Peripheral Memory Authentication for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems are vulnerable to phishing attacks, where hackers deceive users into providing their credentials, allowing unauthorized access to sensitive information and assets, particularly in unsecured internet transactions.

Innovation Solution

A method that provides a secure data communication path using a peripheral memory storage device with trusted secure data, allowing for dual authentication thresholds, where initial security information is verified independently of the secure data, and secondary information is validated using the stored secure data, even over unsecured networks, to prevent impersonation and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication is performed over unsecured networks using standard protocols, then ease of operation is improved, but security is worsened due to phishing attacks

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing a secure communication channel between the server and the memory device before the authentication process. Secure data is exchanged and stored in advance, creating a trusted foundation that prevents phishing attacks during the actual authentication over unsecured networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The memory device acts as an intermediary between the user and the server, holding secure data that enables authentication without exposing credentials to phishing attacks. This intermediary layer allows the system to verify identities through secure data comparison rather than transmitting sensitive information over unsecured channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure data is stored in non-volatile memory for authentication, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: the server, the memory device, and the communication interface. This segmentation allows each component to have a specific role, simplifying the overall system architecture while maintaining high security through the dedicated secure data storage in the memory device.

Inventive Principle:
Principle #1Segmentation

3Reliability

If dual authentication thresholds are implemented, then security is improved, but ease of operation is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidease of authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system dynamically adjusts its verification process based on the situation. The memory device can provide different levels of authentication - a first level for normal operations and a second, more stringent level when needed. This dynamic approach maintains ease of operation for routine tasks while ensuring high security when required.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9736150B2Authentication system and method
Publication Date: 2017.08.15 DATA LOCKER INC
  • US9736150B2 patent drawing
  • US9736150B2 patent drawing
  • US9736150B2 patent drawing

AI summary

A security protocol for use by computing devices communicating over an unsecured network is described. The security protocol makes use of secure data provided to a peripheral memory device from a server via a secure connection. When the peripheral memory device is coupled to a computing device that attempts to establish a secure connection to the server, the secure data is used to verify that the server is authentic. Similarly, the secure data assists the server in verifying that the request to access the server is not being made by a malicious third party.