Secure In-Line Payments via RIA Runtime Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure financial transactions through rich Internet applications (RIAs) on mobile devices lack secure in-line payment capabilities, as they redirect users to external service providers for authentication, exposing them to phishing and man-in-the-middle attacks without standard validation mechanisms for app legitimacy.
Innovation Solution
Implementing a payment library on the user's device that communicates with the RIA runtime to authenticate the application and user, using oblivious hashing and out-of-band confirmations to ensure app validity and prevent attacks, while providing secure in-line payment functionalities within the RIA framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users are redirected to external service providers for authentication, then payment processing can be performed, but users are exposed to phishing and man-in-the-middle attacks without standard validation mechanisms
Solution Approach 1:
The patent introduces an intermediary validation mechanism where the RIA runtime acts as a mediator between the user and the payment transaction. The runtime validates the legitimacy of the RIA and the transaction before allowing payment processing, creating a secure intermediary layer that prevents direct exposure to phishing and man-in-the-middle attacks while still enabling payment processing to occur.
2Reliability
If standard validation mechanisms are implemented for app legitimacy, then security against attacks is improved, but the complexity of the payment system increases
Solution Approach 1:
The patent merges the validation functionality directly into the RIA runtime framework itself, combining the security validation mechanisms with the existing runtime infrastructure. This integration approach allows validation of app legitimacy to be performed as an inherent part of the runtime operation, reducing the need for separate complex validation systems while maintaining strong security against phishing and man-in-the-middle attacks.
3Ease of operation
If in-line payment capabilities are provided within RIA framework, then user experience is improved, but secure authentication becomes more difficult to implement
Solution Approach 1:
The patent implements preliminary authentication and validation actions performed by the RIA runtime before the in-line payment process begins. The runtime预先 validates the legitimacy of the RIA and establishes secure authentication credentials in advance, enabling smooth in-line payment capabilities while maintaining strong authentication security through these preliminary security measures.
Data Source
AI summary
Methods and systems are provided for making secure financial transactions, such as purchase payments, using rich Internet applications (RIA) running an RIA runtime (also referred to as a platform or framework) on the user's smart phone or other mobile device. Embodiments differ from the usual way of re-directing a user from a third-party application and authenticating the user by providing secure in-line payments from a rich Internet application running on an RIA runtime. A system includes: a mobile device executing a rich Internet application running on an RIA runtime; a payment library communicating with the RIA runtime and a service provider, for which the payment library communicates with the service provider to authenticate the rich Internet application; and in response to authentication by the service provider, facilitates secure financial transactions via the rich Internet application.


