Secure PIN Character Retrieval via Hardware Security Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for accessing or modifying a personal identification number (PIN) associated with a financial account are inefficient, as they require generating and mailing a new PIN, leading to delays and confusion, especially with the rise of online banking, where immediate access is necessary.

Innovation Solution

A system and method that allows account holders to securely retrieve or modify their PIN using a hardware security module (HSM) through a web browser or interactive voice response (IVR) interface, where the PIN is decrypted and encrypted one character at a time, providing secure access and validation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a new PIN is generated and mailed to the customer via PIN mailer, then the customer receives a new PIN securely, but the process is expensive and leaves the card unusable until the new PIN is received

Engineering Contradiction:
ImprovePIN securityVSAvoidPIN retrieval time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical mailing system (physical PIN mailers) with an electronic/digital system that uses encrypted data transmission over computer networks. The PIN characters are transmitted electronically to customer devices, eliminating the need for physical mail delivery while maintaining security through encryption protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates digital copies of the PIN characters that can be transmitted and displayed on customer devices. Instead of requiring the customer to receive a physical mailer, the system generates and transmits electronic representations of the PIN characters that the customer can view on their computer or mobile device.

Inventive Principle:
Principle #26Copying

2Reliability

If a new PIN is mailed to the customer, then the customer receives a new PIN, but the process is expensive and leads to administrative expense

Engineering Contradiction:
ImprovePIN securityVSAvoidAdministrative cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces the mechanical mailing infrastructure (envelopes, postal services, tracking systems) with electronic transmission protocols. This substitution eliminates the costs associated with physical mail delivery, printing, and handling while maintaining secure PIN delivery through encrypted digital communication channels.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent enables customers to retrieve their PIN characters independently through automated electronic systems. Customers can access their PIN information through secure online portals or mobile applications without requiring administrative intervention for mailing physical PINs, thereby reducing administrative workload and associated costs.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the PIN is transmitted in decrypted form, then the customer can access the PIN, but the security of the PIN is compromised

Engineering Contradiction:
ImprovePIN accessibilityVSAvoidPIN security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent divides the PIN into individual character segments that are transmitted and displayed separately. Each character is encrypted individually during transmission, and the customer receives them as discrete units. This segmentation allows the PIN to be made accessible while maintaining security through individual character encryption and controlled display mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the encryption parameter state dynamically - the PIN characters are encrypted during transmission and storage, then temporarily decrypted for display to the customer, and re-encrypted or deleted afterward. This parameter change approach allows the PIN to be accessible when needed while maintaining security during transmission and storage phases.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8219826B2Secure pin character retrieval and setting
Publication Date: 2012.07.10 TOTAL SYST SERVICES
  • US8219826B2 patent drawing
  • US8219826B2 patent drawing
  • US8219826B2 patent drawing

AI summary

Disclosing a secure personal identification number (“PIN”) associated with a financial account to an account holder. A PIN reveal application can interact with a hardware security module (“HSM”) to decrypt and disclose the PIN to the account holder one or more PIN character(s) at a time. The account holder also can set a new PIN in a secure manner. A PIN set application can interact with the HSM to encrypt PIN characters received by the PIN set application from the account holder. The HSM provides a secure platform to encrypt and decrypt the secure PIN.