Dynamic Authentication Representations for Phishing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are vulnerable to identity theft and data breaches due to phishing and man-in-the-middle attacks, which conventional authentication methods, such as static visual images and one-time passwords, are insufficient in preventing, especially when attackers intercept secure connections using TLS/SSL.
Innovation Solution
Implementing a dynamic authentication technique that generates unique representations, such as codes, symbols, or audio signals, on both user and server devices, using public key/private key encryption to ensure matching representations for secure communication, thereby thwarting man-in-the-middle attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static visual images are used for authentication, then users can easily recognize legitimate sites, but the authentication method becomes vulnerable to phishing and man-in-the-middle attacks
Solution Approach 1:
The patent transforms static visual images into dynamic representations that change over time or based on authentication state. The visual representation is no longer fixed but evolves to reflect the authentication status, making it both easy to recognize (maintaining simplicity) and secure (preventing phishing attacks since attackers cannot predict the dynamic state)
Solution Approach 2:
The patent changes the parameters of the visual representation by encoding authentication status information into the visual display. The representation modifies its characteristics (such as appearance, state, or properties) based on the authentication outcome, allowing users to quickly assess site legitimacy while preventing unauthorized access
2Reliability
If one-time passwords are used for additional security, then authentication security is improved, but the authentication process becomes more complex
Solution Approach 1:
The patent merges the visual representation authentication with one-time password verification into a unified authentication mechanism. Instead of separate steps for visual recognition and OTP entry, the system combines these into an integrated process where the dynamic visual representation itself conveys authentication status, reducing complexity while maintaining security
3Reliability
If dynamic representations are generated using public key encryption, then security against man-in-the-middle attacks is improved, but the computational overhead increases
Solution Approach 1:
The patent applies partial encryption actions by using public key cryptography only for the critical authentication verification rather than encrypting all data transmissions. The dynamic visual representation is generated using selective cryptographic operations, providing sufficient security against man-in-the-middle attacks while minimizing unnecessary computational overhead
Data Source
AI summary
A technique supports authentication of a server device (e.g., a web site). The technique involves supplying a user device (e.g., a client browser) with a user mechanism (e.g., a browser plug-in) which is constructed and arranged to dynamically generate user representations. The technique further involves receiving, at the server device, a request from the user device. The technique further involves providing a server representation to the user device from the server device in response to the request. The user device successfully authenticates the server device when a user representation dynamically generated by the user mechanism matches the server representation provided to the user device. However, the user device unsuccessfully authenticates the server device when the user representation dynamically generated by the user mechanism does not match the server representation provided to the user device.


