Dynamic Password Generation for IC Card Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional IC cards rely on static passwords, making them vulnerable to fraud if the password is leaked, as they do not dynamically change the authentication password, thereby lacking robust security measures.
Innovation Solution
An IC card system that includes a generation unit to create a dynamic authentication password based on a stored password, a predetermined parameter, and an algorithm, and an authentication unit to compare an input password with the generated password, ensuring the card holder's validity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static password is used for authentication, then the system is simple to operate, but the security is weak and vulnerable to fraud
Solution Approach 1:
The patent implements dynamic password generation where the authentication password changes over time or with each authentication attempt. The generation unit creates a new password based on the stored password and a changing parameter (such as time or counter value), making the authentication mechanism dynamic rather than static. This resolves the contradiction by enhancing security through password variability while maintaining operational simplicity for the user.
Solution Approach 2:
The system changes the password parameter dynamically by combining a stored base password with a changing parameter (time, counter, or other variable). The generation unit produces different password values based on these parameter changes, allowing the same IC card to provide different authentication credentials at different times or conditions, thereby improving security without complicating the user interface.
2Reliability
If a dynamic password is generated and compared, then the security is improved, but the authentication process becomes more complex
Solution Approach 1:
The IC card itself performs the password generation and comparison operations autonomously. When the user presents the IC card, the card's generation unit automatically creates the current password and the comparison unit verifies it against the input, without requiring the user to manually generate or remember multiple passwords. This self-service approach improves security through dynamic authentication while maintaining ease of operation for the end user.
Solution Approach 2:
The patent introduces a terminal device as an intermediary that facilitates the authentication process. The terminal communicates with the IC card, receives the generated password, and handles the comparison process. This intermediary simplifies the user's task by managing the complexity of dynamic password verification in the background, allowing users to simply present their card while the system handles the secure authentication mechanics.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
Provided are an IC card, an IC module and an IC card system that can improve the security. An IC card of embodiments has a generation unit and an authentication unit. The generation unit generates a second password that is a password for authenticating a card user based on a first password stored in a storage unit in advance, a predetermined parameter and a predetermined algorithm. The authentication unit compares a third password acquired from an external apparatus and provide second password, and determines the validity of the card user based on the comparison result.