Smart Card Security Information Dispatch via EMV Protocol
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current EMV protocol-based smart cards lack a satisfactory mechanism to effectively trace security information back to readers or remote issuers, making it difficult to assess security risks and identify potential attacks without modifying existing communication protocols.
Innovation Solution
Implementing a method within the smart card to detect anomalies or attacks and send security information to the reader or issuer during an EMV transaction using predefined rules and existing EMV transaction messages, such as incorporating security information in the ATR or AFL messages, allowing for enhanced security risk assessment and behavior analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the smart card erases sensitive data and renders itself inoperable upon detecting an attack, then security protection is improved, but the ability to transmit security information to the reader is worsened
Solution Approach 1:
The smart card performs preliminary actions by detecting attacks and erasing sensitive data before the transaction completes, preventing fraud while maintaining the ability to communicate attack detection to the reader through predefined rules and status flags that trigger security responses
Solution Approach 2:
The system implements feedback by enabling the smart card to transmit security information about detected attacks back to the reader, allowing the reader to assess security risks and take appropriate actions based on the card's security status
2Reliability
If the ATR response includes minimal information to prevent fraud, then security is improved, but the reader's ability to determine the cause of dialogue failure is worsened
Solution Approach 1:
The security information transmission is segmented into different components: the ATR response provides basic security status, while additional security information can be transmitted through other EMV message structures, allowing the reader to piece together the complete security picture without exposing sensitive data
Solution Approach 2:
The system changes parameters by using predefined rules and status flags within existing EMV message structures to encode security information in a way that maintains fraud prevention while providing sufficient detail for the reader to identify attack causes
3Adaptability or versatility
If existing EMV communication protocols are maintained without modification, then compatibility is improved, but the mechanism for transmitting security information is worsened
Solution Approach 1:
The patent applies universality by enabling existing EMV protocol messages to serve multiple functions: their original transaction purposes plus the additional function of transmitting security information through predefined rules and status flags, eliminating the need for protocol modifications
Solution Approach 2:
The smart card self-services by autonomously detecting attacks, determining security status according to predefined rules, and transmitting security information through existing EMV message structures without requiring external system changes or protocol modifications
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
The invention relates to a method of dispatching an item of security information (IS) implemented by an electronic device (4), the method comprising the following steps: - detection of an event encountered by the electronic device (4); - recording, in a secure memory (10) of the device, of an item of security information (IS) representative of the event; - starting, following the recording, of a transaction with an external terminal; and - dispatching to the external terminal of the item of security information (IS) in a transaction message during said transaction. The invention furthermore relates to an electronic device able to implement such a method of dispatch.