Methods for processing an electronic message and detecting identity theft, associated systems

By generating electronic messages with traceability data linked to static identification data, the method automatically detects identity theft, addressing the limitations of user-dependent detection and preventing fraudulent activities.

FR3160533A1Pending Publication Date: 2025-09-26ORANGE SA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2024002931
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-25
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Existing methods are inadequate in detecting identity theft independently of user suspicions, leading to potential fraudulent activities, and require user confirmation that may not always be feasible.

Method used

A method is introduced to generate an electronic message with traceability data, linking it to static identification data, enabling automatic detection of identity theft by comparing traceability data in suspicious messages with stored correspondence information.

Benefits of technology

This approach allows for immediate detection of identity theft without user confirmation, preventing fraudulent activities by ensuring the authenticity of electronic messages.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Methods for processing an electronic message and detecting identity theft, associated systems The invention relates in particular to a method for processing an initial electronic message sent by a sending device, said method comprising steps of: - generating (F20), from the initial message, an electronic message comprising at least one traceability data item, - storing (F40) information on correspondence between said at least one traceability data item and at least one identification data item of a user of said sending device. This method is used in particular in the detection of identity theft. Figure for the abstract: Fig. 5
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Methods for processing an electronic message and detecting identity theft, associated systems Prior art

[0001] The present invention belongs to the general field of telecommunications. It relates more particularly to a method for processing an electronic message intended for a user of a receiving device, a method for detecting identity theft of this user as well as systems configured to implement these methods.

[0002] Generally speaking, identity theft refers to the use of personal information that allows a person to be identified without their consent to carry out fraudulent actions.

[0003] In practice, this personal information may have been obtained following the loss or theft of the victim's identity documents, through a phishing message, by hacking one of their online accounts or one of their devices or even by hacking a website on which this information was recorded, etc.

[0004] Depending on the information gathered, a usurper can commit various offenses in the victim's name: opening a telephone line or bank account, creating accounts on social networks, taking out a loan, renting a car, defrauding relatives, false classified ads, defamation, etc. Beyond the moral prejudice, identity theft can therefore have very significant consequences for victims who can lose all or part of their money, but also find themselves prosecuted for offenses for which they will have to prove that they were not the perpetrators.

[0005] The ever-increasing development of digital uses, supported by the increase in telecommunications means, has resulted in an increase in cases of identity theft. Indeed, users exchange a lot of personal data via telecommunications networks, more particularly by means of various electronic messaging applications (electronic mail, also known as email, SMS (Short Message Service), MMS (Multimedia Message Service), instant messaging, etc.).

[0006] An example of an identity theft scenario, based on the theft of personal information contained in electronic messages such as email, is illustrated in [Fig.l].

[0007] In [Fig.l], a first user A transmits an electronic message MESS to a second user B (step E10). The MESS message is an email, which is stored in the electronic mailbox MB_B (“Mail Box” in English) of user B (step E20).

[0008] Subsequently, a third malicious user C hacks into the electronic mailbox MB_B of user B (step E30). During this hacking, he retrieves in particular the message MESS, or more simply consults it, so as to extract at least one identification data DATA_ID_A of user A (step E40).

[0009] Said at least one identification data DATA_ID_A includes for example the electronic address of user A (email address), the name of user A, the first name of user A, etc.

[0010] Being in possession of said at least one piece of identification data DATA_ID_A, the malicious user C is now able to usurp the identity of the user A. To this end, said user C generates a MESS_FAKE message using said at least one piece of identification data DATA_ID_A (step E50), and transmits this MESS_FAKE message to a fourth user D (step E60). Said MESS_FAKE message aims for example to obtain a sum of money, to request a modification of bank details, etc.

[0011] Said user D is typically a trusted person known to user A, and whose identity is known to malicious user C, for example following hacking of user B's email inbox (e.g.: user D was copied on an email sent to user B from user A).

[0012] In the current state of the art, two cases can therefore arise. In the first case, user D has no doubts about the authenticity of the MESS_FAKE message. In other words, user D does not detect the identity theft attempt made by user C, which is obviously problematic since it allows user C to commit a crime.

[0013] In a second case, user D may raise suspicions about the authenticity of the origin of the MESS_FAKE message, and report this to user A. However, for user D to obtain confirmation of the lack of authenticity of the MESS_FAKE message, user A must take the step of responding to user D. This way of proceeding, however, proves to be restrictive because it involves user D waiting for user A's response to dispel the suspicions raised. In addition, user A may not be able to respond to user D (e.g.: absence of user A, temporary inability of user A to have access to a suitable device to transmit a response, etc.). However, without this response, user D's suspicions cannot be confirmed, so that the latter may ultimately wrongly believe in the validity of the MESS_FAKE message and thus allow malicious user C to commit a crime.

[0014] Statement of the invention

[0015] The present invention aims to remedy all or part of the drawbacks of the prior art, in particular those set out above, by proposing a solution which makes it possible to prevent the consequences of fraudulent use of identification data obtained by usurpation more effectively than the solutions of the state of the art. In particular, the solution proposed by the invention responds advantageously to the problematic cases identified above by making it possible to detect identity theft independently of suspicions expressed by a user having received a suspicious message.

[0016] To this end, and according to a first aspect, the invention relates to a method for processing an initial electronic message sent by a sending device, said method comprising steps of: - generation, from the initial electronic message, of an electronic message containing at least one traceability data item, - storage of correspondence information between said at least one traceability data item and at least one identification data item of a user of said transmitting device.

[0017] Said at least one identification data item typically corresponds to information of a static nature relating to the identity of the user of the transmitting device. By "of a static nature", reference is made here to information which, by nature, does not vary over time, or at least is not intended to vary over time.

[0018] The message generated from the initial message can be generated in different ways. For example, said generation can include an insertion of said at least one traceability data in the initial message.

[0019] This generation of said message from the initial message is carried out automatically, and, insofar as it is based on one or more static data relating to the identity of the sender, it offers the possibility of “signing” the electronic message generated via the presence of said at least one traceability data.

[0020] This signature of the electronic message with said at least one traceability data item is advantageous because it makes it possible to guarantee the origin of the electronic message, together with said correspondence information. The latter is in fact configured so as to establish (and store) the link between said at least one traceability data item and said at least one identification data item. Thus, said in correspondence formation uniquely characterizes the association of said at least one traceability data item with said at least one identification data item.

[0021] All of these provisions therefore make it easier to detect identity theft, as explained in more detail below, and therefore offer the possibility of triggering actions to avoid the consequences resulting from fraudulent actions carried out in the continuity of identity theft.

[0022] In particular embodiments, the treatment method may further comprise one or more of the following characteristics, taken in isolation or in all technically possible combinations.

[0023] In particular embodiments, said at least one traceability data item is generated by encryption of said at least one identification data item, for example by means of a hash function.

[0024] In particular modes of implementation, said at least one traceability data item comprises at least one data item from: - a numerical value, - an image, - a graphic code, - a string of characters.

[0025] In particular embodiments, said at least one piece of identification data comprises at least one piece of data from: - an email address of the user of the sending device, - a name and / or first name of the user of the transmitting device, - location information of the user of the transmitting device, - a telephone number of the user of the transmitting device.

[0026] In particular modes of implementation, said at least one traceability data item is generated, from at least one auxiliary data item among: - a date and / or time of sending the electronic message, - identification data of a user to whom the electronic message is intended, the correspondence information being representative of the fact that said at least one traceability data item was generated from said at least one auxiliary data item.

[0027] In a second aspect, the invention relates to a method for detecting identity theft of a user of a device sending an initial electronic message previously processed according to the invention. Said detection method comprises steps of: - reception, from a device, called a “third-party device”, of a set of data associated with an electronic message, called a “suspicious message”, comprising said at least one traceability data item, - detection of possible identity theft based on said correspondence information associated with said at least one traceability data item.

[0028] Thus, the detection method according to the invention takes advantage of the processing applied to the initial message (via the processing method according to the invention) insofar as it advantageously makes it possible to automatically detect an identity theft of the user having sent said initial message.

[0029] This detection is based on the absence of correspondence between: - the traceability data taken by the usurper in the suspicious message that he sends to the third-party device, the use of this or these traceability data aimed at passing himself off as the user who originated the initial message to the user of the third-party device (i.e. the usurper “signs” the suspicious message in a similar manner to the initial message), and - the identification data included in this suspicious message. This or these identification data include data relating to the user of the suspicious device (e.g.: email address of the imposter) which could therefore not have been used to generate said traceability data.

[0030] In particular embodiments, the detection method may further comprise one or more of the following characteristics, taken in isolation or in all technically possible combinations.

[0031] In particular embodiments, the detection method further comprises, if identity theft is detected, a step of transmitting to the user of the third-party device a confirmation message that the identity of the user of the sending device has been usurped.

[0032] In particular embodiments, the detection method further comprises, if identity theft is detected, a step of transmitting to the user of the transmitting device an alert message indicating that the identity of said user has been usurped.

[0033] In particular embodiments, the initial message has been previously processed according to the invention so that said at least one traceability data item is also generated from at least one auxiliary data item, said at least one auxiliary data item comprising identification data of a user for whom the initial message is intended, said method further comprising, if identity theft is detected, a step of transmitting to said user for whom the initial message is intended and using said correspondence information an alert message indicating that the identity of the user of the sending device has been usurped.

[0034] In particular modes of implementation, the set of data associated with the suspicious message comprises: - at least one first piece of data contained in the suspicious message and belonging to said at least one traceability data contained in said initial message, - at least one second identification data item of a user of the suspect device, and in which the detection step comprises a verification, based on said correspondence information, of whether said at least one first data item was generated from said at least one second data item, identity theft being detected if the verification is not satisfied.

[0035] In particular modes of implementation: - the initial message has been previously processed according to the invention so that said at least one traceability data item is also generated from at least one auxiliary data item, and - the set of data associated with the suspicious message further comprises at least one third piece of data among said at least one auxiliary piece of data associated with the initial message, the verification also consisting of verifying, based on said correspondence information, whether said at least one first data item was generated from said at least one second data item and said at least one third data item, identity theft being detected if the verification is not satisfied.

[0036] In particular embodiments, the detection method further comprises a step of storing information, called “alert information”, representative of the identity of the user of the suspect device.

[0037] According to a third aspect, the invention relates to a computer program comprising instructions for implementing a processing method according to the invention and / or a detection method according to the invention when said program is executed by a computer.

[0038] This program may use any programming language, and be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0039] According to a fourth aspect, the invention relates to a computer-readable information or recording medium on which a computer program according to the invention is recorded.

[0040] The information or recording medium may be any entity or device capable of storing the program. For example, the medium may comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a hard disk.

[0041] On the other hand, the information or recording medium may be a transmissible medium such as an electrical or optical signal, which may be conveyed via a cable electrically or optically, by radio or by other means. The program according to the invention can in particular be downloaded from an Internet-type network.

[0042] Alternatively, the information or recording medium may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the method in question.

[0043] According to a fifth aspect, the invention relates to a processing device comprising means configured to implement a method for processing an electronic message according to the invention.

[0044] For example, the processing device may be or be part of a server, such as a messaging server, or a communications terminal.

[0045] In particular, the processing device can integrate storage means (example: database server) adapted to the storage of correspondence information.

[0046] Alternatively, these storage means may be external to the processing device, so that said processing device and said storage means form a processing system capable of implementing the processing method according to the invention.

[0047] According to a sixth aspect, the invention relates to a detection device comprising means configured to implement a method for detecting identity theft according to the invention.

[0048] For example, the detection device may be or be part of a server, such as a messaging server, or a communications terminal.

[0049] In particular, the detection device can integrate storage means (example: database server) adapted to the storage of alert information.

[0050] Alternatively, these storage means may be external to the detection device, so that said detection device and said storage means form a detection system capable of implementing the detection method according to the invention.

[0051] Brief description of the drawings

[0052] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures:

[0053] [Fig.l] [Fig.l], already described, schematically represents an example of an identity theft scenario, based on the theft of personal information contained in electronic messages;

[0054] [Fig.2] [Fig.2] schematically represents, in its environment, a particular embodiment of a digital identity protection system according to the invention;

[0055] [Fig.3] [Fig.3] schematically represents an example of hardware architecture of an electronic message processing device belonging to the digital identity protection system of [Fig.2];

[0056] [Fig.4] [Fig.4] schematically represents an example of hardware architecture of an identity theft detection device belonging to the digital identity protection system of [Fig.2];

[0057] [Fig.5] [Fig.5] represents, in the form of a flowchart, a particular mode of implementation of a communication method, called “general method”, the steps of which are implemented by the digital identity protection system of [Fig.2]. Said general method includes a processing method implemented by the processing device of [Fig.3] as well as an identity theft detection method implemented by the detection device of [Fig.4];

[0058] [Fig.6] [Fig.6] represents an example of written content of an electronic message of the email type sent by a user A, before said message has been processed in accordance with the processing method of [Fig.5];

[0059] [Fig.7] [Fig.7] represents an example of written content of the electronic message of [Fig.6], after said message has been processed in accordance with the processing method of [Fig.5];

[0060] [Fig.8] [Fig.8] represents an example of written content of an electronic message of the email type aimed at usurping the identity of user A who sent the initial message of [Fig.6].

[0061]

[0062] Description of embodiments

[0063] [Fig.2] schematically represents, in its environment, a particular embodiment of a digital identity protection system 100 according to the invention.

[0064] The system 100 of [Fig.2] is configured to carry out processing operations making it possible to modify an initial electronic message MESS sent by a sending terminal UE_A belonging to a first user A (Alice) and intended for a receiving terminal UE_B belonging to a second user B (Bob), by implementing a method according to the invention for processing said digital message MESS. For this purpose, the system 100 comprises, in the mode described here, a processing device 110 as well as a first database server 120. The processing device 110 and the first database server 120 thus form a processing system integrated into the digital identity protection system 100.

[0065] In the embodiment described with reference to [Fig.2], the system 100 is also configured to detect identity theft of user A, by implementing a method according to the invention for detecting identity theft. For this purpose, the system 100 also comprises a detection device 130 as well as a second database server 140. The detection device 130 and the second database server 140 thus form a detection system integrated into the digital identity protection system 100

[0066] The configurations, functionalities and uses of said processing 110 and detection 130 devices, of said first and second databases 120, 140, as well as examples of implementations of said processing and detection methods are described in more detail later.

[0067] For the remainder of the description, it is considered in a non-limiting manner that the entities respectively operating the processing device 110 and the first database server 120 on the one hand, and the detection device 130 and the second database server 140 on the other hand, are identical or constitute a single entity (e.g.: same commercial company). Of course, such provisions are not limiting of the invention, and nothing excludes the possibility of these entities being distinct.

[0068] More particularly, in the present embodiment, the system 100 is integrated into a service platform. By “service platform”, we refer here to a platform operated by a communications operator (e.g.: Orange) to offer data processing services, in particular electronic message processing.

[0069] It is further considered in the following that the transmitter terminal UE_A and the receiver terminal UE_B are both smartphones. It is further considered that the electronic message MESS sent by the transmitter terminal UE_A is an email. This email was notably written by the user A by means of an appropriate interface of the transmitter terminal UE_A, and is intended to be consulted (i.e. read) by the user B by means of an appropriate interface of the receiver terminal UE_B.

[0070] These provisions are not, however, limiting of the invention. In particular, no limitation is attached to the nature of said transmitter terminals UE_A and receiver terminals UE_B since they are capable of exchanging electronic messages. Thus, nothing precludes envisaging, for example, that a terminal (transmitter / receiver) is a digital tablet, a laptop computer, a personal assistant, an electronic reader, etc.

[0071] More generally, considering communication terminals constitutes only one variant embodiment of the invention. Thus, depending on the context of application envisaged for the invention, any type of appropriate communication device can be considered, such as for example a server.

[0072] Similarly, considering a MESS electronic message of type Email is not limiting of the invention, which can be implemented regardless of the nature of said electronic message MESS. Thus, it can be for example an SMS, MMS type message, an instant message (i.e. a message exchanged during an online dialogue, "chat" in English), etc.

[0073] The data exchanges between the system 100 and the terminals UE_A, UE_B are carried out via a communication network. Any type of communication network can be envisaged within the framework of the present invention (e.g.: Internet network, local network, LAN network, WAN network, WLAN network, etc.).

[0074] The absence of limitation concerning the nature of the communication network also extends to the nature of the communication protocol(s) used by the different entities (terminals UE_A, UE_B, system 100) to enable them to exchange data via said network, including in particular electronic messages. Generally speaking, these aspects are well known to those skilled in the art and are not described further here.

[0075] In the present embodiment, the routing of the MESS message from the terminal UE_A to the terminal UE_B is here taken care of by the system 100. As a result, said system 100 comprises a messaging server (not shown in the figures), and is therefore also configured in hardware and software to allow the management (reception, sending, redirection, storage, archiving, etc.) of emails.

[0076] It is also noted that the fact of only considering a single messaging server implies in particular that the email addresses respectively used by the sending terminal UE_A and the receiving terminal UE_B are hosted and managed at the level of this single messaging server, the latter being operated by a single messaging operator. That being said, nothing excludes considering, according to other examples not detailed here, that the system 100 comprises two separate messaging servers and respectively associated with the two sending terminals UE_A, receiving UE_B (e.g.: a first messaging server managed by Google (gmail) for the sending terminal UE_A, and a second messaging server managed by Orange (Orange mail) for the receiving terminal UE_B).

[0077] [Fig. 3] schematically represents an example of hardware architecture of the processing device 110 included in the system 100 of [Fig. 2]. Of course, a processing device included in a communication terminal, such as the transmitter terminal UE_A, has a similar hardware architecture.

[0078] As illustrated by [Fig. 3], the device 110 has the hardware architecture of a computer. Thus, the device 110 comprises, in particular, a processor 110_1, a random access memory 110_2, a read only memory 110_3 and a non-volatile memory 110_4. It also has communication means 110_5.

[0079] The read-only memory 110_3 of the device 110 constitutes a recording medium according to the invention, readable by the processor 110_l and on which is recorded a computer program PROG_110 according to the invention, comprising instructions for executing steps of the processing method. The program PROG_110 defines functional modules of the device 110, which rely on or control the hardware elements 110_l to 110_5 of the device 110 cited above. These functional modules are illustrated in [Fig. 3] in a non-limiting manner, and are described in more detail below with reference to different modes of implementation.

[0080] The communication means 110_5 allow the device 110 to exchange (transmission / reception) data with one or more other entities of the system 100. For this purpose, and as mentioned above, these communication means 110_5 rely on a communication interface, which may be wired or wireless, using any communication protocol known to those skilled in the art.

[0081] [Fig.4] schematically represents an example of hardware architecture of the detection device 130 included in the system 100 of [Fig.2]. Of course, a detection device included in a communication terminal, such as the third-party terminal UE_D, has a similar hardware architecture.

[0082] As illustrated by [Fig.4], the device 130 has the hardware architecture of a computer. Thus, the device 130 comprises, in particular, a processor 130_l, a random access memory 130_2, a read only memory 130_3 and a non-volatile memory 130_4. It also has communication means 130_5.

[0083] The read-only memory 130_3 of the device 130 constitutes a recording medium in accordance with the invention, readable by the processor 130_1 and on which is recorded a computer program PROG_130 in accordance with the invention, comprising instructions for executing steps of the detection method. The program PROG_130 defines functional modules of the device 130, which rely on or control the hardware elements 130_1 to 130_5 of the device 130 cited above. These functional modules are illustrated in [Fig. 4] in a non-limiting manner, and are described in more detail below with reference to different modes of implementation.

[0084] The communication means 130_5 allow the device 130 to exchange (transmission / reception) data with one or more other entities of the system 100. For this purpose, and as mentioned above, these communication means 130_5 rely on a communication interface, which may be wired or wireless, using any communication protocol known to those skilled in the art.

[0085] [Fig. 5] represents, in the form of a flowchart, a particular mode of implementation of a method, called “general method”, the steps of which are implemented by the digital identity protection system 100. Said general method includes the method for processing the MESS message implemented by the processing device 110 of [Fig. 3] as well as the method for detecting identity theft implemented by the detection device 130 of [Fig. 4].

[0086] For the remainder of the description, it is considered that user A of terminal UE_A has just finished writing his MESS message and is preparing to send it to user B. An example of written content of the MESS message is illustrated in no way limiting terms by [Fig.6].

[0087] As illustrated by [Fig.5], the electronic message MESS is sent by the terminal UE_A to the user B during a RIO step. Said RIO step belongs to a first communication method implemented by the terminal UE_A, this first communication method not being integrated here into the general method.

[0088] The transmitted MESS message is then received by the processing device 110 during a step F10 of the general method. Said step F10 is implemented by a reception module MOD_110_RX equipping the device 110 and is part of the processing method. The reception module MOD_110_RX is integrated into the communication means 110_5 of the device 110.

[0089] Upon receipt of the MESS message by the device 110, the general method comprises a step F20 of generating, from the MESS message, a MESS_NEW message comprising at least one piece of data, called “traceability data” DATA_TRACK_A. Step F20 is implemented by a generation module MOD_110_GEN equipping the device 110, and is part of the processing method.

[0090] More particularly, in the implementation mode described here, the MESS_NEW message corresponds to the MESS message in which said at least one traceability data DATA_TRACK_A is inserted.

[0091] Such an implementation is however not limiting of the invention, and nothing excludes for example that the MESS_NEW message constitutes a new message with respect to the MESS message (i.e. the MESS_NEW message is not the result of an insertion of said at least one traceability data DATA_TRACK_A in the MESS message). To do this, the MESS_NEW message can for example be generated by copying the content of the MESS message, possibly formatting this content in a specific manner, and adding to it said at least one traceability data DATA_TRACK_A.

[0092] In the present embodiment, said at least one traceability data DATA_TRACK_A is generated from at least one identification data DATA_ID_A of user A.

[0093] Said at least one identification data DATA_ID_A typically corresponds to information of a static nature relating to the identity of user A. By "of a static nature", reference is made here to information which, by nature, does not vary over time, or, at least, is not intended to vary over time.

[0094] Preferably, said at least one identification data DATA_ID_A is contained in the MESS message. However, nothing excludes said at least one identification data DATA_ID_A from comprising one or more data which are not contained as such in the MESS message (i.e. in the body of the text of the email in the exemplary embodiment described here).

[0095] By way of non-limiting example, said at least one piece of identification data DATA_ID_A may include at least one piece of data from: - an email address of user A, - a name and / or first name of user A, - location information for user A, - a phone number of user A.

[0096] In the present embodiment where the MESS message corresponds to an email, all or part of said at least one identification data DATA_ID_A is for example included in the electronic signature appearing at the end of said email. In the example of [Fig.6], this electronic signature corresponds to the last four lines of the email.

[0097] Generally speaking, no limitation is attached to the number of identification data DATA_ID_A that can be used to generate said at least one traceability data DATA_TRACK_A. These provisions are also applicable to the number of traceability data DATA_TRACK_A that can be envisaged.

[0098] In particular, nothing excludes one or more identification data from being used to generate a first traceability data item according to a first generation method, and one or more identification data items (possibly in whole or in part identical to the identification data used to generate the first traceability data item) from being used to generate a second traceability data item according to a second generation method.

[0099] As regards said at least one traceability data item DATA_TRACK_A, this is data whose nature is such that it can be inserted within the MESS message (i.e. in the body of the text of the email in the exemplary embodiment described here).

[0100] For example, said at least one traceability data DATA_TRACK_A may comprise at least one data item from: - a numerical value, - an image, for example in JPEG format. - a graphic code. For example, it may be any of the following graphic codes: QR code (“Quick Response code” in English), mini QR code, barcode (e.g.: type PDF147, code 128, etc.), data matrix (e.g.: Flashcode, 2D-doc, datamatrix, etc.), etc., - a string of characters.

[0101] No limitation is attached to the method used to generate said at least one traceability data DATA_TRACK_A from said at least one identification data DATA_ID_A, and the choice of a particular method constitutes only a variant of implementation of the invention.

[0102] By way of non-limiting example, said at least one traceability data item DATA_TRACK_A may be generated by encrypting said at least one identification data item DATA_ID_A. Any encryption method known to those skilled in the art may be implemented, such as for example a hash function (e.g. MD5 or SHA256 type hash).

[0103] In the mode described here, in addition to being generated from said at least one identification data DATA_ID_A, said at least one traceability data DATA_TRACK_A is also generated from at least one data item, called “auxiliary data” DATA_AUX.

[0104] Said at least one auxiliary data item DATA_AUX is more particularly characterized by the fact that it has no link with the identity of user A. For example, it may be at least one of the following data items: - a date and / or time of transmission of the MESS message. Such data makes it possible in particular to facilitate the identification of the message from which a malicious person may have usurped the identity of user A, as described later, - identification data of user B to whom the MESS message is intended. Here too, such data makes it easier to identify the message from which a malicious person may have usurped the identity of user A. In addition, this offers the possibility, in the event of user A's identity being usurped, of alerting user B. These aspects are also described in more detail below.

[0105] In any event, it is important to note that taking into account one or more auxiliary data DATA_AUX, in addition to one or more identification data DATA_ID_A, to generate said at least one traceability data DATA_TRACK_A only corresponds to an optional aspect of the present invention.

[0106] Once said at least one traceability data item DATA_TRACK_A has been generated (i.e. created and inserted) into the MESS message, so as to obtain the MESS_NEW message, the general method comprises a step F30 of storing information, called “correspondence information” INFO_CO, representative of a correspondence between said at least one traceability data item DATA_TRACK_A and said at least one identification data item DATA_ID_A (and possibly also representative of a correspondence between said at least one traceability data item DATA_TRACK_A and said at least one auxiliary data item DATA_AUX if applicable). (if applicable). Step F30 is implemented by the first database server 120, and is part of the processing method.

[0107] More particularly, in the embodiment described here, said correspondence information INFO_CO is configured so as to make it possible to establish that said at least one traceability data item DATA_TRACK_A was generated from said at least one identification data item DATA_ID_A (and possibly also from said at least one auxiliary data item DATA_AUX). In other words, said correspondence information INFO_CO uniquely characterizes the association of the generation of said at least one traceability data item DATA_TRACK_A with said at least one identification data item DATA_ID_A (and possibly also of said at least one auxiliary data item DATA_AUX).

[0108] No limitation is attached to the nature of said correspondence information INFO_CO. For example, it may be a vector comprising said at least one traceability data item DATA_TRACK_A and said at least one identification data item DATA_ID_A (and possibly also said at least one auxiliary data item DATA_AUX), for example in dedicated fields of the vector (e.g.: input / output fields). A reference to the method used to generate said at least one traceability data item DATA_TRACK_A may also be included in such a vector. All of the data included in this vector may for example be obtained by the first server 120 from the processing device 110.

[0109] The general method also comprises a step F40 of transmitting the electronic message MESS_NEW to the terminal UE_B. Said step F40 is implemented by a transmission module MOD_110_TX equipping the device 110 and is part of the processing method in the present embodiment. The transmission module MOD_110_TX is integrated into the communication means 110_5 of the device 110.

[0110] It is important to note that step F40 is described here as being consecutive to step F30. These arrangements are however not limiting of the invention, and nothing of course excludes considering a reverse order, or even that the respective executions of these two steps F30, F40 are simultaneous.

[0111] Subsequently, the message MESS_NEW is received by the terminal UE_B during a step G10, and stored in the electronic mailbox MB_B of the user B during a step G20. Steps G10 and G20 belong to a second communication method implemented by the terminal UE_B, this second communication method not being integrated here into the general method of the invention.

[0112] For the remainder of the description, and in no way limiting, we consider more specifically that the MESS_NEW message corresponds to the MESS message of [Fig.6] in which the character string “-direct:” is generated at the signature level (which thus makes it possible to simulate the existence of a telephone call line direct), as well as the numerical value “7-0234”. For reasons of simplification of the description, it is further considered that the association of these two data forms a single traceability data DATA_TRACK_A for said MESS_NEW message.

[0113] To obtain this traceability data DATA_TRACK_A, a hash function is applied to the following three data: - the email address of user A, - the email address of user B, - the date and time of transmission of the MESS message by the terminal UE_A, so as to produce (by hashing) the value “70234”, as well as the generation of said character string “- direct:” and the insertion of a hyphen “-” within the numerical value “70234”. An example of said MESS_NEW message is illustrated in [Fig.7].

[0114] It is now assumed that a malicious user C (Charlie) implements a step H10 of intrusion into the electronic mailbox MB_B of the user B and of theft of at least part of the content of said electronic mailbox MB_B, including in particular said message MESS_NEW. Said malicious user C corresponds for example to a pirate (or “hacker” in English), and implements said step H10 by means of equipment UE_C in his possession and configured in hardware and software to carry out said intrusion and said theft. Said step H10 belongs to a usurpation method which is not integrated here into the general method of the invention.

[0115] Once in possession of the MESS_NEW message, the malicious user C extracts various data from it (step H20 of the usurpation method), including in particular data which will enable him to usurp the identity of A. More particularly, in the present embodiment, the data extracted and used by the malicious user C are the first name of the user A (Alice) as well as the entirety of his electronic signature contained in the stolen MESS_NEW message and containing a fortiori the traceability data DATA_TRACK_A (i.e. “- direct: 7-0234”).

[0116] Subsequently, and as illustrated in [Fig.5] without any limitation being implied, the malicious user C generates a MESS_FAKE message using said traceability data DATA_TRACK_A as well as the first name of user A (step H30 of the usurpation method), and transmits this MESS_FAKE message to a third-party terminal UE_D in possession of a fourth user D (David) distinct from user A (step H40 of the usurpation method).

[0117] It is important to note that if the MESS_FAKE message uses the first name of user A, it cannot be transmitted with the same email address as that of said user A. The malicious user C can at most send the MESS_FAKE message from an email address imitating that of user A.

[0118] Said MESS_FAKE message aims for example to obtain a sum of money, to request a change of bank details, etc. An example of the said MESS_FAKE message is shown in [Fig.8]. As can be seen in [Fig.8], although the first name of the sender of the MESS_FAKE message is incorrectly indicated as “Alice”, the email address with which the said MESS_FAKE message is sent is different from that of user A.

[0119] Said user D is typically a trusted person known to user A, and whose identity is known to malicious user C, for example following the hacking of user B's MB_B electronic mailbox.

[0120] The MESS_FAKE message is received by the terminal UE_D during a step K10. Said step K10 belongs to a third communication method implemented by the terminal UE_D, this third communication method not being integrated here into the general method of the invention.

[0121] It is considered here, in no way limiting, that, upon receipt of the MESS_FAKE message, the user D expresses suspicions as to the authenticity of the origin of the MESS_FAKE message (step K20 of the third communication method), these suspicions being able to lead him to consider the MESS_FAKE message as a suspicious message coming from a suspicious device.

[0122] No limitation is attached to the manner in which this conclusion (“suspicious message from a suspicious device”) is reached. For example, this may result from a personal approach by user D upon reading the MESS_FAKE message. Alternatively, this may result from an automatic analysis of the MESS_FAKE message, for example by means of a software application of a type known per se, said application being able to be installed on the device in the possession of user D and used by him to consult said MESS_FAKE message, or even accessible online (for example via a paid service provided by a communications operator).

[0123] Due to the suspicion relating to the content and origin of the MESS_FAKE message, and as illustrated by [Fig.5], the user D transmits to the detection device 130 a set of data associated with said MESS_FAKE message (step K30 of the third communication method).

[0124] Said data set may for example include: - at least one first data item DATA_1 contained in the MESS_FAKE message and belonging to said at least one traceability data item DATA_TRACK_A contained in the MESS_NEW message (e.g.: if two traceability data items are contained in the MESS_NEW message, such as for example a numerical value and an image, only one and / or both traceability data items may be included in said data set), - at least a second DATA_2 data identifying the user incorrectly vigilant C (e.g. in this case, it could be the email address used by the malicious user C to transmit the MESS_FAKE message, i.e. “charly@gmail.com”).

[0125] In the present embodiment, it is considered more particularly, and in no way limiting, that: - a single first data item DATA_1 is transmitted to the detection device 130, namely the data item DATA_TRACK_A (i.e. “- direct: 7-0234”), - a single second data item DATA_2 is transmitted to the detection device 130, namely the email address of user C (i.e. “charly@gmail.com”).

[0126] Generally speaking, no limitation is attached to the number and nature of said at least first data DATA_1 and at least second data DATA_2, provided that they comply with the provisions described above, the objective being to verify whether there is a correspondence between the latter.

[0127] According to a more particular example, the data integrated within the data set are for example selected for this purpose. This selection can for example be implemented according to priorities respectively assigned to different types of data. These priorities can in particular be established on the basis of a learning process (example: machine learning) to detect frequencies of use of types of data in a learning set formed of messages that have been categorized as malicious. Such a learning process makes it possible, for example, to detect that typical email signatures with logos (these logos are often poorly used by hackers), certain extracts of messages with typical spelling and grammar errors, certain extracts of messages with atypical fonts (example: abuse of emoticons), etc., are data to be prioritized when generating the data set at the detection device 130. .

[0128] It is important to note that the implementation mode of [Fig.5] is described here considering that data extracted from the MESS_FAKE message (i.e. said set of data) are transmitted to the detection device 130. That being said, the invention still covers other implementation modes in which the user D can transmit the MESS_FAKE message in its entirety to the detection device 130. In this case, said at least first data DATA_1 and at least second data DATA_2 can be extracted by the detection device 130 to carry out the steps described below.

[0129] Furthermore, the transmission of the data set to the detection device 130, whether in the form of data extracted at the terminal UE_D or of the MESS_FAKE message in its entirety, can be carried out manually by the user D or automatically, for example within the framework of a service offer subscribed to with the communications operator in charge of managing the system 100.

[0130] Furthermore, if it is described here that this transmission of the data set to the detection device 130 is subsequent to an emission of suspicions on the part of the user D (step K20), the presence of such suspicions is in no way essential to the invention, in particular in the case of an automatic transmission carried out within the framework of a service offer as mentioned above.

[0131] The first and second data DATA_1, DATA_2 are then received by the detection device 130 during a step F50 of the general method. Said step F50 is implemented by a reception module MOD_130_RX equipping the device 130 and is part of the detection method. The reception module MOD_130_RX is integrated into the communication means 130_5 of the device 130.

[0132] Upon receipt of the first and second data DATA_1, DATA_2 by the device 130, the general method comprises a step F60 for detecting a possible identity theft based on the correspondence information INFO_CO associated with the traceability data DATA_TRACK_A contained in the data set received during step F602. Step F60 is implemented by a detection module MOD_130_DETEC equipping the device 130, and is part of the detection method.

[0133] More particularly, in the mode described here, said step F60 is implemented by verifying, as a function of said correspondence information INFO_CO, whether said first data item DATA_1 has been generated from said second data item DATA_2. Therefore, an identity theft of user A is detected if said verification is not satisfied.

[0134] In practice, the verification of step F60 consists of verifying whether the second data item DATA_2 is part of the data which was used to generate said at least one data item DATA_TRACK_A (= DATA_1 in this example) during the execution of step F20.

[0135] In this case, in the present embodiment, this verification is not satisfied since the email address of the malicious user C (i.e. "charly@gmail.com") was not used to generate the data DATA_1 (i.e. "- direct: 7-0234"). As a result, it is detected that the identity of user A has been usurped.

[0136] The implementation of the detection step F60 can be carried out in different ways. For example, the detection device 130 can transmit a verification request to the first data server 120 which stores the correspondence information INFO_CO. Upon receipt of this request, said first server 120 transmits said correspondence information INFO_CO to the detection device 130 so that the latter can use it to carry out the verification (this is therefore a verification implemented locally at the level of the detection device 130).

[0137] According to another example, the detection device 130 can transmit the first and second data DATA_1, DATA_2 to the first server 120 which is responsible for carrying out the verification and returning the result of this verification to said detection device 130 (this is therefore a verification implemented externally to the detection device 130).

[0138] To the extent that the verification is not satisfied in the mode described herein, different actions can be implemented.

[0139] Thus, and as illustrated by [Fig.5], the general method also comprises a step F70 of transmission to user D (i.e. to the user at the origin of the transmission of the data DATA_1, DATA_2 to the detection device 130) of a confirmation message MESS_CONF_D that the identity of user A has been usurped. Said step F70 is implemented by a transmission module MOD_130_TX equipping the device 130 and forms part, in the present embodiment, of the detection method. The transmission module MOD_130_TX is integrated into the communication means 130_5 of the device 130.

[0140] Said confirmation message MESS_CONF_D is received by user D during a step K40 of the third communication method.

[0141] In addition to said confirmation message MESS_CONF_D, the detection device 130 also transmits: - an alert message MESS_ALARM_A to user A (transmission: step F80, reception by user A: step R20 of the first communication method), said alert message MESS_ALARM_A indicating that his identity has been usurped, and - an alert message MESS_ALARM_B to user B indicating that the identity of user A has been usurped (transmission: step F90, reception by user B: step G30 of the second communication method).

[0142] The implementation of step F90 is carried out using the correspondence information INFO_CO, given that the latter integrates the fact that, in the present embodiment, the traceability data DATA_TRACK_A (and therefore a fortiori the first data DATA_1 received by the detection device 130) was generated in particular from the email address of the user B.

[0143] Finally, in the implementation mode described here with reference to [Fig.5], the general method comprises a step F100 of storing an alert information INFO_ALARM_C representative of the identity of the malicious user C.

[0144] Step F100 is implemented by the second database server 140, and is part of the detection method. Storing said alert information INFO_ALARM_C makes it possible to create a report of said malicious user C, and thus offers the possibility of more easily detecting other attempts at identity theft committed by said user C.

[0145] No limitation is attached to the nature of said alert information INFO_ALARM_C. For example, it may be said data DATA_2 (i.e. the email address used by the malicious user C to send the message MESS_FAKE).

[0146] The general method, and more particularly the detection method, has been described up to now by considering that the set of data associated with the MESS_FAKE message and transmitted by the user D to the detection device 130 is formed of said first and second data DATA_1, DATA_2. That said, nothing excludes considering other modes of implementation in which still other data are transmitted to the detection device 130.

[0147] In particular, in the case where at least one auxiliary data item DATA_AUX has been used to generate said at least one traceability data item DATA_TRACK_A, said set of data associated with the message MESS_FAKE and transmitted by the user D to the detection device 130 may also comprise at least one third data item DATA_3 among said at least one auxiliary data item associated with the initial message MESS. In this case, the detection step F60 may consist of verifying, as a function of said correspondence information INFO_CO, whether said at least one first data item DATA_1 has been generated from said at least one second data item DATA_2 and said at least one third data item DATA_3. Here again, identity theft is detected if the verification is not satisfied.

[0148] Proceeding in this way makes it possible, in particular, to carry out a more restrictive, and therefore more targeted, correspondence check (via the correspondence information INFO_CO). In this way, it is easier to identify the initial message MESS from which the message MESS_NEW was generated, which is then used by the malicious user C to usurp the identity of the user A, and it is therefore possible to alert the appropriate users without risk of error. This is all the more advantageous if, for example, the user A transmits a large quantity of emails to different users, and if, among these emails, some contain the same numerical hash value.

[0149] As a more specific example, in the context of the messages considered in figures 6, 7 and 8, such at least one third data item DATA_3 may for example correspond to the email address of user B and / or the date and time of transmission of the MESS message by the terminal UE_A.

[0150] The invention has been described so far on the basis of certain assumptions which are in no way limiting of the invention, as now described.

[0151] Thus, if the presence of a fourth user D has been considered, nothing excludes the possibility that the latter is absent and that the MESS_FAKE message is transmitted by the malicious user C to the second user B.

[0152] Nothing also excludes the possibility that the malicious user C might enter the user A's email inbox rather than user B's to steal personal data.

[0153] The invention has also been described up to now by considering that the processing device 110 and the first database server 120 form a processing system integrated into the digital identity protection system 100. In the same way, it has been considered that the detection device 130 and the second database server 140 form a detection system integrated into the digital identity protection system 100. It has further been considered that the processing system is separated (materially) from the detection system. These provisions are however not limiting of the invention, and it is possible to envisage that the processing device 110 and the detection device 130 are integrated (materially) into a single device.Similarly, it is possible to envisage that the first database server 120 and the second database server 140 are integrated (materially) into a single database server.

[0154] Nothing also excludes the possibility of the first data server 120 (respectively the second data server 140) being integrated into the processing device 110 (respectively into the detection device 130).

[0155] It has also been considered above that the storage steps F30, F100 are implemented by the first database server 120 and the second database server 140 which are respectively external to the processing device 110 and to the detection device 130. However, the storage step F30 (respectively the storage step F100) can also be implemented using storage means internal to the processing device 110 (respectively by storage means internal to the detection device 130), such as for example the non-volatile memory 110_4 (respectively the non-volatile memory 130_4).

[0156] Finally, it has also been described up to now that the processing method (respectively the detection method) is implemented by the processing device 110 and the first database server 120 (respectively the detection device 130 and the second database server 140). However, nothing excludes the possibility of all or part of the steps of said method being implemented by the user terminal UE_A in possession of the user A (respectively by the third-party terminal UE_D in possession of the user D).

Claims

Claims

1. Method for processing an initial electronic message sent by a sending device, said method comprising steps of: - generation (F20), from the initial electronic message, of an electronic message comprising at least one traceability data item, - storage (F30) of correspondence information between said at least one traceability data item and at least one identification data item of a user of said sending device.

2. Method according to claim 1, wherein said at least one traceability data is generated by encryption of said at least one identification data, for example by means of a hash function.

3. Method according to any one of claims 1 to 2, in which said at least one traceability data item comprises at least one data item from: - a numerical value, - an image, - a graphic code, - a character string.

4. Method according to any one of claims 1 to 3, in which said at least one identification data item comprises at least one data item from: - an electronic address of the user of the transmitting device, - a name and / or a first name of the user of the transmitting device, - location information of the user of the transmitting device, - a telephone number of the user of the transmitting device.

5. Method according to any one of claims 1 to 4, in which said at least one traceability data item is generated from at least one auxiliary data item among: - a date and / or a time of sending of the electronic message, - identification data of a user to whom the electronic message is intended, the correspondence information being representative of the fact that said at least one traceability data item was generated from said at least one auxiliary data item.

6. Method for detecting identity theft of a user of a device sending an initial electronic message previously processed according to a processing method in accordance with any one of claims 1 to 5, said detection method comprising steps of: - reception (F150), from a device, called a “third-party device”, of a set of data associated with an electronic message, called a “suspect message”, comprising said at least one traceability data item, - detection (F 160) of possible identity theft based on said correspondence information associated with said at least one traceability data item.

7. Method according to claim 6, said method further comprising, if identity theft is detected, a step of transmitting (F170) to the user of the third-party device a confirmation message that the identity of the user of the sending device has been usurped.

8. Method according to any one of claims 6 to 7, said method further comprising, if identity theft is detected, a step of transmitting (F190) to the user of the transmitting device an alert message indicating that the identity of said user has been usurped.

9. Method according to any one of claims 6 to 8, in which the initial message has been previously processed according to claim 5, said at least one auxiliary data item comprising identification data of a user for whom the initial message is intended, said method further comprising, if identity theft is detected, a step of transmitting (F210) to said user for whom the initial message is intended and using said correspondence information of an alert message indicating that the identity of the user of the sending device has been usurped.

10. Method according to any one of claims 6 to 9, in which the set of data associated with the suspect message comprises: - at least one first data item (DATA_1) contained in the suspect message and belonging to said at least one traceability data item contained in said initial message, - at least one second data item (DATA_2) for identifying a user of the suspect device, and in which the detection step comprises a verification, as a function of said correspondence information, of whether said at least one first data item has been generated from said at least one second data item, an identity theft being detected if the verification fication is not satisfied.

11. Method according to any one of claims 6 to 10, said method further comprising a step of storing (F230) information, called “alert information”, representative of the identity of the user of the suspect device.

12. Computer program comprising instructions for implementing a processing method according to any one of claims 1 to 5 and / or a detection method according to any one of claims 6 to 11 when said program is executed by a computer.

13. A computer-readable recording medium having a computer program recorded thereon according to claim 12.

14. Processing device comprising means configured to implement a method for processing an electronic message according to any one of claims 1 to 5.

15. Detection device comprising means configured to implement a method for detecting identity theft according to any one of claims 6 to 11.

Citation Information

Patent Citations

  • Detecting method and device

    US20130305367A1

  • Electronic messaging security and authentication

    US20220255750A1

  • Methods and systems for email verification

    WO2019173732A1