Mutual Authentication Using One-Time Codes for Secure Device Personalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for a simplified mutual authentication technique that allows for secure personalization of transaction devices such as credit or debit cards, contactless payment devices, and identification devices in less secure environments, such as point-of-sale terminals, self-service kiosks, or over-the-air in portable devices, without compromising security.
Innovation Solution
The solution involves generating dynamic data, calculating authentication codes based on this data and stored key data, and using these codes for secure communication and personalization of the devices, ensuring that the encryption key is never exchanged between entities, thereby maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional centralized personalization with physical and logical controls is used, then security is ensured, but device complexity and operational ease deteriorate
Solution Approach 1:
The patent replaces the mechanical/physical control system of centralized personalization facilities with an electronic cryptographic authentication system. The mutual authentication protocol using cryptographic check functions substitutes the physical presence and manual controls of traditional personalization centers, enabling secure key exchange and personalization data transmission through electronic channels without requiring physical security infrastructure.
Solution Approach 2:
The patent introduces cryptographic authentication codes and mutual verification mechanisms as intermediaries between the personalization facility and the transaction device. These authentication protocols act as mediators that verify identities and authorize data transmission, replacing the need for direct physical control and manual verification processes in traditional centralized systems.
2Reliability
If traditional centralized personalization facilities are used, then security is maintained, but ease of operation and accessibility worsen
Solution Approach 1:
The patent enables self-service personalization where the transaction device itself participates in the authentication and personalization process. The device can autonomously engage in mutual authentication protocols, verify cryptographic codes, and receive personalization data without requiring manual intervention at a centralized facility. This allows users to personalize devices remotely through automated electronic processes.
Solution Approach 2:
The patent creates a universal authentication framework that can operate across multiple platforms and devices. The cryptographic mutual authentication protocol is device-agnostic and can be implemented in various transaction devices, personalization facilities, and communication channels, replacing the location-specific nature of traditional centralized personalization centers.
3Ease of operation
If simplified authentication is implemented, then operational ease improves, but security may deteriorate
Solution Approach 1:
The patent performs preliminary authentication actions before personalization data is transmitted. The mutual authentication protocol establishes verified identities and authorized communication channels in advance, ensuring that subsequent personalization operations occur over secure, pre-validated connections. This preliminary verification layer maintains security while enabling simplified subsequent operations.
Solution Approach 2:
The patent implements feedback mechanisms through the mutual authentication protocol where both parties verify each other's credentials and authenticate codes. This bidirectional verification provides continuous security feedback, ensuring that personalization operations only proceed when authentication is confirmed, thereby maintaining security even in simplified automated processes.
Data Source
AI summary
Methods and systems for mutual authentication and personalizing a transaction device, such as a payment, transaction, or identity card. Successively generated one time codes are calculated by a first and second entity. One of the codes is transmitted to the second entity, which verifies the code is proper, then encrypts a second one time code using a third one time code and transmits the encrypted data to the first entity. The first entity decrypts the data using the third one time code, verifies the encrypted second one time code is proper, thereby mutually authenticating, and establishing a shared encryption key for subsequent communications, including transmission of personalization data.


