Hardware Signature Payment Authentication Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Consumers are vulnerable to identity and payment credential exposure due to malware, necessitating an improved system for detecting malware before payment information is compromised during transactions.

Innovation Solution

A system that creates a unique hardware signature based on a computer system's profile, generates a key, and requires user input verification to ensure the transaction is secure, with remediation actions initiated if malware is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional payment authentication methods are used, then transaction speed is maintained, but user identity and payment credentials are vulnerable to malware exposure

Engineering Contradiction:
Improvepayment authentication securityVSAvoidmalware exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary malware detection by creating a hardware signature before the payment transaction occurs. The signature is generated from the device's hardware profile and compared against known malware patterns, allowing the system to detect malicious software presence in advance and prevent credential exposure before it happens

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The hardware signature acts as an intermediary between the payment authentication system and the device hardware. Instead of directly storing or transmitting sensitive payment credentials, the system uses the hardware signature as a mediator to verify device identity and detect malware, thereby protecting credentials while maintaining authentication functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If malware detection is performed before transactions, then payment credential protection is improved, but system complexity increases

Engineering Contradiction:
Improvecredential protectionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the essential hardware identification information needed to create the signature, separating the malware detection function from the full payment processing system. By taking out only the necessary hardware profile data and creating a simplified signature comparison mechanism, the system reduces complexity while maintaining effective malware detection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates a simplified copy of the hardware profile in the form of a signature that can be quickly compared against malware patterns. This copying approach allows malware detection without requiring the full hardware profile to be stored or processed, reducing system complexity while maintaining detection capability

Inventive Principle:
Principle #26Copying

3Measurement precision

If hardware signature creation is performed, then unique device identification is achieved, but processing time increases

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidsignature creation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs partial action by creating a condensed signature from the hardware profile rather than processing the entire profile. This selective signature generation approach maintains sufficient device identification accuracy while significantly reducing processing time compared to full profile analysis

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9824356B2Tool for creating a system hardware signature for payment authentication
Publication Date: 2017.11.21 BANK OF AMERICA CORP
  • US9824356B2 patent drawing
  • US9824356B2 patent drawing
  • US9824356B2 patent drawing

AI summary

Embodiments of the invention provide a method a authenticating a transaction at the point of transaction. In some embodiments of the invention, a unique signature is created based at least in part on a hardware profile of the system. In some embodiments, a request is received from a user to perform a transaction using the system. In some embodiments, in response to receiving the request a key is created based on the unique signature and displayed to the user. In some embodiments, user input entered in response to the user viewing the key is received and it is determined whether to proceed with transaction payment authentication based at least on whether the received user input matches the created key.