Secure Application Transfer via Dual Cryptographic Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to ensure secure transfer and utilization of applications from a server to untrustworthy reading devices, lacking effective authentication and encryption mechanisms.
Innovation Solution
Establishing a first cryptographically secured channel between a data carrier unit and a server, and a second between a security module of the reading device unit and the server, using cryptographic information such as access data, passwords, or PINs, to facilitate secure application transfer and installation, with optional user personalization before or after installation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application transfer is performed over standard communication channels, then transfer simplicity is maintained, but security is compromised on untrustworthy devices
Solution Approach 1:
The patent segments the authentication process into two distinct cryptographic channels: a first secure channel between the data carrier unit and server for user authentication, and a second secure channel between the security module and server for application transfer. This segmentation allows each channel to be optimized for its specific purpose while maintaining overall system security without requiring the entire system to be untrusted.
Solution Approach 2:
The patent introduces a data carrier unit as an intermediary between the user and the server. This intermediary contains a security module that establishes cryptographically secured channels, acting as a trusted mediator that enables secure application transfer even when the reading device or communication channel cannot be fully trusted.
2Reliability
If cryptographic authentication is implemented, then security is improved, but authentication complexity increases
Solution Approach 1:
The patent implements self-service authentication where the data carrier unit autonomously establishes the first cryptographically secured channel with the server using stored cryptographic information. The user simply needs to provide access data to the data carrier unit, while the complex cryptographic negotiations and channel establishment occur automatically without user intervention.
3Adaptability or versatility
If application is transferred to untrustworthy device, then device accessibility is improved, but application security is compromised
Solution Approach 1:
The patent extracts the security-critical functions (authentication and application transfer) from the untrustworthy reading device and relocates them to the trusted data carrier unit and server. The reading device is reduced to a simple interface for initiating the transfer, while the actual secure operations occur in the trusted environment of the data carrier unit and server.
Data Source
AI summary
A method and a system for secure transfer of an application from a server (S) into a reading device unit (2) with authentication of a user with a data carrier unit (1), the server (S) making available the application, wherein, between the data carrier unit (1) and the server (S), a first cryptographically secured channel (K1) is set up based on first cryptographic information (A), and between a security module (3) of the reading device unit (2) and the server (S) a second cryptographically secured channel (K2) is set up based on second cryptographic information (B). The application is transferred from the server to the reading device unit via the second cryptographically secured channel (K2).


