Trusted Storage Token with On-Board Cryptographic Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer security and identity theft risks are heightened due to inadvertent data disclosure during networked data exchanges, with users often unaware of the data accessed, and existing security tokens are vulnerable to malware and lack transparency in transaction processes.
Innovation Solution
A storage token with a separate trusted user interface and operating system routines, communicating via a dedicated bus to shield data and allowing custom APIs for secure execution, featuring an on-board cryptographic engine for secure storage and verification of requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a storage token is used for secure data exchange, then security risk is reduced, but users remain unaware of the actual data being accessed and credentials being used
Solution Approach 1:
The patent introduces a trusted display interface as an intermediary between the storage token and the user. This intermediary component captures and displays information about data access, credentials used, and transaction details in real-time, making the previously hidden operations visible to users without compromising security protocols
Solution Approach 2:
The system implements feedback mechanisms where the storage token provides real-time information about its operations through the trusted display interface. Users receive feedback about what data is being accessed, what credentials are being used, and can see transaction values, enabling informed decision-making while maintaining security
2Reliability
If smart cards are used as security tokens, then compromise risk to cryptographic keys is reduced, but malware attack risk increases as usage increases
Solution Approach 1:
The patent segments the storage token into distinct functional components with separate trusted execution environments. Critical cryptographic operations and key storage are isolated in protected segments that are resistant to malware attacks, while other functions can operate independently, limiting the potential impact of any single compromise
Solution Approach 2:
The system implements prior cushioning through pre-established trusted display interfaces and security protocols that are in place before any potential attack occurs. These pre-configured security measures and monitoring mechanisms are ready to detect and respond to malware attempts, reducing the effectiveness of attacks before they can compromise the token
3Reliability
If users are prompted to approve transactions, then transaction security is improved, but users still lack awareness of actual data accessed and transaction values
Solution Approach 1:
The trusted display interface acts as an intermediary that captures transaction information directly from the storage token operations and presents it to users in a comprehensible format. This intermediary layer translates technical operations into user-friendly displays showing actual data accessed, credentials used, and transaction values, enabling informed approval decisions
Data Source
AI summary
A storage token has a display and a keyboard, or other input device, that allows a user to view a request to access a memory location and enter a response to the request. The display allows presentation of details of the request, such as a pathname to a requested memory location, metadata describing a cryptographic key for use in a transaction confirmation, and/or transaction details which are awaiting verification by a credential stored on the token. The storage token may also include a cryptographic engine and a secure memory allowing signing data returned in response to the request.


