Security Module Attack Counter Reset via Terminal Time Base

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security modules, such as SIM cards, face challenges in accurately distinguishing between error events caused by manipulation attempts and those occurring randomly or as part of normal operation, due to the difficulty in providing a reliable time base for categorizing attacks, especially in autonomous structures without a power supply.

Innovation Solution

A method is introduced to create a time base using a recurring structure signal, like the AUTHENTICATE command, transmitted via a secure end-to-end connection, allowing for accurate resetting of the attack counter and differentiation between malicious and accidental events, thereby reducing unnecessary protective measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a time base is provided using capacitive elements for attack categorization, then attack classification capability is improved, but device complexity increases and the security module becomes vulnerable to charge state disruption attacks

Engineering Contradiction:
Improveattack classification accuracyVSAvoidcharge retention unit complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary approach by using the attack detection mechanism and attack counter as mediators between the error events and the security response. Instead of relying on a complex time base with capacitive elements, the system uses the attack counter incremented by the detection mechanism to categorize attacks, simplifying the device structure while maintaining security functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the time base functionality from the security module itself and relocates it to the terminal device. The terminal device's internal clock or time-keeping mechanism serves as the time base, eliminating the need for complex capacitive elements within the security module while still enabling attack categorization based on timing information.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the attack counter limit is set low for security, then security protection is improved, but false positives from random errors increase unnecessary protective measures

Engineering Contradiction:
Improvesecurity protection levelVSAvoidfalse positive protective measures
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements feedback by using the terminal device's time base to provide timing information back to the security module. This timing feedback allows the system to distinguish between rapid successive errors (potential attacks) and errors spaced over longer periods (likely random), enabling more accurate attack categorization without requiring an excessively low attack counter limit.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces dynamic attack counter limits that can be adjusted based on the timing of error events. Instead of a fixed low limit that triggers false positives, the system dynamically evaluates the time intervals between errors using the terminal's time base, allowing the effective limit to adapt to the observed error pattern and reduce false protective measures.

Inventive Principle:
Principle #15Dynamics

3Object-generated harmful factors

If the attack counter limit is set high to avoid false positives, then false positive reduction is improved, but security buffer is reduced and response to real attacks is delayed

Engineering Contradiction:
Improvefalse positive reductionVSAvoidsecurity buffer
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The timing feedback from the terminal device enables the system to maintain a reasonable attack counter limit while reducing false positives through intelligent categorization. By analyzing the time intervals between errors, the system can confidently trigger protective measures at lower counter values when errors occur in rapid succession, maintaining security buffer without excessive false positives.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If autonomous time base is implemented in security module, then attack categorization accuracy is improved, but vulnerability to time base manipulation attacks increases

Engineering Contradiction:
Improveerror event timing accuracyVSAvoidtime base manipulation vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent uses the terminal device as an intermediary to provide the time base functionality. Instead of implementing an autonomous time base within the security module that could be manipulated, the system leverages the terminal's established time-keeping mechanism, which serves as a trusted intermediary that eliminates the vulnerability while maintaining timing accuracy for attack categorization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2793161B1Method for classifying an attack on a security module
Publication Date: 2017.12.20 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2793161B1 patent drawingFigure 1
  • EP2793161B1 patent drawingFigure 2

AI summary

A method is proposed for resetting an attack counter (10) in a security module (1) without its own continuous power supply. This module performs data exchange with an end device (40) and processes at least one direct signal transmitted by a network operating system (60). The following steps are performed: the operation of the security module (1) is monitored for fault events. If a fault event is detected, the attack counter (10) is incremented, and protective measures are initiated when a limit value is reached. Furthermore, the input of a specific structured signal from a network operating system (60) is monitored, and a reference counter (11) is incremented upon receipt of such a signal. If the reference counter (11) reaches a threshold value and the attack counter (10) has not yet exceeded a limit value, the attack counter (10) is reset to an initial value.