Chip Card Memory Management via Authorization Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for installing applications on chip cards lack sufficient security, particularly for private users, as they do not adequately ensure memory usage limits and data volume constraints, leading to potential risks of 'hostile' applications being installed.

Innovation Solution

A method involving the execution of a data technology protocol to install an additional application on a chip card, where an authorization certificate with specified time and data volume limits is assigned, checked for validity, and used to identify and release memory occupied by applications exceeding their usage limits, ensuring secure installation by managing memory usage effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If batch installation methods are used to reduce installation time and minimize installation data, then productivity is improved, but reliability deteriorates due to insufficient security for individual applications

Engineering Contradiction:
Improveinstallation timeVSAvoidsecurity level
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the installation process into two distinct modes: batch installation for mass processing and individual installation with enhanced security verification for private users. This segmentation allows the system to apply different security protocols appropriate to each installation scenario, resolving the contradiction between efficiency and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic security verification that adapts based on the installation context. For batch installations, minimal verification is performed to maintain speed, while for individual applications, comprehensive security checks including certificate validation and memory limit verification are automatically applied, making the security level dynamic rather than static.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If applications are installed without strict memory usage limits, then ease of operation is improved, but harmful factors increase due to potential malicious applications

Engineering Contradiction:
Improveinstallation simplicityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing memory usage limits and authorization certificates before the actual application installation occurs. The system pre-defines time limits and data volume constraints in the authorization certificate, so that when an application is installed, these controls are already in place to prevent malicious behavior.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authorization certificate that mediates between the user's desire for simple installation and the need for security. This certificate acts as a trusted intermediary that automatically enforces memory limits and time constraints, eliminating the need for complex user configurations while maintaining security through automated verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If memory is allocated without time limits, then device complexity is reduced, but loss of time occurs due to inability to manage expired applications

Engineering Contradiction:
Improvememory management complexityVSAvoidtime management overhead
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the smart card system to automatically manage application lifecycles based on time limits embedded in authorization certificates. The system autonomously identifies expired applications, reclaims their memory, and prevents further execution, eliminating the need for manual intervention and reducing time management overhead while maintaining simple device architecture.

Inventive Principle:
Principle #25Self-service

4Reliability

If comprehensive security verification is performed for every application installation, then reliability is improved, but productivity deteriorates due to increased verification time

Engineering Contradiction:
Improvesecurity verificationVSAvoidinstallation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by tailoring the level of security verification to the specific installation context. For batch installations where speed is critical, minimal verification is performed. For individual applications where security is paramount, comprehensive verification including certificate validation, time limit checking, and memory constraint verification is automatically applied, optimizing both reliability and productivity locally.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3186740B1Method for installing an additional application in a non-volatile memory of a chip card
Publication Date: 2020.06.17 BUNDESDRUCKEREI GMBH
  • EP3186740B1 patent drawingFigure 1
  • EP3186740B1 patent drawingFigure 2
  • EP3186740B1 patent drawingFigure 3

AI summary

A method is proposed for installing an additional application in a non-volatile memory of a chip card by executing a data protocol is proposed, comprising steps for making available the additional application for transmission to the chip card on a provider's computer, for assigning an authorisation certificate to the additional application, wherein the authorisation certificate contains limiting values for the use of the non-volatile memory in terms of time and data volume which are defined for the additional application, in particular by the provider's computer (130), for checking the validity of the authorisation certificate, transmitted to the chip card, by means of the chip card as a precondition for continuation of the data protocol, for searching the non-volatile memory of the chip card for applications which have already been stored and whose time limit for use for storage has been exceeded, and releasing the storage locations which are occupied by the applications (116, 117) whose time limit (116.1, 117.1) has been exceeded, and for storing the additional application transmitted to the chip card in the non-volatile memory thereof, with the limiting values of the use for storage which are specified in the authorisation certificate.