IC Chip Authentication for Online Service Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current transaction authentication methods, such as those using hardware tokens, are inconvenient for users, particularly when using portable devices, and impose a significant cost burden on service providers, while also being vulnerable to theft and loss, and do not effectively defend against Man-In-The-Browser attacks.
Innovation Solution
A system that employs a portable device with an IC chip for user authentication and electronic signatures, allowing secure online service use through an intermediate service provider, reducing the need for physical tokens and enhancing security between multiple parties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware tokens are used for transaction authentication, then security against MITM attacks is improved, but user convenience deteriorates and device complexity increases
Solution Approach 1:
The patent combines the authentication function with the mobile device itself by utilizing the device's existing components (camera, display, processor) rather than requiring a separate hardware token. The authentication application integrates multiple functions including capture of authentication data, generation of one-time passwords, and display of verification information all within a single mobile device interface.
Solution Approach 2:
The mobile device serves multiple purposes: it acts as both the user interface and the authentication mechanism. The device can be used for general communication purposes while simultaneously providing secure authentication capabilities through the integrated application, eliminating the need for dedicated authentication hardware.
2Reliability
If hardware tokens are distributed to all users, then authentication security is improved, but service provider cost increases
Solution Approach 1:
Instead of distributing physical hardware tokens to each user, the patent uses software-based authentication that can be replicated and deployed digitally across multiple users. The authentication logic and security mechanisms are copied as software code rather than requiring physical manufacturing and distribution of hardware devices.
Solution Approach 2:
The software-based authentication solution replaces expensive, durable hardware tokens with inexpensive software implementations that can be easily updated, revoked, or replaced without physical logistics. The authentication credentials can be generated and invalidated at will through software control.
3Ease of operation
If one-time password issuers are used, then basic authentication is enabled, but defense against MITB attacks deteriorates
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the mobile device captures authentication data (such as a displayed code or image) from an intermediate source, processes it through the application, and generates a derived one-time password. This intermediate capture and processing step adds a layer of verification that prevents direct interception of authentication credentials.
Solution Approach 2:
The mobile device application performs preliminary processing of authentication data by capturing and storing reference information before the actual authentication transaction occurs. This preliminary action includes capturing display content, generating cryptographic keys, and preparing verification data in advance, which enables detection of man-in-the-browser attacks during the transaction.
Data Source
AI summary
When a user attempts to execute a procedure for transfer or the like from an app, user authentication is first required by a PIN code or the like. When the user authentication is successful, function limitation of an IC chip is released and a mode in which a function provided by the IC chip can be used is set. The app encrypts a procedure message describing procedure content with a private key using the function of the IC chip and creates electronic signature. The electronic signature and the procedure message are transmitted to a server of an online service via an intermediate server. The server executes a procedure of transfer or the like in accordance with the content of the procedure message.


