MitB Attack Prevention via Image-Based Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for electronic business over the Internet are vulnerable to Man-In-The-Browser (MitB) attacks, where intrusive agents can intercept and alter messages and summaries without detection, compromising security.

Innovation Solution

Generating an encoded representation of encrypted messages with an institution's digital signature, which is sent to a user's computer and then transferred to a hand-held device for decoding and decryption, allowing the user to verify the message and detect any alterations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If messages are encrypted using public key/private key encryption in the conventional system, then confidentiality is maintained during transmission, but the system becomes vulnerable to MitB attacks where intrusive agents can intercept and alter messages without detection

Engineering Contradiction:
Improvemessage integrityVSAvoidMitB attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent moves the decryption process from the browser environment (2D web page) to a mobile device dimension (3D physical device with camera). By encoding encrypted data as an image and requiring physical capture with a mobile device camera, the system adds a spatial dimension that intrusive browser-based agents cannot access, thereby preventing MitB attacks while maintaining message integrity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces an intermediary encoding step where encrypted data is transformed into an image format (QR code or similar). This intermediary representation acts as a bridge between the browser and mobile device, allowing secure data transfer while preventing direct agent access to the encrypted data. The image encoding serves as a protective intermediary layer that neutralizes MitB attack vectors

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If the partner sends a summary of business details encrypted with the client's public key, then the client can verify the business conduct, but the intrusive agent can alter the summary to reflect intended transfers rather than actual transfers

Engineering Contradiction:
Improvetransfer accuracy verificationVSAvoidsummary manipulation
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the verification process from the browser environment and relocates it to a mobile device. By taking out the decryption and verification operations from the vulnerable browser context and performing them on a separate physical device, the system prevents agents from manipulating summaries while ensuring accurate transfer verification

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The verification process transitions from a 2D browser window to a 3D mobile device interaction. The user physically captures an image, transfers it to a mobile device, and verifies the summary there, creating a dimensional barrier that prevents agent manipulation while maintaining verification accuracy

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If decryption occurs at the TLS layer in the conventional system, then efficient decryption is achieved, but the decrypted data remains vulnerable to interception and alteration by intrusive agents before display

Engineering Contradiction:
Improvedecryption efficiencyVSAvoidpost-decryption interception
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the final decryption step from the browser's TLS layer and relocates it to a mobile device. By taking out the sensitive decryption operation from the vulnerable browser environment and performing it on a secure mobile device, the system maintains decryption efficiency while eliminating post-decryption interception risks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an image encoding intermediary between TLS decryption and final data display. Encrypted data is first decoded from the image on the mobile device, then decrypted using stored private keys, and finally displayed. This intermediary process prevents direct agent access to decrypted data while maintaining operational efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8924726B1Robust message encryption
Publication Date: 2014.12.30 EMC IP HLDG CO LLC
  • US8924726B1 patent drawing
  • US8924726B1 patent drawing
  • US8924726B1 patent drawing

AI summary

An improved technique involves generating an encoded representation of encrypted forms of a message which includes an institution's digital signature derived from the message. The institution sends the encoded representation to the user's computer. The user transfers an image of the encoded representation from the user's computer to a separate hand-held device. The user then derives the encrypted forms of the message and the institution's digital signature by decoding the image on the hand-held device; the user then decrypts the encrypted forms of the message and the institution's digital signature on the hand-held device. The user then sees the message without interference from an intrusive agent in a MitB attack. Further, the user can verify the institution's identity as the sender of the message by being able to validate the institution's digital signature. In this way, a MitB attack is very likely to be made apparent to the user.