Anonymous Smart Card Personalization for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional PIN-based user authentication mechanisms are vulnerable to misuse and interception, especially in centralized databases, and multi-application smart cards face challenges in privacy and commercial considerations due to asymmetric business relationships between commercial entities.

Innovation Solution

A method for personalizing multi-application smart cards by preparing an anonymous smart card with disabled applications requiring user linkage and enabled applications not requiring linkage, using unique internal and external identifiers, and allowing end-user-controlled partitions for storing data, ensuring secure and privacy-compliant user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized databases are used to store PINs and user data, then user authentication can be performed, but the system becomes vulnerable to misuse and interception

Engineering Contradiction:
Improveauthentication capabilityVSAvoidvulnerability to misuse and interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive user data (PINs, personal information) from centralized databases and stores it locally on smart cards. Each smart card contains its own encrypted user data and authentication credentials, eliminating the need for a centralized database to store sensitive information. This extraction resolves the contradiction by maintaining authentication capability while removing the vulnerable centralized storage point.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local quality by enabling each smart card to independently store and process encrypted user data locally on the card itself. The smart card contains local copies of authentication credentials and user information, encrypted with card-specific keys. This local storage approach maintains authentication reliability while reducing vulnerability to centralized database breaches.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If multi-application smart cards are personalized with user data, then commercial entities can provide services, but privacy concerns arise due to asymmetric business relationships

Engineering Contradiction:
Improvemulti-application service capabilityVSAvoiduser privacy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments user data and application access rights into separate, controlled partitions on the smart card. Each application on the smart card has its own designated data space and access controls, preventing any single application or commercial entity from accessing all user information. This segmentation enables multi-application versatility while protecting user privacy through spatial separation of data access rights.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of data accessibility by implementing encryption and access control mechanisms that dynamically manage what data each application can access. User data is encrypted with keys that are distributed selectively to different applications based on user consent and business relationship requirements. This parameter change enables services to be provided while maintaining privacy through controlled data accessibility.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8152074B1Method for preparing by a smart card issuer an anonymous smart card and resulting structure
Publication Date: 2012.04.10 ORACLE AMERICAN INC
  • US8152074B1 patent drawing
  • US8152074B1 patent drawing
  • US8152074B1 patent drawing

AI summary

A multi-application smart card may be personalized by receiving a smart card request, preparing an anonymous smart card having multiple user applications that are disabled for uses requiring a link to an identified user and enabled for uses not requiring a link to an identified user, and issuing the anonymous smart card to a user.