Resetting Webpage Protocol for MITM-Resistant Data Confirmation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Email communication is inherently insecure, particularly vulnerable to man-in-the-middle (MITM) attacks, which can compromise sensitive information such as financial transactions, leading to identity theft and financial losses.
Innovation Solution
A resetting webpage protocol is implemented for secure data transfer, where login information is used to delineate read/write permissions, and any data changes trigger verification toggles, alerting all parties to unauthorized modifications, thereby preventing MITM attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If email is used for communication, then ease of operation is improved, but security is worsened due to vulnerability to MITM attacks
Solution Approach 1:
The patent introduces a webpage form as an intermediary between communicating parties. This form acts as a mediator that hosts sensitive information (such as wire transfer details) and requires mutual verification by both parties before confirmation. The intermediary structure prevents direct insecure email transmission while maintaining ease of operation through web-based access.
Solution Approach 2:
The patent implements a feedback mechanism where both communicating parties must independently verify and confirm the accuracy of information hosted on the webpage form. This mutual verification process provides feedback that detects potential MITM attacks, as any unauthorized modification would be detected during the verification stage, alerting the parties to the compromise.
2Reliability
If security measures are enhanced to prevent MITM attacks, then reliability is improved, but device complexity is worsened
Solution Approach 1:
The webpage form serves as a simple intermediary that leverages existing web infrastructure rather than requiring complex new security systems. By using a standard web form hosted on any server, the solution achieves enhanced security through process design rather than technological complexity.
Solution Approach 2:
The patent performs preliminary verification actions by requiring both parties to independently confirm information accuracy before final confirmation. This preliminary check prevents MITM attacks from succeeding, as any modifications would be detected before the transaction is finalized, simplifying the overall security approach by focusing on verification rather than complex encryption or authentication mechanisms.
Data Source
AI summary
A computer-implemented method for performing a bifurcated confirmation process via a resetting webpage form defending against Man-In-The-Middle attacks. An exemplary use case is that of municipal bond closing which is typically performed via large email lists and is subject to Man-In-The-Middle hijacking attacks. The process typically involves a large number of advisors and reviewing entities, any of one of which could become compromised and lead to substantial theft. A disclosed resetting webpage form flips the arrangement such that all of the computers would need to be compromised in order for the attack to be successful. The webpage form further includes verification of data where the multiple parties independently log onto the online platform and indicate validation of the data wherein any change in the data causes all validation indications to become reset, restarting the process.


