Smartcard Transaction Code Generation for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing smartcards without cryptographic capabilities or with disabled cryptographic functions do not meet the security requirements for additional authentication factors in online financial services, and issuing additional security tokens is cost-prohibitive for service providers.
Innovation Solution
Utilizing the non-cryptographic capabilities of existing smartcards, such as generating a monotonically increasing transaction code, to provide an additional authentication factor through a secure processor that interacts with the smartcard to generate a one-time password, enabling multi-factor authentication without the need for separate cryptographic capabilities or additional tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic capabilities are provided in smartcards, then security for authentication is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the cryptographic authentication function from the smartcard itself and relocates it to a remote server. The smartcard only performs simple non-cryptographic operations (generating transaction codes), while the server handles all cryptographic operations. This separation allows the smartcard to remain simple and inexpensive while still providing secure authentication.
Solution Approach 2:
The patent introduces a remote server as an intermediary between the simple smartcard and the authentication system. This intermediary handles the complex cryptographic operations that the smartcard cannot or should not perform, enabling secure authentication without requiring cryptographic capabilities in the smartcard itself.
2Reliability
If additional security tokens are issued for authentication, then authentication security is improved, but cost and device complexity increase
Solution Approach 1:
The patent makes the existing smartcard serve multiple functions: it continues to enable financial transactions while also providing authentication for online services. By leveraging the smartcard's existing presence in the user's wallet and its ability to generate transaction codes, the system eliminates the need for separate authentication tokens, reducing costs and simplifying the system.
Solution Approach 2:
The smartcard is already something the user possesses and uses daily for financial transactions. The system leverages this existing resource to provide authentication functionality without requiring users to acquire additional security tokens. The smartcard's transaction code generation capability is repurposed to serve authentication needs.
3Ease of manufacture
If smartcards without cryptographic capabilities are used, then ease of manufacture and cost are improved, but authentication security deteriorates
Solution Approach 1:
The patent replaces the mechanical/cryptographic capability requirement in the smartcard with a software-based solution. Instead of requiring cryptographic hardware or libraries in the smartcard, the system uses a software protocol where the smartcard generates simple transaction codes and the server performs cryptographic verification. This substitution maintains security while eliminating the need for complex smartcard hardware.
Data Source
AI summary
Methods and systems are provided for non-cryptographic capabilities of a token such as a smartcard to be used as an additional authentication factor when multi-factor authentication is required. Smartcards are configured to generate a transaction code each time a transaction is attempted by the smartcard. The transaction code is dynamic, changing with each transaction, and therefore is used as a one-time password. When a user attempts to access a service or application requiring at least two authentication factors, a secure processor is used to read transaction code from the smartcard. The secure processor establishes a secure communication with the remote computer hosting the service or application. The transaction code can then be encrypted prior to transmission over the public Internet, providing an additional layer of security.


