Access Control Layer for Contactless IC Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated circuit cards with contactless communication interfaces face security challenges, including unauthorized transactions, data theft, and fraudulent use, particularly due to the 'New Card' functionality that requires initial online activation and does not prevent initial online transactions or offline modifications, leading to user perception issues and incompatibility with certain types of cards.
Innovation Solution
A method for controlling access to communication interfaces in integrated circuits using an access control software layer that intercepts events between communication interfaces and applications, assigning specific parameters to indicate authorization, and updating these parameters based on conditions met by intercepted events, ensuring secure and authorized use of both contactless and contact interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the card is equipped with a contactless communication interface, then communication convenience is improved, but security against unauthorized transactions and data theft deteriorates
Solution Approach 1:
The patent applies preliminary action by establishing a prohibited state for the contactless interface before any transaction occurs. The access control layer is pre-configured to block unauthorized applications from accessing the contactless interface, and this blocking state is maintained until specific authorization conditions are met through verified transactions or PIN authentication.
Solution Approach 2:
The patent implements feedback mechanisms where the access control layer continuously monitors transaction outcomes and updates authorization states accordingly. Successful verified transactions or PIN authentication feedback triggers the access control layer to transition from prohibited to authorized state, while failed attempts maintain the blocking state.
2Reliability
If the 'New Card' functionality is implemented, then security against fraudulent use is improved, but ease of use deteriorates due to requirement of initial online activation
Solution Approach 1:
The patent applies preliminary action by pre-configuring the access control layer to maintain a prohibited state for the contactless interface before any transaction. This preliminary blocking state ensures that even if a malicious person obtains the card, they cannot perform unauthorized transactions without going through proper authentication channels.
Solution Approach 2:
The patent implements dynamics by making the access control state changeable based on transaction outcomes. The access control layer transitions from a static prohibited state to a dynamic authorized state when verified transactions or PIN authentication occur, allowing the system to adapt its security level based on actual usage patterns.
3Reliability
If the contactless interface is blocked until first online transaction, then security is improved, but compatibility with certain card types deteriorates
Solution Approach 1:
The patent applies local quality by implementing differentiated access control for different applications and transaction types. The access control layer selectively blocks or allows access based on the specific application attempting to use the contactless interface and the associated transaction characteristics, rather than applying a uniform block to all uses.
Solution Approach 2:
The patent implements universality by designing the access control layer to handle multiple scenarios and card types through a single unified mechanism. The layer can accommodate various transaction modes (online/offline), authentication methods (PIN/visual verification), and card configurations by applying consistent access control principles across all cases.
Data Source
Figure 1~3
Figure 4~5A
Figure 5B~6
AI summary
The method involves intercepting an event transmitted between communication interface and application (AP1,AP2,AP3) performed by integrated circuit. The intercepted event (EVT) is transmitted if specific parameter (I2) of application indicates that the application is authorized to use communication interface. The events for the application are transmitted by communication interface. The authorization or refusal rules of use of communication interface and verification states of rules are stored and update verification states of rules as a function of each event. An independent claim is included for integrated circuit.