Smart Card Authentication via Secret Command Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for preventing the cloning of smart cards are inadequate, as they do not provide sufficient guarantees against counterfeiting, and there is no effective method to detect cloned cards, which can be difficult to distinguish from authentic ones.
Innovation Solution
Implementing a method that uses secret commands stored on authentic smart cards, which can only be recognized and processed correctly by authentic cards, allowing card reader terminals to detect clones by issuing these secret commands and comparing their processing results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys and PINs are used to prevent cloning, then security is improved, but the system becomes vulnerable to disclosure during personalization or at the card issuer
Solution Approach 1:
The patent embeds a secret command directly into the authentic card's memory during manufacturing, before the card enters circulation. This preliminary action ensures that the secret command is already present and cannot be disclosed during personalization or at the card issuer, as it is physically built into the card's circuitry rather than stored in accessible memory.
Solution Approach 2:
The secret command acts as an intermediary element that bridges the terminal and the card's processing capabilities. It enables the terminal to verify authenticity by executing a specific command that only authentic cards can process correctly, without requiring transmission of vulnerable confidential codes through communication channels.
2Adaptability or versatility
If cloned cards are programmed to match authentic cards' logical behavior, then compatibility is improved, but detection becomes difficult
Solution Approach 1:
The patent introduces a local quality difference by embedding a secret command with specific execution characteristics into authentic cards during manufacturing. This secret command performs a particular operation (such as accessing a specific memory location or executing a unique algorithm) that cloned cards cannot replicate, creating a detectable distinction in local processing behavior.
Solution Approach 2:
The patent replaces reliance on external authentication mechanisms (such as PIN verification or cryptographic signatures that can be copied) with an intrinsic mechanical/digital property of the card itself - the presence of the secret command in its memory structure. This substitution makes cloning ineffective because the secret command is physically embedded in the card's circuitry, not programmatically stored.
3Ease of operation
If standard public commands are used for card operations, then ease of operation is improved, but authentication effectiveness deteriorates
Solution Approach 1:
The patent segments card operations into two distinct categories: standard public commands for legitimate use cases (reading, writing, updating data) and secret commands for authentication purposes. This segmentation allows the system to maintain ease of operation for normal transactions while introducing a separate, more secure authentication mechanism that is not exposed during regular operations.
Solution Approach 2:
Instead of trying to make public commands inherently secure (which leads to vulnerability), the patent inverts the approach by using public commands for convenient operation and a separate secret command for authentication. The secret command is executed in reverse logic - rather than asking the card to prove knowledge of a secret through computation, the terminal sends a secret command and verifies the card's ability to execute it correctly, revealing clones through incorrect processing.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The method involves modifying a control program in a smart card reader terminal i.e. payment terminal, such that the program calls a secret command that is pre-inserted into an authentic smart card and is different from a set of standard and public commands such as payment commands. Authenticity of a smart card i.e. payment card, is detected if the secret command is recognized and/or processed correctly, or presence of a clone smart card e.g. clone payment card, is detected if the secret command is not recognized and/or is processed wrongly. Independent claims are also included for the following: (1) a smart card reader terminal comprising a control program receiving and executing unit (2) a computer program product comprising instructions to perform a method of detecting a smart card (3) a computer program product comprising instructions to perform reading and/or writing in a memory and mathematical and logical operations.