Dynamic Email Whitelist Distribution for Spoofing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional email authentication systems that require preliminary registration of transmission source domains and IP addresses are limited in scope and cannot keep up with changes, and are vulnerable to fraudulent registrations by malicious third parties, leading to challenges in preventing email spoofing.

Innovation Solution

An information processing device that extracts transmission information from emails, determines the appropriateness of the transmission source, and distributes whitelisted sources to mail servers, allowing for swift and extensive collection of legitimate email transmission sources and preventing fraudulent activities like email spoofing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If transmission source domain and IP address combinations are registered in advance in an authentication server, then email authentication can be performed, but the scope of authentication is limited and cannot keep up with changes in transmission sources

Engineering Contradiction:
Improveauthentication accuracyVSAvoidscope of authentication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from a static authentication system with pre-registered combinations to a dynamic system that collects transmission source information from multiple mail servers in real-time. The authentication server dynamically updates transmission source information based on actual email transmissions, allowing the system to adapt to changes in transmission domains and IP addresses without requiring manual re-registration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system enables mail servers to automatically contribute transmission source information to the authentication server through self-service mechanisms. Each mail server autonomously transmits transmission source information about received emails to the authentication server, which then distributes updated information to all participating mail servers, eliminating the need for manual registration and maintenance.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If transmission source information is collected from multiple mail servers, then the scope of authentication is expanded, but the system complexity increases

Engineering Contradiction:
Improvescope of authenticationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication functions across multiple mail servers by introducing a central authentication server that collects, consolidates, and distributes transmission source information. This centralization allows individual mail servers to maintain relatively simple configurations while benefiting from the collective knowledge of all participating servers, expanding authentication scope without proportionally increasing complexity at each node.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server acts as an intermediary between multiple mail servers, receiving transmission source information from various mail servers and distributing authenticated information back to them. This intermediary approach simplifies the system architecture by providing a centralized coordination point, avoiding the need for complex peer-to-peer communication and conflict resolution mechanisms between mail servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a malicious third party registers transmission source information in the authentication server, then fraudulent emails can be authenticated, but legitimate security measures are compromised

Engineering Contradiction:
Improveease of registrationVSAvoidsecurity against spoofing
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements preliminary anti-action by having multiple mail servers contribute transmission source information before a single source can be exploited. The authentication server collects transmission source information from multiple independent mail servers and requires consistent validation across these sources before authenticating a transmission source, making it difficult for malicious third parties to register fraudulent information without detection.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The authentication server implements feedback mechanisms by continuously monitoring transmission patterns across multiple mail servers and adjusting authentication decisions based on this feedback. When transmission source information is received from multiple independent mail servers, the system validates consistency and detects anomalies, providing feedback that prevents malicious registrations while maintaining ease of operation for legitimate email transmission.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11785026B2Information processing device, information processing method and information processing program
Publication Date: 2023.10.10 DIGITAL ARTS
  • US11785026B2 patent drawing
  • US11785026B2 patent drawing
  • US11785026B2 patent drawing

AI summary

An information processing device 10 comprises a data reception unit 13 that accepts transmission information of an email received by each of a plurality of mail servers 12, the transmission information being extracted from the emails; a transmission information determination unit 14 that determines whether the transmission source of the email is appropriate based on the transmission information; and a whitelist distribution unit 16 that distributes the transmission source determined to be appropriate to each of the plurality of mail servers.