Browser Extension Authentication With Mobile Device Phishing Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication (MFA) systems are vulnerable to man-in-the-middle attacks where a malicious actor creates a duplicate website to trick users into logging in, allowing access to protected resources.

Innovation Solution

A browser extension and a registered mobile device are used together to authenticate users, requiring a public/private key pair and additional verification steps such as scanning a QR code and entering a PIN, ensuring only authorized users can initiate logins, and using dynamic session identifiers to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional MFA systems are used, then user authentication is provided, but the system is vulnerable to phishing attacks where malicious websites can intercept login assertions

Engineering Contradiction:
Improveauthentication securityVSAvoidphishing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted intermediary component (the browser extension from a verified publisher) that mediates between the user's credentials and the authentication system. This intermediary verifies the legitimacy of the login page by checking publisher trust relationships, preventing phishing attacks where malicious sites attempt to intercept credentials. The intermediary acts as a gatekeeper that validates the authenticity of the authentication context before allowing login proceeds.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification of the login page's authenticity before the user enters credentials. The browser extension checks the publisher's trust status and verifies the authentication context in advance, displaying indicators to the user about the page's legitimacy. This preliminary action prevents users from inadvertently submitting credentials to phishing sites, as the verification occurs before any sensitive information is entered.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If a browser extension is added to enhance security against phishing, then phishing attack resistance is improved, but device complexity increases

Engineering Contradiction:
Improvephishing attack resistanceVSAvoidbrowser extension requirements
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The browser extension is designed to be multi-functional, serving both as a security mechanism against phishing and as a general authentication assistant. It provides publisher verification, authentication context validation, and user interface guidance all through a single extension component. This universality reduces the need for multiple separate tools or complex configurations, as one extension handles multiple security and authentication functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The extension automatically performs verification of login page authenticity and authentication context without requiring manual user configuration. It self-manages the trust verification process by checking publisher relationships and validating authentication flows, providing security enhancements while maintaining ease of use. The system serves itself by automatically detecting and responding to phishing attempts without user intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250254028A1Authentication System and Method Using Browser Extension
Publication Date: 2025.08.07 TRAITWARE INC
  • US20250254028A1 patent drawing
  • US20250254028A1 patent drawing
  • US20250254028A1 patent drawing

AI summary

Systems and methods include features to eliminate or reduce man-in-the middle vulnerability of an authentication process. The systems and methods to login to a protected resource may require two registered devices in the system before the method to authenticate a user is performed. The systems and methods may include any combination of: registration of a browser extension; allow regular login directly to a provider if the extension is not installed, but requiring use of a login through the extension if the extension is installed; require use of an extension for an application, customer, account, or other criteria and not permit login without the extension; allow direct login if authorized through a separate application (whether or not login through a browser is required through a different device); permit administrative approval of an extension and granular controls of the systems and methods described herein permitting selection of features and requirements.