Assertion Provider Token Security Component for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online threats such as phishing and man-in-the-middle attacks compromise user authentication, leading to unauthorized access and data breaches, as existing security measures fail to ensure robust identity verification across all online platforms.

Innovation Solution

A security component is integrated into network-enabled applications, which displays a user-customized embedded region for authentication, utilizing an assertion provider to verify credentials and issue a signed assertion token, ensuring mutual authentication and secure data exchange between the client and relying parties without transmitting sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then users can access online services, but users are vulnerable to phishing and man-in-the-middle attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidphishing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security component as an intermediary between the user and the relying party. This component displays a trusted embedded region with authentication information directly from the relying party, preventing phishing attacks by ensuring users authenticate with the actual service provider rather than a counterfeit site. The embedded region acts as a mediator that verifies the authenticity of the communication channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by displaying authentication information and security indicators before the user enters credentials. The embedded region is populated with trusted content from the relying party in advance, allowing users to verify the site's authenticity before submitting sensitive information, thus preventing man-in-the-middle attacks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication information is transmitted to verify identity, then users can be authenticated, but sensitive information may be compromised

Engineering Contradiction:
Improveidentity verificationVSAvoidsensitive information compromise
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by creating a restricted, secure embedded region within the web page that displays only authenticated content from the relying party. This localized trusted area ensures that authentication information is displayed only in verified contexts, preventing credential theft while maintaining identity verification capabilities.

Inventive Principle:
Principle #3Local quality

3Reliability

If security measures are implemented to prevent attacks, then authentication security is improved, but user interface complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoiduser interface complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functionality directly into the existing web page display by embedding authenticated content within the page itself. Rather than adding separate security interfaces or pop-ups, the security component integrates authentication indicators and trusted content directly into the page layout, maintaining a simple user interface while providing robust security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8555078B2Relying party specifiable format for assertion provider token
Publication Date: 2013.10.08 ADOBE INC
  • US8555078B2 patent drawing
  • US8555078B2 patent drawing
  • US8555078B2 patent drawing

AI summary

A security component may be associated with a network-enabled application. The network-enabled application may request access to restricted content from a relying party (e.g., web site). The security component associated with the network-enabled application may receive authentication policy information from the relying party and send a user's authentication credentials to an assertion provider to authenticate the credentials. The relying party may trust the assertion provider to authenticate user credentials. Upon successful authentication, the assertion provider may return an assertion token to the security component and the security component may sign the assertion token as specified in the authentication policy information. Subsequently, the security token may forward the signed assertion token to the relying party and the relying party may grant access to the restricted content.