Anti-Smishing Server Verification Code Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to effectively protect users from spoofed SMS messages and other malicious communications that may request sensitive information, as they often require a pre-existing relationship for verification and lack robust authentication mechanisms.
Innovation Solution
An anti-phishing system that includes an anti-smishing server for registration and verification of entities, which allocates a unique security code for trusted entities, and checks included URLs and phone numbers against a database, allowing clients to verify messages by matching these codes and addresses, optionally alerting users to unverified messages and providing encryption for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a pre-existing relationship is required for message verification (as in US 2007/028105), then the verification system can use pre-agreed passwords for authentication, but the system cannot protect users from spoofed messages from entities with which they have no prior relationship
Solution Approach 1:
The patent applies preliminary action by having entities register their identifiers (phone numbers, URLs, email addresses) with the verification server before sending messages. The server pre-generates and stores verification codes for these registered entities. When a message is received, the system can immediately verify it against the pre-stored codes, enabling both reliable authentication and protection against spoofing from unknown entities without requiring pre-existing relationships between users.
2Reliability
If comprehensive verification of all message elements is performed, then the security against phishing is maximized, but the complexity of the verification system increases significantly
Solution Approach 1:
The patent extracts the complex verification logic from the client devices and concentrates it in a centralized verification server. The server handles all complex operations including generating verification codes, storing registered entity data, comparing message elements against registered data, and determining verification results. Client devices only need to send simple verification requests and display results, dramatically reducing device complexity while maintaining comprehensive security verification.
3Reliability
If verification codes are transmitted with every message, then message authenticity can be verified, but the message length and data transmission volume increase
Solution Approach 1:
The patent makes the verification code universal by having the verification server store and compare multiple types of entity identifiers (phone numbers, URLs, email addresses) against various message elements (sender address, embedded URLs, phone numbers in message body). A single verification code can verify multiple different types of information within a message, providing comprehensive authentication without requiring separate verification mechanisms for each message element, thus minimizing additional data transmission.
Data Source
Figure 1~2
Figure 3~5
AI summary
First, a sending station (7) transmits to a registration station (6) a registration request including a telecommunications address such as a URL or telephone number for later use; the registration station (6) allocates a security code to the address, stores a database entry containing the address and security code and sends the security code to the sending station (7). When the sending station (7) wishes to send a message that includes the telecommunications address, it also includes the security code. A station (2) receiving the message sends a verification request containing the telecommunications address and the security code to a verification station (6) which determines whether there is a database entry that matches the telecommunication address and security code and if so, sends a clearance notification to the receiving station (2). The receiving station may prohibit, or at least warn against, communication with the address until such time at clearance is received.