US2020404019A1PendingUtilityA1

Mutual authentication security system with detection and mitigation of active man-in-the-middle browser attacks, phishing, and malware and other security improvements

Assignee: DRAKE CHRISTOPHER NATHAN TYRWHITTPriority: May 30, 2016Filed: Jan 23, 2020Published: Dec 24, 2020
Est. expiryMay 30, 2036(~9.8 yrs left)· nominal 20-yr term from priority
H04L 9/0838G06F 21/36H04L 2209/80H04W 12/77H04L 63/1466G06F 21/606H04L 63/061H04L 63/18H04L 9/3226H04L 63/0428H04L 63/0853H04L 9/3273H04W 12/06H04W 12/02H04W 12/00522
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A strong, unified and comprehensive new computer security and authentication solution is disclosed. It is ideal for everyday users, and invents faster and easier enrollments, faster usage, easier usage, numerous aspects of stronger security including token based rapid mutual-authentication with protection against phishing, MitM, malware and user carelessness, secure resilience against token loss or theft, continuing protection in harsh situations, non-repudiation benefits, biometric encryption, code self-defenses, improved deployment, lower costs, new revenue opportunities, and more. One aspect's flow, visually-enforced mutual-authentication is: customer visits protected web site's login page, gets identified via Cookies, site displays one random photograph on said page, triggers customer's smartphone to automatically show a grid of random photos, one of which matches the login page photo, and customer taps it to login. Disclosed techniques teach how to block fraudulent sites and activity by preventing these producing any matching photo the customer can tap.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A method for a Provider to securely authenticate a User associated with an authentication request, the method comprising:
 identifying the User associated with the authentication request, wherein the User is also associated with a security token;   displaying to the User, one or more random images, wherein at least one of the random images is visually same as one or more images in the security token;   requiring the User to select the one or more displayed images that are the same as the one or more images in the security token;   based on the User's selection, associating one or more random codes with the selected one or more displayed images;   communicating to an authenticator, the associated one or more random codes; and   determining whether to permit or deny the authentication request based on the communicated code.   
     
     
         2 . The method of  claim 1 , wherein the security token is protected by the User's biometric data, and wherein determining whether to permit or deny the authentication request further comprises determining whether there is a successful match with the User's biometric data. 
     
     
         3 . The method of  claim 1 , wherein the security token is protected by the User's passcode, and wherein determining whether to permit or deny the authentication request further comprises determining whether there is a successful match with the User's passcode. 
     
     
         4 . The method of  claim 1 , wherein determining whether to permit or deny the authentication request further comprises determining whether the User has completed one or more login steps to access a resource provided by the Provider, wherein the one or more login steps are accomplished by an automatic progression of one or more of the User's login steps to access the resource. 
     
     
         5 . A method for a Provider to securely authenticate a User associated with an authentication request, the method comprising:
 requesting from the User associated with the authentication request, one or more personas associated with the User;   supplying, to the User, one or more authentication requests, wherein the one or more authentication requests includes information identifying the Provider;   requesting, from the User, one or more responses to the one or more authentication requests; and   using a security token pre-associated with the user to complete the authentication request, wherein the authentication request is completed when the requested one or more responses are matched.   
     
     
         6 . The method of  claim 5 , wherein the security token is protected by the User's biometric data, and wherein the authentication request is completed when there is a successful match with the User's biometric data. 
     
     
         7 . The method of  claim 5 , wherein the security token is protected by the User's passcode, and wherein the authentication request is completed when there is a successful match with the User's passcode. 
     
     
         8 . The method of  claim 5 , wherein:
 supplying, to the User, one or more authentication requests, further comprises displaying, to the User, one or more images;   requesting, from the User, one or more responses to the one or more authentication requests further comprises requiring the User to select one or more of displayed images; and   using, a security token pre-associated with the user to complete the authentication request, further comprises matching the selected one or more images the displayed one or more images, and wherein the authentication request is completed when the one or more images are matched.   
     
     
         9 . The method of  claim 8 , wherein the one or more displayed images comprise one or more of: (i) photographs; (ii) graphic images; (iii) shapes; (iv) computer-generated codes; (v) words; (vi) numbers; or (vii) symbols. 
     
     
         10 . The method of  claim 8 , wherein the security token is protected by the User's biometric data, and wherein using a security token pre-associated with the user to complete the authentication request, further comprises matching User input data to the User's biometric data. 
     
     
         11 . The method of  claim 8 , wherein the security token is protected by the User's passcode, and wherein using a security token pre-associated with the user to complete the authentication request, further comprises matching User input data to the User's passcode. 
     
     
         12 . A security token device to securely authenticate a User associated with an authentication request to a Provider, the security token device comprising:
 a first component set, wherein the first component set comprises an assortment of random images selected from a large collection of images, wherein the assortment is selected by an entity associated with the Provider, and wherein each image in the assortment has random codes associated therewith; and   a second component set, wherein the second component set comprises three or more of the following: (i) encryption keys; (ii) encryption salts; (iii) authentication appliance endpoint Uniform Resource Identifiers; (iv) serial numbers; (v) pairing-assistance Uniform Resource Locators; (vi) QR codes; (vii) a name of the Provider; (viii) a logo of the Provider; (ix) support staff information of the Provider; (x) notes; (xi) policy rules; (xii) layout and formatting information.   
     
     
         13 . The security token device of  claim 12 , wherein the security token device is pre-associated with an identity-verified individual. 
     
     
         14 . The security token device of  claim 12 , wherein the assortment of random images comprises one or more of: (i) photographs; (ii) graphic images; (iii) shapes; (iv) computer-generated codes; (v) words; (vi) numbers; or (vii) symbols. 
     
     
         15 . The security token device of  claim 14 , wherein the security token device is pre-associated with an identity-verified individual. 
     
     
         16 . The security token device of  claim 12 , wherein the security token device is protected by the User's password. 
     
     
         17 . The security token device of  claim 12 , wherein the security token device is protected by the User's biometric data. 
     
     
         18 . The security token device of  claim 12 , wherein the security token device is protected by the User's biometric-generated keys. 
     
     
         19 . A security token device to securely authenticate a User associated with an authentication request to a Provider, the security token device comprising:
 one or more serial numbers;   one or more machine-readable barcodes or QR codes; and   an assortment of random images selected from a large collection of images, wherein the assortment is selected by an issuing entity associated with the Provider, and wherein each image in the assortment has random codes associated therewith.   
     
     
         20 . A method for a Provider to mutually authenticate a first party and a second party associated with a mutual authentication request, the method comprising:
 providing to the first party a set of one or more random images, wherein each of the one or more random images in the set is associated with a random code;   displaying to the second party, one or more of the random images in the set;   selecting, by the second party, one or more of the random images in the set;   displaying, to the first party, the one or more selected random images in the set;   locating, by the first party, the one or more random codes associated with the one or more selected random images in the set;   providing, by the first party, to the second party, the one or more located random codes associated with the one or more selected random images; and   determining whether to permit or deny the mutual authentication request based on the provided one or more random codes.

Join the waitlist — get patent alerts

Track US2020404019A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.