Secure Data Carrier Update via Proxy Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for updating data carriers, such as secure SIM cards and SD cards, are limited in allowing new data carrier applications to be installed or access rights to be updated without compromising security, especially when new terminal applications are installed on telecommunications terminals.
Innovation Solution
A method that uses a programming interface as a proxy server to securely update data carriers by enabling communication between the security application and data carrier management, allowing for the installation of new data carrier applications and updating access rights without direct interaction with the security application, thereby ensuring secure and versatile updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless data communication via air interface is used to update data carrier, then data carrier can be updated remotely, but data security is compromised and user confidence is shaken
Solution Approach 1:
The patent introduces a proxy server as an intermediary component that mediates between the security application and the programming interface. This proxy server enables indirect communication paths that maintain security protocols while allowing necessary data updates. The proxy server acts as a trusted intermediary that verifies and controls the update process, preventing direct unauthorized access while enabling legitimate remote updates through controlled channels.
2Reliability
If access rights management system is provided for data carrier applications, then security of confidential data is improved, but new terminal applications cannot access data carrier applications
Solution Approach 1:
The patent implements dynamic access right management where access permissions are not fixed but can be updated and modified. The system allows access rights to be dynamically assigned to new terminal applications through the update mechanism. This dynamic approach enables the security system to adapt to new applications while maintaining protection, resolving the contradiction between static security constraints and dynamic accessibility requirements.
Solution Approach 2:
The patent employs preliminary action by pre-configuring the data carrier with update capabilities and proxy server infrastructure before new terminal applications are installed. This preliminary setup allows the system to anticipate and accommodate future access requests without compromising existing security. The access rights management system is prepared in advance to handle dynamic updates, enabling both security and adaptability from the outset.
3Adaptability or versatility
If data carrier is updated with new applications or access rights, then functionality is enhanced, but security risks increase from potential unauthorized software
Solution Approach 1:
The proxy server serves as a security intermediary that filters and validates all update data before it reaches the data carrier. This intermediary layer checks the authenticity and integrity of update packages, blocking unauthorized software while allowing legitimate updates. The proxy server mediates between the external update source and the secure data carrier environment, enabling functionality enhancement while maintaining security barriers.
Solution Approach 2:
The system implements feedback mechanisms where the security application and proxy server continuously monitor and verify update processes. Authentication feedback loops ensure that only verified updates are applied, and any suspicious activity triggers security protocols. This feedback-driven approach allows the system to enhance functionality through updates while maintaining real-time security validation to prevent unauthorized software installation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for updating a data storage medium inserted in a telecommunications terminal with regard to a data carrier application which can be executed in the data storage medium, comprising the steps of: providing updating data to a security application installed in the data storage medium; updating of the data storage medium according to the updating data, updating the data storage medium comprising the steps of: transmitting at least a part of the updating data from the security application to a programming interface installed in the telecommunications terminal and designed to communicate between the telecommunications terminal and the data storage medium; forwarding the transmitted updating data from the programming interface to a data storage medium manager for the data storage medium installed in the data storage medium; updating the data storage medium according to the forwarded updating data.