Method for processing encrypted and decrypted email attachments by a mail server

The email server automatically decrypts encrypted email attachments by determining the recipient's decryption permissions and capabilities, solving the problem of external clients being unable to decrypt the emails and achieving transparent information security and convenient file retrieval.

CN122247963APending Publication Date: 2026-06-19GIGA BYTE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GIGA BYTE TECH CO LTD
Filing Date
2024-12-17
Publication Date
2026-06-19

Smart Images

  • Figure CN122247963A_ABST
    Figure CN122247963A_ABST
Patent Text Reader

Abstract

A mail server and a method for encrypting and decrypting email attachments are disclosed. The mail server can be used to decrypt a first email with an encrypted attachment sent by a sending end. The method includes: the mail server receiving the first email; the mail server reading the target receiving end of the first email; the mail server determining the target receiving end's decryption capability and decryption permission; if the target receiving end has decryption permission but no decryption capability, the mail server decrypts the encrypted attachment and obtains the original file; the mail server generating a second email based on the first email and the original file; and the mail server sending the second email to the target receiving end.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a computer device and a method for processing emails, and more particularly to a mail server and a method for encrypting and decrypting email attachments. Background Technology

[0002] The rise of the internet has significantly reduced communication costs. Email, in particular, provides end-to-end communication. For businesses, email allows them to send information or responses to customers. Due to information security concerns, companies often require employees to install transparent encryption software. When the recipient reads the email, this software automatically decrypts encrypted attachments. Therefore, internal employee email exchanges do not require decryption.

[0003] However, for external clients, not all of them have transparent encryption / decryption software installed. Therefore, when a client receives an encrypted attachment, it needs to reply to the sender requesting the corresponding software. Summary of the Invention

[0004] In view of this, in one embodiment, the mail server can be used for decryption processing of a first email with encrypted attachments sent by a sending end. The mail server includes a communication unit, a storage unit, and a processing unit. The communication unit is network-connected to the sending end and the target receiving end, and the first email records the sending end, the target receiving end, and a preset receiving end; the storage unit stores an email transmission program and a management program, and the preset receiving end is matched with the management program; the processing unit is connected to the communication unit and the storage unit, and the processing unit executes the email transmission program and the management program. The email transmission program drives the communication unit to transmit the first email to the target receiving end and the preset receiving end. The management program reads the target receiving end from the first email, and the management program determines the decryption capability and decryption permission of the target receiving end. If the target receiving end meets the decryption permission but has no decryption capability, the management program decrypts the encrypted attachment and obtains the original file. The management program generates a second email based on the first email and the original file, and the email transmission program drives the communication unit to transmit the second email to the target receiving end.

[0005] The mail server can determine the decryption permissions and capabilities of the target recipient, thus providing the decrypted original file to the recipient. For internal or external clients, the client does not need to install additional encryption / decryption software to obtain the original file. Besides achieving information security, it also achieves transparent encryption / decryption processing.

[0006] In one embodiment, the mail server includes a communication unit, a storage unit, and a processing unit. The communication unit is network-connected to the sending end and the target receiving end, and a first email record is stored between the sending end and the target receiving end. The storage unit stores an email transmission program and a management program. The processing unit is connected to the communication unit and the storage unit. The processing unit executes the email transmission program and the management program. The email transmission program drives the communication unit to transmit the first email to the target receiving end. The management program reads the target receiving end from the first email and determines the target receiving end's decryption capability and decryption permission. If the target receiving end meets the decryption permission requirements but has no decryption capability, the management program decrypts the encrypted attachment and obtains the original file. The management program generates a second email based on the first email and the original file. The email transmission program drives the communication unit to transmit the second email to the target receiving end.

[0007] In one embodiment, the method for encrypting and decrypting email attachments includes: a mail server receiving a first email; the mail server reading the target recipient of the first email; the mail server determining the decryption capability and decryption permission of the target recipient; if the target recipient has the decryption permission but no decryption capability, the mail server decrypting the encrypted attachment and obtaining the original file; the mail server generating a second email based on the first email and the original file; and the mail server sending the second email to the target recipient.

[0008] The mail server and its method for handling encrypted and decrypted email attachments provide transparent encryption and decryption, allowing the receiving end to obtain the original file without needing to install additional encryption / decryption software. Furthermore, the mail server can update the encryption / decryption software in real time, ensuring that the target recipient receives the original file. Attached Figure Description

[0009] Figure 1 This is a schematic diagram of an email system according to an embodiment.

[0010] Figure 2 This is a schematic diagram of the architecture of a mail server according to one embodiment.

[0011] Figure 3 This is a schematic diagram illustrating the encryption and decryption process of an email in one embodiment.

[0012] Figure 4 This is a schematic diagram of a first email and an encrypted attachment in one embodiment.

[0013] Figure 5 This is a schematic diagram of a second email and the original file in one embodiment.

[0014] Figure 6 This is a schematic diagram of the architecture of a mail server according to another embodiment.

[0015] Figure 7 This is a schematic diagram of a first email and an encrypted attachment, representing another embodiment.

[0016] Figure 8 This is a schematic diagram illustrating the transmission of emails to multiple target terminals in one embodiment.

[0017] The reference numerals in the attached figures are explained as follows:

[0018] 100: Mail Server

[0019] 110: Communication Unit

[0020] 120: Storage unit

[0021] 121: Mail Transfer Program

[0022] 122: Management Procedures

[0023] 123: Encryption / Decryption Program

[0024] 130: Processing Unit

[0025] 200: Client

[0026] 210: Sending end

[0027] 211: Automatic Programs

[0028] 221: Target Receiving End

[0029] 222: Preset receiver

[0030] 310: First Email

[0031] 320: Second Email

[0032] 410: Encrypted Attachment

[0033] 420: Original document

[0034] A, B, C: Target End

[0035] S310, S320, S330, S340, S350, S360, S370: Steps Detailed Implementation

[0036] Please refer to Figure 1 and Figure 2The figures shown are schematic diagrams of an email system and an email server architecture, respectively, according to an embodiment. The email system includes a email server 100 and multiple clients 200. Clients 200 are connected to the email server 100 via a local area network, the Internet, or a mobile communication network. Any client 200 can send emails to other clients 200. For ease of distinction, the client 200 that sends emails will be referred to as the sending end 210, and the client 200 that receives emails will be referred to as the target receiving end 221. In this embodiment, the email server 100 can also be a receiving end, therefore the receiving end of the email server 100 will be referred to as the preset receiving end 222.

[0037] The sending terminal 210 can send a first email 310 to the mail server 100 using existing email software, such as Microsoft Outlook, Mozilla Thunderbird, or Apple Mail. The first email 310 contains at least information about the sending terminal 210, the target receiving terminal 221, and the preset receiving terminal 222. The sending terminal 210 has an original file 420 and an encryption / decryption program 123. The sending terminal 210 can optionally add attachments to the first email 310, hereinafter referred to as the original file 420. The original file 420 can be an unencrypted file or an encrypted file. The encrypted file will be referred to as the encrypted attachment 410.

[0038] For internal client 200s, each client 200 may be required to install a specified encryption / decryption program 123. However, for external client 200s, the corresponding encryption / decryption program 123 may not be installed. Therefore, the target receiving end 221 may lack the ability or permission to decrypt the encrypted attachment 410. For example, the target receiving end 221 may have the corresponding encryption / decryption program 123 installed, but it may not have received the decryption key. Therefore, the target receiving end 221 may only have decryption capability but not decryption permission. The mail server 100 decides whether to send the first email 310 or the second email 320 to the target receiving end 221 based on the encrypted attachment 410, and the relevant operation will be described in detail later.

[0039] The mail server 100 includes a communication unit 110, a storage unit 120, and a processing unit 130. The processing unit 130 is electrically connected to the communication unit 110 and the storage unit 120. The communication unit 110 is network-connected to the sending end 210 and the target receiving end 221. The communication unit 110 transmits emails to the corresponding client 200. The storage unit 120 stores a mail transmission program 121, a management program 122, and an encryption / decryption program 123. The encryption / decryption program 123 of the mail server 100 matches the encryption / decryption program 123 of the sending end 210.

[0040] Email transmission program 121 is used to transmit emails to a designated target recipient 221. Management program 122 is used to determine whether the target recipient 221 has decryption capabilities and permissions. Furthermore, management program 122 is also matched with a preset recipient 222. Therefore, management program 122 can obtain relevant information about the first email 310, such as information about the target recipient 221, through the preset recipient 222. Management program 122 can create a relevant lookup table. The lookup table records the decryption capabilities and permissions of each client 200, or the version information of the encryption / decryption program 123 of the client 200.

[0041] For a clearer explanation of how management procedure 122 works, please refer to [link / reference]. Figure 3 This is a schematic diagram illustrating the encryption and decryption process of an email in one embodiment. The method for processing email attachments includes the following steps:

[0042] Step S310: The first email is received by the mail server;

[0043] Step S320: The mail server reads the target recipient of the first email;

[0044] Step S330: The mail server determines the decryption capability and decryption permission of the target receiving end;

[0045] Step S340: If the target receiving end has decryption permissions but no decryption capability, the mail server decrypts the encrypted attachment and obtains the original file;

[0046] Step S350: The mail server generates a second email based on the first email and the original file;

[0047] Step S360: The mail server sends the second email to the target recipient; and

[0048] Step S370: If the target receiving end does not have decryption permissions, the management program will not generate the original file.

[0049] First, the sending end 210 sends the first email 310 to the mail server 100 (corresponding to step S310). Generally, the first email 310 includes at least one target receiving end 221. The email transmission program 121 can send the email to the corresponding target receiving end 221 according to the information contained in the first email 310. Please refer to [reference needed]. Figure 4 During the email transmission process 121, the management program 122 can synchronously read the target receiving terminal 221 (corresponding to step S320) and determine whether the target receiving terminal 221 has decryption capability and decryption permission (corresponding to step S330). Figure 4 Enter the target recipient 221, "Account A", in the recipient field, and enter the default recipient 222, "Account XXX", in the copy field.

[0050] If the management program 122 determines that the target receiving terminal 221 has the decryption permission for the encrypted attachment 410, and the target receiving terminal 221 does not have the decryption capability, the management program 122 calls the corresponding encryption / decryption program 123 to decrypt the encrypted attachment 410 and obtain the original file 420 (corresponding to step S340). If the management program 122 determines that the target receiving terminal 221 has the decryption permission and the target receiving terminal 221 has the decryption capability, the management program 122 does not need to decrypt the encrypted attachment 410. That is, the management program 122 does not generate the original file 420.

[0051] Management program 122 generates a second email 320 based on the first email 310 and the original file 420 (corresponding to step S350). Generally, management program 122 can generate a second email 320 by adding the original file 420 to the first email 310. Please refer to [reference needed]. Figure 5 The management program 122 sends the second email 320 to the target receiving terminal 221 via the email transmission program 121 (corresponding to step S360). The target receiving terminal 221 will receive the first email 310 and the second email 320 respectively. Figure 5 In this implementation, a link to a network file is used as the original file 420. In other embodiments, the original file 420 may also be a separate file. Alternatively, the management program 122 may perform a second encryption process based on another encryption / decryption program 123 specified by the target receiving end 221. For example, the version of the encryption / decryption program 123 used by the target receiving end 221 may be lower than the version number of the encryption / decryption program 123 used by the sending end 210. The management program 122 can determine that the target receiving end 221 has decryption permissions but lacks decryption capabilities. The management program 122 encrypts the encrypted attachment 410 using the version of the encryption / decryption program 123 compatible with the target receiving end 221 and generates a second email 320.

[0052] In some embodiments, if the management program 122 determines that the target receiving terminal 221 does not have decryption permissions, the management program 122 will not generate the original file 420 (corresponding to step S370). Furthermore, if the management program 122 determines that the target receiving terminal 221 does not have decryption permissions and lacks decryption capabilities, the management program 122 may send a warning notification (without a number) to the sending terminal 210, thereby notifying the sending terminal 210 whether the first email 310 has been mistakenly sent to other personnel.

[0053] In some embodiments, to prevent information security risks arising from users without encryption / decryption permissions forwarding the encrypted attachment 410 to others for decryption, the management program 122 may also determine whether the sending end 210 has encryption / decryption permissions. If the sending end 210 does not have encryption / decryption permissions, the management program 122 does not need to execute steps S340 to S360.

[0054] In some embodiments, the sending terminal 210 also has an automatic program 211, please refer to Figure 6 When the sending terminal 210 sends the first email 310, the automatic program 211 can automatically add the preset receiving terminal 222 to the first email 310. The automatic program 211 can be a standalone application, a function built into email software, an email plugin, or even a service that uses Simple Mail Transfer Protocol (SMTP) to customize email forwarding logic. The preset receiving terminal 222 is matched with the management program 122.

[0055] In other words, the first email 310 can be sent to the target recipient 221 and also received by the management program 122. Therefore, after receiving the first email 310, the management program 122 reads the target recipient 221 from the first email 310 and executes steps S350 to S360. In this embodiment, the management program 122 determines whether the target recipient 221 of the first email 310 belongs to a specified unit, such as a specified person, department, company, or related group. If it matches, the preset recipient 222 is automatically added to the first email 310, for example, by adding it to the Blind Carbon Copy (BCC) field. In this way, the sender does not need to manually add the preset recipient 222, and the inconvenience and time-consuming process of repeated confirmation of emails caused by the user forgetting to add the preset recipient 222 is also avoided.

[0056] In some embodiments, the first email 310 has multiple target recipients 221, please refer to... Figure 7The management program 122 generates corresponding original files 420 based on different target receiving terminals 221 and encrypted attachments 410. The management program 122 checks the decryption permissions and capabilities of each target receiving terminal 221. After obtaining the original file 420, the management program 122 decides whether to attach the original file 420 based on the decryption permissions and capabilities of each target receiving terminal 221, thereby generating a second email 320.

[0057] For example, the first email 310 contains three target recipients 221, hereinafter referred to as target A, target B, and target C. The decryption permissions and capabilities of target A, B, and C are shown in the table below:

[0058] Decryption permission Decryption capability Target A conform to have Target B conform to none Target C Does not meet none

[0059] After mail server 100 receives the first email 310, mail transmission program 121 sends the first email 310 to target terminals A, B, and C. Simultaneously, management program 122 retrieves the first email 310 and queries the decryption permissions and capabilities of target terminals A, B, and C. (Please refer to...) Figure 8 Since target A has decryption permissions and the ability to decrypt, management program 122 does not need to send the second email 320 to target A. In contrast, target B has decryption permissions but does not have decryption capabilities. Therefore, management program 122 executes encryption / decryption program 123 and retrieves the original file 420 from the encrypted attachment 410. Management program 122 generates the second email 320 based on target B, the first email 310, and the original file 420. Email transmission program 121 sends the second email 320 to target B. Therefore, target B will receive the first email 310 and the second email 320 at different times. Since target C does not have decryption permissions, management program 122 will not decrypt the encrypted attachment 410.

[0060] In some embodiments, the mail server 100 processes the first email 310 and the encrypted attachment 410 according to the following process. The components of the mail server 100 can be referenced... Figure 2 The sending terminal 210 sends a first email 310, which includes a target receiving terminal 221 and an encrypted attachment 410. After receiving the first email 310, the email transmission program 121 sends the first email 310 to the target receiving terminal 221. The processing unit 130 drives the management program 122 to parse the content of the first email 310 in order to obtain the target receiving terminal 221 and the encrypted attachment 410 from the first email 310.

[0061] The management program 122 can be a standalone application or embedded in the email transfer program 121. For ease of explanation, the two functions will be described as email transfer program 121 and management program 122 respectively. However, in practice, the email transfer program 121 can also parse the content of the first email 310 to obtain the target recipient 221 and the encrypted attachment 410.

[0062] Management program 122 determines whether the target receiving terminal 221 has decryption permissions and capabilities. If the target receiving terminal 221 has decryption permissions but lacks decryption capabilities, management program 122 will decrypt the encrypted attachment 410 to obtain the corresponding original file 420. Management program 122 can add the original file 420 to the first email 310 to generate the second email 320. Management program 122 can also generate a link to a corresponding cloud file based on the original file 420. Management program 122 adds the link to the first email 310 to generate the second email 320. When management program 122 determines that the target receiving terminal 221 does not have decryption permissions, management program 122 will not decrypt the encrypted attachment 410.

[0063] In some embodiments, when the first email 310 has multiple target recipients 221, the management program 122 determines whether to transmit the decrypted original file 420 to the target recipients 221 based on the decryption permissions and decryption capabilities of the different target recipients 221. For example... Figure 8 According to the description, the management program 122 will provide a second email 320 to the target receiving terminal 221 that has decryption privileges but does not have decryption capabilities.

[0064] The mail server 100 and its method for handling encrypted and decrypted email attachments provide transparent encryption and decryption processing, so the receiving end does not need to install additional encryption / decryption programs 123 to obtain the original file 420. Furthermore, the mail server 100 can update the encryption / decryption programs 123 in real time to ensure that the target receiving end 221 can obtain the original file 420.

Claims

1. A mail server, used for decryption processing of a first email with an encrypted attachment sent by a sending end, characterized in that, The mail server includes: A communication unit, a network connection between the sending end and a target receiving end, the first email record of the sending end, the target receiving end and a preset receiving end; A storage unit stores an email transmission program and a management program, the preset receiving end being matched with the management program; and A processing unit is connected to the communication unit and the storage unit. The processing unit executes the email transmission program and the management program. The email transmission program drives the communication unit to transmit the first email to the target receiving end and the preset receiving end. The management program reads the target receiving end from the first email. The management program determines the decryption capability and decryption permission of the target receiving end. If the target receiving end meets the decryption permission but does not have the decryption capability, the management program decrypts the encrypted attachment and obtains an original file. The management program generates a second email based on the first email and the original file. The email transmission program drives the communication unit to transmit the second email to the target receiving end.

2. The mail server as described in claim 1, characterized in that, If the management program determines that the target receiving end does not have the required decryption permissions, the management program will not generate the original file.

3. The mail server as described in claim 1, characterized in that, The first email has multiple target recipients. The management program generates a corresponding second email based on the different target recipients and the encrypted attachment. The email transmission program drives the communication unit to send multiple second emails to the corresponding target recipients.

4. The mail server as described in claim 1, characterized in that, The sending end has an automatic program that sends the first email and adds the preset receiving end to the first email.

5. The mail server as described in claim 1, characterized in that, If the management program determines that the target receiving end does not have the decryption permission and capability, the management program will send a warning notification to the sending end.

6. A mail server, characterized in that, A decryption process applied to a sender sending a first email with an encrypted attachment, the email server comprising: A communication unit, a network connection between the sending end and a target receiving end, the first email record of the sending end and the target receiving end; A storage unit stores an email transmission program and a management program; and A processing unit is connected to the communication unit and the storage unit. The processing unit executes the email transmission program and the management program. The email transmission program drives the communication unit to transmit the first email to the target receiving end. The management program reads the target receiving end from the first email. The management program determines the target receiving end's decryption capability and decryption permission. If the target receiving end meets the decryption permission but does not have the decryption capability, the management program decrypts the encrypted attachment and obtains an original file. The management program generates a second email based on the first email and the original file. The email transmission program drives the communication unit to transmit the second email to the target receiving end.

7. The mail server as described in claim 6, characterized in that, If the management program determines that the target receiving end does not have the required decryption permissions, the management program will not generate the original file.

8. The mail server as described in claim 6, characterized in that, The first email has multiple target recipients. The management program generates a corresponding second email based on the different target recipients and the encrypted attachment. The email transmission program drives the communication unit to send multiple second emails to the corresponding target recipients.

9. The mail server as described in claim 6, characterized in that, If the management program determines that the target receiving end does not have the decryption permission and capability, the management program will send a warning notification to the sending end.

10. A method for processing encrypted and decrypted email attachments, applied to the decryption of an encrypted attachment in a first email, characterized in that, The methods for handling encrypted and decrypted email attachments include: The first email is received by a mail server; The mail server reads a target recipient of the first email; The mail server determines the target recipient's decryption capability and decryption permission. If the target receiving end has the decryption permission but not the decryption capability, the mail server decrypts the encrypted attachment and obtains the original file. The mail server generates a second email based on the first email and the original file; and The mail server sends the second email to the target recipient.

11. The method for processing encrypted / decrypted email attachments as described in claim 10, characterized in that, The process before the mail server forwards the first email to the target recipient includes: The mail server determines that the first email has multiple target recipients; The mail server generates a second email corresponding to the encrypted attachment based on the different target recipients; and The mail server sends multiple copies of the second email to the corresponding target recipient.

12. The method for processing encrypted / decrypted email attachments as described in claim 10, characterized in that, The process before the mail server forwards the first email to the target recipient includes: The mail server obtains a preset recipient from the first email; The mail server determines the decryption capability and decryption permission of the target mail receiver based on the preset receiving end. The mail server generates the second email based on the target recipient; and The mail server sends the second email to the target recipient.

13. The method for processing encrypted / decrypted email attachments as described in claim 10, characterized in that, The steps by which the mail server determines the decryption capability and decryption permission of the target recipient also include: The mail server determines that the target recipient does not have the required decryption permissions, and therefore does not generate the original file.