Challenge Response System Using Signed IDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional spam filtering techniques, including content-based filters and adaptive filters, are ineffective against disguised spam messages, and existing methods to prevent spam, such as computational puzzles and human interactive proofs, can be bypassed or exploited by spammers, leading to challenges in maintaining secure communication channels.

Innovation Solution

A system and method that utilizes private IDs and secure communication channels to verify the legitimacy of message senders, involving cryptographic signatures and tracking of challenges to prevent spammer interference, ensuring that only legitimate senders respond to challenges and that communication with third-party servers is secure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If computational puzzles and human interactive proofs are used to prevent spam, then spam prevention effectiveness is improved, but spammers can bypass or exploit these methods

Engineering Contradiction:
Improvespam prevention effectivenessVSAvoidspammer adaptation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by requiring senders to solve computational puzzles or HIPs before messages are delivered. This advance verification prevents spammers from sending bulk spam without incurring costs, while the tracking system monitors these preliminary actions to detect and prevent exploitation attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The tracking system implements feedback mechanisms by monitoring challenge-response interactions and adjusting spam prevention measures based on detected patterns. When spammers attempt to bypass or exploit puzzle systems, the tracking data enables dynamic response adjustments to maintain prevention effectiveness.

Inventive Principle:
Principle #23Feedback

2Reliability

If recipients require senders to solve puzzles, then disguised spammers can be caught, but legitimate senders may waste CPU cycles solving fraudulent challenges

Engineering Contradiction:
Improvespammer detection accuracyVSAvoidCPU cycle waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The sender attaches verification information to messages in advance, enabling recipients to verify legitimacy before issuing challenges. This preliminary authentication prevents fraudulent challenge issuance and protects senders from wasting CPU cycles on attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where senders provide authentication data that mediates between the sender and recipient trust relationship. This intermediary information allows recipients to distinguish legitimate senders from spammers without requiring CPU-intensive verification of fraudulent challenges.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7904517B2Challenge response systems
Publication Date: 2011.03.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7904517B2 patent drawing
  • US7904517B2 patent drawing
  • US7904517B2 patent drawing

AI summary

Disclosed are systems and methods that facilitate securing communication channels used in a challenge-response system to mitigate spammer intrusion or deception. The systems and methods make use of unique IDs that can be added to outbound messages originating from a sender, a recipient, and a third-party server. The IDs can be correlated according to the relevant parties. Thus, for example, a sender can add a signed ID to an outgoing message. A challenge sent back to the sender for that particular message can echo the same ID or a new ID derived from the original ID to allow a sender to verify that the challenge corresponds to an actual message. The IDs can include cookies as well to facilitate correlation of messages and to facilitate the retrieval of messages once a sender is determined to be legitimate.