Secure Online Authentication via Protected Data Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online authentication methods are vulnerable to data interception by malicious programs, especially during online transactions, as they may not detect new modifications of malicious software or provide robust protection against interception of one-time passwords.

Innovation Solution

A system and method for secure online authentication that involves determining a connection between a browser application and a protected website, establishing a protected data transmission channel, performing authentication, and using a second authentication factor to ensure secure access, with features like certificate validation and encrypted data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods are used, then ease of operation is maintained, but security against data interception deteriorates

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity against interception
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a protected website as an intermediary that establishes a secure communication channel between the client device and the authentication server. This intermediary validates certificates and encrypts data transmission, preventing malicious programs from intercepting authentication data while maintaining user-friendly operation through automatic certificate validation and encrypted channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If antivirus technologies are used, then detection of known malicious programs is improved, but protection against new modifications deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidprotection against new variants
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary validation of the protected website's certificate before authentication data is transmitted. By pre-establishing a trusted communication channel and validating the website's identity in advance, the system prevents interception by both known and unknown malicious programs, eliminating the need to constantly update detection signatures for new malware variants.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If OTP sending to mobile telephone is used, then authentication security is improved, but vulnerability to interception by malicious programs deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to interception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the SMS-based OTP delivery mechanism with a protected data transmission channel that uses certificate validation and encryption. This substitution eliminates the vulnerability to SMS interception by malicious programs while maintaining strong authentication security through encrypted communication between the client device and authentication server.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If certificate validation and protected channels are established, then security against interception is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against interceptionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The protected website automatically performs certificate validation and establishes encrypted communication channels without requiring user intervention. The system self-manages the security infrastructure, validating certificates and maintaining protected data transmission channels automatically, which reduces the perceived complexity for users while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3261009B1System and method for secure online authentication
Publication Date: 2020.04.22 AO KASPERSKY LAB
  • EP3261009B1 patent drawingFigure 1
  • EP3261009B1 patent drawingFigure 2
  • EP3261009B1 patent drawingFigure 3

AI summary

Disclosed are systems and methods for secure online authentication. An exemplary method comprises: determining, via a processor of a computing device, a connection being established between a browser application installed on a computer system and a protected website; obtaining information relating to the protected website in response to obtaining a request for authentication from the protected website; establishing a protected data transmission channel with the protected website to receive at least one certificate of the protected website; performing authentication and transmitting authentication data to the protected website; and in response to an indication of a successful authentication from the protected website, transmitting identification information to the browser application for enabling access to the protected website.