Email Routing Security via Subnetwork Access Points
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic mail services lack effective security measures to ensure that emails are routed according to the security policies defined within specific domains of both the sender and recipient, and there is a need to manage varying network bandwidth and reception quality among multiple recipients.
Innovation Solution
A method for securing email routing between sender and recipient servers through an IP network with multiple sub-networks of different security levels, where the sender server analyzes the email content to determine the appropriate security level and selects the correct entry access point for transmission, and also dynamically manages attachments and delivery indicators based on network conditions and recipient capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If email is transmitted through IP network without security level analysis, then transmission speed is improved, but security level is worsened
Solution Approach 1:
The patent applies preliminary action by analyzing the email content and determining the required security level before the email is transmitted through the IP network. The sending server interrogates the network orchestrator to obtain subnetwork identifiers that match the required security level, ensuring security compliance is established in advance rather than during transmission, thus maintaining both speed and security.
2Reliability
If multiple sub-networks with different security levels are implemented, then security level compliance is improved, but network complexity is worsened
Solution Approach 1:
The patent introduces a network orchestrator as an intermediary component that manages the complexity of multiple sub-networks with different security levels. The orchestrator maintains a mapping between security levels and subnetwork identifiers, and automatically responds to interrogation requests from sending servers. This intermediary handles the complex routing decisions, allowing the email servers to simply query and transmit without managing the underlying network complexity.
3Measurement precision
If email content analysis is performed to determine security level, then security level accuracy is improved, but processing time is worsened
Solution Approach 1:
The patent extracts the security level determination process as a separate, dedicated function performed by the sending server. Instead of integrating security analysis into the general email processing workflow, the system specifically extracts the content analysis and security level determination as distinct steps. This allows the analysis to be performed efficiently on relevant content elements while maintaining accurate security level determination.
4Loss of energy
If attachments are dynamically managed based on network conditions, then bandwidth efficiency is improved, but system complexity is worsened
Solution Approach 1:
The patent applies dynamics by making attachment management adaptive to real-time network conditions. The system dynamically determines whether to transmit attachments directly or store them on remote servers based on current bandwidth availability and network state. This dynamic approach allows the system to optimize bandwidth usage by switching between different attachment transmission strategies, with the complexity managed through automated decision-making based on network orchestrator feedback.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
In order to route an e-mail between a transmitting server (10) and a recipient server (30), connected by an IP network (20) which comprises at least first and second sub-networks (21; 22) having different levels of security, a data packet being transmitted between two nodes of the first sub-network (21) and respectively of the second sub-network (22), by guaranteeing that at each point of the routing path between said two nodes, the data packet will be treated in accordance with a first security level, respectively a second security level, this method consisting of: analysing the content of an e-mail to be sent, in order to determine a security level indicator value corresponding to the security level with which to route the e-mail; selecting, depending on the security level indicator value and the first and second security levels, a first point of access (23) to the first sub-network or a second point of access (24) to the second sub-network as a point of access to the IP network (20); and transmitting the email to the selected point of access.