Email Server Discovery Secret Header for Secure Domain Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems are vulnerable to spam and denial of service attacks when attempting to identify potential correspondents directly, lacking a secure method to establish a compatible interconnection between domains.

Innovation Solution

A system and method where an email server adds a discovery secret header to messages, allowing the detection of compatible secure email technology by verifying administrative messages with a specific secret, enabling secure connections between domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If systems communicate directly to identify potential correspondents, then the identification process is simple and direct, but the system becomes vulnerable to spam and denial of service attacks

Engineering Contradiction:
Improveidentification processVSAvoidsecurity against spam and DoS attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism using discovery secrets embedded in email headers as a mediator between domains. Instead of direct communication for identification, the system uses these secret headers as a trusted intermediary that enables secure discovery of compatible mail servers without exposing the system to spam and DoS attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by pre-embedding discovery secrets in email headers before the actual communication identification process. This preliminary placement of security mechanisms allows the system to verify compatibility and establish secure connections without exposing vulnerable communication channels to attackers.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a discovery secret header is added to messages, then secure identification and compatibility verification are enabled, but message complexity and processing overhead increase

Engineering Contradiction:
Improvesecure connection establishmentVSAvoidmessage structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security function into a separate discovery secret header component that can be independently processed. This segmentation allows the security verification mechanism to be isolated from the main message body, enabling efficient processing where only the header needs to be validated for compatibility while the main message content remains unchanged.

Inventive Principle:
Principle #1Segmentation

3Reliability

If administrative messages require verification with secrets, then security against unauthorized access is improved, but the complexity of message verification increases

Engineering Contradiction:
Improveauthorization controlVSAvoidverification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback through the discovery secret verification mechanism, where the system checks whether received administrative messages contain the expected secret header. This feedback loop provides automatic authorization control by comparing the secret in the message header against the expected value, enabling secure verification without complex manual processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7529937B2System and method for establishing that a server and a correspondent have compatible secure email
Publication Date: 2009.05.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7529937B2 patent drawing
  • US7529937B2 patent drawing
  • US7529937B2 patent drawing

AI summary

A discovery secret is transmitted from the source domain to the correspondent domain. The discovery secret includes a data element specific to the correspondent domain and. The discovery secret includes a source domain address to which the correspondent domain is permitted send a message in order to determine that a potential correspondent has compatible secure email technology so that a link between the source domain and the correspondent domain may be established. The discovery secret is received by the correspondent domain including receiving the data element and the source domain address. An invitation is transmitted from the correspondent domain to the source domain address. The invitation includes the data element or an element corresponding to the data element. The source domain initiates a process to establish a link with the correspondent domain upon receipt by the source domain of the invitation.