Smartphone IC Chip Secure Authentication System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current transaction authentication methods for online services, such as hardware tokens, are inconvenient for users, impractical due to the need to carry multiple devices, and costly for service providers, while existing security measures like one-time passwords are ineffective against MITM attacks.

Innovation Solution

An online service providing system using integrated circuit chips in user devices with secure memory areas storing personal information and private keys, enabling user authentication and electronic signatures without exposing the private key to external applications, and a server verifying electronic signatures for secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware tokens are used for transaction authentication, then security against MITM attacks is improved, but user convenience deteriorates due to the need to carry additional devices

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the security functions (authentication and electronic signature) directly into the smartphone's existing IC chip infrastructure, eliminating the need for separate hardware tokens. The secure memory area and cryptographic functions are integrated within the device the user already carries, thus maintaining security while improving convenience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The IC chip in the smartphone is designed to perform multiple functions including authentication, electronic signature generation, and secure key storage. This multi-functional approach replaces the need for service-specific tokens, allowing a single device to provide security for multiple online services without requiring users to carry multiple tokens.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If service-specific tokens are distributed for each online service, then authentication security is improved, but device complexity increases as users must manage multiple tokens

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of tokens
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism where the smartphone's IC chip can serve multiple online services. The electronic certificate and private key stored in the secure memory area enable the device to perform authentication and electronic signatures for various services without requiring service-specific tokens, thus reducing the number of devices users must manage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses electronic certificates and cryptographic keys stored in the smartphone's secure memory to replicate the security functions of physical tokens. This digital copying approach allows the smartphone to assume the role of multiple service-specific tokens, eliminating the need for users to physically carry and manage separate token devices for each service.

Inventive Principle:
Principle #26Copying

3Reliability

If hardware tokens are distributed and managed by service providers, then transaction security is improved, but operational cost increases

Engineering Contradiction:
Improvetransaction securityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent enables the smartphone itself to provide security services through its integrated IC chip and secure memory. The device autonomously performs authentication and electronic signature functions using its own cryptographic keys, eliminating the service provider's need to distribute, manage, and replace physical tokens. This self-service approach significantly reduces operational costs while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the security functions from the service provider's operational domain and relocates them to the user's smartphone. By moving authentication and electronic signature capabilities to the user's device, the service provider eliminates the costs associated with token distribution, management, and replacement, while users gain self-sufficient security capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3817279B1Online service provision system and application program
Publication Date: 2025.11.12 JAPAN COMM INC
  • EP3817279B1 patent drawingFigure 1
  • EP3817279B1 patent drawingFigure 2
  • EP3817279B1 patent drawingFigure 3

AI summary

When a user tries to perform a procedure of transfer or the like through an application, user authentication using a PIN code or the like is first requested. If the user authentication succeeds, a function restriction on an IC chip is removed, and a mode in which a function provided by the IC chip is available is established. The application utilizes the function of the IC chip to encrypt a procedure message describing procedure contents using a secret key to generate an electronic signature. When these electronic signature and procedure message are transmitted to a server of an online service, the server verifies the electronic signature using a corresponding electronic certificate. If, as a result of the verification, it is confirmed that the procedure message is a procedure message transmitted from a legitimate user and the contents thereof are not falsified, the server executes a procedure of transfer or the like in accordance with the contents of the procedure message.