Mobile Security App Segmentation for Banking Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As network usage increases, individuals face growing risks of fraud and theft, particularly in online banking and mobile transactions, due to vulnerabilities in identity and credit card information, with criminals exploiting man-in-the-middle attacks and lost or stolen devices potentially accessing sensitive accounts.
Innovation Solution
A mobile security application that provides additional control and security for online and mobile banking accounts by requiring user authentication through a separate access control app, utilizing a unique authentication process involving user ID, password, and activation codes, which can be enrolled and authenticated, and allows users to toggle on/off specific banking features or disable accounts entirely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users rely solely on traditional login credentials (user ID and password) for online banking, then ease of operation is maintained, but security against fraud and theft is insufficient
Solution Approach 1:
The patent divides the authentication system into two separate applications: a banking application for financial transactions and a security application for access control. This segmentation allows each application to have specialized functions, with the security application providing an additional layer of protection through separate authentication credentials (security ID and security password) that are independent from the banking credentials, thereby enhancing security without significantly complicating the user experience
Solution Approach 2:
The security application acts as an intermediary between the user and the banking system. It provides an additional authentication layer by requiring security credentials and enabling features like lock banking functionality, where the security application can prevent access to the banking application even if the banking credentials are compromised, thus mediating the authentication process to enhance security
2Ease of operation
If users store banking access information on their mobile device, then convenience is improved, but vulnerability to loss or theft of the device increases
Solution Approach 1:
By separating banking credentials and security credentials into different applications with independent authentication mechanisms, the patent ensures that compromise of one application does not automatically compromise the other. Even if a device is lost or stolen, an attacker would need both sets of credentials and access to both applications to gain full banking access, significantly reducing the vulnerability associated with device loss
Solution Approach 2:
The security application provides preliminary protective actions through features like lock banking functionality, which can be activated to prevent access to the banking application. This preliminary anti-action is taken in advance to counteract potential threats from device loss or theft, allowing users to remotely secure their banking access before actual compromise occurs
3Reliability
If additional security measures are implemented beyond traditional passwords, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The security application serves multiple functions within a single interface: it provides security credential authentication, enables lock banking functionality, and offers control over banking features. By consolidating these security-related functions into one universal application, the patent avoids the need for users to manage multiple separate security tools, thereby maintaining ease of operation while implementing comprehensive security measures
Data Source
AI summary
An illustrative apparatus includes a memory, a processor coupled to the memory, and a first set of instructions stored on the memory that can be executed by the processor. The processor is configured to determine authentication data, where the authentication data comprises an indication that a first functionality of a second set of instructions can be controlled and where the second set of instructions is separate from the first set of instructions. The processor is further configured to send to a user interface, an indication of the first functionality. The processor is further configured to receive, through the user interface, a request to control the first functionality of a second set of instructions that is separate from the first set of instructions. The processor is further configured to send an order to control the first functionality of the second set of instructions.


