Smart Card Joint Password Generation for Secure Transaction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing smart card transaction methods face safety risks due to multiple connections, which can lead to hijacking of transaction and signature information, reducing transaction security.
Innovation Solution
A method and system where a terminal detects an operation request, sends it to a smart card, which generates a joint password and signature message, and outputs a prompt message if disconnected, allowing the terminal to verify the signature message using the joint password, thereby completing data exchange in a single connection and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the smart card connects with the POS machine multiple times during transaction, then the transaction information and signature information can be transmitted, but the transaction safety is reduced due to risk of hijacking
Solution Approach 1:
The patent merges multiple connection operations into a single connection. The smart card and terminal complete all necessary data exchanges (transaction information, signature information, and joint password transmission) during one continuous connection, eliminating the need for multiple separate connections and thereby reducing hijacking risks while maintaining operational completeness
Solution Approach 2:
The patent introduces a joint password as an intermediary security element. This joint password is generated by both the smart card and terminal, and is used to verify the authenticity of transmitted information. The intermediary mechanism ensures that even if connection data is intercepted, the hijacked information cannot be validated without the correct joint password, thus enhancing transaction safety
2Productivity
If the smart card transmits signature information multiple times, then the transaction can be completed, but the risk of information hijacking increases
Solution Approach 1:
The patent implements preliminary action by establishing a secure joint password before transmitting signature information. The joint password is generated and verified in advance during the single connection, creating a security foundation that protects subsequent information transmissions from hijacking, while ensuring transaction completion through pre-validated secure channels
Solution Approach 2:
The patent changes the security parameter from multiple separate transmissions to a single transmission session protected by a dynamically generated joint password. This parameter change transforms the security model from relying on multiple connection attempts to relying on one secure connection with enhanced authentication, thereby reducing hijacking risk while maintaining transaction productivity
Data Source
AI summary
A method for processing an operation request includes: detecting by a terminal an operation request, and sending an operation request message to a smart card; receiving by the smart card the operation request message, storing by the smart card the operation request message, generating by the smart card a joint password, generating a signature message, sending by the smart card at least the signature message to the terminal; outputting by the smart card a prompt message about the joint password, if the smart card detects that the smart card is disconnected from the terminal after the terminal obtains the signature message; receiving by the terminal the joint password, using the joint password as a password to be verified, notifying a verification device by the terminal to verify the signature message, and triggering by the verification device a procedure responding to the operation request if the signature message is successfully verified.


