Immobile Hardware Token for Location-Restricted Banking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure internet transaction systems, particularly in electronic banking, face vulnerabilities due to the risk of malicious guests accessing account owner's devices and channels, allowing unauthorized transactions from remote locations, which can compromise security and lead to fraudulent activities.

Innovation Solution

An immobile hardware token, such as a 'wall token,' is fixed within a building and equipped with sensors to detect movement and tampering, along with a crypto-processor for secure authentication, ensuring that high-risk transactions like large money transfers can only be performed from the account owner's home, while allowing lower-risk actions from anywhere.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods (username/password) are used for electronic banking, then ease of operation is improved, but security is worsened due to vulnerability to unauthorized access from remote locations

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent factors: something you know (password), something you have (authentication device), and something you are (biometric data). This multi-factor approach ensures that compromising one factor does not compromise the entire security system, thereby maintaining both ease of operation and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An immobile hardware token fixed in the account owner's home acts as an intermediary that verifies the location of the authentication device before allowing high-risk transactions. This intermediary layer prevents remote unauthorized access while maintaining convenient authentication for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-based restrictions are implemented for high-risk transactions, then security is improved, but device complexity is worsened due to the need for multiple sensors and interfaces

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple functional components (motion sensor, tamper sensor, distance bounding interface, authentication interface, and crypto-processor) are merged into a single immobile hardware token device. This consolidation achieves the desired security functionality while minimizing the number of separate devices and interfaces the user must interact with.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The immobile hardware token autonomously performs location verification and authentication validation without requiring complex user configuration or manual location checking. The device self-manages the security protocols, reducing the operational complexity for users while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If distance bounding and proximity verification are implemented, then security is improved by preventing remote access, but measurement precision requirements are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidmeasurement precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system implements partial verification by checking whether the authentication device is within a sufficient proximity threshold for high-risk transactions, rather than requiring precise location mapping or exact distance measurements. This approach provides adequate security for banking transactions without demanding extreme measurement precision.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Physical proximity verification through sensors is combined with cryptographic challenge-response protocols to authenticate transactions. The cryptographic layer provides mathematical certainty about the authenticity of the authentication device, substituting the need for extremely precise physical measurement systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security by ensuring that sensitive transactions are restricted to the account owner's home, preventing unauthorized access and fraud by verifying the proximity of authentication devices to the hardware token, thus providing a robust multi-factor authentication system.

Implementation Method 1

a first sensor configured to detect if the hardware token is moved

Methodology Applied
Scientific EffectMotion sensing:

Implementation Method 2

a second sensor configured to detect if the hardware token is tampered with

Methodology Applied
Scientific EffectMechanical sensing:

Implementation Method 3

a first interface configured to provide distance bounding

Methodology Applied
Scientific EffectDistance bounding:

Implementation Method 4

a crypto-processor configured to provide for secure authentication

Methodology Applied
Scientific EffectCrypto-processing:

Data Source

PatentUS11502843B2Enabling secure internet transactions in an unsecure home using immobile token
Publication Date: 2022.11.15 NXP BV
  • US11502843B2 patent drawing
  • US11502843B2 patent drawing
  • US11502843B2 patent drawing

AI summary

This specification discloses devices and methods for a security concept that includes an immobile hardware token (e.g., a “wall token” that is fixed within a wall) which ensures that the more sensitive actions of electronic banking (e.g., money transfers of large sums to foreign bank accounts) can only be done from the account owner's home, but not from a remote place. However, other less sensitive (and lower security risk) actions can still be done from anywhere else. In some embodiments, the hardware token includes sensors to ensure that the token is not moved or tampered with, interfaces to provide distance bounding, and a crypto-processor to provide secure authentication. The distance bounding can be used to determine if the authentication device is in close proximity to the hardware token, which can in turn ensure that the authentication device is within the account owner's home.