Smart Card PIN Servicing via Intermediary Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing PIN servicing systems are inconvenient for customers who forget their PIN, as they require physical visits to secure terminals and incur costs for banks, and may lead to customer defection due to delays in PIN recovery.
Innovation Solution
A method where a smart card interfaces with a reader to generate authentication messages sent to a PIN servicing centre, allowing validation responses to unlock or change the PIN without the need for physical presence, using dynamic one-time codes and cryptographic keys to ensure security and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the customer physically attends a secure terminal (ATM) to recover a forgotten PIN, then the PIN can be recovered securely, but the customer experiences inconvenience and time delay
Solution Approach 1:
A PIN servicing centre acts as an intermediary between the customer and the smart card system. The centre receives authentication messages from readers, validates them against the card issuer database, and returns validation response messages. This intermediary enables remote PIN recovery while maintaining security controls that would otherwise require physical presence at a secure terminal.
Solution Approach 2:
The patent replaces the mechanical/physical system of attending an ATM terminal with an electronic communication system. Authentication messages are transmitted electronically between the reader, PIN servicing centre, and card issuer database, eliminating the need for physical travel while maintaining security through cryptographic validation.
2Reliability
If the customer physically visits an ATM to unlock the smart card, then the card can be unlocked, but the bank incurs costs for inbound calls and PIN re-advice mailing
Solution Approach 1:
The system enables customers to service their own PIN requirements through remote authentication. The reader and PIN servicing centre allow customers to retrieve or reset their PINs without requiring bank staff intervention, call centre interaction, or physical mailing of PIN re-advice, thereby eliminating associated operational costs.
3Reliability
If the PIN recovery process requires physical presence at a secure terminal, then security is maintained, but customers may defect to competitor products
Solution Approach 1:
The system provides dynamic flexibility in how PIN recovery is performed. While maintaining security through cryptographic validation and authentication protocols, the system adapts to customer needs by allowing remote recovery through various reader interfaces (PC cards, mobile phones, PDAs), preventing customer defection to competitors.
4Reliability
If dynamic one-time codes and cryptographic keys are used for authentication, then fraud is prevented, but the system complexity increases
Solution Approach 1:
The smart card and reader system perform multiple functions using the same cryptographic infrastructure. The smart card serves as both the secure element for storing PIN data and the authentication device for generating cryptographic messages. The reader provides both display/output functionality and authentication input capabilities. This multi-functionality reduces overall system complexity despite the use of sophisticated cryptographic protocols.
Data Source
AI summary
A smart card (1) interfaces with a smart card reader (2) to generate an authentication message (PSRQ), which is sent to a PIN servicing centre (5, 6). If the authentication message (PSRQ) is validated by the PIN servicing centre (5, 6), a validation response message (PSRS) is sent back to the user (3). The user (3) enters the validation response message (PSRS) on the reader (2), which authenticates the validation response message (PSRS) with the smart card (1); the PIN servicing function may then be performed. The smart card cryptographic messages are generated internally and solely by the smart card (1)—the reader (2) acts merely as an input mechanism into the smart card (1) or as an output mechanism from the smart card (1) to the display (10). The reader (2), therefore, does not need to contain any customer information or be personalised by the card issuer.


