Cross-Device App State Verification for Transaction Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) systems are vulnerable to attacks such as dictionary attacks and SIM swapping, as they rely on traditional methods that are easily replicable by nefarious users, failing to provide robust security against unauthorized access and fraud.
Innovation Solution
An authentication system that checks the state of one or more applications on a user's device, requiring them to be in specific states or transition within a specified period, using standardized and custom APIs to ensure compatibility and security, and incorporating contextual factors to adapt authentication requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional single-factor authentication methods (passwords or PINS) are used, then the system is easy to operate, but the security against sophisticated cyber threats is insufficient
Solution Approach 1:
The authentication process is segmented into multiple independent verification steps: checking the first application's state, verifying the second application's state, and confirming state transitions. Each segment provides a separate layer of security that must be satisfied independently, making the overall system more robust while maintaining operational clarity through structured verification steps.
Solution Approach 2:
The system performs preliminary verification of application states and state transitions before allowing the transaction to proceed. By checking whether applications are in expected states and whether required state transitions have occurred prior to transaction completion, the system prevents unauthorized access before it can execute, rather than reacting after a breach.
2Reliability
If multi-factor authentication systems are implemented, then security is enhanced, but the system becomes vulnerable to attacks like dictionary attacks and SIM swapping
Solution Approach 1:
The patent introduces application state information as an intermediary verification layer between the user and the transaction system. Instead of directly relying on traditional MFA factors that can be compromised, the system uses the state of applications (which act as intermediaries) to verify authentication. This intermediary layer makes it harder for attackers to bypass security, as they would need to compromise multiple application states simultaneously rather than just traditional credentials.
Solution Approach 2:
The system dynamically changes authentication parameters by requiring specific application states and state transitions rather than static credentials. The authentication requirements adapt based on the current state of applications, making it more difficult for attackers to use predetermined attack vectors like dictionary attacks or SIM swapping, as the verification criteria are not fixed but depend on real-time application states.
3Reliability
If application state verification is required for authentication, then a personalized security layer is provided, but the device complexity increases
Solution Approach 1:
The patent leverages existing applications that users already have installed on their devices, making these applications serve dual purposes: their original function plus authentication verification. By using applications the user already possesses and interacts with regularly, the system avoids adding specialized hardware or complex new software components, thereby reducing overall device complexity while maintaining strong security.
Data Source
AI summary
Methods, systems, and machine-readable mediums that enhance transaction authentication of a transaction of a first application by checking that a state of one or more other applications matches prespecified states or that one or more of those applications transition states within a prespecified period of time. For example, the prespecified states may correspond to the application being installed on a specified device (e.g., of the user) and having an authenticated session with a specified user.


