Application Manager IC Chip Access Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control methods for secure chips in information processing apparatuses are inadequate in preventing fraudulent accesses, especially when multiple system operating companies share a standard application manager, as modifying the specification can compromise system integrity and is inconvenient for timely access control.

Innovation Solution

An information processing apparatus that includes a reception unit for accessing IC chips, an acquisition unit for obtaining authentication information from an external server, an authentication unit for verifying the application's legitimacy using digital signatures, and a control unit for managing access based on authentication results, allowing secure access without modifying the application manager's specification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the application manager specification is modified to implement access control to secure chips, then fraudulent accesses can be prevented, but system integrity is impaired and the solution cannot be shared across multiple system operating companies

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an application manager as an intermediary component that sits between applications and the secure chip. This mediator handles all access requests, performing authentication and authorization without requiring modifications to the secure chip itself or the applications. The application manager uses digital signatures and certificates to verify application legitimacy, thus preventing fraudulent accesses while maintaining system compatibility across different operating companies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access control functionality into a separate application manager component, distinct from the secure chip and applications. This segmentation allows the application manager to be updated, configured, and maintained independently without affecting the integrity of the secure chip or requiring modifications to applications. The segmented architecture enables different system operating companies to deploy their own application managers while sharing the same secure chip infrastructure.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the application manager specification is modified for each system operating company, then access control can be implemented, but the modification process becomes inconvenient and time-consuming

Engineering Contradiction:
Improveaccess control securityVSAvoidspecification modification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring the application manager with authentication mechanisms, digital signature verification capabilities, and access control policies before deployment. The application manager is designed in advance to handle various authentication scenarios, eliminating the need for time-consuming specification modifications when new access control requirements arise. System operating companies can deploy pre-built application managers that are ready to enforce security policies immediately.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables flexible parameter changes within the application manager without requiring specification modifications. Access control policies, authentication methods, and security parameters can be dynamically adjusted through configuration files or database entries rather than code changes. This allows system operating companies to adapt access control settings to their specific needs while using a standardized application manager framework, significantly reducing the time required to implement security measures.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If conventional access control methods are used without external authentication, then the system is simpler, but fraudulent accesses cannot be effectively prevented

Engineering Contradiction:
Improveaccess control system complexityVSAvoidfraud prevention capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The application manager serves as an intermediary that introduces external authentication mechanisms without significantly increasing overall system complexity. It handles certificate verification, digital signature validation, and authentication protocol management, shielding applications and the secure chip from complex security operations. This intermediary approach provides robust fraud prevention while maintaining a relatively simple system architecture where the application manager encapsulates all security complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces mechanical or manual access control methods with cryptographic authentication mechanisms. Instead of relying on physical security or simple permission flags, the system uses digital signatures, public key infrastructure, and certificate-based authentication. This substitution provides much stronger fraud prevention capabilities while the application manager automates the cryptographic operations, keeping the user interface and overall system interaction relatively simple.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9667426B2Information processing apparatus, program, storage medium and information processing system
Publication Date: 2017.05.30 FELICA NETWORKS INC
  • US9667426B2 patent drawing
  • US9667426B2 patent drawing
  • US9667426B2 patent drawing

AI summary

Provided is an information processing apparatus including a reception unit that receives a request for access to an IC chip from an application having access right information for accessing to the IC chip, an acquisition unit that acquires an authentication information for authenticating the application from an external server based on the access right information contained the request for access received by the reception unit, an authentication unit that authenticates the application based on the authentication information obtained by the acquisition unit, and a control unit that controls an access of the application to the IC chip based on an authentication result by the authentication unit.