Cross-Domain Browsing Session for Man-in-the-Browser Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online secure services, such as online banking and e-commerce, are vulnerable to malicious attacks due to insufficient data filtering, network vulnerabilities, and malware in web browsers, making it difficult to protect against 'man-in-the-browser' attacks, which can modify transaction details transparently to users.
Innovation Solution
Implementing a cross-domain browsing session where the domain name and IP address used for sensitive operations can change dynamically, making it difficult for malware to detect the intended communication, and using anonymous domain names to enhance security without requiring additional software or devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure browser or specific software application is installed to protect against man-in-the-browser attacks, then transaction security is improved, but ease of operation deteriorates because users are not willing to install and use another specific browser
Solution Approach 1:
The patent introduces a secure communication channel as an intermediary between the user's browser and the service server. This channel uses a different domain name (second domain name) than the one the user sees in the browser address bar. The intermediary channel encrypts and protects sensitive operations, allowing security enhancement without requiring users to change their browsing habits or install new software.
Solution Approach 2:
The patent creates a copy of the communication channel using a second domain name that mirrors the functionality of the original domain but operates through a secure, protected path. This copy allows sensitive operations to be performed through the secure channel while the user interacts with the familiar browser interface, thus maintaining ease of operation while improving security.
2Reliability
If extensions to the current browser are used to enhance security, then transaction security is improved, but ease of operation deteriorates because these extensions require the user's intervention
Solution Approach 1:
The patent implements a self-service security mechanism where the secure communication channel automatically operates in the background without requiring user intervention. The system automatically establishes the secure channel, manages the dual domain name routing, and protects sensitive operations transparently, eliminating the need for users to manually configure or activate security extensions.
3Reliability
If out-of-band communication via a different device is used to confirm sensitive operations, then transaction security is improved, but device complexity deteriorates because it requires several devices to carry out the sensitive operation
Solution Approach 1:
The patent merges the secure communication functionality directly into the user's existing browser environment by establishing a hidden secure channel within the same device. Instead of requiring a separate confirmation device, the system combines the browsing interface with a protected communication path that operates simultaneously, thus improving security while avoiding additional device requirements.
4Ease of operation
If the web browser is compromised by malware, then ease of operation is maintained, but transaction security deteriorates because transaction elements can be modified transparently to the user
Solution Approach 1:
The patent segments the communication process into two distinct paths: a visible browsing path that the user interacts with and a hidden secure channel that actually carries out sensitive operations. This segmentation ensures that even if malware compromises the visible browser path, the secure channel remains protected and can execute transactions safely, thus maintaining both ease of operation and transaction security.
Data Source
AI summary
The invention relates to a method for carrying out a sensitive operation in the course of a communication between a processing unit and a first service server, said first server being accessible via a first domain name and/or first electronic address. The method comprises the step of using at least one second domain name different from the first and/or a second electronic address different from the first to carry out all or part of the sensitive operation. The invention also relates to a system corresponding to the method and comprising the server and/or the processing unit.

