Email Access Control via Proxy URL Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for controlling email access fail to limit access to email resources according to enterprise security standards, modify email resources as needed, and ensure authorized access by proper recipients, leading to potential unauthorized access and sensitive information loss.
Innovation Solution
A system and method that include a client device, an email service, and a processor configured to proxy email resources, identify resource rules, and add URLs to ensure compliance with these rules, thereby controlling and securing email access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access credentials are used to control email access, then only authorized parties may access email resources, but the system fails to limit access according to enterprise security standards and fails to modify email resources to meet security requirements
Solution Approach 1:
The system performs preliminary actions by adding URLs and modifying email resources before they are accessed by recipients. The access control service intercepts email resources, adds required URLs in accordance with enterprise security standards, and modifies resources to meet security requirements before delivery, ensuring compliance is built into the email itself rather than relying solely on access control credentials
Solution Approach 2:
The access control service acts as an intermediary between the email system and recipients. It proxies email resources in transit, identifies and adds required URLs, modifies resources to meet security standards, and then delivers them to authorized recipients. This intermediary layer ensures both authorization verification and security standard compliance without requiring changes to the underlying email infrastructure
2Reliability
If access credentials are used to control email access, then authorized parties can access email resources, but the system fails to control the manner in which email resources are accessed
Solution Approach 1:
The system embeds control mechanisms in advance by adding URLs and access control information to email resources before they reach recipients. The access control service prepares the email resources with embedded controls that dictate how they must be accessed, ensuring that manner control is built into the resource itself rather than requiring complex real-time monitoring of recipient behavior
Solution Approach 2:
The system uses feedback mechanisms where the access control service monitors how email resources are being accessed and can modify or revoke access rights based on compliance with specified access manners. The service tracks access patterns and enforces security policies by responding to access attempts, creating a closed-loop control system that adapts to actual usage
3Reliability
If access credentials are used to control email access, then basic authorization is achieved, but the system cannot prevent sensitive information loss or ensure enterprise security standards are met
Solution Approach 1:
The system takes preliminary protective actions by adding URLs and modifying email resources to embed security controls before distribution. The access control service prepares emails with embedded security measures including required URLs that enforce enterprise security standards, creating protective layers that prevent sensitive information loss even if credentials are compromised
Solution Approach 2:
The system implements beforehand cushioning by embedding multiple layers of security controls within email resources themselves. By adding URLs and modifying resources to include security measures before delivery, the system creates protective buffers that cushion against potential security breaches, unauthorized access, and information loss, ensuring enterprise security standards are enforced regardless of credential security
Data Source
AI summary
Embodiments of the disclosure relate to proxying at least one email resource from at least one email service to at least one client device, identifying at least one resource rule associated with the email resources, and adding at least one URL to the email resources in accordance with the resource rules.


