System and method for providing transactional security for an end-user device
Abstract
A network system comprises a transaction network operative to provide a transaction with an end user; a trusted source of a security mechanism (e.g., a start/stop trigger module, an application lockout module, a network/file I/O control module, a trusted driver manager, a keystrokes generator driver, a keystrokes deletion hook, and/or a transaction network VPN manager) for at least partially protecting an end-user device from malicious code operative thereon that attempts to capture confidential data presented during the transaction, the security mechanism being maintained by a party other than the end user; and an agent for providing the security mechanism to the end-user device to protect the end-user device during the transaction
Claims
exact text as granted — not AI-modified1 . A system comprising:
an end-user device including a browser and a security component capable of executing a security policy, the security policy to be downloaded from a website, and a website including a security policy downloadable to the security component.
2 . The system of claim 1 , wherein the security component downloads the security policy from the website upon connection to the website.
3 . The system of claim 1 , wherein the security component activates a security mechanism upon detection of a trigger point.
4 . The system of claim 3 , wherein the trigger point includes an explicit trigger point.
5 . The system of claim 4 , wherein the trigger point includes an implicit trigger point.
6 . The system of claim 1 , wherein the security component connects to the website via a point-to-point tunnel before downloading the security policy.
7 . The system of claim 1 , wherein the website includes an integrity checksum embedded in the website, and the security component includes a website integrity checker to use the integrity checksum to confirm that the website has not been modified during transport.
8 . The system of claim 1 , wherein the security policy identifies alias and affiliate servers where the browser may navigate without raising concern.
9 . A method comprising:
using a browser to navigate to a website, the website including a downloadable security policy; and using a security component to download the security policy from the website and to effect the security policy while navigating the website.
10 . The method of claim 9 , wherein the using eh security component to download the security policy from the website occurs upon connection to the website.
11 . The method of claim 9 , further comprising activating a security mechanism upon detection of a trigger point.
12 . The method of claim 11 , wherein the trigger point includes an explicit trigger point.
13 . The method of claim 12 , wherein the trigger point includes an implicit trigger point.
14 . The method of claim 9 , further comprising connecting to the website via a point-to-point tunnel before downloading the security policy.
15 . The method of claim 9 , wherein the website includes an integrity checksum embedded in the website, and further comprising using the integrity checksum to confirm that the website has not been modified during transport.
16 . The method of claim 9 , wherein the security policy identifies alias and affiliate servers where the browser may navigate without raising concern.
17 . A system comprising;
means for navigating to a website, the website including a downloadable security policy; means for downloading the security policy from the website; and means for effecting the security policy while navigating the website.Join the waitlist — get patent alerts
Track US2011209222A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.