Standalone Browser Integrity Verification on Removable Media

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network systems face security issues such as identity theft, information leakage, and inaccurate auditing, particularly in the banking industry, due to vulnerabilities in untrusted host computers and insecure web browsing practices.

Innovation Solution

A secure data communication system utilizing a removable storage medium with a hardened, standalone browser that performs integrity checks and requires multi-factor authentication, including digital certificates and username/password combinations, to ensure secure communications and limit access to authorized servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional browser is used on an untrusted host computer, then ease of operation is maintained, but security and reliability deteriorate due to vulnerabilities and information leakage

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the browser into separate functional components (loader, browser executable, add-on programs) that are independently verified and loaded. This segmentation allows each component to be individually secured while maintaining overall system functionality, resolving the contradiction between security and complexity by organizing complexity into manageable, verifiable segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A read-only storage medium acts as an intermediary between the untrusted host computer and the browser components. This intermediary provides a secure isolation layer that protects the host system from browser vulnerabilities while enabling browser operation, thus improving security without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity checks are performed on all browser files, then security and reliability improve, but processing time and productivity worsen

Engineering Contradiction:
Improveintegrity verificationVSAvoidbrowser launch speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Integrity verification is performed in advance during the loader phase before the browser executes any operations. By conducting these checks preliminarily, the system ensures security without delaying actual browser functionality, as the verification occurs during the initialization phase rather than during ongoing operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The loader automatically performs integrity verification of its own files and the browser executable without requiring external intervention or manual verification steps. This self-service approach streamlines the security verification process, maintaining speed by eliminating redundant verification steps while ensuring reliability through automated checks.

Inventive Principle:
Principle #25Self-service

3Reliability

If multi-factor authentication is required, then security improves, but ease of operation and user convenience worsen

Engineering Contradiction:
Improveauthentication securityVSAvoiduser authentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system automatically handles multi-factor verification without requiring manual user intervention for each factor. The system self-manages the authentication process, presenting users with simplified login interfaces while automatically verifying multiple factors in the background, thus maintaining security without significantly impacting user convenience.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7624440B2Systems and methods for securely providing and/or accessing information
Publication Date: 2009.11.24 TRUSTATE INT
  • US7624440B2 patent drawing
  • US7624440B2 patent drawing
  • US7624440B2 patent drawing

AI summary

The invention is directed to a secure data communication system and method for use in connection with a potentially untrusted host computer. The system includes a storage medium that is connectable with the potentially untrusted host computer. The system also includes a hardened, stand alone, browser stored on the storage medium. The system can also include client authentication data and/or add-on program data. The browser can use the client authentication data to facilitate secure communications. The system can include has a loader that performs an integrity check of the browser and/or data files and launches the browser only if the browser and associated data files pass the integrity check. The client authentication data can be stored on the storage medium. The storage medium can be read-only, read-write or a combination thereof.