Secured Online Transactions via Prioritized SMS Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Dual-step authentication methods in online transactions are vulnerable to malicious software that can intercept transaction authentication messages, compromising user security and allowing fraudulent transactions.

Innovation Solution

A security application on mobile communication devices prioritizes processing of SMS text messages, identifies transaction authentication messages, and isolates them within a secured environment to prevent interception by malicious applications, ensuring user interaction occurs safely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dual-step authentication is implemented with SMS messages, then transaction security is improved, but vulnerability to malicious software increases

Engineering Contradiction:
Improvetransaction securityVSAvoidmalicious software interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security application is configured to intercept and process SMS messages before other applications can access them. By establishing prioritized access rights in advance, the system prevents malicious software from intercepting authentication messages, thus resolving the contradiction between maintaining security and preventing harmful factors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A dedicated security application acts as an intermediary between the SMS message delivery system and other applications. This intermediary component with prioritized access rights ensures that authentication messages are processed securely before reaching potential malicious software, thereby maintaining transaction security while blocking harmful interception.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security application has prioritized access to SMS messages, then protection against malicious software is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against malicious softwareVSAvoidapplication access management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system establishes prioritized access rights for the security application in advance, before any SMS messages are received. This preliminary configuration simplifies the runtime behavior by pre-determining the processing sequence, thereby providing strong protection against malicious software without introducing complex dynamic access management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If transaction authentication messages are isolated in secured environment, then security against interception is improved, but ease of operation decreases

Engineering Contradiction:
Improvesecurity against interceptionVSAvoiduser interaction with authentication messages
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security application serves as an intermediary that isolates authentication messages in a secured environment while maintaining a simplified user interface. This mediator handles the complex security isolation mechanisms transparently, presenting users with straightforward interaction protocols and thus maintaining ease of operation despite the enhanced security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9626676B2Secured online transactions
Publication Date: 2017.04.18 RPX CORP
  • US9626676B2 patent drawing
  • US9626676B2 patent drawing
  • US9626676B2 patent drawing

AI summary

A method, apparatus, and computer program for improving security in connection with online transactions are provided. A security application configured to monitor received text messages of a short message service is executed in an apparatus. The security application is arranged to have prioritized access to process the received text messages before other applications executed in the apparatus, to identify from contents of a received text message whether or not the received text message includes a transaction authentication message and, upon detecting that the received text message includes the transaction authentication message, prevent the processing of the transaction authentication message by the other applications and carry out user interfacing related to the transaction authentication message within a secured environment provided by the security application.