Smart Card Access Rights Management via Event Validation Register

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access rights management systems for smart cards are complex, occupying significant memory space and resulting in lengthy execution times due to multiple conditions and varying requirements for different commands and communication methods, such as electrical contact versus wireless connections.

Innovation Solution

A method for managing access rights that uses a logical combination of events, where each event's validation status is stored in a security status register, allowing for rapid evaluation by encoding commands and events into binary words, reducing memory usage and execution time through efficient data recording and processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional access rights management programs are used with multiple conditions for different commands and communication methods, then operational security is maintained, but memory space consumption increases significantly

Engineering Contradiction:
Improveoperational securityVSAvoidmemory space consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The access rights management program segments security conditions into distinct event types (authentication events, channel establishment events, etc.), each represented by a unique identifier. This segmentation allows the system to store only the essential event IDs rather than complete condition descriptions, significantly reducing memory consumption while maintaining security functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the core security validation logic from the access rights management program, separating it into independent event validation components. By extracting authentication and channel establishment validations into distinct event handlers, the system reduces the complexity and memory footprint of the overall rights management program.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If traditional access rights management programs with multiple conditions are used, then security is maintained, but execution time increases

Engineering Contradiction:
ImprovesecurityVSAvoidexecution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary validation by pre-defining event identifiers and their corresponding security conditions. When a command is executed, the system first checks whether the required event has been previously validated and recorded in the security status register, avoiding redundant condition evaluations and significantly reducing execution time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access rights management program uses feedback from the security status register, which records the validation status of events. This feedback mechanism allows the system to quickly determine whether security conditions are met without re-evaluating all conditions, thereby reducing execution time while preserving security integrity.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If detailed access rights are stored for each file with multiple conditions, then access control precision is improved, but the complexity of the rights management system increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidrights management system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning specific event identifiers to different security conditions for different files and commands. Each file can have its own customized event requirements (e.g., PIN authentication for sensitive files, channel establishment for wireless operations), allowing precise access control without requiring a complex centralized rights management structure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2210209B1Method for managing access rights in a smart card
Publication Date: 2017.09.27 IDEMIA IDENTITY & SECURITY FRANCE SAS
  • EP2210209B1 patent drawingFigure 1~3

AI summary

The invention relates to a method for managing access rights in a smart card, so that the execution of a control (Cmd1, Cmdk), such as reading or writing, depends on the validation of an event (Evt1', Evtk'), such as an authentication by code checking. The event validation state is stored into a register, and the access rights are stored in a control list (List_Cmd) including pairs (CpI1, CpIk) each associating a control with an event. Upon reception of a control execution request, the method comprises searching the pair (CpI1, CpIk) including the requested control in the control list (List_Cmd), and rejecting the execution in case of an unsuccessful search. In case of a successful search, the method comprises determining, from the register (or so-called card security check register), whether or not the event associated with the control is validated or not in order to authorise or reject the execution. The invention is intended for any smart card application that uses access rights.