Dynamic Authentication Identifiers for Replay-Resistant Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods relying on static usernames and passwords are vulnerable to attacks such as credential theft, social engineering, phishing, brute-force, and MFA fatigue, and do not adequately protect against replay and man-in-the-middle attacks.
Innovation Solution
Implement systems and methods that use dynamic, unique identifiers generated just-in-time by an authentication server, which can be entered by users or machines to authenticate securely, eliminating the need for static credentials and reducing vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static usernames and passwords are used for authentication, then the authentication process is simple and familiar to users, but the system becomes vulnerable to credential theft, social engineering, phishing, brute-force, and replay attacks
Solution Approach 1:
The patent applies dynamics by replacing static credentials with dynamic identifiers that change over time. The authentication server generates unique dynamic identifiers for each authentication session, and these identifiers are valid only for specific time windows and sessions. This dynamic approach eliminates replay attacks while maintaining user-friendly authentication processes.
Solution Approach 2:
The patent changes the parameter of identifier stability by using identifiers that are unique to each session and time-bound. Instead of permanent static credentials, the system generates identifiers with specific validity periods and session constraints, fundamentally changing how authentication credentials behave and interact with the system.
2Reliability
If multiple authentication factors (MFA) are implemented, then authentication security is improved, but the system becomes vulnerable to MFA prompt spamming and MFA fatigue attacks
Solution Approach 1:
The patent applies preliminary action by pre-generating unique dynamic identifiers for each authentication session before the user needs to authenticate. These identifiers are created with built-in session validity and are distributed to users in advance through secure channels, eliminating the need for real-time MFA prompts that can be spammed or cause fatigue.
Solution Approach 2:
The patent uses disposable authentication identifiers that are valid for only one session and expire automatically. Each dynamic identifier is short-lived and single-use, making the system resistant to MFA fatigue attacks since attackers cannot spam unlimited prompts - each identifier can only be used once and then becomes invalid.
3Ease of operation
If static credentials are used, then credential management is simple, but the system is vulnerable to credential theft and replay attacks
Solution Approach 1:
The patent extracts the secret from the authentication equation by using public dynamic identifiers instead of private passwords. The dynamic identifiers can be safely exposed and shared without compromising security, as they cannot be used for replay attacks due to their session-specific and time-bound nature. This extracts the vulnerability of static credentials while maintaining ease of use.
4Reliability
If dynamic identifiers are generated just-in-time, then protection against replay attacks is improved, but the authentication system requires more complex infrastructure
Solution Approach 1:
The patent applies periodic action by generating dynamic identifiers at regular intervals and for specific session durations. The authentication server creates identifiers with predefined validity periods, and these identifiers automatically expire after use or time-out, providing built-in protection against replay attacks through time-based validity constraints.
Data Source
AI summary
Systems and methods involving various registration and authentication workflows are disclosed herein. A user may be authenticated without the use of static usernames or passwords. In some embodiments, an authentication identifier may be generated that is associated with an authentication request for a user to access a protected resource (e.g., a web app). An authentication code may be generated based on the authentication identifier. The authentication code may be sent to a computing device to be provided to the user, who may provide the authentication code to an application on their mobile device. The mobile device may send a payload containing the authentication identifier, credentials saved on the user device from a previous registration step, and a digital signature. The digital signature may be authenticated using contents of the payload before validating the authentication identifier.


