Hardware Cryptographic Element for Secure Electronic Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Insecure electronic devices participating in electronic transactions lack effective cryptographic modules to ensure confidentiality, integrity, and authenticity, making them vulnerable to identity theft and transaction manipulation.
Innovation Solution
An electronic security device with a hardware cryptographic element that stores asymmetric keys, performs various cryptographic operations, and communicates with insecure devices to provide secure authentication and transaction processing, using external services to obtain digital certificates and session keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic modules are integrated into devices during manufacturing (TPM), then security is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The system divides security functionality into separate modules: secure elements embedded in devices for basic cryptographic operations, and remote authentication servers for complex verification. This segmentation allows simple devices to gain security capabilities without integrating complex cryptographic hardware, resolving the contradiction between security and device complexity
Solution Approach 2:
The patent introduces authentication servers as intermediaries between devices and the network. These servers handle complex authentication logic, allowing devices to use simple secure elements while still achieving strong security through the intermediary's verification processes, thus improving security without increasing device complexity
2Reliability
If HSM is used to perform cryptographic operations, then security is improved, but device cost and complexity increase
Solution Approach 1:
The patent extracts complex cryptographic verification functions from devices and places them in remote authentication servers. Devices only need to perform basic cryptographic operations using embedded secure elements, while the extraction of complex HSM functions to external servers reduces device complexity and cost while maintaining security
Solution Approach 2:
The authentication servers provide universal cryptographic services to multiple devices, replacing the need for each device to have full HSM capabilities. This multi-functional approach allows simple devices to access advanced cryptographic operations through the server, improving security without increasing individual device complexity
3Ease of operation
If crypto smartcards are used for authentication, then user authentication is improved, but device security and cryptographic capabilities are insufficient
Solution Approach 1:
The patent merges the functionality of secure elements with authentication servers to create a unified security system. The secure element provides local cryptographic operations while the server provides remote verification, combining both approaches to achieve strong device security while maintaining ease of user authentication through familiar card interfaces
4Device complexity
If simple IoT devices are used for transactions, then device simplicity and cost are improved, but security against identity theft and manipulation is worsened
Solution Approach 1:
The patent introduces authentication servers as intermediaries that compensate for the security limitations of simple IoT devices. These servers perform complex verification on behalf of devices, allowing them to maintain simplicity while achieving strong transaction security through the intermediary's protective functions
Solution Approach 2:
The system performs preliminary authentication and verification actions in advance through the authentication server, before transactions occur. This preliminary action secures the transaction framework upfront, allowing simple devices to participate securely without needing complex real-time security capabilities
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method and a device which equip an insecure electronic device with higher levels of security in order to carry out reliable electronic transactions. To do so, the invention comprises a hardware cryptographic element which generates cryptographic material with high entropy, suitably stores it and enables cryptographic operations to be performed on behalf of the insecure device, to which it connects by means of a communication interface. The connection between both devices leads to an initial pairing, subsequent authentication by means of cryptographic challenge and establishing a secure communication during which the security device is available to the insecure device in order to perform cryptographic operations on its behalf which enable the confidentiality, integrity, authenticity and/or non-repudiation of the electronic transactions thereof to be ensured.