Email Attachment Security via Server-Side Code and OTP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for securing email attachments over public communication networks, such as IRM and cryptographic systems, are inadequate as they lack scalability, are complex to manage, and do not allow for dynamic access policy modifications after transmission, making sensitive information vulnerable to unauthorized access.

Innovation Solution

A computer-implemented system that includes a sender-side application to embed a first code in an email, which processes the email on a server-side to generate access policies, encapsulates parts into proprietary file wrappers, and uses OTP authentication to ensure only authorized recipients access the content, allowing for dynamic access management and logging.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing IRM systems are used to protect email attachments, then access control is provided within enterprise networks, but the system lacks scalability and cannot be deployed across public communication networks

Engineering Contradiction:
Improveaccess controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a server as an intermediary component that mediates between email senders and recipients. This server hosts the protection application and manages access policies dynamically, enabling the system to scale across public networks while maintaining secure access control. The server acts as a central coordination point that eliminates the need for distributed IRM agents on each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional cryptographic key management mechanisms with a service-based approach. Instead of relying on complex key distribution and management infrastructure, the system uses server-hosted access policies and dynamic permission management, simplifying the architecture and improving scalability across public communication networks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If cryptographic systems with multiple encryption keys are used, then security is provided for multiple recipients, but key selection and distribution becomes complex and cumbersome

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complexity of key management from the client devices and centralizes it on the server. The protection application on the server handles all encryption key generation, distribution, and management operations, while client devices simply interact with the server through standardized interfaces. This extraction eliminates the need for complex local key management on each recipient's device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The server acts as an intermediary that manages all cryptographic operations between senders and recipients. It handles key generation, secure distribution to authorized parties, and coordination of decryption processes. This intermediary approach simplifies the user experience while maintaining strong security through centralized cryptographic control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If fixed file access policies are used in IRM systems, then access control is established for internal recipients, but policies cannot be altered after content leaves the protective system

Engineering Contradiction:
Improveaccess policy establishmentVSAvoiddynamic policy modification
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access policies that can be modified in real-time through the server-hosted protection application. Senders and authorized administrators can update access permissions, add or remove recipients, and change policy parameters after content has been distributed. This dynamic approach allows the system to adapt to changing requirements while maintaining security control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms where the server continuously monitors access requests and policy violations. Based on this feedback, administrators can dynamically adjust access policies to respond to security incidents or changing business requirements. The server provides real-time information about content access status, enabling informed policy modifications.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If email attachments are transmitted over public networks, then accessibility and ease of transmission are improved, but vulnerability to unauthorized access and information theft increases

Engineering Contradiction:
Improveemail transmissionVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary protection actions by encrypting and securing email attachments before they leave the sender's device. The protection application on the server prepares secure access policies and encryption parameters in advance. This preliminary security measures ensure that even if emails are intercepted during transmission over public networks, the content remains protected and accessible only to authorized recipients through controlled decryption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9124641B2System and method for securing the data and information transmitted as email attachments
Publication Date: 2015.09.01 SECURELYSHARE SOFTWARE PVT LTD
  • US9124641B2 patent drawing
  • US9124641B2 patent drawing
  • US9124641B2 patent drawing

AI summary

A system for securing data and information transmitted via entails is disclosed. The system includes a sender-side device from which an email including a first code is transmitted. The first code comprises instructions for manipulating server-side processing of the email. The system includes a filter module which determines whether the first code is present within the email, and subsequently transmits the email to a processing server in case if the first code is present within the email. The system includes a processing server which processes the email in accordance with the instructions specified in the first code and generates a first link, thereby enabling the email sender to access and modify the access policy for the email. The processing server further authenticates the intended recipient of the email via an OTP before enabling the intended recipient to access the parts of the email.