Smart Card Password Input Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password input methods are vulnerable to interception during transmission, as passwords are often received and processed by terminal devices connected to the internet, making them susceptible to unauthorized access, even with digital certificates.

Innovation Solution

A method and device that utilize a smart card to securely input and authenticate passwords by receiving instructions according to the ISO/IEC 7816 standard, where the password input is enclosed within a password checking instruction and processed by the smart card, eliminating the need for transmission through a customer terminal connected to the internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password is transmitted through terminal device connected to internet, then password can be received and processed by banking system, but password becomes vulnerable to interception by illegal users

Engineering Contradiction:
Improvepassword securityVSAvoidinterception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password transmission process from the internet-connected terminal device environment and relocates it to the smart card's internal secure environment. The password is input directly into the smart card and processed within the card's secure memory, completely removing it from the vulnerable internet transmission path. This extraction eliminates the interception risk while preserving the authentication function.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card acts as an intermediary device between the user and the banking system. Instead of direct communication between terminal and bank through the internet, the smart card mediates the authentication process by receiving password input, processing it through its secure authentication logic, and transmitting only authentication results back through the terminal. This intermediary role protects the password from exposure during transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital certificates are used to enhance security, then authentication capability is improved, but password interception vulnerability remains when terminal device is compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the password input function, authentication processing, and security protection into a single integrated smart card device. The smart card combines secure memory for storing authentication data, input interface for password entry, and processing logic for verification. This consolidation eliminates the need for separate terminal-based authentication mechanisms and their associated vulnerabilities while maintaining authentication capability.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If password is processed by terminal device, then input convenience is maintained, but security is compromised due to potential terminal compromise

Engineering Contradiction:
Improvepassword input convenienceVSAvoidpassword protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The smart card provides self-service authentication processing by directly receiving password input from the user through its own interface and independently verifying the password against stored credentials. The card autonomously performs the authentication function without requiring terminal device processing or internet communication for the actual verification. This self-service approach maintains user convenience while eliminating terminal-based security risks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8777100B2Method for inputting a password and a device therefor
Publication Date: 2014.07.15 FEITIAN TECHNOLOGIES CO LTD
  • US8777100B2 patent drawing
  • US8777100B2 patent drawing
  • US8777100B2 patent drawing

AI summary

A method for inputting a password and a device thereof are disclosed in the invention, relating to the information security field and solving the problem that a password input by a user is easy to be intercepted. The method includes steps that, a password inputting device acquires an instruction in accordance with ISO/IEC 7816 standard from an upper computer, and determines whether the instruction is a password checking instruction or not, and if it is not, the device sends the instruction to the smart card; or else if it is, the device receives the password input by the user, encloses it to the password checking instruction, sends the instruction enclosed with the password to the smart card, receives the result of executing the password checking instruction from the smart card, and sends the result to the upper computer. The solution of the invention is used for improving the security of inputting a password in avoidance that the password is intercepted when being transmitted.