Dynamic Serial Number Management for MIFARE Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The limited length of unique serial numbers in MIFARE devices, which may lead to exhaustion and vulnerability to unauthorized tracking and phishing, as well as the challenge of managing these identifiers in mobile communication devices.
Innovation Solution
A server-based method for managing unique memory device identifications by maintaining a repository of available identifiers, fetching new values, and instructing mobile communication devices to change their existing serial numbers, thereby preventing unauthorized access and extending the availability of serial numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the serial number length in MIFARE devices is kept short for simplicity and compatibility, then ease of operation and device compatibility are improved, but the quantity of available unique identifiers is limited leading to exhaustion and security vulnerabilities
Solution Approach 1:
The patent transitions from a single-dimension serial number system (fixed length stored in MIFARE devices) to a multi-dimension identification system. The first identification (serial number) remains short for compatibility, while a second identification (longer identifier) is stored on the server. This dimensional expansion allows the system to maintain short serial numbers for ease of operation while accessing a much larger pool of unique identifiers through the server-based second identification.
2Reliability
If a server-based system is implemented to manage and dynamically change serial numbers, then security against phishing and tracking is improved, but device complexity and system complexity increase
Solution Approach 1:
The patent introduces a server as an intermediary between the mobile communication device and the identification management system. The server stores the second identification and manages the dynamic changing process, while the MIFARE device itself remains relatively simple. This intermediary approach enhances security through centralized control and auditing capabilities, while the complexity is distributed to the server infrastructure rather than burdening the mobile device.
Solution Approach 2:
The system performs preliminary actions by pre-generating and storing second identifications on the server before they are needed. When a serial number change is required, the mobile device simply retrieves the pre-prepared second identification from the server, rather than generating or computing it during the authentication process. This reduces the computational complexity and processing time required during actual authentication events.
3Object-affected harmful factors
If dynamic serial number changing is implemented, then protection against unauthorized tracking and phishing is improved, but the frequency of changes and processing overhead increase
Solution Approach 1:
The patent implements periodic action by changing the serial number at specific intervals or under specific conditions (e.g., after a certain number of authentication events, or at scheduled times). The server manages when second identifications are activated, allowing for regular updates that prevent tracking and phishing attacks. This periodic approach balances security enhancement with acceptable processing overhead, as changes occur at predetermined moments rather than continuously.
Data Source
AI summary
A method for server-based managing of unique memory device identifications, such as serial numbers, of memory devices having unique memory device identifications, like MIFARE devices, preferably emulated MIFARE devices like SmartMX cards, which memory devices are arranged in mobile communication devices, comprises keeping a repository of available memory device identifications; fetching a memory device identification from the repository and sending it to a specific mobile communication device; and instructing the mobile communication device to change the memory device identification of its associated memory device from its present value to the received new value. Further, the server instructs the mobile communication device to return the previous value of the memory device identification of its associated memory device. Finally, the server will add the returned memory device identification value to the repository of memory device identifications.


