Smart Card Power Management via Encrypted Resume Commands
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for managing power supply to smart cards in mobile terminals are either inconvenient for users, insecure, or energy-inefficient, particularly when frequent access to secure functions is required, as they often necessitate frequent PIN code entry, risk security breaches, or consume excessive energy.
Innovation Solution
A method that involves encrypting and signing commands to resume smart card operations using negotiated encryption and signature keys, allowing the terminal to maintain power while securely unlocking the smart card without storing the PIN code externally, ensuring secure and energy-efficient operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the power supply to the smart card is cut off during periods of inactivity to conserve energy, then energy consumption is reduced, but the user must re-enter the PIN code each time the card is restarted
Solution Approach 1:
The terminal performs preliminary actions by storing authentication data and negotiating cryptographic keys with the smart card before power shutdown. When the card is restarted, the pre-negotiated keys enable automatic re-authentication without requiring user PIN re-entry, thus resolving the contradiction between energy conservation and user convenience
Solution Approach 2:
Cryptographic keys serve as an intermediary mechanism between the user's PIN authentication and the smart card's secure functions. The terminal stores these keys and uses them to automatically re-authenticate with the card after power restoration, eliminating the need for repeated PIN entry while maintaining security
2Ease of operation
If the PIN code is stored in the terminal memory outside the smart card to enable automatic unlocking, then user convenience is improved, but security is compromised due to unprotected storage
Solution Approach 1:
The invention extracts the PIN code from the terminal's unprotected memory and keeps it exclusively within the secure environment of the smart card. Instead, the terminal stores only cryptographic keys that were negotiated with the card, which can be used for authentication without exposing the actual PIN code, thus maintaining security while enabling automatic unlocking
Solution Approach 2:
The terminal creates a functional copy of authentication capability in the form of cryptographic keys, which replicate the access control function of the PIN code without containing the actual secret. These keys can be stored in terminal memory and used to authenticate with the smart card, providing automatic unlocking without security risks
3Use of energy by moving object
If access to the smart card is reduced by using longer crypto-periods to save energy, then energy consumption is reduced, but security is weakened due to less frequent key regeneration
Solution Approach 1:
The terminal performs preliminary key negotiation with the smart card before power shutdown, establishing cryptographic keys that remain valid across power cycles. This allows the card to be powered down for extended periods without compromising security, as the pre-established keys enable secure re-access when needed
Solution Approach 2:
The system dynamically adjusts its security approach by using long-term negotiated keys for power-efficient operation while maintaining the capability to regenerate keys when security requirements demand. The crypto-period becomes flexible rather than fixed, adapting to both energy conservation needs and security requirements
4Ease of operation
If the power supply to the smart card is maintained continuously to avoid re-authentication, then user convenience is improved, but energy consumption increases and security risks arise from potential card extraction attacks
Solution Approach 1:
The terminal performs preliminary authentication and key negotiation with the smart card before power shutdown. This allows the card to be powered down without interrupting service continuity, as the pre-established authentication credentials enable rapid re-access when the card is restarted
Solution Approach 2:
The invention maintains continuity of secure service across power cycles by using negotiated cryptographic keys that persist through shutdowns. The authentication state is preserved through these keys, allowing seamless resumption of secure functions without continuous power supply to the card
Data Source
Figure 1~2
AI summary
Security method in a terminal (10) comprising a chip card (13) offering secure functions, a user interface (11), a module (12) for interfacing with the chip card (13) and suitable for shutting down or implementing the electrical supply to the chip card, the method comprising the following steps after a shutdown, followed by a reimplementation, of the electrical supply to the chip card by the interfacing module, the terminal being kept switched on, the method comprising the following steps: encryption of a command for resumption of utilization by the interfacing module of functions made secure by the interfacing module with a negotiated key stored by the interfacing module and dispatching of said encrypted command to the chip card; utilization by the interfacing module of secure functions offered by the chip card, only if the resumption command decrypted by the chip card is recognized as a resumption command by the chip card.