Safe Input Browser Whitelist and Encryption for Phishing Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Internet transactions face significant security threats such as phishing, pharming, data theft, and denial of service (DOS) attacks, which compromise user information and hinder smooth network transactions.
Innovation Solution
A safe input browser that connects to a preset website via a VPN or private line network, featuring an unchangeable address and a built-in encrypting keyboard module to encrypt user data, preventing keyboard capturing and side-recording, and bypassing DNS and Proxy servers to avoid redirection to fake sites.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a browser allows users to access any website through standard DNS resolution, then ease of operation is improved, but security against phishing and pharming attacks deteriorates
Solution Approach 1:
The patent pre-configures the browser with a whitelist of authorized website addresses and domains before the user needs to access them. This preliminary action prevents the browser from resolving URLs that are not on the approved list, thereby blocking phishing and pharming attempts before they can execute. The browser is prepared in advance with knowledge of legitimate sites, eliminating the need for real-time DNS resolution for untrusted sites.
Solution Approach 2:
The patent introduces a safe input browser as an intermediary layer between the user and the internet. This browser acts as a mediator that intercepts and controls all website access requests, checking them against the pre-configured whitelist before allowing connection. The intermediary browser prevents direct access to potentially malicious sites while still providing convenient access to legitimate sites through the approved list.
2Ease of operation
If user data is transmitted through standard internet channels, then ease of operation is improved, but security against data theft and keyboard capturing deteriorates
Solution Approach 1:
The patent introduces an encrypting keyboard module as an intermediary between the physical keyboard and the computer system. This intermediary module intercepts all keystrokes at the hardware level and encrypts them before they reach the operating system or application. The encrypting keyboard acts as a secure mediator that prevents keyboard capturing attacks while maintaining seamless operation for legitimate users.
Solution Approach 2:
The patent applies encryption specifically to the keyboard input interface rather than encrypting all data transmission throughout the system. This localized approach focuses security resources on the most vulnerable point (keyboard input) where sensitive information like passwords is entered, providing targeted protection without compromising overall system performance or ease of operation.
3Adaptability or versatility
If the browser uses DNS and Proxy servers for website resolution, then adaptability to different websites is improved, but vulnerability to pharming attacks and side-recording deteriorates
Solution Approach 1:
The patent extracts and removes the browser's dependence on external DNS and Proxy servers for website resolution. By taking out this external dependency, the system eliminates the attack vectors that pharming attacks exploit. The browser instead resolves websites through its own pre-configured whitelist, isolating the resolution process from external manipulation and side-recording threats.
Solution Approach 2:
The patent pre-configures all necessary website resolution information within the browser before the user needs to access any site. This preliminary action creates a self-contained resolution system that does not require external DNS or Proxy servers during operation. The browser has all the information it needs built-in, eliminating real-time external communication that could be intercepted or manipulated by attackers.
4Reliability
If flow cleaning service is used to protect against DOS attacks, then reliability is improved, but cost increases
Solution Approach 1:
The patent implements self-service security measures within the browser that protect against DOS attacks without requiring external flow cleaning services. The browser uses its pre-configured whitelist to automatically filter and block malicious traffic patterns, performing security functions independently. This self-service approach eliminates the need to pay for expensive external security services while maintaining protection against DOS attacks.
Data Source
AI summary
The disclosure provides a safe input browser, an operation method thereof, and a computer system having the safe input browser. Upon receiving a command for activating the safe input browser, the pointed site of a specific website is guided to the safe input browser to be linked thereto, so that only web pages of the specific site liked thereto will be shown. Accordingly, users can logon into their frequently used and visited network services to prevent incidents of data theft. Further, the safe input browser supports keyboard inputs with the security encryption function to prevent data from being hacked and side-recorded. It can be further connected to specific sites by a virtual personal network (VPN) or a private line network to prevent attacks of denial of service (DOS) or distributed denial of service (DDOS), thereby facilitating convenience and safety of network transactions.


