Mobile Terminal Authentication Data Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face the challenge of managing multiple authentication data for various services, often resorting to using the same credentials for security reasons, which compromises access security, and existing solutions require dedicated hardware or smart cards that are not universally applicable.
Innovation Solution
A system that utilizes a mobile terminal with a security module, such as a SIM card, for managing authentication data, allowing secure storage and retrieval of credentials without the need for a dedicated card reader or specific device, using short messages for secure communication and user interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a smart card system is used to manage authentication data, then security is improved, but device complexity and portability requirements worsen
Solution Approach 1:
The patent applies universality by making the mobile terminal itself serve multiple functions: it acts as both the authentication data storage device (replacing the dedicated smart card) and the access device. The terminal's built-in security module handles authentication operations, eliminating the need for separate card readers and dedicated smart cards, thus reducing device complexity while maintaining security.
Solution Approach 2:
The mobile terminal performs self-service by autonomously managing its own authentication data storage and retrieval operations. The security module within the terminal handles encryption, data storage, and authentication protocols without requiring external hardware assistance, making the system self-sufficient and portable.
2Reliability
If a dedicated smart card and card reader are used, then authentication security is improved, but ease of operation worsens due to carrying requirements
Solution Approach 1:
The patent merges the functions of the smart card and card reader into a single integrated mobile terminal. The terminal's security module combines data storage, encryption, and authentication capabilities in one device, eliminating the need for users to carry separate smart cards and card readers, thus significantly improving ease of operation while maintaining authentication security.
Solution Approach 2:
The mobile terminal serves as a universal device that performs authentication data management, storage, and retrieval operations internally, making it portable and eliminating the need for additional hardware accessories that users would need to carry and manage.
3Ease of operation
If multiple authentication data are stored in memory, then convenience is improved, but security worsens due to storage vulnerabilities
Solution Approach 1:
The patent applies local quality by implementing different security characteristics for different data storage locations. Sensitive authentication data is stored encrypted in the terminal's security module with restricted access rights, while metadata and non-sensitive information can be stored in less secure locations. This differentiated security approach maintains convenience for data access while preserving security for critical authentication information.
Solution Approach 2:
The patent replaces mechanical security measures (physical card protection) with cryptographic security mechanisms. The security module uses encryption algorithms, digital signatures, and access control protocols to protect authentication data, providing robust security that cannot be compromised by physical theft or unauthorized access, thus maintaining both convenience and security.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
The invention relates to a system for management of authentication data received by SMS for access to a service for at least one set of data, comprising a device (10) for access to at least one service. According to the invention, the system further comprises: a mobile terminal (20) comprising means (210) for managing said set of authentication data and an identifier for said service, a communication interface (32) between said access device (10) and said management means (210), a software interface (31) for determining said service identifier and for operating said management means (210) through the communication interface (32) on access to said service. The above is of use or website access authorisation services.