Intermediate Node for Secure Password Handling on Public Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public computer terminals pose security risks for accessing private information due to the lack of effective protection against key loggers and other endpoint capture devices, as users often need to type passwords directly, compromising security.
Innovation Solution
A system using an intermediate node, such as a mobile device, to intercept and manage private information by encrypting and decrypting communications between semi-trusted and trusted nodes, preventing unsecured information from being accessed on public terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users type passwords directly on public terminals to access web-based services, then ease of operation is improved, but security is compromised due to key loggers and endpoint capture devices
Solution Approach 1:
The patent introduces an intermediary device (mobile device or dedicated security device) that sits between the user and the public terminal. This intermediary captures the password input and transmits it securely to the web service, preventing key loggers on the public terminal from accessing the password. The intermediary acts as a mediator that preserves both ease of operation (user just types password) and security (password never touches the unsecure terminal).
Solution Approach 2:
The authentication process is segmented into separate components: the public terminal handles only the display and intermediary communication, while the mobile device handles password capture and secure transmission. This segmentation isolates the security-critical operations from the unsecure environment of the public terminal, allowing users to access services without directly typing passwords on potentially compromised devices.
2Productivity
If web proxies are used for caching pages on public terminals, then productivity is improved through faster page loading, but security is not enhanced as they cannot cache secure information
Solution Approach 1:
The patent extends the functionality of mobile devices to serve multiple purposes: they act as security intermediaries for password protection, authentication tokens for secure transactions, and can function as personal web proxies for caching. This multi-functionality allows a single device to address both security concerns and productivity needs simultaneously, making the mobile device a universal solution for public terminal security.
3Reliability
If mobile devices are used to hold security and identity information, then security is improved for payment transactions, but they do not manage personal information at public terminals
Solution Approach 1:
The patent positions the mobile device as a universal intermediary that handles multiple types of information management tasks at public terminals: secure payment transactions, personal information management, web proxy caching, and authentication. This versatility allows the same device to adapt to different use cases and information types, resolving the limitation of existing mobile devices that could only handle security information but not personal information management.
Data Source
AI summary
A system and method for managing private information while using semi-trusted interfaces is described. In an embodiment, an intermediate node may receive a first and second communication between a semi-trusted node and a trusted node. In managing private information, the intermediate node may append private information to the first communication sent from the semi-trusted node to the trusted node, and remove private information from the second communication sent from the trusted node to the semi-trusted node.


