Smart Card Delegation to Host Secure Domain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart cards face limitations in processing power and data transfer speed due to their design for secure data storage, which restricts functionality and efficiency in performing complex operations, especially when interacting with host data processing apparatus via low-speed serial interfaces.

Innovation Solution

A smart card that identifies a secure data processing domain within a host apparatus and delegates certain data processing operations to the host, utilizing the host's processing capabilities to enhance performance and implement previously unattainable functionalities, such as secure user interfaces, by transmitting applications or executables and controlling scheduling signals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data processing operations are performed entirely within the smart card to maintain security, then security is improved, but processing power and functionality are limited

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The processing operations are segmented into two parts: security-critical operations remain on the smart card, while non-critical operations are delegated to the host apparatus. This segmentation allows the system to maintain security requirements while accessing greater processing power for appropriate tasks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary interface is introduced between the smart card and host apparatus that enables selective delegation of processing operations. This intermediary layer manages which operations are performed on the card versus the host, allowing the system to balance security and processing power requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If data processing operations are delegated to host apparatus to increase processing power, then productivity is improved, but security risks increase

Engineering Contradiction:
Improveprocessing powerVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Different quality levels of security are applied to different processing operations. Security-critical operations maintain strict local security controls on the smart card, while non-critical operations can leverage the host apparatus with appropriate security measures. This local quality approach allows the system to optimize security for each specific operation type.

Inventive Principle:
Principle #3Local quality

3Device complexity

If smart cards use low-speed serial interfaces for data transfer, then device complexity is reduced, but data transfer speed deteriorates

Engineering Contradiction:
Improveinterface complexityVSAvoiddata transfer speed
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The system dynamically adapts its data transfer strategy based on the operational context. For operations requiring high data transfer speeds, the system leverages the host apparatus's faster interfaces, while maintaining compatibility with low-speed serial interfaces for basic operations. This dynamic approach allows the system to optimize transfer speed without requiring complex high-speed interfaces in all scenarios.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9256732B2Processing efficiency on secure systems having a host processor and smart card
Publication Date: 2016.02.09 ARM LTD
  • US9256732B2 patent drawing
  • US9256732B2 patent drawing
  • US9256732B2 patent drawing

AI summary

A smart card comprising a data store and a processor, said smart card being operable to connect with a host data processing apparatus, said smart card comprising authentication logic operable when connected to said host data processing apparatus to identify a secure data processing domain having predetermined properties within said host data processing apparatus and in response to identify said secure data processing domain, said smart card is operable to delegate at least some data processing operations to be processed within said secure data processing domain of said host data processing apparatus.