EP1700280A1 - Sicheres endgerät - Google Patents
Sicheres endgerätInfo
- Publication number
- EP1700280A1 EP1700280A1 EP04806364A EP04806364A EP1700280A1 EP 1700280 A1 EP1700280 A1 EP 1700280A1 EP 04806364 A EP04806364 A EP 04806364A EP 04806364 A EP04806364 A EP 04806364A EP 1700280 A1 EP1700280 A1 EP 1700280A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- secure terminal
- main
- peripheral
- security
- data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F19/00—Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
- G07F19/20—Automatic teller machines [ATMs]
- G07F19/201—Accessories of ATMs
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/08—Payment architectures
- G06Q20/10—Payment architectures specially adapted for electronic funds transfer [EFT] systems; specially adapted for home banking systems
- G06Q20/108—Remote banking, e.g. home banking
- G06Q20/1085—Remote banking, e.g. home banking involving automatic teller machines [ATMs]
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F19/00—Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
- G07F19/20—Automatic teller machines [ATMs]
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F19/00—Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
- G07F19/20—Automatic teller machines [ATMs]
- G07F19/206—Software aspects at ATMs
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/0806—Details of the card
- G07F7/0833—Card having specific functional components
Definitions
- the present invention relates to secure terminals, such as for example bank terminals or health terminals.
- a bank terminal connected to a telecommunications network, enables a bank type transaction to be carried out by inserting a bank card of the magnetic and / or chip type in the terminal, authentication of the card holder, and input of the nature and details of the transaction.
- a health terminal connected to a telecommunications network, similarly allows access to medical or social security data concerning a holder of a magnetic and / or smart type health card.
- FIG. 1 illustrates the functional diagram of a secure terminal TS, in particular banking, according to the prior art.
- Such a terminal integrates a set of functions, such as: a central processing unit 1 (microcontroller),
- a means of connection to a telecommunications network such as a modem 10
- a telecommunications network such as a modem 10
- a power supply 11 (battery and / or mains).
- buses 12 of different natures (power supply, memory, control) and are well known to those skilled in the art.
- the whole is based on one or more printed circuits distributed in one or more boxes.
- the realization of this type of terminal is conventional except that certain security elements must be added in order to prohibit any manipulation that can alter or extract confidential or financial information (personal identification code PIN, bank transactions, medical files, etc.). ..).
- the central unit microcontroller
- memories and certain sensitive data input / output devices are confined in the same box.
- This box has an intrusion detector in order to guarantee the integrity of the security domain of said box.
- Security remains mainly physical for this type of solution.
- the sensitive data which travels on the buses and between the functional units is encrypted.
- This mode is generally restricted to the central unit which encrypts this data to the memories or the remote sets via the modem.
- a first configuration is a monolithic assembly, in which all the functional sub-assemblies are grouped in a single housing.
- a second configuration is the bi-module assembly, in which the functional sub-assemblies are grouped in two boxes in two combinations. According to the first combination, in a first box are grouped all the sub-assemblies except the printer and the main power supply, and in a second box are grouped together the printer and the main power supply (for example the sector). According to the second combination, in a first housing are grouped all the sub-assemblies except the main power supply, and in a second housing is the main power supply (for example the sector).
- a first object of the present invention is to reduce the cost of a secure terminal.
- a second object of the invention is to improve the security of a secure terminal. At least one of these objects is reached by a secure terminal according to claim 1.
- the noble functions can be dissociated from those which are not.
- the central processing unit, memory, applications and data, as well as the security associated with protecting these elements are of great value. within a secure terminal.
- the ancillary peripherals such as the printer, the card reader, the modem have a low added value. The same goes for power and mechanics (housing). With the secure terminal according to the invention, the most valued part of the terminal is detached from the peripheral peripherals and concentrates the security efforts.
- the secure terminal according to the invention therefore has advantages both economically and in terms of security.
- FIG. 2 schematically illustrates the functional elements of a secure terminal, in particular banking, according to the invention.
- FIG. 2 illustrates the functional breakdown of a secure banking terminal TS 'according to the invention.
- the valued part is confined within a protected SEP sub-assembly which includes: - a central unit 1,
- keyboard 2 which is a delicate device to protect.
- the display 5 can be a constituent element of this protected SEP sub-assembly, in particular if the latter does not have an encryption means.
- the display 5 can be a constituent element of the basic sub-assembly SEB constituting the part with low added value.
- an encrypted communication can be established with the display.
- the display has symmetrical or asymmetrical cryptographic means.
- the basic SEB subset includes:
- a means of connection to a telecommunications network such as a modem 10
- a telecommunications network such as a modem 10
- a power supply 11 (battery and / or mains).
- This protected sub-assembly can be inserted, for example via a connector 13, into a basic SEB sub-assembly constituting in the part with low added value.
- the connector 13 is for example a connector of the PCMCIA type. There is no need for the SEB base subset to be certified.
- the part (s) with low added value are grouped in one or more boxes and one of them is intended to contain the valued and detachable SEP sub-assembly.
- the SEP protected sub-assembly includes:
- the means ensuring security for example the SAM module, etc.
- the SEP protected sub-assembly constitutes a detachable module, easily distributable and integrable in a bank terminal of the same manufacturer or a third party (OEM Original Equipment Manufacturer "or ODM" Original Design Manufacturer ").
- the SEP protected sub-assembly constitutes, for example, a sealed module, which cannot be dismantled without destruction. It can be certified. It contains the keyboard for entering sensitive data.
- the connection between the keyboard 2 and the microcontroller 1 of the SEP protected sub-assembly is direct, internal and not accessible outside the protected sub-assembly.
- the sealing of the SEP protected sub-assembly prohibits any repair but authorizes the use of insecure components.
- the SEP protected sub-assembly can be manufactured from standard components, including in particular a standard keyboard whose securing is simple and economical.
- the level of security achieved is that traditionally known as “obvious fraud detection” (or “obvious tamper”).
- the solution according to the invention also makes it possible to solve the migration and maintenance problems.
- the invention it is possible to standardize the dimensions and / or the connection of the SEP protected sub-assembly in order to allow a simplified migration for the terminal manufacturer. Indeed, the latter can develop the architecture and technology of the SEP protected sub-assembly according to the opportunities offered by the market.
Landscapes
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Physics & Mathematics (AREA)
- Finance (AREA)
- General Physics & Mathematics (AREA)
- Development Economics (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Economics (AREA)
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Storage Device Security (AREA)
- Accessory Devices And Overall Control Thereof (AREA)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP04806364A EP1700280A1 (de) | 2003-12-18 | 2004-12-16 | Sicheres endgerät |
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP03293219A EP1544818A1 (de) | 2003-12-18 | 2003-12-18 | Gesichertes Endgerät |
| PCT/IB2004/004160 WO2005062266A1 (fr) | 2003-12-18 | 2004-12-16 | Terminal securise |
| EP04806364A EP1700280A1 (de) | 2003-12-18 | 2004-12-16 | Sicheres endgerät |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1700280A1 true EP1700280A1 (de) | 2006-09-13 |
Family
ID=34486489
Family Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP03293219A Withdrawn EP1544818A1 (de) | 2003-12-18 | 2003-12-18 | Gesichertes Endgerät |
| EP04806364A Ceased EP1700280A1 (de) | 2003-12-18 | 2004-12-16 | Sicheres endgerät |
Family Applications Before (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP03293219A Withdrawn EP1544818A1 (de) | 2003-12-18 | 2003-12-18 | Gesichertes Endgerät |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US7757102B2 (de) |
| EP (2) | EP1544818A1 (de) |
| WO (1) | WO2005062266A1 (de) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102005031378B4 (de) * | 2005-07-05 | 2018-05-30 | Rohde & Schwarz Gmbh & Co. Kg | Verfahren zur fälschungssicheren Identifikation individueller elektronischer Baugruppen |
| WO2008131133A2 (en) * | 2007-04-17 | 2008-10-30 | Hypercom Corporation | Methods and systems for security authentication and key exchange |
| CN108463812B (zh) * | 2016-01-08 | 2021-10-08 | 克兰佩门特创新股份有限公司 | 自动交易机中的装置之间的次级总线通信 |
Family Cites Families (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| IT1128032B (it) * | 1980-02-08 | 1986-05-28 | Olivetti Ing C Spa | Apparecchiatura per la dispensazione di banconote sotto il controllo di carte di credito |
| GB2168514A (en) * | 1984-12-12 | 1986-06-18 | Ibm | Security module |
| DE19600769A1 (de) * | 1996-01-11 | 1997-07-17 | Ibm | Sicherheitsmodul mit einteiliger Sicherheitsfolie |
| US6098170A (en) * | 1997-05-21 | 2000-08-01 | At&T Corporation | System and method for using a second resource to store a data element from a first resource in a first-in first-out queue |
| JPH11353237A (ja) * | 1998-06-05 | 1999-12-24 | Fujitsu Ltd | 電子取引装置 |
| GB0010265D0 (en) * | 2000-04-28 | 2000-06-14 | Ncr Int Inc | Encrypting keypad module |
| US7121460B1 (en) * | 2002-07-16 | 2006-10-17 | Diebold Self-Service Systems Division Of Diebold, Incorporated | Automated banking machine component authentication system and method |
-
2003
- 2003-12-18 EP EP03293219A patent/EP1544818A1/de not_active Withdrawn
-
2004
- 2004-12-16 EP EP04806364A patent/EP1700280A1/de not_active Ceased
- 2004-12-16 WO PCT/IB2004/004160 patent/WO2005062266A1/fr not_active Ceased
- 2004-12-16 US US10/583,571 patent/US7757102B2/en not_active Expired - Lifetime
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2005062266A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US20070116279A1 (en) | 2007-05-24 |
| WO2005062266A1 (fr) | 2005-07-07 |
| EP1544818A1 (de) | 2005-06-22 |
| US7757102B2 (en) | 2010-07-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP0552079B1 (de) | Massenspeicherkarte für einen Mikrocomputer | |
| EP0552078B1 (de) | Steckbare, als Lesegerät für Karten mit ebenen Kontakten verwendbare Karte für Kleinstrechner | |
| EP0870222A2 (de) | Verfahren und vorrichtung mit bedingtem zugang | |
| EP2162846A2 (de) | Kryptoprozessor mit verbessertem datenschutz | |
| CA3093385A1 (fr) | Traitement securise de donnees | |
| EP3586258B1 (de) | Segmentiertes schlüsselauthentifikationssystem | |
| EP2488984B1 (de) | Computersystem für den zugang zu vertraulichen daten über mindestens eine entfernte einheit und entfernte einheit | |
| EP0776498B1 (de) | Gesicherte tastatureinrichtung | |
| CA2398317A1 (fr) | Systeme et procede de securisation des transmissions d'informations | |
| EP1700280A1 (de) | Sicheres endgerät | |
| FR2637710A1 (fr) | Procede et dispositif de commande electronique multifonction a haute securite comportant une carte a puce | |
| EP1358641A1 (de) | Chipkarte mit sicherheitssoftware und mit einer solchen karte zusammenarbeitende kommunikationsvorrichtung | |
| Weber | See what you sign secure implementations of digital signatures | |
| EP0329557B1 (de) | Tragbare Einrichtung zum Abfragen, Lesen und Aufzeichnen einer IC- und/oder einer Magnetkarte | |
| FR2745399A1 (fr) | Dispositif electronique delivrant une reference temporelle sure pour la protection d'un logiciel | |
| WO2000030047A1 (fr) | Dispositif pour la limitation de fraudes dans une carte a circuit integre | |
| FR2647937A2 (fr) | Disquette perfectionnee incorporant des circuits integres et des connecteurs, ou amenagee pour recevoir des circuits integres et des connecteurs, et dispositifs de liaison avec un ordinateur | |
| EP2285042A1 (de) | Software-Sicherheitsmodul mit Verwendung einer Verschlüsselung des Hashwertes eines mit einer Saat verketteten Passworts | |
| KR200235145Y1 (ko) | 유에스비 인증키의 접속단자를 보호하기 위한 캡 | |
| CN1328671C (zh) | 使计算机平台中虚拟硬盘激活的方法及其便携式钥匙 | |
| CA2594797A1 (fr) | Procede de securisation pour appareil electronique utilisant une carte a puce | |
| FR2812105A1 (fr) | Dispositif d'acces automatique et securise a divers appareils et services | |
| FR2872937A1 (fr) | Dispositif personnel programmable securise de stockage et de restitution de donnees | |
| FR2971350A1 (fr) | Procede et dispositif de connexion a un service distant depuis un dispositif hote | |
| WO2003054788A1 (fr) | Procede de transmission de donnees entre une carte a puce et un utilisateur, lecteur de carte et carte pour la mise en oeuvre de ce procede |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20060713 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU MC NL PL PT RO SE SI SK TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: RHELIMI, ALAIN, C/O AXALTO SA, IP DEPARTMENT Inventor name: LEGER, MICHEL, C/O AXALTO SA, IP DEPARTMENT |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20070402 |
|
| RAP1 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: GEMALTO SA |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20130119 |