Security Device Authentication for Secure Electronic Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems are inadequate in protecting against attacks on client platforms, particularly in preventing man-in-the-middle and man-in-the-browser attacks, and they often require complex authentication processes that deter users and increase costs due to scalability issues.
Innovation Solution
A method and system that utilize a trusted relationship profile server and a security proxy server to securely authenticate users by storing unique identities of trusted computing units, generating confirmation messages, and replacing local credentials with real credentials for secure electronic transactions, thereby enhancing security and simplifying the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional one-factor authentication (username and password) is used, then the authentication process is simple and user-friendly, but security is insufficient against attacks such as man-in-the-middle, man-in-the-browser, and keystroke logging
Solution Approach 1:
The patent introduces a security device as an intermediary component between the user and the network. This device generates unique transaction authentication numbers (TANs) and manages local credentials, acting as a mediator that enhances security without requiring the user to directly handle complex cryptographic operations. The security device serves as a trusted intermediary that protects against various attacks while maintaining user-friendly interaction.
Solution Approach 2:
The authentication system is segmented into multiple components: a security device for generating and managing credentials, a client computer for user interaction, and server systems for verification. This segmentation distributes security functions across separate entities, allowing the security device to handle complex cryptographic operations while the user interface remains simple.
2Reliability
If two-factor authentication with physical tokens and centralized verification is implemented, then security is improved, but system cost and complexity increase due to scalability issues
Solution Approach 1:
The security device operates autonomously to generate transaction authentication numbers (TANs) and manage credentials without requiring centralized verification for each transaction. The device self-manages the cryptographic operations and credential generation, eliminating the need for complex centralized authentication servers while maintaining high security standards.
Solution Approach 2:
The system performs preliminary actions by pre-generating and storing transaction authentication numbers (TANs) in the security device before transactions occur. This allows rapid authentication during transactions without requiring real-time centralized verification, improving both security and scalability.
3Reliability
If complex authentication processes are used to enhance security, then protection against attacks is improved, but user-friendliness decreases and scalability is limited
Solution Approach 1:
The security device acts as an intermediary that handles complex cryptographic operations autonomously, allowing the user interface to remain simple and responsive. This intermediary approach enables scalable deployment because each security device operates independently without requiring complex coordination with centralized authentication servers for every transaction.
4Ease of operation
If local credentials are stored and used for authentication, then the authentication process is simplified, but vulnerability to attacks on the client platform increases
Solution Approach 1:
The system implements beforehand cushioning by using a security device to generate and manage encrypted credentials before they are used in transactions. The device pre-establishes secure credential storage and management mechanisms, cushioning against potential attacks on the client platform by never exposing raw credentials to the vulnerable client environment.
Data Source
AI summary
Methods and systems for authenticating a security device for providing a secure access and transaction authorization to a remote network location are provided. The security device is authenticated by installing private security software on the security device. A Two-Channel authorization method includes a transaction notification/authorization channel and a transaction channel. A Three-Channel authorization method includes a transaction notification channel, a transaction authorization channel, and the transaction channel. Embodiments of the present invention provide increased security and privacy. A corresponding system for authenticating a security device and preforming secure private transactions is also provided.


