Electronic Verification System for Phishing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to adequately protect users and authentic websites from phishing and pharming attacks, leading to identity theft and fraudulent transactions, as they lack an efficient and effective method to verify the authenticity of electronic entities.
Innovation Solution
A verification system that uses cryptographic algorithms to store and verify shared identification information between users and authenticating entities, including public and secret portions, to ensure the authenticity of electronic entities through message digests and dynamic media, preventing unauthorized access and identity theft.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used, then ease of operation is maintained, but security against phishing and pharming attacks deteriorates
Solution Approach 1:
The patent introduces an intermediary verification system that acts as a mediator between users and electronic entities. This system provides authentication codes and verification mechanisms that bridge the gap between simple user interaction and complex security verification, allowing users to easily verify authenticity without directly implementing complex cryptographic protocols.
Solution Approach 2:
The system performs preliminary authentication and verification actions before the actual transaction occurs. Authentication codes are generated and verified in advance, and the system pre-establishes trust relationships between users and electronic entities, so that during the actual transaction, security verification is already complete and users can proceed with ease.
2Reliability
If cryptographic verification systems are implemented, then security against identity theft is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex cryptographic verification logic from the user's device and relocates it to a centralized verification system. Users only need to interact with simple authentication codes and verification tokens, while the complex cryptographic operations are performed by the verification system server, thereby reducing device complexity while maintaining security.
Solution Approach 2:
The system uses authentication codes and verification tokens as simplified copies or representations of the complex cryptographic verification process. Instead of requiring users to implement full cryptographic protocols, the system provides easily usable code representations that embody the security verification functionality.
3Reliability
If authentication verification is performed for all transactions, then reliability of electronic entities is improved, but loss of time in verification processes increases
Solution Approach 1:
The system performs authentication verification in advance and caches the results. Once an electronic entity is verified, its authenticity is established and stored, allowing subsequent transactions to use pre-verified status without repeating the full verification process, thereby reducing verification time while maintaining reliability.
Solution Approach 2:
The system implements selective verification where full authentication is performed only when necessary, and simpler verification methods are used for routine transactions. The system adjusts the level of verification based on the transaction context, performing complete verification only when security risks are detected or for high-value transactions.
Data Source
AI summary
A verification system which can be used over electronic networks, such as the Internet, to help prevent phishing, electronic identity theft, and similar illicit activities, by verifying the authenticity of electronic entities (for example, websites). Users and electronic entities register with an authenticating entity. The authenticating entity shares an encryption method with registered electronic entities and establishes a secret code for each registered electronic entity. The secret code is combined with other information and encrypted before being transmitted over the network to ensure that the secret code cannot be compromised. Also disclosed are systems for virtual token devices, which provided object-based authentication without a physical device. Also disclosed are dynamic media credentials, which display nearly-unique behavior, previously specified and known to a user, to assist in verifying the authenticity of the presenter.


