Cloud Mail Encryption Key Segmentation for Unauthorized Access Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based mail services face fundamental security issues due to the vulnerability of encryption keys held by service providers, which can be compromised, leading to unauthorized access to user email contents.
Innovation Solution
Implementing a cloud-based mail system that uses a separate key inaccessible to the cloud mail service provider, where emails are encoded with a first key by the user's system and then encoded again with a second key by the cloud server, ensuring secure storage and transmission while maintaining user control over their data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud mail service uses provider-held encryption keys for storage security, then storage security is simplified, but fundamental security is compromised because provider can access user email contents
Solution Approach 1:
The encryption key is segmented into two parts: a first key held by the user's terminal and a second key held by the cloud mail server. The user's key encrypts the email content before transmission, while the server's key provides additional encryption during storage. This segmentation ensures that no single entity (neither user nor provider) can independently access the full email content, resolving the contradiction between simplified security management and fundamental security protection.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism where the user's terminal acts as a mediator between the email content and the cloud storage system. The terminal encrypts emails with the user's key before submission to the cloud server, which then applies its own key. This intermediary layer prevents the cloud provider from directly accessing plaintext emails, while still enabling secure storage and retrieval through coordinated key usage.
2Reliability
If cloud mail service requires separate infrastructure construction, then security control is improved, but operating costs increase significantly
Solution Approach 1:
The patent merges the advantages of self-hosted security control with the cost benefits of cloud services. Users maintain control over their encryption keys (providing security control similar to self-hosting) while leveraging the cloud provider's infrastructure for storage and transmission (reducing infrastructure costs). This combination allows users to achieve both security control and cost efficiency without requiring separate infrastructure construction.
Solution Approach 2:
The user's terminal performs preliminary encryption of email content with the user's key before submitting to the cloud server. This preliminary action ensures that the email is already secured before entering the cloud infrastructure, allowing the cloud provider to store and manage emails without needing to implement additional security measures, thereby reducing overall system costs while maintaining security control.
3Ease of operation
If cloud mail service stores all mail content centrally, then data accessibility is improved, but security vulnerability increases due to centralized key management
Solution Approach 1:
The encryption key is segmented into user-held and provider-held portions, with the user's key applied during email creation and the provider's key applied during storage. This segmentation allows centralized storage of encrypted emails (improving accessibility) while distributing key management responsibilities (reducing security vulnerability). Neither party alone can access plaintext emails, but both can contribute to secure storage and retrieval operations.
Solution Approach 2:
Different parts of the encryption process use different keys according to their specific security requirements. The user's terminal applies the first key for local encryption before transmission, while the cloud server applies the second key for storage encryption. This local quality approach ensures that each component uses the appropriate key for its function, maintaining both accessibility and security in the centralized system.
Data Source
AI summary
Provided are a cloud-based mail system and a mail service method for providing an improved security. The cloud-based mail system including: an e-mail transmission manager configured to encode an e-mail received from a terminal of a user or an external mail server with a first key, and to forward the e-mail encoded with the first key to a cloud mail server that provides a cloud mail service, the first key being configured to be inaccessible by the cloud mail server; and a communication interface to transmit the e-mail encoded with the first key to the cloud mail server. The e-mail encoded with the first key is configured to be encoded at the cloud mail server with a second key of the cloud mail server and stored in a storage of the cloud mail server.


