Remote Authentication Context Verification for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing remote sign-in systems are vulnerable to phishing attacks, where users can be tricked into authenticating with attackers' requests due to the lack of secure verification of the primary entity's location and context, leading to potential man-in-the-middle attacks.

Innovation Solution

The method involves an identity provider providing authentication context to a secondary user entity, which verifies and communicates securely with the user, displaying discrepancies to prevent unauthorized access by comparing authentication context from the primary and secondary entities, thus thwarting phishing attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote sign-in is implemented using a secondary previously provisioned entity, then user convenience and access efficiency are improved, but the system becomes vulnerable to phishing attacks and man-in-the-middle attacks

Engineering Contradiction:
Improveremote sign-in convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an identity provider as an intermediary between the primary entity and secondary entity. The identity provider issues authentication context (including location information) that acts as a mediator to verify the legitimacy of authentication requests, preventing phishing attacks while maintaining remote sign-in convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by having the identity provider issue authentication context with location information before the actual authentication occurs. This preliminary verification of location context prevents unauthorized authentication attempts while allowing legitimate remote access

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication context with location information is verified, then phishing attacks are prevented, but the authentication process complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses location information as a copyable verification attribute that can be included in authentication context. This location copy serves as proof of legitimate origin without requiring complex verification infrastructure, simplifying the overall process while maintaining security

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3437293B1Securing remote authentication
Publication Date: 2021.03.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3437293B1 patent drawingFigure 1
  • EP3437293B1 patent drawingFigure 2
  • EP3437293B1 patent drawingFigure 3

AI summary

Authenticating a secure session between a first user entity and an identity provider using a second user entity. The method receiving a request for a session from an entity that purports to be the first user entity. The method further includes sending authentication context from the request, and wherein the authentication context for the request arrives at the second user entity. The method further includes receiving an indication that the authentication context has been verified. As a result, the method further includes authenticating a secure session between a first user entity and an identity provider or approving a secure transaction.