Smart Card PKI Authentication for Financial Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current username and password authentication methods are vulnerable to forgetfulness, guessability, and shared passwords, and do not ensure the user's identity is verified as the intended recipient of services.

Innovation Solution

Implementing a Public Key Infrastructure (PKI) using private key digital certificates embedded on bank-issued credit/debit cards or mobile devices, where users authenticate by entering a PIN or using biometrics, enabling secure access to services and transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If username and password authentication is used, then ease of operation is improved, but reliability deteriorates due to vulnerabilities such as forgetfulness, guessability, and shared passwords

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical username-password authentication system with a public key infrastructure (PKI) system using digital certificates and cryptographic key pairs. The smart card contains a private key, while the server stores the corresponding public key. Authentication is achieved through cryptographic verification rather than memorized credentials, eliminating vulnerabilities associated with human memory and password management while maintaining ease of use through the smart card interface.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a smart card as an intermediary device that securely stores the private key and facilitates authentication between the user and the server. The smart card acts as a physical mediator that prevents direct exposure of cryptographic keys while enabling secure authentication transactions, thereby improving both reliability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PKI with smart cards is implemented, then reliability is improved through secure authentication, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing multi-functional smart cards that users already possess for other purposes (such as banking or identification). By integrating authentication functionality into these existing universal cards, the system avoids requiring entirely new specialized devices, thereby reducing the perceived complexity for users while maintaining high security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system is designed to be self-service oriented, where the smart card automatically performs cryptographic operations without requiring user intervention beyond presenting the card. The card itself manages key storage and authentication protocols, reducing the complexity burden on both users and system administrators.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If private keys are embedded on smart cards, then ease of operation is improved by eliminating passwords, but loss of information increases risk if the card is lost or stolen

Engineering Contradiction:
Improveelimination of password managementVSAvoidrisk of key loss
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the authentication system into multiple components: the smart card holds the private key, the server holds the public key, and additional verification factors (such as PINs or biometrics) provide layered security. This segmentation ensures that loss or theft of a single component does not compromise the entire system, as the private key remains protected within the secure environment of the smart card and cannot be easily extracted or replicated.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20220067734A1Systems, methods, and devices for user authentication using cards with private keys
Publication Date: 2022.03.03 JPMORGAN CHASE BANK NA
  • US20220067734A1 patent drawing
  • US20220067734A1 patent drawing
  • US20220067734A1 patent drawing

AI summary

Systems and methods for conducting transactions using cards with keys are disclosed. In one embodiment, a method may include: receiving, at a backend for a financial institution in a transaction, a unique identifier for a card, a key read from the card by a card reading device, and additional data received by the card reading device, the card reading device associated with a merchant; retrieving, by the backend, stored additional data associated with the unique identifier; retrieving, by the backend, a stored key associated with the unique identifier in response to the received additional data matching the stored additional data; confirming, by the backend, that the received key and the stored key are related; retrieving, by the backend, a payment mechanism for the transaction; conducting, by the backend, the transaction with the retrieved payment mechanism; and settling, by the backend, the transaction with the merchant.