Smartcard Random ID Generation for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contactless smartcards using RFID technology face collision issues and privacy concerns due to fixed Unique IDs, which lead to unwanted tracking of user interactions and location changes, necessitating a solution that balances security and privacy.

Innovation Solution

Implementing a smartcard that combines fixed and changing Random ID codes, allowing user-controlled generation of Random ID codes, which can be used like fixed IDs for tracking and stored in non-volatile memory for quasi-static ID functionality, enhancing security and privacy by allowing dynamic changes based on user input or random number generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed UID code is used in smartcards, then the card can be reliably identified and tracked across different locations, but the user's location and interaction history can be unwantedly tracked, compromising privacy

Engineering Contradiction:
Improvecard identification reliabilityVSAvoidunwanted tracking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a dynamic ID code that can change over time based on user control or predefined conditions. The ID code transitions from static to dynamic, allowing the card to present different identification values at different times, thereby preventing continuous tracking while maintaining reliable identification during each interaction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the identification parameter (ID code) from a fixed value to a variable value that can be updated. The ID code is modified based on user input or timing conditions, transforming the identification system from one that permanently tracks the card to one that provides reliable identification without enabling unwanted tracking.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If a Random-ID code is generated at each Power-UP, then privacy is protected by preventing tracking, but the card cannot maintain consistent identity for applications requiring fixed ID recognition

Engineering Contradiction:
Improvetracking preventionVSAvoidcard identity consistency
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements controlled dynamics where the ID code remains stable for periods of time (providing consistency) but can change when triggered by user input or specific conditions (providing privacy). This selective dynamic behavior resolves the contradiction between needing consistent identity and preventing tracking.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces periodic or event-driven ID code updates rather than continuous changes. The ID code remains fixed during normal operation for reliable identification, and updates periodically or upon user request to prevent tracking, thus balancing consistency and privacy.

Inventive Principle:
Principle #19Periodic action

3Object-affected harmful factors

If user-controlled Random ID generation is implemented, then security and privacy are enhanced through dynamic ID changes, but the device complexity increases due to additional generation and storage mechanisms

Engineering Contradiction:
Improvesecurity enhancementVSAvoidID generation and storage complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service by allowing the card itself to generate and manage the Random ID codes using its own resources (CPU, memory, random number generator). The card autonomously handles ID generation and storage without requiring external infrastructure, enhancing security while avoiding the complexity of centralized ID management systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes the smartcard's existing resources (CPU, memory, random number generator) multi-functional by using them for both normal card operations and for generating/storing Random ID codes. This approach enhances security through dynamic ID changes without adding separate dedicated hardware components, thus limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2466509B1Random function for smartcards
Publication Date: 2019.04.03 NXP BV
  • EP2466509B1 patent drawingFigure 1
  • EP2466509B1 patent drawingFigure 2
  • EP2466509B1 patent drawingFigure 3a

AI summary

A smartcard (30) having a state machine (380), such as a microcontroller kernel and a non-secure memory (312) capable of storing a Random-ID code, where the non-secure memory is electrically coupled to the state machine. A random number generator (330) may be used for generating a new Random-ID code or a new Random-ID code may be supplied by a card reader system (300) each time the smartcard interacts with the card reader system. A user interface may be electrically coupled to the random number generator (330) so that a user may initiate generation of the new Random-ID code by the random number generator for storage in the non-secure memory (312).