Smart Card Security Verification via Service Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing smart card applications lack effective security verification methods to prevent unauthorized use after a terminal is lost, leading to potential damages.

Innovation Solution

A security verification method and device that obtain and analyze current service data, such as location and transaction information, against user-defined or statistically derived security parameters to determine if a service should be terminated or allowed to continue, ensuring secure usage of smart card applications on intelligent terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If smart card application performs service processing without security verification, then service convenience is improved, but security is deteriorated

Engineering Contradiction:
Improveservice convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by obtaining security parameters and performing verification before the smart card service is executed. The system pre-establishes security criteria including location, time, and transaction amount parameters, then verifies these conditions are met before allowing service processing to proceed, preventing unauthorized use in advance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism between the user and the smart card service. A security verification module acts as a mediator that checks multiple parameters (location, time, transaction amount) and either permits or blocks service execution based on whether these intermediate verification conditions are satisfied

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security verification parameters are strictly enforced, then security is improved, but service availability is deteriorated

Engineering Contradiction:
ImprovesecurityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making security parameters configurable and adjustable rather than fixed. Users can dynamically set different location ranges, time periods, and transaction amount thresholds based on their needs. The system adapts security verification criteria to different service scenarios, allowing legitimate services to proceed while blocking unauthorized ones

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3401823B1Security verification method and device for smart card application
Publication Date: 2022.10.12 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3401823B1 patent drawingFigure 1~2
  • EP3401823B1 patent drawingFigure 3
  • EP3401823B1 patent drawingFigure 4

AI summary

The present application relates to the field of information security technologies, and in particular, to a security verification method and device for a smart card application. The method includes: obtaining related data of a current service when the smart card application performs service processing with the outside; determining the related data of the current service and a security parameter; and terminating the current service if the related data of the current service does not comply to the security parameter. The device corresponding to the method can be built in a virtual smart card application, or independent of a smart card application in an eSE chip to execute the described method. Based on the method and device in implementations of the present application, a geographic location, time, transaction information, etc. of a service are determined, so as to ensure security of performing the service by using the smart card application.