Smart Card Authentication via Personalization Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current HTTP-based authentication methods for websites are weak in terms of confidentiality, integrity, and non-repudiation, particularly for websites managing personal data, and there is a need for a more reliable and user-friendly authentication mechanism.
Innovation Solution
A method and system for secured authentication between a communication device with a smart card and an application server, involving a personalization server that generates an authentication key and international identity, which are sent to the smart card for storage, allowing remote reconfiguration and enabling secure access to services without the need for physical password delivery via postal mail.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HTTP-based authentication using login/password is used, then the authentication process is simple and familiar to users, but the confidentiality, integrity, and non-repudiation are weak
Solution Approach 1:
The patent introduces a personalization server as an intermediary between the user and the application server. This server generates authentication keys and international identities, and personalizes the smart card remotely. The intermediary handles the complex cryptographic operations and key management, while the user simply needs to possess the smart card, thus improving security without significantly increasing user operational complexity
Solution Approach 2:
The patent replaces the mechanical/password-based authentication system with a cryptographic system based on smart cards and asymmetric cryptography. Instead of relying on users to remember and protect passwords, the system uses cryptographic keys stored in the smart card, providing stronger security guarantees for confidentiality, integrity, and non-repudiation
2Reliability
If passwords are sent via postal mail, then the authentication method can be improved, but the process becomes time-consuming and inconvenient for users
Solution Approach 1:
The personalization server performs preliminary actions by pre-generating authentication keys and international identities before the user needs them. The smart card is personalized remotely with the necessary cryptographic credentials, so when the user needs to authenticate, the credentials are already in place, eliminating the need for time-consuming password delivery via postal mail
Solution Approach 2:
The system enables self-service authentication setup where the personalization server automatically generates and delivers authentication credentials to the user's smart card without requiring manual intervention or postal mail. The user simply needs to have the smart card to receive the personalized authentication data
3Reliability
If authentication keys are stored on the smart card, then confidentiality and non-repudiation are improved, but the device complexity increases
Solution Approach 1:
The patent makes the smart card multi-functional by combining traditional authentication functions with cryptographic key storage and processing capabilities. The smart card serves as both a user identification medium and a secure cryptographic device, eliminating the need for separate hardware security modules or complex external key management systems
Solution Approach 2:
The personalization server acts as an intermediary that handles the complexity of key generation and management, while the smart card handles the secure storage and cryptographic operations. This distribution of complexity between the intermediary server and the user's smart card allows strong security without requiring the user's device to be overly complex
Data Source
Figure 1
Figure 2
AI summary
For enabling a secured authentication between a communication device (CD) that is coupled with a smart card (SC) of a user being a subscriber of a telecommunication network (TN) and an application server (AS) that provides a service and is connected to the telecommunication network (TN), a personalization server (PS) included in the telecommunication network receives a request (Req) containing an identifier (IdU) of the user and an identifier (IdS_X) of said service from the application server, generating an authentication key (AK_X) and an international identity (IMSI_X) associated with the identifier of said service. The personalization server (PS) then sends a message (MesP) to the communication device (CD), the message containing the authentication key, the international identity, an admin code (ACps), the identifier of said service, and a personalization command (ComP), in order that the smart card (SC) interprets the personalization command to store the authentication key, the international identity and the identifier if the admin code is valid, The personalization server (PS) then sends a response (Res) containing the authentication key and the international identity to the application server.