Security Device Authentication for Secure Electronic Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems are inadequate in protecting against attacks on client platforms, particularly in preventing man-in-the-middle and man-in-the-browser attacks, and they often require complex authentication processes that deter users and increase costs due to scalability issues.

Innovation Solution

A method and system that utilize a trusted relationship profile server and a security proxy server to securely authenticate users by storing unique identities of trusted computing units, generating confirmation messages, and replacing local credentials with real credentials for secure electronic transactions, thereby enhancing security and simplifying the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional one-factor authentication (username and password) is used, then the authentication process is simple and user-friendly, but security is insufficient against attacks such as man-in-the-middle, man-in-the-browser, and keystroke logging

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security device as an intermediary component between the user and the network. This device generates unique transaction authentication numbers (TANs) and manages local credentials, acting as a mediator that enhances security without requiring the user to directly handle complex cryptographic operations. The security device serves as a trusted intermediary that protects against various attacks while maintaining user-friendly interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into multiple components: a security device for generating and managing credentials, a client computer for user interaction, and server systems for verification. This segmentation distributes security functions across separate entities, allowing the security device to handle complex cryptographic operations while the user interface remains simple.

Inventive Principle:
Principle #1Segmentation

2Reliability

If two-factor authentication with physical tokens and centralized verification is implemented, then security is improved, but system cost and complexity increase due to scalability issues

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device operates autonomously to generate transaction authentication numbers (TANs) and manage credentials without requiring centralized verification for each transaction. The device self-manages the cryptographic operations and credential generation, eliminating the need for complex centralized authentication servers while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-generating and storing transaction authentication numbers (TANs) in the security device before transactions occur. This allows rapid authentication during transactions without requiring real-time centralized verification, improving both security and scalability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If complex authentication processes are used to enhance security, then protection against attacks is improved, but user-friendliness decreases and scalability is limited

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security device acts as an intermediary that handles complex cryptographic operations autonomously, allowing the user interface to remain simple and responsive. This intermediary approach enables scalable deployment because each security device operates independently without requiring complex coordination with centralized authentication servers for every transaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If local credentials are stored and used for authentication, then the authentication process is simplified, but vulnerability to attacks on the client platform increases

Engineering Contradiction:
Improveauthentication simplicityVSAvoidclient platform vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements beforehand cushioning by using a security device to generate and manage encrypted credentials before they are used in transactions. The device pre-establishes secure credential storage and management mechanisms, cushioning against potential attacks on the client platform by never exposing raw credentials to the vulnerable client environment.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS9548978B2Method and system for authorizing secure electronic transactions using a security device
Publication Date: 2017.01.17 INBAY TECH
  • US9548978B2 patent drawing
  • US9548978B2 patent drawing
  • US9548978B2 patent drawing

AI summary

Methods and systems for authenticating a security device for providing a secure access and transaction authorization to a remote network location are provided. The security device is authenticated by installing private security software on the security device. A Two-Channel authorization method includes a transaction notification/authorization channel and a transaction channel. A Three-Channel authorization method includes a transaction notification channel, a transaction authorization channel, and the transaction channel. Embodiments of the present invention provide increased security and privacy. A corresponding system for authenticating a security device and preforming secure private transactions is also provided.