Smart Card Validation Data Generation for Secure Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current smart cards are vulnerable to information theft, as they can be easily replicated and used to steal user information, leading to significant property loss, due to their passive nature in wireless communication.
Innovation Solution
A method for a smart card to generate and output validation data based on operation requests, using pre-stored strategies such as MAC, HASH, or signature calculations, which includes communication mode and transaction details, to prevent unauthorized access by validating the communication mode and terminal type, ensuring secure operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If smart card uses passive wireless communication mode, then communication convenience is improved, but security is worsened due to easy replication and information theft
Solution Approach 1:
The system performs preliminary validation by comparing the detected communication mode with the expected communication mode before processing the operation request. This preliminary check prevents unauthorized operations from proceeding, addressing the security weakness of passive wireless communication while maintaining its convenience.
Solution Approach 2:
The system implements feedback by detecting the actual communication mode used, comparing it with the expected mode, and using this information to validate whether the operation request should be processed. This feedback mechanism ensures that only legitimate communications are accepted, improving security without compromising ease of operation.
2Reliability
If smart card validates communication mode and terminal type, then security is improved, but operation complexity is worsened
Solution Approach 1:
The smart card performs self-validation by detecting its own communication mode and comparing it with the expected mode. This self-service approach eliminates the need for complex external validation systems, improving security while minimizing the increase in operational complexity.
Solution Approach 2:
The validation mechanism is designed to work across multiple communication modes (contact and contactless) and different terminal types. By creating a universal validation framework that handles various scenarios through a unified process, the system improves security without proportionally increasing complexity.
3Productivity
If smart card processes operation request without validation, then processing speed is improved, but security is worsened due to unauthorized access
Solution Approach 1:
The system performs a quick preliminary check of the communication mode match before initiating full request processing. This preliminary action is designed to be fast and does not significantly impact processing speed, while effectively preventing unauthorized access attempts from proceeding to the full processing stage.
Data Source
AI summary
A smart card, a method for outputting validation data, and a method for responding to an operation request are provided. The method for outputting validation data includes acquiring an operation request by a smart card; acquiring smart card operation information of the smart card by the smart card, after acquiring the operation request, wherein the smart card operation information comprises at least a smart card mode factor for indicating a working mode of the smart card, and the working mode of the smart card comprises a non-contact communication mode and/or a contact communication mode; acquiring a validation data generating strategy, and using the validation data generating strategy to process at least the smart card operation information to obtain validation data by the smart card; outputting the validation data by the smart card after obtaining the validation data.


