IP Library Granted Patent US 12712747
Granted Patent B2
US 12712747 · App. 18/804,381 · Granted Aug 18, 2026

Secure channel initiation between card and host

Inventor: Praveen Patel (Pune, IN)
Assignee: GIESECKE+DEVRIENT MOBILE SECURITY GERMANY GMBH
H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12712747
App. No.
18/804,381
Granted
Aug 18, 2026
Kind
B2
Abstract

A procedure is provided for initiating a secure communication session between a card and a host. A static encryption key is assigned to the card and stored in the card. Each of the card and the host provide a key version number and a key identifier of the static key.

Claims (21)

1 . A procedure for initiating a secure communication session between a card and a host, a static encryption key being assigned to the card and stored in the card, each of the card and the host providing a key version number and a key identifier of said static key, the procedure comprising steps at the card:

receive, from the host, an INITIALIZE UPDATE command comprising a host challenge, which is a value unique to the session;

generate a card challenge, which is a value unique to the session, herein processing at least the card's static encryption key, key diversification data and a sequence counter with a first cryptographic function;

generate a session key (S-ENC), herein processing the card's static encryption key, the host challenge and the card challenge with a second cryptographic function;

calculate a card cryptogram using the session key (S-ENC);

send to the host an INITIALIZE UPDATE reply in which the card cryptogram, the sequence counter and the card challenge are comprised, to enable the host to verify the card cryptogram; wherein:

each of the card and the host provide an SCP key identity associated with said key version number and said key identifier of the card's static encryption key;

the INITIALIZE UPDATE command comprises the SCP key identity, and doesn't comprise said key version number and said key identifier;

to generate the card challenge, in addition said key version number and said key identifier are processed with the first cryptographic function.

2 . The procedure according to claim 1 , wherein the SCP key identity is comprised in a data field of said INITIALIZE UPDATE command.

3 . The procedure according to claim 1 , wherein:

the field P1 of said INITIALIZE UPDATE command comprises, instead of a key version number, a fixed value, particularly 0xFF; and/or

the field P2 of said INITIALIZE UPDATE command comprises, instead of a key identifier, a fixed value, particularly 0xFF.

4 . The procedure according to claim 1 , wherein the card comprises an card application, and wherein the session is initiated between the card application and the host, and wherein: to generate the card challenge, in addition an application identifier, AID, of the card application is processed with the first cryptographic function.

5 . The method according to claim 1 , wherein each of the card and the host provides some or all of the following security parameters:

Security parameter tag;

length;

length of SCP key identity;

SCP key identity;

length of key version and/or key identifier;

key version and/or key identifier.