Encrypted Input Intermediary for Browser Authentication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems for access provider systems face challenges such as key loggers, man-in-the-middle attacks, and weaknesses in two-factor authentication, particularly with SMS-based One-Time-Passcode systems, which can be breached by man-in-the-browser attacks.
Innovation Solution
A computer-implemented method and system that uses encrypted input information received from a user on a second electronic device, transmitted to an access provider system, where each access provider system has decryption keys, but the system service remains agnostic to the decryption process, generating session identifiers and secret keys for secure access, and presenting these as visual representations for scanning, ensuring secure access without decrypting the information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security systems use direct input collection and processing, then authentication can be performed, but the system becomes vulnerable to key loggers, screen scraping, and man-in-the-browser attacks
Solution Approach 1:
The patent introduces a second electronic device as an intermediary between the user and the access provider system. This intermediary device collects input information and transmits it encrypted to the access provider, preventing direct exposure of input mechanisms to potential attackers on the first device. The intermediary acts as a security buffer that isolates vulnerable points in the authentication flow.
Solution Approach 2:
The patent replaces traditional direct input collection mechanisms with an encrypted transmission-based system. Instead of directly capturing input data on the first device, the system uses cryptographic encryption to protect input information during transmission to the access provider system, substituting mechanical input collection with secure cryptographic communication.
2Ease of operation
If the system service decrypts input information to verify user identity, then authentication can be performed, but the system service gains access to sensitive data and increases complexity
Solution Approach 1:
The patent extracts the decryption function from the system service and places it with the access provider system. The system service only handles encrypted data transmission and does not perform decryption, separating the decryption capability from the authentication service. This extraction reduces the system service's complexity and data access burden while maintaining authentication functionality.
Solution Approach 2:
The patent segments the authentication process into distinct functional components: input collection on the second device, encrypted transmission to the access provider system, and decryption/verification by the access provider. This segmentation distributes complexity across separate components rather than concentrating it in the system service, making each component simpler and more manageable.
3Reliability
If the system uses SMS-based One-Time-Passcode authentication, then two-factor authentication is provided, but the system becomes vulnerable to man-in-the-browser attacks due to transmission protocol weaknesses
Solution Approach 1:
The patent uses the second electronic device as an intermediary that establishes a secure connection with the access provider system. This intermediary handles the transmission of authentication data through encrypted channels, replacing vulnerable SMS-based transmission protocols with more secure encrypted communication pathways that resist man-in-the-browser attacks.
Solution Approach 2:
The patent substitutes the vulnerable SMS transmission mechanism with an encrypted communication system. Instead of relying on inherently insecure SMS protocols, the system uses cryptographic encryption to protect authentication data during transmission, replacing the mechanical SMS delivery system with a more secure encrypted communication layer.
4Adaptability or versatility
If the access provider system integrates directly with multiple authentication systems, then authentication versatility is improved, but the integration workload and system complexity increase
Solution Approach 1:
The patent creates a universal authentication interface through the second electronic device that can work with multiple access provider systems. The second device provides standardized encrypted input collection and transmission capabilities that can be applied across different authentication systems, allowing the access provider to maintain versatility without implementing multiple specialized integration paths for each authentication method.
Data Source
AI summary
In one form of the present invention, there is provided a computer implemented method 10 of enabling one or more access provider systems 12 to secure access to content on first electronic devices 14, the computer implemented method 10 comprising: receiving encrypted input information 16, the encrypted input information 16 being inputted by users 18 on second electronic devices 20; and transmitting input information 16 to the one or more access provider systems 12 to allow the one or more access provider systems 12 to determine whether to authorise access to content on the first electronic devices 14.


