Intermediate Node for Secure Password Handling on Public Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public computer terminals pose security risks for accessing private information due to the lack of effective protection against key loggers and other endpoint capture devices, as users often need to type passwords directly, compromising security.

Innovation Solution

A system using an intermediate node, such as a mobile device, to intercept and manage private information by encrypting and decrypting communications between semi-trusted and trusted nodes, preventing unsecured information from being accessed on public terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users type passwords directly on public terminals to access web-based services, then ease of operation is improved, but security is compromised due to key loggers and endpoint capture devices

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary device (mobile device or dedicated security device) that sits between the user and the public terminal. This intermediary captures the password input and transmits it securely to the web service, preventing key loggers on the public terminal from accessing the password. The intermediary acts as a mediator that preserves both ease of operation (user just types password) and security (password never touches the unsecure terminal).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into separate components: the public terminal handles only the display and intermediary communication, while the mobile device handles password capture and secure transmission. This segmentation isolates the security-critical operations from the unsecure environment of the public terminal, allowing users to access services without directly typing passwords on potentially compromised devices.

Inventive Principle:
Principle #1Segmentation

2Productivity

If web proxies are used for caching pages on public terminals, then productivity is improved through faster page loading, but security is not enhanced as they cannot cache secure information

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extends the functionality of mobile devices to serve multiple purposes: they act as security intermediaries for password protection, authentication tokens for secure transactions, and can function as personal web proxies for caching. This multi-functionality allows a single device to address both security concerns and productivity needs simultaneously, making the mobile device a universal solution for public terminal security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If mobile devices are used to hold security and identity information, then security is improved for payment transactions, but they do not manage personal information at public terminals

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent positions the mobile device as a universal intermediary that handles multiple types of information management tasks at public terminals: secure payment transactions, personal information management, web proxy caching, and authentication. This versatility allows the same device to adapt to different use cases and information types, resolving the limitation of existing mobile devices that could only handle security information but not personal information management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8281123B2Apparatus and method for managing and protecting information during use of semi-trusted interfaces
Publication Date: 2012.10.02 INTEL CORP
  • US8281123B2 patent drawing
  • US8281123B2 patent drawing
  • US8281123B2 patent drawing

AI summary

A system and method for managing private information while using semi-trusted interfaces is described. In an embodiment, an intermediate node may receive a first and second communication between a semi-trusted node and a trusted node. In managing private information, the intermediate node may append private information to the first communication sent from the semi-trusted node to the trusted node, and remove private information from the second communication sent from the trusted node to the semi-trusted node.