Cross-Device App State Verification for Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) systems are vulnerable to attacks such as dictionary attacks and SIM swapping, as they rely on traditional methods that are easily replicable by nefarious users, failing to provide robust security against unauthorized access and fraud.

Innovation Solution

An authentication system that checks the state of one or more applications on a user's device, requiring them to be in specific states or transition within a specified period, using standardized and custom APIs to ensure compatibility and security, and incorporating contextual factors to adapt authentication requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional single-factor authentication methods (passwords or PINS) are used, then the system is easy to operate, but the security against sophisticated cyber threats is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication process is segmented into multiple independent verification steps: checking the first application's state, verifying the second application's state, and confirming state transitions. Each segment provides a separate layer of security that must be satisfied independently, making the overall system more robust while maintaining operational clarity through structured verification steps.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary verification of application states and state transitions before allowing the transaction to proceed. By checking whether applications are in expected states and whether required state transitions have occurred prior to transaction completion, the system prevents unauthorized access before it can execute, rather than reacting after a breach.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-factor authentication systems are implemented, then security is enhanced, but the system becomes vulnerable to attacks like dictionary attacks and SIM swapping

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces application state information as an intermediary verification layer between the user and the transaction system. Instead of directly relying on traditional MFA factors that can be compromised, the system uses the state of applications (which act as intermediaries) to verify authentication. This intermediary layer makes it harder for attackers to bypass security, as they would need to compromise multiple application states simultaneously rather than just traditional credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes authentication parameters by requiring specific application states and state transitions rather than static credentials. The authentication requirements adapt based on the current state of applications, making it more difficult for attackers to use predetermined attack vectors like dictionary attacks or SIM swapping, as the verification criteria are not fixed but depend on real-time application states.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If application state verification is required for authentication, then a personalized security layer is provided, but the device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing applications that users already have installed on their devices, making these applications serve dual purposes: their original function plus authentication verification. By using applications the user already possesses and interacts with regularly, the system avoids adding specialized hardware or complex new software components, thereby reducing overall device complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250371545A1App profile verification across computing devices using transaction context
Publication Date: 2025.12.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250371545A1 patent drawing
  • US20250371545A1 patent drawing
  • US20250371545A1 patent drawing

AI summary

Methods, systems, and machine-readable mediums that enhance transaction authentication of a transaction of a first application by checking that a state of one or more other applications matches prespecified states or that one or more of those applications transition states within a prespecified period of time. For example, the prespecified states may correspond to the application being installed on a specified device (e.g., of the user) and having an authenticated session with a specified user.