Edge Email Servers for Rights Management Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic messaging systems using Information Rights Management (IRM) face challenges in ensuring that confidential, proprietary, or sensitive subject matter is not inappropriately transferred between domains with differing security rights, as existing solutions rely on client application trust and can be circumvented.

Innovation Solution

The implementation of policy documents that include semantics pattern recognition data to identify deviant messages, with message transfer agents scanning messages for configurable evidence and triggering adaptable actions to prevent inappropriate transfer between domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Information Rights Management (IRM) is used to control content usage, then security and rights protection are improved, but the system can be circumvented by users through printing, copying, or transferring content outside the controlled environment

Engineering Contradiction:
Improverights management enforcementVSAvoidinappropriate content transfer
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces an intermediary system consisting of edge servers and message transfer agents that monitor and control email communications between domains. This intermediary layer enforces rights management policies by scanning messages for sensitive content, verifying recipient authorization, and blocking inappropriate transfers, thereby preventing circumvention of IRM controls through external communication channels

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where message transfer agents continuously monitor outgoing and incoming emails, compare them against rights management policies, and automatically enforce restrictions. The system provides real-time feedback by blocking unauthorized messages and logging compliance events, creating a closed-loop control system that adapts to prevent future violations

Inventive Principle:
Principle #23Feedback

2Reliability

If policy enforcement is implemented at the application level, then rights control is improved, but the complexity of implementing and maintaining trust across all client applications increases

Engineering Contradiction:
Improvepolicy enforcementVSAvoidclient application trust infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent shifts the enforcement burden from individual client applications to intermediary edge servers that act as policy enforcement points. These servers handle the complex tasks of policy interpretation, message scanning, and authorization verification, allowing client applications to remain simple while maintaining robust rights management enforcement across the organization

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The message transfer agents implemented at edge servers provide universal policy enforcement capabilities across multiple domains and applications. A single enforcement mechanism handles diverse rights management scenarios including inter-domain email restrictions, sensitive content identification, and authorization verification, eliminating the need for separate trust infrastructure in each application

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If semantic pattern recognition is used to identify sensitive content, then detection accuracy is improved, but the processing time and computational resources required increase

Engineering Contradiction:
Improvesensitive content identificationVSAvoidmessage processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring semantic patterns and sensitivity rules in the policy definitions before email processing begins. Message transfer agents are pre-loaded with knowledge of what constitutes sensitive content in each domain, allowing for rapid pattern matching during actual email scanning without requiring complex real-time analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the email processing workflow into distinct stages: initial filtering by message transfer agents at edge servers, detailed semantic analysis only for flagged messages, and final policy enforcement. This segmentation allows most routine messages to be processed quickly while applying comprehensive semantic pattern recognition only when necessary, balancing detection accuracy with processing efficiency

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7454778B2Enforcing rights management through edge email servers
Publication Date: 2008.11.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7454778B2 patent drawing
  • US7454778B2 patent drawing
  • US7454778B2 patent drawing

AI summary

The present invention provides for methods, systems, and computer program products for ensuring that sensitive subject matter within electronic messages is not inappropriately transferred between domains with differing security rights. The present invention utilizes the appropriate placement of message transfer agents or servers along with policy documents that include configurable semantics pattern recognition data for identifying deviant messages. Once deviant messages or messages that potentially have sensitive subject matter are identified, the present invention further provides for adaptable actions or remedies for ensuring that the sensitive subject matter is not inappropriately transferred between domains.