Anti-Smishing Server Verification Code Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively protect users from spoofed SMS messages and other malicious communications that may request sensitive information, as they often require a pre-existing relationship for verification and lack robust authentication mechanisms.

Innovation Solution

An anti-phishing system that includes an anti-smishing server for registration and verification of entities, which allocates a unique security code for trusted entities, and checks included URLs and phone numbers against a database, allowing clients to verify messages by matching these codes and addresses, optionally alerting users to unverified messages and providing encryption for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a pre-existing relationship is required for message verification (as in US 2007/028105), then the verification system can use pre-agreed passwords for authentication, but the system cannot protect users from spoofed messages from entities with which they have no prior relationship

Engineering Contradiction:
Improvemessage authentication reliabilityVSAvoidprotection coverage for unknown entities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by having entities register their identifiers (phone numbers, URLs, email addresses) with the verification server before sending messages. The server pre-generates and stores verification codes for these registered entities. When a message is received, the system can immediately verify it against the pre-stored codes, enabling both reliable authentication and protection against spoofing from unknown entities without requiring pre-existing relationships between users.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive verification of all message elements is performed, then the security against phishing is maximized, but the complexity of the verification system increases significantly

Engineering Contradiction:
Improvephishing protection effectivenessVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex verification logic from the client devices and concentrates it in a centralized verification server. The server handles all complex operations including generating verification codes, storing registered entity data, comparing message elements against registered data, and determining verification results. Client devices only need to send simple verification requests and display results, dramatically reducing device complexity while maintaining comprehensive security verification.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If verification codes are transmitted with every message, then message authenticity can be verified, but the message length and data transmission volume increase

Engineering Contradiction:
Improvemessage verification capabilityVSAvoidmessage data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent makes the verification code universal by having the verification server store and compare multiple types of entity identifiers (phone numbers, URLs, email addresses) against various message elements (sender address, embedded URLs, phone numbers in message body). A single verification code can verify multiple different types of information within a message, providing comprehensive authentication without requiring separate verification mechanisms for each message element, thus minimizing additional data transmission.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2204030B1Transmission of messages
Publication Date: 2011.08.03 BRITISH TELECOM PLC
  • EP2204030B1 patent drawingFigure 1~2
  • EP2204030B1 patent drawingFigure 3~5

AI summary

First, a sending station (7) transmits to a registration station (6) a registration request including a telecommunications address such as a URL or telephone number for later use; the registration station (6) allocates a security code to the address, stores a database entry containing the address and security code and sends the security code to the sending station (7). When the sending station (7) wishes to send a message that includes the telecommunications address, it also includes the security code. A station (2) receiving the message sends a verification request containing the telecommunications address and the security code to a verification station (6) which determines whether there is a database entry that matches the telecommunication address and security code and if so, sends a clearance notification to the receiving station (2). The receiving station may prohibit, or at least warn against, communication with the address until such time at clearance is received.