Email Appliance Merging Agents to Enforce Sensitive Data Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email systems assembled from commercial-off-the-shelf (COTS) components fail to provide a full complement of information protection methods, are time-consuming and costly to install and configure, and require individual accreditation, thus inadequately enforcing information assurance policies.

Innovation Solution

A dedicated appliance comprising a mail delivery agent, an adjudicator, and a mail transfer agent that receives and processes emails designated as sensitive, applying policies to determine whether to allow or block them, ensuring efficient installation and integration, and enabling accreditation of similar units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If COTS components are used to assemble email systems, then ease of manufacture is improved, but information protection capability and reliability deteriorate

Engineering Contradiction:
Improveease of manufactureVSAvoidinformation protection capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent merges multiple email system components (mail delivery agent, adjudicator, mail transfer agent) into a single integrated appliance. This consolidation ensures that all components work together as a unified system with consistent security policies, eliminating the reliability issues that arise from assembling separate COTS components while maintaining ease of deployment as a single unit.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The appliance is designed as a universal platform that performs multiple functions: receiving emails, applying security policies, adjudicating sensitivity levels, and directing mail to appropriate recipients. This multi-functional design replaces the need for multiple specialized COTS components while providing comprehensive information protection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If COTS components are installed and configured, then ease of manufacture is improved, but installation time and cost increase

Engineering Contradiction:
Improveease of manufactureVSAvoidinstallation time
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

By combining multiple components into a single appliance, the installation process is simplified from configuring multiple separate systems to deploying one integrated unit. This reduces installation time and complexity while maintaining the ease of manufacture through standardized appliance production.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The appliance is pre-configured with security policies and components during manufacturing, so that deployment requires only minimal on-site configuration. This preliminary action eliminates the need for time-consuming post-manufacturing configuration while maintaining ease of manufacture through standardized production processes.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If COTS components are used, then ease of manufacture is improved, but individual accreditation is required for each system

Engineering Contradiction:
Improveease of manufactureVSAvoidaccreditation complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The appliance serves as a universal platform that can be deployed across multiple systems. Once accredited as a template, the same appliance design can be instantiated multiple times without requiring individual accreditation for each instance, thereby reducing accreditation complexity while maintaining ease of manufacture through standardized production.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system separates the accreditation process from the deployment process. The appliance design itself is accredited once as a template, and then multiple instances can be deployed without repeated accreditation. This segmentation of the accreditation function from individual system deployment reduces the complexity of ensuring information protection across multiple systems.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8448246B2Protecting sensitive email
Publication Date: 2013.05.21 EVERFOX HOLDINGS LLC
  • US8448246B2 patent drawing
  • US8448246B2 patent drawing
  • US8448246B2 patent drawing

AI summary

According to one embodiment, a plurality of components are located within an appliance configured to send and receive email. The appliance receives an email and selects one or more policies to apply based on a designation indicating that the email communicates sensitive information. The policies determine whether to allow or block the email according to rules for assuring email. If the email is allowed, the appliance directs the email to one or more recipients.