Time-Limited Decrypted Access Rights for Encrypted Email Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic email services lack protection against unauthorized access to encrypted content, as recipients can retain encrypted emails indefinitely, increasing the risk of sensitive information being compromised by cyber attackers.
Innovation Solution
Implementing a system that allows senders to set a time period for decrypted access rights to encrypted content, automatically expiring access rights for recipients, even if the email remains in their inbox, and enabling revocation of access rights at any time after the email is sent.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted email messages are stored in recipient inbox indefinitely, then recipients can access encrypted content at any time, but the risk of sensitive information being compromised by cyber attackers increases
Solution Approach 1:
The patent applies preliminary action by establishing expiration metadata and access rights validation mechanisms in advance before the email is delivered. The system pre-configures time-limited access policies that automatically enforce decryption window constraints, ensuring that even if emails are stored indefinitely in recipient inboxes, the decrypted content can only be accessed within the predetermined time frame. This proactive security measure prevents unauthorized long-term access without requiring active monitoring or user intervention.
2Reliability
If decrypted access rights are revoked immediately after sending, then security is enhanced, but recipients cannot access the encrypted content when needed
Solution Approach 1:
The patent implements dynamics by creating time-bound access rights that automatically adjust and expire based on predetermined decryption windows. The system dynamically validates access requests against expiration metadata, allowing recipients to decrypt and access content only within the specified time frame. This dynamic access control mechanism balances security requirements with operational accessibility, ensuring that legitimate recipients can access content when needed while automatically revoking access after the expiration time without requiring manual intervention.
3Quantity of substance
If email messages with encrypted content are removed from sender inbox, then storage space is freed, but the sender loses ability to manage access rights to the content
Solution Approach 1:
The patent applies the extraction principle by separating the encrypted content storage from the access rights management functionality. The system extracts access control capabilities into a independent rights management component that can operate independently of the email storage location. This allows senders to delete encrypted emails from their inboxes to free storage space while the extracted access rights management system continues to enforce decryption windows and validate access requests through expiration metadata embedded in the encrypted content, maintaining full access management capability without requiring the original email to remain stored.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The techniques described herein enable a user that sends an email message that includes encrypted content to define a time period during which a recipient of the encrypted content has decrypted access rights. To effectively define the time period, the user can set a time at which the decrypted access rights for the recipient expire. The time occurs after a time at which the email message is sent to the recipient. Upon expiration of the time period, the decrypted access rights to the encrypted content is revoked for the recipient of the email message, thereby providing a proactive element of security for confidential and/or sensitive information. Further, the techniques enable a user to revoke decrypted access rights to the encrypted content for a recipients at any given time after the email message has already been sent, thereby adding a reactive element of security for confidential and/or sensitive information.