IP Library Granted Patent US 8,953,804
Granted Patent B2
US 8,953,804 · App. 13/497,443 · Granted Feb 10, 2015

Method for establishing a secure communication channel

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,953,804
App. No.
13/497,443
Granted
Feb 10, 2015
Kind
B2
Abstract

In a method for establishing a secure communication channel between a portable data carrier ( 10 ) and a terminal on the basis of an asymmetric cryptosystem, a value (X; Y; V; W) derived from a public key (PKD; PKT) of the cryptosystem is displayed on a display device ( 40 ) of the data carrier ( 10 ).

Claims (40)

1. A method for setting up a secured communication channel between a portable data carrier and a terminal on the basis of an asymmetric crypto system, the method comprising:

deriving a value from a public key of the asymmetric crypto system; and

displaying the value on a display device of the portable data carrier,

wherein the portable data carrier is a chip card.

2. The method according to claim 1 , including displaying on a display device of the terminal a value derived from a public key of the crypto system.

3. The method according to claim 1 , including displaying both on the display device of the portable data carrier and on the display device of the terminal both a value derived from a public key assigned to the data carrier and a value derived from a public key assigned to the terminal.

4. The method according to claim 1 , wherein the value from a public key and displayed on the display device of the terminal is input to the portable data carrier via an input device of the portable data carrier and is compared in the data carrier with a value which has been derived from a public key received by the data carrier.

5. The method according to claim 1 , wherein the value derived from a public key and displayed on the display device of the data carrier is input to the terminal via an input device of the terminal and is compared in the terminal with a value which has been derived from a public key received by the terminal.

6. The method according to claim 1 , wherein the value derived from a public key of the crypto system is transmitted to a communication partner before the associated public key.

7. The method according to claim 1 , wherein the value derived from a public key of the crypto system is formed by means of a hash function.

8. The method according to claim 1 , including generating a common secret on the basis of an asymmetric crypto system using the public and the private keys of the terminal and of the data carrier.

9. The method according to claim 1 , wherein the value from a public key of the crypto system is formed by means of an authentication check value.

10. The method according to claim 9 , wherein a PIN for forming the authentication check value is made available.

11. The method according to claim 10 , wherein the PIN is stored or is generated in the terminal, is displayed on a display device of the terminal and is input to the data carrier via an input device of the data carrier.

12. The method according to claim 1 , including making a PIN for the encrypted transmission of the public key of the data carrier to the terminal.

13. The method according to claim 12 , wherein the PIN is specified by the data carrier and is input to the terminal via an input device of the terminal.

14. The method according to claim 13 , wherein the PIN is generated in the data carrier and is displayed on the display device of the data carrier.

15. The method according to claim 1 , wherein before the setting up of a secured communication channel, the user of the data carrier makes a declaration of will vis-a-vis the data carrier.

16. The method according to claim 15 , wherein the declaration of will is effected with the help of the input device of the data carrier.

17. A method for setting up a secured communication channel between a portable data carrier and a terminal on the basis of a crypto system based on a secret datum, the method comprising:

making available the secret datum by the terminal,

displaying the secret datum on a display device of the terminal, and

transferring the secret datum to the data carrier,

wherein the portable data carrier is a chip card.

18. The method according to claim 17 , including transferring the secret datum to the data carrier by inputting the secret datum to the data carrier via an input device of the data carrier.

19. The method according to claim 17 , wherein the secret datum is displayed on a display device of the data carrier.

20. The method according to claim 17 , wherein the method is further based on an asymmetric crypto system and comprises

deriving a value from a public key of the asymmetric crypto system; and

displaying the value on a display device of the portable data carrier.

21. A portable data carrier comprising:

a display device, and

a control device configured to set up a secured communication channel to a terminal on the basis of at least one of an asymmetric crypto system and a crypto system based on a secret datum via a data communication interface of the data carrier,

wherein the control device is arranged to display a value derived from a public key of the asymmetric crypto system on the display device and/or to display a secret datum received from the terminal via the data communication interface or an input device of the data carrier on the display device,

wherein the portable data carrier is a chip card.

22. The data carrier according to claim 21 , wherein the data carrier and the control device are arranged to

derive a value from a public key of the asymmetric crypto system, and

display the value on a display device of the portable data carrier.

23. A system comprising a data carrier according to claim 21 , and as a terminal, wherein the terminal and the data carrier are configured to

derive a value from a public key of the asymmetric crypto system, and

display the value on a display device of the portable data carrier.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2017
From: GIESECKE & DEVRIENT GMBH
To: GIESECKE+DEVRIENT MOBILE SECURITY GMBH
Reel/Frame 044559/0969 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2012
From: EICHHOLZ, JAN; MEISTER, GISELA; WACKER, DIRK; SAUERMANN, MARKUS
To: GIESECKE & DEVRIENT GMBH
Reel/Frame 028032/0170 →