Hardware Cryptographic Element for Secure Electronic Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Insecure electronic devices participating in electronic transactions lack effective cryptographic modules to ensure confidentiality, integrity, and authenticity, making them vulnerable to identity theft and transaction manipulation.

Innovation Solution

An electronic security device with a hardware cryptographic element that stores asymmetric keys, performs various cryptographic operations, and communicates with insecure devices to provide secure authentication and transaction processing, using external services to obtain digital certificates and session keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic modules are integrated into devices during manufacturing (TPM), then security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides security functionality into separate modules: secure elements embedded in devices for basic cryptographic operations, and remote authentication servers for complex verification. This segmentation allows simple devices to gain security capabilities without integrating complex cryptographic hardware, resolving the contradiction between security and device complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication servers as intermediaries between devices and the network. These servers handle complex authentication logic, allowing devices to use simple secure elements while still achieving strong security through the intermediary's verification processes, thus improving security without increasing device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If HSM is used to perform cryptographic operations, then security is improved, but device cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts complex cryptographic verification functions from devices and places them in remote authentication servers. Devices only need to perform basic cryptographic operations using embedded secure elements, while the extraction of complex HSM functions to external servers reduces device complexity and cost while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication servers provide universal cryptographic services to multiple devices, replacing the need for each device to have full HSM capabilities. This multi-functional approach allows simple devices to access advanced cryptographic operations through the server, improving security without increasing individual device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If crypto smartcards are used for authentication, then user authentication is improved, but device security and cryptographic capabilities are insufficient

Engineering Contradiction:
Improveuser authenticationVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the functionality of secure elements with authentication servers to create a unified security system. The secure element provides local cryptographic operations while the server provides remote verification, combining both approaches to achieve strong device security while maintaining ease of user authentication through familiar card interfaces

Inventive Principle:
Principle #5Merging (Combining)

4Device complexity

If simple IoT devices are used for transactions, then device simplicity and cost are improved, but security against identity theft and manipulation is worsened

Engineering Contradiction:
Improvedevice simplicityVSAvoidtransaction security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces authentication servers as intermediaries that compensate for the security limitations of simple IoT devices. These servers perform complex verification on behalf of devices, allowing them to maintain simplicity while achieving strong transaction security through the intermediary's protective functions

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and verification actions in advance through the authentication server, before transactions occur. This preliminary action secures the transaction framework upfront, allowing simple devices to participate securely without needing complex real-time security capabilities

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3945442B1Security method and device for electronic transactions
Publication Date: 2023.07.12 NTT DATA SPAIN SL
  • EP3945442B1 patent drawingFigure 1
  • EP3945442B1 patent drawingFigure 2
  • EP3945442B1 patent drawingFigure 3

AI summary

The present invention relates to a method and a device which equip an insecure electronic device with higher levels of security in order to carry out reliable electronic transactions. To do so, the invention comprises a hardware cryptographic element which generates cryptographic material with high entropy, suitably stores it and enables cryptographic operations to be performed on behalf of the insecure device, to which it connects by means of a communication interface. The connection between both devices leads to an initial pairing, subsequent authentication by means of cryptographic challenge and establishing a secure communication during which the security device is available to the insecure device in order to perform cryptographic operations on its behalf which enable the confidentiality, integrity, authenticity and/or non-repudiation of the electronic transactions thereof to be ensured.