Trusted Platform Module Authentication for Secure Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic transaction systems are vulnerable to hacking and require additional hardware for dual-authentication, which increases costs and complexity, making them less appealing to users.

Innovation Solution

A system utilizing a secure server that stores user security information and authenticates transactions through a trusted platform module (TPM) on the user's computer, eliminating the need for external hardware by creating a protected environment for transaction processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dual-factor authentication is implemented using a peripheral PIN entry device (PED) and ATM card, then transaction security is improved, but device complexity and additional hardware costs increase

Engineering Contradiction:
Improvetransaction securityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from external hardware (PED, ATM card reader) and relocates it to the user's existing computer system. The authentication logic is implemented as software modules that utilize built-in hardware components (keyboard, display, CPU) rather than requiring separate authentication devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the user's computer system perform multiple functions: it serves as both the transaction processing device and the authentication device. The same keyboard is used for both normal computing input and PIN entry, the same display shows both regular content and authentication prompts, eliminating the need for dedicated authentication hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If peripheral PIN entry device (PED) is attached via USB connection for dual-authentication, then transaction security is improved, but ease of operation deteriorates due to additional hardware setup

Engineering Contradiction:
Improvetransaction securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent removes the requirement for external authentication hardware from the user's interaction flow. By extracting authentication functionality to software running on the existing computer, users simply interact with familiar interfaces (keyboard, display) without needing to connect, configure, or carry additional devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system utilizes the user's existing computer infrastructure to provide authentication services. The computer's own hardware resources (CPU, memory, display, keyboard) are leveraged to perform authentication, making the system self-sufficient and eliminating dependencies on external authentication devices that would require user setup and maintenance.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If encryption provisions of web browser are used for electronic transactions, then basic security is provided, but security reliability is insufficient due to browser and operating system flaws

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the authentication process into distinct modular components: a protected environment creation module, an authentication module, and a transaction processing module. The protected environment isolates critical authentication operations from the potentially compromised browser and operating system, creating security boundaries that prevent malware from interfering with the authentication process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a protected environment as an intermediary layer between the user's input (PIN, card data) and the transaction processing system. This intermediary environment acts as a secure sandbox that verifies authentication credentials before allowing communication with external systems, preventing direct exposure to browser or OS-level vulnerabilities and malware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9053471B2Apparatus and method for conducting securing financial transactions
Publication Date: 2015.06.09 4361423 CANADA INC
  • US9053471B2 patent drawing
  • US9053471B2 patent drawing
  • US9053471B2 patent drawing

AI summary

A system and method are disclosed for conducting secure electronic transactions using dual-authentications. A secure server stores security information for a plurality of users and authorizes transactions being conducted by these users. A user computer system having a trusted platform module is used for storing security information relating to at least one user account. Protected environments are created to facilitate secure connections based on at least the security information stored in the trusted platform module. Transactions between the user/electronic merchants and between the user/secure server are conducted within protected environments. When a user conducts an electronic transaction with an electronic merchant, the transaction is authenticated by the secure server before can be completed.