NFC Authenticator Enrollment for Phishing-Resistant On-Device Login
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems face vulnerabilities in phishing attacks during authenticator enrollment and lack effective mechanisms to ensure secure on-device authentication, particularly in multi-tenant environments.
Innovation Solution
Implementing near-field communication (NFC) devices for secure token encryption and decryption, and using ephemeral servers for authentication challenges to enhance phishing-resistant enrollment and on-device authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional enrollment methods are used, then ease of operation is improved, but security against phishing attacks deteriorates
Solution Approach 1:
The patent introduces an NFC device as an intermediary carrier that physically transports the encryption key from the authentication service to the user's device. This mediator eliminates direct network transmission of sensitive credentials, preventing phishing attacks while maintaining simple enrollment through tap-to-enroll interaction.
Solution Approach 2:
The authentication service pre-generates and encrypts the enrollment token with an encryption key before the user enrollment process. This preliminary encryption action ensures that the token cannot be compromised during transmission or storage, providing phishing resistance before the actual enrollment occurs.
2Ease of operation
If encryption keys are transmitted via network, then ease of operation is improved, but security deteriorates due to interception risks
Solution Approach 1:
The patent extracts the encryption key transmission from the network channel and places it on a physical NFC carrier. By removing the key from digital transmission and embedding it in a tangible NFC device that the user physically receives and taps, the system eliminates network interception vulnerabilities while maintaining operational convenience.
Solution Approach 2:
The patent replaces the electronic/network-based key transmission mechanism with a physical NFC-based mechanism. The encryption key is embedded in an NFC device that communicates via near-field electromagnetic coupling, substituting the vulnerable network transmission with a secure physical handoff that requires direct user action.
3Reliability
If phishing-resistant enrollment is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The NFC device is designed to be self-contained with the encryption key pre-loaded by the authentication service. The user simply receives the NFC device and taps it to enroll, without needing to manually configure security settings or understand cryptographic operations. The complex security mechanisms operate autonomously, presenting a simple interface to the user.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Reduces the likelihood of attackers compromising authenticator applications by ensuring secure enrollment and verifying user identity, thereby enhancing security in multi-tenant systems.
Implementation Method 1
using an encryption key on a near-field communication (NFC) device that is associated with the user
Data Source
AI summary
Methods, systems, and devices for phishing-resistant authenticator enrollment are described. An authentication service may encrypt a token that is usable for an initial enrollment of a user in an authenticator application. The authentication service may transmit a first payload to the user. The first payload includes at least the encrypted token. An authenticator application may receive, from the user, a request to initiate the initial enrollment of the user on a device. The request may include the encrypted token. The authentication service may enroll the user in the authenticator application on the device based on decryption of the encrypted token using an encryption key on a near-field communication (NFC) device.


