IP Library Granted Patent US 10,243,745
Granted Patent B2
US 10,243,745 · App. 15/219,786 · Granted Mar 26, 2019

Method and system for producing a secure communication channel for terminals

Inventors: Steffen Fries (Baldham, DE); Marcus Schafheutle (München, DE)
Assignee: Siemens Aktiengesellschaft
H04L9/3247H04L9/30H04L9/3263H04L9/3268H04L63/0281H04L63/08H04L63/123H04W12/06H04L63/0428H04L63/0823H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,243,745
App. No.
15/219,786
Granted
Mar 26, 2019
Kind
B2
Abstract

A method, system, backend, terminal, and computer program product are disclosed for producing a secure communication channel for a terminal, the method having the following method steps. A first method step for setting up a secure communication channel between a communication partner and a backend by a communication protocol. A second method step for producing a communication channel between the communication partner and the terminal. A third method step for transmitting the channel binding information. A fourth method step for storing the channel binding information on the terminal. A fifth method step for creating a data structure and a first digital signature across the data structure y. A sixth method step for sending the data structure and the digital signature from the backend to the terminal. A seventh method step for checking authenticity of the data structure.

Claims (20)

1. A system having:

a backend having

a first cryptography device;

a production device for creating a data structure and a first digital signature across the data structure using the first cryptography device and a first private key, the first digital signature being able to be checked using a public key;

a first communication device which is programmed by a first processor

to send the data structure and the first digital signature to a terminal;

to set up a secure communication channel to a communication partner by a communication protocol using the first cryptography device, an item of channel binding information respectively being stipulated by the communication protocol for the backend and for the communication partner;

the communication partner having

a second cryptography device;

a second communication device which is programmed by a second processor

to set up the secure communication channel to the backend using the second cryptography device,

to set up a communication channel to the terminal, and

to send the channel binding information to the terminal;

the terminal having

a third communication device which is programmed by a third processor

to set up the communication channel to the communication partner,

to receive the channel binding information and/or the data structure and/or the first digital signature and/or the public key, wherein the public key being made available to the terminal at an earlier time, the earlier time being, the manufacturing time of the terminal, the public key being protected, from being changed on the terminal;

a checking device for checking authenticity of the data structure by a checking algorithm using the first digital signature and the public key;

a memory for storing the channel binding information and/or the data structure and/or the first digital signature and/or the public key, wherein the first private key being a secret which is known to the backend, the secret being known, exclusively to the backend.

2. The system as claimed in claim 1 , the system being a virtualized system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2016
From: FRIES, STEFFEN; SCHAFHEUTLE, MARCUS
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 039775/0501 →
Priority Claims (1)
DE 10 2015 214 267 · Jul 28, 2015 · national
Continuity (1)
Related Publication 20170033931A1 · Feb 2, 2017