Air Gap Issuing Entity for Secure Electronic Coin Data Sets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic payment systems lack secure, flexible, and anonymous methods for generating and issuing electronic coin data sets, particularly in preventing multiple-spending attempts, non-existent monetary value transactions, and ensuring the confidentiality of transactions while maintaining basic control functions.
Innovation Solution
An issuing entity with a coin generating unit and a coin output unit separated by an air gap process, where the electronic coin data sets are generated offline and transmitted securely through physical means, such as portable data carriers or printouts, to ensure confidentiality and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If electronic coin data sets are generated and transmitted through a networked system, then transaction speed and convenience are improved, but security against network attacks and data manipulation deteriorates
Solution Approach 1:
The system divides the electronic coin data set into two separate components: a confidential unit containing sensitive data (stored offline in a secure element) and a public unit containing non-sensitive data (transmitted over the network). This segmentation allows the public unit to be exchanged quickly while the confidential unit remains protected from network attacks, resolving the contradiction between transaction speed and security.
Solution Approach 2:
The sensitive confidential data is extracted from the networked system and stored offline in a secure element within the terminal. Only the non-sensitive public unit is transmitted through the network. This extraction eliminates the vulnerability of sensitive data to network attacks while maintaining the ability to conduct fast electronic transactions using the public unit.
2Adaptability or versatility
If pseudonyms and signature strings are included in electronic coin data sets, then transaction anonymity is improved, but storage requirements and data set size increase
Solution Approach 1:
Instead of storing large pseudonym identifiers and signature strings in the confidential unit, the system uses a compact cryptographic hash (fingerprint) of the confidential unit as the pseudonym in the public unit. This hash acts as a unique identifier that is much smaller in size but still provides anonymity and allows verification without storing the actual sensitive data.
Solution Approach 2:
The system transforms the confidential unit into a fixed-size cryptographic hash representation for use in the public unit. This parameter change from storing variable-length sensitive data to storing a fixed-size hash dramatically reduces the data set size while maintaining the functional requirements for anonymity and verification.
3Reliability
If all terminals are approved and trusted before system entry, then security against fraud is improved, but system flexibility and ease of onboarding deteriorates
Solution Approach 1:
The secure element within the terminal performs preliminary verification of the electronic coin data set's validity and authenticity before the transaction is completed. This preliminary action includes verifying cryptographic signatures and checking the validity of the public unit, enabling fraud detection to occur locally and immediately rather than requiring pre-approval of all terminals.
Solution Approach 2:
The terminal's secure element autonomously verifies the authenticity and validity of electronic coin data sets without requiring external approval or trust establishment. The system enables itself to detect fraud through local cryptographic verification, eliminating the need for manual terminal approval processes while maintaining high security standards.
Data Source
AI summary
An issuing entity for issuing electronic coin data sets in a payment system, includes a coin generating unit, which is designed to generate an electronic coin data set, and a coin output unit, which is designed to obtain the electronic coin data set generated by the coin generating unit and output the electronic coin data set to a participating unit or to a bank entity of the payment system in electronic form. The issuing entity is designed such that the electronic coin data set is transmitted between the coin generating unit and the coin output unit via an air gap process. An issuing method and a payment system adopt features of the issuing entity.


