Mobile Terminal Key Protection via Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In online banking, the lack of verification of the terminal device by the bank server during public key certificate transmission leads to potential interception and theft of user public key certificates, compromising security.

Innovation Solution

A key protection method where a mobile terminal generates and manages user public and private keys, with the mobile bank server and comprehensive pre-position bank server verifying the terminal's identity, and sending the public key to a third-party e-business verification server to generate and store a public key certificate, ensuring secure communication and protecting the private key through updated protection parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the bank server sends the user's public key certificate to the terminal without terminal verification, then the transmission process is simple and fast, but the security is compromised and the certificate may be intercepted or stolen

Engineering Contradiction:
Improvesecurity of public key certificate transmissionVSAvoidcomplexity of terminal verification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing terminal identity verification before the actual transmission of the public key certificate. The bank server verifies the terminal's identity (through device identifiers, installed applications, or other terminal characteristics) before sending the certificate, ensuring that only authorized terminals receive the certificate. This preliminary verification step prevents interception and theft while maintaining a relatively simple overall process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the bank server verifies terminal identity before sending the public key certificate, then the security is improved, but the verification process becomes more complex and time-consuming

Engineering Contradiction:
Improvesecurity of certificate transmissionVSAvoidtime for verification process
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification of terminal identity is performed as a preliminary action before the actual certificate transmission. By checking terminal characteristics (device identifiers, installed applications, etc.) in advance, the system ensures security without requiring complex real-time verification during the transmission process itself, thus minimizing time loss.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the private key is stored without updated protection parameters, then the storage process is simple, but the security of the private key is compromised

Engineering Contradiction:
Improvesecurity of private key storageVSAvoidcomplexity of key protection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by implementing an updated protection mechanism for the private key. Instead of using static protection, the system dynamically updates protection parameters (such as encryption keys or security policies) based on verification results and security requirements. This dynamic approach enhances security while maintaining manageable complexity through automated updates.

Inventive Principle:
Principle #15Dynamics

4Reliability

If the mobile bank server performs identity verification on the mobile terminal, then the safety of communication is secured and simulated terminals are prevented, but the verification process becomes more complex

Engineering Contradiction:
Improvesafety of communicationVSAvoidcomplexity of verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by having the mobile terminal provide its own identity information (device identifiers, installed applications, terminal characteristics) for verification. The bank server uses this self-provided information to verify authenticity, reducing the need for complex active verification mechanisms while maintaining high security. The terminal essentially verifies itself by presenting its unique characteristics.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9824353B2Key protection method and system
Publication Date: 2017.11.21 TENDYRON CORP
  • US9824353B2 patent drawing
  • US9824353B2 patent drawing
  • US9824353B2 patent drawing

AI summary

Proposed are a key protection method and system. The method comprises: a: receiving by a mobile terminal a registration instruction, generating a user's public key and private key, and sending the user's public key to a third-party e-business verification server, if the mobile terminal respectively passes identity verifications of the mobile bank server and a comprehensive pre-position bank server; b: performing a verification by the mobile bank server on user's trade information, and performing a trade by the comprehensive pre-position bank server if the verification is successful; c: generating by the mobile terminal an updated parameter for protecting a private key after the trade is performed, sending to the mobile bank server, receiving a successful updating result from the mobile bank server and encrypting and storing the user's private key. The present invention can increase the difficulty of an attack, and improve security.