Secure Device PIN Entry via Wireless Link
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure transaction methods between a smart card and a terminal, such as an ATM, are vulnerable to PIN theft as the user must enter their PIN on the terminal's input interface, which can be observed by third parties, and existing solutions that use one-time passwords are not compatible with standards where the smart card verifies holder identification data.
Innovation Solution
A method where the secure device obtains and encrypts transaction data, including PINs, and transmits it to the terminal via a wireless link, allowing the secure device to verify the PIN without the user needing to enter it on the terminal's interface, ensuring compatibility with standards like EMV and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the user enters PIN on the terminal's input interface, then the terminal can verify holder identification data, but the user is vulnerable to PIN theft by third parties observing the input interface
Solution Approach 1:
The patent extracts the PIN entry function from the terminal's input interface and relocates it to the secure device. The secure device now obtains and enters the PIN autonomously, removing the vulnerability of public keyboard observation while maintaining the terminal's ability to verify holder identification data.
Solution Approach 2:
The secure device acts as an intermediary between the user and the terminal. It receives the PIN from the user through a secure channel, stores it temporarily, and automatically enters it into the terminal's verification system, thereby eliminating the need for the user to physically interact with the terminal's input interface.
2Reliability
If a one-time password system is used to prevent PIN theft, then security is improved, but it is not compatible with transaction standards where the smart card verifies holder identification data
Solution Approach 1:
The secure device is designed to perform multiple functions: it stores the PIN, retrieves it when needed, and automatically enters it into the terminal. This multi-functional approach maintains compatibility with existing EMV transaction standards that require the smart card to verify holder identification data, while simultaneously providing enhanced security against PIN theft.
3Ease of operation
If the secure device obtains and transmits transaction data including PIN, then the user does not need to enter PIN on terminal interface, but the secure device must securely store and manage the PIN
Solution Approach 1:
The secure device provides self-service functionality by automatically obtaining, storing, and entering the PIN without requiring user interaction with the terminal's input interface. The device manages its own secure data storage and retrieval processes, enhancing user convenience while maintaining security through automated operations.
Data Source
AI summary
A method for performing a secure transaction between a secure device (2) and a terminal (4), the method being carried out by the secure device (2) and comprising the steps of:receiving transaction data from the terminal (4),characterized in that it comprises, before the step of receiving transaction data from the terminal (4), the steps ofobtaining transaction data entered by a user of the secure device (2), andtransmitting the transaction data to the terminal (4).


