Outgoing Email Check System Using Header Appended Verification Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current email security check systems face challenges in balancing security level and convenience, leading to inefficiencies in preventing information leakage due to human errors, particularly in ensuring thorough implementation across all personal computers and detecting unauthorized avoidance of security checks.
Innovation Solution
An outgoing email check system that includes a security check executing apparatus, a check data providing apparatus, and a check data inspecting apparatus, which generates and appends check data to outgoing emails, and inspects this data to determine permission for transmission, ensuring compliance with security policies and preventing unauthorized transmissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security check process is executed for all outgoing emails, then information leakage prevention is improved, but system complexity and user burden increase
Solution Approach 1:
The system divides the security check process into two independent parts: a security check executing apparatus that performs the actual security verification, and a check data inspecting apparatus that validates the check data. This segmentation allows the security function to be isolated and managed separately from the email transmission system, reducing overall system complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The system appends check data to the email header before transmission occurs. This preliminary action ensures that security verification data is already in place when the email is sent, allowing the inspecting apparatus to quickly validate security compliance without adding delay to the transmission process, thus reducing user burden while maintaining security.
2Reliability
If security check level is increased, then information security is improved, but operation convenience deteriorates
Solution Approach 1:
The security check executing apparatus automatically performs security verification and appends check data to emails without requiring user intervention. The system serves itself by autonomously completing security checks, presenting risk information when necessary, and managing the entire security process without burdening the user, thus maintaining high security levels while preserving operation convenience.
Solution Approach 2:
The system presents risk information to the sender when a planned outgoing email violates security policies, providing immediate feedback that allows users to make informed decisions. This feedback mechanism maintains high security standards by alerting users to potential issues while keeping the system convenient by only engaging user attention when actually needed rather than for every email.
3Reliability
If check data is appended to email header, then transmission security verification is improved, but email processing time increases
Solution Approach 1:
The check data is appended to the email header in advance during the email creation process, before the actual transmission occurs. This preliminary action ensures that when the email reaches the inspecting apparatus, the security verification can be performed immediately by simply reading the already-present check data from the header, rather than requiring time-consuming analysis of the email content, thus minimizing processing time while maintaining security verification.
4Productivity
If white list mechanism is used, then check process load is reduced, but security coverage is limited
Solution Approach 1:
The check data providing apparatus serves multiple functions: it generates check data for security verification, appends the data to email headers, and works with both white list and gray list mechanisms. This universal apparatus handles diverse security check scenarios (white list, gray list, and custom policies) through a single unified system, maintaining both efficiency and comprehensive security coverage without requiring separate mechanisms for each approach.
Data Source
AI summary
To allow inspecting whether a security check of a planned outgoing email is finished in an outgoing email check system, a check data providing apparatus 2 of an outgoing email check system 100 stores check information distributed from a check information management apparatus 1, appends check data generated based on the check information to a header of a checked planned outgoing email, and transmits the email to an email transmitting apparatus 9. A check data inspecting apparatus 3 stores the check information distributed from the check information management apparatus 1, inspects the check data extracted from the planned outgoing email received from the email transmitting apparatus 9 based on the check information, determines that the transmission is permitted when the check data of the planned outgoing email matches the check information, and determines that the transmission is rejected when the check data does not match the check information. The email transmitting apparatus 9 executes a transmission process only for the planned outgoing email for which the transmission is permitted.


