Method for producing a soft token, computer program product and service computer system

    公开(公告)号:US09647840B2

    公开(公告)日:2017-05-09

    申请号:US14437906

    申请日:2013-10-17

    发明人: Frank Dietrich

    摘要: The method relates to a method for generating a soft token, having the following: providing a secure element, wherein, in a protected storage area of the secure element, a secret key of a first asymmetric cryptographic key pair is stored, setting up a first cryptographically secured connection between an electronic device and a service computer system, transmitting a request for the generation of the soft token from the electronic device to the service computer system via the first connection, generating a one-time password on the basis of the reception of the request by the service computer system, registering the one-time password as an identifier of the first connection by the service computer system, transmitting the one-time password from the service computer system to the electronic device via the first connection, issuing the one-time password via a user interface of the electronic device, setting up a second cryptographically stored connection between a user computer system and the service computer system, entering the one-time password into the user computer system, transmitting the entered one-time password from the user computer system to the service computer system via the second connection, verifying, by means of the service computer system, whether the registered one-time password is in agreement with the one-time password received via the second connection, and only if this is the case, reading at least one attribute stored in an ID token, generating the soft token by signing the at least one attribute and the public key of the first cryptographic key pair, transmitting the soft token via the first connection to the electronic device and/or transmitting the soft token via the second connection to the user computer system.

    Method for generating a certificate
    14.
    发明授权
    Method for generating a certificate 有权
    生成证书的方法

    公开(公告)号:US09596089B2

    公开(公告)日:2017-03-14

    申请号:US13704351

    申请日:2011-06-10

    IPC分类号: H04L29/06 H04L9/32 G06F21/64

    摘要: The invention relates to a method for generating a certificate for signing electronic documents by means of an ID token (106), having the following steps: —sending (201) a transaction request for a user to carry out a transaction, —as a result of the sending of the transaction request, a check is carried out as to whether the certificate (519) is available and if this is not the case, carrying out the following steps: generating (206) an asymmetrical key pair consisting of a private key and a public key using an ID token, said ID token (106) being assigned to the user; storing (207) the generated asymmetrical key pair on the ID token, wherein at least the private key is stored in a protected memory region of the ID token; transmitting (208; 509) the generated public key (518) to a first computer system, and generating (209) the certificate (519) by means of the first computer system for the public key.

    摘要翻译: 本发明涉及一种用于通过ID令牌(106)生成用于签署电子文档的证书的方法,具有以下步骤: - 发送(201)用于交易的用户的交易请求,结果 执行交易请求的发送,对证书(519)是否可用进行检查,如果不是这样,则执行以下步骤:生成(206)由私钥组成的非对称密钥对 以及使用ID令牌的公钥,所述ID令牌(106)被分配给所述用户; 将所生成的不对称密钥对存储(207)到所述ID令牌上,其中至少所述私钥存储在所述ID令牌的受保护的存储器区域中; 将生成的公钥(518)发送(208; 509)到第一计算机系统,并且通过用于公钥的第一计算机系统生成(209)证书(209)。

    READING OF AN ATTRIBUTE FROM AN ID TOKEN
    15.
    发明申请
    READING OF AN ATTRIBUTE FROM AN ID TOKEN 有权
    从身份证阅读属性

    公开(公告)号:US20170005800A9

    公开(公告)日:2017-01-05

    申请号:US14770546

    申请日:2014-02-19

    发明人: Frank MORGNER

    摘要: The disclosure relates to a method for reading at least one attribute stored in an ID token, wherein the ID token is assigned to a user, said method comprising: determining, by a terminal, of whether a contact-based interface of the ID token is present and can be used for data exchange with the terminal. If the ID token does not have the contact-based interface or this cannot be used, implementing a zero-knowledge authentication protocol via a contactless interface of the terminal and ID token; and deriving an ID token identifier by the terminal. If the ID token has the contact-based interface and this can be used, authenticating the user to the ID token via the contact-based interface; accessing to an ID token identifier by the terminal; sending of the ID token identifier from the terminal to an ID provider computer; use of the ID token identifier by the ID provider computer in order to authenticate the ID provider computer to the ID token; and read access of the ID provider computer to the at least one attribute stored in the ID token.

    摘要翻译: 本公开涉及一种用于读取存储在ID令牌中的至少一个属性的方法,其中所述ID令牌被分配给用户,所述方法包括:由终端确定所述ID令牌的基于联系人的接口是否为 存在并可用于与终端进行数据交换。 如果ID令牌不具有基于联系人的接口或不能使用,则通过终端和ID令牌的非接触式接口实现零知识认证协议; 并由终端导出ID令牌标识符。 如果ID令牌具有基于联系人的接口,并且可以使用该接口,则通过基于接口的接口将用户认证为ID令牌; 由终端访问ID令牌标识符; 将ID令牌标识符从终端发送到ID提供者计算机; 使用ID提供者计算机的ID令牌标识符,以便将ID提供者计算机认证为ID令牌; 并且读取ID提供者计算机对存储在ID令牌中的至少一个属性的访问。

    Document, method for authenticating a user, in particular for releasing a chip card function, and computer system
    16.
    发明授权
    Document, method for authenticating a user, in particular for releasing a chip card function, and computer system 有权
    用于认证用户的文档,方法,特别是用于释放芯片卡功能,以及计算机系统

    公开(公告)号:US09491154B2

    公开(公告)日:2016-11-08

    申请号:US14355271

    申请日:2012-10-15

    IPC分类号: G06F7/04 H04L29/06 G06F21/31

    CPC分类号: H04L63/08 G06F21/31

    摘要: A document having a non-volatile memory area for storing a secret identifier that has a first n-digit character sequence from a predefined character set; a random generator for selecting at least one character from the predefined character set for replacement of at least one character of the first character sequence, such that a second n-digit character sequence is defined as a result of this replacement; a volatile memory area for storing the at least one selected character; a display device for displaying the at least one selected character; an interface for inputting a third character sequence; and a processor element for authenticating the user to the document, wherein the processor element is configured to access the non-volatile memory area and the volatile memory area in order to read the second character sequence and check for a match between the second and third character sequences in order to authenticate the user.

    摘要翻译: 一种具有用于存储具有来自预定义字符集的第一n位字符序列的秘密标识符的非易失性存储区域的文档; 随机发生器,用于从所述预定义字符集中选择至少一个字符来替换所述第一字符序列的至少一个字符,使得第二n位字符序列被定义为所述替换的结果; 用于存储所述至少一个选定字符的易失性存储区域; 用于显示所述至少一个所选字符的显示装置; 用于输入第三字符序列的接口; 以及用于将用户认证给文档的处理器元件,其中所述处理器元件被配置为访问所述非易失性存储器区域和所述易失性存储器区域,以便读取所述第二字符序列并检查所述第二和第三字符之间的匹配 序列以验证用户。

    MOBILE PROXIMITY COUPLING DEVICE WITH DISPLAY
    17.
    发明申请
    MOBILE PROXIMITY COUPLING DEVICE WITH DISPLAY 有权
    具有显示功能的移动接近连接装置

    公开(公告)号:US20160080895A1

    公开(公告)日:2016-03-17

    申请号:US14785584

    申请日:2014-03-28

    发明人: Florian PETERS

    IPC分类号: H04W4/00

    CPC分类号: H04W4/80 G06K7/0008

    摘要: The invention relates to a mobile proximity coupling device (100) for inductive coupling with an integrated circuit of a proximity object, the integrated circuit comprising a coupling interface for inductive coupling, the mobile proximity coupling device (100) comprising a contactless interface (107) for inductive coupling with the coupling interface of the integrated circuit; a processor (109) for determining a quality indicator indicating a quality of the inductive coupling; and a display (111) for displaying a desired change of position of the mobile proximity coupling device relatively to the proximity object if the quality indicator indicates an insufficient quality of the inductive coupling.

    摘要翻译: 本发明涉及一种用于与邻近物体的集成电路进行电感耦合的移动邻近耦合装置(100),所述集成电路包括用于感应耦合的耦合接口,所述移动邻近耦合装置(100)包括非接触式接口(107) 用于与集成电路的耦合接口进行感应耦合; 用于确定指示所述电感耦合的质量的质量指示符的处理器(109); 以及显示器(111),用于如果质量指示符指示电感耦合的质量不足,则显示相对于接近物体的移动接近耦合装置的期望变化的位置。

    Card reader device for contactless readable cards and method for operating said card reader device
    18.
    发明授权
    Card reader device for contactless readable cards and method for operating said card reader device 有权
    用于非接触式可读卡的读卡器装置和用于操作所述读卡器装置的方法

    公开(公告)号:US09235735B2

    公开(公告)日:2016-01-12

    申请号:US13202587

    申请日:2010-02-19

    摘要: A card reader device is configured to carry out communication with a contactless readable card according to standard ISO/IEC 14443 type B. In order to provide that a modulation index, which self-adjusts in close range in a presence of a contactless readable card, corresponds to a desired specified modulation index, the magnetic field is received and evaluated via a reception antenna of the card reader device. The modulation index is controlled or regulated accordingly in case of deviations between a measured modulation index and a specified value for the modulation index in order to approximate the measured modulation index to the specified value.

    摘要翻译: 读卡器设备被配置为根据标准ISO / IEC 14443类型B与非接触式可读卡进行通信。为了提供在存在非接触式可读卡的情况下在近距离自调整的调制指数, 对应于期望的指定调制指数,通过读卡器设备的接收天线接收和评估磁场。 在测量的调制指数与调制指数的指定值之间的偏差的情况下相应地调制或调节调制指数,以便将测得的调制指数近似为指定值。

    PROVIDING POSITION DATA BY MEANS OF A DISTANCE-BOUNDING PROTOCOL
    19.
    发明申请
    PROVIDING POSITION DATA BY MEANS OF A DISTANCE-BOUNDING PROTOCOL 有权
    通过“距离约束协议”提供位置数据

    公开(公告)号:US20150365791A1

    公开(公告)日:2015-12-17

    申请号:US14762273

    申请日:2014-01-23

    发明人: Frank MORGNER

    IPC分类号: H04W4/02 H04W64/00

    摘要: A method is proposed for providing position data for a chip card having portions for receiving or detecting position data of a localisation unit by the localisation unit, wherein the localisation unit is spatially separate from the chip card; transmitting the position data from the localisation unit to the chip card via a contactless interface with use of a cryptographic protocol; executing a distance-bounding protocol between the chip card and the localisation unit, wherein the distance-bounding protocol then concludes successfully precisely when the spatial distance between the chip card and localisation unit does not exceed a predefined maximum distance; and executing a chip card function with successful conclusion of the distance-bounding protocol, wherein the chip card function uses the transmitted position data as position data specifying the current position of the chip card.

    摘要翻译: 提出了一种用于提供具有用于通过定位单元接收或检测定位单元的位置数据的部分的芯片卡的位置数据的方法,其中定位单元在空间上与芯片卡分离; 通过使用密码协议通过非接触式接口将位置数据从定位单元发送到芯片卡; 在芯片卡和定位单元之间执行距离限制协议,其中当芯片卡和定位单元之间的空间距离不超过预定义的最大距离时,距离限制协议然后成功地精确地结束; 以及成功实现距离界限协议执行芯片卡功能,其中芯片卡功能使用发送位置数据作为指定芯片卡当前位置的位置数据。