Chip Card Write Protection via Cryptographic Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure data transmission and write access to chip cards are vulnerable to unauthorized access, lacking effective authorization checks.

Innovation Solution

A cryptographic protocol using a symmetric key, where the chip card generates and transmits the key only after the computer system's authorization is verified through a certification service provider's certificate and public key, ensuring secure write access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cryptographic protocol using symmetric key is implemented where the chip card generates and transmits the key only after authorization verification, then security against unauthorized write access is improved, but device complexity increases due to certificate storage and verification mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The chip card performs preliminary authorization verification by checking the computer system's certificate against its stored certification service provider certificate before generating or transmitting the symmetric key. This ensures that only authorized systems can obtain write access credentials, preventing unauthorized modifications while maintaining security protocols.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a certification service provider as an intermediary that issues certificates to computer systems. The chip card stores the certification service provider's certificate and uses it to verify the computer system's authorization. This intermediary mechanism enables secure authentication without requiring complex direct verification protocols between the chip card and computer system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authorization checks using certification service provider certificates are implemented, then protection against unauthorized data changes is improved, but the ease of operation deteriorates due to additional verification steps

Engineering Contradiction:
Improveprotection against unauthorized changesVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The chip card autonomously performs the authorization verification by checking the computer system's certificate against its stored certification service provider certificate. The computer system simply needs to present its certificate, and the chip card independently validates it, reducing the operational burden on users while maintaining strong security protections.

Inventive Principle:
Principle #25Self-service

3Reliability

If the symmetric key is transmitted only after authorization verification, then security against viruses and sabotage is improved, but the time required for write access operations increases

Engineering Contradiction:
Improveprotection against viruses and sabotageVSAvoidtime for write access
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The chip card performs the authorization verification and symmetric key generation in advance, before any actual write operations commence. By completing the security verification and key establishment beforehand, the patent ensures that once authorization is granted, the subsequent write operations can proceed efficiently without repeated verification delays, thus minimizing time loss while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2562670B1Method for performing a write protection operation, computer program product, computer system and chip card
Publication Date: 2018.06.27 BUNDESDRUCKEREI GMBH
  • EP2562670B1 patent drawingFigure 1
  • EP2562670B1 patent drawingFigure 2

AI summary

The invention relates to a method for performing a write access to a memory area of ​​a chip card (112), wherein a cryptographic method is performed for transmitting an access command (128) and/or the data (130) to be written to the chip card.