Virtual Keyboard Authentication to Block SMS Credential Fraud
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing two-factor authentication methods are vulnerable to unauthorized access when a compromised user device allows a bad actor to interact with text messages, enabling fraudulent acts by providing authentication credentials.
Innovation Solution
A user device provides a virtual keyboard for entering authentication credentials directly on the screen, processes the input using cryptographic techniques, and sends a secure message to the account device for authentication, reducing the risk of unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If text message authentication is used, then ease of operation is improved, but security is worsened due to vulnerability to unauthorized access
Solution Approach 1:
A virtual keyboard interface is introduced as an intermediary between the user and the authentication system. The virtual keyboard captures input directly within the messaging application, preventing external interception while maintaining user convenience. This mediator layer ensures that authentication credentials are entered through a controlled interface that obscures input from potential attackers.
Solution Approach 2:
The system preemptively prevents unauthorized access by implementing input obscuration and direct credential verification within the virtual keyboard. By processing authentication input locally and immediately verifying credentials without exposing them to external systems, the patent applies preliminary protective measures that block potential fraud before it can occur.
2Reliability
If virtual keyboard with input obscuration is used, then security is improved, but device complexity is worsened
Solution Approach 1:
The virtual keyboard is designed to perform multiple functions: it serves as both a standard text input mechanism and a secure authentication interface. By making the virtual keyboard multi-functional, the system avoids adding separate complex authentication hardware or software modules, thereby maintaining security enhancements while minimizing increases in overall device complexity.
Solution Approach 2:
The authentication functionality is merged with the existing virtual keyboard interface rather than being implemented as a separate system. This integration combines the familiar keyboard interaction model with security features, reducing the perceived complexity for users while implementing robust authentication protocols within the same interface.
3Productivity
If direct credential verification is implemented, then productivity is improved, but security is worsened due to potential fraud
Solution Approach 1:
The virtual keyboard acts as a trusted intermediary that captures authentication input directly within the secure context of the messaging application. This intermediary layer enables rapid credential verification by eliminating intermediate transmission steps, while simultaneously preventing fraud by ensuring that input is captured in a controlled environment that obscures it from external attackers.
Solution Approach 2:
The system performs self-verification of authentication credentials directly within the virtual keyboard interface without requiring external validation steps. This self-service approach accelerates the authentication process by eliminating delays associated with external verification systems, while the embedded security measures ensure that the self-verification process itself is resistant to fraud.
Data Source
AI summary
In some implementations, a user device may receive, from a first other device, a first message, wherein the first message includes information indicating an event associated with an account of a user of the user device. The user device may provide, based on receiving the first message, a virtual keyboard for display on a display screen of the user device. The user device may obtain, based on providing the virtual keyboard, particular input. The user device may send to a second other device, and based on the particular input, a second message, wherein sending the second message is to cause the second other device to perform one or more actions associated with the event that is associated with the account of the user.


