DNS Fidelity Monitoring for Behavioral Anomaly Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password-based security systems for online accounts are cumbersome, inefficient, and pose security risks, requiring customers to remember multiple passwords and exposing vendors to security threats.
Innovation Solution
A system and method that uses email authentication for secure account access, leveraging various message authentication techniques and blockchain, allowing vendors to manage secure transactions while minimizing the need for individual passwords and enhancing security through email monitoring and notifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based security systems are used for online accounts, then security protection is provided, but the system becomes cumbersome and inefficient requiring customers to remember multiple passwords
Solution Approach 1:
The patent introduces email as an intermediary authentication mechanism between the customer and the vendor system. Instead of directly managing passwords, the system uses email-based verification tokens to authenticate users. This intermediary approach maintains security while eliminating the need for customers to remember passwords, as email clients already have built-in security and users naturally remember their email credentials.
Solution Approach 2:
The patent extracts the password management function from the vendor's security system and relocates it to the email authentication system. By removing password storage and verification from the vendor's responsibility, the system eliminates the burden of remembering multiple passwords while maintaining security through email-based verification. The vendor system only needs to handle verification tokens, not actual passwords.
2Reliability
If vendors manage and secure customer passwords, then security is maintained, but the vendor is exposed to undue security threats and storage becomes burdensome
Solution Approach 1:
The patent extracts the sensitive password storage function from the vendor's system entirely. Instead of storing passwords, the vendor system only stores and verifies email addresses and temporary authentication tokens. This extraction eliminates the security vulnerability of password databases while maintaining authentication security through email-based verification, significantly reducing the vendor's security burden and exposure.
Solution Approach 2:
The patent introduces email authentication as an intermediary layer between the customer and vendor system. The email service provider acts as a trusted intermediary that handles password security, while the vendor system only interacts with verification tokens. This intermediary approach transfers password management responsibility to a specialized service, reducing the vendor's security burden and exposure to password-related threats.
3Reliability
If customers use password-protected accounts for each vendor, then security is provided, but the login process becomes complicated and deters repeat purchases
Solution Approach 1:
The patent extracts the password entry step from the login process and replaces it with email-based authentication. Customers only need to provide their email address, and the system automatically sends verification tokens to their email client. This extraction eliminates the time-consuming password typing and memorization, reducing login complexity while maintaining security through automated verification.
Solution Approach 2:
The patent implements preliminary email authentication before the actual login process. The system pre-sends verification tokens to the customer's email address, and these tokens are automatically available when needed for login. This preliminary action eliminates the need for customers to remember passwords or manually enter security information during the login process, significantly reducing login time and complexity.
4Ease of operation
If customers remain logged in to their accounts for convenience, then access is streamlined, but security risks increase
Solution Approach 1:
The patent implements periodic re-authentication through email verification tokens. Instead of maintaining continuous logged-in sessions, the system requires customers to periodically obtain fresh authentication tokens from their email client. This periodic action maintains security by ensuring that access credentials are regularly renewed through a secure channel, while still allowing convenient access during authenticated sessions.
Data Source
AI summary
An approach for improving computer security using machine learning and DNS-based monitoring. A server receives requests associated with multiple entities, including at least customers and vendors, and maintains historical behavior data comprising prior requests, corresponding outcomes, and DNS record information for associated domains. A machine learning algorithm determines a range of predictable requests for a given entity based on the historical behavior data and compares new requests to this range to detect anomalies or behavior inconsistent with past activity. When an anomaly is detected, the server causes one or more confirmation messages to be sent, for example via email, SMS, social media messaging, instant messaging, or application notifications, before authorizing a secure operation.


