IP Library Granted Patent US 8,031,871
Granted Patent B2
US 8,031,871 · App. 10/507,291 · Granted Oct 4, 2011

Method of updating an authentication algorithm in a computer system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,031,871
App. No.
10/507,291
Granted
Oct 4, 2011
Kind
B2
Abstract

The invention relates to a method of updating an authentication algorithm in at least one data processing device (CARD, SERV) which can store a subscriber identity (IMSI 1 ) which is associated with an authentication algorithm (Algo 1 ) in a memory element of said device (CARD, SERV). The inventive method comprises the following steps, namely: a step whereby a second inactive (Algo 2 ) authentication algorithm is pre-stored in a memory element of the device and a step for switching from the first algorithm (Algo 1 ) to the second algorithm (Algo 2 ) which can inhibit the first algorithm (Algo 1 ) and activate the second (Algo 2 ).

Claims (21)

1. Method of updating an authentication algorithm used by a device (CARD) to authenticate with a data processing device (SERV) wherein the device (CARD) has a memory element for storing a subscriber identity (IMSI) which is associated with an authentication algorithm, comprising:

a first preliminary step of storing an active first authentication algorithm (Algo 1 ) in a non-volatile memory element of the device (CARD) associated with a first subscriber identity (IMSI 1 );

a second preliminary step of storing an inactive second inactive authentication algorithm (Algo 2 ) in a non-volatile memory element of the device (CARD) associated with a second subscriber identity (IMS 12 ); and

a step for switching from the first authentication algorithm (Algo 1 ) to the second authentication algorithm (Algo 2 ) including inhibiting the first authentication algorithm (Algo 1 ) and activate activating the second authentication algorithm (Algo 2 ) used by the device (CARD).

2. Method according to claim 1 , wherein the switching step is carried out on the initiative of an entity (OP) external to said device.

3. Method according to claim 1 or 2 , wherein, to perform the switching operation, the entity (OP) external to said device transmits a command (COM) remotely to said device (CARD) in order to switch from the first authentication algorithm (Algo 1 ) to the second authentication algorithm (Algo 2 ).

4. Method according to claim 1 or 2 , wherein, to perform the switching operation, the entity external to said device downloads into the device a program which can start up after a time delay and whose purpose is to switch from the first authentication algorithm (Algo 1 ) to the second authentication algorithm (Algo 2 ).

5. Method according to claim 1 , wherein, during the pre-storage step, a second code IMS 12 , different from a code IMSI 1 associated with the first algorithm, and associated with the algorithm AIgo 2 , is stored, and wherein after the step for switching accounts on said device (CARD), said device (CARD) transmits the code IMS 12 to all or some of the data processing devices (SERV) whose algorithms need to be switched, said second code (IMSI 2 ) associated with the second algorithm informing these data processing devices that the algorithms have been switched in order to synchronise the algorithm update.

6. Method according to claim 5 , wherein on reception of the second code (IMSI 2 ) associated with the second authentication algorithm (Algo 2 ), said receiving device switches algorithm from the first authentication algorithm (Algo 1 ) to the second authentication algorithm (Algo 2 ).

7. Method according to claim 1 , wherein after switching, the memory space storing the data associated with the deactivated account is reused.

8. The method of updating an authentication algorithm used by a device (CARD) to authenticate with a data processing device (SERV) of claim 1 , wherein at least one of the first preliminary step and the second preliminary step is performed during card personalization.

9. Data processing device, in particular a smart card having a memory element for storing a subscriber identity (IMSI) and associated with an authentication algorithm (Algo), comprising:

first non-volatile memory means storing an active first authentication algorithm (Algo 1 ) associated with a first subscriber identity (IMSI 1 ),

second non-volatile memory means storing an inactive second authentication algorithm (Algo 2 ) associated with a second subscriber identity (IMSI 2 ),

a microcontroller programmed to carry out a step for switching from the first authentication algorithm (Algo 1 ) to the second authentication algorithm (Algo 2 ), which when executed permanently deactivates the first authentication algorithm (Algo 1 ) and activates the second authentication algorithm (Algo 2 ).

10. A non-volatile computer storage media operable to store instructions for instructing a data processing device, in particular a smart card, to perform certain operations, the storage media comprising:

an active first authentication algorithm (Algo 1 ) associated with a first subscriber identity (IMSI 1 ) stored in the non-volatile storage media during a preliminary phase;

an inactive second inactive authentication algorithm (Algo 2 ) associated with a second subscriber identity (IMS 12 ) stored in the non-volatile storage media during a preliminary phase; and

instructions to direct the data processing device (CARD) to execute a step for switching from the first authentication algorithm (Algo 1 ) to the second authentication algorithm (Algo 2 ), which when executed inhibits the first authentication algorithm (Algo 1 ) associated with a first subscriber identity (IMSI 1 ) and activates the second authentication algorithm.

11. The storage media according to claim 10 , further comprising instructions to direct the data processing device to perform the step of switching from the first authentication algorithm to the second authentication algorithm, upon receiving from a transmitting device a code IMSI 2 different from the code IMSI 1 and therefore associated with the second authentication algorithm Algo 2 .

12. The computer storage media of claim 10 , wherein at least one of the first and second authentication algorithms is stored in the storage media during card personalization.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 062727/0379 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ENCLOSURE: PREVIOUS DOCUMENT ONLY INCLUDED ENGLISH TRANSLATION OF ASSIGNMENT AND NO SIGNED COPY PREVIOUSLY RECORDED AT REEL: 026837 FRAME: 0827. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 30, 2023
From: AXALTO SA
To: GEMALTO SA
Reel/Frame 062540/0381 →
CHANGE OF NAME Recorded Jan 30, 2023
From: GEMALTO SA
To: THALES DIS FRANCE SA
Reel/Frame 064163/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2011
From: AXALTO SA
To: GEMALTO SA
Reel/Frame 026837/0827 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2004
From: BEAUDOU, PATRICE; DUBOIS, CHRISTOPHE
To: AXALTO SA
Reel/Frame 016483/0599 →