Dynamic Authentication Representations for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are vulnerable to identity theft and data breaches due to phishing and man-in-the-middle attacks, which conventional authentication methods, such as static visual images and one-time passwords, are insufficient in preventing, especially when attackers intercept secure connections using TLS/SSL.

Innovation Solution

Implementing a dynamic authentication technique that generates unique representations, such as codes, symbols, or audio signals, on both user and server devices, using public key/private key encryption to ensure matching representations for secure communication, thereby thwarting man-in-the-middle attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static visual images are used for authentication, then users can easily recognize legitimate sites, but the authentication method becomes vulnerable to phishing and man-in-the-middle attacks

Engineering Contradiction:
Improveease of site recognitionVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static visual images into dynamic representations that change over time or based on authentication state. The visual representation is no longer fixed but evolves to reflect the authentication status, making it both easy to recognize (maintaining simplicity) and secure (preventing phishing attacks since attackers cannot predict the dynamic state)

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameters of the visual representation by encoding authentication status information into the visual display. The representation modifies its characteristics (such as appearance, state, or properties) based on the authentication outcome, allowing users to quickly assess site legitimacy while preventing unauthorized access

Inventive Principle:
Principle #35Parameter changes

2Reliability

If one-time passwords are used for additional security, then authentication security is improved, but the authentication process becomes more complex

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the visual representation authentication with one-time password verification into a unified authentication mechanism. Instead of separate steps for visual recognition and OTP entry, the system combines these into an integrated process where the dynamic visual representation itself conveys authentication status, reducing complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If dynamic representations are generated using public key encryption, then security against man-in-the-middle attacks is improved, but the computational overhead increases

Engineering Contradiction:
Improvesecurity against man-in-the-middle attacksVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial encryption actions by using public key cryptography only for the critical authentication verification rather than encrypting all data transmissions. The dynamic visual representation is generated using selective cryptographic operations, providing sufficient security against man-in-the-middle attacks while minimizing unnecessary computational overhead

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8327422B1Authenticating a server device using dynamically generated representations
Publication Date: 2012.12.04 EMC IP HLDG CO LLC
  • US8327422B1 patent drawing
  • US8327422B1 patent drawing
  • US8327422B1 patent drawing

AI summary

A technique supports authentication of a server device (e.g., a web site). The technique involves supplying a user device (e.g., a client browser) with a user mechanism (e.g., a browser plug-in) which is constructed and arranged to dynamically generate user representations. The technique further involves receiving, at the server device, a request from the user device. The technique further involves providing a server representation to the user device from the server device in response to the request. The user device successfully authenticates the server device when a user representation dynamically generated by the user mechanism matches the server representation provided to the user device. However, the user device unsuccessfully authenticates the server device when the user representation dynamically generated by the user mechanism does not match the server representation provided to the user device.