Hardware Wallet Binding Authorization via Pre-generated Code
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hardware wallets are vulnerable to unauthorized access when an illegitimate user obtains both the matching code and PIN code, allowing them to connect to a terminal and misuse the legitimate user's assets.
Innovation Solution
A method and device for binding and authorizing a hardware wallet that generates and uses an authorization code, ensuring that only authorized terminals can connect by authenticating the binding instruction using the authorization code, thereby protecting user assets even if the wallet is lost or stolen.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the hardware wallet uses only matching code and PIN code for authentication, then the connection process is simple and fast, but the security is insufficient and assets can be accessed by illegitimate users who obtain these codes
Solution Approach 1:
The patent applies preliminary action by generating and storing an authorization code in advance within the hardware wallet before any terminal connection occurs. This pre-established authorization mechanism ensures that even if matching code and PIN code are compromised, the pre-generated authorization code remains required for terminal authentication, thereby enhancing security without significantly complicating the connection process
Solution Approach 2:
The patent introduces an authorization code as an intermediary element between the existing authentication mechanisms (matching code and PIN code) and terminal access. This intermediary authorization code acts as an additional layer that mediates the authentication process, allowing the system to maintain simplicity while improving security by requiring this intermediate authorization step
2Reliability
If the hardware wallet requires authorization code for terminal connection, then unauthorized access is prevented, but the binding and connection process becomes more complex
Solution Approach 1:
The authorization code is generated and stored in advance within the hardware wallet before terminal binding occurs. This preliminary generation eliminates the need for complex real-time authorization mechanisms during binding, as the code is already prepared and can be efficiently verified during the connection process
Solution Approach 2:
The hardware wallet autonomously generates and manages its own authorization code without requiring external intervention or complex coordination. The device self-services the authentication mechanism by internally generating the code and handling its verification, which simplifies the overall binding process while maintaining strong security
Data Source
AI summary
A hardware wallet binding authorization method. The method comprises: when a hardware wallet receives a binding state query instruction, determining the value of a verification data existence sign; if the value is first preset data, setting a binding object as null, and setting an authorization state as allowing generation of an authorization code; if the value is second preset data, setting the binding object as a terminal corresponding to the hardware wallet, or other terminals; returning the binding object and a saved hardware wallet certificate to the terminal; when the hardware wallet receives an authorization code generation instruction, if the authorization state is allowing generation of a state code, generating, caching and displaying an authorization code, setting the authorization state as not able to generate an authorization code again, and setting the state of the hardware wallet as unbound; and when the hardware wallet receives a binding instruction, using the acquired authorization code to verify the binding instruction, and if the verification is successful, binding being successful. The terminal can only be connected to the hardware wallet by means of user authorization, such that the security of user assets is ensured.


