IP Library › Granted Patent US 12,019,717
Granted Patent B2
US 12,019,717 · App. 17/328,294 · Granted Jun 25, 2024

Method for the secure interaction of a user with a mobile terminal and a further entity

Inventor: Bastian Bartels (Wolfsburg, DE)
Assignee: VOLKSWAGEN AKTIENGESELLSCHAFT
G06F21/305G06F21/35G06F21/44H04L63/0853H04W4/40H04W4/80H04W12/041H04W12/065H04W12/068G06F2221/2151
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,019,717
App. No.
17/328,294
Granted
Jun 25, 2024
Kind
B2
Abstract

A method for the secure interaction of a user with a mobile terminal and a further entity includes transmitting a secret or an image of the secret generated by a one-way function and an individual data from the user to a back-end, transmitting the image and the individual data from the back-end to a protected execution environment of a processor of the mobile terminal; notifying the user on a secure user interface of the mobile terminal, wherein the individual data is displayed to the user and wherein the user is authenticated with the secret, the user interacting with a secure element of the mobile terminal having a secure connection with the protected execution environment, via the secure user interface and the protected execution environment; and the secure element interacting with the further entity via a secured connection providing a complete security chain of all entities involved in the interaction.

Claims (29)

1. A method for secure interaction of a user's mobile terminal and a further entity, the method comprising:

transmitting a secret or an image of the secret generated by a one-way function and an individual datum from the user's mobile terminal to a backend;

transmitting the image and the individual datum from the backend to a protected execution environment of a processor of the user's mobile terminal;

registering the user at a secure user interface of the user's mobile terminal, wherein the individual datum is shown to the user via the user's mobile terminal and wherein the user is authenticated with the secret;

enabling interaction of the user with a secure element of the user's mobile terminal which has a secure connection to the protected execution environment via the secure user interface of the user's mobile terminal and the protected execution environment based on the authentication; and

enabling interaction of the secure element with the further entity via a secured connection based on the authentication,

wherein the secure user interface is thereafter declared as a secure device by the protected execution environment based on the authentication.

2. The method of claim 1 , wherein the connection between the protected execution environment and the secure element is protected by a key obtained from the backend.

3. The method of claim 1 , wherein a program for interaction with the further entity is executed in an operating system of the user's mobile terminal, and the program interacts with the further entity via the secure element.

4. The method of claim 3 , wherein a secure connection running by the secure element is established between the backend and the program.

5. The method of claim 4 , wherein the secure element comprises a communication interface for the program and a communication interface for the further entity, and the capabilities of at least one communication interface are configured based on the interaction of the user.

6. The method of claim 1 , wherein, for secure communication between the mobile terminal and the further entity, a key is present in the backend and in the further entity, a derivation of the key is inserted into the secure element, and a derivation of the key is performed in the further entity for an authentic connection.

7. The method of claim 1 , wherein the image of the secret is generated by the backend based on the secret transmitted to the backend.

8. A system for secure interaction of a user with a mobile terminal and a further entity, the system comprising:

a backend in which a secret or an image of the secret and of an individual datum transmitted from a user is generated by a one-way function and stored, wherein the backend transmits the image and the individual datum to a protected execution environment of a processor of the mobile terminal for storage;

a secure user interface of the mobile terminal for registration and authentic interaction of the user, wherein the individual datum is shown to the user;

a secure element of the mobile terminal which, with the protected execution environment, comprises a secure connection; and

a further entity for protected communication with the secure element of the mobile terminal,

wherein the user is authenticated using the secret,

wherein authentication enables interaction of the user with the a secure element of the mobile terminal using the secure connection to the protected execution environment via the secure user interface and the protected execution environment,

wherein authentication further enables interaction of the secure element with the further entity via the secured connection, and

wherein the secure user interface is thereafter declared as a secure device by the protected execution environment based on the authentication.

9. The system of claim 8 , wherein the mobile terminal and the further entity comprise a communication interface of a wireless communication standard.

10. The system of claim 8 , wherein the further entity is a transportation vehicle.

11. The system of claim 8 , wherein the connection between the protected execution environment and the secure element is protected by a key obtained from the backend.

12. The system of claim 8 , wherein a program for interaction with the further entity is executed in an operating system of the mobile terminal, and the program interacts with the further entity via the secure element.

13. The system of claim 11 , wherein a secure connection running by the secure element is established between the backend and the program.

14. The system of claim 13 , wherein the secure element comprises a communication interface for the program and a communication interface for the further entity, and the capabilities of at least one communication interface are configured based on the interaction of the user.

15. The system of claim 8 , wherein, for secure communication between the mobile terminal and the further entity, a key is present in the backend and in the further entity, a derivation of the key is inserted into the secure element, and a derivation of the key is performed in the further entity for an authentic connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2021
From: BARTELS, BASTIAN
To: VOLKSWAGEN AKTIENGESELLSCHAFT
Reel/Frame 056330/0590 →
Priority Claims (1)
DE 10 2016 207 339.7 · Apr 29, 2016 · national
Continuity (2)
Continuation 16095993
Related Publication 20210279307A1 · Sep 9, 2021