Translucent Identification Member for Phishing-Resistant Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mutual authentication methods are complex, costly, and impractical for widespread adoption, especially in online communication, as they often require expensive hardware and complex user interactions, and do not effectively address phishing attacks which can lead to identity theft and financial losses.

Innovation Solution

A method and apparatus that uses a translucent identification member with obscured identifiers, which are revealed when combined with a visual filtering pattern, providing a secure and inexpensive way for users to authenticate both themselves and the sender, without the need for electronic components or complex infrastructure, by generating challenges based on usage data and rule sets to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional mutual authentication methods are used, then security against phishing attacks is improved, but device complexity and cost increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses disposable, inexpensive translucent identification members (such as printed cards or stickers) that contain obscured identifiers. These can be easily distributed to users and discarded after use, eliminating the need for expensive, reusable hardware tokens while maintaining security through single-use challenge-response authentication.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent extracts the essential authentication function from complex hardware systems and implements it using simple visual elements. By taking out only the necessary identifier verification mechanism and implementing it through translucent materials with obscured patterns, the system achieves authentication without requiring expensive hardware infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If hardware-based second factor authentication is deployed, then authentication security is improved, but ease of manufacture and distribution deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces expensive hardware tokens with inexpensive, disposable translucent identification members that can be manufactured using simple printing or lamination processes. These can be mass-produced and distributed through conventional mail or digital delivery, dramatically improving ease of manufacture and distribution while maintaining authentication security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent substitutes mechanical/electronic hardware systems with optical/visual mechanisms. Instead of using electronic hardware tokens with complex circuits and power sources, the system uses translucent materials with obscured visual identifiers that can be verified through simple optical filtering, greatly simplifying manufacturing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual authentication steps are required, then security verification is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity verificationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses visual filtering patterns that change the appearance of obscured identifiers on the translucent identification member. When the filtering pattern is applied, specific identifiers become visible while others remain hidden, providing clear visual feedback to guide users through the authentication process without requiring complex manual steps.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces a visual filtering pattern as an intermediary element that mediates between the user and the authentication system. This filter helps users easily identify the correct obscured identifier on the translucent member by making it visually distinct, simplifying the user interaction while maintaining security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If static authentication identifiers are used, then system simplicity is improved, but reliability against replay attacks deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidprotection against replay attacks
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic authentication by generating new obscured identifiers for each authentication session. The translucent identification member contains multiple obscured identifiers that are revealed sequentially or selectively based on the session, preventing replay attacks while maintaining system simplicity through the use of pre-printed materials.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs periodic generation of new challenge identifiers in each authentication session. The system periodically presents different obscured identifiers from the translucent identification member, ensuring that each authentication attempt uses a fresh identifier rather than reusing static values, thereby protecting against replay attacks.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8966579B2Method and apparatus for providing authentication between a sending unit and a recipient based on challenge usage data
Publication Date: 2015.02.24 ENTRUST CORP
  • US8966579B2 patent drawing
  • US8966579B2 patent drawing
  • US8966579B2 patent drawing

AI summary

A method, apparatus and/or system generates a challenge for user authentication, having a challenge data element from a stored pool of challenge data elements. The challenge is based on rule data and stored usage data associated with at least some of the challenge data elements in the stored pool of challenge data elements. The generated challenge is sent for use in an authentication of a user to a sender. A method, apparatus and/or system also generates sender authentication and corresponding location information, having a data element from a stored pool of challenge data elements. Selection of the data elements is based on rule data and stored usage data associated with at least some of the data elements in the stored pool of data elements.