PIN Management with Reader Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control systems are vulnerable to password/PIN interception and lack the ability to manage and verify data objects securely, as they do not natively support dual-factor authentication and are susceptible to data object compromise during transmission or storage.
Innovation Solution
A system and method that alter and store data objects using personal identification numbers (PINs) without disclosing the PIN, allowing for secure verification and detection of data object integrity, using a PIN management module to create and compare altered representations of data objects, ensuring only authorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a master list containing valid PIN numbers is maintained and compared to received PINs, then PIN verification capability is improved, but security is worsened as the master list becomes a honey pot target for malicious hackers
Solution Approach 1:
The patent extracts the PIN verification functionality from the centralized master list and distributes it to individual access control readers. Each reader stores only the data objects and their corresponding altered PIN representations locally, eliminating the need for a centralized master list that would be vulnerable to attacks.
Solution Approach 2:
The patent introduces an intermediary transformation process where PINs are altered using a one-way function before storage. This intermediary step ensures that even if the stored data is compromised, the original PINs cannot be recovered, thus protecting against the honey pot vulnerability.
2Reliability
If readers and credentials are equipped to manage multiple data objects and keep PINs inaccessible, then data security is improved, but device complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-altering PINs using a one-way function before they are stored alongside data objects. This preprocessing step ensures that PINs are automatically protected without requiring complex real-time verification mechanisms, thereby improving security while minimizing added complexity.
Solution Approach 2:
The patent changes the parameter of PIN storage by transforming PINs into altered representations through a one-way function. This parameter change allows PINs to be stored in an inaccessible form, providing security without requiring additional complex hardware or software mechanisms.
3Reliability
If dual-factor authentication is implemented by requiring both access credential and PIN, then security is improved, but susceptibility to PIN interception via keyboard loggers increases
Solution Approach 1:
The patent introduces an intermediary transformation layer where PINs are altered using a one-way function before storage and verification. This intermediary step ensures that even if PINs are intercepted during transmission or storage, they cannot be used to gain unauthorized access because the original PINs cannot be recovered from the altered representations.
Solution Approach 2:
The patent converts the potential harm of PIN interception into a benefit by using one-way functions. The interception of altered PINs is harmless because the original PINs cannot be recovered, thus turning a security vulnerability into a security feature.
Data Source
AI summary
Mechanisms are provided to manage personal identification numbers and data objects residing in a communication system. In particular, solutions are described which allow a PIN associated with a data object to be stored with the data object for later authentication and verification purposes without disclosing the pin. In at least one embodiment, an operation is performed wherein a signature or digest of a data object is altered utilizing a user's entered pin. The altered signature is then stored. Upon verification and authentication, an operation is performed on the stored altered signature and the result is compared to a signature of the data object. If both signatures match, then the PIN can be used to authenticate and verify the data object.


