Smart Card Controlled Keypad Scanning for PIN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing smart card terminals can intercept and store user input data, such as PIN codes, due to their control over the keypad scanning sequence, making them vulnerable to software attacks and fraudulent access.

Innovation Solution

The smart card determines and controls the keypad scanning sequence, ensuring that the terminal does not know which keys are pressed, and key signals are either passed directly to the smart card or stored securely within the terminal, preventing unauthorized access and data interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the terminal controls the keypad scanning sequence, then the terminal can process key inputs, but the terminal can intercept and store user input data

Engineering Contradiction:
Improvekeypad input processingVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the scanning sequence control function from the terminal and transfers it to the smart card. The terminal no longer determines the scanning sequence; instead, the smart card generates and controls the row and column scanning orders, preventing the terminal from intercepting meaningful key input data while maintaining normal keypad processing capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent inverts the traditional control relationship: instead of the terminal controlling the scanning sequence, the smart card now controls the scanning sequence. This inversion ensures that key press information becomes meaningless to the terminal without the corresponding scanning sequence, thereby securing user input data

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If a dedicated security module is added to control the keyboard matrix, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidadditional processor and switch
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the smart card multi-functional by enabling it to perform both authentication functions and scanning sequence control functions. The smart card's existing processor and memory are utilized to generate and control scanning sequences, eliminating the need for dedicated security hardware while maintaining security functionality

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the security control functions with the smart card's existing capabilities. The smart card's processor is used to generate scanning sequences, and its memory stores relevant data, combining authentication and input security functions into a single integrated solution rather than adding separate dedicated security components

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8196815B2Secure card terminal using keypad scanning sequence determined by card
Publication Date: 2012.06.12 NXP BV
  • US8196815B2 patent drawing
  • US8196815B2 patent drawing

AI summary

To provide alphanumeric data, such as a PIN code, to a smart card (2) a terminal (1) is used which is capable of communicating with the smart card. The terminal comprises a keypad (4) for entering the alphanumeric data and an associated keypad matrix (5) for producing key signals, which the keypad matrix (5) is scanned for any pressed keys using a scanning sequence so as to produce key signals. To securely enter the data without the risk of the terminal intercepting them it is proposed that said scanning sequence is determined by the smart card (2). In this way, the terminal has no knowledge of the actual keys pressed and the secrecy of the alphanumeric data is ensured.