Hardened Standalone Browser for Secure Banking Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks, particularly in the banking industry, face challenges with identity theft, information leakage, and accurate auditing due to vulnerabilities in client software and untrusted host computers, which compromise security and authentication processes.

Innovation Solution

A secure data communication system utilizing a hardened, standalone browser on a storage medium that performs integrity checks and requires multi-factor authentication, including digital certificates and username/password combinations, to ensure secure communications and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional browser is used on an untrusted host computer, then ease of operation is maintained, but security and reliability deteriorate due to malware interactions and unauthorized access

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the browser into a hardened standalone browser stored on a removable storage medium, separate from the host computer's operating system. This segmentation isolates the browser from potential malware on the untrusted host while maintaining its functionality, thus improving security without requiring complex system-wide modifications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The removable storage medium acts as an intermediary carrier that holds the hardened browser and authentication data. This intermediary mechanism allows the browser to operate independently from the untrusted host computer's filesystem, preventing direct access by malware while enabling secure communication with trusted servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity checks are performed on all files, then reliability improves, but time consumption increases

Engineering Contradiction:
Improveintegrity verificationVSAvoidtime for integrity checks
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The loader performs integrity checks on critical files (browser executable, authentication data, add-on programs) before launching them. By performing these checks in advance and only on essential files rather than all files, the system ensures reliability while minimizing time consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of performing comprehensive integrity checks on every possible file, the system applies partial checks to the most critical components (browser, authentication data, add-ons). This partial action approach maintains sufficient reliability for security-critical operations without the time penalty of exhaustive verification.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multi-factor authentication is required, then security improves, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication data including digital certificates is automatically loaded and managed by the hardened browser from the removable storage medium without requiring manual user intervention. The system performs self-service authentication by automatically presenting credentials to trusted servers, reducing the operational burden on users while maintaining strong multi-factor authentication.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8650391B2Systems and methods for securely providing and/or accessing information
Publication Date: 2014.02.11 TRUSTATE INT
  • US8650391B2 patent drawing
  • US8650391B2 patent drawing
  • US8650391B2 patent drawing

AI summary

The invention is directed to a system for use with a first device in communication with a second device. The system includes a storage medium that is connectable with the first device, a hardened, stand alone, web browser stored on the storage medium, and client authentication data. The web browser uses the client authentication data to facilitate secure communication between the first device and the second device, and the first device communicates with a third device that provides configuration data that includes one or more approved addresses.