Smart Card Network Time Initialization for PKI Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Microprocessor smart cards lack an internal clock and battery, leading to inaccurate time information when relying on mobile device modems, which can result in erroneous time-based operations and inadequate PKI authentication and token-based authentication processes.

Innovation Solution

The smart card receives a current network time from a network node, which is used to initialize a local clock counter for accurate timekeeping, enabling proper PKI certificate validation and token-based authentication by incorporating the authentication time variable into cryptographic operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the smart card relies on mobile device modem for time information, then the smart card can operate without internal clock and battery, but the time information becomes inaccurate leading to erroneous time-based operations

Engineering Contradiction:
Improvesmart card structureVSAvoidtime information accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent introduces an authentication time variable as an intermediary element that bridges the smart card and network time source. This time variable is obtained through authenticated communication with a network node during the authentication process, ensuring the time information is both accurate and securely sourced, thereby resolving the contradiction between simple smart card structure and accurate timekeeping

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by obtaining the authentication time variable during the authentication process before time-based operations are performed. The smart card receives and stores this authenticated time information in advance, ensuring accurate time is available when needed for certificate validation and token generation, preventing time-related errors in subsequent operations

Inventive Principle:
Principle #10Preliminary action

2Use of energy by moving object

If the smart card lacks internal clock and battery, then power consumption is reduced and device size is minimized, but time-based operations become erroneous

Engineering Contradiction:
Improvepower consumptionVSAvoidtime-based operations
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The authentication time variable serves as a mediator that provides reliable time information without requiring the smart card to maintain its own clock or battery. The time variable is obtained through authenticated communication with the network, ensuring reliability while keeping the smart card power-efficient and compact

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The smart card performs self-service by using the authentication time variable obtained during the authentication process to perform time-based operations independently. The card validates PKI certificates and generates tokens using this authenticated time information without needing external time sources or maintaining internal time-keeping hardware

Inventive Principle:
Principle #25Self-service

3Device complexity

If the smart card uses modem-provided time, then device complexity is reduced, but PKI authentication and token-based authentication become inadequate

Engineering Contradiction:
Improvetimekeeping mechanismVSAvoidauthentication processes
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The authentication time variable acts as a trusted intermediary that enables reliable PKI authentication and token-based authentication. By obtaining time information through authenticated communication with the network during the authentication process, the smart card ensures that certificate validation and token generation are performed with accurate and trustworthy time data

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback by using the authentication time variable obtained during the authentication process to validate PKI certificates and generate tokens. The time variable is cross-checked against the authentication process itself, ensuring that time-based security operations are consistent with the authenticated session and enhancing overall authentication reliability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10069822B2Authenticated network time for mobile device smart cards
Publication Date: 2018.09.04 VERIZON PATENT & LICENSING INC
  • US10069822B2 patent drawing
  • US10069822B2 patent drawing
  • US10069822B2 patent drawing

AI summary

A mobile device sends a network attach request to a network node, and receives an authentication challenge from the network node, where the authentication challenge includes an authentication token, a random number, and a time variable associated with a current time at the network node. A microprocessor smart card of the mobile device retrieves the time variable from the authentication challenge, and starts a clock counter based on the retrieved time variable. The microprocessor smart card uses a current time represented by the clock counter to perform time expiration validation tests on certificates during Public Key Infrastructure (PKI) authentication or on authentication tokens during token-based authentication.