Smart Card Personalization via EMV Authentication Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart cards, such as EMV bank cards, face challenges in personalizing secondary applications with distinct authentication mechanisms, requiring secure key generation and certificate acquisition from different certification authorities, which is inefficient and often necessitates dedicated terminals for secure environments.

Innovation Solution

A method for generating and personalizing asymmetric encryption keys for secondary applications using the existing EMV chip's dynamic data authentication mechanism, allowing key transfer and certificate acquisition through the EMV application's authentication channel without needing a secure environment, enabling use of conventional card readers for personalization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric encryption keys are generated for secondary applications using dedicated secure terminals, then security is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The EMV authentication channel, originally designed for banking applications, is made universal by enabling it to authenticate secondary applications from different certification authorities. The existing secure channel performs multiple functions: authenticating both primary EMV applications and secondary PKI applications, eliminating the need for separate dedicated terminals.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The smart card performs self-service by generating its own asymmetric encryption keys internally using its built-in cryptographic modules. The card autonomously requests certificates from certification authorities through the EMV channel without requiring external secure terminal assistance, making the personalization process independent and self-sufficient.

Inventive Principle:
Principle #25Self-service

2Reliability

If asymmetric encryption keys are generated for secondary applications using dedicated secure terminals, then authentication security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The EMV authentication channel serves multiple purposes: it authenticates primary banking applications and secondary PKI applications from different certification authorities. This multi-functionality allows conventional card readers to perform personalization without requiring specialized secure terminals, greatly improving ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The EMV authentication channel acts as an intermediary between the smart card and certification authorities. It provides a secure communication path that enables key generation and certificate acquisition without requiring the end-user terminal to have special security capabilities, simplifying the operation for users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple certification authorities are used for different applications, then adaptability is improved, but device complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The EMV authentication channel is designed to be universal and application-independent, capable of authenticating multiple applications from different certification authorities. The channel's security mechanisms work the same way regardless of which certification authority is involved, allowing the system to adapt to various applications without increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system maintains adaptability by changing parameters such as certification authority identifiers and application-specific keys while keeping the core authentication mechanism unchanged. The EMV channel handles different certification authorities through parameter variations rather than structural changes, preventing complexity increase.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP1791292B1Personalisation of an electronic circuit
Publication Date: 2013.01.02 PROTON WORLD INT
  • EP1791292B1 patent drawingFigure 1~3
  • EP1791292B1 patent drawingFigure 4~5
  • EP1791292B1 patent drawingFigure 6

AI summary

The invention relates to a method and system for personalizing and authenticating an electronic circuit for an application implementing an asymmetric algorithm and using a certification authority, comprising a step of using an authentication channel from another application implementing the same asymmetric algorithm and using another certification authority.