Secure Application Download via Encrypted Card Connector
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing smart card systems face security issues due to uncontrolled application installation and exposure of confidential data when card providers send application packets for processing, leading to safety and security concerns.
Innovation Solution
A method for safely downloading applications is implemented, ensuring application independence and security by using full-cipher text communication and controlled installation through a card activating operation, limiting card issuance times to prevent arbitrary downloads by intermediaries or customers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If the card provider sends application packets to customers or outside plants for processing, then the application installation can be completed, but confidential data set by the card provider is exposed to the outside
Solution Approach 1:
The patent performs preliminary actions by computing verification results and encrypting application packets before sending them to the card connector. The card connector then verifies and decrypts these pre-prepared packets, eliminating the need to send confidential data to outside plants for processing.
Solution Approach 2:
The card connector acts as an intermediary between the card provider and the smart card. It receives, verifies, and processes application packets locally without exposing confidential data to outside plants, thus mediating the installation process securely.
2Adaptability or versatility
If the card provider installs applications in the card, then all problems of management on applications are taken responsibility by the card provider, but safety problems result from exposing confidential data
Solution Approach 1:
The patent extracts the confidential data processing functions from the card provider and relocates them to the card connector. The card connector performs verification and decryption locally, taking out the harmful exposure of confidential data while maintaining application management capabilities.
3Ease of operation
If uncontrolled times of installation of the application are allowed, then more flexible installation is achieved, but security problems are incurred by repeated using
Solution Approach 1:
The patent implements a feedback mechanism through the activating instruction that limits the number of times an application can be installed. Each installation consumes one activation opportunity, providing feedback control that prevents unlimited repeated installations while maintaining flexible installation processes.
Data Source
AI summary
A method for safely downloading an application, including: after a successful mutual authentication of a card and a card connector, adopting an all-cipher text communication means, and controlling the number of installations of an application by a card activation operation, so as to realize secure downloading of the application. The present invention realizes all-cipher text communication of a card and a card connector, and the issuing frequency of the card is controllable; by means of such a method, the independence and security of the application can be ensured when issuing a card, while the issuing frequency of the card is limited, intermediaries and clients are prevented from arbitrarily downloading an application, and the security is relatively high.


