Context-Aware Secure Token Generation for Laptop Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for securing laptop computer devices during online transactions are vulnerable to data compromise, particularly in 'card-not-present' purchases, as they often require a connection to a token provision service and cannot provide secure tokens to web browsers for use in merchant transactions.

Innovation Solution

A method and system that generates a secure token unique to both the laptop device and its context of use, allowing it to be used only within that context, eliminating the need for a cloud connection by storing the token locally and providing it directly to the web browser for secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a connection to a token provision service is required to access secure tokens, then token security is maintained through centralized control, but system complexity and dependency on external services increase

Engineering Contradiction:
Improvetoken securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the token provisioning system by separating the secure token generation (performed by the security management computing device) from the token storage and usage (performed locally in the laptop's secure element). This allows the laptop to operate independently without continuous connection to external token provision services, reducing system complexity while maintaining security through distributed architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a web browser as an intermediary component that facilitates communication between the application layer and the secure token storage in the secure element. This intermediary enables secure token access for web-based transactions without requiring direct connection to external token provision services, simplifying the system architecture while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If secure tokens are stored locally in the laptop device, then authentication speed and transaction processing time are improved, but security risk increases if the local storage is compromised

Engineering Contradiction:
Improvetransaction processing timeVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by storing secure tokens in a dedicated secure element within the laptop device, separate from the main filesystem and accessible only through controlled interfaces. This localized secure storage provides fast authentication access while maintaining high security through physical and logical isolation, mitigating the risk of local storage compromise

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs preliminary action by pre-generating secure tokens associated with both the laptop device and the context of use before actual transactions occur. These tokens are stored securely in advance, enabling rapid authentication during transactions without real-time connection to external services, thus improving productivity while maintaining security through advance preparation

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a secure token is unique to both the device and context of use, then security and authentication accuracy are improved, but token management complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidtoken management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a secure token that serves multiple functions simultaneously: it authenticates the laptop device identity, validates the context of use, and enables secure transactions. This multi-functional token reduces the need for separate authentication mechanisms, simplifying token management while maintaining high authentication accuracy through consolidated security verification

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10848467B2Systems and methods for securing a laptop computer device
Publication Date: 2020.11.24 MASTERCARD INT INC
  • US10848467B2 patent drawing
  • US10848467B2 patent drawing
  • US10848467B2 patent drawing

AI summary

A method for securing a laptop computer device using a security management computing device includes receiving a request for a secure token, the request including (i) a device unique identifier associated with the laptop computer device, and (ii) a context unique identifier associated with a context of using the laptop computer device to initiate data communications. The method also includes generating a secure token associated with both the laptop computer device and the context of using the laptop computer device, such that the secure token is usable only within the context, and transmitting the secure token to the laptop computer device.