Secure Smart Card Reader Logging and Signature Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing secure smart card reader systems are vulnerable to attacks where malware on the host computer intercepts PIN entry or data substitution, as user interaction, including sensitive operations, occurs on insecure host devices, and the lack of standardized command sets for smart cards complicates firewall configuration, potentially allowing insecure card readers to be used.

Innovation Solution

A secure smart card reader that logs security-related events and generates a reader signature on these logs, using cryptographic algorithms, to detect and prevent attacks by ensuring data approval occurs on a secure interface and maintaining a secure logging mode to verify user interactions and commands exchanged with the smart card, without requiring precise knowledge of sensitive smart card commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user interaction including PIN entry occurs on the host computer, then ease of operation is improved, but security is worsened due to vulnerability to malware attacks

Engineering Contradiction:
Improveuser interaction convenienceVSAvoidmalware attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive operations (PIN entry, data approval) from the insecure host computer environment and relocates them to the secure smart card reader device. The reader's processor directly receives PIN input from the user interface and approves or rejects data signing operations without involving the host computer, thereby isolating sensitive operations from malware attacks while maintaining user convenience.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card reader acts as an intermediary device between the user and the smart card. It mediates sensitive operations by receiving user input through its own secure interface, making security decisions independently, and only communicating necessary commands to the smart card, thereby preventing malware on the host computer from intercepting or manipulating sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a firewall is configured to block insecure card readers, then security is improved, but device complexity increases due to need for precise command knowledge

Engineering Contradiction:
Improveinsecure reader blockingVSAvoidfirewall configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The smart card reader performs self-verification by using its processor to validate whether received commands originate from approved applications. The reader independently checks command authenticity and makes security decisions without requiring external firewall configuration or precise knowledge of smart card command sets, thereby simplifying the system while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The reader's command approval mechanism is designed to be universal and application-agnostic. It can identify and approve commands from different applications using various smart card types without requiring specific firewall rules for each command type, thereby reducing configuration complexity while effectively blocking insecure readers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Difficulty of detecting and measuring

If the reader logs all security events and generates signatures, then detection capability is improved, but loss of time increases due to logging overhead

Engineering Contradiction:
Improveattack detection capabilityVSAvoidlogging processing time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The reader maintains security event logs in real-time during normal operation, preparing the data structure and accumulating events before an attack occurs. When an attack is detected or the signing operation completes, the pre-prepared log data can be quickly signed and verified, reducing the time penalty of logging operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces time-consuming manual security verification processes with automated cryptographic signature generation. The processor automatically signs the security log using cryptographic algorithms, providing rapid and reliable attack detection without requiring time-consuming manual analysis of logged events.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution effectively detects and prevents attacks by ensuring user approval on a secure interface and logging critical events, allowing the reader to be used with various smart card types, reducing the need for complex firewall configurations and enhancing security against malware and insecure reader usage.

Implementation Method 1

The smart card reader is adapted to generate a reader signature on the log using a cryptographic algorithm parameterized with a cryptographic key stored in the smart card reader

Methodology Applied
Scientific EffectCryptographic algorithm:

Data Source

PatentEP2780854B1A smart card reader with a secure logging feature
Publication Date: 2017.04.12 VASCO DATA SECURITY INTERNATIONAL
  • EP2780854B1 patent drawingFigure 1
  • EP2780854B1 patent drawingFigure 2
  • EP2780854B1 patent drawingFigure 3a

AI summary

The present invention provides a secure smart card reader enabled to make reader signatures on data representative of events and actions which may be security related and which may comprise data representative of reader commands the reader receives from a host or remote application, smart card commands the reader exchanges with an inserted smart card, data the reader presents to the user for approval, and/or configuration parameters the reader applies when dealing with any of the foregoing. The smart card reader may furthermore be adapted to maintain logs of certain events and actions which may comprise exchanging reader commands with a host or remote application, exchanging smart card commands with an inserted smart card, and/or interactions with a user. The logs may comprise data representative of reader commands the reader receives from a host or remote application, smart card commands the reader exchanges with an inserted smart card, data the reader presents to the user for approval, and/or configuration parameters the reader applies when dealing with any of the foregoing. The secure smart card reader may be adapted to generate a reader signature over one or more of these logs.