Browser-Agent Device Trust Checks for Phishing-Resistant MFA
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional zero trust security technologies are vulnerable to attacks, particularly multi-factor authentication (MFA) solutions that can be easily phished, and there is a need for a robust, phishing-resistant mechanism to verify device trust and ensure compliance before granting access to enterprise resources.
Innovation Solution
A cloud-based zero trust architecture (ZTA) that uses a local agent and browser script to establish a secure communication channel, enabling device trust through cryptographic challenges and device telemetry, with a phishing-resistant possession-based factor within MFA, and provides user notifications and remediation for non-compliant devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If token or push-based possession-based factors are used in MFA, then authentication convenience is improved, but security against phishing attacks deteriorates
Solution Approach 1:
The patent introduces a phishing-resistant possession-based factor as an intermediary authentication mechanism that replaces vulnerable token/push-based factors. This new factor uses cryptographic challenges and responses that cannot be phished, while still maintaining user convenience through seamless integration into the MFA flow. The intermediary element (phishing-resistant factor) bridges the gap between security requirements and user experience.
Solution Approach 2:
The patent changes the fundamental parameters of possession-based authentication by transitioning from secret-based tokens to cryptographic challenge-response mechanisms. This parameter change transforms the authentication factor from something that can be phished (secret codes) to something that is mathematically resistant to phishing (cryptographic proofs of possession), while maintaining operational convenience.
2Reliability
If device telemetry collection is implemented for security posture validation, then security compliance is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements preliminary device telemetry collection and security posture validation before authentication is completed. By performing these checks in advance during the authentication flow, the system ensures security compliance without adding significant complexity to the core authentication mechanism. The device agent collects telemetry data and validates security posture beforehand, so that when authentication occurs, the compliance verification is already complete.
Solution Approach 2:
The patent employs a device agent that runs locally on the client device to self-collect telemetry data and perform security posture validation. This self-service approach reduces server-side complexity and automation requirements, as the device itself gathers and reports its security state information, rather than requiring complex centralized monitoring and data collection infrastructure.
Data Source
AI summary
A zero trust application enables access to a protected resource from a client device associated with a user. The client device has a browser, and an agent running locally and accessible via a local loopback interface. During an authentication flow, a browser-based script executes in the browser to deliver a challenge to the agent, and to collect a response to that challenge from the agent using a graphics file-based encoding scheme, and to deliver that information to the application for verifying the client device and its security posture. Depending on that security posture, the authentication flow may be permitted to complete. If a failure of the security posture is identified, the user may be permitted during the on-going authentication flow to address that failure and request a re-check of the posture.


