Fraud Sandbox Proxy for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are at risk of providing sensitive information to untrusted entities due to fraudulent schemes, such as phishing, where illegitimate websites request private information, leading to potential harm.

Innovation Solution

A financial institution computing system acts as a proxy, verifying the legitimacy of network destinations and if untrusted, it transmits virtual sandbox content to the user's device, encrypts user input, and alerts the user, preventing sensitive information from being sent to untrusted entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access network destinations directly, then ease of operation is improved, but security against fraudulent entities deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a financial institution computing system as an intermediary between the user computing device and network destinations. This intermediary verifies the legitimacy of network destinations before allowing communication, thus maintaining ease of operation while improving security against fraudulent entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If substitution content is transmitted to untrusted entities, then loss of information is reduced, but device complexity increases

Engineering Contradiction:
Improveloss of informationVSAvoiddevice complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent creates substitution content that mimics the appearance and functionality of legitimate content requests. This copying approach prevents sensitive information loss by redirecting users to safe alternatives while maintaining the user experience, thus reducing information loss without significantly increasing device complexity.

Inventive Principle:
Principle #26Copying

3Reliability

If user input is encrypted before transmission, then security is improved, but processing time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs legitimacy verification and content substitution before the user submits sensitive information. By conducting security checks in advance, the system minimizes the need for time-consuming encryption operations on actual sensitive data, thus improving security while reducing processing time losses.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11593517B1Systems and methods for a virtual fraud sandbox
Publication Date: 2023.02.28 WELLS FARGO BANK NA
  • US11593517B1 patent drawing
  • US11593517B1 patent drawing
  • US11593517B1 patent drawing

AI summary

A financial institution computing system associated with a financial institution includes a network interface configured to communicate data over a network, and a processing circuit comprising a memory and a processor. The memory has instructions stored thereon that cause the processor to receive, by the network interface, a content request from a user computing device associated with a user, the content request requesting content from a network destination, determine if the network destination is associated with a trusted entity, determine that the requested content prompts the user to input sensitive information, and transmit, by the network interface substitution content to the user computing device responsive to determining that the network destination is illegitimate and to determining that the requested content includes at least one field into which the user may input sensitive information, the substitution content including at least one prompt requesting the user to input sensitive information.