Adhoc Secure Document Exchange via Intermediary Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The exchange of sensitive documents over unprotected networks like the Internet is insecure, as existing encryption methods require prior arrangement of software licenses and configuration of encryption keys at both ends, making them impractical for ad-hoc use.
Innovation Solution
An electronic message is checked for attached files, which are stripped and stored securely, with a link included in the message for retrieval over a secure connection, requiring authentication via password or digital certificate if necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption methods like PGP are used to secure document exchange, then security is improved, but device complexity and ease of operation deteriorate due to requiring prior arrangement of software licenses and configuration of encryption keys at both ends
Solution Approach 1:
The patent introduces an intermediary server that mediates between the sender and receiver. The server receives the encrypted document from the sender, stores it securely, and provides it to the receiver after authentication. This eliminates the need for both ends to have encryption software installed and configured, as the server handles the encryption and secure delivery processes.
Solution Approach 2:
The system allows users to send documents securely without requiring them to perform complex encryption configuration. The server automatically handles the encryption process, and users only need to provide basic authentication information (like email addresses), making the system self-servicing and easy to use.
2Reliability
If specialized encryption software is installed at both ends for secure document exchange, then security is improved, but ease of operation deteriorates due to requiring coordinated configuration and prior arrangement
Solution Approach 1:
The server acts as a mediator that eliminates the need for clients to install and configure encryption software. Users simply attach documents to emails, and the server handles the secure encryption and delivery process automatically, making the system much easier to operate while maintaining security.
Solution Approach 2:
The patent replaces the mechanical system of installing and configuring encryption software on client machines with a web-based service approach. Users interact through standard email and browser interfaces, and the server handles the complex encryption mechanics in the background, substituting client-side mechanical configuration with server-side automated processing.
3Ease of operation
If ad-hoc secure document exchange is implemented without preconfiguration, then ease of operation is improved, but security deteriorates due to lack of encryption key coordination
Solution Approach 1:
The server provides a centralized authentication and secure delivery mechanism that works for ad-hoc exchanges. The server maintains secure communication channels and authentication mechanisms, allowing users to send encrypted documents without having pre-configured anything on their end, thus achieving both ease of use and security for spontaneous exchanges.
Data Source
AI summary
Embodiments of the present invention are directed to a system capable of enforcing document security and delivery policies. In particular, the present invention allows for the detection and removal of files attached to electronic messages. When an attached file is removed from an electronic message, the file may be placed in secure storage. A link to the stored file is inserted in the electronic communication prior to delivery of the message to the addressee of the communication. In order to access the stored file, the recipient of the message is required to select the provided link, which establishes a secure communication channel between the secure storage device and the receiving client computer. Optionally, the recipient may also be required to provide a password and/or digital certificate in order to access the stored file.


