Chip Card Mutual Authentication via Symmetric Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting chip card terminals against unauthorized use primarily rely on user identification through PINs, which lack mutual authentication between the chip card and the terminal, and do not effectively prevent unauthorized access when the PIN is compromised or forgotten.
Innovation Solution
A method that generates a ciphertext using a first symmetric key derived from the chip card's identifier, transmitted to the terminal, and decrypted using a second symmetric key, ensuring a protected communication channel only if the identifiers match, enabling mutual authentication through cryptographic information and Diffie-Hellman key exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PIN-based user identification is used for chip card activation, then user authentication is achieved, but mutual authentication between chip card and terminal is lacking and unauthorized access cannot be prevented when PIN is compromised
Solution Approach 1:
The patent introduces cryptographic intermediaries (ciphertext, symmetric keys, communication parameters) that mediate between the chip card and terminal. Instead of direct PIN comparison, the system uses encrypted communication channels where the terminal decrypts ciphertext using symmetric keys derived from communication parameters, enabling mutual authentication without exposing the PIN and preventing unauthorized access even when PIN is compromised.
Solution Approach 2:
The patent replaces the mechanical PIN entry and comparison system with a cryptographic substitution system. Instead of entering and comparing PINs directly, the system uses symmetric key encryption/decryption of communication parameters, where security is based on cryptographic mathematics rather than secret sharing, thereby achieving mutual authentication and preventing unauthorized access.
2Ease of operation
If static PIN is used for chip card authentication, then simple authentication is achieved, but the card user must destroy the chip card if PIN is compromised and obtain a new card
Solution Approach 1:
The patent changes the authentication parameter from a static PIN to dynamic cryptographic elements (symmetric keys derived from communication parameters). The symmetric key is generated based on communication parameters that can be changed without replacing the card, allowing the system to maintain ease of operation while improving security - if compromise is detected, new communication parameters and corresponding symmetric keys can be issued to the same card.
3Adaptability or versatility
If changeable PIN is used for chip card authentication, then user can change identifier at will, but transfer of currently valid PIN is always necessary for security reasons
Solution Approach 1:
The patent extracts the PIN from the authentication process entirely, replacing it with symmetric key-based authentication using communication parameters. This eliminates the need for PIN transfer procedures during changes, as the symmetric key is derived from communication parameters that can be updated independently, thereby reducing complexity while maintaining adaptability.
4Reliability
If first-time user function with personalized PIN is used, then unauthorized use prior to inheritance use can be detected, but the user must replace the personalized PIN with their own during first use
Solution Approach 1:
The patent uses cryptographic copying where the terminal copies the symmetric key derivation process from the chip card. The terminal independently derives the same symmetric key from the communication parameters, enabling verification of first-time use without requiring the user to manually enter or replace PINs, thereby maintaining reliability while improving ease of operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for the two-way protection of a chip card (100) and at least one environment of the chip card (100) against unauthorized use. The environment has a chip card terminal (104), and the chip card has a first identifier (116). The method has the following environment authentication steps: - generating a ciphertext from at least one first communication parameter (K1; KA1, D1) using a first symmetric key (S1) derived from the first identifier, a protected first communication channel (112) being definable between the chip card terminal and the chip card using the communication parameter, - transmitting the ciphertext from the chip card to the chip card terminal via a predefined communication channel (108), and - attempting a decryption of the ciphertext using a second symmetric key (S2) by means of the chip card terminal (104), wherein the result of the decryption is the first communication parameter only if the first symmetric key equals the second symmetric key, and therefore the protected first communication channel is definable between the chip card terminal and the chip card only if the first identifier (116) is correct, said first communication parameter (K1, KA1, D1) comprising cryptographic information of the chip card. In the event that the decryption of the ciphertext is successful, the chip card terminal derives an additional symmetric key (S4) from the cryptographic information in order to encrypt the communication between the chip card terminal and the chip card. The chip card is successfully authenticated with respect to the environment using the encryption with the additional symmetric key (S4).