Authentication App Overlay Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for remote access to computer systems and applications are vulnerable to overlay attacks on multifunctional devices like smartphones, where malware can obscure the authentication window, making it difficult for users to detect fraudulent transactions.

Innovation Solution

The authentication application is adapted to detect and prevent overlay attacks by ensuring its window remains on top, entering a safe mode if obscured, or displaying a dynamic credential in a way that makes it impossible to hide, thus alerting the user to any anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the authentication application is displayed on a multifunctional device screen, then the device can be used for multiple purposes, but malware can create overlay windows to obscure the authentication window and deceive users

Engineering Contradiction:
Improvemultifunctional device usageVSAvoidoverlay attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing protective measures before the overlay attack can succeed. The system pre-establishes visual continuity between the authentication window and its background, and pre-defines security zones that will trigger alerts. When malware attempts to create an overlay window, the pre-configured visual continuity detection and security zone monitoring are already in place to detect and prevent the attack, rather than reacting after the overlay is created.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent converts the harmful overlay window into a detectable anomaly by using visual continuity detection. The system intentionally creates a visually distinctive background pattern that will be disrupted by any overlay window, whether malicious or not. This disruption becomes a beneficial detection signal that alerts the user to potential fraud, transforming the harmful overlay into a visible warning mechanism.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If the authentication window is made always visible and on top, then overlay attacks are prevented, but the device functionality and user interface flexibility are reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidinterface flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by creating security zones within the authentication window that have special properties. These zones are locally differentiated from the rest of the interface - they have specific visual characteristics and trigger specific responses when interacted with. The security zones are embedded only in the authentication context, allowing normal interface flexibility elsewhere while maintaining enhanced security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces visual continuity elements as an intermediary between the authentication window and its background. This intermediary layer maintains the visual relationship between the authentication interface and its surroundings, allowing the authentication window to remain integrated in the user interface while still providing security. The visual continuity acts as a mediator that detects disruptions without requiring the authentication window to be forcibly positioned above all other windows.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If visual continuity elements are added to the authentication window, then overlay attacks become detectable, but the interface complexity increases

Engineering Contradiction:
Improveoverlay attack detectionVSAvoidinterface complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent applies partial action by implementing visual continuity only in the specific areas where security is needed - the authentication window and its immediate background. Rather than applying complex security measures to the entire device interface, the system focuses visual continuity detection and security zones only on the authentication context, reducing overall interface complexity while maintaining effective overlay attack detection where it matters most.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3380977B1A multi-user strong authentication token
Publication Date: 2021.04.28 ONESPAN INT GMBH
  • EP3380977B1 patent drawingFigure 1
  • EP3380977B1 patent drawingFigure 2
  • EP3380977B1 patent drawingFigure 3

AI summary

Apparatus, methods and systems to secure remotely accessible applications using authentication devices are disclosed. More in particular apparatus, methods and systems are disciosed for thwarting overlay attacks against authentication applications for displaying transaction data and for generating signatures over these transaction data.