Transponder Encryption for Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional communication systems between smart cards and readers fail to effectively obscure the applications supported by transponders, leading to potential privacy breaches, as the unique identifier and application information can be easily detected, making users vulnerable to targeting by attackers.
Innovation Solution
A transponder and reader system that uses encryption and Message Authentication Codes (MACs) to obscure application information by expanding application names with random numbers and encrypting them with keys known to both entities, allowing the reader to determine supported applications without revealing this information to attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If application information is transmitted in plain text for reader determination, then the reader can easily identify supported applications, but attackers can also detect and target users based on this information
Solution Approach 1:
The patent introduces encrypted application identifiers as an intermediary between the actual application information and the communication channel. The reader receives encrypted identifiers that it can decrypt using stored keys, while attackers cannot derive meaningful information from the encrypted form. This intermediary layer enables functional operation while preventing harmful information leakage.
Solution Approach 2:
The patent transforms application identifiers from plain text to encrypted form, changing the parameter of information representation. The encrypted identifiers maintain the necessary functional properties for reader verification while altering the information content to prevent attacker analysis. This parameter change enables simultaneous achievement of operational ease and privacy protection.
2Object-affected harmful factors
If encryption is applied to application information, then user privacy is protected from attackers, but the reader cannot directly determine supported applications
Solution Approach 1:
The system uses encrypted application identifiers as intermediaries that the reader can process. The reader stores decryption keys and can decrypt these identifiers to determine supported applications, while the encrypted form protects against attacker analysis. This intermediary mechanism resolves the contradiction by enabling reader functionality while maintaining privacy protection.
Solution Approach 2:
The reader performs preliminary actions by storing decryption keys and preparation data before the actual communication occurs. This preliminary setup enables the reader to decrypt and process application identifiers during operation, resolving the apparent contradiction between encryption and ease of operation. The preliminary key storage eliminates the need for complex real-time decryption negotiations.
3Reliability
If unique identifiers are transmitted for collision detection, then device identification works correctly, but users can be scanned and tracked at multiple locations
Solution Approach 1:
The patent changes the parameter of identifier representation from plain unique identifiers to encrypted forms. The encrypted identifiers maintain the functional properties needed for reliable device identification and collision detection, while transforming the information content to prevent tracking and privacy leakage. This parameter change simultaneously preserves reliability and prevents information loss to unauthorized parties.
4Adaptability or versatility
If card type and manufacturer information are presented, then compatibility verification is enabled, but the bearer's location and identity can be inferred
Solution Approach 1:
The patent introduces encrypted application identifiers as intermediaries that convey compatibility information without revealing identity. The reader can verify compatibility by decrypting and analyzing these identifiers, while attackers cannot infer user identity or location from the encrypted form. This intermediary approach enables adaptability while preventing harmful identity inference.
Data Source
AI summary
Transponder (104), comprising a storage unit (106) having stored a number of different applications, a processing unit (108) which, on request of a reader (102), is adapted to generate a response interpretable using an encryption scheme known by both the transponder (104) and the reader (102) so that the reader (102) is capable of determining whether an application is supported by the transponder (104) by analyzing the response using the encryption scheme, and a transmission unit (110) adapted to send the response to said reader (102).


