Smart Card Security Information Dispatch via EMV Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current EMV protocol-based smart cards lack a satisfactory mechanism to effectively trace security information back to readers or remote issuers, making it difficult to assess security risks and identify potential attacks without modifying existing communication protocols.

Innovation Solution

Implementing a method within the smart card to detect anomalies or attacks and send security information to the reader or issuer during an EMV transaction using predefined rules and existing EMV transaction messages, such as incorporating security information in the ATR or AFL messages, allowing for enhanced security risk assessment and behavior analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the smart card erases sensitive data and renders itself inoperable upon detecting an attack, then security protection is improved, but the ability to transmit security information to the reader is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity information transmission
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The smart card performs preliminary actions by detecting attacks and erasing sensitive data before the transaction completes, preventing fraud while maintaining the ability to communicate attack detection to the reader through predefined rules and status flags that trigger security responses

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by enabling the smart card to transmit security information about detected attacks back to the reader, allowing the reader to assess security risks and take appropriate actions based on the card's security status

Inventive Principle:
Principle #23Feedback

2Reliability

If the ATR response includes minimal information to prevent fraud, then security is improved, but the reader's ability to determine the cause of dialogue failure is worsened

Engineering Contradiction:
Improvefraud preventionVSAvoidcause identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The security information transmission is segmented into different components: the ATR response provides basic security status, while additional security information can be transmitted through other EMV message structures, allowing the reader to piece together the complete security picture without exposing sensitive data

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters by using predefined rules and status flags within existing EMV message structures to encode security information in a way that maintains fraud prevention while providing sufficient detail for the reader to identify attack causes

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If existing EMV communication protocols are maintained without modification, then compatibility is improved, but the mechanism for transmitting security information is worsened

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidsecurity information transmission capability
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies universality by enabling existing EMV protocol messages to serve multiple functions: their original transaction purposes plus the additional function of transmitting security information through predefined rules and status flags, eliminating the need for protocol modifications

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The smart card self-services by autonomously detecting attacks, determining security status according to predefined rules, and transmitting security information through existing EMV message structures without requiring external system changes or protocol modifications

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3234848B1Method of dispatching an item of security information and electronic device able to implement such a method
Publication Date: 2021.08.11 IDEMIA FRANCE SAS
  • EP3234848B1 patent drawingFigure 1
  • EP3234848B1 patent drawingFigure 2~3
  • EP3234848B1 patent drawingFigure 4~5

AI summary

The invention relates to a method of dispatching an item of security information (IS) implemented by an electronic device (4), the method comprising the following steps: - detection of an event encountered by the electronic device (4); - recording, in a secure memory (10) of the device, of an item of security information (IS) representative of the event; - starting, following the recording, of a transaction with an external terminal; and - dispatching to the external terminal of the item of security information (IS) in a transaction message during said transaction. The invention furthermore relates to an electronic device able to implement such a method of dispatch.