Third-Party Security App for SMS Authentication Token Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current second factor authentication systems, particularly those using SMS-based protocols, are vulnerable to phishing attacks and lack effective mechanisms to ensure the authenticity of verification codes, leading to potential security breaches.
Innovation Solution
A computer-implemented method and system that monitors the reception of second factor authentication tokens, verifies their validity by checking against a trusted SMS short-code database, and performs security actions to protect user accounts, ensuring that verification codes are only input into legitimate applications or browsers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SMS-based second factor authentication is implemented, then authentication security is improved compared to static passwords, but the system becomes vulnerable to phishing attacks and lacks verification of code authenticity
Solution Approach 1:
The patent introduces a security application as an intermediary layer between the user and the authentication system. This intermediary monitors SMS messages, verifies their authenticity through multiple checks (message format, short-code validation, template matching), and controls whether verification codes can be entered. This mediator resolves the contradiction by adding verification capabilities without changing the underlying SMS authentication mechanism.
Solution Approach 2:
The security application performs preliminary actions by monitoring and validating SMS messages before the user can input verification codes. It checks message formats, validates short-codes against a database, and verifies templates in advance, preventing phishing attacks before they can compromise authentication security.
2Ease of operation
If verification codes are transmitted via SMS, then user-friendly authentication is achieved, but there is no mechanism to ensure codes are input into legitimate applications
Solution Approach 1:
The security application implements feedback mechanisms that monitor the authentication flow and provide real-time validation. It checks whether SMS messages match expected formats, validates short-codes against stored templates, and provides feedback to block code entry into unauthorized applications, ensuring code input integrity while maintaining ease of use.
Solution Approach 2:
The security application acts as an intermediary that sits between the SMS message reception and the verification code input fields. It monitors the authentication flow, validates message authenticity, and controls whether codes can be entered, resolving the contradiction between ease of operation and code input integrity.
3Reliability
If a third-party security application monitors SMS messages, then authentication security is enhanced, but device permissions and system integration complexity increase
Solution Approach 1:
The security application leverages existing device capabilities and operating system features to perform monitoring and validation functions. It uses built-in SMS reception capabilities, integrates with notification systems, and utilizes device storage for template databases, reducing the need for complex custom implementations while maintaining enhanced security.
Data Source
AI summary
The disclosed computer-implemented method for securing authentication procedures includes (i) monitoring, by a third-party security application, to detect reception of a second factor authentication token as an input to complete a second factor authentication procedure in connection with a second application that is independent from the third-party security application, (ii) verifying, by the third-party security application, whether or not the second factor authentication token was transmitted by a valid server in coordination with the second application as part of an authentic version of the second factor authentication procedure, and (iii) performing a security action to protect a user account based on a result of verifying whether or not the second factor authentication token was transmitted by the valid server in coordination with the second application as part of the authentic version of the second factor authentication procedure.


