SMS OTP Interception for Phishing-Resistant Subscriber Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing two-factor authentication (2FA) methods, such as SMS-based and push notifications, are vulnerable to phishing and fraud, lacking robust security measures to ensure the authenticity of one-time passcodes (OTPs) and user verification.
Innovation Solution
A system intercepts SMS messages containing OTPs, verifies their origin, and delivers them securely to a carrier app on the mobile device as encrypted push notifications, enhancing user authentication with biometric verification and risk assessment features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SMS-based 2FA is used to send OTPs to mobile devices, then user authentication is enabled, but the system becomes vulnerable to phishing and fraud
Solution Approach 1:
The patent introduces an intermediary system between the SMS message and the user's messaging application. This intermediary intercepts OTP-containing SMS messages, verifies their authenticity through risk evaluation, and selectively blocks or delivers them. This mediator prevents phishing attacks by filtering out fraudulent messages before they reach the user, while still allowing legitimate OTPs through, thus resolving the contradiction between enabling authentication and preventing phishing vulnerability.
2Ease of operation
If push notification 2FA is used for authentication, then user verification is simplified, but security against fraudulent access is reduced
Solution Approach 1:
The patent applies preliminary action by performing risk evaluation and authentication verification before delivering the push notification to the user. The system pre-assesses the legitimacy of the authentication request by analyzing device characteristics, location data, and behavioral patterns. This preliminary security check ensures that even though push notifications are convenient, fraudulent access attempts are blocked before reaching the user, thus maintaining both ease of operation and reliability.
3Productivity
If OTP messages are delivered directly to messaging applications, then message delivery is simple, but security control over OTP distribution is lost
Solution Approach 1:
The patent introduces an intermediary component that sits between the SMS messaging system and the user's messaging application. This intermediary captures OTP-containing messages, performs security verification through risk evaluation, and then selectively forwards or blocks them. This approach maintains fast message delivery for legitimate OTPs while providing security control, resolving the contradiction between delivery speed and security control.
4Reliability
If risk evaluation and verification steps are added to 2FA, then security is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service by enabling the mobile device itself to perform risk evaluation and authentication verification through a dedicated application. The device collects its own data (location, device characteristics, behavioral patterns) and performs local analysis, reducing the need for complex centralized verification systems. This self-service approach improves security while minimizing the increase in overall system complexity by distributing the verification burden to the user's own device.
Data Source
AI summary
Aspects of the subject disclosure may include, for example, a device in a messaging core, that includes: a processing system including a processor; and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations including receiving a short messaging system (SMS) message from an application-to-person (A2P) service to a mobile device of a subscriber; verifying an origin of the SMS message; identifying the SMS message as bearing a one-time passcode (OTP); preventing delivery of the SMS message to a messaging application on the mobile device; and delivering the SMS message to an application running on the mobile device. Other embodiments are disclosed.


