Location-Based Anti-Phishing Image Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-phishing methods rely on static images and knowledge-based or SMS-based authentication, which are vulnerable to hacking and do not effectively establish trust in online interactions, particularly in preventing phishing attacks.

Innovation Solution

A non-static, location-based anti-phishing image system where a user selects an image during registration, and the associated location is used for encryption and decryption, providing a unique access code or OTP, enhancing security by requiring the user to be at the registered location for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static anti-phishing images are used for authentication, then the authentication process is simple and easy to implement, but the security against phishing attacks is weak because hackers can steal or determine the image

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidsecurity against phishing attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static anti-phishing images into dynamic location-based images. The anti-phishing image changes based on the user's geographic location, making it impossible for hackers to use a single stolen image for phishing attacks across multiple locations. The system dynamically generates different images for different locations while maintaining the same authentication functionality.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of the anti-phishing image from static to location-dependent. By incorporating location coordinates as a variable parameter, the system generates unique images based on geographic position. This parameter change ensures that even if one image is compromised, other location-based images remain secure and valid.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If location-based encryption is implemented in anti-phishing images, then security is significantly enhanced, but the system complexity increases due to location tracking and encryption requirements

Engineering Contradiction:
Improvesecurity enhancementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service functionality where the mobile device automatically provides its location information without requiring manual input from the user. The device's built-in location services (GPS, network location) automatically supply the necessary coordinates, and the encryption/decryption processes occur automatically in the background, reducing the perceived complexity for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent leverages existing multi-functional components in mobile devices, such as the integrated location services that serve both navigation and security purposes. By reusing these existing capabilities for anti-phishing authentication, the system avoids adding separate dedicated hardware or software components, thereby minimizing the increase in system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If knowledge-based or SMS-based authentication is replaced with location-based anti-phishing images, then vulnerability to hacking is reduced, but the requirement for location services and encryption capabilities increases system requirements

Engineering Contradiction:
Improvevulnerability to hackingVSAvoidsystem requirements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from static authentication methods (knowledge-based or SMS) to dynamic location-based authentication. The system adapts the authentication mechanism to incorporate real-time location data, making it dynamic rather than static. This dynamic approach inherently reduces vulnerability to hacking while utilizing the mobile device's existing adaptive capabilities.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3272093B1Method and system for Anti-phishing using smart images
Publication Date: 2019.09.11 ORACLE INT CORP
  • EP3272093B1 patent drawingFigure 1
  • EP3272093B1 patent drawingFigure 2
  • EP3272093B1 patent drawingFigure 3

AI summary

Embodiments of the invention provide systems and methods for using an anti-phishing image. More specifically, embodiments of the present invention provide for using a non-static, location-based anti-phishing image that can, in some cases, include authentication information. According to one embodiment, a user with a trusted mobile device can go to a particular location during enrollment with an online service or application. This location can be detected by the mobile device, e.g., through a Global Positioning System (GPS) receiver and/or other location detection techniques. Once detected, this location can be provided by the mobile device to the service or application with which the user is registering and saved by the service or application as a "secret location." Also during enrollment, the user can select an anti-phishing image. Once saved, the location information can be used for anti-phishing as well as authentication purposes.