Chip Card Credit Management for Secure Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems in mobile telephony networks rely on server-managed billing, which lacks flexibility and security, particularly in managing communication resource usage and billing for telecommunications networks.
Innovation Solution
Implementing an electronic entity with a secure memory that manages a credit for resource usage, capable of determining the state of communication and generating a positive response only if the credit is sufficient, thereby controlling access to resources within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If billing management is centralized on server, then security control is maintained, but system flexibility and responsiveness are reduced
Solution Approach 1:
The patent segments billing management functionality by separating credit verification (electronic entity) from billing calculation and management (server). The electronic entity autonomously verifies credit availability and controls resource access, while the server handles comprehensive billing operations. This segmentation enables both local security control and centralized billing management to coexist, resolving the contradiction between security and flexibility.
2Reliability
If access control is centralized on server, then security is maintained, but response time and system efficiency are reduced
Solution Approach 1:
The patent implements preliminary action by pre-loading credit information into the electronic entity's secure memory before resource access is needed. The electronic entity autonomously verifies credit availability locally without real-time server intervention, enabling immediate access decisions. This preliminary preparation of credit data eliminates time-consuming server round-trips while maintaining security through cryptographic verification.
Solution Approach 2:
The patent introduces cryptographic authentication mechanisms as intermediaries between the electronic entity and server. The server authenticates the electronic entity's credit verification results using cryptographic keys, enabling fast local verification while maintaining centralized security control. This intermediary authentication layer resolves the contradiction by enabling both speed and security.
3Adaptability or versatility
If credit management is decentralized to terminal, then system flexibility is improved, but security risks increase
Solution Approach 1:
The patent extracts the critical credit verification function from the broader billing management system and places it in a dedicated secure electronic entity with hardware-based security features. This extraction isolates the security-critical credit checking logic in a tamper-resistant environment, enabling decentralized flexibility while maintaining security through specialized hardware protection.
Solution Approach 2:
The patent implements self-service by enabling the electronic entity to autonomously verify its own credit status and control resource access without external intervention. The electronic entity independently checks credit availability, makes access decisions, and manages its own authentication credentials. This self-service capability provides system flexibility while security is maintained through cryptographic self-verification and hardware-based protection.
Data Source
Figure 1
Figure 2~4
Figure 3~5
AI summary
The entity i.e. chip card (1100), has a communication unit (COM) for receiving a determined authentication request emitted by a control device i.e. server. A determination unit determines a communication state e.g. end of communication, between the entity and the device from the request. A cryptographic unit (AUTH) generates a positive response to the request when the communication state is a determined state if communication credit (CC) is sufficient. The communication unit sends the positive response to the device. Independent claims are also included for the following: (1) a resource access method implemented by electronic entity (2) a computer program comprising instructions for executing steps of resource access method (3) a computer readable recording medium for recording a computer program comprising instructions for executing steps of resource access method (4) a method implemented by a control device for controlling access to the resource by electronic entity or by third party device (5) a computer program comprising instructions for executing steps of method for controlling access to the resource (6) a computer readable recording medium for recording a computer program comprising instructions for executing steps of method for controlling access to the resource.