Dynamic Security Code Management for Smart Cards
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for electronic components, such as smart cards, are ineffective against fault injection attacks and incur significant performance penalties, degrading execution time and memory consumption, making them unsuitable for applications like transport or payment systems.
Innovation Solution
A dynamic security management method that conditionally activates security countermeasures based on attack detection, using a detection device to manage the execution of security codes stored in non-volatile memory, allowing for modular and adaptive security levels tailored to the adversary's capability, with a virtual machine executing intermediate codes and employing light and temperature variation detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security countermeasures are implemented in electronic components, then security against fault injection attacks is improved, but execution time and memory consumption increase significantly
Solution Approach 1:
The patent implements dynamic security management where countermeasures are activated or deactivated based on detected attack patterns. The system transitions from static always-on security to dynamic conditional security, adjusting protection levels in real-time based on threat detection from fault injection attacks.
Solution Approach 2:
The system changes security parameters dynamically by modifying which countermeasures are active based on attack detection. When attacks are detected, the system adjusts security parameters to activate additional countermeasures; when no attacks are detected, it reduces security activation to optimize performance.
2Reliability
If security countermeasures are implemented in electronic components, then security against fault injection attacks is improved, but memory consumption increases
Solution Approach 1:
The patent implements dynamic security management where countermeasures are activated or deactivated based on detected attack patterns. The system transitions from static always-on security to dynamic conditional security, adjusting protection levels in real-time based on threat detection from fault injection attacks.
Solution Approach 2:
The system changes security parameters dynamically by modifying which countermeasures are active based on attack detection. When attacks are detected, the system adjusts security parameters to activate additional countermeasures; when no attacks are detected, it reduces security activation to optimize performance.
3Reliability
If security countermeasures are activated by default, then security is maintained, but normal operations suffer performance degradation
Solution Approach 1:
The system prepares security countermeasures in advance but keeps them inactive during normal operations. When attacks are detected, the pre-prepared countermeasures are activated immediately to counter the threat, rather than activating all countermeasures from the start.
Solution Approach 2:
The patent implements dynamic security management where countermeasures are activated or deactivated based on detected attack patterns. The system transitions from static always-on security to dynamic conditional security, adjusting protection levels in real-time based on threat detection from fault injection attacks.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach maintains an optimal balance between performance and security by dynamically activating security measures only when needed, ensuring durable security without rendering the component unusable and minimizing performance impact during normal operations.
Implementation Method 1
employing light and temperature variation detection
Implementation Method 2
employing light and temperature variation detection
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The method involves executing codes in dynamic manner according to a parameter related to the detection of attack by a detection device i.e. sensor, where the parameter is included in a non-volatile memory, and state of the parameter is regularly checked by an electronic component i.e. microcontroller (100). The codes associated with security counter measures are classified into groups, each associated with a security level to prioritize the groups with respect to each other. Execution of the codes is implemented based on number of attacks detected by the detection device. Independent claims are also included for the following: (1) a computer program product comprising program code instructions to perform a method for managing codes associated with sedentary counter measures (2) a device for managing codes associated with security counter measures.