首页> 外国专利> System and method for securing communications between a card reader device and a remote server

System and method for securing communications between a card reader device and a remote server

机译:用于确保读卡器设备与远程服务器之间的通信安全的系统和方法

摘要

The present invention concerns the implementation of end-to-end security for the communication between a low cost card reader and the remote server. The purpose of the present invention is the establishment of a secure channel between the card reader and the remote server through an un-trusted communication device (e.g. a smart phone or a tablet) that is intrinsically resistant to some basic differential side-channel analysis in a context where there is no secure random number generator and no source of entropy in the card reader, while providing the following characteristics:- Mutual authentication between the card reader and the server- Secure channel based on session keys such that the keys of the secure channel related to a past transaction cannot be re-played, or the session keys of a future transaction cannot be pre-computed by the card reader and later re-use by the card reader in a legitimate transaction.
机译:本发明涉及用于低成本读卡器和远程服务器之间的通信的端到端安全性的实现。本发明的目的是通过不可信的通信设备(例如,智能电话或平板电脑)在读卡器和远程服务器之间建立安全通道,该安全通道本质上抵抗某些基本的差分侧通道分析。在读卡器中没有安全随机数生成器且没有熵源的情况下,同时提供以下特征:-读卡器和服务器之间的相互认证-基于会话密钥的安全通道,使得无法重播与过去交易相关的安全通道的密钥,或者读卡器无法预先计算未来交易的会话密钥,并且以后无法再次使用合法交易中的读卡器。

著录项

  • 公开/公告号EP2874421A1

    专利类型

  • 公开/公告日2015-05-20

    原文格式PDF

  • 申请/专利权人 GEMALTO SA;

    申请/专利号EP20130306551

  • 申请日2013-11-13

  • 分类号H04W12/06;H04L29/06;G06Q20/32;G06Q20/20;G06Q20/40;G06Q20/38;

  • 国家 EP

  • 入库时间 2022-08-21 15:02:43

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号