Mail conversion processing device and its operating method for safely transferring mail with large file attachments from an internal network to an external network in an internal network separation security network

The email conversion processing device safely transfers large files from an internal network to an external network by identifying and inserting them into a converted email, addressing the limitations of current systems and ensuring secure data transfer.

JP7799263B2Active Publication Date: 2026-01-15KIWONTECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023555124
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-04-28
Filing Date
2022-11-25
Publication Date
2026-01-15
Estimated Expiration
2042-11-25

AI Technical Summary

Technical Problem

Current email systems fail to safely transfer large files from an internal network-separated security network to an external network, causing inconvenience and security risks, especially when users resort to cloud file sharing services which lack control over data dissemination.

Method used

An email conversion processing device and method that identifies and downloads large files from an internal network, inserts them into a converted email, and transfers it through a network-linked approval process to an external network, ensuring security and compliance with preset policies.

Benefits of technology

Enables safe transfer of large files from an internal network to an external network via an encrypted email system, avoiding cloud sharing services and maintaining network security, allowing secure export of large file data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007799263000001
    Figure 0007799263000001
  • Figure 0007799263000002
    Figure 0007799263000002
  • Figure 0007799263000003
    Figure 0007799263000003
Patent Text Reader

Abstract

An operating method of an email processing device according to an embodiment of the present invention is an operating method of an email processing device located in an internal network of a security network separated from an external network, and includes the steps of: acquiring a forwarded email requested for forwarding from a sender device located in the internal network; identifying link information of a large-capacity file located in the internal network from the forwarded email; acquiring the large-capacity file located in the internal network based on the link information; generating a converted email in which the large-capacity file is inserted so that it is sorted into a general attachment of the forwarded email; and transferring the converted email to an email restoration processing device located in the external network via a network linkage approval device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a mail conversion processing device and an operating method thereof, and more particularly to a mail conversion processing device and an operating method thereof for safely transferring mail with large file attachments from an internal network separated security network to an external network. [Background technology]

[0002] In today's society, with the development of computers and information and communication technology worldwide, dependence on cyberspace is increasing in all areas of social life, and this trend is accelerating. In recent years, 5G mobile communications, which boasts ultra-high speeds, ultra-low latency, and multiple simultaneous connections, has been commercialized, and as new services based on this technology have emerged, cybersecurity systems have become even more important.

[0003] Along with the construction of cybersecurity systems, technological fields such as the Internet of Things (IoT), cloud systems, big data, and artificial intelligence (AI) are combining with information and communication technology to provide new service environments. Systems that provide such services can be used in real life by connecting to PCs or mobile terminal devices via the Internet or wireless networks.

[0004] In particular, email systems, which are utilized in information and communication technology, can provide electronic mail services that include text content so that users can exchange messages using communication lines through computer terminals. At this time, emails can be accompanied by electronic files containing the content to be shared, or a Uniform Resource Locator (URL) can be included in the text or in the attached file.

[0005] In particular, such a uniform resource locator is useful for transferring large files. Typically, a mail service server supports temporary storage of large files and supports generating an arbitrary encrypted URL for downloading the temporarily stored large file and assigning it to an email, so that the recipient of the email can easily download the large file by connecting to the URL described in the email.

[0006] However, in recent years, security risks associated with the exchange of e-mail and documents have increased, and as a result, an increasing number of security systems have been constructed in which the document transfer system is separated into an internal network and an external network (external network), and the transfer of such large files is generally blocked. For example, devices permitted to access the internal network can only send and receive confidential documents such as large files between internal devices, and the transfer of documents such as large files to external networks is blocked.

[0007] As a result, when a user connected to the internal network sends an email to a terminal located on an external network, only ordinary files that can be included in the email data can be attached, and not only is the transmission of internal network resource information linked to large files blocked, but even if a user on the external network obtains the URL of the internal network, they cannot download the file because the network is blocked and access to it is not possible.

[0008] In other words, although the security of mail server systems has been strengthened to date through the development of various security standard technologies, research into spam filtering, and advanced encryption methods, there is currently no way to transmit large files located in an internal network-separated security network to an external network.

[0009] Although such current systems are effective in protecting the network itself by separating the internal network from the external network and blocking the transmission of information itself, they have the problem of causing many inconveniences in actual use.

[0010] As a result, with conventional email transfer methods, there is no way to specify a route for large files located on an internal network and transmit them to an external network via email. To avoid this, users may turn to new services such as cloud file sharing services to share large files on an external network.

[0011] However, cloud file sharing services have the purpose of sharing and disseminating data, which poses a critical security problem: if a large confidential file is accidentally exposed to a third party other than the intended user, there is no way to prevent the confidential data from being publicly disseminated. Summary of the Invention [Problem to be solved by the invention]

[0012] The present invention has been devised to solve the above-mentioned problems, and provides an email conversion processing device and an operating method thereof for safely transferring emails with large file attachments from an internal network in an internal network separation security network to an external network, thereby enabling emails containing large files located on the internal network to be safely transmitted to users of the external network through an encrypted email system, and therefore, an object of the present invention is to realize a network-linked email service that enables the safe export of large file data from an internal network to an external network without using a circumvention process such as a cloud file sharing service. [Means for solving the problem]

[0013] To solve the above-mentioned problems, the operating method of an email processing device located in an internal network of a security network separated from an external network of the present invention includes the steps of: acquiring a forwarded email requested for forwarding from a sender device located in the internal network; identifying link information of a large-capacity file located in the internal network from the forwarded email; acquiring the large-capacity file located in the internal network based on the link information; generating a converted email in which the large-capacity file is inserted so that it is sorted into a general attachment of the forwarded email; and transferring the converted email to an email restoration processing device located in the external network via a network linkage approval device.

[0014] In order to solve the above-mentioned problems, an apparatus according to an embodiment of the present invention is an email processing apparatus located in an internal network of a security network separated from an external network, and includes: an internal network link identification unit that, when receiving a forwarding email requested for forwarding from a sender device located in the internal network, identifies link information of a large-capacity file located in the internal network from the forwarding email; a target file download processing unit that obtains the large-capacity file located in the internal network based on the link information; a general attachment email conversion processing unit that generates a converted email in which the large-capacity file is inserted so that it is sorted into a general attachment file of the forwarding email; and a converted email forwarding unit that forwards the converted email to an email restoration processing apparatus located in the external network via a network link approval device. [Effects of the Invention]

[0015] According to an embodiment of the present invention, a large file located in the internal network is obtained from a forwarding email requested for forwarding from a sender device located in the internal network, a converted email is generated in which the large file is inserted so that it can be sorted into a general attachment of the forwarding email, and the converted email can be processed to be forwarded to a mail restoration processing device located in the external network via a network linkage approval device.

[0016] Therefore, according to an embodiment of the present invention, an email conversion process can be performed to safely transfer emails with large file attachments within an internal network in an internal network separation security network to an external network, and this process allows emails containing large files located on the internal network to be safely transmitted to users on the external network through the security email system and restored.

[0017] Therefore, according to an embodiment of the present invention, it is possible to implement a network-linked mail service that enables the safe export of large-capacity file data within an internal network to an external network without using a bypass process such as a cloud file sharing service. [Brief explanation of the drawings]

[0018] [Figure 1] 1 is a conceptual diagram illustrating an overall system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram for more specifically explaining a mail conversion processing device according to an embodiment of the present invention. [Figure 3] 1 is a block diagram for more specifically explaining a mail recovery processing device according to an embodiment of the present invention; [Figure 4] FIG. 2 is a ladder diagram for explaining the overall system operation according to an embodiment of the present invention. [Figure 5] 4 is a flowchart illustrating the operation of the mail conversion processing device according to the embodiment of the present invention. [Figure 6]10 is a flowchart illustrating the operation of a recipient terminal that receives a mail in the mail restoration processing device according to the embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0019] The following merely exemplifies the principles of the present invention. Therefore, those skilled in the art will be able to devise various devices and methods that embody the principles of the present invention and fall within the concept and scope of the present invention, even if not explicitly described or illustrated herein. Furthermore, all conditional terms and embodiments listed in this specification are expressly intended solely for the purpose of helping to understand the concept of the present invention, and should not be understood as being limited to the embodiments and conditions specifically listed in this specification.

[0020] Furthermore, all detailed descriptions reciting specific embodiments as well as principles, aspects, and embodiments of the present invention should be understood to be intended to encompass structural and functional equivalents of such items, and these equivalents should be understood to include not only currently known equivalents but also equivalents developed in the future, i.e., all elements invented to perform the same function, regardless of structure.

[0021] Thus, for example, the block diagrams herein should be understood to represent conceptual views of illustrative circuitry embodying the principles of the invention. Likewise, all flowcharts, state change diagrams, pseudocode, and the like, may be substantially represented on a computer-readable medium and should be understood to represent various processes performed by a computer or processor, whether or not a computer or processor is explicitly illustrated.

[0022] Additionally, the explicit use of terms such as processor, control, or similar concepts should not be construed as exclusively referring to hardware capable of executing software, but should be understood to implicitly include, without limitation, digital signal processor (DSP) hardware, ROM, RAM, and non-volatile memory for storing software. Other hardware known and commonly used may also be included.

[0023] The above-mentioned objects, features, and advantages will become more apparent through the following detailed description taken in conjunction with the accompanying drawings, so that those skilled in the art can easily implement the technical concept of the present invention. Furthermore, when it is determined that a detailed description of well-known technologies related to the present invention may unnecessarily obscure the gist of the present invention, the detailed description will be omitted.

[0024] The terms used in this application are merely used to describe specific embodiments and are not intended to limit the present invention. The singular expressions include the plural expressions unless the context clearly dictates otherwise. In this application, the terms "comprise" or "have" and the like are intended to specify the presence of features, numbers, steps, operations, components, parts, or combinations thereof described in the specification, and should be understood not to preclude the presence or possibility of addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0025] Hereinafter, preferred embodiments of the present invention will be described in more detail with reference to the accompanying drawings. In order to facilitate overall understanding, the same components in the drawings will be designated by the same reference numerals, and redundant descriptions of the same components will be omitted.

[0026] The term "mail" used in this specification can be used to refer to electronic mail, web mail, electronic mail, electronic mail, etc., which are sent and received by users via a computer communication network through a terminal device and a client program or website installed thereon.

[0027] FIG. 1 is a conceptual diagram illustrating a schematic overall system according to an embodiment of the present invention.

[0028] Referring to Figure 1, a system according to one embodiment of the present invention includes a sender terminal 10, a first email management server device 300, an email conversion processing device 100, a network-linked email approval device 500, an email restoration processing device 200, a second email management server device 400, and a recipient terminal 20.

[0029] More specifically, the sender terminal 10, the first mail management server device 300, and the mail conversion processing device 100 can constitute an isolated security network as an internal network. The isolated security network is a network in which mail cannot be transferred to an external network unless it goes through the network-linked mail approval device 500, and for this purpose, an encrypted internal network and security device based on a variety of network interface environments can be constructed.

[0030] For this purpose, the network-linked email approval device 500 receives an approval request for email data to be transferred to an external network from a first email management server device 300 that constructs an email server on an internal network, and can export only emails that have been approved and security-verified by comparing them with a pre-set approval policy to a second email management server device 400 or the like via the external network.

[0031] Here, the preset approval policy may be a combination of various policies that may be applied to confirm approval, such as checking administrator authentication information, checking the approval of a superior in the organization corresponding to the sender, and inspecting whether the email data has security vulnerabilities.

[0032] Conversely, when an external email from an external user is received by the internal network through the second email management server device 400 on the external network, the network-linked email approval device 500 can perform security checks on the attachments and URLs of the external email, and can process only verified emails into the internal network.

[0033] Unlike the operation of the internal network system and the network-linked email approval device 500, the email recovery processing device 200, the second email management server device 400, and the recipient terminal 20 located in the external network can be connected to a public network via at least one of wired and wireless connections to transmit and receive data. The public network is a communication network constructed and managed by the government or a telecommunications carrier, and generally includes a telephone network, a data network, a CATV network, a mobile communication network, etc., and can provide a connection service so that an unspecified number of ordinary people can connect to other communication networks or the Internet.

[0034] Meanwhile, the forwarder terminal 10, the first email management server device 300, the email conversion processing device 100, and the network-linked email approval device 500 may each include a communication module for communicating using a first protocol corresponding to the internal network.

[0035] In addition, the network-linked email approval device 500, email recovery processing device 200, second email management server device 400, and recipient terminal 20 may each include a communication module for communicating with an external network using a second protocol corresponding to the external network.

[0036] In this way, each internal network separation security network and each device constituting the external network can be connected to each other through wired and wireless networks, and devices or terminals connected to each network can communicate with each other through mutually encrypted network channels.

[0037] Here, each of the networks may be implemented as various wired or wireless networks such as a local area network (LAN), a wide area network (WAN), a value added network (VAN), a personal area network (PAN), a mobile radio communication network, or a satellite communication network.

[0038] Furthermore, the sender terminal 10 and the receiver terminal 20 described in this specification may include a personal computer, a laptop computer, a mobile phone, a tablet PC, a PDA (Personal Digital Assistant), a PMP (Portable Multimedia Player), etc. However, the present invention is not limited to these and may include various devices that can be connected to the first mail management server device 300 or the second mail management server device 400 via an internal network, a public network, a private network, etc. In addition, each of the sender terminal 10 and the receiver terminal 20 may be various devices that can input and output information through application driving or web browsing.

[0039] In addition, each of the first mail management server device 300 and the second mail management server device 400 includes a system that relays and stores the contents of e-mail so that users can send e-mails created by them and receive e-mails created by other parties, and can communicate between devices using a pre-set e-mail protocol according to the intended use of receiving and sending e-mails.

[0040] Typically, the mail protocol can use POP3 (Post Office Protocol 3) or IMAP (Internet Message Access Protocol) when receiving mail. Furthermore, the protocol can use SMTP (Simple Mail Transfer Protocol) or EML (Electronic Mail) when sending mail. Thus, each of the first mail management server device 300 and the second mail management server device 400 is configured as a server system for mail sending and receiving processing within its own separate network, and can operate independently.

[0041] In such a system configuration, the mail conversion processing device 100 according to an embodiment of the present invention can be located in an internal network of a security network isolated from an external network, and can process the function of converting e-mails containing link information of large files located in the isolated internal network and transmitting them to the mail restoration processing device 200 in the external network with the approval of the network-linked mail approval device 500.

[0042] To this end, the mail conversion processing device 100 can first obtain a forwarded mail requested for forwarding from a sender terminal 10 located in the internal network through the first mail management server device 300, identify link information of a large-capacity file located in the isolated internal network from the forwarded mail, and obtain the large-capacity file located in the isolated internal network based on the link information.

[0043] The mail conversion processing device 100 can generate a converted mail in which the large-capacity file is inserted so that it can be sorted into a general attachment file of the forwarded mail, and such a converted mail can be forwarded to the mail restoration processing device 200 located on the external network via the network-linked mail approval device 500.

[0044] In this case, the network-linked email approval device 500 can inspect the security risks of the large-capacity file inserted to be sorted into the general attachment in accordance with a preset email sending policy, and approve the sending of the converted email.The approved converted email can be received by the email recovery processing device 200 according to an embodiment of the present invention before being transmitted to the second email management server device 400.

[0045] The email restoration processing device 200 can be located in an external network separated from the internal network of the security network, and when it receives a converted email that has been converted and forwarded from the internal network through the network-linked email approval device 500, it can construct a restored email in which large files in the internal network isolated from the converted email are restored, and perform a restoration and transmission process to transmit the constructed restored email to the recipient terminal 20 via the second email management server device 400.

[0046] More specifically, the email restoration processing device 200 can obtain large files in an isolated internal network from the general attachment data included in the converted email, separate the large files in the isolated internal network from the converted email, and upload them to any encrypted external network route.

[0047] Then, the email restoration processing device 200 constructs a restoration email for the converted email by including the uploaded external network route information in the converted email from which the large-capacity file has been separated, and the constructed restoration email can be transmitted to the second email management server device 400 and processed for transmission to the recipient terminal.

[0048] With this system configuration, large files in the internal network that could not be sent to the external network can be processed to be sent through the security mail system, and this process allows a mail service to be realized that makes it possible for the mail receiver on the external network to easily check large files in the internal network while still utilizing the security system of the mail system.

[0049] For example, a user of a sender terminal 10 on an internal network simply inputs a file to be exported by email as a large file attachment to a regular email, and the recipient terminal 20 can obtain the large file, restored and uploaded in the same way as a large file attachment to an outgoing email, from the external network route information included in the received email, thereby enabling the export of a substantial large file to be processed.

[0050] In addition, access rights and connection information for large files within such an isolated internal network can be managed by the mail recovery processing device 200, which complements the vulnerable security environment that inevitably required the use of conventional cloud sharing services, etc., and enables more convenient and safe mail transfer of large files within an isolated internal network to an external network.

[0051] FIG. 2 is a block diagram for more specifically explaining the mail conversion processing device according to the embodiment of the present invention.

[0052] Referring to FIG. 2, the mail conversion processing device 100 according to the embodiment of the present invention includes an internal network link identification unit 110, a target file download processing unit 120, a general attachment mail conversion processing unit 130, and a converted mail forwarding unit 140.

[0053] First, the internal network link identification unit 110 receives a forwarding email requested for forwarding from the sender device 10 located in the internal network through the first mail management server device 300, and identifies link information of a large-capacity file located in the internal network from the forwarding email.

[0054] Then, the target file download processing unit 120 performs a download process to acquire a large-capacity file located on the internal network based on the link information.

[0055] Here, the target file download processing unit 120 may include a separate computer-readable storage medium for temporarily storing the large-capacity file.

[0056] Then, the general attachment mail conversion processing unit 130 generates a converted mail in which the large file is inserted so that it can be sorted as a general attachment file of the forwarded mail.

[0057] Here, the general attachment email conversion processing unit 130 can generate the converted email in which the link information of the large file is deleted or invalidated from the forwarding email, thereby including the email content in which the link information of the large file is deleted or invalidated from the forwarding email.

[0058] In addition, the general attachment email conversion processing unit 130 can generate the converted email based on EML (Electronic Mail) format data that contains the same email header and authentication information as the forwarded email and in which the large file is added to the content information.

[0059] More specifically, the email header information may include the IP address of the email sending server, host name information of the email sending server, domain information of the sender's email, the sender's email address, the IP address of the email receiving server, host name information of the email receiving server, domain information of the recipient's email, the recipient's email address, email protocol information, email reception time information, email sending time information, etc.

[0060] The email header may also include network route information required for sending and receiving emails, protocol information used between email service systems for exchanging emails, and the like.

[0061] The email authentication information may include various authentication information such as domain registration information and authentication token information for email security standards such as SPF, DKIM, and DMARC.

[0062] In addition, the content information of the converted email may include a general attachment file extension, hash information, the name of the attachment, and the body of the attachment, since the large file is attached as a general attachment. Here, the hash information of the attachment can check for forgery and alteration of information to ensure the integrity of the information. The hash information or hash value can be mapped to a bit string of a certain length for any data of any length through a hash function.

[0063] In addition, the attachment may include additional content for transmitting additional information or requesting a response in addition to the main content of the email that the sender wants to deliver to the recipient, and in the converted email according to an embodiment of the present invention, the file information of the large file is sorted as a general attachment and added to the additional content. In addition, the main content of the email may be further included in the content information of the converted email.

[0064] Then, the converted mail forwarding unit 140 forwards the converted mail to the mail recovery processing device 200 located in the external network via the network linkage approval device 500. That is, the converted mail thus transmitted can be requested for transmission approval from the network linkage approval device 500 instead of the forwarded mail of the sender terminal 10.

[0065] As described above, the network-linked email approval device 500 can inspect the security risks of the large-capacity file inserted to be sorted into the general attachment in accordance with a pre-set email sending policy, and approve the sending of the converted email.

[0066] Here, as mentioned above, the network-linked email approval device 500 can utilize preset approval policies, and can perform the approval process by applying a variety of policies in combination, such as checking administrator authentication information, checking the approval of a superior in the organization corresponding to the sender, and checking whether the email data has security vulnerabilities.

[0067] Thereafter, the mail restoration processing device 200 separates the large file of the converted mail from the mail restoration processing device, uploads it to an encrypted route of any external network, generates a restored mail to the converted mail from which the large file was separated, and attaches external network route information of the uploaded large file, and transmits the restored mail to the recipient terminal 20 via the second mail management server device 400. This will be described in more detail with reference to FIG.

[0068] FIG. 3 is a block diagram for more specifically explaining the mail recovery processing device according to the embodiment of the present invention.

[0069] Referring to FIG. 3, a mail restoration processing device 200 according to an embodiment of the present invention includes a converted mail receiving unit 210, a large-capacity file reconstructing unit 220, a link information generating unit 230, a restored mail constructing unit 240, and a log information managing unit 250.

[0070] As described above, the mail recovery processing device 200 according to the embodiment of the present invention can be located in an external network separated from the internal network of the security network.

[0071] The converted mail receiving unit 210 receives and processes the converted mail that has been converted and transferred from the internal network by the network-linked mail approval device 500 .

[0072] Here, the large-capacity file reconstructing unit 220 can obtain large-capacity files in the internal network from the general attachment data included in the converted email, separate the large-capacity files in the internal network from the converted email, and upload them to any encrypted external network route.

[0073] Here, the large file reconstructor 220 can upload the large file to a security sharing database managed by the mail recovery processing device 200, and can store and manage any encrypted external network path information corresponding to the uploaded large file. To this end, the large file reconstructor 220 can include one or more storage media for storing and managing the large file on the security sharing database.

[0074] The restored mail constructing unit 240 then constructs a restored mail for the converted mail by including the uploaded external network path information in the converted mail from which the large file has been separated.

[0075] Then, the restoration mail composition unit 240 transmits the restoration mail to the second mail management server device 400, which transfers the mail to the recipient terminal 20.

[0076] Here, the restoration mail constructing unit 240 can attach encrypted external network path information of the uploaded large-capacity file to the restoration mail in various ways.

[0077] More specifically, for example, the restoration mail construction unit 240 can construct the restoration mail so that encrypted external network route information of the uploaded large-capacity file is attached to the restoration mail as link information.

[0078] Also, for example, the restoration mail construction unit 240 can construct the restoration mail so that a web page file that can access the encrypted external network path information of the uploaded large-capacity file is attached to the restoration mail as a normal attachment.

[0079] Here, the web page file may include a security page in which the encrypted external network path information is provided only if the recipient authentication information is confirmed.

[0080] As a result, the recipient terminal 20 can check the external network route information included in the received email through link information or a web page, etc., and connect to the external network route information to download large files uploaded to the security sharing database.

[0081] Meanwhile, the log information management unit 250 can manage the log information of the receiver terminal in response to the large-capacity file uploaded to the encrypted external network path information.

[0082] The log information management unit 250 can then provide the log information to a security device located on the internal network via the network-linked email approval device 500. Here, the security device can be the first email management server device 300 or the email conversion processing device 100, or any of a variety of other security devices that monitor and protect the internal network.

[0083] FIG. 4 is a ladder diagram for explaining the overall system operation according to the embodiment of the present invention.

[0084] Referring to FIG. 4, first, the first mail management server device 300 receives a mail forwarding request from the sender terminal 10 and transmits it to the mail conversion processing device 100 (S1001).

[0085] Thereafter, the mail conversion processing device 100 identifies, from the mail for which a transfer request has been made, internal network link information corresponding to a large-capacity attached file within the isolated internal network (S1003).

[0086] To identify internal network link information, the mail conversion processing device 100 according to an embodiment of the present invention can first extract link information (URL or URI) contained in the mail requested for forwarding through the internal network link identification unit 110, and then perform a tracking check of the link information.

[0087] More specifically, the mail conversion processing device 100 extracts all link information contained in the forwarding requested mail or designated link information designated as a route of a pre-defined internal network (for example, link information whose IP address starts from a private IP address set as an internal network) through the internal network identification unit 110, and can connect to the extracted link information to check whether a file can be downloaded and the size of the file.

[0088] As a result, the internal network link identification unit 110 of the mail conversion processing device 100 identifies the size information of the file to be downloaded from the link information that has been inspected as being downloadable, and if the size information is equal to or larger than a predetermined size, it can be identified as link information corresponding to a large-capacity attachment file within the internal network.

[0089] For example, the specified size may be 2 megabytes, and the internal network link identification unit 110 can extract link information for downloading files on the internal network that exceed 2 megabytes from all link information or specified link information, and identify it as internal network link information corresponding to large-capacity attachments within the internal network.

[0090] Then, the mail conversion processing device 100 downloads the target file from the internal network link, and deletes the large capacity link within the internal network in the forwarded mail (S1005).

[0091] Thereafter, the mail conversion processing device 100 includes the target file as an attachment in a general mail attachment format in the forwarded mail from which the large capacity link has been deleted, and composes EML data (S1007).

[0092] Then, the mail conversion processing device 100 requests the network-linked mail approval device 500 to approve the transfer of the EML data-based converted mail (S1009).

[0093] The network-linked email approval device 500 can determine whether to approve the email based on a preset policy (S1011), and if approval is rejected, it transmits a rejection message to the forwarder terminal 10 via the first email management server device 300 (S1013), and if approval is confirmed, it forwards the converted email to the email recovery processing device 200 connected to the second email management server device 400 in the external network.

[0094] Thereafter, the mail restoration processing device 200 separates the target file from the general attachment file of the converted mail and restores it to a general mail (S1017).

[0095] Then, the mail restoration processing device 200 uploads the separated target file to an arbitrary route (S1019), and creates a web page that allows access to the upload route information (S1021).

[0096] Thereafter, the mail restoration processing device 200 adds a web page to the attachment of the restored general mail (S1023), and transmits the restored general mail to the recipient terminal 20 via the second mail management server device 400 (S1025, S1027).

[0097] In the embodiment of the present invention, the upload path information is added as a web page, but the present invention is not limited to this, and the upload path information can be attached to the restored general email in various ways, such as link information, URL text, etc.

[0098] FIG. 5 is a flowchart for explaining the operation of the mail conversion processing device according to the embodiment of the present invention.

[0099] Referring to FIG. 5, when internal network link information is identified from an email requested to be forwarded by a sender terminal 10, the email conversion processing device 100 according to an embodiment of the present invention may attempt to download a target file based on the identified link information (S101).

[0100] If the target file is successfully downloaded and the validity of the data vulnerability test is confirmed (S103), the mail conversion processing device 100 deletes the internal network link information from the mail for which transfer is requested (S105), and can construct EML data using the transferred mail data and the downloaded file (S107).

[0101] On the other hand, if the download of the target file fails or the validity of the data vulnerability test is not confirmed, the mail conversion processing device 100 can request approval from the network-linked mail approval device 500 for the forwarding of the general mail without the target file attached (S109).

[0102] FIG. 6 is a flowchart for explaining the operation of a recipient terminal that receives a mail in the mail recovery processing device according to the embodiment of the present invention.

[0103] Referring to Figure 6, the recipient terminal 20 loads a web page such as an HTML file included as a general attachment of the restored email received from the email restoration processing device 200 via the second email management server device 400 via a web application or the like (S201).

[0104] Then, the receiver terminal 20 determines whether valid path information and target file are confirmed through the loaded web page (S203).

[0105] If a valid route and target file are confirmed, the recipient terminal 20 can download the restored file of the large-capacity file in the internal network that was uploaded by the mail restoration processing device 200 (S205).

[0106] If a valid route cannot be confirmed or the download of the target file fails, the receiver terminal 20 can output a notification of failure in downloading the restoration file of the internal network file (S207).

[0107] The method according to the present invention described above can be produced as a program to be executed by a computer and stored in a computer-readable recording medium, examples of which include ROM, RAM, CD-ROM, magnetic tape, floppy disk, optical data storage device, etc.

[0108] The computer-readable recording medium can be distributed among computer systems connected via a network, and the computer-readable code can be stored and executed in a distributed manner.Functional programs, codes, and code segments for implementing the method can be easily construed by programmers skilled in the art to which the present invention pertains.

[0109] Furthermore, although the preferred embodiments of the present invention have been illustrated and described above, the present invention is not limited to the specific embodiments described above, and various modifications can be made by a person having ordinary skill in the art to which the invention pertains without departing from the gist of the present invention as claimed in the claims, and these modifications should not be understood individually from the technical ideas and perspectives of the present invention.

Claims

1. 1. A method of operating an email processing device for transferring an email containing a file located in an internal network separated from an external network to the external network, comprising: receiving a forwarded email containing link information of the large attachment, the large attachment being located in the isolated internal network; and identifying the link information of the large attachment from the forwarded email; obtaining a file included in the large-capacity attachment based on the link information; converting the forwarded email into a converted email in which the acquired file is inserted into a normal attachment; and processing the converted mail so that it is forwarded to the external network; a network linkage approval device connected to the internal network and the external network performs a security risk inspection on a file inserted as a general attachment to the converted email in accordance with a preset email forwarding policy, and then approves forwarding of the converted email; An operating method of an email processing device, in which the file inserted as a normal attachment in the converted email is uploaded to a route in the external network in the external network to which the converted email is forwarded by an email restoration processing device in the external network, a restored email including route information of the external network to which the file was uploaded is constructed in the converted email, and the restored email is forwarded to a recipient terminal located in the external network via an email management server device in the external network.

2. The step of converting to a converted email includes:

2. The method of claim 1, further comprising the step of deleting link information of the large-capacity attached file from the forwarded mail.

3. The step of converting to a converted email includes:

2. The method of claim 1, further comprising: constructing the converted email based on data in an Electronic Mail (EML) format that includes the same header and authentication information as the forwarded email and includes the acquired file as a general file.

4. 1. An electronic mail processing device for transferring an email containing a file located in an internal network separated from an external network to the external network, comprising: an internal network link identification unit that receives a forwarded email containing link information of the large-capacity attachment located in the separated internal network and identifies the link information of the large-capacity attachment from the forwarded email; a target file download processing unit that acquires a file included in the large-capacity attachment based on the link information; a general attachment mail conversion processing unit that converts the forwarded mail into a converted mail in which the acquired file is inserted into a general attachment file; a converted mail forwarding unit that processes the converted mail so that the converted mail is forwarded to the external network; a network linkage approval device connected to the internal network and the external network performs a security risk inspection on a file inserted as a general attachment to the converted email in accordance with a preset email forwarding policy, and then approves forwarding of the converted email; An email processing device in which, by an email restoration processing device in the external network, the file inserted in the converted email as a general attachment is uploaded to a route in the external network in the external network to which the converted email is forwarded, a restoration email is constructed in the converted email including route information of the external network to which the file was uploaded, and the restoration email is forwarded to a recipient terminal located in the external network via an email management server device in the external network.

5. 5. The electronic mail processing device according to claim 4, wherein said conversion processing section for general attached mail deletes link information of said large-capacity attached file from said forwarded mail.

6. The conversion processing unit for general attached emails is 5. The email processing device according to claim 4, wherein the converted email is generated based on data in an electronic mail (EML: Electronic Mail) format that includes the same header and authentication information as the forwarded email and includes the acquired file as a general attachment.

Citation Information

Patent Citations

  • System and method for transferring mail, program for utilizing computer as system for transferring mail, and computer readable medium for recording the program

    JP2003016011A

  • Method and apparatus for email gateway

    JP2009535890A

  • Program analysis method and program analysis system

    JP2014089609A