Trust Factor Assessment Module for MFA Phishing Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online systems, particularly those using multi-factor authentication (MFA) or two-factor authentication (2FA), are vulnerable to phishing attacks such as 'man-in-the-middle' attacks, which can deceive users into providing access credentials, making it difficult to detect and prevent unauthorized access.

Innovation Solution

Implementing a trust factor assessment module on computing devices to evaluate the trust between devices involved in the authentication process, using information like IP addresses, geographic locations, and digital tokens to determine if the authentication step should proceed, and denying the step if insufficient trust is established.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented, then account security is improved, but the system becomes vulnerable to phishing attacks that deceive users into providing credentials

Engineering Contradiction:
Improveaccount securityVSAvoidphishing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trust factor assessment module as an intermediary between the authentication request and the authentication process. This module assesses trust factors based on device information, network conditions, and behavioral patterns before allowing MFA to proceed, thereby blocking phishing attempts while permitting legitimate authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary trust factor assessment before initiating the multi-factor authentication process. By evaluating device characteristics, network environment, and user behavior patterns in advance, the system can prevent phishing attacks before they compromise account security.

Inventive Principle:
Principle #10Preliminary action

2Difficulty of detecting and measuring

If trust factor assessment is added to detect phishing, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvephishing detection capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The trust factor assessment module is implemented as a separate, independent component that evaluates specific trust factors (device information, network conditions, behavioral patterns) independently. This segmentation allows the system to enhance detection capability without significantly complicating the core authentication flow.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trust factor assessment leverages existing device data and network information that are already available in the system, rather than requiring additional complex sensors or external services. The module uses self-contained algorithms to evaluate trust factors based on readily accessible information.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11558380B2Defending multi-factor authentication against phishing
Publication Date: 2023.01.17 PAYPAL INC
  • US11558380B2 patent drawing
  • US11558380B2 patent drawing
  • US11558380B2 patent drawing

AI summary

Techniques are disclosed relating to detecting and prevent phishing attacks (such as man-in-the-middle attacks) related to multi-factor authentication (MFA) or two-factor authentication (2FA) processes. A system is described that makes a determination of whether to permit or deny a subsequent authentication step (e.g., a 2FA authentication step) based on a level of trust determined between the computing device making the initial authentication request to a service computer system and the computing device being asked to implement the subsequent authentication step (such as a mobile device). The computing device associated with the subsequent authentication step assesses the trust between the devices and makes the determination of whether to permit or deny the subsequent authentication step. The present techniques enhance computer system security against phishing attacks while maintaining a satisfying user experience for legitimate users.