US2018139183A1PendingUtilityA1

Signed ephemeral email addresses

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jun 22, 2008Filed: Dec 21, 2017Published: May 17, 2018
Est. expiryJun 22, 2028(~1.9 yrs left)· nominal 20-yr term from priority
H04L 2209/80H04L 9/3247H04L 9/0891H04L 63/0281G06Q 10/107H04L 51/12H04L 51/28H04L 51/48H04L 51/212
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Architecture for generating a temporary account (e.g., an email address) with a user-supplied friendly name and a secret used to the sign the temporary account. For example, when a user wishes to create a temporary email address to use with an online organization, a friendly name is provided and the system generates a temporary email address including the friendly name. A signing component signs the temporary email address with a secret. One or more of these secrets can be provisioned prior to the user's creation of a friendly name, which eliminates propagation delay. During use, only incoming email messages having the temporary email address signed with the secret are validated. When the user revokes the temporary email address, the secret is revoked and the revocation is propagated to network gateways, rejecting any email sent to that address.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented system, comprising:
 a provisioning component configured to provision a secret for use with an ephemeral account;   a signing component configured to sign the ephemeral account with the secret to generate a signed ephemeral account and return the signed ephemeral account to a user of the user account;   an address book of a network gateway configured to receive and store the signed ephemeral account and the secret, wherein the network gateway confirms the ephemeral account is valid when the ephemeral account is in the address book, and confirms the signed ephemeral account is signed using the secret when the signed ephemeral account is not in the address book; and   a hardware processor configured to execute computer-executable instructions stored in a memory and associated with the provisioning component, the signing component, and the address book.   
     
     
         2 . The system of  claim 1 , wherein the provisioning component is configured to provision the ephemeral account prior to creation of a friendly name. 
     
     
         3 . The system of  claim 1 , further comprising a revocation component configured to revoke the secret in response to revocation of the ephemeral account, the hardware processor configured to execute computer-executable instructions that implement the revocation component. 
     
     
         4 . The system of  claim 1 , wherein the signing component combines the secret with a friendly name and generates a combination of the secret and friendly name, the hardware processor configured to execute computer-executable instructions that enable the signing component to combine the secret and the friendly name and generate the combination. 
     
     
         5 . The system of  claim 1 , further comprising a validation component of the network gateway, the validation component configured to look up the secret in the address book, to validate ephemeral accounts signed with the secret, the hardware processor executes computer-executable instructions that implement the validation component. 
     
     
         6 . A computer-implemented messaging system, comprising:
 a signing component configured to receive a temporary message address associated with a user account and to sign the temporary message address with a secret to create a signed temporary message address, and return the signed temporary message address to a user of the user account;   an address book of a network gateway configured to store the temporary message address and the secret;   a validation component of the network gateway configured to validate incoming messages directed to the signed temporary message address, configured to confirm the temporary message address is valid when the temporary message address is in the address book, and configured to confirm the signed temporary message address is signed using the secret when the signed temporary message address is not in the address book; and   a hardware processor configured to execute computer-executable instructions in a memory associated with the signing component, the address book, and the validation component.   
     
     
         7 . The system of  claim 6 , wherein the signing component generates a single secret for each user and multiple temporary message addresses are generated using the single secret. 
     
     
         8 . The system of  claim 6 , wherein the signing component generates a plurality of secrets for each user and multiple temporary message addresses are generated that correspond to the secrets. 
     
     
         9 . The system of  claim 6 , wherein the signing component returns the signed temporary message address, which comprises a user identifier, a name, and an encrypted string that includes the secret. 
     
     
         10 . The system of  claim 9 , wherein the encrypted string is derived from an operation on a combination of the secret and the name. 
     
     
         11 . The system of  claim 6 , wherein the validation component further comprises a restriction component configured to restrict incoming messages to messages having the temporary message address signed with the secret and a user-defined domain name. 
     
     
         12 . A computer-implemented method of messaging, comprising acts of:
 propagating a temporary message address for a user and a secret to an address book of a network node;   signing the temporary message address with the secret to create a signed temporary message address, and returning the signed temporary message address to the user;   looking up at least one of the temporary message address or the secret in the address book based on receipt of incoming messages directed to the signed temporary message address; and   confirming the temporary message address is valid when the temporary message address is in the address book, and confirming the signed temporary message address is signed using the secret when the signed temporary message address is not in the address book.   
     
     
         13 . The method of  claim 12 , further comprising provisioning the temporary message addresses prior to creation of the friendly name. 
     
     
         14 . The method of  claim 12 , further comprising revoking the secret in response to revocation of the temporary message address. 
     
     
         15 . The method of  claim 12 , further comprising generating a single secret for each user, and generating a plurality of temporary message addresses using the single secret. 
     
     
         16 . The method of  claim 12 , further comprising generating a plurality of secrets for each user, and generating a plurality of temporary message addresses that correspond to the plurality of secrets. 
     
     
         17 . The method of  claim 12 , further comprising returning a signed message address that comprises a user identifier, the user-supplied name, and an encrypted string that includes the secret. 
     
     
         18 . The method of  claim 17 , further comprising generating the encrypted string by concatenating the secret with the name to generate a hash of the secret and the name. 
     
     
         19 . The method of  claim 12 , further comprising restricting incoming messages to messages having the temporary message address signed with the secret and a user-defined domain name. 
     
     
         20 .- 28 . (canceled)

Join the waitlist — get patent alerts

Track US2018139183A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.