White Box Cardlet Obfuscation for Smart Card Biometric Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart transaction cards are vulnerable to hacking and tampering, especially when using biometric sensors, due to the open nature of their memory devices, which can lead to unauthorized access and data theft, and adding secure memory increases manufacturing costs.

Innovation Solution

Implementing a white box 'cardlet' with obfuscation and cryptography processes to protect sensitive cardholder data and applications on regular memory, using a Java Card platform to secure biometric data and prevent attacks, and periodically re-obfuscating data to maintain security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure memory is added to smart transaction cards to protect sensitive data, then security against hacking and tampering is improved, but manufacturing costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary layer of obfuscation and white-box cryptography mechanisms that sit between the sensitive data and the memory storage. This allows regular memory to be used while providing security protection through software-based obfuscation techniques, avoiding the need for expensive secure memory hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security approach from hardware-based (secure memory) to software-based (obfuscation and cryptography). By transforming the security mechanism from physical to logical, the system achieves protection without incurring additional manufacturing costs for secure memory components.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If biometric sensors are added to smart transaction cards to enhance security, then protection against identity theft is improved, but device complexity and manufacturing costs increase

Engineering Contradiction:
Improveprotection against identity theftVSAvoidcircuitry
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses obfuscation and white-box cryptography as intermediary layers that protect biometric data without requiring additional complex hardware. The software-based protection mechanism shields the biometric information stored in regular memory, achieving security without increasing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If obfuscation and white box processes are implemented on regular memory, then security against hacking is improved, but manufacturing costs are reduced compared to secure memory

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs software-based obfuscation and white-box cryptography that can be easily updated or replaced without changing the hardware. This approach uses inexpensive regular memory with software protection layers, avoiding the need for expensive secure memory while maintaining security through periodically updated obfuscation techniques.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP3577851B1Methods and systems for securely storing sensitive data on smart cards
Publication Date: 2021.04.07 MASTERCARD INT INC
  • EP3577851B1 patent drawingFigure 1~2
  • EP3577851B1 patent drawingFigure 3
  • EP3577851B1 patent drawingFigure 4

AI summary

Methods and systems for permitting sensitive cardholder data to be securely stored in a regular storage element of a smart transaction card. In an embodiment, a transaction card processor of the smart transaction card installs a security application compatible with the operating system of the smart transaction card and that includes a white box cardlet. The transaction card processor uses a code protection process of the white box cardlet to obfuscate biometric reference template data stored in the regular memory of a biometric sensor, next stores the obfuscated biometric reference template data in the regular memory, and then re-obfuscates the biometric reference template data at a predetermined time interval.