Personal Security Device Credential Release via Secure Channel
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current personal security devices (PSDs) face challenges in securely accessing and managing secure host devices, particularly in establishing a reliable and secure channel for credential release, which is essential for authentication and transaction processes.
Innovation Solution
A method and system that provide a personal security device (PSD) with a credential readable only when a secure channel is established between the PSD and the secure host device, using keys stored on the host device, allowing secure access through a non-contact field reader, with options for tethered and roaming modes, and incorporating two-factor authentication via a personal identification number (PIN) or biometrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a personal security device stores credentials for accessing secure host devices, then authentication capability is improved, but security risk increases due to potential credential compromise
Solution Approach 1:
The patent extracts the credential from the PSD and stores it in the secure host device instead. The PSD only contains a reference to the credential, not the credential itself. This extraction eliminates the security risk of credential compromise in the PSD while maintaining authentication capability through secure storage on the host device.
Solution Approach 2:
The patent introduces a secure channel as an intermediary between the PSD and the secure host device. This secure channel, established using cryptographic keys, mediates the credential release process and ensures that credentials are transmitted and accessed securely, preventing unauthorized compromise.
2Ease of operation
If credentials are made accessible for authentication, then ease of operation is improved, but security is worsened due to increased exposure
Solution Approach 1:
The credential is extracted from the PSD and relocated to secure storage on the host device. The PSD retains only a reference identifier, which is insufficient for authentication on its own. This maintains ease of operation through simple PSD presentation while eliminating credential exposure risks.
Solution Approach 2:
The patent moves the credential from one dimension (PSD storage) to another dimension (host device storage), changing the spatial and security dimensional relationship. The credential exists in a different security context on the host device, protected by the secure channel and host device security mechanisms.
3Object-affected harmful factors
If secure channel establishment requires cryptographic binding, then security is improved, but device complexity increases
Solution Approach 1:
The cryptographic binding and secure channel establishment are performed as preliminary actions during the authentication process. The PSD and host device pre-establish cryptographic relationships and secure channels before credential access is needed, simplifying the overall process by preparing security mechanisms in advance.
Data Source
AI summary
A system and method are provided to access a secure host device using a personal security device (PSD). A user's PSD may hold a credential of a requesting component of the secure host device. The credential may only be readable from the PSD when a secure channel is established therewith. The establishment of a secure channel with the PSD may require access to keys. The secure host device may contain a SAM capable of securely storing and operating keys. The SMA may contain the relevant keys to support establishment of a secure channel with the personal security device and release a credential to its requesting component. These criteria may achieve the secure release of the credential from the PSD to the requesting component of the secure host device to achieve access by the user when the PSD is presented in the non-contract field of a card reader monitored by the secure host device.


