Hardware Intermediary for Secure Electronic Transaction Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Internet authentication processes are vulnerable to malicious software and man-in-the-middle attacks, making secure electronic transactions cumbersome and prone to errors, especially when relying on PKI and smart cards, as users lack control over the transaction process and may be tricked into sending sensitive information to incorrect servers.
Innovation Solution
A hardware device acts as an interface between the client and server computers, decrypting and parsing communication to display sensitive transaction information to the user, allowing verification before proceeding with transactions, using established protocols like SSL/TLS for secure communication and mutual authentication, and incorporating a security token for tamper-resistant storage of sensitive data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PKI and smart cards are used for authentication, then security is improved, but ease of operation deteriorates due to cumbersome certificate checking and lack of user control
Solution Approach 1:
A hardware device is introduced as an intermediary between the user's PC and the server. This device establishes a trusted communication channel that bypasses the need for users to manually check certificates or control smart card operations. The hardware device autonomously manages authentication, displaying server information and transaction details to the user while maintaining secure encrypted communication with the server, thus improving both security and ease of operation.
2Reliability
If server certificates are displayed for user verification, then security is improved, but loss of time increases due to cumbersome verification processes
Solution Approach 1:
The hardware device performs preliminary authentication actions by automatically establishing encrypted communication channels with servers using pre-configured security credentials. Server certificates and identities are verified in advance by the hardware device before transactions begin, eliminating the need for users to manually verify certificates during each interaction. The device displays verified server information to the user, maintaining security while reducing time loss.
3Ease of operation
If users enter confidential information on PC, then ease of operation is improved, but security deteriorates due to vulnerability to malicious software and keyboard logging
Solution Approach 1:
The hardware device serves as a secure intermediary that receives confidential information from the user through its own protected interface rather than through the potentially compromised PC keyboard. The device displays transaction information to the user and captures confirmation input in a secure environment isolated from PC-based malicious software. Confidential data is then transmitted through encrypted channels to the server, maintaining both ease of operation and security.
4Reliability
If secure smart card readers with display and keyboard are used, then security is improved, but device complexity increases
Solution Approach 1:
The invention extracts and separates the essential security functions from complex smart card reader systems. Instead of requiring a standalone secure device with built-in display and keyboard, the solution uses a simpler hardware device that establishes encrypted communication channels and displays information through the user's existing PC display. The hardware device focuses on establishing secure channels and protecting data transmission, while leveraging existing PC resources for display and input, thus reducing overall device complexity while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Performing secure electronic transactions The invention relates to a method for performing electronic transactions between a server computer (110) and a client computer (120), the method comprising the steps of: - running a first communication protocol with encrypted data transmission and mutual authentication between the server computer (110) and a hardware device (130) via a communication network (160), - performing a decryption of encrypted server responses received from the server computer (110) in the hardware device (130), - forwarding the decrypted server responses from the hardware device (130) to the client computer (120), - displaying the decrypted server responses on a client computer display (121) of the client computer (120), - receiving client requests to be send from the client computer (120) to the server computer (110) by the hardware device (130), - parsing the client requests for predefined transaction information by the hardware device (130), - encrypting and forwarding client requests that do not contain any predefined transaction information to the server computer (110) by the hardware device (130), - displaying the predefined transaction information upon detection in a client request on a hardware device display (210) of the hardware device (130), - forwarding and encrypting the client request containing the predefined transaction information to the server computer (110) if a user confirmation is received, - canceling the electronic transaction if no user confirmation is received.