Mobile Email DLP via HTTP-to-SMTP Identity Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention (DLP) systems struggle to effectively secure sensitive data on mobile devices, as they lack the ability to identify and enforce policies on emails sent from these devices due to the loss of device identity information during conversion from HTTP to SMTP protocols.

Innovation Solution

A method and system that intercepts HTTP requests from mobile devices, inserts an SMTP compliant header with the device's identity into the HTTP body, and forwards the modified request to a server for DLP policy enforcement, ensuring that DLP systems can identify and apply policies to emails based on the originating mobile device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DLP systems use deep content inspection and analysis to protect sensitive data, then data security is improved, but the ability to identify and enforce policies on mobile device emails deteriorates due to loss of device identity information

Engineering Contradiction:
Improvedata securityVSAvoiddevice identity information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by inserting the mobile device identity into the SMTP header before the email is processed by the DLP system. This ensures that the device identity information is preserved and available for policy enforcement during subsequent DLP inspection, resolving the contradiction between maintaining data security and preventing loss of device identity information

Inventive Principle:
Principle #10Preliminary action

2Reliability

If DLP systems inspect outbound organizational email from mobile devices, then data loss prevention capability is improved, but system complexity increases due to protocol conversion and header modification requirements

Engineering Contradiction:
Improvedata loss prevention capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary component that sits between the mobile device and the DLP system to handle protocol conversion and header modification. This intermediary translates HTTP requests to SMTP format while injecting device identity information, enabling DLP inspection of mobile emails without significantly complicating the overall system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9842315B1Source mobile device identification for data loss prevention for electronic mail
Publication Date: 2017.12.12 CA TECH INC
  • US9842315B1 patent drawing
  • US9842315B1 patent drawing
  • US9842315B1 patent drawing

AI summary

The sources of emails sent from mobile devices using wireless email protocols can be identified. In one embodiment, the invention includes receiving a simple mail transfer protocol (SMTP)-formatted email sent from a mobile device as an HTTP request. An SMTP-compliant header identifying the mobile device is examined, that was inserted into the HTTP request using information contained in one or more HTTP headers of the HTTP request. Then, an email data loss prevention (DLP) policy specific to mobile devices is applied to the received email.