Secure Authentication Module Key Replacement Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current smart card personalization systems using master smart cards are vulnerable to piracy, as the master key can be compromised, leading to fraudulent personalization of cards and the inability to differentiate between genuine and fraudulent cards, posing a significant risk to the security of the entire batch of cards.

Innovation Solution

A method where a secure authentication module generates a new secret key for each smart card after confirming the replacement of the native key, using a counter to track unconfirmed key replacements and limiting further personalizations if the threshold is exceeded, ensuring that each card's personalization is verified before allowing subsequent personalizations, and using message authentication codes to secure exchanges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a master smart card is used to personalize slave cards, then personalization can be performed in versatile readers, but the system becomes vulnerable to piracy attacks where the master key can be compromised

Engineering Contradiction:
Improvepersonalization capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the personalization process into multiple sequential steps: authentication phase, key replacement phase, and confirmation phase. Each phase must complete successfully before proceeding to the next, preventing pirates from interrupting the process to extract keys. The master card's functionality is also segmented into distinct operational modes that cannot be simultaneously exploited.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by requiring authentication and generating a new key before the actual key replacement occurs. The confirmation mechanism is prepared in advance, and the system validates each step before committing to the next. This preliminary validation prevents pirates from capturing keys during the personalization process.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the personalization process allows continuous operation, then productivity is improved, but the risk of piracy increases as pirates can perform statistical analysis over multiple cards

Engineering Contradiction:
Improvepersonalization throughputVSAvoidpiracy risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic action by requiring the master card to be physically reinserted into the reader for each personalization operation. This periodic interruption prevents continuous statistical analysis attacks, as the communication channel is broken between operations. The system maintains productivity by automating the process within each periodic cycle while securing against cumulative attacks.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent implements feedback mechanisms where the master card receives confirmation signals from the slave card after key replacement. This feedback loop validates successful personalization before allowing the next operation. The system monitors and controls the personalization flow, preventing pirates from exploiting uninterrupted access to perform statistical analysis across multiple cards.

Inventive Principle:
Principle #23Feedback

3Difficulty of detecting and measuring

If fault injection attacks are used against the master card, then key discovery becomes possible, but all previously personalized cards become vulnerable to fraudulent personalization

Engineering Contradiction:
Improvekey extraction capabilityVSAvoidbatch security
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent performs preliminary key generation and authentication before the actual key replacement. The new key is generated and validated in advance, and the authentication process confirms the slave card's identity before committing the key replacement. This preliminary action ensures that even if fault injection occurs during key replacement, the previously exchanged keys remain secure as they were established through validated preliminary procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary confirmation mechanism that acts as a mediator between the master card and slave card. The confirmation signal verifies that key replacement was successful and authentic before allowing the process to complete. This intermediary layer prevents fault injection attacks from compromising the key exchange, as the confirmation mechanism validates the integrity of the operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If the native key is replaced in non-volatile memory, then the personalization is complete, but the ability to detect fraudulent cards is lost

Engineering Contradiction:
Improvepersonalization completionVSAvoidfraud detection capability
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the slave card sends confirmation signals to the master card after key replacement. This feedback creates a verified record of successful personalization. The system can detect fraudulent cards by verifying the presence and validity of these confirmation signals, maintaining fraud detection capability even after the native key is replaced in non-volatile memory.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary confirmation mechanism that verifies the authenticity of the key replacement process. This intermediary layer ensures that only genuinely personalized cards receive the new key, and the verification process creates detectable markers that can identify fraudulent cards later, even after the native key has been replaced.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8316221B2Recording of a key in an integrated circuit
Publication Date: 2012.11.20 STMICROELECTRONICS BELGIUM
  • US8316221B2 patent drawing
  • US8316221B2 patent drawing
  • US8316221B2 patent drawing

AI summary

A method and a system for personalizing electronic elements, by replacing, in a non-volatile memory of each of the electronic elements a first secret key with a second secret key, by a secure authentication module automatically generating the second key after having restored the first one from an identifier of the element being personalized, including conditioning, on the authentication module side, the provision of the second key to a current element to the reception of a message confirming the key replacement of at least one preceding element.