Mutual Authentication Using One-Time Codes for Secure Device Personalization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a simplified mutual authentication technique that allows for secure personalization of transaction devices such as credit or debit cards, contactless payment devices, and identification devices in less secure environments, such as point-of-sale terminals, self-service kiosks, or over-the-air in portable devices, without compromising security.

Innovation Solution

The solution involves generating dynamic data, calculating authentication codes based on this data and stored key data, and using these codes for secure communication and personalization of the devices, ensuring that the encryption key is never exchanged between entities, thereby maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional centralized personalization with physical and logical controls is used, then security is ensured, but device complexity and operational ease deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidpersonalization process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical control system of centralized personalization facilities with an electronic cryptographic authentication system. The mutual authentication protocol using cryptographic check functions substitutes the physical presence and manual controls of traditional personalization centers, enabling secure key exchange and personalization data transmission through electronic channels without requiring physical security infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces cryptographic authentication codes and mutual verification mechanisms as intermediaries between the personalization facility and the transaction device. These authentication protocols act as mediators that verify identities and authorize data transmission, replacing the need for direct physical control and manual verification processes in traditional centralized systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional centralized personalization facilities are used, then security is maintained, but ease of operation and accessibility worsen

Engineering Contradiction:
ImprovesecurityVSAvoidpersonalization accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service personalization where the transaction device itself participates in the authentication and personalization process. The device can autonomously engage in mutual authentication protocols, verify cryptographic codes, and receive personalization data without requiring manual intervention at a centralized facility. This allows users to personalize devices remotely through automated electronic processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal authentication framework that can operate across multiple platforms and devices. The cryptographic mutual authentication protocol is device-agnostic and can be implemented in various transaction devices, personalization facilities, and communication channels, replacing the location-specific nature of traditional centralized personalization centers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If simplified authentication is implemented, then operational ease improves, but security may deteriorate

Engineering Contradiction:
Improvepersonalization process simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary authentication actions before personalization data is transmitted. The mutual authentication protocol establishes verified identities and authorized communication channels in advance, ensuring that subsequent personalization operations occur over secure, pre-validated connections. This preliminary verification layer maintains security while enabling simplified subsequent operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms through the mutual authentication protocol where both parties verify each other's credentials and authenticate codes. This bidirectional verification provides continuous security feedback, ensuring that personalization operations only proceed when authentication is confirmed, thereby maintaining security even in simplified automated processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8627080B2Systems and methods for mutual authentication using one time codes
Publication Date: 2014.01.07 MASTERCARD INT INC
  • US8627080B2 patent drawing
  • US8627080B2 patent drawing
  • US8627080B2 patent drawing

AI summary

Methods and systems for mutual authentication and personalizing a transaction device, such as a payment, transaction, or identity card. Successively generated one time codes are calculated by a first and second entity. One of the codes is transmitted to the second entity, which verifies the code is proper, then encrypts a second one time code using a third one time code and transmits the encrypted data to the first entity. The first entity decrypts the data using the third one time code, verifies the encrypted second one time code is proper, thereby mutually authenticating, and establishing a shared encryption key for subsequent communications, including transmission of personalization data.