Smart Card Offline PIN Verification via Local Digest

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smartcards face security risks due to keystroke logging methods that can intercept PIN codes, compromising authentication security in traditional visual security authentication methods.

Innovation Solution

A smartcard with a microprocessor, memory, code input keys, and a display, which generates and stores an encrypted digest of the user's PIN, allowing for one-time PIN code authentication through a proximity communication interface or input/output contact terminal, and includes features like a PIN failure counter and unlock function to manage authentication attempts and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional visual security authentication with PIN code entry is used, then user authentication is enabled, but security is compromised due to keystroke logging attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidkeystroke logging risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the PIN verification process from the card reader and relocates it to the smart card itself. The card now contains verification means that independently verify the PIN without transmitting it to the card reader, thereby removing the vulnerability point that keystroke logging exploits.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary verification mechanism within the smart card that acts as a mediator between the PIN entry and the authentication process. This intermediary component (verification means) processes the PIN locally and generates verification data without exposing the PIN to external interception.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If PIN verification is performed by the card reader, then authentication is simplified, but the PIN code becomes vulnerable to interception

Engineering Contradiction:
Improveauthentication processVSAvoidPIN interception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the traditional authentication architecture by placing the verification capability in the card rather than in the card reader. Instead of the card reader verifying the PIN, the card now performs self-verification, fundamentally reversing where the security-critical function resides.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The smart card provides self-service authentication by containing verification means that can independently verify the PIN code without external assistance. The card serves its own verification needs, eliminating the security vulnerability associated with external verification systems.

Inventive Principle:
Principle #25Self-service

3Reliability

If encrypted digest of PIN is stored in the smart card, then security is enhanced against keystroke logging, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsmart card structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the verification means directly into the smart card structure, combining multiple security functions (encryption, digest generation, verification) into a single integrated component within the card, thereby managing complexity through consolidation rather than addition.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the form of stored authentication data from plaintext PIN to encrypted digest, transforming the data parameter to enhance security. This parameter change allows the card to maintain authentication functionality while protecting against interception and logging attacks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10963864B2Smart card with verification means
Publication Date: 2021.03.30 SCRAMCARD HLDG HONG KONG
  • US10963864B2 patent drawing
  • US10963864B2 patent drawing
  • US10963864B2 patent drawing

AI summary

The present invention is directed to a smartcard that enables a one-time pin code offline security authentication with a card reader. This is achieved by generating a one-time pin code when the user inputs their pin code. The inputted pin code is encrypted and matched with the encrypted user correct pin code. If there is a match the one-time pin code is stored in memory and the transaction can proceed.