Smart Card Software Reloading via Encrypted Data Backup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for updating software on smart cards or Secure Elements are complex and undesirable due to security constraints, limited storage and processing power, and the need for secure execution within the device.

Innovation Solution

A method for reloading software onto a chip card using a reloading machine that encrypts and transfers user and control data to the machine, allowing customization and secure installation without external communication, enabling factory resets and functional testing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software is loaded directly onto the smart card at the factory, then security is improved, but adaptability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The software loading process is segmented into two distinct phases: an initial secure loading phase at the factory for core applications, and a subsequent reloadable phase for additional applications. This segmentation allows the card to maintain security for critical functions while enabling adaptability through post-manufacturing reloading capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The smart card is pre-configured with a reloading application and necessary security infrastructure during factory manufacturing. This preliminary action establishes a secure foundation that enables future software reloading without compromising the card's security architecture, thus resolving the contradiction between initial security and future adaptability.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the smart card is manufactured with all applications pre-loaded, then convenience is improved, but device complexity increases

Engineering Contradiction:
ImproveconvenienceVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The smart card is designed with multi-functionality to serve dual purposes: it operates as a pre-loaded secure card for basic transactions and simultaneously functions as a reloadable card for additional applications. This universal design eliminates the need for separate card types, maintaining convenience while managing complexity through a single versatile platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The smart card implements dynamic software loading capabilities that allow applications to be added or removed based on user needs. This dynamic approach replaces the static pre-loaded model, enabling the card to adapt its functionality while maintaining a streamlined core structure that prevents excessive complexity.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If software reloading capability is added to smart cards, then adaptability is improved, but security risks increase

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A dedicated reloading application acts as an intermediary between external software sources and the smart card's secure environment. This intermediary controls and validates all software loading operations, ensuring that only authorized applications can be loaded while maintaining the card's security architecture. The intermediary mechanism enables adaptability without directly exposing security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The software reloading system implements feedback mechanisms that verify the integrity and authenticity of loaded applications. Security checks and validation protocols provide continuous feedback to ensure that reloading operations do not compromise card security, thus enabling adaptability while maintaining reliable security controls.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3754529B1Method for reloading software on a smart card by means of a post-loader
Publication Date: 2023.06.14 BUNDESDRUCKEREI GMBH
  • EP3754529B1 patent drawingFigure 1
  • EP3754529B1 patent drawingFigure 2
  • EP3754529B1 patent drawingFigure 3

AI summary

The invention relates to a method for reloading software provided by a reloading machine (102) onto a chip card (104, 410) by the reloading machine (102), wherein the chip card (104, 410) has a processor (414), a communication interface (412) and a non-volatile electronic memory (424) with a logical data structure (122) stored therein, as well as user data (124, 126, 442, 450) and control data (128, 130). The procedure comprises the steps of establishing a communication link between the reloading machine (102) and the chip card (104) via the communication interface (412, 106), generating a first data record by the processor (414) by encrypting at least part of the user data (124, 126, 442, 450) stored in the non-volatile electronic memory (424) and/or at least part of the control data (128, 128) stored in the non-volatile electronic memory (424).130) and/or the logical data structure (122), transmitting the first data record to the reloading machine (102) via the communication link, storing the first data record in the reloading machine (102), reloading the software onto the chip card (104, 410) by transferring the software to be reloaded to the chip card (104, 410) via the communication link and storing the transferred software in the non-volatile electronic memory (424), transmitting the first data record to the chip card (104, 410) via the communication link, and restoring the user data (124, 126, 442, 450) and/or the control data (128, 130) and/or the logical data structure (122) of the chip card (102, 410) by decoding the first data record by the processor (414) and storing the data contained in the first data record included user data (124, 126, 442, 450) and/or control data (128,130) and/or logical data structure (122) in the non-volatile electronic memory (424).,