PIN Management with Reader Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems are vulnerable to password/PIN interception and lack the ability to manage and verify data objects securely, as they do not natively support dual-factor authentication and are susceptible to data object compromise during transmission or storage.

Innovation Solution

A system and method that alter and store data objects using personal identification numbers (PINs) without disclosing the PIN, allowing for secure verification and detection of data object integrity, using a PIN management module to create and compare altered representations of data objects, ensuring only authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a master list containing valid PIN numbers is maintained and compared to received PINs, then PIN verification capability is improved, but security is worsened as the master list becomes a honey pot target for malicious hackers

Engineering Contradiction:
ImprovePIN verification capabilityVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the PIN verification functionality from the centralized master list and distributes it to individual access control readers. Each reader stores only the data objects and their corresponding altered PIN representations locally, eliminating the need for a centralized master list that would be vulnerable to attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary transformation process where PINs are altered using a one-way function before storage. This intermediary step ensures that even if the stored data is compromised, the original PINs cannot be recovered, thus protecting against the honey pot vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If readers and credentials are equipped to manage multiple data objects and keep PINs inaccessible, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidreader and credential complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-altering PINs using a one-way function before they are stored alongside data objects. This preprocessing step ensures that PINs are automatically protected without requiring complex real-time verification mechanisms, thereby improving security while minimizing added complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of PIN storage by transforming PINs into altered representations through a one-way function. This parameter change allows PINs to be stored in an inaccessible form, providing security without requiring additional complex hardware or software mechanisms.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If dual-factor authentication is implemented by requiring both access credential and PIN, then security is improved, but susceptibility to PIN interception via keyboard loggers increases

Engineering Contradiction:
Improveauthentication securityVSAvoidPIN interception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary transformation layer where PINs are altered using a one-way function before storage and verification. This intermediary step ensures that even if PINs are intercepted during transmission or storage, they cannot be used to gain unauthorized access because the original PINs cannot be recovered from the altered representations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the potential harm of PIN interception into a benefit by using one-way functions. The interception of altered PINs is harmless because the original PINs cannot be recovered, thus turning a security vulnerability into a security feature.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10726160B2Localized pin management with reader verification and no disclosure
Publication Date: 2020.07.28 ASSA ABLOY AB
  • US10726160B2 patent drawing
  • US10726160B2 patent drawing
  • US10726160B2 patent drawing

AI summary

Mechanisms are provided to manage personal identification numbers and data objects residing in a communication system. In particular, solutions are described which allow a PIN associated with a data object to be stored with the data object for later authentication and verification purposes without disclosing the pin. In at least one embodiment, an operation is performed wherein a signature or digest of a data object is altered utilizing a user's entered pin. The altered signature is then stored. Upon verification and authentication, an operation is performed on the stored altered signature and the result is compared to a signature of the data object. If both signatures match, then the PIN can be used to authenticate and verify the data object.