Personalization Data Providing Unit Encryption Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing personalization systems for portable data carriers lack flexibility and processing efficiency while compromising on data security, particularly when transmitting and processing personalization data over public networks.

Innovation Solution

The system employs a data providing unit that transmits personalization data in a system internal format, converting it to the specific format required by each personalization unit, and uses re-encryption and decryption to maintain security and flexibility, with optional channel encryption and post-transmission processing to adapt to different units without requiring the data providing unit to be adapted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personalization data are transmitted in encrypted form from the data providing unit to the personalization unit, then data security is improved, but processing time and flexibility deteriorate due to complex encryption mechanisms

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the encryption process into two distinct parts: (1) storage encryption using a first encryption algorithm when data is stored in the data providing unit, and (2) transmission encryption using a second encryption algorithm when data is transmitted to the personalization unit. This segmentation allows each encryption method to be optimized independently, balancing security requirements with processing efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the encryption parameters by using different encryption algorithms for different purposes. The storage encryption uses one algorithm while transmission encryption uses another, allowing the system to adapt encryption strength to specific operational contexts and reduce overall processing time while maintaining security.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the data providing unit is adapted to each personalization unit's format requirements, then compatibility is improved, but device complexity and adaptability requirements worsen

Engineering Contradiction:
Improveformat compatibilityVSAvoiddata providing unit complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the format conversion function from the data providing unit and places it in the personalization unit. The data providing unit only needs to transmit data in a standard format, while each personalization unit independently converts the received standard format data into its own specific format requirements. This extraction significantly reduces the complexity of the data providing unit.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a standard format as an intermediary between the data providing unit and various personalization units. All data providing units transmit data in this standardized format, which then serves as a universal interface that different personalization units can independently adapt to their specific requirements without affecting the data providing unit.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If all personalization data fields are transmitted to each personalization unit, then data completeness is improved, but transmission efficiency and processing speed worsen

Engineering Contradiction:
Improvedata completenessVSAvoidtransmission efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent applies partial action by transmitting only the specific data fields that each personalization unit requires, rather than transmitting all available personalization data fields. Each personalization unit specifies which fields it needs, and only those selected fields are transmitted from the data providing unit, reducing transmission volume while ensuring data completeness for the required fields.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If encryption is tightly coupled with the main personalization unit, then security control is improved, but system flexibility and independent adaptability worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encryption functionality into independent components: the data providing unit has its own encryption mechanism for storage and transmission, while the personalization unit has its own decryption capability. This segmentation allows each unit to independently adapt and configure encryption without requiring changes to the other unit, enhancing system flexibility while maintaining security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2386978B1Personalization data providing unit
Publication Date: 2020.01.15 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2386978B1 patent drawingFigure 1~2
  • EP2386978B1 patent drawingFigure 3~4

AI summary

The present invention relates to a method in a system for personalizing portable data carriers 50, the system comprising a personalization data providing unit 20 and a plurality of personalization units and further relates to a corresponding data providing unit and the personalization system. The data providing unit transmits 308 personalization data to a first or a second of the personalization units in an internal system format, the format being defined in the application layer. The transmitted personalization data are converted from the system internal format to a first or a second application layer format of the first or second personalization unit 30, 40 respectively. The converted personalization data are used for personalizing the portable data carriers 50 in the personalization unit. According to the invention the personalization data are decrypted in the data providing unit 20, re-encrypted before being transmitted and correspondingly decrypted in the personalization unit 30, 40 before being converted.