Sender Identity Verification via Unique Web Code

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for preventing phishing attacks, such as monitoring services, browser plug-ins, and digital certificates, are ineffective in verifying the authenticity of websites and are often cumbersome for users, leading to continued threats from fraudulent messages and compromised security.

Innovation Solution

A method where the sender provides a unique identifying code in the message that links to a web document containing confirmatory information known to the recipient, allowing users to verify the legitimacy of the sender and website before providing private information, without requiring additional software or browser plug-ins.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If monitoring services and browser plug-ins are used to detect phishing sites, then phishing detection capability is improved, but device complexity and user burden increase

Engineering Contradiction:
Improvephishing detection capabilityVSAvoidsoftware installation requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables users to verify sender authenticity themselves by checking the identifying code against the document on the sender's website, eliminating the need for external monitoring services or browser plug-ins. The verification process is self-contained and requires no additional software installation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The verification mechanism is extracted from complex monitoring services and simplified to a basic code-checking process that can be performed directly by users in their browser without requiring additional software or plug-ins.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If digital certificates or card readers are used to verify website authenticity, then security reliability is improved, but ease of operation deteriorates due to installation requirements

Engineering Contradiction:
Improvewebsite authenticity verificationVSAvoidaccessibility on different computers
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system allows users to verify website authenticity using only the identifying code provided in the message, without requiring digital certificates or card readers. The verification is performed directly in the browser by comparing the code with the document on the sender's website, making it accessible on any computer.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of requiring users to install security software or hardware, the system uses a copied verification mechanism where the identifying code is checked against a document on the sender's website, creating a portable verification process that works across different devices.

Inventive Principle:
Principle #26Copying

3Object-generated harmful factors

If traditional email filters are used to block phishing messages, then spam reduction is improved, but false rejection of legitimate emails increases

Engineering Contradiction:
Improvephishing attack reductionVSAvoidlegitimate email delivery
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The system provides a feedback mechanism where users can verify the authenticity of senders by checking the identifying code against the document on the sender's website. This allows users to distinguish between phishing and legitimate emails based on the presence and validity of the verification document, rather than relying on filter rules that may cause false positives.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2137939B1Network security method
Publication Date: 2015.05.06 IP MARKETING
  • EP2137939B1 patent drawingFigure 1
  • EP2137939B1 patent drawingFigure 2
  • EP2137939B1 patent drawingFigure 3

AI summary

This invention provides a method for allowing the recipient of a message (2) to confirm the identity of the sender. In the message (1) the sender provides a web address that comprises an identifying code uniquely assigned to that message. The sender also providesa document (4) at that web address that comprises confirmatory information already known to the recipient.