WO2010043679A1 - Dispositif de communication securise - Google Patents

Dispositif de communication securise Download PDF

Info

Publication number
WO2010043679A1
WO2010043679A1 PCT/EP2009/063497 EP2009063497W WO2010043679A1 WO 2010043679 A1 WO2010043679 A1 WO 2010043679A1 EP 2009063497 W EP2009063497 W EP 2009063497W WO 2010043679 A1 WO2010043679 A1 WO 2010043679A1
Authority
WO
WIPO (PCT)
Prior art keywords
component
card component
chip card
information
partitioning
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/EP2009/063497
Other languages
English (en)
Inventor
Laurent Ryckelynck
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Safran Electronics and Defense SAS
Original Assignee
Sagem Defense Securite SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Sagem Defense Securite SA filed Critical Sagem Defense Securite SA
Priority to US13/124,499 priority Critical patent/US20120198231A1/en
Priority to GB1106146.2A priority patent/GB2476023B/en
Publication of WO2010043679A1 publication Critical patent/WO2010043679A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/77Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in smart cards
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/85Protecting input, output or interconnection devices interconnection devices, e.g. bus-connected or in-line devices
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06KGRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
    • G06K19/00Record carriers for use with machines and with at least a part designed to carry digital markings
    • G06K19/06Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
    • G06K19/067Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
    • G06K19/07Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
    • G06K19/073Special arrangements for circuits, e.g. for protecting identification code in memory
    • G06K19/07309Means for preventing undesired reading or writing from or onto record carriers
    • G06K19/07345Means for preventing undesired reading or writing from or onto record carriers by activating or deactivating at least a part of the circuit on the record carrier, e.g. ON/OFF switches

Definitions

  • the present invention relates to the design of a hardware component dedicated to the security of a communication apparatus such as, for example, a mobile phone.
  • the restricted portion of a device on which the security objectives assigned to that equipment in the security target is called a trusted core.
  • More and more devices provide access to secure services such as banking services or access to secure professional services. These devices must be secure and meet particularly strict standards in terms of security. To be used when accessing these services, these devices must be approved by an authority, they undergo a certification procedure. This certification procedure verifies that they meet a set of security criteria and can therefore be used to operate the secure service. Payment terminals and bank chip cards are examples of devices that are subject to these security certifications.
  • the heart of confidence is therefore the device implementing in the device the communication between a so-called red domain and a so-called black domain.
  • This device is a communication device between two zones of different security levels.
  • the red domain deals with intelligible and sensitive information protected by its environment, we also speak of red information.
  • the black domain represents the hostile environment that does not protect the information. In this area, information must be protected.
  • a trust architecture does not allow direct passages of information from the red domain to the black domain and vice versa.
  • Sensitive information is thus protected, in confidentiality and / or in integrity and / or in authenticity, by its passage through the heart of trust of which it is the role. Reciprocally, the protected information from the black domain is made intelligible and / or verified and / or authenticated after passing through the trusted heart.
  • the safety certification of the device amounts to certifying the heart of trust. If it complies with safety standards, certification of the rest of the device is not necessary.
  • Fig. 1 illustrates the architecture of a trusted heart according to the prior art.
  • the heart of confidence 1.1 is composed of a processor 1.2 which is responsible for executing the program of confidence.
  • This processor communicates with a dedicated component 1.3 responsible for cryptographic operations and input-output with the outside.
  • This component is typically made in the form of an ASIC (Application-Specific
  • This component 1.3 allows communication with the red domain 1.4 on the one hand and with the black domain 1.5 on the other hand.
  • a communication link 1.6 allows the injection into the cryptographic component of the keys necessary for its operation.
  • the invention proposes a core architecture of confidence more effective in terms of design and in terms of evaluation than the usual architectures. It's about combining two simple design and evaluation components to get a simply evaluable core of trust.
  • This trusted heart respects the principles of partitioning security recommendations, typically the partitioning between the red and black domains and the injection of keys.
  • the invention proposes to convert an existing single-interface component, namely an evaluated chip card component, into a multi-interface component that respects the principles of partitioning.
  • the component performing this interface conversion is designed on a minimal basis and if possible exclusively hardware that only realizes the safe routing of the flows.
  • the invention makes it possible to reduce the cost of design by a significant factor. Indeed, the base of the heart of confidence consisting of a chip card component exists and the complementary referral function is reduced to a minimum.
  • the innovation also makes it possible to reduce the cost of an evaluation by a significant factor, since the smart card component is already evaluated and the evaluation scheme is mastered.
  • the referral function by its minimalist design is also evaluable simply. The combination of designs and evaluations is then more efficient than the design and evaluation of a monolithic component.
  • the invention relates to a secure communication device between two zones of different security levels which comprises a chip card component which guarantees the confidentiality of the information and the implementation of cryptographic algorithms without leakage of information and a switching component alternately allowing the communication between the chip card component and each of the two zones of different security levels, as well as the introduction of cryptographic keys in the chip card component.
  • the switching component comprises three channels each having a switch such that when one of the switches is closed, the other two are necessarily open.
  • each of the channels further comprises a protocol adaptation module allowing the eventual Protocol conversion if needed between the external interface and the smart card component.
  • Fig. 1 illustrates the architecture of a trusted heart according to the prior art
  • Fig. 2 illustrates the architecture of a trusted heart according to the invention
  • Fig. 3 illustrates the architecture of an example of a smart card component used in the invention
  • Fig. 4 illustrates the architecture of an exemplary embodiment of the switching component.
  • Fig. 2 illustrates the architecture of a trusted heart according to the invention. It is architecture around a classic 2.2 smart card component. This component is a micro-controller resistant to physical aggression, protected against reverse engineering (reverse engineering), against the introduction of errors by particle beam. It guarantees the confidentiality of information and the implementation of cryptographic algorithms without leakage of information.
  • the smart card component already has the security objectives that you want to get from the trusted core.
  • a chip card component that is to say the physical component and the software that it embeds, provides a response to the usual objectives of information protection equipment: safe storage of secret elements, encryption decryption , access control to the resource, etc. This is a good example of an assessed perimeter security resource.
  • This switching component alternately allows the communication between the chip card component and each of the two zones of different security levels, as well as the introduction of cryptographic keys into the chip card component.
  • component 2.3 This is the role of component 2.3. It makes it possible to establish a secure and unidirectional path between the chip card component and either the red zone, the black zone or the keys. This component is designed so that at any given time only one of these paths can be active. The device is designed such that the path through which the keys are introduced into the smart card component is unique. It ensures that no leakage of information can take place both during the introduction and during the subsequent use of the trusted heart. The advantage of this design is that the smart card component is already certified. To certify the heart of confidence according to the invention, it will be sufficient to certify the switching component 2.3.
  • Fig. 3 illustrates the typical architecture of a chip card component 2.2 that can be used in the invention.
  • a processor 3.8 Connected to the communication bus 3.11, there is a processor 3.8. This processor is directly connected to a clock circuit 3.9 and to a reset control component (Reset Logic) 3.10, as well as to a safety circuit 3.1.
  • An input / output management module 3.7 allows communication with the outside and in this case with the switching component.
  • a module 3.6 allows the generation of random numbers used in crypto graphics algorithms.
  • a dedicated crypto graphing module 3.5 provides the cryptographic functions.
  • the memory is broken down into a first E2PROM module 3.4 which contains the data and the on-board software, a second Random Access Memory module 3.3 which contains the data and data. the program temporarily during its execution.
  • a third ROM module Read OnIy Memory in English
  • FLASH 3.2 which also contains embedded software dedicated smart card.
  • Fig. 4 illustrates the architecture of the switching component 2.3.
  • This component includes a link 4.1 for communicating with the smart card core.
  • This link allows communication with three input-output channels 4.2, 4.4 and 4.6 via three switch mechanisms to close or open each channel 4.3, 4.5 and 4.7.
  • Each of the channels is advantageously provided with an adaptation module 4.8, 4.9 and 4.10 allowing the possible protocol conversion if necessary between the external interface and the chip card component.
  • the links are bi-directional, typically serial-type interfaces that can be converted very simply into a protocol that is managed by a smart card component, the ISO 7816-3 protocol.
  • the component is designed so that when a switch is on, the others are necessarily open to ensure the desired partitioning. Any Data transmission can not take place between the different interfaces 4.2, 4.4 and 4.6 without passing through the chip card component which thus ensures the security of the device.
  • This turnout component is ultimately the only component requiring a security certification that remains simple because of the simplicity of design of this component.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • Microelectronics & Electronic Packaging (AREA)
  • Mathematical Physics (AREA)
  • Storage Device Security (AREA)

Abstract

L'invention propose une architecture de coeur de confiance plus efficace en terme de conception et en terme d'évaluation que les architectures habituelles. Ce coeur de confiance respecte les principes de cloisonnement des recommandations sécuritaires, typiquement le cloisonnement entre les domaines rouge, noir et l'injection des clés. Dans cette approche, l'invention propose de convertir un composant mono-interface existant, nommément un composant de carte à puce évalué, en un composant multi-interface qui respecte les principes de cloisonnement. Le composant réalisant cette conversion d'interface est conçu sur une base minimale et si possible exclusivement matérielle qui ne réalise que le routage sûr des flux.

Description

Dispositif de communication sécurisé
La présente invention concerne la conception d'un composant matériel dédié à la sécurité d'un appareil de communication tel que, par exemple, un téléphone mobile.
On appelle cœur de confiance la portion restreinte d'un équipement sur laquelle reposent les objectifs de sécurité assignés à cet équipement dans la cible de sécurité.
De plus en plus d'appareils permettent d'accéder à des services sécurisés comme, par exemple des services bancaires ou l'accès à des services professionnels sécurisé. Ces appareils doivent être sécurisés et répondre à des normes particulièrement strictes au niveau de la sécurité. Pour pouvoir être utilisés lors des accès à ces services, ces appareils doivent être agréés par une autorité, ils subissent pour ce faire une procédure de certification. Cette procédure de certification permet de vérifier qu'ils répondent bien à un ensemble de critères de sécurité et peuvent donc être utilisés pour faire fonctionner le service sécurisé. Les terminaux de paiement et les cartes à puces bancaires sont des exemples d'appareils soumis à ces certifications de sécurité.
Le cœur de confiance est donc le dispositif implémentant dans l'appareil la communication entre un domaine dit rouge et un domaine dit noir. Ce dispositif est un dispositif de communication entre deux zones de niveaux de sécurité différents. Par convention, le domaine rouge traite une information intelligible et sensible protégée par son environnement, on parle aussi d'information rouge. Le domaine noir représente l'environnement hostile qui ne protège pas l'information. Dans ce domaine, l'information doit être protégée. Une architecture de confiance ne permet pas de passages directs d'informations du domaine rouge vers le domaine noir et réciproquement.
L'information sensible est ainsi protégée, en confidentialité et/ou en intégrité et/ou en authenticité, par son passage au travers du cœur de confiance dont c'est le rôle. De manière réciproque, l'information protégée provenant du domaine noir est rendue intelligible et/ou vérifiée et/ou authentifiée après être passée par le cœur de confiance.
La certification de sécurité de l'appareil revient à certifier le cœur de confiance. Si celui-ci est conforme aux normes de sécurité, la certification du reste de l'appareil n'est pas nécessaire.
Les mécanismes mis en œuvre pour assurer ces fonctions de chiffrement déchiffrement, signature, vérification de signature, calcul d'intégrité et vérification d'intégrité mettent en œuvre des algorithmes cryptographiques.
La robustesse de la protection offerte par le cœur de confiance est obtenue d'une part par la complexité mathématique des algorithmes cryptographiques qu'il intègre, d'autre part par sa capacité à garder secrets les clés ou éléments secrets utilisés par ces algorithmes cryptographiques.
La Fig. 1 illustre l'architecture d'un cœur de confiance selon l'art antérieur. Le cœur de confiance 1.1 est composé d'un processeur 1.2 qui est chargé d'exécuter le programme de confiance. Ce processeur communique avec un composant dédié 1.3 chargé des opérations cryptographiques et des entrées-sorties avec l'extérieur. Ce composant est typiquement réalisé sous la forme d'un ASIC (Application-Specific
Integrated Circuit en anglais). Ce composant 1.3 permet la communication avec le domaine rouge 1.4 d'une part et avec le domaine noir 1.5 d'autre part. Un lien de communication 1.6 permet l'injection dans le composant cryptographique des clés nécessaires à son fonctionnement.
La certification d'un tel cœur de confiance nécessite la certification de toutes les fonctionnalités du cœur tant au niveau du processeur et des programmes qu'il embarque que du composant cryptographique. D'autre part, la conception d'un tel cœur de confiance est un processus long, complexe et coûteux.
L'invention propose une architecture de coeur de confiance plus efficace en terme de conception et en terme d'évaluation que les architectures habituelles. Il s'agit de combiner deux composants de conception et d'évaluation simple pour obtenir un coeur de confiance évaluable simplement. Ce cœur de confiance respecte les principes de cloisonnement des recommandations sécuritaires, typiquement le cloisonnement entre les domaines rouge, noir et l'injection des clés. Dans cette approche, l'invention propose de convertir un composant mono-interface existant, nommément un composant de carte à puce évalué, en un composant multi- interface qui respecte les principes de cloisonnement. Le composant réalisant cette conversion d'interface est conçu sur une base minimale et si possible exclusivement matérielle qui ne réalise que le routage sûr des flux.
L'invention permet de réduire d'un facteur important le coût de conception. En effet, la base du coeur de confiance constituée d'un composant de carte à puce existe et la fonction complémentaire d'aiguillage est réduite au minimum. L'innovation permet de manière induite de réduire aussi d'un facteur important le coût d'une évaluation, le composant de carte à puce étant déjà évalué et le schéma d'évaluation est maîtrisé. Par ailleurs, la fonction aiguillage par sa conception minimaliste est elle aussi évaluable simplement. La combinaison des conceptions et des évaluations est alors plus efficace que la conception et l'évaluation d'un composant monolithique.
L'invention concerne un dispositif de communication sécurisé entre deux zones de niveaux de sécurité différents qui comprend un composant de carte à puce qui garantit la confidentialité de l'information et la mise en œuvre d'algorithmes crypto graphiques sans fuite d'informations et un composant d'aiguillage permettant alternativement la communication entre le composant de carte à puce et chacune des deux zones de niveaux de sécurité différents, ainsi que l'introduction de clés crypto graphiques dans le composant de carte à puce.
Selon un mode particulier de réalisation de l'invention, le composant d'aiguillage comprend trois voies disposant chacune d'un interrupteur de telle sorte que lorsqu'un des interrupteurs est fermé, les deux autres sont nécessairement ouverts.
Selon un mode particulier de réalisation de l'invention, chacune des voies comprend en outre un module d'adaptation de protocole permettant l'éventuelle conversion de protocole si besoin entre l'interface extérieure et le composant de carte à puce.
Les caractéristiques de l'invention mentionnées ci-dessus, ainsi que d'autres, apparaîtront plus clairement à la lecture de la description suivante d'un exemple de réalisation, ladite description étant faite en relation avec les dessins joints, parmi lesquels :
La Fig. 1 illustre l'architecture d'un cœur de confiance selon l'art antérieur ;
La Fig. 2 illustre l'architecture d'un cœur de confiance selon l'invention ;
La Fig. 3 illustre l'architecture d'un exemple de composant de carte à puce utilisé dans l'invention ;
La Fig. 4 illustre l'architecture d'un exemple de réalisation du composant d'aiguillage.
La Fig. 2 illustre l'architecture d'un cœur de confiance selon l'invention. Il s 'architecture autour d'un composant classique de carte à puce 2.2. Ce composant est un micro contrôleur résistant aux agressions physiques, protégé contre la rétro conception (reverse engineering en anglais), contre l'introduction d'erreurs par faisceau de particules. Il garantit la confidentialité de l'information et la mise en œuvre d'algorithmes cryptographiques sans fuite d'informations. Le composant de carte à puce possède déjà les objectifs de sécurité que l'on désire obtenir du cœur de confiance. Un composant de carte à puce, c'est-à-dire le composant physique et le logiciel qu'il embarque, apporte une réponse aux objectifs habituels d'équipements de protection de l'information : conservation sûre d'éléments secrets, chiffrement déchiffrement, contrôle d'accès à la ressource, etc. C'est un bon exemple de ressource sécuritaire périphérique évaluée. Pour réaliser le cœur de confiance, il faut apporter à ce composant un composant d'aiguillage qui permet de réaliser les chemins de données vers la zone rouge, la zone noire et l'introduction des clés cryptographiques. Ce composant d'aiguillage permet alternativement la communication entre le composant de carte à puce et chacune des deux zones de niveaux de sécurité différents, ainsi que l'introduction de clés cryptographiques dans le composant de carte à puce.
C'est le rôle du composant 2.3. Il permet d'établir un chemin sécurisé et unidirectionnel entre le composant de carte à puce et soit la zone rouge, soit la zone noire ou les clés. Ce composant est conçu de manière à ce qu'à un instant donné un seul de ces chemins puisse être actif. Le dispositif est conçu de telle sorte que le chemin par lequel les clés sont introduites dans le composant de carte à puce soit unique. Il assure ainsi qu'aucune fuite d'informations ne puisse avoir lieu à la fois pendant l'introduction et pendant la suite de l'utilisation du cœur de confiance. L'avantage de cette conception est que le composant de carte à puce est déjà certifié. Pour certifier le cœur de confiance selon l'invention, il suffira donc de certifier le composant d'aiguillage 2.3.
La Fig. 3 illustre l'architecture typique d'un composant de carte à puce 2.2 pouvant être utilisé dans l'invention. Branché sur le bus de communication 3.11, on trouve un processeur 3.8. Ce processeur est directement connecté à un circuit d'horloge 3.9 et à un composant de gestion de la remise à zéro (Reset Logic en anglais) 3.10, ainsi qu'à un circuit de sécurité 3.1. Un module de gestion des entrées- sorties 3.7 permet la communication avec l'extérieur et en l'occurrence avec le composant d'aiguillage. Un module 3.6 permet la génération de nombres aléatoires utilisés dans les algorithmes crypto graphiques. Un module de calcul crypto graphique dédié 3.5 assure les fonctions cryptographiques. La mémoire se décompose en un premier module de mémoire E2PROM {Electrically Erasable Programmable Read- OnIy Memory en anglais) 3.4 qui contient les données et le logiciel embarqué, un second module de RAM (Random Access Memory en anglais) 3.3 qui contient les données et le programme de manière temporaire pendant son exécution. Un troisième module de mémoire ROM (Read OnIy Memory en anglais) ou FLASH 3.2 qui contient également des logiciels embarqués dédiés carte à puce.
La Fig. 4 illustre l'architecture du composant d'aiguillage 2.3. Ce composant comprend un lien 4.1 servant à communiquer avec le cœur de carte à puce. Ce lien permet la communication avec trois voies d'entrées-sorties 4.2, 4.4 et 4.6 via trois mécanismes d'interrupteurs permettant de fermer ou d'ouvrir chaque voie 4.3, 4.5 et 4.7. Chacune des voies est avantageusement pourvue d'un module d'adaptation 4.8, 4.9 et 4.10 permettant l'éventuelle conversion de protocole si besoin entre l'interface extérieure et le composant de carte à puce. Les liens sont bidirectionnels, il s'agit typiquement d'interfaces de type série capables d'être converties de manière très simple dans un protocole géré par un composant de carte à puce, le protocole ISO 7816-3.
Le composant est conçu de telle sorte que, quand un interrupteur est passant, les autres sont nécessairement ouverts pour assurer le cloisonnement recherché. Aucune transmission de données ne peut avoir lieu entre les différentes interfaces 4.2, 4.4 et 4.6 sans transiter par le composant de carte à puce qui assure donc la sécurité du dispositif. Ce composant d'aiguillage est au final le seul composant nécessitant une certification de sécurité qui reste simple du fait de la simplicité de conception de ce composant.

Claims

REVENDICATIONS
1/ Dispositif de communication sécurisé entre deux zones de niveaux de sécurité différents caractérisé en ce qu'il comprend :
- une ressource sécuritaire périphérique évaluée, telle qu'un composant de carte à puce, qui garantit la confidentialité de l'information et la mise en œuvre d'algorithmes cryptographiques sans fuite d'informations ;
- un composant d'aiguillage permettant alternativement la communication entre le composant de carte à puce, chacune des deux zones de niveau de sécurité différent et le chemin permettant l'introduction de clés crypto graphiques dans le composant de carte à puce.
2/ Dispositif selon la revendication 1, caractérisé en ce que le composant d'aiguillage comprend trois voies disposant chacune d'un interrupteur de telle sorte que lorsqu'un des interrupteurs est fermé, les deux autres sont nécessairement ouverts.
3/ Dispositif selon la revendication 2, caractérisé en ce que chacune des voies comprend en outre un module d'adaptation de protocole permettant l'éventuelle conversion de protocole si besoin entre l'interface extérieure et le composant de carte à puce.
PCT/EP2009/063497 2008-10-15 2009-10-15 Dispositif de communication securise Ceased WO2010043679A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US13/124,499 US20120198231A1 (en) 2008-10-15 2009-10-15 Secure communication device
GB1106146.2A GB2476023B (en) 2008-10-15 2009-10-15 Secure communication device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR0856988 2008-10-15
FR0856988A FR2937212B1 (fr) 2008-10-15 2008-10-15 Dispositif de communication securise.

Publications (1)

Publication Number Publication Date
WO2010043679A1 true WO2010043679A1 (fr) 2010-04-22

Family

ID=40792604

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2009/063497 Ceased WO2010043679A1 (fr) 2008-10-15 2009-10-15 Dispositif de communication securise

Country Status (4)

Country Link
US (1) US20120198231A1 (fr)
FR (1) FR2937212B1 (fr)
GB (1) GB2476023B (fr)
WO (1) WO2010043679A1 (fr)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1258831A2 (fr) * 2001-05-17 2002-11-20 Matsushita Electric Industrial Co., Ltd. Carte à puce avec une interface à contacts et une interface sans contacts
EP1313063A2 (fr) * 2001-10-24 2003-05-21 Kabushiki Kaisha Toshiba Carte à puce combinée avec/sans contact

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5321394A (en) * 1992-04-10 1994-06-14 Alcatel Network Systems, Inc. Spare card connection circuitry for high-speed telecommunications transmitters/receivers and methods
AUPO799197A0 (en) * 1997-07-15 1997-08-07 Silverbrook Research Pty Ltd Image processing method and apparatus (ART01)

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1258831A2 (fr) * 2001-05-17 2002-11-20 Matsushita Electric Industrial Co., Ltd. Carte à puce avec une interface à contacts et une interface sans contacts
EP1313063A2 (fr) * 2001-10-24 2003-05-21 Kabushiki Kaisha Toshiba Carte à puce combinée avec/sans contact

Also Published As

Publication number Publication date
GB2476023A (en) 2011-06-08
US20120198231A1 (en) 2012-08-02
GB201106146D0 (en) 2011-05-25
FR2937212A1 (fr) 2010-04-16
GB2476023B (en) 2013-05-15
FR2937212B1 (fr) 2011-05-20

Similar Documents

Publication Publication Date Title
EP3446436B1 (fr) Procédé d'obtention par un terminal mobile d'un jeton de sécurité
WO2006111626A2 (fr) Procédé et dispositif d'acces a une carte sim logée dans un terminal mobile
FR2971599A1 (fr) Procede de transaction securisee a partir d'un terminal non securise
WO2010084107A1 (fr) Circuit de cryptographie, protégé notamment contre les attaques par observation de fuites d'information par leur chiffrement
WO2016079403A1 (fr) Procédé de sécurisation d'un jeton de paiement.
JP2014522180A (ja) 識別キー漏れを防止するicチップ及びこの認証方法
CA2888662A1 (fr) Systeme et procede de securisation des echanges de donnees, objet portable utilisateur et dispositif distant de telechargement de donnees
Riebe et al. US security policy: The dual-use regulation of cryptography and its effects on surveillance
FR3106909A1 (fr) Circuit intégré configuré pour réaliser des opérations de chiffrement symétrique avec protection de clé secrète
EP3667530B1 (fr) Accès sécurise à des données chiffrées d'un terminal utilisateur
Alliance Host card emulation (hce) 101
Margraf et al. Security evaluation of apple pay at point-of-sale terminals
WO2012031848A1 (fr) Procede simplifie de personnalisation de carte a puce et dispositif associe
WO2010043679A1 (fr) Dispositif de communication securise
Armando et al. Trusted host-based card emulation
EP2813962B1 (fr) Méthode de contrôle d'accès à un type de services spécifique et dispositif d'authentification pour le contrôle de l'accès à un tel type de services.
EP3994596B1 (fr) Architecture informatique en nuage securisee et procede de securisation
US20190305945A1 (en) Method for implementing a cryptographic function for a secret key
da Fonte Host card emulation with tokenisation: Security risk assessments
CH716294A2 (fr) Procédé de signature décentralisée, sous contrôle biométrique et sous conditions d'identification personnelle et de géolocalisation, d'une transaction destinée à une blockchain.
Ramachandran Shielding the digital vault: Harnessing tokenization to safeguard financial transactions
CH716293A2 (fr) Procédé de signature décentralisée, sous contrôle biométrique et sous condition d'identification personnelle, d'une transaction destinée à une blockchain.
Ahonen et al. Information security threats and solutions in the mobile world
Mancini Using Smart Cards to Enhance Security of Android Smartphones in Tactical Scenarios
Orucho et al. Assessing Operation of Mobile Banking Applications that Support Customers to Access Banking Services Remotely

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09744111

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 1106146

Country of ref document: GB

Kind code of ref document: A

Free format text: PCT FILING DATE = 20091015

WWE Wipo information: entry into national phase

Ref document number: 1106146.2

Country of ref document: GB

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 13124499

Country of ref document: US

122 Ep: pct application non-entry in european phase

Ref document number: 09744111

Country of ref document: EP

Kind code of ref document: A1