Counter Challenge Authentication for Phishing Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for preventing phishing attacks are either socially complex, require user education, or involve costly hardware and software solutions, lacking a simple, technical, and computer-independent approach.

Innovation Solution

The counter challenge authentication mechanism, where users pose challenges through a web page with input elements, and the web application responds with corresponding information, ensuring only genuine applications can authenticate correctly, thus protecting against phishing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user education guidelines are provided, then phishing awareness is improved, but implementation complexity and user burden increase

Engineering Contradiction:
Improvephishing awarenessVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically performs phishing detection without requiring user education or manual verification. The counter challenge mechanism self-verifies authentication by comparing challenges against stored user data, eliminating the need for users to learn complex security guidelines while maintaining high phishing awareness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical approach of user education and manual verification with an automated technical system. The counter challenge authentication mechanism uses programmatic comparison of challenges against stored data, substituting human learning processes with automated computational verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware tokens or smart cards are used, then authentication security is improved, but cost and device requirements increase

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a virtual copy of authentication data stored in the server database, eliminating the need for physical hardware tokens. The counter challenge mechanism uses copied data from the database to verify authentication, providing security without requiring users to possess expensive hardware devices.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces physical hardware authentication mechanisms with a software-based counter challenge system. Instead of requiring users to present physical tokens, the system uses computational challenges and database comparisons, substituting mechanical hardware requirements with digital verification processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Difficulty of detecting and measuring

If domain name monitoring services are implemented, then phishing detection capability is improved, but response time and system complexity increase

Engineering Contradiction:
Improvephishing detection capabilityVSAvoidresponse time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-storing user data and authentication challenges in the database before phishing attacks occur. The counter challenge mechanism uses this pre-prepared data to immediately detect and prevent phishing attempts, eliminating the need for post-attack analysis and reducing response time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements real-time feedback by immediately comparing user-submitted challenges against stored data and providing instant verification results. This feedback mechanism allows the system to detect phishing attempts as they occur, providing both high detection capability and rapid response without requiring complex monitoring services.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10880331B2Defeating solution to phishing attacks through counter challenge authentication
Publication Date: 2020.12.29 SHAIK CHEMAN
  • US10880331B2 patent drawing
  • US10880331B2 patent drawing
  • US10880331B2 patent drawing

AI summary

A counter challenge authentication system and method is provided for authentication of online users of web applications. The authentication method involves a counter challenge from a user to a web application asking to provide certain information from one or more user details recorded at the time of registration. The user enters his password and logs into the web application only in case he receives the correct answer from the web application. This advanced authentication method protects online application users from phishing attacks. An incorrect answer to the user's challenge or inability of the web application to provide an answer to the challenge is a clear indication of a phishing attack, thereby alerting the user and stopping him from submitting his sensitive password information to phishers. The authentication method is computer independent and eliminates dependency on two-factor authentication, hardware tokens, client software installations, digital certificates, and user defined seals.