Smart Card Network Time Initialization for PKI Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Microprocessor smart cards lack an internal clock and battery, leading to inaccurate time information when relying on mobile device modems, which can result in erroneous time-based operations and inadequate PKI authentication and token-based authentication processes.
Innovation Solution
The smart card receives a current network time from a network node, which is used to initialize a local clock counter for accurate timekeeping, enabling proper PKI certificate validation and token-based authentication by incorporating the authentication time variable into cryptographic operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the smart card relies on mobile device modem for time information, then the smart card can operate without internal clock and battery, but the time information becomes inaccurate leading to erroneous time-based operations
Solution Approach 1:
The patent introduces an authentication time variable as an intermediary element that bridges the smart card and network time source. This time variable is obtained through authenticated communication with a network node during the authentication process, ensuring the time information is both accurate and securely sourced, thereby resolving the contradiction between simple smart card structure and accurate timekeeping
Solution Approach 2:
The patent applies preliminary action by obtaining the authentication time variable during the authentication process before time-based operations are performed. The smart card receives and stores this authenticated time information in advance, ensuring accurate time is available when needed for certificate validation and token generation, preventing time-related errors in subsequent operations
2Use of energy by moving object
If the smart card lacks internal clock and battery, then power consumption is reduced and device size is minimized, but time-based operations become erroneous
Solution Approach 1:
The authentication time variable serves as a mediator that provides reliable time information without requiring the smart card to maintain its own clock or battery. The time variable is obtained through authenticated communication with the network, ensuring reliability while keeping the smart card power-efficient and compact
Solution Approach 2:
The smart card performs self-service by using the authentication time variable obtained during the authentication process to perform time-based operations independently. The card validates PKI certificates and generates tokens using this authenticated time information without needing external time sources or maintaining internal time-keeping hardware
3Device complexity
If the smart card uses modem-provided time, then device complexity is reduced, but PKI authentication and token-based authentication become inadequate
Solution Approach 1:
The authentication time variable acts as a trusted intermediary that enables reliable PKI authentication and token-based authentication. By obtaining time information through authenticated communication with the network during the authentication process, the smart card ensures that certificate validation and token generation are performed with accurate and trustworthy time data
Solution Approach 2:
The patent implements feedback by using the authentication time variable obtained during the authentication process to validate PKI certificates and generate tokens. The time variable is cross-checked against the authentication process itself, ensuring that time-based security operations are consistent with the authenticated session and enhancing overall authentication reliability
Data Source
AI summary
A mobile device sends a network attach request to a network node, and receives an authentication challenge from the network node, where the authentication challenge includes an authentication token, a random number, and a time variable associated with a current time at the network node. A microprocessor smart card of the mobile device retrieves the time variable from the authentication challenge, and starts a clock counter based on the retrieved time variable. The microprocessor smart card uses a current time represented by the clock counter to perform time expiration validation tests on certificates during Public Key Infrastructure (PKI) authentication or on authentication tokens during token-based authentication.


