IC Card Authentication State Management for Secure Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of IC cards without encryption processors poses security risks as the private key can remain in external devices, and those with encryption processors require the card to remain inserted for processing, leading to potential unauthorized use when the user is away.
Innovation Solution
An information processing apparatus with a user authentication unit, data processor, processing completion detector, and verification state changing unit that authenticates users, performs private key processing, and notifies users when the processing is complete, allowing the IC card to be safely removed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an encryption processor equipped IC card is used to enhance security by prohibiting private key readout, then security is improved, but the IC card must remain inserted in the device during processing which increases the risk of unauthorized use
Solution Approach 1:
The patent implements dynamic state management of the IC card authentication status. The authentication unit changes the authentication state based on processing completion status - maintaining authenticated state during processing and transitioning to unauthenticated state after completion. This dynamic adjustment resolves the contradiction by keeping the card inserted for security during processing while automatically reducing unauthorized use risk after processing ends.
Solution Approach 2:
The patent employs feedback mechanisms where the authentication unit continuously monitors the processing status and adjusts the authentication state accordingly. When processing is detected as complete, the system provides feedback to revoke authentication automatically. This feedback loop ensures that security is maintained during processing while preventing unauthorized use after processing completion.
2Ease of operation
If the IC card is removed after authentication to allow user mobility, then ease of operation is improved, but the private key processing cannot be completed and security is compromised
Solution Approach 1:
The patent implements preliminary notification to the user before authentication is revoked. The notification unit alerts the user that processing is complete and the card can be removed. This allows the user to plan their actions accordingly - either removing the card immediately or staying for brief notification periods. The preliminary action resolves the contradiction by providing user awareness and control over when to remove the card after processing completes.
Solution Approach 2:
The system provides self-service functionality where the authentication state is automatically managed based on processing status without requiring manual user intervention. The authentication unit automatically revokes access when processing completes, and the notification unit informs the user. This self-managed system resolves the contradiction by automatically balancing processing completion requirements with user mobility needs.
Data Source
AI summary
An information processing apparatus includes a user authentication unit that authenticates a user in a condition where an authentication medium used for authenticating the user is inserted, the authentication medium storing personal identification information of the user, a private key, and a software program for using the private key and including a processor for running the software program, to thereby establish a verified state in which the user is allowed to use the apparatus, a data processor that performs data processing including private key processing, a processing completion detector that detects completion of the private key processing performed by the data processor, and a verification state changing unit that changes, the verified state of the user having been established as a result of authenticating the user to a user unverified state based on detection of the completion of the private key processing in the processing completion detector.


