Hardware Security Agent Alias Mapping for Credential Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public computer networks, such as those found in internet cafes or libraries, are vulnerable to attacks that compromise user credentials, leading to potential data breaches and financial losses due to the risk of malicious software intercepting sensitive information.

Innovation Solution

A hardware security agent that generates and manages aliases for sensitive data, allowing secure communication over untrusted networks by mapping these aliases to actual credentials, thereby protecting confidential information from interception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user credentials are transmitted over public networks, then network accessibility and convenience are improved, but security and confidentiality of data are worsened due to interception risks

Engineering Contradiction:
Improvenetwork accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a hardware security agent as an intermediary device between the user computer and the public network. This agent intercepts credential inputs, stores them securely in isolated memory, and transmits them only when authorized, preventing direct exposure to malicious software on public computers while maintaining network accessibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the credential management process into distinct components: input capture, secure storage, authorization verification, and transmission. The hardware security agent separates sensitive credential handling from the untrusted public computer environment, isolating the vulnerability source while preserving overall system functionality

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If public computers are used for network access, then ease of operation is improved, but vulnerability to malicious attacks is worsened

Engineering Contradiction:
Improvepublic network accessVSAvoidmalicious software attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The hardware security agent serves as a trusted intermediary that mediates all interactions between the public computer and the user's credentials. It captures credentials through the public computer's interface but stores and transmits them from its own secure environment, effectively blocking malicious software from accessing the actual credential data

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies preliminary anti-action by pre-emptively capturing and securing credentials before they can be exposed to malicious software. The hardware security agent monitors and intercepts credential inputs at the source, preventing malicious programs from logging or sniffing the data in the first place

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If credentials are stored on the computer, then ease of operation is improved, but security is worsened due to potential compromise of the computer system

Engineering Contradiction:
Improvecredential accessibilityVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The hardware security agent acts as an intermediary storage device that holds credentials securely outside the computer system. The agent receives credentials from the computer, stores them in protected memory with physical isolation, and returns them only when authentication is verified, preventing compromise even if the computer system is breached

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses copying by creating a secure duplicate of the credential data in the hardware security agent's isolated memory. The original credential input on the computer is not retained after transmission, and the agent maintains its own secure copy that is inaccessible to malicious software on the computer

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9225689B2Hardware security agent for network communications
Publication Date: 2015.12.29 SAP SE
  • US9225689B2 patent drawing
  • US9225689B2 patent drawing
  • US9225689B2 patent drawing

AI summary

A hardware security agent may include a request inspector configured to receive an alias at the hardware security agent by way of a network interface of an untrusted computer, and a mapper configured to map the alias to corresponding protected data stored within the hardware security agent. The hardware security agent may further include a substitution manager configured to provide the corresponding protected data from the hardware security agent over a network to a target network site.