Out-of-band Email Authentication via External Verification Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies for preventing phishing attacks, such as SPF, S/MIME, and DKIM, are vulnerable to spoofing and misrepresentations, and may not be widely implemented, making it difficult to authenticate the authenticity of emails, especially those that mimic legitimate messages.
Innovation Solution
An out-of-band authentication method that allows recipients to forward suspicious emails to the claimed source organization for verification using authentication data like outgoing message logs or keys, providing an external channel for validation that is not reliant on embedded message content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If in-band authentication technologies (SPF, S/MIME, DKIM) are used, then some protection against phishing attacks is provided, but the technologies are vulnerable to spoofing and misrepresentations in the email content itself
Solution Approach 1:
The patent introduces an external authentication server as an intermediary that receives email copies through a dedicated channel separate from the email content itself. This mediator verifies authenticity by comparing received email data against stored outbound email records, providing a reliable authentication mechanism that is not vulnerable to spoofing within the email content.
2Reliability
If in-band authentication technologies are used, then authentication protection is provided, but support for associated frameworks and protocols is required in the recipient's e-mail client and transport system
Solution Approach 1:
The patent extracts the authentication verification function from the email client and transport system, placing it in a dedicated authentication server. This allows recipients to forward suspicious emails to the authentication server for verification, eliminating the need for complex client-side and transport-side support for various authentication frameworks.
3Reliability
If in-band authentication technologies are used, then some authentication protection is provided, but these technologies are not widely implemented
Solution Approach 1:
The patent implements a self-service authentication model where recipients can forward any suspicious email to the authentication server for verification. This simple user-initiated action eliminates the need for complex automated client-side authentication, making the system easier to adopt and more versatile across different email clients and platforms.
4Object-affected harmful factors
If out-of-band authentication is implemented, then spoofing of the authentication mechanism becomes difficult, but an additional authentication channel and process are required
Solution Approach 1:
The authentication server acts as an intermediary that receives email copies through a dedicated channel separate from the email content itself. This mediator verifies authenticity by comparing received email data against stored outbound email records, providing a reliable authentication mechanism that is not vulnerable to spoofing within the email content.
Data Source
AI summary
Technologies are described herein for providing out-of-band authentication of an e-mail message. A recipient of an e-mail message purporting to be from an organization forwards the e-mail message or submits its content to that organization for authentication. The authenticity of the e-mail message is determined based on authentication data, such as outgoing message logs or authentication keys, maintained at the source of the e-mail message. Upon authenticating the e-mail message, the recipient is informed of the authenticity of the e-mail message.


