Title: System and method for encrypted smart card PIN entry
Application Number: 200610108186 Application Date: 2006.07.31
Publication Number: 1913427 Publication Date: 2007.02.14
Approval Pub. Date: Granted Pub. Date:
International Classifi-cation: H04L9/00;H04L9/18;H04L9/32;G07F7/10
Applicant(s) Name: Res In Motion Ltd. Address:
Inventor(s) Name: Brown Michael K.;Adams Neil;Little Herb
Attorney & Agent: wang wei
Abstract:
    A smart card, system, and method for securely authorizing a user or user device using the smart card is provided. The smart card is configured to provide, upon initialization or a request for authentication, a public key to the user input device such that the PIN or password entered by the user is encrypted before transmission to the smart card via a smart card reader. The smart card then decrypts the PIN or password to authorize the user. Preferably, the smart card is configured to provide both a public key and a nonce to the user input device, which then encrypts a concatenation or other combination of the nonce and the user-input PIN or password before transmission to the smart card. The smart card reader thus never receives a copy of the PIN or password in the clear, allowing the smart card to be used with untrusted smart card readers.
Time: 4
<- Previous Patent:Automatic vending machine   |  Next Patent:Automatic vending machine ->