Security USB Token for Malware-Resistant Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data processing systems, such as monetary transaction devices, face security challenges in preventing unauthorized data transmission and ensuring secure authentication for user access, particularly when using removable media like flash memory sticks, which can introduce malware risks.

Innovation Solution

A security USB token is designed without permanent memory, featuring a USB hub to attach a regular memory stick, with mechanisms for controlling read/write access and using cryptographic procedures to ensure secure data transmission, including challenge-response authentication and encryption to prevent malware transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a removable memory stick is used for data transmission in monetary transaction devices, then data accessibility and ease of operation are improved, but security against malware attacks and unauthorized access deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity against malware
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security token as an intermediary device between the removable memory stick and the monetary transaction device. The security token contains a security application that mediates all data transmission operations, verifying security conditions before allowing data access. This intermediary layer enables safe data transmission by filtering out malicious content while permitting legitimate data exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into three distinct components: the monetary transaction device, the removable memory stick, and the security token. Each component has a specific security function, with the security token acting as a dedicated security module that separates security verification from data storage and processing functions. This segmentation allows security measures to be applied specifically at the interface without compromising data accessibility.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If conventional data processing systems are used with standard interfaces, then ease of operation and adaptability are improved, but security control and protection against unauthorized access deteriorate

Engineering Contradiction:
Improveinterface compatibilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The security token is designed with universal functionality to work with standard USB interfaces and various memory stick types while maintaining security control. The security application within the token can handle different data formats and communication protocols, enabling compatibility with conventional data processing systems without sacrificing security. This multi-functionality allows the security token to operate across different platforms and device types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Quantity of substance

If permanent memory is integrated into the security token, then data storage capability is improved, but the risk of malware transmission and security vulnerabilities increases

Engineering Contradiction:
Improvedata storage capacityVSAvoidmalware transmission risk
Core Design Contradiction:
Quantity of substanceVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the permanent memory function from the security token and places it in the removable memory stick, which the user already possesses. The security token retains only the security application and minimal operational data storage, while all user data is stored externally on the memory stick. This extraction eliminates the risk of malware being stored in the security token's permanent memory while still providing data storage capability through the external memory stick.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9117096B2Protection of safety token against malware
Publication Date: 2015.08.25 DIEBOLD NIXDORF SYST GMBH
  • US9117096B2 patent drawing
  • US9117096B2 patent drawing

AI summary

Security token for the authentication of access to a self-service terminal, comprising an interface for a connection to the self-service terminal, comprising authentication information, characterized by a second interface that allows a connection of a memory stick the contents of which are made available to the self-service terminal, wherein access to the memory stick is dependent on the authentication information.