CH708123A2 - Process making available a secured time information. - Google Patents
Process making available a secured time information. Download PDFInfo
- Publication number
- CH708123A2 CH708123A2 CH01027/13A CH10272013A CH708123A2 CH 708123 A2 CH708123 A2 CH 708123A2 CH 01027/13 A CH01027/13 A CH 01027/13A CH 10272013 A CH10272013 A CH 10272013A CH 708123 A2 CH708123 A2 CH 708123A2
- Authority
- CH
- Switzerland
- Prior art keywords
- medium
- time information
- secure
- communication
- authentication process
- Prior art date
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/72—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits
- G06F21/725—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information in cryptographic circuits operating on a secure reference time value
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Die Erfindung betrifft ein Verfahren, um insb. für einen Authentifizierungsprozess eine gesicherte Zeitinformation (11) zur Verfügung zu stellen. Ein Benutzermedium (1) umfasst ein erstes Kommunikationsmodul (20) und eine erste gesicherte Umgebung (GU) (22), und ein zweites Medium (2) ein zweites Kommunikationsmodul (21). Das Verfahren umfasst in einem ersten Schritt das Übermitteln einer Referenzzeitinformation (10) an die erste gesicherte Umgebung (22), in einem zweiten Schritt das Erstellen einer Kommunikationsverbindung zwischen dem ersten Kommunikationsmodul (20) und dem zweiten Kommunikationsmodul (21) und in einem dritten Schritt das Übermitteln einer auf der Referenzzeitinformation (10) beruhenden gesicherten Zeitinformation (11) an das zweite Medium und/oder das Verwenden der auf der Referenzzeitinformation (10) beruhenden gesicherten Zeitinformation (11) für den Authentifizierungsprozess.The invention relates to a method in order in particular to provide secure time information (11) for an authentication process. A user medium (1) comprises a first communication module (20) and a first secured environment (GU) (22), and a second medium (2) comprises a second communication module (21). The method comprises, in a first step, transmitting reference time information (10) to the first secured environment (22), in a second step establishing a communication connection between the first communication module (20) and the second communication module (21) and in a third step transmitting secure time information (11) based on the reference time information (10) to the second medium and / or using the secure time information (11) for the authentication process based on the reference time information (10).
Description
[0001] Die Erfindung bezieht sich auf das Gebiet der Sicherheitstechnik und der sicheren Datenübertragung und insbesondere auf Medien welche zu einem Authentifizierungsprozess befähigt sind und welche dafür eine Zeitinformation verwenden. The invention relates to the field of security technology and secure data transmission and in particular to media which are capable of an authentication process and which use time information for this purpose.
[0002] Die Erfindung bezieht sich im Speziellen auf ein Verfahren, um für einen Authentifizierungsprozess zwischen einem Benutzermedium (bspw. einem NFC-fähigen Mobiltelefon) und einem zweiten Medium eine gesicherte Zeitinformation zur Verfügung zu stellen. Sie betrifft auch einen Authentifizierungsprozess, ein Kommunikationssystem und ein Kommunikationsmedium sowie Software dafür. Specifically, the invention relates to a method for providing secure time information for an authentication process between a user medium (eg, an NFC-enabled mobile phone) and a second medium. It also concerns an authentication process, a communication system and a communication medium, as well as software for it.
[0003] Derartige Verfahren und Kommunikationssysteme sind beispielsweise aus den Bereichen der Gebäudesicherung und Raumzutrittsberechtigung bekannt. In handelsüblichen Lösungen von Raumzutrittsberechtigungssystemen, beispielsweise in Hotels, kann ein Zimmerschlüssel in Form einer elektronischen Speicherkarte als Benutzermedium eingesetzt werden. Im Beispiel des Hotels berechtigt die elektronische Speicherkarte zum temporären Zutritt zu beispielsweise einem bestimmten Hotelzimmer. Das bestimmte Hotelzimmer ist mit einem Dienstmedium in Form eines Türschloss-Kontrollmoduls ausgestattet, welches mit der elektronischen Speicherkarte kommunizieren kann. Such methods and communication systems are known for example from the fields of building security and room access authorization. In commercially available solutions of room access authorization systems, for example in hotels, a room key in the form of an electronic memory card can be used as the user medium. In the example of the hotel, the electronic memory card entitles to temporary access to, for example, a specific hotel room. The particular hotel room is equipped with a service medium in the form of a door lock control module which can communicate with the electronic memory card.
[0004] Eine weitere verbreitete Anwendung sind Schreib- und Leseprozesse von bzw. auf Wertkarten, elektronischen Tickets oder dergleichen. Auch für solche findet zunächst ein Authentifizierungsprozess statt. Another common application are writing and reading processes from or to prepaid cards, electronic tickets or the like. Even for such an authentication process takes place first.
[0005] Für die Zugangskontrolle oder andere Vorgänge, insbesondere Vorgänge, die einen Authentifizierungsprozess beinhalten, muss oft die genaue Zeit bekannt sein. Bspw. kann die Zeit als Parameter im Authentifizierungsprozess selbst eingehen, so für die Berechnung eines temporären elektronischen Schlüssels. Ergänzend oder alternativ dazu kann - im Dienstradium oder im Benutzermedium - ein Zeitfenster definiert sein, während welchem eine Berechtigung für den Prozess besteht. Bspw. kann bestimmt - sein, in welchem spezifischen Zeitfenster der Zutritt zum bestimmten Hotelzimmer erlaubt ist. Nur in diesem spezifischen Zeitfenster autorisiert das Türschloss die elektronische Speicherkarte nach einem Authentifizierungsprozess zum Öffnen des Türschlosses. Zu diesem Zweck bzw. zu diesen Zwecken muss das Türschloss über eine verlässliche Zeitinformation verfügen. Schliesslich kann die Zeit auch für die Protokollierung eines Prozesses wichtig sein, insbesondere wenn diese Protokollierung sicherheitsrelevant ist. For access control or other operations, particularly operations involving an authentication process, the exact time often needs to be known. For example. Time can be used as a parameter in the authentication process itself, such as for the calculation of a temporary electronic key. Additionally or alternatively, a time window can be defined - in the service radius or in the user medium - during which an authorization for the process exists. For example. can be determined - in which specific time window the entrance to the certain hotel room is allowed. Only in this specific time window does the door lock authorize the electronic memory card after an authentication process to open the door lock. For this purpose or for these purposes, the door lock must have reliable time information. Finally, the time can also be important for the logging of a process, especially if this logging is security-relevant.
[0006] Um eine hohe Sicherheit gewährleisten zu können, ist dabei eine gesicherte Zeitinformation von Vorteil. Mit gesicherter Zeitinformation ist eine manipulationssichere Zeitinformation (Zeitangabe) gemeint, deren Ursprung eine vertrauenswürdige Quelle ist. Typischerweise verfügt dabei im Stand der Technik jedes Türschloss über eine eigene, manipulationsgesicherte Uhr und somit über eine eigene vertrauenswürdige Quelle für die gesicherte Zeitinformation. Diese Uhr ist dabei häufig als Echtzeituhr (real time clock, RTC) ausgebildet. In order to ensure a high level of security, a secure time information is advantageous. By secure time information is meant tamper-proof time information (time indication) whose origin is a trustworthy source. Typically, in the prior art, each door lock has its own, tamper-proof clock and thus its own trusted source for the secure time information. This clock is often designed as a real-time clock (RTC).
[0007] Ein anderes Beispiel ist ein Erstellen einer sicheren Kommunikationsverbindung. Häufig wird beim Einrichten einer Verschlüsselung ein Zeitsignal in der Berechnung mit verwendet. Dies dient unter anderem beispielsweise dazu, mindestens einem Schritt dieser Erstellung der sicheren Kommunikationsverbindung ein Alleinstellungsmerkmal durch eine Verwendung eines sich nicht wiederholenden Zahlenwerts, also eines Zeitwerts (insbesondere eines Absolutzeitwerts) zuzuordnen. Auch Zeitfenster für die Gültigkeit von Authentifizierungszertifikaten können beispielsweise definiert sein. Another example is creating a secure communication connection. Often, when setting up encryption, a time signal is used in the calculation. Among other things, this serves, for example, to allocate a unique selling point to at least one step of this establishment of the secure communication connection by using a non-repeating numerical value, that is to say a time value (in particular an absolute time value). For example, time slots for the validity of authentication certificates can also be defined.
[0008] Die vorgenannten Beispiele finden in vielen Kombinationen auch beispielsweise gleichzeitig Verwendung und dienen lediglich der Illustration von ausgewählten Anwendungen aus einer Vielzahl von Anwendungsmöglichkeiten einer Zeitinformation in einem Dienstmedium. The aforementioned examples are also used in many combinations, for example, simultaneously and serve only to illustrate selected applications from a variety of applications of time information in a service medium.
[0009] Eine ständig laufende, genaue Echtzeituhr, bspw. mit Funkuhr-Funktionalität, ist jedoch verhältnismässig aufwändig und hat - was insbesondere für Standalone-Systeme mit Batteriespeisung ins Gewicht fällt - einen hohen Energieverbrauch. Neben der Herstellung sind auch Wartung und Reparatur aufwändig, zeitintensiv und kostspielig. Die verhältnismässig grosse Komplexität kann sich auch negativ auf Ausfallraten und technische Komplikationen auswirken. Der Stromverbrauch einer RTC fällt insbesondere dann ins Gewicht, wenn eine grosse Anzahl von räumlich verteilten Dienstmedien wie etwa Schlössern in weiträumigen Anlagen vorhanden ist. However, a constantly running, accurate real-time clock, for example with radio clock functionality, is relatively complex and has - which is particularly important for standalone systems with battery power in the weight - a high energy consumption. In addition to the production and maintenance and repair are complex, time-consuming and costly. The relatively high complexity can also have a negative impact on failure rates and technical complications. The power consumption of an RTC is particularly significant when a large number of spatially distributed service media such as locks in large-scale facilities exists.
[0010] Es ist deshalb Aufgabe der Erfindung, ein Verfahren und ein Kommunikationssystem der eingangs genannten Art zu schaffen, welche mindestens einen oben genannten Nachteile mindestens teilweise behebt. It is therefore an object of the invention to provide a method and a communication system of the type mentioned, which at least partially solves at least one of the disadvantages mentioned above.
[0011] Gemäss einem Aspekt der Erfindung geht es um ein Verfahren um insbesondere für einen Authentifizierungsprozess zwischen einem Benutzermedium und einem zweiten Medium (bspw. Dienstmedium) eine gesicherte Zeitinformation zur Verfügung zu stellen. Dabei weist das Benutzermedium ein erstes Kommunikationsmodul und eine erste gesicherte Umgebung und das zweite Medium ein zweites Kommunikationsmodul auf. Das Verfahren umfasst folgende Schritte: Schritt 1: Übermitteln einer Referenzzeitinformation an die erste gesicherte Umgebung - von einer vertrauenswürdigen Quelle ausserhalb des Benutzermediums, Schritt 2: Erstellen einer Kommunikationsverbindung zwischen dem ersten Kommunikationsmodul und dem zweiten Kommunikationsmodul, Schritt 3: Übermitteln einer auf der Referenzzeitinformation beruhenden gesicherten Zeitinformation an das zweite Medium und/oder Verwenden der auf der Referenzzeitinformation beruhenden gesicherten Zeitinformation für den Authentifizierungsprozess.According to one aspect of the invention, there is a method in particular for an authentication process between a user medium and a second medium (eg service medium) to provide a secure time information available. In this case, the user medium has a first communication module and a first secured environment and the second medium has a second communication module. The method comprises the following steps: Step 1: Transfer reference time information to the first secure environment - from a trusted source outside the user medium, Step 2: Create a communication connection between the first communication module and the second communication module, Step 3: Transmitting a secure time information based on the reference time information to the second medium and / or using the time information for the authentication process based on the reference time information.
[0012] Dabei ist das Benutzermedium i.A. das mobile Medium, das vom Benutzer mitgetragen wird. Das zweite Medium ist oft ortsfest oder fest mit einer Einrichtung (bspw. Fahrzeug oder Terminal) verbunden und fest mit dem Dienst verknüpft, der in Anspruch genommen werden soll. Oft ist ein Authentifizierungsprozess so, dass sich das Benutzermedium gegenüber dem zweiten Medium authentifiziert, wobei der Benutzer Zugang zu einem Dienst begehrt, zu dem der Zugang via das zweite Medium führt. The user medium i.A. the mobile medium that is carried by the user. The second medium is often fixed or fixed to a device (eg, vehicle or terminal) and firmly linked to the service that is to be used. Often, an authentication process is such that the user medium authenticates to the second medium, the user desiring access to a service to which access via the second medium leads.
[0013] Das Verfahren gemäss einem Aspekt der Erfindung zeichnet sich dadurch aus, dass erstens das Benutzermedium als eine Art Vermittler der Zeitinformation verwendet wird. Die Zeit wird also nicht direkt von der vertrauenswürdigen Quelle an das zweite Medium übertragen, sondern eben über das Benutzermedium - oder alternativ wird die Zeitinformation sonstwie im Authentifizierungsprozess verwendet, bspw. wenn dieser durch das Benutzermedium selbst durchgeführt wird. Zweitens zeichnet sich das Vorgehen dadurch aus, dass eine Gesicherte Umgebung (GU) des Benutzermediums für die Speicherung und ggf. Ermittlung der Zeit verwendet wird. The method according to one aspect of the invention is characterized in that, firstly, the user medium is used as a kind of mediator of the time information. The time is thus not transmitted directly from the trusted source to the second medium, but just via the user medium - or alternatively the time information is otherwise used in the authentication process, for example when it is performed by the user medium itself. Secondly, the procedure is characterized by the fact that a secure environment (GU) of the user medium is used for the storage and possibly determination of the time.
[0014] Eine GU ist beispielsweise eine so genannte sichere Umgebung (Englisch: secure environment (SE); oft findet man dafür auch den Begriff Secure dement (SE) in der Literatur). Sichere Umgebungen (SEs) als Chips mit CPU und Speicher und mit normierten Sicherheitsstandards sind mit für unterschiedliche Anwendungen erhältlich. A GU is, for example, a so-called secure environment (English: secure environment (SE), often one also finds the term Secure dement (SE) in the literature). Secure environments (SEs) as chips with CPU and memory and with standardized security standards are available for different applications.
[0015] Ein SE umfasst einen eigenen sicheren Prozessor und einen eigenen sicheren Speicher. Beispielsweise kann der sichere Speicher eines SE verschiedene Teile umfassen, etwa einen Arbeitsspeicher und einen Datenspeicher. Ein SE ist typischerweise in Form eines Sicherheitschips ausgebildet. Dabei ist unter Sicherheitschip ein integrierter Schaltkreis zu verstehen, also eine elektronische Schaltung auf einem Substrat. Ein Sicherheitschip ist beispielsweise ein monolithisches Halbleitersubstrat mit elektronischen Elementen und Leitungen. Ein SE kann dabei insbesondere aus mehreren räumlich getrennt angeordneten aber funktional verbundenen Bereichen bzw. Teilen des Sicherheitschips bestehen, um unbefugtes Auslesen zu erschweren. An SE comprises its own secure processor and its own secure memory. For example, the secure memory of an SE may include various parts, such as a memory and a data memory. An SE is typically in the form of a security chip. In this case, a security chip is an integrated circuit, that is to say an electronic circuit on a substrate. A security chip is for example a monolithic semiconductor substrate with electronic elements and lines. An SE may in particular consist of several spatially separated but functionally connected areas or parts of the security chip to make it difficult to read unauthorized.
[0016] Als Alternative zu einem dedizierten Chip kann eine GU auch als sogenannte «Trusted Zone» ausgebildet sein, d.h. als Bereich eines Chips (bspw. umfassend mindestens einen CPU-Kern und Speicher), welcher funktional einem SE entspricht. Auch in dieser umfasst die GU sichere Prozessormittel und sichere Speichermittel. As an alternative to a dedicated chip, a GU can also be designed as a so-called "Trusted Zone", i. E. as the area of a chip (eg comprising at least one CPU core and memory) which functionally corresponds to an SE. Here, too, the JV comprises secure processor means and secure storage means.
[0017] Ein SE bzw. eine «Trusted Zone» kann beispielsweise von einer SIM-Karte umfasst sein, von einer Speicherkarte (so genannte memory card, wie z.B. einer SD-Karte, MicroSD-Karte oder dergleichen) umfasst sein oder von anderen elektronischen Geräten wie z.B. Mobiltelephonen, Uhren, RPID-Karten, RFID-Lesegeräten, Schlüsseln mit Mikrochips, Schlössern, Verkaufsautomaten, Zahlungsterminals, portablen elektronischen Geräten wie etwa Tabletcomputern und Ähnlichem bzw. deren Modulen umfasst sein. An SE or a "Trusted Zone" can for example be encompassed by a SIM card, by a memory card (so-called memory card, such as an SD card, MicroSD card or the like) includes his or other electronic Devices such as Includes mobile phones, watches, RPID cards, RFID readers, keys with microchips, locks, vending machines, payment terminals, portable electronic devices such as tablet computers and the like or their modules.
[0018] Ein SE bzw. eine, Trusted Zone kann dabei Anforderungen an die Vertrauenswürdigkeit nach verschiedenen bekannten Normen erfüllen bzw. Anforderungen von bekannten Sicherheitslevels erfüllen. Beispielsweise kann ein SE ein bestimmtes so genanntes EAL (Evaluation Assurance Level) aufweisen. Diese EALs existieren in sieben Stufen (von EAL1 bis EAL7). Die gesicherten Umgebungen für die verschiedenen Aspekte der Erfindung entsprechen bspw. mindestens EAL2, mindestens EAL3 oder mindestens EAL4. An SE or a, Trusted Zone can fulfill requirements for the trustworthiness according to various known standards or fulfill requirements of known security levels. For example, an SE may have a specific evaluation assurance level (EAL). These EALs exist in seven stages (from EAL1 to EAL7). The secure environments for the various aspects of the invention correspond, for example, at least EAL2, at least EAL3 or at least EAL4.
[0019] Eine GU kann beispielsweise aber auch mindestens teilweise ausserhalb eines dedizierten Chips eines SE - bzw. einer Trusted Zone - ausgebildete Elemente umfassen. Eine GU kann ganz allgemein sichere Prozessormittel und einen eigenen sicheren Speicher umfassen. Beispielsweise umfasst der sichere Speicher einer GU verschiedene Teile, etwa einen Arbeitsspeicher und einen Datenspeicher. Eine GU ’ kann dabei insbesondere aus mehreren räumlich getrennt angeordneten aber funktional verbundenen Elementen bestehen, um unbefugtes Auslesen zu erschweren. However, a GU may, for example, at least partially outside of a dedicated chip of a SE - or a Trusted Zone - comprise trained elements. A GU can generally include secure processor means and its own secure memory. For example, the secure memory of a GU includes various parts, such as a memory and a data memory. A GU 'can in particular consist of several spatially separated but functionally connected elements to complicate unauthorized reading.
[0020] Es sind auch Lösungen mit virtualisierten gesicherten Umgebungen möglich (bspw. im Rahmen einer «Cloud»-Lösung), wobei auch eine solche physisch nicht im Medium angeordnete sichere Umgebung einem Medium eineindeutig zugeordnet ist und denselben Sicherheitsanforderungen entspricht wie die physisch in einem monolithisch integrierten Prozessor vorhandenen gesicherten Umgebungen. Solutions are also possible with virtualized secure environments (for example in the context of a "cloud" solution), whereby even such a physically non-mediated secure environment is uniquely associated with a medium and meets the same security requirements as the physical one monolithic integrated processor existing secure environments.
[0021] Eine GU ist ganz allgemein als funktionelle Einheit zu verstehen, welche für ein manipulationssicheres und lesegeschütztes Aufbewahren und Verarbeiten von Daten eingerichtet ist und also funktionell einem «Secure Element» gemäss NFC-Standards, bspw. GlobalPlatform-Spezifikationen, entspricht. Eine GU kann demnach eine funktionelle Einheit sein, welche befähigt ist, als «Secure Element» gemäss NFC-Standards und/oder als «Teilnehmer-Identitätsmodul» (Subscriber Identity Module (SIM)) eines mobilen Endgeräts in einem Mobiltelefonnetz zu dienen. A JV is to be understood in general terms as a functional unit which is set up for tamper-proof and read-protected storage and processing of data and thus functionally corresponds to a "secure element" in accordance with NFC standards, for example GlobalPlatform specifications. A GU can therefore be a functional entity which is capable of serving as a "Secure Element" according to NFC standards and / or as a Subscriber Identity Module (SIM) of a mobile terminal in a mobile telephone network.
[0022] In der GU sind insbesondere bspw. die Daten gespeichert, welche im Rahmen eines Authentifizierungsprozesses das Medium mit der GU (z.B. Benutzermedium) gegenüber einem anderen Medium (z.B. Dienstmedium) identifizieren. In particular, the GU stores, for example, the data which, as part of an authentication process, identifies the medium with the GU (for example user medium) with respect to another medium (for example service medium).
[0023] Beim vorstehend beschriebenen Verfahren kann Schritt 2 nach Schritt 1, mindestens teilweise gleichzeitig oder vor Schritt 1 erfolgen. In the method described above, step 2 may take place after step 1, at least partially simultaneously or before step 1.
[0024] Unter «Medium» ist dabei erstens ein elektronisches Gerät (Hardware) zu verstehen, welches ein Datenverarbeitungsmittel umfasst. Das Datenverarbeitungsmittel kann dabei als Software und/oder als mindestens ein Teil des elektronischen Geräts ausgebildet sein. Zweitens kann ein Medium auch ein emuliertes Medium sein, d.h. eine Entität, die durch auf einem Rechnersystem Eigenschaften eines elektronischen Gerätes nachbildet. By "medium" is firstly an electronic device (hardware) to understand, which includes a data processing means. The data processing means can be designed as software and / or as at least a part of the electronic device. Second, a medium may also be an emulated medium, i. an entity that simulates the properties of an electronic device on a computer system.
[0025] Sowohl das das zweite Medium als auch das Benutzermedium sind je ein Medium in diesem Sinn. Ein Medium kann keine, eine oder mehrere GU umfassen. Umfasst ein Medium mehr als eine GU in einer physisch verbundenen (d.h. durch Kontaktschluss miteinander verbundenen) funktionalen Einheit, so ist das Medium als eine mehrere GU umfassende Einheit zu verstehen. Beispielsweise sind eine erste GU in einer SIM-Karte und eine zweite GU in einem diese SIM-Karte umfassenden Mobiltelephon als Teil eines einzigen Mediums zu verstehen, nämlich des Mobiltelephons. Both the second medium and the user medium are each a medium in this sense. A medium may not comprise one, one or more GUs. If a medium comprises more than one GU in a physically connected (i.e., connected by contact closure) functional unit, then the medium is to be understood as a unit comprising several GUs. For example, a first GU in a SIM card and a second GU in a mobile phone comprising this SIM card are to be understood as part of a single medium, namely the mobile phone.
[0026] Ein Authentifizierungsprozess ist ein Erbringen eines Nachweises, also eine Verifizierung, einer behaupteten Eigenschaft eines Kommunikationspartners. Typischerweise wird eine Identität, eine Zahlungsberechtigung bzw. -fähigkeit, eine Bezugsberechtigung und/oder eine Zugangsberechtigung eines Kommunikationspartners verifiziert. Bei erfolgreicher Authentifizierung erfolgt eine abschliessende Bestätigung. Diese abschliessende Bestätigung wird auch als Autorisierung bezeichnet Gemäss einer Gruppe von Ausführungsformen wird als vertrauenswürdige Quelle ein vertrauenswürdiger Vermittler (trusted Service manager, TSM) verwendet. Trusted Service Managers sind aus dem Gebiet der Nahfeldkommunikation (NFC) bekannt und haben fest definierte Eigenschaften, bspw. gemäss GlobalPlatform, GSM Association, oder NFC Forum. An authentication process is a provision of a proof, that is to say a verification, of an alleged property of a communication partner. Typically, an identity, a payment entitlement or ability, a subscription right and / or an access authorization of a communication partner are verified. Upon successful authentication, a final confirmation will be issued. This final confirmation is also referred to as authorization. According to a group of embodiments, trusted service manager (TSM) is used as the trusted source. Trusted Service Managers are well-known in the field of Near Field Communication (NFC) and have well-defined characteristics, eg according to GlobalPlatform, GSM Association, or NFC Forum.
[0027] Ein vertrauenswürdiger Vermittler (trusted service manager, TSM) ist derart ausgebildet, dass er zu einer sicheren Übermittlung von Informationen in eine GU befähigt ist. Die Übermittlung erfolgt dabei gesichert und manipulationsgeschützt. Die Übermittlung kann dabei über physischen Kontakt zwischen TSM und GU erfolgen, oder die Übermittlung kann frei von physischem Kontakt zwischen TSM und GU erfolgen. Ein typisches Beispiel eines TSM ist ein von einem Anbieter eines Mobiltelephonnetzes (mobile network operator MNO) zur Verfügung gestellter entsprechender Server, welcher durch das Mobiltelephonnetz Daten frei von physischem Kontakt und gesichert an eine GU in einem Mobiltelephon übermittelt. A trusted service manager (TSM) is designed to be able to securely transmit information to a JV. The transmission takes place secured and tamper-proof. The transmission may be via physical contact between TSM and GU, or the transmission may be free of physical contact between TSM and GU. A typical example of a TSM is a corresponding server provided by a mobile network operator (MNO) provider which transmits data free of physical contact and secured to a GU in a mobile telephone through the mobile telephone network.
[0028] Die Referenzzeitinformation umfasst eine Zeitangabe, welche einer sicheren und manipulationsgeschützten, zuverlässigen Zeitquelle entstammt. Sicherheit, Manipulationsschutz und Zuverlässigkeit dieser Zeitquelle entsprechen dabei je nach Anwendung verschiedenen Kriterien. Die Referenzzeitinformation kann dabei der vertrauenswürdigen Quelle zur Verfügung gestellt werden, oder diese kann eine genaue Uhr aufweisen und die Referenzzeitinformation von sich aus zur Verfügung stellen. The reference time information comprises a time indication which originates from a secure and manipulation-protected, reliable time source. Security, tamper protection and reliability of this time source correspond to different criteria depending on the application. The reference time information can be made available to the trustworthy source, or it can have an accurate clock and make the reference time information available on its own.
[0029] In dem Verfahren gemäss einem Aspekt der Erfindung wird eine Referenzzeitinformation an eine erste GU eines Benutzermediums übermittelt. Eine solche Referenzzeitinformation kann bspw. eine einfache, genaue Angabe der aktuellen Zeit sein. Nach dieser Übermittlung verfügt das Benutzermedium, und darin die erste GU, über eine Zeitangabe, welche einer sicheren und manipulationsgeschützten, zuverlässigen Zeitquelle entstammt. In the method according to one aspect of the invention, reference time information is transmitted to a first GU of a user medium. Such reference time information may be, for example, a simple, accurate indication of the current time. After this transmission, the user medium, and therein the first GU, has an indication of time which originates from a secure and manipulation-protected, reliable time source.
[0030] Indem eine für den Authentifizierungsprozess verwendbare gesicherte Zeitinformation mit dem hier beschriebenen Verfahren via Benutzermedium zur Verfügung gestellt wird, können die gestellten Aufgaben erfüllt werden. So kann ohne Funkuhr-Funktionalität und ohne direkte Kommunikationsverbindung zwischen dem Dienstmedium und einem sicheren Server stets gewährleistet sein, dass eine Uhr im Dienstmedium die richtige Zeit aufweist. Dies kann auch dann der Fall sein, wenn die Uhr im Dienstmedium nicht ständig läuft, sondern bspw. erst für den Authentifizierungsprozess in Gang gesetzt wird. By providing a secure time information which can be used for the authentication process with the method described here via user medium, the set tasks can be fulfilled. Thus, without radio clock functionality and without a direct communication connection between the service medium and a secure server, it can always be ensured that a clock in the service medium has the correct time. This may also be the case if the clock in the service medium is not constantly running, but, for example, is only set in motion for the authentication process.
[0031] Das erfindungsgemässe Vorgehen kann sogar so genutzt werden, dass das Dienstmedium beispielsweise gar keine eigene Echtzeituhr und gar keinen Zeitgeber aufweisen muss. The inventive method can even be used so that the service medium, for example, no own real-time clock and no timer must have.
[0032] Als andere alternative Möglichkeit kann der Authentifizierungsprozess auch im Benutzermedium selbst durchgeführt werden. Das zweite Medium (Dienstmedium) kann dann in Vertauschung der Rollen rein passiv ausgestaltet sein, bspw. als so genannter «Tag». Indem Authentifizierungsprozess und erfindungsgemäss die gesicherte Zeitinformation in der GU lokalisiert sind, ist die Authentifizierung auch dann manipulationssicher, wenn das Benutzermedium nicht kontrolliert ist. As another alternative possibility, the authentication process can also be carried out in the user medium itself. The second medium (service medium) can then be designed purely passive in exchange of the roles, for example as a so-called "day". By the authentication process and according to the invention, the secure time information is located in the GU, the authentication is tamper-proof even if the user medium is not controlled.
[0033] Ganz allgemein ein Vorteil dieses Verfahrens ist eine hohe Manipulationssicherheit der Zeitinformation. Obwohl das Benutzermedium in den Händen eines Benutzers ist und also an sich auch Manipulationsversuchen ausgesetzt sein kann, wird durch die Nutzung der GU sichergestellt, dass die Zeitinformation sicher ist. In general, an advantage of this method is a high security of manipulation of the time information. Although the user medium is in the hands of a user and thus may be subject to manipulation attempts as well, the use of the GU ensures that the time information is secure.
[0034] Somit erlaubt das Verfahren, ein Dienstmedium mit einfachem Aufbau zu verwenden; welches schnell, einfach und kostengünstig hergestellt werden kann und einfach und weniger häufig gewartet werden muss. Auch können ausfallsichere und wenig störanfällige Dienstmedien verwendet werden. Thus, the method allows to use a service medium with a simple structure; which can be made quickly, easily and inexpensively and requires easy and less frequent maintenance. It is also possible to use fail-safe and low-interference service media.
[0035] In Ausführungsformen kann beispielsweise bei jedem Aufbau der Kommunikationsverbindung zwischen dem ersten und dem zweiten Kommunikationsmodul die Möglichkeit bestehen, vom Benutzermedium an das Dienstmedium eine gesicherte Zeitinformation zu übermitteln. Somit kann etwa bei jeder Kommunikation zwischen Benutzermedium und Dienstmedium das Dienstmedium vom Benutzermedium erneut mit der gesicherten Zeitinformation versehen werden. In embodiments, for example, each time the communication connection between the first and the second communication module is established, it is possible to transmit secured time information from the user medium to the service medium. Thus, about every communication between user medium and service medium, the service medium from the user medium can be provided again with the secure time information.
[0036] Somit kann das Dienstmedium beispielsweise frei von einer eigenen Zeitquelle oder Uhr ausgebildet sein und die gesicherte Zeitinformation bei jeder Kommunikation zwischen Benutzermedium und Dienstmedium erneut von der ersten GU zur Verfügung gestellt bekommen - oder wie erwähnt kann der Authentifizierungsprozess gleich im Benutzermedium stattfinden. Thus, the service medium can be formed, for example, free of its own time source or clock and get the secured time information provided again by the first GU in each communication between the user medium and service medium - or as mentioned, the authentication process can take place right in the user medium.
[0037] Die gesicherte Zeitinformation kann wie folgt auf der Referenzzeitinformation beruhen: die gesicherte Zeitinformation umfasst eine Zeitangabe, welche in einem Zusammenhang mit der Referenzzeitinformation steht und auf dieser beruht. Dadurch steht die gesicherte Zeitinformation in einem eindeutigen Zusammenhang mit der Zeitangabe, welche der sicheren und manipulationsgeschützten, zuverlässigen Zeitquelle entstammt. Die gesicherte Zeitinformation umfasst daher eine Zeitangabe, welche gesichert und manipulationsgeschützt ist und einer vertrauenswürdigen Zeitquelle entstammt. The secured time information may be based on the reference time information as follows: the secured time information includes a time indication which is related to and based on the reference time information. As a result, the secure time information is uniquely related to the time indication which originates from the secure and manipulation-protected, reliable time source. The secured time information therefore includes a time indication which is secured and protected against manipulation and originates from a trusted time source.
[0038] In einer ersten Gruppe von Ausführungsformen («online»-Ausführungsformen) besteht eine Kommunikationsverbindung zwischen der vertrauenswürdigen Zeitquelle und dem Benutzermedium einerseits und zwischen dem Benutzermedium und dem zweiten Medium («Dienstmedium») andererseits gleichzeitig. In dieser Gruppe von Ausführungsformen hat das Benutzermedium die Rolle eines Relais, welches die Information über die Zeit im Wesentlichen einfach weitergibt, wobei optional ein Verarbeitungsschritt stattfinden kann. In a first group of embodiments ("online" embodiments) there is a communication link between the trusted time source and the user medium on the one hand and between the user medium and the second medium ("service medium") on the other hand simultaneously. In this group of embodiments, the user medium has the role of a relay that essentially forwards the information over time, optionally with a processing step taking place.
[0039] Beispielsweise kann die gesicherte Zeitinformation die Referenzzeitinformation sein bzw. diese umfassen. Optional kann auch ein zeitlicher Offset vorgesehen sein, der bspw. einer vorbekannten Verarbeitungszeit (zeitlicher Abstand zwischen Schritten 1 und 3) entsprechen kann. Damit kann im Dienstmedium beispielsweise ein gesicherter aktueller Zeitpunkt relativ zur Referenzzeitinformation nachvollzogen werden. Auch damit kann im Dienstmedium ein gesicherter aktueller Zeitpunkt relativ zur Referenzzeitinformation nachvollzogen werden. In einer Ausführungsform des Verfahrens kann die gesicherte Zeitinformation der Referenzzeitinformation entsprechen, insbesondere wenn die Zeitdifferenz zwischen Schritt 1 und Schritt 3 klein ist oder keine entsprechende Zeitdifferenz besteht. For example, the saved time information may be or include the reference time information. Optionally, a time offset can also be provided which, for example, can correspond to a previously known processing time (time interval between steps 1 and 3). Thus, for example, a saved current time relative to the reference time information can be traced in the service medium. Even so, a secured current time relative to the reference time information can be reconstructed in the service medium. In one embodiment of the method, the saved time information may correspond to the reference time information, in particular if the time difference between step 1 and step 3 is small or there is no corresponding time difference.
[0040] Als optionales Merkmal umfasst im oben beschriebenen Verfahren demnach die gesicherte Zeitinformation die Referenzzeitinformation, und Schritt 3 erfolgt entweder gleichzeitig mit Schritt 1 oder unmittelbar nach Schritt 1. As an optional feature, in the above-described method, therefore, the saved time information includes the reference time information, and step 3 is performed either simultaneously with step 1 or immediately after step 1.
[0041] Je kleiner der Zeitunterschied zwischen den beiden Übermittlungen ist, desto kleiner ist ein möglicher Fehler in der gesicherten Zeitinformation. The smaller the time difference between the two transmissions, the smaller is a possible error in the secure time information.
[0042] Vereinfach ausgedrückt erlaubt dieses optionale Merkmal, dass das Dienstmedium zeitlich direkt oder fast direkt mit der Quelle der Zeitinformation verbunden ist und über das Benutzermedium eine gesicherte Zeitinformation zur Verfügung gestellt bekommt. Das Benutzermedium dient dabei als Verbindung zur Quelle, welche ohne zeitliche Verzögerung oder mit nur einer minimalen zeitlichen Verzögerung funktioniert. Daher ist ein Risiko, dass die gesicherte Zeitinformation mit einem zeitlichen Fehler behaftet ist, relativ gering. Zudem muss das Benutzermedium den zeitlichen Unterschied zwischen Schritt 1 und Schritt 3 nicht zeitlich präzis bemessen an das Dienstmedium weitergeben. Es können auch Mechanismen vorgesehen sein, die das Resultat der Authentifizierung verwerfen oder eine solche gar nicht erlauben, wenn nicht verifiziert ist, dass das Benutzermedium mit der vertrauenswürdigen Quelle in Kommunikationsverbindung steht oder wenn der zeitliche Zusammenhang zwischen Schritten 1 und 3 nicht verifiziert ist. In simple terms, this optional feature allows the service medium to be timed directly or almost directly connected to the source of time information and to be provided with secure time information via the user medium. The user medium serves as a connection to the source, which works without delay or with only a minimal delay. Therefore, a risk that the secured time information is subject to a time error is relatively low. In addition, the user medium does not have to divide the time difference between step 1 and step 3 precisely in terms of time to the service medium. Mechanisms may also be provided which discard or do not permit the result of the authentication if it is not verified that the user medium is in communication with the trusted source or if the temporal relationship between steps 1 and 3 is not verified.
[0043] Beispielsweise kann in dieser Ausführungsform das Benutzermedium die Referenzzeitinformation direkt verarbeiten und die entsprechende gesicherte Zeitinformation an das Dienstmedium übermitteln, ohne die Referenzzeitinformation und/oder die gesicherte Zeitinformation zu speichern und/oder weiterzuverarbeiten. Dies erlaubt eine einfache und schlanke Struktur des Benutzermediums. For example, in this embodiment, the user medium directly process the reference time information and transmit the corresponding saved time information to the service medium without storing and / or processing the reference time information and / or the saved time information. This allows a simple and streamlined structure of the user medium.
[0044] In der ersten Gruppe von Ausführungsformen ist das Benutzermedium bevorzugt mit Mitteln für die mobile Kommunikation versehen, bspw. über ein Mobiltelefon-(Mobilfunk-) Netz und/oder über ein WLAN. Insbesondere kann das Benutzermedium in dieser wie auch in anderen Ausführungsformen als Mobiltelefon ausgestaltet sein. In the first group of embodiments, the user medium is preferably provided with means for mobile communication, for example via a mobile telephone (mobile) network and / or via a WLAN. In particular, the user medium can be designed as a mobile phone in this as well as in other embodiments.
[0045] In einer zweiten Gruppe von Ausführungsformen kann das Übermitteln der Referenzzeitinformation quasi «offline» geschehen, d.h. das Benutzermedium muss während Schritt 3, bzw. unmittelbar davor, nicht mit dem TSM in Kommunikationsverbindung stehen. In a second group of embodiments, the transmission of the reference time information can be done quasi "offline", i. E. The user medium must not be in communication with the TSM during step 3 or immediately before it.
[0046] In Ausführungsform dieser Gruppe erfolgt Schritt 1 zeitlich unabhängig von Schritt 2 und Schritt 3, insbesondere können Schritt 2 und Schritt 3 zu einem anderen Zeitpunkt als Schritt 1 erfolgen. Dabei hängt die gesicherte Zeitinformation funktional mit einem zeitlichen Unterschied zwischen einer Ausführung von Schritt 1 und einer Ausführung von Schritt 3 zusammen. In an embodiment of this group, step 1 takes place independently of time of step 2 and step 3; in particular, step 2 and step 3 can take place at a time other than step 1. In this case, the saved time information is functionally related to a time difference between an execution of step 1 and an execution of step 3.
[0047] Durch dieses Vorgehen ist das Benutzermedium nicht darauf angewiesen, zeitgleich oder zeitnah sowohl mit der vertrauenswürdigen Quelle als auch mit dem Dienstmedium in Kontakt zu stehen. Dies erlaubt einen zeitlich und verfahrenstechnisch flexiblen Einsatz des Verfahrens. By doing so, the user medium is not dependent on being in contact with both the trusted source and the service medium at the same time or in a timely manner. This allows a temporally and procedurally flexible use of the method.
[0048] In dieser Gruppe von Ausführungsformen umfasst die erste GU einen Zeitgeber, insbesondere eine Echtzeituhr (RTC), wobei die Echtzeituhr mindestens einen Teil der gesicherten Zeitinformation liefert. Insbesondere wird dabei der Zeitgeber in Schritt 1 mittels der Referenzzeitinformation zeitlich synchronisiert. In this group of embodiments, the first GU comprises a timer, in particular a real-time clock (RTC), wherein the real-time clock supplies at least part of the saved time information. In particular, the timer is synchronized in time in step 1 by means of the reference time information.
[0049] Je nachdem wie die- gesicherte Zeitinformation auf der Referenzzeitinformation beruht, kann dabei der Zeitgeber (der in Schritt 1 durch die Referenzzeitinformation synchronisiert wurde, wodurch die von ihm gemessene Zeit auf letzterer beruht) die gesicherte Zeitinformation liefern. Depending on how the time information saved is based on the reference time information, the timer (which was synchronized in step 1 by the reference time information, whereby the time measured by it is based on the latter) can provide the saved time information.
[0050] Wie genau die Verarbeitung der Referenzzeitinformation in die gesicherte Zeitinformation erfolgt ist sekundär: Der Zeitgeber kann bspw. auch ohne das erwähnte Synchronisieren betrieben werden und nur den zeitlichen Abstand zwischen Schritt 1 und Schritt 3 liefern. Die gesicherte Zeitinformation wird dann anderswo in der GU aus der gespeicherten Referen2zeitinformation und diesem zeitlichen Abstand berechnet. How exactly the processing of the reference time information in the secured time information is secondary: The timer can, for example, be operated without the mentioned synchronization and provide only the time interval between step 1 and step 3. The saved time information is then calculated elsewhere in the GU from the stored reference time information and this time interval.
[0051] Ein Zeitgeber in der GU ist insbesondere dann von Vorteil, wenn Schritt 1 zeitlich unabhängig von Schritt 2 und Schritt 3 erfolgt. Auf diese Weise wird das Verfahren unabhängig von einer Verbindung zur vertrauenswürdigen Quelle. Die Übermittlung der genauen gesicherten Zeitinformation an das Dienstmedium bzw. der Authentifizierungsprozess kann jederzeit stattfinden, ohne dass durch die fehlende zeitliche Koinzidenz zwischen Schritt 1 und Schritt 3 ein systematischer Fehler entstünde. Je nach Verfügbarkeit kann dabei die Quelle in kurzen oder langen zeitlichen Abständen die Referenzzeitinformation aktualisieren bzw. den Zeitgeber synchronisieren. A timer in the GU is particularly advantageous if step 1 takes place independently of time of step 2 and step 3. In this way, the process becomes independent of any connection to the trusted source. The transmission of the exact secure time information to the service medium or the authentication process can take place at any time, without causing a systematic error by the lack of temporal coincidence between step 1 and step 3. Depending on availability, the source can update the reference time information or synchronize the timer at short or long intervals.
[0052] Auch in Ausführungsformen der zweiten Gruppe dient das Benutzermedium als eine Art Relais zur Übermittlung der Zeit mit den vorstehend diskutierten Vorteilen, allerdings mit dem zusätzlichen Vorteil, dass das Verfahren nicht von einer gleichzeitigen Verbindung mit TSM und Dienstmedium abhängig ist. Also in embodiments of the second group, the user medium serves as a kind of relay for transmitting the time with the advantages discussed above, but with the additional advantage that the method does not depend on a simultaneous connection with TSM and service medium.
[0053] Es kann in Ausführungsformen der zweiten Gruppe vorgesehen sein, dass die Zeitinformation auf dem Benutzermedium periodisch justiert werden muss, mit einer an die Genauigkeit des Zeitgebers im Benutzermedium angepassten Periode. Wenn diese Synchronisation über eine gewisse Zeit nicht möglich ist oder wenn das Benutzermedium neu gestartet wird, so wird in diesen Ausführungsformen die Zeit solange als ungültig betrachtet bis wieder eine Synchronisation erfolgt ist. It may be provided in embodiments of the second group that the time information on the user medium must be periodically adjusted, with a matched to the accuracy of the timer in the user medium period. If this synchronization is not possible for a certain time or if the user medium is restarted, then in these embodiments the time is considered invalid until a synchronization has taken place again.
[0054] Als weiteres optionales Merkmal des Verfahrens in verschiedenen Ausführungsformen (darunter online-Ausführungsformen und «offline»-Ausführungsformen) umfasst das Dienstmedium eine zweite GU, und das zweite Kommunikationsmodul übermittelt in Schritt 3 die gesicherte Zeitinformation an die zweite GU. As another optional feature of the method in various embodiments (including online embodiments and "offline" embodiments), the service medium comprises a second GU, and the second communication module transmits the secured time information to the second GU in step 3.
[0055] Die zweite GU im Dienstmedium bietet den Vorteil einer hohen Sicherheit der gesicherten Zeitinformation und insbesondere einer hohen Manipulationssicherheit auch vor Manipulationen direkt am Dienstmedium. The second GU in the service medium offers the advantage of a high security of the secure time information and in particular a high security against manipulation also directly on the service medium.
[0056] Ein anderes optionales Merkmal des Verfahrens ist, dass das Dienstmedium einen Zeitgeber umfasst. Ein solcher kann in Schritt 3 mittels der gesicherten Zeitinformation zeitlich synchronisiert werden; oder alternativ kann mittels diesem bei einem später stattfindenden Authentifizierungsprozess aus der Referenzzeitinforation die aktuelle Zeit berechnet werden. Another optional feature of the method is that the service medium comprises a timer. Such can be temporally synchronized in step 3 by means of the secure time information; or alternatively, by means of this, the current time can be calculated from the reference time infation in a later-occurring authentication process.
[0057] Ein solcher Zeitgeber im Dienstmedium kann dabei mindesten teilweise oder auch vollständig von der zweiten GU, falls vorhanden, umfasst sein. Dies hat den Vorteil einer hohen Sicherheit und insbesondere einer hohen Manipulationssicherheit der Zeitangabe. Such a timer in the service medium can be at least partially or completely encompassed by the second GU, if present. This has the advantage of a high level of security and, in particular, a high level of manipulation security of the time specification.
[0058] Ein Zeitgeber im Dienstmedium hat den Vorteil, dass das Dienstmedium jederzeit über eine Zeitinformation verfügt. Durch die vom Benutzermedium erhaltene gesicherte Zeitinformation kann ein solcher Dienstmedium-Zeitgeber jederzeit die aktuelle Zeit bestimmen. Die Zeitinformation kann auch für nachfolgende Authentifizierungsprozesse mit Benutzermedien verwendbar sein, welche nicht über eine gesicherte Zeitinformation verfügen. Beispielsweise kann in einem komplexen System vorgesehen sein, dass nur gewisse Benutzer (bspw. der Nachtwächter, der regelmässige Kontrollen durchführt oder eine Wartungsperson) das erfindungsgemässe Verfahren ausführen, während sich für alle anderen nichts ändert. A timer in the service medium has the advantage that the service medium has time information at all times. By the secured time information obtained from the user medium, such a service-medium timer can determine the current time at any time. The time information can also be used for subsequent authentication processes with user media which do not have secure time information. For example, it may be provided in a complex system that only certain users (eg the night watchman performing regular checks or a maintenance person) carry out the method according to the invention while nothing changes for all others.
[0059] In einem anderen Beispiel kann im Dienstmedium etwa die vom ersten GU zur Verfügung gestellte gesicherte Zeitinformation mit der Zeitinformation aus der Echtzeituhr des Dienstmediums verglichen werden, wobei je nach Resultat des Vergleichs bestimmte Schritte eingeleitet werden. Diese Schritte können beispielsweise darin bestehen, dass eine Fehlfunktionswarnung ausgelöst wird und/oder eine Warnung wegen unzureichender Stromzufuhr (beispielsweise Batterien mit ungenügender Leistung) ausgelöst wird. In another example, in the service medium, for example, the secure time information provided by the first GU can be compared with the time information from the real-time clock of the service medium, wherein certain steps are initiated depending on the result of the comparison. For example, these steps may be to trigger a malfunction alert and / or raise a low power alert (eg, insufficiently powered batteries).
[0060] Optional wird die Kommunikationsverbindung in Schritt 2 nach einem bekannten Standard erstellt. Insbesondere wird die Kommunikationsverbindung in Schritt 2 als NFC-, Bluetooth- oder andere kurzreichweitige Kommunikationsverbindung erstellt. Optionally, the communication link is established in step 2 according to a known standard. In particular, the communication link is established in step 2 as an NFC, Bluetooth, or other short-range communication link.
[0061] NFC ist dabei eine Abkürzung des englischen Begriffs Near Field Communication. und bezeichnet einen internationalen Übertragungsstandard zum kontaktlosen Austausch von Daten über kurze Strecken von bis zu 10 cm und einer Datenübertragungsrate von maximal 424 kBit/s. NFC is an abbreviation of the English term Near Field Communication. and denotes an international transmission standard for the contactless exchange of data over short distances of up to 10 cm and a data transfer rate of a maximum of 424 kbit / s.
[0062] Eine Verwendung von bekannten Standards macht die Benutzer- und/oder Dienstmedien vielseitig verwendbar. Die Kommunikationsmodule können dabei auch für weitere Zwecke als der Übermittlung der Referenzzeitinformation bzw. der gesicherten Zeitinformation verwendet werden. Zudem kann das Verfahren beispielsweise auch einfacher auf bereits vorhandene Geräte angewendet werden, wenn das Verfahren und die vorhandenen Geräte bekannte Standards verwenden. [0062] Use of known standards makes the user and / or service media versatile. The communication modules can also be used for other purposes than the transmission of the reference time information or the secure time information. In addition, for example, the method can be more easily applied to existing devices if the method and the existing devices use known standards.
[0063] Als weitere Option wird die Kommunikationsverbindung in Schritt 2 nach einem bekannten gesicherten Standard erstellt, wobei die Kommunikation über die Kommunikationsverbindung insbesondere verschlüsselt erfolgt. As a further option, the communication connection is created in step 2 according to a known secure standard, wherein the communication via the communication connection is particularly encrypted.
[0064] Wenn die Kommunikationsverbindung einen bekannten Standard verwendet, welcher zudem eine Sicherheit der Kommunikationsverbindung gewährleistet, resultiert dies in einer hohen Sicherheit des gesamten beschriebenen Verfahrens. Insbesondere eine Verschlüsselung der Kommunikationsverbindung bietet den Vorteil einer hohen Sicherheit und insbesondere hohen Manipulationssicherheit des Verfahrens. If the communication connection uses a known standard, which also ensures a security of the communication connection, this results in a high security of the entire described method. In particular, an encryption of the communication link offers the advantage of a high level of security and, in particular, high security against manipulation of the method.
[0065] Die Erfindung betrifft auch einen Authentifizierungsprozess zwischen einem Benutzermedium und einem Dienstmedium, wobei zunächst nach dem Verfahren gemäss obiger Beschreibung dem Dienstmedium durch das Benutzermedium eine gesicherte Zeitinformation zur Verfügung gestellt wird und anschliessend die gesicherte Zeitinformation durch das Dienstmedium für die Authentifizierung des Benutzermediums verwendet wird. The invention also relates to an authentication process between a user medium and a service medium, wherein the service medium is provided by the user medium first secured time information according to the method described above and then the secured time information used by the service medium for authentication of the user medium becomes.
[0066] Ein solcher Authentifizierungsprozess hat den Vorteil, dass sowohl das Benutzermedium als auch das Dienstmedium mindestens kurzzeitig über aktuelle Zeitinformationen verfügen, welche manipulationssicher und zuverlässig sind. Dies erlaubt eine hohe Sicherheit beim Authentisieren bei gleichzeitig allen oben erwähnten Vorteilen des Verfahrens, um einem Dienstmedium via ein Benutzermedium eine gesicherte Zeitinformation zur Verfügung zu stellen. Such an authentication process has the advantage that both the user medium and the service medium have current time information at least for a short time, which are tamper-proof and reliable. This allows a high level of security during authentication at the same time as all the above-mentioned advantages of the method in order to provide a service medium with secure time information via a user medium.
[0067] In einer besonderen Ausführungsform des Authentifizierungsprozesses weist das Dienstmedium keinen Zeitgeber oder mindestens keine Echtzeituhr auf. Die Vorteile eines Dienstmediums ohne Echtzeituhr sind bereits weiter oben beschrieben. In a particular embodiment of the authentication process, the service medium has no timer or at least no real-time clock. The advantages of a service medium without real-time clock are already described above.
[0068] Weiter betrifft die Erfindung ein Kommunikationssystem, welches ein Benutzermedium und ein zweites Medium (insbesondere Dienstmedium oder bei der Authentifizierung die passive («Benutzer»-) Rolle einnehmendes Medium) umfasst. Das Benutzermedium umfasst dabei ein erstes Kommunikationsmodul und eine erste gesicherte Umgebung (GU), und das zweite Medium umfasst ein zweites Kommunikationsmodul. Zudem ist das Dienstmedium dazu eingerichtet, einen Authentifizierungsprozess durchzuführen. Die erste GU ist dabei derart ausgebildet, dass sie zu einem Empfang von gesicherten Daten von einer vertrauenswürdigen Quelle (bspw. einem trusted Service manager, TSM) befähigt ist. Die erste GU ist zudem funktional mit dem ersten Kommunikationsmodul verknüpft, und das erste und das zweite Kommunikationsmodul sind derart ausgebildet, dass sie zu einem Aufbau einer Kommunikationsverbindung zwischen sich befähigt sind. Ausserdem ist die erste GU derart ausgebildet, dass sie zu einem Übermitteln einer auf der Referenzzeitinformation beruhenden gesicherten Zeitinformation über die Kommunikationsverbindung an das zweite Medium befähigt oder befähigt ist, einen Authentifizierungsprozess anhand von Daten durchzufuhren, welche vom zweiten Medium empfangen wurden. Furthermore, the invention relates to a communication system, which comprises a user medium and a second medium (in particular service medium or in the authentication, the passive («user») role-taking medium). The user medium comprises a first communication module and a first secure environment (GU), and the second medium comprises a second communication module. In addition, the service medium is set up to perform an authentication process. The first GU is designed such that it is capable of receiving secure data from a trustworthy source (eg a trusted service manager, TSM). The first GU is also operatively linked to the first communication module, and the first and second communication modules are configured to be capable of establishing a communication link between them. Furthermore, the first GU is arranged to be capable of transmitting a secure time information based on the reference time information via the communication connection to the second medium, or capable of performing an authentication process on the basis of data received from the second medium.
[0069] Ein solches Kommunikationssystem kann die oben beschriebenen Verfahren ausführen und weist daher dieselben Vorteile wie die oben beschriebenen Verfahren auf. Dabei sind sowohl die Verfahren, um eine gesicherte Zeitinformation für einen Authentifizierungsprozess zur Verfügung zu stellen gemeint als auch die Authentifizierungsprozesse selbst. Dies gilt jeweils für alle möglichen Kombinationen von als optional beschriebenen Ausführungsformen dieser Verfahren. Die entsprechend beschriebenen Vorteile der Verfahren sind auch Vorteile des jeweiligen sie anwendenden Kommunikationssystems. Such a communication system can carry out the methods described above and therefore has the same advantages as the methods described above. Both the methods for providing secure time information for an authentication process and the authentication processes themselves are meant. This applies to all possible combinations of optionally described embodiments of these methods. The correspondingly described advantages of the methods are also advantages of the respective communication system which uses them.
[0070] Bestimmte spezifisch ausgebildete Kommunikationssysteme eignen sich gut zum Anwenden verschiedener der oben beschriebenen Verfahren. Dies gilt insbesondere für Kommunikationssysteme umfassend die nachstehend genannten optionalen Merkmale. Certain specifically designed communication systems are well suited to employing various of the methods described above. This is especially true for communication systems including the optional features mentioned below.
[0071] Optional kann dass die erste GU derart ausgebildet sein, dass sie zum Empfang der Referenzzeitinformation von der vertrauenswürdigen Quelle und gleichzeitig oder unmittelbar danach zum Übermitteln einer auf der Referenzzeitinformation beruhenden gesicherten Zeitinformation von der ersten GU durch die Kommunikationsverbindung an das Dienstmedium oder zum Durchführen eines Authentifizierungsprozesses befähigt ist. Optionally, the first GU may be arranged to receive the reference time information from the trusted source, and simultaneously or immediately thereafter, to transmit, based on the reference time information, secured time information from the first GU through the communication link to the service medium or to perform an authentication process is enabled.
[0072] Alternativ dazu kann die erste GU optional derart ausgebildet ist, dass sie zum Empfang der Referenzzeitinformation vom TSM und davon zeitlich unabhängig zum Übermitteln einer auf der Referenzzeitinformation beruhenden gesicherten Zeitinformation von der ersten GU durch die Kommunikationsverbindung an das Dienstmedium bzw. zum Durchführen eines Authentifizierungsprozesses befähigt ist. Alternatively, the first GU may be optionally configured to receive the reference time information from the TSM and time independent thereof to transmit a time information based on the reference time information from the first GU through the communication link to the service medium or to perform a Authentication process is enabled.
[0073] In einer optionalen Ausführungsform umfasst das Benutzermedium einen Zeitgeber, bspw. eine Echtzeituhr (RTC). Insbesondere umfasst dabei die erste GU den Zeitgeber vollständig. Eine RTC kann auch teilweise von der ersten GU umfasst sein. In an optional embodiment, the user medium comprises a timer, for example a real-time clock (RTC). In particular, the first GU comprises the timer completely. An RTC may also be partially covered by the first GU.
[0074] Eine andere Option ist, dass das zweite Medium als Dienstmedium eine zweite GU umfasst, wobei die zweite GU funktional mit dem zweiten Kommunikationsmodul verknüpft ist. Another option is that the second medium as service medium comprises a second GU, wherein the second GU is functionally linked to the second communication module.
[0075] Optional umfasst das Dienstmedium einen Zeitgeber, bspw. eine Echtzeituhr. Insbesondere ist die RTC im Dienstmedium dabei mindestens teilweise oder auch vollständig von der zweiten GU umfasst. Optionally, the service medium comprises a timer, for example a real-time clock. In particular, the RTC in the service medium is at least partially or completely encompassed by the second GU.
[0076] Als weitere Option sind das erste und das zweite Kommunikationsmodul derart ausgebildet, dass sie zu einem Aufbau einer insbesondere sicheren Kommunikationsverbindung miteinander nach einem bekannten Standard befähigt sind. Dabei sind das erste und das zweite Kommunikationsmodul insbesondere zum Aufbau einer Kommunikationsverbindung nach NFC, Bluetooth oder anderen bekannten kurzreichweitigen Standards befähigt. As a further option, the first and the second communication module are designed such that they are capable of establishing a particularly secure communication connection with each other according to a known standard. In this case, the first and the second communication module are in particular capable of establishing a communication connection according to NFC, Bluetooth or other known short-range standards.
[0077] Als eine weitere optionale Möglichkeit umfasst die erste GU im Benutzermedium einen ersten Schlüssel und die zweite GU umfasst im Dienstmedium einen zweiten Schlüssel. As a further optional option, the first GU in the user medium comprises a first key and the second GU comprises a second key in the service medium.
[0078] Die Schlüssel in den GUs können zum Aufbau einer gesicherten Kommunikationsverbindung und/oder zur Verschlüsselung der übermittelten Informationen benutzt werden. Dadurch wird das Kommunikationssystem sicher und ist insbesondere von Manipulation geschützt. Der erste und/oder zweite Schlüssel kann dabei insbesondere aus mehreren Teilschlüsseln mit unterschiedlicher Herkunft bestehen. Dies erhöht die Sicherheit zusätzlich. Entsprechende Verfahren und Konfigurationen sind bekannt. The keys in the GUs may be used to establish a secure communication connection and / or to encrypt the transmitted information. As a result, the communication system is secure and is particularly protected from manipulation. The first and / or second key can consist in particular of several subkeys of different origin. This additionally increases security. Corresponding methods and configurations are known.
[0079] In einer optionalen Ausführungsform des Kommunikationssystems ist das Dienstmedium dazu eingerichtet, einen Authentifizierungsprozess durchzuführen, bei welchem das Dienstmedium das Benutzermedium authentifiziert. In an optional embodiment of the communication system, the service medium is adapted to perform an authentication process in which the service medium authenticates the user medium.
[0080] Bei erfolgreicher Authentifizierung erfolgt durch das Dienstmedium eine abschliessende Bestätigung an das Benutzermedium. Diese abschliessende Bestätigung wird auch als Autorisierung bezeichnet. Upon successful authentication, the service medium carries out a final confirmation to the user medium. This final confirmation is also called authorization.
[0081] Optional umfasst das Kommunikationssystem ein Managermedium, welches funktional mit der ersten GU verknüpft ist. Dabei ist die erste GU derart ausgebildet, dass sie zum Empfangen einer Authentifizierungsinformation vom Managermedium befälligt ist. Optionally, the communication system comprises a managerial medium operatively associated with the first GU. In this case, the first GU is designed in such a way that it is liable to receive authentication information from the management medium.
[0082] Unter Managermedium ist dabei ein Medium zu verstehen, welches derart ausgebildet ist, um zu einer Kommunikation mit der ersten GU befähigt zu sein. Das Managermedium wird beispielsweise auch als application backend oder Anwendungsanbietermedium bezeichnet. Dieses Managermedium ist insbesondere dazu befähigt, eine Authentifizierungsinformation von einem TSM zu empfangen. Die Authentifizierungsinformation ist eine Information im ersten GU, welche einen Authentifizierungsprozess zwischen Benutzermedium und Dienstmedium beeinflusst. Dadurch kann das Managermedium im ersten GU zeitlich befristete Berechtigungen bzw. Autorisierungen eintragen, verändern und/oder löschen. By "managerial medium" is meant a medium which is designed to be capable of communicating with the first GU. For example, the manager medium is also referred to as an application backend or application provider medium. This manager medium is particularly capable of receiving authentication information from a TSM. The authentication information is information in the first GU that influences an authentication process between the user medium and the service medium. As a result, the manager medium in the first GU can enter, change and / or delete time-limited authorizations or authorizations.
[0083] Das Managermedium kann dabei über den TSM mit dem ersten GU verbunden sein. Alternativ ist das Managermedium unabhängig vom TSM mit dem ersten GU verbunden; zu diesem Zweck kann es selbst eine GU aufweisen, über welche die Kommunikation mit dem GU des Benutzer- und/oder Dienstmediums läuft. Die Verbindung des Managermediums mit der ersten GU ist aber je nach gewünschtem Sicherheitsstandard nicht dazu befähigt, die von der ersten GU empfangene Referenzzeitinformation zu beeinflussen. Optional kann das TSM auch dem Managermedium eine Zeitangabe übermitteln, welche einer sicheren und manipulationsgeschützten, zuverlässigen Zeitquelle entstammt. Insbesondere kann das TSM dem Managermedium auch die Referenzzeitinformation übermitteln. The manager medium can be connected via the TSM with the first GU. Alternatively, the manager medium is connected to the first GU independently of the TSM; For this purpose, it may itself have a GU, via which the communication with the GU of the user and / or service medium is running. However, depending on the desired security standard, the connection of the managerial medium to the first GU is not capable of influencing the reference time information received by the first GU. Optionally, the TSM may also provide the manager medium with a time indication that is from a secure and tamper-resistant, reliable time source. In particular, the TSM can also transmit the reference time information to the manager medium.
[0084] Ein Managermedium ist einem Beispiel eines Raumzutrittsberechtigungssystems eines Hotels ein Gerät zum Beschreiben und/oder Löschen von Benutzermedien. Dabei sind elektronische Speicherkarten die Benutzermedien und Türschlösser die Dienstmedien. Insbesondere können in diesem Beispiel die Benutzermedien aber auch als Mobiltelephon, virtuelle Speicherkarte und/oder andere Medien ausgebildet sein. A manager medium is an example of a room access authorization system of a hotel, a device for writing and / or deleting user media. Electronic memory cards are the user media and door locks are the service media. In particular, in this example, the user media can also be designed as a mobile phone, virtual memory card and / or other media.
[0085] Weitere bevorzugte Ausführungsformen gehen aus den abhängigen Patentansprüchen hervor. Dabei sind Merkmale der Verfahrensansprüche sinngemäss mit den Vorrichtungsansprüchen kombinierbar und umgekehrt. Further preferred embodiments are evident from the dependent claims. Characteristics of the method claims are analogously combined with the device claims and vice versa.
[0086] Im Folgenden wird der Erfindungsgegenstand anhand von bevorzugten Ausführungsbeispielen, welche in den beiliegenden Zeichnungen dargestellt sind, näher erläutert. Es zeigen jeweils schematisch: <tb>Fig. 1<SEP>ein Kommunikationssystem; <tb>Fig. 2<SEP>ein Kommunikationssystem wie in Fig. 1 aber zusätzlich mit einer zweiten GU; <tb>Fig. 3<SEP>ein Kommunikationssystem wie in Fig. 1 aber zusätzlich mit einer RTC im Benutzermedium; <tb>Fig. 4<SEP>ein Kommunikationssystem wie in Fig. 3 aber zusätzlich einer zweiten GU und einem ersten und zweiten Schlüssel; <tb>Fig. 5<SEP>ein Kommunikationssystem wie in Fig. 4 aber zusätzlich mit einem Managermedium; <tb>Fig. 6<SEP>ein Kommunikationssystem, bei welchem das zweite Medium bei der Authentifizierung eine passive Rolle hat.In the following, the subject invention will be explained in more detail with reference to preferred embodiments, which are illustrated in the accompanying drawings. Each show schematically: <Tb> FIG. 1 <SEP> a communication system; <Tb> FIG. 2 <SEP> a communication system as in FIG. 1 but additionally with a second GU; <Tb> FIG. 3 <SEP> a communication system as in FIG. 1 but additionally with an RTC in the user medium; <Tb> FIG. 4 a communication system as in FIG. 3, but additionally a second GU and a first and second key; <Tb> FIG. 5 <SEP> a communication system as in FIG. 4 but additionally with a manager medium; <Tb> FIG. 6 <SEP> a communication system in which the second medium has a passive role in the authentication.
[0087] Die in den Zeichnungen verwendeten Bezugszeichen und deren Bedeutung sind in der Bezugszeichenliste zusammengefasst aufgelistet. Grundsätzlich sind in den Figuren gleiche Teile mit gleichen Bezugszeichen versehen. The reference numerals used in the drawings and their meaning are listed in the list of reference numerals. Basically, the same parts are provided with the same reference numerals in the figures.
[0088] Die Fig. 1 zeigt ein Kommunikationssystem mit einem Benutzermedium 1 und einem zweiten Medium 2, nämlich einem Dienstmedium. Das Benutzermedium 1 umfasst ein erstes SE 22, welches eine erste GU bildet. Dem ersten SE 22 kann eine Referenzzeitinformation 10 übermittelt werden. Die Referenzzeitinformation 10 wird dem ersten SE 22 von einer vertrauenswürdigen Quelle, hier einem TSM 3 durch ein Mobiltelephonnetz übermittelt; alternativ zum Mobiltelephonnetz könnte bspw. auch ein WLAN benutzt werden. Das Benutzermedium 1 umfasst ausserdem ein erstes Kommunikationsmodul 20, welches sich ausserhalb des ersten SE 22 befindet. Fig. 1 shows a communication system with a user medium 1 and a second medium 2, namely a service medium. The user medium 1 comprises a first SE 22, which forms a first GU. Reference time information 10 can be transmitted to first SE 22. The reference time information 10 is transmitted to the first SE 22 from a trusted source, here a TSM 3, through a mobile telephone network; As an alternative to the mobile telephone network, for example, a WLAN could also be used. The user medium 1 also includes a first communication module 20, which is located outside the first SE 22.
[0089] Das Dienstmedium 2 umfasst ein zweites Kommunikationsmodul 21. Das erste Kommunikationsmodul 20 und das zweite Kommunikationsmodul 21 sind derart ausgebildet, dass sie zum Aufbau einer NFC-Kommunikationsverbindung miteinander befähigt sind. The service medium 2 comprises a second communication module 21. The first communication module 20 and the second communication module 21 are designed such that they are capable of establishing an NFC communication link with each other.
[0090] Dem Dienstmedium 2 wird hier ein gesichertes Zeitsignal 11 zur Verfügung gestellt, indem zuerst die NFC-Kommunikationsverbindung zwischen dem ersten Kommunikationsmodul 20 und dem zweiten Kommunikationsmodul 21 etabliert wird. Danach übermittelt der TSM 3 die Referenzzeitinformation 10 in das erste SE22. Sobald die Referenzzeitinformation 10 im ersten SE 22 empfangen worden ist, wird eine der Referenzzeitinformation 10 entsprechende gesicherte Zeitinformation 11 vom ersten SE 22 an das erste Kommunikationsmodul 20 und über die NFC-Kommunikationsverbindung zum zweiten Kommunikationsmodul 21 an das Dienstmedium 2 übermittelt. Somit ist dem Dienstmedium 2 eine gesicherte Zeitinformation 11 zur Verfügung gestellt. A secure time signal 11 is made available to the service medium 2 here by first establishing the NFC communication connection between the first communication module 20 and the second communication module 21. Thereafter, the TSM 3 transmits the reference time information 10 to the first SE22. As soon as the reference time information 10 has been received in the first SE 22, secure time information 11 corresponding to the reference time information 10 is transmitted from the first SE 22 to the first communication module 20 and via the NFC communication connection to the second communication module 21 to the service medium 2. Thus, a secure time information 11 is provided to the service medium 2.
[0091] Diese gesicherte Zeitinformation 11 benutzt nun das Dienstmedium 2, um in einem Authentifizierungsprozess zwischen dem Dienstmedium 2 und dem Benutzermedium 1 basierend auf der gesicherten Zeitinformation 11 zu entscheiden, ob eine Autorisierung des Benutzermediums 2 erfolgen darf oder nicht. This secured time information 11 now uses the service medium 2 to decide in an authentication process between the service medium 2 and the user medium 1 based on the secure time information 11, whether an authorization of the user medium 2 may or may not take place.
[0092] Beispielsweise kann im Dienstmedium festgelegt sein, dass das Benutzermedium nur während einem gewissen Zeitfenster autorisiert ist. Nur wenn die aktuelle, gesicherte Zeit in diesem Zeitfenster liegt, erfolgt eine Freigabe. Alternativ dazu kann eine im Benutzermedium vorhandene Autorisierungsinformation (bspw. ein elektronischer Hotelzimmerschlüssel oder ein zeitlich in seiner Gültigkeit beschränktes Ticket) nur zu gewissen Zeiten gültig sein, wobei die Gültigkeit durch das Dienstmedium bei Vorhandensein einer Zeitinformation verifizierbar bzw. falsifizierbar ist. For example, it may be specified in the service medium that the user medium is authorized only during a certain time window. Only if the current, secured time is in this time window, a release takes place. Alternatively, an authorization information present in the user medium (for example an electronic hotel room key or a ticket that is limited in time) may only be valid for certain times, the validity being verifiable or falsifiable by the service medium in the presence of time information.
[0093] Das Dienstmedium 2 ist einfach aufgebaut und deswegen gleichzeitig wartungsarm und wenig störanfällig sowie kostengünstig in Produktion, Betrieb und Wartung sein. The service medium 2 is simple and therefore at the same time low maintenance and less susceptible to interference and cost in production, operation and maintenance.
[0094] In Fig. 2 ist ein weiteres Kommunikationssystem beschrieben. Als einzigen in der Figur dargestellten Unterschied zum Kommunikationssystem in Fig. 1 umfasst im Kommunikationssystem von Fig. 2 das Dienstmedium 2 eine zweite GU, welche als zweites SE 23 ausgebildet ist. Die gesicherte Zeitinformation 11 wird nach dem Empfang durch das zweite Kommunikationsmodul 21 innerhalb des Dienstmediums 2 an das zweite SE 11 übermittelt. Dadurch ist die gesicherte Zeitinformation 11 zusätzlich geschützt und vor Manipulation gesichert; der Authentifizierungsprozess kann in der zweiten GU oder ausserhalb davon ablaufen. 2, another communication system is described. As the only difference to the communication system in FIG. 1 shown in the figure, in the communication system of FIG. 2 the service medium 2 comprises a second GU, which is designed as a second SE 23. The secured time information 11 is transmitted to the second SE 11 after reception by the second communication module 21 within the service medium 2. As a result, the secure time information 11 is additionally protected and secured against manipulation; the authentication process can take place in the second GU or outside of it.
[0095] Dem Dienstmedium 2 in Fig. 2 wird ein gesichertes Zeitsignal 11 zur Verfügung gestellt, indem zuerst eine NFC-Kommunikationsverbindung zwischen dem ersten Kommunikationsmodul 20 und dem zweiten Kommunikationsmodul 21 etabliert wird. Danach übermittelt der TSM 3 die Referenzzeitinformation 10 in das erste SE22. Sobald die Referenzzeitinformation 10 im ersten SE 22 empfangen worden ist, wird eine der Referenzzeitinformation 10 entsprechende gesicherte Zeitinformation 11 vom ersten SE 22 an das erste Kommunikationsmodul 20 und über die NFC-Kommunikationsverbindung und nach bekannten Methoden verschlüsselt zum zweiten Kommunikationsmodul 21 und schlussendlich vom zweiten Kommunikationsmodul 21 an das zweite SE 23 im Dienstmedium 2 übermittelt. Somit ist dem Dienstmedium 2 und etwas genauer gesagt der zweiten SE 23 eine gesicherte Zeitinformation zur Verfügung gestellt worden. In diesem Fall ist die gesicherte Zeitinformation 11 auf eine nur durch eine SE entschlüsselbare Weise verschlüsselt übermittelt worden, was eine zusätzliche Sicherheit der gesicherten Zeitinformation bedeutet. Noch weiter erhöht wird die Sicherheit des Kommunikationssystems in Fig. 2 durch den Umstand, dass die gesicherte Zeitinformation 11 in die zweite SE 23 übermittelt wird. A secured time signal 11 is made available to the service medium 2 in FIG. 2 by first establishing an NFC communication connection between the first communication module 20 and the second communication module 21. Thereafter, the TSM 3 transmits the reference time information 10 to the first SE22. As soon as the reference time information 10 has been received in the first SE 22, secure time information 11 corresponding to the reference time information 10 is encrypted from the first SE 22 to the first communication module 20 and via the NFC communication connection and according to known methods to the second communication module 21 and finally from the second communication module 21 is transmitted to the second SE 23 in the service medium 2. Thus, the service medium 2 and, more precisely, the second SE 23 has been provided with secure time information. In this case, the secure time information 11 has been transmitted encrypted in a manner that can only be decrypted by an SE, which means additional security for the secure time information. The security of the communication system in FIG. 2 is further increased by the fact that the secure time information 11 is transmitted to the second SE 23.
[0096] Der Authentifizierungsprozess zwischen dem Dienstmedium 2 und dem Benutzermedium 1 wird analog zum Kommunikationssystem in Fig. 1 vorgenommen. The authentication process between the service medium 2 and the user medium 1 is performed analogously to the communication system in FIG.
[0097] Fig. 3 zeigt ein Kommunikationssystem mit einem Zeitgeber, nämlich einer Echtzeituhr RTC 24 im Benutzermedium. Als einzigen dargestellten Unterschied zum Kommunikationssystem in Fig. 1 umfasst hier das erste SE 22 zusätzlich zur vom TSM 3 empfangenen Referenzinformation 10 noch eine RTC 24. Fig. 3 shows a communication system with a timer, namely a real-time clock RTC 24 in the user medium. As the only difference to the communication system shown in FIG. 1, the first SE 22 additionally comprises an RTC 24 in addition to the reference information 10 received by the TSM 3.
[0098] Dem Dienstmedium 2 in Fig. 3 wird ein gesichertes Zeitsignal 11 zur Verfügung gestellt, indem zuerst der TSM 3 die Referenzzeitinformation 10 in das erste SE 22 übermittelt. Sobald die Referenzzeitinformation 10 im ersten SE 22 empfangen worden ist, wird diese an die RTC 24 weitergeleitet, damit die RTC 24 mit der in der Referenzzeitinformation 11 enthaltenen Zeitangabe synchronisiert werden kann. Die RTC 24 im ersten SE 22 ist nun mit einer zuverlässigen Zeitquelle synchronisiert. Somit verfügt das Dienstmedium 2 über eine RTC 24, welche dazu befähigt ist, eine Zeitangabe zur Verwendung in der gesicherten Zeitinformation 11 zur Verfügung zu stellen. The service medium 2 in FIG. 3 is provided with a secure time signal 11, in which first the TSM 3 transmits the reference time information 10 into the first SE 22. Once the reference time information 10 has been received in the first SE 22, this is forwarded to the RTC 24 so that the RTC 24 can be synchronized with the time included in the reference time information 11. The RTC 24 in the first SE 22 is now synchronized with a reliable time source. Thus, the service medium 2 has an RTC 24 which is capable of providing a time for use in the secure time information 11.
[0099] Nachdem die RTC 24 im Benutzermedium 1 mindestens einmal durch die Referenzzeitinformation 10 synchronisiert worden ist, wird zeitlich unabhängig (typischerweise Minuten, Stunden oder unter Umständen auch Tage später) von der Synchronisation der RTC 24 die NFC-Kommunikationsverbindung zwischen dem ersten Kommunikationsmodul 20 und dem zweiten Kommunikationsmodul 21 etabliert. Danach wird eine dem RTC 24 entstammende Zeitangabe als gesicherte Zeitinformation 11 verwendet und diese gesicherte Zeitinformation 11 vom ersten SE 22 an das erste Kommunikationsmodul 20 und über die NFC-Kommunikationsverbindung zum zweiten Kommunikationsmodul 21 an das Dienstmedium 2 übermittelt. Somit ist dem Dienstmedium 2 eine gesicherte Zeitinformation 11 zur Verfügung gestellt. After the RTC 24 has been synchronized in the user medium 1 at least once by the reference time information 10, the synchronization of the RTC 24, the NFC communication connection between the first communication module 20 is independent of time (typically minutes, hours or even days later) and the second communication module 21 established. After that, a time indication originating from the RTC 24 is used as secure time information 11 and this secured time information 11 is transmitted from the first SE 22 to the first communication module 20 and via the NFC communication connection to the second communication module 21 to the service medium 2. Thus, a secure time information 11 is provided to the service medium 2.
[0100] Alternativ zu diesem Vorgehen kann auch der Zeitgeber im Benutzermedium eine relative Zeit herausgeben, und die Berechnung der aktuellen Zeit erfolgt bei der Authentifizierung anhand der abgespeicherten Referenzzeitinformation und dieser relativen Zeit ausserhalb des Zeitgebers aber bevorzugt innerhalb der GU. As an alternative to this procedure, the timer can also output a relative time in the user medium, and the calculation of the current time takes place during authentication on the basis of the stored reference time information and this relative time outside the timer but preferably within the GU.
[0101] Der Authentifizierungsprozess in Fig. 3 zwischen dem Dienstmedium 2 und dem Benutzermedium 1 wird analog zum Kommunikationssystem in Fig. 1 vorgenommen. The authentication process in Fig. 3 between the service medium 2 and the user medium 1 is made analogous to the communication system in Fig. 1.
[0102] Die Synchronisierung des RTC - oder allgemeiner die Übermittlung der Referenzzeitinformation an das Benutzermedium - kann in den, offline’-Ausführungsformen (d.h. den Ausführungsformen, bei denen kein gleichzeitiger Kontakt zwischen Quelle und Benutzermedium einerseits und Benutzermedium und zweitem Medium andererseits vorausgesetzt wird und das Benutzermedium dafür einen Zeitgeber aufweist - bspw. jeweils beim Aufladen eines elektronischen Schlüssels oder Tickets oder dergleichen geschehen. Ergänzend oder alternativ kann es in regelmässigen Abständen geschehen, bzw. dann, wenn eine Verbindung zwischen der vertrauenswürdigen Quelle und dem Benutzermedium vorhanden ist. The synchronization of the RTC - or more generally the transmission of the reference time information to the user medium - can be assumed in the 'offline' embodiments (ie the embodiments where no simultaneous contact between source and user medium on the one hand and user medium and second medium on the other the user medium has a timer for this purpose - for example, in each case when an electronic key or ticket or the like is loaded in. Additionally or alternatively, it can take place at regular intervals, or if there is a connection between the trusted source and the user medium.
[0103] Fig. 4 zeigt ein Kommunikationssystem wie in Fig. 3 aber zusätzlich mit einer zweiten GU und einem ersten und zweiten Schlüssel. Dieses Kommunikationssystem unterscheidet sich von demjenigen in Fig. 3 also dadurch, dass das Dienstmedium 2 analog zu Fig. 2 eine zweite GU in Form eines zweiten SE 23 aufweist. Zudem umfasst das erste SE 22 einen ersten Schlüssel 30, und das zweite SE 23 umfasst einen zweiten Schlüssel 31 (im Falle von symmetrischer Verschlüsselung sind der erste und der zweite Schlüssel identisch). Wie an sich von SEs bekannt, können der erste und zweite Schlüssel Sicherheitsschlüssel sein, welche vom Erzeuger des SE implementiert sind und dem Betreiber selbst nicht bekannt sind. In Fig. 4 ist zusätzlich in jedem SE jeweils ein eigener sicherer Prozessor dargestellt, da mindestens ein sicherer Prozessor definitionsgemäss von jedem SE umfasst wird. Somit sind in Fig. 4 im ersten SE 22 ein sicherer Prozessor 32 des ersten SE 22 und im zweiten SE 23 ein sicherer Prozessor 33 des zweiten SE 23 dargestellt. FIG. 4 shows a communication system as in FIG. 3 but additionally with a second GU and a first and second key. This communication system thus differs from that in FIG. 3 in that the service medium 2, analogously to FIG. 2, has a second GU in the form of a second SE 23. In addition, the first SE 22 includes a first key 30, and the second SE 23 includes a second key 31 (in the case of symmetric encryption, the first and second keys are identical). As is known per se from SEs, the first and second keys may be security keys which are implemented by the producer of the SE and are not known to the operator himself. In FIG. 4, a separate secure processor is additionally shown in each SE, since at least one secure processor is by definition encompassed by each SE. Thus, a secure processor 32 of the first SE 22 and in the second SE 23 a secure processor 33 of the second SE 23 are shown in FIG. 4 in the first SE 22.
[0104] Grundsätzlich verläuft in Fig. 4 das Verfahren, dem Dienstmedium 2 das gesicherte Zeitsignal 11 zur Verfügung zu stellen, analog zum entsprechenden Verfahren wie bereits zu Fig. 3 beschrieben. Im Unterschied zu Fig. 3 wird aber in Fig. 4 die gesicherte Zeitinformation 11, welche der RTC 24 entstammt, vor einem Verlassen des ersten SE 22 unter Verwendung des ersten Schlüssels 30 verschlüsselt und erst danach an das erste Kommunikationsmodul 20 übermittelt. Das Verschlüsseln erfolgt im sicheren Prozessor 32 des ersten SE 22. Die verschlüsselte, gesicherte Zeitinformation wird dann über die NFC-Kommunikationsverbindung an das zweite Kommunikationsmodul 21 und schliesslich in das zweite SE 23 übermittelt. Im zweiten SE 23 entschlüsselt der sichere Prozessor 33 unter Verwendung des zweiten Schlüssels 31 die verschlüsselte gesicherte Zeitinformation, wodurch schlussendlich die gesicherte Zeitinformation 11 im zweiten SE 23 verfügbar ist. In principle, in FIG. 4 the method of providing the service medium 2 with the saved time signal 11, analogous to the corresponding method as already described with reference to FIG. 3, proceeds. In contrast to FIG. 3, however, in FIG. 4 the secure time information 11 originating from the RTC 24 is encrypted before leaving the first SE 22 using the first key 30 and only then transmitted to the first communication module 20. The encryption takes place in the secure processor 32 of the first SE 22. The encrypted, secure time information is then transmitted via the NFC communication link to the second communication module 21 and finally into the second SE 23. In the second SE 23, the secure processor 33 decrypts the encrypted secure time information using the second key 31, whereby finally the secure time information 11 is available in the second SE 23.
[0105] Vorteil von dieser Methode ist eine sehr hohe Manipulationssicherheit des Verfahrens und des Kommunikationssystems, da die gesicherte Zeitinformation 11 ausserhalb einer GU nicht unverschlüsselt zugänglich ist. Somit ist eine Manipulation selbst innerhalb des Benutzermediums 1 und/oder des Dienstmediums 2 erschwert oder verunmöglicht. Advantage of this method is a very high security against manipulation of the method and the communication system, since the secure time information 11 outside a GU is not accessible unencrypted. Thus, a manipulation even within the user medium 1 and / or the service medium 2 is difficult or impossible.
[0106] Die Verschlüsselung und Entschlüsselung durch die sicheren Prozessoren der jeweiligen SE unter Verwendung von Schlüsseln erfolgen dabei nach bekannten Methoden. Da die Schlüssel von den jeweiligen SE umfasst sind, sind diese in einem hohen Masse gesichert. Das Zusammenspiel der Schlüssel und das zur Verfügung stellen der Schlüssel erfolgt ebenfalls nach bekannten Methoden. Die Schlüssel bestehen beispielsweise je aus verschiedenen Quellen stammenden Teilschlüsseln, was eine hohe Sicherheit des Verfahrens und des Kommunikationssystems zur Folge hat. The encryption and decryption by the secure processors of the respective SE using keys are carried out according to known methods. Since the keys are covered by the respective SE, these are secured to a high degree. The interplay of the keys and the provision of the key is also done by known methods. For example, the keys consist of sub-keys originating from different sources, which results in a high degree of security of the method and the communication system.
[0107] Auch der Authentifizierungsprozess in Fig. 4 zwischen dem Dienstmedium 2 und dem Benutzermedium 1 wird analog zum Kommunikationssystem in Fig. 1 vorgenommen. Also, the authentication process in Fig. 4 between the service medium 2 and the user medium 1 is made analogous to the communication system in Fig. 1.
[0108] Fig. 5 zeigt ein Kommunikationssystem wie in Figur 4 , welches aber zusätzlich ein Managermedium 4 umfasst. In Fig. 5 verläuft das Verfahren, dem Dienstmedium 2 das gesicherte Zeitsignal 11 zur Verfügung zu stellen, analog zum entsprechenden Verfahren wie bereits zu Fig. 4 beschrieben. Zusätzlich ist in Fig. 5 ein Managermedium 4 dargestellt, welches dazu befähigt ist, dem ersten SE 22 eine Authentifizierungsinformation 12 zu übermitteln. Dabei übermittelt das Managermedium 4 dem ersten SE 22 die Authentifizierungsinformation 12 auf eine bekannte Weise analog zum TSM 3, wobei aber die Übermittlung vom Managermedium 4 an das erste SE 22 unabhängig von der Übermittlung vom TSM 3 an das erste SE 22 erfolgen kann. FIG. 5 shows a communication system as in FIG. 4, which additionally comprises a management medium 4. In FIG. 5, the method of providing the service medium 2 with the saved time signal 11 is analogous to the corresponding method as already described with reference to FIG. 4. In addition, a manager medium 4 is shown in FIG. 5, which is capable of transmitting to the first SE 22 an authentication information 12. In this case, the management medium 4 transmits the authentication information 12 to the first SE 22 in a known manner analogously to the TSM 3, but the transmission from the management medium 4 to the first SE 22 can take place independently of the transmission from the TSM 3 to the first SE 22.
[0109] Die Authentifizierungsinformation 12 umfasst einen zeitlich nur beschränkt gültigen elektronischen Schlüssel bzw. ein zeitlich nur beschränkt gültiges elektronisches Ticket oder einen definierten Zeitraum und dazugehörige Angaben über eine Identität mindestens eines Dienstmediums 2. Während dieses definierten Zeitraums sind die mittels der Angaben über die Identität eindeutig festgelegten Dienstmedien 1 dazu befähigt, ein ihnen diese Authentifizierungsinformation 12 übermittelndes Benutzermedium 1 im Authentifizierungsprozess als ein zur Autorisation berechtigtes Benutzermedium 1 zu erkennen. Mit anderen Worten ist das Benutzermedium 1 während dieses definierten Zeitraums zur Autorisierung freigegeben. The authentication information 12 includes an electronic key valid for a limited period of time or an electronic ticket or a defined period of time and associated information about an identity of at least one service medium 2. During this defined period of time, the information about the identity uniquely defined service media 1 enables it to recognize a user medium 1 that transmits this authentication information 12 in the authentication process as a user-authorized medium 1 authorized for authorization. In other words, the user medium 1 is released for authorization during this defined period.
[0110] Im Authentifizierungsprozess benutzt das Dienstmedium 2 also die ihm durch das Benutzermedium 1 (und schlussendlich durch den TSM 3) zur Verfügung gestellte gesicherte Zeitinformation 11, um zwischen dem Dienstmedium 2 und dem Benutzermedium 1 basierend auf der gesicherten Zeitinformation 11 zu entscheiden, ob eine Autorisierung des Benutzermediums 2 erfolgen darf oder nicht. In the authentication process, the service medium 2 thus uses the secure time information 11 provided to it by the user medium 1 (and finally by the TSM 3) to decide between the service medium 2 and the user medium 1 based on the secure time information 11 an authorization of the user medium 2 may or may not be made.
[0111] Die Authentifizierungsinformation 12 wird dabei analog zur gesicherten Zeitinformation 11 vor einem Verlassen des ersten SE 22 unter Verwendung des ersten Schlüssels 30 verschlüsselt und erst danach an das erste Kommunikationsmodul 20 übermittelt. Die Verschlüsselung, Übermittlung und Entschlüsselung der Authentifizierungsinformation 12 erfolgen dabei analog zu denselben Schritten für die gesicherte Zeitinformation. Daher weisen die analogen Schritte auch dieselben Vorteile auf. The authentication information 12 is encrypted analogously to the secure time information 11 before leaving the first SE 22 using the first key 30 and only then transmitted to the first communication module 20. The encryption, transmission and decryption of the authentication information 12 are carried out analogously to the same steps for the secure time information. Therefore, the analog steps also have the same advantages.
[0112] In Fig. 6 ist eine Ausführungsform dargestellt, bei welcher die Authentifizierung im SE 20 des Benutzermediums 1 stattfindet. Bei dieser Ausführungsform sind bei der Authentifizierung die Rollen von Benutzermedium 1 und zweitem Medium 2 vertauscht, das zweite Medium nimmt quasi für die Authentifizierung die Rolle des «Benutzers» ein. FIG. 6 shows an embodiment in which the authentication takes place in the SE 20 of the user medium 1. In this embodiment, the roles of user medium 1 and second medium 2 are reversed in the authentication, the second medium takes the role of the "user", as it were, for authentication.
[0113] Das zweite Medium 2 beinhaltet eine Identifikationsinformation 51, anhand welcher das Benutzermedium 1 feststellt, ob und ggf. in welchem Umfang das Benutzermedium 1 berechtigt ist, zum aktuellen Zeitpunkt einen durch das zweite Medium identifizierten Dienst zu beanspruchen. Dadurch, dass der Authentifizierungsprozess im Benutzermedium im SE stattfindet, ist trotzdem sichergestellt, dass der Träger bzw. aktuelle Inhaber des Benutzermediums sich nicht Rechte verschaffen kann, die ihm eigentlich nicht zustehen. Das SE ist wie an sich bekannt so eingerichtet, dass nur autorisierte Institutionen - bspw-. ein Netzbetreiber, wenn das SE eine SIM-Karte oder ein Teil einer SIM-Karte ist -Umkonfigurierungen oder Umprogrammierungen vornehmen können. The second medium 2 contains identification information 51, on the basis of which the user medium 1 determines whether and to what extent the user medium 1 is entitled to claim a service identified by the second medium at the current time. Due to the fact that the authentication process takes place in the user medium in the SE, it is nonetheless ensured that the carrier or current owner of the user medium can not obtain rights which he is not actually entitled to. The SE is as known per se set up so that only authorized institutions - eg. A network operator, if the SE is a SIM card or part of a SIM card, can reconfigure or reprogram.
[0114] In der Ausführungsform gemäss Fig. 6 hat das zweite Medium eine rein passive Rolle: es dient lediglich der Identifikation des verlangten Dienstes. Entsprechend kann das zweite Medium optional rein passiv ausgestaltet sein, d.h. bspw. als RFID-Tag ohne eigene Energiequelle. Aber auch die Ausgestaltung als aktiv betriebenes, d.h. Signale mit eigener Signalleistung aussendendes Medium ist möglich in dieser Ausführungsform, bspw. dann, wenn die Reichweite der Kommunikation mit passiven Tags nicht ausreicht. In the embodiment according to FIG. 6, the second medium has a purely passive role: it serves only to identify the requested service. Accordingly, the second medium can optionally be made purely passive, i. eg as an RFID tag without its own energy source. But also the embodiment as actively operated, i. Signals with their own signal power emitting medium is possible in this embodiment, for example., When the range of communication with passive tags is not sufficient.
[0115] Das Prinzip der Ausführungsform von Fig. 6 (Authentifizierung im SE des Benutzermediums) kann sowohl für online- als auch für Offline-Ausführungsformen - letztere mit Zeitgeber im SE bzw. in einer anderen GU des Benutzermediums -verwendet werden. The principle of the embodiment of Fig. 6 (authentication in the SE of the user medium) can be used for both online and offline embodiments - the latter with timers in the SE or in another GU of the user medium.
[0116] Auch darüber hinaus sind viele weitere Ausführungsformen denkbar. Bspw. ist die Verwendung eines TSM als vertrauenswürdige Quelle keine Bedingung. Je nach gewähltem Sicherheitsstandard kann auch eine andere Quelle -bspw. ein dafür vorgesehener Server einer Applikation - verwendet werden, welche sich bspw. gegenüber der entsprechenden GU authentifizieren muss. In addition, many other embodiments are conceivable. For example. Using a TSM as a trusted source is not a requirement. Depending on the chosen security standard, another source -bspw. a dedicated server of an application - be used, which must, for example, to authenticate against the corresponding GU.
[0117] In allen Ausführungsformen kann das Benutzermedium physisch ein Mobiltelefon mit GU sein. Es ist auch möglich, die hier beschriebenen Funktionen der GU auf mehrere gesicherte Umgebungen (insbesondere SEs) zu verteilen. Bspw. kann in der Ausführungsform der Fig. 6 der Authentifizierungsprozess im Prinzip in einer anderen GU durchgeführt werden als der GU, in welcher die gesicherte Zeitinformation aufbewahrt bzw. aus der Referenzzeitinformation ermittelt wird. Durch eine Benutzermedium-interne verschlüsselte Kommunikationsverbindung wird dann die gesicherte Zeitinformation für den Authentifizierungsprozess übermittelt. In all embodiments, the user medium may physically be a mobile phone with GU. It is also possible to distribute the functions of the GU described here to several secure environments (in particular SEs). For example. For example, in the embodiment of FIG. 6, the authentication process may, in principle, be performed in a different GU than the GU in which the saved time information is stored or determined from the reference time information. By means of a user-medium-internal encrypted communication connection, the secure time information for the authentication process is then transmitted.
Claims (23)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CH01027/13A CH708123A2 (en) | 2013-05-29 | 2013-05-29 | Process making available a secured time information. |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CH01027/13A CH708123A2 (en) | 2013-05-29 | 2013-05-29 | Process making available a secured time information. |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| CH708123A2 true CH708123A2 (en) | 2014-12-15 |
Family
ID=52014608
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CH01027/13A CH708123A2 (en) | 2013-05-29 | 2013-05-29 | Process making available a secured time information. |
Country Status (1)
| Country | Link |
|---|---|
| CH (1) | CH708123A2 (en) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102017216047A1 (en) | 2017-09-12 | 2019-03-14 | Audi Ag | Method for setting a reference time |
| SE2251284A1 (en) * | 2022-11-04 | 2024-05-05 | Assa Abloy Ab | Method and mobile device for providing a time reading |
-
2013
- 2013-05-29 CH CH01027/13A patent/CH708123A2/en not_active Application Discontinuation
Cited By (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102017216047A1 (en) | 2017-09-12 | 2019-03-14 | Audi Ag | Method for setting a reference time |
| WO2019052864A1 (en) | 2017-09-12 | 2019-03-21 | Audi Ag | METHOD FOR SETTING A REFERENCE TIME |
| SE2251284A1 (en) * | 2022-11-04 | 2024-05-05 | Assa Abloy Ab | Method and mobile device for providing a time reading |
| WO2024094629A1 (en) * | 2022-11-04 | 2024-05-10 | Assa Abloy Ab | Method and mobile device for providing a time reading |
| SE546243C2 (en) * | 2022-11-04 | 2024-09-10 | Assa Abloy Ab | Method and mobile device for providing a time reading |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3295646B1 (en) | Examining a consistency between reference data of a production object and data of a digital twin of the production object | |
| EP2494485B1 (en) | Authentication of a token and integrity protection of its data | |
| DE102013215303B4 (en) | Mobile electronic device and method | |
| WO2016128454A1 (en) | Computer-implemented method for access control | |
| WO2009094683A1 (en) | Method and device for regulating access control | |
| DE102013200017A1 (en) | RFID tag and method for operating an RFID tag | |
| EP2332284A2 (en) | Releasing a service on an electronic appliance | |
| EP3704674A1 (en) | System and method for controlling the access of persons | |
| EP3595237B1 (en) | Reloading of cryptographic program instructions | |
| AT512419A1 (en) | METHOD AND APPARATUS FOR ACCESS CONTROL | |
| EP3373545A1 (en) | Safety unit, in particular for an iot device and method for executing one or more applications for secure data exchange with one or more servers providing web services | |
| AT516288B1 (en) | Method and device for managing access authorizations | |
| WO2014190445A2 (en) | Method for managing media for wireless communication | |
| DE102012203518B4 (en) | Method for communication of energy consumption-specific measurement data elements from a smart meter device to a computer system of an energy supplier and / or metering point operator | |
| EP2996299B1 (en) | Method and assembly for authorising an action on a self-service system | |
| DE102014114072B4 (en) | Methods and systems for secure communication between wireless electronic devices and vehicles | |
| EP3336736B1 (en) | Auxiliary id token for multi-factor authentication | |
| DE112023005554T5 (en) | IN-VEHICLE DEVICE AND VEHICLE AUTHENTICATION SYSTEM | |
| DE102009007367A1 (en) | Method for initiating context-sensitive action e.g. during transportation of passengers in suburban traffic transport system, involves initiating action depending on verified target context and actual context of reading process | |
| EP2823598B1 (en) | Method for creating a derivative instance | |
| DE102014209191A1 (en) | System and method for downloading data stored on a tachograph | |
| EP2764671A1 (en) | Marking insecure data by means of an nfc module | |
| DE102011117186A1 (en) | Method for controlling access to actuator or sensor in private or industrial sectors, involves verifying authority proof when information about access rights is analyzed by authorization functional unit of access control point | |
| DE102014114073A1 (en) | Methods and systems for secure communication between wireless electronic devices and vehicles | |
| WO2015024721A1 (en) | Activation of a network node by means of a message |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| AZW | Rejection (application) |