Dynamic Identifier Management for MIFARE Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The limited length of unique serial numbers in MIFARE devices, which may lead to exhaustion and vulnerability to unauthorized tracking and phishing, as well as the challenge of managing these identifiers efficiently across mobile communication devices.
Innovation Solution
A server-based method for managing unique memory device identifications by maintaining a repository of available identifiers, fetching new values, and instructing mobile communication devices to change their existing serial numbers, thereby preventing unauthorized access and extending the availability of serial numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the serial number length in MIFARE devices is kept short for simplicity and compatibility, then ease of operation and device compatibility are improved, but the pool of available unique identifiers is limited and exhaustion becomes a risk
Solution Approach 1:
The patent transitions from static serial numbers to dynamic identifiers that change over time. The identifier space is extended by adding a temporal dimension - the same physical device can present different identifiers at different times, effectively infiniteing the available identifier pool without increasing the bit length of individual identifiers.
Solution Approach 2:
The patent implements dynamic identifier assignment where serial numbers are not fixed but can be changed remotely. The MIFARE device can receive new identifier values from a remote system, allowing the identifier pool to be virtually unlimited as long as the system can generate and distribute new values.
2Device complexity
If static serial numbers are used in MIFARE devices, then device complexity is reduced and ease of manufacture is improved, but security against tracking and phishing is compromised
Solution Approach 1:
The patent implements preliminary security measures by establishing a trusted relationship between the MIFARE device and the remote system before identifier changes. The device must authenticate and establish trust beforehand, preventing unauthorized tracking and phishing attacks while maintaining relatively simple device hardware.
Solution Approach 2:
The patent introduces a remote system as an intermediary that manages identifier assignment and changes. This intermediary handles the complex security logic and identifier management, keeping the MIFARE device itself relatively simple while significantly enhancing security through centralized control and authentication mechanisms.
3Device complexity
If manual management of serial numbers is used, then device complexity is minimized, but productivity and efficiency in managing unique identifiers across multiple devices is reduced
Solution Approach 1:
The patent implements self-service capability where the MIFARE device can autonomously receive and apply new identifier values from the remote system without manual intervention. The device automatically manages its own identifier lifecycle, significantly improving productivity in deploying and managing unique identifiers across large numbers of devices.
Solution Approach 2:
The patent creates a universal identifier management system that can serve multiple MIFARE devices through a single remote system. This multi-functional approach allows one system to manage identifiers across an entire fleet of devices, dramatically improving productivity compared to manual per-device management while keeping individual device complexity low.
Data Source
AI summary
A method for server-based managing of unique memory device identifications, such as serial numbers, of memory devices having unique memory device identifications, such as emulated MIFARE devices like SmartMX cards, which memory devices are arranged in mobile communication devices, comprises keeping a repository (DB) of available memory device identifications; fetching a memory device identification from the repository and sending it to a specific mobile communication device; and instructing the mobile communication device to change the memory device identification of its associated memory device from its present value to the received new value. Further, the server instructs the mobile communication device to return the previous value of the memory device identification of its associated memory device. Finally, the server will add the returned memory device identification value to the repository of memory device identifications.


