Transponder Encryption for Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication systems between smart cards and readers fail to effectively obscure the applications supported by transponders, leading to potential privacy breaches, as the unique identifier and application information can be easily detected, making users vulnerable to targeting by attackers.

Innovation Solution

A transponder and reader system that uses encryption and Message Authentication Codes (MACs) to obscure application information by expanding application names with random numbers and encrypting them with keys known to both entities, allowing the reader to determine supported applications without revealing this information to attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If application information is transmitted in plain text for reader determination, then the reader can easily identify supported applications, but attackers can also detect and target users based on this information

Engineering Contradiction:
Improveapplication identificationVSAvoidprivacy breach
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces encrypted application identifiers as an intermediary between the actual application information and the communication channel. The reader receives encrypted identifiers that it can decrypt using stored keys, while attackers cannot derive meaningful information from the encrypted form. This intermediary layer enables functional operation while preventing harmful information leakage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms application identifiers from plain text to encrypted form, changing the parameter of information representation. The encrypted identifiers maintain the necessary functional properties for reader verification while altering the information content to prevent attacker analysis. This parameter change enables simultaneous achievement of operational ease and privacy protection.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If encryption is applied to application information, then user privacy is protected from attackers, but the reader cannot directly determine supported applications

Engineering Contradiction:
Improveprivacy protectionVSAvoidapplication determination
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system uses encrypted application identifiers as intermediaries that the reader can process. The reader stores decryption keys and can decrypt these identifiers to determine supported applications, while the encrypted form protects against attacker analysis. This intermediary mechanism resolves the contradiction by enabling reader functionality while maintaining privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The reader performs preliminary actions by storing decryption keys and preparation data before the actual communication occurs. This preliminary setup enables the reader to decrypt and process application identifiers during operation, resolving the apparent contradiction between encryption and ease of operation. The preliminary key storage eliminates the need for complex real-time decryption negotiations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If unique identifiers are transmitted for collision detection, then device identification works correctly, but users can be scanned and tracked at multiple locations

Engineering Contradiction:
Improvedevice identificationVSAvoidprivacy leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the parameter of identifier representation from plain unique identifiers to encrypted forms. The encrypted identifiers maintain the functional properties needed for reliable device identification and collision detection, while transforming the information content to prevent tracking and privacy leakage. This parameter change simultaneously preserves reliability and prevents information loss to unauthorized parties.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If card type and manufacturer information are presented, then compatibility verification is enabled, but the bearer's location and identity can be inferred

Engineering Contradiction:
Improvecompatibility verificationVSAvoididentity inference
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces encrypted application identifiers as intermediaries that convey compatibility information without revealing identity. The reader can verify compatibility by decrypting and analyzing these identifiers, while attackers cannot infer user identity or location from the encrypted form. This intermediary approach enables adaptability while preventing harmful identity inference.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9384440B2Reader and transponder for obscuring the applications supported by a reader and/or a transponder and method thereof
Publication Date: 2016.07.05 NXP BV
  • US9384440B2 patent drawing
  • US9384440B2 patent drawing
  • US9384440B2 patent drawing

AI summary

Transponder (104), comprising a storage unit (106) having stored a number of different applications, a processing unit (108) which, on request of a reader (102), is adapted to generate a response interpretable using an encryption scheme known by both the transponder (104) and the reader (102) so that the reader (102) is capable of determining whether an application is supported by the transponder (104) by analyzing the response using the encryption scheme, and a transmission unit (110) adapted to send the response to said reader (102).