Smart Card Virtual Code Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for generating one-time passwords (OTPs) are insecure due to the need for separate devices and the risk of seed data leakage, which compromises user authentication.
Innovation Solution
A method and system for generating a virtual code for authentication using a smart card device with an embedded IC chip, which transmits time data to the device upon tagging, generates a virtual code for primary authentication, and then generates a secondary authentication code using the primary code, without the need for a separate OTP device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate OTP generation device is used to generate one-time passwords, then authentication security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent combines the OTP generation device with the smart card, merging two previously separate components into one integrated unit. The smart card now contains both the authentication credentials and the OTP generation capability, eliminating the need for a separate OTP device while maintaining security.
Solution Approach 2:
The smart card is enhanced to perform multiple functions: it serves as both the authentication credential carrier and the OTP generation device. This multi-functional design allows the single card to handle both identification and dynamic password generation, simplifying the overall system architecture.
2Reliability
If seed data is stored in a separate OTP device, then authentication security is improved, but ease of operation deteriorates due to the need to carry multiple devices
Solution Approach 1:
The patent merges the seed data storage function with the smart card, consolidating authentication credentials and OTP generation capability into a single portable device. Users no longer need to carry separate OTP devices, improving convenience while maintaining security through the integrated design.
3Ease of operation
If actual card number is written on the card surface for identification, then ease of operation is improved, but security deteriorates due to visual leakage
Solution Approach 1:
The patent replaces the actual card number with a virtual code that serves as a secure copy or representation. This virtual code can be displayed or used for transactions without exposing the real card number, preventing visual leakage while maintaining the functionality needed for identification and transactions.
4Ease of operation
If card number is transferred to POS device during magnetic payment, then ease of operation is improved, but security deteriorates due to data leakage
Solution Approach 1:
The patent uses a virtual code as a secure copy that replaces the actual card number during transactions. The virtual code can be transferred to POS devices for payment processing without exposing the real card number, enabling convenient transactions while preventing data leakage through secure tokenization.
Data Source
AI summary
Provided are a smart card device, a device for generating a virtual code for authentication, a method of generating a virtual code for authentication using the same, and a server for verifying a virtual code for authentication. The method includes transmitting time data to a card upon tagging of the card in which an IC chip has been embedded, receiving, from the card, a virtual code for primary authentication generated based on the time data, generating a virtual code for secondary authentication by using the virtual code for primary authentication, transmitting at least one of the virtual code for primary authentication and the virtual code for secondary authentication to a server, and requesting the server to perform verification on the at least one.


