WO2009083102A1 - Dispositif et procédé de traitement de valeurs de mesure, utilisation d'un support de mémoire pour sauvegarder des composants logiciels signés - Google Patents
Dispositif et procédé de traitement de valeurs de mesure, utilisation d'un support de mémoire pour sauvegarder des composants logiciels signés Download PDFInfo
- Publication number
- WO2009083102A1 WO2009083102A1 PCT/EP2008/010377 EP2008010377W WO2009083102A1 WO 2009083102 A1 WO2009083102 A1 WO 2009083102A1 EP 2008010377 W EP2008010377 W EP 2008010377W WO 2009083102 A1 WO2009083102 A1 WO 2009083102A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- storage medium
- measured values
- signed
- measuring
- module
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C3/00—Registering or indicating the condition or the working of machines or other apparatus, other than vehicles
- G07C3/14—Quality control systems
Definitions
- the invention relates to a device for processing measured values which comprises at least one mechanically sealed measuring device and at least one signed software component for processing the measured values of the measuring device, wherein the mechanically sealed measuring device is connected to a computing unit of the device.
- the invention further relates to a method for securing signed software components for such a device and the use of a storage medium with a write-protect switch for securing signed software components of such a device.
- the authority usually checks the registration documents and a sample device according to the regulations of the respective calibration regulations. Essential aspects here are the measuring accuracy and measuring stability. In particular, the applicable requirements and error limits must be adhered to.
- the admission test includes metrological, technical and administrative examinations.
- the technical examinations which include software examinations, will be examined whether the operating, display and impression functions meet the requirements and the device is sufficiently protected against operating errors and manipulation. Since post office consignments are usually computer controlled, calibration of software components is thus required.
- the applicant will receive from the competent authority a registration certificate and a registration mark which must be displayed on all measuring instruments in a visible place.
- a measuring system may include hardware and software components that are not subject to custody, it is possible to separate custody transferable components from non-custody components. This allows the non-legal components to be freely modified without the need for re-approval or calibration of the entire assembly.
- German patent application DE 195 27 293 A1 discloses, for example, a method and a device for reliable measurement and processing of measured data in the field of exhaust gas analysis.
- a computer connected to a measuring module not to have to be calibrated together with the measuring module, which would lead to a restriction of the initially open PC system, the document suggests that measured values should be transmitted via a suitable PC Interface to a PC.
- the PC does not have to be calibrated, but can also be used freely for other applications.
- German patent application DE 195 27 293 A1 also mentions the solution that is common in this field of depositing custody transferable measuring programs on the EPROM of a computer, where they are protected against manipulation.
- the EPROM is permanently installed and can only seal data stored in the EPROM when installed. After that, no changes can be made.
- this is not possible with a permanently installed EPROM, since its contents can not be changed or supplemented by a calibration official.
- a mailing-in and franking station usually comprises hardware components such as measuring devices and software in conjunction with a search unit which controls the installation and determines the charge for a mailpiece.
- Sealable hardware components can be physically sealed with seals, while software components subject to calibration must be otherwise protected against manipulation.
- Known approaches are not suitable due to the disadvantages mentioned, a custodial and computer-operated device in such a way that a calibration officer on-site check and complement a software requiring custody before it is stored tamper-proof.
- the object of the invention is therefore to provide a method and an associated device which meets these requirements.
- the inventive device for processing measured values comprises at least one mechanically sealed measuring device and at least one signed software component for processing the measured values of the measuring device.
- the mechanically sealed measuring device is connected to a computing unit of the device.
- the signed software component is stored on a storage medium that has a write-protect switch that is mechanically sealed.
- the storage medium may be, for example, a USB stick or a hard disk with a write-protect switch.
- the storage medium is further connected to the computing unit, and the
- Connection between the storage medium and the arithmetic unit is preferably also mechanically sealed.
- the software components may for example be signed by an asymmetric encryption method.
- the device is a delivery station for franking mailpieces which comprise at least one balance for determining the weight of a mailpiece, at least one Dimension measuring device for determining the dimensions of a mail piece, a computing unit for determining the postage fee for a mailpiece and a franking unit for applying a postage indicium on the mail item comprises.
- the scale and the dimension measuring device are each physically sealed and are connected via physically sealed data cables
- the scale and the dimension device or a respectively associated interface have means for signing measured values.
- Measuring tolerances of the scale and the dimension measuring device as well as format categories for postal items are stored in a signed disposable memory, on the data of which a signed measuring module of the arithmetic unit exclusively has read access, wherein the measuring module comprises means for receiving measured values from the balance and the dimension measuring device via the serial interface.
- a correction module of the measuring module comprises means for adding and subtracting the respective measuring tolerances of the scale and the dimension measuring device to the received measured values, thus corrected
- the measurement module further comprises a format module comprising means for determining the format category of a mailpiece from the corrected dimension measurements and the format categories in the disposable memory. Furthermore, the measuring module has means for determining the product category of a mail item from the corrected weight reading of the mail piece and the format category of the mail piece determined by the format module, and the measuring module also has access to a file which contains an association between product categories of mailpieces and postage charges that a postage fee determined therefrom for a mail item can be supplied by the measuring module to a franking unit.
- the measuring module further comprises means for signing data records, comprising at least measurement values of the scale and the dimension measuring device, the associated corrected measured values and the determined product category of a mailpiece, and the measuring module has a memory module for storing a signed data record in the signed disposable memory.
- the measuring module is stored according to the invention on a storage medium with a write-protect switch.
- the invention further includes a method for securing signed software components for a device for processing measured values of at least one measuring device, in which software components are signed and a storage medium having a write-protection switch is connected to a computing unit of the device.
- the signed software components are stored on the storage medium and the write protection switch of the storage medium is activated. This is followed by a mechanical sealing of the write-protect switch of the storage medium and also a mechanical sealing of the connection between the storage medium and the arithmetic unit.
- the signed software components are transferred from the computing unit of the device to the storage medium, and the computing unit accesses the signed software components on the sealed storage medium during operation of the device.
- the invention also includes the use of a known storage medium with a write-protect switch, in which the storage medium is connected to the arithmetic unit of a device for processing the measured values of at least one mechanically sealed measuring device. Signed software components are stored on the storage medium, whereby the write protection switch of the storage medium is activated and mechanically sealed.
- This use of a storage medium for the described delivery station for processing and franking mailpieces is particularly advantageous.
- the invention has the advantage that software components that are subject to calibration and signed by a calibration official can be stored on a storage medium, with the calibration official being able to sign before the storage medium is connected to the computing unit of a measuring device.
- the calibration officer can thus carry out on-site tests and signings, what with fixed built-in and sealed storage media such as EPROMS is not possible.
- By activating a write protection and the mechanical seal of the write-protect switch the memory can be protected in a simple but effective manner against unnoticed manipulations.
- This new approach has advantages for many measuring systems and represents a type of protection approved by the authorities.
- Fig. 1 is a schematic representation of the invention
- FIG. 3 shows the arrangement of custody and non-legal components in the process sequences of FIG. 2.
- the invention provides a device for determining and processing measured values, which comprises at least one measuring device 10 subject to calibration and at least one software component subject to calibration for processing the measured values.
- a meter may determine a weight, the amount or dimensions of an item or medium. Scales determine the weight of a commodity, while, for example, a gasoline pump determines the flow of a fuel.
- Both types of measuring equipment must be approved and signed by calibration officers.
- an associated measuring device can be calibrated and signed in the usual way, for example, by a physical seal in the form of a seal 12 is attached. The meter can not be manipulated without the Break open the seal, so that a manipulation can be clearly detected.
- the measuring device 10 is connected to a computing unit 50 for processing measured data.
- a data cable 70 from the measuring device 10 to the computing unit 50 is preferably also physically sealed, so that manipulations can be detected at this connection.
- the computing unit 50 may be, for example, a PC having a processor, a memory, a plurality of hard disks and removable media.
- the PC also has a network connection, for example in the form of Fast Ethernet.
- non-legal software components for the processing of the measured values.
- parts of the software for processing the measured values are subject to verification, so that, for example, the calculation of fees to be paid by a customer for a good or service can not be manipulated in favor of or to the detriment of the customer.
- encryption mechanisms are used for such software, with which measured values and the software itself are signed.
- the calibration officer usually inserts a private key into the system without which the data can not be changed.
- the custody and therefore signed software components are located on a storage medium 11 which is connected to the arithmetic unit 50.
- the storage medium has a mechanical write-protect switch, upon activation of which the read-only mode of the storage medium can be activated.
- a storage medium for example, a USB memory stick or a hard disk with write-protect switch can be used. If the write-protect switch is activated, only read access to the software components on the storage medium can be made. A writing access, ie a change of the data, is not possible. So that the write-protect switch can not be deactivated unnoticed, it is physically sealed, that is sealed. For example, sealant material may enclose the write-protect switch so that it is not actuated can be without breaking the seal. Also, the connection between the storage medium 11 and the arithmetic unit 50 is physically sealed with a seal.
- the custody transfer software is signed by a calibration official and then transferred to the storage medium 11.
- the write protection is activated and the storage medium physically sealed, so that the calibrated software components can no longer be manipulated unnoticed.
- the security of the custody transfer software components is thus ensured by a software-based signing and a hardware write protection. If software components requiring calibration can be realized on the arithmetic unit 50 without the need for signing by a calibration official, software components that are subject to calibration can also be located on the arithmetic unit 50. This is the case, for example, for measured value memories, which are designed as one-way memories with read-only access. These disposable memories do not have to be swapped out to a storage medium, but instead can be embodied as manipulation-proof storage, for example in a database on the arithmetic unit 50.
- FIGS. 2 and 3 show how the invention can be used particularly advantageously in a mailing station for the processing and franking of mailpieces.
- the post office is a self-service machine where customers can deliver mailings such as mail or consignments.
- the services of the machine is in particular the franking of mail with the required
- a consignment station has an acceptance means for accepting mailpieces. This is preferably a singler, which feeds a stack of mailpieces individually into the device. After the singulation of the mailings, a mail item 20 passes through the device by means of one or more means of transport.
- the various measuring devices determine at least the weight and dimensions of the shipment. The determination of the individual measured values can take place simultaneously or successively by different measuring devices.
- the weight of a shipment is determined by a balance 30, while the
- Measuring devices for determining the length, width and height of a mail item are hereafter referred to in their entirety as a dimension measuring device 40.
- a dimension measuring device can thus consist of one or more measuring devices.
- the various measuring devices are connected to a computing unit 50, which is preferably also located within the machine.
- the determined measured values are transferred to the arithmetic unit 50 for evaluation.
- the arithmetic unit 50 generates measured values corrected from the measured values by processing the negative and positive tolerances of the individual measuring devices.
- these tolerance values are offset with the measured values H for the height, L for the length, G for the weight and B for the width of the mail item.
- the amount of the negative tolerance is added to the measured value measured in order to obtain adapted measured values H ', L', G 'and B 1 .
- the amount of the positive tolerance is subtracted from the measured value measured to obtain adjusted measured values H ", L", G "and B".
- the arithmetic unit 50 compares the adapted measured values with the value ranges of a reference list. If a product or a product class is determined in whose value range all adjusted measured values lie, the assigned postage amount is added to a result list. If this result list contains several postage amounts, the smallest amount is determined and determined as the postage amount to be applied to the mail piece. If the result list contains only one entry, the relevant postage amount is determined as the postage amount to be applied. With the postage amount thus determined, a franking mark is generated in a franking unit 60 and printed on the mailpiece 20. As a franking unit, any known from the prior art franking units are used, for example, imprint a postage indicium in the form of a matrix code on a mailpiece.
- Fig. 3 shows a schematic representation of custody and non-custody components for operating the consignment station according to the invention.
- Hardware components such as a scale 30 and the dimension measuring devices 40 are preferably connected via standardized interfaces to the arithmetic unit 50 of the delivery station, so that they can be exchanged.
- the automatic consignment-taking process within a consignment post determines the format of the consignments and their weight by means of measuring equipment and, on the basis of the results of these measurements, automatically determines the price of the consignment fee
- the calibration extends not only to the measured values themselves but also to the data processing that determines the transmission format from the measured values.
- the verification confirms the correctness of the measurement and the fee determination by a calibration official.
- the primary purpose of the measurement of a consignment is to determine the consignment format and weight, as these form the basis for the product determination and thus the fee determination.
- the program format is determined by means of a software of the arithmetic unit 50 from the entirety of the measurement results and their tolerance parameters. This part of the software is also subject to the
- the customer must be able to understand the charge determination so that the measurement results are displayed to him.
- the display of the measurement results is also subject to the calibration process, as this should not be manipulated. If an output of individual measurements, for example on a receipt or a screen, is not required by the approval authority, it is possible to store the basic data of the format determination in a measured value memory 55 for possible subsequent inspection. This
- Measured value memory like the measured values themselves, must be protected against manipulation, so that it is preferably a disposable memory that can only be read by reading.
- the software component which forms the interface to the measured value memory 55, and the disposable memory itself, are protected against manipulation.
- the measured value memory 55 can be created, for example, in a database of the arithmetic unit 50 and access to the measured value memory is made only via a predetermined interface, which can be done on stored data only a read access.
- the stored data can be stored as binary database files on a hard disk.
- a manipulation of the database files can be excluded by security mechanisms of the database itself, if manipulated database files are identified as corrupt by the database and can no longer be activated.
- a deletion of the database files can be timed within the database schema itself. So there is no deletion function from the outside.
- the storage duration of data records can be stored, for example, by the calibration official in the measured value memory itself and thus controlled at any time.
- the overall system of measuring devices 30 and 40, measurement data transmission to the format-determining software of the arithmetic unit 50, the format determination of the arithmetic unit 50, the measured value memory 55 and an indication of the measurement results on a display 80 are usually signed and sealed on site by a calibration officer.
- a product and price list 93 which shows the postage to be paid for a determined product category, is not subject to custody. This can therefore be changed by the operator of the consignment station, without a renewed calibration must be performed. If this results in new format categories, however, these are to be stored in the measured value memory 55.
- the software of the arithmetic unit 50 must be protected in particular against deliberate changes by means of common software tools.
- the interfaces between software subject to legal custody and software that is not subject to custody transfer must be free of feedback, ie the interfaces prevent the entry of impermissible data, parameters and commands. Measuring devices, for example, must not be influenced inappropriately if their feedback-free interfaces are exposed to external voltages. Furthermore, the interface gives the
- Approval authority attached signature of the calibration-relevant software modules and sealed the whole by signing with its own key.
- the actual calibration takes place with calibration measures, whereby the correctness of the data measured by the measuring devices and the measured data corrected by the tolerance values takes place.
- Measuring devices such as the scale 30 and the dimension measuring devices 40 are subject to the calibration process and are usually sealed with a calibration seal 32. Also, the transport path of measurement data from the measuring devices to a measured value software of the computing unit 50 must be sealed. Such seals are an example of a physical seal in the sense of this invention Scale 30 and the dimension measuring instruments 40 are thus calibrated and then physically sealed.
- the programs are transported, for example, in the automatic feeder occasionally through the measuring chain, and the individual measuring devices automatically take their measured value, sign it and send it via an interface 51 to a measuring module 52 of the arithmetic unit 50.
- the interface 52 is preferably a serial interface, and each meter has a corresponding hardware driver 53 and 54.
- the measuring devices are also connected to the arithmetic unit 50 via physically sealed data cables 70 and 71.
- the measured values themselves can be reported independently by the measuring devices to the measuring module 52 by means of events. An event can either be the reporting of a new measurement result or the reporting of an error that has occurred.
- the data can be exchanged over the interface in XML format. It should be noted that measurement data can be retrieved but not manipulated.
- the measuring instruments sign their measurement data records.
- One possible form of the signature is the formation of a hash value or scatter value over the supplied data record.
- cryptographic hash functions such as MD5, SHA-1 or RIPEMD-160 can be used.
- the use of a certificate or an encryption of the data can additionally be carried out.
- the calibration official must usually be given the opportunity to check the integrity of the signature of each individual measured value in the measured value memory. Depending on the signature used, he must be given access to a public key.
- RSA may be used in various signatures within the scope of the invention.
- Asymmetric methods are also referred to as public-key methods. In these methods, the user has two keys, a public key and a secret key. Both keys fulfill certain tasks.
- the public key is made public. Any other user can use this key to send to the owner a message that has been created by clear text encryption.
- the secret key is kept secret by the owner. It is used to decrypt encrypted messages sent to it.
- signing a message or a binary file means that, according to a known method, a message or binary checksum is computed and then encrypted with the private key of an asymmetric key pair. If it should now be determined whether the present message or binary file is unchanged at the time of signing, this can be determined with the public key of the asymmetric key pair. To do this, the checksum algorithm is used, the encrypted checksum is decrypted with the public key, and the values are compared.
- a public key with the identity of a third person can be created. Certificates can be used.
- a certificate is a kind of proof of authenticity for a public key, whereby a certificate consists of the public key of the holder of the certificate, an identity characteristic of the holder of the certificate, the name of the issuer of the certificate and a digital key of the issuer of the certificate.
- the signing of a measured value can take place in the physical measuring device itself, if, for example, a key is stored in the EPROM of the measuring device.
- the signing can also take place in the interface of the respective measuring device. In this case, the interface is subject to calibration and the software must also be signed.
- the structure of the measuring module 52 and its interaction with other components is shown in FIG.
- the software components for measuring data acquisition and evaluation are available, for example, as Java archive files (jar files).
- the jar files can be provided with a signature, the signature being stored in the jar file itself. This signature is generated using a private key and can be verified using a public key.
- the required key pair consisting of private and public
- TPM Trusted Platform Module
- the TPM is a chip that is permanently installed in the arithmetic unit 50. He is comparable to a smartcard soldered to the motherboard. The chip is passive and can not be directly influenced.
- a TPM chip is thus able to safely store or execute secret data, certificates, keys and cryptographic operations in a protected hardware environment.
- the TPM chip contains a hardware number generator and can encrypt, decrypt and sign data.
- the TPM chip can generate 2048-bit RSA keys directly on the chip.
- the nonvolatile TPM memory has multiple keys, and the volatile area accommodates multiple temporary RSA keys, 16 or 24 Platform Configuration Registers that capture hashes of hardware and software configurations, and two types of phones. As each TPM chip is unique and can not be exchanged, the software signed with it is bound to the respective consignment station.
- any manipulation of a signed Jar file results in a non-valid signature, which can be determined at any time by a check. Without the private key a renewed signature is not possible.
- the private key lies inside the TPM chip and is never visible to the outside. Only functions for using the private key are available. Access to the private key in the TPM chip can be password protected by the calibration officer.
- the correction module 90 for tolerance correction of the measured values is subject to the calibration process.
- the valid tolerance values lie within the saved measured value memory 55 and are retrieved from the correction module 90 therefrom.
- the calibration official previously signed these tolerance values during calibration with his private key.
- the tolerance values including the signature are stored in the measured value memory 55.
- the calibration official can use his public key to verify the tolerance values.
- the recorded measured values are corrected by the correction module 90 by the retrieved tolerance values from the one-way memory 55, as indicated in step 2) in FIG. 2.
- the tolerance correction algorithm is preferably as follows:
- Both the original measurement data and the corrected measured values are forwarded to the measured value memory 55 in the data packet for later storage.
- the complete measurement data set is signed by the measurement module 52 so that stored values can no longer be manipulated at the system level. This can also be done via a hash value over the complete record.
- the measuring module 52 further comprises a module 91 for format determination, wherein this format module 91 is also subject to the calibration process.
- the format module accesses format categories that are also stored in the measured value memory 55. Although the valid format categories are part of the non-legal file 93 with the price and product list (PPL), they are also stored in the saved measured value memory 55.
- the format categories are for example signed in the backend and delivered to the machine 10. There, the format categories after successful verification of the signature by the front-end software in the measured value memory 55 of the arithmetic unit 50 are imported. The format categories are retrieved from the memory module 55 from the format module 91, and the format determination module compares the corrected measurement values of the program with these stored format category limits. The format module 91 determines from this the format category of the program to be used, as indicated in step 3) in FIG. 2.
- the corresponding product from the valid price and product list 93 is selected with the additional information provided by the customer (including ordered quality of service, additional services, etc.), as indicated in step 2 in FIG. 2 .
- This price and product determination is not subject to the calibration process, since, apart from the format category, no measured values are used, but information or wishes of the customer.
- the determined product and its price are preferably recorded to the measured values of the transmission in the measured value memory 55. For this reason, the product identification with the measured values is forwarded to a calibration-relevant memory module 92 of the measuring module 52.
- This memory module 92 is used to store the complete measurement data record.
- the module 92 is also subject to the calibration process. After completion of the data set by the information from the product and price determination of the complete data set is signed to exclude subsequent changes, and then stored in the measured value memory 55. This process is indicated in FIG. 2 as step 5).
- the measuring device itself which one - -
- Measured value has generated, it is preferably identifiable by a unique identification number. For example, a SHA1 checksum per measured value and ID number can be formed for each dimension for a measurement. After the correction of the measured values by the tolerances, a SHA1 hash value is formed via the aggregated data record, which also contains the determined format category and the product ID. This hash value and the SHA1 hash value for all software modules relevant to eich are linked to one another, for example, via an XOR connection. Both the hash value over the data record and the hash value formed via the XOR connection can be verified.
- the postage fee determined by the measuring module 52 as a result of said steps is sent as a print job to a franking module 60 in order to frank the mail item 20 accordingly with a postage indicium. This is shown as step 6) in FIG. If the measurement module 52 determines that a shipment 20 is not a valid product or the shipment can not be further processed, the shipment will be ejected and the captured measurements may be discarded. In this case, the measured values do not have to be stored in the measured value memory 55 since the customer will not be charged for any services.
- the system preferably offers the customer the option of retrospectively reading the measured values of his shipments.
- a menu item is offered to the customer, for example, on a control unit 13 on a screen, which allows him within a fixed period of time (eg 90 days) the stored measurements after specifying the date, the billing number on the receipt of the customer or the shipment number to view a single shipment.
- This display of the measured values on a display 80 is likewise subject to the calibration process, since manipulation of the data between measured value memory and display 80 must be precluded.
- the mask to be displayed is therefore also created and signed by the measuring module 52.
- a root CA authenticated by the machine can be created, which also uses the storage root key of the Trusted Platform Module (TPM chip).
- the TPM chip contains a unique identifier such as an endorsement key in the form of a 2048-bit RSA key pair that the manufacturer writes to the chip.
- the TPM chip can thus serve to identify the processing unit and the software thereon.
- the arithmetic unit 50 with the associated software is thus protected from being transferred to another consignment station.
- the software is thus tied to a specific consignment station and hardware.
- the invention can be used to play it on a USB memory stick 11 connected to the PC, which mechanically follows the signing by the calibration officer a write-protect switch is set to read-only mode and sealed by the calibration official with seals.
- a hard disk with a mechanical write-protection switch can also be used for this purpose.
Landscapes
- Engineering & Computer Science (AREA)
- Automation & Control Theory (AREA)
- Quality & Reliability (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Devices For Checking Fares Or Tickets At Control Points (AREA)
Abstract
L'invention concerne un dispositif pour traiter des valeurs de mesure, qui comprend au moins un appareil de mesure mécaniquement scellé (10; 30; 40) et au moins un composant logiciel signé (52) pour le traitement des valeurs de mesure de l'appareil de mesure (10; 30; 40), sachant que l'appareil de mesure mécaniquement scellé (10; 30; 40) est raccordé à une unité de calcul (50). Selon l'invention, le composant logiciel signé (52) est enregistré sur un support de mémoire (11) qui présente un commutateur de protection d'écriture qui est mécaniquement scellé. Le support de mémoire (11) est raccordé à l'unité de calcul (50).
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP08000014A EP2077530A1 (fr) | 2008-01-02 | 2008-01-02 | Procédé et dispositif destinés au traitement de valeurs de mesure; utilisation d'un support de stockage destiné à la sécurisation de composants logiciels signés |
| EP08000014.4 | 2008-01-02 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2009083102A1 true WO2009083102A1 (fr) | 2009-07-09 |
Family
ID=39399240
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2008/010377 Ceased WO2009083102A1 (fr) | 2008-01-02 | 2008-12-08 | Dispositif et procédé de traitement de valeurs de mesure, utilisation d'un support de mémoire pour sauvegarder des composants logiciels signés |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP2077530A1 (fr) |
| WO (1) | WO2009083102A1 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102009036863A1 (de) * | 2009-08-10 | 2011-02-17 | Bizerba Gmbh & Co Kg | Verfahren zum Betrieb eines Messgeräts |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE4445526A1 (de) * | 1994-02-04 | 1995-08-10 | Sartorius Gmbh | Anlage zur Meßwerterfassung und Anzeige, insbesondere Wägeanlage |
| US20020002080A1 (en) * | 1999-06-22 | 2002-01-03 | Jim Stockdale | Mass storage data protection system for a gaming machine |
| US20040221175A1 (en) * | 2003-04-29 | 2004-11-04 | Pitney Bowes Incorporated | Method for securely loading and executing software in a secure device that cannot retain software after a loss of power |
| DE102005006005A1 (de) * | 2005-02-09 | 2006-08-10 | Deutsche Post Ag | Verfahren und Vorrichtung zur automatisierten Annahme und Frankierung von Postsendungen |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE19527293A1 (de) | 1995-07-26 | 1997-01-30 | Bosch Gmbh Robert | Verfahren und Vorrichtung zur sicheren Messung und Verarbeitung sowie Überprüfung von Meßdaten |
-
2008
- 2008-01-02 EP EP08000014A patent/EP2077530A1/fr not_active Withdrawn
- 2008-12-08 WO PCT/EP2008/010377 patent/WO2009083102A1/fr not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE4445526A1 (de) * | 1994-02-04 | 1995-08-10 | Sartorius Gmbh | Anlage zur Meßwerterfassung und Anzeige, insbesondere Wägeanlage |
| US20020002080A1 (en) * | 1999-06-22 | 2002-01-03 | Jim Stockdale | Mass storage data protection system for a gaming machine |
| US20040221175A1 (en) * | 2003-04-29 | 2004-11-04 | Pitney Bowes Incorporated | Method for securely loading and executing software in a secure device that cannot retain software after a loss of power |
| DE102005006005A1 (de) * | 2005-02-09 | 2006-08-10 | Deutsche Post Ag | Verfahren und Vorrichtung zur automatisierten Annahme und Frankierung von Postsendungen |
Also Published As
| Publication number | Publication date |
|---|---|
| EP2077530A1 (fr) | 2009-07-08 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE69434621T2 (de) | Postgebührensystem mit nachprüfbarer Unversehrtheit | |
| EP1405274B1 (fr) | Procede de verification de la validite de mentions d'affranchissement numeriques | |
| DE69724345T2 (de) | System zur kontrollierten Annahme von Poststücken, das sicher die Wiederverwendung einer ursprünglich für ein Poststück erzeugten digitalen Wertmarke bei einem später vorbereiteten anderen Poststück zum Beglaubigen der Bezahlung der Postgebühren ermöglicht | |
| EP2755846B1 (fr) | Procédé et dispositif pour l'attribution des données de mesure détectées par une station de charge à une transaction | |
| DE69636375T2 (de) | System zur kontrollierten Annahme der Bezahlung und des Nachweises von Postgebühren | |
| DE3613007B4 (de) | System zur Ermittlung von nicht-abgerechneten Drucken | |
| DE3841394C2 (de) | Verfahren für die Ausgabe von Postgebühren | |
| DE69932028T2 (de) | System und Verfahren zum Unterdrücken von übertragenen Aussendungen einer kryptographischen Vorrichtung | |
| DE3644229B4 (de) | Vorrichtung zur stapelweisen Bearbeitung einer großen Menge von Poststücken | |
| DE69636617T2 (de) | Verfahren und System zum Nachweisen von Transaktionen mit hinterherigem Drucken und Verarbeiten des Postens | |
| DE69936013T2 (de) | System und Verfahren zur Detektion von Postgebührenbuchführungsfehlern in einer Umgebung zur kontrollierten Annahme | |
| DE3644318A1 (de) | Postaufgabesystem mit portowert-uebertragung und verrechnungsfaehigkeit | |
| EP1107190B1 (fr) | Procédé et machine à affranchir | |
| WO2004061779A1 (fr) | Procede et dispositif pour le traitement d'information graphique figurant sur des surfaces d'articles postaux | |
| EP2077528B1 (fr) | Station de livraison et procédé d'affranchissement de courriers postaux dans des stations de livraison | |
| EP1450144A2 (fr) | Procédé et dispositif pour la protection digitale de valeurs mesurées | |
| WO2009083102A1 (fr) | Dispositif et procédé de traitement de valeurs de mesure, utilisation d'un support de mémoire pour sauvegarder des composants logiciels signés | |
| EP1340197B1 (fr) | Procede pour apposer des marques d'affranchissement sur des envois postaux | |
| DE60132775T2 (de) | Sichere speicherung von daten auf offenen systemen | |
| DE69636360T2 (de) | Auf Transaktionen mit geschlossener Schleife basierendes Rechnungs- und Bezahlungssystem für Postsendungen mit durch Freigabe der Postversandinformation ausgelöster Bezahlung des Beförderers durch eine dritte Partei | |
| EP1486028B1 (fr) | Procede et dispositif permettant de creer des documents infalsifiables verifiables | |
| DE102007057692A1 (de) | Verfahren und Vorrichtung zum Verarbeiten einer Postsendung, insbesondere eines Briefes | |
| EP2131330A1 (fr) | Station de réception de livraison pour envois postaux et procédé de réception de livraison d'envois postaux | |
| EP2822805A2 (fr) | Plaque signalétique électronique conçue pour des appareils de mesure | |
| EP2140429A1 (fr) | Procédé et dispositif d'affranchissement d'un envoi postal avec enregistrement d'une information d'identification dans une liste positive |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 08868552 Country of ref document: EP Kind code of ref document: A1 |
|
| DPE1 | Request for preliminary examination filed after expiration of 19th month from priority date (pct application filed from 20040101) | ||
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 08868552 Country of ref document: EP Kind code of ref document: A1 |