Authentication App Overlay Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security solutions for remote access to computer systems and applications are vulnerable to overlay attacks on multifunctional devices like smartphones, where malware can obscure the authentication window, making it difficult for users to detect fraudulent transactions.
Innovation Solution
The authentication application is adapted to detect and prevent overlay attacks by ensuring its window remains on top, entering a safe mode if obscured, or displaying a dynamic credential in a way that makes it impossible to hide, thus alerting the user to any anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the authentication application is displayed on a multifunctional device screen, then the device can be used for multiple purposes, but malware can create overlay windows to obscure the authentication window and deceive users
Solution Approach 1:
The patent applies preliminary anti-action by implementing protective measures before the overlay attack can succeed. The system pre-establishes visual continuity between the authentication window and its background, and pre-defines security zones that will trigger alerts. When malware attempts to create an overlay window, the pre-configured visual continuity detection and security zone monitoring are already in place to detect and prevent the attack, rather than reacting after the overlay is created.
Solution Approach 2:
The patent converts the harmful overlay window into a detectable anomaly by using visual continuity detection. The system intentionally creates a visually distinctive background pattern that will be disrupted by any overlay window, whether malicious or not. This disruption becomes a beneficial detection signal that alerts the user to potential fraud, transforming the harmful overlay into a visible warning mechanism.
2Reliability
If the authentication window is made always visible and on top, then overlay attacks are prevented, but the device functionality and user interface flexibility are reduced
Solution Approach 1:
The patent applies local quality by creating security zones within the authentication window that have special properties. These zones are locally differentiated from the rest of the interface - they have specific visual characteristics and trigger specific responses when interacted with. The security zones are embedded only in the authentication context, allowing normal interface flexibility elsewhere while maintaining enhanced security where needed.
Solution Approach 2:
The patent introduces visual continuity elements as an intermediary between the authentication window and its background. This intermediary layer maintains the visual relationship between the authentication interface and its surroundings, allowing the authentication window to remain integrated in the user interface while still providing security. The visual continuity acts as a mediator that detects disruptions without requiring the authentication window to be forcibly positioned above all other windows.
3Difficulty of detecting and measuring
If visual continuity elements are added to the authentication window, then overlay attacks become detectable, but the interface complexity increases
Solution Approach 1:
The patent applies partial action by implementing visual continuity only in the specific areas where security is needed - the authentication window and its immediate background. Rather than applying complex security measures to the entire device interface, the system focuses visual continuity detection and security zones only on the authentication context, reducing overall interface complexity while maintaining effective overlay attack detection where it matters most.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Apparatus, methods and systems to secure remotely accessible applications using authentication devices are disclosed. More in particular apparatus, methods and systems are disciosed for thwarting overlay attacks against authentication applications for displaying transaction data and for generating signatures over these transaction data.