Secure Device PIN Entry via Wireless Link

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure transaction methods between a smart card and a terminal, such as an ATM, are vulnerable to PIN theft as the user must enter their PIN on the terminal's input interface, which can be observed by third parties, and existing solutions that use one-time passwords are not compatible with standards where the smart card verifies holder identification data.

Innovation Solution

A method where the secure device obtains and encrypts transaction data, including PINs, and transmits it to the terminal via a wireless link, allowing the secure device to verify the PIN without the user needing to enter it on the terminal's interface, ensuring compatibility with standards like EMV and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the user enters PIN on the terminal's input interface, then the terminal can verify holder identification data, but the user is vulnerable to PIN theft by third parties observing the input interface

Engineering Contradiction:
ImprovesecurityVSAvoidPIN theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the PIN entry function from the terminal's input interface and relocates it to the secure device. The secure device now obtains and enters the PIN autonomously, removing the vulnerability of public keyboard observation while maintaining the terminal's ability to verify holder identification data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure device acts as an intermediary between the user and the terminal. It receives the PIN from the user through a secure channel, stores it temporarily, and automatically enters it into the terminal's verification system, thereby eliminating the need for the user to physically interact with the terminal's input interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a one-time password system is used to prevent PIN theft, then security is improved, but it is not compatible with transaction standards where the smart card verifies holder identification data

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility with transaction standards
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure device is designed to perform multiple functions: it stores the PIN, retrieves it when needed, and automatically enters it into the terminal. This multi-functional approach maintains compatibility with existing EMV transaction standards that require the smart card to verify holder identification data, while simultaneously providing enhanced security against PIN theft.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If the secure device obtains and transmits transaction data including PIN, then the user does not need to enter PIN on terminal interface, but the secure device must securely store and manage the PIN

Engineering Contradiction:
Improveuser convenienceVSAvoidsecure data management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The secure device provides self-service functionality by automatically obtaining, storing, and entering the PIN without requiring user interaction with the terminal's input interface. The device manages its own secure data storage and retrieval processes, enhancing user convenience while maintaining security through automated operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9792606B2Method and secure device for performing a secure transaction with a terminal
Publication Date: 2017.10.17 IDEMIA FRANCE SAS
  • US9792606B2 patent drawing
  • US9792606B2 patent drawing
  • US9792606B2 patent drawing

AI summary

A method for performing a secure transaction between a secure device (2) and a terminal (4), the method being carried out by the secure device (2) and comprising the steps of:receiving transaction data from the terminal (4),characterized in that it comprises, before the step of receiving transaction data from the terminal (4), the steps ofobtaining transaction data entered by a user of the secure device (2), andtransmitting the transaction data to the terminal (4).