Memory Carrier Authentication Code Nesting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory carriers for access control systems lack comprehensive security, particularly in contract identification records, as they can be copied and used for unauthorized operations due to vulnerabilities in record structure and reading methods.
Innovation Solution
The memory carrier incorporates a dynamic record allocation table with authentication codes linked to both the memory carrier serial code and contract identification record, ensuring that contract identification records cannot be copied or used for unauthorized operations, and includes a life cycle record for additional security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication codes are added to contract identification records, then security against unauthorized copying is improved, but device complexity increases
Solution Approach 1:
The authentication code is nested within the contract identification record structure, with the authentication code forming an integral part of the record. This allows security verification to be performed as part of the existing record validation process, adding security without requiring a completely separate verification system.
Solution Approach 2:
The security system is segmented into distinct components: the contract identification record containing contract-specific information, and the authentication code containing security verification data. This segmentation allows each component to be optimized independently while maintaining overall system security.
2Reliability
If comprehensive security measures are implemented in memory carriers, then protection against unauthorized operations is improved, but ease of operation deteriorates
Solution Approach 1:
The memory carrier performs self-verification by internally validating the authentication code against the contract identification record and serial code. This self-service approach eliminates the need for external verification systems, maintaining security while simplifying the operational process for users and operators.
Solution Approach 2:
The authentication code is pre-calculated and stored within the contract identification record during memory carrier manufacturing. This preliminary action ensures that security verification can be performed instantly during authorization operations without requiring complex real-time calculations or external verification processes.
3Productivity
If dynamic record allocation table is implemented, then authorization speed is improved, but security vulnerability increases
Solution Approach 1:
The authentication code serves multiple functions simultaneously: it validates the contract identification record, verifies the memory carrier serial code, and ensures the integrity of the dynamic record allocation table. This multi-functionality maintains security while enabling fast authorization operations through the dynamic table structure.
Data Source
Figure 1
Figure 2
Figure 3~6
AI summary
Memory carrier (1) for access control, comprising a unique, read-only serial code (2); a plurality of records, comprising a memory carrier identification record (4) and at least one contract identification record (6); wherein each one of the memory carrier identification record (4) and at least one contract identification record (6) comprise an authentication code (4a, 6a); and the authentication code (4a) of said memory carrier identification record (4) matches in a first check a memory carrier security code resulting from encrypting with a security key a combination of at least part of the unique, read-only serial code (2) and at least part said memory carrier identification record (4), and the authentication code (6a) of each at least one contract identification record (6) matches in a second check a business security code resulting from encrypting with a product key a combination of said memory carrier security code, and at least part of said contract identification record (6). The invention also comprises an authorisation method using such a memory carrier (1), a reader (12) for performing said authorisation method, a network (13) of several such readers (12) and an access control system (11) comprising at least one memory carrier (1) and a reader (12) and/or a network (13).