Email Access Restriction via File Content Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional email encryption technologies allow erroneously attached files to be decrypted at the transmission destination, even if the transmission source does not intend them to be readable, and lack control over access rights for attached files.

Innovation Solution

An access restriction device that analyzes attached files for specific character strings associated with access restriction processes, applies encryption or password protection based on registered access restriction information, and sends the restricted file instead of the original file to ensure only authorized recipients can read the content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the mail server automatically encrypts attached files using transmission destination policy, then encryption time and effort are reduced and information leakage is prevented, but erroneously attached files can still be decoded at the transmission destination

Engineering Contradiction:
Improveencryption process efficiencyVSAvoidaccess control accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the encryption key management into two separate components: transmission destination policy (for automatic encryption) and file access rights (for controlled decryption). This allows the mail server to encrypt files automatically while simultaneously applying access restrictions that prevent unauthorized decoding, even by the intended recipient if they lack proper authorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access restriction mechanism that acts between the encryption process and the file access process. This intermediary layer verifies both the transmission destination policy and the file's access rights before allowing decryption, preventing erroneously attached files from being decoded even when encryption keys are available.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional encryption technology is used, then files are encrypted before transmission, but it is not possible to allow only authorized users to read the attached file

Engineering Contradiction:
Improveencryption securityVSAvoidaccess right control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges two previously separate functions into a unified access control system: traditional encryption (for confidentiality) and access right management (for authorization). By combining these functions, the system achieves both strong encryption security and fine-grained access control, allowing only authorized users to read attached files regardless of whether they are correctly attached.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9288172B2Access restriction device, access restriction method, computer readable storage medium
Publication Date: 2016.03.15 FUJITSU LTD
  • US9288172B2 patent drawing
  • US9288172B2 patent drawing
  • US9288172B2 patent drawing

AI summary

An access restriction device including a processor; and a memory. The processor executes: receiving an email from a transmission source; specifying including analyzing, when a file is attached to the email, information in the file, and specifying a character string from the file; executing including specifying, from a storing unit in which a character string is associated with an access restriction process, an access restriction process that is associated with the character string specified at the specifying the character string, and executing the specified access restriction process on the file; and sending including attaching, instead of the file attached to the email, the file that has been subjected to the access restriction process at the executing to the email, and sending the email to which the file subjected to the access restriction process is attached to a transmission destination of the email.