Session PIN Generation for Secure Wireless PKI Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Windows operating system's security-critical processes for user and data object authentication using PKI-based hardware tokens are inflexible and vulnerable to unauthorized PIN tapping during wireless communication, as they require direct keyboard entry of the user PIN, which is not secure and cannot be adapted by users or administrators.
Innovation Solution
A method and system for generating and using a session PIN in a security-critical process, involving a hardware token with a wireless communication link, where user authentication data is received, verified, and a session PIN is generated and stored for secure authentication, using protocols like PACE, challenge-response, or ISO/IEC 7816-4 for secure messaging, preventing unencrypted PIN transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a user PIN is entered via keyboard for direct processing by the Windows process, then the authentication process can be completed, but the transmission of the user PIN becomes unencrypted and vulnerable to unauthorized tapping
Solution Approach 1:
The patent introduces an intermediary session PIN mechanism that mediates between the user and the authentication system. Instead of transmitting the user's actual PIN unencrypted, the system generates a session-specific PIN that acts as a secure intermediary credential. This session PIN is encrypted and transmitted through the wireless communication link, preventing unauthorized tapping of the original user PIN while maintaining authentication functionality.
Solution Approach 2:
The patent creates a cryptographic copy or representation of the authentication credential in the form of a session PIN. Rather than transmitting the original user PIN, the system generates a derived session PIN that serves as a functional copy for authentication purposes. This copy can be securely transmitted and discarded after use, eliminating the security risk of transmitting the original credential.
2Productivity
If the Windows authentication process requires direct keyboard entry of user PIN, then the process can proceed, but the system cannot be adapted or replaced by the user or administrator
Solution Approach 1:
The patent transforms the static, fixed authentication process into a dynamic, adaptable system. The session PIN mechanism allows the authentication process to be customized and controlled by users or administrators through software applications. The system can dynamically generate session PINs with different parameters and security characteristics, enabling flexibility while maintaining efficient authentication throughput.
Solution Approach 2:
The patent performs preliminary actions by pre-generating and storing session PINs in the hardware token before they are needed for authentication. This preliminary preparation allows the actual authentication process to proceed quickly without compromising security, as the session PINs are already prepared and can be securely transmitted when needed.
3Ease of operation
If wireless communication is used between user terminal and hardware token, then data exchange is enabled, but the transmission of authentication data becomes vulnerable to unauthorized access
Solution Approach 1:
The patent changes the parameters of the authentication data being transmitted over the wireless link. Instead of transmitting the original user PIN with its inherent security characteristics, the system transforms it into a session PIN with different security parameters - specifically designed for wireless transmission. The session PIN can be configured with appropriate encryption, expiration times, and usage limits, making it suitable for wireless communication while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for providing and using a session PIN for a security-critical process for authenticating a user and/or a data object when executing a software application in an operating system environment in a system with a user terminal, a hardware token which is assigned to a public key infrastructure, and a communication link between the user terminal and the hardware token, which includes a wireless communication link and is set up to enable data exchange between the user terminal and the hardware token.The procedure comprises the following steps: receiving a user's authentication data via an input device associated with the hardware token; verifying the user's authentication data using the hardware token; generating a session PIN if the user's authentication data is successfully verified; storing the session PIN in the hardware token and/or the user terminal; and using the session PIN for a security-critical process to authenticate a user and/or a data object.When generating the session PIN, at least one of the following generation processes is executed: generating an alphanumeric value as a session PIN, which is verifiable via the Password Authenticated Connection Establishment protocol; generating a symmetric key as a session PIN, which can be used for secure messaging, in particular secure messaging according to ISO/IEC 7816-4, by means of a challenge-response protocol with subsequent derivation of session keys; and determining parts of parameters or complete parameters of a secure messaging system as a session PIN, in particular parameters of secure messaging according to ISO/IEC 7816-4. Furthermore, a data processing system is created for providing and using a session PIN for a security-critical process for authenticating a user and/or a data object when executing a software application in an operating system environment.