Cryptographic Tagging for Multi-Device Authentication Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional multi-device authentication techniques are vulnerable to attacks where users may confuse legitimate and malicious authentication prompts due to their similarity in timing, leading to potential unauthorized access to protected resources.
Innovation Solution
Implementing user-controlled transaction tagging, where a user-generated cryptographic tag is included with authentication requests, allowing users to easily identify and correlate subsequent authentication events, such as mobile push notifications, thereby distinguishing between legitimate and malicious prompts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional multi-device authentication techniques are used, then authentication can be performed across multiple devices, but users may confuse legitimate and malicious authentication prompts due to their similarity in timing
Solution Approach 1:
The system attaches a cryptographic tag to the authentication request before it is processed, allowing the user to see the tag in advance on both the initiating device and the authentication device. This preliminary tagging enables the user to verify that the authentication prompt corresponds to the legitimate request they initiated, rather than a malicious one.
Solution Approach 2:
A cryptographic tag acts as an intermediary element that bridges the authentication request and the authentication prompt. This tag is generated by the system and included in both the request and the subsequent prompt, serving as a verifiable link that helps the user distinguish legitimate authentication flows from malicious ones.
2Reliability
If authentication prompts are sent to multiple devices, then user authentication can be verified across devices, but malicious actors can initiate attacks by anticipating typical authentication times
Solution Approach 1:
The cryptographic tag is attached to the authentication request before processing, allowing the user to verify the legitimacy of the prompt in advance by comparing the tag displayed on the initiating device with the tag shown in the authentication prompt.
Solution Approach 2:
The system provides feedback to the user by displaying the cryptographic tag on both the initiating device and the authentication device. This feedback mechanism allows the user to confirm that the authentication prompt is legitimate by verifying that the tags match, thereby preventing malicious actors from successfully impersonating legitimate authentication requests.
3Reliability
If users are prompted to authenticate on a second device after initiating access on a first device, then multi-factor authentication is achieved, but users cannot determine whether multiple prompts are due to legitimate technical issues or malicious activity
Solution Approach 1:
The cryptographic tag is attached to the authentication request before it is processed by the system. This pre-attached tag is then displayed on both the initiating device and the authentication device, providing the user with a verifiable identifier that links the two authentication prompts and eliminates uncertainty about their legitimacy.
Solution Approach 2:
The cryptographic tag serves as an intermediary element that connects the authentication request and the authentication prompt. By including this tag in both the request and the prompt, the system provides the user with a verifiable link that confirms the legitimacy of the authentication flow, preventing confusion between legitimate and malicious prompts.
Data Source
AI summary
Methods, apparatus, and processor-readable storage media for user-controlled transaction tagging to enable easier identification and co-relation of subsequent related events are provided herein. An example computer-implemented method includes receiving, via a first user device in connection with a request to access a protected resource, a first set of user-generated cryptographic information and a second set of user-generated cryptographic information; generating and outputting an authentication request to a second user device in response to processing the first set of user-generated cryptographic information against a stored set of cryptographic information associated with the protected resource, wherein the authentication request causes the second set of user-generated cryptographic information to be rendered via the second user device; and resolving the authentication request in response to receiving, via the second user device, an indication to grant or deny the request to access the protected resource via the first user device.


