US2019035201A1PendingUtilityA1
Method and apparatus for establishing trust in smart card readers
Est. expiryDec 24, 2023(expired)· nominal 20-yr term from priority
Inventors:Joseph F. Cihula
G07F 7/1008G07F 7/08G06Q 20/40975G06Q 20/4016G06Q 20/367G06Q 20/341G07F 7/12
51
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method for managing a smart card system includes testing a smart card reader for trustworthiness. An indication of the trustworthiness is provided via a smart card.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for managing a smart card system, comprising:
testing a smart card reader for trustworthiness by comparing a test result for a component of the smart card reader with an acceptable test result stored on a smart card; and providing an indication of the trustworthiness of the smart card reader to a smart card user via the smart card.
2 . The method of claim 1 , wherein testing the smart card reader for trustworthiness comprises:
transmitting a request to the smart card reader for trust data; and determining whether the trust data received is acceptable.
3 . The method of claim 2 , wherein determining whether the trust data is acceptable comprises:
determining whether a first certificate has a valid digital signature; determining whether a public key from the first certificate is trustworthy; and comparing data in the first certificate with data in the smart card.
4 . The method of claim 3 , wherein determining whether the public key from the first certificate is trustworthy comprises:
decrypting a signature of a second certificate with a public key for the second certificate to generate a first digest for the second certificate; performing a hash function on data in the second certificate to generate a second digest for the second certificate; identifying the data in the second certificate as the public key for the first certificate if the first digest and the second digest match; and comparing the data in the second certificate with the public key from the first certificate.
5 . The method of claim 3 , wherein determining whether the first certificate has the valid digital signature comprises:
decrypting a signature of the first certificate with the public key for the first certificate to generate a first digest for the first certificate; performing a hash function on data in the first certificate to generate a second digest for the first certificate; and comparing the first digest for the first certificate with the second digest for the first certificate.
6 . The method of claim 1 , wherein providing an indication of the trustworthiness on the smart card comprises turning on a light.
7 . The method of claim 1 , wherein providing an indication of the trustworthiness of the smart card comprises generating an audible sound.
8 . The method of claim 2 , wherein the request includes a nonce.
9 . The method of claim 3 , further comprising comparing a nonce from the smart card with a nonce from the smart card reader.
10 . The method of claim 2 , wherein determining whether the trust data is acceptable comprises:
determining whether signed data has a valid digital signature; determining whether a public key from the signed data is trustworthy; and comparing data in the first signed data with data in the smart card.
11 . The method of claim 9 , wherein the signed data includes measurement values.
12 . A method for managing a smart card system, comprising:
testing a smart card reader for trustworthiness by comparing an identity of a component of the smart card reader with an acceptable identity stored on a smart card; and providing an indication of the trustworthiness of the smart card reader to a smart card user via the smart card.
13 . A method for managing a smart card system, comprising:
testing a smart card reader for trustworthiness by comparing a measurement value of a component of the smart card reader with an acceptable measurement value stored on a smart card; and providing an indication of the trustworthiness of the smart card reader to a smart card user via the smart card.
14 . A smart card, comprising:
an attestation verifier unit to test a trustworthiness of a smart card reader by comparing a test result of a component of the smart card reader with an acceptable test result stored on a smart card.
15 . The smart card of claim 14 , wherein the attestation verifier unit comprises a digest decrypter unit to decrypt an encrypted digest.
16 . A method for managing a smart card system, comprising:
testing a smart card reader for trustworthiness; and providing an indication of the trustworthiness of the smart card reader to a smart card user via the smart card.
17 . The method of claim 16 , wherein providing an indication comprises turning on a light.
18 . The method of claim 16 , wherein providing an indication comprises generating an audible sound.
19 . The method of claim 16 , wherein providing an indication comprises producing a vibration.
20 . The method of claim 16 , wherein providing an indication comprises changing a temperature of the smart card.Join the waitlist — get patent alerts
Track US2019035201A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.