Trusted Platform Module Authentication for Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic transaction systems are vulnerable to hacking and require additional hardware for dual-authentication, which increases costs and complexity, making them less appealing to users.
Innovation Solution
A system utilizing a secure server that stores user security information and authenticates transactions through a trusted platform module (TPM) on the user's computer, eliminating the need for external hardware by creating a protected environment for transaction processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dual-factor authentication is implemented using a peripheral PIN entry device (PED) and ATM card, then transaction security is improved, but device complexity and additional hardware costs increase
Solution Approach 1:
The patent extracts the authentication functionality from external hardware (PED, ATM card reader) and relocates it to the user's existing computer system. The authentication logic is implemented as software modules that utilize built-in hardware components (keyboard, display, CPU) rather than requiring separate authentication devices.
Solution Approach 2:
The patent makes the user's computer system perform multiple functions: it serves as both the transaction processing device and the authentication device. The same keyboard is used for both normal computing input and PIN entry, the same display shows both regular content and authentication prompts, eliminating the need for dedicated authentication hardware.
2Reliability
If peripheral PIN entry device (PED) is attached via USB connection for dual-authentication, then transaction security is improved, but ease of operation deteriorates due to additional hardware setup
Solution Approach 1:
The patent removes the requirement for external authentication hardware from the user's interaction flow. By extracting authentication functionality to software running on the existing computer, users simply interact with familiar interfaces (keyboard, display) without needing to connect, configure, or carry additional devices.
Solution Approach 2:
The system utilizes the user's existing computer infrastructure to provide authentication services. The computer's own hardware resources (CPU, memory, display, keyboard) are leveraged to perform authentication, making the system self-sufficient and eliminating dependencies on external authentication devices that would require user setup and maintenance.
3Ease of manufacture
If encryption provisions of web browser are used for electronic transactions, then basic security is provided, but security reliability is insufficient due to browser and operating system flaws
Solution Approach 1:
The patent segments the authentication process into distinct modular components: a protected environment creation module, an authentication module, and a transaction processing module. The protected environment isolates critical authentication operations from the potentially compromised browser and operating system, creating security boundaries that prevent malware from interfering with the authentication process.
Solution Approach 2:
The patent introduces a protected environment as an intermediary layer between the user's input (PIN, card data) and the transaction processing system. This intermediary environment acts as a secure sandbox that verifies authentication credentials before allowing communication with external systems, preventing direct exposure to browser or OS-level vulnerabilities and malware.
Data Source
AI summary
A system and method are disclosed for conducting secure electronic transactions using dual-authentications. A secure server stores security information for a plurality of users and authorizes transactions being conducted by these users. A user computer system having a trusted platform module is used for storing security information relating to at least one user account. Protected environments are created to facilitate secure connections based on at least the security information stored in the trusted platform module. Transactions between the user/electronic merchants and between the user/secure server are conducted within protected environments. When a user conducts an electronic transaction with an electronic merchant, the transaction is authenticated by the secure server before can be completed.


