Browser Extension Authentication With Mobile Device Phishing Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) systems are vulnerable to man-in-the-middle attacks where a malicious actor creates a duplicate website to trick users into logging in, allowing access to protected resources.
Innovation Solution
A browser extension and a registered mobile device are used together to authenticate users, requiring a public/private key pair and additional verification steps such as scanning a QR code and entering a PIN, ensuring only authorized users can initiate logins, and using dynamic session identifiers to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional MFA systems are used, then user authentication is provided, but the system is vulnerable to phishing attacks where malicious websites can intercept login assertions
Solution Approach 1:
The patent introduces a trusted intermediary component (the browser extension from a verified publisher) that mediates between the user's credentials and the authentication system. This intermediary verifies the legitimacy of the login page by checking publisher trust relationships, preventing phishing attacks where malicious sites attempt to intercept credentials. The intermediary acts as a gatekeeper that validates the authenticity of the authentication context before allowing login proceeds.
Solution Approach 2:
The system performs preliminary verification of the login page's authenticity before the user enters credentials. The browser extension checks the publisher's trust status and verifies the authentication context in advance, displaying indicators to the user about the page's legitimacy. This preliminary action prevents users from inadvertently submitting credentials to phishing sites, as the verification occurs before any sensitive information is entered.
2Object-affected harmful factors
If a browser extension is added to enhance security against phishing, then phishing attack resistance is improved, but device complexity increases
Solution Approach 1:
The browser extension is designed to be multi-functional, serving both as a security mechanism against phishing and as a general authentication assistant. It provides publisher verification, authentication context validation, and user interface guidance all through a single extension component. This universality reduces the need for multiple separate tools or complex configurations, as one extension handles multiple security and authentication functions.
Solution Approach 2:
The extension automatically performs verification of login page authenticity and authentication context without requiring manual user configuration. It self-manages the trust verification process by checking publisher relationships and validating authentication flows, providing security enhancements while maintaining ease of use. The system serves itself by automatically detecting and responding to phishing attempts without user intervention.
Data Source
AI summary
Systems and methods include features to eliminate or reduce man-in-the middle vulnerability of an authentication process. The systems and methods to login to a protected resource may require two registered devices in the system before the method to authenticate a user is performed. The systems and methods may include any combination of: registration of a browser extension; allow regular login directly to a provider if the extension is not installed, but requiring use of a login through the extension if the extension is installed; require use of an extension for an application, customer, account, or other criteria and not permit login without the extension; allow direct login if authorized through a separate application (whether or not login through a browser is required through a different device); permit administrative approval of an extension and granular controls of the systems and methods described herein permitting selection of features and requirements.


