Trusted Storage Token with On-Board Cryptographic Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer security and identity theft risks are heightened due to inadvertent data disclosure during networked data exchanges, with users often unaware of the data accessed, and existing security tokens are vulnerable to malware and lack transparency in transaction processes.

Innovation Solution

A storage token with a separate trusted user interface and operating system routines, communicating via a dedicated bus to shield data and allowing custom APIs for secure execution, featuring an on-board cryptographic engine for secure storage and verification of requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a storage token is used for secure data exchange, then security risk is reduced, but users remain unaware of the actual data being accessed and credentials being used

Engineering Contradiction:
ImprovesecurityVSAvoidtransparency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a trusted display interface as an intermediary between the storage token and the user. This intermediary component captures and displays information about data access, credentials used, and transaction details in real-time, making the previously hidden operations visible to users without compromising security protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the storage token provides real-time information about its operations through the trusted display interface. Users receive feedback about what data is being accessed, what credentials are being used, and can see transaction values, enabling informed decision-making while maintaining security

Inventive Principle:
Principle #23Feedback

2Reliability

If smart cards are used as security tokens, then compromise risk to cryptographic keys is reduced, but malware attack risk increases as usage increases

Engineering Contradiction:
ImprovesecurityVSAvoidmalware attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the storage token into distinct functional components with separate trusted execution environments. Critical cryptographic operations and key storage are isolated in protected segments that are resistant to malware attacks, while other functions can operate independently, limiting the potential impact of any single compromise

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements prior cushioning through pre-established trusted display interfaces and security protocols that are in place before any potential attack occurs. These pre-configured security measures and monitoring mechanisms are ready to detect and respond to malware attempts, reducing the effectiveness of attacks before they can compromise the token

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If users are prompted to approve transactions, then transaction security is improved, but users still lack awareness of actual data accessed and transaction values

Engineering Contradiction:
Improvetransaction securityVSAvoidtransaction transparency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The trusted display interface acts as an intermediary that captures transaction information directly from the storage token operations and presents it to users in a comprehensible format. This intermediary layer translates technical operations into user-friendly displays showing actual data accessed, credentials used, and transaction values, enabling informed approval decisions

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8914901B2Trusted storage and display
Publication Date: 2014.12.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8914901B2 patent drawing
  • US8914901B2 patent drawing
  • US8914901B2 patent drawing

AI summary

A storage token has a display and a keyboard, or other input device, that allows a user to view a request to access a memory location and enter a response to the request. The display allows presentation of details of the request, such as a pathname to a requested memory location, metadata describing a cryptographic key for use in a transaction confirmation, and/or transaction details which are awaiting verification by a credential stored on the token. The storage token may also include a cryptographic engine and a secure memory allowing signing data returned in response to the request.