WO2017114601A1 - Method for protecting the use of a cryptographic key in two different cryptographic environments - Google Patents

Method for protecting the use of a cryptographic key in two different cryptographic environments Download PDF

Info

Publication number
WO2017114601A1
WO2017114601A1 PCT/EP2016/068448 EP2016068448W WO2017114601A1 WO 2017114601 A1 WO2017114601 A1 WO 2017114601A1 EP 2016068448 W EP2016068448 W EP 2016068448W WO 2017114601 A1 WO2017114601 A1 WO 2017114601A1
Authority
WO
WIPO (PCT)
Prior art keywords
cryptographic
key
environment
data
security level
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/EP2016/068448
Other languages
French (fr)
Inventor
Carine Boursier
François Millet
Rudy YANTO
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Thales DIS France SA
Original Assignee
Gemalto SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Gemalto SA filed Critical Gemalto SA
Publication of WO2017114601A1 publication Critical patent/WO2017114601A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/088Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/002Countermeasures against attacks on cryptographic mechanisms
    • H04L9/003Countermeasures against attacks on cryptographic mechanisms for power analysis, e.g. differential power analysis [DPA] or simple power analysis [SPA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/04Masking or blinding
    • H04L2209/046Masking or blinding of operations, operands or results of the operations

Definitions

  • the present invention relates to a method for protecting the use of a cryptographic key into two different cryptographic environment having respectively different security level.
  • the present invention relates to the transformation of the cryptographic key into cryptographic data in order to use said cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of an electronic device with a second security level.
  • the invention also relates to an associated electronic device. BACKG ROU N D OF TH E I NVE NTION
  • a method for transforming at least one cryptographic key into a cryptographic data in order to use said cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of an electronic device with a second security level comprises a step of applying a mask on said cryptographic key to obtain a cryptographic data in order to make the cryptographic key confidential.
  • the cryptographic data is used within any cryptographic environment in the electronic device which needs the use of said cryptographic key, such as the first and the second cryptographic environments.
  • a first cryptographic environment comprises a first security level which is different from a second security level of the second cryptographic environment.
  • the first security level may be protections against Differential Power Analysis (known as DPA), whereas the second security level may be without protections against DPA.
  • DPA Differential Power Analysis
  • the invention proposes a method (MTH) for protecting a cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, wherein: said electronic device being operated to:
  • the method in accordance with the invention further comprises the following characteristics.
  • the first cryptographic environment and the second cryptographic environment are part of a same communication protocol.
  • the first security level is higher than the second security level and the first key adapted to the first security level is securely higher than the second key adapted to the second security level.
  • the first security level is securely lower than the second security level and the first key adapted to the first security level is securely lower than the second key adapted to the second security level.
  • the derivation of said first cryptographic data is a function of said cryptographic key and a first mask.
  • the transformation of said first cryptographic data into said second cryptographic data is function of a second mask and said first mask.
  • said method further comprises generating said first and said second masks associated respectively to the first and to the second cryptographic environment.
  • the transformation of said first cryptographic data comprises:
  • a mask is based on a master mask and on a diversifier.
  • a master mask is common to all the cryptographic keys used by said electronic device and a diversifier is different from on cryptographic key to another one.
  • said first cryptographic environment comprises a first set of cryptographic functions and said second cryptographic environment comprises a second set of cryptographic functions.
  • said first cryptographic environment comprises a first set of cryptographic functions implementing a mutual authentication between said electronic device and a remote server.
  • said second cryptographic environment comprises a second set of cryptographic functions implementing a data exchange between said electronic device and a remote server.
  • said electronic device is a secure element.
  • said secure element is a smart card, an embedded secure element, a micro-SD, an UICC.
  • the present invention also relates to an electronic device comprising - a processor; and a memory coupled to the processor and instructions stored into the memory that performs the method for protecting a cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, wherein:
  • an electronic device adapted to transform at least one cryptographic key into a cryptographic data in order to use said cryptographic key within a first cryptographic environment of said electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, said cryptographic key comprising first and second conditions of use respectively within said first cryptographic environment and said second cryptographic environment, wherein said electronic device comprises an execution platform which is adapted to:
  • Fig.1 illustrates schematically an organization chart of a method according to a non-limitative embodiment of the invention
  • Fig. 2 illustrates an electronic device which is adapted to carry out the method of Fig. 1 ;
  • Fig. 3 illustrates a first cryptographic data and a second cryptographic data which are generated by the method of Fig. 1 and which are respectively paired to two different cryptographic environments;
  • - Fig. 4 illustrates the use of these first cryptographic data and second cryptographic data by the electronic device of Fig. 2, when said electronic device cooperates with a remote server and a local terminal.
  • FIG. 1 to FIG. 4 may communicate via any suitable communication medium using any suitable communication protocol.
  • the present invention relates to a method MTH for transforming at least one cryptographic key K1 into a first cryptographic data CA, and a second cryptographic data CB respectively use within a first cryptographic environment E1 of an electronic device D with a first security level L1 and within a second cryptographic environment E2 of said electronic device D with a second security level L2.
  • Said cryptographic key K1 comprises first and second conditions of use CU1 , CU2 respectively within said first cryptographic environment E1 and said second cryptographic environment E2.
  • Said method MTH is illustrated in Fig. 1 in a non-limitative embodiment. It is carried out by an electronic device D illustrated in Fig. 2.
  • one or a plurality of cryptographic keys K1 are used by the electronic device D within at least one cryptographic environment E.
  • said first cryptographic environment E1 comprises a first set of cryptographic functions F1 and said second cryptographic environment E2 comprises a second set of cryptographic functions F2.
  • Each cryptographic function F1 , F2 uses a cryptographic key K1 and produces a result.
  • a cryptographic function F is always executed with a cryptographic key K1 (in particular with the first cryptographic data CA for F1 , or with the second cryptographic data CB for F2), but said cryptographic key K1 may changed from one execution to the other.
  • a cryptographic function F which is a 3DES may be called with a first cryptographic key for a banking application, and with second cryptographic key for a transport application. Said different cryptographic keys will lead respectively to the first cryptographic data CA and to the second cryptographic data CB generated from the cryptographic key K1 .
  • the first set of cryptographic functions F1 implements session keys generation, a mutual authentication between said electronic device D and a remote server etc.
  • the second set of cryptographic function F2 implements a DES/AES, data exchange, an encryption/decryption of data, a MAC (Message Authentication Code) computation of data, data integrity checking with a MAC etc.
  • the first security level L1 and the second security level L2 are different.
  • the first security level L1 is higher than the second security level L2.
  • said first security level L1 comprises high level security countermeasures.
  • it comprises protections against DPA ("Differential Power Analysis"), against CPA ("Correlation Power Analysis”), against DFA ("Differential Fault Attack”) etc.
  • said second security level L2 comprises low level security countermeasures or none. In a non-limitative example, it doesn't comprise any protection against DPA. In the non-limitative embodiment, the first cryptographic environment
  • E1 is therefore a secure cryptographic environment, whereas the second cryptographic environment E2 is a less secure one.
  • the security level Lk of the cryptographic data generated from the cryptographic key K1 depends on the security level L associated to the cryptographic environment E which will use said cryptographic data.
  • the security level Lk1 of the cryptographic data CA is higher than the second security level Lk2 of the cryptographic data CB.
  • the first cryptographic data CA will provide a first key adapted to the security level Lk1 and will be use only by the cryptographic functions F1 of the first cryptographic environment E1 .
  • the first cryptographic data CA may not be used within another cryptographic environment.
  • the second cryptographic data CB will provide a second key adapted to the security level Lk2 and will be use only by the cryptographic functions F2 of the second cryptographic environment E2.
  • the second cryptographic data CB may not be used within another cryptographic environment.
  • the two different cryptographic environments E1 , E2 with the different security levels L1 , L2 may be
  • the communication protocol is a Global Platform Procedure.
  • This Global Platform Procedure comprises:
  • a mutual authentication phase MUT_AUTH between said electronic device D and a remote server RS which is based on a set of session keys K1 1 , K12 generated from a static key;
  • a secure messaging channel SM set-up for exchanging data between said electronic device D and said remote server RS;
  • a data exchange DAT_E through said secure messaging channel SM using said set of session keys, which comprises encryption/decryption ENCR/DECR of data, MAC (Message Authentication Code) computation, and checking the integrity of the data CHK_MAC.
  • set of session keys which comprises encryption/decryption ENCR/DECR of data, MAC (Message Authentication Code) computation, and checking the integrity of the data CHK_MAC.
  • data exchange may be performed between said electronic device D and said remote server RS.
  • the first conditions of use CU1 and the second conditions of use CU2 refer to how the cryptographic key K1 is used within a cryptographic function F of a cryptographic environment E.
  • the first conditions of use CU1 comprise the ciphering of different messages with the cryptographic key K1 before any authentication, the number of times one may use the cryptographic key K1 within a cryptographic function, the variability of the input of the cryptographic function, the knowledge of the input, the knowledge of the output etc.
  • the second conditions of use CU2 comprise the ciphering of different messages with the cryptographic key K1 only after an authentication, the number of times one may use the cryptographic key K1 within a cryptographic function, the variability of the input of the cryptographic function, the knowledge of the input, the knowledge of the output etc.
  • the variability of the input of the cryptographic function is high, this means that a possible attack to break the cryptographic key K1 may be a DPA. It is to be noted that the variability of the input means that an external entity such as a remote server, in a non-limitative example, is authorized to control and vary the input of the cryptographic function F.
  • the method MTH is described in details hereinafter in a non-limitative embodiment. As illustrated in Fig. 1 , the method MTH comprises:
  • step 1) illustrated in Fig. 1 GEN(D, CA, K1 , Lk1 , E1 ), said electronic device D generates a first cryptographic data CA from the cryptographic key K1 without exposing said cryptographic key K1 in order to obtain a first key adapted to the security level Lk1 of said first cryptographic environment, said first cryptographic data CA being paired with said first cryptographic environment E1 .
  • the generation of said first cryptographic data CA is function of said cryptographic key K1 and a first mask ML
  • the first mask M1 permits to obtain a first key adapted to the security level Lk1 of said first cryptographic environment.
  • the first mask M1 is defined in order to obtain a high secure key adapted to the security level of said first cryptographic environment.
  • the first mask M1 is defined so that it resists the attacks from an attacker who wants to recover the cryptographic key K1 .
  • the first diversifier D1 when the first mask M1 is based on a first master mask MM1 and a first diversifier D1 , in order to make the mask M1 secure, the first diversifier D1 is stored in memory far apart from the cryptographic key K1 so that an attacker will have more difficulties to recover said first diversifier D1 .
  • this first mask M1 will always be used for the cryptographic key K1 which is used with a cryptographic function F1 .
  • the method MTH is further adapted to generate said first mask M1 associated to said first cryptographic environment E1 (illustrated GEN(D, M1 )). This step is performed previously to the first step (step 0)).
  • said first cryptographic data CA K1 XOR M1 .
  • the cryptographic key K1 is never exposed in clear.
  • the first mask M1 is based on a first master mask MM1 and on a first diversifier D1 .
  • the first master mask MM1 and the first diversifier D1 permit to have a different first mask M1 for each different cryptographic key K1 .
  • first master mask MM1 in combination with a first diversifier D1 permit to have a strong security even if the first diversifier D1 is broken by an attacker, this latter may not recover the first master mask MM1 unless he attacks at the same time the first master mask MM1 , which is more difficult to do.
  • said first mask M1 MM1 XOR D1
  • the first cryptographic data CA K1 XOR (MM1 XOR D1 ).
  • Said first cryptographic data CA is stored in memory.
  • the first cryptographic data CA may be stored in a non-volatile memory.
  • the cryptographic key K1 when the cryptographic key K1 is a non-persistent key (also called transient key), the first cryptographic data CA may be stored in a volatile memory.
  • the cryptographic key K1 is stored in the electronic device D in masked value.
  • the first cryptographic data CA is the cryptographic key K1 which is masked in a secure way.
  • Said masked cryptographic key CA will be manipulated within the first cryptographic environment E1 instead of the cryptographic key K1 in clear.
  • the first cryptographic data CA is paired with the first cryptographic environment E1 as it will be used by at least one cryptographic function F1 of said first cryptographic environment E1 . It can only be used by said first cryptographic environment E1 .
  • the pairing is performed by storing in memory a pair CA-L1 , that is to say when storing the first cryptographic data CA, the associated first security level L1 is also stored.
  • the first cryptographic environment E1 is of a high level security L1 and the first mask M1 permits to better protect the cryptographic key K1 against an attacker than the second mask M2 as said cryptographic key K1 is more exposed to attack within said first cryptographic environment E1 .
  • said cryptographic key K1 is transferred that is to say is masked differently so that a second adapted to the security level Lk2 different from the first key adapted to the security level Lk1 is provided, and then said cryptographic key K1 is used within the second cryptographic environment E2.
  • the said cryptographic key K1 is transferred according to the following step.
  • step 2) illustrated in Fig. 1 TRF(D, CA, CB, Lk2, E2) said electronic device D transforms said first cryptographic data CA into a second cryptographic data CB without exposing said cryptographic key K1 in order to obtain a second key adapted to the security level Lk2 of said second cryptographic environment, said second key adapted to the security level Lk2 being different from the first key adapted to the security level Lk1 , and said second cryptographic data CB being paired with said second cryptographic environment E2.
  • the second security level L2 of said second cryptographic environment E2 when the second security level L2 of said second cryptographic environment E2 is lower than the first security level L1 of said first cryptographic environment E1 , the second key adapted to the security level Lk2 is securely lower than the first key adapted to the security level Lk1 .
  • the aim is to mask the cryptographic key K1 with the second mask M2 to obtain a second key adapted to the security level Lk2 securely lower than the first key adapted to the security level Lk1 . If one computes directly the cryptographic key K1 with the mask M2, the cryptographic key K1 is manipulated in clear and therefore is exposed to an attacker. In order to avoid this, said first cryptographic data CA is transformed as following.
  • the transformation of said first cryptographic data CA into said second cryptographic data CB is function of a second mask M2 and said first mask M1 .
  • the second mask M2 permits to obtain a second key adapted to the security level Lk2 of said second cryptographic environment.
  • the second mask M2 is defined in order to obtain a low key adapted to the security level for said cryptographic key K1 .
  • the second mask M2 is defined so that it will less resist the attacks from an attacker who wants to recover the cryptographic key K1 . But if said second mask M2 is recovered by an attacker, it won't jeopardize the security of the first cryptographic data CA which is well secure.
  • the second mask M2 is a constant.
  • the second diversifier D2 is stored in memory next to the cryptographic key K1 .
  • the method MTH is further adapted to generate said second mask M2 associated to said second cryptographic environment E2 (illustrated GEN(D, M2)). This step is performed previously to the first step or just before the second step (step 0)).
  • the transformation of said first cryptographic data CA comprises:
  • the electronic device D only computes CA XOR M2 resulting in X, then X XOR M1 resulting in CB. During these computations to obtain the second cryptographic data CB, the cryptographic key K1 is never exposed in clear and is never manipulated.
  • a second master mask MM2 in combination with a second diversifier D2 permits to have a strong security as if the second diversifier D2 is broken by an attacker, this latter may not recover the second master mask MM2 unless he attacks at the same time the second master mask MM2, which is more difficult to do.
  • said second cryptographic data CB is computed on the fly, each time a cryptographic function F2 of the second cryptographic environment E2 needs the cryptographic key K1 to be executed, that is to say before the execution of said cryptographic function F2.
  • the second cryptographic data CB may be stored in a volatile memory.
  • said second cryptographic data CB is stored in memory, which may be either non-volatile, or volatile, which may depend on if the cryptographic key K1 is respectively static or transient.
  • the storage of the cryptographic key K1 via the second cryptographic data CB is less secure than the storage of the cryptographic key K1 via the first cryptographic data CA.
  • the cryptographic key K1 is stored in the electronic device D in masked value.
  • the second cryptographic data CB is the cryptographic key
  • Said masked cryptographic key CB will be manipulated within the second cryptographic environment E2 instead of the cryptographic key K1 in clear.
  • the second cryptographic data CB is paired with the second cryptographic environment E2 as it will be used by at least one cryptographic function F2 of said second cryptographic environment E2. It can only be used by said second cryptographic environment E2.
  • the pairing is performed by storing in memory a pair CB-L2, that is to say when storing the second cryptographic data CB, the associated second security level L2 is also stored.
  • the second cryptographic data CB is a degraded way to store the cryptographic key K1 .
  • the second key adapted to the security level Lk2 is a degraded secure level compared to the first key adapted to the security level Lk1 .
  • the transformation of the first cryptographic data CA into a second cryptographic data CB permits to perform a key transfer of the cryptographic key K1 from the first cryptographic environment E1 (which is secure in the non-limitative embodiment described) to the second cryptographic environment E2 (which is less secure in the non-limitative embodiment described).
  • the key transfer method proposed herein allows to securely modify the mask of the cryptographic key K1 in order to transform it into a key adapted to the needed security level Lk so as to bring it in line with the security level L of the cryptographic environment E which will use said cryptographic key K1 .
  • the different masks M1 , M2 permit to give respectively the right key adapted to the security level Lk1 , Lk2 to the cryptographic key K1 according to respectively the cryptographic environments E1 , E2 needs, that is to say according to respectively their security levels L1 , L2.
  • the different masks M1 , M2 permit to securely store the cryptographic key K1 and to give respectively a different storage security level Lk1 , Lk2 depending respectively on the security level L1 , L2 of the cryptographic environments E1 , E2.
  • a cryptographic function F (F1 described here or F2 described in the following) is part of a command received by the electronic device D from an external entity, such as for example, a remote server.
  • a cryptographic function F1 is part of an APDU (Application Protocol Data Unit) command.
  • the conditions may be as following: a challenge is sent before executing the current command, an authentication is performed before executing the current command, a previous command is sent and successfully executed before the current command, a security flag is raised, an electronic device state or an application state is set to a given value etc.
  • the first cryptographic environment E1 comprises a first set of cryptographic functions F1 implementing a mutual authentication MUT_AUTH between said electronic device D and a remote server RS.
  • the cryptographic key K1 is a set of sessions key K1 1 , K12 which is generated from a static key which can be an authentication private key.
  • This set of sessions key K1 1 , K12 is used for the mutual authentication, that is to say before an external entity is authenticated.
  • the cryptographic key K1 is highly exposed to attacker. Therefore, it needs a high secure key adapted to the security level, which is in a non-limitative example the first key adapted to the security level Lk1 which is provided through the first cryptographic data CA.
  • the cryptographic key K1 which will be used is less exposed to an attacker as only the authorized entity, here a remote server RS, may reach this phase. Therefore, it needs a lower secure key adapted to the security level, which is in a non-limitative example the second key adapted to the security level Lk2 which is provided through the second cryptographic data CB.
  • step 4) described hereinafter is performed.
  • step 4) illustrated in Fig. 1 US(D, CB, E2, CU2) said electronic device D uses said second cryptographic data CB within said second cryptographic environment E2 with respect to said second conditions of use CU2 of said cryptographic key K1 .
  • a secure message channel SM is set-up between the electronic device D and the remote server RS to exchange data DAT securely.
  • the electronic device D and the remote server RS exchange data using the cryptographic key K1 which is a set of session keys K1 1 , K12.
  • the second cryptographic environment E2 comprises a second set of cryptographic functions F2 implementing a data exchange DAT_E between said electronic device D and a remote server SERV.
  • Said data exchange DAT_E comprises encryption/decryption of data ENCR/DECR, MAC computation, and/or checking integrity of data CHK_MAC.
  • the first session key K1 1 will be used to encrypt data of the electronic device D, and to decrypt incoming data from the remote server RS which has been authenticated before;
  • the second session key K12 will be used to check integrity of the incoming data from the remote server RS which has been authenticated before, via a MAC ( Message Authentication Code) in a non-limitative example.
  • MAC Message Authentication Code
  • the set of session keys K1 1 , K12 is never exposed.
  • the data exchange DAT_E is secure as it is performed via a secure message channel SM.
  • the cryptographic functions F2 comprise less countermeasures, and therefore less complex unit operations than the first cryptographic functions F1 .
  • the cryptographic functions F2 are faster to be executed and they use less volatile memory for their execution. Therefore, it improves the time and memory performances of the whole communication protocol.
  • the electronic device D is a secure element such as a smart card, an eSE, an UICC, a micro-SD
  • the data are exchanged by means of APDU (Application Protocol Data Unit).
  • APDU Application Protocol Data Unit
  • the second cryptographic value CB is erased from the memory of the electronic device D (step 5) illustrated in Fig. 1 CLR(D, CB)). It permits to save some memory.
  • the same cryptographic key K1 with two different keys adapted respectively to the security level Lk1 , Lk2 may be used respectively within two different cryptographic environments E1 , E2 with two different security levels L1 , L2 without compromising and exposing the cryptographic key K1 , and with respect to the different conditions of used CU1 , CU2 of said cryptographic key K1 with respectively the two different cryptographic environments E1 , E2.
  • the method MTH above-described is carried out by the electronic device D adapted to transform at least one cryptographic key K1 into a cryptographic data in order to use said cryptographic key K1 within a first cryptographic environment E1 of said electronic device D with a first security level L1 and within a second cryptographic environment E2 of said electronic device D with a second security level L2, said cryptographic key K1 comprising first and second conditions of use CU1 , CU2 respectively within said first cryptographic environment E1 and said second cryptographic environment E2.
  • the electronic device D is described with reference to Fig. 2.
  • the electronic device D is a secure element.
  • a secure element is a secure component which may perform cryptographic functionalities and is adapted to store a secret key.
  • the electronic device D is a smart card.
  • the smart card is an Electronic Identity Card, is a health card, a driving license, a passport, a privacy card, a financial service card, an access card etc. It may be contact or contactless.
  • the electronic device D is an eSE (embedded secure element), a micro-SD, an UICC (Universal Integrated Circuit Card .
  • the electronic device D is a mobile phone, a smart phone, a tablet etc.
  • Said electronic device D may comprise a secure element.
  • Said electronic device D comprises an execution platform EP which is adapted to:
  • said execution platform EP is further adapted to:
  • said execution platform EP is further adapted to erase said second cryptographic value CB from the electronic device's memory (function illustrated CLR(D, CB)).
  • said execution platform EP is further adapted to:
  • said execution platform EP is a processor unit or a virtual machine.
  • said processor unit comprises one or a plurality of processors.
  • a cryptographic key K1 may be transformed into more than two cryptographic data in order to be used respectively within more than two different cryptographic environments E with different associated security level L.
  • a cryptographic key K1 may be used within three cryptographic environments with three different security levels, one high security level, one medium security level, and one low security level.
  • the first security level L1 is lower than the second security level L2 and the first key adapted to the security level Lk1 is lower than the second key adapted to the security level Lk2.
  • some embodiments of the invention may comprise one or a plurality of the following advantages:
  • the cryptographic key K1 is securely paired to the appropriate cryptographic environment E1 , E2 via the different masks M1 , M2, it increases the security of the use of the cryptographic key K1 ;
  • the electronic card D will use the strongest security cryptographic environment E1 , and for other processes, the electronic card D will use the degraded security cryptographic environment E2;
  • an electronic device D such as a secure element comprises limited resources in term of memory, time processing etc. it permits said electronic device D to improve its performances as the right key adapted to the security level is associated according to the needs of the cryptographic environment E1 , E2;

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Storage Device Security (AREA)

Abstract

The present invention relates to a method (MTH) for protecting a cryptographic key (K1) within a first cryptographic environment (E1) of an electronic device (D) with a first security level (L1) and within a second cryptographic environment (E2) of said electronic device (D) with a second security level (L2), wherein: • said electronic device being operated to derive a first cryptographic data (CA) from the cryptographic key (K1) in order to obtain a first key adapted to the security level (Lk1) of said first cryptographic environment (E1), said first cryptographic data (CA) being paired with said first cryptographic environment (E1); • using said first cryptographic data (CA) within said first cryptographic environment (E1); • said electronic device being operated to apply a transformation operation to said first cryptographic data (CA) to provide a second cryptographic data (CB) in order to obtain a second key adapted to the security level (Lk2) of said second cryptographic environment (E1), said second key adapted to the security level (Lk2) being different from the first key adapted to the security level (Lk1), and said second cryptographic data (CB) being paired with said second cryptographic environment (E2), said operation transformation being configured so that the provided second cryptographic data is derived from the cryptographic key (K1); • using said second cryptographic data (CB) within said second cryptographic environment (E2).

Description

METHOD FOR PROTECTING THE USE OF A CRYPTOGRAPHIC KEY IN TWO DIFFERENT CRYPTOGRAPHIC ENVIRONMENTS
TECHNICAL FIELD
The present invention relates to a method for protecting the use of a cryptographic key into two different cryptographic environment having respectively different security level.
Particularity, the present invention relates to the transformation of the cryptographic key into cryptographic data in order to use said cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of an electronic device with a second security level.
The invention also relates to an associated electronic device. BACKG ROU N D OF TH E I NVE NTION
A method for transforming at least one cryptographic key into a cryptographic data in order to use said cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of an electronic device with a second security level, well-known by the man skilled in the art, comprises a step of applying a mask on said cryptographic key to obtain a cryptographic data in order to make the cryptographic key confidential. The cryptographic data is used within any cryptographic environment in the electronic device which needs the use of said cryptographic key, such as the first and the second cryptographic environments.
A first cryptographic environment comprises a first security level which is different from a second security level of the second cryptographic environment. In a non-limitative example, the first security level may be protections against Differential Power Analysis (known as DPA), whereas the second security level may be without protections against DPA.
One problem of this prior art is that when using a masked key which is highly secure for the first cryptographic environment with also the second environment, this leads to an implementation which is costly in terms of resources as the same security level is to be applied for the first and second cryptographic environments, although the second cryptographic environment doesn't need a security level as secure as the first cryptographic environment's one. SU M MARY OF TH E I NVENTION
The following summary of the invention is provided in order to provide a basic understanding of some aspects and features of the invention. This summary is not an extensive overview of the invention and as such it is not intended to particularly identify key or critical elements of the invention or to delineate the scope of the invention. Its sole purpose is to present some concepts of the invention in a simplified form as a prelude to the more detailed description that is presented below.
It is an object of the invention to provide a method for transforming at least one cryptographic key into a cryptographic data in order to use said cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, said cryptographic key comprising first and second conditions of use respectively for said first cryptographic environment and for said second cryptographic environment, which resolves the above-mentioned problem.
To this end, there is provided a method for transforming at least one cryptographic key into a cryptographic data in order to use said cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, said cryptographic key comprising first and second conditions of use respectively within said first cryptographic environment and said second cryptographic environment, wherein said method comprises:
• generating a first cryptographic data from the cryptographic key without exposing said cryptographic key in order to obtain a first key adapted to the security level of said first cryptographic environment, said first cryptographic data being paired with said first cryptographic environment;
• transforming said first cryptographic data into a second cryptographic data without exposing said cryptographic key in order to obtain a second key adapted to the security level of said second cryptographic environment, said second key adapted to the security level being different from the first key adapted to the security level, and said second cryptographic data being paired with said second cryptographic environment;
• using said first cryptographic data within said first cryptographic environment with respect to said first conditions of use of said cryptographic key; and
• using said second cryptographic data within said second cryptographic environment with respect to said second conditions of use of said cryptographic key.
To achieve those and other advantages, and in accordance with the purpose of the invention as embodied and broadly described, the invention proposes a method (MTH) for protecting a cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, wherein: said electronic device being operated to:
• derive a first cryptographic data from the cryptographic key in order to obtain a first key adapted to the security level of said first cryptographic environment, said first cryptographic data being paired with said first cryptographic environment;
• using said first cryptographic data within said first cryptographic environment;
• apply a transformation operation to said first cryptographic data to provide a second cryptographic data in order to obtain a second key adapted to the security level of said second cryptographic environment, said second key adapted to the security level being different from the first key adapted to the security level, and said second cryptographic data being paired with said second cryptographic environment, said operation transformation being configured so that the provided second cryptographic data is derived from the cryptographic key,
• using said second cryptographic data within said second cryptographic environment.
According to non-limitative embodiments of the invention, the method in accordance with the invention further comprises the following characteristics.
In a non-limitative embodiment, the first cryptographic environment and the second cryptographic environment are part of a same communication protocol.
In a non-limitative embodiment, the first security level is higher than the second security level and the first key adapted to the first security level is securely higher than the second key adapted to the second security level.
In a non-limitative embodiment, the first security level is securely lower than the second security level and the first key adapted to the first security level is securely lower than the second key adapted to the second security level.
In a non-limitative embodiment, the derivation of said first cryptographic data is a function of said cryptographic key and a first mask.
In a non-limitative embodiment, the transformation of said first cryptographic data into said second cryptographic data is function of a second mask and said first mask.
In a non-limitative embodiment, said method further comprises generating said first and said second masks associated respectively to the first and to the second cryptographic environment.
In a non-limitative embodiment, the transformation of said first cryptographic data comprises:
• generating an intermediary value which is the result of an XOR of said first cryptographic data and said second mask ; and
• XORing said intermediary value with said first mask in order to generate said second cryptographic data.
In a non-limitative embodiment, a mask is based on a master mask and on a diversifier. In a non-limitative embodiment, a master mask is common to all the cryptographic keys used by said electronic device and a diversifier is different from on cryptographic key to another one.
In a non-limitative embodiment, said first cryptographic environment comprises a first set of cryptographic functions and said second cryptographic environment comprises a second set of cryptographic functions.
In a non-limitative embodiment, said first cryptographic environment comprises a first set of cryptographic functions implementing a mutual authentication between said electronic device and a remote server. In a non-limitative embodiment, said second cryptographic environment comprises a second set of cryptographic functions implementing a data exchange between said electronic device and a remote server. In a non-limitative embodiment, said electronic device is a secure element.
In a non-limitative embodiment, said secure element is a smart card, an embedded secure element, a micro-SD, an UICC.
The present invention also relates to an electronic device comprising - a processor; and a memory coupled to the processor and instructions stored into the memory that performs the method for protecting a cryptographic key within a first cryptographic environment of an electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, wherein:
In addition, there is provided an electronic device adapted to transform at least one cryptographic key into a cryptographic data in order to use said cryptographic key within a first cryptographic environment of said electronic device with a first security level and within a second cryptographic environment of said electronic device with a second security level, said cryptographic key comprising first and second conditions of use respectively within said first cryptographic environment and said second cryptographic environment, wherein said electronic device comprises an execution platform which is adapted to:
• generate a first cryptographic data from the cryptographic key without exposing said cryptographic key in order to obtain a first key adapted to the security level for said cryptographic key, said first cryptographic data being paired with said first cryptographic environment;
• transform said first cryptographic data into a second cryptographic data without exposing said cryptographic key in order to obtain a second key adapted to the security level for said cryptographic key, said second key adapted to the security level being different from the first key adapted to the security level, and said second cryptographic data being paired with said second cryptographic environment;
• use said first cryptographic data within said first cryptographic environment with respect to said first conditions of use of said cryptographic key; and
· use said second cryptographic data within said second cryptographic environment with respect to said second conditions of use of said cryptographic key.
The foregoing is a summary and thus may contain simplifications, generalizations, and omissions of detail; consequently, those skilled in the art will appreciate that the summary is illustrative only and is not intended to be in any way limiting.
For a better understanding of the embodiments, together with other and further features and advantages thereof, reference is made to the following description, taken in conjunction with the accompanying drawings. The scope of the invention will be pointed out in the appended claims.
BRIEF DESCRIPTION OF THE FIGURES
Some embodiments of methods and/or apparatus in accordance with embodiments of the present invention are now described, by way of example only, and with reference to the accompanying drawings, in which:
- Fig.1 illustrates schematically an organization chart of a method according to a non-limitative embodiment of the invention;
- Fig. 2 illustrates an electronic device which is adapted to carry out the method of Fig. 1 ;
- Fig. 3 illustrates a first cryptographic data and a second cryptographic data which are generated by the method of Fig. 1 and which are respectively paired to two different cryptographic environments; and
- Fig. 4 illustrates the use of these first cryptographic data and second cryptographic data by the electronic device of Fig. 2, when said electronic device cooperates with a remote server and a local terminal.
DESCRIPTION OF EMBODIMENTS OF THE INVENTION
It will be readily understood that the components of the embodiments, as generally described and illustrated in the figures herein, may be arranged and designed in a wide variety of different configurations in addition to the described example embodiments. Thus, the following more detailed description of the example embodiments, as represented in the figures, is not intended to limit the scope of the embodiments, as claimed, but is merely representative of example embodiments.
Reference throughout the specification to one embodiment or an embodiment means that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment of the subject matter disclosed. Thus, the appearance of the phrases in one embodiment or in an embodiment in various places throughout the specification is not necessarily referring to the same embodiment. Further, the particular features, structures or characteristics may be combined in any suitable manner in one or more embodiments.
As used herein, the singular forms a, an and the are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms comprises and/or comprising, when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and/or groups thereof. In the following description, numerous specific details are provided to give a thorough understanding of embodiments. One skilled in the relevant art will recognize, however, that the various embodiments can be practiced without one or more of the specific details, or with other methods, components, materials, et cetera. In other instances, well-known structures, materials, or operations are not shown or described in detail to avoid obfuscation.
The present invention is not specific to any particular hardware or software implementation, and is at a conceptual level above specifics of implementation. It is to be understood that various other embodiments and variations of the invention may be produced without departing from the spirit or scope of the invention. The following is provided to assist in understanding the practical implementation of particular embodiments of the invention.
The same elements have been designated with the same referenced numerals in the different drawings. For clarity, only those elements and steps which are useful to the understanding of the present invention have been shown in the drawings and will be described.
Further, the mechanisms of data communication between the parties and their environment have not been detailed either, the present invention being here again compatible with usual mechanisms.
Furthermore, the connecting lines shown in the various figures contained herein are intended to represent exemplary functional relationships and/or physical couplings between the various elements. It should be noted that many alternatives or additional functional relationships or physical connections may be present in a practical system. Furthermore, the various entities in FIG. 1 to FIG. 4 may communicate via any suitable communication medium using any suitable communication protocol.
The present invention relates to a method MTH for transforming at least one cryptographic key K1 into a first cryptographic data CA, and a second cryptographic data CB respectively use within a first cryptographic environment E1 of an electronic device D with a first security level L1 and within a second cryptographic environment E2 of said electronic device D with a second security level L2. Said cryptographic key K1 comprises first and second conditions of use CU1 , CU2 respectively within said first cryptographic environment E1 and said second cryptographic environment E2.
Said method MTH is illustrated in Fig. 1 in a non-limitative embodiment. It is carried out by an electronic device D illustrated in Fig. 2.
In a non-limitative embodiment, one or a plurality of cryptographic keys K1 are used by the electronic device D within at least one cryptographic environment E.
In a non-limitative embodiment, said first cryptographic environment E1 comprises a first set of cryptographic functions F1 and said second cryptographic environment E2 comprises a second set of cryptographic functions F2.
Each cryptographic function F1 , F2 uses a cryptographic key K1 and produces a result.
Hence a cryptographic function F is always executed with a cryptographic key K1 (in particular with the first cryptographic data CA for F1 , or with the second cryptographic data CB for F2), but said cryptographic key K1 may changed from one execution to the other.
In a non-limitative example, a cryptographic function F which is a 3DES may be called with a first cryptographic key for a banking application, and with second cryptographic key for a transport application. Said different cryptographic keys will lead respectively to the first cryptographic data CA and to the second cryptographic data CB generated from the cryptographic key K1 .
In non-limitative examples, the first set of cryptographic functions F1 implements session keys generation, a mutual authentication between said electronic device D and a remote server etc.
In non-limitative examples, the second set of cryptographic function F2 implements a DES/AES, data exchange, an encryption/decryption of data, a MAC (Message Authentication Code) computation of data, data integrity checking with a MAC etc. The first security level L1 and the second security level L2 are different.
In a non-limitative embodiment, the first security level L1 is higher than the second security level L2.
In a non-limitative embodiment, said first security level L1 comprises high level security countermeasures. In a non-limitative example, it comprises protections against DPA ("Differential Power Analysis"), against CPA ("Correlation Power Analysis"), against DFA ("Differential Fault Attack") etc.
In a non-limitative embodiment, said second security level L2 comprises low level security countermeasures or none. In a non-limitative example, it doesn't comprise any protection against DPA. In the non-limitative embodiment, the first cryptographic environment
E1 is therefore a secure cryptographic environment, whereas the second cryptographic environment E2 is a less secure one.
The security level Lk of the cryptographic data generated from the cryptographic key K1 depends on the security level L associated to the cryptographic environment E which will use said cryptographic data.
In the implementation hereinafter described, the security level Lk1 of the cryptographic data CA is higher than the second security level Lk2 of the cryptographic data CB. As illustrated in Fig. 3, the first cryptographic data CA will provide a first key adapted to the security level Lk1 and will be use only by the cryptographic functions F1 of the first cryptographic environment E1 . The first cryptographic data CA may not be used within another cryptographic environment.
The second cryptographic data CB will provide a second key adapted to the security level Lk2 and will be use only by the cryptographic functions F2 of the second cryptographic environment E2. The second cryptographic data CB may not be used within another cryptographic environment.
The two different cryptographic environments E1 , E2 with the different security levels L1 , L2 may be
part of a same communication protocol.
In a non-limitative embodiment illustrated in Fig. 4, the communication protocol is a Global Platform Procedure.
This Global Platform Procedure comprises:
a mutual authentication phase MUT_AUTH between said electronic device D and a remote server RS, which is based on a set of session keys K1 1 , K12 generated from a static key;
a secure messaging channel SM set-up for exchanging data between said electronic device D and said remote server RS;
a data exchange DAT_E through said secure messaging channel SM using said set of session keys, which comprises encryption/decryption ENCR/DECR of data, MAC (Message Authentication Code) computation, and checking the integrity of the data CHK_MAC.
After the secure messaging channel SM is set-up, data exchange may be performed between said electronic device D and said remote server RS.
The first conditions of use CU1 and the second conditions of use CU2 refer to how the cryptographic key K1 is used within a cryptographic function F of a cryptographic environment E.
In non-limitative examples, the first conditions of use CU1 comprise the ciphering of different messages with the cryptographic key K1 before any authentication, the number of times one may use the cryptographic key K1 within a cryptographic function, the variability of the input of the cryptographic function, the knowledge of the input, the knowledge of the output etc.
In non-limitative examples, the second conditions of use CU2 comprise the ciphering of different messages with the cryptographic key K1 only after an authentication, the number of times one may use the cryptographic key K1 within a cryptographic function, the variability of the input of the cryptographic function, the knowledge of the input, the knowledge of the output etc.
It is to be noted that with the conditions of use CU1 , CU2, one may determine a set of attacks which may be applied to break a cryptographic key K1 . Therefore, according to these attacks, one may set-up some countermeasures that will define the security level L of the cryptographic environment E which will use the cryptographic key K1 . Therefore, to one determined conditions of use CU is associated a determined security level L.
For example, if the variability of the input of the cryptographic function is high, this means that a possible attack to break the cryptographic key K1 may be a DPA. It is to be noted that the variability of the input means that an external entity such as a remote server, in a non-limitative example, is authorized to control and vary the input of the cryptographic function F.
The method MTH is described in details hereinafter in a non-limitative embodiment. As illustrated in Fig. 1 , the method MTH comprises:
In step 1) illustrated in Fig. 1 GEN(D, CA, K1 , Lk1 , E1 ), said electronic device D generates a first cryptographic data CA from the cryptographic key K1 without exposing said cryptographic key K1 in order to obtain a first key adapted to the security level Lk1 of said first cryptographic environment, said first cryptographic data CA being paired with said first cryptographic environment E1 .
In a non-limitative embodiment, the generation of said first cryptographic data CA is function of said cryptographic key K1 and a first mask ML
The first mask M1 permits to obtain a first key adapted to the security level Lk1 of said first cryptographic environment.
In the non-limitative embodiment, the first mask M1 is defined in order to obtain a high secure key adapted to the security level of said first cryptographic environment.
The first mask M1 is defined so that it resists the attacks from an attacker who wants to recover the cryptographic key K1 .
In a non-limitative embodiment (described in the following), when the first mask M1 is based on a first master mask MM1 and a first diversifier D1 , in order to make the mask M1 secure, the first diversifier D1 is stored in memory far apart from the cryptographic key K1 so that an attacker will have more difficulties to recover said first diversifier D1 .
Hence, the way to compute this first mask M1 will always be used for the cryptographic key K1 which is used with a cryptographic function F1 .
In a non-limitative embodiment, the method MTH is further adapted to generate said first mask M1 associated to said first cryptographic environment E1 (illustrated GEN(D, M1 )). This step is performed previously to the first step (step 0)).
In a non-limitative embodiment, said first cryptographic data CA = K1 XOR M1 .
The cryptographic key K1 is never exposed in clear. In a non-limitative embodiment, the first mask M1 is based on a first master mask MM1 and on a first diversifier D1 .
The first master mask MM1 and the first diversifier D1 permit to have a different first mask M1 for each different cryptographic key K1 .
Therefore, if there is a memory dump of the cryptographic data CA corresponding to the masked cryptographic key K1 , an attacker won't be able to recover another cryptographic key K1 of the electronic device D.
The use of a first master mask MM1 in combination with a first diversifier D1 permit to have a strong security even if the first diversifier D1 is broken by an attacker, this latter may not recover the first master mask MM1 unless he attacks at the same time the first master mask MM1 , which is more difficult to do.
In a non-limitative variant of said embodiment, said first mask M1 = MM1 XOR D1 , and the first cryptographic data CA = K1 XOR (MM1 XOR D1 ).
Said first cryptographic data CA is stored in memory.
In a non-limitative embodiment, when the cryptographic key K1 is a persistent key (also called static), the first cryptographic data CA may be stored in a non-volatile memory.
In a non-limitative embodiment, when the cryptographic key K1 is a non-persistent key (also called transient key), the first cryptographic data CA may be stored in a volatile memory.
As the first mask M1 is secure, the storage of the cryptographic key
K1 via the first cryptographic data CA is secure.
The cryptographic key K1 is stored in the electronic device D in masked value. The first cryptographic data CA is the cryptographic key K1 which is masked in a secure way.
Said masked cryptographic key CA will be manipulated within the first cryptographic environment E1 instead of the cryptographic key K1 in clear.
The first cryptographic data CA is paired with the first cryptographic environment E1 as it will be used by at least one cryptographic function F1 of said first cryptographic environment E1 . It can only be used by said first cryptographic environment E1 . In a non-limitative embodiment, the pairing is performed by storing in memory a pair CA-L1 , that is to say when storing the first cryptographic data CA, the associated first security level L1 is also stored.
In the non-limitative embodiment, the first cryptographic environment E1 is of a high level security L1 and the first mask M1 permits to better protect the cryptographic key K1 against an attacker than the second mask M2 as said cryptographic key K1 is more exposed to attack within said first cryptographic environment E1 .
Before any cryptographic function F2 which needs the cryptographic key K1 is executed, said cryptographic key K1 is transferred that is to say is masked differently so that a second adapted to the security level Lk2 different from the first key adapted to the security level Lk1 is provided, and then said cryptographic key K1 is used within the second cryptographic environment E2. The said cryptographic key K1 is transferred according to the following step.
In step 2) illustrated in Fig. 1 TRF(D, CA, CB, Lk2, E2), said electronic device D transforms said first cryptographic data CA into a second cryptographic data CB without exposing said cryptographic key K1 in order to obtain a second key adapted to the security level Lk2 of said second cryptographic environment, said second key adapted to the security level Lk2 being different from the first key adapted to the security level Lk1 , and said second cryptographic data CB being paired with said second cryptographic environment E2.
In a non-limitative embodiment, when the second security level L2 of said second cryptographic environment E2 is lower than the first security level L1 of said first cryptographic environment E1 , the second key adapted to the security level Lk2 is securely lower than the first key adapted to the security level Lk1 .
The aim is to mask the cryptographic key K1 with the second mask M2 to obtain a second key adapted to the security level Lk2 securely lower than the first key adapted to the security level Lk1 . If one computes directly the cryptographic key K1 with the mask M2, the cryptographic key K1 is manipulated in clear and therefore is exposed to an attacker. In order to avoid this, said first cryptographic data CA is transformed as following.
In a non-limitative embodiment, the transformation of said first cryptographic data CA into said second cryptographic data CB is function of a second mask M2 and said first mask M1 .
The second mask M2 permits to obtain a second key adapted to the security level Lk2 of said second cryptographic environment.
In the non-limitative embodiment, the second mask M2 is defined in order to obtain a low key adapted to the security level for said cryptographic key K1 .
The second mask M2 is defined so that it will less resist the attacks from an attacker who wants to recover the cryptographic key K1 . But if said second mask M2 is recovered by an attacker, it won't jeopardize the security of the first cryptographic data CA which is well secure.
In a non-limitative embodiment, the second mask M2 is a constant. In another non-limitative embodiment (described in the following), when the second mask M2 is based on a second master mask MM2 and a second diversifier D2, the second diversifier D2 is stored in memory next to the cryptographic key K1 .
Hence, the way to compute this second mask M2 will always be used for the cryptographic key K1 which is used with a cryptographic function F2. In a non-limitative embodiment, the method MTH is further adapted to generate said second mask M2 associated to said second cryptographic environment E2 (illustrated GEN(D, M2)). This step is performed previously to the first step or just before the second step (step 0)). In a non-limitative embodiment, the transformation of said first cryptographic data CA comprises:
generating by means of said electronic device D an intermediary value X which is the result of an XOR of said first cryptographic data CA and said second mask M2 (sub-step illustrated in Fig. 1 GEN(D, X, CA, M2)); and
XORing by means of said electronic device D said intermediary value X with said first mask M1 in order to generate said second cryptographic data CB (sub-step illustrated in Fig. 1 XOR(D, X, M1 , CB)).
Hence, X = CA XOR M2
CB = X XOR M1
Hence, the electronic device D only computes CA XOR M2 resulting in X, then X XOR M1 resulting in CB. During these computations to obtain the second cryptographic data CB, the cryptographic key K1 is never exposed in clear and is never manipulated.
By applying firstly the second mask M2, then secondly the first mask
M1 , it permits to never manipulate the cryptographic key K1 during the computation of the second cryptographic data CB (contrary to a computation where the first mask M1 would be applied to the first cryptographic data CA, then the second mask M2 applied to the intermediate value X to obtain the second cryptographic data CB).
It is to be noted that said result X XOR M1 is equivalent to K1 XOR M2, as it is equal to = CA XOR M2 XOR M1 = K1 XOR M1 XOR M2 XOR M1 .
In a non-limitative embodiment, the second mask M2 is based on a second master mask MM2 and on a second diversifier D2. In a non-limitative variant of said embodiment, said second mask M2= MM2 XOR D2.
The use of a second master mask MM2 in combination with a second diversifier D2 permits to have a strong security as if the second diversifier D2 is broken by an attacker, this latter may not recover the second master mask MM2 unless he attacks at the same time the second master mask MM2, which is more difficult to do.
In a non-limitative embodiment, said second cryptographic data CB is computed on the fly, each time a cryptographic function F2 of the second cryptographic environment E2 needs the cryptographic key K1 to be executed, that is to say before the execution of said cryptographic function F2. In an embodiment, the second cryptographic data CB may be stored in a volatile memory.
In another non-limitative embodiment, said second cryptographic data CB is stored in memory, which may be either non-volatile, or volatile, which may depend on if the cryptographic key K1 is respectively static or transient.
As the second mask M2 is less secure than the first mask M1 , the storage of the cryptographic key K1 via the second cryptographic data CB is less secure than the storage of the cryptographic key K1 via the first cryptographic data CA.
The cryptographic key K1 is stored in the electronic device D in masked value. The second cryptographic data CB is the cryptographic key
K1 which is masked in a less secure way.
Said masked cryptographic key CB will be manipulated within the second cryptographic environment E2 instead of the cryptographic key K1 in clear.
The second cryptographic data CB is paired with the second cryptographic environment E2 as it will be used by at least one cryptographic function F2 of said second cryptographic environment E2. It can only be used by said second cryptographic environment E2.
In a non-limitative embodiment, the pairing is performed by storing in memory a pair CB-L2, that is to say when storing the second cryptographic data CB, the associated second security level L2 is also stored.
In the non-limitative embodiment above-described, the second cryptographic data CB is a degraded way to store the cryptographic key K1 . The second key adapted to the security level Lk2 is a degraded secure level compared to the first key adapted to the security level Lk1 .
The transformation of the first cryptographic data CA into a second cryptographic data CB permits to perform a key transfer of the cryptographic key K1 from the first cryptographic environment E1 (which is secure in the non-limitative embodiment described) to the second cryptographic environment E2 (which is less secure in the non-limitative embodiment described). The key transfer method proposed herein allows to securely modify the mask of the cryptographic key K1 in order to transform it into a key adapted to the needed security level Lk so as to bring it in line with the security level L of the cryptographic environment E which will use said cryptographic key K1 .
The different masks M1 , M2 permit to give respectively the right key adapted to the security level Lk1 , Lk2 to the cryptographic key K1 according to respectively the cryptographic environments E1 , E2 needs, that is to say according to respectively their security levels L1 , L2.
In other words, the different masks M1 , M2 permit to securely store the cryptographic key K1 and to give respectively a different storage security level Lk1 , Lk2 depending respectively on the security level L1 , L2 of the cryptographic environments E1 , E2.
Others known protection memory can be added to reinforce the protection of the storage of the masked cryptographic key.
In step 3) illustrated in Fig. 1 US(D, CA, E1 , CU1 ), said electronic device D uses said first cryptographic data CA within said first cryptographic environment E1 with respect to said first conditions of use CU1 of said cryptographic key K1 .
It is to be noted that in a non-limitative embodiment, a cryptographic function F (F1 described here or F2 described in the following) is part of a command received by the electronic device D from an external entity, such as for example, a remote server. For example, when the electronic device D is a smart card, a cryptographic function F1 is part of an APDU (Application Protocol Data Unit) command.
For each received command, some conditions must be verified before the execution of the command. In non-limitative examples, the conditions may be as following: a challenge is sent before executing the current command, an authentication is performed before executing the current command, a previous command is sent and successfully executed before the current command, a security flag is raised, an electronic device state or an application state is set to a given value etc.
The implementation of all the checks will be performed according to a communication protocol specifications and/or application specifications which specify the commands to be executed.
By this way, the conditions of use CU for executing a cryptographic function F are checked.
When a cryptographic function F1 is executed by the electronic device D, said electronic device D will use the first cryptographic data CA and the first mask M1 , as it knows which mask to use in this case.
In a non-limitative example as illustrated in Fig. 4, the first cryptographic environment E1 comprises a first set of cryptographic functions F1 implementing a mutual authentication MUT_AUTH between said electronic device D and a remote server RS.
In the case of the Global Platform Procedure above-described, the cryptographic key K1 is a set of sessions key K1 1 , K12 which is generated from a static key which can be an authentication private key. This set of sessions key K1 1 , K12 is used for the mutual authentication, that is to say before an external entity is authenticated. In this case, during the mutual authentication, the cryptographic key K1 is highly exposed to attacker. Therefore, it needs a high secure key adapted to the security level, which is in a non-limitative example the first key adapted to the security level Lk1 which is provided through the first cryptographic data CA.
After the mutual authentication occurred, if it is a success, the cryptographic key K1 which will be used is less exposed to an attacker as only the authorized entity, here a remote server RS, may reach this phase. Therefore, it needs a lower secure key adapted to the security level, which is in a non-limitative example the second key adapted to the security level Lk2 which is provided through the second cryptographic data CB.
Hence, the step 4) described hereinafter is performed.
In step 4) illustrated in Fig. 1 US(D, CB, E2, CU2), said electronic device D uses said second cryptographic data CB within said second cryptographic environment E2 with respect to said second conditions of use CU2 of said cryptographic key K1 .
When a cryptographic function F2 is executed by the electronic device D and if it needs the cryptographic key K1 , said electronic device D will use the second cryptographic data CB and the second mask M2 as it knows which mask to use in this case.
It is to be noted that in a non-limitative embodiment, after the mutual authentication is processed, a secure message channel SM is set-up between the electronic device D and the remote server RS to exchange data DAT securely. The electronic device D and the remote server RS exchange data using the cryptographic key K1 which is a set of session keys K1 1 , K12. In a non-limitative example illustrated in Fig. 4, the second cryptographic environment E2 comprises a second set of cryptographic functions F2 implementing a data exchange DAT_E between said electronic device D and a remote server SERV. Said data exchange DAT_E comprises encryption/decryption of data ENCR/DECR, MAC computation, and/or checking integrity of data CHK_MAC.
In the non-limitative example of the cryptographic key K1 which is a set of session keys K1 1 , K12:
- the first session key K1 1 will be used to encrypt data of the electronic device D, and to decrypt incoming data from the remote server RS which has been authenticated before;
- the second session key K12 will be used to check integrity of the incoming data from the remote server RS which has been authenticated before, via a MAC ( Message Authentication Code) in a non-limitative example.
The set of session keys K1 1 , K12 is never exposed.
The data exchange DAT_E is secure as it is performed via a secure message channel SM.
As the security level L2 of the second cryptographic environment E2 is less secure than the first one L1 of the first cryptographic environment E1 , the cryptographic functions F2 comprise less countermeasures, and therefore less complex unit operations than the first cryptographic functions F1 . Hence, the cryptographic functions F2 are faster to be executed and they use less volatile memory for their execution. Therefore, it improves the time and memory performances of the whole communication protocol.
In a non-limitative embodiment where the electronic device D is a secure element such as a smart card, an eSE, an UICC, a micro-SD, the data are exchanged by means of APDU (Application Protocol Data Unit). In a non-limitative embodiment, after the data exchange has been processed, the second cryptographic value CB is erased from the memory of the electronic device D (step 5) illustrated in Fig. 1 CLR(D, CB)). It permits to save some memory. Hence, with the method MTH, the same cryptographic key K1 with two different keys adapted respectively to the security level Lk1 , Lk2 may be used respectively within two different cryptographic environments E1 , E2 with two different security levels L1 , L2 without compromising and exposing the cryptographic key K1 , and with respect to the different conditions of used CU1 , CU2 of said cryptographic key K1 with respectively the two different cryptographic environments E1 , E2.
The method MTH above-described is carried out by the electronic device D adapted to transform at least one cryptographic key K1 into a cryptographic data in order to use said cryptographic key K1 within a first cryptographic environment E1 of said electronic device D with a first security level L1 and within a second cryptographic environment E2 of said electronic device D with a second security level L2, said cryptographic key K1 comprising first and second conditions of use CU1 , CU2 respectively within said first cryptographic environment E1 and said second cryptographic environment E2.
The electronic device D is described with reference to Fig. 2.
In a non-limitative embodiment, the electronic device D is a secure element.
A secure element is a secure component which may perform cryptographic functionalities and is adapted to store a secret key.
In a non-limitative variant, the electronic device D is a smart card. In non-limitative examples, the smart card is an Electronic Identity Card, is a health card, a driving license, a passport, a privacy card, a financial service card, an access card etc. It may be contact or contactless.
In other non-limitative variants, the electronic device D is an eSE (embedded secure element), a micro-SD, an UICC (Universal Integrated Circuit Card . In another non-limitative embodiment, the electronic device D is a mobile phone, a smart phone, a tablet etc. Said electronic device D may comprise a secure element. Said electronic device D comprises an execution platform EP which is adapted to:
generate a first cryptographic data CA from the cryptographic key K1 without exposing said cryptographic key K1 in order to obtain a first key adapted to the security level Lk1 for said cryptographic key K1 , said first cryptographic data CA being paired with said first cryptographic environment E1 (function illustrated GEN(D, CA, K1 , Lk1 , E1 )) ;
transform said first cryptographic data CA into a second cryptographic data CB without exposing said cryptographic key K1 in order to obtain a second key adapted to the security level Lk2 for said cryptographic key K1 , said second key adapted to the security level Lk2 being different from the first key adapted to the security level Lk1 , and said second cryptographic data CB being paired with said second cryptographic environment E2 (function illustrated TRF(D, CA, CB, Lk2, E2));
- use said first cryptographic data CA within said first cryptographic environment E1 with respect to said first conditions of use CU1 of said cryptographic key K1 (function illustrated US(D, CA, E1 , CU1 )); and use said second cryptographic data CB within said second cryptographic environment E2 with respect to said second conditions of use CU2 of said cryptographic key K1 (function illustrated US(D, CB, E2, CU2)).
In a non-limitative embodiment, said execution platform EP is further adapted to:
generate the first mask M1 (function illustrate GEN(D, M1 )); - generate the second mask M2 (function illustrate GEN(D, M2)).
In a non-limitative embodiment, said execution platform EP is further adapted to erase said second cryptographic value CB from the electronic device's memory (function illustrated CLR(D, CB)).
In a non-limitative embodiment, said execution platform EP is further adapted to:
generate an intermediary value X which is the result of an XOR of said first cryptographic data CA and said second mask M2 (sub-function illustrated in Fig. 2 GEN(D, X, CA, M2)); and XORing said intermediary value X with said first mask M1 in order to generate said second cryptographic data CB (sub-function illustrated in Fig. 2 XOR(D, X, M1 , CB)). In a non-limitative embodiment, said execution platform EP is a processor unit or a virtual machine.
In a non-limitative embodiment, said processor unit comprises one or a plurality of processors.
It is to be understood that the present invention is not limited to the aforementioned embodiments.
Hence, a cryptographic key K1 may be transformed into more than two cryptographic data in order to be used respectively within more than two different cryptographic environments E with different associated security level L. Hence, in a non-limitative example, a cryptographic key K1 may be used within three cryptographic environments with three different security levels, one high security level, one medium security level, and one low security level.
Hence, in another non-limitative embodiment, the first security level L1 is lower than the second security level L2 and the first key adapted to the security level Lk1 is lower than the second key adapted to the security level Lk2. Hence, some embodiments of the invention may comprise one or a plurality of the following advantages:
it gains improvement on time and memory performance;
it permits to use a same cryptographic key K1 during a same communication protocol comprising different cryptographic environments E1 , E2 and to take into account its different conditions of use CU1 , CU2 applied to these different cryptographic environments E1 , E2;
as the cryptographic key K1 is securely paired to the appropriate cryptographic environment E1 , E2 via the different masks M1 , M2, it increases the security of the use of the cryptographic key K1 ;
- as the cryptographic key K1 is kept being transferred with the masks changing every time it is used, this will make the value of the cryptographic key K1 not exposed although it is used in a less secure cryptographic environment E2;
it gives a secure cryptographic key management and also it sustains the ability to use a less secure cryptographic environment E2 in a safer way;
it permits to have a multiple levels of security for some cryptographic functions in order to gain some speed improvement. During critical and sensitive processes, the electronic card D will use the strongest security cryptographic environment E1 , and for other processes, the electronic card D will use the degraded security cryptographic environment E2;
it permits to securely use the same cryptographic key K1 for different cryptographic environment E1 , E2 which have different security levels without exposing the cryptographic key K1 ;
it permits to partition the cryptographic data CA, CB used to protect the cryptographic key K1 , as only the first cryptographic data CA may be used with the first cryptographic environment E1 , and only the second cryptographic data CB may be used with the second cryptographic environment E2;
it permits to associate the cryptographic key K1 and a key adapted to the security level Lk only to one cryptographic environment according to its security level L;
as an electronic device D such as a secure element comprises limited resources in term of memory, time processing etc. it permits said electronic device D to improve its performances as the right key adapted to the security level is associated according to the needs of the cryptographic environment E1 , E2;
it avoids using the same cryptographic key with different cryptographic environments with different security levels. In particular, it avoids using the same masked key which is used for the second cryptographic environment E2 (which in the non-limitative example given comprises a lower security level than the first cryptographic environment) within the first cryptographic environment E1 , which could jeopardize the mechanism to make the cryptographic key confidential as the second security level is not enough secured. Hence, it avoids an attacker breaking the cryptographic key, even masked.

Claims

1 - Method (MTH) for protecting a cryptographic key (K1 ) within a first cryptographic environment (E1 ) of an electronic device (D) with a first security level (L1 ) and within a second cryptographic environment (E2) of said electronic device (D) with a second security level (L2), wherein:
• said electronic device being operated to derive a first cryptographic data (CA) from the cryptographic key (K1 ) in order to obtain a first key adapted to the security level (Lk1 ) of said first cryptographic environment (E1 ), said first cryptographic data (CA) being paired with said first cryptographic environment (E1 );
• using said first cryptographic data (CA) within said first cryptographic environment (E1 );
• said electronic device being operated to apply a transformation operation to said first cryptographic data (CA) to provide a second cryptographic data (CB) in order to obtain a second key adapted to the security level (Lk2) of said second cryptographic environment (E1 ), said second key adapted to the security level (Lk2) being different from the first key adapted to the security level (Lk1 ), and said second cryptographic data (CB) being paired with said second cryptographic environment (E2), said operation transformation being configured so that the provided second cryptographic data is derived from the cryptographic key (K1 );
• using said second cryptographic data (CB) within said second cryptographic environment (E2).
2- Method (MTH) according to claim 1 , wherein the first security level (L1 ) is respectively securely higher or lower than the second security level (L2) and the first key adapted to the first security level (Lk1 ) being respectively securely higher or lower than the second key adapted to the second security level (Lk2).
3- Method (MTH) according to any one of the previous claims 1 to 2, wherein the derivation of said first cryptographic data (CA) is function of said cryptographic key (K1 ) and a first mask (M1 ). 4- Method (MTH) according to the previous claim 3, wherein the transformation of said first cryptographic data (CA) into said second cryptographic data (CB) is function of a second mask (M2) and said first mask (M1 ).
5- Method (MTH) according to the previous claim 4, wherein said method (MTH) further comprises generating said first and said second masks (M1 , M2) associated respectively to the first and to the second cryptographic environment (E1 , E2).
6- Method (MTH) according to the previous claim 5 or claim 6, wherein the transformation of said first cryptographic data (CA) comprises:
generating an intermediary value (X) which is the result of an XOR of said first cryptographic data (CA) and said second mask (M2); and - XORing said intermediary value (X) with said first mask (M1 ) in order to generate said second cryptographic data (CB).
7- Method (MTH) according to any one of the previous claims 3 to 6, wherein the generation of the mask (M1 , M2) is based on a master mask (MM1 , MM2) and on a diversifier (D1 , D2).
8- Method (MTH) according to the previous claim 7, wherein the master mask (MM1 , MM2) is common to all the cryptographic keys (K1 ) used by said electronic device (D) and a diversifier (D1 , D2) is unique for each cryptographic key (K1 ).
9- Method (MTH) according to any one of the previous claims 1 to 8, wherein said first cryptographic environment (E1 ) comprises a first set of cryptographic functions (F1 ) and said second cryptographic environment (E2) comprises a second set of cryptographic functions (F2).
10- Method (MTH) according to any one of the previous claims 1 to 9, wherein said first cryptographic environment (E1 ) comprises a first set of cryptographic functions (F1 ) implementing a mutual authentication between said electronic device (D) and a remote server (SERV). 1 1 - Method (MTH) according to any one of the previous claims 1 to 10, wherein said second cryptographic environment (E2) comprises a second set of cryptographic functions (F2) implementing a data exchange between said electronic device (D) and a remote server (SERV).
12- Method (MTH) according to any one of the previous claims 1 to 1 1 , wherein said electronic device (D) is a secure element. 13- Method (MTH) according to claim 12, wherein said secure element is a smart card, an embedded secure element, a micro-SD, an UICC.
14- Electronic device (D) comprising a processor and an instruction memory operated to perform the method for protecting a cryptographic key (K1 ) within a first cryptographic environment (E1 ) of an electronic device (D) with a first security level (L1 ) and within a second cryptographic environment (E2) of said electronic device (D) with a second security level (L2) according to any previous claims.
PCT/EP2016/068448 2015-12-31 2016-08-02 Method for protecting the use of a cryptographic key in two different cryptographic environments Ceased WO2017114601A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201511023157.7A CN106936787A (en) 2015-12-31 2015-12-31 For protecting the method that encryption key is used in two different encryption environment
CN201511023157.7 2015-12-31

Publications (1)

Publication Number Publication Date
WO2017114601A1 true WO2017114601A1 (en) 2017-07-06

Family

ID=56557711

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/EP2016/068448 Ceased WO2017114601A1 (en) 2015-12-31 2016-08-02 Method for protecting the use of a cryptographic key in two different cryptographic environments

Country Status (2)

Country Link
CN (1) CN106936787A (en)
WO (1) WO2017114601A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12219046B2 (en) 2021-03-18 2025-02-04 Changxin Memory Technologies, Inc. Method for pushing key, method for operating file, storage medium, and computer device

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
IL272126A (en) 2020-01-19 2021-07-29 Google Llc Preventing fraud in aggregated network measurements

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090034724A1 (en) * 2007-08-01 2009-02-05 Stmicroelectronics S.A. Masking of data in a calculation
US20100158246A1 (en) * 2007-06-11 2010-06-24 Nxp B.V. Method for authentication and electronic device for performing the authentication

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100158246A1 (en) * 2007-06-11 2010-06-24 Nxp B.V. Method for authentication and electronic device for performing the authentication
US20090034724A1 (en) * 2007-08-01 2009-02-05 Stmicroelectronics S.A. Masking of data in a calculation

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US12219046B2 (en) 2021-03-18 2025-02-04 Changxin Memory Technologies, Inc. Method for pushing key, method for operating file, storage medium, and computer device

Also Published As

Publication number Publication date
CN106936787A (en) 2017-07-07

Similar Documents

Publication Publication Date Title
EP4195583B1 (en) Data encryption method and apparatus, data decryption method and apparatus, and storage medium
JP6612322B2 (en) Data processing method and data processing apparatus
EP2945410B1 (en) Security for mobile applications
EP3387813B1 (en) Mobile device having trusted execution environment
CN107735793B (en) Binding trusted input sessions to trusted output sessions
USRE42762E1 (en) Device and method for authenticating user's access rights to resources
EP2204008B1 (en) Credential provisioning
JP7076482B2 (en) How to secure cryptographic processes with SBOX from higher-order side-channel attacks
CN111130799B (en) Method and system for HTTPS protocol transmission based on TEE
EP3035585B1 (en) S-box selection in white-box cryptographic implementation
US9847879B2 (en) Protection against passive sniffing
CN113672973A (en) Database system of embedded equipment based on RISC-V architecture of trusted execution environment
US20070106907A1 (en) Method and device for encryption and decryption on the fly
WO2018114574A1 (en) Method for secure management of secrets in a hierarchical multi-tenant environment
EP4004773B1 (en) Systems and methods for managing state
CN119276502A (en) Method, system and medium for realizing unified encryption, decryption and desensitization of data across terminals
KR20150040576A (en) Data protection method and apparatus in open environment
CN106936787A (en) For protecting the method that encryption key is used in two different encryption environment
EP3642820B1 (en) Computing device processing expanded data
KR101448711B1 (en) security system and security method through communication encryption
CN112187458B (en) Method, device, system and medium for activating session between equipment end and platform end
EP3009952A1 (en) System and method for protecting a device against attacks on procedure calls by encrypting arguments
US20230275745A1 (en) Device, method and program for secure communication between white boxes
CN120752941A (en) Method and corresponding system for protecting data transmission
CN121530731A (en) A Symmetric White-Box Encryption Method Based on Substitution-Permutation Network Structure

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16745487

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16745487

Country of ref document: EP

Kind code of ref document: A1