User-Generated Identifier for Spoofing Verification in Electronic Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious third parties can impersonate legitimate financial institutions by sending spoofed electronic communications, making it difficult for users to verify the authenticity of messages, especially on mobile devices, leading to potential fraud.

Innovation Solution

Implementing a user-generated unique identifier that is embedded in electronic communications, allowing users to verify the authenticity of messages by recognizing the unique identifier, which is unique and known only to the user and the organization, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If electronic communications are sent without verification mechanisms, then communication efficiency is maintained, but security and authenticity verification become difficult

Engineering Contradiction:
Improvemessage authenticityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The unique identifier is generated and assigned to the user account in advance, before any communications occur. This preliminary setup enables automatic verification in subsequent communications without adding complexity to the communication process itself, as the verification mechanism is already in place and ready to use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unique identifier serves as an intermediary element that bridges the sender and receiver in the communication process. Instead of requiring complex verification protocols between parties, the unique identifier acts as a trusted mediator that both parties can recognize, simplifying the verification process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user-generated unique identifiers are embedded in all communications, then fraud risk is reduced, but communication processing time increases

Engineering Contradiction:
Improvefraud preventionVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification process is designed to be self-service, where the unique identifier automatically verifies the sender's identity without requiring manual intervention or complex processing. The receiving system can independently validate the message authenticity by checking for the presence and format of the unique identifier, eliminating the need for time-consuming additional verification steps.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If traditional electronic communications are used without unique identifiers, then ease of operation is maintained, but vulnerability to spoofing increases

Engineering Contradiction:
Improvespoofing vulnerabilityVSAvoiduser operation simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The unique identifier is integrated locally into the communication message itself, specifically positioned within the message structure where it can be easily recognized and verified. This localized placement ensures that the anti-spoofing mechanism does not require changes to the overall communication workflow or user interface, maintaining ease of operation while providing targeted protection against spoofing.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240291827A1Techniques for verifying a sender identity using a user-generated identifier
Publication Date: 2024.08.29 ALLY FINANCIAL INC
  • US20240291827A1 patent drawing
  • US20240291827A1 patent drawing
  • US20240291827A1 patent drawing

AI summary

Methods, systems, and devices to support techniques for verifying a sender identity using a user-generated identifier are described. A user having one or more accounts with an organization may generate a unique identifier to associate with one or more accounts, and the organization may include the unique identifier in subsequent electronic communications to the user. For example, the user may generate and transmit the unique identifier to the organization using a device, and the organization may associate the unique identifier with the one or more accounts of the user. The organization may establish a communication session with the user, such as by generating a message which includes information associated with the one or more accounts. The organization may embed the unique identifier into the message and transmit the message to the user. The message including the unique identifier may provide verification that the sender is the organization.