Trusted Device Authentication for Secure Online Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increase in online transactions has led to increased threats of identity theft, account takeover, and online fraud due to the use of usernames and passwords being intercepted or stolen during transmission over unsecured networks, with threats like phishing and 'man in the middle' attacks becoming common.

Innovation Solution

A secure online transaction method utilizing a trusted, secure device distributed to the user, combined with a one-time secret and an authenticating device reader, isolates transaction elements on the user's trusted device, facilitating secure transactions on untrusted machines and networks by encrypting and decrypting data using a cryptographic key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If usernames and passwords are transmitted over the web for online transactions, then online commerce and banking can be conducted conveniently, but the sensitive information may be intercepted or stolen during transmission

Engineering Contradiction:
Improveconvenience of online transactionsVSAvoidinterception and theft of sensitive information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive authentication information (username and password) from the transmission path by implementing authentication at the application layer before data transmission. The user's credentials are verified by the merchant server before any sensitive transaction data is exchanged, eliminating the need to transmit passwords over the network and thus removing the vulnerability to interception.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary authentication of the user by the merchant server before the actual transaction takes place. This preliminary action establishes a trusted session and validates the user's identity in advance, so that subsequent transaction data can be exchanged securely without retransmitting sensitive credentials.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If traditional username and password authentication is used, then users can access online services, but phishing attacks and man in the middle attacks can trick users into providing sensitive information

Engineering Contradiction:
Improveability to access online servicesVSAvoidphishing and man in the middle attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the merchant server acts as a trusted mediator that verifies the user's identity before transaction data is exchanged. This intermediary layer prevents phishing and man-in-the-middle attacks by ensuring that authentication occurs through a verified channel rather than through potentially fraudulent interfaces that trick users into entering credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If sensitive information is transmitted over unsecured networks, then online transactions can be conducted remotely, but the information may be stolen at the user's computing system or merchant's server

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity of transmitted information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process from the transaction data transmission. User credentials are authenticated separately at the application layer before transaction data is exchanged. This segmentation ensures that even if transaction data is transmitted over unsecured networks, the sensitive authentication information remains protected and cannot be stolen during the transaction phase.

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach significantly reduces the risk of fraud by ensuring that sensitive information is only accessed and verified on a trusted, secure environment, enhancing the security of online transactions even over untrusted networks.

Implementation Method 1

encrypting and decrypting data using a cryptographic key

Methodology Applied
Scientific EffectCryptographic encryption:

Data Source

PatentUS9213992B2Secure online transactions using a trusted digital identity
Publication Date: 2015.12.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9213992B2 patent drawing
  • US9213992B2 patent drawing
  • US9213992B2 patent drawing

AI summary

Techniques for conducting secure online transactions are provided. Some techniques utilize a trusted, secure device that is distributed to a human user, and which only the user can access, a device reader, and a one-time secret valid only to authenticate a single transaction to improve on the traditional transaction model by isolating elements of the transaction with the user on the user's trusted, secure device. Isolating elements of the transaction on the trusted, secure device facilitates a secure transaction on an untrusted machine and over an untrusted network.