Validity Checking System for IC Card Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In authentication systems using IC cards, there is a risk of password leakage and unauthorized use due to impersonation, as users cannot verify the authenticity of the authentication terminal, leading to potential theft of their password.

Innovation Solution

A validity checking system that includes an information processing card with a validity authenticating means and an impersonation preventing means, which performs mutual authentication with the authentication system and outputs the authentication result to a checking device for verification, ensuring the user is not inputting credentials to a forged terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mutual authentication is performed between IC card and authentication system terminal, then the validity of IC card is authenticated, but the user cannot verify the authenticity of the authentication terminal

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication result information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a checking device as an intermediary between the IC card and the user. The IC card outputs authentication result information to this checking device, which then displays the verification result to the user in a perceptible manner. This mediator enables the user to verify terminal authenticity without exposing secret information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication result information from the IC card and separates it from the secret information (password). The checking device receives only the authentication result output from the IC card, not the password itself. This extraction allows verification while protecting sensitive data from exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If secret information is displayed on terminal to prevent password leakage, then password leakage is prevented, but third party can potentially view the secret information

Engineering Contradiction:
Improvepassword protectionVSAvoidthird party viewing risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The checking device serves as a secure intermediary that receives authentication results directly from the IC card via dedicated communication interfaces. It displays verification information without requiring the password to be visible on the terminal screen, thus preventing third-party viewing while maintaining password protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts and separates the authentication result information from the password itself. The IC card outputs authentication results that can be verified independently of the password, allowing the checking device to display verification status without ever exposing or requiring display of the password.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authentication result is output from IC card to checking device, then user can verify terminal authenticity, but system complexity increases

Engineering Contradiction:
Improveterminal verification capabilityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The checking device is designed with multi-functionality, serving as both the receiver of authentication results from the IC card and the display device for verification information. It integrates multiple functions (reception, processing, and display) into a single device, reducing the need for additional separate components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication verification function with the existing IC card and terminal structures. The checking device combines the roles of receiving authentication data and presenting verification results to the user, creating a streamlined system that adds verification capability without requiring multiple separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8302176B2Validity checking system, validity checking method, information processing card, checking device, and authentication apparatus
Publication Date: 2012.10.30 NEC CORP
  • US8302176B2 patent drawing
  • US8302176B2 patent drawing
  • US8302176B2 patent drawing

AI summary

OBJECTIVEA user is prevented from inadvertently inputting authentication information to an unauthorized authentication system. In this manner, authentication information leakage is certainly avoided.SOLUTIONA validity checking system includes an information processing card, an authentication system that performs mutual authentication with the information processing card, and a checking device. The information processing card includes a validity authenticating means that authenticates the validity of the authentication system, and an impersonation preventing means that carries out an impersonation preventing process on the result of the authentication performed by the validity authenticating means. The checking device includes a verifying means that verifies the authentication result subjected to the impersonation preventing process and is output from the information processing card, and a verification result output means that outputs the result of the verification performed by the verifying means to a user in a perceptible manner. The verifying means may not be provided in the checking device, and an independent verification device may be provided.