Authentication Device Using Intermediary Adapter for Cryptographic Scheme Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems, such as the Chip Authentication Program (CAP), are proprietary and not compatible with other systems, limiting the use of standard CAP card readers and requiring costly tokens for generating one-time-passwords (OTPs).

Innovation Solution

A custom chip-card is designed to generate OATH-compatible OTPs using standard CAP card readers, allowing the use of existing infrastructure and reducing costs by leveraging deployed card readers, and implementing algorithm substitution in card and reader-based one-time-password devices to work with various cryptographic schemes like RSA SecureID, VASCO DigiPass, and ActivIdentity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary token devices are used for generating OTPs, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidtoken device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component - a software layer or adapter that sits between the simple card reader and the authentication server. This intermediary handles the cryptographic scheme translation, allowing the simple card reader to work with multiple authentication schemes (OATH, CAP, RSA SecureID, VASCO DigiPass) without requiring complex hardware tokens. The intermediary performs the complex cryptographic operations that would otherwise require sophisticated token devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/hardware-based proprietary token devices with a software-based solution. Instead of requiring specialized hardware tokens with proprietary cryptographic engines, the system uses standard card readers combined with software that implements the necessary cryptographic schemes. This substitution reduces device complexity while maintaining security through software-based cryptographic processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If proprietary cryptographic schemes are implemented, then system security is improved, but adaptability and compatibility worsen

Engineering Contradiction:
Improvecryptographic securityVSAvoidcryptographic scheme compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication system where a single card reader device can support multiple cryptographic schemes (OATH, CAP, RSA SecureID, VASCO DigiPass, ActivIdentity). The system achieves this through software that can dynamically select and implement the appropriate cryptographic scheme based on the authentication server being used. This multi-functionality allows the same hardware infrastructure to work across different security domains without requiring scheme-specific hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes to adapt the cryptographic processing. By changing software parameters and configuration settings, the system can switch between different cryptographic schemes. The underlying hardware remains the same, but the cryptographic parameters, algorithms, and processing modes are dynamically adjusted to match the requirements of the target authentication scheme, enabling compatibility across multiple standards.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If standard card readers are used for OTP generation, then device cost is reduced, but manufacturing precision and reliability worsen

Engineering Contradiction:
Improvecard reader costVSAvoidOTP generation reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a software intermediary that compensates for the limitations of standard card readers. This intermediary layer handles the complex cryptographic operations and ensures reliable OTP generation, even though the underlying hardware is a simple, mass-produced card reader. The intermediary performs error handling, cryptographic processing, and protocol management that would be required for reliable operation, effectively masking the limitations of the inexpensive hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7882553B2Authentication device and method
Publication Date: 2011.02.01 CRYPTOMATHIC LTD
  • US7882553B2 patent drawing
  • US7882553B2 patent drawing
  • US7882553B2 patent drawing

AI summary

An apparatus for generating intermediate cryptogram data corresponding to a dynamic password for a first cryptographic scheme, the intermediate cryptogram data being suitable for display using a device designed for a second, different cryptographic scheme, the apparatus including: a communications interface for communicating with a said device; and a processor coupled to a memory, the memory storing processor control code to control the processor, when running, to: generate a dynamic password according to the first cryptographic scheme; and generate intermediate cryptogram data corresponding to said dynamic password, the intermediate cryptogram data being suitable for outputting to the said device so that, when the said device processes said intermediate cryptogram data according to the second cryptographic scheme, the said device generates data suitable for displaying said dynamic password.