IP Library › Granted Patent US 12,289,304
Granted Patent B2
US 12,289,304 · App. 18/503,978 · Granted Apr 29, 2025

Information security system and method for phishing threat prevention using tokens

Inventors: Kelly Renee-Drop Keiter (Waxhaw, NC); Michael Robert Young (Davidson, NC); Tomas Mata Castrejon, III (Fort Mill, SC); Rick Wayne Sumrall (Charlotte, NC)
Assignee: Bank of America Corporation
H04L63/083H04L63/0876H04L63/1483H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,304
App. No.
18/503,978
Filed
Nov 7, 2023
Granted
Apr 29, 2025
Kind
B2
Art Unit
2499
USPC
726/5
Abstract

A system for communicating email messages using tokens receives a request to send an email message to a receiver. The email message is associated with a sender's email address. The system determines whether the sender's email address is associated with a token from a plurality of tokens stored in a token-email address mapping table. The system generates a particular token for the sender's email address in response to determining that the sender's email address is not associated with a token, where the particular token uniquely identifies the sender's email address. The system sends the email message using the particular token instead of the sender's email address, such that the sender's email address remains anonymous from the perspective of the receiver.

Claims (56)

1. A system for communicating email messages using tokens, comprising:

a memory operable to store a token-email address mapping table comprising a plurality of email addresses mapped to a plurality of tokens, wherein:

each of the plurality of email addresses is associated with a different token from the plurality of tokens, and

each of the plurality of tokens uniquely identifies a different email address from the plurality of email addresses; and

a processor, operably coupled with the memory, and configured to:

receive a request to communicate an email message to a receiver, wherein the email message is associated with a sender's email address;

determine whether the sender's email address is associated with a token from the plurality of tokens;

in response to determining that the sender's email address is not associated with a token from the plurality of tokens, generate a particular token for the sender's email address, wherein the particular token uniquely identifies the sender's email address, and wherein the particular token is generated by applying a hash function to a personally identifiable information field of the email message; and

communicate the email message using the particular token instead of the sender's email address, such that the sender's email address remains anonymous from a perspective of the receiver;

a second processor configured to:

access the email message;

determine whether the sender's email address is associated with the particular token by searching for the sender's email address within the token-email address mapping table; and

in response to determining that the sender's email address is associated with the particular token, determine that the email message is not associated with a phishing treat.

2. The system of claim 1 , wherein the particular token comprises at least one of a set of numbers, a set of letters, and a set of symbols.

3. The system of claim 1 , wherein the processor is further configured to, in response to receiving the request to communicate the email message, verify an identity of a sender by performing a multi-factor authentication.

4. The system of claim 3 , wherein the multi-factor authentication comprises at least two of:

verifying login credentials associated with the sender;

verifying a passcode sent to a sending computing device from which the email message is communicated; and

verifying an identification associated with the sending computing device, wherein the identification comprises an Internet Protocol (IP) address, a Media Access Control (MAC) address, or a serial number associated with the sending computing device.

5. The system of claim 1 , wherein accessing the email message comprises intercepting the email message before the email message arrives at a receiving computing device.

6. A method for communicating email messages using tokens, comprising:

receiving a request to communicate an email message to a receiver, wherein the email message is associated with a sender's email address;

determining whether the sender's email address is associated with a token from a plurality of tokens stored in a token-email address mapping table, wherein:

the token-email address mapping table comprising a plurality of email addresses mapped to the plurality of tokens,

each of the plurality of email addresses is associated with a different token from the plurality of tokens, and

each of the plurality of tokens uniquely identifies a different email address from the plurality of email addresses;

accessing, by a server associated with a receiving computing device to which the email message is sent, the email message;

determining whether the sender's email address is associated with a particular token by searching for the sender's email address within the token email address mapping table; and

in response to determining that the sender's email address is associated with the particular token;

determining that the email message is not associated with a phishing threat;

in response to determining that the sender's email address is not associated with a token from the plurality of tokens, generating a particular token for the sender's email address, wherein the particular token uniquely identifies the sender's email address, and wherein the particular token is generated by applying a hash function to a personally identifiable information field of the email message; and

communicating the email message using the particular token instead of the sender's email address, such that the sender's email address remains anonymous from a perspective of the receiver.

7. The method of claim 6 , wherein the particular token comprises at least one of a set of numbers, a set of letters, and a set of symbols.

8. The method of claim 6 , further comprising, in response to receiving the request to communicate the email message, verifying a identity of a sender by performing a multi-factor authentication.

9. The method of claim 8 , wherein the multi-factor authentication comprises at least two of:

verifying login credentials associated with the sender;

verifying a passcode sent to a sending computing device from which the email message is communicated; and

verifying an identification associated with the sending computing device, wherein the identification comprises an Internet Protocol (IP) address, a Media Access Control (MAC) address, or a serial number associated with the sending computing device.

10. The method of claim 6 , wherein accessing the email message comprises intercepting the email message before the email message arrives at the receiving computing device.

11. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to:

receive a request to communicate an email message to a receiver, wherein the email message is associated with a sender's email address;

determine whether the sender's email address is associated with a token from a plurality of tokens stored in a token-email address mapping table, wherein:

the token-email address mapping table comprising a plurality of email addresses mapped to the plurality of tokens,

each of the plurality of email addresses is associated with a different token from the plurality of tokens, and

each of the plurality of tokens uniquely identifies a different email address from the plurality of email addresses;

accessing, by a server associated with a receiving computing device to which the email message is sent, the email message;

determining whether the sender's email address is associated with a particular token by searching for the sender's email address within the token email address mapping table; and

in response to determining that the sender's email address is associated with the particular token, determining that the email message is not associated with a phishing threat;

in response to determining that the sender's email address is not associated with a token from the plurality of tokens, generate a particular token for the sender's email address, wherein the particular token uniquely identifies the sender's email address, and wherein the particular token is generated by applying a hash function to a personally identifiable information field of the email message; and

communicate the email message using the particular token instead of the sender's email address, such that the sender's email address remains anonymous from a perspective of the receiver.

12. The non-transitory computer-readable medium of claim 11 , wherein the particular token comprises at least one of a set of numbers, a set of letters, and a set of symbols.

13. The non-transitory computer-readable medium of claim 11 , wherein the instructions when executed by the processor, further cause the processor to, in response to receiving the request to communicate the email message, verify a identity of a sender by performing a multi-factor authentication.

14. The non-transitory computer-readable medium of claim 13 , wherein the multi-factor authentication comprises at least two of:

verifying login credentials associated with the sender;

verifying a passcode sent to a sending computing device from which the email message is communicated; and

verifying an identification associated with the sending computing device, wherein the identification comprises an Internet Protocol (IP) address, a Media Access Control (MAC) address, or a serial number associated with the sending computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2023
From: KEITER, KELLY RENEE-DROP; YOUNG, MICHAEL ROBERT; CASTREJON, TOMAS MATA, III; SUMRALL, RICK WAYNE
To: BANK OF AMERICA CORPORATION
Reel/Frame 065494/0183 →
Continuity (2)
Continuation 17330580 · May 26, 2021
Related Publication 20240073200A1 · Feb 29, 2024
References Cited (115)
US 6732157B1 · Gordon et al. · 2004 [cited by applicant]
US 7155738B2 · Zhu et al. · 2006 [cited by applicant]
US 7181498B2 · Zhu et al. · 2007 [cited by applicant]
US 7181764B2 · Zhu et al. · 2007 [cited by applicant]
US 7188358B1 · Hisada · 2007 [cited by examiner]
US 7277695B2 · Petry et al. · 2007 [cited by applicant]
US 7287060B1 · Mccown et al. · 2007 [cited by applicant]
US 7290035B2 · Mattathil · 2007 [cited by applicant]
US 7373385B2 · Prakash · 2008 [cited by applicant]
US 7487217B2 · Buckingham et al. · 2009 [cited by applicant]
US 7529802B2 · Nelson et al. · 2009 [cited by applicant]
US 7548544B2 · Quinlan et al. · 2009 [cited by applicant]
US 7580982B2 · Owen et al. · 2009 [cited by applicant]
US 7627635B1 · Logue et al. · 2009 [cited by applicant]
US 7653698B2 · Wieneke et al. · 2010 [cited by applicant]
US 7668921B2 · Proux et al. · 2010 [cited by applicant]
US 7673002B1 · Damarla · 2010 [cited by applicant]
US 7680886B1 · Cooley · 2010 [cited by applicant]
US 7783597B2 · Kirsch · 2010 [cited by applicant]
US 7865561B2 · Kelly et al. · 2011 [cited by applicant]
US 7873695B2 · Clegg et al. · 2011 [cited by applicant]
US 7958197B2 · Hughes et al. · 2011 [cited by applicant]
US 8032594B2 · Helsper et al. · 2011 [cited by applicant]
US 8135779B2 · Rainisto · 2012 [cited by applicant]
US 8176126B2 · Davis et al. · 2012 [cited by applicant]
US 8255468B2 · Vitaldevara et al. · 2012 [cited by applicant]
US 8271588B1 · Bruno et al. · 2012 [cited by applicant]
US 8327445B2 · Gillum et al. · 2012 [cited by applicant]
US 8359649B1 · Sobel et al. · 2013 [cited by applicant]
US 8380791B1 · Gordon et al. · 2013 [cited by applicant]
US 8407786B1 · Elias et al. · 2013 [cited by applicant]
US 8468348B1 · Wasserman · 2013 [cited by examiner]
US 8522347B2 · Yanovsky et al. · 2013 [cited by applicant]
US 8560616B1 · Diac et al. · 2013 [cited by applicant]
US 8566938B1 · Prakash et al. · 2013 [cited by applicant]
US 8589494B2 · Garrett · 2013 [cited by applicant]
US 8601064B1 · Liao et al. · 2013 [cited by applicant]
US 8621614B2 · Vaithilingam et al. · 2013 [cited by applicant]
US 8738050B2 · Backholm et al. · 2014 [cited by applicant]
US 8745143B2 · Vitaldevara et al. · 2014 [cited by applicant]
US 8751808B2 · Gelbard et al. · 2014 [cited by applicant]
US 8756286B2 · Bayles et al. · 2014 [cited by applicant]
US 8782184B2 · Furlong et al. · 2014 [cited by applicant]
US 8838709B2 · Nussey et al. · 2014 [cited by applicant]
US 8839369B1 · Dai et al. · 2014 [cited by applicant]
US 8856239B1 · Oliver et al. · 2014 [cited by applicant]
US 8935802B1 · Mattsson · 2015 [cited by applicant]
US 9143478B2 · Ramaswamy · 2015 [cited by applicant]
US 9148432B2 · Yost · 2015 [cited by applicant]
US 9154514B1 · Prakash · 2015 [cited by applicant]
US 9223998B1 · Grisso · 2015 [cited by applicant]
US 9313170B1 · Shoemaker · 2016 [cited by examiner]
US 9369437B2 · Holloway et al. · 2016 [cited by applicant]
US 9407588B2 · Low et al. · 2016 [cited by applicant]
US 9419927B2 · Shinde et al. · 2016 [cited by applicant]
US 9442881B1 · Narayan et al. · 2016 [cited by applicant]
US 9560074B2 · Stemm et al. · 2017 [cited by applicant]
US 9736149B2 · Bettenburg et al. · 2017 [cited by applicant]
US 9942249B2 · Gatti · 2018 [cited by applicant]
US 10178060B2 · Wood · 2019 [cited by applicant]
US 10243904B1 · Wescoe et al. · 2019 [cited by applicant]
US 10313286B2 · Ordogh · 2019 [cited by applicant]
US 10404745B2 · Verma et al. · 2019 [cited by applicant]
US 10754957B2 · Silverstone · 2020 [cited by applicant]
US 10764327B2 · Yao et al. · 2020 [cited by applicant]
US 10834111B2 · Adir et al. · 2020 [cited by applicant]
US 10893009B2 · Everton · 2021 [cited by applicant]
US 10944730B1 · Boutros et al. · 2021 [cited by applicant]
US 11405379B1 · Clauss · 2022 [cited by examiner]
US 11424930B2 · Grier, Sr. · 2022 [cited by applicant]
US 11792224B2 · Keiter et al. · 2023 [cited by applicant]
US 11882112B2 · Keiter et al. · 2024 [cited by applicant]
US 20040215721A1 · Szeto · 2004 [cited by examiner]
US 20040254990A1 · Mittal · 2004 [cited by applicant]
US 20050091319A1 · Kirsch · 2005 [cited by applicant]
US 20050216588A1 · Keohane et al. · 2005 [cited by applicant]
US 20060004896A1 · Nelson et al. · 2006 [cited by applicant]
US 20060031313A1 · Libbey et al. · 2006 [cited by applicant]
US 20060041621A1 · Libbey · 2006 [cited by applicant]
US 20060168066A1 · Helsper et al. · 2006 [cited by applicant]
US 20080052359A1 · Golan et al. · 2008 [cited by applicant]
US 20080104180A1 · Gabe · 2008 [cited by applicant]
US 20080155026A1 · Daniels-Farrar et al. · 2008 [cited by applicant]
US 20080177843A1 · Gillum et al. · 2008 [cited by applicant]
US 20080184366A1 · Alperovitch et al. · 2008 [cited by applicant]
US 20080270544A1 · Howe · 2008 [cited by applicant]
US 20090063371A1 · Lin · 2009 [cited by applicant]
US 20090089859A1 · Cook et al. · 2009 [cited by applicant]
US 20090094333A1 · Kyprianou · 2009 [cited by applicant]
US 20090119376A1 · Bomma · 2009 [cited by applicant]
US 20090234663A1 · Mccann et al. · 2009 [cited by applicant]
US 20090282112A1 · Prakash · 2009 [cited by applicant]
US 20100251362A1 · Gillum et al. · 2010 [cited by applicant]
US 20110196934A1 · Sheer · 2011 [cited by examiner]
US 20110238765A1 · Wilson et al. · 2011 [cited by applicant]
US 20110283359A1 · Prince · 2011 [cited by examiner]
US 20130046974A1 · Kamara et al. · 2013 [cited by applicant]
US 20130166667A1 · Carr et al. · 2013 [cited by applicant]
US 20130218983A1 · Richard · 2013 [cited by examiner]
US 20140337452A1 · Kay · 2014 [cited by applicant]
US 20150067833A1 · Verma et al. · 2015 [cited by applicant]
US 20150287336A1 · Scheeres · 2015 [cited by applicant]
US 20160004852A1 · McEvoy · 2016 [cited by examiner]
US 20170230323A1 · Jakobsson · 2017 [cited by applicant]
US 20170270517A1 · Vasu · 2017 [cited by examiner]
US 20170324767A1 · Srivastava · 2017 [cited by applicant]
US 20170346851A1 · Drake · 2017 [cited by applicant]
US 20180007061A1 · Liebmann et al. · 2018 [cited by applicant]
US 20180012000A1 · Ogawa · 2018 [cited by examiner]
US 20180198799A1 · Parthasarathy · 2018 [cited by examiner]
US 20190318653A1 · Shi · 2019 [cited by applicant]
US 20200067861A1 · Leddy et al. · 2020 [cited by applicant]
US 20200357026A1 · Liu · 2020 [cited by applicant]
Surmacz, Reliability of E-mail Delivery in the Era of Spam, Jun. 16, 2007, IEEE, pp. 1-7. (Year: 2007). [cited by examiner]
Hudnall et al, Implementing Secure E-mail on the Open Internet with MailTrust, Apr. 26, 2017, IEEE, pp. 1-7. (Year: 2017). [cited by examiner]