IC Card Access Level Control via Physical Characteristic Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information storing apparatuses lack effective mechanisms to securely set and manage access levels for personal information, particularly in preventing impersonation and ensuring privacy protection for integrated IC cards.
Innovation Solution
An information storing apparatus that includes a personal information storing section, an accessible person information storing section, a requester authentication section, and an access level setting section, which authenticates requesters based on physical characteristics and sets access levels for disclosing personal information, using methods such as face recognition and authentication criteria to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access level setting mechanism is implemented, then privacy protection and impersonation prevention are improved, but device complexity increases
Solution Approach 1:
The patent implements nested access control by storing access level information within the IC card structure itself. The personal information is nested within access level containers, which are in turn nested within the card's memory structure. This allows multiple levels of security (card-level, information-level, and person-level) to be integrated without requiring separate external authentication systems for each layer.
Solution Approach 2:
The patent segments personal information into different access levels (first access level and second access level) stored in separate containers. This segmentation allows the system to control and restrict access to different portions of information based on the authenticated person's identity, thereby improving privacy protection while managing complexity through structured organization.
2Reliability
If multiple access levels are implemented, then information security is improved, but ease of operation deteriorates
Solution Approach 1:
The system performs self-service authentication by automatically comparing the person identification information provided during card insertion with the stored access level information. The microprocessor automatically determines which information containers the authenticated person can access, eliminating the need for manual permission grants or complex user interactions while maintaining high security.
Solution Approach 2:
Access level information is pre-stored in the IC card's memory during card initialization or setup. This preliminary action allows the system to automatically determine access rights without requiring real-time manual configuration, thereby maintaining ease of operation while implementing multiple security levels.
3Reliability
If authentication processing is performed for each information request, then impersonation prevention is improved, but processing time increases
Solution Approach 1:
The system performs authentication and access level determination as a preliminary action when the card is first inserted into the reader. The microprocessor compares the person identification information with stored access level information and pre-determines which information containers can be accessed. This preliminary authentication eliminates the need for repeated authentication checks for each individual information request, thereby reducing processing time while maintaining security.
4Adaptability or versatility
If access level information is stored on the card, then adaptability is improved, but manufacturing complexity increases
Solution Approach 1:
The IC card is designed with multi-functionality to serve multiple purposes: it stores not only personal information but also access level information and person identification information. The same card structure and memory system handle both authentication and information storage functions, thereby improving adaptability without requiring separate dedicated systems for each function, which would increase manufacturing complexity.
Data Source
AI summary
An information storing apparatus for judging who requests personal information and for setting an access level for the personal information for the requester. The information storing apparatus includes: a personal information storing section storing thereon the personal information which is to be disclosed to predetermined accessible persons; an accessible person information storing section storing thereon accessible person characteristic information indicating a physical characteristic of each of the plurality of accessible persons; a requester authentication section for receiving requester characteristic information indicating a physical characteristic of a requester who requests the personal information, and for performing authentication processing of the requester using the requester characteristic information and the accessible person characteristic information stored on the accessible person information storing section; an access level setting section for setting an access level, which is a level of the personal information to be disclosed to the requester, when the requester authentication section authenticates the requester as the accessible person; and a personal information output section for outputting a part of the personal information stored on the personal information storing section to the requester in accordance with the access level set-up by the access level setting section.


