Mobile Banking App Data Isolation via Server Hosting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices used for payment transactions face challenges in protecting sensitive financial data from fraudulent usage due to loss or theft, as existing solutions fail to adequately secure data storage and transmission.

Innovation Solution

A method for securing data transmission between a mobile communication device and a server through a mobile application hosted on a management server, which includes generating session keys for valid communication sessions, disabling the application by invalidating session keys, implementing biometric authentication, and using a payment limit PIN to control transactions, ensuring that sensitive information is never stored on the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive financial data is stored on the mobile communication device to enable payment transactions, then transaction convenience is improved, but security against fraudulent usage deteriorates

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraudulent usage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive financial data from the mobile communication device and stores it exclusively on a remote server. The mobile device only contains a mobile application that communicates with the server, eliminating the security risk of storing sensitive data locally while maintaining transaction convenience through networked access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a server as an intermediary between the user and financial data. The server hosts the mobile application and stores all sensitive information, acting as a secure mediator that enables transactions without requiring data to be stored on the mobile device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If session keys are generated for each communication session to enhance security, then security against data theft is improved, but system complexity deteriorates

Engineering Contradiction:
Improvedata theft preventionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by generating session keys before each communication session and automatically managing their creation, transmission, and invalidation. This preliminary setup secures each session without requiring complex user intervention or manual key management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile application automatically handles session key generation, transmission to the server, and invalidation after use. The system performs these security-critical operations autonomously without requiring user intervention, simplifying the user interface while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If biometric authentication and payment limit PIN are implemented to prevent fraudulent transactions, then security against loss or theft is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvefraudulent transaction preventionVSAvoidtransaction speed
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies partial authentication actions by using biometric authentication only for initial login and payment limit PIN only when transactions exceed a predetermined threshold. For routine transactions below the limit, no additional authentication is required, balancing security with operational speed.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the authentication parameter dynamically based on transaction amount. Small transactions use no additional authentication beyond login, while large transactions trigger payment limit PIN requirements. This parameter-based approach adjusts security measures to the actual risk level.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11847649B2Method and system for mobile banking using a server
Publication Date: 2023.12.19 BLAZE MOBILE TECHNOLOGIES LLC
  • US11847649B2 patent drawing
  • US11847649B2 patent drawing

AI summary

A method for transmitting data between a mobile communication device and a server. The method includes running a mobile application on the mobile communication device. The mobile application is hosted on the mobile communication device through the server as a Software as a Service (SaaS). The method further includes transmitting data associated with the mobile application between the mobile communication device and the server, in which transmission of the data between the mobile communication device and the server is monitored through the server.