Secure Financial Transactions Using Virtual TPM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic transaction systems are vulnerable to hacking and require additional hardware for dual-authentication, which increases costs and complexity, making them less appealing to users.
Innovation Solution
A system that uses a secure server to store and authenticate user security information, leveraging a trusted platform module (TPM) on the user's computer to create a protected environment for transactions, eliminating the need for external hardware by embedding security information and using a virtual appliance module for encryption and key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dual-factor authentication is implemented using a peripheral PIN entry device (PED) and ATM card, then transaction security is improved, but device complexity and cost increase due to additional hardware requirements
Solution Approach 1:
The patent extracts the security functionality from external hardware devices (PED, ATM card reader) and relocates it to the user's existing computer system through software-based TPM emulation and virtual appliance technology. This eliminates the need for additional physical authentication devices while maintaining dual-factor authentication capabilities.
Solution Approach 2:
The system enables the user's computer to authenticate itself and store security information autonomously using virtual appliance technology and software-based TPM. The computer serves its own authentication needs without requiring external authentication hardware, making the system self-sufficient and reducing hardware dependencies.
2Reliability
If encryption provisions of web browsers are used for electronic transactions, then some level of security is provided, but security flaws in the browser and operating system remain vulnerable to hacking
Solution Approach 1:
The patent introduces a virtual appliance as an intermediary layer between the user's computer and the transaction processing system. This virtual appliance contains a software-based TPM that securely stores authentication information and cryptographic keys, acting as a protected intermediary that prevents direct access to security credentials even if the host operating system is compromised.
Solution Approach 2:
The system pre-establishes a protected environment through virtual appliance technology before transactions occur. The software-based TPM and encrypted storage of security information create a cushion of protection that prevents hackers from accessing authentication data even if they gain access to the user's computer through Trojans or other malicious programs.
3Reliability
If peripheral PIN entry devices are used for dual-authentication, then security is greatly increased, but additional costs and complications deter conventional users
Solution Approach 1:
The patent makes the authentication system universal by utilizing components already present in most modern computers (CPU with integrated TPM, virtualization capabilities). The software-based approach allows the system to function across different operating systems and hardware configurations without requiring users to acquire or learn how to use specialized authentication hardware.
Solution Approach 2:
The system creates a software copy of the TPM functionality that replicates the security features of hardware-based TPMs. This virtual TPM emulates the behavior and security properties of physical authentication devices, providing the same dual-factor authentication capabilities without requiring physical hardware copies of PEDs or card readers.
Data Source
AI summary
A system and method are disclosed for conducting secure electronic transactions using dual-authentications. A secure server stores security information for a plurality of users and authorizes transactions being conducted by these users. A user computer system having a trusted platform module is used for storing security information relating to at least one user account. Protected environments are created to facilitate secure connections based on at least the security information stored in the trusted platform module. Transactions between the user/electronic merchants and between the user/secure server are conducted within protected environments. When a user conducts an electronic transaction with an electronic merchant, the transaction is authenticated by the secure server before can be completed.


