Hidden Response Verification for Secure System Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing two-step verification process is vulnerable to social engineering, phishing, SIM swapping, single point of failure, and limited security options, allowing attackers to gain instant access to accounts and compromise payment processes, particularly in high-risk security situations.
Innovation Solution
A user verification system that employs hidden response requests, including a primary and secondary address for login and reset verification, with the option to send one-time pins to a secondary, encrypted address that can be updated, providing an additional layer of security by masking the secondary address from view and delaying verification messages to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a two-step verification process is implemented using primary email and phone number, then user verification capability is provided, but security vulnerability increases due to exposure of contact information across multiple platforms
Solution Approach 1:
The patent introduces a secondary hidden email address as an intermediary for verification. This hidden address acts as a mediator between the user and the verification system, receiving verification codes without exposing the user's primary contact information to the system or potential attackers. The hidden address shields the primary email and phone number from direct exposure.
Solution Approach 2:
The patent extracts the verification function from the primary contact information (email and phone number) and relocates it to a secondary hidden address. By separating the verification receiving function from the primary identity markers, the system maintains verification capability while removing the security vulnerability of exposing primary contact details.
2Speed
If verification codes are sent to primary contact information, then instant verification is achieved, but account compromise risk increases when contact information is exposed
Solution Approach 1:
The hidden email address serves as an intermediary that receives verification codes instantly while protecting the primary contact information. Attackers who compromise primary contact details cannot intercept verification codes sent to the hidden address, maintaining both speed and security.
Solution Approach 2:
The verification receiving function is extracted from the primary contact information and assigned to a separate hidden address. This separation allows instant verification to occur without the risk associated with exposing primary contact details, as the verification channel is independent of the compromised information.
3Ease of operation
If a single phone number and email are used for verification, then simplicity is maintained, but single point of failure risk increases
Solution Approach 1:
The patent segments the verification function by introducing a secondary hidden email address alongside the primary contact information. This segmentation creates redundancy where verification can proceed through the hidden address even if primary contact information is compromised, thereby improving reliability while maintaining operational simplicity for the user.
Solution Approach 2:
The system changes the parameter of contact information usage by introducing a hidden address that is not exposed to the system. This parameter change creates a backup verification channel that maintains simplicity for the user while improving reliability through redundancy and isolation of the verification function.
Data Source
AI summary
The invention provides a user verification system to verify whether a user of a secure system is authorised to access the secure system. The user verification system comprises one or more processors and one or more computer memory storage means; stored instructions on the memory storage means for controlling the processor, to create a user profile for a user, which profile input fields require first address such as an email address and second address such as a cellular telephone number; and stored instructions on the memory storage means for controlling the processor, to login to the secure system and which secure system is set up to send a login verification means to the first or second address in the form of a hidden response request.


