Double Anti-Phish Security Token for Email Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of phishing attacks has led to user skepticism and frustration with electronic communications, resulting in legitimate communications being ignored due to the risk of malicious impersonation, necessitating a method to authenticate and verify the authenticity of electronic messages.

Innovation Solution

A two-part anti-phish token is embedded in electronic communications, where the first part is visible and the second part is hidden, with the second part validating the message by communicating with a validation server to display a validation or alert symbol based on the message's authenticity, enhancing user confidence and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security token is added to authenticate electronic communications, then the reliability of electronic communications is improved, but the device complexity increases

Engineering Contradiction:
Improveauthenticity verificationVSAvoidcommunication structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security token is divided into two distinct parts: a visible portion displayed to the user and an invisible portion embedded in the communication metadata. This segmentation allows the authentication mechanism to be integrated without significantly altering the overall communication structure, as each part serves a specific function independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary validation server that acts as a mediator between the communication sender and receiver. This server verifies the token's authenticity by checking the invisible portion against known credentials, thereby improving reliability without requiring direct complex interactions between communication parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a visible security indicator is displayed, then the ease of operation is improved, but the object-generated harmful factors increase due to potential phishing exploitation

Engineering Contradiction:
Improveuser verificationVSAvoidphishing risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The validation server performs preliminary verification of the invisible token portion before the visible indicator is displayed to the user. This advance validation ensures that only authentic communications receive visible security indicators, preventing phishing attempts from exploiting visible indicators without proper backend verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the visible security indicator is dynamically generated based on the validation result of the invisible token portion. The indicator provides real-time feedback to the user about the communication's authenticity, while the coupling between visible and invisible parts ensures that phishing attempts without valid tokens cannot generate legitimate indicators.

Inventive Principle:
Principle #23Feedback

3Productivity

If mass email campaigns are sent, then the productivity is improved, but the loss of information increases due to user skepticism and ignored legitimate messages

Engineering Contradiction:
Improvecommunication volumeVSAvoidmessage response rate
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The token is segmented into visible and invisible parts, allowing mass email campaigns to maintain their volume and efficiency while incorporating authentication. The visible portion provides immediate user confidence, reducing skepticism, while the invisible portion enables batch verification, preserving the productivity benefits of mass communications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The visible security indicator uses visual differentiation (such as color-coded symbols or icons) to immediately signal message authenticity to users. This visual cue cuts through user skepticism in mass campaigns, helping users quickly identify legitimate messages among numerous communications, thereby reducing ignored messages and improving response rates.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS11991172B2Double anti-phish, personalized, security token for use with electronic communications
Publication Date: 2024.05.21 BANK OF AMERICA CORP
  • US11991172B2 patent drawing
  • US11991172B2 patent drawing
  • US11991172B2 patent drawing

AI summary

A double anti-phish, personalized, security token for use with electronic communications is provided. The security token may be embedded in each electronic communication transmitted from an entity to a recipient. A first part of the token may be embedded in a body of the communication. A second part of the token may be embedded in a header of the communication. The second part of the security token may validate that the electronic communication is indeed from the entity. Upon validation, the second part may instruct the first part to display a validation symbol. Upon failure to validate, the second part may instruct the first part to display an alert symbol. The recipient receiving the electronic communication may use the first part of the validation symbol as a visual aid to determine a level of confidence of whether the electronic communication has been validated as being transmitted by the entity.