Reader Device OTP Generation via Secure Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems using personal security devices (PSDs) face challenges in securely generating and managing one-time-passwords (OTPs) for access control, particularly in ensuring secure channel establishment and broad compatibility with various PSD types, including those without exposed crypto functions.

Innovation Solution

A method and system where a reader device, coupled to a host device, authenticates with a PSD to establish a secure channel and receives an OTP key, generating an OTP within the reader device for validation, while maintaining the OTP key's security and supporting a range of PSD types, including smart cards and mobile phones, via non-contact interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the OTP key is stored on the PSD and made readable by the reader device, then OTP generation capability is enabled, but the risk of OTP key exposure increases

Engineering Contradiction:
ImproveOTP generation capabilityVSAvoidOTP key exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and secure channel establishment before the OTP key is made readable. The reader device must be authenticated to the PSD and a secure channel must be established prior to reading the OTP key, preventing unauthorized access while enabling legitimate OTP generation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A secure channel acts as an intermediary between the PSD and reader device during OTP key transmission. This intermediary mechanism protects the OTP key from direct exposure while enabling controlled access for authentication purposes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the system supports multiple PSD types including those without exposed crypto functions, then compatibility is improved, but the complexity of secure channel establishment increases

Engineering Contradiction:
ImprovePSD compatibilityVSAvoidsecure channel establishment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication mechanism is designed to work universally with multiple PSD types including smart cards, tokens, and mobile phones, whether they have exposed crypto functions or not. The system provides a unified interface and authentication protocol that adapts to different PSD capabilities without requiring separate implementation paths

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The PSD autonomously performs authentication and secure channel establishment using its own cryptographic capabilities, even when crypto functions are not exposed to the host. The PSD self-manages the security operations internally, reducing the complexity burden on the reader device and host system

Inventive Principle:
Principle #25Self-service

3Productivity

If the OTP key is transferred to the reader device for OTP generation, then authentication efficiency is improved, but the security risk of key compromise increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidOTP key security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system establishes authentication and secure channels before transferring the OTP key to the reader device. This preliminary security setup ensures that the key transfer occurs only under verified secure conditions, maintaining security while enabling efficient local OTP generation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A secure channel serves as an intermediary protection mechanism during OTP key transfer from PSD to reader device. This intermediary layer encrypts and protects the key transmission, allowing efficient key access for authentication while preventing key compromise during transfer

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10826893B2One-time-password generated on reader device using key read from personal security device
Publication Date: 2020.11.03 ASSA ABLOY AB
  • US10826893B2 patent drawing
  • US10826893B2 patent drawing
  • US10826893B2 patent drawing

AI summary

An authentication system is provided using one-time passwords (OTPs) for user authentication. An OTP key may be stored on a different device than the device on which the OTP is generated. In an embodiment, the system described herein enables a combined authentication system, including the two separate devices communicating over a non-contact interface, to provide advantageous security features compared to the use of a single device, such as a hardware OTP token. One device may be a personal security device and the other device may be a reader device coupled to a host device via which access is being controlled.