Hybrid Authentication Token with Keypad and Display

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication tokens, whether hardware or software, lack the capability to securely store and provide sensitive information and cannot communicate electronically with other entities, limiting their functionality and security.

Innovation Solution

A smartcard token with a keypad and display that combines the portability of stand-alone hardware tokens with the processing power and memory of smartcards, featuring a secure processor and memory with tamper-resistant measures, allowing for both smartcard and stand-alone token functionalities, including PIN-based authentication and digital signature verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If stand-alone hardware tokens are used for authentication, then portability and authentication capability are improved, but the ability to securely store and provide sensitive information and electronic communication capability deteriorates

Engineering Contradiction:
ImproveportabilityVSAvoidelectronic communication capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent combines the portability of stand-alone hardware tokens with the electronic communication and data storage capabilities of smart cards into a single integrated device. The token includes both authentication generating capabilities and smart card functionality with electronic communication interfaces, allowing it to both authenticate users and securely transmit sensitive information electronically.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated token serves multiple functions: it generates authentication codes like traditional hardware tokens, stores sensitive information securely like smart cards, and provides electronic communication capabilities through multiple interfaces. This multi-functional design resolves the contradiction by making a single device adaptable to various authentication and data transmission scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If smartcard functionality is added to provide processing power and memory, then secure storage and communication capabilities are improved, but device complexity increases

Engineering Contradiction:
Improvesecure storage capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges smart card components (processor, memory, communication interfaces) with hardware token functionality into a single integrated device. This consolidation provides secure storage and electronic communication capabilities while managing complexity through integrated design rather than separate components.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If software tokens are used to reduce hardware complexity, then device complexity is reduced, but security deteriorates due to platform dependency

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent combines software-based authentication algorithms with hardware-based security features in a single integrated token. The device includes tamper-resistant measures and secure elements that protect the software components, providing security comparable to hardware tokens while maintaining the flexibility of software implementation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9240891B2Hybrid authentication
Publication Date: 2016.01.19 GEN DIGITAL INC
  • US9240891B2 patent drawing
  • US9240891B2 patent drawing

AI summary

A hybrid authentication device that has a keypad, a display, an electronic communications interface and a processor and memory that can be removable, such as a Subscriber Identity Module. The device can operate in a stand-alone mode, in which a user enters a personal identification number and challenge using the keypad, and the device generates a response. The device can also function as a smartcard, and can be electronically coupled to an external device using the communications interface.