Removable Storage Authentication via Digital Certificate Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing systems, particularly in money transaction devices, lack secure authentication methods for users and removable storage media, allowing unauthorized access and misuse of sensitive data.

Innovation Solution

A system and method that authenticate users by linking a certificate to the identification code of a removable storage medium, using attribute certificates and standard interfaces like USB, ensuring secure access and data transmission by tying authentication to the presence of the medium, preventing unauthorized access to security-related functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional data processing systems are used for data transfer, then ease of operation is improved, but security is worsened allowing unauthorized access

Engineering Contradiction:
Improveease of data transferVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a removable storage medium as an intermediary carrier between the data processing system and external systems. This medium serves as a trusted mediator that physically transports data while maintaining security through certificate-based authentication, resolving the contradiction between ease of data transfer and security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by storing authentication certificates on the removable storage medium before data transfer occurs. The data processing system verifies the certificate and grants access rights in advance, ensuring security is established before the actual data transfer operation, thus preventing unauthorized access while maintaining operational ease.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If user authentication is simplified, then ease of operation is improved, but security is worsened allowing unauthorized access

Engineering Contradiction:
Improveease of user authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses digital certificates stored on removable storage media as copyable authentication credentials. Instead of complex authentication procedures, the system verifies authentication by checking the presence and validity of certificate data on the removable medium, simplifying the authentication process while maintaining high security through cryptographic verification.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The removable storage medium acts as an intermediary authentication carrier that holds certificate data. This mediator simplifies authentication by providing a physical token that automatically presents credentials to the data processing system, eliminating complex authentication interactions while ensuring security through certificate validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If additional user rights are granted, then adaptability is improved, but security is worsened risking system manipulation

Engineering Contradiction:
Improveuser rights assignmentVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements local quality by assigning different authentication certificates to different removable storage media, each certificate containing specific user rights and permissions tailored to the intended user role. This allows the system to grant appropriate adaptability for different user needs while maintaining security by restricting each certificate to its authorized scope, preventing system manipulation through unauthorized privilege escalation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2492839B1Method and system for authenticating a user
Publication Date: 2021.03.31 WINCOR NIXDORF INT GMBH
  • EP2492839B1 patent drawingFigure 1
  • EP2492839B1 patent drawingFigure 2
  • EP2492839B1 patent drawingFigure 3

AI summary

The system has a removable memory unit (12) with a memory region for storing identification data for identification of the memory unit, where data of a digital certificate (14) is stored in the memory region or in another memory region of the memory unit. The memory unit is connected to a data processing system (18) via a data transmission connection, where the identification data and the data of the certificate are transmitted from the memory unit to the processing system. The processing system processes the identification data and the data of the certificate and authenticates a user. An independent claim is also included for a method for authenticating a user.