NFC Authenticator Enrollment for Phishing-Resistant On-Device Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems face vulnerabilities in phishing attacks during authenticator enrollment and lack effective mechanisms to ensure secure on-device authentication, particularly in multi-tenant environments.

Innovation Solution

Implementing near-field communication (NFC) devices for secure token encryption and decryption, and using ephemeral servers for authentication challenges to enhance phishing-resistant enrollment and on-device authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional enrollment methods are used, then ease of operation is improved, but security against phishing attacks deteriorates

Engineering Contradiction:
Improveenrollment process simplicityVSAvoidphishing resistance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an NFC device as an intermediary carrier that physically transports the encryption key from the authentication service to the user's device. This mediator eliminates direct network transmission of sensitive credentials, preventing phishing attacks while maintaining simple enrollment through tap-to-enroll interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service pre-generates and encrypts the enrollment token with an encryption key before the user enrollment process. This preliminary encryption action ensures that the token cannot be compromised during transmission or storage, providing phishing resistance before the actual enrollment occurs.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If encryption keys are transmitted via network, then ease of operation is improved, but security deteriorates due to interception risks

Engineering Contradiction:
Improveenrollment convenienceVSAvoidnetwork interception vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key transmission from the network channel and places it on a physical NFC carrier. By removing the key from digital transmission and embedding it in a tangible NFC device that the user physically receives and taps, the system eliminates network interception vulnerabilities while maintaining operational convenience.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the electronic/network-based key transmission mechanism with a physical NFC-based mechanism. The encryption key is embedded in an NFC device that communicates via near-field electromagnetic coupling, substituting the vulnerable network transmission with a secure physical handoff that requires direct user action.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If phishing-resistant enrollment is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthenticator securityVSAvoidenrollment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The NFC device is designed to be self-contained with the encryption key pre-loaded by the authentication service. The user simply receives the NFC device and taps it to enroll, without needing to manually configure security settings or understand cryptographic operations. The complex security mechanisms operate autonomously, presenting a simple interface to the user.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Reduces the likelihood of attackers compromising authenticator applications by ensuring secure enrollment and verifying user identity, thereby enhancing security in multi-tenant systems.

Implementation Method 1

using an encryption key on a near-field communication (NFC) device that is associated with the user

Methodology Applied
Scientific EffectNear-field communication:

Data Source

PatentUS12531739B2Techniques for phishing-resistant enrollment and on-device authentication
Publication Date: 2026.01.20 OKTA INC
  • US12531739B2 patent drawing
  • US12531739B2 patent drawing
  • US12531739B2 patent drawing

AI summary

Methods, systems, and devices for phishing-resistant authenticator enrollment are described. An authentication service may encrypt a token that is usable for an initial enrollment of a user in an authenticator application. The authentication service may transmit a first payload to the user. The first payload includes at least the encrypted token. An authenticator application may receive, from the user, a request to initiate the initial enrollment of the user on a device. The request may include the encrypted token. The authentication service may enroll the user in the authenticator application on the device based on decryption of the encrypted token using an encryption key on a near-field communication (NFC) device.