External Secure Unit for Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication devices face security risks due to the vulnerability of storing identities and cryptological keys in insecure memory, leading to potential misuse or loss, especially since users often rely on weak or reused PINs and passwords for protection.

Innovation Solution

An external secure unit with a memory, processor, and contactless interfaces is introduced, which stores safety-relevant data and communicates securely with the device, using NFC, biometric features, and multiple interfaces to enhance security and convenience, such as a finger ring that permanently connects to a smartphone, providing secure authentication without the need for complex passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identities and cryptographic keys are stored in the unsecured memory of a mobile phone, then the device can access and use these credentials easily, but the security is compromised as data can be lost, compromised, or misused if the device is lost or accessed without authorization

Engineering Contradiction:
Improveease of access to credentialsVSAvoidsecurity of stored data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the mobile device into two separate components: an external secure unit (ESU) for storing security-relevant data and the main communication device for executing applications. This segmentation ensures that sensitive credentials are physically separated from the device's unsecured memory, allowing easy access through the ESU while maintaining high security through dedicated secure storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The external secure unit acts as an intermediary between the application program and the security credentials. Instead of applications directly accessing unsecured memory, they request credentials through the ESU, which mediates the access by verifying requests and providing authenticated data through secure interfaces (NFC, contactless, or contact-based).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PINs and passwords are used to protect secure devices, then unauthorized access can be prevented, but users can only remember a limited number of combinations and tend to use weak or reused passwords which are highly insecure

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoiduser memory and password strength
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention extracts the password/PIN verification function from the user's cognitive burden and relocates it to the external secure unit. The ESU stores multiple credential sets and handles authentication automatically, allowing users to access multiple services without remembering multiple passwords. The security protection is maintained through cryptographic verification within the ESU, while users only need to remember a single master credential or use biometric authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The external secure unit provides self-service authentication by automatically managing multiple credential sets and selecting the appropriate credentials based on the application's requirements. The ESU independently handles the complexity of credential management, including storing, protecting, and retrieving appropriate authentication data without requiring user intervention for each authentication event.

Inventive Principle:
Principle #25Self-service

3Reliability

If secure devices such as smart cards are carried separately, then security is improved, but the device can be forgotten or lost

Engineering Contradiction:
Improvesecurity through separate secure deviceVSAvoidloss or forgetting of secure device
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The invention merges the secure storage function with a wearable object (such as a finger ring, bracelet, or necklace) that the user constantly carries on their body. This combination ensures that the secure device cannot be forgotten or lost separately, as it is integrated into an item the user always wears. The wearable carrier provides both security through secure storage and prevents loss by being permanently attached to the user's person.

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides robust security by eliminating the need for complex passwords, allowing secure storage and transmission of sensitive data, preventing unauthorized access, and ensuring the external secure unit cannot be lost or stolen, as it is always connected to the user's body, thus enhancing user convenience and security.

Implementation Method 1

data is transmitted contactlessly between the communication device and the external secure unit... the external secure unit uses an NFC interface for communication with the communication device

Methodology Applied
Scientific EffectNFC (Near Field Communication): Electromagnetic Induction

Implementation Method 2

the external secure unit uses a vibration element. This allows the external secure unit to generate a signal by means of vibration when, for example, a transaction has been successfully executed

Methodology Applied
Scientific EffectVibration: Vibration

Data Source

PatentEP3025474B1External secure unit
Publication Date: 2020.04.08 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP3025474B1 patent drawingFigure 1
  • EP3025474B1 patent drawingFigure 2
  • EP3025474B1 patent drawingFigure 3

AI summary

The invention discloses a method for operating an external secure unit (2) that comprises at least one memory for storing data, a processor for processing the data, at least one interface for receiving data from a communication appliance (4) or sending data thereto, wherein the communication appliance (4) comprises at least one memory for storing at least one application program, a processor for processing and executing the application program, at least one first interface for sending data to the external secure unit (2) or receiving data therefrom, at least one second interface for sending data to a transmission network or receiving data therefrom, wherein the method is distinguished in that security-relevant data that are necessary for the execution of the application program in the communication appliance (4) are stored in the external secure unit (2) and the communication appliance (4) requests the security-relevant data from the external secure unit (2) in order to execute the application program.