Headless Browser Secures Mobile Banking Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Small and mid-size banks face challenges in developing customized mobile banking applications with secure data access due to high costs and security risks associated with account aggregation methods, which often limit access to read-only data and do not support features like mobile check deposit and fund transfers.
Innovation Solution
A system that enables mobile devices to access secured data using a native mobile application combined with a headless browser, which emulates desktop browser operations, allowing read and write access without requiring dedicated back-end integrations, using a virtual API to standardize user authentication and data mapping across financial institutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If account aggregation is used to provide mobile banking access, then mobile device access to secured data is enabled, but security risks increase and access is limited to read-only operations
Solution Approach 1:
The patent introduces a headless browser as an intermediary component that runs within the mobile application but maintains separate authentication credentials. This mediator enables the mobile app to access secured data through the bank's website without storing credentials in the cloud, thus resolving the contradiction between enabling access and maintaining security.
2Adaptability or versatility
If account aggregation is used to enable mobile banking, then basic read-only access is provided, but write operations such as fund transfers and mobile check deposit are not supported
Solution Approach 1:
The headless browser is designed to handle both read and write operations by emulating various user interactions including form submissions, button clicks, and navigation. This universal approach allows the same mechanism to support diverse banking functions from simple balance checks to complex transactions like fund transfers and mobile check deposit.
3Reliability
If customized mobile banking applications are developed with proper security integrations, then secure read and write access is achieved, but development costs become prohibitively expensive for small and mid-size banks
Solution Approach 1:
The solution enables banks to self-serve by using their existing website infrastructure without requiring custom mobile application development or dedicated back-end integrations. The headless browser automatically handles authentication and data retrieval using the bank's existing login credentials, eliminating the need for expensive custom development while maintaining security standards.
4Ease of operation
If user credentials are stored on intermediary servers for account aggregation, then mobile access is simplified, but security risks increase
Solution Approach 1:
The patent extracts the authentication credentials from the cloud-based intermediary server model and keeps them locally on the mobile device within the headless browser environment. This extraction eliminates the security vulnerability of storing credentials on external servers while maintaining the operational simplicity of automated mobile access.
Data Source
AI summary
A method includes receiving, at a native application, access credential data and providing the access credential data from the native application to a headless browser. The method also includes initiating a secured connection from the headless browser to a remote server that hosts a website. The remote server supports access to secured data without relying on an application programming interface. The method also includes sending, by the headless browser via the secured connection, the access credential data to the remote server. The method also includes receiving first web page data of the website from the remote server via the secured connection and parsing the first web page data to identify user-specific data. The method further includes receiving, by the headless browser via the secured connection, at least a portion of the secured data.


