Chip Card Activation via Mutual Authentication and Integrity Checking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for activating chip cards do not adequately ensure the security and integrity of data processing systems, particularly for safety-critical functions, as they lack a mechanism to verify the system's integrity before enabling such functions.
Innovation Solution
A method involving mutual card-to-card authentication between two chip cards, where the second chip card generates and verifies an integrity evaluation code from the data processing system, ensuring that the system's integrity is checked before enabling safety-critical functions, using a hash value generated from predetermined files and stored signatures, with secure messaging for communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If chip card activation only requires user authentication (PIN or biometric), then ease of operation is improved, but security and integrity checking of the data processing system is insufficient
Solution Approach 1:
The chip card functions are segmented into two types: first chip card functions (less security-critical) that require only user authentication, and second chip card functions (security-critical) that require additional system integrity checking. This segmentation allows the system to maintain ease of operation for routine functions while enhancing security for critical functions.
Solution Approach 2:
A second chip card acts as an intermediary to perform integrity checking of the data processing system before enabling security-critical functions. This intermediary component verifies system integrity through cryptographic comparison of integrity evaluation codes without requiring continuous user authentication, thus balancing security with operational ease.
2Reliability
If system integrity checking is performed before enabling safety-critical functions, then reliability is improved, but device complexity increases
Solution Approach 1:
The second chip card performs self-service by autonomously generating integrity evaluation codes, decrypting digital signatures, comparing hash values, and determining system integrity without requiring manual intervention. This automation reduces operational complexity while maintaining high reliability through cryptographic verification.
Solution Approach 2:
The system performs preliminary integrity checking actions before enabling safety-critical functions. The second chip card proactively verifies system integrity by comparing current integrity evaluation codes with stored reference codes, ensuring that only trusted systems can activate critical functions. This preliminary verification prevents security issues before they arise.
3Reliability
If mutual card-to-card authentication is implemented between two chip cards, then security is improved, but ease of operation deteriorates
Solution Approach 1:
Different authentication requirements are applied locally to different chip card functions. First chip card functions (non-critical) require only simple user authentication, while second chip card functions (critical) require mutual card-to-card authentication. This localized differentiation ensures high security where needed without unnecessarily complicating routine operations.
Solution Approach 2:
The mutual authentication between chip cards is performed autonomously through cryptographic protocols without requiring user intervention. The second chip card automatically generates and verifies integrity evaluation codes, decrypts digital signatures, and determines system integrity, eliminating the need for users to manually perform authentication steps while maintaining strong security.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method for enabling a first chip card (116) for use with a data processing system (100) with the aid of a second chip card (126), wherein the data processing system has means (110) for generating an integrity assessment code from predetermined data which are stored in the data processing system, said method having the following steps: - the first chip card requests (162) an enable signal (152) from the second chip card, - the integrity assessment code is requested (164) from the means (110) for generating an integrity assessment code, - the second chip card decrypts (156) a signature (118) which is associated with the data processing system, - the second chip card compares (158) the decrypted signature with the integrity assessment code, - the enable signal is generated if the decrypted signature and the integrity assessment code match, - the first chip card is enabled after the first chip card has received the enable signal.