Smart Card PIN Management via Stand-Alone Reader

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of smart cards face difficulties in managing and changing their personal identification numbers (PINs) due to the technical limitations of smart cards, which require real-time two-way communication with the issuer's network, making it impractical for users to change PINs without access to issuer-provided devices or services.

Innovation Solution

A system allowing users to change their smart card PINs using a stand-alone smart card reader that generates a cryptogram for the issuer's PIN change management system, enabling PIN changes without a real-time connection to the issuer's network, and supports additional functions like unblocking locked cards and setting risk management parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time two-way communication with the issuer's network is required for PIN changes, then security and reliability are improved, but device complexity and user accessibility deteriorate

Engineering Contradiction:
ImprovePIN change securityVSAvoidnetwork connection requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the PIN change process into two independent parts: (1) offline cryptogram generation by the smart card reader using the card's data, and (2) online verification by the issuer's system. This allows the smart card reader to function independently without requiring continuous network connectivity, resolving the contradiction between security (verified online) and accessibility (offline operation).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptogram acts as an intermediary data structure that carries the essential verification information from the smart card reader to the issuer's system. This intermediary enables the transfer of security-critical data without requiring real-time communication during the actual PIN change operation, allowing offline functionality while maintaining security verification capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If issuer-provided devices or services are required for PIN management, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovePIN management securityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The smart card reader is designed to autonomously generate cryptograms and perform PIN change operations without requiring user travel to issuer facilities or interaction with issuer staff. The reader independently processes the smart card, generates the necessary cryptographic data, and completes the PIN change, enabling users to perform security-critical operations at any location with the reader device.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The smart card reader is designed as a universal device that can perform multiple functions including PIN changes, unblocking locked cards, and setting risk management parameters. This multi-functional capability eliminates the need for users to access specific issuer-provided devices for different card management tasks, significantly improving ease of operation while maintaining security through the standardized cryptogram verification process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple PINs are stored on smart cards, then adaptability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvemultiple account supportVSAvoidPIN memorization
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system introduces an intermediary management layer that handles the complexity of multiple PINs. The smart card reader and issuer's system work together to manage which PIN is active for which card, shielding users from the complexity of remembering multiple PINs. The cryptogram mechanism enables flexible PIN assignment while the system automatically manages the association between cards and their corresponding PINs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8186586B2System, method, and apparatus for smart card pin management via an unconnected reader
Publication Date: 2012.05.29 ENTRUST CORP
  • US8186586B2 patent drawing
  • US8186586B2 patent drawing
  • US8186586B2 patent drawing

AI summary

A system of changing the PIN associated with a smart card is described. A user can initiate the PIN change using a personal unwired smart card reader, rather than using a system, such as an ATM machine. The smart card reader, loaded with the smart card provides a cryptogram code, which can contain the user's requested new PIN or it can be provided to the issuer via alternative methods. Via various methods the cryptogram code is delivered to the card issuer's PIN change management system, including the user transposing the code from smart card reader screen to the card issuer's web site or audio DTMF transmission from the smart card reader speaker to the card issuer IVR system. Returned from the issuer, via a similar path, will be a command code that when processed by the smart card reader will result in a PIN change on the smart card.