Replacement Contact Relay Against SIM Swap and Email Hijacking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are vulnerable to SIM swap scams and email hijacking attacks, where attackers gain control over users' accounts by intercepting phone numbers or email addresses, enabling unauthorized password resets and transactions.

Innovation Solution

Replace the genuine user's phone number and email address with a trusted service-controlled Replacement Phone Number and Replacement Email Address, monitored by a remote server, which analyzes incoming messages for security risks and blocks or relays them accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the user's genuine phone number or email address is used for account authentication, then the ease of operation is improved, but the reliability is worsened due to vulnerability to SIM swap scams and email hijacking attacks

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted service as an intermediary between the user and the computerized service. The trusted service controls replacement contact information (phone number/email) that receives authentication messages, which are then securely relayed to the user through a different communication channel. This mediator prevents attackers from directly intercepting authentication messages while maintaining the user's ability to receive security codes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the communication dimension by receiving authentication messages on replacement contact information and delivering them through a different communication channel than the original authentication factor. For example, an SMS received on a replacement phone number is delivered to the user via a secure messaging channel within the trusted service's application, adding a dimensional layer of security separation.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If replacement contact information controlled by a trusted service is used instead of genuine user contact information, then the reliability is improved by preventing unauthorized access, but the device complexity is worsened

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted service automatically manages the replacement contact information and message relay process without requiring user intervention. The service self-configures the replacement phone number or email address, receives authentication messages automatically, and delivers them through the secure channel, reducing the operational complexity for the user despite the increased system complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If the trusted service monitors and analyzes incoming messages continuously, then the reliability is improved by blocking malicious messages, but the use of energy is worsened

Engineering Contradiction:
ImprovereliabilityVSAvoiduse of energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The trusted service performs preliminary analysis of incoming messages before they are delivered to the user. By pre-screening messages for malicious content and only delivering legitimate authentication messages through the secure channel, the system reduces the energy required for continuous monitoring while maintaining high reliability in blocking attacks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12407723B2System, device, and method of protecting users and online accounts against attacks that utilize SIM swap scams
Publication Date: 2025.09.02 IRONVEST INC
  • US12407723B2 patent drawing

AI summary

Systems, and methods of protecting users against cyber-attacks that utilize SIM Swap or Email Hijacking. A method includes: (a) detecting that a user is requested to input his genuine email address into an email address field of an account profile page or an account settings page of a computerized service; (b) inserting, into that email address field of that page, a replacement email address that replaces a genuine email address of the genuine user at that computerized service; and later, (c) automatically monitoring and handling, continuously at a remote server or a remote service, incoming email messages that arrive to that replacement email address of that genuine user and that request the genuine user to perform an elevated-security operation or to reset his credentials for accessing that computerized service.