PIN Input Unit Security via One-Way Function Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for inputting a credit card PIN require separate dedicated keyboards and displays, which hinder portability, increase manufacturing costs, and fail to authenticate the validity of program code, making them vulnerable to unauthorized access.

Innovation Solution

A method that calculates and compares one-way function values for the boot loader and operating system before and after activation, invalidating the PIN input unit's function if they differ, ensuring only authorized programs can access the PIN input unit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a PIN input dedicated keyboard and display apparatus are provided, then PIN code security is improved, but device portability deteriorates and manufacturing cost increases

Engineering Contradiction:
ImprovePIN code securityVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the PIN input function with the existing keyboard and display apparatus by validating their authenticity through one-way function values. This allows the shared keyboard and display to be used for both application programs and PIN input, eliminating the need for separate dedicated hardware while maintaining security through software-based authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The keyboard and display apparatus are designed to serve multiple functions: they can be used for general application program input/display and also for secure PIN code input when the authenticity validation passes. This multi-functionality resolves the contradiction by eliminating dedicated hardware while maintaining security through computational validation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If shared keyboard and display apparatus are used for PIN input, then device portability and manufacturing cost are improved, but security against unauthorized programs deteriorates

Engineering Contradiction:
Improvedevice structureVSAvoidPIN code security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent performs preliminary authentication of the keyboard and display apparatus authenticity before allowing them to be used for PIN input. The one-way function values are calculated and compared in advance to ensure the hardware is authorized, preventing unauthorized programs from accessing the PIN input function.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism using one-way function values that mediates between the shared keyboard/display hardware and the PIN input function. This intermediary layer authenticates the hardware's legitimacy before allowing access, thus enabling shared usage while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication processing is performed between client and server, then payment security is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvepayment securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service authentication where the additional function unit itself performs the authenticity validation using stored one-way function values. The validation is performed locally without requiring server communication, eliminating network dependency and reducing authentication time while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The one-way function values are pre-calculated and stored in the additional function unit during manufacturing. This preliminary preparation eliminates the need for real-time server authentication, allowing instant local validation and significantly reducing authentication processing time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8910242B2Enable/disable method of additional-function unit, system for same, program for same, as well as additional-function unit
Publication Date: 2014.12.09 NEC PLATFROMS LTD
  • US8910242B2 patent drawing
  • US8910242B2 patent drawing
  • US8910242B2 patent drawing

AI summary

The objective of the present invention is to disable functionality of an additional-function unit if an unauthorized program has been installed in an information processing device, thereby preventing an unauthorized program from acquiring, in an unauthorized manner, information from the additional-function unit. The present invention is an enable/disable method for an additional-function unit in an information processing device to which the additional-function unit has been added, which has a step for calculating a first directional function value on the basis of data included in a recording medium storing a boot loader and an operating system so as to store the first directional function value at manufacture time into the additional-function unit, a step for calculating a second directional function value on the basis of data included in the recording medium after the information processing device has been started up, and a step for disabling the functionality of the additional-function unit if the first directional function value and the second directional function value are different.