Trusted Computing Unit for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security systems face challenges in detecting and preventing attacks on client platforms, particularly due to vulnerabilities in user authentication methods like man-in-the-middle and man-in-the-browser attacks, which compromise transaction security and scalability, and are cumbersome for users, leading to increased complexity and fraud.
Innovation Solution
A system and method utilizing a trusted computing unit with a portable security device and a security proxy server to verify user identity, replacing local credentials with real credentials, and implementing a secure vault to enhance transaction security through a trusted relationship profile server and security proxy server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then user interaction is simple, but transaction security is compromised due to vulnerabilities like man-in-the-middle and man-in-the-browser attacks
Solution Approach 1:
The patent introduces a trusted computing unit as an intermediary component that mediates between the user and the network. This unit includes a security proxy server that intercepts and verifies authentication requests, blocking man-in-the-middle and man-in-the-browser attacks without requiring users to change their interaction patterns. The security proxy acts as a transparent mediator that enhances security while maintaining ease of use.
Solution Approach 2:
The trusted computing unit performs self-service authentication by automatically verifying credentials and blocking attacks without user intervention. The security proxy server autonomously manages authentication requests, and the system automatically replaces local credentials with real credentials, eliminating the need for users to manually handle security complexities.
2Reliability
If security measures are enhanced to prevent attacks, then transaction security improves, but system complexity increases
Solution Approach 1:
The patent segments the security system into a trusted computing unit with a security proxy server that operates independently from the main application servers. This segmentation isolates security functions, allowing them to be managed separately and reducing overall system complexity. The security proxy handles authentication requests independently, preventing attack vectors while maintaining modularity.
Solution Approach 2:
The trusted computing unit performs preliminary authentication and security verification before requests reach the main system. By pre-processing authentication requests and blocking malicious traffic in advance, the system prevents attacks from penetrating deeper into the infrastructure, reducing the complexity of defensive measures needed elsewhere in the system.
3Reliability
If credential verification is performed at the server level, then security is improved, but scalability is reduced due to increased processing overhead
Solution Approach 1:
The security proxy server acts as an intermediary that handles credential verification locally before requests reach the main application servers. This intermediary approach distributes the verification load, preventing bottlenecks at the central server level and maintaining system scalability while ensuring secure authentication.
Solution Approach 2:
Authentication and credential verification are performed in advance by the trusted computing unit before requests are forwarded to the main system. This preliminary action eliminates the need for repeated verification at the server level, reducing processing overhead and improving system scalability while maintaining security.
Data Source
AI summary
A system for authorizing a secure access from a local device to a remote server computer is disclosed. At the local device having a unique identifier (UID), processor, and memory, a security software obtains a personal identification number (PIN) of a user, and the UID of the local device. Authenticity of the PIN and the UID is verified without communication over a network, using a credential code generated using the PIN, the UID and the security software. Upon verifying the authenticity of the PIN and the UID, access credentials to the remote server computer are retrieved, and the secure access to the remote server computer is authorized using the retrieved access credentials. The remote server computer has a copy of the security software, the PIN, the UID and the credential code.


