IC Card Access Level Control via Physical Characteristic Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information storing apparatuses lack effective mechanisms to securely set and manage access levels for personal information, particularly in preventing impersonation and ensuring privacy protection for integrated IC cards.

Innovation Solution

An information storing apparatus that includes a personal information storing section, an accessible person information storing section, a requester authentication section, and an access level setting section, which authenticates requesters based on physical characteristics and sets access levels for disclosing personal information, using methods such as face recognition and authentication criteria to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access level setting mechanism is implemented, then privacy protection and impersonation prevention are improved, but device complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nested access control by storing access level information within the IC card structure itself. The personal information is nested within access level containers, which are in turn nested within the card's memory structure. This allows multiple levels of security (card-level, information-level, and person-level) to be integrated without requiring separate external authentication systems for each layer.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent segments personal information into different access levels (first access level and second access level) stored in separate containers. This segmentation allows the system to control and restrict access to different portions of information based on the authenticated person's identity, thereby improving privacy protection while managing complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple access levels are implemented, then information security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service authentication by automatically comparing the person identification information provided during card insertion with the stored access level information. The microprocessor automatically determines which information containers the authenticated person can access, eliminating the need for manual permission grants or complex user interactions while maintaining high security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Access level information is pre-stored in the IC card's memory during card initialization or setup. This preliminary action allows the system to automatically determine access rights without requiring real-time manual configuration, thereby maintaining ease of operation while implementing multiple security levels.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication processing is performed for each information request, then impersonation prevention is improved, but processing time increases

Engineering Contradiction:
Improveimpersonation preventionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication and access level determination as a preliminary action when the card is first inserted into the reader. The microprocessor compares the person identification information with stored access level information and pre-determines which information containers can be accessed. This preliminary authentication eliminates the need for repeated authentication checks for each individual information request, thereby reducing processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If access level information is stored on the card, then adaptability is improved, but manufacturing complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoidmanufacturing complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The IC card is designed with multi-functionality to serve multiple purposes: it stores not only personal information but also access level information and person identification information. The same card structure and memory system handle both authentication and information storage functions, thereby improving adaptability without requiring separate dedicated systems for each function, which would increase manufacturing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7769696B2Information storing apparatus
Publication Date: 2010.08.03 FUJIFILM CORP
  • US7769696B2 patent drawing
  • US7769696B2 patent drawing
  • US7769696B2 patent drawing

AI summary

An information storing apparatus for judging who requests personal information and for setting an access level for the personal information for the requester. The information storing apparatus includes: a personal information storing section storing thereon the personal information which is to be disclosed to predetermined accessible persons; an accessible person information storing section storing thereon accessible person characteristic information indicating a physical characteristic of each of the plurality of accessible persons; a requester authentication section for receiving requester characteristic information indicating a physical characteristic of a requester who requests the personal information, and for performing authentication processing of the requester using the requester characteristic information and the accessible person characteristic information stored on the accessible person information storing section; an access level setting section for setting an access level, which is a level of the personal information to be disclosed to the requester, when the requester authentication section authenticates the requester as the accessible person; and a personal information output section for outputting a part of the personal information stored on the personal information storing section to the requester in accordance with the access level set-up by the access level setting section.