Dynamic Authentication Code Entry Device with Removable Capture Means

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication code entry devices are vulnerable to observation-based threats, as the mapping and coding of standard capture means are often predictable, allowing attackers to deduce the code through visual observation or data spying.

Innovation Solution

A device comprising a processing unit, display means, and a removable capture means, where the processing unit assigns characters to zones of the capture means in a dynamic and randomized manner, with a secure link and authentication protocols to ensure the integrity and authenticity of the input process, and a display representation of the assignment to inform the user without revealing the mapping to observers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard capture means with fixed mapping are used, then ease of operation is improved, but security against observation-based attacks deteriorates

Engineering Contradiction:
Improveease of inputVSAvoidvulnerability to observation attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic remapping of the capture means keyboard, where the mapping between physical keys and authentication code characters changes periodically or after each authentication attempt. This dynamic transformation prevents observers from correlating key positions with code characters across multiple attempts, thereby resolving the contradiction between maintaining ease of operation and preventing observation-based attacks.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If removable capture means provided by trusted issuer are used, then security against data spying is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against data spyingVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent divides the authentication system into separate components: a removable capture means (keyboard) provided by a trusted issuer and a processing unit. This segmentation allows the capture means to be independently authenticated and replaced, protecting against data spying while managing complexity through modular design where each component has a specific, simplified function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted issuer as an intermediary that provides and manages the removable capture means. This intermediary handles the complexity of secure key generation, distribution, and authentication, thereby protecting the main system from direct exposure to these complex security mechanisms while maintaining strong protection against data spying.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If dynamic random assignment of characters to zones is implemented, then security against observation is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveresistance to visual observationVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements periodic remapping of characters to keyboard zones, where the mapping changes at predetermined intervals or after a certain number of authentication attempts. This periodic transformation maintains security by preventing long-term observation correlation, while the predictable timing allows users to adapt and maintain ease of operation through repeated exposure to the same mapping patterns.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP2804125B1Device for entering an authentication code
Publication Date: 2017.04.26 OBERTHUR TECH SA
  • EP2804125B1 patent drawingFigure 1~3
  • EP2804125B1 patent drawingFigure 4~6

AI summary

Device (1) for entering an authentication code, comprising a processing unit (2), a display means (3) connected to the processing unit (2) and a capture means (4) connectable to the processing unit (2), where the capture means (4) is removable and supplied by a trusted issuer.