Secure Operating System Replacement in Limited-Resource Identification Documents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing technologies for machine-readable electronic identification documents do not provide a method for securely replacing the operating system in the field, especially for documents with extended lifetimes, leading to potential functional failures or premature replacement with significant costs.
Innovation Solution
A method that allows the operating system of a chip in a machine-readable electronic identification document to be replaced securely in the field by utilizing non-volatile overwritable memory, such as flash memory, and introducing a new terminal certificate with a loading key to ensure only original software is installed, while retaining stored personal data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the operating system is stored in ROM-memory, then the security and stability of the electronic identification document is improved, but the ability to update the operating system is lost and the document must be replaced after a few years
Solution Approach 1:
The patent segments the memory into two distinct parts: ROM-memory for storing the bootstrap loader and critical security data, and overwritable non-volatile memory for storing the operating system. This segmentation allows the bootstrap loader to remain secure and immutable while the operating system can be updated independently, resolving the contradiction between stability and updatability.
Solution Approach 2:
The patent implements a preliminary action by storing a bootstrap loader in ROM-memory during manufacturing that can independently verify and load operating system versions. This preliminary security mechanism enables future operating system updates while maintaining the security foundation, allowing the system to adapt without compromising reliability.
2Adaptability or versatility
If a new card generation is issued to replace identification documents, then the operating system can be updated, but considerable costs are incurred and personal data must be migrated
Solution Approach 1:
The patent extracts the operating system from the immutable ROM-memory and places it in overwritable non-volatile memory, while keeping the bootstrap loader and personal data in ROM-memory. This extraction allows the operating system to be updated independently without requiring physical card replacement, eliminating the costs and effort associated with issuing new cards.
Solution Approach 2:
The patent enables discarding of outdated operating system versions and recovering of the updated version through in-field updates. The personal data is preserved and recovered in the process, while the operating system can be replaced without physical card replacement, significantly reducing costs and effort compared to issuing new cards.
3Adaptability or versatility
If the operating system is stored in overwritable non-volatile memory, then the operating system can be updated in the field, but the security risk of unauthorized changes increases
Solution Approach 1:
The patent introduces a bootstrap loader as an intermediary between the external environment and the operating system. This intermediary verifies the authenticity of incoming operating system updates and controls the loading process, enabling in-field updates while preventing unauthorized changes. The bootstrap loader acts as a security gatekeeper that mediates between update capability and security protection.
Solution Approach 2:
The patent implements preliminary verification actions through the bootstrap loader that checks the authenticity and integrity of operating system updates before loading them into the overwritable memory. This preliminary security check prevents unauthorized changes while allowing legitimate updates, resolving the contradiction between update capability and security protection.
Data Source
AI summary
A method for replacing the operating software of a limited-resource portable data carrier at a terminal includes controlling the operation of the data carrier and executing at least one function provided by the data carrier. The terminal includes new operating software, a bootstrap loader for loading new operating software, and a terminal certificate providing authorization for transmitting a loading key. In authentication of the terminal, the terminal certificate is transmitted to the data carrier and verified there and a loading key is transmitted to the data carrier. The operation control of the data carrier changes over to the bootstrap loader which deletes the present operating software of the data carrier and transmits the new operating software using the loading key from the terminal. The new operating software is then verified and activated by the bootstrap loader which transfers the control of the data carrier to the new operating software.


