IP Library Granted Patent US 10,404,719
Granted Patent B2
US 10,404,719 · App. 15/819,637 · Granted Sep 3, 2019

Data verification method

Inventors: Jean-Yves Bernard (Meyreuil, FR); Yves Fusella (Meyreuil, FR); Maël Berthier (Issy les Moulineaux, FR); Lauren Del Giudice (Issy les Moulineaux, FR)
Assignees: IDEMIA IDENTITY & SECURITY FRANCE; STARCHIP
H04L63/126G06F12/1408G06F21/554G06F21/64G06F21/71G06F21/72G06F21/77H04L9/3226H04L9/3242H04L63/18G06F2221/2105H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,404,719
App. No.
15/819,637
Granted
Sep 3, 2019
Kind
B2
Abstract

Method for verifying data generated by an electronic device included in equipment, the electronic device including a computing unit, a one-time programmable memory and a volatile memory, the equipment including a rewritable non-volatile memory and a communication bus enabling the electronic device to store data in the rewritable non-volatile memory. The method includes: creating a secured channel by encryption between the equipment and a server; obtaining an authentication key from the server; loading data and a message authentication code from the rewritable non-volatile memory to the volatile memory, the message authentication code obtained by the electronic device from the authentication key and said data prior to the storage of said data and message authentication code in the rewritable non-volatile memory, the electronic device not having kept the authentication key following the obtaining of the message authentication code; verifying said data using the secret key and the message authentication code.

Claims (16)

1. A method for verifying data generated by an electronic device included in equipment suitable for communicating with a server via a communication network, the electronic device comprising a computing unit, a non-volatile one-time programmable memory and a volatile memory, the equipment comprising a rewritable non-volatile memory and a communication bus enabling the electronic device to store data in the rewritable non-volatile memory, wherein the method is implemented by the electronic device and comprises:

creating a secured channel by encryption between the equipment and the server;

obtaining a message authentication code key, referred to as an authentication key, from the server;

loading data to be verified and a message authentication code corresponding to said data from the rewritable non-volatile memory to the volatile memory, the message authentication code having been obtained by the electronic device from the authentication key and said data prior to the storage of said data and message authentication code in the rewritable non-volatile memory, the electronic device having had available the authentication key only at a time of generation of the message authentication code;

verifying the data to be verified using the authentication key and the message authentication code and allowing use of the data when the verification is positive, but disallowing use of the data when the verification is negative so that no data stored in the rewritable non-volatile memory can be used if the data has not been verified positively by means of the authentication key and the message authentication code, which limits the possibilities of replay attack.

2. The method according to claim 1 , wherein the data to be verified and the message authentication code have been encrypted using a first encryption key stored in the one-time programmable memory prior to storage thereof in the rewritable non-volatile memory and are deciphered following loading thereof in the volatile memory and prior to verification thereof.

3. The method according to claim 1 , wherein the data to be verified are used only when the secured channel between the equipment and the server can be created.

4. The method according to claim 1 , wherein the encryption used for creating the secured channel uses a second encryption key stored in the one-time programmable memory.

5. The method according to claim 1 , wherein the authentication key is obtained by the electronic device following a transmission by the electronic device of a request to obtain said authentication key from the server.

6. The method according to claim 1 , wherein the authentication key was previously generated by the electronic device and transmitted to the server.

7. The method according to claim 1 , wherein the authentication key was previously generated by the server and transmitted to the electronic device for generating security information.

8. The method according to claim 1 , wherein a different new authentication key is generated whenever data are stored by the electronic device in the rewritable non-volatile memory or at predefined regular time intervals or following a predefined number of storages of data in the rewritable non-volatile memory or at randomly determined instants.

9. An electronic device comprising circuitry adapted for implementing the method according to claim 1 .

10. Equipment able to communicate with a server via a communication network comprising a rewritable non-volatile memory and an electronic device according to claim 9 .

11. A system comprising a server and equipment according to claim 10 , the equipment being adapted for communicating with the server via a communication network.

12. A non-transitory information storage medium, storing a computer program comprising instructions for the implementation, by a device, of the method according to claim 1 , when said program is executed by a computing unit of said device.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2024
From: IDEMIA IDENTITY & SECURITY FRANCE/IDEMIA STARCHIP
To: IDEMIA STARCHIP SAS
Reel/Frame 066191/0687 →
CHANGE OF NAME Recorded Jan 16, 2024
From: STARCHIP
To: IDEMIA STARCHIP
Reel/Frame 066128/0311 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S ADDRESS PREVIOUSLY RECORDED ON REEL 045272 FRAME 0786. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNEE'S ADDRESS IS INCORRECT. Recorded Dec 16, 2019
From: BERNARD, JEAN-YVES; FUSELLA, YVES; BERTHIER, MAEL; DEL GIUDICE, LAUREN
To: IDEMIA IDENTITY & SECURITY FRANCE; STARCHIP
Reel/Frame 051313/0212 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2018
From: BERNARD, JEAN-YVES; FUSELLA, YVES; BERTHIER, MAEL; DEL GIUDICE, LAUREN
To: IDEMIA IDENTITY & SECURITY FRANCE; STARCHIP
Reel/Frame 045272/0786 →
Priority Claims (1)
FR 16 61389 · Nov 23, 2016 · national
Continuity (1)
Related Publication 20180145992A1 · May 24, 2018