการของมูลค่าบัตร ไอซีแท้จริง (10) ที่เก็บไว้ในตัวบันทึกตัวนับตามลำดับ (70) แตกต่างกัน6. IC Card (2) under one of the claims of claim 4 or 5 is of a special nature in which the non-volatile data memory area contains at least a reserve counter area (74) which divides at least two counter recorders (70), each recorder containing at least a counter value (76) in place of the actual IC Card value (10) or at least the previous IC Card value (10'), and management data (75,77) indicating the order of the change entry stored in the counter recorder (70), and such pathways are arranged to update the management data (75, 77) of the actual IC Card value (10) and to use the previous IC Card value (10') for the change entry. If the updated management data and the management data of the actual IC Card value (10) stored in the respective counter recorders (70) differ,
7. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 4 ถึง 6 ที่มีลักษณะพิเศษอยู่ใน ลักษณะที่ว่า เซลล์ทั้งหลายของส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (17 ถึง 20) ต่างถูก ครอบคลุมทางกายภาพโดยสิ่งหุ้มป้องกัน (27) และวงจรรวม (8) มีวิถีทาง (13) เพื่อลบ ข้อมูลไวงานที่เก็บเข้าไปในส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (17 ถึง 20) ถ้าหาก การชำรุดเสียหายใด ๆ แก่สิ่งหุ้มป้องกัน (27) ถูกตรวจพบ7. The IC card (2), according to one of the claims of claims 4 through 6, is characterized in that the cells of the non-volatile memory (17 through 20) are physically covered by a protective enclosure (27), and the integrated circuit (8) has a means (13) to erase the active data stored in the non-volatile memory (17 through 20) if any damage to the protective enclosure (27) is detected.
8. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 4 ถึง 7 ที่มีลักษณะพิเศษอยู่ใน ลักษณะที่ว่า ส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (19) จัดตำแหน่งหน่วยความจำสำหรับ คีย์ช่วย AK ที่ใช้เพื่อถอดรหัสคีย์สร้างรหัสลับใหม่ K และตัวควบคุม (13) สามารถทดแทนคีย์ ที่ล้าสมัย K14 ด้วยคีย์ใหม่8. The IC card (2), pursuant to one of the claims of claims 4 through 7, is of a special nature in which the non-volatile data memory (19) allocates memory for the auxiliary key AK used to decode the new cryptographic key K, and the controller (13) can replace the obsolete key K14 with a new key.
9. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือถือสิทธิ 4 ถึง 8 ที่มีลักษณะพิเศษอยุ่ใน ลักษณะที่ว่า ส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (17) อย่างน้อยประกอบด้วย หมายเลข บัตรอิสระและหมายเลขบัตรอิสระดังฏล่าวเป็นพารามิเตอร์ในการคำณวนการสร้างรหัสลับ9. IC card (2) under one of the claims of claims 4 through 8 is of a special nature in which the non-volatile data memory (17) contains at least one independent card number and such independent card number is a parameter in the calculation of the encryption of the encryption.
10. วิธีการสำหรับการรับรองซึ่งกันและกันระหว่างบัตรไอซี (2) และมอดูลให้ความ ปลอดภัย (4) ที่อยู่ในตัวอ่านบัตร (1) มีเทอร์มินอล (3) สำหรับการแลกเปลี่ยนข้อมูลระหว่าง บัตรไอซี (2) และมอดูลให้ความปลอดภัย (4) ที่อย่างน้อยประกอบด้วยขั้นตอน - การให้กำเนิดหมายเลขสุ่มบัตรโดยบัตรไอซี (2) และการถ่ายโอนมันไปที่มอดูล ให้ความปลอดภัย (4) - การให้กำเนิดหมายเลขสุ่มมอดูลให้ความปลอดภัยโดยมอดูลให้ความปลอดภัย (4) และถ่ายโอนมันไปที่บัตรไอซี (2) - การคำนวณลายเซ็นบัตรโดยบัตรไอซีโดยใช้อย่างน้อยที่สุดคีย์สร้างรหัสลับ K และหมายเลขสุ่มมอดูลให้ความปลอดภัย โดยถ่ายโอนมันไปที่มอดูลให้ความปลอดภัย - การคำนวณลายเซ็นบัตรโดยมอดูลให้ความปลอดภัย และเปรียบเทียบมันไปที่ลายเซ็น บัตรที่ถ่ายโอน การหยุดกรรมวิธีถ้าหากลายเซ็นทั้งสองแตกต่างกัน - การคำนวณลายเซ็นมอดูลให้ความปลอดภัยโดยมอดูลให้ความปลอดภัย (4) โดย ใช้อย่างน้อยที่สุดคีย์สร้างรหัสลับ K หมายเลขสุ่มบัตรและลายเซ็นบัตรและถ่ายโอนมันไปที่บัตร ไอซี (2) - การคำนวณลายเซ็นมอดูลให้ความปลอดภัยโดยบัตรไอซี (2) โดยใช้อย่างน้อย ที่สุด คีย์สร้างรหัสลลับ K หมายเลขสุ่มบัตรและลายเซ็นบัตรและเปรียบเทียบมันไปที่ลายเซ็น มอดูลให้ความปลอดภัยที่ถ่ายโอน การหยุดกรรมวิธีถ้าหากลายเซ็นทั้งสองแตกต่างกัน10. The method for mutual authentication between IC card (2) and the security module (4) contained in the card reader (1) has a terminal (3) for exchanging data between IC card (2) and security module (4) that at least consists of the following steps: - generation of a random card number by IC card (2) and transfer of it to the security module (4); - generation of a random security module number by the security module (4) and transfer of it to IC card (2); - calculation of the card signature by the IC card using at least the K secret code generating key and the security module random number, transferring it to the security module; - calculation of the card signature by the security module and comparison of it to the transferred card signature. The process stops if the two signatures are different - The signature calculation module provides security by the security module (4) by using at least the key to generate a K secret code, a random card number and a card signature and transfer it to the IC card (2) - The signature calculation module provides security by the IC card (2) by using at least the key to generate a K secret code, a random card number and a card signature and compare it to the transferred signature module. The process stops if the two signatures are different.
11. วิธีการตามข้อถือสิทธิ 10 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า หมายเลขสุ่มบัตรถูก ถ่ายโอนมาจากบัตรไอซีพร้อมกับอย่างน้อยที่สุดหมายเลขลำดับเฉพาะของบัตรไอซี คีย์สร้างรหัส ลับ K ถูกกำหนดขึ้นโดยมอดูลให้ความปลอดภัย โดยใช้หมายเลขลำดับเฉพาะของบัตรไอซี11. The method under claim 10 is characterized by the fact that a random card number is transferred from the IC card along with at least the unique serial number of the IC card. The key generating the K code is determined by the security module using the unique serial number of the IC card.
12. วิธีการตามข้อถือสิทธิ 10 และ 11 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า อย่างน้อยยัง ปไระกอบด้วย ขั้นตอนการปรับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยในกรณีที่การ เปรียบเทียบไม่ประสบความสำเร็จ12. The method under claims 10 and 11 is of a special nature in that it includes at least a procedure for updating the defective access number (48) in the event that the comparison fails.
13. วิธีการตามข้อถือสิทธิ 12 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า ก่อนเริ่มต้นกรรมวิธี รับรองซึ่งกันและกัน บัตรไอซี (2) จะตรวจสอบเนื้อความของหมายเลขเข้าถึง ซึ่งมีข้อบกพร่อง (48) แทนหมายเลขของความพยายามเข้าถึงซึ่งหมดอายุและยับยั้งการเข้าถึงบัตรไอซี (2) ในกรณีที่หมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) เป็นหมายเลขที่จำกัดตามที่กำหนดไว้ล่วงหน้า13. The special procedure under claim 12 is such that, prior to the commencement of the mutual authentication procedure, IC Card (2) will examine the contents of the defective access number (48) in place of the number of the expired access attempt and block access to IC Card (2) in the event that the defective access number (48) is a pre-defined restricted number.
14. วิธีการตามข้อถือสิทธิ 10 ถึง 13 มีลักษณะพิเศษอยู่ในลักษณะที่ว่า อย่างน้อย ประกอบด้วย ขั้นตอนการทำเครื่องหมายโดยบัตรไอซีที่พื้นที่อนุญาตในส่วนหน่วยความจำข้อมูล แบบไม่ลบเลือน เมื่อมีการถ่ายโอนลายเซ็นบัตรที่หนึ่ง และคงค่าพื้นที่อนุญาตหลังจากที่การเปรียบ เทียบลายเซ็นประสบความสำเร็จ14. The methods under claims 10 through 13 are characterized by the fact that, at a minimum, they consist of an IC card marking procedure in the authoritative area of the non-volatile data memory when the first card signature is transferred and retain the authoritative area value after successful signature comparison.
15. วิธีการตามข้อถือสิทธิ 14 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า การปรับพื้นที่อนุญาต ให้ทันสมัยอย่างหนึ่งประกอบด้วยขั้นตอน : การปฏิบัติ หลังจากทำการตรวจสอบบัตร (331) และก่อนให้กำเนิดหมายเลขสุ่ม บัตร การตรวจสอบบิด (881) ที่เก็บไว้ในพื้นที่อนุญาต (87) การปรับหมายเลขเข้าถึง ซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยและการคงคำบิด (88) ของพื้นที่อนุญาต (87) ในกรณีพื้นที่อนุญาตชี้บวกส่วนที่ไม่สิ้นสุด การทำเครื่องหมายบิด (88) ในพื้นที่อนุญาต (87) เพื่อชี้บอกการเริ่มต้นของส่วน ดังกล่าว การคงคำบิด (88) ในพื้นที่อนุญาต (87) ในกรณีที่ส่วนสิ้นสุดประสบผลสำเร็จ15. The method under claim 14 is unique in that one of the procedures for updating the permit area consists of the following steps: performing the card verification (331) and prior to the generation of the random number card; verifying the bit (881) stored in the permit area (87); updating the defective access number (48); and maintaining the bit (88) of the permit area (87) in the event that the permit area points to an incomplete section; marking the bit (88) in the permit area (87) to indicate the beginning of such section; and maintaining the bit (88) in the permit area (87) in the event that the section ends successfully.
16. วิธีการตามข้อถือสิทธิ 15 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า การทำเครื่องหมาย และการคงคำบิด (88) ในพื้นที่อนุญาต (87) ถูกทำขึ้นโดยการผกผันบิดสัญญาณหลังจากทำสิ่ง อื่น16. The method under claim 15 is of a special nature in which the marking and retention of the twist (88) in the permitted area (87) is done by inverting the twist after doing the other.
17. วิธีการตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 10 ถึง 16 ที่มีลักษณะพิเศษอยู่ในลักษณะ ที่ว่า รายการเปลี่ยนแปลงการจ่ายเงิน อย่างน้อยประกอบด้วยขั้นตอน การคำนวณโดยมอดูลให้ความปลอดภัย (4) การสร้างรหัสลับโดยตั้งอยู่บนพื้นฐาน อย่างน้อยที่สุด การสร้างรหัสลับแลกเปลี่ยนก่อนหน้าและจำนวนที่จะลดลงโดยการถ่ายโอนมัน ไปที่บัตรไอซี (2) ด้วยจำนวนที่ลดลง การคำณวนโดยบัตรไอซี (2) การสร้างรหัสลับโดยตั้งอยู่บนพื้นฐานอย่างน้อยที่สุด การสร้างรหัสลับแลกเปลี่ยนก่อนหน้าและจำนวนที่จะลดลง โดยการเปรียบมันกับการสร้างรหัส ลับที่ได้รับและลดตัวนับภายในถ้าหากการสร้างรหัสลับทั้งสองเท่ากัน การคำนวณโดยบัตรไอซี (2) การสร้างรหัสลับโดยตั้งอยู่บนพื้นฐานอย่างน้อยที่สุด การสร้างรหัสแลกเปลี่ยนก่อนหน้า และมูลค่าบัตรไอซีที่มมีอยู่ โดยถ่ายโอนมันไปที่มอดูลให้ความ ปลอดภัย (4) การคำนวณโดยมอดูลให้ความปลอดภัย (4) การสร้างรหัสลับ โดยตั้งอยู่บนพื้นฐาน อย่างน้อยที่สุดการสร้างรหัสลับแลกเปลี่ยนก่อนหน้าและผลค่าบัตรไอซีที่มีอยู่ตามที่กำหนด โดย เปรียบเทียบมันกับการสร้างรหัสลับที่ได้รับ และสิ้นสุดรายการเปลี่ยนแปลงอย่างประสบความสำเร็จ และปรับมูลค่าบัตรไอซีให้ทันสมัย ถ้าหากการสร้างรหัสลับทั้งสองเท่ากัน17. The method under one of the claims of Claims 10 through 16 is characterized by the following: the change of payment entry shall at least consist of the following steps: Calculation by security module (4) creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the amount to be reduced by transferring it to IC card (2); with the amount to be reduced by IC card calculation (2); creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the amount to be reduced by comparing it to the received cryptographic code creation and reducing the internal counter if the two cryptographic code creations are equal; Calculation by IC card (2); creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the existing IC card value by transferring it to security module (4); Calculation by security module (4); creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the existing IC card value as determined by comparing it to the received cryptographic code creation and successfully completing the change of payment entry and updating the IC card value if the two cryptographic code creations are equal.
18. วิธีการตามข้อถือสิทธิ 17 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า การปรับมูลค่าบัตรไอซี ให้ทันสมัยอย่างน้อยประกอบด้วยขั้นตอนต่อไปนี้ การให้ตำแหน่งที่อยู่ตัวบันทึกค่าตัวนับต่อไป แต่ละตัวบันทึกอย่างน้อยประกอบด้วย อย่างน้อยที่สุดค่าตัวนับ (76) แทนมูลค่าบัตรไอซีแท้จริง (10) หรือมูลค่าบัตรไอซีก่อนหน้า (10') และข้อมูลจัดการ (75,77) . การเก็บมูลค่าบัตรไอซีที่มีอยู่ในตัวบันทึกค่าตัวนับทีให้ตำแหน่งที่อยู่ การปรับให้ทันสมัยและการเก็บข้อมูลจัดการที่สอดคล้องของมันในตัวบันทึกค่าตัวนับ ที่ให้ตำแหน่งที่อยู่18. The method under claim 17 is of a special nature in which the updating of IC card values consists at least of the following steps: The The The The The The The The The The updating and The The updating of the IC card values in the The The updating and The The updating of the IC card values in the The The updating and The updating of the IC card values in the The updating and ...
19. วิธีการตามข้อถือสิทธิ 10 ถึง 18 ที่มีลักษณะอยู่ในลักษณะที่ว่า ในกรณีที่มอดูลให้ ความ)ลอดภัย (4) รู้จักว่า บัตรไอซี (2) ยังคงใช้คีย์สร้างรหัสลับล้าสมัย K14 ขั้นตอนต่อไป ของกรรมวิธีเปลี่ยนคีย์จะถูกปฏิบัติ ดังนี้ การส่งโดยมอดูลให้ความปลอดภัย (4) คีย์ใหม่ที่สร้างรหัสลับ K โดยใช้คีย์ช่วย AK ไปที่บัตรไอซี (2) และการสร้างรหัสลับการรับรอง (เอ็มเอซี) ซึ่งอย่างน้อยที่สุดตั้งอยู่ บนพื้นฐานคีย์ใหม่ K หรือคีย์ใหม่ที่เข้ารหัสลับ K และลายเซ็นบลัตรที่ถ่ายโอนก่อนหน้า การถอดรหัสโดยบัตรไอซี (2) คีย์ใหม่ที่เข้ารหัสลับ K โดยใช้คีย์ช่วย AK การคำนวณการสร้างรหัสลับรับรอง (เอ็มเอซี) ซึ่งอย่างน้อยที่สุดตังอยู่บนพื้นฐาน คีย์ใหม่ K หรือคีย์ใหม่ที่เข้ารหัส K และลายเซ็นบัตรที่ถ่ายโอนก่อนหน้า การเปรียบเทียบการสร้างรหัสลับรับรองที่ถ่ายโอนและคำนวณแล้ว และถ้าหาก ทั้งสองมีลักษณะเหมือนกัน การเปลี่ยนทดแทนคีย์เดิม K14 ด้วยคีย์ใหม่ K19. The procedure under claims 10 through 18 is such that if the security module (4) recognizes that the IC card (2) still uses the outdated K14 cryptographic key, the following steps of the key replacement procedure are performed: The security module (4) transmits the new K cryptographic key using the auxiliary key AK to the IC card (2), and generates the authentication key (MAC) which is at least based on the new K key or the new encrypted K key and the previously transferred card signature. The IC card (2) then decrypts the new K cryptographic key using the auxiliary key AK. The MAC construct is calculated which is at least based on the new K key or the new encrypted K key and the previously transferred card signature. The transferred and calculated MAC constructs are compared, and if they are identical, the original K14 key is replaced with the new K key.