Secure Input Device Isolating Data Entry from Operating System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure contactless transactions on communications terminals, such as computers or tablets, are vulnerable to data interception by malicious software due to the involvement of the operating system in data entry processes, making it difficult to prevent keyloggers and screen capture attacks.
Innovation Solution
A device with means for acquiring and processing input data independently of the terminal's operating system, featuring a mode selection mechanism to activate or deactivate data handling, ensuring that data entry and processing occur outside the operating system's control, thereby preventing interception by malicious software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data entry is performed through the terminal's operating system (keyboard or visual keypad), then ease of operation is improved, but security is worsened due to vulnerability to keyloggers and screen capture attacks
Solution Approach 1:
The system segments the data entry function into two independent parts: the input peripheral (keyboard or visual keypad) remains under operating system control for ease of use, while a dedicated securing device intercepts and processes the data separately through its own processor and shunt memory, creating isolation from malicious software
Solution Approach 2:
The securing device acts as an intermediary between the input peripheral and the terminal system. It receives data from the input peripheral through dedicated acquisition means, processes it independently, and only transmits necessary information to the terminal, thereby preventing direct exposure to keyloggers and screen capture attacks
2Reliability
If a visual keypad is used to prevent keylogger attacks, then security against keyloggers is improved, but security is worsened due to screen capture attacks
Solution Approach 1:
The system extracts the critical data processing function from the visual display system. The securing device receives data directly from the input peripheral through dedicated acquisition means, bypassing the need to display sensitive information on the terminal screen, thereby eliminating vulnerability to screen capture attacks while maintaining protection against keyloggers
3Reliability
If data processing is performed outside the operating system through a securing device, then security is improved, but device complexity is worsened
Solution Approach 1:
The securing device merges multiple security functions into a single integrated unit: input data acquisition, independent processing, secure storage in shunt memory, and controlled transmission to the terminal. This consolidation achieves high security while managing complexity through functional integration rather than distributed components
Data Source
AI summary
Processing devices, methods and non-transitory computer-readable media for processing data are disclosed. The data comes from a contactless memory card. The device has at least one contactless memory card reader. Such a device also has: a keyboard for acquiring input data coming from an input peripheral; a processor for processing at least one sequence of a remote transaction initialized on the basis of data coming from a contactless card; and a switch or a cell for selecting a mode of operation that has at least two states. The at least two states are: a state, called an inactivation state, in which the processor and the at least one memory card reader are inactive; and a state, called an activation state, in which the processor is active and in which the input data entered through the input peripheral are controlled by the processor.

