Smart Card Offline PIN Verification via Local Digest
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Smartcards face security risks due to keystroke logging methods that can intercept PIN codes, compromising authentication security in traditional visual security authentication methods.
Innovation Solution
A smartcard with a microprocessor, memory, code input keys, and a display, which generates and stores an encrypted digest of the user's PIN, allowing for one-time PIN code authentication through a proximity communication interface or input/output contact terminal, and includes features like a PIN failure counter and unlock function to manage authentication attempts and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional visual security authentication with PIN code entry is used, then user authentication is enabled, but security is compromised due to keystroke logging attacks
Solution Approach 1:
The patent extracts the PIN verification process from the card reader and relocates it to the smart card itself. The card now contains verification means that independently verify the PIN without transmitting it to the card reader, thereby removing the vulnerability point that keystroke logging exploits.
Solution Approach 2:
The patent introduces an intermediary verification mechanism within the smart card that acts as a mediator between the PIN entry and the authentication process. This intermediary component (verification means) processes the PIN locally and generates verification data without exposing the PIN to external interception.
2Ease of operation
If PIN verification is performed by the card reader, then authentication is simplified, but the PIN code becomes vulnerable to interception
Solution Approach 1:
The patent inverts the traditional authentication architecture by placing the verification capability in the card rather than in the card reader. Instead of the card reader verifying the PIN, the card now performs self-verification, fundamentally reversing where the security-critical function resides.
Solution Approach 2:
The smart card provides self-service authentication by containing verification means that can independently verify the PIN code without external assistance. The card serves its own verification needs, eliminating the security vulnerability associated with external verification systems.
3Reliability
If encrypted digest of PIN is stored in the smart card, then security is enhanced against keystroke logging, but device complexity increases
Solution Approach 1:
The patent merges the verification means directly into the smart card structure, combining multiple security functions (encryption, digest generation, verification) into a single integrated component within the card, thereby managing complexity through consolidation rather than addition.
Solution Approach 2:
The patent changes the form of stored authentication data from plaintext PIN to encrypted digest, transforming the data parameter to enhance security. This parameter change allows the card to maintain authentication functionality while protecting against interception and logging attacks.
Data Source
AI summary
The present invention is directed to a smartcard that enables a one-time pin code offline security authentication with a card reader. This is achieved by generating a one-time pin code when the user inputs their pin code. The inputted pin code is encrypted and matched with the encrypted user correct pin code. If there is a match the one-time pin code is stored in memory and the transaction can proceed.


