Local Mail Proxy for Offline Security Command Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise environments, there is a need to enforce compliance with access restrictions on client devices to prevent unauthorized access to corporate resources, particularly when users attempt to bypass software or hardware limitations, such as gaining root access or installing unapproved applications.

Innovation Solution

Implementing a local mail proxy on the client device that communicates with a remote mail server, which enforces compliance rules by issuing security commands, such as a wipe command, if the device is found to have violated these restrictions, ensuring secure access to enterprise data even if network access is impaired.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a remote mail server issues wipe commands to client devices, then security control over enterprise resources is improved, but network dependency increases and reliability deteriorates when network access is impaired

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A local mail proxy is introduced as an intermediary component on the client device that receives and processes wipe commands locally. The proxy acts as a mediator between the remote mail server and the mail client application, enabling security commands to be executed even when network connectivity is unavailable. This resolves the contradiction by maintaining security control reliability while reducing network dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If compliance rules are strictly enforced on client devices, then protection of corporate resources is improved, but user flexibility and ease of operation deteriorate

Engineering Contradiction:
Improveprotection of corporate resourcesVSAvoiduser flexibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system implements feedback mechanisms where the local mail proxy continuously monitors compliance status of the client device against enterprise policies. When compliance violations are detected (such as unauthorized applications or root access attempts), the system automatically responds by issuing wipe commands or notifying administrators. This feedback loop maintains strong security controls while allowing users operational flexibility as long as compliance requirements are met.

Inventive Principle:
Principle #23Feedback

3Reliability

If local mail proxy is implemented on client devices, then reliability of security command execution is improved, but device complexity and ease of manufacture deteriorate

Engineering Contradiction:
Improvesecurity command executionVSAvoidclient device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The local mail proxy is designed as a multi-functional component that handles multiple tasks: receiving and processing wipe commands, monitoring compliance status, managing local mail client communication, and providing offline security enforcement. By consolidating these functions into a single universal proxy component, the system improves reliability without proportionally increasing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10187425B2Issuing security commands to a client device
Publication Date: 2019.01.22 OMNISSA LLC
  • US10187425B2 patent drawing
  • US10187425B2 patent drawing
  • US10187425B2 patent drawing

AI summary

Disclosed are various embodiments for ensuring a client device complies with a compliance rule. An application executed by the client device can receive a request to communicate with a mail server. The request can be sent from a mail client executed on the client device. The application can determine whether the client device complies with a compliance rule. The request can be forwarded to a remote mail server when the client device complies with the compliance rule.