Portable Data Carrier Status Tracking for Unauthorized Read Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting confidential data do not reliably detect unauthorized read access, especially in high-security scenarios, and there is a need to determine if confidential information has been read by an unauthorized party.

Innovation Solution

A portable data carrier with a memory and processor unit that stores status information indicating read access, where this information can only be accessed and changed by the processor unit, allowing for secure and reliable tracking of data access events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional protective measures (seals, encryption) are used to protect confidential data, then data security is improved, but the ability to detect unauthorized read access deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddetection of unauthorized read access
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by pre-modifying the status information in memory during the first read access to confidential data. The processor unit automatically changes the status information from an initial state (e.g., all zeros) to a modified state (e.g., containing a non-zero value or specific pattern) when reading occurs. This pre-prepared status change enables later verification of whether unauthorized access happened, resolving the contradiction by making read access detectable while maintaining security through controlled access procedures.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If status information is stored in memory to track read access, then detection capability is improved, but device complexity worsens

Engineering Contradiction:
Improveread access detectionVSAvoidmemory and processor requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing status information tracking only for specific confidential data subsets rather than all data. The status information is stored in memory locations associated with particular data regions, and the processor unit modifies only the relevant status information when reading confidential data. This selective approach enables read access detection for sensitive information while avoiding the complexity of tracking all data accesses, thus resolving the contradiction between detection capability and device complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If the status information is modified during read access, then unauthorized access detection is improved, but ease of operation worsens

Engineering Contradiction:
Improveunauthorized access detectionVSAvoiddata reading process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies self-service by implementing automatic status information modification through the processor unit during read operations. When the processor unit reads confidential data from memory, it automatically detects the read operation and modifies the associated status information without requiring external intervention or complex control logic. This automation maintains ease of operation for authorized users while reliably detecting unauthorized access attempts, resolving the contradiction between reliability and ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1899883B1Method for protecting confidential data
Publication Date: 2020.01.01 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP1899883B1 patent drawingFigure 1~2

AI summary

The invention relates to a method for protecting confidential data. According to the invention, data is stored in a memory (4) of a portable data carrier (1). Status information is allocated to the stored data and is modified at least during a first reading access to the data.