Email Attachment Header Verification for Secure Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

E-mail messages with attachments are often inadvertently sent to unintended recipients, leading to potential negative consequences for managers and organizations due to misdirected confidential or sensitive information.

Innovation Solution

An e-mail routing platform that analyzes an attachment's header to determine if specified recipients are permitted, ensuring that the message is only relayed to intended recipients by preventing delivery to unintended ones, using a system that can be integrated into mail servers or client applications, and allowing for encryption and compression of the header for parsing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If e-mail messages with attachments are sent without verification, then delivery speed is improved, but security and accuracy of recipient delivery deteriorates

Engineering Contradiction:
Improvedelivery speedVSAvoidrecipient verification accuracy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary verification of recipient permissions by analyzing the attachment header before the e-mail message is delivered. This advance checking ensures that only authorized recipients receive the attachment, preventing inadvertent disclosures while maintaining efficient delivery for legitimate messages.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component that acts as a gateway between the e-mail sending process and the actual delivery. This intermediary analyzes the attachment header to verify recipient permissions, serving as a mediator that ensures security without blocking the overall delivery flow for valid messages.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If header analysis is performed to verify permitted recipients, then security is improved, but processing time and system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The attachment header is analyzed in advance during the e-mail routing process, before final delivery occurs. This preliminary verification allows the system to identify and block unauthorized recipients early in the delivery chain, minimizing the time overhead to only the essential header analysis rather than adding post-delivery verification steps.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If header analysis is performed to verify permitted recipients, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that acts as a gateway between the e-mail sending process and the actual delivery. This intermediary analyzes the attachment header to verify recipient permissions, serving as a mediator that ensures security without blocking the overall delivery flow for valid messages.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is designed to work with standard e-mail protocols and attachment formats, making the header analysis mechanism universally applicable to different e-mail clients and server configurations. This multi-functionality approach allows the security feature to be integrated without requiring specialized complex infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10097489B2Secure e-mail attachment routing and delivery
Publication Date: 2018.10.09 SAP SE
  • US10097489B2 patent drawing
  • US10097489B2 patent drawing
  • US10097489B2 patent drawing

AI summary

An e-mail message is received that specifies at least one recipient and which includes an attachment. The attachment is a file having a header specifying at least one e-mail address for a permitted recipient. The header is analyzed to determine whether the at least one recipient is specified as a permitted recipient. The e-mail message is relayed to the at least one recipient if is determined that the at least one recipient is a permitted recipient. In addition or in the alternative, delivery of the e-mail message to the at least one recipient is prevented if is determined that the at least one recipient is not a permitted recipient. Related apparatus, systems, techniques and articles are also described.