Secure Smart Card Personalization via Virtual Dataset Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing smart card personalization systems face challenges such as network delays, security concerns due to key exchange over the internet, and the need for concurrent secured connections, which limit the efficiency and security of smart card personalization.

Innovation Solution

The method involves generating a customized dataset for smart card personalization using a virtual smart card formatted according to the smart card's operating system, encrypting this dataset with a device-specific encryption key unique to the card issuance device, and transmitting it to the issuance device for secure personalization of the real smart card.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If smart card personalization is performed using sequential APDU exchange over network, then personalization can be accomplished remotely, but network delays and interruptions cause communication delays and personalization failures

Engineering Contradiction:
Improveremote personalization capabilityVSAvoidpersonalization completion reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-generating the complete personalized dataset at the personalization system before transmission. The dataset is fully prepared including all APDU sequences and personalization data, then transmitted as a complete package to the card issuance device. This eliminates the need for sequential APDU exchange during actual personalization, preventing network interruptions from causing failures.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If encryption keys are transmitted over the internet for key exchange, then remote personalization is enabled, but security concerns arise from key exposure during transmission

Engineering Contradiction:
Improveremote personalization capabilityVSAvoidsecurity risks from key transmission
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key exchange from the transmission process. The card issuance device's encryption key is used to encrypt the dataset at the personalization system, but the key itself never leaves the card issuance device. Only the encrypted dataset is transmitted over the network, eliminating the security risk of key exposure during transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The encrypted dataset acts as an intermediary that carries the personalization information without exposing the encryption key. The dataset is encrypted using the card issuance device's key, serving as a secure container that can be transmitted remotely without compromising key security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of time

If personalization data is generated and transmitted in real-time during smart card personalization, then data freshness is maintained, but network bandwidth requirements and transmission time increase

Engineering Contradiction:
Improvepersonalization execution timeVSAvoidpersonalization throughput
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-generating the complete personalized dataset at the personalization system before transmission. The dataset is fully prepared including all APDU sequences and personalization data, then transmitted as a complete package to the card issuance device. This eliminates the need for sequential APDU exchange during actual personalization, preventing network interruptions from causing failures.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If the same encryption key is used for both data transmission and smart card storage, then key management is simplified, but security vulnerabilities increase if the key is compromised

Engineering Contradiction:
Improvekey management complexityVSAvoidsecurity vulnerability from key compromise
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the encryption key usage into two distinct parts: (1) the card issuance device's encryption key used for securing data transmission, and (2) the smart card's internal encryption key used for storing personalization data. This separation ensures that compromise of one key does not affect the other, enhancing security while maintaining manageable key distribution.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3729321B1Secure end-to-end personalization of smart cards
Publication Date: 2025.05.28 ENTRUST CORP
  • EP3729321B1 patent drawingFigure 1
  • EP3729321B1 patent drawingFigure 2A
  • EP3729321B1 patent drawingFigure 2B

AI summary

A secure end-to-end smart card personalization system and method of operation are disclosed. A personalization system generates a customized dataset including personalization data for installation onto a smart card by performing a personalization process using a virtual smart card formatted according to the operating system of the smart card. The personalization system encrypts at least a portion of the customized dataset using an encryption key that is unique to a card issuance device that is separate from the personalization system, the encryption key being different from any encryption key used to secure the customized dataset when stored on the smart card. The personalization system transmits the customized dataset to the card issuance device for personalization of the smart card.