Personalized Network Access Program Encryption for Online Banking Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for online services, such as online banking, are vulnerable to manipulation and eavesdropping, particularly through 'man-in-the-browser' attacks, and existing solutions like 2-factor authentication increase costs significantly.

Innovation Solution

A method involving the generation of a data packet containing a hardened network access program and a personal authentication feature, encrypted with a unique personal key, ensuring the network access program can only be executed and authenticated by the personal authentication feature, thereby reducing the risk of manipulation and eliminating the need for additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 2-factor authentication with hardware components (smart cards, USB devices) is used, then security is improved, but costs increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcosts
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates individualized program copies for different user groups, where each copy contains embedded cryptographic keys and authentication features. Instead of requiring physical hardware tokens, the authentication capability is copied into software form that is distributed to users, eliminating hardware costs while maintaining security through personalized cryptographic protection

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical hardware system (smart cards, USB tokens) with a software-based cryptographic system. The authentication feature is implemented through embedded cryptographic keys and program code rather than physical hardware components, substituting mechanical authentication with electronic/cryptographic authentication

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If conventional internet browsers are used for online banking, then ease of operation is improved, but vulnerability to manipulation attacks increases

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the user base into different user groups and creates individualized program copies tailored to each group's security requirements. This segmentation allows standard browsers for general use while providing enhanced protected versions for security-critical operations, balancing ease of operation with security needs

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary protected program that sits between the user and the online banking service. This intermediary software with embedded cryptographic keys authenticates and protects communications, acting as a mediator that maintains ease of browser operation while adding security protection against manipulation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If individualized program copies with embedded cryptographic keys are created, then security against manipulation is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal framework for generating individualized program copies that can serve multiple user groups with different security requirements. The same underlying technology and process handles all user groups, making the system multi-functional while avoiding the need for completely separate solutions for each user type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2434424B1Method for increasing the security of security-relevant online services
Publication Date: 2014.06.11 KOBIL SYST
  • EP2434424B1 patent drawingFigure 1~2
  • EP2434424B1 patent drawingFigure 3

AI summary

The invention relates to a method for increasing the security of security-relevant online services. The method according to the invention comprises generating a data packet, which includes at least one network access program with a hardening function and at least one personal authentication feature, in a first data processing device, encrypting the data packet, and making the data packet available for transmission to a further data processing device, wherein the transmitted data packet can be decrypted with a personal key on the further data processing device, such that the network access program is executable and authenticable by the personal authentication feature. Furthermore, the invention relates to a computer program, a data storage device, a data processing device, a system, and a data packet.