Context-Aware Secure Token Generation for Laptop Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for securing laptop computer devices during online transactions are vulnerable to data compromise, particularly in 'card-not-present' purchases, as they often require a connection to a token provision service and cannot provide secure tokens to web browsers for use in merchant transactions.
Innovation Solution
A method and system that generates a secure token unique to both the laptop device and its context of use, allowing it to be used only within that context, eliminating the need for a cloud connection by storing the token locally and providing it directly to the web browser for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a connection to a token provision service is required to access secure tokens, then token security is maintained through centralized control, but system complexity and dependency on external services increase
Solution Approach 1:
The patent segments the token provisioning system by separating the secure token generation (performed by the security management computing device) from the token storage and usage (performed locally in the laptop's secure element). This allows the laptop to operate independently without continuous connection to external token provision services, reducing system complexity while maintaining security through distributed architecture
Solution Approach 2:
The patent introduces a web browser as an intermediary component that facilitates communication between the application layer and the secure token storage in the secure element. This intermediary enables secure token access for web-based transactions without requiring direct connection to external token provision services, simplifying the system architecture while maintaining security
2Productivity
If secure tokens are stored locally in the laptop device, then authentication speed and transaction processing time are improved, but security risk increases if the local storage is compromised
Solution Approach 1:
The patent implements local quality by storing secure tokens in a dedicated secure element within the laptop device, separate from the main filesystem and accessible only through controlled interfaces. This localized secure storage provides fast authentication access while maintaining high security through physical and logical isolation, mitigating the risk of local storage compromise
Solution Approach 2:
The patent performs preliminary action by pre-generating secure tokens associated with both the laptop device and the context of use before actual transactions occur. These tokens are stored securely in advance, enabling rapid authentication during transactions without real-time connection to external services, thus improving productivity while maintaining security through advance preparation
3Reliability
If a secure token is unique to both the device and context of use, then security and authentication accuracy are improved, but token management complexity increases
Solution Approach 1:
The patent implements universality by designing a secure token that serves multiple functions simultaneously: it authenticates the laptop device identity, validates the context of use, and enables secure transactions. This multi-functional token reduces the need for separate authentication mechanisms, simplifying token management while maintaining high authentication accuracy through consolidated security verification
Data Source
AI summary
A method for securing a laptop computer device using a security management computing device includes receiving a request for a secure token, the request including (i) a device unique identifier associated with the laptop computer device, and (ii) a context unique identifier associated with a context of using the laptop computer device to initiate data communications. The method also includes generating a secure token associated with both the laptop computer device and the context of using the laptop computer device, such that the secure token is usable only within the context, and transmitting the secure token to the laptop computer device.


