Smart Card Chip Personalization via Master Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for personalizing security elements in mobile terminal devices, such as smart card chips, face challenges in securely pre-personalizing chips in an insecure environment without transmitting personal data to the manufacturer, and require significant administrative effort from both network operators and chip manufacturers.
Innovation Solution
A method that involves pre-personalizing the security element during production by determining a unique master key, which is then transmitted to a trust center, and finalizing personalization when the device is used for the first time by linking the user's personal data with the master key to personalize the security element, eliminating the need for conventional methods that require secure production sites and reducing administrative burdens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If personalization data is transmitted to the chip manufacturer during pre-personalization, then the personalization process can be completed, but security is compromised because personal data is handled in an insecure environment
Solution Approach 1:
The personalization data is segmented into two parts: a first part is transmitted to the chip manufacturer during pre-personalization, while a second part remains at the network operator. This segmentation allows pre-personalization to proceed without compromising security, as the complete personalization data never resides in the insecure manufacturing environment.
Solution Approach 2:
The chip acts as an intermediary that receives the first part of personalization data during manufacturing and later combines it with the second part provided by the user during final personalization. This intermediary role enables the chip to facilitate personalization without requiring the manufacturer to handle complete personalization data.
2Extent of automation
If the chip manufacturer manages all personalization data, then pre-personalization can be fully automated, but administrative effort and complexity increase significantly
Solution Approach 1:
The second part of the personalization data is extracted from the manufacturer's responsibility and kept at the network operator. This extraction reduces the administrative burden on the manufacturer, as they only need to manage the first part of the data and the pre-personalization process, while final personalization is completed by the user with assistance from the network operator.
3Reliability
If secure production sites are used for personalization, then security is maintained, but manufacturing flexibility and cost-effectiveness are reduced
Solution Approach 1:
The chip is pre-personalized with the first part of personalization data during standard manufacturing processes at regular production sites, not secure facilities. This preliminary action allows the chip to be prepared in advance without requiring secure production sites, while final personalization occurs later in a secure manner through the trust center.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for personalizing a safety element (SE) of a mobile terminal device (EG), particularly in the form of a smart card chip of a communication terminal device. The invention comprises the pre-personalizing of the safety element (SE) within the course of the production process thereof, and the final personalizing of the safety element (SE) upon the initial use of the terminal device (EG) by the user (N), wherein a communication connection is established between the terminal device (EG) and a trust center (TC) of a communication network operator. Within the course of the pre-personalizing of the safety element (SE), a unique main key (MK) is determined for the safety element (SE) and transferred to the trust center (TC). Within the course of the final personalizing of the safety element (SE), personal data of the user are transmitted to the trust center (TC) upon the initial use of the terminal device (EG), and linked at the trust center together with the main key (MK) to form a modified main key (MK). The safety element (SE) is personalized using the modified main key (MK).