Authentication Device Multi-Mode Security via Command Parsing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication devices lack support for multiple authentication modes due to the hardware isolation characteristics of security environment chips, limiting their functionality and vulnerability to man-in-middle attacks.

Innovation Solution

An authentication method and device that utilize a security environment chip and a fingerprint management chip to receive and process commands from an upper host, determining authentication modes based on preset values for fingerprint and key authentication identifiers, enabling multiple authentication methods while preventing man-in-middle attacks by setting authentication mode confirmation identifiers and performing signature operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware isolation characteristic of security environment chip is used, then security and reliability are improved, but adaptability and functionality are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication modes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a command parsing mechanism as an intermediary layer between the upper host and the security environment chip. This intermediary interprets different authentication mode commands and translates them into appropriate operations, enabling the hardware-isolated security chip to support multiple authentication modes without compromising its security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication device achieves multi-functionality by implementing a unified command processing architecture that can handle both fingerprint authentication and key authentication modes. The same security environment chip performs different authentication functions based on command parameters, eliminating the need for separate hardware modules for each authentication type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple authentication modes are implemented, then adaptability and functionality are improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication modesVSAvoidauthentication device
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct modular components: command parsing module, fingerprint authentication module, key authentication module, and signature generation module. Each module handles a specific authentication function independently, making the overall system more manageable and easier to implement despite supporting multiple authentication modes.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11930118B2Authentication method and authentication device
Publication Date: 2024.03.12 FEITIAN TECHNOLOGIES CO LTD
  • US11930118B2 patent drawing
  • US11930118B2 patent drawing
  • US11930118B2 patent drawing

AI summary

An authentication method includes: receiving a command of an upper host; parsing an option parameter in the command; determining a value of a fingerprint authentication identifier in the option parameter, and if the value is a first preset value, prompting a user to input a fingerprint and verifying the fingerprint input to obtain a user operation verification result; if the value is a second preset value, prompting the user to press a key and verifying the key pressed to obtain a user operation verification result; determining the user operation verification result, and if the user operation verification result is success, setting an authentication mode confirmation identifier, obtaining client data from the command, generating data to be signed, signing the data to be signed to generate a signature result, sending the signature result to the upper host; if the user operation verification result is failure, reporting an error.