Trusted Device Mutual Authentication for Phishing Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-phishing methods are inadequate in protecting users against Man-in-the-Middle attacks, particularly when DNS spoofing is involved, as they rely heavily on user diligence and are susceptible to active attacks that can bypass traditional security measures.

Innovation Solution

A method that utilizes a trusted device, such as a cellphone, for mutual authentication between the user and the server, creating a public/private key pair and associating it with the server's information, ensuring that attackers must compromise both the user's password and the device to access accounts, thereby preventing Man-in-the-Middle attacks and keyloggers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-phishing methods (heuristics, password modification, origin authentication) are used, then users are provided with some level of protection, but they remain susceptible to Man-in-the-Middle attacks and require heavy reliance on user diligence

Engineering Contradiction:
Improveprotection against phishingVSAvoidvulnerability to Man-in-the-Middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted third-party authentication service that acts as an intermediary between the user and the phishing site. This service provides certificate-based authentication that mediates the security challenge, allowing users to authenticate against a trusted authority rather than relying solely on their own diligence or being vulnerable to MITM attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual user verification mechanisms with automated certificate-based authentication. Instead of relying on users to manually verify site authenticity (mechanical process), the system uses cryptographic certificates (automated mechanism) to provide reliable authentication that is resistant to phishing and MITM attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If user-based authentication mechanisms are used, then authentication can be performed, but users must bear significant security responsibilities and remain vulnerable to attacks

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication service performs self-service by automatically verifying user identities and issuing certificates without requiring manual user verification. The system autonomously handles the security verification process, freeing users from security responsibilities while maintaining strong authentication security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The trusted authentication service acts as an intermediary that assumes security responsibilities normally borne by users. It mediates between the user and the authentication process, providing secure authentication while eliminating the need for users to perform manual security verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If existing authentication systems are used, then users can access accounts, but attackers can intercept credentials and compromise accounts through active attacks

Engineering Contradiction:
Improveaccount accessVSAvoidaccount security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces traditional credential-based authentication with certificate-based authentication. This substitution eliminates the vulnerability to credential interception, as cryptographic certificates provide a more secure mechanism that cannot be easily intercepted or stolen, thereby maintaining account access while significantly improving security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication service acts as a trusted intermediary that secures the authentication process. It mediates between the client and server, using certificate-based verification to ensure that credentials are not intercepted by attackers, thus maintaining both productivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8352738B2Method and apparatus for secure online transactions
Publication Date: 2013.01.08 CARNEGIE MELLON UNIV
  • US8352738B2 patent drawing
  • US8352738B2 patent drawing
  • US8352738B2 patent drawing

AI summary

Phishing attacks succeed by exploiting a user's inability to distinguish legitimate websites from spoofed websites. Most prior work focuses on assisting the user in making this distinction; however, users must make the right security decision every time. Unfortunately, humans are ill-suited for performing the security checks necessary for secure site identification, and a single mistake may result in a total compromise of the user's online account. Fundamentally, users should be authenticated using information that they cannot readily reveal to malicious parties. Placing less reliance on the user during the authentication process enhances security and eliminates many forms of fraud. We disclose using a trusted device to perform mutual authentication that eliminates reliance on perfect user behavior, thwarts Man-in-the-Middle attacks after setup, and protects a user's account even in the presence of keyloggers and most forms of spyware.