Mobile Banking App Security via Remote Session Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices are increasingly used for payment transactions, posing a risk of fraudulent usage due to loss or theft, as sensitive financial data is stored on these devices.

Innovation Solution

A method for transmitting data between a mobile communication device and a server, where a mobile application is hosted on the device through a management server, and data transmission is monitored. This includes generating a session key for each communication session, disabling the application by invalidating the session key, and implementing a payment limit PIN and biometric authentication to secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive financial data is stored on mobile communication devices to enable payment transactions, then transaction convenience is improved, but security against fraudulent usage deteriorates

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraudulent usage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive financial data from the mobile communication device by implementing a tokenization system where only tokenized representations are stored locally, while actual financial data remains secured on remote servers. This allows the device to perform transactions without holding vulnerable sensitive information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments financial data into multiple components: tokenized data stored on the device for transaction processing, and actual sensitive data stored securely on remote servers. This segmentation allows transaction convenience while mitigating security risks by ensuring that compromised device data cannot be used for fraudulent transactions without server validation.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If mobile applications are installed on mobile devices for banking transactions, then service accessibility is improved, but vulnerability to data theft worsens

Engineering Contradiction:
Improveservice accessibilityVSAvoiddata theft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a management server as an intermediary between the mobile device and banking systems. This server hosts the mobile application remotely and manages data transmission, allowing the device to access banking services without storing sensitive data locally. The intermediary architecture enables service accessibility while protecting against data theft by maintaining data control on secure remote servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If session keys are generated for each communication session to enhance security, then transaction security is improved, but system complexity worsens

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements automated session key generation and management where the management server automatically creates, distributes, and invalidates session keys for each communication session without requiring manual intervention. This self-service approach enhances transaction security through unique session authentication while minimizing system complexity by automating the key management process.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250200550A1Using a non-browser based application for mobile banking
Publication Date: 2025.06.19 FISHER MICHELLE T
  • US20250200550A1 patent drawing
  • US20250200550A1 patent drawing

AI summary

A method for transmitting data between a mobile communication device and a server. The method includes running a mobile application on the mobile communication device. The mobile application is hosted on the mobile communication device through the server as a Software as a Service (SaaS). The method further includes transmitting data associated with the mobile application between the mobile communication device and the server, in which transmission of the data between the mobile communication device and the server is monitored through the server.