Chip Card Data Structure Update via Signature Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing chip cards cannot change or delete data stored in their protected memory areas during active operation without replacing the card, which is a limitation for updating sensitive information such as cryptographic parameters or meeting evolving security requirements.

Innovation Solution

A method and system that allows data groups within a chip card's data structure to be changed or deleted using a chip card terminal and a signature device, which generates an updated security object with a new signature, enabling secure updates without compromising the card's security, even after personalization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in a protected memory area of a chip card during personalization, then security and data integrity are ensured, but the data cannot be modified or deleted during active operation

Engineering Contradiction:
Improvedata integrityVSAvoiddata modifiability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the previously static protected memory system dynamic by introducing conditional write capabilities. The memory transitions from a completely read-only state to a state where selective data can be modified under controlled conditions, allowing the system to adapt between security and modifiability requirements based on operational context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of memory accessibility by introducing authorization mechanisms and data structure metadata. The memory system's write protection parameter is dynamically adjusted based on authorization status and data structure properties, enabling selective modification of specific data groups while maintaining overall security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a chip card uses a fixed data structure with security objects, then security against unauthorized access is maintained, but the card cannot adapt to evolving security requirements

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static security structure into a dynamic one where security parameters can be updated. The data structure includes metadata that tracks security object versions and authorization levels, enabling the system to evolve its security posture over time while maintaining cryptographic protection through controlled update mechanisms.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent prepares the data structure in advance with extensibility features, including reserved fields and metadata structures that anticipate future security requirements. This preliminary design enables smooth transitions to updated security standards without requiring complete system replacement.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If the protected memory area is made completely read-only, then unauthorized manipulation is prevented, but legitimate updates require card replacement

Engineering Contradiction:
Improveunauthorized manipulationVSAvoidupdate process complexity
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The patent applies different access control qualities to different parts of the data structure. Individual data groups can have distinct read-write permissions based on their security classification and operational requirements, allowing some data to be mutable while other data remains strictly protected, eliminating the need for complete card replacement for updates.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary authorization mechanism that mediates between the read-only protection and write access requirements. The authorization system acts as a gatekeeper, allowing legitimate updates through cryptographic verification while blocking unauthorized modifications, thus enabling updates without card replacement.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If data structure metadata is used to control access, then selective modification is enabled, but the system complexity increases

Engineering Contradiction:
Improveselective data modificationVSAvoiddata structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the data structure into distinct data groups with individual metadata descriptors. Each data group can be independently controlled with its own access permissions, enabling selective modification without affecting other data. This segmentation manages complexity by organizing data into manageable, independently controllable units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses metadata copying and verification mechanisms to manage data structure complexity. Authorization information and data structure descriptors are copied and verified through cryptographic checks, allowing the system to handle complex access control requirements through systematic replication of security attributes rather than complex decision logic.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3215977B1Method for altering a data structure stored in a chip card, signature device and electronic system
Publication Date: 2021.03.31 BUNDESDRUCKEREI GMBH
  • EP3215977B1 patent drawingFigure 1
  • EP3215977B1 patent drawingFigure 2
  • EP3215977B1 patent drawingFigure 3

AI summary

The invention relates to a method for altering a data structure (124) stored in a protected memory area (104) of a chip card (100), the data structure containing multiple data groups (DG1, DG2,... DGi, DG N). A security object (126) for the data structure is stored in the protected memory area, said object containing a hash value for each of the data groups and a signature (128) by means of a combination (K) of the hash values, said signature having been generated using a private key (130) of a signature device (112). The method comprises the following steps: authentication of a chip card terminal (110) in relation to the chip card; establishment of a first channel (134) between the chip card terminal and the chip card, alteration of at least one of the data groups (DG' i) of the data structure stored in the chip card by means of write-access by the chip card terminal to the protected memory area via the first channel; establishment of a second channel (146) to the signature device via a network; transmission of at least those hash values of the data groups of the data structure of the security object that are not affected by the alteration, in addition to transmission of the altered data group (DG' i) and/or a hash value (Hash' DG'i) of the altered data group to the signature device via the second channel; generation by the signature device of an updated security object (126') for the altered data structure (124'); transmission of the updated security object from the signature device to the chip card; storage of the updated security object of the altered structure in the secure memory area of the chip card.