Trusted Integrity Manager for Wireless Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing financial transaction systems via electronic devices face security issues due to the susceptibility of data transferred wirelessly, including credit card and financial information, to theft or malicious attacks, and require cooperation among multiple parties to establish a secure over-the-air link.

Innovation Solution

The integration of a Trusted Integrity Manager (TIM) within the Trusted Service Manager (TSM) framework, utilizing an embedded secure element in mobile devices to authenticate users through data such as time and geo-location, enhancing security by validating and authorizing transactions and managing payment instruments securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If data is transferred wirelessly for financial transactions, then convenience and speed of transaction are improved, but security against theft and malicious attacks deteriorates

Engineering Contradiction:
Improvetransaction speedVSAvoidsecurity vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Trusted Service Manager (TSM) and Trusted Integrity Manager (TIM) as intermediary entities between the mobile device and the financial network. These intermediaries establish secure over-the-air links using authentication mechanisms, acting as trusted mediators that protect both the convenience of wireless transactions and the security against attacks. The TSM manages the authentication infrastructure while TIM verifies device integrity, creating a secure pathway that enables fast wireless transactions without exposing sensitive data to attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple parties are involved in the transaction system, then functionality and service coverage are improved, but system complexity and coordination difficulty increase

Engineering Contradiction:
Improveservice coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent designs the Trusted Service Manager (TSM) and Trusted Integrity Manager (TIM) as universal multi-functional components that handle multiple roles within the financial transaction ecosystem. The TSM performs authentication, authorization, and key management functions, while TIM conducts integrity verification and device validation. These universal components serve multiple parties (mobile devices, financial institutions, merchants) through standardized interfaces, reducing the need for separate specialized systems for each party and simplifying coordination while maintaining broad service coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional authentication methods are used, then ease of operation is maintained, but security level against sophisticated attacks deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service authentication mechanisms where the mobile device automatically performs integrity verification and authentication through the TIM and TSM infrastructure. The device's phone function feeds data back to the TIM for automatic authentication without requiring user intervention in the security process. This self-service approach maintains ease of operation for users while implementing sophisticated security checks including device integrity verification, authentication proof generation, and secure credential validation, thereby achieving both convenience and high security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9467292B2Hardware-based zero-knowledge strong authentication (H0KSA)
Publication Date: 2016.10.11 PAYPAL INC
  • US9467292B2 patent drawing
  • US9467292B2 patent drawing
  • US9467292B2 patent drawing

AI summary

Systems and methods are provided for a device to engage in a zero-knowledge proof with an entity requiring authentication either of secret material or of the device itself. The device may provide protection of the secret material or its private key for device authentication using a hardware security module (HSM) of the device, which may include, for example, a read-only memory (ROM) accessible or programmable only by the device manufacturer. In the case of authenticating the device itself a zero-knowledge proof of knowledge may be used. The zero-knowledge proof or zero-knowledge proof of knowledge may be conducted via a communication channel on which an end-to-end (e.g., the device at one end and entity requiring authentication at the other end) unbroken chain of trust is established, unbroken chain of trust referring to a communication channel for which endpoints of each link in the communication channel mutually authenticate each other prior to conducting the zero-knowledge proof of knowledge and for which each link of the communication channel is protected by at least one of hardware protection and encryption.