Portable Data Carrier Application Execution Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure execution of applications using portable data carriers are compromised by manipulation risks when external devices, such as personal computers, are not tamper-proof, especially during online transactions, leading to potential data falsification and unauthorized actions.

Innovation Solution

The method employs two different data channels for executing an application, where the first part is executed on one device and the second part is activated only after user confirmation on another device, using distinct interfaces and interfaces, enhancing security by requiring user intervention to prevent manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a tamper-proof portable data carrier is used to execute applications, then security against manipulation is improved, but the ability to use external devices for application execution is limited

Engineering Contradiction:
Improvesecurity against manipulationVSAvoidability to use external devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The application execution process is segmented into two distinct parts: the first part executes within the tamper-proof portable data carrier, while the second part executes on the external device. This segmentation allows the system to maintain security boundaries while enabling external device functionality, resolving the contradiction between security and versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The portable data carrier acts as an intermediary between the secure execution environment and the external device. It receives characteristic data from the first part execution, transmits it to the second part for external device execution, and requires user activation to bridge the two parts. This intermediary role enables external device usage while maintaining security through controlled data flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If external devices like personal computers are used to run applications, then functionality and adaptability are improved, but security against manipulation deteriorates due to viruses and Trojans

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity against manipulation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The application is divided such that the critical first part executes on the secure portable data carrier, while only the non-critical second part runs on the external device. This segmentation ensures that even if the external device is compromised by viruses or Trojans, the security-critical operations remain protected within the tamper-proof carrier.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements a feedback mechanism where the portable data carrier transmits characteristic data from the first part execution to the second part, and requires user activation confirmation. This feedback loop allows the user to verify data integrity before allowing external device execution, mitigating the risk of manipulation from external devices.

Inventive Principle:
Principle #23Feedback

3Reliability

If display units and confirmation devices are integrated into the portable data carrier, then security through user verification is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity through user verificationVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of integrating display and confirmation devices directly into the portable data carrier, the system uses the external device as an intermediary for user interaction. The portable data carrier transmits characteristic data to the external device for display and confirmation, eliminating the need for expensive integrated display hardware while maintaining security through user verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a functional copy of the user verification process by using the external device to display characteristic data and receive user confirmation. This copying approach allows the portable data carrier to maintain security verification functionality without physically integrating expensive display and confirmation hardware, reducing device complexity and cost.

Inventive Principle:
Principle #26Copying

4Reliability

If user activation is required for application execution, then security against unauthorized actions is improved, but operation time and complexity increase

Engineering Contradiction:
Improvesecurity against unauthorized actionsVSAvoidoperation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by executing the first part of the application within the portable data carrier before requiring user activation. Characteristic data is generated and transmitted in advance, so that when the user provides activation confirmation, the critical security operations have already been completed, minimizing the time window for potential manipulation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2393032B1Method for running an application with the help of a portable data storage device
Publication Date: 2020.04.22 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2393032B1 patent drawingFigure 1

AI summary

The method involves forming data links with personal computer (2) and portable radio telephone (3) over interfaces (5, 6) of a portable data medium e.g. smart card (1) or token. Known data provided with execution of a part of an application e.g. homebanking application, are transmitted to the portable radio telephone by the portable data medium over one of the interfaces. Another part of the application is implemented according to a connection by a user. The latter part of the application is executed with the known data provided by the former part of the application.