Secure Encryption Unit for Internet Security Information Interaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing internet-based systems for security information interaction face complexity and security risks due to the need for multiple devices for different applications, with encryption and decryption often performed on vulnerable internet terminals, leading to potential security hazards and lack of universality.

Innovation Solution

A device and method for security information interaction that includes an interface circuit, secure encryption/decryption unit, information reader, and initial register module, employing a secure channel established via handshake protocol and record layer protocol, requiring user input of device and authentication passwords, and utilizing hardware encryption with IC card readers and asymmetric key systems for enhanced security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different information processing devices are used for different applications, then the capability to handle various application categories is improved, but the device complexity and operational complexity are substantially increased

Engineering Contradiction:
Improvecapability to handle various application categoriesVSAvoidcomplexity of information processing
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a single information processing device that can handle multiple application categories (banking, shopping, communication, etc.) through a unified architecture. The device includes a universal interface circuit that can connect to different internet terminals, a secure encryption/decryption unit that processes various types of security information, and an information reader that can read from different external information carriers, eliminating the need for multiple specialized devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If encryption and decryption are performed at the internet terminal, then the processing capability is improved, but the security level is reduced due to vulnerability to attacks and monitoring

Engineering Contradiction:
Improveprocessing capabilityVSAvoidsecurity level
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts the encryption and decryption functions from the vulnerable internet terminal environment and relocates them to a dedicated secure encryption/decryption unit within the information processing device. This isolated secure unit processes security information locally without exposing cryptographic operations to the potentially vulnerable terminal environment, thereby maintaining processing capability while enhancing security by removing the system from the attack surface.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If a single device is used for all applications, then the simplicity and universality are improved, but the security risk increases due to potential information recording or hooking by the internet terminal

Engineering Contradiction:
ImprovesimplicityVSAvoidsecurity risk from information recording or hooking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure channel establishing module and secure encryption/decryption unit as intermediary components between the information processing device and the internet terminal. These intermediaries create a secure communication layer that prevents direct access to security information by the terminal, thereby maintaining simplicity of operation while blocking harmful factors like information recording and hooking through cryptographic protection and protocol-level security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If different devices are required for different applications, then the security for each application can be optimized, but the lack of universality increases the complexity of information processing

Engineering Contradiction:
Improvesecurity for each applicationVSAvoidcomplexity of information processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent achieves universality by implementing a single information processing device with a unified secure encryption/decryption unit that can securely handle multiple application types. The device includes a flexible interface circuit that can connect to various internet terminals and an information reader that can read from different external information carriers, allowing one device to replace multiple application-specific devices while maintaining security through standardized cryptographic protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2690840B1Internet based security information interaction apparatus and method
Publication Date: 2020.03.11 CHINA UNIONPAY
  • EP2690840B1 patent drawingFigure 1
  • EP2690840B1 patent drawingFigure 2

AI summary

The present invention discloses a device and method for security information interaction. The device for security information interaction includes: an interface circuit, configured to connect the device for security information interaction to an internet terminal; an information input unit, configured to allow user to input security information; a secure encryption/decryption unit, configured to store and process the security information; an information reader, configured to read information data from an external information carrier; wherein the secure encryption/decryption unit processes the security information in connection with the information data, and complete a business function on the secure channel through the interaction with the security information processing server. The device and method for security information interaction disclosed in the present invention improves the flexibility and efficiency of the information processing system, enhances the security of the information processing system, and extending new applications of an external information carrier in an open network environment.