Contactless IC Card Password Management via Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing log-on systems using contactless IC cards require expensive special readers/writers for secure password management, as they need to write lockable keys, making secure password changes costly and inaccessible without specialized equipment.

Innovation Solution

A password management device with a password storage section, state information storage, and wireless communication capabilities that generates and writes new passwords without needing a special reader/writer, allowing secure password changes via a standard reader/writer and user instructions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a special reader/writer with writing lockable key function is used to ensure security, then password management security is improved, but device cost and complexity increase significantly

Engineering Contradiction:
Improvepassword management securityVSAvoidreader/writer complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the password storage and management function from the expensive special reader/writer device and relocates it to a standard IC card. This allows the IC card to independently manage passwords using its own storage resources, eliminating the need for complex special reader/writer equipment while maintaining security through the card's inherent storage capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The IC card performs self-service by storing and managing its own password data in its internal memory. The card can read and write password information using standard reader/writer equipment, making it self-sufficient for password management without requiring expensive specialized devices or complex external systems

Inventive Principle:
Principle #25Self-service

2Device complexity

If a standard reader/writer is used for password management, then device cost is reduced, but security is compromised due to inability to write lockable keys

Engineering Contradiction:
Improvereader/writer complexityVSAvoidpassword management security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent creates a copy of the password management functionality within the IC card itself. By storing password data directly in the card's memory, the system replicates the secure storage function that previously required expensive special reader/writer equipment, allowing standard readers to safely access the data without compromising security

Inventive Principle:
Principle #26Copying

3Ease of operation

If password changes are performed manually without automated generation, then operation simplicity is improved, but time consumption and labor requirements increase

Engineering Contradiction:
Improveoperation simplicityVSAvoidpassword change time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables automated password generation and management through the IC card's computational capabilities. The card can autonomously generate new passwords, manage password changes, and communicate with readers without requiring manual intervention or complex user operations, significantly reducing the time and effort needed for password management tasks

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7657532B2Password management device, password management method, and password management program
Publication Date: 2010.02.02 FUJITSU LTD
  • US7657532B2 patent drawing
  • US7657532B2 patent drawing
  • US7657532B2 patent drawing

AI summary

There is provided a password management device, password management method, and password management program to carry out secure logon. The management device includes: a first password storage region; a second password storage region; a password state information storage region that stores each of states of passwords as password state information; a wireless communication section that performs reading from the first password storage region and the second password storage region and performs reading from and writing into the password state information storage region, in accordance with an instruction from a PC via wireless communication with a reader/writer; and a contactless IC card control section that generates a new password if a change of a password registered in the PC to a new password is determined to be necessary, and writes the new password into a storage region different from another storage region of the registered password.