Email Attribution Extension for Multi-Tenant Tenant Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional e-mail systems struggle to establish trusted communication channels in multi-tenant environments, where service providers' certificates and IP addresses are shared among customers, making it difficult to authenticate and differentiate messages from specific tenants.

Innovation Solution

Implementing a system that validates message source organizations and uses attribution data extensions, such as the XOORG SMTP extension, to securely transmit messages with attribution elements, allowing recipient organizations to apply specific message handling rules based on the source organization's identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication or IP-address-based authentication is used to establish a trusted communication channel, then authentication between organizations is improved, but the ability to differentiate messages from specific tenants in a multi-tenant environment deteriorates because the service provider's certificate and IP addresses are shared among all customers

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtenant identification precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the authentication and identification process into two distinct components: (1) service provider-level authentication using certificates/IP addresses to establish trust, and (2) tenant-level identification using attribution data (such as XOORG SMTP extension) to differentiate specific customers. This segmentation allows the system to maintain reliable authentication while achieving precise tenant identification, resolving the contradiction between authentication reliability and tenant differentiation capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional e-mail authentication methods are used, then security is improved through certificate verification, but message handling differentiation between tenants deteriorates because all tenants share the same authentication credentials

Engineering Contradiction:
ImprovesecurityVSAvoidmessage handling adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces attribution data as an intermediary mechanism that bridges service provider-level authentication and tenant-level message handling. The attribution data ( transmitted through SMTP extensions like XOORG) acts as a mediator that carries tenant identification information without compromising the existing certificate-based security framework. This enables differentiated message handling policies for different tenants while maintaining the security benefits of conventional authentication methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If shared certificates and IP addresses are used in multi-tenant environments, then service provider authentication is simplified, but the complexity of establishing trusted channels between specific tenants increases

Engineering Contradiction:
Improveauthentication setup easeVSAvoidtrusted channel establishment complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring attribution data associations between tenants and their identification parameters before message transmission. The service provider establishes and maintains a mapping between tenants and their attribution identifiers in advance, so that when messages are transmitted, the recipient can immediately differentiate tenants using the pre-established attribution data without complex real-time authentication negotiations. This reduces the complexity of establishing trusted channels while maintaining ease of operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2572328B1Trusted e-mail communication in a multi-tenant environment
Publication Date: 2018.07.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2572328B1 patent drawingFigure 1
  • EP2572328B1 patent drawingFigure 2
  • EP2572328B1 patent drawingFigure 3

AI summary

Trusted e-mail communication may be provided. A message source organization may be validated. When a message is received from the validated message source organization for a recipient organization, a determination may be made as to whether the recipient organization supports an attribution data extension. If so, the message may be transmitted to the recipient organization with an attribution element associated with the message source organization.