Secure Communications Service for Phishing Message Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies for detecting and mitigating phishing attempts often quarantine or spam-filter suspicious emails, leaving recipients unable to verify their authenticity, which can lead to false positives and compromised security.

Innovation Solution

A secure communications service that intercepts suspicious electronic communications, stores them in a purgatory memory, and prompts the intended recipient, purported sender, or actual sender to verify the authenticity of the message through a backchannel verification process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If filters are set up to automatically detect phishing emails based on detectable characteristics, then the ability to identify suspicious communications is improved, but legitimate communications may be incorrectly quarantined or spam-filtered, causing disruptions and false positives

Engineering Contradiction:
Improvephishing detection accuracyVSAvoiduser access to legitimate communications
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary verification system that sits between the filter and the user's inbox. When a message is flagged as suspicious, it is quarantined and a verification request is sent through an alternative channel (SMS, email to different address, push notification) to confirm whether the message is legitimate. This mediator resolves the contradiction by allowing aggressive filtering while providing a recovery mechanism for false positives.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where users can report false positives or confirm phishing attempts. The verification process sends requests back to users through alternative channels to get feedback on the authenticity of quarantined messages. This feedback mechanism allows the system to maintain high filtering thresholds while correcting errors through user input.

Inventive Principle:
Principle #23Feedback

2Reliability

If suspicious emails are quarantined subject to administrator approval, then security is improved by blocking potential threats, but the intended recipient is left helpless to assess whether the email was not a phishing email, causing loss of time and productivity

Engineering Contradiction:
Improvesecurity against phishingVSAvoidtime for recipient verification
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables recipients to self-verify the authenticity of quarantined messages through alternative communication channels. Instead of requiring administrator intervention, the recipient receives a verification request via SMS, email to a different address, or push notification and can independently confirm whether the message is legitimate. This self-service approach eliminates the time loss associated with administrator approval while maintaining security.

Inventive Principle:
Principle #25Self-service

3Productivity

If suspicious emails are stored in a spam folder that a user is unlikely to see, then filtering efficiency is improved, but users may be harmed if they attempt to access the email from the spam folder, increasing harmful factors

Engineering Contradiction:
Improveemail filtering efficiencyVSAvoidrisk of phishing attack
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system takes preliminary anti-action by verifying the authenticity of suspicious messages before they are delivered to the user's inbox or spam folder. Through the backchannel verification process, the system proactively identifies and blocks phishing attempts before they can cause harm, rather than relying on users to recognize and avoid suspicious messages in their spam folder.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The verification system acts as an intermediary between the spam filter and the user. Instead of directly placing potentially harmful messages in the spam folder, the system intercepts suspicious messages, verifies them through alternative channels, and only delivers them to the spam folder after confirmation of legitimacy. This intermediary step prevents harmful messages from reaching users while maintaining efficient filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If aggressive filtering is applied to block all suspicious communications, then security is improved, but legitimate communications are disrupted, reducing ease of operation

Engineering Contradiction:
Improvesecurity against phishingVSAvoidcommunication flow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts its filtering behavior based on verification results. Messages that pass verification are delivered normally, while only unverified or failed verification messages are blocked. This dynamic approach allows aggressive filtering thresholds without permanently disrupting legitimate communications, as the system adapts its blocking decisions based on real-time verification outcomes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250175470A1Secure Communications Service for Intercepting Suspicious Messages and Performing Backchannel Verification Thereon
Publication Date: 2025.05.29 MATERIAL SECURITY INC
  • US20250175470A1 patent drawing
  • US20250175470A1 patent drawing
  • US20250175470A1 patent drawing

AI summary

A system and a method are disclosed for verifying a suspicious electronic communication. To this end, a secure communications service may detect an electronic communication comprising an identifier of a purported originator of the electronic communication and an identifier of an intended recipient, and determine that an attribute of the electronic communication corresponds to a suspicious attribute. Responsively, the service may intercept the electronic communication and storing the electronic communication in purgatory memory, so as to prevent the electronic communication from being populated in a private repository of the intended recipient, transmit a verification message, and receive a reply to the verification message that verifies the authenticity of the electronic communication. In response to receiving the reply, the service may release the electronic communication from the purgatory memory, so as to cause the electronic communication to be populated in the private repository of the intended recipient.