MIFARE Application Substitution via Secure Zone Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mechanisms for substituting MIFARE applications in microcircuit cards fail to allow replacement of applications from different suppliers due to the requirement for identical or shared keys and access data, which is impractical and insecure.
Innovation Solution
A method and device that utilize the key-set of a security domain to securely obtain and copy keys and access data from the current MIFARE application, enabling the substitution of one MIFARE application with another from a different supplier by using the current application's keys to write new keys and data into the MIFARE memory, while maintaining a secure and faithful image of the original application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional MIFARE substitution mechanisms are used, then application replacement is simple, but substitution between applications from different suppliers is impossible due to key compatibility requirements
Solution Approach 1:
The patent introduces a secure zone as an intermediary layer between the MIFARE memory and the substitution mechanism. This secure zone stores initialization keys that act as a mediator, allowing the system to bypass the key compatibility requirement between different MIFARE applications while maintaining security through controlled access to the substitution process
2Ease of operation
If MIFARE memory is made accessible for substitution, then application replacement is enabled, but security of the MIFARE card is compromised
Solution Approach 1:
The patent segments the memory system into two distinct parts: a secure zone that stores initialization keys and is accessible only during the substitution process, and the MIFARE memory that contains application data. This segmentation allows easy substitution operations while protecting the critical security elements in the secure zone from unauthorized access
Solution Approach 2:
The patent performs preliminary actions by storing initialization keys in the secure zone before any substitution operation occurs. These pre-stored keys are used to authenticate and control the substitution process, enabling easy application replacement while maintaining security through pre-established authentication mechanisms
Data Source
Figure 1~2
Figure 3
AI summary
The method involves obtaining current access data and key i.e. initialization key, protecting access to a MIFARE(RTM: contactless smartcard technology)memory (1340) from secured zones (1305, 1311). The current access data and key and an instruction are sent to a management application (1110) that manages the memory, such that the management application copies new access data and key of a MIFARE(RTM: contactless smartcard technology)application (1320) in the memory using the current access data and key. Independent claims are also included for the following: (1) a device for installing a contactless smartcard technology application in a contactless smartcard technology memory (2) a security domain comprising a contactless smartcard technology application (3) a computer program comprising instructions to execute a contactless smartcard technology application installation method (4) a recording medium comprising instructions to execute a contactless smartcard technology application installation method.