Trusted Hardware Computing Device for Legacy System Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems are vulnerable to malware infections, which can compromise user data and privacy by allowing sensitive information to be accessed and manipulated, leading to potential damage and privacy breaches.

Innovation Solution

A system comprising a trusted hardware computing device that communicates wirelessly with a legacy computing system, providing security functions such as authentication, encryption, and data protection to prevent malicious access and ensure secure communication, even if the legacy system is infected with malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a legacy computing system is used, then ease of operation and compatibility are maintained, but security and reliability deteriorate due to malware vulnerabilities

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system is divided into two separate environments: a legacy environment for general computing operations and a trusted hardware environment for security-critical functions. This segmentation allows the legacy system to maintain ease of operation while the trusted environment provides enhanced security, resolving the contradiction between operational convenience and security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted hardware device acts as an intermediary between the user and the legacy computing system. This intermediary handles authentication, credential protection, and security-sensitive operations, preventing malware in the legacy system from accessing sensitive information while maintaining the system's ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security functions are integrated into the legacy system, then reliability improves, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security functions are extracted from the legacy computing system and placed in a separate trusted hardware device. This extraction maintains security reliability while avoiding the increase in device complexity that would result from integrating security components into the legacy system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted hardware device is designed as a universal security solution that can protect multiple legacy systems and applications. By providing multi-functional security capabilities in a single device, the solution achieves high reliability without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If hands-free operation is implemented, then ease of operation improves, but security risks increase due to lack of user verification

Engineering Contradiction:
Improvehands-free operationVSAvoidsecurity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

User authentication and verification are performed in advance through the trusted hardware device before hands-free operations are executed. This preliminary action ensures that security verification is completed beforehand, allowing subsequent hands-free operations to proceed with verified credentials, thus maintaining both ease of operation and security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trusted hardware device provides continuous feedback regarding authentication status and security verification results during hands-free operations. This feedback mechanism ensures that user verification is maintained throughout the operation, resolving the contradiction between hands-free convenience and security verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12164666B2Hands free access management and credential protection
Publication Date: 2024.12.10 BARKAN MORDECAI
  • US12164666B2 patent drawing
  • US12164666B2 patent drawing
  • US12164666B2 patent drawing

AI summary

A trusted component is suggested to be added to off the shelf computing systems such as PCs or smartphone providing secure functions for access management and credential protection—safe authentication, maintaining session integrity and validation of content modification. An additional advantage of the solution that it detects malware/hacking attempts on first try allowing of taking action while oblivious to the malware/hacker to avoid retaliation. The trusted component may be any type of computing system that could be regarded trusted.