WO2010043679A1 - Dispositif de communication securise - Google Patents
Dispositif de communication securise Download PDFInfo
- Publication number
- WO2010043679A1 WO2010043679A1 PCT/EP2009/063497 EP2009063497W WO2010043679A1 WO 2010043679 A1 WO2010043679 A1 WO 2010043679A1 EP 2009063497 W EP2009063497 W EP 2009063497W WO 2010043679 A1 WO2010043679 A1 WO 2010043679A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- component
- card component
- chip card
- information
- partitioning
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/77—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in smart cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/82—Protecting input, output or interconnection devices
- G06F21/85—Protecting input, output or interconnection devices interconnection devices, e.g. bus-connected or in-line devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06K—GRAPHICAL DATA READING; PRESENTATION OF DATA; RECORD CARRIERS; HANDLING RECORD CARRIERS
- G06K19/00—Record carriers for use with machines and with at least a part designed to carry digital markings
- G06K19/06—Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
- G06K19/067—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components
- G06K19/07—Record carriers with conductive marks, printed circuits or semiconductor circuit elements, e.g. credit or identity cards also with resonating or responding marks without active components with integrated circuit chips
- G06K19/073—Special arrangements for circuits, e.g. for protecting identification code in memory
- G06K19/07309—Means for preventing undesired reading or writing from or onto record carriers
- G06K19/07345—Means for preventing undesired reading or writing from or onto record carriers by activating or deactivating at least a part of the circuit on the record carrier, e.g. ON/OFF switches
Definitions
- the present invention relates to the design of a hardware component dedicated to the security of a communication apparatus such as, for example, a mobile phone.
- the restricted portion of a device on which the security objectives assigned to that equipment in the security target is called a trusted core.
- More and more devices provide access to secure services such as banking services or access to secure professional services. These devices must be secure and meet particularly strict standards in terms of security. To be used when accessing these services, these devices must be approved by an authority, they undergo a certification procedure. This certification procedure verifies that they meet a set of security criteria and can therefore be used to operate the secure service. Payment terminals and bank chip cards are examples of devices that are subject to these security certifications.
- the heart of confidence is therefore the device implementing in the device the communication between a so-called red domain and a so-called black domain.
- This device is a communication device between two zones of different security levels.
- the red domain deals with intelligible and sensitive information protected by its environment, we also speak of red information.
- the black domain represents the hostile environment that does not protect the information. In this area, information must be protected.
- a trust architecture does not allow direct passages of information from the red domain to the black domain and vice versa.
- Sensitive information is thus protected, in confidentiality and / or in integrity and / or in authenticity, by its passage through the heart of trust of which it is the role. Reciprocally, the protected information from the black domain is made intelligible and / or verified and / or authenticated after passing through the trusted heart.
- the safety certification of the device amounts to certifying the heart of trust. If it complies with safety standards, certification of the rest of the device is not necessary.
- Fig. 1 illustrates the architecture of a trusted heart according to the prior art.
- the heart of confidence 1.1 is composed of a processor 1.2 which is responsible for executing the program of confidence.
- This processor communicates with a dedicated component 1.3 responsible for cryptographic operations and input-output with the outside.
- This component is typically made in the form of an ASIC (Application-Specific
- This component 1.3 allows communication with the red domain 1.4 on the one hand and with the black domain 1.5 on the other hand.
- a communication link 1.6 allows the injection into the cryptographic component of the keys necessary for its operation.
- the invention proposes a core architecture of confidence more effective in terms of design and in terms of evaluation than the usual architectures. It's about combining two simple design and evaluation components to get a simply evaluable core of trust.
- This trusted heart respects the principles of partitioning security recommendations, typically the partitioning between the red and black domains and the injection of keys.
- the invention proposes to convert an existing single-interface component, namely an evaluated chip card component, into a multi-interface component that respects the principles of partitioning.
- the component performing this interface conversion is designed on a minimal basis and if possible exclusively hardware that only realizes the safe routing of the flows.
- the invention makes it possible to reduce the cost of design by a significant factor. Indeed, the base of the heart of confidence consisting of a chip card component exists and the complementary referral function is reduced to a minimum.
- the innovation also makes it possible to reduce the cost of an evaluation by a significant factor, since the smart card component is already evaluated and the evaluation scheme is mastered.
- the referral function by its minimalist design is also evaluable simply. The combination of designs and evaluations is then more efficient than the design and evaluation of a monolithic component.
- the invention relates to a secure communication device between two zones of different security levels which comprises a chip card component which guarantees the confidentiality of the information and the implementation of cryptographic algorithms without leakage of information and a switching component alternately allowing the communication between the chip card component and each of the two zones of different security levels, as well as the introduction of cryptographic keys in the chip card component.
- the switching component comprises three channels each having a switch such that when one of the switches is closed, the other two are necessarily open.
- each of the channels further comprises a protocol adaptation module allowing the eventual Protocol conversion if needed between the external interface and the smart card component.
- Fig. 1 illustrates the architecture of a trusted heart according to the prior art
- Fig. 2 illustrates the architecture of a trusted heart according to the invention
- Fig. 3 illustrates the architecture of an example of a smart card component used in the invention
- Fig. 4 illustrates the architecture of an exemplary embodiment of the switching component.
- Fig. 2 illustrates the architecture of a trusted heart according to the invention. It is architecture around a classic 2.2 smart card component. This component is a micro-controller resistant to physical aggression, protected against reverse engineering (reverse engineering), against the introduction of errors by particle beam. It guarantees the confidentiality of information and the implementation of cryptographic algorithms without leakage of information.
- the smart card component already has the security objectives that you want to get from the trusted core.
- a chip card component that is to say the physical component and the software that it embeds, provides a response to the usual objectives of information protection equipment: safe storage of secret elements, encryption decryption , access control to the resource, etc. This is a good example of an assessed perimeter security resource.
- This switching component alternately allows the communication between the chip card component and each of the two zones of different security levels, as well as the introduction of cryptographic keys into the chip card component.
- component 2.3 This is the role of component 2.3. It makes it possible to establish a secure and unidirectional path between the chip card component and either the red zone, the black zone or the keys. This component is designed so that at any given time only one of these paths can be active. The device is designed such that the path through which the keys are introduced into the smart card component is unique. It ensures that no leakage of information can take place both during the introduction and during the subsequent use of the trusted heart. The advantage of this design is that the smart card component is already certified. To certify the heart of confidence according to the invention, it will be sufficient to certify the switching component 2.3.
- Fig. 3 illustrates the typical architecture of a chip card component 2.2 that can be used in the invention.
- a processor 3.8 Connected to the communication bus 3.11, there is a processor 3.8. This processor is directly connected to a clock circuit 3.9 and to a reset control component (Reset Logic) 3.10, as well as to a safety circuit 3.1.
- An input / output management module 3.7 allows communication with the outside and in this case with the switching component.
- a module 3.6 allows the generation of random numbers used in crypto graphics algorithms.
- a dedicated crypto graphing module 3.5 provides the cryptographic functions.
- the memory is broken down into a first E2PROM module 3.4 which contains the data and the on-board software, a second Random Access Memory module 3.3 which contains the data and data. the program temporarily during its execution.
- a third ROM module Read OnIy Memory in English
- FLASH 3.2 which also contains embedded software dedicated smart card.
- Fig. 4 illustrates the architecture of the switching component 2.3.
- This component includes a link 4.1 for communicating with the smart card core.
- This link allows communication with three input-output channels 4.2, 4.4 and 4.6 via three switch mechanisms to close or open each channel 4.3, 4.5 and 4.7.
- Each of the channels is advantageously provided with an adaptation module 4.8, 4.9 and 4.10 allowing the possible protocol conversion if necessary between the external interface and the chip card component.
- the links are bi-directional, typically serial-type interfaces that can be converted very simply into a protocol that is managed by a smart card component, the ISO 7816-3 protocol.
- the component is designed so that when a switch is on, the others are necessarily open to ensure the desired partitioning. Any Data transmission can not take place between the different interfaces 4.2, 4.4 and 4.6 without passing through the chip card component which thus ensures the security of the device.
- This turnout component is ultimately the only component requiring a security certification that remains simple because of the simplicity of design of this component.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Software Systems (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Mathematical Physics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US13/124,499 US20120198231A1 (en) | 2008-10-15 | 2009-10-15 | Secure communication device |
| GB1106146.2A GB2476023B (en) | 2008-10-15 | 2009-10-15 | Secure communication device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0856988 | 2008-10-15 | ||
| FR0856988A FR2937212B1 (fr) | 2008-10-15 | 2008-10-15 | Dispositif de communication securise. |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2010043679A1 true WO2010043679A1 (fr) | 2010-04-22 |
Family
ID=40792604
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2009/063497 Ceased WO2010043679A1 (fr) | 2008-10-15 | 2009-10-15 | Dispositif de communication securise |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20120198231A1 (fr) |
| FR (1) | FR2937212B1 (fr) |
| GB (1) | GB2476023B (fr) |
| WO (1) | WO2010043679A1 (fr) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1258831A2 (fr) * | 2001-05-17 | 2002-11-20 | Matsushita Electric Industrial Co., Ltd. | Carte à puce avec une interface à contacts et une interface sans contacts |
| EP1313063A2 (fr) * | 2001-10-24 | 2003-05-21 | Kabushiki Kaisha Toshiba | Carte à puce combinée avec/sans contact |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5321394A (en) * | 1992-04-10 | 1994-06-14 | Alcatel Network Systems, Inc. | Spare card connection circuitry for high-speed telecommunications transmitters/receivers and methods |
| AUPO799197A0 (en) * | 1997-07-15 | 1997-08-07 | Silverbrook Research Pty Ltd | Image processing method and apparatus (ART01) |
-
2008
- 2008-10-15 FR FR0856988A patent/FR2937212B1/fr active Active
-
2009
- 2009-10-15 GB GB1106146.2A patent/GB2476023B/en active Active
- 2009-10-15 WO PCT/EP2009/063497 patent/WO2010043679A1/fr not_active Ceased
- 2009-10-15 US US13/124,499 patent/US20120198231A1/en not_active Abandoned
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1258831A2 (fr) * | 2001-05-17 | 2002-11-20 | Matsushita Electric Industrial Co., Ltd. | Carte à puce avec une interface à contacts et une interface sans contacts |
| EP1313063A2 (fr) * | 2001-10-24 | 2003-05-21 | Kabushiki Kaisha Toshiba | Carte à puce combinée avec/sans contact |
Also Published As
| Publication number | Publication date |
|---|---|
| GB2476023A (en) | 2011-06-08 |
| US20120198231A1 (en) | 2012-08-02 |
| GB201106146D0 (en) | 2011-05-25 |
| FR2937212A1 (fr) | 2010-04-16 |
| GB2476023B (en) | 2013-05-15 |
| FR2937212B1 (fr) | 2011-05-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3446436B1 (fr) | Procédé d'obtention par un terminal mobile d'un jeton de sécurité | |
| WO2006111626A2 (fr) | Procédé et dispositif d'acces a une carte sim logée dans un terminal mobile | |
| FR2971599A1 (fr) | Procede de transaction securisee a partir d'un terminal non securise | |
| WO2010084107A1 (fr) | Circuit de cryptographie, protégé notamment contre les attaques par observation de fuites d'information par leur chiffrement | |
| WO2016079403A1 (fr) | Procédé de sécurisation d'un jeton de paiement. | |
| JP2014522180A (ja) | 識別キー漏れを防止するicチップ及びこの認証方法 | |
| CA2888662A1 (fr) | Systeme et procede de securisation des echanges de donnees, objet portable utilisateur et dispositif distant de telechargement de donnees | |
| Riebe et al. | US security policy: The dual-use regulation of cryptography and its effects on surveillance | |
| FR3106909A1 (fr) | Circuit intégré configuré pour réaliser des opérations de chiffrement symétrique avec protection de clé secrète | |
| EP3667530B1 (fr) | Accès sécurise à des données chiffrées d'un terminal utilisateur | |
| Alliance | Host card emulation (hce) 101 | |
| Margraf et al. | Security evaluation of apple pay at point-of-sale terminals | |
| WO2012031848A1 (fr) | Procede simplifie de personnalisation de carte a puce et dispositif associe | |
| WO2010043679A1 (fr) | Dispositif de communication securise | |
| Armando et al. | Trusted host-based card emulation | |
| EP2813962B1 (fr) | Méthode de contrôle d'accès à un type de services spécifique et dispositif d'authentification pour le contrôle de l'accès à un tel type de services. | |
| EP3994596B1 (fr) | Architecture informatique en nuage securisee et procede de securisation | |
| US20190305945A1 (en) | Method for implementing a cryptographic function for a secret key | |
| da Fonte | Host card emulation with tokenisation: Security risk assessments | |
| CH716294A2 (fr) | Procédé de signature décentralisée, sous contrôle biométrique et sous conditions d'identification personnelle et de géolocalisation, d'une transaction destinée à une blockchain. | |
| Ramachandran | Shielding the digital vault: Harnessing tokenization to safeguard financial transactions | |
| CH716293A2 (fr) | Procédé de signature décentralisée, sous contrôle biométrique et sous condition d'identification personnelle, d'une transaction destinée à une blockchain. | |
| Ahonen et al. | Information security threats and solutions in the mobile world | |
| Mancini | Using Smart Cards to Enhance Security of Android Smartphones in Tactical Scenarios | |
| Orucho et al. | Assessing Operation of Mobile Banking Applications that Support Customers to Access Banking Services Remotely |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 09744111 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 1106146 Country of ref document: GB Kind code of ref document: A Free format text: PCT FILING DATE = 20091015 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 1106146.2 Country of ref document: GB |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 13124499 Country of ref document: US |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 09744111 Country of ref document: EP Kind code of ref document: A1 |