Federation Server Token Exchange for Secure Inter-Organization Email

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Email security is inadequate due to its lack of encryption and susceptibility to interception and spoofing, especially when messages traverse unsecured networks, and existing solutions for secure email exchange between organizations are cumbersome and do not scale well.

Innovation Solution

An email security system utilizing a federation server that provides tokens for secure communication between email servers of different organizations, allowing encryption and decryption of messages using public and private keys, ensuring secure transmission across unsecured networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If email messages are transmitted over unsecured networks using SMTP, then email delivery is simple and widely compatible, but message security and confidentiality are compromised due to lack of encryption and susceptibility to interception

Engineering Contradiction:
Improveemail delivery compatibilityVSAvoidmessage security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a federation server as an intermediary that acts as a trusted third party between email servers of different organizations. This mediator issues security tokens that enable encrypted communication without requiring direct key exchange between communicating parties, thus maintaining compatibility while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary key exchange and token issuance through the federation server before actual email communication occurs. Organizations pre-register with the federation server, which stores their public keys and issues tokens in advance, eliminating the need for ad-hoc key exchange and enabling immediate secure communication.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If organizations exchange certificates and use SSL or IPSEC for secure email transmission, then message security is improved, but the complexity of key management and certificate exchange increases significantly

Engineering Contradiction:
Improvemessage securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The federation server serves as a centralized intermediary that manages all certificate and key operations. Instead of each organization maintaining complex bilateral key management relationships, the federation server centralizes trust, issuing tokens that simplify the key management process while maintaining strong security through cryptographic protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If each organization securely conveys storage media with keys to every other organization for secure email exchange, then direct secure communication is enabled, but the scalability of the system deteriorates as the number of organizations increases

Engineering Contradiction:
Improvedirect secure communicationVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The federation server provides universal service to all member organizations, acting as a single point of trust that enables any organization to communicate securely with any other. This multi-functional hub approach replaces the need for numerous bilateral key exchange relationships, achieving both direct secure communication and scalability through a centralized coordination point.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By introducing the federation server as an intermediary, the system transforms the scaling problem from O(n²) bilateral relationships to O(n) relationships with the central mediator. Each organization only needs to establish trust with the federation server once, enabling efficient scaling as new organizations join the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If private email servers transmit email over secure corporate networks using LAN or VPN, then message security within organizations is maintained, but communication between different organizations becomes impossible

Engineering Contradiction:
Improveinternal email securityVSAvoidinter-organization communication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The federation server acts as a trusted intermediary that bridges isolated corporate email systems. By establishing trust relationships with the federation server, organizations can securely extend their internal email security policies to external communications without requiring direct physical or network connections between organizations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9917828B2Secure message delivery using a trust broker
Publication Date: 2018.03.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9917828B2 patent drawing
  • US9917828B2 patent drawing
  • US9917828B2 patent drawing

AI summary

An email security system is described that allows users within different organizations to securely send email to one another. The email security system provides a federation server on the Internet or other unsecured network accessible by each of the organizations. Each organization provides identity information to the federation server. When a sender in one organization sends a message to a recipient in another organization, the federation server provides the sender's email server with a secure token for encrypting the message to provide secure delivery over the unsecured network.