IP Library Granted Patent US 7,894,601
Granted Patent B2
US 7,894,601 · App. 11/771,326 · Granted Feb 22, 2011

Method for key diversification on an IC card

Assignee: Incard S.A.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,894,601
App. No.
11/771,326
Granted
Feb 22, 2011
Kind
B2
Abstract

Key diversification is performed during a mutual authentication between a SAM integrated circuit (IC) card storing a master key, and a user IC card storing an identification number. The user IC card is connected to the SAM IC card through a communications interface. The key diversification includes deriving sub keys from the master key, and computing ciphered strings through corresponding cryptographic computations on a string obtained by an elaboration on the identification number with the sub keys. A diversification key is generated by linking together a combination of bytes of the ciphered strings.

Claims (42)

1. A method for generating a diversification key during an authentication between a master IC card having a master key associated therewith and a user IC card having an identification number associated therewith, the method comprising:

deriving a plurality of sub-keys from the master key;

computing a plurality of ciphered strings through corresponding cryptographic computations on a string with the sub-keys, the string obtained by performing an elaboration of the identification number;

the elaboration comprising performing

a CRC operation on the identification number, and

a concatenation of the identification number with a fixed text string and at least one of a most significant byte and a least significant byte of the CRC operation; and

building the diversification key by concatenating a combination of bytes of the plurality of ciphered strings.

2. A method according to claim 1 , further comprising coupling the user IC card and the master IC card through a communication interface.

3. A method according to claim 1 , wherein the combination of bytes is obtained by performing a XOR operation on the plurality of ciphered strings.

4. A method according to claim 1 , further comprising adjusting at least one parity bit for the diversification key.

5. A method according to claim 1 , wherein the cryptographic computations comprise at least one DES computation.

6. A method for generating a diversification key during a mutual authentication between a master IC card having a master key associated therewith, and a user IC card having an identification number associated therewith, the user IC card being connected to the master IC card through a communication interface, the method comprising:

deriving a plurality of sub-keys from the master key;

computing a plurality of ciphered strings through corresponding cryptographic computations on a string with the sub-keys, the string obtained by performing an elaboration on the identification number including a CRC operation on the identification number;

the elaboration also including a concatenation of the identification number with a fixed text string and at least one of a most significant byte and a least significant byte of the CRC operation; and

building the diversification key by concatenating a combination of bytes of the plurality of ciphered strings.

7. A method according to claim 6 , wherein the combination of bytes is obtained by performing a XOR operation on the plurality of ciphered strings.

8. A method according to claim 6 , further comprising adjusting at least one parity bit for the diversification key.

9. A method according to claim 6 , wherein the cryptographic computations comprise one or more DES computations.

10. An IC card having an identification number associated therewith to communicate with a master IC card having a master key associated therewith, the IC card comprising:

an IC card substrate; and

a processor carried by said IC card substrate and being configured to derive a plurality of sub-keys from the master key and to compute a plurality of ciphered strings through corresponding cryptographic computations on a string with the sub-keys, the string obtained by performing an elaboration of the identification number;

said processor performing the elaboration by

performing a CRC operation on the identification number, and

performing a concatenation of the identification number with a fixed text string and at least one of a most significant byte and a least significant byte of the CRC operation;

said processor being further configured to build a diversification key by concatenating a combination of bytes of the plurality of ciphered strings.

11. An IC card according to claim 10 , wherein said processor is configured to obtain the combination of bytes by performing a XOR operation on the plurality of ciphered strings.

12. An IC card according to claim 10 , wherein said processor is further configured to adjust at least one parity bit for the diversification key.

13. An IC card according to claim 10 , wherein said processor performs the cryptographic computations by performing at least one DES computation.

14. A communication system comprising:

a master IC card having a master key associated therewith;

a user IC card having an identification number associated therewith and comprising:

an IC card substrate, and

a processor carried by said IC card substrate and being configured to derive a plurality of sub-keys from the master key and to compute a plurality of ciphered strings through corresponding cryptographic computations on a string with the sub-keys, the string obtained by performing an elaboration of the identification number,

said processor performing the elaboration by

performing a CRC operation on the identification number, and

performing a concatenation of the identification number with a fixed text string and at least one of a most significant byte and a least significant byte of the CRC operation;

said processor being further configured to build a diversification key by concatenating a combination of bytes of the plurality of ciphered strings; and

a communication interface to couple said master IC card to said user IC card.

15. A communication system according to claim 14 , wherein said processor is configured to obtain the combination of bytes by performing a XOR operation on the plurality of ciphered strings.

16. A communication system according to claim 14 , wherein said processor is further configured to adjust at least one parity bit for the diversification key.

17. A communication system according to claim 14 , wherein said processor performs the cryptographic computations by performing at least one DES computation.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2013
From: INCARD SA
To: STMICROELECTRONICS N.V.
Reel/Frame 030669/0192 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2013
From: STMICROELECTRONICS N.V.
To: STMICROELECTRONICS INTERNATIONAL N.V.
Reel/Frame 030669/0257 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2007
From: FONTANA, GIOVANNI; DONATIELLO, SAVERIO
To: INCARD S.A.
Reel/Frame 019499/0397 →
Priority Claims (1)
EP 06013463 · Jun 29, 2006 · regional
Continuity (1)
Related Publication 20080008315A1 · Jan 10, 2008