Secure Access Module Operation Range Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure access modules (SAMs) used in smart cards are vulnerable to unauthorized use due to loss or robbery, compromising transaction security both online and offline.

Innovation Solution

A secure access system that includes a management server, terminal, and secure access module (SAM), where the management server sets and registers an operation parameter for the SAM, allowing it to operate within a permissible range, and if the SAM is used outside this range, it sends an authentication request to the management server to update the parameter, ensuring authorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the SAM allows offline transactions without strict authentication, then transaction convenience is improved, but security against unauthorized use deteriorates

Engineering Contradiction:
Improvetransaction convenienceVSAvoidsecurity against unauthorized use
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The management server performs preliminary authentication and sets operation parameters (including counter limits and time windows) before the SAM engages in offline transactions. This preliminary action establishes security boundaries that allow convenient offline operation while preventing unauthorized use, as the SAM can only operate within pre-approved parameters.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the SAM monitors its own operation counter and compares it against authorized limits. When the counter reaches threshold values or time windows expire, the SAM automatically seeks online authentication from the management server. This feedback loop maintains security while enabling offline operation within safe boundaries.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the SAM operates without operation parameter limits, then transaction flexibility is improved, but vulnerability to loss or robbery deteriorates

Engineering Contradiction:
Improvetransaction flexibilityVSAvoidvulnerability to loss or robbery
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The management server dynamically changes operational parameters (counter limits, time windows, transaction thresholds) based on authentication results and risk assessment. These parameter changes allow the SAM to be flexible within authorized boundaries while preventing excessive use that could indicate theft or loss. The parameters are adjusted without physical replacement of the SAM module.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The operation parameters are made dynamic rather than static. The counter limits and time windows can be adjusted by the management server based on ongoing authentication, allowing the system to adapt to changing conditions. This dynamic approach provides flexibility for legitimate users while automatically restricting compromised modules.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the SAM requires frequent online authentication, then security is improved, but transaction efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidtransaction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of requiring continuous online authentication, the system uses periodic authentication at predetermined intervals or when counter thresholds are reached. The management server authenticates the SAM periodically and updates operation parameters, allowing multiple offline transactions between authentication events. This periodic approach maintains security while minimizing online connectivity requirements.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The management server performs authentication and parameter setting in advance before offline transaction periods begin. This preliminary authentication establishes a window of authorized operation that doesn't require continuous online presence, improving transaction efficiency while maintaining security through pre-validated credentials and parameter limits.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2953078B1Secure access system and operating method method thereof
Publication Date: 2018.07.11 LG CNS CO LTD
  • EP2953078B1 patent drawingFigure 1
  • EP2953078B1 patent drawingFigure 2
  • EP2953078B1 patent drawingFigure 3

AI summary

A method of operating a secure access module (SAM) includes receiving an operation parameter via a terminal from a management server, the operation parameter including a registered value indicating a permissible range for operation of the SAM, receiving an authentication request for providing a card-related service from the terminal when a corresponding card is coupled to the terminal, determining whether the SAM is within the permissible range for operation in response to the authentication request, and transmitting information on a determination result to the terminal.