Smart Card Certificate Hash Storage for Upgrade Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart cards require complex operations to initialize certificates for new purposes, and existing systems face issues when certificate information is deleted during device upgrades, necessitating user intervention and manual re-initialization.

Innovation Solution

A computerized device method to select and import certificates from a smart card, calculate and store hashes for certificate verification, allowing continued use even if the original certificate is deleted, ensuring seamless operation without dedicated personnel intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a smart card is initialized with certificates for specific purposes using dedicated equipment and personnel, then the certificate initialization is secure and reliable, but the process becomes complex and requires specialized intervention

Engineering Contradiction:
Improvecertificate initialization reliabilityVSAvoidinitialization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to autonomously select and import certificates from their smart cards without requiring dedicated personnel or complex initialization procedures. The computerized device automatically manages certificate selection, import, and hash storage, allowing users to perform certificate operations independently.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates hash copies of certificates for verification purposes. Instead of requiring the original certificate to remain on the device, the system stores hash values that can verify certificate authenticity, enabling certificate replacement after import while maintaining security verification capabilities.

Inventive Principle:
Principle #26Copying

2Loss of substance

If certificate information is deleted during device upgrades, then device storage is optimized, but the certificate functionality is lost and requires manual re-initialization

Engineering Contradiction:
Improvecertificate data retentionVSAvoidcertificate re-initialization efficiency
Core Design Contradiction:
Loss of substanceVSProductivity

Solution Approach 1:

The system performs preliminary import of certificates from the smart card to the computerized device before device upgrades occur. By having the certificate already imported and its hash stored locally, the system ensures certificate functionality is preserved through upgrades without requiring re-initialization, as the imported certificate and its verification hash remain available.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates and stores hash copies of certificates locally on the device. These hash copies serve as verification tokens that persist through device upgrades, allowing the system to verify certificate authenticity even if the original smart card certificate is deleted or unavailable after an upgrade.

Inventive Principle:
Principle #26Copying

3Reliability

If the entire certificate is stored in the computerized device, then certificate verification is straightforward, but storage space is consumed and security risks increase

Engineering Contradiction:
Improvecertificate verification reliabilityVSAvoiddevice storage consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system extracts only the essential verification component (the hash value) from the complete certificate and stores it locally. This extracted hash serves as a compact verification token that confirms certificate authenticity without requiring storage of the entire certificate data, significantly reducing storage consumption while maintaining verification reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates hash copies of the certificate as a compact representation. Instead of storing the full certificate data, the system stores these condensed hash copies that occupy minimal storage space but provide sufficient information for verifying certificate authenticity and integrity.

Inventive Principle:
Principle #26Copying

4Reliability

If dedicated personnel are required for certificate initialization, then security control is maintained, but user autonomy and operational efficiency are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoiduser autonomy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system empowers users to independently perform certificate selection, import, and verification operations without requiring dedicated personnel. The computerized device provides automated guidance and execution of certificate operations, maintaining security through automated hash verification while fully enabling user autonomy and eliminating the need for specialized personnel intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements automated feedback mechanisms where the computerized device verifies certificate imports by comparing hashes and providing confirmation to the user. This automated feedback loop maintains security control by verifying certificate authenticity while enabling user autonomy, as users receive immediate verification results without requiring personnel review.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP1890270B1Hash of a certificate imported from a smart card
Publication Date: 2012.06.13 BLACKBERRY LTD
  • EP1890270B1 patent drawingFigure 1~3
  • EP1890270B1 patent drawingFigure 4
  • EP1890270B1 patent drawingFigure 5

AI summary

A certificate (420) from a smart card (102, 400) is imported into a computerized device (108, 200) via a smart card reader (104, 300). The computerized device (108, 200) calculates a hash (234) of the imported certificate and stores the hash (234) in memory (206). The hash (234) may be stored in a region of the memory (206) that is unaffected by upgrades to the device (108, 200).