Dual-Security Applet Account Protection via Joint Risk Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current applet security systems, which rely on third-party application security systems for protection, are insufficient for ensuring the security of target accounts, particularly for special applets like bank applets that require more robust security measures.
Innovation Solution
Implementing a dual-security system approach where both the service provider's security system and the third-party application's security system are triggered jointly to perform risk prevention and control, including joint identity verification, to enhance account security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If only the third-party application's security system is used to protect the target account, then the device complexity is reduced and ease of operation is improved, but the reliability of account security protection is insufficient
Solution Approach 1:
The security protection system is segmented into two independent but coordinated components: the third-party application's security system and the service provider's security system. Each system operates independently with its own risk control and identity verification capabilities, yet they work together through a coordinated mechanism where the service provider's system provides additional layered protection for the target account without completely replacing the third-party system.
Solution Approach 2:
The service provider's security system is nested within the existing third-party application security framework. The dual-security mechanism allows the service provider's risk control and identity verification systems to operate inside the broader third-party security environment, creating a nested protective structure where both systems' capabilities are utilized simultaneously for comprehensive account protection.
2Reliability
If a dual-security system is implemented with both service provider and third-party security systems, then the reliability of account security is improved, but the device complexity increases
Solution Approach 1:
The risk control and identity verification capabilities of both the service provider's security system and the third-party application's security system are merged into a unified dual-security protection mechanism. The systems combine their respective strengths through coordinated operation, where both systems jointly evaluate risks and verify identities, creating a consolidated security approach that leverages multiple layers of protection simultaneously.
Solution Approach 2:
The dual-security system is designed with multi-functionality, where both the service provider's security system and the third-party application's security system can perform multiple functions including risk control, identity verification, and account protection. This universal design allows either system to operate independently or in combination depending on the specific security requirements of the target account and service context.
3Reliability
If joint identity verification by both security systems is performed, then the reliability of user authentication is improved, but the loss of time increases
Solution Approach 1:
The service provider's security system performs preliminary risk control assessment and identity verification checks before the final authentication decision is made. By conducting preliminary verification actions, the system can identify and filter out obviously suspicious cases early, reducing the need for both systems to perform complete verification procedures in all cases, thereby minimizing time loss while maintaining high reliability.
Solution Approach 2:
The dual-security verification process implements partial action by having both systems perform verification only when necessary based on risk levels. For low-risk operations, the third-party system's verification may suffice, while for high-risk operations, both systems perform full verification. This selective approach ensures high reliability for critical operations while reducing time loss for routine operations.
Data Source
AI summary
An applet-based account security protection method and system are disclosed. The method may comprise: receiving, from an applet, a processing request for a target service related to a target account, wherein the target account is opened by a user at a service provider corresponding to the applet, and the applet runs on a client of a third-party application; and triggering a first security system and a second security system to jointly perform risk prevention and control on a target service related to the target account. The first security system is a security system of the service provider, and the second security system is a security system corresponding to the third-party application.


