Secure Authentication via Hardware Credential Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting against phishing and pharming attacks, such as blacklists and heuristic algorithms, are ineffective due to frequent URL changes and vulnerabilities in standard web browsers, leading to false positives and negatives, and are compromised by malicious software plug-ins.

Innovation Solution

A secure authentication process that combines a dedicated hardware password store with a private web browser and a whitelist database of financial institution web sites, using a digital signature for protection and periodic updates, to prevent unauthorized access and malicious plug-ins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If standard web browsers are used for web site authentication, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities from malicious software plug-ins

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the authentication process by separating credential storage from the web browser environment. A dedicated hardware password store is isolated from the vulnerable browser plug-in ecosystem, while still enabling seamless authentication through integrated software components that bridge the hardware token and web sites.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary software components that mediate between the secure hardware password store and the web browser. These intermediaries handle credential retrieval and transmission without exposing credentials to the vulnerable browser environment, thus maintaining both ease of operation and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If blacklists and heuristic algorithms are used to detect phishing attacks, then measurement precision is improved, but reliability deteriorates due to false positives and negatives from frequent URL changes

Engineering Contradiction:
Improvemeasurement precisionVSAvoidreliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary validation by maintaining a whitelist database of known legitimate web site characteristics (IP addresses, domain names, SSL certificates) before authentication occurs. This proactive approach prevents phishing attacks by verifying site identity in advance, eliminating false positives and negatives associated with reactive blacklist and heuristic methods.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If user credentials are stored in standard computer memory, then ease of operation is improved, but security reliability deteriorates due to vulnerabilities to corruption and theft

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts credential storage from the vulnerable standard computer memory environment and places it in a dedicated hardware password store. This separation removes credentials from the attack surface of software-based systems while maintaining ease of access through automated retrieval mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system combines hardware security features (secure element, cryptographic processing) with software convenience (automated credential management, seamless integration with web browsing) to create a composite authentication solution that achieves both security reliability and ease of operation.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS8095967B2Secure web site authentication using web site characteristics, secure user credentials and private browser
Publication Date: 2012.01.10 CF NEWCO INC
  • US8095967B2 patent drawing
  • US8095967B2 patent drawing
  • US8095967B2 patent drawing

AI summary

A secure authentication process detects and prevents phishing and pharming attacks for specific web sites. The process is based on a dedicated secure hardware store for user sign-in credentials, a database of information about specific web sites, and a private secure browser. All user web activity is monitored by an agent program. The agent program checks to make sure that user attempts to send any sign-in credentials stored in secure hardware store of user sign-in credentials, to any web site accessed by the user, is allowed only if the IP address of the web site accessed by the user matches at least one of the IP addresses stored web site database associated with the sign-in credential the user is attempting to send. The process also detects mismatches between a URL and the actual IP address of the web site associated with the URL.