Client-Side Message Encryption for Third-Party Hosting Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in protecting sensitive data from disclosure to third-party service providers while transitioning to hosted services, as existing solutions lack effective mechanisms to prevent unauthorized access by third-party administrators.

Innovation Solution

The implementation of a security architecture that employs encryption and storage of encryption keys, allowing administrators to define policies for applying security rules to client messages, ensuring that only intended recipients can access the message content, thereby protecting messages from untrusted hosting services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If organizations use hosted services to reduce IT costs, then productivity and cost efficiency are improved, but security and control over confidential data deteriorate

Engineering Contradiction:
Improvecost efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the security management function from the hosted service provider by implementing client-side security rules that encrypt messages before they leave the organization's control. This allows the organization to maintain security policies independently while using third-party hosting services for message delivery.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security layer (encryption mechanism with security rules) between the organization's confidential data and the untrusted hosted service. This intermediary ensures that even though the message passes through third-party infrastructure, the content remains protected and accessible only to authorized recipients.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If third-party service providers access message content to provide hosting services, then service functionality is improved, but data confidentiality deteriorates

Engineering Contradiction:
Improveservice functionalityVSAvoiddata confidentiality
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent changes the state of the message from plaintext to encrypted form before it enters the hosted service infrastructure. This parameter change (encryption) allows the service provider to handle and route the message without being able to read its contents, thus maintaining confidentiality while preserving service functionality.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies security rules and encryption to messages before they are submitted to the hosted service provider. This preliminary action ensures that the message is already protected when it enters the untrusted environment, preventing any potential access to confidential content by the service provider.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security rules are applied to all messages through hosted services, then data protection is improved, but message processing time and complexity increase

Engineering Contradiction:
Improvedata protectionVSAvoidmessage processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security where the client system automatically applies security rules to messages based on predefined policies. The security mechanism operates autonomously without requiring manual intervention or complex configuration, reducing processing overhead while maintaining strong protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal security framework that can be applied to all messages regardless of their destination or content type. This multi-functional approach allows the same security infrastructure to protect various types of communications through hosted services, simplifying the overall system rather than requiring separate solutions for different scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10044763B2Protecting content from third party using client-side security protection
Publication Date: 2018.08.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10044763B2 patent drawing
  • US10044763B2 patent drawing
  • US10044763B2 patent drawing

AI summary

Architecture that employs encryption and storage of encryption keys to protect trusted client message content from an untrusted third-party hosted service. Each trusted user machine is configured to optionally apply security to messages. Rules determine when automatic protection is applied and the level of protection to apply. The trusted client automatically downloads the rules (or rules policies) from a trusted rules service and caches the rules locally. During composition, the rules analyze the message and automatically apply security template(s) to the message. The security template(s) encrypt the body of the message, but not the headers or subject. The untrusted message service processes the header and delivers the message to the correct recipient. The hosted service cannot view the contents of the message body, and only intended recipients of the protected message can view the message body. Offline protection is supported, and the user can override protection by the rules.