Mobile Email DLP via HTTP-to-SMTP Identity Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention (DLP) systems struggle to effectively secure sensitive data on mobile devices, as they lack the ability to identify and enforce policies on emails sent from these devices due to the loss of device identity information during conversion from HTTP to SMTP protocols.
Innovation Solution
A method and system that intercepts HTTP requests from mobile devices, inserts an SMTP compliant header with the device's identity into the HTTP body, and forwards the modified request to a server for DLP policy enforcement, ensuring that DLP systems can identify and apply policies to emails based on the originating mobile device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DLP systems use deep content inspection and analysis to protect sensitive data, then data security is improved, but the ability to identify and enforce policies on mobile device emails deteriorates due to loss of device identity information
Solution Approach 1:
The patent applies preliminary action by inserting the mobile device identity into the SMTP header before the email is processed by the DLP system. This ensures that the device identity information is preserved and available for policy enforcement during subsequent DLP inspection, resolving the contradiction between maintaining data security and preventing loss of device identity information
2Reliability
If DLP systems inspect outbound organizational email from mobile devices, then data loss prevention capability is improved, but system complexity increases due to protocol conversion and header modification requirements
Solution Approach 1:
The patent uses an intermediary component that sits between the mobile device and the DLP system to handle protocol conversion and header modification. This intermediary translates HTTP requests to SMTP format while injecting device identity information, enabling DLP inspection of mobile emails without significantly complicating the overall system architecture
Data Source
AI summary
The sources of emails sent from mobile devices using wireless email protocols can be identified. In one embodiment, the invention includes receiving a simple mail transfer protocol (SMTP)-formatted email sent from a mobile device as an HTTP request. An SMTP-compliant header identifying the mobile device is examined, that was inserted into the HTTP request using information contained in one or more HTTP headers of the HTTP request. Then, an email data loss prevention (DLP) policy specific to mobile devices is applied to the received email.


