Secure IM File Transfer via Intermediary Server Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Instant Messaging (IM) systems face challenges in ensuring secure file transfers due to the lack of effective malware scanning and encryption, leading to exposure of IP addresses and increased risks of malware transmission, with existing solutions being costly and incomplete in coverage across various IM architectures and versions.
Innovation Solution
A method and system that intercepts direct file transfer requests in IM systems, redirecting users to a secure file transfer server for scanning and analysis, using upload and download URLs to facilitate secure transfers, ensuring files are scanned for malware before being approved for transfer, thereby blocking malicious content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If direct file transfer is allowed in IM systems, then ease of operation is improved, but security and malware protection deteriorate
Solution Approach 1:
The patent introduces a server as an intermediary between sending and receiving peers. The server mediates the file transfer process by receiving files from senders, scanning them for malware, and then distributing approved files to recipients. This intermediary approach maintains the convenience of direct peer-to-peer transfer while adding necessary security checks, resolving the contradiction between ease of operation and malware protection.
2Reliability
If file transfer scanning is implemented, then malware protection is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the complex malware scanning and analysis functionality from individual peer devices and consolidates it into a centralized server. This extraction eliminates the need for each peer to maintain complex transfer analysis modules, reducing device complexity and cost while maintaining comprehensive malware protection through the centralized scanning service.
3Reliability
If encryption is implemented, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements automatic encryption and decryption processes that occur without user intervention. The server automatically encrypts files during storage and transmission, and automatically decrypts them for approved recipients. This self-service approach maintains strong data security while preserving the simplicity of the user experience, as users do not need to manually manage encryption keys or settings.
4Reliability
If IP address exposure is prevented, then security is improved, but information loss increases
Solution Approach 1:
The server acts as an intermediary that masks the actual IP addresses of peers. Instead of peers directly exposing their IP addresses to each other, all communication routes through the server, which uses its own IP address as an intermediary. This protects peer privacy while maintaining the ability to identify and connect with the correct recipients through the server's mediation.
Data Source
AI summary
A method and system for providing secure peer-to-peer file transfers whereby request/negotiation message mechanisms used to negotiate file transfers between peers is used to identify/intercept, and block, direct file transfers. The request/negotiation messages are then replaced with messages sent to both peers that include upload and download URL links through which the file can be uploaded, scanned analyzed, and then transferred, via a secure file transfer server. Using the method and system for providing secure peer-to-peer file transfers disclosed herein, peer-to-peer file transfer transactions are provided protection from malware, and provided additional data security, so that peer-to-peer users can utilize this important capability without taking unacceptable risks.


