Partial Randomization ID Authentication for IC Card Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In non-contact communication systems, the leakage of unique IDs from IC cards poses a risk of unauthorized identification tracking, as they need to be notified to the reader/writer, making it difficult to prevent their exposure even when degenerate keys are individualized.

Innovation Solution

A processor-based system that determines whether a target ID is unique or partially randomized, generating an access key using a second part of the partial randomization ID based on the unique ID, to execute mutual authentication and prevent ID leakage, by using a communication section and memory device storing instructions for this process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the unique ID is notified to the reader/writer for mutual authentication, then the authentication process can be completed, but the unique ID may be leaked to third parties enabling unauthorized tracking

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidID leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a degenerate key as an intermediary element that replaces the direct use of unique ID in authentication. The degenerate key is generated by applying a one-way function to the unique ID, allowing authentication to proceed without exposing the actual unique ID to the reader/writer or third parties

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the identification function from the unique ID itself and separates it into a derived degenerate key. This extraction allows the authentication system to use only the necessary derived information while keeping the sensitive unique ID concealed and secure within the IC card

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of time

If a common degenerate key is used for multiple services, then the mutual authentication process time is reduced, but the security risk increases if the key is leaked

Engineering Contradiction:
Improveauthentication timeVSAvoidkey security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent segments the authentication system by creating service-specific degenerate keys derived from the common unique ID. Each service has its own degenerate key, allowing efficient authentication while isolating security risks to individual services rather than compromising the entire system if one key is compromised

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of the degenerate key from a common shared key to individualized service-specific keys. This is achieved by applying different service identifiers or random values to the base degenerate key derivation process, maintaining the one-way function property while creating unique keys for each service

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8677137B2Communication device, communication method, information processing device, information processing method, program, and communication system
Publication Date: 2014.03.18 SONY GROUP CORP
  • US8677137B2 patent drawing
  • US8677137B2 patent drawing
  • US8677137B2 patent drawing

AI summary

In one example embodiment, an information processing apparatus determines whether a target ID is a unique ID or a partial randomization ID that includes a first part being replaced by a different number and a second part being generated based on the unique ID. In response to the target ID being the partial randomization ID, the information processing apparatus generates an access key based on the second part of the partial randomization ID and a key. The information processing apparatus executes a mutual authentication process using the generated access key.