TH41409A - Pre-loaded IC cards and methods for certifying them. - Google Patents

Pre-loaded IC cards and methods for certifying them.

Info

Publication number
TH41409A
TH41409A TH9901001792A TH9901001792A TH41409A TH 41409 A TH41409 A TH 41409A TH 9901001792 A TH9901001792 A TH 9901001792A TH 9901001792 A TH9901001792 A TH 9901001792A TH 41409 A TH41409 A TH 41409A
Authority
TH
Thailand
Prior art keywords
card
security module
key
signature
random
Prior art date
Application number
TH9901001792A
Other languages
Thai (th)
Other versions
TH41409A3 (en
Inventor
แคมบอยส์ อีเตนเน่
Original Assignee
แลนดิส แอนด์ เจียร์ คอมมูนิเคชั่น เอสเออาร์แอล
Filing date
Publication date
Application filed by แลนดิส แอนด์ เจียร์ คอมมูนิเคชั่น เอสเออาร์แอล filed Critical แลนดิส แอนด์ เจียร์ คอมมูนิเคชั่น เอสเออาร์แอล
Publication of TH41409A publication Critical patent/TH41409A/en
Publication of TH41409A3 publication Critical patent/TH41409A3/en

Links

Abstract

DC60 (25/05/42) ระบบที่อย่างน้อยประกอบด้วย ตัวอ่านบัตร (1) ที่มีเทอร์มินอล (3) และมอดูลให้ ความปลอดภัย (4) ซึ่ง ยอมรับบัตรไอซีที่บันทึกข้อมูลล่วงหน้าที่พกพกได้ (2) ที่มีวงจร รวม (8) พร้อมด้วยตัวสอด (9) เพื่อป้องกันการใช้บัตรไอซี (2) โดยไม่ได้รับอนุญาต และเนื้อ ความตัวนับหน่วยมูลค่าเงิน สด (10) ซึ่งแทนมูลค่าเงินสด และถูกลดมูลค่าลงในระหว่างที่ มี รายการเปลี่ยนแปลงที่จุดจำหน่ายอิสระ บัตรไอซี (2) ให้ กำเนิดหมายเลขสุ่มบัตร โดยที่ มอดูลให้ความปลอดภัย (4) ให้ กำเนิดหมายเลขสุ่มมอดูลให้ความปลอดภัย บัตรไอซี (2) เข้า รหัสหมายเลขสุ่มมอดูลให้ความปลอดภัยเข้าไปในลายเซ็นบัตร และมอ ดูลให้ความปลอดภัย (4) ถอดรหัสลายเซ็นบัตรอีกครั้ง เพื่อตรวจพิสูจน์สภาพการรับรองของบัตรไอซี (2) มอดูลให้ ความปลอดภัย (4) สร้างลายเซ็นมอดูลให้ความปลอดภัยจากหมาย เลขสุ่มบัตรที่ถูกถอดรหัส โดยบัตรไอซี (2) เพื่อตรวจพิสูจน์ สภาพรับรองของมอดูลให้ความปลอดภัย (4) ถ้าหากการ รับรองซึ่ง กันและกันถูกต้อง ตัวสอด (9) จะอนุญาตให้มีรายการเปลี่ยน แปลงการจ่ายเงิน (รูปที่ 1) ระบบที่อย่างน้อยประกอบด้วย ตัวอ่านบัตร (1 ) ที่มีเทอร์มิแอล (3 และมอดูลให้ ความปลอดภัย (4) ซึ่ง ยอมรับบัตรไอซีที่บันทึกข้อมูลล่วงหน้าที่พกพกได้ (2) ที่วงจร รวม (8) พร้อมด้วยตัวสอด (9) เพื่อป้องกันการใช้บัตรไอซี (2) โดยไม่ได้รับอนุญาต และเนื้อ ความตัวนับหน่วยมูลค่าเงิน สด (10) ซึ่งแทนมูลค่าเงินสด และถูกลดมูลค่าลงในระหว่างที่ มี รายการเปลี่ยนแปลงที่จุดจำหน่ายอิสระ บัตรไอซี (2) ให้ กำเนิดหมายเลขสุ่มบัตร โดยที่ มอดูลให้ความปลอดภัย (4) ให้ กำเนิดหมายเลขสุ่มมอดูลให้ความปลอดภัย บัตรไอซี (2) เข้า รหัสหมายเลขสุ่มให้ความปลอดภัยเข้าไปในลายเซ็นบัตร และมอ ดูลให้ความปลอดภัย (4) ถอดรหัสลายเซ็นบัตรอีกครั้ง เพื่อตรวจพิสูจน์สภาพการรับรองของบัตรไอซี (2) มอดูลให้ ความปลอดภัย (4) สร้างลายเซ็นมอดูลให้ความปลอดภัยจากหมาย เลขสุ่มบัตรที่ถูกถอดรหัส โดยบัตรไอซี (2) เพื่อตรวจพิสูจน์ สภาพรับรองของมอดูลให้ความปลอดภัย (4) ถ้าหากการ รับรองซึ่ง กันและกันถูกต้อง ตัวสอด (9) จะอนุญาตให้มีรายการเปลี่ยน แปลงการจ่ายเงิน (รูปที่ 1)DC60 (25/05/42) A system that at least consists of a card reader (1) with terminals (3) and a security module (4) which accepts a portable pre-programmed IC card (2) with integrated circuits (8) and an insert (9) to prevent unauthorized use of the IC card (2) and a cash counter (10) which represents the cash value and is devalued during transaction changes at an independent point of sale. The IC card (2) generates a random card number, whereby the security module (4) generates a random security module number. The IC card (2) encrypts the random security module number into the card signature, and the security module (4) decodes the card signature to verify the validity of the IC card (2). The security module (4) creates a security module signature from the random card number decoded by the IC card (2) to verify the validity of the IC card (2). The validity of the security module (4) is confirmed if the mutual validity is correct. The insert (9) allows for a change of payment transaction (Figure 1). The system consists of at least a card reader (1) with a terminal (3) and a security module (4) which accepts a portable pre-programmed IC card (2) on the integrated circuit (8) with an insert (9) to prevent unauthorized use of the IC card (2) and a cash counter body (10) which represents the cash value and is devalued during a change of payment transaction at an independent point of sale. The IC card (2) generates a random card number, whereby the security module (4) generates a random security module number. The IC card (2) encrypts the random security number into the card signature, and the security module (4) decodes the card signature again to verify the validity of the IC card (2). The security module (4) generates a security module signature from the number. A random number is decoded by the IC card (2) to verify the validity of the security module (4). If the validity is correct, the interceptor (9) will allow the payment change transaction (Figure 1).

Claims (19)

1.ระบบที่อย่างน้อยประกอบด้วย ตัวอ่านบัตร (1)ที่มีเทอร์มิแอลอิเล็กทรอนิกส์ (3) และมอดูลให้ความปลอดภัยอย่าง น้อยที่สุดหนึ่งมอดูล (4) และบัตรไอซีที่บันทึกข้อมูลล่วง หน้า ที่สามารถพกพาได้ (2) ที่มีวงจรรวม (B) พร้อมด้วย ตัวล็อค (9) เพื่อป้องกันการใช้บัตร ไอซี (2) โดยไม่ได้รับ อนุญาต และส่วนหน่วยความจำแบบไม่ลบเลือน (20) เพื่อเก็บมูล ค่า บัตรไอซีที่มีอยู่ (10) พร้อมด้วยวิถีทางเพื่อลดมูลค่า บัตรไอซีที่มีอยู่ลงตามลำดับในระหว่างที่มี รายการเปลี่ยน แปลงที่จุดหน่วยอิสระ (56) ที่ต่อเข้ากับเทอร์มินอล (3) ของตัวอ่านบัตร, (1) และเทอร์มินอล 3 ดังกล่าวจัดให้มีช่อง สื่อสาร (5, 6, 7 ) อยู่ระหว่างบัตรไอซี (2) และ มอดูล ให้ความปลอดภัย (4) โดยมีลักษณะพิเศษอยู่ในลักษณะที่ว่า บัตรไอซี (2) มีวิถีทาง (9, 21, 28, 29) เพื่อให้กำเนิดหมาย เลขสุ่มบัตรและลายเซ็นบัตร และเสนอสิ่งดังกล่าวไปที่มอดูล ให้ความปลอดภัย (4) ซึ่งมอดูลให้ความปลอดภัย (4) ดังกล่าว มีวิถีทาง (11,12) เพื่อให้ กำเนิดหมายเลขสุ่มมอดูลให้ความ ปลอดภัย และสายเซ็นมอดูลให้ความปลอดภัย และเสนอสิ่ง ดัง กล่าวไปที่บัตรไอซี (2) ซึ่งบัตรไอซี (2) มีคีย์สร้างรหัส ลับ K และวิถีทาง (29) สำหรับ สร้างลายเซ็นบัตรโดยตั้งอยู่ ฐานอย่างน้อยที่สุดหมายเลขสุ่มมอดูลให้ความปลอดภัย และ สำหรับถอดถอดรหัสลายเซ็นมอดูลให้ความปลอดภัยเพื่อตรวจ พิสูจน์สภาพการรับรองของมอดูลให้ ความปลอดภัย (4) ซึ่งแอดูล ให้ความปลอดภัย (4) ดังกล่าว คีย์สร้างรหัสลับ K และวิถี ทาง (11) เพื่อสร้างลายเซ็นมอดูล ให้ความปลอดภัยจากอย่างน้อยที่สุดหมายเลขสุ่มบัตรและ เพื่อถอดรหัสลายเซ็นบัตรเพื่อตรวจพิสูจน์สภาพรับรองของบัตร ไอซี (2) ซึ่งวงจรรวม (8) ดังกล่าวอย่างน้อยประกอบด้วย ส่วนหน่วยความจำอเนกประสงค์ (16) ที่มีพื้นที่ (49) ที่ เก็บ อย่างน้อยที่สุดหมายเลขสุ่มและหมายเลขสุ่มมอดูลให้ความ ปลอดภัย และตัวล็อค (9) ซึ่ง สามารถอนุญาตให้มีรายการเปลี่ยนแปลงการจ่ายเงินเกิดขึ้นเมื่อการรับรองซึ่งกันและกันของ บัตรไอซี (2) และมอดูลให้ความปลอดภัย (4) ถูกต้อง1. A system that consists of at least one card reader (1) with electronic terminals (3) and at least one security module (4) and a portable pre-recorded IC card (2) with an integrated circuit (B) with a lock (9) to prevent unauthorized use of the IC card (2) and a non-volatile memory (20) to store the existing IC card value (10) with a means to decrement the existing IC card value sequentially during changes at an independent unit point (56) connected to terminal (3) of the card reader, (1) and such terminal 3 provides communication channels (5, 6, 7) between the IC card (2) and the security module (4) with the special characteristic that the IC card (2) has means (9, 21, 28, 29) to generate random card numbers and card signatures and offer them to the module. Security Module (4) contains the following paths (11,12) to generate a security module random number and a security module signature line and offers these to IC Card (2), which contains the K encryption key and paths (29) to generate the card signature based on at least the security module random number and to decrypt the security module signature to verify the validity of Security Module (4), which contains the K encryption key and paths (11) to generate the security module signature from at least the card random number and to decrypt the card signature to verify the validity of IC Card (2), which contains the following integrated circuit (8) and at least: The multipurpose memory (16) contains space (49) that stores at least a random number and a random number security module and lock (9) which can allow a change of payment entry to occur when the mutual authentication of the IC card (2) and the security module (4) is correct. 2. ระบบตามข้อถือสิทธิ 1 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า บัตรไอซี (2) และมอดูล ให้ความปลอดภัย (4) อย่างน้อยประกอบด้วย วงจรอัลกออลิทิม (29) และหน่วยที-ดีอีเอส (11) ตามลำดับ สำหรับปฏิบัติการแปลงที-ดีอีเอส ด้วยคีย์สร้างรหัสลับ K ที่ข้อมูลที่จะถูกแลก เปลี่ยนและตรวจพิสูจน์ซึ่งกันและกัน2. The system under claim 1 is characterized by the IC card (2) and the security module (4) containing at least one algorithm circuit (29) and a T-DES unit (11), respectively, for performing T-DES conversion operations with a K-key cryptographic key on which data is to be exchanged and verified. 3. ระบบตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 1 หรือ 2 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า มอดูลให้ความปลอดภัย (4) มีวิถีทางทดแทนคีย์รหัสลับที่ล้าสมัย K14 ของบัตรไอซี (2) ด้วยคีย์ สร้างรหัสลับใหม่ K คีย์ช่วย AK ถูกเก็บไว้ในยตำแหน่งหน่วยความจำ (BO) ของบัตไอซี (2) และคีย์ช่วย AK ดังกล่าว ถูกใช้อย่างอิสระเพื่อการถอดรหัสคีย์สร้างสรหัสลับใหม่ K บรรจุเข้า ไปในบัตรไอซี (2)3. A system under one of the claims of claim 1 or 2 is of a special nature in which the security module (4) has a means of replacing the obsolete cryptographic key K14 of the IC card (2) with a new cryptographic key K. An auxiliary key AK is stored in memory location (BO) of the IC card (2) and such auxiliary key AK is independently used to decrypt the new cryptographic key K embedded in the IC card (2). 4. บัตรไอซีที่บันทึกข้อมูลล่วงหน้า (2) พร้อมด้วยวงจรรวม (8) ที่มีตัวล็อค (9) เพื่อ ป้องกันการใช้บัตรไอซี (2) โดยไม่ได้รับอนุญาติ ส่วนหน่วยความจำแบบไม่ลบเลือน (17 ถึง 20) เพื่อเก็บอย่างน้อยที่สุด มูลค่าบัตรไอซีแท้จริง (10) ซึ่งจะถูกลดมูลค่าลงตามลำดับใน ระกว่างที่มีรายการเปลี่ยนแปลงการจ่ายเงิน และช่องสื่อสาร (5, 21) เพื่อเสนอข้อมูลไปยัง โลกภายนอก ส่วนหน่วยความจำที่โปรแกรมข้อมูลแบบไม่ลบเลือน (14, 15) พื้นที่ (80) ของ ส่วนหน่วยความจำอเนกประสงค์ (16) และวงจรตัวให้กำเนิดหมายเลขสุ่มบัตร (28) ที่ให้ กำเนิดหมายเลขสุ่มบัตร โดยมีลักษณะพิเศษอยู่ในลักษณะที่ว่า ส่วนหน่วยความจำอเนกประสงค์ ดังกล่าว (16) อย่างน้อยประกอบด้วย วิถีทางเก็บอย่างน้อยที่สุดหมายเลขสุ่มบัตรชั่วคราว ลายเซ็นบัตร หมายเลขสุ่มมอดูลให้ความปลอดภัย และลายเซ็นมอดูลให้ความปลอดภัย ส่วน หน่วยความจำข้อมูลแบบไม่ลบเลือนดังกล่าว (17, 18, 19, 20) อย่างน้อยประกอบด้วย วิถีทาง เก็บอย่างน้อยที่สุดหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) คีย์สร้างรหัสลับ K และมูลค่าบัตร ไอซีก่อนหน้า (10') ตัวล็อค (9) ดังกล่าวอย่างน้อยประกอบด้วย วิถีทางป้องกันการเข้าถึง บัตร ทั้งนี้ขึ้นอยู่กับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) และมันยังอย่างน้อยประกอบด้วย วิถีทางปรับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยในกรณีที่ความพยายามเขช้าถึงหมด อายุ หน่วยอัลกอลิทึม (29) ที่ใช้คีย์สร้างรหัสลับ K เพื่อเข้ารหัสลายเซ็นบัตรและเพื่อถอดรหัส ลายเซ็นมอดูลให้ความปลอดภัย และมีตัวเปรียบเทียบ (47) เพื่อตรวจพิสูจน์ลายเซ็นมอดูลให้ ความปลอดภัยที่ได้รับ4. Pre-programmed IC cards (2) with integrated circuits (8) with locking (9) to prevent unauthorized use of IC cards (2), non-volatile memory (17 to 20) to store at least the actual IC card value (10) which is depreciated sequentially during payment changes, and communication channels (5, 21) to provide information to the outside world, non-volatile programmed data memory (14, 15), area (80) of the general-purpose memory (16) and random number generator circuit (28) which generates random numbers, with the special characteristic that the general-purpose memory (16) contains at least a path to store at least temporary random numbers, card signatures, and security module random numbers. The security module's signature, and the non-volatile data memory (17, 18, 19, 20), contain at least a path to store at least the defective access number (48), the K cryptographic key, and the previous IC card value (10'). The lock (9) contains at least a path to prevent card access depending on the defective access number (48), and it also contains at least a path to update the defective access number (48) in case the access attempt expires. The algorithm (29) that uses the K cryptographic key to encrypt the card signature and to decrypt the security module's signature contains a comparator (47) to verify the acquired security module's signature. 5. บัตรไอซี (2) ตามข้อถือสิทธิ 4 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า ส่วนหน่วยความ จำข้อมูลแบบไม่ลบเลือน (20) อย่างน้อยประกอบด้วย ส่วนเข้าถึงซึ่งมีข้อบกพร่อง (86) ที่มี หมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) และพื้นที่อนุญาต (87) เป็นตัวชี้ของการเข้าถึงก่อน หน้าที่สิ้นสุดอย่างไม่ปกติ และวงจรรวม (8) ดังกล่าวถูกเตรียมขึ้นโดยมีวิถีทาง (9, 13) เพื่อ จัดให้มีพื้นที่อนุญาต (87) และเพื่อปรับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยใน กรณีที่พื้นที่อนุญาต (87) ชี้บอกการเข้าถึงไม่ปกติ5. The IC card (2) under claim 4 is of a special nature in which the nonvolatile data memory (20) contains at least a defective access area (86) with a defective access number (48) and an authorization area (87) that indicates an abnormally terminated prior access, and such integrated circuit (8) is provided with a means (9, 13) to provide the authorization area (87) and to update the defective access number (48) in the event that the authorization area (87) indicates an abnormal access. 6. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 4 หรือ 5 ที่มีลักษณะพิเศษอนู่ใน ลักษณะที่ว่า ส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือนอย่างน้อยประกอบด้วย พื้นที่ตัวนับสำรอง (74) ที่แบ่งตัวบันทึกตัวนับ (70) อย่างน้อยที่สุดสองตัวแต่ละตัวบันทึกอย่างน้อยประกอบด้วย มูลค่าตัวนับ (76) แทนมูลค่าบัตรไอซีแท้จริง (10) หรืออย่างน้อยที่สุดมูลค่าบัตรไอซีก่อนหน้า (10') และข้อมูลจัดการ (75,77) ที่ชี้บอกคำสั่งของรายการเปลี่ยนแปลงที่เก็บไว้ที่ตัวบันทึก ตัวนับ (70) และวิถีทางทั้งหลายดังกล่าวถูกจัดขึ้นเพื่อปรับข้อมูลจัดการ (75, 77) ของมูลค่า บัตรไอซีแท้จริง (10) ให้ทันสมัย และเพื่อใช้มูค่าบัตรไอซีก่อนหน้า (10') สำหรับรายการ เปลี่ยนแปลงการจ่ายเงิน ถ้าหากข้อมูลจัดการที่ปรับให้ทันสมัยและข้อมูลจัดการของมูลค่าบัตร ไอซีแท้จริง (10) ที่เก็บไว้ในตัวบันทึกตัวนับตามลำดับ (70) แตกต่างกัน6. IC Card (2) under one of the claims of claim 4 or 5 is of a special nature in which the non-volatile data memory area contains at least a reserve counter area (74) which divides at least two counter recorders (70), each recorder containing at least a counter value (76) in place of the actual IC Card value (10) or at least the previous IC Card value (10'), and management data (75,77) indicating the order of the change entry stored in the counter recorder (70), and such pathways are arranged to update the management data (75, 77) of the actual IC Card value (10) and to use the previous IC Card value (10') for the change entry. If the updated management data and the management data of the actual IC Card value (10) stored in the respective counter recorders (70) differ, 7. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 4 ถึง 6 ที่มีลักษณะพิเศษอยู่ใน ลักษณะที่ว่า เซลล์ทั้งหลายของส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (17 ถึง 20) ต่างถูก ครอบคลุมทางกายภาพโดยสิ่งหุ้มป้องกัน (27) และวงจรรวม (8) มีวิถีทาง (13) เพื่อลบ ข้อมูลไวงานที่เก็บเข้าไปในส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (17 ถึง 20) ถ้าหาก การชำรุดเสียหายใด ๆ แก่สิ่งหุ้มป้องกัน (27) ถูกตรวจพบ7. The IC card (2), according to one of the claims of claims 4 through 6, is characterized in that the cells of the non-volatile memory (17 through 20) are physically covered by a protective enclosure (27), and the integrated circuit (8) has a means (13) to erase the active data stored in the non-volatile memory (17 through 20) if any damage to the protective enclosure (27) is detected. 8. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 4 ถึง 7 ที่มีลักษณะพิเศษอยู่ใน ลักษณะที่ว่า ส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (19) จัดตำแหน่งหน่วยความจำสำหรับ คีย์ช่วย AK ที่ใช้เพื่อถอดรหัสคีย์สร้างรหัสลับใหม่ K และตัวควบคุม (13) สามารถทดแทนคีย์ ที่ล้าสมัย K14 ด้วยคีย์ใหม่8. The IC card (2), pursuant to one of the claims of claims 4 through 7, is of a special nature in which the non-volatile data memory (19) allocates memory for the auxiliary key AK used to decode the new cryptographic key K, and the controller (13) can replace the obsolete key K14 with a new key. 9. บัตรไอซี (2) ตามข้อถือสิทธิหนึ่งของข้อถือถือสิทธิ 4 ถึง 8 ที่มีลักษณะพิเศษอยุ่ใน ลักษณะที่ว่า ส่วนหน่วยความจำข้อมูลแบบไม่ลบเลือน (17) อย่างน้อยประกอบด้วย หมายเลข บัตรอิสระและหมายเลขบัตรอิสระดังฏล่าวเป็นพารามิเตอร์ในการคำณวนการสร้างรหัสลับ9. IC card (2) under one of the claims of claims 4 through 8 is of a special nature in which the non-volatile data memory (17) contains at least one independent card number and such independent card number is a parameter in the calculation of the encryption of the encryption. 10. วิธีการสำหรับการรับรองซึ่งกันและกันระหว่างบัตรไอซี (2) และมอดูลให้ความ ปลอดภัย (4) ที่อยู่ในตัวอ่านบัตร (1) มีเทอร์มินอล (3) สำหรับการแลกเปลี่ยนข้อมูลระหว่าง บัตรไอซี (2) และมอดูลให้ความปลอดภัย (4) ที่อย่างน้อยประกอบด้วยขั้นตอน - การให้กำเนิดหมายเลขสุ่มบัตรโดยบัตรไอซี (2) และการถ่ายโอนมันไปที่มอดูล ให้ความปลอดภัย (4) - การให้กำเนิดหมายเลขสุ่มมอดูลให้ความปลอดภัยโดยมอดูลให้ความปลอดภัย (4) และถ่ายโอนมันไปที่บัตรไอซี (2) - การคำนวณลายเซ็นบัตรโดยบัตรไอซีโดยใช้อย่างน้อยที่สุดคีย์สร้างรหัสลับ K และหมายเลขสุ่มมอดูลให้ความปลอดภัย โดยถ่ายโอนมันไปที่มอดูลให้ความปลอดภัย - การคำนวณลายเซ็นบัตรโดยมอดูลให้ความปลอดภัย และเปรียบเทียบมันไปที่ลายเซ็น บัตรที่ถ่ายโอน การหยุดกรรมวิธีถ้าหากลายเซ็นทั้งสองแตกต่างกัน - การคำนวณลายเซ็นมอดูลให้ความปลอดภัยโดยมอดูลให้ความปลอดภัย (4) โดย ใช้อย่างน้อยที่สุดคีย์สร้างรหัสลับ K หมายเลขสุ่มบัตรและลายเซ็นบัตรและถ่ายโอนมันไปที่บัตร ไอซี (2) - การคำนวณลายเซ็นมอดูลให้ความปลอดภัยโดยบัตรไอซี (2) โดยใช้อย่างน้อย ที่สุด คีย์สร้างรหัสลลับ K หมายเลขสุ่มบัตรและลายเซ็นบัตรและเปรียบเทียบมันไปที่ลายเซ็น มอดูลให้ความปลอดภัยที่ถ่ายโอน การหยุดกรรมวิธีถ้าหากลายเซ็นทั้งสองแตกต่างกัน10. The method for mutual authentication between IC card (2) and the security module (4) contained in the card reader (1) has a terminal (3) for exchanging data between IC card (2) and security module (4) that at least consists of the following steps: - generation of a random card number by IC card (2) and transfer of it to the security module (4); - generation of a random security module number by the security module (4) and transfer of it to IC card (2); - calculation of the card signature by the IC card using at least the K secret code generating key and the security module random number, transferring it to the security module; - calculation of the card signature by the security module and comparison of it to the transferred card signature. The process stops if the two signatures are different - The signature calculation module provides security by the security module (4) by using at least the key to generate a K secret code, a random card number and a card signature and transfer it to the IC card (2) - The signature calculation module provides security by the IC card (2) by using at least the key to generate a K secret code, a random card number and a card signature and compare it to the transferred signature module. The process stops if the two signatures are different. 11. วิธีการตามข้อถือสิทธิ 10 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า หมายเลขสุ่มบัตรถูก ถ่ายโอนมาจากบัตรไอซีพร้อมกับอย่างน้อยที่สุดหมายเลขลำดับเฉพาะของบัตรไอซี คีย์สร้างรหัส ลับ K ถูกกำหนดขึ้นโดยมอดูลให้ความปลอดภัย โดยใช้หมายเลขลำดับเฉพาะของบัตรไอซี11. The method under claim 10 is characterized by the fact that a random card number is transferred from the IC card along with at least the unique serial number of the IC card. The key generating the K code is determined by the security module using the unique serial number of the IC card. 12. วิธีการตามข้อถือสิทธิ 10 และ 11 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า อย่างน้อยยัง ปไระกอบด้วย ขั้นตอนการปรับหมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยในกรณีที่การ เปรียบเทียบไม่ประสบความสำเร็จ12. The method under claims 10 and 11 is of a special nature in that it includes at least a procedure for updating the defective access number (48) in the event that the comparison fails. 13. วิธีการตามข้อถือสิทธิ 12 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า ก่อนเริ่มต้นกรรมวิธี รับรองซึ่งกันและกัน บัตรไอซี (2) จะตรวจสอบเนื้อความของหมายเลขเข้าถึง ซึ่งมีข้อบกพร่อง (48) แทนหมายเลขของความพยายามเข้าถึงซึ่งหมดอายุและยับยั้งการเข้าถึงบัตรไอซี (2) ในกรณีที่หมายเลขเข้าถึงซึ่งมีข้อบกพร่อง (48) เป็นหมายเลขที่จำกัดตามที่กำหนดไว้ล่วงหน้า13. The special procedure under claim 12 is such that, prior to the commencement of the mutual authentication procedure, IC Card (2) will examine the contents of the defective access number (48) in place of the number of the expired access attempt and block access to IC Card (2) in the event that the defective access number (48) is a pre-defined restricted number. 14. วิธีการตามข้อถือสิทธิ 10 ถึง 13 มีลักษณะพิเศษอยู่ในลักษณะที่ว่า อย่างน้อย ประกอบด้วย ขั้นตอนการทำเครื่องหมายโดยบัตรไอซีที่พื้นที่อนุญาตในส่วนหน่วยความจำข้อมูล แบบไม่ลบเลือน เมื่อมีการถ่ายโอนลายเซ็นบัตรที่หนึ่ง และคงค่าพื้นที่อนุญาตหลังจากที่การเปรียบ เทียบลายเซ็นประสบความสำเร็จ14. The methods under claims 10 through 13 are characterized by the fact that, at a minimum, they consist of an IC card marking procedure in the authoritative area of the non-volatile data memory when the first card signature is transferred and retain the authoritative area value after successful signature comparison. 15. วิธีการตามข้อถือสิทธิ 14 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า การปรับพื้นที่อนุญาต ให้ทันสมัยอย่างหนึ่งประกอบด้วยขั้นตอน : การปฏิบัติ หลังจากทำการตรวจสอบบัตร (331) และก่อนให้กำเนิดหมายเลขสุ่ม บัตร การตรวจสอบบิด (881) ที่เก็บไว้ในพื้นที่อนุญาต (87) การปรับหมายเลขเข้าถึง ซึ่งมีข้อบกพร่อง (48) ให้ทันสมัยและการคงคำบิด (88) ของพื้นที่อนุญาต (87) ในกรณีพื้นที่อนุญาตชี้บวกส่วนที่ไม่สิ้นสุด การทำเครื่องหมายบิด (88) ในพื้นที่อนุญาต (87) เพื่อชี้บอกการเริ่มต้นของส่วน ดังกล่าว การคงคำบิด (88) ในพื้นที่อนุญาต (87) ในกรณีที่ส่วนสิ้นสุดประสบผลสำเร็จ15. The method under claim 14 is unique in that one of the procedures for updating the permit area consists of the following steps: performing the card verification (331) and prior to the generation of the random number card; verifying the bit (881) stored in the permit area (87); updating the defective access number (48); and maintaining the bit (88) of the permit area (87) in the event that the permit area points to an incomplete section; marking the bit (88) in the permit area (87) to indicate the beginning of such section; and maintaining the bit (88) in the permit area (87) in the event that the section ends successfully. 16. วิธีการตามข้อถือสิทธิ 15 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า การทำเครื่องหมาย และการคงคำบิด (88) ในพื้นที่อนุญาต (87) ถูกทำขึ้นโดยการผกผันบิดสัญญาณหลังจากทำสิ่ง อื่น16. The method under claim 15 is of a special nature in which the marking and retention of the twist (88) in the permitted area (87) is done by inverting the twist after doing the other. 17. วิธีการตามข้อถือสิทธิหนึ่งของข้อถือสิทธิ 10 ถึง 16 ที่มีลักษณะพิเศษอยู่ในลักษณะ ที่ว่า รายการเปลี่ยนแปลงการจ่ายเงิน อย่างน้อยประกอบด้วยขั้นตอน การคำนวณโดยมอดูลให้ความปลอดภัย (4) การสร้างรหัสลับโดยตั้งอยู่บนพื้นฐาน อย่างน้อยที่สุด การสร้างรหัสลับแลกเปลี่ยนก่อนหน้าและจำนวนที่จะลดลงโดยการถ่ายโอนมัน ไปที่บัตรไอซี (2) ด้วยจำนวนที่ลดลง การคำณวนโดยบัตรไอซี (2) การสร้างรหัสลับโดยตั้งอยู่บนพื้นฐานอย่างน้อยที่สุด การสร้างรหัสลับแลกเปลี่ยนก่อนหน้าและจำนวนที่จะลดลง โดยการเปรียบมันกับการสร้างรหัส ลับที่ได้รับและลดตัวนับภายในถ้าหากการสร้างรหัสลับทั้งสองเท่ากัน การคำนวณโดยบัตรไอซี (2) การสร้างรหัสลับโดยตั้งอยู่บนพื้นฐานอย่างน้อยที่สุด การสร้างรหัสแลกเปลี่ยนก่อนหน้า และมูลค่าบัตรไอซีที่มมีอยู่ โดยถ่ายโอนมันไปที่มอดูลให้ความ ปลอดภัย (4) การคำนวณโดยมอดูลให้ความปลอดภัย (4) การสร้างรหัสลับ โดยตั้งอยู่บนพื้นฐาน อย่างน้อยที่สุดการสร้างรหัสลับแลกเปลี่ยนก่อนหน้าและผลค่าบัตรไอซีที่มีอยู่ตามที่กำหนด โดย เปรียบเทียบมันกับการสร้างรหัสลับที่ได้รับ และสิ้นสุดรายการเปลี่ยนแปลงอย่างประสบความสำเร็จ และปรับมูลค่าบัตรไอซีให้ทันสมัย ถ้าหากการสร้างรหัสลับทั้งสองเท่ากัน17. The method under one of the claims of Claims 10 through 16 is characterized by the following: the change of payment entry shall at least consist of the following steps: Calculation by security module (4) creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the amount to be reduced by transferring it to IC card (2); with the amount to be reduced by IC card calculation (2); creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the amount to be reduced by comparing it to the received cryptographic code creation and reducing the internal counter if the two cryptographic code creations are equal; Calculation by IC card (2); creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the existing IC card value by transferring it to security module (4); Calculation by security module (4); creation of a cryptographic code based on at least the previous exchange cryptographic code creation and the existing IC card value as determined by comparing it to the received cryptographic code creation and successfully completing the change of payment entry and updating the IC card value if the two cryptographic code creations are equal. 18. วิธีการตามข้อถือสิทธิ 17 ที่มีลักษณะพิเศษอยู่ในลักษณะที่ว่า การปรับมูลค่าบัตรไอซี ให้ทันสมัยอย่างน้อยประกอบด้วยขั้นตอนต่อไปนี้ การให้ตำแหน่งที่อยู่ตัวบันทึกค่าตัวนับต่อไป แต่ละตัวบันทึกอย่างน้อยประกอบด้วย อย่างน้อยที่สุดค่าตัวนับ (76) แทนมูลค่าบัตรไอซีแท้จริง (10) หรือมูลค่าบัตรไอซีก่อนหน้า (10') และข้อมูลจัดการ (75,77) . การเก็บมูลค่าบัตรไอซีที่มีอยู่ในตัวบันทึกค่าตัวนับทีให้ตำแหน่งที่อยู่ การปรับให้ทันสมัยและการเก็บข้อมูลจัดการที่สอดคล้องของมันในตัวบันทึกค่าตัวนับ ที่ให้ตำแหน่งที่อยู่18. The method under claim 17 is of a special nature in which the updating of IC card values consists at least of the following steps: The The The The The The The The The The updating and The The updating of the IC card values in the The The updating and The The updating of the IC card values in the The The updating and The updating of the IC card values in the The updating and ... 19. วิธีการตามข้อถือสิทธิ 10 ถึง 18 ที่มีลักษณะอยู่ในลักษณะที่ว่า ในกรณีที่มอดูลให้ ความ)ลอดภัย (4) รู้จักว่า บัตรไอซี (2) ยังคงใช้คีย์สร้างรหัสลับล้าสมัย K14 ขั้นตอนต่อไป ของกรรมวิธีเปลี่ยนคีย์จะถูกปฏิบัติ ดังนี้ การส่งโดยมอดูลให้ความปลอดภัย (4) คีย์ใหม่ที่สร้างรหัสลับ K โดยใช้คีย์ช่วย AK ไปที่บัตรไอซี (2) และการสร้างรหัสลับการรับรอง (เอ็มเอซี) ซึ่งอย่างน้อยที่สุดตั้งอยู่ บนพื้นฐานคีย์ใหม่ K หรือคีย์ใหม่ที่เข้ารหัสลับ K และลายเซ็นบลัตรที่ถ่ายโอนก่อนหน้า การถอดรหัสโดยบัตรไอซี (2) คีย์ใหม่ที่เข้ารหัสลับ K โดยใช้คีย์ช่วย AK การคำนวณการสร้างรหัสลับรับรอง (เอ็มเอซี) ซึ่งอย่างน้อยที่สุดตังอยู่บนพื้นฐาน คีย์ใหม่ K หรือคีย์ใหม่ที่เข้ารหัส K และลายเซ็นบัตรที่ถ่ายโอนก่อนหน้า การเปรียบเทียบการสร้างรหัสลับรับรองที่ถ่ายโอนและคำนวณแล้ว และถ้าหาก ทั้งสองมีลักษณะเหมือนกัน การเปลี่ยนทดแทนคีย์เดิม K14 ด้วยคีย์ใหม่ K19. The procedure under claims 10 through 18 is such that if the security module (4) recognizes that the IC card (2) still uses the outdated K14 cryptographic key, the following steps of the key replacement procedure are performed: The security module (4) transmits the new K cryptographic key using the auxiliary key AK to the IC card (2), and generates the authentication key (MAC) which is at least based on the new K key or the new encrypted K key and the previously transferred card signature. The IC card (2) then decrypts the new K cryptographic key using the auxiliary key AK. The MAC construct is calculated which is at least based on the new K key or the new encrypted K key and the previously transferred card signature. The transferred and calculated MAC constructs are compared, and if they are identical, the original K14 key is replaced with the new K key.
TH9901001792A 1999-05-25 Pre-recorded IC cards and how to certify them. TH41409A3 (en)

Publications (2)

Publication Number Publication Date
TH41409A true TH41409A (en) 2000-11-24
TH41409A3 TH41409A3 (en) 2000-11-24

Family

ID=

Similar Documents

Publication Publication Date Title
US5068894A (en) Method of generating a unique number for a smart card and its use for the cooperation of the card with a host system
US10298403B2 (en) RFID secure authentication
RU2224288C2 (en) Intercept-protected memory device
US7469837B2 (en) Storage device
US6058477A (en) System and method for authentication, and device and method for authentication
JP3774260B2 (en) Memory card security system device and memory card thereof
US7080256B1 (en) Method for authenticating a chip card in a message transmission network
US20100250936A1 (en) Integrated circuit, encryption communication apparatus, encryption communication system, information processing method and encryption communication method
JP4598857B2 (en) IC card and access control method thereof
US20040255119A1 (en) Memory device and passcode generator
JP4651212B2 (en) Portable information storage medium and authentication method thereof
JP2003536304A (en) A method for securing a system mounted on an electronic chip, particularly a pre-initialization stage of a chip card, and a mounting system for implementing the method
JP2005529547A (en) Method and system for checking electronic signature and card with microcircuit used in the method
JP2001512873A (en) Data carrier authentication inspection method
US7788490B2 (en) Methods for authenticating an identity of an article in electrical communication with a verifier system
WO1999064996A1 (en) Preloaded ic-card and method for authenticating the same
US20190005495A1 (en) Method for verifying transactions in chip cards
JP2003528515A (en) Cryptographic communication method for protection against fraud
US6662151B1 (en) System for secured reading and processing of data on intelligent data carriers
CN101883357A (en) Method, device and system for mutual authentication between terminal and intelligent card
CN119232358B (en) Electronic lock device and encryption and authentication method thereof
KR20220086135A (en) Block chain-based power transaction operation system
WO2025260534A1 (en) Entity identity authentication method for quantum access control system
JP3792808B2 (en) Authentication method and authentication system
JP4659148B2 (en) How to protect electronic chips against fraud