Secure Typing Module for Cryptographic Data Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security schemes using external cryptographic tokens face challenges in ensuring the authenticity and integrity of data entering cryptographic operations, as harmful software can modify data in an unreliable computer environment, potentially damaging user interests.
Innovation Solution
The Secure Typing Module (STM) directly transmits data from a Human Interface Device (like a keyboard) to an external token, ensuring data integrity and authenticity by switching to a secure typing mode, where the STM autonomously controls data entry and cryptographic processing, preventing modifications and ensuring user verification of PIN codes, while maintaining transparency in standard operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data are transmitted through the computer environment for cryptographic processing, then the computer can display and process the data, but the data integrity and authenticity cannot be guaranteed due to potential modification by harmful software
Solution Approach 1:
The patent introduces an intermediary device (secure input device with embedded cryptographic module) that acts as a mediator between the user and the computer system. This intermediary directly transmits cryptographic data to the external token without passing through the computer's vulnerable software environment, thereby ensuring data integrity while maintaining system functionality.
Solution Approach 2:
The patent segments the data transmission path into two distinct channels: a secure direct path for cryptographic data through the intermediary device, and a normal path for other operations through the computer system. This segmentation isolates critical cryptographic operations from potential software attacks while preserving overall system functionality.
2Ease of operation
If the computer displays the data for user verification, then the user can visually check the data, but harmful software can modify the displayed data without the user's knowledge
Solution Approach 1:
The intermediary device provides a trusted display mechanism that shows the actual data being transmitted to the cryptographic token, independent of the computer's display system. This allows users to verify the authentic data while the intermediary ensures the displayed content matches what is actually processed.
Solution Approach 2:
The system implements feedback by displaying to the user the exact data that will be cryptographically processed, allowing real-time verification. The intermediary device ensures this feedback reflects the true data state, creating a trusted verification loop between user, intermediary, and cryptographic processing.
3Reliability
If the STM module autonomously controls data entry in secure typing mode, then data integrity is ensured, but the system complexity increases
Solution Approach 1:
The intermediary device dynamically switches between two operational modes: transparent mode for standard operations and secure typing mode for cryptographic operations. This dynamic behavior allows the device to provide enhanced security functionality only when needed, minimizing the impact on overall system complexity while ensuring data integrity during critical operations.
Data Source
AI summary
A method and device for authorized data entry and securing the authenticity of such data when entering cryptographic operations in a computer requiring authorized data entry, sends a specific command to an STM module which defines a template of input data intended to be cryptographically processed. The STM module is switched over to a secure typing mode, the STM module autonomously controls the typing of required data items of the data template by recording characters typed on the connected entry device, and the recorded characters are arranged by the STM module in its internal memory in requested data structures defined by the input data template, and such created data are sent by the STM module directly to a token where the requested cryptographic operation is called, the result of which is sent to the computer by the STM module, and subsequently the STM module switches back to the transparent mode.

