Smart Card Authentication via Dynamic Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current smart lock systems require a preset unlocking key to be set by manufacturers before shipping, which complicates the production process and security, as they rely on third-party key allocation and lack real-time authentication mechanisms.
Innovation Solution
A method where the smart lock authenticates the smart card by acquiring a digital certificate, generating an unlocking key using the smart card's public key, and encrypting it for secure transmission, allowing local key generation and real-time authentication without pre-set keys or third-party involvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a preset unlocking key is configured by the manufacturer before shipping, then the smart lock can perform authentication, but the production process becomes complicated and security is reduced due to reliance on third-party key allocation
Solution Approach 1:
The patent extracts the key generation and allocation process from the manufacturer's production workflow. Instead of pre-configuring unlocking keys during manufacturing, the system allows smart cards to independently obtain unlocking keys from smart locks after deployment. This separation eliminates the need for manufacturers to integrate with third-party key allocation services, simplifying the production process while maintaining security through post-deployment key establishment.
Solution Approach 2:
The smart card performs self-authentication by independently obtaining unlocking keys from the smart lock without manufacturer intervention. The smart card uses its digital certificate to authenticate itself to the smart lock, which then generates and provides the unlocking key. This self-service mechanism eliminates reliance on third-party key allocation services and simplifies the production process.
2Ease of operation
If a preset unlocking key is used for authentication, then the smart lock can be unlocked, but the system is vulnerable to malicious copy attacks and lacks real-time authentication
Solution Approach 1:
The patent transforms the static preset unlocking key into a dynamic real-time authentication mechanism. Instead of using a fixed key configured during manufacturing, the system generates unlocking keys dynamically during the authentication process. The smart card presents its digital certificate, the smart lock verifies it, and then generates a fresh unlocking key for that specific authentication event. This dynamic approach maintains unlocking convenience while preventing malicious copy attacks, as each authentication session uses a newly generated key rather than a reusable preset key.
3Reliability
If third-party key allocation services are used, then key distribution can be managed, but the system relies on external services and increases complexity
Solution Approach 1:
The patent extracts the key allocation function from external third-party services and relocates it to the smart lock itself. The smart lock uses the smart card's digital certificate to authenticate the card and then generates the unlocking key locally without contacting any external key management service. This extraction eliminates the dependency on third-party services and reduces system complexity while maintaining secure key distribution through the existing digital certificate infrastructure.
Solution Approach 2:
The smart lock performs self-service key generation and allocation using the smart card's digital certificate. Instead of relying on external key management services, the smart lock independently verifies the smart card's identity through its digital certificate and generates the appropriate unlocking key. This self-service approach eliminates the need for third-party key allocation services and reduces system complexity.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
A method for authenticating a smart card, includes: determining (S201,S401,S601) whether the smart card satisfies a first authentication condition according to authentication information provided by the smart card; in response to the determination that the smart card satisfies the first authentication condition, sending (S202) a generated unlocking key to the smart card; and in response to receiving feedback information of the smart card, determining (S203) the smart card to be an authenticated smart card.