Headless Browser Secures Mobile Banking Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small and mid-size banks face challenges in developing customized mobile banking applications with secure data access due to high costs and security risks associated with account aggregation methods, which often limit access to read-only data and do not support features like mobile check deposit and fund transfers.

Innovation Solution

A system that enables mobile devices to access secured data using a native mobile application combined with a headless browser, which emulates desktop browser operations, allowing read and write access without requiring dedicated back-end integrations, using a virtual API to standardize user authentication and data mapping across financial institutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If account aggregation is used to provide mobile banking access, then mobile device access to secured data is enabled, but security risks increase and access is limited to read-only operations

Engineering Contradiction:
Improvemobile device access to secured dataVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a headless browser as an intermediary component that runs within the mobile application but maintains separate authentication credentials. This mediator enables the mobile app to access secured data through the bank's website without storing credentials in the cloud, thus resolving the contradiction between enabling access and maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If account aggregation is used to enable mobile banking, then basic read-only access is provided, but write operations such as fund transfers and mobile check deposit are not supported

Engineering Contradiction:
Improvemobile banking functionalityVSAvoidread and write access capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The headless browser is designed to handle both read and write operations by emulating various user interactions including form submissions, button clicks, and navigation. This universal approach allows the same mechanism to support diverse banking functions from simple balance checks to complex transactions like fund transfers and mobile check deposit.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If customized mobile banking applications are developed with proper security integrations, then secure read and write access is achieved, but development costs become prohibitively expensive for small and mid-size banks

Engineering Contradiction:
Improvesecure data accessVSAvoiddevelopment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The solution enables banks to self-serve by using their existing website infrastructure without requiring custom mobile application development or dedicated back-end integrations. The headless browser automatically handles authentication and data retrieval using the bank's existing login credentials, eliminating the need for expensive custom development while maintaining security standards.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If user credentials are stored on intermediary servers for account aggregation, then mobile access is simplified, but security risks increase

Engineering Contradiction:
Improvemobile access implementationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credentials from the cloud-based intermediary server model and keeps them locally on the mobile device within the headless browser environment. This extraction eliminates the security vulnerability of storing credentials on external servers while maintaining the operational simplicity of automated mobile access.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240430677A1Secured data access from a mobile device executing a native mobile application and a headless browser
Publication Date: 2024.12.26 APPBRILLIANCE INC
  • US20240430677A1 patent drawing
  • US20240430677A1 patent drawing
  • US20240430677A1 patent drawing

AI summary

A method includes receiving, at a native application, access credential data and providing the access credential data from the native application to a headless browser. The method also includes initiating a secured connection from the headless browser to a remote server that hosts a website. The remote server supports access to secured data without relying on an application programming interface. The method also includes sending, by the headless browser via the secured connection, the access credential data to the remote server. The method also includes receiving first web page data of the website from the remote server via the secured connection and parsing the first web page data to identify user-specific data. The method further includes receiving, by the headless browser via the secured connection, at least a portion of the secured data.