Secure Authentication via Hardware Credential Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting against phishing and pharming attacks, such as blacklists and heuristic algorithms, are ineffective due to frequent URL changes and vulnerabilities in standard web browsers, leading to false positives and negatives, and are compromised by malicious software plug-ins.
Innovation Solution
A secure authentication process that combines a dedicated hardware password store with a private web browser and a whitelist database of financial institution web sites, using a digital signature for protection and periodic updates, to prevent unauthorized access and malicious plug-ins.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If standard web browsers are used for web site authentication, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities from malicious software plug-ins
Solution Approach 1:
The system segments the authentication process by separating credential storage from the web browser environment. A dedicated hardware password store is isolated from the vulnerable browser plug-in ecosystem, while still enabling seamless authentication through integrated software components that bridge the hardware token and web sites.
Solution Approach 2:
The patent introduces intermediary software components that mediate between the secure hardware password store and the web browser. These intermediaries handle credential retrieval and transmission without exposing credentials to the vulnerable browser environment, thus maintaining both ease of operation and security reliability.
2Measurement precision
If blacklists and heuristic algorithms are used to detect phishing attacks, then measurement precision is improved, but reliability deteriorates due to false positives and negatives from frequent URL changes
Solution Approach 1:
The system performs preliminary validation by maintaining a whitelist database of known legitimate web site characteristics (IP addresses, domain names, SSL certificates) before authentication occurs. This proactive approach prevents phishing attacks by verifying site identity in advance, eliminating false positives and negatives associated with reactive blacklist and heuristic methods.
3Ease of operation
If user credentials are stored in standard computer memory, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities to corruption and theft
Solution Approach 1:
The patent extracts credential storage from the vulnerable standard computer memory environment and places it in a dedicated hardware password store. This separation removes credentials from the attack surface of software-based systems while maintaining ease of access through automated retrieval mechanisms.
Solution Approach 2:
The system combines hardware security features (secure element, cryptographic processing) with software convenience (automated credential management, seamless integration with web browsing) to create a composite authentication solution that achieves both security reliability and ease of operation.
Data Source
AI summary
A secure authentication process detects and prevents phishing and pharming attacks for specific web sites. The process is based on a dedicated secure hardware store for user sign-in credentials, a database of information about specific web sites, and a private secure browser. All user web activity is monitored by an agent program. The agent program checks to make sure that user attempts to send any sign-in credentials stored in secure hardware store of user sign-in credentials, to any web site accessed by the user, is allowed only if the IP address of the web site accessed by the user matches at least one of the IP addresses stored web site database associated with the sign-in credential the user is attempting to send. The process also detects mismatches between a URL and the actual IP address of the web site associated with the URL.


