Email Access Control via URL Proxying and Modification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for controlling email access fail to ensure that email resources are accessed only by authorized parties in authorized manners and do not modify email resources to comply with enterprise security standards, leading to potential unauthorized access and sensitive information loss.
Innovation Solution
A system and method that includes a client device, an email service, and a processor configured to proxy email resources, remove URLs, and add modified URLs, ensuring that only authorized parties access email resources in compliance with enterprise security standards by modifying the resources to satisfy access restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access credentials are used to control email access, then authorized parties can access email resources, but the system fails to control how those resources are accessed and cannot modify resources to comply with security standards
Solution Approach 1:
The patent introduces an access control service as an intermediary component between email services and client devices. This service proxies email resources, inspects them for URLs, and modifies them by replacing URLs with modified URLs that enforce access restrictions. The intermediary handles the complexity of monitoring and modifying email content, allowing the core email system to remain simple while achieving comprehensive security control.
2Productivity
If email resources are transmitted without modification, then access speed is maintained, but unauthorized access and information loss risks increase
Solution Approach 1:
The access control service performs preliminary actions by inspecting and modifying email resources before they are transmitted to client devices. URLs are identified and replaced with modified URLs that embed access control policies in advance. This preliminary modification ensures that security restrictions are enforced during transmission without requiring real-time intervention, maintaining productivity while preventing unauthorized access.
3Reliability
If URLs are removed from email resources, then unauthorized access is prevented, but the functionality of the email resource may be degraded
Solution Approach 1:
Instead of completely removing URLs, the access control service creates modified URLs that copy the essential functionality of the original URLs while adding security controls. The modified URLs maintain the ability to access the intended resources but enforce access restrictions and monitoring. This copying approach preserves email resource functionality while ensuring security compliance.
Data Source
AI summary
Embodiments of the disclosure relate to controlling access to email content. According to various embodiments as described herein, an email message may be accessed by a computing device to identify a uniform resource locator (URL) within the email message, wherein the URL corresponds to a resource residing in a protected location that is not accessible by a native browser application of the client device. The computing device may determine whether the client device is permitted to access the URL and request access to the resource via the secure browser application of the client device upon a determination that the client device is permitted to access the resource in accordance with the at least one resource rule.


