Token-Based Phishing Detection via Email Address Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information security technologies lack a reliable and efficient solution for detecting phishing threats, particularly in email communications, where spoofed or impersonated trusted email addresses can be used to launch social engineering attacks.
Innovation Solution
A system and method utilizing a token-email address mapping table, where each email address is associated with a unique token, enabling anonymous communication by using tokens instead of email addresses, and employing a token authentication engine to verify the authenticity of email messages and detect phishing threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If email addresses are used directly for communication, then communication efficiency is improved, but security against phishing attacks deteriorates
Solution Approach 1:
The patent introduces tokens as intermediary elements that mediate between email addresses and communication. Instead of directly exposing email addresses, the system uses tokens as a middle layer that can be verified for authenticity. The token acts as a mediator that protects the underlying email address from being directly accessed or spoofed by phishing attackers, while still enabling efficient communication through the token verification mechanism.
Solution Approach 2:
The patent creates a copy mechanism where tokens serve as verified representations of email addresses. Rather than using the actual email address directly in communications, the system generates token copies that represent authenticated email addresses. These token copies can be safely exchanged and verified without exposing the original email address to potential phishing attacks.
2Ease of operation
If sender email addresses are exposed in communications, then communication transparency is improved, but unauthorized access and data extraction risk increases
Solution Approach 1:
Tokens serve as intermediary elements that maintain communication transparency without exposing actual email addresses. The token verification process provides the necessary transparency for recipients to verify sender authenticity, while the token itself acts as a protective layer that prevents direct exposure and unauthorized access to the underlying email address data.
Solution Approach 2:
The patent employs tokens as temporary, disposable authentication objects that are used once for verification and then discarded or invalidated. These short-lived token objects provide the necessary transparency for communication verification without creating persistent exposure risks, as they cannot be reused for unauthorized access after their single use.
3Measurement precision
If token verification is implemented for all emails, then phishing detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal token verification system that can be applied across different email communication scenarios. The token mechanism serves multiple functions: authentication, phishing detection, and communication verification. This multi-functional approach allows the system to maintain high phishing detection accuracy while avoiding the need for separate complex systems for each function, as the token mechanism handles all these tasks through a unified framework.
Data Source
AI summary
A system for identifying email messages associated with phishing threats accesses an email message sent to a receiving computing device, where the email message is associated with a sender's email address. The system determines whether the sender's email address is associated with a token from a plurality of tokens stored in a token-email address mapping table. The system determines that the email message is associated with a phishing threat, in response to determining that the sender's email address is not associated with a token from a plurality of tokens from among a token-email mapping table.

