Mobile Banking App Data Isolation via Server Hosting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication devices used for payment transactions face challenges in protecting sensitive financial data from fraudulent usage due to loss or theft, as existing solutions fail to adequately secure data storage and transmission.
Innovation Solution
A method for securing data transmission between a mobile communication device and a server through a mobile application hosted on a management server, which includes generating session keys for valid communication sessions, disabling the application by invalidating session keys, implementing biometric authentication, and using a payment limit PIN to control transactions, ensuring that sensitive information is never stored on the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive financial data is stored on the mobile communication device to enable payment transactions, then transaction convenience is improved, but security against fraudulent usage deteriorates
Solution Approach 1:
The patent extracts sensitive financial data from the mobile communication device and stores it exclusively on a remote server. The mobile device only contains a mobile application that communicates with the server, eliminating the security risk of storing sensitive data locally while maintaining transaction convenience through networked access.
Solution Approach 2:
The patent introduces a server as an intermediary between the user and financial data. The server hosts the mobile application and stores all sensitive information, acting as a secure mediator that enables transactions without requiring data to be stored on the mobile device.
2Object-affected harmful factors
If session keys are generated for each communication session to enhance security, then security against data theft is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements preliminary action by generating session keys before each communication session and automatically managing their creation, transmission, and invalidation. This preliminary setup secures each session without requiring complex user intervention or manual key management.
Solution Approach 2:
The mobile application automatically handles session key generation, transmission to the server, and invalidation after use. The system performs these security-critical operations autonomously without requiring user intervention, simplifying the user interface while maintaining strong security.
3Object-affected harmful factors
If biometric authentication and payment limit PIN are implemented to prevent fraudulent transactions, then security against loss or theft is improved, but ease of operation deteriorates
Solution Approach 1:
The patent applies partial authentication actions by using biometric authentication only for initial login and payment limit PIN only when transactions exceed a predetermined threshold. For routine transactions below the limit, no additional authentication is required, balancing security with operational speed.
Solution Approach 2:
The patent changes the authentication parameter dynamically based on transaction amount. Small transactions use no additional authentication beyond login, while large transactions trigger payment limit PIN requirements. This parameter-based approach adjusts security measures to the actual risk level.
Data Source
AI summary
A method for transmitting data between a mobile communication device and a server. The method includes running a mobile application on the mobile communication device. The mobile application is hosted on the mobile communication device through the server as a Software as a Service (SaaS). The method further includes transmitting data associated with the mobile application between the mobile communication device and the server, in which transmission of the data between the mobile communication device and the server is monitored through the server.

