Website Verification Service Using Synchronized Multi-Modal Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity mechanisms are user-focused and rely on certificate authorities, which can be compromised by sophisticated cyber-attacks, leading to vulnerabilities in verifying the authenticity of websites.

Innovation Solution

A website verification service that generates and provides authentication credentials, including images, sounds, and tactile outputs, to both web browsers and verifier devices, allowing users to compare and verify the authenticity of websites through a synchronized temporal sequence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If certificate authorities are used to verify website authenticity, then website verification is simplified, but security reliability deteriorates due to potential certificate spoofing and compromise

Engineering Contradiction:
Improvewebsite verificationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a third-party verification service that acts as an intermediary between the user and the website. This service generates and distributes authentication credentials to both the user's device and the website server, creating an independent verification channel that does not rely on the website's own certificates or the user's memory, thereby resolving the trust issue while maintaining ease of verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where authentication credentials are dynamically generated and distributed to multiple devices, and verification results are fed back to users. This continuous verification loop ensures that authentication information is fresh and cannot be pre-stored or spoofed, improving both reliability and ease of operation

Inventive Principle:
Principle #23Feedback

2Device complexity

If authentication credentials are provided only through traditional means, then system complexity is low, but security against sophisticated cyber-attacks deteriorates

Engineering Contradiction:
Improveauthentication systemVSAvoidcyber-attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into multiple independent components: a verification service, user devices, and website servers. Each component receives and processes authentication credentials separately, distributing the security burden and preventing single-point failures or attacks. This segmentation increases security against sophisticated cyber-attacks while maintaining manageable system complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to authentication by introducing temporal sequencing and synchronization. Authentication credentials are not just static data but time-sensitive information that must be verified in real-time across multiple devices. This temporal dimension makes it extremely difficult for attackers to spoof or reuse credentials, significantly improving security without overwhelming complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If multiple authentication credentials are provided through synchronized temporal sequence, then security reliability is improved, but device complexity and operation difficulty increase

Engineering Contradiction:
Improveauthentication securityVSAvoidverification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification service automatically generates, distributes, and manages authentication credentials without requiring manual intervention. The system self-synchronizes timestamps and automatically verifies credentials across devices, eliminating the need for users to manually coordinate verification steps. This automation improves security through multiple credentials while keeping device complexity manageable through centralized service coordination

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12003497B2Website verification service
Publication Date: 2024.06.04 AT&T INTELLECTUAL PROPERTY I L P
  • US12003497B2 patent drawing
  • US12003497B2 patent drawing
  • US12003497B2 patent drawing

AI summary

The concepts and technologies disclosed herein are directed to a website verification service. A system can receive, from a web server that hosts a website, a query for a set of authentication credentials (“credentials”) to be used to verify that the website is trustworthy. The system can generate and provide the credentials to the web server. The web server can, in turn, provide the credentials to a web browser device for presentation to a user via a web browser application executing on the web browser device. The system also can provide the credentials to a verifier device. The verifier device can present the credentials to the user via a verifier application executing on the verifier device. The user can compare the credentials presented via the web browser application to the credentials presented via the verifier application executing on the verifier device to determine whether the website can be trusted.