Replacement Contact Relay Against SIM Swap and Email Hijacking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems are vulnerable to SIM swap scams and email hijacking attacks, where attackers gain control over users' accounts by intercepting phone numbers or email addresses, enabling unauthorized password resets and transactions.
Innovation Solution
Replace the genuine user's phone number and email address with a trusted service-controlled Replacement Phone Number and Replacement Email Address, monitored by a remote server, which analyzes incoming messages for security risks and blocks or relays them accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the user's genuine phone number or email address is used for account authentication, then the ease of operation is improved, but the reliability is worsened due to vulnerability to SIM swap scams and email hijacking attacks
Solution Approach 1:
The patent introduces a trusted service as an intermediary between the user and the computerized service. The trusted service controls replacement contact information (phone number/email) that receives authentication messages, which are then securely relayed to the user through a different communication channel. This mediator prevents attackers from directly intercepting authentication messages while maintaining the user's ability to receive security codes.
Solution Approach 2:
The patent changes the communication dimension by receiving authentication messages on replacement contact information and delivering them through a different communication channel than the original authentication factor. For example, an SMS received on a replacement phone number is delivered to the user via a secure messaging channel within the trusted service's application, adding a dimensional layer of security separation.
2Reliability
If replacement contact information controlled by a trusted service is used instead of genuine user contact information, then the reliability is improved by preventing unauthorized access, but the device complexity is worsened
Solution Approach 1:
The trusted service automatically manages the replacement contact information and message relay process without requiring user intervention. The service self-configures the replacement phone number or email address, receives authentication messages automatically, and delivers them through the secure channel, reducing the operational complexity for the user despite the increased system complexity.
3Reliability
If the trusted service monitors and analyzes incoming messages continuously, then the reliability is improved by blocking malicious messages, but the use of energy is worsened
Solution Approach 1:
The trusted service performs preliminary analysis of incoming messages before they are delivered to the user. By pre-screening messages for malicious content and only delivering legitimate authentication messages through the secure channel, the system reduces the energy required for continuous monitoring while maintaining high reliability in blocking attacks.
Data Source
AI summary
Systems, and methods of protecting users against cyber-attacks that utilize SIM Swap or Email Hijacking. A method includes: (a) detecting that a user is requested to input his genuine email address into an email address field of an account profile page or an account settings page of a computerized service; (b) inserting, into that email address field of that page, a replacement email address that replaces a genuine email address of the genuine user at that computerized service; and later, (c) automatically monitoring and handling, continuously at a remote server or a remote service, incoming email messages that arrive to that replacement email address of that genuine user and that request the genuine user to perform an elevated-security operation or to reset his credentials for accessing that computerized service.
