Email Pre-Signing for Impersonation Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email systems lack effective security measures to prevent impersonation attacks and ensure the authenticity of emails, leading to vulnerabilities in domain identity and potential threats such as account takeovers, data exfiltration, and financial theft.

Innovation Solution

The implementation of a method that involves pre-signing emails with allowed anticipated changes, generating digital signatures for both the original and modified messages, and embedding these signatures in the email to ensure authentication and integrity across organizational trust boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If email authentication protocols are implemented to prevent impersonation attacks, then domain identity security is improved, but the complexity of email sending infrastructure increases and adoption becomes slower

Engineering Contradiction:
Improvedomain identity securityVSAvoidemail sending infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-signing emails with anticipated changes before they are forwarded. The sending domain generates digital signatures for the original message and for anticipated modified versions that may be created by forwarding services. This advance preparation ensures that even if the message is altered during forwarding, the receiving domain can verify the signature against the pre-generated signatures, maintaining security without requiring complex real-time verification infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism by using a list of anticipated changes as a mediator between the sending and receiving domains. This list acts as a bridge that allows forwarding services to modify messages within predefined boundaries while maintaining authentication. The intermediary approach simplifies infrastructure by providing a clear contract for acceptable modifications rather than requiring complex trust verification between all participating domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If forwarding services are allowed to modify email messages, then email routing flexibility is improved, but message integrity and authentication are compromised

Engineering Contradiction:
Improveemail routing flexibilityVSAvoidmessage integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the sending domain pre-sign the message with anticipated changes before forwarding. The sending domain generates digital signatures for the original message and for anticipated modified versions that may be created by forwarding services. This advance preparation ensures that even if the message is altered during forwarding, the receiving domain can verify the signature against the pre-generated signatures, maintaining security without requiring complex real-time verification infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies dynamics by making the message signature flexible to accommodate predefined changes. Instead of using a static signature that would break upon any modification, the system dynamically generates multiple signatures corresponding to anticipated changes. The receiving domain can then match the actual message against these dynamic signatures, allowing forwarding services to modify messages within the predefined change list while maintaining authentication validity.

Inventive Principle:
Principle #15Dynamics

3Reliability

If strict authentication verification is performed at receiving domains, then security against fraudulent emails is improved, but legitimate forwarded emails may be rejected

Engineering Contradiction:
Improvesecurity against fraudulent emailsVSAvoidlegitimate email delivery rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the sending domain pre-sign the message with anticipated changes before forwarding. The sending domain generates digital signatures for the original message and for anticipated modified versions that may be created by forwarding services. This advance preparation ensures that even if the message is altered during forwarding, the receiving domain can verify the signature against the pre-generated signatures, maintaining security without requiring complex real-time verification infrastructure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by implementing selective verification at the receiving domain. Instead of rejecting all messages with modifications, the receiving domain only verifies messages against the list of anticipated changes provided by the sending domain. This partial verification approach allows legitimate forwarded emails that match the anticipated changes to pass through while maintaining security, avoiding the excessive action of rejecting all modified messages.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250175349A1Email authentication and data integrity validation
Publication Date: 2025.05.29 FRAUDMARC INC
  • US20250175349A1 patent drawing
  • US20250175349A1 patent drawing
  • US20250175349A1 patent drawing

AI summary

A method consistent with embodiments of the present disclosure may begin with retrieving a message to be electronically transmitted. The method may proceed with digitally securing the message by generating a first digital signature for the message. The first digital signature may be added to a list of digital signatures for inclusion in the message. A list of allowed anticipated changes may be retrieved. In accordance to embodiments disclosed herein, the message may be pre-signed for the allowed anticipated changes. Pre-signing the message may comprise editing the message with each allowed anticipated change, generating a subsequent digital signature for the message edited with the allowed anticipated change, and adding the subsequent digital signature to the list of digital signatures for inclusion in the electronic message. This process may be repeated for each allowed anticipated change in the allowed anticipated changes.