SMS Spoofing Protection via User-Specific System Number

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current text messaging systems lack effective security measures to prevent spoofing, allowing unauthorized users to send messages that appear to originate from a different number, compromising communication security.

Innovation Solution

Implementing a user-specific system number that is difficult for attackers to guess, where users send messages to a designated system number for authentication, and if unauthorized, a notification is sent to switch to a new system number, preventing spoofing and securing communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SMS messaging is used with standard phone numbers, then ease of operation is maintained, but security against spoofing deteriorates

Engineering Contradiction:
Improvemessage authenticationVSAvoiduser complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication system between the user and the messaging platform. A unique authentication code is generated and sent to the user's registered email address, serving as a mediator to verify the user's identity without exposing the actual phone number. This intermediary mechanism ensures secure authentication while maintaining ease of use, as users simply need to enter the code received via email rather than managing complex security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of the user's identity through an authentication code that is sent to their email address. Instead of directly using the phone number for authentication, the system generates a temporary authentication credential (the code) that serves as a copy or representation of the user's identity. This copying mechanism allows for secure verification without exposing the actual identifying information, thus preventing spoofing while maintaining operational simplicity.

Inventive Principle:
Principle #26Copying

2Ease of operation

If user phone numbers are exposed in message headers, then message routing functionality is enabled, but vulnerability to spoofing increases

Engineering Contradiction:
Improvemessage routingVSAvoidspoofing attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication code that mediates between the user's identity and the message routing system. The authentication code, sent to the user's registered email, serves as a intermediary credential that verifies the user's identity without exposing their phone number in message headers. This intermediary mechanism enables secure message routing while preventing spoofing attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the sensitive phone number information from the message header and replaces it with an authentication code. By taking out the vulnerable element (the exposed phone number) and substituting it with a secure alternative (the authentication code sent to email), the system maintains message routing functionality while eliminating the vulnerability to spoofing attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9998919B1SMS spoofing protection
Publication Date: 2018.06.12 GOOGLE LLC
  • US9998919B1 patent drawing
  • US9998919B1 patent drawing
  • US9998919B1 patent drawing

AI summary

A method for establishing credentials for securing text message communications. The method includes receiving, at a text messaging hub executing at a server device, a text message from a user, the text message being directed to a service number and including (1) a user number and (2) a request to establish a secure credential for communicating with a text messaging application. The method also includes transmitting, by the text messaging hub executing at the server device, an initiation message to the user, the initiation message includes a user-specific system number to which the user is to direct future text messages.