Smartphone Authentication Using External Secure Medium

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for authenticating users on smartphones running Android or Apple iOS to access secure WEB applications are limited, as they typically store keys and digital certificates internally or on µSD cards, restricting secure transactions.

Innovation Solution

A method that uses a smartphone with an internet browser and a mobile authentication application to redirect the user to an authentication server, where a challenge is sent, prompting the user to unlock a secure external device (smart card or USB key) for authentication, calculating a cryptogram, and transmitting it to the server for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If keys and digital certificates are stored internally on smartphone or on µSD card, then authentication can be performed on smartphone, but secure transactions are restricted and authentication strength is limited

Engineering Contradiction:
Improveauthentication strengthVSAvoidtransaction capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a secure external medium (smart card or USB key) as an intermediary device that stores cryptographic keys and digital certificates. This external medium acts as a mediator between the user and the authentication system, enabling strong authentication while maintaining versatility across different devices. The secure external medium contains a cryptographic module that performs cryptographic operations without exposing the private key, thus providing both security and adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the secure external medium universal by enabling it to work with multiple device types (PC, Mac, Smartphone) through standardized communication interfaces. The same smart card or USB key can be used for authentication across different operating systems and devices, eliminating the need for device-specific authentication mechanisms and enhancing both authentication strength and transaction versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple key media and digital certificates are used for different devices, then device-specific authentication is enabled, but user management complexity increases

Engineering Contradiction:
Improvedevice compatibilityVSAvoidkey media management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal secure external medium that can be used across multiple device types (PC, Mac, Smartphone) with different operating systems. The smart card or USB key contains all necessary cryptographic credentials and can perform authentication operations on any supported device, eliminating the need for users to manage separate key media for each device and significantly reducing management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If cryptographic operations are performed on smartphone, then authentication can be completed on mobile device, but security may be compromised due to smartphone vulnerabilities

Engineering Contradiction:
Improvemobile authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses a secure external medium as an intermediary that performs all sensitive cryptographic operations outside the smartphone's vulnerable environment. The smart card or USB key contains a protected cryptographic module that generates and stores private keys in a secure element, performing all cryptographic operations internally without exposing sensitive data to the smartphone's potentially insecure software environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication system into two distinct parts: a secure external medium that handles sensitive cryptographic operations and key storage, and a smartphone that provides only the user interface and communication channel. This segmentation isolates security-critical functions from the vulnerable smartphone environment while maintaining ease of mobile operation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3732852B1Method for authentication by means of a mobile terminal using a key and a certificate stored on an external medium
Publication Date: 2021.12.22 IMPRIMERIE NAT
  • EP3732852B1 patent drawingFigure 1

AI summary

The invention relates to a method for authentication in a secure web application of a user provided with a smartphone previously loaded with an internet browser and a mobile authentication application, said method using a standard internet browser on the smartphone, and a secure external medium such as a chip card in order to calculate a cryptogram that is submitted by the smartphone to an authentication server.