Smart Card Authentication via Shared-Bus Challenge Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional smart card authentication systems face challenges in the field of existing technologies in the field of existing technologies in the field of existing technologies in the field of existing technologies in the field of existing technologies have not addressed the challenges or limitations of existing technologies have not effectively addressed the limitations of smart card readers with low-functionality and high-functionality card readers, leading to communication bottlenecks and high costs.
Innovation Solution
A system that uses low-functionality card readers with minimal memory and processing capabilities, connected to a local device that provides cryptographic functionality, reducing the size of messages transmitted between the card reader and the local device, thereby improving network speed and reducing costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If high-functionality card readers with significant memory and processing power are used to perform cryptographic functions locally, then authentication capability is improved, but device cost and complexity increase
Solution Approach 1:
The system divides the authentication functionality into two segments: the card reader handles card communication and message transmission, while the server handles cryptographic operations including challenge generation, encryption, and response verification. This segmentation allows the card reader to remain simple with minimal memory and processing requirements, while the server performs the computationally intensive cryptographic functions.
Solution Approach 2:
The patent introduces an intermediary communication protocol where the card reader acts as a mediator between the smart card and the server. The reader transmits authentication messages between the card and server but does not perform cryptographic verification itself, effectively using the server as an intermediary for the actual authentication decision.
2Ease of manufacture
If multiple card readers are connected via shared data bus to the database, then system cost is reduced, but communication speed decreases
Solution Approach 1:
The patent optimizes communication by transmitting only essential authentication data over the shared data bus between card readers and the server. Instead of transmitting large amounts of raw card data or multiple authentication rounds, the system uses a streamlined challenge-response protocol that minimizes message size and transmission time, effectively creating an optimized copy of the authentication process suitable for shared bus environments.
3Ease of manufacture
If low-functionality card readers with minimal memory and processing capabilities are used, then device cost is reduced, but authentication performance deteriorates
Solution Approach 1:
The server acts as an intermediary that compensates for the limited capabilities of low-functionality card readers. The server performs the computationally intensive cryptographic operations including generating random challenges, encrypting them with the card's public key, and verifying the decrypted responses, thereby enabling simple card readers to achieve secure authentication without requiring significant processing power.
Solution Approach 2:
The patent changes the distribution of computational parameters in the authentication protocol. Instead of requiring the card reader to perform complex cryptographic operations, the system shifts the computational burden to the server by having it generate and manage the challenge-response pairs, while the card reader only handles simple message transmission and basic protocol management.
Data Source
AI summary
Systems and methods for key card authentication are provided. The system may involve multiple simple key card readers connected to a central, local device over a shared data bus. A key card reader may receive an identifier from the key card and transmit it to a local device. The local device may generate a challenge/response pair and send it to the key card reader. The key card reader challenges the key card and determines whether the key card's response matches the expected response. The system uses minimal bandwidth on the shared data bus network.


