Token-Injected Email Authentication Against Message Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for message authentication, such as employee training and image comparison, are costly and error-prone, allowing sophisticated spoofers to replicate messages undetected, posing network security threats.

Innovation Solution

A computing platform verifies message senders, generates and injects authentication tokens into messages, and validates these tokens at the recipient end to ensure message authenticity, using machine learning for context analysis and policy-based token insertion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If employee training and manual security verification methods are used, then network security awareness is improved, but cost and error rate increase

Engineering Contradiction:
Improvemessage authentication reliabilityVSAvoidsecurity verification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces manual security verification methods (mechanical human processes) with automated token-based authentication (electronic/digital system). The computing platform automatically generates, injects, and validates authentication tokens without requiring manual employee training or human judgment, thereby improving reliability while reducing system complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system performs self-service by automatically generating tokens for senders and validating them at the recipient end without requiring external security teams or manual verification. The system serves itself by embedding the authentication mechanism within the messaging platform, eliminating the need for separate manual verification processes.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If image comparison methods are used for message verification, then spoofing detection capability is improved, but error rate increases due to sophisticated spoofers

Engineering Contradiction:
Improvemessage authenticity detection precisionVSAvoidverification reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an authentication token as an intermediary element that mediates between the sender and recipient to verify message authenticity. Instead of directly comparing message images (which sophisticated spoofers can replicate), the token serves as a trusted intermediary that cannot be easily forged, thereby improving both detection precision and verification reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication token is generated and injected into the message in advance (preliminary action) before the message is transmitted. This preliminary authentication allows the recipient to verify the message's authenticity without needing to perform complex image comparisons, improving both precision and reliability by establishing trust before potential spoofing can occur.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If manual security verification methods are used, then security expertise can be applied, but productivity decreases due to manual processes

Engineering Contradiction:
Improvesecurity verification reliabilityVSAvoidmessage verification productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual security verification processes with automated computational methods. The computing platform automatically generates, injects, and validates authentication tokens using algorithms rather than human experts, thereby maintaining security reliability while dramatically improving productivity by eliminating manual intervention in each verification process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication system operates autonomously without requiring security experts to manually verify each message. The system self-services by automatically managing token generation and validation, which maintains security reliability while improving productivity through automation of the verification process.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If authentication tokens are injected into all outgoing messages, then message authentication coverage is improved, but device complexity increases

Engineering Contradiction:
Improvemessage authentication coverageVSAvoidtoken injection system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The computing platform is designed with universal functionality to handle token generation, injection, and validation across all message types and communication scenarios. This multi-functional design improves authentication coverage while managing complexity by consolidating authentication operations into a single versatile platform rather than requiring separate systems for different message types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12438863B2Email verification using injected tokens for message authentication
Publication Date: 2025.10.07 BANK OF AMERICA CORP
  • US12438863B2 patent drawing
  • US12438863B2 patent drawing
  • US12438863B2 patent drawing

AI summary

Aspects of the disclosure relate to message validation. A computing platform may receive a message, sent by a first device and directed to a second device, from an electronic messaging server. The computing platform may verify, based on message sender details, an identity of a sender of the message. The computing platform may generate, after verifying the identity of the sender of the message, an authentication token for the message, and may inject the authentication token into the message. The computing platform may route, to the electronic messaging server and after injecting the authentication token into the message, the message. The computing platform may receive a request to validate the message, which may include the authentication token and details of the message. The computing platform may identify, using the authentication token and the details of the message, that the message is authenticated.