Email Access Control via Proxy URL Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for controlling email access fail to limit access to email resources according to enterprise security standards, modify email resources as needed, and ensure authorized access by proper recipients, leading to potential unauthorized access and sensitive information loss.

Innovation Solution

A system and method that include a client device, an email service, and a processor configured to proxy email resources, identify resource rules, and add URLs to ensure compliance with these rules, thereby controlling and securing email access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access credentials are used to control email access, then only authorized parties may access email resources, but the system fails to limit access according to enterprise security standards and fails to modify email resources to meet security requirements

Engineering Contradiction:
Improveemail access securityVSAvoidcompliance with enterprise security standards
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by adding URLs and modifying email resources before they are accessed by recipients. The access control service intercepts email resources, adds required URLs in accordance with enterprise security standards, and modifies resources to meet security requirements before delivery, ensuring compliance is built into the email itself rather than relying solely on access control credentials

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control service acts as an intermediary between the email system and recipients. It proxies email resources in transit, identifies and adds required URLs, modifies resources to meet security standards, and then delivers them to authorized recipients. This intermediary layer ensures both authorization verification and security standard compliance without requiring changes to the underlying email infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access credentials are used to control email access, then authorized parties can access email resources, but the system fails to control the manner in which email resources are accessed

Engineering Contradiction:
Improveauthorized access controlVSAvoidaccess manner control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system embeds control mechanisms in advance by adding URLs and access control information to email resources before they reach recipients. The access control service prepares the email resources with embedded controls that dictate how they must be accessed, ensuring that manner control is built into the resource itself rather than requiring complex real-time monitoring of recipient behavior

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback mechanisms where the access control service monitors how email resources are being accessed and can modify or revoke access rights based on compliance with specified access manners. The service tracks access patterns and enforces security policies by responding to access attempts, creating a closed-loop control system that adapts to actual usage

Inventive Principle:
Principle #23Feedback

3Reliability

If access credentials are used to control email access, then basic authorization is achieved, but the system cannot prevent sensitive information loss or ensure enterprise security standards are met

Engineering Contradiction:
Improvebasic access authorizationVSAvoidsensitive information loss
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system takes preliminary protective actions by adding URLs and modifying email resources to embed security controls before distribution. The access control service prepares emails with embedded security measures including required URLs that enforce enterprise security standards, creating protective layers that prevent sensitive information loss even if credentials are compromised

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements beforehand cushioning by embedding multiple layers of security controls within email resources themselves. By adding URLs and modifying resources to include security measures before delivery, the system creates protective buffers that cushion against potential security breaches, unauthorized access, and information loss, ensuring enterprise security standards are enforced regardless of credential security

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS9325713B2Systems and methods for controlling email access
Publication Date: 2016.04.26 OMNISSA LLC
  • US9325713B2 patent drawing
  • US9325713B2 patent drawing
  • US9325713B2 patent drawing

AI summary

Embodiments of the disclosure relate to proxying at least one email resource from at least one email service to at least one client device, identifying at least one resource rule associated with the email resources, and adding at least one URL to the email resources in accordance with the resource rules.