System and method for secure message verification
The secure message verification system addresses vulnerabilities in traditional communication systems by using a security module to create and compare message hashes and encrypted messages, ensuring message authenticity and integrity.
Patent Information
- Application Number
- PCT/SG2024/050157
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2025-09-18
AI Technical Summary
Traditional message communication systems lack adequate security measures, making them susceptible to scams, unauthorized access, and malicious attacks, and there is a need for enhanced verification mechanisms to ensure the authenticity and integrity of message content.
A secure message verification system using a security module that stores message records, creates message hashes and encrypted messages, and compares these against verification requests from recipient terminals to authenticate and verify the integrity of messages.
The system ensures the authenticity, integrity, and privacy of messages by leveraging hashing and cryptographic algorithms, providing a secure audit trail and reducing the risk of tampering.
Smart Images

Figure SG2024050157_18092025_PF_FP_ABST
Abstract
Description
[0001] SYSTEM AND METHOD FOR SECURE MESSAGE VERIFICATION
[0002] TECHNICAL CONTRIBUTION
[0003] The present invention generally relates to secure message verification. More particularly, the invention relates to use of a security module to use message records to verify messages received by a recipient terminal.
[0004] BACKGROUND
[0005] Traditional message communication systems, including SMS, message apps, and other instant messaging platforms, have long served as integral means of communication in both personal and professional applications. However, the widespread use of message communication has also exposed users to various security risks and threats. The traditional systems lack adequate security measures, making them susceptible to scams, unauthorized access, and malicious attacks.
[0006] To address these critical security concerns, there is a clear need for an enhanced and more secure message verification system that incorporates robust verification mechanisms to ensure the authenticity of senders and the integrity of message content. The system should provide users with a higher level of confidence in the privacy and security of their message communications.
[0007] Furthermore, other desirable feature and characteristics will become apparent from the subsequent detailed description and the appended claims, taken in conjunction with the accompanying drawings and this background of the disclosure. SUMMARY OF INVENTION
[0008] The method and system of secure message verification employing a security module to store message records of messages received from sender terminals and process verification requests from recipient terminals for forwarded message received. In a verification request, the appropriate message record can be identified by a hash of the forwarded message received by the recipient terminal or a message identifier appended to the forwarded message by the security module. The security module can verify the message by comparing data in the message record against data received from the recipient terminal.
[0009] A first embodiment of the invention is a method of secure message verification comprising the steps of: (a) receiving a message from a sender terminal at a message module through a network; (b) accessing the message from the message module with a security module; (c) creating a message record of the message with the security module; (d) routing the message record to an immutable database from the security module via the network; (e) sending a forwarded message to a recipient terminal via the network; (f) receiving and storing the forwarded message in the recipient terminal; (g) sending, from the recipient terminal, a verification request to the security module for the forwarded message; (h) upon receiving the verification request at the security module, retrieving from the immutable database the message record associated with the forwarded message; (i) for the message record associated with the forwarded message retrieved from the immutable database, determining at the security module at least one of a first comparison result and a second comparison result; and (j) delivering the first comparison result and / or the second comparison result from the security module to the recipient terminal via the network for display on the recipient terminal. The message includes message content and message metadata. The message metadata includes at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp. The message record includes either: (1) a first message hash and an encrypted message; or (2) the first message hash, the encrypted message, and a message identifier. The first message hash is created by hashing a first selection of the message using a hash function. The encrypted message is an encrypted string resulting from the encryption of an encrypted selection of the message employing encryption keys from a key server. The message identifier comprises at least one of: (1) an identifier selection of the first message hash; (2) a pseudo-random identifier of the message supplied by the security module, and (3) a non-random identifier of the message supplied by the security module. The forwarded message includes either: (i) the message received from the sender terminal; or (ii) an appended string including the message received from the sender terminal and the message identifier created by the security module for the message. The verification request includes at least one of: (i) either: a second message hash created by the recipient terminal from a second selection of the forwarded message using the hash function; or the message identifier received in the appended string of the forwarded message; and (ii) the message received from the sender terminal via the forwarded message. The message record is identified by the second message hash or the message identifier included in the verification request. The first comparison result is based on a first comparison of: ( 1) the first message hash of the message record stored in the message record; and (2) the second message hash included in the verification request. The second comparison result is based a second comparison of: (1) a decrypted version of the encrypted message stored in the message record; and (2) the message received from the sender terminal via the forwarded message.
[0010] A second embodiment of the invention is a system of secure message verification for a recipient terminal comprising: (a) a message module configured to receive a message from a sender terminal through a network, and (b) a security module. The security module is configured to: (i) access the message from the message module; (ii) create a message record of the message; (iii) route the message record to an immutable database from the security module via the network; (iv) instruct the message module to send a forwarded message to the recipient te minal via the network; (v) upon receiving the verification request at the security module, retrieve from the immutable database the message record associated with the forwarded message, wherein the message record is identified by the second message hash or the message identifier included in the verification request; (vi) for the message record associated with the forwarded message retrieved from the immutable database, determine at the security module at least one of a first comparison result based on a first comparison and a second comparison result based a second comparison; (vii) deliver the first comparison result and / or the second comparison result from the security module to the recipient terminal via the network for display on the recipient terminal. The message includes message content and message metadata. The message metadata includes at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp. The message record includes cither: (a) a first message hash and an encrypted message; or (b) the first message hash, the encrypted message, and a message identifier. The first message hash is created by hashing a first selection of the message using a hash function. The encrypted message is an encrypted string resulting from the encryption of an encrypted selection of the message employing encryption keys from a key server. The message identifier comprises at least one of: (a) an identifier selection of the first message hash, (b) a pseudo-random identifier of the message supplied by the security module; and (c) a nonrandom identifier of the message supplied by the security module. The forwarded message includes either: (a) the message received from the sender terminal; or (b) an appended string including the message received from the sender terminal and the message identifier created by the security module for the message. The recipient terminal is configured to create and send a verification request to the security module for the forwarded message. The verification request includes at least one of: (a) either a second message hash created by the recipient terminal from a second selection of the forwarded message using the hash function or, alternatively, the message identifier received in the appended string of the forwarded message; and (b) the message received from the sender terminal via the forwarded message. The first comparison result is based on a first comparison of: (a) the first message hash of the message record stored in the message record; and (b) the second message hash included in the verification request. The second comparison result is based a second comparison of: (a) a decrypted version of the encrypted message stored in the message record, and (b) the message received from the sender terminal via the forwarded message.
[0011] The secure message verification system disclosed herein addresses the inherent vulnerabilities and security risks associated with traditional message communication. By leveraging the power of hashing and cryptographic algorithms, the system ensures the authenticity, integrity, and privacy of messages exchanged between users.
[0012] The embodiments described herein are not exhaustive and that additional features and variations of the invention may be incorporated. Various other advantages and novel features of the invention will become apparent from the following detailed description when considered in conjunction with the accompanying drawings.
[0013] BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Embodiments of the present disclosure are described herein with reference to the drawings in which:
[0015] FIG. 1 is an architecture diagram of a secure messaging system in an embodiment of the invention.
[0016] FIG. 2 is an architecture diagram of a portion of the secure messaging system in an embodiment of the invention.
[0017] FIG. 3 is a flowchart illustrating the transformation and use of the message in an embodiment of the invention. FIG. 4 is a flowchart illustrating steps taken in a secure messaging system or method in an embodiment of the invention.
[0018] DETAILED DESCRIPTION
[0019] In the following detailed description, reference is made to the accompanying drawings, which form a part hereof. The illustrative embodiments described in the detailed description, drawings and claims are not meant to be limiting. Other embodiments can be utilized, and other changes can be made, without departing from the spirit or scope of the subject matter presented herein. Unless specified otherwise, the terns “comprising,” “comprise,” “including” and “include” used herein, and grammatical variants thereof, arc intended to represent “open” or “inclusive” language such that they include recited elements but also permit inclusion of additional, unrecited elements.
[0020] The method and system of secure message verification employing a security module to store message records of messages received from sender terminals and process verification requests from recipient terminals for forwarded message received. In a verification request, the appropriate message record can be identified by a hash of the forwarded message received by the recipient terminal or a message identifier appended to the forwarded message by the security module. The security module can verify the message by comparing data in the message record against data received from the recipient terminal.
[0021] A first embodiment of the invention is a method of secure message verification comprising the steps of: (a) receiving a message from a sender terminal at a message module through a network; (b) accessing the message from the message module with a security module; (c) creating a message record of the message with the security module; (d) routing the message record to an immutable database from the security module via the network; (e) sending a forwarded message to a recipient terminal via the network; (f) receiving and storing the forwarded message in the recipient terminal; (g) sending, from the recipient terminal, a verification request to the security module for the forwarded message; (h) upon receiving the verification request at the security module, retrieving from the immutable database the message record associated with the forwarded message; (i) for the message record associated with the forwarded message retrieved from the immutable database, determining at the security module at least one of a first comparison result and a second comparison result; and (j) delivering the first comparison result and / or the second comparison result from the security module to the recipient terminal via the network for display on the recipient terminal. The message includes message content and message metadata. The message metadata includes at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp. The message record includes either: (1) a first message hash and an encrypted message, or (2) the first message hash, the encrypted message, and a message identifier. The first message hash is created by hashing a first selection of the message using a hash function. The encrypted message is an encrypted string resulting from the encryption of an encrypted selection of the message employing encryption keys from a key server. The message identifier comprises at least one of: (1) an identifier selection of the first message hash; (2) a pseudo-random identifier of the message supplied by the security module; and (3) a non-random identifier of the message supplied by the security module. The forwarded message includes either: (i) the message received from the sender terminal; or (ii) an appended string including the message received from the sender terminal and the message identifier created by the security module for the message. The verification request includes at least one of: (i) either: a second message hash created by the recipient terminal from a second selection of the forwarded message using the hash function; or the message identifier received in the appended string of the forwarded message; and (ii) the message received from the sender terminal via the forwarded message. The message record is identified by the second message hash or the message identifier included in the verification request. The first comparison result is based on a first comparison of: (1 ) the first message hash of the message record stored in the message record; and (2) the second message hash included in the verification request. The second comparison result is based a second comparison of: (1) a decrypted version of the enciypted message stored in the message record; and (2) the message received from the sender terminal via the forwarded message.
[0022] A second embodiment of the invention is a system of secure message verification for a recipient terminal comprising: (a) a message module configured to receive a message from a sender terminal through a network, and (b) a security module. The security module is configured to: (i) access the message from the message module; (ii) create a message record of the message; (iii) route the message record to an immutable database from the security module via the network; (iv) instruct the message module to send a forwarded message to the recipient terminal via the network; (v) upon receiving the verification request at the security module, retrieve from the immutable database the message record associated with the forwarded message, wherein the message record is identified by the second message hash or the message identifier included in the verification request; (vi) for the message record associated with the forwarded message retrieved from the immutable database, determine at the security module at least one of a first comparison result based on a first comparison and a second comparison result based a second comparison; (vii) deliver the first comparison result and / or the second comparison result from the security module to the recipient terminal via the network for display on the recipient terminal. The message includes message content and message metadata. The message metadata includes at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp. The message record includes either: (a) a first message hash and an encrypted message; or (b) the first message hash, the encrypted message, and a message identifier. The first message hash is created by hashing a first selection of the message using a hash function. The encrypted message is an encrypted string resulting from the encryption of an encrypted selection of the message employing encryption keys from a key server. The message identifier comprises at least one of: (a) an identifier selection of the first message hash, (b) a pseudo-random identifier of the message supplied by the security module; and (c) a nonrandom identifier of the message supplied by the security module. The forwarded message includes cither: (a) the message received from the sender terminal; or (b) an appended string including the message received from the sender terminal and the message identifier created by the security module for the message. The recipient terminal is configured to create and send a verification request to the security module for the forwarded message. The verification request includes at least one of: (a) either a second message hash created by the recipient terminal from a second selection of the forwarded message using the hash function or, alternatively, the message identifier received in the appended string of the forwarded message; and (b) the message received from the sender terminal via the forwarded message. The first comparison result is based on a first comparison of: (a) the first message hash of the message record stored in the message record, and (b) the second message hash included in the verification request. The second comparison result is based a second comparison of: (a) a decrypted version of the encrypted message stored in the message record, and (b) the message received from the sender terminal via the forwarded message.
[0023] In an alternative embodiment of first and second embodiment of the invention, routing of the message record to the immutable database includes: sending the message record to a mutable database from the security module; queuing the message record in the mutable database; and delivering the message record to the immutable database from the mutable database. In an alternative embodiment of first and second embodiment of the invention: the message identifier is the first message hash; and the message record is identified in the verification request by the second message hash when retrieving the message record from the immutable database.
[0024] In an alternative embodiment of first and second embodiment of the invention: the message identifier is the pseudo-random identifier of the message supplied by the security module; and the message record is identified in the verification request by the pseudo-random identifier when retrieving the message record from the immutable database.
[0025] In an alternative embodiment of first and second embodiment of the invention, the encryption keys from the key server are asymmetrical encryption keys generated using an RSA or an ECC algorithm.
[0026] In an alternative embodiment of first and second embodiment of the invention, a warning signal is generated by the recipient terminal when the first comparison result is a first invalidity or the second comparison result is a second invalidity.
[0027] In an alternative embodiment of first and second embodiment of the invention: the sender terminal and the recipient terminal both include a message app and a verification app; and an authorization token is generated for both the sender terminal and the recipient terminal permitting direct or indirect access to the security module.
[0028] The method and system may require an authorization token generated by the verification app. The authorization token could be obtained by the user of the terminal by providing credentials, such as user ID and password. Two factor authentication could additionally be employed for added security. Upon successful verification, the user can be granted an authentication token that serves as a unique identifier and access pass. This token ensures that only authenticated users can interact with the system. The sender terminal and user terminal may download the message app and the verification app to their terminal (such as through the branded Google Play Store or Apple App Store). The message app and verification app can be integrated into a single app. In an alternative embodiment of first and second embodiment of the invention: an application server includes the message module, the security module, and the comparison module; and the application server is in data communication through the network with the key server, the immutable database, the sender terminal, and the recipient terminal.
[0029] In an alternative embodiment of first and second embodiment of the invention: an application server includes the message module; a verification server includes the security module and the mutable database; and all data communication between the verification server and the recipient terminal is routed through the application server.
[0030] In an alternative embodiment of first and second embodiment of the invention: the immutable database is a blockchain database; and the mutable database is a high-speed database.
[0031] FIG. 1 is an architecture diagram of a secure messaging system in an embodiment of the invention. The exemplified configuration of system 100 includes, but is not limited to, the following components: sender terminal 101, a recipient terminal 102, an application server 103, a verification server 104, a key server 105, and an immutable database 106. These elements within the system 100 can be interconnected by a network 107.
[0032] The network 107 can include a combination of a local area network (LAN), a wide area network (WAN), a land network, a wireless network, a data bus, telephone network, a point-to-point network, a satellite network, a token ring network, and / or a hub network.
[0033] In some embodiments of the invention the application server 103 and the verification server 104 are consolidated within into a single server. As used herein, a server can be a stand-alone server, a grouping of servers, a virtual server, or a cloud computing platform.
[0034] In some embodiments of the invention, the message app (101A and 102A) can be integrated together with the verification app (101B and 102B).
[0035] Sender terminal 101 includes a message app 101A and a verification app 101B. Similarly, recipient terminal 102 includes a message app 102 A and a verification app 102B. For simplicity in this specification, the messages are sent from the sender terminal 101 to the recipient terminal 102, but in actual practice of the invention, messages can be sent in both directions (such as in a text message exchange). The sender terminal 101 and the recipient terminal 102 also include processors, memory / storage, and a user display.
[0036] The message apps 101A and 102A are employed for viewing, editing, and sending messages. Example message apps include generic a short message / messaging service (SMS) applications and branded applications (such as those branded WhatsApp, WeChat, Messenger, and Viber). A message app includes basic interface service, message protocol service, and message queue service. A message app is responsible for receiving, distributing and responding to requests from the message client, assembling and parsing the content of the message according to the basic format of the message.
[0037] The sender terminal 101 and the recipient terminal 102 can be any type of computing device which is capable of connecting to and communicating messages over a network 108. For example, the sender terminal 101 and the recipient terminal 102 can be a handheld computing device, a mobile phone, a laptop computer, a workstation, and / or a network of computing devices.
[0038] The verification server 104 coordinates the message verification process. The verification server 104 links with an immutable database 106. The immutable database can be a decentralized blockchain network, that acts as a tamper-proof ledger for storing the content of message records. By distributing the data across multiple nodes in the network, it significantly reduces the risk of unauthorized access or modification. The immutable database 106 can also be cloud based service, such as the cloud storage database branded Amazon Web Service (AWS) Quantum Ledger.
[0039] The verification server 104 links with the key server 105. The key server includes a key generator 204 and can be a public infrastructure key server. The key server 105 can generates a public and private key pair for data encryption employed by the invention.
[0040] FIG. 2 is an architecture diagram of a portion of the secure messaging system in an embodiment of the invention. FIG. 2 illustrates a message module 201 within an application server 103, a security module 202 and mutable database within a verification server 104, a key generator 204 within a key server 105, and an immutable database connected by the network 107.
[0041] Tn alternative embodiments of the invention, the message module 201 and the security module 202 can be integrated into a single server.
[0042] The mutable database 203 can be a specialized high-performance database. A high- performance database is designed to efficiently handle and manage large volumes of data while providing rapid and reliable access to that data. The high-performance database is a critical component for applications that demand rapid data access, scalability, and reliability, such as e-commerce platforms, financial platforms, and large-scale enterprise applications. Not shown in FIG. 2, the mutable database 203 may be located in the application server, the verification server, or in another server.
[0043] FIG. 3 is a flowchart illustrating the transformation of the message in accordance with an embodiment of the present application using the message hash for verification.
[0044] At block 301 , the message (M) is composed at the sender terminal 101 using a message app 101A. As discussed in this specification, a message includes both the message content as well as the message metadata. The message metadata includes at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp.
[0045] At block 302, the message (M) is received by the application server 103 from the sender terminal 101.
[0046] At block 303, the message (M) is accessed by the verification server 104 from the application server 103. The verification server creates a message record (M-RECORD) that includes a first message hash (M-Hl), a message identifier (M-ID), and an encrypted message (M-EN). The message record is stored in the immutable database 106.
[0047] At block 304, the application server 103 potentially additionally receives the message identifier (M-TD) from the verification server 104. At block 305, the recipient terminal 102 receives form the application server 103 either just the message (M) or the message appended with its associated message identifier (e.g., M + M-TD), which is later called the “forwarded message” in this specification. The recipient terminal 102 creates a second message hash (M-H2) using the same hash function as the verification server 104 employed to create the first message hash (M-H2). Thus, M-Hl and M-H2 should be identical for the same message (M) received from the sender terminal 101.
[0048] At block 306, the verification server 104 compares cither: (i) the first message hash (M-Hl) retrieved from the immutable database 106 against the second message hash (M-H2) generated by the recipient terminal 102; or (ii) the message (M) against a decrypted version of the encrypted message (M-EN) retrieved from the immutable database 106. Tf the comparisons fail, then the message cannot be verified.
[0049] For block 306 comparisons, the first message hash (M-Hl) and the encrypted message (M-EN) arc taken from the message record (M-RECORD) associated with the message. The appropriate message record (M-RECORD) is located and accessed by employing either the second message hash (M-H2) or the message identifier (M-ID) that is available to the recipient terminal in block 305. E.g., the first message hash (M-H1 ) and the second message hash (M-H2) act as unique identifiers for the message record (M-RECORD).
[0050] At block 307, the recipient terminal 102 receives the comparison results. If the comparisons fail, then the message cannot be verified.
[0051] FIG. 4 details steps S401 to S414 that are performed by different components and modules of the system.
[0052] At S401, a message is sent from a sender terminal 101 to an application server 103. The message can be sent via plain text (such as by SMS) or via a message app. The message contains both message contents and message metadata. Message metadata includes at least one of the pieces of information related to the sender, recipient, message subject, and timestamp etc. At S402, the message is accessed by the verification server 104 from the application server 103.
[0053] At S403, the verification server 104 creates a message identifier for the message. The message identifier can be an identifier selection (e.g., all or a subset) of the first message hash, a pseudorandom identifier, or a non-random identifier. The message identifier is employed to track a message record discussed below between the verification server 104, the immutable database 106, and the recipient terminal 102.
[0054] At S404, the verification server 104 creates a first message hash. The first message hash is created employing a hash function, such as the SHA256 function, ft should be noted that other hashing algorithms may also be employed. This cryptographic hash serves as a digital fingerprint of the message. The inputs to the hashing function can a first selection (e.g., all or a subset) of the message.
[0055] At S405, the verification server 104 creates an encrypted message record employing data communication with a key server 105. This interaction includes use of a pair of asymmetrical encryption keys, comprising a public key and a private key, generated by the key server 105. The keys can be generated by employing an Rivest-Shamir-Adleman / Elliptic Curve Cryptography (RSA / ECC) algorithms and the like. The public key can used to encrypt data from associated with the message. The encrypted data can include varying selections of the message content (e.g., the text of the message read by the recipient) and the message metadata. The message metadata can include at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp.
[0056] At S406, this message record is stored in the mutable database 203 in a queue for the next step. The mutable database 203 can be a high-performance database.
[0057] At S407, once the message record is written to the mutable database 203, a job is created to copy the data to an immutable database 106 asynchronously.
[0058] The encryption process for portions of the record ensures that the message contents and message metadata of the message remain confidential and inaccessible to unauthorized entities during transmission and storage. Data that will be used to identify the message record (such as the message identifier or the first message hash) may not be encrypted. The message identifier can be a pseudo-random number. The hash, by its nature, does not disclose content of the message (other than identifying a matching hash of the content). Hence, the data used to identify the message record will be confidential even if the immutable database is publicly accessible.
[0059] At S408, the message identifier can be sent to the application server 103.
[0060] At S409 the application server 103 sends a forwarded message to the recipient terminal 102. The forwarded message includes either: (i) the message received from the sender terminal; or (ii) an appended string including the message received from the sender terminal and the message identifier created by the security module for the message.
[0061] At S410, the recipient terminal 102 sends a verification request to the verification server 104. The verification request includes a second message hash of the message received from the recipient terminal 102 or the message identifier of the message. This information is used to identify the message record associated with the message received from the recipient terminal 102. The verification request can also include the message itself.
[0062] In S411, the verification server retrieves the relevant message record from the immutable database 106. The relevant message record is identified by cither the message identifier or the first message hash under which the message record was originally stored in the immutable database 106.
[0063] At S412, the verification server 104 can decrypt the encrypted message employing data communication with a key server 105. This step is performed so that the contents of the message can be compared against the data included in the verification request. If only the message hash is required, the encrypted message need not be decrypted.
[0064] At S413, a comparison is made between the data received from the recipient terminal 102 and the data retrieved from the message record. A first comparison result can be based on a first comparison of: (1) the first message hash of the message record stored in the message record, and (2) the second message hash included in the verification request. A second comparison can be based on a second comparison of: (1) a decrypted version of the encrypted message stored in the message record; and (2) the message received from the sender terminal via the forwarded message.
[0065] In S414, the verification result (e.g., valid or invalid) is delivered by the verification server to the recipient terminal. This delivery can be performed through the application server.
[0066] While the application server 103 and the verification server 104 are discussed separately above, the two can be potentially consolidated into a single server. The application server 103 can also include a gateway for receiving and sending data communications to the sender terminal 101 and recipient terminal 102.
[0067] The verification process presented herein improves data integrity and user authenticity. This verification process ensures the integrity of the message and establishes trust in the communication between the sender and recipient. Furthermore, it confirms that the message content has remained unchanged during transit and storage, providing assurance that the message has not been tampered with or modified.
[0068] The immutable database 106 further provides a secure audit trail. Message records can be distributed across multiple nodes, making it difficult for malicious actors to tamper with or forge verification data, maintaining the integrity and transparency of the verification process.
[0069] The security module 202 can be integrated into an application server 103. The additional capabilities can be fully integrated or accessed via an Application Programming Interface (API) and / or a plug-in / add-on. Such software can be distributed as a Software Development Kit (SDK). Similarly, the verification app (101B and 102B) can also be integrated into existing message apps (101A and 102A) or provided as a plug-in / add-on. In this manner, the secure message verification method and system can be integrated into an email message application, a SMS message application, a text message application, chat message application, voice message application, P2P message application, P2M message application, M2M message application, or a M2P message application. While various aspects and embodiments have been disclosed herein, it will be apparent that various other modifications and adaptations of the invention will be apparent to the person skilled in the art after reading the foregoing disclosure without departing from the spirit and scope of the invention and it is intended that all such modifications and adaptations come within the scope of the appended claims. The various aspects and embodiments disclosed herein are for purposes of illustration and are not intended to be limiting, with the true scope and spirit of the invention being indicated by the appended claims.
Claims
CLAIMS1. A method of secure message verification comprising the steps of:(a) receiving a message from a sender terminal at a message module through a network,(i) wherein the message includes message content and message metadata; and(ii) wherein the message metadata includes at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp;(b) accessing the message from the message module with a security module;(c) creating a message record of the message with the security module,(i) wherein the message record includes either:(1 ) a first message hash and an encrypted message; or(2) a first message hash, an encrypted message, and a message identifier;(ii) wherein the first message hash is created by hashing a first selection of the message using a hash function;(iii) wherein the encrypted message is an encrypted string resulting from the encryption of an encrypted selection of the message employing encryption keys from a key server; and(iv) wherein the message identifier comprises at least one of:(1) an identifier selection of the first message hash,(2) a pseudo-random identifier of the message supplied by the security module; and(3) a non-random identifier of the message supplied by the security module;(d) routing the message record to an immutable database from the security module via the network;(e) sending a forwarded message to a recipient terminal via the network, wherein the forwarded message includes either:(i) the message received from the sender terminal; or(ii) an appended string including:(1) the message received from the sender terminal; and(2) the message identifier created by the security module for the message;(f) receiving and storing the forwarded message in the recipient terminal;(g) sending, from the recipient terminal, a verification request to the security module for the forwarded message, wherein the verification request includes at least one of:(i) either:(1 ) a second message hash created by the recipient terminal from a second selection of the forwarded message using the hash function; or(2) the message identifier received in the appended string of the forwarded message; and(ii) the message received from the sender terminal via the forwarded message;(h) upon receiving the verification request at the security module, retrieving from the immutable database the message record associated with the forwarded message, wherein the message record is identified by the second message hash or the message identifier included in the verification request;(i) for the message record associated with the forwarded message retrieved from the immutable database, determining at the security module at least one of:(i) a first comparison result based on a first comparison of:(1) the first message hash of the message record stored in the message record; and(2) the second message hash included in the verification request; and(ii) a second comparison result based a second comparison of:(1 ) a decrypted version of the encrypted message stored in the message record; and(2) the message received from the sender terminal via the forwarded message; and(j) delivering the first comparison result and / or the second comparison result from the security module to the recipient terminal via the network for display on the recipient terminal.
2. The method of claim 1 , wherein the step of routing the message record to the immutable database includes: sending the message record to a mutable database from the security module; queuing the message record in the mutable database; and delivering the message record to the immutable database from the mutable database.
3. The method of claim 1, wherein the message identifier is the first message hash; andwherein the message record is identified in the verification request by the second message hash when retrieving the message record from the immutable database.
4. The method of claim 1 , wherein the message identifier is the pseudo-random identifier of the message supplied by the security module; and wherein the message record is identified in the verification request by the pseudorandom identifier when retrieving the message record from the immutable database.
5. The method of claim 1, wherein the encryption keys from the key server are asymmetrical encryption keys generated using an RSA or an ECC algorithm.
6. The method of claim 1, wherein a warning signal is generated by the recipient terminal when the first comparison result is a first invalidity or the second comparison result is a second invalidity.
7. The method of claim 1, wherein the sender terminal and the recipient terminal both include a message app and a verification app; and wherein an authorization token is generated for both the sender terminal and the recipient terminal permitting direct or indirect access to the security module.
8. The method of claim 1, wherein an application server includes the message module, the security module, and the comparison module; and wherein the application server is in data communication through the network with the key server, the immutable database, the sender terminal, and the recipient terminal.
9. The method of claim 1, wherein an application server includes the message module; wherein a verification server includes the security module and the mutable database; andwherein all data communication between the verification server and the recipient terminal is routed through the application server.
10. The method of claim 1 , wherein the immutable database is a blockchain database; and wherein the mutable database is a high-speed database.
11. A system of secure message verification for a recipient terminal comprising:(a) a message module configured to receive a message from a sender terminal through a network,(i) wherein the message includes message content and message metadata; and(ii) wherein the message metadata includes at least one of a sender identifier, a recipient identifier, a message subject, and a timestamp;(b) a security module configured to:(i) access the message from the message module;(ii) create a message record of the message,(1) wherein the message record includes either:(a) a first message hash and an encrypted message; or(b) a first message hash, an encrypted message, and a message identifier;(2) wherein the first message hash is created by hashing a first selection of the message using a hash function;(3) wherein the encrypted message is an encrypted string resulting from the encryption of an encrypted selection of the message employing encryption keys from a key server; and(4) wherein the message identifier comprises at least one of:(a) an identifier selection of the first message hash;(b) a pseudo-random identifier of the message supplied by the security module; and(c) a non-random identifier of the message supplied by the security module;(iii) route the message record to an immutable database from the security module via the network;(iv) instruct the message module to send a forwarded message to the recipient terminal via the network,(1) wherein the forwarded message includes either:(a) the message received from the sender terminal; or(b) an appended string including:(i) the message received from the sender terminal; and(ii) the message identifier created by the security module for the message;(2) wherein the recipient terminal is configured to create and send a verification request to the security module for the forwarded message;(3) wherein the verification request includes at least one of:(a) either:(i) a second message hash created by the recipient terminal from a second selection of the forwarded message using the hash function; or(ii) the message identifier received in the appended string of the forwarded message; and(b) the message received from the sender terminal via the forwarded message;(v) upon receiving the verification request at the security module, retrieve from the immutable database the message record associated with the forwarded message, wherein the message record is identified by the second message hash or the message identifier included in the verification request;(vi) for the message record associated with the forwarded message retrieved from the immutable database, determine at the security module at least one of:(1 ) a first comparison result based on a first comparison of:(a) the first message hash of the message record stored in the message record; and(b) the second message hash included in the verification request; and(2) a second comparison result based a second comparison of:(a) a decrypted version of the encrypted message stored in the message record; and(b) the message received from the sender terminal via the forwarded message; and(vii) deliver the first comparison result and / or the second comparison result from the security module to the recipient terminal via the network for display on the recipient terminal.
12. The system of claim 11, wherein routing the message record to the immutable database includes: sending the message record to a mutable database from the security module; queuing the message record in the mutable database; and delivering the message record to the immutable database from the mutable database.
13. The system of claim 11 , wherein the message identifier is the first message hash, and wherein the message record is identified in the verification request by the second message hash when retrieving the message record from the immutable database.
14. The system of claim 11, wherein the message identifier is the pseudo-random identifier of the message supplied by the security module; and wherein the message record is identified in the verification request by the pseudorandom identifier when retrieving the message record from the immutable database.
15. The system of claim 11, wherein the encryption keys from the key server arc asymmetrical encryption keys generated using an RSA or an ECC algorithm.
16. The system of claim 11 , wherein a warning signal is generated by the recipient terminal when the first comparison result is a first invalidity or the second comparison result is a second invalidity.
17. The system of claim 11, wherein the sender terminal and the recipient terminal both include a message app and a verification app; and wherein an authorization token is generated for both the sender terminal and the recipient terminal permitting direct or indirect access to the security module.
18. The system of claim 11 , wherein an application server includes the message module, the security module, and the comparison module; and wherein the application server is in data communication through the network with the key server, the immutable database, the sender terminal, and the recipient terminal.
19. The system of claim 11, wherein an application server includes the message module; wherein a verification server includes the security module and the mutable database; and wherein all data communication between the verification server and the recipient terminal is routed through the application server.
20. The system of claim 11, wherein the immutable database is a blockchain database; and wherein the mutable database is a high-speed database.
Citation Information
Patent Citations
Information authentication method and system
US20190327094A1
Messaging systems and methods that employ a blockchain to ensure integrity of message delivery
US20210211397A1
Electronic messaging security and authentication
US20220255750A1