Secure Chip Card OS Update via Generic Boot Loader
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing chip card technologies do not allow for secure loading of executable program instructions during active operation, which is necessary for government applications and secure transactions, as they lack sufficient security mechanisms to prevent malware introduction and require a boot loader tailored to each chip card operating system.
Innovation Solution
Implementing an authentication function within the chip card operating system that authenticates the chip card terminal before allowing the loading of executable program instructions, allowing the boot loader to verify the authentication and enabling secure updates without compromising the chip card's security, thus avoiding the need for a tailored boot loader for each operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the boot loader is used to load executable program instructions during active operation, then the chip card operating system can be updated, but the security of the chip card is compromised
Solution Approach 1:
The system is divided into two distinct authentication mechanisms: one for the personalisation facility during production and another for the chip card terminal during active operation. This segmentation allows each component to have specialised security protocols, enabling OS updates while maintaining overall system security through role-based authentication separation.
Solution Approach 2:
The chip card operating system acts as an intermediary between the chip card terminal and the boot loader. It receives authentication from the terminal, verifies credentials, and then controls the boot loader's execution. This intermediary layer prevents direct access to the boot loader, ensuring that only authenticated terminals can initiate OS updates while maintaining security during active operation.
2Manufacturing precision
If a boot loader tailored to each chip card operating system is created, then the loading process is optimised, but the production cost increases
Solution Approach 1:
The boot loader is designed as a universal, generic component that can load and execute any chip card operating system. It contains a memory management unit capable of handling different OS types without requiring customisation. This universal approach eliminates the need for separate boot loaders for each OS, reducing production costs while maintaining the ability to load and optimise any operating system through a single standardized interface.
Data Source
AI summary
The method includes authenticating a chip card terminal to a chip card by a chip card operating system, verifying the authorization of the chip card terminal to load executable program instructions by the chip card operating system, storing data in a predefined memory region of the NVM, which data indicate a successful execution of the authentication and the verification, by the chip card operating system, starting execution of a boot loader by the chip card operating system and interrupting the execution of the chip card operating system following the start of the boot loader, reading the data from the predefined memory region by the boot loader, loading the program instructions from the chip card terminal into the NVM by the boot loader on the precondition that the data indicate the successful authentication and verification in the predefined memory region.


