Tactile Security Token for Secure On-Card Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security tokens face issues with secure authentication due to vulnerabilities in code information transfer, limited interactivity, and usability problems for users with disabilities, as well as high costs and short battery life, which compromise security and acceptance in online transactions.
Innovation Solution
A security token with an embedded tactile sensing user interface that allows users to enter secrets through tactile patterns, using a decoding unit to verify against stored data, and an external power source for extended battery life, reducing costs and enhancing usability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If code information is transferred through a keypad or keyboard, then authentication can be performed, but security is compromised due to man-in-the-middle attacks and unencrypted transmission
Solution Approach 1:
The patent extracts the secret entry function from the host system and implements it directly on the card through a tactile sensor that detects finger movements on the card surface. This eliminates the need to transfer code information through vulnerable communication channels, as the secret is entered and processed locally on the secure element.
Solution Approach 2:
The tactile sensor acts as an intermediary between the user and the authentication system. Instead of transferring encrypted code information through vulnerable channels, the system uses finger movement patterns detected by the tactile sensor as a secure intermediary mechanism for secret entry, which cannot be intercepted or replicated by man-in-the-middle attacks.
2Ease of operation
If a numerical keypad is integrated into the Smartcard, then code entry is enabled, but the key sizes become unacceptably small causing usability problems
Solution Approach 1:
The patent transitions from a discrete keypad with separate buttons to a continuous tactile surface where any position can be touched. This dimensional change from 0D buttons to 2D surface allows users to enter secrets by touching specific positions on the card surface, providing ample space for accurate finger placement while maintaining a compact card form factor.
Solution Approach 2:
The tactile sensor array dynamically identifies which specific sensor element was activated by the user's finger. Instead of having fixed physical buttons, the system dynamically determines the touched position from among many possible locations on the card surface, enabling large-area input without requiring physically large buttons.
3Area of stationary object
If a tactile sensor array is implemented on the Smartcard, then large-area secret entry is enabled, but the available surface area is limited
Solution Approach 1:
The tactile sensor array serves multiple functions: it detects finger position for secret entry, provides haptic feedback to the user, and can potentially display tactile patterns. This multi-functionality maximizes the utility of the sensor array within the limited card surface area, reducing the need for separate components and lowering overall device complexity.
4Adaptability or versatility
If battery-powered solutions are used, then interactivity is enabled, but product quality and lifetime requirements are not met
Solution Approach 1:
The card uses the existing contactless power transfer infrastructure to receive power during authentication operations. The tactile sensor and processing circuitry are designed to operate during these powered intervals, eliminating the need for a separate battery while maintaining interactivity and meeting lifetime requirements.
Data Source
AI summary
Techniques are provided for entering a secret into a security token using an embedded tactile sensing user interface with the purpose of verifying the secret against a stored representation of the same secret. In particular, an embodiment of the security token according to the invention comprises a tactile sensing user interface being arranged to receive a user-encoded secret, a decoding unit being arranged to generate a decoded secret by decoding the user-encoded secret, a comparison unit being arranged to compare the decoded secret with a copy of the secret stored in the token in order to verify the authenticity of a user. Thereby, the security token provides on-card matching functionality.


