Security Module Activation Control via Date Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security modules lack a method to enable access to applications at a selectable point in time after delivery, risking misuse or premature activation, especially in scenarios requiring delayed activation.
Innovation Solution
A method that allows an authorized agency to release access to a security module's function by presenting a date, which is checked against a specified secret, ensuring the application remains in a delivery state until authorized, using either a stored secret or a module-specific secret derived from an identifier, and enabling access only upon successful verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the application is activated immediately upon delivery, then the user can use the security module without delay, but the risk of premature use or misuse increases
Solution Approach 1:
The security module is prepared in advance with all necessary components (application, secret, identifier) but the application is kept in an inactive delivery state. The activation action is postponed until the authorized body presents the correct date, which matches the secret stored in the module. This preliminary preparation without immediate activation resolves the contradiction by enabling future availability while maintaining security during storage and transport.
2Reliability
If the application is kept in delivery state until activation, then security against premature use is maintained, but the user cannot use the application before the activation point
Solution Approach 1:
The date presentation mechanism acts as an intermediary between the authorized body and the application activation. The authorized body presents a date through an interface (manual entry or automated device), which is then verified against the secret stored in the module. This intermediary mechanism allows controlled activation at a precisely determined moment, eliminating unnecessary delays while maintaining security until activation.
3Reliability
If a secret verification mechanism is implemented, then access control is improved, but the device complexity increases
Solution Approach 1:
Instead of implementing a complex cryptographic verification system, the patent uses a simplified copying approach: the same date value is stored as a secret in the security module and is also presented by the authorized body. The verification simply checks if the presented date matches the stored secret. This copying mechanism provides robust access control while keeping the device complexity minimal.
4Reliability
If module-specific secrets are used for each security module, then security is improved, but the manufacturing and configuration complexity increases
Solution Approach 1:
The patent transforms the secret from a complex cryptographic key into a simple date parameter (day, month, year). This parameter change allows each security module to have a unique secret that can be easily configured during manufacturing by simply programming the activation date into the module's memory. The authorized body then presents the same date through their interface. This approach maintains module-specific security while dramatically simplifying the manufacturing and configuration process.
Data Source
Figure 1
Figure 2
AI summary
According to the invention, an application in a security module may be first activated in a simple manner, at a selectable time after provision of the security module to a user, by means of a method for activation of access to a given function (150) of a security module (100, 100') on initiation from an authorised point (200, 200'). The method comprises the preparation of a security module (100, 100'), presentation of a datum (G*) to the security module (100, 100'), checking the presented datum (G*) by the security module (100, 100'), depending on a given secret formula (G), and activation of access to the given function (150) by the security module (100, 100') only after successful checking of the presented datum (G*).