Cross-Device App Profile Verification Against MFA Account Takeover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) systems are vulnerable to attacks such as dictionary attacks and SIM swapping, which compromise the security of user accounts by intercepting One Time Passcodes (OTP) and other authentication methods.
Innovation Solution
Enhance transaction authentication by checking the state of one or more other applications on a user's device, requiring them to be in specific states or transition to certain states within a predetermined period, leveraging a personalized layer of security that is difficult for attackers to replicate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional single-factor authentication methods (passwords, PINs) are used, then ease of operation is improved, but security against sophisticated cyber threats deteriorates
Solution Approach 1:
The patent combines multiple authentication factors including biometric data (fingerprint, facial recognition), device state information (application states, location, time), and contextual data to create a comprehensive authentication system. This merging of multiple verification dimensions provides robust security while maintaining user convenience through automated multi-factor verification.
Solution Approach 2:
The authentication system serves multiple security functions simultaneously: verifying user identity, detecting fraudulent activity, assessing transaction risk, and providing adaptive authentication. The system can be applied across different applications and devices, making it a universal security solution that addresses both security requirements and operational ease.
2Reliability
If multi-factor authentication systems are implemented, then security is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into independent modules: biometric verification module, device state verification module, contextual analysis module, and risk assessment module. Each module handles specific authentication aspects and can operate independently, reducing overall system complexity while maintaining comprehensive security through coordinated operation of these segmented components.
Solution Approach 2:
The patent introduces an intermediary authentication service layer that mediates between various authentication factors and the main application. This intermediary layer consolidates complex verification logic, manages multiple authentication providers, and presents a simplified interface to both users and applications, thereby reducing perceived system complexity while maintaining enhanced security.
3Reliability
If application state verification is performed, then security against SIM swapping and dictionary attacks is improved, but authentication time increases
Solution Approach 1:
The system performs preliminary verification of application states and device conditions during normal operation rather than only during authentication events. By continuously monitoring and pre-verifying authentication factors such as application presence, device legitimacy, and environmental context, the system reduces authentication time when actual verification is needed while maintaining robust security.
Solution Approach 2:
The authentication system operates continuously in the background, continuously verifying device states, monitoring application conditions, and assessing contextual factors. This continuous verification ensures that authentication factors remain valid without requiring repeated verification steps, thereby reducing overall authentication time while maintaining constant security oversight.
Data Source
AI summary
Methods, systems, and machine-readable mediums that enhance transaction authentication of a transaction of a first application by checking that a state of one or more other applications matches prespecified states or that one or more of those applications transition states within a prespecified period of time. For example, the prespecified states may correspond to the application being installed on a specified device (e.g., of the user) and having an authenticated session with a specified user.


