Portable Data Carrier Attack Detection via Time-Based Error Criteria

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing portable data carriers struggle to differentiate between true attack error events and random error events, such as those caused by aging processes or environmental factors, leading to indiscriminate protective measures.

Innovation Solution

A method that employs time-based attack error criteria to distinguish between attack and random error events by monitoring the frequency and timing of error events, using an error counter to register events only if they meet specific criteria, such as a short restart period or error period, thereby differentiating between intentional manipulation and random occurrences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an error counter is used to detect all error events, then attack error events can be detected, but random error events cause false positives leading to unnecessary protective measures

Engineering Contradiction:
Improveattack detection capabilityVSAvoiderror event classification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments error events into two distinct categories: attack error events and random error events. This is achieved by implementing separate error counters (attack error counter and random error counter) that independently track different types of errors. The segmentation allows the system to apply differentiated protective measures based on the specific error type detected, thereby improving classification accuracy while maintaining reliable attack detection.

Inventive Principle:
Principle #1Segmentation

2Reliability

If protective measures are initiated for all error events, then security is enhanced, but legitimate operations are disrupted due to random errors

Engineering Contradiction:
Improvedata carrier securityVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing differentiated protective measures tailored to the specific type of error detected. For attack error events, stringent protective measures such as blocking or resetting the data carrier are applied. For random error events, milder measures or no protective measures are taken, allowing legitimate operations to continue uninterrupted. This localized approach to security ensures that protective actions are precisely matched to the actual threat level.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If the error counter has a long retention period, then random errors can be distinguished from attacks, but attack detection responsiveness is reduced

Engineering Contradiction:
Improveerror pattern discriminationVSAvoidattack detection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent implements dynamics by configuring error counters with different retention periods based on the type of error they track. The attack error counter uses a shorter retention period to enable rapid detection and response to attack attempts. The random error counter uses a longer retention period to accumulate sufficient data for accurate discrimination of random errors from attacks. This dynamic configuration allows the system to optimize both detection speed and discrimination precision simultaneously.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2689373B1Detecting attacks on a portable data carrier
Publication Date: 2015.09.02 GIESECKEDEVRIENT IP
  • EP2689373B1 patent drawingFigure 1
  • EP2689373B1 patent drawingFigure 2
  • EP2689373B1 patent drawingFigure 3

AI summary

The invention relates to a method that can be implemented in a portable data carrier (1) for detecting attacks on the data carrier (1), wherein an error event is detected in the data carrier (1) (S2) and registered (S15) by means of an error counter (14). Protective measures (S6, S17) are introduced as a function of the counter level of the error counter (14). The error event (S2), however, is thereby registered as an attack error event (S15) by means of an attack error counter (14) if at least one time-based attack error criterion (A, B) is met (S11, S4). The error event (S2) is registered as an attack error event (S15) if a prescribed reboot time span (TR) indicating the time span between the last reboot (S8) of the data carrier (1) and the prior reset (S7) of the data carrier (1) due to the error event (S2) is not met (S11), or if a prescribed error time span indicating the time span between the last reboot (S8) of the data carrier (1) and the detected error event (S2) is not met (S4).