Out-of-band Email Authentication via External Verification Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies for preventing phishing attacks, such as SPF, S/MIME, and DKIM, are vulnerable to spoofing and misrepresentations, and may not be widely implemented, making it difficult to authenticate the authenticity of emails, especially those that mimic legitimate messages.

Innovation Solution

An out-of-band authentication method that allows recipients to forward suspicious emails to the claimed source organization for verification using authentication data like outgoing message logs or keys, providing an external channel for validation that is not reliant on embedded message content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If in-band authentication technologies (SPF, S/MIME, DKIM) are used, then some protection against phishing attacks is provided, but the technologies are vulnerable to spoofing and misrepresentations in the email content itself

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidspoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an external authentication server as an intermediary that receives email copies through a dedicated channel separate from the email content itself. This mediator verifies authenticity by comparing received email data against stored outbound email records, providing a reliable authentication mechanism that is not vulnerable to spoofing within the email content.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If in-band authentication technologies are used, then authentication protection is provided, but support for associated frameworks and protocols is required in the recipient's e-mail client and transport system

Engineering Contradiction:
Improveauthentication protectionVSAvoidclient and transport system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication verification function from the email client and transport system, placing it in a dedicated authentication server. This allows recipients to forward suspicious emails to the authentication server for verification, eliminating the need for complex client-side and transport-side support for various authentication frameworks.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If in-band authentication technologies are used, then some authentication protection is provided, but these technologies are not widely implemented

Engineering Contradiction:
Improveauthentication protectionVSAvoidimplementation adoption
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a self-service authentication model where recipients can forward any suspicious email to the authentication server for verification. This simple user-initiated action eliminates the need for complex automated client-side authentication, making the system easier to adopt and more versatile across different email clients and platforms.

Inventive Principle:
Principle #25Self-service

4Object-affected harmful factors

If out-of-band authentication is implemented, then spoofing of the authentication mechanism becomes difficult, but an additional authentication channel and process are required

Engineering Contradiction:
Improvespoofing resistanceVSAvoidauthentication channel complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication server acts as an intermediary that receives email copies through a dedicated channel separate from the email content itself. This mediator verifies authenticity by comparing received email data against stored outbound email records, providing a reliable authentication mechanism that is not vulnerable to spoofing within the email content.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8966621B1Out-of-band authentication of e-mail messages
Publication Date: 2015.02.24 AMAZON TECH INC
  • US8966621B1 patent drawing
  • US8966621B1 patent drawing
  • US8966621B1 patent drawing

AI summary

Technologies are described herein for providing out-of-band authentication of an e-mail message. A recipient of an e-mail message purporting to be from an organization forwards the e-mail message or submits its content to that organization for authentication. The authenticity of the e-mail message is determined based on authentication data, such as outgoing message logs or authentication keys, maintained at the source of the e-mail message. Upon authenticating the e-mail message, the recipient is informed of the authenticity of the e-mail message.