Mutual authentication security system with detection and mitigation of active man-in-the-middle browser attacks, phishing, and malware and other security improvements
Abstract
A strong, unified and comprehensive new computer security and authentication solution is disclosed. It is ideal for everyday users, and invents faster and easier enrollments, faster usage, easier usage, numerous aspects of stronger security including token based rapid mutual-authentication with protection against phishing, MitM, malware and user carelessness, secure resilience against token loss or theft, continuing protection in harsh situations, non-repudiation benefits, biometric encryption, code self-defenses, improved deployment, lower costs, new revenue opportunities, and more. One aspect's flow, visually-enforced mutual-authentication is: customer visits protected web site's login page, gets identified via Cookies, site displays one random photograph on said page, triggers customer's smartphone to automatically show a grid of random photos, one of which matches the login page photo, and customer taps it to login. Disclosed techniques teach how to block fraudulent sites and activity by preventing these producing any matching photo the customer can tap.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method for a Provider to securely authenticate a User associated with an authentication request, the method comprising:
identifying the User associated with the authentication request, wherein the User is also associated with a security token; displaying to the User, one or more random images, wherein at least one of the random images is visually same as one or more images in the security token; requiring the User to select the one or more displayed images that are the same as the one or more images in the security token; based on the User's selection, associating one or more random codes with the selected one or more displayed images; communicating to an authenticator, the associated one or more random codes; and determining whether to permit or deny the authentication request based on the communicated code.
2 . The method of claim 1 , wherein the security token is protected by the User's biometric data, and wherein determining whether to permit or deny the authentication request further comprises determining whether there is a successful match with the User's biometric data.
3 . The method of claim 1 , wherein the security token is protected by the User's passcode, and wherein determining whether to permit or deny the authentication request further comprises determining whether there is a successful match with the User's passcode.
4 . The method of claim 1 , wherein determining whether to permit or deny the authentication request further comprises determining whether the User has completed one or more login steps to access a resource provided by the Provider, wherein the one or more login steps are accomplished by an automatic progression of one or more of the User's login steps to access the resource.
5 . A method for a Provider to securely authenticate a User associated with an authentication request, the method comprising:
requesting from the User associated with the authentication request, one or more personas associated with the User; supplying, to the User, one or more authentication requests, wherein the one or more authentication requests includes information identifying the Provider; requesting, from the User, one or more responses to the one or more authentication requests; and using a security token pre-associated with the user to complete the authentication request, wherein the authentication request is completed when the requested one or more responses are matched.
6 . The method of claim 5 , wherein the security token is protected by the User's biometric data, and wherein the authentication request is completed when there is a successful match with the User's biometric data.
7 . The method of claim 5 , wherein the security token is protected by the User's passcode, and wherein the authentication request is completed when there is a successful match with the User's passcode.
8 . The method of claim 5 , wherein:
supplying, to the User, one or more authentication requests, further comprises displaying, to the User, one or more images; requesting, from the User, one or more responses to the one or more authentication requests further comprises requiring the User to select one or more of displayed images; and using, a security token pre-associated with the user to complete the authentication request, further comprises matching the selected one or more images the displayed one or more images, and wherein the authentication request is completed when the one or more images are matched.
9 . The method of claim 8 , wherein the one or more displayed images comprise one or more of: (i) photographs; (ii) graphic images; (iii) shapes; (iv) computer-generated codes; (v) words; (vi) numbers; or (vii) symbols.
10 . The method of claim 8 , wherein the security token is protected by the User's biometric data, and wherein using a security token pre-associated with the user to complete the authentication request, further comprises matching User input data to the User's biometric data.
11 . The method of claim 8 , wherein the security token is protected by the User's passcode, and wherein using a security token pre-associated with the user to complete the authentication request, further comprises matching User input data to the User's passcode.
12 . A security token device to securely authenticate a User associated with an authentication request to a Provider, the security token device comprising:
a first component set, wherein the first component set comprises an assortment of random images selected from a large collection of images, wherein the assortment is selected by an entity associated with the Provider, and wherein each image in the assortment has random codes associated therewith; and a second component set, wherein the second component set comprises three or more of the following: (i) encryption keys; (ii) encryption salts; (iii) authentication appliance endpoint Uniform Resource Identifiers; (iv) serial numbers; (v) pairing-assistance Uniform Resource Locators; (vi) QR codes; (vii) a name of the Provider; (viii) a logo of the Provider; (ix) support staff information of the Provider; (x) notes; (xi) policy rules; (xii) layout and formatting information.
13 . The security token device of claim 12 , wherein the security token device is pre-associated with an identity-verified individual.
14 . The security token device of claim 12 , wherein the assortment of random images comprises one or more of: (i) photographs; (ii) graphic images; (iii) shapes; (iv) computer-generated codes; (v) words; (vi) numbers; or (vii) symbols.
15 . The security token device of claim 14 , wherein the security token device is pre-associated with an identity-verified individual.
16 . The security token device of claim 12 , wherein the security token device is protected by the User's password.
17 . The security token device of claim 12 , wherein the security token device is protected by the User's biometric data.
18 . The security token device of claim 12 , wherein the security token device is protected by the User's biometric-generated keys.
19 . A security token device to securely authenticate a User associated with an authentication request to a Provider, the security token device comprising:
one or more serial numbers; one or more machine-readable barcodes or QR codes; and an assortment of random images selected from a large collection of images, wherein the assortment is selected by an issuing entity associated with the Provider, and wherein each image in the assortment has random codes associated therewith.
20 . A method for a Provider to mutually authenticate a first party and a second party associated with a mutual authentication request, the method comprising:
providing to the first party a set of one or more random images, wherein each of the one or more random images in the set is associated with a random code; displaying to the second party, one or more of the random images in the set; selecting, by the second party, one or more of the random images in the set; displaying, to the first party, the one or more selected random images in the set; locating, by the first party, the one or more random codes associated with the one or more selected random images in the set; providing, by the first party, to the second party, the one or more located random codes associated with the one or more selected random images; and determining whether to permit or deny the mutual authentication request based on the provided one or more random codes.Join the waitlist — get patent alerts
Track US2020404019A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.