Smart Card Issuance System with Mutual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing smart card issuance model is limited by requiring banks to directly issue IC cards, which restricts market scope and application, especially in the content delivery business where numerous content owners need flexible and secure solutions for customer authentication and personalization.
Innovation Solution
A system and method for issuing smart card devices that allows customers to purchase and initialize them through retail channels, enabling remote personalization and authentication by service providers, ensuring security and brand recognition through mutual authentication and session key encryption for data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If banks directly issue IC cards to customers through their card making facility, then security is ensured, but market scope and application flexibility are restricted
Solution Approach 1:
The IC card issuance process is segmented into distinct phases: initialization by manufacturer, first-time authentication by bank, and subsequent field personalization. This segmentation allows different entities to perform different functions, expanding market scope while maintaining security through the bank's authentication role.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the bank verifies the IC card through mutual authentication protocol before allowing field personalization. This intermediary step ensures security is maintained even as the issuance process becomes more distributed and flexible.
2Reliability
If IC cards are initialized and personalized only by banks in their facility, then security is maintained, but issuance efficiency and cost-effectiveness deteriorate
Solution Approach 1:
The patent enables field personalization where customers can initialize and personalize their own IC cards using portable devices after bank authentication. This self-service capability dramatically improves issuance efficiency and reduces bank facility requirements while maintaining security through the authentication protocol.
Solution Approach 2:
The bank performs preliminary authentication and verification of the IC card before allowing field personalization. This preliminary action ensures security is established upfront, enabling subsequent efficient self-service personalization without compromising security.
3Adaptability or versatility
If multiple content owners issue smart card devices, then market scope expands, but security management complexity increases
Solution Approach 1:
The patent implements a universal mutual authentication protocol that works across multiple content owners and banks. This universal mechanism allows any authorized issuer to securely issue and personalize IC cards without requiring complex issuer-specific security management, thus expanding market scope while keeping security management manageable.
4Ease of operation
If IC card personalization is done in bank facility, then brand recognition is ensured, but operational flexibility and customer convenience deteriorate
Solution Approach 1:
The patent enables customers to personalize their IC cards themselves in the field using portable devices after bank authentication. This self-service approach maximizes customer convenience and operational flexibility while the bank's preliminary authentication maintains brand recognition and security.
Data Source
AI summary
A smart card issuance system and method are disclosed. In a first aspect a method and system for issuing a smart card device (SC) is disclosed. The method and system comprise providing an initialization phase of the SC by a manufacturer and providing an authentication phase of the SC by the manufacturer. The method and system also include deploying the SC, providing a first time authentication phase for a specific customer by the issuer (IS) after the SC is deployed and starting a first phase of the registration process of the SC for the specific customer by the issuer. The method and system further include providing another authentication phase of the SC by IS after the first time authentication; and providing of an authentication of the IS by the SC. When both the SC and IS are mutually authenticated, the IS and the specific customer are allowed to complete the registration process. In a second aspect, a data transmission process and system for a smart card device (SC) of an issuer (IS) is disclosed. The process and system comprises performing a login of the SC by a user and performing a mutual authentication of the SC and the IS. The process and system further includes establishing a session key after mutual authentication is established. The session key is used to encrypt and decrypt data for transmission between the IS and the SC.


