Dynamic Pairing Device for Secure Contactless Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Smart cards with contactless communication struggle to discriminate between multiple computers in a multi-computer environment, leading to unauthorized connections when the card is within range of several devices.
Innovation Solution
A dynamic pairing system utilizing capacitive coupling and radiofrequency communication, where the memory card is worn close to the body, using the human body as an antenna to establish a secure communication channel between a badge holder and a computer-connected base, ensuring secure and targeted connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless communication is used for memory card authentication, then user convenience is improved (no need to insert card into reader), but security is worsened (card can be read by multiple computers within range)
Solution Approach 1:
The system performs preliminary pairing between the memory card and computer before authentication. This pairing creates a pre-established trusted relationship stored in both devices, so that when the card is later presented for authentication, the computer can verify it is an authorized device. This preliminary action resolves the contradiction by maintaining convenience while ensuring security through pre-validated device relationships.
Solution Approach 2:
The system implements feedback mechanisms where the computer and memory card exchange and verify pairing identifiers during the authentication process. The computer checks whether the presented card matches its paired card through cryptographic verification of identifiers. This feedback loop ensures that even though contactless communication allows multiple computers to detect the card, only the paired computer can successfully authenticate, thus resolving the security concern while maintaining operational convenience.
2Ease of operation
If the memory card is worn close to the body for contactless communication, then ease of operation is improved (card always accessible), but unauthorized access risk increases (card within range of multiple computers)
Solution Approach 1:
The system establishes a preliminary paired relationship between the memory card and the authorized computer before authentication occurs. This pairing information is stored in both devices, creating a trusted connection. When the user wears the card close to their body and approaches any computer, the authentication process verifies whether the computer is the paired authorized device. This resolves the contradiction by allowing constant card accessibility while preventing unauthorized access through cryptographic verification of the pre-established relationship.
Solution Approach 2:
The system introduces pairing identifiers and cryptographic verification mechanisms as intermediaries between the memory card and computer. These intermediaries act as mediators that verify the authenticity of the connection without requiring physical proximity constraints. The pairing identifier serves as a digital mediator that ensures only the authorized computer can communicate with the card, thus resolving the contradiction between constant accessibility and unauthorized access prevention.
3Reliability
If dynamic pairing system with capacitive coupling and radiofrequency communication is implemented, then connection security is improved (discriminating between computers), but device complexity increases (multiple communication channels and protocols)
Solution Approach 1:
The system segments the authentication process into distinct phases: pairing phase and authentication phase. During pairing, cryptographic keys and identifiers are exchanged and stored. During authentication, these pre-established credentials are verified. This segmentation allows the system to implement robust security measures without requiring complex real-time decision-making, as the heavy cryptographic work is done during the initial pairing phase. This resolves the contradiction by maintaining high security while reducing operational complexity through process separation.
Solution Approach 2:
The system performs preliminary cryptographic key exchange and pairing identifier establishment before the actual authentication occurs. This preliminary action stores trusted relationship information in both the memory card and computer, so that subsequent authentication can proceed with simpler verification steps. By moving the complex cryptographic operations to the preliminary pairing phase, the system achieves high connection security while keeping the authentication phase relatively simple, thus resolving the contradiction between security and complexity.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure and discriminate connections between the memory card and the intended computer, eliminating unauthorized access by requiring a voluntary human act to initiate communication, thus ensuring secure authentication and session opening.
Implementation Method 1
Said first communication channel is advantageously implemented in the form of a capacitive coupling via a human body between said second device and said first device
Implementation Method 2
The second communication channel is advantageously a radio frequency channel, the frequency of which is, for example, in an ISM band
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Device for dynamic pairing between a first peripheral (1) that can dialogue with a memory card (3) and a second peripheral (2) connected to a computer (4), characterized in that said first peripheral comprises means: able to read the data contained in said memory card and able to receive via a first communication channel (C_BF) a first item of information (ID_BASE) emitted by said second peripheral and able to emit via a second communication channel (C_HF) a second item of information (ID_PB), and in that said second peripheral (2) comprises means: able to emit via said first communication channel (C_BF) said first item of information (ID_BASE) and able to receive via said second communication channel (C_HF) said second item of information (ID_PB), the value of this second item of information (ID_PB) conditioning the authorization to open a bidirectional communication channel (C_B) between said first and said second peripherals.