IC Card Secure Personalization via Finite-State Machine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IC card personalization methods restrict finalization to the manufacturer's factory, preventing external organizations from performing personalization without disclosing industrial secrets, and do not allow for re-programming in case of errors, leading to high costs and inoperable cards.

Innovation Solution

A method that enables personalization outside the manufacturer's organization by storing an algorithm in the non-volatile memory as a finite-state machine, allowing secure access and re-programming through hidden data structures and authentication, enabling entities to store data in secret memory locations without revealing storage locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the personalization phase is performed only within the manufacturer's factory in the secured state, then security and secrecy of memory locations are maintained, but external organizations cannot perform personalization and re-programming is not possible

Engineering Contradiction:
Improvesecurity of personalization processVSAvoidability to perform personalization externally
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of a controlled access interface between the secured memory and external entities. This interface allows authenticated external organizations to perform personalization operations without directly accessing the secured memory locations, thereby maintaining security while enabling external operation capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The personalization process is segmented into two distinct phases: an administrative phase where external entities can prepare and verify personalization data, and a secured phase where the actual memory writing occurs. This segmentation allows external organizations to participate in the process while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If the personalization phase is performed only within the manufacturer's factory, then industrial secrets regarding memory locations are protected, but outside organizations cannot perform personalization without disclosing secrets

Engineering Contradiction:
Improveprotection of industrial secretsVSAvoidability to outsource personalization
Core Design Contradiction:
Loss of informationVSEase of manufacture

Solution Approach 1:

The patent implements an intermediary access mechanism that allows external organizations to perform personalization without revealing industrial secrets. The intermediary layer abstracts the memory location details from external entities, enabling them to write data without knowing the physical memory addresses or storage structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy or abstraction of the memory interface for external entities. This virtual interface provides the necessary functionality for personalization while maintaining the actual secret memory locations hidden from external view, allowing outsourcing without information disclosure.

Inventive Principle:
Principle #26Copying

3Reliability

If the personalization process uses hardware gates that are automatically destroyed, then the association between card and PIN cannot be changed, but wrong PINs or personalization codes cannot be changed and access to memory locations is physically interrupted

Engineering Contradiction:
Improvesecurity of PIN associationVSAvoidability to correct personalization errors
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent transitions from a static hardware gate approach to a dynamic software-controlled access mechanism. The access rights and memory locations can be dynamically adjusted through authenticated commands, allowing correction of errors while maintaining security. The system can switch between different access modes (administrative and secured) as needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of personalization from permanent hardware-level binding to flexible software-level control. This allows the system to modify personalization data and access rights through parameter changes in the software layer, enabling error correction without compromising the original security mechanism.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If the personalization phase is performed by external entities, then re-programming capability is enabled, but security authentication and controlled access mechanisms are required

Engineering Contradiction:
Improvere-programming capabilityVSAvoidauthentication and access control mechanisms
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication and authorization actions before allowing external entities to access the memory for personalization. The system first verifies the identity and rights of external entities, then grants controlled access to specific memory locations and operations, thereby enabling re-programming with appropriate security measures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7942333B2IC card secure personalization method
Publication Date: 2011.05.17 STMICROELECTRONICS INT NV
  • US7942333B2 patent drawing
  • US7942333B2 patent drawing
  • US7942333B2 patent drawing

AI summary

A method for an entity different than a manufacturer of an integrated circuit (IC) card to perform a secure personalization phase of the semi-finished IC card is provided. The semi-finished IC card includes a non-volatile memory storing an algorithm for processing data as a finite-state machine, and enabling the entity different from the IC card manufacturer to access the algorithm for storing personalization data and information in the non-volatile memory. The method includes performing a security authentication before enabling the algorithm to receive the personalization data and information, enabling the algorithm to receive the personalization data and information, and storing the personalization data and information in secret memory locations in the non-volatile memory according to a data structure and an access procedure hidden to the entity different from the manufacturer of the integrated circuit card. The enabling and storing may be repeated if the personalization data and information were not correct.