Chip Card Secure Communication Transport Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Global Platform Open Platform Specification, Version 2.0.1, does not provide security for data communicated from a chip card to an off-card entity, leaving it vulnerable to man-in-the-middle attacks.

Innovation Solution

A method is introduced to generate a transport key at the off-card entity, securely transmit it to the chip card, and use it to encrypt data sent from the chip card to the off-card entity, establishing a secure channel for two-way communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Open Platform Specification Version 2.0.1 is used to establish a secure channel, then secure communication from the off-card entity to the chip card is achieved, but data transmission from the chip card to the off-card entity remains vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improvesecurity of data transmissionVSAvoidcomplexity of secure communication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A transport key is introduced as an intermediary element to enable secure encryption of data transmitted from the chip card to the off-card entity. The transport key is generated by the off-card entity, transmitted securely to the chip card, and then used by the chip card's encryption application to encrypt outgoing data, thereby filling the security gap without fundamentally altering the Open Platform Specification protocol structure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The transport key is generated and transmitted to the chip card before actual data transmission occurs. This preliminary establishment of encryption capabilities ensures that when data needs to be sent from the chip card to the off-card entity, the encryption mechanism is already in place and ready to protect the communication

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7805611B1Method for secure communication from chip card and system for performing the same
Publication Date: 2010.09.28 ORACLE AMERICAN INC
  • US7805611B1 patent drawing
  • US7805611B1 patent drawing
  • US7805611B1 patent drawing

AI summary

A method and system is provided to secure a data transmission from a chip card to an off-card entity. A transport key is generated at the off-card entity. The transport key is transmitted in a secure manner from the off-card entity to the chip card. At the chip card, the transport key is used to encrypt data to be sent from the chip card to the off-card entity. The data having been encrypted at the chip card using the transport key is then transmitted from the chip card to the off-card entity. The off-card entity is capable of decrypting the data received from the chip card through use of the transport key previously generated at the off-card entity.