One-Time Passcode Delivery via Email Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Email-based two-factor authentication is vulnerable to security threats such as phishing attacks, account compromise, and interception, which can nullify the added security benefit, and email delivery can be delayed or disrupted, making it inconvenient for immediate access.

Innovation Solution

Implementing server-side vulnerability scans, email provider security policy compliance enforcement, email provider integration for real-time threat scanning, executable files for local security assessments, and secure links for additional authentication to ensure OTPs are sent to secure, verified email addresses and environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If email-based two-factor authentication is used, then convenience and cost-effectiveness are improved, but security vulnerabilities such as phishing attacks and account compromise increase

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary vulnerability scanning and security assessments of the email account and associated devices before delivering the OTP. This includes checking for malware, verifying email account security settings, and assessing device security posture in advance of code delivery, ensuring the environment is secure before the authentication code is made available

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security assessment layer between the email service and the OTP delivery. This intermediary system evaluates the security of the email account and user environment, acting as a mediator that only permits OTP delivery when security thresholds are met, thereby protecting against phishing and account compromise while maintaining email-based authentication convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If email-based two-factor authentication is used, then no additional hardware or software tokens are required, but email delivery delays or disruptions can occur

Engineering Contradiction:
Improveimplementation simplicityVSAvoiddelivery delay
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The system continuously monitors email delivery status and performs real-time security assessments during the authentication process. If delays or disruptions are detected, the system can initiate alternative authentication methods or notify users of potential issues, ensuring continuous authentication capability without relying solely on email delivery timing

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If vulnerability scanning and security assessments are performed, then security is improved, but system complexity and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security assessment system is segmented into multiple independent components: email account vulnerability scanning, device malware detection, security settings verification, and real-time threat monitoring. Each component operates independently and can be selectively activated based on risk levels, reducing overall system complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial security assessments based on risk profiles and contextual factors. For low-risk authentication attempts, only essential security checks are performed, while high-risk attempts trigger comprehensive scans. This selective approach maintains security reliability while avoiding unnecessary complexity and processing time for routine authentications

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250317436A1Enhanced security for one time passcode delivery via email
Publication Date: 2025.10.09 WELLS FARGO BANK NA
  • US20250317436A1 patent drawing
  • US20250317436A1 patent drawing
  • US20250317436A1 patent drawing

AI summary

Disclosed are methods, systems, computing devices, and machine-readable mediums for securing the delivery of OTPs via email. The disclosed methods utilize one or more of a combination of server-side vulnerability scans; security policy compliance enforcement; email provider integration to allow for real-time threat scanning; and/or utilizing executable files or secure links for additional authentication and OTP retrieval. This system ensures that OTPs are only sent to secure, verified email addresses and that the recipient's environment meets the necessary security standards.