IC Card Mutual Authentication via Merged Communication Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authentication method between a SAM IC card and a user IC card is time-consuming and susceptible to external attacks due to a large number of communications, which reduces the throughput of the POS terminal and exposes secure data to potential risks.

Innovation Solution

The authentication method involves transmitting an identification number from the user IC card to the SAM IC card to derive a key, generating and storing an authentication number, encrypting it, and transmitting it back, allowing for simultaneous authentication of both IC cards with reduced communication steps.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the existing authentication method is used with multiple communication steps, then the authentication security is maintained, but the authentication time increases and terminal throughput decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple authentication operations into a single communication exchange. The first IC card transmits both its identification number and a random number simultaneously, while the second IC card returns both its identification number and an encrypted random number in one response. This merging of multiple authentication steps into a single exchange maintains security while significantly reducing authentication time and improving terminal throughput.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary actions by having the first IC card generate and transmit a random number before the actual authentication verification. This random number is then encrypted by the second IC card and returned, allowing the system to prepare authentication materials in advance and reduce the time needed for the actual authentication decision-making process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple communications are performed for authentication, then the authentication completeness is ensured, but the number of transmissions increases exposing data to external attacks

Engineering Contradiction:
Improveauthentication completenessVSAvoiddata exposure to external attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges multiple authentication communications into a single exchange where both IC cards simultaneously transmit their identification numbers and authentication data. This consolidation reduces the number of transmission cycles, thereby minimizing the window of opportunity for external attacks while maintaining complete authentication verification through the integrated exchange of identification numbers and encrypted random numbers.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If a large number of communications are performed for mutual authentication, then the authentication thoroughness is improved, but the terminal throughput is reduced

Engineering Contradiction:
Improveauthentication thoroughnessVSAvoidterminal throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines mutual authentication operations from both IC cards into a single simultaneous communication exchange. The first IC card transmits its identification number and random number while the second IC card transmits its identification number and encrypted random number in the same exchange cycle. This merging approach maintains thorough mutual authentication verification while doubling the terminal throughput capability by eliminating the sequential communication overhead.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8195941B2Authentication method for IC cards
Publication Date: 2012.06.05 STMICROELECTRONICS INT NV
  • US8195941B2 patent drawing
  • US8195941B2 patent drawing
  • US8195941B2 patent drawing

AI summary

An authentication method between a first IC card and a second IC card interconnected through a terminal includes transmitting an identification number from the second IC card to the first IC card for deriving and storing a key in the first IC card. An authentication number is generated and stored in the first IC card, and is transmitted to the second IC card. The authentication number is encrypted inside the second IC card, and is transmitted to the first IC card. The encrypted authentication number is decrypted through the derived key, and is compared with the authentication number. The second IC card is authorized if the encrypted authentication number in the first IC card is equal to the authentication number. At least one of the transmissions includes an identification and/or authentication number to authorize the first IC card from the second IC card. The identification and/or authentication numbers include a reverse authentication number.