Chip Card Personalization via Segmented Key Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current chip card personalization methods require secure environments for key generation and application activation, leading to time-consuming processes and limitations in flexibility, especially for multi-application cards which need frequent updates outside secure centers.
Innovation Solution
A method where key information is stored on the chip card for secure partial personalization in a secure center, allowing supplemental personalization in non-secure environments using an instruction sequence definition and authentication checks to ensure only valid instructions are executed, enabling activation of applications outside the center.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If personalization is carried out in a secure personalization center, then security requirements are met, but personalization time increases and flexibility decreases
Solution Approach 1:
The personalization process is divided into two independent phases: (1) secure phase in personalization center for key information storage, and (2) supplemental personalization phase in non-secure environment for application activation. This segmentation allows time-consuming secure operations to be separated from routine personalization tasks, reducing overall personalization time while maintaining security requirements.
Solution Approach 2:
Key information is stored on the chip card during initial personalization in the secure center before the card is issued. This preliminary secure setup enables subsequent supplemental personalization to be performed in non-secure environments without requiring repeated secure center access, significantly reducing personalization time for multi-application cards.
2Reliability
If personalization is carried out in a secure personalization center, then security requirements are met, but flexibility for post-issue updates decreases
Solution Approach 1:
The personalization process is divided into two independent phases: (1) secure phase in personalization center for key information storage, and (2) supplemental personalization phase in non-secure environment for application activation. This segmentation allows time-consuming secure operations to be separated from routine personalization tasks, reducing overall personalization time while maintaining security requirements.
Solution Approach 2:
The patent changes the security parameter requirements for different personalization phases. Initial personalization requires secure center environment with high security parameters, while supplemental personalization uses modified security parameters enabled by pre-stored key information, allowing flexible post-issue updates without returning to secure center.
3Adaptability or versatility
If multiple applications are activated on multi-application chip cards, then card functionality increases, but personalization time increases due to repeated secure center visits
Solution Approach 1:
Key information is stored on the chip card during initial personalization in the secure center before the card is issued. This preliminary secure setup enables subsequent supplemental personalization to be performed in non-secure environments without requiring repeated secure center access, significantly reducing personalization time for multi-application cards.
Solution Approach 2:
Key information stored on the chip card acts as an intermediary that enables supplemental personalization in non-secure environments. This intermediary security mechanism allows application activation without direct secure center involvement, reducing personalization time while maintaining security for multi-application functionality.
4Reliability
If security keys are generated during personalization, then card security is ensured, but personalization process becomes time consuming
Solution Approach 1:
Key information is stored on the chip card during initial personalization in the secure center before the card is issued. This preliminary secure setup enables subsequent supplemental personalization to be performed in non-secure environments without requiring repeated secure center access, significantly reducing personalization time for multi-application cards.
Solution Approach 2:
The personalization process is divided into two independent phases: (1) secure phase in personalization center for key information storage, and (2) supplemental personalization phase in non-secure environment for application activation. This segmentation allows time-consuming secure operations to be separated from routine personalization tasks, reducing overall personalization time while maintaining security requirements.
Data Source
AI summary
Key information is stored in a memory of a chip card for the purposes of partial personalization. For a complete personalization, an instruction sequence definition and an instruction sequence designed for a chip card application and including instructions to be carried out by the chip card are transmitted to the chip card. A check which is secured by the key information is carried out for each chip card instruction to determine whether the chip card instruction satisfies the instruction sequence definition, and if it does, the chip card instruction is carried out by the chip card.


