Mobile Banking App Security via Remote Session Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication devices are increasingly used for payment transactions, posing a risk of fraudulent usage due to loss or theft, as sensitive financial data is stored on these devices.
Innovation Solution
A method for transmitting data between a mobile communication device and a server, where a mobile application is hosted on the device through a management server, and data transmission is monitored. This includes generating a session key for each communication session, disabling the application by invalidating the session key, and implementing a payment limit PIN and biometric authentication to secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive financial data is stored on mobile communication devices to enable payment transactions, then transaction convenience is improved, but security against fraudulent usage deteriorates
Solution Approach 1:
The patent extracts sensitive financial data from the mobile communication device by implementing a tokenization system where only tokenized representations are stored locally, while actual financial data remains secured on remote servers. This allows the device to perform transactions without holding vulnerable sensitive information.
Solution Approach 2:
The system segments financial data into multiple components: tokenized data stored on the device for transaction processing, and actual sensitive data stored securely on remote servers. This segmentation allows transaction convenience while mitigating security risks by ensuring that compromised device data cannot be used for fraudulent transactions without server validation.
2Adaptability or versatility
If mobile applications are installed on mobile devices for banking transactions, then service accessibility is improved, but vulnerability to data theft worsens
Solution Approach 1:
The patent introduces a management server as an intermediary between the mobile device and banking systems. This server hosts the mobile application remotely and manages data transmission, allowing the device to access banking services without storing sensitive data locally. The intermediary architecture enables service accessibility while protecting against data theft by maintaining data control on secure remote servers.
3Reliability
If session keys are generated for each communication session to enhance security, then transaction security is improved, but system complexity worsens
Solution Approach 1:
The system implements automated session key generation and management where the management server automatically creates, distributes, and invalidates session keys for each communication session without requiring manual intervention. This self-service approach enhances transaction security through unique session authentication while minimizing system complexity by automating the key management process.
Data Source
AI summary
A method for transmitting data between a mobile communication device and a server. The method includes running a mobile application on the mobile communication device. The mobile application is hosted on the mobile communication device through the server as a Software as a Service (SaaS). The method further includes transmitting data associated with the mobile application between the mobile communication device and the server, in which transmission of the data between the mobile communication device and the server is monitored through the server.

