IP Library Granted Patent US 11,146,409
Granted Patent B2
US 11,146,409 · App. 16/012,645 · Granted Oct 12, 2021

Process for challenge response authentication of a secure element (SE) in a micro controller unit

Inventors: Houssem Maghrebi (Issy-les-Moulineaux, FR); Ahmadou Sere (Issy-les-Moulineaux, FR); David Daille-Lefevre (Issy-les-Moulineaux, FR); Deny Carhuel (Issy-les-Moulineaux, FR)
Assignee: IDEMIA IDENTITY & SECURITY FRANCE
H04L9/3271H04L9/0869H04L9/3231H04L63/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,146,409
App. No.
16/012,645
Granted
Oct 12, 2021
Kind
B2
Abstract

Challenge-response authentication process of a secure element (SE) in a micro controller unit (MCU) devoid of a random number generator. The process includes the following steps conducted by the micro controller unit (MCU): receipt of at least one random datum (T, IDX) generated randomly by the secure element (SE), generation of a challenge datum (Z) specific to the micro controller unit (MCU) from the received random datum (T, IDX), sending of the generated challenge datum (Z) to the secure element (SE), receipt of a response datum (R) generated by the secure element (SE) as a function of the challenge datum (Z), and determination of an authentication result as a function of the received response datum.

Claims (61)

1. A challenge-response authentication process of a secure element in a micro controller unit devoid of a random number generator, the process comprising the following steps conducted by the micro controller unit:

receiving at least one random datum generated randomly by the secure element, wherein said at least one random datum comprises a set of random data,

generating a challenge datum specific to the micro controller unit from the received random datum, wherein generating the challenge datum comprises:

selecting a first random datum and a second random datum data in the set of random data, and

encrypting the first random datum by using the second random datum as an encryption key so as to produce an encrypted random datum, wherein the challenge datum depends on the encrypted random datum,

sending the generated challenge datum to the secure element,

receiving a response datum generated by the secure element from the challenge datum,

determining an authentication result as a function of the received response datum.

2. The process according to claim 1 , wherein the set of random data comprises a table and an index datum associated with the table, and selecting the first random datum in the set of random data comprises locating the first random datum in the table using the index datum.

3. The process according to claim 2 , wherein the second random datum is a complement of the first random datum in the table.

4. The process according to claim 1 , wherein generating the challenge datum also comprises truncating the encrypted random datum.

5. A challenge-response authentication process of a secure element in a micro controller unit devoid of a random number generator, the process comprising the following steps conducted by the secure element:

randomly generating at least one random datum, wherein said at least one random datum comprises a set of random data,

sending the random datum to the micro controller unit,

receiving a challenge datum specific to the micro controller unit and generated by the micro controller unit from the random datum sent,

generating a response datum from the received challenge datum,

sending of the response datum to the micro controller unit in order to determine an authentication result as a function of the response datum sent,

wherein generating the challenge datum comprises:

selecting a first random datum and a second random datum data in the set of random data, and

encrypting the first random datum by using the second random datum as an encryption key so as to produce an encrypted random datum, wherein the challenge datum depends on the encrypted random datum.

6. The process according to claim 5 , further comprising:

generating at the secure element another challenge datum from the generated random datum,

comparing the challenge datum received by the secure element and the other challenge datum generated by the secure element,

executing a security measure adapted so that the authentication result is negative when the compared challenge data are different.

7. The process according to claim 1 , wherein the secure element is a smart card or wherein the micro controller unit is a transmission interface of biometric data previously acquired by a biometric sensor to the secure element.

8. A micro controller unit devoid of a random number generator, wherein the micro controller unit comprises a communication interface with a secure element, and further comprises at least one processor configured, during an authentication of the secure element by challenge-response in the micro controller unit, to:

receive, via the communication interface, at least one random datum generated randomly by the secure element, wherein said at least one random datum comprises a set of random data,

generate a challenge datum specific to the micro controller unit from the received random datum,

control sending by the communication interface of the generated challenge datum to the secure element,

receive, via the communication interface, a response datum generated by the secure element from the challenge datum,

determine an authentication result as a function of the received response datum,

wherein generating the challenge datum comprises:

selecting a first random datum and a second random datum data in the set of random data, and

encrypting the first random datum by using the second random datum as an encryption key so as to produce an encrypted random datum, wherein the challenge datum depends on the encrypted random datum.

9. A secure element comprising a communication interface with a micro controller unit devoid of a random number generator, wherein the secure element comprises at least one processor configured, during an authentication of the secure element by challenge-response in the micro controller unit, to:

randomly generate at least one random datum, wherein said at least one random datum comprises a set of random data,

control sending of the random datum to the micro controller unit by the communication interface,

receive a challenge datum specific to the micro controller unit and generated by the micro controller unit from the sent random datum,

generate a response datum from the received challenge datum,

control sending by the communication interface of the response datum to the micro controller unit in order to determine an authentication result as a function of the sent response datum,

wherein venerating the challenge datum comprises:

selecting a first random datum and a second random datum data in the set of random data, and

encrypting the first random datum by using the second random datum as an encryption key so as to produce an encrypted random datum, wherein the challenge datum depends on the encrypted random datum.

10. A non-transitory computer-readable medium comprising code instructions for causing a micro controller unit devoid of a random number generator to perform a challenge-response authentication process of a secure element in the micro controller unit, the process comprising:

receiving at least one random datum generated randomly by the secure element, wherein said at least one random datum comprises a set of random data,

generating a challenge datum specific to the micro controller unit from the received random datum,

sending the generated challenge datum to the secure element,

receipt of a response datum generated by the secure element from the challenge datum,

determining an authentication result as a function of the received response datum,

wherein generating the challenge datum comprises:

selecting a first random datum and a second random datum data in the set of random data, and

encrypting the first random datum by using the second random datum as an encryption key so as to produce an encrypted random datum, wherein the challenge datum depends on the encrypted random datum.

11. A non-transitory computer-readable medium comprising code instructions for causing a secure element to perform a challenge-response authentication process of a secure element in a micro controller unit devoid of a random number generator, the process comprising:

randomly generating at least one random datum, wherein said at least one random datum comprises a set of random data,

sending the random datum to the micro controller unit,

receiving a challenge datum specific to the micro controller unit and generated by the micro controller unit from the random datum sent,

generating a response datum from the received challenge datum,

sending of the response datum to the micro controller unit in order to determine an authentication result as a function of the response datum sent,

wherein generating the challenge datum comprises:

selecting a first random datum and a second random datum data in the set of random data, and

encrypting the first random datum by using the second random datum as an encryption key so as to produce an encrypted random datum, wherein the challenge datum depends on the encrypted random datum.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA FRANCE
Reel/Frame 070632/0157 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2019
From: MAGHREBI, HOUSSEM; SERE, AHMADOU; DAILLE-LEFEVRE, DAVID; CARUHEL, DENY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 049597/0828 →