Biometric Smart Card Reader for Secure PIN Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure device authentication methods, which rely on Personal Identification Numbers (PINs), are vulnerable to interception as PINs are transmitted in clear text or encrypted form between devices, providing multiple opportunities for attackers to intercept the PIN.

Innovation Solution

A biometric multi-factor authentication method using a fingerprint, where a fingerprint is used to decrypt and verify the PIN, reducing the need for explicit PIN entry and minimizing interception risks by using a smart card reader with a fingerprint sensor to encrypt and decrypt the PIN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PIN is transmitted through multiple software and hardware components, then authentication functionality is achieved, but the number of interception opportunities increases

Engineering Contradiction:
Improveauthentication functionalityVSAvoidinterception opportunities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the PIN from the transmission path by using a smart card with a keypad that directly inputs the PIN into the secure element of the smart card itself, eliminating the need for the PIN to traverse multiple software and hardware components in the primary device. This extraction of the PIN from the transmission path removes the interception opportunities while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card acts as an intermediary between the user and the authentication system. The user inputs the PIN on the smart card's keypad, and the PIN is processed within the smart card's secure element, which then communicates with the primary device. This intermediary approach isolates the PIN transmission within a secure boundary, preventing interception by external components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PIN is entered and transmitted through multiple components, then authentication is enabled, but device complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidnumber of components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the PIN input function, PIN processing function, and authentication function into a single smart card device. The smart card combines the keypad for PIN entry with a secure element that processes and stores the PIN, eliminating the need for separate components in the primary device. This consolidation reduces device complexity while maintaining authentication capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The smart card serves multiple functions: it acts as a storage medium for the PIN, a processing unit for authentication, and a communication interface with the primary device. This multi-functionality reduces the need for multiple separate components, simplifying the overall system architecture while enabling robust authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If biometric authentication is used, then interception risks are reduced, but the requirement for biometric enrollment and processing increases system complexity

Engineering Contradiction:
Improveinterception risksVSAvoidbiometric processing requirements
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The smart card serves as an intermediary that handles biometric data locally within its secure element. The biometric enrollment and processing occur within the smart card itself rather than requiring complex biometric processing infrastructure in the primary device. This intermediary approach reduces system complexity while maintaining security against interception.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2587400B1Simplified multi-factor authentication
Publication Date: 2017.02.15 BLACKBERRY LTD
  • EP2587400B1 patent drawingFigure 1
  • EP2587400B1 patent drawingFigure 2
  • EP2587400B1 patent drawingFigure 3

AI summary

A reader element is associated with an identity verification element. The reader element has a biometric input device and is configured, through enrollment of a biometric element, to encrypt a character sequence associated with the identity verification element. In a verification phase subsequent to the enrollment, a user may be spared a step of providing the character sequence by, instead, providing the biometric element. Responsive to receiving the biometric element, the reader element may decrypt the character sequence and provide the character sequence to the identity verification element.