Contactless Smart Card Password Generation With Verifiable Randomness
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional password managers are vulnerable to brute-force attacks, require users to remember a master password, and may not generate verifiably random passwords, with the risk of data exposure due to device dependency and weak master password security.
Innovation Solution
Utilizing a near-field communication (NFC) enabled contactless smart card to generate and manage secure passwords through a random number generator or cryptographic hash function, converting outputs to human-readable characters, and optionally transforming them for added security, with the card acting as a 'master' password for the password manager application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a conventional password manager uses a master password for access, then the system can be operated with simple authentication, but the security is compromised because the master password may be weak or remembered incorrectly
Solution Approach 1:
The patent replaces the mechanical/mental process of remembering and typing a master password with a contactless NFC card authentication system. The card uses NFC technology to establish secure communication with the password manager application, eliminating the need for users to remember complex master passwords while maintaining strong security through physical possession of the card.
Solution Approach 2:
The NFC card acts as an intermediary between the user and the password manager system. Instead of directly providing a master password, the card mediates the authentication process by establishing secure communication channels and enabling access without requiring the user to recall or type a master password, thus simplifying operation while maintaining security.
2Adaptability or versatility
If a password manager stores passwords in an encrypted database, then password management is centralized, but the system becomes device-dependent and vulnerable to data exposure
Solution Approach 1:
The patent extracts the password storage function from centralized databases and distributes it to individual users through NFC cards. Each card contains or references encrypted password data specific to that user, eliminating the centralized database that could be exposed to hackers. Passwords are taken out of the central system and embedded in secure, user-specific cards.
Solution Approach 2:
Instead of maintaining a single centralized copy of password data, the system creates multiple secure copies distributed across different NFC cards. Each card holds encrypted password information that can be accessed independently, ensuring that if one card is compromised, other passwords remain secure. This distributed copying approach eliminates the single point of failure in centralized databases.
3Ease of manufacture
If a password generator uses conventional algorithms, then password generation is simple, but the randomness cannot be verified and passwords may not be sufficiently secure
Solution Approach 1:
The patent replaces conventional software-based random number generation with hardware-based random number generators (RNG) embedded in the NFC cards. These hardware RNGs utilize physical processes to generate truly random numbers that can be cryptographically verified. The hardware-based approach provides verifiable randomness while maintaining simple operation for the end user.
Solution Approach 2:
The NFC cards perform self-service by generating their own random passwords using embedded hardware random number generators. The cards autonomously create secure passwords without requiring external intervention or complex configuration, while the randomness can be verified through cryptographic protocols built into the card system.
4Reliability
If users must physically possess devices to access password managers, then security is improved, but convenience is reduced and access becomes difficult
Solution Approach 1:
The NFC cards serve multiple functions: they act as authentication credentials, password storage containers, and access keys for the password manager application. This multi-functionality consolidates what would otherwise require separate devices and operations into a single card, improving both security through physical possession requirements and convenience through unified access.
Solution Approach 2:
The patent replaces complex device-based authentication systems with simple NFC card tapping. Instead of requiring users to remember master passwords, enter PINs, or authenticate through multiple factors across different devices, users simply tap their NFC card against a reader to access their password manager, significantly improving convenience while maintaining security.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Provides highly secure, verifiable, and device-independent password generation and management, minimizing exposure by generating unique passwords without storage and requiring physical possession of the card for access, thus enhancing security against hacking.
Implementation Method 1
a near-field communication (NFC) enabled contactless smart card
Data Source
AI summary
Various embodiments are directed to securely generating and managing passwords using a near-field communication (NFC) enabled contactless smart card. For example, a secure password may be generated by generating a random number via a random number generator of the contactless smart card and converting the random number to one or more human-readable characters. In another example, a secure cryptographic hash function of the contactless smart card may generate a hash output value, which may be converted to one or more human-readable characters. The human-readable characters may be used as the secure password or it may be transformed to add more layers of security and complexity.


