Virtual Desktop Isolation for Secure Internet Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
End users face significant risks when conducting electronic transactions due to vulnerabilities in using shared networks and unknown equipment, lack of user knowledge about security measures, and limitations of existing security solutions like OTPs and antivirus software, which are often ineffective against unknown viruses and require technical expertise.
Innovation Solution
A method that creates a virtual desktop or isolated execution environment using message listening techniques like hooking or Quartz to intercept messages between transaction applications and the OS, blocking malicious code execution and generating trash events to secure sensitive information exchange, without requiring special hardware or user configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users conduct transactions on shared networks or unknown equipment, then accessibility and convenience are improved, but security risk increases
Solution Approach 1:
The system creates a segmented virtual desktop environment that isolates transaction applications from the host operating system. This segmentation allows users to access transactions on any device while protecting the underlying system, resolving the contradiction between accessibility and security risk.
Solution Approach 2:
The virtual desktop acts as an intermediary layer between the user application and the host OS. It intercepts and manages system calls, preventing direct access to sensitive system resources while maintaining application functionality, thus enabling secure transactions on shared networks and unknown equipment.
2Reliability
If companies restrict users to known access scenarios, then security is improved, but versatility deteriorates
Solution Approach 1:
The virtual desktop environment provides universal security protection across multiple platforms and devices (Windows, macOS, Linux, mobile devices). It enables secure transaction access from any location or device type without requiring company-controlled infrastructure, thus improving both security and access flexibility.
Solution Approach 2:
The system shifts security from the network/access point dimension to the application execution dimension. By creating a secure virtual environment within the application layer, it maintains security regardless of the access point or network used, resolving the contradiction between security and access flexibility.
3Reliability
If message listening techniques are implemented, then security against malware is improved, but system complexity increases
Solution Approach 1:
The virtual desktop implementation library automatically manages the complexity of message interception and system call monitoring. It provides self-contained security functionality that works transparently without requiring users to configure or understand the underlying complex mechanisms, thus improving security while hiding system complexity.
4Object-affected harmful factors
If virtual desktop environment is created, then protection from spyware is improved, but resource consumption increases
Solution Approach 1:
The virtual desktop environment implements selective isolation - it creates full protection only when transaction applications are running, rather than maintaining constant isolation for all applications. This partial action approach provides spyware protection during critical operations while reducing overall resource consumption during normal system usage.
Data Source
AI summary
The present invention consists of a computer security method that enables all users of a computer application to enjoy superior security levels when sensitive information is being exchanged with transaction applications. The method of the present invention consists of developing a virtual desktop or isolated execution environment that restricts the user to working in a specific zone. Said virtual desktop or isolated environment is programmed in such a way that message listening techniques such as hooking or quartz techniques are implanted for intercepting messages between the transaction application, such as the electronic bank, and the user's Operating System (OS). The method that is used in the present invention also blocks special key combinations in order to prevent malicious code execution in OS support devices, like Apple® IOS and Google™ Android, where special key combinations are not evident, but combinations such as “*#06#′ exist.


