Email Authentication via Embedded Message Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Internet-based identity theft, particularly through phishing and spoofing, poses a significant threat to consumers and businesses, as existing technologies lack effective measures to authenticate the authenticity of emails and protect against fraudulent activities.

Innovation Solution

Embedding a message code in emails that can be verified by recipients, either message-specific or recipient-specific, to authenticate the email's authenticity, which can be generated and stored for each message or reused for multiple messages, and can be implemented using a system involving application and web servers for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If no authentication mechanism is implemented in emails, then emails can be sent freely and easily, but recipients cannot verify authenticity and are vulnerable to phishing and spoofing

Engineering Contradiction:
Improveemail authenticity verificationVSAvoidemail system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by embedding authentication codes (watermarks) in emails before they are sent. The sender's system pre-generates and inserts unique message codes or recipient-specific watermarks into outgoing emails, storing them in a database for later verification. This advance preparation enables recipients to authenticate emails without adding complexity to the receiving end, resolving the contradiction between reliability and device complexity.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If message-specific codes are generated for each email, then authentication precision is improved, but the system requires more database storage and processing overhead

Engineering Contradiction:
Improvemessage authentication precisionVSAvoiddatabase storage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies local quality by offering two authentication approaches: message-specific codes for high-security requirements and recipient-specific watermarks for lower-security scenarios. Message-specific codes provide unique authentication for each email (higher precision), while recipient-specific watermarks reuse the same code across multiple emails to a particular recipient (lower storage requirements). This localized quality adjustment allows systems to balance authentication precision against database storage based on specific security needs.

Inventive Principle:
Principle #3Local quality

3Quantity of substance

If recipient-specific watermarks are used, then database storage is reduced, but authentication cannot verify individual message authenticity

Engineering Contradiction:
Improvedatabase storage efficiencyVSAvoidmessage-level authentication capability
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent applies dynamics by making the authentication system flexible and adaptable to different security requirements. The system can dynamically select between message-specific codes and recipient-specific watermarks based on the security needs of each communication scenario. This dynamic approach allows organizations to optimize the balance between database storage efficiency and authentication precision according to their specific use cases, such as using watermarks for routine communications and message-specific codes for sensitive transactions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7584255B1Method and apparatus for enabling authentication of e-mail messages
Publication Date: 2009.09.01 BANK OF AMERICA CORP
  • US7584255B1 patent drawing
  • US7584255B1 patent drawing
  • US7584255B1 patent drawing

AI summary

Method and apparatus for enabling authentication of e-mail messages. A message code is embedded in an e-mail, where the message code can be used by the recipient to verify the authenticity of the e-mail. In some embodiments, this code can be created for a particular e-mail message; in other embodiments, the code is created as a watermark for use in all e-mail to a specific recipient. The message code is associated with both the e-mail message and the recipient. In the case of a message-specific code, a recipient can verify the e-mail message by inputting the code via a Web server to be looked up in the database. The invention can be implemented in a system including a server which creates e-mail messages and injects message codes and a database for storing codes and recipient e-mail addresses.