All news

NEWS

Exact-Action Authorization: Proving What Was Authorized

· Chrome Roads

We have created a big hammer for a very big security problem.

Most security systems are designed to answer one question: Who are you?

We think an increasingly important question is: What, exactly, did you authorize?

Chrome Roads has been developing a new approach to transaction security we call exact-action authorization and cross-channel verification — designed to cryptographically bind a person’s approval to the action and terms they intended.

Consider a wire transfer.

It is one thing to authenticate the customer. It is another to prove that the customer approved:

  • this amount
  • to this destination
  • under these terms

—and that what the institution ultimately executes is the same transaction that was authorized.

That distinction matters far beyond banking.

The same architecture can help protect a sensitive document transfer, approval of a high-value enterprise action, a change to an industrial system, or a critical customer interaction.

And it is cross-channel.

The architecture is designed to extend cryptographically verifiable authorization across web, mobile, messaging, email, voice and other communications channels.

Underneath it is modern cryptographic authentication, including FIDO2/WebAuthn, combined with mechanisms that bind authorization to the action itself rather than simply granting access to an account or session.

We recently filed a portfolio of related provisional patent applications around this technology.

The first implementations can run on modern smartphones, making the technology deployable through existing mobile applications.

Our forthcoming Chrome Roads Card will provide a purpose-built endpoint for applications requiring still higher levels of security and assurance.

There is another reason the timing matters.

OpenAI, Anthropic, AWS, Microsoft and more than 100 other organizations warned this week that AI is rapidly changing the cyber threat environment, making sophisticated attacks cheaper and more accessible and creating what they describe as a limited window to strengthen defenses. (Axios)

At the same time, AI agents are beginning to take actions on behalf of people and organizations.

That makes the authorization question even more important: Not simply what can an AI agent do — but what, exactly, was it authorized to do?

The larger idea is simple: Authentication should not stop at proving identity.

It should be possible to prove intent.

For financial transactions, customer communications, document transfers and other high-consequence actions, we think that can meaningfully raise the security bar.

We’re now looking for technology and implementation partners across industries who can bring this capability into real customer environments.

If you work with customers where proving exactly what was authorized matters, we’d like to talk.

Email us at info@chromeroads.com.

Originally posted on LinkedIn.