Email Server Authentication Intermediary for Compromised Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When a user's email account is compromised, unauthorized access to associated user applications can occur, allowing hackers to obtain and change authentication information for other accounts, posing a significant security risk.

Innovation Solution

An email server requires additional authentication credentials from the user before allowing access to email messages containing authentication information for user applications, and an authentication server includes a secure indicator in email messages to alert the email server of potentially sensitive content, ensuring that only authenticated users can view such information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If email accounts are associated with user applications for managing authentication information, then convenience of managing authentication information is improved, but security risk when email account is compromised worsens

Engineering Contradiction:
Improveconvenience of managing authentication informationVSAvoidsecurity risk when email account is compromised
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the email server and user applications. When an email containing authentication information is sent, the authentication server intercepts it, verifies the user's identity through a separate authentication process, and then delivers the information. This intermediary layer ensures that even if the email account is compromised, unauthorized parties cannot access the authentication information without passing through the additional authentication barrier.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication information is sent via email for resetting passwords, then ease of password recovery is improved, but vulnerability to email account compromise worsens

Engineering Contradiction:
Improveease of password recoveryVSAvoidvulnerability to email account compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authentication action before delivering password recovery information. Instead of sending authentication information directly to the email account, the system first initiates an authentication process that requires the user to verify their identity through means other than the potentially compromised email account. Only after successful preliminary authentication is the password recovery information delivered, ensuring that even if the email account is compromised, the attacker cannot recover passwords without first passing the authentication hurdle.

Inventive Principle:
Principle #10Preliminary action

3Speed

If email server sends authentication information directly to user, then speed of authentication process is improved, but security against compromised email accounts worsens

Engineering Contradiction:
Improvespeed of authentication processVSAvoidsecurity against compromised email accounts
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The authentication server acts as a mediator that maintains speed while enhancing security. The intermediary automatically verifies user identity through pre-configured authentication methods and rapidly delivers authentication information upon verification. This automated intermediary process adds minimal time overhead while providing the necessary security layer to prevent unauthorized access even when email accounts are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8621581B2Protecting authentication information of user applications when access to a users email account is compromised
Publication Date: 2013.12.31 ORACLE INT CORP
  • US8621581B2 patent drawing
  • US8621581B2 patent drawing
  • US8621581B2 patent drawing

AI summary

An email server provided according to an aspect of the present invention protects authentication information of user applications when access user's email account is compromised. In an embodiment, when an email message directed to a user contains content which provides access to authentication information for accessing a user application implemented external to said email server, the email server requires authentication credentials from the user before providing access to the content. As a result, even if the user's email account is compromised, additional controls are provided to reduce the probability of compromise of access to user applications implemented external to the email server.