Secure Transaction Device Using Segmented Processor Modes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer network-based commercial and sensitive data transactions are vulnerable to security breaches due to operating system and software vulnerabilities, which existing technologies have not adequately addressed.
Innovation Solution
A consumer transaction device operates in both secure and non-secure modes, utilizing a secure processor, secure memory, and image processing to isolate sensitive operations, ensuring that only the secure processor controls sensitive transactions, and authenticates communications with servers using digital certificates and cryptographic protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a standard operating system and software are used for network-based transactions, then ease of operation and adaptability are improved, but security reliability deteriorates due to vulnerabilities to viruses, backdoors, and keyloggers
Solution Approach 1:
The device is divided into two distinct modes: a non-secure mode for general operations and a secure mode for sensitive transactions. The secure mode isolates critical functions from the vulnerable operating system, creating a segmented architecture where only authorized processes can access sensitive data and operations.
Solution Approach 2:
A secure coprocessor or trusted execution environment acts as an intermediary between the user and the network during sensitive transactions. This intermediary verifies the security state, manages cryptographic operations, and ensures that transaction data is processed in isolation from potential attacks on the main operating system.
2Reliability
If a secure mode with isolated processing is implemented, then security reliability is improved, but device complexity increases due to multiple processing modes and secure components
Solution Approach 1:
The device maintains a single unified architecture that can operate in multiple modes (secure and non-secure) rather than requiring separate physical devices. The same hardware resources are shared between modes, with the secure mode activating only when needed for sensitive transactions, thereby reducing overall complexity while maintaining security.
Solution Approach 2:
The secure processing environment is nested within the existing device architecture, with the secure coprocessor or trusted execution environment embedded within the main device. This nested structure allows the secure functions to leverage existing hardware resources while maintaining isolation, avoiding the need for a completely separate secure device.
3Reliability
If hardwired connections to secure memory are established, then security reliability is improved by ensuring data integrity, but ease of operation deteriorates due to restricted access control
Solution Approach 1:
The system dynamically switches between secure and non-secure modes based on the transaction requirements. During secure transactions, the device transitions to secure mode where restricted access is enforced; outside of these transactions, the device operates in non-secure mode with full accessibility, thereby adapting the security level to the operational context.
Solution Approach 2:
Restricted access control is applied locally only to specific sensitive operations and data during secure transactions, rather than imposing system-wide access restrictions. The secure mode enforces strict access controls only where needed for cryptographic operations and transaction processing, while other device functions remain fully accessible.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
The systems, methods and apparatuses described herein provide a computing environment for completing a secure transaction. An apparatus according to the present disclosure may comprise a screen, a first switching device coupled to the screen, an input device, a second switching device coupled to the input device, a non-secure processor, a secure processor and a credit card reader operatively coupled to the secure processor. The non-secure processor may generate a message containing a purchase transaction request. The secure processor may receive the message, assume control of the screen and input device while the apparatus is operating in a secure mode, establish a secure connection with a server, receive payment information to be submitted to the server, digitally sign certain transaction information and submit the digitally signed certain transaction information to the server to complete the secure transaction.