WAP Gateway Security Verification for Mobile Banking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing wireless access protocol (WAP) 1.x systems lack true end-to-end security, leading to a 'WAP gap' where data integrity is compromised, especially in mobile banking communications, as users may unknowingly use insecure channels, especially when roaming or using outdated devices.
Innovation Solution
A system and method to determine whether communication from a wireless device to a remote computer is end-to-end secure by identifying and verifying user agent headers, IP addresses, and gateway compliance using a list of approved identifiers stored in a computer data file, ensuring secure communication channels are used before allowing access to sensitive services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If WAP 1.x protocol is used for mobile device communication, then compatibility with existing devices is maintained, but end-to-end security is compromised due to the WAP gap
Solution Approach 1:
The patent introduces a WAP gateway as an intermediary component that bridges WAP 1.x mobile devices and HTTP web servers. The gateway performs protocol conversion while implementing security measures to mitigate the WAP gap vulnerability, acting as a mediator between incompatible systems with different security requirements
Solution Approach 2:
The system performs preliminary security verification by checking whether the WAP gateway supports end-to-end security capabilities before allowing communication. This preliminary check prevents insecure connections from being established, addressing the security concern before data transmission occurs
2Adaptability or versatility
If WAP gateway protocol conversion is implemented, then communication between mobile devices and web servers is enabled, but security integrity is compromised during decryption and re-encryption
Solution Approach 1:
The WAP gateway serves as a controlled intermediary that manages protocol conversion between WAP 1.x and HTTP. By implementing security checks and using approved gateways with proper SSL/TLS termination, the system enables necessary protocol conversion while minimizing security exposure during the decryption and re-encryption process
Solution Approach 2:
The system implements feedback mechanisms where the server verifies whether the WAP gateway supports end-to-end security capabilities. Based on this feedback, the system either establishes secure connections through approved gateways or blocks connections from insecure gateways, creating a closed-loop security verification system
3Ease of operation
If users are not informed about security status, then system operation is simple, but users unknowingly use insecure communication channels
Solution Approach 1:
The system provides feedback to users about the security status of their communication channel. The server determines whether the WAP gateway supports end-to-end security and communicates this information back to the user, enabling informed decision-making without complicating the overall system operation
Solution Approach 2:
The system uses visual indicators (such as color-coded security status displays) to communicate security information to users in an intuitive manner. This allows users to quickly understand the security status of their connection without requiring technical knowledge, maintaining ease of operation while improving security awareness
Data Source
AI summary
Systems and methods are disclosed for identifying circumstances where end-to-end security is not available to a mobile banking customer. The user may be alerted/warned or restricted from accessing some banking services through his/her WAP-enabled mobile device if the server (e.g., bank server) determines that end-to-end security is not available. In some instances, the bank server may access a computer data file containing a list of known end-to-end secure devices and gateways to verify the integrity of the data communication. The server may verify the integrity of the data communication using loose matching.


