Web Email Security Classification via Metadata Headers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web-based email systems lack effective classification and management capabilities, particularly in corporate environments, as they do not allow users to assign meaningful security classifications, distribution restrictions, or retention policies to emails, leading to difficulties in handling and distributing sensitive information.

Innovation Solution

A method and system for message security classification in web email access clients that includes a classification toolbar allowing users to select predefined security classifications, assigning metadata properties, and inserting visual markings into email headers, enabling administrators to enforce compliance and retention policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If web-based email systems use pre-defined importance properties (Low Priority, Urgent), then the system is easy to operate, but the system cannot satisfy corporate security and distribution control requirements

Engineering Contradiction:
Improvesecurity classification capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system pre-defines a set of standard classification categories (Confidential, Internal, Public, etc.) with associated handling rules before email composition begins. Users select from these pre-configured options rather than creating custom classifications, achieving corporate security requirements while maintaining ease of use through preliminary system configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transforms the email message by adding classification parameters and metadata headers (X-Classification, X-Handling-Instructions) that encode security and distribution rules. This parameter enrichment enables corporate control requirements without changing the core email system architecture.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If email classification properties are not assigned, then the email system remains simple, but recipients cannot identify security requirements and compliance verification is impossible

Engineering Contradiction:
Improvecompliance verification capabilityVSAvoidclassification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces classification metadata headers as intermediary elements between the email content and compliance verification processes. These headers (X-Classification, X-Handling-Instructions) carry security requirements without requiring complex changes to email clients or servers, enabling reliable compliance verification through standard email infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts classification and handling instructions as separate metadata properties from the email body, storing them in dedicated headers. This separation allows compliance verification to operate on structured classification data independent of the email content, simplifying both the classification system and verification processes.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If web-based email systems allow user-defined classification properties, then the system adapts to corporate needs, but the system becomes more complex and difficult to maintain

Engineering Contradiction:
Improvecorporate policy adaptabilityVSAvoiduser operation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Administrators pre-configure classification categories and associated handling rules according to corporate policies before users interact with the system. Users then select from these pre-defined options during email composition, achieving corporate policy adaptability while maintaining user operation simplicity through guided selection rather than free-form input.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The classification system uses universal metadata headers (X-Classification, X-Handling-Instructions) that can encode multiple types of corporate requirements (security levels, distribution restrictions, retention policies) within a single standardized framework, making the system adaptable to diverse corporate needs without requiring separate mechanisms for each policy type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8239473B2Security classification of e-mail in a web e-mail access client
Publication Date: 2012.08.07 TITUS INC
  • US8239473B2 patent drawing
  • US8239473B2 patent drawing
  • US8239473B2 patent drawing

AI summary

Web based e-mail classification is disclosed. A popup dialog adds the ability to classify message such as web e-mail, calendar items and meeting appointments based on specific properties such as security classification, information type, document type, document retention, document caveats, and the like associated with the message. The popup dialog through dropdown selections allows users to select the appropriate classification and properties based upon the content of the message. Administrators can predefine all the classification selections that are available to the user. E-mail classification properties are generated that are associated with the message by metadata insertion and by inserting visual markings that allow users to quickly identify the security, sensitivity, intended distribution or retention of the e-mail or calendar item. By utilizing the classification popup dialog a user can classify an e-mail by one or more classification levels and be ensured that the message is delivered and processed in the appropriate manner.