Sensitive Information Storage Island for Hardware-Gated Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face security risks due to the use of easily guessable usernames and passwords across multiple online accounts, leading to 'break once, run everywhere' attacks, and the inconvenience of managing multiple unique credentials.
Innovation Solution
A non-software-based barrier, referred to as an 'island', is activated by user interaction on a sensitive information storage device (SIS device), controlling access to stored sensitive information, with direct machine-to-machine communication between the SIS device and a master controller, ensuring that user intent is demonstrated before information is accessed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users employ the same username and password across most or all online sources, then ease of operation is improved, but security is worsened due to exposure to break once, run everywhere attacks
Solution Approach 1:
The patent introduces a secure element as an intermediary device that stores credentials and provides them to the master controller through a controlled interface. This mediator isolates the user's memory of simple credentials from the actual complex authentication mechanism, allowing users to remember easy passwords while the secure element handles the security-critical credential management and presentation to online sources.
Solution Approach 2:
The system segments the authentication function into separate components: a user-friendly interface for entering credentials, a secure element for storing and managing actual authentication data, and a master controller for coordinating the authentication process. This segmentation allows each component to optimize for its specific function while maintaining overall security.
2Object-affected harmful factors
If users come up with multiple different usernames and passwords for different online sources, then security is improved, but ease of operation deteriorates due to difficulty in remembering and managing credentials
Solution Approach 1:
The secure element acts as an intermediary that manages the complexity of multiple credentials. Users interact with a simplified interface through the master controller, while the secure element handles the intricate task of storing, organizing, and retrieving appropriate credentials for different online sources, eliminating the burden of manual credential management.
Solution Approach 2:
The secure element provides self-service functionality by automatically managing credential storage and retrieval without user intervention. The system autonomously handles the complex operations of matching users to appropriate credentials based on the online source being accessed, freeing users from manual credential management.
3Ease of operation
If software is used as the gatekeeper to control access to sensitive information, then ease of operation is improved, but security is worsened due to increased vulnerability to software exploits
Solution Approach 1:
The patent replaces the software-based gatekeeper with a hardware-based secure element that uses physical security mechanisms. Instead of relying on software authentication that can be exploited, the system employs a dedicated secure hardware component with physical access controls, such as button presses or other tactile inputs, to authorize credential disclosure to the master controller.
Solution Approach 2:
The secure element serves as a hardware intermediary between the user interface and the master controller, introducing a physical layer of security. This hardware mediator requires tangible user interaction to authorize any credential access, creating a barrier that is significantly more resistant to automated software-based attacks compared to pure software gatekeeping.
Data Source
AI summary
Devices, systems, and methods for storing and managing sensitive information in a connected environment are provided. The system comprises a master controller and a sensitive information storage device (“SIS device”). The SIS device has an island that can be activated by user interaction with the SIS device. In general, the island is deactivated by default and when the island is deactivated, sensitive information that is stored on the SIS device cannot be accessed. Only when the island is activated by user interaction can the stored sensitive information be accessed.


