Identity Document Skimming Resistance via Segmented Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity documents with machine-readable electronic chips face risks of data leakage and fraud due to inadequate security measures, particularly with RFID interfaces, and existing solutions fail to provide a universally accepted and compliant security standard across different countries.

Innovation Solution

A secured identity document with an externally readable chip storing a cryptographic configuration and a private key, along with an optically readable area encoding both non-ciphered and ciphered cryptographic data, allows for secure communication without terminal authentication, using a contactless interface and cryptographic key pair for authentication and secure channel establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If RFID interface is used for contactless communication with the chip, then ease of operation is improved, but security against skimming attacks deteriorates

Engineering Contradiction:
Improvecontactless communication convenienceVSAvoidsecurity against skimming
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The cryptographic configuration is segmented into two distinct forms: a non-ciphered version for optical readability and a ciphered version stored in the chip. This segmentation allows the system to provide contactless optical reading convenience while maintaining cryptographic security through the separate ciphered storage in the chip that requires proper authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The optically readable area acts as an intermediary between the physical document and the cryptographic verification process. It provides machine-readable cryptographic configuration data that can be verified optically without requiring direct chip access, thereby preventing skimming attacks while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic configuration is stored in non-ciphered form for optical reading, then ease of operation is improved, but security against fraud deteriorates

Engineering Contradiction:
Improveoptical reading capabilityVSAvoidfraudulent access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The cryptographic configuration is divided into non-ciphered data for optical display and ciphered data stored in the chip. The non-ciphered portion enables optical reading and verification without exposing the actual cryptographic keys, while the ciphered portion in the chip prevents fraudulent access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the cryptographic configuration have different security properties: the optically readable area contains non-ciphered data suitable for verification, while the chip contains ciphered data with higher security. This local differentiation of security quality allows both optical reading and fraud prevention.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If ciphered cryptographic configuration is stored in the chip, then security against fraud is improved, but device complexity increases

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoiddual storage format requirement
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The cryptographic configuration is prepared in advance in both non-ciphered and ciphered forms during document issuance. The non-ciphered version is optically readable and the ciphered version is stored in the chip, eliminating the need for complex real-time conversion or processing during verification.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If aluminum shielding is applied to the chip, then security against RFID skimming is improved, but ease of operation deteriorates

Engineering Contradiction:
ImproveRFID shielding protectionVSAvoiddocument access requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The optically readable area serves as an intermediary that provides verification capability without requiring physical access to the chip. Users can verify the cryptographic configuration optically through the readable area without opening the document or exposing the shielded chip.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9396506B2System providing an improved skimming resistance for an electronic identity document
Publication Date: 2016.07.19 THALES DIS FRANCE SA
  • US9396506B2 patent drawing
  • US9396506B2 patent drawing
  • US9396506B2 patent drawing

AI summary

The invention relates to a secured identity document having an externally readable chip storing a cryptographic configuration of the chip, defining the cryptographic security levels supported by the chip, for establishing a secure communication with a controlling terminal, storing a private key of a cryptography key pair and adapted to cipher data based on the stored private key; a support to which the chip is fastened, the support having a machine optically readable area, the data encoded in this area including the cryptographic configuration of the chip for establishing a secure communication with a controlling terminal in non ciphered form and the cryptographic configuration of the chip ciphered based on said private key.