Email Access Control via Proxy Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for controlling email access fail to ensure that email resources are accessed only by authorized parties in authorized manners and do not modify email resources to comply with enterprise security standards, leading to potential unauthorized access and sensitive information loss.

Innovation Solution

A system and method that includes a processor configured to proxy email resources, determine if they are accessible via unauthorized applications on client devices, and configure them to be inaccessible if determined to be so, using a client device, email service, and memory storing executable instructions to enforce access controls and security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access credentials are used to control email access, then authorized parties can access email resources, but the method fails to control how email resources are accessed and cannot prevent unauthorized applications from accessing email resources

Engineering Contradiction:
Improveemail access controlVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an access control service as an intermediary component that sits between email services and client devices. This service proxies email resources and enforces access controls, preventing unauthorized applications from accessing email resources while allowing authorized access. The intermediary monitors and controls the manner of access, not just whether access is permitted.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the email access control function into separate components: the access control service that enforces policies, the email services that provide email functionality, and client devices that access email. This segmentation allows the access control service to independently monitor and control access methods without affecting the core email functionality.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If traditional access control methods are used, then authorized users can access email, but email resources cannot be modified to comply with enterprise security standards

Engineering Contradiction:
Improvesecurity complianceVSAvoidemail resource configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control service performs preliminary actions by modifying email resources before they are accessed by client applications. It configures email resources to comply with enterprise security standards in advance, ensuring that security requirements are met before access occurs, rather than attempting to control access after the fact.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control service acts as an intermediary that modifies email resources to comply with security standards while maintaining compatibility with authorized applications. It transforms email resources into a format that satisfies enterprise security requirements without preventing legitimate access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If email resources are made accessible to multiple applications, then user convenience is improved, but unauthorized applications can access sensitive information

Engineering Contradiction:
Improveemail access convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The access control service serves as an intermediary that allows multiple applications to access email resources while enforcing security policies. It monitors which applications access email and ensures they meet enterprise security standards, maintaining user convenience while blocking unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the access control service continuously monitors application access attempts and enforces security policies in real-time. This feedback loop ensures that unauthorized applications are detected and blocked while authorized applications maintain access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12120077B2Systems and methods for controlling email access
Publication Date: 2024.10.15 OMNISSA LLC
  • US12120077B2 patent drawing
  • US12120077B2 patent drawing
  • US12120077B2 patent drawing

AI summary

Embodiments of the disclosure relate to proxying at least one email resource from at least one email service to at least one client device, determining whether the email resources are accessible to the client devices via at least one unauthorized application on the client devices, and modifying the email resources to be inaccessible via the unauthorized applications on the client devices in response to a determination that the email resources are accessible via the unauthorized applications on the client devices.