Portable Device Interface Security Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security mechanisms for portable electronic devices with multiple interfaces, such as contact and contactless interfaces, are vulnerable to attacks where a hacker can block the device by sending multiple incorrect authentication attempts through the contactless interface, leading to unintended blocking and requiring external intervention for unblocking.

Innovation Solution

A portable electronic device with separate security measures for each interface, including counters and indicator elements, that detect and respond to attacks by blocking only the affected interface while allowing the other interface to remain operational for unblocking, using different communication protocols and security methods like secret codes, cryptographic keys, and biometric data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single security mechanism is used for all interfaces, then the device structure is simple, but the device becomes vulnerable to attacks through any interface and cannot selectively block affected interfaces

Engineering Contradiction:
Improvesecurity against attacksVSAvoidsecurity mechanism structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security mechanism into separate components for each interface. Each interface has its own counter element, indicator element, and threshold value stored in distinct memory areas. This segmentation allows the device to independently monitor and block each interface based on attack patterns specific to that interface, preventing a single point of failure across all interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements interface-specific security parameters where each interface can have customized counter thresholds, indicator states, and blocking behaviors. This local quality allows the contactless interface to be blocked independently from the contact interface, enabling selective response to attacks on specific interfaces while maintaining functionality of others.

Inventive Principle:
Principle #3Local quality

2Reliability

If the device blocks all interfaces when an attack is detected, then security is maximized, but legitimate access through unaffected interfaces is lost requiring external intervention

Engineering Contradiction:
Improvesecurity blocking effectivenessVSAvoiduser access to unblock device
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By segmenting the blocking mechanism to operate independently per interface, the patent enables a user to unblock one interface through another interface. For example, if the contactless interface is blocked due to attacks, the user can still use the contact interface to reset counters and restore functionality, eliminating the need for external intervention.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables self-service unblocking where the device can restore its own functionality through alternative interfaces. The counter elements can be reset and indicator elements reverted to their initial states through legitimate authentication on unaffected interfaces, allowing the device to serve itself without requiring external authority intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9047727B2Portable electronic device and method for securing such device
Publication Date: 2015.06.02 IDEMIA FRANCE SAS
  • US9047727B2 patent drawing
  • US9047727B2 patent drawing
  • US9047727B2 patent drawing

AI summary

A portable electronic device includes a first interface adapted for establishing a communication with a first external electronic entity. A first security element is adapted for detecting at least one type of attack and forbidding at least one data communication using the first interface after the detection of an attack. A second interface is different from the first interface and is adapted for establishing a communication with a second external electronic entity. A management element of the first security element uses the second interface for managing the first security element.