Internet Smart Card for Secure Identity Theft Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security mechanisms fail to protect against identity theft perpetrated using keystroke loggers and other malicious software, as they capture confidential information before encryption can occur, leaving it vulnerable during online transactions.
Innovation Solution
Implementing an Internet smart card that stores and encrypts confidential information, allowing it to be transmitted securely from the card to a remote server without ever being in unencrypted form on the user's computer, using a secure connection and authentication mechanisms to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption mechanisms are used to protect confidential information during online transactions, then information security is improved, but the system becomes vulnerable to keystroke loggers and screen capturers that capture data before encryption occurs
Solution Approach 1:
The patent extracts the vulnerable point by removing the moment when confidential information exists in unencrypted form on the computer. The smart card stores encrypted data and transmits it directly to the server, eliminating the window where keystroke loggers could capture credentials before encryption.
Solution Approach 2:
The system performs preliminary encryption of confidential information in the smart card before any transmission occurs. This preliminary security measure ensures that even if a keystroke logger captures the data during transmission, it is already encrypted and cannot be read or used for identity theft.
2Ease of operation
If confidential information is stored and processed on the user's computer, then ease of operation is improved, but security is worsened due to exposure to malicious software
Solution Approach 1:
The smart card serves as an intermediary device between the user's computer and the server. It handles the sensitive cryptographic operations and data storage externally, allowing the computer to maintain ease of operation for users while the smart card provides enhanced security protection against malicious software.
Solution Approach 2:
The system segments the security function from the user's computer by implementing it in a separate, dedicated smart card. This segmentation allows the computer to remain simple and easy to use while the smart card independently provides robust security against malware and keystroke loggers.
3Reliability
If a secure connection is established between the user's computer and the server, then information transmission security is improved, but the system fails to protect against data captured before encryption on the computer
Solution Approach 1:
The patent removes the vulnerable intermediate step where data exists in clear text on the computer by using a smart card that directly transmits encrypted information to the server, eliminating the window for pre-encryption capture while maintaining secure transmission.
Solution Approach 2:
The smart card performs preliminary encryption of data before transmission to the server, ensuring that even if a secure connection is established, any data captured during transmission is already encrypted and cannot be read by malicious software.
Data Source
AI summary
A system and method for effecting secure transactions over a computer network in a manner designed to foil identity theft perpetrated from an untrusted computer. A connection from a client computer to the network wherein the client computer provides a user interface for a user, a connection from a server computer to the network, and a connection from a portable secure computing device to the network provides for secure transmission of private confidential user information from the user to a server. The private information is transmitted directly from the secure computing device to the server over the secure connection without possibility of capture on the computer with which the user is interacting.


