Derived Authentication Authority for Secure Data Carrier Replacement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable data carriers, such as security documents with memory and processor capabilities, face issues with loss or theft, leading to unauthorized use and wear and tear, compromising user security and functionality.

Innovation Solution

A method is introduced to create a derived authentication instance from an original data carrier, using a trustworthy entity to derive a secret key and transmit authentication data, allowing secure transactions without the original data carrier, with the derived instance being limited to specific transactions or tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the original data carrier is used continuously for authentication transactions, then authentication functionality is maintained, but wear and tear increases and risk of loss or theft grows

Engineering Contradiction:
Improveauthentication securityVSAvoidwear and tear, loss, theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication functionality is segmented into multiple instances: the original data carrier and one or more derived authentication instances. Each instance can perform authentication transactions independently, allowing the original carrier to be used less frequently or replaced without compromising overall system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Derived authentication instances are created as copies of the original data carrier's authentication functionality. These copies contain derived secret keys and authentication data that enable them to perform the same authentication transactions as the original, reducing the original's exposure to wear, loss, or theft.

Inventive Principle:
Principle #26Copying

2Reliability

If the original data carrier is lost or stolen, then unauthorized use becomes possible, but creating a derived instance requires secure key derivation

Engineering Contradiction:
Improveprotection against unauthorized useVSAvoidkey derivation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key derivation process is performed preliminarily by a trustworthy authority before the derived authentication instance is activated. The authority derives the secret key from the original carrier's secret key and securely transmits it to the derived instance, preparing the derived instance in advance for immediate use if the original is lost or stolen.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A trustworthy authority acts as an intermediary in the key derivation and transmission process. This intermediary securely manages the derivation of secret keys from the original data carrier and distributes them to derived instances, ensuring that the process remains secure despite the added complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a derived authentication instance is created to replace the original, then risk of unauthorized use is reduced, but authentication protocol compatibility must be maintained

Engineering Contradiction:
Improvereplacement capabilityVSAvoidprotocol compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The derived authentication instance uses modified cryptographic parameters, specifically derived secret keys and authentication data, while maintaining the same authentication protocol structure. This allows the derived instance to operate seamlessly in the same authentication environment as the original carrier.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The derived authentication instance is designed to be universally compatible with the authentication protocol used by the original data carrier. It can participate in the same authentication transactions and interact with the same authentication partners, making it a versatile replacement that maintains full functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2893668B1Method for generating a derived authority from an original data carrier
Publication Date: 2018.09.12 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2893668B1 patent drawingFigure 1
  • EP2893668B1 patent drawingFigure 2~3
  • EP2893668B1 patent drawingFigure 4~5

AI summary

The invention relates to a method for generating an authentication authority derived from an original data carrier, said original data carrier having a key pair that is unique to the original data carrier and that comprises a public key and a private key of the original data carrier, in addition to a certificate for the public key of the original data carrier. The method comprises the following steps: derivation of a private key for the derived authentication authority by the original data carrier from the private key of the original data carrier; formation of derivation data for the derived authentication authority; transmission of authentication data to the derived authentication authority, said authentication data having the derivation data, the certificate for the public key of the original data carrier and a derived key pair which comprises the derived private key and the public key of the original data carrier.