ID Token Secure Microcontroller Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ID tokens are vulnerable to unauthorized use and manipulation, as they rely solely on the token for user identification, and additional security attributes can be compromised, leading to potential misuse and skimming attacks.

Innovation Solution

An ID token with a sensor, communication interface, and protected microcontroller that captures measurement data, compares it with stored comparison data, and establishes an encrypted connection with a reader, allowing for secure authentication and authorization checks using additional security attributes like biometrics or PINs, while maintaining limited physical access to prevent manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a protected microcontroller with limited communication interfaces is used to prevent manipulation, then security against unauthorized access is improved, but the ability to exchange data with both reading devices and sensors is worsened

Engineering Contradiction:
Improvesecurity against manipulationVSAvoiddata exchange capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system is divided into two separate microcontrollers: a protected second microcontroller that handles secure data storage and communication with the reading device, and a first microcontroller that manages sensor operations and additional security attributes. This segmentation allows each microcontroller to have specialized communication interfaces while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first microcontroller acts as an intermediary between the protected second microcontroller and the sensors. It receives sensor data, processes it through the operating system, and forwards relevant information to the second microcontroller for secure storage and transmission, thereby enabling sensor integration without compromising the protected microcontroller's limited interface design.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional security attributes like PIN or biometric features are added to verify user identity, then authentication security is improved, but vulnerability to skimming attacks and manipulation is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidskimming attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of additional security attributes by the first microcontroller before allowing the protected second microcontroller to establish encrypted communication with the reading device. This preliminary action ensures that only authenticated users can initiate secure data exchange, preventing skimming attacks before they can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the result of additional security attribute verification is used to control subsequent communication operations. The first microcontroller provides feedback about authentication status to the second microcontroller, which then decides whether to proceed with encrypted data exchange, creating a closed-loop security system.

Inventive Principle:
Principle #23Feedback

3Reliability

If encrypted communication is established between ID token and reader, then data exchange security is improved, but the complexity of communication protocols is worsened

Engineering Contradiction:
Improvedata exchange securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Communication protocols are segmented and distributed across two microcontrollers: the first microcontroller handles unencrypted or lightly encrypted communication with sensors and operating system interactions, while the second protected microcontroller handles the encrypted communication with the reading device. This segmentation reduces the protocol complexity burden on any single component.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3422243B1Id-token with secure microcontroller
Publication Date: 2021.08.18 BUNDESDRUCKEREI GMBH
  • EP3422243B1 patent drawingFigure 1
  • EP3422243B1 patent drawingFigure 2
  • EP3422243B1 patent drawingFigure 3

AI summary

The invention relates to an ID token comprising a sensor (70, 72), a communication interface (30), and a first microcontroller (40), wherein the ID token (10) comprises a protected second microcontroller (50) with at least one microcontroller communication interface (59), which is arranged in a receptacle (60) of the ID token (10), wherein the microcontroller communication interface (59) provides a data input and a data output, wherein the first microcontroller (40) is configured as a proxy to mediate between the acquisition of measurement data by the sensor (70, 72) and the forwarding of the acquired measurement data from the sensor (70, 72).72) to the first application (56) of the protected second microcontroller (50) via its microcontroller communication interface (59) on the one hand, and to forward messages to establish a connection between the second application (58) and the reader (20) and/or to forward APDUs via the connection between the second application (58) and the reader (20) on the other hand.