Email Encryption Flag for Secure Mail Server Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for securing email communications are inefficient and unreliable, as they often rely on best-effort encryption protocols that may not guarantee encrypted transmission throughout the delivery path, especially when multiple mail servers are involved, leading to potential interception and monitoring.

Innovation Solution

Incorporating a flag or indicator in the message header to specify encryption requirements, allowing mail servers to verify and enforce encryption standards along the delivery path, ensuring that messages are only transmitted to servers that support the specified encryption, thereby ensuring encrypted delivery without requiring users to manage encryption keys or perform complex security tasks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If message-level encryption (PGP) is used, then security is improved, but ease of operation deteriorates due to high barrier to use

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system comprising mail servers and a flag in the message header that mediates between the user and the encryption process. The flag indicates encryption requirements, and the intermediary system automatically handles verification and enforcement of encryption standards along the delivery path, eliminating the need for users to manually manage encryption keys or perform complex security tasks while maintaining strong encryption security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing mail servers to automatically verify encryption support of recipient servers through the flag mechanism and autonomously enforce encryption requirements along the delivery path without user intervention. The intermediary system performs self-verification of encryption capabilities and self-enforcement of security policies, reducing operational complexity for users

Inventive Principle:
Principle #25Self-service

2Ease of operation

If transport layer encryption (STARTTLS) is used, then ease of operation is improved, but reliability deteriorates due to best-effort encryption

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by inserting a flag in the message header that pre-specifies encryption requirements before message transmission begins. This flag enables the sending mail server to pre-verify the encryption capabilities of the recipient server, ensuring that encryption is established as a prerequisite for message delivery rather than as an optional best-effort measure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by requiring mail servers to verify the encryption support capabilities of recipient servers before message delivery. The flag mechanism provides feedback about encryption requirements, and the intermediary system uses this feedback to enforce encryption standards, ensuring that messages are only delivered to servers that meet the specified encryption criteria rather than relying on best-effort encryption

Inventive Principle:
Principle #23Feedback

3Reliability

If encryption is enforced through user-managed keys, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system comprising mail servers and protocol extensions that mediates between users and encryption key management. The flag in the message header specifies encryption requirements, and the intermediary mail servers automatically handle verification of encryption capabilities and enforcement of encryption standards, eliminating the need for users to directly manage encryption keys or understand cryptographic protocols while maintaining strong security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing mail servers to automatically verify encryption support and enforce encryption requirements without user intervention. The intermediary system performs self-verification of encryption capabilities through the flag mechanism and self-enforcement of security policies along the delivery path, reducing the cryptographic management burden on user devices

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10742586B2Assured encrypted delivery
Publication Date: 2020.08.11 AMAZON TECH INC
  • US10742586B2 patent drawing
  • US10742586B2 patent drawing
  • US10742586B2 patent drawing

AI summary

Information can be added to the headers of email messages to ensure the messages are delivered using encryption, without the user having to manage keys or perform the encryption. A user can select an option in an email program that causes a flag to be added to the message header. Each mail server along the delivery path can provide (or expose) information about the type(s) of encryption supported, and if the encryption is not sufficient then the message will not be delivered to that server. This ensures the transport will remain encrypted before delivering the message to the next hop along the path. If the message cannot be delivered encrypted then the message will not be transmitted past that point. An end user then only needs to click a button or perform another such action to ensure encrypted message delivery.