Secure Transaction Device Using Segmented Processor Modes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer network-based commercial and sensitive data transactions are vulnerable to security breaches due to operating system and software vulnerabilities, which existing technologies have not adequately addressed.

Innovation Solution

A consumer transaction device operates in both secure and non-secure modes, utilizing a secure processor, secure memory, and image processing to isolate sensitive operations, ensuring that only the secure processor controls sensitive transactions, and authenticates communications with servers using digital certificates and cryptographic protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a standard operating system and software are used for network-based transactions, then ease of operation and adaptability are improved, but security reliability deteriorates due to vulnerabilities to viruses, backdoors, and keyloggers

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The device is divided into two distinct modes: a non-secure mode for general operations and a secure mode for sensitive transactions. The secure mode isolates critical functions from the vulnerable operating system, creating a segmented architecture where only authorized processes can access sensitive data and operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure coprocessor or trusted execution environment acts as an intermediary between the user and the network during sensitive transactions. This intermediary verifies the security state, manages cryptographic operations, and ensures that transaction data is processed in isolation from potential attacks on the main operating system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secure mode with isolated processing is implemented, then security reliability is improved, but device complexity increases due to multiple processing modes and secure components

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device maintains a single unified architecture that can operate in multiple modes (secure and non-secure) rather than requiring separate physical devices. The same hardware resources are shared between modes, with the secure mode activating only when needed for sensitive transactions, thereby reducing overall complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The secure processing environment is nested within the existing device architecture, with the secure coprocessor or trusted execution environment embedded within the main device. This nested structure allows the secure functions to leverage existing hardware resources while maintaining isolation, avoiding the need for a completely separate secure device.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If hardwired connections to secure memory are established, then security reliability is improved by ensuring data integrity, but ease of operation deteriorates due to restricted access control

Engineering Contradiction:
Improvedata integrityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically switches between secure and non-secure modes based on the transaction requirements. During secure transactions, the device transitions to secure mode where restricted access is enforced; outside of these transactions, the device operates in non-secure mode with full accessibility, thereby adapting the security level to the operational context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Restricted access control is applied locally only to specific sensitive operations and data during secure transactions, rather than imposing system-wide access restrictions. The secure mode enforces strict access controls only where needed for cryptographic operations and transaction processing, while other device functions remain fully accessible.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2836968B1Apparatuses, methods and systems for computer-based secure transactions
Publication Date: 2020.05.06 OLOGN TECH AG
  • EP2836968B1 patent drawingFigure 1
  • EP2836968B1 patent drawingFigure 2A
  • EP2836968B1 patent drawingFigure 2B

AI summary

The systems, methods and apparatuses described herein provide a computing environment for completing a secure transaction. An apparatus according to the present disclosure may comprise a screen, a first switching device coupled to the screen, an input device, a second switching device coupled to the input device, a non-secure processor, a secure processor and a credit card reader operatively coupled to the secure processor. The non-secure processor may generate a message containing a purchase transaction request. The secure processor may receive the message, assume control of the screen and input device while the apparatus is operating in a secure mode, establish a secure connection with a server, receive payment information to be submitted to the server, digitally sign certain transaction information and submit the digitally signed certain transaction information to the server to complete the secure transaction.