Internet Smart Card for Secure Identity Theft Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms fail to protect against identity theft perpetrated using keystroke loggers and other malicious software, as they capture confidential information before encryption can occur, leaving it vulnerable during online transactions.

Innovation Solution

Implementing an Internet smart card that stores and encrypts confidential information, allowing it to be transmitted securely from the card to a remote server without ever being in unencrypted form on the user's computer, using a secure connection and authentication mechanisms to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption mechanisms are used to protect confidential information during online transactions, then information security is improved, but the system becomes vulnerable to keystroke loggers and screen capturers that capture data before encryption occurs

Engineering Contradiction:
Improveinformation securityVSAvoidvulnerability to keystroke loggers
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the vulnerable point by removing the moment when confidential information exists in unencrypted form on the computer. The smart card stores encrypted data and transmits it directly to the server, eliminating the window where keystroke loggers could capture credentials before encryption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary encryption of confidential information in the smart card before any transmission occurs. This preliminary security measure ensures that even if a keystroke logger captures the data during transmission, it is already encrypted and cannot be read or used for identity theft.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If confidential information is stored and processed on the user's computer, then ease of operation is improved, but security is worsened due to exposure to malicious software

Engineering Contradiction:
Improveuser interface accessibilityVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The smart card serves as an intermediary device between the user's computer and the server. It handles the sensitive cryptographic operations and data storage externally, allowing the computer to maintain ease of operation for users while the smart card provides enhanced security protection against malicious software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the security function from the user's computer by implementing it in a separate, dedicated smart card. This segmentation allows the computer to remain simple and easy to use while the smart card independently provides robust security against malware and keystroke loggers.

Inventive Principle:
Principle #1Segmentation

3Reliability

If a secure connection is established between the user's computer and the server, then information transmission security is improved, but the system fails to protect against data captured before encryption on the computer

Engineering Contradiction:
Improvetransmission securityVSAvoidpre-encryption data capture
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent removes the vulnerable intermediate step where data exists in clear text on the computer by using a smart card that directly transmits encrypted information to the server, eliminating the window for pre-encryption capture while maintaining secure transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card performs preliminary encryption of data before transmission to the server, ensuring that even if a secure connection is established, any data captured during transmission is already encrypted and cannot be read by malicious software.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7392534B2System and method for preventing identity theft using a secure computing device
Publication Date: 2008.06.24 GEMALTO INC
  • US7392534B2 patent drawing
  • US7392534B2 patent drawing
  • US7392534B2 patent drawing

AI summary

A system and method for effecting secure transactions over a computer network in a manner designed to foil identity theft perpetrated from an untrusted computer. A connection from a client computer to the network wherein the client computer provides a user interface for a user, a connection from a server computer to the network, and a connection from a portable secure computing device to the network provides for secure transmission of private confidential user information from the user to a server. The private information is transmitted directly from the secure computing device to the server over the secure connection without possibility of capture on the computer with which the user is interacting.