Dynamic PIN Generation for Hardware Token Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing magnetic stripe and chip cards do not allow PIN changes, leading to increased security risks as the PIN remains constant, making it vulnerable to unauthorized access over time.

Innovation Solution

A password management system that enables PIN changes by storing a change value on the hardware token or in a database, using it to determine a new PIN through a hash function, allowing for individual PIN validity periods based on PIN quality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a constant PIN is assigned to a hardware token for authentication, then the authentication system is simple to operate, but the security risk increases over time as the PIN remains vulnerable to unauthorized access

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from a static PIN to a dynamic PIN that changes over time. The system generates time-limited PINs that are valid only for specific time windows or transaction instances, making the authentication credential dynamic rather than constant. This resolves the contradiction by maintaining operational simplicity while enhancing security through temporal validity constraints.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of PIN validity from indefinite to time-limited. By introducing temporal parameters (expiration times, valid time windows) to the PIN system, the patent enables PINs to automatically become invalid after certain conditions are met. This parameter change allows the system to maintain ease of use while reducing long-term security risks through automatic expiration.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a PIN is derived from constant data on the hardware token using a cryptographic process, then the PIN generation is secure, but the PIN cannot be changed by the customer

Engineering Contradiction:
ImprovePIN generation securityVSAvoidPIN changeability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-generating multiple potential PINs or pre-establishing PIN generation rules during token initialization. The system prepares advance PIN candidates or cryptographic templates that can be used to generate valid PINs at different time points, enabling customers to obtain new PINs without requiring complex cryptographic operations or system reconfiguration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (such as a key derivation function with changing inputs or a PIN generation algorithm that accepts time parameters) between the constant token data and the PIN output. This intermediary layer allows the same underlying cryptographic material to produce different PINs at different times, enabling PIN changes while maintaining cryptographic security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If the PIN validity period is unlimited or only limited by card validity, then the customer receives a stable authentication credential, but the risk of PIN compromise increases with prolonged use

Engineering Contradiction:
ImprovePIN stabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent applies periodic action by implementing time-limited PIN validity periods. PINs are generated with expiration times or valid time windows, requiring periodic regeneration. This periodic renewal mechanism maintains authentication stability within each validity period while reducing long-term security risks by limiting the window of opportunity for unauthorized access.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent changes the validity parameter of the PIN from unlimited to time-bound. By introducing temporal constraints (expiration dates, valid time windows, usage counters) as parameters, the system creates PINs that automatically become invalid after meeting certain temporal conditions. This parameter change enables the system to provide stable authentication during the validity period while inherently limiting exposure to unauthorized access risks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2281259B1Variable pin for hardware token
Publication Date: 2013.04.03 DEUTSCHE TELEKOM AG
  • EP2281259B1 patent drawingFigure 1
  • EP2281259B1 patent drawingFigure 2
  • EP2281259B1 patent drawing

AI summary

Password management system for changing and checking of a password and allocation of this password to a hardware token, in particular magnetic strip card and/or chip card, wherein the password is used for authentication of the hardware token with respect to a technical system, wherein the password is a personal identification number PIN and wherein the PIN can be determined by means of an algorithm from data which are read out from the hardware token, wherein to change the original PIN into a new PIN, a change value is saved in the password management system and/or is saved in a readable manner on the hardware token and is used to determine the new PIN by means of the same or another algorithm.