Third-Party Email Security via Cloud API Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Third-party e-mail security vendors face challenges in accessing and responding to potentially harmful or deceptive emails reported by users of services like Microsoft Office 365 and Google Gmail without requiring end users to install custom add-ons on their email clients.
Innovation Solution
A system that uses network API calls to a cloud-based service to detect and analyze end-user actions indicating negatively assessed emails, applying machine learning to identify and take action against harmful emails, and re-trains the inspection model based on user feedback without modifying the native email clients.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If third-party security vendors implement custom e-mail client add-ons to access and analyze suspicious e-mails, then security inspection capability is improved, but device complexity and ease of operation deteriorate due to requiring users to install and manage additional software
Solution Approach 1:
The patent introduces an intermediary component - a security service provider system that acts as a mediator between the e-mail service provider and third-party security vendors. This intermediary receives suspicious e-mails through the e-mail service provider's infrastructure and distributes them to authorized third-party inspectors, eliminating the need for direct client-side add-ons while maintaining security inspection capabilities.
Solution Approach 2:
The system enables third-party security vendors to self-register and self-configure their inspection capabilities through web-based interfaces provided by the security service provider. Vendors can independently manage their inspection engines, update security rules, and receive notifications without requiring user intervention or custom client installations.
2Reliability
If third-party security vendors deploy custom e-mail client add-ons for security inspection, then security response capability is improved, but ease of operation worsens due to requiring user installation and configuration
Solution Approach 1:
The e-mail service provider acts as an intermediary that handles all interactions between users and third-party security vendors. The service provider's system receives user reports of suspicious e-mails and automatically routes them to appropriate third-party inspectors, maintaining user simplicity while enabling comprehensive security response.
Solution Approach 2:
The security service provider system provides universal access to multiple third-party security vendors through a single interface. Users interact with one standardized system that can engage multiple security inspectors simultaneously, eliminating the need for separate add-ons for each vendor while maintaining ease of operation.
3Reliability
If third-party security vendors require custom add-on installation for access to suspicious e-mails, then security inspection effectiveness is improved, but adaptability worsens due to limiting compatibility across different e-mail clients
Solution Approach 1:
The security service provider system serves as a universal intermediary that interfaces with the e-mail service provider's infrastructure rather than individual client applications. This architecture enables compatibility across all e-mail clients that use the service provider's platform, maintaining security inspection effectiveness through centralized access to suspicious e-mails.
Solution Approach 2:
The system transitions from a client-side dimension (requiring add-ons in each user's e-mail client) to a server-side dimension (centralized security service provider system). This dimensional shift enables universal compatibility across all clients while maintaining inspection effectiveness through centralized processing of suspicious e-mails.
Data Source
AI summary
A data security system, including a security manager computer making network application programming interface (API) calls to a cloud-based service that performs data exchange transactions among end users, the API calls remotely controlling the cloud-based service so that the security manager computer accesses transactions that have entered the cloud-based service, whereby an end user may forward a transaction received through the cloud-based service to a central authority as being a potentially harmful or deceptive transaction, and a data inspector operative to analyze a transaction as being indeed harmful or deceptive, by applying machine learning, wherein the security manager computer controls the cloud-based service so as to transmit to the security manager transactions forwarded to the central authority, instead of or in addition to transmitting these transactions to the central authority, for analysis by the data inspector.


