Mail data encryption gateway, encryption method and application
Through the email data encryption gateway and national secret algorithm, the security issues of cross-enterprise or cross-border email transmission are solved, user operations are simplified, the security and compliance of email content are ensured, and the secure transmission of cross-enterprise and cross-border emails is achieved.
Patent Information
- Application Number
- CN202510909914.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-09-05
AI Technical Summary
Existing technologies cannot effectively protect the security of email transmission across enterprises or borders. User operations are complicated, email content can be easily intercepted or tampered with after leaving the VPN tunnel, there is a lack of source encryption protection, and third-party email clients are not encrypted, leading to the risk of data leakage.
We use an email data encryption gateway, combined with national secret algorithms, certificate systems and transmission tunnel encryption technology, and ensure the security and compliance of emails during transmission through dedicated email security communication protocols, identity authentication modules and source encryption engines.
It achieves secure transmission of emails across enterprises and borders, simplifies user operations, ensures the confidentiality and integrity of email content, and meets high-intensity security and policy compliance requirements.
Smart Images

Figure CN120602191A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to an email data encryption gateway, encryption method and application. Background Art
[0002] With the continuous advancement of digital transformation in enterprises and institutions, an increasing number of application systems are beginning to offer mobile and remote access capabilities based on the internet. Many enterprises and institutions are currently facing challenges in how to securely roll out various application systems from headquarters to branch offices, offices, and mobile workers, while achieving secure, real-time, and unified management of these systems. With the advancement of digital transformation, email has become a crucial tool for daily communication and information exchange. It not only improves work efficiency but also brings unprecedented convenience to businesses. However, the openness and ubiquity of email systems also make them a prime target for cyberattacks. Email security not only impacts the confidentiality, integrity, and availability of corporate information, but also directly affects business secrets and customer trust.
[0003] In recent years, security incidents such as email scams, phishing attacks, and malware distribution have become increasingly frequent, causing significant financial losses and reputational risks to businesses. According to incomplete statistics, over 90% of cyberattacks are carried out via email, making email security a top priority for enterprise information security management.
[0004] Currently, some enterprises have deployed nationally recognized IPSec VPN or SSL VPN security gateways to ensure secure communications between email clients and servers within their domain. However, while this measure has improved the security of internal communications to a certain extent, enterprises still face multiple challenges in email security.
[0005] First, emails sent outside the domain are not protected by the network, so their security cannot be effectively guaranteed. This means that once email data leaves the enterprise's internal network, it is at risk of being intercepted or tampered with. Communication between different email servers, if not protected by tunnels, is also subject to security threats. This can lead to the leakage of sensitive information during transmission, especially when communicating across enterprises or borders. Second, with a variety of email clients, users often need to activate additional VPN dial-up proxy software before opening their email clients to send or receive emails. This operation not only increases user complexity but also prevents their devices from accessing the internet during the VPN connection, significantly disrupting their daily network life. After sending or receiving emails, users need to close the VPN tunnel to restore internet access, a cumbersome and error-prone process. Furthermore, if the source of email is not encrypted, email data is highly vulnerable to attack or leakage after leaving the VPN tunnel. Server and client security vulnerabilities can also pose a risk of email data leakage, exposing all email data to the risk of compromise. Users may send files containing sensitive information in plain text due to lack of understanding of security requirements or for convenience. This not only violates the company's security policy but also poses potential security risks to the company.
[0006] Currently, businesses lack a protection mechanism for outgoing email content, including source encryption and security measures. While businesses can implement security mechanisms to protect purely internal email, they are unable to protect and control data leaks once email content has been distributed externally. Currently, most businesses use third-party email clients or web-based platforms as their primary email delivery tools, and they fail to encrypt emails and related attachments. This makes emails vulnerable to interception and direct tampering during transmission, making it impossible to effectively verify the identities of both parties and the integrity of the data.
[0007] In summary, the openness of email systems makes them a prime target for cyberattacks. Existing technologies primarily address email security issues through the following methods:
[0008] 1. Use national secret IPSec VPN or SSL VPN to ensure the security of internal corporate communications, but it cannot cover external domain email transmission.
[0009] 2. Third-party email clients or web-based tools do not encrypt email content and attachments, leading to the risk of data leakage during transmission.
[0010] 3. There is a lack of source encryption mechanism for email content, which cannot effectively protect email data that has flowed to the outside.
[0011] Existing technologies have the following issues: Email, as a core tool for corporate information exchange, faces increasingly prominent security challenges. According to incomplete statistics, over 90% of cyberattacks occur via email. Existing email encryption technologies often rely on VPN tunnels or third-party encryption tools, but these methods have the following shortcomings:
[0012] 1. VPN tunnels only protect internal corporate communications and cannot cover cross-enterprise or cross-border email transmission.
[0013] 2. Users need to install a VPN client separately, which is complicated and affects daily network use.
[0014] 3. Email content may be intercepted or tampered with after leaving the VPN tunnel, and there is a lack of source encryption protection.
[0015] The shortcomings of existing technologies are that they fail to fully cover internal and external email transmission scenarios, are complex to operate, and fail to meet high-intensity security and policy compliance requirements. Therefore, developing and implementing an effective email security strategy is crucial to protecting enterprises from cyber threats. Summary of the Invention
[0016] The present invention provides an email data encryption gateway, encryption method and application, which adopts the national secret algorithm to meet the requirements of high-intensity security and policy compliance, and ensures the secure transmission of emails within the enterprise, across enterprises and across borders through data encryption and decryption, certificate system, transmission tunnel encryption and other technologies.
[0017] The present invention provides an email data encryption gateway, comprising a core service module, a management subsystem, a data scheduling bus, a domestically produced trust-based innovation platform, an extended service module, and a national secret password acceleration card, wherein the data scheduling bus is respectively connected to the core service module, the management subsystem, the domestically produced trust-based innovation platform, the extended service module, and the national secret password acceleration card;
[0018] The data scheduling bus is also connected to the user management module, administrator management module, certificate management module, service management module, device management module, system management module, database, key management module and HAL interface respectively, and the HAL interface is also connected to the national secret password acceleration card.
[0019] Furthermore, the core service module includes a dedicated email security communication protocol, an identity authentication module, deep message inspection, and a source encryption engine. The dedicated email security communication protocol is used to ensure the security of emails during transmission; the identity authentication module is used to verify user identity to ensure that only authorized users can access the network through the gateway's client suite; the deep message inspection is used to detect potential threats in email content; and the source encryption engine is used to encrypt email content using a national secret algorithm.
[0020] Furthermore, the management subsystem includes a front-end UI and a management framework / middleware. The front-end UI is a user interface used for daily management and maintenance of the system; the management framework / middleware is used to provide a system management framework and middleware services for interaction between various subsystems.
[0021] Furthermore, the user management module is used to perform operations such as adding, deleting, modifying and checking user information, and supports the original user system;
[0022] The administrator management module is used to meet the information requirements of security protection and divide the administrator's authority and management user scope;
[0023] The certificate management module is used to generate, request, apply for and maintain certificates used in the process of sending and receiving emails and certificates required by the system itself;
[0024] The service management module is used to configure email-related services, including viewing and analyzing the running status of the service itself and the email server;
[0025] The system management module is used to manage and allocate other modules of the system.
[0026] Furthermore, the national secret password acceleration card supports the national secret encryption card for accelerating the encryption and decryption process, and supports the national secret encryption and decryption algorithms including SM2, SM3, and SM4.
[0027] The present invention also provides a mail data encryption method, using the mail data encryption gateway described above, the method comprising:
[0028] S1. The sender uses email terminal A to edit the email content and enter the recipient's email address, and clicks the send button;
[0029] S2. The email arrives at the email data encryption gateway and is passed to the email server through the email security gateway. It is then passed to the recipient's email terminal B in different forms depending on the type of email sending and receiving. The types of email sending and receiving include sending and receiving emails within the enterprise, sending and receiving emails between enterprises, sending and receiving emails between enterprises and branches / partners, and sending and receiving emails between enterprises and Internet users.
[0030] Furthermore, when the type of email sending and receiving is internal email sending and receiving within an enterprise, step S2 specifically includes:
[0031] S211: The email arrives at the email data encryption gateway and is passed to the email server through the email security gateway. The email server temporarily stores the email and waits for email terminal B to receive it.
[0032] S212. Email terminal B on the external network uses a client suite to automatically establish a dedicated national encryption transmission tunnel with the email data encryption gateway to receive emails. There are three main environments for internal employees to send and receive emails:
[0033] (1) In the enterprise intranet environment, emails can be sent and received directly without installing any additional software;
[0034] (2) In the external network environment, use the original VPN client to establish a tunnel for sending and receiving emails;
[0035] (3) In the external network environment, use the installed national encryption security kit to establish a national encryption transmission tunnel, and send and receive emails after two-way certificate authentication.
[0036] Furthermore, when the type of email sending and receiving is email sending and receiving between enterprises, step S2 specifically includes:
[0037] S221: The email arrives at the email data encryption gateway of enterprise A and is passed through enterprise A's email security gateway to enterprise A's email server for temporary storage.
[0038] S222: When it is found that the email needs to be forwarded to the mailbox domain of enterprise B, it is immediately sent through the email data encryption gateway. The email data encryption gateway of enterprise A automatically establishes an encrypted tunnel with the email data encryption gateway of enterprise B and sends the email to the email data encryption gateway of enterprise B through the encrypted tunnel.
[0039] S213. The email data encryption gateway of enterprise B transmits it to the email server of enterprise B through the email security gateway of enterprise B, and the employees of enterprise B use email terminal B to receive the relevant emails.
[0040] Furthermore, when the type of email sending and receiving is email sending and receiving between an enterprise and its branches / partners, step S2 specifically includes:
[0041] S231: The email arrives at the email data encryption gateway and is passed to the enterprise email server through the email security gateway;
[0042] S232. The mail server determines that the recipient belongs to an external domain and sends the mail to the gateway for delivery. The gateway finds through the user certificate synchronization platform / user certificate synchronization module that the address is a trusted address of the user certificate synchronization platform / user certificate synchronization module. The source of the certificate includes:
[0043] (1) The recipient provides the certificate to the sender, who then uploads the certificate as a file or has the IT administrator upload it to the user certificate synchronization platform / user certificate synchronization module;
[0044] (2) The sender directly applies for and downloads a certificate for the recipient in the certificate synchronization platform / user certificate synchronization module, or instructs the IT administrator to apply for a relevant certificate for someone;
[0045] S233. The email data encryption gateway determines that the recipient's email registration information is an S / MIME certificate user, and automatically encrypts the email content using the public key in the recipient's digital certificate and sends it to the recipient's email server. The branch / partner logs in to the email client B with S / MIME function, receives the email and automatically decrypts it to obtain the original content of the email.
[0046] Furthermore, when the type of email sending and receiving is email sending and receiving between an enterprise and an Internet user, step S2 specifically includes:
[0047] S241. The enterprise employee's email terminal A automatically establishes a dedicated encrypted tunnel with the email data encryption gateway. The email arrives at the email data encryption gateway and is then delivered to the enterprise email server via the email security gateway.
[0048] S242: The email data encryption gateway finds that the email needs to be forwarded to another Internet mailbox. The email data encryption gateway determines that the address is not a safe recipient and automatically analyzes the email content. If there is no other sensitive information, the email is allowed to be forwarded and the content is recorded;
[0049] S243: The email data encryption gateway encrypts the email content and attachments, queries the mobile phone number corresponding to the email address, and sends the encryption password and email title to the mobile phone number via the SMS gateway;
[0050] S244. If there is no relevant corresponding mobile phone number in the query, an email message is returned to inform that there is no relevant mobile phone number to send the password, and a reminder is given to add a mobile phone number, or to upload the corresponding mobile phone number on the user platform in advance;
[0051] S245. The Internet user logs in to the mail client B and receives mails through the corresponding mail server according to the encryption password and mail title.
[0052] The beneficial effects of the present invention are:
[0053] 1. Provides a dedicated email security protocol, adopts national secret algorithms, complies with commercial cryptography certification qualifications, meets high-intensity security requirements and policy compliance, has a built-in national secret encryption card and encryption engine, provides national secret algorithms and post-quantum algorithms, and meets high-performance email encryption and decryption needs.
[0054] 2. Users in the security domain do not need to change their usage habits and do not need to install any clients or plug-ins.
[0055] 3. For emails sent outside the domain, if they are within the same security boundary (where this gateway is deployed), the mail servers will automatically use the security protocol to forward the communication, and the client will not be aware of it. For emails sent outside the domain to non-security boundaries, the mail server can automatically determine and take source protection measures, and process them through S / MIME or overall encapsulation encryption.
[0056] 4. Use deep packet inspection (DPI) to identify email domain addresses and message information, and detect plaintext emails. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 This is an architectural diagram of the email data encryption gateway of the present invention.
[0058] Figure 2 This is a schematic diagram of the basic functions of the email data encryption gateway in the present invention.
[0059] Figure 3 This is a schematic diagram of the application of the email data encryption gateway of the present invention.
[0060] Figure 4 The figure is a flow chart of sending and receiving emails within an enterprise in the email data encryption method of the present invention.
[0061] Figure 5 The figure is a flow chart of sending and receiving emails between enterprises in the email data encryption method of the present invention.
[0062] Figure 6 The figure is a flow chart of the process of sending and receiving emails between an enterprise and its branches / partners in the email data encryption method of the present invention.
[0063] Figure 7 The figure is a flow chart of the process of sending and receiving emails between an enterprise and an Internet user in the email data encryption method of the present invention.
[0064] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0065] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0066] An email data encryption gateway is a crucial component of enterprise email security, protecting email content from unauthorized third parties and ensuring only the intended recipient can read it. Email encryption involves the exchange of encryption keys. Through the paired use of public and private keys, emails cannot be read even if intercepted during transmission.
[0067] This invention provides an email data encryption gateway, encryption method, and application, designed to address security and compliance issues during email transmission. Using a national encryption algorithm to meet high-intensity security and policy compliance requirements, this invention ensures secure email transmission within, across enterprises, and across borders through data encryption and decryption, a certificate system, and transmission tunnel encryption. This eliminates the limitations of VPN tunnels and simplifies user operations. It implements source encryption of email content, ensuring the confidentiality and integrity of emails during transmission. This is achieved through the following technical solutions:
[0068] Dedicated email security communication protocol: uses national secret algorithms (such as SM2, SM3, SM4) to encrypt email content to ensure security during transmission.
[0069] Identity authentication module: through two-way certificate authentication, ensure that only authorized users can access email data.
[0070] Source encryption engine: encrypts email content at the source, so even if the email leaves the encryption tunnel, the content cannot be illegally obtained.
[0071] Certificate management: Supports the national secret X509 digital certificate mode to realize certificate generation, request and maintenance during the email sending and receiving process.
[0072] System architecture: Through modular design, it supports multiple deployment modes (such as series, parallel, load balancing, and dual-machine hot standby) to meet the needs of different enterprises.
[0073] like Figure 1 As shown, the present invention provides an email data encryption gateway, including a core service module, a management subsystem, a data scheduling bus, a domestically produced information and innovation basic platform, an extended service module, and a national secret password acceleration card. The data scheduling bus is respectively connected to the core service module, the management subsystem, the domestically produced information and innovation basic platform, the extended service module, and the national secret password acceleration card; the data scheduling bus is also respectively connected to the user management module, the administrator management module, the certificate management module, the service management module, the device management module, the system management module, the database, the key management module and the HAL interface, and the HAL interface is also connected to the national secret password acceleration card; the national secret password acceleration card supports the national secret encryption card for accelerating the encryption and decryption process, and supports the national secret encryption and decryption algorithms including SM2, SM3, and SM4.
[0074] 1. Core service module
[0075] The core service modules include a dedicated email security communication protocol, an identity authentication module, deep packet inspection, and a source encryption engine. The dedicated email security communication protocol ensures the security of emails during transmission. The identity authentication module verifies user identities, ensuring only authorized users can access the network through the gateway's client suite. Deep packet inspection detects potential threats in email content, such as malware or viruses. The source encryption engine encrypts email content using a national secret algorithm.
[0076] 2. Management platform and subsystems:
[0077] Front-end UI: User interface, used for daily management and maintenance of the system.
[0078] Management framework / middleware: Provides system management framework and middleware services for interaction between various subsystems.
[0079] User management: Perform operations such as adding, deleting, modifying, and querying user information, and support integration with existing user systems such as LDAP, AD, 4A, and other user systems.
[0080] Administrator management: To meet the requirements of information security, administrators' permissions and management user scope are divided.
[0081] Certificate management: Generate, request, apply for and maintain certificates used in the process of sending and receiving emails, as well as certificates required by the system itself.
[0082] Service management: Configure email-related services, such as viewing and analyzing the operating status of the service itself and the email server.
[0083] System management: manage and allocate other modules of the system.
[0084] 3. Email security gateway function
[0085] Support national secret standard SSLv1.1 protocol; support international algorithm SSL v3 / TLS1.0 / 1.1 / 1.2 / 1.3 protocol; support TLCP protocol, meet the "GB / T 38636-2020 Information Security Technology Transport Layer Cryptography Protocol"; national secret standard SSL follows GM / T 0028-2014 "Technical Requirements for Cryptographic Module Security"; supports encrypted transmission for three-layer IP protocol and four-layer TCP / UDP / ICMP protocol; supports IPv6 network protocol, supports IPv6 to IPv4, supports IPv4 to IPv6; tunnel supports acceleration using UDP transmission protocol; gateway supports remote push of multiple different routing strategies to different clients; gateway supports virtual NAT function to solve the problem of client grabbing intranet IP resources; gateway supports DHCP server function, which can automatically assign IP addresses to clients; supports RSA and SM2 simultaneous adaptation on one address port; supports SSL acceleration of TCP; supports DTLS protocol acceleration of UDP; supports forward SSL loading security proxy mode, converting HTTP protocol to HTTPS protocol; supports X-PID parsing and transparent transmission; supports HTTP diversion and forwarding based on X-PID; supports TCP Option to pass client IP; supports internal key generation and generation of CSR certificate request; supports file import / LDAP / HTTP CRL loading methods; supports mail proxy technology, supports mail forwarding and encryption and decryption processing; supports mail body encryption in ZIP format; supports mail storage timeliness configuration; supports mail ZIP encrypted package link and SMS gateway connection and sending, including password and title; supports ordinary mail automatic conversion to S / MIME encrypted mail, and S / MIME automatic decryption; supports software deployment, cloud deployment, and cloud encryption machine; supports passing certificates or certificate specified parameters to background services, including serial number, validity period, issuer, CN, and DN combination.
[0086] 4. Certificate management function
[0087] Supports user certificate system docking with RA platform; built-in national secret authentication hardware password card; supports national secret X509 digital dual certificate mode, supports international standard X.509 digital certificate; supports importing keys, certificates and PKCS12 format files; supports importing CFCA certificates and digital envelope formats; supports e-government CA and provincial CA certificates and digital envelope formats; supports extended national secret SM2 / SM3 / SM4 algorithms; supports AES256 / 512, RSA1024 / 2048 / 4096 and other international standard algorithms; multiple certificate chains can be configured in one service at the same time to verify user certificates of different CAs; built-in national secret CA certificate authentication and management center, which can issue digital certificates for itself and other nodes.
[0088] 5. Device management function
[0089] Supports using a National Security Browser to connect to management devices; supports using National Security Level 2 USBKEY bidirectional authentication mode to access the management system; supports synchronization of system configurations between devices; supports web-based system upgrades; supports local log viewing and remote syslog logging; supports SNMP functionality. It supports the separation of powers, assigning different roles to administrators and defining user operation permissions; supports the GM algorithm for log integrity protection and log level settings; supports console port diagnosis and management; and supports the collection of resource information such as CPU, memory, disk capacity, number of connections, and processes to facilitate system maintenance and problem location.
[0090] like Figure 2 As shown, the email data encryption gateway of the present invention utilizes secure encryption technology to build security protection capabilities in four areas: user authentication, data storage protection, data transmission protection, and password status monitoring. This modular third-party email data security solution is established. Through the independent deployment or arbitrary combination of multiple security products, from the overall construction of integrated email data security to the local transformation of outbound email data security, it meets the email data security needs of enterprises with different construction foundations and different scenarios, covering all scenarios of internal and external enterprise email data transmission and cross-border transmission.
[0091] like Figure 3 As shown, the present invention also provides an email data encryption method, which targets commonly used email sending and receiving scenarios of enterprises, performs differentiated processing according to different needs and scenarios, and meets the email security protection requirements under various network environments, organizational structures, and sending and receiving rules.
[0092] The email data encryption method provided by the present invention uses the email data encryption gateway described above, and the method includes:
[0093] S1. The sender uses email terminal A to edit the email content and enter the recipient's email address, and clicks the send button;
[0094] S2. The email arrives at the email data encryption gateway and is passed to the email server through the email security gateway. It is then passed to the recipient's email terminal B in different forms depending on the type of email sending and receiving. The types of email sending and receiving include sending and receiving emails within the enterprise, sending and receiving emails between enterprises, sending and receiving emails between enterprises and branches / partners, and sending and receiving emails between enterprises and Internet users.
[0095] In one embodiment, Figure 4 As shown, when the type of email sending and receiving is internal email sending and receiving within an enterprise, step S2 specifically includes:
[0096] S211: The email arrives at the email data encryption gateway and is passed to the email server through the email security gateway. The email server temporarily stores the email and waits for email terminal B to receive it.
[0097] S212. Email terminal B on the external network uses a client suite to automatically establish a dedicated national encryption transmission tunnel with the email data encryption gateway to receive emails. There are three main environments for internal employees to send and receive emails:
[0098] (1) In the enterprise intranet environment, emails can be sent and received directly without installing any additional software;
[0099] (2) In the external network environment, use the original VPN client to establish a tunnel for sending and receiving emails;
[0100] (3) In the external network environment, use the installed national encryption security kit to establish a national encryption transmission tunnel, and send and receive emails after two-way certificate authentication.
[0101] In one embodiment, Figure 5 As shown, when the type of email sending and receiving is inter-enterprise email sending and receiving, step S2 specifically includes:
[0102] S221: The email arrives at the email data encryption gateway of enterprise A and is passed through enterprise A's email security gateway to enterprise A's email server for temporary storage.
[0103] S222: When it is found that the email needs to be forwarded to the mailbox domain of enterprise B, it is immediately sent through the email data encryption gateway. The email data encryption gateway of enterprise A automatically establishes an encrypted tunnel with the email data encryption gateway of enterprise B and sends the email to the email data encryption gateway of enterprise B through the encrypted tunnel.
[0104] S213. The email data encryption gateway of enterprise B transmits it to the email server of enterprise B through the email security gateway of enterprise B, and the employees of enterprise B use email terminal B to receive the relevant emails.
[0105] In one embodiment, Figure 6 As shown, when the type of email sending and receiving is email sending and receiving between an enterprise and a branch / partner, step S2 specifically includes:
[0106] S231: The email arrives at the email data encryption gateway and is passed to the enterprise email server through the email security gateway;
[0107] S232. The mail server determines that the recipient belongs to an external domain and sends the mail to the gateway for delivery. The gateway finds through the user certificate synchronization platform / user certificate synchronization module that the address is a trusted address of the user certificate synchronization platform / user certificate synchronization module. The source of the certificate includes:
[0108] (1) The recipient provides the certificate to the sender, who then uploads the certificate as a file or has the IT administrator upload it to the user certificate synchronization platform / user certificate synchronization module;
[0109] (2) The sender directly applies for and downloads a certificate for the recipient in the certificate synchronization platform / user certificate synchronization module, or instructs the IT administrator to apply for a relevant certificate for someone;
[0110] S233. The email data encryption gateway determines that the recipient's email registration information is an S / MIME certificate user, and automatically encrypts the email content using the public key in the recipient's digital certificate and sends it to the recipient's email server. The branch / partner logs in to the email client B with S / MIME function, receives the email and automatically decrypts it to obtain the original content of the email.
[0111] In one embodiment, Figure 7 As shown, when the type of email sending and receiving is email sending and receiving between an enterprise and an Internet user, step S2 specifically includes:
[0112] S241. The enterprise employee's email terminal A automatically establishes a dedicated encrypted tunnel with the email data encryption gateway. The email arrives at the email data encryption gateway and is then delivered to the enterprise email server via the email security gateway.
[0113] S242: The email data encryption gateway finds that the email needs to be forwarded to another Internet mailbox. The email data encryption gateway determines that the address is not a safe recipient and automatically analyzes the email content. If there is no other sensitive information, the email is allowed to be forwarded and the content is recorded;
[0114] S243: The email data encryption gateway encrypts the email content and attachments, queries the mobile phone number corresponding to the email address, and sends the encryption password and email title to the mobile phone number via the SMS gateway;
[0115] S244. If there is no relevant corresponding mobile phone number in the query, an email message is returned to inform the user that there is no relevant mobile phone number to send the password, and the user is reminded to add the mobile phone number on the relevant system. The user can also upload the corresponding mobile phone number on the user platform in advance.
[0116] S245. The Internet user logs in to the mail client B and receives mails through the corresponding mail server according to the encryption password and mail title.
[0117] This invention is based on the integrated email data security product design, meeting the security needs of various email sending and receiving scenarios of enterprises:
[0118] 1. Provides a dedicated email security protocol, adopts national secret algorithms, complies with commercial cryptography certification qualifications, meets high-intensity security requirements and policy compliance, has a built-in national secret encryption card and encryption engine, provides national secret algorithms and post-quantum algorithms, and meets high-performance email encryption and decryption needs.
[0119] 2. Users in the security domain do not need to change their usage habits and do not need to install any clients or plug-ins.
[0120] 3. For emails sent outside the domain, if they are within the same security boundary (where this gateway is deployed), the mail servers will automatically use the security protocol to forward the communication, and the client will not be aware of it. For emails sent outside the domain to non-security boundaries, the mail server can automatically determine and take source protection measures, and process them through S / MIME or overall encapsulation encryption.
[0121] 4. Use deep packet inspection (DPI) to identify email domain addresses and message information, and detect plaintext emails.
[0122] 5. Supports multiple modes such as series and parallel connection, supports load balancing, and supports dual-machine hot standby; supports customized email security policies and sets the email system security level on demand; supports external email certificate synchronization and self-built CA certificate issuance and management; supports domestic hardware equipment and domestic operating systems.
[0123] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, apparatus, article, or method comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, apparatus, article, or method. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, apparatus, article, or method comprising the element.
[0124] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A mail data encryption gateway, characterized in that: It includes a core service module, a management subsystem, a data scheduling bus, a domestically-produced information innovation basic platform, an extended service module, and a national secret password acceleration card. The data scheduling bus is respectively connected to the core service module, the management subsystem, the domestically-produced information innovation basic platform, the extended service module, and the national secret password acceleration card; The data scheduling bus is also connected to the user management module, administrator management module, certificate management module, service management module, device management module, system management module, database, key management module and HAL interface respectively, and the HAL interface is also connected to the national secret password acceleration card.
2. The email data encryption gateway according to claim 1, characterized in that: The core service module includes a dedicated email security communication protocol, an identity authentication module, deep message inspection, and a source encryption engine. The dedicated email security communication protocol is used to ensure the security of emails during transmission; the identity authentication module is used to verify user identity to ensure that only authorized users can access the network through the gateway's client suite; the deep message inspection is used to detect potential threats in email content; and the source encryption engine is used to encrypt email content using a national secret algorithm.
3. The email data encryption gateway according to claim 1, characterized in that: The management subsystem includes a front-end UI and a management framework / middleware. The front-end UI is a user interface used for daily management and maintenance of the system; the management framework / middleware is used to provide a system management framework and middleware services for interaction between various subsystems.
4. The email data encryption gateway according to claim 1, wherein: The user management module is used to perform operations such as adding, deleting, modifying and checking user information, and supports the original user system; The administrator management module is used to meet the information requirements of security protection and divide the administrator's authority and management user scope; The certificate management module is used to generate, request, apply for and maintain certificates used in the process of sending and receiving emails and certificates required by the system itself; The service management module is used to configure email-related services, including viewing and analyzing the running status of the service itself and the email server; The system management module is used to manage and allocate other modules of the system.
5. The email data encryption gateway according to claim 1, characterized in that: The national secret password acceleration card supports the national secret encryption card for accelerating the encryption and decryption process, and supports the national secret encryption and decryption algorithms including SM2, SM3, and SM4.
6. A mail data encryption method, using the mail data encryption gateway according to any one of claims 1 to 5, characterized in that: The method comprises: S1. The sender uses email terminal A to edit the email content and enter the recipient's email address, and clicks the send button; S2. The email arrives at the email data encryption gateway and is passed to the email server through the email security gateway. It is then passed to the recipient's email terminal B in different forms depending on the type of email sending and receiving. The types of email sending and receiving include sending and receiving emails within the enterprise, sending and receiving emails between enterprises, sending and receiving emails between enterprises and branches / partners, and sending and receiving emails between enterprises and Internet users.
7. The mail data encryption method according to claim 6, characterized in that: When the type of email sending and receiving is internal email sending and receiving within an enterprise, step S2 specifically includes: S211: The email arrives at the email data encryption gateway and is passed to the email server through the email security gateway. The email server temporarily stores the email and waits for email terminal B to receive it. S212. Email terminal B on the external network uses a client suite to automatically establish a dedicated national encryption transmission tunnel with the email data encryption gateway to receive emails. There are three main environments for internal employees to send and receive emails: (1) In the enterprise intranet environment, emails can be sent and received directly without installing any additional software; (2) In the external network environment, use the original VPN client to establish a tunnel for sending and receiving emails; (3) In the external network environment, use the installed national encryption security kit to establish a national encryption transmission tunnel, and send and receive emails after two-way certificate authentication.
8. The mail data encryption method according to claim 6, characterized in that: When the type of email sending and receiving is inter-enterprise email sending and receiving, step S2 specifically includes: S221: The email arrives at the email data encryption gateway of enterprise A and is passed through enterprise A's email security gateway to enterprise A's email server for temporary storage. S222: When it is found that the email needs to be forwarded to the mailbox domain of enterprise B, it is immediately sent through the email data encryption gateway. The email data encryption gateway of enterprise A automatically establishes an encrypted tunnel with the email data encryption gateway of enterprise B and sends the email to the email data encryption gateway of enterprise B through the encrypted tunnel. S213. The email data encryption gateway of enterprise B transmits it to the email server of enterprise B through the email security gateway of enterprise B, and the employees of enterprise B use email terminal B to receive the relevant emails.
9. The mail data encryption method according to claim 6, characterized in that: When the type of email sending and receiving is email sending and receiving between an enterprise and its branches / partners, step S2 specifically includes: S231: The email arrives at the email data encryption gateway and is passed to the enterprise email server through the email security gateway; S232. The mail server determines that the recipient belongs to an external domain and sends the mail to the gateway for delivery. The gateway finds through the user certificate synchronization platform / user certificate synchronization module that the address is a trusted address of the user certificate synchronization platform / user certificate synchronization module. The source of the certificate includes: (1) The recipient provides the certificate to the sender, who then uploads the certificate as a file or has the IT administrator upload it to the user certificate synchronization platform / user certificate synchronization module; (2) The sender directly applies for and downloads a certificate for the recipient in the certificate synchronization platform / user certificate synchronization module, or instructs the IT administrator to apply for a relevant certificate for someone; S233. The email data encryption gateway determines that the recipient's email registration information is an S / MIME certificate user, and automatically encrypts the email content using the public key in the recipient's digital certificate and sends it to the recipient's email server. The branch / partner logs in to the email client B with S / MIME function, receives the email and automatically decrypts it to obtain the original content of the email.
10. The mail data encryption method according to claim 6, characterized in that: When the type of email sending and receiving is email sending and receiving between an enterprise and an Internet user, step S2 specifically includes: S241. The enterprise employee's email terminal A automatically establishes a dedicated encrypted tunnel with the email data encryption gateway. The email arrives at the email data encryption gateway and is then delivered to the enterprise email server via the email security gateway. S242: The email data encryption gateway finds that the email needs to be forwarded to another Internet mailbox. The email data encryption gateway determines that the address is not a safe recipient and automatically analyzes the email content. If there is no other sensitive information, the email is allowed to be forwarded and the content is recorded; S243. The email data encryption gateway encrypts the email content and attachments, queries the mobile phone number corresponding to the email address, and sends the encryption password and email title to the mobile phone number via the SMS gateway; S244. If there is no relevant corresponding mobile phone number in the query, an email message is returned to inform that there is no relevant mobile phone number to send the password, and a reminder is given to add a mobile phone number, or to upload the corresponding mobile phone number on the user platform in advance; S245. The Internet user logs in to the mail client B and receives mails through the corresponding mail server according to the encryption password and mail title.