ID Token Secure Microcontroller Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing ID tokens are vulnerable to unauthorized use and manipulation, as they rely solely on the token for user identification, and additional security attributes can be compromised, leading to potential misuse and skimming attacks.
Innovation Solution
An ID token with a sensor, communication interface, and protected microcontroller that captures measurement data, compares it with stored comparison data, and establishes an encrypted connection with a reader, allowing for secure authentication and authorization checks using additional security attributes like biometrics or PINs, while maintaining limited physical access to prevent manipulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a protected microcontroller with limited communication interfaces is used to prevent manipulation, then security against unauthorized access is improved, but the ability to exchange data with both reading devices and sensors is worsened
Solution Approach 1:
The system is divided into two separate microcontrollers: a protected second microcontroller that handles secure data storage and communication with the reading device, and a first microcontroller that manages sensor operations and additional security attributes. This segmentation allows each microcontroller to have specialized communication interfaces while maintaining overall system security.
Solution Approach 2:
The first microcontroller acts as an intermediary between the protected second microcontroller and the sensors. It receives sensor data, processes it through the operating system, and forwards relevant information to the second microcontroller for secure storage and transmission, thereby enabling sensor integration without compromising the protected microcontroller's limited interface design.
2Reliability
If additional security attributes like PIN or biometric features are added to verify user identity, then authentication security is improved, but vulnerability to skimming attacks and manipulation is worsened
Solution Approach 1:
The system performs preliminary verification of additional security attributes by the first microcontroller before allowing the protected second microcontroller to establish encrypted communication with the reading device. This preliminary action ensures that only authenticated users can initiate secure data exchange, preventing skimming attacks before they can occur.
Solution Approach 2:
The system implements a feedback mechanism where the result of additional security attribute verification is used to control subsequent communication operations. The first microcontroller provides feedback about authentication status to the second microcontroller, which then decides whether to proceed with encrypted data exchange, creating a closed-loop security system.
3Reliability
If encrypted communication is established between ID token and reader, then data exchange security is improved, but the complexity of communication protocols is worsened
Solution Approach 1:
Communication protocols are segmented and distributed across two microcontrollers: the first microcontroller handles unencrypted or lightly encrypted communication with sensors and operating system interactions, while the second protected microcontroller handles the encrypted communication with the reading device. This segmentation reduces the protocol complexity burden on any single component.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to an ID token comprising a sensor (70, 72), a communication interface (30), and a first microcontroller (40), wherein the ID token (10) comprises a protected second microcontroller (50) with at least one microcontroller communication interface (59), which is arranged in a receptacle (60) of the ID token (10), wherein the microcontroller communication interface (59) provides a data input and a data output, wherein the first microcontroller (40) is configured as a proxy to mediate between the acquisition of measurement data by the sensor (70, 72) and the forwarding of the acquired measurement data from the sensor (70, 72).72) to the first application (56) of the protected second microcontroller (50) via its microcontroller communication interface (59) on the one hand, and to forward messages to establish a connection between the second application (58) and the reader (20) and/or to forward APDUs via the connection between the second application (58) and the reader (20) on the other hand.