Removable Security Device Trusted Server Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security methods using portable storage media are vulnerable to fraud, particularly social engineering and adware-based attacks, as they rely on self-managed security processes that can be compromised by phishing and keylogging, lacking effective mechanisms to prevent unauthorized access and data interception.
Innovation Solution
A removable security device with integrated security processes that establishes secure communications with a remote server system, authenticates the device, and manages access privileges, preventing secure communication unless the remote system is verified, thereby protecting against unauthorized access and data interception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If self-managed security processes are used in portable storage devices, then device autonomy and ease of operation are improved, but security reliability deteriorates due to vulnerability to phishing and keylogging attacks
Solution Approach 1:
The patent introduces a remote server system as an intermediary that verifies the authenticity of security processes. Instead of the portable device independently managing security, the device communicates with a remote server that validates security processes and credentials, preventing phishing attacks by ensuring credentials are only provided to authorized servers.
Solution Approach 2:
The system implements feedback mechanisms where the remote server verifies security processes and provides authentication responses. The portable device receives verification results from the remote server, allowing it to determine whether to proceed with security operations based on the server's authentication of the security process.
2Reliability
If credentials are provided to remote servers for secure communication, then secure access is improved, but vulnerability to fraud increases if servers are not properly verified
Solution Approach 1:
The patent implements preliminary verification where the portable device checks whether a remote server is an authorized security server before providing any credentials. This pre-verification step ensures that credentials are only transmitted to legitimate servers, preventing phishing attacks where fraudulent servers attempt to steal credentials.
Solution Approach 2:
The remote server acts as a trusted intermediary that the portable device communicates with for verification. The device only provides credentials after confirming the server's authenticity through this intermediary relationship, creating a trusted communication channel that prevents fraud.
3Reliability
If security processes are continuously enabled, then security coverage is improved, but resource consumption and ease of operation deteriorate
Solution Approach 1:
The patent implements dynamic security process management where security processes are enabled or disabled based on whether an authorized remote server is accessible. Instead of continuous operation, the security processes adapt their state based on server availability and authentication status, reducing resource consumption when security operations are not needed.
Data Source
AI summary
A method of secure communication involves determining that a remote system is trusted prior to authorizing secure communication therewith. A removable security device is coupled with a first system. When the first system communicates with a remote system securely, the remote system is evaluated to ensure that it is a trusted remote system prior to secure communication therewith being allowed.


