Session PIN Generation for Secure Wireless PKI Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Windows operating system's security-critical processes for user and data object authentication using PKI-based hardware tokens are inflexible and vulnerable to unauthorized PIN tapping during wireless communication, as they require direct keyboard entry of the user PIN, which is not secure and cannot be adapted by users or administrators.

Innovation Solution

A method and system for generating and using a session PIN in a security-critical process, involving a hardware token with a wireless communication link, where user authentication data is received, verified, and a session PIN is generated and stored for secure authentication, using protocols like PACE, challenge-response, or ISO/IEC 7816-4 for secure messaging, preventing unencrypted PIN transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user PIN is entered via keyboard for direct processing by the Windows process, then the authentication process can be completed, but the transmission of the user PIN becomes unencrypted and vulnerable to unauthorized tapping

Engineering Contradiction:
ImprovePIN entry convenienceVSAvoidPIN tapping vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary session PIN mechanism that mediates between the user and the authentication system. Instead of transmitting the user's actual PIN unencrypted, the system generates a session-specific PIN that acts as a secure intermediary credential. This session PIN is encrypted and transmitted through the wireless communication link, preventing unauthorized tapping of the original user PIN while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a cryptographic copy or representation of the authentication credential in the form of a session PIN. Rather than transmitting the original user PIN, the system generates a derived session PIN that serves as a functional copy for authentication purposes. This copy can be securely transmitted and discarded after use, eliminating the security risk of transmitting the original credential.

Inventive Principle:
Principle #26Copying

2Productivity

If the Windows authentication process requires direct keyboard entry of user PIN, then the process can proceed, but the system cannot be adapted or replaced by the user or administrator

Engineering Contradiction:
Improveauthentication process speedVSAvoidsystem flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static, fixed authentication process into a dynamic, adaptable system. The session PIN mechanism allows the authentication process to be customized and controlled by users or administrators through software applications. The system can dynamically generate session PINs with different parameters and security characteristics, enabling flexibility while maintaining efficient authentication throughput.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary actions by pre-generating and storing session PINs in the hardware token before they are needed for authentication. This preliminary preparation allows the actual authentication process to proceed quickly without compromising security, as the session PINs are already prepared and can be securely transmitted when needed.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If wireless communication is used between user terminal and hardware token, then data exchange is enabled, but the transmission of authentication data becomes vulnerable to unauthorized access

Engineering Contradiction:
Improvewireless communication convenienceVSAvoiddata transmission security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the parameters of the authentication data being transmitted over the wireless link. Instead of transmitting the original user PIN with its inherent security characteristics, the system transforms it into a session PIN with different security parameters - specifically designed for wireless transmission. The session PIN can be configured with appropriate encryption, expiration times, and usage limits, making it suitable for wireless communication while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3401821A1Method and data processing system for providing and using a session pin for a security-critical process for authenticating a user and/or a data object
Publication Date: 2018.11.14 BUNDESDRUCKEREI GMBH
  • EP3401821A1 patent drawingFigure 1
  • EP3401821A1 patent drawingFigure 2
  • EP3401821A1 patent drawingFigure 3

AI summary

The invention relates to a method for providing and using a session PIN for a security-critical process for authenticating a user and/or a data object when executing a software application in an operating system environment in a system with a user terminal, a hardware token which is assigned to a public key infrastructure, and a communication link between the user terminal and the hardware token, which includes a wireless communication link and is set up to enable data exchange between the user terminal and the hardware token.The procedure comprises the following steps: receiving a user's authentication data via an input device associated with the hardware token; verifying the user's authentication data using the hardware token; generating a session PIN if the user's authentication data is successfully verified; storing the session PIN in the hardware token and/or the user terminal; and using the session PIN for a security-critical process to authenticate a user and/or a data object.When generating the session PIN, at least one of the following generation processes is executed: generating an alphanumeric value as a session PIN, which is verifiable via the Password Authenticated Connection Establishment protocol; generating a symmetric key as a session PIN, which can be used for secure messaging, in particular secure messaging according to ISO/IEC 7816-4, by means of a challenge-response protocol with subsequent derivation of session keys; and determining parts of parameters or complete parameters of a secure messaging system as a session PIN, in particular parameters of secure messaging according to ISO/IEC 7816-4. Furthermore, a data processing system is created for providing and using a session PIN for a security-critical process for authenticating a user and/or a data object when executing a software application in an operating system environment.