Portable Data Carrier Authentication via Checksum Challenge-Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for accessing e-services via server instances are complex, costly, and not flexible enough for client instances with limited resources, often requiring middleware and digital certificates with limited validity, which can be cumbersome and expensive for server instances.
Innovation Solution
A method using a portable data carrier that sends a first checksum calculated from identification data to a server instance, allowing the server to authenticate the user without needing the actual data record, thereby simplifying the authentication process and reducing the need for complex cryptographic mechanisms, while ensuring high security through possessive and cognitive identification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods using digital certificates and middleware are used, then authentication security is maintained, but device complexity and cost increase significantly
Solution Approach 1:
The patent extracts the essential authentication function from the complex certificate infrastructure. Instead of requiring full digital certificate validation with middleware, the system uses a simplified challenge-response mechanism where the server sends a challenge and the client proves knowledge of the secret without revealing it. This extracts only the necessary authentication element while discarding the cumbersome certificate infrastructure.
Solution Approach 2:
The patent replaces expensive, long-validity digital certificates with inexpensive, short-lived challenge-response tokens. Each authentication session uses a fresh challenge and response pair that is discarded after use. This eliminates the need for costly certificate management, validation infrastructure, and middleware while maintaining security through the unbreakable nature of the cryptographic challenge-response mechanism.
2Reliability
If digital certificates with limited validity are used for authentication, then security is maintained, but authentication cost and complexity increase for server instances
Solution Approach 1:
The patent replaces expensive, long-validity digital certificates with inexpensive, short-lived challenge-response tokens. Each authentication session uses a fresh challenge and response pair that is discarded after use. This eliminates the need for costly certificate management, validation infrastructure, and middleware while maintaining security through the unbreakable nature of the cryptographic challenge-response mechanism.
Solution Approach 2:
The authentication system becomes self-service in that the server instance can independently verify client authentication without requiring external certificate authorities or validation services. The server generates challenges and verifies responses using only the shared secret, making the authentication process self-contained and eliminating external dependency costs.
3Reliability
If complex authentication infrastructure is implemented, then authentication reliability is improved, but ease of operation decreases for client instances with limited resources
Solution Approach 1:
The patent extracts the essential authentication function from the complex certificate infrastructure. Instead of requiring full digital certificate validation with middleware, the system uses a simplified challenge-response mechanism where the server sends a challenge and the client proves knowledge of the secret without revealing it. This extracts only the necessary authentication element while discarding the cumbersome certificate infrastructure.
Solution Approach 2:
The patent replaces expensive, long-validity digital certificates with inexpensive, short-lived challenge-response tokens. Each authentication session uses a fresh challenge and response pair that is discarded after use. This eliminates the need for costly certificate management, validation infrastructure, and middleware while maintaining security through the unbreakable nature of the cryptographic challenge-response mechanism.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The invention relates to a method for authenticating a person with respect to a server instance (2), wherein a portable data storage medium (1) is assigned to the person and the data storage medium (1) is arranged spatially remote from the server instance (2). The method comprises the steps of: transmitting an authentication request (12) by the server instance (2); transmitting (14) a first checksum (5) as a digital certificate from the data storage medium (1) to the server instance (2), wherein the first checksum (5) is calculated by means of at least one data set (4) that identifies the person; receiving (17) an input data set (4) in the server instance (2), wherein the input (16) of the data set (4) is effected by the person; calculating (18) a second checksum (6) in the server instance (2) by means of the received data set (4); comparing (19) the first checksum (5) with the second checksum (6) in the server instance (2) and authenticating (20) the person by the server instance (2) if the result of the comparison (19) is that the first checksum (5) and the second checksum (6) are the same. The invention further comprises a portable data storage medium (1) and a server instance (2).