Virtual Desktop Isolation for Secure Internet Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End users face significant risks when conducting electronic transactions due to vulnerabilities in using shared networks and unknown equipment, lack of user knowledge about security measures, and limitations of existing security solutions like OTPs and antivirus software, which are often ineffective against unknown viruses and require technical expertise.

Innovation Solution

A method that creates a virtual desktop or isolated execution environment using message listening techniques like hooking or Quartz to intercept messages between transaction applications and the OS, blocking malicious code execution and generating trash events to secure sensitive information exchange, without requiring special hardware or user configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users conduct transactions on shared networks or unknown equipment, then accessibility and convenience are improved, but security risk increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system creates a segmented virtual desktop environment that isolates transaction applications from the host operating system. This segmentation allows users to access transactions on any device while protecting the underlying system, resolving the contradiction between accessibility and security risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual desktop acts as an intermediary layer between the user application and the host OS. It intercepts and manages system calls, preventing direct access to sensitive system resources while maintaining application functionality, thus enabling secure transactions on shared networks and unknown equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If companies restrict users to known access scenarios, then security is improved, but versatility deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The virtual desktop environment provides universal security protection across multiple platforms and devices (Windows, macOS, Linux, mobile devices). It enables secure transaction access from any location or device type without requiring company-controlled infrastructure, thus improving both security and access flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system shifts security from the network/access point dimension to the application execution dimension. By creating a secure virtual environment within the application layer, it maintains security regardless of the access point or network used, resolving the contradiction between security and access flexibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If message listening techniques are implemented, then security against malware is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual desktop implementation library automatically manages the complexity of message interception and system call monitoring. It provides self-contained security functionality that works transparently without requiring users to configure or understand the underlying complex mechanisms, thus improving security while hiding system complexity.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If virtual desktop environment is created, then protection from spyware is improved, but resource consumption increases

Engineering Contradiction:
Improvespyware protectionVSAvoidresource consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The virtual desktop environment implements selective isolation - it creates full protection only when transaction applications are running, rather than maintaining constant isolation for all applications. This partial action approach provides spyware protection during critical operations while reducing overall resource consumption during normal system usage.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9369439B2Method for internet transactions
Publication Date: 2016.06.14 AZUAN TECH
  • US9369439B2 patent drawing
  • US9369439B2 patent drawing
  • US9369439B2 patent drawing

AI summary

The present invention consists of a computer security method that enables all users of a computer application to enjoy superior security levels when sensitive information is being exchanged with transaction applications. The method of the present invention consists of developing a virtual desktop or isolated execution environment that restricts the user to working in a specific zone. Said virtual desktop or isolated environment is programmed in such a way that message listening techniques such as hooking or quartz techniques are implanted for intercepting messages between the transaction application, such as the electronic bank, and the user's Operating System (OS). The method that is used in the present invention also blocks special key combinations in order to prevent malicious code execution in OS support devices, like Apple® IOS and Google™ Android, where special key combinations are not evident, but combinations such as “*#06#′ exist.