Secure Identification Item for Online Banking Session Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online banking transactions face challenges in verifying the security of online sessions, despite the use of secure operating systems and TPM, as ensuring the content of the session is secure remains elusive.

Innovation Solution

A 'share secret' is created to initiate a secure process, involving a transaction security module that establishes a secure identification item, initiates a guest OS, and connects with the entity, ensuring secure communication by displaying the secure identification item on the user's screen, thereby preventing security breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure operating systems and TPM are used to verify the OS, then the system security is improved, but the ability to verify that the content of the session is secure remains elusive

Engineering Contradiction:
Improvesystem securityVSAvoidsession content security verification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the verification process into two distinct parts: OS verification (handled by existing TPM) and session content verification (newly introduced). By creating separate verification mechanisms for different security layers, the system can verify both the operating system integrity and the session content security independently, resolving the contradiction between having OS verification while lacking session content verification capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure identification item (such as a visual verification code or cryptographic token) as an intermediary element that bridges the gap between the system's internal security state and the user's ability to verify session content security. This intermediary provides tangible proof that session content is secure without requiring direct inspection of encrypted data or complex cryptographic proofs by the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If a secure identification item is displayed to verify session security, then session content security verification is improved, but the complexity of the security verification process increases

Engineering Contradiction:
Improvesession content security verificationVSAvoidsecurity verification process
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent creates a simplified copy or representation of the security verification state in the form of a secure identification item that is displayed to the user. Instead of requiring users to understand complex cryptographic protocols or inspect raw security data, the system generates an accessible visual or textual representation that conveys security status, thereby reducing the perceived complexity while maintaining verification capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The secure identification item is designed as a transient, single-use verification element that is generated, displayed, and then discarded after verification. This disposable nature reduces long-term system complexity as these identification items do not require persistent storage or complex management mechanisms, yet provide effective session verification when needed.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8205248B2Local verification of trusted display based on remote server verification
Publication Date: 2012.06.19 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8205248B2 patent drawing
  • US8205248B2 patent drawing
  • US8205248B2 patent drawing

AI summary

In a system with a main memory, a network adapter, and a display, a transaction security module in communication with the network adapter. The transaction security module acts to: establish a secure identification item with an entity which positively identifies the entity; accept an application OS of the entity; and initiate a guest OS with the entity; the network adapter acting to connect with the entity subsequent to initiation of a guest OS; and the display acting to display the secure identification item subsequent to connection with the entity.