Dual-Interface Card Security Mechanisms for Contactless Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Dual-interface payment cards face security concerns regarding data protection, particularly during shipping, as existing methods to disable the contactless interface are costly and inefficient, and quality control of personalized data is challenging without enabling the contactless interface.

Innovation Solution

Implementing security mechanisms, such as read record filters, on dual-interface payment devices to prevent specific data from being read using the contactless interface while allowing data to be read using the contact interface, enabling personalized data verification without enabling the contactless interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the contactless interface is disabled during shipping to prevent data theft, then security is improved, but quality control and testing become difficult

Engineering Contradiction:
Improvedata securityVSAvoidquality control
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments data access rights by interface type. The contactless interface is disabled for data reading during shipping, while the contact interface remains enabled. This segmentation allows quality control personnel to access and verify personalized data through the contact interface without compromising the security of the contactless interface, thus resolving the contradiction between security and quality control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If physical shielding or switches are used to disable the contactless interface, then data protection is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvedata protectionVSAvoidinterface control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces mechanical disabling mechanisms (physical shields, switches, or buttons) with a logical/software-based interface control mechanism. The contactless interface is disabled through logical control at the data link layer, allowing the same security function to be achieved without adding mechanical components, thereby reducing device complexity and manufacturing cost while maintaining data protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Difficulty of detecting and measuring

If the contactless interface is enabled for quality control testing, then measurement capability is improved, but security risk increases

Engineering Contradiction:
Improvedata verification capabilityVSAvoiddata theft risk
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic interface control where the accessibility of the contactless interface changes based on the operational context. During shipping and before personalization, the contactless interface is disabled. After personalization and quality control verification through the contact interface, the contactless interface can be enabled for normal use. This dynamic control allows quality control when needed while maintaining security when the interface is disabled.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11120441B2Apparatus, method, and computer program product for providing a quality control mechanism for the contactless interface of a dual-interface card
Publication Date: 2021.09.14 MASTERCARD INT INC
  • US11120441B2 patent drawing
  • US11120441B2 patent drawing
  • US11120441B2 patent drawing

AI summary

Techniques for enabling performance of a quality control function on the contactless interface while the contactless interface is disabled are provided. The techniques include implementing, on a dual-interface payment device, one or more security mechanisms, wherein the dual-interface payment device comprises a first interface and a second interface, using the one or more security mechanisms to prevent a subset of data corresponding to the first interface from being read using the second interface while allowing data corresponding to the second interface to be read using the first interface, and personalizing the dual-interface payment device and the one or more security mechanisms according to one or more requirements of an issuer of the dual-interface payment device.