Secure USB Device with Local Processing and Version Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Secure computing environments that rely on USB flash memory devices for software applications are susceptible to security breaches due to the need for host computer processing and communication, which can expose them to malicious software or hardware.
Innovation Solution
A portable electronic device with a memory for storing executable software components, a data interface for coupling to a host computer, a contactless interface for receiving payment token data, and a cellular network interface for secure communication, enabling software upgrades and payment transactions without relying on the host computer's network, using logical storage partitions for version management and secure connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If USB flash memory devices rely on host computer for processing and communication, then device complexity is reduced, but security reliability deteriorates due to susceptibility to malicious software or hardware on the host computer
Solution Approach 1:
The system segments the computing functionality by separating the secure processing unit from the host computer. The secure processing unit on the USB device handles sensitive operations independently, while the host computer provides only basic connectivity. This segmentation isolates critical functions from potential host-based attacks while maintaining system functionality.
Solution Approach 2:
The patent introduces a secure processing unit as an intermediary between the USB storage device and the host computer. This intermediary handles all security-critical operations including authentication, encryption, and transaction processing, preventing direct exposure to host computer vulnerabilities while maintaining communication capabilities.
2Ease of operation
If secure computing environments use host computer for network communication, then ease of operation is improved, but vulnerability to host-based threats increases
Solution Approach 1:
The secure processing unit acts as an intermediary that manages all network communication securely. It establishes encrypted channels and handles authentication protocols, allowing the device to operate independently of the host computer's network security status while maintaining ease of use through automatic secure connection management.
Solution Approach 2:
The system implements local security processing within the USB device itself rather than relying on host computer security infrastructure. The secure processing unit executes security functions locally, ensuring that sensitive operations are performed in a controlled environment isolated from host-based threats while maintaining operational simplicity.
3Adaptability or versatility
If software components are updated on USB flash memory devices, then adaptability is improved, but security risks from update processes increase
Solution Approach 1:
The system performs preliminary verification of update packages before installation. The secure processing unit validates digital signatures and checks integrity of downloaded software components against known good versions, preventing execution of malicious or corrupted code during the update process while enabling regular software maintenance.
Solution Approach 2:
The update mechanism incorporates feedback loops where the secure processing unit continuously monitors the integrity of software components during download and installation. If any anomaly is detected, the process is automatically aborted and the system reports the issue, ensuring that updates only proceed when security requirements are met.
Data Source
AI summary
A method and device are described for maintaining software components in a portable electronic device. The device includes memory storing software components executable from the device, with associated pairs of logical storage partitions for storing different versions of the software components, a data interface for coupling the device to a host computer, a contactless interface for receiving payment token data from a contactless payment token, and a cellular network interface for communication of data over a cellular network. An upgrade process is initiated when the device is coupled to the host computer. Data including a different version of at least one of said software components is received, installed and executed to initiate a payment transaction with a remote system. Payment token data is received via the contactless interface means and transmitted to the remote system.


