Distribution system and distribution method

The distribution system uses a whitelist of trusted senders to automatically deliver messages and request additional information from untrusted senders, enhancing message accuracy and reducing unnecessary judgment efforts.

JP2026084426APending Publication Date: 2026-05-21DISCO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
DISCO CORP
Filing Date
2024-11-11
Publication Date
2026-05-21

AI Technical Summary

Technical Problem

Existing systems fail to accurately distinguish between necessary and unauthorized messages, leading to unnecessary effort in determining message necessity and increased risk of judging necessary messages as unnecessary.

Method used

A distribution system and method utilizing a whitelist of trusted senders, where messages from trusted senders are automatically delivered, and untrusted senders are prompted for additional information to determine trustworthiness before being added to the whitelist.

Benefits of technology

This approach reduces the risk of necessary messages being deemed unnecessary by ensuring accurate determination of message necessity and reducing repetitive decision-making, thereby minimizing effort and improving message handling efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026084426000001_ABST
    Figure 2026084426000001_ABST
Patent Text Reader

Abstract

The present invention provides a delivery system that can appropriately determine whether or not a sent message is necessary. [Solution] The distribution system includes a receiving unit that receives messages, a storage unit that stores a whitelist in which information about trusted senders is registered, a matching unit that compares information about the message sender with information registered in the whitelist, a distribution unit that sends the message to the recipient distribution unit when the information about the sender matches the information registered in the whitelist, an input request unit that requests information from the sender when the information about the sender does not match the information registered in the whitelist, and an update unit that adds information about the sender to the whitelist when permission to add information about the sender to the whitelist is granted based on the information entered by the sender.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a system and method for delivering a message transmitted from a source to a destination.

Background Art

[0002] In recent years, against the backdrop of the development of the Internet, the transmission and reception of information by electronic means such as e-mail has become widespread. In such a situation, the distribution of unauthorized messages that are unilaterally transmitted regardless of the intention of the recipient, such as spam e-mails, has long been a serious social problem.

[0003] Such unauthorized messages include various types and natures of messages, such as spam e-mails (spam messages) sent to an unspecified large number of recipients and messages called targeted mails targeting specific individuals or organizations.

[0004] For the recipient of a message, there is a problem that the recipient has to distinguish between necessary messages and such unauthorized messages and select necessary messages, which takes time and effort.

[0005]

[0006] Therefore, technologies for automatically discriminating such unauthorized messages and isolating or deleting them as unnecessary messages have been developed and put into practical use. For example, Patent Document 1 discloses a technology for determining that an e-mail is an unnecessary e-mail when there is a link to a URL, an e-mail address, etc. in the text of the e-mail.

[0007] To avoid such situations, recipients need to periodically check messages that have been quarantined by the system as unnecessary. In other words, because the accuracy of the automated judgment is not practically sufficient, recipients ultimately have to decide whether or not a message is necessary, resulting in a problem where the time and effort caused by sending malicious messages are not sufficiently reduced. [Prior art documents] [Patent Documents]

[0008] [Patent Document 1] Japanese Patent Publication No. 2003-131999 [Overview of the Initiative] [Problems that the invention aims to solve]

[0009] The object of the present invention is to provide a delivery system and delivery method that can suitably determine whether a transmitted message is necessary or not, and reduce the risk that a necessary message may be judged as unnecessary. [Means for solving the problem]

[0010] According to one aspect of the present invention, a distribution system is provided comprising: a receiving unit that receives a message sent from a sender to a recipient; a storage unit that stores a whitelist in which information about trusted senders is registered; a matching unit that compares information about the sender of the message with information about trusted senders registered in the whitelist; a transmitting unit that sends the message to the recipient's receiving unit if the information about the sender matches the information about trusted senders registered in the whitelist; an input request unit that requests the sender to input information if the information about the sender does not match the information about trusted senders registered in the whitelist; and an update unit that adds information about the sender to the whitelist if the addition of information about the sender to the whitelist is permitted based on the information input by the sender.

[0011] According to another aspect of the present invention, a distribution system is provided comprising a processor, a memory storing a whitelist in which information about trusted sources is registered and control software, and a transceiver that receives messages sent from a source to a destination, wherein the processor, in accordance with the software, compares information about the source of the message received by the transceiver with information about trusted sources registered in the whitelist, sends the message to the destination if the information about the source matches the information about trusted sources registered in the whitelist, requests the source to input information if the information about the source does not match the information about trusted sources registered in the whitelist, and adds the information about the source to the whitelist if, based on the information input by the source, it is permitted to add the information about the source to the whitelist.

[0012] Preferably, the distribution system includes an addition decision unit that transmits the information entered by the sender to the distribution unit, requests approval for adding the information about the sender to the whitelist, and determines whether or not to add the information about the sender to the whitelist based on whether or not the approval for the addition is granted.

[0013] According to another aspect of the present invention, a delivery method is provided comprising: a receiving step of receiving a message; a matching step of comparing information about the sender of the message with information about trusted senders registered in a whitelist in which information about trusted senders is registered; an input request step of requesting the sender to input information if the information about the sender does not match the information about trusted senders registered in the whitelist; an input information acquisition step of acquiring information entered by the sender; an addition determination step of determining whether to add the information about the sender to the whitelist based on the information entered by the sender; and an update step of adding the information about the sender to the whitelist if the addition is permitted in the addition determination step. [Effects of the Invention]

[0014] According to the distribution system and distribution method relating to each aspect of the present invention, a whitelist containing information about trusted senders is used, and only messages from senders matching the information registered in the whitelist are sent to the recipient's distribution unit. This allows for a suitable determination of whether or not a sent message is necessary, and reduces the risk of necessary messages being deemed unnecessary. [Brief explanation of the drawing]

[0015] [Figure 1] Figure 1 is a block diagram that schematically shows an example of the overall configuration of the distribution system. [Figure 2] Figure 2 is a schematic block diagram showing an example of the hardware configuration of the message server (message distribution device) in the distribution system shown in Figure 1. [Figure 3] Figure 3 is a block diagram schematically showing an example of the functions implemented by software and their relationships in the distribution system shown in Figure 1. [Figure 4] Figure 4 is a flowchart showing an example of the procedure for delivering messages. [Modes for carrying out the invention]

[0016] Embodiments of the present invention will be described with reference to the attached drawings. Figure 1 is a schematic block diagram showing an example of the overall configuration of the distribution system.

[0017] The distribution system 100 according to this embodiment includes a message server 2. Client terminals 4 are connected to the message server 2 via a local area network 6. The message server 2 is also connected to an external message server (external server) 10 via a wide area network 8.

[0018] The message server 2 is a device that sends and receives messages, and is, for example, an information processing device referred to as a computer, server, etc. The message server 2 has various functions such as management of email addresses, storage of messages, and determination of the necessity of messages.

[0019] The client terminal 4 is a terminal device owned and operated by a user who uses the distribution system 100, and is, for example, an information and communication device such as a smartphone, a personal computer, a tablet, etc. Each client terminal 4 uses the email address managed by the message server 2 to exchange messages with the external server 10. The client terminal 4 can also refer to settings, data, etc. related to the electronic messages held by the message server 2 via the in-house network 6 and perform operations such as viewing and editing them.

[0020] In addition to functions related to sending, receiving, and managing such electronic messages, the client terminal 4 also has a function of receiving, displaying, and playing various contents such as images, videos, applications, etc. from an external server 10 connected to the wide area network 8 and other servers (not shown).

[0021] The in-house network 6 is, for example, a LAN (Local Area Network), and the wide area network 8 is, for example, the Internet.

[0022] The external server 10 is an information and communication device installed, for example, by an individual, a company, a government agency, etc. and connected to the wide area network 8. The external server 10 is, for example, a device equivalent to the above-mentioned message server 2. The external server 10 may be a device that provides various contents such as messages, images, videos, applications, etc. to the client terminal 4 through the wide area network 8.

[0023] One or more client terminals 4 are connected to message server 2. Similarly, one or more terminal devices (external terminals) 12 are connected to external server 10, and messages and various types of data are exchanged between client terminals 4 and external terminals 12, or between client terminals 4 and external server 10.

[0024] In the following, assuming that a message is sent from an external terminal 12 or an external server 10 to a client terminal 4, the external terminal 12 and the external server 10 are treated as sending devices used by the sending user, and the message server 2 and client terminal 4 are treated as receiving devices used by the receiving user.

[0025] Figure 2 is a schematic block diagram showing an example of the hardware configuration of the receiving message server (message distribution device) 2 in the distribution system 100 of Figure 1. As shown in Figure 2, the message server 2 comprises a processor 14, memory 16, and transceiver 18. The processor 14, memory 16, and transceiver 18 are interconnected via a bus.

[0026] The processor 14 is, for example, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), or an NPU (Neural Network Processing Unit), and controls various information processing within the message server 2. The processor 14 performs various processing by, for example, reading software such as programs and data from the memory 16 and executing them. The message server 2, which is a message distribution device, may have multiple processors 14.

[0027] Memory 16 is comprised of storage devices such as ROM (Read Only Memory), RAM (Random Access Memory), HDD (Hard Disk Drive), and SSD (Solid State Drive). Memory 16 stores various information, such as programs and data necessary for processing by the processor 14, as software. In particular, memory 16 stores a whitelist containing information about trusted sources and control software. The functions of the whitelist and software will be explained in detail later.

[0028] The transceiver 18 is connected to external equipment via the local network 6 and is a device that communicates with said external equipment, and in particular receives messages sent from a source to a destination. The transceiver 18 includes, for example, a network card, a communication module, an antenna, a modulator, a demodulator, etc.

[0029] Figure 3 is a schematic block diagram illustrating an example of the functions and their relationships implemented by software in the distribution system 100 of Figure 1. As shown in Figure 3, the message server 2 includes a receiving unit 20 and a transmitting unit 22 for sending and receiving messages, a storage unit 24 and a matching unit 26 for determining whether a message is necessary, an input request unit 28, an information input unit 30, an additional decision unit 32, and an update unit 34 for updating the data used to determine whether a message is necessary.

[0030] In Figure 3, a client terminal 4 is shown connected to the message server 2 as the receiving device, and an external terminal 12 is shown as the transmitting device. However, devices such as the external server 10, the wide area network 8, and the local area network 6 located between them are not shown in the illustration.

[0031] The receiving unit 20 receives messages sent from an external terminal 12 or external server 10 (see Figure 1) used by the sending user.

[0032] The transmitting unit 22 sends the messages received by the receiving unit 20 to the client terminal 4, which is the recipient unit. In this embodiment, the transmitting unit 22 of the message server 2 sends only the messages that meet specific conditions from among the messages received by the receiving unit 20 to the client terminal 4.

[0033] The memory unit 24 stores a whitelist containing information about specific senders. Here, a "specific sender" refers to a trusted sender that has been judged by a user using the client terminal 4, the administrator of the distribution system 100, etc., as safe, useful, or necessary as a message source. The "information about the sender" registered in the whitelist refers to information that can be used to determine the sender or its attributes, such as email addresses, domains, IP addresses, the country or region of the sender, or specific strings contained in the message header, etc.

[0034] Furthermore, if, for example, a user using client terminal 4 and a specific sender agree in advance that the body or title of the messages sent and received will include a specific string, then it will be possible to identify the sender of a message if that string is included in the body or title of the message. Such strings can also be treated as "information about the sender."

[0035] The matching unit 26 compares the information regarding the sender of the message received by the receiving unit 20 with the information registered in the whitelist, and determines whether the former information matches the latter information.

[0036] Hereinafter, information regarding the sender that is registered in the whitelist will be referred to as "registered information" for convenience. Furthermore, information regarding the sender of a message received by the receiving unit 20 that is compared with the suitability information registered in the whitelist will be referred to as "suitability determination information" for convenience.

[0037] The input request unit 28 requests the relevant sender to input information based on the determination made by the matching unit 26. Specifically, if the information regarding the sender of a message received by the receiving unit 20 (suitability determination information) does not match the information registered in the whitelist (registered information), the unit requests the relevant sender to input information. The request for information input is made, for example, using the information input unit 30.

[0038] In the following, the information requested from the sender in such cases will be referred to as "additional input information" for convenience.

[0039] The information input unit 30 is the part that, in response to a request from the input request unit 28, allows the user who sent the message to input the requested additional information. For example, the information input unit 30 sends an input form to the external terminal 12, which allows the user who sent the message to input the additional information using the external terminal 12. The input form is displayed on the screen of the external terminal 12. Once the information is entered by the user of the external terminal 12, the information input unit 30 stores the entered additional information.

[0040] The input form used in this case is, for example, placed as data at a specific URL on the wide-area network 8, and a link to that URL is sent to the external terminal 12 as a message such as an email. Alternatively, the input form data itself may be sent to the external terminal 12, or, for example, an email containing the items of data required as additional input information may be sent to the external terminal 12, and the user who sent the email may send the necessary data as a reply to that email.

[0041] Here, the additional input information requested from the sender by the input request unit 28 is information that the receiver can use to make a judgment about the sender or its attributes. As additional input information, for example, the following information about the sender is requested from the sender. • The name of the sender (the user who sent the message). • Sender's date of birth, phone number, address, etc. • Name of the sender's organization, telephone number, address, etc. The relationship between the recipient user and the sender. • The matter related to the message sent. The country or region to which the sender belongs. • A specific string of characters, password, etc.

[0042] The additional decision unit 32 determines, based on the additional input information entered by the sender in response to the request from the input request unit 28, whether or not to register the information about the relevant sender, that is, whether or not to add it to the whitelist.

[0043] When determining whether or not to add someone to the whitelist, for example, the addition decision unit 32 sends the additional input information entered by the sender in accordance with the request of the input request unit 28 to the client terminal 4, which is the receiving unit of the user, and requests approval to add the information about the sender to the whitelist. In response to this request, the user views the additional input information entered by the sender on the client terminal 4 and decides whether or not to trust the sender based on the additional input information.

[0044] A user who has determined that the sender is trustworthy approves the addition to the whitelist requested by the additional decision unit 32. In response to the user's approval to add the sender to the whitelist, the additional decision unit 32 permits the addition of information about the relevant sender to the whitelist.

[0045] If the user determines that they do not trust the sender, the user will not authorize the addition of the sender's information to the whitelist. In that case, the addition decision unit 32 decides not to add the information of the relevant sender to the whitelist.

[0046] Regarding whether or not to add to the whitelist, the addition decision unit 32 can automatically make a decision without requiring user confirmation each time. For example, certain rules for determining whether or not to add to the whitelist are stored in memory 16 in the form of data beforehand, and the addition decision unit 32 reads this data from memory 16 and determines whether or not the additional input information entered from the sender matches the rules defined in the data.

[0047] If the additional input information matches the rule, the additional decision unit 32 permits the addition of information about the relevant sender to the whitelist. If the information input from the sender does not match the rule, the additional decision unit 32 does not permit the addition to the whitelist.

[0048] Alternatively, for example, each item of information entered as additional input information could be automatically scored according to predetermined rules, and if the total score exceeds a threshold, information about the sender could be added to a whitelist.

[0049] In addition, decisions can also be made using, for example, machine learning models. A machine learning model is a model created using a dataset as training data that includes, for example, information about multiple sources (this information may be, for example, information input by the source in response to requests to multiple sources in the past, or information input by a user using the client terminal 4 for multiple sources) and whether or not each source's information can be added to a whitelist. The model takes the additional input information input by the source in response to a request from the input request unit 28 as an input value and outputs whether or not the source's information can be added to the whitelist.

[0050] Furthermore, in determining whether or not to add an item to the whitelist, in addition to the additional input information, the message itself sent by the sender may also be used to make the decision.

[0051] For example, when a user decides whether to add a message to a whitelist or send a message, the user may refer to a part of the message received by the receiving unit 20 (title, part of the body, header, etc.), or the components of the message may be defined in some of the rules used for automatic decision-making. In addition, some or all of the message may be included in the training data of a machine learning model, and some or all of the message may be used as input values ​​for the machine learning model.

[0052] The update unit 34 adds the relevant source information to the whitelist as registered information if the addition decision unit 32 has authorized the addition.

[0053] In the aforementioned distribution system 100, information such as registration information, suitability judgment information, and additional input information is handled as information related to the message sender. Here, the additional input information may be of the same type or quality as the registration information and suitability judgment information, or it may be of a different type or nature.

[0054] For example, the whitelist contains multiple email addresses as information about trusted senders (registration information). If the email address of a message received by the receiving unit 20 (suitability determination information) does not match an email address registered in the whitelist, the input request unit 28 requests the sender to enter the sender's name, date of birth, and password (additional input information). The sender is identified based on the additional input information entered accordingly, and if it is determined to be a trusted sender, the email address of the sender of the message is added to the whitelist as registration information. In this case, the registration information, suitability determination information, and additional input information are all different types and characteristics of information.

[0055] Alternatively, the whitelist may contain information about senders who are permitted to send messages (registered information), such as "senders belonging to a specific company." If the company name of the sender of a message received by the receiving unit 20 is not included in the list of registered senders, the input request unit 28 requests the sender to input the name of their company. If the receiving user determines that the company entered is trustworthy, the company's name is added to the whitelist as registered information. In this case, the registered information, the suitability judgment information, and the additional input information are all of the same type and nature.

[0056] Next, the method for delivering messages using the aforementioned distribution system 100 will be explained. Figure 4 is a flowchart showing an example of the procedure for sending a message. At least part of the following procedure is executed by the processor 14 according to the software stored in memory 16.

[0057] When a message sent from an external source is received by the receiving unit 20 (reception step S10), the matching unit 26 compares the information regarding the source of the message (suitability determination information) with the information registered in the whitelist (registration information) (matching step S20). The whitelist stored in the storage unit 24 contains information about trusted sources (registration information), and the matching unit 26 determines whether the information regarding the source of the message received by the receiving unit 20 (suitability determination information) matches the registration information in the whitelist.

[0058] If the matching unit 26 determines, as a result of the matching step S20, that the appropriateness judgment information of the message matches the registration information in the whitelist, the transmission unit 22 transmits the message received by the reception unit 20 to the recipient, the client terminal 4 (transmission step S30), and the procedure ends.

[0059] If the matching unit 26 determines that the suitability judgment information does not match the registered information as a result of the matching step S20, the transmission of the message to the client terminal 4 is suspended, and the input request step S40 is performed. In the input request step S40, the input request unit 28 requests the sending user to input additional information.

[0060] The input request is sent, for example, to an external terminal 12, and the user of the external terminal 12, the source of the request, inputs additional information in the form of entering information into an input form or replying to a message from the input request unit 28. The additional input information entered from the source is acquired by the message server 2 through the information input unit 30 (input information acquisition step S50).

[0061] Based on the additional input information acquired in the input information acquisition step S50, the addition decision unit 32 decides whether or not to add the information about the sender to the whitelist (addition decision step S60). This decision is made, for example, manually based on the judgment of the user using the client terminal 4, as described above, or automatically based on certain rules, or by a machine learning model.

[0062] If the addition decision unit 32 permits the addition of information about the sender to the whitelist, the update step S80 is executed. The update unit 34 adds the information about the sender to the whitelist as registered information. Then, the message that was held back from transmission is sent by the transmission unit 22 to the recipient, the client terminal 4.

[0063] If the additional decision unit 32 does not permit the addition of information about the sender to the whitelist, the information will not be added to the whitelist, and the pending message will not be sent. The message server 2 may also send a notification to the client terminal 4 indicating that the sending of a message from an untrusted sender is pending. Users of the client terminal 4 can respond to this notification by viewing, for example, the pending message and any information attached to it, and deleting it or receiving it on the client terminal 4 as needed.

[0064] According to the distribution system 100 and distribution method described above, a whitelist containing information about trusted senders is used, and only messages from senders matching the registered information in the whitelist are sent to the recipient's distribution unit.

[0065] If the message's suitability criteria do not match the registered information in the whitelist, the message will be withheld, and the sender will be requested to enter information about themselves (additional input information). Based on the entered additional input information, a decision will be made on whether to add the sender to the whitelist and whether to send the message.

[0066] The user or message server 2, which is the recipient of the message, can refer to additional input information entered by the sender in response to a request from the input request unit 28, in addition to or instead of the message itself sent by the sender, to make decisions such as whether to trust the sender, whether to add information about the sender to a whitelist, and whether to receive or view the message.

[0067] In other words, when a message is received by the receiving unit 20, it is first determined whether the information regarding the sender (suitability determination information) matches the registered information in the whitelist. If it does not match, additional input information is requested from the sender, and further determination is made using this additional input information. This two-stage determination process allows for highly accurate judgments regarding the necessity of the message and the trustworthiness of the recipient, and helps to prevent situations where a message that should be received is mistakenly judged as unnecessary.

[0068] Furthermore, if the message suitability judgment information does not match the registered information in the whitelist, additional input information will be requested from the sender, the sender will input the additional information in response, and then a judgment will be made on the sender's trustworthiness and whether or not the message should be sent based on that additional input information. However, if the information about that sender is registered in the whitelist as a result, the same process will not be required for the same sender in the future.

[0069] Conventionally, even if messages originate from the same sender, the receiving user or system had to determine each message's content and accompanying information to determine whether it was necessary or not. This resulted in the need for repeated decision-making and often led to low accuracy in the decision-making process. The distribution system and distribution method of the above embodiment make it possible to determine the necessity of messages with high accuracy with minimal effort.

[0070] In the above embodiment, an example was described in which the receiving message server 2 is equipped with a mechanism for determining whether or not a message is necessary, but the form of the distribution system is not limited to this. For example, a distribution system could be conceivable in which another information processing device is provided as a message distribution device between the message server 2 and the local area network 6, or between the local area network 6 and the client terminal 4, and this information processing device makes various decisions regarding messages transmitted from an external source.

[0071] Alternatively, it is conceivable that the client terminal 4 has similar functionality (i.e., the client terminal 4 functions as a message distribution device), and that the recipient's delivery section is configured as an application such as email software installed on the client terminal 4, or as part of such an application.

[0072] Alternatively, a system can be envisioned in which, in addition to the receiving devices (message server 2, client terminal 4, etc.), an external server 10 configured as a cloud server is equipped with devices (processor, memory, transceiver, etc.) capable of implementing at least some of the functions described above, and the necessary software is stored in the memory of the external server 10, and the external server 10 causes the receiving devices such as message server 2 and client terminal 4 to execute at least some of the functions described above. In this case, for example, multiple processors may work together to perform the necessary processing, or the necessary software and data may be distributed and stored in multiple memories.

[0073] Furthermore, the structures, methods, etc., according to the embodiments described above are not limited to those embodiments and may be modified as appropriate without departing from the scope of the object of the present invention. [Explanation of Symbols]

[0074] 2: Message server (message distribution device), 4: Client terminal (receiving unit) 6: Local network, 8: Wide area network, 10: Message server (external server) 12: Terminal device (external terminal) 14: Processor, 16: Memory, 18: Transmitter / Receiver 20: Receiving unit, 22: Transmitting unit, 24: Storage unit, 26: Verification unit, 28: Input request unit 30: Information input unit, 32: Additional decision unit, 34: Update unit 100: Distribution System

Claims

1. A receiving unit that receives a message sent from the sender to the recipient, A memory unit that stores a whitelist containing information about trusted sources, A matching unit that compares information about the sender of the message with information about trusted senders registered in the whitelist, A sending unit that sends the message to the recipient's receiving unit if the information about the sender matches the information about trusted senders registered in the whitelist, An input request unit that requests information from the sender if the information about the sender does not match the information about trusted senders registered in the whitelist, A distribution system comprising: an update unit that adds information about the sender to the whitelist when permission is granted to add information about the sender to the whitelist based on information entered by the sender.

2. Processor and A memory containing a whitelist of information about trusted sources and control software, It comprises a transceiver that receives a message sent from a sender to a destination, The processor, in accordance with the software, The transceiver compares the information regarding the source of the message it receives with the information regarding trusted sources registered in the whitelist. If the information regarding the sender matches the information regarding trusted senders registered in the whitelist, the message will be sent to the recipient. If the information regarding the sender does not match the information regarding trusted senders registered in the whitelist, the sender is requested to enter information. A distribution system that adds information about a sender to a whitelist if, based on the information entered by the sender, it is permitted to add information about the sender to the whitelist.

3. The receiving unit transmits the information entered by the sender and requests approval for the addition of information about the sender to the whitelist. The distribution system according to claim 1, further comprising an addition decision unit that determines whether or not to add information about the sender to the whitelist based on whether or not the additional approval is granted.

4. Message reception step, A matching step involves comparing information about the sender of the message with information about trusted senders registered in a whitelist containing information about trusted senders. An input request step in which, if the information about the sender does not match the information about trusted senders registered in the whitelist, the sender is requested to enter information; An input information acquisition step to acquire information entered by the sender, An addition decision step that determines whether or not to add information about the sender to the whitelist based on the information entered by the sender, A distribution method comprising: an update step that adds information about the source to the whitelist if the addition is permitted in the addition decision step.