WO2006010913A1 - Remote smartcard application management - Google Patents
Remote smartcard application management Download PDFInfo
- Publication number
- WO2006010913A1 WO2006010913A1 PCT/GB2005/002907 GB2005002907W WO2006010913A1 WO 2006010913 A1 WO2006010913 A1 WO 2006010913A1 GB 2005002907 W GB2005002907 W GB 2005002907W WO 2006010913 A1 WO2006010913 A1 WO 2006010913A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- file system
- file
- commands
- accessing
- content
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07F—COIN-FREED OR LIKE APPARATUS
- G07F7/00—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
- G07F7/08—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
- G07F7/10—Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data
- G07F7/1008—Active credit-cards provided with means to personalise their use, e.g. with PIN-introduction/comparison system
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/341—Active cards, i.e. cards including their own processing means, e.g. including an IC or chip
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/355—Personalisation of cards for use
- G06Q20/3552—Downloading or loading of personalisation data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/34—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using cards, e.g. integrated circuit [IC] cards or magnetic cards
- G06Q20/357—Cards having a plurality of specified features
Definitions
- the present invention relates to systems utilising programmable devices such as so-called 'smartcards', including systems which use such devices for financial transactions.
- the system described in the earlier application referred to above is a component- based architecture framework which interacts with ISO 7816 compliant smartcard applications.
- This architecture allows both new applications and existing applications to interact with information stored on a smartcard without any knowledge of how or where that information is sourced.
- the system uses a set of security policies and conditions to determine the access rights to the files and objects stored on the cards and modifies the behaviour of the system accordingly.
- the file system, structure and content, the commands for accessing the file system and the security conditions associated with the files in the file system can all be described uniquely by means of a file formatted in extensible Markup Language ('XML 1 ), a web standard for self-describing messages.
- 'XML 1 extensible Markup Language
- a programmable device carrying a file system and operating software enabling the on-device file system to interface with at least one off-device file and/or application; the structure and content of the file system, the commands to be used for accessing the file system and any security conditions associated therewith being defined by at least one file formatted in a web (internet) standard language for self -describing messages; the device including means for running a script derived from the said at least one file to modify structure and content of the file system, or the commands to be used for accessing the file system or any security conditions associated therewith
- an interface device comprising means for upgrading the on-device file system by loading to the programmable device a script derived from at least one file formatted in a web (internet) standard language for self - describing messages so as to modify definitions of the structure and content of the on-device file system, or the commands to be used for accessing the file system or any security conditions associated therewith, and
- a secure software distribution means between the software tool and the interface device to provide secure distribution of the file formatted in web (internet) standard language for self-describing messages or any script or file derived therefrom; • the software tool including at least one input form accessible on-line over a computer network or the internet to allow the holder of a programmable device to input data to be used to modify definitions of the structure and content of the on-device file system, or the commands to be used for accessing the file system or any security conditions associated therewith.
- the invention provides a degree of self-management of the card and terminal applications by the cardholders themselves.
- the invention proposes that fragments of XML templates are accessed by the cardholder via web forms available at one or more websites available on the internet or other similar computer network.
- the form comprises a file or a portion of a file formatted in web (internet) standard language for self-describing messages, for example an XML document or template.
- the cardholder logs into a web site using the smartcard previously issued to them under a scheme of the kind described in described in International Patent Application No WO03/049056 to verify or authenticate their identity and selects a form to complete.
- This form could be chosen with a view, for example, to registering with a medical specialist or to applying for school meals.
- Undertaking an operation of this kind requires a change to the data stored on the cardholder's card and to the security policies to be enforced by it.
- the right to access certain data might be enforced by a remote authentication from a third party using the key assigned to a professional role holder or service provider, eg. a medical specialist or a benefits officer.
- a professional role holder or service provider eg. a medical specialist or a benefits officer.
- the resulting XML document with the specific data added by the card holder through the medium of the web form, then goes through the rest of the application generation process described in International Patent Application No WO03/049056, fetching the appropriate key-material and preparing a secure script to download to the card holder's card when the card holder next interacts with one of the scheme's interface devices.
- the system may then also distribute the terminal or interface component of the XML to a predefined terminal base relevant to the specific service to be provided by the professional role holder, for example, a message might also be sent to a selected medical specialist's terminal to interoperate with that terminal so that it will provide the newly required service to the card holder as requested when the web form was completed.
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Microelectronics & Electronic Packaging (AREA)
- Computer Networks & Wireless Communication (AREA)
- Accounting & Taxation (AREA)
- Strategic Management (AREA)
- General Business, Economics & Management (AREA)
- Theoretical Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| GB0416618A GB0416618D0 (en) | 2004-07-26 | 2004-07-26 | Remote smartcard application management |
| GB0416618.7 | 2004-07-26 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2006010913A1 true WO2006010913A1 (en) | 2006-02-02 |
Family
ID=32922800
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/GB2005/002907 Ceased WO2006010913A1 (en) | 2004-07-26 | 2005-07-26 | Remote smartcard application management |
Country Status (2)
| Country | Link |
|---|---|
| GB (1) | GB0416618D0 (en) |
| WO (1) | WO2006010913A1 (en) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO1999040549A1 (en) * | 1998-02-03 | 1999-08-12 | Mondex International Limited | System and method for controlling access to computer code in an ic card |
| WO2003049056A2 (en) * | 2001-12-07 | 2003-06-12 | Ecebs Limited | Smartcard system |
-
2004
- 2004-07-26 GB GB0416618A patent/GB0416618D0/en not_active Ceased
-
2005
- 2005-07-26 WO PCT/GB2005/002907 patent/WO2006010913A1/en not_active Ceased
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO1999040549A1 (en) * | 1998-02-03 | 1999-08-12 | Mondex International Limited | System and method for controlling access to computer code in an ic card |
| WO2003049056A2 (en) * | 2001-12-07 | 2003-06-12 | Ecebs Limited | Smartcard system |
Also Published As
| Publication number | Publication date |
|---|---|
| GB0416618D0 (en) | 2004-08-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP4348190B2 (en) | Smart card system | |
| US9769163B1 (en) | System integrating an identity selector and user-portable device and method of use in a user-centric identity management system | |
| US9768965B2 (en) | Methods and apparatus for validating a digital signature | |
| US20020078159A1 (en) | Method and system for the approval of an electronic document over a network | |
| US20070300057A1 (en) | Dynamic Web Services Systems and Method For Use of Personal Trusted Devices and Identity Tokens | |
| DE60122612T2 (en) | Authentication device and user authentication system and method | |
| WO2002048843A2 (en) | Web-based method and system for applying a legally enforceable signature on an electronic document | |
| WO2009123712A2 (en) | Information server and mobile delivery system and method | |
| JP6042766B2 (en) | Electronic trading system, electronic trading method, and program | |
| EP2692157A2 (en) | Updating a data storage medium application | |
| CN109767359A (en) | Endorsement method, device, equipment and storage medium based on fingerprint recognition | |
| US7540416B2 (en) | Smart card authentication system with multiple card and server support | |
| WO2006010913A1 (en) | Remote smartcard application management | |
| JP4156388B2 (en) | AP addition / AP personalization method, implementation apparatus thereof, and processing program thereof | |
| EP3147809B1 (en) | Processing files to be stored on virtual drive | |
| JP2003187194A (en) | Terminal device, personal information processing device and revocation information file creating device | |
| Horsch et al. | The German eCard-Strategy | |
| Cooper et al. | Interfaces for Personal Identity Verification–Part 1: PIV Card Application Namespace, Data Model and Representation | |
| Hühnlein et al. | How to use ISO/IEC 24727-3 with arbitrary Smart Cards | |
| Elliott | The one-card trick. Multi-application smart card E-commerce prototypes | |
| KR101020059B1 (en) | How to adjust the work element file storage area in ICChip | |
| Bühler et al. | Security versus usability–user-friendly qualified signatures based on German ID cards | |
| KR100971120B1 (en) | How to adjust the work element file storage area included in the smart card | |
| CN118819626A (en) | Data processing method and device, non-volatile storage medium, and electronic device | |
| Hybl | The Czech Social Security Smart Card |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KM KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NG NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SM SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW |
|
| AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LT LU LV MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |