Personalized Anti-Phish Security Token Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of phishing communications has led to user skepticism and frustration with entering information or clicking links in legitimate electronic communications, resulting in missed responses due to the difficulty in distinguishing between genuine and malicious messages.

Innovation Solution

An anti-phish, personalized security token is injected into electronic communications, allowing users to select and register unique visual elements such as numeric codes, photographs, or animations, which are dynamically generated and linked to a non-fungible token (NFT), ensuring each recipient receives a distinct token, thereby enhancing communication authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If users enter information or click links in electronic communications, then communication efficiency improves, but security risk increases due to phishing threats

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidphishing risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication by injecting a unique security token into each electronic communication before transmission. This token is generated and embedded in advance, allowing recipients to verify authenticity before interacting with the communication content, thus enabling safe information entry and link clicking.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security token acts as an intermediary element between the communication content and the recipient's trust decision. Instead of directly trusting the communication based on sender identity alone, the token serves as a verifiable mediator that confirms the communication's legitimacy, bridging the gap between efficiency and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users are cautious about phishing communications, then security improves, but communication response rate decreases

Engineering Contradiction:
ImprovesecurityVSAvoidresponse rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables recipients to independently verify communication authenticity through the embedded security token without requiring external validation or complex security checks. Users can self-verify the token matches the expected format and source, maintaining security while reducing friction and improving response rates.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security token incorporates visual elements such as colored indicators, images, or animated graphics that provide immediate visual confirmation of authenticity. These visual cues make verification intuitive and engaging, reducing user frustration while maintaining high security standards.

Inventive Principle:
Principle #32Color changes

3Reliability

If a security token is injected into each electronic communication, then authentication reliability improves, but system complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security token system is designed to work across multiple communication channels (email, SMS, instant messaging) using a universal token format and verification mechanism. This multi-functional approach consolidates complexity into a single system that serves all communication types, rather than requiring separate authentication systems for each channel.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system generates digital copies of security tokens that can be embedded in various communication formats without requiring physical security elements. These digital token copies maintain authenticity verification capabilities while being easy to generate, transmit, and validate, reducing system complexity compared to physical security devices.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11991207B2Anti-phish, personalized, security token for use with electronic communications
Publication Date: 2024.05.21 BANK OF AMERICA CORP
  • US11991207B2 patent drawing
  • US11991207B2 patent drawing
  • US11991207B2 patent drawing

AI summary

Methods for securing an electronic communication is provided. Methods may include, in a registration process, creating and/or selecting an anti-phish, personalized, security token for a predetermined account. Methods may include, in the registration process, storing the token in a database. Methods may include, in an in-use process, generating an electronic communication at a channel. The database may be interposed along the channel. Methods may include, in the in-use process, forwarding the communication to a recipient. The recipient may be associated with the account. Methods may include, in the in-use process, intercepting the communication at the database. Methods may include, in the in-use process, selecting, from the database, the anti-phish, personalized, security token that is associated with the account. Methods may include, in the in-use process, injecting the selected token into the communication. Methods may include, in the in-use process, transmitting the communication with the token to the recipient.