Browser Plugin Authentication Intermediary for Secure Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online authentication methods are vulnerable to data interception by malicious programs, particularly during online transactions, as they may not effectively detect new modifications of malicious software or provide robust protection against interception of one-time passwords.
Innovation Solution
A system and method for secure online authentication that involves determining a connection between a browser application and a protected website, establishing a protected data transmission channel, obtaining and verifying certificates, and using a second authentication factor to ensure secure access, utilizing a plugin and driver to intercept and validate network traffic and certificates, and storing encrypted data for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standard browser applications are used for online transactions, then ease of operation is improved, but security against data interception deteriorates
Solution Approach 1:
The patent introduces a plugin as an intermediary component between the browser application and the protected website. This plugin establishes a protected data transmission channel that intercepts and encrypts authentication data before it leaves the browser, preventing malicious programs from intercepting the data while maintaining the ease of using standard browsers.
Solution Approach 2:
The patent segments the authentication process into multiple components: the browser application handles user interaction, the plugin manages secure data transmission and certificate verification, and the protected website receives authentication. This segmentation allows each component to specialize in its function while maintaining overall security.
2Reliability
If antivirus technologies are used to detect malicious programs, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by establishing a protected data transmission channel before authentication data is transmitted. The plugin proactively sets up encryption and certificate verification mechanisms in advance, so that when authentication data needs to be sent, it is already protected. This prevents the need for complex real-time detection of malicious programs.
3Reliability
If one-time password (OTP) authentication is used, then security is improved, but vulnerability to interception by malicious programs increases
Solution Approach 1:
The patent uses the plugin as an intermediary that captures authentication data directly from the browser's memory or data entry fields before it can be intercepted by malicious programs. The plugin then transmits this data through an encrypted protected channel, making it inaccessible to keyloggers, screen capture tools, or network sniffers that might intercept OTPs.
Solution Approach 2:
The patent replaces the mechanical system of OTP transmission through standard channels (which are vulnerable to interception) with a software-based protected transmission channel that uses encryption and certificate verification. This substitution eliminates the vulnerability to traditional interception methods while maintaining OTP authentication security.
Data Source
AI summary
Disclosed is a methods for secure online authentication comprising determining, by a secure device, that a connection is being established between a browser and a protected website by analyzing web requests from the browser, obtaining information for the protected website when a request for authentication is received from the protected website, establishing a protected data transmission channel between the secure device and the protected website, receiving one or more authentication certificates from the protected website, verifying validity of the one or more authentication certificates, performing authentication and transmitting, from the device, authentication data stored on the device to the protected website, transmitting a new session identifier from the device to the browser for enabling access to the protected website and requesting that the browser dispatch the new session identifier to the protected website in response to the connection being established via the web requests.


