Trusted Device Authentication for Secure Online Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increase in online transactions has led to increased threats of identity theft, account takeover, and online fraud due to the use of usernames and passwords being intercepted or stolen during transmission over unsecured networks, with threats like phishing and 'man in the middle' attacks becoming common.
Innovation Solution
A secure online transaction method utilizing a trusted, secure device distributed to the user, combined with a one-time secret and an authenticating device reader, isolates transaction elements on the user's trusted device, facilitating secure transactions on untrusted machines and networks by encrypting and decrypting data using a cryptographic key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If usernames and passwords are transmitted over the web for online transactions, then online commerce and banking can be conducted conveniently, but the sensitive information may be intercepted or stolen during transmission
Solution Approach 1:
The patent extracts the sensitive authentication information (username and password) from the transmission path by implementing authentication at the application layer before data transmission. The user's credentials are verified by the merchant server before any sensitive transaction data is exchanged, eliminating the need to transmit passwords over the network and thus removing the vulnerability to interception.
Solution Approach 2:
The patent performs preliminary authentication of the user by the merchant server before the actual transaction takes place. This preliminary action establishes a trusted session and validates the user's identity in advance, so that subsequent transaction data can be exchanged securely without retransmitting sensitive credentials.
2Adaptability or versatility
If traditional username and password authentication is used, then users can access online services, but phishing attacks and man in the middle attacks can trick users into providing sensitive information
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the merchant server acts as a trusted mediator that verifies the user's identity before transaction data is exchanged. This intermediary layer prevents phishing and man-in-the-middle attacks by ensuring that authentication occurs through a verified channel rather than through potentially fraudulent interfaces that trick users into entering credentials.
3Ease of operation
If sensitive information is transmitted over unsecured networks, then online transactions can be conducted remotely, but the information may be stolen at the user's computing system or merchant's server
Solution Approach 1:
The patent segments the authentication process from the transaction data transmission. User credentials are authenticated separately at the application layer before transaction data is exchanged. This segmentation ensures that even if transaction data is transmitted over unsecured networks, the sensitive authentication information remains protected and cannot be stolen during the transaction phase.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach significantly reduces the risk of fraud by ensuring that sensitive information is only accessed and verified on a trusted, secure environment, enhancing the security of online transactions even over untrusted networks.
Implementation Method 1
encrypting and decrypting data using a cryptographic key
Data Source
AI summary
Techniques for conducting secure online transactions are provided. Some techniques utilize a trusted, secure device that is distributed to a human user, and which only the user can access, a device reader, and a one-time secret valid only to authenticate a single transaction to improve on the traditional transaction model by isolating elements of the transaction with the user on the user's trusted, secure device. Isolating elements of the transaction on the trusted, secure device facilitates a secure transaction on an untrusted machine and over an untrusted network.


