Email Security Engine Routing Replies via Intermediate Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional email systems face security vulnerabilities as they rely on the trustworthiness of recipients to protect and route emails securely, particularly when replies are sent over unsecured channels, potentially compromising the original email content.

Innovation Solution

Implementing an email security engine that determines when to encrypt outgoing emails and changes recipient email address data to route replies through an intermediate device over encrypted channels, ensuring that both the original email and its replies are secured.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If email encryption is implemented for outgoing emails, then email security is improved, but reply emails may be sent over unsecured channels compromising the original content

Engineering Contradiction:
Improveemail securityVSAvoidunsecured reply channels
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediate device (email security gateway) that sits between the email client and the email server. This gateway intercepts reply emails and reroutes them through secure channels, ensuring that even if the original recipient sends replies through unsecured channels, the content remains protected. The gateway acts as a mediator that maintains security policies throughout the email conversation lifecycle.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional email systems rely on recipient trustworthiness to protect email content, then system complexity is reduced, but security control is lost once email is sent

Engineering Contradiction:
Improvesystem simplicityVSAvoidsender control over sent email
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing security policies and encryption mechanisms before emails are sent. The email security gateway pre-configures secure channels, encrypts sensitive content, and sets up routing rules in advance. This allows the sender to maintain control over email content throughout its lifecycle without adding significant complexity to the email system architecture.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If email content is encrypted to protect from unauthorized access, then confidentiality is improved, but control and monitoring of email transmissions is reduced

Engineering Contradiction:
Improveemail confidentialityVSAvoidemail transmission control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms where the email security gateway continuously monitors email transmissions, encrypts content as needed, and adjusts security measures based on the sensitivity and context of each email. The system provides feedback to senders about encryption status and security measures applied, maintaining both confidentiality and operational control through automated policy enforcement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9560020B2Securing email conversations
Publication Date: 2017.01.31 MCAFEE LLC
  • US9560020B2 patent drawing
  • US9560020B2 patent drawing
  • US9560020B2 patent drawing

AI summary

At least a portion of a transmission of an outgoing first email from a first email account to at least a second email account is encrypted. Second email address data is changed corresponding to the second email account to cause replies to the first email intended for the second email account to be sent to an intermediate device prior to being routed to the second email account. Replies to the first email are then sent to the intermediate device and sent over one or more encrypted channels. Replies to the first email including the changed email address data are decoded to identify the second email address data associated with the second email account. A reply to the first email is then sent to the second email account based on the identified second email address data.