Secure Application Download via Encrypted Card Connector

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing smart card systems face security issues due to uncontrolled application installation and exposure of confidential data when card providers send application packets for processing, leading to safety and security concerns.

Innovation Solution

A method for safely downloading applications is implemented, ensuring application independence and security by using full-cipher text communication and controlled installation through a card activating operation, limiting card issuance times to prevent arbitrary downloads by intermediaries or customers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If the card provider sends application packets to customers or outside plants for processing, then the application installation can be completed, but confidential data set by the card provider is exposed to the outside

Engineering Contradiction:
Improveapplication installationVSAvoidconfidential data exposure
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary actions by computing verification results and encrypting application packets before sending them to the card connector. The card connector then verifies and decrypts these pre-prepared packets, eliminating the need to send confidential data to outside plants for processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The card connector acts as an intermediary between the card provider and the smart card. It receives, verifies, and processes application packets locally without exposing confidential data to outside plants, thus mediating the installation process securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the card provider installs applications in the card, then all problems of management on applications are taken responsibility by the card provider, but safety problems result from exposing confidential data

Engineering Contradiction:
Improveapplication management responsibilityVSAvoidsafety of confidential data
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the confidential data processing functions from the card provider and relocates them to the card connector. The card connector performs verification and decryption locally, taking out the harmful exposure of confidential data while maintaining application management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If uncontrolled times of installation of the application are allowed, then more flexible installation is achieved, but security problems are incurred by repeated using

Engineering Contradiction:
Improveinstallation flexibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism through the activating instruction that limits the number of times an application can be installed. Each installation consumes one activation opportunity, providing feedback control that prevents unlimited repeated installations while maintaining flexible installation processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9182967B2Method for safely downloading application
Publication Date: 2015.11.10 FEITIAN TECHNOLOGIES CO LTD
  • US9182967B2 patent drawing
  • US9182967B2 patent drawing
  • US9182967B2 patent drawing

AI summary

A method for safely downloading an application, including: after a successful mutual authentication of a card and a card connector, adopting an all-cipher text communication means, and controlling the number of installations of an application by a card activation operation, so as to realize secure downloading of the application. The present invention realizes all-cipher text communication of a card and a card connector, and the issuing frequency of the card is controllable; by means of such a method, the independence and security of the application can be ensured when issuing a card, while the issuing frequency of the card is limited, intermediaries and clients are prevented from arbitrarily downloading an application, and the security is relatively high.