Message Field Order Authentication for Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional OTP-based authentication methods are cumbersome, prone to errors, and vulnerable to fraudulent activities, such as unauthorized access and phishing, as they require manual input and do not provide continuous authentication throughout a session.

Innovation Solution

Implementing a bi-directional authentication mechanism using messages with message fields arranged in a specific order, such as HTTP header fields, which are automatically verified to ensure authenticity, reducing the need for manual input and enhancing security against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual OTP input is used for authentication, then authentication can be performed, but the process is cumbersome and error-prone

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the manual mechanical input system (typing OTP) with an automated electronic system that extracts OTP directly from clipboard, eliminating manual intervention and its associated errors

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs authentication automatically by monitoring clipboard for OTP, comparing it with expected value, and completing login without user intervention, making the system self-serving

Inventive Principle:
Principle #25Self-service

2Reliability

If OTP authentication is provided for the entire session, then security is maintained, but the authentication process becomes complex

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements continuous authentication by monitoring clipboard throughout the session, maintaining security without requiring repeated manual authentication steps from the user

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system continuously monitors clipboard for OTP and provides immediate feedback by comparing against expected value, maintaining security through ongoing verification rather than single-point authentication

Inventive Principle:
Principle #23Feedback

3Ease of operation

If automated clipboard monitoring is implemented, then manual input errors are reduced, but the device complexity increases

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent leverages the existing universal clipboard functionality across applications, avoiding the need for dedicated hardware or specialized input devices, thus minimizing added complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9747434B1Authenticating with an external device by providing a message having message fields arranged in a particular message field order
Publication Date: 2017.08.29 EMC IP HLDG CO LLC
  • US9747434B1 patent drawing
  • US9747434B1 patent drawing
  • US9747434B1 patent drawing

AI summary

A technique performs authentication with an external device. The technique involves receiving, by electronic circuitry, a messaging command. The technique further involves providing, by the electronic circuitry, a message to the external device in response to the messaging command. The message includes message fields which store message operating parameters e.g., Hypertext Transfer Protocol (HTTP) header fields containing HTTP operating parameters to form part of an HTTP transaction. The message fields of the message are arranged in a particular order to match an expected order during an order comparison operation performed by the external device to gauge authenticity of the message source. If the particular order matches the expected order, there is lower risk that the message source is fraudulent. However, if the particular order does not match the expected order, there is higher risk that the message source is fraudulent.