system

The system addresses the challenge of phishing email detection by using generating AI to analyze sender domain and email content, offering real-time, accurate warnings to users, thereby enhancing security.

JP2026060653APending Publication Date: 2026-04-08SOFTBANK GROUP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-27
Publication Date
2026-04-08

AI Technical Summary

Technical Problem

Users face challenges in distinguishing between legitimate and phishing emails, particularly on smartphones, leading to high risks of deception due to insufficient automated phishing detection mechanisms.

Method used

A system that extracts sender domain information and email content, uses a generating AI to determine phishing characteristics, and notifies users with warnings, integrating with email applications for real-time security checks.

Benefits of technology

Enhances user security by providing highly accurate and rapid phishing email detection, reducing the risk of personal information leaks and unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026060653000001_ABST
    Figure 2026060653000001_ABST
Patent Text Reader

Abstract

We provide the system. [Solution] A means for extracting the sender domain information of an email, A means for querying the generating AI to determine whether the aforementioned source domain information is legitimate, A means for receiving the judgment result from the aforementioned generating AI and notifying the user, A system that includes this.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology of the present disclosure relates to a system.

Background Art

[0002] Patent Document 1 discloses a persona chatbot control method performed by at least one processor, including steps of receiving a user utterance, adding the user utterance to a prompt including an instruction sentence related to an explanation of a chatbot character, encoding the prompt, and inputting the encoded prompt into a language model to generate a chatbot utterance in response to the user utterance.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Currently, the damage caused by phishing emails has been increasing rapidly, and it is difficult for users to distinguish between legitimate emails and phishing emails. Especially in the email apps of smartphones, it is often judged only by the display name, and the risk of being deceived by forged emails is high. Therefore, in order for users to use emails with confidence, a mechanism for automatically judging phishing emails and giving warnings is necessary.

Means for Solving the Problems

[0005] The present invention provides a system that includes means for extracting sender domain information of an email, means for querying a generating AI to determine whether the sender domain information is legitimate, and means for receiving the determination result from the generating AI and notifying the user. Furthermore, the system provides means for extracting the subject and a portion of the body of an email, means for querying a generating AI to determine whether the content of the subject and body has characteristics of phishing, and means for notifying the user of the email's safety based on the determination result from the generating AI. The system also provides initial setup means for linking with an email application, means for directly obtaining email information from the linked email application, and means for displaying a warning message on the user's device based on the determination result. This makes it easier for users to determine whether a received email is a phishing email, thus preventing damage.

[0006] "Email sender domain information" refers to the information about the sender's internet domain that is recorded when an email is sent, and is used to verify the sender's trustworthiness.

[0007] "Generative AI" refers to artificial intelligence that can learn from large amounts of data and derive conclusions based on specific patterns and characteristics, and in this invention, it is used to identify phishing emails.

[0008] The "judgment result" is information output by the generating AI after it has determined whether or not an email is a phishing email, and is intended to notify the user.

[0009] A "user device" refers to an electronic device that can connect to the internet, such as a smartphone, tablet, or computer, and in this invention, it refers to a device that has the function of receiving and displaying the judgment result.

[0010] A "phishing email" is a fraudulent email sent under the guise of a real company or organization, with the aim of deceiving the recipient into revealing their ID, password, or other confidential information.

[0011] A "linked email application" refers to an email application that runs on a user's device and is configured to exchange data with other applications (the system of the present invention).

[0012] A "warning message" is text or a notification displayed to inform a user of the dangers or problems associated with a particular action, and in this invention, it refers to a message that warns of the possibility of a phishing email.

[0013] A "user" is an individual or organization that uses the system to verify the security of their emails. [Brief explanation of the drawing]

[0014] [Figure 1] This is a conceptual diagram showing an example of the configuration of a data processing system according to the first embodiment. [Figure 2] This is a conceptual diagram showing an example of the essential functions of a data processing device and a smart device according to the first embodiment. [Figure 3] This is a conceptual diagram showing an example of the configuration of a data processing system according to the second embodiment. [Figure 4] This is a conceptual diagram showing an example of the main functions of a data processing device and smart glasses according to the second embodiment. [Figure 5] This is a conceptual diagram showing an example of the configuration of a data processing system according to the third embodiment. [Figure 6] This is a conceptual diagram showing an example of the main functions of a data processing device and a headset-type terminal according to the third embodiment. [Figure 7] This is a conceptual diagram showing an example of the configuration of a data processing system according to the fourth embodiment. [Figure 8] This is a conceptual diagram showing an example of the main functions of a data processing device and a robot according to the fourth embodiment. [Figure 9] This shows an emotion map where multiple emotions are mapped. [Figure 10] This shows an emotion map where multiple emotions are mapped. [Figure 11] It is a sequence diagram showing the processing flow of the data processing system in Embodiment 1. [Figure 12] It is a sequence diagram showing the processing flow of the data processing system in Application Example 1. [Figure 13] It is a sequence diagram showing the processing flow of the data processing system in Embodiment 2 when the emotion engine is combined. [Figure 14] It is a sequence diagram showing the processing flow of the data processing system in Application Example 2 when the emotion engine is combined.

Mode for Carrying Out the Invention

[0015] Hereinafter, an example of an embodiment of a system according to the technology of the present disclosure will be described with reference to the accompanying drawings.

[0016] First, the terms used in the following description will be explained.

[0017] In the following embodiments, a numbered processor (hereinafter simply referred to as "processor") may be a single arithmetic unit or a combination of multiple arithmetic units. Also, the processor may be a single type of arithmetic unit or a combination of multiple types of arithmetic units. Examples of arithmetic units include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a GPGPU (General-Purpose computing on Graphics Processing Units), an APU (Accelerated Processing Unit), and the like.

[0018] In the following embodiments, a numbered RAM (Random Access Memory) is a memory in which information is temporarily stored and is used as a work memory by the processor.

[0019] In the following embodiments, the signed storage is one or more non-volatile storage devices that store various programs and various parameters. Examples of non-volatile storage devices include flash memory (SSD (Solid State Drive)), magnetic disks (e.g., hard disks), or magnetic tapes.

[0020] In the following embodiments, the signed communication interface (I / F) is an interface that includes a communication processor and an antenna, etc. The communication interface manages communication between multiple computers. Examples of communication standards applicable to the communication interface include wireless communication standards such as 5G (5th Generation Mobile Communication System), Wi-Fi (registered trademark), or Bluetooth (registered trademark).

[0021] In the following embodiments, "A and / or B" is synonymous with "at least one of A and B." That is, "A and / or B" means that it may be A alone, or B alone, or a combination of A and B. Furthermore, in this specification, the same concept as "A and / or B" applies when expressing three or more things linked by "and / or."

[0022] [First Embodiment]

[0023] Figure 1 shows an example of the configuration of the data processing system 10 according to the first embodiment.

[0024] As shown in Figure 1, the data processing system 10 includes a data processing device 12 and a smart device 14. An example of the data processing device 12 is a server.

[0025] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0026] The smart device 14 comprises a computer 36, a reception device 38, an output device 40, a camera 42, and a communication interface 44. The computer 36 comprises a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The reception device 38, output device 40, and camera 42 are also connected to the bus 52.

[0027] The reception device 38 is equipped with a touch panel 38A and a microphone 38B, etc., and receives user input. The touch panel 38A receives user input by detecting contact with an object (e.g., a pen or finger). The microphone 38B receives user input by detecting the user's voice. The control unit 46A transmits data indicating the user input received by the touch panel 38A and microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the data indicating the user input.

[0028] The output device 40 includes a display 40A and a speaker 40B, and presents data to the user 20 by outputting the data in a form perceptible to the user 20 (e.g., audio and / or text). The display 40A displays visible information such as text and images according to instructions from the processor 46. The speaker 40B outputs audio according to instructions from the processor 46. The camera 42 is a small digital camera equipped with an optical system such as a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor.

[0029] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various types of information between processor 46 and processor 28 via network 54.

[0030] Figure 2 shows an example of the main functions of the data processing device 12 and the smart device 14.

[0031] As shown in Figure 2, in the data processing device 12, a specific processing is performed by the processor 28. A specific processing program 56 is stored in the storage 32. The specific processing program 56 is an example of a "program" related to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 according to the specific processing program 56 executed on the RAM 30.

[0032] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0033] In the smart device 14, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The reception output program 60 is used in conjunction with a specific processing program 56 by the data processing system 10. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0034] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0035] This invention relates to a system that automatically identifies phishing emails and alerts users. To implement this system, a specific method is described for using an AI to analyze the sender domain information, subject, and part of the email body, and for notifying the user of the analysis result.

[0036] overview

[0037] The system of the present invention primarily consists of an application installed on the user's terminal and a server located in the cloud. When a user receives an email, the sender's domain, subject, and body of the email are sent to the cloud server, where a generating AI is used to determine if it is a phishing email, and the result is notified to the user.

[0038] Program processing flow

[0039] 1. User registration and initial setup

[0040] The user first downloads and installs the smartphone application.

[0041] The app requires the user to connect with their email app as part of the initial setup. This connection is established via OAuth authentication, which obtains the necessary access permissions.

[0042] 2. Receiving emails and sending judgment requests

[0043] When a user receives an email, this application, which is integrated with the email app, displays a judgment button in the email view.

[0044] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[0045] The app sends this information to the cloud server as an API request.

[0046] 3. Judgment processing by generating AI

[0047] The server receives requests from applications and parses the email information.

[0048] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[0049] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data. The result of the determination includes information such as "It is a phishing email" or "It is not a phishing email."

[0050] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[0051] 4. User notification of the judgment result

[0052] The app receives the judgment result from the server and reflects the result in the email view.

[0053] If an email is identified as a phishing email, the app will display a warning message to the user such as, "This email may be a phishing attempt."

[0054] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[0055] Specific example

[0056] The following are specific examples of when a user is using a phishing detection service.

[0057] 1. The user receives a notification email from the bank.

[0058] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[0059] 3. The app sends this information to the server.

[0060] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[0061] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[0062] 6. The server receives the judgment result and sends it back to the user.

[0063] 7. The app displays the result and warns, "This email may be a phishing attempt."

[0064] In this way, users are protected from the risks of phishing emails and can use email with peace of mind. This invention enhances user security by performing highly accurate judgments using generation AI.

[0065] The following describes the processing flow.

[0066] Step 1:

[0067] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. The integration is performed via OAuth authentication, and the necessary access permissions are obtained.

[0068] Step 2:

[0069] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[0070] Step 3:

[0071] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[0072] Step 4:

[0073] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[0074] Step 5:

[0075] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[0076] Step 6:

[0077] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[0078] Step 7:

[0079] The device (app) receives the judgment result from the server and reflects it on the screen within the email view. If it is determined to be a phishing email, the app displays a warning message to the user saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[0080] Step 8:

[0081] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[0082] (Example 1)

[0083] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0084] Conventional email filtering systems have difficulty accurately identifying phishing emails, resulting in problems with false positives and missed detections. Furthermore, insufficient warnings and notifications to users can increase security risks. This increases the risk of personal information leaks and unauthorized access, as well as the likelihood of users becoming victims of phishing emails. Therefore, the present invention aims to solve these problems by providing a system that uses a generative AI model to perform advanced phishing email detection and provide users with rapid and accurate warnings.

[0085] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0086] In this invention, the server includes means for extracting the sender domain information of an email, means for extracting the subject and part of the body, means for querying a generating AI whether the sender domain information and the subject and body have characteristics of phishing, and means for notifying the user of the determination result from the generating AI. This enables highly accurate detection of phishing emails and rapid user notification.

[0087] "Email sender domain information" refers to the domain portion of the sender address of a received email, and is used to identify the origin of the email.

[0088] The "subject line" is the text information displayed as the title of an email, and is used to concisely express the content of the email.

[0089] The "body" of an email is the text area that contains the main content of the email, including messages and information addressed to the user.

[0090] "Generative AI" is an artificial intelligence system that learns from past data and performs inferences and judgments on new input data, and is used for things like detecting phishing in emails.

[0091] An "API request" is a request from an application to send data to a service such as a server, and is called to perform a specific function.

[0092] "User devices" refer to all electronic devices used by individuals, including smartphones, tablets, and personal computers.

[0093] A "prompt statement" is an input statement given to a generating AI to request a specific judgment, and it serves as a criterion for the generating AI to produce an appropriate response.

[0094] A "cloud server" is a remote server provided over the internet, used for storing and processing data.

[0095] This invention relates to a system that automatically identifies phishing emails and alerts users. The main components of this system are an application installed on the user's terminal and a server located in the cloud.

[0096] System Configuration

[0097] Hardware and software

[0098] User device: Use a device such as a smartphone, tablet, or personal computer. This includes smartphones running the iOS or Android® operating system.

[0099] Application: A dedicated application installed on the user's device. It integrates with the email application and has the function of extracting email information. This application uses OAuth authentication to integrate with the email application.

[0100] Cloud server: A remote server accessible via the internet, which performs phishing detection using AI models for analyzing and generating email information.

[0101] Generative AI Model: A pre-trained AI model is used to determine whether the input email information is a phishing email.

[0102] How it works

[0103] 1. User registration and initial setup

[0104] Users download and install the app from their smartphone's app store. Upon first launching the app, a user registration screen appears. Users enter their email address, password, and other information to create an account.

[0105] The app performs user authentication and requests integration with the email application. This integration is securely performed through OAuth authentication.

[0106] 2. Receiving emails and sending judgment requests

[0107] When a user receives a new email, the app interacts with the email app and displays a "Determine" button in the email view.

[0108] When the user clicks the "Analyze" button, the app automatically extracts the sender domain, subject, and part of the email body and sends them to the cloud server.

[0109] 3. Judgment by Generating AI

[0110] The server receives a request from the app and analyzes the email information. Based on the sender domain, subject, and part of the body, it generates a prompt message and inputs this prompt message into the AI ​​model.

[0111] The generative AI model learns from past data and determines whether a received email has phishing characteristics.

[0112] For example, the prompt message "Sender domain: examplebank.com, Subject: Important Notice: Account Freezing, Body: Your account has been frozen" is input to the generating AI model.

[0113] 4. Notification of the judgment result

[0114] The server receives the judgment results obtained from the generated AI model and sends those results back to the user's terminal.

[0115] The app displays the received judgment results within the email viewer. If it is determined to be a phishing email, it displays a warning message saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[0116] Specific example

[0117] Let's illustrate this with an example where a user receives a notification email from their bank. Suppose the sender domain of this notification email is "examplebank.com", the subject is "Important Notice: Account Freezing", and the body of the email is "Your account has been frozen". In this case, the app extracts this information and sends it to a cloud server. The cloud server passes this information to a generating AI model to determine whether it is a phishing email. The result of the determination is returned, and the user is notified that "This email may be a phishing email".

[0118] This system protects users from phishing emails and reduces security risks.

[0119] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0120] Step 1:

[0121] The user downloads and installs the application from the app store on their smartphone.

[0122] Input: Application from the app store

[0123] Output: Installed applications

[0124] Specific operation: The user searches for the app in the device's app store and presses the install button, which downloads and installs the application on the user's device.

[0125] Step 2:

[0126] When a user launches the app for the first time, the application displays a user information registration screen.

[0127] Input: User information such as email address and password

[0128] Output: User information registered in the application

[0129] Specific operation: The user launches the app and creates an account by entering their email address and password on the registration screen. The application saves this information to a database.

[0130] Step 3:

[0131] The application performs user authentication and sets up integration with the email application.

[0132] Input: Display OAuth authentication prompt

[0133] Output: Settings for linking with the email app

[0134] Specific operation: The app requests integration with the email app used by the user using OAuth. Once the user grants authentication, the app obtains the necessary permissions and the integration is complete.

[0135] Step 4:

[0136] When a user receives a new email, the application checks the email information. A "Determine" button is displayed in the email view.

[0137] Input: Received email

[0138] Output: Email view showing the "Determine" button

[0139] Specific operation: When a user receives an email, the app parses the email and adds a "Determine" button to the view.

[0140] Step 5:

[0141] When the user clicks the "Determine" button, the application automatically extracts the sender domain, subject, and part of the email body, and sends them to the cloud server.

[0142] Input: Sender domain of the email, subject, and part of the email body.

[0143] Output: Email information sent as an API request

[0144] Specific operation: When the user clicks a button, the app extracts information from the email, compiles it, and sends it to the cloud server in JSON format.

[0145] Step 6:

[0146] The server receives a request from the app and parses the email information. It generates a prompt message and inputs it into the generation AI model.

[0147] Input: Email information in JSON format

[0148] Output: Prompt text input to the generating AI model

[0149] Specific operation: The server parses the received JSON and generates a prompt message based on the email content, such as "Sender domain: example.com, Subject: Important Notice, Body: Your account has been frozen," and inputs it into the generation AI model.

[0150] Step 7:

[0151] The generative AI model determines whether an email is a phishing email based on the prompt text.

[0152] Input: Prompt message

[0153] Output: Result of determining whether it is a phishing email.

[0154] Specific operation: The generative AI model utilizes past training data to analyze the information contained in the prompt message and determine whether or not the email is a phishing email. The result is then sent back to the server.

[0155] Step 8:

[0156] The server receives the judgment results from the generated AI model and sends them back to the user's terminal.

[0157] Input: Judgment result from the generated AI model

[0158] Output: Judgment result sent back to the user terminal

[0159] Specific operation: The server organizes the judgment results of the generated AI model, converts them into a data format for return to the user terminal, and sends them as an API response.

[0160] Step 9:

[0161] The application receives the judgment result from the server and displays it in the email view.

[0162] Input: Judgment result from the server

[0163] Output: Judgment result displayed in the email view

[0164] Specific operation: The application receives an API response and displays the result in the email view as either "This email may be a phishing attempt" or "This email is safe." The user then takes appropriate action based on this.

[0165] (Application Example 1)

[0166] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0167] With the threat of phishing emails on the rise, there is a need for a means to determine the security of emails received by users in real time and to warn them appropriately. However, many current email services require users to make their own judgments, which carries the risk of misjudgment. There is also a need for a system that reduces the burden on users and identifies phishing emails quickly and with high accuracy.

[0168] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0169] In this invention, the server includes means for extracting the sender domain information of an email, means for querying a generating AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generating AI and notifying the user, means for initial setup to link with the user's email account, means for directly obtaining email information from the linked email account, and means for displaying a warning message on the user's device based on the determination result. This makes it possible to check the security of emails received by the user in real time and to issue a quick and accurate warning against phishing emails.

[0170] "Email sender domain information" refers to the original internet domain name from which the email was sent.

[0171] "Generative AI" is a type of artificial intelligence technology that refers to a system that automatically performs specific tasks using natural language processing and pattern recognition.

[0172] The "judgment result" refers to the result of the AI's judgment on the phishing email, and indicates whether or not the email is a phishing email.

[0173] "Means of notifying the user" refers to the methods and processes for informing the user of the email's evaluation results, which are usually provided in the form of on-screen messages or push notifications.

[0174] "Initial setup means" refers to the methods and processes for performing the initial setup of the system, including, for example, the steps for setting up the link between the user and their email account.

[0175] "Means of directly obtaining email information" refers to a mechanism for directly obtaining necessary email information from the email account used by the user.

[0176] "Means of displaying warning messages" refers to methods and processes for displaying warning messages to alert users to suspicious emails, such as phishing emails.

[0177] This invention relates to a system that automatically identifies phishing emails and notifies the user. This system works in conjunction with the user's email account to check the security of emails in real time and displays a warning message if an email is suspected to be a phishing email.

[0178] The main components of the system are as follows:

[0179] User terminal: An application installed on a device such as a smartphone.

[0180] Cloud server: A server that receives data and uses generated AI to identify phishing emails.

[0181] Generative AI models: Artificial intelligence systems that use natural language processing and pattern recognition to determine the legitimacy of emails. Specific examples include OpenAI's ChatGPT and Google's BERT.

[0182] Program processing flow

[0183] 1. User registration and initial setup

[0184] The user downloads and installs the application on their smartphone. The application prompts the user for initial setup and configures the linking with their email account. OAuth authentication is used for the linking to obtain the necessary access permissions.

[0185] 2. Receiving emails and sending judgment requests

[0186] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. This information is then sent to a cloud server as an API request.

[0187] 3. Judgment processing by generating AI

[0188] The cloud server passes the received email information to an AI model that determines whether it is a phishing email. The result is indicated as either "It is a phishing email" or "It is not a phishing email." This information is then sent back to the user's device.

[0189] 4. User notification of the judgment result

[0190] The user's terminal receives the judgment result from the server and reflects the result in the email view. If it is determined to be a phishing email, the user will be shown a warning message such as "This email may be a phishing email."

[0191] As a concrete example, the following process is performed: When a user receives a "notification email from the bank," the sender's domain, subject, and part of the email body are extracted and sent to a cloud server. The cloud server makes a judgment based on a generated AI model, and if it determines, for example, that "examplebank.com" is not an official domain, it determines that the email is likely a phishing attempt. The user is then shown a warning that "this email may be a phishing attempt."

[0192] The following are examples of prompt messages:

[0193] "

[0194] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[0195] Sender: example@examplebank.com

[0196] Subject: Important Notice: Account Freezing

[0197] Part of the text: Please check.

[0198] "

[0199] This system allows users to verify the security of incoming emails and protect themselves from phishing risks. The highly accurate and rapid detection using generated AI significantly improves user security.

[0200] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0201] Step 1:

[0202] The user downloads and installs the application on their smartphone. The input is the user's download action and the app installation process, and the output is the installed application. Specifically, the user downloads the app from the Apple App Store or Google Play Store and installs the app on their device following the installation instructions.

[0203] Step 2:

[0204] The application prompts the user for initial setup and configures the linking of their email account. Inputs include the user's email account information and the OAuth authentication process, while output is the linked email account. Specifically, the user configures the email account linking within the app, and the app obtains the necessary access permissions through OAuth authentication.

[0205] Step 3:

[0206] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. The input is the information of the received email, and the output is the extracted sender's domain, subject, and portion of the body. Specifically, the app runs in the background and executes code to parse the information of the received email.

[0207] Step 4:

[0208] The application sends the extracted email information to the cloud server as an API request. The input is the extracted email information and the API request, and the output is the status indicating that the transmission to the cloud server is complete. Specifically, the application uses an HTTP POST request to send the email information to the server.

[0209] Step 5:

[0210] The cloud server passes the received email information to the generating AI model and makes a judgment request. The input is the sent email information, and the output is the judgment result of the generating AI model. Specifically, the cloud server converts the email information into a prompt message and inputs it into the generating AI model. For example,

[0211] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[0212] Sender: example@examplebank.com

[0213] Subject: Important Notice: Account Freezing

[0214] Part of the text: Please check.

[0215] The prompt " " is sent to the generating AI.

[0216] Step 6:

[0217] The generative AI model determines the legitimacy of an email based on the prompt text and returns a result indicating whether or not it is a phishing email. The input is the prompt text, and the output is a determination such as "This is a phishing email" or "This is not a phishing email." Specifically, the generative AI compares the text in the email with past training data to determine whether or not it has phishing characteristics.

[0218] Step 7:

[0219] The cloud server receives the judgment result from the generated AI and sends it back to the user's terminal. The input is the judgment result, and the output is the message sent to the user's terminal. Specifically, the cloud server uses an HTTP response to send the judgment result to the application.

[0220] Step 8:

[0221] The user's device receives the judgment result from the server and reflects the result in the email view. The input is the judgment result from the cloud server, and the output is the result displayed to the user. Specifically, the app executes code to display the judgment result in the notification area or within the email app. For example, it might display a warning message such as "This email may be a phishing attempt" as a pop-up.

[0222] This process allows users to verify the security of incoming emails in real time and protect themselves from phishing risks. The rapid and highly accurate judgment using generated AI significantly improves user security.

[0223] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0224] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system uses a generating AI to determine the sender domain information and content of emails, and notifies the user of the determination result. Furthermore, by adding a function that recognizes user sentiment and adjusts the notification method and content accordingly, it achieves more effective security measures.

[0225] overview

[0226] The system of this invention combines a smartphone application, a cloud-based server, and an emotion engine. Upon receiving an email, it extracts the sender's domain information, subject, and a portion of the email body, sends this information to the server, and is judged by a generating AI. The judgment result is notified to the user, and at that time, the user's emotion engine is used to select the most appropriate notification method. The specific processing flow is described below.

[0227] Program processing flow

[0228] 1. User registration and initial setup

[0229] The user downloads and installs the smartphone application.

[0230] The app requests integration with the user's email app during initial setup. This integration is performed via OAuth authentication, which obtains the necessary access permissions.

[0231] The app will ask for your consent to use the emotion engine and configure it to monitor the user's emotional state.

[0232] 2. Receiving emails and sending judgment requests

[0233] When a user receives an email, this application, which is linked to the email app, displays a judgment button.

[0234] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[0235] The app sends this information to the cloud server as an API request.

[0236] 3. Judgment processing by generating AI

[0237] The server receives requests from applications and parses the email information.

[0238] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[0239] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data.

[0240] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[0241] 4. Notification of judgment results and application of the emotion engine

[0242] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state.

[0243] The emotion engine selects the optimal notification method (e.g., text, voice, visual) based on the user's emotional state (e.g., tension, anxiety, relaxation).

[0244] Based on the detection result, the app displays or notifies the user in the most appropriate way with a warning message stating, "This email may be a phishing attempt."

[0245] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[0246] Specific example

[0247] The following are specific examples of when a user is using a phishing detection service.

[0248] 1. The user receives a notification email from the bank.

[0249] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[0250] 3. The app sends this information to the server.

[0251] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[0252] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[0253] 6. The server receives the judgment result and sends it back to the user.

[0254] 7. The app receives the assessment result and analyzes the user's emotional state using its emotion engine. For example, if the user is relaxed, it will notify them via text; if they are feeling anxious, it will notify them gently via voice.

[0255] 8. The app displays or notifies the user in a format that is most appropriate for them, stating, "This email may be a phishing attempt."

[0256] In this way, users are protected from the risks of phishing emails and can receive appropriate notifications that take their emotions into consideration. The present invention provides a highly accurate and user-friendly security system that combines generative AI and an emotion engine.

[0257] The following describes the processing flow.

[0258] Step 1:

[0259] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. This integration is performed via OAuth authentication, obtaining the necessary access permissions. Furthermore, it requests permission to enable the emotion engine and monitor the user's emotional state.

[0260] Step 2:

[0261] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[0262] Step 3:

[0263] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[0264] Step 4:

[0265] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[0266] Step 5:

[0267] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[0268] Step 6:

[0269] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[0270] Step 7:

[0271] The device (app) receives the judgment result from the server and activates the emotion engine. The emotion engine monitors the user's emotional state and analyzes the user's current emotional state (e.g., tension, anxiety, relaxation).

[0272] Step 8:

[0273] The emotion engine determines how the assessment results are communicated. For example, it sends a quiet text notification when the user is relaxed and a gentle voice notification when the user is anxious. It also avoids visual notifications and opts for a combination of text and voice notifications when the user is stressed.

[0274] Step 9:

[0275] The device (app) notifies the user of the judgment result according to the notification method determined by the emotion engine. If it is a phishing email, it displays a warning message saying "This email may be a phishing email," and if it is a legitimate email, it notifies the user saying "This email is safe."

[0276] Step 10:

[0277] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[0278] For example, this process occurs when a user receives a notification email from their bank. When the user opens the email and clicks the phishing detection button, the app sends the email information to a server for detection and notifies the user of the result in the most appropriate way through the sentiment engine. Based on this notification, the user can take appropriate action against the phishing email.

[0279] (Example 2)

[0280] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart device 14 as the "terminal".

[0281] Phishing attacks via email are becoming increasingly sophisticated, making it difficult to take adequate countermeasures with conventional manual or simple automatic detection systems. Furthermore, even when users receive warnings, they may not be able to properly understand and respond to the content. Therefore, there is a need to provide a system that has an effective phishing email detection and an appropriate notification method based on the user's emotional state.

[0282] The specific processing by the specific processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0283] In this invention, the server includes means for extracting the sender domain information, subject, and part of the body of the email, means for querying the generation AI model, means for receiving the determination result from the generation AI model and notifying the user, and means for recognizing the user's emotional state using an emotion engine and optimizing the notification method. Thereby, it is possible to improve the phishing determination accuracy of the email and issue a warning with an optimal notification method according to the user's emotional state.

[0284] "Sender domain information" refers to the Internet domain name of the sender of the email and is information for identifying from which organization or individual the email was sent.

[0285] "Subject" refers to the title part described so that the main idea and content of the email can be understood at a glance.

[0286] "Part of the body" refers to part of the information in the part where the main content of the email is described and is the text or data used to infer the overall content of the email.

[0287] "Generation AI model" is an artificial intelligence model that uses machine learning technology to learn the patterns and features of phishing emails from past data and determines whether the received email is a phishing email.

[0288] The "judgment result" is information indicating the evaluation and status of email security, obtained as a result of the generation AI model analyzing the given email information.

[0289] "Notification" refers to the act or means of communication that a system uses to inform a user of its judgment results.

[0290] An "emotion engine" is a software or hardware function that analyzes a user's emotional state and optimizes notification methods accordingly.

[0291] "Initial setup procedures" refer to the means of performing the initial configuration tasks necessary for the system to function correctly and to interact with applications and other software.

[0292] "To collaborate" refers to the communication and synchronization operations necessary for different applications and systems to share information and function as a single unit.

[0293] "To acquire" refers to the act of a system or application collecting necessary data or information.

[0294] A "warning message" is a message sent by the system to alert the user and may contain information about the possibility of phishing emails or other risks.

[0295] The "optimal format" refers to the format used to convey information in the most effective and easily understandable way, depending on the user's emotional state and circumstances.

[0296] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[0297] First, the user downloads and installs the smartphone application. After installing the app, the user enters their information on the account registration screen to create an account. Next, during the initial setup, the app requests integration with the email app and obtains the necessary access permissions through OAuth authentication. It also requests consent to use the emotion engine, enabling the monitoring of the user's emotional state.

[0298] When an email is received, this application, which is linked to the email app, displays a "Analyze this email" button. When the user clicks this button, the application extracts the sender domain information, subject, and part of the email body, and sends them to the cloud server as an API request.

[0299] The server receives requests from applications and analyzes email information using a generative AI model. Specifically, the server passes the sender domain information, subject, and part of the email body to the generative AI model and requests a determination of whether it is a phishing email. Based on past training data, the generative AI model determines whether the received email has the characteristics of a phishing email. The server receives the determination result from the generative AI model and sends it back to the user's terminal.

[0300] The device (app) receives the judgment result from the server and uses an emotion engine to recognize the user's current emotional state. The emotion engine analyzes input data from the camera, microphone, etc., and analyzes the user's facial expressions and tone of voice. Next, it selects the most appropriate notification method based on the user's emotional state (e.g., tension, anxiety, relaxation). For example, if it is determined that the user is feeling anxious, an audio notification will be selected, and a warning will be given in a gentle tone. Conversely, if the user is relaxed, a text notification will be selected.

[0301] A specific operation example is shown. Suppose the user receives a notification email from the bank. The subject of this email is "Important Notice: Regarding Account Freezing", and a part of the body contains "Your account has been frozen". The app extracts the sender domain "examplebank.com", the subject, and a part of the body, and sends this information to the server. The server uses a generative AI model to determine that "examplebank.com" is not an official domain and concludes that it is a phishing email. The server returns the determination result to the terminal, and the app analyzes the user's emotional state using an emotion engine. For example, if the user is in a relaxed state, it notifies in text that "This email may be phishing", and if the user is in a state of increasing anxiety, it notifies gently in voice.

[0302] In this way, the system of the present invention can improve the phishing determination accuracy of emails and issue warnings in an optimal notification method according to the user's emotional state.

[0303] Example of prompt sentence

[0304] "Please explain a system that determines whether a specific email is a phishing email and provides an optimal notification method based on the user's emotional state. Include a specific example such as notifying in a text message when the user is relaxed and notifying in voice when the user feels anxious."

[0305] The flow of a specific process in Example 2 will be described using FIG. 13.

[0306] Flow of program processing

[0307] Step 1:

[0308] The user downloads and installs a smartphone application. The input is the user's account information (e.g., email address, password), and the output is a success message for account creation. Specifically, the user launches the app, enters the required information on the displayed registration screen, and creates an account.

[0309] Step 2:

[0310] The app requests integration with the user's email application during initial setup. The input is the user's email application credentials, and the output is a notification of successful integration. The app opens an OAuth authentication window and prompts the user to enter their email application credentials. Once authentication is complete, the app establishes integration with the email application and obtains the necessary access permissions.

[0311] Step 3:

[0312] The app requests consent to use the emotion engine. The input is the user's consent information, and the output is a notification that the emotion engine has been enabled. The app displays a consent dialog to the user regarding the use of the emotion engine, and if the user consents, it requests device access permissions such as the camera and microphone, and sets up emotional state monitoring.

[0313] Step 4:

[0314] The user receives an email, and the app displays a "Describe this email" button. The input is the information of the received email, and the output is the display of the "Describe this email" button. When an email is received, this application, which is linked to the email app, displays the "Describe this email" button in the email viewer.

[0315] Step 5:

[0316] When the user clicks the judgment button, the app extracts the sender domain information, subject, and part of the body of the email. The input is the user's click operation, and the output is the extracted email information. The app analyzes the sender domain information, subject, and part of the body of the email and extracts information such as "Sender: phishing@example.com, Subject: Free Gift, Part of Body: You have won."

[0317] Step 6:

[0318] The application sends email information to a cloud server as an API request. The input is the extracted email information, and the output is a success message for sending the API request to the server. The application sends a request to the API endpoint containing the email information and user authentication information.

[0319] Step 7:

[0320] The server receives a request and analyzes the email information using a generative AI model. The input is the email information, and the output is the phishing detection result. The server passes the sender domain, subject, and part of the body of the received email to the generative AI model to analyze whether it is a phishing email. For example, it uses features such as "the sender domain is not an official domain" or "the subject matches a typical phishing email pattern" to make the determination.

[0321] Step 8:

[0322] The server receives the judgment results from the generated AI model and sends them back to the user's terminal. The input is the judgment result from the generated AI model, and the output is the result sent back to the user's terminal. The server organizes the judgment results and sends a result such as "This email is a phishing email" or "This email is safe" to the user's terminal.

[0323] Step 9:

[0324] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state. The input is the judgment result from the server, and the output is the evaluation result of the user's emotional state. The device analyzes input data from the camera and microphone to analyze the user's facial expressions and voice tone.

[0325] Step 10:

[0326] The emotion engine selects the optimal notification method based on the user's emotional state. The input is the result of the user's emotional state evaluation, and the output is the result of selecting the optimal notification format. Based on the user's emotional state (e.g., tension, anxiety, relaxation), the emotion engine selects the most appropriate method from text notifications, voice notifications, and visual notifications.

[0327] Step 11:

[0328] The app displays or notifies the user of a warning message in the most appropriate format based on its assessment results. The input is the optimal notification format and assessment result, and the output is the display or notification of the warning message. For example, if the user is relaxed, a pop-up notification saying "This email may be a phishing attempt" will be displayed, and if the user is feeling anxious, a gentle voice message saying "This email may be a phishing attempt" will be displayed.

[0329] By following these steps, users will be protected from the risks of phishing emails and will receive appropriate notifications tailored to their emotional state.

[0330] (Application Example 2)

[0331] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart device 14 will be referred to as the "terminal."

[0332] Currently, many systems for detecting phishing emails and notifying users simply analyze the email content and display warnings, but this does not take into account the user's psychological state and therefore does not provide sufficient security. Furthermore, the uniform notification method may prevent users from responding appropriately or may cause excessive anxiety. Solving these problems is the objective of this invention.

[0333] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for extracting the sender domain information of an email, means for querying the generation AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generation AI and notifying the user, and means for including an emotion engine that analyzes the user's emotional state and optimizing the notification method based on the emotion engine. This makes it possible to detect phishing emails and provide an optimal notification method that corresponds to the user's psychological state.

[0334] "Sender domain information" refers to information that identifies the domain name used to identify the sender of an email.

[0335] "Generative AI" is a system that uses artificial intelligence technology to learn and analyze email information to determine whether or not it is a phishing email.

[0336] "Means of notifying the user" refers to methods or functions for communicating the judgment result to the user.

[0337] An "emotion engine" is a system that analyzes and recognizes a user's emotional state in real time.

[0338] "Means of optimizing notification methods" refer to means of delivering notifications in the most effective and sensitive way, based on the user's current emotional state.

[0339] "The subject line and part of the email body" refers to the title of the received email and a portion of its content.

[0340] "Initial setup method" refers to the method or function for performing the necessary settings when using the system for the first time.

[0341] "Methods for directly obtaining email information from linked email applications" refers to a function that links with the email application used by the user and directly obtains email information from that application.

[0342] "Means of displaying warning messages" refers to methods or functions for displaying messages on a user's device that inform them that an email may be a phishing email.

[0343] "Text notification" refers to a method of notifying users using text information.

[0344] "Voice notification" refers to a method of notifying users using voice.

[0345] This invention relates to a system that automatically identifies phishing emails and optimizes notification methods using a user's sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[0346] First, the user installs the smartphone application and completes the initial setup. This setup includes integration with the email application and obtaining necessary access permissions through OAuth authentication. The user also agrees to use the emotion engine, allowing for real-time monitoring of their emotional state.

[0347] When an email is received, this system, which is integrated with the email application, extracts the sender domain information, subject, and a portion of the email body, and sends them to the cloud server. This extraction includes analysis to identify the sender domain information of the email. The cloud server uses generative AI to determine whether the sender domain information and email content are legitimate. Based on past data, the generative AI accurately evaluates whether the email is a phishing email.

[0348] The user is notified of the assessment result, but at that time, an emotion engine is used to analyze the user's emotional state (e.g., relaxed, anxious, tense) and select the optimal notification method (text, voice). For example, if the user is relaxed, a text notification is sent, and if they are feeling anxious, a gentle voice notification is sent.

[0349] The primary hardware used includes smartphones and cloud servers, while the main software includes generative AI and an emotion engine. As a concrete example, the legitimacy of an email is determined by sending prompts like the following to the generative AI.

[0350] Example of a prompt:

[0351] Is the email from the domain "examplebank.com" a potential phishing email? Subject: "Important Notice: Account Freeze", Part of the body: "Your account has been frozen. Please check this link immediately."

[0352] In this way, users are protected from the risks of phishing emails and receive appropriate notifications that take their emotions into consideration. This system provides highly accurate and user-friendly security measures by combining generative AI and an emotion engine.

[0353] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0354] Step 1:

[0355] The user installs the smartphone application and completes the initial setup. The user then connects with their email application and obtains the necessary access permissions through OAuth authentication. Additionally, the user agrees to use the emotion engine and configures settings to monitor their emotional state in real time.

[0356] Input: Smartphone application, email application account information

[0357] Output: Application installation and configuration complete, OAuth authentication performed and access permissions obtained.

[0358] Step 2:

[0359] When a user receives an email, the linked smartphone application extracts the sender's domain information, subject, and a portion of the email's body. This provides the basic information about the email.

[0360] Input: Received email

[0361] Output: Sender domain information, subject, and part of the message body.

[0362] Step 3:

[0363] The terminal (application) sends the extracted sender domain information, subject, and a portion of the email body to the cloud server as an API request. This request includes a prompt asking whether the email is a phishing attempt.

[0364] Input: Sender domain information, subject, and part of the message body.

[0365] Output: Sending an API request

[0366] Step 4:

[0367] The server passes the received request to the generating AI, which determines whether the email content and sender domain information have characteristics of a phishing email. Based on past training data, the generating AI analyzes whether the email is a phishing email.

[0368] Input: Sender domain information, subject, part of the message body, prompt message

[0369] Output: Judgment result by the generated AI

[0370] Step 5:

[0371] The server receives the judgment results from the generating AI, organizes the results, and sends them back to the user's terminal. These results include information on whether or not the email is a phishing email.

[0372] Input: Judgment result generated by AI

[0373] Output: Return of judgment result

[0374] Step 6:

[0375] The terminal (application) receives the judgment result from the server and optimizes the notification method using an emotion engine that analyzes the user's current emotional state. For example, if the user is relaxed, a text notification is sent, and if anxiety is heightened, an audio notification is sent.

[0376] Input: Judgment result, user's emotional state

[0377] Output: Selection of an optimized notification method

[0378] Step 7:

[0379] The application notifies the user of the phishing email detection result based on an optimized notification method. For example, if the user is relaxed, it will notify them via text message saying, "This email may be a phishing email," while if the user is feeling anxious, it will notify them of the same message in a gentle voice message.

[0380] Input: Optimized notification method

[0381] Output: Notification to the user

[0382] In this way, users are protected from the risks of phishing emails and can receive appropriate, emotionally sensitive notifications.

[0383] The specific processing unit 290 transmits the result of the specific processing to the smart device 14. In the smart device 14, the control unit 46A causes the output device 40 to output the result of the specific processing. The microphone 38B acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 38B to the data processing device 12. In the data processing device 12, the specific processing unit 290 acquires the audio data.

[0384] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (registered trademark) (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0385] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart device 14.

[0386] [Second Embodiment]

[0387] Figure 3 shows an example of the configuration of the data processing system 210 according to the second embodiment.

[0388] As shown in Figure 3, the data processing system 210 includes a data processing device 12 and smart glasses 214. An example of the data processing device 12 is a server.

[0389] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0390] The smart glasses 214 include a computer 36, a microphone 238, a speaker 240, a camera 42, and a communication interface 44. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, and camera 42 are also connected to the bus 52.

[0391] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0392] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0393] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0394] Figure 4 shows an example of the main functions of the data processing device 12 and the smart glasses 214. As shown in Figure 4, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0395] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0396] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0397] In the smart glasses 214, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0398] Next, the identification processing performed by the identification processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0399] This invention relates to a system that automatically identifies phishing emails and alerts users. To implement this system, a specific method is described for using an AI to analyze the sender domain information, subject, and part of the email body, and for notifying the user of the analysis result.

[0400] overview

[0401] The system of the present invention primarily consists of an application installed on the user's terminal and a server located in the cloud. When a user receives an email, the sender's domain, subject, and body of the email are sent to the cloud server, where a generating AI is used to determine if it is a phishing email, and the result is notified to the user.

[0402] Program processing flow

[0403] 1. User registration and initial setup

[0404] The user first downloads and installs the smartphone application.

[0405] The app requires the user to connect with their email app as part of the initial setup. This connection is established via OAuth authentication, which obtains the necessary access permissions.

[0406] 2. Receiving emails and sending judgment requests

[0407] When a user receives an email, this application, which is integrated with the email app, displays a judgment button in the email view.

[0408] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[0409] The app sends this information to the cloud server as an API request.

[0410] 3. Judgment processing by generating AI

[0411] The server receives requests from applications and parses the email information.

[0412] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[0413] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data. The result of the determination includes information such as "It is a phishing email" or "It is not a phishing email."

[0414] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[0415] 4. User notification of the judgment result

[0416] The app receives the judgment result from the server and reflects the result in the email view.

[0417] If an email is identified as a phishing email, the app will display a warning message to the user such as, "This email may be a phishing attempt."

[0418] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[0419] Specific example

[0420] The following are specific examples of when a user is using a phishing detection service.

[0421] 1. The user receives a notification email from the bank.

[0422] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[0423] 3. The app sends this information to the server.

[0424] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[0425] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[0426] 6. The server receives the judgment result and sends it back to the user.

[0427] 7. The app displays the result and warns, "This email may be a phishing attempt."

[0428] In this way, users are protected from the risks of phishing emails and can use email with peace of mind. This invention enhances user security by performing highly accurate judgments using generation AI.

[0429] The following describes the processing flow.

[0430] Step 1:

[0431] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. The integration is performed via OAuth authentication, and the necessary access permissions are obtained.

[0432] Step 2:

[0433] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[0434] Step 3:

[0435] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[0436] Step 4:

[0437] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[0438] Step 5:

[0439] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[0440] Step 6:

[0441] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[0442] Step 7:

[0443] The device (app) receives the judgment result from the server and reflects it on the screen within the email view. If it is determined to be a phishing email, the app displays a warning message to the user saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[0444] Step 8:

[0445] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[0446] (Example 1)

[0447] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0448] Conventional email filtering systems have difficulty accurately identifying phishing emails, resulting in problems with false positives and missed detections. Furthermore, insufficient warnings and notifications to users can increase security risks. This increases the risk of personal information leaks and unauthorized access, as well as the likelihood of users becoming victims of phishing emails. Therefore, the present invention aims to solve these problems by providing a system that uses a generative AI model to perform advanced phishing email detection and provide users with rapid and accurate warnings.

[0449] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0450] In this invention, the server includes means for extracting the sender domain information of an email, means for extracting the subject and part of the body, means for querying a generating AI whether the sender domain information and the subject and body have characteristics of phishing, and means for notifying the user of the determination result from the generating AI. This enables highly accurate detection of phishing emails and rapid user notification.

[0451] "Email sender domain information" refers to the domain portion of the sender address of a received email, and is used to identify the origin of the email.

[0452] The "subject line" is the text information displayed as the title of an email, and is used to concisely express the content of the email.

[0453] The "body" of an email is the text area that contains the main content of the email, including messages and information addressed to the user.

[0454] "Generative AI" is an artificial intelligence system that learns from past data and performs inferences and judgments on new input data, and is used for things like detecting phishing in emails.

[0455] An "API request" is a request from an application to send data to a service such as a server, and is called to perform a specific function.

[0456] "User devices" refer to all electronic devices used by individuals, including smartphones, tablets, and personal computers.

[0457] A "prompt statement" is an input statement given to a generating AI to request a specific judgment, and it serves as a criterion for the generating AI to produce an appropriate response.

[0458] A "cloud server" is a remote server provided over the internet, used for storing and processing data.

[0459] This invention relates to a system that automatically identifies phishing emails and alerts users. The main components of this system are an application installed on the user's terminal and a server located in the cloud.

[0460] System Configuration

[0461] Hardware and software

[0462] User device: Uses devices such as smartphones, tablets, and personal computers. This includes smartphones running iOS or Android operating systems.

[0463] Application: A dedicated application installed on the user's device. It integrates with the email application and has the function of extracting email information. This application uses OAuth authentication to integrate with the email application.

[0464] Cloud server: A remote server accessible via the internet, which performs phishing detection using AI models for analyzing and generating email information.

[0465] Generative AI Model: A pre-trained AI model is used to determine whether the input email information is a phishing email.

[0466] How it works

[0467] 1. User registration and initial setup

[0468] Users download and install the app from their smartphone's app store. Upon first launching the app, a user registration screen appears. Users enter their email address, password, and other information to create an account.

[0469] The app performs user authentication and requests integration with the email application. This integration is securely performed through OAuth authentication.

[0470] 2. Receiving emails and sending judgment requests

[0471] When a user receives a new email, the app interacts with the email app and displays a "Determine" button in the email view.

[0472] When the user clicks the "Analyze" button, the app automatically extracts the sender domain, subject, and part of the email body and sends them to the cloud server.

[0473] 3. Judgment by Generating AI

[0474] The server receives a request from the app and analyzes the email information. Based on the sender domain, subject, and part of the body, it generates a prompt message and inputs this prompt message into the AI ​​model.

[0475] The generative AI model learns from past data and determines whether a received email has phishing characteristics.

[0476] For example, the prompt message "Sender domain: examplebank.com, Subject: Important Notice: Account Freezing, Body: Your account has been frozen" is input to the generating AI model.

[0477] 4. Notification of the judgment result

[0478] The server receives the judgment results obtained from the generated AI model and sends those results back to the user's terminal.

[0479] The app displays the received judgment results within the email viewer. If it is determined to be a phishing email, it displays a warning message saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[0480] Specific example

[0481] Let's illustrate this with an example where a user receives a notification email from their bank. Suppose the sender domain of this notification email is "examplebank.com", the subject is "Important Notice: Account Freezing", and the body of the email is "Your account has been frozen". In this case, the app extracts this information and sends it to a cloud server. The cloud server passes this information to a generating AI model to determine whether it is a phishing email. The result of the determination is returned, and the user is notified that "This email may be a phishing email".

[0482] This system protects users from phishing emails and reduces security risks.

[0483] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0484] Step 1:

[0485] The user downloads and installs the application from the app store on their smartphone.

[0486] Input: Application from the app store

[0487] Output: Installed applications

[0488] Specific operation: The user searches for the app in the device's app store and presses the install button, which downloads and installs the application on the user's device.

[0489] Step 2:

[0490] When a user launches the app for the first time, the application displays a user information registration screen.

[0491] Input: User information such as email address and password

[0492] Output: User information registered in the application

[0493] Specific operation: The user launches the app and creates an account by entering their email address and password on the registration screen. The application saves this information to a database.

[0494] Step 3:

[0495] The application performs user authentication and sets up integration with the email application.

[0496] Input: Display OAuth authentication prompt

[0497] Output: Settings for linking with the email app

[0498] Specific operation: The app requests integration with the email app used by the user using OAuth. Once the user grants authentication, the app obtains the necessary permissions and the integration is complete.

[0499] Step 4:

[0500] When a user receives a new email, the application checks the email information. A "Determine" button is displayed in the email view.

[0501] Input: Received email

[0502] Output: Email view showing the "Determine" button

[0503] Specific operation: When a user receives an email, the app parses the email and adds a "Determine" button to the view.

[0504] Step 5:

[0505] When the user clicks the "Determine" button, the application automatically extracts the sender domain, subject, and part of the email body, and sends them to the cloud server.

[0506] Input: Sender domain of the email, subject, and part of the email body.

[0507] Output: Email information sent as an API request

[0508] Specific operation: When the user clicks a button, the app extracts information from the email, compiles it, and sends it to the cloud server in JSON format.

[0509] Step 6:

[0510] The server receives a request from the app and parses the email information. It generates a prompt message and inputs it into the generation AI model.

[0511] Input: Email information in JSON format

[0512] Output: Prompt text input to the generating AI model

[0513] Specific operation: The server parses the received JSON and generates a prompt message based on the email content, such as "Sender domain: example.com, Subject: Important Notice, Body: Your account has been frozen," and inputs it into the generation AI model.

[0514] Step 7:

[0515] The generative AI model determines whether an email is a phishing email based on the prompt text.

[0516] Input: Prompt message

[0517] Output: Result of determining whether it is a phishing email.

[0518] Specific operation: The generative AI model utilizes past training data to analyze the information contained in the prompt message and determine whether or not the email is a phishing email. The result is then sent back to the server.

[0519] Step 8:

[0520] The server receives the judgment results from the generated AI model and sends them back to the user's terminal.

[0521] Input: Judgment result from the generated AI model

[0522] Output: Judgment result sent back to the user terminal

[0523] Specific operation: The server organizes the judgment results of the generated AI model, converts them into a data format for return to the user terminal, and sends them as an API response.

[0524] Step 9:

[0525] The application receives the judgment result from the server and displays it in the email view.

[0526] Input: Judgment result from the server

[0527] Output: Judgment result displayed in the email view

[0528] Specific operation: The application receives an API response and displays the result in the email view as either "This email may be a phishing attempt" or "This email is safe." The user then takes appropriate action based on this.

[0529] (Application Example 1)

[0530] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0531] With the threat of phishing emails on the rise, there is a need for a means to determine the security of emails received by users in real time and to warn them appropriately. However, many current email services require users to make their own judgments, which carries the risk of misjudgment. There is also a need for a system that reduces the burden on users and identifies phishing emails quickly and with high accuracy.

[0532] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0533] In this invention, the server includes means for extracting the sender domain information of an email, means for querying a generating AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generating AI and notifying the user, means for initial setup to link with the user's email account, means for directly obtaining email information from the linked email account, and means for displaying a warning message on the user's device based on the determination result. This makes it possible to check the security of emails received by the user in real time and to issue a quick and accurate warning against phishing emails.

[0534] "Email sender domain information" refers to the original internet domain name from which the email was sent.

[0535] "Generative AI" is a type of artificial intelligence technology that refers to a system that automatically performs specific tasks using natural language processing and pattern recognition.

[0536] The "judgment result" refers to the result of the AI's judgment on the phishing email, and indicates whether or not the email is a phishing email.

[0537] "Means of notifying the user" refers to the methods and processes for informing the user of the email's evaluation results, which are usually provided in the form of on-screen messages or push notifications.

[0538] "Initial setup means" refers to the methods and processes for performing the initial setup of the system, including, for example, the steps for setting up the link between the user and their email account.

[0539] "Means of directly obtaining email information" refers to a mechanism for directly obtaining necessary email information from the email account used by the user.

[0540] "Means of displaying warning messages" refers to methods and processes for displaying warning messages to alert users to suspicious emails, such as phishing emails.

[0541] This invention relates to a system that automatically identifies phishing emails and notifies the user. This system works in conjunction with the user's email account to check the security of emails in real time and displays a warning message if an email is suspected to be a phishing email.

[0542] The main components of the system are as follows:

[0543] User terminal: An application installed on a device such as a smartphone.

[0544] Cloud server: A server that receives data and uses generated AI to identify phishing emails.

[0545] Generative AI models: Artificial intelligence systems that use natural language processing and pattern recognition to determine the legitimacy of emails. Specific examples include OpenAI's ChatGPT and Google's BERT.

[0546] Program processing flow

[0547] 1. User registration and initial setup

[0548] The user downloads and installs the application on their smartphone. The application prompts the user for initial setup and configures the linking with their email account. OAuth authentication is used for the linking to obtain the necessary access permissions.

[0549] 2. Receiving emails and sending judgment requests

[0550] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. This information is then sent to a cloud server as an API request.

[0551] 3. Judgment processing by generating AI

[0552] The cloud server passes the received email information to an AI model that determines whether it is a phishing email. The result is indicated as either "It is a phishing email" or "It is not a phishing email." This information is then sent back to the user's device.

[0553] 4. User notification of the judgment result

[0554] The user's terminal receives the judgment result from the server and reflects the result in the email view. If it is determined to be a phishing email, the user will be shown a warning message such as "This email may be a phishing email."

[0555] As a concrete example, the following process is performed: When a user receives a "notification email from the bank," the sender's domain, subject, and part of the email body are extracted and sent to a cloud server. The cloud server makes a judgment based on a generated AI model, and if it determines, for example, that "examplebank.com" is not an official domain, it determines that the email is likely a phishing attempt. The user is then shown a warning that "this email may be a phishing attempt."

[0556] The following are examples of prompt messages:

[0557] "

[0558] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[0559] Sender: example@examplebank.com

[0560] Subject: Important Notice: Account Freezing

[0561] Part of the text: Please check.

[0562] "

[0563] This system allows users to verify the security of incoming emails and protect themselves from phishing risks. The highly accurate and rapid detection using generated AI significantly improves user security.

[0564] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0565] Step 1:

[0566] The user downloads and installs an application on their smartphone. The input is the user's download action and the app installation process, and the output is the installed application. Specifically, the user downloads the app from the Apple App Store or Google Play Store and installs it on their device following the installation instructions.

[0567] Step 2:

[0568] The application prompts the user for initial setup and configures the linking of their email account. Inputs include the user's email account information and the OAuth authentication process, while output is the linked email account. Specifically, the user configures the email account linking within the app, and the app obtains the necessary access permissions through OAuth authentication.

[0569] Step 3:

[0570] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. The input is the information of the received email, and the output is the extracted sender's domain, subject, and portion of the body. Specifically, the app runs in the background and executes code to parse the information of the received email.

[0571] Step 4:

[0572] The application sends the extracted email information to the cloud server as an API request. The input is the extracted email information and the API request, and the output is the status indicating that the transmission to the cloud server is complete. Specifically, the application uses an HTTP POST request to send the email information to the server.

[0573] Step 5:

[0574] The cloud server passes the received email information to the generating AI model and makes a judgment request. The input is the sent email information, and the output is the judgment result of the generating AI model. Specifically, the cloud server converts the email information into a prompt message and inputs it into the generating AI model. For example,

[0575] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[0576] Sender: example@examplebank.com

[0577] Subject: Important Notice: Account Freezing

[0578] Part of the text: Please check.

[0579] The prompt " " is sent to the generating AI.

[0580] Step 6:

[0581] The generative AI model determines the legitimacy of an email based on the prompt text and returns a result indicating whether or not it is a phishing email. The input is the prompt text, and the output is a determination such as "This is a phishing email" or "This is not a phishing email." Specifically, the generative AI compares the text in the email with past training data to determine whether or not it has phishing characteristics.

[0582] Step 7:

[0583] The cloud server receives the judgment result from the generated AI and sends it back to the user's terminal. The input is the judgment result, and the output is the message sent to the user's terminal. Specifically, the cloud server uses an HTTP response to send the judgment result to the application.

[0584] Step 8:

[0585] The user's device receives the judgment result from the server and reflects the result in the email view. The input is the judgment result from the cloud server, and the output is the result displayed to the user. Specifically, the app executes code to display the judgment result in the notification area or within the email app. For example, it might display a warning message such as "This email may be a phishing attempt" as a pop-up.

[0586] This process allows users to verify the security of incoming emails in real time and protect themselves from phishing risks. The rapid and highly accurate judgment using generated AI significantly improves user security.

[0587] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0588] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system uses a generating AI to determine the sender domain information and content of emails, and notifies the user of the determination result. Furthermore, by adding a function that recognizes user sentiment and adjusts the notification method and content accordingly, it achieves more effective security measures.

[0589] overview

[0590] The system of this invention combines a smartphone application, a cloud-based server, and an emotion engine. Upon receiving an email, it extracts the sender's domain information, subject, and a portion of the email body, sends this information to the server, and is judged by a generating AI. The judgment result is notified to the user, and at that time, the user's emotion engine is used to select the most appropriate notification method. The specific processing flow is described below.

[0591] Program processing flow

[0592] 1. User registration and initial setup

[0593] The user downloads and installs the smartphone application.

[0594] The app requests integration with the user's email app during initial setup. This integration is performed via OAuth authentication, which obtains the necessary access permissions.

[0595] The app will ask for your consent to use the emotion engine and configure it to monitor the user's emotional state.

[0596] 2. Receiving emails and sending judgment requests

[0597] When a user receives an email, this application, which is linked to the email app, displays a judgment button.

[0598] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[0599] The app sends this information to the cloud server as an API request.

[0600] 3. Judgment processing by generating AI

[0601] The server receives requests from applications and parses the email information.

[0602] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[0603] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data.

[0604] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[0605] 4. Notification of judgment results and application of the emotion engine

[0606] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state.

[0607] The emotion engine selects the optimal notification method (e.g., text, voice, visual) based on the user's emotional state (e.g., tension, anxiety, relaxation).

[0608] Based on the detection result, the app displays or notifies the user in the most appropriate way with a warning message stating, "This email may be a phishing attempt."

[0609] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[0610] Specific example

[0611] The following are specific examples of when a user is using a phishing detection service.

[0612] 1. The user receives a notification email from the bank.

[0613] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[0614] 3. The app sends this information to the server.

[0615] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[0616] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[0617] 6. The server receives the judgment result and sends it back to the user.

[0618] 7. The app receives the assessment result and analyzes the user's emotional state using its emotion engine. For example, if the user is relaxed, it will notify them via text; if they are feeling anxious, it will notify them gently via voice.

[0619] 8. The app displays or notifies the user in a format that is most appropriate for them, stating, "This email may be a phishing attempt."

[0620] In this way, users are protected from the risks of phishing emails and can receive appropriate notifications that take their emotions into consideration. The present invention provides a highly accurate and user-friendly security system that combines generative AI and an emotion engine.

[0621] The following describes the processing flow.

[0622] Step 1:

[0623] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. This integration is performed via OAuth authentication, obtaining the necessary access permissions. Furthermore, it requests permission to enable the emotion engine and monitor the user's emotional state.

[0624] Step 2:

[0625] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[0626] Step 3:

[0627] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[0628] Step 4:

[0629] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[0630] Step 5:

[0631] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[0632] Step 6:

[0633] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[0634] Step 7:

[0635] The device (app) receives the judgment result from the server and activates the emotion engine. The emotion engine monitors the user's emotional state and analyzes the user's current emotional state (e.g., tension, anxiety, relaxation).

[0636] Step 8:

[0637] The emotion engine determines how the assessment results are communicated. For example, it sends a quiet text notification when the user is relaxed and a gentle voice notification when the user is anxious. It also avoids visual notifications and opts for a combination of text and voice notifications when the user is stressed.

[0638] Step 9:

[0639] The device (app) notifies the user of the judgment result according to the notification method determined by the emotion engine. If it is a phishing email, it displays a warning message saying "This email may be a phishing email," and if it is a legitimate email, it notifies the user saying "This email is safe."

[0640] Step 10:

[0641] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[0642] For example, this process occurs when a user receives a notification email from their bank. When the user opens the email and clicks the phishing detection button, the app sends the email information to a server for detection and notifies the user of the result in the most appropriate way through the sentiment engine. Based on this notification, the user can take appropriate action against the phishing email.

[0643] (Example 2)

[0644] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the smart glasses 214 will be referred to as the "terminal".

[0645] Phishing attacks via email are becoming increasingly sophisticated, making it difficult to adequately counter them with traditional manual or simple automated detection systems. Furthermore, users may not be able to properly understand or respond to warnings. Therefore, there is a need to provide a system that offers effective phishing email detection and appropriate notification methods based on the user's emotional state.

[0646] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[0647] In this invention, the server includes means for extracting the sender domain information, subject, and a portion of the body of an email; means for querying a generative AI model; means for receiving the judgment result from the generative AI model and notifying the user; and means for recognizing the user's emotional state using an emotion engine and optimizing the notification method. This improves the accuracy of email phishing detection and enables the issuance of warnings using the most appropriate notification method according to the user's emotional state.

[0648] "Sender domain information" refers to the internet domain name from which an email was sent, and is information that identifies which organization or individual sent the email.

[0649] The "subject line" refers to the title portion of an email, designed to allow recipients to understand the main point and content of the email at a glance.

[0650] "Part of the email body" refers to a portion of the information contained within the main content of an email, and is the text or data used to infer the overall content of the email.

[0651] A "generative AI model" is an artificial intelligence model that uses machine learning techniques to learn patterns and characteristics of phishing emails from past data and determine whether a received email is a phishing email.

[0652] The "judgment result" is information indicating the evaluation and status of email security, obtained as a result of the generation AI model analyzing the given email information.

[0653] "Notification" refers to the act or means of communication that a system uses to inform a user of its judgment results.

[0654] An "emotion engine" is a software or hardware function that analyzes a user's emotional state and optimizes notification methods accordingly.

[0655] "Initial setup procedures" refer to the means of performing the initial configuration tasks necessary for the system to function correctly and to interact with applications and other software.

[0656] "To collaborate" refers to the communication and synchronization operations necessary for different applications and systems to share information and function as a single unit.

[0657] "To acquire" refers to the act of a system or application collecting necessary data or information.

[0658] A "warning message" is a message sent by the system to alert the user and may contain information about the possibility of phishing emails or other risks.

[0659] The "optimal format" refers to the format used to convey information in the most effective and easily understandable way, depending on the user's emotional state and circumstances.

[0660] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[0661] First, the user downloads and installs the smartphone application. After installing the app, the user enters their information on the account registration screen to create an account. Next, during the initial setup, the app requests integration with the email app and obtains the necessary access permissions through OAuth authentication. It also requests consent to use the emotion engine, enabling the monitoring of the user's emotional state.

[0662] When an email is received, this application, which is linked to the email app, displays a "Analyze this email" button. When the user clicks this button, the application extracts the sender domain information, subject, and part of the email body, and sends them to the cloud server as an API request.

[0663] The server receives requests from applications and analyzes email information using a generative AI model. Specifically, the server passes the sender domain information, subject, and part of the email body to the generative AI model and requests a determination of whether it is a phishing email. Based on past training data, the generative AI model determines whether the received email has the characteristics of a phishing email. The server receives the determination result from the generative AI model and sends it back to the user's terminal.

[0664] The device (app) receives the judgment result from the server and uses an emotion engine to recognize the user's current emotional state. The emotion engine analyzes input data from the camera, microphone, etc., and analyzes the user's facial expressions and tone of voice. Next, it selects the most appropriate notification method based on the user's emotional state (e.g., tension, anxiety, relaxation). For example, if it is determined that the user is feeling anxious, an audio notification will be selected, and a warning will be given in a gentle tone. Conversely, if the user is relaxed, a text notification will be selected.

[0665] Let's look at a concrete example of how it works. Suppose a user receives a notification email from their bank. The subject line of this email is "Important Notice: Account Freeze," and part of the body contains the phrase "Your account has been frozen." The app extracts the sender domain "examplebank.com," the subject line, and part of the body, and sends this information to the server. The server uses a generative AI model to determine that "examplebank.com" is not an official domain and identifies it as a phishing email. The server sends the result back to the device, and the app uses an emotion engine to analyze the user's emotional state. For example, if the user is relaxed, it will notify them in text that "This email may be a phishing attempt." If the user is feeling anxious, it will notify them gently in voice.

[0666] In this way, the system of the present invention can improve the accuracy of email phishing detection and issue warnings using the most appropriate notification method according to the user's emotional state.

[0667] Example of a prompt

[0668] "Describe a system that determines whether a particular email is a phishing email and provides the most appropriate notification method based on the user's emotional state. Include specific examples, such as notifying the user via text message when they are relaxed and via voice notification when they are feeling anxious."

[0669] The flow of the specific processing in Example 2 will be explained using Figure 13.

[0670] Program processing flow

[0671] Step 1:

[0672] The user downloads and installs a smartphone application. The input is the user's account information (e.g., email address, password), and the output is a success message for account creation. Specifically, the user launches the app, enters the required information on the displayed registration screen, and creates an account.

[0673] Step 2:

[0674] The app requests integration with the user's email application during initial setup. The input is the user's email application credentials, and the output is a notification of successful integration. The app opens an OAuth authentication window and prompts the user to enter their email application credentials. Once authentication is complete, the app establishes integration with the email application and obtains the necessary access permissions.

[0675] Step 3:

[0676] The app requests consent to use the emotion engine. The input is the user's consent information, and the output is a notification that the emotion engine has been enabled. The app displays a consent dialog to the user regarding the use of the emotion engine, and if the user consents, it requests device access permissions such as the camera and microphone, and sets up emotional state monitoring.

[0677] Step 4:

[0678] The user receives an email, and the app displays a "Describe this email" button. The input is the information of the received email, and the output is the display of the "Describe this email" button. When an email is received, this application, which is linked to the email app, displays the "Describe this email" button in the email viewer.

[0679] Step 5:

[0680] When the user clicks the judgment button, the app extracts the sender domain information, subject, and part of the body of the email. The input is the user's click operation, and the output is the extracted email information. The app analyzes the sender domain information, subject, and part of the body of the email and extracts information such as "Sender: phishing@example.com, Subject: Free Gift, Part of Body: You have won."

[0681] Step 6:

[0682] The application sends email information to a cloud server as an API request. The input is the extracted email information, and the output is a success message for sending the API request to the server. The application sends a request to the API endpoint containing the email information and user authentication information.

[0683] Step 7:

[0684] The server receives a request and analyzes the email information using a generative AI model. The input is the email information, and the output is the phishing detection result. The server passes the sender domain, subject, and part of the body of the received email to the generative AI model to analyze whether it is a phishing email. For example, it uses features such as "the sender domain is not an official domain" or "the subject matches a typical phishing email pattern" to make the determination.

[0685] Step 8:

[0686] The server receives the judgment results from the generated AI model and sends them back to the user's terminal. The input is the judgment result from the generated AI model, and the output is the result sent back to the user's terminal. The server organizes the judgment results and sends a result such as "This email is a phishing email" or "This email is safe" to the user's terminal.

[0687] Step 9:

[0688] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state. The input is the judgment result from the server, and the output is the evaluation result of the user's emotional state. The device analyzes input data from the camera and microphone to analyze the user's facial expressions and voice tone.

[0689] Step 10:

[0690] The emotion engine selects the optimal notification method based on the user's emotional state. The input is the result of the user's emotional state evaluation, and the output is the result of selecting the optimal notification format. Based on the user's emotional state (e.g., tension, anxiety, relaxation), the emotion engine selects the most appropriate method from text notifications, voice notifications, and visual notifications.

[0691] Step 11:

[0692] The app displays or notifies the user of a warning message in the most appropriate format based on its assessment results. The input is the optimal notification format and assessment result, and the output is the display or notification of the warning message. For example, if the user is relaxed, a pop-up notification saying "This email may be a phishing attempt" will be displayed, and if the user is feeling anxious, a gentle voice message saying "This email may be a phishing attempt" will be displayed.

[0693] By following these steps, users will be protected from the risks of phishing emails and will receive appropriate notifications tailored to their emotional state.

[0694] (Application Example 2)

[0695] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the smart glasses 214 will be referred to as the "terminal."

[0696] Currently, many systems for detecting phishing emails and notifying users simply analyze the email content and display warnings, but this does not take into account the user's psychological state and therefore does not provide sufficient security. Furthermore, the uniform notification method may prevent users from responding appropriately or may cause excessive anxiety. Solving these problems is the objective of this invention.

[0697] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for extracting the sender domain information of an email, means for querying the generation AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generation AI and notifying the user, and means for including an emotion engine that analyzes the user's emotional state and optimizing the notification method based on the emotion engine. This makes it possible to detect phishing emails and provide an optimal notification method that corresponds to the user's psychological state.

[0698] "Sender domain information" refers to information that identifies the domain name used to identify the sender of an email.

[0699] "Generative AI" is a system that uses artificial intelligence technology to learn and analyze email information to determine whether or not it is a phishing email.

[0700] "Means of notifying the user" refers to methods or functions for communicating the judgment result to the user.

[0701] An "emotion engine" is a system that analyzes and recognizes a user's emotional state in real time.

[0702] "Means of optimizing notification methods" refer to means of delivering notifications in the most effective and sensitive way, based on the user's current emotional state.

[0703] "The subject line and part of the email body" refers to the title of the received email and a portion of its content.

[0704] "Initial setup method" refers to the method or function for performing the necessary settings when using the system for the first time.

[0705] "Methods for directly obtaining email information from linked email applications" refers to a function that links with the email application used by the user and directly obtains email information from that application.

[0706] "Means of displaying warning messages" refers to methods or functions for displaying messages on a user's device that inform them that an email may be a phishing email.

[0707] "Text notification" refers to a method of notifying users using text information.

[0708] "Voice notification" refers to a method of notifying users using voice.

[0709] This invention relates to a system that automatically identifies phishing emails and optimizes notification methods using a user's sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[0710] First, the user installs the smartphone application and completes the initial setup. This setup includes integration with the email application and obtaining necessary access permissions through OAuth authentication. The user also agrees to use the emotion engine, allowing for real-time monitoring of their emotional state.

[0711] When an email is received, this system, which is integrated with the email application, extracts the sender domain information, subject, and a portion of the email body, and sends them to the cloud server. This extraction includes analysis to identify the sender domain information of the email. The cloud server uses generative AI to determine whether the sender domain information and email content are legitimate. Based on past data, the generative AI accurately evaluates whether the email is a phishing email.

[0712] The user is notified of the assessment result, but at that time, an emotion engine is used to analyze the user's emotional state (e.g., relaxed, anxious, tense) and select the optimal notification method (text, voice). For example, if the user is relaxed, a text notification is sent, and if they are feeling anxious, a gentle voice notification is sent.

[0713] The primary hardware used includes smartphones and cloud servers, while the main software includes generative AI and an emotion engine. As a concrete example, the legitimacy of an email is determined by sending prompts like the following to the generative AI.

[0714] Example of a prompt:

[0715] Is the email from the domain "examplebank.com" a potential phishing email? Subject: "Important Notice: Account Freeze", Part of the body: "Your account has been frozen. Please check this link immediately."

[0716] In this way, users are protected from the risks of phishing emails and receive appropriate notifications that take their emotions into consideration. This system provides highly accurate and user-friendly security measures by combining generative AI and an emotion engine.

[0717] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[0718] Step 1:

[0719] The user installs the smartphone application and completes the initial setup. The user then connects with their email application and obtains the necessary access permissions through OAuth authentication. Additionally, the user agrees to use the emotion engine and configures settings to monitor their emotional state in real time.

[0720] Input: Smartphone application, email application account information

[0721] Output: Application installation and configuration complete, OAuth authentication performed and access permissions obtained.

[0722] Step 2:

[0723] When a user receives an email, the linked smartphone application extracts the sender's domain information, subject, and a portion of the email's body. This provides the basic information about the email.

[0724] Input: Received email

[0725] Output: Sender domain information, subject, and part of the message body.

[0726] Step 3:

[0727] The terminal (application) sends the extracted sender domain information, subject, and a portion of the email body to the cloud server as an API request. This request includes a prompt asking whether the email is a phishing attempt.

[0728] Input: Sender domain information, subject, and part of the message body.

[0729] Output: Sending an API request

[0730] Step 4:

[0731] The server passes the received request to the generating AI, which determines whether the email content and sender domain information have characteristics of a phishing email. Based on past training data, the generating AI analyzes whether the email is a phishing email.

[0732] Input: Sender domain information, subject, part of the message body, prompt message

[0733] Output: Judgment result by the generated AI

[0734] Step 5:

[0735] The server receives the judgment results from the generating AI, organizes the results, and sends them back to the user's terminal. These results include information on whether or not the email is a phishing email.

[0736] Input: Judgment result generated by AI

[0737] Output: Return of judgment result

[0738] Step 6:

[0739] The terminal (application) receives the judgment result from the server and optimizes the notification method using an emotion engine that analyzes the user's current emotional state. For example, if the user is relaxed, a text notification is sent, and if anxiety is heightened, an audio notification is sent.

[0740] Input: Judgment result, user's emotional state

[0741] Output: Selection of an optimized notification method

[0742] Step 7:

[0743] The application notifies the user of the phishing email detection result based on an optimized notification method. For example, if the user is relaxed, it will notify them via text message saying, "This email may be a phishing email," while if the user is feeling anxious, it will notify them of the same message in a gentle voice message.

[0744] Input: Optimized notification method

[0745] Output: Notification to the user

[0746] In this way, users are protected from the risks of phishing emails and can receive appropriate, emotionally sensitive notifications.

[0747] The specific processing unit 290 transmits the result of the specific processing to the smart glasses 214. In the smart glasses 214, the control unit 46A causes the speaker 240 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[0748] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[0749] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the smart glasses 214.

[0750] [Third Embodiment]

[0751] Figure 5 shows an example of the configuration of the data processing system 310 according to the third embodiment.

[0752] As shown in Figure 5, the data processing system 310 includes a data processing device 12 and a headset terminal 314. An example of the data processing device 12 is a server.

[0753] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[0754] The headset terminal 314 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a display 343. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and display 343 are also connected to the bus 52.

[0755] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[0756] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[0757] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[0758] Figure 6 shows an example of the main functions of the data processing device 12 and the headset terminal 314. As shown in Figure 6, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[0759] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[0760] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[0761] In the headset terminal 314, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[0762] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the headset terminal 314 will be referred to as the "terminal".

[0763] This invention relates to a system that automatically identifies phishing emails and alerts users. To implement this system, a specific method is described for using an AI to analyze the sender domain information, subject, and part of the email body, and for notifying the user of the analysis result.

[0764] overview

[0765] The system of the present invention primarily consists of an application installed on the user's terminal and a server located in the cloud. When a user receives an email, the sender's domain, subject, and body of the email are sent to the cloud server, where a generating AI is used to determine if it is a phishing email, and the result is notified to the user.

[0766] Program processing flow

[0767] 1. User registration and initial setup

[0768] The user first downloads and installs the smartphone application.

[0769] The app requires the user to connect with their email app as part of the initial setup. This connection is established via OAuth authentication, which obtains the necessary access permissions.

[0770] 2. Receiving emails and sending judgment requests

[0771] When a user receives an email, this application, which is integrated with the email app, displays a judgment button in the email view.

[0772] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[0773] The app sends this information to the cloud server as an API request.

[0774] 3. Judgment processing by generating AI

[0775] The server receives requests from applications and parses the email information.

[0776] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[0777] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data. The result of the determination includes information such as "It is a phishing email" or "It is not a phishing email."

[0778] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[0779] 4. User notification of the judgment result

[0780] The app receives the judgment result from the server and reflects the result in the email view.

[0781] If an email is identified as a phishing email, the app will display a warning message to the user such as, "This email may be a phishing attempt."

[0782] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[0783] Specific example

[0784] The following are specific examples of when a user is using a phishing detection service.

[0785] 1. The user receives a notification email from the bank.

[0786] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[0787] 3. The app sends this information to the server.

[0788] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[0789] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[0790] 6. The server receives the judgment result and sends it back to the user.

[0791] 7. The app displays the result and warns, "This email may be a phishing attempt."

[0792] In this way, users are protected from the risks of phishing emails and can use email with peace of mind. This invention enhances user security by performing highly accurate judgments using generation AI.

[0793] The following describes the processing flow.

[0794] Step 1:

[0795] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. The integration is performed via OAuth authentication, and the necessary access permissions are obtained.

[0796] Step 2:

[0797] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[0798] Step 3:

[0799] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[0800] Step 4:

[0801] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[0802] Step 5:

[0803] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[0804] Step 6:

[0805] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[0806] Step 7:

[0807] The device (app) receives the judgment result from the server and reflects it on the screen within the email view. If it is determined to be a phishing email, the app displays a warning message to the user saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[0808] Step 8:

[0809] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[0810] (Example 1)

[0811] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0812] Conventional email filtering systems have difficulty accurately identifying phishing emails, resulting in problems with false positives and missed detections. Furthermore, insufficient warnings and notifications to users can increase security risks. This increases the risk of personal information leaks and unauthorized access, as well as the likelihood of users becoming victims of phishing emails. Therefore, the present invention aims to solve these problems by providing a system that uses a generative AI model to perform advanced phishing email detection and provide users with rapid and accurate warnings.

[0813] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[0814] In this invention, the server includes means for extracting the sender domain information of an email, means for extracting the subject and part of the body, means for querying a generating AI whether the sender domain information and the subject and body have characteristics of phishing, and means for notifying the user of the determination result from the generating AI. This enables highly accurate detection of phishing emails and rapid user notification.

[0815] "Email sender domain information" refers to the domain portion of the sender address of a received email, and is used to identify the origin of the email.

[0816] The "subject line" is the text information displayed as the title of an email, and is used to concisely express the content of the email.

[0817] The "body" of an email is the text area that contains the main content of the email, including messages and information addressed to the user.

[0818] "Generative AI" is an artificial intelligence system that learns from past data and performs inferences and judgments on new input data, and is used for things like detecting phishing in emails.

[0819] An "API request" is a request from an application to send data to a service such as a server, and is called to perform a specific function.

[0820] "User devices" refer to all electronic devices used by individuals, including smartphones, tablets, and personal computers.

[0821] A "prompt statement" is an input statement given to a generating AI to request a specific judgment, and it serves as a criterion for the generating AI to produce an appropriate response.

[0822] A "cloud server" is a remote server provided over the internet, used for storing and processing data.

[0823] This invention relates to a system that automatically identifies phishing emails and alerts users. The main components of this system are an application installed on the user's terminal and a server located in the cloud.

[0824] System Configuration

[0825] Hardware and software

[0826] User device: Uses devices such as smartphones, tablets, and personal computers. This includes smartphones running iOS or Android operating systems.

[0827] Application: A dedicated application installed on the user's device. It integrates with the email application and has the function of extracting email information. This application uses OAuth authentication to integrate with the email application.

[0828] Cloud server: A remote server accessible via the internet, which performs phishing detection using AI models for analyzing and generating email information.

[0829] Generative AI Model: A pre-trained AI model is used to determine whether the input email information is a phishing email.

[0830] How it works

[0831] 1. User registration and initial setup

[0832] Users download and install the app from their smartphone's app store. Upon first launching the app, a user registration screen appears. Users enter their email address, password, and other information to create an account.

[0833] The app performs user authentication and requests integration with the email application. This integration is securely performed through OAuth authentication.

[0834] 2. Receiving emails and sending judgment requests

[0835] When a user receives a new email, the app interacts with the email app and displays a "Determine" button in the email view.

[0836] When the user clicks the "Analyze" button, the app automatically extracts the sender domain, subject, and part of the email body and sends them to the cloud server.

[0837] 3. Judgment by Generating AI

[0838] The server receives a request from the app and analyzes the email information. Based on the sender domain, subject, and part of the body, it generates a prompt message and inputs this prompt message into the AI ​​model.

[0839] The generative AI model learns from past data and determines whether a received email has phishing characteristics.

[0840] For example, the prompt message "Sender domain: examplebank.com, Subject: Important Notice: Account Freezing, Body: Your account has been frozen" is input to the generating AI model.

[0841] 4. Notification of the judgment result

[0842] The server receives the judgment results obtained from the generated AI model and sends those results back to the user's terminal.

[0843] The app displays the received judgment results within the email viewer. If it is determined to be a phishing email, it displays a warning message saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[0844] Specific example

[0845] Let's illustrate this with an example where a user receives a notification email from their bank. Suppose the sender domain of this notification email is "examplebank.com", the subject is "Important Notice: Account Freezing", and the body of the email is "Your account has been frozen". In this case, the app extracts this information and sends it to a cloud server. The cloud server passes this information to a generating AI model to determine whether it is a phishing email. The result of the determination is returned, and the user is notified that "This email may be a phishing email".

[0846] This system protects users from phishing emails and reduces security risks.

[0847] The flow of the specific processing in Example 1 will be explained using Figure 11.

[0848] Step 1:

[0849] The user downloads and installs the application from the app store on their smartphone.

[0850] Input: Application from the app store

[0851] Output: Installed applications

[0852] Specific operation: The user searches for the app in the device's app store and presses the install button, which downloads and installs the application on the user's device.

[0853] Step 2:

[0854] When a user launches the app for the first time, the application displays a user information registration screen.

[0855] Input: User information such as email address and password

[0856] Output: User information registered in the application

[0857] Specific operation: The user launches the app and creates an account by entering their email address and password on the registration screen. The application saves this information to a database.

[0858] Step 3:

[0859] The application performs user authentication and sets up integration with the email application.

[0860] Input: Display OAuth authentication prompt

[0861] Output: Settings for linking with the email app

[0862] Specific operation: The app requests integration with the email app used by the user using OAuth. Once the user grants authentication, the app obtains the necessary permissions and the integration is complete.

[0863] Step 4:

[0864] When a user receives a new email, the application checks the email information. A "Determine" button is displayed in the email view.

[0865] Input: Received email

[0866] Output: Email view showing the "Determine" button

[0867] Specific operation: When a user receives an email, the app parses the email and adds a "Determine" button to the view.

[0868] Step 5:

[0869] When the user clicks the "Determine" button, the application automatically extracts the sender domain, subject, and part of the email body, and sends them to the cloud server.

[0870] Input: Sender domain of the email, subject, and part of the email body.

[0871] Output: Email information sent as an API request

[0872] Specific operation: When the user clicks a button, the app extracts information from the email, compiles it, and sends it to the cloud server in JSON format.

[0873] Step 6:

[0874] The server receives a request from the app and parses the email information. It generates a prompt message and inputs it into the generation AI model.

[0875] Input: Email information in JSON format

[0876] Output: Prompt text input to the generating AI model

[0877] Specific operation: The server parses the received JSON and generates a prompt message based on the email content, such as "Sender domain: example.com, Subject: Important Notice, Body: Your account has been frozen," and inputs it into the generation AI model.

[0878] Step 7:

[0879] The generative AI model determines whether an email is a phishing email based on the prompt text.

[0880] Input: Prompt message

[0881] Output: Result of determining whether it is a phishing email.

[0882] Specific operation: The generative AI model utilizes past training data to analyze the information contained in the prompt message and determine whether or not the email is a phishing email. The result is then sent back to the server.

[0883] Step 8:

[0884] The server receives the judgment results from the generated AI model and sends them back to the user's terminal.

[0885] Input: Judgment result from the generated AI model

[0886] Output: Judgment result sent back to the user terminal

[0887] Specific operation: The server organizes the judgment results of the generated AI model, converts them into a data format for return to the user terminal, and sends them as an API response.

[0888] Step 9:

[0889] The application receives the judgment result from the server and displays it in the email view.

[0890] Input: Judgment result from the server

[0891] Output: Judgment result displayed in the email view

[0892] Specific operation: The application receives an API response and displays the result in the email view as either "This email may be a phishing attempt" or "This email is safe." The user then takes appropriate action based on this.

[0893] (Application Example 1)

[0894] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[0895] With the threat of phishing emails on the rise, there is a need for a means to determine the security of emails received by users in real time and to warn them appropriately. However, many current email services require users to make their own judgments, which carries the risk of misjudgment. There is also a need for a system that reduces the burden on users and identifies phishing emails quickly and with high accuracy.

[0896] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[0897] In this invention, the server includes means for extracting the sender domain information of an email, means for querying a generating AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generating AI and notifying the user, means for initial setup to link with the user's email account, means for directly obtaining email information from the linked email account, and means for displaying a warning message on the user's device based on the determination result. This makes it possible to check the security of emails received by the user in real time and to issue a quick and accurate warning against phishing emails.

[0898] "Email sender domain information" refers to the original internet domain name from which the email was sent.

[0899] "Generative AI" is a type of artificial intelligence technology that refers to a system that automatically performs specific tasks using natural language processing and pattern recognition.

[0900] The "judgment result" refers to the result of the AI's judgment on the phishing email, and indicates whether or not the email is a phishing email.

[0901] "Means of notifying the user" refers to the methods and processes for informing the user of the email's evaluation results, which are usually provided in the form of on-screen messages or push notifications.

[0902] "Initial setup means" refers to the methods and processes for performing the initial setup of the system, including, for example, the steps for setting up the link between the user and their email account.

[0903] "Means of directly obtaining email information" refers to a mechanism for directly obtaining necessary email information from the email account used by the user.

[0904] "Means of displaying warning messages" refers to methods and processes for displaying warning messages to alert users to suspicious emails, such as phishing emails.

[0905] This invention relates to a system that automatically identifies phishing emails and notifies the user. This system works in conjunction with the user's email account to check the security of emails in real time and displays a warning message if an email is suspected to be a phishing email.

[0906] The main components of the system are as follows:

[0907] User terminal: An application installed on a device such as a smartphone.

[0908] Cloud server: A server that receives data and uses generated AI to identify phishing emails.

[0909] Generative AI models: Artificial intelligence systems that use natural language processing and pattern recognition to determine the legitimacy of emails. Specific examples include OpenAI's ChatGPT and Google's BERT.

[0910] Program processing flow

[0911] 1. User registration and initial setup

[0912] The user downloads and installs the application on their smartphone. The application prompts the user for initial setup and configures the linking with their email account. OAuth authentication is used for the linking to obtain the necessary access permissions.

[0913] 2. Receiving emails and sending judgment requests

[0914] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. This information is then sent to a cloud server as an API request.

[0915] 3. Judgment processing by generating AI

[0916] The cloud server passes the received email information to an AI model that determines whether it is a phishing email. The result is indicated as either "It is a phishing email" or "It is not a phishing email." This information is then sent back to the user's device.

[0917] 4. User notification of the judgment result

[0918] The user's terminal receives the judgment result from the server and reflects the result in the email view. If it is determined to be a phishing email, the user will be shown a warning message such as "This email may be a phishing email."

[0919] As a concrete example, the following process is performed: When a user receives a "notification email from the bank," the sender's domain, subject, and part of the email body are extracted and sent to a cloud server. The cloud server makes a judgment based on a generated AI model, and if it determines, for example, that "examplebank.com" is not an official domain, it determines that the email is likely a phishing attempt. The user is then shown a warning that "this email may be a phishing attempt."

[0920] The following are examples of prompt messages:

[0921] "

[0922] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[0923] Sender: example@examplebank.com

[0924] Subject: Important Notice: Account Freezing

[0925] Part of the text: Please check.

[0926] "

[0927] This system allows users to verify the security of incoming emails and protect themselves from phishing risks. The highly accurate and rapid detection using generated AI significantly improves user security.

[0928] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[0929] Step 1:

[0930] The user downloads and installs an application on their smartphone. The input is the user's download action and the app installation process, and the output is the installed application. Specifically, the user downloads the app from the Apple App Store or Google Play Store and installs it on their device following the installation instructions.

[0931] Step 2:

[0932] The application prompts the user for initial setup and configures the linking of their email account. Inputs include the user's email account information and the OAuth authentication process, while output is the linked email account. Specifically, the user configures the email account linking within the app, and the app obtains the necessary access permissions through OAuth authentication.

[0933] Step 3:

[0934] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. The input is the information of the received email, and the output is the extracted sender's domain, subject, and portion of the body. Specifically, the app runs in the background and executes code to parse the information of the received email.

[0935] Step 4:

[0936] The application sends the extracted email information to the cloud server as an API request. The input is the extracted email information and the API request, and the output is the status indicating that the transmission to the cloud server is complete. Specifically, the application uses an HTTP POST request to send the email information to the server.

[0937] Step 5:

[0938] The cloud server passes the received email information to the generating AI model and makes a judgment request. The input is the sent email information, and the output is the judgment result of the generating AI model. Specifically, the cloud server converts the email information into a prompt message and inputs it into the generating AI model. For example,

[0939] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[0940] Sender: example@examplebank.com

[0941] Subject: Important Notice: Account Freezing

[0942] Part of the text: Please check.

[0943] The prompt " " is sent to the generating AI.

[0944] Step 6:

[0945] The generative AI model determines the legitimacy of an email based on the prompt text and returns a result indicating whether or not it is a phishing email. The input is the prompt text, and the output is a determination such as "This is a phishing email" or "This is not a phishing email." Specifically, the generative AI compares the text in the email with past training data to determine whether or not it has phishing characteristics.

[0946] Step 7:

[0947] The cloud server receives the judgment result from the generated AI and sends it back to the user's terminal. The input is the judgment result, and the output is the message sent to the user's terminal. Specifically, the cloud server uses an HTTP response to send the judgment result to the application.

[0948] Step 8:

[0949] The user's device receives the judgment result from the server and reflects the result in the email view. The input is the judgment result from the cloud server, and the output is the result displayed to the user. Specifically, the app executes code to display the judgment result in the notification area or within the email app. For example, it might display a warning message such as "This email may be a phishing attempt" as a pop-up.

[0950] This process allows users to verify the security of incoming emails in real time and protect themselves from phishing risks. The rapid and highly accurate judgment using generated AI significantly improves user security.

[0951] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[0952] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system uses a generating AI to determine the sender domain information and content of emails, and notifies the user of the determination result. Furthermore, by adding a function that recognizes user sentiment and adjusts the notification method and content accordingly, it achieves more effective security measures.

[0953] overview

[0954] The system of this invention combines a smartphone application, a cloud-based server, and an emotion engine. Upon receiving an email, it extracts the sender's domain information, subject, and a portion of the email body, sends this information to the server, and is judged by a generating AI. The judgment result is notified to the user, and at that time, the user's emotion engine is used to select the most appropriate notification method. The specific processing flow is described below.

[0955] Program processing flow

[0956] 1. User registration and initial setup

[0957] The user downloads and installs the smartphone application.

[0958] The app requests integration with the user's email app during initial setup. This integration is performed via OAuth authentication, which obtains the necessary access permissions.

[0959] The app will ask for your consent to use the emotion engine and configure it to monitor the user's emotional state.

[0960] 2. Receiving emails and sending judgment requests

[0961] When a user receives an email, this application, which is linked to the email app, displays a judgment button.

[0962] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[0963] The app sends this information to the cloud server as an API request.

[0964] 3. Judgment processing by generating AI

[0965] The server receives requests from applications and parses the email information.

[0966] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[0967] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data.

[0968] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[0969] 4. Notification of judgment results and application of the emotion engine

[0970] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state.

[0971] The emotion engine selects the optimal notification method (e.g., text, voice, visual) based on the user's emotional state (e.g., tension, anxiety, relaxation).

[0972] Based on the detection result, the app displays or notifies the user in the most appropriate way with a warning message stating, "This email may be a phishing attempt."

[0973] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[0974] Specific example

[0975] The following are specific examples of when a user is using a phishing detection service.

[0976] 1. The user receives a notification email from the bank.

[0977] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[0978] 3. The app sends this information to the server.

[0979] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[0980] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[0981] 6. The server receives the judgment result and sends it back to the user.

[0982] 7. The app receives the assessment result and analyzes the user's emotional state using its emotion engine. For example, if the user is relaxed, it will notify them via text; if they are feeling anxious, it will notify them gently via voice.

[0983] 8. The app displays or notifies the user in a format that is most appropriate for them, stating, "This email may be a phishing attempt."

[0984] In this way, users are protected from the risks of phishing emails and can receive appropriate notifications that take their emotions into consideration. The present invention provides a highly accurate and user-friendly security system that combines generative AI and an emotion engine.

[0985] The following describes the processing flow.

[0986] Step 1:

[0987] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. This integration is performed via OAuth authentication, obtaining the necessary access permissions. Furthermore, it requests permission to enable the emotion engine and monitor the user's emotional state.

[0988] Step 2:

[0989] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[0990] Step 3:

[0991] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[0992] Step 4:

[0993] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[0994] Step 5:

[0995] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[0996] Step 6:

[0997] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[0998] Step 7:

[0999] The device (app) receives the judgment result from the server and activates the emotion engine. The emotion engine monitors the user's emotional state and analyzes the user's current emotional state (e.g., tension, anxiety, relaxation).

[1000] Step 8:

[1001] The emotion engine determines how the assessment results are communicated. For example, it sends a quiet text notification when the user is relaxed and a gentle voice notification when the user is anxious. It also avoids visual notifications and opts for a combination of text and voice notifications when the user is stressed.

[1002] Step 9:

[1003] The device (app) notifies the user of the judgment result according to the notification method determined by the emotion engine. If it is a phishing email, it displays a warning message saying "This email may be a phishing email," and if it is a legitimate email, it notifies the user saying "This email is safe."

[1004] Step 10:

[1005] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[1006] For example, this process occurs when a user receives a notification email from their bank. When the user opens the email and clicks the phishing detection button, the app sends the email information to a server for detection and notifies the user of the result in the most appropriate way through the sentiment engine. Based on this notification, the user can take appropriate action against the phishing email.

[1007] (Example 2)

[1008] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1009] Phishing attacks via email are becoming increasingly sophisticated, making it difficult to adequately counter them with traditional manual or simple automated detection systems. Furthermore, users may not be able to properly understand or respond to warnings. Therefore, there is a need to provide a system that offers effective phishing email detection and appropriate notification methods based on the user's emotional state.

[1010] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[1011] In this invention, the server includes means for extracting the sender domain information, subject, and a portion of the body of an email; means for querying a generative AI model; means for receiving the judgment result from the generative AI model and notifying the user; and means for recognizing the user's emotional state using an emotion engine and optimizing the notification method. This improves the accuracy of email phishing detection and enables the issuance of warnings using the most appropriate notification method according to the user's emotional state.

[1012] "Sender domain information" refers to the internet domain name from which an email was sent, and is information that identifies which organization or individual sent the email.

[1013] The "subject line" refers to the title portion of an email, designed to allow recipients to understand the main point and content of the email at a glance.

[1014] "Part of the email body" refers to a portion of the information contained within the main content of an email, and is the text or data used to infer the overall content of the email.

[1015] A "generative AI model" is an artificial intelligence model that uses machine learning techniques to learn patterns and characteristics of phishing emails from past data and determine whether a received email is a phishing email.

[1016] The "judgment result" is information indicating the evaluation and status of email security, obtained as a result of the generation AI model analyzing the given email information.

[1017] "Notification" refers to the act or means of communication that a system uses to inform a user of its judgment results.

[1018] An "emotion engine" is a software or hardware function that analyzes a user's emotional state and optimizes notification methods accordingly.

[1019] "Initial setup procedures" refer to the means of performing the initial configuration tasks necessary for the system to function correctly and to interact with applications and other software.

[1020] "To collaborate" refers to the communication and synchronization operations necessary for different applications and systems to share information and function as a single unit.

[1021] "To acquire" refers to the act of a system or application collecting necessary data or information.

[1022] A "warning message" is a message sent by the system to alert the user and may contain information about the possibility of phishing emails or other risks.

[1023] The "optimal format" refers to the format used to convey information in the most effective and easily understandable way, depending on the user's emotional state and circumstances.

[1024] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[1025] First, the user downloads and installs the smartphone application. After installing the app, the user enters their information on the account registration screen to create an account. Next, during the initial setup, the app requests integration with the email app and obtains the necessary access permissions through OAuth authentication. It also requests consent to use the emotion engine, enabling the monitoring of the user's emotional state.

[1026] When an email is received, this application, which is linked to the email app, displays a "Analyze this email" button. When the user clicks this button, the application extracts the sender domain information, subject, and part of the email body, and sends them to the cloud server as an API request.

[1027] The server receives requests from applications and analyzes email information using a generative AI model. Specifically, the server passes the sender domain information, subject, and part of the email body to the generative AI model and requests a determination of whether it is a phishing email. Based on past training data, the generative AI model determines whether the received email has the characteristics of a phishing email. The server receives the determination result from the generative AI model and sends it back to the user's terminal.

[1028] The device (app) receives the judgment result from the server and uses an emotion engine to recognize the user's current emotional state. The emotion engine analyzes input data from the camera, microphone, etc., and analyzes the user's facial expressions and tone of voice. Next, it selects the most appropriate notification method based on the user's emotional state (e.g., tension, anxiety, relaxation). For example, if it is determined that the user is feeling anxious, an audio notification will be selected, and a warning will be given in a gentle tone. Conversely, if the user is relaxed, a text notification will be selected.

[1029] Let's look at a concrete example of how it works. Suppose a user receives a notification email from their bank. The subject line of this email is "Important Notice: Account Freeze," and part of the body contains the phrase "Your account has been frozen." The app extracts the sender domain "examplebank.com," the subject line, and part of the body, and sends this information to the server. The server uses a generative AI model to determine that "examplebank.com" is not an official domain and identifies it as a phishing email. The server sends the result back to the device, and the app uses an emotion engine to analyze the user's emotional state. For example, if the user is relaxed, it will notify them in text that "This email may be a phishing attempt." If the user is feeling anxious, it will notify them gently in voice.

[1030] In this way, the system of the present invention can improve the accuracy of email phishing detection and issue warnings using the most appropriate notification method according to the user's emotional state.

[1031] Example of a prompt

[1032] "Describe a system that determines whether a particular email is a phishing email and provides the most appropriate notification method based on the user's emotional state. Include specific examples, such as notifying the user via text message when they are relaxed and via voice notification when they are feeling anxious."

[1033] The flow of the specific processing in Example 2 will be explained using Figure 13.

[1034] Program processing flow

[1035] Step 1:

[1036] The user downloads and installs a smartphone application. The input is the user's account information (e.g., email address, password), and the output is a success message for account creation. Specifically, the user launches the app, enters the required information on the displayed registration screen, and creates an account.

[1037] Step 2:

[1038] The app requests integration with the user's email application during initial setup. The input is the user's email application credentials, and the output is a notification of successful integration. The app opens an OAuth authentication window and prompts the user to enter their email application credentials. Once authentication is complete, the app establishes integration with the email application and obtains the necessary access permissions.

[1039] Step 3:

[1040] The app requests consent to use the emotion engine. The input is the user's consent information, and the output is a notification that the emotion engine has been enabled. The app displays a consent dialog to the user regarding the use of the emotion engine, and if the user consents, it requests device access permissions such as the camera and microphone, and sets up emotional state monitoring.

[1041] Step 4:

[1042] The user receives an email, and the app displays a "Describe this email" button. The input is the information of the received email, and the output is the display of the "Describe this email" button. When an email is received, this application, which is linked to the email app, displays the "Describe this email" button in the email viewer.

[1043] Step 5:

[1044] When the user clicks the judgment button, the app extracts the sender domain information, subject, and part of the body of the email. The input is the user's click operation, and the output is the extracted email information. The app analyzes the sender domain information, subject, and part of the body of the email and extracts information such as "Sender: phishing@example.com, Subject: Free Gift, Part of Body: You have won."

[1045] Step 6:

[1046] The application sends email information to a cloud server as an API request. The input is the extracted email information, and the output is a success message for sending the API request to the server. The application sends a request to the API endpoint containing the email information and user authentication information.

[1047] Step 7:

[1048] The server receives a request and analyzes the email information using a generative AI model. The input is the email information, and the output is the phishing detection result. The server passes the sender domain, subject, and part of the body of the received email to the generative AI model to analyze whether it is a phishing email. For example, it uses features such as "the sender domain is not an official domain" or "the subject matches a typical phishing email pattern" to make the determination.

[1049] Step 8:

[1050] The server receives the judgment results from the generated AI model and sends them back to the user's terminal. The input is the judgment result from the generated AI model, and the output is the result sent back to the user's terminal. The server organizes the judgment results and sends a result such as "This email is a phishing email" or "This email is safe" to the user's terminal.

[1051] Step 9:

[1052] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state. The input is the judgment result from the server, and the output is the evaluation result of the user's emotional state. The device analyzes input data from the camera and microphone to analyze the user's facial expressions and voice tone.

[1053] Step 10:

[1054] The emotion engine selects the optimal notification method based on the user's emotional state. The input is the result of the user's emotional state evaluation, and the output is the result of selecting the optimal notification format. Based on the user's emotional state (e.g., tension, anxiety, relaxation), the emotion engine selects the most appropriate method from text notifications, voice notifications, and visual notifications.

[1055] Step 11:

[1056] The app displays or notifies the user of a warning message in the most appropriate format based on its assessment results. The input is the optimal notification format and assessment result, and the output is the display or notification of the warning message. For example, if the user is relaxed, a pop-up notification saying "This email may be a phishing attempt" will be displayed, and if the user is feeling anxious, a gentle voice message saying "This email may be a phishing attempt" will be displayed.

[1057] By following these steps, users will be protected from the risks of phishing emails and will receive appropriate notifications tailored to their emotional state.

[1058] (Application Example 2)

[1059] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server," and the headset-type terminal 314 will be referred to as the "terminal."

[1060] Currently, many systems for detecting phishing emails and notifying users simply analyze the email content and display warnings, but this does not take into account the user's psychological state and therefore does not provide sufficient security. Furthermore, the uniform notification method may prevent users from responding appropriately or may cause excessive anxiety. Solving these problems is the objective of this invention.

[1061] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for extracting the sender domain information of an email, means for querying the generation AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generation AI and notifying the user, and means for including an emotion engine that analyzes the user's emotional state and optimizing the notification method based on the emotion engine. This makes it possible to detect phishing emails and provide an optimal notification method that corresponds to the user's psychological state.

[1062] "Sender domain information" refers to information that identifies the domain name used to identify the sender of an email.

[1063] "Generative AI" is a system that uses artificial intelligence technology to learn and analyze email information to determine whether or not it is a phishing email.

[1064] "Means of notifying the user" refers to methods or functions for communicating the judgment result to the user.

[1065] An "emotion engine" is a system that analyzes and recognizes a user's emotional state in real time.

[1066] "Means of optimizing notification methods" refer to means of delivering notifications in the most effective and sensitive way, based on the user's current emotional state.

[1067] "The subject line and part of the email body" refers to the title of the received email and a portion of its content.

[1068] "Initial setup method" refers to the method or function for performing the necessary settings when using the system for the first time.

[1069] "Methods for directly obtaining email information from linked email applications" refers to a function that links with the email application used by the user and directly obtains email information from that application.

[1070] "Means of displaying warning messages" refers to methods or functions for displaying messages on a user's device that inform them that an email may be a phishing email.

[1071] "Text notification" refers to a method of notifying users using text information.

[1072] "Voice notification" refers to a method of notifying users using voice.

[1073] This invention relates to a system that automatically identifies phishing emails and optimizes notification methods using a user's sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[1074] First, the user installs the smartphone application and completes the initial setup. This setup includes integration with the email application and obtaining necessary access permissions through OAuth authentication. The user also agrees to use the emotion engine, allowing for real-time monitoring of their emotional state.

[1075] When an email is received, this system, which is integrated with the email application, extracts the sender domain information, subject, and a portion of the email body, and sends them to the cloud server. This extraction includes analysis to identify the sender domain information of the email. The cloud server uses generative AI to determine whether the sender domain information and email content are legitimate. Based on past data, the generative AI accurately evaluates whether the email is a phishing email.

[1076] The user is notified of the assessment result, but at that time, an emotion engine is used to analyze the user's emotional state (e.g., relaxed, anxious, tense) and select the optimal notification method (text, voice). For example, if the user is relaxed, a text notification is sent, and if they are feeling anxious, a gentle voice notification is sent.

[1077] The primary hardware used includes smartphones and cloud servers, while the main software includes generative AI and an emotion engine. As a concrete example, the legitimacy of an email is determined by sending prompts like the following to the generative AI.

[1078] Example of a prompt:

[1079] Is the email from the domain "examplebank.com" a potential phishing email? Subject: "Important Notice: Account Freeze", Part of the body: "Your account has been frozen. Please check this link immediately."

[1080] In this way, users are protected from the risks of phishing emails and receive appropriate notifications that take their emotions into consideration. This system provides highly accurate and user-friendly security measures by combining generative AI and an emotion engine.

[1081] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[1082] Step 1:

[1083] The user installs the smartphone application and completes the initial setup. The user then connects with their email application and obtains the necessary access permissions through OAuth authentication. Additionally, the user agrees to use the emotion engine and configures settings to monitor their emotional state in real time.

[1084] Input: Smartphone application, email application account information

[1085] Output: Application installation and configuration complete, OAuth authentication performed and access permissions obtained.

[1086] Step 2:

[1087] When a user receives an email, the linked smartphone application extracts the sender's domain information, subject, and a portion of the email's body. This provides the basic information about the email.

[1088] Input: Received email

[1089] Output: Sender domain information, subject, and part of the message body.

[1090] Step 3:

[1091] The terminal (application) sends the extracted sender domain information, subject, and a portion of the email body to the cloud server as an API request. This request includes a prompt asking whether the email is a phishing attempt.

[1092] Input: Sender domain information, subject, and part of the message body.

[1093] Output: Sending an API request

[1094] Step 4:

[1095] The server passes the received request to the generating AI, which determines whether the email content and sender domain information have characteristics of a phishing email. Based on past training data, the generating AI analyzes whether the email is a phishing email.

[1096] Input: Sender domain information, subject, part of the message body, prompt message

[1097] Output: Judgment result by the generated AI

[1098] Step 5:

[1099] The server receives the judgment results from the generating AI, organizes the results, and sends them back to the user's terminal. These results include information on whether or not the email is a phishing email.

[1100] Input: Judgment result generated by AI

[1101] Output: Return of judgment result

[1102] Step 6:

[1103] The terminal (application) receives the judgment result from the server and optimizes the notification method using an emotion engine that analyzes the user's current emotional state. For example, if the user is relaxed, a text notification is sent, and if anxiety is heightened, an audio notification is sent.

[1104] Input: Judgment result, user's emotional state

[1105] Output: Selection of an optimized notification method

[1106] Step 7:

[1107] The application notifies the user of the phishing email detection result based on an optimized notification method. For example, if the user is relaxed, it will notify them via text message saying, "This email may be a phishing email," while if the user is feeling anxious, it will notify them of the same message in a gentle voice message.

[1108] Input: Optimized notification method

[1109] Output: Notification to the user

[1110] In this way, users are protected from the risks of phishing emails and can receive appropriate, emotionally sensitive notifications.

[1111] The specific processing unit 290 transmits the result of the specific processing to the headset terminal 314. In the headset terminal 314, the control unit 46A causes the speaker 240 and display 343 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[1112] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1113] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and specific processing may also be performed by the headset terminal 314.

[1114] [Fourth Embodiment]

[1115] Figure 7 shows an example of the configuration of the data processing system 410 according to the fourth embodiment.

[1116] As shown in Figure 7, the data processing system 410 includes a data processing device 12 and a robot 414. An example of the data processing device 12 is a server.

[1117] The data processing device 12 comprises a computer 22, a database 24, and a communication interface 26. The computer 22 is an example of a "computer" related to the technology of this disclosure. The computer 22 comprises a processor 28, RAM 30, and storage 32. The processor 28, RAM 30, and storage 32 are connected to a bus 34. The database 24 and the communication interface 26 are also connected to the bus 34. The communication interface 26 is connected to a network 54. An example of the network 54 is a WAN (Wide Area Network) and / or a LAN (Local Area Network).

[1118] The robot 414 includes a computer 36, a microphone 238, a speaker 240, a camera 42, a communication interface 44, and a controlled object 443. The computer 36 includes a processor 46, RAM 48, and storage 50. The processor 46, RAM 48, and storage 50 are connected to a bus 52. The microphone 238, speaker 240, camera 42, and controlled object 443 are also connected to the bus 52.

[1119] The microphone 238 receives voice signals from the user 20 and receives instructions from the user 20. The microphone 238 captures the voice signals from the user 20, converts the captured voice into audio data, and outputs it to the processor 46. The speaker 240 outputs audio according to the instructions from the processor 46.

[1120] Camera 42 is a small digital camera equipped with an optical system including a lens, aperture, and shutter, and an image sensor such as a CMOS (Complementary Metal-Oxide-Semiconductor) image sensor or a CCD (Charge Coupled Device) image sensor, and captures images of the area around the user 20 (for example, an imaging range defined by a field of view equivalent to the width of a typical healthy person's field of vision).

[1121] Communication interface 44 is connected to network 54. Communication interfaces 44 and 26 are responsible for the exchange of various information between processor 46 and processor 28 via network 54. The exchange of various information between processor 46 and processor 28 using communication interfaces 44 and 26 is performed in a secure manner.

[1122] The controlled object 443 includes a display device, LEDs in the eyes, and motors that drive the arms, hands, and feet. The posture and gestures of the robot 414 are controlled by controlling the motors of the arms, hands, and feet. Some of the robot 414's emotions can be expressed by controlling these motors. Furthermore, the robot 414's facial expressions can also be expressed by controlling the illumination state of the LEDs in its eyes.

[1123] Figure 8 shows an example of the main functions of the data processing device 12 and the robot 414. As shown in Figure 8, the data processing device 12 performs specific processing using the processor 28. The storage 32 stores the specific processing program 56.

[1124] The specific processing program 56 is an example of a "program" relating to the technology of this disclosure. The processor 28 reads the specific processing program 56 from the storage 32 and executes the read specific processing program 56 on the RAM 30. The specific processing is realized by the processor 28 operating as a specific processing unit 290 in accordance with the specific processing program 56 executed on the RAM 30.

[1125] The storage 32 stores the data generation model 58 and the emotion identification model 59. The data generation model 58 and the emotion identification model 59 are used by the identification processing unit 290.

[1126] In robot 414, the processor 46 performs the reception output processing. The storage 50 stores the reception output program 60. The processor 46 reads the reception output program 60 from the storage 50 and executes the read reception output program 60 on the RAM 48. The reception output processing is realized by the processor 46 operating as a control unit 46A according to the reception output program 60 executed on the RAM 48.

[1127] Next, the specific processing performed by the specific processing unit 290 of the data processing device 12 will be described. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1128] This invention relates to a system that automatically identifies phishing emails and alerts users. To implement this system, a specific method is described for using an AI to analyze the sender domain information, subject, and part of the email body, and for notifying the user of the analysis result.

[1129] overview

[1130] The system of the present invention primarily consists of an application installed on the user's terminal and a server located in the cloud. When a user receives an email, the sender's domain, subject, and body of the email are sent to the cloud server, where a generating AI is used to determine if it is a phishing email, and the result is notified to the user.

[1131] Program processing flow

[1132] 1. User registration and initial setup

[1133] The user first downloads and installs the smartphone application.

[1134] The app requires the user to connect with their email app as part of the initial setup. This connection is established via OAuth authentication, which obtains the necessary access permissions.

[1135] 2. Receiving emails and sending judgment requests

[1136] When a user receives an email, this application, which is integrated with the email app, displays a judgment button in the email view.

[1137] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[1138] The app sends this information to the cloud server as an API request.

[1139] 3. Judgment processing by generating AI

[1140] The server receives requests from applications and parses the email information.

[1141] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[1142] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data. The result of the determination includes information such as "It is a phishing email" or "It is not a phishing email."

[1143] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[1144] 4. User notification of the judgment result

[1145] The app receives the judgment result from the server and reflects the result in the email view.

[1146] If an email is identified as a phishing email, the app will display a warning message to the user such as, "This email may be a phishing attempt."

[1147] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[1148] Specific example

[1149] The following are specific examples of when a user is using a phishing detection service.

[1150] 1. The user receives a notification email from the bank.

[1151] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[1152] 3. The app sends this information to the server.

[1153] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[1154] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[1155] 6. The server receives the judgment result and sends it back to the user.

[1156] 7. The app displays the result and warns, "This email may be a phishing attempt."

[1157] In this way, users are protected from the risks of phishing emails and can use email with peace of mind. This invention enhances user security by performing highly accurate judgments using generation AI.

[1158] The following describes the processing flow.

[1159] Step 1:

[1160] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. The integration is performed via OAuth authentication, and the necessary access permissions are obtained.

[1161] Step 2:

[1162] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[1163] Step 3:

[1164] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[1165] Step 4:

[1166] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[1167] Step 5:

[1168] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[1169] Step 6:

[1170] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[1171] Step 7:

[1172] The device (app) receives the judgment result from the server and reflects it on the screen within the email view. If it is determined to be a phishing email, the app displays a warning message to the user saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[1173] Step 8:

[1174] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[1175] (Example 1)

[1176] Next, we will describe Example 1. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1177] Conventional email filtering systems have difficulty accurately identifying phishing emails, resulting in problems with false positives and missed detections. Furthermore, insufficient warnings and notifications to users can increase security risks. This increases the risk of personal information leaks and unauthorized access, as well as the likelihood of users becoming victims of phishing emails. Therefore, the present invention aims to solve these problems by providing a system that uses a generative AI model to perform advanced phishing email detection and provide users with rapid and accurate warnings.

[1178] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 1 is realized by the following means.

[1179] In this invention, the server includes means for extracting the sender domain information of an email, means for extracting the subject and part of the body, means for querying a generating AI whether the sender domain information and the subject and body have characteristics of phishing, and means for notifying the user of the determination result from the generating AI. This enables highly accurate detection of phishing emails and rapid user notification.

[1180] "Email sender domain information" refers to the domain portion of the sender address of a received email, and is used to identify the origin of the email.

[1181] The "subject line" is the text information displayed as the title of an email, and is used to concisely express the content of the email.

[1182] The "body" of an email is the text area that contains the main content of the email, including messages and information addressed to the user.

[1183] "Generative AI" is an artificial intelligence system that learns from past data and performs inferences and judgments on new input data, and is used for things like detecting phishing in emails.

[1184] An "API request" is a request from an application to send data to a service such as a server, and is called to perform a specific function.

[1185] "User devices" refer to all electronic devices used by individuals, including smartphones, tablets, and personal computers.

[1186] A "prompt statement" is an input statement given to a generating AI to request a specific judgment, and it serves as a criterion for the generating AI to produce an appropriate response.

[1187] A "cloud server" is a remote server provided over the internet, used for storing and processing data.

[1188] This invention relates to a system that automatically identifies phishing emails and alerts users. The main components of this system are an application installed on the user's terminal and a server located in the cloud.

[1189] System Configuration

[1190] Hardware and software

[1191] User device: Uses devices such as smartphones, tablets, and personal computers. This includes smartphones running iOS or Android operating systems.

[1192] Application: A dedicated application installed on the user's device. It integrates with the email application and has the function of extracting email information. This application uses OAuth authentication to integrate with the email application.

[1193] Cloud server: A remote server accessible via the internet, which performs phishing detection using AI models for analyzing and generating email information.

[1194] Generative AI Model: A pre-trained AI model is used to determine whether the input email information is a phishing email.

[1195] How it works

[1196] 1. User registration and initial setup

[1197] Users download and install the app from their smartphone's app store. Upon first launching the app, a user registration screen appears. Users enter their email address, password, and other information to create an account.

[1198] The app performs user authentication and requests integration with the email application. This integration is securely performed through OAuth authentication.

[1199] 2. Receiving emails and sending judgment requests

[1200] When a user receives a new email, the app interacts with the email app and displays a "Determine" button in the email view.

[1201] When the user clicks the "Analyze" button, the app automatically extracts the sender domain, subject, and part of the email body and sends them to the cloud server.

[1202] 3. Judgment by Generating AI

[1203] The server receives a request from the app and analyzes the email information. Based on the sender domain, subject, and part of the body, it generates a prompt message and inputs this prompt message into the AI ​​model.

[1204] The generative AI model learns from past data and determines whether a received email has phishing characteristics.

[1205] For example, the prompt message "Sender domain: examplebank.com, Subject: Important Notice: Account Freezing, Body: Your account has been frozen" is input to the generating AI model.

[1206] 4. Notification of the judgment result

[1207] The server receives the judgment results obtained from the generated AI model and sends those results back to the user's terminal.

[1208] The app displays the received judgment results within the email viewer. If it is determined to be a phishing email, it displays a warning message saying, "This email may be a phishing email." If it is determined to be a legitimate email, it notifies the user that "This email is safe."

[1209] Specific example

[1210] Let's illustrate this with an example where a user receives a notification email from their bank. Suppose the sender domain of this notification email is "examplebank.com", the subject is "Important Notice: Account Freezing", and the body of the email is "Your account has been frozen". In this case, the app extracts this information and sends it to a cloud server. The cloud server passes this information to a generating AI model to determine whether it is a phishing email. The result of the determination is returned, and the user is notified that "This email may be a phishing email".

[1211] This system protects users from phishing emails and reduces security risks.

[1212] The flow of the specific processing in Example 1 will be explained using Figure 11.

[1213] Step 1:

[1214] The user downloads and installs the application from the app store on their smartphone.

[1215] Input: Application from the app store

[1216] Output: Installed applications

[1217] Specific operation: The user searches for the app in the device's app store and presses the install button, which downloads and installs the application on the user's device.

[1218] Step 2:

[1219] When a user launches the app for the first time, the application displays a user information registration screen.

[1220] Input: User information such as email address and password

[1221] Output: User information registered in the application

[1222] Specific operation: The user launches the app and creates an account by entering their email address and password on the registration screen. The application saves this information to a database.

[1223] Step 3:

[1224] The application performs user authentication and sets up integration with the email application.

[1225] Input: Display OAuth authentication prompt

[1226] Output: Settings for linking with the email app

[1227] Specific operation: The app requests integration with the email app used by the user using OAuth. Once the user grants authentication, the app obtains the necessary permissions and the integration is complete.

[1228] Step 4:

[1229] When a user receives a new email, the application checks the email information. A "Determine" button is displayed in the email view.

[1230] Input: Received email

[1231] Output: Email view showing the "Determine" button

[1232] Specific operation: When a user receives an email, the app parses the email and adds a "Determine" button to the view.

[1233] Step 5:

[1234] When the user clicks the "Determine" button, the application automatically extracts the sender domain, subject, and part of the email body, and sends them to the cloud server.

[1235] Input: Sender domain of the email, subject, and part of the email body.

[1236] Output: Email information sent as an API request

[1237] Specific operation: When the user clicks a button, the app extracts information from the email, compiles it, and sends it to the cloud server in JSON format.

[1238] Step 6:

[1239] The server receives a request from the app and parses the email information. It generates a prompt message and inputs it into the generation AI model.

[1240] Input: Email information in JSON format

[1241] Output: Prompt text input to the generating AI model

[1242] Specific operation: The server parses the received JSON and generates a prompt message based on the email content, such as "Sender domain: example.com, Subject: Important Notice, Body: Your account has been frozen," and inputs it into the generation AI model.

[1243] Step 7:

[1244] The generative AI model determines whether an email is a phishing email based on the prompt text.

[1245] Input: Prompt message

[1246] Output: Result of determining whether it is a phishing email.

[1247] Specific operation: The generative AI model utilizes past training data to analyze the information contained in the prompt message and determine whether or not the email is a phishing email. The result is then sent back to the server.

[1248] Step 8:

[1249] The server receives the judgment results from the generated AI model and sends them back to the user's terminal.

[1250] Input: Judgment result from the generated AI model

[1251] Output: Judgment result sent back to the user terminal

[1252] Specific operation: The server organizes the judgment results of the generated AI model, converts them into a data format for return to the user terminal, and sends them as an API response.

[1253] Step 9:

[1254] The application receives the judgment result from the server and displays it in the email view.

[1255] Input: Judgment result from the server

[1256] Output: Judgment result displayed in the email view

[1257] Specific operation: The application receives an API response and displays the result in the email view as either "This email may be a phishing attempt" or "This email is safe." The user then takes appropriate action based on this.

[1258] (Application Example 1)

[1259] Next, we will explain Application Example 1. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1260] With the threat of phishing emails on the rise, there is a need for a means to determine the security of emails received by users in real time and to warn them appropriately. However, many current email services require users to make their own judgments, which carries the risk of misjudgment. There is also a need for a system that reduces the burden on users and identifies phishing emails quickly and with high accuracy.

[1261] The specific processing performed by the specific processing unit 290 of the data processing device 12 in Application Example 1 is realized by the following means.

[1262] In this invention, the server includes means for extracting the sender domain information of an email, means for querying a generating AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generating AI and notifying the user, means for initial setup to link with the user's email account, means for directly obtaining email information from the linked email account, and means for displaying a warning message on the user's device based on the determination result. This makes it possible to check the security of emails received by the user in real time and to issue a quick and accurate warning against phishing emails.

[1263] "Email sender domain information" refers to the original internet domain name from which the email was sent.

[1264] "Generative AI" is a type of artificial intelligence technology that refers to a system that automatically performs specific tasks using natural language processing and pattern recognition.

[1265] The "judgment result" refers to the result of the AI's judgment on the phishing email, and indicates whether or not the email is a phishing email.

[1266] "Means of notifying the user" refers to the methods and processes for informing the user of the email's evaluation results, which are usually provided in the form of on-screen messages or push notifications.

[1267] "Initial setup means" refers to the methods and processes for performing the initial setup of the system, including, for example, the steps for setting up the link between the user and their email account.

[1268] "Means of directly obtaining email information" refers to a mechanism for directly obtaining necessary email information from the email account used by the user.

[1269] "Means of displaying warning messages" refers to methods and processes for displaying warning messages to alert users to suspicious emails, such as phishing emails.

[1270] This invention relates to a system that automatically identifies phishing emails and notifies the user. This system works in conjunction with the user's email account to check the security of emails in real time and displays a warning message if an email is suspected to be a phishing email.

[1271] The main components of the system are as follows:

[1272] User terminal: An application installed on a device such as a smartphone.

[1273] Cloud server: A server that receives data and uses generated AI to identify phishing emails.

[1274] Generative AI models: Artificial intelligence systems that use natural language processing and pattern recognition to determine the legitimacy of emails. Specific examples include OpenAI's ChatGPT and Google's BERT.

[1275] Program processing flow

[1276] 1. User registration and initial setup

[1277] The user downloads and installs the application on their smartphone. The application prompts the user for initial setup and configures the linking with their email account. OAuth authentication is used for the linking to obtain the necessary access permissions.

[1278] 2. Receiving emails and sending judgment requests

[1279] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. This information is then sent to a cloud server as an API request.

[1280] 3. Judgment processing by generating AI

[1281] The cloud server passes the received email information to an AI model that determines whether it is a phishing email. The result is indicated as either "It is a phishing email" or "It is not a phishing email." This information is then sent back to the user's device.

[1282] 4. User notification of the judgment result

[1283] The user's terminal receives the judgment result from the server and reflects the result in the email view. If it is determined to be a phishing email, the user will be shown a warning message such as "This email may be a phishing email."

[1284] As a concrete example, the following process is performed: When a user receives a "notification email from the bank," the sender's domain, subject, and part of the email body are extracted and sent to a cloud server. The cloud server makes a judgment based on a generated AI model, and if it determines, for example, that "examplebank.com" is not an official domain, it determines that the email is likely a phishing attempt. The user is then shown a warning that "this email may be a phishing attempt."

[1285] The following are examples of prompt messages:

[1286] "

[1287] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[1288] Sender: example@examplebank.com

[1289] Subject: Important Notice: Account Freezing

[1290] Part of the text: Please check.

[1291] "

[1292] This system allows users to verify the security of incoming emails and protect themselves from phishing risks. The highly accurate and rapid detection using generated AI significantly improves user security.

[1293] The flow of a specific process in Application Example 1 will be explained using Figure 12.

[1294] Step 1:

[1295] The user downloads and installs an application on their smartphone. The input is the user's download action and the app installation process, and the output is the installed application. Specifically, the user downloads the app from the Apple App Store or Google Play Store and installs it on their device following the installation instructions.

[1296] Step 2:

[1297] The application prompts the user for initial setup and configures the linking of their email account. Inputs include the user's email account information and the OAuth authentication process, while output is the linked email account. Specifically, the user configures the email account linking within the app, and the app obtains the necessary access permissions through OAuth authentication.

[1298] Step 3:

[1299] When a user receives an email, the application extracts the sender's domain, subject, and a portion of the email's body. The input is the information of the received email, and the output is the extracted sender's domain, subject, and portion of the body. Specifically, the app runs in the background and executes code to parse the information of the received email.

[1300] Step 4:

[1301] The application sends the extracted email information to the cloud server as an API request. The input is the extracted email information and the API request, and the output is the status indicating that the transmission to the cloud server is complete. Specifically, the application uses an HTTP POST request to send the email information to the server.

[1302] Step 5:

[1303] The cloud server passes the received email information to the generating AI model and makes a judgment request. The input is the sent email information, and the output is the judgment result of the generating AI model. Specifically, the cloud server converts the email information into a prompt message and inputs it into the generating AI model. For example,

[1304] Please determine whether this email is a phishing attempt based on the sender, subject, and body information below.

[1305] Sender: example@examplebank.com

[1306] Subject: Important Notice: Account Freezing

[1307] Part of the text: Please check.

[1308] The prompt " " is sent to the generating AI.

[1309] Step 6:

[1310] The generative AI model determines the legitimacy of an email based on the prompt text and returns a result indicating whether or not it is a phishing email. The input is the prompt text, and the output is a determination such as "This is a phishing email" or "This is not a phishing email." Specifically, the generative AI compares the text in the email with past training data to determine whether or not it has phishing characteristics.

[1311] Step 7:

[1312] The cloud server receives the judgment result from the generated AI and sends it back to the user's terminal. The input is the judgment result, and the output is the message sent to the user's terminal. Specifically, the cloud server uses an HTTP response to send the judgment result to the application.

[1313] Step 8:

[1314] The user's device receives the judgment result from the server and reflects the result in the email view. The input is the judgment result from the cloud server, and the output is the result displayed to the user. Specifically, the app executes code to display the judgment result in the notification area or within the email app. For example, it might display a warning message such as "This email may be a phishing attempt" as a pop-up.

[1315] This process allows users to verify the security of incoming emails in real time and protect themselves from phishing risks. The rapid and highly accurate judgment using generated AI significantly improves user security.

[1316] Furthermore, an emotion engine that estimates the user's emotions may be incorporated. That is, the identification processing unit 290 may use the emotion identification model 59 to estimate the user's emotions and perform identification processing using the user's emotions.

[1317] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system uses a generating AI to determine the sender domain information and content of emails, and notifies the user of the determination result. Furthermore, by adding a function that recognizes user sentiment and adjusts the notification method and content accordingly, it achieves more effective security measures.

[1318] overview

[1319] The system of this invention combines a smartphone application, a cloud-based server, and an emotion engine. Upon receiving an email, it extracts the sender's domain information, subject, and a portion of the email body, sends this information to the server, and is judged by a generating AI. The judgment result is notified to the user, and at that time, the user's emotion engine is used to select the most appropriate notification method. The specific processing flow is described below.

[1320] Program processing flow

[1321] 1. User registration and initial setup

[1322] The user downloads and installs the smartphone application.

[1323] The app requests integration with the user's email app during initial setup. This integration is performed via OAuth authentication, which obtains the necessary access permissions.

[1324] The app will ask for your consent to use the emotion engine and configure it to monitor the user's emotional state.

[1325] 2. Receiving emails and sending judgment requests

[1326] When a user receives an email, this application, which is linked to the email app, displays a judgment button.

[1327] When the user clicks the judgment button, the application extracts the sender domain information, subject, and a portion of the email body.

[1328] The app sends this information to the cloud server as an API request.

[1329] 3. Judgment processing by generating AI

[1330] The server receives requests from applications and parses the email information.

[1331] The server passes the sender's domain information, subject, and part of the email body to the AI ​​that generates the data, and requests a determination to determine whether it is a phishing email.

[1332] The generating AI determines whether a received email has the characteristics of a phishing email based on past training data.

[1333] The server receives the judgment results from the generated AI, organizes the results, and sends them back to the user's terminal.

[1334] 4. Notification of judgment results and application of the emotion engine

[1335] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state.

[1336] The emotion engine selects the optimal notification method (e.g., text, voice, visual) based on the user's emotional state (e.g., tension, anxiety, relaxation).

[1337] Based on the detection result, the app displays or notifies the user in the most appropriate way with a warning message stating, "This email may be a phishing attempt."

[1338] If the email is determined to be legitimate, the app will notify you with the message, "This email is safe."

[1339] Specific example

[1340] The following are specific examples of when a user is using a phishing detection service.

[1341] 1. The user receives a notification email from the bank.

[1342] 2. The app extracts the sender domain "examplebank.com", the subject "Important Notice: Account Freezing", and a portion of the email body.

[1343] 3. The app sends this information to the server.

[1344] 4. The server receives the information and passes it to the generating AI, requesting it to determine the legitimacy of "examplebank.com" and the email content.

[1345] 5. The generating AI determines that "examplebank.com" is not an official domain and concludes that it is a phishing email.

[1346] 6. The server receives the judgment result and sends it back to the user.

[1347] 7. The app receives the assessment result and analyzes the user's emotional state using its emotion engine. For example, if the user is relaxed, it will notify them via text; if they are feeling anxious, it will notify them gently via voice.

[1348] 8. The app displays or notifies the user in a format that is most appropriate for them, stating, "This email may be a phishing attempt."

[1349] In this way, users are protected from the risks of phishing emails and can receive appropriate notifications that take their emotions into consideration. The present invention provides a highly accurate and user-friendly security system that combines generative AI and an emotion engine.

[1350] The following describes the processing flow.

[1351] Step 1:

[1352] The user downloads and installs the application on their smartphone. Upon first launch, the app prompts the user to configure integration with their email app. This integration is performed via OAuth authentication, obtaining the necessary access permissions. Furthermore, it requests permission to enable the emotion engine and monitor the user's emotional state.

[1353] Step 2:

[1354] The user receives an email. When the user opens a specific email within the linked email app, the app displays a phishing detection button. The user clicks the detection button.

[1355] Step 3:

[1356] The device (app) extracts the sender domain information, subject, and part of the email body. Based on the extracted information, it sends an API request to the cloud server.

[1357] Step 4:

[1358] The server receives API requests from the app and analyzes the sender domain information, subject, and a portion of the email body. It then passes this information to a generating AI to request a determination of whether or not the email is a phishing email.

[1359] Step 5:

[1360] The generating AI uses past training data to determine whether a received email has the characteristics of a phishing email. The result includes information indicating whether it is a "phishing email" or "not a phishing email." The generating AI then sends the result back to the server.

[1361] Step 6:

[1362] The server receives the judgment results from the generated AI and organizes them in an appropriate format for return to the user. The organized judgment results are then sent back to the terminal.

[1363] Step 7:

[1364] The device (app) receives the judgment result from the server and activates the emotion engine. The emotion engine monitors the user's emotional state and analyzes the user's current emotional state (e.g., tension, anxiety, relaxation).

[1365] Step 8:

[1366] The emotion engine determines how the assessment results are communicated. For example, it sends a quiet text notification when the user is relaxed and a gentle voice notification when the user is anxious. It also avoids visual notifications and opts for a combination of text and voice notifications when the user is stressed.

[1367] Step 9:

[1368] The device (app) notifies the user of the judgment result according to the notification method determined by the emotion engine. If it is a phishing email, it displays a warning message saying "This email may be a phishing email," and if it is a legitimate email, it notifies the user saying "This email is safe."

[1369] Step 10:

[1370] Based on the information provided by the app, users will review the email content and take necessary actions. If it is determined to be a phishing email, they will delete the email or take appropriate measures.

[1371] For example, this process occurs when a user receives a notification email from their bank. When the user opens the email and clicks the phishing detection button, the app sends the email information to a server for detection and notifies the user of the result in the most appropriate way through the sentiment engine. Based on this notification, the user can take appropriate action against the phishing email.

[1372] (Example 2)

[1373] Next, we will describe Example 2. In the following description, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1374] Phishing attacks via email are becoming increasingly sophisticated, making it difficult to adequately counter them with traditional manual or simple automated detection systems. Furthermore, users may not be able to properly understand or respond to warnings. Therefore, there is a need to provide a system that offers effective phishing email detection and appropriate notification methods based on the user's emotional state.

[1375] The identification process performed by the identification processing unit 290 of the data processing device 12 in Example 2 is realized by the following means.

[1376] In this invention, the server includes means for extracting the sender domain information, subject, and a portion of the body of an email; means for querying a generative AI model; means for receiving the judgment result from the generative AI model and notifying the user; and means for recognizing the user's emotional state using an emotion engine and optimizing the notification method. This improves the accuracy of email phishing detection and enables the issuance of warnings using the most appropriate notification method according to the user's emotional state.

[1377] "Sender domain information" refers to the internet domain name from which an email was sent, and is information that identifies which organization or individual sent the email.

[1378] The "subject line" refers to the title portion of an email, designed to allow recipients to understand the main point and content of the email at a glance.

[1379] "Part of the email body" refers to a portion of the information contained within the main content of an email, and is the text or data used to infer the overall content of the email.

[1380] A "generative AI model" is an artificial intelligence model that uses machine learning techniques to learn patterns and characteristics of phishing emails from past data and determine whether a received email is a phishing email.

[1381] The "judgment result" is information indicating the evaluation and status of email security, obtained as a result of the generation AI model analyzing the given email information.

[1382] "Notification" refers to the act or means of communication that a system uses to inform a user of its judgment results.

[1383] An "emotion engine" is a software or hardware function that analyzes a user's emotional state and optimizes notification methods accordingly.

[1384] "Initial setup procedures" refer to the means of performing the initial configuration tasks necessary for the system to function correctly and to interact with applications and other software.

[1385] "To collaborate" refers to the communication and synchronization operations necessary for different applications and systems to share information and function as a single unit.

[1386] "To acquire" refers to the act of a system or application collecting necessary data or information.

[1387] A "warning message" is a message sent by the system to alert the user and may contain information about the possibility of phishing emails or other risks.

[1388] The "optimal format" refers to the format used to convey information in the most effective and easily understandable way, depending on the user's emotional state and circumstances.

[1389] This invention relates to a system that automatically identifies phishing emails and further optimizes notification methods using a user sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[1390] First, the user downloads and installs the smartphone application. After installing the app, the user enters their information on the account registration screen to create an account. Next, during the initial setup, the app requests integration with the email app and obtains the necessary access permissions through OAuth authentication. It also requests consent to use the emotion engine, enabling the monitoring of the user's emotional state.

[1391] When an email is received, this application, which is linked to the email app, displays a "Analyze this email" button. When the user clicks this button, the application extracts the sender domain information, subject, and part of the email body, and sends them to the cloud server as an API request.

[1392] The server receives requests from applications and analyzes email information using a generative AI model. Specifically, the server passes the sender domain information, subject, and part of the email body to the generative AI model and requests a determination of whether it is a phishing email. Based on past training data, the generative AI model determines whether the received email has the characteristics of a phishing email. The server receives the determination result from the generative AI model and sends it back to the user's terminal.

[1393] The device (app) receives the judgment result from the server and uses an emotion engine to recognize the user's current emotional state. The emotion engine analyzes input data from the camera, microphone, etc., and analyzes the user's facial expressions and tone of voice. Next, it selects the most appropriate notification method based on the user's emotional state (e.g., tension, anxiety, relaxation). For example, if it is determined that the user is feeling anxious, an audio notification will be selected, and a warning will be given in a gentle tone. Conversely, if the user is relaxed, a text notification will be selected.

[1394] Let's look at a concrete example of how it works. Suppose a user receives a notification email from their bank. The subject line of this email is "Important Notice: Account Freeze," and part of the body contains the phrase "Your account has been frozen." The app extracts the sender domain "examplebank.com," the subject line, and part of the body, and sends this information to the server. The server uses a generative AI model to determine that "examplebank.com" is not an official domain and identifies it as a phishing email. The server sends the result back to the device, and the app uses an emotion engine to analyze the user's emotional state. For example, if the user is relaxed, it will notify them in text that "This email may be a phishing attempt." If the user is feeling anxious, it will notify them gently in voice.

[1395] In this way, the system of the present invention can improve the accuracy of email phishing detection and issue warnings using the most appropriate notification method according to the user's emotional state.

[1396] Example of a prompt

[1397] "Describe a system that determines whether a particular email is a phishing email and provides the most appropriate notification method based on the user's emotional state. Include specific examples, such as notifying the user via text message when they are relaxed and via voice notification when they are feeling anxious."

[1398] The flow of the specific processing in Example 2 will be explained using Figure 13.

[1399] Program processing flow

[1400] Step 1:

[1401] The user downloads and installs a smartphone application. The input is the user's account information (e.g., email address, password), and the output is a success message for account creation. Specifically, the user launches the app, enters the required information on the displayed registration screen, and creates an account.

[1402] Step 2:

[1403] The app requests integration with the user's email application during initial setup. The input is the user's email application credentials, and the output is a notification of successful integration. The app opens an OAuth authentication window and prompts the user to enter their email application credentials. Once authentication is complete, the app establishes integration with the email application and obtains the necessary access permissions.

[1404] Step 3:

[1405] The app requests consent to use the emotion engine. The input is the user's consent information, and the output is a notification that the emotion engine has been enabled. The app displays a consent dialog to the user regarding the use of the emotion engine, and if the user consents, it requests device access permissions such as the camera and microphone, and sets up emotional state monitoring.

[1406] Step 4:

[1407] The user receives an email, and the app displays a "Describe this email" button. The input is the information of the received email, and the output is the display of the "Describe this email" button. When an email is received, this application, which is linked to the email app, displays the "Describe this email" button in the email viewer.

[1408] Step 5:

[1409] When the user clicks the judgment button, the app extracts the sender domain information, subject, and part of the body of the email. The input is the user's click operation, and the output is the extracted email information. The app analyzes the sender domain information, subject, and part of the body of the email and extracts information such as "Sender: phishing@example.com, Subject: Free Gift, Part of Body: You have won."

[1410] Step 6:

[1411] The application sends email information to a cloud server as an API request. The input is the extracted email information, and the output is a success message for sending the API request to the server. The application sends a request to the API endpoint containing the email information and user authentication information.

[1412] Step 7:

[1413] The server receives a request and analyzes the email information using a generative AI model. The input is the email information, and the output is the phishing detection result. The server passes the sender domain, subject, and part of the body of the received email to the generative AI model to analyze whether it is a phishing email. For example, it uses features such as "the sender domain is not an official domain" or "the subject matches a typical phishing email pattern" to make the determination.

[1414] Step 8:

[1415] The server receives the judgment results from the generated AI model and sends them back to the user's terminal. The input is the judgment result from the generated AI model, and the output is the result sent back to the user's terminal. The server organizes the judgment results and sends a result such as "This email is a phishing email" or "This email is safe" to the user's terminal.

[1416] Step 9:

[1417] The device (app) receives the judgment result from the server and uses the emotion engine to recognize the user's current emotional state. The input is the judgment result from the server, and the output is the evaluation result of the user's emotional state. The device analyzes input data from the camera and microphone to analyze the user's facial expressions and voice tone.

[1418] Step 10:

[1419] The emotion engine selects the optimal notification method based on the user's emotional state. The input is the result of the user's emotional state evaluation, and the output is the result of selecting the optimal notification format. Based on the user's emotional state (e.g., tension, anxiety, relaxation), the emotion engine selects the most appropriate method from text notifications, voice notifications, and visual notifications.

[1420] Step 11:

[1421] The app displays or notifies the user of a warning message in the most appropriate format based on its assessment results. The input is the optimal notification format and assessment result, and the output is the display or notification of the warning message. For example, if the user is relaxed, a pop-up notification saying "This email may be a phishing attempt" will be displayed, and if the user is feeling anxious, a gentle voice message saying "This email may be a phishing attempt" will be displayed.

[1422] By following these steps, users will be protected from the risks of phishing emails and will receive appropriate notifications tailored to their emotional state.

[1423] (Application Example 2)

[1424] Next, we will explain application example 2. In the following explanation, the data processing device 12 will be referred to as the "server" and the robot 414 as the "terminal".

[1425] Currently, many systems for detecting phishing emails and notifying users simply analyze the email content and display warnings, but this does not take into account the user's psychological state and therefore does not provide sufficient security. Furthermore, the uniform notification method may prevent users from responding appropriately or may cause excessive anxiety. Solving these problems is the objective of this invention.

[1426] The identification processing performed by the identification processing unit 290 of the data processing device 12 in Application Example 2 is realized by the following means. In this invention, the server includes means for extracting the sender domain information of an email, means for querying the generation AI to determine whether the sender domain information is legitimate, means for receiving the determination result from the generation AI and notifying the user, and means for including an emotion engine that analyzes the user's emotional state and optimizing the notification method based on the emotion engine. This makes it possible to detect phishing emails and provide an optimal notification method that corresponds to the user's psychological state.

[1427] "Sender domain information" refers to information that identifies the domain name used to identify the sender of an email.

[1428] "Generative AI" is a system that uses artificial intelligence technology to learn and analyze email information to determine whether or not it is a phishing email.

[1429] "Means of notifying the user" refers to methods or functions for communicating the judgment result to the user.

[1430] An "emotion engine" is a system that analyzes and recognizes a user's emotional state in real time.

[1431] "Means of optimizing notification methods" refer to means of delivering notifications in the most effective and sensitive way, based on the user's current emotional state.

[1432] "The subject line and part of the email body" refers to the title of the received email and a portion of its content.

[1433] "Initial setup method" refers to the method or function for performing the necessary settings when using the system for the first time.

[1434] "Methods for directly obtaining email information from linked email applications" refers to a function that links with the email application used by the user and directly obtains email information from that application.

[1435] "Means of displaying warning messages" refers to methods or functions for displaying messages on a user's device that inform them that an email may be a phishing email.

[1436] "Text notification" refers to a method of notifying users using text information.

[1437] "Voice notification" refers to a method of notifying users using voice.

[1438] This invention relates to a system that automatically identifies phishing emails and optimizes notification methods using a user's sentiment engine. This system combines a smartphone application, a cloud-based server, and a sentiment engine.

[1439] First, the user installs the smartphone application and completes the initial setup. This setup includes integration with the email application and obtaining necessary access permissions through OAuth authentication. The user also agrees to use the emotion engine, allowing for real-time monitoring of their emotional state.

[1440] When an email is received, this system, which is integrated with the email application, extracts the sender domain information, subject, and a portion of the email body, and sends them to the cloud server. This extraction includes analysis to identify the sender domain information of the email. The cloud server uses generative AI to determine whether the sender domain information and email content are legitimate. Based on past data, the generative AI accurately evaluates whether the email is a phishing email.

[1441] The user is notified of the assessment result, but at that time, an emotion engine is used to analyze the user's emotional state (e.g., relaxed, anxious, tense) and select the optimal notification method (text, voice). For example, if the user is relaxed, a text notification is sent, and if they are feeling anxious, a gentle voice notification is sent.

[1442] The primary hardware used includes smartphones and cloud servers, while the main software includes generative AI and an emotion engine. As a concrete example, the legitimacy of an email is determined by sending prompts like the following to the generative AI.

[1443] Example of a prompt:

[1444] Is the email from the domain "examplebank.com" a potential phishing email? Subject: "Important Notice: Account Freeze", Part of the body: "Your account has been frozen. Please check this link immediately."

[1445] In this way, users are protected from the risks of phishing emails and receive appropriate notifications that take their emotions into consideration. This system provides highly accurate and user-friendly security measures by combining generative AI and an emotion engine.

[1446] The flow of a specific process in Application Example 2 will be explained using Figure 14.

[1447] Step 1:

[1448] The user installs the smartphone application and completes the initial setup. The user then connects with their email application and obtains the necessary access permissions through OAuth authentication. Additionally, the user agrees to use the emotion engine and configures settings to monitor their emotional state in real time.

[1449] Input: Smartphone application, email application account information

[1450] Output: Application installation and configuration complete, OAuth authentication performed and access permissions obtained.

[1451] Step 2:

[1452] When a user receives an email, the linked smartphone application extracts the sender's domain information, subject, and a portion of the email's body. This provides the basic information about the email.

[1453] Input: Received email

[1454] Output: Sender domain information, subject, and part of the message body.

[1455] Step 3:

[1456] The terminal (application) sends the extracted sender domain information, subject, and a portion of the email body to the cloud server as an API request. This request includes a prompt asking whether the email is a phishing attempt.

[1457] Input: Sender domain information, subject, and part of the message body.

[1458] Output: Sending an API request

[1459] Step 4:

[1460] The server passes the received request to the generating AI, which determines whether the email content and sender domain information have characteristics of a phishing email. Based on past training data, the generating AI analyzes whether the email is a phishing email.

[1461] Input: Sender domain information, subject, part of the message body, prompt message

[1462] Output: Judgment result by the generated AI

[1463] Step 5:

[1464] The server receives the judgment results from the generating AI, organizes the results, and sends them back to the user's terminal. These results include information on whether or not the email is a phishing email.

[1465] Input: Judgment result generated by AI

[1466] Output: Return of judgment result

[1467] Step 6:

[1468] The terminal (application) receives the judgment result from the server and optimizes the notification method using an emotion engine that analyzes the user's current emotional state. For example, if the user is relaxed, a text notification is sent, and if anxiety is heightened, an audio notification is sent.

[1469] Input: Judgment result, user's emotional state

[1470] Output: Selection of an optimized notification method

[1471] Step 7:

[1472] The application notifies the user of the phishing email detection result based on an optimized notification method. For example, if the user is relaxed, it will notify them via text message saying, "This email may be a phishing email," while if the user is feeling anxious, it will notify them of the same message in a gentle voice message.

[1473] Input: Optimized notification method

[1474] Output: Notification to the user

[1475] In this way, users are protected from the risks of phishing emails and can receive appropriate, emotionally sensitive notifications.

[1476] The specific processing unit 290 transmits the result of the specific processing to the robot 414. In the robot 414, the control unit 46A causes the speaker 240 and the controlled object 443 to output the result of the specific processing. The microphone 238 acquires audio indicating user input for the result of the specific processing. The control unit 46A transmits the audio data indicating user input acquired by the microphone 238 to the data processing unit 12. In the data processing unit 12, the specific processing unit 290 acquires the audio data.

[1477] Data generation model 58 is a type of so-called generative AI (Artificial Intelligence). One example of data generation model 58 is ChatGPT (Internet search<URL: https: / / openai.com / blog / chatgpt> ), Gemini (Internet search) <url: https: gemini.google.com ?hl="ja">Examples of generative AI include the following. The data generation model 58 is obtained by performing deep learning on a neural network. The data generation model 58 is input with prompts containing instructions, and with inference data such as audio data representing speech, text data representing text, and image data representing images. The data generation model 58 infers from the input inference data according to the instructions indicated by the prompts, and outputs the inference results in data formats such as audio data and text data. Here, inference refers to, for example, analysis, classification, prediction, and / or summarization.

[1478] In the above embodiment, an example was given in which specific processing is performed by the data processing device 12, but the technology of this disclosure is not limited thereto, and the specific processing may also be performed by the robot 414.

[1479] Furthermore, the emotion identification model 59, acting as an emotion engine, may determine the user's emotion according to a specific mapping. Specifically, the emotion identification model 59 may determine the user's emotion according to a specific mapping, which is an emotion map (see Figure 9). Similarly, the emotion identification model 59 may also determine the robot's emotion, and the identification processing unit 290 may perform identification processing using the robot's emotion.

[1480] Figure 9 shows an emotion map 400 in which multiple emotions are mapped. In the emotion map 400, emotions are arranged in concentric circles radiating from the center. The closer to the center of the concentric circles, the more primitive the emotions are located. Further out of the concentric circles, emotions representing states and actions arising from mental states are located. Emotion is a concept that includes feelings and mental states. On the left side of the concentric circles, emotions that are generally generated from reactions occurring in the brain are located. On the right side of the concentric circles, emotions that are generally induced by situational judgment are located. Above and below the concentric circles, emotions that are generally generated from reactions occurring in the brain and induced by situational judgment are located. In addition, the emotion of "pleasure" is located on the upper side of the concentric circles, and the emotion of "displeasure" is located on the lower side. Thus, in the emotion map 400, multiple emotions are mapped based on the structure in which emotions arise, and emotions that are likely to occur simultaneously are mapped close together.

[1481] These emotions are distributed at the 3 o'clock position on the Emotion Map 400, and usually fluctuate between feelings of security and anxiety. In the right half of the Emotion Map 400, situational awareness takes precedence over internal feelings, resulting in a calm impression.

[1482] The inside of the Emotion Map 400 represents inner thoughts, while the outside represents actions. Therefore, the further you go from the outside of the Emotion Map 400, the more visible (expressed in actions) your emotions become.

[1483] Here, human emotions are based on various balances, such as posture and blood sugar levels. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. Similarly, in robots, cars, motorcycles, etc., emotions can be created based on various balances, such as posture and battery level. When these balances deviate from the ideal, it results in discomfort, and when they approach the ideal, it results in pleasure. The emotion map can be generated based, for example, on Dr. Mitsuyoshi's emotion map (Research on a system for analyzing brain physiological signals of speech emotion recognition and emotion, Tokushima University, doctoral dissertation: https: / / ci.nii.ac.jp / naid / 500000375379). The left half of the emotion map contains emotions belonging to a region called "response," where sensation is dominant. The right half of the emotion map contains emotions belonging to a region called "situation," where situational awareness is dominant.

[1484] The emotion map defines two emotions that promote learning. One is the emotion around the middle of the negative "repentance" and "reflection" on the situation side. In other words, it is when the robot experiences negative emotions such as "I never want to feel this way again" or "I don't want to be scolded again." The other is the emotion around the positive "desire" on the reaction side. In other words, it is when the robot has positive feelings such as "I want more" or "I want to know more."

[1485] The emotion identification model 59 inputs user input into a pre-trained neural network, obtains emotion values ​​representing each emotion shown in the emotion map 400, and determines the user's emotion. This neural network is pre-trained based on multiple training data sets, which are combinations of user input and emotion values ​​representing each emotion shown in the emotion map 400. Furthermore, this neural network is trained so that emotions located close together have similar values, as shown in the emotion map 900 in Figure 10. Figure 10 shows an example where multiple emotions such as "reassured," "calm," and "confident" have similar emotion values.

[1486] The above description primarily focuses on the functions of the data processing device 12 in relation to this disclosure. However, the system related to this disclosure is not necessarily implemented on a server. The system related to this disclosure may be implemented as a general information processing system. This disclosure may be implemented, for example, as a software program that runs on a personal computer or as an application that runs on a smartphone. The method related to this disclosure may be provided to users in SaaS (Software as a Service) format.

[1487] In the above embodiment, an example was given in which a specific process is performed by a single computer 22. However, the technology of this disclosure is not limited thereto, and a distributed processing of the specific process may be performed by multiple computers, including computer 22. For example, a data generation model 58 may be provided in an external device of the data processing device 12, and the external device may generate data according to the input data.

[1488] In the above embodiment, an example was given in which the specific processing program 56 is stored in the storage 32, but the technology of this disclosure is not limited thereto. For example, the specific processing program 56 may be stored in a portable, computer-readable, non-temporary storage medium such as a USB (Universal Serial Bus) memory. The specific processing program 56 stored in the non-temporary storage medium is installed in the computer 22 of the data processing device 12. The processor 28 executes specific processing according to the specific processing program 56.

[1489] Alternatively, the specific processing program 56 may be stored in a storage device such as a server connected to the data processing device 12 via the network 54, and the specific processing program 56 may be downloaded and installed on the computer 22 in response to a request from the data processing device 12.

[1490] Furthermore, it is not necessary to store the entirety of the specific processing program 56 in a storage device such as a server connected to the data processing device 12 via the network 54, or to store the entirety of the specific processing program 56 in the storage 32; it is acceptable to store only a portion of the specific processing program 56.

[1491] The following types of processors can be used as hardware resources to perform specific processing. Examples of processors include a CPU, a general-purpose processor that functions as a hardware resource to perform specific processing by executing software, i.e., a program. Other examples of processors include dedicated electrical circuits, such as FPGAs (Field-Programmable Gate Arrays), PLDs (Programmable Logic Devices), or ASICs (Application Specific Integrated Circuits), which have circuit configurations specifically designed to perform specific processing. All of these processors have built-in or connected memory, and all of them perform specific processing by using memory.

[1492] The hardware resource that performs a specific process may consist of one of these various processors, or it may consist of a combination of two or more processors of the same or different types (for example, a combination of multiple FPGAs, or a combination of a CPU and an FPGA). Alternatively, the hardware resource that performs a specific process may consist of a single processor.

[1493] Examples of configurations using a single processor include, firstly, a configuration in which one or more CPUs and software are combined to form a single processor, and this processor functions as a hardware resource that performs a specific process. Secondly, there is a configuration using a processor that realizes the functions of the entire system, including multiple hardware resources that perform a specific process, on a single IC chip, as exemplified by SoCs (System-on-a-chip). In this way, a specific process is realized using one or more of the above types of processors as hardware resources.

[1494] Furthermore, the hardware structure of these various processors can more specifically utilize electrical circuits that combine circuit elements such as semiconductor devices. Also, the specific processing described above is merely an example. Therefore, it goes without saying that unnecessary steps can be deleted, new steps added, or the processing order rearranged, as long as it does not deviate from the main purpose.

[1495] The descriptions and illustrations presented above are detailed explanations of the technical aspects of this disclosure and are merely examples of the technical aspects. For example, the above descriptions of the structure, function, operation, and effect are examples of the structure, function, operation, and effect of the technical aspects of this disclosure. Therefore, it goes without saying that you may delete unnecessary parts, add new elements, or replace elements in the descriptions and illustrations presented above, as long as you do not deviate from the essence of the technical aspects of this disclosure. Furthermore, in order to avoid confusion and facilitate understanding of the technical aspects of this disclosure, explanations of common technical knowledge and the like that do not require special explanation to enable the implementation of the technical aspects of this disclosure have been omitted from the descriptions and illustrations presented above.

[1496] All documents, patent applications, and technical standards described herein are incorporated by reference to the same extent as if each individual document, patent application, and technical standard were specifically and individually noted as being incorporated by reference.

[1497] The following is further disclosed regarding the embodiments described above.

[1498] (Claim 1)

[1499] A method for extracting the sender domain information of an email,

[1500] A means for querying the generating AI to determine whether the aforementioned source domain information is legitimate,

[1501] A means for receiving the judgment result from the aforementioned generating AI and notifying the user,

[1502] A system that includes this.

[1503] (Claim 2)

[1504] A method for extracting the subject and part of the body of an email,

[1505] A means for querying the generating AI whether the subject and content of the text have characteristics of phishing,

[1506] A means of notifying the user of the email's security based on the judgment result from the aforementioned generating AI,

[1507] The system according to claim 1, including the following:

[1508] (Claim 3)

[1509] Initial setup method for linking with the email app,

[1510] A method to directly obtain email information from a linked email application,

[1511] A means for displaying a warning message on the user device based on the aforementioned determination result,

[1512] The system according to claim 1, including the following:

[1513] "Example 1"

[1514] (Claim 1)

[1515] A method for extracting the sender domain information of an email,

[1516] A means for querying the generating AI to determine whether the aforementioned source domain information is legitimate,

[1517] A method for extracting the subject and part of the body of an email,

[1518] A means for querying the generating AI whether the subject and content of the text have characteristics of phishing,

[1519] A means for receiving the judgment result from the aforementioned generating AI and notifying the user,

[1520] A system that includes this.

[1521] (Claim 2)

[1522] Initial setup method for linking with the email app,

[1523] A method to directly obtain email information from a linked email application,

[1524] A means for displaying a warning message on the user device based on the aforementioned determination result,

[1525] The system according to claim 1, including the following:

[1526] (Claim 3)

[1527] A means for generating a prompt message for determining whether an email is a phishing email based on the aforementioned generated AI,

[1528] A means for inputting the aforementioned prompt sentence into the generating AI model,

[1529] A means for returning the judgment result obtained from the generated AI model to the user device via the server,

[1530] The system according to claim 1, including the following:

[1531] "Application Example 1"

[1532] (Claim 1)

[1533] A method for extracting the sender domain information of an email,

[1534] A means for querying the generating AI to determine whether the aforementioned source domain information is legitimate,

[1535] A means for receiving the judgment result from the aforementioned generating AI and notifying the user,

[1536] Initial setup method for linking with the user's email account,

[1537] A method for directly obtaining email information from linked email accounts,

[1538] A means for displaying a warning message on the user device based on the aforementioned determination result,

[1539] ...a system that includes

[1540] (Claim 2)

[1541] A method for extracting the subject and part of the body of an email,

[1542] A means for querying the generating AI whether the subject and content of the text have characteristics of phishing,

[1543] A means of notifying the user of the email's security based on the judgment result from the aforementioned generating AI,

[1544] A means of displaying the judgment result in real time on the user's smart device,

[1545] ...the system according to claim 1, including

[1546] (Claim 3)

[1547] A method for determining the legitimacy of an email by inputting a prompt message into a generative AI model,

[1548] A means for sending the phishing email detection result from the generating AI based on the aforementioned prompt message to a cloud server,

[1549] A means for notifying the user device of the phishing email detection result from the aforementioned cloud server,

[1550] ...the system according to claim 1, including

[1551] "Example 2 of combining an emotion engine"

[1552] (Claim 1)

[1553] A means for extracting the sender domain information, subject, and part of the body of an email,

[1554] A means for querying a generating AI model to determine whether the aforementioned sender domain information, subject, and content of the body have characteristics of phishing,

[1555] A means for receiving the judgment result from the aforementioned generated AI model and notifying the user,

[1556] An emotion engine means that recognizes the user's emotional state and optimizes the notification method,

[1557] A system that includes this.

[1558] (Claim 2)

[1559] Initial setup method for integrating with email applications,

[1560] A means of directly obtaining email information from a linked email application,

[1561] A means for displaying or notifying a warning message in a format optimized for the user device based on the aforementioned determination result,

[1562] The system according to claim 1, including the following:

[1563] (Claim 3)

[1564] A means of analyzing a user's emotional state in real time using an emotion engine,

[1565] A means of selecting the optimal notification method (e.g., text, voice, visual) based on the user's emotional state,

[1566] A means for providing a phishing warning based on the judgment result of the aforementioned generation AI model and the analysis result of the emotion engine,

[1567] The system according to claim 1, including the following:

[1568] "Application example 2 when combining with an emotional engine"

[1569] (Claim 1)

[1570] A method for extracting the sender domain information of an email,

[1571] A means for querying the generating AI to determine whether the aforementioned source domain information is legitimate,

[1572] A means for receiving the judgment result from the aforementioned generating AI and notifying the user,

[1573] Includes an emotion engine that analyzes the user's emotional state,

[1574] Means for optimizing the notification method based on the aforementioned emotion engine,

[1575] A system that includes this.

[1576] (Claim 2)

[1577] A method for extracting the subject and part of the body of an email,

[1578] A means for querying the generating AI whether the subject and content of the text have characteristics of phishing,

[1579] A means of notifying the user of the email's security based on the judgment result from the aforementioned generating AI,

[1580] A means of selecting the optimal notification method based on the user's current emotional state,

[1581] The system according to claim 1, including the following:

[1582] (Claim 3)

[1583] Initial setup method for linking with the email app,

[1584] A method to directly obtain email information from a linked email application,

[1585] A means for displaying a warning message on the user device based on the aforementioned determination result,

[1586] A method to send text notifications when the user's emotional state is relaxed, and voice notifications when their anxiety level is high.

[1587] The system according to claim 1, including the following: [Explanation of Symbols]

[1588] 10, 210, 310, 410 Data Processing Systems 12 Data Processing Devices 14 Smart Devices 214 Smart Glasses 314 Headset-type terminal 414 Robots< / url:> < / url:> < / url:> < / url:>

Claims

1. A method for extracting the sender domain information of an email, A means for querying the generating AI to determine whether the aforementioned source domain information is legitimate, A means for receiving the judgment result from the aforementioned generating AI and notifying the user, A system that includes this.

2. A method for extracting the subject and part of the body of an email, A means for querying the generating AI whether the subject and content of the text have characteristics of phishing, A means of notifying the user of the email's security based on the judgment result from the aforementioned generating AI, The system according to claim 1, including the following:

3. Initial setup method for linking with the email app, A method to directly obtain email information from a linked email application, A means for displaying a warning message on the user device based on the aforementioned determination result, The system according to claim 1, including the following:

Citation Information

Patent Citations

  • Persona chatbot control method and system

    JP2022180282A