Symbol-Based Multi-Factor Authentication Against Verbal Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication (MFA) methods, such as SMS OTP, are vulnerable to 'man-in-the-middle' attacks where a malicious person can manipulate the user into reading and verbally communicating numerical passcodes over the phone.
Innovation Solution
A system that uses a symbol composed of multiple elements, which is difficult to describe verbally, for MFA. The system transmits an image or animation of the authentication symbol to a user device and provides a user interface on a client device for the user to recreate the symbol by selecting and combining elements, allowing for secure authentication without relying on verbal descriptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If numerical passcodes are used for MFA, then authentication can be communicated verbally over the phone, but the system becomes vulnerable to man-in-the-middle attacks
Solution Approach 1:
The patent replaces the acoustic/verbal transmission mechanism with an optical/visual mechanism. Instead of communicating passcodes through sound waves (phone calls), the system transmits authentication symbols through light waves (display screens). This substitution fundamentally changes the physical medium of communication, making verbal interception impossible while maintaining the authentication function.
Solution Approach 2:
The patent changes the parameter of the authentication credential from numerical/alphanumeric characters to graphical symbols composed of multiple elements. This parameter change transforms the authentication data from something that can be easily verbalized into something that must be visually perceived and reproduced, thereby eliminating the vulnerability to verbal manipulation attacks.
2Reliability
If complex symbols composed of multiple elements are used for MFA, then security against man-in-the-middle attacks is improved, but the device complexity and user interface complexity increase
Solution Approach 1:
The patent segments the authentication symbol into multiple discrete elements that can be independently selected and combined. This segmentation allows the complex symbol to be broken down into manageable components, reducing the cognitive load on users while maintaining the security benefits of complexity. The user interface presents these segmented elements in a structured manner, making the interaction simpler despite the underlying complexity.
Solution Approach 2:
The patent uses copying by transmitting an image or animation of the authentication symbol to the user device, and then having the user recreate the symbol by selecting elements that match the transmitted image. This copying approach simplifies the user interface because users don't need to understand or generate the complex symbol from scratch - they only need to replicate what they see in the transmitted image, making the interaction intuitive despite the symbol's complexity.
3Reliability
If symbols are transmitted as images or animations, then verbal description is avoided, but data transmission requirements and processing increase
Solution Approach 1:
The patent employs dynamic animations instead of static images to convey the authentication symbol. The animation provides temporal dimension to the symbol representation, allowing the system to encode more information in a visually compact form. The animation can show the formation, transformation, or sequence of elements, reducing the need to transmit large amounts of static data while maintaining security against verbal manipulation.
Data Source
AI summary
In some implementations, a server device may receive, from a first device, a credential and a request to access a resource. The server device may transmit, to a second device associated with the credential, an image that includes a first symbol composed of a set of elements. The server device may receive, from the first device, information associated with a second symbol formed via user interaction with a user interface of the first device. The second symbol may be formed by dragging elements, presented via the user interface, to an area of the user interface in which the second symbol is to be formed, or drawing elements in the area of the user interface in which the second symbol is to be formed. The server device may grant or denying access to the resource based on the first symbol and the information associated with the second symbol.


