Smart Card Access Rights Management via Event Validation Register
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access rights management systems for smart cards are complex, occupying significant memory space and resulting in lengthy execution times due to multiple conditions and varying requirements for different commands and communication methods, such as electrical contact versus wireless connections.
Innovation Solution
A method for managing access rights that uses a logical combination of events, where each event's validation status is stored in a security status register, allowing for rapid evaluation by encoding commands and events into binary words, reducing memory usage and execution time through efficient data recording and processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access rights management programs are used with multiple conditions for different commands and communication methods, then operational security is maintained, but memory space consumption increases significantly
Solution Approach 1:
The access rights management program segments security conditions into distinct event types (authentication events, channel establishment events, etc.), each represented by a unique identifier. This segmentation allows the system to store only the essential event IDs rather than complete condition descriptions, significantly reducing memory consumption while maintaining security functionality.
Solution Approach 2:
The patent extracts the core security validation logic from the access rights management program, separating it into independent event validation components. By extracting authentication and channel establishment validations into distinct event handlers, the system reduces the complexity and memory footprint of the overall rights management program.
2Reliability
If traditional access rights management programs with multiple conditions are used, then security is maintained, but execution time increases
Solution Approach 1:
The system performs preliminary validation by pre-defining event identifiers and their corresponding security conditions. When a command is executed, the system first checks whether the required event has been previously validated and recorded in the security status register, avoiding redundant condition evaluations and significantly reducing execution time while maintaining security.
Solution Approach 2:
The access rights management program uses feedback from the security status register, which records the validation status of events. This feedback mechanism allows the system to quickly determine whether security conditions are met without re-evaluating all conditions, thereby reducing execution time while preserving security integrity.
3Measurement precision
If detailed access rights are stored for each file with multiple conditions, then access control precision is improved, but the complexity of the rights management system increases
Solution Approach 1:
The patent applies local quality by assigning specific event identifiers to different security conditions for different files and commands. Each file can have its own customized event requirements (e.g., PIN authentication for sensitive files, channel establishment for wireless operations), allowing precise access control without requiring a complex centralized rights management structure.
Data Source
Figure 1~3
AI summary
The invention relates to a method for managing access rights in a smart card, so that the execution of a control (Cmd1, Cmdk), such as reading or writing, depends on the validation of an event (Evt1', Evtk'), such as an authentication by code checking. The event validation state is stored into a register, and the access rights are stored in a control list (List_Cmd) including pairs (CpI1, CpIk) each associating a control with an event. Upon reception of a control execution request, the method comprises searching the pair (CpI1, CpIk) including the requested control in the control list (List_Cmd), and rejecting the execution in case of an unsuccessful search. In case of a successful search, the method comprises determining, from the register (or so-called card security check register), whether or not the event associated with the control is validated or not in order to authorise or reject the execution. The invention is intended for any smart card application that uses access rights.