PKI Smart Card Authentication Without Digital Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing PKI-enabled smart cards and devices require a digital connection for authentication and signature processes, limiting mobility and security due to reliance on insecure PCs for user interaction and signature verification, and often lack support for symmetric cryptographic operations.

Innovation Solution

A method and apparatus using a PKI private key for generating One-Time Passwords (OTPs) or Message Authentication Codes (MACs) that do not require a digital connection, utilizing asymmetric cryptographic operations to produce shorter security values, allowing for secure authentication and signature generation without direct digital interaction with the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI smart cards are used for authentication and signature, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential cryptographic functionality from complex PKI infrastructure by using simplified digital signature schemes. Instead of requiring full PKI with certificate authorities and complex key management, the invention uses a streamlined approach where a server generates signature pairs and stores only the public signature basis, eliminating the need for complex PKI infrastructure while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs disposable, short-lived signature pairs that are generated on-demand by the server. Each signature pair is used once and then discarded, eliminating the need for long-term key management and complex PKI infrastructure. This approach reduces both device complexity and operational costs while maintaining security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If PKI smart cards are used for authentication, then authentication security is improved, but adaptability to non-digital channels deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiddelivery channel flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables self-service authentication where the server automatically generates and manages signature pairs without requiring smart cards or digital connections. The system serves itself by generating cryptographic materials on-demand, allowing authentication to occur through any delivery channel including telephone, mail, or other non-digital channels.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical smart card system with a software-based signature generation system. Instead of requiring physical smart cards with cryptographic hardware, the invention uses software-generated signature pairs that can be delivered through any channel, substituting the mechanical card system with a more versatile software approach.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If PKI smart cards with symmetric cryptographic operations are used, then functionality is improved, but device complexity increases

Engineering Contradiction:
Improvecryptographic functionalityVSAvoidcryptographic processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential asymmetric cryptographic functionality needed for signatures, eliminating the need for symmetric cryptographic operations. By using a simplified digital signature scheme where the server generates signature pairs, the invention removes complex symmetric cryptography while maintaining the core authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses public signature bases that are copied and distributed to multiple servers. Instead of requiring each device to perform complex cryptographic operations, the public signature basis is replicated across servers, allowing any server to verify signatures without needing complex cryptographic processing capabilities.

Inventive Principle:
Principle #26Copying

4Ease of operation

If unconnected smart card readers are used with PKI cards, then mobility is improved, but security deteriorates due to insecure PC interaction

Engineering Contradiction:
Improveuser mobilityVSAvoidinteraction security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical smart card reader system with a software-based signature generation system. Instead of requiring physical readers and cards that interact through potentially insecure PC interfaces, the invention uses software-generated signatures that can be delivered through any secure channel, eliminating the security vulnerabilities of PC-based interaction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system provides self-service authentication where signatures are generated automatically by the server without requiring user interaction through potentially insecure PC interfaces. This eliminates the security problem of insecure PC interaction while maintaining user mobility, as the authentication process does not depend on specific hardware interfaces.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2158717B1Remote authentication and transaction signatures
Publication Date: 2017.09.06 VASCO DATA SECURITY INTERNATIONAL
  • EP2158717B1 patent drawingFigure 1
  • EP2158717B1 patent drawingFigure 2
  • EP2158717B1 patent drawingFigure 3

AI summary

The invention provides a method, apparatus, computer readable medium and signal which allows the usage of devices containing PKl private keys such as PKI- enabled smart cards or USB sticks to authenticate users and to sign transactions. The authenticity of the user and/or the message is verified. Furthermore the operation (authentication and/or signing) occurs without the need for an application to have some kind of a direct or indirect digital connection with the device containing the private key. In other words a digital connection that would allow an application to submit data to the card for signing by the card's private key and that would allow retrieving the entire resulting signature from the card is not required. In addition the operation occurs without the need for the PKI-enabled device containing the private key (e.g. a PKI smart card or USB stick) to either support symmetric cryptographic operations or to have been personalized with some secret or confidential data element that can be read by a suitable reader.