Smart Key Device Authentication for Secure Online Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online transaction methods, such as dynamic passwords and quick payments using SMS codes, are inconvenient and unsafe, especially if a user's cellphone is lost, leading to potential irreparable losses.
Innovation Solution
A smart key device method that enables quick and secure user authentication for online transactions by powering on, initializing, setting descriptors, determining command types, generating user key pairs, issuing digital certificates, and signing data fields using preset algorithms to facilitate efficient and secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dynamic password is used for online transaction, then authentication security is improved, but operation convenience deteriorates due to manual input requirement
Solution Approach 1:
The patent replaces the mechanical manual input system with an automated optical recognition system. The smart key device captures images of the dynamic password through its imaging module and automatically transmits authentication data to the terminal device, eliminating the need for manual typing while maintaining security.
Solution Approach 2:
The smart key device performs self-service authentication by automatically capturing, processing, and transmitting password data without requiring user intervention. The device autonomously completes the authentication process by interfacing directly with the terminal device's recognition system.
2Productivity
If SMS identifying code is used for quick payment, then authentication speed is improved, but security deteriorates due to vulnerability to loss or theft
Solution Approach 1:
The patent introduces a smart key device as an intermediary authentication device that stores cryptographic key pairs securely. This intermediary replaces the vulnerable SMS code system with a more secure hardware-based authentication mechanism while maintaining quick access through automatic recognition and transmission capabilities.
Solution Approach 2:
The authentication credentials (cryptographic key pairs) are pre-configured and stored securely in the smart key device before transactions occur. This preliminary setup eliminates the need for real-time SMS verification while maintaining security, as the credentials are already prepared and ready for immediate authentication.
3Reliability
If manual password input is required for each transaction, then authentication security is improved, but transaction efficiency deteriorates
Solution Approach 1:
The patent replaces the mechanical manual input process with automated optical recognition and digital transmission. The smart key device's imaging module captures password data and automatically transmits it to the terminal device, maintaining security through cryptographic methods while dramatically improving transaction speed by eliminating repetitive manual typing.
4Ease of operation
If quick payment with SMS code is implemented, then transaction convenience is improved, but risk of loss increases when device is lost
Solution Approach 1:
The smart key device serves as a secure intermediary that stores cryptographic credentials in a protected environment. This intermediary replaces the vulnerable SMS-based system with hardware-security-module-protected storage, maintaining convenience through automatic authentication while reducing risk through secure key management and the ability to remotely revoke access.
Solution Approach 2:
The system implements beforehand cushioning through secure key storage and the ability to remotely invalidate credentials. If the smart key device is lost, the authentication credentials can be remotely deactivated before misuse occurs, providing a safety buffer that prevents loss while maintaining normal convenient operation during legitimate use.
Data Source
AI summary
A work method for a smart key device. A host machine acquires data from a trusted server via a browser and then transmits the data to a smart key device; the smart key device performs a signing operation when the data transmitted by the host machine is received and when a user confirmed by pressing a key and then returns a signing result to the host machine; and the host machine transmits data returned by the smart key device to the trusted server to verify the validity of the smart key device. This implements rapid authentication of user identity, thus allowing highly efficient, secure, and expedited online transactions.


