Email Access Control via Proxy Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for controlling email access fail to ensure that email resources are accessed only by authorized parties in authorized manners and do not modify email resources to comply with enterprise security standards, leading to potential unauthorized access and sensitive information loss.
Innovation Solution
A system and method that includes a processor configured to proxy email resources, determine if they are accessible via unauthorized applications on client devices, and configure them to be inaccessible if determined to be so, using a client device, email service, and memory storing executable instructions to enforce access controls and security standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access credentials are used to control email access, then authorized parties can access email resources, but the method fails to control how email resources are accessed and cannot prevent unauthorized applications from accessing email resources
Solution Approach 1:
The patent introduces an access control service as an intermediary component that sits between email services and client devices. This service proxies email resources and enforces access controls, preventing unauthorized applications from accessing email resources while allowing authorized access. The intermediary monitors and controls the manner of access, not just whether access is permitted.
Solution Approach 2:
The patent segments the email access control function into separate components: the access control service that enforces policies, the email services that provide email functionality, and client devices that access email. This segmentation allows the access control service to independently monitor and control access methods without affecting the core email functionality.
2Adaptability or versatility
If traditional access control methods are used, then authorized users can access email, but email resources cannot be modified to comply with enterprise security standards
Solution Approach 1:
The access control service performs preliminary actions by modifying email resources before they are accessed by client applications. It configures email resources to comply with enterprise security standards in advance, ensuring that security requirements are met before access occurs, rather than attempting to control access after the fact.
Solution Approach 2:
The access control service acts as an intermediary that modifies email resources to comply with security standards while maintaining compatibility with authorized applications. It transforms email resources into a format that satisfies enterprise security requirements without preventing legitimate access.
3Ease of operation
If email resources are made accessible to multiple applications, then user convenience is improved, but unauthorized applications can access sensitive information
Solution Approach 1:
The access control service serves as an intermediary that allows multiple applications to access email resources while enforcing security policies. It monitors which applications access email and ensures they meet enterprise security standards, maintaining user convenience while blocking unauthorized access.
Solution Approach 2:
The system implements feedback mechanisms where the access control service continuously monitors application access attempts and enforces security policies in real-time. This feedback loop ensures that unauthorized applications are detected and blocked while authorized applications maintain access.
Data Source
AI summary
Embodiments of the disclosure relate to proxying at least one email resource from at least one email service to at least one client device, determining whether the email resources are accessible to the client devices via at least one unauthorized application on the client devices, and modifying the email resources to be inaccessible via the unauthorized applications on the client devices in response to a determination that the email resources are accessible via the unauthorized applications on the client devices.


