Trusted Device Mutual Authentication for Phishing Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anti-phishing methods are inadequate in protecting users against Man-in-the-Middle attacks, particularly when DNS spoofing is involved, as they rely heavily on user diligence and are susceptible to active attacks that can bypass traditional security measures.
Innovation Solution
A method that utilizes a trusted device, such as a cellphone, for mutual authentication between the user and the server, creating a public/private key pair and associating it with the server's information, ensuring that attackers must compromise both the user's password and the device to access accounts, thereby preventing Man-in-the-Middle attacks and keyloggers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-phishing methods (heuristics, password modification, origin authentication) are used, then users are provided with some level of protection, but they remain susceptible to Man-in-the-Middle attacks and require heavy reliance on user diligence
Solution Approach 1:
The patent introduces a trusted third-party authentication service that acts as an intermediary between the user and the phishing site. This service provides certificate-based authentication that mediates the security challenge, allowing users to authenticate against a trusted authority rather than relying solely on their own diligence or being vulnerable to MITM attacks.
Solution Approach 2:
The patent replaces manual user verification mechanisms with automated certificate-based authentication. Instead of relying on users to manually verify site authenticity (mechanical process), the system uses cryptographic certificates (automated mechanism) to provide reliable authentication that is resistant to phishing and MITM attacks.
2Ease of operation
If user-based authentication mechanisms are used, then authentication can be performed, but users must bear significant security responsibilities and remain vulnerable to attacks
Solution Approach 1:
The authentication service performs self-service by automatically verifying user identities and issuing certificates without requiring manual user verification. The system autonomously handles the security verification process, freeing users from security responsibilities while maintaining strong authentication security.
Solution Approach 2:
The trusted authentication service acts as an intermediary that assumes security responsibilities normally borne by users. It mediates between the user and the authentication process, providing secure authentication while eliminating the need for users to perform manual security verification.
3Productivity
If existing authentication systems are used, then users can access accounts, but attackers can intercept credentials and compromise accounts through active attacks
Solution Approach 1:
The patent replaces traditional credential-based authentication with certificate-based authentication. This substitution eliminates the vulnerability to credential interception, as cryptographic certificates provide a more secure mechanism that cannot be easily intercepted or stolen, thereby maintaining account access while significantly improving security.
Solution Approach 2:
The authentication service acts as a trusted intermediary that secures the authentication process. It mediates between the client and server, using certificate-based verification to ensure that credentials are not intercepted by attackers, thus maintaining both productivity and security.
Data Source
AI summary
Phishing attacks succeed by exploiting a user's inability to distinguish legitimate websites from spoofed websites. Most prior work focuses on assisting the user in making this distinction; however, users must make the right security decision every time. Unfortunately, humans are ill-suited for performing the security checks necessary for secure site identification, and a single mistake may result in a total compromise of the user's online account. Fundamentally, users should be authenticated using information that they cannot readily reveal to malicious parties. Placing less reliance on the user during the authentication process enhances security and eliminates many forms of fraud. We disclose using a trusted device to perform mutual authentication that eliminates reliance on perfect user behavior, thwarts Man-in-the-Middle attacks after setup, and protects a user's account even in the presence of keyloggers and most forms of spyware.


