Passkey Credential Selection for Phishing-Resistant Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online interactions lack security due to the risk of data breaches and phishing attacks, especially when sensitive authentication data is exposed or provided to potentially untrusted resource providers, relying on insecure communication channels.
Innovation Solution
Implementing passkeys and WebAuthn to enable secure, frictionless authentication by leveraging discoverable credentials, eliminating the need for personal information and enhancing card-present security in online interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication data is stored in a database, then user authentication can be performed, but security is compromised in case of data breaches
Solution Approach 1:
The patent extracts the authentication data from centralized databases and stores it locally in the user device's secure element. This eliminates the centralized database that is vulnerable to data breaches, while maintaining the ability to authenticate users through local credential storage and verification.
Solution Approach 2:
The patent introduces a credential verification system that acts as an intermediary between the user device and the resource provider. Instead of directly storing authentication data in databases, the system uses secure elements and verification protocols to mediate authentication, reducing exposure to data breaches.
2Reliability
If authentication data is provided directly by user device to resource provider, then no database storage is needed, but users must input sensitive data into potentially unknown webpages
Solution Approach 1:
The patent implements self-service authentication where the user device automatically provides authentication data to the resource provider without requiring manual input from the user. The system uses secure elements to store and transmit credentials automatically, eliminating the need for users to enter sensitive data into webpages and thus preventing phishing attacks.
Solution Approach 2:
The patent performs preliminary actions by pre-storing authentication data in secure elements on user devices before the authentication event. This allows the system to automatically provide credentials when needed without exposing users to phishing risks during data entry, as the credentials are already prepared and can be transmitted securely.
3Ease of operation
If authentication data is provided to resource provider computer, then authentication can be performed, but security relies on communication channel between user device and resource provider
Solution Approach 1:
The patent extracts authentication data from the communication channel dependency and stores it locally in secure elements on user devices. This allows authentication to occur without relying solely on the security of the communication channel between user device and resource provider, while maintaining ease of operation through automatic credential provision.
Data Source
AI summary
A computer receives an interaction request message. The computer transmits, to a user device, a relying party identifier associated with a relying party computer. The user device thereafter determines a list of credentials or identifiers thereof based on the relying party identifier. The computer receives the list of credentials or identifiers thereof from the user device. The computer conducts an interaction using a credential, identifier thereof, of the list of credentials or identifiers thereof.


