Client-Side Security Indicator for Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web-based authentication techniques are vulnerable to attacks like man-in-the-middle attacks, where hackers intercept and modify messages between clients and servers, compromising user credentials and personal information.
Innovation Solution
A system and method for computer system authentication using a security indicator local to the client and unknown to the server, which includes a user interface module, consistency module, initiation module, authentication module, security indicator database, and indicator retrieval and presentation module, ensuring that the security indicator remains local and is not transmitted over the network, thus mitigating the risk of interception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If web-based authentication transmits security indicators over the network, then authentication can be performed, but the security indicator becomes vulnerable to man-in-the-middle attacks and interception
Solution Approach 1:
The patent extracts the security indicator from the network transmission path and keeps it local to the client device. The security indicator is stored in a secure storage mechanism on the client side and never transmitted over the network, eliminating the vulnerability to interception while maintaining authentication functionality.
Solution Approach 2:
The patent introduces a secure storage mechanism as an intermediary between the authentication module and the network. This intermediary holds the security indicator locally and provides it to authentication processes without exposing it to network transmission, thereby protecting against man-in-the-middle attacks.
2Object-affected harmful factors
If the security indicator is stored locally on the client, then interception attacks are prevented, but the system complexity increases with additional security modules
Solution Approach 1:
The patent merges the security indicator storage and retrieval functions directly into the existing authentication module. By combining these security functions with the authentication logic in a single integrated module, the system achieves local security indicator management without proportionally increasing overall system complexity.
Solution Approach 2:
The authentication module is designed to perform multiple functions: it handles network authentication protocols, manages local security indicator storage, and controls retrieval processes. This multi-functionality reduces the need for separate dedicated security components, thereby limiting complexity increase.
Data Source
AI summary
A method to authenticate a first computer system over a network to a second computer system is disclosed. A login user interface (UI) is presented to a user of the first computer system while disconnected from the second computer system. The login UI presents at least one input field to receive login input from the user and a security indicator that has been previously selected by the user and that is local to the first computer system. Login input is selectively received from the user based on a determination that the user recognizes the security indicator as having been previously selected by the user. A connection is established between the first computer system and the second computer system over the network. The received user input is transmitted using the established connection to the second computer system for authentication of the first computer system.


