Secure Email File Transfer via Trusted Provider Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for transmitting encrypted files often require recipients to set up usernames and passwords, making them vulnerable to phishing schemes and malicious emails, which are difficult to detect due to their resemblance to legitimate messages.
Innovation Solution
A system that uses a registered account with a trusted provider like HP, Apple, or Amazon, where the sender includes a web address and instructions for verification in the email, and the recipient receives an authentication code via SMS or voice call to securely download encrypted files, ensuring the authenticity of the sender and preventing malicious access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encrypted file transmission methods are used requiring username and password setup, then file security is improved, but vulnerability to phishing schemes increases
Solution Approach 1:
The patent introduces an intermediary authentication system that mediates between the sender and recipient. Instead of direct password-based authentication, the system uses a trusted provider as an intermediary to verify identities through authentication codes sent to registered phone numbers, eliminating the need for password exchange while maintaining security.
Solution Approach 2:
The patent implements preliminary registration and verification actions before file transmission. Both sender and recipient must pre-register with the trusted provider, establishing authenticated identities in advance. This preliminary setup creates a secure foundation that prevents phishing attacks during the actual file transfer process.
2Reliability
If authentication codes are sent via SMS or voice call to verify recipient identity, then phishing detection is improved, but system complexity increases
Solution Approach 1:
The system leverages existing self-service infrastructure (SMS and voice call services) that users already interact with regularly. By using these familiar, trusted communication channels for authentication, the system gains reliability without requiring users to learn or interact with complex new verification mechanisms.
Solution Approach 2:
The trusted provider acts as an intermediary that manages the complexity of authentication code generation and delivery. Rather than requiring the file transmission system to build its own complex authentication infrastructure, it delegates this function to a specialized intermediary service that handles phone number verification and code delivery.
3Reliability
If a trusted provider hosts the verification system, then sender authenticity verification is improved, but dependency on external providers increases
Solution Approach 1:
The trusted provider is designed with universal functionality that can serve multiple purposes: email verification, phone number authentication, code generation, and identity verification. This multi-functional approach allows the same infrastructure to support various authentication scenarios without requiring provider-specific customizations, enhancing both reliability and adaptability.
Data Source
AI summary
A system for and method of transmitting verifiable e-mail includes a message ID sent to a recipient of the e-mail. A system for and method of transmitting encrypted files using e-mail and other electronic communication channels includes a computer program for storing encrypted files supplied by a user, creating a link to the encrypted files to be e-mailed to a recipient, allowing download of the encrypted files when an authorization code is provided after the link is used to go to a system server, wherein the authorization code is sent to a telephone of the recipient, via text or aurally.


