Source Confirmation Data for Phishing Message Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic messaging and anti-phishing systems are ineffective in distinguishing authentic from malicious messages, leading to significant financial losses due to phishing attacks, as users often cannot verify the authenticity of electronic communications.

Innovation Solution

The generation and multi-directional transmission of source confirmation data, recorded in an activity log, is used to verify the legitimacy of electronic messages by matching confirmation data within the message with previously logged data, thereby identifying potentially malicious communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional electronic messaging systems are used, then communication simplicity is maintained, but security and authenticity verification capability deteriorates

Engineering Contradiction:
Improvemessage authenticity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system generates and records confirmation data in advance before the actual message is sent. This preliminary action creates a reference trail that enables later verification of message authenticity without adding complexity to the message transmission process itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Confirmation data acts as an intermediary element between the messaging system and the verification process. This separate data structure mediates the authenticity verification by providing independently generated reference information that can be compared against received messages.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If no confirmation mechanism is implemented, then system operation simplicity is maintained, but vulnerability to phishing attacks increases

Engineering Contradiction:
Improvephishing attack vulnerabilityVSAvoidverification system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The verification system is segmented into distinct components: confirmation data generation, confirmation data recording in activity logs, and confirmation data verification. This segmentation allows each component to perform its function independently, reducing overall system complexity while providing comprehensive phishing protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a copy of essential message attributes (subject, from address, timestamp) along with independently generated confirmation data. This copy serves as a reference pattern that can be compared against received messages to detect phishing attempts without requiring complex real-time analysis.

Inventive Principle:
Principle #26Copying

3Reliability

If confirmation data is generated and transmitted multi-directionally, then message authentication capability is improved, but data transmission complexity increases

Engineering Contradiction:
Improvesource authenticationVSAvoiddata transmission structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The confirmation data structure is designed to be universal and multi-functional. The same confirmation data format is used across different communication channels and verification methods (email verification, website verification, customer service verification), simplifying the transmission structure by avoiding channel-specific formats.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback loops where confirmation data is generated, transmitted to multiple destinations (activity logs, message recipients, verification systems), and then used to verify message authenticity. This feedback mechanism ensures source authentication while maintaining a manageable data transmission structure through standardized processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10652276B1System and method for distinguishing authentic and malicious electronic messages
Publication Date: 2020.05.12 INTUIT INC
  • US10652276B1 patent drawing
  • US10652276B1 patent drawing
  • US10652276B1 patent drawing

AI summary

Anti-phishing computing systems and methods. A first computer that hosts an online software application with which an end user or customer has an account generates an electronic message and independent confirmation data and transmits electronic message data and the confirmation data to a second computer, which updates an activity log for the end user's account such that the confirmation data is associated with the electronic message data in the activity log. The confirmation data may be a randomly generated number and incorporate an identifier of the online software application. The electronic message including the confirmation data is transmitted to the end user computing device such that using the activity log and multiple confirmation data transmissions to different computing systems can be used to confirm that a source of the electronic message was the online software application and that the electronic message is not a fraudulent phishing electronic message.