Smartcard Random ID Generation for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless smartcards using RFID technology face collision issues and privacy concerns due to fixed Unique IDs, which lead to unwanted tracking of user interactions and location changes, necessitating a solution that balances security and privacy.
Innovation Solution
Implementing a smartcard that combines fixed and changing Random ID codes, allowing user-controlled generation of Random ID codes, which can be used like fixed IDs for tracking and stored in non-volatile memory for quasi-static ID functionality, enhancing security and privacy by allowing dynamic changes based on user input or random number generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a fixed UID code is used in smartcards, then the card can be reliably identified and tracked across different locations, but the user's location and interaction history can be unwantedly tracked, compromising privacy
Solution Approach 1:
The patent implements a dynamic ID code that can change over time based on user control or predefined conditions. The ID code transitions from static to dynamic, allowing the card to present different identification values at different times, thereby preventing continuous tracking while maintaining reliable identification during each interaction.
Solution Approach 2:
The patent changes the identification parameter (ID code) from a fixed value to a variable value that can be updated. The ID code is modified based on user input or timing conditions, transforming the identification system from one that permanently tracks the card to one that provides reliable identification without enabling unwanted tracking.
2Object-affected harmful factors
If a Random-ID code is generated at each Power-UP, then privacy is protected by preventing tracking, but the card cannot maintain consistent identity for applications requiring fixed ID recognition
Solution Approach 1:
The patent implements controlled dynamics where the ID code remains stable for periods of time (providing consistency) but can change when triggered by user input or specific conditions (providing privacy). This selective dynamic behavior resolves the contradiction between needing consistent identity and preventing tracking.
Solution Approach 2:
The patent introduces periodic or event-driven ID code updates rather than continuous changes. The ID code remains fixed during normal operation for reliable identification, and updates periodically or upon user request to prevent tracking, thus balancing consistency and privacy.
3Object-affected harmful factors
If user-controlled Random ID generation is implemented, then security and privacy are enhanced through dynamic ID changes, but the device complexity increases due to additional generation and storage mechanisms
Solution Approach 1:
The patent implements self-service by allowing the card itself to generate and manage the Random ID codes using its own resources (CPU, memory, random number generator). The card autonomously handles ID generation and storage without requiring external infrastructure, enhancing security while avoiding the complexity of centralized ID management systems.
Solution Approach 2:
The patent makes the smartcard's existing resources (CPU, memory, random number generator) multi-functional by using them for both normal card operations and for generating/storing Random ID codes. This approach enhances security through dynamic ID changes without adding separate dedicated hardware components, thus limiting the increase in device complexity.
Data Source
Figure 1
Figure 2
Figure 3a
AI summary
A smartcard (30) having a state machine (380), such as a microcontroller kernel and a non-secure memory (312) capable of storing a Random-ID code, where the non-secure memory is electrically coupled to the state machine. A random number generator (330) may be used for generating a new Random-ID code or a new Random-ID code may be supplied by a card reader system (300) each time the smartcard interacts with the card reader system. A user interface may be electrically coupled to the random number generator (330) so that a user may initiate generation of the new Random-ID code by the random number generator for storage in the non-secure memory (312).