Battery-Free Security Token Using Wireless Energy Harvesting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security tokens require a battery to maintain a common time base with authentication servers, which limits their functionality and increases complexity, and they often require a direct connection between the terminal and authentication server, making them vulnerable to 'man in the middle' attacks.

Innovation Solution

A security token that uses a wireless interface to receive electrical energy from a terminal, such as a smartphone, and generates one-time passwords (OTPs) through cryptographic derivation using first and second data stored in its electronic memory, eliminating the need for a battery and allowing for secure authentication without a direct connection to the authentication server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a battery is used to maintain a common time base with the authentication server, then the security token can generate constantly changing passwords synchronously, but the device complexity and power requirements increase

Engineering Contradiction:
Improvesynchronous password generationVSAvoidbattery requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the time base maintenance function from the security token by implementing a state machine that generates timestamps purely from internal state transitions and counter increments. This eliminates the battery requirement while maintaining synchronous password generation capability through algorithmic time derivation rather than physical time synchronization.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the fundamental parameter of timekeeping from continuous battery-powered clock synchronization to discrete state-based timestamp generation. The state machine transitions through defined states and increments counters to generate monotonically increasing timestamps, transforming the time base from a continuous physical phenomenon to a discrete computational sequence.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If a direct connection between terminal and authentication server is required, then real-time authentication is possible, but the system becomes vulnerable to man in the middle attacks

Engineering Contradiction:
Improvereal-time authenticationVSAvoidman in the middle attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the OTP value as an intermediary that carries authentication information without requiring direct real-time communication between terminal and server. The OTP encapsulates the authentication state and can be transmitted through potentially insecure channels while maintaining security, as it is derived from secret data and timestamps rather than requiring active connection verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary authentication by generating the OTP value in advance based on secret data and current timestamp, before actual authentication occurs. This allows the authentication information to be prepared and transmitted separately from the authentication event itself, decoupling the timing requirements and reducing vulnerability to interception attacks.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If cryptographic derivation uses only secret data and timestamp, then security is enhanced, but the OTP may not be unique across different authentication instances

Engineering Contradiction:
Improvesecurity against attacksVSAvoidOTP uniqueness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements dynamics by making the OTP generation dependent on the current timestamp value, which continuously changes. The state machine transitions through different states and increments counters based on time progression, ensuring that even with the same secret data, each authentication instance produces a unique OTP due to the changing temporal parameter.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary counter incrementing and state transitions before generating the OTP value. This ensures that each authentication request operates on updated internal state, guaranteeing uniqueness of the generated OTP even when derived from the same secret data, by incorporating the progression of time through counter values.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2909779B1Method for generating a one-time-password (OTP)
Publication Date: 2019.12.04 BUNDESDRUCKEREI GMBH
  • EP2909779B1 patent drawingFigure 1
  • EP2909779B1 patent drawingFigure 2
  • EP2909779B1 patent drawingFigure 3

AI summary

The invention relates to a method for generating an OTP using a security token (106) for authentication with respect to an authentication module (184). The security token has an electronic memory (118) which only a processor (128) of the security token can access, first (160) and second (162) data being stored in said electronic memory and in addition, a version of the first data and the second data being stored in a database (188).