Smart Card Joint Password Generation for Secure Transaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing smart card transaction methods face safety risks due to multiple connections, which can lead to hijacking of transaction and signature information, reducing transaction security.

Innovation Solution

A method and system where a terminal detects an operation request, sends it to a smart card, which generates a joint password and signature message, and outputs a prompt message if disconnected, allowing the terminal to verify the signature message using the joint password, thereby completing data exchange in a single connection and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the smart card connects with the POS machine multiple times during transaction, then the transaction information and signature information can be transmitted, but the transaction safety is reduced due to risk of hijacking

Engineering Contradiction:
Improvetransaction safetyVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple connection operations into a single connection. The smart card and terminal complete all necessary data exchanges (transaction information, signature information, and joint password transmission) during one continuous connection, eliminating the need for multiple separate connections and thereby reducing hijacking risks while maintaining operational completeness

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a joint password as an intermediary security element. This joint password is generated by both the smart card and terminal, and is used to verify the authenticity of transmitted information. The intermediary mechanism ensures that even if connection data is intercepted, the hijacked information cannot be validated without the correct joint password, thus enhancing transaction safety

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the smart card transmits signature information multiple times, then the transaction can be completed, but the risk of information hijacking increases

Engineering Contradiction:
Improvetransaction completionVSAvoidinformation hijacking risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing a secure joint password before transmitting signature information. The joint password is generated and verified in advance during the single connection, creating a security foundation that protects subsequent information transmissions from hijacking, while ensuring transaction completion through pre-validated secure channels

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security parameter from multiple separate transmissions to a single transmission session protected by a dynamically generated joint password. This parameter change transforms the security model from relying on multiple connection attempts to relying on one secure connection with enhanced authentication, thereby reducing hijacking risk while maintaining transaction productivity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9438586B2Method and system for processing operation request
Publication Date: 2016.09.06 TENDYRON CORP
  • US9438586B2 patent drawing
  • US9438586B2 patent drawing
  • US9438586B2 patent drawing

AI summary

A method for processing an operation request includes: detecting by a terminal an operation request, and sending an operation request message to a smart card; receiving by the smart card the operation request message, storing by the smart card the operation request message, generating by the smart card a joint password, generating a signature message, sending by the smart card at least the signature message to the terminal; outputting by the smart card a prompt message about the joint password, if the smart card detects that the smart card is disconnected from the terminal after the terminal obtains the signature message; receiving by the terminal the joint password, using the joint password as a password to be verified, notifying a verification device by the terminal to verify the signature message, and triggering by the verification device a procedure responding to the operation request if the signature message is successfully verified.