Security Module Activation Control via Date Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security modules lack a method to enable access to applications at a selectable point in time after delivery, risking misuse or premature activation, especially in scenarios requiring delayed activation.

Innovation Solution

A method that allows an authorized agency to release access to a security module's function by presenting a date, which is checked against a specified secret, ensuring the application remains in a delivery state until authorized, using either a stored secret or a module-specific secret derived from an identifier, and enabling access only upon successful verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the application is activated immediately upon delivery, then the user can use the security module without delay, but the risk of premature use or misuse increases

Engineering Contradiction:
Improveavailability of applicationVSAvoidsecurity against premature use
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The security module is prepared in advance with all necessary components (application, secret, identifier) but the application is kept in an inactive delivery state. The activation action is postponed until the authorized body presents the correct date, which matches the secret stored in the module. This preliminary preparation without immediate activation resolves the contradiction by enabling future availability while maintaining security during storage and transport.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the application is kept in delivery state until activation, then security against premature use is maintained, but the user cannot use the application before the activation point

Engineering Contradiction:
Improvesecurity against premature useVSAvoiddelay in application availability
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The date presentation mechanism acts as an intermediary between the authorized body and the application activation. The authorized body presents a date through an interface (manual entry or automated device), which is then verified against the secret stored in the module. This intermediary mechanism allows controlled activation at a precisely determined moment, eliminating unnecessary delays while maintaining security until activation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a secret verification mechanism is implemented, then access control is improved, but the device complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidactivation verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of implementing a complex cryptographic verification system, the patent uses a simplified copying approach: the same date value is stored as a secret in the security module and is also presented by the authorized body. The verification simply checks if the presented date matches the stored secret. This copying mechanism provides robust access control while keeping the device complexity minimal.

Inventive Principle:
Principle #26Copying

4Reliability

If module-specific secrets are used for each security module, then security is improved, but the manufacturing and configuration complexity increases

Engineering Contradiction:
Improvemodule-specific securityVSAvoidconfiguration of secrets
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent transforms the secret from a complex cryptographic key into a simple date parameter (day, month, year). This parameter change allows each security module to have a unique secret that can be easily configured during manufacturing by simply programming the activation date into the module's memory. The authorized body then presents the same date through their interface. This approach maintains module-specific security while dramatically simplifying the manufacturing and configuration process.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP1987466B1Method for securing authority over activation of applications within a security module
Publication Date: 2018.02.21 DEUTSCHE TELEKOM AG
  • EP1987466B1 patent drawingFigure 1
  • EP1987466B1 patent drawingFigure 2

AI summary

According to the invention, an application in a security module may be first activated in a simple manner, at a selectable time after provision of the security module to a user, by means of a method for activation of access to a given function (150) of a security module (100, 100') on initiation from an authorised point (200, 200'). The method comprises the preparation of a security module (100, 100'), presentation of a datum (G*) to the security module (100, 100'), checking the presented datum (G*) by the security module (100, 100'), depending on a given secret formula (G), and activation of access to the given function (150) by the security module (100, 100') only after successful checking of the presented datum (G*).