Outgoing Email Check System Using Header Appended Verification Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email security check systems face challenges in balancing security level and convenience, leading to inefficiencies in preventing information leakage due to human errors, particularly in ensuring thorough implementation across all personal computers and detecting unauthorized avoidance of security checks.

Innovation Solution

An outgoing email check system that includes a security check executing apparatus, a check data providing apparatus, and a check data inspecting apparatus, which generates and appends check data to outgoing emails, and inspects this data to determine permission for transmission, ensuring compliance with security policies and preventing unauthorized transmissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security check process is executed for all outgoing emails, then information leakage prevention is improved, but system complexity and user burden increase

Engineering Contradiction:
Improveinformation leakage preventionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the security check process into two independent parts: a security check executing apparatus that performs the actual security verification, and a check data inspecting apparatus that validates the check data. This segmentation allows the security function to be isolated and managed separately from the email transmission system, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system appends check data to the email header before transmission occurs. This preliminary action ensures that security verification data is already in place when the email is sent, allowing the inspecting apparatus to quickly validate security compliance without adding delay to the transmission process, thus reducing user burden while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security check level is increased, then information security is improved, but operation convenience deteriorates

Engineering Contradiction:
Improveinformation security levelVSAvoidoperation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security check executing apparatus automatically performs security verification and appends check data to emails without requiring user intervention. The system serves itself by autonomously completing security checks, presenting risk information when necessary, and managing the entire security process without burdening the user, thus maintaining high security levels while preserving operation convenience.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system presents risk information to the sender when a planned outgoing email violates security policies, providing immediate feedback that allows users to make informed decisions. This feedback mechanism maintains high security standards by alerting users to potential issues while keeping the system convenient by only engaging user attention when actually needed rather than for every email.

Inventive Principle:
Principle #23Feedback

3Reliability

If check data is appended to email header, then transmission security verification is improved, but email processing time increases

Engineering Contradiction:
Improvetransmission security verificationVSAvoidemail processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The check data is appended to the email header in advance during the email creation process, before the actual transmission occurs. This preliminary action ensures that when the email reaches the inspecting apparatus, the security verification can be performed immediately by simply reading the already-present check data from the header, rather than requiring time-consuming analysis of the email content, thus minimizing processing time while maintaining security verification.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If white list mechanism is used, then check process load is reduced, but security coverage is limited

Engineering Contradiction:
Improvecheck process efficiencyVSAvoidsecurity coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The check data providing apparatus serves multiple functions: it generates check data for security verification, appends the data to email headers, and works with both white list and gray list mechanisms. This universal apparatus handles diverse security check scenarios (white list, gray list, and custom policies) through a single unified system, maintaining both efficiency and comprehensive security coverage without requiring separate mechanisms for each approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8997183B2Outgoing email check system, check data providing apparatus, check data inspecting apparatus, and outgoing email check method
Publication Date: 2015.03.31 FUJITSU LTD
  • US8997183B2 patent drawing
  • US8997183B2 patent drawing
  • US8997183B2 patent drawing

AI summary

To allow inspecting whether a security check of a planned outgoing email is finished in an outgoing email check system, a check data providing apparatus 2 of an outgoing email check system 100 stores check information distributed from a check information management apparatus 1, appends check data generated based on the check information to a header of a checked planned outgoing email, and transmits the email to an email transmitting apparatus 9. A check data inspecting apparatus 3 stores the check information distributed from the check information management apparatus 1, inspects the check data extracted from the planned outgoing email received from the email transmitting apparatus 9 based on the check information, determines that the transmission is permitted when the check data of the planned outgoing email matches the check information, and determines that the transmission is rejected when the check data does not match the check information. The email transmitting apparatus 9 executes a transmission process only for the planned outgoing email for which the transmission is permitted.