According to a press release from the Japan Institute for Promotion of Digital Economy and Community (JIPDEC)[1], JIPDEC has begun introducing the “Trusted Email Mark” shown in the image to banks in cooperation with Yahoo and 6 other companies[2], with the aim of preventing email spoofing. Joyo Bank is the first adopter and has reportedly decided to use the Trusted Email Mark shown in Figure 1 as a security measure for webmail.

図1 安心マーク
Figure 1: Trusted Email Mark

The system allows recipients to easily verify that an email is not spoofed by combining DKIM[3], a digital-signature technology for email, with ROBINS, a cyber registry of corporations provided by JIPDEC. It indicates the result by displaying the “Trusted Email Mark” when the message is viewed in webmail[4].

The Trusted Email Mark service was launched during the House of Councillors election in July last year, and service has now been newly extended to financial institutions. At the time of writing, the Liberal Democratic Party, the Democratic Party of Japan, JIPDEC, and Joyo Bank use the Trusted Email Mark.

One drawback at present is that the mark can be verified only through webmail, but it is still a first step in a more trustworthy direction. It would be even better if it were also made available for major email clients through plugins or similar means.

To get a little technical, this can also be viewed as ROBINS functioning as a trust framework, while the present DKIM-based mechanism functions as a kind of “metadata service” that verifies registration in that framework.

On the other hand, in a borderless society, it would be even better if the system could integrate comparable mechanisms from other countries rather than relying solely on ROBINS, which is probably limited to corporations in Japan.

In any event, future developments will be worth watching.

Note: Disclosure: As of 2014, the author is a member of JIPDEC’s advisory committee.

[1] JIPDEC News Release Initiatives Toward a Secure and Trustworthy Email Environment
—Introduction of the Trusted Email Mark for Preventing Email Spoofing Begins at Banks—”

[2] Infomania, Synergy Marketing, Tricorn, NIFTY, PIPED BITS, and Yahoo

[3] This article provides a detailed explanation of how DKIM works: What Is “DKIM,” the Latest Digital Signature Technology?

[4] Bank Becomes First to Adopt “Trusted Email Mark,” Preventing Spoofed Email Through Sender Domain Authentication (2014/8/11)

 

Related posts