Smart Card Module Multi-Level Authentication for Secure Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication devices lack secure methods for transmitting and accessing sensitive or confidential information, particularly in healthcare settings, due to inadequate security measures for data access and transmission.

Innovation Solution

Incorporating a secured smart card module within the wireless communication device that requires multi-level authentication, including user authentication and scanning of machine-readable data, to ensure secure access and transmission of sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a wireless communication device is used to transmit sensitive information, then data accessibility and communication speed are improved, but security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system divides authentication into multiple levels: first authentication verifies user identity, then a second authentication verifies additional credentials before granting access to sensitive information. This segmentation of security checks ensures that no single point of failure compromises the entire system, thereby improving data security while maintaining operational ease through automated multi-factor verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication checks before allowing access to sensitive information. By requiring users to complete authentication procedures in advance (including both first and second authentication), the system ensures that only verified users can access protected data, improving security without impacting ease of operation during actual data access since the security verification is already completed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-level authentication is implemented, then security against unauthorized access is improved, but device complexity and authentication time increase

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The wireless communication device is designed to perform multiple functions: it serves as both the authentication device and the target device for verification. The same device can initiate authentication, verify credentials, and access protected information. This multi-functionality reduces overall system complexity while maintaining strong multi-level security, as one device handles all authentication operations rather than requiring separate dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables the wireless communication device to perform self-verification through the second authentication process. The device can independently verify additional credentials and authenticate itself without requiring external verification infrastructure, thereby reducing system complexity while maintaining robust security through automated self-service authentication mechanisms.

Inventive Principle:
Principle #25Self-service

3Reliability

If token session IDs with time and location limitations are used, then protection against device loss is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveprotection against device lossVSAvoidsession management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes parameters of the token session ID by incorporating time-based and location-based constraints. Instead of using static authentication credentials, the system generates dynamic session tokens that are valid only within specific time windows and geographic locations. This parameter-based approach provides robust protection against device loss while maintaining relatively simple implementation through standard token generation and validation mechanisms that most wireless devices already support.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP1864467B1Phone with secure element and critical data
Publication Date: 2020.05.06 NXP BV
  • EP1864467B1 patent drawingFigure 1
  • EP1864467B1 patent drawingFigure 2
  • EP1864467B1 patent drawingFigure 3A~3B

AI summary

A wireless communication device is implemented with a smart card module to secure the transmission of sensitive or confidential information. The user of the device must request permission to activate an application on the smart card module from a remote source. After this first level of security is satisfied, the application on the smart card module enables the user to scan data via a machine-readable medium in order to make a data request to the remote source. If a second level authorization is met in regard to the data request, the remote source will transmit the requested sensitive or confidential information to the user to view and/or update.