Personal Security Device Credential Release via Secure Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current personal security devices (PSDs) face challenges in securely accessing and managing secure host devices, particularly in establishing a reliable and secure channel for credential release, which is essential for authentication and transaction processes.

Innovation Solution

A method and system that provide a personal security device (PSD) with a credential readable only when a secure channel is established between the PSD and the secure host device, using keys stored on the host device, allowing secure access through a non-contact field reader, with options for tethered and roaming modes, and incorporating two-factor authentication via a personal identification number (PIN) or biometrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a personal security device stores credentials for accessing secure host devices, then authentication capability is improved, but security risk increases due to potential credential compromise

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcredential compromise risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential from the PSD and stores it in the secure host device instead. The PSD only contains a reference to the credential, not the credential itself. This extraction eliminates the security risk of credential compromise in the PSD while maintaining authentication capability through secure storage on the host device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure channel as an intermediary between the PSD and the secure host device. This secure channel, established using cryptographic keys, mediates the credential release process and ensures that credentials are transmitted and accessed securely, preventing unauthorized compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If credentials are made accessible for authentication, then ease of operation is improved, but security is worsened due to increased exposure

Engineering Contradiction:
Improveauthentication processVSAvoidcredential exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The credential is extracted from the PSD and relocated to secure storage on the host device. The PSD retains only a reference identifier, which is insufficient for authentication on its own. This maintains ease of operation through simple PSD presentation while eliminating credential exposure risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent moves the credential from one dimension (PSD storage) to another dimension (host device storage), changing the spatial and security dimensional relationship. The credential exists in a different security context on the host device, protected by the secure channel and host device security mechanisms.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-affected harmful factors

If secure channel establishment requires cryptographic binding, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidcryptographic binding process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The cryptographic binding and secure channel establishment are performed as preliminary actions during the authentication process. The PSD and host device pre-establish cryptographic relationships and secure channels before credential access is needed, simplifying the overall process by preparing security mechanisms in advance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9722999B2Secure access to secure access module-enabled machine using personal security device
Publication Date: 2017.08.01 ASSA ABLOY AB
  • US9722999B2 patent drawing
  • US9722999B2 patent drawing
  • US9722999B2 patent drawing

AI summary

A system and method are provided to access a secure host device using a personal security device (PSD). A user's PSD may hold a credential of a requesting component of the secure host device. The credential may only be readable from the PSD when a secure channel is established therewith. The establishment of a secure channel with the PSD may require access to keys. The secure host device may contain a SAM capable of securely storing and operating keys. The SMA may contain the relevant keys to support establishment of a secure channel with the personal security device and release a credential to its requesting component. These criteria may achieve the secure release of the credential from the PSD to the requesting component of the secure host device to achieve access by the user when the PSD is presented in the non-contract field of a card reader monitored by the secure host device.